none
想看看用户配置文件夹:贴这一起学: RRS feed

  • 问题

  • C:\Documents and Settings>dir /a-a
     驱动器 C 中的卷没有标签。
     卷的序列号是 D875-3440

     C:\Documents and Settings 的目录

    2009-10-27  10:42    <DIR>          .
    2009-10-27  10:42    <DIR>          ..
    2009-10-27  10:42    <DIR>          111
    2009-06-01  08:21    <DIR>          Administrator
    2009-10-27  16:16    <DIR>          All Users
    2008-08-23  16:03    <DIR>          Default User
    2008-08-11  13:38    <DIR>          LocalService
    2008-08-11  13:38    <DIR>          NetworkService
    2009-10-27  17:08    <DIR>          user
                   0 个文件              0 字节
                   9 个目录 35,383,455,744 可用字节
    1
    ********************

    C:\Documents and Settings\All Users\  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [DdSrwarEwEfx]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\All Users\Application Data  

            NT AUTHORITY\SYSTEM       Full Control [ALL]

            BUILTIN\Administrators    Full Control [ALL]

            CREATOR OWNER             Special Access [A]

            BUILTIN\Power Users       Change [RWXD]

            BUILTIN\Users             Read [RX]

            BUILTIN\Users             Special Access [wawE]

    A  S       C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\afe9e16b3837b74fd9d31d5189f8f991_7af661bb-c176-4e00-9bfa-39a407ce9229

    A  S       C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\d42cc0c3858a58db2db37658219e6400_7af661bb-c176-4e00-9bfa-39a407ce9229

    A          C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\drwtsn32.log

    A          C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp

    A          C:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig.dll

        HR     C:\Documents and Settings\All Users\Application Data\Microsoft\Media Player\DefaultStore_59R.bin

        HR     C:\Documents and Settings\All Users\Application Data\Microsoft\Media Player\UserMigratedStore_59R.bin

    A          C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk

    A          C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\sharedaccess.ini

     

     

     

     

    A  SH      C:\Documents and Settings\All Users\Application Data\desktop.ini

     

     

       SH      C:\Documents and Settings\All Users\Documents\My Music\示例音乐\desktop.ini

     

    A  SH      C:\Documents and Settings\All Users\Documents\My Music\Desktop.ini

     

       SH      C:\Documents and Settings\All Users\Documents\My Pictures\示例图片\desktop.ini

    A          C:\Documents and Settings\All Users\Documents\My Pictures\示例图片\Sunset.jpg

    A  SH      C:\Documents and Settings\All Users\Documents\My Pictures\示例图片\Thumbs.db

     

    A  SH      C:\Documents and Settings\All Users\Documents\My Pictures\Desktop.ini

    A  SH      C:\Documents and Settings\All Users\Documents\My Videos\Desktop.ini

    A  SH      C:\Documents and Settings\All Users\Documents\desktop.ini

       SH      C:\Documents and Settings\All Users\DRM\drmv2.lic

       SH      C:\Documents and Settings\All Users\DRM\drmv2.sst

     

     

    A  SH      C:\Documents and Settings\All Users\「开始」菜单\程序\启动\desktop.ini

     

    A  SH      C:\Documents and Settings\All Users\「开始」菜单\程序\管理工具\desktop.ini

     

     

     

    A  SH      C:\Documents and Settings\All Users\「开始」菜单\程序\附件\娱乐\desktop.ini

     

    A  SH      C:\Documents and Settings\All Users\「开始」菜单\程序\附件\系统工具\desktop.ini

     

    A  SH      C:\Documents and Settings\All Users\「开始」菜单\程序\附件\辅助工具\desktop.ini

     

    A  SH      C:\Documents and Settings\All Users\「开始」菜单\程序\附件\通讯\desktop.ini

     

    A  SH      C:\Documents and Settings\All Users\「开始」菜单\程序\附件\desktop.ini

     

    A  SH      C:\Documents and Settings\All Users\「开始」菜单\程序\desktop.ini

     

