Elite Member
|
photo.exe 程序行為
CreateRegValue \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{304F6EBC-3717-49A0-AAE5-9F458932695D}
CreateRegValue \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{304F6EBC-3717-49A0-AAE5-9F458932695D}\InProcServer32\ThreadingModel
CreateRegKey \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{304F6EBC-3717-49A0-AAE5-9F458932695D}\InProcServer32
CreateRegKey \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{304F6EBC-3717-49A0-AAE5-9F458932695D}
CreateFile C:\WINDOWS\winvar.dll
CreateFile C:\WINDOWS\system32\winsp2.exe
KAV 是擋的住的
|