这些全部不认识,自己看文件判断去,用解压工具WinRAR依路径打开找所有文件,压缩发来。
启动项目
注册表
<Windows防火墙><C:\WINDOWS\system32\Lenov06644609.exe> []
==================================
启动文件夹
[Key Tools]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Key Tools.lnk --> C:\WINDOWS\locker.exe [Lenovo Co. LTD]><H>
==================================
服务
[Lenovo file service / secsvr][Running/Auto Start]
<C:\WINDOWS\secsvr.exe><N/A>
==================================
浏览器加载项
[prjBDBHO.CBDBHO]
{EB3ED5BB-61F2-4372-9E43-1110DB6E4866} <C:\WINDOWS\system32\bdbho.dll, Syslink>
[百度一下,你就知道]
{F2C63239-A5DB-487B-B283-4132351E7AB6} <
http://www.baidu.com/index.php?tn=mm667_pg, N/A>
[System Link]
{5F79F575-5D71-41EC-98C2-4769AAFA740D} <C:\WINDOWS\system32\bdsyslink.dll, SysLink>
[System Link]
{5F79F575-5D71-41EC-98C2-4769AAFA740D} <C:\WINDOWS\system32\bdsyslink.dll, SysLink>
[prjBDBHO.CBDBHO]
{EB3ED5BB-61F2-4372-9E43-1110DB6E4866} <C:\WINDOWS\system32\bdbho.dll, Syslink>
==================================
正在运行的进程
[C:\WINDOWS\system32\mangdrive.dll] [N/A, ]
[PID: 1196 / new][C:\WINDOWS\system32\Lenov06644609.exe] [N/A, ]
[C:\DOCUME~1\new\LOCALS~1\Temp\E_N4\krnln.fnr] [, 1, 0, 0, 1]
[C:\DOCUME~1\new\LOCALS~1\Temp\E_N4\HtmlView.fne] [, 1, 0, 0, 1]
[C:\DOCUME~1\new\LOCALS~1\Temp\E_N4\shell.fne] [N/A, ]
[C:\DOCUME~1\new\LOCALS~1\Temp\E_N4\eAPI.fne] [, 1, 0, 0, 1]
[C:\DOCUME~1\new\LOCALS~1\Temp\E_N4\ERawSock.fne] [N/A, ]
[PID: 2328 / SYSTEM][C:\WINDOWS\secsvr.exe] [N/A, ]
[PID: 2564 / SYSTEM][C:\WINDOWS\usblogon.exe] [Lenovo Co. LTD, 1, 0, 0, 1]
[C:\WINDOWS\system32\usbkey.dll] [Lenovo Co. LTD, 1, 0, 0, 1]
[C:\WINDOWS\system32\api2090_wrapper.dll] [, 4, 39, 4, 0]
[C:\WINDOWS\system32\bfcipher.dll] [N/A, ]
[C:\WINDOWS\system32\api2090_dll.dll] [, 4, 39, 4, 0]
==================================
Autorun.inf
[C:\]
[AutoRun]
OPEN=Lenov06644609.exe
shell\open=打开(&O)
shell\open\Command=Lenov06644609.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=Lenov06644609.exe
==================================
计划任务
[已启用] 查看 Windows Live Toolbar 更新.job
C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE