|
|
7 m g% S, ^9 x3 x! C, S, K0 E- 2008-05-22,20:37:435 D# W/ K7 [ i4 m- ~
- System Repair Engineer 2.5.16.900
7 ^' L: n6 i" L Y& ` - Smallfrogs (http://www.KZTechs.com)+ K5 c& L& f) P* j, C) G
- Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能+ b8 y+ \0 |5 M7 C* U* Y
- 以下内容被选中:
& ~8 m; L5 ]# M9 Y - 所有的启动项目(包括注册表、启动文件夹、服务等)
( a2 o& }8 x. L - 浏览器加载项
6 J' S5 d& n: V; V( _ - 正在运行的进程(包括进程模块信息)
- N$ Q# ?, x$ Y' I - 文件关联
, p4 K4 Q2 P! G8 t0 ?+ o9 H, M1 X - Winsock 提供者
6 M; N& `1 e9 B: b" g: D - Autorun.inf
" ]9 ?$ q$ _8 s f/ P+ `, b$ R - HOSTS 文件8 T7 J3 u* C( Y0 X
- 进程特权扫描
; ]( D$ {3 h$ U- M - 1 S+ @. C1 e* T- p8 @: N
- 启动项目$ d& X- [" q: F: s, z- O" ~% \; t
- 注册表/ @ ], J" ]# _
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]: X- Z6 M* U3 g9 ^+ c
- <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]1 R1 ~3 p: |- p1 _" l
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]1 _1 B' \1 {7 F2 \& a& g F
- <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]; }- I& @2 a+ U
- <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
; X; C" P; ~7 H4 H( E% j+ o% d - <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]4 b K. @. u) O
- <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]6 O, o3 X7 W# @) S$ K: _/ Y
- <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]
! {0 p/ c1 N# ` - <PHIME2002A><; > [N/A]3 o* i, e1 ]( S
- <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A], G% q+ k1 k1 c5 k
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]; {* w$ a+ q H" y" E1 P
- <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]% [* L( T' H3 X* [% }
- <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]/ e6 z M3 ]$ U
- <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]6 T) ~! O$ U: }( H) q2 |; } Y
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
+ N6 O) Z7 q# `' g - <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]
! m! W1 |; U4 t. P5 W: g' @" r+ j - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
p* `$ |$ a8 g! h% H& V - <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]) c, d( [# |* b1 a/ l
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]9 x K1 E% p. |' W
- <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]: ]0 z! y. V( [ x* \4 R9 n
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
: J5 R1 [5 G7 t& h5 y2 q# h8 q: T - <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
4 [5 [4 M. W& B/ \ - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]3 X4 o1 H8 R) S
- <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
7 x$ l2 c7 w8 m t/ I - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
) x. t1 c/ i8 U9 a. F/ P - <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]
+ K" c- h5 X7 J0 k - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
' u7 ]8 @0 t. S: I/ c* O+ c# F - <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
, U" p/ t& {; T! [6 Y - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] A9 y' V% A) F- {, J! T. [' r9 j" C
- <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]/ [% P4 y0 E [, T5 Z9 ?6 W1 o
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]# W i" i }+ u1 m" {( q6 b6 p( N
- <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
) g4 z1 \$ {+ r: u6 y - ==================================$ F2 F, G% c# x2 g8 F) z
- 启动文件夹 Q1 M# g$ a' h$ g
- N/A
$ [) X$ r7 f' k - ==================================
4 K3 A& N) G+ V( b9 i - 服务
7 L ^3 }. N K% N1 ~ - [3ware Controller Service / 3wareSrv][Stopped/Auto Start]# W/ a! m. p, c; W0 I; k: B
- <C:\WINDOWS\System32\3wareSrv.exe><N/A>& D( c" R2 u2 E1 b0 S1 d- A7 {6 ]" \6 A
- [Google Updater Service / gusvc][Stopped/Manual Start]
9 e% N+ j* Y" w% M - <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
$ a8 f {1 L: U5 k1 e - [Help and Support / helpsvc][Stopped/Disabled]
! Z0 S. h* e1 D - <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>! S) ^2 W p K3 J
- [Human Interface Device Access / HidServ][Stopped/Boot Start]3 i# x4 s% v {! S6 F9 @
- <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
- X5 I4 t2 v# s+ t8 [ - [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]! {* {" P! I4 Y' ]- o$ y, u
- <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>
* a3 U& b5 s& I% J" t+ y+ {9 i1 O ` - [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
0 {6 O" [, M. z - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>
" h* T* K6 K* Y - [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
