注册表: <run><> [N/A]
<340A73><C:\WINDOWS\system32\824F55\340A73.EXE> []
启动: <C:\Documents and Settings\CShe.AP\「开始」菜单\程序\启动\340A73.lnk --> C:\WINDOWS\system32\824F55\340A73.EXE [N/A]><N>
[PID: 3288 / cshe][C:\WINDOWS\system32\824F55\340A73.EXE] [N/A, ]
[C:\DOCUME~1\CShe.AP\LOCALS~1\Temp\E_N4\krnln.fnr] [N/A, ]
[C:\DOCUME~1\CShe.AP\LOCALS~1\Temp\E_N4\HtmlView.fne] [N/A, ]
[C:\DOCUME~1\CShe.AP\LOCALS~1\Temp\E_N4\shell.fne] [N/A, ]
[C:\DOCUME~1\CShe.AP\LOCALS~1\Temp\E_N4\dp1.fne] [N/A, ]
[C:\DOCUME~1\CShe.AP\LOCALS~1\Temp\E_N4\eAPI.fne] [N/A, ]
[C:\DOCUME~1\CShe.AP\LOCALS~1\Temp\E_N4\internet.fne] [N/A, ]
[C:\DOCUME~1\CShe.AP\LOCALS~1\Temp\E_N4\spec.fne] [N/A, ]
[C:\DOCUME~1\CShe.AP\LOCALS~1\Temp\E_N4\cnvpe.fne] [N/A, ]
[PID: 3248 / cshe][C:\WINDOWS\system32\AF899C\V5-30BC6.EXE] [N/A, ]
[C:\WINDOWS\system32\AF899C\krnln.fnr] [N/A, ]
[C:\WINDOWS\system32\AF899C\dp1.fne] [N/A, ]
[C:\WINDOWS\system32\AF899C\eAPI.fne] [N/A, ]