[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\symc8xx]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Type"=dword:00000001
"Tag"=dword:00000036
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\symc8xx\Parameters]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\symc8xx\Parameters\PnpInterface]
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\symlcbrd]
"Type"=dword:00000001
"Start"=dword:00000002
"ErrorControl"=dword:00000000
"ImagePath"=hex(2):5c,3f,3f,5c,43,3a,5c,57,49,4e,44,4f,57,53,5c,73,79,73,74,65,\
6d,33,32,5c,64,72,69,76,65,72,73,5c,73,79,6d,6c,63,62,72,64,2e,73,79,73,00
"DisplayName"="symlcbrd"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\symlcbrd\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\symlcbrd\Enum]
"0"="Root\\LEGACY_SYMLCBRD\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sym_hi]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Type"=dword:00000001
"Tag"=dword:00000037
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sym_hi\Parameters]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sym_hi\Parameters\PnpInterface]
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sym_u3]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Type"=dword:00000001
"Tag"=dword:00000037
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sym_u3\Parameters]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sym_u3\Parameters\PnpInterface]
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sysaudio]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):73,79,73,74,65,6d,33,32,5c,64,72,69,76,65,72,73,5c,73,79,73,\
61,75,64,69,6f,2e,73,79,73,00
"DisplayName"="Microsoft Kernel System Audio Device"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sysaudio\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sysaudio\Enum]
"0"="SW\\{a7c7a5b0-5af3-11d1-9ced-00a024bf0407}\\{9B365890-165F-11D0-A195-0020AFD156E4}"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SysmonLog]
"Description"="Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start."
"DisplayName"="Performance Logs and Alerts"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,\
32,5c,73,6d,6c,6f,67,73,76,63,2e,65,78,65,00
"ObjectName"="NT Authority\\NetworkService"
"Start"=dword:00000003
"Type"=dword:00000010
"DefaultLogFileFolder"=hex(2):25,53,79,73,74,65,6d,44,72,69,76,65,25,5c,50,65,\
72,66,4c,6f,67,73,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SysmonLog\Log Queries]
"Defaults Installed"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TapiSrv]
"DependOnService"=hex(7):50,6c,75,67,50,6c,61,79,00,52,70,63,53,73,00,00
"Description"="Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service."
"DisplayName"="Telephony"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,\
32,5c,73,76,63,68,6f,73,74,2e,65,78,65,20,2d,6b,20,6e,65,74,73,76,63,73,00
"ObjectName"="LocalSystem"
"Start"=dword:00000003
"Type"=dword:00000020
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TapiSrv\Parameters]
"ServiceDll"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,\
