My computers absolutely taken over,,cant even stop crackers from uninstalling hijacck this!!

Posted 9/26/2006 5:23 AM
#36873
User avatar

SirPkralot Member

Date Joined Nov 2016
Total Posts: 4
hi i have written many paragraphd before..only to have it dissapear before posting...

so i will be brief



i have major takeover probs for the last 15 months..serious crackers or ..."enemie" have used remoe/messenger.windows media etc atc, and are able to gain access to, and make my computer a limited account on some ?? sever..which captures all info and is msking me frustated (15 months



here is a copy of SD backup systems..which I have not touched, and should be in default mode....but I think not



please give me some feedback



ty



sirpkralot



aka john

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Abiosdsk]
"ErrorControl"=dword:00000000
"Group"="Primary disk"
"Start"=dword:00000004
"Tag"=dword:00000003
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\abp480n5]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000038
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\abp480n5\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\abp480n5\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ACPI]
"ErrorControl"=dword:00000001
"Group"="Boot Bus Extender"
"Start"=dword:00000000
"Tag"=dword:00000001
"Type"=dword:00000001
"DisplayName"="Microsoft ACPI Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,41,00,43,00,50,00,49,00,2e,00,73,\
00,79,00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ACPI\Enum]
"0"="ACPI_HAL\\PNP0C08\\0"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ACPIEC]
"ErrorControl"=dword:00000001
"Group"="Boot Bus Extender"
"Start"=dword:00000004
"Tag"=dword:00000005
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\adpu160m]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000003c
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\adpu160m\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\adpu160m\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aec]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
72,00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,65,00,63,00,2e,00,73,00,79,\
00,73,00,00,00
"DisplayName"="Microsoft Kernel Acoustic Echo Canceller"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aec\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AFD]
"Type"=dword:00000001
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,66,00,64,00,2e,00,73,00,79,00,\
73,00,00,00
"DisplayName"="AFD Networking Support Environment"
"Group"="TDI"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AFD\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AFD\Enum]
"0"="Root\\LEGACY_AFD\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\agp440]
"Type"=dword:00000001
"Start"=dword:00000000
"ErrorControl"=dword:00000001
"Tag"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,67,00,70,00,34,00,34,00,30,\
00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Intel AGP Bus Filter"
"Group"="PnP Filter"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\agp440\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\agp440\Enum]
"0"="PCI\\VEN_8086&DEV_1A31&SUBSYS_00000000&REV_04\\3&13c0b0c5&0&08"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Aha154x]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000006
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Aha154x\Parameters]
"LegacyAdapterDetection"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Aha154x\Parameters\PnpInterface]
"1"=dword:00000001
"3"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78u2]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000034
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78u2\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78u2\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78xx]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000001e
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78xx\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\aic78xx\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ALG]
"Type"=dword:00000010
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,61,\
00,6c,00,67,00,2e,00,65,00,78,00,65,00,00,00
"DisplayName"="Application Layer Gateway Service"
"ObjectName"="NT AUTHORITY\\LocalService"
"Description"="Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Internet Connection Firewall"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ALG\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ALG\Enum]
"0"="Root\\LEGACY_ALG\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AliIde]
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Start"=dword:00000004
"Tag"=dword:00000004
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\amsint]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000024
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\amsint\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\amsint\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AppMgmt]
"Description"="Provides software installation services such as Assign, Publish, and Remove."
"DisplayName"="Application Management"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000003
"Type"=dword:00000020

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AppMgmt\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
61,00,70,00,70,00,6d,00,67,00,6d,00,74,00,73,00,2e,00,64,00,6c,00,6c,00,00,\
00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AppMgmt\Security]
"Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\
02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\
18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,\
00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000029
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3350p]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000039
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3350p\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3350p\Parameters\PnpInterface]
"1"=dword:00000011

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3550]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000002a
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3550\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\asc3550\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AsyncMac]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,73,00,79,00,6e,00,63,00,6d,\
00,61,00,63,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="RAS Asynchronous Media Driver"
"Description"="RAS Asynchronous Media Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AsyncMac\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\atapi]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000000
"Tag"=dword:00000019
"Type"=dword:00000001
"DisplayName"="Standard IDE/ESDI Hard Disk Controller"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,74,00,61,00,70,00,69,00,2e,\
00,73,00,79,00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\atapi\Parameters]
"LegacyDetection"=dword:00000001
"GhostSlave"=hex(7):53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,20,00,00,00,00,\
00
"UseCheckPowerForFlush"=hex(7):53,00,41,00,4d,00,53,00,55,00,4e,00,47,00,20,00,\
57,00,4e,00,52,00,2d,00,33,00,31,00,36,00,30,00,31,00,41,00,20,00,28,00,31,\
00,36,00,30,00,30,00,4d,00,42,00,29,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,41,00,4d,00,53,00,55,\
00,4e,00,47,00,20,00,57,00,4e,00,52,00,2d,00,33,00,31,00,36,00,30,00,31,00,\
41,00,20,00,28,00,31,00,2e,00,36,00,47,00,42,00,29,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,49,00,\
42,00,4d,00,2d,00,44,00,54,00,43,00,41,00,2d,00,32,00,34,00,30,00,39,00,30,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,54,00,43,00,36,00,4f,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,\
4d,00,2d,00,44,00,54,00,43,00,41,00,2d,00,32,00,34,00,30,00,39,00,30,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,54,00,43,00,36,00,49,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,\
2d,00,44,00,50,00,4c,00,41,00,2d,00,32,00,35,00,31,00,32,00,30,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,\
00,4c,00,38,00,4f,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,\
44,00,50,00,4c,00,41,00,2d,00,32,00,35,00,31,00,32,00,30,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,\
00,38,00,49,00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,\
50,00,4c,00,41,00,2d,00,32,00,35,00,31,00,32,00,30,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,00,38,\
00,49,00,41,00,41,00,34,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,54,00,\
43,00,41,00,2d,00,32,00,33,00,32,00,34,00,30,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,54,00,43,00,35,00,4f,\
00,41,00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,54,00,43,00,\
41,00,2d,00,32,00,33,00,32,00,34,00,30,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,54,00,43,00,35,00,49,00,41,\
00,41,00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,50,00,4c,00,41,00,\
2d,00,32,00,34,00,34,00,38,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,00,37,00,4f,00,41,00,41,\
00,32,00,41,00,00,00,49,00,42,00,4d,00,2d,00,44,00,50,00,4c,00,41,00,2d,00,\
32,00,34,00,34,00,38,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,50,00,4c,00,37,00,49,00,41,00,41,00,32,\
00,41,00,00,00,00,00
"NoFlushDevice"=hex(7):51,00,55,00,41,00,4e,00,54,00,55,00,4d,00,5f,00,4c,00,\
50,00,53,00,35,00,32,00,35,00,41,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,43,00,52,00,2d,00,37,00,33,\
00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,00,00
"PioOnlyDevice"=hex(7):20,00,20,00,20,00,20,00,43,00,6f,00,6e,00,6e,00,65,00,\
72,00,20,00,50,00,65,00,72,00,69,00,70,00,68,00,65,00,72,00,61,00,6c,00,73,\
00,20,00,34,00,32,00,35,00,4d,00,42,00,20,00,2d,00,20,00,43,00,46,00,53,00,\
34,00,32,00,35,00,41,00,20,00,20,00,00,00,4d,00,41,00,54,00,53,00,48,00,49,\
00,54,00,41,00,20,00,43,00,52,00,2d,00,35,00,38,00,31,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,46,00,58,00,\
36,00,30,00,30,00,53,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,00,00,43,00,44,00,2d,00,34,00,34,00,45,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,00,00,51,00,55,00,41,00,4e,00,54,00,55,00,4d,00,20,\
00,54,00,52,00,42,00,38,00,35,00,30,00,41,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,51,00,55,00,41,00,4e,00,\
54,00,55,00,4d,00,20,00,4d,00,41,00,52,00,56,00,45,00,52,00,49,00,43,00,4b,\
00,20,00,35,00,34,00,30,00,41,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,20,\
00,4d,00,41,00,58,00,54,00,4f,00,52,00,20,00,4d,00,58,00,54,00,2d,00,35,00,\
34,00,30,00,20,00,20,00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,31,00,32,\
00,36,00,30,00,20,00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,\
20,00,37,00,38,00,35,00,30,00,20,00,41,00,56,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,\
00,74,00,6f,00,72,00,20,00,37,00,35,00,34,00,30,00,20,00,41,00,56,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,32,00,31,00,33,00,20,\
00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,\
33,00,34,00,35,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,\
00,72,00,20,00,37,00,32,00,34,00,35,00,20,00,41,00,54,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,4d,00,\
61,00,78,00,74,00,6f,00,72,00,20,00,37,00,32,00,34,00,35,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,00,37,00,32,00,31,00,\
31,00,41,00,55,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,00,00,4d,00,61,00,78,00,74,00,6f,00,72,00,20,\
00,37,00,31,00,37,00,31,00,20,00,41,00,54,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,43,00,44,00,2d,00,\
33,00,31,00,36,00,45,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,\
00,53,00,41,00,4d,00,53,00,55,00,4e,00,47,00,5f,00,53,00,43,00,52,00,2d,00,\
32,00,34,00,33,00,30,00,00,00,43,00,52,00,2d,00,32,00,38,00,30,00,31,00,54,\
00,45,00,00,00,00,00
"NonRemovableMedia"=hex(7):4b,00,69,00,6e,00,67,00,73,00,74,00,6f,00,6e,00,20,\
00,54,00,65,00,63,00,68,00,6e,00,6f,00,6c,00,6f,00,67,00,79,00,20,00,44,00,\
61,00,74,00,61,00,50,00,61,00,6b,00,20,00,33,00,34,00,30,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,75,00,6e,00,44,00,69,00,\
73,00,6b,00,20,00,53,00,44,00,50,00,35,00,41,00,2d,00,31,00,30,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,75,\
00,6e,00,44,00,69,00,73,00,6b,00,20,00,53,00,44,00,43,00,46,00,42,00,2d,00,\
31,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,00,00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,20,00,53,00,44,00,50,\
00,33,00,42,00,2d,00,32,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,00,00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,\
20,00,53,00,44,00,50,00,33,00,42,00,2d,00,31,00,37,00,35,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,53,00,75,00,6e,00,44,\
00,69,00,73,00,6b,00,20,00,53,00,44,00,50,00,35,00,2d,00,32,00,2e,00,35,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,\
43,00,61,00,6c,00,6c,00,75,00,6e,00,61,00,20,00,54,00,65,00,63,00,68,00,6e,\
00,6f,00,6c,00,6f,00,67,00,79,00,20,00,43,00,54,00,32,00,36,00,30,00,4d,00,\
43,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,00,00,42,00,4e,00,2d,00,53,00,30,00,30,00,34,00,41,00,43,00,\
2d,00,53,00,20,00,31,00,2e,00,30,00,30,00,00,00,43,00,61,00,6c,00,6c,00,75,\
00,6e,00,61,00,20,00,54,00,65,00,63,00,68,00,6e,00,6f,00,6c,00,6f,00,67,00,\
79,00,20,00,43,00,54,00,35,00,32,00,30,00,52,00,4d,00,00,00,48,00,69,00,74,\
00,61,00,63,00,68,00,69,00,20,00,43,00,56,00,20,00,35,00,2e,00,31,00,2e,00,\
31,00,00,00,20,00,20,00,20,00,20,00,20,00,20,00,41,00,54,00,41,00,5f,00,46,\
00,4c,00,41,00,53,00,48,00,20,00,00,00,4d,00,69,00,74,00,73,00,75,00,62,00,\
69,00,73,00,68,00,69,00,20,00,41,00,54,00,41,00,20,00,43,00,61,00,72,00,64,\
00,20,00,00,00,4c,00,45,00,58,00,41,00,52,00,20,00,41,00,54,00,41,00,5f,00,\
46,00,4c,00,41,00,53,00,48,00,00,00,4d,00,69,00,63,00,72,00,6f,00,6e,00,20,\
00,4d,00,54,00,43,00,46,00,30,00,30,00,34,00,41,00,00,00,4d,00,69,00,63,00,\
72,00,6f,00,6e,00,20,00,4d,00,54,00,43,00,46,00,30,00,30,00,38,00,41,00,00,\
00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,00,20,00,53,00,44,00,50,00,33,00,\
42,00,2d,00,31,00,31,00,30,00,00,00,53,00,75,00,6e,00,44,00,69,00,73,00,6b,\
00,20,00,53,00,44,00,43,00,46,00,42,00,2d,00,34,00,00,00,42,00,4e,00,2d,00,\
43,00,41,00,42,00,2d,00,54,00,00,00,4d,00,45,00,4d,00,4f,00,52,00,59,00,53,\
00,54,00,49,00,43,00,4b,00,00,00,4d,00,45,00,4d,00,4f,00,52,00,59,00,53,00,\
54,00,49,00,43,00,4b,00,20,00,20,00,20,00,38,00,4d,00,20,00,20,00,38,00,4b,\
00,00,00,00,00
"NoPowerDownDevice"=hex(7):52,00,44,00,2d,00,44,00,52,00,43,00,30,00,30,00,31,\
00,2d,00,4d,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,43,00,53,00,2d,00,52,00,33,00,\
37,00,20,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,00,00,00,00
"AutoEjectZipDevice"=hex(7):49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,\
00,49,00,50,00,20,00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,41,00,54,00,41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,20,00,32,00,33,00,2e,00,44,00,20,00,20,00,\
20,00,20,00,00,00,49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,\
00,50,00,20,00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
41,00,54,00,41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,20,00,32,00,31,00,2e,00,44,00,20,00,20,00,20,00,\
20,00,00,00,49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,\
00,20,00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,41,00,\
54,00,41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,20,00,32,00,30,00,2e,00,44,00,20,00,20,00,20,00,20,00,\
00,00,49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,00,20,\
00,31,00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,41,00,54,00,\
41,00,50,00,49,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,20,00,39,00,31,00,2e,00,44,00,20,00,20,00,20,00,20,00,00,00,\
49,00,4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,00,20,00,31,\
00,30,00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,20,00,42,00,2e,00,32,00,39,00,20,00,20,00,20,00,20,00,00,00,49,00,\
4f,00,4d,00,45,00,47,00,41,00,20,00,20,00,5a,00,49,00,50,00,20,00,31,00,30,\
00,30,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,\
20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,00,20,\
00,20,00,42,00,2e,00,32,00,32,00,20,00,20,00,20,00,20,00,00,00,00,00
"NeedIdentDevice"=hex(7):51,00,55,00,41,00,4e,00,54,00,55,00,4d,00,20,00,46,00,\
49,00,52,00,45,00,42,00,41,00,4c,00,4c,00,00,00,00,00
"DefaultPioAtapiDevice"=hex(7):54,00,4f,00,52,00,69,00,53,00,41,00,4e,00,20,00,\
44,00,56,00,44,00,2d,00,52,00,4f,00,4d,00,20,00,44,00,52,00,44,00,2d,00,4e,\
00,32,00,31,00,36,00,00,00,49,00,44,00,45,00,2d,00,43,00,44,00,20,00,52,00,\
2f,00,52,00,57,00,20,00,32,00,78,00,32,00,78,00,32,00,34,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\atapi\Enum]
"0"="PCIIDE\\IDEChannel\\4&e3ec092&0&0"
"Count"=dword:00000002
"NextInstance"=dword:00000002
"1"="PCIIDE\\IDEChannel\\4&e3ec092&0&1"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Atdisk]
"ErrorControl"=dword:00000000
"Group"="Primary disk"
"Start"=dword:00000004
"Tag"=dword:00000001
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Atmarpc]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"Tag"=dword:0000000b
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,74,00,6d,00,61,00,72,00,70,\
00,63,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="ATM ARP Client Protocol"
"Group"="NDIS"
"DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"Description"="ATM ARP Client Protocol"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Atmarpc\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AudioSrv]
"DependOnService"=hex(7):50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,00,00,\
52,00,70,00,63,00,53,00,73,00,00,00,00,00
"Description"="Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start."
"DisplayName"="Windows Audio"
"ErrorControl"=dword:00000001
"Group"="AudioGroup"
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000002
"Type"=dword:00000020

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AudioSrv\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
61,00,75,00,64,00,69,00,6f,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,\
00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AudioSrv\Enum]
"0"="Root\\LEGACY_AUDIOSRV\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\audstub]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,61,00,75,00,64,00,73,00,74,00,75,\
00,62,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Audio Stub Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\audstub\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\audstub\Enum]
"0"="Root\\MEDIA\\MS_MMACM"
"Count"=dword:00000005
"NextInstance"=dword:00000005
"1"="Root\\MEDIA\\MS_MMDRV"
"2"="Root\\MEDIA\\MS_MMMCI"
"3"="Root\\MEDIA\\MS_MMVCD"
"4"="Root\\MEDIA\\MS_MMVID"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Alrt]
"Type"=dword:00000110
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,41,00,7e,00,\
31,00,5c,00,47,00,72,00,69,00,73,00,6f,00,66,00,74,00,5c,00,41,00,56,00,47,\
00,46,00,52,00,45,00,7e,00,31,00,5c,00,61,00,76,00,67,00,61,00,6d,00,73,00,\
76,00,72,00,2e,00,65,00,78,00,65,00,00,00
"DisplayName"="AVG7 Alert Manager Server"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Alrt\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Alrt\Enum]
"0"="Root\\LEGACY_AVG7ALRT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Core]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"Tag"=dword:00000001
"ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,76,00,67,00,37,00,63,00,6f,00,\
72,00,65,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="AVG7 Kernel"
"Group"="AVG"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Core\Parameters]
"AvgDir"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\"
"AvgLng"=dword:00000001
"TempDir"="C:\\DOCUME~1\\ALLUSE~1\\APPLIC~1\\Grisoft\\Avg7Data\\"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Core\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7Core\Enum]
"0"="Root\\LEGACY_AVG7CORE\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsW]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"Tag"=dword:00000002
"ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,76,00,67,00,37,00,72,00,73,00,\
77,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="AVG7 Wrap Driver"
"Group"="AVG"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsW\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsW\Enum]
"0"="Root\\LEGACY_AVG7RSW\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsXP]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"Tag"=dword:00000003
"ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,76,00,67,00,37,00,72,00,73,00,\
78,00,70,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="AVG7 Resident Driver XP"
"Group"="AVG"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsXP\Parameters]
"Params"=dword:0005c007
"IgnoreFilesystem"=dword:000000c0
"Extensions"=hex:36,69,c4,8b,53,68,0c,c8,f7,fa,2a,09,15,f2,ab,88,44,3a,ca,67,\
e6,cf,eb,95,e5,93,34,f4,36,6a,c4,8b,53,3c,4d,8a,28,33,ed,c5,ca,2d,74,57,44,\
74,83,55,39,40,67,0b,3a,4c,eb,2b,36,3a,89,c9,8c,b7,d3,17,f7,ec,32,1a,ca,62,\
3b,15,9b,e5,15,c8,e6,9f,b8,d4,3a,01,a3,68,e9,b5,1b,54,53,68,0c,c8,f7,ad,7e,\
59,15,f2,ab,88,44,3a,ca,17,b5,de,f4,97,e5,93,34,f4,36,6a,c4,8b,53,2c,41,8b,\
28,33,ed,c5,ca,2d,74,57,44,77,84,54,39,40,67,0b,3a,4c,eb,2b,36,27,8b,c8,8c,\
b7,d3,17,f7,ec,32,1a,ca,61,24,14,9b,e5,15,c8,e6,9f,b8,d4,3a,1a,ae,6f,e9,b5,\
1b,54,53,68,0c,c8,f7,a0,7e,5e,15,f2,ab,88,44,3a,ca,17,e6,9f,f7,90,3a,4c,34,\
f4,36,6a,c4,8b,53,3e,5e,8c,28,33,ed,c5,ca,2d,74,57,44,76,87,52,39,40,67,0b,\
3a,4c,eb,2b,36,2f,9c,ce,8c,b7,d3,17,f7,ec,32,1a,ca,6b,3d,10,9b,e5,15,c8,e6,\
9f,b8,d4,3a,1c,a7,63,e9,b5,1b,54,53,68,0c,c8,f7,ec,66,52,ca,2d,ab,88,44,3a,\
ca,17,e6,d6,f6,9d,e5,93,34,f4,36,6a,c4,8b,14,2d,5c,82,28,33,ed,c5,ca,2d,74,\
57,44,7d,9a,5d,39,40,67,0b,3a,4c,eb,2b,36,6a,97,c1,53,68,d3,17,f7,ec,32,1a,\
ca,66,3a,1b,9b,e5,15,c8,e6,9f,b8,d4,3a,4c,af,66,36,6a,1b,54,53,68,0c,c8,f7,\
ab,61,57,15,f2,ab,88,44,3a,ca,17,e6,cc,ef,9a,e5,93,34,f4,36,6a,c4,8b,53,30,\
4f,87,28,33,ed,c5,ca,2d,74,57,44,3a,9c,58,e6,9f,67,0b,3a,4c,eb,2b,36,32,87,\
db,8c,b7,d3,17,f7,ec,32,1a,ca,60,33,07,9b,e5,15,c8,e6,9f,b8,d4,3a,1c,a3,7b,\
36,b5,1b,54,53,68,0c,c8,f7,aa,7b,4a,15,f2,ab,88,44,3a,ca,17,e6,9f,f4,84,3a,\
4c,34,f4,36,6a,c4,8b,53,2f,42,98,28,33,ed,c5,ca,2d,74,57,44,6e,85,47,39,40,\
67,0b,3a,4c,eb,2b,36,6a,94,db,53,68,d3,17,f7,ec,32,1a,ca,7f,37,04,9b,e5,15,\
c8,e6,9f,b8,d4,3a,1f,a3,78,e9,b5,1b,54,53,68,0c,c8,f7,a1,7f,49,15,f2,ab,88,\
44,3a,ca,17,e6,cc,e1,87,e5,93,34,f4,36,6a,c4,8b,53,2e,45,9c,28,33,ed,c5,ca,\
2d,74,57,44,7f,88,41,39,40,67,0b,3a,4c,eb,2b,36,39,86,dd,8c,b7,d3,17,f7,ec,\
32,1a,ca,75,36,01,9b,e5,15,c8,e6,9f,b8,d4,3a,08,b3,7d,e9,b5,1b,54,53,68,0c,\
c8,f7,aa,7f,4d,15,f2,ab,88,44,3a,ca,17,e6,9f,f4,8c,3a,4c,34,f4,36,6a,c4,8b,\
53,24,41,90,28,33,ed,c5,ca,2d,74,57,44,3a,86,4d,e6,9f,67,0b,3a,4c,eb,2b,c9,\
95,3b,74,53,68,0c,c8,f7,ec,32,1a,35,d2,8b,a8,44,3a,ca,17,e6,9f,b8,d4,c5,b3,\
14,d4,36,6a,c4,8b,53,68,0c,c8,08,13,cd,e5,ca,2d,74,57,44,3a,ca,17,19,60,47,\
2b,3a,4c,eb,2b,36,6a,c4,8b,ac,97,f3,37,f7,ec,32,1a,ca,2d,74,57,bb,c5,35,e8,\
e6,9f,b8,d4,3a,4c,eb,2b,c9,95,3b,74,53,68,0c,c8,f7,ec,32,1a,35,d2,8b,a8,44,\
3a,ca,17,e6,9f,b8,d4,c5,b3,14,d4,36,6a,c4,8b,53,68,0c,c8,08,13,cd,e5,ca,2d,\
74,57,44,3a,ca,17,0b,6d

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsXP\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7RsXP\Enum]
"0"="Root\\LEGACY_AVG7RSXP\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7UpdSvc]
"Type"=dword:00000010
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,41,00,7e,00,\
31,00,5c,00,47,00,72,00,69,00,73,00,6f,00,66,00,74,00,5c,00,41,00,56,00,47,\
00,46,00,52,00,45,00,7e,00,31,00,5c,00,61,00,76,00,67,00,75,00,70,00,73,00,\
76,00,63,00,2e,00,65,00,78,00,65,00,00,00
"DisplayName"="AVG7 Update Service"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7UpdSvc\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Avg7UpdSvc\Enum]
"0"="Root\\LEGACY_AVG7UPDSVC\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AVGEMS]
"Type"=dword:00000110
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,41,00,7e,00,\
31,00,5c,00,47,00,72,00,69,00,73,00,6f,00,66,00,74,00,5c,00,41,00,56,00,47,\
00,46,00,52,00,45,00,7e,00,31,00,5c,00,61,00,76,00,67,00,65,00,6d,00,63,00,\
2e,00,65,00,78,00,65,00,00,00
"DisplayName"="AVG E-mail Scanner"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AVGEMS\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AVGEMS\Enum]
"0"="Root\\LEGACY_AVGEMS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AvgTdi]
"Type"=dword:00000001
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,76,00,67,00,74,00,64,00,69,00,\
2e,00,73,00,79,00,73,00,00,00
"DisplayName"="AVG Network Redirector"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AvgTdi\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\AvgTdi\Enum]
"0"="Root\\LEGACY_AVGTDI\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\BattC]
"MofImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,\
00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,62,00,61,00,74,00,74,00,63,00,\
2e,00,73,00,79,00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Beep]
"ErrorControl"=dword:00000001
"Group"="Base"
"Start"=dword:00000001
"Tag"=dword:00000002
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Beep\Enum]
"0"="Root\\LEGACY_BEEP\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\BITS]
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Background Intelligent Transfer Service"
"DependOnService"=hex(7):52,00,70,00,63,00,73,00,73,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Uses idle network bandwidth to transfer data."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\BITS\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
71,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\BITS\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\BITS\Enum]
"0"="Root\\LEGACY_BITS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cbidf2k]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000019
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cbidf2k\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cbidf2k\Parameters\PnpInterface]
"1"=dword:00000001
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cd20xrnt]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000003a
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cd20xrnt\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\cd20xrnt\Parameters\PnpInterface]
"1"=dword:00000011

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdaudio]
"ErrorControl"=dword:00000000
"Group"="Filter"
"Start"=dword:00000001
"Tag"=dword:00000006
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdaudio\Enum]
"Count"=dword:00000000
"NextInstance"=dword:00000000
"INITSTARTFAILED"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdfs]
"DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,43,00,44,00,52,00,4f,00,\
4d,00,20,00,43,00,6c,00,61,00,73,00,73,00,00,00,00,00
"ErrorControl"=dword:00000001
"Group"="File system"
"Start"=dword:00000004
"Type"=dword:00000002

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdfs\Enum]
"0"="Root\\LEGACY_CDFS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdrom]
"DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,6d,00,69,00,6e,00,69,00,\
70,00,6f,00,72,00,74,00,00,00,00,00
"ErrorControl"=dword:00000001
"Group"="SCSI CDROM Class"
"Start"=dword:00000001
"Tag"=dword:00000002
"Type"=dword:00000001
"DisplayName"="CD-ROM Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,63,00,64,00,72,00,6f,00,6d,00,2e,\
00,73,00,79,00,73,00,00,00
"AutoRun"=dword:00000001
"AutoRunAlwaysDisable"=hex(7):4e,00,45,00,43,00,20,00,20,00,20,00,20,00,20,00,\
4d,00,42,00,52,00,2d,00,37,00,20,00,20,00,20,00,00,00,4e,00,45,00,43,00,20,\
00,20,00,20,00,20,00,20,00,4d,00,42,00,52,00,2d,00,37,00,2e,00,34,00,20,00,\
00,00,50,00,49,00,4f,00,4e,00,45,00,45,00,52,00,20,00,43,00,48,00,41,00,4e,\
00,47,00,52,00,20,00,44,00,52,00,4d,00,2d,00,31,00,38,00,30,00,34,00,58,00,\
00,00,50,00,49,00,4f,00,4e,00,45,00,45,00,52,00,20,00,43,00,44,00,2d,00,52,\
00,4f,00,4d,00,20,00,44,00,52,00,4d,00,2d,00,36,00,33,00,32,00,34,00,58,00,\
00,00,50,00,49,00,4f,00,4e,00,45,00,45,00,52,00,20,00,43,00,44,00,2d,00,52,\
00,4f,00,4d,00,20,00,44,00,52,00,4d,00,2d,00,36,00,32,00,34,00,58,00,20,00,\
00,00,54,00,4f,00,52,00,69,00,53,00,41,00,4e,00,20,00,43,00,44,00,2d,00,52,\
00,4f,00,4d,00,20,00,43,00,44,00,52,00,5f,00,43,00,33,00,36,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cdrom\Enum]
"0"="IDE\\CdRomLG_CD-ROM_CRD-8521B_____________________2.00____\\5&3494138e&0&0.1.0"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Changer]
"ErrorControl"=dword:00000000
"Group"="Filter"
"Start"=dword:00000001
"Tag"=dword:00000005
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CiSvc]
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"Description"="Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language."
"DisplayName"="Indexing Service"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,\
00,69,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000003
"Type"=dword:00000120

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ClipSrv]
"DependOnService"=hex(7):4e,00,65,00,74,00,44,00,44,00,45,00,00,00,00,00
"Description"="Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start."
"DisplayName"="ClipBook"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,\
00,6c,00,69,00,70,00,73,00,72,00,76,00,2e,00,65,00,78,00,65,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000003
"Type"=dword:00000010

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ClipSrv\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\
02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CmdIde]
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Start"=dword:00000004
"Tag"=dword:00000004
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\COMSysApp]
"Type"=dword:00000010
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\
5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,6c,00,6c,\
00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2f,00,50,00,72,00,\
6f,00,63,00,65,00,73,00,73,00,69,00,64,00,3a,00,7b,00,30,00,32,00,44,00,34,\
00,42,00,33,00,46,00,31,00,2d,00,46,00,44,00,38,00,38,00,2d,00,31,00,31,00,\
44,00,31,00,2d,00,39,00,36,00,30,00,44,00,2d,00,30,00,30,00,38,00,30,00,35,\
00,46,00,43,00,37,00,39,00,32,00,33,00,35,00,7d,00,00,00
"DisplayName"="COM+ System Application"
"DependOnService"=hex(7):72,00,70,00,63,00,73,00,73,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start."
"FailureActions"=hex:1e,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,52,00,49,\
00,01,00,00,00,e8,03,00,00,01,00,00,00,88,13,00,00,00,00,00,00,e8,03,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\COMSysApp\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\COMSysApp\Enum]
"0"="Root\\LEGACY_COMSYSAPP\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentFilter]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentFilter\Linkage]
"Bind"="\\Dummy"
"Export"="\\Dummy"
"Route"="\\Dummy"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentFilter\Performance]
"Close"="DoneFILTERPerformanceData"
"Collect"="CollectFILTERPerformanceData"
"Open"="InitializeFILTERPerformanceData"
"Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,71,\
00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00
"Last Counter"=dword:000008c8
"Last Help"=dword:000008c9
"First Counter"=dword:000008c2
"First Help"=dword:000008c3
"Object List"="2242"
"WbemAdapFileSignature"=hex:9b,54,7a,f3,fd,4c,f8,29,29,9e,4f,3c,05,c4,96,40
"WbemAdapFileTime"=hex:00,a7,70,96,48,4f,c2,01
"WbemAdapFileSize"=dword:00149600
"WbemAdapStatus"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentIndex]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentIndex\Linkage]
"Bind"="\\Dummy"
"Export"="\\Dummy"
"Route"="\\Dummy"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ContentIndex\Performance]
"Close"="DoneCIPerformanceData"
"Collect"="CollectCIPerformanceData"
"Open"="InitializeCIPerformanceData"
"Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,71,\
00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00
"Last Counter"=dword:000008c0
"Last Help"=dword:000008c1
"First Counter"=dword:000008aa
"First Help"=dword:000008ab
"Object List"="2218"
"WbemAdapFileSignature"=hex:9b,54,7a,f3,fd,4c,f8,29,29,9e,4f,3c,05,c4,96,40
"WbemAdapFileTime"=hex:00,a7,70,96,48,4f,c2,01
"WbemAdapFileSize"=dword:00149600
"WbemAdapStatus"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cpqarray]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000100
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cpqarray\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Cpqarray\Parameters\PnpInterface]
"2"=dword:00000001
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CryptSvc]
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
"Description"="Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start."
"DisplayName"="Cryptographic Services"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000002
"Type"=dword:00000020

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CryptSvc\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
63,00,72,00,79,00,70,00,74,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\
00
"ServiceMain"="CryptServiceMain"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CryptSvc\Security]
"Security"=hex:00,00,0e,00,01

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\CryptSvc\Enum]
"0"="Root\\LEGACY_CRYPTSVC\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac2w2k]
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000020
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac2w2k\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac2w2k\Parameters\PnpInterface]
"2"=dword:00000001
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac960nt]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000020
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac960nt\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dac960nt\Parameters\PnpInterface]
"2"=dword:00000001
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="DHCP Client"
"Group"="TDI"
"DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,41,00,66,00,64,00,\
00,00,4e,00,65,00,74,00,42,00,54,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Manages network configuration by registering and updating IP addresses and DNS names."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Configurations]
"Options"=hex:32,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,ff,ff,ff,7f,00,\
00,00,00,01,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,ff,ff,ff,7f,00,00,\
00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Linkage]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Linkage\Disabled]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
64,00,68,00,63,00,70,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\
00
"{AA3FF2ED-8F1D-42D2-B26C-3CDE58983B26}"=hex:0c,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,a1,f3,13,45,fc,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
a1,f3,13,45,36,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,12,44,15,45,c0,\
a8,01,01,33,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,12,44,15,45,00,01,\
51,80,0f,00,00,00,00,00,00,00,11,00,00,00,00,00,00,00,12,44,15,45,67,76,2e,\
73,68,61,77,63,61,62,6c,65,2e,6e,65,74,00,00,00,00,06,00,00,00,00,00,00,00,\
08,00,00,00,00,00,00,00,12,44,15,45,40,3b,a0,0d,40,3b,a0,0f,03,00,00,00,00,\
00,00,00,04,00,00,00,00,00,00,00,12,44,15,45,c0,a8,01,01,01,00,00,00,00,00,\
00,00,04,00,00,00,00,00,00,00,12,44,15,45,ff,ff,ff,00,35,00,00,00,00,00,00,\
00,01,00,00,00,00,00,00,00,12,44,15,45,05,00,00,00
"{FECCB1AF-DC8C-4AE7-A621-DBC0CBB158AB}"=hex:0c,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,c2,6f,18,45,fc,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
c2,6f,18,45,36,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,3f,c1,19,45,c0,\
a8,01,01,33,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,3f,c1,19,45,00,01,\
51,80,0f,00,00,00,00,00,00,00,11,00,00,00,00,00,00,00,3f,c1,19,45,67,76,2e,\
73,68,61,77,63,61,62,6c,65,2e,6e,65,74,00,00,00,00,06,00,00,00,00,00,00,00,\
08,00,00,00,00,00,00,00,3f,c1,19,45,40,3b,a0,0d,40,3b,a0,0f,03,00,00,00,00,\
00,00,00,04,00,00,00,00,00,00,00,3f,c1,19,45,c0,a8,01,01,01,00,00,00,00,00,\
00,00,04,00,00,00,00,00,00,00,3f,c1,19,45,ff,ff,ff,00,35,00,00,00,00,00,00,\
00,01,00,00,00,00,00,00,00,3f,c1,19,45,05,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\1]
"KeyType"=dword:00000007
"RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\
00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\
65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\
00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\
65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\
00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,53,00,75,00,62,00,6e,00,\
65,00,74,00,4d,00,61,00,73,00,6b,00,4f,00,70,00,74,00,00,00,53,00,59,00,53,\
00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,\
6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,53,00,65,00,72,\
00,76,00,69,00,63,00,65,00,73,00,5c,00,3f,00,5c,00,50,00,61,00,72,00,61,00,\
6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5c,\
00,44,00,68,00,63,00,70,00,53,00,75,00,62,00,6e,00,65,00,74,00,4d,00,61,00,\
73,00,6b,00,4f,00,70,00,74,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\15]
"KeyType"=dword:00000001
"RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\
00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\
65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\
00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\
65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\
00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,44,00,6f,00,6d,00,61,00,\
69,00,6e,00,00,00,53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\
00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\
65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\
00,63,00,70,00,49,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\
65,00,72,00,73,00,5c,00,44,00,68,00,63,00,70,00,44,00,6f,00,6d,00,61,00,69,\
00,6e,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\3]
"KeyType"=dword:00000007
"RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\
00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\
65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\
00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\
65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\
00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,44,00,65,00,66,00,61,00,\
75,00,6c,00,74,00,47,00,61,00,74,00,65,00,77,00,61,00,79,00,00,00,53,00,59,\
00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,\
43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,53,00,65,\
00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,3f,00,5c,00,50,00,61,00,72,00,\
61,00,6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,54,00,63,00,70,00,69,00,70,\
00,5c,00,44,00,68,00,63,00,70,00,44,00,65,00,66,00,61,00,75,00,6c,00,74,00,\
47,00,61,00,74,00,65,00,77,00,61,00,79,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\44]
"KeyType"=dword:00000001
"RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\
00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\
65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,4e,\
00,65,00,74,00,42,00,54,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\
65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\
00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,3f,00,5c,00,44,00,68,00,\
63,00,70,00,4e,00,61,00,6d,00,65,00,53,00,65,00,72,00,76,00,65,00,72,00,4c,\
00,69,00,73,00,74,00,00,00,53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,\
75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,\
00,53,00,65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,\
5c,00,4e,00,65,00,74,00,42,00,54,00,5c,00,41,00,64,00,61,00,70,00,74,00,65,\
00,72,00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,4e,00,61,00,6d,00,\
65,00,53,00,65,00,72,00,76,00,65,00,72,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\46]
"KeyType"=dword:00000004
"RegLocation"="SYSTEM\\CurrentControlSet\\Services\\NetBT\\Parameters\\DhcpNodeType"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\47]
"KeyType"=dword:00000001
"RegLocation"="SYSTEM\\CurrentControlSet\\Services\\NetBT\\Parameters\\DhcpScopeID"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\6]
"KeyType"=dword:00000001
"RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\
00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\
65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,54,\
00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\
65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\
00,73,00,5c,00,3f,00,5c,00,44,00,68,00,63,00,70,00,4e,00,61,00,6d,00,65,00,\
53,00,65,00,72,00,76,00,65,00,72,00,00,00,53,00,59,00,53,00,54,00,45,00,4d,\
00,5c,00,43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,\
72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,\
00,65,00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,\
61,00,6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,44,00,68,00,63,00,70,00,4e,\
00,61,00,6d,00,65,00,53,00,65,00,72,00,76,00,65,00,72,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Parameters\Options\DhcpNetbiosOptions]
"KeyType"=dword:00000004
"OptionId"=dword:00000001
"VendorType"=dword:00000001
"RegLocation"=hex(7):53,00,59,00,53,00,54,00,45,00,4d,00,5c,00,43,00,75,00,72,\
00,72,00,65,00,6e,00,74,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,53,00,\
65,00,74,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,5c,00,4e,\
00,65,00,74,00,42,00,54,00,5c,00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,\
65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,\
00,73,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,3f,00,5c,00,44,00,68,00,\
63,00,70,00,4e,00,65,00,74,00,62,00,69,00,6f,00,73,00,4f,00,70,00,74,00,69,\
00,6f,00,6e,00,73,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
2c,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dhcp\Enum]
"0"="Root\\LEGACY_DHCP\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Disk]
"DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,6d,00,69,00,6e,00,69,00,\
70,00,6f,00,72,00,74,00,00,00,00,00
"ErrorControl"=dword:00000001
"Group"="SCSI Class"
"Start"=dword:00000000
"Tag"=dword:00000002
"Type"=dword:00000001
"DisplayName"="Disk Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,64,00,69,00,73,00,6b,00,2e,00,73,\
00,79,00,73,00,00,00
"AutoRunAlwaysDisable"=hex(7):42,00,72,00,6f,00,74,00,68,00,65,00,72,00,20,00,\
52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,44,00,69,00,73,00,6b,\
00,28,00,55,00,29,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Disk\Enum]
"0"="IDE\\DiskMAXTOR_6L020J1__________________________AR1.0400\\3636313135333439323237382020202020202020"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmadmin]
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,50,00,6c,00,75,00,\
67,00,50,00,6c,00,61,00,79,00,00,00,44,00,6d,00,53,00,65,00,72,00,76,00,65,\
00,72,00,00,00,00,00
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,\
00,6d,00,61,00,64,00,6d,00,69,00,6e,00,2e,00,65,00,78,00,65,00,20,00,2f,00,\
63,00,6f,00,6d,00,00,00
"DisplayName"="Logical Disk Manager Administrative Service"
"ObjectName"="LocalSystem"
"Description"="Configures hard disk drives and volumes. The service only runs for configuration processes and then stops."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmadmin\Parameters]
"EnableDynamicConversionFor1394"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmboot]
"Type"=dword:00000001
"Start"=dword:00000004
"ErrorControl"=dword:00000001
"Group"="Filter"
"Tag"=dword:0000000b
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,62,00,6f,00,6f,00,74,\
00,2e,00,73,00,79,00,73,00,00,00
"VolumeRecoveryNeeded"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmboot\Enum]
"0"="Root\\LEGACY_DMBOOT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmio]
"Type"=dword:00000001
"Start"=dword:00000000
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Tag"=dword:0000000d
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,69,00,6f,00,2e,00,73,\
00,79,00,73,00,00,00
"DisplayName"="Logical Disk Manager Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmio\Boot Info]
"Boot ID"="a9c72dc1-2788-11db-91ee-806d6172696f"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmio\Enum]
"0"="Root\\dmio\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmload]
"Type"=dword:00000001
"Start"=dword:00000000
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Tag"=dword:0000000c
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,6c,00,6f,00,61,00,64,\
00,2e,00,73,00,79,00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmload\Enum]
"0"="Root\\LEGACY_DMLOAD\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmserver]
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,50,00,6c,00,75,00,\
67,00,50,00,6c,00,61,00,79,00,00,00,00,00
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Logical Disk Manager"
"ObjectName"="LocalSystem"
"Description"="Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmserver\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
64,00,6d,00,73,00,65,00,72,00,76,00,65,00,72,00,2e,00,64,00,6c,00,6c,00,00,\
00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmserver\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dmserver\Enum]
"0"="Root\\LEGACY_DMSERVER\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\DMusic]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
72,00,69,00,76,00,65,00,72,00,73,00,5c,00,44,00,4d,00,75,00,73,00,69,00,63,\
00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Microsoft Kernel DLS Syntheiszer"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\DMusic\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dnscache]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,53,00,65,00,72,00,76,\
00,69,00,63,00,65,00,00,00
"DisplayName"="DNS Client"
"Group"="TDI"
"DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="NT AUTHORITY\\NetworkService"
"Description"="Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dnscache\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
64,00,6e,00,73,00,72,00,73,00,6c,00,76,00,72,00,2e,00,64,00,6c,00,6c,00,00,\
00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dnscache\Security]
"Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,2c,\
02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,\
00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,\
00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Dnscache\Enum]
"0"="Root\\LEGACY_DNSCACHE\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dpti2o]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000003c
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dpti2o\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dpti2o\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\drmkaud]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,72,00,6d,00,6b,00,61,00,75,\
00,64,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Microsoft Kernel DRM Audio Descrambler"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\drmkaud\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ERSvc]
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
"Description"="Allows error reporting for services and applictions running in non-standard environments."
"DisplayName"="Error Reporting Service"
"ErrorControl"=dword:00000000
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000002
"Type"=dword:00000020

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ERSvc\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
65,00,72,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ERSvc\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ERSvc\Enum]
"0"="Root\\LEGACY_ERSVC\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\es1371]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
72,00,69,00,76,00,65,00,72,00,73,00,5c,00,65,00,73,00,31,00,33,00,37,00,31,\
00,6d,00,70,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Creative AudioPCI (ES1371,ES1373) (WDM)"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\es1371\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\es1371\Enum]
"0"="PCI\\VEN_1274&DEV_5880&SUBSYS_A0001458&REV_04\\4&3ab31f7f&0&50F0"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog]
"Description"="Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped."
"DisplayName"="Event Log"
"ErrorControl"=dword:00000001
"Group"="Event log"
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,2e,00,65,00,78,00,65,00,00,00
"ObjectName"="LocalSystem"
"PlugPlayServiceType"=dword:00000003
"Start"=dword:00000002
"Type"=dword:00000020
"ComputerName"="PCZONE11"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application]
"DisplayNameFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\
6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\
00,65,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"DisplayNameID"=dword:00000100
"File"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,\
6f,00,6e,00,66,00,69,00,67,00,5c,00,41,00,70,00,70,00,45,00,76,00,65,00,6e,\
00,74,00,2e,00,45,00,76,00,74,00,00,00
"MaxSize"=dword:00080000
"PrimaryModule"="Application"
"Retention"=dword:00093a80
"Sources"=hex(7):57,00,53,00,48,00,00,00,57,00,4d,00,49,00,41,00,64,00,61,00,\
70,00,74,00,65,00,72,00,00,00,57,00,6d,00,64,00,6d,00,50,00,6d,00,53,00,70,\
00,00,00,57,00,69,00,6e,00,4d,00,67,00,6d,00,74,00,00,00,57,00,69,00,6e,00,\
6c,00,6f,00,67,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,\
00,20,00,50,00,72,00,6f,00,64,00,75,00,63,00,74,00,20,00,41,00,63,00,74,00,\
69,00,76,00,61,00,74,00,69,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,\
00,77,00,73,00,20,00,33,00,2e,00,31,00,20,00,4d,00,69,00,67,00,72,00,61,00,\
74,00,69,00,6f,00,6e,00,00,00,57,00,65,00,62,00,43,00,6c,00,69,00,65,00,6e,\
00,74,00,00,00,56,00,53,00,53,00,00,00,56,00,42,00,52,00,75,00,6e,00,74,00,\
69,00,6d,00,65,00,00,00,55,00,73,00,65,00,72,00,69,00,6e,00,69,00,74,00,00,\
00,55,00,73,00,65,00,72,00,65,00,6e,00,76,00,00,00,55,00,70,00,6c,00,6f,00,\
61,00,64,00,4d,00,00,00,54,00,6c,00,6e,00,74,00,73,00,76,00,72,00,00,00,53,\
00,79,00,73,00,6d,00,6f,00,6e,00,4c,00,6f,00,67,00,00,00,53,00,70,00,6f,00,\
6f,00,6c,00,65,00,72,00,43,00,74,00,72,00,73,00,00,00,53,00,6f,00,66,00,74,\
00,77,00,61,00,72,00,65,00,20,00,49,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,\
61,00,74,00,69,00,6f,00,6e,00,00,00,53,00,63,00,6c,00,67,00,4e,00,74,00,66,\
00,79,00,00,00,53,00,63,00,65,00,53,00,72,00,76,00,00,00,53,00,63,00,65,00,\
43,00,6c,00,69,00,00,00,73,00,61,00,66,00,72,00,73,00,6c,00,76,00,00,00,53,\
00,41,00,46,00,72,00,64,00,6d,00,73,00,00,00,50,00,65,00,72,00,66,00,50,00,\
72,00,6f,00,63,00,00,00,50,00,65,00,72,00,66,00,4f,00,53,00,00,00,50,00,65,\
00,72,00,66,00,4e,00,65,00,74,00,00,00,50,00,65,00,72,00,66,00,6d,00,6f,00,\
6e,00,00,00,50,00,65,00,72,00,66,00,6c,00,69,00,62,00,00,00,50,00,65,00,72,\
00,66,00,44,00,69,00,73,00,6b,00,00,00,50,00,65,00,72,00,66,00,63,00,74,00,\
72,00,73,00,00,00,4f,00,66,00,66,00,6c,00,69,00,6e,00,65,00,20,00,46,00,69,\
00,6c,00,65,00,73,00,00,00,4f,00,61,00,6b,00,6c,00,65,00,79,00,00,00,6e,00,\
74,00,62,00,61,00,63,00,6b,00,75,00,70,00,00,00,4d,00,73,00,69,00,49,00,6e,\
00,73,00,74,00,61,00,6c,00,6c,00,65,00,72,00,00,00,4d,00,53,00,44,00,54,00,\
43,00,20,00,43,00,6c,00,69,00,65,00,6e,00,74,00,00,00,4d,00,53,00,44,00,54,\
00,43,00,00,00,6d,00,6e,00,6d,00,73,00,72,00,76,00,63,00,00,00,4d,00,69,00,\
63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,48,00,2e,00,33,00,32,00,33,\
00,20,00,54,00,65,00,6c,00,65,00,70,00,68,00,6f,00,6e,00,79,00,20,00,53,00,\
65,00,72,00,76,00,69,00,63,00,65,00,20,00,50,00,72,00,6f,00,76,00,69,00,64,\
00,65,00,72,00,00,00,4c,00,6f,00,61,00,64,00,50,00,65,00,72,00,66,00,00,00,\
4a,00,61,00,76,00,61,00,20,00,56,00,4d,00,00,00,48,00,65,00,6c,00,70,00,53,\
00,76,00,63,00,00,00,46,00,6f,00,6c,00,64,00,65,00,72,00,20,00,52,00,65,00,\
64,00,69,00,72,00,65,00,63,00,74,00,69,00,6f,00,6e,00,00,00,46,00,69,00,6c,\
00,65,00,20,00,44,00,65,00,70,00,6c,00,6f,00,79,00,6d,00,65,00,6e,00,74,00,\
00,00,45,00,76,00,65,00,6e,00,74,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,\
00,45,00,53,00,45,00,4e,00,54,00,00,00,45,00,41,00,50,00,4f,00,4c,00,00,00,\
44,00,72,00,57,00,61,00,74,00,73,00,6f,00,6e,00,00,00,44,00,69,00,73,00,6b,\
00,51,00,75,00,6f,00,74,00,61,00,00,00,63,00,72,00,79,00,70,00,74,00,33,00,\
32,00,00,00,43,00,4f,00,4d,00,2b,00,00,00,43,00,69,00,00,00,43,00,68,00,6b,\
00,64,00,73,00,6b,00,00,00,41,00,76,00,67,00,45,00,6d,00,73,00,00,00,41,00,\
76,00,67,00,37,00,55,00,70,00,64,00,53,00,76,00,63,00,00,00,41,00,76,00,67,\
00,37,00,41,00,6c,00,72,00,74,00,00,00,41,00,56,00,47,00,37,00,00,00,41,00,\
75,00,74,00,6f,00,45,00,6e,00,72,00,6f,00,6c,00,6c,00,6d,00,65,00,6e,00,74,\
00,00,00,41,00,75,00,74,00,6f,00,63,00,68,00,6b,00,00,00,41,00,70,00,70,00,\
6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,4d,00,61,00,6e,00,61,\
00,67,00,65,00,6d,00,65,00,6e,00,74,00,00,00,41,00,70,00,70,00,6c,00,69,00,\
63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,48,00,61,00,6e,00,67,00,00,00,41,\
00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,45,00,\
72,00,72,00,6f,00,72,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,\
00,69,00,6f,00,6e,00,00,00,00,00
"RestrictGuestAccess"=dword:00000001
@="mnmsrvc"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Application]
"CategoryCount"=dword:00000007
"CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,65,00,76,00,65,00,6e,00,74,00,6c,00,6f,00,67,00,2e,00,64,00,6c,00,\
6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Application Error]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Application Hang]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Application Management]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,61,00,70,00,70,00,6d,00,67,00,6d,00,74,00,73,00,2e,00,64,00,6c,00,6c,\
00,00,00
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Autochk]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,77,00,69,00,6e,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,65,00,78,00,65,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\AutoEnrollment]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,70,00,61,00,75,00,74,00,6f,00,65,00,6e,00,72,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\AVG7]
"EventMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avglog.dll"
"CategoryMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avglog.dll"
"TypesSupported"=dword:00000007
"CategoryCount"=dword:00000005

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Avg7Alrt]
"EventMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgamint.dll"
"CategoryMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgamint.dll"
"CategoryCount"=dword:00000001
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Avg7UpdSvc]
"EventMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgupsvc.dll"
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\AvgEms]
"EventMessageFile"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgemc.exe"
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Chkdsk]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,75,00,6c,00,69,00,62,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Ci]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,71,00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00
"CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,71,00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
"CategoryCount"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\COM+]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\
00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\
4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\
57,00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\
00,4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"ParameterMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\
57,00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\
00,4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"TypeSupported"=dword:00000007
"CategoryCount"=dword:00000075

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\crypt32]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,\
00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\DiskQuota]
"EventMessageFile"="%SystemRoot%\\System32\\dskquota.dll"
"TypesSupported"="0x00000007"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\DrWatson]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,64,00,72,00,77,00,74,00,73,00,6e,00,33,00,32,00,2e,00,65,00,78,00,65,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\EAPOL]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,77,00,7a,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\ESENT]
"EventMessageFile"=hex(2):63,00,3a,00,5c,00,77,00,69,00,6e,00,64,00,6f,00,77,\
00,73,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,45,00,\
53,00,45,00,4e,00,54,00,2e,00,64,00,6c,00,6c,00,00,00
"CategoryMessageFile"=hex(2):63,00,3a,00,5c,00,77,00,69,00,6e,00,64,00,6f,00,\
77,00,73,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,45,\
00,53,00,45,00,4e,00,54,00,2e,00,64,00,6c,00,6c,00,00,00
"CategoryCount"=dword:00000010
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\EventSystem]
"CategoryCount"=dword:00000006
"TypesSupported"=dword:00000007
"CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\
57,00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\
00,4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\
00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\
4f,00,4d,00,52,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\File Deployment]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,66,00,64,00,65,00,70,00,6c,00,6f,00,79,00,2e,00,64,00,6c,00,6c,00,00,\
00
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Folder Redirection]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,66,00,64,00,65,00,70,00,6c,00,6f,00,79,00,2e,00,64,00,6c,00,6c,00,00,\
00
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\HelpSvc]
"EventMessageFile"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HCAppRes.dll"
"TypesSupported"=dword:0000001f

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Java VM]
"EventMessageFile"="C:\\WINDOWS\\System32\\vmhelper.dll"
"TypesSupported"=hex:07,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\LoadPerf]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6c,00,6f,00,61,00,64,00,70,00,65,00,72,00,66,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Microsoft H.323 Telephony Service Provider]
"EventMessageFile"="C:\\WINDOWS\\System32\\h323.tsp"
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\mnmsrvc]
"EventMessageFile"="%SystemRoot%\\System32\\nmevtmsg.dll"
"TypeSupported"=hex:07,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\MSDTC]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\
00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\
4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,00,00
"TypesSupported"=dword:00000007
"CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\
57,00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\
00,4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,00,00
"CategoryCount"=dword:0000000f

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\MSDTC Client]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\
00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,00,\
4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,00,00
"TypesSupported"=dword:00000007
"CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\
57,00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,43,\
00,4f,00,4d,00,52,00,45,00,53,00,2e,00,44,00,4c,00,4c,00,00,00
"CategoryCount"=dword:0000000f

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\MsiInstaller]
"EventMessageFile"="C:\\WINDOWS\\System32\\msi.dll"
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\ntbackup]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,74,00,62,00,61,00,63,00,6b,00,75,00,70,00,2e,00,65,00,78,00,65,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Oakley]
"EventMessageFile"="%SystemRoot%\\System32\\oakley.dll"
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Offline Files]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,63,00,73,00,63,00,75,00,69,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"="0x00000007"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Perfctrs]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,70,00,65,00,72,00,66,00,63,00,74,00,72,00,73,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\PerfDisk]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,70,00,65,00,72,00,66,00,64,00,69,00,73,00,6b,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Perflib]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,70,00,72,00,66,00,6c,00,62,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Perfmon]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,70,00,65,00,72,00,66,00,6d,00,6f,00,6e,00,2e,00,65,00,78,00,65,00,00,\
00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\PerfNet]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,70,00,65,00,72,00,66,00,6e,00,65,00,74,00,2e,00,64,00,6c,00,6c,00,00,\
00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\PerfOS]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,70,00,65,00,72,00,66,00,4f,00,53,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\PerfProc]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,70,00,65,00,72,00,66,00,70,00,72,00,6f,00,63,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SAFrdms]
"EventMessageFile"="C:\\WINDOWS\\System32\\safrdm.dll"
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\safrslv]
"EventMessageFile"="C:\\WINDOWS\\System32\\safrslv.dll"
"TypesSupported"=dword:0000001f

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SceCli]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,63,00,65,00,63,00,6c,00,69,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SceSrv]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,63,00,65,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SclgNtfy]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Software Installation]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,61,00,70,00,70,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SpoolerCtrs]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,77,00,69,00,6e,00,73,00,70,00,6f,00,6f,00,6c,00,2e,00,64,00,72,00,76,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\SysmonLog]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,6d,00,6c,00,6f,00,67,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Tlntsvr]
"EventMessageFile"="C:\\WINDOWS\\System32\\tlntsvr.exe;C:\\WINDOWS\\System32\\xpsp1res.dll"
"TypesSupported"=dword:0000001f

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\UploadM]
"EventMessageFile"="C:\\WINDOWS\\PCHealth\\UploadLB\\Binaries\\UploadM.exe"
"TypesSupported"=dword:0000001f

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Userenv]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,75,00,73,00,65,00,72,00,65,00,6e,00,76,00,2e,00,64,00,6c,00,6c,00,3b,\
00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,\
5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,78,00,70,00,73,\
00,70,00,31,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Userinit]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,75,00,73,00,65,00,72,00,69,00,6e,00,69,00,74,00,2e,00,65,00,78,00,65,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\VBRuntime]
"EventMessageFile"="C:\\WINDOWS\\System32\\MSVBVM60.DLL"
"TypesSupported"=dword:00000004

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\VSS]
"TypesSupported"=dword:00000007
"EventMessageFile"="C:\\WINDOWS\\System32\\vssvc.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\WebClient]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Windows 3.1 Migration]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,61,00,64,00,76,00,61,00,70,00,69,00,33,00,32,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Windows Product Activation]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,64,00,70,00,63,00,64,00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\Winlogon]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,77,00,69,00,6e,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,65,00,78,00,65,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\WinMgmt]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,57,00,42,00,45,00,4d,00,5c,00,57,00,69,00,6e,00,4d,00,67,00,6d,00,74,\
00,52,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\WmdmPmSp]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\
00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,\
73,00,70,00,6d,00,73,00,70,00,73,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\WMIAdapter]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,57,00,42,00,45,00,4d,00,5c,00,57,00,4d,00,49,00,41,00,70,00,52,00,65,\
00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Application\WSH]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,77,00,73,00,68,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:0000001f

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security]
"DisplayNameFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\
6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\
00,65,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"DisplayNameID"=dword:00000101
"File"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,\
6f,00,6e,00,66,00,69,00,67,00,5c,00,53,00,65,00,63,00,45,00,76,00,65,00,6e,\
00,74,00,2e,00,45,00,76,00,74,00,00,00
"MaxSize"=dword:00080000
"PrimaryModule"="Security"
"Retention"=dword:00093a80
"Sources"=hex(7):53,00,70,00,6f,00,6f,00,6c,00,65,00,72,00,00,00,53,00,65,00,\
63,00,75,00,72,00,69,00,74,00,79,00,20,00,41,00,63,00,63,00,6f,00,75,00,6e,\
00,74,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,00,00,53,00,43,00,\
20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,00,00,4e,00,65,00,74,00,44,\
00,44,00,45,00,20,00,4f,00,62,00,6a,00,65,00,63,00,74,00,00,00,4c,00,53,00,\
41,00,00,00,44,00,53,00,00,00,53,00,65,00,63,00,75,00,72,00,69,00,74,00,79,\
00,00,00,00,00
"RestrictGuestAccess"=dword:00000001
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security\DS]
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security\DS\ObjectNames]
"Directory Service Object"=dword:00001e00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security\LSA]
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security\LSA\ObjectNames]
"PolicyObject"=dword:00001600
"SecretObject"=dword:00001610
"TrustedDomainObject"=dword:00001620
"UserAccountObject"=dword:00001630

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security\NetDDE Object]
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security\NetDDE Object\ObjectNames]
"DDE Share"=dword:00001d00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security\SC Manager]
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security\SC Manager\ObjectNames]
"SC_MANAGER Object"=dword:00001c00
"SERVICE Object"=dword:00001c10

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security\Security]
"CategoryCount"=dword:00000009
"CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,4d,00,73,00,41,00,75,00,64,00,69,00,74,00,45,00,2e,00,64,00,6c,00,\
6c,00,00,00
"GuidMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\
6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\
00,4e,00,74,00,4d,00,61,00,72,00,74,00,61,00,2e,00,64,00,6c,00,6c,00,00,00
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,4d,00,73,00,41,00,75,00,64,00,69,00,74,00,45,00,2e,00,64,00,6c,00,6c,\
00,00,00
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:0000001c

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security\Security\ObjectNames]
"Channel"=dword:00001400
"Desktop"=dword:00001a10
"Device"=dword:00001100
"Directory"=dword:00001110
"Event"=dword:00001120
"EventPair"=dword:00001130
"File"=dword:00001140
"IoCompletion"=dword:00001300
"Job"=dword:00001410
"Key"=dword:00001150
"MailSlot"=dword:00001140
"Mutant"=dword:00001160
"NamedPipe"=dword:00001140
"Port"=dword:00001170
"Process"=dword:00001180
"Profile"=dword:00001190
"Section"=dword:000011a0
"Semaphore"=dword:000011b0
"SymbolicLink"=dword:000011c0
"Thread"=dword:000011d0
"Timer"=dword:000011e0
"Token"=dword:000011f0
"Type"=dword:00001200
"WaitablePort"=dword:00001170
"WindowStation"=dword:00001a00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security\Security Account Manager]
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security\Security Account Manager\ObjectNames]
"SAM_ALIAS"=dword:00001530
"SAM_DOMAIN"=dword:00001510
"SAM_GROUP"=dword:00001520
"SAM_SERVER"=dword:00001500
"SAM_USER"=dword:00001540

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security\Spooler]
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\Security\Spooler\ObjectNames]
"Document"=dword:00001b20
"Printer"=dword:00001b10
"Server"=dword:00001b00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System]
"DisplayNameFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\
6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\
00,65,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"DisplayNameID"=dword:00000102
"File"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,\
6f,00,6e,00,66,00,69,00,67,00,5c,00,53,00,79,00,73,00,45,00,76,00,65,00,6e,\
00,74,00,2e,00,45,00,76,00,74,00,00,00
"MaxSize"=dword:00080000
"PrimaryModule"="System"
"Retention"=dword:00093a80
"Sources"=hex(7):57,00,5a,00,43,00,53,00,56,00,43,00,00,00,57,00,6f,00,72,00,\
6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,\
00,6f,00,77,00,73,00,4d,00,65,00,64,00,69,00,61,00,00,00,57,00,69,00,6e,00,\
64,00,6f,00,77,00,73,00,20,00,55,00,70,00,64,00,61,00,74,00,65,00,20,00,41,\
00,67,00,65,00,6e,00,74,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,\
20,00,53,00,63,00,72,00,69,00,70,00,74,00,20,00,48,00,6f,00,73,00,74,00,00,\
00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,49,00,6e,00,73,00,74,00,\
61,00,6c,00,6c,00,65,00,72,00,20,00,33,00,2e,00,31,00,00,00,57,00,69,00,6e,\
00,64,00,6f,00,77,00,73,00,20,00,46,00,69,00,6c,00,65,00,20,00,50,00,72,00,\
6f,00,74,00,65,00,63,00,74,00,69,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,33,\
00,32,00,6b,00,00,00,57,00,47,00,41,00,00,00,57,00,33,00,32,00,54,00,69,00,\
6d,00,65,00,00,00,76,00,73,00,64,00,61,00,74,00,61,00,6e,00,74,00,00,00,56,\
00,6f,00,6c,00,53,00,6e,00,61,00,70,00,00,00,76,00,69,00,61,00,69,00,64,00,\
65,00,00,00,56,00,67,00,61,00,53,00,61,00,76,00,65,00,00,00,55,00,53,00,45,\
00,52,00,33,00,32,00,00,00,55,00,50,00,53,00,00,00,75,00,6c,00,74,00,72,00,\
61,00,00,00,75,00,64,00,66,00,73,00,00,00,74,00,6f,00,73,00,69,00,64,00,65,\
00,00,00,54,00,65,00,72,00,6d,00,53,00,65,00,72,00,76,00,53,00,65,00,73,00,\
73,00,44,00,69,00,72,00,00,00,54,00,65,00,72,00,6d,00,53,00,65,00,72,00,76,\
00,69,00,63,00,65,00,00,00,54,00,65,00,72,00,6d,00,53,00,65,00,72,00,76,00,\
44,00,65,00,76,00,69,00,63,00,65,00,73,00,00,00,54,00,65,00,72,00,6d,00,44,\
00,44,00,00,00,74,00,64,00,69,00,00,00,54,00,43,00,50,00,4d,00,6f,00,6e,00,\
00,00,54,00,63,00,70,00,69,00,70,00,00,00,53,00,79,00,73,00,74,00,65,00,6d,\
00,20,00,45,00,72,00,72,00,6f,00,72,00,00,00,73,00,79,00,6d,00,5f,00,75,00,\
33,00,00,00,73,00,79,00,6d,00,5f,00,68,00,69,00,00,00,73,00,79,00,6d,00,63,\
00,38,00,78,00,78,00,00,00,73,00,79,00,6d,00,63,00,38,00,31,00,30,00,00,00,\
53,00,74,00,69,00,6c,00,6c,00,49,00,6d,00,61,00,67,00,65,00,00,00,53,00,53,\
00,44,00,50,00,53,00,52,00,56,00,00,00,53,00,72,00,76,00,00,00,73,00,72,00,\
73,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,73,00,72,00,00,00,73,00,70,\
00,61,00,72,00,72,00,6f,00,77,00,00,00,53,00,6f,00,66,00,74,00,77,00,61,00,\
72,00,65,00,20,00,52,00,65,00,73,00,74,00,72,00,69,00,63,00,74,00,69,00,6f,\
00,6e,00,20,00,50,00,6f,00,6c,00,69,00,63,00,79,00,00,00,73,00,6e,00,64,00,\
62,00,6c,00,73,00,74,00,00,00,53,00,69,00,6d,00,62,00,61,00,64,00,00,00,53,\
00,69,00,64,00,65,00,42,00,79,00,53,00,69,00,64,00,65,00,00,00,73,00,66,00,\
6c,00,6f,00,70,00,70,00,79,00,00,00,53,00,65,00,74,00,75,00,70,00,00,00,53,\
00,65,00,72,00,76,00,69,00,63,00,65,00,20,00,43,00,6f,00,6e,00,74,00,72,00,\
6f,00,6c,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,00,00,53,00,65,\
00,72,00,76,00,65,00,72,00,00,00,73,00,65,00,72,00,69,00,61,00,6c,00,00,00,\
73,00,63,00,73,00,69,00,70,00,6f,00,72,00,74,00,00,00,53,00,63,00,68,00,65,\
00,64,00,75,00,6c,00,65,00,00,00,53,00,63,00,68,00,61,00,6e,00,6e,00,65,00,\
6c,00,00,00,53,00,43,00,61,00,72,00,64,00,53,00,76,00,72,00,00,00,53,00,61,\
00,76,00,65,00,20,00,44,00,75,00,6d,00,70,00,00,00,53,00,41,00,4d,00,00,00,\
72,00,74,00,6c,00,38,00,31,00,33,00,39,00,00,00,52,00,53,00,56,00,50,00,00,\
00,52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,20,00,53,00,74,00,\
6f,00,72,00,61,00,67,00,65,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,\
00,00,00,52,00,65,00,6d,00,6f,00,74,00,65,00,41,00,63,00,63,00,65,00,73,00,\
73,00,00,00,52,00,65,00,6d,00,6f,00,74,00,65,00,20,00,44,00,65,00,73,00,6b,\
00,74,00,6f,00,70,00,20,00,48,00,65,00,6c,00,70,00,20,00,53,00,65,00,73,00,\
73,00,69,00,6f,00,6e,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,00,\
00,72,00,65,00,64,00,62,00,6f,00,6f,00,6b,00,00,00,52,00,64,00,62,00,73,00,\
73,00,00,00,52,00,61,00,73,00,4d,00,61,00,6e,00,00,00,52,00,61,00,73,00,41,\
00,75,00,74,00,6f,00,00,00,71,00,6c,00,31,00,32,00,38,00,30,00,00,00,71,00,\
6c,00,31,00,32,00,34,00,30,00,00,00,71,00,6c,00,31,00,32,00,31,00,36,00,30,\
00,00,00,71,00,6c,00,31,00,30,00,77,00,6e,00,74,00,00,00,71,00,6c,00,31,00,\
30,00,38,00,30,00,00,00,50,00,53,00,63,00,68,00,65,00,64,00,00,00,50,00,72,\
00,6f,00,63,00,65,00,73,00,73,00,6f,00,72,00,00,00,50,00,72,00,69,00,6e,00,\
74,00,00,00,50,00,70,00,74,00,70,00,4d,00,69,00,6e,00,69,00,70,00,6f,00,72,\
00,74,00,00,00,50,00,6f,00,6c,00,69,00,63,00,79,00,41,00,67,00,65,00,6e,00,\
74,00,00,00,50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,4d,00,61,00,6e,\
00,61,00,67,00,65,00,72,00,00,00,70,00,65,00,72,00,63,00,32,00,00,00,70,00,\
63,00,6d,00,63,00,69,00,61,00,00,00,70,00,63,00,69,00,69,00,64,00,65,00,00,\
00,70,00,63,00,69,00,00,00,70,00,61,00,72,00,76,00,64,00,6d,00,00,00,70,00,\
61,00,72,00,74,00,6d,00,67,00,72,00,00,00,70,00,61,00,72,00,70,00,6f,00,72,\
00,74,00,00,00,4f,00,75,00,74,00,6c,00,6f,00,6f,00,6b,00,20,00,45,00,78,00,\
70,00,72,00,65,00,73,00,73,00,20,00,36,00,00,00,4f,00,53,00,50,00,46,00,4d,\
00,69,00,62,00,00,00,4f,00,53,00,50,00,46,00,00,00,6e,00,76,00,00,00,6e,00,\
75,00,6c,00,6c,00,00,00,4e,00,74,00,53,00,65,00,72,00,76,00,69,00,63,00,65,\
00,50,00,61,00,63,00,6b,00,00,00,6e,00,74,00,66,00,73,00,00,00,6e,00,70,00,\
66,00,73,00,00,00,4e,00,6c,00,61,00,00,00,4e,00,65,00,74,00,4d,00,61,00,74,\
00,65,00,32,00,00,00,4e,00,65,00,74,00,6c,00,6f,00,67,00,6f,00,6e,00,00,00,\
4e,00,65,00,74,00,44,00,44,00,45,00,00,00,4e,00,65,00,74,00,42,00,54,00,00,\
00,4e,00,65,00,74,00,42,00,49,00,4f,00,53,00,00,00,4e,00,64,00,69,00,73,00,\
57,00,61,00,6e,00,00,00,6e,00,64,00,69,00,73,00,00,00,4d,00,75,00,70,00,00,\
00,6d,00,73,00,66,00,73,00,00,00,6d,00,73,00,61,00,64,00,6c,00,69,00,62,00,\
00,00,4d,00,72,00,78,00,53,00,6d,00,62,00,00,00,4d,00,52,00,78,00,44,00,41,\
00,56,00,00,00,6d,00,72,00,61,00,69,00,64,00,33,00,35,00,78,00,00,00,6d,00,\
6f,00,75,00,68,00,69,00,64,00,00,00,6d,00,6f,00,75,00,63,00,6c,00,61,00,73,\
00,73,00,00,00,4d,00,6f,00,64,00,65,00,6d,00,00,00,4c,00,73,00,61,00,53,00,\
72,00,76,00,00,00,4c,00,6d,00,48,00,6f,00,73,00,74,00,73,00,00,00,4c,00,44,\
00,4d,00,53,00,00,00,4c,00,44,00,4d,00,00,00,6c,00,62,00,72,00,74,00,66,00,\
64,00,63,00,00,00,4b,00,65,00,72,00,62,00,65,00,72,00,6f,00,73,00,00,00,6b,\
00,62,00,64,00,63,00,6c,00,61,00,73,00,73,00,00,00,69,00,73,00,61,00,70,00,\
6e,00,70,00,00,00,49,00,50,00,58,00,53,00,41,00,50,00,00,00,49,00,50,00,58,\
00,52,00,6f,00,75,00,74,00,65,00,72,00,4d,00,61,00,6e,00,61,00,67,00,65,00,\
72,00,00,00,49,00,50,00,58,00,52,00,49,00,50,00,00,00,49,00,50,00,58,00,43,\
00,50,00,00,00,49,00,50,00,53,00,65,00,63,00,00,00,49,00,50,00,52,00,6f,00,\
75,00,74,00,65,00,72,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,00,00,49,\
00,50,00,52,00,49,00,50,00,32,00,00,00,49,00,50,00,4e,00,41,00,54,00,48,00,\
4c,00,50,00,00,00,49,00,50,00,4d,00,47,00,4d,00,00,00,49,00,50,00,42,00,4f,\
00,4f,00,54,00,50,00,00,00,49,00,6e,00,74,00,65,00,72,00,6e,00,65,00,74,00,\
20,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,20,00,36,00,00,00,69,\
00,6e,00,74,00,65,00,6c,00,69,00,64,00,65,00,00,00,69,00,6e,00,69,00,39,00,\
31,00,30,00,75,00,00,00,49,00,47,00,4d,00,50,00,76,00,32,00,00,00,69,00,38,\
00,30,00,34,00,32,00,70,00,72,00,74,00,00,00,69,00,32,00,6f,00,6d,00,70,00,\
00,00,69,00,32,00,6f,00,6d,00,67,00,6d,00,74,00,00,00,68,00,70,00,6e,00,00,\
00,66,00,74,00,64,00,69,00,73,00,6b,00,00,00,66,00,73,00,5f,00,72,00,65,00,\
63,00,00,00,66,00,6c,00,70,00,79,00,64,00,69,00,73,00,6b,00,00,00,46,00,69,\
00,70,00,73,00,00,00,66,00,64,00,63,00,00,00,66,00,61,00,73,00,74,00,66,00,\
61,00,74,00,00,00,65,00,76,00,65,00,6e,00,74,00,6c,00,6f,00,67,00,00,00,65,\
00,66,00,73,00,00,00,64,00,70,00,74,00,69,00,32,00,6f,00,00,00,44,00,6e,00,\
73,00,63,00,61,00,63,00,68,00,65,00,00,00,44,00,6e,00,73,00,61,00,70,00,69,\
00,00,00,64,00,6d,00,69,00,6f,00,00,00,64,00,6d,00,62,00,6f,00,6f,00,74,00,\
00,00,44,00,69,00,73,00,74,00,72,00,69,00,62,00,75,00,74,00,65,00,64,00,20,\
00,4c,00,69,00,6e,00,6b,00,20,00,54,00,72,00,61,00,63,00,6b,00,69,00,6e,00,\
67,00,20,00,43,00,6c,00,69,00,65,00,6e,00,74,00,00,00,64,00,69,00,73,00,6b,\
00,00,00,44,00,68,00,63,00,70,00,00,00,44,00,66,00,73,00,53,00,76,00,63,00,\
00,00,44,00,66,00,73,00,44,00,72,00,69,00,76,00,65,00,72,00,00,00,44,00,43,\
00,4f,00,4d,00,00,00,64,00,61,00,63,00,39,00,36,00,30,00,6e,00,74,00,00,00,\
64,00,61,00,63,00,32,00,77,00,32,00,6b,00,00,00,63,00,70,00,71,00,61,00,72,\
00,72,00,61,00,79,00,00,00,63,00,6d,00,64,00,69,00,64,00,65,00,00,00,63,00,\
68,00,61,00,6e,00,67,00,65,00,72,00,00,00,63,00,64,00,72,00,6f,00,6d,00,00,\
00,43,00,64,00,6d,00,00,00,63,00,64,00,66,00,73,00,00,00,63,00,64,00,61,00,\
75,00,64,00,69,00,6f,00,00,00,63,00,64,00,32,00,30,00,78,00,72,00,6e,00,74,\
00,00,00,63,00,62,00,69,00,64,00,66,00,32,00,6b,00,00,00,42,00,72,00,6f,00,\
77,00,73,00,65,00,72,00,00,00,42,00,49,00,54,00,53,00,00,00,62,00,65,00,65,\
00,70,00,00,00,41,00,74,00,6d,00,61,00,72,00,70,00,63,00,00,00,61,00,74,00,\
64,00,69,00,73,00,6b,00,00,00,61,00,74,00,61,00,70,00,69,00,00,00,41,00,73,\
00,79,00,6e,00,63,00,4d,00,61,00,63,00,00,00,61,00,73,00,63,00,33,00,35,00,\
35,00,30,00,00,00,61,00,73,00,63,00,33,00,33,00,35,00,30,00,70,00,00,00,61,\
00,73,00,63,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,\
6f,00,6e,00,20,00,50,00,6f,00,70,00,75,00,70,00,00,00,61,00,70,00,70,00,68,\
00,65,00,6c,00,70,00,00,00,61,00,6d,00,73,00,69,00,6e,00,74,00,00,00,61,00,\
6d,00,69,00,30,00,6e,00,74,00,00,00,61,00,6c,00,69,00,69,00,64,00,65,00,00,\
00,41,00,6c,00,65,00,72,00,74,00,65,00,72,00,00,00,61,00,69,00,63,00,37,00,\
38,00,78,00,78,00,00,00,61,00,69,00,63,00,37,00,38,00,75,00,32,00,00,00,61,\
00,68,00,61,00,31,00,35,00,34,00,78,00,00,00,61,00,64,00,70,00,75,00,31,00,\
36,00,30,00,6d,00,00,00,61,00,63,00,70,00,69,00,65,00,63,00,00,00,61,00,63,\
00,70,00,69,00,00,00,61,00,62,00,70,00,34,00,38,00,30,00,6e,00,35,00,00,00,\
61,00,62,00,69,00,6f,00,73,00,64,00,73,00,6b,00,00,00,53,00,79,00,73,00,74,\
00,65,00,6d,00,00,00,00,00
"RestrictGuestAccess"=dword:00000001
"EventMessageFile"="%systemroot%\\system32\\stisvc.exe"
"TypesSupported"=hex:07,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\abiosdsk]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\abp480n5]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\acpi]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,63,00,70,00,69,00,2e,00,73,00,\
79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\acpiec]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,63,00,70,00,69,00,65,00,63,00,\
2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\adpu160m]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\aha154x]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\aic78u2]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\aic78xx]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Alerter]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\aliide]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,41,00,6c,00,69,00,49,00,64,00,65,00,\
2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\ami0nt]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\amsint]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\apphelp]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,61,00,70,00,70,00,68,00,65,00,6c,00,70,00,2e,00,64,00,6c,00,6c,00,00,\
00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Application Popup]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,74,00,64,00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\asc]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\asc3350p]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\asc3550]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\AsyncMac]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:0000001f

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\atapi]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\atdisk]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Atmarpc]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\beep]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\BITS]
"TypesSupported"=dword:00000007
"CategoryCount"=dword:00000001
"CategoryMessageFile"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,\
6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,78,00,70,00,6f,00,62,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,\
6c,00,00,00
"EventMessageFile"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,\
00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,78,00,70,00,6f,00,62,00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,\
00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Browser]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\cbidf2k]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\cd20xrnt]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\cdaudio]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\cdfs]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Cdm]
@=""

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\cdrom]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\changer]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\cmdide]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,43,00,6d,00,64,00,49,00,64,00,65,00,\
2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\cpqarray]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\dac2w2k]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\dac960nt]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\DCOM]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\DfsDriver]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\DfsSvc]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Dhcp]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,64,00,68,00,63,00,70,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,\
00,00,00
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\disk]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Distributed Link Tracking Client]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\dmboot]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,44,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,62,00,6f,\
00,6f,00,74,00,2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\dmio]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,64,00,6d,00,69,00,6f,00,2e,00,73,00,\
79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Dnsapi]
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Dnscache]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\dpti2o]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\efs]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6c,00,73,00,61,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\eventlog]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\fastfat]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\fdc]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,66,00,64,00,63,00,2e,00,73,00,79,00,\
73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Fips]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,44,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,66,00,69,00,70,00,73,\
00,2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\flpydisk]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,66,00,6c,00,70,00,79,00,64,00,69,00,\
73,00,6b,00,2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\fs_rec]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\ftdisk]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,46,00,74,00,44,00,69,00,73,00,6b,00,\
2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\hpn]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\i2omgmt]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\i2omp]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\i8042prt]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,69,00,38,00,30,00,34,00,32,00,70,00,\
72,00,74,00,2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\IGMPv2]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,69,00,67,00,6d,00,70,00,76,00,32,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\ini910u]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\intelide]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,6c,00,49,00,\
64,00,65,00,2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Internet Explorer 6]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\IPBOOTP]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,69,00,70,00,62,00,6f,00,6f,00,74,00,70,00,2e,00,64,00,6c,00,6c,00,00,\
00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\IPMGM]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,72,00,74,00,6d,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\IPNATHLP]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,69,00,70,00,6e,00,61,00,74,00,68,00,6c,00,70,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\IPRIP2]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,69,00,70,00,72,00,69,00,70,00,32,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\IPRouterManager]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\IPSec]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\IPXCP]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\IPXRIP]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\IPXRouterManager]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\IPXSAP]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\isapnp]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,69,00,73,00,61,00,70,00,6e,00,70,00,\
2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\kbdclass]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,6b,00,62,00,64,00,63,00,6c,00,61,00,\
73,00,73,00,2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Kerberos]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6b,00,65,00,72,00,62,00,65,00,72,00,6f,00,73,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\lbrtfdc]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,6c,00,62,00,72,00,74,00,66,00,64,00,\
63,00,2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\LDM]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,64,00,6d,00,61,00,64,00,6d,00,69,00,6e,00,2e,00,65,00,78,00,65,00,00,\
00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\LDMS]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,64,00,6d,00,73,00,65,00,72,00,76,00,65,00,72,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\LmHosts]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\LsaSrv]
"TypesSupported"=dword:00000007
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6c,00,73,00,61,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,6c,00,73,00,61,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"CategoryCount"=dword:00000004

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Modem]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,4d,00,6f,00,64,00,65,00,6d,00,2e,00,\
73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\mouclass]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,6d,00,6f,00,75,00,63,00,6c,00,61,00,\
73,00,73,00,2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\mouhid]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,6d,00,6f,00,75,00,68,00,69,00,64,00,\
2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\mraid35x]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\MRxDAV]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\MrxSmb]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,69,00,6f,\
00,6c,00,6f,00,67,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\msadlib]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\msfs]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Mup]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\ndis]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\NdisWan]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:0000001f

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\NetBIOS]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,69,00,6f,00,6c,00,6f,00,67,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\NetBT]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\NetDDE]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,64,00,64,00,65,00,2e,00,65,00,78,00,65,00,00,00
"TypesSupported"=dword:0000001f

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Netlogon]
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\NetMate2]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Nla]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\npfs]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\ntfs]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\NtServicePack]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\null]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\nv]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,6e,00,76,00,34,00,5f,00,6d,00,69,00,\
6e,00,69,00,2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\OSPF]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6f,00,73,00,70,00,66,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\OSPFMib]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6f,00,73,00,70,00,66,00,6d,00,69,00,62,00,2e,00,64,00,6c,00,6c,00,00,\
00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Outlook Express 6]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\parport]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,70,00,61,00,72,00,70,00,6f,00,72,00,\
74,00,2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\partmgr]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\parvdm]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,50,00,61,00,72,00,56,00,64,00,6d,00,\
2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\pci]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,50,00,63,00,69,00,2e,00,73,00,79,00,\
73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\pciide]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,50,00,63,00,69,00,49,00,64,00,65,00,\
2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\pcmcia]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,50,00,63,00,6d,00,63,00,69,00,61,00,\
2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\perc2]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\PlugPlayManager]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,75,00,6d,00,70,00,6e,00,70,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\PolicyAgent]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,70,00,6f,00,6c,00,61,00,67,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\PptpMiniport]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Print]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,70,00,6c,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Processor]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,70,00,72,00,6f,00,63,00,65,00,73,00,\
73,00,72,00,2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\PSched]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\ql1080]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\ql10wnt]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\ql12160]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\ql1240]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\ql1280]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\RasAuto]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:0000001f

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\RasMan]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:0000001f

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Rdbss]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\redbook]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,72,00,65,00,64,00,62,00,6f,00,6f,00,\
6b,00,2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Remote Desktop Help Session Manager]
"EventMessageFile"="C:\\WINDOWS\\system32\\sessmgr.exe"
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\RemoteAccess]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6d,00,70,00,72,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,69,00,61,00,73,00,73,00,76,00,63,00,73,00,2e,00,64,00,6c,00,6c,00,\
00,00
"TypesSupported"=dword:0000001f

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Removable Storage Service]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,4e,00,54,00,4d,00,53,00,45,00,56,00,54,00,2e,00,44,00,4c,00,4c,00,00,\
00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\RSVP]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,72,00,73,00,76,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,\
00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\rtl8139]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\SAM]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,61,00,6d,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Save Dump]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,53,00,61,00,76,00,65,00,44,00,75,00,6d,00,70,00,2e,00,65,00,78,00,65,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\SCardSvr]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,53,00,43,00,61,00,72,00,64,00,53,00,76,00,72,00,2e,00,65,00,78,00,65,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Schannel]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6c,00,73,00,61,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Schedule]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\scsiport]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\serial]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,73,00,65,00,72,00,69,00,61,00,6c,00,\
2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Server]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Service Control Manager]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Setup]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,79,00,73,00,73,00,65,00,74,00,75,00,70,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\sfloppy]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\SideBySide]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,78,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Simbad]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\sndblst]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Software Restriction Policy]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,74,00,64,00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\sparrow]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\sr]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\
00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,49,00,\
6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,3b,00,43,\
00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,5c,00,53,00,79,00,\
73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,\
00,53,00,5c,00,73,00,72,00,2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\srservice]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\
00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,\
72,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Srv]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\SSDPSRV]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\StillImage]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,77,00,69,00,61,00,73,00,65,00,72,00,76,00,63,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\symc810]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\symc8xx]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\sym_hi]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\sym_u3]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\System]
"CategoryCount"=dword:00000007
"CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,65,00,76,00,65,00,6e,00,74,00,6c,00,6f,00,67,00,2e,00,64,00,6c,00,\
6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\System Error]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Tcpip]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\TCPMon]
"TypesSupported"=dword:00000007
"EventMessageFile"="%SystemRoot%\\System32\\tcpmon.dll"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\tdi]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\TermDD]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,74,00,64,00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\TermServDevices]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\TermService]
"TypesSupported"=dword:00000007
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,74,00,65,00,72,00,6d,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,3b,\
00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,\
5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6e,00,74,00,64,\
00,6c,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\TermServSessDir]
"TypesSupported"=dword:00000007
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,74,00,73,00,73,00,64,00,69,00,73,00,2e,00,65,00,78,00,65,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\toside]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,54,00,6f,00,73,00,49,00,64,00,65,00,\
2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\udfs]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\ultra]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\UPS]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\USER32]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,75,00,73,00,65,00,72,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\VgaSave]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,76,00,67,00,61,00,2e,00,73,00,79,00,\
73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\viaide]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,56,00,69,00,61,00,49,00,64,00,65,00,\
2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\VolSnap]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,56,00,6f,00,6c,00,53,00,6e,00,61,00,\
70,00,2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\vsdatant]
@=""
"EventMessageFile"="C:\\WINDOWS\\System32\\vsdatant.sys"
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\W32Time]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,\
00,53,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,\
33,00,32,00,74,00,69,00,6d,00,65,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\WGA]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Win32k]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,77,00,69,00,6e,00,33,00,32,00,6b,00,2e,00,73,00,79,00,73,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Windows File Protection]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,66,00,63,00,5f,00,6f,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Windows Installer 3.1]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Windows Script Host]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,77,00,73,00,68,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000018

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Windows Update Agent]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,77,00,75,00,61,00,75,00,63,00,70,00,6c,00,2e,00,63,00,70,00,6c,00,00,\
00
"TypesSupported"=dword:00000007
"CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,77,00,75,00,61,00,75,00,63,00,70,00,6c,00,2e,00,63,00,70,00,6c,00,\
00,00
"CategoryCount"=dword:00000009

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\WindowsMedia]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,70,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\Workstation]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,65,00,74,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Eventlog\System\WZCSVC]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,77,00,7a,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\EventSystem]
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\
5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,\
00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,\
6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="COM+ Event System"
"Group"="Network"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\EventSystem\Parameters]
"ServiceDll"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\
00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,65,00,73,00,\
2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\EventSystem\Security]
"Security"=hex:01,00,14,80,7c,00,00,00,88,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,4c,00,03,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\
02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,\
00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\EventSystem\Enum]
"0"="Root\\LEGACY_EVENTSYSTEM\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Fastfat]
"ErrorControl"=dword:00000001
"Group"="Boot file system"
"Start"=dword:00000004
"Type"=dword:00000002

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Fastfat\Enum]
"0"="Root\\LEGACY_FASTFAT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\FastUserSwitchingCompatibility]
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Fast User Switching Compatibility"
"DependOnService"=hex(7):54,00,65,00,72,00,6d,00,53,00,65,00,72,00,76,00,69,00,\
63,00,65,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Provides management for applications that require assistance in a multiple user environment."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\FastUserSwitchingCompatibility\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
73,00,68,00,73,00,76,00,63,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"ServiceMain"="BadApplicationServiceMain"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\FastUserSwitchingCompatibility\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\FastUserSwitchingCompatibility\Enum]
"0"="Root\\LEGACY_FASTUSERSWITCHINGCOMPATIBILITY\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Fdc]
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Start"=dword:00000003
"Tag"=dword:00000002
"Type"=dword:00000001
"SetupDone"=dword:00000001
"DisplayName"="Floppy Disk Controller Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,66,00,64,00,63,00,2e,00,73,00,79,\
00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Fdc\Enum]
"0"="ACPI\\PNP0700\\3&13c0b0c5&0"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Fips]
"ErrorControl"=dword:00000001
"Start"=dword:00000001
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Fips\Enum]
"0"="Root\\LEGACY_FIPS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Flpydisk]
"ErrorControl"=dword:00000001
"Group"="Primary disk"
"Start"=dword:00000003
"Tag"=dword:00000002
"Type"=dword:00000001
"DisplayName"="Floppy Disk Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,66,00,6c,00,70,00,79,00,64,00,69,\
00,73,00,6b,00,2e,00,73,00,79,00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Flpydisk\Enum]
"0"="FDC\\GENERIC_FLOPPY_DRIVE\\4&33bc18fa&0&0"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Fs_Rec]
"ErrorControl"=dword:00000000
"Group"="Boot file system"
"Start"=dword:00000001
"Type"=dword:00000008

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Fs_Rec\Enum]
"0"="Root\\LEGACY_FS_REC\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Ftdisk]
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Start"=dword:00000000
"Tag"=dword:00000009
"Type"=dword:00000001
"DisplayName"="Volume Manager Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,66,00,74,00,64,00,69,00,73,00,6b,\
00,2e,00,73,00,79,00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Ftdisk\Enum]
"0"="Root\\ftdisk\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\gameenum]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000000
"Tag"=dword:00000006
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,67,00,61,00,6d,00,65,00,65,00,6e,\
00,75,00,6d,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Game Port Enumerator"
"Group"="Extended Base"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\gameenum\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Gpc]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"Tag"=dword:00000003
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,73,00,67,00,70,00,63,00,2e,\
00,73,00,79,00,73,00,00,00
"DisplayName"="Generic Packet Classifier"
"Group"="PNP_TDI"
"Description"="Generic Packet Classifier"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Gpc\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Gpc\Enum]
"0"="Root\\LEGACY_GPC\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\helpsvc]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Help and Support"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start."
"FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,74,00,65,\
00,01,00,00,00,64,00,00,00,01,00,00,00,64,00,00,00,00,00,00,00,64,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\helpsvc\Parameters]
"ServiceDll"=hex(2):25,00,57,00,49,00,4e,00,44,00,49,00,52,00,25,00,5c,00,50,\
00,43,00,48,00,65,00,61,00,6c,00,74,00,68,00,5c,00,48,00,65,00,6c,00,70,00,\
43,00,74,00,72,00,5c,00,42,00,69,00,6e,00,61,00,72,00,69,00,65,00,73,00,5c,\
00,70,00,63,00,68,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\helpsvc\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\helpsvc\Enum]
"0"="Root\\LEGACY_HELPSVC\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\HidServ]
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
"Description"="Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start."
"DisplayName"="Human Interface Device Access"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000004
"Type"=dword:00000020

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\HidServ\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
68,00,69,00,64,00,73,00,65,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\hidusb]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000000
"DisplayName"="Microsoft HID Class Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,68,00,69,00,64,00,75,00,73,00,62,\
00,2e,00,73,00,79,00,73,00,00,00
"Group"="extended base"
"Tag"=dword:00000005

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\hpn]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\hpn\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\hpn\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\i2omgmt]
"ErrorControl"=dword:00000001
"Group"="SCSI Class"
"Start"=dword:00000001
"Tag"=dword:0000002d
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\i2omp]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000002d
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\i2omp\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\i2omp\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\i8042prt]
"Type"=dword:00000001
"Start"=dword:00000001
"Group"="Keyboard Port"
"ErrorControl"=dword:00000001
"DisplayName"="i8042 Keyboard and PS/2 Mouse Port Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,38,00,30,00,34,00,32,00,70,\
00,72,00,74,00,2e,00,73,00,79,00,73,00,00,00
"Tag"=dword:00000004

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\i8042prt\Parameters]
"LayerDriver JPN"="kbd101.dll"
"LayerDriver KOR"="kbd101a.dll"
"PollingIterations"=dword:00002ee0
"PollingIterationsMaximum"=dword:00002ee0
"ResendIterations"=dword:00000003

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\i8042prt\Enum]
"0"="ACPI\\PNP0F13\\3&13c0b0c5&0"
"Count"=dword:00000002
"NextInstance"=dword:00000002
"1"="ACPI\\PNP0303\\3&13c0b0c5&0"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Imapi]
"ErrorControl"=dword:00000001
"Group"="Pnp Filter"
"Start"=dword:00000001
"Tag"=dword:00000002
"Type"=dword:00000001
"DisplayName"="CD-Burning Filter Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,6d,00,61,00,70,00,69,00,2e,\
00,73,00,79,00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Imapi\Enum]
"Count"=dword:00000000
"NextInstance"=dword:00000000
"INITSTARTFAILED"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ImapiService]
"Type"=dword:00000010
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"="C:\\WINDOWS\\System32\\imapi.exe"
"ObjectName"="LocalSystem"
"DisplayName"="IMAPI CD-Burning COM Service"
"Description"="Manages CD recording using Image Mastering Applications Programming Interface (IMAPI). If this service is stopped, this computer will be unable to record CDs. If this service is disabled, any services that explicitly depend on it will fail to start."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\inetaccs]
@=""

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\inetaccs\Parameters]
@=""

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ini910u]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000030
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ini910u\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ini910u\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Inport]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Inport\Parameters]
"HzMode"=dword:00000002

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\IntelIde]
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Start"=dword:00000000
"Tag"=dword:00000004
"Type"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,6e,00,74,00,65,00,6c,00,69,\
00,64,00,65,00,2e,00,73,00,79,00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\IntelIde\Enum]
"0"="PCI\\VEN_8086&DEV_244B&SUBSYS_24428086&REV_05\\3&13c0b0c5&0&F9"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\IpFilterDriver]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,70,00,66,00,6c,00,74,00,64,\
00,72,00,76,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="IP Traffic Filter Driver"
"DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"Description"="IP Traffic Filter Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\IpFilterDriver\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\IpInIp]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,70,00,69,00,6e,00,69,00,70,\
00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="IP in IP Tunnel Driver"
"DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"Description"="IP in IP Tunnel Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\IpInIp\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\IpNat]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,70,00,6e,00,61,00,74,00,2e,\
00,73,00,79,00,73,00,00,00
"DisplayName"="IP Network Address Translator"
"DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"Description"="IP Network Address Translator"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\IpNat\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\IpNat\Enum]
"0"="Root\\LEGACY_IPNAT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\IPSec]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"Tag"=dword:00000005
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,70,00,73,00,65,00,63,00,2e,\
00,73,00,79,00,73,00,00,00
"DisplayName"="IPSEC driver"
"Group"="PNP_TDI"
"Description"="IPSEC driver"
"NoDefaultExempt"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\IPSec\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\IPSec\Enum]
"0"="Root\\LEGACY_IPSEC\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\IRENUM]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,72,00,65,00,6e,00,75,00,6d,\
00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="IR Enumerator Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\IRENUM\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ISAPISearch]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ISAPISearch\Linkage]
"Bind"="\\Dummy"
"Export"="\\Dummy"
"Route"="\\Dummy"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ISAPISearch\Performance]
"Close"="DoneCIISAPIPerformanceData"
"Collect"="CollectCIISAPIPerformanceData"
"Open"="InitializeCIISAPIPerformanceData"
"Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,71,\
00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00
"Last Counter"=dword:000008de
"Last Help"=dword:000008df
"First Counter"=dword:000008ca
"First Help"=dword:000008cb
"Object List"="2250"
"WbemAdapFileSignature"=hex:9b,54,7a,f3,fd,4c,f8,29,29,9e,4f,3c,05,c4,96,40
"WbemAdapFileTime"=hex:00,a7,70,96,48,4f,c2,01
"WbemAdapFileSize"=dword:00149600
"WbemAdapStatus"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\isapnp]
"ErrorControl"=dword:00000003
"Group"="Boot Bus Extender"
"Start"=dword:00000000
"Tag"=dword:00000003
"Type"=dword:00000001
"HasBootConfig"=dword:00000000
"DisplayName"="PnP ISA/EISA Bus Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,73,00,61,00,70,00,6e,00,70,\
00,2e,00,73,00,79,00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\isapnp\Parameters]
"ADP1502"=dword:00000001
"ADP1505"=dword:00000001
"ADP1510"=dword:00000001
"ADP1512"=dword:00000001
"ADP1515"=dword:00000001
"ADP1520"=dword:00000001
"ADP1522"=dword:00000001
"ADP3015"=dword:00000001
"ADP3215"=dword:00000001
"ADP6360"=dword:00000001
"ADP6370"=dword:00000001
"USR0014"=dword:00000001
"USR1001"=dword:00000001
"USR1002"=dword:00000001
"USR1003"=dword:00000001
"USR1004"=dword:00000001
"USR6001"=dword:00000001
"USR6002"=dword:00000001
"USR6003"=dword:00000001
"USR6004"=dword:00000001
"USR6005"=dword:00000001
"USR6006"=dword:00000001
"USR6007"=dword:00000001
"USR6008"=dword:00000001
"USR6009"=dword:00000001
"USR600A"=dword:00000001
"USR600B"=dword:00000001
"USR600C"=dword:00000001
"USR600D"=dword:00000001
"USR600E"=dword:00000001
"USR600F"=dword:00000001
"USR6010"=dword:00000001
"USR6011"=dword:00000001
"USR6012"=dword:00000001
"USR6101"=dword:00000001
"USR6020"=dword:00000001
"USR0041"=dword:00000001
"USR002C"=dword:00000001
"AZT4029"=dword:00000001
"AZT4023"=dword:00000001
"USR0040"=dword:00000001
"HAY8601"=dword:00000001
"EQX2400"=dword:00000002
"EQX0900"=dword:00000002
"EQX1B00"=dword:00000002
"EQX1700"=dword:00000002
"EQX0700"=dword:00000002
"EQX0F00"=dword:00000002
"EQX0800"=dword:00000002
"EQX1000"=dword:00000002
"EQX3F00"=dword:00000002
"EQX1200"=dword:00000002
"IBM0001"=dword:00000010

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\isapnp\Enum]
"0"="PCI\\VEN_8086&DEV_2440&SUBSYS_00000000&REV_05\\3&13c0b0c5&0&F8"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Kbdclass]
"ErrorControl"=dword:00000001
"Group"="Keyboard Class"
"Start"=dword:00000001
"Tag"=dword:00000001
"Type"=dword:00000001
"DisplayName"="Keyboard Class Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6b,00,62,00,64,00,63,00,6c,00,61,\
00,73,00,73,00,2e,00,73,00,79,00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Kbdclass\Parameters]
"ConnectMultiplePorts"=dword:00000000
"KeyboardDataQueueSize"=dword:00000064
"KeyboardDeviceBaseName"="KeyboardClass"
"MaximumPortsServiced"=dword:00000003
"SendOutputToAllPorts"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Kbdclass\Enum]
"0"="Root\\RDP_KBD\\0000"
"Count"=dword:00000002
"NextInstance"=dword:00000002
"1"="ACPI\\PNP0303\\3&13c0b0c5&0"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\kmixer]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
72,00,69,00,76,00,65,00,72,00,73,00,5c,00,6b,00,6d,00,69,00,78,00,65,00,72,\
00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Microsoft Kernel Wave Audio Mixer"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\kmixer\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\KSecDD]
"ErrorControl"=dword:00000001
"Group"="Base"
"Start"=dword:00000000
"Tag"=dword:00000001
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\KSecDD\Enum]
"0"="Root\\LEGACY_KSECDD\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\lbrtfdc]
"ErrorControl"=dword:00000000
"Group"="System Bus Extender"
"Start"=dword:00000001
"Tag"=dword:0000000e
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ldap]
"ldapclientintegrity"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\LicenseService]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\LicenseService\FilePrint]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\LicenseService\FilePrint\TermService]
@=""

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\LmHosts]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\
00,65,00,00,00
"DisplayName"="TCP/IP NetBIOS Helper"
"Group"="TDI"
"DependOnService"=hex(7):4e,00,65,00,74,00,42,00,54,00,00,00,41,00,66,00,64,00,\
00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="NT AUTHORITY\\LocalService"
"Description"="Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\LmHosts\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
6c,00,6d,00,68,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\LmHosts\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\LmHosts\Enum]
"0"="Root\\LEGACY_LMHOSTS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\mnmdd]
"ErrorControl"=dword:00000000
"Group"="Video Save"
"Start"=dword:00000001
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\mnmdd\Device0]
"InstalledDisplayDrivers"=hex(7):6d,00,6e,00,6d,00,64,00,64,00,00,00,00,00
"Device Description"="NetMeeting driver"
"VgaCompatible"=dword:00000000
"MirrorDriver"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\mnmdd\Video]
"VideoID"="{8B6D7859-A639-4A15-8790-7161976D057A}"
"Service"="mnmdd"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\mnmdd\Enum]
"0"="Root\\LEGACY_MNMDD\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\mnmsrvc]
"Type"=dword:00000110
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\
5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,6e,00,6d,\
00,73,00,72,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00
"DisplayName"="NetMeeting Remote Desktop Sharing"
"ObjectName"="LocalSystem"
"Description"="Enables an authorized user to access this computer remotely by using NetMeeting over a corporate intranet. If this service is stopped, remote desktop sharing will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\mnmsrvc\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Modem]
"ErrorControl"=dword:00000000
"Group"="Extended base"
"Start"=dword:00000003
"Tag"=dword:00000004
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Modem\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Mouclass]
"ErrorControl"=dword:00000001
"Group"="Pointer Class"
"Start"=dword:00000001
"Tag"=dword:00000001
"Type"=dword:00000001
"DisplayName"="Mouse Class Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,6f,00,75,00,63,00,6c,00,61,\
00,73,00,73,00,2e,00,73,00,79,00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Mouclass\Parameters]
"ConnectMultiplePorts"=dword:00000000
"MaximumPortsServiced"=dword:00000003
"MouseDataQueueSize"=dword:00000064
"PointerDeviceBaseName"="PointerClass"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Mouclass\Enum]
"0"="Root\\RDP_MOU\\0000"
"Count"=dword:00000002
"NextInstance"=dword:00000002
"1"="ACPI\\PNP0F13\\3&13c0b0c5&0"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\mouhid]
"Type"=dword:00000001
"Start"=dword:00000003
"Group"="Pointer Port"
"ErrorControl"=dword:00000000
"DisplayName"="Mouse HID Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,6f,00,75,00,68,00,69,00,64,\
00,2e,00,73,00,79,00,73,00,00,00
"Tag"=dword:00000004

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\mouhid\Parameters]
"UseOnlyMice"=dword:00000000
"TreatAbsoluteAsRelative"=dword:00000000
"TreatAbsolutePointerAsAbsolute"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MountMgr]
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Start"=dword:00000000
"Tag"=dword:00000008
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MountMgr\Enum]
"0"="Root\\LEGACY_MOUNTMGR\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\mraid35x]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000002b
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\mraid35x\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\mraid35x\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MRxDAV]
"Type"=dword:00000002
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6d,00,72,00,78,00,64,00,61,00,76,\
00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="WebDav Client Redirector"
"Description"="WebDav Client Redirector"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MRxDAV\EncryptedDirectories]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MRxDAV\Parameters]
"FileInformationCacheLifeTimeInSec"=dword:0000003c
"FileNotFoundCacheLifeTimeInSec"=dword:0000003c
"NameCacheMaxEntries"=dword:0000012c
"DAVDebugFlag"=dword:00000000
"UMRxDebugFlag"=dword:00000000
"RequestTimeoutInSec"=dword:00000258

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MRxDAV\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MRxDAV\Enum]
"0"="Root\\LEGACY_MRXDAV\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MSDTC]
"Type"=dword:00000010
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\
5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,73,00,64,\
00,74,00,63,00,2e,00,65,00,78,00,65,00,00,00
"DisplayName"="Distributed Transaction Coordinator"
"Group"="MS Transactions"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,53,00,61,00,6d,00,\
53,00,53,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="NT AUTHORITY\\NetworkService"
"Description"="Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start. "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MSDTC\Performance]
"Library"="msdtcuiu.DLL"
"Open"="DtcPerfOpen"
"Collect"="DtcPerfCollect"
"Close"="DtcPerfClose"
"Last Counter"=dword:000008a2
"Last Help"=dword:000008a3
"First Counter"=dword:00000888
"First Help"=dword:00000889
"Object List"="2184"
"WbemAdapFileSignature"=hex:cf,8a,ac,14,1e,21,b7,42,de,d7,fc,a7,0f,ae,c8,ec
"WbemAdapFileTime"=hex:20,7a,3b,33,d2,bb,c6,01
"WbemAdapFileSize"=dword:00024e00
"WbemAdapStatus"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MSDTC\Security]
"Security"=hex:01,00,14,80,b8,00,00,00,c4,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,88,00,06,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\
02,00,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,\
00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,\
00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,18,00,fd,01,\
02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,00,00,14,00,9d,00,02,\
00,01,01,00,00,00,00,00,05,14,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,\
01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MSDTC\Enum]
"0"="Root\\LEGACY_MSDTC\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Msfs]
"ErrorControl"=dword:00000001
"Group"="File system"
"Start"=dword:00000001
"Type"=dword:00000002

