[Version] Signature = "$Windows NT$" ClassGUID={00000000-0000-0000-0000-000000000000} [AddReg] ; ; Core entries ; HKLM,"ControlSet001\Control\GraphicsDrivers\DCI","Timeout",REG_DWORD,0x7 HKLM,"ControlSet001\Control\ProductOptions","ProductSuite",REG_MULTI_SZ,"" HKLM,"ControlSet001\Control\ProductOptions","ProductType",,"WinNT" HKLM,"ControlSet001\Control\SecurityProviders","SecurityProviders",REG_SZ,"schannel.dll" HKLM,"ControlSet001\Control\SecurityProviders\SaslProfiles","GSSAPI",REG_SZ,"Kerberos" HKLM,"ControlSet001\Control\Session Manager\","BootExecute",0x00010002,"" HKLM,"ControlSet001\Control\Session Manager\AppCompatability" HKLM,"ControlSet001\Control\Session Manager\AppPatches" HKLM,"ControlSet001\Control\Session Manager\DOS Devices","AUX",REG_SZ,"\DosDevices\COM1" HKLM,"ControlSet001\Control\Session Manager\DOS Devices","MAILSLOT",REG_SZ,"\Device\MailSlot" HKLM,"ControlSet001\Control\Session Manager\DOS Devices","NUL",REG_SZ,"\Device\Null" HKLM,"ControlSet001\Control\Session Manager\DOS Devices","PIPE",REG_SZ,"\Device\NamedPipe" HKLM,"ControlSet001\Control\Session Manager\DOS Devices","PRN",REG_SZ,"\DosDevices\LPT1" HKLM,"ControlSet001\Control\Session Manager\DOS Devices","UNC",REG_SZ,"\Device\Mup" HKLM,"ControlSet001\Control\Session Manager\Environment","OS",REG_SZ,"Windows_NT" HKLM,"ControlSet001\Control\Session Manager\Environment","Path",REG_EXPAND_SZ,"%SystemRoot%;%SystemRoot%\System32" HKLM,"ControlSet001\Control\Session Manager\Executive" HKLM,"System\WPA\Pnp","Seed", REG_DWORD, 0x1B7D38EA HKLM,"ControlSet001\Control\Session Manager\FileRenameOperations" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","advapi32",,"advapi32.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","comdlg32",,"comdlg32.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","DllDirectory",REG_EXPAND_SZ,"%systemroot%\system32" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","gdi32",,"gdi32.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","imagehlp",,"imagehlp.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","kernel32",,"kernel32.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","lz32",,"lz32.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","ole32",,"ole32.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","oleaut32",,"oleaut32.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","olecli32",,"olecli32.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","olecnv32",,"olecnv32.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","olesvr32",,"olesvr32.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","olethk32",,"olethk32.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","rpcrt4",,"rpcrt4.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","shell32",,"shell32.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","url",,"url.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","urlmon",,"urlmon.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","user32",,"user32.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","version",,"version.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","wininet",,"wininet.dll" HKLM,"ControlSet001\Control\Session Manager\KnownDLLs","wldap32",,"wldap32.dll" HKLM,"ControlSet001\Control\Session Manager\Power" HKLM,"ControlSet001\Control\Session Manager\SFC","CommonFilesDir",REG_SZ,"\" HKLM,"ControlSet001\Control\Session Manager\SFC","ProgramFilesDir",REG_SZ,"\" HKLM,"ControlSet001\Control\Session Manager\SubSystems","Debug",REG_EXPAND_SZ, HKLM,"ControlSet001\Control\Session Manager\SubSystems","kmode",REG_EXPAND_SZ,"%SystemRoot%\System32\win32k.sys" HKLM,"ControlSet001\Control\Session Manager\SubSystems","Required",REG_MULTI_SZ,"Debug","Windows" HKLM,"ControlSet001\Control\Session Manager\SubSystems","Windows",REG_EXPAND_SZ,"%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization, 3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16" HKLM,"ControlSet001\Services\i8042prt","Group",,"Keyboard