33,32,5c,74,61,70,69,73,72,76,2e,64,6c,6c,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TapiSrv\Performance]
"Close"="CloseTapiPerformanceData"
"Collect"="CollectTapiPerformanceData"
"Library"="tapiperf.dll"
"ObjectList"="1150"
"Open"="OpenTapiPerformanceData"
"WbemAdapFileSignature"=hex:69,51,b8,9b,4f,59,1a,a6,94,04,8a,6c,d0,e5,22,4a
"WbemAdapFileTime"=hex:00,20,7c,22,cb,2b,c1,01
"WbemAdapFileSize"=dword:00001600
"WbemAdapStatus"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TapiSrv\Security]
"Security"=hex:01,00,14,80,6c,00,00,00,78,00,00,00,14,00,00,00,34,00,00,00,02,\
00,20,00,01,00,00,00,02,80,18,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,20,02,00,00,02,00,38,00,02,00,00,00,00,03,18,00,ff,01,0f,00,01,02,00,\
00,00,00,00,05,20,00,00,00,20,02,00,00,00,03,18,00,9d,00,00,00,01,02,00,00,\
00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,\
01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TapiSrv\Enum]
"0"="Root\\LEGACY_TAPISRV\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"Tag"=dword:00000004
"ImagePath"=hex(2):73,79,73,74,65,6d,33,32,5c,44,52,49,56,45,52,53,5c,74,63,70,\
69,70,2e,73,79,73,00
"DisplayName"="TCP/IP Protocol Driver"
"Group"="PNP_TDI"
"DependOnService"=hex(7):49,50,53,65,63,00,00
"DependOnGroup"=hex(7):00
"Description"="TCP/IP Protocol Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Linkage]
"Bind"=hex(7):5c,44,65,76,69,63,65,5c,7b,43,45,35,46,41,30,44,30,2d,33,38,34,\
44,2d,34,33,38,37,2d,39,45,34,37,2d,44,32,35,31,38,34,30,33,30,44,39,39,7d,\
00,5c,44,65,76,69,63,65,5c,7b,41,45,43,38,31,34,31,31,2d,42,45,31,45,2d,34,\
44,45,31,2d,42,42,37,39,2d,44,37,39,32,36,31,37,38,32,33,33,33,7d,00,5c,44,\
65,76,69,63,65,5c,4e,64,69,73,57,61,6e,49,70,00,00
"Route"=hex(7):22,7b,43,45,35,46,41,30,44,30,2d,33,38,34,44,2d,34,33,38,37,2d,\
39,45,34,37,2d,44,32,35,31,38,34,30,33,30,44,39,39,7d,22,00,22,7b,41,45,43,\
38,31,34,31,31,2d,42,45,31,45,2d,34,44,45,31,2d,42,42,37,39,2d,44,37,39,32,\
36,31,37,38,32,33,33,33,7d,22,00,22,4e,64,69,73,57,61,6e,49,70,22,00,00
"Export"=hex(7):5c,44,65,76,69,63,65,5c,54,63,70,69,70,5f,7b,43,45,35,46,41,30,\
44,30,2d,33,38,34,44,2d,34,33,38,37,2d,39,45,34,37,2d,44,32,35,31,38,34,30,\
33,30,44,39,39,7d,00,5c,44,65,76,69,63,65,5c,54,63,70,69,70,5f,7b,41,45,43,\
38,31,34,31,31,2d,42,45,31,45,2d,34,44,45,31,2d,42,42,37,39,2d,44,37,39,32,\
36,31,37,38,32,33,33,33,7d,00,5c,44,65,76,69,63,65,5c,54,63,70,69,70,5f,7b,\
45,46,41,41,31,41,32,30,2d,31,31,33,36,2d,34,41,31,33,2d,41,35,33,43,2d,42,\
31,45,34,45,34,43,35,32,43,42,45,7d,00,5c,44,65,76,69,63,65,5c,54,63,70,69,\
70,5f,7b,39,35,42,42,43,34,35,35,2d,30,43,42,41,2d,34,45,44,33,2d,42,39,44,\
38,2d,32,41,46,43,45,31,38,43,34,39,45,37,7d,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
"NV Hostname"="Phil"
"DataBasePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,\
33,32,5c,64,72,69,76,65,72,73,5c,65,74,63,00
"NameServer"=""
"ForwardBroadcasts"=dword:00000000
"IPEnableRouter"=dword:00000000
"Domain"=""
"Hostname"="Phil"
"SearchList"=""
"UseDomainNameDevolution"=dword:00000001