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Msfs\Enum]
"0"="Root\\LEGACY_MSFS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MSIServer]
"Description"="Installs, repairs and removes software according to instructions contained in .MSI files."
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\
5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,73,00,69,\
00,65,00,78,00,65,00,63,00,2e,00,65,00,78,00,65,00,20,00,2f,00,56,00,00,00
"DisplayName"="Windows Installer"
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MSIServer\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MSIServer\Enum]
"0"="Root\\LEGACY_MSISERVER\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MSKSSRV]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"Tag"=dword:00000008
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
72,00,69,00,76,00,65,00,72,00,73,00,5c,00,4d,00,53,00,4b,00,53,00,53,00,52,\
00,56,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Microsoft Streaming Service Proxy"
"Group"="Extended Base"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MSKSSRV\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MSPCLOCK]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"Tag"=dword:00000007
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
72,00,69,00,76,00,65,00,72,00,73,00,5c,00,4d,00,53,00,50,00,43,00,4c,00,4f,\
00,43,00,4b,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Microsoft Streaming Clock Proxy"
"Group"="Extended Base"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MSPCLOCK\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MSPQM]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"Tag"=dword:00000009
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
72,00,69,00,76,00,65,00,72,00,73,00,5c,00,4d,00,53,00,50,00,51,00,4d,00,2e,\
00,73,00,79,00,73,00,00,00
"DisplayName"="Microsoft Streaming Quality Manager Proxy"
"Group"="Extended Base"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\MSPQM\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Mup]
"DisplayName"="Mup"
"ErrorControl"=dword:00000001
"Group"="Network"
"Start"=dword:00000000
"Tag"=dword:00000002
"Type"=dword:00000002

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Mup\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Mup\Enum]
"0"="Root\\LEGACY_MUP\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NDIS]
"DisplayName"="NDIS System Driver"
"ErrorControl"=dword:00000001
"Group"="NDIS Wrapper"
"Start"=dword:00000000
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NDIS\MediaTypes]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NDIS\Parameters]
"ProcessorAffinityMask"=dword:ffffffff

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NDIS\Enum]
"0"="Root\\LEGACY_NDIS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NdisTapi]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,64,00,69,00,73,00,74,00,61,\
00,70,00,69,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Remote Access NDIS TAPI Driver"
"Description"="Remote Access NDIS TAPI Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NdisTapi\Parameters]
"AsyncEventQueueSize"=dword:00000300

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NdisTapi\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NdisTapi\Enum]
"0"="Root\\LEGACY_NDISTAPI\\0000"
"Count"=dword:00000004
"NextInstance"=dword:00000004
"1"="Root\\MS_NDISWANIP\\0000"
"2"="Root\\MS_PPPOEMINIPORT\\0000"
"3"="Root\\MS_PPTPMINIPORT\\0000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Ndisuio]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"Tag"=dword:0000000c
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,64,00,69,00,73,00,75,00,69,\
00,6f,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="NDIS Usermode I/O Protocol"
"Group"="NDIS"
"Description"="NDIS Usermode I/O Protocol"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Ndisuio\Linkage]
"Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,41,00,41,\
00,33,00,46,00,46,00,32,00,45,00,44,00,2d,00,38,00,46,00,31,00,44,00,2d,00,\
34,00,32,00,44,00,32,00,2d,00,42,00,32,00,36,00,43,00,2d,00,33,00,43,00,44,\
00,45,00,35,00,38,00,39,00,38,00,33,00,42,00,32,00,36,00,7d,00,00,00,5c,00,\
44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,46,00,45,00,43,00,43,00,42,\
00,31,00,41,00,46,00,2d,00,44,00,43,00,38,00,43,00,2d,00,34,00,41,00,45,00,\
37,00,2d,00,41,00,36,00,32,00,31,00,2d,00,44,00,42,00,43,00,30,00,43,00,42,\
00,42,00,31,00,35,00,38,00,41,00,42,00,7d,00,00,00,00,00
"Route"=hex(7):22,00,7b,00,41,00,41,00,33,00,46,00,46,00,32,00,45,00,44,00,2d,\
00,38,00,46,00,31,00,44,00,2d,00,34,00,32,00,44,00,32,00,2d,00,42,00,32,00,\
36,00,43,00,2d,00,33,00,43,00,44,00,45,00,35,00,38,00,39,00,38,00,33,00,42,\
00,32,00,36,00,7d,00,22,00,00,00,22,00,7b,00,46,00,45,00,43,00,43,00,42,00,\
31,00,41,00,46,00,2d,00,44,00,43,00,38,00,43,00,2d,00,34,00,41,00,45,00,37,\
00,2d,00,41,00,36,00,32,00,31,00,2d,00,44,00,42,00,43,00,30,00,43,00,42,00,\
42,00,31,00,35,00,38,00,41,00,42,00,7d,00,22,00,00,00,00,00
"Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,\
00,73,00,75,00,69,00,6f,00,5f,00,7b,00,41,00,41,00,33,00,46,00,46,00,32,00,\
45,00,44,00,2d,00,38,00,46,00,31,00,44,00,2d,00,34,00,32,00,44,00,32,00,2d,\
00,42,00,32,00,36,00,43,00,2d,00,33,00,43,00,44,00,45,00,35,00,38,00,39,00,\
38,00,33,00,42,00,32,00,36,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,\
00,65,00,5c,00,4e,00,64,00,69,00,73,00,75,00,69,00,6f,00,5f,00,7b,00,46,00,\
45,00,43,00,43,00,42,00,31,00,41,00,46,00,2d,00,44,00,43,00,38,00,43,00,2d,\
00,34,00,41,00,45,00,37,00,2d,00,41,00,36,00,32,00,31,00,2d,00,44,00,42,00,\
43,00,30,00,43,00,42,00,42,00,31,00,35,00,38,00,41,00,42,00,7d,00,00,00,00,\
00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Ndisuio\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Ndisuio\Enum]
"0"="Root\\LEGACY_NDISUIO\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NdisWan]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,64,00,69,00,73,00,77,00,61,\
00,6e,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Remote Access NDIS WAN Driver"
"Description"="Remote Access NDIS WAN Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NdisWan\Linkage]
"Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,32,00,33,\
00,30,00,41,00,37,00,44,00,38,00,33,00,2d,00,30,00,32,00,41,00,32,00,2d,00,\
34,00,37,00,39,00,30,00,2d,00,38,00,35,00,34,00,34,00,2d,00,33,00,44,00,32,\
00,36,00,39,00,37,00,45,00,31,00,44,00,42,00,35,00,32,00,7d,00,00,00,5c,00,\
44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,38,00,35,00,31,00,32,00,31,\
00,43,00,41,00,38,00,2d,00,46,00,38,00,37,00,31,00,2d,00,34,00,38,00,38,00,\
38,00,2d,00,38,00,46,00,35,00,33,00,2d,00,36,00,45,00,37,00,32,00,36,00,41,\
00,36,00,30,00,30,00,44,00,42,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,\
69,00,63,00,65,00,5c,00,7b,00,46,00,34,00,31,00,35,00,45,00,39,00,39,00,38,\
00,2d,00,42,00,32,00,44,00,45,00,2d,00,34,00,31,00,46,00,31,00,2d,00,38,00,\
45,00,33,00,41,00,2d,00,32,00,41,00,35,00,46,00,37,00,37,00,31,00,46,00,34,\
00,44,00,32,00,35,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,\
5c,00,7b,00,31,00,35,00,37,00,46,00,45,00,42,00,35,00,32,00,2d,00,46,00,32,\
00,30,00,30,00,2d,00,34,00,30,00,45,00,46,00,2d,00,39,00,44,00,46,00,31,00,\
2d,00,42,00,30,00,33,00,32,00,42,00,38,00,36,00,44,00,43,00,41,00,44,00,42,\
00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,33,00,\
30,00,36,00,35,00,37,00,44,00,46,00,35,00,2d,00,33,00,38,00,36,00,35,00,2d,\
00,34,00,35,00,33,00,34,00,2d,00,38,00,42,00,37,00,37,00,2d,00,35,00,45,00,\
36,00,42,00,30,00,39,00,31,00,33,00,31,00,44,00,31,00,45,00,7d,00,00,00,00,\
00
"Route"=hex(7):22,00,7b,00,32,00,33,00,30,00,41,00,37,00,44,00,38,00,33,00,2d,\
00,30,00,32,00,41,00,32,00,2d,00,34,00,37,00,39,00,30,00,2d,00,38,00,35,00,\
34,00,34,00,2d,00,33,00,44,00,32,00,36,00,39,00,37,00,45,00,31,00,44,00,42,\
00,35,00,32,00,7d,00,22,00,00,00,22,00,7b,00,38,00,35,00,31,00,32,00,31,00,\
43,00,41,00,38,00,2d,00,46,00,38,00,37,00,31,00,2d,00,34,00,38,00,38,00,38,\
00,2d,00,38,00,46,00,35,00,33,00,2d,00,36,00,45,00,37,00,32,00,36,00,41,00,\
36,00,30,00,30,00,44,00,42,00,39,00,7d,00,22,00,00,00,22,00,7b,00,46,00,34,\
00,31,00,35,00,45,00,39,00,39,00,38,00,2d,00,42,00,32,00,44,00,45,00,2d,00,\
34,00,31,00,46,00,31,00,2d,00,38,00,45,00,33,00,41,00,2d,00,32,00,41,00,35,\
00,46,00,37,00,37,00,31,00,46,00,34,00,44,00,32,00,35,00,7d,00,22,00,00,00,\
22,00,7b,00,31,00,35,00,37,00,46,00,45,00,42,00,35,00,32,00,2d,00,46,00,32,\
00,30,00,30,00,2d,00,34,00,30,00,45,00,46,00,2d,00,39,00,44,00,46,00,31,00,\
2d,00,42,00,30,00,33,00,32,00,42,00,38,00,36,00,44,00,43,00,41,00,44,00,42,\
00,7d,00,22,00,00,00,22,00,7b,00,33,00,30,00,36,00,35,00,37,00,44,00,46,00,\
35,00,2d,00,33,00,38,00,36,00,35,00,2d,00,34,00,35,00,33,00,34,00,2d,00,38,\
00,42,00,37,00,37,00,2d,00,35,00,45,00,36,00,42,00,30,00,39,00,31,00,33,00,\
31,00,44,00,31,00,45,00,7d,00,22,00,00,00,00,00
"Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,\
00,73,00,57,00,61,00,6e,00,5f,00,7b,00,32,00,33,00,30,00,41,00,37,00,44,00,\
38,00,33,00,2d,00,30,00,32,00,41,00,32,00,2d,00,34,00,37,00,39,00,30,00,2d,\
00,38,00,35,00,34,00,34,00,2d,00,33,00,44,00,32,00,36,00,39,00,37,00,45,00,\
31,00,44,00,42,00,35,00,32,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,\
00,65,00,5c,00,4e,00,64,00,69,00,73,00,57,00,61,00,6e,00,5f,00,7b,00,38,00,\
35,00,31,00,32,00,31,00,43,00,41,00,38,00,2d,00,46,00,38,00,37,00,31,00,2d,\
00,34,00,38,00,38,00,38,00,2d,00,38,00,46,00,35,00,33,00,2d,00,36,00,45,00,\
37,00,32,00,36,00,41,00,36,00,30,00,30,00,44,00,42,00,39,00,7d,00,00,00,5c,\
00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,00,73,00,57,00,\
61,00,6e,00,5f,00,7b,00,46,00,34,00,31,00,35,00,45,00,39,00,39,00,38,00,2d,\
00,42,00,32,00,44,00,45,00,2d,00,34,00,31,00,46,00,31,00,2d,00,38,00,45,00,\
33,00,41,00,2d,00,32,00,41,00,35,00,46,00,37,00,37,00,31,00,46,00,34,00,44,\
00,32,00,35,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,\
4e,00,64,00,69,00,73,00,57,00,61,00,6e,00,5f,00,7b,00,31,00,35,00,37,00,46,\
00,45,00,42,00,35,00,32,00,2d,00,46,00,32,00,30,00,30,00,2d,00,34,00,30,00,\
45,00,46,00,2d,00,39,00,44,00,46,00,31,00,2d,00,42,00,30,00,33,00,32,00,42,\
00,38,00,36,00,44,00,43,00,41,00,44,00,42,00,7d,00,00,00,5c,00,44,00,65,00,\
76,00,69,00,63,00,65,00,5c,00,4e,00,64,00,69,00,73,00,57,00,61,00,6e,00,5f,\
00,7b,00,33,00,30,00,36,00,35,00,37,00,44,00,46,00,35,00,2d,00,33,00,38,00,\
36,00,35,00,2d,00,34,00,35,00,33,00,34,00,2d,00,38,00,42,00,37,00,37,00,2d,\
00,35,00,45,00,36,00,42,00,30,00,39,00,31,00,33,00,31,00,44,00,31,00,45,00,\
7d,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NdisWan\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NdisWan\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NdisWan\Enum]
"0"="Root\\MS_NDISWANIP\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NDProxy]
"DisplayName"=hex(7):4e,00,44,00,49,00,53,00,20,00,50,00,72,00,6f,00,78,00,79,\
00,00,00,00,00
"ErrorControl"=dword:00000001
"Group"="PNP_TDI"
"Start"=dword:00000003
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NDProxy\Enum]
"0"="Root\\LEGACY_NDPROXY\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NetBT]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"Tag"=dword:00000006
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,65,00,74,00,62,00,74,00,2e,\
00,73,00,79,00,73,00,00,00
"DisplayName"="NetBios over Tcpip"
"Group"="PNP_TDI"
"DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"Description"="NetBios over Tcpip"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NetBT\Linkage]
"OtherDependencies"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00
"Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,\
00,69,00,70,00,5f,00,7b,00,41,00,41,00,33,00,46,00,46,00,32,00,45,00,44,00,\
2d,00,38,00,46,00,31,00,44,00,2d,00,34,00,32,00,44,00,32,00,2d,00,42,00,32,\
00,36,00,43,00,2d,00,33,00,43,00,44,00,45,00,35,00,38,00,39,00,38,00,33,00,\
42,00,32,00,36,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,\
00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,46,00,45,00,43,00,43,00,42,00,\
31,00,41,00,46,00,2d,00,44,00,43,00,38,00,43,00,2d,00,34,00,41,00,45,00,37,\
00,2d,00,41,00,36,00,32,00,31,00,2d,00,44,00,42,00,43,00,30,00,43,00,42,00,\
42,00,31,00,35,00,38,00,41,00,42,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,\
00,63,00,65,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,33,00,36,00,\
36,00,37,00,41,00,42,00,45,00,31,00,2d,00,46,00,42,00,43,00,32,00,2d,00,34,\
00,33,00,39,00,44,00,2d,00,38,00,31,00,41,00,46,00,2d,00,33,00,42,00,36,00,\
42,00,39,00,39,00,38,00,38,00,36,00,34,00,45,00,37,00,7d,00,00,00,5c,00,44,\
00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,\
7b,00,45,00,36,00,45,00,41,00,43,00,41,00,31,00,44,00,2d,00,35,00,38,00,43,\
00,38,00,2d,00,34,00,34,00,44,00,42,00,2d,00,39,00,36,00,46,00,32,00,2d,00,\
42,00,35,00,36,00,33,00,39,00,44,00,33,00,32,00,32,00,38,00,42,00,34,00,7d,\
00,00,00,00,00
"Route"=hex(7):22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,41,\
00,41,00,33,00,46,00,46,00,32,00,45,00,44,00,2d,00,38,00,46,00,31,00,44,00,\
2d,00,34,00,32,00,44,00,32,00,2d,00,42,00,32,00,36,00,43,00,2d,00,33,00,43,\
00,44,00,45,00,35,00,38,00,39,00,38,00,33,00,42,00,32,00,36,00,7d,00,22,00,\
00,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,46,00,45,\
00,43,00,43,00,42,00,31,00,41,00,46,00,2d,00,44,00,43,00,38,00,43,00,2d,00,\
34,00,41,00,45,00,37,00,2d,00,41,00,36,00,32,00,31,00,2d,00,44,00,42,00,43,\
00,30,00,43,00,42,00,42,00,31,00,35,00,38,00,41,00,42,00,7d,00,22,00,00,00,\
22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,4e,00,64,00,69,00,73,\
00,57,00,61,00,6e,00,49,00,70,00,22,00,00,00,00,00
"Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,\
00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,41,00,41,00,\
33,00,46,00,46,00,32,00,45,00,44,00,2d,00,38,00,46,00,31,00,44,00,2d,00,34,\
00,32,00,44,00,32,00,2d,00,42,00,32,00,36,00,43,00,2d,00,33,00,43,00,44,00,\
45,00,35,00,38,00,39,00,38,00,33,00,42,00,32,00,36,00,7d,00,00,00,5c,00,44,\
00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,\
54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,46,00,45,00,43,00,43,00,42,00,31,\
00,41,00,46,00,2d,00,44,00,43,00,38,00,43,00,2d,00,34,00,41,00,45,00,37,00,\
2d,00,41,00,36,00,32,00,31,00,2d,00,44,00,42,00,43,00,30,00,43,00,42,00,42,\
00,31,00,35,00,38,00,41,00,42,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,\
63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,\
00,70,00,5f,00,7b,00,33,00,36,00,36,00,37,00,41,00,42,00,45,00,31,00,2d,00,\
46,00,42,00,43,00,32,00,2d,00,34,00,33,00,39,00,44,00,2d,00,38,00,31,00,41,\
00,46,00,2d,00,33,00,42,00,36,00,42,00,39,00,39,00,38,00,38,00,36,00,34,00,\
45,00,37,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,\
00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,\
45,00,36,00,45,00,41,00,43,00,41,00,31,00,44,00,2d,00,35,00,38,00,43,00,38,\
00,2d,00,34,00,34,00,44,00,42,00,2d,00,39,00,36,00,46,00,32,00,2d,00,42,00,\
35,00,36,00,33,00,39,00,44,00,33,00,32,00,32,00,38,00,42,00,34,00,7d,00,00,\
00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NetBT\Parameters]
"NbProvider"="_tcp"
"NameServerPort"=dword:00000089
"CacheTimeout"=dword:000927c0
"BcastNameQueryCount"=dword:00000003
"BcastQueryTimeout"=dword:000002ee
"NameSrvQueryCount"=dword:00000003
"NameSrvQueryTimeout"=dword:000005dc
"Size/Small/Medium/Large"=dword:00000001
"SessionKeepAlive"=dword:0036ee80
"TransportBindName"="\\Device\\"
"EnableLMHOSTS"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NetBT\Parameters\Interfaces]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NetBT\Parameters\Interfaces\Tcpip_{3667ABE1-FBC2-439D-81AF-3B6B998864E7}]
"NameServerList"=hex(7):00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NetBT\Parameters\Interfaces\Tcpip_{AA3FF2ED-8F1D-42D2-B26C-3CDE58983B26}]
"NameServerList"=hex(7):00,00
"NetbiosOptions"=dword:00000002

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NetBT\Parameters\Interfaces\Tcpip_{E6EACA1D-58C8-44DB-96F2-B5639D3228B4}]
"NameServerList"=hex(7):00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NetBT\Parameters\Interfaces\Tcpip_{FECCB1AF-DC8C-4AE7-A621-DBC0CBB158AB}]
"NameServerList"=hex(7):00,00
"NetbiosOptions"=dword:00000002

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NetBT\Security]
"Security"=hex:01,00,14,80,e8,00,00,00,f4,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,b8,00,08,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,25,02,\
00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,00,00,14,\
00,40,00,00,00,01,01,00,00,00,00,00,05,13,00,00,00,00,00,14,00,40,00,00,00,\
01,01,00,00,00,00,00,05,14,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,\
00,00,05,20,00,00,00,2c,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NetBT\Enum]
"0"="Root\\LEGACY_NETBT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NetDDE]
"DependOnService"=hex(7):4e,00,65,00,74,00,44,00,44,00,45,00,44,00,53,00,44,00,\
4d,00,00,00,00,00
"Description"="Provides network transport and security for Dynamic Data Exchange (DDE) for programs running on the same computer or on different computers. If this service is stopped, DDE transport and security will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start."
"DisplayName"="Network DDE"
"ErrorControl"=dword:00000001
"Group"="NetDDEGroup"
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6e,\
00,65,00,74,00,64,00,64,00,65,00,2e,00,65,00,78,00,65,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000003
"Type"=dword:00000020

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NetDDE\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\
02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NetDDEdsdm]
"DependOnService"=hex(7):00,00
"Description"="Manages Dynamic Data Exchange (DDE) network shares. If this service is stopped, DDE network shares will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. "
"DisplayName"="Network DDE DSDM"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6e,\
00,65,00,74,00,64,00,64,00,65,00,2e,00,65,00,78,00,65,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000003
"Type"=dword:00000020

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NetDDEdsdm\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\
02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Netman]
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
"Description"="Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections."
"DisplayName"="Network Connections"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000003
"Type"=dword:00000120

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Netman\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
6e,00,65,00,74,00,6d,00,61,00,6e,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Netman\Enum]
"0"="Root\\LEGACY_NETMAN\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NetMate2]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"Tag"=dword:0000000d
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,65,00,74,00,6d,00,61,00,74,\
00,65,00,32,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="CATC USB/Ethernet Link II device driver"
"Group"="NDIS"
"TextModeFlags"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NetMate2\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Nla]
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Network Location Awareness (NLA)"
"DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,41,00,66,00,64,00,\
00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Collects and stores network configuration and location information, and notifies applications when this information changes."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Nla\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
6d,00,73,00,77,00,73,00,6f,00,63,00,6b,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Nla\Security]
"Security"=hex:01,00,14,80,7c,00,00,00,88,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,4c,00,03,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,\
00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Nla\Enum]
"0"="Root\\LEGACY_NLA\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Npfs]
"ErrorControl"=dword:00000001
"Group"="File system"
"Start"=dword:00000001
"Type"=dword:00000002

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Npfs\Aliases]
"lsass"=hex(7):70,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,5f,00,73,\
00,74,00,6f,00,72,00,61,00,67,00,65,00,00,00,6e,00,65,00,74,00,6c,00,6f,00,\
67,00,6f,00,6e,00,00,00,6c,00,73,00,61,00,72,00,70,00,63,00,00,00,73,00,61,\
00,6d,00,72,00,00,00,00,00
"ntsvcs"=hex(7):65,00,76,00,65,00,6e,00,74,00,6c,00,6f,00,67,00,00,00,73,00,76,\
00,63,00,63,00,74,00,6c,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Npfs\Enum]
"0"="Root\\LEGACY_NPFS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Ntfs]
"ErrorControl"=dword:00000001
"Group"="File system"
"Start"=dword:00000004
"Type"=dword:00000002

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Ntfs\Enum]
"0"="Root\\LEGACY_NTFS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NtmsSvc]
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Removable Storage"
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NtmsSvc\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
6e,00,74,00,6d,00,73,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
"ShutdownTimeout"=dword:00007530

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NtmsSvc\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Null]
"ErrorControl"=dword:00000001
"Group"="Base"
"Start"=dword:00000001
"Tag"=dword:00000001
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Null\Enum]
"0"="Root\\LEGACY_NULL\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\nv]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000000
"Tag"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,76,00,34,00,5f,00,6d,00,69,\
00,6e,00,69,00,2e,00,73,00,79,00,73,00,00,00
"Group"="Video"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\nv\Device0]
"InstalledDisplayDrivers"=hex(7):6e,00,76,00,34,00,5f,00,64,00,69,00,73,00,70,\
00,00,00,00,00
"VgaCompatible"=dword:00000000
"CapabilityOverride"=dword:00000008
"Attach.ToDesktop"=dword:00000001
"DefaultSettings.BitsPerPel"=dword:00000010
"DefaultSettings.XResolution"=dword:00000320
"DefaultSettings.YResolution"=dword:00000258
"UseCompressedModeFormat"=dword:00000001
"NV4_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;1024,768,-,140-170;1152,864,-16,140-150;1152,864,32,140;S 1280,768,-,-;1280,960,-,-;1280,1024,32,120;1600,900,-16,100-;1600,900,32,85-;1600,1024,-16,100-;1600,1024,32,85-;1600,1200,-16,100-;1600,1200,32,85-;1920,1080,-16,100-;1920,1080,32,75-;1920,1200,-16,85-;1920,1200,32,70-;1920,1440,-,-;2048,1536,-,-"
"NV5_Modes_Delta"="A 640,480,-16,140-240;640,480,32,140-170;800,600,-16,140-240;800,600,32,140-150;1024,768,-16,140-200;1152,864,-16,140-170;1280,768,-16,140-150;1280,960,-16,140-150;1280,1024,-16,140-150;S 1600,900,32,100-;1600,1024,-16,120;1600,1024,32,100-;1600,1200,-16,120;1600,1200,32,100-;1920,1080,-16,120;1920,1080,32,85-;1920,1200,-16,100-;1920,1200,32,72-;1920,1440,-16,85-;1920,1440,32,70-;2048,1536,-16,70-;2048,1536,32,-"
"NV0A_Modes_Delta"="S 1600,900,-16,120;1600,900,32,100-;1600,1024,-16,120;1600,1024,32,100-;1600,1200,-16,120;1600,1200,32,100-;1920,1080,-16,120;1920,1080,32,85-;1920,1200,-16,100-;1920,1200,32,72-;1920,1440,-16,85-;1920,1440,32,70-;2048,1536,-16,70-;2048,1536,32,-"
"NVVANTA_Modes_Delta"="S 1280,768,-,-;1280,960,-,-;1280,1024,32,120;1600,900,-16,100-;1600,900,32,85-;1600,1024,-16,100-;1600,1024,32,85-;1600,1200,-16,100-;1600,1200,32,85-;1920,1080,-16,100-;1920,1080,32,70-;1920,1200,-16,85-;1920,1200,32,70-;1920,1440,-,-;2048,1536,-,-"
"NV5M64_Modes_Delta"="S 1600,900,-16,120;1600,900,32,100-;1600,1024,-16,120;1600,1024,32,100-;1600,1200,-16,120;1600,1200,32,100-;1920,1080,-16,120;1920,1080,32,85-;1920,1200,-16,100-;1920,1200,32,-;1920,1440,-16,85-;1920,1440,32,-;2048,1536,-16,70-;2048,1536,32,-"
"NV5ULTRA_Modes_Delta"="A 640,480,-16,140-240;640,480,32,140-170;800,600,-16,140-240;800,600,32,140-150;1024,768,-16,140-200;1152,864,-16,140-170;1280,768,-16,140-150;1280,960,-16,140-150;1280,1024,-16,140-150;S 1600,900,32,100-;1600,1024,-16,120;1600,1024,32,100-;1600,1200,-16,120;1600,1200,32,100-;1920,1080,-16,120;1920,1080,32,85-;1920,1200,-16,100-;1920,1200,32,72-;1920,1440,-16,85-;1920,1440,32,70-;2048,1536,-16,70-;2048,1536,32,-"
"NV10_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV10DDR_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV10GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV11_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV11DDR_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV11M_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV11GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"CRUSH11_Modes_Delta"="S 640,400,-,120;640,480,-,120;800,600,-,120;1024,768,-,120;1152,864,-,-;1280,768,-,-;1280,960,-,-;1280,1024,-,120;1600,900,-,120;1600,1024,-,-;1600,1200,-,120;1920,1080,-,-;1920,1200,-,120;1920,1440,-16,120;1920,1440,32,85-;2048,1536,-16,85-;2048,1536,32,70-"
"NV15_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV15DDR_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV15BR_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV15GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV20_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV20_1_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV20_2_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV20_3_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV17_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV17GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV25_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV25GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"Device Description"="NVIDIA GeForce2 MX/MX 400 (Microsoft Corporation)"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\nv\Device1]
"InstalledDisplayDrivers"=hex(7):6e,00,76,00,34,00,5f,00,64,00,69,00,73,00,70,\
00,00,00,00,00
"VgaCompatible"=dword:00000000
"CapabilityOverride"=dword:00000008
"Attach.ToDesktop"=dword:00000001
"DefaultSettings.BitsPerPel"=dword:00000010
"DefaultSettings.XResolution"=dword:00000320
"DefaultSettings.YResolution"=dword:00000258
"UseCompressedModeFormat"=dword:00000001
"NV4_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;1024,768,-,140-170;1152,864,-16,140-150;1152,864,32,140;S 1280,768,-,-;1280,960,-,-;1280,1024,32,120;1600,900,-16,100-;1600,900,32,85-;1600,1024,-16,100-;1600,1024,32,85-;1600,1200,-16,100-;1600,1200,32,85-;1920,1080,-16,100-;1920,1080,32,75-;1920,1200,-16,85-;1920,1200,32,70-;1920,1440,-,-;2048,1536,-,-"
"NV5_Modes_Delta"="A 640,480,-16,140-240;640,480,32,140-170;800,600,-16,140-240;800,600,32,140-150;1024,768,-16,140-200;1152,864,-16,140-170;1280,768,-16,140-150;1280,960,-16,140-150;1280,1024,-16,140-150;S 1600,900,32,100-;1600,1024,-16,120;1600,1024,32,100-;1600,1200,-16,120;1600,1200,32,100-;1920,1080,-16,120;1920,1080,32,85-;1920,1200,-16,100-;1920,1200,32,72-;1920,1440,-16,85-;1920,1440,32,70-;2048,1536,-16,70-;2048,1536,32,-"
"NV0A_Modes_Delta"="S 1600,900,-16,120;1600,900,32,100-;1600,1024,-16,120;1600,1024,32,100-;1600,1200,-16,120;1600,1200,32,100-;1920,1080,-16,120;1920,1080,32,85-;1920,1200,-16,100-;1920,1200,32,72-;1920,1440,-16,85-;1920,1440,32,70-;2048,1536,-16,70-;2048,1536,32,-"
"NVVANTA_Modes_Delta"="S 1280,768,-,-;1280,960,-,-;1280,1024,32,120;1600,900,-16,100-;1600,900,32,85-;1600,1024,-16,100-;1600,1024,32,85-;1600,1200,-16,100-;1600,1200,32,85-;1920,1080,-16,100-;1920,1080,32,70-;1920,1200,-16,85-;1920,1200,32,70-;1920,1440,-,-;2048,1536,-,-"
"NV5M64_Modes_Delta"="S 1600,900,-16,120;1600,900,32,100-;1600,1024,-16,120;1600,1024,32,100-;1600,1200,-16,120;1600,1200,32,100-;1920,1080,-16,120;1920,1080,32,85-;1920,1200,-16,100-;1920,1200,32,-;1920,1440,-16,85-;1920,1440,32,-;2048,1536,-16,70-;2048,1536,32,-"
"NV5ULTRA_Modes_Delta"="A 640,480,-16,140-240;640,480,32,140-170;800,600,-16,140-240;800,600,32,140-150;1024,768,-16,140-200;1152,864,-16,140-170;1280,768,-16,140-150;1280,960,-16,140-150;1280,1024,-16,140-150;S 1600,900,32,100-;1600,1024,-16,120;1600,1024,32,100-;1600,1200,-16,120;1600,1200,32,100-;1920,1080,-16,120;1920,1080,32,85-;1920,1200,-16,100-;1920,1200,32,72-;1920,1440,-16,85-;1920,1440,32,70-;2048,1536,-16,70-;2048,1536,32,-"
"NV10_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV10DDR_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV10GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV11_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV11DDR_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV11M_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV11GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"CRUSH11_Modes_Delta"="S 640,400,-,120;640,480,-,120;800,600,-,120;1024,768,-,120;1152,864,-,-;1280,768,-,-;1280,960,-,-;1280,1024,-,120;1600,900,-,120;1600,1024,-,-;1600,1200,-,120;1920,1080,-,-;1920,1200,-,120;1920,1440,-16,120;1920,1440,32,85-;2048,1536,-16,85-;2048,1536,32,70-"
"NV15_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV15DDR_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV15BR_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV15GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV20_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV20_1_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV20_2_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV20_3_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV17_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV17GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV25_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV25GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"Device Description"="NVIDIA GeForce2 MX/MX 400 (Microsoft Corporation)"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\nv\Device2]
"InstalledDisplayDrivers"=hex(7):6e,00,76,00,34,00,5f,00,64,00,69,00,73,00,70,\
00,00,00,00,00
"VgaCompatible"=dword:00000000
"CapabilityOverride"=dword:00000008
"Attach.ToDesktop"=dword:00000001
"DefaultSettings.BitsPerPel"=dword:00000010
"DefaultSettings.XResolution"=dword:00000320
"DefaultSettings.YResolution"=dword:00000258
"UseCompressedModeFormat"=dword:00000001
"NV4_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;1024,768,-,140-170;1152,864,-16,140-150;1152,864,32,140;S 1280,768,-,-;1280,960,-,-;1280,1024,32,120;1600,900,-16,100-;1600,900,32,85-;1600,1024,-16,100-;1600,1024,32,85-;1600,1200,-16,100-;1600,1200,32,85-;1920,1080,-16,100-;1920,1080,32,75-;1920,1200,-16,85-;1920,1200,32,70-;1920,1440,-,-;2048,1536,-,-"
"NV5_Modes_Delta"="A 640,480,-16,140-240;640,480,32,140-170;800,600,-16,140-240;800,600,32,140-150;1024,768,-16,140-200;1152,864,-16,140-170;1280,768,-16,140-150;1280,960,-16,140-150;1280,1024,-16,140-150;S 1600,900,32,100-;1600,1024,-16,120;1600,1024,32,100-;1600,1200,-16,120;1600,1200,32,100-;1920,1080,-16,120;1920,1080,32,85-;1920,1200,-16,100-;1920,1200,32,72-;1920,1440,-16,85-;1920,1440,32,70-;2048,1536,-16,70-;2048,1536,32,-"
"NV0A_Modes_Delta"="S 1600,900,-16,120;1600,900,32,100-;1600,1024,-16,120;1600,1024,32,100-;1600,1200,-16,120;1600,1200,32,100-;1920,1080,-16,120;1920,1080,32,85-;1920,1200,-16,100-;1920,1200,32,72-;1920,1440,-16,85-;1920,1440,32,70-;2048,1536,-16,70-;2048,1536,32,-"
"NVVANTA_Modes_Delta"="S 1280,768,-,-;1280,960,-,-;1280,1024,32,120;1600,900,-16,100-;1600,900,32,85-;1600,1024,-16,100-;1600,1024,32,85-;1600,1200,-16,100-;1600,1200,32,85-;1920,1080,-16,100-;1920,1080,32,70-;1920,1200,-16,85-;1920,1200,32,70-;1920,1440,-,-;2048,1536,-,-"
"NV5M64_Modes_Delta"="S 1600,900,-16,120;1600,900,32,100-;1600,1024,-16,120;1600,1024,32,100-;1600,1200,-16,120;1600,1200,32,100-;1920,1080,-16,120;1920,1080,32,85-;1920,1200,-16,100-;1920,1200,32,-;1920,1440,-16,85-;1920,1440,32,-;2048,1536,-16,70-;2048,1536,32,-"
"NV5ULTRA_Modes_Delta"="A 640,480,-16,140-240;640,480,32,140-170;800,600,-16,140-240;800,600,32,140-150;1024,768,-16,140-200;1152,864,-16,140-170;1280,768,-16,140-150;1280,960,-16,140-150;1280,1024,-16,140-150;S 1600,900,32,100-;1600,1024,-16,120;1600,1024,32,100-;1600,1200,-16,120;1600,1200,32,100-;1920,1080,-16,120;1920,1080,32,85-;1920,1200,-16,100-;1920,1200,32,72-;1920,1440,-16,85-;1920,1440,32,70-;2048,1536,-16,70-;2048,1536,32,-"
"NV10_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV10DDR_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV10GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV11_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV11DDR_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV11M_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV11GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"CRUSH11_Modes_Delta"="S 640,400,-,120;640,480,-,120;800,600,-,120;1024,768,-,120;1152,864,-,-;1280,768,-,-;1280,960,-,-;1280,1024,-,120;1600,900,-,120;1600,1024,-,-;1600,1200,-,120;1920,1080,-,-;1920,1200,-,120;1920,1440,-16,120;1920,1440,32,85-;2048,1536,-16,85-;2048,1536,32,70-"
"NV15_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV15DDR_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV15BR_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV15GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV20_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV20_1_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV20_2_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV20_3_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV17_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV17GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV25_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV25GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"Device Description"="NVIDIA GeForce2 MX/MX 400 (Microsoft Corporation)"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\nv\Device3]
"InstalledDisplayDrivers"=hex(7):6e,00,76,00,34,00,5f,00,64,00,69,00,73,00,70,\
00,00,00,00,00
"VgaCompatible"=dword:00000000
"CapabilityOverride"=dword:00000008
"Attach.ToDesktop"=dword:00000001
"DefaultSettings.BitsPerPel"=dword:00000010
"DefaultSettings.XResolution"=dword:00000320
"DefaultSettings.YResolution"=dword:00000258
"UseCompressedModeFormat"=dword:00000001
"NV4_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;1024,768,-,140-170;1152,864,-16,140-150;1152,864,32,140;S 1280,768,-,-;1280,960,-,-;1280,1024,32,120;1600,900,-16,100-;1600,900,32,85-;1600,1024,-16,100-;1600,1024,32,85-;1600,1200,-16,100-;1600,1200,32,85-;1920,1080,-16,100-;1920,1080,32,75-;1920,1200,-16,85-;1920,1200,32,70-;1920,1440,-,-;2048,1536,-,-"
"NV5_Modes_Delta"="A 640,480,-16,140-240;640,480,32,140-170;800,600,-16,140-240;800,600,32,140-150;1024,768,-16,140-200;1152,864,-16,140-170;1280,768,-16,140-150;1280,960,-16,140-150;1280,1024,-16,140-150;S 1600,900,32,100-;1600,1024,-16,120;1600,1024,32,100-;1600,1200,-16,120;1600,1200,32,100-;1920,1080,-16,120;1920,1080,32,85-;1920,1200,-16,100-;1920,1200,32,72-;1920,1440,-16,85-;1920,1440,32,70-;2048,1536,-16,70-;2048,1536,32,-"
"NV0A_Modes_Delta"="S 1600,900,-16,120;1600,900,32,100-;1600,1024,-16,120;1600,1024,32,100-;1600,1200,-16,120;1600,1200,32,100-;1920,1080,-16,120;1920,1080,32,85-;1920,1200,-16,100-;1920,1200,32,72-;1920,1440,-16,85-;1920,1440,32,70-;2048,1536,-16,70-;2048,1536,32,-"
"NVVANTA_Modes_Delta"="S 1280,768,-,-;1280,960,-,-;1280,1024,32,120;1600,900,-16,100-;1600,900,32,85-;1600,1024,-16,100-;1600,1024,32,85-;1600,1200,-16,100-;1600,1200,32,85-;1920,1080,-16,100-;1920,1080,32,70-;1920,1200,-16,85-;1920,1200,32,70-;1920,1440,-,-;2048,1536,-,-"
"NV5M64_Modes_Delta"="S 1600,900,-16,120;1600,900,32,100-;1600,1024,-16,120;1600,1024,32,100-;1600,1200,-16,120;1600,1200,32,100-;1920,1080,-16,120;1920,1080,32,85-;1920,1200,-16,100-;1920,1200,32,-;1920,1440,-16,85-;1920,1440,32,-;2048,1536,-16,70-;2048,1536,32,-"
"NV5ULTRA_Modes_Delta"="A 640,480,-16,140-240;640,480,32,140-170;800,600,-16,140-240;800,600,32,140-150;1024,768,-16,140-200;1152,864,-16,140-170;1280,768,-16,140-150;1280,960,-16,140-150;1280,1024,-16,140-150;S 1600,900,32,100-;1600,1024,-16,120;1600,1024,32,100-;1600,1200,-16,120;1600,1200,32,100-;1920,1080,-16,120;1920,1080,32,85-;1920,1200,-16,100-;1920,1200,32,72-;1920,1440,-16,85-;1920,1440,32,70-;2048,1536,-16,70-;2048,1536,32,-"
"NV10_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV10DDR_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV10GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV11_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV11DDR_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV11M_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV11GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"CRUSH11_Modes_Delta"="S 640,400,-,120;640,480,-,120;800,600,-,120;1024,768,-,120;1152,864,-,-;1280,768,-,-;1280,960,-,-;1280,1024,-,120;1600,900,-,120;1600,1024,-,-;1600,1200,-,120;1920,1080,-,-;1920,1200,-,120;1920,1440,-16,120;1920,1440,32,85-;2048,1536,-16,85-;2048,1536,32,70-"
"NV15_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV15DDR_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV15BR_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV15GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV20_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV20_1_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV20_2_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV20_3_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV17_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV17GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV25_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"NV25GL_Modes_Delta"="A 640,480,-,140-240;800,600,-,140-240;848,480,-,-240;1024,768,-16,140-240;1024,768,32,140-200;1152,864,-16,140-200;1152,864,32,140-170;1280,720,-16,-170;1280,720,32,-150;1280,768,-16,140-170;1280,768,32,140-150;1280,960,-16,140-170;1280,960,32,140-150;1280,1024,-16,140-170;1280,1024,32,140-150;1360,768,-16,-170;1360,768,32,-150;1600,900,-16,140-150;S 1600,1024,32,120;1600,1200,32,120;1920,1080,-16,120;1920,1080,32,100-;1920,1200,-16,120;1920,1200,32,100-;1920,1440,-16,100-;1920,1440,32,85-;2048,1536,-16,85"
"Device Description"="NVIDIA GeForce2 MX/MX 400 (Microsoft Corporation)"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\nv\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\nv\Video]
"Service"="nv"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\nv\Enum]
"0"="PCI\\VEN_10DE&DEV_0110&SUBSYS_00000000&REV_B2\\4&33b01bd3&0&0008"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NwlnkFlt]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,77,00,6c,00,6e,00,6b,00,66,\
00,6c,00,74,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="IPX Traffic Filter Driver"
"DependOnService"=hex(7):4e,00,77,00,6c,00,6e,00,6b,00,46,00,77,00,64,00,00,00,\
00,00
"DependOnGroup"=hex(7):00,00
"Description"="IPX Traffic Filter Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NwlnkFlt\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NwlnkFwd]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,77,00,6c,00,6e,00,6b,00,66,\
00,77,00,64,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="IPX Traffic Forwarder Driver"
"Description"="IPX Traffic Forwarder Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\NwlnkFwd\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Parport]
"ErrorControl"=dword:00000001
"Group"="Parallel arbitrator"
"Start"=dword:00000003
"Tag"=dword:00000001
"Type"=dword:00000001
"DisplayName"="Parallel port driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,70,00,61,00,72,00,70,00,6f,00,72,\
00,74,00,2e,00,73,00,79,00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Parport\Enum]
"0"="ACPI\\PNP0400\\3&13c0b0c5&0"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PartMgr]
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Start"=dword:00000000
"Tag"=dword:00000005
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PartMgr\Enum]
"0"="Root\\LEGACY_PARTMGR\\0000"
"Count"=dword:00000002
"NextInstance"=dword:00000002
"1"="IDE\\DiskMAXTOR_6L020J1__________________________AR1.0400\\3636313135333439323237382020202020202020"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ParVdm]
"DependOnGroup"=hex(7):50,00,61,00,72,00,61,00,6c,00,6c,00,65,00,6c,00,20,00,\
61,00,72,00,62,00,69,00,74,00,72,00,61,00,74,00,6f,00,72,00,00,00,00,00
"DependOnService"=hex(7):50,00,61,00,72,00,70,00,6f,00,72,00,74,00,00,00,00,00
"ErrorControl"=dword:00000000
"Group"="Extended base"
"Start"=dword:00000002
"Tag"=dword:00000002
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ParVdm\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ParVdm\Enum]
"0"="Root\\LEGACY_PARVDM\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PCI]
"ErrorControl"=dword:00000003
"Group"="Boot Bus Extender"
"Start"=dword:00000000
"Tag"=dword:00000002
"Type"=dword:00000001
"DisplayName"="PCI Bus Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,70,00,63,00,69,00,2e,00,73,00,79,\
00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PCI\Parameters]
"1045C621"=hex:04,00,00,00,00,00,00,00
"10950640"=hex:04,00,00,00,00,00,00,00
"80861230"=hex:04,00,00,00,00,00,00,00
"80867010"=hex:04,00,00,00,00,00,00,00
"104B0140"=hex:08,00,00,00,00,00,00,00
"11790603"=hex:08,00,00,00,00,00,00,00
"80867113"=hex:08,00,00,00,00,00,00,00
"497884C5"=hex:08,00,00,00,00,00,00,00
"11063040"=hex:08,00,00,00,00,00,00,00
"0E111000"=hex:10,00,00,00,00,00,00,00
"0E112000"=hex:10,00,00,00,00,00,00,00
"10390406"=hex:10,00,00,00,00,00,00,00
"80860482"=hex:00,40,00,00,00,00,00,00
"80860008"=hex:10,00,00,00,00,00,00,00
"10140002"=hex:10,00,00,00,00,00,00,00
"10800600"=hex:20,00,00,00,00,00,00,00
"10131100"=hex:40,00,00,00,00,00,00,00
"10B95219"=hex:80,00,00,00,00,00,00,00
"1C1C0001"=hex:00,01,00,00,00,00,00,00
"10970038"=hex:00,01,00,00,00,00,00,00
"100BD001"=hex:00,04,00,00,00,00,00,00
"808604A3"=hex:00,08,00,00,00,00,00,00
"10AA0000"=hex:00,08,00,00,00,00,00,00
"533388D1"=hex:00,00,00,00,01,00,00,00
"11790605"=hex:00,10,00,00,00,00,00,00
"10131110"=hex:00,20,00,00,00,00,00,00
"11800478"=hex:00,20,00,00,00,00,00,00
"11800475"=hex:00,20,00,00,00,00,00,00
"11800476"=hex:00,20,00,00,00,00,00,00
"10040101"=hex:00,40,00,00,00,00,00,00
"10421000"=hex:00,40,00,00,00,00,00,00
"104CAC12"=hex:00,00,01,00,00,00,00,00
"11800466"=hex:00,00,01,00,00,00,00,00
"10140095"=hex:00,00,04,00,00,00,00,00
"80862418"=hex:00,00,04,00,00,00,00,00
"80862428"=hex:00,00,04,00,00,00,00,00
"8086244E"=hex:00,00,04,00,00,00,00,00
"80862448"=hex:00,00,04,00,00,00,00,00
"8086122E"=hex:00,00,08,00,00,00,00,00
"80867000"=hex:00,00,08,00,00,00,00,00
"80867110"=hex:00,00,08,00,00,00,00,00
"80867600"=hex:00,00,08,00,00,00,00,00
"10024747"=hex:00,00,40,00,00,00,00,00
"10024754"=hex:00,00,00,00,01,00,00,00
"53338901"=hex:00,00,00,00,01,00,00,00
"101300D6"=hex:00,00,40,00,00,00,00,00
"104CAC15"=hex:00,00,40,00,00,00,00,00
"110B0004"=hex:00,00,40,00,00,00,00,00
"1000000F"=hex:00,00,40,00,00,00,00,00
"104CAC17"=hex:00,00,40,00,00,00,00,00
"10239397"=hex:00,00,40,00,00,00,00,00
"10024742"=hex:00,00,40,00,00,00,00,00
"10024744"=hex:00,00,40,00,00,00,00,00
"10024749"=hex:00,00,40,00,00,00,00,00
"10024750"=hex:00,00,40,00,00,00,00,00
"10024751"=hex:00,00,40,00,00,00,00,00
"10024755"=hex:00,00,40,00,00,00,00,00
"10024757"=hex:00,00,40,20,00,00,00,00
"10024759"=hex:00,00,40,20,00,00,00,00
"10024C42"=hex:00,00,40,00,00,00,00,00
"10024C44"=hex:00,00,40,00,00,00,00,00
"10024C47"=hex:00,00,40,00,00,00,00,00
"10024C49"=hex:00,00,40,00,00,00,00,00
"10024C50"=hex:00,00,40,00,00,00,00,00
"10024C51"=hex:00,00,40,00,00,00,00,00
"10025654"=hex:00,00,00,00,01,00,00,00
"10025655"=hex:00,00,40,00,00,00,00,00
"10025656"=hex:00,00,40,00,00,00,00,00
"121A0003"=hex:00,00,40,00,00,00,00,00
"1045C861107B9300"=hex:00,00,40,00,00,00,00,00
"1045C8611045C861"=hex:00,00,40,00,00,00,00,00
"80861231"=hex:00,00,00,01,00,00,00,00
"12730002"=hex:00,00,00,01,00,00,00,00
"1014007D"=hex:00,00,00,01,00,00,00,00
"12850100"=hex:00,00,00,01,00,00,00,00
"12176836"=hex:00,00,00,08,00,00,00,00
"12176832"=hex:00,00,00,08,00,00,00,00
"109107A0"=hex:00,00,00,20,00,00,00,00
"80867800"=hex:00,00,00,20,00,00,00,00
"10c88005"=hex:00,00,00,20,00,00,00,00
"10c88006"=hex:00,00,00,20,00,00,00,00
"10c80005"=hex:00,00,00,20,00,00,00,00
"10c80006"=hex:00,00,00,20,00,00,00,00
"102B1001"=hex:00,00,00,80,00,00,00,00
"10DD0100"=hex:00,00,00,20,00,00,00,00
"10950646"=hex:00,00,00,20,00,00,00,00
"10950670"=hex:00,00,00,20,00,00,00,00
"10950648"=hex:00,00,00,20,00,00,00,00
"10110026"=hex:00,00,00,20,00,00,00,00
"8086B154"=hex:00,00,00,20,00,00,00,00
"53338904"=hex:00,00,00,20,00,00,00,00
"11068598"=hex:00,00,00,20,00,00,00,00
"11068605"=hex:00,00,00,20,00,00,00,00
"11790609"=hex:00,00,00,40,00,00,00,00
"10140047"=hex:00,00,00,40,00,00,00,00
"102B051B"=hex:00,00,00,80,00,00,00,00
"102B0520"=hex:00,00,00,80,00,00,00,00
"102B0521"=hex:00,00,00,80,00,00,00,00
"102B1025"=hex:00,00,00,80,00,00,00,00
"102B0525"=hex:00,00,00,80,00,00,00,00
"80867121"=hex:00,00,00,80,00,00,00,00
"80867123"=hex:00,00,00,80,00,00,00,00
"80867125"=hex:00,00,00,80,00,00,00,00
"80861132"=hex:00,00,00,80,00,00,00,00
"90050050"=hex:00,00,00,80,00,00,00,00
"9005005F"=hex:00,00,00,80,00,00,00,00
"10024752"=hex:00,00,00,80,00,00,00,00
"1002474F"=hex:00,00,00,80,00,00,00,00
"1002474D"=hex:00,00,00,80,00,00,00,00
"10024753"=hex:00,00,00,80,00,00,00,00
"1002474C"=hex:00,00,00,80,00,00,00,00
"1002474E"=hex:00,00,00,80,00,00,00,00
"10024C4D"=hex:00,00,00,80,00,00,00,00
"10024C4E"=hex:00,00,00,80,00,00,00,00
"10024C52"=hex:00,00,00,80,00,00,00,00
"10024C53"=hex:00,00,00,80,00,00,00,00
"10239880"=hex:00,00,00,80,00,00,00,00
"10DE00A0"=hex:00,00,00,80,00,00,00,00
"10DE00A1"=hex:00,00,00,80,00,00,00,00
"10DE00A3"=hex:00,00,00,80,00,00,00,00
"10DE00B0"=hex:00,00,00,80,00,00,00,00
"10DE00B1"=hex:00,00,00,80,00,00,00,00
"10DE00B3"=hex:00,00,00,80,00,00,00,00
"10DE0100"=hex:00,00,00,80,00,00,00,00
"10DE0101"=hex:00,00,00,80,00,00,00,00
"10DE0102"=hex:00,00,00,80,00,00,00,00
"10DE0103"=hex:00,00,00,80,00,00,00,00
"10DE0120"=hex:00,00,00,80,00,00,00,00
"10DE0121"=hex:00,00,00,80,00,00,00,00
"10DE0122"=hex:00,00,00,80,00,00,00,00
"10DE0123"=hex:00,00,00,80,00,00,00,00
"10DE0150"=hex:00,00,00,80,00,00,00,00
"10DE0151"=hex:00,00,00,80,00,00,00,00
"10DE0152"=hex:00,00,00,80,00,00,00,00
"10DE0153"=hex:00,00,00,80,00,00,00,00
"10DE0200"=hex:00,00,00,80,00,00,00,00
"10DE0201"=hex:00,00,00,80,00,00,00,00
"10DE0202"=hex:00,00,00,80,00,00,00,00
"10DE0203"=hex:00,00,00,80,00,00,00,00
"12D20018"=hex:00,00,00,80,00,00,00,00
"12D20019"=hex:00,00,00,80,00,00,00,00
"10136003"=hex:00,00,00,80,00,00,00,00
"3D3D000A"=hex:00,00,00,80,00,00,00,00
"10024158"=hex:00,00,00,00,01,00,00,00
"10024354"=hex:00,00,00,00,01,00,00,00
"10024358"=hex:00,00,00,00,01,00,00,00
"10024554"=hex:00,00,00,00,01,00,00,00
"10024758"=hex:00,00,00,00,01,00,00,00
"10024C54"=hex:00,00,00,00,01,00,00,00
"53338810"=hex:00,00,00,00,01,00,00,00
"53338811"=hex:00,00,00,00,01,00,00,00
"53338812"=hex:00,00,00,00,01,00,00,00
"53338814"=hex:00,00,00,00,01,00,00,00
"53338880"=hex:00,00,00,00,01,00,00,00
"533388B0"=hex:00,00,00,00,01,00,00,00
"533388C0"=hex:00,00,00,00,01,00,00,00
"533388C1"=hex:00,00,00,00,01,00,00,00
"533388D0"=hex:00,00,00,00,01,00,00,00
"533388F0"=hex:00,00,00,00,01,00,00,00
"53338902"=hex:00,00,00,00,01,00,00,00
"0E11B109"=hex:00,00,00,00,02,00,00,00
"100C3202"=hex:00,8a,00,00,00,00,00,00
"10668002"=hex:00,00,30,00,00,00,00,00
"10660002"=hex:00,00,30,00,00,00,00,00
"10040102"=hex:00,40,00,02,00,00,00,00
"1045C814"=hex:00,00,40,20,00,00,00,00
"10024756"=hex:00,00,40,20,00,00,00,00
"1002475A"=hex:00,00,40,20,00,00,00,00
"1000000B"=hex:00,00,00,a0,00,00,00,00
"10DE0020"=hex:00,00,00,a0,00,00,00,00
"10DE0028"=hex:00,00,00,a0,00,00,00,00
"10DE0029"=hex:00,00,00,a0,00,00,00,00
"10DE002A"=hex:00,00,00,a0,00,00,00,00
"10DE002B"=hex:00,00,00,a0,00,00,00,00
"10DE002C"=hex:00,00,00,a0,00,00,00,00
"10DE002D"=hex:00,00,00,a0,00,00,00,00
"10DE002E"=hex:00,00,00,a0,00,00,00,00
"10DE002F"=hex:00,00,00,a0,00,00,00,00
"101300D6101880D6"=hex:00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PCI\Enum]
"0"="ACPI\\PNP0A03\\1"
"Count"=dword:00000003
"NextInstance"=dword:00000003
"1"="PCI\\VEN_8086&DEV_1A31&SUBSYS_00000000&REV_04\\3&13c0b0c5&0&08"
"2"="PCI\\VEN_8086&DEV_244E&SUBSYS_00000000&REV_05\\3&13c0b0c5&0&F0"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PCIDump]
"ErrorControl"=dword:00000000
"Group"="PCI Configuration"
"Start"=dword:00000001
"Tag"=dword:00000001
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PCIIde]
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Start"=dword:00000004
"Tag"=dword:00000003
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Pcmcia]
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Start"=dword:00000004
"Tag"=dword:00000001
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Pcmcia\Parameters]
"SoundsEnabled"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PDCOMP]
"ErrorControl"=dword:00000000
"Start"=dword:00000003
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PDFRAME]
"ErrorControl"=dword:00000000
"Start"=dword:00000003
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PDRELI]
"ErrorControl"=dword:00000000
"Start"=dword:00000003
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PDRFRAME]
"ErrorControl"=dword:00000000
"Start"=dword:00000003
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\perc2]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\perc2\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\perc2\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\perc2hib]
"ErrorControl"=dword:00000001
"Group"="Filter"
"Start"=dword:00000004
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PerfDisk]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PerfDisk\Performance]
"Close"="CloseDiskObject"
"Collect"="CollectDiskObjectData"
"Collect Timeout"=dword:000007d0
"Library"="perfdisk.dll"
"Object List"="234 236"
"Open"="OpenDiskObject"
"Open Timeout"=dword:00001388
"WbemAdapFileSignature"=hex:bf,3b,02,5d,03,c0,d1,21,66,65,63,bc,86,92,48,09
"WbemAdapFileTime"=hex:00,f8,da,ce,05,2c,c1,01
"WbemAdapFileSize"=dword:00005c00
"WbemAdapStatus"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PerfNet]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PerfNet\Performance]
"Close"="CloseNetSvcsObject"
"Collect"="CollectNetSvcsObjectData"
"Collect Timeout"=dword:00001388
"Library"="perfnet.dll"
"Object List"="52 262 330 1300"
"Open"="OpenNetSvcsObject"
"Open Timeout"=dword:00001f40
"WbemAdapFileSignature"=hex:63,6a,03,aa,52,09,fc,2e,84,16,a7,46,b1,98,61,55
"WbemAdapFileTime"=hex:00,f8,da,ce,05,2c,c1,01
"WbemAdapFileSize"=dword:00004200
"WbemAdapStatus"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PerfOS]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PerfOS\Performance]
"Close"="CloseOSObject"
"Collect"="CollectOSObjectData"
"Collect Timeout"=dword:000007d0
"Library"="perfos.dll"
"Object List"="2 4 86 238 260 700"
"Open"="OpenOSObject"
"Open Timeout"=dword:00001388
"WbemAdapFileSignature"=hex:e8,db,f3,4d,fe,60,63,c5,1e,4d,37,93,35,ce,2f,28
"WbemAdapFileTime"=hex:00,f8,da,ce,05,2c,c1,01
"WbemAdapFileSize"=dword:00005a00
"WbemAdapStatus"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PerfProc]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PerfProc\Performance]
"Close"="CloseSysProcessObject"
"Collect"="CollectSysProcessObjectData"
"Collect Timeout"=dword:00001f40
"Library"="perfproc.dll"
"Object List"="230 232 786 740 816 1408 1500 1548 1760"
"Open"="OpenSysProcessObject"
"Open Timeout"=dword:00002710
"WbemAdapFileSignature"=hex:a7,5a,98,c4,9b,94,d7,3d,25,77,29,0f,9a,2e,5f,a2
"WbemAdapFileTime"=hex:00,f8,da,ce,05,2c,c1,01
"WbemAdapFileSize"=dword:00007e00
"WbemAdapStatus"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PlugPlay]
"Description"="Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability."
"DisplayName"="Plug and Play"
"ErrorControl"=dword:00000001
"Group"="PlugPlay"
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,2e,00,65,00,78,00,65,00,00,00
"ObjectName"="LocalSystem"
"PlugPlayServiceType"=dword:00000003
"Start"=dword:00000002
"Type"=dword:00000020

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PlugPlay\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PolicyAgent]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6c,\
00,73,00,61,00,73,00,73,00,2e,00,65,00,78,00,65,00,00,00
"DisplayName"="IPSEC Services"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,54,00,63,00,70,00,\
69,00,70,00,00,00,49,00,50,00,53,00,65,00,63,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver."
"PolstoreDllRegisterVersion"=dword:00000002

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PolicyAgent\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PolicyAgent\Enum]
"0"="Root\\LEGACY_POLICYAGENT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PptpMiniport]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,61,00,73,00,70,00,70,00,74,\
00,70,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="WAN Miniport (PPTP)"
"Description"="WAN Miniport (PPTP)"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PptpMiniport\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\PptpMiniport\Enum]
"0"="Root\\MS_PPTPMINIPORT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Processor]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"Tag"=dword:00000003
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,70,00,72,00,6f,00,63,00,65,00,73,\
00,73,00,72,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Processor Driver"
"Group"="Extended Base"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Processor\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Processor\Enum]
"0"="ACPI\\GenuineIntel_-_x86_Family_15_Model_1\\_0"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ProtectedStorage]
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
"Description"="Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users."
"DisplayName"="Protected Storage"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6c,\
00,73,00,61,00,73,00,73,00,2e,00,65,00,78,00,65,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000002
"Type"=dword:00000120

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ProtectedStorage\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ProtectedStorage\Enum]
"0"="Root\\LEGACY_PROTECTEDSTORAGE\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Ptilink]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,70,00,74,00,69,00,6c,00,69,00,6e,\
00,6b,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Direct Parallel Link Driver"
"Description"="Direct Parallel Link Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Ptilink\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Ptilink\Enum]
"0"="Root\\MS_PTIMINIPORT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ql1080]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000003d
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ql1080\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ql1080\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Ql10wnt]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000023
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Ql10wnt\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Ql10wnt\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ql12160]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000003f
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ql12160\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ql12160\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ql1240]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000031
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ql1240\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ql1240\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ql1280]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000003f
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ql1280\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ql1280\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasAcd]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"Tag"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,61,00,73,00,61,00,63,00,64,\
00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Remote Access Auto Connection Driver"
"Group"="Streams Drivers"
"Description"="Remote Access Auto Connection Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasAcd\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasAcd\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasAcd\Enum]
"0"="Root\\LEGACY_RASACD\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasAuto]
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Remote Access Auto Connection Manager"
"DependOnService"=hex(7):52,00,61,00,73,00,4d,00,61,00,6e,00,00,00,54,00,61,00,\
70,00,69,00,73,00,72,00,76,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasAuto\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
72,00,61,00,73,00,61,00,75,00,74,00,6f,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasAuto\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Rasl2tp]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,61,00,73,00,6c,00,32,00,74,\
00,70,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="WAN Miniport (L2TP)"
"Description"="WAN Miniport (L2TP)"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Rasl2tp\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Rasl2tp\Enum]
"0"="Root\\MS_L2TPMINIPORT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasMan]
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Remote Access Connection Manager"
"DependOnService"=hex(7):54,00,61,00,70,00,69,00,73,00,72,00,76,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Creates a network connection."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasMan\Parameters]
"Medias"=hex(7):72,00,61,00,73,00,74,00,61,00,70,00,69,00,00,00,00,00
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
72,00,61,00,73,00,6d,00,61,00,6e,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"CustomDLL"=hex(7):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,\
20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,53,00,4e,00,5c,00,4d,00,53,\
00,4e,00,43,00,6f,00,72,00,65,00,46,00,69,00,6c,00,65,00,73,00,5c,00,63,00,\
75,00,73,00,74,00,64,00,69,00,61,00,6c,00,2e,00,64,00,6c,00,6c,00,00,00,00,\
00
"IpOutLowWatermark"=dword:00000001
"IpOutHighWatermark"=dword:00000005

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasMan\PPP]
"MaxConfigure"=dword:0000000a
"MaxFailure"=dword:0000000a
"MaxReject"=dword:00000005
"MaxTerminate"=dword:00000002
"Multilink"=dword:00000000
"NegotiateTime"=dword:00000096
"RestartTimer"=dword:00000003

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasMan\PPP\ControlProtocols]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasMan\PPP\ControlProtocols\BuiltIn]
"Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\
61,00,73,00,70,00,70,00,70,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasMan\PPP\ControlProtocols\Chap]
"Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\
61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasMan\PPP\EAP]
"Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\
61,00,73,00,70,00,70,00,70,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasMan\PPP\EAP\13]
"FriendlyName"="Smart Card or other Certificate"
"Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\
61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"ConfigUiPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"IdentityPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"InteractiveUIPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"InvokeUsernameDialog"=dword:00000000
"InvokePasswordDialog"=dword:00000000
"MPPEEncryptionSupported"=dword:00000001
"ConfigCLSID"="{58AB2366-D597-11d1-B90E-00C04FC9B263}"
"StandaloneSupported"=dword:00000000
"NoRootRevocationCheck"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasMan\PPP\EAP\25]
"FriendlyName"="Protected EAP (PEAP)"
"Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\
61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"ConfigUiPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"IdentityPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"InteractiveUIPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,72,00,61,00,73,00,74,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"InvokeUsernameDialog"=dword:00000000
"InvokePasswordDialog"=dword:00000000
"MPPEEncryptionSupported"=dword:00000001
"ConfigCLSID"="{58AB2366-D597-11d1-B90E-00C04FC9B263}"
"StandaloneSupported"=dword:00000001
"NoRootRevocationCheck"=dword:00000001
"RolesSupported"=dword:0000001a

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasMan\PPP\EAP\26]
"FriendlyName"="Secured password (EAP-MSCHAP v2)"
"Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\
61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,00
"ConfigUiPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
72,00,61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,00
"IdentityPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
72,00,61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,00
"InteractiveUIPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,72,00,61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,\
00
"InvokeUsernameDialog"=dword:00000000
"InvokePasswordDialog"=dword:00000000
"MPPEEncryptionSupported"=dword:00000001
"ConfigCLSID"="{2af6bcaa-f526-4803-aeb8-5777ce386647}"
"StandaloneSupported"=dword:00000001
"RolesSupported"=dword:00000004

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasMan\PPP\EAP\4]
"FriendlyName"="MD5-Challenge"
"Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\
61,00,73,00,63,00,68,00,61,00,70,00,2e,00,64,00,6c,00,6c,00,00,00
"InvokeUsernameDialog"=dword:00000001
"InvokePasswordDialog"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasMan\Security]
"Security"=hex:01,00,14,80,7c,00,00,00,88,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,4c,00,03,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,\
00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasMan\Enum]
"0"="Root\\LEGACY_RASMAN\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasPppoe]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,61,00,73,00,70,00,70,00,70,\
00,6f,00,65,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Remote Access PPPOE Driver"
"Description"="Remote Access PPPOE Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasPppoe\Linkage]
"Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,41,00,41,\
00,33,00,46,00,46,00,32,00,45,00,44,00,2d,00,38,00,46,00,31,00,44,00,2d,00,\
34,00,32,00,44,00,32,00,2d,00,42,00,32,00,36,00,43,00,2d,00,33,00,43,00,44,\
00,45,00,35,00,38,00,39,00,38,00,33,00,42,00,32,00,36,00,7d,00,00,00,5c,00,\
44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,46,00,45,00,43,00,43,00,42,\
00,31,00,41,00,46,00,2d,00,44,00,43,00,38,00,43,00,2d,00,34,00,41,00,45,00,\
37,00,2d,00,41,00,36,00,32,00,31,00,2d,00,44,00,42,00,43,00,30,00,43,00,42,\
00,42,00,31,00,35,00,38,00,41,00,42,00,7d,00,00,00,00,00
"Route"=hex(7):22,00,7b,00,41,00,41,00,33,00,46,00,46,00,32,00,45,00,44,00,2d,\
00,38,00,46,00,31,00,44,00,2d,00,34,00,32,00,44,00,32,00,2d,00,42,00,32,00,\
36,00,43,00,2d,00,33,00,43,00,44,00,45,00,35,00,38,00,39,00,38,00,33,00,42,\
00,32,00,36,00,7d,00,22,00,00,00,22,00,7b,00,46,00,45,00,43,00,43,00,42,00,\
31,00,41,00,46,00,2d,00,44,00,43,00,38,00,43,00,2d,00,34,00,41,00,45,00,37,\
00,2d,00,41,00,36,00,32,00,31,00,2d,00,44,00,42,00,43,00,30,00,43,00,42,00,\
42,00,31,00,35,00,38,00,41,00,42,00,7d,00,22,00,00,00,00,00
"Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,52,00,61,00,73,\
00,50,00,70,00,70,00,6f,00,65,00,5f,00,7b,00,41,00,41,00,33,00,46,00,46,00,\
32,00,45,00,44,00,2d,00,38,00,46,00,31,00,44,00,2d,00,34,00,32,00,44,00,32,\
00,2d,00,42,00,32,00,36,00,43,00,2d,00,33,00,43,00,44,00,45,00,35,00,38,00,\
39,00,38,00,33,00,42,00,32,00,36,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,\
00,63,00,65,00,5c,00,52,00,61,00,73,00,50,00,70,00,70,00,6f,00,65,00,5f,00,\
7b,00,46,00,45,00,43,00,43,00,42,00,31,00,41,00,46,00,2d,00,44,00,43,00,38,\
00,43,00,2d,00,34,00,41,00,45,00,37,00,2d,00,41,00,36,00,32,00,31,00,2d,00,\
44,00,42,00,43,00,30,00,43,00,42,00,42,00,31,00,35,00,38,00,41,00,42,00,7d,\
00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasPppoe\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RasPppoe\Enum]
"0"="Root\\MS_PPPOEMINIPORT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Raspti]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,61,00,73,00,70,00,74,00,69,\
00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Direct Parallel"
"Description"="Direct Parallel"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Raspti\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Raspti\Enum]
"0"="Root\\MS_PTIMINIPORT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RDPCDD]
"ErrorControl"=dword:00000000
"Group"="Video Save"
"ImagePath"="System32\\DRIVERS\\RDPCDD.sys"
"Start"=dword:00000001
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RDPCDD\Device0]
"Device Description"="RDPDD Chained DD"
"InstalledDisplayDrivers"=hex(7):52,00,44,00,50,00,44,00,44,00,00,00,00,00
"MirrorDriver"=dword:00000001
"VgaCompatible"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RDPCDD\Video]
"VideoID"="{DEB039CC-B704-4F53-B43E-9DD4432FA2E9}"
"Service"="RDPCDD"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RDPCDD\Enum]
"0"="Root\\LEGACY_RDPCDD\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RDPDD]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RDPDD\Device0]
"InstalledDisplayDrivers"=hex(7):52,00,44,00,50,00,44,00,44,00,00,00,00,00
"VgaCompatible"=dword:00000000
"Attach.RelativeX"=dword:00000000
"Attach.RelativeY"=dword:00000000
"Attach.ToDesktop"=dword:00000001
"DefaultSettings.XResolution"=dword:00000320
"DefaultSettings.YResolution"=dword:00000258

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\rdpdr]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,64,00,70,00,64,00,72,00,2e,\
00,73,00,79,00,73,00,00,00
"DisplayName"="Terminal Server Device Redirector Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\rdpdr\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\rdpdr\Enum]
"0"="Root\\RDPDR\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RDPNP]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RDPNP\NetworkProvider]
"DeviceName"="\\Device\\RdpDr"
"Name"="Microsoft Terminal Services"
"ProviderPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
64,00,72,00,70,00,72,00,6f,00,76,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RDPNP\Enum]
"0"="Root\\LEGACY_RDPNP\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RDPWD]
"ErrorControl"=dword:00000000
"Start"=dword:00000003
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RDSessMgr]
"Type"=dword:00000010
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\
5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,65,00,73,\
00,73,00,6d,00,67,00,72,00,2e,00,65,00,78,00,65,00,00,00
"DisplayName"="Remote Desktop Help Session Manager"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Manages and controls Remote Assistance. If this service is stopped, Remote Assistance will be unavailable. Before stopping this service, see the Dependencies tab of the Properties dialog box."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RDSessMgr\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\redbook]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"Tag"=dword:00000004
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,72,00,65,00,64,00,62,00,6f,00,6f,\
00,6b,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Digital CD Audio Playback Filter Driver"
"Group"="Pnp Filter"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\redbook\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\redbook\Enum]
"0"="IDE\\CdRomLG_CD-ROM_CRD-8521B_____________________2.00____\\5&3494138e&0&0.1.0"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess]
@=""
"Type"=dword:00000020
"Start"=dword:00000004
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Routing and Remote Access"
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,53,00,00,00,00,00
"DependOnGroup"=hex(7):4e,00,65,00,74,00,42,00,49,00,4f,00,53,00,47,00,72,00,\
6f,00,75,00,70,00,00,00,00,00
"ObjectName"="LocalSystem"
"Description"="Offers routing services to businesses in local area and wide area network environments."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Accounting]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Accounting\Providers]
"ActiveProvider"="{1AA7F846-C7F5-11D0-A376-00C04FC9DA04}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Accounting\Providers\{1AA7F840-C7F5-11D0-A376-00C04FC9DA04}]
"ConfigClsid"="{1AA7F840-C7F5-11D0-A376-00C04FC9DA04}"
"DisplayName"="RADIUS Accounting"
"Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\
61,00,73,00,72,00,61,00,64,00,2e,00,64,00,6c,00,6c,00,00,00
"ProviderTypeGUID"="{76560D80-2BFD-11d2-9539-3078302C2030}"
"VendorName"="Microsoft"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Accounting\Providers\{1AA7F846-C7F5-11D0-A376-00C04FC9DA04}]
"ConfigClsid"=""
"DisplayName"="Windows Accounting"
"Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,\
70,00,72,00,64,00,64,00,6d,00,2e,00,64,00,6c,00,6c,00,00,00
"ProviderTypeGUID"="{76560D81-2BFD-11d2-9539-3078302C2030}"
"VendorName"="Microsoft"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Authentication]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Authentication\Providers]
"ActiveProvider"="{1AA7F841-C7F5-11D0-A376-00C04FC9DA04}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Authentication\Providers\{1AA7F83F-C7F5-11D0-A376-00C04FC9DA04}]
"ConfigClsid"="{1AA7F83F-C7F5-11D0-A376-00C04FC9DA04}"
"DisplayName"="RADIUS Authentication"
"Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,00,\
61,00,73,00,72,00,61,00,64,00,2e,00,64,00,6c,00,6c,00,00,00
"VendorName"="Microsoft"
"ProviderTypeGUID"="{76560D00-2BFD-11d2-9539-3078302C2030}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Authentication\Providers\{1AA7F841-C7F5-11D0-A376-00C04FC9DA04}]
"ConfigClsid"=""
"DisplayName"="Windows Authentication"
"Path"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,\
70,00,72,00,64,00,64,00,6d,00,2e,00,64,00,6c,00,6c,00,00,00
"VendorName"="Microsoft"
"ProviderTypeGUID"="{76560D01-2BFD-11d2-9539-3078302C2030}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\DemandDialManager]
"DllPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,\
00,70,00,72,00,64,00,64,00,6d,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Interfaces]
"Stamp"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Interfaces\0]
"InterfaceName"="Loopback"
"Type"=dword:00000005
"Enabled"=dword:00000001
"Stamp"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Interfaces\0\Ip]
"ProtocolId"=dword:00000021
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\
00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Interfaces\1]
"InterfaceName"="Internal"
"Type"=dword:00000004
"Enabled"=dword:00000001
"Stamp"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Interfaces\1\Ip]
"ProtocolId"=dword:00000021
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\
00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Interfaces\2]
"InterfaceName"="{FECCB1AF-DC8C-4AE7-A621-DBC0CBB158AB}"
"Type"=dword:00000003
"Enabled"=dword:00000001
"Stamp"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Interfaces\2\Ip]
"ProtocolId"=dword:00000021
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\
00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Interfaces\3]
"InterfaceName"="{AA3FF2ED-8F1D-42D2-B26C-3CDE58983B26}"
"Type"=dword:00000003
"Enabled"=dword:00000001
"Stamp"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Interfaces\3\Ip]
"ProtocolId"=dword:00000021
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,38,00,00,\
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
07,00,ff,ff,10,00,00,00,01,00,00,00,48,00,00,00,00,00,00,00,01,00,00,00,00,\
00,00,00,58,02,c2,01,08,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Parameters]
"RouterType"=dword:00000001
"ServerFlags"=dword:00002702
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
6d,00,70,00,72,00,64,00,69,00,6d,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Parameters\AppleTalk]
"EnableIn"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Parameters\Ip]
"AllowClientIpAddresses"=dword:00000000
"AllowNetworkAccess"=dword:00000001
"EnableIn"=dword:00000001
"IpAddress"="0.0.0.0"
"IpMask"="0.0.0.0"
"UseDhcpAddressing"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Parameters\Ipx]
"EnableIn"=dword:00000001
"AcceptRemoteNodeNumber"=dword:00000001
"AllowNetworkAccess"=dword:00000001
"AutoWanNetAllocation"=dword:00000001
"FirstWanNet"=dword:00000000
"GlobalWanNet"=dword:00000001
"LastWanNet"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Parameters\Nbf]
"EnableIn"=dword:00000001
"AllowNetworkAccess"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Performance]
"Open"="OpenRasPerformanceData"
"Close"="CloseRasPerformanceData"
"Collect"="CollectRasPerformanceData"
"Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,\
00,61,00,73,00,63,00,74,00,72,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"Last Counter"=dword:00000804
"Last Help"=dword:00000805
"First Counter"=dword:000007de
"First Help"=dword:000007df
"WbemAdapFileSignature"=hex:b0,b0,d7,90,5a,c7,1b,c2,78,f1,7f,45,5e,18,26,11
"WbemAdapFileTime"=hex:00,f8,da,ce,05,2c,c1,01
"WbemAdapFileSize"=dword:00002e00
"WbemAdapStatus"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Policy]
"ProductDir"="C:\\WINDOWS\\System32\\IAS"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Policy\Pipeline]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Policy\Pipeline\01]
@="IAS.ProxyPolicyEnforcer"
"Requests"="0 1 2"
"Responses"="0 1 2 3 4"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Policy\Pipeline\02]
@="IAS.NTSamNames"
"Providers"="1"
"Requests"="0"
"Responses"="0 1 3"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Policy\Pipeline\03]
@="IAS.BaseCampHost"
"Requests"="0 1"
"Responses"="0 1 2 4"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Policy\Pipeline\04]
@="IAS.RadiusProxy"
"Providers"="2"
"Responses"="0"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Policy\Pipeline\05]
@="IAS.NTSamAuthentication"
"Providers"="1"
"Requests"="0"
"Responses"="0"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Policy\Pipeline\06]
@="IAS.AccountValidation"
"Providers"="1"
"Requests"="0"
"Responses"="0 1"
"Reasons"="33"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Policy\Pipeline\07]
@="IAS.PolicyEnforcer"
"Providers"="1"
"Requests"="0"
"Responses"="0 1 3"
"Reasons"="33"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Policy\Pipeline\08]
@="IAS.NTSamPerUser"
"Providers"="1"
"Requests"="0"
"Responses"="0 1 3"
"Reasons"="33"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Policy\Pipeline\09]
@="IAS.EAP"
"Providers"="1"
"Requests"="0 2"
"Responses"="0"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Policy\Pipeline\10]
@="IAS.URHandler"
"Providers"="0 1"
"Requests"="0 2"
"Responses"="0 1"
"Reasons"="33"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Policy\Pipeline\11]
@="IAS.ChangePassword"
"Providers"="1"
"Requests"="0"
"Responses"="0 1"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Policy\Pipeline\12]
@="IAS.AuthorizationHost"
"Requests"="0 1 2"
"Responses"="0 1 2 4"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Policy\Pipeline\13]
@="IAS.Accounting"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Policy\Pipeline\14]
@="IAS.MSChapErrorReporter"
"Providers"="0 1"
"Requests"="0"
"Responses"="2"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\RouterManagers]
"Stamp"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\RouterManagers\Ip]
"ProtocolId"=dword:00000021
"GlobalInfo"=hex:01,00,00,00,80,00,00,00,02,00,00,00,03,00,ff,ff,08,00,00,00,\
01,00,00,00,30,00,00,00,06,00,ff,ff,3c,00,00,00,01,00,00,00,38,00,00,00,00,\
00,00,00,00,00,00,00,01,00,00,00,07,00,00,00,02,00,00,00,01,00,00,00,03,00,\
00,00,0a,00,00,00,16,27,00,00,03,00,00,00,17,27,00,00,05,00,00,00,12,27,00,\
00,07,00,00,00,0d,00,00,00,6e,00,00,00,08,00,00,00,78,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"DLLPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,69,\
00,70,00,72,00,74,00,72,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteAccess\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteRegistry]
"Description"="Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start."
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"DisplayName"="Remote Registry"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\
00,65,00,00,00
"ObjectName"="NT AUTHORITY\\LocalService"
"Group"=""
"Start"=dword:00000002
"Type"=dword:00000020
"FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,e0,ad,08,\
00,01,00,00,00,e8,03,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteRegistry\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
72,00,65,00,67,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteRegistry\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RemoteRegistry\Enum]
"0"="Root\\LEGACY_REMOTEREGISTRY\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RpcSs]
"Description"="Provides the endpoint mapper and other miscellaneous RPC services."
"DisplayName"="Remote Procedure Call (RPC)"
"ErrorControl"=dword:00000001
"Group"="COM Infrastructure"
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,20,00,2d,00,6b,00,20,00,72,00,70,00,\
63,00,73,00,73,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000002
"Type"=dword:00000020
"FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,\
00,02,00,00,00,60,ea,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RpcSs\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
72,00,70,00,63,00,73,00,73,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RpcSs\Security]
"Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\
02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\
18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,\
00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RpcSs\Enum]
"0"="Root\\LEGACY_RPCSS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RSVP]
"Type"=dword:00000010
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,\
00,73,00,76,00,70,00,2e,00,65,00,78,00,65,00,00,00
"DisplayName"="QoS RSVP"
"DependOnService"=hex(7):54,00,63,00,70,00,49,00,70,00,00,00,41,00,66,00,64,00,\
00,00,52,00,70,00,63,00,53,00,73,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RSVP\Parameters]
"StartBlocker"=""
"Requests"=""
"Upcalls"=""

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RSVP\Performance]
"Open"="OpenRsvpPerformanceData"
"Close"="CloseRsvpPerformanceData"
"Collect"="CollectRsvpPerformanceData"
"Library"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,\
00,73,00,76,00,70,00,70,00,65,00,72,00,66,00,2e,00,64,00,6c,00,6c,00,00,00
"Last Counter"=dword:0000078e
"Last Help"=dword:0000078f
"First Counter"=dword:00000738
"First Help"=dword:00000739
"WbemAdapFileSignature"=hex:f9,dd,79,9e,07,ed,50,28,db,2f,1f,fe,a7,2c,93,57
"WbemAdapFileTime"=hex:00,f8,da,ce,05,2c,c1,01
"WbemAdapFileSize"=dword:00002600
"WbemAdapStatus"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\RSVP\Security]
"Security"=hex:01,00,14,80,7c,00,00,00,88,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,4c,00,03,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,\
00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\rtl8139]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"Tag"=dword:0000000a
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,52,00,54,00,4c,00,38,00,31,00,33,\
00,39,00,2e,00,53,00,59,00,53,00,00,00
"DisplayName"="Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver"
"Group"="NDIS"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\rtl8139\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\rtl8139\Enum]
"0"="PCI\\VEN_1186&DEV_1300&SUBSYS_13001186&REV_10\\4&3ab31f7f&0&28F0"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SamSs]
"Description"="Stores security information for local user accounts."
"DisplayName"="Security Accounts Manager"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6c,\
00,73,00,61,00,73,00,73,00,2e,00,65,00,78,00,65,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000002
"Type"=dword:00000020
"Group"="LocalValidation"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SamSs\Security]
"Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\
02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\
18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,\
00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SamSs\Enum]
"0"="Root\\LEGACY_SAMSS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SCardDrv]
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000000
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,53,\
00,43,00,61,00,72,00,64,00,53,00,76,00,72,00,2e,00,65,00,78,00,65,00,00,00
"Description"="Enables support for legacy non-plug and play smart-card readers used by this computer. If this service is stopped, this computer will not support legacy reader. If this service is disabled, any services that explicitly depend on it will fail to start."
"DisplayName"="Smart Card Helper"
"DependOnGroup"=hex(7):53,00,6d,00,61,00,72,00,74,00,20,00,43,00,61,00,72,00,\
64,00,20,00,52,00,65,00,61,00,64,00,65,00,72,00,00,00,00,00
"ObjectName"="NT AUTHORITY\\LocalService"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SCardDrv\Security]
"Security"=hex:01,00,14,80,ac,00,00,00,b8,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,7c,00,05,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,14,00,ff,01,0f,00,01,01,00,00,00,00,00,05,13,00,00,00,\
00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,\
00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,25,02,00,00,00,00,\
14,00,9d,01,02,00,01,01,00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,\
00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SCardSvr]
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000000
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,53,\
00,43,00,61,00,72,00,64,00,53,00,76,00,72,00,2e,00,65,00,78,00,65,00,00,00
"Description"="Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start."
"DisplayName"="Smart Card"
"DependOnService"=hex(7):50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,00,00,\
00,00
"ObjectName"="NT AUTHORITY\\LocalService"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SCardSvr\Security]
"Security"=hex:01,00,14,80,a4,00,00,00,b0,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,74,00,05,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,13,00,00,00,\
00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,\
00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,25,02,00,00,00,00,\
14,00,9d,01,02,00,01,01,00,00,00,00,00,02,00,00,00,00,01,01,00,00,00,00,00,\
05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Schedule]
"Description"="Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start."
"Type"=dword:00000120
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Task Scheduler"
"Group"="SchedulerGroup"
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"NextAtJobId"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Schedule\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
73,00,63,00,68,00,65,00,64,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\
00
"ServiceMain"="SchedServiceMain"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Schedule\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Schedule\Enum]
"0"="Root\\LEGACY_SCHEDULE\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Secdrv]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,65,00,63,00,64,00,72,00,76,\
00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Secdrv"
"Description"="SafeDisc driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Secdrv\Security]
"Security"=hex:01,00,14,80,78,00,00,00,84,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,48,00,03,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,\
05,04,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,\
01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\seclogon]
"Description"="Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start."
"DisplayName"="Secondary Logon"
"ErrorControl"=dword:00000000
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"Objectname"="LocalSystem"
"Start"=dword:00000002
"Type"=dword:00000120

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\seclogon\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
73,00,65,00,63,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,64,00,6c,00,6c,00,00,\
00
"ServiceMain"="SvcEntry_Seclogon"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\seclogon\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\seclogon\Enum]
"0"="Root\\LEGACY_SECLOGON\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SENS]
"DependOnService"=hex(7):45,00,76,00,65,00,6e,00,74,00,53,00,79,00,73,00,74,00,\
65,00,6d,00,00,00,00,00
"Description"="Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events."
"DisplayName"="System Event Notification"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"ObjectName"="LocalSystem"
"Group"="Network"
"Start"=dword:00000002
"Type"=dword:00000020

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SENS\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
73,00,65,00,6e,00,73,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SENS\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SENS\Enum]
"0"="Root\\LEGACY_SENS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\serenum]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"DisplayName"="Serenum Filter Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,65,00,72,00,65,00,6e,00,75,\
00,6d,00,2e,00,73,00,79,00,73,00,00,00
"Group"="PNP Filter"
"Tag"=dword:00000003

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\serenum\Enum]
"0"="ACPI\\PNP0501\\1"
"Count"=dword:00000002
"NextInstance"=dword:00000002
"1"="ACPI\\PNP0501\\2"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Serial]
"ErrorControl"=dword:00000000
"Group"="Extended base"
"Start"=dword:00000001
"Tag"=dword:00000001
"Type"=dword:00000001
"ForceFifoEnable"=dword:00000001
"RxFIFO"=dword:00000008
"TxFIFO"=dword:0000000e
"PermitShare"=dword:00000000
"LogFifo"=dword:00000000
"DisplayName"="Serial port driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,65,00,72,00,69,00,61,00,6c,\
00,2e,00,73,00,79,00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Serial\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Serial\Enum]
"0"="ACPI\\PNP0501\\1"
"Count"=dword:00000002
"NextInstance"=dword:00000002
"1"="ACPI\\PNP0501\\2"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Sfloppy]
"DependOnGroup"=hex(7):53,00,43,00,53,00,49,00,20,00,6d,00,69,00,6e,00,69,00,\
70,00,6f,00,72,00,74,00,00,00,00,00
"ErrorControl"=dword:00000000
"Group"="Primary disk"
"Start"=dword:00000001
"Tag"=dword:00000004
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Sfloppy\Enum]
"Count"=dword:00000000
"NextInstance"=dword:00000000
"INITSTARTFAILED"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SharedAccess]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS)"
"DependOnService"=hex(7):4e,00,65,00,74,00,6d,00,61,00,6e,00,00,00,4e,00,4c,00,\
41,00,00,00,52,00,61,00,73,00,4d,00,61,00,6e,00,00,00,41,00,4c,00,47,00,00,\
00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SharedAccess\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
69,00,70,00,6e,00,61,00,74,00,68,00,6c,00,70,00,2e,00,64,00,6c,00,6c,00,00,\
00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SharedAccess\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SharedAccess\Enum]
"0"="Root\\LEGACY_SHAREDACCESS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ShellHWDetection]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000000
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Shell Hardware Detection"
"Group"="ShellSvcGroup"
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ShellHWDetection\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
73,00,68,00,73,00,76,00,63,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"ServiceMain"="HardwareDetectionServiceMain"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ShellHWDetection\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ShellHWDetection\Enum]
"0"="Root\\LEGACY_SHELLHWDETECTION\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Simbad]
"ErrorControl"=dword:00000001
"Group"="Filter"
"Start"=dword:00000004
"Tag"=dword:00000001
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Sparrow]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:00000007
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Sparrow\Parameters]
"LegacyAdapterDetection"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Sparrow\Parameters\PnpInterface]
"1"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\splitter]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
72,00,69,00,76,00,65,00,72,00,73,00,5c,00,73,00,70,00,6c,00,69,00,74,00,74,\
00,65,00,72,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Microsoft Kernel Audio Splitter"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\splitter\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Spooler]
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"Description"="Loads files to memory for later printing."
"DisplayName"="Print Spooler"
"ErrorControl"=dword:00000001
"FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,e8,47,0c,\
00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,00,00,00,00
"Group"="SpoolerGroup"
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,70,00,6f,00,6f,00,6c,00,73,00,76,00,2e,00,65,00,78,00,65,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000002
"Type"=dword:00000110

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Spooler\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Spooler\Performance]
"Close"="PerfClose"
"Collect"="PerfCollect"
"Collect Timeout"=dword:000007d0
"Library"="winspool.drv"
"Object List"="1450"
"Open"="PerfOpen"
"Open Timeout"=dword:00000fa0
"WbemAdapFileSignature"=hex:12,6c,5c,67,9c,9d,52,12,37,ca,57,4b,78,a2,8d,55
"WbemAdapFileTime"=hex:00,96,8d,a3,48,4f,c2,01
"WbemAdapFileSize"=dword:00020400
"WbemAdapStatus"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Spooler\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Spooler\Enum]
"0"="Root\\LEGACY_SPOOLER\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sr]
"Type"=dword:00000002
"Start"=dword:00000000
"ErrorControl"=dword:00000001
"Tag"=dword:00000004
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,72,00,2e,00,73,00,79,00,73,\
00,00,00
"DisplayName"="System Restore Filter Driver"
"Group"="FSFilter System Recovery"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sr\Parameters]
"FirstRun"=dword:00000000
"DontBackup"=dword:00000000
"MachineGuid"="{5D2D1EEE-2B52-44BB-A132-C10906005E34}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sr\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sr\Enum]
"0"="Root\\LEGACY_SR\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\srescan]
"Type"=dword:00000001
"Start"=dword:00000000
"ErrorControl"=dword:00000000
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,5a,00,\
6f,00,6e,00,65,00,4c,00,61,00,62,00,73,00,5c,00,73,00,72,00,65,00,73,00,63,\
00,61,00,6e,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="srescan"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\srescan\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\srescan\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\srescan\Enum]
"0"="Root\\LEGACY_SRESCAN\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
"INITSTARTFAILED"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\srservice]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="System Restore Service"
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\srservice\Parameters]
"ServiceDll"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\
00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,72,00,\
73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\srservice\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\srservice\Enum]
"0"="Root\\LEGACY_SRSERVICE\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SSDPSRV]
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\
00,65,00,00,00
"DisplayName"="SSDP Discovery Service"
"ObjectName"="NT AUTHORITY\\LocalService"
"Description"="Enables discovery of UPnP devices on your home network."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SSDPSRV\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
73,00,73,00,64,00,70,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SSDPSRV\Security]
"Security"=hex:01,00,14,80,bc,00,00,00,c8,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,8c,00,06,00,00,00,00,00,14,00,ff,01,0f,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\
02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,25,02,\
00,00,00,00,14,00,9d,00,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,14,\
00,70,00,02,00,01,01,00,00,00,00,00,05,13,00,00,00,01,01,00,00,00,00,00,05,\
12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SSDPSRV\Enum]
"0"="Root\\LEGACY_SSDPSRV\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\stisvc]
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,69,00,6d,00,67,00,73,00,76,00,63,00,00,00
"DisplayName"="Windows Image Acquisition (WIA)"
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Provides image acquisition services for scanners and cameras."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\stisvc\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
77,00,69,00,61,00,73,00,65,00,72,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\
00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\stisvc\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\stisvc\Enum]
"0"="Root\\LEGACY_STISVC\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum]
"ErrorControl"=dword:00000001
"Start"=dword:00000003
"Type"=dword:00000001
"DisplayName"="Software Bus Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,77,00,65,00,6e,00,75,00,6d,\
00,2e,00,73,00,79,00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{2f412ab5-ed3a-4590-ab24-b0ce2aa77d3c}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{2f412ab5-ed3a-4590-ab24-b0ce2aa77d3c}\{9B365890-165F-11D0-A195-0020AFD156E4}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{2f412ab5-ed3a-4590-ab24-b0ce2aa77d3c}\{9B365890-165F-11D0-A195-0020AFD156E4}\{6994ad04-93ef-11d0-a3cc-00a0c9223196}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{2f412ab5-ed3a-4590-ab24-b0ce2aa77d3c}\{9B365890-165F-11D0-A195-0020AFD156E4}\{9ea331fa-b91b-45f8-9285-bd2bc77afcde}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{4245ff73-1db4-11d2-86e4-98ae20524153}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{4245ff73-1db4-11d2-86e4-98ae20524153}\{9B365890-165F-11D0-A195-0020AFD156E4}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{4245ff73-1db4-11d2-86e4-98ae20524153}\{9B365890-165F-11D0-A195-0020AFD156E4}\{2eb07ea0-7e70-11d0-a5d6-28db04c10000}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{4245ff73-1db4-11d2-86e4-98ae20524153}\{9B365890-165F-11D0-A195-0020AFD156E4}\{6994ad04-93ef-11d0-a3cc-00a0c9223196}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{4245ff73-1db4-11d2-86e4-98ae20524153}\{9B365890-165F-11D0-A195-0020AFD156E4}\{bf963d80-c559-11d0-8a2b-00a0c9255ac1}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{6c1b9f60-c0a9-11d0-96d8-00aa0051e51d}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{6c1b9f60-c0a9-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{6c1b9f60-c0a9-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\{2eb07ea0-7e70-11d0-a5d6-28db04c10000}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{6c1b9f60-c0a9-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\{6994ad04-93ef-11d0-a3cc-00a0c9223196}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{6c1b9f60-c0a9-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\{dff220f3-f70f-11d0-b917-00a0c9223196}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{8c07dd50-7a8d-11d2-8f8c-00c04fbf8fef}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{8c07dd50-7a8d-11d2-8f8c-00c04fbf8fef}\dmusic]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{8c07dd50-7a8d-11d2-8f8c-00c04fbf8fef}\dmusic\{2eb07ea0-7e70-11d0-a5d6-28db04c10000}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{8c07dd50-7a8d-11d2-8f8c-00c04fbf8fef}\dmusic\{6994ad04-93ef-11d0-a3cc-00a0c9223196}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{8c07dd50-7a8d-11d2-8f8c-00c04fbf8fef}\dmusic\{dff220f3-f70f-11d0-b917-00a0c9223196}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{96e080c7-143c-11d1-b40f-00a0c9223196}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{96e080c7-143c-11d1-b40f-00a0c9223196}\{3C0D501A-140B-11D1-B40F-00A0C9223196}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{96e080c7-143c-11d1-b40f-00a0c9223196}\{3C0D501A-140B-11D1-B40F-00A0C9223196}\{3c0d501a-140b-11d1-b40f-00a0c9223196}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{97ebaacc-95bd-11d0-a3ea-00a0c9223196}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{97ebaacc-95bd-11d0-a3ea-00a0c9223196}\{53172480-4791-11D0-A5D6-28DB04C10000}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{97ebaacc-95bd-11d0-a3ea-00a0c9223196}\{53172480-4791-11D0-A5D6-28DB04C10000}\{53172480-4791-11d0-a5d6-28db04c10000}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{a7c7a5b0-5af3-11d1-9ced-00a024bf0407}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{a7c7a5b0-5af3-11d1-9ced-00a024bf0407}\{9B365890-165F-11D0-A195-0020AFD156E4}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{a7c7a5b0-5af3-11d1-9ced-00a024bf0407}\{9B365890-165F-11D0-A195-0020AFD156E4}\{a7c7a5b1-5af3-11d1-9ced-00a024bf0407}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\{6994ad04-93ef-11d0-a3cc-00a0c9223196}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\{ad809c00-7b88-11d0-a5d6-28db04c10000}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{cd171de3-69e5-11d2-b56d-0000f8754380}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{cd171de3-69e5-11d2-b56d-0000f8754380}\{9B365890-165F-11D0-A195-0020AFD156E4}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{cd171de3-69e5-11d2-b56d-0000f8754380}\{9B365890-165F-11D0-A195-0020AFD156E4}\{3e227e76-690d-11d2-8161-0000f8775bf1}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{ddf4358e-bb2c-11d0-a42f-00a0c9223196}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{ddf4358e-bb2c-11d0-a42f-00a0c9223196}\{97EBAACB-95BD-11D0-A3EA-00A0C9223196}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{ddf4358e-bb2c-11d0-a42f-00a0c9223196}\{97EBAACB-95BD-11D0-A3EA-00A0C9223196}\{97ebaacb-95bd-11d0-a3ea-00a0c9223196}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{eeab7790-c514-11d1-b42b-00805fc1270e}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\{ad498944-762f-11d0-8dcb-00c04fc3358c}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{eec12db6-ad9c-4168-8658-b03daef417fe}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{eec12db6-ad9c-4168-8658-b03daef417fe}\{ABD61E00-9350-47e2-A632-4438B90C6641}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{eec12db6-ad9c-4168-8658-b03daef417fe}\{ABD61E00-9350-47e2-A632-4438B90C6641}\{2eb07ea0-7e70-11d0-a5d6-28db04c10000}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{eec12db6-ad9c-4168-8658-b03daef417fe}\{ABD61E00-9350-47e2-A632-4438B90C6641}\{6994ad04-93ef-11d0-a3cc-00a0c9223196}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Devices\{eec12db6-ad9c-4168-8658-b03daef417fe}\{ABD61E00-9350-47e2-A632-4438B90C6641}\{ffbb6e3f-ccfe-4d84-90d9-421418b03a8e}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swenum\Enum]
"0"="Root\\SYSTEM\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swmidi]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
72,00,69,00,76,00,65,00,72,00,73,00,5c,00,73,00,77,00,6d,00,69,00,64,00,69,\
00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Microsoft Kernel GS Wavetable Synthesizer"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\swmidi\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SwPrv]
"Type"=dword:00000010
"Start"=dword:00000003
"ErrorControl"=dword:00000000
"ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\
5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,6c,00,6c,\
00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2f,00,50,00,72,00,\
6f,00,63,00,65,00,73,00,73,00,69,00,64,00,3a,00,7b,00,37,00,41,00,33,00,30,\
00,33,00,37,00,39,00,36,00,2d,00,37,00,46,00,43,00,39,00,2d,00,34,00,41,00,\
36,00,41,00,2d,00,39,00,30,00,46,00,33,00,2d,00,41,00,36,00,33,00,30,00,32,\
00,43,00,43,00,33,00,38,00,41,00,46,00,42,00,7d,00,00,00
"DisplayName"="MS Software Shadow Copy Provider"
"DependOnService"=hex(7):72,00,70,00,63,00,73,00,73,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SwPrv\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\symc810]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000001a
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\symc810\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\symc810\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\symc8xx]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Type"=dword:00000001
"Tag"=dword:00000036

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\symc8xx\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\symc8xx\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sym_hi]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Type"=dword:00000001
"Tag"=dword:00000037

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sym_hi\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sym_hi\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sym_u3]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Type"=dword:00000001
"Tag"=dword:00000037

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sym_u3\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sym_u3\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sysaudio]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
72,00,69,00,76,00,65,00,72,00,73,00,5c,00,73,00,79,00,73,00,61,00,75,00,64,\
00,69,00,6f,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Microsoft Kernel System Audio Device"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sysaudio\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SysmonLog]
"Description"="Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start."
"DisplayName"="Performance Logs and Alerts"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,6d,00,6c,00,6f,00,67,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00
"ObjectName"="NT Authority\\NetworkService"
"Start"=dword:00000003
"Type"=dword:00000010
"DefaultLogFileFolder"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,44,00,\
72,00,69,00,76,00,65,00,25,00,5c,00,50,00,65,00,72,00,66,00,4c,00,6f,00,67,\
00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\SysmonLog\Log Queries]
"Defaults Installed"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TapiSrv]
"DependOnService"=hex(7):50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,00,00,\
52,00,70,00,63,00,53,00,73,00,00,00,00,00
"Description"="Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service."
"DisplayName"="Telephony"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000003
"Type"=dword:00000020

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TapiSrv\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
74,00,61,00,70,00,69,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TapiSrv\Performance]
"Close"="CloseTapiPerformanceData"
"Collect"="CollectTapiPerformanceData"
"Library"="tapiperf.dll"
"ObjectList"="1150"
"Open"="OpenTapiPerformanceData"
"WbemAdapFileSignature"=hex:69,51,b8,9b,4f,59,1a,a6,94,04,8a,6c,d0,e5,22,4a
"WbemAdapFileTime"=hex:00,f8,da,ce,05,2c,c1,01
"WbemAdapFileSize"=dword:00001600
"WbemAdapStatus"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TapiSrv\Security]
"Security"=hex:01,00,14,80,6c,00,00,00,78,00,00,00,14,00,00,00,34,00,00,00,02,\
00,20,00,01,00,00,00,02,80,18,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,20,02,00,00,02,00,38,00,02,00,00,00,00,03,18,00,ff,01,0f,00,01,02,00,\
00,00,00,00,05,20,00,00,00,20,02,00,00,00,03,18,00,9d,00,00,00,01,02,00,00,\
00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,\
01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TapiSrv\Enum]
"0"="Root\\LEGACY_TAPISRV\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"Tag"=dword:00000004
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,74,00,63,00,70,00,69,00,70,00,2e,\
00,73,00,79,00,73,00,00,00
"DisplayName"="TCP/IP Protocol Driver"
"Group"="PNP_TDI"
"DependOnService"=hex(7):49,00,50,00,53,00,65,00,63,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"Description"="TCP/IP Protocol Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Linkage]
"Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,41,00,41,\
00,33,00,46,00,46,00,32,00,45,00,44,00,2d,00,38,00,46,00,31,00,44,00,2d,00,\
34,00,32,00,44,00,32,00,2d,00,42,00,32,00,36,00,43,00,2d,00,33,00,43,00,44,\
00,45,00,35,00,38,00,39,00,38,00,33,00,42,00,32,00,36,00,7d,00,00,00,5c,00,\
44,00,65,00,76,00,69,00,63,00,65,00,5c,00,7b,00,46,00,45,00,43,00,43,00,42,\
00,31,00,41,00,46,00,2d,00,44,00,43,00,38,00,43,00,2d,00,34,00,41,00,45,00,\
37,00,2d,00,41,00,36,00,32,00,31,00,2d,00,44,00,42,00,43,00,30,00,43,00,42,\
00,42,00,31,00,35,00,38,00,41,00,42,00,7d,00,00,00,5c,00,44,00,65,00,76,00,\
69,00,63,00,65,00,5c,00,4e,00,64,00,69,00,73,00,57,00,61,00,6e,00,49,00,70,\
00,00,00,00,00
"Route"=hex(7):22,00,7b,00,41,00,41,00,33,00,46,00,46,00,32,00,45,00,44,00,2d,\
00,38,00,46,00,31,00,44,00,2d,00,34,00,32,00,44,00,32,00,2d,00,42,00,32,00,\
36,00,43,00,2d,00,33,00,43,00,44,00,45,00,35,00,38,00,39,00,38,00,33,00,42,\
00,32,00,36,00,7d,00,22,00,00,00,22,00,7b,00,46,00,45,00,43,00,43,00,42,00,\
31,00,41,00,46,00,2d,00,44,00,43,00,38,00,43,00,2d,00,34,00,41,00,45,00,37,\
00,2d,00,41,00,36,00,32,00,31,00,2d,00,44,00,42,00,43,00,30,00,43,00,42,00,\
42,00,31,00,35,00,38,00,41,00,42,00,7d,00,22,00,00,00,22,00,4e,00,64,00,69,\
00,73,00,57,00,61,00,6e,00,49,00,70,00,22,00,00,00,00,00
"Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,\
00,69,00,70,00,5f,00,7b,00,41,00,41,00,33,00,46,00,46,00,32,00,45,00,44,00,\
2d,00,38,00,46,00,31,00,44,00,2d,00,34,00,32,00,44,00,32,00,2d,00,42,00,32,\
00,36,00,43,00,2d,00,33,00,43,00,44,00,45,00,35,00,38,00,39,00,38,00,33,00,\
42,00,32,00,36,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,\
00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,46,00,45,00,43,00,43,00,42,00,\
31,00,41,00,46,00,2d,00,44,00,43,00,38,00,43,00,2d,00,34,00,41,00,45,00,37,\
00,2d,00,41,00,36,00,32,00,31,00,2d,00,44,00,42,00,43,00,30,00,43,00,42,00,\
42,00,31,00,35,00,38,00,41,00,42,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,\
00,63,00,65,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,33,00,36,00,\
36,00,37,00,41,00,42,00,45,00,31,00,2d,00,46,00,42,00,43,00,32,00,2d,00,34,\
00,33,00,39,00,44,00,2d,00,38,00,31,00,41,00,46,00,2d,00,33,00,42,00,36,00,\
42,00,39,00,39,00,38,00,38,00,36,00,34,00,45,00,37,00,7d,00,00,00,5c,00,44,\
00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,\
7b,00,45,00,36,00,45,00,41,00,43,00,41,00,31,00,44,00,2d,00,35,00,38,00,43,\
00,38,00,2d,00,34,00,34,00,44,00,42,00,2d,00,39,00,36,00,46,00,32,00,2d,00,\
42,00,35,00,36,00,33,00,39,00,44,00,33,00,32,00,32,00,38,00,42,00,34,00,7d,\
00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Parameters]
"NV Hostname"="pc11"
"DataBasePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
64,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,65,00,74,00,63,00,00,00
"NameServer"=""
"ForwardBroadcasts"=dword:00000000
"IPEnableRouter"=dword:00000000
"Domain"=""
"Hostname"="pc11"
"SearchList"=""
"UseDomainNameDevolution"=dword:00000000
"EnableICMPRedirect"=dword:00000001
"DeadGWDetectDefault"=dword:00000001
"DontAddDefaultGatewayDefault"=dword:00000000
"EnableSecurityFilters"=dword:00000000
"DhcpDomain"="gv.shawcable.net"
"DhcpNameServer"="64.59.160.13 64.59.160.15"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Parameters\Adapters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Parameters\Adapters\NdisWanIp]
"LLInterface"="WANARP"
"IpConfig"=hex(7):54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,\
6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,\
00,61,00,63,00,65,00,73,00,5c,00,7b,00,33,00,36,00,36,00,37,00,41,00,42,00,\
45,00,31,00,2d,00,46,00,42,00,43,00,32,00,2d,00,34,00,33,00,39,00,44,00,2d,\
00,38,00,31,00,41,00,46,00,2d,00,33,00,42,00,36,00,42,00,39,00,39,00,38,00,\
38,00,36,00,34,00,45,00,37,00,7d,00,00,00,54,00,63,00,70,00,69,00,70,00,5c,\
00,50,00,61,00,72,00,61,00,6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,49,00,\
6e,00,74,00,65,00,72,00,66,00,61,00,63,00,65,00,73,00,5c,00,7b,00,45,00,36,\
00,45,00,41,00,43,00,41,00,31,00,44,00,2d,00,35,00,38,00,43,00,38,00,2d,00,\
34,00,34,00,44,00,42,00,2d,00,39,00,36,00,46,00,32,00,2d,00,42,00,35,00,36,\
00,33,00,39,00,44,00,33,00,32,00,32,00,38,00,42,00,34,00,7d,00,00,00,00,00
"NumInterfaces"=dword:00000002
"IpInterfaces"=hex:e1,ab,67,36,c2,fb,9d,43,81,af,3b,6b,99,88,64,e7,1d,ca,ea,e6,\
c8,58,db,44,96,f2,b5,63,9d,32,28,b4

