|
|
' t3 |: D# j/ w; F) F' K% _0 a- 2008-05-22,20:37:43
l( T" i/ z2 t$ F - System Repair Engineer 2.5.16.9008 x3 z5 r5 n( k; R% }4 J
- Smallfrogs (http://www.KZTechs.com); D" s* ]$ h* ^9 `# s/ q# U
- Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
' _; G& i; T$ o) g3 ? - 以下内容被选中:; T/ c; E* Z# e* _5 Y. ]' k
- 所有的启动项目(包括注册表、启动文件夹、服务等): E2 x4 J$ K: X7 O, U- O' t
- 浏览器加载项
% R6 S* a/ J5 f" ]4 p3 z h - 正在运行的进程(包括进程模块信息)
$ |$ n |5 N5 ~9 i4 l& R) w - 文件关联
. h8 B+ z4 y( h; g& `6 Q - Winsock 提供者
7 D$ ?. d- n; b' d }4 F6 U# U - Autorun.inf4 N9 _3 V, R0 c) P7 p
- HOSTS 文件
8 l1 `& `+ L6 Q3 Z7 S - 进程特权扫描
. ^5 c2 j1 r7 u* O
3 ?5 N7 v5 B' U# _- 启动项目4 b: O2 L) s( q0 {" r
- 注册表
& d2 c# _* {* U$ r5 q8 U m - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
3 p8 ]( [! a( @5 s ~1 n9 |7 h& z - <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]
- y' h; @# _9 u1 U! m7 } - [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]6 S' I/ }' z, N) j
- <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd], f! P9 A5 c( C+ h2 s
- <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]; T8 T( S# h7 N) i7 e& `% W: m
- <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
6 H) w' V! h! N% _" p0 n& }8 m @! @ - <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]6 Q# F* H* K( E6 \8 e% i9 w2 C2 f
- <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]
' J8 h9 X+ k% }( J! I - <PHIME2002A><; > [N/A]4 W' I$ Q# b7 h, i& O+ T9 \
- <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]7 a! ?6 z3 E6 p/ k9 G4 v( G
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
7 Z4 G% j& `6 k- | P, \ - <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
$ H2 Z$ t% P" n; d d# \# G - <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]
1 p; l: z. P2 k5 \# k0 Y2 M; M - <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
- ?" W1 e0 D2 t8 ^; F" g - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]3 [& h7 s4 x: s9 N( p3 A/ i
- <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]% J# n: q, W3 f. {3 J; P% L
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]+ }1 [. }0 g0 H' y, Z
- <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
! q: a& Q/ Z4 g. x0 ]1 v - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]5 {! I& A2 J' |9 f+ d+ Z
- <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]8 o9 }3 c# Y7 a# k: A6 a; g
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]2 }0 X5 L: D. B4 Q
- <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
$ t8 X' I$ ?' C - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
9 Z) n0 w& b" w5 t3 o& i7 i - <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]2 J% ~; Y9 P) l2 Q+ y
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
: T+ N* F! a1 d - <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]
' e4 L' g* X# t& s8 P# Q - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]. P, _- p7 i: }; E. ^. @
- <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]' n( I0 I9 B& S3 S/ R+ n7 M& @& q" ~
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
6 p* T* U/ Q8 d1 X. p( r! n9 ? - <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
$ g( z' R7 R# d' d* }) j - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]5 N, h- I7 P, p: y) k& z6 o" k ^
- <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
% c. Q, Z* [7 g* _4 i - ================================== I# ~! p B% }) F7 m1 H1 p) G
- 启动文件夹
& w9 k, @, _) C# m - N/A
5 |+ }, |; M, A' ~5 \ - ==================================
6 P+ J, N9 E2 [8 y. T - 服务
: ]+ {1 I: v$ Q: m - [3ware Controller Service / 3wareSrv][Stopped/Auto Start]& W. i: b% }+ W( P/ ^" C4 X W8 V
- <C:\WINDOWS\System32\3wareSrv.exe><N/A>
* W5 ?! s; @: y% D4 ^ - [Google Updater Service / gusvc][Stopped/Manual Start]7 Z& @ ^8 E% e2 Z
- <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
* q7 Y' c5 M {9 Z: v q0 t2 l - [Help and Support / helpsvc][Stopped/Disabled]
) O. f% `) F& {5 o8 }+ S. N - <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>
" x, }6 f/ A" B - [Human Interface Device Access / HidServ][Stopped/Boot Start]
) t9 Y3 i% f! w$ e! R - <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>- @' Z$ I; m0 O* [* h% G7 w
- [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]
2 D0 n- i( c& [ - <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>8 m( @% j1 M2 w& ?5 u5 m6 A$ {
- [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
7 S2 d, W, q% y" S9 W* c3 w% X - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>