Port" HKLM,"ControlSet001\Services\i8042prt","Start",REG_DWORD,0x01 HKLM,"ControlSet001\Services\i8042prt","Type",REG_DWORD,0x01 HKLM,"ControlSet001\Services\i8042prt\Parameters","PollingIterations",REG_DWORD,0x2ee0 HKLM,"ControlSet001\Services\i8042prt\Parameters","PollingIterationsMaximum",REG_DWORD,0x2ee0 HKLM,"ControlSet001\Services\i8042prt\Parameters","ResendIterations",REG_DWORD,0x03 HKLM,"ControlSet001\Services\kbdclass","Group",,"Keyboard Class" HKLM,"ControlSet001\Services\kbdclass","ImagePath",REG_EXPAND_SZ,"System32\drivers\kbdclass.sys" HKLM,"ControlSet001\Services\kbdclass","Start",REG_DWORD,0x1 HKLM,"ControlSet001\Services\kbdclass","Tag",REG_DWORD,0x1 HKLM,"ControlSet001\Services\kbdclass","Type",REG_DWORD,0x1 HKLM,"ControlSet001\Services\kbdclass\Parameters","ConnectMultiplePorts",REG_DWORD,0x0 HKLM,"ControlSet001\Services\kbdclass\Parameters","ConnectMultiplePortsChanged",REG_DWORD,0x1 HKLM,"ControlSet001\Services\kbdclass\Parameters","ConnectMultiplePortsUpgraded",REG_DWORD,0x1 HKLM,"ControlSet001\Services\kbdclass\Parameters","KeyboardDataQueueSize",REG_DWORD,0x64 HKLM,"ControlSet001\Services\kbdclass\Parameters","KeyboardDeviceBaseName",,"KeyboardClass" HKLM,"ControlSet001\Services\kbdclass\Parameters","MaximumPortsServiced",REG_DWORD,0x03 HKLM,"ControlSet001\Services\kbdclass\Parameters","SentOutputToAllPorts",REG_DWORD,0x01 HKLM,"ControlSet001\Services\mouclass","Group",,"Pointer Class" HKLM,"ControlSet001\Services\mouclass","ImagePath",REG_EXPAND_SZ,"System32\drivers\mouclass.sys" HKLM,"ControlSet001\Services\mouclass","Start",REG_DWORD,0x1 HKLM,"ControlSet001\Services\mouclass","Tag",REG_DWORD,0x1 HKLM,"ControlSet001\Services\mouclass","Type",REG_DWORD,0x1 HKLM,"ControlSet001\Services\mouclass\Parameters","ConnectMultiplePorts",REG_DWORD,0x0 HKLM,"ControlSet001\Services\mouclass\Parameters","ConnectMultiplePortsChanged",REG_DWORD,0x1 HKLM,"ControlSet001\Services\mouclass\Parameters","ConnectMultiplePortsUpgraded",REG_DWORD,0x1 HKLM,"ControlSet001\Services\mouclass\Parameters","MaximumPortsServiced",REG_DWORD,0x3 HKLM,"ControlSet001\Services\mouclass\Parameters","MouseDataQueueSize",REG_DWORD,0x64 HKLM,"ControlSet001\Services\mouclass\Parameters","PointerDeviceBaseName",,"PointerClass" HKLM,"ControlSet001\Services\VgaSave","ErrorControl",0x00010003,0 HKLM,"ControlSet001\Services\VgaSave","Group",0x00000000,"Video Save" HKLM,"ControlSet001\Services\VgaSave","ImagePath",0x00020000,"\SystemRoot\System32\drivers\vga.sys" HKLM,"ControlSet001\Services\VgaSave","Start",0x00010001,1 HKLM,"ControlSet001\Services\VgaSave","Tag",0x00010001,1 HKLM,"ControlSet001\Services\VgaSave","Type",0x00010001,1 HKLM,"ControlSet001\Services\VgaSave\Video","VideoID",0x00000000,"{23A77BF7-ED96-40EC-AF06-9B1F4867732A}" HKLM,"ControlSet001\Services\VgaSave\Video","Service",0x00000000,"VgaSave" HKLM,"ControlSet001\Services\VgaSave\Device0","InstalledDisplayDrivers",0x00010000,"vga", "framebuf", "vga256", "vga64k" HKLM,"ControlSet001\Services\VgaSave\Device0","VgaCompatible",0x00010001,1 HKLM,"ControlSet001\Control\Video\{23A77BF7-ED96-40EC-AF06-9B1F4867732A}\Video","Service",0x00000000,"VgaSave" HKLM,"ControlSet001\Control\Video\{23A77BF7-ED96-40EC-AF06-9B1F4867732A}\0000","InstalledDisplayDrivers",0x00010000,"vga", "framebuf", "vga256", "vga64k" HKLM,"ControlSet001\Control\Video\{23A77BF7-ED96-40EC-AF06-9B1F4867732A}\0000","VgaCompatible",0x00010001,1 ; ; startup configuration ; HKLM,"Setup","CmdLine",,"cmd.exe /k startnet.cmd" HKLM,"Setup","OsLoaderPath",,"\" HKLM,"Setup","SetupType",REG_DWORD,0x01 HKLM,"Setup","SystemSetupInProgress",REG_DWORD,0x01 HKLM,"Setup\AllowStart\AFD" HKLM,"Setup\AllowStart\EventLog" HKLM,"Setup\AllowStart\PlugPlay" HKLM,"Setup\AllowStart\ProtectedStorage" HKLM,"Setup\AllowStart\Rpcss" HKLM,"Setup\AllowStart\Samss" HKLM,"Setup\AllowStart\Seclogon" HKLM,"Setup\AllowStart\WS2IFSL" ; ; Subsys & services ; HKLM,"SYSTEM\ControlSet001\Control\Session Manager\Environment","ComSpec",0x00020002,"%SystemRoot%\system32\cmd.exe" HKLM,"SYSTEM\ControlSet001\Control\Session Manager\Environment","Path",0x00020002,"%SystemRoot%\system32;%SystemRoot%" HKLM,"SYSTEM\ControlSet001\Control\Session Manager\Environment","windir",0x00020002,"%SystemRoot%" HKLM,"SYSTEM\ControlSet001\Control\PriorityControl","Win32PrioritySeparation",0x00010003,2 HKLM,"SYSTEM\ControlSet001\Services\EventLog\Security",,0x00000012 HKLM,"SYSTEM\ControlSet001\Control\Lsa","Authentication Packages",0x00010002,"msv1_0" HKLM,"SYSTEM\ControlSet001\Control\Lsa","Bounds",0x00030003,\ 00,30,00,00,00,20,00,00 HKLM,"SYSTEM\ControlSet001\Control\Lsa","Security Packages",0x00010000,"kerberos","msv1_0","schannel" HKLM,"SYSTEM\ControlSet001\Control\Lsa\AccessProviders","ProviderOrder",0x00010002,"Windows NT Access Provider" HKLM,"SYSTEM\ControlSet001\Control\Lsa\AccessProviders\Windows NT AccessProvider","ProviderPath",0x00020002,"%SystemRoot%\system32\ntmarta.dll" HKLM,"SYSTEM\ControlSet001\Control\Lsa\MSV1_0","Auth132",0x00000002,"IISSUBA" HKLM,"SYSTEM\ControlSet001\Services\WinTrust",,0x00000012 HKLM,"SYSTEM\ControlSet001\Services\WinTrust\SubjectPackages",,0x00000012 HKLM,"SYSTEM\ControlSet001\Services\WinTrust\SubjectPackages\MS Subjects 1","$DLL",0x00020002,"%SystemRoot%\system32\MsSip1.dll" HKLM,"SYSTEM\ControlSet001\Services\WinTrust\SubjectPackages\MS Subjects 2","$DLL",0x00020002,"%SystemRoot%\system32\MsSip2.dll" HKLM,"SYSTEM\ControlSet001\Services\WinTrust\SubjectPackages\MS Subjects 3","$DLL",0x00020002,"%SystemRoot%\system32\MsSip3.dll" HKLM,"SYSTEM\ControlSet001\Services\WinTrust\TrustProviders",,0x00000012 HKLM,"SYSTEM\ControlSet001\Services\WinTrust\TrustProviders\Software Publisher","$DLL",0x00020002,"%SystemRoot%\system32\SoftPub.dll" HKLM,"SYSTEM\ControlSet001\Services\Afd","DisplayName",0x00000000,"AFD Networking Support Environment" HKLM,"SYSTEM\ControlSet001\Services\Afd","ErrorControl",0x00010003,1 HKLM,"SYSTEM\ControlSet001\Services\Afd","Group",0x00000002,"TDI" HKLM,"SYSTEM\ControlSet001\Services\Afd","ImagePath",0x00020002,"\SystemRoot\system32\drivers\afd.sys" HKLM,"SYSTEM\ControlSet001\Services\Afd","Start",0x00010003,3 HKLM,"SYSTEM\ControlSet001\Services\Afd","Type",0x00010003,1 HKLM,"SYSTEM\ControlSet001\Services\Msfs","ErrorControl",0x00010003,1 HKLM,"SYSTEM\ControlSet001\Services\Msfs","Group",0x00000002,"File system" HKLM,"SYSTEM\ControlSet001\Services\Msfs","Start",0x00010003,1 HKLM,"SYSTEM\ControlSet001\Services\Msfs","Type",0x00010003,2 HKLM,"SYSTEM\ControlSet001\Services\Null","ErrorControl",0x00010003,1 HKLM,"SYSTEM\ControlSet001\Services\Null","Group",0x00000002,"Base" HKLM,"SYSTEM\ControlSet001\Services\Null","Start",0x00010003,1 HKLM,"SYSTEM\ControlSet001\Services\Null","Tag",0x00010003,1 HKLM,"SYSTEM\ControlSet001\Services\Null","Type",0x00010003,1 HKLM,"SYSTEM\ControlSet001\Services\Beep","ErrorControl",0x00010003,1 HKLM,"SYSTEM\ControlSet001\Services\Beep","Group",0x00000002,"Base" HKLM,"SYSTEM\ControlSet001\Services\Beep","Start",0x00010001,1 HKLM,"SYSTEM\ControlSet001\Services\Beep","Tag",0x00010003,2 HKLM,"SYSTEM\ControlSet001\Services\Beep","Type",0x00010003,1 HKLM,"ControlSet001\Services\Npfs","ErrorControl",0x00010003,1 HKLM,"ControlSet001\Services\Npfs","Group",0x00000002,"File system" HKLM,"ControlSet001\Services\Npfs","Start",0x00010003,1 HKLM,"ControlSet001\Services\Npfs","Type",0x00010003,2 HKLM,"ControlSet001\Services\Npfs\Aliases","lsass",0x00010002,"protected_storage","netlogon","lsarpc","samr" HKLM,"ControlSet001\Services\Npfs\Aliases","ntsvcs",0x00010000,"eventlog","svcctl" HKLM,"ControlSet001\Services\PlugPlay","Description",0x00000000,"%PLUG_AND_PLAY_DESCRIPTION%" HKLM,"ControlSet001\Services\PlugPlay","DisplayName",0x00000000,"%PLUG_AND_PLAY%" HKLM,"ControlSet001\Services\PlugPlay","ErrorControl",0x00010003,1 