|
|
' a$ T. C. B+ G! a+ W4 r# j- 2008-05-22,20:37:43- S) k& ^" i/ m6 K, I4 Q0 p8 l
- System Repair Engineer 2.5.16.900
6 X/ F- S! k! n, n9 H# k; Q8 { - Smallfrogs (http://www.KZTechs.com)
/ o! c1 K2 @1 {7 m* [" c* t( G5 q - Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能' m+ {" J1 s' `( h5 R, b3 M
- 以下内容被选中:
+ x5 n9 h9 Q, g. b+ N - 所有的启动项目(包括注册表、启动文件夹、服务等)/ u$ @7 b& o* M U* u* F
- 浏览器加载项
9 x+ y% l. k7 B9 M, N; M - 正在运行的进程(包括进程模块信息); A9 {# O4 h0 c6 z! B
- 文件关联
1 a3 k6 s# A3 b! B3 i! h - Winsock 提供者5 k2 D$ k+ x+ H# p
- Autorun.inf
# i6 d; A4 z+ o! U - HOSTS 文件% {+ a+ s& L/ Z2 g1 { ^7 j7 R
- 进程特权扫描
o1 Y% x8 b% z7 F# c4 M, n6 B: W! K4 \ - + H4 I3 T2 ~# S- M& k7 D6 o8 V
- 启动项目: X; C- ^$ ]5 Y0 O
- 注册表! x' b* F' E, {# B
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]- Z( L! {# { B* h; j0 S- l
- <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher], Q$ L% u- ~ {1 k3 y+ y
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
6 P: Z' m- A4 t" }# @9 \ B - <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]: l/ H; I- R% v
- <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
/ K- r* h2 s. \1 u' A - <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]0 z- ~8 [& N+ g
- <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]
* S( h3 l' ~/ J/ } - <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]) h! g: a2 E& S9 y( _8 M- T
- <PHIME2002A><; > [N/A]
& k/ x$ l( D' s, h - <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]% B7 A' e; W2 `; Z# w$ V
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]1 t; H* |; x- Q# x
- <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
- {, J! |. X' {1 b, _/ p: `# Z7 D+ G - <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]
& _' {1 F! s. o A" Y0 p6 j - <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]" B2 W& M c& t4 t" y& k" k! n
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]$ o9 U. y$ @1 A3 ~# ?
- <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]
, q- i6 O9 j: F! k. N6 \& m - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
) e3 z' }0 U; B4 D& S t t - <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]6 f+ w0 ]' e8 S' m. Z5 W8 h( D1 W
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}], z& X6 e' x/ A* m6 L; t# v
- <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]" ? O8 o. N3 R& ?4 ?% E
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]9 m. J! }+ @5 ?# M
- <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]$ ?' f5 t* c( U9 w N/ c5 g$ z
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]% p1 ~: ~6 C* i1 r2 X: u! m
- <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]) z0 A% Z" a6 i5 N' Z- s# N- U
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]" ~0 P! K m% v: O; w& c' [
- <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]: S: {# I! s( x: G, k
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]- f) j3 b& s3 r, f j
- <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]/ t, Z9 r0 l6 O: }, e# E {; l+ W
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
. H& T/ D( W4 Y" w - <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
5 A% R3 h% L, q - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
6 y! D0 v0 I% X1 ` - <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
) p" A' B0 X- k - ==================================
% C3 n# F& O% [' P5 V3 a - 启动文件夹$ ^( x$ H& l9 G6 N: b# M/ a6 g2 w
- N/A
! e' X$ C) p) @7 c W& @* w - ==================================7 e" t6 a+ F1 q( O- T7 P
- 服务, y) y7 H) F; j3 T
- [3ware Controller Service / 3wareSrv][Stopped/Auto Start] O& j& {) n* E1 r4 ]0 a' F
- <C:\WINDOWS\System32\3wareSrv.exe><N/A>
9 c2 X1 d: q+ F7 U - [Google Updater Service / gusvc][Stopped/Manual Start]6 @2 o& m5 S! r/ ^$ m# ^
- <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>1 r, r0 Z2 ^/ f6 ]
- [Help and Support / helpsvc][Stopped/Disabled]5 d# Y" B6 ~" @7 y% [
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>
& t5 m' h2 s2 }) E* K0 I; K' W4 `6 Q - [Human Interface Device Access / HidServ][Stopped/Boot Start]
\. v1 C f) n9 { - <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>3 ~: Y# [8 b! V5 {& k7 y
- [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]9 n- b, w) }! G/ ^
- <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>
