(1) Run
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Run
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Run
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ Run
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ Run
(2) RunOnce
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ RunOnce
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ RunOnce
(3) RunServicesOnce
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ RunServicesOnce
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ RunServicesOnce
(4) RunServices
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ RunServices
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ RunServices
(5) RunOnceEx
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ RunOnceEx
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ RunOnceEx
(This key is a self-starting registry key unique to Windows XP/2003)
(6) UserInit
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ WindowsNT \ CurrentVersion \ Winlogon \ UserInit
(Valid value: c: \ windows \ system32 \ userinit.exe)
(7) load
HKEY_CURRENT_USER \ Software \ Microsoft \ WindowsNT \ CurrentVersion \ Windows \ load
(8) image hijacking
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ WindowsNT \ CurrentVersion \ Image File Execution Options
(9) prohibit taskbar, Folder Options, registry, etc.
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System \ DisableTaskMgr
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System \ DisableRegedit
(10) forbidden to modify the IE browser Homepage
HKEY_CURRENT_USER \ Software \ policies \ Microsoft \ internet explorer \ control panel \ homepage
If the value is 1, modification is prohibited.
HKEY_CURRENT_USER \ Software \ policies \ Microsoft \ internet explorer \ main \ Startpage
(The above is suitable for win200 2003 xp)
Vista and win7 are set as follows:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Internet Explorer \ MAIN \ Start Page
(11) hiding Disk Partitions
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ NoDrivers
(12) Modifying File Associations
HKEY_CLASSES_ROOT \ textfile \ shell \ open \ command
HKEY_LOCAL_MACHINE \ Software \ CLASSES \ textfile \ shell \ open \ command
(13) SPI
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ WinSock2 \ Parameters \ Protocol_Catalog9 \ Catalog_Entries
(14) BHO
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Browser Helper Objects
This key is the CLSID of all BHO registered by the system.
GUID (Global Unique Identifier) also becomes the CLSID for Class ID
(15) CLSID
HKEY_CLASSES_ROOT \ CLSID \
The ID under this key corresponds to different programs and components in the system.
(16) default IE prefix
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ URL \ defapreprefix
(17)
HKEY_CURRENT_USER \ Software \ policies \ Microsoft \ internet explorer \ MenuExt
Right-click IE webpage menu
HKEY_LOCAL_MACHINE \ Software \ policies \ Microsoft \ internet explorer \ Extension registry key
Items that correspond to buttons on the IE Toolbar or that are not installed by default in the IE tool menu
(18) IE advanced options
HKEY_LOCAL_MACHINE \ Software \ policies \ Microsoft \ internet explorer \ AdvancedOptions
Corresponding to the project under the IE option Advanced Tab
(19) IE Extension
HKEY_LOCAL_MACHINE \ Software \ policies \ Microsoft \ internet explorer \ Plugins
(20) default IE settings
C: \ windows \ inf \ iereset. inf (IE default configuration information)
(21) trusted IE Region
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ InternetSettings \ ZoneMap \ Domains
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ InternetSettings \ ZoneMap \ Domain
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ InternetSettings \ ZoneMap \ Ranges
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ InternetSettings \ ZoneMap \ Ranges
Correspondence between IE authorization region and identifier
Region region ing
My Computer 0
Intranet 1
Trusted 2 Internet 3
Restricted 4
========================================================== ====================================
Correspondence between protocols and authorization regions
HTTP 3
HTTPS 3
FTP 3
@ Vit 1
Shell 0
========================================================== ======================================
Corresponding registry key value:
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ InternetSettings \ ZoneMap \ ProtocolDefaults
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ InternetSettings \ ZoneMap \ ProtocolDefaults
(22) Domain Name Hijacking
HKEY_LOCAL_MACHINE \ System \ CurrentControlSet \ services \ tcpip \ Parameters \ Interfaces \ {0F3EE3DD-D14D-4925-8671-87F4D7244B91} \ NameServer
HKEY_LOCAL_MACHINE \ Software \ Class \ PROTOCOLS
For additional protocol and Protocol hijacking, hackers can achieve this by changing the standard protocol driver used by our computers to the driver provided by the hijacking program.
(23) User style sheet hijacking
Key value:
HKEY_CURRENT_USER \ Software \ Microsoft \ internet explorer \ Style \ User Stylesheets
(24) AppInit_DLLs registry value self-start loading
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ WindowsNT \ CurrentVersion \ Windows \ AppInit_DLLs
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ IniFileMapping \ win. ini \ Windows \ AppInit_DLLs
User32.dll can be used by many processes or programs, including some self-starting processes. The AppInit_DLLs registry value contains a series of dynamic link libraries that will be loaded when user32.dll is loaded.
