项:HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
键值:fkcdblg
指向文件:%SystemRoot%\system32\kpsebig.exe
项:HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
键值:giulmej
指向文件:%SystemRoot%\system32\pdvxiha.exe
项:HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\
健值:CheckedValue
指向数据:00
项:HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
键值:NoDriveTypeAutoRun
指向变量:95 |
|