Re: Reboot-loop problem with D-Link DWA-542 n-protocol wireless-carddrivers
On Sep 6, 10:31 am, "no_spam_paque...@uwo.ca" <paque...@uwo.ca> wrote:
> On Sep 6, 10:14 am, "John John (MVP)" <audetw...@nbnet.nb.ca> wrote:
>
>
>
> > Could you post the contents of the
> > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
> > key? Get the contents of the key when the problem is present.
>
> > John
>
> > no_spam_paque...@uwo.ca wrote:
> > > About four months ago I purchased a D-Link DWA-542 n-protocol wireless
> > > card for use with a legacy desktop whose motherboard I had just
> > > replaced with an identical “new” (sealed in original package) Intel
> > > D845GEBV2 replacement motherboard that I bought on eBay for a
> > > reasonable price. The motherboard works fine but I have had no end of
> > > difficulty with wireless card.
>
> > > Various problems, including the one that I am about to describe, led D-
> > > Link support to recommend that I exchange the originally purchased
> > > wireless card for an identical replacement which I did on July 22.
> > > With the latest D-Link driver available for that card at the time,
> > > this card worked well for about six weeks and then I began having the
> > > same problem that I've had with the original card, namely a continuous
> > > “reboot loop” starting just before the logon-authentication screen
> > > appears (i.e., after the XP splash screen and momentary blue-screen
> > > that follows it just before authentication). The only way to reboot
> > > once the DWA-542 driver is installed is to boot in safe mode and
> > > remove the driver. When I reinstall the latest D-Link drivers in
> > > normal mode the card works perfectly but I can't reboot. On the
> > > advice of D-Link technicians I have tried the DWA-542 in all of the
> > > available PCI slots and removed the only other PCI card. Changing
> > > slots makes no difference so this is obviously not some exotic IRQ
> > > problem. Furthermore, the reboot problem persists until the driver is
> > > removed whether or not the card is physically present.
>
> > > D-Link is now insisting that the problem lies in my BIOS settings. I
> > > have checked all potentially relevant BIOS settings and do not believe
> > > that to be the case. Specifically, all PCI slots are set to allow
> > > automatic IRQ allocation. Furthermore, this explanation overlooks the
> > > fact that the replacement card worked just fine for about six weeks.
>
> > > Here is what I have tried so far:
>
> > > 1. rotate the wireless card through all PCI slots and remove the only
> > > other PCI card in the machine;
> > > 2. completely remove antivirus software from machine, reinstall
> > > driver, and test for reboot loop—still there;
> > > 3. enable boot logging and examine boot log for clear indication of
> > > what is failing to install—all of the D-Link drivers are failing to
> > > load but so are a great many other things;
> > > 4. check the system display under event viewer for system events
> > > associated with failed boot-ups with D-Link drivers installed—the only
> > > promising system-error event was the failure of a PC-Cillin (my anti-
> > > virus software) driver to load which is why I removed PC-Cillin
> > > completely to see if the problem would go away but it didn't; the only
> > > other system error associated sometimes (only sometimes!) with the
> > > failed bootup is the following, about which I could find no useful
> > > information anywhere:
>
> > > Plug & Play service not ready. EFS server will not try to detect
> > > interrupted encryption/decryption operation(s).
>
> > > My next step will probably be to use msconfig to try to figure out by
> > > a process of elimination what is interfering with boot up when the
> > > wireless-card software is present but that could be a long and painful
> > > process—and may well take far more time than I have available to give
> > > to it. I'm really hoping someone has a better idea!
>
> > > I am leaning toward some sort of hardware (highly unlikely since
> > > physically removing the card makes no difference to the “reboot-loop”
> > > problem) or software conflict as an explanation but so far I just
> > > can't seem to get to the bottom of the problem and would welcome any
> > > suggestions to help me do so.
>
> > > Thanks in advance for any help!
>
> As below--also booting to safe mode with networking goes into reboot
> loop too!
>
> Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
> \CurrentVersion\Winlogon
> Class Name: <NO CLASS>
> Last Write Time: 9/6/2008 - 10:19 AM
> Value 0
> Name: System
> Type: REG_SZ
> Data:
>
> Value 1
> Name: AutoRestartShell
> Type: REG_DWORD
> Data: 0x1
>
> Value 2
> Name: Shell
> Type: REG_SZ
> Data: Explorer.exe
>
> Value 3
> Name: DefaultUserName
> Type: REG_SZ
> Data: Administrator
>
> Value 4
> Name: DefaultDomainName
> Type: REG_SZ
> Data: PAQUETTE_HOME
>
> Value 5
> Name: VmApplet
> Type: REG_SZ
> Data: rundll32 shell32,Control_RunDLL "sysdm.cpl"
>
> Value 6
> Name: Userinit
> Type: REG_SZ
> Data: C:\WINNT\system32\userinit.exe,
>
> Value 7
> Name: ReportBootOk
> Type: REG_SZ
> Data: 1
>
> Value 8
> Name: LegalNoticeCaption
> Type: REG_SZ
> Data:
>
> Value 9
> Name: LegalNoticeText
> Type: REG_SZ
> Data:
>
> Value 10
> Name: ShutdownWithoutLogon
> Type: REG_SZ
> Data: 0
>
> Value 11
> Name: PowerdownAfterShutdown
> Type: REG_SZ
> Data: 0
>
> Value 12
> Name: DebugServerCommand
> Type: REG_SZ
> Data: no
>
> Value 13
> Name: DCacheUpdate
> Type: REG_BINARY
> Data:
> 00000000 06 97 ea ea 0e 5a c8 01 - ..êê.ZÈ.
>
> Value 14
> Name: AutoAdminLogon
> Type: REG_SZ
> Data: 0
>
> Value 15
> Name: SfcQuota
> Type: REG_DWORD
> Data: 0xffffffff
>
> Value 16
> Name: AllowMultipleTSSessions
> Type: REG_DWORD
> Data: 0x0
>
> Value 17
> Name: UIHost
> Type: REG_EXPAND_SZ
> Data: logonui.exe
>
> Value 18
> Name: SFCDisable
> Type: REG_DWORD
> Data: 0x0
>
> Value 19
> Name: WinStationsDisabled
> Type: REG_SZ
> Data: 0
>
> Value 20
> Name: LogonType
> Type: REG_DWORD
> Data: 0x0
>
> Value 21
> Name: HibernationPreviouslyEnabled
> Type: REG_DWORD
> Data: 0x1
>
> Value 22
> Name: ShowLogonOptions
> Type: REG_DWORD
> Data: 0x1
>
> Value 23
> Name: AltDefaultUserName
> Type: REG_SZ
> Data: Administrator
>
> Value 24
> Name: AltDefaultDomainName
> Type: REG_SZ
> Data: PAQUETTE_HOME
>
> Value 25
> Name: DisableCAD
> Type: REG_DWORD
> Data: 0x0
>
> Value 26
> Name: GpNetworkStartTimeoutPolicyValue
> Type: REG_DWORD
> Data: 0x0
>
> Value 27
> Name: GinaDLL
> Type: REG_SZ
> Data: C:\WINNT\WlanGINA\Version\1.0.4.0\WlanGINA.dll
>
> Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
> \CurrentVersion\Winlogon\GPExtensions
> Class Name: <NO CLASS>
> Last Write Time: 9/10/2004 - 5:48 PM
>
> Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
> \CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-
> BF6DE7E7FE63}
> Class Name: <NO CLASS>
> Last Write Time: 12/25/2005 - 8:19 PM
> Value 0
> Name: <NO NAME>
> Type: REG_SZ
> Data: Wireless
>
> Value 1
> Name: ProcessGroupPolicy
> Type: REG_SZ
> Data: ProcessWIRELESSPolicy
>
> Value 2
> Name: DllName
> Type: REG_EXPAND_SZ
> Data: gptext.dll
>
> Value 3
> Name: NoUserPolicy
> Type: REG_DWORD
> Data: 0x1
>
> Value 4
> Name: NoGPOListChanges
> Type: REG_DWORD
> Data: 0x1
>
> Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
> \CurrentVersion\Winlogon\GPExtensions
> \{25537BA6-77A8-11D2-9B6C-0000F8080861}
> Class Name: <NO CLASS>
> Last Write Time: 2/28/2003 - 6:16 PM
> Value 0
> Name: <NO NAME>
> Type: REG_SZ
> Data: Folder Redirection
>
> Value 1
> Name: ProcessGroupPolicyEx
> Type: REG_SZ
> Data: ProcessGroupPolicyEx
>
> Value 2
> Name: DllName
> Type: REG_EXPAND_SZ
> Data: fdeploy.dll
>
> Value 3
> Name: NoMachinePolicy
> Type: REG_DWORD
> Data: 0x1
>
> Value 4
> Name: NoSlowLink
> Type: REG_DWORD
> Data: 0x1
>
> Value 5
> Name: PerUserLocalSettings
> Type: REG_DWORD
> Data: 0x1
>
> Value 6
> Name: NoGPOListChanges
> Type: REG_DWORD
> Data: 0x0
>
> Value 7
> Name: NoBackgroundPolicy
> Type: REG_DWORD
> Data: 0x0
>
> Value 8
> Name: GenerateGroupPolicy
> Type: REG_SZ
> Data: GenerateGroupPolicy
>
> Value 9
> Name: EventSources
> Type: REG_MULTI_SZ
> Data: (Folder Redirection,Application)
>
> Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
> \CurrentVersion\Winlogon\GPExtensions\{35378EAC-683F-11D2-
> A89A-00C04FBBCFA2}
> Class Name: <NO CLASS>
> Last Write Time: 1/18/2008 - 4:39 PM
> Value 0
> Name: Status
> Type: REG_DWORD
> Data: 0x0
>
> Value 1
> Name: RsopStatus
> Type: REG_DWORD
> Data: 0x0
>
> Value 2
> Name: LastPolicyTime
> Type: REG_DWORD
> Data: 0xe11b57
>
> Value 3
> Name: PrevSlowLink
> Type: REG_DWORD
> Data: 0x0
>
> Value 4
> Name: PrevRsopLogging
> Type: REG_DWORD
> ...
>
> read more »
Below is the same key without the D-Link software installed. This
boots just fine. I used Word to compare this key with and without the
D-Link drivers installed. There are only two differences:
1. GinaDLL is referenced with the drivers installed but not without,
and
2. the binary code in the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings key is
very different.
I'm not sure, however, that that moves the much closer to a solution
to this problem but perhaps I am missing something!
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon
Class Name: <NO CLASS>
Last Write Time: 9/6/2008 - 10:37 AM
Value 0
Name: System
Type: REG_SZ
Data:
Value 1
Name: AutoRestartShell
Type: REG_DWORD
Data: 0x1
Value 2
Name: Shell
Type: REG_SZ
Data: Explorer.exe
Value 3
Name: DefaultUserName
Type: REG_SZ
Data: Administrator
Value 4
Name: DefaultDomainName
Type: REG_SZ
Data: PAQUETTE_HOME
Value 5
Name: VmApplet
Type: REG_SZ
Data: rundll32 shell32,Control_RunDLL "sysdm.cpl"
Value 6
Name: Userinit
Type: REG_SZ
Data: C:\WINNT\system32\userinit.exe,
Value 7
Name: ReportBootOk
Type: REG_SZ
Data: 1
Value 8
Name: LegalNoticeCaption
Type: REG_SZ
Data:
Value 9
Name: LegalNoticeText
Type: REG_SZ
Data:
Value 10
Name: ShutdownWithoutLogon
Type: REG_SZ
Data: 0
Value 11
Name: PowerdownAfterShutdown
Type: REG_SZ
Data: 0
Value 12
Name: DebugServerCommand
Type: REG_SZ
Data: no
Value 13
Name: DCacheUpdate
Type: REG_BINARY
Data:
00000000 06 97 ea ea 0e 5a c8 01 - ..êê.ZÈ..
Value 14
Name: AutoAdminLogon
Type: REG_SZ
Data: 0
Value 15
Name: SfcQuota
Type: REG_DWORD
Data: 0xffffffff
Value 16
Name: AllowMultipleTSSessions
Type: REG_DWORD
Data: 0x0
Value 17
Name: UIHost
Type: REG_EXPAND_SZ
Data: logonui.exe
Value 18
Name: SFCDisable
Type: REG_DWORD
Data: 0x0
Value 19
Name: WinStationsDisabled
Type: REG_SZ
Data: 0
Value 20
Name: LogonType
Type: REG_DWORD
Data: 0x0
Value 21
Name: HibernationPreviouslyEnabled
Type: REG_DWORD
Data: 0x1
Value 22
Name: ShowLogonOptions
Type: REG_DWORD
Data: 0x1
Value 23
Name: AltDefaultUserName
Type: REG_SZ
Data: Administrator
Value 24
Name: AltDefaultDomainName
Type: REG_SZ
Data: PAQUETTE_HOME
Value 25
Name: DisableCAD
Type: REG_DWORD
Data: 0x0
Value 26
Name: GpNetworkStartTimeoutPolicyValue
Type: REG_DWORD
Data: 0x0
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\GPExtensions
Class Name: <NO CLASS>
Last Write Time: 9/10/2004 - 5:48 PM
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-
BF6DE7E7FE63}
Class Name: <NO CLASS>
Last Write Time: 12/25/2005 - 8:19 PM
Value 0
Name: <NO NAME>
Type: REG_SZ
Data: Wireless
Value 1
Name: ProcessGroupPolicy
Type: REG_SZ
Data: ProcessWIRELESSPolicy
Value 2
Name: DllName
Type: REG_EXPAND_SZ
Data: gptext.dll
Value 3
Name: NoUserPolicy
Type: REG_DWORD
Data: 0x1
Value 4
Name: NoGPOListChanges
Type: REG_DWORD
Data: 0x1
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\GPExtensions
\{25537BA6-77A8-11D2-9B6C-0000F8080861}
Class Name: <NO CLASS>
Last Write Time: 2/28/2003 - 6:16 PM
Value 0
Name: <NO NAME>
Type: REG_SZ
Data: Folder Redirection
Value 1
Name: ProcessGroupPolicyEx
Type: REG_SZ
Data: ProcessGroupPolicyEx
Value 2
Name: DllName
Type: REG_EXPAND_SZ
Data: fdeploy.dll
Value 3
Name: NoMachinePolicy
Type: REG_DWORD
Data: 0x1
Value 4
Name: NoSlowLink
Type: REG_DWORD
Data: 0x1
Value 5
Name: PerUserLocalSettings
Type: REG_DWORD
Data: 0x1
Value 6
Name: NoGPOListChanges
Type: REG_DWORD
Data: 0x0
Value 7
Name: NoBackgroundPolicy
Type: REG_DWORD
Data: 0x0
Value 8
Name: GenerateGroupPolicy
Type: REG_SZ
Data: GenerateGroupPolicy
Value 9
Name: EventSources
Type: REG_MULTI_SZ
Data: (Folder Redirection,Application)
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\GPExtensions\{35378EAC-683F-11D2-
A89A-00C04FBBCFA2}
Class Name: <NO CLASS>
Last Write Time: 1/18/2008 - 4:39 PM
Value 0
Name: Status
Type: REG_DWORD
Data: 0x0
Value 1
Name: RsopStatus
Type: REG_DWORD
Data: 0x0
Value 2
Name: LastPolicyTime
Type: REG_DWORD
Data: 0xe11b57
Value 3
Name: PrevSlowLink
Type: REG_DWORD
Data: 0x0
Value 4
Name: PrevRsopLogging
Type: REG_DWORD
Data: 0x1
Value 5
Name: ForceRefreshFG
Type: REG_DWORD
Data: 0x0
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\GPExtensions
\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
Class Name: <NO CLASS>
