1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73
|
#include <tchar.h>
#include <Windows.h>
#include <stdio.h>
#include <malloc.h>
int main()
{
//HKEY hKey = HKEY_USERS;
//wchar_t * lpSubKey = L"S-1-5-21-1421355107-4124689249-2030404034-1473129\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ComDlg32\\CIDSizeMRU";
//wchar_t * lpValueName = L"29";
wchar_t * lpSubKey = L"SOFTWARE\\test";
HKEY hKey = HKEY_LOCAL_MACHINE;
wchar_t * lpValueName = L"cletest";
BYTE* lpData = NULL;
HKEY phkResult;
DWORD dwSize;
DWORD dwType;
long lResult = RegOpenKeyExW(hKey, lpSubKey, 0, KEY_READ, &phkResult);
wprintf(L"[?] Tentative d\'ouverture de cl\x82 :\n");
wprintf(L"[?] Nom de la Cl\x82 : %ls\n", lpValueName);
wprintf(L"[?] Chemin de la cl\x82 : %ls\n\n", lpSubKey);
wprintf(L"[?] Code Retour de l\'ouverture de cl\x82 RegOpenKeyExW : %ld \n\n",lResult);
if (lResult == 0)
{
wprintf(L"[?] Cl\x82 ouverte.\n");
wprintf(L"[?] Calcul de dwSize et dwType\n");
lResult = RegQueryValueExW(phkResult, lpValueName, NULL,&dwType,NULL,&dwSize);
wprintf(L"[?] Code Retour du Calcul de dwSize et dwType: %ld \n\n",lResult);
lpData = (BYTE*) malloc(dwSize) ;
wprintf(L"\t dwType : %ld \n",dwType);
wprintf(L"\t dwSize : %ld \n",dwType);
wprintf(L"\t dwSize : %ld \n\n",lpData);
if(dwType == REG_DWORD)
{
wprintf(L"[?] La cl\x82 est de type REG_DWORD.\n");
wprintf(L"[?] Calcul de lpData\n");
lResult = RegQueryValueExW(phkResult, lpValueName, NULL,&dwType,(BYTE*)&lpData,&dwSize);
wprintf(L"[?] Code Retour du Calcul de lpData: %ld \n\n",lResult);
wprintf(L"[?] valeur de la cl\x82 %s: %ld \n",lpValueName ,lpData);
}
else if(dwType == REG_SZ)
{
wprintf(L"[?] La cl\x82 est de type REG_SZ.\n");
wprintf(L"[?] Calcul de lpData\n");
lResult = RegQueryValueExW(phkResult, lpValueName, NULL,&dwType,(BYTE*)&lpData,&dwSize);
wprintf(L"[?] Code Retour du Calcul de lpData: %ld \n\n",lResult);
wprintf(L"[?] valeur de la cl\x82 %s: %ld \n",lpValueName ,lpData);
}
else if(dwType == REG_BINARY)
{
wprintf(L"[?] La cl\x82 est de type REG_BINARY.\n");
wprintf(L"[?] Calcul de lpData\n");
lResult = RegQueryValueExW(phkResult, lpValueName, NULL,&dwType,(BYTE*)&lpData,&dwSize);
wprintf(L"[?] Code Retour du Calcul de lpData: %ld \n\n",lResult);
wprintf(L"[?] valeur de la cl\x82 %s: %ls \n",lpValueName ,lpData);
}
else
wprintf(L"[?] La cl\x82 est de type %ld.\n,dwType");
}
else
{
wprintf(L"[?] Cl\x82 non ouverte.\n");
}
//system("pause");
free(lpData);
wprintf(L"\nFermeture de la Cl\x82.\n");
RegCloseKey(hKey);
return 0;
} |
Partager