. G6 |; j2 p- L7 O/ V; X0 j& P6 m - [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
) G1 N2 L6 e, ~' | - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>
8 a- B9 u6 ^" _- h3 d - [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]3 D: I* Z" V! ]" V
- <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>
% S" y3 ^! E* |4 a( d) n% O2 \' ~ - [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]: A) \. h% J6 Z4 C7 J
- <><N/A>
' d8 S" d7 ^2 r; l& q4 l% W - [Qvod Terminal / Qvod Terminal][Running/Auto Start]4 ^6 n5 [9 s! ~- \- N e
- <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>, E4 U( Y) H) D' q" Q: v
- ==================================7 e0 s* }! w8 `/ ?5 ]" D4 K
- 驱动程序% z/ f6 R6 L" _4 u
- [22j / 22jn][Stopped/Boot Start]) O3 H4 L! W; F0 p$ j5 S
- <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>
p, r1 \# C9 c$ ]0 I6 O - [360AntiArp / 360AntiArp][Running/System Start]
7 c% \8 L% D! |9 V6 J. I( W - <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
4 ~; E& r9 ], J, s" J8 G! e) f - [43ec / 43ecu][Stopped/Boot Start]/ _6 e' @* @) Y
- <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>/ ^4 Y+ {0 {8 L9 A
- [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]* |1 S' z- L, Y N% i
- <system32\drivers\ac97intc.sys><Intel Corporation>" i- c4 u* ]4 m6 M
- [Promise driver accelerator / bb-run][Running/Boot Start]
: o" l: D8 p% I& L - <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.>
1 f$ o7 @5 t- C - [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]$ F* `4 h5 G1 m
- <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>7 V6 w4 N% x; X0 U5 g
- [KAVBase / KAVBase][Running/Auto Start]- I4 ^" [( `5 z g8 W7 |6 b2 w
- <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
8 E1 m0 o, T5 L1 j- l' G - [KAVBootC / KAVBootC][Running/Boot Start]! U- {1 `, C# B8 I9 X. _1 L( J8 Y
- <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>0 V6 K# B/ [2 Z; R
- [KAVSafe / KAVSafe][Running/Auto Start]
+ N3 r$ d' j R( }% y - <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>
6 Z6 {2 | A4 T; ^: [0 t" W/ J1 h - [KNetWch / KNetWch][Running/System Start]
( Z+ V9 c8 C2 K; k3 f: M$ [ - <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation> K# P) v: t6 v* Q0 j
- [KWatch3 / KWatch3][Running/Auto Start]
2 r9 |1 `- S: M- d: _ - <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
+ B( r$ f z" R$ g. _ - [ntptdb / ntptdb][Stopped/Auto Start]! A; g9 N) E2 a% |/ B
- <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>) X+ A; B' ~; u
- [nv / nv][Running/Manual Start], M& u8 @% P8 U- b; x7 X
- <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>; O; Z. v2 b5 x; _! x3 U' v Z
- [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]# Z% s ]% i' s
- <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>) j5 U& [5 K. [% R
- [DDK PACKET Protocol / Packet][Running/Manual Start]6 d7 @ o$ t. w6 b2 n9 k, k
- <system32\DRIVERS\ProtoDrv.sys><360安全中心>2 ]5 [+ e! a/ N
- [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]
p: s% f7 H0 ` - <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>
$ u$ n$ Q) h. L I - [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
* d2 ?' Z" o- ^7 F8 ~ - <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>7 P/ i" d! l5 ]3 l( E: w9 o
- [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]
6 t) X& F) V0 s1 ~" o - <\SystemRoot\system32\drivers\RsBoot.sys><N/A>
7 v( t' k* f+ e% j - [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
/ O# D: h* O) {6 W - <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>2 m9 [9 |0 f/ j8 h
- [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]& o3 D5 J P* i! N: o* }( h* X- N
- <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>
2 g- @8 I8 D5 w& M - [Secdrv / Secdrv][Stopped/Manual Start]
0 B6 B: j, b4 k, J0 ~ - <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>/ C, d% m! }$ i& z
- [SATALink External Device Filter / SiRemFil][Running/Boot Start]
# u n3 I' ^/ C5 J- c6 U - <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>
. i0 w) j, o$ y$ P9 r2 Y$ P - [System Restore Filter Driver / sr][Stopped/Disabled]
. t1 ~$ I' g: K% b& H- B - <system32\DRIVERS\sr.sys><N/A>
9 t9 Y, \. ]7 {5 w4 g( \ - [TesSafe / TesSafe][Stopped/Manual Start]8 _+ r$ G! P& d& D5 ]