HKLM,"ControlSet001\Services\PlugPlay","Group",0x00000002,"PlugPlay" HKLM,"ControlSet001\Services\PlugPlay","ImagePath",0x00020002,"%SystemRoot%\system32\services.exe" HKLM,"ControlSet001\Services\PlugPlay","ObjectName",0x00000002,"LocalSystem" HKLM,"ControlSet001\Services\PlugPlay","PlugPlayServiceType",0x00010003,3 HKLM,"ControlSet001\Services\PlugPlay","Start",0x00010001,2 HKLM,"ControlSet001\Services\PlugPlay","Type",0x00010003,32 HKLM,"ControlSet001\Services\ProtectedStorage","DependOnService",0x00010002,"RpcSs" HKLM,"ControlSet001\Services\ProtectedStorage","Description",0x00000000,%PROTECTEDSTORAGE_DESCRIPTION% HKLM,"ControlSet001\Services\ProtectedStorage","DisplayName",0x00000000,%PROTECTEDSTORAGE_DISPLAYNAME% HKLM,"ControlSet001\Services\ProtectedStorage","ErrorControl",0x00010003,1 HKLM,"ControlSet001\Services\ProtectedStorage","ImagePath",0x00020000,"%SystemRoot%\system32\lsass.exe" HKLM,"ControlSet001\Services\ProtectedStorage","ObjectName",0x00000002,"LocalSystem" HKLM,"ControlSet001\Services\ProtectedStorage","Start",0x00010001,2 HKLM,"ControlSet001\Services\ProtectedStorage","Type",0x00010001,288 HKLM,"ControlSet001\Services\SamSs","Description",0x00000000,"%SECURITY_ACCOUNTS_MANAGER_DESCRIPTION%" HKLM,"ControlSet001\Services\SamSs","DisplayName",0x00000000,"%SECURITY_ACCOUNTS_MANAGER_SERVICE%" HKLM,"ControlSet001\Services\SamSs","ErrorControl",0x00010003,1 HKLM,"ControlSet001\Services\SamSs","ImagePath",0x00020002,"%SystemRoot%\system32\lsass.exe" HKLM,"ControlSet001\Services\SamSs","ObjectName",0x00000002,"LocalSystem" HKLM,"ControlSet001\Services\SamSs","Start",0x00010003,2 HKLM,"ControlSet001\Services\SamSs","Type",0x00010003,32 HKLM,"ControlSet001\Services\SamSs","Group",0x00000002,"LocalValidation" HKLM,"ControlSet001\Services\SamSs","DependOnService",0x00010000,"RPCSS" HKLM,"ControlSet001\Services\Samss\Security","Security",0x00030003,\ 01,00,14,80,b4,00,00,00,c0,00,00,00,14,00,00,00,34,00,00,00,02,00,20,00,01,\ 00,00,00,02,80,18,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,00,00,20,02,\ 00,00,02,00,80,00,05,00,00,00,00,03,18,00,8d,00,02,00,01,01,00,00,00,00,00,\ 01,00,00,00,00,00,00,00,00,00,03,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,20,02,00,00,00,03,18,00,8f,00,02,00,01,02,00,00,00,00,00,05,20,\ 00,00,00,23,02,00,00,00,03,18,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,\ 00,00,23,02,00,00,00,03,18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,\ 00,21,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,\ 12,00,00,00 HKLM,"ControlSet001\Services\RpcSs","Description",0x00000000,"%REMOTE_PROCEDURE_CALL_RPC_DESCRIPTION%" HKLM,"ControlSet001\Services\RpcSs","DisplayName",0x00000000,"%REMOTE_PROCEDURE_CALL_RPC_SERVICE%" HKLM,"ControlSet001\Services\RpcSs","ErrorControl",0x00010001,1 HKLM,"ControlSet001\Services\RpcSs","ImagePath",0x00020000,"%SystemRoot%\system32\svchost -k rpcss" HKLM,"ControlSet001\Services\RpcSs","ObjectName",0x00000000,"LocalSystem" HKLM,"ControlSet001\Services\RpcSs","Start",0x00010001,2 HKLM,"ControlSet001\Services\RpcSs","Type",0x00010001,32 HKLM,"ControlSet001\Services\RpcSs\Parameters",,0x00000012 HKLM,"ControlSet001\Services\RpcSs\Parameters","ServiceDll",0x00020002,"%SystemRoot%\system32\rpcss.dll" HKLM,"ControlSet001\Services\RpcSs\Security","Security",0x00030001,\ 01,00,14,80,b4,00,00,00,c0,00,00,00,14,00,00,00,34,00,00,00,02,00,20,00,01,\ 00,00,00,02,80,18,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,00,00,20,02,\ 00,00,02,00,80,00,05,00,00,00,00,03,18,00,8d,00,02,00,01,01,00,00,00,00,00,\ 01,00,00,00,00,00,00,00,00,00,03,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,20,02,00,00,00,03,18,00,8f,00,02,00,01,02,00,00,00,00,00,05,20,\ 00,00,00,23,02,00,00,00,03,18,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,\ 00,00,23,02,00,00,00,03,18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,\ 