|
|
1 U! \ W. U+ [. Y- 2008-05-22,20:37:43
2 f( L6 y( e8 O. z" x - System Repair Engineer 2.5.16.900- `) w- I$ v# m7 n v
- Smallfrogs (http://www.KZTechs.com)
* |% J8 k4 u' B. S, L: Z; f - Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能- m+ F: h4 X3 }- c$ z+ y- R' U
- 以下内容被选中:4 G- e4 F& W0 b- D
- 所有的启动项目(包括注册表、启动文件夹、服务等)
0 q0 t R' S0 m2 {0 N( G3 o - 浏览器加载项, L# `! A7 r+ Y/ P7 J8 d2 D# n
- 正在运行的进程(包括进程模块信息)
" p. L$ D- w9 J0 o* K9 @; I - 文件关联
# f" v" |; V7 Z! _9 R6 y; Y6 B - Winsock 提供者
# W2 U3 _" V, k2 J( q3 ?$ l4 x - Autorun.inf* Y q4 B1 v+ |8 b0 r) ?
- HOSTS 文件( D4 |) b0 M# b$ {2 H
- 进程特权扫描
6 T7 w K# A7 C7 i2 Y. |4 k. d) B8 f - % }8 U3 K3 V3 T, ^% N) d1 b
- 启动项目9 t1 A' q" t7 ?" K& X+ A7 J
- 注册表
# T" t) t9 B! f% v - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]1 M+ [! n1 E, L9 M# b X
- <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]) z% B1 P1 B. t D! ^) m
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run], H, P, @! b8 @8 K' C
- <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]
8 a9 M% b2 X% ~$ e/ a - <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd] z7 i% M5 b1 e
- <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]3 H6 V3 G) o. I- V7 a
- <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]
5 A x1 Q( g- c6 p - <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]% S. ?4 k/ [4 Z$ H) O* J
- <PHIME2002A><; > [N/A]
, s# V2 ]$ ~( @ l' A0 |1 A8 i; _ - <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]4 c7 y% T0 \* d6 w( c
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
. I) S ^/ l+ q/ f% G - <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]0 {' i/ X+ I+ j4 L4 E
- <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]
K# [0 `4 K; k* y) l0 {& z - <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
6 L+ R1 r4 a; R - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
: Q4 ~( U' G0 W - <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]
1 F& R7 B* F- \ I9 J! W0 Y* b - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]3 d b4 X5 ]/ e- X( r
- <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]) ~4 O8 t3 u: m
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] X9 J! a7 ]4 q( U; {( }& w
- <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
0 t* Q' v2 M ~, y7 R. \ - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
3 }5 s7 U+ F9 P1 H# | - <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]. @5 d4 L, D5 U0 j
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}], ^0 K, ^4 R8 G! Q. f! b
- <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]( M$ X5 H" B7 w6 J. T, `6 `
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]0 h+ t4 F9 o6 y: d6 c3 t( R6 J
- <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]8 o- X4 h! I4 e0 H( R5 L
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] f0 R8 R$ ]& Y1 ?: ]! o
- <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
* y8 g: Y& `# d/ t - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
5 ?' ~5 j- D J9 }1 ]( s" A - <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]: A% C* [6 Q! e& V+ R& X4 v
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
' D6 W' k% ~0 h, \9 f - <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
7 }. u/ o0 P" |& p( y; @) @ - ==================================
4 _* g2 d# R+ V- ?! @6 n5 G% R - 启动文件夹
: C' [: c% Y) J$ T/ H8 s - N/A" ]2 Q g( _* t. c# d4 F
- ==================================4 x8 G! P6 x, Y/ b1 P
- 服务+ R- _0 { j& F0 W0 J' a
- [3ware Controller Service / 3wareSrv][Stopped/Auto Start]6 c a) q$ o* B) k# ~
- <C:\WINDOWS\System32\3wareSrv.exe><N/A>
. P- \, c7 N1 F& l5 Q; V. ^: r2 _& ^ - [Google Updater Service / gusvc][Stopped/Manual Start]
: t7 \, @8 i/ E - <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
* E$ X4 s# q$ d3 O - [Help and Support / helpsvc][Stopped/Disabled]
) f$ N- R; V0 Z - <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>
3 g( f: P- m8 C. n$ h' F - [Human Interface Device Access / HidServ][Stopped/Boot Start]+ f6 g: X) n0 m6 X0 ]
- <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>) x1 `# P/ f3 q4 E
- [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]
- S/ s- l9 I+ ~2 H, u; ^* Q - <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>6 w1 s7 Z! X9 r4 j2 B2 B
- [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
0 M( x* A0 z: g: e# o) f - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>2 @, L2 Y4 L9 b7 m5 t
- [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
. U2 r: s) g* w4 W" G - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>9 N7 \. L7 z% I j* G5 g3 o; S. m& s
- [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]; |" Z: B n) i3 b+ z. y$ ]/ e
- <><N/A>
6 U, t7 j2 i1 {$ i2 j; `9 \ M( L- W+ M - [Qvod Terminal / Qvod Terminal][Running/Auto Start]
0 j( d9 q4 w7 t [3 m1 W: n - <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>
, m D0 @# S$ |5 ]4 i! A. |- b, `$ a - ==================================
6 a( W) c8 U1 \. ?7 q5 A - 驱动程序
8 Y5 Y5 l- l: o" ?( L - [22j / 22jn][Stopped/Boot Start]/ u5 q. {- `! \* O& y3 R/ U
- <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>
/ \+ B- d c7 ] - [360AntiArp / 360AntiArp][Running/System Start]5 T1 r+ K3 O# R! }
- <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>/ A9 l: N) D" ]$ L8 i0 e! K
- [43ec / 43ecu][Stopped/Boot Start]% I% U+ k' x( [0 X! U; r
- <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>
" J' `4 h4 y! u( l. L: Y+ Y+ c - [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]1 S" D: W8 M3 \! @5 C" R
- <system32\drivers\ac97intc.sys><Intel Corporation>+ N' c. @- C: W( U: C1 [/ w
- [Promise driver accelerator / bb-run][Running/Boot Start]! w3 L9 L0 l0 ~3 H- h% ~
- <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.> v# \5 y8 y5 X) S% y" _5 T
- [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]3 s' I* a7 [& I
- <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>
. C! x: ?, k% M7 q5 i1 w% u3 s - [KAVBase / KAVBase][Running/Auto Start]
# {; ~, R0 h z1 Z+ g - <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
6 Q$ l' V7 L7 Z0 j: y9 n - [KAVBootC / KAVBootC][Running/Boot Start]* q& j: F# ^+ m' C/ l; Z3 U) E
- <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>2 V5 I7 y$ O: ?' f
- [KAVSafe / KAVSafe][Running/Auto Start]3 U& k& J+ L3 n: U
- <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>: G1 e) F. z) J$ O2 b# R; C
- [KNetWch / KNetWch][Running/System Start]
* [; o3 _( N v) t2 @1 C: ~ - <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
8 ~9 f# i$ V# ^* l$ o - [KWatch3 / KWatch3][Running/Auto Start]
. L% H' D+ S5 \' i2 H: H8 D - <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
4 {, k3 w) p9 m% B Y - [ntptdb / ntptdb][Stopped/Auto Start]) B' |# Y: C9 s9 m! Y
- <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>, Z; _! j% `$ |% h
- [nv / nv][Running/Manual Start]
4 k/ n- U3 n) W! S7 m" O - <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>$ I* a- h1 p$ ?