: n: G. K. D( @( N3 K" F( q5 l - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>: J, L9 _) b# g
- [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]
$ L2 E7 x) I1 \3 s& {$ b4 c5 E7 D - <><N/A>
\* x) X! X% l - [Qvod Terminal / Qvod Terminal][Running/Auto Start]
4 E+ e1 s W0 j) L - <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>
8 {& i5 x& P1 ~5 v8 p8 i9 l' w - ==================================
. a$ x1 t s, K: B% l$ f, u- N: b - 驱动程序
9 l0 M9 |2 t9 b8 T - [22j / 22jn][Stopped/Boot Start]
! Z" d: ^# V0 u3 }; P6 M2 L - <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>
% T% F* R5 |0 J' P( }) [. v) z2 k - [360AntiArp / 360AntiArp][Running/System Start]4 O) Z% n7 X1 i
- <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>) j% G& I* |6 ?/ J, d
- [43ec / 43ecu][Stopped/Boot Start]
2 u, W# @0 @7 E) S. Z - <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>- ~8 K# ~2 k; L- s* n0 p6 t* x3 @
- [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
' o3 i" h v7 U) I5 N- { - <system32\drivers\ac97intc.sys><Intel Corporation>. \" \. o3 T" |3 G! e
- [Promise driver accelerator / bb-run][Running/Boot Start]" l+ s) j- _! Y7 P
- <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.>4 q' o; D2 r7 n. z: Y; A
- [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]
( V4 q7 d' Y( T3 b( j - <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>
& P# m9 X' q% m! i: |! Z* Q8 l9 {; ` - [KAVBase / KAVBase][Running/Auto Start]
2 s( J$ d$ |4 p* P& n' C, W+ y( n, } - <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
' [2 i) X! {) A - [KAVBootC / KAVBootC][Running/Boot Start]
, T* y$ ~$ a, H! S- N; g2 ^ - <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>
& t1 W; m, R9 m# s - [KAVSafe / KAVSafe][Running/Auto Start]6 j$ q& s7 ?1 i3 A8 C. x% e
- <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>/ i3 J5 g2 w" C: Q/ O9 x& I4 k
- [KNetWch / KNetWch][Running/System Start]" j# D9 ?" C, H/ H" x
- <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
8 r7 H$ _3 e: T- k8 L - [KWatch3 / KWatch3][Running/Auto Start]1 s- G3 a$ u/ o6 P0 R8 X
- <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
& x5 S2 M% {% F! |0 h4 b! D" ?. { - [ntptdb / ntptdb][Stopped/Auto Start]- | ^ n1 P g) m7 _( p: _3 [% x
- <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>
4 p4 E2 U- M/ U r+ n h u' g - [nv / nv][Running/Manual Start]
1 Q7 q7 s! X: L5 @ - <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
) F6 B9 o1 E9 j$ O - [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]
& U1 G- Z) ?2 z5 x: ? - <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>
5 w; k' T: b" S: ` - [DDK PACKET Protocol / Packet][Running/Manual Start]- S+ q& k4 T. T
- <system32\DRIVERS\ProtoDrv.sys><360安全中心>
7 ?# `; t" o" C% X) L' r6 X - [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]
2 m$ f% ^8 ?0 s* `- w3 }/ x - <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>4 s% f! G0 h7 E" W# @, r
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]8 e3 j2 m- j( ~0 a% S+ M
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
$ ^. v- ^! j- m e0 D8 M - [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]8 R- h0 y4 m! S7 [8 T+ W, z/ S5 f
- <\SystemRoot\system32\drivers\RsBoot.sys><N/A>4 ^1 R% U" }( k; _" F
- [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
1 F v' d; u' M5 @. g - <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>- e4 u+ p& q" d
- [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]* `" n% V" p" K9 q4 e0 v
- <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>
7 r1 k( {- \: E2 G, ]! d1 k" R - [Secdrv / Secdrv][Stopped/Manual Start]
, z+ V+ f, B% I' `) A" t - <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>8 ]6 `- S7 G$ F2 v' ?) a
- [SATALink External Device Filter / SiRemFil][Running/Boot Start]
3 I5 q" z' j: R6 { - <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>2 j. g" _7 d% Y& ~6 w
- [System Restore Filter Driver / sr][Stopped/Disabled]
. s% \# r0 u" p - <system32\DRIVERS\sr.sys><N/A>8 k; j! q1 Q# |' K+ H' h
- [TesSafe / TesSafe][Stopped/Manual Start]2 i+ Q4 z, N! w- L$ c( O6 X3 U: D
- <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>/ X2 |+ O3 P( k7 N. a. m
- [System Services / unzxzsrs][Stopped/Boot Start]
/ h6 x! w0 W) r/ l; s x/ h - <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>
- g$ p; |& W+ S: j& U' `0 ?# b - [ViBus / ViBus][Stopped/Boot Start], n. J& G( O8 p( [5 [- g
- <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>) [: a# Q: [8 `5 L$ ]" ?
