Hi Pieter..I did as you suggested and here are the contents of the text file.Thanks, Amrita
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application]
"DisplayNameFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\
6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\
00,65,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"DisplayNameID"=dword:00000100
"File"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,\
6f,00,6e,00,66,00,69,00,67,00,5c,00,41,00,70,00,70,00,45,00,76,00,65,00,6e,\
00,74,00,2e,00,45,00,76,00,74,00,00,00
"MaxSize"=dword:00080000
"PrimaryModule"="Application"
"Retention"=dword:00093a80
@="mnmsrvc"
"Sources"=hex(7):57,00,53,00,48,00,00,00,57,00,72,00,53,00,6f,00,63,00,6b,00,\
65,00,74,00,00,00,57,00,72,00,52,00,54,00,00,00,57,00,72,00,4f,00,53,00,20,\
00,43,00,6f,00,6e,00,73,00,6f,00,6c,00,65,00,00,00,57,00,72,00,4f,00,53,00,\
00,00,57,00,72,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,44,00,72,00,69,\
00,76,00,65,00,72,00,00,00,57,00,72,00,46,00,43,00,00,00,57,00,6d,00,64,00,\
6d,00,50,00,6d,00,53,00,4e,00,00,00,57,00,4d,00,44,00,4d,00,20,00,50,00,4d,\
00,53,00,50,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,57,00,\
69,00,6e,00,4d,00,67,00,6d,00,74,00,00,00,57,00,69,00,6e,00,6c,00,6f,00,67,\
00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,33,00,\
2e,00,31,00,20,00,4d,00,69,00,67,00,72,00,61,00,74,00,69,00,6f,00,6e,00,00,\
00,56,00,42,00,52,00,75,00,6e,00,74,00,69,00,6d,00,65,00,00,00,55,00,73,00,\
65,00,72,00,69,00,6e,00,69,00,74,00,00,00,55,00,73,00,65,00,72,00,65,00,6e,\
00,76,00,00,00,54,00,72,00,75,00,65,00,56,00,65,00,63,00,74,00,6f,00,72,00,\
20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,54,00,6c,00,6e,00,74,\
00,73,00,76,00,72,00,00,00,53,00,79,00,73,00,6d,00,6f,00,6e,00,4c,00,6f,00,\
67,00,00,00,53,00,70,00,6f,00,6f,00,6c,00,65,00,72,00,43,00,74,00,72,00,73,\
00,00,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,20,00,49,00,6e,00,\
73,00,74,00,61,00,6c,00,6c,00,61,00,74,00,69,00,6f,00,6e,00,00,00,53,00,63,\
00,6c,00,67,00,4e,00,74,00,66,00,79,00,00,00,53,00,63,00,65,00,53,00,72,00,\
76,00,00,00,53,00,63,00,65,00,43,00,6c,00,69,00,00,00,70,00,74,00,73,00,73,\
00,76,00,63,00,00,00,50,00,50,00,50,00,4f,00,45,00,00,00,50,00,6c,00,75,00,\
67,00,50,00,6c,00,61,00,79,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,00,\
00,50,00,65,00,72,00,66,00,50,00,72,00,6f,00,63,00,00,00,50,00,65,00,72,00,\
66,00,4f,00,53,00,00,00,50,00,65,00,72,00,66,00,4e,00,65,00,74,00,00,00,50,\
00,65,00,72,00,66,00,6d,00,6f,00,6e,00,00,00,50,00,65,00,72,00,66,00,6c,00,\
69,00,62,00,00,00,50,00,65,00,72,00,66,00,44,00,69,00,73,00,6b,00,00,00,50,\
00,65,00,72,00,66,00,63,00,74,00,72,00,73,00,00,00,4f,00,66,00,66,00,6c,00,\
69,00,6e,00,65,00,20,00,46,00,69,00,6c,00,65,00,73,00,00,00,4f,00,61,00,6b,\
00,6c,00,65,00,79,00,00,00,6e,00,74,00,62,00,61,00,63,00,6b,00,75,00,70,00,\
00,00,6e,00,61,00,76,00,61,00,70,00,73,00,76,00,63,00,00,00,4d,00,53,00,53,\
00,4f,00,41,00,50,00,00,00,4d,00,73,00,69,00,49,00,6e,00,73,00,74,00,61,00,\
6c,00,6c,00,65,00,72,00,00,00,4d,00,53,00,44,00,54,00,43,00,20,00,43,00,6c,\
00,69,00,65,00,6e,00,74,00,00,00,4d,00,53,00,44,00,54,00,43,00,00,00,6d,00,\
6e,00,6d,00,73,00,72,00,76,00,63,00,00,00,4d,00,41,00,43,00,20,00,46,00,52,\
00,41,00,4d,00,45,00,00,00,4c,00,6f,00,61,00,64,00,50,00,65,00,72,00,66,00,\
00,00,4c,00,69,00,76,00,65,00,55,00,70,00,64,00,61,00,74,00,65,00,00,00,4a,\
00,61,00,76,00,61,00,20,00,56,00,4d,00,00,00,49,00,50,00,53,00,45,00,43,00,\
50,00,6f,00,6c,00,69,00,63,00,79,00,53,00,74,00,6f,00,72,00,61,00,67,00,65,\
00,00,00,69,00,50,00,6f,00,64,00,53,00,72,00,76,00,00,00,49,00,49,00,53,00,\
41,00,44,00,4d,00,49,00,4e,00,00,00,49,00,45,00,78,00,70,00,6c,00,6f,00,72,\
00,65,00,00,00,68,00,70,00,6d,00,6f,00,6e,00,00,00,46,00,6f,00,6c,00,64,00,\
65,00,72,00,20,00,52,00,65,00,64,00,69,00,72,00,65,00,63,00,74,00,69,00,6f,\
00,6e,00,00,00,46,00,69,00,6c,00,65,00,20,00,44,00,65,00,70,00,6c,00,6f,00,\
79,00,6d,00,65,00,6e,00,74,00,00,00,46,00,61,00,78,00,20,00,53,00,65,00,72,\
00,76,00,69,00,63,00,65,00,00,00,45,00,58,00,54,00,52,00,41,00,21,00,00,00,\
45,00,76,00,65,00,6e,00,74,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,00,45,\
00,53,00,45,00,4e,00,54,00,00,00,44,00,72,00,57,00,61,00,74,00,73,00,6f,00,\
6e,00,00,00,44,00,69,00,73,00,6b,00,51,00,75,00,6f,00,74,00,61,00,00,00,43,\
00,4f,00,4d,00,2b,00,00,00,43,00,69,00,00,00,43,00,68,00,6b,00,64,00,73,00,\
6b,00,00,00,63,00,63,00,50,00,77,00,64,00,53,00,76,00,63,00,00,00,63,00,63,\
00,45,00,76,00,74,00,4d,00,67,00,72,00,00,00,41,00,75,00,74,00,6f,00,63,00,\
68,00,6b,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,\
00,6e,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,6d,00,65,00,6e,00,74,00,\
00,00,41,00,50,00,47,00,54,00,53,00,00,00,41,00,64,00,77,00,61,00,74,00,63,\
00,68,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,\
6e,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Adwatch]
"EventMessageFile"="C:\\PROGRA~1\\Lavasoft\\AD-AWA~2\\Ad-Watch.exe"
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\APGTS]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,4e,00,54,00,5c,\
00,68,00,65,00,6c,00,70,00,5c,00,54,00,53,00,68,00,6f,00,6f,00,74,00,2e,00,\
6f,00,63,00,78,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Application Management]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,61,00,70,00,70,00,6d,00,67,00,6d,00,74,00,73,00,2e,00,64,00,6c,00,6c,\
00,00,00
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Autochk]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,77,00,69,00,6e,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,65,00,78,00,65,\
00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ccEvtMgr]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,\
6f,00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,00,6d,00,61,\
00,6e,00,74,00,65,00,63,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,5c,00,\
63,00,63,00,45,00,76,00,74,00,4d,00,67,00,72,00,2e,00,65,00,78,00,65,00,00,\
00
"TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ccPwdSvc]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,\
6f,00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,00,6d,00,61,\
00,6e,00,74,00,65,00,63,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,5c,00,\
63,00,63,00,50,00,77,00,64,00,53,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,\
00
"TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ccSetMgr]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,\
6f,00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,00,6d,00,61,\
00,6e,00,74,00,65,00,63,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,5c,00,\
63,00,63,00,53,00,65,00,74,00,4d,00,67,00,72,00,2e,00,65,00,78,00,65,00,00,\
00
"TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Chkdsk]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,75,00,6c,00,69,00,62,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Ci]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,71,00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00
"CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,71,00,75,00,65,00,72,00,79,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
"CategoryCount"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\COM+]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,4e,00,54,00,5c,\
00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,6f,00,6d,00,\
73,00,76,00,63,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,4e,00,54,00,\
5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,6f,00,6d,\
00,73,00,76,00,63,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"ParameterMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,4e,00,54,00,\
5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,6f,00,6d,\
00,73,00,76,00,63,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"TypeSupported"=dword:00000007
"CategoryCount"=dword:00000014
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DiskQuota]
"EventMessageFile"="%SystemRoot%\\System32\\dskquota.dll"
"TypesSupported"="0x00000007"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DrWatson]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,64,00,72,00,77,00,74,00,73,00,6e,00,33,00,32,00,2e,00,65,00,78,00,65,\
00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ESENT]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,4e,00,54,00,5c,\
00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,45,00,53,00,45,00,\
4e,00,54,00,2e,00,64,00,6c,00,6c,00,00,00
"CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,4e,00,54,00,\
5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,45,00,53,00,45,\
00,4e,00,54,00,2e,00,64,00,6c,00,6c,00,00,00
"CategoryCount"=dword:0000000f
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\EventSystem]
"CategoryCount"=dword:00000006
"TypesSupported"=dword:00000007
"CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,4e,00,54,00,\
5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,65,00,73,00,2e,\
00,64,00,6c,00,6c,00,00,00
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,4e,00,54,00,5c,\
00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,65,00,73,00,2e,00,\
64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\EXTRA!]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,61,00,6f,00,6d,00,62,00,6d,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,\
00
"TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Fax Service]
"EventMessageFile"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,\
00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,66,00,61,00,78,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,6c,\
00,00,00
"CategoryMessageFile"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,\
6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,66,00,61,00,78,00,65,00,76,00,65,00,6e,00,74,00,2e,00,64,00,6c,00,\
6c,00,00,00
"CategoryCount"=dword:00000004
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\File Deployment]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,66,00,64,00,65,00,70,00,6c,00,6f,00,79,00,2e,00,64,00,6c,00,6c,00,00,\
00
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Folder Redirection]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,66,00,64,00,65,00,70,00,6c,00,6f,00,79,00,2e,00,64,00,6c,00,6c,00,00,\
00
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,6b,00,65,00,72,00,6e,00,65,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\hpmon]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,68,00,70,00,6d,00,6f,00,6e,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IExplore]
"EventMessageFile"="C:\\Program Files\\Internet Explorer\\DW15.EXE"
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IISADMIN]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,69,00,6e,00,65,00,74,00,73,00,72,00,76,00,5c,00,73,00,76,00,63,00,65,\
00,78,00,74,00,2e,00,64,00,6c,00,6c,00,3b,00,25,00,53,00,79,00,73,00,74,00,\
65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,\
00,6d,00,33,00,32,00,5c,00,73,00,70,00,34,00,69,00,69,00,73,00,2e,00,65,00,\
78,00,65,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\iPodSrv]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,4e,00,54,00,5c,\
00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,69,00,50,00,6f,00,\
64,00,53,00,72,00,76,00,5f,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IPSECPolicyStorage]
"EventMessageFile"="%SystemRoot%\\System32\\polstore.dll"
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Java VM]
"EventMessageFile"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,\
00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,76,00,6d,00,68,00,65,00,6c,00,70,00,65,00,72,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=hex:07,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\LiveUpdate]
"EventMessageFile"="C:\\Program Files\\Symantec\\LiveUpdate\\LuComServer.exe"
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\LoadPerf]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6c,00,6f,00,61,00,64,00,70,00,65,00,72,00,66,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,70,\
00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MAC FRAME]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,56,00,65,00,72,00,69,00,\
7a,00,6f,00,6e,00,20,00,4f,00,6e,00,6c,00,69,00,6e,00,65,00,5c,00,57,00,69,\
00,6e,00,50,00,6f,00,45,00,54,00,5c,00,57,00,72,00,45,00,76,00,65,00,6e,00,\
74,00,4c,00,6f,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\mnmsrvc]
"EventMessageFile"="%SystemRoot%\\System32\\nmevtmsg.dll"
"TypeSupported"=hex:07,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSDTC]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,4e,00,54,00,5c,\
00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4d,00,53,00,44,00,\
54,00,43,00,50,00,52,00,58,00,2e,00,44,00,4c,00,4c,00,00,00
"TypesSupported"=dword:00000007
"CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,4e,00,54,00,\
5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4d,00,53,00,44,\
00,54,00,43,00,50,00,52,00,58,00,2e,00,44,00,4c,00,4c,00,00,00
"CategoryCount"=dword:00000012
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSDTC Client]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,4e,00,54,00,5c,\
00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4d,00,53,00,44,00,\
54,00,43,00,50,00,52,00,58,00,2e,00,44,00,4c,00,4c,00,00,00
"TypesSupported"=dword:00000007
"CategoryMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,4e,00,54,00,\
5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4d,00,53,00,44,\
00,54,00,43,00,50,00,52,00,58,00,2e,00,44,00,4c,00,4c,00,00,00
"CategoryCount"=dword:00000012
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MsiInstaller]
"EventMessageFile"="C:\\WINNT\\system32\\msi.dll"
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MSSOAP]
"TypesSupported"=dword:00000001
"CategoryCount"=dword:00000004
"EventMessageFile"="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"
"CategoryMessageFile"="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\navapsvc]
"EventMessageFile"="\"C:\\Program Files\\Norton AntiVirus\\navapsvc.exe\""
