|
- ; f3 |+ ?7 t! q# P% ?* A
- 2008-05-22,20:37:43$ P0 @9 e; o9 n0 i$ ~) W' J
- System Repair Engineer 2.5.16.900. h) d. |& n1 h9 G7 w4 _: V
- Smallfrogs (http://www.KZTechs.com)& K8 g; x5 t) h# p2 C
- Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
" h5 j3 z4 q% s W - 以下内容被选中:( J/ ^* X2 V- `3 Q
- 所有的启动项目(包括注册表、启动文件夹、服务等)7 S6 G& q. s$ H" W
- 浏览器加载项
' _( Z0 ?6 L8 W4 U K: F - 正在运行的进程(包括进程模块信息)
5 p9 ^, f. b. k9 |1 W0 N - 文件关联
' ?) ?6 [) c& B3 |, ~ - Winsock 提供者1 o7 T) f% U( s" P- Z! }
- Autorun.inf1 k2 f# P$ m. ]! k) {
- HOSTS 文件# d( y& b2 W, K! U; p
- 进程特权扫描
6 Y7 i" {" b- x( x" r5 z9 b
5 C1 z1 |: A% K; Z& ?; N# p- 启动项目
5 o4 D3 n9 r4 t) p5 l# ~/ z2 Z: p - 注册表
! H6 a' w- p9 s& `$ b) `6 F - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
: G4 h4 ]" i! A( O% y* J5 K - <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]( ~4 D9 }5 ^! J! ]# g5 L
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]* E+ i, A, \3 D! ^7 A# U
- <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]7 l: R/ R9 Z+ O
- <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]3 ]0 T" P F, Y% e
- <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd], T- g. @& @5 q; E. y, T9 D6 O8 Q
- <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]
0 O P( B2 \) `. U7 K0 K - <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]6 c3 C. g& e2 A/ U% i& z s
- <PHIME2002A><; > [N/A]0 v' ~" D5 k) g( @3 P
- <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]+ m; F9 Z- ?; [& y5 D: A
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]$ c6 h9 M0 R8 f3 @7 Z
- <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
D7 `, O9 j& i7 F2 W - <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]
6 b% ^# ]2 N8 F; j) a* u - <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
1 b8 N- z8 T: O2 a" n2 [ - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
" T/ b) A, S: I& t0 [1 r6 l! ~- q - <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]0 N2 z0 q5 D8 O* Z, @4 ?
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
. U( F( [& V8 N1 Q" N - <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]8 J; K( i' Q6 O! z4 [
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]; A1 C% w5 `0 N
- <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
& [* {6 V* a0 v+ [/ m( @$ X - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]6 t0 d; a) v9 G1 Q+ `( I
- <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A] w. p, w: H ?! |' \
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
" L( Q, }# ?1 X- W2 x - <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]: C( I+ m* {, ]$ n. Z& u2 t/ w
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
1 @( _ z+ F( U( u - <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]7 D& n! b* Y. W* ]5 h
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]8 j i: Z% Z" x% V8 A' l2 K5 C
- <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]3 F, n5 ^% _) J6 N
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]% d! w1 K' q0 u6 Q2 _8 \' E
- <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]2 [, _% l! y; R/ v2 }! F" U6 j
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]- \6 u+ [7 o3 |2 ]! L* G
- <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]' @) {) I, I5 R5 ^' v& h
- ==================================
/ Y$ ] ~) G! o0 P9 { y1 k2 G - 启动文件夹
# S8 K% W7 g2 w% M/ V; L - N/A* ~7 v K2 p4 s0 F
- ==================================
! l. Z8 l0 w( \# i1 N: _ - 服务
& ^+ A; P# Y/ G1 I5 p1 G - [3ware Controller Service / 3wareSrv][Stopped/Auto Start]( m* L: i( e7 w- s: [ r
- <C:\WINDOWS\System32\3wareSrv.exe><N/A>& Q U. X; h6 Q, } T1 f
- [Google Updater Service / gusvc][Stopped/Manual Start]
' b% O0 ^; q# B. B& ?; j( {0 l - <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
. f5 {; ~% H$ P7 l6 d - [Help and Support / helpsvc][Stopped/Disabled]: \+ P; [; s( k
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>% E" C) z% U# j& O
- [Human Interface Device Access / HidServ][Stopped/Boot Start]
2 D$ h/ W3 o3 H- {7 G8 A - <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A> n* ]& E C$ y+ x5 M5 @+ j9 w% v
- [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]
1 ^4 j; R% T3 g& h- N9 P - <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>
' ]$ o- c" E7 @3 G' ?; ?2 `" G: j2 m - [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]3 w+ L3 L% P) m3 M1 M: X
- <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>! D: k* B- R, V* k/ Q
- [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
" b5 K) b, I- d! ~3 b0 Q - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>
0 _* u4 o* s7 v5 x, F, y1 M - [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]8 u+ k) [8 m) i+ T0 s
- <><N/A>
3 Z5 J; `2 _$ Y1 ~9 L. I - [Qvod Terminal / Qvod Terminal][Running/Auto Start]
/ Y3 u6 E) V/ \) w. b - <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>
& g2 M- {) s3 ]9 N9 ]- P - ==================================. `/ [9 I7 P2 N
- 驱动程序
/ _& L# y& W; y' j/ w$ Y9 m! l - [22j / 22jn][Stopped/Boot Start]/ Y# \1 p3 }3 R9 D; N' k
- <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>
7 l3 c: Z2 S" h: N- ]9 O - [360AntiArp / 360AntiArp][Running/System Start]. v7 r$ J( k8 h) Z* t
- <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>7 K; R0 ?# r, B: N% q
- [43ec / 43ecu][Stopped/Boot Start]
$ S" x6 y6 r3 o5 w; |* J3 d, A - <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>1 h. }* N8 [- w
- [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
. D2 [% P0 W. f, h+ p' v+ I% \ - <system32\drivers\ac97intc.sys><Intel Corporation>4 I w0 l) P/ A# X3 y% P1 i7 Z
- [Promise driver accelerator / bb-run][Running/Boot Start]! L: K& J3 X9 `
- <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.>' J* X( B% T+ Z1 _* d6 x' b
- [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]$ W0 f0 q! Z1 X/ M; r
- <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>1 e0 w3 j5 ?, q ]. A# C% N
- [KAVBase / KAVBase][Running/Auto Start]0 i# A: `1 s5 `$ A9 I
- <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>% g( E% |7 t, J2 ]9 O( j
- [KAVBootC / KAVBootC][Running/Boot Start]
$ N9 Z2 O# I% Z0 f - <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>
; V/ s) B) Z6 x) l1 P - [KAVSafe / KAVSafe][Running/Auto Start]2 k0 S5 [$ W$ u: \; j
- <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation> w! Y% }/ A& _6 ?
- [KNetWch / KNetWch][Running/System Start]
+ i8 ?: _8 t5 q6 a {: u - <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
7 u) `4 Q* c' S - [KWatch3 / KWatch3][Running/Auto Start]7 h8 g0 i: }. g' ]5 ], J: o
- <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>* ]% l8 g, X! S. X/ V' d' g+ k
- [ntptdb / ntptdb][Stopped/Auto Start]
# J! x8 B2 F, h% g8 l - <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>
8 o! |& x4 K3 U. H0 D, i - [nv / nv][Running/Manual Start]
. z Z) {) a( C" r- S1 B' B - <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>+ C# Y, e0 s$ h# a U
- [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]- p2 P2 L9 L" c# ~8 m
- <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>: m- s1 T" x6 l" t8 X; e6 e
- [DDK PACKET Protocol / Packet][Running/Manual Start]
0 h4 p9 R8 P9 l0 A* G! R O( F - <system32\DRIVERS\ProtoDrv.sys><360安全中心>4 p9 u5 n: l3 O( e' Y+ l
- [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]
7 K7 j4 S; |/ t; r" o3 Y: @ - <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>6 P$ @- R4 j9 ]7 `5 H
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]) h% n" z) x$ ~0 K Y K' l( C
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>+ {- ~3 k1 X/ y! A2 @/ @* w
- [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]
" X {* B/ ~4 t" J - <\SystemRoot\system32\drivers\RsBoot.sys><N/A>$ H$ n B5 }' V F' h
- [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]# g [2 j5 ~6 a$ i- N8 G& w
- <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>3 ~: v$ r. b% W# r* Y
- [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]; \9 Y# @2 [$ Z" y n8 _
- <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>7 h* K: }' w0 @& Y1 Q8 R, x
- [Secdrv / Secdrv][Stopped/Manual Start]5 N3 |% T$ K# n* E. i: f
- <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
' w6 Q3 A8 ?- T5 z - [SATALink External Device Filter / SiRemFil][Running/Boot Start]
, Z5 v, R8 a, }; a - <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>. |- x" u& a! e5 Y7 a2 R
- [System Restore Filter Driver / sr][Stopped/Disabled]5 A: e% I9 w! d. k1 i
- <system32\DRIVERS\sr.sys><N/A>
( ^0 U7 O( a) z: y5 D) Z7 {6 u - [TesSafe / TesSafe][Stopped/Manual Start]
5 S/ ?, ?! A) |! } - <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>
+ k' \) @' X( z) }3 M2 _! O% C - [System Services / unzxzsrs][Stopped/Boot Start]: x' l+ f' S# Z( w% d
- <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>, y5 u" M" I# p
- [ViBus / ViBus][Stopped/Boot Start]
|3 B% }9 j, i' ~ - <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>1 {$ i8 E& y) N: I9 X. j/ r, b
- [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]3 b; J2 c9 F' y$ y, e/ h6 i
- <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
# I9 z$ _) m" j5 ?& i - [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]
; C2 `/ N" m" `; G( T6 A% A) l - <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>0 y# |: p9 y+ O7 {, p
- [ATI Extend / zhibmaso][Stopped/Boot Start]3 ^1 D9 y W, o
- <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>7 D) G! x" G8 O
- [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]$ h4 O& R8 s$ |/ m2 s; m
- <System32\Drivers\usbVM31b.sys><Vimicro Corporation>. i7 Y6 t+ Q1 f- A( g
- ==================================8 a# w' s6 D3 O# s5 `
- 浏览器加载项
1 Q2 q5 |: z* O. T2 k - [Google Toolbar Helper]
% [* Q; w" ]0 Z R' `3 ? - {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>4 k3 \ w/ Z, l9 }( @3 [1 w8 z% z
- [Google Toolbar Notifier BHO]
1 I4 V$ B. W, A. J. B8 n - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
# A' Q# A$ n6 V - [SafeMon Class]% @; R3 O" V, d/ g/ q) {. g5 }
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>' O, _- ?2 l/ z7 L, y- B
- [kingsoft browser shield]
4 G/ e! j8 t0 q* S- U6 q - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
) Q2 E0 D$ g+ r - [IEBuddyExtControl Class]2 p" q* [1 |% k
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>3 x; u& Z2 r: I
- [Zcom 杂志]6 p0 r9 c' X& G; V ^ b
- {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>4 a: {7 e5 p4 z- g6 M8 E
- [&Google]
+ ]3 \0 ]# Z i9 i3 a( u8 f: _ - {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.># W3 M( ]: b \2 @: p7 W
- [KooPlayer Control]: d, b/ T7 J% d( J. {$ X( Q. n5 i
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos># b/ r( K7 w8 ], L3 B( X, C
- [Shockwave Flash Object]! j4 ]+ {/ ]7 o4 B' H: i/ H
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
' G5 a7 m3 d. l/ _& {4 S% ~ - [KUpdateObj2 Class]
! k" {+ o; Q$ Q - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
- D1 c. g+ g& J5 f% B - [Google Script Object]
, s, M0 M! p/ c0 d! r1 p - {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>9 a# L/ h' w% s4 M( r
- [EWA Control]3 z# e2 n. l5 X2 P% |# z
- {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>
7 t$ S' h: b' r+ D9 s - [Windows Media Player]
' V) t3 B* S# g3 S$ ] - {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>* S7 h& m5 Z4 D A ]
- [&Google]
* D6 |9 Y$ K6 y; |% x, l4 n - {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
2 |& a% s# ^4 {$ o! Z; q - [HTML Document]0 v5 G5 C2 L8 E) I' L
- {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>2 z5 f9 {) x- n4 |' V2 N
- [DHTML Edit Control Safe for Scripting for IE5]
* v6 T9 V& T4 P' _" U' N - {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>3 M6 t% s; [/ Y! [% `
- [RealPlayer RAM Download Handler]
0 g7 F+ O1 x# G - {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
1 a+ [" l4 U/ q* W - [IEBuddyExtControl Class]
! A1 | Y. C( F6 w# @0 ` - {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
% a) M, @+ d7 D! _ - [XML Document]1 v# w% j7 e( c" U0 k
- {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>4 K% Y( j! k: I3 O
- [HHCtrl Object]
/ m2 C- _! X! i) h9 v! z7 E - {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>* w4 @# W8 F* H! \/ y: M0 ~
- [Windows Media Player]
' D/ o0 [- x; [ - {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>4 Y* p1 z% c$ ]" n
- [Active Desktop Mover]' u7 }7 p2 h: ]! X E0 d- J
- {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
" W% _) M% a5 E: b8 i, b - [360SafeLive]
# \( T: \8 ?+ O$ T" y - {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>5 d( p& i7 K% R3 e1 e
- [Microsoft Web 浏览器]
4 r, P) C3 E5 Z4 Z. l% O - {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
8 y, H+ W1 z& s2 S* S - [Browser Enhanced Objects]$ B$ o6 i( p( R+ b0 i" O4 {* |
- {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>
1 @9 \0 \& P: p, p- e( b5 K - [Google Toolbar Helper]
6 v6 N% E7 ]) n! l+ q% f" o) c* j - {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>& v% Q" O) _- c" |4 ~
- [Microsoft Scriptlet Component]
" I3 b$ _5 u7 @* ^7 Z - {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>3 M' r2 M$ _6 @$ U8 @6 h
- [Google Toolbar Notifier BHO]( O4 N. i: H# r' h" k: q
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>; `: | M% E% v$ c0 B& _
- [SearchAssistantOC]
4 s; `/ q1 k6 Y) p' E+ o9 L* D - {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>. B3 }% [$ G9 ^! `& B8 }4 J! s" ]
- [SafeMon Class]
5 k3 w* J$ h& H# L$ s - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>& x$ g" V3 Z7 B( h) ~; t/ o+ N
- [RDS.DataSpace]
* l! f4 F$ u. A( W* ~ - {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>3 e) v2 k! t+ _( Z2 U& S
- [KooPlayer Control]1 g0 b7 q6 z# Z$ M: P" H
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
7 o& j5 y6 B0 ~7 b2 W7 m - [AUDIO__MID Moniker Class]- N$ k( i0 c7 c
- {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>( m! s& X; b7 x! l g
- [AUDIO__MP3 Moniker Class]/ E. Y: [ ^( N
- {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>; h+ o% w: z' y# L" [5 c8 W
- [AUDIO__X_MS_WMA Moniker Class]8 B! z4 i9 y5 G' A. q* b' c
- {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>8 C7 X1 W: _8 W; z: Z
- [VIDEO__X_MS_WMV Moniker Class]
6 `6 {% c- o, J6 U. w4 {7 u! e - {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>; a6 E# g; I- _6 | F! c0 h
- [RealPlayer G2 Control]
4 g/ Z. N- U+ }. t+ E$ P! F; Q - {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
' O) m+ }6 ~4 R% @ - [Shockwave Flash Object]
- q# @( A3 E: x8 d) ~ - {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>$ M8 I# z7 j, _% Q
- [KUpdateObj2 Class]
7 ]1 f# D# Y; y. r* C4 `8 ^ - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>- l; s4 [9 ^" v$ S
- [kingsoft browser shield]" T' {7 ~8 h: m+ V# o( c# F3 X: O( U! G
- {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>) ~" |' r k6 `+ s' ]
- [PasswordEditCtrl Class]
$ e- C2 T3 A2 s9 @( ` - {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>6 ?6 W6 E. ^/ m1 R* }$ S* w$ y) A
- [QvodCtrl Class]7 C1 x' c& r: m. ~# [
- {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>
1 ^ p7 y. q/ T4 O - [&使用超级旋风下载]
! ~$ V) T; M) `* l& C - <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>/ s9 d7 p- _* [7 [% X
- [&使用超级旋风下载全部链接]
7 i0 m* g# ^" s# T% ?6 [2 v4 p; z - <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
+ p O1 W7 Q8 H) W - [使用迅雷下载]0 A z3 c8 s# h4 Z( t7 K
- <, N/A>
1 n7 L, y- ^& Y - [使用迅雷下载全部链接]
G2 p0 F- B( V' \+ ?0 E - <, N/A>5 N" `5 s* J8 P
- [导出到 Microsoft Office Excel(&X)]
2 ], O- w% O4 g5 g - <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>& ~6 R' B9 |* {, r) [2 @9 @
- [添加到QQ表情]
0 T5 X' h8 y( B - <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>' Q" v# t9 [1 L' ~" ^% f3 v
- ==================================: U# U: S9 g, p2 V7 Y
- 正在运行的进程3 j% i- }; y' L# C4 A
- [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]7 A! J1 `8 S! g) Y9 r$ m
- [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]8 y `3 H/ U. n; |7 l
- [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]" X3 g/ P, Z: x- `/ V& x
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]- b3 D, n! u, U- |
- [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
. l3 }0 K$ s3 G t$ U2 g! r - [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]8 V- I. L1 n* |" M, } ^, L# O
- [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
! G" u* L! u9 Z: ~ - [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]% w! b" l! W7 {0 Y# w# ]/ v5 R' O
- [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]# N8 R0 a, u& M
- [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
9 }) {- d- z8 ~/ @/ D( i - [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]/ t# P5 q3 v3 Y% I) G
- [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]
# ]0 V8 W w7 M$ T# P - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
! B+ C4 q' H7 Q, Q& D8 a - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
. C" h8 D- y' q! ~/ F- c# i* l! b: Z - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]1 x3 P8 t* z0 b$ i) H9 U
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
& R) J0 z" e. B1 ]& [ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]
, M4 I E' b+ N$ w0 T - [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]$ | B: S% }2 T% M
- [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]: O; L) }! N4 ~
- [C:\Program Files\WinRAR\rarext.dll] [N/A, ] M) }* W; q2 D0 m; j1 z
- [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
- u9 ]% y( a* U3 {2 T! W - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
2 Q4 Q* d( t( C/ N9 |' @ - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] T* d$ o) g h) i( ]6 G
- [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]1 d! \1 y8 [" N- }
- [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]* u7 Q) j8 ]# S# c# m! j/ A
- [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]- e p8 o! F. X4 d1 w
- [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008]6 I$ r# T6 b s9 }/ x( g
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
2 i" F3 i( p! R' x1 _ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]! y9 C: ?, y3 m' w
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]1 w; z- C4 O A/ P5 F
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
' Y0 r3 k9 N b$ M4 i - [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
/ A: X5 e4 R, |- j - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
/ B( V, v, O0 e% a - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]& L: n' g; i- V( g8 j5 b0 W
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]5 a& z0 A* R& C9 o2 o1 l( J
- [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]9 l! w- |3 Q/ J3 x$ b
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]+ c! L( c8 ~2 d8 Y
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5] W) H2 p( {- f' `$ s
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
6 N" V! L% q. k& J4 c3 T( \ - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]
9 |+ `) l/ \4 z6 {5 l/ Z% s) e3 H - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
8 o f9 J ~6 R; m6 V- b2 _ - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
. ? }$ z( }( d ` - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
1 K" i& P: S8 C2 L2 U: ~0 S - [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]- ~' A9 ?1 z+ ^2 l/ z/ J
- [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]8 h) }9 c" }9 M2 z
- [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]3 v8 U8 T% ]; {- ^' V
- [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
# g" E* ?. s' @! S2 T+ @ - [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
1 ?# q* H# h' L! R0 i - [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] j6 v6 G# N) o
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]3 u. }+ b( d! O6 b) U6 ^( e" s
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]3 r/ a' `# c& j' [
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
# s4 v. g* E ~* k9 f - [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]
2 l8 \* {8 x7 Y3 l, I' { - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
, f! L& {) M& X' f- H/ X6 Z5 r - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]7 q0 ] L, C; [; R9 z. ]% t
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]# S- U/ z- p! _3 ?* f
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]
1 i! _: @6 x, B' I9 V( |6 _ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]
3 p$ p! w2 a, w1 r1 Y - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78]4 s/ l, J6 Y. v# ]4 v8 T& X/ D
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
- h" L* { b: e+ j5 ^% N* d - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]) q7 P; s0 ^' n" ?
- [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]4 a+ ~. J: L3 ^5 U' d
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
2 z. ]/ R. d) u4 } - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
% u3 E. n/ |! z: n( U1 q# b" Y9 ] - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]" |! k! \4 A. a* f* ^4 T5 E
- [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]) s# y/ u2 K, R$ ?
