|
|
- 6 O: p' M! ~, Z' m- S
- 2008-05-22,20:37:43
9 V! U9 e$ L5 ^, i6 X3 Z1 i - System Repair Engineer 2.5.16.900
! d( x" ~; ]. v8 m1 m7 F6 M8 I - Smallfrogs (http://www.KZTechs.com)) [7 s1 n1 M j0 b* R7 C5 I0 k W* G
- Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能: q' c, Z" ]( }5 c" ]8 s- H
- 以下内容被选中:
4 T, P; q- {9 D. ?/ P. N0 g/ C1 T - 所有的启动项目(包括注册表、启动文件夹、服务等)
) e3 }! F7 c8 Y, A7 c/ x+ K8 f; { - 浏览器加载项8 K* ]: D* g- m" @! Z% E
- 正在运行的进程(包括进程模块信息)
1 k% G- a" L! s5 v: l- a - 文件关联# {1 `6 @7 m8 W" t8 L" ]
- Winsock 提供者" b5 C9 o' [/ b. r0 ^
- Autorun.inf
1 h& N( Q" c8 n" \. [ { - HOSTS 文件
% L4 r+ Q% L' Y/ E `5 Z. M - 进程特权扫描& V! e( _% S* [' D; t' }
- 0 g- O( Q4 B; y0 T' _8 ?& @
- 启动项目
& f$ `, C' n4 I0 R% A/ m" z - 注册表8 Z; R& m. L( e6 i- l
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run], h( s+ }5 y5 X2 z
- <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]# J, _! d3 K1 H6 i
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
/ n5 h" ~( S9 |& C6 h) X0 z - <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]# o6 o& d+ E* P6 V/ Y( s% w
- <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
! @5 w/ ?3 @9 w$ N% r5 W - <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
& I- \, w# X4 A; p: I+ O - <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]7 x( \' r7 X: Q; U
- <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]
) E/ v9 X9 c9 S3 k. Z6 Q; u - <PHIME2002A><; > [N/A]
, h3 e2 `) F$ H1 Z$ Y - <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]
+ ]9 [" K2 t" {: P/ \ - [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
$ {) M7 C" A( c - <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
5 L2 b2 s( j: L; i! q$ p - <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]- o7 `# r- J/ A; o
- <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
0 P) f$ K: W8 K3 I$ @4 G! r1 K5 ^ - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
0 Q8 ^: T# G" }) ] - <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]% [4 P8 H" j# ^9 B
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
8 i; S8 i+ o. L3 X - <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]0 [: p* G5 h% r. }1 j4 m% V0 {8 v
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
6 o3 a% I3 O" N1 u& g' ]8 m7 U - <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
3 X4 z0 Z! N7 m V8 q - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
" Y+ ^1 w7 p' w, p3 |9 O - <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
z/ F- z! a6 E, I - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
. E) [# w V% N1 |1 R4 I1 O6 i% q - <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
7 [* Z* ?8 S8 E) b; j& [ - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
( v" F$ L# A; ]( g7 N8 t& F2 P& r - <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]
( i7 a! Q- F& S - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
# ^. r Q6 C! } - <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
$ l: ^6 {9 m5 h5 ` - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
% `, M+ ~! _1 l; J& G - <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
( [7 \/ v: q! f( H - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
; `" A2 ]& c) `3 X ?8 w# v - <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
$ a6 C) m: Z2 r4 h. v: I+ ?" | - ================================== j; ~- H! Y8 d7 z
- 启动文件夹
7 G4 ?7 E) H3 c4 r/ i/ e - N/A
& y0 C. {! J9 j* J" }' K, A" V - ==================================
! Y$ R0 d8 o* V, V - 服务( t! n c/ [! O/ `0 p
- [3ware Controller Service / 3wareSrv][Stopped/Auto Start]
2 t3 }/ M3 k$ Z3 [ - <C:\WINDOWS\System32\3wareSrv.exe><N/A>' g4 C! x% F! y4 W
- [Google Updater Service / gusvc][Stopped/Manual Start]; n6 U* ~5 y( x( }3 Q. W
- <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
4 O* [2 B' g! r8 C. D1 z - [Help and Support / helpsvc][Stopped/Disabled]
; \. Y, X; r( {* ~ - <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>' n- K7 `3 Z5 e/ s; B2 [; n3 b
