startup tool v1.0
-------------------------------------------------------------
التاريخ: 2011/03/30م
الوقت: 18:32:39
نوع المعالج:
X64
نظام التشغيل:
Microsoft Windows XP || 5.1
البناء:
2600
حزمة الخدمة:
Service Pack 2
إصدار المتصفح"Internet Explorer":
6.0.2900.2180
-------------------------------------------------------------
بدء التشغيل في الريجستري "قيم ريجستري":
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
SuperCopier2.exe REG_SZ C:\Program Files\SuperCopier2\SuperCopier2.exe
BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} REG_SZ "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
Messenger (Yahoo!) REG_SZ "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
IDMan REG_SZ C:\Program Files\Internet Download Manager\IDMan.exe /onboot
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
High Definition Audio Property Page Shortcut REG_SZ HDAShCut.exe
WinampAgent REG_SZ C:\Program Files\Winamp\winampa.exe
NeroFilterCheck REG_SZ C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
TheaterMgr REG_SZ C:\Program Files\AxtromDTV\TheaterMgr.exe
egui REG_SZ "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
SoundMAXPnP REG_SZ C:\Program Files\Analog Devices\Core\smax4pnp.exe
SoundMAX REG_SZ "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
igfxtray REG_SZ C:\WINDOWS\system32\igfxtray.exe
igfxhkcmd REG_SZ C:\WINDOWS\system32\hkcmd.exe
igfxpers REG_SZ C:\WINDOWS\system32\igfxpers.exe
MobileConnect REG_EXPAND_SZ %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL
Installed REG_SZ 1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI
Installed REG_SZ 1
NoChange REG_SZ 1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS
Installed REG_SZ 1
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
! REG.EXE VERSION 3.0
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run
CTFMON.EXE REG_SZ C:\WINDOWS\system32\CTFMON.EXE
! REG.EXE VERSION 3.0
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce
nlsf REG_EXPAND_SZ cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
tscuninstall REG_EXPAND_SZ %systemroot%\system32\tscupgrd.exe
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run
CTFMON.EXE REG_SZ C:\WINDOWS\system32\CTFMON.EXE
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce
nlsf REG_EXPAND_SZ cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
tscuninstall REG_EXPAND_SZ %systemroot%\system32\tscupgrd.exe
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run
CTFMON.EXE REG_SZ C:\WINDOWS\system32\CTFMON.EXE
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce
nlsf REG_EXPAND_SZ cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
tscuninstall REG_EXPAND_SZ %systemroot%\system32\tscupgrd.exe
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run
CTFMON.EXE REG_SZ C:\WINDOWS\system32\CTFMON.EXE
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce
nlsf REG_EXPAND_SZ cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
tscuninstall REG_EXPAND_SZ %systemroot%\system32\tscupgrd.exe
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
<NO NAME> REG_SZ
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Runonce
<NO NAME> REG_SZ
-------------------------------------------------------------
بدء التشغيل في ملف المستخدم "ملفات تشغيلية":
Volume in drive C is Win Xp
Volume Serial Number is 8024-EC25
Directory of C:\Documents and Settings\All Users\Start Menu\Programs\Startup
03/30/2011 06:31 PM <DIR> .
03/30/2011 06:31 PM <DIR> ..
0 File(s) 0 bytes
2 Dir(s) 4,974,723,072 bytes free
Volume in drive C is Win Xp
Volume Serial Number is 8024-EC25
Directory of C:\Documents and Settings\M.shama\Start Menu\Programs\Startup
03/30/2011 11:31 AM <DIR> .
03/30/2011 11:31 AM <DIR> ..
0 File(s) 0 bytes
2 Dir(s) 4,974,723,072 bytes free
-------------------------------------------------------------
بدء التشغيل في أماكن متفرقة من الريجستري "متفرقات الريجستري":
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components
HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}
Version REG_SZ 2,0,0,0
Locale REG_SZ *
HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
Version REG_SZ 2,0,0,0
Locale REG_SZ *
HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
Version REG_SZ 10,0,0,3802
Locale REG_SZ EN
HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
Version REG_SZ 10,0,0,3802
Locale REG_SZ EN
HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
Version REG_SZ 1,1,1,7
Locale REG_SZ EN
HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
Version REG_SZ 6,0,2900,2180
Locale REG_SZ EN
Username REG_SZ M.shama
HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
Locale REG_SZ EN
Version REG_SZ 4,4,0,3400
HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
Locale REG_SZ EN
Version REG_SZ 10,0,0,3802
HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{4b218e3e-bc98-4770-93d3-2731b9329278}
Version REG_SZ 1,0,0,0
Locale REG_SZ EN
HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
Version REG_SZ 10,0,0,3802
Locale REG_SZ EN
HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}
Version REG_SZ 6,0,2600,0000
Locale REG_SZ EN
HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}
Version REG_SZ 6,0,2900,2180
Locale REG_SZ en
HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}
Version REG_SZ 6,0,2900,2180
Locale REG_SZ en
HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
DontAsk REG_DWORD 0x2
Version REG_SZ 10,0,0,3802
IsInstalled REG_DWORD 0x0
Stubpath REG_SZ C:\WINDOWS\inf\unregmp2.exe /ShowWMP
<NO NAME> REG_SZ Microsoft Windows Media Player
ComponentID REG_SZ WMPACCESS
Locale REG_SZ *
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}
<NO NAME> REG_SZ Internet Explorer
ComponentID REG_SZ IEACCESS
Dontask REG_DWORD 0x2
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
StubPath REG_EXPAND_SZ %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
Version REG_SZ 2,0,0,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
<NO NAME> REG_SZ Outlook Express
ComponentID REG_SZ OEACCESS
Dontask REG_DWORD 0x2
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
StubPath REG_EXPAND_SZ %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
Version REG_SZ 2,0,0,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
<NO NAME> REG_SZ Vector Graphics Rendering (VML)
ComponentID REG_SZ MSVML
Version REG_SZ 6,0,2462,0001
IsInstalled REG_BINARY 01000000
Locale REG_SZ EN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
<NO NAME> REG_SZ
ComponentID REG_SZ NetShow
IsInstalled REG_DWORD 0x1
DontAsk REG_DWORD 0x2
Locale REG_SZ EN
StubPath REG_SZ
Version REG_SZ 10,0,0,3802
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
StubPath REG_SZ
ComponentID REG_SZ Microsoft Windows Media Player
DontAsk REG_DWORD 0x2
Locale REG_SZ EN
IsInstalled REG_DWORD 0x1
<NO NAME> REG_SZ Microsoft Windows Media Player 6.4
Version REG_SZ 10,0,0,3802
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{233C1507-6A77-46A4-9443-F871F945D258}
ComponentID REG_SZ Director
IsInstalled REG_BINARY 01000000
Version REG_SZ 10,2,0,23
Locale REG_SZ EN
<NO NAME> REG_SZ Adobe Shockwave Director 10.2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
<NO NAME> REG_SZ DirectAnimation
IsInstalled REG_DWORD 0x1
Version REG_SZ 6,0,3,531
Locale REG_SZ EN
ComponentID REG_SZ DirectAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2A202491-F00D-11cf-87CC-0020AFEECF20}
ComponentID REG_SZ Director
IsInstalled REG_BINARY 01000000
Version REG_SZ 10,2,0,23
Locale REG_SZ EN
<NO NAME> REG_SZ Adobe Shockwave Director 10.2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
<NO NAME> REG_SZ Themes Setup
ComponentID REG_SZ Theme Component
IsInstalled REG_DWORD 0x1
Locale REG_SZ EN
StubPath REG_EXPAND_SZ %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
Version REG_SZ 1,1,1,7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
<NO NAME> REG_SZ Dynamic HTML Data Binding for Java
ComponentID REG_SZ TridataJava
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
Version REG_SZ 4,7,0,0320
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{3af36230-a269-11d1-b5bf-0000f8051515}
Version REG_SZ 6,0,2900,2180
<NO NAME> REG_SZ Offline Browsing Pack
ComponentID REG_SZ MobilePk
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
<NO NAME> REG_SZ Uniscribe
ComponentID REG_SZ USP10
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
Version REG_SZ 1,397,2406,1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4278c270-a269-11d1-b5bf-0000f8051515}
<NO NAME> REG_SZ Advanced Authoring
ComponentID REG_SZ AdvAuth
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
Version REG_SZ 6,0,2900,2180
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
Version REG_SZ 6,0,2900,2180
<NO NAME> REG_SZ Microsoft Outlook Express 6
IsInstalled REG_DWORD 0x1
Locale REG_SZ EN
ComponentID REG_SZ MailNews
CloneUser REG_DWORD 0x1
StubPath REG_EXPAND_SZ "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
<NO NAME> REG_SZ NetMeeting 3.01
ComponentID REG_SZ NetMeeting
IsInstalled REG_BINARY 01000000
Version REG_SZ 4,4,0,3400
Locale REG_SZ EN
StubPath REG_SZ rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
<NO NAME> REG_SZ DirectShow
ComponentID REG_SZ activemovie
IsInstalled REG_DWORD 0x1
DontAsk REG_DWORD 0x2
Locale REG_SZ EN
Version REG_SZ 10,0,0,3802
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
<NO NAME> REG_SZ DirectDrawEx
ComponentID REG_SZ DirectDrawEx
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
Version REG_SZ 4,71,1113,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
<NO NAME> REG_SZ Internet Explorer Help
ComponentID REG_SZ HelpCont
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
Version REG_SZ 6,0,2900,2180
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4b218e3e-bc98-4770-93d3-2731b9329278}
<NO NAME> REG_SZ Internet Explorer
ComponentID REG_SZ Windows Marketplace Link
IsInstalled REG_DWORD 0x1
Locale REG_SZ EN
StubPath REG_EXPAND_SZ
Version REG_SZ 1,0,0,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4f216970-c90c-11d1-b5c7-0000f8051515}
<NO NAME> REG_SZ DirectAnimation Java Classes
ComponentID REG_SZ DAJava
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
Version REG_SZ 6,00,01,0223
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}
Version REG_SZ 5,6,0,8825
<NO NAME> REG_SZ Microsoft Windows Script 5.6
ComponentID REG_SZ MSVBScript
IsInstalled REG_DWORD 0x1
Locale REG_SZ EN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5A8D6EE0-3E18-11D0-821E-444553540000}
(Default) REG_SZ Internet Connection Wizard
ComponentID REG_SZ ICW
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
Version REG_SZ 5,00,2918,1900
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
<NO NAME> REG_SZ Internet Explorer Setup Tools
ComponentID REG_SZ GenSetup
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
Version REG_SZ 5,0,0,1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
Version REG_SZ 6,0,2900,2180
