|
|
" P4 q+ z) _1 Q$ U; Z# i0 U8 h2 F- 2008-05-22,20:37:43
8 g( M9 H' b3 E5 {" H. o - System Repair Engineer 2.5.16.900
) k1 O0 P* q- s1 U6 Z" Y8 z' @& w; \: D1 h - Smallfrogs (http://www.KZTechs.com)( G3 t" z3 N1 @! D" L
- Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能- M/ Y6 T7 q. n
- 以下内容被选中:
) I; P+ W. u. \' }7 U - 所有的启动项目(包括注册表、启动文件夹、服务等)
7 ^: y/ S7 U4 I8 Y - 浏览器加载项
G6 V5 l: ]. k& b4 ?% v - 正在运行的进程(包括进程模块信息)0 W- N3 @/ z4 E( Y5 w T% F
- 文件关联
% a. X/ l6 y# e, t7 Y) T$ ~ - Winsock 提供者: U4 |% c( N4 R
- Autorun.inf
0 `) G- ?% }( @! y - HOSTS 文件 ~" \0 c" W5 Q, I
- 进程特权扫描
! k% W9 J' }; t6 V3 ~
; D% E' v' c" X- 启动项目
W: d, |( V Z6 m - 注册表. K# ~; }( K5 X1 Y) |$ n
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
5 Y4 U4 q: W: F+ U6 b& F5 T - <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]
/ L$ R; v8 M9 P) U1 k - [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
3 V8 A4 q4 U; U7 v! {5 L; K' U - <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]
% l6 F; e& {; C7 Z - <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
6 O( B% n+ `( H5 d - <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]) M) ]; B1 t7 J3 N4 o D
- <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]! ]! z! q2 L! H5 o; @" ^8 L: ?
- <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]
9 R) w: x4 d7 _% n# }2 c2 n) w" | - <PHIME2002A><; > [N/A]
# X" Z( o- B% Z" M/ ~ - <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]6 ~( I% v& w! [6 g" ^# P* [! O
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]+ ~! q, f+ m; C" `8 {% r) O* u
- <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
, _- u! L. \0 X0 d - <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]9 F1 }* s( v3 m- c5 b4 N6 t1 z
- <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]4 [: Z. L5 ]( z# k" e s
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
: V ~% }+ d; j) K- @5 N2 E3 c - <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]
3 C F0 z$ y( X9 m6 ~ H. C - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
6 b9 \: G+ Y1 t$ e8 r2 ] - <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
+ O4 T. [2 m0 e - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]* o4 k" y# b' t# ^( m# ^. X
- <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]7 k# d* E$ R Y# v7 `' o
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]5 r4 o% ^, B* N$ @+ T; B
- <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]9 e H G' n) Q+ e. [
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
) C( @; p* M' f8 {- Z - <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
; H& c" X) ` X& p. }! M: Z% ? - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
% A* I9 V& N# K- T6 t5 `; q - <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]
# t; K d, X8 J4 [5 t - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
1 N5 p( A5 v$ ]' n - <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]9 Z7 Z2 S4 F4 J S M7 K9 }
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
( T2 E5 A5 X. D g) |! x* S - <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
: e. p _0 n" g. W - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
: G' m- V$ e5 @) Z8 R4 x/ [$ P - <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]- b$ ?; H0 G0 l5 L: v+ Q& K1 K1 N
- ==================================
' A( P1 _) o& P; c/ X7 I5 l2 t# Y - 启动文件夹' n& E9 y ^1 s3 r
- N/A, x: g! N6 w* w. N# e$ q0 z
- ==================================6 H; `; ?3 E; Q* t4 x: w
- 服务
! g b/ b) a# M+ P- B# } R$ b: [ - [3ware Controller Service / 3wareSrv][Stopped/Auto Start]+ i- ~0 n) I' m! |
- <C:\WINDOWS\System32\3wareSrv.exe><N/A>
$ `8 O B2 n4 x$ J4 r4 E - [Google Updater Service / gusvc][Stopped/Manual Start]3 z8 o( j% e# i$ \
- <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>. V. _( `1 g/ r* Y
- [Help and Support / helpsvc][Stopped/Disabled]( {- ^1 d6 U( l! X j
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>
; U' O2 _0 r' i W4 M' r7 Q - [Human Interface Device Access / HidServ][Stopped/Boot Start]
0 i9 _) w( l4 T% N6 f2 ^. w. m0 a - <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
! j( a/ |" O4 q( ?0 e/ m - [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]
$ }) |, W* U3 k, f' F5 L& K - <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>" L/ x% o3 C6 X& t* \5 _
- [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
S& _ F/ \% c* v8 y$ z - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>* O5 k- d2 m7 v9 E: V
