الجهاز يستخدم نصف سرعة النت فقط

الحالة
مغلق و غير مفتوح للمزيد من الردود.

ugd ali

New Member

الجهاز يستخدم نصف سرعة النت فقط حيث تكون اقصى سرعة داونلود 60 كيلو بايت في الثانيه مع العلم مشترك في سرعه 1 ميجا سرعه داونلود تكون 120 كيلو بايت في الثانيه و المشكله في الجهاز جربت وصلة نت اخرى وايضا يستخدم نصف سرعة النت فقط


رابط التقارير
http://up-master.com/data/Reports_1.rar


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:21:42 PM, on 3/30/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\AxtromDTV\TheaterMgr.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\Zyzoom_Forum_Tools\zHijak.com
C:\Program Files\Mozilla Firefox\plugin-container.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [TheaterMgr] C:\Program Files\AxtromDTV\TheaterMgr.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{6AAD02F9-B3BC-4EAC-9FDD-5D5A27000161}: NameServer = 129.250.35.250,195.241.77.53
O17 - HKLM\System\CCS\Services\Tcpip\..\{EDB980BD-5080-43D4-8676-6E74C273F7A9}: NameServer = 129.250.35.250,195.241.77.53
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe

--
End of file - 6494 bytes

Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8
Adobe Shockwave Player
AxtromDTV
CCleaner
DirectX10 GFR
Hotfix for Windows XP (KB942288-v3)
Intel(R) Graphics Media *********** Driver
Internet Download Manager
K-Lite Mega Codec Pack 5.0.5
Microsoft .NET Framework 2.0
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Mozilla Firefox 4.0 (x86 en-US)
Nero 7 Ultra Edition
ProgDVB
REALTEK Gigabit and Fast Ethernet NIC Driver
Seven Remix XP 2.41
SoundMAX
SuperCopier2
Vodafone Mobile Connect Lite
Winamp (remove only)
WinRAR archiver
Yahoo! Messenger
 


احذف هذه القيم:

O17 - HKLM\System\CCS\Services\Tcpip\..\{6AAD02F9-B3BC-4EAC-9FDD-5D5A27000161}: NameServer = 129.250.35.250,195.241.77.53


O17 - HKLM\System\CCS\Services\Tcpip\..\{EDB980BD-5080-43D4-8676-6E74C273F7A9}: NameServer = 129.250.35.250,195.241.77.53

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll


O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe


O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe


ثم ادخل هذا الموضوع وافحص جهازك واعطيني التقرير:
http://www.delegnt.net/vb/showthread.php?t=8457
 


لم اتمكن من الرفع على الموقع فلم يظهر browse


PHP:
startup tool v1.0
-------------------------------------------------------------
التاريخ: 2011/03/30م
الوقت: 18:32:39

نوع المعالج:
X64

نظام التشغيل:
Microsoft Windows XP || 5.1

البناء:
2600

حزمة الخدمة:
Service Pack 2

إصدار المتصفح"Internet Explorer":
6.0.2900.2180
-------------------------------------------------------------

بدء التشغيل في الريجستري "قيم ريجستري":

! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    CTFMON.EXE    REG_SZ    C:\WINDOWS\system32\ctfmon.exe
    SuperCopier2.exe    REG_SZ    C:\Program Files\SuperCopier2\SuperCopier2.exe
    BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}    REG_SZ    "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    Messenger (Yahoo!)    REG_SZ    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    IDMan    REG_SZ    C:\Program Files\Internet Download Manager\IDMan.exe /onboot

! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
    High Definition Audio Property Page Shortcut    REG_SZ    HDAShCut.exe
    WinampAgent    REG_SZ    C:\Program Files\Winamp\winampa.exe
    NeroFilterCheck    REG_SZ    C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    TheaterMgr    REG_SZ    C:\Program Files\AxtromDTV\TheaterMgr.exe
    egui    REG_SZ    "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
    SoundMAXPnP    REG_SZ    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    SoundMAX    REG_SZ    "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
    igfxtray    REG_SZ    C:\WINDOWS\system32\igfxtray.exe
    igfxhkcmd    REG_SZ    C:\WINDOWS\system32\hkcmd.exe
    igfxpers    REG_SZ    C:\WINDOWS\system32\igfxpers.exe
    MobileConnect    REG_EXPAND_SZ    %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL
    Installed    REG_SZ    1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI
    Installed    REG_SZ    1
    NoChange    REG_SZ    1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS
    Installed    REG_SZ    1

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

! REG.EXE VERSION 3.0

HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run
    CTFMON.EXE    REG_SZ    C:\WINDOWS\system32\CTFMON.EXE

! REG.EXE VERSION 3.0

HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce
    nlsf    REG_EXPAND_SZ    cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
    tscuninstall    REG_EXPAND_SZ    %systemroot%\system32\tscupgrd.exe

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run
    CTFMON.EXE    REG_SZ    C:\WINDOWS\system32\CTFMON.EXE

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce
    nlsf    REG_EXPAND_SZ    cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
    tscuninstall    REG_EXPAND_SZ    %systemroot%\system32\tscupgrd.exe

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run
    CTFMON.EXE    REG_SZ    C:\WINDOWS\system32\CTFMON.EXE

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce
    nlsf    REG_EXPAND_SZ    cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
    tscuninstall    REG_EXPAND_SZ    %systemroot%\system32\tscupgrd.exe

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run
    CTFMON.EXE    REG_SZ    C:\WINDOWS\system32\CTFMON.EXE

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce
    nlsf    REG_EXPAND_SZ    cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
    tscuninstall    REG_EXPAND_SZ    %systemroot%\system32\tscupgrd.exe

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
    <NO NAME>    REG_SZ    

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Runonce
    <NO NAME>    REG_SZ    
-------------------------------------------------------------

بدء التشغيل في ملف المستخدم "ملفات تشغيلية":

 Volume in drive C is Win Xp
 Volume Serial Number is 8024-EC25

 Directory of C:\Documents and Settings\All Users\Start Menu\Programs\Startup

03/30/2011  06:31 PM    <DIR>          .
03/30/2011  06:31 PM    <DIR>          ..
               0 File(s)              0 bytes
               2 Dir(s)   4,974,723,072 bytes free

 Volume in drive C is Win Xp
 Volume Serial Number is 8024-EC25

 Directory of C:\Documents and Settings\M.shama\Start Menu\Programs\Startup

03/30/2011  11:31 AM    <DIR>          .
03/30/2011  11:31 AM    <DIR>          ..
               0 File(s)              0 bytes
               2 Dir(s)   4,974,723,072 bytes free
-------------------------------------------------------------

بدء التشغيل في أماكن متفرقة من الريجستري "متفرقات الريجستري":


! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components

HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}
    Version    REG_SZ    2,0,0,0
    Locale    REG_SZ    *

HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
    Version    REG_SZ    2,0,0,0
    Locale    REG_SZ    *

HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
    Version    REG_SZ    10,0,0,3802
    Locale    REG_SZ    EN

HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
    Version    REG_SZ    10,0,0,3802
    Locale    REG_SZ    EN

HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
    Version    REG_SZ    1,1,1,7
    Locale    REG_SZ    EN

HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
    Version    REG_SZ    6,0,2900,2180
    Locale    REG_SZ    EN
    Username    REG_SZ    M.shama

HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
    Locale    REG_SZ    EN
    Version    REG_SZ    4,4,0,3400

HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
    Locale    REG_SZ    EN
    Version    REG_SZ    10,0,0,3802

HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{4b218e3e-bc98-4770-93d3-2731b9329278}
    Version    REG_SZ    1,0,0,0
    Locale    REG_SZ    EN

HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
    Version    REG_SZ    10,0,0,3802
    Locale    REG_SZ    EN

HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}
    Version    REG_SZ    6,0,2600,0000
    Locale    REG_SZ    EN

HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}
    Version    REG_SZ    6,0,2900,2180
    Locale    REG_SZ    en

HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}
    Version    REG_SZ    6,0,2900,2180
    Locale    REG_SZ    en

HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
    DontAsk    REG_DWORD    0x2
    Version    REG_SZ    10,0,0,3802
    IsInstalled    REG_DWORD    0x0
    Stubpath    REG_SZ    C:\WINDOWS\inf\unregmp2.exe /ShowWMP
    <NO NAME>    REG_SZ    Microsoft Windows Media Player
    ComponentID    REG_SZ    WMPACCESS
    Locale    REG_SZ    *

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}
    <NO NAME>    REG_SZ    Internet Explorer
    ComponentID    REG_SZ    IEACCESS
    Dontask    REG_DWORD    0x2
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    StubPath    REG_EXPAND_SZ    %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
    Version    REG_SZ    2,0,0,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
    <NO NAME>    REG_SZ    Outlook Express
    ComponentID    REG_SZ    OEACCESS
    Dontask    REG_DWORD    0x2
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    StubPath    REG_EXPAND_SZ    %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
    Version    REG_SZ    2,0,0,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
    <NO NAME>    REG_SZ    Vector Graphics Rendering (VML)
    ComponentID    REG_SZ    MSVML
    Version    REG_SZ    6,0,2462,0001
    IsInstalled    REG_BINARY    01000000
    Locale    REG_SZ    EN

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
    <NO NAME>    REG_SZ    
    ComponentID    REG_SZ    NetShow
    IsInstalled    REG_DWORD    0x1
    DontAsk    REG_DWORD    0x2
    Locale    REG_SZ    EN
    StubPath    REG_SZ    
    Version    REG_SZ    10,0,0,3802

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
    StubPath    REG_SZ    
    ComponentID    REG_SZ    Microsoft Windows Media Player
    DontAsk    REG_DWORD    0x2
    Locale    REG_SZ    EN
    IsInstalled    REG_DWORD    0x1
    <NO NAME>    REG_SZ    Microsoft Windows Media Player 6.4
    Version    REG_SZ    10,0,0,3802

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{233C1507-6A77-46A4-9443-F871F945D258}
    ComponentID    REG_SZ    Director
    IsInstalled    REG_BINARY    01000000
    Version    REG_SZ    10,2,0,23
    Locale    REG_SZ    EN
    <NO NAME>    REG_SZ    Adobe Shockwave Director 10.2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
    <NO NAME>    REG_SZ    DirectAnimation
    IsInstalled    REG_DWORD    0x1
    Version    REG_SZ    6,0,3,531
    Locale    REG_SZ    EN
    ComponentID    REG_SZ    DirectAnimation

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2A202491-F00D-11cf-87CC-0020AFEECF20}
    ComponentID    REG_SZ    Director
    IsInstalled    REG_BINARY    01000000
    Version    REG_SZ    10,2,0,23
    Locale    REG_SZ    EN
    <NO NAME>    REG_SZ    Adobe Shockwave Director 10.2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
    <NO NAME>    REG_SZ    Themes Setup
    ComponentID    REG_SZ    Theme Component
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    EN
    StubPath    REG_EXPAND_SZ    %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
    Version    REG_SZ    1,1,1,7

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
    <NO NAME>    REG_SZ    Dynamic HTML Data Binding for Java
    ComponentID    REG_SZ    TridataJava
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    Version    REG_SZ    4,7,0,0320

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{3af36230-a269-11d1-b5bf-0000f8051515}
    Version    REG_SZ    6,0,2900,2180
    <NO NAME>    REG_SZ    Offline Browsing Pack
    ComponentID    REG_SZ    MobilePk
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
    <NO NAME>    REG_SZ    Uniscribe
    ComponentID    REG_SZ    USP10
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    Version    REG_SZ    1,397,2406,1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4278c270-a269-11d1-b5bf-0000f8051515}
    <NO NAME>    REG_SZ    Advanced Authoring
    ComponentID    REG_SZ    AdvAuth
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    Version    REG_SZ    6,0,2900,2180

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
    Version    REG_SZ    6,0,2900,2180
    <NO NAME>    REG_SZ    Microsoft Outlook Express 6
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    EN
    ComponentID    REG_SZ    MailNews
    CloneUser    REG_DWORD    0x1
    StubPath    REG_EXPAND_SZ    "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
    <NO NAME>    REG_SZ    NetMeeting 3.01
    ComponentID    REG_SZ    NetMeeting
    IsInstalled    REG_BINARY    01000000
    Version    REG_SZ    4,4,0,3400
    Locale    REG_SZ    EN
    StubPath    REG_SZ    rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
    <NO NAME>    REG_SZ    DirectShow
    ComponentID    REG_SZ    activemovie
    IsInstalled    REG_DWORD    0x1
    DontAsk    REG_DWORD    0x2
    Locale    REG_SZ    EN
    Version    REG_SZ    10,0,0,3802

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
    <NO NAME>    REG_SZ    DirectDrawEx
    ComponentID    REG_SZ    DirectDrawEx
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    Version    REG_SZ    4,71,1113,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
    <NO NAME>    REG_SZ    Internet Explorer Help
    ComponentID    REG_SZ    HelpCont
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    Version    REG_SZ    6,0,2900,2180

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4b218e3e-bc98-4770-93d3-2731b9329278}
    <NO NAME>    REG_SZ    Internet Explorer
    ComponentID    REG_SZ    Windows Marketplace Link
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    EN
    StubPath    REG_EXPAND_SZ    
    Version    REG_SZ    1,0,0,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4f216970-c90c-11d1-b5c7-0000f8051515}
    <NO NAME>    REG_SZ    DirectAnimation Java Classes
    ComponentID    REG_SZ    DAJava
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    Version    REG_SZ    6,00,01,0223

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}
    Version    REG_SZ    5,6,0,8825
    <NO NAME>    REG_SZ    Microsoft Windows Script 5.6
    ComponentID    REG_SZ    MSVBScript
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    EN

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5A8D6EE0-3E18-11D0-821E-444553540000}
    (Default)    REG_SZ    Internet Connection Wizard
    ComponentID    REG_SZ    ICW
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    Version    REG_SZ    5,00,2918,1900

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
    <NO NAME>    REG_SZ    Internet Explorer Setup Tools
    ComponentID    REG_SZ    GenSetup
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    Version    REG_SZ    5,0,0,1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
    Version    REG_SZ    6,0,2900,2180
    <NO NAME>    REG_SZ    Browsing Enhancements
    ComponentID    REG_SZ    ExtraPack
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    KeyFileName    REG_SZ    C:\WINDOWS\system32\msieftp.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
    <NO NAME>    REG_SZ    Microsoft Windows Media Player
    ComponentID    REG_SZ    Microsoft Windows Media Player
    DontAsk    REG_DWORD    0x2
    Locale    REG_SZ    EN
    StubPath    REG_SZ    rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub
    IsInstalled    REG_DWORD    0x1
    Version    REG_SZ    10,0,0,3802

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
    <NO NAME>    REG_SZ    MSN Site Access
    ComponentID    REG_SZ    MSN_Auth
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    Version    REG_SZ    4,9,9,2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
    ComponentID    REG_SZ    .NETFramework
    <NO NAME>    REG_SZ    .NET Framework
    Locale    REG_SZ    
    Version    REG_SZ    2,0,50727,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{73fa19d0-2d75-11d2-995d-00c04f98bbc9}
    <NO NAME>    REG_SZ    Web Folders
    ComponentID    REG_SZ    WebFolders
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    Version    REG_SZ    1,0,1,7

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}
    Version    REG_SZ    6,0,2600,0000
    <NO NAME>    REG_SZ    Address Book 6
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    EN
    ComponentID    REG_SZ    WAB
    StubPath    REG_EXPAND_SZ    "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}
    Version    REG_SZ    6,0,2900,2180
    <NO NAME>    REG_SZ    Windows Desktop Update
    ComponentID    REG_SZ    IE4Shell_NT
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    en
    StubPath    REG_EXPAND_SZ    regsvr32.exe /s /n /i:U shell32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}
    Version    REG_SZ    6,0,2900,2180
    <NO NAME>    REG_SZ    Internet Explorer 6
    ComponentID    REG_SZ    BASEIE40_W2K
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    en
    StubPath    REG_EXPAND_SZ    %SystemRoot%\system32\ie4uinit.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}\AuthorizedCDFPrefix

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
    DontAsk    REG_DWORD    0x2
    StubPath    REG_SZ    C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
    IsInstalled    REG_DWORD    0x1
    ComponentID    REG_SZ    DOTNETFRAMEWORKS

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
    <NO NAME>    REG_SZ    Dynamic HTML Data Binding
    ComponentID    REG_SZ    Tridata
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    Version    REG_SZ    5,5000,3130,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}
    Version    REG_SZ    6,0,2800,2180

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{C9E9A340-D1F1-11D0-821E-444553540600}
    <NO NAME>    REG_SZ    Internet Explorer Core Fonts
    ComponentID    REG_SZ    Fontcore
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    Version    REG_SZ    1,00,0000,6

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
    <NO NAME>    REG_SZ    Task Scheduler
    ComponentID    REG_SZ    MSTASK
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    Version    REG_SZ    4,71,1968,1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
    ComponentID    REG_SZ    Windows Movie Maker v2.1
    IsInstalled    REG_BINARY    01000000
    Version    REG_SZ    2,1,4026,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
    <NO NAME>    REG_SZ    Adobe Flash Player
    ComponentID    REG_SZ    Flash
    IsInstalled    REG_BINARY    01000000
    Version    REG_SZ    10.0.22.87
    Locale    REG_SZ    EN

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
    <NO NAME>    REG_SZ    HTML Help
    ComponentID    REG_SZ    HTMLHelp
    IsInstalled    REG_DWORD    0x1
    Locale    REG_SZ    *
    Version    REG_SZ    4,74,9273,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}
    ComponentID    REG_SZ    Yahoo! Messenger
    IsInstalled    REG_DWORD    0x1
    Version    REG_SZ    10.0.0.1102

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
    <NO NAME>    REG_SZ    Active Directory Service Interface
    ComponentID    REG_SZ    ADSI
    IsInstalled    REG_BINARY    01000000
    Locale    REG_SZ    EN
    Version    REG_SZ    5,0,00,0

! REG.EXE VERSION 3.0

HKEY_USERS\.DEFAULT\Software\Microsoft\Active Setup\Installed Components

HKEY_USERS\.DEFAULT\Software\Microsoft\Active Setup\Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
    Version    REG_SZ    10,0,0,3802

HKEY_USERS\.DEFAULT\Software\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
    Version    REG_SZ    10,0,0,3802

HKEY_USERS\.DEFAULT\Software\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
    Locale    REG_SZ    EN
    Version    REG_SZ    4,4,0,3400

HKEY_USERS\.DEFAULT\Software\Microsoft\Active Setup\Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
    Locale    REG_SZ    EN
    Version    REG_SZ    10,0,0,3802

HKEY_USERS\.DEFAULT\Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
    Version    REG_SZ    10,0,0,3802

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-18\Software\Microsoft\Active Setup\Installed Components

HKEY_USERS\S-1-5-18\Software\Microsoft\Active Setup\Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
    Version    REG_SZ    10,0,0,3802

HKEY_USERS\S-1-5-18\Software\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
    Version    REG_SZ    10,0,0,3802

HKEY_USERS\S-1-5-18\Software\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
    Locale    REG_SZ    EN
    Version    REG_SZ    4,4,0,3400

HKEY_USERS\S-1-5-18\Software\Microsoft\Active Setup\Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
    Locale    REG_SZ    EN
    Version    REG_SZ    10,0,0,3802

HKEY_USERS\S-1-5-18\Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
    Version    REG_SZ    10,0,0,3802

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-19\Software\Microsoft\Active Setup\Installed Components

HKEY_USERS\S-1-5-19\Software\Microsoft\Active Setup\Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
    Version    REG_SZ    10,0,0,3802

HKEY_USERS\S-1-5-19\Software\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
    Version    REG_SZ    10,0,0,3802

HKEY_USERS\S-1-5-19\Software\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
    Locale    REG_SZ    EN
    Version    REG_SZ    4,4,0,3400

HKEY_USERS\S-1-5-19\Software\Microsoft\Active Setup\Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
    Locale    REG_SZ    EN
    Version    REG_SZ    10,0,0,3802

HKEY_USERS\S-1-5-19\Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
    Version    REG_SZ    10,0,0,3802

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-20\Software\Microsoft\Active Setup\Installed Components

HKEY_USERS\S-1-5-20\Software\Microsoft\Active Setup\Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
    Version    REG_SZ    10,0,0,3802

HKEY_USERS\S-1-5-20\Software\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
    Version    REG_SZ    10,0,0,3802

HKEY_USERS\S-1-5-20\Software\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
    Locale    REG_SZ    EN
    Version    REG_SZ    4,4,0,3400

HKEY_USERS\S-1-5-20\Software\Microsoft\Active Setup\Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
    Locale    REG_SZ    EN
    Version    REG_SZ    10,0,0,3802

HKEY_USERS\S-1-5-20\Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
    Version    REG_SZ    10,0,0,3802

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}
    <NO NAME>    REG_SZ    IDM Helper
    NoExplorer    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
    <NO NAME>    REG_SZ    

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\IDM Shell Extension
    <NO NAME>    REG_SZ    {CDC95B92-E27C-4745-A8C5-64A52A78855D}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Offline Files
    <NO NAME>    REG_SZ    {750fdf0e-2a26-11d1-a3ea-080036587f03}

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
    {00022613-0000-0000-C000-000000000046}    REG_SZ    Multimedia File Property Sheet
    {176d6597-26d3-11d1-b350-080036a75b03}    REG_SZ    ICM Scanner Management
    {1F2E5C40-9550-11CE-99D2-00AA006E086C}    REG_SZ    NTFS Security Page
    {3EA48300-8CF6-101B-84FB-666CCB9BCD32}    REG_SZ    OLE Docfile Property Page
    {40dd6e20-7c17-11ce-a804-00aa003ca9f6}    REG_SZ    Shell extensions for sharing
    {41E300E0-78B6-11ce-849B-444553540000}    REG_SZ    PlusPack CPL Extension
    {42071712-76d4-11d1-8b24-00a0c9068ff3}    REG_SZ    Display Adapter CPL Extension
    {42071713-76d4-11d1-8b24-00a0c9068ff3}    REG_SZ    Display Monitor CPL Extension
    {42071714-76d4-11d1-8b24-00a0c9068ff3}    REG_SZ    Display Panning CPL Extension
    {4E40F770-369C-11d0-8922-00A024AB2DBB}    REG_SZ    DS Security Page
    {513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}    REG_SZ    Compatibility Page
    {56117100-C0CD-101B-81E2-00AA004AE837}    REG_SZ    Shell Scrap DataHandler
    {59099400-57FF-11CE-BD94-0020AF85B590}    REG_SZ    Disk Copy Extension
    {59be4990-f85c-11ce-aff7-00aa003ca9f6}    REG_SZ    Shell extensions for Microsoft Windows Network objects
    {5DB2625A-54DF-11D0-B6C4-0800091AA605}    REG_SZ    ICM Monitor Management
    {675F097E-4C4D-11D0-B6C1-0800091AA605}    REG_SZ    ICM Printer Management
    {764BF0E1-F219-11ce-972D-00AA00A14F56}    REG_SZ    Shell extensions for file compression
    {77597368-7b15-11d0-a0c2-080036af3f03}    REG_SZ    Web Printer Shell Extension
    {7988B573-EC89-11cf-9C00-00AA00A14F56}    REG_SZ    Disk Quota UI
    {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}    REG_SZ    Encryption Context Menu
    {85BBD920-42A0-1069-A2E4-08002B30309D}    REG_SZ    Briefcase
    {88895560-9AA2-1069-930E-00AA0030EBC8}    REG_SZ    HyperTerminal Icon Ext
    {BD84B380-8CA2-1069-AB1D-08000948F534}    REG_SZ    Fonts
    {DBCE2480-C732-101B-BE72-BA78E9AD5B27}    REG_SZ    ICC Profile
    {F37C5810-4D3F-11d0-B4BF-00AA00BBB723}    REG_SZ    Printers Security Page
    {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}    REG_SZ    Shell extensions for sharing
    {f92e8c40-3d33-11d2-b1aa-080036a75b03}    REG_SZ    Display TroubleShoot CPL Extension
    {7444C717-39BF-11D1-8CD9-00C04FC29D45}    REG_SZ    Crypto PKO Extension
    {7444C719-39BF-11D1-8CD9-00C04FC29D45}    REG_SZ    Crypto Sign Extension
    {7007ACC7-3202-11D1-AAD2-00805FC1270E}    REG_SZ    Network Connections
    {992CFFA0-F557-101A-88EC-00DD010CCC48}    REG_SZ    Network Connections
    {E211B736-43FD-11D1-9EFB-0000F8757FCD}    REG_SZ    Scanners & Cameras
    {FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}    REG_SZ    Scanners & Cameras
    {905667aa-acd6-11d2-8080-00805f6596d2}    REG_SZ    Scanners & Cameras
    {3F953603-1008-4f6e-A73A-04AAC7A992F1}    REG_SZ    Scanners & Cameras
    {83bbcbf3-b28a-4919-a5aa-73027445d672}    REG_SZ    Scanners & Cameras
    {F0152790-D56E-4445-850E-4F3117DB740C}    REG_SZ    Remote Sessions CPL Extension
    {640167b4-59b0-47a6-b335-a6b3c0695aea}    REG_SZ    Portable Media Devices
    {cc86590a-b60a-48e6-996b-41d25ed39a1e}    REG_SZ    Portable Media Devices Menu
    {21569614-B795-46b1-85F4-E737A8DC09AD}    REG_SZ    Shell Search Band
    {60254CA5-953B-11CF-8C96-00AA00B8708C}    REG_SZ    Shell extensions for Windows Script Host
    {2206CDB2-19C1-11D1-89E0-00C04FD7A829}    REG_SZ    Microsoft Data Link
    {DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}    REG_SZ    Tasks Folder Icon Handler
    {797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}    REG_SZ    Tasks Folder Shell Extension
    {D6277990-4C6A-11CF-8D87-00AA0060F5BF}    REG_SZ    Scheduled Tasks
    {2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}    REG_SZ    Set Program Access and Defaults
    {5F327514-6C5E-4d60-8F16-D07FA08A78ED}    REG_SZ    Auto Update Property Sheet Extension
    {0DF44EAA-FF21-4412-828E-260A8728E7F1}    REG_SZ    Taskbar and Start Menu
    {2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}    REG_SZ    Search
    {2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}    REG_SZ    Help and Support
    {2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}    REG_SZ    Help and Support
    {2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}    REG_SZ    Run...
    {2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}    REG_SZ    Internet
    {2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}    REG_SZ    E-mail
    {D20EA4E1-3957-11d2-A40B-0C5020524152}    REG_SZ    Fonts
    {D20EA4E1-3957-11d2-A40B-0C5020524153}    REG_SZ    Administrative Tools
    {596AB062-B4D2-4215-9F74-E9109B0A8153}    REG_SZ    Previous Versions Property Page
    {9DB7A13C-F208-4981-8353-73CC61AE2783}    REG_SZ    Previous Versions
    {875CB1A1-0F29-45de-A1AE-CFB4950D0B78}    REG_SZ    Audio Media Properties Handler
    {40C3D757-D6E4-4b49-BB41-0E5BBEA28817}    REG_SZ    Video Media Properties Handler
    {E4B29F9D-D390-480b-92FD-7DDB47101D71}    REG_SZ    Wav Properties Handler
    {87D62D94-71B3-4b9a-9489-5FE6850DC73E}    REG_SZ    Avi Properties Handler
    {A6FD9E45-6E44-43f9-8644-08598F5A74D9}    REG_SZ    Midi Properties Handler
    {c5a40261-cd64-4ccf-84cb-c394da41d590}    REG_SZ    Video Thumbnail Extractor
    {5E6AB780-7743-11CF-A12B-00AA004AE837}    REG_SZ    Microsoft Internet Toolbar
    {22BF0C20-6DA7-11D0-B373-00A0C9034938}    REG_SZ    Download Status
    {91EA3F8B-C99B-11d0-9815-00C04FD91972}    REG_SZ    Augmented Shell Folder
    {6413BA2C-B461-11d1-A18A-080036B11A03}    REG_SZ    Augmented Shell Folder 2
    {F61FFEC1-754F-11d0-80CA-00AA005B4383}    REG_SZ    BandProxy
    {7BA4C742-9E81-11CF-99D3-00AA004AE837}    REG_SZ    Microsoft BrowserBand
    {169A0691-8DF9-11d1-A1C4-00C04FD75D13}    REG_SZ    In-pane search
    {AF4F6510-F982-11d0-8595-00AA004CD6D8}    REG_SZ    Registry Tree Options Utility
    {01E04581-4EEE-11d0-BFE9-00AA005B4383}    REG_SZ    &Address
    {A08C11D2-A228-11d0-825B-00AA005B4383}    REG_SZ    Address EditBox
    {00BB2763-6A77-11D0-A535-00C04FD7D062}    REG_SZ    Shell Microsoft AutoComplete
    {6756A641-DE71-11d0-831B-00AA005B4383}    REG_SZ    MRU AutoComplete List
    {6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}    REG_SZ    Custom MRU AutoCompleted List
    {7e653215-fa25-46bd-a339-34a2790f3cb7}    REG_SZ    Accessible
    {acf35015-526e-4230-9596-becbe19f0ac9}    REG_SZ    Track Popup Bar
    {00BB2764-6A77-11D0-A535-00C04FD7D062}    REG_SZ    Microsoft History AutoComplete List
    {03C036F1-A186-11D0-824A-00AA005B4383}    REG_SZ    Microsoft Shell Folder AutoComplete List
    {00BB2765-6A77-11D0-A535-00C04FD7D062}    REG_SZ    Microsoft Multiple AutoComplete List Container
    {ECD4FC4E-521C-11D0-B792-00A0C90312E1}    REG_SZ    Shell Band Site Menu
    {3CCF8A41-5C85-11d0-9796-00AA00B90ADF}    REG_SZ    Shell DeskBarApp
    {ECD4FC4C-521C-11D0-B792-00A0C90312E1}    REG_SZ    Shell DeskBar
    {ECD4FC4D-521C-11D0-B792-00A0C90312E1}    REG_SZ    Shell Rebar BandSite
    {DD313E04-FEFF-11d1-8ECD-0000F87A470C}    REG_SZ    User Assist
    {EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}    REG_SZ    Global Folder Settings
    {30D02401-6A81-11d0-8274-00C04FD5AE38}    REG_SZ    IE Search Band
    {3028902F-6374-48b2-8DC6-9725E775B926}    REG_SZ    IE Microsoft AutoComplete
    {07798131-AF23-11d1-9111-00A0C98BA67D}    REG_SZ    Web Search
    {7376D660-C583-11d0-A3A5-00C04FD706EC}    REG_SZ    TridentImageExtractor
    {EFA24E61-B078-11d0-89E4-00C04FC9E26E}    REG_SZ    Favorites Band
    {EFA24E62-B078-11d0-89E4-00C04FC9E26E}    REG_SZ    History Band
    {0A89A860-D7B1-11CE-8350-444553540000}    REG_SZ    Shell Automation Inproc Service
    {A5E46E3A-8849-11D1-9D8C-00C04FC99D61}    REG_SZ    Microsoft Browser Architecture
    {131A6951-7F78-11D0-A979-00C04FD705A2}    REG_SZ    ISFBand OC
    {9461b922-3c5a-11d2-bf8b-00c04fb93661}    REG_SZ    Search Assistant OC
    {E7E4BC40-E76A-11CE-A9BB-00AA004AE837}    REG_SZ    Shell DocObject Viewer
    {FBF23B40-E3F0-101B-8488-00AA003E56F8}    REG_SZ    InternetShortcut
    {3C374A40-BAE4-11CF-BF7D-00AA006946EE}    REG_SZ    Microsoft Url History Service
    {FF393560-C2A7-11CF-BFF4-444553540000}    REG_SZ    History
    {7BD29E00-76C1-11CF-9DD0-00A0C9034933}    REG_SZ    Temporary Internet Files
    {7BD29E01-76C1-11CF-9DD0-00A0C9034933}    REG_SZ    Temporary Internet Files
    {CFBFAE00-17A6-11D0-99CB-00C04FD64497}    REG_SZ    Microsoft Url Search Hook
    {A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}    REG_SZ    IE4 Suite Splash Screen
    {67EA19A0-CCEF-11d0-8024-00C04FD75D13}    REG_SZ    CDF Extension Copy Hook
    {3DC7A020-0ACD-11CF-A9BB-00AA004AE837}    REG_SZ    The Internet
    {EFA24E64-B078-11d0-89E4-00C04FC9E26E}    REG_SZ    Explorer Band
    {871C5380-42A0-1069-A2EA-08002B30309D}    REG_SZ    Internet Name Space
    {9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}    REG_SZ    Sendmail service
    {9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}    REG_SZ    Sendmail service
    {88C6C381-2E85-11D0-94DE-444553540000}    REG_SZ    ActiveX Cache Folder
    {E6FB5E20-DE35-11CF-9C87-00AA005127ED}    REG_SZ    WebCheck
    {ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}    REG_SZ    Subscription Mgr
    {F5175861-2688-11d0-9C5E-00AA00A45957}    REG_SZ    Subscription Folder
    {08165EA0-E946-11CF-9C87-00AA005127ED}    REG_SZ    WebCheckWebCrawler
    {E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}    REG_SZ    WebCheckChannelAgent
    {E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}    REG_SZ    TrayAgent
    {7D559C10-9FE9-11d0-93F7-00AA0059CE02}    REG_SZ    Code Download Agent
    {E6CC6978-6B6E-11D0-BECA-00C04FD940BE}    REG_SZ    ConnectionAgent
    {D8BD2030-6FC9-11D0-864F-00AA006809D9}    REG_SZ    PostAgent
    {7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}    REG_SZ    WebCheck SyncMgr Handler
    {352EC2B7-8B9A-11D1-B8AE-006008059382}    REG_SZ    Shell Application Manager
    {0B124F8F-91F0-11D1-B8B5-006008059382}    REG_SZ    Installed Apps Enumerator
    {CFCCC7A0-A282-11D1-9082-006008059382}    REG_SZ    Darwin App Publisher
    {e84fda7c-1d6a-45f6-b725-cb260c236066}    REG_SZ    Shell Image Verbs
    {66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}    REG_SZ    Shell Image Data Factory
    {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}    REG_SZ    Autoplay for SlideShow
    {3F30C968-480A-4C6C-862D-EFC0897BB84B}    REG_SZ    GDI+ file thumbnail extractor
    {9DBD2C50-62AD-11d0-B806-00C04FD706EC}    REG_SZ    Summary Info Thumbnail handler (DOCFILES)
    {EAB841A0-9550-11cf-8C16-00805F1408F3}    REG_SZ    HTML Thumbnail Extractor
    {eb9b1153-3b57-4e68-959a-a3266bc3d7fe}    REG_SZ    Shell Image Property Handler
    {CC6EEFFB-43F6-46c5-9619-51D571967F7D}    REG_SZ    Web Publishing Wizard
    {add36aa8-751a-4579-a266-d66f5202ccbb}    REG_SZ    Print Ordering via the Web
    {6b33163c-76a5-4b6c-bf21-45de9cd503a1}    REG_SZ    Shell Publishing Wizard Object
    {58f1f272-9240-4f51-b6d4-fd63d1618591}    REG_SZ    Get a Passport Wizard
    {7A9D77BD-5403-11d2-8785-2E0420524153}    REG_SZ    User Accounts
    {E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31}    REG_SZ    Compressed (zipped) Folder
    {BD472F60-27FA-11cf-B8B4-444553540000}    REG_SZ    Compressed (zipped) Folder Right Drag Handler
    {888DCA60-FC0A-11CF-8F0F-00C04FD7D062}    REG_SZ    Compressed (zipped) Folder SendTo Target
    {f39a0dc0-9cc8-11d0-a599-00c04fd64433}    REG_SZ    Channel File
    {f3aa0dc0-9cc8-11d0-a599-00c04fd64434}    REG_SZ    Channel Shortcut
    {f3ba0dc0-9cc8-11d0-a599-00c04fd64435}    REG_SZ    Channel Handler Object
    {f3da0dc0-9cc8-11d0-a599-00c04fd64437}    REG_SZ    Channel Menu
    {f3ea0dc0-9cc8-11d0-a599-00c04fd64438}    REG_SZ    Channel Properties
    {692F0339-CBAA-47e6-B5B5-3B84DB604E87}    REG_SZ    Extensions Manager Folder
    {63da6ec0-2e98-11cf-8d82-444553540000}    REG_SZ    FTP Folders Webview
    {883373C3-BF89-11D1-BE35-080036B11A03}    REG_SZ    Microsoft DocProp Shell Ext
    {A9CF0EAE-901A-4739-A481-E35B73E47F6D}    REG_SZ    Microsoft DocProp Inplace Edit Box Control
    {8EE97210-FD1F-4B19-91DA-67914005F020}    REG_SZ    Microsoft DocProp Inplace ML Edit Box Control
    {0EEA25CC-4362-4A12-850B-86EE61B0D3EB}    REG_SZ    Microsoft DocProp Inplace Droplist Combo Control
    {6A205B57-2567-4A2C-B881-F787FAB579A3}    REG_SZ    Microsoft DocProp Inplace Calendar Control
    {28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}    REG_SZ    Microsoft DocProp Inplace Time Control
    {8A23E65E-31C2-11d0-891C-00A024AB2DBB}    REG_SZ    Directory Query UI
    {9E51E0D0-6E0F-11d2-9601-00C04FA31A86}    REG_SZ    Shell properties for a DS object
    {163FDC20-2ABC-11d0-88F0-00A024AB2DBB}    REG_SZ    Directory Object Find
    {F020E586-5264-11d1-A532-0000F8757D7E}    REG_SZ    Directory Start/Search Find
    {0D45D530-764B-11d0-A1CA-00AA00C16E65}    REG_SZ    Directory Property UI
    {62AE1F9A-126A-11D0-A14B-0800361B1103}    REG_SZ    Directory Context Menu Verbs
    {ECF03A33-103D-11d2-854D-006008059367}    REG_SZ    MyDocs Copy Hook
    {ECF03A32-103D-11d2-854D-006008059367}    REG_SZ    MyDocs Drop Target
    {4a7ded0a-ad25-11d0-98a8-0800361b1103}    REG_SZ    MyDocs Properties
    {750fdf0e-2a26-11d1-a3ea-080036587f03}    REG_SZ    Offline Files Menu
    {10CFC467-4392-11d2-8DB4-00C04FA31A66}    REG_SZ    Offline Files Folder Options
    {AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}    REG_SZ    Offline Files Folder
    {143A62C8-C33B-11D1-84FE-00C04FA34A14}    REG_SZ    Microsoft Agent Character Property Sheet Handler
    {ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}    REG_SZ    DfsShell
    {60fd46de-f830-4894-a628-6fa81bc0190d}    REG_SZ    %DESC_PublishDropTarget%
    {7A80E4A8-8005-11D2-BCF8-00C04F72C717}    REG_SZ    MMC Icon Handler
    {0CD7A5C0-9F37-11CE-AE65-08002B2E1262}    REG_SZ    .CAB file viewer
    {32714800-2E5F-11d0-8B85-00AA0044F941}    REG_SZ    For &People...
    {8DD448E6-C188-4aed-AF92-44956194EB1F}    REG_SZ    Windows Media Player Play as Playlist Context Menu Handler
    {CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}    REG_SZ    Windows Media Player Burn Audio CD Context Menu Handler
    {F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}    REG_SZ    Windows Media Player Add to Playlist Context Menu Handler
    {BDEADF00-C265-11D0-BCED-00A0C90AB50F}    REG_SZ    Web Folders
    {B41DB860-8EE4-11D2-9906-E49FADC173CA}    REG_SZ    WinRAR shell extension
    {00020D75-0000-0000-C000-000000000046}    REG_SZ    Microsoft Office Outlook Desktop Icon Handler
    {0006F045-0000-0000-C000-000000000046}    REG_SZ    Microsoft Office Outlook Custom Icon Handler
    {42042206-2D85-11D3-8CFF-005004838597}    REG_SZ    Microsoft Office HTML Icon Handler
    {B089FE88-FB52-11D3-BDF1-0050DA34150D}    REG_SZ    ESET Smart Security - Context Menu Shell Extension
    {CDC95B92-E27C-4745-A8C5-64A52A78855D}    REG_SZ    IDM Shell Extension
    {e82a2d71-5b2f-43a0-97b8-81be15854de8}    REG_SZ    ShellLink for Application References
    {E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}    REG_SZ    Shell Icon Handler for Application References