' l2 S8 J# {4 {. y - [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]( _0 e! G% B' c. R4 y# Y1 [
- <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>
- a6 p; W. }% p, G - [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]
. o; ?" b3 D9 B1 B9 V8 p& r' B - <><N/A>
" `+ j8 \1 S+ u3 j+ B - [Qvod Terminal / Qvod Terminal][Running/Auto Start]
; I* M* b$ R' o% M0 a: G - <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>8 _1 [1 m' M0 _$ I) L# [
- ==================================' [) ~, u7 M+ Y" |& A
- 驱动程序
' ?6 h2 n( e) f% \3 N) a - [22j / 22jn][Stopped/Boot Start]
8 o% K0 J# j Y8 x - <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>0 o$ i P% y4 c7 V) f. E
- [360AntiArp / 360AntiArp][Running/System Start]1 Y: M+ T1 d+ H" g
- <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
6 y% S3 C* w: ~( v/ M, V - [43ec / 43ecu][Stopped/Boot Start]
9 u+ ^3 x s5 r( g ~ - <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>6 m) A% Z/ T7 l1 Y3 f
- [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
4 o/ R! R7 S4 y& T( {; u - <system32\drivers\ac97intc.sys><Intel Corporation>
7 @/ d; c) y( i6 m" J - [Promise driver accelerator / bb-run][Running/Boot Start]9 a/ \" c9 i8 H# C" w; y
- <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.>0 f6 o: l/ R. M! S& g/ D
- [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]% j/ W2 S/ u, Z# A4 L% M
- <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>& e' W9 e6 \ ~) |. f
- [KAVBase / KAVBase][Running/Auto Start]( Q& k1 V+ D; o# M0 l, K( a
- <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
3 `3 G& Y" l9 ]% i% j - [KAVBootC / KAVBootC][Running/Boot Start]
( U7 @/ z0 e! ~% s2 P' i: `6 } - <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>- M' m, k' w2 e; l9 i& R9 n3 U$ }
- [KAVSafe / KAVSafe][Running/Auto Start]) L \9 E7 E( |$ Z1 l8 y
- <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>5 I- e, C& {' _* Y& }7 Z
- [KNetWch / KNetWch][Running/System Start]1 v8 K) L+ R; L* {5 d1 \1 `
- <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
8 V7 `# H( i2 I - [KWatch3 / KWatch3][Running/Auto Start]
7 }. B. Z9 W7 b+ ]1 t# U6 c - <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
4 V% {. R4 z6 S# g" a/ G% Z0 a - [ntptdb / ntptdb][Stopped/Auto Start]
1 C- d# k' L. L) o* `5 R3 _ - <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>* r" H$ R( r, _' Y( a
- [nv / nv][Running/Manual Start]
& m+ G+ t. o, }, [5 {9 h+ \ - <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
" k/ I1 F) r' r; t - [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]
1 ~/ a: ?' g0 d% X( H - <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>. `4 Y6 b0 S* k& Z$ C: @ V, @
- [DDK PACKET Protocol / Packet][Running/Manual Start]
" @- i& }$ A* w0 F - <system32\DRIVERS\ProtoDrv.sys><360安全中心>
* {6 k$ e/ g( X( ] T/ |% v. i - [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]
3 t, N: `, [ S3 ~# o- Y1 t( t - <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>0 A# E& W( B: v
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
0 q- q% [7 L1 _- [7 ] - <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>! x6 }: f* o/ X+ i x
- [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]+ t5 H e: c- l" K5 s; w0 B5 c1 T! f
- <\SystemRoot\system32\drivers\RsBoot.sys><N/A>
" ?9 V& t9 U! R( g/ }/ A - [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
( {' D% \3 h, I - <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>+ N( x1 Q7 t8 ~: K
- [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]
. y8 ?; s! z! C# o" T# D - <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>
/ b& Y7 Q+ E4 u - [Secdrv / Secdrv][Stopped/Manual Start]/ |1 U. n m u! P& A. D7 J4 j
- <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>' K, d1 @8 d0 n$ D8 O
- [SATALink External Device Filter / SiRemFil][Running/Boot Start]
* d* U0 Q5 l( g* P - <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>1 T. v2 @% J2 J# g: `
- [System Restore Filter Driver / sr][Stopped/Disabled]2 X) E( k8 s0 _+ A5 _
- <system32\DRIVERS\sr.sys><N/A># V D9 x" P7 Z1 m
- [TesSafe / TesSafe][Stopped/Manual Start]! ?1 i# F! i$ R9 z( k9 q. B3 E! N! T, [
- <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>
# e+ b- B% q5 o5 n - [System Services / unzxzsrs][Stopped/Boot Start]/ i1 {- T0 O5 ~2 ?7 I; n, B1 N
- <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>% I+ ^! m2 I/ w2 K$ p
