Professional Documents
Culture Documents
XP :sfc.exe
/purgecache , 3xxMb
zipfldr.dll
: regsvr32 /u zipfldr.dll
Win XP
32 32M
XP XP 256M
128M 32M XP
XP
? XP?
98 ( XP 98
)
1K XP
(:
XP SP1
SP2 BTQQ
3 XP )
R U ready?Lets go
WinXP ms
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\MSMSGS
/BACKGROUND cfmon
2
regedit
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
\PrefetchParameters EnablePrefetcher 1
none()
3
win2000
XP
5 XP Qos 20%
: gpedit.msc
QoS
QoS Packet
Scheduler(QoS )
Qos ()
Windows XP
30 Regedit
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\ Current
Version\Explorer\RemoteComputer\NameSpace{D6277990- 4C6A-11CF-8D8700AA0060F5BF}Windows XP
hoho~~~ !
7 Dr. Watson
win95 :
HKEY_LOCAL_MACHINE\SOFTWARE\ Microsoft\Windows NT\CurrentVersion\AeDebug
Auto 0 F5
memory.dmp
8KAO !:---->---->
---->--->---->>!
Windows XP 9 10 10
0 !
CHKNTFS /T:0 10
10
Bootvis
TraceOptimize System; Windows XP
MsConfig msconfig
Startup
?:
1 XP :
sfc.exe /purgecache 3xxM
4%windows%\$NtUninstallQ311889$
1x-3xM
6:\%windows%\inf\sysoc.inf/
,hide,hide -
/ Windows ;
10
Windows XP Windows XP
11
1.4G XP 800
?? GHOST
??
()
: Windows XP
BBS
WELCOME
QQ Windows XP
QQ Windows XP QQ710
MSNMessenger ?
QQXP
:!
!
1 3D 3D
3D
2 ( C )
4
??
:?
(
)
(: 20G
)
5 :1
2
Win XP
Before
ANSON
2006-02-17 14:29:35
Windows XP
Windows XP
Windows XP
WinRAR Zip
zipfldr.dll regsvr32
/u zipfldr.dll()
XP
regsvr32
/u schmedia.dll
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion]
NoCDBurningDWORD1 1
Windows XP Windows Me
1.
[HKEY_CURRENT_USER\Software\Microsoft
\Windows\CurrentVersion\Applets\Regedit]
LastKey 2
2. Regedit
Administrators 3
30
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
\CurrentVersion\Explorer\RemoteComputer\NameSpace]
Windows 4
IE
IE Internet Explorer
IE
1.gpedit.msc
2.Windows Internet
Explorer Internet Explorer
Internet Explorer
3. Internet Explorer
IE IE Internet
Explorer Internet Explorer
Internet Explorer IE
Windows XP
Windows XP Windows XP
[HKEY_CURRENT_Software\Microsoft\Windows
\CurrentVersion\Explorer\Advanced]
TaskbarGroUPSizeDWORD
8 8
Windows XP
60 60
60 9
Windows XP
[HKEY_CURRENT_USER/Software/Microsoft/Windows
/CurrentVersion/Policies/Explorer]
NoLowDiskSpaceChecks1
10
10
Windows XP sysoc.inf
11 C:\WINDOWS\inf
Dr.Watson
11
WindowsXP
XP
1 XP
sfc.exe /purgecache 3xxM
3 help %windows%help
4xM
4%windows%$NtUninstallQ311889$
1x-3xM
5 pagefile.sys
6\%windows%infsysoc.inf/
,hide,hide -
/ Windows
8 NTFS 2x%
10
50M
1.4G XP 800M
XP
WinXP
2
regedit
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSession ManagerMemory
ManagementPrefetchParameters EnablePrefetcher 1
none
3
win2000
XP
5 XP QoS