- [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]
8 b, D1 W# i8 R+ ]: j6 |* C3 V7 e% A: ? - <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>
5 B9 K: ^/ F4 [3 w# i - [DDK PACKET Protocol / Packet][Running/Manual Start]
. T5 Q$ {$ \% \8 q - <system32\DRIVERS\ProtoDrv.sys><360安全中心>
; U9 X! o9 s! u8 [8 f- N$ I( M3 A - [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]2 R& L% C B! y/ C) a# Y0 u
- <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>
* D$ q; r' z6 f2 j9 q) Q. F" { - [Direct Parallel Link Driver / Ptilink][Running/Manual Start]! S0 t0 @1 h! d6 J4 k. C- f
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>3 L, {" }% b' t5 ^9 n2 z
- [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]
( i7 ~- m( j. v: q" }! Q - <\SystemRoot\system32\drivers\RsBoot.sys><N/A>
* V9 ^8 r7 L4 M/ y - [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]1 g) y" ~/ l2 e4 Y
- <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
, S2 N \% \3 _: l$ \2 \- u9 W - [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]
) s. Y0 |1 m$ E - <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>9 R1 W$ m+ j; G- n, {9 S
- [Secdrv / Secdrv][Stopped/Manual Start]6 i p+ [2 v$ Y; b
- <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>8 c8 g0 S* V6 ^& V8 W/ d+ A
- [SATALink External Device Filter / SiRemFil][Running/Boot Start]8 O( o/ b% Z, R. |' ~4 n; ^5 Z0 X
- <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>
9 v' D5 D: p; {4 w/ S8 G - [System Restore Filter Driver / sr][Stopped/Disabled]" y8 }. _, @3 I+ i+ e! s& r/ n1 G
- <system32\DRIVERS\sr.sys><N/A>; y" ?5 {8 B9 X4 C1 ^
- [TesSafe / TesSafe][Stopped/Manual Start]) W, p( K- N7 a! p& S- z7 \; H
- <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>% ]- [5 M1 h0 n
- [System Services / unzxzsrs][Stopped/Boot Start]
4 X5 Z/ P- A+ ?" D9 R - <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>3 M" x1 ~* i! B4 K2 A: E2 G) _1 d+ o
- [ViBus / ViBus][Stopped/Boot Start]
4 L! X* ^8 U. K - <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>
- Y) }2 \8 T* X, J - [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
( z/ }) A8 x6 g/ e - <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
% X# O5 B6 x d; j - [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]& l2 b2 O! Y- P0 |
- <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>0 Q$ c0 ^2 G& n" \# ]/ k
- [ATI Extend / zhibmaso][Stopped/Boot Start]
& S: z/ `9 K$ Y2 c: ` - <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>
; O _- d/ f; H, F" z' E: S. E8 j - [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]
7 I' O# ^. \! R M" @+ e e9 J - <System32\Drivers\usbVM31b.sys><Vimicro Corporation>- @! F+ @' V) U( P; \
- ==================================* }8 D9 C7 U' a" I9 t* E% _
- 浏览器加载项
" y2 \/ W/ x4 b - [Google Toolbar Helper]
& g8 t" F X# {0 f - {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>1 o$ a* p g( T0 T$ z) s! \1 u3 ?6 J
- [Google Toolbar Notifier BHO]
& T1 X* @, A; L5 Z, I - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>6 E0 E: G$ _4 b
- [SafeMon Class]
, W1 z# q5 {. ]+ t* P - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
/ z# R. x. `& J/ L9 B; r, u- p - [kingsoft browser shield]
0 \4 U) u6 H1 A3 k; B - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>$ b' J" l+ b9 s6 n( a" F
- [IEBuddyExtControl Class]2 S* w5 n, X6 v% {
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
- j$ C8 N0 @6 w6 ^* } - [Zcom 杂志]
) z6 i0 S+ U2 M3 U9 k - {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>
: x# m$ b2 ~ Q - [&Google]( A! v0 e) d) e- x _
- {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>$ I4 `( S& Z$ \; g# q
- [KooPlayer Control]
2 U5 @) H) ^6 z4 s, R K - {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>2 ]8 g! U- A* [. w/ T# T) ^" h. R
- [Shockwave Flash Object]& `) T4 H4 l, h5 |
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
8 O; l& l5 D8 f- ]4 O8 [ - [KUpdateObj2 Class]' v1 O7 f1 ?) l% l
- {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>- t4 L8 ~+ q/ Z3 l- t6 E6 Q) i
- [Google Script Object]
6 I9 P9 n. W0 k5 ^9 { - {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
% N! ]9 A( Q' F% H$ t( K9 V - [EWA Control]
5 D2 H3 o5 J. |: e! _ - {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>
$ G: o2 E2 l% s# t. B# s - [Windows Media Player]) j Y* i. j& G9 u M3 s2 B" V1 ?
- {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>5 S, h" i8 u1 T2 n
- [&Google]
( \, X% N" D2 X3 H - {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
; C/ F2 ]' [6 i2 V1 _ W9 G9 v - [HTML Document]0 D5 x) I) X3 t
- {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>/ N( f2 \7 V* f1 w0 W
- [DHTML Edit Control Safe for Scripting for IE5]
) w5 l5 e/ q$ W - {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
( C' R' O& I) j# ` - [RealPlayer RAM Download Handler]' j1 T! J6 Y9 u* J; C
- {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>1 l# L; _- G9 v7 b5 X
- [IEBuddyExtControl Class]
P4 K: ]8 C8 Y) R - {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation># ]7 l! G3 K) Y$ J
- [XML Document]3 o6 \1 E/ `* b8 {6 g- U1 x) O
- {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>. }& J' g e* F' K J. {% l
- [HHCtrl Object]
. h4 v( R) b3 j# w# t a - {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>; s' F( ~4 C3 C
- [Windows Media Player]
7 E4 Y) b3 e" H+ b/ `/ o - {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
$ X, c# F" N0 D3 i- O9 }) e/ _ - [Active Desktop Mover]
# j" _( R! R. }0 Y6 T* O - {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>1 X$ E/ ~' u9 h3 M4 U
- [360SafeLive]' |! X* e1 Z: v. T' e
- {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>; E: N& I/ O; b' H/ w0 i
- [Microsoft Web 浏览器]
6 G+ i* F. } k1 E5 [ - {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
, m7 q( r S" X* k - [Browser Enhanced Objects]9 e# G# R% g3 S4 v. ?% s
- {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A> S. B ]4 e# t
- [Google Toolbar Helper]: Z7 c- `5 F1 D
- {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
& |# c! |6 f; } - [Microsoft Scriptlet Component]
8 h% h8 e$ o! k - {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>+ T) [6 ^# h2 _6 s3 Q, `$ h, l
- [Google Toolbar Notifier BHO]: p+ T- s3 K. z9 K8 ~1 Q, R3 V
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>+ {5 Q& N; o4 g( O" c) D4 ]
- [SearchAssistantOC]
' F3 z7 d, E; K) s# F- C - {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
8 E+ [; M! o; ^/ K$ o5 d - [SafeMon Class]
4 r6 V# j9 J, j$ b3 g- U - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
; v" R8 c/ O7 O. R% [2 X% D# v7 l$ j - [RDS.DataSpace] o( q3 h& x+ @; f# B. b* M
- {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>, d: I1 U9 U' F9 x" d
- [KooPlayer Control]
: M, P7 n9 h! i2 G0 C - {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos> a. o# m- ~% e' d' m
- [AUDIO__MID Moniker Class]
7 v0 R& f5 X- ^ - {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
- R+ @. a' \( w; {3 ] - [AUDIO__MP3 Moniker Class]- U$ R. \5 W- D
- {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
: b+ G- f& Z3 q* F* V - [AUDIO__X_MS_WMA Moniker Class]
1 d7 ?4 s) m3 x% A3 c - {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>( u) P) G Z0 c+ {0 z2 h. G5 [
- [VIDEO__X_MS_WMV Moniker Class]3 \- z1 H# \* e9 i# M; S' ~
- {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>7 }1 Z! Y6 A5 r' W l
- [RealPlayer G2 Control]3 t9 @0 S$ v6 q8 V& Q- g
- {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
: F3 n4 Z6 j) [& }' I - [Shockwave Flash Object]
7 p1 A5 c1 O# w( q, M" N. m. u u - {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>) b& d9 u9 C$ v: W: Q* p$ z$ r
- [KUpdateObj2 Class]
- W% S# s/ v7 Q. [+ d1 M% Z3 b - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
8 m% o& g0 }! J0 \& B- g2 u - [kingsoft browser shield]7 P5 Q& p; }. h7 a1 e; \9 R1 H
- {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>, }/ f0 h! P3 B$ n5 o. V+ x1 j
- [PasswordEditCtrl Class]* a6 b# m9 d3 {
- {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>5 V& `; u" D1 ]
- [QvodCtrl Class]
* X. @: w3 j+ z& j9 m; l - {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>" N. D3 t- |! d6 `7 O" b1 P" i
- [&使用超级旋风下载]
0 `7 Z3 t/ ]( K5 I! z7 Z5 R - <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
7 w5 D6 p4 r% k5 F1 P4 J - [&使用超级旋风下载全部链接]
( C0 C" D' V& y% }* [; V2 ^3 \ - <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A> f/ l* g! P& v( c
- [使用迅雷下载]
3 u( u" J7 A- ^+ R5 h' I - <, N/A>$ j0 g! o9 v# _
- [使用迅雷下载全部链接]
# A" P3 Q! M& C/ ^, k, P( s$ D - <, N/A>, b0 G7 O! H5 G9 b7 |( }
- [导出到 Microsoft Office Excel(&X)]( s# W3 O; h& e5 C# e& N
- <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>6 u! o+ `- q0 d% N; O; r
- [添加到QQ表情]
& O# V# Q& z; D* D8 t1 t - <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
8 A. O: h( ?# G& S2 G3 I - ==================================6 M3 v+ h# a- l( U" n& T' @) C
- 正在运行的进程
6 g# w3 q3 h. {+ ^ - [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]: |9 }$ ~& O( a' Z5 X, T# p
- [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
1 ^8 P1 Y- x7 F4 p4 i' o- Q1 ` - [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
. h( p2 Y0 C" w - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
# }/ _5 ?* T/ v; w - [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
' e2 z7 p3 d6 h7 C( c! ]4 Z- s - [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
6 L( {: I! l) O: S. q+ {; I* o - [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]! V' g! H, c& W; g$ z7 D. R; y! r7 _
- [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
) P& w* m0 ^: J; M* ]/ z - [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]( Q( A9 L- O& X6 e
- [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
! A9 q" O) a# M8 d - [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
& |: D7 C N2 U - [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]
( |1 t. H( m7 ^4 g8 e2 s0 A/ L - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]+ L* N; O* ^$ A- M% I/ h
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364], ]4 W# D" S' G8 L0 r7 c$ S
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
7 q: r) }; P/ g, f3 o - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]# z, t$ }/ e$ W5 T; ?5 ?
