HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

{
ظѲ
HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Windows\run

}


HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System\Scripts

HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\Scripts

{

עϵͳͻұѲ
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services
}



{

עϵͳͻұѲ

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager



}



HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor



HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows



{
Ѳãwin7ұ

HKEY_CLASSES_ROOT\exefile\shell\open\command

HKEY_LOCAL_MACHINE\Software\classes\exefile\shell\open\command



HKEY_CLASSES_ROOT\comfile\shell\open\command

HKEY_LOCAL_MACHINE\Software\CLASSES\comfile\shell\open\command


HKEY_CLASSES_ROOT\cmdfile\shell\open\command

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\cmdfile\shell\open\command


HKEY_CLASSES_ROOT\batfile\shell\open\command

HKEY_LOCAL_MACHINE\Software\CLASSES\batfile\shell\open\command







HKEY_CLASSES_ROOT\htafile\shell\open\command

HKEY_LOCAL_MACHINE\Software\CLASSES\htafile\shell\open\command


HKEY_CLASSES_ROOT\piffile\shell\open\command

HKEY_LOCAL_MACHINE\Software\CLASSES\piffile\shell\open\command

}







HKEY_USERS\.DEFAULT

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VxD

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\aedebug

{
עϵͳͻұѲ
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy
}




{
עϵͳͻұѲ

HKEY_CURRENT_USER\Control Panel\Desktop
}


HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\Names










