NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\CurrentVersion Operating system: version number
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\InstallDate Operating system: installation date
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProductId Operating system: product id
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProductName Operating system: name
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\RegisteredOwner Operating system: name of registered person
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization Operating system: name of registered organization
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber Operating system: build number
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\CurrentType Operating system: processor architecture
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\CSDVersion Operating system: service pack
NT HKLM\System\Select\Current Number of control set that is currently active
NT HKLM\System\ControlSet*\Services\DMIO\Boot Info\Primary Disk Group\* Last removable disk mounted into system
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\Device Default printer
NT HKLM\ControlSet*\Control\TimeZoneInformation\StandardName User-configured time zone
NT HKLM\ControlSet*\Control\TimeZoneInformation\DaylightName User-configured daylight savings time
NT HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeText Legal notice text appearing before logon
NT HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeCaption Legal notice caption appearing before logon
NT HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\* User-specific directories
NT HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\* User-specific directories
NT HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\DefaultUserName Last logged on user
NT HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\DefaultDomainName Domain that last user logged on to
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\*\ProfileLoadTimeHigh Profile load time of user
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\*\ProfileLoadTimeLow Profile load time low of user
NT HKLM\System\ControlSet*\Control\Windows\ShutdownTime Time of last system shutdown
NT HKLM\System\ControlSet*\Services\LanManServer\Shares\SharedDocs Shared folders in a network
NT HKCU\Network\*\RemotePath Path of mapped network drive
NT HKCU\Network\*\ProviderName Type of network
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards\*\Description Model description of installed network card
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards\*\ServiceName Unique identifier for installed network cards
NT HKLM\System\ControlSet001\Services\{*}\Parameters\Tcpip\* Parameters of network card like IP address
NT HKLM\System\ControlSet002\Services\{*}\Parameters\Tcpip\* Parameters of network card like IP address
NT HKLM\System\ControlSet003\Services\{*}\Parameters\Tcpip\* Parameters of network card like IP address
NT HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Logon User Name Name of registered user
NT HKCU\Environment\* System environment variables
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\AccountName User-defined account name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\HTTPMail User Name Hotmail?
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\HTTPMail Password2 Hotmail?
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 User Name Incoming mail: user name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 Server Incoming mail: server name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 Email Address Incoming mail: email address
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 Reply To Email Address Incoming mail: reply-to address
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Signature Outgoing mail: signature
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Server Outgoing mail: server name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP User Name Outgoing mail: user name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Display Name Outgoing mail: display name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Email Address Outgoing mail: email address
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Reply To Email Address Outgoing mail: reply-to address
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Signature Newsgroup: signature
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP User Name Newsgroup: user name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Display Name Newsgroup: display name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Server Newsgroup: server name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Email Address Newsgroup: email address
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP ReplyTo Newsgroup: reply-to address
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\LDAP Server LDAP Server
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\LDAP Url LDAP URL
NT HKCU\Software\Mirabilis\ICQ\NewOwners\*\Name ICQ user name
NT HKCU\Software\Mirabilis\ICQ\NewOwners\*\LastLoginDate ICQ user's last login date
NT HKCU\Software\Yahoo\Pager\Yahoo! User ID Yahoo Messenger login name
NT HKCU\Software\Yahoo\Pager\File Transfer\* Yahoo Messenger file transfer history
NT HKCU\Software\Yahoo\Pager\profiles\*\Chat\LastSelCategory Yahoo Messenger last chat room visited
NT HKCU\Software\Kazaa\UserDetails\* Kazaa user information
NT HKCU\Software\Kazaa\Search\* Kazaa history of search expressions
NT HKCU\Software\Kazaa\LocalContent\DownloadDir Kazaa current download directory
NT HKCU\Software\Kazaa\Transfer\DlDir0 Kazaa first used download directory
NT HKCU\Software\Kazaa\Transfer\DlDir1 Kazaa second used download directory
NT HKCU\Software\Kazaa\Transfer\DlDir2 Kazaa third used download directory
NT HKCU\Software\Kazaa\Transfer\DlDir3 Kazaa fourth used download directory
NT HKCU\Software\Kazaa\Transfer\DlDir4 Kazaa fifth used download directory
NT HKCU\Software\Kazaa\Transfer\DlDir5 Kazaa sixth used download directory
NT HKCU\Software\Kazaa\Transfer\DlDir6 Kazaa seventh used download directory
NT HKCU\Software\Kazaa\Transfer\DlDir7 Kazaa eigth used download directory
NT HKCU\Software\Kazaa\Transfer\DlDir8 Kazaa nineth used download directory
NT HKCU\Software\Kazaa\Transfer\DlDir9 Kazaa tenth used download directory
NT HKCU\Software\Microsoft\Windows\CurrentVersion\Themes\InstallTheme Installed wallpaper/desktop theme
NT HKCU\Software\Microsoft\Windows\CurrentVersion\Themes\LastTheme\Wallpaper Last installed wallpaper/desktop theme
NT HKCU\Control Panel\Desktop\ConvertedWallpaper Converted desktop wallpaper
NT HKCU\Control Panel\Desktop\Wallpaper Bitmap desktop wallpaper
NT HKCU\Control Panel\Desktop\OriginalWallpaper Original Bitmap desktop wallpaper
NT HKCU\Control Panel\Desktop\SCRNSAVE.EXE Screensaver
NT HKCU\Software\Microsoft\Windows NT\CurrentVersion\Network\Persistent Connections\*\* Foreign host name and shared resources (only one-character names)
NT HKLM\Software\Microsoft\Windows\CurrentVersion\Installer
NT HKCU\Software\Microsoft\Windows\CurrentVersion\
没有合适的资源?快使用搜索试试~ 我知道了~
资源推荐
资源详情
资源评论
收起资源包目录
X-Ways Forensics只有正式用户才可下载的文档集合.rar (5个子文件)
集合
rar.dll 68KB
Reg Report Keys.txt 27KB
Zip.dll 304KB
devil.dll 231KB
File Type Categories.txt 5KB
共 5 条
- 1
lwb_hao
- 粉丝: 0
- 资源: 2
上传资源 快速赚钱
- 我的内容管理 展开
- 我的资源 快来上传第一个资源
- 我的收益 登录查看自己的收益
- 我的积分 登录查看自己的积分
- 我的C币 登录后查看C币余额
- 我的收藏
- 我的下载
- 下载帮助
最新资源
资源上传下载、课程学习等过程中有任何疑问或建议,欢迎提出宝贵意见哦~我们会及时处理!
点击此处反馈
安全验证
文档复制为VIP权益,开通VIP直接复制
信息提交成功
- 1
- 2
前往页