00,21,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,\ 12,00,00,00 HKLM,"ControlSet001\Services\Mup","DisplayName",0x00000002,"%MUP%" HKLM,"ControlSet001\Services\Mup","ErrorControl",0x00010003,1 HKLM,"ControlSet001\Services\Mup","Group",0x00000002,"Network" HKLM,"ControlSet001\Services\Mup","Start",0x00010003,0 HKLM,"ControlSet001\Services\Mup","Tag",0x00010003,2 HKLM,"ControlSet001\Services\Mup","Type",0x00010003,2 HKLM,"ControlSet001\Services\Mup\Parameters",,0x00000012 ; ; disk management entries ; ;;;;;;;;;;;;;;;;;;;;;;;;;;; ; LDM kernel entries ;;;;;;;;;;;;;;;;;;;;;;;;;;; ; Event logging HKLM,"System\ControlSet001\Services\EventLog\System\dmio","EventMessageFile",0x00020000,"%SystemRoot%\System32\IoLogMsg.dll;%SystemRoot%\System32\Drivers\dmio.sys" HKLM,"System\ControlSet001\Services\EventLog\System\dmio","TypesSupported",0x00010001,0x00000007 HKLM,"System\ControlSet001\Services\EventLog\System\dmboot","EventMessageFile",0x00020000,"%SystemRoot%\System32\Drivers\dmboot.sys" HKLM,"System\ControlSet001\Services\EventLog\System\dmboot","TypesSupported",0x00010001,0x00000007 ; Service registration ; dmload HKLM,"System\ControlSet001\Services\dmload","Type",0x00010001,0x00000001 HKLM,"System\ControlSet001\Services\dmload","Start",0x00010001,0x00000000 HKLM,"System\ControlSet001\Services\dmload","ErrorControl",0x00010001,0x00000001 HKLM,"System\ControlSet001\Services\dmload","Group",0x00000000,"System Bus Extender" HKLM,"System\ControlSet001\Services\dmload","Tag",0x00010001,0x0000000c HKLM,"System\ControlSet001\Services\dmload","ImagePath",0x00020000,"System32\drivers\dmload.sys" ; dmboot HKLM,"System\ControlSet001\Services\dmboot","Type",0x00010001,0x00000001 HKLM,"System\ControlSet001\Services\dmboot","Start",0x00010001,0x00000000 HKLM,"System\ControlSet001\Services\dmboot","ErrorControl",0x00010001,0x00000001 HKLM,"System\ControlSet001\Services\dmboot","Group",0x00000000,"Filter" HKLM,"System\ControlSet001\Services\dmboot","Tag",0x00010001,0x0000000b HKLM,"System\ControlSet001\Services\dmboot","ImagePath",0x00020000,"System32\drivers\dmboot.sys" ; dmio HKLM,"System\ControlSet001\Services\dmio","Type",0x00010001,0x00000001 HKLM,"System\ControlSet001\Services\dmio","Start",0x00010001,0x00000000 HKLM,"System\ControlSet001\Services\dmio","ErrorControl",0x00010001,0x00000001 HKLM,"System\ControlSet001\Services\dmio","Group",0x00000000,"System Bus Extender" HKLM,"System\ControlSet001\Services\dmio","Tag",0x00010001,0x0000000d HKLM,"System\ControlSet001\Services\dmio","ImagePath",0x00020000,"System32\drivers\dmio.sys" ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;; ; LDM watchdog service entries ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;; ; Service registration HKLM,"System\ControlSet001\Services\dmserver","DependOnService",0x00010002,"RpcSs","PlugPlay" HKLM,"System\ControlSet001\Services\dmserver","Type",0x00010001,0x00000020 HKLM,"System\ControlSet001\Services\dmserver","Start",0x00010001,0x00000002 HKLM,"System\ControlSet001\Services\dmserver","ErrorControl",0x00010001,0x00000001 HKLM,"System\ControlSet001\Services\dmserver","ImagePath",0x00020000,"%SystemRoot%\System32\svchost.exe -k netsvcs" HKLM,"System\ControlSet001\Services\dmserver","DisplayName",,%strDMServiceDispName% HKLM,"System\ControlSet001\Services\dmserver","ObjectName",,"LocalSystem" HKLM,"System\ControlSet001\Services\dmserver","Description",,%strDMServiceDescription% HKLM,"System\ControlSet001\Services\dmserver\Parameters","ServiceDll",0x00020000,"%SystemRoot%\System32\dmserver.dll" ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;; ; LDM administrative service entries ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;; ; Service registration HKLM,"System\ControlSet001\Services\dmadmin","DependOnService",0x00010002,"RpcSs","PlugPlay","DmServer" HKLM,"System\ControlSet001\Services\dmadmin","Type",0x00010001,0x00000020 