<9c8ij><D:\DOCUME~1\song\LOCALS~1\Temp\iexpl0re.exe> []
<fwm05jusuyfjlu><D:\DOCUME~1\song\LOCALS~1\Temp\Servere.exe> []
<75r92><D:\DOCUME~1\song\LOCALS~1\Temp\Servera.exe> []
<cmdbcs><D:\WINDOWS\cmdbcs.exe> []
<pklihiss><D:\WINDOWS\pklihiss.exe /i> []
<{A6011F8F-A7F8-49AA-9ADA-49127D43138F}><D:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.dll> []
<{131AB311-16F1-F13B-1E43-11A24B51AFD1}><D:\WINDOWS\system32\gdipri.dll> []
<{E25C29AB-12B9-4523-A53C-324B5FBA648C}><e:\program files\rising\kakatoolbar\soecofir.dll> []
<{99F1D023-7CEB-4586-80F7-BB1A98DB7602}><D:\Program Files\Internet Explorer\IEXPLORE.Sys> [N/A]
<{FEB94F5A-69F3-4645-8C2B-9E71D270AF2E}><D:\Program Files\Internet Explorer\IEXPLORE.Dat> []
<{923509F1-45CB-4EC0-BDE0-1DED35B8FD60}><D:\Program Files\Internet Explorer\IEXPLORE.win> []
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<D:\WINDOWS\system32\\rundll32.exe windhcp.ocx,input><Microsoft Corporation>
[WinWMServiceNow / WinWMServiceNow][Stopped/Auto Start]
<D:\DOCUME~1\song\LOCALS~1\Temp\RAVWM.EXE><N/A>
:\WINDOWS\system32\ldmedia7.dll连Winsock也被劫持了?