东营科瑞石油是国企:ntldr?IO.SYS?MSDOS.SYS?CONFIG.SYS?conflg.sys?系统文件?

来源:百度文库 编辑:查人人中国名人网 时间:2024/04/29 17:26:12
ntldr?IO.SYS?MSDOS.SYS?CONFIG.SYS?conflg.sys?这些都是系统文件吗?
winsock.reg这又是什么?
他们都在我C盘里面
以下是winsock.reg的部分内容:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters]
"WinSock_Registry_Version" = "2.0"
"Current_NameSpace_Catalog" = "NameSpace_Catalog5"
"Current_Protocol_Catalog" = "Protocol_Catalog9"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5]
"Num_Catalog_Entries" = dword:00000003
"Serial_Access_Num" = dword:00000004

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001]
"LibraryPath" = "%SystemRoot%\\System32\\mswsock.dll"
"DisplayString" = "Tcpip"
"ProviderId" = hex:40,9d,05,22,9e,7e,cf,11,ae,5a,00,aa,00,a7,11,2b
"SupportedNameSpace" = dword:0000000c
"Enabled" = dword:00000001
"Version" = dword:00000000
"StoresServiceClassInfo" = dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002]
"LibraryPath" = "%SystemRoot%\\System32\\winrnr.dll"
"DisplayString" = "NTDS"
"ProviderId" = hex:ee,37,26,3b,80,e5,cf,11,a5,55,00,c0,4f,d8,d4,ac
"SupportedNameSpace" = dword:00000020
"Enabled" = dword:00000001
"Version" = dword:00000000
"StoresServiceClassInfo" = dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003]
"LibraryPath" = "%SystemRoot%\\System32\\mswsock.dll"
"DisplayString" = "网络位置知晓 (NLA) 名称空间 "
"ProviderId" = hex:3a,24,42,66,a8,3b,a6,4a,ba,a5,2e,0b,d7,1f,dd,83
"SupportedNameSpace" = dword:0000000f
"Enabled" = dword:00000001
"Version" = dword:00000000
"StoresServiceClassInfo" = dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9]
"Num_Catalog_Entries" = dword:0000000f
"Next_Catalog_Entry_ID" = dword:00000410
"Serial_Access_Num" = dword:0000000c

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001]
"PackedCatalogItem" = hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,32,\
5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,\

...................

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\0000000000**]

省略的部分都差不多,只是后面的不同,从Catalog_Entries\0000000000001]到15

他们确实是系统文件