Leaked source code of windows server 2003
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

891 lines
56 KiB

  1. @*:This file defines default security settings.
  2. @*:Please do not edit. Instead, email kirksol with the requested change.
  3. @*:Thanks!
  4. ; Copyright (c) Microsoft Corporation. All rights reserved.
  5. ;
  6. ; Security Configuration Template for Security Configuration Editor
  7. ;
  8. ; Template Name: DWUp.INF
  9. ; Template Version: 05.10.DK.0000
  10. ;
  11. ; Default Security Settings applied on Professional Upgrade
  12. [Profile Description]
  13. %SCEDWUpProfileDescription%
  14. [version]
  15. signature="$CHICAGO$"
  16. revision=1
  17. [System Access]
  18. LSAAnonymousNameLookup = 0
  19. ;----------------------------------------------------------------
  20. ;Event Log - Log Settings
  21. ;----------------------------------------------------------------
  22. [System Log]
  23. RestrictGuestAccess = 1
  24. [Security Log]
  25. RestrictGuestAccess = 1
  26. [Application Log]
  27. RestrictGuestAccess = 1
  28. ;----------------------------------------------------------------
  29. ;Registry Values
  30. ;----------------------------------------------------------------
  31. [Registry Values]
  32. ;On upgrade (NT4 or 5), we can only set those registry values that meet the following criteria:
  33. ;a. value known not to exist on previous versions OR
  34. ;b. default setting has changed from less secure (NT4) to more secure (Win2k+) OR
  35. ;c. PERsonal-specific settings that should be set differently on PRO
  36. ;Note PER to PRO upgrade is feasible unlike PRO to SRv. We assume default reg values for PER remain unchanged.
  37. MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UndockWithoutLogon=4,1
  38. MACHINE\System\CurrentControlSet\Control\Lsa\DisableDomainCreds=4,0
  39. MACHINE\System\CurrentControlSet\Control\Lsa\EveryoneIncludesAnonymous=4,0
  40. MACHINE\System\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy=4,0
  41. ;Maintain previous forceguest behavior
  42. ;MACHINE\System\CurrentControlSet\Control\Lsa\ForceGuest=4,0
  43. MACHINE\System\CurrentControlSet\Control\Lsa\LmCompatibilityLevel=4,2
  44. MACHINE\System\CurrentControlSet\Control\Lsa\LimitBlankPasswordUse=4,1
  45. MACHINE\System\CurrentControlSet\Control\Lsa\NoDefaultAdminOwner=4,1
  46. MACHINE\System\CurrentControlSet\Control\Lsa\RestrictAnonymousSAM=4,1
  47. MACHINE\System\CurrentControlSet\Control\SecurePipeServers\Winreg\AllowedPaths\Machine=8,Add:,Software\Microsoft\Windows NT\CurrentVersion\Print,Software\Microsoft\Windows NT\CurrentVersion\Windows,Remove:,System\CurrentControlSet\Control\ProductOptions,System\CurrentControlSet\Control\Server Applications,Software\Microsoft\Windows NT\CurrentVersion
  48. MACHINE\System\CurrentControlSet\Control\SecurePipeServers\Winreg\AllowedExactPaths\Machine=8,Add:,System\CurrentControlSet\Control\ProductOptions,System\CurrentControlSet\Control\Server Applications,Software\Microsoft\Windows NT\CurrentVersion
  49. MACHINE\System\CurrentControlSet\Control\Session Manager\Kernel\ObCaseInsensitive=4,1
  50. MACHINE\System\CurrentControlSet\Control\Session Manager\ProtectionMode=4,1
  51. MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\RestrictNullSessAccess=4,1
  52. MACHINE\System\CurrentControlSet\Services\LDAP\LDAPClientIntegrity=4,1
  53. MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\RequireSignOrSeal=4,1
  54. ;We cannot set the following values which were new for Win2k, because
  55. ;Win2k customers may have already configured them differently.
  56. ;Therefore, the following may not be configured on NT4 upgrade.
  57. ;
  58. ;MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Setup\RecoveryConsole\SecurityLevel=4,0
  59. ;MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Setup\RecoveryConsole\SetCommand=4,0
  60. ;MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AllocateDASD=1,0
  61. ;MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ScRemoveOption=1,0
  62. [Privilege Rights]
  63. ;
  64. ;World S-1-1-0
  65. ;
  66. ;NT Authority S-1-5
  67. ;LOCAL_SERVICE 19
  68. ;NETWORK_SERVICE 20
  69. ;
  70. ;Built-In Domain SubAuthority = S-1-5-32
  71. ;ADMINISTRATORS 544
  72. ;USERS 545
  73. ;GUESTS 546
  74. ;POWER_USERS 547
  75. ;ACCOUNT_OPS 548
  76. ;SYSTEM_OPS 549
  77. ;PRINT_OPS 550
  78. ;BACKUP_OPS 551
  79. ;REPLICATOR 552
  80. ;RAS_SERVERS 553
  81. ;PREW2KCOMPACCESS 554
  82. ;REMOTE_DESKTOP_USERS 555
  83. ;NETWORK_CONFIGURATION_OPS 556
  84. SeAssignPrimaryTokenPrivilege = Add:, *S-1-5-19, *S-1-5-20
  85. SeAuditPrivilege = Add:, *S-1-5-19, *S-1-5-20
  86. SeCreateGlobalPrivilege = Add:, *S-1-5-6, *S-1-5-32-544
  87. SeImpersonatePrivilege = Add:, *S-1-5-6, *S-1-5-32-544
  88. SeIncreaseBasePriorityPrivilege = Remove:, *S-1-5-32-547
  89. SeIncreaseQuotaPrivilege = Add:, *S-1-5-19, *S-1-5-20
  90. SeManageVolumePrivilege = Add:, *S-1-5-32-544
  91. SeRemoteInteractiveLogonRight = Add:, *S-1-5-32-544, *S-1-5-32-555
  92. SeRemoteShutdownPrivilege = Remove:, *S-1-5-32-547
  93. SeSystemTimePrivilege = Remove:, *S-1-5-19, *S-1-5-20
  94. ;Undock was added in Win2k. Not adding Users because:
  95. ;a.) Win2k customers may have justifiably removed them.
