[Link]
1_HKey=HKEY_CLASSES_ROOT
1_Key=.exe
1_Name=
1_Value=exefile
1_HKeyLink=HKEY_CLASSES_ROOT
1_KeyLink=exefile\shell\open\command
1_NameLink=
1_ValueLink="%1" %*
2_HKey=HKEY_CLASSES_ROOT
2_Key=.com
2_Name=
2_Value=comfile
2_HKeyLink=HKEY_CLASSES_ROOT
2_KeyLink=comfile\shell\open\command
2_NameLink=
2_ValueLink="%1" %*
3_HKey=HKEY_CLASSES_ROOT
3_Key=.lnk
3_Name=
3_Value=lnkfile
3_HKeyLink=HKEY_CLASSES_ROOT
3_KeyLink=lnkfile\CLSID
3_NameLink=
3_ValueLink={00021401-0000-0000-C000-000000000046}
4_HKey=HKEY_CLASSES_ROOT
4_Key=.txt
4_Name=
4_Value=txtfile
4_HKeyLink=HKEY_CLASSES_ROOT
4_KeyLink=txtfile\shell\open\command
4_NameLink=
4_ValueLink=%SystemRoot%\system32\NOTEPAD.EXE %1
4_FileSizeLink=66560
4_FileDateLink=2005-8-1 上午 08:00:00
4_FileVersionLink=5.1.2600.2180
5_HKey=HKEY_CLASSES_ROOT
5_Key=.htm
5_Name=
5_Value=htmlfile
5_HKeyLink=HKEY_CLASSES_ROOT
5_KeyLink=htmlfile\shell\open\command
5_NameLink=
5_ValueLink="E:\Program Files\Internet Explorer\iexplore.exe" -nohome
5_FileSizeLink=93184
5_FileDateLink=2005-8-1 上午 08:00:00
5_FileVersionLink=6.0.2900.2180
6_HKey=HKEY_CLASSES_ROOT
6_Key=.html
6_Name=
6_Value=htmlfile
6_HKeyLink=HKEY_CLASSES_ROOT
6_KeyLink=htmlfile\shell\open\command
6_NameLink=
6_ValueLink="E:\Program Files\Internet Explorer\iexplore.exe" -nohome
6_FileSizeLink=93184
6_FileDateLink=2005-8-1 上午 08:00:00
6_FileVersionLink=6.0.2900.2180
7_HKey=HKEY_CLASSES_ROOT
7_Key=.url
7_Name=
7_Value=InternetShortcut
7_HKeyLink=HKEY_CLASSES_ROOT
7_KeyLink=InternetShortcut\shell\open\command
7_NameLink=
7_ValueLink=rundll32.exe shdocvw.dll,OpenURL %l
8_HKey=HKEY_CLASSES_ROOT
8_Key=PROTOCOLS\Filter\text/html
8_Name=CLSID
8_Value=
9_HKey=HKEY_CLASSES_ROOT
9_Key=PROTOCOLS\Filter\text/plain
9_Name=CLSID
9_Value=
10_HKey=HKEY_LOCAL_MACHINE
10_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
10_Name=
10_Value=http://
11_HKey=HKEY_LOCAL_MACHINE
11_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes
11_Name=www
11_Value=http://
Max=11
[Shdoclc]
1_FileSize=498176
1_FileDate=2005-8-1 上午 08:00:00
1_FileVersion=6.0.2900.2180
Max=1
[AppInit_DLLs]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
1_Name=AppInit_DLLs
1_Value=
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
2_Name=Userinit
2_Value=E:\WINDOWS\system32\userinit.exe,
2_FileSize=23552
2_FileDate=2005-8-1 上午 08:00:00
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
3_Name=Shell
3_Value=Explorer.exe
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
4_Name=System
3_Value=
Max=4
