检查到注册表服务项目:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\heng_pro]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000000
"ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,\
44,00,4f,00,57,00,53,00,5c,00,4d,00,65,00,64,00,69,00,61,00,5c,00,44,00,65,\
00,73,00,6b,00,74,00,6f,00,70,00,2e,00,69,00,6e,00,69,00,3a,00,78,00,69,00,\
6e,00,73,00,74,00,61,00,6c,00,6c,00,65,00,72,00,2e,00,73,00,79,00,73,00,00,\
00
"DisplayName"="heng_pro"
"WOW64"=dword:00000001
|