EQ是国内的一款知名的主动防御软件,卡巴也有主动防御模块,同时安装很容易造成底层冲突,建议两个里面卸载一个。
EQ在日志中的表现:
=====================================================================
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<EQSysSecure><C:\Program Files\EQSecure\EQSysSecure.exe /background> [EQSecure]
服务
[EQService / EQService][Running/Auto Start]
<C:\Program Files\EQSecure\EQService.exe><EQSecure>
驱动程序
[EQSysSecure / EQSysSecure][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\EQSysSecure.sys><EQSecure>
正在运行的进程(DLL插入)
[PID: 3040 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\Program Files\EQSecure\EQSandBoxUI.dll] [EQSecure, 2008, 9, 1, 4]
[PID: 2744 / Administrator][C:\Program Files\SogouInput\PinyinUp.exe] [N/A, ]
[C:\Program Files\EQSecure\EQSandBoxUI.dll] [EQSecure, 2008, 9, 1, 4]
[PID: 3368 / Administrator][d:\My Documents\SRENG\SRE5adef2a7.EXE] [Smallfrogs Studio, 2.6.12.1018]
[C:\Program Files\EQSecure\EQSandBoxUI.dll] [EQSecure, 2008, 9, 1, 4]
隐藏进程
[493] C:\Program Files\EQSecure\EQSysSecure.exe
[1829] C:\Program Files\EQSecure\EQService.exe
====================================================================