本文共 10784 字,大约阅读时间需要 35 分钟。
This is a list of auto-start locations that malware’s normally use to restart themselves on a system reboot. It was with us since the time we basically started working on .
We have tried to find their Vista entries too. , we don’t know yet. Now, some might not work on all platforms. They might not work on Windows 98, 95, ME, etc. as they are not Windows NT bases and the NT’s work differently. Some will also work without any registry key manipulation.
We have maintained a few known abbreviations just to shorten the post. They are as follows:
HKLM : HKEY_LOCAL_MACHINEHKCU : HKEY_CURRENT_USERHKCR : HKEY_CLASSES_ROOT%windir% : The Windows Directory. Can be C:/Windows or C:/WINNT or anything, depending on the location, the OS & the customization of the OS!%USERPROFILE% : Normally is C:/Documents and Settings/, depending on the installation location.%ALLUSERSPROFILE% : Normally is C:/Documents and Settings/All Users, depending on the installation location.Please keep in mind that the Windows registry is very sensitive and you should fiddle with it only if you know how to get out of it! We should not be held responsible for any harm coming out of their usage!
Beginning with registry methods:
1. HKLM/System/CurrentControlSet/Control/Terminal Server/Wds/rdpwd/StartupPrograms2. HKLM/SOFTWARE//Windows NT/CurrentVersion/Winlogon/AppSetup3. HKLM/Software/Policies/Microsoft/Windows/System/Scripts/Startup4. HKCU/Software/Policies/Microsoft/Windows/System/Scripts/Logon5. HKLM/Software/Policies/Microsoft/Windows/System/Scripts/Logon6. HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Winlogon/Userinit7. HKCU/Software/Microsoft/Windows/CurrentVersion/Policies/System/Shell8. HKCU/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Winlogon/Shell9. HKLM/Software/Microsoft/Windows/CurrentVersion/Policies/System/Shell10. HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Winlogon/Shell11. HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Winlogon/Taskman12. HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Terminal Server/Install/Software/Microsoft/Windows/CurrentVersion/Runonce13. HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Terminal Server/Install/Software/Microsoft/Windows/CurrentVersion/RunonceEx14. HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Terminal Server/Install/Software/Microsoft/Windows/CurrentVersion/Run15. HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Run16. HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/RunOnceEx17. HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/RunOnce18. HKCU/Software/Microsoft/Windows NT/CurrentVersion/Windows/Load19. HKCU/Software/Microsoft/Windows NT/CurrentVersion/Windows/Run20. HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Policies/Explorer/Run21. HKCU/Software/Microsoft/Windows/CurrentVersion/Policies/Explorer/Run22. HKCU/Software/Microsoft/Windows/CurrentVersion/Run23. HKCU/Software/Microsoft/Windows/CurrentVersion/RunOnce24. HKCU/Software/Microsoft/Windows/CurrentVersion/RunOnce/Setup/25. HKCU/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Terminal Server/Install/Software/Microsoft/Windows/CurrentVersion/Runonce26. HKCU/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Terminal Server/Install/Software/Microsoft/Windows/CurrentVersion/RunonceEx27. HKCU/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Terminal Server/Install/Software/Microsoft/Windows/CurrentVersion/Run28. HKLM/SOFTWARE/Classes/Protocols/Filter29. HKLM/SOFTWARE/Classes/Protocols/Handler30. HKCU/SOFTWARE/Microsoft/Internet Explorer/Desktop/Components31. HKLM/SOFTWARE/Microsoft/Active Setup/Installed Components32. HKCU/SOFTWARE/Microsoft/Active Setup/Installed Components33. HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Explorer/SharedTaskScheduler34. HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/ShellServiceObjectDelayLoad35. HKCU/SOFTWARE/Microsoft/Windows/CurrentVersion/ShellServiceObjectDelayLoad36. HKLM/Software/Microsoft/Windows/CurrentVersion/Explorer/ShellExecuteHooks37. HKCU/Software/Classes/*/ShellEx/ContextMenuHandlers38. HKLM/Software/Classes/*/ShellEx/ContextMenuHandlers39. HKCU/Software/Classes/AllFileSystemObjects/ShellEx/ContextMenuHandlers40. HKLM/Software/Classes/AllFileSystemObjects/ShellEx/ContextMenuHandlers41. HKCU/Software/Classes/Folder/ShellEx/ContextMenuHandlers42. HKLM/Software/Classes/Folder/ShellEx/ContextMenuHandlers43. HKCU/Software/Classes/Directory/ShellEx/ContextMenuHandlers44. HKLM/Software/Classes/Directory/ShellEx/ContextMenuHandlers45. HKCU/Software/Classes/Directory/Background/ShellEx/ContextMenuHandlers46. HKLM/Software/Classes/Directory/Background/ShellEx/ContextMenuHandlers47. HKCU/Software/Classes/Folder/Shellex/ColumnHandlers48. HKLM/Software/Classes/Folder/Shellex/ColumnHandlers49. HKCU/Software/Microsoft/Windows/CurrentVersion/Explorer/ShellIconOverlayIdentifiers50. HKLM/Software/Microsoft/Windows/CurrentVersion/Explorer/ShellIconOverlayIdentifiers51. HKCU/Software/Microsoft/Ctf/LangBarAddin52. HKLM/Software/Microsoft/Ctf/LangBarAddin53. HKCU/Software/Microsoft/Windows/CurrentVersion/Shell Extensions/Approved54. HKLM/Software/Microsoft/Windows/CurrentVersion/Shell Extensions/Approved55. HKLM/Software/Microsoft/Windows/CurrentVersion/Explorer/Browser Helper Objects56. HKCU/Software/Microsoft/Internet Explorer/UrlSearchHooks57. HKLM/Software/Microsoft/Internet Explorer/Toolbar58. HKCU/Software/Microsoft/Internet Explorer/Explorer Bars59. HKLM/Software/Microsoft/Internet Explorer/Explorer Bars60. HKCU/Software/Microsoft/Internet Explorer/Extensions61. HKLM/Software/Microsoft/Internet Explorer/Extensions62. HKLM/System/CurrentControlSet/Services63. HKLM/System/CurrentControlSet/Services64. HKLM/System/CurrentControlSet/Control/Session Manager/BootExecute65. HKLM/System/CurrentControlSet/Control/Session Manager/SetupExecute66. HKLM/System/CurrentControlSet/Control/Session Manager/Execute67. HKLM/Software/Microsoft/Windows NT/CurrentVersion/Image File Execution Options68. HKLM/Software/Microsoft/Command Processor/Autorun69. HKCU/Software/Microsoft/Command Processor/Autorun70. HKLM/SOFTWARE/Classes/Exefile/Shell/Open/Command/(Default)71. HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Windows/Appinit_Dlls72. HKLM/System/CurrentControlSet/Control/Session Manager/KnownDlls73. HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Winlogon/System74. HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Winlogon/UIHost75. HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Winlogon/Notify76. HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Winlogon/GinaDLL77. HKCU/Control Panel/Desktop/Scrnsave.exe78. HKLM/System/CurrentControlSet/Control/BootVerificationProgram/ImagePath79. HKLM/System/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog980. HKLM/SYSTEM/CurrentControlSet/Control/Print/Monitors81. HKLM/SYSTEM/CurrentControlSet/Control/SecurityProviders/SecurityProviders82. HKLM/SYSTEM/CurrentControlSet/Control/Lsa/Authentication Packages83. HKLM/SYSTEM/CurrentControlSet/Control/Lsa/Notification Packages84. HKLM/SYSTEM/CurrentControlSet/Control/Lsa/ Packages85. HKLM/SYSTEM/CurrentControlSet/Control/NetworkProvider/Order86. HKCU/Software/Microsoft/Windows