! REG.EXE VERSION 3.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon AutoRestartShell REG_DWORD 0x1 DefaultDomainName REG_SZ YOUR-RVLNHR6V8D DefaultUserName REG_SZ Owner LegalNoticeCaption REG_SZ LegalNoticeText REG_SZ PowerdownAfterShutdown REG_SZ 0 ReportBootOk REG_SZ 1 Shell REG_SZ Explorer.exe ShutdownWithoutLogon REG_SZ 0 System REG_SZ Userinit REG_SZ C:\WINDOWS\system32\userinit.exe, VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl" SfcQuota REG_DWORD 0xffffffff allocatecdroms REG_SZ 0 allocatedasd REG_SZ 0 allocatefloppies REG_SZ 0 cachedlogonscount REG_SZ 10 forceunlocklogon REG_DWORD 0x0 passwordexpirywarning REG_DWORD 0xe scremoveoption REG_SZ 0 AllowMultipleTSSessions REG_DWORD 0x1 UIHost REG_EXPAND_SZ logonui.exe LogonType REG_DWORD 0x1 Background REG_SZ 0 0 0 DebugServerCommand REG_SZ no SFCDisable REG_DWORD 0x0 WinStationsDisabled REG_SZ 0 HibernationPreviouslyEnabled REG_DWORD 0x1 ShowLogonOptions REG_DWORD 0x0 AltDefaultUserName REG_SZ Owner AltDefaultDomainName REG_SZ YOUR-RVLNHR6V8D LegalNotice Text REG_SZ ChangePasswordUseKerberos REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} REG_SZ Microsoft Disk Quota NoMachinePolicy REG_DWORD 0x0 NoUserPolicy REG_DWORD 0x1 NoSlowLink REG_DWORD 0x1 NoBackgroundPolicy REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x0 RequiresSuccessfulRegistry REG_DWORD 0x1 EnableAsynchronousProcessing REG_DWORD 0x0 DllName REG_EXPAND_SZ dskquota.dll ProcessGroupPolicy REG_SZ ProcessGroupPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} REG_SZ Internet Explorer Zonemapping DllName REG_SZ C:\WINDOWS\system32\iedkcs32.dll ProcessGroupPolicy REG_SZ ProcessGroupPolicyForZoneMap NoGPOListChanges REG_DWORD 0x1 RequiresSucessfulRegistry REG_DWORD 0x1 DisplayName REG_SZ @C:\WINDOWS\system32\iedkcs32.dll.mui,-3051 RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE} REG_SZ Internet Explorer User Accelerators DisplayName REG_SZ @C:\WINDOWS\system32\iedkcs32.dll.mui,-3051 DllName REG_SZ C:\WINDOWS\system32\iedkcs32.dll NoGPOListChanges REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyForActivities ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyForActivitiesEx RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} ProcessGroupPolicy REG_SZ SceProcessSecurityPolicyGPO GenerateGroupPolicy REG_SZ SceGenerateGroupPolicy ExtensionRsopPlanningDebugLevel REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ SceProcessSecurityPolicyGPOEx ExtensionDebugLevel REG_DWORD 0x1 DllName REG_EXPAND_SZ scecli.dll REG_SZ Security NoUserPolicy REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 EnableAsynchronousProcessing REG_DWORD 0x1 MaxNoGPOListChangesInterval REG_DWORD 0x3c0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx GenerateGroupPolicy REG_SZ GenerateGroupPolicy ProcessGroupPolicy REG_SZ ProcessGroupPolicy DllName REG_SZ C:\WINDOWS\system32\iedkcs32.dll REG_SZ Internet Explorer Branding NoSlowLink REG_DWORD 0x1 NoBackgroundPolicy REG_DWORD 0x0 NoGPOListChanges REG_DWORD 0x1 NoMachinePolicy REG_DWORD 0x1 DisplayName REG_SZ @C:\WINDOWS\system32\iedkcs32.dll.mui,-3014 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} ProcessGroupPolicy REG_SZ SceProcessEFSRecoveryGPO DllName REG_EXPAND_SZ scecli.dll REG_SZ EFS recovery NoUserPolicy REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053} REG_SZ 802.3 Group Policy DisplayName REG_EXPAND_SZ @dot3gpclnt.dll,-100 ProcessGroupPolicyEx REG_SZ ProcessLANPolicyEx GenerateGroupPolicy REG_SZ GenerateLANPolicy DllName REG_EXPAND_SZ dot3gpclnt.dll NoUserPolicy REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} REG_SZ Microsoft Offline Files DllName REG_EXPAND_SZ %SystemRoot%\System32\cscui.dll EnableAsynchronousProcessing REG_DWORD 0x0 NoBackgroundPolicy REG_DWORD 0x0 NoGPOListChanges REG_DWORD 0x0 NoMachinePolicy REG_DWORD 0x0 NoSlowLink REG_DWORD 0x0 NoUserPolicy REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x0 ProcessGroupPolicy REG_SZ ProcessGroupPolicy RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} REG_SZ Software Installation DllName REG_EXPAND_SZ appmgmts.dll ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyObjectsEx GenerateGroupPolicy REG_SZ GenerateGroupPolicy NoBackgroundPolicy REG_DWORD 0x0 RequiresSucessfulRegistry REG_DWORD 0x0 NoSlowLink REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x1 EventSources REG_MULTI_SZ (Application Management,Application)\0(MsiInstaller,Application)\0\0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} REG_SZ Internet Explorer Machine Accelerators DisplayName REG_SZ @C:\WINDOWS\system32\iedkcs32.dll.mui,-3051 DllName REG_SZ C:\WINDOWS\system32\iedkcs32.dll NoGPOListChanges REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyForActivities ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyForActivitiesEx RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon DllName REG_SZ C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL Logon REG_SZ SABWINLOLogon Logoff REG_SZ SABWINLOLogoff Startup REG_SZ SABWINLOStartup Shutdown REG_SZ SABWINLOShutdown Asynchronous REG_DWORD 0x0 Impersonate REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain Asynchronous REG_DWORD 0x0 Impersonate REG_DWORD 0x0 DllName REG_EXPAND_SZ crypt32.dll Logoff REG_SZ ChainWlxLogoffEvent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet Asynchronous REG_DWORD 0x0 Impersonate REG_DWORD 0x0 DllName REG_EXPAND_SZ cryptnet.dll Logoff REG_SZ CryptnetWlxLogoffEvent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll DLLName REG_SZ cscdll.dll Logon REG_SZ WinlogonLogonEvent Logoff REG_SZ WinlogonLogoffEvent ScreenSaver REG_SZ WinlogonScreenSaverEvent Startup REG_SZ WinlogonStartupEvent Shutdown REG_SZ WinlogonShutdownEvent StartShell REG_SZ WinlogonStartShellEvent Impersonate REG_DWORD 0x0 Asynchronous REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy Asynchronous REG_DWORD 0x1 DllName REG_EXPAND_SZ %SystemRoot%\System32\dimsntfy.dll Startup REG_SZ WlDimsStartup Shutdown REG_SZ WlDimsShutdown Logon REG_SZ WlDimsLogon Logoff REG_SZ WlDimsLogoff StartShell REG_SZ WlDimsStartShell Lock REG_SZ WlDimsLock Unlock REG_SZ WlDimsUnlock HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui REG_SZ DLLName REG_SZ igfxsrvc.dll Asynchronous REG_DWORD 0x1 Impersonate REG_DWORD 0x1 Unlock REG_SZ WinlogonUnlockEvent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp DLLName REG_SZ wlnotify.dll Logon REG_SZ SCardStartCertProp Logoff REG_SZ SCardStopCertProp Lock REG_SZ SCardSuspendCertProp Unlock REG_SZ SCardResumeCertProp Enabled REG_DWORD 0x1 Impersonate REG_DWORD 0x1 Asynchronous REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule Asynchronous REG_DWORD 0x0 DllName REG_EXPAND_SZ wlnotify.dll Impersonate REG_DWORD 0x0 StartShell REG_SZ SchedStartShell Logoff REG_SZ SchedEventLogOff HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy Logoff REG_SZ WLEventLogoff Impersonate REG_DWORD 0x0 Asynchronous REG_DWORD 0x1 DllName REG_EXPAND_SZ sclgntfy.dll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn DLLName REG_SZ WlNotify.dll Lock REG_SZ SensLockEvent Logon REG_SZ SensLogonEvent Logoff REG_SZ SensLogoffEvent Safe REG_DWORD 0x1 MaxWait REG_DWORD 0x258 StartScreenSaver REG_SZ SensStartScreenSaverEvent StopScreenSaver REG_SZ SensStopScreenSaverEvent Startup REG_SZ SensStartupEvent Shutdown REG_SZ SensShutdownEvent StartShell REG_SZ SensStartShellEvent PostShell REG_SZ SensPostShellEvent Disconnect REG_SZ SensDisconnectEvent Reconnect REG_SZ SensReconnectEvent Unlock REG_SZ SensUnlockEvent Impersonate REG_DWORD 0x1 Asynchronous REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv Asynchronous REG_DWORD 0x0 DllName REG_EXPAND_SZ wlnotify.dll Impersonate REG_DWORD 0x0 Logoff REG_SZ TSEventLogoff Logon REG_SZ TSEventLogon PostShell REG_SZ TSEventPostShell Shutdown REG_SZ TSEventShutdown StartShell REG_SZ TSEventStartShell Startup REG_SZ TSEventStartup MaxWait REG_DWORD 0x258 Reconnect REG_SZ TSEventReconnect Disconnect REG_SZ TSEventDisconnect HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon DLLName REG_SZ wlnotify.dll Logon REG_SZ RegisterTicketExpiredNotificationEvent Logoff REG_SZ UnregisterTicketExpiredNotificationEvent Impersonate REG_DWORD 0x1 Asynchronous REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SCLogon HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList HelpAssistant REG_DWORD 0x0 TsInternetUser REG_DWORD 0x0 SQLAgentCmdExec REG_DWORD 0x0 NetShowServices REG_DWORD 0x0 IWAM_ REG_DWORD 0x10000 IUSR_ REG_DWORD 0x10000 VUSR_ REG_DWORD 0x10000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Credentials