|
|
: z1 c% u- K0 B# f [ X5 s1 y- 2008-05-22,20:37:43
& |( V1 a9 q6 ~8 s- ~4 V/ g+ ^8 Y - System Repair Engineer 2.5.16.900
' ]0 \5 V3 g% _0 F0 q - Smallfrogs (http://www.KZTechs.com)
! T4 |* r# t5 \7 e - Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能/ D: Z. M O+ E g
- 以下内容被选中:# ]4 a( K2 A6 z$ Y5 R
- 所有的启动项目(包括注册表、启动文件夹、服务等)- o4 Q a! \8 T5 ?
- 浏览器加载项
$ e6 F; |# |# k5 V: n; l# x# N - 正在运行的进程(包括进程模块信息)
; {# q/ h& q( \0 Q - 文件关联+ V: s" l/ ^# Z8 o
- Winsock 提供者0 V A9 g) a A6 N3 s0 B; \& `
- Autorun.inf
: M$ `8 x8 u% L1 v8 _2 I - HOSTS 文件6 j' @) }0 g0 F' Z# q
- 进程特权扫描
" l4 L# j; a: k, X ~; l! `8 g - ) `9 Z! U; F8 r
- 启动项目
s$ S* f& p% r9 m6 `; i( y - 注册表
6 E4 q9 w p% A% w' z. Y - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
# k s/ T- Q' a* r/ O: e - <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]
+ h2 |' O: g1 ?- y# a - [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
. O e9 W) y$ a6 o# L5 W# _ - <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]. C6 ^ k m2 j4 [$ }/ w
- <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]; r2 V w+ z) V) }
- <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
& C/ |/ b# @7 ^7 v" m - <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]
; x t8 [7 |# U( V# {5 w - <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]7 d# a8 j' d: ~) D" t5 }3 N9 [ e
- <PHIME2002A><; > [N/A]
6 z: z1 d2 _! ] {" R - <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]
7 i+ |; h3 A! t; ^) q+ Z( `3 s. s7 L - [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]1 t( I8 s% C% n9 p0 M/ Q3 w
- <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
" \& O& T# Q" V$ s3 _# N* w - <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]
# V, }+ F9 @; j/ M0 \$ e6 P; l - <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
: G$ D8 Z( e2 n - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
9 A; M# M9 L8 V, y& {( t - <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]* `1 M% `& A0 O- f
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
+ Z2 h! u+ s# t8 |/ {8 {( G7 i - <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]" u, V3 A' J) L
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]3 B% o% g- r9 v! D
- <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]' I) D* S: S1 a7 G# ^. N2 e
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
! y L X! F* S, X2 e. V7 C/ ~" ` - <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
# R) ^/ [# d- Q$ E5 c - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
' C6 O" u" h. E/ l2 T, q - <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
6 V9 w& u7 A# j+ e - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
4 f8 P( O" _" N" Z - <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]- q7 i$ z4 Q# e& w( f
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
3 `9 x, e( `+ D3 \6 U+ ]- A7 H - <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
[6 o0 H+ Q: T0 h( t - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
( A- Q( K: b% L1 f6 m, S - <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]7 O ~: m4 n0 B) A0 L3 e
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]: i2 Y1 b1 b7 ~' b6 {( s9 g7 r, r
- <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
/ y* u& x8 p, C6 c' f - ==================================
+ g7 o6 q2 D# `! v - 启动文件夹3 N* k) N! g: f9 M( k
- N/A
' d7 I9 G/ p' e9 B' u1 G. h - ==================================
) V; P2 N+ Q/ [ - 服务$ C( r! j2 ^1 I, k- h9 N. h
- [3ware Controller Service / 3wareSrv][Stopped/Auto Start]# X" N. X! \ V# p3 c; D, N; w
- <C:\WINDOWS\System32\3wareSrv.exe><N/A>8 o) g$ r$ V- f# G
- [Google Updater Service / gusvc][Stopped/Manual Start]! P: }, s- {0 j0 n: {9 P$ M- P2 h b
- <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
( T+ j) f( u; p* D y - [Help and Support / helpsvc][Stopped/Disabled]$ M* _; M" a9 H/ x
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>
+ k; \! [$ P1 u2 { - [Human Interface Device Access / HidServ][Stopped/Boot Start]
/ w* y. Q) [; z0 A7 C - <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
. y( \, T) l, X7 x. w - [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start], ^ I: S0 Q% Q8 C$ t4 E
- <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>
: h+ j6 k* G/ F4 ]2 w - [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]9 |2 r2 b' B3 L* v, u3 [/ p# E* N
- <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>8 V2 u( t! K0 Q F
- [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
- j! m' m" R, Z# s$ f - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>$ F& Q! n0 r: S: s0 L
- [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]
( c6 A' k& V$ q" O; I - <><N/A>
1 S4 V+ F' C1 w% m# R. J& b% K - [Qvod Terminal / Qvod Terminal][Running/Auto Start]9 t& ?& X% G0 J
- <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>
- N1 k# K) D9 w& s5 x4 c) S - ==================================! B3 `9 P; G& _0 I; A4 I7 ~
- 驱动程序
: [0 F! @) R8 c2 U. S2 h# | - [22j / 22jn][Stopped/Boot Start]- s* q2 H8 `1 v& M/ ?
- <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>
6 u, L, Y5 e4 ^6 B9 R- {# o - [360AntiArp / 360AntiArp][Running/System Start]
* s- m; V( V0 q7 e( F4 r& F, M# b - <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
0 O! r' ~, e# ]. _& `' c, p - [43ec / 43ecu][Stopped/Boot Start]. F$ @3 N3 d5 b& R+ Q
- <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>
6 U$ P7 u2 G% r, d; o4 y% T2 d) L; t6 ] - [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
! v* y- K: F( \# k0 x: @ - <system32\drivers\ac97intc.sys><Intel Corporation>( }) O1 h6 |& ]: H
- [Promise driver accelerator / bb-run][Running/Boot Start]
/ r1 V( V/ Y0 h- N6 z: @3 B( e - <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.># b' i5 c+ x$ Y4 K$ n
- [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]
6 y- l- L6 N4 X/ J% v6 y# m$ v - <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>
, ^9 N; H3 L2 j% K- S5 v - [KAVBase / KAVBase][Running/Auto Start]
/ v9 u1 A% X% c B6 }% W - <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
5 ]8 Q5 `. F; x) }3 B5 b - [KAVBootC / KAVBootC][Running/Boot Start]( U7 _1 ]" A! i5 I/ O
- <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>% Q4 y8 k+ `+ A( o. A/ m
- [KAVSafe / KAVSafe][Running/Auto Start]* W+ x" u: ~- W* u
- <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>( X7 P2 `- ~( |, [- C1 U" ?2 s% i
- [KNetWch / KNetWch][Running/System Start]
- i# N( q8 ~8 r3 G! |( }* K. b4 `4 M - <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
1 \7 ?- S7 e4 H, V3 b - [KWatch3 / KWatch3][Running/Auto Start]
8 g/ |0 E0 ?; q8 J, [. C7 j! n - <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>, }1 K( Y8 `+ C7 ]' S; X
- [ntptdb / ntptdb][Stopped/Auto Start]
- g9 P6 E; V$ |* c0 A - <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>( T0 V V& ]; p9 S7 V
- [nv / nv][Running/Manual Start]1 W8 g5 U3 }; U) A# A+ n
- <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>9 W5 @2 C% B7 d6 i+ k
- [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]
* J8 ~# c- y/ }9 b1 w, g - <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>0 m# x" c- G3 N0 N' z
- [DDK PACKET Protocol / Packet][Running/Manual Start]
. [1 C5 ?( y! d2 G6 k - <system32\DRIVERS\ProtoDrv.sys><360安全中心>' m$ U, l+ K& {- S& {) u& @
- [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]
W9 ^$ {3 e# H" L/ R( ]0 z- ^ M - <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>: V( N% {2 l& ]# P7 a( q
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]" ?, t% @4 J; ?% \! Z1 e
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
g, }; H) n, n7 n" c8 s0 u - [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]
* P R" Z C- I: q( i$ `, ` - <\SystemRoot\system32\drivers\RsBoot.sys><N/A>
4 ]" i+ @$ R; t* S+ A - [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
. z# T! Q3 y( f) M - <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>8 {8 n$ C) k4 R7 n5 p! { x7 j
- [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]) \* K# R' m/ T; x# w3 Z
- <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>
{2 Q6 ~7 s- n- Q1 Y; f6 u - [Secdrv / Secdrv][Stopped/Manual Start]
8 k- q1 j1 o; W+ [* L+ C) L - <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
/ P# S5 ~ Q/ f& I! Z - [SATALink External Device Filter / SiRemFil][Running/Boot Start]
) d+ Q& ~* z4 N - <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>
) j+ Y- m6 a- t/ P6 `6 [* x - [System Restore Filter Driver / sr][Stopped/Disabled]
, M$ l! e# K% q7 Q# { - <system32\DRIVERS\sr.sys><N/A>
~. d& u& T$ W/ `/ | - [TesSafe / TesSafe][Stopped/Manual Start]' i' g2 l! Q1 q
- <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>
' G T& Y5 c* {. o( Z - [System Services / unzxzsrs][Stopped/Boot Start]8 ], w+ o9 m% u& d8 ^( a b
- <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>
* K6 W3 ^1 R% a9 ` Q& m - [ViBus / ViBus][Stopped/Boot Start]
! e4 _# ?9 ~; W/ T L: Y2 E - <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>
8 b2 l* E4 b: v# s- q E- D$ W - [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]9 A4 ] B t1 A3 m, z( z& J
- <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
1 _ N* }5 g/ P2 M - [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]7 F" Q' c3 G$ q* e, ]5 u
- <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>
) e# j, ]& `$ z7 e - [ATI Extend / zhibmaso][Stopped/Boot Start]1 Y- {0 V! d% w( H6 L/ T7 j1 h
- <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>; t8 e* B8 q {; p
- [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]
, X: x( v( g- o, e. B7 t - <System32\Drivers\usbVM31b.sys><Vimicro Corporation>. |5 G3 b) G/ f4 G: U
- ==================================
3 V, e; J8 D; Z! \1 O C ~/ ?! I4 t" D. | - 浏览器加载项
6 ?$ p. w; ?. d6 Z - [Google Toolbar Helper]
( G. n* ^$ j0 a - {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
2 B( A6 `1 ^* K- s2 _' ^* [6 Z - [Google Toolbar Notifier BHO]
$ a9 U3 e+ Y- V' g( I" s$ d3 A - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.># |* ], p- w* T
- [SafeMon Class]5 g9 {$ O4 g2 s s) e9 k
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>- y% r: J1 W# Y
- [kingsoft browser shield]! q- b: X) ?2 D" g
- {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>) _( _" D6 ]/ x1 v
- [IEBuddyExtControl Class]% c% w; X- @! k b0 ^
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
( `1 ?; `( R" }, | - [Zcom 杂志]/ a; k8 X3 d L, A
- {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>" }6 K8 O/ ~5 n' Q2 P/ c
- [&Google]
* Z- o) J6 z* {4 n0 A& p9 x - {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
- D3 E$ @" K8 ]2 t: V- [8 ^9 I' ? - [KooPlayer Control]: b" P2 V" w! l: y2 {
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
; ^: N+ w+ @2 k( |" X1 q$ e! [; W$ W - [Shockwave Flash Object]
8 P6 D# S' V* m! A4 I - {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>9 X5 ?5 `7 U; \
- [KUpdateObj2 Class]8 f8 z6 X: X6 }3 c# z
- {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
' Y' J: T; `7 J4 V$ T* g - [Google Script Object]" {( L* T, \' U& H6 [
- {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
3 ]+ ]5 i) D2 v. e: ` G - [EWA Control]1 ^! i4 e$ h! w% \
- {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>
1 N( [; q( X! x; s: w; I% T1 { - [Windows Media Player]
0 M$ Z; T& T- t O - {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>* @) l5 |" i: r! y3 J
- [&Google]
8 U" X0 r% t! ?; {& |6 ^ W1 ] - {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
0 z- U. g8 q/ O2 ]! A6 v G7 X/ ? - [HTML Document]/ q3 o- D5 z9 u
- {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>( O% ~9 c/ l/ n* D+ e
- [DHTML Edit Control Safe for Scripting for IE5]
3 {3 W8 N% D. W5 L1 b - {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>; O5 {1 e+ J6 m
- [RealPlayer RAM Download Handler]
0 L8 E% [. G. F- P8 @ - {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
" R9 E5 P" Y5 O6 W - [IEBuddyExtControl Class]
' V7 u7 G; V9 H" G3 k6 R! t - {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
) p# ^% W# @7 A2 i' Z. H" t6 @/ f - [XML Document]- Y! @8 W/ |/ O0 \0 v
- {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
# E, f" C2 u2 q/ \: `7 t - [HHCtrl Object]
9 d# r9 B2 k: d: Z - {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
Z5 R- b) d, `( W& k - [Windows Media Player]5 h% Z$ ]- B2 s4 M2 Y
- {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
9 Z5 K# ~: g4 c, t( P- g - [Active Desktop Mover]) J! Q. a" q2 \4 h5 P+ V! u
- {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A># L+ c0 ~. R- X
- [360SafeLive]4 L$ u- `2 g; L; F" h7 B
- {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>: B2 w0 J& L: m9 H3 V6 d& ^" B! e
- [Microsoft Web 浏览器]9 z- E2 z" K4 E- X5 W
- {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>: j+ Y2 o/ |" {9 }
- [Browser Enhanced Objects]3 Y$ @- h; I4 W3 u( u' k3 c3 R
- {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>
3 C: G4 ?, F$ o/ {9 g R+ b9 f - [Google Toolbar Helper]9 u, _/ q3 K9 f6 {9 n4 ]# W
- {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>/ [: [" w4 h$ z. s* K" X, X( X% l' P
- [Microsoft Scriptlet Component]/ N0 I! N7 L4 i. B9 h# q
- {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>; W8 ?& m/ i& [; d9 R
- [Google Toolbar Notifier BHO]0 |7 W7 W! [3 R: Q- }, O- q
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>6 m/ Z u) g2 S4 ^# S7 D
- [SearchAssistantOC]
0 [% V1 ^0 N# a- r - {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>) ^5 d2 y/ n% V6 {: T2 a
- [SafeMon Class]8 n- b2 F+ u5 i/ g; k- \! W2 n# V
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
5 o5 _ ]" U! D! Z, x - [RDS.DataSpace]' n* g" v. q9 l8 r0 e/ Y7 i
- {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>% M* s$ b6 {; M) N* D, R8 R
- [KooPlayer Control]" A. M( _: a7 B' Q. _' @! v) K
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>; \5 T6 j1 U7 G% }
- [AUDIO__MID Moniker Class]9 r: d' c5 B+ K
- {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>/ A, l# j/ T6 l8 N4 U0 {; D
- [AUDIO__MP3 Moniker Class]
! Q# B* Q$ B& ^4 r: A - {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation> v8 G4 ?/ s% D. o+ S% P
- [AUDIO__X_MS_WMA Moniker Class]
6 I) P- F N$ o0 l! w - {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
, M' @" ?' k( ^' U- U$ @5 N7 u - [VIDEO__X_MS_WMV Moniker Class]
8 [0 U% Q* \8 N3 X$ R" g5 a - {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>' E5 b T" F% b3 ?; _
- [RealPlayer G2 Control]) m# M( t. O1 P! T! X% t# ^
- {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
& d: _' u4 e, T1 w& | - [Shockwave Flash Object]
5 ?6 f" P1 E- \4 p. |5 Q- O Y - {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
! O! B ? L% e6 x$ i0 W; J - [KUpdateObj2 Class]
+ ^- F; @( | K" ?4 v' ]3 w - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
2 @% r9 Q; S4 }! Y* e - [kingsoft browser shield]3 J" ~& T0 U) F6 |
- {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
6 o2 e+ a6 j2 g# a* A$ E - [PasswordEditCtrl Class]
% Y7 t4 @4 U* ?2 m! x, G' U - {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>+ A: X. [% s2 a! v& J- F
- [QvodCtrl Class]
- \; k7 \. m; H: K$ b - {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>( P0 S) U, l3 a( [: V8 S2 W
- [&使用超级旋风下载]. }6 J" G3 `" M# l* s
- <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>; o& C8 W& l, x) J2 G# Z
- [&使用超级旋风下载全部链接]1 c0 d& r% f: V& j9 q
- <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>" F1 m$ Z+ _ T
- [使用迅雷下载]7 s7 h1 p0 b0 I4 ]( b
- <, N/A>
i8 S, W y5 M7 O1 b: \ - [使用迅雷下载全部链接]
# |+ q( L6 P; @! L - <, N/A># k- g0 ?/ Z g5 j, r9 r/ s0 X$ x3 c
- [导出到 Microsoft Office Excel(&X)]& v7 K7 x" b7 P- f" _
- <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
6 V2 Z" [. E0 J- l1 t" _3 T) H: i - [添加到QQ表情]0 k9 h2 S7 s" v w/ _6 `: y
- <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>, q0 _- x4 }) J" T0 A7 v
- ==================================
; x4 C( O" g$ j- U$ M% S0 d - 正在运行的进程
7 L4 }! k( g; k4 I3 P# _3 w8 r - [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
; z! `0 O8 V- z# t - [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- \5 o( m/ A4 ]/ Y - [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
6 g! C5 }. M3 f7 d5 h9 y( D - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
* q' B" D4 c. S) a - [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]' E% B; k. d+ i& E
- [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
1 [2 m! t" }; q( C2 p$ D2 P6 C% }* h5 B - [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]6 q: q6 Q, R3 u# j; V
- [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]+ I7 t4 ]' T! I) L8 t
- [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]4 N& u3 _& s0 b0 ~
- [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]6 l8 S$ J& S) K6 P, u, Z9 P5 L* Y
- [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]; }1 ~: r$ L9 B3 s
- [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]$ g! o: l) F/ [# f3 Z
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
9 A4 s& {& D$ H: V - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
' W: @$ e- \" Y- b% L0 ? - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]- s0 R6 k& ]* [
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]) U- q6 ]/ V. n
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]6 { K/ k% ^% j0 G* A& |8 O/ k7 t
- [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]& ]& `- G0 T2 h
- [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]1 N( ?+ c1 _ B; _3 J. S
- [C:\Program Files\WinRAR\rarext.dll] [N/A, ]) n" {0 v$ K4 T" g$ N" t
- [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
4 ^ Y3 c7 h# c; Z/ R0 y! ~) V8 N5 p - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]- E; {8 p/ l3 _; O- J+ f- {2 \
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]8 x0 W5 u9 h. I, [" _
- [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
2 n- [- i( K5 o. J/ [ - [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]
; o* Z( K& Z2 i' T% O$ s- `8 C - [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]
0 b" i/ c) j) b; p - [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008]) s+ i7 r% `9 N2 _
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]' w8 a( G9 S2 ^6 B
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]: j6 \1 U. a5 e* Y3 P
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
j7 {8 B/ D' W - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
0 Z- u' y/ S! p9 @ - [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [% A$ J7 N" ~# o6 f/ P - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
9 w' z: h" e, o5 u" [) Y - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
% b3 R6 h! \. |6 |/ y- z - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
- f7 Q3 a$ ~, d3 U - [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]
) S" v7 Z A4 g; w - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]
6 U, }# E/ g$ x% g' V* Z0 ^& k - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]* p" u, f3 I/ S. t2 q6 P1 M
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]$ ?2 R7 F# b8 @2 z
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]
$ }' B; w& U! G4 t3 a - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
2 w# r" f" ^0 l6 ~4 S) R - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]0 G1 a1 R7 q" l; c
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]; D" N% [. K W
- [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]( y0 h4 m2 F2 E; z
- [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]3 n Z! d( w3 h H
- [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]1 r1 {! b0 ]" {) k
- [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]$ ?- n5 [5 g! ~& h6 t- g, y- j
- [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]" A `7 Z" {7 }6 Y# ~$ g' p
- [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]' e1 |6 k9 H6 \: ]+ @5 d7 f2 A
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]1 [- q% @4 U9 \: [2 N* M2 e
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]6 |, E( \% e+ R d0 i' o9 q
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
2 k. [5 C5 _4 \5 g - [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]
' z, V7 a0 P! Q - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
1 i$ L& H2 F7 G, }# w c' X. R. | - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]
5 G( ?0 t6 |' B - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]
! M0 }* J0 S& d Y - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]
& T6 h' t; S8 N- f. v - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]
2 |1 l- Y9 r& Z' }+ S/ b, E - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78]9 G$ W( a) m8 _& \$ A
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
# h o0 T) c! z! Q; u7 d1 t - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]; B3 }, T/ Y; k: `2 ^
- [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
7 ~1 M; F+ k6 M5 p - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]% E% z# J+ `% I* U7 h2 u6 u4 ~% H
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
: Z5 w! Y( v5 P: }" o - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
8 Y' X0 s f, Z2 W8 C - [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]
: f" I) [$ Z1 J2 K' G - [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]6 Z9 w b2 D/ Q1 Z
- [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950]) {3 T% V& _1 P; n1 Z
- [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]( F, k0 t6 B' J
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
5 Z M# y- h; @2 ~, _& P& J - [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]
2 ]! S1 O& g3 ]# N7 ]+ Q9 G - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]% ~3 }7 T# Y, D7 H( L
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
; g( u% N4 g! E6 n% m9 b - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]/ @; U3 ]2 |8 \; O% `( b- v
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
$ d) J% R# `) v& h/ r - [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]
! ?, F) M# {: e3 F- ? z5 b6 ^) e - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
$ n2 G" x1 J: _. _ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]( E$ {6 r/ l0 I' Q% h7 E. M; C
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
# G: x: l3 L4 @. W - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
1 R$ W* O6 M( ^' x - [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]1 I# @" z% k3 R, ]; D8 j
- [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]
& D* w$ g- r- |/ g6 b( \- t# K - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]4 h! ]5 K7 }, B' Z
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
3 n1 J+ x- [; k: K - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]. u9 G5 B/ t! d- o/ F( ?9 V0 [% o
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
% U5 T/ G1 b! p D3 ] - [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]4 q. Y) L5 {, V2 e3 y B
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
+ @/ |/ q7 E! h: U% y! i - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]; R& h% h. s6 z6 d7 i
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]; ~/ a) K2 L9 H; o
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]- n5 \& q8 c" E$ N2 R0 l. K
- [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
! G+ R) S' {* y X' a3 i - ==================================
/ b# P. K/ m) E - 文件关联- u$ t: U8 s# l3 g
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]0 B$ ^) d, I( I, Z7 I# c
- .EXE OK. ["%1" %*]
! K! Q" h6 ^- G0 R3 v6 d) I! m - .COM OK. ["%1" %*]
1 C: Z- H$ F- T7 i! h- a - .PIF OK. ["%1" %*]
' U2 B7 n& l/ e- N: G% g - .REG OK. [regedit.exe "%1"]
, o* Z) m! C3 E( x' Y" b - .BAT OK. ["%1" %*]
+ h5 O7 y9 F, c' N: v6 C, V - .SCR OK. ["%1" /S]( {- Y+ H8 U+ C) P) P0 B% w
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]
. @4 g' d& z/ Y - .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]9 h) w: U3 G+ X/ S4 D
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
' [ z; K' ^& n7 v* m - .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]# u' o |% d0 w" d0 q9 X. W
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
b p2 o* n+ K0 M% \0 q - .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]7 x. x$ W2 V, r0 H9 ]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]: U$ L6 Y4 }1 k9 U
- ==================================
9 ] n" Z( {7 f1 K# g - Winsock 提供者
6 x& J. r' t7 l# K- | - N/A5 s. Y' T8 q( ]. D1 ]
- ==================================
# I) _! E0 g/ m* }, p; G - Autorun.inf
8 N, g8 o+ |* c9 s5 n7 U) t - N/A
7 I- F7 R; u* g+ W- x1 w# Q& o) r& O - ==================================" E0 P# i" e" ?! f6 J) ~" c7 v
- HOSTS 文件
2 m2 W, }/ F, W - N/A0 H/ A5 D8 f s
- ==================================
$ x/ [' L! U& w - 进程特权扫描/ z0 r5 B- [3 ^0 a
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
+ b& h" p$ a* D% h; A9 v4 h' } - 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]
; a3 n, v2 i( d. j7 M - 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]
2 \+ M* d0 Y! _- T) }& _ - 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]' d* ]3 B0 A$ B9 t
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE] z) |& S3 ]; { F4 ^5 {! Z
- ==================================
* D- M7 v2 i9 J - API HOOK6 D0 ?+ A. W n' `9 e9 W3 R, ]6 u+ l
- N/A" @- L3 L: T$ V3 U8 e* D' m
- ==================================2 j2 L6 S* \1 ~$ z8 t
- 隐藏进程
' E3 I0 |' ?1 r; B) ~ - N/A3 ]' \1 F) y) b) ?- r
- ==================================
9 x* n; r: q9 x) Y7 }1 }. V - 5 S# w- `% ~" B3 b7 P
复制代码 |
|