--- beforedivvun11.reg 2012-12-11 00:07:19.000000000 +0100 +++ afterdivvun11installed.reg 2012-12-11 00:11:10.000000000 +0100 @@ -565544,6 +565544,26 @@ 00,5f,00,31,00,30,00,33,00,33,00,3e,00,3f,00,72,00,54,00,5d,00,6a,00,49,00,\ 7b,00,6a,00,66,00,28,00,3d,00,31,00,26,00,4c,00,5b,00,2d,00,38,00,31,00,2d,\ 00,5d,00,00,00,00,00 +"5179"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,00,71,\ + 00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,66,00,33,00,\ + 66,00,70,00,5f,00,6b,00,4c,00,51,00,64,00,3f,00,6b,00,3d,00,79,00,67,00,2d,\ + 00,5d,00,67,00,5b,00,6a,00,3f,00,00,00,00,00 +"1083"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,00,71,\ + 00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,37,00,2a,00,\ + 63,00,2b,00,70,00,34,00,31,00,4b,00,5d,00,41,00,48,00,58,00,6c,00,75,00,79,\ + 00,76,00,69,00,58,00,5e,00,50,00,00,00,00,00 +"3131"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,00,71,\ + 00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,37,00,2a,00,\ + 63,00,2b,00,70,00,34,00,31,00,4b,00,5d,00,41,00,48,00,58,00,6c,00,75,00,79,\ + 00,76,00,69,00,58,00,5e,00,50,00,00,00,00,00 +"2107"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,00,71,\ + 00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,37,00,2a,00,\ + 63,00,2b,00,70,00,34,00,31,00,4b,00,5d,00,41,00,48,00,58,00,6c,00,75,00,79,\ + 00,76,00,69,00,58,00,5e,00,50,00,00,00,00,00 +"4155"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,00,71,\ + 00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,66,00,33,00,\ + 66,00,70,00,5f,00,6b,00,4c,00,51,00,64,00,3f,00,6b,00,3d,00,79,00,67,00,2d,\ + 00,5d,00,67,00,5b,00,6a,00,3f,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Components\54BE92CC2CB71D119A12000A9CE1A22A] "3082"=hex(7):76,00,55,00,70,00,41,00,56,00,5e,00,7d,00,74,00,72,00,26,00,21,\ @@ -569831,6 +569851,26 @@ 00,5f,00,31,00,30,00,33,00,33,00,3e,00,41,00,72,00,54,00,5d,00,6a,00,49,00,\ 7b,00,6a,00,66,00,28,00,3d,00,31,00,26,00,4c,00,5b,00,2d,00,38,00,31,00,2d,\ 00,5d,00,00,00,00,00 +"5179"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,00,71,\ + 00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,36,00,51,00,\ + 69,00,7a,00,29,00,70,00,76,00,4b,00,40,00,39,00,7a,00,42,00,3f,00,4b,00,4b,\ + 00,7b,00,7a,00,39,00,4e,00,3d,00,00,00,00,00 +"1083"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,00,71,\ + 00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,72,00,7d,00,\ + 41,00,39,00,52,00,30,00,52,00,27,00,31,00,3f,00,67,00,51,00,45,00,42,00,3d,\ + 00,4d,00,45,00,2d,00,69,00,41,00,00,00,00,00 +"3131"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,00,71,\ + 00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,72,00,7d,00,\ + 41,00,39,00,52,00,30,00,52,00,27,00,31,00,3f,00,67,00,51,00,45,00,42,00,3d,\ + 00,4d,00,45,00,2d,00,69,00,41,00,00,00,00,00 +"2107"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,00,71,\ + 00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,72,00,7d,00,\ + 41,00,39,00,52,00,30,00,52,00,27,00,31,00,3f,00,67,00,51,00,45,00,42,00,3d,\ + 00,4d,00,45,00,2d,00,69,00,41,00,00,00,00,00 +"4155"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,00,71,\ + 00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,36,00,51,00,\ + 69,00,7a,00,29,00,70,00,76,00,4b,00,40,00,39,00,7a,00,42,00,3f,00,4b,00,4b,\ + 00,7b,00,7a,00,39,00,4e,00,3d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Components\7BEAAA678348EF84FA21340B6D9C7269] "OGL"=hex(7):76,00,55,00,70,00,41,00,56,00,35,00,21,00,21,00,21,00,21,00,21,00,\ @@ -571115,6 +571155,26 @@ 00,6d,00,61,00,72,00,46,00,69,00,6c,00,65,00,73,00,5f,00,31,00,30,00,33,00,\ 36,00,3e,00,4b,00,2b,00,59,00,7e,00,48,00,37,00,28,00,41,00,49,00,39,00,35,\ 00,47,00,3d,00,6d,00,30,00,53,00,6c,00,34,00,6f,00,69,00,00,00,00,00 +"3131\\Normal"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,\ + 00,71,00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,46,00,\ + 6e,00,4c,00,33,00,2a,00,54,00,28,00,68,00,64,00,3d,00,2d,00,64,00,35,00,71,\ + 00,43,00,4c,00,46,00,75,00,35,00,32,00,00,00,00,00 +"2107\\Normal"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,\ + 00,71,00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,46,00,\ + 6e,00,4c,00,33,00,2a,00,54,00,28,00,68,00,64,00,3d,00,2d,00,64,00,35,00,71,\ + 00,43,00,4c,00,46,00,75,00,35,00,32,00,00,00,00,00 +"1083\\Normal"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,\ + 00,71,00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,46,00,\ + 6e,00,4c,00,33,00,2a,00,54,00,28,00,68,00,64,00,3d,00,2d,00,64,00,35,00,71,\ + 00,43,00,4c,00,46,00,75,00,35,00,32,00,00,00,00,00 +"4155\\Normal"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,\ + 00,71,00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,62,00,\ + 40,00,33,00,69,00,52,00,58,00,56,00,75,00,4c,00,41,00,62,00,48,00,5f,00,5d,\ + 00,6e,00,4f,00,44,00,28,00,32,00,6d,00,00,00,00,00 +"5179\\Normal"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,\ + 00,71,00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,62,00,\ + 40,00,33,00,69,00,52,00,58,00,56,00,75,00,4c,00,41,00,62,00,48,00,5f,00,5d,\ + 00,6e,00,4f,00,44,00,28,00,32,00,6d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Components\D3C84C3C6B7369C458A98CF4752D1D80] "1033/3082"=hex(7):76,00,55,00,70,00,41,00,56,00,5e,00,7d,00,74,00,72,00,26,00,\ @@ -571762,6 +571822,26 @@ 00,6d,00,61,00,72,00,46,00,69,00,6c,00,65,00,73,00,5f,00,31,00,30,00,33,00,\ 36,00,3e,00,78,00,37,00,65,00,78,00,61,00,59,00,77,00,2a,00,66,00,40,00,28,\ 00,70,00,51,00,2c,00,78,00,49,00,76,00,6f,00,41,00,27,00,00,00,00,00 +"3131\\Normal"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,\ + 00,71,00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,6f,00,\ + 3f,00,34,00,50,00,38,00,61,00,34,00,52,00,7e,00,3d,00,7a,00,62,00,60,00,45,\ + 00,6f,00,68,00,6a,00,6e,00,39,00,21,00,00,00,00,00 +"2107\\Normal"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,\ + 00,71,00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,6f,00,\ + 3f,00,34,00,50,00,38,00,61,00,34,00,52,00,7e,00,3d,00,7a,00,62,00,60,00,45,\ + 00,6f,00,68,00,6a,00,6e,00,39,00,21,00,00,00,00,00 +"1083\\Normal"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,\ + 00,71,00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,6f,00,\ + 3f,00,34,00,50,00,38,00,61,00,34,00,52,00,7e,00,3d,00,7a,00,62,00,60,00,45,\ + 00,6f,00,68,00,6a,00,6e,00,39,00,21,00,00,00,00,00 +"4155\\Normal"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,\ + 00,71,00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,79,00,\ + 79,00,69,00,62,00,6f,00,43,00,4b,00,7b,00,24,00,40,00,69,00,5f,00,4a,00,50,\ + 00,2a,00,43,00,61,00,46,00,6b,00,53,00,00,00,00,00 +"5179\\Normal"=hex(7):5a,00,27,00,4b,00,70,00,62,00,74,00,4c,00,46,00,67,00,3d,\ + 00,71,00,7e,00,75,00,38,00,77,00,71,00,39,00,5b,00,36,00,66,00,3e,00,79,00,\ + 79,00,69,00,62,00,6f,00,43,00,4b,00,7b,00,24,00,40,00,69,00,5f,00,4a,00,50,\ + 00,2a,00,43,00,61,00,46,00,6b,00,53,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Components\F4BE92CC2CB71D119A12000A9CE1A22A] "3082"=hex(7):76,00,55,00,70,00,41,00,56,00,5e,00,7d,00,74,00,72,00,26,00,21,\ @@ -572227,6 +572307,9 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\00004109500200000000000000F01FEC] "OfficeFileValidator"="" +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\57CB6F3B98FBBB64A855473F371F97EB] +"Sami_F"="" + [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\5C1093C35543A0E32A41B090A305076A] "NetFx_Core_x86"="" "Installer_Setup_ddf"="" @@ -573583,6 +573666,39 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109500200000000000000F01FEC\SourceList\Media] "1"=";" +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\57CB6F3B98FBBB64A855473F371F97EB] +"ProductName"="Sámi Proofing Tools" +"PackageCode"="D5396B7C01BF6E44BB9E3500DF64A2CB" +"Language"=dword:00000409 +"Version"=dword:01000003 +"Assignment"=dword:00000001 +"AdvertiseFlags"=dword:00000184 +"ProductIcon"="C:\\Windows\\Installer\\{B3F6BC75-BF89-46BB-8A55-74F373F179BE}\\ARPPRODUCTICON.exe" +"InstanceType"=dword:00000000 +"AuthorizedLUAApp"=dword:00000000 +"DeploymentFlags"=dword:00000003 +"Clients"=hex(7):3a,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\57CB6F3B98FBBB64A855473F371F97EB\SourceList] +"PackageName"="setupSami_Northern.msi" +"LastUsedSource"=hex(2):6e,00,3b,00,31,00,3b,00,43,00,3a,00,5c,00,55,00,73,00,\ + 65,00,72,00,73,00,5c,00,33,00,32,00,2d,00,37,00,2d,00,57,00,7e,00,31,00,5c,\ + 00,41,00,70,00,70,00,44,00,61,00,74,00,61,00,5c,00,4c,00,6f,00,63,00,61,00,\ + 6c,00,5c,00,54,00,65,00,6d,00,70,00,5c,00,70,00,62,00,38,00,34,00,36,00,34,\ + 00,5c,00,69,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,65,00,72,00,73,00,5c,00,\ + 00,00 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\57CB6F3B98FBBB64A855473F371F97EB\SourceList\Media] +"DiskPrompt"="[1]" +"1"="DISK1;1" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\57CB6F3B98FBBB64A855473F371F97EB\SourceList\Net] +"1"=hex(2):43,00,3a,00,5c,00,55,00,73,00,65,00,72,00,73,00,5c,00,33,00,32,00,\ + 2d,00,37,00,2d,00,57,00,7e,00,31,00,5c,00,41,00,70,00,70,00,44,00,61,00,74,\ + 00,61,00,5c,00,4c,00,6f,00,63,00,61,00,6c,00,5c,00,54,00,65,00,6d,00,70,00,\ + 5c,00,70,00,62,00,38,00,34,00,36,00,34,00,5c,00,69,00,6e,00,73,00,74,00,61,\ + 00,6c,00,6c,00,65,00,72,00,73,00,5c,00,00,00 + [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5C1093C35543A0E32A41B090A305076A] "ProductName"="Microsoft .NET Framework 4 Client Profile" "PackageCode"="4972953F9C7CD5949858DE0D1DE9DC01" @@ -573857,6 +573973,9 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\00004100500200000000000000F01FEC] "00004109500200000000000000F01FEC"="" +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\36A23EF78F3EA5E488346BD88373774E] +"57CB6F3B98FBBB64A855473F371F97EB"="" + [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\43B89FB1368B7FA459C6EFBE91832B8C] "FA0C624739E20D84084025F5A931C7FF"="" @@ -838507,7 +838626,7 @@ 1f,cd,b0,2c,3f,21,41,ba,cc,47,77,ba,b9,b0,91,d4,39,eb,bc,a1,45,f5,8c,38,7c,\ b2,99,dd,c4,90,3a,02,dd,5e,dc,7c,2e,73,5a,08,81,31,2a,95,25,1b,18,48,0a,6c,\ 90,af,e6,2c,d2,5f,18,ea,83,0e,4c,aa,22,9e,fe,da,7e,fd,b6,b0,f9,07 -"DisallowedCertLastSyncTime"=hex:06,c0,9c,96,a5,d3,cd,01 +"DisallowedCertLastSyncTime"=hex:51,3a,34,31,2b,d7,cd,01 "EncodedCtl"=hex:30,83,01,c2,8e,06,09,2a,86,48,86,f7,0d,01,07,02,a0,83,01,c2,\ 7e,30,83,01,c2,79,02,01,01,31,0b,30,09,06,05,2b,0e,03,02,1a,05,00,30,83,01,\ a4,ce,06,09,2b,06,01,04,01,82,37,0a,01,a0,83,01,a4,be,30,83,01,a4,b9,30,0c,\ @@ -856526,7 +856645,7 @@ 00,74,00,61,00,74,00,69,00,73,00,74,00,69,00,63,00,73,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,30,00,00,00,1a,00,00,00,49,00,6e,00,73,00,74,00,61,00,6e,\ 00,63,00,65,00,4e,00,61,00,6d,00,65,00,00,00,00,00,00,00,00,00,06,00,00,06,\ - 9b,32,00,00,48,00,00,00,0c,00,00,00,0e,00,00,00,15,00,00,00,00,00,00,00,64,\ + 9c,73,00,00,48,00,00,00,0c,00,00,00,0e,00,00,00,15,00,00,00,00,00,00,00,64,\ 00,00,00,00,05,41,10,48,00,00,00,1c,00,00,00,42,00,79,00,74,00,65,00,73,00,\ 52,00,65,00,63,00,65,00,69,00,76,00,65,00,64,00,00,00,00,00,00,00,00,00,00,\ 00,40,00,00,00,0c,00,00,00,10,00,00,00,15,00,00,00,00,00,00,00,64,00,00,00,\ @@ -856543,8 +856662,8 @@ 5f,00,49,00,6e,00,69,00,74,00,69,00,61,00,74,00,6f,00,72,00,49,00,6e,00,73,\ 00,74,00,61,00,6e,00,63,00,65,00,53,00,74,00,61,00,74,00,69,00,73,00,74,00,\ 69,00,63,00,73,00,00,00,00,00,00,00,30,00,00,00,1a,00,00,00,49,00,6e,00,73,\ - 00,74,00,61,00,6e,00,63,00,65,00,4e,00,61,00,6d,00,65,00,00,00,00,06,9b,32,\ - 00,00,2e,00,01,2f,85,32,00,08,70,00,00,00,16,00,00,00,18,00,00,00,13,00,00,\ + 00,74,00,61,00,6e,00,63,00,65,00,4e,00,61,00,6d,00,65,00,00,00,00,06,9c,73,\ + 00,00,2e,00,01,2f,82,73,00,08,70,00,00,00,16,00,00,00,18,00,00,00,13,00,00,\ 00,00,00,00,00,64,00,00,00,00,00,01,00,70,00,00,00,46,00,00,00,53,00,65,00,\ 73,00,73,00,69,00,6f,00,6e,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,00,69,\ 00,6f,00,6e,00,54,00,69,00,6d,00,65,00,6f,00,75,00,74,00,45,00,72,00,72,00,\ @@ -856565,7 +856684,7 @@ 6f,00,67,00,69,00,6e,00,53,00,74,00,61,00,74,00,69,00,73,00,74,00,69,00,63,\ 00,73,00,00,00,00,00,00,00,00,00,00,00,00,00,30,00,00,00,1a,00,00,00,49,00,\ 6e,00,73,00,74,00,61,00,6e,00,63,00,65,00,4e,00,61,00,6d,00,65,00,00,00,00,\ - 06,9b,32,00,00,2e,00,01,2f,85,32,00,08,48,00,00,00,20,00,00,00,22,00,00,00,\ + 06,9c,73,00,00,2e,00,01,2f,82,73,00,08,48,00,00,00,20,00,00,00,22,00,00,00,\ 13,00,00,00,00,00,00,00,64,00,00,00,00,00,01,00,48,00,00,00,20,00,00,00,4c,\ 00,6f,00,67,00,69,00,6e,00,41,00,63,00,63,00,65,00,70,00,74,00,52,00,73,00,\ 70,00,73,00,00,00,00,00,00,00,58,00,00,00,20,00,00,00,24,00,00,00,13,00,00,\ @@ -857398,7 +857517,7 @@ "RollbackFailed"=dword:00000000 "CanceledCurrentFailedTransaction"=dword:00000000 "SessionIdHigh"=dword:01cdd72b -"SessionIdLow"=dword:04e02f01 +"SessionIdLow"=dword:237db111 "DoqTime"=dword:00000013 "DoqCount"=dword:00000004 "PoqTime"=dword:0000000b @@ -904662,6 +904781,9 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\00004100500200000000000000F01FEC] "00004109500200000000000000F01FEC"="" +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\36A23EF78F3EA5E488346BD88373774E] +"57CB6F3B98FBBB64A855473F371F97EB"="" + [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\43B89FB1368B7FA459C6EFBE91832B8C] "FA0C624739E20D84084025F5A931C7FF"="" @@ -906377,6 +906499,9 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2113BE5FDFB87F834998D72BC0F6E5CA] "FCDAC0A0AD874C333A05DC1548B97920"="02:\\SOFTWARE\\Microsoft\\NET Framework Setup\\NDP\\v4\\Full\\1033\\Version" +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\21149A5106EBB324CA0B03E684AE9D54] +"57CB6F3B98FBBB64A855473F371F97EB"="C:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\mshy3samiLule-SE.dll" + [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2140372DDD2448850CF18C3B9B1A1EE8] "00002109110000000000000000F01FEC"="" @@ -906764,6 +906889,9 @@ "SharedComponent"="0" "IsFullFile"="1" +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2922D4AB6EF5D4740B298CD75C24E4C5] +"57CB6F3B98FBBB64A855473F371F97EB"="C:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\mshy3samiLule-dic.lex" + [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29322913B4A79444B8DD69E9B291FA9D] "5C1093C35543A0E32A41B090A305076A"="C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe" @@ -906938,6 +907066,9 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2DDB01A5DC3F2B43F9BD7A3E962726AC] "5C1093C35543A0E32A41B090A305076A"="C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\SetupCache\\Client\\1033\\eula.rtf" +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2DF27058FFEB22F48BA0D98DA860714D] +"57CB6F3B98FBBB64A855473F371F97EB"="C:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\mssp3samiLule.lex" + [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2DF3423286177E54B9DCD34B716252E5] "5C1093C35543A0E32A41B090A305076A"="C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\WPF\\WindowsBase.dll" @@ -908215,6 +908346,9 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EB0A34D63E668B4FA1E24B45DC3DB0A] "00002109110000000000000000F01FEC"="C:\\Program Files\\Common Files\\Microsoft Shared\\THEMES12\\QUAD\\QUAD.INF" +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EB657382DC3A08489B4A654984D1205] +"57CB6F3B98FBBB64A855473F371F97EB"="C:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\mshy3samiNorthern-NO.dll" + [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EBB202F98A9ADB4D82A2F4DCBF41FF9] "5C1093C35543A0E32A41B090A305076A"="" @@ -908538,6 +908672,9 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\55B5FB707172B1B429F7DEEE895A8C7B] "00002109110000000000000000F01FEC"="C:\\Program Files\\Common Files\\Microsoft Shared\\OFFICE12\\MUOPTIN.DLL" +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\55EF2BF3CD33B874CBC22EAD2AA7CC00] +"57CB6F3B98FBBB64A855473F371F97EB"="C:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\mssp3samiNorthern-NO.dll" + [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\55FEBDE02B33A964E990073C347747AE] "5C1093C35543A0E32A41B090A305076A"="" @@ -908800,6 +908937,9 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5CD521FB6DFE3D115AF2000A9CAC24AB] "00002109E60090400000000000F01FEC"="C:\\Program Files\\Common Files\\Microsoft Shared\\Help\\3082\\hxdsui.dll" +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5CF385611BB33A64DB4A6A6517AF63C2] +"57CB6F3B98FBBB64A855473F371F97EB"="C:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\mssp3samiNorthern.lex" + [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D02285EC1D05B150AA103451DDF5E6C] "B2E10DC5244BD9343BE94F177BE0A9A2"="C:\\Program Files\\MSBuild\\Microsoft\\WiX\\v3.x\\wix200x.targets" @@ -912621,6 +912761,9 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B42F239FFD106204FBA9EB1699061975] "00002109B10090400000000000F01FEC"="C:\\Program Files\\Microsoft Office\\Office12\\1033\\QuickStyles\\Default.dotx" +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B4499EBD185EEBA4F974247163428388] +"57CB6F3B98FBBB64A855473F371F97EB"="C:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\mssp3samiLule-SE.dll" + [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B470EAB9550F3C6D0BF18C3B9B1A1EE8] "00002109110000000000000000F01FEC"="" @@ -913204,6 +913347,9 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C410115A903B8C7318C4B0167FBD1DFC] "5C1093C35543A0E32A41B090A305076A"="02:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2742595\\NoRemove" +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C4235A1B947FF844FAA4AB8A7E83DC91] +"57CB6F3B98FBBB64A855473F371F97EB"="C:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\mshy3samiNorthern-dic.lex" + [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C423EFD3C31BABA4EA47C3982B9E7A96] "00002109110000000000000000F01FEC"="02:\\Software\\Microsoft\\Office\\12.0\\Common\\DRM\\CloudLicenseServer" @@ -915093,6 +915239,9 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDEBFFDD9304B413CAD812F52A578C3A] "676CE5AF906BBBD4C95028918B82A784"="C?\\Windows\\system32\\mfc100kor.dll" +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDF04AAADDD5DB940B50B61293AB6F94] +"57CB6F3B98FBBB64A855473F371F97EB"="C:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\mshy3samiLule.lex" + [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EE0FD56954BACD943B9F92B7F59028D3] "5C1093C35543A0E32A41B090A305076A"="C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Microsoft.JScript.dll" @@ -915683,6 +915832,9 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FBFC0F36C55A64A439A747B668E50D4D] "00002109F10090400000000000F01FEC"="C:\\Program Files\\Microsoft Office\\OFFICE12\\1033\\MSO.ACL" +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FCB2A3DD99D14BF47A819BBF6F2CA6E7] +"57CB6F3B98FBBB64A855473F371F97EB"="C:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\mshy3samiNorthern.lex" + [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FCC9B3EAD8B2DDC4AB7B1F8B38A5BEBD] "00002109B10090400000000000F01FEC"="C:\\Program Files\\Microsoft Office\\Templates\\1033\\EquityMergeFax.Dotx" @@ -917686,6 +917838,54 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109500200000000000000F01FEC\Usage] +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\57CB6F3B98FBBB64A855473F371F97EB] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\57CB6F3B98FBBB64A855473F371F97EB\Features] +"Sami_F"="6Qiz)pvK@9zB?KK{z9N=f3fp_kLQd?k=yg-]g[j?6IVsdXGuv=]Z=LP+_caEyyiboCK{$@i_JP*CaFkSb@3iRXVuLAbH_]nOD(2mr}A9R0R'1?gQEB=ME-iA7*c+p41K]AHXluyviX^PS6)+b9*'&=+]N7_*2s@+o?4P8a4R~=zb`Eohjn9!FnL3*T(hd=-d5qCLFu52" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\57CB6F3B98FBBB64A855473F371F97EB\InstallProperties] +"RegOwner"="32-7-windows" +"RegCompany"="" +"ProductID"="none" +"LocalPackage"="C:\\Windows\\Installer\\4aa21.msi" +"AuthorizedCDFPrefix"="" +"Comments"="" +"Contact"="" +"DisplayVersion"="1.0.3" +"HelpLink"="" +"HelpTelephone"="" +"InstallDate"="20121211" +"InstallLocation"="C:\\Program Files\\" +"InstallSource"="C:\\Users\\32-7-W~1\\AppData\\Local\\Temp\\pb8464\\installers\\" +"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\ + 00,65,00,20,00,2f,00,58,00,7b,00,42,00,33,00,46,00,36,00,42,00,43,00,37,00,\ + 35,00,2d,00,42,00,46,00,38,00,39,00,2d,00,34,00,36,00,42,00,42,00,2d,00,38,\ + 00,41,00,35,00,35,00,2d,00,37,00,34,00,46,00,33,00,37,00,33,00,46,00,31,00,\ + 37,00,39,00,42,00,45,00,7d,00,00,00 +"NoModify"=dword:00000001 +"Publisher"="Polderland Language & Speech Technology bv" +"Readme"="" +"Size"="" +"EstimatedSize"=dword:00002208 +"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\ + 78,00,65,00,20,00,2f,00,58,00,7b,00,42,00,33,00,46,00,36,00,42,00,43,00,37,\ + 00,35,00,2d,00,42,00,46,00,38,00,39,00,2d,00,34,00,36,00,42,00,42,00,2d,00,\ + 38,00,41,00,35,00,35,00,2d,00,37,00,34,00,46,00,33,00,37,00,33,00,46,00,31,\ + 00,37,00,39,00,42,00,45,00,7d,00,00,00 +"URLInfoAbout"="http://www.polderland.nl" +"URLUpdateInfo"="" +"VersionMajor"=dword:00000001 +"VersionMinor"=dword:00000000 +"WindowsInstaller"=dword:00000001 +"Version"=dword:01000003 +"Language"=dword:00000409 +"DisplayName"="Sámi Proofing Tools" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\57CB6F3B98FBBB64A855473F371F97EB\Patches] +"AllPatches"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\57CB6F3B98FBBB64A855473F371F97EB\Usage] + [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5C1093C35543A0E32A41B090A305076A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5C1093C35543A0E32A41B090A305076A\Features] @@ -983905,6 +984105,40 @@ "Language"=dword:00000000 "DisplayName"="Microsoft Office File Validation Add-In" +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B3F6BC75-BF89-46BB-8A55-74F373F179BE}] +"AuthorizedCDFPrefix"="" +"Comments"="" +"Contact"="" +"DisplayVersion"="1.0.3" +"HelpLink"="" +"HelpTelephone"="" +"InstallDate"="20121211" +"InstallLocation"="C:\\Program Files\\" +"InstallSource"="C:\\Users\\32-7-W~1\\AppData\\Local\\Temp\\pb8464\\installers\\" +"ModifyPath"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,78,\ + 00,65,00,20,00,2f,00,58,00,7b,00,42,00,33,00,46,00,36,00,42,00,43,00,37,00,\ + 35,00,2d,00,42,00,46,00,38,00,39,00,2d,00,34,00,36,00,42,00,42,00,2d,00,38,\ + 00,41,00,35,00,35,00,2d,00,37,00,34,00,46,00,33,00,37,00,33,00,46,00,31,00,\ + 37,00,39,00,42,00,45,00,7d,00,00,00 +"NoModify"=dword:00000001 +"Publisher"="Polderland Language & Speech Technology bv" +"Readme"="" +"Size"="" +"EstimatedSize"=dword:00002208 +"UninstallString"=hex(2):4d,00,73,00,69,00,45,00,78,00,65,00,63,00,2e,00,65,00,\ + 78,00,65,00,20,00,2f,00,58,00,7b,00,42,00,33,00,46,00,36,00,42,00,43,00,37,\ + 00,35,00,2d,00,42,00,46,00,38,00,39,00,2d,00,34,00,36,00,42,00,42,00,2d,00,\ + 38,00,41,00,35,00,35,00,2d,00,37,00,34,00,46,00,33,00,37,00,33,00,46,00,31,\ + 00,37,00,39,00,42,00,45,00,7d,00,00,00 +"URLInfoAbout"="http://www.polderland.nl" +"URLUpdateInfo"="" +"VersionMajor"=dword:00000001 +"VersionMinor"=dword:00000000 +"WindowsInstaller"=dword:00000001 +"Version"=dword:01000003 +"Language"=dword:00000409 +"DisplayName"="Sámi Proofing Tools" + [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FA5EC676-B609-4DBB-9C05-8219B8287A48}] "AuthorizedCDFPrefix"="" "Comments"="Windows Shell Integration For SubVersion Source Control, v1.7.10.23359" @@ -983974,7 +984208,7 @@ "SusClientIdValidation"=hex:06,02,28,01,00,00,56,00,42,00,30,00,30,00,32,00,64,\ 00,35,00,39,00,63,00,39,00,2d,00,61,00,64,00,33,00,31,00,63,00,62,00,62,00,\ 32,00,20,00,06,08,00,27,94,e1,4c -"LastRestorePointSetTime"="2012-12-06 09:42:35" +"LastRestorePointSetTime"="2012-12-10 23:10:22" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update] "ElevateNonAdmins"=dword:00000001 @@ -983985,7 +984219,7 @@ "ScheduledInstallDay"=dword:00000000 "ScheduledInstallTime"=dword:00000003 "IncludeRecommendedUpdates"=dword:00000001 -"NextDetectionTime"="2012-12-10 23:06:01" +"NextDetectionTime"="2012-12-11 18:48:29" "NextFeaturedUpdatesNotificationTime"="2012-11-30 00:23:38" "ScheduledInstallDate"="2012-12-11 02:00:00" "BalloonTime"="2012-12-10 15:58:45" @@ -983993,21 +984227,22 @@ "ActionCenterNotificationCount"=dword:00000004 "ActionCenterLastPossibleRestartNotification"="2012-11-30 02:00:00" "EnableFeaturedSoftware"=dword:00000001 -"UnableToDetectTime"="2012-12-10 16:01:01" "LastRestoreId"="{EE9CAB38-03E6-4CAC-8B87-FAA92975DEDE}" +"DownloadExpirationTime"="2012-12-12 23:07:35" +"OfflineDetectionPending"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Detect] -"LastError"=dword:8024402c -"LastSuccessTime"="2012-12-06 09:40:31" +"LastError"=dword:00000000 +"LastSuccessTime"="2012-12-10 23:07:35" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Download] -"LastSuccessTime"="2012-12-04 13:47:07" +"LastSuccessTime"="2012-12-10 23:07:52" "LastError"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] -"LastSuccessTime"="2012-12-06 09:42:35" +"LastSuccessTime"="2012-12-10 23:10:22" "LastError"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\UAS] @@ -999892,9 +1000127,9 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Signature Updates] "EngineVersion"="1.1.9002.0" -"ASSignatureVersion"="1.141.1048.0" -"ASSignatureApplied"=hex:80,c9,dc,26,b2,d1,cd,01 -"SignatureLocation"="C:\\ProgramData\\Microsoft\\Windows Defender\\Definition Updates\\{9FB661F0-1A60-44B6-AFAE-E81BBC1C4677}" +"ASSignatureVersion"="1.141.1308.0" +"ASSignatureApplied"=hex:80,82,6a,54,ff,d3,cd,01 +"SignatureLocation"="C:\\ProgramData\\Microsoft\\Windows Defender\\Definition Updates\\{9858C690-7422-404C-AEA9-BA16DCB5F6E0}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\SpyNet] "SpyNetReporting"=dword:00000001 @@ -1085433,7 +1085668,7 @@ 7b,e9,03,00,00 "ProfileLoadTimeLow"=dword:00000000 "ProfileLoadTimeHigh"=dword:00000000 -"RefCount"=dword:00000002 +"RefCount"=dword:00000003 "RunLogonScriptSync"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3898710555-553147626-2072628306-1003] @@ -1085587,6 +1085822,8 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{071D41B6-8806-4EB0-B661-6CB67BE6E86E}] +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{086DC180-B591-4337-8457-6E7F09DBD2E0}] + [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0987CEAB-5DED-4C19-AAA3-89E429A87D17}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0B264AD2-A9B1-4026-BBD8-E7C5476EE12A}] @@ -1085649,8 +1085886,6 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8164BDEE-6760-44A9-A6A0-DECBD46B3A1A}] -[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{86CDA5D2-88F0-4123-BFD4-46C466ABDCCD}] - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8F84B2C2-23C9-4B7C-B277-D2EDC4BD7E12}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9EFACBE6-A797-4905-A0C6-014CD3000DBB}] @@ -1085787,6 +1086022,25 @@ "Hash"=hex:82,eb,d6,01,08,50,0f,cd,35,7b,f2,8c,ce,59,52,ef,b6,ff,94,3b,38,e8,\ 25,0a,3a,f3,45,07,c6,16,2f,ae +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{086DC180-B591-4337-8457-6E7F09DBD2E0}] +"Path"="\\Microsoft\\Windows Defender\\MP Scheduled Scan" +"Hash"=hex:b9,df,af,2b,a8,46,2d,8d,c0,4d,9a,ee,f6,e2,dd,3a,00,49,72,36,1e,09,\ + 8a,76,5f,d2,51,20,68,ab,18,d3 +"Triggers"=hex:15,00,00,00,00,00,00,00,01,e7,3d,01,c8,e7,3d,01,00,d6,a6,4b,13,\ + 54,bf,01,01,e7,3d,01,c8,e7,3d,01,00,00,64,77,63,71,2f,02,52,21,c2,03,48,48,\ + 48,48,61,6a,9a,02,48,48,48,48,00,48,48,48,48,48,48,48,00,48,48,48,48,48,48,\ + 48,05,00,00,00,48,48,48,48,0c,00,00,00,48,48,48,48,01,01,00,00,00,00,00,05,\ + 12,00,00,00,48,48,48,48,00,00,00,00,48,48,48,48,38,00,00,00,48,48,48,48,3c,\ + 00,00,00,40,38,00,00,80,f4,03,00,ff,ff,ff,ff,07,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b8,c8,3d,01,00,00,00,\ + 00,00,00,00,00,dd,dd,00,00,00,00,00,00,01,e7,3d,01,c8,e7,3d,01,00,d6,a6,4b,\ + 13,54,bf,01,01,e7,3d,01,c8,e7,3d,01,00,00,64,77,63,71,2f,02,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,ff,ff,ff,ff,01,00,\ + 00,00,01,00,00,00,00,00,00,00,00,01,ab,00,01,00,00,00,00,00,00,00,27,00,00,\ + 00 +"DynamicInfo"=hex:03,00,00,00,d1,fa,97,89,2b,d7,cd,01,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 + [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0987CEAB-5DED-4C19-AAA3-89E429A87D17}] "Path"="\\Microsoft\\Windows\\Media Center\\mcupdate" "Triggers"=hex:15,00,00,00,00,00,00,00,00,e6,c5,01,3c,75,0a,72,ff,ff,ff,ff,ff,\ @@ -1086471,25 +1086725,6 @@ "Hash"=hex:0d,7c,e5,3b,5d,ed,f3,bb,73,8e,23,e6,af,cf,f4,82,9c,8a,f0,a3,b1,17,\ 9e,fb,42,dd,3d,af,ed,86,58,33 -[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{86CDA5D2-88F0-4123-BFD4-46C466ABDCCD}] -"Path"="\\Microsoft\\Windows Defender\\MP Scheduled Scan" -"Hash"=hex:61,b4,7a,53,c6,a2,91,75,33,53,63,00,90,e2,0a,6a,5f,05,0b,2d,0e,8e,\ - f0,69,66,47,a8,10,64,a4,9b,21 -"Triggers"=hex:15,00,00,00,00,00,00,00,01,07,56,01,60,07,56,01,80,53,8e,1f,19,\ - 54,bf,01,01,07,56,01,60,07,56,01,00,00,64,77,63,71,2f,02,52,21,c2,03,48,48,\ - 48,48,3b,0c,71,71,48,48,48,48,00,48,48,48,48,48,48,48,00,48,48,48,48,48,48,\ - 48,05,00,00,00,48,48,48,48,0c,00,00,00,48,48,48,48,01,01,00,00,00,00,00,05,\ - 12,00,00,00,48,48,48,48,00,00,00,00,48,48,48,48,38,00,00,00,48,48,48,48,3c,\ - 00,00,00,40,38,00,00,80,f4,03,00,ff,ff,ff,ff,07,00,00,00,00,00,00,00,00,00,\ - 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,20,00,20,00,00,00,00,\ - 00,00,00,00,00,dd,dd,00,00,00,00,00,00,01,07,56,01,60,07,56,01,80,53,8e,1f,\ - 19,54,bf,01,01,07,56,01,60,07,56,01,00,00,64,77,63,71,2f,02,00,00,00,00,00,\ - 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,ff,ff,ff,ff,01,00,\ - 00,00,01,00,00,00,00,00,00,00,00,01,9c,00,01,00,00,00,00,00,00,00,27,00,00,\ - 00 -"DynamicInfo"=hex:03,00,00,00,27,e7,5e,4d,01,d7,cd,01,00,00,00,00,00,00,00,00,\ - 00,00,00,00,00,00,00,00 - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8905ECD8-016F-4DC2-90E6-A5F1FA6A841A}] "Path"="\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)" "Triggers"=hex:15,00,00,00,00,00,00,00,00,d1,ff,72,28,f6,be,07,00,00,00,00,00,\ @@ -1087698,7 +1087933,7 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows Defender] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows Defender\MP Scheduled Scan] -"Id"="{86CDA5D2-88F0-4123-BFD4-46C466ABDCCD}" +"Id"="{086DC180-B591-4337-8457-6E7F09DBD2E0}" "Index"=dword:00000003 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SeCEdit] @@ -1088495,7 +1088730,7 @@ "OEM"="%windir%\\system32\\oem" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP] -"LastIndex"=dword:00000037 +"LastIndex"=dword:00000039 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP\Clients] "{09F7EDC5-294E-4180-AF6A-FB0E6A0E9513}"=hex(7):5c,00,5c,00,3f,00,5c,00,56,00,\ @@ -1088742,7 +1088977,7 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "RPSessionInterval"=dword:00000001 "FirstRun"=dword:00000000 -"LastIndex"=dword:00000037 +"LastIndex"=dword:00000039 "RestoreStatusResult"=dword:00000000 "GenerateErrorReport"=dword:00000000 "RestoreStatusRestore"="{D66612F4-CFDC-4412-9127-933B1F218D2F}" @@ -1088762,6 +1088997,10 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Setup_Last] "Generalize_DisableSR"=dword:00000000 +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile] +"NestingLevel"=dword:00000000 +"StartNesting"=hex(b):41,82,b7,44,2b,d7,cd,01 + [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList] @@ -1093386,7 +1093625,7 @@ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Catalogs] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Catalogs\SystemIndex] -"{43270265-3A78-11E2-8C8C-806E6F6E6963}"="318377680" +"{43270265-3A78-11E2-8C8C-806E6F6E6963}"="330122568" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Volumes] @@ -1119398,7 +1119637,7 @@ [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\Settings\LanguageConfiguration] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings] -"StringCacheGeneration"=dword:0000009f +"StringCacheGeneration"=dword:000000a1 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\UILanguages] @@ -1146974,6 +1147213,8 @@ [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot3\LogConf] +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot3\Control] + [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot4] "Capabilities"=dword:000000f0 "ConfigFlags"=dword:00000000 @@ -1149740,7 +1149981,7 @@ "Description"="@%SystemRoot%\\system32\\qmgr.dll,-1001" "ObjectName"="LocalSystem" "ErrorControl"=dword:00000001 -"Start"=dword:00000003 +"Start"=dword:00000002 "DelayedAutoStart"=dword:00000001 "Type"=dword:00000020 "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,45,00,76,00,65,00,\ @@ -1169354,13 +1169595,13 @@ "AddressType"=dword:00000000 "IsServerNapAware"=dword:00000000 "DhcpConnForceBroadcastFlag"=dword:00000000 -"DhcpInterfaceOptions"=hex:36,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,5b,\ - bc,c7,50,0a,00,02,02,33,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,5b,bc,\ - c7,50,00,01,51,80,06,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,5b,bc,c7,\ - 50,0a,00,02,03,03,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,5b,bc,c7,50,\ - 0a,00,02,02,01,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,5b,bc,c7,50,ff,\ - ff,ff,00,35,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,5b,bc,c7,50,05,00,\ - 00,00,fc,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,6b,6a,c6,50 +"DhcpInterfaceOptions"=hex:36,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,f6,\ + bc,c7,50,0a,00,02,02,33,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,f6,bc,\ + c7,50,00,01,51,80,06,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,f6,bc,c7,\ + 50,0a,00,02,03,03,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,f6,bc,c7,50,\ + 0a,00,02,02,01,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,f6,bc,c7,50,ff,\ + ff,ff,00,35,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,f6,bc,c7,50,05,00,\ + 00,00,fc,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,75,6b,c6,50 "DhcpGatewayHardware"=hex:0a,00,02,02,06,00,00,00,52,54,00,12,35,02 "DhcpGatewayHardwareCount"=dword:00000001 "DhcpNameServer"="10.0.2.3" @@ -1170853,40 +1171094,514 @@ "SppEnumGroups (Leave)"=hex:40,00,00,00,00,00,00,00,76,3d,c3,27,a8,d3,cd,01,b0,\ 0f,00,00,50,0d,00,00,d1,07,00,00,01,00,00,00,00,00,00,00,01,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 -"SppCreate (Enter)"=hex:40,00,00,00,00,00,00,00,c8,26,71,3b,fe,d6,cd,01,3c,0f,\ - 00,00,3c,0b,00,00,d0,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ +"SppCreate (Enter)"=hex:40,00,00,00,00,00,00,00,41,82,b7,44,2b,d7,cd,01,10,0c,\ + 00,00,40,0f,00,00,d0,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 -"SppGatherWriterMetadata (Enter)"=hex:40,00,00,00,00,00,00,00,f8,ad,72,3b,fe,\ - d6,cd,01,3c,0f,00,00,3c,0b,00,00,d3,07,00,00,00,00,00,00,00,00,00,00,00,00,\ +"SppGatherWriterMetadata (Enter)"=hex:40,00,00,00,00,00,00,00,81,34,a7,7a,2b,\ + d7,cd,01,10,0c,00,00,40,0f,00,00,d3,07,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00 -"SppGatherWriterMetadata (Leave)"=hex:40,00,00,00,00,00,00,00,e8,42,87,3c,fe,\ - d6,cd,01,3c,0f,00,00,3c,0b,00,00,d3,07,00,00,01,00,00,00,00,00,00,00,00,00,\ +"SppGatherWriterMetadata (Leave)"=hex:40,00,00,00,00,00,00,00,61,c6,0c,7c,2b,\ + d7,cd,01,10,0c,00,00,40,0f,00,00,d3,07,00,00,01,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00 -"SppAddInterestingComponents (Enter)"=hex:40,00,00,00,00,00,00,00,e8,42,87,3c,\ - fe,d6,cd,01,3c,0f,00,00,3c,0b,00,00,d4,07,00,00,00,00,00,00,00,00,00,00,00,\ +"SppAddInterestingComponents (Enter)"=hex:40,00,00,00,00,00,00,00,61,c6,0c,7c,\ + 2b,d7,cd,01,10,0c,00,00,40,0f,00,00,d4,07,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00 -"SppAddInterestingComponents (Leave)"=hex:40,00,00,00,00,00,00,00,28,99,99,3c,\ - fe,d6,cd,01,3c,0f,00,00,3c,0b,00,00,d4,07,00,00,01,00,00,00,00,00,00,00,00,\ +"SppAddInterestingComponents (Leave)"=hex:40,00,00,00,00,00,00,00,c1,47,28,7c,\ + 2b,d7,cd,01,10,0c,00,00,40,0f,00,00,d4,07,00,00,01,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00 -"SppCreate (Leave)"=hex:40,00,00,00,00,00,00,00,c8,61,d4,3d,fe,d6,cd,01,3c,0f,\ - 00,00,3c,0b,00,00,d0,07,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ +"SppCreate (Leave)"=hex:40,00,00,00,00,00,00,00,c1,24,c2,86,2b,d7,cd,01,10,0c,\ + 00,00,40,0f,00,00,d0,07,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore] -"SrCreateRp (Enter)"=hex:40,00,00,00,00,00,00,00,c8,26,71,3b,fe,d6,cd,01,3c,0f,\ - 00,00,3c,0b,00,00,d5,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ +"SrCreateRp (Enter)"=hex:40,00,00,00,00,00,00,00,41,82,b7,44,2b,d7,cd,01,10,0c,\ + 00,00,40,0f,00,00,d5,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 -"SrCreateRp (Leave)"=hex:40,00,00,00,00,00,00,00,c8,61,d4,3d,fe,d6,cd,01,3c,0f,\ - 00,00,3c,0b,00,00,d5,07,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ +"SrCreateRp (Leave)"=hex:40,00,00,00,00,00,00,00,c1,24,c2,86,2b,d7,cd,01,10,0c,\ + 00,00,40,0f,00,00,d5,07,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer] +"IDENTIFY (Enter)"=hex:40,00,00,00,00,00,00,00,a1,5f,b0,7a,2b,d7,cd,01,a4,0c,\ + 00,00,f0,0c,00,00,e8,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"IDENTIFY (Leave)"=hex:40,00,00,00,00,00,00,00,31,c1,16,7b,2b,d7,cd,01,a4,0c,\ + 00,00,f0,0c,00,00,e8,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\BITS Writer] + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer] +"IDENTIFY (Enter)"=hex:40,00,00,00,00,00,00,00,71,d8,ae,7a,2b,d7,cd,01,a4,0c,\ + 00,00,f0,0c,00,00,e8,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"IDENTIFY (Leave)"=hex:40,00,00,00,00,00,00,00,71,d8,ae,7a,2b,d7,cd,01,a4,0c,\ + 00,00,f0,0c,00,00,e8,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Enter)"=hex:40,00,00,00,00,00,00,00,a1,75,68,7c,2b,d7,cd,01,a4,\ + 0c,00,00,94,0a,00,00,e9,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Leave)"=hex:40,00,00,00,00,00,00,00,31,0b,6d,7c,2b,d7,cd,01,a4,\ + 0c,00,00,94,0a,00,00,e9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_STABLE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,31,0b,6d,7c,2b,\ + d7,cd,01,a4,0c,00,00,94,0a,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,\ + 00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,\ + 00 +"GETSTATE (Enter)"=hex:40,00,00,00,00,00,00,00,f1,27,73,7c,2b,d7,cd,01,a4,0c,\ + 00,00,f0,0c,00,00,f9,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"GETSTATE (Leave)"=hex:40,00,00,00,00,00,00,00,21,af,74,7c,2b,d7,cd,01,a4,0c,\ + 00,00,f0,0c,00,00,f9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,51,e4,f1,7e,2b,d7,cd,01,\ + a4,0c,00,00,e4,0a,00,00,ea,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,21,43,21,7f,2b,d7,cd,01,\ + a4,0c,00,00,e4,0a,00,00,ea,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,21,\ + 43,21,7f,2b,d7,cd,01,a4,0c,00,00,e4,0a,00,00,02,00,00,00,01,00,00,00,01,00,\ + 00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,\ + 00,00,00,00,00 +"FREEZE (Enter)"=hex:40,00,00,00,00,00,00,00,81,aa,6d,7f,2b,d7,cd,01,a4,0c,00,\ + 00,e4,0a,00,00,eb,03,00,00,01,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE (Leave)"=hex:40,00,00,00,00,00,00,00,81,aa,6d,7f,2b,d7,cd,01,a4,0c,00,\ + 00,e4,0a,00,00,eb,03,00,00,00,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_THAW (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,81,aa,\ + 6d,7f,2b,d7,cd,01,a4,0c,00,00,e4,0a,00,00,03,00,00,00,01,00,00,00,02,00,00,\ + 00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,\ + 00,00,00,00 +"BKGND_FREEZE_THREAD (Enter)"=hex:40,00,00,00,00,00,00,00,81,aa,6d,7f,2b,d7,cd,\ + 01,a4,0c,00,00,38,05,00,00,fc,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Enter)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,a4,0c,00,00,\ + 3c,0c,00,00,f2,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"BKGND_FREEZE_THREAD (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,\ + 01,a4,0c,00,00,38,05,00,00,fc,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,a4,0c,00,00,\ + 3c,0c,00,00,f2,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)"=hex:40,00,00,00,00,00,00,\ + 00,91,7f,da,88,2b,d7,cd,01,a4,0c,00,00,3c,0c,00,00,04,00,00,00,01,00,00,00,\ + 03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,\ + 00,00,00,00,00,00,00 +"POSTSNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,21,9e,af,8a,2b,d7,cd,01,a4,\ + 0c,00,00,e4,0a,00,00,f5,03,00,00,01,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"POSTSNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,21,9e,af,8a,2b,d7,cd,01,a4,\ + 0c,00,00,e4,0a,00,00,f5,03,00,00,00,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)"=hex:40,00,00,00,00,00,\ + 00,00,21,9e,af,8a,2b,d7,cd,01,a4,0c,00,00,e4,0a,00,00,05,00,00,00,01,00,00,\ + 00,04,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,\ + 00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Enter)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a4,0c,00,00,48,0f,00,00,fb,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Leave)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a4,0c,00,00,48,0f,00,00,fb,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace] +"OPEN_VOLUME_HANDLE (Enter)"=hex:40,00,00,00,00,00,00,00,f1,53,e3,7f,2b,d7,cd,\ + 01,a4,0c,00,00,f0,05,00,00,fd,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"OPEN_VOLUME_HANDLE (Leave)"=hex:40,00,00,00,00,00,00,00,51,af,ea,85,2b,d7,cd,\ + 01,a4,0c,00,00,f0,05,00,00,fd,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"IOCTL_FLUSH_AND_HOLD (Enter)"=hex:40,00,00,00,00,00,00,00,51,af,ea,85,2b,d7,\ + cd,01,a4,0c,00,00,f0,05,00,00,fe,03,00,00,01,00,00,00,00,00,00,00,00,00,00,\ + 00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"IOCTL_FLUSH_AND_HOLD (Leave)"=hex:40,00,00,00,00,00,00,00,31,c3,5b,86,2b,d7,\ + cd,01,a4,0c,00,00,f0,05,00,00,fe,03,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"IOCTL_RELEASE (Enter)"=hex:40,00,00,00,00,00,00,00,61,4a,5d,86,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,ff,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"IOCTL_RELEASE (Leave)"=hex:40,00,00,00,00,00,00,00,61,4a,5d,86,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,ff,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}_)] +"OPEN_VOLUME_HANDLE (Enter)"=hex:40,00,00,00,00,00,00,00,f1,53,e3,7f,2b,d7,cd,\ + 01,a4,0c,00,00,a8,07,00,00,fd,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"OPEN_VOLUME_HANDLE (Leave)"=hex:40,00,00,00,00,00,00,00,51,af,ea,85,2b,d7,cd,\ + 01,a4,0c,00,00,a8,07,00,00,fd,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"IOCTL_FLUSH_AND_HOLD (Enter)"=hex:40,00,00,00,00,00,00,00,51,af,ea,85,2b,d7,\ + cd,01,a4,0c,00,00,a8,07,00,00,fe,03,00,00,01,00,00,00,00,00,00,00,00,00,00,\ + 00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"IOCTL_FLUSH_AND_HOLD (Leave)"=hex:40,00,00,00,00,00,00,00,31,c3,5b,86,2b,d7,\ + cd,01,a4,0c,00,00,a8,07,00,00,fe,03,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"IOCTL_RELEASE (Enter)"=hex:40,00,00,00,00,00,00,00,61,4a,5d,86,2b,d7,cd,01,a4,\ + 0c,00,00,a8,07,00,00,ff,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"IOCTL_RELEASE (Leave)"=hex:40,00,00,00,00,00,00,00,61,4a,5d,86,2b,d7,cd,01,a4,\ + 0c,00,00,a8,07,00,00,ff,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 + [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\MSSearch Service Writer] +"IDENTIFY (Enter)"=hex:40,00,00,00,00,00,00,00,81,a7,bf,7a,2b,d7,cd,01,20,01,\ + 00,00,c8,0a,00,00,e8,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"IDENTIFY (Leave)"=hex:40,00,00,00,00,00,00,00,71,4b,c7,7a,2b,d7,cd,01,20,01,\ + 00,00,c8,0a,00,00,e8,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Enter)"=hex:40,00,00,00,00,00,00,00,21,3c,5c,7c,2b,d7,cd,01,20,\ + 01,00,00,f8,09,00,00,e9,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Leave)"=hex:40,00,00,00,00,00,00,00,41,67,65,7c,2b,d7,cd,01,20,\ + 01,00,00,f8,09,00,00,e9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_STABLE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,41,67,65,7c,2b,\ + d7,cd,01,20,01,00,00,f8,09,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,\ + 00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,\ + 00 +"GETSTATE (Enter)"=hex:40,00,00,00,00,00,00,00,e1,cb,7a,7c,2b,d7,cd,01,20,01,\ + 00,00,f8,09,00,00,f9,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"GETSTATE (Leave)"=hex:40,00,00,00,00,00,00,00,11,53,7c,7c,2b,d7,cd,01,20,01,\ + 00,00,f8,09,00,00,f9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,81,6b,f3,7e,2b,d7,cd,01,\ + 20,01,00,00,f8,09,00,00,ea,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,91,ad,1c,7f,2b,d7,cd,01,\ + 20,01,00,00,f8,09,00,00,ea,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,91,\ + ad,1c,7f,2b,d7,cd,01,20,01,00,00,f8,09,00,00,02,00,00,00,01,00,00,00,01,00,\ + 00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,\ + 00,00,00,00,00 +"FREEZE (Enter)"=hex:40,00,00,00,00,00,00,00,81,aa,6d,7f,2b,d7,cd,01,20,01,00,\ + 00,f8,09,00,00,eb,03,00,00,01,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE (Leave)"=hex:40,00,00,00,00,00,00,00,81,aa,6d,7f,2b,d7,cd,01,20,01,00,\ + 00,f8,09,00,00,eb,03,00,00,00,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_THAW (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,81,aa,\ + 6d,7f,2b,d7,cd,01,20,01,00,00,f8,09,00,00,03,00,00,00,01,00,00,00,02,00,00,\ + 00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,\ + 00,00,00,00 +"BKGND_FREEZE_THREAD (Enter)"=hex:40,00,00,00,00,00,00,00,81,aa,6d,7f,2b,d7,cd,\ + 01,20,01,00,00,cc,09,00,00,fc,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Enter)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,20,01,00,00,\ + f8,09,00,00,f2,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"BKGND_FREEZE_THREAD (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,\ + 01,20,01,00,00,cc,09,00,00,fc,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,20,01,00,00,\ + f8,09,00,00,f2,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)"=hex:40,00,00,00,00,00,00,\ + 00,91,7f,da,88,2b,d7,cd,01,20,01,00,00,f8,09,00,00,04,00,00,00,01,00,00,00,\ + 03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,\ + 00,00,00,00,00,00,00 +"POSTSNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,61,f4,c1,8a,2b,d7,cd,01,20,\ + 01,00,00,f8,09,00,00,f5,03,00,00,01,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"POSTSNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,91,f9,b7,8b,2b,d7,cd,01,20,\ + 01,00,00,f8,09,00,00,f5,03,00,00,00,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)"=hex:40,00,00,00,00,00,\ + 00,00,91,f9,b7,8b,2b,d7,cd,01,20,01,00,00,f8,09,00,00,05,00,00,00,01,00,00,\ + 00,04,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,\ + 00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Enter)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + 20,01,00,00,c8,0a,00,00,fb,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Leave)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + 20,01,00,00,c8,0a,00,00,fb,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer] +"IDENTIFY (Enter)"=hex:40,00,00,00,00,00,00,00,a1,5f,b0,7a,2b,d7,cd,01,a4,0c,\ + 00,00,fc,0d,00,00,e8,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"IDENTIFY (Leave)"=hex:40,00,00,00,00,00,00,00,d1,e6,b1,7a,2b,d7,cd,01,a4,0c,\ + 00,00,fc,0d,00,00,e8,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Enter)"=hex:40,00,00,00,00,00,00,00,a1,75,68,7c,2b,d7,cd,01,a4,\ + 0c,00,00,f0,0c,00,00,e9,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Leave)"=hex:40,00,00,00,00,00,00,00,61,92,6e,7c,2b,d7,cd,01,a4,\ + 0c,00,00,f0,0c,00,00,e9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_STABLE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,61,92,6e,7c,2b,\ + d7,cd,01,a4,0c,00,00,f0,0c,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,\ + 00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,\ + 00 +"GETSTATE (Enter)"=hex:40,00,00,00,00,00,00,00,b1,44,79,7c,2b,d7,cd,01,a4,0c,\ + 00,00,94,0a,00,00,f9,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"GETSTATE (Leave)"=hex:40,00,00,00,00,00,00,00,e1,cb,7a,7c,2b,d7,cd,01,a4,0c,\ + 00,00,94,0a,00,00,f9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,81,6b,f3,7e,2b,d7,cd,01,\ + a4,0c,00,00,3c,0c,00,00,ea,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,81,51,24,7f,2b,d7,cd,01,\ + a4,0c,00,00,3c,0c,00,00,ea,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,81,\ + 51,24,7f,2b,d7,cd,01,a4,0c,00,00,3c,0c,00,00,02,00,00,00,01,00,00,00,01,00,\ + 00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,\ + 00,00,00,00,00 +"FREEZE (Enter)"=hex:40,00,00,00,00,00,00,00,c1,e6,b0,7f,2b,d7,cd,01,a4,0c,00,\ + 00,e4,0a,00,00,eb,03,00,00,01,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE (Leave)"=hex:40,00,00,00,00,00,00,00,81,76,cf,7f,2b,d7,cd,01,a4,0c,00,\ + 00,e4,0a,00,00,eb,03,00,00,00,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_THAW (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,81,76,\ + cf,7f,2b,d7,cd,01,a4,0c,00,00,e4,0a,00,00,03,00,00,00,01,00,00,00,02,00,00,\ + 00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,\ + 00,00,00,00 +"BKGND_FREEZE_THREAD (Enter)"=hex:40,00,00,00,00,00,00,00,d1,28,da,7f,2b,d7,cd,\ + 01,a4,0c,00,00,10,07,00,00,fc,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Enter)"=hex:40,00,00,00,00,00,00,00,61,f8,d8,88,2b,d7,cd,01,a4,0c,00,00,\ + 30,06,00,00,f2,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"BKGND_FREEZE_THREAD (Leave)"=hex:40,00,00,00,00,00,00,00,61,f8,d8,88,2b,d7,cd,\ + 01,a4,0c,00,00,10,07,00,00,fc,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Leave)"=hex:40,00,00,00,00,00,00,00,61,f8,d8,88,2b,d7,cd,01,a4,0c,00,00,\ + 30,06,00,00,f2,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)"=hex:40,00,00,00,00,00,00,\ + 00,61,f8,d8,88,2b,d7,cd,01,a4,0c,00,00,30,06,00,00,04,00,00,00,01,00,00,00,\ + 03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,\ + 00,00,00,00,00,00,00 +"POSTSNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,21,9e,af,8a,2b,d7,cd,01,a4,\ + 0c,00,00,e4,0a,00,00,f5,03,00,00,01,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"POSTSNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,21,9e,af,8a,2b,d7,cd,01,a4,\ + 0c,00,00,e4,0a,00,00,f5,03,00,00,00,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)"=hex:40,00,00,00,00,00,\ + 00,00,21,9e,af,8a,2b,d7,cd,01,a4,0c,00,00,e4,0a,00,00,05,00,00,00,01,00,00,\ + 00,04,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,\ + 00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Enter)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a4,0c,00,00,e4,0a,00,00,fb,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Leave)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a4,0c,00,00,e4,0a,00,00,fb,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer] +"IDENTIFY (Enter)"=hex:40,00,00,00,00,00,00,00,d1,e6,b1,7a,2b,d7,cd,01,a4,0c,\ + 00,00,fc,0d,00,00,e8,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"IDENTIFY (Leave)"=hex:40,00,00,00,00,00,00,00,31,f5,b4,7a,2b,d7,cd,01,a4,0c,\ + 00,00,fc,0d,00,00,e8,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Enter)"=hex:40,00,00,00,00,00,00,00,21,c9,43,7c,2b,d7,cd,01,a4,\ + 0c,00,00,f0,0c,00,00,e9,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Leave)"=hex:40,00,00,00,00,00,00,00,b1,5e,48,7c,2b,d7,cd,01,a4,\ + 0c,00,00,f0,0c,00,00,e9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_STABLE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,b1,5e,48,7c,2b,\ + d7,cd,01,a4,0c,00,00,f0,0c,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,\ + 00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,\ + 00 +"GETSTATE (Enter)"=hex:40,00,00,00,00,00,00,00,11,53,7c,7c,2b,d7,cd,01,a4,0c,\ + 00,00,f0,0c,00,00,f9,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"GETSTATE (Leave)"=hex:40,00,00,00,00,00,00,00,41,da,7d,7c,2b,d7,cd,01,a4,0c,\ + 00,00,f0,0c,00,00,f9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,51,e4,f1,7e,2b,d7,cd,01,\ + a4,0c,00,00,48,0f,00,00,ea,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,21,43,21,7f,2b,d7,cd,01,\ + a4,0c,00,00,48,0f,00,00,ea,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,21,\ + 43,21,7f,2b,d7,cd,01,a4,0c,00,00,48,0f,00,00,02,00,00,00,01,00,00,00,01,00,\ + 00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,\ + 00,00,00,00,00 +"FREEZE (Enter)"=hex:40,00,00,00,00,00,00,00,d1,e9,5f,7f,2b,d7,cd,01,a4,0c,00,\ + 00,58,0f,00,00,eb,03,00,00,01,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE (Leave)"=hex:40,00,00,00,00,00,00,00,d1,e9,5f,7f,2b,d7,cd,01,a4,0c,00,\ + 00,58,0f,00,00,eb,03,00,00,00,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_THAW (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,d1,e9,\ + 5f,7f,2b,d7,cd,01,a4,0c,00,00,58,0f,00,00,03,00,00,00,01,00,00,00,02,00,00,\ + 00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,\ + 00,00,00,00 +"BKGND_FREEZE_THREAD (Enter)"=hex:40,00,00,00,00,00,00,00,d1,e9,5f,7f,2b,d7,cd,\ + 01,a4,0c,00,00,70,09,00,00,fc,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Enter)"=hex:40,00,00,00,00,00,00,00,61,f8,d8,88,2b,d7,cd,01,a4,0c,00,00,\ + e4,0a,00,00,f2,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"BKGND_FREEZE_THREAD (Leave)"=hex:40,00,00,00,00,00,00,00,61,f8,d8,88,2b,d7,cd,\ + 01,a4,0c,00,00,70,09,00,00,fc,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Leave)"=hex:40,00,00,00,00,00,00,00,61,f8,d8,88,2b,d7,cd,01,a4,0c,00,00,\ + e4,0a,00,00,f2,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)"=hex:40,00,00,00,00,00,00,\ + 00,61,f8,d8,88,2b,d7,cd,01,a4,0c,00,00,e4,0a,00,00,04,00,00,00,01,00,00,00,\ + 03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,\ + 00,00,00,00,00,00,00 +"POSTSNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,21,9e,af,8a,2b,d7,cd,01,a4,\ + 0c,00,00,e4,0a,00,00,f5,03,00,00,01,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"POSTSNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,d1,70,eb,75,2b,d7,cd,01,a4,\ + 0c,00,00,48,0f,00,00,f5,03,00,00,00,00,00,00,04,00,00,00,00,00,00,00,34,8b,\ + ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)"=hex:40,00,00,00,00,00,\ + 00,00,d1,70,eb,75,2b,d7,cd,01,a4,0c,00,00,48,0f,00,00,05,00,00,00,01,00,00,\ + 00,04,00,00,00,00,00,00,00,34,8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,\ + 00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Enter)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a4,0c,00,00,48,0f,00,00,fb,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Leave)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a4,0c,00,00,48,0f,00,00,fb,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}] +"PROVIDER_BEGINPREPARE (Enter)"=hex:40,00,00,00,00,00,00,00,61,ac,3d,7c,2b,d7,\ + cd,01,a4,0c,00,00,f0,0c,00,00,01,04,00,00,01,00,00,00,00,00,00,00,00,00,00,\ + 00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_BEGINPREPARE (Leave)"=hex:40,00,00,00,00,00,00,00,91,33,3f,7c,2b,d7,\ + cd,01,a4,0c,00,00,f0,0c,00,00,01,04,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_ENDPREPARE (Enter)"=hex:40,00,00,00,00,00,00,00,61,05,87,7c,2b,d7,cd,\ + 01,a4,0c,00,00,f0,05,00,00,02,04,00,00,01,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_ENDPREPARE (Leave)"=hex:40,00,00,00,00,00,00,00,61,40,ea,7e,2b,d7,cd,\ + 01,a4,0c,00,00,f0,05,00,00,02,04,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_PRECOMMIT (Enter)"=hex:40,00,00,00,00,00,00,00,a1,a1,d8,7f,2b,d7,cd,\ + 01,a4,0c,00,00,f0,05,00,00,03,04,00,00,01,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_PRECOMMIT (Leave)"=hex:40,00,00,00,00,00,00,00,f1,53,e3,7f,2b,d7,cd,\ + 01,a4,0c,00,00,f0,05,00,00,03,04,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_COMMIT (Enter)"=hex:40,00,00,00,00,00,00,00,31,c3,5b,86,2b,d7,cd,01,\ + a4,0c,00,00,2c,07,00,00,04,04,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_COMMIT (Leave)"=hex:40,00,00,00,00,00,00,00,61,4a,5d,86,2b,d7,cd,01,\ + a4,0c,00,00,2c,07,00,00,04,04,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_POSTCOMMIT (Enter)"=hex:40,00,00,00,00,00,00,00,61,4a,5d,86,2b,d7,cd,\ + 01,a4,0c,00,00,f0,05,00,00,05,04,00,00,01,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_POSTCOMMIT (Leave)"=hex:40,00,00,00,00,00,00,00,31,8f,bd,86,2b,d7,cd,\ + 01,a4,0c,00,00,f0,05,00,00,05,04,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_PREFINALCOMMIT (Enter)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,\ + d7,cd,01,a4,0c,00,00,f0,05,00,00,06,04,00,00,01,00,00,00,00,00,00,00,00,00,\ + 00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,\ + 00 +"PROVIDER_PREFINALCOMMIT (Leave)"=hex:40,00,00,00,00,00,00,00,31,fa,a7,8a,2b,\ + d7,cd,01,a4,0c,00,00,f0,05,00,00,06,04,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,\ + 00 +"PROVIDER_POSTFINALCOMMIT (Enter)"=hex:40,00,00,00,00,00,00,00,d1,70,eb,75,2b,\ + d7,cd,01,a4,0c,00,00,14,0f,00,00,07,04,00,00,01,00,00,00,00,00,00,00,00,00,\ + 00,00,34,8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,\ + 00 +"PROVIDER_POSTFINALCOMMIT (Leave)"=hex:40,00,00,00,00,00,00,00,f1,06,df,79,2b,\ + d7,cd,01,a4,0c,00,00,14,0f,00,00,07,04,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,34,8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,\ + 00 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\System Writer] +"IDENTIFY (Enter)"=hex:40,00,00,00,00,00,00,00,61,7c,b6,7a,2b,d7,cd,01,a8,04,\ + 00,00,34,07,00,00,e8,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"IDENTIFY (Leave)"=hex:40,00,00,00,00,00,00,00,81,00,09,7b,2b,d7,cd,01,a8,04,\ + 00,00,34,07,00,00,e8,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Enter)"=hex:40,00,00,00,00,00,00,00,a1,02,50,7c,2b,d7,cd,01,a8,\ + 04,00,00,34,07,00,00,e9,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Leave)"=hex:40,00,00,00,00,00,00,00,a1,75,68,7c,2b,d7,cd,01,a8,\ + 04,00,00,34,07,00,00,e9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_STABLE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,a1,75,68,7c,2b,\ + d7,cd,01,a8,04,00,00,34,07,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,\ + 00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,\ + 00 +"GETSTATE (Enter)"=hex:40,00,00,00,00,00,00,00,51,36,76,7c,2b,d7,cd,01,a8,04,\ + 00,00,34,07,00,00,f9,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"GETSTATE (Leave)"=hex:40,00,00,00,00,00,00,00,81,bd,77,7c,2b,d7,cd,01,a8,04,\ + 00,00,34,07,00,00,f9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,f1,bb,1f,7f,2b,d7,cd,01,\ + a8,04,00,00,34,07,00,00,ea,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,11,cd,59,7f,2b,d7,cd,01,\ + a8,04,00,00,34,07,00,00,ea,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,11,\ + cd,59,7f,2b,d7,cd,01,a8,04,00,00,34,07,00,00,02,00,00,00,01,00,00,00,01,00,\ + 00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,\ + 00,00,00,00,00 +"FREEZE (Enter)"=hex:40,00,00,00,00,00,00,00,81,aa,6d,7f,2b,d7,cd,01,a8,04,00,\ + 00,34,07,00,00,eb,03,00,00,01,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE (Leave)"=hex:40,00,00,00,00,00,00,00,d1,5c,78,7f,2b,d7,cd,01,a8,04,00,\ + 00,34,07,00,00,eb,03,00,00,00,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_THAW (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,d1,5c,\ + 78,7f,2b,d7,cd,01,a8,04,00,00,34,07,00,00,03,00,00,00,01,00,00,00,02,00,00,\ + 00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,\ + 00,00,00,00 +"BKGND_FREEZE_THREAD (Enter)"=hex:40,00,00,00,00,00,00,00,91,79,7e,7f,2b,d7,cd,\ + 01,a8,04,00,00,a0,07,00,00,fc,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Enter)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,a8,04,00,00,\ + 34,07,00,00,f2,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"BKGND_FREEZE_THREAD (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,\ + 01,a8,04,00,00,a0,07,00,00,fc,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,a8,04,00,00,\ + 34,07,00,00,f2,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)"=hex:40,00,00,00,00,00,00,\ + 00,91,7f,da,88,2b,d7,cd,01,a8,04,00,00,34,07,00,00,04,00,00,00,01,00,00,00,\ + 03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,\ + 00,00,00,00,00,00,00 +"POSTSNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,51,25,b1,8a,2b,d7,cd,01,a8,\ + 04,00,00,34,07,00,00,f5,03,00,00,01,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"POSTSNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,61,f4,c1,8a,2b,d7,cd,01,a8,\ + 04,00,00,34,07,00,00,f5,03,00,00,00,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)"=hex:40,00,00,00,00,00,\ + 00,00,61,f4,c1,8a,2b,d7,cd,01,a8,04,00,00,34,07,00,00,05,00,00,00,01,00,00,\ + 00,04,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,\ + 00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Enter)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a8,04,00,00,34,07,00,00,fb,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Leave)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a8,04,00,00,34,07,00,00,fb,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VolSnap] "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}DiscoverSnapshots (Enter)"=hex:40,\ @@ -1170906,15 +1171621,15 @@ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}ComputeIgnorableProduct (Enter)"=hex:40,\ - 00,00,00,00,00,00,00,70,78,ee,77,2a,d7,cd,01,00,00,00,00,00,00,00,00,0c,00,\ + 00,00,00,00,00,00,00,c1,15,cf,87,2b,d7,cd,01,00,00,00,00,00,00,00,00,0c,00,\ 00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}ComputeIgnorableProduct (Leave)"=hex:40,\ - 00,00,00,00,00,00,00,00,0e,f3,77,2a,d7,cd,01,00,00,00,00,00,00,00,00,0d,00,\ + 00,00,00,00,00,00,00,a1,43,0f,88,2b,d7,cd,01,00,00,00,00,00,00,00,00,0d,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}DeleteProcess (Enter)"=hex:40,00,\ - 00,00,00,00,00,00,00,0e,f3,77,2a,d7,cd,01,00,00,00,00,00,00,00,00,12,00,00,\ + 00,00,00,00,00,00,31,8f,bd,86,2b,d7,cd,01,00,00,00,00,00,00,00,00,12,00,00,\ 00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}Activate (Leave)"=hex:40,00,00,00,\ @@ -1170926,15 +1171641,15 @@ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}SetIgnorable (Enter)"=hex:40,00,\ - 00,00,00,00,00,00,00,0e,f3,77,2a,d7,cd,01,00,00,00,00,00,00,00,00,0a,00,00,\ + 00,00,00,00,00,00,31,8f,bd,86,2b,d7,cd,01,00,00,00,00,00,00,00,00,0a,00,00,\ 00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}SetIgnorable (Leave)"=hex:40,00,\ - 00,00,00,00,00,00,60,b4,b9,78,2a,d7,cd,01,00,00,00,00,00,00,00,00,0b,00,00,\ + 00,00,00,00,00,00,a1,52,02,87,2b,d7,cd,01,00,00,00,00,00,00,00,00,0b,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}AdjustBitmap (Enter)"=hex:40,00,\ - 00,00,00,00,00,00,60,b4,b9,78,2a,d7,cd,01,00,00,00,00,00,00,00,00,04,00,00,\ + 00,00,00,00,00,00,a1,52,02,87,2b,d7,cd,01,00,00,00,00,00,00,00,00,04,00,00,\ 00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}ValidateDiffAreaFiles (Enter)"=hex:40,\ @@ -1170952,15 +1171667,207 @@ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}DeleteProcess (Leave)"=hex:40,00,\ - 00,00,00,00,00,00,f0,3a,cb,79,2a,d7,cd,01,00,00,00,00,00,00,00,00,13,00,00,\ + 00,00,00,00,00,00,91,74,fe,87,2b,d7,cd,01,00,00,00,00,00,00,00,00,13,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}AdjustBitmap (Leave)"=hex:40,00,\ - 00,00,00,00,00,00,f0,3a,cb,79,2a,d7,cd,01,00,00,00,00,00,00,00,00,05,00,00,\ + 00,00,00,00,00,00,a1,43,0f,88,2b,d7,cd,01,00,00,00,00,00,00,00,00,05,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00 +"Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}PrepareForSnapshot (Enter)"=hex:40,\ + 00,00,00,00,00,00,00,11,c6,94,7c,2b,d7,cd,01,9c,02,00,00,b8,00,00,00,00,00,\ + 00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00 +"Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}PreExposure (Enter)"=hex:40,00,00,\ + 00,00,00,00,00,61,40,ea,7e,2b,d7,cd,01,9c,02,00,00,b8,00,00,00,02,00,00,00,\ + 01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00 +"Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}PreExposure (Leave)"=hex:40,00,00,\ + 00,00,00,00,00,61,40,ea,7e,2b,d7,cd,01,9c,02,00,00,b8,00,00,00,03,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00 +"Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}PrepareForSnapshot (Leave)"=hex:40,\ + 00,00,00,00,00,00,00,61,40,ea,7e,2b,d7,cd,01,9c,02,00,00,b8,00,00,00,01,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00 +"Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}EndCommit (Enter)"=hex:40,00,00,\ + 00,00,00,00,00,31,8f,bd,86,2b,d7,cd,01,04,00,00,00,2c,00,00,00,06,00,00,00,\ + 01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00 +"Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}EndCommit (Leave)"=hex:40,00,00,\ + 00,00,00,00,00,31,8f,bd,86,2b,d7,cd,01,04,00,00,00,2c,00,00,00,07,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher] +"IDENTIFY (Enter)"=hex:40,00,00,00,00,00,00,00,e1,42,aa,7a,2b,d7,cd,01,10,0c,\ + 00,00,e8,0f,00,00,e8,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"IDENTIFY (Leave)"=hex:40,00,00,00,00,00,00,00,31,c1,16,7b,2b,d7,cd,01,10,0c,\ + 00,00,e8,0f,00,00,e8,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Enter)"=hex:40,00,00,00,00,00,00,00,c1,ba,40,7c,2b,d7,cd,01,10,\ + 0c,00,00,80,0a,00,00,e9,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Leave)"=hex:40,00,00,00,00,00,00,00,61,92,6e,7c,2b,d7,cd,01,10,\ + 0c,00,00,80,0a,00,00,e9,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"GETSTATE (Enter)"=hex:40,00,00,00,00,00,00,00,91,19,70,7c,2b,d7,cd,01,10,0c,\ + 00,00,fc,0c,00,00,f9,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"GETSTATE (Leave)"=hex:40,00,00,00,00,00,00,00,41,da,7d,7c,2b,d7,cd,01,10,0c,\ + 00,00,fc,0c,00,00,f9,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"DOSNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,31,7e,85,7c,2b,d7,cd,01,10,0c,\ + 00,00,40,0f,00,00,0a,04,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"DOSNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,c1,24,c2,86,2b,d7,cd,01,10,0c,\ + 00,00,14,06,00,00,0a,04,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher] +"PREPARESNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,91,c7,eb,7e,2b,d7,cd,01,\ + a4,0c,00,00,f0,05,00,00,ea,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,11,cd,59,7f,2b,d7,cd,01,\ + a4,0c,00,00,f0,05,00,00,ea,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE (Enter)"=hex:40,00,00,00,00,00,00,00,11,cd,59,7f,2b,d7,cd,01,a4,0c,00,\ + 00,f0,05,00,00,eb,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_FRONT (Enter)"=hex:40,00,00,00,00,00,00,00,11,cd,59,7f,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,ec,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_FRONT (Leave)"=hex:40,00,00,00,00,00,00,00,d1,e9,5f,7f,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,ec,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_BACK (Enter)"=hex:40,00,00,00,00,00,00,00,d1,e9,5f,7f,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,ed,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_BACK (Leave)"=hex:40,00,00,00,00,00,00,00,c1,8d,67,7f,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,ed,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_SYSTEM (Enter)"=hex:40,00,00,00,00,00,00,00,c1,8d,67,7f,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,ee,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_SYSTEM (Leave)"=hex:40,00,00,00,00,00,00,00,91,79,7e,7f,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,ee,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_KTM (Enter)"=hex:40,00,00,00,00,00,00,00,91,79,7e,7f,2b,d7,cd,01,a4,0c,\ + 00,00,f0,05,00,00,f0,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_KTM (Leave)"=hex:40,00,00,00,00,00,00,00,91,79,7e,7f,2b,d7,cd,01,a4,0c,\ + 00,00,f0,05,00,00,f0,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_RM (Enter)"=hex:40,00,00,00,00,00,00,00,91,79,7e,7f,2b,d7,cd,01,a4,0c,\ + 00,00,f0,05,00,00,ef,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_RM (Leave)"=hex:40,00,00,00,00,00,00,00,a1,a1,d8,7f,2b,d7,cd,01,a4,0c,\ + 00,00,f0,05,00,00,ef,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE (Leave)"=hex:40,00,00,00,00,00,00,00,a1,a1,d8,7f,2b,d7,cd,01,a4,0c,00,\ + 00,f0,05,00,00,eb,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW_KTM (Enter)"=hex:40,00,00,00,00,00,00,00,c1,24,c2,86,2b,d7,cd,01,a4,0c,\ + 00,00,f0,05,00,00,f4,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW_KTM (Leave)"=hex:40,00,00,00,00,00,00,00,71,54,d1,88,2b,d7,cd,01,a4,0c,\ + 00,00,f0,05,00,00,f4,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Enter)"=hex:40,00,00,00,00,00,00,00,71,54,d1,88,2b,d7,cd,01,a4,0c,00,00,\ + f0,05,00,00,f2,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,a4,0c,00,00,\ + f0,05,00,00,f2,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"POSTSNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,31,fa,a7,8a,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,f5,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"POSTSNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,d1,70,eb,75,2b,d7,cd,01,a4,\ + 0c,00,00,14,0f,00,00,f5,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,34,8b,\ + ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Enter)"=hex:40,00,00,00,00,00,00,00,81,db,5d,7a,2b,d7,cd,01,\ + a4,0c,00,00,14,0f,00,00,fb,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Leave)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a4,0c,00,00,14,0f,00,00,fb,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\WMI Writer] +"IDENTIFY (Enter)"=hex:40,00,00,00,00,00,00,00,71,d8,ae,7a,2b,d7,cd,01,6c,03,\ + 00,00,30,0a,00,00,e8,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"IDENTIFY (Leave)"=hex:40,00,00,00,00,00,00,00,61,7c,b6,7a,2b,d7,cd,01,6c,03,\ + 00,00,30,0a,00,00,e8,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Enter)"=hex:40,00,00,00,00,00,00,00,e1,e5,49,7c,2b,d7,cd,01,6c,\ + 03,00,00,30,0a,00,00,e9,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Leave)"=hex:40,00,00,00,00,00,00,00,a1,02,50,7c,2b,d7,cd,01,6c,\ + 03,00,00,30,0a,00,00,e9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_STABLE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,a1,02,50,7c,2b,\ + d7,cd,01,6c,03,00,00,30,0a,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,\ + 00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,\ + 00 +"GETSTATE (Enter)"=hex:40,00,00,00,00,00,00,00,21,af,74,7c,2b,d7,cd,01,6c,03,\ + 00,00,30,0a,00,00,f9,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"GETSTATE (Leave)"=hex:40,00,00,00,00,00,00,00,51,36,76,7c,2b,d7,cd,01,6c,03,\ + 00,00,30,0a,00,00,f9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,e1,79,f6,7e,2b,d7,cd,01,\ + 6c,03,00,00,30,0a,00,00,ea,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,f1,bb,1f,7f,2b,d7,cd,01,\ + 6c,03,00,00,30,0a,00,00,ea,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,f1,\ + bb,1f,7f,2b,d7,cd,01,6c,03,00,00,30,0a,00,00,02,00,00,00,01,00,00,00,01,00,\ + 00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,\ + 00,00,00,00,00 +"FREEZE (Enter)"=hex:40,00,00,00,00,00,00,00,d1,e9,5f,7f,2b,d7,cd,01,6c,03,00,\ + 00,30,0a,00,00,eb,03,00,00,01,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE (Leave)"=hex:40,00,00,00,00,00,00,00,d1,e9,5f,7f,2b,d7,cd,01,6c,03,00,\ + 00,30,0a,00,00,eb,03,00,00,00,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_THAW (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,d1,e9,\ + 5f,7f,2b,d7,cd,01,6c,03,00,00,30,0a,00,00,03,00,00,00,01,00,00,00,02,00,00,\ + 00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,\ + 00,00,00,00 +"BKGND_FREEZE_THREAD (Enter)"=hex:40,00,00,00,00,00,00,00,d1,e9,5f,7f,2b,d7,cd,\ + 01,6c,03,00,00,ac,0b,00,00,fc,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Enter)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,6c,03,00,00,\ + 30,0a,00,00,f2,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"BKGND_FREEZE_THREAD (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,\ + 01,6c,03,00,00,ac,0b,00,00,fc,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,6c,03,00,00,\ + 30,0a,00,00,f2,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)"=hex:40,00,00,00,00,00,00,\ + 00,91,7f,da,88,2b,d7,cd,01,6c,03,00,00,30,0a,00,00,04,00,00,00,01,00,00,00,\ + 03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,\ + 00,00,00,00,00,00,00 +"POSTSNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,31,6d,c0,8a,2b,d7,cd,01,6c,\ + 03,00,00,78,03,00,00,f5,03,00,00,01,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"POSTSNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,31,6d,c0,8a,2b,d7,cd,01,6c,\ + 03,00,00,78,03,00,00,f5,03,00,00,00,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)"=hex:40,00,00,00,00,00,\ + 00,00,31,6d,c0,8a,2b,d7,cd,01,6c,03,00,00,78,03,00,00,05,00,00,00,01,00,00,\ + 00,04,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,\ + 00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Enter)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + 6c,03,00,00,30,0a,00,00,fb,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Leave)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + 6c,03,00,00,30,0a,00,00,fb,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Providers] @@ -1250623,10 +1251530,10 @@ [HKEY_LOCAL_MACHINE\SYSTEM\RNG] "ExternalEntropyCount"=dword:00000002 -"Seed"=hex:53,65,65,64,46,69,6c,65,01,00,00,00,c1,e6,e3,90,84,b3,9a,90,54,27,\ - ea,e8,e4,f1,a8,0b,9b,c2,10,b2,a6,e2,c5,5b,d1,0d,10,0d,58,79,b3,53,57,8a,e4,\ - 52,70,c5,4b,db,82,6d,35,e6,14,fe,45,59,7b,cc,20,d9,70,57,1c,45,d5,d2,3a,48,\ - 4b,13,c3,df +"Seed"=hex:53,65,65,64,46,69,6c,65,d2,6c,04,00,c5,90,52,05,69,40,4e,68,fc,3b,\ + 72,3d,61,dd,63,87,95,ea,a2,a8,ff,45,78,09,9b,f1,15,aa,7f,3b,ec,e9,9a,57,32,\ + e9,52,a6,7c,cc,47,d4,e1,e3,fb,40,a2,dc,c7,5e,09,98,a5,c1,3f,45,aa,52,1f,79,\ + 7a,7d,0f,07 [HKEY_LOCAL_MACHINE\SYSTEM\Select] "Current"=dword:00000001 @@ -1275833,7 +1276740,7 @@ [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings] -"StringCacheGeneration"=dword:0000009f +"StringCacheGeneration"=dword:000000a1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\UILanguages] @@ -1303409,6 +1304316,8 @@ [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot3\LogConf] +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot3\Control] + [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot4] "Capabilities"=dword:000000f0 "ConfigFlags"=dword:00000000 @@ -1306175,7 +1307084,7 @@ "Description"="@%SystemRoot%\\system32\\qmgr.dll,-1001" "ObjectName"="LocalSystem" "ErrorControl"=dword:00000001 -"Start"=dword:00000003 +"Start"=dword:00000002 "DelayedAutoStart"=dword:00000001 "Type"=dword:00000020 "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,45,00,76,00,65,00,\ @@ -1325789,13 +1326698,13 @@ "AddressType"=dword:00000000 "IsServerNapAware"=dword:00000000 "DhcpConnForceBroadcastFlag"=dword:00000000 -"DhcpInterfaceOptions"=hex:36,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,5b,\ - bc,c7,50,0a,00,02,02,33,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,5b,bc,\ - c7,50,00,01,51,80,06,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,5b,bc,c7,\ - 50,0a,00,02,03,03,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,5b,bc,c7,50,\ - 0a,00,02,02,01,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,5b,bc,c7,50,ff,\ - ff,ff,00,35,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,5b,bc,c7,50,05,00,\ - 00,00,fc,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,6b,6a,c6,50 +"DhcpInterfaceOptions"=hex:36,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,f6,\ + bc,c7,50,0a,00,02,02,33,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,f6,bc,\ + c7,50,00,01,51,80,06,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,f6,bc,c7,\ + 50,0a,00,02,03,03,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,f6,bc,c7,50,\ + 0a,00,02,02,01,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,f6,bc,c7,50,ff,\ + ff,ff,00,35,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,f6,bc,c7,50,05,00,\ + 00,00,fc,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,75,6b,c6,50 "DhcpGatewayHardware"=hex:0a,00,02,02,06,00,00,00,52,54,00,12,35,02 "DhcpGatewayHardwareCount"=dword:00000001 "DhcpNameServer"="10.0.2.3" @@ -1327288,40 +1328197,514 @@ "SppEnumGroups (Leave)"=hex:40,00,00,00,00,00,00,00,76,3d,c3,27,a8,d3,cd,01,b0,\ 0f,00,00,50,0d,00,00,d1,07,00,00,01,00,00,00,00,00,00,00,01,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 -"SppCreate (Enter)"=hex:40,00,00,00,00,00,00,00,c8,26,71,3b,fe,d6,cd,01,3c,0f,\ - 00,00,3c,0b,00,00,d0,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ +"SppCreate (Enter)"=hex:40,00,00,00,00,00,00,00,41,82,b7,44,2b,d7,cd,01,10,0c,\ + 00,00,40,0f,00,00,d0,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 -"SppGatherWriterMetadata (Enter)"=hex:40,00,00,00,00,00,00,00,f8,ad,72,3b,fe,\ - d6,cd,01,3c,0f,00,00,3c,0b,00,00,d3,07,00,00,00,00,00,00,00,00,00,00,00,00,\ +"SppGatherWriterMetadata (Enter)"=hex:40,00,00,00,00,00,00,00,81,34,a7,7a,2b,\ + d7,cd,01,10,0c,00,00,40,0f,00,00,d3,07,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00 -"SppGatherWriterMetadata (Leave)"=hex:40,00,00,00,00,00,00,00,e8,42,87,3c,fe,\ - d6,cd,01,3c,0f,00,00,3c,0b,00,00,d3,07,00,00,01,00,00,00,00,00,00,00,00,00,\ +"SppGatherWriterMetadata (Leave)"=hex:40,00,00,00,00,00,00,00,61,c6,0c,7c,2b,\ + d7,cd,01,10,0c,00,00,40,0f,00,00,d3,07,00,00,01,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00 -"SppAddInterestingComponents (Enter)"=hex:40,00,00,00,00,00,00,00,e8,42,87,3c,\ - fe,d6,cd,01,3c,0f,00,00,3c,0b,00,00,d4,07,00,00,00,00,00,00,00,00,00,00,00,\ +"SppAddInterestingComponents (Enter)"=hex:40,00,00,00,00,00,00,00,61,c6,0c,7c,\ + 2b,d7,cd,01,10,0c,00,00,40,0f,00,00,d4,07,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00 -"SppAddInterestingComponents (Leave)"=hex:40,00,00,00,00,00,00,00,28,99,99,3c,\ - fe,d6,cd,01,3c,0f,00,00,3c,0b,00,00,d4,07,00,00,01,00,00,00,00,00,00,00,00,\ +"SppAddInterestingComponents (Leave)"=hex:40,00,00,00,00,00,00,00,c1,47,28,7c,\ + 2b,d7,cd,01,10,0c,00,00,40,0f,00,00,d4,07,00,00,01,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00 -"SppCreate (Leave)"=hex:40,00,00,00,00,00,00,00,c8,61,d4,3d,fe,d6,cd,01,3c,0f,\ - 00,00,3c,0b,00,00,d0,07,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ +"SppCreate (Leave)"=hex:40,00,00,00,00,00,00,00,c1,24,c2,86,2b,d7,cd,01,10,0c,\ + 00,00,40,0f,00,00,d0,07,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Diag\SystemRestore] -"SrCreateRp (Enter)"=hex:40,00,00,00,00,00,00,00,c8,26,71,3b,fe,d6,cd,01,3c,0f,\ - 00,00,3c,0b,00,00,d5,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ +"SrCreateRp (Enter)"=hex:40,00,00,00,00,00,00,00,41,82,b7,44,2b,d7,cd,01,10,0c,\ + 00,00,40,0f,00,00,d5,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 -"SrCreateRp (Leave)"=hex:40,00,00,00,00,00,00,00,c8,61,d4,3d,fe,d6,cd,01,3c,0f,\ - 00,00,3c,0b,00,00,d5,07,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ +"SrCreateRp (Leave)"=hex:40,00,00,00,00,00,00,00,c1,24,c2,86,2b,d7,cd,01,10,0c,\ + 00,00,40,0f,00,00,d5,07,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Diag\ASR Writer] +"IDENTIFY (Enter)"=hex:40,00,00,00,00,00,00,00,a1,5f,b0,7a,2b,d7,cd,01,a4,0c,\ + 00,00,f0,0c,00,00,e8,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"IDENTIFY (Leave)"=hex:40,00,00,00,00,00,00,00,31,c1,16,7b,2b,d7,cd,01,a4,0c,\ + 00,00,f0,0c,00,00,e8,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Diag\BITS Writer] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Diag\COM+ REGDB Writer] +"IDENTIFY (Enter)"=hex:40,00,00,00,00,00,00,00,71,d8,ae,7a,2b,d7,cd,01,a4,0c,\ + 00,00,f0,0c,00,00,e8,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"IDENTIFY (Leave)"=hex:40,00,00,00,00,00,00,00,71,d8,ae,7a,2b,d7,cd,01,a4,0c,\ + 00,00,f0,0c,00,00,e8,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Enter)"=hex:40,00,00,00,00,00,00,00,a1,75,68,7c,2b,d7,cd,01,a4,\ + 0c,00,00,94,0a,00,00,e9,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Leave)"=hex:40,00,00,00,00,00,00,00,31,0b,6d,7c,2b,d7,cd,01,a4,\ + 0c,00,00,94,0a,00,00,e9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_STABLE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,31,0b,6d,7c,2b,\ + d7,cd,01,a4,0c,00,00,94,0a,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,\ + 00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,\ + 00 +"GETSTATE (Enter)"=hex:40,00,00,00,00,00,00,00,f1,27,73,7c,2b,d7,cd,01,a4,0c,\ + 00,00,f0,0c,00,00,f9,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"GETSTATE (Leave)"=hex:40,00,00,00,00,00,00,00,21,af,74,7c,2b,d7,cd,01,a4,0c,\ + 00,00,f0,0c,00,00,f9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,51,e4,f1,7e,2b,d7,cd,01,\ + a4,0c,00,00,e4,0a,00,00,ea,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,21,43,21,7f,2b,d7,cd,01,\ + a4,0c,00,00,e4,0a,00,00,ea,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,21,\ + 43,21,7f,2b,d7,cd,01,a4,0c,00,00,e4,0a,00,00,02,00,00,00,01,00,00,00,01,00,\ + 00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,\ + 00,00,00,00,00 +"FREEZE (Enter)"=hex:40,00,00,00,00,00,00,00,81,aa,6d,7f,2b,d7,cd,01,a4,0c,00,\ + 00,e4,0a,00,00,eb,03,00,00,01,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE (Leave)"=hex:40,00,00,00,00,00,00,00,81,aa,6d,7f,2b,d7,cd,01,a4,0c,00,\ + 00,e4,0a,00,00,eb,03,00,00,00,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_THAW (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,81,aa,\ + 6d,7f,2b,d7,cd,01,a4,0c,00,00,e4,0a,00,00,03,00,00,00,01,00,00,00,02,00,00,\ + 00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,\ + 00,00,00,00 +"BKGND_FREEZE_THREAD (Enter)"=hex:40,00,00,00,00,00,00,00,81,aa,6d,7f,2b,d7,cd,\ + 01,a4,0c,00,00,38,05,00,00,fc,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Enter)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,a4,0c,00,00,\ + 3c,0c,00,00,f2,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"BKGND_FREEZE_THREAD (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,\ + 01,a4,0c,00,00,38,05,00,00,fc,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,a4,0c,00,00,\ + 3c,0c,00,00,f2,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)"=hex:40,00,00,00,00,00,00,\ + 00,91,7f,da,88,2b,d7,cd,01,a4,0c,00,00,3c,0c,00,00,04,00,00,00,01,00,00,00,\ + 03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,\ + 00,00,00,00,00,00,00 +"POSTSNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,21,9e,af,8a,2b,d7,cd,01,a4,\ + 0c,00,00,e4,0a,00,00,f5,03,00,00,01,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"POSTSNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,21,9e,af,8a,2b,d7,cd,01,a4,\ + 0c,00,00,e4,0a,00,00,f5,03,00,00,00,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)"=hex:40,00,00,00,00,00,\ + 00,00,21,9e,af,8a,2b,d7,cd,01,a4,0c,00,00,e4,0a,00,00,05,00,00,00,01,00,00,\ + 00,04,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,\ + 00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Enter)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a4,0c,00,00,48,0f,00,00,fb,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Leave)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a4,0c,00,00,48,0f,00,00,fb,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Diag\Lovelace] +"OPEN_VOLUME_HANDLE (Enter)"=hex:40,00,00,00,00,00,00,00,f1,53,e3,7f,2b,d7,cd,\ + 01,a4,0c,00,00,f0,05,00,00,fd,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"OPEN_VOLUME_HANDLE (Leave)"=hex:40,00,00,00,00,00,00,00,51,af,ea,85,2b,d7,cd,\ + 01,a4,0c,00,00,f0,05,00,00,fd,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"IOCTL_FLUSH_AND_HOLD (Enter)"=hex:40,00,00,00,00,00,00,00,51,af,ea,85,2b,d7,\ + cd,01,a4,0c,00,00,f0,05,00,00,fe,03,00,00,01,00,00,00,00,00,00,00,00,00,00,\ + 00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"IOCTL_FLUSH_AND_HOLD (Leave)"=hex:40,00,00,00,00,00,00,00,31,c3,5b,86,2b,d7,\ + cd,01,a4,0c,00,00,f0,05,00,00,fe,03,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"IOCTL_RELEASE (Enter)"=hex:40,00,00,00,00,00,00,00,61,4a,5d,86,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,ff,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"IOCTL_RELEASE (Leave)"=hex:40,00,00,00,00,00,00,00,61,4a,5d,86,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,ff,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Diag\Lovelace(__?_Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}_)] +"OPEN_VOLUME_HANDLE (Enter)"=hex:40,00,00,00,00,00,00,00,f1,53,e3,7f,2b,d7,cd,\ + 01,a4,0c,00,00,a8,07,00,00,fd,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"OPEN_VOLUME_HANDLE (Leave)"=hex:40,00,00,00,00,00,00,00,51,af,ea,85,2b,d7,cd,\ + 01,a4,0c,00,00,a8,07,00,00,fd,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"IOCTL_FLUSH_AND_HOLD (Enter)"=hex:40,00,00,00,00,00,00,00,51,af,ea,85,2b,d7,\ + cd,01,a4,0c,00,00,a8,07,00,00,fe,03,00,00,01,00,00,00,00,00,00,00,00,00,00,\ + 00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"IOCTL_FLUSH_AND_HOLD (Leave)"=hex:40,00,00,00,00,00,00,00,31,c3,5b,86,2b,d7,\ + cd,01,a4,0c,00,00,a8,07,00,00,fe,03,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"IOCTL_RELEASE (Enter)"=hex:40,00,00,00,00,00,00,00,61,4a,5d,86,2b,d7,cd,01,a4,\ + 0c,00,00,a8,07,00,00,ff,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"IOCTL_RELEASE (Leave)"=hex:40,00,00,00,00,00,00,00,61,4a,5d,86,2b,d7,cd,01,a4,\ + 0c,00,00,a8,07,00,00,ff,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Diag\MSSearch Service Writer] +"IDENTIFY (Enter)"=hex:40,00,00,00,00,00,00,00,81,a7,bf,7a,2b,d7,cd,01,20,01,\ + 00,00,c8,0a,00,00,e8,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"IDENTIFY (Leave)"=hex:40,00,00,00,00,00,00,00,71,4b,c7,7a,2b,d7,cd,01,20,01,\ + 00,00,c8,0a,00,00,e8,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Enter)"=hex:40,00,00,00,00,00,00,00,21,3c,5c,7c,2b,d7,cd,01,20,\ + 01,00,00,f8,09,00,00,e9,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Leave)"=hex:40,00,00,00,00,00,00,00,41,67,65,7c,2b,d7,cd,01,20,\ + 01,00,00,f8,09,00,00,e9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_STABLE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,41,67,65,7c,2b,\ + d7,cd,01,20,01,00,00,f8,09,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,\ + 00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,\ + 00 +"GETSTATE (Enter)"=hex:40,00,00,00,00,00,00,00,e1,cb,7a,7c,2b,d7,cd,01,20,01,\ + 00,00,f8,09,00,00,f9,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"GETSTATE (Leave)"=hex:40,00,00,00,00,00,00,00,11,53,7c,7c,2b,d7,cd,01,20,01,\ + 00,00,f8,09,00,00,f9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,81,6b,f3,7e,2b,d7,cd,01,\ + 20,01,00,00,f8,09,00,00,ea,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,91,ad,1c,7f,2b,d7,cd,01,\ + 20,01,00,00,f8,09,00,00,ea,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,91,\ + ad,1c,7f,2b,d7,cd,01,20,01,00,00,f8,09,00,00,02,00,00,00,01,00,00,00,01,00,\ + 00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,\ + 00,00,00,00,00 +"FREEZE (Enter)"=hex:40,00,00,00,00,00,00,00,81,aa,6d,7f,2b,d7,cd,01,20,01,00,\ + 00,f8,09,00,00,eb,03,00,00,01,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE (Leave)"=hex:40,00,00,00,00,00,00,00,81,aa,6d,7f,2b,d7,cd,01,20,01,00,\ + 00,f8,09,00,00,eb,03,00,00,00,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_THAW (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,81,aa,\ + 6d,7f,2b,d7,cd,01,20,01,00,00,f8,09,00,00,03,00,00,00,01,00,00,00,02,00,00,\ + 00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,\ + 00,00,00,00 +"BKGND_FREEZE_THREAD (Enter)"=hex:40,00,00,00,00,00,00,00,81,aa,6d,7f,2b,d7,cd,\ + 01,20,01,00,00,cc,09,00,00,fc,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Enter)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,20,01,00,00,\ + f8,09,00,00,f2,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"BKGND_FREEZE_THREAD (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,\ + 01,20,01,00,00,cc,09,00,00,fc,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,20,01,00,00,\ + f8,09,00,00,f2,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)"=hex:40,00,00,00,00,00,00,\ + 00,91,7f,da,88,2b,d7,cd,01,20,01,00,00,f8,09,00,00,04,00,00,00,01,00,00,00,\ + 03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,\ + 00,00,00,00,00,00,00 +"POSTSNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,61,f4,c1,8a,2b,d7,cd,01,20,\ + 01,00,00,f8,09,00,00,f5,03,00,00,01,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"POSTSNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,91,f9,b7,8b,2b,d7,cd,01,20,\ + 01,00,00,f8,09,00,00,f5,03,00,00,00,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)"=hex:40,00,00,00,00,00,\ + 00,00,91,f9,b7,8b,2b,d7,cd,01,20,01,00,00,f8,09,00,00,05,00,00,00,01,00,00,\ + 00,04,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,\ + 00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Enter)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + 20,01,00,00,c8,0a,00,00,fb,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Leave)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + 20,01,00,00,c8,0a,00,00,fb,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Diag\Registry Writer] +"IDENTIFY (Enter)"=hex:40,00,00,00,00,00,00,00,a1,5f,b0,7a,2b,d7,cd,01,a4,0c,\ + 00,00,fc,0d,00,00,e8,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"IDENTIFY (Leave)"=hex:40,00,00,00,00,00,00,00,d1,e6,b1,7a,2b,d7,cd,01,a4,0c,\ + 00,00,fc,0d,00,00,e8,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Enter)"=hex:40,00,00,00,00,00,00,00,a1,75,68,7c,2b,d7,cd,01,a4,\ + 0c,00,00,f0,0c,00,00,e9,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Leave)"=hex:40,00,00,00,00,00,00,00,61,92,6e,7c,2b,d7,cd,01,a4,\ + 0c,00,00,f0,0c,00,00,e9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_STABLE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,61,92,6e,7c,2b,\ + d7,cd,01,a4,0c,00,00,f0,0c,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,\ + 00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,\ + 00 +"GETSTATE (Enter)"=hex:40,00,00,00,00,00,00,00,b1,44,79,7c,2b,d7,cd,01,a4,0c,\ + 00,00,94,0a,00,00,f9,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"GETSTATE (Leave)"=hex:40,00,00,00,00,00,00,00,e1,cb,7a,7c,2b,d7,cd,01,a4,0c,\ + 00,00,94,0a,00,00,f9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,81,6b,f3,7e,2b,d7,cd,01,\ + a4,0c,00,00,3c,0c,00,00,ea,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,81,51,24,7f,2b,d7,cd,01,\ + a4,0c,00,00,3c,0c,00,00,ea,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,81,\ + 51,24,7f,2b,d7,cd,01,a4,0c,00,00,3c,0c,00,00,02,00,00,00,01,00,00,00,01,00,\ + 00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,\ + 00,00,00,00,00 +"FREEZE (Enter)"=hex:40,00,00,00,00,00,00,00,c1,e6,b0,7f,2b,d7,cd,01,a4,0c,00,\ + 00,e4,0a,00,00,eb,03,00,00,01,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE (Leave)"=hex:40,00,00,00,00,00,00,00,81,76,cf,7f,2b,d7,cd,01,a4,0c,00,\ + 00,e4,0a,00,00,eb,03,00,00,00,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_THAW (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,81,76,\ + cf,7f,2b,d7,cd,01,a4,0c,00,00,e4,0a,00,00,03,00,00,00,01,00,00,00,02,00,00,\ + 00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,\ + 00,00,00,00 +"BKGND_FREEZE_THREAD (Enter)"=hex:40,00,00,00,00,00,00,00,d1,28,da,7f,2b,d7,cd,\ + 01,a4,0c,00,00,10,07,00,00,fc,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Enter)"=hex:40,00,00,00,00,00,00,00,61,f8,d8,88,2b,d7,cd,01,a4,0c,00,00,\ + 30,06,00,00,f2,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"BKGND_FREEZE_THREAD (Leave)"=hex:40,00,00,00,00,00,00,00,61,f8,d8,88,2b,d7,cd,\ + 01,a4,0c,00,00,10,07,00,00,fc,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Leave)"=hex:40,00,00,00,00,00,00,00,61,f8,d8,88,2b,d7,cd,01,a4,0c,00,00,\ + 30,06,00,00,f2,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)"=hex:40,00,00,00,00,00,00,\ + 00,61,f8,d8,88,2b,d7,cd,01,a4,0c,00,00,30,06,00,00,04,00,00,00,01,00,00,00,\ + 03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,\ + 00,00,00,00,00,00,00 +"POSTSNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,21,9e,af,8a,2b,d7,cd,01,a4,\ + 0c,00,00,e4,0a,00,00,f5,03,00,00,01,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"POSTSNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,21,9e,af,8a,2b,d7,cd,01,a4,\ + 0c,00,00,e4,0a,00,00,f5,03,00,00,00,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)"=hex:40,00,00,00,00,00,\ + 00,00,21,9e,af,8a,2b,d7,cd,01,a4,0c,00,00,e4,0a,00,00,05,00,00,00,01,00,00,\ + 00,04,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,\ + 00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Enter)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a4,0c,00,00,e4,0a,00,00,fb,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Leave)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a4,0c,00,00,e4,0a,00,00,fb,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Diag\Shadow Copy Optimization Writer] +"IDENTIFY (Enter)"=hex:40,00,00,00,00,00,00,00,d1,e6,b1,7a,2b,d7,cd,01,a4,0c,\ + 00,00,fc,0d,00,00,e8,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"IDENTIFY (Leave)"=hex:40,00,00,00,00,00,00,00,31,f5,b4,7a,2b,d7,cd,01,a4,0c,\ + 00,00,fc,0d,00,00,e8,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Enter)"=hex:40,00,00,00,00,00,00,00,21,c9,43,7c,2b,d7,cd,01,a4,\ + 0c,00,00,f0,0c,00,00,e9,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Leave)"=hex:40,00,00,00,00,00,00,00,b1,5e,48,7c,2b,d7,cd,01,a4,\ + 0c,00,00,f0,0c,00,00,e9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_STABLE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,b1,5e,48,7c,2b,\ + d7,cd,01,a4,0c,00,00,f0,0c,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,\ + 00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,\ + 00 +"GETSTATE (Enter)"=hex:40,00,00,00,00,00,00,00,11,53,7c,7c,2b,d7,cd,01,a4,0c,\ + 00,00,f0,0c,00,00,f9,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"GETSTATE (Leave)"=hex:40,00,00,00,00,00,00,00,41,da,7d,7c,2b,d7,cd,01,a4,0c,\ + 00,00,f0,0c,00,00,f9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,51,e4,f1,7e,2b,d7,cd,01,\ + a4,0c,00,00,48,0f,00,00,ea,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,21,43,21,7f,2b,d7,cd,01,\ + a4,0c,00,00,48,0f,00,00,ea,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,21,\ + 43,21,7f,2b,d7,cd,01,a4,0c,00,00,48,0f,00,00,02,00,00,00,01,00,00,00,01,00,\ + 00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,\ + 00,00,00,00,00 +"FREEZE (Enter)"=hex:40,00,00,00,00,00,00,00,d1,e9,5f,7f,2b,d7,cd,01,a4,0c,00,\ + 00,58,0f,00,00,eb,03,00,00,01,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE (Leave)"=hex:40,00,00,00,00,00,00,00,d1,e9,5f,7f,2b,d7,cd,01,a4,0c,00,\ + 00,58,0f,00,00,eb,03,00,00,00,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_THAW (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,d1,e9,\ + 5f,7f,2b,d7,cd,01,a4,0c,00,00,58,0f,00,00,03,00,00,00,01,00,00,00,02,00,00,\ + 00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,\ + 00,00,00,00 +"BKGND_FREEZE_THREAD (Enter)"=hex:40,00,00,00,00,00,00,00,d1,e9,5f,7f,2b,d7,cd,\ + 01,a4,0c,00,00,70,09,00,00,fc,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Enter)"=hex:40,00,00,00,00,00,00,00,61,f8,d8,88,2b,d7,cd,01,a4,0c,00,00,\ + e4,0a,00,00,f2,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"BKGND_FREEZE_THREAD (Leave)"=hex:40,00,00,00,00,00,00,00,61,f8,d8,88,2b,d7,cd,\ + 01,a4,0c,00,00,70,09,00,00,fc,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Leave)"=hex:40,00,00,00,00,00,00,00,61,f8,d8,88,2b,d7,cd,01,a4,0c,00,00,\ + e4,0a,00,00,f2,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)"=hex:40,00,00,00,00,00,00,\ + 00,61,f8,d8,88,2b,d7,cd,01,a4,0c,00,00,e4,0a,00,00,04,00,00,00,01,00,00,00,\ + 03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,\ + 00,00,00,00,00,00,00 +"POSTSNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,21,9e,af,8a,2b,d7,cd,01,a4,\ + 0c,00,00,e4,0a,00,00,f5,03,00,00,01,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"POSTSNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,d1,70,eb,75,2b,d7,cd,01,a4,\ + 0c,00,00,48,0f,00,00,f5,03,00,00,00,00,00,00,04,00,00,00,00,00,00,00,34,8b,\ + ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)"=hex:40,00,00,00,00,00,\ + 00,00,d1,70,eb,75,2b,d7,cd,01,a4,0c,00,00,48,0f,00,00,05,00,00,00,01,00,00,\ + 00,04,00,00,00,00,00,00,00,34,8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,\ + 00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Enter)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a4,0c,00,00,48,0f,00,00,fb,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Leave)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a4,0c,00,00,48,0f,00,00,fb,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}] +"PROVIDER_BEGINPREPARE (Enter)"=hex:40,00,00,00,00,00,00,00,61,ac,3d,7c,2b,d7,\ + cd,01,a4,0c,00,00,f0,0c,00,00,01,04,00,00,01,00,00,00,00,00,00,00,00,00,00,\ + 00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_BEGINPREPARE (Leave)"=hex:40,00,00,00,00,00,00,00,91,33,3f,7c,2b,d7,\ + cd,01,a4,0c,00,00,f0,0c,00,00,01,04,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_ENDPREPARE (Enter)"=hex:40,00,00,00,00,00,00,00,61,05,87,7c,2b,d7,cd,\ + 01,a4,0c,00,00,f0,05,00,00,02,04,00,00,01,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_ENDPREPARE (Leave)"=hex:40,00,00,00,00,00,00,00,61,40,ea,7e,2b,d7,cd,\ + 01,a4,0c,00,00,f0,05,00,00,02,04,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_PRECOMMIT (Enter)"=hex:40,00,00,00,00,00,00,00,a1,a1,d8,7f,2b,d7,cd,\ + 01,a4,0c,00,00,f0,05,00,00,03,04,00,00,01,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_PRECOMMIT (Leave)"=hex:40,00,00,00,00,00,00,00,f1,53,e3,7f,2b,d7,cd,\ + 01,a4,0c,00,00,f0,05,00,00,03,04,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_COMMIT (Enter)"=hex:40,00,00,00,00,00,00,00,31,c3,5b,86,2b,d7,cd,01,\ + a4,0c,00,00,2c,07,00,00,04,04,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_COMMIT (Leave)"=hex:40,00,00,00,00,00,00,00,61,4a,5d,86,2b,d7,cd,01,\ + a4,0c,00,00,2c,07,00,00,04,04,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_POSTCOMMIT (Enter)"=hex:40,00,00,00,00,00,00,00,61,4a,5d,86,2b,d7,cd,\ + 01,a4,0c,00,00,f0,05,00,00,05,04,00,00,01,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_POSTCOMMIT (Leave)"=hex:40,00,00,00,00,00,00,00,31,8f,bd,86,2b,d7,cd,\ + 01,a4,0c,00,00,f0,05,00,00,05,04,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PROVIDER_PREFINALCOMMIT (Enter)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,\ + d7,cd,01,a4,0c,00,00,f0,05,00,00,06,04,00,00,01,00,00,00,00,00,00,00,00,00,\ + 00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,\ + 00 +"PROVIDER_PREFINALCOMMIT (Leave)"=hex:40,00,00,00,00,00,00,00,31,fa,a7,8a,2b,\ + d7,cd,01,a4,0c,00,00,f0,05,00,00,06,04,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,\ + 00 +"PROVIDER_POSTFINALCOMMIT (Enter)"=hex:40,00,00,00,00,00,00,00,d1,70,eb,75,2b,\ + d7,cd,01,a4,0c,00,00,14,0f,00,00,07,04,00,00,01,00,00,00,00,00,00,00,00,00,\ + 00,00,34,8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,\ + 00 +"PROVIDER_POSTFINALCOMMIT (Leave)"=hex:40,00,00,00,00,00,00,00,f1,06,df,79,2b,\ + d7,cd,01,a4,0c,00,00,14,0f,00,00,07,04,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,34,8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,\ + 00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Diag\System Writer] +"IDENTIFY (Enter)"=hex:40,00,00,00,00,00,00,00,61,7c,b6,7a,2b,d7,cd,01,a8,04,\ + 00,00,34,07,00,00,e8,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"IDENTIFY (Leave)"=hex:40,00,00,00,00,00,00,00,81,00,09,7b,2b,d7,cd,01,a8,04,\ + 00,00,34,07,00,00,e8,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Enter)"=hex:40,00,00,00,00,00,00,00,a1,02,50,7c,2b,d7,cd,01,a8,\ + 04,00,00,34,07,00,00,e9,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Leave)"=hex:40,00,00,00,00,00,00,00,a1,75,68,7c,2b,d7,cd,01,a8,\ + 04,00,00,34,07,00,00,e9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_STABLE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,a1,75,68,7c,2b,\ + d7,cd,01,a8,04,00,00,34,07,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,\ + 00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,\ + 00 +"GETSTATE (Enter)"=hex:40,00,00,00,00,00,00,00,51,36,76,7c,2b,d7,cd,01,a8,04,\ + 00,00,34,07,00,00,f9,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"GETSTATE (Leave)"=hex:40,00,00,00,00,00,00,00,81,bd,77,7c,2b,d7,cd,01,a8,04,\ + 00,00,34,07,00,00,f9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,f1,bb,1f,7f,2b,d7,cd,01,\ + a8,04,00,00,34,07,00,00,ea,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,11,cd,59,7f,2b,d7,cd,01,\ + a8,04,00,00,34,07,00,00,ea,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,11,\ + cd,59,7f,2b,d7,cd,01,a8,04,00,00,34,07,00,00,02,00,00,00,01,00,00,00,01,00,\ + 00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,\ + 00,00,00,00,00 +"FREEZE (Enter)"=hex:40,00,00,00,00,00,00,00,81,aa,6d,7f,2b,d7,cd,01,a8,04,00,\ + 00,34,07,00,00,eb,03,00,00,01,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE (Leave)"=hex:40,00,00,00,00,00,00,00,d1,5c,78,7f,2b,d7,cd,01,a8,04,00,\ + 00,34,07,00,00,eb,03,00,00,00,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_THAW (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,d1,5c,\ + 78,7f,2b,d7,cd,01,a8,04,00,00,34,07,00,00,03,00,00,00,01,00,00,00,02,00,00,\ + 00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,\ + 00,00,00,00 +"BKGND_FREEZE_THREAD (Enter)"=hex:40,00,00,00,00,00,00,00,91,79,7e,7f,2b,d7,cd,\ + 01,a8,04,00,00,a0,07,00,00,fc,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Enter)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,a8,04,00,00,\ + 34,07,00,00,f2,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"BKGND_FREEZE_THREAD (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,\ + 01,a8,04,00,00,a0,07,00,00,fc,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,a8,04,00,00,\ + 34,07,00,00,f2,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)"=hex:40,00,00,00,00,00,00,\ + 00,91,7f,da,88,2b,d7,cd,01,a8,04,00,00,34,07,00,00,04,00,00,00,01,00,00,00,\ + 03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,\ + 00,00,00,00,00,00,00 +"POSTSNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,51,25,b1,8a,2b,d7,cd,01,a8,\ + 04,00,00,34,07,00,00,f5,03,00,00,01,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"POSTSNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,61,f4,c1,8a,2b,d7,cd,01,a8,\ + 04,00,00,34,07,00,00,f5,03,00,00,00,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)"=hex:40,00,00,00,00,00,\ + 00,00,61,f4,c1,8a,2b,d7,cd,01,a8,04,00,00,34,07,00,00,05,00,00,00,01,00,00,\ + 00,04,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,\ + 00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Enter)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a8,04,00,00,34,07,00,00,fb,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Leave)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a8,04,00,00,34,07,00,00,fb,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Diag\VolSnap] "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}DiscoverSnapshots (Enter)"=hex:40,\ @@ -1327341,15 +1328724,15 @@ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}ComputeIgnorableProduct (Enter)"=hex:40,\ - 00,00,00,00,00,00,00,70,78,ee,77,2a,d7,cd,01,00,00,00,00,00,00,00,00,0c,00,\ + 00,00,00,00,00,00,00,c1,15,cf,87,2b,d7,cd,01,00,00,00,00,00,00,00,00,0c,00,\ 00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}ComputeIgnorableProduct (Leave)"=hex:40,\ - 00,00,00,00,00,00,00,00,0e,f3,77,2a,d7,cd,01,00,00,00,00,00,00,00,00,0d,00,\ + 00,00,00,00,00,00,00,a1,43,0f,88,2b,d7,cd,01,00,00,00,00,00,00,00,00,0d,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}DeleteProcess (Enter)"=hex:40,00,\ - 00,00,00,00,00,00,00,0e,f3,77,2a,d7,cd,01,00,00,00,00,00,00,00,00,12,00,00,\ + 00,00,00,00,00,00,31,8f,bd,86,2b,d7,cd,01,00,00,00,00,00,00,00,00,12,00,00,\ 00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}Activate (Leave)"=hex:40,00,00,00,\ @@ -1327361,15 +1328744,15 @@ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}SetIgnorable (Enter)"=hex:40,00,\ - 00,00,00,00,00,00,00,0e,f3,77,2a,d7,cd,01,00,00,00,00,00,00,00,00,0a,00,00,\ + 00,00,00,00,00,00,31,8f,bd,86,2b,d7,cd,01,00,00,00,00,00,00,00,00,0a,00,00,\ 00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}SetIgnorable (Leave)"=hex:40,00,\ - 00,00,00,00,00,00,60,b4,b9,78,2a,d7,cd,01,00,00,00,00,00,00,00,00,0b,00,00,\ + 00,00,00,00,00,00,a1,52,02,87,2b,d7,cd,01,00,00,00,00,00,00,00,00,0b,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}AdjustBitmap (Enter)"=hex:40,00,\ - 00,00,00,00,00,00,60,b4,b9,78,2a,d7,cd,01,00,00,00,00,00,00,00,00,04,00,00,\ + 00,00,00,00,00,00,a1,52,02,87,2b,d7,cd,01,00,00,00,00,00,00,00,00,04,00,00,\ 00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}ValidateDiffAreaFiles (Enter)"=hex:40,\ @@ -1327387,15 +1328770,207 @@ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}DeleteProcess (Leave)"=hex:40,00,\ - 00,00,00,00,00,00,f0,3a,cb,79,2a,d7,cd,01,00,00,00,00,00,00,00,00,13,00,00,\ + 00,00,00,00,00,00,91,74,fe,87,2b,d7,cd,01,00,00,00,00,00,00,00,00,13,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00 "Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}AdjustBitmap (Leave)"=hex:40,00,\ - 00,00,00,00,00,00,f0,3a,cb,79,2a,d7,cd,01,00,00,00,00,00,00,00,00,05,00,00,\ + 00,00,00,00,00,00,a1,43,0f,88,2b,d7,cd,01,00,00,00,00,00,00,00,00,05,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00 +"Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}PrepareForSnapshot (Enter)"=hex:40,\ + 