技术部 收藏本版 今日: 0 主题: 115

4061 10

在这里

[复制链接]
发表于 2008-5-22 20:53:41 | 显示全部楼层 |阅读模式

  1. 1 V5 Z1 A# u* V! S
  2. 2008-05-22,20:37:43
    / F! p  Z; O4 U
  3. System Repair Engineer 2.5.16.900( \1 X% Z7 Z* O
  4. Smallfrogs (http://www.KZTechs.com)
    7 c( ]) b5 S  H+ [  J
  5. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能% D+ q# Y+ h+ e* v1 T2 P
  6. 以下内容被选中:- |: S2 U2 V: v6 y; i5 o
  7.     所有的启动项目(包括注册表、启动文件夹、服务等)9 j( p1 r* m) U4 O' h; t
  8.     浏览器加载项# B" ]6 `0 N( \) C5 \% v$ a
  9.     正在运行的进程(包括进程模块信息)
    * f( ]6 B9 o- T; [3 U& T) k# P" D
  10.     文件关联" p1 t& r  {+ u0 h1 S% Q
  11.     Winsock 提供者
    : ~* T0 D2 ^1 O
  12.     Autorun.inf, Q* Y# t' U2 W5 n4 E) X0 z
  13.     HOSTS 文件7 D: f& L$ Q4 R6 |. s+ _2 _
  14.     进程特权扫描
    * @# W6 H* J$ Q* K
  15. 2 e' _: T' y+ r  c) C
  16. 启动项目$ ]4 l) Y2 k. |' w
  17. 注册表
    9 |8 F! i1 ?( }$ T* ^) x( b  V, Q
  18. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]. E5 [$ V5 E. w) |/ a& \
  19.     <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE>  [(Verified)Microsoft Windows Publisher]; \6 {/ c# A9 X% ^5 Y# f- y* ]
  20. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
      j3 i$ [/ o! g! u) s
  21.     <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r>  [(Verified)Qizhi Software (beijing) Co. Ltd]: |! H! z1 d$ v2 n$ p( H
  22.     <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start>  [(Verified)Qizhi Software (beijing) Co. Ltd]. A& p) ?$ i- a' \4 Q. y& }
  23.     <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start>  [(Verified)Qizhi Software (beijing) Co. Ltd]# k+ M" L: @$ q- u3 G' f9 R; ?
  24.     <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup>  [(Verified)KINGSOFT CORPORATION]' l; ~: i5 U& g2 B- `) _
  25.     <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>  [N/A]1 y5 P+ Z/ t/ c  W  I
  26.     <PHIME2002A><; >  [N/A]
      j- C, _8 \" t6 [4 s
  27.     <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>  [N/A]: q9 B3 ~, N6 C  h8 q& |
  28. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]" S, X3 `; p% [" X9 o
  29.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Component Publisher]8 _0 F% |3 u& ?: ?
  30.     <Userinit><C:\WINDOWS\system32\UserInit.exe,>  [(Verified)Microsoft Windows Publisher]
    8 C# n7 u8 q5 R
  31.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]" e& l+ w: P' h" R* B
  32. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]' |# K, C; V1 w1 c8 E$ a* \1 {
  33.     <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll>  [Beijing Rising Technology Co., Ltd.]
    1 x7 Z$ R+ V2 w
  34. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    5 V+ L1 M1 q7 M$ `  }0 Q% o
  35.     <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A], X% ]8 a1 v; s( ]
  36. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    1 ~* d0 j8 q0 H, E" `: P. j
  37.     <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]) w, o9 @0 S! W% _; p  {
  38. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    & b# i3 L) h2 L3 a
  39.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]  ?, i' W& p) X  A8 K$ ?1 C
  40. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    # R) t6 E8 Y$ N
  41.     <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]4 o% |1 C; O& V" ~2 W; z* W5 ?
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]+ d! l# k# _, ~7 A; w8 `; t
  43.     <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
    : w# H- K" h( z& [3 l; p9 x2 T
  44. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]! E8 m) b$ I' N' ?& i# R; I+ s
  45.     <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]# \! d6 Q  U  C6 |, E
  46. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]) U0 e# _# @1 F( X  {
  47.     <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub>  [(Verified)Microsoft Windows Publisher]
    : q9 \7 T+ O' Q" _; ]
  48. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]8 w. j+ T- k/ A& Y+ I; g
  49.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
    ! u; b$ |' F% T/ z+ G; ?5 X
  50. ==================================
    # ?8 g, j- |6 A
  51. 启动文件夹
    ) r* a5 b2 k7 s1 N1 K' t: F& N0 T
  52. N/A
    ) A# L$ B2 ^; X# K! c& [
  53. ==================================
    9 f' W( P9 R! W" b
  54. 服务4 ~9 Z7 C7 y) w2 R. b, I* @
  55. [3ware Controller Service / 3wareSrv][Stopped/Auto Start]; }$ e; r0 }' Y! D) K6 w
  56.   <C:\WINDOWS\System32\3wareSrv.exe><N/A>6 k( i# f8 f% ~
  57. [Google Updater Service / gusvc][Stopped/Manual Start]; Q2 ~- E9 G$ b7 {. I# E9 k
  58.   <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
    8 S- s+ a4 h0 @) c; Z6 {
  59. [Help and Support / helpsvc][Stopped/Disabled]- k& G7 o, N8 D7 L: i
  60.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>
    ; @. H5 E/ _: H$ ~+ `
  61. [Human Interface Device Access / HidServ][Stopped/Boot Start]
    6 S$ t) {3 q; N7 ]! |+ R: t8 ]
  62.   <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>' I# A* i. h  `
  63. [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]
