两次注册表快照,跟以前看到的还真不一样。应该是软件限制次数的吧?如何实现的呢?
望高手分解一下。
REGSHOT 记录文件 个人注释:
日期时间:2010/5/18 14:57:03 , 2010/5/18 14:57:36
计算机名:xxx , xxxx
用户名称:xxx , xxxx
修改键值:11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG\Seed: D9 72 C0 6A
0A B6 F9 02 6E DD 4D 75 66 C8 41 1A AC BB 91 C1 57 5A EC 4A 48 06 34 E8 D6
BB 73 94 EA C5 93 FE 5A 0E 74 CD A3 FD 61 13 37 AF 06 94 08 3C 65 05 11 92
3D B9 C1 94 B2 14 2E 5E C7 E6 A3 71 83 7D 64 E3 F6 53 E8 13 93 DD 3D B4 53
FB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG\Seed: 21 6D DB EB
67 4F DC C1 66 65 C8 4D 64 9B C8 1F EA 93 E6 8C 97 39 E1 E6 7C 44 2D 83 2C
45 42 37 68 12 67 99 CF 27 E4 0B AB 82 99 0F A9 02 42 95 91 BE D8 70 EA A5
06 F3 C9 C0 64 39 5A 21 4F C0 C6 92 3D 0E C1 27 FD FF A0 91 77 50 90 F7 CE
C8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Prefetcher\TracesProcessed: 0x000000AC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Prefetcher\TracesProcessed: 0x000000AD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Epoch\Epoch:
0x000002D3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Epoch\Epoch:
0x000002D4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{6CD2456C-8A2F-4072-A497-D594BD3EBCA9}\DhcpRetryStatus:
0x00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{6CD2456C-8A2F-4072-A497-D594BD3EBCA9}\DhcpRetryStatus:
0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\HardSysInfo\Disk1: "003917D492DF0873"
HKEY_LOCAL_MACHINE\SYSTEM\HardSysInfo\Disk1: "B51AA4E097227A13"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\Epoch:
0x000002D3
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\Epoch:
0x000002D4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6CD2456C-8A2F-4072-A497-D594BD3EBCA9}\DhcpRetryStatus:
0x00000000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6CD2456C-8A2F-4072-A497-D594BD3EBCA9}\DhcpRetryStatus:
0x00000001
HKEY_USERS\S-1-5-21-1031626584-1083309504-1141271209-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_HVFPHG:
03 00 00 00 67 00 00 00 C0 27 FB 55 9A F6 CA 01
HKEY_USERS\S-1-5-21-1031626584-1083309504-1141271209-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_HVFPHG:
03 00 00 00 68 00 00 00 10 42 C0 67 9A F6 CA 01
HKEY_USERS\S-1-5-21-1031626584-1083309504-1141271209-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:
03 00 00 00 E4 00 00 00 80 F5 12 56 9A F6 CA 01
HKEY_USERS\S-1-5-21-1031626584-1083309504-1141271209-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:
03 00 00 00 E6 00 00 00 D0 80 DA 67 9A F6 CA 01
HKEY_USERS\S-1-5-21-1031626584-1083309504-1141271209-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:Q:\Cebtenz
Svyrf\管理系统\LQGfbsg.rkr: 03 00 00 00 11 00 00 00 80 F5 12 56 9A F6
CA 01
HKEY_USERS\S-1-5-21-1031626584-1083309504-1141271209-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:Q:\Cebtenz
Svyrf\管理系统\LQGfbsg.rkr: 03 00 00 00 12 00 00 00 D0 80 DA 67 9A F6
CA 01
HKEY_USERS\S-1-5-21-1031626584-1083309504-1141271209-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:管理系统.yax:
03 00 00 00 10 00 00 00 C0 27 FB 55 9A F6 CA 01
HKEY_USERS\S-1-5-21-1031626584-1083309504-1141271209-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:管理系统.yax:
03 00 00 00 11 00 00 00 10 42 C0 67 9A F6 CA 01
修改文件:4
C:\WINDOWS\system32\config\SYSTEM
C:\WINDOWS\system32\config\SOFTWARE
C:\WINDOWS\system32\config\SYSTEM.LOG
C:\WINDOWS\system32\config\SOFTWARE.LOG
总计:15
错误报告:regshot.yeah.net
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课