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
    {438755C2-A8BA-11D1-B96B-00A0C90312E1}    REG_SZ    Browseui preloader
    {8C7461EF-2B13-11d2-BE35-3078302C2030}    REG_SZ    Component Categories cache daemon

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
    {AEB6717E-7E19-11d0-97EE-00C04FD91972}    REG_SZ    

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
    PostBootReminder    REG_SZ    {7849596a-48ea-486e-8937-a2a3009f31a9}
    CDBurn    REG_SZ    {fbeb8a05-beee-4442-804e-409d6c4515e9}
    WebCheck    REG_SZ    {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
    SysTray    REG_SZ    {35CEC8A3-2BE6-11D2-8773-92E220524153}

! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\Software\Microsoft\Command Processor
    CompletionChar    REG_DWORD    0x9
    DefaultColor    REG_DWORD    0x0
    EnableExtensions    REG_DWORD    0x1

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor
    AutoRun    REG_SZ    
    CompletionChar    REG_DWORD    0x40
    DefaultColor    REG_DWORD    0x0
    EnableExtensions    REG_DWORD    0x1
    PathCompletionChar    REG_DWORD    0x40

! REG.EXE VERSION 3.0

HKEY_USERS\.DEFAULT\Software\Microsoft\Command Processor
    CompletionChar    REG_DWORD    0x9
    DefaultColor    REG_DWORD    0x0
    EnableExtensions    REG_DWORD    0x1

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-18\Software\Microsoft\Command Processor
    CompletionChar    REG_DWORD    0x9
    DefaultColor    REG_DWORD    0x0
    EnableExtensions    REG_DWORD    0x1

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-19\Software\Microsoft\Command Processor
    CompletionChar    REG_DWORD    0x9
    DefaultColor    REG_DWORD    0x0
    EnableExtensions    REG_DWORD    0x1

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-20\Software\Microsoft\Command Processor
    CompletionChar    REG_DWORD    0x9
    DefaultColor    REG_DWORD    0x0
    EnableExtensions    REG_DWORD    0x1

! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    ParseAutoexec    REG_SZ    1
    ExcludeProfileDirs    REG_SZ    Local Settings;Temporary Internet Files;History;Temp;Local Settings\Application Data\Microsoft\Outlook
    BuildNumber    REG_DWORD    0xa28

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\winlogon

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\winlogon\DEBUG
    Trace Level    REG_SZ    

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    AutoRestartShell    REG_DWORD    0x1
    DefaultDomainName    REG_SZ    SICOWIN
    DefaultUserName    REG_SZ    M.shama
    LegalNoticeCaption    REG_SZ    
    LegalNoticeText    REG_SZ    
    PowerdownAfterShutdown    REG_SZ    0
    ReportBootOk    REG_SZ    1
    Shell    REG_SZ    Explorer.exe
    ShutdownWithoutLogon    REG_SZ    0
    System    REG_SZ    
    Userinit    REG_SZ    C:\WINDOWS\system32\userinit.exe,
    VmApplet    REG_SZ    rundll32 shell32,Control_RunDLL "sysdm.cpl"
    SfcQuota    REG_DWORD    0x0
    SfcDisable    REG_DWORD    0xffffff9d
    allocatecdroms    REG_SZ    0
    allocatedasd    REG_SZ    0
    allocatefloppies    REG_SZ    0
    cachedlogonscount    REG_SZ    10
    forceunlocklogon    REG_DWORD    0x0
    passwordexpirywarning    REG_DWORD    0xe
    scremoveoption    REG_SZ    0
    AllowMultipleTSSessions    REG_DWORD    0x1
    UIHost    REG_EXPAND_SZ    logonui.exe
    LogonType    REG_DWORD    0x1
    Background    REG_SZ    0 0 0
    DebugServerCommand    REG_SZ    no
    WinStationsDisabled    REG_SZ    0
    HibernationPreviouslyEnabled    REG_DWORD    0x1
    ShowLogonOptions    REG_DWORD    0x1
    AltDefaultUserName    REG_SZ    M.shama
    AltDefaultDomainName    REG_SZ    SICOWIN
    AutoAdminLogon    REG_SZ    1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}
    <NO NAME>    REG_SZ    Wireless
    ProcessGroupPolicy    REG_SZ    ProcessWIRELESSPolicy
    DllName    REG_EXPAND_SZ    gptext.dll
    NoUserPolicy    REG_DWORD    0x1
    NoGPOListChanges    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}
    <NO NAME>    REG_SZ    Folder Redirection
    ProcessGroupPolicyEx    REG_SZ    ProcessGroupPolicyEx
    DllName    REG_EXPAND_SZ    fdeploy.dll
    NoMachinePolicy    REG_DWORD    0x1
    NoSlowLink    REG_DWORD    0x1
    PerUserLocalSettings    REG_DWORD    0x1
    NoGPOListChanges    REG_DWORD    0x0
    NoBackgroundPolicy    REG_DWORD    0x0
    GenerateGroupPolicy    REG_SZ    GenerateGroupPolicy
    EventSources    REG_MULTI_SZ    (Folder Redirection,Application)\0\0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{35378EAC-683F-11D2-A89A-00C04FBBCFA2}
    Status    REG_DWORD    0x0
    RsopStatus    REG_DWORD    0x0
    LastPolicyTime    REG_DWORD    0xfa8ba7
    PrevSlowLink    REG_DWORD    0x0
    PrevRsopLogging    REG_DWORD    0x1
    ForceRefreshFG    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
    <NO NAME>    REG_SZ    Microsoft Disk Quota
    NoMachinePolicy    REG_DWORD    0x0
    NoUserPolicy    REG_DWORD    0x1
    NoSlowLink    REG_DWORD    0x1
    NoBackgroundPolicy    REG_DWORD    0x1
    NoGPOListChanges    REG_DWORD    0x1
    PerUserLocalSettings    REG_DWORD    0x0
    RequiresSuccessfulRegistry    REG_DWORD    0x1
    EnableAsynchronousProcessing    REG_DWORD    0x0
    DllName    REG_EXPAND_SZ    dskquota.dll
    ProcessGroupPolicy    REG_SZ    ProcessGroupPolicy

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}
    <NO NAME>    REG_SZ    QoS Packet Scheduler
    ProcessGroupPolicy    REG_SZ    ProcessPSCHEDPolicy
    DllName    REG_EXPAND_SZ    gptext.dll
    NoUserPolicy    REG_DWORD    0x1
    NoGPOListChanges    REG_DWORD    0x1
    Status    REG_DWORD    0x0
    RsopStatus    REG_DWORD    0x80070032
    LastPolicyTime    REG_DWORD    0xfa8ba7
    PrevSlowLink    REG_DWORD    0x0
    PrevRsopLogging    REG_DWORD    0x1
    ForceRefreshFG    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}
    <NO NAME>    REG_SZ    Scripts
    ProcessGroupPolicy    REG_SZ    ProcessScriptsGroupPolicy
    ProcessGroupPolicyEx    REG_SZ    ProcessScriptsGroupPolicyEx
    GenerateGroupPolicy    REG_SZ    GenerateScriptsGroupPolicy
    DllName    REG_EXPAND_SZ    gptext.dll
    NoSlowLink    REG_DWORD    0x1
    NoGPOListChanges    REG_DWORD    0x1
    NotifyLinkTransition    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}
    <NO NAME>    REG_SZ    Internet Explorer Zonemapping
    DllName    REG_EXPAND_SZ    iedkcs32.dll
    ProcessGroupPolicy    REG_SZ    ProcessGroupPolicyForZoneMap
    NoGPOListChanges    REG_DWORD    0x1
    RequiresSucessfulRegistry    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
    ProcessGroupPolicy    REG_SZ    SceProcessSecurityPolicyGPO
    GenerateGroupPolicy    REG_SZ    SceGenerateGroupPolicy
    ExtensionRsopPlanningDebugLevel    REG_DWORD    0x1
    ProcessGroupPolicyEx    REG_SZ    SceProcessSecurityPolicyGPOEx
    ExtensionDebugLevel    REG_DWORD    0x1
    DllName    REG_EXPAND_SZ    scecli.dll
    <NO NAME>    REG_SZ    Security
    NoUserPolicy    REG_DWORD    0x1
    NoGPOListChanges    REG_DWORD    0x1
    EnableAsynchronousProcessing    REG_DWORD    0x1
    MaxNoGPOListChangesInterval    REG_DWORD    0x3c0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}
    ProcessGroupPolicyEx    REG_SZ    ProcessGroupPolicyEx
    GenerateGroupPolicy    REG_SZ    GenerateGroupPolicy
    ProcessGroupPolicy    REG_SZ    ProcessGroupPolicy
    DllName    REG_EXPAND_SZ    iedkcs32.dll
    <NO NAME>    REG_SZ    Internet Explorer Branding
    NoSlowLink    REG_DWORD    0x1
    NoBackgroundPolicy    REG_DWORD    0x0
    NoGPOListChanges    REG_DWORD    0x1
    NoMachinePolicy    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}
    ProcessGroupPolicy    REG_SZ    SceProcessEFSRecoveryGPO
    DllName    REG_EXPAND_SZ    scecli.dll
    <NO NAME>    REG_SZ    EFS recovery
    NoUserPolicy    REG_DWORD    0x1
    NoGPOListChanges    REG_DWORD    0x1
    RequiresSuccessfulRegistry    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}
    <NO NAME>    REG_SZ    Microsoft Offline Files
    DllName    REG_EXPAND_SZ    %SystemRoot%\System32\cscui.dll
    EnableAsynchronousProcessing    REG_DWORD    0x0
    NoBackgroundPolicy    REG_DWORD    0x0
    NoGPOListChanges    REG_DWORD    0x0
    NoMachinePolicy    REG_DWORD    0x0
    NoSlowLink    REG_DWORD    0x0
    NoUserPolicy    REG_DWORD    0x1
    PerUserLocalSettings    REG_DWORD    0x0
    ProcessGroupPolicy    REG_SZ    ProcessGroupPolicy
    RequiresSuccessfulRegistry    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}
    <NO NAME>    REG_SZ    Software Installation
    DllName    REG_EXPAND_SZ    appmgmts.dll
    ProcessGroupPolicyEx    REG_SZ    ProcessGroupPolicyObjectsEx
    GenerateGroupPolicy    REG_SZ    GenerateGroupPolicy
    NoBackgroundPolicy    REG_DWORD    0x0
    RequiresSucessfulRegistry    REG_DWORD    0x0
    NoSlowLink    REG_DWORD    0x1
    PerUserLocalSettings    REG_DWORD    0x1
    EventSources    REG_MULTI_SZ    (Application Management,Application)\0(MsiInstaller,Application)\0\0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}
    <NO NAME>    REG_SZ    IP Security
    ProcessGroupPolicy    REG_SZ    ProcessIPSECPolicy
    DllName    REG_EXPAND_SZ    gptext.dll
    NoUserPolicy    REG_DWORD    0x1
    NoGPOListChanges    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
    Asynchronous    REG_DWORD    0x0
    Impersonate    REG_DWORD    0x0
    DllName    REG_EXPAND_SZ    crypt32.dll
    Logoff    REG_SZ    ChainWlxLogoffEvent

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
    Asynchronous    REG_DWORD    0x0
    Impersonate    REG_DWORD    0x0
    DllName    REG_EXPAND_SZ    cryptnet.dll
    Logoff    REG_SZ    CryptnetWlxLogoffEvent

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
    DLLName    REG_SZ    cscdll.dll
    Logon    REG_SZ    WinlogonLogonEvent
    Logoff    REG_SZ    WinlogonLogoffEvent
    ScreenSaver    REG_SZ    WinlogonScreenSaverEvent
    Startup    REG_SZ    WinlogonStartupEvent
    Shutdown    REG_SZ    WinlogonShutdownEvent
    StartShell    REG_SZ    WinlogonStartShellEvent
    Impersonate    REG_DWORD    0x0
    Asynchronous    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui
    <NO NAME>    REG_SZ    
    DLLName    REG_SZ    igfxdev.dll
    Asynchronous    REG_DWORD    0x1
    Impersonate    REG_DWORD    0x1
    Unlock    REG_SZ    WinlogonUnlockEvent

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
    DLLName    REG_SZ    wlnotify.dll
    Logon    REG_SZ    SCardStartCertProp
    Logoff    REG_SZ    SCardStopCertProp
    Lock    REG_SZ    SCardSuspendCertProp
    Unlock    REG_SZ    SCardResumeCertProp
    Enabled    REG_DWORD    0x1
    Impersonate    REG_DWORD    0x1
    Asynchronous    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
    Asynchronous    REG_DWORD    0x0
    DllName    REG_EXPAND_SZ    wlnotify.dll
    Impersonate    REG_DWORD    0x0
    StartShell    REG_SZ    SchedStartShell
    Logoff    REG_SZ    SchedEventLogOff

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
    Logoff    REG_SZ    WLEventLogoff
    Impersonate    REG_DWORD    0x0
    Asynchronous    REG_DWORD    0x1
    DllName    REG_EXPAND_SZ    sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
    DLLName    REG_SZ    WlNotify.dll
    Lock    REG_SZ    SensLockEvent
    Logon    REG_SZ    SensLogonEvent
    Logoff    REG_SZ    SensLogoffEvent
    Safe    REG_DWORD    0x1
    MaxWait    REG_DWORD    0x258
    StartScreenSaver    REG_SZ    SensStartScreenSaverEvent
    StopScreenSaver    REG_SZ    SensStopScreenSaverEvent
    Startup    REG_SZ    SensStartupEvent
    Shutdown    REG_SZ    SensShutdownEvent
    StartShell    REG_SZ    SensStartShellEvent
    PostShell    REG_SZ    SensPostShellEvent
    Disconnect    REG_SZ    SensDisconnectEvent
    Reconnect    REG_SZ    SensReconnectEvent
    Unlock    REG_SZ    SensUnlockEvent
    Impersonate    REG_DWORD    0x1
    Asynchronous    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
    Asynchronous    REG_DWORD    0x0
    DllName    REG_EXPAND_SZ    wlnotify.dll
    Impersonate    REG_DWORD    0x0
    Logoff    REG_SZ    TSEventLogoff
    Logon    REG_SZ    TSEventLogon
    PostShell    REG_SZ    TSEventPostShell
    Shutdown    REG_SZ    TSEventShutdown
    StartShell    REG_SZ    TSEventStartShell
    Startup    REG_SZ    TSEventStartup
    MaxWait    REG_DWORD    0x258
    Reconnect    REG_SZ    TSEventReconnect
    Disconnect    REG_SZ    TSEventDisconnect

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon
    Asynchronous    REG_DWORD    0x0
    Disconnect    REG_SZ    WLEventDisconnect
    DllName    REG_EXPAND_SZ    WgaLogon.dll
    Event    REG_DWORD    0x1
    Impersonate    REG_DWORD    0x1
    Lock    REG_SZ    WLEventLock
    Logoff    REG_SZ    WLEventLogoff
    Logon    REG_SZ    WLEventLogon
    MaxWait    REG_DWORD    0xffffffff
    PostShell    REG_SZ    WLEventPostShell
    Reconnect    REG_SZ    WLEventReconnect
    SafeMode    REG_DWORD    0x1
    Shutdown    REG_SZ    WLEventShutdown
    StartScreenSaver    REG_SZ    WLEventStartScreenSaver
    StartShell    REG_SZ    WLEventStartShell
    Startup    REG_SZ    WLEventStartup
    StopScreenSaver    REG_SZ    WLEventStopScreenSaver
    Unlock    REG_SZ    WLEventUnlock

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings
    Data    REG_BINARY    01000000D08C9DDF0115D1118C7A00C04FC297EB01000000FABC978A70C2424CBA5FFB0C718885B504000000040000005300000003660000A800000010000000A8F072D54005919BF1EA1065B627CFFF0000000004800000A000000010000000B55AA05E947FE0D105ABD0C67621EC7DB001000074D2C780E3B2ABDE644FCECAD17A5C56347477B239FE9AC01B8486046A347AF0993264F6BD82AD2C77FED3D0E13CFCFEF5D1B75ACA51B03A8B898AED2FCFD55DBF03448C4E82AA4E3C495EFB686AE7F05F4E70796EE0D8637E13E4E8985899223B887A0168D5F15D1126F96D08D382CAC51405A05E597B56FDB74F74B9DE4AC64129E321E8DC2BE4DC7B6DD76807A8104E7A3FEEE92C870F5F818569AF961DEFD2A7788F2FF459D0CF45C0EF21790CCFE81C19713F2D6F9BA863DF4F2C8BA806E0456AE25A0829CE0518992D7153E209B9ACADF0DE93BEDB910DB9B18D1924E87FFF893C279335DF6B7D8D83763DC5675BD0F341A6F0750280164EB8D1ED2FA9248D9908621E36A752C5070AEDC18100C22083312E8AF921649A6B6796440C0B7C7119B889F7C6158550D811C1D381CED28665D397C4221E100EBB2F2A039459DD7159F6461D975511FA4179CCF7FE4C6B539AB81703C9D239A9BC811B140C2B94DED1F2D092969E9760D478C99CB96E895552924CF921BBB1CE7A03262D47051391A916E893A894892B36142F162570FAC0FFE19A574D88F54E0DD49A24E34ED536D3E92191061AE8645D686D7154F41400000084AFA321BF988E5578402AC8DEFE0C2F4C4E0C49

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
    DLLName    REG_SZ    wlnotify.dll
    Logon    REG_SZ    RegisterTicketExpiredNotificationEvent
    Logoff    REG_SZ    UnregisterTicketExpiredNotificationEvent
    Impersonate    REG_DWORD    0x1
    Asynchronous    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
    HelpAssistant    REG_DWORD    0x0
    TsInternetUser    REG_DWORD    0x0
    SQLAgentCmdExec    REG_DWORD    0x0
    NetShowServices    REG_DWORD    0x0
    IWAM_    REG_DWORD    0x10000
    IUSR_    REG_DWORD    0x10000
    VUSR_    REG_DWORD    0x10000

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Credentials

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon
    EventMessageFile    REG_EXPAND_SZ    %SystemRoot%\System32\winlogon.exe
    TypesSupported    REG_DWORD    0x7

! REG.EXE VERSION 3.0

HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    ParseAutoexec    REG_SZ    1
    ExcludeProfileDirs    REG_SZ    Local Settings;Temporary Internet Files;History;Temp
    BuildNumber    REG_DWORD    0xa28

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    ParseAutoexec    REG_SZ    1
    ExcludeProfileDirs    REG_SZ    Local Settings;Temporary Internet Files;History;Temp
    BuildNumber    REG_DWORD    0xa28

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    ParseAutoexec    REG_SZ    1
    ExcludeProfileDirs    REG_SZ    Local Settings;Temporary Internet Files;History;Temp
    BuildNumber    REG_DWORD    0xa28

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    ParseAutoexec    REG_SZ    1
    ExcludeProfileDirs    REG_SZ    Local Settings;Temporary Internet Files;History;Temp
    BuildNumber    REG_DWORD    0xa28

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BootVerificationProgram

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
    Authentication Packages    REG_MULTI_SZ    msv1_0\0\0
    Bounds    REG_BINARY    0030000000200000
    Security Packages    REG_MULTI_SZ    kerberos\0msv1_0\0schannel\0wdigest\0\0
    ImpersonatePrivilegeUpgradeToolHasRun    REG_DWORD    0x1
    LsaPid    REG_DWORD    0x3f0
    SecureBoot    REG_DWORD    0x1
    auditbaseobjects    REG_DWORD    0x0
    crashonauditfail    REG_DWORD    0x0
    disabledomaincreds    REG_DWORD    0x0
    everyoneincludesanonymous    REG_DWORD    0x0
    fipsalgorithmpolicy    REG_DWORD    0x0
    forceguest    REG_DWORD    0x1
    fullprivilegeauditing    REG_BINARY    00
    limitblankpassworduse    REG_DWORD    0x1
    lmcompatibilitylevel    REG_DWORD    0x0
    nodefaultadminowner    REG_DWORD    0x1
    nolmhash    REG_DWORD    0x1
    restrictanonymous    REG_DWORD    0x0
    restrictanonymoussam    REG_DWORD    0x1
    Notification Packages    REG_MULTI_SZ    scecli\0\0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders
    ProviderOrder    REG_MULTI_SZ    Windows NT Access Provider\0\0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider
    ProviderPath    REG_EXPAND_SZ    %SystemRoot%\system32\ntmarta.dll

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\System

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data
    Pattern    REG_BINARY    C4B57FC40F6395C7418E8719D6FF45EB653535636564623600FD07001E16000034FA07004E827C7520FA070040FD07004CFD0700B2F844360A075C7FDD4BCAE5

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG
    GrafBlumGroup    REG_BINARY    1156E3A40DB67D1694

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD
    Lookup    REG_BINARY    F81B94B4D052

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\SidCache

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0
    Auth132    REG_SZ    IISSUBA
    ntlmminclientsec    REG_DWORD    0x0
    ntlmminserversec    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1
    SkewMatrix    REG_BINARY    52951567754E709DAE7FF0F68233AE2E

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4
    SSOURL    REG_SZ    http://www.passport.com

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache
    Time    REG_BINARY    F01E2A508B2ECA01

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll
    Name    REG_SZ    Digest
    Comment    REG_SZ    Digest SSPI Authentication Package
    Capabilities    REG_DWORD    0x4050
    RpcId    REG_DWORD    0xffff
    Version    REG_DWORD    0x1
    TokenSize    REG_DWORD    0xffff
    Time    REG_BINARY    00C65887B579C401
    Type    REG_DWORD    0x31

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll
    Name    REG_SZ    DPA
    Comment    REG_SZ    DPA Security Package
    Capabilities    REG_DWORD    0x37
    RpcId    REG_DWORD    0x11
    Version    REG_DWORD    0x1
    TokenSize    REG_DWORD    0x300
    Time    REG_BINARY    00C65887B579C401
    Type    REG_DWORD    0x31

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll
    Name    REG_SZ    MSN
    Comment    REG_SZ    MSN Security Package
    Capabilities    REG_DWORD    0x37
    RpcId    REG_DWORD    0x12
    Version    REG_DWORD    0x1
    TokenSize    REG_DWORD    0x300
    Time    REG_BINARY    00C65887B579C401
    Type    REG_DWORD    0x31

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA
    ParameterMessageFile    REG_EXPAND_SZ    %SystemRoot%\System32\MsObjs.dll

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA\ObjectNames
    PolicyObject    REG_DWORD    0x1600
    SecretObject    REG_DWORD    0x1610
    TrustedDomainObject    REG_DWORD    0x1620
    UserAccountObject    REG_DWORD    0x1630

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot
    AlternateShell    REG_SZ    cmd.exe

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmadmin
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmboot.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmio.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmload.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmserver
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys
    <NO NAME>    REG_SZ    FSFilter System Recovery

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SRService
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vga.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}
    <NO NAME>    REG_SZ    Universal Serial Bus controllers

