正在运行的进程
[PID: 996 / SYSTEM][C:\WINDOWS\system32\winsersec.exe] [N/A, ]
[PID: 1860 / SYSTEM][C:\WINDOWS\3600tray.exe] [N/A, ]
[C:\WINDOWS\WSEC32HK.dll] [N/A, ]
[PID: 468 / Administrator][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
[C:\WINDOWS\WSEC32HK.dll] [N/A, ]
[PID: 1800 / Administrator][C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe] [ESET, 3.0.669 ]
[C:\WINDOWS\WSEC32HK.dll] [N/A, ]
[PID: 1388 / Administrator][C:\WINDOWS\sdaemon.exe] [Tropical Software, 6.4]
[C:\WINDOWS\WSEC32HK.dll] [N/A, ]
[C:\WINDOWS\system32\servdll.dll] [N/A, ]
[PID: 1480 / Administrator][C:\WINDOWS\winwd.exe] [N/A, ]
[C:\WINDOWS\WSEC32HK.dll] [N/A, ]
[PID: 1696 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\WSEC32HK.dll] [N/A, ]
[PID: 1708 / Administrator][C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe] [Nero AG, 3.3.3.0]
[C:\WINDOWS\WSEC32HK.dll] [N/A, ]
[PID: 2420 / Administrator][D:\Program Files\Maxthon2\Maxthon.exe] [Maxthon International ltd., 2, 1, 5, 1250]
[C:\WINDOWS\WSEC32HK.dll] [N/A, ]
[PID: 2528 / Administrator][C:\WINDOWS\system32\conime.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\WSEC32HK.dll] [N/A, ]
[PID: 3272 / Administrator][E:\Downloads软件工具\sreng2\SRE9b4eb966.EXE] [Smallfrogs Studio, 2.7.0.1210]
[C:\WINDOWS\WSEC32HK.dll] [N/A, ]
==================================
Autorun.inf
[C:\]
[AutoRun]
open=Folder.htt
shellexecute=Folder.htt
shell\Auto\command=Folder.htt
[D:\]
[AutoRun]
[AutoRun]
open=Folder.htt
shellexecute=Folder.htt
shell\Auto\command=Folder.htt
[E:\]
[AutoRun]
open=Folder.htt
shellexecute=Folder.htt
shell\Auto\command=Folder.htt
[F:\]
open=Folder.htt
shellexecute=Folder.htt
shell\Auto\command=Folder.htt