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]4 D5 ?) s. m2 T5 [
- [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]
3 ]( C) b/ u7 | - [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]6 Z0 t, T3 l9 b5 H( g
- [C:\Program Files\WinRAR\rarext.dll] [N/A, ]; E6 E) e: V) t& ~ d5 M
- [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
: e5 B9 w' w1 I* d* r+ z! z - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
& ~# Q& `0 f* D - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]+ u& C* k/ x' [( }" Z
- [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]2 S" Y* |8 ]2 G/ h: H# I
- [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]3 F& Q) b0 e7 d. F. a
- [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]2 f3 d/ m( k2 |9 Q, N2 H0 W2 }+ M
- [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008]4 e. P# S! V7 u- i3 P
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
' V% i1 n# ?3 I, b* U; ` - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
8 Q1 A3 O$ y8 r/ n4 | - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]/ \/ n9 X4 g& {" e0 w3 n
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]5 d% _6 T7 c+ t2 ^) {) m
- [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
6 v0 T, V# E4 r+ X! H5 U4 H- o - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]9 _0 y: a r/ M5 r: q& [) I
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]9 s1 T: K* D. G! K9 W$ Q9 } F1 H
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]) B; {& Q/ R3 ?
- [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]
+ \ w" Y$ y1 v: M! G' o - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]7 m$ N( X6 o) n) C* Z' u
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
) z" N2 Q' }5 T* _$ ]: X1 j5 _, k - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
+ c# l" F6 |' O; M, M, T2 f - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]7 L; x% ^# B) _( g
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164] N. A# R3 M$ H
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]- ^5 Y- i# E: u K+ t0 Q
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
; f9 f% x, n, \) f/ B - [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
5 @( \: t5 c1 J+ f/ n) U* `' D+ | - [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]1 a3 n4 f( I8 l' Z9 K9 e5 B# n
- [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
/ `+ C# o3 U( M" g- d* }$ r. ] - [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]/ a" Y8 K/ Y9 R/ t
- [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
- w/ v+ ~: J/ Q+ F* o) V! X& D - [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
; D: ?5 ~: a( e8 W1 j( d) n - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
& S1 G! P B/ r4 _" c: z( V5 D - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]4 Y4 H0 w$ I2 s, H9 R( d7 x
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
* H. |! c) k# z' _$ a+ d - [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]
& V; C1 u) V: W- ~ - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
1 i0 N, X `: q! C# D1 O - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]
# f; R2 o* t6 q# n2 s+ q - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]/ N, V0 {' U5 ? T
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]
" | g: l; F# n! U" O) j - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2] E+ w/ x2 ~9 i6 Z$ Z
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78]6 P* E2 f# l, S: r( n% F
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]6 i* m0 L' g/ z% C
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]& K- o, A4 ^' }; ^$ V K) k
- [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]- Q% y9 r1 O' F4 \) |( Z8 V
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
9 t5 i1 h1 F% Z% Z d4 O - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
/ K! t0 J- L4 C - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]- \% B& x2 h$ }) B7 d3 o
- [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0] [; r: _* p$ `
- [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0] Z3 i' w- Q. n+ _
- [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950]/ x4 a7 h/ R5 n5 \/ A: |4 A3 l