- [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0], V9 z M0 Y) Q* {
- [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950]! y% @: d& l. V
- [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]( U, w5 k% [% d- s- |
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
J2 B; W2 a2 o" P, \8 ^ - [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]
J3 D( z- T! h, N" C& w( J) [8 x - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
! F, \. N/ Z6 u V, s- @ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]+ b: G$ ^8 {! z! l2 _
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]6 Z. ]: Q6 [4 i' |4 K; y
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
* F- @) @3 l# a5 Z. e- g/ ~ - [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]( P3 U* U4 s# A) t. L" K! O
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
% W7 e/ k* o' a/ V - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]' C; T) _5 B, B- Y& K; _
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]; A$ X9 q* I+ K# I
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
. f- j; G# ] G- p# z# G - [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]" @- N9 M3 y- o9 D$ N
- [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]/ j3 j8 K8 M# q3 V
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
- G1 A9 ~; Y1 O. _3 Z9 ^' ~ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]9 ?+ u5 n, S9 Z. ], G
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
/ J& p* o; i6 o' H; F; A6 a - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
5 d" y5 F+ N( b& b3 P" @9 u ~ - [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
' b. G9 _* o6 n0 h, k3 t: F - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]% f$ ~( g% b$ g7 V5 {: V. G
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
( u3 t/ W) {* G9 h5 f - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
. \7 Z8 n) p0 H. S - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
$ P; ~, I8 J4 @# L - [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]; m* _8 E! l" J2 F6 f& L
- ==================================8 A5 R; e b: f
- 文件关联+ u( ^* Y( S7 j t9 f
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
1 f3 s8 ~! o7 d. g0 ~( f$ u - .EXE OK. ["%1" %*]' K# \+ g4 k6 y- u8 N% B: L7 d
- .COM OK. ["%1" %*]
) a: P: [# [4 O9 ? - .PIF OK. ["%1" %*]# W7 m, m4 }( \* L- V
- .REG OK. [regedit.exe "%1"]
' g, v# u8 D' X3 R0 c - .BAT OK. ["%1" %*]2 S9 p2 S7 \: g4 _6 \# K* F
- .SCR OK. ["%1" /S]/ g, C1 d8 E6 L+ V6 U
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]
* S$ j7 o5 q2 |, a1 U: |: q# v - .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
+ a. J7 A1 Z# _# n - .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]5 B! ]6 `5 s+ M
- .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
; U( [) V+ `) Q0 ]* | - .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]: q+ j& w1 I% s6 i! H
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
, P9 F( D6 u; h8 D - .LNK OK. [{00021401-0000-0000-C000-000000000046}], s: E+ M% ~% \* r! z
- ==================================2 ]) j+ g8 y' M# ]' v% k4 R
- Winsock 提供者
! R0 s: T$ W$ p/ f) Y) G+ H. U( W - N/A
( ~7 |$ ]. U7 |4 m; U* x' h - ==================================
* @( T5 X7 m" q* y) m) Y# t4 d - Autorun.inf. @7 N% H$ z8 O* w4 R2 b
- N/A
8 T; v0 s. Q+ r" {9 Q v - ==================================5 L& Y+ |0 v# j3 f: h7 q
- HOSTS 文件 D1 R# P$ Q8 f! P& F- ]
- N/A
) ]$ [, ?! a% h2 R5 ~ - ==================================! w5 D0 f7 h; D& D, c* o
- 进程特权扫描
0 C+ |# u* u7 l7 E - 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
. I* K* K# a' e! }1 I - 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]) M/ g* ? N# c8 f2 P2 H
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]. ?; |! @1 w# N
- 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]
: P% N; ~( L4 Q) L - 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]. p8 W2 b( l, e+ v* H9 f7 G
- ==================================. `/ O- b8 Y* K* n
- API HOOK
/ f2 } {9 X- f - N/A$ [. j* U) M: m$ f2 n
- ==================================
" @7 I+ l) [' j$ }- @ - 隐藏进程
" z; x" K/ ]( J) {) X. \5 c - N/A* |; f4 ^: N a
- ==================================3 u @& a4 B1 J% y2 W
- # I+ H+ ?& V! ?
复制代码 |
|