|
|
- 2 m8 Z+ I; Q% o }
- 2008-05-22,20:37:43$ X" U0 V8 f1 v2 N3 D
- System Repair Engineer 2.5.16.900
' W! F& N+ `( F; S - Smallfrogs (http://www.KZTechs.com)8 x( n/ y8 S+ }6 l
- Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能7 R- N% e, ^. N) Z
- 以下内容被选中:9 A. Y0 }: i0 \9 e R
- 所有的启动项目(包括注册表、启动文件夹、服务等). }. D) `) A9 r( K
- 浏览器加载项
/ T, a/ |4 |" _- R6 S - 正在运行的进程(包括进程模块信息)0 B7 Y. R0 t- E" m: F
- 文件关联. E2 ~6 Z7 C( q4 o5 P8 M
- Winsock 提供者
/ h. t* Q- R8 n - Autorun.inf, G) K8 U" R' Y
- HOSTS 文件
J* d: L F7 n0 m - 进程特权扫描0 D7 r9 @0 L+ I. p7 ]
- 9 y6 b) ~9 d/ |( ^; F$ S
- 启动项目$ L; g- M$ m% O/ U8 o" I
- 注册表
; ?: R, y$ p$ x - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]3 w4 Y2 v: o- b* Y9 @
- <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]
3 D- h- ^2 ?9 O$ P2 x - [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]* E6 O& X% C2 L/ q2 Z( I
- <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]
) H, `& p4 b# `" ^1 E2 Z) h - <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
2 G0 ]7 o( Z8 R( G0 W6 e5 S - <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]0 F/ }" V2 L% t H* D, P K
- <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]
3 z2 t1 t* K9 g - <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]
+ w3 u7 i3 l7 W9 `, S# H6 w* x' Z3 P k+ T - <PHIME2002A><; > [N/A]
d U2 L( d: a, i% a - <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]
, m; D% m. O j ` - [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]! I$ c9 C6 U: U, g& X0 y! L
- <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]; l& A n6 O. X+ V! c
- <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]
2 c; W( {2 M8 A! z - <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]& u; K" L8 Q- j/ J/ w" }5 T6 r
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
# O6 I t" Y/ Q- W- W7 s$ b9 D8 f - <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]
% c4 z! i" v6 y2 p - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
, o6 ~+ y9 W7 T$ a; y - <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
. C# r6 o0 g7 h+ r3 B7 a+ I - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}], D/ d# k; r3 _6 [6 M5 y5 c
- <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]) S; E, p. N; E" L
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]9 ]3 ^1 [) g: @; V H' F1 A& p
- <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]: @4 ]6 b# Z* _& B# {) U% F3 C" M
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]# J+ i6 a4 s( ]9 E1 t
- <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]$ u& ^ s2 {0 s
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
! _8 y$ b3 ~# b - <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]) O' R9 w, d( J& |* j
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]- w( z. r9 F. r- t) }! Y: h% ~" i
- <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]/ k7 `5 y" b- s6 N3 F
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
5 S0 x! g1 ]5 R3 S/ Z - <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]5 z1 i( T2 y+ V! q# t" T2 u
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
& B) l- D8 i) v( B - <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]# c1 S# \' T4 {0 \) t
- ==================================
0 M0 f. c5 @4 C - 启动文件夹
0 w3 X9 ~3 K* }4 a, Y - N/A
6 T' ~ k; P: i: Z9 k+ ]# T& o+ [ - ==================================
1 B9 }! _8 [8 { - 服务
) o: I1 H X) v, D+ D( U1 o - [3ware Controller Service / 3wareSrv][Stopped/Auto Start]2 i! e, i4 {8 G4 _
- <C:\WINDOWS\System32\3wareSrv.exe><N/A>) l0 X7 x: p! D9 w0 N
- [Google Updater Service / gusvc][Stopped/Manual Start]' p8 b3 y7 W5 V- A/ W" w( x: H
- <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>+ q% b1 }$ i% M) f$ I* _& k: n
