|
本帖最后由 2010hook 于 2021-10-18 15:19 编辑
Reg2Cmd 转换 hex(b) REG_QWORD 错误,本该是little-endian,倒叙复写原本数值,并把开头改成0x形式即可。
For example, the value 0x12345678 is stored as (78 56 34 12) in little-endian format.
NT6x 系统 IFEO 可找到实例:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe]
"MitigationOptions"=hex(b):00,01,00,00,00,00,00,00
|
|