|
|
7 [# w6 l- b5 U0 l B' _$ `- 2008-05-22,20:37:43
7 J$ V4 y$ j0 h3 x - System Repair Engineer 2.5.16.900
- z# i2 X a: j r0 q- z - Smallfrogs (http://www.KZTechs.com)
) R7 t% k5 N7 H& P - Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
* A# U+ {, F$ m8 o7 J - 以下内容被选中:
& \8 z) Q/ z8 X - 所有的启动项目(包括注册表、启动文件夹、服务等)
' r+ u1 d( e& k# z- ?# D - 浏览器加载项
1 ^3 J1 ?8 K8 X) Y - 正在运行的进程(包括进程模块信息)
- q9 x8 }+ |+ t1 ` - 文件关联$ k3 y* V# A/ _: r; t: z( g4 |. e
- Winsock 提供者! I% A2 T- Q" m. J" [4 @6 W
- Autorun.inf
1 S1 S/ T) r. ]8 y, Q' x - HOSTS 文件; G) Q9 i; R5 I
- 进程特权扫描
: h0 M! q- ?3 a4 h0 r8 p. j4 A, u
9 g6 C: k7 L: ]+ s1 ~1 w8 |' ^- 启动项目) Q; S4 q) @8 Q7 N& L$ ]
- 注册表8 c- g- C* x. K* i& h) b: p+ ~; l
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]+ Y4 `& _$ ~! X+ C- u) E! f
- <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]1 A" L6 {" f& @6 V) X4 W$ X8 {1 T0 h. e
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]+ M# Y2 v0 Q: z0 q1 F3 G3 T
- <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]
; Q9 f& V! S4 e2 K$ m# L - <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
/ K9 p" A- i- A0 s - <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]2 e9 `# F/ I3 Z+ I
- <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]) o- m8 ^! s" d7 o% X2 S1 `5 R
- <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]
% z0 U/ j1 Q) p9 J - <PHIME2002A><; > [N/A]' h; Z! D* A4 e2 o
- <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]0 X' \) r. c% b- ~
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]( ^3 | {( F( n, P. c
- <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]+ k! d8 P' k. @. A9 E
- <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]
# C5 ^" w p! F3 S - <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
5 F& a j' i( ` M3 E - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
0 e7 M8 D+ d4 c' p5 ` - <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]
$ B7 e# B; _4 K& |' ?5 _* k: W% [ - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
1 ]- v- t4 M( k8 U0 D - <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
; t* I7 C$ U+ m2 M% K7 O - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
2 r" i3 I! U7 [( r4 G - <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]! e7 l% b1 O z, c7 z
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]4 y" d1 V% _ k& {1 M7 |
- <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]* m$ T$ I X; u& {1 x# N& f
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]1 @- \/ q& B% U0 j& _- E
- <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
1 N) v0 P" M& o, v- | - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]8 S; Q' H% k# x0 |; |6 H/ q- r6 y
- <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]
: F/ Q, {7 _$ J) ], v4 D' U - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
) G: q1 }2 q8 v6 V! u3 S - <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]; T$ t1 H# g B' p( F9 R5 ~
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
. }- _# H, R, {" f - <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]( H. R9 g$ ^5 T: }: `" k7 j4 ^) t
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
. w4 Y% a2 D; G8 ~/ s! v+ I* F - <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
% W; L5 ]8 D$ M7 A; C j - ==================================2 H1 u& i+ l, W3 z/ {4 d
- 启动文件夹
1 n9 o% ?: u7 U# ^) P. ? - N/A- q' e! q9 x3 {" s
- ==================================
4 p5 W$ }) {! S \: }" U - 服务" I# |! ^& O3 y4 v
- [3ware Controller Service / 3wareSrv][Stopped/Auto Start]
5 T. B7 u" Z4 k1 v" J) C# M1 T - <C:\WINDOWS\System32\3wareSrv.exe><N/A>
. Q3 p8 d# i9 o" x# Z( H p# L1 j1 s - [Google Updater Service / gusvc][Stopped/Manual Start]
# W' d1 y5 \& N# T" n - <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>3 r8 w: o- d* n- p1 Z
- [Help and Support / helpsvc][Stopped/Disabled]7 l! f! ^! J/ M" l4 ?5 w$ \
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>9 ?; F1 s C6 ]; a, t. f6 j