- [Help and Support / helpsvc][Stopped/Disabled]% }) _+ ~. E1 f7 B7 B3 ~! s
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>. b3 a1 Z8 E: j) D2 Y' B) S9 S
- [Human Interface Device Access / HidServ][Stopped/Boot Start]
7 m$ b- p+ d. ]& l - <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>, Y! }- {& m; K
- [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]. N2 r2 Q: A7 j
- <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>
# q; z! r# X( F# f2 N/ Y) I - [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]* e3 [; o$ \( _
- <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>
2 `4 {9 _/ a7 Q - [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]4 }+ I' n1 _. z; q; k! C/ Z
- <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>
7 l* P$ m* i# ^+ `4 R - [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]
6 q. ^5 F2 o% h4 j - <><N/A>
$ U( ^/ B4 D1 |1 ` - [Qvod Terminal / Qvod Terminal][Running/Auto Start]) T. a! Y4 L1 j- r; J% E* m6 j
- <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>
; y# v* i4 U- s - ==================================& }/ {/ n1 w6 _# x3 t7 |
- 驱动程序
" w, e4 p2 c' d6 q3 e. W- [ - [22j / 22jn][Stopped/Boot Start]
3 z7 ]3 a3 S2 K$ X! v, E6 ]5 r - <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>
' H1 e) ? v, B* v - [360AntiArp / 360AntiArp][Running/System Start]. D" u3 {. V5 w4 v2 b
- <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
3 g: h; _+ e% ?+ e/ ~6 W" Z5 x' [ - [43ec / 43ecu][Stopped/Boot Start]
( r( C) h6 @1 q - <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>
. H/ I$ U1 w9 ?- J' k - [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
& |9 F: a/ A% m u5 M& n* h - <system32\drivers\ac97intc.sys><Intel Corporation>4 J7 y2 b) U- v1 I( L% F- `
- [Promise driver accelerator / bb-run][Running/Boot Start]4 q, Z v! O4 _0 h0 d
- <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.>
# z3 V/ U+ G! Q1 a# M! {$ s - [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]. b/ _9 x- t0 q& o t) k
- <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>
h2 C3 }/ m! l - [KAVBase / KAVBase][Running/Auto Start], b+ J( q" e0 u' s) e
- <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
3 L# D( s; B0 G' v. v, b" S - [KAVBootC / KAVBootC][Running/Boot Start]
% J4 t( y$ z$ s. E - <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>' n! r$ f$ `1 _- A6 S, e! \% I
- [KAVSafe / KAVSafe][Running/Auto Start]
% c# R l- d0 [& F9 o - <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>% ]7 K5 C$ S' g' l
- [KNetWch / KNetWch][Running/System Start]; m* e0 k& @. i, F
- <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
/ N" G$ W% x0 Z! ~ - [KWatch3 / KWatch3][Running/Auto Start]) I" G( W9 Z8 P" F" }$ G: {
- <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>6 ]* { f# r/ i4 [
- [ntptdb / ntptdb][Stopped/Auto Start]. D+ s) G. L4 ~/ @. K2 t
- <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>
3 z9 ~: q+ j. f! e - [nv / nv][Running/Manual Start]: F- p5 }7 g' J% s+ x. x9 I3 K* f
- <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>4 k8 q: }1 z+ ]% X1 V- m. n. p: |7 j0 W
- [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]! O1 M6 E: ?1 B5 ~+ M- Z8 M
- <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>; x1 G4 ?" e5 D7 i
- [DDK PACKET Protocol / Packet][Running/Manual Start]- h9 u- M8 Q( e1 D! I
- <system32\DRIVERS\ProtoDrv.sys><360安全中心>
, z4 A( q( t1 } n4 x - [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]% t& z+ ~: o- n5 D6 P" X, y# i3 U' p2 I
- <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>
" V4 ^" R, d8 `4 w7 @ G9 z - [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
0 O+ r- i/ i3 _& {" A& p3 \( g - <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>0 T9 Y$ p3 T/ U# r0 I
- [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]4 n% B) Q Q$ y- E" x; S e2 V! n
- <\SystemRoot\system32\drivers\RsBoot.sys><N/A>
: m- }/ [8 B* w - [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
6 h1 I8 @, A( R: v7 r - <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>) G$ g4 _6 x. Q& i8 w1 k
- [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]
! v* h: }; \! }. {4 e - <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>6 \* o; w* M; y1 G! b
- [Secdrv / Secdrv][Stopped/Manual Start]! B8 `" N$ j) J$ q& b
- <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
" n P- D7 i4 O$ F+ `3 f+ \ - [SATALink External Device Filter / SiRemFil][Running/Boot Start]
; G: D, i2 B( A/ `, j - <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>
, a9 {5 {& ?. q5 x! \% P$ l' C$ G - [System Restore Filter Driver / sr][Stopped/Disabled]
+ N* P5 A: s$ ?; { p - <system32\DRIVERS\sr.sys><N/A>
2 ^" [* g. J7 O* Z7 ?" f- ^ - [TesSafe / TesSafe][Stopped/Manual Start]
! X$ ~: `! O) c" ~2 z - <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>/ }! W# X: T2 ] n0 d# N
- [System Services / unzxzsrs][Stopped/Boot Start]5 q: w4 T+ u# n7 g
- <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>
& U' z4 ?" A0 _$ [2 N8 ? - [ViBus / ViBus][Stopped/Boot Start]
% } O+ i" C% o - <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>( Q' h9 ?: P' U. i1 W9 U
- [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
+ s% y- @: O4 ?! a4 [ - <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation># v. {) Z3 f) q' A( O+ t
- [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]+ i! N8 G) W( z) Z: f
- <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>- g! D# K' C, t+ H! T
- [ATI Extend / zhibmaso][Stopped/Boot Start]
$ N, i& A! n- _6 I N9 m - <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>2 G. C6 x. |8 h4 [
- [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]
3 S3 m2 e8 I% I6 D3 t - <System32\Drivers\usbVM31b.sys><Vimicro Corporation>6 n3 K3 c$ _5 n3 U
- ==================================. h) ]1 A6 W0 w4 k3 F. F. V r
- 浏览器加载项+ O; q$ Q4 d! L3 C- A
- [Google Toolbar Helper]
3 }0 y3 u% I& M$ s/ h7 l9 ` - {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
) d+ Z, n8 P d' E% E6 r; ]7 F2 Z - [Google Toolbar Notifier BHO]* c# [9 u- k8 U; c- h/ t
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
7 `" T7 L* ]2 y3 ~9 M - [SafeMon Class]
! E4 e4 O- e' x - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
8 r: ^ n1 j7 k( l+ } - [kingsoft browser shield]
/ D0 J. `* k; |$ P - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>7 u% b: W5 z) R- ]+ ]6 t& G: I
- [IEBuddyExtControl Class]; U# B, }0 u+ _+ S9 X
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>5 |7 ?) D3 Z8 [9 q
- [Zcom 杂志]
* E2 P8 I! O! e3 |; D - {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>5 I! r3 E2 O: K* J4 H/ y
- [&Google]- [/ l) p' D" W
- {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>5 P: D9 m. h5 j5 @8 ]. f! k7 K
- [KooPlayer Control]
- l( V( x% `7 b - {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>+ x1 T( }9 V' u7 j. ` w! T
- [Shockwave Flash Object]. ?, `2 v! z: n- o
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
" {$ _& g. S1 K" G - [KUpdateObj2 Class]
5 i/ L' X8 k: k, E - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
" Z+ O, N5 B5 ~5 C5 N+ j% V - [Google Script Object]. g( A- t( M$ |) `+ n. t6 B
- {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
2 D$ G3 Y7 O9 r) c8 z - [EWA Control]; r* M8 J/ ], `
- {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>' R, }/ S* B0 ? E S! s
- [Windows Media Player]2 W" g T# S6 f; j# `/ k
- {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>9 H v, {7 p/ e' O7 _6 J/ I% ?