- <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>& l4 w3 C) z; a9 b1 v" B
- [System Services / unzxzsrs][Stopped/Boot Start]
2 X3 w6 \: j$ Y( O! n3 }8 f/ p - <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>. {9 e! T; h. }, f7 I
- [ViBus / ViBus][Stopped/Boot Start]: o# G( j" k2 V& {( A
- <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>
" p4 g4 z' D. n) r4 G; q$ | - [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
5 w$ L( m0 k% Z( H2 w( Q; X - <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
+ s) V# v6 ~. X3 y5 i, M# v - [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]# g+ n/ a$ p2 q+ c5 |. M/ V
- <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>
& F& a% \1 m" H6 s1 |4 N1 n, |% R - [ATI Extend / zhibmaso][Stopped/Boot Start]
$ f7 M! M6 M1 m# w+ Z0 O1 v) x - <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>
: | Q8 u$ H3 E; L2 P/ K8 j- n - [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]; f- I. H- z, c
- <System32\Drivers\usbVM31b.sys><Vimicro Corporation># q3 ^; t7 f/ l/ D2 U
- ==================================1 g3 l- j$ {( Q7 S
- 浏览器加载项
. k% }# z! D1 f5 S3 }" F - [Google Toolbar Helper]5 b Y; S; @2 x! b" ?0 v
- {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>; j0 M# G0 y: Q
- [Google Toolbar Notifier BHO]" Q7 F7 w* W. x0 d" W5 t1 l* Y s
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>* q3 p4 W, H2 v& N
- [SafeMon Class]4 @2 K W; S3 ~! H8 F9 ~" ^
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
& s6 k3 {9 T4 ^ - [kingsoft browser shield]& I0 l5 V* w4 B
- {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
1 G1 x7 r7 _9 n7 ~ - [IEBuddyExtControl Class]6 N4 q5 }) W* B- @3 c) Z+ g
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>6 m7 _+ H: H9 e! T Q! [4 i
- [Zcom 杂志]
- b1 R* @9 h6 p3 X+ K; l( j4 @! e - {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>7 p$ b% ` K E
- [&Google], ~ p( j7 U3 H; M2 J/ T
- {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.> D0 H0 V) u( [0 b* q/ n( Z
- [KooPlayer Control]% o1 T% H+ G8 P
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>" r L6 v) e4 T' @: |
- [Shockwave Flash Object] B3 }: x/ W% i: ~, ?
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>5 C1 K/ K% G& j( A$ F* i% c4 A
- [KUpdateObj2 Class]3 h* ?' t4 H! l: ]# V
- {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
" E# f* Q. F# ~0 s& q2 ^, d - [Google Script Object]( f( J6 {$ F* R% n& i* K1 T
- {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
! B+ X3 U, Z0 f# w, |0 X" ]* r - [EWA Control]
+ ^' w* Y; ]: Z s, j( z9 s - {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>
! R0 p' U. w2 T - [Windows Media Player]
, S7 I, Q/ l' V6 h. i Q$ h - {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>6 t5 x9 \0 x9 q* b ?1 x. w7 r, q R) j
- [&Google]) y- \2 I, y0 n# u; g! n3 X
- {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
! l4 P" S/ S: j; }; F1 s9 l' d8 b' @ - [HTML Document]1 w) f- u, l+ `( H# @
- {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>: I P# J2 f6 [, `1 G/ B
- [DHTML Edit Control Safe for Scripting for IE5]2 P* ^2 e( t5 ]0 \
- {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
, Q7 [3 n0 w3 O - [RealPlayer RAM Download Handler]; p- d9 t- d5 y( l
- {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
# w, T* c; M* ?/ c - [IEBuddyExtControl Class]: q5 h/ d) ~# O2 L6 c
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
, _5 o: ?% c% r2 R* R- }1 i3 o - [XML Document]
- G1 t1 b$ N4 [ M& m% u$ B. b# K# W6 J - {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
: S" A. J# }: |5 F! O - [HHCtrl Object]/ d& P# V+ \# j- d
- {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation> L- k1 {- h: }: i. j5 I
- [Windows Media Player]
/ p* w8 S" _5 `; x. f1 Z - {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
) I+ h3 P4 q% x+ l' s$ d - [Active Desktop Mover]
7 B! ~0 [ ~+ u# Z2 X) p - {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
; L) g* l8 i: L9 F - [360SafeLive]
. d* v+ Y. p6 i* O - {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>5 E; m) k- {2 z, T1 Q7 ~
- [Microsoft Web 浏览器]
# ^$ a+ x$ R3 g/ H# p - {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
2 |. }0 ?, d0 _/ C7 \1 w- \& i - [Browser Enhanced Objects]