    A  SH      C:\Documents and Settings\All Users\「开始」菜单\desktop.ini

    A          C:\Documents and Settings\All Users\1111.txt

    A          C:\Documents and Settings\All Users\2222.txt

    A  SHR     C:\Documents and Settings\All Users\ntuser.pol

    A          C:\Documents and Settings\All Users\showacls.exe

    **********************************


    2009年10月27日 9:41

全部回复

  • 2
    ***************************************

    C:\Documents and Settings\AC:\Documents and Settings\Default User  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Application Data  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Application Data\Identities  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Application Data\Identities\{F92DA2FA-4964-4A7C-9FC0-0F49BA1EBA9B}   

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Application Data\Microsoft  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C

     

    C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Cookies  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Favorites  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Favorites\收藏夹  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Favorites\链接  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Local Settings  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Local Settings\Application Data  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

     

     

    C:\Documents and Settings\Default User\Local Settings\History  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Local Settings\History\History.IE5  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Local Settings\Temp  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

     

     

    C:\Documents and Settings\Default User\My Documents  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\NetHood  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\PrintHood  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Recent  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\SendTo  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\Templates  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\「开始」菜单  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

    C:\Documents and Settings\Default User\「开始」菜单\程序  

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

            BUILTIN\Users             Special Access [RX]

            BUILTIN\Power Users       Special Access [RX]

            Everyone                  Special Access [RX]

     

     

     

     


    2009年10月27日 9:44
  • A          C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\brndlog.bak

    A          C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\brndlog.txt

    A  SH      C:\Documents and Settings\Default User\Application Data\desktop.ini

    A          C:\Documents and Settings\Default User\Cookies\index.dat

     

     

       SH      C:\Documents and Settings\Default User\Local Settings\History\History.IE5\desktop.ini

    A          C:\Documents and Settings\Default User\Local Settings\History\History.IE5\index.dat

       SH      C:\Documents and Settings\Default User\Local Settings\History\desktop.ini

       SH      C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\K5IJW1I3\desktop.ini

       SH      C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\KDMNOLAN\desktop.ini

       SH      C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\SH6FOPIB\desktop.ini

       SH      C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\W5Q38X2V\desktop.ini

       SH      C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini

    A          C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\index.dat

       SH      C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\desktop.ini

    A  SH      C:\Documents and Settings\Default User\Local Settings\desktop.ini

    A  SH      C:\Documents and Settings\Default User\SendTo\desktop.ini

     

     

    A          C:\Documents and Settings\Default User\Templates\winword.doc

    A          C:\Documents and Settings\Default User\Templates\winword2.doc

    A    R     C:\Documents and Settings\Default User\Templates\wordpfct.wpd

    A    R     C:\Documents and Settings\Default User\Templates\wordpfct.wpg

    A  SH      C:\Documents and Settings\Default User\「开始」菜单\程序\启动\desktop.ini

    A  SH      C:\Documents and Settings\Default User\「开始」菜单\程序\附件\娱乐\desktop.ini

    A          C:\Documents and Settings\Default User\「开始」菜单\程序\附件\娱乐\Windows Media Player.lnk

    A  SH      C:\Documents and Settings\Default User\「开始」菜单\程序\附件\辅助工具\desktop.ini

     

    A  SH      C:\Documents and Settings\Default User\「开始」菜单\程序\附件\desktop.ini

     

     

    A  SH      C:\Documents and Settings\Default User\「开始」菜单\程序\desktop.ini

    A

    A  SH      C:\Documents and Settings\Default User\「开始」菜单\desktop.ini

        H      C:\Documents and Settings\Default User\NTUSER.DAT

    A   H      C:\Documents and Settings\Default User\NTUSER.DAT.LOG

    **********************************


    2009年10月27日 9:44
  • 3

    ***************************8888888

    C:\Documents and Settings\user  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

     

     

     

    C:\Documents and Settings\user\Application Data\Identities  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Identities\{F92DA2FA-4964-

    4A7C-9FC0-0F49BA1EBA9B}  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

     

     

    C:\Documents and Settings\user\Application Data\Microsoft  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\AddIns  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\Credentials  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\Credentials\S-1-5-21-

    1343024091-1682526488-839522115-1003  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\CryptnetUrlCache  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application

