Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Windows Registry Editor Version 5.00
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
- "AutoRestartShell"=dword:00000001
- "LegalNoticeCaption"=""
- "LegalNoticeText"=""
- "PowerdownAfterShutdown"="0"
- "ReportBootOk"="1"
- "Shell"="Explorer.exe"
- "ShutdownWithoutLogon"="0"
- "System"=""
- "Userinit"="C:\\WINNT\\system32\\userinit.exe,"
- "VmApplet"="rundll32 shell32,Control_RunDLL \"sysdm.cpl\""
- "SfcQuota"=dword:ffffffff
- "allocatecdroms"="0"
- "allocatedasd"="0"
- "allocatefloppies"="0"
- "cachedlogonscount"=dword:00000000
- "forceunlocklogon"=dword:00000000
- "passwordexpirywarning"=dword:0000000e
- "scremoveoption"="0"
- "DisableCAD"=dword:00000000
- "AllowMultipleTSSessions"=dword:00000000
- "UIHost"=hex(2):6c,00,6f,00,67,00,6f,00,6e,00,75,00,69,00,2e,00,65,00,78,00,65,\
- 00,00,00
- "AutoLogonCount"=dword:00000008
- "DebugServerCommand"="no"
- "SFCDisable"=dword:00000000
- "WinStationsDisabled"="0"
- "LogonType"=dword:00000000
- "HibernationPreviouslyEnabled"=dword:00000001
- "CachePrimaryDomain"="IC"
- "DCacheUpdate"=hex:70,81,2b,5b,14,76,c4,01
- "ShowLogonOptions"=dword:00000001
- "AltDefaultUserName"="administrator"
- "Welcome"="- %COMPUTERNAME%"
- "DeleteRoamingCache"=dword:00000001
- "DefaultUserName"="opacauto"
- "DefaultDomainName"="IC"
- "DisableLockWorkstation"=dword:00000000
- "DefaultPassword"="HYLotC?"
- "AutoAdminLogon"="1"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\DomainCache]
- "ADMINISTRATION"="ad.ic.ac.uk"
- "BIO1"="bio.ic.ac.uk"
- "BIOENGINEERING"="bg.ic.ac.uk"
- "CC"=""
- "CCBACKUP"=""
- "CH1"="ch.ic.ac.uk"
- "CV"="cv.ic.ac.uk"
- "IC"="ic.ac.uk"
- "ICT"="ict.ic.ac.uk"
- "PH1"="ph.ic.ac.uk"
- "PHAD"="ad.ph.ic.ac.uk"
- "TH1"="th.ic.ac.uk"
- "TP"="tp.ph.ic.ac.uk"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}]
- @="Wireless"
- "ProcessGroupPolicy"="ProcessWIRELESSPolicy"
- "DllName"=hex(2):67,00,70,00,74,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,\
- 00,00
- "NoUserPolicy"=dword:00000001
- "NoGPOListChanges"=dword:00000001
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}]
- @="Folder Redirection"
- "ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
- "DllName"=hex(2):66,00,64,00,65,00,70,00,6c,00,6f,00,79,00,2e,00,64,00,6c,00,\
- 6c,00,00,00
- "NoMachinePolicy"=dword:00000001
- "NoSlowLink"=dword:00000001
- "PerUserLocalSettings"=dword:00000001
- "NoGPOListChanges"=dword:00000000
- "NoBackgroundPolicy"=dword:00000000
- "GenerateGroupPolicy"="GenerateGroupPolicy"
- "EventSources"=hex(7):28,00,46,00,6f,00,6c,00,64,00,65,00,72,00,20,00,52,00,65,\
- 00,64,00,69,00,72,00,65,00,63,00,74,00,69,00,6f,00,6e,00,2c,00,41,00,70,00,\
- 70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,29,00,00,00,00,00
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{35378EAC-683F-11D2-A89A-00C04FBBCFA2}]
- "Status"=dword:00000000
- "RsopStatus"=dword:00000000
- "LastPolicyTime"=dword:00c53db2
- "PrevSlowLink"=dword:00000000
- "PrevRsopLogging"=dword:00000001
- "ForceRefreshFG"=dword:00000000
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}]
- @="Microsoft Disk Quota"
- "NoMachinePolicy"=dword:00000000
- "NoUserPolicy"=dword:00000001
- "NoSlowLink"=dword:00000001
- "NoBackgroundPolicy"=dword:00000001
- "NoGPOListChanges"=dword:00000001
- "PerUserLocalSettings"=dword:00000000
- "RequiresSuccessfulRegistry"=dword:00000001
- "EnableAsynchronousProcessing"=dword:00000000