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    CD-ROM Drive

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    DiskDrive

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    Standard floppy disk controller

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    Hdc

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    Keyboard

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    Mouse

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    PCMCIA Adapters

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    SCSIAdapter

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    System

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    Floppy disk drive

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}
    <NO NAME>    REG_SZ    Volume

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
    <NO NAME>    REG_SZ    Human Interface Devices

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmadmin
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmboot.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmio.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmload.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmserver
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ip6fw.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nm
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nm.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NtLmSsp
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpcdd.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpdd.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpwd.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sr.sys
    <NO NAME>    REG_SZ    FSFilter System Recovery

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SRService
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI
    <NO NAME>    REG_SZ    Driver Group

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdpipe.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdtcp.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\termservice
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vga.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vgasave.sys
    <NO NAME>    REG_SZ    Driver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WZCSVC
    <NO NAME>    REG_SZ    Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}
    <NO NAME>    REG_SZ    Universal Serial Bus controllers

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    CD-ROM Drive

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    DiskDrive

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    Standard floppy disk controller

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    Hdc

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    Keyboard

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    Mouse

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    Net

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    NetClient

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    NetService

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    NetTrans

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    PCMCIA Adapters

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    SCSIAdapter

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    System

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}
    <NO NAME>    REG_SZ    Floppy disk drive

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}
    <NO NAME>    REG_SZ    Volume

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
    <NO NAME>    REG_SZ    Human Interface Devices

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders
    SecurityProviders    REG_SZ    msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SaslProfiles
    GSSAPI    REG_SZ    Kerberos

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL
    EventLogging    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\DES 56/56

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\NULL

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 128/128

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 40/128

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 56/128

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 128/128

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 40/128

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 56/128

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\Triple DES 168/168

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Hashes

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Hashes\MD5

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Hashes\SHA

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\KeyExchangeAlgorithms

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\KeyExchangeAlgorithms\Diffie-Hellman

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\KeyExchangeAlgorithms\PKCS

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\Multi-Protocol Unified Hello

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\Multi-Protocol Unified Hello\Client

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\Multi-Protocol Unified Hello\Server

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0\Client

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0\Server

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Client

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Server

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Client

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Server

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Client

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Server

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest
    Lifetime    REG_DWORD    0x8ca0
    Negotiate    REG_DWORD    0x0
    UTF8HTTP    REG_DWORD    0x1
    UTF8SASL    REG_DWORD    0x1

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\CWD

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\CWD\ff060102423da0000407108e0500

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\CWD\ff060102423da0000407108e0500\1
    Add1    REG_BINARY    021540A0101EB823008ED88B0E140781E100021FC3
    Change1    REG_BINARY    011D50480C558BECB800009C5981E10002558BECB80000E8E757909090

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBI01

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBI01\ff06010242935100040720730500

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBI01\ff06010242935100040720730500\1
    Change1    REG_BINARY    0149D0182245558BEC1EB44332C0C55606CD211F720AC45E0A26890F33C0EB0450E8FA025D4DCB558BEC1EB80043C55606CD211F720DC45E0A80E11F26890F33C0EB0450E8FA025DCB

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBI02

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBI02\ff06010242468300040790c80400

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBI02\ff06010242468300040790c80400\1
    Change1    REG_BINARY    015112462645558BEC56571EB44332C0C55606CD211F720AC45E0A26890F33C0EB0450E84B035F5E5D4DCB45558BEC1EB44332C0C55606CD211F720AC45E0A80E11F26890F33C0EB0450E84B035D4DCB90

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBIN

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBIN\ff0601024cab7b000407b0ea0400

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBIN\ff0601024cab7b000407b0ea0400\2
    Change1    REG_BINARY    0115F03B083D035F7403E906003D035F9090E90600

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTSCR

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTSCR\ff060102c47b1f00040750db0100

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTSCR\ff060102c47b1f00040750db0100\e
    Change1    REG_BINARY    0113841E0745558BEC68002045558BEC680220

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\LTSPRINT

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\LTSPRINT\ff060102424f3f000306706600

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\LTSPRINT\ff060102424f3f000306706600\1
    Change1    REG_BINARY    010B9C1C033D00013D0006

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\MYST

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\MYST\ff060102423bab000407102e0600

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\MYST\ff060102423bab000407102e0600\1
    Add1    REG_BINARY    021540AB101EB823008ED88B0E140781E100021FC3
    Change1    REG_BINARY    011D50490C558BECB800009C5981E10002558BECB80000E8E761909090

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\OUTPOST

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\OUTPOST\ff06010242410f000306801500

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\OUTPOST\ff06010242410f000306801500\1
    Change1    REG_BINARY    010F090A059A7305FF01B8030A9090

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\PALED40

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\PALED40\ff060102420032000407401b0100

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\PALED40\ff060102420032000407401b0100\1
    Change1    REG_BINARY    0107B72101D80C

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601024211e100040750e50700

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601024211e100040750e50700\1
    Change1    REG_BINARY    011D3FE00C8B46E88B56EA2B46FA1B56FCB85001BA0000909090909090

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601024237e6000407d00e0800

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601024237e6000407d00e0800\1
    Change1    REG_BINARY    011D65E50C8B46E88B56EA2B46FA1B56FCB85001BA0000909090909090

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff060102428203000306401600

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff060102428203000306401600\1
    Change1    REG_BINARY    010F28030533ED559A13B8004CCD21

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601025621ef000407f07a0700

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601025621ef000407f07a0700\3
    Change1    REG_BINARY    011DF3450C8B4EF08B5EF22B4EF41B5EF6B95001BB0000909090909090

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601025642ea00040750550700

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601025642ea00040750550700\3
    Change1    REG_BINARY    011DB7410C8B4EF08B5EF22B4EF41B5EF6B95001BB0000909090909090

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff060102564ee6000407b0670700

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff060102564ee6000407b0670700\3
    Change1    REG_BINARY    01157C3508668B46FC662B46F066B8500100009090

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff060102565ce5000407d0600700

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff060102565ce5000407d0600700\3
    Change1    REG_BINARY    011DFD340C8B4EF08B5EF22B4EF41B5EF6B95001BB0000909090909090

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601025674e6000407704d0700

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601025674e6000407704d0700\3
    Change1    REG_BINARY    011DCF3D0C8B4EF08B5EF22B4EF41B5EF6B95001BB0000909090909090

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256b1dd00040760ef0b00

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256b1dd00040760ef0b00\3
    Change1    REG_BINARY    01152C3B08668B46F0662B46F466B8500100009090

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256c1ef00040770fb0600

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256c1ef00040770fb0600\3
    Change1    REG_BINARY    011DFD380C8B46F08B56F22B46F41B56F6B85001BA0000909090909090

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256e2e400040750600700

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256e2e400040750600700\3
    Change1    REG_BINARY    011DFD340C8B4EF08B5EF22B4EF41B5EF6B95001BB0000909090909090

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256eae500040710640700

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256eae500040710640700\3
    Change1    REG_BINARY    011DFD340C8B4EF08B5EF22B4EF41B5EF6B95001BB0000909090909090

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256faef00040710c50600

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256faef00040710c50600\3
    Change1    REG_BINARY    011DB7330C8B46F08B56F22B46F41B56F6B85001BA0000909090909090

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP16

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP16\ff0601024cd875000407a0db0100

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP16\ff0601024cd875000407a0db0100\2
    Change1    REG_BINARY    012317420F8BC88BD08B5E0E2AE489078ACD2AEDB90A00BA030A8B5E0E2AE490909090

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\USA

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\USA\ff06010242059b00040710780600

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\USA\ff06010242059b00040710780600\1
    Change1    REG_BINARY    011D95440C558BECB800009C5981E10002558BECB80000E86756909090
    Change2    REG_BINARY    0125059B10000000000000000000000000000000001EB823008ED88B0E140781E100021FC3

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\VB

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\VB\ff060102ec353f00040780c81300

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\VB\ff060102ec353f00040780c81300\12
    Change1    REG_BINARY    01111B0306813EBA313403813EBA310903

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\VB40016

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\VB40016\ff0702021401ee3e000407d0460e00

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\VB40016\ff0702021401ee3e000407d0460e00\16
    Change1    REG_BINARY    01116D2A06813E6E363403813E6E360903

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\WISE0001

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\WISE0001\ff0601024cf4ef000407604e0100

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\WISE0001\ff0601024cf4ef000407604e0100\2
    Change1    REG_BINARY    010F8E00059A4B000F02B80C299090

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\DOS Devices
    AUX    REG_SZ    \DosDevices\COM1
    MAILSLOT    REG_SZ    \Device\MailSlot
    NUL    REG_SZ    \Device\Null
    PIPE    REG_SZ    \Device\NamedPipe
    PRN    REG_SZ    \DosDevices\LPT1
    UNC    REG_SZ    \Device\Mup

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment
    ComSpec    REG_EXPAND_SZ    %SystemRoot%\system32\cmd.exe
    Path    REG_EXPAND_SZ    %SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\PROGRA~1\DISKEE~1\DISKEE~1\
    windir    REG_EXPAND_SZ    %SystemRoot%
    FP_NO_HOST_CHECK    REG_SZ    NO
    OS    REG_SZ    Windows_NT
    PROCESSOR_ARCHITECTURE    REG_SZ    x86
    PROCESSOR_LEVEL    REG_SZ    15
    PROCESSOR_IDENTIFIER    REG_SZ    x86 Family 15 Model 4 Stepping 10, GenuineIntel
    PROCESSOR_REVISION    REG_SZ    040a
    NUMBER_OF_PROCESSORS    REG_SZ    2
    TEMP    REG_EXPAND_SZ    %SystemRoot%\TEMP
    TMP    REG_EXPAND_SZ    %SystemRoot%\TEMP
    PATHEXT    REG_SZ    .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Executive
    AdditionalCriticalWorkerThreads    REG_DWORD    0x0
    AdditionalDelayedWorkerThreads    REG_DWORD    0x0
    PriorityQuantumMatrix    REG_BINARY    1861A25F000000003F2ECA01

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\FileRenameOperations

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\kernel
    ObUnsecureGlobalNames    REG_MULTI_SZ    netfxcustomperfcounters.1.0\0SharedPerfIPCBlock\0Cor_Private_IPCBlock\0\0
    obcaseinsensitive    REG_DWORD    0x1

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs
    advapi32    REG_SZ    advapi32.dll
    comdlg32    REG_SZ    comdlg32.dll
    DllDirectory    REG_EXPAND_SZ    %SystemRoot%\system32
    gdi32    REG_SZ    gdi32.dll
    imagehlp    REG_SZ    imagehlp.dll
    kernel32    REG_SZ    kernel32.dll
    lz32    REG_SZ    lz32.dll
    ole32    REG_SZ    ole32.dll
    oleaut32    REG_SZ    oleaut32.dll
    olecli32    REG_SZ    olecli32.dll
    olecnv32    REG_SZ    olecnv32.dll
    olesvr32    REG_SZ    olesvr32.dll
    olethk32    REG_SZ    olethk32.dll
    rpcrt4    REG_SZ    rpcrt4.dll
    shell32    REG_SZ    shell32.dll
    url    REG_SZ    url.dll
    urlmon    REG_SZ    urlmon.dll
    user32    REG_SZ    user32.dll
    version    REG_SZ    version.dll
    wininet    REG_SZ    wininet.dll
    wldap32    REG_SZ    wldap32.dll

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
    ClearPageFileAtShutdown    REG_DWORD    0x0
    DisablePagingExecutive    REG_DWORD    0x0
    LargeSystemCache    REG_DWORD    0x0
    NonPagedPoolQuota    REG_DWORD    0x0
    NonPagedPoolSize    REG_DWORD    0x0
    PagedPoolQuota    REG_DWORD    0x0
    PagedPoolSize    REG_DWORD    0x0
    SecondLevelDataCache    REG_DWORD    0x0
    SystemPages    REG_DWORD    0xc3000
    PagingFiles    REG_MULTI_SZ    C:\pagefile.sys 1024 2048\0\0
    PhysicalAddressExtension    REG_DWORD    0x0
    SessionViewSize    REG_DWORD    0x30
    SessionPoolSize    REG_DWORD    0x4

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters
    VideoInitTime    REG_DWORD    0xda
    EnablePrefetcher    REG_DWORD    0x3
    AppLaunchMaxNumPages    REG_DWORD    0xfa0
    AppLaunchMaxNumSections    REG_DWORD    0xaa
    AppLaunchTimerPeriod    REG_BINARY    806967FFFFFFFFFF
    BootMaxNumPages    REG_DWORD    0x1f400
    BootMaxNumSections    REG_DWORD    0xff0
    BootTimerPeriod    REG_BINARY    00F2D8F8FFFFFFFF
    MaxNumActiveTraces    REG_DWORD    0x8
    MaxNumSavedTraces    REG_DWORD    0x8
    RootDirPath    REG_SZ    Prefetch
    HostingAppList    REG_SZ    DLLHOST.EXE,MMC.EXE,RUNDLL32.EXE