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Parameters\Adapters\{AA3FF2ED-8F1D-42D2-B26C-3CDE58983B26}]
"LLInterface"=""
"IpConfig"=hex(7):54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,\
6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,\
00,61,00,63,00,65,00,73,00,5c,00,7b,00,41,00,41,00,33,00,46,00,46,00,32,00,\
45,00,44,00,2d,00,38,00,46,00,31,00,44,00,2d,00,34,00,32,00,44,00,32,00,2d,\
00,42,00,32,00,36,00,43,00,2d,00,33,00,43,00,44,00,45,00,35,00,38,00,39,00,\
38,00,33,00,42,00,32,00,36,00,7d,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Parameters\Adapters\{FECCB1AF-DC8C-4AE7-A621-DBC0CBB158AB}]
"LLInterface"=""
"IpConfig"=hex(7):54,00,63,00,70,00,69,00,70,00,5c,00,50,00,61,00,72,00,61,00,\
6d,00,65,00,74,00,65,00,72,00,73,00,5c,00,49,00,6e,00,74,00,65,00,72,00,66,\
00,61,00,63,00,65,00,73,00,5c,00,7b,00,46,00,45,00,43,00,43,00,42,00,31,00,\
41,00,46,00,2d,00,44,00,43,00,38,00,43,00,2d,00,34,00,41,00,45,00,37,00,2d,\
00,41,00,36,00,32,00,31,00,2d,00,44,00,42,00,43,00,30,00,43,00,42,00,42,00,\
31,00,35,00,38,00,41,00,42,00,7d,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Parameters\DNSRegisteredAdapters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Parameters\Interfaces]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Parameters\Interfaces\{3667ABE1-FBC2-439D-81AF-3B6B998864E7}]
"UseZeroBroadcast"=dword:00000000
"EnableDHCP"=dword:00000000
"IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00
"SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00
"DefaultGateway"=hex(7):00,00
"EnableDeadGWDetect"=dword:00000001
"DontAddDefaultGateway"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Parameters\Interfaces\{AA3FF2ED-8F1D-42D2-B26C-3CDE58983B26}]
"UseZeroBroadcast"=dword:00000000
"EnableDeadGWDetect"=dword:00000001
"EnableDHCP"=dword:00000001
"IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00
"SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00
"DefaultGateway"=hex(7):00,00
"DefaultGatewayMetric"=hex(7):00,00
"NameServer"=""
"Domain"=""
"RegistrationEnabled"=dword:00000000
"RegisterAdapterName"=dword:00000000
"TCPAllowedPorts"=hex(7):30,00,00,00,00,00
"UDPAllowedPorts"=hex(7):30,00,00,00,00,00
"RawIPAllowedProtocols"=hex(7):30,00,00,00,00,00
"NTEContextList"=hex(7):30,00,78,00,30,00,30,00,30,00,30,00,30,00,30,00,30,00,\
33,00,00,00,00,00
"DhcpClassIdBin"=hex:
"DhcpServer"="192.168.1.1"
"Lease"=dword:00015180
"LeaseObtainedTime"=dword:4513f292
"T1"=dword:45149b52
"T2"=dword:451519e2
"LeaseTerminatesTime"=dword:45154412
"IPAutoconfigurationAddress"="0.0.0.0"
"IPAutoconfigurationMask"="255.255.0.0"
"IPAutoconfigurationSeed"=dword:00000000
"AddressType"=dword:00000000
"DhcpIPAddress"="192.168.1.103"
"DhcpSubnetMask"="255.255.255.0"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Parameters\Interfaces\{E6EACA1D-58C8-44DB-96F2-B5639D3228B4}]
"UseZeroBroadcast"=dword:00000000
"EnableDHCP"=dword:00000000
"IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00
"SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00
"DefaultGateway"=hex(7):00,00
"EnableDeadGWDetect"=dword:00000001
"DontAddDefaultGateway"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Parameters\Interfaces\{FECCB1AF-DC8C-4AE7-A621-DBC0CBB158AB}]
"UseZeroBroadcast"=dword:00000000
"EnableDeadGWDetect"=dword:00000001
"EnableDHCP"=dword:00000001
"IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00
"SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00
"DefaultGateway"=hex(7):00,00
"DefaultGatewayMetric"=hex(7):00,00
"NameServer"=""
"Domain"=""
"RegistrationEnabled"=dword:00000000
"RegisterAdapterName"=dword:00000000
"TCPAllowedPorts"=hex(7):30,00,00,00,00,00
"UDPAllowedPorts"=hex(7):30,00,00,00,00,00
"RawIPAllowedProtocols"=hex(7):30,00,00,00,00,00
"NTEContextList"=hex(7):30,00,78,00,30,00,30,00,30,00,30,00,30,00,30,00,30,00,\
32,00,00,00,00,00
"DhcpClassIdBin"=hex:
"DhcpServer"="192.168.1.1"
"Lease"=dword:00015180
"LeaseObtainedTime"=dword:45186fbf
"T1"=dword:4519187f
"T2"=dword:4519970f
"LeaseTerminatesTime"=dword:4519c13f
"IPAutoconfigurationAddress"="0.0.0.0"
"IPAutoconfigurationMask"="255.255.0.0"
"IPAutoconfigurationSeed"=dword:00000000
"AddressType"=dword:00000000
"DhcpIPAddress"="192.168.1.101"
"DhcpSubnetMask"="255.255.255.0"
"DhcpDomain"="gv.shawcable.net"
"DhcpNameServer"="64.59.160.13 64.59.160.15"
"DhcpDefaultGateway"=hex(7):31,00,39,00,32,00,2e,00,31,00,36,00,38,00,2e,00,31,\
00,2e,00,31,00,00,00,00,00
"DhcpSubnetMaskOpt"=hex(7):32,00,35,00,35,00,2e,00,32,00,35,00,35,00,2e,00,32,\
00,35,00,35,00,2e,00,30,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Parameters\PersistentRoutes]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Parameters\Winsock]
"UseDelayedAcceptance"=dword:00000000
"HelperDllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\
6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\
00,77,00,73,00,68,00,74,00,63,00,70,00,69,00,70,00,2e,00,64,00,6c,00,6c,00,\
00,00
"MaxSockAddrLength"=dword:00000010
"MinSockAddrLength"=dword:00000010
"Mapping"=hex:0b,00,00,00,03,00,00,00,02,00,00,00,01,00,00,00,06,00,00,00,02,\
00,00,00,01,00,00,00,00,00,00,00,02,00,00,00,00,00,00,00,06,00,00,00,00,00,\
00,00,00,00,00,00,06,00,00,00,00,00,00,00,01,00,00,00,06,00,00,00,02,00,00,\
00,02,00,00,00,11,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,02,00,00,00,\
00,00,00,00,11,00,00,00,00,00,00,00,00,00,00,00,11,00,00,00,00,00,00,00,02,\
00,00,00,11,00,00,00,02,00,00,00,03,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Performance]
"Close"="CloseTcpIpPerformanceData"
"Collect"="CollectTcpIpPerformanceData"
"Library"="Perfctrs.dll"
"Open"="OpenTcpIpPerformanceData"
"Object List"="502 510 546 582 638 658"
"WbemAdapFileSignature"=hex:97,2e,ff,c8,0d,9e,80,65,39,48,98,83,d3,70,32,f5
"WbemAdapFileTime"=hex:00,f8,da,ce,05,2c,c1,01
"WbemAdapFileSize"=dword:00009200
"WbemAdapStatus"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\ServiceProvider]
"Class"=dword:00000008
"DnsPriority"=dword:000007d0
"HostsPriority"=dword:000001f4
"LocalPriority"=dword:000001f3
"ProviderPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
77,00,73,00,6f,00,63,00,6b,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,00
"NetbtPriority"=dword:000007d1
"Name"="TCP/IP"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Tcpip\Enum]
"0"="Root\\LEGACY_TCPIP\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TDPIPE]
"ErrorControl"=dword:00000000
"Start"=dword:00000003
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TDTCP]
"ErrorControl"=dword:00000000
"Start"=dword:00000003
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TermDD]
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,74,00,65,00,72,00,6d,00,64,00,64,\
00,2e,00,73,00,79,00,73,00,00,00
"Start"=dword:00000001
"Type"=dword:00000001
"DisplayName"="Terminal Device Driver"
"PortDriverEnable"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TermDD\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TermDD\Enum]
"0"="Root\\RDP_KBD\\0000"
"Count"=dword:00000002
"NextInstance"=dword:00000002
"1"="Root\\RDP_MOU\\0000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TermService]
"ErrorControl"=dword:00000001
"ObjectName"="LocalSystem"
"Start"=dword:00000003
"Description"="Allows multiple users to be connected interactively to a machine as well as the display of desktops and applications to remote computers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server."
"DisplayName"="Terminal Services"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"Type"=dword:00000020
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TermService\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
74,00,65,00,72,00,6d,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"Certificate"=hex:01,00,00,00,01,00,00,00,01,00,00,00,06,00,5c,00,52,53,41,31,\
48,00,00,00,00,02,00,00,3f,00,00,00,01,00,01,00,fd,5c,ee,f5,80,40,42,4d,20,\
71,5f,e5,e3,2b,a3,b4,43,8f,3e,09,54,9f,d2,4b,f0,cf,c4,4b,82,6c,98,66,34,e5,\
50,6c,96,5e,9c,71,42,9a,32,8e,34,dc,32,fb,70,17,75,fa,e3,04,99,b5,81,22,d7,\
5b,92,d6,a6,ab,00,00,00,00,00,00,00,00,08,00,48,00,fd,a6,7b,9b,75,ec,29,b9,\
86,a5,a9,2d,15,e5,8b,46,b7,d4,eb,07,70,2c,26,f5,63,f9,6a,d8,7c,5d,26,58,f7,\
a9,fc,33,74,f4,c9,3c,6d,33,f1,97,df,f5,3e,57,c2,72,46,a2,63,c6,93,27,9d,c7,\
d0,ab,e5,b6,46,68,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TermService\Performance]
"Close"="CloseTSObject"
"Collect Timeout"=dword:000003e8
"Collect"="CollectTSObjectData"
"Open Timeout"=dword:000003e8
"Open"="OpenTSObject"
"Library"="perfts.dll"
"Last Counter"=dword:00000886
"Last Help"=dword:00000887
"First Counter"=dword:00000806
"First Help"=dword:00000807
"Object List"="2054 2176"
"Library Validation Code"=hex:00,f8,da,ce,05,2c,c1,01,00,30,00,00,00,00,00,00
"WbemAdapFileSignature"=hex:7e,fd,21,14,ea,d1,ac,72,34,26,10,d7,19,2b,fb,32
"WbemAdapFileTime"=hex:00,f8,da,ce,05,2c,c1,01
"WbemAdapFileSize"=dword:00003000
"WbemAdapStatus"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TermService\Enum]
"0"="Root\\LEGACY_TERMSERVICE\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Themes]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Themes"
"Group"="UIGroup"
"ObjectName"="LocalSystem"
"FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,74,00,65,\
00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,00,00,00,00
"Description"="Provides user experience theme management."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Themes\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
73,00,68,00,73,00,76,00,63,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"ServiceMain"="ThemeServiceMain"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Themes\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Themes\Enum]
"0"="Root\\LEGACY_THEMES\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TlntSvr]
"Type"=dword:00000010
"Start"=dword:00000004
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\
5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,74,00,6c,00,6e,\
00,74,00,73,00,76,00,72,00,2e,00,65,00,78,00,65,00,00,00
"DisplayName"="Telnet"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,54,00,43,00,50,00,\
49,00,50,00,00,00,4e,00,54,00,4c,00,4d,00,53,00,53,00,50,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"=hex(2):45,00,6e,00,61,00,62,00,6c,00,65,00,73,00,20,00,61,00,20,\
00,72,00,65,00,6d,00,6f,00,74,00,65,00,20,00,75,00,73,00,65,00,72,00,20,00,\
74,00,6f,00,20,00,6c,00,6f,00,67,00,20,00,6f,00,6e,00,20,00,74,00,6f,00,20,\
00,74,00,68,00,69,00,73,00,20,00,63,00,6f,00,6d,00,70,00,75,00,74,00,65,00,\
72,00,20,00,61,00,6e,00,64,00,20,00,72,00,75,00,6e,00,20,00,70,00,72,00,6f,\
00,67,00,72,00,61,00,6d,00,73,00,2c,00,20,00,61,00,6e,00,64,00,20,00,73,00,\
75,00,70,00,70,00,6f,00,72,00,74,00,73,00,20,00,76,00,61,00,72,00,69,00,6f,\
00,75,00,73,00,20,00,54,00,43,00,50,00,2f,00,49,00,50,00,20,00,54,00,65,00,\
6c,00,6e,00,65,00,74,00,20,00,63,00,6c,00,69,00,65,00,6e,00,74,00,73,00,2c,\
00,20,00,69,00,6e,00,63,00,6c,00,75,00,64,00,69,00,6e,00,67,00,20,00,55,00,\
4e,00,49,00,58,00,2d,00,62,00,61,00,73,00,65,00,64,00,20,00,61,00,6e,00,64,\
00,20,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,2d,00,62,00,61,00,73,00,\
65,00,64,00,20,00,63,00,6f,00,6d,00,70,00,75,00,74,00,65,00,72,00,73,00,2e,\
00,20,00,49,00,66,00,20,00,74,00,68,00,69,00,73,00,20,00,73,00,65,00,72,00,\
76,00,69,00,63,00,65,00,20,00,69,00,73,00,20,00,73,00,74,00,6f,00,70,00,70,\
00,65,00,64,00,2c,00,20,00,72,00,65,00,6d,00,6f,00,74,00,65,00,20,00,75,00,\
73,00,65,00,72,00,20,00,61,00,63,00,63,00,65,00,73,00,73,00,20,00,74,00,6f,\
00,20,00,70,00,72,00,6f,00,67,00,72,00,61,00,6d,00,73,00,20,00,6d,00,69,00,\
67,00,68,00,74,00,20,00,62,00,65,00,20,00,75,00,6e,00,61,00,76,00,61,00,69,\
00,6c,00,61,00,62,00,6c,00,65,00,2e,00,20,00,49,00,66,00,20,00,74,00,68,00,\
69,00,73,00,20,00,73,00,65,00,72,00,76,00,69,00,63,00,65,00,20,00,69,00,73,\
00,20,00,64,00,69,00,73,00,61,00,62,00,6c,00,65,00,64,00,2c,00,20,00,61,00,\
6e,00,79,00,20,00,73,00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,20,00,74,\
00,68,00,61,00,74,00,20,00,65,00,78,00,70,00,6c,00,69,00,63,00,69,00,74,00,\
6c,00,79,00,20,00,64,00,65,00,70,00,65,00,6e,00,64,00,20,00,6f,00,6e,00,20,\
00,69,00,74,00,20,00,77,00,69,00,6c,00,6c,00,20,00,66,00,61,00,69,00,6c,00,\
20,00,74,00,6f,00,20,00,73,00,74,00,61,00,72,00,74,00,2e,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TlntSvr\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TosIde]
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Start"=dword:00000004
"Tag"=dword:00000004
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TrkWks]
"Description"="Maintains links between NTFS files within a computer or across computers in a network domain."
"DisplayName"="Distributed Link Tracking Client"
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000002
"Type"=dword:00000020

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TrkWks\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
74,00,72,00,6b,00,77,00,6b,00,73,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TrkWks\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TrkWks\Enum]
"0"="Root\\LEGACY_TRKWKS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TSDDD]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\TSDDD\Device0]
"InstalledDisplayDrivers"=hex(7):54,00,53,00,44,00,44,00,44,00,00,00,00,00
"VgaCompatible"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Udfs]
"ErrorControl"=dword:00000001
"Group"="File system"
"Start"=dword:00000004
"Type"=dword:00000002

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ultra]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Tag"=dword:0000003b
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ultra\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ultra\Parameters\PnpInterface]
"5"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Update]
"ErrorControl"=dword:00000001
"Start"=dword:00000003
"Type"=dword:00000001
"DisplayName"="Microcode Update Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,75,00,70,00,64,00,61,00,74,00,65,\
00,2e,00,73,00,79,00,73,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Update\Devices]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Update\Enum]
"0"="Root\\SYSTEM\\0001"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\uploadmgr]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Upload Manager"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Manages synchronous and asynchronous file transfers between clients and servers on the network. If this service is stopped, synchronous and asynchronous file transfers between clients and servers on the network will not occur. If this service is disabled, any services that explicitly depend on it will fail to start."
"FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,74,00,65,\
00,01,00,00,00,64,00,00,00,01,00,00,00,64,00,00,00,00,00,00,00,64,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\uploadmgr\Parameters]
"ServiceDll"=hex(2):25,00,57,00,49,00,4e,00,44,00,49,00,52,00,25,00,5c,00,50,\
00,43,00,48,00,65,00,61,00,6c,00,74,00,68,00,5c,00,48,00,65,00,6c,00,70,00,\
43,00,74,00,72,00,5c,00,42,00,69,00,6e,00,61,00,72,00,69,00,65,00,73,00,5c,\
00,70,00,63,00,68,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\uploadmgr\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\uploadmgr\Enum]
"0"="Root\\LEGACY_UPLOADMGR\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\upnphost]
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\
00,65,00,00,00
"DisplayName"="Universal Plug and Play Device Host"
"DependOnService"=hex(7):53,00,53,00,44,00,50,00,53,00,52,00,56,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="NT AUTHORITY\\LocalService"
"Description"="Provides support to host Universal Plug and Play devices."
"FailureActions"=hex:ff,ff,ff,ff,00,00,00,00,00,00,00,00,01,00,00,00,02,00,03,\
00,01,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\upnphost\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
75,00,70,00,6e,00,70,00,68,00,6f,00,73,00,74,00,2e,00,64,00,6c,00,6c,00,00,\
00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\upnphost\Security]
"Security"=hex:01,00,14,80,bc,00,00,00,c8,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,8c,00,06,00,00,00,00,00,14,00,ff,01,0f,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\
02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,25,02,\
00,00,00,00,14,00,9d,00,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,14,\
00,8f,01,02,00,01,01,00,00,00,00,00,05,13,00,00,00,01,01,00,00,00,00,00,05,\
12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\UPS]
"Description"="Manages an uninterruptible power supply (UPS) connected to the computer."
"DisplayName"="Uninterruptible Power Supply"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,75,\
00,70,00,73,00,2e,00,65,00,78,00,65,00,00,00
"ObjectName"="NT AUTHORITY\\LocalService"
"Start"=dword:00000003
"Type"=dword:00000010

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\usbhub]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"DisplayName"="USB2 Enabled Hub"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,75,00,73,00,62,00,68,00,75,00,62,\
00,2e,00,73,00,79,00,73,00,00,00
"Group"="Base"
"Tag"=dword:00000010

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\usbhub\Enum]
"0"="USB\\ROOT_HUB\\4&9a3f73&0"
"Count"=dword:00000002
"NextInstance"=dword:00000002
"1"="USB\\ROOT_HUB\\4&21b6d192&0"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\usbuhci]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"DisplayName"="Microsoft USB Universal Host Controller Miniport Driver"
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,75,00,73,00,62,00,75,00,68,00,63,\
00,69,00,2e,00,73,00,79,00,73,00,00,00
"Group"="Base"
"Tag"=dword:0000000f

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\usbuhci\Enum]
"0"="PCI\\VEN_8086&DEV_2442&SUBSYS_24428086&REV_05\\3&13c0b0c5&0&FA"
"Count"=dword:00000002
"NextInstance"=dword:00000002
"1"="PCI\\VEN_8086&DEV_2444&SUBSYS_24428086&REV_05\\3&13c0b0c5&0&FC"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\VgaSave]
"ErrorControl"=dword:00000000
"Group"="Video Save"
"ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\
00,69,00,76,00,65,00,72,00,73,00,5c,00,76,00,67,00,61,00,2e,00,73,00,79,00,\
73,00,00,00
"Start"=dword:00000001
"Tag"=dword:00000001
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\VgaSave\Device0]
"InstalledDisplayDrivers"=hex(7):76,00,67,00,61,00,00,00,66,00,72,00,61,00,6d,\
00,65,00,62,00,75,00,66,00,00,00,76,00,67,00,61,00,32,00,35,00,36,00,00,00,\
76,00,67,00,61,00,36,00,34,00,6b,00,00,00,00,00
"VgaCompatible"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\VgaSave\Video]
"VideoID"="{23A77BF7-ED96-40EC-AF06-9B1F4867732A}"
"Service"="VgaSave"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\VgaSave\Enum]
"0"="Root\\LEGACY_VGASAVE\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\ViaIde]
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Start"=dword:00000004
"Tag"=dword:00000004
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\VolSnap]
"ErrorControl"=dword:00000001
"Group"="System Bus Extender"
"Start"=dword:00000000
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\VolSnap\Enum]
"0"="Root\\LEGACY_VOLSNAP\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\vsdatant]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,76,00,\
73,00,64,00,61,00,74,00,61,00,6e,00,74,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="vsdatant"
"Group"="PNP_TDI"
"DependOnService"=hex(7):54,00,43,00,50,00,49,00,50,00,00,00,00,00
"DependOnGroup"=hex(7):00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\vsdatant\Parameters]
"TdiEnable"=dword:00000003
"InstallDirDevice"="\\Device\\HarddiskVolume1\\Program Files\\Zone Labs\\ZoneAlarm"
"InstallDirDrive"="C:\\Program Files\\Zone Labs\\ZoneAlarm"
"DisableFireWire"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\vsdatant\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\vsdatant\Enum]
"0"="Root\\LEGACY_VSDATANT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\vsmon]
"Type"=dword:00000110
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\
5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,5a,00,4f,00,4e,\
00,45,00,4c,00,41,00,42,00,53,00,5c,00,76,00,73,00,6d,00,6f,00,6e,00,2e,00,\
65,00,78,00,65,00,20,00,2d,00,73,00,65,00,72,00,76,00,69,00,63,00,65,00,00,\
00
"DisplayName"="TrueVector Internet Monitor"
"Group"="TDI"
"DependOnService"=hex(7):41,00,66,00,64,00,00,00,52,00,70,00,63,00,53,00,73,00,\
00,00,76,00,73,00,64,00,61,00,74,00,61,00,6e,00,74,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Monitors internet traffic and generates alerts for disallowed access."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\vsmon\Security]
"Security"=hex:01,00,14,80,a4,00,00,00,b0,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,74,00,05,00,00,00,00,00,14,00,10,00,02,00,01,01,00,00,00,00,00,\
01,00,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,\
00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,\
00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,18,00,fd,01,\
02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,00,00,00,00,00,\
05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\vsmon\Enum]
"0"="Root\\LEGACY_VSMON\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\VSS]
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"Description"="Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start."
"DisplayName"="Volume Shadow Copy"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,76,\
00,73,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000003
"Type"=dword:00000010

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\VSS\Providers]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\VSS\Providers\{b5946137-7b9f-4925-af80-51abd60b20d5}]
@="MS Software Shadow Copy provider 1.0"
"Type"=dword:00000001
"Version"="1.0.0.7"
"VersionId"="{00000001-0000-0000-0007-000000000001}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\VSS\Providers\{b5946137-7b9f-4925-af80-51abd60b20d5}\CLSID]
@="{65EE1DBA-8FF4-4a58-AC1C-3470EE2F376A}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\VXD]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\VXD\JAVASUP]
"Start"=hex:00
"StaticVxD"="JAVASUP.VXD"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\W32Time]
"Description"="Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.

"
"DisplayName"="Windows Time"
"ErrorControl"=dword:00000001
"Group"=""
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"Objectname"="LocalSystem"
"Start"=dword:00000002
"Type"=dword:00000020

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\W32Time\Config]
"LastClockRate"=dword:0002625a
"MinClockRate"=dword:000260d4
"MaxClockRate"=dword:000263e0
"FrequencyCorrectRate"=dword:00000004
"PollAdjustFactor"=dword:00000005
"LargePhaseOffset"=dword:00138800
"SpikeWatchPeriod"=dword:0000005a
"HoldPeriod"=dword:00000005
"MaxPollInterval"=dword:0000000f
"LocalClockDispersion"=dword:0000000a
"EventLogFlags"=dword:00000002
"PhaseCorrectRate"=dword:00000001
"MinPollInterval"=dword:0000000a
"UpdateInterval"=dword:00057e40
"MaxNegPhaseCorrection"=dword:0000d2f0
"MaxPosPhaseCorrection"=dword:0000d2f0
"AnnounceFlags"=dword:0000000a
"MaxAllowedPhaseOffset"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\W32Time\Parameters]
"ServiceMain"="SvchostEntry_W32Time"
"ServiceDll"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\
00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,33,00,\
32,00,74,00,69,00,6d,00,65,00,2e,00,64,00,6c,00,6c,00,00,00
"NtpServer"="time.windows.com,0x1"
"Type"="NTP"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\W32Time\Security]
"Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\
02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\
18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,\
00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\W32Time\TimeProviders]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\W32Time\TimeProviders\NtpClient]
"Enabled"=dword:00000001
"InputProvider"=dword:00000001
"AllowNonstandardModeCombinations"=dword:00000001
"CrossSiteSyncFlags"=dword:00000002
"ResolvePeerBackoffMinutes"=dword:0000000f
"ResolvePeerBackoffMaxTimes"=dword:00000007
"CompatibilityFlags"=dword:80000000
"EventLogFlags"=dword:00000000
"DllName"="C:\\WINDOWS\\System32\\w32time.dll"
"SpecialPollTimeRemaining"=hex(7):74,00,69,00,6d,00,65,00,2e,00,77,00,69,00,6e,\
00,64,00,6f,00,77,00,73,00,2e,00,63,00,6f,00,6d,00,2c,00,37,00,61,00,31,00,\
39,00,63,00,63,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00
"SpecialPollInterval"=dword:00093a80

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\W32Time\TimeProviders\NtpServer]
"Enabled"=dword:00000001
"InputProvider"=dword:00000000
"AllowNonstandardModeCombinations"=dword:00000001
"DllName"="C:\\WINDOWS\\System32\\w32time.dll"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\W32Time\Enum]
"0"="Root\\LEGACY_W32TIME\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\W3SVC]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\W3SVC\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\W3SVC\Parameters\ADCLaunch]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\W3SVC\Parameters\ADCLaunch\AdvancedDataFactory]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\W3SVC\Parameters\ADCLaunch\RDSServer.DataFactory]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Wanarp]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,61,00,6e,00,61,00,72,00,70,\
00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Remote Access IP ARP Driver"
"Description"="Remote Access IP ARP Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Wanarp\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Wanarp\Enum]
"0"="Root\\LEGACY_WANARP\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WDICA]
"ErrorControl"=dword:00000000
"Start"=dword:00000003
"Type"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\wdmaud]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,\
72,00,69,00,76,00,65,00,72,00,73,00,5c,00,77,00,64,00,6d,00,61,00,75,00,64,\
00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Microsoft WINMM WDM Audio Compatibility Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\wdmaud\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WebClient]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\
00,65,00,00,00
"DisplayName"="WebClient"
"Group"="NetworkProvider"
"DependOnService"=hex(7):4d,00,52,00,78,00,44,00,41,00,56,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="NT AUTHORITY\\LocalService"
"Description"="Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WebClient\NetworkProvider]
"Name"="Web Client Network"
"ProviderPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
64,00,61,00,76,00,63,00,6c,00,6e,00,74,00,2e,00,64,00,6c,00,6c,00,00,00
"DeviceName"="\\Device\\WebDavRedirector"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WebClient\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
77,00,65,00,62,00,63,00,6c,00,6e,00,74,00,2e,00,64,00,6c,00,6c,00,00,00
"ServerNotFoundCacheLifeTimeInSec"=dword:0000003c
"AcceptOfficeAndTahoeServers"=dword:00000000
"ServiceDebug"=dword:00000000
"ClientDebug"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WebClient\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WebClient\Enum]
"0"="Root\\LEGACY_WEBCLIENT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\winmgmt]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000000
"ImagePath"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Windows Management Instrumentation"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,45,00,76,00,65,00,\
6e,00,74,00,6c,00,6f,00,67,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,02,00,00,00,65,00,6e,\
00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00
"Description"="Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\winmgmt\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
77,00,62,00,65,00,6d,00,5c,00,57,00,4d,00,49,00,73,00,76,00,63,00,2e,00,64,\
00,6c,00,6c,00,00,00
"ServiceMain"="ServiceMain"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\winmgmt\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\winmgmt\Enum]
"0"="Root\\LEGACY_WINMGMT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Winsock]
"ErrorControl"=dword:00000001
"Start"=dword:00000003
"Type"=dword:00000004

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Winsock\Parameters]
"Transports"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,4e,00,65,00,74,00,42,\
00,49,00,4f,00,53,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Winsock\Setup Migration]
"Setup Version"=dword:00001009
"Provider List"=hex(7):4e,00,65,00,74,00,42,00,49,00,4f,00,53,00,00,00,54,00,\
63,00,70,00,69,00,70,00,00,00,00,00
"Known Static Providers"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,4e,00,77,\
00,6c,00,6e,00,6b,00,49,00,70,00,78,00,00,00,4e,00,77,00,6c,00,6e,00,6b,00,\
53,00,70,00,78,00,00,00,41,00,70,00,70,00,6c,00,65,00,54,00,61,00,6c,00,6b,\
00,00,00,49,00,73,00,6f,00,54,00,70,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Winsock\Setup Migration\Providers]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Winsock\Setup Migration\Providers\NetBIOS]
"WinSock 1.1 Provider Data"=hex:0e,10,00,00,11,00,00,00,14,00,00,00,14,00,00,\
00,05,00,00,00,00,00,00,80,00,fa,00,00,0e,03,00,00,09,12,00,00,11,00,00,00,\
14,00,00,00,14,00,00,00,02,00,00,00,00,00,00,80,00,fa,00,00,98,02,00,00,0e,\
10,00,00,11,00,00,00,14,00,00,00,14,00,00,00,05,00,00,00,ff,ff,ff,ff,00,fa,\
00,00,22,02,00,00,09,12,00,00,11,00,00,00,14,00,00,00,14,00,00,00,02,00,00,\
00,ff,ff,ff,ff,00,fa,00,00,ac,01,00,00,0e,10,00,00,11,00,00,00,14,00,00,00,\
14,00,00,00,05,00,00,00,fe,ff,ff,ff,00,fa,00,00,36,01,00,00,09,12,00,00,11,\
00,00,00,14,00,00,00,14,00,00,00,02,00,00,00,fe,ff,ff,ff,00,fa,00,00,c0,00,\
00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,\
00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,45,00,36,00,45,00,\
41,00,43,00,41,00,31,00,44,00,2d,00,35,00,38,00,43,00,38,00,2d,00,34,00,34,\
00,44,00,42,00,2d,00,39,00,36,00,46,00,32,00,2d,00,42,00,35,00,36,00,33,00,\
39,00,44,00,33,00,32,00,32,00,38,00,42,00,34,00,7d,00,00,00,5c,00,44,00,65,\
00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,\
63,00,70,00,69,00,70,00,5f,00,7b,00,45,00,36,00,45,00,41,00,43,00,41,00,31,\
00,44,00,2d,00,35,00,38,00,43,00,38,00,2d,00,34,00,34,00,44,00,42,00,2d,00,\
39,00,36,00,46,00,32,00,2d,00,42,00,35,00,36,00,33,00,39,00,44,00,33,00,32,\
00,32,00,38,00,42,00,34,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,\
65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\
00,5f,00,7b,00,33,00,36,00,36,00,37,00,41,00,42,00,45,00,31,00,2d,00,46,00,\
42,00,43,00,32,00,2d,00,34,00,33,00,39,00,44,00,2d,00,38,00,31,00,41,00,46,\
00,2d,00,33,00,42,00,36,00,42,00,39,00,39,00,38,00,38,00,36,00,34,00,45,00,\
37,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,\
00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,33,00,\
36,00,36,00,37,00,41,00,42,00,45,00,31,00,2d,00,46,00,42,00,43,00,32,00,2d,\
00,34,00,33,00,39,00,44,00,2d,00,38,00,31,00,41,00,46,00,2d,00,33,00,42,00,\
36,00,42,00,39,00,39,00,38,00,38,00,36,00,34,00,45,00,37,00,7d,00,00,00,5c,\
00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,\
5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,46,00,45,00,43,00,43,00,42,\
00,31,00,41,00,46,00,2d,00,44,00,43,00,38,00,43,00,2d,00,34,00,41,00,45,00,\
37,00,2d,00,41,00,36,00,32,00,31,00,2d,00,44,00,42,00,43,00,30,00,43,00,42,\
00,42,00,31,00,35,00,38,00,41,00,42,00,7d,00,00,00,5c,00,44,00,65,00,76,00,\
69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,\
00,69,00,70,00,5f,00,7b,00,46,00,45,00,43,00,43,00,42,00,31,00,41,00,46,00,\
2d,00,44,00,43,00,38,00,43,00,2d,00,34,00,41,00,45,00,37,00,2d,00,41,00,36,\
00,32,00,31,00,2d,00,44,00,42,00,43,00,30,00,43,00,42,00,42,00,31,00,35,00,\
38,00,41,00,42,00,7d,00,00,00
"WinSock 2.0 Provider ID"=hex:30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,48,a1,92

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Winsock\Setup Migration\Providers\Tcpip]
"WinSock 2.0 Provider ID"=hex:a0,1a,0f,e7,8b,ab,cf,11,8c,a3,00,80,5f,48,a1,92

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Winsock\Setup Migration\Well Known Guids]
"IsoTp"=hex:b0,cb,e4,89,c1,b9,cf,11,95,c8,00,80,5f,48,a1,92
"McsXns"=hex:b1,cb,e4,89,c1,b9,cf,11,95,c8,00,80,5f,48,a1,92
"AppleTalk"=hex:a0,17,3b,2c,df,c6,cf,11,95,c8,00,80,5f,48,a1,92

