|
|
- ' X! f; r, \7 |" C
- 2008-05-22,20:37:43
) A6 y! W+ v6 d& w" \ - System Repair Engineer 2.5.16.900
8 m, m! l; ^# Y0 L5 y - Smallfrogs (http://www.KZTechs.com)3 s" o |4 O* K- \
- Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
- b7 j( G; e4 }+ y - 以下内容被选中:6 w" n# {6 U5 @5 o0 \3 X3 F
- 所有的启动项目(包括注册表、启动文件夹、服务等)
! A# \5 M$ s- b* R/ _4 @ - 浏览器加载项$ P7 ]+ |7 i, e5 n: S8 y, u# @ G
- 正在运行的进程(包括进程模块信息)
' h; _( [, r+ E4 B. b6 m - 文件关联
) z; B4 k X& a3 H3 j$ |# P8 v) K, t! ? - Winsock 提供者: q% B* |! }9 Y1 o
- Autorun.inf
" j8 s- u, v, b' T6 B - HOSTS 文件# k8 P( |& O; Q) b: }* M
- 进程特权扫描
% x4 v M& `" x0 h! N9 Z* y( v
6 B( e- A4 r2 l4 d# R- 启动项目& q6 M v. W5 q
- 注册表
, i3 L; _' d, X1 J* {) T& D - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]( c) _9 q) h; B {* W
- <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]
3 k) V6 _. a) D$ q/ S - [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
3 K. H- Z/ ?4 X; [) K W- c - <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]# p& p0 i* y0 A; {" w& i
- <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]' t! K' Y. I0 y o+ x1 N/ q
- <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
7 V1 F+ {$ y8 _5 w$ C - <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]
; `) p9 d; w4 ]6 i, {5 k( ?# a - <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]3 Z! m% L |; E1 c
- <PHIME2002A><; > [N/A]" n9 @- _* W9 j. s+ V
- <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]( g3 M; h4 N, @
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
6 w9 u" e1 F/ C5 Y - <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
; A. t6 q9 |6 o- j5 R - <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]
+ E- p' a) l% ^ - <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]' n$ R& h, u' ]3 B+ A9 M' k; A
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
. y4 x, ^) D" j; b' W N( K, N - <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]
# z& E( e5 G/ m+ e3 D9 Z6 O5 P0 c - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
2 R- R% D" {0 ? ]- {9 o' C/ h - <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]9 u$ c& K# l+ Z$ ^
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]7 l1 Q6 A6 k. M
- <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
$ V( I9 l; r9 b - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
9 E1 d2 ?0 Q% P. c3 q4 C - <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A], m$ }# N6 d7 U6 N6 [4 j. P! n, b% U
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
+ M2 d' V- V, D4 ^+ n$ M [9 L - <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
4 r5 |' B$ g0 t - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]) R- s1 O& q1 r
- <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]& F2 n. s6 Y1 v8 l
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]& y) G7 B! R# ` M, o0 a
- <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]! q( q# G( H8 ?* I& y. [. |
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]: O. |, R- j4 I m$ s
- <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
. Q( f2 P9 e: c; v8 x* | - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]" R0 e7 ~" C% |! _% \9 k5 O5 d& A4 y. j
- <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
* v1 q# A) O2 ^ - ==================================4 a" }) i9 {9 \* R
- 启动文件夹
1 o: q+ p- o6 V; A8 p - N/A: ?/ o1 }0 M2 d* C" c
- ==================================
9 G4 k# Y6 x+ i - 服务3 n. Q( w+ f5 y' }, E" i# I
- [3ware Controller Service / 3wareSrv][Stopped/Auto Start]( z& K2 j# l: U4 r" {7 J4 u0 `' W& `
- <C:\WINDOWS\System32\3wareSrv.exe><N/A>: @3 E3 Z2 q4 `4 E$ j
- [Google Updater Service / gusvc][Stopped/Manual Start]( ~3 q/ W& t# Z+ ~0 f
- <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>, p8 W& N& J `9 J1 b6 `
- [Help and Support / helpsvc][Stopped/Disabled]2 q8 y+ H; R0 U/ Z0 B+ ]% L# M
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>
' Z( P m n) ?: B5 U& R) c, f - [Human Interface Device Access / HidServ][Stopped/Boot Start]- u6 Q5 z, D8 O& D
- <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
* g) D/ o! ?4 c0 s4 y - [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]
5 ]2 s- F2 B8 I$ f' F- m3 j - <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>; e/ T9 \2 e T- T$ g t+ a6 q6 n
- [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]3 c5 }6 d& C- k
- <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>
" } X8 L4 r; g" C2 d, m - [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
, S4 s: S5 N T- v - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>
; T( s2 c+ `, l. }, T7 c+ Z - [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]+ ]& k3 y1 T9 s/ A" K, W0 o
- <><N/A>* a8 F: B6 u9 K2 T) j% Q
- [Qvod Terminal / Qvod Terminal][Running/Auto Start]. {. [5 C) r3 \2 C( F
- <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>! U8 b/ p% `9 }+ z( B3 z
- ==================================) W! q8 n1 i6 }& K- l& j" C4 K( ?
- 驱动程序7 \# X8 c9 @; i5 l% Q" [0 h- x
- [22j / 22jn][Stopped/Boot Start]4 L* d3 o# M; @) X& g
- <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>0 ^) Q; H) A6 [2 y: H7 k$ p
- [360AntiArp / 360AntiArp][Running/System Start]2 a5 ^8 T; p; B% B# ]3 D2 X3 n2 J' W
- <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
! u# F. \6 l7 v! e - [43ec / 43ecu][Stopped/Boot Start]$ x* @/ r' ]& Z- m
- <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>
6 ^0 q8 K9 t# Y d+ d - [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
1 { J R) L7 l: C4 F! f - <system32\drivers\ac97intc.sys><Intel Corporation>
& j/ |) R# K; M, y! G - [Promise driver accelerator / bb-run][Running/Boot Start]
$ u: a/ g+ |) O- y - <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.>
: u9 ]( i; z+ y) Q - [Promise Removable Disk Control Driver / dontgo][Running/Boot Start], ^# j/ S+ V; l; p. {- p$ G6 v9 f
- <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>3 c% E6 h, m) v0 ~$ S% G% d
- [KAVBase / KAVBase][Running/Auto Start]
6 s P R4 c- {1 i* F - <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>$ w8 t- @6 u9 `8 o) ^
- [KAVBootC / KAVBootC][Running/Boot Start]8 v+ {( p8 T. @/ M# x) D6 p* K
- <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>; T9 _0 y$ B" T9 }
- [KAVSafe / KAVSafe][Running/Auto Start]
* C! M# d& o* t5 u - <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>
5 D5 `( q7 o$ {4 L; ]' c6 y - [KNetWch / KNetWch][Running/System Start] I! [; P, @3 H/ j" H- W6 U) k
- <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
- ]! Y# h3 x3 s, s- B+ c) }" ^( N6 J - [KWatch3 / KWatch3][Running/Auto Start]7 Y: \4 e9 a4 s: z
- <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
: v* b3 n3 X+ r8 B - [ntptdb / ntptdb][Stopped/Auto Start]+ \) M3 L6 Q" N; x0 r% ]. N
- <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>* K: [2 t7 |; I7 {
- [nv / nv][Running/Manual Start]9 U B( a/ V5 u; r q4 O
- <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>1 p2 P. f3 L/ j4 A: u7 }: J
- [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]
* R' O# R+ ]& @1 x - <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>- Z/ ^; K' z+ ]$ q
- [DDK PACKET Protocol / Packet][Running/Manual Start]
5 Q$ i( n3 R) q5 T! V g - <system32\DRIVERS\ProtoDrv.sys><360安全中心>
- k6 W" f1 |" ?) T - [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]0 _3 [% M& [- `7 z* z7 a
- <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>, L# D2 T8 j: f4 f2 j8 Y
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]" r% P" w) j# W7 E: ?4 _6 b7 ]" g
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>+ i7 J5 l. u; J ]2 A: F0 d
- [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]
4 M8 i& j* C3 G0 x, g8 j' v% f - <\SystemRoot\system32\drivers\RsBoot.sys><N/A>( S5 L8 l2 F3 y3 Y& |7 {
- [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
& Q u4 g3 o6 {/ o2 @% _+ [2 N( j - <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>% W j9 v) L& N0 @6 [5 y `0 n( o" \
- [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]7 w: Z6 G, z" q4 U$ U& h: J/ o
- <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>
( N6 {) Q% t3 L) _: k2 L6 m) ` - [Secdrv / Secdrv][Stopped/Manual Start]
2 r7 q6 d3 q0 [" k1 J - <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>: t2 ^0 }6 j8 _! ?, E/ ]; H, I
- [SATALink External Device Filter / SiRemFil][Running/Boot Start]
# U2 [ R( X; w: }8 v - <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>) @/ F2 k* C3 s' F- y, X5 r
- [System Restore Filter Driver / sr][Stopped/Disabled]2 M6 }7 f* l2 R7 W/ e- ]3 H
- <system32\DRIVERS\sr.sys><N/A>/ _% y6 l: ~, c7 P( l+ G( w
- [TesSafe / TesSafe][Stopped/Manual Start]6 r& ]& o( G3 J# N* _, [/ U6 U
- <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>; k! E2 {6 B# C3 f3 R& W
- [System Services / unzxzsrs][Stopped/Boot Start]
3 a# n/ m$ ^5 b& F0 q: K0 D4 r5 T - <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>
' u* `' F8 f8 p3 ?3 P, B; Q - [ViBus / ViBus][Stopped/Boot Start]
: L9 X0 K, z5 Q. k, ~: f - <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>7 l0 K: Q+ |; [; [- {0 N
- [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
8 N- ?( ?0 `8 O5 w$ n! k - <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>% w9 o! Z( C' h! V" W
- [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]
5 w2 }3 p. g z+ p. [ - <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>3 V! i, t9 F% X/ o( D5 g
- [ATI Extend / zhibmaso][Stopped/Boot Start]
; C4 k( U# k: H4 o0 T- m - <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>
4 S! `1 g5 k* z$ G - [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]
5 w: s! g$ g+ K- x - <System32\Drivers\usbVM31b.sys><Vimicro Corporation>
& a7 G% S. }$ l% P2 J& G& Y( s - ==================================
, j3 L+ m# j8 T( K - 浏览器加载项8 O9 O: u g. v( N- C. k
- [Google Toolbar Helper]+ T* D, o# h8 v
- {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>8 A/ T3 }2 o o+ z5 h6 h
- [Google Toolbar Notifier BHO]: }, _1 O4 D) S; L1 [ H; G
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
1 \# b B# L- N. Y1 d - [SafeMon Class]
/ h5 ?. U" h" ^' U/ j - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>* [* w% ]* u5 Q4 W, m
- [kingsoft browser shield]* K/ z6 D) G$ i k3 B2 y
- {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>8 o! ?& o6 z7 M6 Z7 P' ?) E
- [IEBuddyExtControl Class]
2 F) P2 ^5 L1 C6 X0 l, Y2 K* ]0 I2 l - {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>1 U4 Z( M+ a3 B" E w/ i
- [Zcom 杂志]; N( l# ~' p" A8 u2 a+ n
- {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>
; y# _4 P- F7 P. @, Z - [&Google]
1 t$ Q" l7 x o: A* g - {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
4 V9 I* B3 o/ w% x3 E2 ? - [KooPlayer Control]
$ f- A) `; z& P3 @" h* F; q( ^ - {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
0 N5 q# D! k0 f8 i - [Shockwave Flash Object]
, G7 E; h( U3 _6 k7 D: f - {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
9 M: s; _+ ]$ c% X - [KUpdateObj2 Class]
9 O: i& h! ~9 L, r3 U - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>" Y4 H/ x* Z% p
- [Google Script Object]
1 q U* A8 k1 u( ?2 y$ ?* w' o0 F - {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
/ b0 p7 U" ]( \$ F# p( L9 S - [EWA Control]
, u' h9 k6 I4 c% ] - {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>+ E/ }; M4 @( n
- [Windows Media Player]$ |/ L2 o( x g* B% i2 d* ]+ q
- {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>" u x8 ?4 e: s& w1 P
- [&Google]! Q! F4 u9 }- _0 h# t
- {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>4 S! i( A+ M/ N- J+ p0 D
- [HTML Document]
# S0 B8 h8 m# M1 V6 Z J1 D6 g - {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
! q1 _; ^3 D+ T, J! y# x - [DHTML Edit Control Safe for Scripting for IE5]
N$ m2 S* y8 Z* P - {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation># s9 M0 v/ y' J9 W K
- [RealPlayer RAM Download Handler], Y. H# e4 H8 s
- {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>) P/ Y/ y9 a( N# @
- [IEBuddyExtControl Class]- D2 i& g' u0 Y; D, s# V* V0 ^% h
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
$ O6 v) ]% K/ n' r8 O; | - [XML Document]7 w8 X1 N6 a$ R$ a5 i ^
- {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation> [$ Z5 s7 u1 l1 x! q( \8 r
- [HHCtrl Object]
5 {: M7 U0 f' {. f - {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
; M2 o5 t: m# l - [Windows Media Player]. C% v4 A" ^6 @' B3 _! F& d
- {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
! s. E/ U5 Q$ n4 k! q) Y- r - [Active Desktop Mover]
% s- s0 Y1 u. R - {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
: b/ n% R8 m. E$ U' } - [360SafeLive]0 B* w* \4 `* ^
- {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>' ~1 g. D4 k% i: F* w9 N) k8 R
- [Microsoft Web 浏览器]' I0 ~" r# B1 B3 H# |- G0 l
- {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
$ j6 n; E0 u3 F% k2 J- `; K6 C - [Browser Enhanced Objects], R0 k1 e0 ~5 o( c
- {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>
# J/ r$ I( ^# `, O% ~- N: a) p - [Google Toolbar Helper]
$ K" ^ q# Q' o5 `9 z, n - {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
( F) X+ O8 G( |: V! M; y - [Microsoft Scriptlet Component]