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\NPFMntor]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4e,00,6f,00,72,00,74,00,\
6f,00,6e,00,20,00,41,00,6e,00,74,00,69,00,56,00,69,00,72,00,75,00,73,00,5c,\
00,49,00,57,00,50,00,5c,00,4e,00,50,00,46,00,4d,00,6e,00,74,00,6f,00,72,00,\
2e,00,65,00,78,00,65,00,00,00
"TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ntbackup]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6e,00,74,00,62,00,61,00,63,00,6b,00,75,00,70,00,2e,00,65,00,78,00,65,\
00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Oakley]
"EventMessageFile"="%SystemRoot%\\System32\\oakley.dll"
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Offline Files]
"EventMessageFile"="%SystemRoot%\\System32\\cscui.dll"
"TypesSupported"="0x00000007"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Perfctrs]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,70,00,65,00,72,00,66,00,63,00,74,00,72,00,73,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\PerfDisk]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,70,00,65,00,72,00,66,00,64,00,69,00,73,00,6b,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Perflib]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,70,00,72,00,66,00,6c,00,62,00,6d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Perfmon]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,70,00,65,00,72,00,66,00,6d,00,6f,00,6e,00,2e,00,65,00,78,00,65,00,00,\
00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\PerfNet]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,70,00,65,00,72,00,66,00,6e,00,65,00,74,00,2e,00,64,00,6c,00,6c,00,00,\
00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\PerfOS]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,70,00,65,00,72,00,66,00,4f,00,53,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\PerfProc]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,70,00,65,00,72,00,66,00,70,00,72,00,6f,00,63,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\PlugPlayManager]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,75,00,6d,00,70,00,6e,00,70,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\PPPOE]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,56,00,65,00,72,00,69,00,\
7a,00,6f,00,6e,00,20,00,4f,00,6e,00,6c,00,69,00,6e,00,65,00,5c,00,57,00,69,\
00,6e,00,50,00,6f,00,45,00,54,00,5c,00,57,00,72,00,45,00,76,00,65,00,6e,00,\
74,00,4c,00,6f,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ptssvc]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4b,00,6f,00,64,00,61,00,\
6b,00,5c,00,4b,00,6f,00,64,00,61,00,6b,00,20,00,45,00,61,00,73,00,79,00,53,\
00,68,00,61,00,72,00,65,00,20,00,73,00,6f,00,66,00,74,00,77,00,61,00,72,00,\
65,00,5c,00,62,00,69,00,6e,00,5c,00,70,00,74,00,73,00,73,00,76,00,63,00,2e,\
00,65,00,78,00,65,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SAVSCAN]
"TypesSupported"=dword:00000007
"EventMessageFile"="C:\\Program Files\\Norton AntiVirus\\SAVScan.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SceCli]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,63,00,65,00,63,00,6c,00,69,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SceSrv]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,63,00,65,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SclgNtfy]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SNDSrvc]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,\
6f,00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,00,6d,00,61,\
00,6e,00,74,00,65,00,63,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,5c,00,\
53,00,4e,00,44,00,53,00,72,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00
"TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Software Installation]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,61,00,70,00,70,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SPBBCSvc]
"TypesSupported"=dword:0000001f
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,\
6f,00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,00,6d,00,61,\
00,6e,00,74,00,65,00,63,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,5c,00,\
53,00,50,00,42,00,42,00,43,00,5c,00,53,00,50,00,42,00,42,00,43,00,53,00,76,\
00,63,00,2e,00,65,00,78,00,65,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SpoolerCtrs]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,77,00,69,00,6e,00,73,00,70,00,6f,00,6f,00,6c,00,2e,00,64,00,72,00,76,\
00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SymWSC]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,\
6f,00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,00,6d,00,61,\
00,6e,00,74,00,65,00,63,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,5c,00,\
53,00,65,00,63,00,75,00,72,00,69,00,74,00,79,00,20,00,43,00,65,00,6e,00,74,\
00,65,00,72,00,5c,00,53,00,79,00,6d,00,57,00,53,00,43,00,2e,00,65,00,78,00,\
65,00,00,00
"TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SysmonLog]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,73,00,6d,00,6c,00,6f,00,67,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,\
00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Tlntsvr]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,74,00,6c,00,6e,00,74,00,73,00,76,00,72,00,2e,00,65,00,78,00,65,00,00,\
00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\TrueVector Service]
"EventMessageFile"="C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\VSINIT.dll"
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Userenv]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,75,00,73,00,65,00,72,00,65,00,6e,00,76,00,2e,00,64,00,6c,00,6c,00,00,\
00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Userinit]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,75,00,73,00,65,00,72,00,69,00,6e,00,69,00,74,00,2e,00,65,00,78,00,65,\
00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\VBRuntime]
"EventMessageFile"="C:\\WINNT\\system32\\msvbvm60.dll"
"TypesSupported"=dword:00000004
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Windows 3.1 Migration]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,61,00,64,00,76,00,61,00,70,00,69,00,33,00,32,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Winlogon]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,77,00,69,00,6e,00,6c,00,6f,00,67,00,6f,00,6e,00,2e,00,65,00,78,00,65,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,70,\
00,33,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WinMgmt]
"EventMessageFile"="C:\\WINNT\\System32\\WBEM\\WinMgmtR.dll"
"TypesSupported"=hex:07
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WMDM PMSP Service]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,4e,00,54,00,5c,\
00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,73,00,70,00,\
6d,00,73,00,70,00,73,00,76,00,2e,00,65,00,78,00,65,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WmdmPmSN]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,4e,00,54,00,5c,\
00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,73,00,70,00,\
6d,00,73,00,6e,00,73,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WrFC]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,56,00,65,00,72,00,69,00,\
7a,00,6f,00,6e,00,20,00,4f,00,6e,00,6c,00,69,00,6e,00,65,00,5c,00,57,00,69,\
00,6e,00,50,00,6f,00,45,00,54,00,5c,00,57,00,72,00,45,00,76,00,65,00,6e,00,\
74,00,4c,00,6f,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WrNetworkDriver]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,56,00,65,00,72,00,69,00,\
7a,00,6f,00,6e,00,20,00,4f,00,6e,00,6c,00,69,00,6e,00,65,00,5c,00,57,00,69,\
00,6e,00,50,00,6f,00,45,00,54,00,5c,00,57,00,72,00,45,00,76,00,65,00,6e,00,\
74,00,4c,00,6f,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WrOS]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,56,00,65,00,72,00,69,00,\
7a,00,6f,00,6e,00,20,00,4f,00,6e,00,6c,00,69,00,6e,00,65,00,5c,00,57,00,69,\
00,6e,00,50,00,6f,00,45,00,54,00,5c,00,57,00,72,00,45,00,76,00,65,00,6e,00,\
74,00,4c,00,6f,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WrOS Console]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,56,00,65,00,72,00,69,00,\
7a,00,6f,00,6e,00,20,00,4f,00,6e,00,6c,00,69,00,6e,00,65,00,5c,00,57,00,69,\
00,6e,00,50,00,6f,00,45,00,54,00,5c,00,57,00,72,00,45,00,76,00,65,00,6e,00,\
74,00,4c,00,6f,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WrRT]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,56,00,65,00,72,00,69,00,\
7a,00,6f,00,6e,00,20,00,4f,00,6e,00,6c,00,69,00,6e,00,65,00,5c,00,57,00,69,\
00,6e,00,50,00,6f,00,45,00,54,00,5c,00,57,00,72,00,45,00,76,00,65,00,6e,00,\
74,00,4c,00,6f,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WrSocket]
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,56,00,65,00,72,00,69,00,\
7a,00,6f,00,6e,00,20,00,4f,00,6e,00,6c,00,69,00,6e,00,65,00,5c,00,57,00,69,\
00,6e,00,50,00,6f,00,45,00,54,00,5c,00,57,00,72,00,45,00,76,00,65,00,6e,00,\
74,00,4c,00,6f,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WSH]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,77,00,73,00,68,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:0000001f
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security]
"DisplayNameFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\
6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\
00,65,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"DisplayNameID"=dword:00000101
"File"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,\
6f,00,6e,00,66,00,69,00,67,00,5c,00,53,00,65,00,63,00,45,00,76,00,65,00,6e,\
00,74,00,2e,00,45,00,76,00,74,00,00,00
"MaxSize"=dword:00080000
"PrimaryModule"="Security"
"Retention"=dword:00093a80
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
"Sources"=hex(7):53,00,70,00,6f,00,6f,00,6c,00,65,00,72,00,00,00,53,00,65,00,\
63,00,75,00,72,00,69,00,74,00,79,00,20,00,41,00,63,00,63,00,6f,00,75,00,6e,\
00,74,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,00,00,53,00,43,00,\
20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,00,00,4e,00,65,00,74,00,44,\
00,44,00,45,00,20,00,4f,00,62,00,6a,00,65,00,63,00,74,00,00,00,4c,00,53,00,\
41,00,00,00,44,00,53,00,00,00,53,00,65,00,63,00,75,00,72,00,69,00,74,00,79,\
00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\DS]
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\DS\ObjectNames]
"Directory Service Object"=dword:00001e00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA]
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA\ObjectNames]
"PolicyObject"=dword:00001600
"SecretObject"=dword:00001610
"TrustedDomainObject"=dword:00001620
"UserAccountObject"=dword:00001630
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\NetDDE Object]
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\NetDDE Object\ObjectNames]
"DDE Share"=dword:00001d00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\SC Manager]
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\SC Manager\ObjectNames]
"SC_MANAGER Object"=dword:00001c00
"SERVICE Object"=dword:00001c10
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security]
"CategoryCount"=dword:00000009
"CategoryMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,4d,00,73,00,41,00,75,00,64,00,69,00,74,00,45,00,2e,00,64,00,6c,00,\
6c,00,00,00
"GuidMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\
6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\
00,4e,00,74,00,4d,00,61,00,72,00,74,00,61,00,2e,00,64,00,6c,00,6c,00,00,00
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,4d,00,73,00,41,00,75,00,64,00,69,00,74,00,45,00,2e,00,64,00,6c,00,6c,\
00,3b,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,\
25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,70,\
00,32,00,72,00,65,00,73,00,2e,00,64,00,6c,00,6c,00,3b,00,25,00,53,00,79,00,\
73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,\
00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,70,00,33,00,72,00,65,00,73,00,\
2e,00,64,00,6c,00,6c,00,00,00
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"TypesSupported"=dword:0000001c
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames]
"Channel"=dword:00001400
"Desktop"=dword:00001a10
"Device"=dword:00001100
"Directory"=dword:00001110
"Event"=dword:00001120
"EventPair"=dword:00001130
"File"=dword:00001140
"IoCompletion"=dword:00001300
"Job"=dword:00001410
"Key"=dword:00001150
"MailSlot"=dword:00001140
"Mutant"=dword:00001160
"NamedPipe"=dword:00001140
"Port"=dword:00001170
"Process"=dword:00001180
"Profile"=dword:00001190
"Section"=dword:000011a0
"Semaphore"=dword:000011b0
"SymbolicLink"=dword:000011c0
"Thread"=dword:000011d0
"Timer"=dword:000011e0
"Token"=dword:000011f0
"Type"=dword:00001200
"WaitablePort"=dword:00001170
"WindowStation"=dword:00001a00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager]
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager\ObjectNames]
"SAM_ALIAS"=dword:00001530
"SAM_DOMAIN"=dword:00001510
"SAM_GROUP"=dword:00001520
"SAM_SERVER"=dword:00001500
"SAM_USER"=dword:00001540
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler]
"ParameterMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,\
6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,4d,00,73,00,4f,00,62,00,6a,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler\ObjectNames]
"Document"=dword:00001b20
"Printer"=dword:00001b10
"Server"=dword:00001b00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System]
"DisplayNameFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\
6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\
00,65,00,6c,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"DisplayNameID"=dword:00000102
"File"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,00,\
6f,00,6e,00,66,00,69,00,67,00,5c,00,53,00,79,00,73,00,45,00,76,00,65,00,6e,\
00,74,00,2e,00,45,00,76,00,74,00,00,00
"MaxSize"=dword:00080000
"PrimaryModule"="System"
"Retention"=dword:00093a80
"Sources"=hex(7):57,00,5a,00,43,00,53,00,56,00,43,00,00,00,57,00,6f,00,72,00,\
6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,00,00,57,00,6d,00,69,00,00,\
00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,4d,00,65,00,64,00,69,00,61,00,\
00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,53,00,63,00,72,00,69,\
00,70,00,74,00,20,00,48,00,6f,00,73,00,74,00,00,00,57,00,69,00,6e,00,64,00,\
6f,00,77,00,73,00,20,00,49,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,65,00,72,\
00,20,00,33,00,2e,00,31,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,\
20,00,46,00,69,00,6c,00,65,00,20,00,50,00,72,00,6f,00,74,00,65,00,63,00,74,\
00,69,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,61,00,63,00,70,00,63,00,69,00,\
00,00,57,00,69,00,6e,00,33,00,32,00,6b,00,00,00,77,00,65,00,69,00,74,00,65,\
00,6b,00,70,00,39,00,5f,00,64,00,65,00,74,00,65,00,63,00,74,00,00,00,77,00,\
64,00,76,00,67,00,61,00,5f,00,64,00,65,00,74,00,65,00,63,00,74,00,00,00,77,\
00,61,00,6e,00,61,00,74,00,77,00,00,00,57,00,33,00,32,00,54,00,69,00,6d,00,\
65,00,00,00,76,00,73,00,64,00,61,00,74,00,61,00,6e,00,74,00,00,00,56,00,67,\
00,61,00,53,00,61,00,76,00,65,00,00,00,75,00,72,00,76,00,70,00,6e,00,64,00,\
72,00,76,00,00,00,55,00,50,00,53,00,00,00,75,00,6c,00,74,00,72,00,61,00,36,\
00,36,00,00,00,75,00,64,00,66,00,73,00,00,00,74,00,72,00,69,00,64,00,33,00,\
64,00,00,00,54,00,65,00,72,00,6d,00,53,00,65,00,72,00,76,00,69,00,63,00,65,\
00,00,00,74,00,64,00,69,00,00,00,54,00,43,00,50,00,4d,00,6f,00,6e,00,00,00,\
54,00,63,00,70,00,69,00,70,00,00,00,73,00,79,00,6d,00,5f,00,68,00,69,00,00,\
00,73,00,79,00,6d,00,63,00,38,00,78,00,78,00,00,00,73,00,79,00,6d,00,63,00,\
38,00,31,00,30,00,00,00,53,00,74,00,69,00,6c,00,6c,00,49,00,6d,00,61,00,67,\
00,65,00,00,00,53,00,72,00,76,00,00,00,73,00,70,00,61,00,72,00,72,00,6f,00,\
77,00,00,00,73,00,6e,00,64,00,62,00,6c,00,73,00,74,00,00,00,53,00,69,00,6d,\
00,62,00,61,00,64,00,00,00,73,00,67,00,6c,00,66,00,62,00,00,00,73,00,66,00,\
6c,00,6f,00,70,00,70,00,79,00,00,00,53,00,65,00,72,00,76,00,69,00,63,00,65,\
00,20,00,43,00,6f,00,6e,00,74,00,72,00,6f,00,6c,00,20,00,4d,00,61,00,6e,00,\
61,00,67,00,65,00,72,00,00,00,53,00,65,00,72,00,76,00,65,00,72,00,00,00,73,\
00,65,00,72,00,69,00,61,00,6c,00,00,00,73,00,63,00,73,00,69,00,70,00,6f,00,\
72,00,74,00,00,00,53,00,63,00,68,00,65,00,64,00,75,00,6c,00,65,00,00,00,53,\
00,63,00,68,00,61,00,6e,00,6e,00,65,00,6c,00,00,00,53,00,43,00,61,00,72,00,\
64,00,53,00,76,00,72,00,00,00,73,00,61,00,76,00,72,00,74,00,00,00,53,00,61,\
00,76,00,65,00,20,00,44,00,75,00,6d,00,70,00,00,00,53,00,41,00,4d,00,00,00,\
73,00,33,00,6c,00,65,00,67,00,61,00,63,00,79,00,5f,00,64,00,65,00,74,00,65,\
00,63,00,74,00,00,00,52,00,53,00,56,00,50,00,00,00,52,00,65,00,6d,00,6f,00,\
76,00,61,00,62,00,6c,00,65,00,20,00,53,00,74,00,6f,00,72,00,61,00,67,00,65,\
00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,52,00,65,00,6d,00,\
6f,00,74,00,65,00,41,00,63,00,63,00,65,00,73,00,73,00,00,00,72,00,65,00,64,\
00,62,00,6f,00,6f,00,6b,00,00,00,52,00,64,00,62,00,73,00,73,00,00,00,52,00,\
61,00,73,00,4d,00,61,00,6e,00,00,00,52,00,61,00,73,00,41,00,75,00,74,00,6f,\
00,00,00,71,00,76,00,5f,00,64,00,65,00,74,00,65,00,63,00,74,00,00,00,71,00,\
6c,00,32,00,31,00,30,00,30,00,00,00,71,00,6c,00,31,00,32,00,34,00,30,00,00,\
00,71,00,6c,00,31,00,30,00,77,00,6e,00,74,00,00,00,71,00,6c,00,31,00,30,00,\
38,00,30,00,00,00,50,00,78,00,48,00,65,00,6c,00,70,00,32,00,30,00,00,00,50,\
00,72,00,69,00,6e,00,74,00,00,00,50,00,70,00,74,00,70,00,4d,00,69,00,6e,00,\
69,00,70,00,6f,00,72,00,74,00,00,00,50,00,6f,00,6c,00,69,00,63,00,79,00,41,\
00,67,00,65,00,6e,00,74,00,00,00,70,00,63,00,6d,00,63,00,69,00,61,00,00,00,\
70,00,63,00,69,00,69,00,64,00,65,00,00,00,70,00,63,00,69,00,00,00,70,00,61,\
00,72,00,76,00,64,00,6d,00,00,00,70,00,61,00,72,00,70,00,6f,00,72,00,74,00,\
00,00,70,00,61,00,72,00,61,00,6c,00,6c,00,65,00,6c,00,00,00,4f,00,53,00,50,\
00,46,00,4d,00,69,00,62,00,00,00,4f,00,53,00,50,00,46,00,00,00,6e,00,75,00,\
6c,00,6c,00,00,00,4e,00,74,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,50,\
00,61,00,63,00,6b,00,00,00,4e,00,54,00,4d,00,53,00,00,00,6e,00,74,00,66,00,\
73,00,00,00,6e,00,70,00,66,00,73,00,00,00,4e,00,65,00,74,00,6c,00,6f,00,67,\
00,6f,00,6e,00,00,00,4e,00,65,00,74,00,44,00,44,00,45,00,00,00,4e,00,65,00,\
74,00,42,00,54,00,00,00,4e,00,65,00,74,00,42,00,49,00,4f,00,53,00,00,00,4e,\
00,64,00,69,00,73,00,57,00,61,00,6e,00,00,00,6e,00,64,00,69,00,73,00,00,00,\
6e,00,63,00,72,00,63,00,37,00,31,00,30,00,00,00,4d,00,75,00,70,00,00,00,6d,\
00,73,00,66,00,73,00,00,00,6d,00,73,00,61,00,64,00,6c,00,69,00,62,00,00,00,\
4d,00,72,00,78,00,53,00,6d,00,62,00,00,00,6d,00,72,00,61,00,69,00,64,00,33,\
00,35,00,78,00,00,00,6d,00,6f,00,75,00,63,00,6c,00,61,00,73,00,73,00,00,00,\
4d,00,6f,00,64,00,65,00,6d,00,00,00,6d,00,67,00,61,00,5f,00,64,00,65,00,74,\
00,65,00,63,00,74,00,00,00,4c,00,73,00,61,00,53,00,72,00,76,00,00,00,6c,00,\
70,00,36,00,6e,00,64,00,73,00,33,00,35,00,00,00,4c,00,6d,00,48,00,6f,00,73,\