00,00,00,00,00,00,00,11,c6,94,7c,2b,d7,cd,01,9c,02,00,00,b8,00,00,00,00,00,\ + 00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00 +"Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}PreExposure (Enter)"=hex:40,00,00,\ + 00,00,00,00,00,61,40,ea,7e,2b,d7,cd,01,9c,02,00,00,b8,00,00,00,02,00,00,00,\ + 01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00 +"Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}PreExposure (Leave)"=hex:40,00,00,\ + 00,00,00,00,00,61,40,ea,7e,2b,d7,cd,01,9c,02,00,00,b8,00,00,00,03,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00 +"Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}PrepareForSnapshot (Leave)"=hex:40,\ + 00,00,00,00,00,00,00,61,40,ea,7e,2b,d7,cd,01,9c,02,00,00,b8,00,00,00,01,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00 +"Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}EndCommit (Enter)"=hex:40,00,00,\ + 00,00,00,00,00,31,8f,bd,86,2b,d7,cd,01,04,00,00,00,2c,00,00,00,06,00,00,00,\ + 01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00 +"Volume{43270265-3a78-11e2-8c8c-806e6f6e6963}EndCommit (Leave)"=hex:40,00,00,\ + 00,00,00,00,00,31,8f,bd,86,2b,d7,cd,01,04,00,00,00,2c,00,00,00,07,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Diag\VssapiPublisher] +"IDENTIFY (Enter)"=hex:40,00,00,00,00,00,00,00,e1,42,aa,7a,2b,d7,cd,01,10,0c,\ + 00,00,e8,0f,00,00,e8,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"IDENTIFY (Leave)"=hex:40,00,00,00,00,00,00,00,31,c1,16,7b,2b,d7,cd,01,10,0c,\ + 00,00,e8,0f,00,00,e8,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Enter)"=hex:40,00,00,00,00,00,00,00,c1,ba,40,7c,2b,d7,cd,01,10,\ + 0c,00,00,80,0a,00,00,e9,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Leave)"=hex:40,00,00,00,00,00,00,00,61,92,6e,7c,2b,d7,cd,01,10,\ + 0c,00,00,80,0a,00,00,e9,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"GETSTATE (Enter)"=hex:40,00,00,00,00,00,00,00,91,19,70,7c,2b,d7,cd,01,10,0c,\ + 00,00,fc,0c,00,00,f9,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"GETSTATE (Leave)"=hex:40,00,00,00,00,00,00,00,41,da,7d,7c,2b,d7,cd,01,10,0c,\ + 00,00,fc,0c,00,00,f9,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"DOSNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,31,7e,85,7c,2b,d7,cd,01,10,0c,\ + 00,00,40,0f,00,00,0a,04,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"DOSNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,c1,24,c2,86,2b,d7,cd,01,10,0c,\ + 00,00,14,06,00,00,0a,04,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Diag\VssvcPublisher] +"PREPARESNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,91,c7,eb,7e,2b,d7,cd,01,\ + a4,0c,00,00,f0,05,00,00,ea,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,11,cd,59,7f,2b,d7,cd,01,\ + a4,0c,00,00,f0,05,00,00,ea,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE (Enter)"=hex:40,00,00,00,00,00,00,00,11,cd,59,7f,2b,d7,cd,01,a4,0c,00,\ + 00,f0,05,00,00,eb,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_FRONT (Enter)"=hex:40,00,00,00,00,00,00,00,11,cd,59,7f,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,ec,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_FRONT (Leave)"=hex:40,00,00,00,00,00,00,00,d1,e9,5f,7f,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,ec,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_BACK (Enter)"=hex:40,00,00,00,00,00,00,00,d1,e9,5f,7f,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,ed,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_BACK (Leave)"=hex:40,00,00,00,00,00,00,00,c1,8d,67,7f,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,ed,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_SYSTEM (Enter)"=hex:40,00,00,00,00,00,00,00,c1,8d,67,7f,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,ee,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_SYSTEM (Leave)"=hex:40,00,00,00,00,00,00,00,91,79,7e,7f,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,ee,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_KTM (Enter)"=hex:40,00,00,00,00,00,00,00,91,79,7e,7f,2b,d7,cd,01,a4,0c,\ + 00,00,f0,05,00,00,f0,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_KTM (Leave)"=hex:40,00,00,00,00,00,00,00,91,79,7e,7f,2b,d7,cd,01,a4,0c,\ + 00,00,f0,05,00,00,f0,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_RM (Enter)"=hex:40,00,00,00,00,00,00,00,91,79,7e,7f,2b,d7,cd,01,a4,0c,\ + 00,00,f0,05,00,00,ef,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE_RM (Leave)"=hex:40,00,00,00,00,00,00,00,a1,a1,d8,7f,2b,d7,cd,01,a4,0c,\ + 00,00,f0,05,00,00,ef,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE (Leave)"=hex:40,00,00,00,00,00,00,00,a1,a1,d8,7f,2b,d7,cd,01,a4,0c,00,\ + 00,f0,05,00,00,eb,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW_KTM (Enter)"=hex:40,00,00,00,00,00,00,00,c1,24,c2,86,2b,d7,cd,01,a4,0c,\ + 00,00,f0,05,00,00,f4,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW_KTM (Leave)"=hex:40,00,00,00,00,00,00,00,71,54,d1,88,2b,d7,cd,01,a4,0c,\ + 00,00,f0,05,00,00,f4,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Enter)"=hex:40,00,00,00,00,00,00,00,71,54,d1,88,2b,d7,cd,01,a4,0c,00,00,\ + f0,05,00,00,f2,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,a4,0c,00,00,\ + f0,05,00,00,f2,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"POSTSNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,31,fa,a7,8a,2b,d7,cd,01,a4,\ + 0c,00,00,f0,05,00,00,f5,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"POSTSNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,d1,70,eb,75,2b,d7,cd,01,a4,\ + 0c,00,00,14,0f,00,00,f5,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,34,8b,\ + ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Enter)"=hex:40,00,00,00,00,00,00,00,81,db,5d,7a,2b,d7,cd,01,\ + a4,0c,00,00,14,0f,00,00,fb,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Leave)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + a4,0c,00,00,14,0f,00,00,fb,03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Diag\WMI Writer] +"IDENTIFY (Enter)"=hex:40,00,00,00,00,00,00,00,71,d8,ae,7a,2b,d7,cd,01,6c,03,\ + 00,00,30,0a,00,00,e8,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"IDENTIFY (Leave)"=hex:40,00,00,00,00,00,00,00,61,7c,b6,7a,2b,d7,cd,01,6c,03,\ + 00,00,30,0a,00,00,e8,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Enter)"=hex:40,00,00,00,00,00,00,00,e1,e5,49,7c,2b,d7,cd,01,6c,\ + 03,00,00,30,0a,00,00,e9,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPAREBACKUP (Leave)"=hex:40,00,00,00,00,00,00,00,a1,02,50,7c,2b,d7,cd,01,6c,\ + 03,00,00,30,0a,00,00,e9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_STABLE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,a1,02,50,7c,2b,\ + d7,cd,01,6c,03,00,00,30,0a,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,\ + 00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,\ + 00 +"GETSTATE (Enter)"=hex:40,00,00,00,00,00,00,00,21,af,74,7c,2b,d7,cd,01,6c,03,\ + 00,00,30,0a,00,00,f9,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"GETSTATE (Leave)"=hex:40,00,00,00,00,00,00,00,51,36,76,7c,2b,d7,cd,01,6c,03,\ + 00,00,30,0a,00,00,f9,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,d0,53,\ + 6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,e1,79,f6,7e,2b,d7,cd,01,\ + 6c,03,00,00,30,0a,00,00,ea,03,00,00,01,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"PREPARESNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,f1,bb,1f,7f,2b,d7,cd,01,\ + 6c,03,00,00,30,0a,00,00,ea,03,00,00,00,00,00,00,01,00,00,00,00,00,00,00,b7,\ + d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,f1,\ + bb,1f,7f,2b,d7,cd,01,6c,03,00,00,30,0a,00,00,02,00,00,00,01,00,00,00,01,00,\ + 00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,\ + 00,00,00,00,00 +"FREEZE (Enter)"=hex:40,00,00,00,00,00,00,00,d1,e9,5f,7f,2b,d7,cd,01,6c,03,00,\ + 00,30,0a,00,00,eb,03,00,00,01,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"FREEZE (Leave)"=hex:40,00,00,00,00,00,00,00,d1,e9,5f,7f,2b,d7,cd,01,6c,03,00,\ + 00,30,0a,00,00,eb,03,00,00,00,00,00,00,02,00,00,00,00,00,00,00,b7,d0,53,6d,\ + a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_THAW (SetCurrentState)"=hex:40,00,00,00,00,00,00,00,d1,e9,\ + 5f,7f,2b,d7,cd,01,6c,03,00,00,30,0a,00,00,03,00,00,00,01,00,00,00,02,00,00,\ + 00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,\ + 00,00,00,00 +"BKGND_FREEZE_THREAD (Enter)"=hex:40,00,00,00,00,00,00,00,d1,e9,5f,7f,2b,d7,cd,\ + 01,6c,03,00,00,ac,0b,00,00,fc,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Enter)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,6c,03,00,00,\ + 30,0a,00,00,f2,03,00,00,01,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"BKGND_FREEZE_THREAD (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,\ + 01,6c,03,00,00,ac,0b,00,00,fc,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,\ + b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"THAW (Leave)"=hex:40,00,00,00,00,00,00,00,91,7f,da,88,2b,d7,cd,01,6c,03,00,00,\ + 30,0a,00,00,f2,03,00,00,00,00,00,00,03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,\ + 4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)"=hex:40,00,00,00,00,00,00,\ + 00,91,7f,da,88,2b,d7,cd,01,6c,03,00,00,30,0a,00,00,04,00,00,00,01,00,00,00,\ + 03,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,\ + 00,00,00,00,00,00,00 +"POSTSNAPSHOT (Enter)"=hex:40,00,00,00,00,00,00,00,31,6d,c0,8a,2b,d7,cd,01,6c,\ + 03,00,00,78,03,00,00,f5,03,00,00,01,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"POSTSNAPSHOT (Leave)"=hex:40,00,00,00,00,00,00,00,31,6d,c0,8a,2b,d7,cd,01,6c,\ + 03,00,00,78,03,00,00,f5,03,00,00,00,00,00,00,04,00,00,00,00,00,00,00,b7,d0,\ + 53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,00,00,00,00,00,00,00,00 +"VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)"=hex:40,00,00,00,00,00,\ + 00,00,31,6d,c0,8a,2b,d7,cd,01,6c,03,00,00,78,03,00,00,05,00,00,00,01,00,00,\ + 00,04,00,00,00,00,00,00,00,b7,d0,53,6d,a6,4c,b5,46,a4,cb,b4,b8,2c,e9,59,16,\ + 00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Enter)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + 6c,03,00,00,30,0a,00,00,fb,03,00,00,01,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 +"BACKUPSHUTDOWN (Leave)"=hex:40,00,00,00,00,00,00,00,71,7f,65,7a,2b,d7,cd,01,\ + 6c,03,00,00,30,0a,00,00,fb,03,00,00,00,00,00,00,05,00,00,00,00,00,00,00,34,\ + 8b,ce,67,e0,27,7a,47,bd,1f,ff,f8,73,69,f5,6f,00,00,00,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSS\Providers] @@ -1330661,265 +1332236,7 @@ [HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache] -[HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\9F] - -[HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\9F\52C64B7E] -"LanguageList"=hex(7):65,00,6e,00,2d,00,55,00,53,00,00,00,65,00,6e,00,00,00,00,\ - 00 -"@%SystemRoot%\\system32\\aelupsvc.dll,-1"="Application Experience" -"@%systemroot%\\system32\\drivers\\afd.sys,-1000"="Ancillary Function Driver for Winsock" -"@%SystemRoot%\\system32\\Alg.exe,-112"="Application Layer Gateway Service" -"@%systemroot%\\system32\\appidsvc.dll,-102"="AppID Driver" -"@%systemroot%\\system32\\appidsvc.dll,-100"="Application Identity" -"@%systemroot%\\system32\\appinfo.dll,-100"="Application Information" -"@appmgmts.dll,-3250"="Application Management" -"@%systemroot%\\system32\\rascfg.dll,-32000"="RAS Asynchronous Media Driver" -"@%SystemRoot%\\system32\\audiosrv.dll,-204"="Windows Audio Endpoint Builder" -"@%SystemRoot%\\system32\\audiosrv.dll,-200"="Windows Audio" -"@%SystemRoot%\\system32\\AxInstSV.dll,-103"="ActiveX Installer (AxInstSV)" -"@%SystemRoot%\\system32\\bdesvc.dll,-100"="BitLocker Drive Encryption Service" -"@%SystemRoot%\\system32\\bfe.dll,-1001"="Base Filtering Engine" -"@%SystemRoot%\\system32\\qmgr.dll,-1000"="Background Intelligent Transfer Service" -"@%systemroot%\\system32\\browser.dll,-102"="Browser Support Driver" -"@%systemroot%\\system32\\browser.dll,-100"="Computer Browser" -"@%SystemRoot%\\System32\\bthserv.dll,-101"="Bluetooth Support Service" -"@%SystemRoot%\\System32\\certprop.dll,-11"="Certificate Propagation" -"@%SystemRoot%\\system32\\clfs.sys,-100"="Common Log (CLFS)" -"@comres.dll,-947"="COM+ System Application" -"@%SystemRoot%\\system32\\cryptsvc.dll,-1001"="Cryptographic Services" -"@%systemroot%\\system32\\cscsvc.dll,-202"="Offline Files Driver" -"@%systemroot%\\system32\\cscsvc.dll,-200"="Offline Files" -"@oleres.dll,-5012"="DCOM Server Process Launcher" -"@%SystemRoot%\\system32\\defragsvc.dll,-101"="Disk Defragmenter" -"@%systemroot%\\system32\\drivers\\dfsc.sys,-101"="DFS Namespace Client Driver" -"@%SystemRoot%\\system32\\dhcpcore.dll,-100"="DHCP Client" -"@%systemroot%\\system32\\drivers\\discache.sys,-102"="System Attribute Cache" -"@%SystemRoot%\\System32\\dnsapi.dll,-101"="DNS Client" -"@%systemroot%\\system32\\dot3svc.dll,-1102"="Wired AutoConfig" -"@%systemroot%\\system32\\dps.dll,-500"="Diagnostic Policy Service" -"@%systemroot%\\system32\\eapsvc.dll,-1"="Extensible Authentication Protocol" -"@%SystemRoot%\\system32\\efssvc.dll,-100"="Encrypting File System (EFS)" -"@%SystemRoot%\\ehome\\ehrecvr.exe,-101"="Windows Media Center Receiver Service" -"@%SystemRoot%\\ehome\\ehsched.exe,-101"="Windows Media Center Scheduler Service" -"@%SystemRoot%\\system32\\wevtsvc.dll,-200"="Windows Event Log" -"@comres.dll,-2450"="COM+ Event System" -"@%systemroot%\\system32\\fxsresm.dll,-118"="Fax" -"@%systemroot%\\system32\\fdPHost.dll,-100"="Function Discovery Provider Host" -"@%systemroot%\\system32\\fdrespub.dll,-100"="Function Discovery Resource Publication" -"@%SystemRoot%\\system32\\drivers\\fileinfo.sys,-100"="File Information FS MiniFilter" -"@%SystemRoot%\\system32\\drivers\\filetrace.sys,-10001"="FileTrace" -"@%SystemRoot%\\system32\\drivers\\fltmgr.sys,-10001"="FltMgr" -"@%systemroot%\\system32\\FntCache.dll,-100"="Windows Font Cache Service" -"@%SystemRoot%\\system32\\PresentationHost.exe,-3309"="Windows Presentation Foundation Font Cache 3.0.0.0" -"@%SystemRoot%\\system32\\drivers\\fsdepends.sys,-10001"="File System Dependency Minifilter" -"@%SystemRoot%\\system32\\drivers\\fvevol.sys,-100"="Bitlocker Drive Encryption Filter Driver" -"@gpapi.dll,-112"="Group Policy Client" -"@%SystemRoot%\\System32\\hidserv.dll,-101"="Human Interface Device Access" -"@%SystemRoot%\\system32\\kmsvc.dll,-6"="Health Key and Certificate Management" -"@%SystemRoot%\\System32\\ListSvc.dll,-100"="HomeGroup Listener" -"@%SystemRoot%\\System32\\provsvc.dll,-100"="HomeGroup Provider" -"@%SystemRoot%\\system32\\drivers\\http.sys,-1"="HTTP" -"@%systemroot%\\system32\\drivers\\hwpolicy.sys,-101"="Hardware Policy Driver" -"@%systemroot%\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelInstallRC.dll,-8193"="Windows CardSpace" -"@%SystemRoot%\\system32\\ikeext.dll,-501"="IKE and AuthIP IPsec Keying Modules" -"@%systemroot%\\system32\\IPBusEnum.dll,-102"="PnP-X IP Bus Enumerator" -"@%systemroot%\\system32\\rascfg.dll,-32013"="IP Traffic Filter Driver" -"@%SystemRoot%\\system32\\iphlpsvc.dll,-500"="IP Helper" -"@%SystemRoot%\\system32\\drivers\\irenum.sys,-100"="IR Bus Enumerator" -"@keyiso.dll,-100"="CNG Key Isolation" -"@comres.dll,-2946"="KtmRm for Distributed Transaction Coordinator" -"@%systemroot%\\system32\\srvsvc.dll,-100"="Server" -"@%systemroot%\\system32\\wkssvc.dll,-100"="Workstation" -"@%SystemRoot%\\system32\\lltdres.dll,-1"="Link-Layer Topology Discovery Mapper" -"@%SystemRoot%\\system32\\lmhsvc.dll,-101"="TCP/IP NetBIOS Helper" -"@%systemroot%\\system32\\drivers\\luafv.sys,-100"="UAC File Virtualization" -"@%SystemRoot%\\ehome\\ehres.dll,-15501"="Media Center Extender Service" -"@%systemroot%\\system32\\mmcss.dll,-100"="Multimedia Class Scheduler" -"@%SystemRoot%\\system32\\drivers\\mountmgr.sys,-100"="Mount Point Manager" -"@%SystemRoot%\\system32\\FirewallAPI.dll,-23092"="Windows Firewall Authorization Driver" -"@%SystemRoot%\\system32\\FirewallAPI.dll,-23090"="Windows Firewall" -"@%systemroot%\\system32\\webclnt.dll,-104"="WebDav Client Redirector Driver" -"@%systemroot%\\system32\\wkssvc.dll,-1002"="SMB MiniRedirector Wrapper and Engine" -"@%systemroot%\\system32\\wkssvc.dll,-1004"="SMB 1.x MiniRedirector" -"@%systemroot%\\system32\\wkssvc.dll,-1006"="SMB 2.0 MiniRedirector" -"@comres.dll,-2797"="Distributed Transaction Coordinator" -"@%SystemRoot%\\system32\\drivers\\mshidkmdf.sys,-100"="Pass-through HID to KMDF Filter Driver" -"@%SystemRoot%\\system32\\iscsidsc.dll,-5000"="Microsoft iSCSI Initiator Service" -"@%SystemRoot%\\system32\\msimsg.dll,-27"="Windows Installer" -"@%systemroot%\\system32\\drivers\\mup.sys,-101"="MUP" -"@%SystemRoot%\\system32\\qagentrt.dll,-6"="Network Access Protection Agent" -"@%SystemRoot%\\system32\\drivers\\ndis.sys,-200"="NDIS System Driver" -"@%systemroot%\\system32\\rascfg.dll,-32001"="Remote Access NDIS TAPI Driver" -"@%systemroot%\\system32\\rascfg.dll,-32002"="Remote Access NDIS WAN Driver" -"@%SystemRoot%\\system32\\drivers\\netbt.sys,-2"="NETBT" -"@%SystemRoot%\\System32\\netlogon.dll,-102"="Netlogon" -"@%SystemRoot%\\system32\\netman.dll,-109"="Network Connections" -"@C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\\\ServiceModelInstallRC.dll,-8195"="Net.Msmq Listener Adapter" -"@C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\\\ServiceModelInstallRC.dll,-8197"="Net.Pipe Listener Adapter" -"@%SystemRoot%\\system32\\netprofm.dll,-202"="Network List Service" -"@C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\\\ServiceModelInstallRC.dll,-8199"="Net.Tcp Listener Adapter" -"@C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\\\ServiceModelInstallRC.dll,-8201"="Net.Tcp Port Sharing Service" -"@%SystemRoot%\\System32\\nlasvc.dll,-1"="Network Location Awareness" -"@%SystemRoot%\\system32\\nsisvc.dll,-200"="Network Store Interface Service" -"@%SystemRoot%\\system32\\drivers\\nsiproxy.sys,-2"="NSI proxy service driver." -"@%SystemRoot%\\system32\\pnrpsvc.dll,-8004"="Peer Networking Identity Manager" -"@%SystemRoot%\\system32\\p2psvc.dll,-8006"="Peer Networking Grouping" -"@%SystemRoot%\\system32\\drivers\\partmgr.sys,-100"="Partition Manager" -"@%SystemRoot%\\system32\\pcasvc.dll,-1"="Program Compatibility Assistant Service" -"@%SystemRoot%\\system32\\peerdistsvc.dll,-9000"="BranchCache" -"@%systemroot%\\system32\\pla.dll,-500"="Performance Logs & Alerts" -"@%SystemRoot%\\system32\\umpnpmgr.dll,-100"="Plug and Play" -"@%SystemRoot%\\system32\\pnrpauto.dll,-8002"="PNRP Machine Name Publication Service" -"@%SystemRoot%\\system32\\pnrpsvc.dll,-8000"="Peer Name Resolution Protocol" -"@%SystemRoot%\\System32\\polstore.dll,-5010"="IPsec Policy Agent" -"@%SystemRoot%\\system32\\umpo.dll,-100"="Power" -"@%systemroot%\\system32\\rascfg.dll,-32006"="WAN Miniport (PPTP)" -"@%systemroot%\\system32\\profsvc.dll,-300"="User Profile Service" -"@%systemroot%\\system32\\psbase.dll,-300"="Protected Storage" -"@%SystemRoot%\\System32\\drivers\\pacer.sys,-101"="QoS Packet Scheduler" -"@%SystemRoot%\\system32\\qwave.dll,-1"="Quality Windows Audio Video Experience" -"@%SystemRoot%\\system32\\drivers\\qwavedrv.sys,-1"="QWAVE driver" -"@%Systemroot%\\system32\\rasauto.dll,-200"="Remote Access Auto Connection Manager" -"@%systemroot%\\system32\\rascfg.dll,-32005"="WAN Miniport (L2TP)" -"@%Systemroot%\\system32\\rasmans.dll,-200"="Remote Access Connection Manager" -"@%systemroot%\\system32\\rascfg.dll,-32007"="Remote Access PPPOE Driver" -"@%systemroot%\\system32\\sstpsvc.dll,-202"="WAN Miniport (SSTP)" -"@%systemroot%\\system32\\wkssvc.dll,-1000"="Redirected Buffering Sub Sysytem" -"@%systemroot%\\system32\\DRIVERS\\RDPCDD.sys,-100"="RDPCDD" -"@%systemroot%\\system32\\drivers\\RDPENCDD.sys,-101"="RDP Encoder Mirror Driver" -"@%systemroot%\\system32\\drivers\\RdpRefMp.sys,-101"="Reflector Display Driver used to gain access to graphics data" -"@%Systemroot%\\system32\\mprdim.dll,-200"="Routing and Remote Access" -"@regsvc.dll,-1"="Remote Registry" -"@%windir%\\system32\\RpcEpMap.dll,-1001"="RPC Endpoint Mapper" -"@%systemroot%\\system32\\Locator.exe,-2"="Remote Procedure Call (RPC) Locator" -"@oleres.dll,-5010"="Remote Procedure Call (RPC)" -"@%SystemRoot%\\system32\\samsrv.dll,-1"="Security Accounts Manager" -"@%SystemRoot%\\System32\\SCardSvr.dll,-1"="Smart Card" -"@%SystemRoot%\\System32\\drivers\\scfilter.sys,-11"="Smart card PnP Class Filter Driver" -"@%SystemRoot%\\system32\\schedsvc.dll,-100"="Task Scheduler" -"@%SystemRoot%\\System32\\certprop.dll,-13"="Smart Card Removal Policy" -"@%SystemRoot%\\system32\\sdrsvc.dll,-107"="Windows Backup" -"@%SystemRoot%\\system32\\seclogon.dll,-7001"="Secondary Logon" -"@%SystemRoot%\\system32\\Sens.dll,-200"="System Event Notification Service" -"@%SystemRoot%\\System32\\sensrsvc.dll,-1000"="Adaptive Brightness" -"@%SystemRoot%\\System32\\SessEnv.dll,-1026"="Remote Desktop Configuration" -"@%SystemRoot%\\system32\\ipnathlp.dll,-106"="Internet Connection Sharing (ICS)" -"@%SystemRoot%\\System32\\shsvcs.dll,-12288"="Shell Hardware Detection" -"@%SystemRoot%\\system32\\tcpipcfg.dll,-50005"="Message-oriented TCP/IP and TCP/IPv6 Protocol (SMB session)" -"@%SystemRoot%\\system32\\snmptrap.exe,-3"="SNMP Trap" -"@%systemroot%\\system32\\spoolsv.exe,-1"="Print Spooler" -"@%SystemRoot%\\system32\\sppsvc.exe,-101"="Software Protection" -"@%SystemRoot%\\system32\\sppuinotify.dll,-103"="SPP Notification Service" -"@%systemroot%\\system32\\srvsvc.dll,-102"="Server SMB 1.xxx Driver" -"@%systemroot%\\system32\\srvsvc.dll,-104"="Server SMB 2.xxx Driver" -"@%systemroot%\\system32\\ssdpsrv.dll,-100"="SSDP Discovery" -"@%SystemRoot%\\system32\\sstpsvc.dll,-200"="Secure Socket Tunneling Protocol Service" -"@%SystemRoot%\\system32\\wiaservc.dll,-9"="Windows Image Acquisition (WIA)" -"@%SystemRoot%\\system32\\vmstorfltres.dll,-1000"="Disk Virtual Machine Bus Acceleration Filter Driver" -"@%SystemRoot%\\System32\\StorSvc.dll,-100"="Storage Service" -"@%SystemRoot%\\System32\\swprv.dll,-103"="Microsoft Software Shadow Copy Provider" -"@%SystemRoot%\\system32\\sysmain.dll,-1000"="Superfetch" -"@%SystemRoot%\\system32\\TabSvc.dll,-100"="Tablet PC Input Service" -"@%SystemRoot%\\system32\\tapisrv.dll,-10100"="Telephony" -"@%SystemRoot%\\system32\\tbssvc.dll,-100"="TPM Base Services" -"@%SystemRoot%\\system32\\tcpipcfg.dll,-50003"="TCP/IP Protocol Driver" -"@%SystemRoot%\\system32\\tcpipcfg.dll,-50004"="NetIO Legacy TDI Support Driver" -"@%SystemRoot%\\System32\\termsrv.dll,-268"="Remote Desktop Services" -"@%SystemRoot%\\System32\\themeservice.dll,-8192"="Themes" -"@%systemroot%\\system32\\mmcss.dll,-102"="Thread Ordering Server" -"@%SystemRoot%\\system32\\trkwks.dll,-1"="Distributed Link Tracking Client" -"@%SystemRoot%\\servicing\\TrustedInstaller.exe,-100"="Windows Modules Installer" -"@%SystemRoot%\\System32\\DRIVERS\\tssecsrv.sys,-101"="Remote Desktop Services Security Filter Driver" -"@%SystemRoot%\\system32\\ui0detect.exe,-101"="Interactive Services Detection" -"@%SystemRoot%\\system32\\umrdp.dll,-1000"="Remote Desktop Services UserMode Port Redirector" -"@%systemroot%\\system32\\upnphost.dll,-213"="UPnP Device Host" -"@%SystemRoot%\\system32\\dwm.exe,-2000"="Desktop Window Manager Session Manager" -"@%SystemRoot%\\system32\\vaultsvc.dll,-1003"="Credential Manager" -"@%SystemRoot%\\system32\\vds.exe,-100"="Virtual Disk" -"@%SystemRoot%\\system32\\vmbusres.dll,-1000"="Virtual Machine Bus" -"@%SystemRoot%\\system32\\drivers\\volmgrx.sys,-100"="Dynamic Volume Manager" -"@%systemroot%\\system32\\vssvc.exe,-102"="Volume Shadow Copy" -"@%SystemRoot%\\System32\\drivers\\vwifibus.sys,-257"="Virtual WiFi Bus Driver" -"@%SystemRoot%\\system32\\w32time.dll,-200"="Windows Time" -"@%systemroot%\\system32\\rascfg.dll,-32011"="Remote Access IP ARP Driver" -"@%systemroot%\\system32\\rascfg.dll,-32012"="Remote Access IPv6 ARP Driver" -"@%SystemRoot%\\system32\\Wat\\WatUX.exe,-601"="Windows Activation Technologies Service" -"@%systemroot%\\system32\\wbengine.exe,-104"="Block Level Backup Engine Service" -"@%systemroot%\\system32\\wbiosrvc.dll,-100"="Windows Biometric Service" -"@%SystemRoot%\\system32\\wcncsvc.dll,-3"="Windows Connect Now - Config Registrar" -"@%SystemRoot%\\system32\\WcsPlugInService.dll,-200"="Windows Color System" -"@%SystemRoot%\\system32\\drivers\\Wdf01000.sys,-1000"="Kernel Mode Driver Frameworks service" -"@%systemroot%\\system32\\wdi.dll,-502"="Diagnostic Service Host" -"@%systemroot%\\system32\\wdi.dll,-500"="Diagnostic System Host" -"@%systemroot%\\system32\\webclnt.dll,-100"="WebClient" -"@%SystemRoot%\\system32\\wecsvc.dll,-200"="Windows Event Collector" -"@%SystemRoot%\\System32\\wercplsupport.dll,-101"="Problem Reports and Solutions Control Panel Support" -"@%SystemRoot%\\System32\\wersvc.dll,-100"="Windows Error Reporting Service" -"@%ProgramFiles%\\Windows Defender\\MsMpRes.dll,-103"="Windows Defender" -"@%SystemRoot%\\system32\\winhttp.dll,-100"="WinHTTP Web Proxy Auto-Discovery Service" -"@%Systemroot%\\system32\\wbem\\wmisvc.dll,-205"="Windows Management Instrumentation" -"@%Systemroot%\\system32\\wsmsvc.dll,-101"="Windows Remote Management (WS-Management)" -"@%SystemRoot%\\System32\\wlansvc.dll,-257"="WLAN AutoConfig" -"@%Systemroot%\\system32\\wbem\\wmiapsrv.exe,-110"="WMI Performance Adapter" -"@%PROGRAMFILES%\\Windows Media Player\\wmpnetwk.exe,-101"="Windows Media Player Network Sharing Service" -"@%SystemRoot%\\system32\\wpcsvc.dll,-100"="Parental Controls" -"@%SystemRoot%\\system32\\wpdbusenum.dll,-100"="Portable Device Enumerator Service" -"@%systemroot%\\System32\\drivers\\ws2ifsl.sys,-1000"="Winsock IFS Driver" -"@%SystemRoot%\\System32\\wscsvc.dll,-200"="Security Center" -"@%systemroot%\\system32\\SearchIndexer.exe,-103"="Windows Search" -"@%systemroot%\\system32\\wuaueng.dll,-105"="Windows Update" -"@%SystemRoot%\\system32\\drivers\\Wudfpf.sys,-1000"="User Mode Driver Frameworks Platform Driver" -"@%SystemRoot%\\system32\\wudfsvc.dll,-1000"="Windows Driver Foundation - User-mode Driver Framework" -"@%SystemRoot%\\System32\\wwansvc.dll,-257"="WWAN AutoConfig" -"@%SystemRoot%\\System32\\drivers\\pacer.sys,-100"="Quality of Service Packet Scheduler. This component provides network traffic control, including rate-of-flow and prioritization services." -"@netcfgx.dll,-50003"="Allows other computers to access resources on your computer using a Microsoft network." -"@netcfgx.dll,-50002"="Allows your computer to access resources on a Microsoft network." -"@tcpipcfg.dll,-50002"="TCP/IP