    # D+ k6 O( q: c
  64.   <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>
    $ s& G& c2 b" i& I+ l4 S- g1 C
  65. [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]2 \. U9 i( J. Q% q' w) @* t/ b2 p
  66.   <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>3 x4 r8 r1 ]) n* o; M
  67. [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]% L5 k7 ~, L5 }4 R1 C* s
  68.   <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>
    : m; f9 h5 C& Z& b, r8 N* }
  69. [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]
    $ u" F0 F2 }, R  S( Z; r$ Q
  70.   <><N/A>/ u3 R% ?5 f4 m
  71. [Qvod Terminal / Qvod Terminal][Running/Auto Start]
    2 n! T$ ]. B: r
  72.   <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>/ F( X9 A2 u& q6 E
  73. ==================================% r0 `& Z/ S* u: B4 g9 S
  74. 驱动程序' {" f$ R- ?! L1 D' ]. a! a
  75. [22j / 22jn][Stopped/Boot Start]
    1 X$ t+ r; F7 V6 m! y9 H: M
  76.   <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>4 C- E: z) X5 _) T7 B
  77. [360AntiArp / 360AntiArp][Running/System Start]
    ) |/ a9 W7 g5 `- I. j+ G
  78.   <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
    2 l; B: a+ m, y, F6 l; d
  79. [43ec / 43ecu][Stopped/Boot Start]& @+ _* d# |6 o- K8 w2 C
  80.   <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>
    $ r4 g6 g+ R* P( ?: m
  81. [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]2 q5 W( Q( _1 O
  82.   <system32\drivers\ac97intc.sys><Intel Corporation>
    4 N6 P9 P, B( A1 ?5 Z0 V( q9 G6 x
  83. [Promise driver accelerator / bb-run][Running/Boot Start]$ j1 M, z: v( l  B  O4 {( k: V
  84.   <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.>( B) l- A! u# \0 S3 @8 y
  85. [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]0 q: w1 u9 o. d7 R
  86.   <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>8 g0 j0 S# B# C( P) s9 z* L
  87. [KAVBase / KAVBase][Running/Auto Start]" F: R# s0 G0 P+ g2 C
  88.   <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
    % Q8 V( o, Q0 D( a" v$ f' O
  89. [KAVBootC / KAVBootC][Running/Boot Start]/ T  x) ]; I& f% b
  90.   <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>( P% S/ B5 J9 S& G5 G9 q7 X* s
  91. [KAVSafe / KAVSafe][Running/Auto Start]
    * R( Q" R! r. f% z1 l/ l
  92.   <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>
    2 H; l& c/ ^$ ~/ s' e, L4 f+ `8 m
  93. [KNetWch / KNetWch][Running/System Start]& P+ ]4 G) K- n- \7 ]+ {6 m8 e
  94.   <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>" b; ]1 M  ?7 X: `# O
  95. [KWatch3 / KWatch3][Running/Auto Start]
    # Y# J5 e# u2 U
  96.   <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>% o9 n, w8 X1 U! X
  97. [ntptdb / ntptdb][Stopped/Auto Start]7 T. Y! S. Q8 A0 p- `" j: V
  98.   <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>+ Q0 k% L+ B0 u% \, Z
  99. [nv / nv][Running/Manual Start]( A3 x4 N! q7 ^) [5 c! R* X
  100.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
    * B9 {$ @; P+ B- C+ @
  101. [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]
    & u% I! {- d) ]; s. [* e
  102.   <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>3 h7 v: ?3 v( I, m
  103. [DDK PACKET Protocol / Packet][Running/Manual Start]
    & o& W$ r4 Q% n( A" n
  104.   <system32\DRIVERS\ProtoDrv.sys><360安全中心>, a) ?, ?( r1 }" I4 Z6 @+ a5 f
  105. [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]  x) P7 T# r4 q
  106.   <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>
    $ @5 [% U( {- b* S
  107. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]6 a+ s# |, m( g' b* ]  s
  108.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
      q8 O+ _; m1 B7 x  P0 b4 H
  109. [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]+ \, `0 i! o% \
  110.   <\SystemRoot\system32\drivers\RsBoot.sys><N/A>7 ?# c( a6 J0 J! ?
  111. [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
    ' e+ }/ w- \, w  o3 e% ^/ T1 ]
  112.   <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
    $ t+ a' s) Y8 L  H& K- z+ q
  113. [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]
    0 \& Y1 P! {3 A
  114.   <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>
    1 q4 d+ l. z5 M$ [, c) w9 s5 U
  115. [Secdrv / Secdrv][Stopped/Manual Start], i: I' _: w' A* r8 M- L
  116.   <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
    6 P& l0 C2 b3 U2 m, A7 V
  117. [SATALink External Device Filter / SiRemFil][Running/Boot Start]
    & E: ~2 `: k% i: N
  118.   <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>5 j' T1 w1 }' o9 Z. m( \* a
  119. [System Restore Filter Driver / sr][Stopped/Disabled]# E( ^8 `$ {2 t" ~
  120.   <system32\DRIVERS\sr.sys><N/A>
    3 z7 C$ h" `0 O' z! c2 r- g3 E
  121. [TesSafe / TesSafe][Stopped/Manual Start]
    , ?6 I  a& l  c6 u0 j' Y
  122.   <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>
    : A4 o4 ?; _/ k4 }. M3 |8 J
  123. [System Services / unzxzsrs][Stopped/Boot Start]
    3 Z- c2 ^0 w  U5 p$ k0 B, t1 K
