新建键
HKEY_CURRENT_USER\Software\LdShih\
HKEY_CURRENT_USER\Software\LdShih\LsFileExplorer\
HKEY_CURRENT_USER\Software\LdShih\LsFileExplorer\ParentImgIdx
键值: DWORD: 5 (0x5)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\JVAAG\flfgrz\gbbyf\fp.rkr
键值: 类型: REG_BINARY 长度: 16 (0x10) 字节
01 00 00 00 06 00 00 00 B0 1F 0A 7E AF 6B C7 01 | ...........~.k..
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\Qbphzragf naq Frggvatf\rhfre\桌面\SLSverJnyy.rkr
键值: 类型: REG_BINARY 长度: 16 (0x10) 字节
01 00 00 00 06 00 00 00 B0 15 C5 6D AF 6B C7 01 | ...........m.k..
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007032120070322\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007032120070322\CacheLimit
键值: DWORD: 8192 (0x2000)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007032120070322\CacheOptions
键值: DWORD: 11 (0xb)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007032120070322\CachePath
键值: 类型: REG_EXPAND_SZ 长度: 75 (0x4b) 字节
000000: 25 55 53 45 52 50 52 4F 46 49 4C 45 25 5C 4C 6F | %USERPROFILE%\Lo 000010: 63 61 6C 20 53 65 74 74 69 6E 67 73 5C 48 69 73 | cal Settings\His 000020: 74 6F 72 79 5C 48 69 73 74 6F 72 79 2E 49 45 35 | tory\History.IE5 000030: 5C 4D 53 48 69 73 74 30 31 32 30 30 37 30 33 32 | \MSHist012007032 000040: 31 32 30 30 37 30 33 32 32 5C 00 | 120070322\.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007032120070322\CachePrefix
键值: 字符串: ":2007032120070322: "
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007032120070322\CacheRepair
键值: DWORD: 0 (0)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\IgfxTray
键值: 字符串: "C:\Program Files\Internet Explorer\IEXPL0RE.EXE"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WebTime\
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WebTime\Description
键值: 字符串: "自动与 Internet 时间服务器同步。"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WebTime\DisplayName
键值: 字符串: "WebTime"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WebTime\ErrorControl
键值: DWORD: 1 (0x1)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WebTime\ImagePath
键值: 类型: REG_EXPAND_SZ 长度: 47 (0x2f) 字节
43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73 | C:\Program Files 5C 49 6E 74 65 72 6E 65 74 20 45 78 70 6C 6F 72 | \Internet Explor 65 72 5C 57 65 62 54 69 6D 65 2E 65 78 65 00 | er\WebTime.exe.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WebTime\
ObjectName
键值: 字符串: "LocalSystem"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WebTime\Security\
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WebTime\Security\Security
键值: 类型: REG_BINARY 长度: 184 (0xb8) 字节
000000: 01 00 14 80 A0 00 00 00 AC 00 00 00 14 00 00 00 | ...€............ 000010: 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 | 0............€.. 000020: FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 | ................ 000030: 02 00 70 00 04 00 00 00 00 00 18 00 FD 01 02 00 | ..p............. ...还有...
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WebTime\Start
键值: DWORD: 2 (0x2)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WebTime\Type
键值: DWORD: 272 (0x110)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebTime\
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebTime\Description
键值: 字符串: "自动与 Internet 时间服务器同步。"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebTime\DisplayName
键值: 字符串: "WebTime"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebTime\ErrorControl
键值: DWORD: 1 (0x1)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebTime\ImagePath
键值: 类型: REG_EXPAND_SZ 长度: 47 (0x2f) 字节
43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73 | C:\Program Files 5C 49 6E 74 65 72 6E 65 74 20 45 78 70 6C 6F 72 | \Internet Explor 65 72 5C 57 65 62 54 69 6D 65 2E 65 78 65 00 | er\WebTime.exe.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebTime\
ObjectName
键值: 字符串: "LocalSystem"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebTime\Security\
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebTime\Security\Security
键值: 类型: REG_BINARY 长度: 184 (0xb8) 字节
000000: 01 00 14 80 A0 00 00 00 AC 00 00 00 14 00 00 00 | ...€............ 000010: 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 | 0............€.. 000020: FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 | ................ 000030: 02 00 70 00 04 00 00 00 00 00 18 00 FD 01 02 00 | ..p............. ...还有...
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebTime\Start
键值: DWORD: 2 (0x2)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebTime\Type
键值: DWORD: 272 (0x110)
--------------
位置总数: 32
--------------------------------------------------------------------------------
文件列表位于 C:\WINNT\*.*
摘要信息:
已删除文件: 0
已修改文件: 0
新建文件 : 0
--------------------------------------------------------------------------------
文件列表位于 C:\WINNT\system32\*.*
摘要信息:
已删除文件: 1
已修改文件: 0
新建文件 : 1
已删除文件
perflib_perfdata_13c.dat 大小: 16,384,日期/时间: 2007年03月21日 19:51:46
--------------
位置总数: 1
新建文件
perflib_perfdata_374.dat 大小: 16,384,日期/时间: 2007年03月21日 19:53:26
--------------
位置总数: 1
--------------------------------------------------------------------------------
文件列表位于 C:\Documents and Settings\euser\My Documents\*.*
摘要信息:
已删除文件: 0
已修改文件: 1
新建文件 : 0
已修改文件
1.rsnp
旧: 大小: 7,160,800,日期/时间: 2007年02月03日 14:45:58
新: 大小: 7,226,384,日期/时间: 2007年03月21日 19:52:38
--------------
位置总数: 1
--------------------------------------------------------------------------------
文件列表位于 C:\Program Files\*.*
摘要信息:
已删除文件: 0
已修改文件: 0
新建文件 : 0