|
|
! z2 O& b( V8 ?- 2008-05-22,20:37:432 @, t. t4 B7 H* P* Q( H) p
- System Repair Engineer 2.5.16.900
4 K9 X7 J2 t% ?* W" t - Smallfrogs (http://www.KZTechs.com)0 O. x% B# X+ ]
- Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能- u9 o- ~# s" U2 I9 d* I! C
- 以下内容被选中:
) @2 v6 F; j! s# J- }% u - 所有的启动项目(包括注册表、启动文件夹、服务等)# Z3 q6 m- g1 x Q4 u
- 浏览器加载项
0 R( n/ V5 }3 Q5 D# z R5 f - 正在运行的进程(包括进程模块信息)+ q7 m F) V0 O; D. |" |
- 文件关联3 I1 @% R! G- K
- Winsock 提供者2 N+ }) Q" X' M
- Autorun.inf
: F g- T1 p0 [5 H* x" K - HOSTS 文件; d! S" k; z& d! f/ n
- 进程特权扫描
9 e% V0 H: }, I& \4 x - ( X) T( n1 [) u6 s- ]
- 启动项目6 B+ H \6 c [$ U l R ^( y
- 注册表# b7 g+ s( @& k1 ^" F) _, m" B4 ?/ `
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]. ?7 X- H/ L% ?5 y
- <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]4 K9 C T' w4 k* ?( c+ u
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]: z2 {0 g6 n V2 ?5 z9 B
- <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]& T$ I& f& I# Y. b
- <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]: J* a( Y9 c0 X* ^, v* j' T
- <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]3 m- }: {: G* P( w! i+ A3 r
- <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION], R5 e5 f5 k5 S
- <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]
+ V, G/ n& ^; ]/ h1 |! b7 Q% N - <PHIME2002A><; > [N/A]% a p4 X" k4 E* h e2 o% L* V- r$ ]
- <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]' z g2 y9 ]! T% q- y
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]2 n; K+ n% I& A8 B4 V/ w: S
- <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
- t5 e; _$ j s1 R2 @. v4 d - <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]
* Q. Z# W' I+ M, j. ]* D5 h* D - <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]7 I) w5 C# S4 ^8 ~
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
" p" @. L$ H; f( j - <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]' f% L6 D3 A! Z R3 n# x
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
# [5 T! A& z/ d Z! O2 F# I; s - <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]" U- D# U8 J! Y+ ^- @: w; v- N
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
e; @ u3 |- V, n e, \) E5 @4 h - <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]* E1 s; C: z$ Y9 O8 x; {
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]9 r1 T) x9 E9 T3 P2 R4 L! `
- <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
: K$ S2 u" y, u7 g - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]9 h0 [6 H% O- S6 j% b
- <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
( i$ {) z) K9 S* [1 H - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]: m" c( v, Z: v% X
- <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]# N6 S) N. j8 O, d3 @
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
# T. M4 Z7 U' U- c0 O3 b, b - <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]8 c: [, E0 E" E5 x# ]+ Z
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
9 V- k. B; M( c2 z; T5 u. }0 U6 Z - <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
7 A, f: X" V/ b* ^ - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]2 o' C2 K6 l$ ?. J
- <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
. u( w' o S: k% L. U6 m& Y$ d4 x - ==================================
+ x7 ^, _# t. E" [6 `% n: H - 启动文件夹" d4 b: [: ?! j
- N/A
& g7 s+ P( z/ N' [7 l - ==================================
$ K; o: s% X2 n5 R - 服务! `# i/ i2 Y& B
- [3ware Controller Service / 3wareSrv][Stopped/Auto Start]! F. F) {: ?' ~; u. m
- <C:\WINDOWS\System32\3wareSrv.exe><N/A>6 v' D8 \( s# e* A: F
- [Google Updater Service / gusvc][Stopped/Manual Start]" v) [6 }/ o7 S& Y8 Q1 j
- <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>4 K% M% X3 J7 q% k# ] n4 P
- [Help and Support / helpsvc][Stopped/Disabled]* w! P9 V; }* w% e" l- Z6 v$ @, V
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>
' j8 U$ D$ _0 H, J - [Human Interface Device Access / HidServ][Stopped/Boot Start]
( |5 M- a$ j$ Q - <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>! B7 n4 `3 W4 m3 E/ D6 N
- [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]6 t$ y. g; I) c
- <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>
0 U5 I! D7 ?$ r5 Z, p* ^* f - [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]. N( t! L6 W* f. D2 g
- <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>
8 X0 y. |( X* l7 B: R - [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]* o+ k4 h2 M! K) W S, z0 V0 V9 P
- <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>+ f0 O! \$ S! s3 L
- [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]& ]9 s+ i# k# H( @0 M2 P9 |
- <><N/A>4 f5 C H3 x" d1 U2 g4 K
- [Qvod Terminal / Qvod Terminal][Running/Auto Start]
2 `* |8 J- |- k4 U" ~1 R+ L+ W: w - <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>" H: Q; e0 j9 d$ X
- ==================================
% g- \- D' S, l# H! B8 ]6 P9 F - 驱动程序
& w- ^. v4 ~$ P - [22j / 22jn][Stopped/Boot Start]4 h" \7 \! t+ m3 f4 C+ k' Q
- <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>: ^5 Y' G- i' E. p; K# B
- [360AntiArp / 360AntiArp][Running/System Start]
$ z- Y, o, r: Z# ~( _: S) P - <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
: V! A$ f$ T# f# ]3 h7 u - [43ec / 43ecu][Stopped/Boot Start]) S4 `' A' @( ~/ U/ K+ J- {3 B
- <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>
# w0 w+ I; t: M6 ~ - [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
7 |; t/ J$ R4 ~" K5 \( Z& V6 T+ T* r - <system32\drivers\ac97intc.sys><Intel Corporation>
6 J+ K( x! y3 _ - [Promise driver accelerator / bb-run][Running/Boot Start]# w* }: f$ _4 s3 p% i1 _! Q' E) Y9 s
- <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.>. w' r5 T: l/ F, ~2 Y
- [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]
4 U6 L' T; F3 \6 J Q6 F - <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>1 s$ m+ w6 x) D9 D" s [0 T' a8 E
- [KAVBase / KAVBase][Running/Auto Start]
8 S- {8 b+ S* r% n! { - <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
, l( R7 Q8 D$ v$ ~: q) y2 } - [KAVBootC / KAVBootC][Running/Boot Start]
5 m9 q0 s0 _3 j" N. m, F- J$ d( e - <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>" f( r$ {" p6 t
- [KAVSafe / KAVSafe][Running/Auto Start]6 w8 Z- H/ {- t. {$ N
- <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>& I1 u: h0 |5 B
- [KNetWch / KNetWch][Running/System Start]8 U0 w5 @$ h) ^& A3 A1 U, P! c
- <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
! S; r/ z' H4 K0 x - [KWatch3 / KWatch3][Running/Auto Start]2 `# J; P! H5 P
- <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>, _% F7 u) }' f$ J5 |
- [ntptdb / ntptdb][Stopped/Auto Start]
, h5 J" P" S- w. R. o. [( Y: E5 ~ - <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>, c8 e# ^/ e$ M$ |
- [nv / nv][Running/Manual Start]
0 r& \7 K( T9 f& N' [ - <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
$ J+ F( c4 I% Q5 N K - [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]* j" H) |5 V, H4 ]! d/ `* u
- <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>9 p# w- F) F, Y" p! m
- [DDK PACKET Protocol / Packet][Running/Manual Start]
2 H% v2 T, |& T/ n - <system32\DRIVERS\ProtoDrv.sys><360安全中心>7 f( g2 @1 }) v
- [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]
8 d) e! M* S# N5 k. Y - <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>6 D, e# P5 E4 N; Y
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]! {2 r& j- [9 n
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
: N$ V% ]1 b' Q+ |+ B; d - [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]
8 O; c9 V- k k: ~" ?3 J- r - <\SystemRoot\system32\drivers\RsBoot.sys><N/A>
( l) E) q' j' A& R - [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
/ z& B5 V8 H5 k4 X - <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>. I9 ~' a/ d9 p( n) y' ?