<NO NAME> REG_SZ Browsing Enhancements
ComponentID REG_SZ ExtraPack
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
KeyFileName REG_SZ C:\WINDOWS\system32\msieftp.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
<NO NAME> REG_SZ Microsoft Windows Media Player
ComponentID REG_SZ Microsoft Windows Media Player
DontAsk REG_DWORD 0x2
Locale REG_SZ EN
StubPath REG_SZ rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub
IsInstalled REG_DWORD 0x1
Version REG_SZ 10,0,0,3802
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
<NO NAME> REG_SZ MSN Site Access
ComponentID REG_SZ MSN_Auth
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
Version REG_SZ 4,9,9,2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
ComponentID REG_SZ .NETFramework
<NO NAME> REG_SZ .NET Framework
Locale REG_SZ
Version REG_SZ 2,0,50727,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{73fa19d0-2d75-11d2-995d-00c04f98bbc9}
<NO NAME> REG_SZ Web Folders
ComponentID REG_SZ WebFolders
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
Version REG_SZ 1,0,1,7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}
Version REG_SZ 6,0,2600,0000
<NO NAME> REG_SZ Address Book 6
IsInstalled REG_DWORD 0x1
Locale REG_SZ EN
ComponentID REG_SZ WAB
StubPath REG_EXPAND_SZ "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}
Version REG_SZ 6,0,2900,2180
<NO NAME> REG_SZ Windows Desktop Update
ComponentID REG_SZ IE4Shell_NT
IsInstalled REG_DWORD 0x1
Locale REG_SZ en
StubPath REG_EXPAND_SZ regsvr32.exe /s /n /i:U shell32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}
Version REG_SZ 6,0,2900,2180
<NO NAME> REG_SZ Internet Explorer 6
ComponentID REG_SZ BASEIE40_W2K
IsInstalled REG_DWORD 0x1
Locale REG_SZ en
StubPath REG_EXPAND_SZ %SystemRoot%\system32\ie4uinit.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}\AuthorizedCDFPrefix
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
DontAsk REG_DWORD 0x2
StubPath REG_SZ C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
IsInstalled REG_DWORD 0x1
ComponentID REG_SZ DOTNETFRAMEWORKS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
<NO NAME> REG_SZ Dynamic HTML Data Binding
ComponentID REG_SZ Tridata
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
Version REG_SZ 5,5000,3130,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}
Version REG_SZ 6,0,2800,2180
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{C9E9A340-D1F1-11D0-821E-444553540600}
<NO NAME> REG_SZ Internet Explorer Core Fonts
ComponentID REG_SZ Fontcore
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
Version REG_SZ 1,00,0000,6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
<NO NAME> REG_SZ Task Scheduler
ComponentID REG_SZ MSTASK
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
Version REG_SZ 4,71,1968,1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
ComponentID REG_SZ Windows Movie Maker v2.1
IsInstalled REG_BINARY 01000000
Version REG_SZ 2,1,4026,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
<NO NAME> REG_SZ Adobe Flash Player
ComponentID REG_SZ Flash
IsInstalled REG_BINARY 01000000
Version REG_SZ 10.0.22.87
Locale REG_SZ EN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
<NO NAME> REG_SZ HTML Help
ComponentID REG_SZ HTMLHelp
IsInstalled REG_DWORD 0x1
Locale REG_SZ *
Version REG_SZ 4,74,9273,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}
ComponentID REG_SZ Yahoo! Messenger
IsInstalled REG_DWORD 0x1
Version REG_SZ 10.0.0.1102
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
<NO NAME> REG_SZ Active Directory Service Interface
ComponentID REG_SZ ADSI
IsInstalled REG_BINARY 01000000
Locale REG_SZ EN
Version REG_SZ 5,0,00,0
! REG.EXE VERSION 3.0
HKEY_USERS\.DEFAULT\Software\Microsoft\Active Setup\Installed Components
HKEY_USERS\.DEFAULT\Software\Microsoft\Active Setup\Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
Version REG_SZ 10,0,0,3802
HKEY_USERS\.DEFAULT\Software\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
Version REG_SZ 10,0,0,3802
HKEY_USERS\.DEFAULT\Software\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
Locale REG_SZ EN
Version REG_SZ 4,4,0,3400
HKEY_USERS\.DEFAULT\Software\Microsoft\Active Setup\Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
Locale REG_SZ EN
Version REG_SZ 10,0,0,3802
HKEY_USERS\.DEFAULT\Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
Version REG_SZ 10,0,0,3802
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-18\Software\Microsoft\Active Setup\Installed Components
HKEY_USERS\S-1-5-18\Software\Microsoft\Active Setup\Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
Version REG_SZ 10,0,0,3802
HKEY_USERS\S-1-5-18\Software\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
Version REG_SZ 10,0,0,3802
HKEY_USERS\S-1-5-18\Software\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
Locale REG_SZ EN
Version REG_SZ 4,4,0,3400
HKEY_USERS\S-1-5-18\Software\Microsoft\Active Setup\Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
Locale REG_SZ EN
Version REG_SZ 10,0,0,3802
HKEY_USERS\S-1-5-18\Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
Version REG_SZ 10,0,0,3802
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-19\Software\Microsoft\Active Setup\Installed Components
HKEY_USERS\S-1-5-19\Software\Microsoft\Active Setup\Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
Version REG_SZ 10,0,0,3802
HKEY_USERS\S-1-5-19\Software\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
Version REG_SZ 10,0,0,3802
HKEY_USERS\S-1-5-19\Software\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
Locale REG_SZ EN
Version REG_SZ 4,4,0,3400
HKEY_USERS\S-1-5-19\Software\Microsoft\Active Setup\Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
Locale REG_SZ EN
Version REG_SZ 10,0,0,3802
HKEY_USERS\S-1-5-19\Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
Version REG_SZ 10,0,0,3802
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-20\Software\Microsoft\Active Setup\Installed Components
HKEY_USERS\S-1-5-20\Software\Microsoft\Active Setup\Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
Version REG_SZ 10,0,0,3802
HKEY_USERS\S-1-5-20\Software\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
Version REG_SZ 10,0,0,3802
HKEY_USERS\S-1-5-20\Software\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
Locale REG_SZ EN
Version REG_SZ 4,4,0,3400
HKEY_USERS\S-1-5-20\Software\Microsoft\Active Setup\Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
Locale REG_SZ EN
Version REG_SZ 10,0,0,3802
HKEY_USERS\S-1-5-20\Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
Version REG_SZ 10,0,0,3802
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}
<NO NAME> REG_SZ IDM Helper
NoExplorer REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
<NO NAME> REG_SZ
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\IDM Shell Extension
<NO NAME> REG_SZ {CDC95B92-E27C-4745-A8C5-64A52A78855D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Offline Files
<NO NAME> REG_SZ {750fdf0e-2a26-11d1-a3ea-080036587f03}
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
{00022613-0000-0000-C000-000000000046} REG_SZ Multimedia File Property Sheet
{176d6597-26d3-11d1-b350-080036a75b03} REG_SZ ICM Scanner Management
{1F2E5C40-9550-11CE-99D2-00AA006E086C} REG_SZ NTFS Security Page
{3EA48300-8CF6-101B-84FB-666CCB9BCD32} REG_SZ OLE Docfile Property Page
{40dd6e20-7c17-11ce-a804-00aa003ca9f6} REG_SZ Shell extensions for sharing
{41E300E0-78B6-11ce-849B-444553540000} REG_SZ PlusPack CPL Extension
{42071712-76d4-11d1-8b24-00a0c9068ff3} REG_SZ Display Adapter CPL Extension
{42071713-76d4-11d1-8b24-00a0c9068ff3} REG_SZ Display Monitor CPL Extension
{42071714-76d4-11d1-8b24-00a0c9068ff3} REG_SZ Display Panning CPL Extension
{4E40F770-369C-11d0-8922-00A024AB2DBB} REG_SZ DS Security Page
{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8} REG_SZ Compatibility Page
{56117100-C0CD-101B-81E2-00AA004AE837} REG_SZ Shell Scrap DataHandler
{59099400-57FF-11CE-BD94-0020AF85B590} REG_SZ Disk Copy Extension
{59be4990-f85c-11ce-aff7-00aa003ca9f6} REG_SZ Shell extensions for Microsoft Windows Network objects
{5DB2625A-54DF-11D0-B6C4-0800091AA605} REG_SZ ICM Monitor Management
{675F097E-4C4D-11D0-B6C1-0800091AA605} REG_SZ ICM Printer Management
{764BF0E1-F219-11ce-972D-00AA00A14F56} REG_SZ Shell extensions for file compression
{77597368-7b15-11d0-a0c2-080036af3f03} REG_SZ Web Printer Shell Extension
{7988B573-EC89-11cf-9C00-00AA00A14F56} REG_SZ Disk Quota UI
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} REG_SZ Encryption Context Menu
{85BBD920-42A0-1069-A2E4-08002B30309D} REG_SZ Briefcase
{88895560-9AA2-1069-930E-00AA0030EBC8} REG_SZ HyperTerminal Icon Ext
{BD84B380-8CA2-1069-AB1D-08000948F534} REG_SZ Fonts
{DBCE2480-C732-101B-BE72-BA78E9AD5B27} REG_SZ ICC Profile
{F37C5810-4D3F-11d0-B4BF-00AA00BBB723} REG_SZ Printers Security Page
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} REG_SZ Shell extensions for sharing
{f92e8c40-3d33-11d2-b1aa-080036a75b03} REG_SZ Display TroubleShoot CPL Extension
{7444C717-39BF-11D1-8CD9-00C04FC29D45} REG_SZ Crypto PKO Extension
{7444C719-39BF-11D1-8CD9-00C04FC29D45} REG_SZ Crypto Sign Extension
{7007ACC7-3202-11D1-AAD2-00805FC1270E} REG_SZ Network Connections
{992CFFA0-F557-101A-88EC-00DD010CCC48} REG_SZ Network Connections
{E211B736-43FD-11D1-9EFB-0000F8757FCD} REG_SZ Scanners & Cameras
{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD} REG_SZ Scanners & Cameras
{905667aa-acd6-11d2-8080-00805f6596d2} REG_SZ Scanners & Cameras
{3F953603-1008-4f6e-A73A-04AAC7A992F1} REG_SZ Scanners & Cameras
{83bbcbf3-b28a-4919-a5aa-73027445d672} REG_SZ Scanners & Cameras
{F0152790-D56E-4445-850E-4F3117DB740C} REG_SZ Remote Sessions CPL Extension
{640167b4-59b0-47a6-b335-a6b3c0695aea} REG_SZ Portable Media Devices
{cc86590a-b60a-48e6-996b-41d25ed39a1e} REG_SZ Portable Media Devices Menu
{21569614-B795-46b1-85F4-E737A8DC09AD} REG_SZ Shell Search Band
{60254CA5-953B-11CF-8C96-00AA00B8708C} REG_SZ Shell extensions for Windows Script Host
{2206CDB2-19C1-11D1-89E0-00C04FD7A829} REG_SZ Microsoft Data Link
{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF} REG_SZ Tasks Folder Icon Handler
{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF} REG_SZ Tasks Folder Shell Extension
{D6277990-4C6A-11CF-8D87-00AA0060F5BF} REG_SZ Scheduled Tasks
{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0} REG_SZ Set Program Access and Defaults
{5F327514-6C5E-4d60-8F16-D07FA08A78ED} REG_SZ Auto Update Property Sheet Extension
{0DF44EAA-FF21-4412-828E-260A8728E7F1} REG_SZ Taskbar and Start Menu
{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0} REG_SZ Search
{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0} REG_SZ Help and Support
{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0} REG_SZ Help and Support
{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} REG_SZ Run...
