项:HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
健值:xpserve
指向数据:%SystemRoot%\system32\xpserve.exe
项:HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
健值:System
指向数据:%SystemRoot%\system32\dllcache\lsoss.exe
项:HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
健值:NoCommon Groups
指向数据:01
项:HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\WinOld-App\Disabled\
健值:Disabled
指向数据:01
项:HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\WinOld-App\Disabled\
健值:NoRealMode
指向数据:01
项:HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\
健值:DisableRegistryTools
指向数据:01
项:HKCU\Software\Policies\Microsoft\Internet Explorer\Control Pane\
健值:SecurityTab
指向数据:01
项:HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\
健值:No_LaunchMediaBar
指向数据:00
项:HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
健值:Hidden
指向数据:01
项:HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
健值:ShowSuperHidden
指向数据:01
项:HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\
健值:NoBrowserOptions
指向数据:01
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}
HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}
HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}
HKCU\Software\Policies\Microsoft\MMC\{58221C66-EA27-11CF-ADCF-00AA00A80033}
HKCR\regfile\shell\open\command |
|