Installation Report: Win32 Cabinet Self-Extractor
Generated by InCtrl5, version 1.0.0.0
Install program: E:\DownLoads\infected\禁片-罗曼史[中文字幕].rmvb .exe
4-29-2011 9:35 AM
------------------------------------------------------------
Registry
********
Keys ignored: 0
---------------
* (none)
Keys added: 1
-------------
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\FDC\GENERIC_FLOPPY_DRIVE\5&345fbd89&0&0\Capabilities
Keys deleted: 1
---------------
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\FDC\GENERIC_FLOPPY_DRIVE\5&345fbd89&0&0\DeviceDe
Values added: 1
---------------
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache "E:\DownLoads\infected\禁片-罗曼史[中文字幕].rmvb .exe"
Type: REG_SZ
Data: Win32 Cabinet Self-Extractor
Values changed: 6
-----------------
HKEY_CURRENT_USER\SessionInformation "ProgramCount"
Old type: REG_DWORD
New type: REG_DWORD
Old data: 03, 00, 00, 00
New data: 02, 00, 00, 00
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\170\Shell "WinPos1024x768(1).bottom"
Old type: REG_DWORD
New type: REG_DWORD
Old data: 75, 02, 00, 00
New data: F3, 02, 00, 00
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\170\Shell "WinPos1024x768(1).left"
Old type: REG_DWORD
New type: REG_DWORD
Old data: 16, 00, 00, 00
New data: DC, 00, 00, 00
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\170\Shell "WinPos1024x768(1).right"
Old type: REG_DWORD
New type: REG_DWORD
Old data: 36, 03, 00, 00
New data: FC, 03, 00, 00
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\170\Shell "WinPos1024x768(1).top"
Old type: REG_DWORD
New type: REG_DWORD
Old data: 1D, 00, 00, 00
New data: 8E, 01, 00, 00
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG "Seed"
Old type: REG_BINARY
New type: REG_BINARY
Old data: 9D, 84, 36, 59, 62, DC, 8D, 41, 3B, 40, 70, EE, 25, 0E, 80, C7, C8, CD, CB, B9, 51, A4, BD, 86, 8F, 15, 5E, 25, 18, 05, 14, 6E, 2A, 9D, A0, E9, 78, 96, 13, 8D, 91, AE, 5B, 23, 04, FE, 72, CE, 0F, 3C, D9, F9, C6, 5B, 5B, AA, 5F, 6E, 87, 24, B6, 7F, A0, 59, 26, 03, AB, 17, B8, AB, 89, 1E, 7A, 67, BA, 06, 1C, 0C, 86, 53
New data: F3, 38, 29, 49, 2F, 64, FA, 89, 6F, C0, B6, AB, 0B, E4, A5, 62, 22, DD, C7, C7, A9, 1A, 96, 18, AB, 6C, 4C, 4E, FC, 1A, 16, 50, 8A, C5, 41, EF, 83, 77, 76, 12, D9, C6, 6D, 88, C5, DE, 06, 02, A1, 80, 27, BD, 67, E7, 56, D0, 0A, CA, 7F, D3, 9F, AF, 14, 46, 12, 22, 8B, 9F, F7, 9D, 7B, A1, F6, DD, 98, 6E, 4F, EF, 8D, FA
------------------------------------------------------------
Disk contents
*************
Drives tracked: 4
-----------------
* c:\
* d:\
* e:\
* f:\
Files changed: 2
----------------
c:\Documents and Settings\Administrator\ntuser.dat.LOG
Old date: 4-29-2011 9:34 AM
New date: 4-29-2011 9:35 AM
Old size: 1,024 bytes
New size: 1,024 bytes
c:\WINDOWS\system32\config\software.LOG
Old date: 4-29-2011 9:33 AM
New date: 4-29-2011 9:35 AM
Old size: 1,024 bytes
New size: 1,024 bytes
------------------------------------------------------------
INI file
********
Ini files tracked: 3
--------------------
* C:\boot.ini
* c:\windows\control.ini
* c:\windows\system.ini
------------------------------------------------------------
Text file
*********
Text files tracked: 2
---------------------
* c:\windows\system32\autoexec.nt
* c:\windows\system32\config.nt
------------------------------------------------------------
InCtrl5, Copyright ?2000 by Ziff Davis Media, Inc.
Written by Neil J. Rubenking
First published in PC Magazine, December 5, 2000.
|