昨天,别人用我的机器,不知道安装了什么软件,增加了一个服务,文件名字叫SVCHOSI.EXE。
这是服务调用的dll文件列表:
名称 描述 公司名称 版本
advapi32.dll Advanced Windows 32 Base API Microsoft Corporation 5.01.2600.2180
avicap32.dll AVI Capture window class Microsoft Corporation 5.01.2600.0000
c_1252.nls
comctl32.dll Common Controls Library Microsoft Corporation 5.82.2900.2180
comctl32.dll User Experience Controls Library Microsoft Corporation 6.00.2900.2180
crypt32.dll Crypto API32 Microsoft Corporation 5.131.2600.218
ctype.nls
dnsapi.dll DNS Client API DLL Microsoft Corporation 5.01.2600.2180
gdi32.dll GDI Client DLL Microsoft Corporation 5.01.2600.2818
imm32.dll Windows XP IMM32 API Client DLL Microsoft Corporation 5.01.2600.2180
index.dat
index.dat
index.dat
iphlpapi.dll IP Helper API Microsoft Corporation 5.01.2600.2180
kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 5.01.2600.2180
locale.nls
lpk.dll Language Pack Microsoft Corporation 5.01.2600.2180
mpr.dll Multiple Provider Router DLL Microsoft Corporation 5.01.2600.2180
msasn1.dll ASN.1 Runtime APIs Microsoft Corporation 5.01.2600.2180
MSCTFIME.IME Microsoft Text Frame Work Service IME Microsoft Corporation 5.01.2600.2180
msv1_0.dll Microsoft Authentication Package v1.0 Microsoft Corporation 5.01.2600.2180
msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.2600.2180
msvfw32.dll Microsoft Video for Windows DLL Microsoft Corporation 5.01.2600.2180
mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 5.01.2600.2180
netapi32.dll Net Win32 API DLL Microsoft Corporation 5.01.2600.2180
ntdll.dll NT Layer DLL Microsoft Corporation 5.01.2600.2180
ole32.dll Microsoft OLE for Windows Microsoft Corporation 5.01.2600.2726
oleaut32.dll Microsoft Corporation 5.01.2600.2180
rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 5.01.2600.2180
rasapi32.dll Remote Access API Microsoft Corporation 5.01.2600.2180
rasman.dll Remote Access Connection Manager Microsoft Corporation 5.01.2600.2180
rpcrt4.dll Remote Procedure Call Runtime Microsoft Corporation 5.01.2600.2180
rtutils.dll Routing Utilities Microsoft Corporation 5.01.2600.2180
secur32.dll Security Support Provider Interface Microsoft Corporation 5.01.2600.2180
sensapi.dll SENS Connectivity API DLL Microsoft Corporation 5.01.2600.2180
shell32.dll Windows Shell Common Dll Microsoft Corporation 6.00.2900.2763
shlwapi.dll Shell Light-weight Utility Library Microsoft Corporation 6.00.2900.2781
sortkey.nls
sorttbls.nls
SVCHOSI.EXE
tapi32.dll Microsoft(R) Windows(TM) Telephony API Client DLL Microsoft Corporation 5.01.2600.2180
unicode.nls
urlmon.dll OLE32 Extensions for Win32 Microsoft Corporation 6.00.2900.2790
user32.dll Windows XP USER API Client DLL Microsoft Corporation 5.01.2600.2622
usp10.dll Uniscribe Unicode script processor Microsoft Corporation 1.420.2600.218
uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.00.2900.2180
version.dll Version Checking and File Installation Libraries Microsoft Corporation 5.01.2600.2180
wininet.dll Internet Extensions for Win32 Microsoft Corporation 6.00.2900.2781
winmm.dll MCI API DLL Microsoft Corporation 5.01.2600.2180
winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 5.01.2600.2180
wldap32.dll Win32 LDAP API DLL Microsoft Corporation 5.01.2600.2180
ws2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 5.01.2600.2180
ws2help.dll Windows Socket 2.0 Helper for Windows NT Microsoft Corporation 5.01.2600.2180
wsock32.dll Windows Socket 32-Bit DLL Microsoft Corporation 5.01.2600.2180
这是句柄:
类型 名称
Desktop \Default
Directory \Windows
Directory \BaseNamed
Objects
Directory \KnownDlls
Event \BaseNamed
Objects\crypt32LogoffEvent
Event \BaseNamed
Objects\DINPUTWINMM
File \Device\Tcp
File \Device\Tcp
File \Device\Ip
File \Device\Ip
File \Device\Ip
File \Device\Tcp
File \Device\HarddiskVolume4\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat
File \Device\NetBT_Tcpip_{EE16A716-FD7C-4C92-B19C-D428E1A96252}
File \Device\HarddiskVolume4\Documents and Settings\LocalService\Cookies\index.dat
File \Device\HarddiskVolume4\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat
File \Device\HarddiskVolume4\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a...
File \Device\NamedPipe\ROUTER
File \Device\NamedPipe\ROUTER
File \Device\KsecDD
File \Device\HarddiskVolume4\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a...
File \Device\HarddiskVolume4\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a...
File \Device\HarddiskVolume4\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a...
File \Device\HarddiskVolume4\WINDOWS\system32
File \Device\NamedPipe\net\NtControlPipe16
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Linkage
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters
Key HKLM\SYSTEM\ControlSet001\Services\NetBT\Parameters\Interfaces
Key HKLM\SYSTEM\ControlSet001\Services\NetBT\Parameters
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKLM\SOFTWARE\Microsoft\Tracing\RASAPI32
Key HKU
Key HKU\.DEFAULT
Key HKLM\SYSTEM\ControlSet001\Hardware Profiles\0001
Key HKLM
Key HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder
Key HKU\.DEFAULT
Key HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings