其他设置保护注册表分区免于被修改(包括系统区域和所有用户区域)。
对Image File Execution Options的访问:
•Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options 对User Drivers的访问:
•Software\Microsoft\Windows NT\CurrentVersion\Drivers32 •Software\Microsoft\Windows NT\CurrentVersion\Userinstallable.drivers Winlogon参数:
•Software\Microsoft\Windows NT\CurrentVersion\Winlogon, Userinit, Shell, UIHost, System, Taskman, GinaDLL Winlogon事件通知:
•Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify Windows外壳程序自动运行:
•Software\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs, LoadAppInit_DLLs, Load, Run, IconServiceLib 可执行文件关联:
•Software\Classes\.exe, .pif, .com, .bat, .cmd, .scr, .lnk (参数) •Software\Classes\exefile, piffile, comfile, batfile, cmdfile, scrfile, lnkfile (参数) 软件限制策略(SRP):
•Software\Policies\Microsoft\Windows\Safer Internet Explorer插件(BHO):
•Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects 软件自启动:
•Software\Microsoft\Windows\CurrentVersion\Run •Software\Microsoft\Windows\CurrentVersion\RunOnce •Software\Microsoft\Windows\CurrentVersion\RunOnceEx •Software\Microsoft\Windows\CurrentVersion\RunOnce\Setup •Software\Microsoft\Windows\CurrentVersion\RunOnceEx\Setup •Software\Microsoft\Windows\CurrentVersion\RunServices •Software\Microsoft\Windows\CurrentVersion\RunServicesOnce 策略自动运行:
•Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run 安全模式配置:
•SYSTEM\ControlSetXXX\Control\SafeBoot\Minimal •SYSTEM\ControlSetXXX\Control\SafeBoot\Network 对话管理器参数:
•System\ControlSetXXX\Control\Session Manager\SubSystems, Windows 系统服务:
•System\CurrentControlXXX\Services |