瀏覽單個文章
野口隆史
Elite Member
 
野口隆史的大頭照
 

加入日期: Mar 2001
您的住址: Rivia
文章: 7,036
photo.exe 程序行為

CreateRegValue \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{304F6EBC-3717-49A0-AAE5-9F458932695D}
CreateRegValue \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{304F6EBC-3717-49A0-AAE5-9F458932695D}\InProcServer32\ThreadingModel
CreateRegKey \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{304F6EBC-3717-49A0-AAE5-9F458932695D}\InProcServer32
CreateRegKey \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{304F6EBC-3717-49A0-AAE5-9F458932695D}
CreateFile C:\WINDOWS\winvar.dll
CreateFile C:\WINDOWS\system32\winsp2.exe

KAV 是擋的住的
__________________
Folding@home with GPGPU集中討論串

Unix Review: ArchLinuxSabayonOpenSolaris 2008.5Ubuntu 8.10
AVs Review: GDTCAntiVir SSESSKIS 09NIS 09Norton 360 V3

I Always Get What I Want.
舊 2007-04-12, 10:23 PM #127
回應時引用此文章
野口隆史離線中