    Data\Microsoft\CryptnetUrlCache\Content  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application

    Data\Microsoft\CryptnetUrlCache\MetaData  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\Crypto  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\Crypto\RSA  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\Crypto\RSA\S-1-5-21-

    1343024091-1682526488-839522115-1003  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

     

     

     

    C:\Documents and Settings\user\Application Data\Microsoft\IdentityCRL  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application

    Data\Microsoft\IdentityCRL\Production  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\IME  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

     

    C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\Internet

    Explorer\Quick Launch  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\Internet

    Explorer\UserData  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

     

    C:\Documents and Settings\user\Application Data\Microsoft\Media Player  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\MMC  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

     

    C

    C:\Documents and Settings\user\Application Data\Microsoft\Proof   

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\Protect  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\Protect\S-1-5-21-

    1343024091-1682526488-839522115-1003  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\SystemCertificates  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\SystemCertificates\My 

     

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application

    Data\Microsoft\SystemCertificates\My\Certificates  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application

    Data\Microsoft\SystemCertificates\My\CRLs  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application

    Data\Microsoft\SystemCertificates\My\CTLs  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\Templates  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\Windows  

            lilianjie\user                Special Access [A]


    2009年10月27日 9:49
  •         NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Application Data\Microsoft\Windows\Themes  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

     

    C:\Documents and Settings\user\Cookies  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Favorites  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Local Settings  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Local Settings\Application Data  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

     

    C:\Documents and Settings\user\Local Settings\Application Data\Microsoft  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\CD

    Burning  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Local Settings\Application

    Data\Microsoft\Credentials  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Local Settings\Application

    Data\Microsoft\Credentials\S-1-5-21-1343024091-1682526488-839522115-1003  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Feeds  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Feeds

    Cache  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

     

    C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\HelpCtr

     

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Internet

    Explorer  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

     

    C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Office  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\OIS  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C

    C:\Documents and Settings\user\Local Settings\Application

    Data\Microsoft\Windows  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C

     

    C:\Documents and Settings\user\Local Settings\Application

    Data\Microsoft\Windows Media\9.0  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Local Settings\Apps  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

     

    C:\Documents and Settings\user\Local Settings\History  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Local Settings\History\History.IE5  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

     

    C:\Documents and Settings\user\Local Settings\Temp  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Local Settings\Temp\OIS  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Local Settings\Temp\OIS\cacheFiles  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

     

    C:\Documents and Settings\user\Local Settings\Temporary Internet Files  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Local Settings\Temporary Internet

    Files\AntiPhishing  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Local Settings\Temporary Internet

    Files\Content.IE5  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

     

    C:\Documents and Settings\user\Local Settings\Temporary Internet

    Files\Content.MSO  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\My Documents  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\My Documents\My Music  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     


    2009年10月27日 9:50
  • C:\Documents and Settings\user\My Documents\My Pictures  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\My Documents\我接收到的文件  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\NetHood  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\PrintHood  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Recent  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\SendTo  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\Templates  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\「开始」菜单  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\「开始」菜单\程序  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\「开始」菜单\程序\启动  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\「开始」菜单\程序\附件  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\「开始」菜单\程序\附件\娱乐  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\「开始」菜单\程序\附件\系统工具  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\「开始」菜单\程序\附件\辅助工具  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\「开始」菜单\程序\附件\通讯  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\「开始」菜单\程序\附件\通讯\超级终端  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\桌面  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\桌面\文本编缉  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

     

    C:\Documents and Settings\user\桌面\阅读器  

            lilianjie\user                Special Access [A]

            NT AUTHORITY\SYSTEM       Special Access [A]

            BUILTIN\Administrators    Special Access [A]

    A  S       C:\Documents and Settings\user\Application Data\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5

    A  S       C:\Documents and Settings\user\Application Data\Microsoft\CryptnetUrlCache\Content\A44F4E7CB3133FF765C39A53AD8FCFDD

    A  S       C:\Documents and Settings\user\Application Data\Microsoft\CryptnetUrlCache\Content\A8FABA189DB7D25FBA7CAC806625FD30

    A  S       C:\Documents and Settings\user\Application Data\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5