version 6. The latest version of the internet protocol that provides communication across diverse interconnected networks." -"@%SystemRoot%\\system32\\tcpipcfg.dll,-50001"="Transmission Control Protocol/Internet Protocol. The default wide area network protocol that provides communication across diverse interconnected networks." -"@%SystemRoot%\\system32\\lltdres.dll,-4"="Used to discover and locate other PCs, devices, and network infrastructure components on the network. Also used to determine network bandwidth." -"@%SystemRoot%\\system32\\lltdres.dll,-3"="Allows this PC to be discovered and located on the network." -"@%systemroot%\\system32\\rascfg.dll,-32010"="Provides the abilitiy to connect a host to a Remote Access Concentrator that supports RFC2516." -"@%systemroot%\\system32\\rascfg.dll,-32009"="Allows you to securely connect to a private network using the Internet." -"@%systemroot%\\system32\\rascfg.dll,-32008"="Allows you to securely connect to a private network using the Internet." -"@%systemroot%\\system32\\sstpsvc.dll,-203"="Allows you to securely connect to a private network using the Internet." -"@provsvc.dll,-202"="HomeGroup" -"@C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\\\ServiceModelEvents.dll,-2002"="Windows Communication Foundation" -"@peerdistsh.dll,-9003"="BranchCache - Hosted Cache Client (Uses HTTPS)" -"@peerdistsh.dll,-9002"="BranchCache - Hosted Cache Server (Uses HTTPS)" -"@peerdistsh.dll,-9001"="BranchCache - Peer Discovery (Uses WSD)" -"@peerdistsh.dll,-9000"="BranchCache - Content Retrieval (Uses HTTP)" -"@%systemroot%\\system32\\provsvc.dll,-202"="HomeGroup" -"@snmptrap.exe,-3"="SNMP Trap" -"@netlogon.dll,-1010"="Netlogon Service" -"@sstpsvc.dll,-35001"="Secure Socket Tunneling Protocol" -"@%SystemRoot%\\system32\\p2pcollab.dll,-8042"="Peer to Peer Trust" -"@%SystemRoot%\\system32\\qagentrt.dll,-10"="System Health Authentication" -"@%SystemRoot%\\system32\\dnsapi.dll,-103"="Domain Name System (DNS) Server Trust" -"@%SystemRoot%\\System32\\fveui.dll,-843"="BitLocker Drive Encryption" -"@%SystemRoot%\\System32\\fveui.dll,-844"="BitLocker Data Recovery Agent" -"C:\\Windows\\system32,@elscore.dll,-2"="Microsoft Script Detection" -"C:\\Windows\\system32,@elscore.dll,-5"="Microsoft Transliteration Engine" -"C:\\Windows\\system32,@elscore.dll,-4"="Microsoft Simplified Chinese to Traditional Chinese Transliteration" -"C:\\Windows\\system32,@elscore.dll,-6"="Microsoft Cyrillic to Latin Transliteration" -"C:\\Windows\\system32,@elscore.dll,-3"="Microsoft Traditional Chinese to Simplified Chinese Transliteration" -"C:\\Windows\\system32,@elscore.dll,-7"="Microsoft Devanagari to Latin Transliteration" -"C:\\Windows\\system32,@elscore.dll,-8"="Microsoft Malayalam to Latin Transliteration" -"C:\\Windows\\system32,@elscore.dll,-9"="Microsoft Bengali to Latin Transliteration" -"C:\\Windows\\system32,@elscore.dll,-1"="Microsoft Language Detection" -"@C:\\Windows\\system32\\unregmp2.exe,-9914"="Windows Media Audio/Video file" -"@C:\\Windows\\system32\\SampleRes.dll,-142"="Wildlife" -"@C:\\Windows\\system32\\SampleRes.dll,-106"="Tulips" -"@C:\\Windows\\system32\\SampleRes.dll,-108"="Penguins" -"@C:\\Windows\\system32\\SampleRes.dll,-107"="Lighthouse" -"@C:\\Windows\\system32\\SampleRes.dll,-105"="Koala" -"@C:\\Windows\\system32\\SampleRes.dll,-104"="Jellyfish" -"@C:\\Windows\\system32\\SampleRes.dll,-103"="Hydrangeas" -"@C:\\Windows\\system32\\SampleRes.dll,-102"="Desert" -"@C:\\Windows\\system32\\SampleRes.dll,-101"="Chrysanthemum" -"@C:\\Windows\\system32\\unregmp2.exe,-9925"="MP3 Format Sound" -"@C:\\Windows\\system32\\SampleRes.dll,-118"="Sleep Away" -"@C:\\Windows\\system32\\SampleRes.dll,-117"="Maid with the Flaxen Hair" -"@C:\\Windows\\system32\\SampleRes.dll,-116"="Kalimba" +[HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\A1] [HKEY_USERS\.DEFAULT\Software\Microsoft] @@ -1340779,8 +1342096,8 @@ 65,00,35,00,30,00,39,00,2d,00,31,00,62,00,33,00,34,00,2d,00,34,00,31,00,63,\ 00,30,00,2d,00,61,00,63,00,62,00,37,00,2d,00,36,00,64,00,34,00,36,00,35,00,\ 30,00,31,00,36,00,38,00,39,00,31,00,35,00,00,00,00,00,00,00,00,00,ad,a4,ee,\ - eb,04,00,00,00,00,00,00,00,08,00,00,00,00,00,00,00,00,00,00,00,35,ec,4b,78,\ - 04,00,00,00,00,00,00,00,08,00,00,00,97,60,4d,4c,01,d7,cd,01,58,19,2c,c1,01,\ + eb,04,00,00,00,00,00,00,00,08,00,00,00,00,00,00,00,00,00,00,00,12,22,c2,00,\ + 04,00,00,00,00,00,00,00,08,00,00,00,91,80,43,82,2b,d7,cd,01,58,19,2c,c1,01,\ 00,00,00,00,00,00,00,04,00,00,00,78,00,00,00,00,00,00,00,84,7b,cc,f1,01,00,\ 00,00,00,00,00,00,04,00,00,00,60,27,00,00,00,00,00,00 @@ -1348196,10 +1349513,10 @@ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,64,00,69,\ 00,76,00,76,00,75,00,6e,00,31,00,31,00,75,00,6e,00,69,00,6e,00,73,00,74,00,\ 61,00,6c,00,6c,00,65,00,64,00,2e,00,72,00,65,00,67,00,00,00,26,00,00,00 -"MRUListEx"=hex:0b,00,00,00,0a,00,00,00,09,00,00,00,08,00,00,00,07,00,00,00,06,\ - 00,00,00,05,00,00,00,04,00,00,00,03,00,00,00,02,00,00,00,00,00,00,00,13,00,\ - 00,00,12,00,00,00,10,00,00,00,11,00,00,00,0f,00,00,00,01,00,00,00,0e,00,00,\ - 00,0d,00,00,00,0c,00,00,00,ff,ff,ff,ff +"MRUListEx"=hex:0c,00,00,00,0b,00,00,00,0a,00,00,00,09,00,00,00,08,00,00,00,07,\ + 00,00,00,06,00,00,00,05,00,00,00,04,00,00,00,03,00,00,00,02,00,00,00,00,00,\ + 00,00,13,00,00,00,12,00,00,00,10,00,00,00,11,00,00,00,0f,00,00,00,01,00,00,\ + 00,0e,00,00,00,0d,00,00,00,ff,ff,ff,ff "1"=hex:14,00,1f,42,25,48,1e,03,94,7b,c3,4d,b1,31,e9,46,b4,4c,8d,d5,74,00,00,\ 00,1a,00,ee,bb,fe,23,00,00,10,00,7d,b1,0d,7b,d2,9c,93,4a,97,33,46,cc,89,02,\ 2e,7c,00,00,2a,00,00,00,00,00,ef,be,00,00,00,20,00,00,00,00,00,00,00,00,00,\ @@ -1348564,21 +1349881,41 @@ 00,00,00,00,00,00,00,00,00,00,62,00,65,00,66,00,6f,00,72,00,65,00,64,00,69,\ 00,76,00,76,00,75,00,6e,00,31,00,31,00,2e,00,72,00,65,00,67,00,00,00,22,00,\ 00,00 -"12"=hex:14,00,1f,50,e0,4f,d0,20,ea,3a,69,10,a2,d8,08,00,2b,30,30,9d,19,00,2f,\ - 43,3a,5c,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,88,00,31,\ - 00,00,00,00,00,83,41,60,54,11,00,50,52,4f,47,52,41,7e,31,00,00,70,00,08,00,\ - 04,00,ef,be,ee,3a,a3,14,83,41,60,54,2a,00,00,00,3c,00,00,00,00,00,01,00,00,\ - 00,00,00,00,00,00,00,46,00,00,00,00,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ - 6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,00,00,40,00,73,00,68,00,65,00,6c,\ - 00,6c,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,2c,00,2d,00,32,00,31,00,37,00,\ - 38,00,31,00,00,00,18,00,58,00,31,00,00,00,00,00,83,41,60,54,10,00,4e,4f,54,\ - 45,50,41,7e,31,00,00,40,00,08,00,04,00,ef,be,83,41,60,54,83,41,60,54,2a,00,\ - 00,00,fa,24,01,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,4e,\ - 00,6f,00,74,00,65,00,70,00,61,00,64,00,2b,00,2b,00,00,00,18,00,64,00,32,00,\ - 00,f0,18,00,72,41,4b,89,20,00,4e,4f,54,45,50,41,7e,31,2e,45,58,45,00,00,48,\ - 00,08,00,04,00,ef,be,72,41,4b,89,83,41,60,54,2a,00,00,00,0f,25,01,00,00,00,\ - 02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,6e,00,6f,00,74,00,65,00,70,\ - 00,61,00,64,00,2b,00,2b,00,2e,00,65,00,78,00,65,00,00,00,1c,00,00,00 +"12"=hex:14,00,1f,58,0d,1a,2c,f0,21,be,50,43,88,b0,73,67,fc,96,ef,3c,1a,02,00,\ + 00,14,02,bb,af,93,3b,06,02,04,00,00,00,00,00,3d,00,00,00,31,53,50,53,30,f1,\ + 25,b7,ef,47,1a,10,a5,f1,02,60,8c,9e,eb,ac,21,00,00,00,0a,00,00,00,00,1f,00,\ + 00,00,08,00,00,00,56,00,42,00,4f,00,58,00,53,00,56,00,52,00,00,00,00,00,00,\ + 00,2d,00,00,00,31,53,50,53,3a,a4,bd,de,b3,37,83,43,91,e7,44,98,da,29,95,ab,\ + 11,00,00,00,03,00,00,00,00,13,00,00,00,02,00,00,00,00,00,00,00,d6,00,00,00,\ + 31,53,50,53,73,43,e5,0a,be,43,ad,4f,85,e4,69,dc,86,33,98,6e,11,00,00,00,0b,\ + 00,00,00,00,0b,00,00,00,ff,ff,00,00,a9,00,00,00,07,00,00,00,00,1f,00,00,00,\ + 4c,00,00,00,50,00,72,00,6f,00,76,00,69,00,64,00,65,00,72,00,5c,00,4d,00,69,\ + 00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,4e,00,65,00,74,00,77,00,\ + 6f,00,72,00,6b,00,69,00,6e,00,67,00,2e,00,4e,00,65,00,74,00,62,00,69,00,6f,\ + 00,73,00,2f,00,2f,00,56,00,69,00,72,00,74,00,75,00,61,00,6c,00,42,00,6f,00,\ + 78,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,20,00,46,00,6f,00,6c,00,64,\ + 00,65,00,72,00,73,00,3a,00,3a,00,5c,00,5c,00,56,00,42,00,4f,00,58,00,53,00,\ + 56,00,52,00,00,00,00,00,00,00,45,00,00,00,31,53,50,53,02,d5,cd,d5,9c,2e,1b,\ + 10,93,97,08,00,2b,2c,f9,ae,29,00,00,00,02,00,00,00,00,1f,10,00,00,01,00,00,\ + 00,09,00,00,00,43,00,6f,00,6d,00,70,00,75,00,74,00,65,00,72,00,00,00,00,00,\ + 00,00,00,00,61,00,00,00,31,53,50,53,a6,6a,63,28,3d,95,d2,11,b5,d6,00,c0,4f,\ + d9,18,d0,45,00,00,00,1f,00,00,00,00,1f,00,00,00,1a,00,00,00,56,00,69,00,72,\ + 00,74,00,75,00,61,00,6c,00,42,00,6f,00,78,00,20,00,53,00,68,00,61,00,72,00,\ + 65,00,64,00,20,00,46,00,6f,00,6c,00,64,00,65,00,72,00,73,00,00,00,00,00,00,\ + 00,1c,00,00,00,31,53,50,53,b3,3b,6a,65,c0,ec,fd,43,84,77,4a,e0,40,4a,96,cd,\ + 00,00,00,00,00,00,00,00,00,00,39,00,c3,01,81,5c,5c,56,42,4f,58,53,56,52,5c,\ + 76,69,72,74,75,61,6c,62,6f,78,6d,61,70,00,56,69,72,74,75,61,6c,42,6f,78,20,\ + 53,68,61,72,65,64,20,46,6f,6c,64,65,72,73,00,25,00,5c,00,31,00,00,10,00,00,\ + 8a,41,b8,75,10,00,77,37,2d,33,32,2d,32,30,30,37,00,00,42,00,08,00,04,00,ef,\ + be,8a,41,b8,75,8a,41,b9,75,2a,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,77,00,37,00,2d,00,33,00,32,00,2d,00,32,00,30,\ + 00,30,00,37,00,00,00,1a,00,8c,00,32,00,79,db,3d,05,84,41,fa,5e,80,00,61,66,\ + 74,65,72,64,69,76,76,75,6e,31,31,69,6e,73,74,61,6c,6c,65,64,2e,72,65,67,00,\ + 00,62,00,08,00,04,00,ef,be,86,41,85,5a,8a,41,6f,73,2a,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,61,00,66,00,74,00,65,\ + 00,72,00,64,00,69,00,76,00,76,00,75,00,6e,00,31,00,31,00,69,00,6e,00,73,00,\ + 74,00,61,00,6c,00,6c,00,65,00,64,00,2e,00,72,00,65,00,67,00,00,00,2a,00,00,\ + 00 "13"=hex:14,00,1f,42,25,48,1e,03,94,7b,c3,4d,b1,31,e9,46,b4,4c,8d,d5,74,00,00,\ 00,1a,00,ee,bb,fe,23,00,00,10,00,7d,b1,0d,7b,d2,9c,93,4a,97,33,46,cc,89,02,\ 2e,7c,00,00,2a,00,00,00,00,00,ef,be,00,00,00,20,00,00,00,00,00,00,00,00,00,\ @@ -1349442,17 +1350779,21 @@ 00,1c,00,00,00,31,53,50,53,b3,3b,6a,65,c0,ec,fd,43,84,77,4a,e0,40,4a,96,cd,\ 00,00,00,00,00,00,00,00,00,00,39,00,c3,01,81,5c,5c,56,42,4f,58,53,56,52,5c,\ 76,69,72,74,75,61,6c,62,6f,78,6d,61,70,00,56,69,72,74,75,61,6c,42,6f,78,20,\ - 53,68,61,72,65,64,20,46,6f,6c,64,65,72,73,00,25,00,8e,00,32,00,00,00,00,00,\ - 00,00,00,00,80,00,75,74,65,6e,73,61,6d,69,73,6b,73,74,61,76,65,6b,6f,6e,74,\ - 72,6f,6c,6c,2e,72,65,67,00,64,00,08,00,04,00,ef,be,00,00,00,00,00,00,00,00,\ - 2a,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ - 00,75,00,74,00,65,00,6e,00,73,00,61,00,6d,00,69,00,73,00,6b,00,73,00,74,00,\ - 61,00,76,00,65,00,6b,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,6c,00,2e,00,72,\ - 00,65,00,67,00,00,00,2a,00,00,00 -"MRUListEx"=hex:13,00,00,00,12,00,00,00,11,00,00,00,10,00,00,00,0f,00,00,00,0e,\ - 00,00,00,0d,00,00,00,0c,00,00,00,0b,00,00,00,0a,00,00,00,09,00,00,00,08,00,\ - 00,00,07,00,00,00,06,00,00,00,05,00,00,00,04,00,00,00,03,00,00,00,02,00,00,\ - 00,01,00,00,00,00,00,00,00,ff,ff,ff,ff + 53,68,61,72,65,64,20,46,6f,6c,64,65,72,73,00,25,00,5c,00,31,00,00,10,00,00,\ + 8a,41,b8,75,10,00,77,37,2d,33,32,2d,32,30,30,37,00,00,42,00,08,00,04,00,ef,\ + be,8a,41,b8,75,8a,41,b9,75,2a,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,77,00,37,00,2d,00,33,00,32,00,2d,00,32,00,30,\ + 00,30,00,37,00,00,00,1a,00,8c,00,32,00,79,db,3d,05,84,41,fa,5e,80,00,61,66,\ + 74,65,72,64,69,76,76,75,6e,31,31,69,6e,73,74,61,6c,6c,65,64,2e,72,65,67,00,\ + 00,62,00,08,00,04,00,ef,be,86,41,85,5a,8a,41,6f,73,2a,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,61,00,66,00,74,00,65,\ + 00,72,00,64,00,69,00,76,00,76,00,75,00,6e,00,31,00,31,00,69,00,6e,00,73,00,\ + 74,00,61,00,6c,00,6c,00,65,00,64,00,2e,00,72,00,65,00,67,00,00,00,2a,00,00,\ + 00 +"MRUListEx"=hex:00,00,00,00,13,00,00,00,12,00,00,00,11,00,00,00,10,00,00,00,0f,\ + 00,00,00,0e,00,00,00,0d,00,00,00,0c,00,00,00,0b,00,00,00,0a,00,00,00,09,00,\ + 00,00,08,00,00,00,07,00,00,00,06,00,00,00,05,00,00,00,04,00,00,00,03,00,00,\ + 00,02,00,00,00,01,00,00,00,ff,ff,ff,ff "1"=hex:14,00,1f,58,0d,1a,2c,f0,21,be,50,43,88,b0,73,67,fc,96,ef,3c,1a,02,00,\ 00,14,02,bb,af,93,3b,06,02,04,00,00,00,00,00,3d,00,00,00,31,53,50,53,30,f1,\ 25,b7,ef,47,1a,10,a5,f1,02,60,8c,9e,eb,ac,21,00,00,00,0a,00,00,00,00,1f,00,\ @@ -1355251,7 +1356592,7 @@ 68,06,00,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,\ 80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,ff,ff,ff,ff,60,bb,8b,\ b7,85,ce,cd,01,00,00,00,00 -"HRZR_PGYFRFFVBA"=hex:00,00,00,00,d6,00,00,00,6a,02,00,00,77,66,0f,01,18,00,00,\ +"HRZR_PGYFRFFVBA"=hex:00,00,00,00,d7,00,00,00,75,02,00,00,1a,6a,10,01,18,00,00,\ 00,34,00,00,00,4a,41,0b,00,7b,00,37,00,43,00,35,00,41,00,34,00,30,00,45,00,\ 46,00,2d,00,41,00,30,00,46,00,42,00,2d,00,34,00,42,00,46,00,43,00,2d,00,38,\ 00,37,00,34,00,41,00,2d,00,43,00,30,00,46,00,32,00,45,00,30,00,42,00,39,00,\ @@ -1355273,46 +1356614,46 @@ 44,25,02,7c,e5,00,00,fd,74,05,80,2c,e5,da,01,8f,96,a2,76,7c,e5,da,01,30,e5,\ da,01,33,9a,a2,76,00,00,00,00,7c,35,2a,02,58,e5,da,01,d9,99,a2,76,7c,35,2a,\ 02,04,e6,da,01,f0,30,2a,02,ed,99,a2,76,00,00,00,00,f0,30,2a,02,04,e6,da,01,\ - 60,e5,da,01,0b,00,00,00,9e,00,00,00,e3,f3,3b,00,7b,00,46,00,33,00,38,00,42,\ + 60,e5,da,01,0b,00,00,00,a3,00,00,00,df,00,3c,00,7b,00,46,00,33,00,38,00,42,\ 00,46,00,34,00,30,00,34,00,2d,00,31,00,44,00,34,00,33,00,2d,00,34,00,32,00,\ 46,00,32,00,2d,00,39,00,33,00,30,00,35,00,2d,00,36,00,37,00,44,00,45,00,30,\ 00,42,00,32,00,38,00,46,00,43,00,32,00,33,00,7d,00,5c,00,65,00,78,00,70,00,\ - 6c,00,6f,00,72,00,65,00,72,00,2e,00,65,00,78,00,65,00,00,00,ff,ff,ff,ff,82,\ - 06,00,00,00,00,00,00,f5,00,00,00,00,00,00,00,00,00,00,00,70,59,22,75,51,bd,\ - 17,83,08,e5,0c,02,2d,71,1e,75,48,fb,2c,00,00,00,00,08,c0,e5,0c,02,ff,ff,ff,\ - ff,10,df,2e,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,34,e5,0c,02,67,71,1e,75,\ - b6,f9,07,00,00,00,00,00,c0,e5,0c,02,ff,ff,ff,ff,10,df,2e,00,ff,ff,ff,ff,70,\ - 59,22,75,00,00,00,00,00,00,00,00,5c,e5,0c,02,7a,7f,1e,75,00,04,00,00,00,00,\ - 00,00,c0,e5,0c,02,ff,ff,ff,ff,10,df,2e,00,ff,ff,ff,ff,90,c2,2e,00,30,c3,2e,\ - 00,08,df,2e,00,8c,e5,0c,02,fd,ab,cd,75,40,a0,00,76,cc,f2,0c,02,88,d9,cd,75,\ - 9b,76,ce,75,30,a9,2c,00,c0,e5,0c,02,00,00,00,00,77,00,00,00,65,5f,15,83,a0,\ - e5,0c,02,6a,77,ce,75,30,a9,2c,00,c0,e5,0c,02,00,00,00,00,cc,e7,0c,02,24,77,\ - ce,75,30,a9,2c,00,c0,e5,0c,02,00,00,04,00,00,00,00,80,31,77,ce,75,30,a9,2c,\ - 00,63,00,3a,00,5c,00,75,00,73,00,65,00,00,00,00,00,00,00,00,00,04,00,1f,02,\ - 00,00,2b,00,10,e6,0c,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,04,\ - 00,1f,02,00,00,2b,00,2c,e6,0c,02,11,00,00,00,20,d9,2c,00,18,d9,2c,00,40,92,\ - 2c,00,26,30,03,77,38,01,2b,00,84,e6,00,00,f5,5c,15,83,34,e6,0c,02,8f,96,ce,\ + 6c,00,6f,00,72,00,65,00,72,00,2e,00,65,00,78,00,65,00,00,00,65,00,78,00,65,\ + 00,00,00,0e,00,00,00,80,e5,0c,02,f0,e4,0c,02,65,16,8e,76,e8,e4,0c,02,d8,48,\ + af,02,5a,71,8a,76,80,e5,0c,02,f4,e4,0c,02,83,64,8c,76,d8,48,af,02,04,e5,0c,\ + 02,47,42,8e,76,d8,48,af,02,08,e8,0c,02,d4,e6,0c,02,75,2f,8e,76,14,e7,0c,02,\ + ec,e7,0c,02,00,00,00,00,84,2f,8e,76,4c,e8,0c,02,01,e8,0c,02,4e,3a,35,03,58,\ + 3a,35,03,4e,c6,35,03,d0,e5,0c,02,00,01,00,01,01,00,00,00,00,01,0c,02,00,00,\ + 00,00,10,a9,af,02,20,e8,0c,02,86,e0,31,03,fc,e7,0c,02,00,01,00,01,01,00,00,\ + 00,2c,e8,0c,02,4a,3a,35,03,10,00,00,00,4e,3a,35,03,01,00,00,00,ac,e7,0c,02,\ + 58,3a,35,03,00,00,00,00,0a,3a,35,03,00,00,00,00,0f,00,0f,00,b6,b0,af,02,d4,\ + 3a,35,03,10,00,00,00,0f,00,00,00,4c,e8,0c,02,14,e8,0c,02,10,a9,af,02,10,00,\ + 00,00,72,ab,af,02,da,cb,31,03,0e,00,00,00,14,e7,0c,02,30,e8,0c,02,04,e8,0c,\ + 02,4e,c6,35,03,04,00,00,00,72,ab,af,02,00,09,11,11,00,00,00,00,09,09,09,00,\ + 09,09,09,09,00,09,11,11,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,11,00,00,00,20,d9,2c,00,18,d9,2c,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,84,e6,00,00,f5,5c,15,83,34,e6,0c,02,8f,96,ce,\ 75,84,e6,0c,02,38,e6,0c,02,33,9a,ce,75,00,00,00,00,4c,37,1a,04,60,e6,0c,02,\ d9,99,ce,75,4c,37,1a,04,0c,e7,0c,02,c0,32,1a,04,ed,99,ce,75,00,00,00,00,c0,\ - 32,1a,04,0c,e7,0c,02,68,e6,0c,02,0b,00,00,00,9e,00,00,00,e3,f3,3b,00,7b,00,\ + 32,1a,04,0c,e7,0c,02,68,e6,0c,02,0b,00,00,00,a3,00,00,00,df,00,3c,00,7b,00,\ 46,00,33,00,38,00,42,00,46,00,34,00,30,00,34,00,2d,00,31,00,44,00,34,00,33,\ 00,2d,00,34,00,32,00,46,00,32,00,2d,00,39,00,33,00,30,00,35,00,2d,00,36,00,\ 37,00,44,00,45,00,30,00,42,00,32,00,38,00,46,00,43,00,32,00,33,00,7d,00,5c,\ 00,65,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,2e,00,65,00,78,00,65,00,\ - 00,00,ff,ff,ff,ff,82,06,00,00,00,00,00,00,f5,00,00,00,00,00,00,00,00,00,00,\ - 00,70,59,22,75,51,bd,17,83,08,e5,0c,02,2d,71,1e,75,48,fb,2c,00,00,00,00,08,\ - c0,e5,0c,02,ff,ff,ff,ff,10,df,2e,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,34,\ - e5,0c,02,67,71,1e,75,b6,f9,07,00,00,00,00,00,c0,e5,0c,02,ff,ff,ff,ff,10,df,\ - 2e,00,ff,ff,ff,ff,70,59,22,75,00,00,00,00,00,00,00,00,5c,e5,0c,02,7a,7f,1e,\ - 75,00,04,00,00,00,00,00,00,c0,e5,0c,02,ff,ff,ff,ff,10,df,2e,00,ff,ff,ff,ff,\ - 90,c2,2e,00,30,c3,2e,00,08,df,2e,00,8c,e5,0c,02,fd,ab,cd,75,40,a0,00,76,cc,\ - f2,0c,02,88,d9,cd,75,9b,76,ce,75,30,a9,2c,00,c0,e5,0c,02,00,00,00,00,77,00,\ - 00,00,65,5f,15,83,a0,e5,0c,02,6a,77,ce,75,30,a9,2c,00,c0,e5,0c,02,00,00,00,\ - 00,cc,e7,0c,02,24,77,ce,75,30,a9,2c,00,c0,e5,0c,02,00,00,04,00,00,00,00,80,\ - 31,77,ce,75,30,a9,2c,00,63,00,3a,00,5c,00,75,00,73,00,65,00,00,00,00,00,00,\ - 00,00,00,04,00,1f,02,00,00,2b,00,10,e6,0c,02,00,00,00,00,00,00,00,00,00,00,\ - 00,00,00,00,00,00,04,00,1f,02,00,00,2b,00,2c,e6,0c,02,11,00,00,00,20,d9,2c,\ - 00,18,d9,2c,00,40,92,2c,00,26,30,03,77,38,01,2b,00,84,e6,00,00,f5,5c,15,83,\ + 00,00,65,00,78,00,65,00,00,00,0e,00,00,00,80,e5,0c,02,f0,e4,0c,02,65,16,8e,\ + 76,e8,e4,0c,02,d8,48,af,02,5a,71,8a,76,80,e5,0c,02,f4,e4,0c,02,83,64,8c,76,\ + d8,48,af,02,04,e5,0c,02,47,42,8e,76,d8,48,af,02,08,e8,0c,02,d4,e6,0c,02,75,\ + 2f,8e,76,14,e7,0c,02,ec,e7,0c,02,00,00,00,00,84,2f,8e,76,4c,e8,0c,02,01,e8,\ + 0c,02,4e,3a,35,03,58,3a,35,03,4e,c6,35,03,d0,e5,0c,02,00,01,00,01,01,00,00,\ + 00,00,01,0c,02,00,00,00,00,10,a9,af,02,20,e8,0c,02,86,e0,31,03,fc,e7,0c,02,\ + 00,01,00,01,01,00,00,00,2c,e8,0c,02,4a,3a,35,03,10,00,00,00,4e,3a,35,03,01,\ + 00,00,00,ac,e7,0c,02,58,3a,35,03,00,00,00,00,0a,3a,35,03,00,00,00,00,0f,00,\ + 0f,00,b6,b0,af,02,d4,3a,35,03,10,00,00,00,0f,00,00,00,4c,e8,0c,02,14,e8,0c,\ + 02,10,a9,af,02,10,00,00,00,72,ab,af,02,da,cb,31,03,0e,00,00,00,14,e7,0c,02,\ + 30,e8,0c,02,04,e8,0c,02,4e,c6,35,03,04,00,00,00,72,ab,af,02,00,09,11,11,00,\ + 00,00,00,09,09,09,00,09,09,09,09,00,09,11,11,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,11,00,00,00,20,d9,2c,\ + 00,18,d9,2c,00,00,00,00,00,00,00,00,00,00,00,00,00,84,e6,00,00,f5,5c,15,83,\ 34,e6,0c,02,8f,96,ce,75,84,e6,0c,02,38,e6,0c,02,33,9a,ce,75,00,00,00,00,4c,\ 37,1a,04,60,e6,0c,02,d9,99,ce,75,4c,37,1a,04,0c,e7,0c,02,c0,32,1a,04,ed,99,\ ce,75,00,00,00,00,c0,32,1a,04,0c,e7,0c,02,68,e6,0c,02 @@ -1355361,7 +1356702,7 @@ bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,ff,ff,ff,ff,90,85,4a,26,\ 86,ce,cd,01,00,00,00,00 "{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\\rkcybere.rkr"=hex:00,00,00,00,0b,00,\ - 00,00,9e,00,00,00,e3,f3,3b,00,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,\ + 00,00,a3,00,00,00,df,00,3c,00,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,\ bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,\ ff,ff,ff,ff,a0,14,98,31,fe,d6,cd,01,00,00,00,00 "{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\\gnfxubfg.rkr"=hex:00,00,00,00,00,00,\ @@ -1355381,14 +1356722,14 @@ 00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,ff,\ ff,ff,ff,40,0f,e2,6d,8b,ce,cd,01,00,00,00,00 "{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\\ertrqvg.rkr"=hex:00,00,00,00,0a,00,00,\ - 00,3c,00,00,00,53,2e,27,00,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,\ + 00,3e,00,00,00,a7,88,27,00,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,\ 00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,ff,\ ff,ff,ff,50,f8,57,e8,2a,d7,cd,01,00,00,00,00 "{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\\ehaqyy32.rkr"=hex:00,00,00,00,03,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,\ bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,\ ff,ff,ff,ff,10,83,81,68,41,d1,cd,01,00,00,00,00 -"Zvpebfbsg.Jvaqbjf.PbagebyCnary"=hex:00,00,00,00,00,00,00,00,61,00,00,00,85,17,\ +"Zvpebfbsg.Jvaqbjf.PbagebyCnary"=hex:00,00,00,00,00,00,00,00,64,00,00,00,09,66,\ 28,00,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,\ bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,ff,ff,ff,ff,00,00,00,00,\ 00,00,00,00,00,00,00,00 @@ -1355441,7 +1356782,7 @@ bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,ff,ff,ff,ff,50,97,1c,52,40,d1,cd,01,\ 00,00,00,00 "Zvpebfbsg.Jvaqbjf.JvaqbjfVafgnyyre"=hex:00,00,00,00,00,00,00,00,02,00,00,00,\ - 13,5c,01,00,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,\ + c2,74,01,00,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,\ 00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,ff,ff,ff,ff,00,00,\ 00,00,00,00,00,00,00,00,00,00 "{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\\zfvrkrp.rkr"=hex:00,00,00,00,0c,00,00,\ @@ -1355493,9 +1356834,9 @@ 00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,\ 00,80,bf,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00 "P:\\Hfref\\32-7-jvaqbjf\\Qbjaybnqf\\QviihaVafgnyyre-20081231.rkr"=hex:00,00,\ - 00,00,03,00,00,00,03,00,00,00,e7,53,00,00,00,00,80,bf,00,00,80,bf,00,00,80,\ + 00,00,04,00,00,00,04,00,00,00,25,60,00,00,00,00,80,bf,00,00,80,bf,00,00,80,\ bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,\ - 00,00,80,bf,ff,ff,ff,ff,e0,49,d3,13,16,d2,cd,01,00,00,00,00 + 00,00,80,bf,ff,ff,ff,ff,70,64,cd,27,2b,d7,cd,01,00,00,00,00 "P:\\Hfref\\32-7-jvaqbjf\\NccQngn\\Ybpny\\Grzc\\co5Q3P\\vafgnyyreZYF.rkr"=hex:00,\ 00,00,00,00,00,00,00,01,00,00,00,13,09,00,00,00,00,80,bf,00,00,80,bf,00,00,\ 80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,\ @@ -1355536,6 +1356877,14 @@ 00,00,00,00,00,00,00,01,00,00,00,a2,1e,00,00,00,00,80,bf,00,00,80,bf,00,00,\ 80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,\ bf,00,00,80,bf,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00 +"P:\\Hfref\\32-7-jvaqbjf\\NccQngn\\Ybpny\\Grzc\\co8464\\vafgnyyreZYF.rkr"=hex:00,\ + 00,00,00,00,00,00,00,00,00,00,00,6e,09,00,00,00,00,80,bf,00,00,80,bf,00,00,\ + 80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,\ + bf,00,00,80,bf,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00 +"P:\\Hfref\\32-7-jvaqbjf\\NccQngn\\Ybpny\\Grzc\\co8464\\vafgnyyref\\frghcFnzv_Abegurea.rkr"=hex:00,\ + 00,00,00,00,00,00,00,00,00,00,00,74,1f,00,00,00,00,80,bf,00,00,80,bf,00,00,\ + 80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,\ + bf,00,00,80,bf,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00 [HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}] "Version"=dword:00000005 @@ -1357860,6 +1359209,8 @@ [HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001\Software\Microsoft\Wisp\Touch] "TouchUI"=dword:00000000 +[HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001\Software\Microsoft\RestartManager] + [HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001\Software\Netscape] [HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001\Software\Netscape\Netscape Navigator] @@ -1358191,193 +1359542,12 @@ [HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001\Software\Classes\Local Settings\MuiCache] -[HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001\Software\Classes\Local Settings\MuiCache\9F] +[HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001\Software\Classes\Local Settings\MuiCache\A1] -[HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001\Software\Classes\Local Settings\MuiCache\9F\52C64B7E] +[HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001\Software\Classes\Local Settings\MuiCache\A1\52C64B7E] "LanguageList"=hex(7):65,00,6e,00,2d,00,55,00,53,00,00,00,65,00,6e,00,00,00,00,\ 00 -"@C:\\Windows\\system32\\appwiz.cpl,-159"="Programs and Features" -"@appwiz.cpl,-165"="Uninstall" -"@appwiz.cpl,-166"="Uninstall this program." -"@appwiz.cpl,-167"="Change" -"@appwiz.cpl,-168"="Change the installation of this program." -"@appwiz.cpl,-169"="Repair" -"@appwiz.cpl,-170"="Repair the installation of this program." -"@appwiz.cpl,-171"="Uninstall/Change" -"@appwiz.cpl,-172"="Uninstall or change this program." -"@C:\\Windows\\system32\\ntshrui.dll,-103"="S&hare with" -"@C:\\Windows\\system32\\ntshrui.dll,-5112"="Share the selected items with other people on the network." -"@C:\\Windows\\System32\\msimsg.dll,-34"="Windows Installer Package" -"@C:\\Windows\\System32\\msimsg.dll,-36"="&Install" -"@C:\\Windows\\System32\\msimsg.dll,-37"="Re&pair" -"@C:\\Windows\\System32\\msimsg.dll,-38"="&Uninstall" -"@%SystemRoot%\\system32\\p2pcollab.dll,-8042"="Peer to Peer Trust" -"@%SystemRoot%\\system32\\qagentrt.dll,-10"="System Health Authentication" -"@%SystemRoot%\\system32\\dnsapi.dll,-103"="Domain Name System (DNS) Server Trust" -"@%SystemRoot%\\System32\\fveui.dll,-843"="BitLocker Drive Encryption" -"@%SystemRoot%\\System32\\fveui.dll,-844"="BitLocker Data Recovery Agent" -"@%systemroot%\\system32\\oobefldr.dll,-1102"="Go online to make setting up your computer easier and learn more about Windows 7." -"@%systemroot%\\system32\\oobefldr.dll,-1122"="Change your desktop background, window color, sounds, and screen saver." -"@%systemroot%\\system32\\oobefldr.dll,-1142"="Transfer your files and settings from another computer." -"@%systemroot%\\system32\\oobefldr.dll,-1162"="Share files and printers with other computers in your home." -"@%systemroot%\\system32\\oobefldr.dll,-1182"="Choose when you want User Account Control (UAC) to notify you about changes to your computer." -"@%systemroot%\\system32\\oobefldr.dll,-1202"="Go online to get Windows Live Essentials to communicate, share, and publish online." -"@%systemroot%\\system32\\oobefldr.dll,-1222"="Configure Windows to back up your photos, music, and other files automatically." -"@%systemroot%\\system32\\oobefldr.dll,-1242"="Create user accounts for other people who will use this computer." -"@%systemroot%\\system32\\oobefldr.dll,-1262"="Make text and other items on your screen larger or smaller." -"@C:\\Windows\\System32\\ie4uinit.exe,-731"="Internet