SpiritOfVite
02-11-2006, 17:19
Ich habe das reine Setup der Tages Treiber mal unter die Lupe genommen, was bei rausgekommen ist, kann unten betrachtet werden:
; Legende:
; [-]= Gelöschter Schlüssel/Dir, [+]= Neuer Schlüssel/Dir, [#]= Inhalte dieses Schlüssels/Dir geändert
; [-]= Gelöschter Wert/Datei, [+]= Neuer Wert/Datei
; [%]= Geänderter Wert (alter Wert/Datei), = Geänderter Wert (neuer Wert/Datei)
;
[#][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography \RNG]
[%]"Seed"=hex(3):2E,6C,48,8F,38,33,00,A4,38,EC,EF,EE,CB,5C, 37,85,E1,C0,0F,D9,EF,\
D1,78,AA,B9,9E,34,05,EF,8F,B7,05,D6,26,96,56,1C,0C ,D8,F3,94,FB,65,92,40,68,B7,DB,\
82,7E,DA,15,64,12,9F,9B,14,E3,57,1F,CD,E1,0F,47,79 ,FF,F2,E0,BB,3F,81,57,8D,BB,2B,\
86,B0,C1,99,FE
"Seed"=hex(3):CD,63,CA,A0,EC,40,78,0E,57,C4,E4,21,6E,7D, F3,C7,2F,99,2B,0D,A1,\
23,19,EA,D5,E5,9F,A4,CF,ED,DE,2E,1A,14,95,B8,6A,33 ,36,49,DE,0B,38,61,8D,98,2E,70,\
10,AD,6A,B6,5E,4C,76,8D,B3,FB,49,DF,74,E5,2E,4B,28 ,43,EC,30,C8,AA,73,02,A5,0D,46,\
7B,38,97,9F,2D
[#][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Reliability]
[%]"LastAliveStamp"=hex(3):D6,07,0B,00,04,00,02,00,10,00,0A,00,11,00, 80,02
"LastAliveStamp"=hex(3):D6,07,0B,00,04,00,02,00,10,00,0D,00,11,00, 80,02
[%]"LastAliveUptime" = $0000031E (798)
"LastAliveUptime" = $000003D2 (978)
[#][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\SharedDlls]
[+]"C:\WINDOWS\system32\DRIVERS\atksgt.sys" = $00000001 (1)
[+]"C:\WINDOWS\system32\DRIVERS\lirsgt.sys" = $00000001 (1)
[+][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\R oot\LEGACY_ATKSGT\0000\Control]
[+]"*NewlyCreated*" = $00000000 (0)
[+]"ActiveService" = "atksgt"
[+][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\R oot\LEGACY_ATKSGT\0000]
[+]"Class" = "LegacyDriver"
[+]"ClassGUID" = "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
[+]"ConfigFlags" = $00000000 (0)
[+]"DeviceDesc" = "atksgt"
[+]"Legacy" = $00000001 (1)
[+]"Service" = "atksgt"
[+][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\R oot\LEGACY_ATKSGT]
[+]"NextInstance" = $00000001 (1)
[+][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\atksgt\Enum]
[+]"0" = "Root\LEGACY_ATKSGT\0000"
[+]"Count" = $00000001 (1)
[+]"NextInstance" = $00000001 (1)
[+][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\atksgt\Security]
[+]"Security"=hex(3):01,00,14,80,B8,00,00,00,C4,00,00,00,14,00, 00,00,30,00,00,00,\
02,00,1C,00,01,00,00,00,02,80,14,00,FF,01,0F,00,01 ,01,00,00,00,00,00,01,00,00,00,\
00,02,00,88,00,06,00,00,00,00,00,14,00,FD,01,02,00 ,01,01,00,00,00,00,00,05,12,00,\
00,00,00,00,18,00,FF,01,0F,00,01,02,00,00,00,00,00 ,05,20,00,00,00,20,02,00,00,00,\
00,14,00,8D,01,02,00,01,01,00,00,00,00,00,05,04,00 ,00,00,00,00,14,00,8D,01,02,00,\
01,01,00,00,00,00,00,05,06,00,00,00,00,00,14,00,00 ,01,00,00,01,01,00,00,00,00,00,\
05,0B,00,00,00,00,00,18,00,FD,01,02,00,01,02,00,00 ,00,00,00,05,20,00,00,00,23,02,\
00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00 ,00,00,00,00,05,12,00,00,00
[+][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\atksgt]
[+]"DisplayName" = "atksgt"
[+]"ErrorControl" = $00000001 (1)
[+]"ImagePath"=hex(2):73,79,73,74,65,6D,33,32,5C,44,52,49,56,45, 52,53,5C,61,74,\
6B,73,67,74,2E,73,79,73,00
[+]"Start" = $00000002 (2)
[+]"Type" = $00000001 (1)
[+][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\lirsgt\Enum]
[+]"0" = "Root\LEGACY_LIRSGT\0000"
[+]"Count" = $00000001 (1)
[+]"NextInstance" = $00000001 (1)
[+][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\lirsgt\Security]
[+]"Security"=hex(3):01,00,14,80,B8,00,00,00,C4,00,00,00,14,00, 00,00,30,00,00,00,\
02,00,1C,00,01,00,00,00,02,80,14,00,FF,01,0F,00,01 ,01,00,00,00,00,00,01,00,00,00,\
00,02,00,88,00,06,00,00,00,00,00,14,00,FD,01,02,00 ,01,01,00,00,00,00,00,05,12,00,\
00,00,00,00,18,00,FF,01,0F,00,01,02,00,00,00,00,00 ,05,20,00,00,00,20,02,00,00,00,\
00,14,00,8D,01,02,00,01,01,00,00,00,00,00,05,04,00 ,00,00,00,00,14,00,8D,01,02,00,\
01,01,00,00,00,00,00,05,06,00,00,00,00,00,14,00,00 ,01,00,00,01,01,00,00,00,00,00,\
05,0B,00,00,00,00,00,18,00,FD,01,02,00,01,02,00,00 ,00,00,00,05,20,00,00,00,23,02,\
00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00 ,00,00,00,00,05,12,00,00,00
[+][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\lirsgt]
[+]"DisplayName" = "lirsgt"
[+]"ErrorControl" = $00000001 (1)
[+]"ImagePath"=hex(2):73,79,73,74,65,6D,33,32,5C,44,52,49,56,45, 52,53,5C,6C,69,\
72,73,67,74,2E,73,79,73,00
[+]"Start" = $00000002 (2)
[+]"Type" = $00000001 (1)
vBulletin v3.5.4, Copyright ©2000-2007, Jelsoft Enterprises Ltd.