    A  S       C:\Documents and Settings\user\Application Data\Microsoft\CryptnetUrlCache\MetaData\A44F4E7CB3133FF765C39A53AD8FCFDD

    A  S       C:\Documents and Settings\user\Application Data\Microsoft\CryptnetUrlCache\MetaData\A8FABA189DB7D25FBA7CAC806625FD30

    A  S       C:\Documents and Settings\user\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1343024091-1682526488-839522115-1003\d1adb89f57202f6f2b1b0c17c20f91ff_7af661bb-c176-4e00-9bfa-39a407ce9229

    A  S       C:\Documents and Settings\user\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1343024091-1682526488-839522115-1003\f58155b4b1d5a524ca0261c3ee99fb50_7af661bb-c176-4e00-9bfa-39a407ce9229

     

    A          C:\Documents and Settings\user\Application Data\Microsoft\HTML Help\hh.dat

    A          C:\Documents and Settings\user\Application Data\Microsoft\IME\MSSCIPY\PuserLx.DAT

    A          C:\Documents and Settings\user\Application Data\Microsoft\IME\MSSCIPY\PuserSx.DAT

       SH      C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini

     

    l

    A  SH      C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\UserData\index.dat

    A          C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\brndlog.bak

    A          C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\brndlog.txt

    A  SH      C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Desktop.htt

    A  SH      C:\Documents and Settings\user\Application Data\Microsoft\Office\Recent\Desktop.ini

     

        H      C:\Documents and Settings\user\Application Data\Microsoft\Office\Recent\index.dat

     

     

    A          C:\Documents and Settings\user\Application Data\Microsoft\Proof\CUSTOM.DIC

    A  SH      C:\Documents and Settings\user\Application Data\Microsoft\Protect\S-1-5-21-1343024091-1682526488-839522115-1003\a82c3ef6-aec5-4306-9ad7-82916a3861f2

    A  SH      C:\Documents and Settings\user\Application Data\Microsoft\Protect\S-1-5-21-1343024091-1682526488-839522115-1003\f47bfb48-6f54-4410-8fea-d832c8824271

    A  SH      C:\Documents and Settings\user\Application Data\Microsoft\Protect\S-1-5-21-1343024091-1682526488-839522115-1003\Preferred

    A  SH      C:\Documents and Settings\user\Application Data\Microsoft\Protect\CREDHIST

     

     

    A          C:\Documents and Settings\user\Application

    A  SH      C:\Documents and Settings\user\Application Data\desktop.ini

    A          C:\Documents and Settings\user\Cookies\index.dat

     

       SH      C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Feeds Cache\20U15RWG\desktop.ini

       SH      C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Feeds Cache\JK9S071P\desktop.ini

       SH      C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Feeds Cache\WZGBKAZ0\desktop.ini

       SH      C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Feeds Cache\YN885SVJ\desktop.ini

       SH      C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Feeds Cache\desktop.ini

    A  SH      C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat

     

     

    A   H      C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat

    A   H      C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG

     

     

    A          C:\Documents and Settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

    A   H      C:\Documents and Settings\user\Local Settings\Application Data\IconCache.db

    A  SH      C:\Documents and Settings\user\Local Settings\History\History.IE5\MSHist012009102720091028\index.dat

       SH      C:\Documents and Settings\user\Local Settings\History\History.IE5\desktop.ini

     

       SH      C:\Documents and Settings\user\Local Settings\History\desktop.ini

     

    Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat

       SH      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\5A4GPCQH\desktop.ini

     

       SH      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\C85FC9X4\desktop.ini

       SH      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\H6BWUKI7\desktop.ini

       SH      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\I2Y8ITIT\desktop.ini

     

    A  SH      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\W5Q38X2V\desktop.ini

     

       SH      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini

     

       SH      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\desktop.ini

    A  SH      C:\Documents and Settings\user\Local Settings\desktop.ini

    A  SH      C:\Documents and Settings\user\My Documents\My Music\Desktop.ini

     

    A  SH      C:\Documents and Settings\user\My Documents\My Pictures\Desktop.ini

     

     

    A  SH      C:\Documents and Settings\user\Recent\Desktop.ini

     