- [Human Interface Device Access / HidServ][Stopped/Boot Start]
: N' y8 U: ?" ~8 o - <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>9 i1 y! p7 ~% ^) E0 j2 l
- [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]
: u/ E: j" {. v3 N! @+ { - <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>
+ h# k+ U5 Q' ` i - [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]; x' ?& o" m( ^+ l! {' `
- <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>4 H. q# j4 _$ z J0 t# Q
- [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
# y4 Y% V# q( p! a, u: D* @ - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>
5 P8 ^, ?7 O6 |; e) v# |- e4 C9 @ - [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]3 Z" l2 g3 U/ `8 t
- <><N/A>
4 X) m* u9 q: t& w - [Qvod Terminal / Qvod Terminal][Running/Auto Start]
' ^$ ^4 a. b$ u - <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>- Q1 n$ `7 y$ H4 p: f2 P1 a1 k' ^
- ==================================
8 }1 Z) W; d4 H% { - 驱动程序1 a. [3 V9 ~9 N
- [22j / 22jn][Stopped/Boot Start]
/ ~1 }& _4 R1 G - <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>, k3 `9 H+ r* ^& {" n
- [360AntiArp / 360AntiArp][Running/System Start]
4 ~4 ^" ^$ [) x1 p! { - <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心># ]: `+ E; [8 l/ Q
- [43ec / 43ecu][Stopped/Boot Start]
6 _, i% \* ]5 [1 t - <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>
) @9 u& W3 o9 t9 h - [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]( ]' P) P/ P ^5 }; N/ b
- <system32\drivers\ac97intc.sys><Intel Corporation># C h0 n3 _2 A
- [Promise driver accelerator / bb-run][Running/Boot Start]' O/ Z: b& W. [9 M' H
- <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.> y) [; f' p) t5 k0 n" O
- [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]. p. I* `: o' d b
- <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>1 Y" F4 e) @, B0 e+ P4 ^9 n
- [KAVBase / KAVBase][Running/Auto Start]" H+ {6 O& f8 p! V
- <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
' G" E- E! |7 x2 c9 O( R - [KAVBootC / KAVBootC][Running/Boot Start]
' y/ e* }, q, T' \8 q6 ` - <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>
! @ X5 [1 s1 K3 z - [KAVSafe / KAVSafe][Running/Auto Start]
& G1 s$ i1 C- |* { c5 v, ^+ G - <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>( O$ b" V2 P* K& {+ z- k
- [KNetWch / KNetWch][Running/System Start]
8 ^1 h, _& J0 x; m/ P3 }0 O' F1 U - <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>* W/ x( W g) N5 L
- [KWatch3 / KWatch3][Running/Auto Start]( W! N; G; w N0 C; @6 |
- <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
1 B! ~2 j I( d8 f$ i - [ntptdb / ntptdb][Stopped/Auto Start]
% X0 o1 n/ P2 C' d' @/ ` - <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>8 a2 h: k' }2 U K
- [nv / nv][Running/Manual Start]/ y8 s( w" q6 ]0 \9 d6 y
- <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>+ ^, T3 i- C3 M# R8 {: }% ], e
- [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]
7 F2 ~ I% @& i1 [: j - <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>6 C% M& K& \/ q& p0 L+ ^
- [DDK PACKET Protocol / Packet][Running/Manual Start]
6 s9 x# F+ a& [9 G8 z - <system32\DRIVERS\ProtoDrv.sys><360安全中心>
# h( Z4 \, Z3 ^6 z& p - [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]4 ^+ P3 a) O, r1 g, U# i; a
- <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>" b( @% I' z- g4 E
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
! ~' ~. L1 Z7 q+ d - <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>$ z" T. `5 Y1 u/ V
- [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]
4 v- X0 c& ]( h ^% ] - <\SystemRoot\system32\drivers\RsBoot.sys><N/A>
4 Q( J# f" p5 L9 r) f- f0 C - [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
2 e% z: I* y5 ^0 h0 c( I - <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>( E: C, g& T1 c) H8 [4 f/ x
- [SafeBoxKrnl / SafeBoxKrnl][Running/System Start] Z& q" Q x1 u
- <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>
2 Q1 U2 q$ ^7 Q0 A }4 Q - [Secdrv / Secdrv][Stopped/Manual Start]9 f" C2 J$ Z7 u0 L5 A
- <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
7 I' O9 g/ Y% \2 P& H' A; M0 M - [SATALink External Device Filter / SiRemFil][Running/Boot Start]
; a% V3 @+ \) F2 D$ ] - <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>
$ s7 Q* e, m8 h6 L* F - [System Restore Filter Driver / sr][Stopped/Disabled]
i4 i, ~2 O' x' D, B+ V5 ^ - <system32\DRIVERS\sr.sys><N/A>" @: s, @- r a m: c/ f% V* N
- [TesSafe / TesSafe][Stopped/Manual Start]4 X# X/ x; E1 Q9 X
- <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>
" w1 s2 k. G+ h) } Z8 I7 { - [System Services / unzxzsrs][Stopped/Boot Start]
( e. x" y6 O. Z - <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>
) g8 p5 [; W6 B, u# j3 j! [" @ - [ViBus / ViBus][Stopped/Boot Start]
9 l$ `) ~& R! G' A9 [ - <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>
' J( F3 _" i4 g3 D+ d - [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]% R+ ?% s5 I" R* m8 |! e
- <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
! v2 X# A1 T& [# F* u. N - [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]2 ?, f- R+ T/ J
- <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>
+ D. M2 E& }- m7 ~ - [ATI Extend / zhibmaso][Stopped/Boot Start] i4 A' [* g Q1 v: I; X0 R
- <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>
% i# W& g: o% ~; A! h8 |% p/ G - [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]- U8 }, O0 o5 ?+ [" n* Q
- <System32\Drivers\usbVM31b.sys><Vimicro Corporation>, G# l* W. q- U$ i7 ^2 a* ~- h
- ==================================
1 `2 G) Z: n# ]( P2 o, q& N& Z - 浏览器加载项
6 A5 ~2 J. ~! ~* A3 F - [Google Toolbar Helper]
8 [/ ]1 U. s$ o9 O) g - {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>7 F# b" Z L4 w7 J8 a# p6 z! v
- [Google Toolbar Notifier BHO]* t, Y" `6 b7 y* q% y4 h2 O9 @
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>- @% N" j, T1 ~& O4 e" w! n
- [SafeMon Class]$ Q/ F6 Q8 s) Q. j) r6 |
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
! q: i% G: e7 ?, c4 [9 e- i - [kingsoft browser shield]
0 {2 N3 p7 d. x$ Z5 R1 ~. F. t - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>: @/ A9 a8 g* T) E9 h- u4 Y; L
- [IEBuddyExtControl Class]
# z, U @" G3 w9 O4 M' J - {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>" ]3 Y- X( b ~. N
- [Zcom 杂志]( x0 D& _' o% \0 E5 L- _4 J1 z
- {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>8 V: r0 G9 h8 E% g5 g0 J( y" L
- [&Google]# q' B$ @( Y: S6 V3 W. @
- {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
- a/ N, e( S7 u4 N" G3 { - [KooPlayer Control]
' v+ p/ G1 [( |+ R; w) p! [ - {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
( M/ n5 e7 e+ n( g - [Shockwave Flash Object]
$ b3 v; _0 U k+ }: }9 f - {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
% ~9 B# E3 g) ^; u8 F" R; q - [KUpdateObj2 Class]
& |/ y4 C* o ~+ i Q - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation># o* _& m8 T1 e* G
- [Google Script Object]
+ H7 S+ [( Y3 k+ D% I! Z% G - {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>0 L8 S- e! K( U( F! _' s- J& t" G
- [EWA Control]
* |0 }4 h w2 ~8 D" `& N - {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>. {) L7 R# P5 r8 U( I
- [Windows Media Player]4 z8 ^5 u0 a, ~& I! w( v
- {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>
. p4 G7 Z$ K9 B6 J' T! w9 C) N - [&Google]$ @5 ~& w2 F2 X
- {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
/ o; G9 X9 ~& x1 W, H: e - [HTML Document]9 h+ t f: Q/ W& i. ~; `
- {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>" U8 d7 ]$ W: M
- [DHTML Edit Control Safe for Scripting for IE5]5 N' W! v8 J4 |& S, e
- {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
! N& A# `0 ]& j9 q& s9 ^* | - [RealPlayer RAM Download Handler]. C3 x; W1 O) S. ^( @' p$ ?
