注册表操作相关
(124)主程序,路径:C:\Documents and Settings\Administrator\桌面\lsass.exe,命令行:C:\Documents and Settings\Administrator\桌面\lsass.exe,隐藏(NO),成功(YES)
----线程(1116)
--------注册表操作(设置键值):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders,键名:Cache,原类型:REG_SZ,值:C:\Documents and Settings\Administrator\Local Settings\Temporary Intern
--------注册表操作(设置键值):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths,键名:Directory,原类型:REG_SZ,值:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5,设置类型:R
--------注册表操作(设置键值):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths,键名:Paths,原类型:REG_DWORD,值:0x4,设置类型:REG_DWORD,设置值:0x4,成功(YES)
--------注册表操作(设置键值):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1,键名:CachePath,原类型:REG_SZ,值:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache
--------注册表操作(设置键值):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2,键名:CachePath,原类型:REG_SZ,值:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache
--------注册表操作(设置键值):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3,键名:CachePath,原类型:REG_SZ,值:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache
--------注册表操作(设置键值):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4,键名:CachePath,原类型:REG_SZ,值:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache
--------注册表操作(设置键值):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1,键名:CacheLimit,原类型:REG_DWORD,值:0xc606,设置类型:REG_DWORD,设置值:0xc606,成功(YES)
--------注册表操作(设置键值):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2,键名:CacheLimit,原类型:REG_DWORD,值:0xc606,设置类型:REG_DWORD,设置值:0xc606,成功(YES)
--------注册表操作(设置键值):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3,键名:CacheLimit,原类型:REG_DWORD,值:0xc606,设置类型:REG_DWORD,设置值:0xc606,成功(YES)
--------注册表操作(设置键值):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4,键名:CacheLimit,原类型:REG_DWORD,值:0xc606,设置类型:REG_DWORD,设置值:0xc606,成功(YES)
--------注册表操作(设置键值):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders,键名:Cookies,原类型:REG_SZ,值:C:\Documents and Settings\Administrator\Cookies,设置类型:REG_SZ,设置
--------注册表操作(设置键值):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders,键名:History,原类型:REG_SZ,值:C:\Documents and Settings\Administrator\Local Settings\History,设置类
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS,成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI,成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL,成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents,成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318},成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318},成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options,成功(NO)
--------注册表操作(设置键值):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden,键名:Type,原类型:REG_SZ,值:checkbox,设置类型:REG_SZ,设置值:radio,成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8D406E45-73B3-46D4-B785-C885BB766922}User,成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{8D406E45-73B3-46D4-B785-C885BB766922}Machine,成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects,成功(YES)
--------注册表操作(设置键值):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap,键名:ProxyBypass,原类型:REG_DWORD,值:0x1,设置类型:REG_DWORD,设置值:0x1,成功(YES)
--------注册表操作(设置键值):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap,键名:IntranetName,原类型:REG_DWORD,值:0x1,设置类型:REG_DWORD,设置值:0x1,成功(YES)
--------注册表操作(设置键值):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap,键名:UNCAsIntranet,原类型:REG_DWORD,值:0x1,设置类型:REG_DWORD,设置值:0x1,成功(YES)
--------注册表操作(设置键值):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap,键名:ProxyBypass,原类型:REG_DWORD,值:0x1,设置类型:REG_DWORD,设置值:0x1,成功(YES)
--------注册表操作(设置键值):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap,键名:IntranetName,原类型:REG_DWORD,值:0x1,设置类型:REG_DWORD,设置值:0x1,成功(YES)
--------注册表操作(设置键值):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap,键名:UNCAsIntranet,原类型:REG_DWORD,值:0x1,设置类型:REG_DWORD,设置值:0x1,成功(YES)
--------注册表操作(设置键值):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0706e4b-2ebe-4b57-88cb-d239c61505fe},键名:BaseClass,原类型:REG_SZ,值:Drive,设置类型:REG_SZ,设置值
--------注册表操作(设置键值):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5b8c9240-3c58-11dc-83e0-806d6172696f},键名:BaseClass,原类型:REG_SZ,值:Drive,设置类型:REG_SZ,设置值