- [ViBus / ViBus][Stopped/Boot Start]) d& {8 ~: s5 w, P' T
- <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A> X% }7 n9 J* H
- [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]* }) ~! h- C3 D; ^3 e* B3 ~, k
- <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>- O& e- s+ M8 m: c$ J: I
- [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]
4 r7 F6 a" {! a8 n - <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>
9 E/ D* ~1 C4 b - [ATI Extend / zhibmaso][Stopped/Boot Start]& B( A* m& a3 \4 x# N. B( m+ d2 @
- <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>
h; \5 }. v& E3 d: u5 f - [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]* j* j& Q' V+ m
- <System32\Drivers\usbVM31b.sys><Vimicro Corporation>
6 g- `9 Z% e2 n% _( Y - ==================================
) |' C$ R1 |/ ^- W$ z" | - 浏览器加载项
e% |/ N$ t; d6 P, N - [Google Toolbar Helper]
; o% `2 {$ G5 F# c$ C; W; x! }! i( r - {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>% |! A* c9 U7 |, ~' s, \
- [Google Toolbar Notifier BHO]
1 Z% s0 S8 p& |6 g+ c) E - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
; z$ g6 p/ j* f! [' p" J- c - [SafeMon Class]
) C. k! @: E0 O& z/ C W7 M - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>8 l* n1 z5 v& i- h" j/ ^
- [kingsoft browser shield]
# Q6 D. Z0 @/ | - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>: @7 u0 u& H, x. H
- [IEBuddyExtControl Class]
- v9 R- y! a. z7 D. v6 g0 \: B, G - {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>+ k( d$ G: ^) M! U' }! n! M) B
- [Zcom 杂志]
& z+ t5 F7 k0 u k7 Z( _ - {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>
9 z. o/ l7 W9 P# M - [&Google]; d) l& n4 A' k- P" Z
- {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>5 n, u! `9 d E4 C: R! k- |
- [KooPlayer Control]2 O6 D" q' P; y6 y6 V) y1 o
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>: [: K4 S" ~* L# |/ O
- [Shockwave Flash Object]' P" z5 ~' y/ E+ W9 w) e7 t! B0 F
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>& J+ P! H: E+ [* R: E
- [KUpdateObj2 Class]
7 \ i! v) ~5 f+ G4 P O: T - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>5 I" S/ H$ A# b$ Y9 q
- [Google Script Object]$ |& `0 U3 r, |, K6 _
- {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
1 H k+ W1 e# z - [EWA Control]' T9 }% c( G1 o; t# X$ H
- {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>
) M a J! Y2 j - [Windows Media Player]( F: ]) e3 ]+ f i5 B" u
- {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>
4 j: K: v/ b j2 }$ A! l0 } - [&Google]3 W- q% a1 O$ G% N3 T$ P0 K
- {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>$ G8 M; W, D) V. M" x' s g/ B
- [HTML Document]
8 }9 b6 M# A' u3 c" S - {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>2 y' h! F9 K* m1 R# r
- [DHTML Edit Control Safe for Scripting for IE5]
- j6 a' t7 s1 B - {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>9 m0 R6 d$ ]# I6 `
- [RealPlayer RAM Download Handler]
# i2 x% J: w6 ?* |! y4 ]7 i - {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>3 @/ o! G, W+ _7 p
- [IEBuddyExtControl Class]
& b. d) j5 J+ ]$ E6 s. b5 l0 |5 f) y9 ^ - {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>+ z9 ~- |0 a( P* Z+ S
- [XML Document]- G2 c6 ]' {7 h
- {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
9 d7 e( V' h$ e+ o - [HHCtrl Object]( ?3 h, d4 y! [1 Z
- {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>2 Y" ~2 e- R6 b/ {
- [Windows Media Player]
& d3 H/ ? U( |. ?4 a' N# V - {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>% k- {) C% b6 `' p
- [Active Desktop Mover]+ Z$ x- s8 u6 x3 F- c. U
- {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>/ y2 g# s" G9 Y M6 K
- [360SafeLive]( j. ?7 F ?4 |+ _
- {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>! s. \; I* r' Z" t2 p/ t/ k
- [Microsoft Web 浏览器]
3 ]) V' d; P4 t - {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
+ R& e$ u, u$ h& D$ O - [Browser Enhanced Objects]
! A/ I/ F. u# s# F - {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>
1 }$ g- Y1 X9 D! f( x - [Google Toolbar Helper]) L6 V: o7 k* g3 t" o; w& l, {
- {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
" B' G' L% ^9 g+ m - [Microsoft Scriptlet Component]
) _- i3 u$ l4 d% X/ G7 f - {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
. f8 p7 K1 y# B7 p& l F - [Google Toolbar Notifier BHO]5 \( s) t7 _ O. z3 ~
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
% w, s$ `! o& s. t. n! [5 E - [SearchAssistantOC]
