HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\w32Time
DisplayName REG_SZ @%SystemRoot%\system32\w32time.dll,-200
ImagePath REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k LocalService
Description REG_SZ @%SystemRoot%\system32\w32time.dll,-201
ObjectName REG_SZ NT AUTHORITY\LocalService
ErrorControl REG_DWORD 0x1
Start REG_DWORD 0x3
Type REG_DWORD 0x20
ServiceSidType REG_DWORD 0x1
RequiredPrivileges REG_MULTI_SZ SeAuditPrivilege\0SeChangeNotifyPrivilege\0SeCreateGlobalPrivilege\0SeSystemTimePrivilege
FailureActions REG_BINARY 80510100000000000000000003000000140000000100000060EA000001000000C0D401000000000000000000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\w32Time\Config
FrequencyCorrectRate REG_DWORD 0x4
PollAdjustFactor REG_DWORD 0x5
LargePhaseOffset REG_DWORD 0x2faf080
SpikeWatchPeriod REG_DWORD 0x384
LocalClockDispersion REG_DWORD 0xa
HoldPeriod REG_DWORD 0x5
PhaseCorrectRate REG_DWORD 0x1
UpdateInterval REG_DWORD 0x57e40
EventLogFlags REG_DWORD 0x2
AnnounceFlags REG_DWORD 0xa
TimeJumpAuditOffset REG_DWORD 0x7080
MinPollInterval REG_DWORD 0xa
MaxPollInterval REG_DWORD 0xf
MaxNegPhaseCorrection REG_DWORD 0xd2f0
MaxPosPhaseCorrection REG_DWORD 0xd2f0
MaxAllowedPhaseOffset REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\w32Time\Parameters
ServiceDll REG_EXPAND_SZ %systemroot%\system32\w32time.dll
ServiceMain REG_SZ SvchostEntry_W32Time
ServiceDllUnloadOnStop REG_DWORD 0x1
Type REG_SZ NTP
NtpServer REG_SZ time.windows.com,0x9
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\w32Time\Security
Security REG_BINARY 0100048084000000900000000000000014000000020070000500000000001400FD01020001010000000000051200000000001800FF010F0001020000000000052000000020020000000014008D010200010100000000000504000000000014008D010200010100000000000506000000000014009D010200010100000000000513000000010100000000000512000000010100000000000512000000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\w32Time\TimeProviders
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\w32Time\TimeProviders\NtpClient
DllName REG_EXPAND_SZ %systemroot%\system32\w32time.dll
Enabled REG_DWORD 0x1
InputProvider REG_DWORD 0x1
AllowNonstandardModeCombinations REG_DWORD 0x1
CrossSiteSyncFlags REG_DWORD 0x2
ResolvePeerBackoffMinutes REG_DWORD 0xf
ResolvePeerBackoffMaxTimes REG_DWORD 0x7
CompatibilityFlags REG_DWORD 0x80000000
EventLogFlags REG_DWORD 0x1
LargeSampleSkew REG_DWORD 0x3
SpecialPollInterval REG_DWORD 0x93a80
SpecialPollTimeRemaining REG_MULTI_SZ time.windows.com,0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\w32Time\TimeProviders\NtpServer
DllName REG_EXPAND_SZ %systemroot%\system32\w32time.dll
Enabled REG_DWORD 0x0
InputProvider REG_DWORD 0x0
AllowNonstandardModeCombinations REG_DWORD 0x1
EventLogFlags REG_DWORD 0x0
ChainEntryTimeout REG_DWORD 0x10
ChainMaxEntries REG_DWORD 0x80
ChainMaxHostEntries REG_DWORD 0x4
ChainDisable REG_DWORD 0x0
ChainLoggingRate REG_DWORD 0x1e
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\w32Time\TriggerInfo
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\w32Time\TriggerInfo\0
Type REG_DWORD 0x3
Action REG_DWORD 0x1
GUID REG_BINARY BA0AE21C5198214494301DDEB766E809
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\w32Time\TriggerInfo\1
Type REG_DWORD 0x3
Action REG_DWORD 0x2
GUID REG_BINARY 6E51AFDDC25866489574C3B615D42EA1