{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0} REG_SZ Internet
{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0} REG_SZ E-mail
{D20EA4E1-3957-11d2-A40B-0C5020524152} REG_SZ Fonts
{D20EA4E1-3957-11d2-A40B-0C5020524153} REG_SZ Administrative Tools
{596AB062-B4D2-4215-9F74-E9109B0A8153} REG_SZ Previous Versions Property Page
{9DB7A13C-F208-4981-8353-73CC61AE2783} REG_SZ Previous Versions
{875CB1A1-0F29-45de-A1AE-CFB4950D0B78} REG_SZ Audio Media Properties Handler
{40C3D757-D6E4-4b49-BB41-0E5BBEA28817} REG_SZ Video Media Properties Handler
{E4B29F9D-D390-480b-92FD-7DDB47101D71} REG_SZ Wav Properties Handler
{87D62D94-71B3-4b9a-9489-5FE6850DC73E} REG_SZ Avi Properties Handler
{A6FD9E45-6E44-43f9-8644-08598F5A74D9} REG_SZ Midi Properties Handler
{c5a40261-cd64-4ccf-84cb-c394da41d590} REG_SZ Video Thumbnail Extractor
{5E6AB780-7743-11CF-A12B-00AA004AE837} REG_SZ Microsoft Internet Toolbar
{22BF0C20-6DA7-11D0-B373-00A0C9034938} REG_SZ Download Status
{91EA3F8B-C99B-11d0-9815-00C04FD91972} REG_SZ Augmented Shell Folder
{6413BA2C-B461-11d1-A18A-080036B11A03} REG_SZ Augmented Shell Folder 2
{F61FFEC1-754F-11d0-80CA-00AA005B4383} REG_SZ BandProxy
{7BA4C742-9E81-11CF-99D3-00AA004AE837} REG_SZ Microsoft BrowserBand
{169A0691-8DF9-11d1-A1C4-00C04FD75D13} REG_SZ In-pane search
{AF4F6510-F982-11d0-8595-00AA004CD6D8} REG_SZ Registry Tree Options Utility
{01E04581-4EEE-11d0-BFE9-00AA005B4383} REG_SZ &Address
{A08C11D2-A228-11d0-825B-00AA005B4383} REG_SZ Address EditBox
{00BB2763-6A77-11D0-A535-00C04FD7D062} REG_SZ Shell Microsoft AutoComplete
{6756A641-DE71-11d0-831B-00AA005B4383} REG_SZ MRU AutoComplete List
{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A} REG_SZ Custom MRU AutoCompleted List
{7e653215-fa25-46bd-a339-34a2790f3cb7} REG_SZ Accessible
{acf35015-526e-4230-9596-becbe19f0ac9} REG_SZ Track Popup Bar
{00BB2764-6A77-11D0-A535-00C04FD7D062} REG_SZ Microsoft History AutoComplete List
{03C036F1-A186-11D0-824A-00AA005B4383} REG_SZ Microsoft Shell Folder AutoComplete List
{00BB2765-6A77-11D0-A535-00C04FD7D062} REG_SZ Microsoft Multiple AutoComplete List Container
{ECD4FC4E-521C-11D0-B792-00A0C90312E1} REG_SZ Shell Band Site Menu
{3CCF8A41-5C85-11d0-9796-00AA00B90ADF} REG_SZ Shell DeskBarApp
{ECD4FC4C-521C-11D0-B792-00A0C90312E1} REG_SZ Shell DeskBar
{ECD4FC4D-521C-11D0-B792-00A0C90312E1} REG_SZ Shell Rebar BandSite
{DD313E04-FEFF-11d1-8ECD-0000F87A470C} REG_SZ User Assist
{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} REG_SZ Global Folder Settings
{30D02401-6A81-11d0-8274-00C04FD5AE38} REG_SZ IE Search Band
{3028902F-6374-48b2-8DC6-9725E775B926} REG_SZ IE Microsoft AutoComplete
{07798131-AF23-11d1-9111-00A0C98BA67D} REG_SZ Web Search
{7376D660-C583-11d0-A3A5-00C04FD706EC} REG_SZ TridentImageExtractor
{EFA24E61-B078-11d0-89E4-00C04FC9E26E} REG_SZ Favorites Band
{EFA24E62-B078-11d0-89E4-00C04FC9E26E} REG_SZ History Band
{0A89A860-D7B1-11CE-8350-444553540000} REG_SZ Shell Automation Inproc Service
{A5E46E3A-8849-11D1-9D8C-00C04FC99D61} REG_SZ Microsoft Browser Architecture
{131A6951-7F78-11D0-A979-00C04FD705A2} REG_SZ ISFBand OC
{9461b922-3c5a-11d2-bf8b-00c04fb93661} REG_SZ Search Assistant OC
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} REG_SZ Shell DocObject Viewer
{FBF23B40-E3F0-101B-8488-00AA003E56F8} REG_SZ InternetShortcut
{3C374A40-BAE4-11CF-BF7D-00AA006946EE} REG_SZ Microsoft Url History Service
{FF393560-C2A7-11CF-BFF4-444553540000} REG_SZ History
{7BD29E00-76C1-11CF-9DD0-00A0C9034933} REG_SZ Temporary Internet Files
{7BD29E01-76C1-11CF-9DD0-00A0C9034933} REG_SZ Temporary Internet Files
{CFBFAE00-17A6-11D0-99CB-00C04FD64497} REG_SZ Microsoft Url Search Hook
{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC} REG_SZ IE4 Suite Splash Screen
{67EA19A0-CCEF-11d0-8024-00C04FD75D13} REG_SZ CDF Extension Copy Hook
{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} REG_SZ The Internet
{EFA24E64-B078-11d0-89E4-00C04FC9E26E} REG_SZ Explorer Band
{871C5380-42A0-1069-A2EA-08002B30309D} REG_SZ Internet Name Space
{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE} REG_SZ Sendmail service
{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE} REG_SZ Sendmail service
{88C6C381-2E85-11D0-94DE-444553540000} REG_SZ ActiveX Cache Folder
{E6FB5E20-DE35-11CF-9C87-00AA005127ED} REG_SZ WebCheck
{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE} REG_SZ Subscription Mgr
{F5175861-2688-11d0-9C5E-00AA00A45957} REG_SZ Subscription Folder
{08165EA0-E946-11CF-9C87-00AA005127ED} REG_SZ WebCheckWebCrawler
{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB} REG_SZ WebCheckChannelAgent
{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7} REG_SZ TrayAgent
{7D559C10-9FE9-11d0-93F7-00AA0059CE02} REG_SZ Code Download Agent
{E6CC6978-6B6E-11D0-BECA-00C04FD940BE} REG_SZ ConnectionAgent
{D8BD2030-6FC9-11D0-864F-00AA006809D9} REG_SZ PostAgent
{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB} REG_SZ WebCheck SyncMgr Handler
{352EC2B7-8B9A-11D1-B8AE-006008059382} REG_SZ Shell Application Manager
{0B124F8F-91F0-11D1-B8B5-006008059382} REG_SZ Installed Apps Enumerator
{CFCCC7A0-A282-11D1-9082-006008059382} REG_SZ Darwin App Publisher
{e84fda7c-1d6a-45f6-b725-cb260c236066} REG_SZ Shell Image Verbs
{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178} REG_SZ Shell Image Data Factory
{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} REG_SZ Autoplay for SlideShow
{3F30C968-480A-4C6C-862D-EFC0897BB84B} REG_SZ GDI+ file thumbnail extractor
{9DBD2C50-62AD-11d0-B806-00C04FD706EC} REG_SZ Summary Info Thumbnail handler (DOCFILES)
{EAB841A0-9550-11cf-8C16-00805F1408F3} REG_SZ HTML Thumbnail Extractor
{eb9b1153-3b57-4e68-959a-a3266bc3d7fe} REG_SZ Shell Image Property Handler
{CC6EEFFB-43F6-46c5-9619-51D571967F7D} REG_SZ Web Publishing Wizard
{add36aa8-751a-4579-a266-d66f5202ccbb} REG_SZ Print Ordering via the Web
{6b33163c-76a5-4b6c-bf21-45de9cd503a1} REG_SZ Shell Publishing Wizard Object
{58f1f272-9240-4f51-b6d4-fd63d1618591} REG_SZ Get a Passport Wizard
{7A9D77BD-5403-11d2-8785-2E0420524153} REG_SZ User Accounts
{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} REG_SZ Compressed (zipped) Folder
{BD472F60-27FA-11cf-B8B4-444553540000} REG_SZ Compressed (zipped) Folder Right Drag Handler
{888DCA60-FC0A-11CF-8F0F-00C04FD7D062} REG_SZ Compressed (zipped) Folder SendTo Target
{f39a0dc0-9cc8-11d0-a599-00c04fd64433} REG_SZ Channel File
{f3aa0dc0-9cc8-11d0-a599-00c04fd64434} REG_SZ Channel Shortcut
{f3ba0dc0-9cc8-11d0-a599-00c04fd64435} REG_SZ Channel Handler Object
{f3da0dc0-9cc8-11d0-a599-00c04fd64437} REG_SZ Channel Menu
{f3ea0dc0-9cc8-11d0-a599-00c04fd64438} REG_SZ Channel Properties
{692F0339-CBAA-47e6-B5B5-3B84DB604E87} REG_SZ Extensions Manager Folder
{63da6ec0-2e98-11cf-8d82-444553540000} REG_SZ FTP Folders Webview
{883373C3-BF89-11D1-BE35-080036B11A03} REG_SZ Microsoft DocProp Shell Ext
{A9CF0EAE-901A-4739-A481-E35B73E47F6D} REG_SZ Microsoft DocProp Inplace Edit Box Control
{8EE97210-FD1F-4B19-91DA-67914005F020} REG_SZ Microsoft DocProp Inplace ML Edit Box Control
{0EEA25CC-4362-4A12-850B-86EE61B0D3EB} REG_SZ Microsoft DocProp Inplace Droplist Combo Control
{6A205B57-2567-4A2C-B881-F787FAB579A3} REG_SZ Microsoft DocProp Inplace Calendar Control
{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33} REG_SZ Microsoft DocProp Inplace Time Control
{8A23E65E-31C2-11d0-891C-00A024AB2DBB} REG_SZ Directory Query UI
{9E51E0D0-6E0F-11d2-9601-00C04FA31A86} REG_SZ Shell properties for a DS object
{163FDC20-2ABC-11d0-88F0-00A024AB2DBB} REG_SZ Directory Object Find
{F020E586-5264-11d1-A532-0000F8757D7E} REG_SZ Directory Start/Search Find
{0D45D530-764B-11d0-A1CA-00AA00C16E65} REG_SZ Directory Property UI
{62AE1F9A-126A-11D0-A14B-0800361B1103} REG_SZ Directory Context Menu Verbs
{ECF03A33-103D-11d2-854D-006008059367} REG_SZ MyDocs Copy Hook
{ECF03A32-103D-11d2-854D-006008059367} REG_SZ MyDocs Drop Target
{4a7ded0a-ad25-11d0-98a8-0800361b1103} REG_SZ MyDocs Properties
{750fdf0e-2a26-11d1-a3ea-080036587f03} REG_SZ Offline Files Menu
{10CFC467-4392-11d2-8DB4-00C04FA31A66} REG_SZ Offline Files Folder Options
{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E} REG_SZ Offline Files Folder
{143A62C8-C33B-11D1-84FE-00C04FA34A14} REG_SZ Microsoft Agent Character Property Sheet Handler
{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6} REG_SZ DfsShell
{60fd46de-f830-4894-a628-6fa81bc0190d} REG_SZ %DESC_PublishDropTarget%
{7A80E4A8-8005-11D2-BCF8-00C04F72C717} REG_SZ MMC Icon Handler
{0CD7A5C0-9F37-11CE-AE65-08002B2E1262} REG_SZ .CAB file viewer
{32714800-2E5F-11d0-8B85-00AA0044F941} REG_SZ For &People...
