|
|
3 k3 _ |/ \0 n4 m- 2008-05-22,20:37:43% F" z- ]1 E+ v: ]* F: u
- System Repair Engineer 2.5.16.900% p" ^1 m, W: Z b
- Smallfrogs (http://www.KZTechs.com)! [* i* S6 F: N8 [) S* `) S
- Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
8 i/ \- w: l6 Y. a! d& b6 P. a2 C - 以下内容被选中:
/ k& Z' w! s& h1 X, k, b - 所有的启动项目(包括注册表、启动文件夹、服务等)* @/ ?8 i9 ~* W1 L W5 v8 o7 y
- 浏览器加载项2 {6 y [/ U+ c* y! {2 c! J& x
- 正在运行的进程(包括进程模块信息)8 C) Z" {# G' X! U h
- 文件关联& Z2 l: J0 M# E3 N4 \! B
- Winsock 提供者0 [/ m2 S6 l; e6 W) ^4 o2 k
- Autorun.inf! l3 `, u; \! `, r- P0 M
- HOSTS 文件
5 j+ A/ ]6 R+ @6 l2 K/ `1 \0 v$ X: { - 进程特权扫描0 @( q0 H+ g1 l( T" H* m
- B8 d( @) C3 S7 Q9 Q1 i h- 启动项目
/ h9 k; o2 G( V- Y* w - 注册表
4 b% t5 |6 z8 e, N - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
4 V2 Y6 l2 y8 Z) C1 f) T - <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]
/ m, y7 X$ v5 `+ [ - [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]) k# G. X4 N2 D0 j
- <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]
( }% h; O" C+ c6 k - <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
1 F3 D# z+ M F, l7 ^ - <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
8 L6 i$ [( _8 v$ k3 n - <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]
+ {, E8 a7 k) W2 f5 V: o( A - <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]6 E+ K, }* t* j+ Z
- <PHIME2002A><; > [N/A]$ [! B/ ^. e# ^6 e( h8 e/ [
- <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]
: _5 [( V1 `4 |5 M6 N - [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]+ O% x; k# Z$ s" { f' W/ D$ `& _& i3 g
- <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
* S$ N# S1 ~# i4 j+ @" D - <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]
3 }+ v8 d u+ a* ^ B1 f - <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]6 V9 ^: M' ~' S% q; U" C2 ~6 g, g N
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]+ v4 _0 }( t4 |2 y1 R
- <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]( o2 J% i/ R: p) H
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
7 G+ m6 \; x; A3 } Z9 v - <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]0 q U8 Z, F5 ]( J% Z* P& M
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]2 U4 V) A5 A+ e$ X5 p
- <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
9 l4 |: v% Z5 ? - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]2 }$ Y0 A1 C% O: M
- <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]# ~$ N2 i2 g9 L+ S# B
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
4 ?( v1 ~7 ~+ W' E2 e- H! O - <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]( @& J/ P5 c' O" Z
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]7 ~2 k7 b7 H! L
- <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]3 q& z% b4 a* W; S1 [* C2 J+ U f
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]8 E* I# c6 w+ r6 C0 e2 x: b7 U5 S" {
- <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
0 v& @: b7 c+ s* n6 i4 v - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
1 n$ E3 x# H, o1 l+ m! L: g - <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
$ J* b8 ~$ y# ?1 q8 l U% d - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
! Y7 @% n4 |2 z# p% F - <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]8 Q( ^8 W# n5 c( O
- ==================================
+ F9 t: i% S: S! w( h0 M# h" m - 启动文件夹9 S# P: N# c6 F; I- M* K* O+ ~
- N/A
9 C+ s% z t1 g: F& J4 @ - ==================================
}( A4 E# F4 R" ?! [ - 服务
- D! s; u m; d" H - [3ware Controller Service / 3wareSrv][Stopped/Auto Start]
: \- C) W; I6 B* U) A( u - <C:\WINDOWS\System32\3wareSrv.exe><N/A>- P* B1 s, U; l% V$ @% Y/ \& l
- [Google Updater Service / gusvc][Stopped/Manual Start]
r4 D. x& u8 f; D) ^( |3 t - <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
- A* S( J# ]. Q0 a; \& z - [Help and Support / helpsvc][Stopped/Disabled]
2 I+ k5 U8 I+ f1 n6 N# d - <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>
5 h( h/ z+ f9 a5 z% ?, ~ - [Human Interface Device Access / HidServ][Stopped/Boot Start]! n2 h Z: D3 H8 |# Z! w
- <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
+ u5 \5 d* b8 X6 P% ~ - [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]/ k6 O5 `5 e3 K6 l
- <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>* S+ ]3 g. \. G. o
- [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]5 B1 i$ x& Q) v( S" z/ q: w
- <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>
& Z; { v4 o0 j' H - [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
2 x' ]: e- l1 r( D - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>: u& o* Q2 o7 \5 ]1 M
- [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]
5 q1 T1 J9 M+ T - <><N/A>& h- U; c/ E) M3 T
- [Qvod Terminal / Qvod Terminal][Running/Auto Start]
. v% A& a' a: X6 X - <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>
2 S# p5 p6 m D7 n6 F1 n - ==================================9 I7 |% y( p/ F) [* |. B
- 驱动程序5 d k5 u/ W+ @: @
- [22j / 22jn][Stopped/Boot Start]
, z4 w( T- V L# t8 Z5 v - <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>/ a$ U9 A6 ^9 j' j" p
- [360AntiArp / 360AntiArp][Running/System Start]
' @# @: k/ @, K3 q) P) U; @- f - <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
! }5 H& X. D. c& A" ^' K - [43ec / 43ecu][Stopped/Boot Start]
5 i0 b" t1 b/ g% Z; ^ - <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>1 v/ P5 D3 _. T& l/ v
- [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
+ D: s1 W% n2 e% J% D - <system32\drivers\ac97intc.sys><Intel Corporation>, W( y) v7 z& i3 v. g2 T
- [Promise driver accelerator / bb-run][Running/Boot Start]
6 E9 Q* G' B2 _3 U$ h4 n - <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.>
9 s8 S# D' h6 L. a; T' T - [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]
. I9 S, ]& W2 h4 r - <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>; E( ~2 |# \6 N. r+ a% u
- [KAVBase / KAVBase][Running/Auto Start]
, f9 c4 x: B" I* z { - <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>- V. u; `7 G, z0 @: ~, z5 I) f* t
- [KAVBootC / KAVBootC][Running/Boot Start]
1 o% s" [! Z' p- w - <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>. Z/ T/ E F( `( G! J: ]
- [KAVSafe / KAVSafe][Running/Auto Start]
% i o5 S `! B8 x! m% S - <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>4 w" L: t# w5 B' G$ M
- [KNetWch / KNetWch][Running/System Start]
: H" ~/ M) Q0 B# _. i - <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>! E& d; A/ _/ y; O4 q( m5 k
- [KWatch3 / KWatch3][Running/Auto Start]
3 {+ Q+ r- T# b2 \8 j - <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>* n& A+ a& s, I4 C+ T: l
- [ntptdb / ntptdb][Stopped/Auto Start]
% v4 Z6 t9 m4 b3 ~- i - <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>
' A3 U. N7 ]* a, {5 H+ W6 k: a7 a - [nv / nv][Running/Manual Start]
! ?( M1 J9 Z; P, q" }! _ - <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
3 G. W2 j8 `0 f; y - [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]' J5 R# w% j1 k% b3 I' f/ F
- <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>% i3 X/ M6 {7 p$ S5 `& @
- [DDK PACKET Protocol / Packet][Running/Manual Start]
7 c F5 ^8 T; H4 p# D5 z5 y - <system32\DRIVERS\ProtoDrv.sys><360安全中心>
- T0 u; J5 m$ o) c - [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]
c m, r( F: H- |8 D6 k# B - <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>
7 {+ [( F- q* {% k$ E; p9 ] - [Direct Parallel Link Driver / Ptilink][Running/Manual Start]5 w' o0 x/ ?* h/ w1 N
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
* {5 J2 z9 g! H% k- I7 b - [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]
+ V5 N5 I3 ~/ B$ J2 r - <\SystemRoot\system32\drivers\RsBoot.sys><N/A>
' A1 C5 p7 r0 _: Z( d) |, B - [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
`- ^9 M+ n( v$ N& d& |1 u9 d - <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>3 [( D4 G- @6 u
- [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]2 O' p. z- x: Y8 b) e0 b# C3 \1 Y
- <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>9 p# Q7 H- ?, ~ A
- [Secdrv / Secdrv][Stopped/Manual Start]
5 o9 N3 C- E" b" P) u# Y. h - <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
$ o) j: ?2 s: g1 J - [SATALink External Device Filter / SiRemFil][Running/Boot Start], `* `% W& P% b. o
- <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>
# c: O z- u$ |+ I' R; V - [System Restore Filter Driver / sr][Stopped/Disabled]/ P; ]% W6 L+ z' x
- <system32\DRIVERS\sr.sys><N/A>7 M8 J0 h1 Q* A5 v r, h
- [TesSafe / TesSafe][Stopped/Manual Start]
- ?# I: w! v* h- l F! { - <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>- N' z( z2 w) |$ T' D1 i: n
- [System Services / unzxzsrs][Stopped/Boot Start]+ f F5 Y. U% O5 Z2 C
- <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>
/ n. e2 _& G! j5 v) C - [ViBus / ViBus][Stopped/Boot Start]
! S% k6 X0 z7 X" a+ I9 H, M - <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>4 }3 n! F: o# ^8 y
- [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]9 ^# j: A0 ?1 N" `1 d$ j
- <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
) P( {2 r2 E( T2 X& u - [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]+ H! T( z! O6 Q4 x ?) t
- <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>7 i1 Z h( ^7 d8 O( P: S$ Q
- [ATI Extend / zhibmaso][Stopped/Boot Start]
: u5 T$ b' @9 g( S, J, Y* j" V" Z' N - <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>
8 b: O# q7 ~' f0 |* w# X$ h - [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]. Y& m4 y) k: P1 S! c2 B) k
- <System32\Drivers\usbVM31b.sys><Vimicro Corporation>& f; Q2 S# v/ D% [- a+ `9 A
- ==================================
* z( N& _+ @' O7 y& u- y) r - 浏览器加载项
6 I* \. X) T5 } - [Google Toolbar Helper]
/ b! P. K2 V H- D9 { - {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
2 ]5 M/ Y% c* U5 r - [Google Toolbar Notifier BHO]
- E* A: A' B1 r2 e( k1 g - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>8 M: [$ [, P* \+ `5 p' |+ |
- [SafeMon Class]7 W$ j; X) z: [7 Q6 k6 k$ ~0 r
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>0 B/ i1 ?( _1 ?* k! Z
- [kingsoft browser shield]& ?* ]# [" m) V) E8 a; B F
- {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
0 `3 o3 k4 d, Y. L* E9 Q - [IEBuddyExtControl Class]3 i6 b- T. ^( G! z
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
y }# {/ _5 O - [Zcom 杂志]
2 A) d/ R A" @ - {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>
0 z7 g! W* ~$ L1 Y% a6 W - [&Google]3 A( P: R/ S/ c
- {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>5 X+ Y( G; g' H, j/ ?* r& W
- [KooPlayer Control]2 S6 z0 y8 A: o! O. T+ n) y2 f
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>- v. N7 R9 z# f8 H" B
- [Shockwave Flash Object]
7 U8 u9 q% t3 E9 V - {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
9 T7 O A7 o l6 T - [KUpdateObj2 Class]
+ N' U5 Z% H; `# [ - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>' F5 F/ p h5 w, Q' J7 S( d& p
- [Google Script Object]5 z4 ~# R& E1 G& w( U$ ~% w% H' f
- {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
+ ^5 d+ G/ M0 h! P) k - [EWA Control]+ U) D! v, \) K3 r8 M
- {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>6 Q3 F& X/ E" j
- [Windows Media Player]1 l. _7 \ g5 f7 s) C* i0 L: G
- {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>( Y6 h9 q. e0 b4 W B& M
- [&Google]; a. v! q& i5 Q6 Q2 G3 }9 }
- {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.># T. q" P9 q; z+ Q) K$ O4 k1 g
- [HTML Document]: B5 S/ @) J: j M Q8 X
- {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>7 w- q% Z7 L4 k! B8 `6 R
- [DHTML Edit Control Safe for Scripting for IE5]/ Z! N. a5 n/ c9 ~! ^+ h: b
- {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
1 l3 u! ^/ m" d7 R - [RealPlayer RAM Download Handler]
6 `3 b6 o3 [- I3 v4 _1 W - {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
# y& X; d& l& V - [IEBuddyExtControl Class]
. p* c) N. ^7 Z- _ - {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>. w3 j) ~5 D& E5 q7 e1 I! O' a f2 Y
- [XML Document]/ R/ l2 C3 |8 G' A' N/ J; }! V
- {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>1 d6 }9 L: Q3 V) F
- [HHCtrl Object]
) v7 z+ O1 L, ^" r+ e - {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>3 i8 Y) ]' _! k& E1 S
- [Windows Media Player] ^: e# _6 O9 Y F# }* T
- {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
4 ?3 }6 H% G, g; B" I6 i% m9 A - [Active Desktop Mover]- `+ v) `5 x$ z, B
- {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A># h% o* M4 G* x. k( \
- [360SafeLive]
) t y3 L$ j. i/ `5 C! J' f1 f - {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>
. i, K6 v1 k, u1 h - [Microsoft Web 浏览器]
) t2 A2 b$ W5 v* z. s# }, P1 Z - {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
8 _- Z+ E0 e8 h1 L! P8 G" D, |( H/ a - [Browser Enhanced Objects]/ }( h' `) i' Y
- {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>
% v" N# z6 g0 l; Y5 W0 w - [Google Toolbar Helper]
1 {+ W; R& V: W( a: A1 E2 Q/ _ - {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
$ c7 m! A" C: r d8 g P - [Microsoft Scriptlet Component]
0 T, \' N* w$ v9 W& b6 I: V _ - {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>$ P) f& s% O4 |+ r+ R, R
- [Google Toolbar Notifier BHO]9 \' N# A# \) Z9 b, }* K
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>/ L, l8 |8 r, @; G5 I/ l) ?
- [SearchAssistantOC]( v! U; u1 P# b! ^; R' E* }
- {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
2 V6 v+ {$ r# F- s" S$ m - [SafeMon Class]
0 u: f6 ]" T; a$ D' u - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
) ^6 ^0 O- a9 I; h$ w) _ - [RDS.DataSpace]' d8 u( ]2 `6 c3 P
- {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
. B4 j9 f& S( H( G: x - [KooPlayer Control]% E4 ]6 c. z3 @0 o
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>$ _+ B6 I' k& M. }* X
- [AUDIO__MID Moniker Class]
: r% n5 @& E$ H6 A9 @9 x2 U - {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>, |0 [ q7 Q6 _; H, Y+ w
- [AUDIO__MP3 Moniker Class]
( a m7 G0 v0 E - {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>1 @7 ]2 [3 T, r$ B6 q
- [AUDIO__X_MS_WMA Moniker Class]( u7 b% ^+ R3 d% l
- {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
5 i& v$ F3 I3 l/ n' x" @- n; e3 n - [VIDEO__X_MS_WMV Moniker Class]
6 |1 j: u3 S2 K7 @" u0 I* T4 `5 ` - {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
_% \* F/ U; X7 _/ T - [RealPlayer G2 Control]
# W4 R( P7 `; r% |6 w, E$ Q - {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>% ^: b ?6 i% l. o* a
- [Shockwave Flash Object]
9 N2 h5 v- V I# ~ - {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>& u) N- T- A6 I, Q
- [KUpdateObj2 Class]
" M/ h( ` _ x" E2 ` - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>. J( Q" X/ z; M& \! x' i* K
- [kingsoft browser shield]
" ]6 y- L) t6 i3 w$ o( Y* N* L - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
& j' e7 {7 L5 E+ s# W3 e" D) G1 `8 } - [PasswordEditCtrl Class]
% S& f- e1 U; }( v/ n4 |, t - {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
6 [+ r5 `1 k; h+ z0 m: S2 H, G - [QvodCtrl Class]+ e, Q0 O$ L+ N& y
- {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>
2 n$ f+ v8 \" c - [&使用超级旋风下载]
( D9 k; B0 u {: ~0 y - <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>& w, R f' J( W2 Z- I* s
- [&使用超级旋风下载全部链接]8 L6 u' k; L. e0 |( @
- <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>+ a1 D* R- E t" P9 g
- [使用迅雷下载]+ E. I9 z9 T1 ~( ]1 }' J' c& W2 m
- <, N/A>5 W+ W6 Y0 }& m
- [使用迅雷下载全部链接]) D8 G) z9 h! W# B( k7 j& w
- <, N/A>0 M/ U5 B6 z9 w* _- j4 L1 l
- [导出到 Microsoft Office Excel(&X)]
% j& O; S9 R; {- \; b2 ], h - <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
5 B. A m0 F5 F3 \: D - [添加到QQ表情]
: O; ]. N0 [! w& {; ^" S - <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>- J L- \$ t: ]- N
- ==================================
- ^% b9 Y' @1 c' i* W y - 正在运行的进程
% R" c& Z/ Y% q, j - [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
/ e. ~& G: L1 {6 } - [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
. N0 } t+ J% ~6 X. ? - [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
% V1 f# p( P& e- H - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
& U4 E' {( [3 ?; x0 W - [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]% k; Z8 y' N, V( c, p' Q
- [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
) U8 \' i1 o, j - [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
# o( {6 A; Z+ P, v8 G, \; ] - [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
* A8 m3 ^" ?: ?- J* D x - [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]/ v. c- K( @ m f* V! l
- [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]8 ]# x+ {' {. g0 u: ]$ M; \
- [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]7 T* Q2 y" y- i* T! x# _
- [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]
, w7 T1 ?! y& ^2 T7 P - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
1 H! ]- S( R/ G5 p - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
. ?8 P0 e' i% X) ]8 T* J - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]& w) q3 G' N3 Z5 m& p# ~2 G4 a) r
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]: a4 {2 V* C* j7 V3 A! k) m
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]
7 @& |6 \ f, o$ f8 v* l8 j - [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]
$ C7 U7 ?0 d0 o* } - [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
' ]* g% y) i2 Y# \ - [C:\Program Files\WinRAR\rarext.dll] [N/A, ]# Y; N0 B$ ^( Z; u m
- [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]$ H5 P. f" E5 ^& V: M( k5 N
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
, x, j9 X$ B6 q9 d# P5 | - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
. B+ {2 [! C2 Y, l - [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
( p, @7 P/ @/ ]" B9 w( a - [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]$ a6 t, c0 B8 l7 t( U6 T8 D: t1 I1 ^
- [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]; K K5 }0 @" g
- [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008]0 [) q0 ~2 B& @6 B; {+ y
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]/ N5 S9 y' z# W6 p# {
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
6 q( W) W. q1 I; ]4 c! d+ b - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
, N3 A# J4 ]3 a4 c - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]1 u% g! H9 i* v* S8 B
- [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]/ v7 t \9 C6 f! h
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
% H L: n1 h4 ~; c - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]' |0 e- S: |4 J
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]" q. j+ X7 J+ T; a+ G& }
- [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]2 m% B% U& \# c: q- s9 i% |
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]
: l( z+ q0 a: i* u- g4 { - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]& j# }+ x: a, S+ q4 a
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]0 s7 Y( H2 R+ x* H! D
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]
# L( U9 `( H" q3 p. M/ Q4 D - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]+ {& D% B$ a$ T( [
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]. Z& ?: N4 N- C
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
2 u4 s$ R; o7 j7 ~/ D5 P, | - [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
" |' K9 S- r& C, T( C- r2 K - [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]
* h' ?/ z% k, x6 O - [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]7 V! c+ H0 c) i
- [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]5 }/ m6 r ?" V4 L5 ^
- [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]+ I* O' \! Y" B3 ?
- [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
( E6 w# g) N" _( T - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
- S6 t: t' U6 q& n - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
; ^! J9 a, ?' K6 B2 F6 P - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]( v6 S1 e7 n( W0 A( E, X) _
- [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]
: p, u& o: y/ \! [+ ] - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
. V0 I" t3 k0 T* F Q+ ]- e3 C$ Q - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]
0 Y, `: D ^) W& Q7 O4 z - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]3 {: n9 _& B# y/ E: J" t
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]8 \+ ?6 o; x8 c: r- {, B, y0 V
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]. J! {: C" {3 k" P7 k; E2 Y, N4 X
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78]
. x3 Q, c4 h7 G4 v# S - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
5 Z6 a5 p2 S! v/ M - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
. R- m# W& h& E0 l% A6 q7 U/ N - [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
, c( a3 h7 a( A - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
7 e! y3 x* U$ S( |$ |6 Q - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]+ ?0 P/ I. C: h
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]1 c2 B6 c/ G4 u" J+ V
- [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]2 g' e1 O( P# V4 P S. w
- [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]4 y; B6 H) D( M- i: x' C& v( u
- [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950]! r" i4 v( \+ g( J) W* G8 |' x9 V
- [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]8 o7 d p7 ^/ ^) a8 G; R
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
5 i" n3 w! D/ L' b - [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]: b L* W, D3 H8 o$ J4 ?
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
8 _* j. Q- }9 A - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]' E8 L* h( p6 B) J
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
$ W: H( D* A7 c0 M8 y - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
/ a1 f6 \& A) r, R6 M$ Z - [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]7 B, |; G% X8 u% ` K
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]+ |+ U2 e, m, {- B/ L/ c
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
& @# }: N2 s+ s5 z8 \ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]0 T5 A4 O S6 F2 L
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]( h8 c6 z0 O7 O4 P! P; A3 e) a9 b
- [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]
( ]+ q5 X9 n* @$ q - [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201] v/ }8 h" m7 d
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]! E q: y! E9 L: ]9 E
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
5 u, Z% P# f U8 I1 }! b - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]! C# Y h: p7 O8 N& g
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
! g5 \( G* V1 c @0 A6 c" Z - [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]' o; c1 A/ z% W6 P+ g4 p
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
) t4 j8 {( D* Q0 b - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]) { w( ~4 F$ V+ n' l Z
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]# i4 U% _: R8 R
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
( u. s- _% A4 ^% i - [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]1 l+ \% [" ^/ k1 _8 f
- ==================================2 o! \0 z( C3 y$ D) |& l5 Q, R7 Q
- 文件关联
1 l! ]' h$ t6 z& c& v - .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]. N9 ~( r3 u! J9 E' c$ M1 Z
- .EXE OK. ["%1" %*]6 n6 n2 h# u' X" S9 ^% ] ?- n9 n% x
- .COM OK. ["%1" %*]. w+ c& T; V4 r: z
- .PIF OK. ["%1" %*]% L6 X; N9 T6 W( K9 n: r( v' V
- .REG OK. [regedit.exe "%1"]2 m7 w) ~# A0 j" U# ?4 `! ^
- .BAT OK. ["%1" %*]
: s# C6 a4 v! M4 R% G i) R& ~ - .SCR OK. ["%1" /S]: \5 O; ~7 r6 S0 q- Z9 Z
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]6 }9 X5 M* R5 }8 W( G8 c& J% k, g: o
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
( G: n( K+ `5 _8 x4 c - .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1], L0 k3 ~! ^7 G( t+ N1 E
- .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
: w9 Q! l& V6 }$ s* e - .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
% }$ Q9 Z1 m5 @! C& A - .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]" P* I3 g% \" T' \4 [
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
5 J( [! p$ P' k/ J6 [! @ - ==================================( J7 N: ~) K7 m
- Winsock 提供者1 K R, q k- b$ g- |4 I: @; {
- N/A
% `# q& ]0 c' K' p/ A+ f* C; y2 l - ================================== [1 t5 A5 i/ w* u) g$ J
- Autorun.inf
4 z# z7 O0 X( N( l2 \ - N/A3 v& x. ~4 ~+ X3 A; W; P
- ==================================
% N* ^7 @# T4 M - HOSTS 文件
0 f. u0 e& F- v$ R3 y m - N/A# ~ e5 Y' I U/ C; L7 b, i
- ==================================' b. j7 ?- Z( h! w
- 进程特权扫描" I8 J% f- u/ C5 O: h/ L8 @
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
9 t8 j+ e \% U# ] - 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]2 _! `. m2 e7 t
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]
$ e4 d4 A; K; n) R& n# _; \# M - 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]
, B1 [; e7 D, }6 `, u6 E0 i - 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]
# |5 r0 Y1 b" d/ B! j- G - ==================================
+ S% a1 v+ g* g9 o0 ?# g$ |) Y, E - API HOOK$ D: P/ b% z0 t' T; U0 Q: I' `
- N/A
$ A' M5 v& |6 R0 W - ================================== t/ _' V3 X2 K, @8 p
- 隐藏进程
( U+ ?( G3 U2 R& W3 H6 ~ - N/A r# J( D3 D0 g; r* ]
- ==================================
9 M5 s# v- _% O+ A: s* x: T! u - 7 N: s8 n* K4 W4 s- I4 h/ `( W
复制代码 |
|