Last Write Time: 2/28/2003 - 6:27 PM
Value 0
Name: <NO NAME>
Type: REG_SZ
Data: Microsoft Disk Quota
Value 1
Name: NoMachinePolicy
Type: REG_DWORD
Data: 0x0
Value 2
Name: NoUserPolicy
Type: REG_DWORD
Data: 0x1
Value 3
Name: NoSlowLink
Type: REG_DWORD
Data: 0x1
Value 4
Name: NoBackgroundPolicy
Type: REG_DWORD
Data: 0x1
Value 5
Name: NoGPOListChanges
Type: REG_DWORD
Data: 0x1
Value 6
Name: PerUserLocalSettings
Type: REG_DWORD
Data: 0x0
Value 7
Name: RequiresSuccessfulRegistry
Type: REG_DWORD
Data: 0x1
Value 8
Name: EnableAsynchronousProcessing
Type: REG_DWORD
Data: 0x0
Value 9
Name: DllName
Type: REG_EXPAND_SZ
Data: dskquota.dll
Value 10
Name: ProcessGroupPolicy
Type: REG_SZ
Data: ProcessGroupPolicy
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-
ac3d37bfcb39}
Class Name: <NO CLASS>
Last Write Time: 2/28/2003 - 6:16 PM
Value 0
Name: <NO NAME>
Type: REG_SZ
Data: QoS Packet Scheduler
Value 1
Name: ProcessGroupPolicy
Type: REG_SZ
Data: ProcessPSCHEDPolicy
Value 2
Name: DllName
Type: REG_EXPAND_SZ
Data: gptext.dll
Value 3
Name: NoUserPolicy
Type: REG_DWORD
Data: 0x1
Value 4
Name: NoGPOListChanges
Type: REG_DWORD
Data: 0x1
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-
AE5A-0000F87571E3}
Class Name: <NO CLASS>
Last Write Time: 2/28/2003 - 6:16 PM
Value 0
Name: <NO NAME>
Type: REG_SZ
Data: Scripts
Value 1
Name: ProcessGroupPolicy
Type: REG_SZ
Data: ProcessScriptsGroupPolicy
Value 2
Name: ProcessGroupPolicyEx
Type: REG_SZ
Data: ProcessScriptsGroupPolicyEx
Value 3
Name: GenerateGroupPolicy
Type: REG_SZ
Data: GenerateScriptsGroupPolicy
Value 4
Name: DllName
Type: REG_EXPAND_SZ
Data: gptext.dll
Value 5
Name: NoSlowLink
Type: REG_DWORD
Data: 0x1
Value 6
Name: NoGPOListChanges
Type: REG_DWORD
Data: 0x1
Value 7
Name: NotifyLinkTransition
Type: REG_DWORD
Data: 0x1
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-
FAA6-47f1-89AA-0B18730C9FD3}
Class Name: <NO CLASS>
Last Write Time: 11/22/2006 - 6:59 PM
Value 0
Name: <NO NAME>
Type: REG_SZ
Data: Internet Explorer Zonemapping
Value 1
Name: DllName
Type: REG_EXPAND_SZ
Data: iedkcs32.dll
Value 2
Name: ProcessGroupPolicy
Type: REG_SZ
Data: ProcessGroupPolicyForZoneMap
Value 3
Name: NoGPOListChanges
Type: REG_DWORD
Data: 0x1
Value 4
Name: RequiresSucessfulRegistry
Type: REG_DWORD
Data: 0x1
Value 5
Name: DisplayName
Type: REG_EXPAND_SZ
Data: @iedkcs32.dll,-3051
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-
A4EA-00C04F79F83A}
Class Name: <NO CLASS>
Last Write Time: 1/18/2008 - 4:40 PM
Value 0
Name: ProcessGroupPolicy
Type: REG_SZ
Data: SceProcessSecurityPolicyGPO
Value 1
Name: GenerateGroupPolicy
Type: REG_SZ
Data: SceGenerateGroupPolicy
Value 2
Name: ExtensionRsopPlanningDebugLevel
Type: REG_DWORD
Data: 0x1
Value 3
Name: ProcessGroupPolicyEx
Type: REG_SZ
Data: SceProcessSecurityPolicyGPOEx
Value 4
Name: ExtensionDebugLevel
Type: REG_DWORD
Data: 0x1
Value 5
Name: DllName
Type: REG_EXPAND_SZ
Data: scecli.dll
Value 6
Name: <NO NAME>
Type: REG_SZ
Data: Security
Value 7
Name: NoUserPolicy
Type: REG_DWORD
Data: 0x1
Value 8
Name: NoGPOListChanges
Type: REG_DWORD
Data: 0x1
Value 9
Name: EnableAsynchronousProcessing
Type: REG_DWORD
Data: 0x1
Value 10
Name: MaxNoGPOListChangesInterval
Type: REG_DWORD
Data: 0x3c0
Value 11
Name: PreviousPolicyAreas
Type: REG_DWORD
Data: 0x0
Value 12
Name: Status
Type: REG_DWORD
Data: 0x0
Value 13
Name: RsopStatus
Type: REG_DWORD
Data: 0x0
Value 14
Name: LastPolicyTime
Type: REG_DWORD
Data: 0xe11b57
Value 15
Name: PrevSlowLink
Type: REG_DWORD
Data: 0x0
Value 16
Name: PrevRsopLogging
Type: REG_DWORD
Data: 0x1
Value 17
Name: ForceRefreshFG
Type: REG_DWORD
Data: 0x0
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-
BBDE-00C04F86AE3B}
Class Name: <NO CLASS>
Last Write Time: 11/22/2006 - 6:59 PM
Value 0
Name: ProcessGroupPolicyEx