(25) Winlogon Notify
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ y
(26) ShellServiceObjectDelayLoad
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ ShellServiceObjectDelayLoad
The files under the shellserviceobjectdelayloadkey value will be automatically loaded by the computer shell program assumer.exe.
The key value under ShellServiceObjectDelayLoad points to CLSID.
(26) SharedTaskScheduler
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ sharedtasksched.pdf
Loaded with windows Startup
(26) Service
Programs automatically loaded when windows is started during service. These programs are loaded no matter whether a user logs on to a computer or not, and are often used to process system tasks.
Delete a service
1. Command Line command SC dete servername
2. Delete the Registry
Windows Registry Editor Version 5.00
[-......] Save it as the reg file and import it to the Registry to delete it.
Delete key value
[......]
"Key Value Name" =-
Import
3. Related Service deletion tools
(27) IE favorites, IE browsing history, cookies
HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ User Shell Folders
(28) do not share C $, D $, ADMIN $ by default.
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ lanmanserver \ parameters, create a Dword Value in the window on the right, and set the name
Set AutoShareServer to 0
Create a Dword Value autoscaling wks 0 (xp win7 vista)
[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ lanmanserver \ parameters] "AutoShareServer" = dword: 00000000 "autosharwks" = dword: 00000000 // AutoShareWks for pro version // AutoShareServer for server version // 0
Do not share admin $, c $, d $, or other resources by default.
[HKEY_LOCAL_MACHINE \ System \ CurrentControlSet \ Control \ LSA] "restrictanonymous" = dword: 00000001 // 0x1 anonymous users cannot list native users/0x2 anonymous users cannot connect to native IPC $ share (maybe SQL server cannot start
(29) hide important files/Directories
You can modify the Registry to hide it completely: "HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Fol der \ Hi-ddenSHOWALL", right-click "CheckedValue", and select modify, change the value from 1 to 0.
(30) Prevent SYN flood attacks
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters create a DWORD Value named SynAttackProtect and the value is 2
(31) disabling response to ICMP route notification packets
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters \ Interfacesinterface creates a DWORD value, and the value of "descrimrouterdiscovery" is 0.
(32) Prevent ICMP redirection packet attacks
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters set EnableICMPRedirects to 0
(33) IGMP protocol not supported
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTcpipParameters create a DWORD Value named IGMPLevel with a value of 0
(34) The default port of the terminal service is 3389. You can change it to another port.
Modify to: Server: Open the registry, find a RDP-TCP-like subkey at HKLM \ SYSTEM \ Current ControlSet \ Control \ Terminal Server \ Win Stations, and modify the PortNumber value. Client: follow the normal steps to create a client connection, select this connection, and select export from the "file" menu. A file with the extension of. cns will be generated at the specified position. Open the file and change the "Server Port" value to the value corresponding to the PortNumber on the Server. Then import the file (method: menu> File> Import), so that the client modifies the port.
(35) modify the default log storage location of the system
HKEY_LOCAL_MACHINE \ System \ CurrentControlSet \ Services \ Eventlog
Log File Size Limit
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Eventlog \ ***** \ MaxSize
Change log storage location
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Eventlog \ ***** \ File
(36) Schedluler (Task Scheduler) Service
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ SchedulingAgent
(37) prohibit NULL connections (restrictions on anonymous connections ):
[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Lsa \ restrictanonymous set to 1
(38) Enable the wins agent on the wins Client
HKEY_LOCAL_MACHINE \ System \ CurrentControlSet \ Services \ NetBT \ Parameters
EnableProxy DWORD
(39)
HKEY_CURRENT_USER \ Software \ Microsoft \ office \
Microsoft Office software-related options
(40) tcp semi-connections
HKEY_LOCAL_MACHINE \ System \ CurrentControlSet \ Services \ Tcpip \ Parameters \ TcpMaxHalfOpenRetried
--- Defines the size of TCP semi-connections (applicable to win2000 systems)
HKEY_LOCAL_MACHINESYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters \ EnableConnectionRateLimiting
If the value of EnableConnectionRateLimiting does not exist, it indicates that your system has no TCP/IP connection restrictions. If the value is 0, it indicates that your system has no TCP/IP ip.
