[MSJDrvr / MSJDrvr][Running/System Start]
<System32\DRIVERS\MSJDrvr.sys>
Qizhi Software (beijing) Co. Ltd是360安全卫士在国际互联网根证书CA注册时的登记名称。查看360安全卫士等程序文件属性,进入“数字签名”页,在“签名列表”中的“签名人姓名” 可以看到“Qizhi Software (beijing) Co. Ltd”。
注册表
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<ThunderAdvise><C:\WINNT\Downloaded Program Files\ThunderAdvise.dll>
浏览器加载项
[ThunderHlpObj Class]
{97421D0D-E07F-40DF-8F07-99597B9585AD} <C:\WINNT\Downloaded Program Files\ThunderAdvise.dll>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\aetsprov]
<N/A><C:\WINDOWS\system32\regsvr32.exe /s C:\WINDOWS\system32\aetsprov.dll>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<Webcam><C:\Program Files\Messenger\msgswcam.dll>
C:\Program Files\MSN Messenger\MSGSWCAM.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ZCfgSvc.exe><c:\WINDOWS\system32\ZCfgSvc.exe> [Intel Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Sebring]
<WinlogonNotify: Sebring><c:\WINDOWS\system32\LgNotify.dll> [Intel Corporation]