Type: REG_SZ
Data: ProcessGroupPolicyEx
Value 1
Name: GenerateGroupPolicy
Type: REG_SZ
Data: GenerateGroupPolicy
Value 2
Name: ProcessGroupPolicy
Type: REG_SZ
Data: ProcessGroupPolicy
Value 3
Name: DllName
Type: REG_SZ
Data: iedkcs32.dll
Value 4
Name: <NO NAME>
Type: REG_SZ
Data: Internet Explorer Branding
Value 5
Name: NoSlowLink
Type: REG_DWORD
Data: 0x1
Value 6
Name: NoBackgroundPolicy
Type: REG_DWORD
Data: 0x0
Value 7
Name: NoGPOListChanges
Type: REG_DWORD
Data: 0x1
Value 8
Name: NoMachinePolicy
Type: REG_DWORD
Data: 0x1
Value 9
Name: DisplayName
Type: REG_EXPAND_SZ
Data: @iedkcs32.dll,-3014
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-
A4EA-00C04F79F83A}
Class Name: <NO CLASS>
Last Write Time: 1/18/2008 - 4:40 PM
Value 0
Name: ProcessGroupPolicy
Type: REG_SZ
Data: SceProcessEFSRecoveryGPO
Value 1
Name: DllName
Type: REG_EXPAND_SZ
Data: scecli.dll
Value 2
Name: <NO NAME>
Type: REG_SZ
Data: EFS recovery
Value 3
Name: NoUserPolicy
Type: REG_DWORD
Data: 0x1
Value 4
Name: NoGPOListChanges
Type: REG_DWORD
Data: 0x1
Value 5
Name: RequiresSuccessfulRegistry
Type: REG_DWORD
Data: 0x1
Value 6
Name: Status
Type: REG_DWORD
Data: 0x0
Value 7
Name: RsopStatus
Type: REG_DWORD
Data: 0x80070032
Value 8
Name: LastPolicyTime
Type: REG_DWORD
Data: 0xe11b57
Value 9
Name: PrevSlowLink
Type: REG_DWORD
Data: 0x0
Value 10
Name: PrevRsopLogging
Type: REG_DWORD
Data: 0x1
Value 11
Name: ForceRefreshFG
Type: REG_DWORD
Data: 0x0
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\GPExtensions\
{c6dc5466-785a-11d2-84d0-00c04fb169f7}
Class Name: <NO CLASS>
Last Write Time: 2/28/2003 - 6:16 PM
Value 0
Name: <NO NAME>
Type: REG_SZ
Data: Software Installation
Value 1
Name: DllName
Type: REG_EXPAND_SZ
Data: appmgmts.dll
Value 2
Name: ProcessGroupPolicyEx
Type: REG_SZ
Data: ProcessGroupPolicyObjectsEx
Value 3
Name: GenerateGroupPolicy
Type: REG_SZ
Data: GenerateGroupPolicy
Value 4
Name: NoBackgroundPolicy
Type: REG_DWORD
Data: 0x0
Value 5
Name: RequiresSucessfulRegistry
Type: REG_DWORD
Data: 0x0
Value 6
Name: NoSlowLink
Type: REG_DWORD
Data: 0x1
Value 7
Name: PerUserLocalSettings
Type: REG_DWORD
Data: 0x1
Value 8
Name: EventSources
Type: REG_MULTI_SZ
Data: (Application Management,Application)
(MsiInstaller,Application)
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-
a382-00c04f991e27}
Class Name: <NO CLASS>
Last Write Time: 2/28/2003 - 6:16 PM
Value 0
Name: <NO NAME>
Type: REG_SZ
Data: IP Security
Value 1
Name: ProcessGroupPolicy
Type: REG_SZ
Data: ProcessIPSECPolicy
Value 2
Name: DllName
Type: REG_EXPAND_SZ
Data: gptext.dll
Value 3
Name: NoUserPolicy
Type: REG_DWORD
Data: 0x1
Value 4
Name: NoGPOListChanges
Type: REG_DWORD
Data: 0x1
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\Notify
Class Name: <NO CLASS>
Last Write Time: 4/25/2006 - 4:23 PM
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\Notify\AtiExtEvent
Class Name: <NO CLASS>
Last Write Time: 1/28/2007 - 12:25 PM
Value 0
Name: DLLName
Type: REG_SZ
Data: Ati2evxx.dll
Value 1
Name: Asynchronous
Type: REG_DWORD
Data: 0x0
Value 2
Name: Impersonate
Type: REG_DWORD
Data: 0x1
Value 3
Name: Lock
Type: REG_SZ
Data: AtiLockEvent
Value 4
Name: Logoff
Type: REG_SZ
Data: AtiLogoffEvent
Value 5
Name: Logon
Type: REG_SZ
Data: AtiLogonEvent
Value 6
Name: Disconnect
Type: REG_SZ
Data: AtiDisConnectEvent
Value 7
Name: Reconnect
Type: REG_SZ
Data: AtiReConnectEvent
Value 8
Name: Safe
Type: REG_DWORD
Data: 0x0
Value 9
Name: Shutdown
Type: REG_SZ
Data: AtiShutdownEvent
Value 10
Name: StartScreenSaver
Type: REG_SZ
Data: AtiStartScreenSaverEvent
Value 11
Name: StartShell
Type: REG_SZ
Data: AtiStartShellEvent
Value 12
Name: Startup
Type: REG_SZ
Data: AtiStartupEvent
Value 13
Name: StopScreenSaver
Type: REG_SZ
Data: AtiStopScreenSaverEvent
