|
|
- [/ Y1 u+ z# c; H& C0 _9 T* b- 2008-05-22,20:37:43
+ ~) O @) B( B: u4 S) R8 u - System Repair Engineer 2.5.16.9001 {" T2 P3 l) m" f
- Smallfrogs (http://www.KZTechs.com)
^( o6 K4 F6 Z5 _ - Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能. @% ~" J4 t2 A
- 以下内容被选中:+ b1 v9 @' M3 I( v5 \! {
- 所有的启动项目(包括注册表、启动文件夹、服务等)6 G' j# v$ V& V5 X& Y5 n8 a
- 浏览器加载项
9 V& ~. f4 P% z - 正在运行的进程(包括进程模块信息)
x/ U$ F( V$ g: q7 Z4 b0 ?4 J - 文件关联
% d& a! g+ H# G - Winsock 提供者- A- P) w( a; ^- Y) w; c( n
- Autorun.inf
+ s0 o* @& e1 W' I* r+ u% o. w# p - HOSTS 文件
, j0 F+ a7 |$ M: l - 进程特权扫描- J* B P" s( F* w; `8 r
- 2 R, a9 Q2 r' g- f% k* _7 J
- 启动项目
: L/ S7 V6 m4 c9 K - 注册表* y2 v9 ?! F3 E& _! N# a* s
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
, X$ ~& C) `/ I) P. U) I# H+ } - <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]
2 h ]! I1 L6 k3 I. F - [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
7 ~9 V! `" Z9 L% Q/ S& |& l - <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]
) c7 ~. C% a4 q' ~! T - <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]; s4 I7 B$ w" a/ c9 m
- <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]" v7 [' p0 J* d1 X0 ?
- <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]- o; x" Y4 {9 Y& d9 _* j
- <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]
4 ^' \7 T# N) q% w- J' O0 b - <PHIME2002A><; > [N/A]& ~6 Z! Z+ J' R
- <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]
( A, a/ Y/ z8 Q! O6 [ - [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
: w/ {8 z: f- p/ \6 f - <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
' G( W3 g" \8 X/ q3 A+ M7 d - <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]! T$ @/ [1 Y5 k9 H9 b
- <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
( r9 G( s! `/ j" A - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
9 p/ _' |* V5 Q6 m O - <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]
, [+ m2 T" h/ c4 a6 B4 r8 @3 ? - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
# z* H$ c8 ^- n7 A/ `/ J* { q4 J - <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
- \( L# m; a% F) c; i4 m - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
/ J4 D5 g$ n/ T; H/ R - <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]0 J5 j2 [* W4 g4 |! t8 j
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
) r2 B; P. D* R# j5 z5 M0 w - <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]+ E! \) I H) l& _7 o T
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]3 m" x, b. X+ @! }& B$ }
- <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]1 G( |7 o: r, b3 c9 V3 _' _
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
3 q0 }) ] G6 Y6 L) H0 d - <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]
+ j% K g) f, h3 A3 o& A, h - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
8 e9 E2 \) ^' n B! @4 q* X) g - <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
' i1 L9 b4 j( b# g$ D- c, |' _ - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]( l# e- y: Z. G
- <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
# T$ f$ X( d1 Z: n" [ @ - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]' e; |5 e3 [2 t1 P- s3 [. a* a5 z
- <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]3 U; D* {' _% _0 u: p
- ==================================. K* m9 z- Z: ~& ]5 L, T
- 启动文件夹7 A$ L8 {2 f! v& C
- N/A
& |$ K6 b) l" I ?8 ~$ s. y - ==================================* Q/ l3 b4 O% e
- 服务+ S6 d; J# K5 ]( i; C6 j0 V6 x% v# N: r& N5 P
- [3ware Controller Service / 3wareSrv][Stopped/Auto Start]
3 ~0 ?" U! J4 s* N - <C:\WINDOWS\System32\3wareSrv.exe><N/A>( }9 [$ M- {9 ?+ M) k
- [Google Updater Service / gusvc][Stopped/Manual Start]! e- T' w) C5 O& W/ C, F, j
- <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>, S& e8 ^5 ^: i3 P$ p/ \
- [Help and Support / helpsvc][Stopped/Disabled]
5 Z! @3 k/ X1 m/ N4 q - <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>3 N* }2 k e3 W h! Q. R
- [Human Interface Device Access / HidServ][Stopped/Boot Start]
4 d5 J1 R! K) A6 O+ U8 n T - <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>0 a, @- a+ z3 V. Y9 }+ R
- [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]2 @, _4 T% b1 y/ W( i! A$ G* b
- <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>- b, N9 r6 n- V
- [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]$ I+ z: M; @9 ^' j
- <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>* Q! i- g. h& e
- [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
: q b6 V0 X5 D( g9 K+ F - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>; X$ P L! @; {* H% [$ U. |
- [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]
9 Z9 R- n+ X e. g: Z( v0 J2 m - <><N/A>4 o" G& O3 u- U( @9 s$ a- g ]
- [Qvod Terminal / Qvod Terminal][Running/Auto Start]
6 h" {: L# D' n8 \; {+ V+ ~ - <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>
0 K$ @9 \& ^% t E - ==================================) {/ K" T7 F; S; q$ r
- 驱动程序
2 [. d: c. a+ g# t! D7 N5 J - [22j / 22jn][Stopped/Boot Start]( \8 Q( v. B' `2 a' B5 P
- <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>
& U+ f* b1 t. H! A, v3 i; { - [360AntiArp / 360AntiArp][Running/System Start]
. k; i1 {$ ^% ~ - <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>) W1 X# B8 M$ `/ D* h
- [43ec / 43ecu][Stopped/Boot Start]9 w2 V) X8 }1 z( G0 S2 d( U+ ^
- <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>: u) ^( n; n" _* }
- [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
* L' n+ v! ^: _) r( M$ D- C - <system32\drivers\ac97intc.sys><Intel Corporation>' S, o9 j+ c4 c
- [Promise driver accelerator / bb-run][Running/Boot Start]
4 Y9 Q/ g; |) h4 g - <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.>
! K6 e, @+ B7 K$ q$ t - [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]( Y. C/ G7 z2 y* M4 e( ?
