启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Explorer><C:\WINDOWS\system32\drivers\TXP1atform.exe> []
<ISUSPM Startup><; C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup> [InstallShield Software Corporation]
<Grid Service><; "C:\Program Files\GridService\peer.exe" -n Grid> [FS2YOU]
<{E45C0FF6-B170-43B2-B897-6D02C43A2E18}><C:\WINDOWS\system32\ybM7kf9heVHDx.dll> []
<{FCA4D3BE-C6C7-4F4D-9CBD-CB2666647ACA}><C:\WINDOWS\system32\EN7hzSreCat8.dll> []
<{750DBD56-AF03-47CB-BB28-BBF312B059F9}><C:\WINDOWS\fonts\xbpCfXnG6wUVF.fon> []
<{91F5C9DB-ACD1-4812-BAB9-6F5AE433930A}><C:\WINDOWS\fonts\MbsV2QQJe.fon> []
<{51F88A10-09E6-4763-948F-1C8861003255}><C:\WINDOWS\fonts\MqppW9KYn.fon> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360hotfix.exe]
<IFEO[360hotfix.exe]><ntsd -d> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe]
<IFEO[360rpt.exe]><ntsd -d> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safe.exe]
<IFEO[360safe.exe]><ntsd -d> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.exe]
<IFEO[360safebox.exe]><ntsd -d> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe]
<IFEO[360tray.exe]><ntsd -d> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe]
<IFEO[agentsvr.exe]><ntsd -d> [N/A]
==================================
启动文件夹
N/A
==================================
服务
==================================
驱动程序
<2 - 系统找不到指定的文件。
><N/A>
[klan / klan][Running/]
<2 - 系统找不到指定的文件。
><N/A>
[SafeMon2 / SafeMon2][Running/]
<2 - 系统找不到指定的文件。
><N/A>
==================================
浏览器加载项
[百度首页]
{02496EBD-8455-48db-B3C7-5DAC97D9F5A7} <
http://baidu.com/index.php?tn=LordFoxdg, N/A>
[]
{e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, (Signed) N/A>
[]
{03507A1A-E0C5-4404-AA26-205385C0892D} <, >
[访问通用网址]
<, >
==================================
正在运行的进程
[C:\WINDOWS\system32\GameLink.dll] [
www.Easy2Game.com, 17, 2, 6, 8]
[C:\WINDOWS\system32\Va7SpUWgCA5f.dll] [N/A, ]
[C:\Program Files\Kingsoft\KSWebShieldSVC\KSWBC.dll] [N/A, ]
==================================
文件关联
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
Easy2Game-TCPChain
C:\WINDOWS\system32\GameLink.dll(
www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-UDPChain
C:\WINDOWS\system32\GameLink.dll(
www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-UDPChain
C:\WINDOWS\system32\GameLink.dll(
www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-TCPChain
C:\WINDOWS\system32\GameLink.dll(
www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-TCPFilter
C:\WINDOWS\system32\GameLink.dll(
www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-UDPFilter
C:\WINDOWS\system32\GameLink.dll(
www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-UDPFilter
C:\WINDOWS\system32\GameLink.dll(
www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-TCPFilter
C:\WINDOWS\system32\GameLink.dll(
www.Easy2Game.com, Easy2Game Service Provider)