de nbo » 15 Juin 2006, 18:26
Bonjour,
Merci pour vos réponses, n'ayant pas beaucoup de temps pour m'occuper de mon ordinateur en panne, j'ai mis quelque temps à répondre.
Voici le contenus des fichiers demandés par nickW.
Merci encore pour votre aide.
c:\hklm-inimapping-060604.txt
*************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Clock.ini]
@="#USR:Software\\Microsoft\\Clock"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\control.ini]
"Color Schemes"="#USR:Control Panel\\Color Schemes"
"Current"="#USR:Control Panel\\Current"
"Custom Colors"="#USR:Control Panel\\Custom Colors"
"don't load"="USR:Control Panel\\don't load"
"drivers.desc"="SYS:Microsoft\\Windows NT\\CurrentVersion\\drivers.desc"
"MMCPL"="USR:Control Panel\\MMCPL"
"Patterns"="#USR:Control Panel\\Patterns"
"related.desc"="SYS:Microsoft\\Windows NT\\CurrentVersion\\related.desc"
"Screen Saver.3DFlowerBox"="USR:Control Panel\\Screen Saver.3DFlowerBox"
"Screen Saver.3DFlyingObj"="USR:Control Panel\\Screen Saver.3DFlyingObj"
"Screen Saver.3DMaze"="USR:Control Panel\\Screen Saver.3DMaze"
"Screen Saver.3DPipes"="USR:Control Panel\\Screen Saver.3DPipes"
"Screen Saver.3DText"="USR:Control Panel\\Screen Saver.3DText"
"Screen Saver.Bezier"="USR:Control Panel\\Screen Saver.Bezier"
"Screen Saver.Marquee"="#USR:Control Panel\\Screen Saver.Marquee"
"Screen Saver.Mystify"="#USR:Control Panel\\Screen Saver.Mystify"
"Screen Saver.Stars"="#USR:Control Panel\\Screen Saver.Stars"
"Userinstallable.drivers"="SYS:Microsoft\\Windows NT\\CurrentVersion\\Userinstallable.drivers"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\ImageFileExecutionOptions.ini]
@="SYS:Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\KeyboardLayout.ini]
@=""
"Preload"="USR:Keyboard Layout\\Preload"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\KeyboardLayout.ini\Keyboard Layout]
@="\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Keyboard Layout"
"Active"="USR:Keyboard Layout"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\KeyboardLayout.ini\Substitutes]
@="USR:Keyboard Layout\\Substitutes"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\msacm.ini]
@="USR:Software\\Microsoft\\Multimedia\\Audio Compression Manager"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Ntbackup.ini]
@="#USR:Software\\Microsoft\\Ntbackup"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\ntnet.ini]
@="USR:Software\\Microsoft\\Windows NT\\CurrentVersion\\Network"
"Shared Parameters"="SYS:Microsoft\\Windows NT\\CurrentVersion\\Network\\World Full Access Shared Parameters"
"SMAddOns"="SYS:Microsoft\\Windows NT\\CurrentVersion\\Network\\SMAddOns"
"UMAddOns"="SYS:Microsoft\\Windows NT\\CurrentVersion\\Network\\UMAddOns"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\regedt32.ini]
@="USR:Software\\Microsoft\\RegEdt32"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\schdpl32.ini]
@="USR:Software\\Microsoft\\Schedule+"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini]
"boot.description"="SYS:Microsoft\\Windows NT\\CurrentVersion\\WOW\\boot.description"
"drivers"="#SYS:Microsoft\\Windows NT\\CurrentVersion\\drivers"
"drivers32"="SYS:Microsoft\\Windows NT\\CurrentVersion\\Drivers32"
"keyboard"="SYS:Microsoft\\Windows NT\\CurrentVersion\\WOW\\keyboard"
"MCI"="SYS:Microsoft\\Windows NT\\CurrentVersion\\MCI"
"MCI32"="SYS:Microsoft\\Windows NT\\CurrentVersion\\MCI32"
"msacm.drv"="USR:Software\\Microsoft\\Multimedia\\Sound Mapper"
"NonWindowsApp"="SYS:Microsoft\\Windows NT\\CurrentVersion\\WOW\\NonWindowsApp"
"standard"="SYS:Microsoft\\Windows NT\\CurrentVersion\\WOW\\standard"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\boot]
@="SYS:Microsoft\\Windows NT\\CurrentVersion\\WOW\\boot"
"ScreenSaverActive"="USR:Control Panel\\Desktop"
"ScreenSaverIsSecure"="USR:Control Panel\\Desktop"
"SCRNSAVE.EXE"="USR:Control Panel\\Desktop"
"Shell"="SYS:Microsoft\\Windows NT\\CurrentVersion\\Winlogon"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini]
"AeDebug"="SYS:Microsoft\\Windows NT\\CurrentVersion\\AeDebug"
"Clock"="#USR:Software\\Microsoft\\Clock"
"Colors"="#USR:Control Panel\\Colors"
"Compatibility"="#SYS:Microsoft\\Windows NT\\CurrentVersion\\Compatibility"
"Console"="USR:Console"
"Cursors"="#USR:Control Panel\\Cursors"
"DeskTop"="#USR:Control Panel\\Desktop"
"Devices"="USR:Software\\Microsoft\\Windows NT\\CurrentVersion\\Devices"
"Embedding"="!#SYS:Microsoft\\Windows NT\\CurrentVersion\\Embedding"
"Extensions"="#USR:Software\\Microsoft\\Windows NT\\CurrentVersion\\Extensions"
"Fonts"="#SYS:Microsoft\\Windows NT\\CurrentVersion\\Fonts"
"FontSubstitutes"="#SYS:Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes"
"GRE_Initialize"="SYS:Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize"
"Intl"="#USR:Control Panel\\International"
"IOProcs"="#USR:Control Panel\\IOProcs"
"MCI Extensions"="SYS:Microsoft\\Windows NT\\CurrentVersion\\MCI Extensions"
"ModuleCompatibility"="SYS:Microsoft\\Windows NT\\CurrentVersion\\ModuleCompatibility"
"MSCharMap"="#USR:Software\\Microsoft\\Charmap"
"Net_Files"="USR:Software\\Microsoft\\Windows NT\\CurrentVersion\\Network\\Persistent Connections"
"NWCS"="SYS:Microsoft\\Windows NT\\CurrentVersion\\NWCS"
"Ports"="SYS:Microsoft\\Windows NT\\CurrentVersion\\Ports"
"PrinterPorts"="USR:Software\\Microsoft\\Windows NT\\CurrentVersion\\PrinterPorts"
"Sounds"="#USR:Control Panel\\Sounds"
"TrueType"="#USR:Software\\Microsoft\\Windows NT\\CurrentVersion\\TrueType"
"Twain"="#USR:Software\\Microsoft\\Windows NT\\CurrentVersion\\Twain"
"Windows Help"="USR:Software\\Microsoft\\Windows Help"
"Winlogon"="SYS:Microsoft\\Windows NT\\CurrentVersion\\Winlogon"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Network]
@="USR:Software\\Microsoft\\Windows NT\\CurrentVersion\\Network\\Persistent Connections"
"ExpandLogonDomain"="SYS:Microsoft\\Windows NT\\CurrentVersion\\Network\\World Full Access Shared Parameters"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows]
@="USR:Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows"
"AppInit_DLLs"="SYS:Microsoft\\Windows NT\\CurrentVersion\\Windows"
"Beep"="#USR:Control Panel\\Sound"
"BorderWidth"="#USR:Control Panel\\Desktop\\WindowMetrics"
"CoolSwitch"="USR:Control Panel\\Desktop"
"CursorBlinkRate"="#USR:Control Panel\\Desktop"
"DefaultSeparateVDM"="\\Registry\\Machine\\System\\CurrentControlSet\\Control\\WOW"
"DeviceNotSelectedTimeout"="#SYS:Microsoft\\Windows NT\\CurrentVersion\\Windows"
"DoubleClickHeight"="#USR:Control Panel\\Mouse"
"DoubleClickSpeed"="#USR:Control Panel\\Mouse"
"DoubleClickWidth"="#USR:Control Panel\\Mouse"
"DragFullWindows"="USR:Control Panel\\Desktop"