  124.   <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>
    * u5 U, f/ H( M; ^2 p& y5 H
  125. [ViBus / ViBus][Stopped/Boot Start]/ E1 Q. {6 i0 w
  126.   <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>
    / \$ G$ Q- g  O1 N* s' n
  127. [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
    : y! F3 J1 o: u! h7 @# I0 T
  128.   <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>4 k" P  p3 i$ Z( d" B
  129. [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]
    : d! X2 m  L( z) p9 s
  130.   <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>
    & A9 z/ \0 ^; L0 N1 n0 a; T
  131. [ATI Extend / zhibmaso][Stopped/Boot Start]1 [! s- q+ F/ W4 j2 t: p
  132.   <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>
    ; i6 r/ b  z" ?- Q& E8 m# K  c
  133. [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start], C* o( _9 u; V6 `% w- O
  134.   <System32\Drivers\usbVM31b.sys><Vimicro Corporation>
    0 h0 q* \  Q( j6 B  w/ t5 ^
  135. ==================================
    - O0 I1 w& r. @* S( B* N$ k8 I, z
  136. 浏览器加载项
    - b# L4 C* S' I& E. w. _/ Y9 M
  137. [Google Toolbar Helper]
    - E9 q% G( q4 _. D& F. b
  138.   {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>8 B1 w7 D$ ]& Z& r% H
  139. [Google Toolbar Notifier BHO]2 y1 M" |* P* C" a0 f7 u; N% V& H
  140.   {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>* D' ~$ V; F: [" h5 b; k8 o
  141. [SafeMon Class]
    ( c8 g+ A- _9 o1 n: P5 s. a
  142.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>" Q& @# a: Q$ {: l: W
  143. [kingsoft browser shield]
    * T  P) t8 h8 l- D9 V4 E% C
  144.   {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
    $ A" S- d& }( E$ x4 ?; y/ L: x
  145. [IEBuddyExtControl Class]' P1 O3 Y/ M9 T. n* ~4 K
  146.   {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
    & L; m/ J. r2 I& Q  {% S3 H- |
  147. [Zcom 杂志]% L7 X+ W5 h: c; f
  148.   {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>" Z9 N# E$ }% `: ~# l6 n' n# k
  149. [&Google]
    7 H& a& Z. e% z1 w$ w# f' `" L) O) r
  150.   {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
    % _- v' w* }' u! E: l
  151. [KooPlayer Control]
    + ~3 ~( ~0 y+ a$ y4 j
  152.   {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
    - z/ u7 A% M, q5 e+ A
  153. [Shockwave Flash Object]
    . I) ?, h+ s/ n. f8 Y' L8 @
  154.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
    0 u$ L1 r! N5 f( J. Q
  155. [KUpdateObj2 Class]  ^4 T6 g1 T4 l  |+ Q
  156.   {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
    & a+ C! k, J& g# d' S) {
  157. [Google Script Object]9 I' b  f6 A& g: o& B
  158.   {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>4 G2 b+ Y- k" |- B
  159. [EWA Control]
      Q  X% _2 T, k4 F
  160.   {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>/ V! k2 j  o1 Q( _8 I
  161. [Windows Media Player]6 a" F* i$ S% Z7 ~2 R
  162.   {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation># K! o8 s* _5 I# |6 f
  163. [&Google]4 E2 m6 q, G3 [# Y  _- t/ G
  164.   {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>9 ?6 |  v6 s) J: J4 ?  H  ^
  165. [HTML Document]* U6 ~, F; k0 g
  166.   {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>- I3 U  f) h7 p2 S
  167. [DHTML Edit Control Safe for Scripting for IE5]
    : s/ P; s0 C  e6 x- ^/ G
  168.   {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
    ; M: l/ A: N# t6 k+ k$ d! V- J
  169. [RealPlayer RAM Download Handler]' g$ E2 ?! W- ~1 y5 _2 X/ m, ~
  170.   {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
    0 F3 J+ q" c6 o' H' U3 v. [
  171. [IEBuddyExtControl Class]4 ?4 U; B; j$ w/ Q* o3 j
  172.   {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation># e8 l) k* m+ P
  173. [XML Document]
    ) n# Q1 M9 {( ~6 f( t! e$ @
  174.   {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
    ' c0 d2 Q/ c6 ]/ x+ g& _7 Z
  175. [HHCtrl Object]
    % \! P* F2 z7 G. {7 E1 T4 `$ x
  176.   {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
    : J2 \/ t! [8 C; v
  177. [Windows Media Player]
    4 n! x; ]6 [0 E& D
  178.   {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>$ |' G1 y( f+ P* }, u) |0 L' i
  179. [Active Desktop Mover]0 \3 y# y0 {8 ~# X" U
  180.   {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
    ) O1 F: e& F1 L3 Y
  181. [360SafeLive]
    6 R9 @. _2 ~$ J( A; U$ c
  182.   {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>7 x4 {* f) y5 z% V
  183. [Microsoft Web 浏览器]
    : F0 ~( `0 J' ]& p; X
  184.   {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
    + t+ k* q+ B" j+ O
  185. [Browser Enhanced Objects]
    / i4 o  N' t2 c
  186.   {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>. [- B8 s' l6 U8 _
  187. [Google Toolbar Helper]# q! j1 C+ c5 \% Y* f
  188.   {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>6 K2 M0 a( T5 p, _% `0 H
  189. [Microsoft Scriptlet Component]
    7 V1 O. \) i, x2 |
  190.   {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>5 ]% P- R6 e2 q6 d4 \$ e
  191. [Google Toolbar Notifier BHO]
    % n8 T  W$ D  ]5 d
  192.   {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>$ m: y  J% N' m! i
  193. [SearchAssistantOC]% W9 }2 }" }" ?' i) }
  194.   {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
    9 ]9 k( O0 Q3 l1 j+ K
  195. [SafeMon Class]
    + S4 C) x0 C' H5 |
  196.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>3 H- R0 ]$ x% ^4 n! ?% Q1 w, i
  197. [RDS.DataSpace]
    2 `4 L) L8 _! Q* b8 z9 Q
  198.   {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>: W' i$ t0 ^8 }/ u
  199. [KooPlayer Control]# m& h% R- m+ }, n' K
  200.   {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
    : m( j4 V0 c8 t3 k( M
  201. [AUDIO__MID Moniker Class]
    0 G% F- L8 h! z) D+ T9 D9 _% N
  202.   {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>& P4 w% T9 Z$ h3 V
  203. [AUDIO__MP3 Moniker Class]" m4 n4 f" }# h
  204.   {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
    $ ]+ Q2 X5 E4 a9 w1 d* x) }# U6 b
  205. [AUDIO__X_MS_WMA Moniker Class]+ O' q4 Q; b6 h" y7 g- H! }
  206.   {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>, ]3 R; \& h8 O5 c" C/ `* S+ b
  207. [VIDEO__X_MS_WMV Moniker Class]0 B+ r6 ?, y( k/ W
  208.   {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
    + ?5 F' [' f- @+ }$ y
  209. [RealPlayer G2 Control]
    ( U9 t8 H! d3 t1 E( V3 q% C
  210.   {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
    3 r% ]+ b8 [8 _: R! Z- T( a
  211. [Shockwave Flash Object]
    7 S' i6 L- s# L! X5 y( J
  212.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
    ; }- Z: v; F. z; L0 @* w
  213. [KUpdateObj2 Class]) }( A% s  T" A5 Y0 }- X
  214.   {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>6 E& p' Q* A% i5 @
  215. [kingsoft browser shield]; i1 d  E- o' S6 B& _+ L
  216.   {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>7 h  {* z; A! a% M4 \, P
  217. [PasswordEditCtrl Class]
    / v& [( q" B1 I) k' u" a! o: B. T
  218.   {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
    0 V) B# G" F7 A8 N9 c; t
  219. [QvodCtrl Class], t0 a& P0 M+ S5 F1 r1 N5 F4 T
  220.   {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>
    * X3 e  |; t6 `/ P. L4 W  U
  221. [&使用超级旋风下载]+ o+ n# z9 @2 K" S6 \* o
  222.   <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>8 J0 W' e* F3 X1 r: V1 a7 b
  223. [&使用超级旋风下载全部链接], o' G1 P* M4 t8 f1 i0 B- P" y1 ]
  224.   <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>4 ]4 @: |1 b( Q2 [4 i( N
  225. [使用迅雷下载]
    ; s  i7 b1 j. o
  226.   <, N/A>
    1 q# e; u; B+ e! U7 `1 Z! X5 c
  227. [使用迅雷下载全部链接]
    9 ^, ^! S+ g* s  d9 k
  228.   <, N/A>
    $ }! b' }/ H; ~& [8 o
  229. [导出到 Microsoft Office Excel(&X)]( b' W/ k% }1 ~0 p  H  L) N; s& H
  230.   <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
    ) y! @% L) @+ [! X! f6 ?
  231. [添加到QQ表情]
    0 N5 s0 c* ?; z2 h
  232.   <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>" h* h& ?9 t9 L' o, M
  233. ==================================
    6 F3 a& k* t% m6 F( A* Z3 e% n
  234. 正在运行的进程0 y( Y& z- H. y7 `
  235. [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]' K, ~1 s9 `5 u6 `
  236. [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]8 ?4 q: p) O! N6 Q' D" ]3 g
  237. [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]/ o6 Y1 Q; r/ _' t5 f- J$ ~& m6 P
  238.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]. k' T2 v4 S; E) {2 k5 k( {# i
  239. [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    3 N1 Y9 D/ [: v6 V: k
  240. [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    , o9 s/ I* f' i( i2 e
  241. [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    ! |6 o! p$ v5 d/ B3 R; F; ^
  242. [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
      r/ ^# s& M& b; n1 d
  243. [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    ) g5 D. u0 j7 e. {! [
  244. [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]7 L6 `# Y% I' ]4 R. k* k" y# a
  245. [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    . B5 o! \0 X: d' x
  246. [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]
    $ {3 x0 Z+ z5 e3 D+ }
  247.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]- c5 g8 a/ d8 i
  248.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]% k: a4 `  I# S) ^( w' b2 V% R1 s* C
  249.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]+ g# t) [' l1 h
  250.     [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 1, 5, 1001]
    2 V7 V" g2 m) h$ R! R
  251.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL]  [Kingsoft Corporation, 2008,05,07,373]
    3 X# W$ _) W% d7 P0 L$ }4 v
  252.     [C:\Program Files\Tencent\QQ\qdshm.dll]  [, 1, 0, 101, 20]
    2 M# `7 f, |0 ~. Y: K2 {
  253.     [C:\Program Files\Tencent\QQ\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    % Z  o! h! [0 w! Q5 p
  254.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]. Y3 G6 {; {- ]- W4 R
  255.     [C:\WINDOWS\system32\shlhook.dll]  [Beijing Rising Technology Co., Ltd., 4.0.0.9]# X  n& m$ k2 C; G, N
  256.     [C:\Program Files\Tencent\QQ\DShared.dll]  [Tencent, 2, 1, 0, 0]' y; f6 f% J: `! ]/ ~" H% j
  257.     [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]/ ]6 ^/ e3 g6 c$ n
  258. [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]: V# y3 n# a. K9 I: X# q3 H
  259.     [C:\WINDOWS\system32\mdimon.dll]  [Microsoft Corporation, 11.3.8166.2]
    + v' S& n8 V% N% x$ V$ U' u) h9 O
  260.     [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll]  [Microsoft Corporation, 11.3.8166.2]4 @7 Z; E1 C* V( S6 |
  261. [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe]  [360安全中心, 2, 0, 0, 1008]4 H& w" [2 q% H: t, Z5 P2 O
  262.     [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 1, 5, 1001]: F5 ]  S5 I; ]3 \: [/ J( o/ v
  263.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]% l+ `, }, s( i2 g0 ]7 A
  264.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    ( R7 E7 Z- s& l: T/ w5 f
  265.     [C:\Program Files\Tencent\QQ\DShared.dll]  [Tencent, 2, 1, 0, 0]- o4 n" e/ ]0 Q9 o
  266. [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]( I& I" L' ~4 ~4 u' y7 n
  267.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    4 [/ w8 u/ p* z: n0 y
  268.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    * `$ V, S  g+ B( G2 Q
  269.     [C:\Program Files\Tencent\QQ\DShared.dll]  [Tencent, 2, 1, 0, 0], x, r" }' ^5 x( x: ^  u- G
  270. [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe]  [Google Inc., 2, 0, 301, 1654]
    ; W. w  I. E/ `: w$ L* {
  271.     [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll]  [Google Inc., 2, 0, 301, 7164]4 S8 y- w% k  ^6 ]8 t. Y
  272.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]+ M& ^7 n- U! B" `
  273.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]/ i# X0 T& V2 X7 c/ `) G. ^' Z
  274.     [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll]  [Google Inc., 2, 0, 301, 7164]
    : I0 B% R) ^# q" w9 U; v
  275.     [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll]  [Google Inc., 2, 0, 301, 7164]
    . O9 W" C, S- h5 J6 q( z
  276.     [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 1, 5, 1001]* N  i- Z6 B; r( E& L
  277.     [C:\Program Files\Tencent\QQ\DShared.dll]  [Tencent, 2, 1, 0, 0]
      J# ~; H) {- X6 c
  278. [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    0 G9 v8 e( s9 [
  279. [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe]  [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]
    " X2 j3 q8 a0 `; G, w& X' z
  280. [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    ! Q! U, o4 t% Z1 Q# K* A3 e; v3 s5 }
  281. [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]" ?, m9 T) R" a" E/ x
  282. [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
    ' Y9 I. h$ S9 s) K- a+ E5 X
  283. [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]' z  F$ Z1 T1 H) {6 Y
  284.     [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 1, 5, 1001]
    0 m0 T% x% R1 p5 j1 r/ a" S: q
  285.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    2 m. i  [& \  t  q4 Z
  286.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]0 ]7 \) w+ c7 q
  287.     [c:\program files\google\googletoolbar2.dll]  [Google Inc., 4, 0, 1606, 6690]- J, {, u% j! b$ Z
  288.     [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll]  [Google Inc., 2, 0, 301, 7164]- [9 ?% g7 N$ g* u+ ~$ I6 W
  289.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL]  [Kingsoft Corporation, 2008,04,15,2]9 `2 c: g% |; k, S* W4 B
  290.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll]  [Kingsoft Corporation, 2008,04,15,2]
    0 i1 _# d( _7 q
  291.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL]  [Kingsoft Corporation, 2008,05,14,83]' b/ o& j9 t0 r% k4 ^
  292.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll]  [Kingsoft Corporation, 2008,04,15,2]
    * D, |: p$ _( O/ a' m2 m
  293.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL]  [Kingsoft Corporation, 2008,05,13,78]
    2 C( h0 x" l. W8 G$ }
  294.     [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]3 O; g& _$ v. w: t4 L; Q
  295.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]: L& Y& Q* d% V
  296.     [C:\WINDOWS\system32\WN.IME]  [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]1 k, _# _  c) i
  297.     [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll]  [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]7 g; f& j3 A' Z
  298.     [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll]  [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
    % N) m! D7 V& k0 z) M& |, Z& \
  299.     [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll]  [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
    # h7 J$ x, \; Z, Y- _
  300.     [C:\WINDOWS\system32\SOGOUPY.IME]  [Sogou.com Inc., 3.2.0.0]
    ' F$ V! p( R4 f! E) k) N7 @+ j
  301.     [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll]  [Sogou.com Inc., 3.2.0.0]
    2 P6 B8 I3 Q( o# Y
  302.     [C:\WINDOWS\system32\WINWB98.IME]  [Microsoft Corporation, 4.00.950]
    * H# v8 C8 Q6 ?" f8 f- B, w( g
  303.     [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    ' y5 G4 z; j- p/ s8 [
  304.     [C:\Program Files\Tencent\QQ\DShared.dll]  [Tencent, 2, 1, 0, 0]! y* }) M" ~3 Y0 @, ~
  305. [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe]  [Tencent, 1, 0, 170, 0]
      A) w  A% S$ y% o7 v  H8 x% I
  306.     [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 1, 5, 1001]
    7 |% Q8 H/ _# m; S
  307.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    * _7 C" l. l7 ?" W* T7 z
  308.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]  E# f5 R4 m' h4 X1 i
  309.     [C:\Program Files\Tencent\QQ\DShared.dll]  [Tencent, 2, 1, 0, 0]
    ' ]* W; n. w" `8 h! i* r
  310. [PID: 928 / Administrator][F:\arvmon.exe]  [任软工作室, 2.2.5.201]
      `( Y2 w0 `5 @) s* n3 B; t
  311.     [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 1, 5, 1001]
    ) Y; P% s( E, e/ m
  312.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]! H" j' W! x" x- B0 _8 r, B  E
  313.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    1 O: @# \. W) x
  314.     [C:\Program Files\Tencent\QQ\DShared.dll]  [Tencent, 2, 1, 0, 0]
    2 \9 N2 i+ _/ z2 n" k1 |
  315.     [F:\Vdata.dll]  [任软工作室, 2, 2, 1, 94]
    6 }3 X- D9 z/ W
  316. [PID: 2540 / Administrator][F:\AutoGuarder.exe]  [任软工作室, 2.2.5.201]9 l0 |% P; L) X$ ^8 R: C6 s
  317.     [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 1, 5, 1001]5 _7 ~/ }0 I% b3 E/ p# P8 k& L- l8 {
  318.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    0 J. j: P# Q, J( K# X' @
  319.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]. m6 t0 P' ^& l0 X1 R7 f
  320.     [C:\Program Files\Tencent\QQ\DShared.dll]  [Tencent, 2, 1, 0, 0]
    . x7 C% M  _) ?! A+ ]: Z- K
  321. [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]; g( u; a5 L+ F! O" _
  322.     [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 1, 5, 1001]+ P2 P( \+ ]+ K6 K: Z5 V* ^& w5 A' J
  323.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]; X) K" k( w" T- s1 B( O. [9 H3 a
  324.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    6 S9 T. t7 ^0 l/ n! o/ K
  325.     [C:\Program Files\Tencent\QQ\DShared.dll]  [Tencent, 2, 1, 0, 0]
      B  F! m) T7 ?+ O9 T" A9 ]
  326.     [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    3 s& e: V! m) ~
  327. ==================================
    4 k+ ]' Q4 s# e& `5 V: p
  328. 文件关联1 D& i3 c( C9 T# ?5 b
  329. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
    : q( `8 M5 q( y* n! B9 v9 R; e
  330. .EXE  OK. ["%1" %*]
    0 s5 y: M* H3 g4 w2 ]
  331. .COM  OK. ["%1" %*]
    3 o- j' e1 e! _0 L: g9 D
  332. .PIF  OK. ["%1" %*]
    ! s# d+ [& n. g1 B- C
  333. .REG  OK. [regedit.exe "%1"]' f& d5 d. X0 n' c7 ]% _5 s& Q
  334. .BAT  OK. ["%1" %*]" _+ V8 r2 B6 D- j
  335. .SCR  OK. ["%1" /S]
    4 n0 r4 V6 T) G* S: ~
  336. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]& T* Z& \, H$ ~" [/ i! |, E+ g
  337. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]. N6 l! c2 K) t; j
  338. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
    : m  p+ m3 ]) [: F% t6 U0 U, O
  339. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
    9 x3 u, T5 s1 F2 o
  340. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]( Q' p7 n4 g+ W4 v7 q
  341. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]% [, v1 ]7 `% R( M0 h
  342. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]# |4 c( V/ L+ e4 J
  343. ==================================
    ' z' h0 R4 [  t# c1 z( K) U* j
  344. Winsock 提供者
    / i( P8 o* E2 f9 N8 \! g+ [
  345. N/A& z  C7 g: `2 g/ P- b
  346. ==================================
    : h( A: t8 T" D) ]
  347. Autorun.inf/ P: Q7 p* x. N
  348. N/A7 \5 ?  L1 t( O- t# p9 C
  349. ==================================
    & H, d" N$ e  ?; x0 a9 f+ P
  350. HOSTS 文件4 X$ ^2 g' b8 r4 B! L# |
  351. N/A7 K7 O4 G7 t9 H- F- @
  352. ==================================
    . |) f) A8 O8 G( w  n
  353. 进程特权扫描
    7 T. d$ X9 A. B: {
  354. 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
    9 b  Y( a- G8 V5 Z7 R+ E
  355. 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]5 k8 {1 Y( u2 r8 T1 B+ N" e( E: _
  356. 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]
    9 f1 p/ U- ~" ^4 L1 g* ?, ~$ \
  357. 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]
    * y3 F* K1 A  x
  358. 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]+ N6 M( Q' v$ N( m( _
  359. ==================================- C; ]1 r. ^: M9 J5 _3 j" r
  360. API HOOK1 w# `# C& I' `4 A+ l/ |. l
  361. N/A2 k* A3 B9 L! ^7 C- E
  362. ==================================
    6 a, `0 y% ~0 i4 U5 Y3 w, M" F
  363. 隐藏进程
    + R8 F$ D; n  s+ p$ K- @
  364. N/A, r3 _8 ?! c% i: D0 q1 W" x
  365. ==================================
    " X( [; f; k( u) p+ \
  366. " e- `2 }+ I+ ~: y6 l
复制代码
发表于 2008-5-22 21:40:31 | 显示全部楼层
跟原始说了,不知道能不能看明白。。。
发表于 2008-5-22 22:23:55 | 显示全部楼层
[Start]: p9 j0 D9 ~+ l& X! P  l

7 z7 G5 X: Y7 e& D9 C% \2008-05-22,22:24:211 _5 ]. |2 f# P7 m* |& ^
$ u; O+ G, U1 T0 d. i
SREngLOG智能分析专家 V1.2.0.125
' O$ k8 C. Z4 T8 I. M0 i2 p: z- OTored (http://hi.baidu.com/peaset)8 x& d1 W3 @. `& Y, n) j( T6 ^
: S- r! r7 V; l+ e; E) J
======================================================
+ Z: M) G7 }$ ?, F% w- G1 b( M. e6 S! K以下过程将用到SREng、PowerRmv,如果您不熟悉这两款工具的使用方法,请参考下列链接:: [" b/ J$ n% Y
SREng详细操作方法: http://hi.baidu.com/peaset/blog/ ... dd19224e4aeadf.html
; R4 _" j( T; }6 z  QPowerRmv详细操作方法: http://hi.baidu.com/peaset/blog/ ... 6fb5eb77c63816.html
8 D# N( U4 r5 [; S" P- Y. Q5 A======================================================0 N$ o. V9 C9 q! r

* g$ Z6 d; x* j; V5 O, [0 {- }以下是病毒清除步骤:
1 f2 A! h! X5 o7 q: f. u
6 L5 b4 z  ^2 ]! U! D0 |2 g; v1、用PowerRmv删除以下文件(没有则跳过):
4 Y% M$ t$ o" h- r6 }( F$ v/ N: M; m) P$ L( G1 P
; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
# I& ]- A. L% G0 x& _: X! ?;
# {- B- d0 Q; q9 s+ Q0 C& H% J$ `; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
1 H& s3 R; I0 ^% A* z" hC:\WINDOWS\System32\3wareSrv.exe* C' h: J% R: }& Y9 D$ q7 U
\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll, u. j' D; r8 e# g
+ w/ ~- z5 P6 Z- K% z0 E. M/ o
\SystemRoot\System32\DRIVERS\22jn.sys* s7 V7 u# y, b- W; P6 U' F5 n
\SystemRoot\System32\DRIVERS\43ecu.sys6 S* y* r* C5 q
\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys
: {) a% b9 p: ?3 c- M/ O3 a\SystemRoot\system32\drivers\pnduojtwbt.sys
! g7 U. g" F! V2 s" q  A6 H\SystemRoot\system32\drivers\RsBoot.sys/ ^# N1 M$ e; a
system32\DRIVERS\sr.sys
0 Z/ z2 S% Z6 ?5 r+ p% d\SystemRoot\system32\drivers\unzxzsrs.sys
2 ?4 n. Y! O/ S0 y$ m* a4 `' Y\SystemRoot\system32\DRIVERS\ViBus.sys
9 C3 a+ s( L( T/ ?, V5 O\SystemRoot\system32\drivers\zhibmaso.sys# Y& `6 v" C# f' L1 ^/ @
, d, y5 H( \+ g8 f9 X6 M+ j
2、用SREng删除以下【注册表】项(没有则跳过):! F1 Z4 [; l  {4 P) X