[WinSock2NameSpace]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
1_Name=DisplayString
1_Value=Tcpip
1_Enabled=1
1_LibraryPath=%SystemRoot%\System32\mswsock.dll
1_FileSize=240640
1_FileDate=2005-8-1 上午 08:00:00
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
2_Name=DisplayString
2_Value=NTDS
2_Enabled=1
2_LibraryPath=%SystemRoot%\System32\winrnr.dll
2_FileSize=16896
2_FileDate=2005-8-1 上午 08:00:00
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
3_Name=DisplayString
3_Value=网络位置知晓 (NLA) 名称空间
3_Enabled=1
3_LibraryPath=%SystemRoot%\System32\mswsock.dll
3_FileSize=240640
3_FileDate=2005-8-1 上午 08:00:00
Max=3
[WinSock2Protocol]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001
1_Name=PackedCatalogItem
1_FileName=%SystemRoot%\system32\mswsock.dll c a m v i d 3 0 . i n f
1_Value= ??挀挀搀攀挀漀搀攀?椀渀昀 ā 氀挀攀爀琀挀氀愀猀?椀渀昀 戀瀅挀漀洀洀甀渀椀挀?椀渀昀 ??揿漀洀渀琀??椀渀昀 吀
挀漀爀攀氀椀猀琀?椀渀昀 戀%?揿礀挀氀愀搀昀? ? ????耀?銡?ā ? ? ? ? ā ? ?匀????吀挀瀀椀瀀?嬀吀?倀??倀崀
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002
2_Name=PackedCatalogItem
2_FileName=%SystemRoot%\system32\mswsock.dll c a m v i d 3 0 . i n f
2_Value= ??挀挀搀攀挀漀搀攀?椀渀昀 ā 氀挀攀爀琀挀氀愀猀?椀渀昀 戀瀅挀漀洀洀甀渀椀挀?椀渀昀 ??揿漀洀渀琀??椀渀昀 吀
挀漀爀攀氀椀猀琀?椀渀昀 戀%?揿礀挀氀愀搀?? ? ????耀?銡?ā ? ? ? ? ? ? ? MSAFD Tcpip [UDP/IP]
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003
3_Name=PackedCatalogItem
3_FileName=%SystemRoot%\system32\mswsock.dll c a m v i d 3 0 . i n f
3_Value= ??挀挀搀攀挀漀搀攀?椀渀昀 ā 氀挀攀爀琀挀氀愀猀?椀渀昀 戀瀅挀漀洀洀甀渀椀挀?椀渀昀 ??揿漀洀渀琀??椀渀昀 吀
挀漀爀攀氀椀猀琀?椀渀昀 戀%?揿礀挀氀愀搀?? ? ????耀?銡?ā ? ? ? ? ? ? ? MSAFD Tcpip [RAW/IP]
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004
4_Name=PackedCatalogItem
4_FileName=%SystemRoot%\system32\rsvpsp.dll
4_Value=?揿愀洀瘀椀搀? ?椀渀昀 ā 戀? ccdecode.inf ? certclas.inf ?? communic.inf ??comnt5.inf ? corelist.inf ???cyclad☉ ?鵠????? 龍???唼u 砀??嚇u ? ? ? ? ? ? ? RSVP UDP Service Provider ?? ā ?矵?? ?? 捻欿??矵?w ???矵豈?聆氿?封?攀瘀椀挀攀尀笀??????????? ??? ???????????????? ?? 紀 ?????? ?? 紀 ????屐瀂鯁倂?????蠴畖? ?畕類??墶矷?? ???矚易?坐u 瀀鯁 ??龐矛???矚??矵??矵 ?? ?? tt??矵 ??矵 X ??矵 ?? 陳畗 ???SY?倀?? ā ?躐?漀渀琀?矵
5_HKey=HKEY_LOCAL_MACHINE
5_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005
5_Name=PackedCatalogItem
5_FileName=%SystemRoot%\system32\rsvpsp.dll
5_Value=?揿愀洀瘀椀搀? ?椀渀昀 ā 戀? ccdecode.inf ? certclas.inf ?? communic.inf ??comnt5.inf ? corelist.inf ???cyclad? ?鵠????? ockdow ? ? ? ? ? ā ? 刀匀嘀倀?吀?倀?匀攀爀瘀椀挀攀?倀爀漀瘀椀搀攀爀 ?姨?姨???????囝?? ?????? ?囝??囜 搀??矵 ???樀?w 囜囜耂 ā ???t? ??t? ? ??铀? ? ? ā ?t??? ??囜 ` 誥矵?蠿????矵 ? ?蠀? ???w??矵??矵?? ??斴矷????????矵?矚 ? ? ?????ā ? ?? 栀鯊 搀岨?矵?桷鯊 搀岨??