gpedit.msc "
"QoS " "
"
"QoS Packet Scheduler
QoS " Qos
6
Windows XP
30 Regedit
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrent
VersionExplorerRemoteComputerNameSpace{D6277990-4C6A-11CF-8700AA0060F5BF}Windows XP
hoho~~~
7 Dr. Watson
win95
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionAeDebug
Auto 0 F5
memory.dmp
1)alerter
2)automatic updates windows
3)background intelligent transfer service
4)clipbook
5)Computer browser
6)DHCP client
7)Distributed link tracking client M
16)Indexing service
17)Internet Connection Firewall(ICF) ICF
18)IPSEC Services Quack
19)Logical Disk manager administrative service
20)messenger net send
21)MS software shadow copy provider
22)Net Logon
23)Netmeeting remote desktop sharing netmeeting
24)Network DDE
47)telnet
48)terminal services
49)uninterruptible power supply UPS
50)universal plug and play device host
51)upload manager
52)volume shadow copy
53)webclient
54)Windows Installer
55)windows image acquisition (WIA)
56)windows management instrumentation driver extensions
57)windows time
58)wireless zero configuration
59)WMI perfromance adapter
60)world wide web publishing service www
XP
IPC$
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLsa]
"restrictanonymous"=dword:00000001
.REG
3721 hosts
127.0.0.1 cnsmin.3721.com
127.0.0.1 http://www.3721.net/
XP
1.../...
[HKEY_LOCAL_MACHINESOFTWAREClassesAllFilesystemObjectsshellex]
[HKEY_LOCAL_MACHINESOFTWAREClassesAllFilesystemObjectsshellexContextMenuHandlers]
[HKEY_LOCAL_MACHINESOFTWAREClassesAllFilesystemObjectsshellexContextMenuHandlers
Copy To]@="{C2FBB630-2971-11D1-A18C-00C04FD75D13}"
[HKEY_LOCAL_MACHINESOFTWAREClassesAllFilesystemObjectsshellexContextMenuHandlers
Move To]@="{C2FBB631-2971-11D1-A18C-00C04FD75D13}"
add.reg
2---->---->
---->--->---->>
3
4WinXP
OK
5
6HKEY_CURRENT_USERControl PanelDesktop
AugoEndTasks1
7
8chkntfs/t:0
XP
tasklist.exe /svc
Ghost .GHO
Ghost
Winxp Deploy.cab sysprep.exe
sysprep.exe
Ghost Ghost
.GHO
XP
XP
F1
windows
F2
F3
F10 ALT
windows CTRL+ESC
CTRL+ALT+DELETE
win9x
DELETE
SHIFT+DELETE
CTRL+N
CTRL+O
CTRL+P
CTRL+S
CTRL+X
CTRL+INSERT CTRL+C
SHIFT+INSERT CTRL+V
ALT+BACKSPACE CTRL+Z
ALT+SHIFT+BACKSPACE
Windows +M
Windows +CTRL+M
Windows +E
Windows +F
Windows +R
Windows +BREAK
Windows +CTRL+F
SHIFT+F10
SHIFT
CD CD word
ALT+F4
ALT+SPACEBAR
ALT+TAB
ALT+ESC
ALT+ENTER
windows MSDOS
PRINT SCREEN
ALT+PRINT SCREEN
CTRL+F4
word
CTRL+F6
shift
IE
ALT+RIGHT ARROW
ALT+LEFT ARROW
CTRL+TAB
shift
F5
CTRL+F5
F10
ALT+
CTRL+ F4
ALT+ F4
CTRL+ C
CTRL+ X
DELETE
F1
ALT+
SHIFT+ F10
CTRL+ ESC
ALT+(-)
CTR L+ V
ALT TAB
ALT+ TAB
CTRL+ Z
Windows
, NUM LOCK+(-)
NUM LOCK+*
NUM LOCK+(+)
F6
WINDOWS
Microsoft Windows
WINDOWS+ TAB
WINDOWS+ F
CTRL+ WINDOWS+ F
WINDOWS+ F1
WINDOWS+ R
WINDOWS
WINDOWS+ BREAK
Windows WINDOWS+ E
WINDOWS+ D
SHIFT+ WINDOWS+ M
Windows
SHIFT
ALT+
ALT+
BACKSPACE
ALT+
ENTER
SHIFT+ TAB
TAB
CTRL+ TAB
BACKSPACE
F5
Windows
SHIFT CD-ROM
CTRL
CTRL+SHIFT
SHIFT+DELETE
F3
APPLICATION
F5
F2
CTRL+ A
Microsoft
Windows
Windows + PAGE UP
Windows +
Windows +
SHIFT
SHIFT
NUM LOCK XP
XP
CABLE MODEM XP
F8
CABLE MODEM
XP
IDE GUI ULTRA DMA
Windows
Win XP
Windows XP
1.system32
Windows XP
Windows XP Windows XP
Windows XP C:WindowsSystem32 ourstart.exe
2.Accwizsystem32
Windows
Windows
Windows
3.Charmapsystem32
Word Windows
Windows
4.CINTSETP(system32IMECintlgnt )
98b Windows XP
Windows
Windows XP
5.Cleanmgrsystem32
Windows
6.Clipbrdsystem32
Windows Windows
Windows XP
Windows 9X/Me
7.Control.exesystem32
Windows
8.Windows XP Drwtsn32system32
9.DVD DVDplaysystem32
DVD DVD
Windows XP DVD DVD
10.Iexpresssystem32
11.Migwizsystem32usmt
Windows
12.MsconfigWindowsPChealthHELPCTRBinaries
Windows SYSTEM.iniWIN.ini
BOOT.ini
13.Ntbackupsystem32
Windows XP
14.ODBC Odbcad32system32
15.IP Nslookupsystem32
IP IP
IP ping IP
http://www.popsoft.com.cn IP DOS ping www.popsoft.com.cn
16.Osksystem32
CAI
17.Packagersystem32
Windows
18.Regedit32system32
Windows XP Regedit
19.ActiveX Regsvr32
ActiveX ActiveX
Windows
System regsvr32.exe Windows ActiveX
regsvr32 [/s] [/n] [/i(:cmdline)] dllname dllname ActiveX
System
/u
/s
/c
/i
/n/i
20.Rundll32
Windows Windows
Windows API
Windows rundll32.exe rundll32.exe
,,
rundll32.exe user.exe,ExitWindows F4
rundll32.exe shell32.dll,Control_RunDLL
rundll32.exe shell32.dll,Control_RunDLL desk.cpl
Win XP ()
--------------------------------------------------------------------------------
21.Sfcsystem32
Windows
Sfc.exe
22.Shrpubwsystem32
23.Microsoft Sigverifsystem32
Microsoft
24.Sndvol32
Windows
Windows sndvol32.exe Windows
sndvol32.exe
/r
C:WindowsSndvol32.exe /R
C:WindowsSndvol32.exe /R
Ctrl+S
25.Taskmgrsystem32
15
CPU
26.Telnetsystem32
Internet
Windows telnet.exe
FTP
FTP
28.Windows Wupdmgrsystem32
Windows XP
cpu
xp cpu xp
cpu
1."regedit";
2."[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSession ManagerMemory
ManagementSecondLevelDataCache]";
3. :
4.
xp
xp I/O
1. "regedit";
2.[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSession ManagerMemory
ManagementIoPageLockLimit];
3.:
64M: 1000;
128M: 4000;
256M: 10000;
512M : 40000.
4.
1.egedit
2.[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSession ManagerMemory
ManagementPrefetchParametersEnablePrefetcher];
3. 01230-Disable,1-,2-,3- ("3"
)
4.
xp
c:windowsprefetch
dos chkntfs/t:0
0 0
Xp
1.
2.
3.
bug
2.regedit
3.[HKEY_CURRENT_USERControl PanelMouse]
"SmoothMouseXCurve"=hex:00,00,00,00,00,00,00,00,00,a0,00,00,00,00,00,00,00,40,
01,00,00,00,00,00,00,80,02,00,00,00,00,00,00,00,05,00,00,00,00,00
"SmoothMouseYCurve"=hex:00,00,00,00,00,00,00,00,66,a6,02,00,00,00,00,00,cd,4c,
05,00,00,00,00,00,a0,99,0a,00,00,00,00,00,38,33,15,00,00,00,00,00
4.
ntfs
ntfs
regedit
HKEY_LOCAL_MACHINESYSTEMCurrentContolSetControlFilesystem) DWORD 1
XP
Windows XP
Windows XP
WinXP
winnt32.exe i386 windows
Windows XP Windows 95Windows 98Windows MeWindows NT
Windows 2000 Windows XP winnt32
/checkupgradeonly
Windows XP /unattend
Upgrade.txt systemroot
/cmd:command_line
/cmdcons
NTFS
/cmdcons
/copydir:i386folder_name
Windows XP
i386 Private_drivers
/copydir:i386Private_drivers
systemrootPrivate_drivers
/copydir
/copysource:folder_name
Windows XP
Private_drivers
/copysourcerivate_drivers
/debug[level]:[filename]
/debug4ebug.log C:systemrootWinnt32.log
20 -- 1 -- 2 -- 3 -- 4 -
/dudisable
/dushare:pathname
Windows Update
/duprepare
/duprepare
pathname
/duprepare
Windows Update
Windows XP /dushare
/m:folder_name
/makelocalsource
/makelocalsource
/noreboot
/s:sourcepath
Windows XP /s:sourcepath
/syspart:drive_letter
/tempdrive
/syspart Windows NT 4.0Windows 2000 Windows XP
/syspart Winnt32 Windows 95Windows 98 Windows Me
/tempdrive:drive_letter
Windows XP
/tempdrive winnt32
/udf:id [,UDB_file]
(UD (id)
/unattend UDF UDF
/udf:RAS_user,Our_company.udb Our_company.udb RAS_user
UDF_file Unique.udb
/unattend
Windows 98 Windows Me
/unattend[num]:[answer_file]
Num Windows 98
Windows MeWindows NTWindows 2000 Windows XP num
/unattend Windows XP
Microsoft Windows XP
Windows XP
Microsoft OEM
Windows Windows XP
Windows XP ""
setup.exe
Windows XP C ""
""
DOS
Windows DOS NT
9x DOS Windows 98 setup.exe
smartdrv.exe,/i386 winnt.exe
Windows XP
"Winnt.sif", I386 ,
. , :
1.
2.
WinXP "",
.
:
1. Administrator "", .
2. NetBEUI TCP/IP , .
3. QoS, gpedit.msc, , .
4.IE Google, IE , .
5.WORKGROUP 'WORKGROUP', Administrator ,
.
6. "ProductID=", 'xxxxx-xxxxx-xxxxx-xxxxx-xxxxx'
7., .
8. 137GB IDE , "EnableBigLba=Yes".
;SetupMgrTag
[Data]
AutoPartition=1
MsDosInitiated="0"
UnattendedInstall="Yes"
[Unattended]
UnattendMode=FullUnattended
OemSkipEula=Yes
OemPreinstall=No
TargetPath=WINDOWS
EnableBigLba=Yes
[GuiUnattended]
AdminPassword=*
EncryptedAdminPassword=No
AutoLogon=Yes
AutoLogonCount=1
OEMSkipRegional=1
TimeZone=220
OemSkipWelcome=1
[UserData]
ProductID=
FullName="."
OrgName="."
ComputerName=*
[Display]
BitsPerPel=16
Xresolution=800
YResolution=600
Vrefresh=75
[TapiLocation]
CountryCode=886
AreaCode=02
[RegionalSettings]
LanguageGroup=1,9
Language=00000404
[Branding]
BrandIEUsingUnattended=Yes
[URL]
Home_Page=http://www.google.com/
Help_Page=http://help.htm
Search_Page=http://search.htm
[Proxy]
Proxy_Enable=0
Use_Same_Proxy=1
[Identification]
JoinWorkgroup=WORKGROUP
[Networking]
InstallDefaultComponents=No
[NetAdapters]
Adapter1=params.Adapter1
[NetClients]
MS_MSClient=params.MS_MSClient
[NetServices]
MS_SERVER=params.MS_SERVER
MS_PSched=params.MS_PSched
[NetProtocols]
MS_TCPIP=params.MS_TCPIP
MS_NetBEUI=params.MS_NetBEUI
[params.MS_TCPIP]
DNS=Yes
UseDomainNameDevolution=No
EnableLMHosts=Yes
AdapterSections=params.MS_TCPIP.Adapter1
[params.MS_TCPIP.Adapter1]
SpecificTo=Adapter1
DHCP=Yes
WINS=No
NetBIOSOptions=0
;--------------------------------------------------------------------end of file
?
1. WinISO , .
2. WinISO, .
3. WinISO 1..
Windows XP
http://www.microsoft.com/downloads/release.asp?releaseid=33291
http://www.microsoft.com/downloads/release.asp?releaseid=33290
HDcopy .img
----NTFS
NTFS C NTFS
NTFS FAT32 FAT
NTFS, FAT32,"" NTFS
convert.exe "convert c: /fs:ntfs" c
NTFS
NTFS Windows XP Windows 2000
NTFS
pccat a.txt, whislter
whistler a.txt NTFS
NTFS
FAT32 FAT16
2G 2G 2G
EFS EFS EFS
2G
WindowsNT 9x NT4.0 2000xp,98me NT,9x
Windows XP
XP
XP 5080 XP
XP XP
XP
C
XP
DOS SMARTDRV.EXE
CONFIG.SYS HIMEM.SYS SMARTDRV 815
SMARTDRV
Windows
Windows2000
FATFAT32NTFS
NTFS NTFS
NTFS XP
Windows XP
Windows XP
STOP 0x000000ED UNMOUNTABLE_BOOT_VOLUME
BIOS
3. (BIOS) UDMA
80 UDMA 40
UDMA IDE
XP C NT
RESET XP
XP
Windows
XP DOS
XP
XP
XP XP
XP
Windows XP
USB i815
XP
2 3 XP
CMOS
1999 XP
XP
XP
Windows
XP C
XP
XP
XP
-->-->-->
2
Windows XP
Windows XP
Windows XP
Regedit.exe
4
3.5 1 2 3 4
Windows XP
5
Windows XP
Microsoft Word
7 Windows XP
Windows XP
8 Ghost
Ghost DiskPartition
Local 3 Disk
Partition Check
LocalPartitionTo Image
TAB
GHO
3 No Fast
High Yes
Ghost GHO
LocalDiskTo Disk
Ghost Yes
Ghost
Ghost
LocalDiskTo Image
Win XP
1
zipfldr.dll
: regsvr32 /u zipfldr.dll
:chkntfs /t:0
3, XP
:sfc.exe /purgecache
4: services.msc XP
CSDN
http://blog.csdn.net/ajinn/archive/2006/08/14/1062537.aspx
XP
XP ms
V4V5V6
V5 V6
XP MS
XP
sysrep
XP
1 XP
:sfc.exe /purgecache 3xxM
3 help %windows%help
4xM
4%windows%$NtUninstallQ311889$
1x-3xM
5 win2000/server pagefile.sys :
""
6:%windows%infsysoc.inf/
,hide,hide "-"
"/ Windows ";
8 NTFS 2x%
9
""""""""
10 :(
50M
1.4G XP 800
WinXP ms
2
regedit
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSession
ManagerMemoryManagementPrefetchParameters EnablePrefetcher "1"
none()
3
win2000
XP ""
5 XP Qos
: gpedit.msc "" "
""" "QoS " ""
""""""
"QoS PacketScheduler(QoS
)" Qos ()
WindowsXP
30 Regedit
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerRemoteComputerNameSpac
e{D6277990-4C6A-11CF-87-00AA0060F5BF}
Windows XP hoho~~~ !
7 Dr. Watson
win95 :
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionAeDebug
Auto "" 0 F5
memory.dmp
"" 8
1)alerter
4)clipbook
5)Computer browser
6)DHCP client
9)DNS Client
11)Event Log
16)Indexing service ?
22)Net Logon !
24)Network DDE
34)remote registry
35)removable storage
44)Telephony ?
45)telnet
46)terminal services
49)upload manager
51)webclient
55)windows time
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServiceslanmanserverparameters]
"AutoShareServer"=dword:00000000
"AutoSharewks"=dword:00000000
IPC$
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLsa] "restrictanonymous"=
dword:00000001
.REG
1.../...
[HKEY_LOCAL_MACHINESOFTWAREClassesAllFilesystemObjectsshellex]
[HKEY_LOCAL_MACHINESOFTWAREClassesAllFilesystemObjectsshellex
ContextMenuHandlers]
[HKEY_LOCAL_MACHINESOFTWAREClassesAllFilesystemObjectsshellex
ContextMenuHandlersCopy To]
@="{C2FBB630-2971-11D1-A18C-00C04FD75D13}"
[HKEY_LOCAL_MACHINESOFTWAREClassesAllFilesystemObjectsshellex
ContextMenuHandlersMove To]
@="{C2FBB631-2971-11D1-A18C-00C04FD75D13}"
add.reg
2*** !:>>>
->>>!
3:""
""
4WinXP
:"""""""
""""" OK
5:""""""
"""""""
"
6:HKEY_CURRENT_USERControl PanelDesktop
"AugoEndTasks""1"
7:""""""
""
8"chkntfs/t:0"
ms XP
tasklist.exe /svc
Ghost .GHO
Ghost
Winxp Deploy.cab sysprep.exe
sysprep.exe""""
Ghost Ghost
.GHO !
XP
CSDN
http://blog.csdn.net/scmzhx/archive/2009/10/11/4618200.aspx
WinXP
WinXP
1
2
3
4
1 XP
sfc.exe /purgecache 3xxM
3 help %windows%help
4xM
4%windows% $NtUninstallQ311889 $
1x-3xM
5 win2000/server pagefile.sys
6%windows%infsysoc.inf/
,hide,hide -
/ Windows
8 NTFS 2x%
10
50M
1.4G XP 800
WinXP ms
2
regedit
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSession ManagerMemory
ManagementPrefetchParameters EnablePrefetcher 1( 3
none
3
win2000
XP
5 XP Qos
gpedit.msc "
"QoS " "
"
"QoS Packet Scheduler
QoS " Qos
6
Windows XP
30 Regedit
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrent
VersionExplorerRemoteComputerNameSpace{D6277990-4C6A-11CF-8D8700AA0060F5BF}Windows XP
hoho~~~
7 Dr. Watson
win95
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionAeDebug
Auto 0 1 F5
memory.dmp
1)alerter
2)automatic updates windows
3)background intelligent transfer service
4)clipbook
5)Computer browser
6)DHCP client
7)Distributed link tracking client M
16)Indexing service
17)Internet Connection Firewall(ICF) ICF
18)IPSEC Services Quack
44)Telephony
45)telnet
46)terminal services
47)uninterruptible power supply UPS
48)universal plug and play device host
49)upload manager
50)volume shadow copy
51)webclient
52)Windows Installer
53)windows image acquisition (WIA)
54)windows management instrumentation driver extensions
55)windows time
56)wireless zero configuration
57)WMI perfromance adapter
IPC $
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLsa]
"restrictanonymous"=dword:00000001
.REG
3721 hosts
127.0.0.1 cnsmin.3721.com
127.0.0.1 www.3721.net
1.../...
