注册表是启动程序隐藏最多的地方,主要包括以下各项:
A,运行键
“运行”键是最流行的病毒自我启动场所。密钥位置是[HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Run]和[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Run]。每次您开始登录时,所有程序都会自动按顺序执行。
在注册表[HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ Run]和[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ Run]中,还有一个未被注意的运行项,请仔细检查。
B,RunOnce键

RunOnce位于[HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ RunOnce]和[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ RunOnce]项中。与Run不同,RunOnce下的程序将仅自动执行一次。
C,RunServicesOnce键
RunServicesOnce项位于[HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ RunServicesOnce]和[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ RunServicesOnce]下,其中的程序将在系统启动时自动启动并执行一次加载
D,RunServices键

RunServicesOnce之后由RunServices启动的程序位于注册表项[HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ RunServices]和[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ RunServices]中。
E,RunOnceEx键
此密钥是Windows XP / 2003和更高版本的Windows所独有的自启动注册表项,位于[HKEY_CURRENT_USER \\ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ RunOnceEx]和[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ RunOnceEx]。
F,加载键

[HKEY_CURRENT_USER \ Software \ Microsoft \ WindowsNT \ CurrentVersion \ Windows]下的加载密钥程序也可以自动启动。
G,Winlogon键
项位于注册表[HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ WindowsNT \ CurrentVersion \ Winlogon]和[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ WindowsNT \ CurrentVersion \ Winlogon]中。请注意,以下Notify,Userinit和Shell键值也将具有自启动程序,并且它们的键值可以用逗号分隔,以便登录时可以启动多个程序。
H,其他注册表位置
还有其他一些键值,并且某些程序通常在此处自动运行,例如:
[HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System \ Shell] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ ShellServiceObjectDelayLoad] [HKEY_CURRENT_USER \ Software \ Policies \ Microsoft \ Windows \ System \ Scripts] [HKEY_LOCAL_MACHINE \ Software \ Policies \ Microsoft \ Windows \ System \ Scripts]
本文来自电脑杂谈,转载请注明本文网址:
http://www.pc-fly.com/a/jisuanjixue/article-365648-1.html
喝了睡觉好