----------------------------------
添加键值:67
----------------------------------
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C574040B-C11C-41EF-8401-E2AF6F5F6841}\Version\: "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C574040B-C11C-41EF-8401-E2AF6F5F6841}\TypeLib\: "{8B5396EC-B2EF-4B66-85C7-3AF65E3B82B0}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C574040B-C11C-41EF-8401-E2AF6F5F6841}\ProgID\: "VCFIWZDY32.NTSockSrv"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C574040B-C11C-41EF-8401-E2AF6F5F6841}\LocalServer32\: "c:\WINDOWS\system32\wbem\lsass.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C574040B-C11C-41EF-8401-E2AF6F5F6841}\: "SysBackHelper
Object"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F8F1D406-1CCA-402A-8D02-12F5B4DEBA30}\TypeLib\: "{8B5396EC-B2EF-4B66-85C7-3AF65E3B82B0}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F8F1D406-1CCA-402A-8D02-12F5B4DEBA30}\TypeLib\Version: "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F8F1D406-1CCA-402A-8D02-12F5B4DEBA30}\ProxyStubClsid32\: "{00020424-0000-0000-C000-000000000046}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F8F1D406-1CCA-402A-8D02-12F5B4DEBA30}\ProxyStubClsid\: "{00020424-0000-0000-C000-000000000046}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F8F1D406-1CCA-402A-8D02-12F5B4DEBA30}\: "INTSockInt"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8B5396EC-B2EF-4B66-85C7-3AF65E3B82B0}\1.0\0\win32\: "c:\WINDOWS\system32\wbem\lsass.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8B5396EC-B2EF-4B66-85C7-3AF65E3B82B0}\1.0\HELPDIR\: "c:\WINDOWS\system32\wbem\"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8B5396EC-B2EF-4B66-85C7-3AF65E3B82B0}\1.0\FLAGS\: "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8B5396EC-B2EF-4B66-85C7-3AF65E3B82B0}\1.0\: "NTSockSrv32 Library"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VCFIWZDY32.NTSockSrv\Clsid\: "{C574040B-C11C-41EF-8401-E2AF6F5F6841}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VCFIWZDY32.NTSockSrv\: "SysBackHelper
Object"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NTWorkStan: 'NTWorkStan'
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NTWORKSTAN\0000\Control\*NewlyCreated*: 0x00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NTWORKSTAN\0000\Control\ActiveService: "NTWorkStan"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NTWORKSTAN\0000\Service: "NTWorkStan"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NTWORKSTAN\0000\Legacy: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NTWORKSTAN\0000\ConfigFlags: 0x00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NTWORKSTAN\0000\Class: "LegacyDriver"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NTWORKSTAN\0000\ClassGUID: "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NTWORKSTAN\0000\DeviceDesc: "WindowsNt Workstation"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NTWORKSTAN\NextInstance: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\WINDOWS\system32\wbem\lsass.exe: "C:\WINDOWS\system32\wbem\lsass.exe:*:Enabled:Generic Hosts for WinService"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\6100:UDP: "6100:UDP:*:Enabled:winsocksv"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTWorkStan\Enum\0: "Root\LEGACY_NTWORKSTAN\0000"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTWorkStan\Enum\Count: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTWorkStan\Enum\NextInstance: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTWorkStan\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTWorkStan\Parameters\ServiceDll: "c:\windows\system32\ntworkstan.dll"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTWorkStan\Start: 0x00000002
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTWorkStan\Type: 0x00000120
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTWorkStan\ErrorControl: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTWorkStan\DisplayName: "WindowsNt Workstation"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTWorkStan\ImagePath: "%SystemRoot%\System32\svchost.exe -k NTWorkStan"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTWorkStan\Description: "创建和维护到NT环境下远程服务的客户端网络连接。如果服务停止,这些连接将不可用。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTWorkStan\
ObjectName: "LocalSystem"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NTWORKSTAN\0000\Control\*NewlyCreated*: 0x00000000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NTWORKSTAN\0000\Control\ActiveService: "NTWorkStan"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NTWORKSTAN\0000\Service: "NTWorkStan"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NTWORKSTAN\0000\Legacy: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NTWORKSTAN\0000\ConfigFlags: 0x00000000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NTWORKSTAN\0000\Class: "LegacyDriver"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NTWORKSTAN\0000\ClassGUID: "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NTWORKSTAN\0000\DeviceDesc: "WindowsNt Workstation"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NTWORKSTAN\NextInstance: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\WINDOWS\system32\wbem\lsass.exe: "C:\WINDOWS\system32\wbem\lsass.exe:*:Enabled:Generic Hosts for WinService"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\6100:UDP: "6100:UDP:*:Enabled:winsocksv"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTWorkStan\Enum\0: "Root\LEGACY_NTWORKSTAN\0000"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTWorkStan\Enum\Count: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTWorkStan\Enum\NextInstance: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTWorkStan\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTWorkStan\Parameters\ServiceDll: "c:\windows\system32\ntworkstan.dll"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTWorkStan\Start: 0x00000002
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTWorkStan\Type: 0x00000120
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTWorkStan\ErrorControl: 0x00000001
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTWorkStan\DisplayName: "WindowsNt Workstation"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTWorkStan\ImagePath: "%SystemRoot%\System32\svchost.exe -k NTWorkStan"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTWorkStan\Description: "创建和维护到NT环境下远程服务的客户端网络连接。如果服务停止,这些连接将不可用。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTWorkStan\
ObjectName: "LocalSystem"