$ e b+ ^- a! B/ S - {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
8 _# P8 j4 y2 ?! O* l - [SafeMon Class]
, A/ C' B$ _5 I* Z% O' e - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
+ [( X8 w3 {9 U$ c6 J - [RDS.DataSpace]
8 e. ]3 m$ i3 g- Y - {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
5 g! q+ b/ y0 T9 G; {# n t - [KooPlayer Control]0 h5 p# P5 j1 x8 t0 L* _: ~
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>& a; c; f$ X. s. ]$ V
- [AUDIO__MID Moniker Class]
3 j# I1 ^$ M1 O( G* q$ v; J2 y - {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
8 N' c. V, B8 I - [AUDIO__MP3 Moniker Class]
2 ]/ l- h$ u9 J1 A& G: Q1 U9 n - {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>" b J8 A$ N' o# B, |% _ t$ k) p5 r
- [AUDIO__X_MS_WMA Moniker Class]8 f) {- `' S/ W' D% c
- {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
5 q/ G8 e) u& b$ l' j - [VIDEO__X_MS_WMV Moniker Class]! m0 A# A7 p0 {3 r/ Y9 x
- {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
, _8 A1 A4 e8 M - [RealPlayer G2 Control]7 S( }6 z" n7 G
- {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>$ \5 H% m* D8 \* T( n+ ~! s
- [Shockwave Flash Object]
8 n2 G7 Z9 {9 E( z. k6 f/ m% [ - {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>, {# e% j9 n# a7 O5 M
- [KUpdateObj2 Class]
! o* z0 |7 Q6 X% f4 l$ }2 U$ O - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>4 b0 L( J3 Z* B
- [kingsoft browser shield]
`9 y/ W! a; J' J) G - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>* y0 U( o& e: j3 P, G
- [PasswordEditCtrl Class]
) X6 V/ r0 b. i' R, v1 @, x( l - {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
. m4 u+ `# i: T- d' e4 a& W7 Y - [QvodCtrl Class]
h: ^& `& I. ~" Q9 T - {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd> O! X6 }% T. i# Y5 _& m
- [&使用超级旋风下载]
3 f5 K7 e, G: u! k# @ - <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>$ ]" @% o6 a, b4 p$ y# L( _/ Y
- [&使用超级旋风下载全部链接]
- Z9 @' {2 B7 v' [+ U - <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>6 ]$ y4 f8 A9 g# \
- [使用迅雷下载]& s7 q; ?: D, ~' |" ^# K7 {# w
- <, N/A>
* y" H1 R/ o; u; j/ \ - [使用迅雷下载全部链接]$ K$ v' ~5 x3 L5 `: _" r: f
- <, N/A>9 {. X+ O# r2 Z" C) M; H! Q
- [导出到 Microsoft Office Excel(&X)]
$ u: b- Q/ k8 t - <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
( W& f* R7 W S2 D4 k - [添加到QQ表情]3 j$ F7 X4 B# G1 s/ w0 f3 w
- <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>2 Q* j6 c: z1 ]
- ==================================
; ?8 r3 I8 A) z - 正在运行的进程% f4 J$ C6 G: Z# z; T# x9 \9 g- O
- [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]8 C4 Z: b+ A1 p1 [1 m7 g8 e
- [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
; Y' |3 ]( n; F - [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]2 O" Q$ Y0 \: J7 D0 ^) @7 b2 v
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
1 _5 K6 l( }& p# i9 g - [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]& {! }! O7 ]! K, H) @ d1 S
- [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]$ Y( B) R4 \$ O. O
- [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
4 n0 k: p( ~% \& Y+ q, L2 x3 H# {/ G - [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
. R: K S7 L# A8 @ - [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]! I! p, Z; S8 Y, B8 F% O& X
- [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]% z/ P6 T; R& z1 b4 F$ I0 Y
- [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
3 b3 U2 Y2 d0 |$ r1 O- N8 Y$ S - [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]
% m' H u7 l, I - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
5 _3 b/ G6 x S* y4 b2 `7 `9 B1 ^ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364], y, l1 b) e6 w+ ^' o& w& y2 |
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]; E0 ?% o- j, l, A3 ~! X! Y
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
+ z5 Q! v$ x2 U6 {% \& g7 D - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]
- n7 X5 ]+ t* Y, {$ n- x4 @! D - [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]
& \' N2 I+ h9 w" S - [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
2 p, _: J; {# @1 h( u" n - [C:\Program Files\WinRAR\rarext.dll] [N/A, ]" V8 }3 @, S7 v/ `# |% P, [0 R; O) j
- [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
9 U3 E4 `/ \, p - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]6 L% V2 M) d& W4 o
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