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters]
"WinSock_Registry_Version"="2.0"
"Current_NameSpace_Catalog"="NameSpace_Catalog5"
"Current_Protocol_Catalog"="Protocol_Catalog9"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\NameSpace_Catalog5]
"Num_Catalog_Entries"=dword:00000003
"Serial_Access_Num"=dword:00000004

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001]
"LibraryPath"="%SystemRoot%\\System32\\mswsock.dll"
"DisplayString"="Tcpip"
"ProviderId"=hex:40,9d,05,22,9e,7e,cf,11,ae,5a,00,aa,00,a7,11,2b
"SupportedNameSpace"=dword:0000000c
"Enabled"=dword:00000001
"Version"=dword:00000000
"StoresServiceClassInfo"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002]
"LibraryPath"="%SystemRoot%\\System32\\winrnr.dll"
"DisplayString"="NTDS"
"ProviderId"=hex:ee,37,26,3b,80,e5,cf,11,a5,55,00,c0,4f,d8,d4,ac
"SupportedNameSpace"=dword:00000020
"Enabled"=dword:00000001
"Version"=dword:00000000
"StoresServiceClassInfo"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003]
"LibraryPath"="%SystemRoot%\\System32\\mswsock.dll"
"DisplayString"="Network Location Awareness (NLA) Namespace"
"ProviderId"=hex:3a,24,42,66,a8,3b,a6,4a,ba,a5,2e,0b,d7,1f,dd,83
"SupportedNameSpace"=dword:0000000f
"Enabled"=dword:00000001
"Version"=dword:00000000
"StoresServiceClassInfo"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\Protocol_Catalog9]
"Num_Catalog_Entries"=dword:0000000b
"Next_Catalog_Entry_ID"=dword:000003f4
"Serial_Access_Num"=dword:00000004

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001]
"PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,33,76,f8,d7,02,02,00,00,00,\
00,00,00,00,00,01,00,01,00,00,00,00,00,7f,57,00,00,40,0b,e5,02,b0,c2,33,76,\
00,00,00,00,3d,00,58,02,81,3d,00,00,00,00,00,00,01,00,00,00,00,00,00,00,10,\
08,d3,02,1c,0b,e5,02,fb,00,00,00,00,00,00,00,84,00,58,02,02,3d,00,00,00,00,\
00,00,b0,0b,e5,02,08,00,d3,02,8d,00,46,00,04,00,08,00,d0,86,81,02,78,01,1c,\
00,88,0b,e5,02,10,00,00,00,90,0b,e5,02,00,00,00,00,00,00,00,00,80,81,ef,c4,\
4a,4f,c2,01,00,00,00,00,00,00,00,00,1a,f6,1c,00,02,00,00,00,a0,0b,e5,02,00,\
00,00,00,00,00,00,00,01,00,00,00,18,08,d3,02,aa,bd,1d,00,00,00,00,00,61,90,\
55,27,12,fc,00,48,9a,71,d5,16,60,aa,32,6e,05,00,00,00,1c,00,00,00,7f,00,0e,\
00,04,01,0c,00,24,00,00,00,00,00,00,00,12,00,00,00,66,00,02,00,00,00,00,00,\
00,00,00,00,00,00,00,00,08,00,00,00,a0,1a,0f,e7,8b,ab,cf,11,8c,a3,00,80,5f,\
48,a1,92,e9,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,02,00,00,00,10,00,00,\
00,10,00,00,00,01,00,00,00,06,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,54,00,63,00,70,\
00,69,00,70,00,20,00,5b,00,54,00,43,00,50,00,2f,00,49,00,50,00,5d,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002]
"PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,33,76,f8,d7,02,02,00,00,00,\
00,00,00,00,00,01,00,01,00,00,00,00,00,7f,57,00,00,40,0b,e5,02,b0,c2,33,76,\
00,00,00,00,3d,00,58,02,81,3d,00,00,00,00,00,00,01,00,00,00,00,00,00,00,10,\
08,d3,02,1c,0b,e5,02,fb,00,00,00,00,00,00,00,84,00,58,02,02,3d,00,00,00,00,\
00,00,b0,0b,e5,02,08,00,d3,02,8d,00,46,00,04,00,08,00,d0,86,81,02,78,01,1c,\
00,88,0b,e5,02,10,00,00,00,90,0b,e5,02,00,00,00,00,00,00,00,00,80,81,ef,c4,\
4a,4f,c2,01,00,00,00,00,00,00,00,00,1a,f6,1c,00,02,00,00,00,a0,0b,e5,02,00,\
00,00,00,00,00,00,00,01,00,00,00,18,08,d3,02,aa,bd,1d,00,00,00,00,00,61,90,\
55,27,12,fc,00,48,9a,71,d5,16,60,aa,32,6e,05,00,00,00,1c,00,00,00,7f,00,0e,\
00,04,01,0c,00,24,00,00,00,00,00,00,00,12,00,00,00,09,06,02,00,00,00,00,00,\
00,00,00,00,00,00,00,00,08,00,00,00,a0,1a,0f,e7,8b,ab,cf,11,8c,a3,00,80,5f,\
48,a1,92,ea,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,02,00,00,00,10,00,00,\
00,10,00,00,00,02,00,00,00,11,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
bb,ff,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,54,00,63,00,70,\
00,69,00,70,00,20,00,5b,00,55,00,44,00,50,00,2f,00,49,00,50,00,5d,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003]
"PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,33,76,f8,d7,02,02,00,00,00,\
00,00,00,00,00,01,00,01,00,00,00,00,00,7f,57,00,00,40,0b,e5,02,b0,c2,33,76,\
00,00,00,00,3d,00,58,02,81,3d,00,00,00,00,00,00,01,00,00,00,00,00,00,00,10,\
08,d3,02,1c,0b,e5,02,fb,00,00,00,00,00,00,00,84,00,58,02,02,3d,00,00,00,00,\
00,00,b0,0b,e5,02,08,00,d3,02,8d,00,46,00,04,00,08,00,d0,86,81,02,78,01,1c,\
00,88,0b,e5,02,10,00,00,00,90,0b,e5,02,00,00,00,00,00,00,00,00,80,81,ef,c4,\
4a,4f,c2,01,00,00,00,00,00,00,00,00,1a,f6,1c,00,02,00,00,00,a0,0b,e5,02,00,\
00,00,00,00,00,00,00,01,00,00,00,18,08,d3,02,aa,bd,1d,00,00,00,00,00,61,90,\
55,27,12,fc,00,48,9a,71,d5,16,60,aa,32,6e,05,00,00,00,1c,00,00,00,7f,00,0e,\
00,04,01,0c,00,24,00,00,00,00,00,00,00,12,00,00,00,09,06,02,00,00,00,00,00,\
00,00,00,00,00,00,00,00,0c,00,00,00,a0,1a,0f,e7,8b,ab,cf,11,8c,a3,00,80,5f,\
48,a1,92,eb,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,02,00,00,00,10,00,00,\
00,10,00,00,00,03,00,00,00,00,00,00,00,ff,00,00,00,00,00,00,00,00,00,00,00,\
bb,ff,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,54,00,63,00,70,\
00,69,00,70,00,20,00,5b,00,52,00,41,00,57,00,2f,00,49,00,50,00,5d,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004]
"PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
6d,33,32,5c,72,73,76,70,73,70,2e,64,6c,6c,00,00,33,76,f8,d7,02,02,00,00,00,\
00,00,00,00,00,01,00,01,00,00,00,00,00,7f,57,00,00,40,0b,e5,02,b0,c2,33,76,\
00,00,00,00,3d,00,58,02,81,3d,00,00,00,00,00,00,01,00,00,00,00,00,00,00,10,\
08,d3,02,1c,0b,e5,02,fb,00,00,00,00,00,00,00,84,00,58,02,02,3d,00,00,00,00,\
00,00,b0,0b,e5,02,08,00,d3,02,8d,00,46,00,04,00,08,00,d0,86,81,02,78,01,1c,\
00,88,0b,e5,02,10,00,00,00,90,0b,e5,02,00,00,00,00,00,00,00,00,80,81,ef,c4,\
4a,4f,c2,01,00,00,00,00,00,00,00,00,1a,f6,1c,00,02,00,00,00,a0,0b,e5,02,00,\
00,00,00,00,00,00,00,01,00,00,00,18,08,d3,02,aa,bd,1d,00,00,00,00,00,61,90,\
55,27,12,fc,00,48,9a,71,d5,16,60,aa,32,6e,05,00,00,00,1c,00,00,00,7f,00,0e,\
00,04,01,0c,00,24,00,00,00,00,00,00,00,12,00,00,00,09,26,02,00,00,00,00,00,\
00,00,00,00,00,00,00,00,08,00,00,00,e0,a9,60,9d,7a,33,d0,11,bd,88,00,00,c0,\
82,e6,9a,ec,03,00,00,01,00,00,00,c4,f9,48,01,16,00,18,00,10,3c,5f,75,00,00,\
00,00,78,f8,48,01,3f,87,60,75,00,00,00,00,06,00,00,00,02,00,00,00,10,00,00,\
00,10,00,00,00,02,00,00,00,11,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
bb,ff,00,00,00,00,00,00,52,00,53,00,56,00,50,00,20,00,55,00,44,00,50,00,20,\
00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,20,00,50,00,72,00,6f,00,76,00,\
69,00,64,00,65,00,72,00,00,00,fc,fb,48,01,02,00,00,00,00,00,00,00,00,00,00,\
00,01,00,00,00,8c,24,f5,77,b2,17,f5,77,01,00,00,00,fc,fb,48,01,01,00,00,00,\
00,00,00,00,a4,f9,48,01,6b,11,f5,77,9a,11,f5,77,9f,11,f5,77,00,00,00,00,a4,\
f9,48,01,6b,11,f5,77,00,f9,48,01,b0,f9,48,01,6c,f9,48,01,5c,00,44,00,65,00,\
76,00,69,00,63,00,65,00,5c,00,7b,00,46,00,45,00,43,00,43,00,42,00,31,00,41,\
00,46,00,2d,00,44,00,43,00,38,00,43,00,2d,00,34,00,41,00,45,00,37,00,2d,00,\
41,00,36,00,32,00,31,00,2d,00,44,00,42,00,43,00,30,00,43,00,42,00,42,00,31,\
00,35,00,38,00,41,00,42,00,7d,00,00,00,43,00,30,00,43,00,42,00,42,00,31,00,\
35,00,38,00,41,00,42,00,7d,00,00,00,f5,77,0e,00,07,80,8c,41,9e,02,a0,58,2a,\
00,50,fc,48,01,00,01,00,00,02,00,07,80,c8,f9,48,01,34,88,60,75,18,0b,00,00,\
10,3c,5f,75,d0,f9,48,01,d4,f9,48,01,b6,58,f7,77,b9,17,dd,77,f8,0a,00,00,00,\
00,00,00,58,fc,48,01,59,18,dd,77,e0,f9,48,01,ef,50,61,75,00,00,00,00,a0,58,\
2a,00,00,00,00,00,dc,58,2a,00,90,9f,de,77,ff,ff,ff,ff,3b,19,dd,77,8c,24,f5,\
77,b2,17,f5,77,8c,24,f5,77,b2,17,f5,77,01,00,00,00,68,fd,48,01,04,00,00,00,\
70,fc,48,01,00,00,00,00,74,00,74,00,8c,24,f5,77,b2,17,f5,77,01,00,00,00,8c,\
24,f5,77,b2,17,f5,77,00,00,00,00,00,00,00,00,58,00,00,00,8c,24,f5,77,b2,17,\
f5,77,01,00,00,00,68,fd,48,01,01,00,00,00,73,96,61,75,00,00,00,00,dc,58,2a,\
00,b4,fc,48,01,53,00,59,00,e8,27,81,02,80,04,e7,02,5c,00,43,00,75,00,72,00,\
88,01,1c,00,88,04,e7,02,43,00,6f,00,6e,00,74,00,8c,24,f5,77

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005]
"PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
6d,33,32,5c,72,73,76,70,73,70,2e,64,6c,6c,00,00,33,76,f8,d7,02,02,00,00,00,\
00,00,00,00,00,01,00,01,00,00,00,00,00,7f,57,00,00,40,0b,e5,02,b0,c2,33,76,\
00,00,00,00,3d,00,58,02,81,3d,00,00,00,00,00,00,01,00,00,00,00,00,00,00,10,\
08,d3,02,1c,0b,e5,02,fb,00,00,00,00,00,00,00,84,00,58,02,02,3d,00,00,00,00,\
00,00,b0,0b,e5,02,08,00,d3,02,8d,00,46,00,04,00,08,00,d0,86,81,02,78,01,1c,\
00,88,0b,e5,02,10,00,00,00,90,0b,e5,02,00,00,00,00,00,00,00,00,80,81,ef,c4,\
4a,4f,c2,01,00,00,00,00,00,00,00,00,1a,f6,1c,00,02,00,00,00,a0,0b,e5,02,00,\
00,00,00,00,00,00,00,01,00,00,00,18,08,d3,02,aa,bd,1d,00,00,00,00,00,61,90,\
55,27,12,fc,00,48,9a,71,d5,16,60,aa,32,6e,05,00,00,00,1c,00,00,00,7f,00,0e,\
00,04,01,0c,00,24,00,00,00,00,00,00,00,12,00,00,00,66,20,02,00,00,00,00,00,\
00,00,00,00,00,00,00,00,08,00,00,00,e0,a9,60,9d,7a,33,d0,11,bd,88,00,00,c0,\
82,e6,9a,ed,03,00,00,01,00,00,00,6f,00,63,00,6b,00,64,00,6f,00,77,00,02,00,\
00,00,00,00,1c,00,78,04,e7,02,00,00,00,00,06,00,00,00,02,00,00,00,10,00,00,\
00,10,00,00,00,01,00,00,00,06,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,52,00,53,00,56,00,50,00,20,00,54,00,43,00,50,00,20,\
00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,20,00,50,00,72,00,6f,00,76,00,\
69,00,64,00,65,00,72,00,00,00,00,00,00,00,1b,e8,63,75,2c,e8,63,75,fc,fb,48,\
01,e8,27,81,02,80,04,e7,02,80,04,e7,02,b0,fb,48,01,88,01,1c,00,78,04,e7,02,\
00,00,00,00,00,00,00,00,00,00,b8,00,00,00,1c,00,70,44,8c,02,00,00,00,00,4c,\
fc,48,01,c9,1d,f5,77,00,00,1c,00,00,00,1c,00,d8,71,89,02,00,00,00,00,64,fc,\
48,01,c9,1d,f5,77,00,00,1c,00,c8,1e,f5,77,08,06,1c,00,6a,16,f5,77,00,00,00,\
00,e0,71,89,02,e0,71,89,02,68,fd,48,01,08,00,00,00,20,7c,82,02,b8,f3,81,02,\
a0,1e,87,02,f0,0f,f1,02,90,01,1c,00,88,01,1c,00,a8,1e,87,02,90,01,1c,00,00,\
00,00,00,10,00,00,00,08,00,00,00,d8,71,89,02,10,00,00,00,01,00,00,00,d8,01,\
1c,00,08,00,00,00,01,00,00,00,98,1e,87,02,e0,71,89,02,10,00,00,00,01,00,00,\
00,d8,01,1c,00,d8,71,89,02,00,00,00,00,00,00,00,00,00,00,b8,00,60,00,00,00,\
04,00,00,00,02,00,00,00,30,1c,87,02,50,fc,48,01,1c,1d,f5,77,02,00,00,00,98,\
1e,87,02,00,00,1c,00,30,1c,87,02,00,00,00,00,24,fd,48,01,c9,1d,f5,77,00,00,\
1c,00,c8,1e,f5,77,08,06,1c,00,6a,16,f5,77,00,9a,83,02,00,00,00,00,0c,44,b0,\
02,b4,65,f7,77,f4,fc,48,01,05,90,f7,77,a8,d5,f6,77,ff,ff,ff,ff,9f,11,f5,77,\
21,37,dd,77,00,00,00,00,00,00,00,00,00,00,00,00,18,0b,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,18,0b,00,00,04,fd,48,01,e3,37,\
dd,77,f0,03,1c,00,38,1c,87,02,80,00,00,00,09,00,00,00,f0,03,1c,00,30,1c,87,\
02,00,00,00,00,00,00,00,00,00,9a,83,02,00,00,00,00,0c,44,b0,02,9a,11,f5,77,\
9f,11,f5,77,00,9a,83,02,00,00,00,00,0c,44,b0,02,f4,fc,48,01

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006]
"PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,33,76,f8,d7,02,02,00,00,00,\
00,00,00,00,00,01,00,01,00,00,00,00,00,7f,57,00,00,40,0b,e5,02,b0,c2,33,76,\
00,00,00,00,3d,00,58,02,81,3d,00,00,00,00,00,00,01,00,00,00,00,00,00,00,10,\
08,d3,02,1c,0b,e5,02,fb,00,00,00,00,00,00,00,84,00,58,02,02,3d,00,00,00,00,\
00,00,b0,0b,e5,02,08,00,d3,02,8d,00,46,00,04,00,08,00,d0,86,81,02,78,01,1c,\
00,88,0b,e5,02,10,00,00,00,90,0b,e5,02,00,00,00,00,00,00,00,00,80,81,ef,c4,\
4a,4f,c2,01,00,00,00,00,00,00,00,00,1a,f6,1c,00,02,00,00,00,a0,0b,e5,02,00,\
00,00,00,00,00,00,00,01,00,00,00,18,08,d3,02,aa,bd,1d,00,00,00,00,00,61,90,\
55,27,12,fc,00,48,9a,71,d5,16,60,aa,32,6e,05,00,00,00,1c,00,00,00,7f,00,0e,\
00,04,01,0c,00,24,00,00,00,00,00,00,00,12,00,00,00,0e,00,02,00,00,00,00,00,\
00,00,00,00,00,00,00,00,08,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\
48,a1,92,ee,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\
00,14,00,00,00,05,00,00,00,00,00,00,80,00,00,00,00,00,00,00,00,00,00,00,00,\
00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\
00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\
65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\
00,5f,00,7b,00,46,00,45,00,43,00,43,00,42,00,31,00,41,00,46,00,2d,00,44,00,\
43,00,38,00,43,00,2d,00,34,00,41,00,45,00,37,00,2d,00,41,00,36,00,32,00,31,\
00,2d,00,44,00,42,00,43,00,30,00,43,00,42,00,42,00,31,00,35,00,38,00,41,00,\
42,00,7d,00,5d,00,20,00,53,00,45,00,51,00,50,00,41,00,43,00,4b,00,45,00,54,\
00,20,00,30,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007]
"PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,33,76,f8,d7,02,02,00,00,00,\
00,00,00,00,00,01,00,01,00,00,00,00,00,7f,57,00,00,40,0b,e5,02,b0,c2,33,76,\
00,00,00,00,3d,00,58,02,81,3d,00,00,00,00,00,00,01,00,00,00,00,00,00,00,10,\
08,d3,02,1c,0b,e5,02,fb,00,00,00,00,00,00,00,84,00,58,02,02,3d,00,00,00,00,\
00,00,b0,0b,e5,02,08,00,d3,02,8d,00,46,00,04,00,08,00,d0,86,81,02,78,01,1c,\
00,88,0b,e5,02,10,00,00,00,90,0b,e5,02,00,00,00,00,00,00,00,00,80,81,ef,c4,\
4a,4f,c2,01,00,00,00,00,00,00,00,00,1a,f6,1c,00,02,00,00,00,a0,0b,e5,02,00,\
00,00,00,00,00,00,00,01,00,00,00,18,08,d3,02,aa,bd,1d,00,00,00,00,00,61,90,\
55,27,12,fc,00,48,9a,71,d5,16,60,aa,32,6e,05,00,00,00,1c,00,00,00,7f,00,0e,\
00,04,01,0c,00,24,00,00,00,00,00,00,00,12,00,00,00,09,02,02,00,00,00,00,00,\
00,00,00,00,00,00,00,00,08,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\
48,a1,92,ef,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\
00,14,00,00,00,02,00,00,00,00,00,00,80,00,00,00,00,00,00,00,00,00,00,00,00,\
00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\
00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\
65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\
00,5f,00,7b,00,46,00,45,00,43,00,43,00,42,00,31,00,41,00,46,00,2d,00,44,00,\
43,00,38,00,43,00,2d,00,34,00,41,00,45,00,37,00,2d,00,41,00,36,00,32,00,31,\
00,2d,00,44,00,42,00,43,00,30,00,43,00,42,00,42,00,31,00,35,00,38,00,41,00,\
42,00,7d,00,5d,00,20,00,44,00,41,00,54,00,41,00,47,00,52,00,41,00,4d,00,20,\
00,30,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008]
"PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,33,76,f8,d7,02,02,00,00,00,\
00,00,00,00,00,01,00,01,00,00,00,00,00,7f,57,00,00,40,0b,e5,02,b0,c2,33,76,\
00,00,00,00,3d,00,58,02,81,3d,00,00,00,00,00,00,01,00,00,00,00,00,00,00,10,\
08,d3,02,1c,0b,e5,02,fb,00,00,00,00,00,00,00,84,00,58,02,02,3d,00,00,00,00,\
00,00,b0,0b,e5,02,08,00,d3,02,8d,00,46,00,04,00,08,00,d0,86,81,02,78,01,1c,\
00,88,0b,e5,02,10,00,00,00,90,0b,e5,02,00,00,00,00,00,00,00,00,80,81,ef,c4,\
4a,4f,c2,01,00,00,00,00,00,00,00,00,1a,f6,1c,00,02,00,00,00,a0,0b,e5,02,00,\
00,00,00,00,00,00,00,01,00,00,00,18,08,d3,02,aa,bd,1d,00,00,00,00,00,61,90,\
55,27,12,fc,00,48,9a,71,d5,16,60,aa,32,6e,05,00,00,00,1c,00,00,00,7f,00,0e,\
00,04,01,0c,00,24,00,00,00,00,00,00,00,12,00,00,00,0e,00,02,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\
48,a1,92,f0,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\
00,14,00,00,00,05,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\
00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\
00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\
65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\
00,5f,00,7b,00,33,00,36,00,36,00,37,00,41,00,42,00,45,00,31,00,2d,00,46,00,\
42,00,43,00,32,00,2d,00,34,00,33,00,39,00,44,00,2d,00,38,00,31,00,41,00,46,\
00,2d,00,33,00,42,00,36,00,42,00,39,00,39,00,38,00,38,00,36,00,34,00,45,00,\
37,00,7d,00,5d,00,20,00,53,00,45,00,51,00,50,00,41,00,43,00,4b,00,45,00,54,\
00,20,00,31,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009]
"PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,33,76,f8,d7,02,02,00,00,00,\
00,00,00,00,00,01,00,01,00,00,00,00,00,7f,57,00,00,40,0b,e5,02,b0,c2,33,76,\
00,00,00,00,3d,00,58,02,81,3d,00,00,00,00,00,00,01,00,00,00,00,00,00,00,10,\
08,d3,02,1c,0b,e5,02,fb,00,00,00,00,00,00,00,84,00,58,02,02,3d,00,00,00,00,\
00,00,b0,0b,e5,02,08,00,d3,02,8d,00,46,00,04,00,08,00,d0,86,81,02,78,01,1c,\
00,88,0b,e5,02,10,00,00,00,90,0b,e5,02,00,00,00,00,00,00,00,00,80,81,ef,c4,\
4a,4f,c2,01,00,00,00,00,00,00,00,00,1a,f6,1c,00,02,00,00,00,a0,0b,e5,02,00,\
00,00,00,00,00,00,00,01,00,00,00,18,08,d3,02,aa,bd,1d,00,00,00,00,00,61,90,\
55,27,12,fc,00,48,9a,71,d5,16,60,aa,32,6e,05,00,00,00,1c,00,00,00,7f,00,0e,\
00,04,01,0c,00,24,00,00,00,00,00,00,00,12,00,00,00,09,02,02,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\
48,a1,92,f1,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\
00,14,00,00,00,02,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\
00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\
00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\
65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\
00,5f,00,7b,00,33,00,36,00,36,00,37,00,41,00,42,00,45,00,31,00,2d,00,46,00,\
42,00,43,00,32,00,2d,00,34,00,33,00,39,00,44,00,2d,00,38,00,31,00,41,00,46,\
00,2d,00,33,00,42,00,36,00,42,00,39,00,39,00,38,00,38,00,36,00,34,00,45,00,\
37,00,7d,00,5d,00,20,00,44,00,41,00,54,00,41,00,47,00,52,00,41,00,4d,00,20,\
00,31,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010]
"PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,33,76,f8,d7,02,02,00,00,00,\
00,00,00,00,00,01,00,01,00,00,00,00,00,7f,57,00,00,40,0b,e5,02,b0,c2,33,76,\
00,00,00,00,3d,00,58,02,81,3d,00,00,00,00,00,00,01,00,00,00,00,00,00,00,10,\
08,d3,02,1c,0b,e5,02,fb,00,00,00,00,00,00,00,84,00,58,02,02,3d,00,00,00,00,\
00,00,b0,0b,e5,02,08,00,d3,02,8d,00,46,00,04,00,08,00,d0,86,81,02,78,01,1c,\
00,88,0b,e5,02,10,00,00,00,90,0b,e5,02,00,00,00,00,00,00,00,00,80,81,ef,c4,\
4a,4f,c2,01,00,00,00,00,00,00,00,00,1a,f6,1c,00,02,00,00,00,a0,0b,e5,02,00,\
00,00,00,00,00,00,00,01,00,00,00,18,08,d3,02,aa,bd,1d,00,00,00,00,00,61,90,\
55,27,12,fc,00,48,9a,71,d5,16,60,aa,32,6e,05,00,00,00,1c,00,00,00,7f,00,0e,\
00,04,01,0c,00,24,00,00,00,00,00,00,00,12,00,00,00,0e,00,02,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\
48,a1,92,f2,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\
00,14,00,00,00,05,00,00,00,fe,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\
00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\
00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\
65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\
00,5f,00,7b,00,45,00,36,00,45,00,41,00,43,00,41,00,31,00,44,00,2d,00,35,00,\
38,00,43,00,38,00,2d,00,34,00,34,00,44,00,42,00,2d,00,39,00,36,00,46,00,32,\
00,2d,00,42,00,35,00,36,00,33,00,39,00,44,00,33,00,32,00,32,00,38,00,42,00,\
34,00,7d,00,5d,00,20,00,53,00,45,00,51,00,50,00,41,00,43,00,4b,00,45,00,54,\
00,20,00,32,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011]
"PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,33,76,f8,d7,02,02,00,00,00,\
00,00,00,00,00,01,00,01,00,00,00,00,00,7f,57,00,00,40,0b,e5,02,b0,c2,33,76,\
00,00,00,00,3d,00,58,02,81,3d,00,00,00,00,00,00,01,00,00,00,00,00,00,00,10,\
08,d3,02,1c,0b,e5,02,fb,00,00,00,00,00,00,00,84,00,58,02,02,3d,00,00,00,00,\
00,00,b0,0b,e5,02,08,00,d3,02,8d,00,46,00,04,00,08,00,d0,86,81,02,78,01,1c,\
00,88,0b,e5,02,10,00,00,00,90,0b,e5,02,00,00,00,00,00,00,00,00,80,81,ef,c4,\
4a,4f,c2,01,00,00,00,00,00,00,00,00,1a,f6,1c,00,02,00,00,00,a0,0b,e5,02,00,\
00,00,00,00,00,00,00,01,00,00,00,18,08,d3,02,aa,bd,1d,00,00,00,00,00,61,90,\
55,27,12,fc,00,48,9a,71,d5,16,60,aa,32,6e,05,00,00,00,1c,00,00,00,7f,00,0e,\
00,04,01,0c,00,24,00,00,00,00,00,00,00,12,00,00,00,09,02,02,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\
48,a1,92,f3,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\
00,14,00,00,00,02,00,00,00,fe,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\
00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\
00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\
65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\
00,5f,00,7b,00,45,00,36,00,45,00,41,00,43,00,41,00,31,00,44,00,2d,00,35,00,\
38,00,43,00,38,00,2d,00,34,00,34,00,44,00,42,00,2d,00,39,00,36,00,46,00,32,\
00,2d,00,42,00,35,00,36,00,33,00,39,00,44,00,33,00,32,00,32,00,38,00,42,00,\
34,00,7d,00,5d,00,20,00,44,00,41,00,54,00,41,00,47,00,52,00,41,00,4d,00,20,\
00,32,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinTrust]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinTrust\SubjectPackages]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinTrust\SubjectPackages\MS Subjects 1]
"$DLL"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4d,00,\
73,00,53,00,69,00,70,00,31,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinTrust\SubjectPackages\MS Subjects 2]
"$DLL"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4d,00,\
73,00,53,00,69,00,70,00,32,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinTrust\SubjectPackages\MS Subjects 3]
"$DLL"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4d,00,\
73,00,53,00,69,00,70,00,33,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinTrust\TrustProviders]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WinTrust\TrustProviders\Software Publisher]
"$DLL"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,53,00,\
6f,00,66,00,74,00,50,00,75,00,62,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WmdmPmSp]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Portable Media Serial Number"
"ObjectName"="LocalSystem"
"Description"="Retrieves the serial number of any portable music player connected to your computer"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WmdmPmSp\Parameters]
"ServiceDll"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\
00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,73,00,\
70,00,6d,00,73,00,70,00,73,00,76,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WmdmPmSp\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WmdmPmSp\Enum]
"0"="Root\\LEGACY_WMDMPMSP\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Wmi]
"Description"="Provides systems management information to and from drivers."
"DisplayName"="Windows Management Instrumentation Driver Extensions"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000003
"Type"=dword:00000020

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Wmi\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
61,00,64,00,76,00,61,00,70,00,69,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,\
00
"ServiceMain"="WdmWmiServiceMain"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Wmi\Security]
"Security"=hex:01,00,14,80,b4,00,00,00,c0,00,00,00,14,00,00,00,34,00,00,00,02,\
00,20,00,01,00,00,00,02,80,18,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,20,02,00,00,02,00,80,00,05,00,00,00,00,03,18,00,8d,00,02,00,01,01,00,\
00,00,00,00,01,00,00,00,00,00,00,00,00,00,03,18,00,ff,01,0f,00,01,02,00,00,\
00,00,00,05,20,00,00,00,20,02,00,00,00,03,18,00,8f,00,02,00,01,02,00,00,00,\
00,00,05,20,00,00,00,23,02,00,00,00,03,18,00,9d,00,00,00,01,01,00,00,00,00,\
00,05,04,00,00,00,23,02,00,00,00,03,18,00,9d,00,00,00,01,02,00,00,00,00,00,\
05,20,00,00,00,21,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,\
00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WmiApRpl]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WmiApRpl\Performance]
"Library"="C:\\WINDOWS\\System32\\wbem\\wmiaprpl.dll"
"Open"="WmiOpenPerfData"
"Collect"="WmiCollectPerfData"
"Close"="WmiClosePerfData"
"Last Counter"=dword:000008ec
"Last Help"=dword:000008ed
"First Counter"=dword:000008e0
"First Help"=dword:000008e1
"Object List"="2272 2278"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WmiApSrv]
"Type"=dword:00000010
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\
5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,62,00,65,\
00,6d,00,5c,00,77,00,6d,00,69,00,61,00,70,00,73,00,72,00,76,00,2e,00,65,00,\
78,00,65,00,00,00
"DisplayName"="WMI Performance Adapter"
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Provides performance library information from WMI HiPerf providers."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WmiApSrv\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\wuauserv]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Automatic Updates"
"ObjectName"="LocalSystem"
"Description"="Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site."

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\wuauserv\Parameters]
"ServiceDll"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,\
00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,75,00,\
61,00,75,00,73,00,65,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\wuauserv\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\wuauserv\Enum]
"0"="Root\\LEGACY_WUAUSERV\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WZCSVC]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Wireless Zero Configuration"
"Group"="TDI"
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,4e,00,64,00,69,00,\
73,00,75,00,69,00,6f,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Provides automatic configuration for the 802.11 adapters"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WZCSVC\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
77,00,7a,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
"ServiceMain"="WZCSvcMain"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WZCSVC\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\WZCSVC\Enum]
"0"="Root\\LEGACY_WZCSVC\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\{AA3FF2ED-8F1D-42D2-B26C-3CDE58983B26}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\{AA3FF2ED-8F1D-42D2-B26C-3CDE58983B26}\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\{AA3FF2ED-8F1D-42D2-B26C-3CDE58983B26}\Parameters\Tcpip]
"EnableDHCP"=dword:00000001
"IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00
"SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00
"DefaultGateway"=hex(7):00,00
"DhcpIPAddress"="192.168.1.103"
"DhcpSubnetMask"="255.255.255.0"
"DhcpServer"="192.168.1.1"
"Lease"=dword:00015180
"LeaseObtainedTime"=dword:4513f292
"T1"=dword:45149b52
"T2"=dword:451519e2
"LeaseTerminatesTime"=dword:45154412

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\{FECCB1AF-DC8C-4AE7-A621-DBC0CBB158AB}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\{FECCB1AF-DC8C-4AE7-A621-DBC0CBB158AB}\Parameters]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\{FECCB1AF-DC8C-4AE7-A621-DBC0CBB158AB}\Parameters\Tcpip]
"EnableDHCP"=dword:00000001
"IPAddress"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00
"SubnetMask"=hex(7):30,00,2e,00,30,00,2e,00,30,00,2e,00,30,00,00,00,00,00
"DefaultGateway"=hex(7):00,00
"DhcpIPAddress"="192.168.1.101"
"DhcpSubnetMask"="255.255.255.0"
"DhcpServer"="192.168.1.1"
"Lease"=dword:00015180
"LeaseObtainedTime"=dword:45186fbf
"T1"=dword:4519187f
"T2"=dword:4519970f
"LeaseTerminatesTime"=dword:4519c13f
"DhcpDefaultGateway"=hex(7):31,00,39,00,32,00,2e,00,31,00,36,00,38,00,2e,00,31,\
00,2e,00,31,00,00,00,00,00
"DhcpSubnetMaskOpt"=hex(7):32,00,35,00,35,00,2e,00,32,00,35,00,35,00,2e,00,32,\
00,35,00,35,00,2e,00,30,00,00,00,00,00

" An In justice ANYWHERE is a threat to justice EVERYWHERE "



( Rev. Martin Luther King Jr. ..)



echoed by the late great lawyer (whether u agree with certain verdicts is not important).........

Jonnie Cochran Jr.

may they both .....RIP
Posted 5/24/2017 2:39 AM
#124541
User avatar

aclp24 Member

Date Joined May 2017
Total Posts: 1
ive been fighting thr prick for loner than you i lost once already when thr=e finnally srnt all my info somwher ovedr a email in arabic.i had to wipe my lasptopand reinstall win 10 but it was still in therte somewher but tyhey mainlly use mine for downloading a ton of shit my laptop it tells me my modem moved to a connection speec not  supporteed by my com driver.somtime when i turnb it on there a bunch of new screen savers ,and it takes over all of the administrative orders so i cant do shit.and removed all of my diagnostic drivers its just fn alfue and it like there another systen running behind mine ab =-ndeverthing i do ius shawdowed .all i can say is start from scratch oe enen get a new conputer\





 
  • Unread posts or replies
  • No unread posts or replies
  • Unread Posts (Read Only Forum)
  • No Unread Posts (Read Only Forum)

Forum Information

Currently it is Sunday, November 17, 2019, 5:24 AM (GMT +1)
There are a total of 61,741 posts in 13,621 threads.
In the last 3 days there were 0 new threads and 3 reply posts.

Who's online

This forum has 38,538 registered members. Please welcome our newest member, BrianE.
There are currently no users on-line.
We use cookies to ensure that we give you the best experience on our website. By continuing to browse, we are assuming that you have no objection in accepting cookies. You can change your cookie settings at any time.