_, P) D7 F' U4 a2 @6 W" [; H* A - {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>
8 X% l; b7 W6 ~4 Z - [Google Toolbar Helper]% \' N4 s$ J7 z& c# k6 S8 q2 T
- {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
" r1 G& p8 G; Y) Z - [Microsoft Scriptlet Component]8 w0 i5 q8 F. }0 j% e0 i4 `5 p- C
- {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
4 e9 o8 J, |; `5 T9 g) m - [Google Toolbar Notifier BHO]/ m: }: q6 W6 @* D& g* \: F
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>; z* a; B& K/ I8 k
- [SearchAssistantOC]
. R+ }% B$ L) @: W7 U" |* D9 w - {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>; w6 V& O6 `+ u, t9 E
- [SafeMon Class]$ T, }. r" {, c% c! t7 L
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
0 q* Z8 o( i8 \' x! u9 p4 d - [RDS.DataSpace]$ {* h2 N8 v7 ^$ a* B4 a% t
- {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
# L' F! Q/ n( ?" E - [KooPlayer Control]
0 I3 A8 o3 q8 @' t* `6 ]( W - {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
0 ]5 @& w; G% q) j8 u3 J - [AUDIO__MID Moniker Class]
3 a. s' Q6 l1 m/ ^/ Q - {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
1 a2 E6 H8 f* Q9 F3 P0 i - [AUDIO__MP3 Moniker Class]
2 ~( [# a5 b' ]- k - {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
3 q2 i. \3 Q1 A, F: e" D9 e - [AUDIO__X_MS_WMA Moniker Class]' t+ Q. j* ?( t! G, K' C, |
- {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>3 i9 p0 C0 |9 e$ }
- [VIDEO__X_MS_WMV Moniker Class]
+ x! k9 H9 l& C. I; } - {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>; q2 s" J- ?7 {5 u) z* w
- [RealPlayer G2 Control]0 x# t* X+ {% B! e1 `4 {
- {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
o4 i0 L6 V8 q. i8 {7 K( h) V6 K - [Shockwave Flash Object]: `+ |+ ~" o& R# B' ^5 r
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
8 N4 y8 ?+ N3 A3 ]3 }2 [) b - [KUpdateObj2 Class]
( g7 w& P0 l$ X, @# N/ m5 h - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>6 [4 K& [1 J/ J) T% M
- [kingsoft browser shield]9 F: h# S' j$ u4 R1 N& R
- {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>$ T: ~- @9 X5 j! ?+ S5 b
- [PasswordEditCtrl Class]' y9 J; N4 N- Z- V; b
- {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>7 V) q' d" v9 g0 [ T! H
- [QvodCtrl Class]% t' A! M1 |, q, z
- {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>
8 n1 V9 Y& H' J/ U, E0 y* y L - [&使用超级旋风下载]$ E0 o& L- r" j0 K+ `
- <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>% A# s0 |$ Q7 k6 |) y$ c
- [&使用超级旋风下载全部链接]2 q& N! a6 U6 }( E, t% E5 V
- <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
" C" x( e, h: f! E3 {2 e/ K8 c - [使用迅雷下载]
5 Z5 p# Z' H" I/ p6 c6 R4 i# O - <, N/A>
1 F# P+ w7 Z4 ?; Z7 Y - [使用迅雷下载全部链接]: t q& b" {8 p) Y
- <, N/A>
9 g5 a. u ~" N W( d# R- N - [导出到 Microsoft Office Excel(&X)]
, e6 G- S3 c' G. P4 B2 o - <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
5 W& s" H, F+ u* `7 e$ m! p - [添加到QQ表情]
. O& ~8 T% S4 Y5 B - <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
. M& E4 }1 L4 |$ a7 n/ |; l+ b - ==================================) }; T. t* J, n2 R3 M! r! l
- 正在运行的进程
$ A6 m8 w6 |! j% V, e) v - [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]& x, b7 e# H6 Y, r
- [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]7 j: c5 R- @: U5 k( q O
- [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
1 P1 o8 r. Z" J' q* O& C5 z9 V; R - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]3 d: u! ~: v0 E; {" |2 t
- [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
( r# n+ Q0 @4 ?$ U& u - [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]6 {% n+ y; o u5 t9 p, a- q
- [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]6 `# X! Y/ E- Z
- [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]' Y2 N2 l6 z4 C2 P6 m2 D
- [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]4 ^. N. V6 J. W: D1 M
- [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- V" Z$ `. J# m2 T/ s5 u$ @ - [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]" n9 k* H' s+ A
- [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]
& ]/ _. [4 i# X; c6 }! m7 q9 i - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]* M( e2 Y# d* M# S3 h2 B( z7 R
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364] Z' G1 C7 W$ V* T1 ?7 r5 W! m0 M$ G$ t