- "DllName"=hex(2):64,00,73,00,6b,00,71,00,75,00,6f,00,74,00,61,00,2e,00,64,00,\
- 6c,00,6c,00,00,00
- "ProcessGroupPolicy"="ProcessGroupPolicy"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}]
- @="QoS Packet Scheduler"
- "ProcessGroupPolicy"="ProcessPSCHEDPolicy"
- "DllName"=hex(2):67,00,70,00,74,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,\
- 00,00
- "NoUserPolicy"=dword:00000001
- "NoGPOListChanges"=dword:00000001
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}]
- @="Scripts"
- "ProcessGroupPolicy"="ProcessScriptsGroupPolicy"
- "ProcessGroupPolicyEx"="ProcessScriptsGroupPolicyEx"
- "GenerateGroupPolicy"="GenerateScriptsGroupPolicy"
- "DllName"=hex(2):67,00,70,00,74,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,\
- 00,00
- "NoSlowLink"=dword:00000001
- "NoGPOListChanges"=dword:00000001
- "NotifyLinkTransition"=dword:00000001
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}]
- "ProcessGroupPolicy"="SceProcessSecurityPolicyGPO"
- "GenerateGroupPolicy"="SceGenerateGroupPolicy"
- "ExtensionRsopPlanningDebugLevel"=dword:00000001
- "ProcessGroupPolicyEx"="SceProcessSecurityPolicyGPOEx"
- "ExtensionDebugLevel"=dword:00000001
- "DllName"=hex(2):73,00,63,00,65,00,63,00,6c,00,69,00,2e,00,64,00,6c,00,6c,00,\
- 00,00
- @="Security"
- "NoUserPolicy"=dword:00000001
- "NoGPOListChanges"=dword:00000001
- "EnableAsynchronousProcessing"=dword:00000001
- "MaxNoGPOListChangesInterval"=dword:000003c0
- "PreviousPolicyAreas"=dword:00000060
- "Status"=dword:00000000
- "RsopStatus"=dword:00000000
- "LastPolicyTime"=dword:00c541c1
- "PrevSlowLink"=dword:00000000
- "PrevRsopLogging"=dword:00000001
- "ForceRefreshFG"=dword:00000000
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}]
- "ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
- "GenerateGroupPolicy"="GenerateGroupPolicy"
- "ProcessGroupPolicy"="ProcessGroupPolicy"
- "DllName"=hex(2):69,00,65,00,64,00,6b,00,63,00,73,00,33,00,32,00,2e,00,64,00,\
- 6c,00,6c,00,00,00
- @="Internet Explorer Branding"
- "NoSlowLink"=dword:00000001
- "NoBackgroundPolicy"=dword:00000000
- "NoGPOListChanges"=dword:00000001
- "NoMachinePolicy"=dword:00000001
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}]
- "ProcessGroupPolicy"="SceProcessEFSRecoveryGPO"
- "DllName"=hex(2):73,00,63,00,65,00,63,00,6c,00,69,00,2e,00,64,00,6c,00,6c,00,\
- 00,00
- @="EFS recovery"
- "NoUserPolicy"=dword:00000001
- "NoGPOListChanges"=dword:00000001
- "RequiresSuccessfulRegistry"=dword:00000001
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}]
- @="Software Installation"
- "DllName"=hex(2):61,00,70,00,70,00,6d,00,67,00,6d,00,74,00,73,00,2e,00,64,00,\
- 6c,00,6c,00,00,00
- "ProcessGroupPolicyEx"="ProcessGroupPolicyObjectsEx"
- "GenerateGroupPolicy"="GenerateGroupPolicy"
- "NoBackgroundPolicy"=dword:00000000
- "RequiresSucessfulRegistry"=dword:00000000
- "NoSlowLink"=dword:00000001
- "PerUserLocalSettings"=dword:00000001
- "EventSources"=hex(7):28,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,\
- 00,6f,00,6e,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,6d,00,65,00,6e,00,\
- 74,00,2c,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,\
- 00,29,00,00,00,28,00,4d,00,73,00,69,00,49,00,6e,00,73,00,74,00,61,00,6c,00,\
- 6c,00,65,00,72,00,2c,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,\
- 00,6f,00,6e,00,29,00,00,00,00,00
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}]
- @="IP Security"
- "ProcessGroupPolicy"="ProcessIPSECPolicy"
- "DllName"=hex(2):67,00,70,00,74,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,\
- 00,00
- "NoUserPolicy"=dword:00000001
- "NoGPOListChanges"=dword:00000001
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
- "Asynchronous"=dword:00000000
- "Impersonate"=dword:00000000
- "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
- 6c,00,00,00
- "Logoff"="ChainWlxLogoffEvent"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
- "Asynchronous"=dword:00000000
- "Impersonate"=dword:00000000
- "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
- 6c,00,6c,00,00,00
- "Logoff"="CryptnetWlxLogoffEvent"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
- "DLLName"="cscdll.dll"
- "Logon"="WinlogonLogonEvent"
- "Logoff"="WinlogonLogoffEvent"
- "ScreenSaver"="WinlogonScreenSaverEvent"
- "Startup"="WinlogonStartupEvent"
- "Shutdown"="WinlogonShutdownEvent"
- "StartShell"="WinlogonStartShellEvent"
- "Impersonate"=dword:00000000
- "Asynchronous"=dword:00000001
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
- "StartShell"="NavStartShellEvent"
- "DllName"="C:\\WINNT\\System32\\NavLogon.dll"
- "Logoff"="NavLogoffEvent"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
- "DLLName"="wlnotify.dll"
- "Logon"="SCardStartCertProp"
- "Logoff"="SCardStopCertProp"
- "Lock"="SCardSuspendCertProp"
- "Unlock"="SCardResumeCertProp"
- "Enabled"=dword:00000001
- "Impersonate"=dword:00000001
- "Asynchronous"=dword:00000001
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
- "Logoff"="WLEventLogoff"
- "Impersonate"=dword:00000000
- "Asynchronous"=dword:00000001
- "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
- 6c,00,6c,00,00,00
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
- "DLLName"="WlNotify.dll"
- "Lock"="SensLockEvent"
- "Logon"="SensLogonEvent"
- "Logoff"="SensLogoffEvent"
- "Safe"=dword:00000001
- "MaxWait"=dword:00000258
- "StartScreenSaver"="SensStartScreenSaverEvent"
- "StopScreenSaver"="SensStopScreenSaverEvent"
- "Startup"="SensStartupEvent"
- "Shutdown"="SensShutdownEvent"
- "StartShell"="SensStartShellEvent"
- "PostShell"="SensPostShellEvent"
- "Disconnect"="SensDisconnectEvent"
- "Reconnect"="SensReconnectEvent"
- "Unlock"="SensUnlockEvent"
- "Impersonate"=dword:00000001
- "Asynchronous"=dword:00000001
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
- "Asynchronous"=dword:00000000
- "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
- 6c,00,6c,00,00,00
- "Impersonate"=dword:00000000
- "Logoff"="TSEventLogoff"
- "Logon"="TSEventLogon"
- "PostShell"="TSEventPostShell"
- "Shutdown"="TSEventShutdown"
- "StartShell"="TSEventStartShell"
- "Startup"="TSEventStartup"
- "MaxWait"=dword:00000258
- "Reconnect"="TSEventReconnect"
- "Disconnect"="TSEventDisconnect"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
- "DLLName"="wlnotify.dll"
- "Logon"="RegisterTicketExpiredNotificationEvent"
- "Logoff"="UnregisterTicketExpiredNotificationEvent"
- "Impersonate"=dword:00000001
- "Asynchronous"=dword:00000001
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList]
- "HelpAssistant"=dword:00000000
- "TsInternetUser"=dword:00000000
- "SQLAgentCmdExec"=dword:00000000
- "NetShowServices"=dword:00000000
- "IWAM_"=dword:00010000
- "IUSR_"=dword:00010000
- "VUSR_"=dword:00010000
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Credentials]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement