内容劫持项HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
+ Your Image File Name Here without a path Symbolic Debugger for Windows 2000 Microsoft Corporation C:\WINDOWS\system32\NTSD.EXE
附件:
896328200779163624.txt