- [&Google]- H3 k( r# L' q$ ~, G- a) b+ L$ c
- {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>, Z x" ?7 ]! {* ]
- [HTML Document]
9 u& P7 [0 y0 Q4 K - {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>4 F$ y+ P$ K1 U' O/ W
- [DHTML Edit Control Safe for Scripting for IE5]: p# Q" \- l) r- r
- {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>5 \9 m2 E4 Y Q T: U) p
- [RealPlayer RAM Download Handler]
9 h: x$ n( ~) r+ k, S - {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>, N( j( R2 y, G) a, P) W
- [IEBuddyExtControl Class]9 ?7 n9 U- P2 g
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>1 }8 L. a0 c8 M; \
- [XML Document]
7 g$ C# u! x: A' {8 E5 |9 L/ e - {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
- n; A8 b2 o3 F1 _4 s& f" e - [HHCtrl Object]
/ l* w/ U. ~) S/ n - {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
7 ` @5 y; Z8 J8 }7 @ - [Windows Media Player]
9 g6 w8 z) R. U+ g! b- I. X; D$ ~ - {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
7 }3 S1 X) d: \9 X, A2 W. c5 { - [Active Desktop Mover]
7 D6 y; Y- K ]0 r# y - {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>% D+ Q" d1 C5 K2 L
- [360SafeLive]
- n+ y# F$ S2 Z. M - {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>2 H* Y& {; A1 Z% u! o$ y
- [Microsoft Web 浏览器] L% j; G9 s. Z2 Q5 }" N* ]* W6 Q
- {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>0 |6 o( N! l& A' y) n
- [Browser Enhanced Objects]% g" ?5 m! i4 G
- {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>1 C' C7 Q$ i/ T j( |: L
- [Google Toolbar Helper]. ^# G2 a* Z4 t) A' H s
- {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
0 _8 N' N9 s/ K- T - [Microsoft Scriptlet Component]* I8 D6 X5 V3 r; T9 m j9 `+ [: t
- {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
+ a7 T6 Y8 c# y5 s* G6 a - [Google Toolbar Notifier BHO]. x$ h# ~ [4 P6 q9 I1 U4 \1 U% e
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>+ ]- l# t# E5 @% w0 u- @
- [SearchAssistantOC]
7 o; J9 s; V, J% h - {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
8 K1 X" y! L/ Q+ | - [SafeMon Class]
( O# J, ]& w7 m/ g1 f+ l - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>/ F1 }+ @$ X! z; H9 O" ^
- [RDS.DataSpace]
! k1 P1 u$ \* U - {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>8 Z! L4 m' y% f1 D' S% ]# i
- [KooPlayer Control]
8 d2 I- D4 D6 |- w% {# Y, ~. P* W9 [5 g - {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>4 b- i; h; c& J* H& \, ]) _4 n" d) X
- [AUDIO__MID Moniker Class] Q: { Y0 w, P. K! n. o. o, q* p0 F7 o- S
- {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>; n6 }/ S7 J- H `/ `* p
- [AUDIO__MP3 Moniker Class]/ K$ F f4 w% u0 e; L) b
- {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>' ]9 r- a3 g' n9 a5 D
- [AUDIO__X_MS_WMA Moniker Class]" G3 G/ O* v' o
- {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
9 y8 V# g0 X6 j" C - [VIDEO__X_MS_WMV Moniker Class]
& E- _7 a4 j! ?: \2 R - {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
/ T& @0 ^; N X) ^( { - [RealPlayer G2 Control]. _/ Z e x4 h8 o+ ], l5 f
- {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>( T, S9 I* J% ?/ ?( V
- [Shockwave Flash Object]
1 L6 W4 t5 F H2 |+ m5 p" v - {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>- q, T& i+ y/ R0 M
- [KUpdateObj2 Class]7 V6 F, F s0 x9 z
- {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
: Y- Q, V6 f2 u2 m( u$ @ - [kingsoft browser shield]
5 R* P7 A' ^5 K0 O3 _4 ~ - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
" {5 x, H) i7 J) c5 y - [PasswordEditCtrl Class]/ I8 V* q$ u( ^0 G
- {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
# i* D8 ^: y" h" p - [QvodCtrl Class]5 @" O/ l: X) o. k
- {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>+ V3 g3 o' w# }. s# C6 Y: b
- [&使用超级旋风下载]1 d9 y [9 g0 o0 d' E7 \1 K0 [$ Y: Q
- <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>* Y, [# E; ]6 C) x3 t# x/ W; o
- [&使用超级旋风下载全部链接]
0 o9 j" n# y, e) ] - <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>' d! c: S: w4 T0 b+ e( ]; b# ]
- [使用迅雷下载]. _+ _8 K4 h$ Q7 |" D
- <, N/A>2 T8 A' O* S$ P# [& |: F" C
- [使用迅雷下载全部链接]
$ q9 Y* ^) l0 I0 D9 b - <, N/A>0 e( `' i! h" L% ?