/ d+ B" E. l/ S4 e( J3 P7 @<IMJPMIG8.1>" E' L. |" f, \  S/ n
<PHIME2002A>
: N2 f& l8 D: ~- r<PHIME2002ASync>+ `" j; J4 a3 N% o, m
9 X$ q) c5 L6 D3 J0 E1 Q3 @
3、用SREng删除【所有启动文件夹】内容(没有则跳过), r8 C8 m& T5 V/ [

5 R' r! [  z' `9 t) u$ _4、用SREng删除以下【服务】项(没有则跳过):6 h# T% x+ E: c  {- c' A
. s; Z  x: p# h5 [# F( n9 I1 ?  X
[3ware Controller Service / 3wareSrv]
. \2 y1 l2 V  I+ N& i9 Y[NetMeeting Remote Desktop Sharing / mnmsrvc]* V2 A. ~4 S1 q7 v; G" w

) G  Q. X1 ]0 t8 D5、用SREng删除以下【驱动程序】项(没有则跳过):
1 E* L& e5 A1 D; s8 P' p' K
2 ^5 M9 N  O1 h% l[22j / 22jn]& Q1 W( L$ a2 `3 O, c% Z7 e3 o
[43ec / 43ecu]% Y! D8 ?8 z1 \# ]* l0 X5 _2 t
[ntptdb / ntptdb]
" v' [% o+ h7 ?/ F8 R. z' }; c[pnduojtwbt / pnduojtwbt]
6 H% B8 a( n% Q: p[RsAntiSpyware / RsAntiSpyware]
" X; O: M+ b4 e  V' ^. I* l[System Restore Filter Driver / sr]
5 V1 p& t2 x! Q" t+ p) s% e[System Services / unzxzsrs]1 \& A! K% f* \8 L1 o/ Y( _" l6 m
[ViBus / ViBus]2 k( [( \- e' N2 N! b  l6 C8 |
[ATI Extend / zhibmaso]
' D- D* ^1 K% h" l3 Y, Y3 {2 b4 D& Z8 p2 B! O: M9 \7 U
6、用SREng删除以下【浏览器加载项】项(没有则跳过):
# V, Y6 }* g2 k/ q4 S& o
: x$ }# Q% r! V  N1 K[Zcom 杂志]' \" ~, o! O0 h. }, K+ _# s$ \
[Browser Enhanced Objects]" e/ j/ |- m7 q5 H) ]3 G

$ }1 o8 L4 m4 k( p; ^最后,重新启动计算机.Tored祝您好运!+ ~5 v' W8 ]0 E1 Z& D
======================================================- Z- \+ A5 _) ?+ [
[End]
发表于 2008-5-22 22:24:30 | 显示全部楼层
你就这样弄,不行我也没办法
发表于 2008-5-23 13:18:44 | 显示全部楼层
独恋有按原始说的重新操作一次吗?
发表于 2008-5-24 20:09:59 | 显示全部楼层
找不到要删的文件。。。。
发表于 2008-5-25 08:54:35 | 显示全部楼层
有些都是隐藏起来的
发表于 2008-6-5 03:36:36 | 显示全部楼层
2 H" b( K; M) M- z2 l, a2 }4 u

: n( u$ q( P. A3 F我对代码 一点都不懂
发表于 2008-6-5 14:21:26 | 显示全部楼层
。。。这不是代码只是系统的扫描日志而已
发表于 2008-6-5 18:19:32 | 显示全部楼层
我汗~~~
$ p0 q9 I+ N# J0 C这么多代码~~~
您需要登录后才可以回帖 登录 | 注册

本版积分规则

傲天阁游戏公会
联系我们
咨询电话 : 020-88888888
事务 QQ : 85075421
电子邮箱 : admin@admin.com

小黑屋|手机版|Archiver|傲天阁游戏公会 ( 粤ICP备14058347号 )|免责声明

GMT+8, 2026-4-2 23:50 , Processed in 0.110022 second(s), 6 queries , Redis On.

Powered by Discuz! X3.4

© 2001-2013 Comsenz Inc.

快速回复 返回顶部 返回列表