    A          C:\Documents and Settings\user\Recent\手机证书备份.lnk

    A  SH      C:\Documents and Settings\user\SendTo\desktop.ini

     

    A  SH      C:\Documents and Settings\user\「开始」菜单\程序\启动\desktop.ini

    A  SH      C:\Documents and Settings\user\「开始」菜单\程序\附件\娱乐\desktop.ini

     

    A  SH      C:\Documents and Settings\user\「开始」菜单\程序\附件\辅助工具\desktop.ini

     

    A  SH      C:\Documents and Settings\user\「开始」菜单\程序\附件\desktop.ini

     

    A  SH      C:\Documents and Settings\user\「开始」菜单\程序\desktop.ini

     

     

    A  SH      C:\Documents and Settings\user\「开始」菜单\desktop.ini

    A  SH      C:\Documents and Settings\user\桌面\文本编缉\Desktop.ini

     

    A          C:\Documents and Settings\user\My

    A   H      C:\Documents and Settings\user\NTUSER.DAT

    A   H      C:\Documents and Settings\user\NTUSER.DAT.LOG

       SH      C:\Documents and Settings\user\ntuser.ini

    A  SHR     C:\Documents and Settings\user\ntuser.pol

    A          C:\Documents and Settings\user\showacls.exe

     


    2009年10月27日 9:51
  • 红的是All Users下的

    蓝的是Default User下的

    绿的是user-------------POWER USERS组的


    2009年10月27日 9:56
  • GOOGLE:

    每一个用户配置文件都以 Default User 的副本--------Default User 中的 NTuser.dat (NTuser.dat 文件是用户配置文件的注册表部

    分。当用户从计算机上注销时,系统将注册表的用户特定部分(即 HKEY_CURRENT_USER)卸载到 NTuser.dat 文件中并进行更

    新)文件复制

    每个用户配置文件还使用包含在 All Users 文件夹中的公用程序组,All Users 文件夹中的设置不复制到用户配置文件夹,但可以用来创

    建个人用户配置文件,公用程序组保存在 All Users 文件夹中。All Users 文件夹还包含每台计算机的桌面和“开始”菜单设置


  • 默认情况下,我的文档、图片收藏、收藏夹、“开始”菜单以及桌面文件夹是在 Windows 资源管理器中显示的仅有的文件夹。NetHood、PrintHood、Local Settings、Recent 和 Templates 文件夹是隐藏的,在 Windows 资源管理器中不显示。要在 Windows 资源管理器中查看这些文件夹和它们的内容,请在“工具”菜单上指向“文件夹选项”,单击“视图”选项卡,然后单击“显示隐藏文件和文件夹”。
  • 在运行 Windows Server 2003 操作系统并具有 NTFS 文件系统的计算机上,只有 Administrators 组的成员才能创建、删除或修改公用程序组




  • ======================

    应用程序数据

    程序专用数据(例如自定义词典)。程序供应商决定在用户配置文件文件夹中存储哪些数据。

    Cookie

    用户信息和首选项。

    桌面

    桌面项目,包括文件、快捷方式和文件夹。

    Favorites

    到 Internet 上经常访问位置的快捷方式。

    Local Settings

    应用程序数据、历史和临时文件。应用程序数据通过漫游用户配置文件的方式与用户一起漫游。

    我的文档

    用户文档和子文件夹。

    My Recent Documents

    指向最近使用过的文档和访问过的文件夹的快捷方式。

    NetHood

    指向“网上邻居”项的快捷方式。

    PrintHood

    指向打印机文件夹项的快捷方式。

    SendTo

    指向文档处理实用程序的快捷方式。

    “开始”菜单

    指向程序项的快捷方式。

    Templat

    用户模板项目


    ===============

    C:\Documents and Settings\user>dir /q /ad /s >123.txt & findstr /i "Application Data" "Favorites" "Cookies" "桌面" "Local Settings" "我最近的文档" "My documents " "NetHood" "「开始」菜单" "Templates" FINDSTR: 无法打开 我最近的文档

    C:\Documents and Settings\user>dir "C:\Documents and Settings\Default User"/q /a
    d /s >124.txt & findstr /i "Application Data" "Favorites" "Cookies" "桌面" "Loca
    l Settings" "我最近的文档" "My documents" "NetHood" "「开始」菜单" "Templates"
    FINDSTR: 无法打开 我最近的文档


    我最近的文档很怪啊,看着在,就是FINDSTR不到



2009年10月27日 10:47




  • All Users\「开始」菜单里的desktop.ini


    [.ShellClassInfo]
    LocalizedResourceName=@shell32.dll,-21786
    [LocalizedFileNames]
    Windows Catalog.lnk=@%SystemRoot%\system32\shell32.dll,-22075
    激活 Windows.lnk=@%SystemRoot%\system32\oobe\msoobe.exe,-2000
    设定程序访问和默认值.lnk=@xpsp1res.dll,-10077
    ===========================
    Default User\「开始」菜单里的desktop.ini

    [.ShellClassInfo]
    LocalizedResourceName=@shell32.dll,-21786

    =============================

    User「开始」菜单里的desktop.ini
    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787




    http://baike.baidu.com/view/676737.htm
    2009年10月27日 11:15
  • all users里的:Application Data\Microsoft\Crypto\RSA\:

    A  S       C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\afe9e16b3837b74fd9d31d5189f8f991_7af661bb-c176-4e00-9bfa-39a407ce9229

     ???????????????????????????????? ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
    A  S       C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\d42cc0c3858a58db2db37658219e6400_7af661bb-c176-4e00-9bfa-39a407ce9229
     ???????????????????????????????? ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^



    user里的Application Data\Microsoft\Crypto\RSA:

    A  S       C:\Documents and Settings\user\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1343024091-
                                                                                     @@@@@@@@@@@@@@@@@@
    1682526488-839522115-1003\d1adb89f57202f6f2b1b0c17c20f91ff_7af661bb-c176-4e00-9bfa-39a407ce9229

    @@@@@@@@@@@@@@@@@@@@@@@@@ ???????????????????????????????? ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
    A  S       C:\Documents and Settings\user\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1343024091-
                                                                                    @@@@@@@@@@@@@@@@@@@
                                                        
    1682526488-839522115-1003\f58155b4b1d5a524ca0261c3ee99fb50_7af661bb-c176-4e00-9bfa-39a407ce9229
    @@@@@@@@@@@@@@@@@@@@@@@@@@?????????????????????????????????^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

    WHOAMI /ALL

    user S-1-5-21-1343024091-1682526488-839522115-1003

     


    2009年10月28日 3:24
  • C:\Documents and Settings\user>reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
    Windows NT\CurrentVersion\ProfileList" /s

    ! REG.EXE VERSION 3.0

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
        ProfilesDirectory   REG_EXPAND_SZ   %SystemDrive%\Documents and Settings
        DefaultUserProfile  REG_SZ  Default User
        AllUsersProfile     REG_SZ  All Users

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
    5-18
        Flags       REG_DWORD       0xc
        State       REG_DWORD       0x0
        RefCount    REG_DWORD       0x1
        Sid REG_BINARY      010100000000000512000000
        ProfileImagePath    REG_EXPAND_SZ   %systemroot%\system32\config\systemprofi
    le

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
    5-19
        ProfileImagePath    REG_EXPAND_SZ   %SystemDrive%\Documents and Settings\Loc
    alService
        Sid REG_BINARY      010100000000000513000000
        Flags       REG_DWORD       0x9
        State       REG_DWORD       0x0
        CentralProfile      REG_SZ
        ProfileLoadTimeLow  REG_DWORD       0x8c31638a
        ProfileLoadTimeHigh REG_DWORD       0x1ca5763
        RefCount    REG_DWORD       0x3

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
    5-20
        ProfileImagePath    REG_EXPAND_SZ   %SystemDrive%\Documents and Settings\Net
    workService
        Sid REG_BINARY      010100000000000514000000
        Flags       REG_DWORD       0x9
        State       REG_DWORD       0x0
        CentralProfile      REG_SZ
        ProfileLoadTimeLow  REG_DWORD       0x8c10029e
        ProfileLoadTimeHigh REG_DWORD       0x1ca5763
        RefCount    REG_DWORD       0x2