Connection restriction. If the value is 1, it indicates that the connection is restricted by TCP/IP connections. If the value is changed to 0, the restriction can be canceled. (Applicable to vista sp2 and win7)
(4
1) TCP connection Delay
HKEY_LOCAL_MACHINESYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters \ TcpTimedWaitDelay
TcpTimedWaitDelay is 1e (30 seconds) by default (win7 and 2008)
(42) Maximum port used by tcp users
HKEY_LOCAL_MACHINESYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters \ MaxUserPort
(43) disable the check of invalid gateways
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters \ EnableDeadGWDetect "= dword: 00000000
(2000, xp)
(44) NETBIOS names cannot be released
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters \ "NonameReleaseOnDemand" = dword: 00000001
(2000sp2, xp)
(45) Prohibit Access logs from the Guest account
HKEY_LOCAL_MACHINE \ System \ CurrentControlSet \ Services \ Eventlog \
Change the value of RestrictGuestAccess under the three sub-keys Application, Security, and System to 1.
(46) do not display the user name for the last login
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ winlogon
Change Dontdisplaylastusername to 1
(47) Disable File Name Creation
Remove the performance loss caused by compatibility with the naming method of Microsoft File names for windows Server and windows Server
HKEY_LOCAL_MACHINE \ System \ CurrentControlSet \ Control \ FileSystem \
Set NtfsDisable8dot3NameCreation to 1
Of course, there are other settings on the file system under this key item, such as encryption or extension.
(48) potential risks caused by using program subsystems such as DOS, Win16, 0 S/2, and Posix Application Systems
HKEY_LOCAL_MACHINE \ System \ CurrentControlSet \ Control \ Session Manager \ SubSystems
Change Optional to 0000
Delete OS2 and posix items
At the same time, find HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ WOW to delete the subkey under it.
Locate HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Session Manager \ Environment
Delete the OS2libpath entry under it
Locate HKEY_LOCAL_MACHINE \ software \ Microsoft \ OS/2 Subsystem for nt and delete all its subkeys.
(49) IGMP protocol not supported
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters \
Change IGMPLevel to 0 (50) and modify the default port of the terminal service.
Find HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Terminal Server \ Wds \ rdpwd \ Tds \ tcp
Change PortNumber to the changed Value
Locate HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Terminal Server \ WinStations \ RDP-Tcp
Remember to change the PortNumber to the same value as above
(50) The protection system is not subject to certain denial-of-service attacks.
Prevent SYN flood attacks
Find HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters \
Add
DWORD Value
SynAttackProtect is 2
Tcpmaxhalfopen is 100
The value of Tcpmaxhalfopenedretried is 80.
Tcpmaxportsexhausted is 5
(51) strengthen defense against DoS Attacks
Terminate the half-open TCP connections, and find HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters \
The condition DWORD Tcpmaxconnectresponseretransmission is 3.
(52) tcp null link Timer
Find HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters \
Add DWORD Keepalivetime to 300000, in milliseconds, that is, 5 minutes
(53) do not change the MTU value easily
Find HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters \
Set DWORD: EnablePMTUDiscovery to 0
(54) Disable IP routing
Find HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Tcpip \ Parameters \
Modify DWORD: IPEnableRouter to 0
(55) Disable Automatic startup of the CD
[HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ CurrentVersion \ elastes \ Explorer
Set Nodrivetypeautorun to 149
(56) only local users can access a floppy disk.
Find HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon
Modify allocatefloppyes to 1
(57) only local users are allowed to access the CD
Find HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon
Modify AllocateCDRoms to 1
(58) Clear page files when Shutdown
Find HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Session Manager \ Memory Management
Modify DWORD: ClearPageFileAtShutdown to 1
(59) HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Seting \ MaxConnectionPerServer ===== IE connections to each service
(60)
The system module is completely forbidden.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ MyComputer \ NameSpace \ DelegateFolders \ {59031a47-3f72-44a7-89c5-5595fe6b30ee}]
(61)
3389 replace service -----------------------
Modify [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ TermService]
C: \ winnt \ system32 \ copy termsrv.exe service.exe
C: \ winnt \ system32 \ cd ..
C: \ winnt \ SC \ 127.0.0.1 config Alerter binpath = c: \ winnt \ system32 \ service.exe
(62 ),
Currently, many optimization software have the "installed software check" and "uninstall software" functions, which are more powerful than the "add or delete programs" function provided by Windows, in fact, the following registry items are scanned. Interested users can study them separately.
HKEY_CLASSES_ROOT \ Installer \ Products
HKEY_CURRENT_USER \ Software \ Microsoft \ Installer \ Products
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uninstall
(63 ),
Make Registry Editor fail: Find
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Applets \ Regedit
Right-click Regedit, select permission> Administrator, select "deny", and click "OK.
(64 ),
Windows File Protection
-Description
Path: SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon: SFCDisable
Windows File Protection
-Current exception
The registry key value is empty.
-Normal
Registry Key Value: 00000000
(65) Security Center
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Security Center
(66) Right-click Extension
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Shell Extensions