[HKEY_LOCAL_MACHINESOFTWAREClassesAllFilesystemObjectsshellex]
[HKEY_LOCAL_MACHINESOFTWAREClassesAllFilesystemObjectsshellexContextMenuHandlers]
[HKEY_LOCAL_MACHINESOFTWAREClassesAllFilesystemObjectsshellexContextMenuHandlersCopy To]
@="{C2FBB630-2971-11D1-A18C-00C04FD75D13}"
[HKEY_LOCAL_MACHINESOFTWAREClassesAllFilesystemObjectsshellexContextMenuHandlersMove To]
@="{C2FBB631-2971-11D1-A18C-00C04FD75D13}"
add.reg
2KAO **---->---->
---->--->---->>
3
4WinXP
OK
5
6HKEY_CURRENT_USERControl PanelDesktop
AutoEndTasks1 ( 0
7
8chkntfs/t:0
ms XP
tasklist.exe /svc
Ghost .GHO
Ghost
Winxp Deploy.cab sysprep.exe
sysprep.exe
Ghost Ghost
.GHO
XP
CSDN
http://blog.csdn.net/dong1983/archive/2004/11/28/196946.aspx
WinXP Win98
WinXP
XP ms
V4V5V6
V5 V6
XP MS
XP
sysrep
XP come on baby ~~
1 XP
sfc.exe /purgecache 3xxM
3 help %windows%help
4xM
4%windows%$NtUninstallQ311889$
1x-3xM
5 win2000/server pagefile.sys
6%windows%infsysoc.inf/
,hide,hide -
/ Windows
8 NTFS 2x%
10
50M
1.4G XP 800
WinXP ms
2
regedit
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSession ManagerMemory
ManagementPrefetchParameters EnablePrefetcher 1
none
3
win2000
XP
5 XP Qos
gpedit.msc
" "QoS " "
"
"QoS Packet Scheduler
Windows XP
30 Regedit
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrent
VersionExplorerRemoteComputerNameSpace D6277990-4C6A-11CF-8D8700AA0060F5BF{}Windows XP
hoho~~~
7 Dr. Watson
win95
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionAeDebug
Auto 0 F5
memory.dmp
1)alerter
4)clipbook
5)Computer browser
6)DHCP client
9)DNS Client
11)Event Log
16)Indexing service
22)Net Logon
24)Network DDE
34)remote registry
35)removable storage
38)smart card
44)Telephony
45)telnet
46)terminal services
49)upload manager
51)webclient
52)Windows Installer
55)windows time
IPC
Windows XP IPC
IPC
IPC
HKEY_LOCAL_MACHINESYSTEMCurrentControlSet Services
LanmanServerParameters
AutoShareServerREG_DWORD0
AutoShareWksREG_DWORD0
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLsa]
"restrictanonymous"=dword:00000001
.REG
3721 hosts
127.0.0.1 cnsmin.3721.com
127.0.0.1 www.3721.net
1.../...
[HKEY_LOCAL_MACHINESOFTWAREClassesAllFilesystemObjectsshellex]
[HKEY_LOCAL_MACHINESOFTWAREClassesAllFilesystemObjectsshellexContextMenuHandlers]
[HKEY_LOCAL_MACHINESOFTWAREClassesAllFilesystemObjectsshellexContextMenuHandlersCopy To]
@="C2FBB630-2971-11D1-A18C-00C04FD75D13{}"
[HKEY_LOCAL_MACHINESOFTWAREClassesAllFilesystemObjectsshellexContextMenuHandlersMove
To]
@="C2FBB631-2971-11D1-A18C-00C04FD75D13{}"
add.reg
2KAO ---->--->---->--->---->>
4WinXP
OK
6HKEY_CURRENT_USERControl PanelDesktop
AugoEndTasks1
8chkntfs/t:0
ms XP
tasklist.exe /svc
Ghost .GHO
Ghost
Winxp Deploy.cab sysprep.exe
sysprep.exe
Ghost Ghost
.GHO
XP
CSDN http://blog.csdn.net/aupha/archive/2004/07/27/53731.aspx