"EnableICMPRedirect"=dword:00000001
"DeadGWDetectDefault"=dword:00000001
"DontAddDefaultGatewayDefault"=dword:00000000
"EnableSecurityFilters"=dword:00000000
"DhcpNameServer"="62.31.176.39 194.117.134.19 195.188.53.175"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Adapters]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Adapters\NdisWanIp]
"LLInterface"="WANARP"
"IpConfig"=hex(7):54,63,70,69,70,5c,50,61,72,61,6d,65,74,65,72,73,5c,49,6e,74,\
65,72,66,61,63,65,73,5c,7b,45,46,41,41,31,41,32,30,2d,31,31,33,36,2d,34,41,\
31,33,2d,41,35,33,43,2d,42,31,45,34,45,34,43,35,32,43,42,45,7d,00,54,63,70,\
69,70,5c,50,61,72,61,6d,65,74,65,72,73,5c,49,6e,74,65,72,66,61,63,65,73,5c,\
7b,39,35,42,42,43,34,35,35,2d,30,43,42,41,2d,34,45,44,33,2d,42,39,44,38,2d,\
32,41,46,43,45,31,38,43,34,39,45,37,7d,00,00
"NumInterfaces"=dword:00000002
"IpInterfaces"=hex:20,1a,aa,ef,36,11,13,4a,a5,3c,b1,e4,e4,c5,2c,be,55,c4,bb,95,\
ba,0c,d3,4e,b9,d8,2a,fc,e1,8c,49,e7
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Adapters\{AEC81411-BE1E-4DE1-BB79-D79261782333}]
"LLInterface"=""
"IpConfig"=hex(7):54,63,70,69,70,5c,50,61,72,61,6d,65,74,65,72,73,5c,49,6e,74,\
65,72,66,61,63,65,73,5c,7b,41,45,43,38,31,34,31,31,2d,42,45,31,45,2d,34,44,\
45,31,2d,42,42,37,39,2d,44,37,39,32,36,31,37,38,32,33,33,33,7d,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Adapters\{CE5FA0D0-384D-4387-9E47-D25184030D99}]
"LLInterface"=""
"IpConfig"=hex(7):54,63,70,69,70,5c,50,61,72,61,6d,65,74,65,72,73,5c,49,6e,74,\
65,72,66,61,63,65,73,5c,7b,43,45,35,46,41,30,44,30,2d,33,38,34,44,2d,34,33,\
38,37,2d,39,45,34,37,2d,44,32,35,31,38,34,30,33,30,44,39,39,7d,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DNSRegisteredAdapters]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{95BBC455-0CBA-4ED3-B9D8-2AFCE18C49E7}]
"UseZeroBroadcast"=dword:00000000
"EnableDHCP"=dword:00000000
"IPAddress"=hex(7):30,2e,30,2e,30,2e,30,00,00
"SubnetMask"=hex(7):30,2e,30,2e,30,2e,30,00,00
"DefaultGateway"=hex(7):00
"EnableDeadGWDetect"=dword:00000001
"DontAddDefaultGateway"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{AEC81411-BE1E-4DE1-BB79-D79261782333}]
"UseZeroBroadcast"=dword:00000000
"EnableDeadGWDetect"=dword:00000001
"EnableDHCP"=dword:00000001
"IPAddress"=hex(7):30,2e,30,2e,30,2e,30,00,00
"SubnetMask"=hex(7):30,2e,30,2e,30,2e,30,00,00
"DefaultGateway"=hex(7):00
"DefaultGatewayMetric"=hex(7):00
"Domain"=""
"RegistrationEnabled"=dword:00000001
"RegisterAdapterName"=dword:00000000
"TCPAllowedPorts"=hex(7):30,00,00
"UDPAllowedPorts"=hex(7):30,00,00
"RawIPAllowedProtocols"=hex(7):30,00,00
"NTEContextList"=hex(7):00
"DhcpClassIdBin"=hex:
"DhcpIPAddress"="192.168.0.73"
"DhcpSubnetMask"="255.255.255.0"
"DhcpServer"="192.168.0.1"
"Lease"=dword:00093a80
"LeaseObtainedTime"=dword:422dfc27
"T1"=dword:422dfd53
"T2"=dword:4234e807
"LeaseTerminatesTime"=dword:423736a7
"IPAutoconfigurationAddress"="0.0.0.0"
"IPAutoconfigurationMask"="255.255.0.0"
"IPAutoconfigurationSeed"=dword:00000000
"AddressType"=dword:00000000
"MTU"=dword:000005ae
"MTU_OLD"=dword:000005ae