Value 14
Name: Unlock
Type: REG_SZ
Data: AtiUnLockEvent
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\Notify\crypt32chain
Class Name: <NO CLASS>
Last Write Time: 2/28/2003 - 6:16 PM
Value 0
Name: Asynchronous
Type: REG_DWORD
Data: 0x0
Value 1
Name: Impersonate
Type: REG_DWORD
Data: 0x0
Value 2
Name: DllName
Type: REG_EXPAND_SZ
Data: crypt32.dll
Value 3
Name: Logoff
Type: REG_SZ
Data: ChainWlxLogoffEvent
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\Notify\cryptnet
Class Name: <NO CLASS>
Last Write Time: 2/28/2003 - 6:16 PM
Value 0
Name: Asynchronous
Type: REG_DWORD
Data: 0x0
Value 1
Name: Impersonate
Type: REG_DWORD
Data: 0x0
Value 2
Name: DllName
Type: REG_EXPAND_SZ
Data: cryptnet.dll
Value 3
Name: Logoff
Type: REG_SZ
Data: CryptnetWlxLogoffEvent
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\Notify\cscdll
Class Name: <NO CLASS>
Last Write Time: 2/28/2003 - 6:16 PM
Value 0
Name: DLLName
Type: REG_SZ
Data: cscdll.dll
Value 1
Name: Logon
Type: REG_SZ
Data: WinlogonLogonEvent
Value 2
Name: Logoff
Type: REG_SZ
Data: WinlogonLogoffEvent
Value 3
Name: ScreenSaver
Type: REG_SZ
Data: WinlogonScreenSaverEvent
Value 4
Name: Startup
Type: REG_SZ
Data: WinlogonStartupEvent
Value 5
Name: Shutdown
Type: REG_SZ
Data: WinlogonShutdownEvent
Value 6
Name: StartShell
Type: REG_SZ
Data: WinlogonStartShellEvent
Value 7
Name: Impersonate
Type: REG_DWORD
Data: 0x0
Value 8
Name: Asynchronous
Type: REG_DWORD
Data: 0x1
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\Notify\igfxcui
Class Name: <NO CLASS>
Last Write Time: 3/28/2004 - 1:27 AM
Value 0
Name: <NO NAME>
Type: REG_SZ
Data:
Value 1
Name: DLLName
Type: REG_SZ
Data: igfxsrvc.dll
Value 2
Name: Asynchronous
Type: REG_DWORD
Data: 0x1
Value 3
Name: Impersonate
Type: REG_DWORD
Data: 0x1
Value 4
Name: Unlock
Type: REG_SZ
Data: WinlogonUnlockEvent
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\Notify\ScCertProp
Class Name: <NO CLASS>
Last Write Time: 2/28/2003 - 6:16 PM
Value 0
Name: DLLName
Type: REG_SZ
Data: wlnotify.dll
Value 1
Name: Logon
Type: REG_SZ
Data: SCardStartCertProp
Value 2
Name: Logoff
Type: REG_SZ
Data: SCardStopCertProp
Value 3
Name: Lock
Type: REG_SZ
Data: SCardSuspendCertProp
Value 4
Name: Unlock
Type: REG_SZ
Data: SCardResumeCertProp
Value 5
Name: Enabled
Type: REG_DWORD
Data: 0x1
Value 6
Name: Impersonate
Type: REG_DWORD
Data: 0x1
Value 7
Name: Asynchronous
Type: REG_DWORD
Data: 0x1
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\Notify\Schedule
Class Name: <NO CLASS>
Last Write Time: 2/28/2003 - 6:16 PM
Value 0
Name: Asynchronous
Type: REG_DWORD
Data: 0x0
Value 1
Name: DllName
Type: REG_EXPAND_SZ
Data: wlnotify.dll
Value 2
Name: Impersonate
Type: REG_DWORD
Data: 0x0
Value 3
Name: StartShell
Type: REG_SZ
Data: SchedStartShell
Value 4
Name: Logoff
Type: REG_SZ
Data: SchedEventLogOff
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\Notify\sclgntfy
Class Name: <NO CLASS>
Last Write Time: 2/28/2003 - 6:16 PM
Value 0
Name: Logoff
Type: REG_SZ
Data: WLEventLogoff
Value 1
Name: Impersonate
Type: REG_DWORD
Data: 0x0
Value 2
Name: Asynchronous
Type: REG_DWORD
Data: 0x1
Value 3
Name: DllName
Type: REG_EXPAND_SZ
Data: sclgntfy.dll
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\Notify\SensLogn
Class Name: <NO CLASS>
Last Write Time: 2/28/2003 - 6:16 PM
Value 0
Name: DLLName
Type: REG_SZ
Data: WlNotify.dll
Value 1
Name: Lock
Type: REG_SZ
Data: SensLockEvent
Value 2
Name: Logon
Type: REG_SZ
Data: SensLogonEvent
Value 3
Name: Logoff
Type: REG_SZ
Data: SensLogoffEvent
Value 4
Name: Safe
Type: REG_DWORD
Data: 0x1
Value 5
Name: MaxWait
Type: REG_DWORD
Data: 0x258
Value 6
Name: StartScreenSaver
Type: REG_SZ
Data: SensStartScreenSaverEvent
Value 7
Name: StopScreenSaver
Type: REG_SZ
Data: SensStopScreenSaverEvent
Value 8
Name: Startup
Type: REG_SZ
Data: SensStartupEvent
Value 9
Name: Shutdown
Type: REG_SZ
Data: SensShutdownEvent
Value 10
Name: StartShell
Type: REG_SZ
Data: SensStartShellEvent
Value 11
Name: PostShell
Type: REG_SZ
Data: SensPostShellEvent
Value 12
Name: Disconnect
Type: REG_SZ
Data: SensDisconnectEvent
Value 13
Name: Reconnect
Type: REG_SZ
Data: SensReconnectEvent
Value 14
Name: Unlock
Type: REG_SZ
Data: SensUnlockEvent
Value 15
Name: Impersonate
Type: REG_DWORD
Data: 0x1
Value 16
Name: Asynchronous
Type: REG_DWORD
Data: 0x1
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\Notify\termsrv
Class Name: <NO CLASS>
Last Write Time: 2/28/2003 - 6:16 PM
Value 0
Name: Asynchronous
Type: REG_DWORD
Data: 0x0
Value 1
Name: DllName
Type: REG_EXPAND_SZ
Data: wlnotify.dll
Value 2
Name: Impersonate
Type: REG_DWORD
Data: 0x0
Value 3
Name: Logoff
Type: REG_SZ
Data: TSEventLogoff
Value 4
Name: Logon
Type: REG_SZ
Data: TSEventLogon
Value 5
Name: PostShell
Type: REG_SZ
Data: TSEventPostShell
Value 6
Name: Shutdown
Type: REG_SZ
Data: TSEventShutdown
Value 7
Name: StartShell
Type: REG_SZ
Data: TSEventStartShell
Value 8
Name: Startup
Type: REG_SZ
Data: TSEventStartup
Value 9
Name: MaxWait
Type: REG_DWORD
Data: 0x258
Value 10
Name: Reconnect
Type: REG_SZ
Data: TSEventReconnect
Value 11
Name: Disconnect
Type: REG_SZ
Data: TSEventDisconnect
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\Notify\WgaLogon
Class Name: <NO CLASS>
Last Write Time: 12/12/2007 - 11:15 AM
Value 0
Name: Logon
Type: REG_SZ
Data: WLEventLogon
Value 1
Name: Logoff
Type: REG_SZ
Data: WLEventLogoff
Value 2
Name: Startup
Type: REG_SZ
Data: WLEventStartup
Value 3
Name: Shutdown
Type: REG_SZ
Data: WLEventShutdown
Value 4
Name: StartScreenSaver
Type: REG_SZ
Data: WLEventStartScreenSaver
Value 5
Name: StopScreenSaver
Type: REG_SZ
Data: WLEventStopScreenSaver
Value 6
Name: Lock
Type: REG_SZ
Data: WLEventLock
Value 7
Name: Unlock
Type: REG_SZ
Data: WLEventUnlock
Value 8
Name: StartShell
Type: REG_SZ
Data: WLEventStartShell
Value 9
Name: PostShell
Type: REG_SZ
Data: WLEventPostShell
Value 10
Name: Disconnect
Type: REG_SZ
Data: WLEventDisconnect
Value 11
Name: Reconnect
Type: REG_SZ
Data: WLEventReconnect
Value 12
Name: Impersonate
Type: REG_DWORD
Data: 0x1
Value 13
Name: Asynchronous
Type: REG_DWORD
Data: 0x0
Value 14
Name: SafeMode
Type: REG_DWORD
Data: 0x1
Value 15
Name: MaxWait
Type: REG_DWORD
Data: 0xffffffff
Value 16
Name: DllName
Type: REG_EXPAND_SZ
Data: WgaLogon.dll
Value 17
Name: Event
Type: REG_DWORD
Data: 0x3
Value 18
Name: EulaAccepted
Type: REG_DWORD
Data: 0x1
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\Notify\WgaLogon\Settings
Class Name: <NO CLASS>
Last Write Time: 9/6/2008 - 10:40 AM
Value 0
Name: Data
Type: REG_BINARY
Data:
00000000 01 00 00 00 d0 8c 9d df - 01 15 d1 11 8c 7a 00
c0 ....Ð..ß..Ñ..z.À
00000010 4f c2 97 eb 01 00 00 00 - d8 d8 e3 1e 57 4b 15 41
OÂ.ë....ØØã.WK.A
00000020 bb ea 2e 41 d2 5c 2e 63 - 04 00 00 00 04 00 00 00 »ê.AÒ
\.c........
00000030 53 00 00 00 03 66 00 00 - a8 00 00 00 10 00 00 00
S....f..¨.......
00000040 ea 25 29 ff 22 1d 92 41 - 25 a8 6b 61 c7 c0 eb 3b ê%)ÿ"..A
%¨kaÇÀë;
00000050 00 00 00 00 04 80 00 00 - a0 00 00 00 10 00 00
00 ........ .......
00000060 f3 7b b9 fc e7 43 d2 92 - 8f 5a df f8 5a 4b 18 5a
ó{¹üçCÒ..ZßøZK.Z
00000070 b0 01 00 00 92 b8 d7 fa - 15 3f 5d 63 80 6b 39 40
°....¸×ú.?]c.k9@
00000080 6c 0a 67 57 21 f7 ee c4 - d2 89 69 1a 0e 15 b5 08 l.gW!
÷îÄÒ.i...µ.
00000090 56 6d a4 8c 24 6e 76 62 - 08 f0 17 7c 04 c8 51 2f Vm¤.
$nvb.ð.|.ÈQ/
000000a0 02 e2 3c 8e 6e 1c 03 88 - 23 66 95 a9 c5 00 2a
08 .â<.n...#f.©Å.*.
000000b0 bf a6 76 c8 a3 04 d9 c9 - 1d 44 5e 89 a0 b1 8a 54 ¿¦vÈ
£.ÙÉ.D^. ±.T
000000c0 2a 1d d1 25 66 0d 95 25 - 02 3f 2e 1a 6e 5a 82 18 *.Ñ%f..
%.?..nZ..