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
    5-21-1343024091-1682526488-839522115-1003
        ProfileImagePath    REG_EXPAND_SZ   %SystemDrive%\Documents and Settings\use
    r
        Sid REG_BINARY      010500000000000515000000DBEB0C501851496443170A32EB030000

        Flags       REG_DWORD       0x0
        State       REG_DWORD       0x0
        CentralProfile      REG_SZ
        ProfileLoadTimeLow  REG_DWORD       0x8c9cad5c
        ProfileLoadTimeHigh REG_DWORD       0x1ca5763
        RefCount    REG_DWORD       0x1
        RunLogonScriptSync  REG_DWORD       0x0
        OptimizedLogonStatus        REG_DWORD       0xb

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
    5-21-1343024091-1682526488-839522115-500
        ProfileImagePath    REG_EXPAND_SZ   %SystemDrive%\Documents and Settings\Adm
    inistrator
        Sid REG_BINARY      010500000000000515000000DBEB0C501851496443170A32F4010000

        Flags       REG_DWORD       0x0
        State       REG_DWORD       0x100
        CentralProfile      REG_SZ
        ProfileLoadTimeLow  REG_DWORD       0x41d297c6
        ProfileLoadTimeHigh REG_DWORD       0x1c9faae
        RefCount    REG_DWORD       0x1
        RunLogonScriptSync  REG_DWORD       0x0
        OptimizedLogonStatus        REG_DWORD       0xb


    2009年10月28日 3:35


  • A  S       C:\Documents and Settings\user\Application Data\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5

    A  S       C:\Documents and Settings\user\Application Data\Microsoft\CryptnetUrlCache\Content\A44F4E7CB3133FF765C39A53AD8FCFDD

    A  S       C:\Documents and Settings\user\Application Data\Microsoft\CryptnetUrlCache\Content\A8FABA189DB7D25FBA7CAC806625FD30

    A  S       C:\Documents and Settings\user\Application Data\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5

    A  S       C:\Documents and Settings\user\Application Data\Microsoft\CryptnetUrlCache\MetaData\A44F4E7CB3133FF765C39A53AD8FCFDD

    A  S       C:\Documents and Settings\user\Application Data\Microsoft\CryptnetUrlCache\MetaData\A8FABA189DB7D25FBA7CAC806625FD30




    =====================
    google:


    C:\Documents and Settings\user\Application Data\Microsoft\CryptnetUrlCache
    证书缓存:

    选择 “Internet 选项", 然后点击 “内容” 选项卡.

    在中间有个叫 "证书" 的区域… 只需点击 “清除 SSL 状态” 就能清空这些文件夹中的任何临时证书.

    另外要说一下它导致 IE 变慢的原因, 这是因为 XP 会验证每个证书以确定它们是否仍然有效. 因此, 清空 SSL 缓存是个好注意.

    稍微深入研究一下...

    工具 > Internet选项 > 内容 > “证书” 按钮 > “中级证书颁发机构” 选项卡 > 选中一个条目 > 点击 “删除”.

    工具 > Internet选项 > 内容 > “证书” 按钮 > “受信任的根证书颁发机构” 选项卡 > 选中一个条目 > 点击 “删除”.

    工具 > Internet选项 > 内容 > “证书” 按钮 > “未受信任的发行者” 选项卡 > 选中一个条目 > 点击 “删除”.

     

     

    只要你愿意, 那么你可以删除所有的条目. 这些东西类似于你在 Windows Update 网站上得到的安全警告? 你可以在弹出的对话框上选中总是信任 Microsoft?

    如果你选中了其中的一个, 那么就能在 “证书” 对话框中找到对应的证书. 受信任的证书就会在这个区域中保留一个记录了.

    探讨的再深入一点, 比如说, 工具 > Internet 选项 > 高级 > 下拉到 “安全” 区段>
    "检查服务器证书吊销 (需要重启动)"

    这个用于指定你是否想在接受证书是否有效之前先让Internet Explorer 检查网站的证书是否已被吊销.



    google:





    This folder applies to Windows XP SP2 and similar applications.  It has to do with Windows certificates. If you have a %SystemDrive% folder on your desktop, you should see the same (internal folders) in your User account. Look in C:\Documents and Settings\Your User Name\Application Data\Microsoft\.