--------注册表操作(设置键值):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5b8c9241-3c58-11dc-83e0-806d6172696f},键名:BaseClass,原类型:REG_SZ,值:Drive,设置类型:REG_SZ,设置值
--------注册表操作(设置键值):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5b8c9242-3c58-11dc-83e0-886dcf7d88d4},键名:BaseClass,原类型:REG_SZ,值:Drive,设置类型:REG_SZ,设置值
--------注册表操作(创建键值):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\ShellNoRoam\MUICache,键名:C:\WINDOWS\system32\cacls.exe,类型:REG_SZ,值:Control ACLs Program,成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33},成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths,成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc},成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d},成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f},成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91},成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328},成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes,成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0,成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers,成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer,成功(YES)
--------注册表操作(创建键值):路径:\REGISTRY\USER\S-1-5-21-2351090138-3547460704-1241520142-500\Software\Microsoft\Windows\ShellNoRoam\MUICache,键名:C:\WINDOWS\system32\regsvr32.exe,类型:REG_SZ,值:Microsoft(C) Register Server,成功(YES)
--------注册表操作(设置键值):路径:\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager,键名:PendingFileRenameOperations,原类型:REG_MULTI_SZ,值:\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\VMwareDnD\00006fe1\,设置类型:REG_MULTI_SZ,设置值:\??\C:\DOCUME~1\
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options,成功(NO)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options,成功(NO)
--------注册表操作(设置键值):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication,键名:Name,原类型:REG_SZ,值:漂亮金鱼.SCR,设置类型:REG_SZ,设置值:lsass.exe,成功(YES)
--------注册表操作(设置键值):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication,键名:ID,原类型:REG_DWORD,值:0x3f81df0d,设置类型:REG_DWORD,设置值:0x47de77b1,成功(YES)
--------注册表操作(设置键值):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication,键名:Name,原类型:REG_SZ,值:lsass.exe,设置类型:REG_SZ,设置值:lsass.exe,成功(YES)
--------注册表操作(设置键值):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication,键名:ID,原类型:REG_DWORD,值:0x47de77b1,设置类型:REG_DWORD,设置值:0x47de77b1,成功(YES)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options,成功(NO)
--------注册表操作(删除项):路径:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options,成功(NO)
----(932)子程序,父程序PID(124),路径:C:\WINDOWS\System32\cmd.exe,命令行:cmd.exe /c echo ok,隐藏(NO),挂起(NO),成功(YES)
----(1912)子程序,父程序PID(124),路径:C:\WINDOWS\System32\cacls.exe,命令行:"C:\WINDOWS\system32\cacls.exe" C:\WINDOWS\system32\com /e /t /g Administrator:F,隐藏(NO),挂起(NO),成功(YES)
----(1948)子程序,父程序PID(124),路径:C:\WINDOWS\System32\cacls.exe,命令行:"C:\WINDOWS\system32\cacls.exe" C:\WINDOWS\system32\com /e /t /g Everyone:F,隐藏(NO),挂起(NO),成功(YES)
----(300)子程序,父程序PID(124),路径:C:\WINDOWS\System32\REGSVR32.EXE,命令行:"C:\WINDOWS\system32\regsvr32.exe" C:\WINDOWS\system32\com\netcfg.dll /s,隐藏(NO),挂起(NO),成功(YES)
--------线程(1968)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{814293BA-8708-42E9-A6B7-1BD3172B9DDF},成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{814293BA-8708-42E9-A6B7-1BD3172B9DDF}\1.0,成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{814293BA-8708-42E9-A6B7-1BD3172B9DDF}\1.0,键名:,类型:REG_SZ,值:ifObj ActiveX Control module,成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{814293BA-8708-42E9-A6B7-1BD3172B9DDF}\1.0\FLAGS,成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{814293BA-8708-42E9-A6B7-1BD3172B9DDF}\1.0\FLAGS,键名:,类型:REG_SZ,值:2,成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{814293BA-8708-42E9-A6B7-1BD3172B9DDF}\1.0\0,成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{814293BA-8708-42E9-A6B7-1BD3172B9DDF}\1.0\0\win32,成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{814293BA-8708-42E9-A6B7-1BD3172B9DDF}\1.0\0\win32,键名:,类型:REG_SZ,值:C:\WINDOWS\system32\com\netcfg.dll,成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{814293BA-8708-42E9-A6B7-1BD3172B