lllllLlllLllllllllll Security Winlogon (0x%x,0x%x) OptionValue system\currentcontrolset\control\safeboot\option AEPolicy SOFTWARE\Policies\Microsoft\Cryptography\AutoEnrollment oEnrollmentRefreshTime Software\Policies\Microsoft\Windows\System userinit.exe %s\%s Default UserInitAutoEnroll UserInitAutoEnrollMode ShellReadyEvent AUTOENRL:UserEnrollmentShellTimer AUTOENRL:UserEnrollmentTimer AUTOENRL:MachineEnrollmentTimer AUTOENRL:TriggerUserEnrollment Local\ AUTOENRL:TriggerMachineEnrollment Global\ Warning Sounds Control Panel\Accessibility /Hotkey UtilMan utilman.exe /debug ForceAutoLogon WINLOGON AutoAdminLogon DefaultUserName DefaultDomainName Software\Microsoft\Windows NT\CurrentVersion\Winlogon \Registry\Machine\System\CurrentControlSet\Control\Terminal Server fSingleSessionPerUser EnableConcurrentSessions System\CurrentControlSet\Control\Terminal Server\Licensing Core %-25ws %4d:%02d:%02d Global\TermSrvReadyEvent unknown OEM Driver %dx%d %s AutoSelectLogon Container-%lx Provider-%lx Reader-%lx Card-%lx Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SCLogon ediskeer.dll Starter _CsCapLib Microsoft Enhanced Cryptographic Provider v1.0 Non-fatal error (%d:%016I64X) occurred. Error (%d:%016I64X). Rebooting. Error (%d:%016I64X). Shutting down. Windows Starter Edition %016I64X HOMEPATH HOMESHARE HOMEDRIVE System\CurrentControlSet\Control\Session Manager\Environment GinaDll msgina.dll RASMAN KeepRasConnections COMPUTERNAME netapi32.dll IMM32.DLL Start SYSTEM\CurrentControlSet\Services\NetDDE ClipSrv default WinSta0 \\.\pipe\NetDDE WinSta0\Default NDDE$ NDDEAgnt WlMprNotifyWinlogonWindow WlMprNotifyPassword WlMprNotifyOldPassword WlMprNotifyOldPasswordValid WlMprNotifyDomain WlMprNotifyUserName WlMprNotifyStationHandle WlMprNotifyStationName WlMprNotifyDesktop WlMprNotifyLogonFlag WlMprNotifyLogonId WlMprNotifyProvider WlMprNotifyPassThrough WlMprNotifyChangeInfo %s\Winlogon ntsd -d %s%s -g -G mpnotify mpnotify.exe Class system\CurrentControlSet\Services\ \NetworkProvider ProviderOrder system\CurrentControlSet\Control\NetworkProvider\Order \cdfs \ntfs AllocateDASD AllocateCDRoms AllocateFloppies AppEvents\Schemes\Apps\PowerCfg\CriticalBatteryAlarm\.Current AppEvents\Schemes\Apps\PowerCfg\LowBatteryAlarm\.Current Low Battery Alarm Program Critical Battery Alarm Program SnapShot Maximize Minimize RestoreDown RestoreUp Close MenuCommand MenuPopup SystemAsterisk SystemExclamation SystemQuestion SystemHand .Default SAS window class sethc %ws PromptPasswordOnResume Software\Policies\Microsoft\Windows\System\Power ShadowFilter Software\Microsoft\Remote Desktop __DDrawExclMode__ __DDrawCheckExclMode__ taskmgr.exe WINSTATIONNAME Software\Policies\Microsoft\Windows\Control Panel\Desktop eControl Panel\Desktop Shell explorer.exe AutoRestartShell SAS Logon Notify SAS window scrnsave.scr (NONE) SCRNSAVE.EXE ScreenSaverGracePeriod Screen-saver RestrictNonInteractiveAccess \Sessions\%d\BaseNamedObjects lsass.exe System %SystemRoot%\system32\userinit.exe nddeagnt userinit Nddeagnt.exe Userinit \INSTALLATION_SECURITY_HOLD SetupType SYSTEM\Setup SetupShutdownRequired SystemSetupInProgress syssetup.dll Repair HibernationPreviouslyEnabled SetWin9xUpgradePasswords \migpwd.exe Winsta0\Winlogon MigPwd SOFTWARE\Microsoft\Windows\CurrentVersion\Run SYSTEM\CurrentControlSet\Control\MiniNT ydnetplwiz.dll RunNetAccessWizard winsta0\Default ntsd %s %s Cmdline \Security\NetworkProviderLoad Autochk bootex.log Fonts PagingFiles \temppf.sys srrstr.dll RestoreInProgress Software\Microsoft\Windows NT\CurrentVersion\SystemRestore System shutting down. \Sessions\%ld\DosDevices -winlogon %d -setup LsaStart %SystemRoot%\system32\lsass.exe SaveDumpStart %SystemRoot%\system32\savedump.exe ShutdownStateSnapshot ShutdownEventPending SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability TempDestination DumpFile \Registry\Machine\System\CurrentControlSet\Control\CrashControl\MachineCrash \MEMORY.DMP EventFlag SYSTEM\CurrentControlSet\Control\Watchdog\Display SYSTEM\CurrentControlSet\Control\CrashControl\MachineCrash ServiceControllerStart %SystemRoot%\system32\services.exe InitShutdown %02d:%02d:%02d %d days Win32 Registry/SystemShutdown module Win32 SystemShutdown module %u.