3 J( a2 [% E0 u! a- W. C+ c+ z - [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]3 U& {- |2 j& Q* y# @+ i3 P
- [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2] e% a& `- {# h% A, S+ U7 J+ F3 g
- [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]
, [) ^) S5 x9 Y' H, f7 \ - [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008]
- _( D' ]' P% R3 |0 g6 T: K - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
S/ B i: C- C - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]! H/ Y: T* `8 N* U1 B! U3 j
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
- o" h( C( `+ {: @1 \ - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]. X& Z$ U- @- Z, D8 [. V) u
- [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
) A; G1 Z! ^8 K R* t; L& w - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
" L& T5 H3 T+ H' h- c - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]/ V. o c0 V* {$ P3 F
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]4 ^% `/ Q) u% R! u7 g: r$ r
- [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]
2 h& ~% M! N. G, F - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]
# F( B5 ], Y ]* r' b1 f, [. P - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5] M3 G# ?; {3 o- ]# I8 l( U/ V. q
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]- z8 M( e0 f; H8 |/ f
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]# y% E! M) J; M: E$ t- J
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
' f; R e" _. S1 \" n - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]2 F, m% {. d/ i; L4 c) e- t+ k2 u; ?' C
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]6 B6 c5 V4 G1 z& {( G* X3 w
- [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]" P, q g' t9 D7 z
- [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]6 i# u9 J0 p9 F6 Z& N$ @
- [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] L/ l0 w0 H7 a5 _; J0 c# n
- [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
! b( t( ^" F$ d. ] - [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
, T9 g& f$ V. a - [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
1 N5 P7 z2 E6 s - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
1 P0 E& t& E3 [ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]7 J4 A. q; L6 v. Y0 p* |1 m
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
4 b1 p1 W, B- L4 p - [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]) \, m5 ?) {1 l% A y! Y- i
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]1 J. P' @/ ]+ W2 _' d3 h1 Q/ C
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]
9 f- E" Z$ q2 v" F& q3 M0 E - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]
" X1 D8 B; Z' ^$ D( j" d - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]
7 i; l. Q Y. a. }# ?% K - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]/ ^: S$ T8 X& I( w1 H
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78]: W5 | S* o3 g; Z3 ~
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
8 l/ I ]5 {$ W+ Y" n/ W* | - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
* g( ]5 z$ p* B* g p& G( R - [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
8 k2 i, Y, @7 x0 _ - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
' G5 K: @/ {+ z8 E" J - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]. D$ ?" X4 A3 T) X
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]; z& B* D* I6 B3 ~# R
- [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]
6 [" }1 z' k. b* o, j) w - [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]
: p1 h6 i$ ^% S$ B - [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950], ^" _& t& h P2 u7 G
- [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]
8 E5 x* _5 u e7 Y - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]3 e/ q' N' _' s3 r- b G! D
- [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]
% I9 k: s2 J j' q, Z, ] - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]2 y/ M' D6 Y7 u" [% f: F" ~
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5] R: l Z2 l7 B! H2 G& h( K, ? u
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
. }& i) e5 z- {# }' {; L- S4 ^ - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
0 f% l# b% L) E/ i - [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201], s- x9 U4 v, y1 P
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]* x4 m* o& T% M" ~* F& f& ]
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]+ Q! m: O* X9 J0 M0 U$ L' u! \7 [2 V# ?
