+ 其他自启动项目
+ C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
腾讯QQ.lnk
[A ] 27. c:\qq\qq.exe
TENCENT
QQ
.text,.rdata,.data,.rsrc,
55 8B EC 6A FF 68 08 54 52 00 68 AE 54 48 00 64
+ 系统活动模块
+ 00000090(144) smss.exe
+ 000000a4(164) winlogon.exe
77520000[00008000]
[ M] 42. c:\winnt\system32\wdmaud.drv
Microsoft Corporation
WDM Audio driver mapper
.text,.data,.rsrc,.reloc,
83 7C 24 08 01 75 19 FF 74 24 04 FF 15 84 10 52
10000000[00021000]
[ M] 43. c:\program files\nxzg\akmt.dll
stdstub Module
.text,.rdata,.data,.Shared,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
016E0000[00029000]
[ M] 44. c:\program files\nxzg\fpry.dll
stdplay
.text,.rdata,.data,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
02390000[00037000]
[ M] 45. c:\winnt\system32\winabcx.ime
PKUETI
智能ABC 5.23版
.text,.rdata,.data,.rsrc,.reloc,
8D 45 EC 50 6A 00 6A 00 68 20 E3 53 01 8B 4D F0
+ 000000a8(168) csrss.exe
+ 000000d8(216) services.exe
+ 000000e4(228) lsass.exe
+ 00000178(376) svchost.exe
+ 000001a4(420) svchost.exe
63B50000[00034000]
[ M] 46. c:\winnt\system32\unimdm.tsp
Microsoft Corporation
Unimodem 5 Service Provider
.text,.data,.rsrc,.reloc,
53 55 56 8B 74 24 14 85 F6 57 B8 01 00 00 00 75
63BC0000[00008000]
[ M] 47. c:\winnt\system32\kmddsp.tsp
Microsoft Corporation
TAPI Kernel-Mode Service Provider
.text,.data,.rsrc,.reloc,
63BB0000[0000C000]
[ M] 48. c:\winnt\system32\ndptsp.tsp
Microsoft Corporation
NDIS Proxy TAPI Service Provider
.text,.data,.rsrc,.reloc,
63BD0000[00006000]
[ M] 49. c:\winnt\system32\ipconf.tsp
Microsoft Corporation
Microsoft Multicast Conference TAPI Service Provider
.text,.data,.rsrc,.reloc,
53 55 56 8B 74 24 14 85 F6 57 B8 01 00 00 00 75
63BE0000[00044000]
[ M] 50. c:\winnt\system32\h323.tsp
Microsoft Corporation
Microsoft H.323 TAPI Service Provider
.text,.data,.rsrc,.reloc,
53 55 56 8B 74 24 14 85 F6 57 B8 01 00 00 00 75
+ 000001c4(452) spoolsv.exe
+ 000001e8(488) hidserv.exe
+ 00000218(536) regsvc.exe
+ 0000022c(556) svchost.exe
10000000[00062000]
[AM] 2. c:\program files\nxzg\xhjq.dll
AdDm
.text,.rdata,.data,.idata,.didat,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
01460000[00021000]
[ M] 43. c:\program files\nxzg\akmt.dll
stdstub Module
.text,.rdata,.data,.Shared,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
014A0000[00029000]
[ M] 44. c:\program files\nxzg\fpry.dll
stdplay
.text,.rdata,.data,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
014E0000[00028000]
[ M] 51. c:\program files\nxzg\cmov.dll
stdvote
UPX0,UPX1,.rsrc,
80 7C 24 08 01 0F 85 C2 01 00 00 60 BE 00 B0 01
01520000[00040000]
[ M] 52. c:\program files\nxzg\tdfm.dll
navseg
UPX0,UPX1,.rsrc,
80 7C 24 08 01 0F 85 B9 01 00 00 60 BE 00 50 03
+ 00000230(560) MSTask.exe
10000000[00021000]
[ M] 43. c:\program files\nxzg\akmt.dll
stdstub Module
.text,.rdata,.data,.Shared,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
00D40000[00029000]
[ M] 44. c:\program files\nxzg\fpry.dll
stdplay
.text,.rdata,.data,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
+ 0000026c(620) svchost.exe
00400000[0007C000]
[AM] 3. c:\windows\system32\md8\svchost.exe
CODE,DATA,BSS,.idata,.tls,.rdata,.reloc,.rsrc,
55 8B EC 83 C4 F0 53 B8 A4 37 46 00 E8 5B 2F FA
10000000[00021000]
[ M] 43. c:\program files\nxzg\akmt.dll
stdstub Module
.text,.rdata,.data,.Shared,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
00E50000[00029000]
[ M] 44. c:\program files\nxzg\fpry.dll
stdplay
.text,.rdata,.data,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
022D0000[00039000]
[ M] 53. c:\winnt\system32\c_g18030.dll
Microsoft Corporation
GB18030 DBCS-Unicode Conversion DLL
.text,.data,.rsrc,.reloc,
00 51 02 C7 E7 44 01 48 01 F9 01 61 02 C9 E7 CA
+ 000002c8(712) WinMgmt.exe
+ 000002d8(728) svchost.exe
+ 0000036c(876) Explorer.EXE
23000000[00056000]
[ M] 54. c:\winnt\apppatch\aclayers.dll
Microsoft Corporation
Windows 2000 Shim Accessory DLL
.text,.data,.CRT,.rsrc,.reloc,
8B 44 24 08 53 33 DB 2B C3 74 4E 48 75 67 8B 44
10000000[00021000]
[ M] 43. c:\program files\nxzg\akmt.dll
stdstub Module
.text,.rdata,.data,.Shared,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
00C70000[00029000]
[ M] 44. c:\program files\nxzg\fpry.dll
stdplay
.text,.rdata,.data,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
00CB0000[00037000]
[ M] 45. c:\winnt\system32\winabcx.ime
PKUETI
智能ABC 5.23版
.text,.rdata,.data,.rsrc,.reloc,
8D 45 EC 50 6A 00 6A 00 68 20 E3 53 01 8B 4D F0
016B0000[00039000]
[ M] 53. c:\winnt\system32\c_g18030.dll
Microsoft Corporation
GB18030 DBCS-Unicode Conversion DLL
.text,.data,.rsrc,.reloc,
00 51 02 C7 E7 44 01 48 01 F9 01 61 02 C9 E7 CA
77520000[00008000]
[ M] 42. c:\winnt\system32\wdmaud.drv
Microsoft Corporation
WDM Audio driver mapper
.text,.data,.rsrc,.reloc,
83 7C 24 08 01 75 19 FF 74 24 04 FF 15 84 10 52
773C0000[00008000]
[ M] 55. c:\winnt\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
8B 44 24 08 56 83 E8 00 74 2E 48 75 38 8B 74 24
02900000[0001B000]
[ M] 56. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
6A 0C 68 00 CD 8F 01 E8 BD 02 00 00 33 C0 40 89
029A0000[0001C000]
[AM] 25. c:\360safe\safemon\safemon.dll