----------------------------------
修改键值:6
----------------------------------
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG\Seed: 60 DD 20 5E 1E E7 DB 0B CC DD CF 44 1B 72 16 C1 10 E3 FC AB 55 5B D8 9D A9 99 A4 55 2E DA 93 1C 68 CE 76 2A B7 5A EF E8 8F EA 1E 28 DB F3 DC 0D E4 F7 0A 64 A2 A4 35 8F F7 9E 2F 7C C2 84 64 73 0C 84 71 2C 4F 62 E6 06 17 92 3F 83 BC 04 C8 5E
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG\Seed: 26 B3 C4 4E 5D 82 EA EB 5A 1B 9D 11 68 C4 E6 26 AC 53 54 9E C6 32 47 AC 03 FA 22 0B 29 D1 90 04 8A B8 4C CB 8B 5E 90 22 E6 26 77 B9 60 83 42 94 00 2A 9F 33 3F 3F 29 7A 12 BD 81 D8 65 F5 3E CB 3D C1 47 22 3B 1D 65 B2 53 4B E8 0F 85 2B BA 04
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name: "msoobe.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name: "iexplore.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\ID: 0x3B7D853E
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\ID: 0x41107B81
HKEY_USERS\S-1-5-21-117609710-2025429265-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings: 3C 00 00 00 03 00 00 00 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKEY_USERS\S-1-5-21-117609710-2025429265-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings: 3C 00 00 00 04 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKEY_USERS\S-1-5-21-117609710-2025429265-725345543-1003\Software\Microsoft\Windows\ShellNoRoam\BagMRU\NodeSlots: 02 02 02 02 02 02 02
HKEY_USERS\S-1-5-21-117609710-2025429265-725345543-1003\Software\Microsoft\Windows\ShellNoRoam\BagMRU\NodeSlots: 02 02 02 02 02 02 02 02
HKEY_USERS\S-1-5-21-117609710-2025429265-725345543-1003\Software\Microsoft\Windows\ShellNoRoam\BagMRU\MRUListEx: 00 00 00 00 FF FF FF FF
HKEY_USERS\S-1-5-21-117609710-2025429265-725345543-1003\Software\Microsoft\Windows\ShellNoRoam\BagMRU\MRUListEx: 01 00 00 00 00 00 00 00 FF FF FF FF
----------------------------------
添加文件:75
----------------------------------
C:\Documents and Settings\ufo\Cookies\ufo@www.mishuren[2].txt
C:\Documents and Settings\ufo\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT
C:\Documents and Settings\ufo\Local Settings\Temp\Wolvez.Com
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YB0HQ7\20060405145810144[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YB0HQ7\459367da7b473[1].jpg
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YB0HQ7\459368b78c5ec[1].jpg
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YB0HQ7\bg_all[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YB0HQ7\CAYVQ3YL.htm
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YB0HQ7\code[1].php
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YB0HQ7\index_01[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YB0HQ7\left_tdbg1[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YB0HQ7\main_announce[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YB0HQ7\qq[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YB0HQ7\ShowClass_Menu[1].js
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YB0HQ7\ShowSpecialList[1].js
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YB0HQ7\system[1].exe
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YB0HQ7\tongji[1].htm
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YB0HQ7\voteView[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YZWDIN\1[1].htm
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YZWDIN\405[1].htm
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YZWDIN\a1[1].txt
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YZWDIN\a2[1].exe
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YZWDIN\beijing888[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YZWDIN\click[1].htm
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YZWDIN\cool[1].js
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YZWDIN\hengjiange[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YZWDIN\icon_0[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YZWDIN\index_02[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YZWDIN\left_tdbg2[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YZWDIN\main_title_575[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YZWDIN\newguest[1].htm
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YZWDIN\sa[1].htm
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\01YZWDIN\stm31[1].js
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KT2F8LMB\528438[1].js
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KT2F8LMB\a1[1].exe
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KT2F8LMB\announce[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KT2F8LMB\article_common[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KT2F8LMB\blank[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KT2F8LMB\code[1].htm
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KT2F8LMB\dbtl1[1].htm
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KT2F8LMB\DefaultSkin[1].css
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KT2F8LMB\index_03[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KT2F8LMB\jiange888[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KT2F8LMB\mishuren[1].htm
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KT2F8LMB\nologo[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KT2F8LMB\qq1[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KT2F8LMB\s[1].htm
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KT2F8LMB\UserLogin[1].htm
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KT2F8LMB\voteSubmit[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KXYBK5UV\a2[1].txt
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KXYBK5UV\ad[1].htm
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KXYBK5UV\arrow3[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KXYBK5UV\arrow_r[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KXYBK5UV\article_elite[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KXYBK5UV\dbtl[1].htm
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KXYBK5UV\flash[1].exe
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KXYBK5UV\google[1].htm
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KXYBK5UV\icon2[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KXYBK5UV\left_title[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KXYBK5UV\menu[1].js
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KXYBK5UV\Soft_common[1].gif
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KXYBK5UV\stat[1].htm
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KXYBK5UV\tvlm[1].css
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\KXYBK5UV\wzclick[1].htm
C:\Program Files\Internet Explorer\SMSS.EXE
C:\Program Files\Internet Explorer\SVCHOST.EXE
C:\WINDOWS\Prefetch\NET.EXE-01A53C2F.pf
C:\WINDOWS\Prefetch\NET1.EXE-029B9DB4.pf
C:\WINDOWS\Prefetch\SMSS.EXE-11FFFDBB.pf
C:\WINDOWS\Prefetch\SVCHOST.EXE-16C7D411.pf
C:\WINDOWS\Prefetch\WOLVEZ.COM-3983CE74.pf
C:\WINDOWS\system32\windhcp.ocx
C:\WINDOWS\RichDll.dll
C:\WINDOWS\svchost.exe
C:\WINDOWS\uninstall\rundl132.exe
----------------------------------
修改文件:15
----------------------------------
C:\Documents and Settings\ufo\Cookies\index.dat
C:\Documents and Settings\ufo\Local Settings\History\History.IE5\MSHist012007012520070126\index.dat
C:\Documents and Settings\ufo\Local Settings\Temporary Internet Files\Content.IE5\index.dat
C:\Documents and Settings\ufo\NTUSER.DAT.LOG
C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf
C:\WINDOWS\system32\CatRoot2\edb.chk
C:\WINDOWS\system32\config\software.LOG
C:\WINDOWS\system32\config\system.LOG
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP
C:\WINDOWS\system32\wbem\Repository\FS\
OBJECTS.DATA
C:\WINDOWS\system32\wbem\Repository\FS\
OBJECTS.MAP
----------------------------------
添加目录:6
----------------------------------
C:\Documents and Settings\ufo\Local Settings\Application Data\Microsoft\Internet Explorer
C:\Documents and Settings\ufo\Local Settings\Application Data\Microsoft\Internet Explorer\.
C:\Documents and Settings\ufo\Local Settings\Application Data\Microsoft\Internet Explorer\..
C:\WINDOWS\uninstall
C:\WINDOWS\uninstall\.
C:\WINDOWS\uninstall\..
----------------------------------
总计:183
----------------------------------