回复:7月21日 日志分析 练习1
[c6424110 / c6424110][Running/Manual Start]
<\??\C:\WINDOWS\system32\c6424110.sys><N/A>
[Windows Accounts Driver / WindowsRemote][Stopped/Auto Start]
<C:\WINDOWS\system32\081231-6-4.exe><(File is missing)>
[$ServerGMH / $GMH][Stopped/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\ServerGMH.dll><>
[123 / 123][Stopped/Auto Start]
<C:\WINDOWS\System32\Ly_Server2008.exe><(File is missing)>
启动文件夹
[TTPlayer.exe]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\TTPlayer.exe.lnk --> C:\PROGRA~1\TTPlayer\TTPlayer.exe [Alen Soft]><N>
<internetnet><C:\WINDOWS\system32\spoolsv.exe> [File is missing]
<AppInit_DLLs><HBKDXY.dll,HBWULIN2.dll,HBJXSJ.dll,HBXMJ.dll,HBSHQ.dll,HBW2I.dll,035224A5.dll,CF02013C.dll,895A5FB1.dll,D640CC5A.dll,BF50F3F9.dll,7D76C16B.dll,12496E12.dll,HBCHIBI.dll,HBQQXX.dll,HBQQFFO.dll squalne.dll,HBQQSG.dll,HBmhly.dll meyotme.dll> [N/A]
我找的这不知是不是啊 看看答案 呵呵