12   2  /  2  页   跳转

========Title========

用冰刃也找不那几个东东
gototop
 

一、有问题的注册表项目
==================================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<DbgHlp32><C:\WINNT\DbgHlp32.exe> []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<MSDCG32 ><LYLeador.exe> [N/A]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><avwlamn.dll> []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{1859245F-345D-BC13-AC4F-145D47DA34F1}><C:\WINNT\system32\avzxamn.dll> []
<{12FAACDE-34DA-CCD4-AB4D-DA34485A3421}><C:\WINNT\system32\rsjzapm.dll> []
<{1960356A-458E-DE24-BD50-268F589A56A1}><C:\WINNT\system32\avwlamn.dll> []
==================================
驱动程序
[leljrj / leljrj][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\leljrj.sys><N/A>
[mssock / mssock][Stopped/Manual Start]
<\??\C:\WINNT\system32\mssock.sys><N/A>
[Netgroup Packet Filter / NPF][Running/Manual Start]
<system32\DRIVERS\npf.sys><CACE Technologies>
===================================
文件关联
.CHM Error. ["hh.exe" %1]
.HLP Error. [winhlp32.exe %1]
==================================
Winsock 提供者
MSAPI Tcpip [TCP/IP]
C:\WINNT\system32\mscomm.dll(, N/A)
MSAPI Tcpip [UDP/IP]
C:\WINNT\system32\mscomm.dll(, N/A)


二、可疑和有问题的文件(红色可疑):
==================================
[C:\WINNT\system32\PA207Usd.dll] [, 1, 0, 0, 0]
[C:\Program Files\Common Files\SyInfo.bps] [N/A, ]
[C:\DOCUME~1\maxezu\LOCALS~1\Temp\sysldy.exe]
[C:\DOCUME~1\maxezu\LOCALS~1\Temp\packet.dll]
[C:\DOCUME~1\maxezu\LOCALS~1\Temp\WanPacket.dll]

[C:\Program Files\NetMeeting\avpwm.dat] [N/A, ]
[C:\Program Files\NetMeeting\avpqj.dat] [N/A, ]
[C:\WINNT\system32\avzxamn.dll] [N/A, ]
[C:\WINNT\system32\avwlamn.dll] [N/A, ]
[C:\Program Files\NetMeeting\avpqj.dat] [N/A, ]
[C:\Program Files\NetMeeting\ravdhmon.dat] [N/A, ]
[C:\Program Files\NetMeeting\ravgjmon.dat] [N/A, ]
[C:\Program Files\NetMeeting\ravztmon.dat] [N/A, ]
[C:\WINNT\system32\rsjzapm.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, ]
[C:\WINNT\system32\lhpwhd.dll] [N/A, ]
[C:\WINNT\system32\srjltl.dll] [N/A, ]
[C:\WINNT\kulionrx.dll] [N/A, ]
[C:\WINNT\system32\mscomm.dll] [N/A, ]
C:\WINNT\system32\LYLeador.exe
C:\WINNT\system32\mssock.sys
C:\WINNT\System32\drivers\leljrj.sys
C:\WINNT\system32\DRIVERS\npf.sys
C:\WINNT\DbgHlp32.exe
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT