pe_xscan做了几个改动

来源:互联网 发布:硅谷数模 知乎 编辑:程序博客网 时间:2024/04/30 19:15

1、整理优化了F2、O4、O23、O24组的检测代码

 

2、修改了生成的LOG中的O23项的显示,由:

 

O23 - 服务: porting (Microsoft Device Logical) - C:/WINDOWS/System32/svchost.exe -k "porting"|2008-4-13 19:14:14|Microsoft? Windows? Operating System|5.1.2600.5512|Generic Host Process for Win32 Services|? Microsoft Corporation. All rights reserved.|5.1.2600.5512 (xpsp.080413-2111)|Microsoft Corporation|?|svchost.exe|svchost.exe->C:/WINDOWS/system32/5b3185.dll|2009-6-11 11:26:22|Microsoft(R) Windows(R) Operating System|1, 0, 0, 1|.Net support application|Copyright (C) 2008|1, 0, 0, 1|Microsoft Corporation|?|Microsoft(R) Windows(R) Operating System|Server.exe(自动)

 

 

改为:

 

O23 - 服务: porting (Microsoft Device Logical) - C:/WINDOWS/System32/svchost.exe -k "porting" | 2008-4-13 19:14:14|Microsoft? Windows? Operating System|5.1.2600.5512|Generic Host Process for Win32 Services|? Microsoft Corporation. All rights reserved.|5.1.2600.5512 (xpsp.080413-2111)|Microsoft Corporation|?|svchost.exe|svchost.exe
        -> C:/WINDOWS/system32/5b3185.dll |2009-6-11 11:26:22|Microsoft(R) Windows(R) Operating System|1, 0, 0, 1|.Net support application|Copyright (C) 2008|1, 0, 0, 1|Microsoft Corporation|?|Microsoft(R) Windows(R) Operating System|Server.exe(自动)
原创粉丝点击