[PID: 124][D:\Program Files\Fuji Xerox\SimpleMonitor\FXPSP.EXE] [Fuji Xerox Co., Ltd., 1.000.307.18]
[D:\WINDOWS\system32\FXSRM.dll] [Fuji Xerox Co., Ltd., 1.000.305.22]
[D:\Program Files\Common Files\Microsoft Shared\MSINFO\CEC205B5.dll] [N/A, ]
[D:\Program Files\Fuji Xerox\SimpleMonitor\FX DocuPrint 202\FXH01DZ.DLL] [Fuji Xerox Co., Ltd., 1.001.307.18]
[D:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 5, 1, 14]
[PID: 144][D:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5.1.0.34]
[D:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 5, 1, 14]
[D:\Program Files\Common Files\Microsoft Shared\MSINFO\CEC205B5.dll] [N/A, ]
[PID: 216][D:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\Common Files\Microsoft Shared\MSINFO\CEC205B5.dll] [N/A, ]
[D:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 5, 1, 14]
[PID: 256][D:\WINDOWS\System32\cmd.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\Common Files\Microsoft Shared\MSINFO\CEC205B5.dll] [N/A, ]
[D:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 5, 1, 14]
[PID: 280][D:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\Common Files\Microsoft Shared\MSINFO\CEC205B5.dll] [N/A, ]
[D:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 5, 1, 14]
[D:\WINDOWS\uda.a] [N/A, ]
[PID: 812][D:\WINDOWS\System32\cmd.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\Common Files\Microsoft Shared\MSINFO\CEC205B5.dll] [N/A, ]
[D:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 5, 1, 14]
[D:\WINDOWS\qwe\weg.com] [Smallfrogs Studio, 2.4.12.806]
[D:\Program Files\Common Files\Microsoft Shared\MSINFO\CEC205B5.dll] [N/A, ]
[D:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 5, 1, 14]
[PID: 472][D:\WINDOWS\System32\WScript.exe] [Microsoft Corporation, 5.6.0.8820]
[D:\Program Files\Common Files\Microsoft Shared\MSINFO\CEC205B5.dll] [N/A, ]
[D:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 5, 1, 14]
==================================
文件关联
.TXT Error. [D:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR Error. [AutoCADScriptFile]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [D:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
[C:\]
[AutoRun]
open=wscript.exe u.vbe
shell\open\Command=wscript.exe u.vbe
shell\explore\Command=wscript.exe u.vbe
shell\find\Command=wscript.exe u.vbe
[D:\]
[AutoRun]
open=CEC205B5.exe
shell\open=打开(&O)
shell\open\Command=CEC205B5.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=CEC205B5.exe
[E:\]
[AutoRun]
open=CEC205B5.exe
shell\open=打开(&O)
shell\open\Command=CEC205B5.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=CEC205B5.exe
[F:\]
[AutoRun]
open=CEC205B5.exe
shell\open=打开(&O)
shell\open\Command=CEC205B5.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=CEC205B5.exe
[G:\]
[AutoRun]
open=CEC205B5.exe
shell\open=打开(&O)
shell\open\Command=CEC205B5.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=CEC205B5.exe
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]