  96. ;b.) NT4 upgrade adds interactive to the Power Users group.
  97. SeUndockPrivilege = Add:, *S-1-5-32-544, *S-1-5-32-547
  98. ;[Group Membership]
  99. ;During upgrade, use net api's to
  100. ;1 - add Authenticated Users and Interactive into the Users group
  101. ;2 - add Interactive to the Power Users group if NT4 Workstation Upgrade
  102. [Service General Setting]
  103. ;Note: startup type should not be configured during setup\dcpromo.
  104. ;autostarted on workstations and servers, standalone or joined - Remove PU ability to stop\start.
  105. Browser,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  106. Dhcp,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRRC;;;NO)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  107. TrkWks,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  108. Dnscache,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRRC;;;NO)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  109. Eventlog,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  110. PolicyAgent,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  111. dmserver,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  112. Messenger,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  113. PlugPlay,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  114. Spooler,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  115. ProtectedStorage,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  116. RpcSs,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLORC;;;PU)(A;;CCLCSWRPLO;;;IU)(A;;CCLCSWRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  117. NtmsSvc,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  118. seclogon,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  119. SamSs,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLORC;;;PU)(A;;CCLCSWRPLO;;;IU)(A;;CCLCSWRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  120. lanmanserver,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  121. SENS,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  122. Schedule,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  123. Sysmonlog,,"D:(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCRPLOCR;;;LU)S:AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  124. LmHosts,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  125. LanmanWorkstation,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  126. RemoteRegistry,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  127. ;Not autostarted, but non-default DACL - Remove PU ability to change template
  128. ClipSrv,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLORC;;;PU)(A;;CCLCSWRPLO;;;IU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  129. NetDDE,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLORC;;;PU)(A;;CCLCSWRPLO;;;IU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  130. NetDDEdsdm,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLORC;;;PU)(A;;CCLCSWRPLO;;;IU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  131. EventSystem,,"D:(A;;CCLCSWRPLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLORC;;;PU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  132. ;Not autostarted if machine is standalone
  133. ;Netlogon,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  134. ;W32Time,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLORC;;;PU)(A;;CCLCSWRPLO;;;IU)(A;;CCLCSWRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  135. ;Not autostarted if Wksta
  136. ;Alerter,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SO)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  137. ;MSDTC,,"D:(A;;CCLCSWRPLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SO)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLORC;;;NS)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  138. ;Server Only Services
  139. ;Dfs,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SO)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  140. ;LicenseService,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SO)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  141. ;IIS Specific Services - Leave them alone
  142. ;IISADMIN,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SO)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  143. ;W3SVC,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SO)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  144. ;MSFTPSVC,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SO)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  145. ;SMTPSVC,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPLOCRRC;;;PU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SO)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  146. [Registry Keys]
  147. "MACHINE\Software",0,"D:P(A;CI;GR;;;BU)(A;CI;GRGWSD;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  148. ;Same as parent, but this is the target of a symlink - set explicitly.
  149. "MACHINE\SOFTWARE\Classes",2,"D:P(A;CI;GR;;;BU)(A;CI;GRGWSD;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  150. "MACHINE\SOFTWARE\Classes\helpfile",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  151. "MACHINE\SOFTWARE\Classes\.hlp",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  152. "MACHINE\SOFTWARE\Microsoft\ADs\Providers\LDAP\Extensions",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  153. @@:@i:"MACHINE\SOFTWARE\Microsoft\ADs\Providers\NDS",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  154. @@:@i:"MACHINE\SOFTWARE\Microsoft\ADs\Providers\NWCOMPAT",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  155. "MACHINE\SOFTWARE\Microsoft\ADs\Providers\WinNT",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  156. "MACHINE\SOFTWARE\Microsoft\Command Processor",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  157. "MACHINE\SOFTWARE\Microsoft\Cryptography",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  158. "MACHINE\SOFTWARE\Microsoft\Cryptography\Calais",2,"D:AR(A;CI;GRGWSD;;;LS)"
  159. "MACHINE\SOFTWARE\Microsoft\DeviceManager",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  160. "MACHINE\SOFTWARE\Microsoft\Driver Signing",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  161. "MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  162. "MACHINE\Software\Microsoft\EventSystem",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  163. "MACHINE\SOFTWARE\Microsoft\Non-Driver Signing",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  164. "MACHINE\SOFTWARE\Microsoft\NetDDE",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  165. "MACHINE\SOFTWARE\Microsoft\OLAP Server\CurrentVersion\SECURITY",1,"D:AR"
  166. "MACHINE\SOFTWARE\Microsoft\Ole",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  167. "MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider",1,"D:AR"
  168. "MACHINE\SOFTWARE\Microsoft\Rpc",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  169. "MACHINE\SOFTWARE\Microsoft\Secure",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  170. "MACHINE\Software\Microsoft\Speech",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  171. "MACHINE\SOFTWARE\Microsoft\SystemCertificates",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  172. "MACHINE\SOFTWARE\Microsoft\Windows",2,"D:AR"
  173. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  174. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  175. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  176. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  177. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  178. ;The following keys do not exist when we run
  179. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy",1,"D:AR"
  180. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer",1,"D:AR"
  181. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies",1,"D:AR"
  182. "MACHINE\SOFTWARE\Microsoft\MSDTC",1,"D:AR"
  183. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony",2,"D:P(A;CIOI;GR;;;BU)(A;CIOI;GRGWSD;;;PU)(A;CIOI;GA;;;NS)(A;CIOI;GA;;;LS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  184. "MACHINE\SOFTWARE\Microsoft\Windows NT",2,"D:AR"
  185. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  186. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AEDebug",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  187. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Asr\Commands",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GRGWSD;;;BO)"
  188. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Classes",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  189. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  190. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EFS",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  191. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Event Viewer",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  192. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Font Drivers",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  193. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontMapper",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  194. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  195. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  196. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GR;;;LS)(A;CI;GR;;;NS)(A;CI;GR;;;LU)(A;CI;GR;;;MU)"
  197. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009",1,"D:AR"
  198. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  199. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList",0,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  200. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SecEdit",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  201. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Setup\RecoveryConsole",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  202. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  203. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  204. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing",2,"D:P(A;CI;GRGWSD;;;LS)(A;CI;GRGWSD;;;NS)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  205. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WbemPerf",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GR;;;LS)(A;CI;GR;;;NS)(A;CI;GR;;;LU)(A;CI;GR;;;MU)"
  206. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  207. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  208. "MACHINE\SOFTWARE\Microsoft\wbem",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GA;;;NS)(A;CI;GR;;;BU)"
  209. "MACHINE\SOFTWARE\Microsoft\wbem\CIMOM",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GR;;;BU)"
  210. "MACHINE\SOFTWARE\Microsoft\wbem\Transports",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GR;;;BU)"
  211. "MACHINE\SOFTWARE\Microsoft\wbem\ESS",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GR;;;BU)"
  212. "MACHINE\SOFTWARE\Microsoft\wbem\FWD",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GR;;;BU)"
  213. "MACHINE\SOFTWARE\Policies",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  214. "MACHINE\System",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  215. "MACHINE\SYSTEM\Clone",1,"D:AR"
  216. "MACHINE\SYSTEM\ControlSet001",1,"D:AR"
  217. "MACHINE\SYSTEM\ControlSet002",1,"D:AR"
  218. "MACHINE\SYSTEM\ControlSet003",1,"D:AR"
  219. "MACHINE\SYSTEM\ControlSet004",1,"D:AR"
  220. "MACHINE\SYSTEM\ControlSet005",1,"D:AR"
  221. "MACHINE\SYSTEM\ControlSet006",1,"D:AR"
  222. "MACHINE\SYSTEM\ControlSet007",1,"D:AR"
  223. "MACHINE\SYSTEM\ControlSet008",1,"D:AR"
  224. "MACHINE\SYSTEM\ControlSet009",1,"D:AR"
  225. "MACHINE\SYSTEM\ControlSet010",1,"D:AR"
  226. "MACHINE\SYSTEM\CurrentControlSet\Control\Class",1,"D:AR"
  227. "MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layout",2,"D:(A;CI;GR;;;WD)"
  228. "MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layouts",2,"D:(A;CI;GR;;;WD)"
  229. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Audit",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  230. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\JD",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  231. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Skew1",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  232. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\GBG",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  233. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Data",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  234. "MACHINE\SYSTEM\CurrentControlSet\Control\Network",2,"D:(A;CI;GRGWSD;;;NO)"
  235. "MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg",2,"D:P(A;CI;GA;;;BA)(A;;GR;;;BO)(A;CI;GR;;;LS)"
  236. "MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  237. "MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Executive",2,"D:(A;CI;GRGWSD;;;PU)"
  238. "MACHINE\SYSTEM\CurrentControlSet\Control\TimeZoneInformation",2,"D:(A;CI;GRGWSD;;;PU)"
  239. "MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security",2,"D:P(A;CI;GR;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  240. "MACHINE\SYSTEM\CurrentControlSet\Enum",1,"D:AR"
  241. "MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles",1,"D:AR"
  242. ;Don't whack more restrictive security subkeys.
  243. "MACHINE\SYSTEM\CurrentControlSet\Services",0,"D:AR"
  244. ;Set security subkey permissions for those services created via default hives
  245. "MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  246. "MACHINE\SYSTEM\CurrentControlSet\Services\ClipSrv\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  247. "MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  248. "MACHINE\SYSTEM\CurrentControlSet\Services\ERSvc\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  249. @*:Fix for 477845 causes regression for 32625
  250. ;"MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  251. @*:We still can add a SACL to it though.
  252. "MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security",2,"S:AR(AU;OICISAFA;DCLCSDWDWO;;;WD)"
  253. @@:@6:"MACHINE\SYSTEM\CurrentControlSet\Services\IASJet\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  254. "MACHINE\SYSTEM\CurrentControlSet\Services\NetDDE\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  255. "MACHINE\SYSTEM\CurrentControlSet\Services\NetDDEdsdm\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  256. "MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  257. "MACHINE\SYSTEM\CurrentControlSet\Services\Samss\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  258. "MACHINE\SYSTEM\CurrentControlSet\Services\SCardSvr\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  259. "MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  260. "MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  261. ;Set security subkey permissions for those services created in GUI-mode setup before SCE runs
  262. "MACHINE\SYSTEM\CurrentControlSet\Services\IREnum\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  263. "MACHINE\SYSTEM\CurrentControlSet\Services\STISvc\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  264. "MACHINE\SYSTEM\CurrentControlSet\Services\WMI\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  265. "MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog\Log Queries",2,"D:(A;CI;GA;;;NS)(A;CI;CCDCLCSWSDRC;;;LU)"
  266. "USERS\.DEFAULT",2,"D:P(A;CI;GR;;;BU)(A;CI;GR;;;PU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  267. "USERS\.DEFAULT\Software\Microsoft\NetDDE",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  268. "USERS\.DEFAULT\SOFTWARE\Microsoft\Protected Storage System Provider",1,"D:AR"
  269. "USERS\.DEFAULT\SOFTWARE\Microsoft\SystemCertificates\Root\ProtectedRoots",1,"D:AR"
