|
|
- + v1 ?4 s1 z2 ]5 v- c3 r2 ]
- 2008-05-22,20:37:43
5 O6 T2 x) x& i6 f' Z9 c - System Repair Engineer 2.5.16.9002 u, E; ?; o* S6 n
- Smallfrogs (http://www.KZTechs.com)
) J2 X9 o. I! a- \6 R6 I - Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
, ~6 c. L1 [( [: M - 以下内容被选中:
* ?9 u+ K$ Q$ s1 n3 ^, K - 所有的启动项目(包括注册表、启动文件夹、服务等)
F# o) W" }9 E3 J& L. Z- j, w6 Z - 浏览器加载项
& W$ x/ W& g- w9 z2 X - 正在运行的进程(包括进程模块信息)2 N% c; }, A, j* O) _' V( E
- 文件关联$ y. Z$ Z( d( o) A( ]4 j# _0 `. k
- Winsock 提供者
5 v9 j7 T1 }9 o5 Z" w* u- x& r - Autorun.inf# i* m$ {9 S9 w- P, `& H
- HOSTS 文件$ a- w3 S0 {; `2 i6 A* m
- 进程特权扫描
k) T/ O! D+ G- z0 i% e3 \ - 8 [, B- ~! S$ J5 m2 ]
- 启动项目: `5 [9 M& s/ ?) U1 `! j, u. `& A/ F, h
- 注册表
* G- I4 Q. f: E& L) u - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
7 d9 L' q, k' W& b& R - <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]
' W& K. p* ^: e4 ^1 d- U - [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]* q0 d' m% M2 m9 a
- <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]0 ~2 N/ q( i2 d& B, e8 n! X
- <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
. |$ T; N4 s" }, ^ - <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]% q/ V$ U' w1 W2 p% }
- <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]
! J' X8 o" m/ c: W - <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]
- N# G# I6 S8 }& ? - <PHIME2002A><; > [N/A]
8 I/ k, t2 s U" }- c$ M. M - <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]+ [7 ]& V9 n v* V0 O
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
G1 k ~% }2 q. | - <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]+ x- S- ?2 J0 Y* L% f
- <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]$ L% Z3 i" I, O w- U7 W
- <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
2 `- v7 {; \! O* Z8 x - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
/ J" s. T7 w2 z5 x5 }, R - <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]6 h# Y& V6 [. q5 M+ ]' U
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
: f% D" Z" c5 @' H - <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
% q+ t, c0 q( j2 y( v - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
& q* W7 w: F* {/ ~$ D0 b: R0 ] - <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
* v' Q) V: o2 |3 q4 A6 `; v7 C - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
( g" F8 @" V& _9 } V1 g+ p - <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
& z. H/ p6 R" @ - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]7 }& M8 w) ~% i
- <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
7 S( D: Y5 V( O7 R: o - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
3 M" @: h" g0 b1 A" K - <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]
_1 |0 D4 h/ I' }3 B& ?& @4 ^ - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]- n0 p$ v8 @+ D- D6 J) G2 ^
- <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]/ k# P) ?7 v* `% O* e# M& E
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
3 Q5 h8 b1 o1 q) j - <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
. w% a5 p+ }0 D! K, q! B - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
, u0 E7 h, l) |9 r8 E1 g - <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
% V, O' J- s. p, O - ==================================
2 s3 ]% i1 h5 W' f/ f - 启动文件夹9 ]' G5 y3 U; G% U- ~" k
- N/A4 J& h8 t. d- N+ U: [
- ==================================, b" c. R, k" b$ m
- 服务% U u: W! \$ c9 f8 X3 Z! W# f( J
- [3ware Controller Service / 3wareSrv][Stopped/Auto Start]# ~, p5 C2 J @& z0 F
- <C:\WINDOWS\System32\3wareSrv.exe><N/A>
3 M4 {3 X1 p) J) q5 D L - [Google Updater Service / gusvc][Stopped/Manual Start]
9 M5 G# e4 e: w& O1 H# q1 _ - <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>/ B" x. ], E, V/ H' B w4 `
- [Help and Support / helpsvc][Stopped/Disabled]
) [2 l5 j. y' F7 u - <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>* m5 ^' o" f( m$ o
- [Human Interface Device Access / HidServ][Stopped/Boot Start]! I- U. Q7 ^( f$ c$ |4 ^
- <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
. @- Y P' z* y3 O$ x- E - [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]9 m) F* @3 m, A/ ~6 b: Q3 \
- <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>
# z8 |! f1 u8 r5 {+ m( [, a( A - [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]) i$ [9 r/ N+ w) { {5 g
- <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>, [/ i7 A$ e* i4 n) _2 _
- [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
* R8 [2 ]3 R& C5 k - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>+ O0 \- J4 \. D
- [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]5 r. C( p9 `% `; S$ G5 p! l
- <><N/A>% i& q8 |) R% v* `' h: ?
- [Qvod Terminal / Qvod Terminal][Running/Auto Start]1 P* U" s8 E- Y: u7 d
- <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>
2 a$ j: i4 y3 v% `1 B$ t, R - ==================================
7 w, o" h( D9 @$ h$ o8 n' Z& } - 驱动程序1 q; @; |9 V# J, F
- [22j / 22jn][Stopped/Boot Start]
3 T2 @ Z$ @/ F; m; k% @3 z - <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>
m0 K/ t# s. z1 B" O' B - [360AntiArp / 360AntiArp][Running/System Start]
) O, {" W9 E% s8 O' \: P9 g - <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>/ F" {# ^/ U" V* d" n' Z
- [43ec / 43ecu][Stopped/Boot Start]) }/ I0 x h( U$ j
- <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>
" y4 |! M0 V5 e3 N7 A# U - [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
2 O0 X9 g- O; ]! P: X/ f6 { - <system32\drivers\ac97intc.sys><Intel Corporation>
& F* n6 p+ J3 t0 t0 v0 [/ n - [Promise driver accelerator / bb-run][Running/Boot Start]
! h+ ~; z% j0 Y" K - <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.>2 D2 W. c1 y" B: W2 [- ~
- [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]) y4 w& {! v+ n% x5 s+ E
- <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>, ~/ K N0 Q, Q* j. H$ U
- [KAVBase / KAVBase][Running/Auto Start]
' L$ e5 g( S( D0 x' L2 c0 A - <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>. D2 _ z2 n. r# [, {& N% l
- [KAVBootC / KAVBootC][Running/Boot Start]8 q4 @4 ^: F @
- <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>
; ?3 p0 B, E; {" C) L - [KAVSafe / KAVSafe][Running/Auto Start]
# t# k+ v7 l* e! V \ - <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>$ g R! Q# L" Y7 k
- [KNetWch / KNetWch][Running/System Start] X/ S4 R, m0 { Y# z
- <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
8 g' F% s; D( ^: ]2 ]+ ~$ |# b4 a - [KWatch3 / KWatch3][Running/Auto Start]
& v/ X' M: F3 K" B. g0 z( \6 p - <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>( B8 }* F8 g/ m' L# k3 T4 t/ T
- [ntptdb / ntptdb][Stopped/Auto Start]
; I0 f6 e$ n+ W; O' u - <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>9 s; m7 i* `0 v$ K8 A0 G
- [nv / nv][Running/Manual Start]' m- k: H D( d* K0 p" v( f
- <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
6 k) A, G6 V- ?2 E0 r - [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]$ i. }6 n+ ]1 D( C( G1 |" O
- <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>$ l& Q9 B3 x( M1 p; @( F) W5 }
- [DDK PACKET Protocol / Packet][Running/Manual Start]
# L, ?) a T! l9 a/ p! K - <system32\DRIVERS\ProtoDrv.sys><360安全中心>
4 i1 P; D2 P6 [4 w - [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]4 g, r* z, ]" C+ s/ }8 [
- <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>/ Y) Q6 U9 l; i$ g" m
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
3 ]: n# N6 p) {7 F+ k* E9 k9 {$ t - <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
% {/ L3 e+ l$ o; u* W$ C8 _ - [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]4 K. j4 z0 ?1 }3 [# p! k6 ]
- <\SystemRoot\system32\drivers\RsBoot.sys><N/A>
3 e* z) }9 X3 {1 _7 l* a - [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]- Q& j* l% u* V j7 r
- <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>1 }: Y3 R1 }# Y+ q8 g7 F
- [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]+ x/ C B j+ I. [* L2 y9 e
- <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>8 e; ?* P! M, p$ z8 z
- [Secdrv / Secdrv][Stopped/Manual Start]
4 r4 j% G/ m/ P' s7 Q1 b" g$ o; o - <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
W$ S- G$ h" y( F: P - [SATALink External Device Filter / SiRemFil][Running/Boot Start]
) x" \1 y4 f6 ~ - <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>" H: G! g/ q+ m8 g/ v" T2 Y/ T
- [System Restore Filter Driver / sr][Stopped/Disabled]
3 q, H. ?! y0 k - <system32\DRIVERS\sr.sys><N/A>; J: J5 j6 |" B3 H& G9 L. o. u
- [TesSafe / TesSafe][Stopped/Manual Start]& T3 h F y6 h1 |2 p$ b
- <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>
2 C" h9 `: I, A7 B3 j4 K - [System Services / unzxzsrs][Stopped/Boot Start]$ Z4 n) \# V/ M: E
- <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A> N5 u; A1 b% z( X; ~2 F' V8 s' p
- [ViBus / ViBus][Stopped/Boot Start]
+ k" @* Z$ ~& b# F7 N$ a% x7 n2 N - <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>: @/ P2 v( o! U
- [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
4 q' [2 l# z! s1 ?( ]& l. E - <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>. q! O, Q5 E. \4 i4 R( Y
- [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]
" d" `& a; W$ V! y& h - <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>
Q6 F- c9 ]: v( W - [ATI Extend / zhibmaso][Stopped/Boot Start]
3 E. J" S; _) E0 o! [ - <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>
$ e/ q: ]1 T; _7 b - [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]
e% _+ I4 Q8 ?; c5 W9 D - <System32\Drivers\usbVM31b.sys><Vimicro Corporation>
2 D# j9 `# Q; Q; x) R6 w# L, ] - ==================================
* x5 p8 f' d; s$ A- w - 浏览器加载项
) u2 x# L* d0 ~* I- C: @ - [Google Toolbar Helper]2 X6 z& j$ D' T+ `5 ~
- {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>) t% S. |, k7 H: O" Q
- [Google Toolbar Notifier BHO]
; j& ?2 S$ c+ E, l9 e - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
: h4 U$ O1 [; u" | w - [SafeMon Class]5 \+ \6 k. W2 `# S$ v, v- u4 ]
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>* e; f& l7 I6 t8 |7 s3 G! g
- [kingsoft browser shield]
* \, C! v; ~, L/ K' @ - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
^6 F& r s1 Q. D7 @ - [IEBuddyExtControl Class]4 ~; ]9 _! E$ N( D
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>+ t# F( N' d* l) M, u, Y
- [Zcom 杂志]8 [8 b3 p* ?4 q- X
- {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>1 V9 R. {9 q+ A7 b
- [&Google]8 t: m" ^& x: ^5 E3 L$ V% q
- {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
4 m; b8 s- X0 L - [KooPlayer Control]" F5 a1 ^% ` \9 `. J1 L" G
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
% ?+ `6 ^1 H6 R' K2 j$ V# \" A - [Shockwave Flash Object]8 N0 P% Q/ J3 {0 c3 _
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>" B; |: f" @6 F: {
- [KUpdateObj2 Class]
) U4 f( U# R/ T - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>" A. j' `* q# ]
- [Google Script Object]3 X* O# Y& A T% ~
- {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
+ w% G3 `! u. m$ g+ D - [EWA Control]
. J* ?5 o# A: i( n - {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>
5 a; f" C( v0 @. ?1 j; g& ^ - [Windows Media Player]$ P8 g0 m/ S8 s- [' d
- {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>; R8 w+ Y% j9 [
- [&Google]/ e7 j; F* s& ?6 L8 L( x
- {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
8 ?6 j3 S" w- @2 P - [HTML Document]
& D# M: ^$ |0 V8 v - {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>. C7 E; g, r9 ~' \* x' v
- [DHTML Edit Control Safe for Scripting for IE5]
" O! T5 X" q; u" Q7 \ - {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
0 U+ D( n. o+ L2 Y/ }4 e - [RealPlayer RAM Download Handler]" Q) d$ {0 J- K' J/ ^/ G9 |
- {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
8 F" z+ ^' J: I9 Z5 V6 b - [IEBuddyExtControl Class]
' ^2 K0 _) Z! Y0 r7 i - {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
' v# P2 F$ o5 c2 W4 k/ ~$ R4 I, Q - [XML Document]. f5 O7 x- j0 e8 _# N' ^
- {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
4 q5 r4 s' \0 b' s, B - [HHCtrl Object]
# q# ^$ n( K- i4 t* {" }3 u6 A$ b/ { - {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
2 W8 H2 k0 [6 v3 l! s# ~ - [Windows Media Player]9 N e5 o; s1 M+ ~
- {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>" n/ T# H0 F/ E! ^) k
- [Active Desktop Mover]
$ l8 p3 [, I. Q3 }- Y - {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
& t$ M/ W4 Z4 f2 g: B8 u - [360SafeLive]
' p2 m1 V$ Z3 P; }1 o - {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>
r, Z3 d! U& l4 [ - [Microsoft Web 浏览器], R! S9 m& V) v8 O: z( f
- {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>5 |/ Y0 h1 W7 {; x3 ]% @3 ?' f5 @
- [Browser Enhanced Objects]
: A! u6 L$ o& Z4 W. @ w - {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>6 x5 u% Y% o' _7 C3 F7 Q+ _) B
- [Google Toolbar Helper]
* M( d( M' X* F- U; A - {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
7 k1 g! i3 K: M7 s6 _ - [Microsoft Scriptlet Component]) I5 t2 m3 }/ U! `. h
- {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>% l* t d3 Q U" Z. g
- [Google Toolbar Notifier BHO]4 w, Q. A9 i4 J! G/ k
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>! Y! s0 ~. F- E1 ]: d
- [SearchAssistantOC]# `$ Q: U, {" j E" G) @# d
- {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
7 [. b4 d4 F7 f1 W' y3 N - [SafeMon Class]
: r, n$ A6 E& b3 u4 u - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
/ ?' A7 L9 f) I$ C; O4 g - [RDS.DataSpace]. b6 j: Q) p& {4 W( i8 }; M
- {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
" h0 U' P0 r5 f1 D3 H6 J4 F) F - [KooPlayer Control]
# A5 m1 j2 D% T2 ]: w p - {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
, s0 a8 i6 H) S0 n - [AUDIO__MID Moniker Class]2 L) `. C7 q4 A o$ m4 s
- {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>, D5 [" Z; k+ ]; d* E
- [AUDIO__MP3 Moniker Class]. Z" e+ H: g \) h- w% S
- {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>1 ?- b/ k) \" x' k/ B
- [AUDIO__X_MS_WMA Moniker Class]
3 u8 m% N6 u" `! W. [3 g - {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
) R1 r" F2 G- u# W+ j8 L6 O) D - [VIDEO__X_MS_WMV Moniker Class]
5 u4 r; \: Z8 ~3 W* t3 \ - {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>* ], q4 g! W% s5 ~7 f! N
- [RealPlayer G2 Control]
+ x. H9 `$ O' t0 c' h+ K - {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
6 B2 A' e3 h6 c( B - [Shockwave Flash Object]
; _ r' d5 a7 W2 t; Z - {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>1 y4 {; M d) S0 ^
- [KUpdateObj2 Class]
1 P# w3 d7 F/ ?) j - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
# m- G( F: n4 x O7 n1 `1 ] - [kingsoft browser shield]! r) a, [3 p, t( b a
- {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
% S0 I4 e4 a/ a) X8 {0 b - [PasswordEditCtrl Class], P9 }" `& q# K9 s) y
- {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
2 c! [6 t" J- |* `3 ] - [QvodCtrl Class]
. y. L8 n7 P/ R8 Y3 u) G) | - {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>
7 H2 ^ m! N9 S8 Q2 O" B - [&使用超级旋风下载]. E% s( Q8 @6 g( U
- <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>( j5 u- _% `# _
- [&使用超级旋风下载全部链接]8 F2 ~+ \" g6 P; \0 T9 w e
- <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
0 S! X) f7 M7 K9 Q" i1 S q# { - [使用迅雷下载]8 h. {# @% r' W) b2 z" G
- <, N/A>
: Y$ V. L! l% U - [使用迅雷下载全部链接]8 w+ b, i% E* }+ y& e
- <, N/A>
7 Q% X. H& P+ a9 `$ I& ?5 h - [导出到 Microsoft Office Excel(&X)]
% n, {' n# Z/ z+ v - <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>/ i. `& N7 s6 m$ P# h ^& g
- [添加到QQ表情]
" X; Z& i ~ | - <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
" f) U. q' {. d |: o9 C - ==================================
& t8 j6 r7 d7 O: a. a0 v - 正在运行的进程9 Y+ P# S8 q4 Y, r" s
- [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
. x/ H4 U6 i' L' ^ - [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]- ?! E! P7 l7 m* l& h5 K
- [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]2 v E g6 k b0 K/ g
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
4 q: Y8 A! o& q8 }' g/ f - [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]9 \1 e, K2 O: G* d& V$ F
- [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]9 V' d& a( Z% J0 E; B& g
- [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]8 ]. a; h; w" k4 i
- [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
% F- P5 m; r& I; }: ~) A" W - [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]8 P4 v" M; p5 Z* X4 b9 n" U
- [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
6 X* P4 u4 {% b( ^* e - [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]1 M- N! J. ~( T g% L$ v
- [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]
6 m, N4 _: k$ G' r - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]* u0 g3 \9 I( g# V6 w' h/ K
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]9 F: W( ], d o8 W! G
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]$ I) o* q' t$ |6 _/ M2 }
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
9 v$ t+ \) k% K. Y& X4 O" M - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]
# J8 f) s0 N# p1 b+ j - [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]
; E H, T2 A0 Z - [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]( d4 V7 D! W2 v, O4 V# _
- [C:\Program Files\WinRAR\rarext.dll] [N/A, ]
7 ]; y' z: [$ v; o# r v. u5 c - [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]! s4 _8 B! q2 R; x1 C# |, @. r
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
/ ~3 `. a% g9 _) f - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]( k6 O' ~1 v$ e) r& z. C/ p6 G
- [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
7 K6 j; o- [; b" c* y+ E( u* \ - [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]
( H5 g5 M5 Y( i* H - [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]
& [6 w! Z5 U! A- b, z' K - [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008]; o1 H! g# h9 O2 W$ M+ a. [
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
* w R6 ]) B, f( P - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
( D. l1 I/ [, C% z7 u - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]0 j- U6 J0 X7 `! o9 c' z
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
0 Y! `$ G# Q5 F. o/ w - [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
' x8 M# _2 y; A1 k - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
7 E% ?; o, n$ H/ t {, ^: x. ^# O - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
$ b7 v, W# P9 `' I( F - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]9 p1 D- C5 j. |5 M% S3 c' k
- [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654] P1 M& \! w s. t* Q
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]2 A3 ?. s- g8 U4 H4 w
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
5 }; S6 J; ]6 H7 `( l4 } - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]. I8 O! r# B# g& l3 V4 N; \# ]
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]
4 p; M; N' X& W% a5 a - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]% x. H2 r' t/ E
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]3 Q6 O$ |& {/ i
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]7 _- [& L4 f& y) `! r
- [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]& N5 f( r. r) v* @4 b! e5 F5 K
- [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]
: K' M; ]' m" M: X, j - [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]) F& Z) _% ?" A6 \4 q) P
- [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
* s8 n( @/ H& h1 W+ c0 f: t7 g - [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]3 [* B1 j$ ~2 P& }3 G3 z7 z0 t9 I' G
- [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]9 `5 J7 i7 h4 i$ F
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
) r- W) w' [- b/ s! T) L - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]; U% m& B$ V" p( k* B) F
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]9 P" ^2 i( f. W) A, p
- [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]
, C4 n; B+ N3 g/ ~ - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]4 i) l* u" ^7 E6 v- P& A" e
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]
5 p6 ]% U/ u( o- M2 C2 z) \4 R& p( } - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]
3 q. ~' n7 h! N" ] - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]5 K0 O# s: e [) V) b+ U& `
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]: P) F+ u5 f: P' O! }) }
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78]. N5 v# r" f7 d) X8 _1 Y6 q, Y
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
" R% E3 y; c) b; j' { - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]) q) e8 Q( \4 |$ q+ i
- [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
, w$ V6 ]9 e; w" m* C2 Q8 C# j% @ - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
# W, X6 b/ S( E7 p9 u5 g3 E - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]2 W# M3 \1 ]3 h* L8 y p
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
4 l4 w3 r' n, f& } - [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]
+ Y$ [1 h; t! m$ q* B - [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]/ _8 b5 h+ W$ v0 [/ u* q
- [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950]
# ~3 l% P/ H0 W p* ^. E - [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]- e0 {# N" ^/ K8 y6 x$ f" W
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
9 K! N. m/ A7 g" Q7 l - [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]) J! _& i/ z( {# m! t/ J
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]( v- X$ B; A9 W! U! j
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
( t' C0 m2 L* D* c- w0 j' p - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
6 R* b9 ^7 m, G) ~ - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]' B/ L G: y1 N; f/ I, Y
- [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]
0 y. ]0 Y# }( t- ]; S) N) V) i - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]; O" N' _* O ^
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
" h" I2 `0 m" ?. e - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
- B8 ] \" v5 _1 n2 g; C" B - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]/ F: c$ C3 z) f" X, I- k' i
- [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]( [0 {. @, Z* M. i+ ^
- [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]
" K4 F8 y M$ `5 t* e @; L" a0 J - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]% S2 V; h* `) `! u
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5] p+ j$ z8 P/ d2 h& K
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
) X& B2 @7 }& ?& D- ? - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]+ t7 a V1 \. g# O1 n) q
- [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]; e6 O. A" [: R8 y8 l! `
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]9 h1 n/ e! f' Q& t/ n
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
0 z+ j2 ], T+ n' r2 ?9 h | - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
) x- |0 p! [' t5 b - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
& B2 i5 y# S4 }8 S) A - [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
# X9 N! Z# @8 x/ A9 n: d/ H - ==================================3 B) w' c K' R: k/ l6 J! k
- 文件关联
+ Q' w# P% O: ^3 v: [7 V - .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]& a7 ?/ m" W, W0 g
- .EXE OK. ["%1" %*]' Y3 o! x1 F/ N' T( T+ H8 L
- .COM OK. ["%1" %*]
( m K* C! u9 s# M& e6 B, c7 h - .PIF OK. ["%1" %*]
9 m& m. e6 L# K, x9 l - .REG OK. [regedit.exe "%1"]
& y1 O3 S% x- V) q7 m - .BAT OK. ["%1" %*]
4 c5 w2 o2 R; B! V, o1 Y4 t, U' C - .SCR OK. ["%1" /S]
, i0 \3 |, Q% T; F1 n3 ^2 B* O - .CHM OK. ["C:\WINDOWS\hh.exe" %1]
j4 C# T) q7 D( c( N* _ - .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]9 \6 m- S8 U! a: v% |
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]! n/ q4 r( J1 q* B$ D: o
- .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
/ T) T v! v# e# F7 V3 ] - .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]2 X8 k, }# o/ g6 n7 b4 B) C) {) Z% {
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]' r0 T/ G: V/ |" T" K2 e; \
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- H* Z+ J3 J8 L, c/ n# v6 H - ==================================
. V' O! C( _$ A, l9 e - Winsock 提供者8 L! g* s4 f9 ]5 J1 o6 u6 z
- N/A
1 F! W: a* T, |& r - ==================================, D9 t0 w# C' j7 v
- Autorun.inf: x$ P: Y- y% e
- N/A2 x* z& f( }' R/ y1 m
- ==================================
3 p4 {3 Y& v$ x9 O, v' W - HOSTS 文件6 f9 t) S' u Y& J' L6 g
- N/A, C! n. d* ~: h
- ==================================
I2 h5 U9 d: ` f - 进程特权扫描' {. ?7 `0 F6 D6 m" H1 S
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]/ W! j7 u; X' R) a7 x2 f
- 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]
) K& _, N1 p8 T t! t - 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]0 N$ | h+ p+ g% X0 c
- 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]# m& T7 }1 \) A2 ~4 u& d
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]
9 `6 c$ l7 Q% y: K. M8 E7 e - ==================================
0 M$ b- a( r! G - API HOOK
* p7 s0 U( Z) ?& ?9 T# x8 S) G: R4 \ - N/A6 b, i+ o! }: P6 A
- ==================================% x2 \* D' V1 h- |4 Q. A
- 隐藏进程
# y$ y+ X, R' h - N/A
" }) @. C9 d$ f/ E V, u, q7 q) z; ? - ==================================
/ l9 }- n7 ~5 t! j6 J4 D- o
4 e" n& q/ \+ E( N9 L8 s3 D
复制代码 |
|