|
Key
|
Name
|
Value
|
Times
|
| HKLM\SOFTWARE\CLASSES\APPID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}
|
LocalService |
winmgmt
|
1 |
| HKLM\SOFTWARE\CLASSES\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\INPROCSERVER32
|
|
C:\WINDOWS\system32\wbem\wbemprox.dll
|
1 |
| HKLM\SOFTWARE\CLASSES\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\INPROCSERVER32
|
ThreadingModel |
Both
|
1 |
| HKLM\SOFTWARE\CLASSES\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\INPROCSERVER32
|
|
C:\WINDOWS\system32\wbem\wbemsvc.dll
|
1 |
| HKLM\SOFTWARE\CLASSES\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\INPROCSERVER32
|
ThreadingModel |
Both
|
1 |
| HKLM\SOFTWARE\CLASSES\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}
|
AppID |
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
|
1 |
| HKLM\SOFTWARE\CLASSES\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\INPROCSERVER32
|
|
C:\WINDOWS\system32\wbem\fastprox.dll
|
1 |
| HKLM\SOFTWARE\CLASSES\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\INPROCSERVER32
|
ThreadingModel |
Both
|
1 |
| HKLM\SOFTWARE\CLASSES\CLSID\{EA4A0A43-1C8F-4C7B-A4B1-28ECBD96BA8C}\INPROCSERVER32
|
|
%SystemRoot%\System32\qagent.dll
|
1 |
| HKLM\SOFTWARE\CLASSES\CLSID\{EA4A0A43-1C8F-4C7B-A4B1-28ECBD96BA8C}\INPROCSERVER32
|
ThreadingModel |
Apartment
|
1 |
| HKLM\SOFTWARE\CLASSES\CLSID\{EB082BA1-DF8A-46BE-82F3-35BF9E9BE52F}\INPROCSERVER32
|
|
%SystemRoot%\System32\qagent.dll
|
1 |
| HKLM\SOFTWARE\CLASSES\CLSID\{EB082BA1-DF8A-46BE-82F3-35BF9E9BE52F}\INPROCSERVER32
|
ThreadingModel |
Apartment
|
1 |
| HKLM\SOFTWARE\CLASSES\INTERFACE\{9556DC99-828C-11CF-A37E-00AA003240C7}\PROXYSTUBCLSID32
|
|
{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
|
1 |
| HKLM\SOFTWARE\CLASSES\INTERFACE\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\PROXYSTUBCLSID32
|
|
{7C857801-7381-11CF-884D-00AA004B2E24}
|
1 |
| HKLM\SOFTWARE\CLASSES\INTERFACE\{F309AD18-D86A-11D0-A075-00C04FB68820}\PROXYSTUBCLSID32
|
|
{7C857801-7381-11CF-884D-00AA004B2E24}
|
1 |
| HKLM\SOFTWARE\Microsoft\CTF\SystemShared\
|
CUAS |
0
|
1 |
| HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Gemplus GemSAFE Card CSP v1.0
|
Type |
1
|
16 |
| HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Infineon SICRYPT Base Smart Card CSP
|
Type |
1
|
16 |
| HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Cryptographic Provider v1.0
|
Type |
1
|
16 |
| HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Base DSS Cryptographic Provider
|
Type |
3
|
16 |
| HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Base DSS and Diffie-Hellman Cryptographic Provider
|
Type |
13
|
16 |
| HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Smart Card Crypto Provider
|
Type |
1
|
16 |
| HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft DH SChannel Cryptographic Provider
|
Type |
18
|
16 |
| HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced Cryptographic Provider v1.0
|
Type |
1
|
16 |
| HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider
|
Type |
13
|
16 |
| HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider (Prototype)
|
Type |
24
|
16 |
| HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Exchange Cryptographic Provider v1.0
|
Type |
5
|
16 |
| HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft RSA SChannel Cryptographic Provider
|
Type |
12
|
16 |
| HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider
|
Type |
1
|
16 |
| HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Schlumberger Cryptographic Service Provider
|
Type |
1
|
16 |
| HKLM\SOFTWARE\Microsoft\NetSh
|
1 |
ipmontr.dll
|
1 |
| HKLM\SOFTWARE\Microsoft\NetSh
|
2 |
ifmon.dll
|
1 |
| HKLM\SOFTWARE\Microsoft\NetSh
|
3 |
ippromon.dll
|
1 |
| HKLM\SOFTWARE\Microsoft\NetSh
|
4 |
rasmontr.dll
|
1 |
| HKLM\SOFTWARE\Microsoft\NetSh
|
5 |
ipxmontr.dll
|
1 |
| HKLM\SOFTWARE\Microsoft\NetSh
|
6 |
ipxpromn.dll
|
1 |
| HKLM\SOFTWARE\Microsoft\NetSh
|
FWCFG |
fwcfg.dll
|
1 |
| HKLM\SOFTWARE\Microsoft\NetSh
|
dgnet |
dgnet.dll
|
1 |
| HKLM\SOFTWARE\Microsoft\NetSh
|
dot3cfg |
dot3cfg.dll
|
1 |
| HKLM\SOFTWARE\Microsoft\NetSh
|
hnetmon |
hnetmon.dll
|
1 |
| HKLM\SOFTWARE\Microsoft\NetSh
|
ipv6mon |
ipv6mon.dll
|
1 |
| HKLM\SOFTWARE\Microsoft\NetSh
|
napmontr |
napmontr.dll
|
1 |
| HKLM\SOFTWARE\Microsoft\WBEM\CIMOM
|
Log File Max Size |
65536
|
4 |
| HKLM\SOFTWARE\Microsoft\WBEM\CIMOM
|
Logging |
1
|
2 |
| HKLM\SOFTWARE\Microsoft\WBEM\CIMOM
|
Logging Directory |
C:\WINDOWS\system32\WBEM\Logs\
|
4 |
| HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
|
CurrentBuildNumber |
2600
|
1 |
| HKLM\Software\Microsoft\COM3
|
Com+Enabled |
1
|
2 |
| HKLM\Software\Microsoft\COM3
|
REGDBVersion |
0x0f00000000000000
|
12 |
| HKLM\Software\Microsoft\Tracing
|
EnableConsoleTracing |
0
|
1 |
| HKLM\Software\Microsoft\Tracing\FWCFG
|
ConsoleTracingMask |
4294901760
|
2 |
| HKLM\Software\Microsoft\Tracing\FWCFG
|
EnableConsoleTracing |
0
|
2 |
| HKLM\Software\Microsoft\Tracing\FWCFG
|
EnableFileTracing |
0
|
2 |
| HKLM\Software\Microsoft\Tracing\FWCFG
|
FileDirectory |
%windir%\tracing
|
4 |
| HKLM\Software\Microsoft\Tracing\FWCFG
|
FileTracingMask |
4294901760
|
2 |
| HKLM\Software\Microsoft\Tracing\FWCFG
|
MaxFileSize |
1048576
|
2 |
| HKLM\Software\Microsoft\WBEM\CIMOM
|
Log File Max Size |
65536
|
1 |
| HKLM\Software\Microsoft\WBEM\CIMOM
|
Logging |
1
|
1 |
| HKLM\Software\Microsoft\WBEM\CIMOM
|
Logging Directory |
C:\WINDOWS\system32\WBEM\Logs\
|
2 |
| HKLM\Software\Microsoft\WBEM\CIMOM
|
ProcessID |
860
|
1 |
| HKLM\Software\Microsoft\WBEM\CIMOM
|
Repository Directory |
%SystemRoot%\system32\WBEM\Repository
|
2 |
| HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName
|
ComputerName |
USER
|
3 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79617
|
Description |
Provides DHCP based enforcement for NAP
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79617
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79617
|
Friendly Name |
DHCP Quarantine Enforcement Client
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79617
|
Vendor Name |
Microsoft Corporation
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79617
|
Version |
1.0
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79618
|
Description |
Provides the quarantine enforcement for RAS Client
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79618
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79618
|
Friendly Name |
Remote Access Quarantine Enforcement Client
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79618
|
Vendor Name |
Microsoft Corporation
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79618
|
Version |
1.0
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79619
|
Component Type |
2
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79619
|
Description |
Provides IPSec based enforcement for Network Access Protection
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79619
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79619
|
Friendly Name |
IPSec Relying Party
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79619
|
Vendor Name |
Microsoft Corporation
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79619
|
Version |
1.0
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79620
|
Description |
Provides wireless Eapol based enforcement for NAP
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79620
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79620
|
Friendly Name |
Wireless Eapol Quarantine Enforcement Client
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79620
|
Vendor Name |
Microsoft Corporation
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79620
|
Version |
1.0
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79621
|
Description |
Provides TS Gateway enforcement for NAP
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79621
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79621
|
Friendly Name |
TS Gateway Quarantine Enforcement Client
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79621
|
Vendor Name |
Microsoft Corporation
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79621
|
Version |
1.0
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79623
|
Description |
Provides EAP based enforcement for NAP
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79623
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79623
|
Friendly Name |
EAP Quarantine Enforcement Client
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79623
|
Vendor Name |
Microsoft Corporation
|
1 |
| HKLM\System\CurrentControlSet\Services\NapAgent\Qecs\79623
|
Version |
1.0
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters
|
Domain |
|
2 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters
|
Hostname |
user
|
2 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters
|
UseDomainNameDevolution |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters
|
WinSock_Registry_Version |
2.0
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5
|
Num_Catalog_Entries |
3
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5
|
Serial_Access_Num |
4
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
DisplayString |
Tcpip
|
4 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
LibraryPath |
%SystemRoot%\System32\mswsock.dll
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
ProviderId |
0x409d05229e7ecf11ae5a00aa00a7112b
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
StoresServiceClassInfo |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
SupportedNameSpace |
12
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
Version |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
DisplayString |
NTDS
|
4 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
LibraryPath |
%SystemRoot%\System32\winrnr.dll
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
ProviderId |
0xee37263b80e5cf11a55500c04fd8d4ac
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
StoresServiceClassInfo |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
SupportedNameSpace |
32
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
Version |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
DisplayString |
Network Location Awareness (NLA) Namespace
|
4 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
LibraryPath |
%SystemRoot%\System32\mswsock.dll
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
ProviderId |
0x3a244266a83ba64abaa52e0bd71fdd83
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
StoresServiceClassInfo |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
SupportedNameSpace |
15
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
Version |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
|
Next_Catalog_Entry_ID |
1012
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
|
Num_Catalog_Entries |
11
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
|
Serial_Access_Num |
4
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004
|
PackedCatalogItem |
%SystemRoot%\system32\rsvpsp.d
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005
|
PackedCatalogItem |
%SystemRoot%\system32\rsvpsp.d
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\Setup
|
SystemSetupInProgress |
0
|
1 |