- [导出到 Microsoft Office Excel(&X)]
4 h+ i4 a/ z3 W8 n7 F - <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>, [! @" @9 P# @: d7 L+ c5 b" h2 b
- [添加到QQ表情], ^" ]% I4 g$ {2 H
- <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
{" u( L( \3 N* B- \) P% O2 l - ==================================
( u+ k6 [: ?4 X/ p3 _ - 正在运行的进程2 v" r/ g# x+ |2 a7 ^8 w) M+ Y2 s2 o
- [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]/ B- s( n) b7 S1 }) S6 `& u
- [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
1 ~( r4 K" ?: o, E - [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
; n0 _5 D- k9 p# x: \. y - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]1 Y1 w1 l1 }- P! o: I4 Z
- [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]- l- S0 R1 W& j! L* V6 t. F! Q
- [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
5 n8 I0 `3 o4 @* h - [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]0 e+ y: o r2 ~5 [8 J, x9 S% @
- [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
6 _( l; }( h8 X - [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
. Q3 ]/ {# `2 {. w+ Q3 l+ \) { - [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
8 q1 @7 `# o9 t/ ]2 ]. _ - [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]2 n. V3 c; b& [5 P d
- [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]0 P5 N; N) j6 ?( f/ C: T
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]" G/ U/ [ K8 Z, p
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
! w1 L# M3 a0 D1 c( R. H: ? - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
6 D! n9 z# b: i) P - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
' I' F9 I& h' }6 ] C; o3 x o5 s - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]
/ y0 l. J2 A+ O l4 V - [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]! g% i# l1 x2 i4 Z
- [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
/ z5 u; }; }3 \+ }. v - [C:\Program Files\WinRAR\rarext.dll] [N/A, ]
$ s% o, N! N1 ?. P w - [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]* V& \# T. ?: I, Z
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
' h; d# X+ f' k& g' f& | - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]+ G/ P( v( v, H
- [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]* ~( w" ~: r/ R6 m. J: C) ]
- [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]6 j* K; p/ t5 d$ I% F( t. Q
- [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]
7 t1 F# R- J/ T& ] - [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008]
! }" v& V0 H" L - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
0 h" L* g! }9 _ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]) h5 D1 e+ H% b' i, ~
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
8 o# s/ P6 g+ K - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]9 V. X% O* E7 f: L+ }! R
- [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]+ r3 V/ t% a) h+ N6 a" s1 D9 x
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
* V8 o1 Z& ^( {6 ?- g3 y4 ? - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]* d( t- r' Y9 }2 c* {( C
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]0 r! k* j1 H: t" h9 O
- [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]
# T! g- Z( b D/ z5 ]7 G - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]
7 L* J: ?% n/ G. e9 B' K1 E - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]& Q7 q- t y% N7 O$ S w
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]7 j8 M6 Q `! ?
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]$ f% h( _. G, u. m
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]3 g5 J+ J @6 Y8 j3 h# H* h
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]* o b& g( m: t
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
4 Q+ v9 [5 V7 M# d9 z( [9 q: e - [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
! Z6 N/ r, j* Y+ Z+ H - [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]# I# U7 F5 J0 I
- [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]$ u- r/ t* e. `0 i% A+ p
- [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]0 G6 w9 l( A( l: J
- [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]/ i# {6 `% q. r: m" R6 B4 l6 J, I
- [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
3 C! j3 u; x0 E3 Z g" ~# k - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]9 z; P9 u. F- _7 A5 Q
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
6 x5 d+ j' L1 @: g! p6 d0 C - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
$ g+ {( L0 @/ J: Y! m - [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]" U. p6 L- Z) g/ s. Z0 I3 B* S) w3 S
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]+ j5 m- Q v$ G9 ^) V
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]. ^8 ? o" [1 G) ?' L% N
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]! o; J9 b- f1 q9 ~- k
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]3 G A0 I* i$ ^! {: @; v& \