- [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]
5 u" v' M( @/ R - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
" k% m+ K5 ~. q9 w, b - [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]. j5 n7 C" P2 A( w9 ?2 Y+ j' b
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
: U* @, F7 h/ A J - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
1 j" I7 g* @! @ M- Z [ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
1 S2 K, E9 M- y4 ]# R1 j6 {2 C - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
: r( q1 i% e, W s* M - [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]
0 Z8 s. v! l" B5 H7 C' d% \ - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
5 g0 Q5 R( K( ?) P, u - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
; Q; i/ M2 ]8 c A, O/ @8 Q: S5 S) l - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364], U0 X: O4 h5 F8 N! l, o
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
+ P; [ f O; _- O6 o - [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]" S# {( Q ?# |% Q& M$ S
- [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]/ S0 o3 ^9 s7 j2 x* M& w! v* }
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]5 k! I3 F4 r* ?% X
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
$ ^3 J4 p& Q6 T! s7 |$ j0 i - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
* I- V, g% f! d# d( Z6 _- C d - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]4 q' o' `/ b+ n W$ i% Z1 W T
- [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]9 y; E' k7 m- |6 A2 d0 ~
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]% V0 U& n0 P. T3 g
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]3 `$ G9 l3 `* {: S! L4 V C* i. E
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
/ i+ m* w- U: i8 j2 f( f1 W. | - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
; ^( a/ G8 ?4 f - [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]8 R2 ?5 w4 ~: F6 e$ w
- ==================================0 V( u9 Y3 |$ z: [7 k
- 文件关联0 i; T$ P# w. Q i. J5 O
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
% A5 |( |9 Y: e - .EXE OK. ["%1" %*]5 J3 K4 V5 @' r/ }# O
- .COM OK. ["%1" %*]
$ K; k. _. F+ c8 K4 {) j9 j - .PIF OK. ["%1" %*]6 u* v. u$ D4 m. T8 S8 S
- .REG OK. [regedit.exe "%1"]6 w" ?5 ]6 ~$ a s, m
- .BAT OK. ["%1" %*]: C0 E0 }* G& M7 |4 E0 S
- .SCR OK. ["%1" /S]
8 {% N9 { r" @: q - .CHM OK. ["C:\WINDOWS\hh.exe" %1] L. D) y2 v. `0 s
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]2 J8 N* m4 P& ]" \" `% r
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]" l8 r6 v9 s3 @
- .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
6 H0 e/ ~; |- X. a0 c* J$ ^8 ]. m - .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- b3 z9 `: z* o) x" K! i7 j - .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]: L$ v' E& Q5 x! l
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]% B& V% o% ~' s% h2 |/ `; b+ X/ w
- ==================================0 s5 g; b% n, j7 R+ o
- Winsock 提供者
. {* b1 k' l1 d! p0 g! D0 o - N/A
8 } S8 [* E3 e* b' u+ y - ==================================+ @$ s: r8 I% I% h- q$ m
- Autorun.inf7 Z Y8 w: }& @; ^8 h3 [$ Q
- N/A
, R! l0 x7 _& N5 p - ==================================
7 l9 a1 d3 |8 r( o8 n - HOSTS 文件
' R' u0 W! j$ O - N/A
4 X) ?* a! Y5 y; g: H { ` - ==================================# _8 U \$ ~2 T- o: ]& M5 j& I
- 进程特权扫描
( m% o4 N/ k- d - 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
" Q1 l, x' d5 u" B* T, G/ I - 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]
$ _; w( H2 n* E1 ?; h - 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]$ H- G( u$ G. ^- v
- 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]8 b8 P' K$ A5 M3 ~" O* d# k9 F
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]7 K/ F/ p" G' q& F
- ==================================2 Y) `1 g. p8 W0 z- @5 `
- API HOOK
* }- r9 A; l" [ - N/A
; O7 M0 n! @- Q7 t - ==================================
& t/ l8 J/ c$ j' y) V1 R! o! ^" v - 隐藏进程! a9 f0 p5 X+ l3 Q* J' |2 l
- N/A: ^* P, @ N# }$ d+ Y
- ==================================
`/ w( C5 g% R: w - 2 v; ~, _9 a: z3 m3 k; g
复制代码 |
|