我用了RegSnap对起启用syskey前的注册表和启用syskey后的注册表进行了对比。结果如下:
已删除键: 6
已修改键: 42
新建键 : 32
已删除键
HKEY_USERS\S-1-5-21-1645522239-1060284298-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\@
键值: <值未设置>
HKEY_USERS\S-1-5-21-1645522239-1060284298-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU\@
键值: <值未设置>
HKEY_USERS\S-1-5-21-1645522239-1060284298-725345543-1003\Software\Microsoft\Windows\ShellNoRoam\BagMRU\4\1\0\0
键值: 类型: REG_BINARY 长度: 54 字节
34 00 31 00 00 00 00 00 F4 32 D1 0D 10 00 44 41 | 4.1......2....DA
54 41 00 00 20 00 03 00 04 00 EF BE 8B 33 39 15 | TA.. ........39.
8A 33 00 80 14 00 00 00 44 00 61 00 74 00 61 00 | .3......D.a.t.a.
00 00 14 00 00 00 | ......
HKEY_USERS\S-1-5-21-1645522239-1060284298-725345543-1003\Software\Microsoft\Windows\ShellNoRoam\BagMRU\4\1\0\0\MRUListEx
键值: 类型: REG_BINARY 长度: 4 字节
FF FF FF FF | ....
HKEY_USERS\S-1-5-21-1645522239-1060284298-725345543-1003\Software\Microsoft\Windows\ShellNoRoam\BagMRU\4\1\0\0\NodeSlot
键值: DWORD: 316 (0x13c)
HKEY_USERS\S-1-5-21-1645522239-1060284298-725345543-1003\Software\Vitas\RegSnap\estimReg\@
键值: <值未设置>
--------------
位置总数: 6
已修改键
HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\F
新建键
HKEY_USERS\S-1-5-21-1645522239-1060284298-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU\a
另外:下面的键值,RegSnap处理失败。
SAC子键 主键为secrets
SAI子键 主键为secrets
SCM:{C36729C6-65CB-4A6F-8B96-53FF94E3A8D2} 主键为secrets
SCM:{D0362CF9-9DAC-4898-8D1A-CC11034B1B68} 主键为secrets
SCM:{D1362CF9-9DAC-4898-8D1A-CC11034B1B68} 主键为secrets
Old value: 类型: REG_BINARY 长度: 240 字节
02 00 01 00 00 00 00 00 00 95 C0 DA FB D9 C5 01 | ................
2E 00 00 00 00 00 00 00 00 00 00 00 40 DE FF FF | ............@...
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 | ................
00 CC 1D CF FB FF FF FF 00 CC 1D CF FB FF FF FF | ................
00 00 00 00 00 00 00 00 F1 03 00 00 00 00 00 00 | ................
00 00 00 00 00 00 00 00 01 00 00 00 03 00 00 00 | ................
01 00 00 00 01 00 01 00 01 00 00 00 38 00 00 00 | ............8...
81 60 6A 3C 3D C7 F6 68 83 06 42 E9 7D B6 6E F5 | .`j<=..h..B.}.n.
24 39 A1 FB 9D B0 62 C2 36 8E 38 C5 BF 0B C3 65 | $9....b.6.8....e
91 26 79 B0 1E 31 73 73 68 A8 75 11 AB 92 BD 43 | .&y..1ssh.u....C
| 对此文章发表了评论 |