- [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
! ?! l; V, u Q - <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
1 \) B# h% }, a5 X; w$ s/ y - [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]$ M9 C4 G, U; r# \3 d
- <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>% q T$ E- R8 \: R+ A: C7 `% T* {8 ]
- [ATI Extend / zhibmaso][Stopped/Boot Start]
+ R+ }; D" H2 p3 Q - <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>
; S( y# G* d0 ^* [( ~& z - [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]
" c, f% W' V4 ]+ A+ q2 ` - <System32\Drivers\usbVM31b.sys><Vimicro Corporation>3 R: K0 g( y1 P
- ==================================
: V! a u" p% q6 B8 v4 p - 浏览器加载项
2 G4 F0 [) C9 ~6 I# S! e - [Google Toolbar Helper]& Z ?0 T6 X8 J5 r# _ o
- {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
* ^# ^" S. T( |! K - [Google Toolbar Notifier BHO]6 C- f/ C; I! ?& W; i
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
% b4 t7 X. p2 A' s8 X/ a, G - [SafeMon Class]1 M3 p' A+ V2 g; w! B" B4 l9 C1 ^
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
% Y( E9 x1 e1 U - [kingsoft browser shield]! _3 i4 k6 r8 b( n& C: E9 H* w
- {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
' h5 o, q* I: D( o* L: @! Q+ s - [IEBuddyExtControl Class]3 T4 P! K+ _5 g
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
5 Y1 U0 t) A0 ^ - [Zcom 杂志]% K3 L3 p8 j2 t/ E
- {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>; r2 b2 Z! N0 {. {
- [&Google], y; |- H6 P- S3 F- J$ x- [4 _' Q
- {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
2 J4 N$ {: r' Z1 u4 I2 P - [KooPlayer Control]
4 m3 F4 |3 ]3 w6 Z - {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>9 o7 Y! C# |) K* R5 B
- [Shockwave Flash Object]1 V1 b4 m, @7 G3 Q. M/ `0 b
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>8 ]9 J% {9 l+ a& V: M1 y
- [KUpdateObj2 Class]
. K! W4 @7 t! D7 H - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
3 g& P& E- V' v/ }) L& E9 y% A - [Google Script Object]( [: ]; w1 \* l, Z4 @0 x
- {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>; C% L2 I. L$ k0 T& p( t
- [EWA Control]
! k1 S) L6 T: w) E2 `3 h6 X - {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>
* t. ~- K( G! h& U" e, q - [Windows Media Player]0 U h, R2 N, q0 s+ P: g( }' b7 W
- {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>! ~3 v" U6 T, I: V
- [&Google]
% u& Y( \9 g' B+ ` - {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
' N2 |2 W9 U4 d - [HTML Document]/ ]8 q/ v0 y+ g2 y
- {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
4 n+ j1 H3 k( O+ H - [DHTML Edit Control Safe for Scripting for IE5]3 O" ]8 W1 h0 t9 S
- {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>: |8 R. b+ T5 Z2 O4 ]. y3 {
- [RealPlayer RAM Download Handler]
: [5 Z, k6 x7 j2 C& O7 Q" J - {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
1 A) F- A; H, F8 v) w( M. I - [IEBuddyExtControl Class]
/ C0 P0 Q' V- t; |' D" G; C/ t - {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
% L O: G/ |+ x( Q6 g - [XML Document]
" X7 t* V8 e) k5 N* q - {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
i/ R3 A9 A: x P3 R h0 f" _ - [HHCtrl Object]
# y% N/ f7 N2 M, }/ G5 K3 f - {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
! k& m) z9 c: N: [- ^8 A7 x. n# A3 b - [Windows Media Player]( h R$ c# D W$ t1 ]
- {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
- M' F9 h6 I- j0 F2 M. _ - [Active Desktop Mover]% B4 Y" i0 E" ^8 n7 _
- {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>5 E7 W: I4 H7 o8 d% P& K
- [360SafeLive]4 a3 m* B7 u) i* B9 }: f! r4 I
- {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>
+ i4 g' }7 o" G, `& k! d - [Microsoft Web 浏览器]) W5 x: W1 s0 ?# n* _
- {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>- K) C6 c, g) s$ r; y& k8 E
- [Browser Enhanced Objects]
3 H! ~$ {" B0 G# A, a - {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>
% J' m1 Z' a# j - [Google Toolbar Helper]
6 x8 X3 h% g5 { - {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>3 N/ c1 ^, g; ^
- [Microsoft Scriptlet Component]
2 \7 s$ {$ h4 N; `( v, M% O - {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>* I0 z' a% b& p8 A& u' @3 B
- [Google Toolbar Notifier BHO]
, \- ^. }6 U) u2 o& y. b - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>1 v% t8 i* o3 T+ q
- [SearchAssistantOC]( I6 ~0 l" v: b
- {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
" }6 Q4 ~4 J/ _% r2 d& I6 U - [SafeMon Class]) W7 ?$ p8 k# q$ `! \( R- B, I. j
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
: W# d& m4 s3 s( e: r - [RDS.DataSpace]
: e+ s& y7 C8 M( Y2 ~- S - {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>! \ c+ z9 { X# R3 Q
- [KooPlayer Control]: [( z5 ]: V8 T* J
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
# J# m$ |3 s. m( z1 _ - [AUDIO__MID Moniker Class]
. u3 u& L$ W) n - {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
3 V7 P8 t. ?. _# a3 Q2 | - [AUDIO__MP3 Moniker Class]
1 B" G) D+ R3 j: E% J - {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>! ~6 n4 \3 Y/ s. G
- [AUDIO__X_MS_WMA Moniker Class]
- o b& p( c0 c+ w% ` - {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
: g3 J ^1 z. s' O+ ~ - [VIDEO__X_MS_WMV Moniker Class]
1 W1 l5 i! r8 n& `( P3 D - {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>! k' E# J; t( ]7 g0 u
- [RealPlayer G2 Control]
0 Z# F8 ?# E! j! u' K* A - {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
' ]7 Z9 b- F, H5 a6 g - [Shockwave Flash Object]6 D$ f# v5 t: ]( M/ a+ n; W
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
" `3 B" u/ K( m6 ? - [KUpdateObj2 Class]- J2 U7 D$ l2 s8 G( Q" J3 C
- {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>6 `' [6 l% D* h
- [kingsoft browser shield]2 Z! n& h% U- p3 u- A$ }
- {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
: [# m4 t5 p- g+ e+ Y3 g/ O7 h1 p R - [PasswordEditCtrl Class]+ H4 R$ @' V1 V& {3 r
- {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>9 `& T) m+ P' n
- [QvodCtrl Class]
7 S, e8 B! f' ? {) r - {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>
$ z4 _7 X, r6 ` - [&使用超级旋风下载]) K z& z' I" v7 j6 ?" n( Y. p3 ~
- <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
6 r4 U! C; w" V9 h - [&使用超级旋风下载全部链接]
+ D7 d2 \4 S9 d - <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
: V; q) G5 [' L& X+ L - [使用迅雷下载]" O1 ~' K/ f+ H3 l9 e
- <, N/A>! R, Z/ s2 I1 Z: U5 z! Q
- [使用迅雷下载全部链接]
' o4 u( O) j1 d9 d+ W! P - <, N/A>' V3 g5 X; Y+ f
- [导出到 Microsoft Office Excel(&X)]+ H" L* b0 ]2 |7 r4 b) y. x% ]
- <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
+ v* a' k& l, f - [添加到QQ表情]/ Z- m: n u0 v6 j
- <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>1 y! c. g0 H- A0 X3 e
- ==================================
; ~$ b4 q( P, r3 g- G0 { p( l0 i9 X% E - 正在运行的进程
6 }7 @4 Z! |1 D - [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- u! }: M: h$ t6 ]: |8 C7 g - [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]* {) T* a ~+ {4 z2 i+ L
- [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]4 H7 y# h' U0 x7 E* f" n3 B
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
4 n5 k/ t/ y5 d! Q4 j - [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]; v, A4 N7 H8 N; b3 `
- [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
/ R Z) Z8 f. ?. {" f - [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
; }% p5 l- |1 N6 a - [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]+ `# v3 J6 R* Q+ d6 g. N
- [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
4 K2 J: H% k |) T - [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]7 B, X" n( a3 y/ N6 h
- [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]4 M/ a9 f) n1 ?4 x: U1 k3 w. b
- [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)] m6 D/ u# N. u4 F+ o% r& J0 e7 L
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
+ i8 Y: ?& y% W" U% M/ r. O& z - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
( C+ W4 @3 n! S8 Y, `$ D! ~+ f - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
7 @" z5 o) k0 h1 v! @ - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
( D8 k/ U" B J: w; m/ v k' e - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]
# r6 R, ~/ p4 X, D0 j' ] - [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]) ?$ I2 t& T- L+ o @' W
- [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]/ S% R% c: Y7 X1 s0 e' j7 c8 L
- [C:\Program Files\WinRAR\rarext.dll] [N/A, ]
& u' y0 G J* q9 z - [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
1 a& B( K: [4 x4 I, P3 E6 P/ e - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0] @+ J/ J2 |' v: O6 F) Z1 ^) C b3 M
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]: p* z/ v1 x: _2 f8 M' R
- [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
. s" q# {( Y* f! L) b7 S - [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]
3 d" [# P) u* x4 A! ] - [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]) q1 q/ Y3 R0 F
- [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008]
4 y( I5 n; O; P - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001] Z; M# |5 `9 i. V3 C/ X4 Y" a
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5] @" i& ^7 m: y
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
4 X0 ^! G! q0 M+ D) H% r, ~% B - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
6 D( z% l- L- J: G - [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]9 }% I/ v n) r( w1 ?
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
: Q" l5 e- ?1 m - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364], ? U1 b$ b; F4 @& Q/ U
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0] [( z( N4 }9 d9 s: M, Y& J3 F
- [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]
$ T4 O4 o* z4 u( G8 G - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]9 ~8 M" R% ?# E& O. }4 H% ?
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
s- Q* \: j6 `, ? m4 r& U - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]! A$ H8 e; E# u* X
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]
5 i! Y5 j, L8 @- C% v4 X - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]' l# O3 u2 {# @- M8 B* L
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
! D" D8 U1 Y3 I8 b4 H7 E5 f3 {& [ - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
8 `$ t1 N& X3 w/ R9 b( v; _6 c1 @ - [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]) f$ |- R, a! T% a4 \
- [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53] B/ s2 D8 {/ [0 Y2 B5 ?& I
- [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]! s8 g6 U$ m" i; _2 W
- [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
' r0 b3 p# c5 C; q; | - [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
; T" H& z# d6 ~1 i4 x: y* _ - [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]- z$ w3 L' ?" K- ]) f# u4 p ^
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
/ N' q% ], r9 m8 d" e! W, y - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]6 n8 M! n2 A9 j2 S7 G; B8 C
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364], B" X9 ^4 N4 R4 j
- [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]
) K' F% ]9 h% ] - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
; R( y& h( U5 G; j! \ G* W - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]' K) i5 K9 C- Y1 K' R
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]
# ~% V7 {- t5 c6 v" ^( v6 v - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]
H& p; o! o* v - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]
. [ p( n* R% Q) w" `; R - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78]
3 e, ^& n$ O. c! O( A) s - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]6 W/ Y' L4 e0 @
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]6 P2 }5 I0 @: V7 d
- [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
/ |: ]- s# ]0 a1 `( n - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
1 x1 j8 S3 w/ k2 j& m, F4 _; ~ - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
+ b0 {# }$ l( E! I - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]1 c. m3 Y+ M: B
- [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]7 I( h5 L g# V6 Y5 f
- [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]$ V# [" L( z* G+ z$ ]
- [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950]+ o* z3 g5 N( \3 c& ~/ p @
- [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]
1 g1 _. a4 m- l, p2 s - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
' D8 ?: a* j6 f - [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]( a! f, A4 N2 C' n# K
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
( I- w7 r$ Y( @1 z5 L6 P - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
# e7 d! h6 }2 n* f - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]: `' `& |( g, |
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
. l" e( U* w) T3 s0 F+ ^; e - [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]: k8 l8 t- Y9 p
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
8 }0 \) X4 n$ D1 C. b - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]: ?9 J7 {6 p. ]# y" g, ?