    Certificate Revocation List (CRL) - Client's Cache
    the CRL can be cached in various locations:

    - Memory
    - Local File System.

    In order to clear the CRL cache immidietly do the following:

    1. Memory – You need to restart the application which is checking the CRL validity as it seems that in my case when using CAPICOM isValid the state is not refreshed immidiatly until the process restarts.
    note: if you are trying to debug inside Visual Studio you will have to close and open the Studio of just start the process outside the studio for the memory to get refreshed.

    2. Local File System – the cache file is stored in the following directories:
    \Document and Settings\Username\Application Data\Microsoft\CryptnetUrlCache\Methadata 
    Delete the file in this directory.


    2009年10月28日 6:07
  • GOOGLE:


    C:\Documents and Settings\All Users\DRM

    ”数字权利管理规定” (DRM) 提供了涉及数字版权的相关功能.

    Windows Media DRM 平台可以保护并安全地传递点播内容和订阅内容, 以在计算机, 便携设备或网络设备上播放.

    ---------------------
    C:\Documents and Settings\All Users\Templates

    WORD等工具的模板

    C:\Documents and Settings\USER\Templates
    USER安装工具的模板

    C:\Documents and Settings\USER\UserData

    USER安装工具的Data
    当你访问 Windows Update 时, 会自动重新生成UserData 文件夹.

     

    --------------------------

    C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\Quick Launch

    快速启动快捷方式

    ------------------------

    C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson
    我把 “Dr Watson” 文件夹删掉了.

    除非你禁用 Dr Watson , 否则 ”Dr Watson” 文件夹总会重新自动创建的.

    若要禁用 Dr. Watson, 请转到注册表的以下位置:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AeDebug

    删除 “AeDebug” 注册表项.

    -----------------------


    C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help
    你可以删除这个文件夹.

    在你打开一个 .chm 帮助文件之后, 这个文件夹就会再次出现了.


    ----------------------

    :\Documents and Settings\USER\Application Data\Microsoft\SystemCertificates


    然而, 在你访问过 Windows Update 之后, 会自动重新生成SystemCertificates 文件夹.

    C:\Documents and Settings\USER\Local Settings\Application Data\Microsoft\Credentials
    你可以删除Credentials 文件夹.

    然而, 在你重新启动之后就会自动重新生成Credentials 文件夹.

     

    证书和公共密钥存储

    Windows XP Professional将公钥证书存储在个人证书存储区中。由于是公开信息,所以证书以纯文本形式进行保存,证书经过证书颁发机构的数字签署,以保证其内容不被篡改。
    用户证书位于 “Documents and Settings\username\ApplicationData\ Microsoft\SystemCertificates\My\Certificates” 目录下的用户配置文件中。在你每次登录到计算机上的时候,这些证书都被写入到你的个人存储区中。对于漫游配置文件,你的证书可以在任意一


    私钥存储

    面向Microsoft加密服务提供程序(CSP)--包括Base CSP和Enhanced CSP--的私钥位于位于“RootDirectory\Documents and Settings\username\Application Data\Microsoft\Crypto\RSA”目录下的用户配置文件中。
    在使用漫游配置文件的情况下,私钥保存在域控制器的RSA文件夹中,用户可以将私钥下载到自己使用的计算机上,当用户从计算机上注销或者重新启动计算机后,下载的私钥将被删除。

    因为私钥必须收到保护,所以RSA文件夹中的所有文件都会通过一个被称为“用户主密钥”的随机对称密钥进行加密。用户主密钥的长度为64个字节,由一个强大的随机数字生成程序产生。3DES密钥则从主密钥派生出来,并且用来对私钥进行保护。主密钥是由系统自动生成

    在将主密钥保存到磁盘上的时候,系统会使用3DES算法和根据你的密码得出的一个密钥保护主密钥。在文件创建时,它会对RS文件夹中的每一个文件进行自动加密。

     


    <hr class="sig"><img


    2009年10月28日 7:19