reg add "HKLM\SYSTEM\CurrentControlSet\Services\EventLog" ServiceDll /t REG_EXPAND_SZ /d "%SystemRoot%\System32\wevtsvc.dll" /f