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Type"=dword:00000001
"Tag"=dword:00000036
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\symc8xx\Parameters]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\symc8xx\Parameters\PnpInterface]
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\symlcbrd]
"Type"=dword:00000001
"Start"=dword:00000002
"ErrorControl"=dword:00000000
"ImagePath"=hex(2):5c,3f,3f,5c,43,3a,5c,57,49,4e,44,4f,57,53,5c,73,79,73,74,65,\
6d,33,32,5c,64,72,69,76,65,72,73,5c,73,79,6d,6c,63,62,72,64,2e,73,79,73,00
"DisplayName"="symlcbrd"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\symlcbrd\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\symlcbrd\Enum]
"0"="Root\\LEGACY_SYMLCBRD\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sym_hi]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Type"=dword:00000001
"Tag"=dword:00000037
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sym_hi\Parameters]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sym_hi\Parameters\PnpInterface]
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sym_u3]
"ErrorControl"=dword:00000001
"Group"="SCSI miniport"
"Start"=dword:00000004
"Type"=dword:00000001
"Tag"=dword:00000037
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sym_u3\Parameters]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sym_u3\Parameters\PnpInterface]
"5"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sysaudio]
"Type"=dword:00000001
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):73,79,73,74,65,6d,33,32,5c,64,72,69,76,65,72,73,5c,73,79,73,\
61,75,64,69,6f,2e,73,79,73,00
"DisplayName"="Microsoft Kernel System Audio Device"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sysaudio\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sysaudio\Enum]
"0"="SW\\{a7c7a5b0-5af3-11d1-9ced-00a024bf0407}\\{9B365890-165F-11D0-A195-0020AFD156E4}"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SysmonLog]
"Description"="Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start."
"DisplayName"="Performance Logs and Alerts"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,\
32,5c,73,6d,6c,6f,67,73,76,63,2e,65,78,65,00
"ObjectName"="NT Authority\\NetworkService"
"Start"=dword:00000003
"Type"=dword:00000010
"DefaultLogFileFolder"=hex(2):25,53,79,73,74,65,6d,44,72,69,76,65,25,5c,50,65,\
72,66,4c,6f,67,73,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SysmonLog\Log Queries]
"Defaults Installed"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TapiSrv]
"DependOnService"=hex(7):50,6c,75,67,50,6c,61,79,00,52,70,63,53,73,00,00
"Description"="Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service."
"DisplayName"="Telephony"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,\
32,5c,73,76,63,68,6f,73,74,2e,65,78,65,20,2d,6b,20,6e,65,74,73,76,63,73,00
"ObjectName"="LocalSystem"
"Start"=dword:00000003
"Type"=dword:00000020
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TapiSrv\Parameters]
"ServiceDll"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,\