  270. [File Security]
  271. ;---------------------------------------------------------------------------------------
  272. ;x86 Boot Files
  273. ;---------------------------------------------------------------------------------------
  274. @@:@i:"%BootDrive%\boot.ini",2,"D:P(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  275. @@:@i:"%BootDrive%\ntdetect.com",2,"D:P(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  276. @@:@i:"%BootDrive%\ntldr",2,"D:P(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  277. @@:@i:"%BootDrive%\ntbootdd.sys",2,"D:P(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  278. @@:@i:"%BootDrive%\autoexec.bat",2,"D:P(A;;GRGX;;;BU)(A;;GRGWGXSD;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  279. @@:@i:"%BootDrive%\config.sys",2,"D:P(A;;GRGX;;;BU)(A;;GRGWGXSD;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  280. ;---------------------------------------------------------------------------------------
  281. ;amd64 Boot Files
  282. ;---------------------------------------------------------------------------------------
  283. @@:@a:"%BootDrive%\boot.ini",2,"D:P(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  284. @@:@a:"%BootDrive%\ntdetect.com",2,"D:P(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  285. @@:@a:"%BootDrive%\ntldr",2,"D:P(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  286. ;---------------------------------------------------------------------------------------
  287. ;System Drive
  288. ;---------------------------------------------------------------------------------------
  289. ;SetupSecurity will contain the new root acl. Ignore docs and settings if it's reapplied (e.g. on conversion from FAT)
  290. "%SystemDrive%\Documents and Settings",1,"D:AR"
  291. ; Directories that might not exist when security is applied; but are listed here
  292. ; so that they get secured correctly on converting the file system to NTFS
  293. "%SystemDrive%\perflogs",2,"D:P(A;CIOI;GRGX;;;MU)(A;CIOI;GRGWGXSDRC;;;NS)(A;CIOI;GRGWGXSDRC;;;LU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  294. "%SystemDrive%\System Volume Information",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  295. "%SystemDrive%\wmpub",2,"D:P(A;CIOI;GRGWGXSD;;;BU)(A;CIOI;GRGWGXSD;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  296. ;---------------------------------------------------------------------------------------------
  297. ;ProgramFiles
  298. ;---------------------------------------------------------------------------------------------
  299. "%SceInfProgramFiles%",0,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  300. "%SceInfProgramFiles%\Microsoft SQL Server\MSSQL$UDDI",2,"D:P(A;CIOI;GA;;;BA)"
  301. "%SceInfProgramFiles%\WindowsUpdate",2,"D:P(A;CIOI;GRGWGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  302. "%SceInfCommonProgramFiles%\Microsoft Shared\Speech",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  303. "%SceInfCommonProgramFiles%\SpeechEngines\Microsoft\TTS",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  304. ;---------------------------------------------------------------------------------------------
  305. ;ia64 ProgramFiles Directory
  306. ;---------------------------------------------------------------------------------------------
  307. @@:@m:"%SceInfProgramFilesx86%",0,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  308. ;---------------------------------------------------------------------------------------------
  309. ;System Root (Typically \WINDOWS)
  310. ;---------------------------------------------------------------------------------------------
  311. "%SystemRoot%",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  312. ;Directories that existed and inherited on NT4 out of the box.
  313. ;The text-mode files within these directories are individually secured below.
  314. ;Config, Cursors, Help, Media, Repair, System, Fonts, INF
  315. ;Directories that existed but did not inherit on NT4.
  316. "%SystemRoot%\repair",2,"D:P(A;CI;GRGX;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  317. ;Directories with a legacy history that now ship in the box.
  318. ;Allow Power User Modify on the directory, but Read Only to the files installed during setup.
  319. "%SystemRoot%\addins",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  320. "%SystemRoot%\Connection Wizard",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  321. "%SystemRoot%\java",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  322. "%SystemRoot%\msagent",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  323. "%SystemRoot%\twain_32",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  324. "%SystemRoot%\Web",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  325. ;Directories with a legacy history that no longer ship in the box
  326. "%SystemRoot%\speech",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  327. ;Directories with a legacy history being changed for security reasons
  328. "%SystemRoot%\Debug",2,"D:P(A;;GX;;;BU)(A;;GX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  329. "%SystemRoot%\Debug\UserMode",2,"D:PAR(A;;0x00100023;;;BU)(A;OIIO;0x00100006;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  330. "%SystemRoot%\Temp",2,"D:P(A;CI;0x100026;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  331. ;Directories with no legacy to preserve. Power Users the same as Users
  332. "%SystemRoot%\AppPatch",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  333. "%SystemRoot%\Driver Cache",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  334. "%SystemRoot%\mui",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  335. "%SystemRoot%\Resources",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  336. "%SystemRoot%\Security",2,"D:P(A;CI;GX;;;BU)(A;CI;GX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  337. "%SystemRoot%\Security\templates",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  338. "%SystemRoot%\Web\printers\prtcabs",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)(A;CIOI;GRGWGXSD;;;NS)"
  339. "%SystemRoot%\WinSxS",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  340. ;Directories that do not exist when security applied during clean-install - Creator specifies directory security.
  341. ;We explicitly ignore so as not to whack the component-specified DIRECTORY security on upgrade or reapplication of defaults.
  342. "%SystemRoot%\CSC",1,"D:AR"
  343. ;Profiles folder (typically %SystemRoot%\Profiles)
  344. "%Profiles%",1,"D:AR"
  345. ; Directories that might not exist when security is applied; but are listed here
  346. ; so that they get secured correctly on converting the file system to NTFS
  347. "%SystemRoot%\Installer",2,"D:P(A;CIOI;GRGX;;;WD)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  348. "%SystemRoot%\PCHEALTH\HELPCTR",2,"D:P(A;CIOI;GRGX;;;WD)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  349. "%SystemRoot%\PCHEALTH\HELPCTR\Config",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  350. "%SystemRoot%\PCHEALTH\HELPCTR\DataColl",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  351. "%SystemRoot%\PCHEALTH\HELPCTR\PackageStore",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  352. "%SystemRoot%\prefetch",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  353. "%SystemRoot%\Registration",2,"D:P(A;OI;GRGX;;;WD)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  354. "%SystemRoot%\Registration\CRMLog",0,"D:P(A;;0x1200ab;;;BU)(A;OIIO;GRGWSD;;;BU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  355. "%SystemRoot%\Tasks",2,"D:P(A;;0x1200ab;;;AU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  356. ;Directories that do not exist when security applied during setup - Creator does not specify directory security.
  357. ;Creator should specify FILE security in optional component INF that gets applied on clean-install AND upgrade.
  358. ;Omit (rather than ignore) to allow component-specified file security to be set on reapplication of defaults.
  359. ;Use MARTA (rather than omit) for any components that set protected run-time security.
  360. ;"%SystemRoot%\Downloaded Program Files",0,"D:AR"
  361. ;"%SystemRoot%\Offline Web Pages",0,"D:AR"
  362. ;"%SystemRoot%\IME",0,"D:AR"
  363. ;"%SystemRoot%\mww32",0,"D:AR"
  364. ;"%SystemRoot%\PCHEALTH",0,"D:AR"
  365. ;"%SystemRoot%\SchCache",0,"D:AR"
  366. ;"%SystemRoot%\srchasst",0,"D:AR"
  367. ;---------------------------------------------------------------------------------------------
  368. ;System Directory (Typically \Windows\System32)
  369. ;---------------------------------------------------------------------------------------------
  370. "%SystemDirectory%",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  371. ;Directories that existed and inherited on NT4 out of the box.
  372. ;The text-mode files within these directories are individually secured below.
  373. ;OS2, RAS, Spool, Viewers, WINS
  374. ;So spooler can load drivers while impersonating the forced Guest
  375. "%SystemDirectory%\spool\drivers",2,"D:(A;CIOI;GRGX;;;WD)"
  376. ;Directories that existed but did not inherit on NT4.
  377. "%SystemDirectory%\config",2,"D:P(A;CI;GRGX;;;BU)(A;CI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  378. ;Profile for system account - moved from Docs and Settings in Whistler. Creator specifies security.
  379. "%SystemDirectory%\config\systemprofile",1,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  380. "%SystemDirectory%\dhcp",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  381. "%SystemDirectory%\dllcache",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  382. "%SystemDirectory%\drivers",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  383. ;Directories with a legacy history that now ship in the box.
  384. ;Allow Power User Modify on the directory, but Read Only to the files installed during setup.
  385. "%SystemDirectory%\ShellExt",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  386. "%SystemDirectory%\wbem",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  387. ;Directories with a legacy history that no longer ship in the box
  388. ;
  389. ;Directories with a legacy history being changed for security reasons
  390. "%SystemDirectory%\catroot",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  391. "%SystemDirectory%\catroot2",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  392. "%SystemDirectory%\ias",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  393. ;Directories with no legacy to preserve. Power Users the same as Users
  394. "%SystemDirectory%\3com_dmi",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  395. "%SystemDirectory%\Export",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  396. "%SystemDirectory%\icsxml",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  397. "%SystemDirectory%\mui",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  398. @@:@i:"%SystemDirectory%\oobe",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  399. ;Directories with no legacy to preserve. Different from parent.
  400. "%SystemDirectory%\LogFiles\ShutDown",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  401. "%SystemDirectory%\setup",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  402. "%SystemDirectory%\wbem\mof",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  403. "%SystemDirectory%\wbem\repository",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  404. "%SystemDirectory%\wbem\logs",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)(A;CIOI;GRGXGW;;;NS)(A;CIOI;GRGXGW;;;LS)"
  405. "%SystemDirectory%\wbem\AutoRecover",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  406. ;Directories that do not exist when security applied during clean-install - Creator specifies directory security.
  407. ;We explicitly ignore so as not to whack the component-specified DIRECTORY security on upgrade or reapplication of defaults.
  408. "%SystemDirectory%\appmgmt",1,"D:AR"
  409. "%SystemDirectory%\DTCLog",1,"D:AR"
  410. "%SystemDirectory%\ReinstallBackups",1,"D:AR"
  411. "%SystemDirectory%\repl",1,"D:AR"
  412. ; Directories that might not exist when security is applied; but are listed here
  413. ; so that they get secured correctly on converting the file system to NTFS
  414. "%SystemDirectory%\com\dmp",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  415. "%SystemDirectory%\CPL.CFG",2,"D:(A;CIOI;GA;;;NS)"
  416. "%SystemDirectory%\CertLog",2,"D:P(A;CIOI;GA;;;BO)(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICIIO;FA;;;CO)"
  417. "%SystemDirectory%\GroupPolicy",2,"D:P(A;CIOI;GRGX;;;AU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  418. "%SystemDirectory%\FxsTmp",2,"D:P(A;;0x100003;;;BU)(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICIIO;FA;;;CO)"
  419. "%SystemDirectory%\LLS",2,"D:(A;CIOI;GA;;;NS)"
  420. "%SystemDirectory%\LLS\CPL.CFG",2,"D:P(A;CIOI;GA;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  421. "%SystemDirectory%\LLS\LlsCert.LLS",2,"D:P(A;CIOI;GA;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  422. "%SystemDirectory%\LLS\LlsMap.LLS",2,"D:P(A;CIOI;GA;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  423. "%SystemDirectory%\LLS\LlsUser.LLS",2,"D:P(A;CIOI;GA;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  424. "%SystemDirectory%\LogFiles\Fax\Incoming",2,"D:P(A;CIOI;GA;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  425. "%SystemDirectory%\LogFiles\Fax\Outgoing",2,"D:P(A;CIOI;GA;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  426. "%SystemDirectory%\LogFiles\UDDI",2,"D:(A;CIOI;GRGWGXSD;;;NS)"
  427. "%SystemDirectory%\LogFiles\wms",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GRGWGXSD;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  428. "%SystemDirectory%\LServer",2,"D:P(A;OICI;GRGWGXDTSDCCLC;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  429. "%SystemDirectory%\msdtc",2,"D:P(A;OICI;GRGWGX;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  430. "%SystemDirectory%\msmq",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  431. "%SystemDirectory%\NTMSData",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  432. "%SystemDirectory%\RemoteStorage",2,"D:P(A;CIOI;GRGX;;;BO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  433. "%SystemDirectory%\spool\printers",2,"D:P(A;CI;0x1000ae;;;BU)(A;CI;0x1000ae;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  434. "%SystemDirectory%\tssesdir",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  435. "%SystemDirectory%\Windows media",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGWGXSD;;;NS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  436. ;Directories that do not exist when security applied during setup - Creator does not specify directory security.
