Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS]
"DisplayName"="Volume Shadow Copy"
"Description"="@%systemroot%\\system32\\vssvc.exe,-101"
"ObjectName"="LocalSystem"
"ErrorControl"=dword:00000001
"Start"=dword:00000002
"Type"=dword:00000010
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"ServiceSidType"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\SPP]
"SppCreate (Enter)"=hex:48,00,00,00,00,00,00,00,7a,77,4e,bb,f0,a2,c9,01,2c,11,\
00,00,70,11,00,00,d0,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00
"SppGatherWriterMetadata (Enter)"=hex:48,00,00,00,00,00,00,00,e0,0e,b1,1e,a8,\
46,c9,01,e0,03,00,00,58,08,00,00,d3,07,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00
"SppGatherWriterMetadata (Leave)"=hex:48,00,00,00,00,00,00,00,a0,61,7a,24,a8,\
46,c9,01,e0,03,00,00,58,08,00,00,d3,07,00,00,01,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00
"SppCreate (Leave)"=hex:48,00,00,00,00,00,00,00,aa,5d,51,bb,f0,a2,c9,01,2c,11,\
00,00,70,11,00,00,d0,07,00,00,01,00,00,00,00,00,00,00,ff,ff,00,80,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00
"SppAddInterestingComponents (Enter)"=hex:48,00,00,00,00,00,00,00,b0,88,7a,24,\
a8,46,c9,01,e0,03,00,00,58,08,00,00,d4,07,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00
"SppAddInterestingComponents (Leave)"=hex:48,00,00,00,00,00,00,00,20,e6,98,24,\
a8,46,c9,01,e0,03,00,00,58,08,00,00,d4,07,00,00,01,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00
"SppEnumGroups (Enter)"=hex:48,00,00,00,00,00,00,00,fa,65,5e,4e,e4,a2,c9,01,60,\
0c,00,00,5c,13,00,00,d1,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00
"SppGetSnapshots (Enter)"=hex:48,00,00,00,00,00,00,00,0a,8d,5e,4e,e4,a2,c9,01,\
60,0c,00,00,5c,13,00,00,d2,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
"SppGetSnapshots (Leave)"=hex:48,00,00,00,00,00,00,00,ca,d2,62,4e,e4,a2,c9,01,\
60,0c,00,00,5c,13,00,00,d2,07,00,00,01,00,00,00,00,00,00,00,ff,ff,00,80,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
"SppEnumGroups (Leave)"=hex:48,00,00,00,00,00,00,00,da,f9,62,4e,e4,a2,c9,01,60,\
0c,00,00,5c,13,00,00,d1,07,00,00,01,00,00,00,00,00,00,00,ff,ff,00,80,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\SystemRestore]
"SrCreateRp (Enter)"=hex:40,00,00,00,00,00,00,00,5a,29,4e,bb,f0,a2,c9,01,0c,0d,\
00,00,54,0b,00,00,d5,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"SrCreateRp (Leave)"=hex:40,00,00,00,00,00,00,00,aa,5d,51,bb,f0,a2,c9,01,0c,0d,\
00,00,54,0b,00,00,d5,07,00,00,01,00,00,00,00,00,00,00,ff,ff,00,80,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\BITS Writer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\MSSearch Service Writer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\System Writer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\VolSnap]
"Volume{cfd50d03-920b-11dd-9ea1-806e6f6e6963}DiscoverSnapshots (Enter)"=hex:48,\
00,00,00,00,00,00,00,22,5f,66,8a,db,a2,c9,01,00,00,00,00,00,00,00,00,20,00,\
00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Volume{cfd50d03-920b-11dd-9ea1-806e6f6e6963}DiscoverSnapshots (Leave)"=hex:48,\
00,00,00,00,00,00,00,22,5f,66,8a,db,a2,c9,01,00,00,00,00,00,00,00,00,21,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"VolumesSafeForWrite (Enter)"=hex:48,00,00,00,00,00,00,00,ea,95,66,93,db,a2,c9,\
01,00,00,00,00,00,00,00,00,1e,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00
"VolumesSafeForWrite (Leave)"=hex:48,00,00,00,00,00,00,00,2d,47,1b,96,db,a2,c9,\
01,00,00,00,00,00,00,00,00,1f,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\VssapiPublisher]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Providers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Providers\{b5946137-7b9f-4925-af80-51abd60b20d5}]
@="Microsoft Software Shadow Copy provider 1.0"
"Type"=dword:00000001
"Version"="1.0.0.7"
"VersionId"="{00000001-0000-0000-0007-000000000001}"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Providers\{b5946137-7b9f-4925-af80-51abd60b20d5}\CLSID]
@="{65EE1DBA-8FF4-4a58-AC1C-3470EE2F376A}"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings\WritersBlockingRevert]
"{2707761B-2324-473D-88EB-EB007A359533}"="DFS-R Writer"
"{D76F5A28-3092-4589-BA48-2958FB88CE29}"="FRS Writer"
"{B2014C9E-8711-4C5C-A5A9-3CF384484757}"="AD Writer"
"{DD846AAA-A1B6-42a8-AAF8-03DCB6114BFD}"="ADAM Writer"
"TornComponentsBlockRevert"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl]
"NT Authority\\NetworkService"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Enum]
"0"="Root\\LEGACY_VSS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
Text file attached also. Also, thanks for helping thus far.
