|
本帖最后由 martin313 于 2025-7-18 18:37 编辑
\Windows\System32\HealthAttestationClient
\Windows\System32\hmkd.dll
\Windows\System32\ieframe.dll
--------------------------------------------
call RegCopy "HKLM\System\ControlSet001\CI"
call RegCopy "HKLM\System\ControlSet001\Control\BackupRestore\FilesNotToBackup"
call RegCopy "HKLM\System\ControlSet001\Control\BackupRestore\FilesNotToSnapshot"
call RegCopy "HKLM\System\ControlSet001\Control\CI\Policy"
call RegCopy "HKLM\System\ControlSet001\Control\CI\Protected"
call RegCopy "HKLM\System\ControlSet001\Control\Cryptography\Providers\Microsoft Platform Crypto Provider"
call RegCopy "HKLM\System\ControlSet001\Control\FeatureManagement\EnterpriseTempControls"
call RegCopy "HKLM\System\ControlSet001\Control\GraphicsDrivers"
call RegCopy "HKLM\System\ControlSet001\Control\Ubpm"
call RegCopy "HKLM\System\ControlSet001\Control\WMI\Autologger\EventLog-Application\{3f471139-acb7-4a01-b7a7-ff5da4ba2d43}"
call RegCopy "HKLM\System\ControlSet001\Control\WMI\Autologger\EventLog-Application\{595f33ea-d4af-4f4d-b4dd-9dacdd17fc6e}"
call RegCopy "HKLM\System\ControlSet001\Control\WMI\Autologger\EventLog-Application\{7e58e69a-e361-4f06-b880-ad2f4b64c944}"
call RegCopy "HKLM\System\ControlSet001\Control\WMI\Autologger\EventLog-Application\{8127f6d4-59f9-4abf-8952-3e3a02073d5f}"
call RegCopy "HKLM\System\ControlSet001\Control\WMI\Autologger\EventLog-Application\{85fe7609-ff4a-48e9-9d50-12918e43e1da}"
call RegCopy "HKLM\System\ControlSet001\Control\WMI\Autologger\EventLog-Application\{88c09888-118d-48fc-8863-e1c6d39ca4df}"
call RegCopy "HKLM\System\ControlSet001\Control\WMI\Autologger\EventLog-Application\{9580d7dd-0379-4658-9870-d5be7d52d6de}"
call RegCopy "HKLM\System\ControlSet001\Control\WMI\Autologger\EventLog-Application\{a83fa99f-c356-4ded-9fd6-5a5eb8546d68}"
call RegCopy "HKLM\System\ControlSet001\Control\WMI\Autologger\EventLog-Application\{ba723d81-0d0c-4f1e-80c8-54740f508ddf}"
call RegCopy "HKLM\System\ControlSet001\Control\WMI\Autologger\EventLog-Application\{f8ad09ba-419c-5134-1750-270f4d0fb889}"
call RegCopy "HKLM\System\ControlSet001\Control\WMI\Autologger\EventLog-System\{3f471139-acb7-4a01-b7a7-ff5da4ba2d43}"
call RegCopy "HKLM\System\ControlSet001\Control\WMI\Autologger\EventLog-System\{945a8954-c147-4acd-923f-40c45405a658}"
call RegCopy "HKLM\System\ControlSet001\Control\WMI\Autologger\EventLog-System\{9580d7dd-0379-4658-9870-d5be7d52d6de}"
call RegCopy "HKLM\System\ControlSet001\Control\WMI\Autologger\WiFiDriverIHVSession"
call RegCopy "HKLM\System\ControlSet001\Control\WMI\Autologger\WiFiDriverIHVSessionRepro"
call RegCopy "HKLM\System\ControlSet001\Control\WMI\Security"
call RegCopy "HKLM\System\ControlSet001\Services\BITS"
call RegCopy "HKLM\System\ControlSet001\Services\EventLog\Application\DeliveryOptimization"
call RegCopy "HKLM\System\ControlSet001\Services\EventLog\System\MSiSCSI"
call RegCopy "HKLM\System\ControlSet001\Services\UsoSvc"
call RegCopy "HKLM\System\Setup\SETUPCL"
call RegCopy "HKLM\System\Setup\WindowsUpdate"
|
|