Open mingkuang-Chuyu opened 6 years ago
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\AITEventLog] "Start"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Audio] "Start"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\AutoLogger-Diagtrack-Listener] "Start"=dword:00000000 "Status"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Circular Kernel Context Logger] "Start"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DiagLog] "Start"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SQMLogger] "Start"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\UBPM] "Start"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WdiContextLog] "Start"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WDI\Config] "SEMEnabled"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\NtfsLog] "Start"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoInternetOpenWith"=dword:00000001 "NoRecentDocsNetHood"=dword:00000001 "NoRecentDocsHistory"=dword:00000001 "NoRecentDocsMenu"=dword:00000001 "NoDriveTypeAutoRun"=dword:000000dd "NoLowDiskSpaceChecks"=dword:00000001 "NoInstrumentation"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\TerminalServer] "fDenyTSConnection"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem] "NtfsDisableLastAccessUpdate"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\kernel] "DisableExceptionChainValidation"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager] "CWDIllegalInDllSearch"=dword:00000002
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] "EnableInstallerDetection"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Memory Management] "DisablePagingExecutive"=dword:00000000 "LargeSystemCache"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer] "AlwaysUnloadDLL"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer] "AlwaysUnloadDLL"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters] "EnableSuperfetch"=dword:00000000 "EnablePrefetcher"=dword:00000000 "EnableBootTrace"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\WBEM\CIMOM] "EnableEvents"=dword:00000000 "Logging"="0"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanServer\Parameters] "SMB1"=dword:00000000 "SMB2"=dword:00000000 "SMB3"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects] "VisualFXSetting"=dword:00000003
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\AnimateMinMax] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ComboBoxAnimation] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ControlAnimations] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\CursorShadow] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DragFullWindows] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DropShadow] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DWMAeroPeekEnabled] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DWMEnabled] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DWMSaveThumbnailEnabled] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\FontSmoothing]
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListBoxSmoothScrolling] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewAlphaSelect] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewShadow] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\MenuAnimation] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\SelectionFade] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TaskbarAnimations] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\Themes]
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ThumbnailsOrIcon] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TooltipAnimation] "DefaultApplied"=dword:00000000
[HKEY_USERS\S-1-5-21-3951754341-2864742727-2729762979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TransparentGlass] "DefaultApplied"=dword:00000000
By Datum
WDI Diagnostics Logs
C:\Windows\System32\wdi
Cached Applications Compatibility Information
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\AppCompatCache HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery HKEY_CURRENT_USER\Software\Microsoft\DirectInput\MostRecentApplication HKEY_CURRENT_USER\Software\Microsoft\Direct3D HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32
Most Recent Connected Disks
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
Startup File Renaming Log
C:\Windows\PFRO.log
Cryptographic Services Traces
C:\Windows\System32\catroot2*.log C:\Windows\System32\catroot2*.jrs C:\Windows\System32\catroot2*.edb C:\Windows\System32\catroot2*.chk C:\Windows\System32\catroot2*dberr.txt
Others
C:\Users\USERNAME\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog.etl C:\Users\USERNAME\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl C:\Windows\System32\umstartup.etl C:\ProgramData\Microsoft\Diagnosis\ETLLogs C:\Users\USERNAME\AppData\Local\Microsoft\Windows\WebCache