Explorer" -"@C:\\Windows\\System32\\ie4uinit.exe,-737"="Internet Explorer (No Add-ons)" -"@\"%windir%\\System32\\ie4uinit.exe\",-738"="Start Internet Explorer without ActiveX controls or browser extensions." -"@C:\\Windows\\system32\\AccessibilityCpl.dll,-10"="Ease of Access Center" -"@C:\\Windows\\system32\\sud.dll,-1"="Default Programs" -"@C:\\Windows\\system32\\wucltux.dll,-1"="Windows Update" -"@C:\\Windows\\ehome\\ehres.dll,-100"="Windows Media Center" -"@C:\\Program Files\\Windows Sidebar\\sidebar.exe,-1005"="Desktop Gadget Gallery" -"@C:\\Program Files\\DVD Maker\\DVDMaker.exe,-61403"="Windows DVD Maker" -"@C:\\Windows\\system32\\FXSRESM.dll,-114"="Windows Fax and Scan" -"@C:\\Windows\\system32\\unregmp2.exe,-4"="Windows Media Player" -"@C:\\Windows\\system32\\XpsRchVw.exe,-102"="XPS Viewer" -"@C:\\Windows\\system32\\sdcpl.dll,-101"="Backup and Restore" -"@C:\\Windows\\system32\\recdisc.exe,-2000"="Create a System Repair Disc" -"@C:\\Windows\\system32\\msra.exe,-100"="Windows Remote Assistance" -"@C:\\Windows\\system32\\gameux.dll,-10082"="Games Explorer" -"@C:\\Windows\\system32\\comres.dll,-3410"="Component Services" -"@C:\\Windows\\system32\\mycomput.dll,-300"="Computer Management" -"@C:\\Windows\\system32\\odbcint.dll,-1310"="Data Sources (ODBC)" -"@C:\\Windows\\system32\\miguiresource.dll,-101"="Event Viewer" -"@C:\\Windows\\system32\\iscsicpl.dll,-5001"="iSCSI Initiator" -"@C:\\Windows\\system32\\MdSched.exe,-4001"="Windows Memory Diagnostic" -"@C:\\Windows\\system32\\wdc.dll,-10021"="Performance Monitor" -"@C:\\Windows\\system32\\pmcsnap.dll,-700"="Print Management" -"@C:\\Windows\\system32\\wsecedit.dll,-718"="Local Security Policy" -"@C:\\Windows\\system32\\filemgmt.dll,-2204"="Services" -"@C:\\Windows\\system32\\msconfig.exe,-126"="System Configuration" -"@C:\\Windows\\system32\\miguiresource.dll,-201"="Task Scheduler" -"@C:\\Windows\\System32\\AuthFWGP.dll,-20"="Windows Firewall with Advanced Security" -"@C:\\Windows\\system32\\displayswitch.exe,-320"="Connect to a Projector" -"@C:\\Program Files\\Common Files\\Microsoft Shared\\Ink\\mip.exe,-291"="Math Input Panel" -"@C:\\Windows\\system32\\mblctr.exe,-1008"="Windows Mobility Center" -"@C:\\Windows\\system32\\NetProjW.dll,-501"="Connect to a Network Projector" -"@C:\\Windows\\system32\\mstsc.exe,-4000"="Remote Desktop Connection" -"@C:\\Windows\\system32\\SnippingTool.exe,-15051"="Snipping Tool" -"@C:\\Windows\\system32\\SoundRecorder.exe,-100"="Sound Recorder" -"@C:\\Windows\\system32\\SNTSearch.dll,-505"="Sticky Notes" -"@C:\\Windows\\System32\\SyncCenter.dll,-3000"="Sync Center" -"@C:\\Program Files\\windows journal\\journal.exe,-62005"="Tablet PC" -"@C:\\Windows\\system32\\OobeFldr.dll,-33056"="Getting Started" -"@C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-101"="Windows PowerShell ISE" -"@C:\\Program Files\\Common Files\\Microsoft Shared\\Ink\\ShapeCollector.exe,-298"="Personalize Handwriting Recognition" -"@C:\\Program Files\\Common Files\\Microsoft Shared\\Ink\\TipTsf.dll,-80"="Tablet PC Input Panel" -"@C:\\Program Files\\Windows Journal\\Journal.exe,-3074"="Windows Journal" -"@C:\\Windows\\system32\\dfrgui.exe,-103"="Disk Defragmenter" -"@C:\\Windows\\system32\\wdc.dll,-10030"="Resource Monitor" -"@C:\\Windows\\system32\\msinfo32.exe,-100"="System Information" -"@C:\\Windows\\system32\\rstrui.exe,-100"="System Restore" -"@C:\\Windows\\system32\\migwiz\\wet.dll,-591"="Windows Easy Transfer Reports" -"@C:\\Windows\\system32\\migwiz\\wet.dll,-588"="Windows Easy Transfer" -"@C:\\Windows\\system32\\Speech\\SpeechUX\\sapi.cpl,-5555"="Windows Speech Recognition" -"@%SystemRoot%\\system32\\SNTSearch.dll,-504"="Create short handwritten or text notes." -"@%SystemRoot%\\system32\\NetProjW.dll,-511"="Display your desktop on a network projector." -"@C:\\Program Files\\Common Files\\system\\wab32res.dll,-10100"="Contacts" "@C:\\Windows\\system32\\NetworkExplorer.dll,-1"="Network" -"@C:\\Windows\\System32\\powercpl.dll,-1"="Power Options" -"@C:\\Windows\\System32\\powercpl.dll,-2"="Conserve energy or maximize performance by choosing how your computer manages power." -"@C:\\Windows\\System32\\taskbarcpl.dll,-1"="Notification Area Icons" -"@C:\\Windows\\System32\\taskbarcpl.dll,-2"="Select which icons and notifications appear in the notification area." -"@C:\\Windows\\system32\\Vault.dll,-1"="Credential Manager" -"@C:\\Windows\\system32\\Vault.dll,-2"="Manage your Windows Credentials." -"@C:\\Windows\\System32\\sud.dll,-10"="Choose which programs you want Windows to use for activities like web browsing, editing photos, sending e-mail, and playing music." -"@C:\\Windows\\System32\\tsworkspace.dll,-15300"="RemoteApp and Desktop Connections" -"@C:\\Windows\\System32\\tsworkspace.dll,-15301"="Manage your RemoteApp and Desktop Connections" -"@C:\\Windows\\system32\\wucltux.dll,-4"="Check for software and driver updates, choose automatic updating settings, or view installed updates." -"@C:\\Program Files\\Windows Sidebar\\sidebar.exe,-11003"="Desktop Gadgets" -"@C:\\Program Files\\Windows Sidebar\\sidebar.exe,-11002"="View the desktop gadgets installed on your computer." -"@C:\\Windows\\system32\\FirewallControlPanel.dll,-12122"="Windows Firewall" -"@C:\\Windows\\system32\\FirewallControlPanel.dll,-12123"="Set firewall security options to help protect your computer from hackers and malicious software." -"@C:\\Windows\\System32\\telephon.cpl,-1"="Phone and Modem" -"@C:\\Windows\\System32\\telephon.cpl,-2"="Configure your telephone dialing rules and modem settings." -"@C:\\Windows\\System32\\Speech\\SpeechUX\\speechuxcpl.dll,-1"="Speech Recognition" -"@C:\\Windows\\System32\\Speech\\SpeechUX\\speechuxcpl.dll,-2"="Configure how speech recognition works on your computer." -"@C:\\Windows\\system32\\mblctr.exe,-1002"="Windows Mobility Center" -"@C:\\Windows\\system32\\mblctr.exe,-1003"="Adjust display brightness, volume, power options, and other commonly used mobile PC settings." -"@C:\\Windows\\System32\\usercpl.dll,-1"="User Accounts" -"@C:\\Windows\\System32\\usercpl.dll,-2"="Change user account settings and passwords for people who share this computer." -"@C:\\Windows\\System32\\intl.cpl,-1"="Region and Language" -"@C:\\Windows\\System32\\intl.cpl,-2"="Customize settings for the display of languages, numbers, times, and dates." -"@C:\\Windows\\System32\\hgcpl.dll,-1"="HomeGroup" -"@C:\\Windows\\System32\\hgcpl.dll,-2"="View HomeGroup settings, choose sharing options, and view or change the password." -"@C:\\Windows\\System32\\main.cpl,-100"="Mouse" -"@C:\\Windows\\System32\\main.cpl,-101"="Customize your mouse settings, such as the button configuration, double-click speed, mouse pointers, and motion speed." -"@C:\\Windows\\System32\\main.cpl,-102"="Keyboard" -"@C:\\Windows\\System32\\main.cpl,-103"="Customize your keyboard settings, such as the cursor blink rate and the character repeat rate." -"@C:\\Windows\\System32\\devmgr.dll,-4"="Device Manager" -"@C:\\Windows\\System32\\devmgr.dll,-5"="View and update your hardware's settings and driver software." -"@C:\\Windows\\System32\\icardres.dll,-4097"="Windows CardSpace" -"@C:\\Windows\\System32\\icardres.dll,-4098"="Manage Information Cards used to log on and register with websites and online services." -"@C:\\Windows\\System32\\PerfCenterCPL.dll,-1"="Performance Information and Tools" -"@C:\\Windows\\System32\\PerfCenterCPL.dll,-2"="Get information about your computer's speed and performance. If solutions to performance problems are available, Windows lets you know." -"@C:\\Windows\\system32\\appwiz.cpl,-160"="Uninstall or change programs on your computer." -"@C:\\Windows\\System32\\srchadmin.dll,-601"="Indexing Options" -"@C:\\Windows\\System32\\srchadmin.dll,-602"="Change how Windows indexes items for faster searching" -"@C:\\Windows\\System32\\netcenter.dll,-1"="Network and Sharing Center" -"@C:\\Windows\\System32\\netcenter.dll,-2"="Check network status, change network settings and set preferences for sharing files and printers." -"@C:\\Windows\\System32\\wpccpl.dll,-100"="Parental Controls" -"@C:\\Windows\\System32\\wpccpl.dll,-101"="Change Parental Controls settings." -"@C:\\Windows\\System32\\autoplay.dll,-1"="AutoPlay" -"@C:\\Windows\\System32\\autoplay.dll,-2"="Change default settings for CDs, DVDs, and devices so that you can automatically play music, view pictures, install software, and play games." -"@C:\\Windows\\System32\\SyncCenter.dll,-3001"="Sync files between your computer and network folders" -"@C:\\Windows\\System32\\recovery.dll,-101"="Recovery" -"@C:\\Windows\\System32\\recovery.dll,-2"="Restore your system to an earlier time without affecting your files, or replace everything on your computer and reinstall Windows." -"@C:\\Windows\\System32\\inetcpl.cpl,-4312"="Internet Options" -"@C:\\Windows\\System32\\inetcpl.cpl,-4313"="Configure your Internet display and connection settings." -"@C:\\Windows\\system32\\DeviceCenter.dll,-1000"="Devices and Printers" -"@C:\\Windows\\system32\\DeviceCenter.dll,-2000"="View and manage devices, printers, and print jobs" -"@C:\\Windows\\system32\\colorcpl.exe,-6"="Color Management" -"@C:\\Windows\\system32\\colorcpl.exe,-7"="Change advanced color management settings for displays, scanners, and printers." -"@C:\\Windows\\System32\\sdcpl.dll,-100"="Backup and restore your files and system. Monitor latest backup status and configuration." -"@C:\\Windows\\System32\\systemcpl.dll,-1"="System" -"@C:\\Windows\\System32\\systemcpl.dll,-2"="View information about your computer, and change settings for hardware, performance, and remote connections." -"@C:\\Windows\\System32\\ActionCenterCPL.dll,-1"="Action Center" -"@C:\\Windows\\System32\\ActionCenterCPL.dll,-2"="Review recent messages and resolve problems with your computer." -"@C:\\Windows\\System32\\Display.dll,-1"="Display" -"@C:\\Windows\\System32\\Display.dll,-2"="Change your display settings and make it easier to read what's on your screen." -"@C:\\Windows\\System32\\DiagCpl.dll,-1"="Troubleshooting" -"@C:\\Windows\\System32\\DiagCpl.dll,-15"="Troubleshoot and fix common computer problems." -"@C:\\Windows\\system32\\OobeFldr.dll,-33057"="Learn about Windows features and start using them." -"@C:\\Windows\\System32\\accessibilitycpl.dll,-45"="Make your computer easier to use." -"@C:\\Program Files\\Windows Defender\\MsMpRes.dll,-104"="Windows Defender" -"@C:\\Program Files\\Windows Defender\\MsMpRes.dll,-1176"="Protection against spyware and potentially unwanted software" -"@C:\\Windows\\System32\\fvecpl.dll,-1"="BitLocker Drive Encryption" -"@C:\\Windows\\System32\\fvecpl.dll,-2"="Protect your computer using BitLocker Drive Encryption." -"@C:\\Windows\\System32\\timedate.cpl,-51"="Date and Time" -"@C:\\Windows\\System32\\timedate.cpl,-52"="Set the date, time, and time zone for your computer." -"@C:\\Windows\\System32\\SensorsCpl.dll,-1"="Location and Other Sensors" -"@C:\\Windows\\System32\\SensorsCpl.dll,-701"="Configure your sensor settings." -"@C:\\Windows\\System32\\themecpl.dll,-1"="Personalization" -"@C:\\Windows\\System32\\themecpl.dll,-2"="Change the pictures, colors, and sounds for this computer." -"@C:\\Windows\\System32\\mmsys.cpl,-300"="Sound" -"@C:\\Windows\\System32\\mmsys.cpl,-301"="Configure your audio devices or change the sound scheme for your computer." -"@C:\\Windows\\system32\\wmploc.dll,-128"="Microsoft Windows Media Player" -"@C:\\Windows\\system32\\themeui.dll,-2682"="Themes Setup" -"@C:\\Windows\\explorer.exe,-7021"="Help and Support" -"@C:\\Windows\\System32\\acppage.dll,-6002"="Windows Batch File" -"@C:\\Windows\\System32\\display.dll,-4"="S&creen resolution" -"@C:\\Program Files\\Windows Sidebar\\sidebar.exe,-11100"="&Gadgets" -"@C:\\Windows\\system32\\themecpl.dll,-10"="Pe&rsonalize" -"@C:\\Program Files\\Common Files\\System\\wab32res.dll,-4602"="Contact file" -"@C:\\Program Files\\Common Files\\system\\wab32res.dll,-10203"="Contact" -"@\"C:\\Program Files\\Windows Journal\\Journal.exe\",-3072"="Journal Document" -"@C:\\Windows\\system32\\notepad.exe,-469"="Text Document" -"@C:\\Windows\\system32\\zipfldr.dll,-10195"="Compressed (zipped) Folder" -"@%CommonProgramFiles%\\Microsoft Shared\\Ink\\ShapeCollector.exe,-299"="Provide writing samples to help improve the recognition of your handwriting." -"@%systemroot%\\system32\\recdisc.exe,-2001"="Creates a disc you can use to access system recovery options." -"@%windir%\\system32\\speech\\speechux\\sapi.cpl,-5556"="Dictate text and control your computer by voice." -"@%systemroot%\\system32\\sdcpl.dll,-100"="Backup and restore your files and system. Monitor latest backup status and configuration." -"@%windir%\\system32\\msra.exe,-635"="Invite a friend or technical support person to connect to your computer and help you, or offer to help someone else." -"@%SystemRoot%\\system32\\SoundRecorder.exe,-32790"="Record sound and save it on your computer." -"@%windir%\\system32\\migwiz\\wet.dll,-601"="View reports from transfers you've performed" -"@C:\\Windows\\System32\\ieframe.dll,-12385"="Favorites Bar" -"@C:\\Windows\\regedit.exe,-309"="Registration Entries" [HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001\Software\Classes\Local Settings\Software] @@ -1367932,8 +1369102,8 @@ "NodeSlots"=hex:02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,\ 02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,\ 02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02 -"MRUListEx"=hex:04,00,00,00,05,00,00,00,01,00,00,00,02,00,00,00,00,00,00,00,08,\ - 00,00,00,07,00,00,00,03,00,00,00,06,00,00,00,ff,ff,ff,ff +"MRUListEx"=hex:07,00,00,00,00,00,00,00,04,00,00,00,05,00,00,00,01,00,00,00,02,\ + 00,00,00,08,00,00,00,03,00,00,00,06,00,00,00,ff,ff,ff,ff "0"=hex:14,00,1f,50,e0,4f,d0,20,ea,3a,69,10,a2,d8,08,00,2b,30,30,9d,00,00 "1"=hex:14,00,1f,42,25,48,1e,03,94,7b,c3,4d,b1,31,e9,46,b4,4c,8d,d5,00,00 "2"=hex:14,00,1f,70,68,06,ee,26,0a,a0,d7,44,93,71,be,b0,64,c9,86,83,00,00 @@ -1368786,7 +1369956,7 @@ 00,08,00,04,00,ef,be,7e,41,b6,02,7e,41,b6,02,2a,00,00,00,a7,b8,00,00,00,00,\ 01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,42,00,61,00,63,00,6b,00,75,\ 00,70,00,00,00,16,00,00,00 -"MRUListEx"=hex:02,00,00,00,00,00,00,00,01,00,00,00,03,00,00,00,ff,ff,ff,ff +"MRUListEx"=hex:01,00,00,00,02,00,00,00,00,00,00,00,03,00,00,00,ff,ff,ff,ff "1"=hex:74,00,31,00,00,00,00,00,7d,41,92,b8,11,00,55,73,65,72,73,00,60,00,08,\ 00,04,00,ef,be,ee,3a,a3,14,7d,41,92,b8,2a,00,00,00,5a,01,00,00,00,00,01,00,\ 00,00,00,00,00,00,00,00,36,00,00,00,00,00,55,00,73,00,65,00,72,00,73,00,00,\ @@ -1371366,8 +1372536,8 @@ "WFlags"=dword:00000000 "ShowCmd"=dword:00000001 "HotKey"=dword:00000000 -"MinPos1262x891x96(1).x"=dword:ffff8300 -"MinPos1262x891x96(1).y"=dword:ffff8300 +"MinPos1262x891x96(1).x"=dword:ffffffff +"MinPos1262x891x96(1).y"=dword:ffffffff "MaxPos1262x891x96(1).x"=dword:ffffffff "MaxPos1262x891x96(1).y"=dword:ffffffff "WinPos1262x891x96(1).left"=dword:000000f1 @@ -1371656,193 +1372826,12 @@ [HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001_Classes\Local Settings\MuiCache] -[HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001_Classes\Local Settings\MuiCache\9F] +[HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001_Classes\Local Settings\MuiCache\A1] -[HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001_Classes\Local Settings\MuiCache\9F\52C64B7E] +[HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001_Classes\Local Settings\MuiCache\A1\52C64B7E] "LanguageList"=hex(7):65,00,6e,00,2d,00,55,00,53,00,00,00,65,00,6e,00,00,00,00,\ 00 -"@C:\\Windows\\system32\\appwiz.cpl,-159"="Programs and Features" -"@appwiz.cpl,-165"="Uninstall" -"@appwiz.cpl,-166"="Uninstall this program." -"@appwiz.cpl,-167"="Change" -"@appwiz.cpl,-168"="Change the installation of this program." -"@appwiz.cpl,-169"="Repair" -"@appwiz.cpl,-170"="Repair the installation of this program." -"@appwiz.cpl,-171"="Uninstall/Change" -"@appwiz.cpl,-172"="Uninstall or change this program." -"@C:\\Windows\\system32\\ntshrui.dll,-103"="S&hare with" -"@C:\\Windows\\system32\\ntshrui.dll,-5112"="Share the selected items with other people on the network." -"@C:\\Windows\\System32\\msimsg.dll,-34"="Windows Installer Package" -"@C:\\Windows\\System32\\msimsg.dll,-36"="&Install" -"@C:\\Windows\\System32\\msimsg.dll,-37"="Re&pair" -"@C:\\Windows\\System32\\msimsg.dll,-38"="&Uninstall" -"@%SystemRoot%\\system32\\p2pcollab.dll,-8042"="Peer to Peer Trust" -"@%SystemRoot%\\system32\\qagentrt.dll,-10"="System Health Authentication" -"@%SystemRoot%\\system32\\dnsapi.dll,-103"="Domain Name System (DNS) Server Trust" -"@%SystemRoot%\\System32\\fveui.dll,-843"="BitLocker Drive Encryption" -"@%SystemRoot%\\System32\\fveui.dll,-844"="BitLocker Data Recovery Agent" -"@%systemroot%\\system32\\oobefldr.dll,-1102"="Go online to make setting up your computer easier and learn more about Windows 7." -"@%systemroot%\\system32\\oobefldr.dll,-1122"="Change your desktop background, window color, sounds, and screen saver." -"@%systemroot%\\system32\\oobefldr.dll,-1142"="Transfer your files and settings from another computer." -"@%systemroot%\\system32\\oobefldr.dll,-1162"="Share files and printers with other computers in your home." -"@%systemroot%\\system32\\oobefldr.dll,-1182"="Choose when you want User Account Control (UAC) to notify you about changes to your computer." -"@%systemroot%\\system32\\oobefldr.dll,-1202"="Go online to get Windows Live Essentials to communicate, share, and publish online." -"@%systemroot%\\system32\\oobefldr.dll,-1222"="Configure Windows to back up your photos, music, and other files automatically." -"@%systemroot%\\system32\\oobefldr.dll,-1242"="Create user accounts for other people who will use this computer." -"@%systemroot%\\system32\\oobefldr.dll,-1262"="Make text and other items on your screen larger or smaller." -"@C:\\Windows\\System32\\ie4uinit.exe,-731"="Internet Explorer" -"@C:\\Windows\\System32\\ie4uinit.exe,-737"="Internet Explorer (No Add-ons)" -"@\"%windir%\\System32\\ie4uinit.exe\",-738"="Start Internet Explorer without ActiveX controls or browser extensions." -"@C:\\Windows\\system32\\AccessibilityCpl.dll,-10"="Ease of Access Center" -"@C:\\Windows\\system32\\sud.dll,-1"="Default Programs" -"@C:\\Windows\\system32\\wucltux.dll,-1"="Windows Update" -"@C:\\Windows\\ehome\\ehres.dll,-100"="Windows Media Center" -"@C:\\Program Files\\Windows Sidebar\\sidebar.exe,-1005"="Desktop Gadget Gallery" -"@C:\\Program Files\\DVD Maker\\DVDMaker.exe,-61403"="Windows DVD Maker" -"@C:\\Windows\\system32\\FXSRESM.dll,-114"="Windows Fax and Scan" -"@C:\\Windows\\system32\\unregmp2.exe,-4"="Windows Media Player" -"@C:\\Windows\\system32\\XpsRchVw.exe,-102"="XPS Viewer" -"@C:\\Windows\\system32\\sdcpl.dll,-101"="Backup and Restore" -"@C:\\Windows\\system32\\recdisc.exe,-2000"="Create a System Repair Disc" -"@C:\\Windows\\system32\\msra.exe,-100"="Windows Remote Assistance" -"@C:\\Windows\\system32\\gameux.dll,-10082"="Games Explorer" -"@C:\\Windows\\system32\\comres.dll,-3410"="Component Services" -"@C:\\Windows\\system32\\mycomput.dll,-300"="Computer Management" -"@C:\\Windows\\system32\\odbcint.dll,-1310"="Data Sources (ODBC)" -"@C:\\Windows\\system32\\miguiresource.dll,-101"="Event Viewer" -"@C:\\Windows\\system32\\iscsicpl.dll,-5001"="iSCSI Initiator" -"@C:\\Windows\\system32\\MdSched.exe,-4001"="Windows Memory Diagnostic" -"@C:\\Windows\\system32\\wdc.dll,-10021"="Performance Monitor" -"@C:\\Windows\\system32\\pmcsnap.dll,-700"="Print Management" -"@C:\\Windows\\system32\\wsecedit.dll,-718"="Local Security Policy" -"@C:\\Windows\\system32\\filemgmt.dll,-2204"="Services" -"@C:\\Windows\\system32\\msconfig.exe,-126"="System Configuration" -"@C:\\Windows\\system32\\miguiresource.dll,-201"="Task Scheduler" -"@C:\\Windows\\System32\\AuthFWGP.dll,-20"="Windows Firewall with Advanced Security" -"@C:\\Windows\\system32\\displayswitch.exe,-320"="Connect to a Projector" -"@C:\\Program Files\\Common Files\\Microsoft Shared\\Ink\\mip.exe,-291"="Math Input Panel" -"@C:\\Windows\\system32\\mblctr.exe,-1008"="Windows Mobility Center" -"@C:\\Windows\\system32\\NetProjW.dll,-501"="Connect to a Network Projector" -"@C:\\Windows\\system32\\mstsc.exe,-4000"="Remote Desktop Connection" -"@C:\\Windows\\system32\\SnippingTool.exe,-15051"="Snipping Tool" -"@C:\\Windows\\system32\\SoundRecorder.exe,-100"="Sound Recorder" -"@C:\\Windows\\system32\\SNTSearch.dll,-505"="Sticky Notes" -"@C:\\Windows\\System32\\SyncCenter.dll,-3000"="Sync Center" -"@C:\\Program Files\\windows journal\\journal.exe,-62005"="Tablet PC" -"@C:\\Windows\\system32\\OobeFldr.dll,-33056"="Getting Started" -"@C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-101"="Windows PowerShell ISE" -"@C:\\Program Files\\Common Files\\Microsoft Shared\\Ink\\ShapeCollector.exe,-298"="Personalize Handwriting Recognition" -"@C:\\Program Files\\Common Files\\Microsoft Shared\\Ink\\TipTsf.dll,-80"="Tablet PC Input Panel" -"@C:\\Program Files\\Windows Journal\\Journal.exe,-3074"="Windows Journal" -"@C:\\Windows\\system32\\dfrgui.exe,-103"="Disk Defragmenter" -"@C:\\Windows\\system32\\wdc.dll,-10030"="Resource Monitor" -"@C:\\Windows\\system32\\msinfo32.exe,-100"="System Information" -"@C:\\Windows\\system32\\rstrui.exe,-100"="System Restore" -"@C:\\Windows\\system32\\migwiz\\wet.dll,-591"="Windows Easy Transfer Reports" -"@C:\\Windows\\system32\\migwiz\\wet.dll,-588"="Windows Easy Transfer" -"@C:\\Windows\\system32\\Speech\\SpeechUX\\sapi.cpl,-5555"="Windows Speech Recognition" -"@%SystemRoot%\\system32\\SNTSearch.dll,-504"="Create short handwritten or text notes." -"@%SystemRoot%\\system32\\NetProjW.dll,-511"="Display your desktop on a network projector." -"@C:\\Program Files\\Common Files\\system\\wab32res.dll,-10100"="Contacts" "@C:\\Windows\\system32\\NetworkExplorer.dll,-1"="Network" -"@C:\\Windows\\System32\\powercpl.dll,-1"="Power Options" -"@C:\\Windows\\System32\\powercpl.dll,-2"="Conserve energy or maximize performance by choosing how your computer manages power." -"@C:\\Windows\\System32\\taskbarcpl.dll,-1"="Notification Area Icons" -"@C:\\Windows\\System32\\taskbarcpl.dll,-2"="Select which icons and notifications appear in the notification area." -"@C:\\Windows\\system32\\Vault.dll,-1"="Credential Manager" -"@C:\\Windows\\system32\\Vault.dll,-2"="Manage your Windows Credentials." -"@C:\\Windows\\System32\\sud.dll,-10"="Choose which programs you want Windows to use for activities like web browsing, editing photos, sending e-mail, and playing music." -"@C:\\Windows\\System32\\tsworkspace.dll,-15300"="RemoteApp and Desktop Connections" -"@C:\\Windows\\System32\\tsworkspace.dll,-15301"="Manage your RemoteApp and Desktop Connections" -"@C:\\Windows\\system32\\wucltux.dll,-4"="Check for software and driver updates, choose automatic updating settings, or view installed updates." -"@C:\\Program Files\\Windows Sidebar\\sidebar.exe,-11003"="Desktop Gadgets" -"@C:\\Program Files\\Windows Sidebar\\sidebar.exe,-11002"="View the desktop gadgets installed on your computer." -"@C:\\Windows\\system32\\FirewallControlPanel.dll,-12122"="Windows Firewall" -"@C:\\Windows\\system32\\FirewallControlPanel.dll,-12123"="Set firewall security options to help protect your computer from hackers and malicious software." -"@C:\\Windows\\System32\\telephon.cpl,-1"="Phone and Modem" -"@C:\\Windows\\System32\\telephon.cpl,-2"="Configure your telephone dialing rules and modem settings." -"@C:\\Windows\\System32\\Speech\\SpeechUX\\speechuxcpl.dll,-1"="Speech Recognition" -"@C:\\Windows\\System32\\Speech\\SpeechUX\\speechuxcpl.dll,-2"="Configure how speech recognition works on your computer." -"@C:\\Windows\\system32\\mblctr.exe,-1002"="Windows Mobility Center" -"@C:\\Windows\\system32\\mblctr.exe,-1003"="Adjust display brightness, volume, power options, and other commonly used mobile PC settings." -"@C:\\Windows\\System32\\usercpl.dll,-1"="User Accounts" -"@C:\\Windows\\System32\\usercpl.dll,-2"="Change user account settings and passwords for people who share this computer." -"@C:\\Windows\\System32\\intl.cpl,-1"="Region and Language" -"@C:\\Windows\\System32\\intl.cpl,-2"="Customize settings for the display of languages, numbers, times, and dates." -"@C:\\Windows\\System32\\hgcpl.dll,-1"="HomeGroup" -"@C:\\Windows\\System32\\hgcpl.dll,-2"="View HomeGroup settings, choose sharing options, and view or change the password." -"@C:\\Windows\\System32\\main.cpl,-100"="Mouse" -"@C:\\Windows\\System32\\main.cpl,-101"="Customize your mouse settings, such as the button configuration, double-click speed, mouse pointers, and motion speed." -"@C:\\Windows\\System32\\main.cpl,-102"="Keyboard" -"@C:\\Windows\\System32\\main.cpl,-103"="Customize your keyboard settings, such as the cursor blink rate and the character repeat rate." -"@C:\\Windows\\System32\\devmgr.dll,-4"="Device Manager" -"@C:\\Windows\\System32\\devmgr.dll,-5"="View and update your hardware's settings and driver software." -"@C:\\Windows\\System32\\icardres.dll,-4097"="Windows CardSpace" -"@C:\\Windows\\System32\\icardres.dll,-4098"="Manage Information Cards used to log on and register with websites and online services." -"@C:\\Windows\\System32\\PerfCenterCPL.dll,-1"="Performance Information and Tools" -"@C:\\Windows\\System32\\PerfCenterCPL.dll,-2"="Get information about your computer's speed and performance. If solutions to performance problems are available, Windows lets you know." -"@C:\\Windows\\system32\\appwiz.cpl,-160"="Uninstall or change programs on your computer." -"@C:\\Windows\\System32\\srchadmin.dll,-601"="Indexing Options" -"@C:\\Windows\\System32\\srchadmin.dll,-602"="Change how Windows indexes items for faster searching" -"@C:\\Windows\\System32\\netcenter.dll,-1"="Network and Sharing Center" -"@C:\\Windows\\System32\\netcenter.dll,-2"="Check network status, change network settings and set preferences for sharing files and printers." -"@C:\\Windows\\System32\\wpccpl.dll,-100"="Parental Controls" -"@C:\\Windows\\System32\\wpccpl.dll,-101"="Change Parental Controls settings." -"@C:\\Windows\\System32\\autoplay.dll,-1"="AutoPlay" -"@C:\\Windows\\System32\\autoplay.dll,-2"="Change default settings for CDs, DVDs, and devices so that you can automatically play music, view pictures, install software, and play games." -"@C:\\Windows\\System32\\SyncCenter.dll,-3001"="Sync files between your