- [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
) N8 q3 x$ R- y. ?: a4 X0 x - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>
0 ~) V" H9 }- N2 C/ B# \5 ^. ` - [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]7 q7 w0 ?' N/ `, H) f
- <><N/A>) I0 s9 [" C5 z7 q# m X
- [Qvod Terminal / Qvod Terminal][Running/Auto Start]
8 H. g& V& P# ?6 ~1 l! \ - <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>0 @* H2 F0 L1 u5 f
- ==================================, s& {4 q$ X$ U3 X2 Y! a1 i
- 驱动程序# x$ P$ L/ o; A9 h
- [22j / 22jn][Stopped/Boot Start]
5 h) d' e! L5 V, X4 O. Q - <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>
) U( {' {& G! C& ]1 D - [360AntiArp / 360AntiArp][Running/System Start]
6 b* u _3 v5 Y - <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
6 Q5 J& P6 n2 v! ^ - [43ec / 43ecu][Stopped/Boot Start]
u1 n9 P% H) e - <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>
4 i; \# e( c* N, b7 b+ I( s - [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]' W4 I0 G: c" r' A3 i
- <system32\drivers\ac97intc.sys><Intel Corporation>2 q4 r8 y+ n0 O8 P; c
- [Promise driver accelerator / bb-run][Running/Boot Start]6 |8 S* X0 W- v+ }( S1 e: F; O* }( T
- <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.>
; H+ F1 _8 A7 ]$ c - [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]% x9 ~0 A& P0 x6 a
- <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>, N6 q j: h' C S$ T1 o
- [KAVBase / KAVBase][Running/Auto Start]/ T8 d b y, H* @3 ^
- <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
) p; R" B' h" a% s - [KAVBootC / KAVBootC][Running/Boot Start]
$ g1 G( H: W4 N" }5 [ - <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>* s7 `- {- O e7 O! H% V
- [KAVSafe / KAVSafe][Running/Auto Start]% e" r5 d4 ]5 D, `6 x
- <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>
) }8 c& o* N( k2 W( J) D; Q - [KNetWch / KNetWch][Running/System Start]2 u, Y! R: U; x1 o8 W d
- <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>" z( i5 W2 U0 y; ?+ A- ~
- [KWatch3 / KWatch3][Running/Auto Start]6 N6 `/ [. P& ?! P
- <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
5 m% P3 `5 L+ ]; {/ i' K - [ntptdb / ntptdb][Stopped/Auto Start]
8 J' G7 m1 f% }- k u/ t& u - <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>8 [. `0 E7 Y, [2 H% E
- [nv / nv][Running/Manual Start]
$ `% a0 z8 Q" k; Y; J* | - <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>7 b5 K. S' [. _3 p9 p8 |" i
- [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]9 J! O$ `8 Y3 z$ k3 G- S3 [6 y( j
- <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation> \" |3 @ c. e6 f C% Y
- [DDK PACKET Protocol / Packet][Running/Manual Start]
* Y7 ~9 Y( i5 P) X+ s - <system32\DRIVERS\ProtoDrv.sys><360安全中心>4 V0 h# c+ ?1 a# H
- [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]
. A% ^4 T, M3 b" ^ - <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>
' y& c5 r) c) [ - [Direct Parallel Link Driver / Ptilink][Running/Manual Start]8 _. a* y1 T" n
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
, J$ I' b9 |9 L# B l# I# @4 ] - [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]
) l7 k% E) S- \8 m H - <\SystemRoot\system32\drivers\RsBoot.sys><N/A>, v$ R5 X# O4 e( e; T9 L
- [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
# U6 A9 Q; n4 ]0 N( Q1 r - <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
' D" A4 S3 I# w5 X. u8 ~4 ` - [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]3 i0 ~. E; ^. X9 [/ E& }) {% ~2 O$ \9 a
- <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>7 c5 c3 \( z6 J [6 {5 N
- [Secdrv / Secdrv][Stopped/Manual Start]
% g' {) n5 F7 M - <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>/ p- D7 Z' S/ r m% B2 {9 D
- [SATALink External Device Filter / SiRemFil][Running/Boot Start]8 Y) P1 P U" f- j% h; b
- <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>. I2 K( N0 }7 V1 b( y
- [System Restore Filter Driver / sr][Stopped/Disabled]
" K1 i$ q& Y6 ]8 X - <system32\DRIVERS\sr.sys><N/A>) h( V0 d, B% ~- o
- [TesSafe / TesSafe][Stopped/Manual Start]
5 A: ~# V# c' e, ?& n0 r- R - <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>
! B7 I, ^6 U- Y/ g: B( | - [System Services / unzxzsrs][Stopped/Boot Start]
& n- G+ ^" S U% ]. B8 w8 J9 h - <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>
# `+ \1 \* i6 w0 y+ ~4 { - [ViBus / ViBus][Stopped/Boot Start]" j- X v( z0 k, q T( F5 T
- <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>+ a4 v: T4 L2 m' r' B+ R! ?& e! ?
- [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]+ h1 ?: f% | Z5 s+ [4 y
- <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>) D0 y) N2 m7 q, X
- [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]3 [( n; b: E% k, {9 I- ~6 L
- <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>6 G2 `% ]: p! W' F1 G f
- [ATI Extend / zhibmaso][Stopped/Boot Start]
$ E& u0 d% r- C2 p - <\SystemRoot\system32\drivers\zhibmaso.sys><N/A># `* ^" n2 P. T. @. C# u
- [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]: Z1 c3 H! R# w* q
- <System32\Drivers\usbVM31b.sys><Vimicro Corporation>
$ C: R* q& P& s- n7 f - ==================================
( Y& I/ U; s# p - 浏览器加载项 _" h* b3 b4 ]' p$ H( F
- [Google Toolbar Helper]+ W* _ l S5 Q% m! {# X
- {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
+ n3 e8 e* T2 a# F/ }) F, W: M$ \ - [Google Toolbar Notifier BHO]& l! y5 S4 G7 g5 T
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
) n7 H9 _3 L1 i0 L0 }3 L' m - [SafeMon Class]
\! Z3 {/ g2 y6 `$ {; P( C) F. h - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
; h) l- P& t3 @! E' n! [+ f: |% O: J - [kingsoft browser shield]1 q0 c# _; D; j8 ?2 J) N& H: A# e
- {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
/ U2 Q, y( U9 d - [IEBuddyExtControl Class]
. @. R1 p& s" C2 S ?4 L# { - {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>& B2 T' T7 l( t% {# f$ |, g6 ]
- [Zcom 杂志]
# u& L, m9 }, f) H1 l# j3 z# `% B - {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>
% I. V# s- }, E) g3 i% y - [&Google]* z# T9 [! V' p, ?! v1 Z- C
- {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>, ]$ p+ O% t4 V* L- p6 d
- [KooPlayer Control]
- l& b8 D* d2 W; Q" d7 N$ ] - {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>; p# G) L- N& q1 B# [: x7 t& i
- [Shockwave Flash Object]8 {7 O' t7 f+ E- H, q
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>3 |# h9 Z5 i+ v
- [KUpdateObj2 Class]% H! s+ b9 `% ~0 p
- {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>0 \/ a; D+ `' {0 d; j! e; ~: k
- [Google Script Object]% N/ |5 E1 \1 Y3 I8 p
- {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>4 m( x4 x3 b3 y0 ~
- [EWA Control]5 W6 h. y) G5 T8 |& j& H
- {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>. z( z7 Q2 m, }9 ~) H$ @
- [Windows Media Player]
- g$ H9 q$ {' [ - {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>4 j" t, ]; q& V( L# \
- [&Google]* H, ]8 d; Z& {9 o* C" u- T+ L
- {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>' z3 k% X& P: k2 ?2 z/ \0 t' S
- [HTML Document]& ]/ _- v6 A; D& ?
- {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>' J1 ^0 O5 }) b/ x5 P
- [DHTML Edit Control Safe for Scripting for IE5]
) P2 Y8 G2 Y7 z8 \$ q - {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>5 T( ^7 ?! l- U' ?) v* z. O+ ]
- [RealPlayer RAM Download Handler]
2 p* b3 }/ M/ G r+ l - {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
) _" [9 @1 v7 M# N0 y# k5 O - [IEBuddyExtControl Class]
- r: }, z" J3 c, k+ _3 [- c# t - {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
( ^( q# D$ ^ ] |: t& E - [XML Document]
) u5 O! |9 X0 D8 v5 P! ~- I" k - {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
5 q9 M" m( K% X* X, O - [HHCtrl Object]5 ^/ b" R5 L5 J& U; N
- {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>/ N( x9 f$ J( ^2 {0 }
- [Windows Media Player]1 n. y& s E6 s
- {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
/ b. w* q" a5 _# U: A( Q9 Z - [Active Desktop Mover]
1 ] c) }1 ?- y. b - {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>- { W4 @' h# |* v3 m
- [360SafeLive]% ^# v) k1 {2 _- B* n
- {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>
* h1 S& `$ X+ {& G% O8 E. S* _ - [Microsoft Web 浏览器]
- ]) T5 X8 c0 W9 l- F - {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>$ ^" k1 ?8 j2 p' n/ `1 O$ C8 J5 q
- [Browser Enhanced Objects]+ f7 n# Z7 J5 ?
- {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>% f+ a. r7 y! d3 d* B0 n; Q _
- [Google Toolbar Helper]
9 s$ Y( _9 a7 d! _( S) C - {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
# i6 m+ y& m2 g - [Microsoft Scriptlet Component]( N0 j/ l0 d$ c6 k
- {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
6 [1 f# L0 c+ {; }7 m! X" ^ - [Google Toolbar Notifier BHO]; \& m- t6 n% i U J/ h2 Q2 G
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.> D0 I5 j6 p- a+ R6 }
- [SearchAssistantOC]: o+ v: @ P$ y* J3 I8 k
- {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
( H" u3 p3 i9 C4 s1 n# ^ - [SafeMon Class]- B/ o, [" |9 {. P
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>" y/ B. P# n! V. w5 E: z' U
- [RDS.DataSpace]2 F) }7 H5 ?% ` l) v; ?
- {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation> V$ }: I( ~/ t6 b& d4 J( q
- [KooPlayer Control]
( @ a6 U. q% J6 h - {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
( s6 L( `$ E# ] - [AUDIO__MID Moniker Class]9 E: Y, d* g2 h4 Y# G% _$ Y' U5 A" X, g
- {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
3 W# Z+ d0 F/ w5 x8 @6 ^3 U - [AUDIO__MP3 Moniker Class]
+ U$ b, m. R" D8 s* H& C - {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
, ?# [3 a! f4 t% ?% A$ F7 @ - [AUDIO__X_MS_WMA Moniker Class]: F# ], M* [1 @1 h7 E
- {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
8 g7 ~( w+ g1 ` N* a - [VIDEO__X_MS_WMV Moniker Class]) W0 o3 } m$ C5 ?. f9 \
- {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
: T1 S. V, a+ J) g - [RealPlayer G2 Control]
. m% ^1 w3 f) p$ q! `! Z' n - {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
8 B, I' h6 B R7 y4 Z - [Shockwave Flash Object]: q8 v* C C- A' K) s0 o% i* D
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
3 q6 Q \$ \ |# @7 d5 |# [8 S& p - [KUpdateObj2 Class]; H5 c" Q0 v# N5 C
- {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
" \5 @ k2 Q" q; { f' P - [kingsoft browser shield]
. F. z; s) f8 ? - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
' z$ D2 A5 d- F - [PasswordEditCtrl Class]
8 r4 L3 K. K) E$ B% q. w! Y - {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>+ u9 J3 A5 i% B0 r" J, J
- [QvodCtrl Class]& S: j: f$ X+ K3 u* f$ e0 ]: M" h
- {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>' p, t7 Y* W' k# v
- [&使用超级旋风下载]* i# J" H2 ]2 K
- <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
) C9 N$ q! z# G) V0 g- ~2 b3 R - [&使用超级旋风下载全部链接]
. f8 Z( j( G; Z7 D- h" k - <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>( Z' W& f) A3 O+ o
- [使用迅雷下载]9 a% E0 h# ^8 o* M
- <, N/A>
1 \! Q- d0 J/ S: s( [- N6 ` - [使用迅雷下载全部链接]" m5 V- _, ~) d# L
- <, N/A>
j" v% |) G2 _- N2 [ - [导出到 Microsoft Office Excel(&X)]
5 P- A! z/ x5 D0 e; e - <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
; B, Y9 h+ W9 @2 z9 L3 i8 ~ J - [添加到QQ表情]
! w8 h2 `6 P2 ]. R - <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
5 f" t' e. l" K% Y R1 i6 ] - ==================================6 _5 t4 O, e- m% @# C y2 p$ d
- 正在运行的进程
6 w' n" J# i' @2 x - [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]" a5 E+ g. i/ k* j+ m
- [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]! s# L( g- r& s0 \/ _; n
- [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- ^& {# \. O, O" K2 V8 d* M3 A - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
0 y+ k( U. v% O Q - [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]( d" B# v# u+ b+ q
- [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]/ g2 J% o+ {" Y6 n
- [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]: w6 k$ s4 U. r; j
- [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
0 p: I6 m# j5 C6 y - [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]0 x: x: b, @6 t: \
- [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]2 v" t! \) N" z O' u c
- [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
, H4 K' l+ R: @1 Z4 M7 v" N* x! ]- e8 A - [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]
: C4 K7 G' @. n$ f" F5 S; T: m/ f' S - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]. v8 F! f2 K: z6 z9 ]0 ^
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]* q% T9 M# {6 C( d k z
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]- e( v- q. j2 W! C
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]* a% c% P, }$ V. m" p2 y9 e8 Y: V4 ~7 V
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]
( ?2 @! i4 \4 P4 x6 ^% ~# | - [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]
0 C b5 _8 M: j. }! F; }. U - [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]# L7 l9 b8 V0 M% C4 E" i
- [C:\Program Files\WinRAR\rarext.dll] [N/A, ]% {0 {& o) g# w/ @2 _
- [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]; H7 R) }8 ~/ w) h# A m( h
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]) X9 U' q8 P) t: p6 J4 R! Y; S8 u
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]' z0 o, l8 Z Z7 Y
- [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
( N3 k/ u* z2 t# E - [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]
# }) f! ]4 c8 E: I; Z - [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]
5 T: H, @& g# \ - [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008]
2 q3 m, Q8 m, ~; g. t0 |2 x1 ` - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
6 Q( C; |2 G: Q2 I. }4 V+ x" x3 e - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
% W4 k2 e5 t: u5 g8 K8 q - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]( k+ d4 w- s8 O- [
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
) S- f2 C* U* A Q% g+ x! f - [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
: y' j' P) L3 p. H9 j& i - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]- `6 @+ l. U* \7 v Z
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
5 s3 n. F: o& w - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
4 t# a$ P; R# h* h5 y+ e& e$ L+ \ - [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]
2 f' Y r4 H, n* n+ R - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]
) y% a c8 F0 G( J - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
& [+ F; \: Q! N9 x - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]1 s& q7 a, x/ n% C% _/ @: e9 m5 m
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164], j1 r* }, G: P! t; B
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]7 i6 U) J2 a) ~ f% G, x9 q
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]) m( h6 F; e& @. |
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
f8 N' w N& s. T/ Z# y/ X" P - [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
4 _, m3 l$ l2 }8 m. V: D9 b- T; Y - [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]
! C* d7 Z: H+ K& y& N3 I. j - [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]+ V1 Q1 I9 z C0 m: l
- [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]% z* f5 k- x n! p2 [, z
- [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]% F* `# A5 _) K3 N4 u
- [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]5 h5 t3 \! \) \9 `, b4 N
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]( ~+ |& n* p0 W: h& S; z
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5] ?4 ^) L( B: t! u' I3 O
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
4 |5 l% v7 k1 w2 j7 @ - [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]
" f6 U' W3 ^- G5 [4 z9 g - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
3 X& Y; S. G, ^$ d5 E. `$ f* M: }) N - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]
+ `; D d* w! k7 Y% F - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]! ]* {: T x+ S
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]
# a; o8 T6 J9 u* X - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]
& {( c+ Z) U1 Z8 Q6 Y - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78]. A/ {. s2 ?8 v- E U
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]/ u8 a' y/ W+ B0 \; Y
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]6 @& F% \( j" u1 g- i' p
- [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]& n |; |+ O& G% }: h5 }' k
