G
Guest
Hi,
I am hoping someone might help educate me about a couple of files,
apparently part of the manufacturers' installation, that have many references
to registry keys that involve "impersonation."
One called HiveSys had this:
HKLM,"SYSTEM\CurrentControlSet\Control\Lsa",
"ImpersonatePrivilegeUpgradeToolHasRun", 0x00010003, 1
Another, called I think, HiveProg, had many, many, many of them, including:
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\cscdll","Impersonate",0x00010001,0
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\wlballoon","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\cscdll","Impersonate",0x00010001,0
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\ScCertProp","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\wlballoon","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\cscdll","Impersonate",0x00010001,0
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\ScCertProp","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
HKLM,"SOFTWARE\Microsoft\Windows
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\wlballoon","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\Windows
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\cscdll","Impersonate",0x00010001,0
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\ScCertProp","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\wlballoon","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\cscdll","Impersonate",0x00010001,0
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\ScCertProp","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\wlballoon","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\Windows
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\cscdll","Impersonate",0x00010001,0
HKLM,"SOFTWARE\Microsoft\Windows
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\ScCertProp","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\wlballoon","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\cscdll","Impersonate",0x00010001,0
HKLM,"SOFTWARE\Microsoft\Windows
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\ScCertProp","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\wlballoon","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\cscdll","Impersonate",0x00010001,0
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\ScCertProp","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
I am hoping someone might help educate me about a couple of files,
apparently part of the manufacturers' installation, that have many references
to registry keys that involve "impersonation."
One called HiveSys had this:
HKLM,"SYSTEM\CurrentControlSet\Control\Lsa",
"ImpersonatePrivilegeUpgradeToolHasRun", 0x00010003, 1
Another, called I think, HiveProg, had many, many, many of them, including:
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\cscdll","Impersonate",0x00010001,0
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\wlballoon","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\cscdll","Impersonate",0x00010001,0
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\ScCertProp","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\wlballoon","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\cscdll","Impersonate",0x00010001,0
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\ScCertProp","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
HKLM,"SOFTWARE\Microsoft\Windows
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\wlballoon","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\Windows
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\cscdll","Impersonate",0x00010001,0
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\ScCertProp","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\wlballoon","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\cscdll","Impersonate",0x00010001,0
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\ScCertProp","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\wlballoon","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\Windows
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\cscdll","Impersonate",0x00010001,0
HKLM,"SOFTWARE\Microsoft\Windows
HKLM,"SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\ScCertProp","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\wlballoon","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\cscdll","Impersonate",0x00010001,0
HKLM,"SOFTWARE\Microsoft\Windows
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\ScCertProp","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\wlballoon","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\cscdll","Impersonate",0x00010001,0
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\ScCertProp","Impersonate",0x00010001,1
HKLM,"SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\SensLogn","Impersonate",0x00010003,1