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
( ~5 s' q( _; |1 j! j) i% ` - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
! ~4 n/ A! l5 h( b5 D - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]
' U4 t! F* [ `3 ]2 W6 P - [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]
4 D: v$ {/ ^, K( G3 c - [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0] ?( s% H. j( Z/ i+ @. D8 Q
- [C:\Program Files\WinRAR\rarext.dll] [N/A, ]
% M; z# }! H- ~' Y8 I) {0 g4 }4 u - [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]5 h1 o ]. E3 |
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]/ p6 `1 q5 O* S- a2 y _0 Q+ d
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
/ Z8 g0 ?& @. U, a& U - [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]/ L; B( L. c; m( A9 t K$ [# `9 {, G
- [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]
1 e0 ~; F! O4 ?) k' ^$ x - [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]
0 |( Q" _1 p" u/ d% d: Y) f6 W - [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008]
8 t0 Y) c5 p3 e7 }& N+ G - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]; ^5 ]+ C* |. T
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]( V% m1 {! F) z5 \/ M
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]1 G& z' @/ x; K9 R
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]' X' G$ R5 P" ?8 \6 `
- [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]/ ?7 m% P/ |) A/ u
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
( f$ x* @! U& M1 R; {7 @ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]$ R3 g+ A: L, a" t+ Z
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
2 A, O0 E8 K2 s/ ]6 o - [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]: | [! A& m y& R0 C5 n: @+ G+ C7 v
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164], ]7 N* A1 s3 L
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
4 Q7 l; d- R: b7 h8 g - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]; u# ~2 C% h2 j0 ?
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]
) C5 h( t% d1 L5 P - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
; k5 v8 Q' z2 e# \7 Q% C8 q - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
* ] t; A2 m: p0 K" F- p - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
0 _6 U% l* L d1 f" b" a3 B% M - [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
7 W" m3 p+ K* c2 J5 P' c3 A - [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]4 `& x& J/ Q# [, [) i, u' A
- [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]+ X- D$ N& h- z) N9 T- c3 _5 ^
- [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]/ p, z) F% Y, T m$ q
- [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]# J& u- d6 a, ] k$ I
- [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]' K. s) H3 W0 C3 t {1 y
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
6 A! o3 v# E! e2 u ^- F$ T- B$ a& Q! y - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
% Q+ A9 ]: [+ S) F' M9 t, \4 J - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]/ g, ~0 \/ @; d/ ~7 U9 ^
- [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]1 ^+ Y! G6 `9 U- S: r9 U5 Q
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164], ^9 |4 C5 g7 R; r1 ^7 _4 f8 P
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]) H3 c" u" a* \) d1 |
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]
# o5 S4 p+ i. T2 G - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]' W, f C9 D! _& _( w% [4 L
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]) m# g# Y7 m) v
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78]
$ L1 h+ R( `9 p: N' s. t9 i - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]! V3 ] l3 W I" t' W
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
Q" b$ T/ f2 j$ n4 w% p - [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]( m% B5 N3 i5 {( }
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]' P" w& q3 D8 u7 J' j
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]0 r+ M& T0 J2 \
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]2 h/ A8 }- Z6 _5 C7 d
- [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]
+ `4 M2 s/ T6 I, P - [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]3 P, h5 a8 c9 Y' e/ h
