|
|
11楼

楼主 |
发表于 2007-4-30 17:02:43
|
只看该作者
来自:河南
ver 1.0
注册表启动信息
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
BluetoothAuthenticationAgent rem rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
kav "D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
racer C:\Program Files\racer-han-cnc\racer.exe
BigDogPath rem C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
CnsM.dll Rundll32.exe C:\PROGRA~1\3721\CnsM.dll,Rundll32
helper.dll rem C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
YLive.exe rem C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
CnsMin Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
yassistse rem c:\progra~1\yahoo!\assistant\yassistse.exe
===========================================
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
ctfmon.exe C:\WINDOWS\system32\ctfmon.exe
===========================================
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
DebugOptions 2048
Documents
DosPrint no
load
NetMessage no
NullPort None
Programs com exe bat pif cmd
===========================================
系统进程列表
[System Process] 0
System 4
smss.exe 484
csrss.exe 556
winlogon.exe 580
SERVICES.EXE 624
LSASS.EXE 636
SVCHOST.EXE 784
SVCHOST.EXE 832
SVCHOST.EXE 936
SVCHOST.EXE 1016
SVCHOST.EXE 1088
Explorer.EXE 1304
Rundll32.exe 1500
avp.exe 1524
avp.exe 1672
SVCHOST.EXE 1692
SVCHOST.EXE 1764
racer.exe 368
ctfmon.exe 428
alg.exe 468
ylive.exe 3884
iexplore.exe 4008
ProcessInfo.exe 3808
my.exe 2040
===========================================
开云(中国)官方进程信息
2040 my.exe
4194304 1323008 C:\Program Files\开云(中国)官方\my.exe
2089943040 606208 C:\WINDOWS\system32\ntdll.dll
2088763392 1163264 C:\WINDOWS\system32\kernel32.dll
1561788416 630784 C:\WINDOWS\system32\COMCTL32.dll
2010775552 692224 C:\WINDOWS\system32\ADVAPI32.dll
2011496448 593920 C:\WINDOWS\system32\RPCRT4.dll
2012151808 290816 C:\WINDOWS\system32\GDI32.dll
2010185728 585728 C:\WINDOWS\system32\USER32.dll
1982857216 118784 C:\WINDOWS\system32\IMM32.DLL
1656881152 36864 C:\WINDOWS\system32\LPK.DLL
1945763840 438272 C:\WINDOWS\system32\USP10.dll
2008940544 360448 C:\WINDOWS\system32\msvcrt.dll
1991311360 172032 C:\WINDOWS\system32\winmm.dll
1906442240 94208 C:\WINDOWS\system32\WS2_32.dll
1906376704 32768 C:\WINDOWS\system32\WS2HELP.dll
2102984704 8331264 C:\WINDOWS\system32\SHELL32.dll
2012479488 483328 C:\WINDOWS\system32\SHLWAPI.dll
1998061568 1060864 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
1524367360 225280 C:\WINDOWS\system32\uxtheme.dll
924909568 548864 C:\WINDOWS\DOWNLO~1\CnsMin.dll
1992687616 163840 C:\WINDOWS\system32\imagehlp.dll
1608318976 344064 C:\WINDOWS\system32\NETAPI32.dll
2008875008 32768 C:\WINDOWS\system32\VERSION.dll
268435456 36864 C:\PROGRA~1\3721\CnsM.dll
1392508928 45056 C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll
1952972800 307200 C:\WINDOWS\system32\MSCTF.dll
1993801728 139264 C:\WINDOWS\system32\apphelp.dll
1935933440 188416 C:\WINDOWS\system32\msctfime.ime
1989738496 1298432 C:\WINDOWS\system32\ole32.dll
1906049024 253952 C:\WINDOWS\System32\mswsock.dll
1995374592 159744 C:\WINDOWS\system32\DNSAPI.dll
1995964416 32768 C:\WINDOWS\System32\winrnr.dll
1995636736 180224 C:\WINDOWS\system32\WLDAP32.dll
1959526400 122880 C:\WINDOWS\system32\wshbth.dll
1980104704 1400832 C:\WINDOWS\system32\SETUPAPI.dll
1996029952 24576 C:\WINDOWS\system32\rasadhlp.dll
1627193344 348160 C:\WINDOWS\system32\hnetcfg.dll
1906311168 32768 C:\WINDOWS\System32\wshtcpip.dll
285212672 4292608 C:\Program Files\开云(中国)官方\mhmain.dll
1956839424 32768 C:\WINDOWS\system32\POWRPROF.dll
1936523264 299008 C:\WINDOWS\system32\DDRAW.dll
1941110784 24576 C:\WINDOWS\system32\DCIMAN32.dll
1944518656 376832 C:\WINDOWS\system32\DSOUND.dll
2008743936 86016 C:\WINDOWS\system32\MSACM32.dll
1925775360 36864 C:\WINDOWS\system32\wdmaud.drv
1992294400 188416 C:\WINDOWS\system32\WINTRUST.dll
1985871872 598016 C:\WINDOWS\system32\CRYPT32.dll
1994063872 73728 C:\WINDOWS\system32\MSASN1.dll
1925709824 32768 C:\WINDOWS\system32\msacm32.drv
2008678400 28672 C:\WINDOWS\system32\midimap.dll
1944322048 16384 C:\WINDOWS\system32\KsUser.dll
181338112 131072 c:\progra~1\yahoo!\assist~1\rpxllont.dll
1943207936 1040384 C:\WINDOWS\system32\MFC42.DLL
1639841792 53248 C:\WINDOWS\system32\MFC42LOC.DLL |
|