"InitialKeyboardIndicators"="USR:Control Panel\\Keyboard"
"KeyboardDelay"="#USR:Control Panel\\Keyboard"
"KeyboardSpeed"="#USR:Control Panel\\Keyboard"
"LowPowerActive"="#USR:Control Panel\\Desktop"
"LowPowerTimeOut"="#USR:Control Panel\\Desktop"
"MouseSpeed"="#USR:Control Panel\\Mouse"
"MouseThreshold1"="#USR:Control Panel\\Mouse"
"MouseThreshold2"="#USR:Control Panel\\Mouse"
"PowerOffActive"="#USR:Control Panel\\Desktop"
"PowerOffTimeOut"="#USR:Control Panel\\Desktop"
"ScreenSaveActive"="#USR:Control Panel\\Desktop"
"ScreenSaveTimeOut"="#USR:Control Panel\\Desktop"
"SnapToDefaultButton"="#USR:Control Panel\\Mouse"
"Spooler"="#SYS:Microsoft\\Windows NT\\CurrentVersion\\Windows"
"swapdisk"="SYS:Microsoft\\Windows NT\\CurrentVersion\\Windows"
"SwapMouseButtons"="#USR:Control Panel\\Mouse"
"TransmissionRetryTimeout"="#SYS:Microsoft\\Windows NT\\CurrentVersion\\Windows"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\winfile.ini]
"AddOns"="SYS:Microsoft\\Windows NT\\CurrentVersion\\File Manager\\AddOns"
"Settings"="#USR:Software\\Microsoft\\File Manager\\Settings"
c:\hklm-winlogon-060604.txt
************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"AutoRestartShell"=dword:00000001
"DefaultDomainName"="ACER-E0C1F33C8C"
"DefaultUserName"="Nicolas"
"LegalNoticeCaption"=""
"LegalNoticeText"=""
"PowerdownAfterShutdown"="0"
"ReportBootOk"="1"
"Shell"="Explorer.exe"
"ShutdownWithoutLogon"="0"
"System"=""
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"VmApplet"="rundll32 shell32,Control_RunDLL \"sysdm.cpl\""
"SfcQuota"=dword:ffffffff
"allocatecdroms"="0"
"allocatedasd"="0"
"allocatefloppies"="0"
"cachedlogonscount"="10"
"forceunlocklogon"=dword:00000000
"passwordexpirywarning"=dword:0000000e
"scremoveoption"="0"
"AllowMultipleTSSessions"=dword:00000001
"UIHost"=hex(2):6c,00,6f,00,67,00,6f,00,6e,00,75,00,69,00,2e,00,65,00,78,00,65,\
00,00,00
"LogonType"=dword:00000001
"Background"="0 0 0"
"DebugServerCommand"="no"
"SFCDisable"=dword:00000000
"WinStationsDisabled"="0"
"HibernationPreviouslyEnabled"=dword:00000001
"ShowLogonOptions"=dword:00000001
"AltDefaultUserName"="Nicolas"
"AltDefaultDomainName"="ACER-E0C1F33C8C"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}]
@="Quota du disque Microsoft"
"NoMachinePolicy"=dword:00000000
"NoUserPolicy"=dword:00000001
"NoSlowLink"=dword:00000001
"NoBackgroundPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"PerUserLocalSettings"=dword:00000000
"RequiresSuccessfulRegistry"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000000
"DllName"=hex(2):64,00,73,00,6b,00,71,00,75,00,6f,00,74,00,61,00,2e,00,64,00,\
6c,00,6c,00,00,00
"ProcessGroupPolicy"="ProcessGroupPolicy"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}]
@="Mappage de zones Internet Explorer"
"DllName"=hex(2):69,00,65,00,64,00,6b,00,63,00,73,00,33,00,32,00,2e,00,64,00,\
6c,00,6c,00,00,00
"ProcessGroupPolicy"="ProcessGroupPolicyForZoneMap"
"NoGPOListChanges"=dword:00000001
"RequiresSucessfulRegistry"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}]
"ProcessGroupPolicy"="SceProcessSecurityPolicyGPO"
"GenerateGroupPolicy"="SceGenerateGroupPolicy"
"ExtensionRsopPlanningDebugLevel"=dword:00000001
"ProcessGroupPolicyEx"="SceProcessSecurityPolicyGPOEx"
"ExtensionDebugLevel"=dword:00000001
"DllName"=hex(2):73,00,63,00,65,00,63,00,6c,00,69,00,2e,00,64,00,6c,00,6c,00,\