00,74,00,73,00,00,00,4c,00,44,00,4d,00,53,00,00,00,4c,00,44,00,4d,00,00,00,\
6c,00,62,00,72,00,74,00,66,00,64,00,63,00,00,00,4b,00,65,00,72,00,62,00,65,\
00,72,00,6f,00,73,00,00,00,6b,00,62,00,64,00,63,00,6c,00,61,00,73,00,73,00,\
00,00,69,00,73,00,61,00,70,00,6e,00,70,00,00,00,49,00,50,00,58,00,53,00,41,\
00,50,00,00,00,49,00,50,00,58,00,52,00,6f,00,75,00,74,00,65,00,72,00,4d,00,\
61,00,6e,00,61,00,67,00,65,00,72,00,00,00,49,00,50,00,58,00,52,00,49,00,50,\
00,00,00,49,00,50,00,58,00,43,00,50,00,00,00,69,00,70,00,73,00,72,00,61,00,\
69,00,64,00,6e,00,00,00,49,00,50,00,53,00,45,00,43,00,00,00,49,00,50,00,52,\
00,6f,00,75,00,74,00,65,00,72,00,4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,\
00,00,49,00,50,00,52,00,49,00,50,00,32,00,00,00,49,00,50,00,4e,00,41,00,54,\
00,48,00,4c,00,50,00,00,00,49,00,50,00,42,00,4f,00,4f,00,54,00,50,00,00,00,\
49,00,6e,00,74,00,65,00,72,00,6e,00,65,00,74,00,20,00,45,00,78,00,70,00,6c,\
00,6f,00,72,00,65,00,72,00,20,00,36,00,00,00,69,00,6e,00,74,00,65,00,6c,00,\
69,00,64,00,65,00,00,00,69,00,6e,00,69,00,39,00,31,00,30,00,75,00,00,00,69,\
00,38,00,30,00,34,00,32,00,70,00,72,00,74,00,00,00,66,00,74,00,64,00,69,00,\
73,00,6b,00,00,00,66,00,73,00,5f,00,72,00,65,00,63,00,00,00,66,00,6c,00,70,\
00,79,00,64,00,69,00,73,00,6b,00,00,00,66,00,6c,00,61,00,73,00,68,00,70,00,\
6e,00,74,00,00,00,66,00,69,00,72,00,65,00,70,00,6f,00,72,00,74,00,00,00,46,\
00,69,00,70,00,73,00,00,00,66,00,64,00,63,00,00,00,66,00,64,00,31,00,36,00,\
5f,00,37,00,30,00,30,00,00,00,66,00,61,00,73,00,74,00,66,00,61,00,74,00,00,\
00,65,00,76,00,65,00,6e,00,74,00,6c,00,6f,00,67,00,00,00,65,00,74,00,34,00,\
30,00,30,00,30,00,5f,00,64,00,65,00,74,00,65,00,63,00,74,00,00,00,65,00,66,\
00,73,00,00,00,44,00,6e,00,73,00,63,00,61,00,63,00,68,00,65,00,00,00,44,00,\
6e,00,73,00,61,00,70,00,69,00,00,00,64,00,6d,00,69,00,6f,00,00,00,64,00,6d,\
00,62,00,6f,00,6f,00,74,00,00,00,44,00,69,00,73,00,74,00,72,00,69,00,62,00,\
75,00,74,00,65,00,64,00,20,00,4c,00,69,00,6e,00,6b,00,20,00,54,00,72,00,61,\
00,63,00,6b,00,69,00,6e,00,67,00,20,00,43,00,6c,00,69,00,65,00,6e,00,74,00,\
00,00,64,00,69,00,73,00,6b,00,70,00,65,00,72,00,66,00,00,00,64,00,69,00,73,\
00,6b,00,00,00,44,00,69,00,72,00,65,00,63,00,74,00,58,00,00,00,44,00,68,00,\
63,00,70,00,00,00,44,00,66,00,73,00,53,00,76,00,63,00,00,00,44,00,66,00,73,\
00,44,00,72,00,69,00,76,00,65,00,72,00,00,00,64,00,65,00,63,00,6b,00,7a,00,\
70,00,73,00,78,00,00,00,44,00,43,00,4f,00,4d,00,00,00,64,00,61,00,63,00,39,\
00,36,00,30,00,6e,00,74,00,00,00,63,00,70,00,71,00,66,00,77,00,73,00,32,00,\
65,00,00,00,63,00,70,00,71,00,66,00,63,00,61,00,6c,00,6d,00,00,00,63,00,70,\
00,71,00,61,00,72,00,72,00,79,00,32,00,00,00,63,00,70,00,71,00,61,00,72,00,\
72,00,61,00,79,00,00,00,63,00,69,00,72,00,72,00,75,00,73,00,5f,00,64,00,65,\
00,74,00,65,00,63,00,74,00,00,00,63,00,68,00,61,00,6e,00,67,00,65,00,72,00,\
00,00,63,00,64,00,72,00,6f,00,6d,00,00,00,63,00,64,00,66,00,73,00,00,00,63,\
00,64,00,61,00,75,00,64,00,69,00,6f,00,00,00,63,00,64,00,32,00,30,00,78,00,\
72,00,6e,00,74,00,00,00,62,00,75,00,73,00,6c,00,6f,00,67,00,69,00,63,00,00,\
00,42,00,72,00,6f,00,77,00,73,00,65,00,72,00,00,00,42,00,49,00,54,00,53,00,\
00,00,62,00,65,00,65,00,70,00,00,00,41,00,75,00,74,00,6f,00,6d,00,61,00,74,\
00,69,00,63,00,20,00,55,00,70,00,64,00,61,00,74,00,65,00,73,00,00,00,41,00,\
74,00,6d,00,61,00,72,00,70,00,63,00,00,00,61,00,74,00,69,00,5f,00,64,00,65,\
00,74,00,65,00,63,00,74,00,00,00,61,00,74,00,64,00,69,00,73,00,6b,00,00,00,\
61,00,74,00,61,00,70,00,69,00,00,00,41,00,73,00,79,00,6e,00,63,00,4d,00,61,\
00,63,00,00,00,61,00,73,00,63,00,33,00,35,00,35,00,30,00,00,00,61,00,73,00,\
63,00,33,00,33,00,35,00,30,00,70,00,00,00,61,00,73,00,63,00,00,00,41,00,70,\
00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,50,00,6f,00,\
70,00,75,00,70,00,00,00,61,00,6d,00,73,00,69,00,6e,00,74,00,00,00,61,00,6d,\
00,69,00,30,00,6e,00,74,00,00,00,41,00,6c,00,65,00,72,00,74,00,65,00,72,00,\
00,00,61,00,69,00,63,00,37,00,38,00,78,00,78,00,00,00,61,00,69,00,63,00,37,\
00,38,00,75,00,32,00,00,00,61,00,69,00,63,00,31,00,31,00,36,00,78,00,00,00,\
61,00,68,00,61,00,31,00,35,00,34,00,78,00,00,00,61,00,64,00,70,00,75,00,31,\
00,36,00,30,00,6d,00,00,00,41,00,44,00,4d,00,39,00,58,00,00,00,61,00,63,00,\
70,00,69,00,65,00,63,00,00,00,61,00,63,00,70,00,69,00,00,00,61,00,62,00,70,\
00,34,00,38,00,30,00,6e,00,35,00,00,00,61,00,62,00,69,00,6f,00,73,00,64,00,\
73,00,6b,00,00,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\abiosdsk]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\
00,00,00
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\abp480n5]
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,49,00,6f,00,4c,00,6f,00,67,00,4d,00,73,00,67,00,2e,00,64,00,6c,00,6c,\