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Power
    AcProcessorPolicy    REG_BINARY    01000000000000000000000003000000A0860100A0860100A08601002832000002000000A0860100A0860100A0860100283C000003000000A0860100A0860100A08601002850000001000000
    DcProcessorPolicy    REG_BINARY    01000000030000000000000003000000A0860100A0860100A08601000A14000002000000A0860100A0860100A08601001428000003000000A0860100A0860100A08601001446000001000000
    AcPolicy    REG_BINARY    010000000000000003000000100000000200000003000000000000000200000001000000000000000100000000000000020000000100000000000000000000003200584802000000040000000200000001000000304E16000000000003000000010000000300000003000000000000C00100000005000000010000000A00000000000000030000000100010001000000000000000000000000000000000000000000020000000000000000000000000000000000000000000000030000000000B004000071FB907C34F20600FEE1907CF4F20600000000000164643202000000040000C000000000
    DcPolicy    REG_BINARY    0100000000000000030000001000000002000000030000000000000002000000010000000000000001000000FFFF00000200000000000000000000002C01000032032D0004000000040000000200000001000000330030008403000003000000010000000300000003000000000000C00100000005000000010000000A000000000000000300000001000100010000000000000000000000000000000000000000000200000000000000000000000000000000000000000000000300000000002C01000001000000000000000000000000000000580200000150643202000000040000C000000000

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SFC
    ProgramFilesDir    REG_SZ    C:\Program Files
    CommonFilesDir    REG_SZ    C:\Program Files\Common Files

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems
    Debug    REG_EXPAND_SZ    
    Kmode    REG_EXPAND_SZ    %SystemRoot%\system32\win32k.sys
    Optional    REG_MULTI_SZ    Posix\0\0
    Posix    REG_EXPAND_SZ    %SystemRoot%\system32\psxss.exe
    Required    REG_MULTI_SZ    Debug\0Windows\0\0
    Windows    REG_EXPAND_SZ    %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\CSRSS
    CsrSrvSharedSectionBase    REG_DWORD    0x7f6f0000

! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Syncmgr\Handlers

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACDSeePro40ImportPicturesOnArrival
    Action    REG_SZ    Import pictures
    Provider    REG_SZ    ACDSee Pro 4
    InvokeProgID    REG_SZ    ACDSee Pro 4.AutoPlayHandlerImport
    InvokeVerb    REG_SZ    Import
    DefaultIcon    REG_SZ    C:\Program Files\ACD Systems\ACDSee Pro\4.0\ACDSeeQVPro4.exe,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACDSeePro40ImportVideoFilesOnArrival
    Action    REG_SZ    Import videos
    Provider    REG_SZ    ACDSee Pro 4
    InvokeProgID    REG_SZ    ACDSee Pro 4.AutoPlayHandlerImport
    InvokeVerb    REG_SZ    Import
    DefaultIcon    REG_SZ    C:\Program Files\ACD Systems\ACDSee Pro\4.0\ACDSeeQVPro4.exe,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACDSeePro40PlayVideoFilesOnArrival
    Action    REG_SZ    Manage videos
    Provider    REG_SZ    ACDSee Pro 4
    InvokeProgID    REG_SZ    ACDSee Pro 4.AutoPlayHandler
    InvokeVerb    REG_SZ    Open
    DefaultIcon    REG_SZ    C:\Program Files\ACD Systems\ACDSee Pro\4.0\ACDSeeQVPro4.exe,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACDSeePro40ShowPicturesOnArrival
    Action    REG_SZ    Manage pictures
    Provider    REG_SZ    ACDSee Pro 4
    InvokeProgID    REG_SZ    ACDSee Pro 4.AutoPlayHandler
    InvokeVerb    REG_SZ    Open
    DefaultIcon    REG_SZ    C:\Program Files\ACD Systems\ACDSee Pro\4.0\ACDSeeQVPro4.exe,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MPCPlayCDAudioOnArrival
    Action    REG_SZ    Play Audio CD
    DefaultIcon    REG_SZ    "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe",4
    InvokeProgID    REG_SZ    MediaPlayerClassic.Autorun
    InvokeVerb    REG_SZ    PlayCDAudio
    Provider    REG_SZ    Media Player Classic

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MPCPlayDVDMovieOnArrival
    Action    REG_SZ    Play DVD Movie
    DefaultIcon    REG_SZ    "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe",3
    InvokeProgID    REG_SZ    MediaPlayerClassic.Autorun
    InvokeVerb    REG_SZ    PlayDVDMovie
    Provider    REG_SZ    Media Player Classic

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MPCPlayMusicFilesOnArrival
    Action    REG_SZ    Play Music
    DefaultIcon    REG_SZ    "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe",0
    InvokeProgID    REG_SZ    MediaPlayerClassic.Autorun
    InvokeVerb    REG_SZ    PlayMusicFiles
    Provider    REG_SZ    Media Player Classic

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MPCPlayVideoFilesOnArrival
    Action    REG_SZ    Play Video
    DefaultIcon    REG_SZ    "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe",0
    InvokeProgID    REG_SZ    MediaPlayerClassic.Autorun
    InvokeVerb    REG_SZ    PlayVideoFiles
    Provider    REG_SZ    Media Player Classic

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSCDBurningOnArrival
    DefaultIcon    REG_EXPAND_SZ    %SystemRoot%\system32\SHELL32.dll,-5
    Action    REG_SZ    @%SystemRoot%\system32\SHELL32.dll,-17169
    Provider    REG_SZ    @%SystemRoot%\system32\SHELL32.dll,-17170
    InvokeProgID    REG_SZ    Folder
    InvokeVerb    REG_SZ    open

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSOpenFolder
    DefaultIcon    REG_EXPAND_SZ    %SystemRoot%\system32\SHELL32.dll,-5
    Action    REG_SZ    @%SystemRoot%\system32\SHELL32.dll,-17154
    Provider    REG_SZ    @%SystemRoot%\system32\SHELL32.dll,-17155
    InvokeProgID    REG_SZ    Folder
    InvokeVerb    REG_SZ    open

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPlayCDAudioOnArrival
    Action    REG_SZ    @wmploc.dll,-6503
    Provider    REG_SZ    @wmploc.dll,-6502
    InvokeProgID    REG_SZ    WMP.AudioCD
    InvokeVerb    REG_SZ    play
    DefaultIcon    REG_EXPAND_SZ    %ProgramFiles%\Windows Media Player\wmplayer.exe,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPlayDVDMovieOnArrival
    Action    REG_SZ    @wmploc.dll,-6504
    Provider    REG_SZ    @wmploc.dll,-6502
    InvokeProgID    REG_SZ    WMP.DVD
    InvokeVerb    REG_SZ    play
    DefaultIcon    REG_EXPAND_SZ    %ProgramFiles%\Windows Media Player\wmplayer.exe,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPlayMediaOnArrival
    Action    REG_SZ    @wmploc.dll,-1800
    Provider    REG_SZ    @wmploc.dll,-6502
    InvokeProgid    REG_SZ    WMP.PlayMedia
    InvokeVerb    REG_SZ    play
    DefaultIcon    REG_SZ    C:\Program Files\Windows Media Player\wmplayer.exe,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPrintPicturesOnArrival
    DefaultIcon    REG_EXPAND_SZ    %SystemRoot%\system32\SHELL32.dll,-17
    Action    REG_SZ    @%SystemRoot%\system32\SHELL32.dll,-17158
    Provider    REG_SZ    @%SystemRoot%\system32\SHELL32.dll,-17159
    InvokeProgID    REG_SZ    Applications\shimgvw.dll
    InvokeVerb    REG_SZ    print

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPromptEachTime
    DefaultIcon    REG_EXPAND_SZ    %SystemRoot%\system32\SHELL32.dll,-3
    Action    REG_SZ    Prompt each time
    Provider    REG_SZ    Windows Explorer
    ProgID    REG_SZ    Shell.Autoplay
    InitCmdLine    REG_SZ    PromptEachTime

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPromptEachTimeNoContent
    DefaultIcon    REG_EXPAND_SZ    %SystemRoot%\system32\SHELL32.dll,-3
    Action    REG_SZ    Prompt each time - No Content
    Provider    REG_SZ    Windows Explorer
    ProgID    REG_SZ    Shell.Autoplay
    InitCmdLine    REG_SZ    PromptEachTimeNoContent

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSRipCDAudioOnArrival
    Action    REG_SZ    @wmploc.dll,-6506
    Provider    REG_SZ    @wmploc.dll,-6502
    InvokeProgID    REG_SZ    WMP.RipCD
    InvokeVerb    REG_SZ    Rip
    DefaultIcon    REG_EXPAND_SZ    %ProgramFiles%\Windows Media Player\wmplayer.exe,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSSHAudioDevHandler
    <NO NAME>    REG_SZ    
    Action    REG_SZ    @%SystemRoot%\system32\Audiodev.dll,-500
    Provider    REG_SZ    @%SystemRoot%\system32\Audiodev.dll,-501
    DefaultIcon    REG_EXPAND_SZ    %SystemRoot%\system32\Audiodev.dll,-50
    ProgID    REG_SZ    Shell.HWEventHandlerShellExecute
    InitCmdLine    REG_SZ    ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{21EC2020-3AEA-1069-A2DD-08002B30309D}\::{640167b4-59b0-47a6-b335-a6b3c0695aea}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSShowPicturesOnArrival
    DefaultIcon    REG_EXPAND_SZ    %SystemRoot%\system32\SHELL32.dll,-249
    Action    REG_SZ    @%SystemRoot%\system32\SHELL32.dll,-17156
    Provider    REG_SZ    @%SystemRoot%\system32\SHELL32.dll,-17157
    InvokeProgID    REG_SZ    Shell.AutoplayForSlideShow.1
    InvokeVerb    REG_SZ    open

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSTakeNoAction
    DefaultIcon    REG_EXPAND_SZ    %SystemRoot%\system32\SHELL32.dll,-338
    Action    REG_SZ    @%SystemRoot%\system32\SHELL32.dll,-17168
    Provider    REG_SZ    <TakeNoAction>
    ProgID    REG_SZ    Shell.AutoplaySpecial

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSVideoCameraArrival
    InitCmdLine    REG_SZ    "C:\Program Files\Movie Maker\moviemk.exe" /RECORD
    ProgID    REG_SZ    Shell.HWEventHandlerShellExecute
    DefaultIcon    REG_SZ    C:\Program Files\Movie Maker\moviemk.exe,0
    CLSIDForCancel    REG_SZ    {AB007EC8-E2D4-4664-ACD9-1D059681F3DE}
    Action    REG_SZ    @C:\Program Files\Movie Maker\wmm2res.dll,-63095
    Provider    REG_SZ    @C:\Program Files\Movie Maker\wmm2res.dll,-100

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSWiaEventHandler
    ProgID    REG_SZ    WiaDevMgr
    Action    REG_SZ    @%systemroot%\System32\wiaacmgr.exe,-276
    Provider    REG_SZ    @%systemroot%\System32\wiaacmgr.exe,-101
    DefaultIcon    REG_EXPAND_SZ    %systemroot%\System32\wiaacmgr.exe,-2
    InvokeProgID    REG_SZ    WIA.AutoplayDropHandler.1
    InvokeVerb    REG_SZ    open

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSWMDMHandler
    Action    REG_SZ    @wmploc.dll,-29300
    CLSIDForCancel    REG_SZ    {91778246-9BE4-4713-A651-E833B853CC30}
    DefaultIcon    REG_EXPAND_SZ    %ProgramFiles%\Windows Media Player\wmplayer.exe,0
    ProgID    REG_SZ    WMP.Device
    Provider    REG_SZ    @wmploc.dll,-6502
    InitCmdLine    REG_EXPAND_SZ    "%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:3 /task:PortableDevice

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSWMPBurnCDOnArrival
    Action    REG_SZ    @wmploc.dll,-6505
    Provider    REG_SZ    @wmploc.dll,-6502
    InvokeProgID    REG_SZ    WMP.BurnCD
    InvokeVerb    REG_SZ    Burn
    DefaultIcon    REG_EXPAND_SZ    %ProgramFiles%\Windows Media Player\wmplayer.exe,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\NeroAutoPlay7AudioToNeroDigital
    Action    REG_SZ    Convert Audio CDs to Nero Digital Audio
    DefaultIcon    REG_SZ    C:\Program Files\Common Files\Ahead\Lib\ShellManager.dll,-501
    Provider    REG_SZ    Nero Burning ROM
    InvokeProgID    REG_SZ    Nero.AutoPlay7
    InvokeVerb    REG_SZ    AudioToNeroDigital_PlayCDAudioOnArrival

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\NeroAutoPlay7CDAudio
    Action    REG_SZ    Make Audio CD
    DefaultIcon    REG_SZ    C:\Program Files\Common Files\Ahead\Lib\ShellManager.dll,-503
    Provider    REG_SZ    Nero Express
    InvokeProgID    REG_SZ    Nero.AutoPlay7
    InvokeVerb    REG_SZ    CDAudio_HandleCDBurningOnArrival

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\NeroAutoPlay7CopyCD
    Action    REG_SZ    Copy CD
    DefaultIcon    REG_SZ    C:\Program Files\Common Files\Ahead\Lib\ShellManager.dll,-504
    Provider    REG_SZ    Nero Burning ROM
    InvokeProgID    REG_SZ    Nero.AutoPlay7
    InvokeVerb    REG_SZ    CopyCD_PlayMusicFilesOnArrival

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\NeroAutoPlay7DataDisc
    Action    REG_SZ    Make Data Disc
    DefaultIcon    REG_SZ    C:\Program Files\Common Files\Ahead\Lib\ShellManager.dll,-505
    Provider    REG_SZ    Nero Express
    InvokeProgID    REG_SZ    Nero.AutoPlay7
    InvokeVerb    REG_SZ    DataDisc_HandleCDBurningOnArrival

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\NeroAutoPlay7LaunchNeroStartSmart
    Action    REG_SZ    Create Your Own Disc
    DefaultIcon    REG_SZ    C:\Program Files\Common Files\Ahead\Lib\ShellManager.dll,-508
    Provider    REG_SZ    Nero StartSmart
    InvokeProgID    REG_SZ    Nero.AutoPlay7
    InvokeVerb    REG_SZ    LaunchNeroStartSmart_HandleCDBurningOnArrival

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\NeroAutoPlay7RipCD
    Action    REG_SZ    Convert Audio CDs to Audio Files
    DefaultIcon    REG_SZ    C:\Program Files\Common Files\Ahead\Lib\ShellManager.dll,-511
    Provider    REG_SZ    Nero Burning ROM
    InvokeProgID    REG_SZ    Nero.AutoPlay7
    InvokeVerb    REG_SZ    RipCD_PlayCDAudioOnArrival

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\NeroAutoPlay7VideoCapture
    Action    REG_SZ    Capture Video
    DefaultIcon    REG_SZ    C:\Program Files\Common Files\Ahead\Lib\ShellManager.dll,-502
    Provider    REG_SZ    Nero Vision
    ProgID    REG_SZ    Shell.HWEventHandlerShellExecute
    InitCmdLine    REG_SZ    "C:\Program Files\Nero\Nero 7\Nero Vision\NeroVision.exe" /New:VideoCapture

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Syncmgr\Handlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Syncmgr\Handlers\{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}
    <NO NAME>    REG_SZ    WebCheck SyncMgr Handler

! REG.EXE VERSION 3.0

HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Syncmgr\Handlers

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Syncmgr\Handlers

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Syncmgr\Handlers

! REG.EXE VERSION 3.0

HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Syncmgr\Handlers

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Clock.ini
    <NO NAME>    REG_SZ    #USR:Software\Microsoft\Clock

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\control.ini
    Color Schemes    REG_SZ    #USR:Control Panel\Color Schemes
    Current    REG_SZ    #USR:Control Panel\Current
    Custom Colors    REG_SZ    #USR:Control Panel\Custom Colors
    don't load    REG_SZ    USR:Control Panel\don't load
    drivers.desc    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\drivers.desc
    MMCPL    REG_SZ    USR:Control Panel\MMCPL
    Patterns    REG_SZ    #USR:Control Panel\Patterns
    related.desc    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\related.desc
    Screen Saver.3DFlowerBox    REG_SZ    USR:Control Panel\Screen Saver.3DFlowerBox
    Screen Saver.3DFlyingObj    REG_SZ    USR:Control Panel\Screen Saver.3DFlyingObj
    Screen Saver.3DMaze    REG_SZ    USR:Control Panel\Screen Saver.3DMaze
    Screen Saver.3DPipes    REG_SZ    USR:Control Panel\Screen Saver.3DPipes
    Screen Saver.3DText    REG_SZ    USR:Control Panel\Screen Saver.3DText
    Screen Saver.Bezier    REG_SZ    USR:Control Panel\Screen Saver.Bezier
    Screen Saver.Marquee    REG_SZ    #USR:Control Panel\Screen Saver.Marquee
    Screen Saver.Mystify    REG_SZ    #USR:Control Panel\Screen Saver.Mystify
    Screen Saver.Stars    REG_SZ    #USR:Control Panel\Screen Saver.Stars
    Userinstallable.drivers    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\Userinstallable.drivers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\ImageFileExecutionOptions.ini
    <NO NAME>    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\Image File Execution Options

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Irremote.ini
    Nero Home    REG_SZ    USR:Software\Ahead\Shared\RemoteCtrl\HppgeIni\Nero Home
    Nero Home Essentials    REG_SZ    USR:Software\Ahead\Shared\RemoteCtrl\HppgeIni\Nero Home
    Nero Home Essentials SE    REG_SZ    USR:Software\Ahead\Shared\RemoteCtrl\HppgeIni\Nero Home

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Irremote.ini\Applications
    Default    REG_SZ    USR:Software\Ahead\Shared\RemoteCtrl\HppgeIni\Applications
    Nero Home    REG_SZ    USR:Software\Ahead\Shared\RemoteCtrl\HppgeIni\Applications
    Nero Home Essentials    REG_SZ    USR:Software\Ahead\Shared\RemoteCtrl\HppgeIni\Applications
    Nero Home Essentials SE    REG_SZ    USR:Software\Ahead\Shared\RemoteCtrl\HppgeIni\Applications

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\KeyboardLayout.ini
    <NO NAME>    REG_SZ    
    Preload    REG_SZ    USR:Keyboard Layout\Preload

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\KeyboardLayout.ini\Keyboard Layout
    <NO NAME>    REG_SZ    \Registry\Machine\System\CurrentControlSet\Control\Keyboard Layout
    Active    REG_SZ    USR:Keyboard Layout

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\KeyboardLayout.ini\Substitutes
    <NO NAME>    REG_SZ    USR:Keyboard Layout\Substitutes

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\msacm.ini
    <NO NAME>    REG_SZ    USR:Software\Microsoft\Multimedia\Audio Compression Manager

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Ntbackup.ini
    <NO NAME>    REG_SZ    #USR:Software\Microsoft\Ntbackup

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\ntnet.ini
    <NO NAME>    REG_SZ    USR:Software\Microsoft\Windows NT\CurrentVersion\Network
    Shared Parameters    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\Network\World Full Access Shared Parameters
    SMAddOns    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\Network\SMAddOns
    UMAddOns    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\Network\UMAddOns

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\regedt32.ini
    <NO NAME>    REG_SZ    USR:Software\Microsoft\RegEdt32

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\schdpl32.ini
    <NO NAME>    REG_SZ    USR:Software\Microsoft\Schedule+

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini
    boot.description    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot.description
    drivers    REG_SZ    #SYS:Microsoft\Windows NT\CurrentVersion\drivers
    drivers32    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\Drivers32
    keyboard    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\WOW\keyboard
    MCI    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\MCI
    MCI32    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\MCI32
    msacm.drv    REG_SZ    USR:Software\Microsoft\Multimedia\Sound Mapper
    NonWindowsApp    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\WOW\NonWindowsApp
    standard    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\WOW\standard

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\boot
    <NO NAME>    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot
    ScreenSaverActive    REG_SZ    USR:Control Panel\Desktop
    ScreenSaverIsSecure    REG_SZ    USR:Control Panel\Desktop
    SCRNSAVE.EXE    REG_SZ    USR:Control Panel\Desktop
    Shell    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\Winlogon

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini
    AeDebug    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\AeDebug
    Clock    REG_SZ    #USR:Software\Microsoft\Clock
    Colors    REG_SZ    #USR:Control Panel\Colors
    Compatibility    REG_SZ    #SYS:Microsoft\Windows NT\CurrentVersion\Compatibility
    Console    REG_SZ    USR:Console
    Cursors    REG_SZ    #USR:Control Panel\Cursors
    DeskTop    REG_SZ    #USR:Control Panel\Desktop
    Devices    REG_SZ    USR:Software\Microsoft\Windows NT\CurrentVersion\Devices
    Embedding    REG_SZ    !#SYS:Microsoft\Windows NT\CurrentVersion\Embedding
    Extensions    REG_SZ    #USR:Software\Microsoft\Windows NT\CurrentVersion\Extensions
    Fonts    REG_SZ    #SYS:Microsoft\Windows NT\CurrentVersion\Fonts
    FontSubstitutes    REG_SZ    #SYS:Microsoft\Windows NT\CurrentVersion\FontSubstitutes
    GRE_Initialize    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\GRE_Initialize
    Intl    REG_SZ    #USR:Control Panel\International
    IOProcs    REG_SZ    #USR:Control Panel\IOProcs
    MCI Extensions    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\MCI Extensions
    ModuleCompatibility    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\ModuleCompatibility
    MSCharMap    REG_SZ    #USR:Software\Microsoft\Charmap
    Net_Files    REG_SZ    USR:Software\Microsoft\Windows NT\CurrentVersion\Network\Persistent Connections
    NWCS    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\NWCS
    Ports    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\Ports
    PrinterPorts    REG_SZ    USR:Software\Microsoft\Windows NT\CurrentVersion\PrinterPorts
    Sounds    REG_SZ    #USR:Control Panel\Sounds
    TrueType    REG_SZ    #USR:Software\Microsoft\Windows NT\CurrentVersion\TrueType
    Twain    REG_SZ    #USR:Software\Microsoft\Windows NT\CurrentVersion\Twain
    Windows Help    REG_SZ    USR:Software\Microsoft\Windows Help
    Winlogon    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\Winlogon

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Network
    <NO NAME>    REG_SZ    USR:Software\Microsoft\Windows NT\CurrentVersion\Network\Persistent Connections
    ExpandLogonDomain    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\Network\World Full Access Shared Parameters

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows
    <NO NAME>    REG_SZ    USR:Software\Microsoft\Windows NT\CurrentVersion\Windows
    AppInit_DLLs    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\Windows
    Beep    REG_SZ    #USR:Control Panel\Sound
    BorderWidth    REG_SZ    #USR:Control Panel\Desktop\WindowMetrics
    CoolSwitch    REG_SZ    USR:Control Panel\Desktop
    CursorBlinkRate    REG_SZ    #USR:Control Panel\Desktop
    DefaultSeparateVDM    REG_SZ    \Registry\Machine\System\CurrentControlSet\Control\WOW
    DeviceNotSelectedTimeout    REG_SZ    #SYS:Microsoft\Windows NT\CurrentVersion\Windows
    DoubleClickHeight    REG_SZ    #USR:Control Panel\Mouse
    DoubleClickSpeed    REG_SZ    #USR:Control Panel\Mouse
    DoubleClickWidth    REG_SZ    #USR:Control Panel\Mouse
    DragFullWindows    REG_SZ    USR:Control Panel\Desktop
    InitialKeyboardIndicators    REG_SZ    USR:Control Panel\Keyboard
    KeyboardDelay    REG_SZ    #USR:Control Panel\Keyboard
    KeyboardSpeed    REG_SZ    #USR:Control Panel\Keyboard
    LowPowerActive    REG_SZ    #USR:Control Panel\Desktop
    LowPowerTimeOut    REG_SZ    #USR:Control Panel\Desktop
    MouseSpeed    REG_SZ    #USR:Control Panel\Mouse
    MouseThreshold1    REG_SZ    #USR:Control Panel\Mouse
    MouseThreshold2    REG_SZ    #USR:Control Panel\Mouse
    PowerOffActive    REG_SZ    #USR:Control Panel\Desktop
    PowerOffTimeOut    REG_SZ    #USR:Control Panel\Desktop
    ScreenSaveActive    REG_SZ    #USR:Control Panel\Desktop
    ScreenSaveTimeOut    REG_SZ    #USR:Control Panel\Desktop
    SnapToDefaultButton    REG_SZ    #USR:Control Panel\Mouse
    Spooler    REG_SZ    #SYS:Microsoft\Windows NT\CurrentVersion\Windows
    swapdisk    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\Windows
    SwapMouseButtons    REG_SZ    #USR:Control Panel\Mouse
    TransmissionRetryTimeout    REG_SZ    #SYS:Microsoft\Windows NT\CurrentVersion\Windows

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\winfile.ini
    AddOns    REG_SZ    SYS:Microsoft\Windows NT\CurrentVersion\File Manager\AddOns
    Settings    REG_SZ    #USR:Software\Microsoft\File Manager\Settings
 
الحالة
مغلق و غير مفتوح للمزيد من الردود.
عودة
أعلى