- [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950]
2 M$ y6 q& ?% L& \% {) p - [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]3 L+ l8 S/ f( G# g
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]4 |% _% l* P$ U! ?' i
- [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]
& m2 g3 O( ^ Y' d/ C$ E7 d - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
( S k% I% X& @7 t( b5 N4 Z8 _ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
' [) k, h+ s6 T8 D - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
. d3 a% z- B# E; Q" A/ G2 h: { - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]! T, {1 y* b' e% e6 g: }. C" N
- [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]
3 ~1 a/ k) F+ e W6 o - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
+ E4 b R8 {+ i6 q' n - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5] d2 S2 @; d! S3 x4 o$ a5 B
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]' j4 M5 f. k: E: v& T
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]8 [* ?8 v& v3 d/ t/ o
- [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]
/ z, X+ p4 t N- I' y - [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]
6 s- H. M2 `* M2 O2 [ - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]) j! B$ j) X& ^9 Y
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
6 d; o/ E7 ~7 w! ^; U - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]" z' m9 x. ?. Y6 u" M- n9 i ]2 O+ k
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]* v5 h+ S% J0 }0 }: J: g. n
- [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
9 m, G9 x! z) ? - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
* n+ I" O( S4 S8 g4 N - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
- ^* c4 y5 `0 r* [$ H* I1 A# l0 s - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
* ` X: y4 J- [ - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]+ v' ~" ]- n' z+ Y4 \- v
- [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
$ }. Y) I) g1 G. F - ==================================
6 Q* l; V0 [, _7 {+ h9 p - 文件关联 n2 s1 m& \" A5 Z2 h% j
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
5 O7 O- J& j/ [5 `' | - .EXE OK. ["%1" %*]
' S8 ]1 @; I) E: [, |8 F, F; K' G: g - .COM OK. ["%1" %*]
8 D N1 a' H/ j9 e2 k' p - .PIF OK. ["%1" %*]; T6 ~( H7 f# I. U3 j
- .REG OK. [regedit.exe "%1"]
1 r' Q/ I$ B+ j3 m9 g, p; t- }! p7 L - .BAT OK. ["%1" %*]
0 o! m& h s' Y - .SCR OK. ["%1" /S]
' N( X) Y" j# l# s( i0 X# Z3 S - .CHM OK. ["C:\WINDOWS\hh.exe" %1]% G' i' _1 H1 D; Q% J/ N% y7 ]8 N
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
: {) \- ]3 q( R0 J' L - .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]: J! d8 S/ I9 F7 G; m% h2 `# N+ r! R
- .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]0 c9 `2 z$ [2 ~% Q: f- n' s
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]* |; i- T2 d) ? P
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
1 }$ J9 N5 t! L8 q ~- S8 e+ m: T$ J - .LNK OK. [{00021401-0000-0000-C000-000000000046}]
* _3 L0 g' u3 W2 e4 s - ==================================; }3 z0 d7 Q( e5 b5 [# c
- Winsock 提供者
! j" _; u6 P d5 ~ - N/A8 n! i5 U! r3 S: Q8 a
- ==================================2 l1 r1 d( V U a: L, n6 U- H4 v
- Autorun.inf" ], F- E) V' T9 Z$ g* g9 f
- N/A
/ f4 ^; I5 o0 D4 q/ c& J - ==================================
) q2 Z: _: J% S1 N3 M - HOSTS 文件
4 m. w0 H! ? T1 P - N/A
5 r+ K. [7 g0 r0 F/ | - ==================================4 R: N8 m" ^9 o+ r4 l! s$ A3 c
- 进程特权扫描
: S3 g- a: [! t' s- `' q% T - 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]; D9 B3 d( D/ S! H, l
- 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]
% \% h. E3 A3 ?9 ], A ^ - 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]
# `# t9 m$ Z% p: v v0 g - 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]1 s) Y# d7 z. N9 J$ O
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]6 D) j6 M# t" `/ c+ u4 `9 H. E
- ==================================/ [& M5 ~ X; u
- API HOOK
" B8 p1 o2 K6 F- a$ |8 d8 R6 p - N/A
/ k: H2 b; m! d* r. |+ J" ]6 q - ==================================" }. G" W/ ^; @9 t; t3 j
- 隐藏进程
5 A7 w% r; F" }/ z& Q. P - N/A' o& I! J+ {6 ]6 Q% A
- ==================================
* a1 P& V. D) v1 O9 K3 G) u) C
2 S8 _3 |4 x7 T9 F6 T7 X
复制代码 |
|