Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-CAPI2/Operational]
"OwningPublisher"="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}"
"Enabled"=dword:00000000
"Isolation"=dword:00000000
"ChannelAccess"="O:BAG:SYD
A;;0x7;;;BA)(A;;0x2;;;AU)"
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}]
@="Microsoft-Windows-CAPI2"
"ResourceFileName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,\
00
"MessageFileName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\
6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\
00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}\ChannelReferences]
"Count"=dword:00000002
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}\ChannelReferences\0]
@="Application"
"Id"=dword:00000009
"Flags"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}\ChannelReferences\1]
@="Microsoft-Windows-CAPI2/Operational"
"Id"=dword:00000010
"Flags"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WMI\Autologger\EventLog-Application\{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}]
"Enabled"=dword:00000001
"EnableLevel"=dword:00000000
"LoggerName"="EventLog-Application"
"MatchAnyKeyword"=hex(b):00,00,00,00,00,00,00,80
"MatchAllKeyword"=hex(b):00,00,00,00,00,00,00,00
"EnableProperty"=dword:00000001
"Status"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Microsoft-Windows-CAPI2]
"ProviderGuid"="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}"
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,\
00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\WMI\Autologger\EventLog-Application\{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}]
"Enabled"=dword:00000001
"EnableLevel"=dword:00000000
"LoggerName"="EventLog-Application"
"MatchAnyKeyword"=hex(b):00,00,00,00,00,00,00,80
"MatchAllKeyword"=hex(b):00,00,00,00,00,00,00,00
"EnableProperty"=dword:00000001
"Status"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\eventlog\Application\Microsoft-Windows-CAPI2]
"ProviderGuid"="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}"
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,\
00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-Application\{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}]
"Enabled"=dword:00000001
"EnableLevel"=dword:00000000
"LoggerName"="EventLog-Application"
"MatchAnyKeyword"=hex(b):00,00,00,00,00,00,00,80
"MatchAllKeyword"=hex(b):00,00,00,00,00,00,00,00
"EnableProperty"=dword:00000001
"Status"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Microsoft-Windows-CAPI2]
"ProviderGuid"="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}"
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,\
00
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-capi2_31bf3856ad364e35_none_b1f5ea6c8bad0657]
@="6.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-capi2_31bf3856ad364e35_none_b1f5ea6c8bad0657\6.1]
"6.1.7600.16385"=hex:01
@="6.1.7600.16385"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-capi2-certs_31bf3856ad364e35_none_eda830a0cd7fe1e1]
@="6.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-capi2-certs_31bf3856ad364e35_none_eda830a0cd7fe1e1\6.1]
"6.1.7600.16385"=hex:01
@="6.1.7600.16385"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-capi2-cryptdlg-reg_31bf3856ad364e35_none_79c86b575a4b48ac]
@="6.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-capi2-cryptdlg-reg_31bf3856ad364e35_none_79c86b575a4b48ac\6.1]
"6.1.7600.16385"=hex:01
@="6.1.7600.16385"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-capi2-cryptext-reg_31bf3856ad364e35_none_816249bf8233184e]
@="6.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-capi2-cryptext-reg_31bf3856ad364e35_none_816249bf8233184e\6.1]
"6.1.7600.16385"=hex:01
@="6.1.7600.16385"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-capi2-cryptnet-reg_31bf3856ad364e35_none_377672c37cd86232]
@="6.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-capi2-cryptnet-reg_31bf3856ad364e35_none_377672c37cd86232\6.1]
"6.1.7600.16385"=hex:01
@="6.1.7600.16385"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-capi2-instrumentation_31bf3856ad364e35_none_b5a792e14f0cc68a]
@="6.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-capi2-instrumentation_31bf3856ad364e35_none_b5a792e14f0cc68a\6.1]
"6.1.7600.16385"=hex:01
@="6.1.7600.16385"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-capi2-setreg_31bf3856ad364e35_none_1e71bdb6c1e0e8e8]
@="6.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-capi2-setreg_31bf3856ad364e35_none_1e71bdb6c1e0e8e8\6.1]
"6.1.7600.16385"=hex:01
@="6.1.7600.16385"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-capi2-wintrust-reg_31bf3856ad364e35_none_1d27acb106745f9b]
@="6.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-capi2-wintrust-reg_31bf3856ad364e35_none_1d27acb106745f9b\6.1]
"6.1.7600.16385"=hex:01
@="6.1.7600.16385"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-sf-capi2_31bf3856ad364e35_none_62319e58cfd6b51d]
@="6.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_microsoft-windows-sf-capi2_31bf3856ad364e35_none_62319e58cfd6b51d\6.1]
"6.1.7600.16385"=hex:01
@="6.1.7600.16385"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-CAPI2/Operational]
"OwningPublisher"="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}"
"Enabled"=dword:00000000
"Isolation"=dword:00000000
"ChannelAccess"="O:BAG:SYD
A;;0x7;;;BA)(A;;0x2;;;AU)"
"Type"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}]
@="Microsoft-Windows-CAPI2"
"ResourceFileName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,\
00
"MessageFileName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\
6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\
00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}\ChannelReferences]
"Count"=dword:00000002
"Count"=dword:00000002
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}\ChannelReferences\0]
@="Application"
"Id"=dword:00000009
"Flags"=dword:00000001
@="Application"
"Id"=dword:00000009
"Flags"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}\ChannelReferences\1]
@="Microsoft-Windows-CAPI2/Operational"
"Id"=dword:00000010
"Flags"=dword:00000000
@="Microsoft-Windows-CAPI2/Operational"
"Id"=dword:00000010
"Flags"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Microsoft-Windows-CAPI2]
"ProviderGuid"="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}"
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,\
00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\eventlog\Application\Microsoft-Windows-CAPI2]
"ProviderGuid"="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}"
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,\
00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Microsoft-Windows-CAPI2]
"ProviderGuid"="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}"
"EventMessageFile"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,\
00