{8DD448E6-C188-4aed-AF92-44956194EB1F} REG_SZ Windows Media Player Play as Playlist Context Menu Handler
{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C} REG_SZ Windows Media Player Burn Audio CD Context Menu Handler
{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD} REG_SZ Windows Media Player Add to Playlist Context Menu Handler
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} REG_SZ Web Folders
{B41DB860-8EE4-11D2-9906-E49FADC173CA} REG_SZ WinRAR shell extension
{00020D75-0000-0000-C000-000000000046} REG_SZ Microsoft Office Outlook Desktop Icon Handler
{0006F045-0000-0000-C000-000000000046} REG_SZ Microsoft Office Outlook Custom Icon Handler
{42042206-2D85-11D3-8CFF-005004838597} REG_SZ Microsoft Office HTML Icon Handler
{B089FE88-FB52-11D3-BDF1-0050DA34150D} REG_SZ ESET Smart Security - Context Menu Shell Extension
{CDC95B92-E27C-4745-A8C5-64A52A78855D} REG_SZ IDM Shell Extension
{e82a2d71-5b2f-43a0-97b8-81be15854de8} REG_SZ ShellLink for Application References
{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} REG_SZ Shell Icon Handler for Application References
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{438755C2-A8BA-11D1-B96B-00A0C90312E1} REG_SZ Browseui preloader
{8C7461EF-2B13-11d2-BE35-3078302C2030} REG_SZ Component Categories cache daemon
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
PostBootReminder REG_SZ {7849596a-48ea-486e-8937-a2a3009f31a9}
CDBurn REG_SZ {fbeb8a05-beee-4442-804e-409d6c4515e9}
WebCheck REG_SZ {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
SysTray REG_SZ {35CEC8A3-2BE6-11D2-8773-92E220524153}
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Command Processor
CompletionChar REG_DWORD 0x9
DefaultColor REG_DWORD 0x0
EnableExtensions REG_DWORD 0x1
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor
AutoRun REG_SZ
CompletionChar REG_DWORD 0x40
DefaultColor REG_DWORD 0x0
EnableExtensions REG_DWORD 0x1
PathCompletionChar REG_DWORD 0x40
! REG.EXE VERSION 3.0
HKEY_USERS\.DEFAULT\Software\Microsoft\Command Processor
CompletionChar REG_DWORD 0x9
DefaultColor REG_DWORD 0x0
EnableExtensions REG_DWORD 0x1
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-18\Software\Microsoft\Command Processor
CompletionChar REG_DWORD 0x9
DefaultColor REG_DWORD 0x0
EnableExtensions REG_DWORD 0x1
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-19\Software\Microsoft\Command Processor
CompletionChar REG_DWORD 0x9
DefaultColor REG_DWORD 0x0
EnableExtensions REG_DWORD 0x1
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-20\Software\Microsoft\Command Processor
CompletionChar REG_DWORD 0x9
DefaultColor REG_DWORD 0x0
EnableExtensions REG_DWORD 0x1
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
ParseAutoexec REG_SZ 1
ExcludeProfileDirs REG_SZ Local Settings;Temporary Internet Files;History;Temp;Local Settings\Application Data\Microsoft\Outlook
BuildNumber REG_DWORD 0xa28
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\winlogon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\winlogon\DEBUG
Trace Level REG_SZ
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
AutoRestartShell REG_DWORD 0x1
DefaultDomainName REG_SZ SICOWIN
DefaultUserName REG_SZ M.shama
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ReportBootOk REG_SZ 1
Shell REG_SZ Explorer.exe
ShutdownWithoutLogon REG_SZ 0
System REG_SZ
Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
SfcQuota REG_DWORD 0x0
SfcDisable REG_DWORD 0xffffff9d
allocatecdroms REG_SZ 0
allocatedasd REG_SZ 0
allocatefloppies REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0x0
passwordexpirywarning REG_DWORD 0xe
scremoveoption REG_SZ 0
AllowMultipleTSSessions REG_DWORD 0x1
UIHost REG_EXPAND_SZ logonui.exe
LogonType REG_DWORD 0x1
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
WinStationsDisabled REG_SZ 0
HibernationPreviouslyEnabled REG_DWORD 0x1
ShowLogonOptions REG_DWORD 0x1
AltDefaultUserName REG_SZ M.shama
AltDefaultDomainName REG_SZ SICOWIN
AutoAdminLogon REG_SZ 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}
<NO NAME> REG_SZ Wireless
ProcessGroupPolicy REG_SZ ProcessWIRELESSPolicy
DllName REG_EXPAND_SZ gptext.dll
NoUserPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}
<NO NAME> REG_SZ Folder Redirection
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx
DllName REG_EXPAND_SZ fdeploy.dll
NoMachinePolicy REG_DWORD 0x1
NoSlowLink REG_DWORD 0x1
PerUserLocalSettings REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x0
NoBackgroundPolicy REG_DWORD 0x0
GenerateGroupPolicy REG_SZ GenerateGroupPolicy
EventSources REG_MULTI_SZ (Folder Redirection,Application)\0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{35378EAC-683F-11D2-A89A-00C04FBBCFA2}
Status REG_DWORD 0x0
RsopStatus REG_DWORD 0x0
LastPolicyTime REG_DWORD 0xfa8ba7
PrevSlowLink REG_DWORD 0x0
PrevRsopLogging REG_DWORD 0x1
ForceRefreshFG REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
<NO NAME> REG_SZ Microsoft Disk Quota
NoMachinePolicy REG_DWORD 0x0
NoUserPolicy REG_DWORD 0x1
NoSlowLink REG_DWORD 0x1
NoBackgroundPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1
PerUserLocalSettings REG_DWORD 0x0
RequiresSuccessfulRegistry REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x0
DllName REG_EXPAND_SZ dskquota.dll
ProcessGroupPolicy REG_SZ ProcessGroupPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}
<NO NAME> REG_SZ QoS Packet Scheduler
ProcessGroupPolicy REG_SZ ProcessPSCHEDPolicy
DllName REG_EXPAND_SZ gptext.dll
NoUserPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1
Status REG_DWORD 0x0
RsopStatus REG_DWORD 0x80070032
LastPolicyTime REG_DWORD 0xfa8ba7
PrevSlowLink REG_DWORD 0x0
PrevRsopLogging REG_DWORD 0x1
ForceRefreshFG REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}
<NO NAME> REG_SZ Scripts
ProcessGroupPolicy REG_SZ ProcessScriptsGroupPolicy
ProcessGroupPolicyEx REG_SZ ProcessScriptsGroupPolicyEx
GenerateGroupPolicy REG_SZ GenerateScriptsGroupPolicy
DllName REG_EXPAND_SZ gptext.dll
NoSlowLink REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1
NotifyLinkTransition REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}
<NO NAME> REG_SZ Internet Explorer Zonemapping
DllName REG_EXPAND_SZ iedkcs32.dll
ProcessGroupPolicy REG_SZ ProcessGroupPolicyForZoneMap
NoGPOListChanges REG_DWORD 0x1
RequiresSucessfulRegistry REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
ProcessGroupPolicy REG_SZ SceProcessSecurityPolicyGPO
GenerateGroupPolicy REG_SZ SceGenerateGroupPolicy
ExtensionRsopPlanningDebugLevel REG_DWORD 0x1
ProcessGroupPolicyEx REG_SZ SceProcessSecurityPolicyGPOEx
ExtensionDebugLevel REG_DWORD 0x1
DllName REG_EXPAND_SZ scecli.dll
<NO NAME> REG_SZ Security
NoUserPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1
MaxNoGPOListChangesInterval REG_DWORD 0x3c0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx
GenerateGroupPolicy REG_SZ GenerateGroupPolicy
ProcessGroupPolicy REG_SZ ProcessGroupPolicy
DllName REG_EXPAND_SZ iedkcs32.dll
<NO NAME> REG_SZ Internet Explorer Branding
NoSlowLink REG_DWORD 0x1
NoBackgroundPolicy REG_DWORD 0x0
NoGPOListChanges REG_DWORD 0x1
NoMachinePolicy REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}
ProcessGroupPolicy REG_SZ SceProcessEFSRecoveryGPO
DllName REG_EXPAND_SZ scecli.dll
<NO NAME> REG_SZ EFS recovery
NoUserPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1
RequiresSuccessfulRegistry REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}
<NO NAME> REG_SZ Microsoft Offline Files
DllName REG_EXPAND_SZ %SystemRoot%\System32\cscui.dll
EnableAsynchronousProcessing REG_DWORD 0x0
NoBackgroundPolicy REG_DWORD 0x0
NoGPOListChanges REG_DWORD 0x0
NoMachinePolicy REG_DWORD 0x0
NoSlowLink REG_DWORD 0x0
NoUserPolicy REG_DWORD 0x1
PerUserLocalSettings REG_DWORD 0x0
ProcessGroupPolicy REG_SZ ProcessGroupPolicy
RequiresSuccessfulRegistry REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}
<NO NAME> REG_SZ Software Installation
DllName REG_EXPAND_SZ appmgmts.dll
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyObjectsEx
GenerateGroupPolicy REG_SZ GenerateGroupPolicy
NoBackgroundPolicy REG_DWORD 0x0
RequiresSucessfulRegistry REG_DWORD 0x0
NoSlowLink REG_DWORD 0x1
PerUserLocalSettings REG_DWORD 0x1
EventSources REG_MULTI_SZ (Application Management,Application)\0(MsiInstaller,Application)\0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}
<NO NAME> REG_SZ IP Security
ProcessGroupPolicy REG_SZ ProcessIPSECPolicy
DllName REG_EXPAND_SZ gptext.dll
NoUserPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
Asynchronous REG_DWORD 0x0
Impersonate REG_DWORD 0x0
DllName REG_EXPAND_SZ crypt32.dll
Logoff REG_SZ ChainWlxLogoffEvent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
Asynchronous REG_DWORD 0x0
Impersonate REG_DWORD 0x0
DllName REG_EXPAND_SZ cryptnet.dll
Logoff REG_SZ CryptnetWlxLogoffEvent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
DLLName REG_SZ cscdll.dll
Logon REG_SZ WinlogonLogonEvent
Logoff REG_SZ WinlogonLogoffEvent
ScreenSaver REG_SZ WinlogonScreenSaverEvent
Startup REG_SZ WinlogonStartupEvent
Shutdown REG_SZ WinlogonShutdownEvent
StartShell REG_SZ WinlogonStartShellEvent
Impersonate REG_DWORD 0x0
Asynchronous REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui
<NO NAME> REG_SZ
DLLName REG_SZ igfxdev.dll
Asynchronous REG_DWORD 0x1
Impersonate REG_DWORD 0x1
Unlock REG_SZ WinlogonUnlockEvent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
DLLName REG_SZ wlnotify.dll
Logon REG_SZ SCardStartCertProp
Logoff REG_SZ SCardStopCertProp
Lock REG_SZ SCardSuspendCertProp
Unlock REG_SZ SCardResumeCertProp
Enabled REG_DWORD 0x1
Impersonate REG_DWORD 0x1
Asynchronous REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
Asynchronous REG_DWORD 0x0
DllName REG_EXPAND_SZ wlnotify.dll
Impersonate REG_DWORD 0x0
StartShell REG_SZ SchedStartShell
Logoff REG_SZ SchedEventLogOff
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
Logoff REG_SZ WLEventLogoff
Impersonate REG_DWORD 0x0
Asynchronous REG_DWORD 0x1
DllName REG_EXPAND_SZ sclgntfy.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
DLLName REG_SZ WlNotify.dll
Lock REG_SZ SensLockEvent
Logon REG_SZ SensLogonEvent
Logoff REG_SZ SensLogoffEvent
Safe REG_DWORD 0x1
MaxWait REG_DWORD 0x258
StartScreenSaver REG_SZ SensStartScreenSaverEvent
StopScreenSaver REG_SZ SensStopScreenSaverEvent
Startup REG_SZ SensStartupEvent
Shutdown REG_SZ SensShutdownEvent
StartShell REG_SZ SensStartShellEvent
PostShell REG_SZ SensPostShellEvent
Disconnect REG_SZ SensDisconnectEvent
Reconnect REG_SZ SensReconnectEvent
Unlock REG_SZ SensUnlockEvent
Impersonate REG_DWORD 0x1
Asynchronous REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
Asynchronous REG_DWORD 0x0
DllName REG_EXPAND_SZ wlnotify.dll
Impersonate REG_DWORD 0x0
Logoff REG_SZ TSEventLogoff
Logon REG_SZ TSEventLogon
PostShell REG_SZ TSEventPostShell
Shutdown REG_SZ TSEventShutdown
StartShell REG_SZ TSEventStartShell
Startup REG_SZ TSEventStartup
MaxWait REG_DWORD 0x258
Reconnect REG_SZ TSEventReconnect
Disconnect REG_SZ TSEventDisconnect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon
Asynchronous REG_DWORD 0x0
Disconnect REG_SZ WLEventDisconnect
DllName REG_EXPAND_SZ WgaLogon.dll
Event REG_DWORD 0x1
Impersonate REG_DWORD 0x1
Lock REG_SZ WLEventLock
Logoff REG_SZ WLEventLogoff
Logon REG_SZ WLEventLogon
MaxWait REG_DWORD 0xffffffff
PostShell REG_SZ WLEventPostShell
Reconnect REG_SZ WLEventReconnect
SafeMode REG_DWORD 0x1
Shutdown REG_SZ WLEventShutdown
StartScreenSaver REG_SZ WLEventStartScreenSaver
StartShell REG_SZ WLEventStartShell
Startup REG_SZ WLEventStartup
StopScreenSaver REG_SZ WLEventStopScreenSaver
Unlock REG_SZ WLEventUnlock
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings
Data REG_BINARY 01000000D08C9DDF0115D1118C7A00C04FC297EB01000000FABC978A70C2424CBA5FFB0C718885B504000000040000005300000003660000A800000010000000A8F072D54005919BF1EA1065B627CFFF0000000004800000A000000010000000B55AA05E947FE0D105ABD0C67621EC7DB001000074D2C780E3B2ABDE644FCECAD17A5C56347477B239FE9AC01B8486046A347AF0993264F6BD82AD2C77FED3D0E13CFCFEF5D1B75ACA51B03A8B898AED2FCFD55DBF03448C4E82AA4E3C495EFB686AE7F05F4E70796EE0D8637E13E4E8985899223B887A0168D5F15D1126F96D08D382CAC51405A05E597B56FDB74F74B9DE4AC64129E321E8DC2BE4DC7B6DD76807A8104E7A3FEEE92C870F5F818569AF961DEFD2A7788F2FF459D0CF45C0EF21790CCFE81C19713F2D6F9BA863DF4F2C8BA806E0456AE25A0829CE0518992D7153E209B9ACADF0DE93BEDB910DB9B18D1924E87FFF893C279335DF6B7D8D83763DC5675BD0F341A6F0750280164EB8D1ED2FA9248D9908621E36A752C5070AEDC18100C22083312E8AF921649A6B6796440C0B7C7119B889F7C6158550D811C1D381CED28665D397C4221E100EBB2F2A039459DD7159F6461D975511FA4179CCF7FE4C6B539AB81703C9D239A9BC811B140C2B94DED1F2D092969E9760D478C99CB96E895552924CF921BBB1CE7A03262D47051391A916E893A894892B36142F162570FAC0FFE19A574D88F54E0DD49A24E34ED536D3E92191061AE8645D686D7154F41400000084AFA321BF988E5578402AC8DEFE0C2F4C4E0C49
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
DLLName REG_SZ wlnotify.dll
Logon REG_SZ RegisterTicketExpiredNotificationEvent
Logoff REG_SZ UnregisterTicketExpiredNotificationEvent
Impersonate REG_DWORD 0x1
Asynchronous REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
HelpAssistant REG_DWORD 0x0
TsInternetUser REG_DWORD 0x0
SQLAgentCmdExec REG_DWORD 0x0
NetShowServices REG_DWORD 0x0
IWAM_ REG_DWORD 0x10000
IUSR_ REG_DWORD 0x10000
VUSR_ REG_DWORD 0x10000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Credentials
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon
EventMessageFile REG_EXPAND_SZ %SystemRoot%\System32\winlogon.exe
TypesSupported REG_DWORD 0x7
! REG.EXE VERSION 3.0
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
ParseAutoexec REG_SZ 1
ExcludeProfileDirs REG_SZ Local Settings;Temporary Internet Files;History;Temp
BuildNumber REG_DWORD 0xa28
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
ParseAutoexec REG_SZ 1
ExcludeProfileDirs REG_SZ Local Settings;Temporary Internet Files;History;Temp
BuildNumber REG_DWORD 0xa28
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
ParseAutoexec REG_SZ 1
ExcludeProfileDirs REG_SZ Local Settings;Temporary Internet Files;History;Temp
BuildNumber REG_DWORD 0xa28
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
ParseAutoexec REG_SZ 1
ExcludeProfileDirs REG_SZ Local Settings;Temporary Internet Files;History;Temp
BuildNumber REG_DWORD 0xa28
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BootVerificationProgram
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Bounds REG_BINARY 0030000000200000
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
ImpersonatePrivilegeUpgradeToolHasRun REG_DWORD 0x1
LsaPid REG_DWORD 0x3f0
SecureBoot REG_DWORD 0x1
auditbaseobjects REG_DWORD 0x0
crashonauditfail REG_DWORD 0x0
disabledomaincreds REG_DWORD 0x0
everyoneincludesanonymous REG_DWORD 0x0
fipsalgorithmpolicy REG_DWORD 0x0
forceguest REG_DWORD 0x1
fullprivilegeauditing REG_BINARY 00
limitblankpassworduse REG_DWORD 0x1
lmcompatibilitylevel REG_DWORD 0x0
nodefaultadminowner REG_DWORD 0x1
nolmhash REG_DWORD 0x1
restrictanonymous REG_DWORD 0x0
restrictanonymoussam REG_DWORD 0x1
Notification Packages REG_MULTI_SZ scecli\0\0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders
ProviderOrder REG_MULTI_SZ Windows NT Access Provider\0\0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider
ProviderPath REG_EXPAND_SZ %SystemRoot%\system32\ntmarta.dll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\System
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data
Pattern REG_BINARY C4B57FC40F6395C7418E8719D6FF45EB653535636564623600FD07001E16000034FA07004E827C7520FA070040FD07004CFD0700B2F844360A075C7FDD4BCAE5
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG
GrafBlumGroup REG_BINARY 1156E3A40DB67D1694
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD
Lookup REG_BINARY F81B94B4D052
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\SidCache
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0
Auth132 REG_SZ IISSUBA
ntlmminclientsec REG_DWORD 0x0
ntlmminserversec REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1
SkewMatrix REG_BINARY 52951567754E709DAE7FF0F68233AE2E
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4
SSOURL REG_SZ http://www.passport.com
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache
Time REG_BINARY F01E2A508B2ECA01
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll
Name REG_SZ Digest
Comment REG_SZ Digest SSPI Authentication Package
Capabilities REG_DWORD 0x4050
RpcId REG_DWORD 0xffff
Version REG_DWORD 0x1
TokenSize REG_DWORD 0xffff
Time REG_BINARY 00C65887B579C401
Type REG_DWORD 0x31
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll
Name REG_SZ DPA
Comment REG_SZ DPA Security Package
Capabilities REG_DWORD 0x37
RpcId REG_DWORD 0x11
Version REG_DWORD 0x1
TokenSize REG_DWORD 0x300
Time REG_BINARY 00C65887B579C401
Type REG_DWORD 0x31
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll
Name REG_SZ MSN
Comment REG_SZ MSN Security Package
Capabilities REG_DWORD 0x37
RpcId REG_DWORD 0x12
Version REG_DWORD 0x1
TokenSize REG_DWORD 0x300
Time REG_BINARY 00C65887B579C401
Type REG_DWORD 0x31
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA
ParameterMessageFile REG_EXPAND_SZ %SystemRoot%\System32\MsObjs.dll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA\ObjectNames
PolicyObject REG_DWORD 0x1600
SecretObject REG_DWORD 0x1610
TrustedDomainObject REG_DWORD 0x1620
UserAccountObject REG_DWORD 0x1630
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot
AlternateShell REG_SZ cmd.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmadmin
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmboot.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmio.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmload.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmserver
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys
<NO NAME> REG_SZ FSFilter System Recovery
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SRService
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vga.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}
<NO NAME> REG_SZ Universal Serial Bus controllers
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ CD-ROM Drive
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ DiskDrive
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ Standard floppy disk controller
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ Hdc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ Keyboard
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ Mouse
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ PCMCIA Adapters
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ SCSIAdapter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ System
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ Floppy disk drive
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}
<NO NAME> REG_SZ Volume
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
<NO NAME> REG_SZ Human Interface Devices
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmadmin
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmboot.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmio.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmload.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmserver
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ip6fw.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nm
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nm.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NtLmSsp
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpcdd.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpdd.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpwd.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sr.sys
<NO NAME> REG_SZ FSFilter System Recovery
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SRService
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI
<NO NAME> REG_SZ Driver Group
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdpipe.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdtcp.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\termservice
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vga.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vgasave.sys
<NO NAME> REG_SZ Driver
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WZCSVC
<NO NAME> REG_SZ Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}
<NO NAME> REG_SZ Universal Serial Bus controllers
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ CD-ROM Drive
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ DiskDrive
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ Standard floppy disk controller
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ Hdc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ Keyboard
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ Mouse
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ Net
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ NetClient
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ NetService
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ NetTrans
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ PCMCIA Adapters
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ SCSIAdapter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ System
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}
<NO NAME> REG_SZ Floppy disk drive
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}
<NO NAME> REG_SZ Volume
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
<NO NAME> REG_SZ Human Interface Devices
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders
SecurityProviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SaslProfiles
GSSAPI REG_SZ Kerberos
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL
EventLogging REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\DES 56/56
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\NULL
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 128/128
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 40/128
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 56/128
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 128/128
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 40/128
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 56/128
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\Triple DES 168/168
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Hashes
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Hashes\MD5
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Hashes\SHA
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\KeyExchangeAlgorithms
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\KeyExchangeAlgorithms\Diffie-Hellman
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\KeyExchangeAlgorithms\PKCS
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\Multi-Protocol Unified Hello
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\Multi-Protocol Unified Hello\Client
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\Multi-Protocol Unified Hello\Server
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0\Client
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0\Server
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Client
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Server
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Client
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Server
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Client
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Server
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest
Lifetime REG_DWORD 0x8ca0
Negotiate REG_DWORD 0x0
UTF8HTTP REG_DWORD 0x1
UTF8SASL REG_DWORD 0x1
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\CWD
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\CWD\ff060102423da0000407108e0500
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\CWD\ff060102423da0000407108e0500\1
Add1 REG_BINARY 021540A0101EB823008ED88B0E140781E100021FC3
Change1 REG_BINARY 011D50480C558BECB800009C5981E10002558BECB80000E8E757909090
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBI01
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBI01\ff06010242935100040720730500
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBI01\ff06010242935100040720730500\1
Change1 REG_BINARY 0149D0182245558BEC1EB44332C0C55606CD211F720AC45E0A26890F33C0EB0450E8FA025D4DCB558BEC1EB80043C55606CD211F720DC45E0A80E11F26890F33C0EB0450E8FA025DCB
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBI02
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBI02\ff06010242468300040790c80400
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBI02\ff06010242468300040790c80400\1
Change1 REG_BINARY 015112462645558BEC56571EB44332C0C55606CD211F720AC45E0A26890F33C0EB0450E84B035F5E5D4DCB45558BEC1EB44332C0C55606CD211F720AC45E0A80E11F26890F33C0EB0450E84B035D4DCB90
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBIN
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBIN\ff0601024cab7b000407b0ea0400
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTBIN\ff0601024cab7b000407b0ea0400\2
Change1 REG_BINARY 0115F03B083D035F7403E906003D035F9090E90600
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTSCR
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTSCR\ff060102c47b1f00040750db0100
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\INSTSCR\ff060102c47b1f00040750db0100\e
Change1 REG_BINARY 0113841E0745558BEC68002045558BEC680220
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\LTSPRINT
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\LTSPRINT\ff060102424f3f000306706600
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\LTSPRINT\ff060102424f3f000306706600\1
Change1 REG_BINARY 010B9C1C033D00013D0006
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\MYST
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\MYST\ff060102423bab000407102e0600
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\MYST\ff060102423bab000407102e0600\1
Add1 REG_BINARY 021540AB101EB823008ED88B0E140781E100021FC3
Change1 REG_BINARY 011D50490C558BECB800009C5981E10002558BECB80000E8E761909090
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\OUTPOST
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\OUTPOST\ff06010242410f000306801500
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\OUTPOST\ff06010242410f000306801500\1
Change1 REG_BINARY 010F090A059A7305FF01B8030A9090
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\PALED40
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\PALED40\ff060102420032000407401b0100
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\PALED40\ff060102420032000407401b0100\1
Change1 REG_BINARY 0107B72101D80C
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601024211e100040750e50700
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601024211e100040750e50700\1
Change1 REG_BINARY 011D3FE00C8B46E88B56EA2B46FA1B56FCB85001BA0000909090909090
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601024237e6000407d00e0800
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601024237e6000407d00e0800\1
Change1 REG_BINARY 011D65E50C8B46E88B56EA2B46FA1B56FCB85001BA0000909090909090
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff060102428203000306401600
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff060102428203000306401600\1
Change1 REG_BINARY 010F28030533ED559A13B8004CCD21
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601025621ef000407f07a0700
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601025621ef000407f07a0700\3
Change1 REG_BINARY 011DF3450C8B4EF08B5EF22B4EF41B5EF6B95001BB0000909090909090
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601025642ea00040750550700
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601025642ea00040750550700\3
Change1 REG_BINARY 011DB7410C8B4EF08B5EF22B4EF41B5EF6B95001BB0000909090909090
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff060102564ee6000407b0670700
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff060102564ee6000407b0670700\3
Change1 REG_BINARY 01157C3508668B46FC662B46F066B8500100009090
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff060102565ce5000407d0600700
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff060102565ce5000407d0600700\3
Change1 REG_BINARY 011DFD340C8B4EF08B5EF22B4EF41B5EF6B95001BB0000909090909090
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601025674e6000407704d0700
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff0601025674e6000407704d0700\3
Change1 REG_BINARY 011DCF3D0C8B4EF08B5EF22B4EF41B5EF6B95001BB0000909090909090
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256b1dd00040760ef0b00
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256b1dd00040760ef0b00\3
Change1 REG_BINARY 01152C3B08668B46F0662B46F466B8500100009090
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256c1ef00040770fb0600
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256c1ef00040770fb0600\3
Change1 REG_BINARY 011DFD380C8B46F08B56F22B46F41B56F6B85001BA0000909090909090
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256e2e400040750600700
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256e2e400040750600700\3
Change1 REG_BINARY 011DFD340C8B4EF08B5EF22B4EF41B5EF6B95001BB0000909090909090
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256eae500040710640700
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256eae500040710640700\3
Change1 REG_BINARY 011DFD340C8B4EF08B5EF22B4EF41B5EF6B95001BB0000909090909090
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256faef00040710c50600
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP\ff06010256faef00040710c50600\3
Change1 REG_BINARY 011DB7330C8B46F08B56F22B46F41B56F6B85001BA0000909090909090
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP16
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP16\ff0601024cd875000407a0db0100
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\SETUP16\ff0601024cd875000407a0db0100\2
Change1 REG_BINARY 012317420F8BC88BD08B5E0E2AE489078ACD2AEDB90A00BA030A8B5E0E2AE490909090
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\USA
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\USA\ff06010242059b00040710780600
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\USA\ff06010242059b00040710780600\1
Change1 REG_BINARY 011D95440C558BECB800009C5981E10002558BECB80000E86756909090
Change2 REG_BINARY 0125059B10000000000000000000000000000000001EB823008ED88B0E140781E100021FC3
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\VB
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\VB\ff060102ec353f00040780c81300
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\VB\ff060102ec353f00040780c81300\12
Change1 REG_BINARY 01111B0306813EBA313403813EBA310903
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\VB40016
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\VB40016\ff0702021401ee3e000407d0460e00
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\VB40016\ff0702021401ee3e000407d0460e00\16
Change1 REG_BINARY 01116D2A06813E6E363403813E6E360903
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\WISE0001
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\WISE0001\ff0601024cf4ef000407604e0100
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppPatches\WISE0001\ff0601024cf4ef000407604e0100\2
Change1 REG_BINARY 010F8E00059A4B000F02B80C299090
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\DOS Devices
AUX REG_SZ \DosDevices\COM1
MAILSLOT REG_SZ \Device\MailSlot
NUL REG_SZ \Device\Null
PIPE REG_SZ \Device\NamedPipe
PRN REG_SZ \DosDevices\LPT1
UNC REG_SZ \Device\Mup
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment
ComSpec REG_EXPAND_SZ %SystemRoot%\system32\cmd.exe
Path REG_EXPAND_SZ %SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\PROGRA~1\DISKEE~1\DISKEE~1\
windir REG_EXPAND_SZ %SystemRoot%
FP_NO_HOST_CHECK REG_SZ NO
OS REG_SZ Windows_NT
PROCESSOR_ARCHITECTURE REG_SZ x86
PROCESSOR_LEVEL REG_SZ 15
PROCESSOR_IDENTIFIER REG_SZ x86 Family 15 Model 4 Stepping 10, GenuineIntel
PROCESSOR_REVISION REG_SZ 040a
NUMBER_OF_PROCESSORS REG_SZ 2
TEMP REG_EXPAND_SZ %SystemRoot%\TEMP
TMP REG_EXPAND_SZ %SystemRoot%\TEMP
PATHEXT REG_SZ .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Executive
AdditionalCriticalWorkerThreads REG_DWORD 0x0
AdditionalDelayedWorkerThreads REG_DWORD 0x0
PriorityQuantumMatrix REG_BINARY 1861A25F000000003F2ECA01
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\FileRenameOperations
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\kernel
ObUnsecureGlobalNames REG_MULTI_SZ netfxcustomperfcounters.1.0\0SharedPerfIPCBlock\0Cor_Private_IPCBlock\0\0
obcaseinsensitive REG_DWORD 0x1
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs
advapi32 REG_SZ advapi32.dll
comdlg32 REG_SZ comdlg32.dll
DllDirectory REG_EXPAND_SZ %SystemRoot%\system32
gdi32 REG_SZ gdi32.dll
imagehlp REG_SZ imagehlp.dll
kernel32 REG_SZ kernel32.dll
lz32 REG_SZ lz32.dll
ole32 REG_SZ ole32.dll
oleaut32 REG_SZ oleaut32.dll
olecli32 REG_SZ olecli32.dll
olecnv32 REG_SZ olecnv32.dll
olesvr32 REG_SZ olesvr32.dll
olethk32 REG_SZ olethk32.dll
