1. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><C:\WINDOWS\system32\dnsq.dll> []
2. ==================================
正在运行的进程
[PID: 724 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[C:\WINDOWS\system32\WgaLogon.dll] [, ]
[PID: 768 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 780][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 940 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 1004 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 1124 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 1232 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 1344 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 1452 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 1760 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 1840][C:\WINDOWS\system32\com\lsass.exe] [N/A, ]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 516][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 536 / SYSTEM][C:\Program Files\StormII\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 3, 15]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 564 / SYSTEM][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE] [Microsoft Corporation, 7.00.9466]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 1876][C:\WINDOWS\system32\com\smss.exe] [N/A, ]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 3184 / Administrator][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 2304 / Administrator][D:\sreng2\SREf0465bfe.EXE] [Smallfrogs Studio, 2.6.11.992]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]