9DDF}\1.0\HELPDIR,成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{814293BA-8708-42E9-A6B7-1BD3172B9DDF}\1.0\HELPDIR,键名:,类型:REG_SZ,值:C:\WINDOWS\system32\com,成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{AAC17985-187F-4457-A841-E60BAE6359C2},成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{AAC17985-187F-4457-A841-E60BAE6359C2},键名:,类型:REG_SZ,值:_DIfObj,成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{AAC17985-187F-4457-A841-E60BAE6359C2}\ProxyStubClsid,成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{AAC17985-187F-4457-A841-E60BAE6359C2}\ProxyStubClsid,键名:,类型:REG_SZ,值:{00020420-0000-0000-C000-000000000046},成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{AAC17985-187F-4457-A841-E60BAE6359C2}\ProxyStubClsid32,成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{AAC17985-187F-4457-A841-E60BAE6359C2}\ProxyStubClsid32,键名:,类型:REG_SZ,值:{00020420-0000-0000-C000-000000000046},成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{AAC17985-187F-4457-A841-E60BAE6359C2}\TypeLib,成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{AAC17985-187F-4457-A841-E60BAE6359C2}\TypeLib,键名:,类型:REG_SZ,值:{814293BA-8708-42E9-A6B7-1BD3172B9DDF},成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{AAC17985-187F-4457-A841-E60BAE6359C2}\TypeLib,键名:Version,类型:REG_SZ,值:1.0,成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{2D96C4BF-8DCA-4A97-A24A-896FF841AE2D},成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{2D96C4BF-8DCA-4A97-A24A-896FF841AE2D},键名:,类型:REG_SZ,值:_DIfObjEvents,成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{2D96C4BF-8DCA-4A97-A24A-896FF841AE2D}\ProxyStubClsid,成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{2D96C4BF-8DCA-4A97-A24A-896FF841AE2D}\ProxyStubClsid,键名:,类型:REG_SZ,值:{00020420-0000-0000-C000-000000000046},成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{2D96C4BF-8DCA-4A97-A24A-896FF841AE2D}\ProxyStubClsid32,成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{2D96C4BF-8DCA-4A97-A24A-896FF841AE2D}\ProxyStubClsid32,键名:,类型:REG_SZ,值:{00020420-0000-0000-C000-000000000046},成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{2D96C4BF-8DCA-4A97-A24A-896FF841AE2D}\TypeLib,成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{2D96C4BF-8DCA-4A97-A24A-896FF841AE2D}\TypeLib,键名:,类型:REG_SZ,值:{814293BA-8708-42E9-A6B7-1BD3172B9DDF},成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{2D96C4BF-8DCA-4A97-A24A-896FF841AE2D}\TypeLib,键名:Version,类型:REG_SZ,值:1.0,成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{450EC9C4-0F7F-407F-B084-D1147FE9DDCC},成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{450EC9C4-0F7F-407F-B084-D1147FE9DDCC},键名:,类型:REG_SZ,值:IfObj Property Page,成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{450EC9C4-0F7F-407F-B084-D1147FE9DDCC}\InprocServer32,成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{450EC9C4-0F7F-407F-B084-D1147FE9DDCC}\InprocServer32,键名:,类型:REG_SZ,值:C:\WINDOWS\system32\com\netcfg.dll,成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{D9901239-34A2-448D-A000-3705544ECE9D},成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\IFOBJ.IfObjCtrl.1,成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\IFOBJ.IfObjCtrl.1,键名:,类型:REG_SZ,值:IfObj Control,成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\IFOBJ.IfObjCtrl.1\CLSID,成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\IFOBJ.IfObjCtrl.1\CLSID,键名:,类型:REG_SZ,值:{D9901239-34A2-448D-A000-3705544ECE9D},成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{D9901239-34A2-448D-A000-3705544ECE9D},键名:,类型:REG_SZ,值:IfObj Control,成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{D9901239-34A2-448D-A000-3705544ECE9D}\ProgID,成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{D9901239-34A2-448D-A000-3705544ECE9D}\ProgID,键名:,类型:REG_SZ,值:IFOBJ.IfObjCtrl.1,成功(YES)
------------注册表操作(创建项):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{D9901239-34A2-448D-A000-3705544ECE9D}\InprocServer32,成功(YES)
------------注册表操作(创建键值):路径:\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{D9901239-34A2-448D-A000-3705544ECE9D}\InprocServer32,键名:,类型:REG_SZ,值:C:\WINDOWS\system32\com\netcfg.dll,成功(YES) |