列举下载的程序文件:
[CKAVWebScan
Object]
InProcServer32 = C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner Pro\kavwebscan.dll
CODEBASE = http://www.kaspersky.com.cn/webscanner/kavwebscan_unicode.cab
[InstaFred]
InProcServer32 = C:\WINNT\DOWNLO~1\InstFred.ocx
CODEBASE =
file://F:\Program Files\AutoCAD 2002\InstFred.ocx
[PowerList Control]
InProcServer32 = C:\DOCUME~1\aa\APPLIC~1\ppStream\100~1.139\POWERL~1.OCX
CODEBASE = http://www.ppstream.com/bin/powerplayer.cab
[WebActivater Control]
InProcServer32 = C:\WINNT\system32\WEBACT~1.OCX
CODEBASE = http://game.qq.com/QQGame2.cab
[MSN Photo Upload Tool]
InProcServer32 = C:\WINNT\Downloaded Program Files\MsnPUpld.dll
CODEBASE = http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
[AcDcToday 控件]
InProcServer32 = C:\WINNT\DOWNLO~1\ACDCTO~1.OCX
CODEBASE =
file://F:\Program Files\AutoCAD 2002\AcDcToday.ocx
[SysMonOCX Control]
InProcServer32 = C:\WINNT\DOWNLO~1\SYSMON~1.OCX
CODEBASE = http://www.ahn.com.cn/aspservice/plugin/myfirewall20.cab
[photo_uploader Control]
InProcServer32 = C:\PROGRA~1\PHOTO_~1\PHOTO_~1.OCX
CODEBASE = http://upload.photo.163.com/photoup.cab
[NOXLATE-BANR]
InProcServer32 = C:\WINNT\DOWNLO~1\InstBanr.ocx
CODEBASE =
file://F:\Program Files\AutoCAD 2002\InstBanr.ocx
[Shockwave Flash
Object]
InProcServer32 = C:\WINNT\system32\Macromed\Flash\Flash8b.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
[vc Control]
InProcServer32 = C:\WINNT\DOWNLO~1\vco.ocx
CODEBASE = http://update.viruschina.com/wmsj/vco.cab
[VqqSpeedDlProxy Class]
InProcServer32 = C:\WINNT\vqqsdl.dll
CODEBASE = http://218.85.138.27/vqqsdl1009.cab
[AcPreview 控件]
InProcServer32 = C:\WINNT\DOWNLO~1\ACPREV~1.OCX
CODEBASE =
file://F:\Program Files\AutoCAD 2002\AcPreview.ocx
--------------------------------------------------
列举 ShellService
ObjectDelayLoad 项目:
Network.ConnectionTray: C:\WINNT\system32\NETSHELL.dll
WebCheck: C:\WINNT\System32\webcheck.dll
SysTray: st
object.dll
--------------------------------------------------
报告完毕,共 7,358 字节
报告生成用时:0.047秒
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only