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]3 u9 _) k4 o' R! H7 Z: D, M
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
7 h5 E( @2 Y: |- w; Z1 a/ o - [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]
0 X z8 g& _9 j) }) ~ - [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]$ {3 O l* B* I% Y
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
1 t- w6 Y9 `/ G7 f/ C- G; @2 Z - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]: K2 g$ i+ Z. q+ e( `4 D. s. ?
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
- W( T2 S8 ~9 w5 i5 E - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]* \0 _4 |/ w5 g/ o6 E
- [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]$ Z- y* U- X) ?, K7 S( e* H7 ~6 b
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
- ?! B9 E4 L7 @- p" f. R. ] - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
/ K( u9 ~ _- U5 }( ?# I4 q( y3 j0 ?- B, H - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
9 z' Q: F7 G' C: b# _/ x7 M - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
' [3 D! d0 `7 f1 R - [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
6 S+ U- l: _' o$ E5 E0 f - ==================================) N$ M0 r1 S* d( x
- 文件关联
: G' u1 ?- u- D8 ?, Q8 n( H - .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
& s6 R* O5 L# P5 \- u. R; d - .EXE OK. ["%1" %*]
' S+ R2 y# `$ t - .COM OK. ["%1" %*]
8 E' @" m; ]; a$ [) D S; p - .PIF OK. ["%1" %*]
6 @6 o. S2 Q( L# U* A; A - .REG OK. [regedit.exe "%1"]; C6 J" v4 ?' J1 x% G. J( I
- .BAT OK. ["%1" %*]; K1 t; ]8 l' ^# _+ k! `
- .SCR OK. ["%1" /S]
, ~8 `; U O5 p! L/ ]- J5 d _ - .CHM OK. ["C:\WINDOWS\hh.exe" %1]+ w+ R5 i; ?) I7 f
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]$ j* m: z# `3 h A1 O9 A8 H8 r
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
4 f) G" [' n9 G. R - .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]& I% r$ w+ e2 k4 q1 I. h
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]( U. w9 V$ g) M0 [' u! P
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
, `0 ]9 h2 P- J; R0 o - .LNK OK. [{00021401-0000-0000-C000-000000000046}]% p8 K- \8 _/ u0 x4 E
- ==================================* n) g4 P W/ L
- Winsock 提供者
]$ e/ a4 b: B7 G% d& M - N/A( u- o* F0 { ^' ~5 B
- ==================================
Z% E4 I5 M- K; d' Q* Z J% D# x - Autorun.inf
* A2 w! b& V W6 L* Y. l7 n - N/A
% U/ C7 G* V, m4 J% p4 f - ==================================
/ D% p' w7 Q4 t. t1 i; u2 {# V - HOSTS 文件
' e7 j [1 h+ n# f7 ^: P/ m- a - N/A4 ]; b* K4 n- l5 B' p# e, ]+ c* ]7 w
- ==================================
' g7 ?0 \9 m: L+ r* ` - 进程特权扫描& Q# ~5 N0 Q# o) | a- b! g
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]% Y. Y) v _5 w6 P; M' H) I
- 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]
5 |) @7 }, T" Q* y7 h; _ - 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]
) G$ R: [/ H. Y3 F. I% B - 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]1 i: v) y. o# O8 v2 _2 J \
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]
' ?9 v% a$ l1 v$ {4 G$ V1 N8 [3 l6 ] - ==================================
$ Z% z9 j& r4 B$ ` - API HOOK
2 H7 c, {2 B; y* U5 |: j. i - N/A0 W1 x9 o/ U& `0 d/ U& P
- ==================================
8 [! k0 S* q; E2 ^4 p/ E( l - 隐藏进程
8 |5 Q# O3 ?, m" T( t9 P/ v+ F - N/A
9 Q4 l q5 b0 } s - ==================================8 X8 s ~5 g1 v% H9 n. \4 I; Z
4 X6 X6 n- V; O: T- z
复制代码 |
|