项:HKLM\SYSTEM\CurrentControlSet\Services\RemoteStorage\
键值:DisplayName
指向数据:Windows Accounts Driver
项:HKLM\SYSTEM\CurrentControlSet\Services\RemoteStorage\
键值:ImagePath
指向数据:C:\WINDOWS\system32\server.exe
项:HKLM\SYSTEM\CurrentControlSet\Services\RemoteStorage\
键值:Start
指向数据:02
项:HKLM\SYSTEM\CurrentControlSet\Services\Hooking\
键值:DisplayName
指向数据:SSDT HOOK
项:HKLM\SYSTEM\CurrentControlSet\Services\Hooking\
键值:ImagePath
指向数据:\??\C:\WINDOWS\system32\drivers\GTHOOK.sys
项:HKLM\SYSTEM\CurrentControlSet\Services\Hooking\
键值:Start
指向数据:02 |
|