33,32,5c,74,61,70,69,73,72,76,2e,64,6c,6c,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TapiSrv\Performance]
"Close"="CloseTapiPerformanceData"
"Collect"="CollectTapiPerformanceData"
"Library"="tapiperf.dll"
"ObjectList"="1150"
"Open"="OpenTapiPerformanceData"
"WbemAdapFileSignature"=hex:69,51,b8,9b,4f,59,1a,a6,94,04,8a,6c,d0,e5,22,4a
"WbemAdapFileTime"=hex:00,20,7c,22,cb,2b,c1,01
"WbemAdapFileSize"=dword:00001600
"WbemAdapStatus"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TapiSrv\Security]
"Security"=hex:01,00,14,80,6c,00,00,00,78,00,00,00,14,00,00,00,34,00,00,00,02,\
00,20,00,01,00,00,00,02,80,18,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,20,02,00,00,02,00,38,00,02,00,00,00,00,03,18,00,ff,01,0f,00,01,02,00,\
00,00,00,00,05,20,00,00,00,20,02,00,00,00,03,18,00,9d,00,00,00,01,02,00,00,\
00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,\
01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TapiSrv\Enum]
"0"="Root\\LEGACY_TAPISRV\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"Tag"=dword:00000004
"ImagePath"=hex(2):73,79,73,74,65,6d,33,32,5c,44,52,49,56,45,52,53,5c,74,63,70,\
69,70,2e,73,79,73,00
"DisplayName"="TCP/IP Protocol Driver"
"Group"="PNP_TDI"
"DependOnService"=hex(7):49,50,53,65,63,00,00
"DependOnGroup"=hex(7):00
"Description"="TCP/IP Protocol Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Linkage]
"Bind"=hex(7):5c,44,65,76,69,63,65,5c,7b,43,45,35,46,41,30,44,30,2d,33,38,34,\
44,2d,34,33,38,37,2d,39,45,34,37,2d,44,32,35,31,38,34,30,33,30,44,39,39,7d,\
00,5c,44,65,76,69,63,65,5c,7b,41,45,43,38,31,34,31,31,2d,42,45,31,45,2d,34,\
44,45,31,2d,42,42,37,39,2d,44,37,39,32,36,31,37,38,32,33,33,33,7d,00,5c,44,\
65,76,69,63,65,5c,4e,64,69,73,57,61,6e,49,70,00,00
"Route"=hex(7):22,7b,43,45,35,46,41,30,44,30,2d,33,38,34,44,2d,34,33,38,37,2d,\
39,45,34,37,2d,44,32,35,31,38,34,30,33,30,44,39,39,7d,22,00,22,7b,41,45,43,\
38,31,34,31,31,2d,42,45,31,45,2d,34,44,45,31,2d,42,42,37,39,2d,44,37,39,32,\
36,31,37,38,32,33,33,33,7d,22,00,22,4e,64,69,73,57,61,6e,49,70,22,00,00
"Export"=hex(7):5c,44,65,76,69,63,65,5c,54,63,70,69,70,5f,7b,43,45,35,46,41,30,\
44,30,2d,33,38,34,44,2d,34,33,38,37,2d,39,45,34,37,2d,44,32,35,31,38,34,30,\
33,30,44,39,39,7d,00,5c,44,65,76,69,63,65,5c,54,63,70,69,70,5f,7b,41,45,43,\
38,31,34,31,31,2d,42,45,31,45,2d,34,44,45,31,2d,42,42,37,39,2d,44,37,39,32,\
36,31,37,38,32,33,33,33,7d,00,5c,44,65,76,69,63,65,5c,54,63,70,69,70,5f,7b,\
45,46,41,41,31,41,32,30,2d,31,31,33,36,2d,34,41,31,33,2d,41,35,33,43,2d,42,\
31,45,34,45,34,43,35,32,43,42,45,7d,00,5c,44,65,76,69,63,65,5c,54,63,70,69,\
70,5f,7b,39,35,42,42,43,34,35,35,2d,30,43,42,41,2d,34,45,44,33,2d,42,39,44,\
38,2d,32,41,46,43,45,31,38,43,34,39,45,37,7d,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
"NV Hostname"="Phil"
"DataBasePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,\
33,32,5c,64,72,69,76,65,72,73,5c,65,74,63,00
"NameServer"=""
"ForwardBroadcasts"=dword:00000000
"IPEnableRouter"=dword:00000000
"Domain"=""
"Hostname"="Phil"
"SearchList"=""
"UseDomainNameDevolution"=dword:00000001
"EnableICMPRedirect"=dword:00000001
"DeadGWDetectDefault"=dword:00000001
"DontAddDefaultGatewayDefault"=dword:00000000
"EnableSecurityFilters"=dword:00000000
"DhcpNameServer"="62.31.176.39 194.117.134.19 195.188.53.175"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Adapters]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Adapters\NdisWanIp]
"LLInterface"="WANARP"
"IpConfig"=hex(7):54,63,70,69,70,5c,50,61,72,61,6d,65,74,65,72,73,5c,49,6e,74,\
65,72,66,61,63,65,73,5c,7b,45,46,41,41,31,41,32,30,2d,31,31,33,36,2d,34,41,\
31,33,2d,41,35,33,43,2d,42,31,45,34,45,34,43,35,32,43,42,45,7d,00,54,63,70,\
69,70,5c,50,61,72,61,6d,65,74,65,72,73,5c,49,6e,74,65,72,66,61,63,65,73,5c,\
7b,39,35,42,42,43,34,35,35,2d,30,43,42,41,2d,34,45,44,33,2d,42,39,44,38,2d,\
32,41,46,43,45,31,38,43,34,39,45,37,7d,00,00
"NumInterfaces"=dword:00000002
"IpInterfaces"=hex:20,1a,aa,ef,36,11,13,4a,a5,3c,b1,e4,e4,c5,2c,be,55,c4,bb,95,\
ba,0c,d3,4e,b9,d8,2a,fc,e1,8c,49,e7
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Adapters\{AEC81411-BE1E-4DE1-BB79-D79261782333}]
"LLInterface"=""
"IpConfig"=hex(7):54,63,70,69,70,5c,50,61,72,61,6d,65,74,65,72,73,5c,49,6e,74,\
65,72,66,61,63,65,73,5c,7b,41,45,43,38,31,34,31,31,2d,42,45,31,45,2d,34,44,\
45,31,2d,42,42,37,39,2d,44,37,39,32,36,31,37,38,32,33,33,33,7d,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Adapters\{CE5FA0D0-384D-4387-9E47-D25184030D99}]
"LLInterface"=""
"IpConfig"=hex(7):54,63,70,69,70,5c,50,61,72,61,6d,65,74,65,72,73,5c,49,6e,74,\
65,72,66,61,63,65,73,5c,7b,43,45,35,46,41,30,44,30,2d,33,38,34,44,2d,34,33,\
38,37,2d,39,45,34,37,2d,44,32,35,31,38,34,30,33,30,44,39,39,7d,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DNSRegisteredAdapters]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{95BBC455-0CBA-4ED3-B9D8-2AFCE18C49E7}]
"UseZeroBroadcast"=dword:00000000
"EnableDHCP"=dword:00000000
"IPAddress"=hex(7):30,2e,30,2e,30,2e,30,00,00
"SubnetMask"=hex(7):30,2e,30,2e,30,2e,30,00,00
"DefaultGateway"=hex(7):00
"EnableDeadGWDetect"=dword:00000001
"DontAddDefaultGateway"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{AEC81411-BE1E-4DE1-BB79-D79261782333}]
"UseZeroBroadcast"=dword:00000000
"EnableDeadGWDetect"=dword:00000001
"EnableDHCP"=dword:00000001
"IPAddress"=hex(7):30,2e,30,2e,30,2e,30,00,00
"SubnetMask"=hex(7):30,2e,30,2e,30,2e,30,00,00
"DefaultGateway"=hex(7):00
"DefaultGatewayMetric"=hex(7):00
"Domain"=""
"RegistrationEnabled"=dword:00000001
"RegisterAdapterName"=dword:00000000
"TCPAllowedPorts"=hex(7):30,00,00
"UDPAllowedPorts"=hex(7):30,00,00
"RawIPAllowedProtocols"=hex(7):30,00,00
"NTEContextList"=hex(7):00
"DhcpClassIdBin"=hex:
"DhcpIPAddress"="192.168.0.73"
"DhcpSubnetMask"="255.255.255.0"
"DhcpServer"="192.168.0.1"
"Lease"=dword:00093a80
"LeaseObtainedTime"=dword:422dfc27
"T1"=dword:422dfd53
"T2"=dword:4234e807
"LeaseTerminatesTime"=dword:423736a7
"IPAutoconfigurationAddress"="0.0.0.0"
"IPAutoconfigurationMask"="255.255.0.0"
"IPAutoconfigurationSeed"=dword:00000000
"AddressType"=dword:00000000
"MTU"=dword:000005ae
"MTU_OLD"=dword:000005ae