00,00
@="Security"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
"MaxNoGPOListChangesInterval"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}]
"ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
"GenerateGroupPolicy"="GenerateGroupPolicy"
"ProcessGroupPolicy"="ProcessGroupPolicy"
"DllName"=hex(2):69,00,65,00,64,00,6b,00,63,00,73,00,33,00,32,00,2e,00,64,00,\
6c,00,6c,00,00,00
@="Personnalisation de Internet Explorer"
"NoSlowLink"=dword:00000001
"NoBackgroundPolicy"=dword:00000000
"NoGPOListChanges"=dword:00000001
"NoMachinePolicy"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}]
"ProcessGroupPolicy"="SceProcessEFSRecoveryGPO"
"DllName"=hex(2):73,00,63,00,65,00,63,00,6c,00,69,00,2e,00,64,00,6c,00,6c,00,\
00,00
@="EFS recovery"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"RequiresSuccessfulRegistry"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}]
@="Microsoft Offline Files"
"DllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,63,\
00,73,00,63,00,75,00,69,00,2e,00,64,00,6c,00,6c,00,00,00
"EnableAsynchronousProcessing"=dword:00000000
"NoBackgroundPolicy"=dword:00000000
"NoGPOListChanges"=dword:00000000
"NoMachinePolicy"=dword:00000000
"NoSlowLink"=dword:00000000
"NoUserPolicy"=dword:00000001
"PerUserLocalSettings"=dword:00000000
"ProcessGroupPolicy"="ProcessGroupPolicy"
"RequiresSuccessfulRegistry"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}]
@="Installation de logiciel"
"DllName"=hex(2):61,00,70,00,70,00,6d,00,67,00,6d,00,74,00,73,00,2e,00,64,00,\
6c,00,6c,00,00,00
"ProcessGroupPolicyEx"="ProcessGroupPolicyObjectsEx"
"GenerateGroupPolicy"="GenerateGroupPolicy"
"NoBackgroundPolicy"=dword:00000000
"RequiresSucessfulRegistry"=dword:00000000
"NoSlowLink"=dword:00000001
"PerUserLocalSettings"=dword:00000001
"EventSources"=hex(7):28,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,\
00,6f,00,6e,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,6d,00,65,00,6e,00,\
74,00,2c,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,\
00,29,00,00,00,28,00,4d,00,73,00,69,00,49,00,6e,00,73,00,74,00,61,00,6c,00,\
6c,00,65,00,72,00,2c,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,\
00,6f,00,6e,00,29,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
"DLLName"="Ati2evxx.dll"
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000001
"Lock"="AtiLockEvent"
"Logoff"="AtiLogoffEvent"
"Logon"="AtiLogonEvent"
"Disconnect"="AtiDisConnectEvent"
"Reconnect"="AtiReConnectEvent"
"Safe"=dword:00000000
"Shutdown"="AtiShutdownEvent"
"StartScreenSaver"="AtiStartScreenSaverEvent"
"StartShell"="AtiStartShellEvent"
"Startup"="AtiStartupEvent"
"StopScreenSaver"="AtiStopScreenSaverEvent"
"Unlock"="AtiUnLockEvent"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SCLogon]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList]
"HelpAssistant"=dword:00000000
"TsInternetUser"=dword:00000000
"SQLAgentCmdExec"=dword:00000000
"NetShowServices"=dword:00000000
"IWAM_"=dword:00010000
"IUSR_"=dword:00010000
"VUSR_"=dword:00010000
"ASPNET"=dword:00000000
c:\hkcu-expl-060604.txt
********************
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoDriveTypeAutoRun"=dword:00000091
c:\hkcu-syst-060604.txt
c:\hklm-expl-060604.txt
c:\hklm-syst-060604.txt
********************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001