rpcrt4 REG_SZ rpcrt4.dll
shell32 REG_SZ shell32.dll
url REG_SZ url.dll
urlmon REG_SZ urlmon.dll
user32 REG_SZ user32.dll
version REG_SZ version.dll
wininet REG_SZ wininet.dll
wldap32 REG_SZ wldap32.dll
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
ClearPageFileAtShutdown REG_DWORD 0x0
DisablePagingExecutive REG_DWORD 0x0
LargeSystemCache REG_DWORD 0x0
NonPagedPoolQuota REG_DWORD 0x0
NonPagedPoolSize REG_DWORD 0x0
PagedPoolQuota REG_DWORD 0x0
PagedPoolSize REG_DWORD 0x0
SecondLevelDataCache REG_DWORD 0x0
SystemPages REG_DWORD 0xc3000
PagingFiles REG_MULTI_SZ C:\pagefile.sys 1024 2048\0\0
PhysicalAddressExtension REG_DWORD 0x0
SessionViewSize REG_DWORD 0x30
SessionPoolSize REG_DWORD 0x4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters
VideoInitTime REG_DWORD 0xda
EnablePrefetcher REG_DWORD 0x3
AppLaunchMaxNumPages REG_DWORD 0xfa0
AppLaunchMaxNumSections REG_DWORD 0xaa
AppLaunchTimerPeriod REG_BINARY 806967FFFFFFFFFF
BootMaxNumPages REG_DWORD 0x1f400
BootMaxNumSections REG_DWORD 0xff0
BootTimerPeriod REG_BINARY 00F2D8F8FFFFFFFF
MaxNumActiveTraces REG_DWORD 0x8
MaxNumSavedTraces REG_DWORD 0x8
RootDirPath REG_SZ Prefetch
HostingAppList REG_SZ DLLHOST.EXE,MMC.EXE,RUNDLL32.EXE
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Power
AcProcessorPolicy REG_BINARY 01000000000000000000000003000000A0860100A0860100A08601002832000002000000A0860100A0860100A0860100283C000003000000A0860100A0860100A08601002850000001000000
DcProcessorPolicy REG_BINARY 01000000030000000000000003000000A0860100A0860100A08601000A14000002000000A0860100A0860100A08601001428000003000000A0860100A0860100A08601001446000001000000
AcPolicy REG_BINARY 010000000000000003000000100000000200000003000000000000000200000001000000000000000100000000000000020000000100000000000000000000003200584802000000040000000200000001000000304E16000000000003000000010000000300000003000000000000C00100000005000000010000000A00000000000000030000000100010001000000000000000000000000000000000000000000020000000000000000000000000000000000000000000000030000000000B004000071FB907C34F20600FEE1907CF4F20600000000000164643202000000040000C000000000
DcPolicy REG_BINARY 0100000000000000030000001000000002000000030000000000000002000000010000000000000001000000FFFF00000200000000000000000000002C01000032032D0004000000040000000200000001000000330030008403000003000000010000000300000003000000000000C00100000005000000010000000A000000000000000300000001000100010000000000000000000000000000000000000000000200000000000000000000000000000000000000000000000300000000002C01000001000000000000000000000000000000580200000150643202000000040000C000000000
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SFC
ProgramFilesDir REG_SZ C:\Program Files
CommonFilesDir REG_SZ C:\Program Files\Common Files
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems
Debug REG_EXPAND_SZ
Kmode REG_EXPAND_SZ %SystemRoot%\system32\win32k.sys
Optional REG_MULTI_SZ Posix\0\0
Posix REG_EXPAND_SZ %SystemRoot%\system32\psxss.exe
Required REG_MULTI_SZ Debug\0Windows\0\0
Windows REG_EXPAND_SZ %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\CSRSS
CsrSrvSharedSectionBase REG_DWORD 0x7f6f0000
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Syncmgr\Handlers
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACDSeePro40ImportPicturesOnArrival
Action REG_SZ Import pictures
Provider REG_SZ ACDSee Pro 4
InvokeProgID REG_SZ ACDSee Pro 4.AutoPlayHandlerImport
InvokeVerb REG_SZ Import
DefaultIcon REG_SZ C:\Program Files\ACD Systems\ACDSee Pro\4.0\ACDSeeQVPro4.exe,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACDSeePro40ImportVideoFilesOnArrival
Action REG_SZ Import videos
Provider REG_SZ ACDSee Pro 4
InvokeProgID REG_SZ ACDSee Pro 4.AutoPlayHandlerImport
InvokeVerb REG_SZ Import
DefaultIcon REG_SZ C:\Program Files\ACD Systems\ACDSee Pro\4.0\ACDSeeQVPro4.exe,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACDSeePro40PlayVideoFilesOnArrival
Action REG_SZ Manage videos
Provider REG_SZ ACDSee Pro 4
InvokeProgID REG_SZ ACDSee Pro 4.AutoPlayHandler
InvokeVerb REG_SZ Open
DefaultIcon REG_SZ C:\Program Files\ACD Systems\ACDSee Pro\4.0\ACDSeeQVPro4.exe,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACDSeePro40ShowPicturesOnArrival
Action REG_SZ Manage pictures
Provider REG_SZ ACDSee Pro 4
InvokeProgID REG_SZ ACDSee Pro 4.AutoPlayHandler
InvokeVerb REG_SZ Open
DefaultIcon REG_SZ C:\Program Files\ACD Systems\ACDSee Pro\4.0\ACDSeeQVPro4.exe,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MPCPlayCDAudioOnArrival
Action REG_SZ Play Audio CD
DefaultIcon REG_SZ "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe",4
InvokeProgID REG_SZ MediaPlayerClassic.Autorun
InvokeVerb REG_SZ PlayCDAudio
Provider REG_SZ Media Player Classic
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MPCPlayDVDMovieOnArrival
Action REG_SZ Play DVD Movie
DefaultIcon REG_SZ "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe",3
InvokeProgID REG_SZ MediaPlayerClassic.Autorun
InvokeVerb REG_SZ PlayDVDMovie
Provider REG_SZ Media Player Classic
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MPCPlayMusicFilesOnArrival
Action REG_SZ Play Music
DefaultIcon REG_SZ "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe",0
InvokeProgID REG_SZ MediaPlayerClassic.Autorun
InvokeVerb REG_SZ PlayMusicFiles
Provider REG_SZ Media Player Classic
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MPCPlayVideoFilesOnArrival
Action REG_SZ Play Video
DefaultIcon REG_SZ "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe",0
InvokeProgID REG_SZ MediaPlayerClassic.Autorun
InvokeVerb REG_SZ PlayVideoFiles
Provider REG_SZ Media Player Classic
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSCDBurningOnArrival
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,-5
Action REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17169
Provider REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17170
InvokeProgID REG_SZ Folder
InvokeVerb REG_SZ open
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSOpenFolder
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,-5
Action REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17154
Provider REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17155
InvokeProgID REG_SZ Folder
InvokeVerb REG_SZ open
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPlayCDAudioOnArrival
Action REG_SZ @wmploc.dll,-6503
Provider REG_SZ @wmploc.dll,-6502
InvokeProgID REG_SZ WMP.AudioCD
InvokeVerb REG_SZ play
DefaultIcon REG_EXPAND_SZ %ProgramFiles%\Windows Media Player\wmplayer.exe,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPlayDVDMovieOnArrival
Action REG_SZ @wmploc.dll,-6504
Provider REG_SZ @wmploc.dll,-6502
InvokeProgID REG_SZ WMP.DVD
InvokeVerb REG_SZ play
DefaultIcon REG_EXPAND_SZ %ProgramFiles%\Windows Media Player\wmplayer.exe,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPlayMediaOnArrival
Action REG_SZ @wmploc.dll,-1800
Provider REG_SZ @wmploc.dll,-6502
InvokeProgid REG_SZ WMP.PlayMedia
InvokeVerb REG_SZ play
DefaultIcon REG_SZ C:\Program Files\Windows Media Player\wmplayer.exe,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPrintPicturesOnArrival
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,-17
Action REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17158
Provider REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17159
InvokeProgID REG_SZ Applications\shimgvw.dll
InvokeVerb REG_SZ print
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPromptEachTime
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,-3
Action REG_SZ Prompt each time
Provider REG_SZ Windows Explorer
ProgID REG_SZ Shell.Autoplay
InitCmdLine REG_SZ PromptEachTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPromptEachTimeNoContent
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,-3
Action REG_SZ Prompt each time - No Content
Provider REG_SZ Windows Explorer
ProgID REG_SZ Shell.Autoplay
InitCmdLine REG_SZ PromptEachTimeNoContent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSRipCDAudioOnArrival
Action REG_SZ @wmploc.dll,-6506
Provider REG_SZ @wmploc.dll,-6502
InvokeProgID REG_SZ WMP.RipCD
InvokeVerb REG_SZ Rip
DefaultIcon REG_EXPAND_SZ %ProgramFiles%\Windows Media Player\wmplayer.exe,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSSHAudioDevHandler
<NO NAME> REG_SZ
Action REG_SZ @%SystemRoot%\system32\Audiodev.dll,-500
Provider REG_SZ @%SystemRoot%\system32\Audiodev.dll,-501
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\Audiodev.dll,-50
ProgID REG_SZ Shell.HWEventHandlerShellExecute
InitCmdLine REG_SZ ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{21EC2020-3AEA-1069-A2DD-08002B30309D}\::{640167b4-59b0-47a6-b335-a6b3c0695aea}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSShowPicturesOnArrival
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,-249
Action REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17156
Provider REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17157
InvokeProgID REG_SZ Shell.AutoplayForSlideShow.1
InvokeVerb REG_SZ open
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSTakeNoAction
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,-338
Action REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17168
Provider REG_SZ <TakeNoAction>
ProgID REG_SZ Shell.AutoplaySpecial
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSVideoCameraArrival
InitCmdLine REG_SZ "C:\Program Files\Movie Maker\moviemk.exe" /RECORD
ProgID REG_SZ Shell.HWEventHandlerShellExecute
DefaultIcon REG_SZ C:\Program Files\Movie Maker\moviemk.exe,0
CLSIDForCancel REG_SZ {AB007EC8-E2D4-4664-ACD9-1D059681F3DE}
Action REG_SZ @C:\Program Files\Movie Maker\wmm2res.dll,-63095
Provider REG_SZ @C:\Program Files\Movie Maker\wmm2res.dll,-100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSWiaEventHandler
ProgID REG_SZ WiaDevMgr
Action REG_SZ @%systemroot%\System32\wiaacmgr.exe,-276
Provider REG_SZ @%systemroot%\System32\wiaacmgr.exe,-101
DefaultIcon REG_EXPAND_SZ %systemroot%\System32\wiaacmgr.exe,-2
InvokeProgID REG_SZ WIA.AutoplayDropHandler.1
InvokeVerb REG_SZ open
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSWMDMHandler
Action REG_SZ @wmploc.dll,-29300
CLSIDForCancel REG_SZ {91778246-9BE4-4713-A651-E833B853CC30}
DefaultIcon REG_EXPAND_SZ %ProgramFiles%\Windows Media Player\wmplayer.exe,0
ProgID REG_SZ WMP.Device
Provider REG_SZ @wmploc.dll,-6502
InitCmdLine REG_EXPAND_SZ "%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:3 /task:PortableDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSWMPBurnCDOnArrival
Action REG_SZ @wmploc.dll,-6505
Provider REG_SZ @wmploc.dll,-6502
InvokeProgID REG_SZ WMP.BurnCD
InvokeVerb REG_SZ Burn
DefaultIcon REG_EXPAND_SZ %ProgramFiles%\Windows Media Player\wmplayer.exe,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\NeroAutoPlay7AudioToNeroDigital
Action REG_SZ Convert Audio CDs to Nero Digital Audio
DefaultIcon REG_SZ C:\Program Files\Common Files\Ahead\Lib\ShellManager.dll,-501
Provider REG_SZ Nero Burning ROM
InvokeProgID REG_SZ Nero.AutoPlay7
InvokeVerb REG_SZ AudioToNeroDigital_PlayCDAudioOnArrival
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\NeroAutoPlay7CDAudio
Action REG_SZ Make Audio CD
DefaultIcon REG_SZ C:\Program Files\Common Files\Ahead\Lib\ShellManager.dll,-503
Provider REG_SZ Nero Express
InvokeProgID REG_SZ Nero.AutoPlay7
InvokeVerb REG_SZ CDAudio_HandleCDBurningOnArrival
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\NeroAutoPlay7CopyCD
Action REG_SZ Copy CD
DefaultIcon REG_SZ C:\Program Files\Common Files\Ahead\Lib\ShellManager.dll,-504
Provider REG_SZ Nero Burning ROM
InvokeProgID REG_SZ Nero.AutoPlay7
InvokeVerb REG_SZ CopyCD_PlayMusicFilesOnArrival
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\NeroAutoPlay7DataDisc
Action REG_SZ Make Data Disc
DefaultIcon REG_SZ C:\Program Files\Common Files\Ahead\Lib\ShellManager.dll,-505
Provider REG_SZ Nero Express
InvokeProgID REG_SZ Nero.AutoPlay7
InvokeVerb REG_SZ DataDisc_HandleCDBurningOnArrival
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\NeroAutoPlay7LaunchNeroStartSmart
Action REG_SZ Create Your Own Disc
DefaultIcon REG_SZ C:\Program Files\Common Files\Ahead\Lib\ShellManager.dll,-508
Provider REG_SZ Nero StartSmart
InvokeProgID REG_SZ Nero.AutoPlay7
InvokeVerb REG_SZ LaunchNeroStartSmart_HandleCDBurningOnArrival
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\NeroAutoPlay7RipCD
Action REG_SZ Convert Audio CDs to Audio Files
DefaultIcon REG_SZ C:\Program Files\Common Files\Ahead\Lib\ShellManager.dll,-511
Provider REG_SZ Nero Burning ROM
InvokeProgID REG_SZ Nero.AutoPlay7
InvokeVerb REG_SZ RipCD_PlayCDAudioOnArrival
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\NeroAutoPlay7VideoCapture
Action REG_SZ Capture Video
DefaultIcon REG_SZ C:\Program Files\Common Files\Ahead\Lib\ShellManager.dll,-502
Provider REG_SZ Nero Vision
ProgID REG_SZ Shell.HWEventHandlerShellExecute
InitCmdLine REG_SZ "C:\Program Files\Nero\Nero 7\Nero Vision\NeroVision.exe" /New:VideoCapture
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Syncmgr\Handlers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Syncmgr\Handlers\{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}
<NO NAME> REG_SZ WebCheck SyncMgr Handler
! REG.EXE VERSION 3.0
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Syncmgr\Handlers
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Syncmgr\Handlers
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Syncmgr\Handlers
! REG.EXE VERSION 3.0
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Syncmgr\Handlers
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Clock.ini
<NO NAME> REG_SZ #USR:Software\Microsoft\Clock
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\control.ini
Color Schemes REG_SZ #USR:Control Panel\Color Schemes
Current REG_SZ #USR:Control Panel\Current
Custom Colors REG_SZ #USR:Control Panel\Custom Colors
don't load REG_SZ USR:Control Panel\don't load
drivers.desc REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\drivers.desc
MMCPL REG_SZ USR:Control Panel\MMCPL
Patterns REG_SZ #USR:Control Panel\Patterns
related.desc REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\related.desc
Screen Saver.3DFlowerBox REG_SZ USR:Control Panel\Screen Saver.3DFlowerBox
Screen Saver.3DFlyingObj REG_SZ USR:Control Panel\Screen Saver.3DFlyingObj
Screen Saver.3DMaze REG_SZ USR:Control Panel\Screen Saver.3DMaze
Screen Saver.3DPipes REG_SZ USR:Control Panel\Screen Saver.3DPipes
Screen Saver.3DText REG_SZ USR:Control Panel\Screen Saver.3DText
Screen Saver.Bezier REG_SZ USR:Control Panel\Screen Saver.Bezier
Screen Saver.Marquee REG_SZ #USR:Control Panel\Screen Saver.Marquee
Screen Saver.Mystify REG_SZ #USR:Control Panel\Screen Saver.Mystify
Screen Saver.Stars REG_SZ #USR:Control Panel\Screen Saver.Stars
Userinstallable.drivers REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\Userinstallable.drivers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\ImageFileExecutionOptions.ini
<NO NAME> REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Irremote.ini
Nero Home REG_SZ USR:Software\Ahead\Shared\RemoteCtrl\HppgeIni\Nero Home
Nero Home Essentials REG_SZ USR:Software\Ahead\Shared\RemoteCtrl\HppgeIni\Nero Home
Nero Home Essentials SE REG_SZ USR:Software\Ahead\Shared\RemoteCtrl\HppgeIni\Nero Home
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Irremote.ini\Applications
Default REG_SZ USR:Software\Ahead\Shared\RemoteCtrl\HppgeIni\Applications
Nero Home REG_SZ USR:Software\Ahead\Shared\RemoteCtrl\HppgeIni\Applications
Nero Home Essentials REG_SZ USR:Software\Ahead\Shared\RemoteCtrl\HppgeIni\Applications
Nero Home Essentials SE REG_SZ USR:Software\Ahead\Shared\RemoteCtrl\HppgeIni\Applications
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\KeyboardLayout.ini
<NO NAME> REG_SZ
Preload REG_SZ USR:Keyboard Layout\Preload
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\KeyboardLayout.ini\Keyboard Layout
<NO NAME> REG_SZ \Registry\Machine\System\CurrentControlSet\Control\Keyboard Layout
Active REG_SZ USR:Keyboard Layout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\KeyboardLayout.ini\Substitutes
<NO NAME> REG_SZ USR:Keyboard Layout\Substitutes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\msacm.ini
<NO NAME> REG_SZ USR:Software\Microsoft\Multimedia\Audio Compression Manager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Ntbackup.ini
<NO NAME> REG_SZ #USR:Software\Microsoft\Ntbackup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\ntnet.ini
<NO NAME> REG_SZ USR:Software\Microsoft\Windows NT\CurrentVersion\Network
Shared Parameters REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\Network\World Full Access Shared Parameters
SMAddOns REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\Network\SMAddOns
UMAddOns REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\Network\UMAddOns
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\regedt32.ini
<NO NAME> REG_SZ USR:Software\Microsoft\RegEdt32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\schdpl32.ini
<NO NAME> REG_SZ USR:Software\Microsoft\Schedule+
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini
boot.description REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot.description
drivers REG_SZ #SYS:Microsoft\Windows NT\CurrentVersion\drivers
drivers32 REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\Drivers32
keyboard REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\WOW\keyboard
MCI REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\MCI
MCI32 REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\MCI32
msacm.drv REG_SZ USR:Software\Microsoft\Multimedia\Sound Mapper
NonWindowsApp REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\WOW\NonWindowsApp
standard REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\WOW\standard
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\boot
<NO NAME> REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot
ScreenSaverActive REG_SZ USR:Control Panel\Desktop
ScreenSaverIsSecure REG_SZ USR:Control Panel\Desktop
SCRNSAVE.EXE REG_SZ USR:Control Panel\Desktop
Shell REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\Winlogon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini
AeDebug REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\AeDebug
Clock REG_SZ #USR:Software\Microsoft\Clock
Colors REG_SZ #USR:Control Panel\Colors
Compatibility REG_SZ #SYS:Microsoft\Windows NT\CurrentVersion\Compatibility
Console REG_SZ USR:Console
Cursors REG_SZ #USR:Control Panel\Cursors
DeskTop REG_SZ #USR:Control Panel\Desktop
Devices REG_SZ USR:Software\Microsoft\Windows NT\CurrentVersion\Devices
Embedding REG_SZ !#SYS:Microsoft\Windows NT\CurrentVersion\Embedding
Extensions REG_SZ #USR:Software\Microsoft\Windows NT\CurrentVersion\Extensions
Fonts REG_SZ #SYS:Microsoft\Windows NT\CurrentVersion\Fonts
FontSubstitutes REG_SZ #SYS:Microsoft\Windows NT\CurrentVersion\FontSubstitutes
GRE_Initialize REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\GRE_Initialize
Intl REG_SZ #USR:Control Panel\International
IOProcs REG_SZ #USR:Control Panel\IOProcs
MCI Extensions REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\MCI Extensions
ModuleCompatibility REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\ModuleCompatibility
MSCharMap REG_SZ #USR:Software\Microsoft\Charmap
Net_Files REG_SZ USR:Software\Microsoft\Windows NT\CurrentVersion\Network\Persistent Connections
NWCS REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\NWCS
Ports REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\Ports
PrinterPorts REG_SZ USR:Software\Microsoft\Windows NT\CurrentVersion\PrinterPorts
Sounds REG_SZ #USR:Control Panel\Sounds
TrueType REG_SZ #USR:Software\Microsoft\Windows NT\CurrentVersion\TrueType
Twain REG_SZ #USR:Software\Microsoft\Windows NT\CurrentVersion\Twain
Windows Help REG_SZ USR:Software\Microsoft\Windows Help
Winlogon REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\Winlogon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Network
<NO NAME> REG_SZ USR:Software\Microsoft\Windows NT\CurrentVersion\Network\Persistent Connections
ExpandLogonDomain REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\Network\World Full Access Shared Parameters
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows
<NO NAME> REG_SZ USR:Software\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\Windows
Beep REG_SZ #USR:Control Panel\Sound
BorderWidth REG_SZ #USR:Control Panel\Desktop\WindowMetrics
CoolSwitch REG_SZ USR:Control Panel\Desktop
CursorBlinkRate REG_SZ #USR:Control Panel\Desktop
DefaultSeparateVDM REG_SZ \Registry\Machine\System\CurrentControlSet\Control\WOW
DeviceNotSelectedTimeout REG_SZ #SYS:Microsoft\Windows NT\CurrentVersion\Windows
DoubleClickHeight REG_SZ #USR:Control Panel\Mouse
DoubleClickSpeed REG_SZ #USR:Control Panel\Mouse
DoubleClickWidth REG_SZ #USR:Control Panel\Mouse
DragFullWindows REG_SZ USR:Control Panel\Desktop
InitialKeyboardIndicators REG_SZ USR:Control Panel\Keyboard
KeyboardDelay REG_SZ #USR:Control Panel\Keyboard
KeyboardSpeed REG_SZ #USR:Control Panel\Keyboard
LowPowerActive REG_SZ #USR:Control Panel\Desktop
LowPowerTimeOut REG_SZ #USR:Control Panel\Desktop
MouseSpeed REG_SZ #USR:Control Panel\Mouse
MouseThreshold1 REG_SZ #USR:Control Panel\Mouse
MouseThreshold2 REG_SZ #USR:Control Panel\Mouse
PowerOffActive REG_SZ #USR:Control Panel\Desktop
PowerOffTimeOut REG_SZ #USR:Control Panel\Desktop
ScreenSaveActive REG_SZ #USR:Control Panel\Desktop
ScreenSaveTimeOut REG_SZ #USR:Control Panel\Desktop
SnapToDefaultButton REG_SZ #USR:Control Panel\Mouse
Spooler REG_SZ #SYS:Microsoft\Windows NT\CurrentVersion\Windows
swapdisk REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\Windows
SwapMouseButtons REG_SZ #USR:Control Panel\Mouse
TransmissionRetryTimeout REG_SZ #SYS:Microsoft\Windows NT\CurrentVersion\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\winfile.ini
AddOns REG_SZ SYS:Microsoft\Windows NT\CurrentVersion\File Manager\AddOns
Settings REG_SZ #USR:Software\Microsoft\File Manager\Settings