# E( r- x9 ^) e# C8 \9 [ - {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>+ r. U* o: Y1 }6 y! I7 {
- [Google Toolbar Notifier BHO]; b, B K3 o5 x. p5 G' v
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>8 u7 l1 m" j: K" o7 x
- [SearchAssistantOC] d* s6 H# K+ s, G% D
- {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
& T L! u- ~: ^ P. k - [SafeMon Class]
6 m8 G* J+ ^, _! H6 I - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
) Z/ j0 A+ A9 M" S- E2 |" G - [RDS.DataSpace]
/ @2 w7 @% T: A - {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>! q& Y9 ?1 K$ |2 S$ u% q
- [KooPlayer Control]. G2 }) r& [1 L1 E0 K$ \9 R
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
0 q6 B2 w K" M" n9 z2 | - [AUDIO__MID Moniker Class]
# I* n1 ^: Z, u0 A - {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
8 Z4 }% R: r/ @" m - [AUDIO__MP3 Moniker Class]
" y6 N% o& o/ Y0 s: Y( W1 Y - {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
0 A! Z+ x8 O, t3 ~* I( [- b7 U - [AUDIO__X_MS_WMA Moniker Class]$ E5 A' | d6 @( }, y
- {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>7 [' B# q V2 k
- [VIDEO__X_MS_WMV Moniker Class]
' A, B; d4 [" X& B' c. r - {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
{4 N3 m& J7 F8 T3 r - [RealPlayer G2 Control]
4 v3 [" J) z- Y E0 F1 C& G. Z - {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>: Y& J7 d! W1 n: S
- [Shockwave Flash Object]& |* Y' P5 a% q- L) P: P
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
% E, G; C6 E* z% R7 S+ B - [KUpdateObj2 Class]
( Y+ h2 K7 e7 k% ? - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>: w# `" D5 S2 ~5 \
- [kingsoft browser shield]) J0 \; z3 t5 f) T% |
- {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
( A$ ~6 [8 J3 S( I5 O5 u9 t2 u - [PasswordEditCtrl Class]
5 i7 w: E9 q" o3 D! G - {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司># o+ j L; D R! K3 z
- [QvodCtrl Class]5 A4 \ _- r- r3 Z( J
- {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>
+ H t* }: r. j# ~0 I - [&使用超级旋风下载]' ^. `' w) ]$ D
- <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>* o1 {: D* U# Q7 \! a" t
- [&使用超级旋风下载全部链接]
& a: O. N$ g; a/ W1 \+ @5 U c/ @) R - <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>8 V! V. g0 ]) B3 E2 p( }
- [使用迅雷下载]
# L" n1 F. F* Z" Z/ O- T; B - <, N/A># p' |+ u; T# {* n( s1 B
- [使用迅雷下载全部链接]
" N) u) j7 \# Q; { - <, N/A>
1 W8 y3 }. s. x - [导出到 Microsoft Office Excel(&X)]
- e6 l- A7 m% f5 f- \ - <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>: ], x7 }- U6 y0 s4 d+ P
- [添加到QQ表情]$ d: V' o2 }1 R/ @7 P/ R6 }
- <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
! A" d( J6 p0 e. u' O - ==================================0 c+ Q$ e0 p4 |: _
- 正在运行的进程% D5 x: |( h7 y+ i% l. p
- [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
! X# X# v2 Q U5 f0 K2 O - [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]& n1 Z$ |- p5 Z0 d9 j
- [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]% k8 Z( U0 v& s' f/ z, F. V
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
# m& S4 q+ M$ c6 d0 a - [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- Z. O$ O4 w' Z. ?* r( l5 @ - [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]+ l! X' b, x! W: t+ _9 s
- [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]3 @% d/ }8 W/ _6 `5 }/ c
- [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
% }9 x# c6 |0 c! z4 s5 F. H - [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
& o$ c0 W$ q5 X, I - [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
) r1 B' ~9 t T C5 o - [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
2 q3 M- Y. `4 j+ f6 F - [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]4 y E- X# ^; V
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]6 y* W1 o" r" @
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
" u2 U. P6 x; x$ p R - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
; i# T- w8 V; Q& |, T" ?" a - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]+ s) r; D8 X8 P2 U- ^
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]! m5 M# Z6 d7 d9 e0 ]
- [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]
, x5 J: W5 `! t# j7 H d( X - [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]" R* L% M, U: f* H
- [C:\Program Files\WinRAR\rarext.dll] [N/A, ]2 M& T: e$ h( i- J7 R. i0 a- _" y' t
- [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
7 p& e' h7 H" C4 ~: b0 _ - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
+ _6 j: a ?9 ?; r3 W: d - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]1 p0 o, k, X/ D+ {. f/ K( J" `
- [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
9 N Y. a9 i+ e- F/ R' F4 ^ - [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]
0 _2 j9 g; f; j, p0 j% h& I - [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]" B4 O- y: a7 q$ r! O6 j) W& O
- [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008]1 D; I+ }* z# [# \/ G1 x
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
2 J' P: b! E( i) | - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
: t( m+ g8 J# y3 G$ L - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
Y0 u6 l# g/ t: g - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
/ s% F3 S, v2 `1 p! i- F% e - [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
' F+ P s |9 z6 G5 S - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
+ ^* I# y2 x! s. o5 ~6 n9 b7 l - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]. f/ T- m+ t- i U$ T9 l0 ]+ H
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
: F/ i: O+ i7 o [) l6 U& @: O - [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]# g1 P$ K) p' o$ |9 w$ Z
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]) @+ A, n7 L( [0 \
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
1 j4 \* ?; L+ h* W( V# R" J/ V - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]( L( t; q. x |0 o+ U( }# N
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]& e! y+ {3 }/ D6 e
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
$ Y& X, |9 v4 Q6 @# Z( ], I - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
/ Y9 C; v; b% G/ W9 w - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0] J; m" @; M0 H3 v9 ]3 R
- [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
4 ?) m. P8 F, ~1 Y% H - [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]1 V# P, b; X- `2 H' l
- [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]5 J$ z% h f3 e4 o6 [: v) v
- [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]4 L, I, y- r6 W+ b& v
- [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]- v, U9 n5 V5 W
- [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]: h* ^& m, t3 V- ~2 M4 x, z
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]; t5 g9 H2 X4 F; C, p) j6 m7 z& i# p* D
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
% D2 M7 t0 I: q" q% a/ H - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]6 e$ L8 ~. u x' [( z" b' L
- [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]* x6 z/ e: W& P1 i! c/ y
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
" c" r4 C# J2 n) S& I - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]
9 u8 b- }& N+ w7 v8 s* k - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]
: q; ]# B. y x8 j% O: F& O - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]
5 J1 q# R/ c t- x' H - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]$ x4 w- e# \6 n( F$ G% M' Z* ` Y
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78]- G1 `7 W6 w( j
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
9 ] e5 H: Q' K& N+ ~5 }( v - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
" U% E/ o: b' s* @) ]6 X2 I! v0 v) W% _ - [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]1 r2 ~ ]2 n0 g8 |7 H
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]& x- G) u- `$ q1 J+ q1 P
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
* x# e$ r* e# V7 A5 L) C! Q9 j - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]6 F, z! T* P4 j% n. _6 I
- [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]: q9 Z7 o0 v3 M
- [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]/ D9 x9 v5 a; Y# ~- x3 D
- [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950]
( M- a+ o# H/ Q- d8 T - [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]) C0 d1 w$ P; M; x5 V, [ q
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
" y# M0 ^, G1 d1 P3 j4 D - [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]/ L5 {! U) @' z
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]) o) U& o: B; [8 O5 j9 X
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
* J8 Y, w1 \3 n c- P, [; r' t! G - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
, X t2 X$ ?! Y7 z% E - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
7 w! t9 P, B! r. d6 }/ Y - [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]
) {" y5 O$ J2 O0 ]2 e* I1 F - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
% G# k, A, D' V! l3 L# G - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]: Q( o3 G6 }) J
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]. i7 Y7 w4 @/ k) N( f
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]4 C. E) q- k+ F1 y# q) Y8 E
- [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]
! Q- J d& V, A: ~: D& S+ i# u- B - [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]2 f7 Q! x# M( U* B' ]) Z
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
4 O* u1 x5 B3 `: J# x2 s - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]% x8 F' ^) s l: z" F* l' N
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
+ ^( b% r! l2 I8 X$ N4 r - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
( J- R$ c/ D' A" V# G- k! } - [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
0 @$ c! u/ y9 N0 H3 f9 u - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]7 V5 I# p1 p) S# k; u
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]$ s4 i' V6 r8 }
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]& H, ?# w, @8 V& O/ r* h1 }+ i
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]2 R) f5 E- b F, K u, ?
- [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
) G9 G. W, ]; a/ p2 Q, k - ==================================
- R! D/ r- C7 y5 B - 文件关联
/ q; |+ q! s1 h - .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
3 d" q9 J7 r+ q - .EXE OK. ["%1" %*]8 q% V9 x) Z- R
- .COM OK. ["%1" %*]$ l& I- s- C8 Z* ^2 M
- .PIF OK. ["%1" %*]# s, ^6 I" b4 O
- .REG OK. [regedit.exe "%1"]
9 o, V F- c: ~5 E - .BAT OK. ["%1" %*]
! v' u0 e* h' O- Z5 {1 a - .SCR OK. ["%1" /S]7 e3 }( A( g, N: c, P! b! f
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]
; B1 Y/ D5 |0 O& s! k - .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
5 ]3 D+ |' s0 o$ B4 l0 s" } - .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
6 l- z6 O. |" p8 J% E; \. S - .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
6 S s' O2 x5 ~, k$ y - .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
8 n+ h0 T9 y; U b1 D+ E$ t5 \ - .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
$ w1 u1 b% l1 z& M8 b - .LNK OK. [{00021401-0000-0000-C000-000000000046}]
6 [$ k% Y6 D& b7 o - ==================================
. ^" z7 i. v# O- N/ R - Winsock 提供者. ^/ V! Y, v# l% _$ w
- N/A$ K5 B3 C5 m1 i% d) I0 y4 M
- ==================================
3 ^, R7 s) J6 u2 w- e/ j) p, t2 y - Autorun.inf
, w$ U7 p8 a: \6 _0 S; X - N/A( M8 O. ^5 l: D3 t
- ==================================
- u" y" ]1 N2 q+ b4 i - HOSTS 文件# B5 ^( X# h- [0 y
- N/A
: \; I t# U2 u2 \$ \/ F; C8 L P - ==================================5 X1 U% S- }. u3 m
- 进程特权扫描
: N' H' ^' e# c - 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]: K. U' r; E& l
- 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]
) j- j) H( Q0 A! c' v+ y - 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]
, m1 m* V# @8 s+ W! E4 E; p - 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]
, p) Y2 M2 h. e$ o - 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]) c# [% G* @- N
- ================================== U- @' L/ T1 C8 f- _+ L$ p, g' F9 D
- API HOOK
& O) w- s* y$ }3 X9 ~ - N/A
% D% C$ L1 W9 Z! l% w - ==================================( r5 q7 f( d- W
- 隐藏进程
2 E: l: U) j. t; S9 e( p3 f; `+ t - N/A( p% S. c( V- @% S; k
- ==================================7 R9 `9 u6 Y* o# T" k$ a
0 t8 S) ^, z% F
复制代码 |
|