C:\Documents and Settings\All Users\Application Data\Tencent\TSVulFw\TSVulFW.DAT
这个正常情况下是TT浏览器的DD,基本可以排除:
[PID: 3164 / Administrator][C:\Program Files\Tencent\QQ\Bin\QQ.exe] [Tencent, 1, 50, 1720, 0]
………………………………………………
[C:\Documents and Settings\All Users\Application Data\Tencent\TSVulFw\TSVulFW.DAT] [Tencent, 2011.1.12.1]