- [Human Interface Device Access / HidServ][Stopped/Boot Start]" }, r a: j" d- Z1 O( f
- <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>9 ]% Q4 {# v' W* m
- [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]! x; n5 B$ B; F& w& x
- <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>
) w# }- \3 X! f9 U; Z J8 Y - [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
5 j6 y0 {7 F6 X% I1 E. P4 f2 M - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>
1 P3 F; J1 }6 W - [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
: m. E: p" n: A8 z( t5 J - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>% l" P6 I! R, n% Y+ |( P7 s
- [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]
9 q& x8 |1 R+ [- l - <><N/A>) c7 X# F2 Q0 \# i
- [Qvod Terminal / Qvod Terminal][Running/Auto Start]
2 i+ a/ g. B6 ]8 F! A5 _9 @ _: F - <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>" @! g9 _ }4 g9 V
- ==================================* U7 p0 L" z- `/ D
- 驱动程序
X# q4 O6 A }3 x( { - [22j / 22jn][Stopped/Boot Start]
1 w/ B" c& @) r9 E+ t - <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>9 j/ \+ Q, y+ v
- [360AntiArp / 360AntiArp][Running/System Start]+ q5 D+ ? ?$ W% Z' k1 z1 X
- <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
6 Z$ |' h6 E: f/ @. t - [43ec / 43ecu][Stopped/Boot Start]
7 U9 w* r8 [( }* Q& V2 M% | - <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>
3 C: M1 H& ^# T2 j* Y - [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]: x% A0 ?) R# d: @ ~! K" R
- <system32\drivers\ac97intc.sys><Intel Corporation>3 [- l1 t2 y& `0 f# W
- [Promise driver accelerator / bb-run][Running/Boot Start]% U& ]5 \( j" Z% p) D5 M& l
- <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.>" d% g3 F3 I# N6 Y
- [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]' R/ r" p- r* f5 C7 u: C8 X
- <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>
4 L" J6 K! U x1 ^9 w: B3 t4 C$ M4 o - [KAVBase / KAVBase][Running/Auto Start]
* h) H# J0 c* ~$ n - <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
6 E5 G" _, Q; [- v - [KAVBootC / KAVBootC][Running/Boot Start]
# p2 a& s9 i4 n. }4 r; l7 o7 A1 o - <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>
8 n8 ^5 C+ s4 m' @9 k: P - [KAVSafe / KAVSafe][Running/Auto Start]. h# U* T! L! i# {9 P$ i8 x
- <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>
, W! g8 D8 K1 p. z - [KNetWch / KNetWch][Running/System Start]
8 h/ k3 Z6 z( N - <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
9 H" @! ]; Z2 \# T6 Z9 Y. _" E - [KWatch3 / KWatch3][Running/Auto Start]) n! V+ K- M# Y" ^, @/ X* G3 o3 r. @
- <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
4 h$ f: }+ |# L3 F9 }7 d - [ntptdb / ntptdb][Stopped/Auto Start]- `7 H7 u5 W r" `5 P; y9 B
- <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>
/ y a: `- g0 \8 ^$ Y - [nv / nv][Running/Manual Start]* H5 E X1 C5 p: ~
- <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
$ D6 [! a" z" H6 w- J6 B% U. w7 r - [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]
! ?0 Z# I+ C0 r' U: O! `. b: O - <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>
% X% U& J& ^1 B, N) z - [DDK PACKET Protocol / Packet][Running/Manual Start]* m5 R7 z7 N! ^" Y7 z
- <system32\DRIVERS\ProtoDrv.sys><360安全中心>: `) ?+ B. s( o# \1 L
- [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]0 c% r/ G* |1 D3 ], m- d2 H8 C0 _
- <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>+ @) e5 l9 W# R
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]& m' o* s- [4 Q; h3 w$ t6 u
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
- e7 l7 k) c5 H* u - [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]: c1 x+ p4 M- t+ Q* ]! W5 s" H
- <\SystemRoot\system32\drivers\RsBoot.sys><N/A>% @/ {3 B1 ]' N' u5 k
- [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
( q2 t( s9 O. q% A1 R3 r# D- f; n - <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
5 i8 U. g1 ~" H: |, @" s - [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]4 h, ?& x2 v j o. Y" X
- <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>
5 f' b0 J( r- u& }. ?' w$ ? - [Secdrv / Secdrv][Stopped/Manual Start]
$ w: l- z& e8 F, d7 N$ x" I2 G - <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
; ]0 Z4 Q9 F& ]" z3 [5 l - [SATALink External Device Filter / SiRemFil][Running/Boot Start] a! D- h5 k6 v: Q
- <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>
7 V8 x" K. W& a+ g3 N! b, B5 D# j - [System Restore Filter Driver / sr][Stopped/Disabled]
# ~) ^: p/ O* X0 j - <system32\DRIVERS\sr.sys><N/A># d+ |. `% e- k
- [TesSafe / TesSafe][Stopped/Manual Start]4 M" V" H$ B* E X
- <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>
* P' v |6 S5 h( K3 v) i - [System Services / unzxzsrs][Stopped/Boot Start]4 ?" i" y0 t, {1 u2 z( \
- <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>
& r+ d6 M) W0 W. u9 D7 M$ z - [ViBus / ViBus][Stopped/Boot Start]; \* }0 A. v H# F; K8 q
- <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>
, ?8 [" P7 L' h% [ - [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
( C J& F/ q4 c1 @, o& i - <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>6 a4 w* p$ \" \- q8 p) a+ h
- [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]
- p7 _ s9 ]. t+ V - <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>! \, F* x' L1 p1 ?! W3 J
- [ATI Extend / zhibmaso][Stopped/Boot Start]
& I; [$ q) U7 u* T2 K1 ~ - <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>& Q$ i6 o! ~ G8 C) O
- [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]/ t* Z; z u' m# H
- <System32\Drivers\usbVM31b.sys><Vimicro Corporation>
' M$ `) u; Z/ R3 K( n1 W - ==================================
' {4 k+ B" ~/ F1 i4 W - 浏览器加载项+ g& V' H& X( B4 H: o5 h
- [Google Toolbar Helper]$ U5 i1 v5 P3 L6 g, N; ]! v
- {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
+ W- E @: D9 s- V# I z - [Google Toolbar Notifier BHO]* }$ ^5 W( @; n) F! d$ [) Z
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
: k0 p# l# x( c$ ^5 t - [SafeMon Class]
7 ^3 C6 j; J4 M2 Y2 E; I# w! e - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>& n3 B; D* Y3 y' y! D
- [kingsoft browser shield]
7 S0 u1 }6 ]$ d. I1 N, Q+ k - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
9 e$ w( A7 i1 t, j - [IEBuddyExtControl Class]" O; x/ z" M5 y2 Y% h) N( A# u& |
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
. s7 i! N$ |. w, n - [Zcom 杂志]
( n6 s& p2 `3 M6 a - {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>
0 u5 d3 L( i, D" I - [&Google]
# E3 o% x, h: q; {/ p$ D: E - {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>; B V; \) S7 \3 S' w4 G
- [KooPlayer Control]! ? \& e( Z9 U6 [$ }2 H/ }
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>6 u; T* l' q$ E. f- ^- t
- [Shockwave Flash Object]/ Y5 `# J, L/ t$ b; O& r* _' k
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
/ e0 e. N4 i; e+ |. g/ h' M - [KUpdateObj2 Class]2 ?, e1 f2 d8 m4 I) t) R0 Z' R
- {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>1 G0 e% E% f0 j4 _6 D
- [Google Script Object]
! y( j n: {( q0 y: v4 e8 S- e - {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
# O+ ~' N* D% a& {2 o - [EWA Control]5 M$ H& k' e9 p( \# h* L% X
- {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>
8 w2 E8 _7 [3 b# O - [Windows Media Player]
& S. o3 e# f# T/ I' J# G3 K - {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>
1 M, O9 B; |) A - [&Google]
- F- I7 V& h& f0 W% ~5 w) B# d$ G0 f - {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>8 b. b7 F* d' x7 [" d; C' }
- [HTML Document]9 o5 Y0 i- y4 X* z4 Y
- {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>, l: B; S2 {) X% \# r! C
- [DHTML Edit Control Safe for Scripting for IE5]! _) q0 y, U* l1 c* o# p* G' t
- {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>: M5 W2 l( ^% r
- [RealPlayer RAM Download Handler]0 R. F0 K* U% f% |' I( k+ ?
- {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
% _; z d- C& K" J* m u D - [IEBuddyExtControl Class]4 ^# x0 R: m2 h: E7 ^- ^& k
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>" n5 h" x7 y2 @9 y7 b
- [XML Document]4 D7 ^) E8 g% u+ p5 Q
- {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
2 f$ y. c% {. b) B% o - [HHCtrl Object]" B0 w; B" J( i0 u: S% u5 O9 C1 P
- {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>4 _3 ~' M; E# X) J7 v
- [Windows Media Player]
( y/ t* m4 M8 H# q - {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>' O0 M- U" T7 K" _' S
- [Active Desktop Mover]4 q! I6 z Y3 x8 m+ b8 N' D9 O' ~
- {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
) n+ p( s: Y) k - [360SafeLive]1 A; Y, O$ H6 ?. l3 ]" W, I
- {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>, G3 p9 i8 U- Z! o5 t: d9 p# O
- [Microsoft Web 浏览器]2 [9 M; g, Z4 s' M$ u
- {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
3 L9 b! u3 E4 {1 j) w - [Browser Enhanced Objects]
0 e I6 d& e; }8 r. K - {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A># X! N& P5 M2 A' [- b1 \
- [Google Toolbar Helper]
+ A6 Q. o0 O) n - {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
# i' `1 ]: y! b4 E - [Microsoft Scriptlet Component]* T8 Q$ ]6 V3 e6 e I# C# Y
- {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
2 G5 r+ d4 X+ i2 n6 y - [Google Toolbar Notifier BHO]1 h P, _$ ^: R) e- \2 s
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
. A% E# c& Y3 N y1 O+ Y2 S! H - [SearchAssistantOC]4 N& ?6 s4 z& [4 H/ L1 ?7 F
- {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>2 g6 Y; `! v& r* M& b
- [SafeMon Class]- L' h; i8 ^* W) [
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>& O2 J/ w+ y: G" Y, E% A( A O
- [RDS.DataSpace]
$ _8 i0 `- \8 S' F$ H - {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>+ U7 ^& g4 H2 l! F ~# Z
- [KooPlayer Control]6 U3 D+ @+ ?# C. x/ w: d. v* Y
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>! o: I4 e2 I! Z8 m* [7 R' R
- [AUDIO__MID Moniker Class]. A. h$ t9 v' h$ J
- {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>: Y- q) r# X' }( }3 X" H2 C3 d4 m
- [AUDIO__MP3 Moniker Class]
8 ^5 V. ^$ U8 B2 Q - {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>, V% A" D/ Y; p
- [AUDIO__X_MS_WMA Moniker Class]/ C. O" c/ V! u3 t
- {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>0 j2 C5 L: g; Q2 @' n/ V; Q
- [VIDEO__X_MS_WMV Moniker Class]8 e" U' @" d9 w w
- {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>3 \# Z8 L5 f H2 I$ @5 J4 O4 m
- [RealPlayer G2 Control]
1 N5 E6 I- ~) u3 d" v - {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>+ M. h r$ b ]. D) P4 _$ K
- [Shockwave Flash Object]
* a8 h! B7 w; v: [/ d - {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>4 x4 Q% j2 B) o! Z! `
- [KUpdateObj2 Class]# A8 z, U8 ~# Y% W0 |. Q6 [1 d9 r
- {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
; W; L% w0 x t& s: U - [kingsoft browser shield]
& J& ^, {9 X; i$ ~% u, `; U4 W - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>2 ?5 ~7 ~; ^0 L* {" s( D
- [PasswordEditCtrl Class]
* L' ]/ j7 D+ y; f& j2 A$ P - {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
# O% ^5 Z0 D( v9 b8 r5 u2 E3 j - [QvodCtrl Class]& m+ w8 @, a! m+ L. T5 P/ u$ X- h
- {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>* |% e/ q. }- g Q# R0 s1 Q4 D
- [&使用超级旋风下载]/ n# d/ i0 t3 u% P; n
- <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>; n8 i- F5 n7 {1 [% p$ |
- [&使用超级旋风下载全部链接]
8 Q. p0 r4 R6 n& g$ ~ - <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
8 x: J8 E: [; C T1 T4 L- _ - [使用迅雷下载]+ @0 f* _: `% C7 W5 W1 D
- <, N/A>
& P& L5 Q }% b4 Z! }5 H W - [使用迅雷下载全部链接]8 u" t1 _! T9 z0 O& h8 D* m7 X
- <, N/A>/ O4 W/ R4 P' M& k6 r- Y4 {
- [导出到 Microsoft Office Excel(&X)]3 Y9 }. D8 `! J6 O8 r3 _# `
- <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>6 _/ S2 }0 N1 }4 r* [& G
- [添加到QQ表情]
" O( M( \6 f; ?2 c6 T& [ - <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>- f5 m# K; w* _& J2 P
- ==================================' q+ B1 x/ {3 m D
- 正在运行的进程( V# a- j$ D) i
- [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
+ ?- g# X3 G4 w5 y - [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- E& C E" ^3 C" S( ^) H g - [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]; p3 @. K& {+ W
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
& I S& e C6 b' P6 Y x - [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]( g% w# {7 h' {: V
- [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]( F; Q w5 e& o! R* m+ E" L
- [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
' E$ Z" L" F6 w5 F - [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]' k; K. N5 o- E& E" u' F3 A* S! v
- [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
" f s2 {- q# @# h9 t6 r - [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]- X0 o! q; o/ r. i2 U" W/ h, h
- [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]4 g/ p; X) q4 i7 v4 S! `4 Z
- [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]) V* \: m7 T' B: D; j# E4 i
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
5 q; i$ S6 F! [1 v - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]8 s- B& H/ @3 @! o1 q% m8 c3 l0 z _) C
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
5 w7 b% b/ R1 F2 B. p, Y* d6 j - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
. o# L& M6 G c7 W - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]* M5 B2 { b3 s8 N) B
- [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]
+ ~5 i" I2 D' i - [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]% B% c1 P7 h+ r4 @
- [C:\Program Files\WinRAR\rarext.dll] [N/A, ]. l: L2 e5 b+ d" U1 y
- [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
, Y4 S3 q7 g8 {7 D& B2 A - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
; k' A1 U( D, T) k2 B - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
( Z5 `1 s/ X) c6 J - [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
$ F+ |( F0 T" ^* A8 w5 P5 I - [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]
* l/ g% I: ^/ s- m' R - [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]% s5 Y" ~3 c) D1 m
- [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008]
6 z# \' T6 {; q y1 B \6 j - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]/ d" s1 B) }3 b2 v1 i
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]8 Z% R9 H! M4 d! {3 S; f
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]- O+ j, S. G* e6 ?7 m3 y6 C
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]. \0 T! V7 S7 u, V) x- C# ]$ q
- [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]) |7 q3 G" x* C6 @
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
4 a* T4 s0 r8 g0 n9 V0 R: G9 Q/ Y - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]) Y' G4 g f7 I# V' p/ B# W9 e
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
4 a6 v' ?3 F# f5 E# n- O - [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]: U4 P$ {1 L0 ] j5 i9 W" x
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]
0 w* H* `2 J* V$ @7 s' s - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
, [$ N+ I n2 {# y9 s2 s - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364] p) \5 g" _1 z
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]
$ |6 W2 c! W9 [ - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]+ R, [& F: E+ _
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
: l9 Q) Q- a9 f7 I5 K - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
5 N$ f; Y. D) W+ |4 G/ H$ r - [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
/ ~* g: m, H8 J6 R' N$ { - [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]0 \* d& ^4 A, C# H; f
- [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]% Z$ P# o6 y0 m* f+ H+ n9 \7 [
- [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
1 F7 C1 w9 n& V+ l9 B1 s5 [ - [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
0 @- m U, J- r7 m9 e - [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
, Q1 y; h# p% s9 t% }* j& |2 O - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
7 S! k/ i4 [. T - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]$ \ T$ l7 D* `# [9 o( E; m2 k
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]+ ]( s2 t2 ~5 C* D5 [, _
- [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]* ]) H: D; A9 F" d0 J
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]$ n2 Z$ S. A- O. z' t
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]8 X2 }$ x7 }, v" o; _
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]" g% S. P( B" i' X9 u- D4 D! A
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]
) e7 @ @6 m4 l% Y! S3 E0 w# L: T - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]( B, F- I- R" _* I) N
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78] f) e6 q, M! U$ C! o( _, a0 @
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]9 h1 g% L7 X" H6 l. ] V
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
) A3 O& L, }- _' j3 U; v - [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]& F) m# o) i& C' g
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
4 e" @; J6 u: T; N' N1 g. y - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]: V0 V9 I7 @7 A8 d" e+ i8 H$ j4 f7 D( p
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
1 |" }# c. g+ i0 Z - [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]
' ^# |7 b. V, Z- v - [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]+ W, }7 K! l8 g. E8 } t/ M
- [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950]# t( f- J8 {! \3 `
- [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]5 e1 D( u4 X% K# r3 K+ I
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0], V% Y9 _# y0 {( w
- [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]
$ W4 r+ ]4 ^/ g- [; h& ^ - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]1 @2 Y/ a* {9 e7 u
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]" @5 @( z0 W" z' S2 P* o( d
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
0 T" H! b' g$ l) {# j - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
4 T8 {/ u, {5 ]& J1 m0 Z - [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]- X6 w* q( M7 U. o. M
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
) t1 O( g8 l9 X$ M' I3 L - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
% F4 k) x5 t$ e4 {; q. a. |* }, A - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
. I# u& _2 T3 E" |# {& B - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]1 u# t1 ~/ h# O. }. }8 `" l/ @
- [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]
. ^) ` M/ p: X2 A3 {' C$ y* `& j - [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]
" x4 I; }" N& X8 Q - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]' w: \, o4 y! |; K0 ?3 N
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]' C7 ?% N4 E: }2 `$ C4 [* W
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
' Q0 e$ X; C! t- w% S3 w - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
. Q$ a! L- h+ }: a# U8 z - [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]) f9 y: H( B b+ u7 ]
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]' b7 W S* W# l7 q" C$ f
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
! {, w# G3 c$ {( G a - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364], s4 O s' x' A+ p9 k
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]0 d7 x5 {3 r& v& k2 G
- [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
' V) ?0 F9 y5 K/ P; ~! n - ==================================, G G4 e% b( T$ i; k
- 文件关联% k' R/ C( v8 f9 W1 e
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]/ i! j5 D6 ~* n9 b |' H) ]
- .EXE OK. ["%1" %*]) L9 l A* B4 M1 A. u7 W+ f
- .COM OK. ["%1" %*]
9 b" b u3 |+ E% w8 @ - .PIF OK. ["%1" %*]
: c" d; Q5 v( T4 {5 \ I0 l- e - .REG OK. [regedit.exe "%1"]
6 W! X9 M3 a, f- h( Z E. h' | - .BAT OK. ["%1" %*]# {- _, y9 J5 Q$ l/ ?
- .SCR OK. ["%1" /S]
& ?& m, Y3 d5 E4 z: R4 f+ L# x0 H - .CHM OK. ["C:\WINDOWS\hh.exe" %1]
/ i1 l3 ]3 z$ B - .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
, U+ c8 M U8 {" U. _/ Y q - .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
/ j$ d" O# N) f: M( H - .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]3 G( f" v8 v$ T9 x/ [
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
+ G4 s1 e( U' U# o3 N# } - .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
: \0 F2 E i5 E$ P - .LNK OK. [{00021401-0000-0000-C000-000000000046}]
+ `6 A, c* Y0 T W - ==================================
8 \: x8 q2 U: W8 `$ E5 \ - Winsock 提供者& j1 Z3 _. v/ D. |' s7 e4 J1 R" L
- N/A! h7 X7 x2 w0 J2 x% h* j1 _2 m; L' P
- ==================================7 a& ^3 F. c/ k& `, a8 ]
- Autorun.inf- B# T( y% m0 g* C& z( C
- N/A/ R, S* Y) ]1 L
- ==================================
6 M- m$ L, d3 t4 i; ^1 v7 J) o - HOSTS 文件; E0 t, U6 b5 X$ B: l. o
- N/A
( }$ b$ ~& ^& T2 ? ]. P - ==================================0 M7 l; w6 z! ?5 B
- 进程特权扫描
* F, Z% T. r( K6 {1 h7 j - 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
7 Q) R9 Q/ y$ q% N% D - 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]) I* Q2 |! q6 Z a$ M( r
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]
, n8 g H7 K, v$ d - 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]8 W) f6 f' G" [1 x% z3 x' Z
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]
3 e# r/ x- {4 F& B - ==================================
4 H/ |! a! A, P& y$ ?% ]' H ~ - API HOOK' [+ k7 s% E7 F% g" x
- N/A
) r- C9 {# T0 I - ==================================
" d) l/ v8 q5 K - 隐藏进程
. P! t/ a2 B/ r( t" G - N/A# W+ p7 ^! f9 k8 u: b. y' D
- ==================================1 P3 Z- Z" m8 q3 n) f2 Z" x0 @
9 u; o7 T$ f, ?2 s
复制代码 |
|