%u.%u.%u AllowMultipleTSSessions DisableIdleLogonTimeout \\.\Pipe\TerminalServer\AutoReconnect Global\TS-WPAAE TermService winlogon: user logon event NNRCommonProgramFiles CommonFilesDir ProgramFiles ProgramFilesDir Software\Microsoft\Windows\CurrentVersion APPDATA shell32.dll SESSIONNAME Console USERDNSDOMAIN Volatile Environment USERPROFILE %x:%x USERDNSDOMAIN=\NT4 NoPopupsOnBoot System\CurrentControlSet\Control\Windows RasAutodialLogoffUserDone RasAutodialLogoffUser winlogon: User GPO Event %d Software\Microsoft\Windows\CurrentVersion\Policies\System DisableBkGndGroupPolicy Software\Policies\Microsoft\Windows\System\Scripts\ MaxGPOScriptWait wlnotify.dll Software\Policies\Microsoft\Windows NT\Terminal Services PerSessionTempDir System\CurrentControlSet\Control\Terminal Server UserInitGPOScriptType Startup winlogon: machine GPO Event %d RunStartupScriptSync NETLOGON NTDS.IndexRecreateEvent Shutdown Logoff RunLogonScriptSync Logon Run Group Policy Logon Scripts Finish User Group Policy Begin User Group Policy Finish Machine Group Policy Begin Machine Group Policy win9xupg RunGrpConv System\CurrentControlSet\Control\SafeBoot\Option PrimaryDnsSuffix NV PrimaryDnsSuffix Software\Policies\Microsoft\System\DNSclient Domain NV Domain Hostname NV Hostname System\CurrentControlSet\Services\Tcpip\Parameters e%windir%\system32\sfc.dll ALLUSERSPROFILE Local\WinlogonTSSynchronizeEvent ntsd -d -p %d ntdll.dll WinStationsDisabled \Sessions\%d\BaseNamedObjects\ReconEvent \BaseNamedObjects\ReconEvent Global\SingleSesMutex Windows setup has completed, and the computer must restart. UserRequestedUpdate Software\Microsoft\Windows\CurrentVersion\WindowsUpdate wuaueng.dll sbasesrv.dll Windows Update Reset ComCtl32 %SystemRoot%\system32\msgina.dll %windir%\system32\ CLSID NoDebugThread DisableLockWorkstation COMCTL32 powrprof.dll Shell32.dll Software\Microsoft\Windows NT\CurrentVersion\Winlogon\LocalUsers ::{20D04FE0-3AEA-1069-A2D8-08002B30309D} shell32.dll,10 Microsoft.NetDriveReconnectFailed USERNAME Owner Skew1 System\CurrentControlSet\Control\Lsa SecureBoot Impersonate Asynchronous MaxWait DLLName SafeMode %SystemRoot%\system32\sfc.dll sfc.dll termsrv Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify tWINSCARD.DLL DefaultPIN SCard$AllReaders \\?PnP?\Notification O:SYG:SYD:(A;;RC;;;SY) ncalrpc %s-%lx sclogonrpc VerboseStatus wkssvc: MUP finished initializing event lanmanworkstation WaitForNetwork MaxRetrySysvolAccess \\%s\sysvol\*.* SysVolReadyEvent SysVolReady SYSTEM\CurrentControlSet\Services\netlogon\parameters NtdsDelayedStartupCompletedEvent RpcSs SamSs Winlogon Job %x-%x \SAM_SERVICE_STARTED Comctl32.dll WindowsLogon.manifest eventlog \Registry\Machine\System\CurrentControlSet\Control\SecurePipeServers\ ncacn_np \PIPE\ Remote\%d\GdiPlus Remote\%d\Control Panel\Desktop Software\Microsoft\Windows\CurrentVersion\ThemeManager\Remote\%d Software\Microsoft\Windows\CurrentVersion\Explorer\Remote\%d UserPreferencesMask HighQualityRender FontSmoothingType SmoothScroll DragFullWindows ThemeActive Wallpaper TaskbarAnimations Force Blank ActiveDesktop uxtheme.dll TSConnectEvent \Security\WxApiPort 0x%08lX Smart Card Logon TypesSupported EventMessageFile %SystemRoot%\System32\scarddlg.dll System\CurrentControlSet\Services\EventLog\Application\Smart Card Logon \\.\%s\%s Software\Microsoft\Windows NT\CurrentVersion\ProfileList NextLogonCacheable UserPreference LocalProfile ShutdownWithoutLogon OOBE Job %s %s \oobe\msoobe.exe %s\EmbdTrst.dll MediaCenter Installed Global\WPA_LT_MUTEX Global\WPA_PR_MUTEX Global\WPA_HWID_MUTEX Global\WPA_RT_MUTEX OOBETimer Windows Product Activation 4 0x%x 3 0x%x 6 0x%x 5 0x%x %s %u \wpabaln.exe 1 0x%x 2 0x%x 8: 0x%x 1: 0x%x BCDFGHJKMPQRTVWXY2346789 Microsoft Strong Cryptographic Provider %s\oembios.bin IDR_WPA_LICSTORE Global\WPA_LICSTORE_MUTEX 0123456789 -OEM- System\WPA\ %s%s-%s lllLl PemtDe"t.%0 %2. .%0 VS_VERSION_INFO StringFileInfo 041904B0 CompanyName FileDescription Windows NT FileVersion 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) InternalName winlogon LegalCopyright OriginalFilename WINLOGON.EXE ProductName Microsoft Windows ProductVersion 5.1.2600.2180 VarFileInfo Translation