NT/CurrentVersion/Windows/load87. HKCR/batfile/shell/open/command @="/"%1/" %*"88. HKCR/comfile/shell/open/command @="/"%1/" %*"89. HKCR/exefile/shell/open/command @="/"%1/" %*"90. HKCR/htafile/Shell/Open/Command @="/"%1/" %*"91. HKCR/piffile/shell/open/command @="/"%1/" %*"92. HKLM/Software/Classes/batfile/shell/open/command93. HKLM/Software/Classes/comfile/shell/open/command 94. HKLM/Software/Classes/exefile/shell/open/command95. HKLM/Software/Classes/htafile/shell/open/command96. HKLM/Software/Classes/piffile/shell/open/command97. HKLM/System/CurrentControlSet/Control/Class/{4D36E96B-E325-11CE-BFC1-08002BE10318}/UpperFilters98. HKLM/Software/Microsoft/Windows NT/CurrentVersion/Winlogon/VmApplet99. HKLM/Software/Microsoft/Windows NT/CurrentVersion/InitFileMapping100. HKLM/Software/Microsoft/Windows NT/CurrentVersion/Aedebug101. HKLM/Software/Classes/CLSID/{CLSID}/Implemented Categories/{00021493-0000-0000-C000-000000000046}102. HKLM/Software/Classes/CLSID/{CLSID}/Implemented Categories/{00021494-0000-0000-C000-000000000046}103. HKCU/Software/Microsoft/Windows/CurrentVersion/Explorer/FileExts/.bat/Application104. HKCU/Software/Microsoft/Windows/CurrentVersion/Explorer/FileExts/.cmd/Application105. HKCU/Software/Microsoft/Windows/CurrentVersion/Explorer/FileExts/.com/Application106. HKCU/Software/Microsoft/Windows/CurrentVersion/Explorer/FileExts/.exe/Application107. HKCU/Software/Microsoft/Windows/CurrentVersion/Explorer/FileExts/.hta/Application108. HKCU/Software/Microsoft/Windows/CurrentVersion/Explorer/FileExts/.pif/Application109. HKCU/Software/Microsoft/Windows/CurrentVersion/Explorer/FileExts/.scr/Application110. HKCU/Software/Microsoft/Windows/CurrentVersion/Explorer/FileExts/.bat/ProgID111. HKCU/Software/Microsoft/Windows/CurrentVersion/Explorer/FileExts/.cmd/ProgID112. HKCU/Software/Microsoft/Windows/CurrentVersion/Explorer/FileExts/.com/ProgID113. HKCU/Software/Microsoft/Windows/CurrentVersion/Explorer/FileExts/.exe/ProgID114. HKCU/Software/Microsoft/Windows/CurrentVersion/Explorer/FileExts/.hta/ProgID115. HKCU/Software/Microsoft/Windows/CurrentVersion/Explorer/FileExts/.pif/ProgID116. HKCU/Software/Microsoft/Windows/CurrentVersion/Explorer/FileExts/.scr/ProgID117. HKLM/Software/CLASSES/batfile/shell/open/command @="/"%1/" %*"118. HKLM/Software/CLASSES/comfile/shell/open/command @="/"%1/" %*"119. HKLM/Software/CLASSES/exefile/shell/open/command @="/"%1/" %*"120. HKLM/Software/CLASSES/htafile/Shell/Open/Command @="/"%1/" %*"121. HKLM/Software/CLASSES/piffile/shell/open/command @="/"%1/" %*"122. HKCR/vbsfile/shell/open/command/123. HKCR/vbefile/shell/open/command/124. HKCR/jsfile/shell/open/command/125. HKCR/jsefile/shell/open/command/126. HKCR/wshfile/shell/open/command/127. HKCR/wsffile/shell/open/command/128. HKCR/scrfile/shell/open/command/129. HKLM/Software/Microsoft/Active Setup/Installed Components/KeyNameStubPath=C:/PathToFile/Filename.exe
Now, we will start with folder auto start locations.
%ALLUSERSPROFILE%/Start Menu/Programs/Startup%USERPROFILE%/Start Menu/Programs/Startup%windir%/Tasks%windir%/System32/Tasks - Windows Vista%ALLUSERSPROFILE%/Microsoft/Windows/Start Menu/Programs/Startup%USERPROFILE%/AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup
In addition to this, there are some more files which when added an entry, will restart the file.
win.ini:[windows]load=file.exe
OR
[windows]run=file.exe
system.ini:[boot]Shell=Explorer.exe file.exe
windir/dosstart.bat (Windows 95 or Windows 98 only)
windir/system/autoexec.ntwindir/system/config.nt转载地址:http://ngmmb.baihongyu.com/