| 引用: |
【怀安LEDA電腦的贴子】用超级巡警的熊猫专杀1.6可以完全稿定的。 ……………… |
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<avptask><C:\WINDOWS\System32\rund1132.exe> [N/A]
<4><C:\WINDOWS\winlog0n.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<cmdbcs><C:\WINDOWS\zaq10.exe> [N/A]
<wsvbs><C:\WINDOWS\zaq4.exe> [N/A]
<msccr><C:\WINDOWS\zaq2.exe> [N/A]
<upxdn><C:\DOCUME~1\tangwei\LOCALS~1\Temp\upxdn.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{B8A170A8-7AD3-4678-B2FE-F2D7381CC1B5}><C:\Program Files\Internet Explorer\Connection Wizard\isignup.sys> [N/A]
[Network System / NetSystem][Running/Auto Start]
<C:\WINDOWS\System32\NetSystem.exe><Microsoft Corporation>
[Win32 Display Driver / Win32DDS][Stopped/Auto Start]
<C:\WINDOWS\System32\\rundll32.exe windds32.dll,input><Microsoft Corporation>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\System32\\rundll32.exe windhcp.ocx,input><Microsoft Corporation>
[New0 / New0][Running/Auto Start]
<\??\C:\WINDOWS\System32\new.sys><N/A>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
<System32\DRIVERS\npf.sys><CACE Technologies>
[PID: 1268][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)][C:\WINDOWS\System32\msccr.dll] [N/A, N/A]
[C:\WINDOWS\System32\cmdbcs.dll] [N/A, N/A]
[C:\WINDOWS\System32\wsvbs.dll] [N/A, N/A]
[C:\WINDOWS\System32\LgSyl.dll] [N/A, N/A]
[C:\WINDOWS\System32\windds32.dll] [N/A, N/A]
[C:\WINDOWS\System32\windhcp.ocx] [N/A, N/A]
[PID: 1620][C:\WINDOWS\VM_STI.EXE] [VM., 4.2.610.4]
[C:\Program Files\Internet Explorer\Connection Wizard\isignup.sys] [N/A, N/A]
[C:\WINDOWS\System32\msdmo.dll] [N/A, N/A]
[PID: 1744][C:\WINDOWS\System32\rund1132.exe] [N/A, N/A]
[PID: 1752][C:\WINDOWS\winlog0n.exe] [N/A, N/A]
[C:\WINDOWS\System32\LgSyl.dll] [N/A, N/A]
[PID: 880][F:\sreng23\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\Program Files\Internet Explorer\Connection Wizard\isignup.sys] [N/A, N/A]
[C:\WINDOWS\System32\LgSyl.dll] [N/A, N/A]
Autorun.inf
[D:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
[E:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
[F:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
[G:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
所有这些————一个超级巡警就能搞掂?痴人说梦!!