- [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]4 ?1 z7 t: b3 Y# U, h Z
- <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>/ D7 G3 T, J+ S0 E1 a7 y
- [Secdrv / Secdrv][Stopped/Manual Start]8 \5 _/ y4 J: U$ j9 u- a
- <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
6 a" K$ ^" n' Q2 u. j6 M' \+ ~; i1 ^ - [SATALink External Device Filter / SiRemFil][Running/Boot Start]% r# k Y7 q3 \+ H
- <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>
' `' l8 Q; n- K" x+ }' i/ ?% A! x - [System Restore Filter Driver / sr][Stopped/Disabled]
6 E9 P7 u. K, l - <system32\DRIVERS\sr.sys><N/A>
1 \3 G! P% x& Z" o - [TesSafe / TesSafe][Stopped/Manual Start]
; m) _8 M: w, `4 B4 U - <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>
" r2 j. R3 Q* s# A; G$ A" ~7 x - [System Services / unzxzsrs][Stopped/Boot Start]: F% f+ j. F& E" E5 F, D7 O
- <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>- l( m! i" u$ A, q
- [ViBus / ViBus][Stopped/Boot Start]+ ]" K; P! S W! ?4 T7 Y; l
- <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>
! W V, D0 _/ h1 x, N - [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
& t( p }: \& o4 ]) v - <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation># J2 u9 E N1 _
- [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]$ c) z; u9 s1 H# }
- <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>: H7 ~9 a' o/ a! v8 m' `1 K( |4 a
- [ATI Extend / zhibmaso][Stopped/Boot Start]
( H( [% t) B0 i: r' B! u/ W - <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>$ f( `% v; x: }
- [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]0 M' c2 C0 U! `7 Q7 w
- <System32\Drivers\usbVM31b.sys><Vimicro Corporation>0 a9 k( N2 X% M- w B# ^$ `- X" c
- ==================================) J1 I5 d2 k8 G/ V3 M6 P& [
- 浏览器加载项
i3 [- C+ N; K& @$ t& { - [Google Toolbar Helper]
' W0 k, G& _- @- C6 p4 n* z - {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>* h8 U2 n; c4 E4 o
- [Google Toolbar Notifier BHO]& \& a. X0 L9 p; o, M. k& \- y
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>7 i) A1 c5 P' }8 V8 F4 \9 J, e
- [SafeMon Class]! X& j8 v/ } y6 ^8 L$ H& O" ?
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
8 G! }+ q( P) }$ O' V - [kingsoft browser shield] |( z$ m% P% T- r- _
- {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
" l6 C8 _2 v) S4 V - [IEBuddyExtControl Class]
2 {2 b* e6 s& g - {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
! p* m1 D) T: l$ g9 Q: c, D9 @, E4 | - [Zcom 杂志]
# d- d4 {6 m x! [) W - {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>
1 u* N3 o0 E7 a - [&Google]
$ A+ r+ g3 n U4 a4 ^ Z* P' q - {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>7 `4 C% E+ j; o1 e: V7 h E& o7 B5 i
- [KooPlayer Control]+ v. T& P+ p5 k" a; }2 ^
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
1 C+ [8 t8 C7 a' ` - [Shockwave Flash Object]
) }1 X; n; Q/ `9 | - {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
/ p3 T0 a) h2 i" U! a1 e( V- S - [KUpdateObj2 Class]
6 E0 J/ H& l" ^3 `" F0 W - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>7 q1 `, r/ |0 |$ ]; N4 M6 v
- [Google Script Object]
, v' R+ X( ~- m/ Q7 w m) Z - {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
5 ?, m0 E. C+ u" L. k7 _ - [EWA Control] K( p) K% b" J0 r0 C, |' W$ u7 I
- {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>2 n3 X, S6 f( g3 \5 ]
- [Windows Media Player]
) U/ `/ A: E' @# _2 Y& P$ D" [1 _ - {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>1 x3 V( g/ i0 ^2 x$ R% o9 M! N
- [&Google]2 }1 j; N8 Y0 F$ I9 E
- {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
$ N; }5 T: I" R6 Q8 C5 V b - [HTML Document]
; ~ o6 [. h9 l/ h8 A! N4 w- m - {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
9 y' f0 h! y) c3 p - [DHTML Edit Control Safe for Scripting for IE5]7 `; ~9 s* s9 i8 E$ ]
- {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>, X4 u, ]" w4 `* \
- [RealPlayer RAM Download Handler]3 c1 _6 X" i5 s/ x0 Z
- {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>2 h2 v4 H' e$ P: p
- [IEBuddyExtControl Class]! W& R' n8 O4 B( U }
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>" W# }3 r8 r; ?3 D$ ^2 q S
- [XML Document]1 |8 F ]2 @$ ], ]$ b" j- {
- {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>2 M9 v' t' [* j( Q1 a
- [HHCtrl Object]
4 M* v/ J* l5 A6 r& e' Y - {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>1 P- n R, o6 j
- [Windows Media Player]
- R, v/ e& g1 K7 S) y" a/ R: x - {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>- p' m8 k8 E- J
- [Active Desktop Mover]' Q6 n: X& z [2 ^
- {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>0 y8 M( F7 }. r- o
- [360SafeLive]
" x @: U% d8 O - {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>
! H! S9 d) K9 C% M' ^" `/ g - [Microsoft Web 浏览器]1 J" l5 U, }- V- q7 l) G/ ^
- {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>2 [% F( C. C4 w- t! d6 ` d _
- [Browser Enhanced Objects]
7 L% b- Q& P) I% R- I1 @* S, T - {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>3 H# W' k! l* m* [1 `2 C a
- [Google Toolbar Helper]) b: n, A( z' u) d
- {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
8 Y1 j6 i- I5 G. O- v/ T - [Microsoft Scriptlet Component]$ b0 Z" \. l. ?% t" t% ^9 q! B
- {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>; y `! m K8 u7 x2 s( t9 p# X
- [Google Toolbar Notifier BHO]3 a+ r+ T1 C8 g
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>$ I3 p; B9 s5 d1 k1 a
- [SearchAssistantOC]
3 B4 u* s @7 E# H - {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>' I8 P' s( n6 Y K* ]: h
- [SafeMon Class]
5 w1 G8 B3 L/ P" ?1 w - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
8 x2 a+ V1 M) J% f; Y" t& [; r* Q - [RDS.DataSpace]
9 s& J) z7 n' ` r5 ^/ ~6 p - {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>% F; ^. Y. f0 A, o$ q, j Z4 j# n
- [KooPlayer Control]
6 O' `( J2 c6 ?1 _& E" _ - {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
3 l; m# N5 ^% Z: T* A6 K - [AUDIO__MID Moniker Class]
& l& W: x4 @1 Z7 Z5 G3 \1 H - {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>, f) Q! D ?, z' ~' ?8 G0 Q9 E2 L
- [AUDIO__MP3 Moniker Class]4 S- F. K$ m7 ~! F+ ^3 b
- {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>) Y6 H9 y% V* j+ J' D. S n
- [AUDIO__X_MS_WMA Moniker Class]( ?" c1 L5 D7 L3 o/ i" J# c
- {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
0 H0 o3 M6 K' h# `+ [2 |7 |. K - [VIDEO__X_MS_WMV Moniker Class]+ k$ [! M( A4 E: Z0 p- ?
- {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>! l+ l# Z6 e$ F. S
- [RealPlayer G2 Control]. q' f5 e, T/ s& w3 k
- {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
+ o' W( v0 ]0 W" h0 z* ~ - [Shockwave Flash Object]
' v0 e4 v ]5 [8 z - {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.> k- k+ G, O& m* a6 e0 K
- [KUpdateObj2 Class]& w, R c9 i+ Q: D. _- e
- {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
% T2 x6 z8 Y+ P _, T/ q - [kingsoft browser shield]
6 F8 V5 ?$ `0 o1 j/ R! c - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>$ Q5 `( Z+ }2 ^9 ?& A* r2 D9 r2 `9 z
- [PasswordEditCtrl Class]
& d4 I8 R) F5 |- b7 H - {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
8 j9 M" M4 s5 q* K5 x( d, @ - [QvodCtrl Class]
& l4 r- O& B% \/ s5 a0 U' Z3 _ - {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>4 D; C/ e; f; h/ g& c) [" ^
- [&使用超级旋风下载]+ b6 U# ]# ^7 i# |
- <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>+ |8 k3 i$ r8 J7 \, V( Y
- [&使用超级旋风下载全部链接]' ~" y. W* H2 i& U
- <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>9 \' ^" e8 @9 F$ z
- [使用迅雷下载]: m* c& z5 }2 |/ v6 o1 i! G
- <, N/A>) M: O) n. [# r% q ?
- [使用迅雷下载全部链接]+ ?/ `& A" Z+ a
- <, N/A>
1 n4 M- T2 U# }, b3 v, z* z - [导出到 Microsoft Office Excel(&X)]
9 \7 {' p2 ^* B( }4 u' G; j - <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>/ h* a6 G/ \' a+ V4 K
- [添加到QQ表情]
( q& ^- _) Z% R - <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>! J8 J) }/ \" v- p# ]# c) ?. p
- ==================================
$ Z E @1 z! Z0 s, J. v! j - 正在运行的进程, G/ ~" r- u4 M- W
- [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]* V: |& A# m( v. E4 O/ E. h
- [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]' h8 x: H: _6 S: Y1 {
- [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
) m. a2 O0 L1 w- l& T+ R - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]! X, |# j" u9 A1 w9 q
- [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]% I2 b, t- T$ ~9 b; Q* z
- [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]! C$ G8 R" a5 E, P
- [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
" l3 |# G0 l% M/ G7 H5 ^7 ^ - [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
5 _! {$ x/ O3 a- P5 W* x - [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)], S4 G3 Z Q7 p9 @2 Z/ v7 y3 S
- [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
: q5 g/ ~- V5 Q) L - [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]! e. ?& q$ Y0 D
- [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]5 w% z1 Z6 Z, O0 Q
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
! s- Z5 J/ t$ k9 \ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]. ]) f# L; A' A) G3 s
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]2 S+ P- _+ n" V E0 b. I
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]6 N( S+ f5 Z) v; h& H5 L1 |' S
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]
$ y1 ^+ L, ^7 h/ @( s/ `5 P5 N - [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]
2 k# L$ Q( E% b) {! N6 Y5 M* u, e - [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]; x- h- d3 o! f& A% B# T+ e" _/ k
- [C:\Program Files\WinRAR\rarext.dll] [N/A, ]/ t N* A Y; j5 o
- [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
- ~; ^8 `- X6 }% b X. L4 o% S7 h - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]! V4 s& R2 q! {! U
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]2 [% P1 T6 y8 x, y5 ~' ^$ h9 G
- [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
4 f, D u1 Q6 F8 t- F - [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]* g0 a( k# {/ ?; H6 }2 D
- [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]
3 Q$ _) W3 H! K3 z# l- |) d! f - [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008], N7 b6 B! j2 e
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
- O8 ^* J1 H1 {$ L4 j7 ?' Q' z - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
( x/ I' R) R2 {; c, B - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]. a/ |/ V+ g" X% c4 s
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
, Q- M7 J" T( s A3 z+ }8 r9 w - [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[: ~+ L2 h' L9 r: k7 J - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]& ]* C0 d; U2 j+ ~
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
( K% ~$ V0 f3 W7 N$ _+ k - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]* U. `* N& ~3 }7 R4 ?
- [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]$ \" J: ~5 W9 b* d3 m
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]6 @: Y7 w+ p2 F9 g& J" l
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
- S/ \$ o4 M3 k" D1 G9 E - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364] h9 H' z( B; V0 i* k$ V1 n' f# m# f
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]0 M* p' R% u B
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]3 z. n; z: j% @# k
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
, L- y6 ?, c" p7 a - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]% ?2 i1 F, ?! N0 Y
- [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
+ ^; ]$ M, M& D' c - [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]+ F1 w( n, B/ F- X
- [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]; C5 c1 |. `5 b* @- Z9 \, \1 D
- [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]2 e' Y- H( J1 S" ~
- [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]5 L3 E- M5 N) ?6 l; P
- [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
; _5 [+ I; n1 Y# ^ s- D0 k - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
+ K; B1 H# B ^8 [0 r) E - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
8 y3 ]3 c; k ~" ?. t5 N - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]7 y6 ^. `) e- }# X/ p1 o2 s A
- [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]& T4 |) ?2 Z+ u7 C1 _; x4 j
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]& h2 l3 Q9 i! ~# z
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]% J2 c z2 q) i( B; z# |/ j
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]4 K$ y1 O, T3 K7 ]
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83], S6 O: c; [6 D+ Z2 I( V/ _
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]