- {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
7 j; ~3 A& r7 a+ ^5 |( C% k - [IEBuddyExtControl Class]3 O/ D" w; J/ r8 A" G
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
4 I/ U! X0 u+ m8 G7 B - [XML Document]1 e, R- H P$ i0 h5 Q
- {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
6 y2 x0 {( x' }! f - [HHCtrl Object]
* `! L# b3 G- A! W$ B) @. K - {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
T Y8 P) X: l0 c8 |5 J - [Windows Media Player]' n8 {7 V! H+ y; [+ J7 Y
- {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>1 i) F* o4 s& ]- |5 K. G) I
- [Active Desktop Mover]
- f7 @9 C% P; x6 q9 o5 t. Y9 Q. p - {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>$ P1 K( E9 W& |7 {, k# a
- [360SafeLive]
. O. N0 K9 I/ Z' T* h8 m - {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>, J3 P5 Q4 A9 N
- [Microsoft Web 浏览器]4 L9 u" a9 l* K$ M* D$ {9 I2 o
- {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
7 [6 E: p3 K2 F0 I- q# ~8 s - [Browser Enhanced Objects]
9 O( c4 N; O' | - {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>8 \1 h( E4 W( s! G/ ^! g/ P- L
- [Google Toolbar Helper]6 O5 |2 X- |' ?. i! h8 j2 f
- {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
/ ?2 I4 { c- @/ t4 ?2 ]" |3 Z - [Microsoft Scriptlet Component]
+ K, l) r0 [6 P, P! T! [% @2 K - {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>4 x# \* @! c# ?/ D( g x
- [Google Toolbar Notifier BHO]
. C3 ?9 O6 | u; A - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.> \" K/ ?, o& V8 i% }) f
- [SearchAssistantOC]
/ h- I9 K) y) n4 v- n& U, p& N: _ - {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>/ g0 s- D1 H! Z! L" a9 U
- [SafeMon Class]$ i0 o, i& n" s/ R5 t- @+ D! B7 {
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
( j- {( u8 o1 u - [RDS.DataSpace]
2 k3 u' X* Q' c - {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
6 i( j$ {7 o6 L) S4 x& ] - [KooPlayer Control]
: H6 m( i7 ~& S) _, N6 d - {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>& p/ f- }3 E9 y
- [AUDIO__MID Moniker Class]
. V3 @0 {) s2 b# G6 p+ t - {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>1 O7 g# G3 M6 Q& i# R9 W# d8 H% x
- [AUDIO__MP3 Moniker Class]
, o. _' a( p4 ~) m/ H1 |' r4 `) k - {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>- I; F9 {2 H S9 k& U7 b8 e
- [AUDIO__X_MS_WMA Moniker Class]
. g5 b' {+ d8 O5 y - {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
% k0 D+ h! s& i) \( k' h0 q8 s8 p - [VIDEO__X_MS_WMV Moniker Class]$ `% r, a7 p" y. N. }
- {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>% L" `' @$ x% c: D/ S
- [RealPlayer G2 Control]6 ~6 W% a. T& C$ T( R6 x1 v' u! L
- {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
- f$ {4 n7 ]8 A) _% A - [Shockwave Flash Object]2 B2 `+ f8 E% ?. ]# M9 ?/ ]9 T
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
; r2 ^' x( {$ ?) c w9 H - [KUpdateObj2 Class]; m* H& J! Y4 J( w
- {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>( v$ ?6 Y" S0 i. A* P- O# O
- [kingsoft browser shield]
* F: D1 z5 \7 B/ S2 ] - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>7 h# v' k- V3 b7 f- g( z
- [PasswordEditCtrl Class] G- P- b4 F# h! n0 D9 g% T" W
- {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>( G9 o3 _8 Q; n9 Y4 o) M, f
- [QvodCtrl Class]3 E# `/ S1 w, l/ a
- {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>
6 x. X) S$ s( [5 D( b, N2 p; F - [&使用超级旋风下载]* O) t r# U* W" b
- <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
7 d4 Z' V0 b' F9 }% Y; H; n - [&使用超级旋风下载全部链接]
' S0 J- Z5 Q) M* m H - <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>" ?' U9 O3 @- u& r
- [使用迅雷下载]: Z3 B. ^( E, \% I4 U
- <, N/A>
" H) K- J7 B- O8 R- D - [使用迅雷下载全部链接]
/ u5 @( \6 [/ g. j2 ` - <, N/A>- H7 ~ { F) ? }
- [导出到 Microsoft Office Excel(&X)]
, s$ ?/ ]& j! Z/ {+ ^: f2 ~- P - <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>* h3 p" n' N5 U( Z) L
- [添加到QQ表情]
9 j" ^0 Y4 j( r - <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
7 P! ~# @( |- U6 E - ==================================
) N& D0 s6 N; c' M# v0 c - 正在运行的进程
7 K+ w- ~# U2 I5 z: h; ^ - [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
6 y0 Z1 D" `* g$ b4 g - [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
' Z9 O$ V3 `4 f. ^4 D - [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
) W; O/ O4 b' T8 ? - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
" N7 {9 r" _: Y1 ~; F7 Q! N9 O - [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
5 w+ E! V0 n( D/ u$ h* M/ a - [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]3 ?3 j! L/ r2 p
- [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
, w, h8 d. E. L6 } y; Z, w! z" V - [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]- q( ~. `, A+ ]
- [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]8 @* L/ l7 }6 N/ s6 w; C* G3 X0 A
- [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
! v& g5 n+ U% T7 g: R - [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]; ?. S6 r/ v7 t) N3 T' I4 Y V
- [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]
+ \2 d# X3 j9 S5 ^+ I; y - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
; G2 [% X7 d, ? - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
3 _: j9 m+ w# z3 W - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]3 t5 Q% w& u+ g8 [( |( [6 v
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]6 U$ E/ N2 x9 [3 V! q3 U g
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]
) W9 M* X' p+ e1 o! U/ C8 O, { - [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]1 Z2 C5 B9 N2 K* u* L) R/ s9 @
- [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
* J; |. ^: T( i+ U; c0 I' @ - [C:\Program Files\WinRAR\rarext.dll] [N/A, ]5 i: a" M& |4 ~* h
- [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]9 A* L7 F. o% j& H/ u
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0], b, ?: a8 h9 i: V' {. H9 i
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
% ]( z" y% w) r0 C2 O7 I - [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]# L: K2 ~& u( M! f
- [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]4 U8 @# W5 S" {* F* @ P' h
- [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]
: z' d8 v6 \9 P - [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008]/ g; E- {9 j, \( |* @3 V& r. [
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]5 w- {/ c$ q. ^1 b( h
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]& K T- }& A# g$ ?' \3 ^7 q
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
% I# H7 |# S4 C" ~/ W* A) z m. v7 R( D - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
4 P3 X S1 m! x9 P4 f" S - [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]& [: A1 I% H U$ x
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]2 o' q. |0 u0 |/ o7 g' ~
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]# ~, W4 Z( |! l/ t7 H
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]) r9 t( x8 y% c9 [' X
- [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]
: w8 H6 N) v- P- ]" ~# ^# w - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]
7 B/ O' [2 k: @6 N2 Z - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
6 G* R6 v y" ] E) Q8 K0 l - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
* q# q: e( }1 {3 l# Q+ B* |) K - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]
4 V1 {6 x) `, ]5 f - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]8 }4 C1 k3 t5 }; B' q8 {6 z# ^$ B2 d& a! N
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]: C$ F7 m5 s; Z, N
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]& X/ q; b3 ]5 J) K" K7 l
- [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
. J8 X, e4 _ F. e: I - [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]" ~# t1 I3 y+ Q$ N7 m) i) y
- [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
8 y4 q* D" o. ^; h - [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
2 c: B3 `+ C: k6 `9 f, K& o - [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
8 ~2 _* \7 k S7 u - [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
* u/ m9 B1 _% ]6 e - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
8 n$ i! b" I8 p! C/ R( G8 ~ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
5 S2 |2 }7 y- m# j - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]+ j/ D3 }" T0 C* ?7 w5 s) I* {" l
- [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]
: F0 D6 O9 o8 M/ o. [. e; ~ - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]* g1 O8 S: T9 ?
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]; |$ [( [& S j6 t' F" `7 d! e2 d0 i
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]! {6 |$ C) |' x" @0 N8 G
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]
( y. U: L% w4 h$ N$ o2 Y% E- O - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]6 i) v% ?3 i6 u
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78]
) r* D, p( |5 Y5 }( Q2 n9 V - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
5 Q( M' e1 y& Q% V4 n7 r - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)], `5 I1 S5 e2 M4 q; [
- [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]6 t4 Z5 C- c# U
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
6 z& ~) D1 R8 m7 @' V - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]! N! u0 l: K/ `7 ~2 g1 p$ i+ g* C
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]7 b9 b& T* j# \, Y8 ~" w4 b
- [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]+ a8 h; E: b+ p( b
- [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]! s& P$ T/ m: X3 B
- [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950]; a, K5 D* L' T
- [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]& Y s9 f$ t9 l; e
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
C0 ~6 Q/ A9 C1 A - [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]: {/ ~! N b. F% X0 P. G, |6 `* q
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]* N1 ~% P7 s; S+ a
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]+ R7 a) H( u+ ]9 g G
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]! R6 }: E: z& M0 g" A. Q1 l: u
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]- W$ A+ p. O* ]2 c# ^& |8 ]
- [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]
8 _$ [8 I& [/ u3 o U( \6 o. y - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]& h9 B/ k9 d- b; _9 H
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
; A# Y* x. b: X0 m5 `8 k) _ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
- c7 A. R/ o' O4 T8 L - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
9 w' Q7 {3 K5 Y2 S" p( a - [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]: O* N; V6 e6 ^# l
- [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]
$ r: {5 S' z+ ^ - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]. e; S% ?" f/ d \0 a
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]' S, b- u% ~/ J, r* \' s1 N: o) J
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]% ^# m+ @0 L! u/ L x! `
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]3 X/ a; j5 a" g$ V1 z7 x6 |' T
- [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900], M6 ]& d7 Q( n! k" R/ r
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
$ ^4 h( @1 x2 R6 W - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
6 }+ k7 U& J6 M, w0 n - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364], j: p! c& z) V+ b
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
" x% S' A; j' F& m - [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]) p) @. q3 A# w+ k
- ==================================
& o4 u! X5 u! ?' f) l - 文件关联6 N' G1 S5 L1 k L
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
* {) M0 d- q g) N" ]7 ]. m; f - .EXE OK. ["%1" %*]. B; p3 D. q# `
- .COM OK. ["%1" %*]2 l7 q! C; l" F. w% |$ g& j; e
- .PIF OK. ["%1" %*]% x! p/ D; x2 k7 _8 W( D/ c4 j
- .REG OK. [regedit.exe "%1"]
V. ] t/ |, N! H - .BAT OK. ["%1" %*]
% l7 R9 k0 F: W( X* B* s3 ]; x - .SCR OK. ["%1" /S]" i# |+ u7 h0 b! R5 s6 H
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]( d3 L/ L( H1 s; y+ C9 L: G4 l
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
/ K0 d( l, G& ?/ u z. k. [/ m - .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]/ \1 c) K: [& M g# d
- .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]6 |/ _. I, e' Z
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
, s( ~7 _5 k6 z1 E - .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
' _6 q8 [. [0 E7 ?) A - .LNK OK. [{00021401-0000-0000-C000-000000000046}]
, u) f/ X0 n8 A) K - ==================================( { s- a O1 Q2 y$ f
- Winsock 提供者! U1 Y1 N$ m+ T. F# S
- N/A T7 Z" q! `% m
- ==================================3 w2 e8 i5 H8 S. r8 N1 d
- Autorun.inf
( [& f+ S, L. M4 W- v) o3 X8 D1 ?: O( g - N/A
0 ~7 g7 W9 M" x1 i7 q4 c4 ^4 m- ` - ==================================
4 X6 w8 a# J% N5 n- A - HOSTS 文件1 S/ a0 C" h/ V% g- c, H8 b: _
- N/A
' }) ], I6 y# E$ ` - ==================================
: T5 `7 x" l4 Z+ v! U9 n; {6 P1 h5 q. k - 进程特权扫描+ t( J. u* @; W8 y
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]% v! c5 x" J) U9 h( x1 T
- 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]) ^, J3 Y. f- c, \
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]7 e2 k9 u4 E% p6 G& k! w
- 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]( V- t1 w9 e! B! C$ A6 b
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]
& Y. z8 u; I4 ^ - ==================================
% m7 Q: S6 j' I3 b( V# f5 g- W) g - API HOOK
' h* F ]4 T5 d6 J$ Z+ Y - N/A- {) t& G) v% ?# n) \ @' b9 o# J
- ================================== i; @( }9 W) E# `! ^( \) Z4 \
- 隐藏进程
% Z( `9 V9 |6 M& }6 a" f( k - N/A9 l0 ^" \# W/ P! A0 f) y& V7 S
- ==================================6 h# b/ p2 S. U/ ?
- 3 m! E% i( ]! i) I$ L& a$ v3 e
复制代码 |
|