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
- C; v. z0 }7 w8 n - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
4 E7 w! T3 H1 E/ g% N h' J3 w - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
+ @" C9 X0 |$ Q7 g - [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]
' q" G0 e( d3 m - [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]& Y& e3 x6 _1 K( y- b* D, z3 K/ I
- [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950]
4 |6 b; P$ e# s+ O - [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]7 I) j V7 z. O; s9 T8 m- O1 H
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]% z3 y+ e, K7 z1 A
- [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0] F4 r0 X4 Y. n! a+ ]' V `: x' p
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]# N+ x! i2 R+ F" L/ u2 K
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
' k" o- [; Y$ l" K" G9 h, S - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
; g4 m7 N: D) x5 H/ Z - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]8 x/ r9 ~" ^2 Y G& I
- [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]
# M2 X- m5 ^- u: M - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]% Y2 n- D, F3 @' g1 @6 D
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]- L4 K6 K: V1 |/ ?% o
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
/ p0 T3 A: w7 U9 X, v1 q, |- I - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
3 ^0 ]. c7 v6 y - [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]) b# G" N+ S4 ^. Q1 _5 x
- [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]
$ i& W4 ~8 n% [$ M/ D4 j - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
/ `/ K4 ^5 [9 e6 u6 z5 |) ]- f - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5] J- g% j8 D( V9 C+ c
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]! m: w( l3 |5 @6 v# }
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
6 C+ l5 U( Q( C( j - [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
9 a) n# s j+ B: l) D; M - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001], C3 O1 n" N3 a) S) Z3 G
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
- [0 M9 M3 E4 \/ k" w2 u8 p) y8 [ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
# q/ l: L2 h Q( F2 Z - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
. E# N4 \5 ^ h' q! h - [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] o+ T$ D/ h' p* S. ^
- ==================================
, l3 W: y5 t# B# m. `1 l - 文件关联
1 i- u5 \ q+ j0 o7 Z9 ] - .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]; ^6 e, J/ [. B8 @" k2 r/ o$ x* U
- .EXE OK. ["%1" %*]
2 ?+ i* K2 n' e# Y9 Z$ g' {# {+ H - .COM OK. ["%1" %*]
* I/ m j4 S" ?3 S# ^: O - .PIF OK. ["%1" %*]
) Z9 R# V: X& U. Z1 g8 G - .REG OK. [regedit.exe "%1"]& Y$ i* g" E( s6 S
- .BAT OK. ["%1" %*]
1 `( V9 {: [. I' ~% u, {+ |; n - .SCR OK. ["%1" /S]" H! P/ ~" V; [$ M/ S; G( B, _; \
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]2 F; r2 v2 D$ T, k
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]9 c+ d# Y4 h- j9 ?
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
$ G' ~7 I$ @" C, n$ y0 g& ] - .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]( W2 l, b% W4 I$ C. ?
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
9 W, P; R; V; y' N+ P - .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
3 ]' b" W1 G$ r' d: d4 m2 ? - .LNK OK. [{00021401-0000-0000-C000-000000000046}]
; R: t& [+ U1 X K - ==================================/ K5 S3 V1 M# V5 f/ e+ b# b) L
- Winsock 提供者- N/ ] g8 m* r: m1 c/ s
- N/A
& S# n% p2 _, }- g+ Q5 ? - ==================================
8 p: ? }/ `; d; `8 s; A; s - Autorun.inf
0 ?3 C7 C* A2 P* k0 l( N$ h3 a - N/A- k! B. f$ o: B% e% P" f
- ==================================7 j: d0 w$ a6 G% ?
- HOSTS 文件) G% `- f" [" }* ?8 v
- N/A! J$ A4 G( W: V+ l
- ==================================3 H2 ]# { L! g H3 X
- 进程特权扫描8 e* o! p3 z4 ~
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
$ t) E6 D5 `( n4 q0 h - 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]
4 c; R4 m2 Q' Y9 p* j3 Z! g - 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]0 d; G4 O1 {# x# W# Z4 ~- R7 r% h
- 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]( \8 ?/ }$ b/ I8 m9 q
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]: d6 G# V6 `% ~3 D
- ==================================( K; P2 ]+ g3 y6 {
- API HOOK
# V2 L l4 {9 W3 i/ F) e! e - N/A
. S( Q* w+ f$ s$ ]; s - ==================================
5 \7 {( f% K9 c7 E - 隐藏进程
, s: {# R4 d9 v/ F5 ] - N/A
3 w9 a8 R, {/ L0 t/ x* a - ==================================+ G0 q! r& T2 T$ ]" ?- e
4 x: u! o; S, @: r, M9 m
复制代码 |
|