computer and network folders" -"@C:\\Windows\\System32\\recovery.dll,-101"="Recovery" -"@C:\\Windows\\System32\\recovery.dll,-2"="Restore your system to an earlier time without affecting your files, or replace everything on your computer and reinstall Windows." -"@C:\\Windows\\System32\\inetcpl.cpl,-4312"="Internet Options" -"@C:\\Windows\\System32\\inetcpl.cpl,-4313"="Configure your Internet display and connection settings." -"@C:\\Windows\\system32\\DeviceCenter.dll,-1000"="Devices and Printers" -"@C:\\Windows\\system32\\DeviceCenter.dll,-2000"="View and manage devices, printers, and print jobs" -"@C:\\Windows\\system32\\colorcpl.exe,-6"="Color Management" -"@C:\\Windows\\system32\\colorcpl.exe,-7"="Change advanced color management settings for displays, scanners, and printers." -"@C:\\Windows\\System32\\sdcpl.dll,-100"="Backup and restore your files and system. Monitor latest backup status and configuration." -"@C:\\Windows\\System32\\systemcpl.dll,-1"="System" -"@C:\\Windows\\System32\\systemcpl.dll,-2"="View information about your computer, and change settings for hardware, performance, and remote connections." -"@C:\\Windows\\System32\\ActionCenterCPL.dll,-1"="Action Center" -"@C:\\Windows\\System32\\ActionCenterCPL.dll,-2"="Review recent messages and resolve problems with your computer." -"@C:\\Windows\\System32\\Display.dll,-1"="Display" -"@C:\\Windows\\System32\\Display.dll,-2"="Change your display settings and make it easier to read what's on your screen." -"@C:\\Windows\\System32\\DiagCpl.dll,-1"="Troubleshooting" -"@C:\\Windows\\System32\\DiagCpl.dll,-15"="Troubleshoot and fix common computer problems." -"@C:\\Windows\\system32\\OobeFldr.dll,-33057"="Learn about Windows features and start using them." -"@C:\\Windows\\System32\\accessibilitycpl.dll,-45"="Make your computer easier to use." -"@C:\\Program Files\\Windows Defender\\MsMpRes.dll,-104"="Windows Defender" -"@C:\\Program Files\\Windows Defender\\MsMpRes.dll,-1176"="Protection against spyware and potentially unwanted software" -"@C:\\Windows\\System32\\fvecpl.dll,-1"="BitLocker Drive Encryption" -"@C:\\Windows\\System32\\fvecpl.dll,-2"="Protect your computer using BitLocker Drive Encryption." -"@C:\\Windows\\System32\\timedate.cpl,-51"="Date and Time" -"@C:\\Windows\\System32\\timedate.cpl,-52"="Set the date, time, and time zone for your computer." -"@C:\\Windows\\System32\\SensorsCpl.dll,-1"="Location and Other Sensors" -"@C:\\Windows\\System32\\SensorsCpl.dll,-701"="Configure your sensor settings." -"@C:\\Windows\\System32\\themecpl.dll,-1"="Personalization" -"@C:\\Windows\\System32\\themecpl.dll,-2"="Change the pictures, colors, and sounds for this computer." -"@C:\\Windows\\System32\\mmsys.cpl,-300"="Sound" -"@C:\\Windows\\System32\\mmsys.cpl,-301"="Configure your audio devices or change the sound scheme for your computer." -"@C:\\Windows\\system32\\wmploc.dll,-128"="Microsoft Windows Media Player" -"@C:\\Windows\\system32\\themeui.dll,-2682"="Themes Setup" -"@C:\\Windows\\explorer.exe,-7021"="Help and Support" -"@C:\\Windows\\System32\\acppage.dll,-6002"="Windows Batch File" -"@C:\\Windows\\System32\\display.dll,-4"="S&creen resolution" -"@C:\\Program Files\\Windows Sidebar\\sidebar.exe,-11100"="&Gadgets" -"@C:\\Windows\\system32\\themecpl.dll,-10"="Pe&rsonalize" -"@C:\\Program Files\\Common Files\\System\\wab32res.dll,-4602"="Contact file" -"@C:\\Program Files\\Common Files\\system\\wab32res.dll,-10203"="Contact" -"@\"C:\\Program Files\\Windows Journal\\Journal.exe\",-3072"="Journal Document" -"@C:\\Windows\\system32\\notepad.exe,-469"="Text Document" -"@C:\\Windows\\system32\\zipfldr.dll,-10195"="Compressed (zipped) Folder" -"@%CommonProgramFiles%\\Microsoft Shared\\Ink\\ShapeCollector.exe,-299"="Provide writing samples to help improve the recognition of your handwriting." -"@%systemroot%\\system32\\recdisc.exe,-2001"="Creates a disc you can use to access system recovery options." -"@%windir%\\system32\\speech\\speechux\\sapi.cpl,-5556"="Dictate text and control your computer by voice." -"@%systemroot%\\system32\\sdcpl.dll,-100"="Backup and restore your files and system. Monitor latest backup status and configuration." -"@%windir%\\system32\\msra.exe,-635"="Invite a friend or technical support person to connect to your computer and help you, or offer to help someone else." -"@%SystemRoot%\\system32\\SoundRecorder.exe,-32790"="Record sound and save it on your computer." -"@%windir%\\system32\\migwiz\\wet.dll,-601"="View reports from transfers you've performed" -"@C:\\Windows\\System32\\ieframe.dll,-12385"="Favorites Bar" -"@C:\\Windows\\regedit.exe,-309"="Registration Entries" [HKEY_USERS\S-1-5-21-3898710555-553147626-2072628306-1001_Classes\Local Settings\Software] @@ -1381397,8 +1382386,8 @@ "NodeSlots"=hex:02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,\ 02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,\ 02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02,02 -"MRUListEx"=hex:04,00,00,00,05,00,00,00,01,00,00,00,02,00,00,00,00,00,00,00,08,\ - 00,00,00,07,00,00,00,03,00,00,00,06,00,00,00,ff,ff,ff,ff +"MRUListEx"=hex:07,00,00,00,00,00,00,00,04,00,00,00,05,00,00,00,01,00,00,00,02,\ + 00,00,00,08,00,00,00,03,00,00,00,06,00,00,00,ff,ff,ff,ff "0"=hex:14,00,1f,50,e0,4f,d0,20,ea,3a,69,10,a2,d8,08,00,2b,30,30,9d,00,00 "1"=hex:14,00,1f,42,25,48,1e,03,94,7b,c3,4d,b1,31,e9,46,b4,4c,8d,d5,00,00 "2"=hex:14,00,1f,70,68,06,ee,26,0a,a0,d7,44,93,71,be,b0,64,c9,86,83,00,00 @@ -1382251,7 +1383240,7 @@ 00,08,00,04,00,ef,be,7e,41,b6,02,7e,41,b6,02,2a,00,00,00,a7,b8,00,00,00,00,\ 01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,42,00,61,00,63,00,6b,00,75,\ 00,70,00,00,00,16,00,00,00 -"MRUListEx"=hex:02,00,00,00,00,00,00,00,01,00,00,00,03,00,00,00,ff,ff,ff,ff +"MRUListEx"=hex:01,00,00,00,02,00,00,00,00,00,00,00,03,00,00,00,ff,ff,ff,ff "1"=hex:74,00,31,00,00,00,00,00,7d,41,92,b8,11,00,55,73,65,72,73,00,60,00,08,\ 00,04,00,ef,be,ee,3a,a3,14,7d,41,92,b8,2a,00,00,00,5a,01,00,00,00,00,01,00,\ 00,00,00,00,00,00,00,00,36,00,00,00,00,00,55,00,73,00,65,00,72,00,73,00,00,\ @@ -1384831,8 +1385820,8 @@ "WFlags"=dword:00000000 "ShowCmd"=dword:00000001 "HotKey"=dword:00000000 -"MinPos1262x891x96(1).x"=dword:ffff8300 -"MinPos1262x891x96(1).y"=dword:ffff8300 +"MinPos1262x891x96(1).x"=dword:ffffffff +"MinPos1262x891x96(1).y"=dword:ffffffff "MaxPos1262x891x96(1).x"=dword:ffffffff "MaxPos1262x891x96(1).y"=dword:ffffffff "WinPos1262x891x96(1).left"=dword:000000f1 @@ -1385463,265 +1386452,7 @@ [HKEY_USERS\S-1-5-18\Software\Classes\Local Settings\MuiCache] -[HKEY_USERS\S-1-5-18\Software\Classes\Local Settings\MuiCache\9F] - -[HKEY_USERS\S-1-5-18\Software\Classes\Local Settings\MuiCache\9F\52C64B7E] -"LanguageList"=hex(7):65,00,6e,00,2d,00,55,00,53,00,00,00,65,00,6e,00,00,00,00,\ - 00 -"@%SystemRoot%\\system32\\aelupsvc.dll,-1"="Application Experience" -"@%systemroot%\\system32\\drivers\\afd.sys,-1000"="Ancillary Function Driver for Winsock" -"@%SystemRoot%\\system32\\Alg.exe,-112"="Application Layer Gateway Service" -"@%systemroot%\\system32\\appidsvc.dll,-102"="AppID Driver" -"@%systemroot%\\system32\\appidsvc.dll,-100"="Application Identity" -"@%systemroot%\\system32\\appinfo.dll,-100"="Application Information" -"@appmgmts.dll,-3250"="Application Management" -"@%systemroot%\\system32\\rascfg.dll,-32000"="RAS Asynchronous Media Driver" -"@%SystemRoot%\\system32\\audiosrv.dll,-204"="Windows Audio Endpoint Builder" -"@%SystemRoot%\\system32\\audiosrv.dll,-200"="Windows Audio" -"@%SystemRoot%\\system32\\AxInstSV.dll,-103"="ActiveX Installer (AxInstSV)" -"@%SystemRoot%\\system32\\bdesvc.dll,-100"="BitLocker Drive Encryption Service" -"@%SystemRoot%\\system32\\bfe.dll,-1001"="Base Filtering Engine" -"@%SystemRoot%\\system32\\qmgr.dll,-1000"="Background Intelligent Transfer Service" -"@%systemroot%\\system32\\browser.dll,-102"="Browser Support Driver" -"@%systemroot%\\system32\\browser.dll,-100"="Computer Browser" -"@%SystemRoot%\\System32\\bthserv.dll,-101"="Bluetooth Support Service" -"@%SystemRoot%\\System32\\certprop.dll,-11"="Certificate Propagation" -"@%SystemRoot%\\system32\\clfs.sys,-100"="Common Log (CLFS)" -"@comres.dll,-947"="COM+ System Application" -"@%SystemRoot%\\system32\\cryptsvc.dll,-1001"="Cryptographic Services" -"@%systemroot%\\system32\\cscsvc.dll,-202"="Offline Files Driver" -"@%systemroot%\\system32\\cscsvc.dll,-200"="Offline Files" -"@oleres.dll,-5012"="DCOM Server Process Launcher" -"@%SystemRoot%\\system32\\defragsvc.dll,-101"="Disk Defragmenter" -"@%systemroot%\\system32\\drivers\\dfsc.sys,-101"="DFS Namespace Client Driver" -"@%SystemRoot%\\system32\\dhcpcore.dll,-100"="DHCP Client" -"@%systemroot%\\system32\\drivers\\discache.sys,-102"="System Attribute Cache" -"@%SystemRoot%\\System32\\dnsapi.dll,-101"="DNS Client" -"@%systemroot%\\system32\\dot3svc.dll,-1102"="Wired AutoConfig" -"@%systemroot%\\system32\\dps.dll,-500"="Diagnostic Policy Service" -"@%systemroot%\\system32\\eapsvc.dll,-1"="Extensible Authentication Protocol" -"@%SystemRoot%\\system32\\efssvc.dll,-100"="Encrypting File System (EFS)" -"@%SystemRoot%\\ehome\\ehrecvr.exe,-101"="Windows Media Center Receiver Service" -"@%SystemRoot%\\ehome\\ehsched.exe,-101"="Windows Media Center Scheduler Service" -"@%SystemRoot%\\system32\\wevtsvc.dll,-200"="Windows Event Log" -"@comres.dll,-2450"="COM+ Event System" -"@%systemroot%\\system32\\fxsresm.dll,-118"="Fax" -"@%systemroot%\\system32\\fdPHost.dll,-100"="Function Discovery Provider Host" -"@%systemroot%\\system32\\fdrespub.dll,-100"="Function Discovery Resource Publication" -"@%SystemRoot%\\system32\\drivers\\fileinfo.sys,-100"="File Information FS MiniFilter" -"@%SystemRoot%\\system32\\drivers\\filetrace.sys,-10001"="FileTrace" -"@%SystemRoot%\\system32\\drivers\\fltmgr.sys,-10001"="FltMgr" -"@%systemroot%\\system32\\FntCache.dll,-100"="Windows Font Cache Service" -"@%SystemRoot%\\system32\\PresentationHost.exe,-3309"="Windows Presentation Foundation Font Cache 3.0.0.0" -"@%SystemRoot%\\system32\\drivers\\fsdepends.sys,-10001"="File System Dependency Minifilter" -"@%SystemRoot%\\system32\\drivers\\fvevol.sys,-100"="Bitlocker Drive Encryption Filter Driver" -"@gpapi.dll,-112"="Group Policy Client" -"@%SystemRoot%\\System32\\hidserv.dll,-101"="Human Interface Device Access" -"@%SystemRoot%\\system32\\kmsvc.dll,-6"="Health Key and Certificate Management" -"@%SystemRoot%\\System32\\ListSvc.dll,-100"="HomeGroup Listener" -"@%SystemRoot%\\System32\\provsvc.dll,-100"="HomeGroup Provider" -"@%SystemRoot%\\system32\\drivers\\http.sys,-1"="HTTP" -"@%systemroot%\\system32\\drivers\\hwpolicy.sys,-101"="Hardware Policy Driver" -"@%systemroot%\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\ServiceModelInstallRC.dll,-8193"="Windows CardSpace" -"@%SystemRoot%\\system32\\ikeext.dll,-501"="IKE and AuthIP IPsec Keying Modules" -"@%systemroot%\\system32\\IPBusEnum.dll,-102"="PnP-X IP Bus Enumerator" -"@%systemroot%\\system32\\rascfg.dll,-32013"="IP Traffic Filter Driver" -"@%SystemRoot%\\system32\\iphlpsvc.dll,-500"="IP Helper" -"@%SystemRoot%\\system32\\drivers\\irenum.sys,-100"="IR Bus Enumerator" -"@keyiso.dll,-100"="CNG Key Isolation" -"@comres.dll,-2946"="KtmRm for Distributed Transaction Coordinator" -"@%systemroot%\\system32\\srvsvc.dll,-100"="Server" -"@%systemroot%\\system32\\wkssvc.dll,-100"="Workstation" -"@%SystemRoot%\\system32\\lltdres.dll,-1"="Link-Layer Topology Discovery Mapper" -"@%SystemRoot%\\system32\\lmhsvc.dll,-101"="TCP/IP NetBIOS Helper" -"@%systemroot%\\system32\\drivers\\luafv.sys,-100"="UAC File Virtualization" -"@%SystemRoot%\\ehome\\ehres.dll,-15501"="Media Center Extender Service" -"@%systemroot%\\system32\\mmcss.dll,-100"="Multimedia Class Scheduler" -"@%SystemRoot%\\system32\\drivers\\mountmgr.sys,-100"="Mount Point Manager" -"@%SystemRoot%\\system32\\FirewallAPI.dll,-23092"="Windows Firewall Authorization Driver" -"@%SystemRoot%\\system32\\FirewallAPI.dll,-23090"="Windows Firewall" -"@%systemroot%\\system32\\webclnt.dll,-104"="WebDav Client Redirector Driver" -"@%systemroot%\\system32\\wkssvc.dll,-1002"="SMB MiniRedirector Wrapper and Engine" -"@%systemroot%\\system32\\wkssvc.dll,-1004"="SMB 1.x MiniRedirector" -"@%systemroot%\\system32\\wkssvc.dll,-1006"="SMB 2.0 MiniRedirector" -"@comres.dll,-2797"="Distributed Transaction Coordinator" -"@%SystemRoot%\\system32\\drivers\\mshidkmdf.sys,-100"="Pass-through HID to KMDF Filter Driver" -"@%SystemRoot%\\system32\\iscsidsc.dll,-5000"="Microsoft iSCSI Initiator Service" -"@%SystemRoot%\\system32\\msimsg.dll,-27"="Windows Installer" -"@%systemroot%\\system32\\drivers\\mup.sys,-101"="MUP" -"@%SystemRoot%\\system32\\qagentrt.dll,-6"="Network Access Protection Agent" -"@%SystemRoot%\\system32\\drivers\\ndis.sys,-200"="NDIS System Driver" -"@%systemroot%\\system32\\rascfg.dll,-32001"="Remote Access NDIS TAPI Driver" -"@%systemroot%\\system32\\rascfg.dll,-32002"="Remote Access NDIS WAN Driver" -"@%SystemRoot%\\system32\\drivers\\netbt.sys,-2"="NETBT" -"@%SystemRoot%\\System32\\netlogon.dll,-102"="Netlogon" -"@%SystemRoot%\\system32\\netman.dll,-109"="Network Connections" -"@C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\\\ServiceModelInstallRC.dll,-8195"="Net.Msmq Listener Adapter" -"@C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\\\ServiceModelInstallRC.dll,-8197"="Net.Pipe Listener Adapter" -"@%SystemRoot%\\system32\\netprofm.dll,-202"="Network List Service" -"@C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\\\ServiceModelInstallRC.dll,-8199"="Net.Tcp Listener Adapter" -"@C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\\\ServiceModelInstallRC.dll,-8201"="Net.Tcp Port Sharing Service" -"@%SystemRoot%\\System32\\nlasvc.dll,-1"="Network Location Awareness" -"@%SystemRoot%\\system32\\nsisvc.dll,-200"="Network Store Interface Service" -"@%SystemRoot%\\system32\\drivers\\nsiproxy.sys,-2"="NSI proxy service driver." -"@%SystemRoot%\\system32\\pnrpsvc.dll,-8004"="Peer Networking Identity Manager" -"@%SystemRoot%\\system32\\p2psvc.dll,-8006"="Peer Networking Grouping" -"@%SystemRoot%\\system32\\drivers\\partmgr.sys,-100"="Partition Manager" -"@%SystemRoot%\\system32\\pcasvc.dll,-1"="Program Compatibility Assistant Service" -"@%SystemRoot%\\system32\\peerdistsvc.dll,-9000"="BranchCache" -"@%systemroot%\\system32\\pla.dll,-500"="Performance Logs & Alerts" -"@%SystemRoot%\\system32\\umpnpmgr.dll,-100"="Plug and Play" -"@%SystemRoot%\\system32\\pnrpauto.dll,-8002"="PNRP Machine Name Publication Service" -"@%SystemRoot%\\system32\\pnrpsvc.dll,-8000"="Peer Name Resolution Protocol" -"@%SystemRoot%\\System32\\polstore.dll,-5010"="IPsec Policy Agent" -"@%SystemRoot%\\system32\\umpo.dll,-100"="Power" -"@%systemroot%\\system32\\rascfg.dll,-32006"="WAN Miniport (PPTP)" -"@%systemroot%\\system32\\profsvc.dll,-300"="User Profile Service" -"@%systemroot%\\system32\\psbase.dll,-300"="Protected Storage" -"@%SystemRoot%\\System32\\drivers\\pacer.sys,-101"="QoS Packet Scheduler" -"@%SystemRoot%\\system32\\qwave.dll,-1"="Quality Windows Audio Video Experience" -"@%SystemRoot%\\system32\\drivers\\qwavedrv.sys,-1"="QWAVE driver" -"@%Systemroot%\\system32\\rasauto.dll,-200"="Remote Access Auto Connection Manager" -"@%systemroot%\\system32\\rascfg.dll,-32005"="WAN Miniport (L2TP)" -"@%Systemroot%\\system32\\rasmans.dll,-200"="Remote Access Connection Manager" -"@%systemroot%\\system32\\rascfg.dll,-32007"="Remote Access PPPOE Driver" -"@%systemroot%\\system32\\sstpsvc.dll,-202"="WAN Miniport (SSTP)" -"@%systemroot%\\system32\\wkssvc.dll,-1000"="Redirected Buffering Sub Sysytem" -"@%systemroot%\\system32\\DRIVERS\\RDPCDD.sys,-100"="RDPCDD" -"@%systemroot%\\system32\\drivers\\RDPENCDD.sys,-101"="RDP Encoder Mirror Driver" -"@%systemroot%\\system32\\drivers\\RdpRefMp.sys,-101"="Reflector Display Driver used to gain access to graphics data" -"@%Systemroot%\\system32\\mprdim.dll,-200"="Routing and Remote Access" -"@regsvc.dll,-1"="Remote Registry" -"@%windir%\\system32\\RpcEpMap.dll,-1001"="RPC Endpoint Mapper" -"@%systemroot%\\system32\\Locator.exe,-2"="Remote Procedure Call (RPC) Locator" -"@oleres.dll,-5010"="Remote Procedure Call (RPC)" -"@%SystemRoot%\\system32\\samsrv.dll,-1"="Security Accounts Manager" -"@%SystemRoot%\\System32\\SCardSvr.dll,-1"="Smart Card" -"@%SystemRoot%\\System32\\drivers\\scfilter.sys,-11"="Smart card PnP Class Filter Driver" -"@%SystemRoot%\\system32\\schedsvc.dll,-100"="Task Scheduler" -"@%SystemRoot%\\System32\\certprop.dll,-13"="Smart Card Removal Policy" -"@%SystemRoot%\\system32\\sdrsvc.dll,-107"="Windows Backup" -"@%SystemRoot%\\system32\\seclogon.dll,-7001"="Secondary Logon" -"@%SystemRoot%\\system32\\Sens.dll,-200"="System Event Notification Service" -"@%SystemRoot%\\System32\\sensrsvc.dll,-1000"="Adaptive Brightness" -"@%SystemRoot%\\System32\\SessEnv.dll,-1026"="Remote Desktop Configuration" -"@%SystemRoot%\\system32\\ipnathlp.dll,-106"="Internet Connection Sharing (ICS)" -"@%SystemRoot%\\System32\\shsvcs.dll,-12288"="Shell Hardware Detection" -"@%SystemRoot%\\system32\\tcpipcfg.dll,-50005"="Message-oriented TCP/IP and TCP/IPv6 Protocol (SMB session)" -"@%SystemRoot%\\system32\\snmptrap.exe,-3"="SNMP Trap" -"@%systemroot%\\system32\\spoolsv.exe,-1"="Print Spooler" -"@%SystemRoot%\\system32\\sppsvc.exe,-101"="Software Protection" -"@%SystemRoot%\\system32\\sppuinotify.dll,-103"="SPP Notification Service" -"@%systemroot%\\system32\\srvsvc.dll,-102"="Server SMB 1.xxx Driver" -"@%systemroot%\\system32\\srvsvc.dll,-104"="Server SMB 2.xxx Driver" -"@%systemroot%\\system32\\ssdpsrv.dll,-100"="SSDP Discovery" -"@%SystemRoot%\\system32\\sstpsvc.dll,-200"="Secure Socket Tunneling Protocol Service" -"@%SystemRoot%\\system32\\wiaservc.dll,-9"="Windows Image Acquisition (WIA)" -"@%SystemRoot%\\system32\\vmstorfltres.dll,-1000"="Disk Virtual Machine Bus Acceleration Filter Driver" -"@%SystemRoot%\\System32\\StorSvc.dll,-100"="Storage Service" -"@%SystemRoot%\\System32\\swprv.dll,-103"="Microsoft Software Shadow Copy Provider" -"@%SystemRoot%\\system32\\sysmain.dll,-1000"="Superfetch" -"@%SystemRoot%\\system32\\TabSvc.dll,-100"="Tablet PC Input Service" -"@%SystemRoot%\\system32\\tapisrv.dll,-10100"="Telephony" -"@%SystemRoot%\\system32\\tbssvc.dll,-100"="TPM Base Services" -"@%SystemRoot%\\system32\\tcpipcfg.dll,-50003"="TCP/IP Protocol Driver" -"@%SystemRoot%\\system32\\tcpipcfg.dll,-50004"="NetIO Legacy TDI Support Driver" -"@%SystemRoot%\\System32\\termsrv.dll,-268"="Remote Desktop Services" -"@%SystemRoot%\\System32\\themeservice.dll,-8192"="Themes" -"@%systemroot%\\system32\\mmcss.dll,-102"="Thread Ordering Server" -"@%SystemRoot%\\system32\\trkwks.dll,-1"="Distributed Link Tracking Client" -"@%SystemRoot%\\servicing\\TrustedInstaller.exe,-100"="Windows Modules Installer" -"@%SystemRoot%\\System32\\DRIVERS\\tssecsrv.sys,-101"="Remote Desktop Services Security Filter Driver" -"@%SystemRoot%\\system32\\ui0detect.exe,-101"="Interactive Services Detection" -"@%SystemRoot%\\system32\\umrdp.dll,-1000"="Remote Desktop Services UserMode Port Redirector" -"@%systemroot%\\system32\\upnphost.dll,-213"="UPnP Device Host" -"@%SystemRoot%\\system32\\dwm.exe,-2000"="Desktop Window Manager Session Manager" -"@%SystemRoot%\\system32\\vaultsvc.dll,-1003"="Credential Manager" -"@%SystemRoot%\\system32\\vds.exe,-100"="Virtual Disk" -"@%SystemRoot%\\system32\\vmbusres.dll,-1000"="Virtual Machine Bus" -"@%SystemRoot%\\system32\\drivers\\volmgrx.sys,-100"="Dynamic Volume Manager" -"@%systemroot%\\system32\\vssvc.exe,-102"="Volume Shadow Copy" -"@%SystemRoot%\\System32\\drivers\\vwifibus.sys,-257"="Virtual WiFi Bus Driver" -"@%SystemRoot%\\system32\\w32time.dll,-200"="Windows Time" -"@%systemroot%\\system32\\rascfg.dll,-32011"="Remote Access IP ARP Driver" -"@%systemroot%\\system32\\rascfg.dll,-32012"="Remote Access IPv6 ARP Driver" -"@%SystemRoot%\\system32\\Wat\\WatUX.exe,-601"="Windows Activation Technologies Service" -"@%systemroot%\\system32\\wbengine.exe,-104"="Block Level Backup Engine Service" -"@%systemroot%\\system32\\wbiosrvc.dll,-100"="Windows Biometric Service" -"@%SystemRoot%\\system32\\wcncsvc.dll,-3"="Windows Connect Now - Config Registrar" -"@%SystemRoot%\\system32\\WcsPlugInService.dll,-200"="Windows Color System" -"@%SystemRoot%\\system32\\drivers\\Wdf01000.sys,-1000"="Kernel Mode Driver Frameworks service" -"@%systemroot%\\system32\\wdi.dll,-502"="Diagnostic Service Host" -"@%systemroot%\\system32\\wdi.dll,-500"="Diagnostic System Host" -"@%systemroot%\\system32\\webclnt.dll,-100"="WebClient" -"@%SystemRoot%\\system32\\wecsvc.dll,-200"="Windows Event Collector" -"@%SystemRoot%\\System32\\wercplsupport.dll,-101"="Problem Reports and Solutions Control Panel Support" -"@%SystemRoot%\\System32\\wersvc.dll,-100"="Windows Error Reporting Service" -"@%ProgramFiles%\\Windows Defender\\MsMpRes.dll,-103"="Windows Defender" -"@%SystemRoot%\\system32\\winhttp.dll,-100"="WinHTTP Web Proxy Auto-Discovery Service" -"@%Systemroot%\\system32\\wbem\\wmisvc.dll,-205"="Windows Management Instrumentation" -"@%Systemroot%\\system32\\wsmsvc.dll,-101"="Windows Remote Management (WS-Management)" -"@%SystemRoot%\\System32\\wlansvc.dll,-257"="WLAN AutoConfig" -"@%Systemroot%\\system32\\wbem\\wmiapsrv.exe,-110"="WMI Performance Adapter" -"@%PROGRAMFILES%\\Windows Media Player\\wmpnetwk.exe,-101"="Windows Media Player Network Sharing Service" -"@%SystemRoot%\\system32\\wpcsvc.dll,-100"="Parental Controls" -"@%SystemRoot%\\system32\\wpdbusenum.dll,-100"="Portable Device Enumerator Service" -"@%systemroot%\\System32\\drivers\\ws2ifsl.sys,-1000"="Winsock IFS Driver" -"@%SystemRoot%\\System32\\wscsvc.dll,-200"="Security Center" -"@%systemroot%\\system32\\SearchIndexer.exe,-103"="Windows Search" -"@%systemroot%\\system32\\wuaueng.dll,-105"="Windows Update" -"@%SystemRoot%\\system32\\drivers\\Wudfpf.sys,-1000"="User Mode Driver Frameworks Platform Driver" -"@%SystemRoot%\\system32\\wudfsvc.dll,-1000"="Windows Driver Foundation - User-mode Driver Framework" -"@%SystemRoot%\\System32\\wwansvc.dll,-257"="WWAN AutoConfig" -"@%SystemRoot%\\System32\\drivers\\pacer.sys,-100"="Quality of Service Packet Scheduler. This component provides network traffic control, including rate-of-flow and prioritization services." -"@netcfgx.dll,-50003"="Allows other computers to access resources on your computer using a Microsoft network." -"@netcfgx.dll,-50002"="Allows your computer to access resources on a Microsoft network." -"@tcpipcfg.dll,-50002"="TCP/IP version 6. The latest version of the internet protocol that provides communication across diverse interconnected networks." -"@%SystemRoot%\\system32\\tcpipcfg.dll,-50001"="Transmission Control Protocol/Internet Protocol. The default wide area network protocol that provides communication across diverse interconnected networks." -"@%SystemRoot%\\system32\\lltdres.dll,-4"="Used to discover and locate other PCs, devices, and network infrastructure components on the network. Also used to determine network bandwidth." -"@%SystemRoot%\\system32\\lltdres.dll,-3"="Allows this PC to be discovered and located on the network." -"@%systemroot%\\system32\\rascfg.dll,-32010"="Provides the abilitiy to connect a host to a Remote Access Concentrator that supports RFC2516." -"@%systemroot%\\system32\\rascfg.dll,-32009"="Allows you to securely connect to a private network using the Internet." -"@%systemroot%\\system32\\rascfg.dll,-32008"="Allows you to securely connect to a private network using the Internet." -"@%systemroot%\\system32\\sstpsvc.dll,-203"="Allows you to securely connect to a private network using the Internet." -"@provsvc.dll,-202"="HomeGroup" -"@C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\\\ServiceModelEvents.dll,-2002"="Windows Communication Foundation" -"@peerdistsh.dll,-9003"="BranchCache - Hosted Cache Client (Uses HTTPS)" -"@peerdistsh.dll,-9002"="BranchCache - Hosted Cache Server (Uses HTTPS)" -"@peerdistsh.dll,-9001"="BranchCache - Peer Discovery (Uses WSD)" -"@peerdistsh.dll,-9000"="BranchCache - Content Retrieval (Uses HTTP)" -"@%systemroot%\\system32\\provsvc.dll,-202"="HomeGroup" -"@snmptrap.exe,-3"="SNMP Trap" -"@netlogon.dll,-1010"="Netlogon Service" -"@sstpsvc.dll,-35001"="Secure Socket Tunneling Protocol" -"@%SystemRoot%\\system32\\p2pcollab.dll,-8042"="Peer to Peer Trust" -"@%SystemRoot%\\system32\\qagentrt.dll,-10"="System Health Authentication" -"@%SystemRoot%\\system32\\dnsapi.dll,-103"="Domain Name System (DNS) Server Trust" -"@%SystemRoot%\\System32\\fveui.dll,-843"="BitLocker Drive Encryption" -"@%SystemRoot%\\System32\\fveui.dll,-844"="BitLocker Data Recovery Agent" -"C:\\Windows\\system32,@elscore.dll,-2"="Microsoft Script Detection" -"C:\\Windows\\system32,@elscore.dll,-5"="Microsoft Transliteration Engine" -"C:\\Windows\\system32,@elscore.dll,-4"="Microsoft Simplified Chinese to Traditional Chinese Transliteration" -"C:\\Windows\\system32,@elscore.dll,-6"="Microsoft Cyrillic to Latin Transliteration" -"C:\\Windows\\system32,@elscore.dll,-3"="Microsoft Traditional Chinese to Simplified Chinese Transliteration" -"C:\\Windows\\system32,@elscore.dll,-7"="Microsoft Devanagari to Latin Transliteration" -"C:\\Windows\\system32,@elscore.dll,-8"="Microsoft Malayalam to Latin Transliteration" -"C:\\Windows\\system32,@elscore.dll,-9"="Microsoft Bengali to Latin Transliteration" -"C:\\Windows\\system32,@elscore.dll,-1"="Microsoft Language Detection" -"@C:\\Windows\\system32\\unregmp2.exe,-9914"="Windows Media Audio/Video file" -"@C:\\Windows\\system32\\SampleRes.dll,-142"="Wildlife" -"@C:\\Windows\\system32\\SampleRes.dll,-106"="Tulips" -"@C:\\Windows\\system32\\SampleRes.dll,-108"="Penguins" -"@C:\\Windows\\system32\\SampleRes.dll,-107"="Lighthouse" -"@C:\\Windows\\system32\\SampleRes.dll,-105"="Koala" -"@C:\\Windows\\system32\\SampleRes.dll,-104"="Jellyfish" -"@C:\\Windows\\system32\\SampleRes.dll,-103"="Hydrangeas" -"@C:\\Windows\\system32\\SampleRes.dll,-102"="Desert" -"@C:\\Windows\\system32\\SampleRes.dll,-101"="Chrysanthemum" -"@C:\\Windows\\system32\\unregmp2.exe,-9925"="MP3 Format Sound" -"@C:\\Windows\\system32\\SampleRes.dll,-118"="Sleep Away" -"@C:\\Windows\\system32\\SampleRes.dll,-117"="Maid with the Flaxen Hair" -"@C:\\Windows\\system32\\SampleRes.dll,-116"="Kalimba" +[HKEY_USERS\S-1-5-18\Software\Classes\Local Settings\MuiCache\A1] [HKEY_USERS\S-1-5-18\Software\Microsoft]