HKLM,"System\ControlSet001\Services\dmadmin","Start",0x00010001,0x00000003 HKLM,"System\ControlSet001\Services\dmadmin","ErrorControl",0x00010001,0x00000001 HKLM,"System\ControlSet001\Services\dmadmin","ImagePath",0x00020000,"%SystemRoot%\System32\dmadmin.exe /com" HKLM,"System\ControlSet001\Services\dmadmin","DisplayName",,%strDMAdminDispName% HKLM,"System\ControlSet001\Services\dmadmin","ObjectName",,"LocalSystem" HKLM,"System\ControlSet001\Services\dmadmin","Description",,%strDMAdminDescription% ; Event logging HKLM,"System\ControlSet001\Services\EventLog\System\LDMS","EventMessageFile",0x00020000,"%SystemRoot%\System32\dmserver.dll" HKLM,"System\ControlSet001\Services\EventLog\System\LDMS","TypesSupported",0x00010001,0x00000007 ; Event logging HKLM,"System\ControlSet001\Services\EventLog\System\LDM","EventMessageFile",0x00020000,"%SystemRoot%\System32\dmadmin.exe" HKLM,"System\ControlSet001\Services\EventLog\System\LDM","TypesSupported",0x00010001,0x00000007 ; ; network configuration entries ; HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}","",0x00000002,"%NETWORK_ADAPTERS2%" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}","Class",0x00000002,"Net" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}","Icon",0x00000002,"-5" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}","Installer32",0x00000000,"NetCfgx.Dll,NetClassInstaller" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}","EnumPropPages32",0x00000000,"NetCfgx.Dll,NetPropPageProvider" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E973-E325-11CE-BFC1-08002BE10318}","",0x00000002,"%NETWORK_CLIENT%" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E973-E325-11CE-BFC1-08002BE10318}","Class",0x00000002,"NetClient" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E973-E325-11CE-BFC1-08002BE10318}","Icon",0x00000002,"-7" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E973-E325-11CE-BFC1-08002BE10318}","Installer32",0x00000000,"NetCfgx.Dll,NetClassInstaller" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E973-E325-11CE-BFC1-08002BE10318}","NoInstallClass",0x00000002,"1" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E973-E325-11CE-BFC1-08002BE10318}","NoDisplayClass",0x00000002,"1" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E974-E325-11CE-BFC1-08002BE10318}","",0x00000002,"%NETWORK_SERVICE%" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E974-E325-11CE-BFC1-08002BE10318}","Class",0x00000002,"NetService" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E974-E325-11CE-BFC1-08002BE10318}","Icon",0x00000002,"-8" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E974-E325-11CE-BFC1-08002BE10318}","Installer32",0x00000000,"NetCfgx.Dll,NetClassInstaller" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E974-E325-11CE-BFC1-08002BE10318}","NoInstallClass",0x00000002,"1" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E974-E325-11CE-BFC1-08002BE10318}","NoDisplayClass",0x00000002,"1" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E975-E325-11CE-BFC1-08002BE10318}","",0x00000002,"%NETWORK_PROTOCOL%" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E975-E325-11CE-BFC1-08002BE10318}","Class",0x00000002,"NetTrans" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E975-E325-11CE-BFC1-08002BE10318}","Icon",0x00000002,"-6" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E975-E325-11CE-BFC1-08002BE10318}","NoInstallClass",0x00000002,"1" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E975-E325-11CE-BFC1-08002BE10318}","NoDisplayClass",0x00000002,"1" HKLM,"SYSTEM\ControlSet001\Control\Class\{4D36E975-E325-11CE-BFC1-08002BE10318}","Installer32",0x00000000,"NetCfgx.Dll,NetClassInstaller" HKLM,"SYSTEM\ControlSet001\Control\CoDeviceInstallers",,0x00000012 HKLM,"SYSTEM\ControlSet001\Control\ComputerName",,0x00000012 ; ; modified ComputerName for miniNT...is MACHINENAME in hivesys ; HKLM,"SYSTEM\ControlSet001\Control\ComputerName\ComputerName","ComputerName",0x00000002,"MININT-JVC" HKLM,"SYSTEM\ControlSet001\Control\Network",,0x00000012 HKLM,"SYSTEM\ControlSet001\Control\Network\Connections","ClassManagers",0x00010000,\ "{BA126AD3-2166-11D1-B1D0-00805FC1270E}",\ "{BA126AD5-2166-11D1-B1D0-00805FC1270E}",\ "{BA126ADD-2166-11D1-B1D0-00805FC1270E}" HKLM,"SYSTEM\ControlSet001\Control\Network","FilterClasses",0x00010000,\ "scheduler",\ "loadbalance",\ "failover" HKLM,"SYSTEM\ControlSet001\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}","",0x00000002,"%NETWORK_ADAPTERS%" HKLM,"SYSTEM\ControlSet001\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}","Class",0x00000002,"Net" HKLM,"SYSTEM\ControlSet001\Control\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}","",0x00000002,"%NETWORK_CLIENT%" HKLM,"SYSTEM\ControlSet001\Control\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}","Class",0x00000002,"NetClient" HKLM,"SYSTEM\ControlSet001\Control\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}","",0x00000002,"%NETWORK_SERVICE%" HKLM,"SYSTEM\ControlSet001\Control\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}","Class",0x00000002,"NetService" HKLM,"SYSTEM\ControlSet001\Control\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}","",0x00000002,"%NETWORK_PROTOCOL%" HKLM,"SYSTEM\ControlSet001\Control\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}","Class",0x00000002,"NetTrans" HKLM,"SYSTEM\ControlSet001\Control\NetworkProvider",,0x00000012 HKLM,"SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder",,0x00000012 HKLM,"SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder","ProviderOrder",0x00000002,"LanmanWorkstation" HKLM,"SYSTEM\ControlSet001\Control\NetworkProvider\Order",,0x00000012 HKLM,"SYSTEM\ControlSet001\Control\NetworkProvider\Order","ProviderOrder",0x00000002,"LanmanWorkstation" ; ; services ; HKLM,"SYSTEM\ControlSet001\Services\NDIS","DisplayName",0x00000000,"%MICROSOFT_NDIS_SYSTEM_DRIVER%" HKLM,"SYSTEM\ControlSet001\Services\NDIS","ErrorControl",0x00010001,1 HKLM,"SYSTEM\ControlSet001\Services\NDIS","Group",0x00000000,"NDIS Wrapper" HKLM,"SYSTEM\ControlSet001\Services\NDIS","Start",0x00010001,0 HKLM,"SYSTEM\ControlSet001\Services\NDIS","Type",0x00010001,1 HKLM,"SYSTEM\ControlSet001\Services\NDIS\MediaTypes",,0x00000012 HKLM,"SYSTEM\ControlSet001\Services\NDIS\Parameters","ProcessorAffinityMask",0x00010003,4294967295 HKLM,"SYSTEM\ControlSet001\Services\NDProxy","DisplayName",0x00010002,"%NDIS_PROXY%" HKLM,"SYSTEM\ControlSet001\Services\NDProxy","ErrorControl",0x00010003,1 HKLM,"SYSTEM\ControlSet001\Services\NDProxy","Group",0x00000002,"PNP_TDI" HKLM,"SYSTEM\ControlSet001\Services\NDProxy","Start",0x00010001,3 HKLM,"SYSTEM\ControlSet001\Services\NDProxy","Type",0x00010003,1 HKLM,"SYSTEM\ControlSet001\Services\NetDDE","DependOnService",0x00010002,"NetDDEDSDM" HKLM,"SYSTEM\ControlSet001\Services\NetDDE","Description",0x00000000,"%NETWORK_DDE_DESCRIPTION%" HKLM,"SYSTEM\ControlSet001\Services\NetDDE","DisplayName",0x00000000,"%NETWORK_DDE%" HKLM,"SYSTEM\ControlSet001\Services\NetDDE","ErrorControl",0x00010003,1 HKLM,"SYSTEM\ControlSet001\Services\NetDDE","Group",0x00000002,"NetDDEGroup" HKLM,"SYSTEM\ControlSet001\Services\NetDDE","ImagePath",0x00020002,"%SystemRoot%\system32\netdde.exe" HKLM,"SYSTEM\ControlSet001\Services\NetDDE","ObjectName",0x00000002,"LocalSystem" HKLM,"SYSTEM\ControlSet001\Services\NetDDE","Start",0x00010003,4 HKLM,"SYSTEM\ControlSet001\Services\NetDDE","Type",0x00010003,32 HKLM,"SYSTEM\ControlSet001\Services\NetDDE\Security","Security",0x00030003,\ 01,00,14,80,9c,00,00,00,a8,00,00,00,14,00,00,00,34,00,00,00,02,00,20,00,01,\ 00,00,00,02,80,18,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,00,00,20,02,\ 00,00,02,00,68,00,04,00,00,00,00,03,18,00,8d,00,02,00,01,01,00,00,00,00,00,\ 01,00,00,00,00,00,00,00,00,00,03,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,20,02,00,00,00,03,18,00,8f,00,02,00,01,02,00,00,00,00,00,05,20,\ 