1 E4 V) q1 t" b5 k5 N - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78]
g* s$ c# k' Y4 C" a* ^, J0 r - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
. \6 L* N! k: D+ k& ^ - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]! V& g: p& j1 p
- [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]4 F: H% v+ M* S z7 o9 t" r
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]1 z3 m5 d4 ^ S5 p
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]" A* Y+ C6 o4 e
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]2 Z* J8 F1 A) s: g( m8 N& B8 L; l
- [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]
( H: e, l+ G1 |$ w - [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]
% J7 C% j# z* ?* Z - [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950]( Y |, z5 j3 ^
- [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]
5 l' Y8 _4 z* I0 l+ X) D6 U0 z - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]5 R$ W& q: z! g+ ?* E- M
- [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]
' L- D% a* @( B& f7 K1 F9 w - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]8 F. M% [: c7 m, h0 K5 j
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5] q# |3 u9 `8 y* V# y
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]( i' D' G7 x' |2 B5 a: x, y5 [: O
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
* s1 `/ W# w4 z3 p# s - [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]
. q6 T: Z2 {9 i* ~, K+ H) C# d - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
, n/ d' v% K# u, o - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
1 a' k. _/ {8 q$ |# [ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
% s( [$ a+ I- P5 e) S( S# q% [ - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
( S8 D" u' c5 D) J/ v' a8 S6 b - [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94], [( q& s) M S- z1 T3 l6 e! S
- [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]
9 V( W( |+ T' g2 ]" {7 R - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001] a* S+ i6 W; R- z/ A
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
* Q8 L, [7 n; t( D - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
: }2 K( \8 }: {0 Q/ u7 ?( _% D! p% m - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
; Z$ o2 |. n9 @# b! B- E - [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]. |* ^# N1 N2 ~
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]7 p( D( E$ l0 H
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]$ R: M+ n, f" U- T _, F6 E
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
2 h( S8 Q4 b1 Y$ u) e - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
8 T$ C6 @9 l! X - [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]: |2 ?1 o* B8 {& T; t# J* y3 v( W, @
- ==================================5 M2 o* Y1 x, z, C
- 文件关联5 b1 M- o2 \/ v6 n( |5 R% e2 S
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
$ g1 \" {+ H$ `( E; b - .EXE OK. ["%1" %*]+ x5 ~& B) E+ O4 }9 n% I7 b: s& a
- .COM OK. ["%1" %*]/ o! y* B' ~% G V
- .PIF OK. ["%1" %*]$ q8 X. a9 ^8 W' } L7 w
- .REG OK. [regedit.exe "%1"]9 t/ M6 Z% a6 e# r2 F
- .BAT OK. ["%1" %*]
X; \1 A+ t5 k/ q - .SCR OK. ["%1" /S]
1 W: D0 u8 a7 k T) M) O" m - .CHM OK. ["C:\WINDOWS\hh.exe" %1]7 J# A9 }- E" E/ F) g& M
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]: Y9 B$ h8 o4 G& z8 j( G
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
Y5 Z; C8 V. }# V- N w& z - .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]; |' |. p+ t+ g# c! e' K3 G. p, |' _
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
7 h& P0 Q" W3 u6 f8 n6 ~/ W( C - .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]) r# O% Z7 V+ n4 h3 ]) }/ `
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
; j( K+ g8 A$ @7 N( ~ - ==================================. I" I' w# J; I% r" L/ o$ y
- Winsock 提供者
z/ p' _- C N6 ?8 K, n - N/A
9 V& ?" t# d6 E2 F9 u3 } - ==================================
, u7 J0 U* G0 s% @ - Autorun.inf
4 H r/ O! M9 m. g7 l - N/A
' u3 f& o/ I5 P% U3 W' V' w - ==================================
' J! I2 ^+ L8 E# q* F, N$ U - HOSTS 文件
' A$ ?: o& f% I- ^3 H- A0 J5 f - N/A' L& C: E3 X6 s6 V, @7 M7 g- S3 J
- ==================================
: l" Z8 I: \4 v3 Z - 进程特权扫描
6 p, P, q: O2 A, l - 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
- S6 l4 e6 g! ?' x. I' L' _" { N - 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]
6 u' C) ?0 i" s* J* e - 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]
9 [/ s+ c/ e7 g. G6 ^& u9 @ - 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]* S y$ Q6 m& ?, M+ }
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]* R# N& ]: k' Q `5 @3 r: v
- ==================================1 M0 y( A, `* A1 {# Z% R0 g, P0 p
- API HOOK
" ]5 M& {: W1 y, A - N/A) V, y( k$ ~5 |
- ==================================
8 y% e2 o: w# E - 隐藏进程2 e# r/ p( X0 t* D# G1 i
- N/A/ x- j8 v2 g" z2 m4 y
- ==================================7 T! m. M0 w: q# y4 I( U8 T7 s
- 2 d- f6 B' O8 T. P
复制代码 |
|