  437. ;Creator should specify FILE security in optional component INF that gets applied on clean-install AND upgrade.
  438. ;Omit (rather than ignore) to allow component-specified file security to be set on reapplication of defaults.
  439. ;Use MARTA (rather than omit) for any components that set protected run-time security.
  440. ;"%SystemDirectory%\Cache",0,"D:AR"
  441. ;"%SystemDirectory%\Com",0,"D:AR"
  442. ;"%SystemDirectory%\clients",0,"D:AR"
  443. ;"%SystemDirectory%\inetsrv",0,"D:AR"
  444. ;"%SystemDirectory%\Microsoft",0,"D:AR"
  445. ;"%SystemDirectory%\npp",0,"D:AR"
  446. ;"%SystemDirectory%\oobe",0,"D:AR"
  447. ;"%SystemDirectory%\restore",0,"D:AR"
  448. ;"%SystemDirectory%\reminst",0,"D:AR"
  449. ;"%SystemDirectory%\rocket",0,"D:AR"
  450. ;"%SystemDirectory%\usmt",0,"D:AR"
  451. ;-----------------------------------------------------------------------------------------
  452. ; SysWOW64 directories
  453. ;-----------------------------------------------------------------------------------------
  454. @@:@6:"%Systemroot%\SysWOW64",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  455. @@:@6:"%Systemroot%\SysWOW64\wbem",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CI;GRGWGXSD;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  456. @@:@6:"%Systemroot%\SysWOW64\Export",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GRGX;;;PU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  457. @@:@6:"%Systemroot%\SysWOW64\ias",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  458. ;-----------------------------------------------------------------------------------------
  459. ;Individual File Settings.
  460. ;So that Power User Modify is not inherited from parent.
  461. ;-----------------------------------------------------------------------------------------
  462. "%Systemroot%\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  463. Exception="win.ini"
  464. "%Systemroot%\System\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  465. "%Systemroot%\Inf\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  466. Exception="msmail.inf"
  467. "%Systemroot%\Help\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  468. "%Systemroot%\Help\mail\smtpsnap.cnt",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  469. "%Systemroot%\Help\mail\smtpsnap.hlp",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  470. "%Systemroot%\Help\news\nntpsnap.cnt",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  471. "%Systemroot%\Help\news\nntpsnap.hlp",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  472. "%Systemroot%\Fonts\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  473. "%Systemroot%\Config\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  474. "%Systemroot%\Media\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  475. "%Systemroot%\Cursors\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  476. "%Systemroot%\repair\default",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  477. "%Systemroot%\repair\ntuser.dat",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  478. "%Systemroot%\repair\sam",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  479. "%Systemroot%\repair\security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  480. "%Systemroot%\repair\software",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  481. "%Systemroot%\repair\system",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  482. "%SystemRoot%\TAPI\tsec.ini",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  483. "%Systemdirectory%\hal.dll",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  484. "%Systemdirectory%\inetsrv\aqadmin.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  485. "%Systemdirectory%\inetsrv\aqueue.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  486. "%Systemdirectory%\inetsrv\ddrop.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  487. "%Systemdirectory%\inetsrv\isrpc.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  488. "%Systemdirectory%\inetsrv\mailmsg.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  489. "%Systemdirectory%\inetsrv\nntpadm.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  490. "%Systemdirectory%\inetsrv\nntpfs.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  491. "%Systemdirectory%\inetsrv\nntpsnap.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  492. "%Systemdirectory%\inetsrv\nntpsvc.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  493. "%Systemdirectory%\inetsrv\ntfsdrv.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  494. "%Systemdirectory%\inetsrv\rcancel.vbs",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  495. "%Systemdirectory%\inetsrv\regfilt.vbs",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  496. "%Systemdirectory%\inetsrv\rexpire.vbs",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  497. "%Systemdirectory%\inetsrv\rfeed.vbs",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  498. "%Systemdirectory%\inetsrv\rgroup.vbs",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  499. "%Systemdirectory%\inetsrv\rsess.vbs",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  500. "%Systemdirectory%\inetsrv\SCRIPTO.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  501. "%Systemdirectory%\inetsrv\seo.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  502. "%Systemdirectory%\inetsrv\seos.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  503. "%Systemdirectory%\inetsrv\smtpadm.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  504. "%Systemdirectory%\inetsrv\smtpsnap.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  505. "%Systemdirectory%\inetsrv\smtpsvc.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  506. "%Systemdirectory%\netmon\bhsupp.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  507. "%Systemdirectory%\netmon\hexedit.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  508. "%Systemdirectory%\netmon\netmon.exe",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  509. "%Systemdirectory%\netmon\netmon.ini",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  510. "%Systemdirectory%\netmon\nmapi.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  511. "%Systemdirectory%\netmon\parser.