RW FAVORITES 系统账户列表6 HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\Names IE 浏览器 Internet Explorer_Machine7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Internet Explorer_User6 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer My Favorites Session Manager Session ManagerC HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager Session Manager_2? HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager 安装/卸载组件 Installer HKEY_CLASSES_ROOT\Installer MenuOrderN HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder UninstallF HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall 策略 FirewallPolicy[ HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy Machine_Explorer_Network_SystemE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies S-1-5(UserID)-Scripts-LogoOff/OnO HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State User_Explorer_Network_SystemD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies 开机/关机脚本D HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\Scripts 软件限制策略T HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths 服务 Services4 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services Services_Set0010 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services 自动运行 BootExecute(高优先级)C HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager BootExecute CurrentUser_Policies_RunQ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run LoadF HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Machine_Policies_RunR HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run RunOnceEx_MachineF HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx RunOnce_MachineD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce RunOnce_UserC HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce Run_Machine@ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Run_User? HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ShellExecuteHooksW HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks * 请根据这里的ID查找对应的外壳加载程序模块! Shell_Userinit_WinlogonH HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Windows 初始化 DLLG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Winlogon_Shell_GinaDLLH HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon % 程序映射 Image File Execution Options\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options 磁盘自动运行加载MountPoints2Q HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 & 命令行 Autorun (HCU_Command Processor)6 HKEY_CURRENT_USER\Software\Microsoft\Command Processor & 命令行 Autorun (HLM_Command Processor)7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor
|
|