3、索性关闭所有安全软件,再次重启,看看它到底有多厉害。
再次重启后,SREng日志显示————连Tiny的进程都没幸免:
服务
[winlogon server / winlogon server]
<c:\windows\system\winlogon><N/A>
进程
[PID: 1696][C:\Program Files\Tiny Firewall Pro\UmxAgent.exe] <Computer Associates International, Inc.><6.0.1.76>
[C:\windows\TEMP\9ojhp8r.dll] <N/A><N/A>
[PID: 1712][C:\Program Files\Tiny Firewall Pro\UmxTray.exe] <Computer Associates International, Inc.><6.5.1.59>
[c:\windows\system\winlKey.DLL] <N/A><N/A>
[C:\windows\TEMP\9ojhp8r.dll] <N/A><N/A>
[C:\DOCUME~1\baohelin\LOCALS~1\Temp\9ojhp8r.dll] <N/A><N/A>
[PID: 1816][C:\windows\System32\Ati2evxx.exe] <N/A><N/A>
[c:\windows\system\winlKey.DLL] <N/A><N/A>
[C:\windows\TEMP\9ojhp8r.dll] <N/A><N/A>
[PID: 2000][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE] <Microsoft Corporation><7.00.9466>
[c:\windows\system\winlKey.DLL] <N/A><N/A>
[C:\windows\TEMP\9ojhp8r.dll] <N/A><N/A>
[C:\windows\system32\UmxSbxw.dll] <Computer Associates International, Inc.><6.0.1.58>
[PID: 688][C:\windows\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[c:\windows\system\winlKey.DLL] <N/A><N/A>
[C:\DOCUME~1\baohelin\LOCALS~1\Temp\9ojhp8r.dll] <N/A><N/A>
[PID: 1036][C:\Program Files\Common Files\PFShared\umxlu.exe] <Tiny Software, Inc.><6.0.1.15>
[c:\windows\system\winlogon] <N/A><N/A>
[C:\windows\TEMP\e2.dll] <N/A><N/A>
[PID: 1800][C:\windows\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\DOCUME~1\baohelin\LOCALS~1\Temp\9ojhp8r.dll] <N/A><N/A>
[c:\windows\system\winlKey.DLL] <N/A><N/A>
[PID: 2072][C:\Program Files\Tiny Firewall Pro\amon.exe] <Computer Associates International, Inc.><6.5.3.2>
[C:\DOCUME~1\baohelin\LOCALS~1\Temp\9ojhp8r.dll] <N/A><N/A>
[c:\windows\system\winlKey.DLL] <N/A><N/A>
[PID: 2168][C:\Program Files\Internet Download Manager\IDMan.exe] <Internet Download Manager Corp., Tonec Inc. ><5, 0, 0, 0>
[C:\DOCUME~1\baohelin\LOCALS~1\Temp\9ojhp8r.dll] <N/A><N/A>
[c:\windows\system\winlKey.DLL] <N/A><N/A>
[PID: 2024][C:\Documents and Settings\baohelin\桌面\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\DOCUME~1\baohelin\LOCALS~1\Temp\9ojhp8r.dll] <N/A><N/A>
[c:\windows\system\winlKey.DLL] <N/A><N/A>