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  512. "%Systemdirectory%\netmon\parser.ini",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  513. "%Systemdirectory%\netmon\slbs.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  514. "%Systemdirectory%\netmon\default.adr",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  515. "%Systemdirectory%\netmon\captures\default.cf",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  516. "%Systemdirectory%\netmon\captures\default.df",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  517. "%Systemdirectory%\netmon\parsers\atalk.ini",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  518. "%Systemdirectory%\netmon\parsers\atalk.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  519. "%Systemdirectory%\netmon\parsers\BONE.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  520. "%Systemdirectory%\netmon\parsers\BROWSER.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  521. "%Systemdirectory%\netmon\parsers\FRAME.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  522. "%Systemdirectory%\netmon\parsers\IPX.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  523. "%Systemdirectory%\netmon\parsers\IPX.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  524. "%Systemdirectory%\netmon\parsers\LLC.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  525. "%Systemdirectory%\netmon\parsers\LLC.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  526. "%Systemdirectory%\netmon\parsers\MAC.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  527. "%Systemdirectory%\netmon\parsers\MAC.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  528. "%Systemdirectory%\netmon\parsers\MSRPC.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  529. "%Systemdirectory%\netmon\parsers\MSRPC.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  530. "%Systemdirectory%\netmon\parsers\NCP.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  531. "%Systemdirectory%\netmon\parsers\NETBIOS.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  532. "%Systemdirectory%\netmon\parsers\NETLOGON.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  533. "%Systemdirectory%\netmon\parsers\PPP.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  534. "%Systemdirectory%\netmon\parsers\PPP.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  535. "%Systemdirectory%\netmon\parsers\PPPOE.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  536. "%Systemdirectory%\netmon\parsers\SMB.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  537. "%Systemdirectory%\netmon\parsers\SNMP.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  538. "%Systemdirectory%\netmon\parsers\TCPIP.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  539. "%Systemdirectory%\netmon\parsers\TCPIP.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  540. "%Systemdirectory%\netmon\parsers\TRAIL.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  541. "%Systemdirectory%\netmon\parsers\TRAIL.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  542. "%Systemdirectory%\netmon\parsers\VINES.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  543. "%Systemdirectory%\netmon\parsers\VINES.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  544. "%Systemdirectory%\netmon\parsers\XNS.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  545. "%Systemdirectory%\netmon\parsers\XNS.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  546. "%Systemdirectory%\netmon\parsers\LOGON.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  547. "%Systemdirectory%\netmon\parsers\LSARPC.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  548. "%Systemdirectory%\netmon\parsers\WINSPL.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  549. "%Systemdirectory%\netmon\parsers\RSVP.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  550. "%Systemdirectory%\netmon\parsers\LANE.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  551. "%Systemdirectory%\netmon\parsers\ATMARP.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  552. "%Systemdirectory%\netmon\parsers\ATMARP.INI",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  553. "%Systemdirectory%\netmon\parsers\LDAP.DLL",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  554. "%Systemdirectory%\netmon\parsers\mcast.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  555. "%Systemdirectory%\netmon\parsers\kerbprsr.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  556. "%Systemdirectory%\netmon\parsers\upnpparser.dll",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  557. "%Systemdirectory%\netmon\parsers\upnpparser.ini",2,"D:P(A;;GRGX;;;WD)(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  558. "%Systemdirectory%\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  559. Exception="autoexec.nt"
  560. Exception="cmos.ram"
  561. Exception="config.nt"
  562. Exception="hpmon.dll"
  563. Exception="hpmon.hlp"
  564. Exception="localmon.dll"
  565. Exception="midimap.cfg"
  566. Exception="append.exe"
  567. Exception="arp.exe"
  568. Exception="at.exe"
  569. Exception="atmadm.exe"
  570. Exception="attrib.exe"
  571. Exception="bootcfg.exe"
  572. Exception="cacls.exe"
  573. Exception="certreq.exe"
  574. Exception="certutil.exe"
  575. Exception="change.exe"
  576. Exception="chcp.com"
  577. Exception="chglogon.exe"
  578. Exception="chgport.exe"
  579. Exception="chgusr.exe"
  580. Exception="chkdsk.exe"
  581. Exception="chkntfs.exe"
  582. Exception="choice.exe"
  583. Exception="cidaemon.exe"
  584. Exception="cipher.exe"
  585. Exception="clip.exe"
  586. Exception="cluster.exe"
  587. Exception="cmd.exe"
  588. Exception="cmdkey.exe"
  589. Exception="comclust.exe"
  590. Exception="command.com"
  591. Exception="comp.exe"
  592. Exception="compact.exe"
  593. Exception="convert.exe"
  594. Exception="convlog.exe"
  595. Exception="cprofile.exe"
  596. Exception="cscript.exe"
  597. Exception="csvde.exe"
  598. Exception="dcgpofix.exe"
  599. Exception="dcphelp.exe"
  600. Exception="debug.exe"
  601. Exception="defrag.exe"
  602. Exception="dfscmd.exe"
  603. Exception="diantz.exe"
  604. Exception="diskcomp.com"
  605. Exception="diskcopy.com"
  606. Exception="diskpart.exe"
  607. Exception="diskperf.exe"
  608. Exception="dns.exe"
  609. Exception="doskey.exe"
  610. Exception="dosx.exe"
  611. Exception="driverquery.exe"
  612. Exception="dsadd.exe"
  613. Exception="dsget.exe"
  614. Exception="dsmod.exe"
  615. Exception="dsmove.exe"
  616. Exception="dsquery.exe"
  617. Exception="dsrm.exe"
  618. Exception="edit.com"
  619. Exception="edlin.exe"
  620. Exception="esentutl.exe"
  621. Exception="eventcreate.exe"
  622. Exception="eventtriggers.exe"
  623. Exception="evntcmd.exe"
  624. Exception="exe2bin.exe"
  625. Exception="expand.exe"
  626. Exception="fastopen.exe"
  627. Exception="fc.exe"
  628. Exception="find.exe"
  629. Exception="findstr.exe"
  630. Exception="finger.exe"
  631. Exception="flattemp.exe"
  632. Exception="forcedos.exe"
  633. Exception="forfiles.exe"
  634. Exception="format.com"
  635. Exception="freedisk.exe"
  636. Exception="fsutil.exe"
  637. Exception="ftp.exe"
  638. Exception="fxssvc.exe"
  639. Exception="getmac.exe"
  640. Exception="gettype.exe"
  641. Exception="gpresult.exe"
  642. Exception="gpupdate.exe"
  643. Exception="graftabl.com"
  644. Exception="graphics.com"
  645. Exception="grovel.exe"
  646. Exception="help.exe"
  647. Exception="hostname.exe"
  648. Exception="iisreset.exe"
  649. Exception="inuse.exe"
  650. Exception="ipconfig.exe"
  651. Exception="ipsec6.exe"
  652. Exception="ipxroute.exe"
  653. Exception="ismserv.exe"
  654. Exception="jetconv.exe"
  655. Exception="jetpack.exe"
  656. Exception="kb16.com"
  657. Exception="label.exe"
  658. Exception="ldifde.exe"
  659. Exception="loadfix.com"
  660. Exception="locator.exe"
  661. Exception="lodctr.exe"
  662. Exception="logman.exe"
  663. Exception="logoff.exe"
  664. Exception="lpq.exe"
  665. Exception="lpr.exe"
  666. Exception="lserver.exe"
  667. Exception="macfile.exe"
  668. Exception="makecab.exe"
  669. Exception="mem.exe"
  670. Exception="mode.com"
  671. Exception="more.com"
  672. Exception="mountvol.exe"
  673. Exception="mqbkup.exe"
  674. Exception="mqdssvc.exe"
  675. Exception="mqsvc.exe"
  676. Exception="mqtgsvc.exe"
  677. Exception="mrinfo.exe"
  678. Exception="mscdexnt.exe"
  679. Exception="msg.exe"
  680. Exception="msiexec.exe"
  681. Exception="nbtstat.exe"
  682. Exception="net.exe"
  683. Exception="net1.exe"
  684. Exception="netsh.exe"
  685. Exception="netstat.exe"
  686. Exception="nlb.exe"
  687. Exception="nlsfunc.exe"
  688. Exception="nslookup.exe"
  689. Exception="ntbackup.exe"
  690. Exception="ntdsutil.exe"
  691. Exception="ntfrs.exe"
  692. Exception="ntsd.exe"
  693. Exception="ntvdm.exe"
  694. Exception="nw16.exe"
  695. Exception="nwscript.exe"
  696. Exception="odbcconf.exe"
  697. Exception="openfiles.exe"
  698. Exception="pathping.exe"
  699. Exception="pentnt.exe"
  700. Exception="ping.exe"
  701. Exception="ping6.exe"
  702. Exception="powercfg.exe"
  703. Exception="print.exe"
  704. Exception="proxycfg.exe"
  705. Exception="qappsrv.exe"
  706. Exception="qprocess.exe"
  707. Exception="query.exe"
  708. Exception="quser.exe"
  709. Exception="qwinsta.exe"
  710. Exception="rasautou.exe"
  711. Exception="rasdial.exe"
  712. Exception="rcp.exe"
  713. Exception="recover.exe"
  714. Exception="redir.exe"
  715. Exception="reg.exe"
  716. Exception="regini.exe"
  717. Exception="register.exe"
  718. Exception="regsvr32.exe"
  719. Exception="relog.exe"
  720. Exception="replace.exe"
  721. Exception="reset.exe"
  722. Exception="rexec.exe"
  723. Exception="route.exe"
  724. Exception="routemon.exe"
  725. Exception="rsh.exe"
  726. Exception="RsLnk.exe"
  727. Exception="rsm.exe"
  728. Exception="Rss.exe"
  729. Exception="RsServ.exe"
  730. Exception="RsTore.exe"
  731. Exception="runas.exe"
  732. Exception="rwinsta.exe"
  733. Exception="sacsess.exe"
  734. Exception="sc.exe"
  735. Exception="scardsvr.exe"
  736. Exception="schtasks.exe"
  737. Exception="schupgr.exe"
  738. Exception="secedit.exe"
  739. Exception="setver.exe"
  740. Exception="setx.exe"
  741. Exception="sfc.exe"
  742. Exception="sfmprint.exe"
  743. Exception="sfmpsexe.exe"
  744. Exception="sfmsvc.exe"
  745. Exception="shadow.exe"
  746. Exception="share.exe"
  747. Exception="shutdown.exe"
  748. Exception="snmp.exe"
  749. Exception="snmptrap.exe"
  750. Exception="sort.exe"
  751. Exception="subst.exe"
  752. Exception="systeminfo.exe"
  753. Exception="takeown.exe"
  754. Exception="tapicfg.exe"
  755. Exception="taskkill.exe"
  756. Exception="tasklist.exe"
  757. Exception="tcpsvcs.exe"
  758. Exception="telnet.exe"
  759. Exception="tftp.exe"
  760. Exception="tftpd.exe"
  761. Exception="timeout.exe"
  762. Exception="tlntadmn.exe"
  763. Exception="tlntsess.exe"
  764. Exception="tracerpt.exe"
  765. Exception="tracert.exe"
  766. Exception="tracert6.exe"
  767. Exception="tree.com"
  768. Exception="tscon.exe"
  769. Exception="tsdiscon.exe"
  770. Exception="tsecimp.exe"
  771. Exception="tskill.exe"
  772. Exception="tsprof.exe"
  773. Exception="tssdis.exe"
  774. Exception="tsshutdn.exe"
  775. Exception="typeperf.exe"
  776. Exception="unlodctr.exe"
  777. Exception="upg351db.exe"
  778. Exception="ups.exe"
  779. Exception="verifier.exe"
  780. Exception="vssadmin.exe"
  781. Exception="vwipxspx.exe"
  782. Exception="w32tm.exe"
  783. Exception="waitfor.exe"
  784. Exception="where.exe"
  785. Exception="whoami.exe"
  786. Exception="win.com"
  787. Exception="wins.exe"
  788. Exception="wlbs.exe"
  789. Exception="xcopy.exe"
  790. Exception="wpa.bak"
  791. Exception="wpa.dbl"
  792. "%Systemdirectory%\cmd.exe",2,"D:P(A;;GRGX;;;IU)(A;;GRGX;;;SU)(A;;GA;;;BA)(A;;GA;;;SY)(A;;GA;;;CO)"
  793. "%Systemdirectory%\wpa.bak",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  794. "%Systemdirectory%\wpa.dbl",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  795. "%Systemdirectory%\OS2\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  796. "%Systemdirectory%\OS2\DLL\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  797. "%Systemdirectory%\RAS\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"
  798. "%Systemdirectory%\Viewers\*",2,"D:P(A;;GRGX;;;BU)(A;;GRGX;;;PU)(A;;GA;;;BA)(A;;GA;;;SY)"