6_HKey=HKEY_LOCAL_MACHINE
6_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006
6_Name=PackedCatalogItem
6_FileName=%SystemRoot%\system32\mswsock.dll c a m v i d 3 0 . i n f
6_Value= ??挀挀搀攀挀漀搀攀?椀渀昀 ā 氀挀攀爀琀挀氀愀猀?椀渀昀 戀瀅挀漀洀洀甀渀椀挀?椀渀昀 ??揿漀洀渀琀??椀渀昀 吀
挀漀爀攀氀椀猀琀?椀渀昀 戀%?揿礀挀氀愀搀?? ? 弘玍?锑è往?? 耀 ?匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀??????????? ??? ???????????????? ?? 紀崀?匀?儀倀????吀?
7_HKey=HKEY_LOCAL_MACHINE
7_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007
7_Name=PackedCatalogItem
7_FileName=%SystemRoot%\system32\mswsock.dll c a m v i d 3 0 . i n f
7_Value= ??挀挀搀攀挀漀搀攀?椀渀昀 ā 氀挀攀爀琀挀氀愀猀?椀渀昀 戀瀅挀漀洀洀甀渀椀挀?椀渀昀 ??揿漀洀渀琀??椀渀昀 吀
挀漀爀攀氀椀猀琀?椀渀昀 戀%?揿礀挀氀愀搀?? ? 弘玍?锑è往?? 耀 ?匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀??????????? ??? ???????????????? ?? 紀崀???吀??刀???
8_HKey=HKEY_LOCAL_MACHINE
8_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008
8_Name=PackedCatalogItem
8_FileName=%SystemRoot%\system32\mswsock.dll c a m v i d 3 0 . i n f
8_Value= ??挀挀搀攀挀漀搀攀?椀渀昀 ā 氀挀攀爀琀挀氀愀猀?椀渀昀 戀瀅挀漀洀洀甀渀椀挀?椀渀昀 ??揿漀洀渀琀??椀渀昀 吀
挀漀爀攀氀椀猀琀?椀渀昀 戀%?揿礀挀氀愀搀?? 弘玍?锑è往?? ?? ?匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀??????????? ???????????? ?????????? 紀崀?匀?儀倀????吀??
9_HKey=HKEY_LOCAL_MACHINE
9_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009
9_Name=PackedCatalogItem
9_FileName=%SystemRoot%\system32\mswsock.dll c a m v i d 3 0 . i n f
9_Value= ??挀挀搀攀挀漀搀攀?椀渀昀 ā 氀挀攀爀琀挀氀愀猀?椀渀昀 戀瀅挀漀洀洀甀渀椀挀?椀渀昀 ??揿漀洀渀琀??椀渀昀 吀
挀漀爀攀氀椀猀琀?椀渀昀 戀%?揿礀挀氀愀搀?? 弘玍?锑è往?? ?? ?匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀??????????? ???????????? ?????????? 紀崀???吀??刀????
10_HKey=HKEY_LOCAL_MACHINE
10_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010
10_Name=PackedCatalogItem
10_FileName=%SystemRoot%\system32\mswsock.dll c a m v i d 3 0 . i n f
10_Value= ??挀挀搀攀挀漀搀攀?椀渀昀 ā 氀挀攀爀琀挀氀愀猀?椀渀昀 戀瀅挀漀洀洀甀渀椀挀?椀渀昀 ??揿漀洀渀琀??椀渀昀 吀
挀漀爀攀氀椀猀琀?椀渀昀 戀%?揿礀挀氀愀搀?? 弘玍?锑è往?? _? MSAFD NetBIOS [\Device\NetBT_Tcpip_{F9DE49EA-8406-4523-B289-91B8F0BDE0DA}] SEQPACKET