00,00,00,23,02,00,00,00,03,18,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,\ 00,00,23,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,\ 05,12,00,00,00 HKLM,"SYSTEM\ControlSet001\Services\NetDDEdsdm","DependOnService",0x00010002 HKLM,"SYSTEM\ControlSet001\Services\NetDDEdsdm","Description",0x00000000,"%NETWORK_DDE_DSDM_DESCRIPTION%" HKLM,"SYSTEM\ControlSet001\Services\NetDDEdsdm","DisplayName",0x00000000,"%NETWORK_DDE_DSDM%" HKLM,"SYSTEM\ControlSet001\Services\NetDDEdsdm","ErrorControl",0x00010003,1 HKLM,"SYSTEM\ControlSet001\Services\NetDDEdsdm","ImagePath",0x00020002,"%SystemRoot%\system32\netdde.exe" HKLM,"SYSTEM\ControlSet001\Services\NetDDEdsdm","ObjectName",0x00000002,"LocalSystem" HKLM,"SYSTEM\ControlSet001\Services\NetDDEdsdm","Start",0x00010003,4 HKLM,"SYSTEM\ControlSet001\Services\NetDDEdsdm","Type",0x00010003,32 HKLM,"SYSTEM\ControlSet001\Services\NetDDEdsdm\Security","Security",0x00030003,\ 01,00,14,80,9c,00,00,00,a8,00,00,00,14,00,00,00,34,00,00,00,02,00,20,00,01,\ 00,00,00,02,80,18,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,00,00,20,02,\ 00,00,02,00,68,00,04,00,00,00,00,03,18,00,8d,00,02,00,01,01,00,00,00,00,00,\ 01,00,00,00,00,00,00,00,00,00,03,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,\ 20,00,00,00,20,02,00,00,00,03,18,00,8f,00,02,00,01,02,00,00,00,00,00,05,20,\ 00,00,00,23,02,00,00,00,03,18,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,\ 00,00,23,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,\ 05,12,00,00,00 HKLM,"SYSTEM\ControlSet001\Services\Netlogon",,0x00000012 HKLM,"SYSTEM\ControlSet001\Services\Netlogon\Parameters","DisablePasswordChange",0x00010003,0 HKLM,"SYSTEM\ControlSet001\Services\Netman","DependOnService",0x00010002,"RpcSs" HKLM,"SYSTEM\ControlSet001\Services\Netman","Description",0x00000000,"%NETMAN_DESCRIPTION%" HKLM,"SYSTEM\ControlSet001\Services\Netman","DisplayName",0x00000000,"%NETMAN_NAME%" HKLM,"SYSTEM\ControlSet001\Services\Netman","ErrorControl",0x00010003,1 HKLM,"SYSTEM\ControlSet001\Services\Netman","ImagePath",0x00020000,"%SystemRoot%\System32\svchost.exe -k netsvcs" HKLM,"SYSTEM\ControlSet001\Services\Netman","ObjectName",0x00000002,"LocalSystem" HKLM,"SYSTEM\ControlSet001\Services\Netman","Start",0x00010001,3 HKLM,"SYSTEM\ControlSet001\Services\Netman","Type",0x00010001,0x00000120 HKLM,"SYSTEM\ControlSet001\Services\Netman\Parameters","ServiceDll",0x00020000,"%SystemRoot%\System32\netman.dll" HKLM,"SYSTEM\ControlSet001\Services\Spooler","DependOnService",0x00010000,"RPCSS" HKLM,"SYSTEM\ControlSet001\Services\Spooler","Description",0x00000000,"%SPOOLER_DESCRIPTION%" HKLM,"SYSTEM\ControlSet001\Services\Spooler","DisplayName",0x00000000,"%SPOOLER_DISPLAYNAME%" HKLM,"SYSTEM\ControlSet001\Services\Spooler","ErrorControl",0x00010003,1 HKLM,"SYSTEM\ControlSet001\Services\Spooler","Group",0x00000002,"SpoolerGroup" HKLM,"SYSTEM\ControlSet001\Services\Spooler","ImagePath",0x00020000,"%SystemRoot%\system32\spoolsv.exe" HKLM,"SYSTEM\ControlSet001\Services\Spooler","ObjectName",0x00000002,"LocalSystem" HKLM,"SYSTEM\ControlSet001\Services\Spooler","Start",0x00010003,3 HKLM,"SYSTEM\ControlSet001\Services\Spooler","Type",0x00010003,272 HKLM,"SYSTEM\ControlSet001\Services\Spooler\Parameters",,0x00000012 HKLM,"SYSTEM\ControlSet001\Services\Spooler\Performance","Close",0x00000002,"PerfClose" HKLM,"SYSTEM\ControlSet001\Services\Spooler\Performance","Collect",0x00000002,"PerfCollect" HKLM,"SYSTEM\ControlSet001\Services\Spooler\Performance","Collect Timeout",0x00010003,2000 HKLM,"SYSTEM\ControlSet001\Services\Spooler\Performance","Library",0x00000002,"winspool.drv" HKLM,"SYSTEM\ControlSet001\Services\Spooler\Performance","Object List",0x00000002,"1450" HKLM,"SYSTEM\ControlSet001\Services\Spooler\Performance","Open",0x00000002,"PerfOpen" HKLM,"SYSTEM\ControlSet001\Services\Spooler\Performance","Open Timeout",0x00010003,4000