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]
& Q& N1 _1 v7 S* `$ z! c. z - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78], u/ s8 D# R- u
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
7 O1 r3 I* {) s( Q9 A - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
& n' L5 \. S5 \ - [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]- ?6 I7 A" O: y$ F& y0 r: b( E
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]0 N {* d) J' C4 q# h2 w! @/ g- [. K
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
1 {/ f5 q, [0 J4 A1 k$ t - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]8 l4 t G# C9 _
- [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]
z5 a9 i0 r/ `/ x8 K - [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]' ~- r( A0 D9 C1 I, ]
- [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950]* j8 t6 g8 \& E$ p6 n" i
- [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]9 ?5 _/ p* P& p. u
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
4 E: a! P3 P" j, e& Q - [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]
0 J' B5 p8 v# Z+ z% j - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
9 ?8 K% G2 x( v" n6 H" \% x J - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]. M# P5 {: T! L4 V7 `( D4 e7 G
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]- z/ ^* K4 B7 b0 H& p* V( U% _
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
( H- }% V4 }0 \ - [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]- i1 h" ]3 y+ J8 r4 A/ t; G$ K* t* X
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]# N8 [* l( K+ N6 j$ H
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]+ @" p7 C0 ]% a9 l, M+ h
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]/ K' g& ~3 P8 Y/ ?8 s
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
6 B! l1 V- {* }1 t8 Q1 Y/ A - [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]' Q* m: i( o4 q% G% t
- [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]
. W* q8 C1 M7 v+ v0 m# k - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
) T$ p7 H- g/ _! ?6 J+ J - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
) _# ^% [5 p. {1 w# X: l - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
/ ~) c# g. z5 G4 i8 G/ E4 b - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]& ~$ Y+ v% }! T$ b' f& f" U5 k
- [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
# a0 n) g+ J* T* A0 U$ i! o5 T# V1 G - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
( ^" M, p" m* U: Q# \ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
! D! ?0 ?5 V& R l: B( c - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]0 b! r* M: @. Y+ e
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
$ a& A# |4 |: N - [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]) S& D; z3 H8 V& a
- ==================================
; D+ N* U, H3 c( p - 文件关联) t) o. W) [ n
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]% x; o. Z# ~% i+ J
- .EXE OK. ["%1" %*]9 n4 k0 Z* t0 E" W0 V
- .COM OK. ["%1" %*]
/ d9 W6 j0 m ?" e - .PIF OK. ["%1" %*]6 i* W0 k" s8 T: R1 [
- .REG OK. [regedit.exe "%1"]9 }/ D% ` ]# j- ]) S
- .BAT OK. ["%1" %*]. N) u( C8 l( u4 } u/ B
- .SCR OK. ["%1" /S]
3 T& ?1 e" w& ] - .CHM OK. ["C:\WINDOWS\hh.exe" %1]
3 c5 F( ~+ E* g - .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]' |) t# J! Q2 ^* v Y6 L( U$ |3 Z: p
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
9 s8 G! A7 h+ O* q1 x' l1 ` v# m - .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]+ ^* {' u3 ^- o) |2 A* G0 f
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
( H( b, T: N9 b# ?' K) f! l; E - .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]8 @7 [2 r9 b4 I
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]- U h" Y- J2 m& `* u/ y
- ==================================
( C9 }/ v% P, R5 h - Winsock 提供者
# u) F. M/ N5 {% i: } - N/A
( ^* k: |5 J7 i. b - ==================================3 t' d' x+ c- |6 r% R( J
- Autorun.inf
+ \" O0 N2 I4 j) U! V - N/A% Q( H* j- l5 m# J9 E
- ==================================
8 R2 Y7 S, R$ k, c3 o; l - HOSTS 文件3 \5 Y3 O$ f8 G2 t/ G2 D T! p% N5 Q
- N/A
, J' n1 W6 G, c' M$ [ - ==================================& z) T/ q: @: j5 P
- 进程特权扫描
6 w- w9 t8 b% W# M - 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]' s/ b4 P0 u/ L/ w+ U
- 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]$ _! K, b& A( v
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]
6 `5 L3 L- C$ D3 a* G3 ~1 V - 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]) u; l; V0 H5 }0 T: f
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]* @5 i+ s/ W) {; E. D' c$ J1 h
- ==================================5 A6 h7 l* _" q3 t1 I
- API HOOK
/ x7 M9 r) g# q - N/A
& G2 A1 }& L5 n - ==================================/ t/ p/ u( M3 N
- 隐藏进程9 \! l& k. C1 Q/ l+ U
- N/A
0 a8 N' s# F8 F: I - ==================================
0 v: R1 G2 @: j% C
/ a1 ^+ I5 m. w$ R) F
复制代码 |
|