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
) f3 r, |/ Z" n; ?# b$ ?3 ]1 Y- w Z9 o* q - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
$ a4 @" u8 K' i - [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]
# o7 S" n; u" l! y$ X - [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]
+ I. k7 D. }: c- T+ g) F - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
, q' _! V6 L- s- z! d) I; a9 k# O2 t - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
2 p. k! e( q! |0 R9 s - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
* T8 a: x: b9 o' A# N - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
2 k! k* `3 P3 `& C. _- Q* d - [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]9 R% a U4 ]/ d
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
1 O7 S- a6 J2 i+ [0 t4 y, _* ^ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
) S' r4 \& \+ l% D1 `/ |0 N7 _( O - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]7 X8 d0 B, l0 b
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]# n+ u, l k( v1 }8 m8 ~
- [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]% v) w/ [6 Q" O2 f! w- f% o
- ==================================- |+ ^ C1 m9 y2 Z! N; }7 Y
- 文件关联0 K1 ^5 E1 I0 M) y
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] `* t5 D# C/ t; g7 Z1 R- h
- .EXE OK. ["%1" %*]
/ C: }* _) X* z* ]6 N8 r( d. i4 ] - .COM OK. ["%1" %*]0 j( n2 _- }1 n+ d# V c
- .PIF OK. ["%1" %*]0 b. k6 Y+ g' E5 }" ?8 r
- .REG OK. [regedit.exe "%1"]# s3 E0 F8 T2 R, f6 ?/ m! G
- .BAT OK. ["%1" %*]- B6 V, k" w* q, g- q/ S$ E* |! L
- .SCR OK. ["%1" /S]
1 }5 X; t; g+ v+ } - .CHM OK. ["C:\WINDOWS\hh.exe" %1]
: L8 n% S! C1 F, W. g! r% s4 U - .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
# l' b& e! R& Y - .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]$ d" m) U8 O& e
- .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]7 {+ w3 p) l7 E/ O* u
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]/ Y4 q. d2 r1 D' k/ b
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
6 s; H" c! X8 v# w& ^ - .LNK OK. [{00021401-0000-0000-C000-000000000046}]$ \; Y* B2 k+ y2 h7 q8 F/ O
- ==================================$ ?- h: r/ b; ]+ p8 _4 t- _
- Winsock 提供者% n. x/ S9 Z' |
- N/A) p/ ]2 a* B( r; _
- ==================================9 R3 E' E/ w) t- \+ y
- Autorun.inf, ^( _ J! }) O% L1 j
- N/A7 C8 C* s$ S; z9 }9 W
- ==================================" B$ {2 M- c5 ?
- HOSTS 文件' [8 c5 i" u& ` M1 F" i
- N/A
: [8 t' \$ A& _ - ==================================, u# j& D# `6 d( T, w# a m2 `
- 进程特权扫描
' r7 }& j3 \ Z7 G- v0 w! o5 A7 W - 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
9 T$ x# W# n2 J9 Y. v: j - 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]; ?4 J$ d6 m& w& C) `: y5 L
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]
! ^0 O7 m$ M" D* t2 @) e3 H/ E - 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE] F+ ~5 E) s; b; U7 s; H0 ?
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]
+ i" {' W2 o6 C - ==================================: u- s5 G' V! a% i# |8 R4 y
- API HOOK$ \: R3 c# q4 m- O5 u6 n
- N/A
; g2 E4 ]- s3 o5 E8 t! O. A - ==================================
! N# n- ^7 `8 \1 h4 E* J6 w- j - 隐藏进程- t3 E, |5 p% H6 j, Y$ ^3 o0 A5 G% {4 K
- N/A) \! J( K3 ]2 G. W* c
- ==================================3 T! e7 D B/ _! c# S% z, n
' R& }% g- Z6 X' @: x
复制代码 |
|