000000d0 ef a3 13 da d4 8a 49 a5 - e3 43 4c da c4 31 8f 9d ï£.ÚÔ..I
¥ãCLÚÄ1..
000000e0 61 04 c1 0d 24 fb 11 85 - 99 41 83 1c 5b 25 63 60 a.Á.
$û...A..[%c`
000000f0 40 5c 73 81 35 19 c8 4f - 7b d5 c0 12 0c f5 42 f2 @\s.
5.ÈO{ÕÀ..õBò
00000100 a9 7f e5 6a d5 40 11 86 - 78 42 bc 58 f5 d9 28 34
©.åjÕ@..xB¼XõÙ(4
00000110 2b e9 82 0b 58 0c 65 99 - b4 39 99 4b a0 6f 03 99 +é..X.e.
´9.K o..
00000120 e6 fb 7b 35 64 14 a7 2e - 50 50 29 fb 81 a5 57 b8
æû{5d.§.PP)û.¥W¸
00000130 6b d2 2f e7 a2 7a d0 87 - be 44 52 b1 04 d1 a1 37 kÒ/ç
¢zÐ.¾DR±.Ñ¡7
00000140 d3 a1 00 21 db a5 bb a0 - 3e ed 15 cb 35 d1 ff a2 Ó¡.!Û¥»
>í.Ë5Ñÿ¢
00000150 06 b1 7c df 45 92 89 c1 - 35 5b 7d 08 6b d0 9a d8 .±|
ßE..Á5[}.kÐ.Ø
00000160 11 ba 53 83 e6 f1 d3 ea - 87 f4 54 ad 67 86 51
ce .ºS.æñÓê.ôTg.QÎ
00000170 84 da 9e a5 e0 04 63 49 - 56 48 95 3f 26 39 1e 0a .Ú.
¥à.cIVH.?&9..
00000180 70 c8 36 6d a8 ae ec a6 - 1c b7 8d 0a 53 66 9e 93
pÈ6m¨®ì¦.•..Sf..
00000190 05 a4 d2 9d f6 c5 b6 0c - ec 15 d2 53 4b a4 98 f5 .
¤Ò.öŶ.ì.ÒSK¤.õ
000001a0 19 9c d3 92 39 9d aa f4 - 6f 55 03 43 13 44 a7 2f ..Ó.
9.ªôoU.C.D§/
000001b0 c4 dd f3 92 5f cf e6 80 - c9 48 db 33 e0 14 15 78
ÄÝó._Ïæ.ÉHÛ3à..x
000001c0 f8 58 81 40 ec 19 e2 99 - 78 72 aa a2 7c e5 9c 8a
øX.@ì.â.xrª¢|å..
000001d0 c5 bf 69 3c 57 ce 75 7b - c9 9c 79 ff f3 58 d8 03
Å¿i<WÎu{É.yÿóXØ.
000001e0 5e b0 17 b3 0d a2 01 fc - 65 cb 88 80 e4 5c 23 77 ^°.³.
¢.üeË..ä\#w
000001f0 52 a5 92 0d 74 93 33 5c - c2 df 96 c0 5b 33 31 c6 R¥..t.
3\Âß.À[31Æ
00000200 49 ca cd 55 05 35 54 a3 - 7a 4e e2 1c af 20 23 0d IÊÍU.5T
£zNâ.¯ #.
00000210 a6 1b e8 1d 31 0e ed 18 - 4b 77 e2 9e a0 ad 3d 50 ¦.è.
1.í.Kwâ. =P
00000220 be 86 91 4d 14 00 00 00 - fd ab fb 5b b5 10 41 39
¾..M....ý«û[µ.A9
00000230 4f 12 cc d0 44 67 d2 01 - 0e b4 e3 38 O.ÌÐDgÒ...
´ã8
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\Notify\wlballoon
Class Name: <NO CLASS>
Last Write Time: 2/28/2003 - 6:16 PM
Value 0
Name: DLLName
Type: REG_SZ
Data: wlnotify.dll
Value 1
Name: Logon
Type: REG_SZ
Data: RegisterTicketExpiredNotificationEvent
Value 2
Name: Logoff
Type: REG_SZ
Data: UnregisterTicketExpiredNotificationEvent
Value 3
Name: Impersonate
Type: REG_DWORD
Data: 0x1
Value 4
Name: Asynchronous
Type: REG_DWORD
Data: 0x1
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\SCLogon
Class Name: <NO CLASS>
Last Write Time: 7/13/2003 - 5:07 PM
Value 0
Name: Reader-0
Type: REG_SZ
Data: O2Micro PCMCIA Reader 0
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\SpecialAccounts
Class Name: <NO CLASS>
Last Write Time: 2/28/2003 - 6:16 PM
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion\Winlogon\SpecialAccounts\UserList
Class Name: <NO CLASS>
Last Write Time: 7/12/2006 - 9:46 AM
Value 0
Name: HelpAssistant
Type: REG_DWORD
Data: 0x0
Value 1
Name: TsInternetUser
Type: REG_DWORD
Data: 0x0
Value 2
Name: SQLAgentCmdExec
Type: REG_DWORD
Data: 0x0
Value 3
Name: NetShowServices
Type: REG_DWORD
Data: 0x0
Value 4
Name: IWAM_
Type: REG_DWORD
Data: 0x10000
Value 5
Name: IUSR_
Type: REG_DWORD
Data: 0x10000
Value 6
Name: VUSR_
Type: REG_DWORD
Data: 0x10000
Value 7
Name: ASPNET
Type: REG_DWORD
Data: 0x0