RD:
[HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\BitBucket]
"NukeOnDelete"=dword:00000001
"UseGlobalSettings"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run]
"NetWindow"="x:\\DESKTOP\\netwindows\\netwindows\\Server.exe"
[HKEY_LOCAL_MACHINE\software\NetWindow]
"Parameter"="121"
"Password"="77878978977"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5 ]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9 ]
FD
\Device\Afd\AsyncSelectHlp
File Control Code
==============================================
\Device\Afd\Endpoint AFD_SET_INFO (0x0001203B)
\Device\Afd\AsyncSelectHlp AFD_SELECT (0x00012024)
\Device\Afd\Endpoint AFD_GET_TDI_HANDLES (0x00012037)
\Device\Afd\Endpoint AFD_SET_CONTEXT (0x00012047)
\Device\Afd\Endpoint AFD_BIND (0x00012003)
\Device\Afd\Endpoint AFD_GET_SOCK_NAME (0x0001202F)
\Device\Afd\Endpoint AFD_SEND_DATAGRAM (0x00012023)
\Device\Afd\Endpoint AFD_RECV_DATAGRAM (0x0001201B)
C:\WINDOWS\system32\Msimtf.dll (Mem Map)
ND:
open port: TCP 5050
需要客户端的程序才能看出这东西有多厉害。
[
本帖最后由 ALEXBLAIR 于 2008-7-18 01:14 编辑 ]