- <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>
/ K3 A0 q5 l: H& t - [KAVBase / KAVBase][Running/Auto Start]
{. N0 v, K, g6 I6 ? - <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>( }2 g6 c6 n5 _: x: O# F
- [KAVBootC / KAVBootC][Running/Boot Start]1 R! x9 m H" j2 Z$ ^4 }
- <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>0 y& H, z. _- }" c* }9 i e6 f9 _* ^
- [KAVSafe / KAVSafe][Running/Auto Start]
0 C: m7 ~4 U! w" e1 b/ b - <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>& S7 s* t7 b3 X2 j
- [KNetWch / KNetWch][Running/System Start] Q9 W# E& G- z0 \* ^1 N+ ~5 A
- <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>( V, b7 Y: z! a' X6 t/ z1 V
- [KWatch3 / KWatch3][Running/Auto Start]; g& x( x9 d' a1 N6 f
- <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>9 f: f) f1 N ?
- [ntptdb / ntptdb][Stopped/Auto Start]
+ T' W1 V. |/ k5 Z - <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>
- Z# y: p) G k t4 g5 G7 H - [nv / nv][Running/Manual Start]
0 ]2 A! l) u4 | - <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
; b3 I+ y# c- w# F( ? - [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]
4 f# S' D. t" T( s( [2 O - <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>0 p( s# q; Z' G/ c& U9 U
- [DDK PACKET Protocol / Packet][Running/Manual Start]0 T! e' a$ v7 e2 Z; V: e' ]
- <system32\DRIVERS\ProtoDrv.sys><360安全中心>
B2 S: M% P7 a - [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]
; V6 u, {8 x' z& X# ^ - <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>9 H- P, {2 f, J" ~6 G8 _
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
$ v! Y. D0 Q. @) n - <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>. L9 M1 K3 A: I& K% a
- [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]8 n+ ~# X/ Z) Q, [: `
- <\SystemRoot\system32\drivers\RsBoot.sys><N/A>
+ s$ N1 }7 e G9 w+ m - [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]# ]3 [; y" H9 A. g8 Q
- <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>6 | K* \ _2 u' a& N X
- [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]
1 N8 ^6 l' q# a - <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>
& Y* Q6 B, X: p7 A; X' t - [Secdrv / Secdrv][Stopped/Manual Start]/ Z2 Q4 ~4 g1 x1 a0 M' Y' e* n
- <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
! b6 }; P, l# _ - [SATALink External Device Filter / SiRemFil][Running/Boot Start]# H$ R5 r5 d) d" U! h
- <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>2 c. _1 ]8 z. A& x) Z# ~& w6 j
- [System Restore Filter Driver / sr][Stopped/Disabled]
+ [6 W" x M6 d! N8 p2 e( j% c - <system32\DRIVERS\sr.sys><N/A>
( O4 Q6 g, ?7 q1 } - [TesSafe / TesSafe][Stopped/Manual Start]
* Z2 D2 a2 W9 H- z# s! [ - <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>+ v' N4 G* ?. I4 \
- [System Services / unzxzsrs][Stopped/Boot Start]
( N- N+ a" o' K% ` - <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>' v+ W- ` K' s+ M' B
- [ViBus / ViBus][Stopped/Boot Start]
5 p" {) B+ d4 }) X* Q& C4 l3 n - <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>6 t# E# f5 B- p4 o6 ]3 h7 \- F: ]
- [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]/ y- r& k, B7 w! J
- <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
2 {# H- @3 ^" V# ^9 y - [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]7 Q- C( d: V# @8 n( \- _
- <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>
( s3 _& |! i3 O/ b" Z - [ATI Extend / zhibmaso][Stopped/Boot Start]
" I r# B* m! \' t) } - <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>2 J. F& `8 C. Z
- [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]$ n* G4 i* |3 Y) y" h
- <System32\Drivers\usbVM31b.sys><Vimicro Corporation>0 N3 ?6 D# o$ X9 C# O' X
- ==================================/ F) v) `/ n7 H* A. E
- 浏览器加载项5 g# `5 a% g* ?! X9 d
- [Google Toolbar Helper]
# w* a) M7 [; X4 \& I - {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>6 `+ h7 j) E8 u* _' X
- [Google Toolbar Notifier BHO]- a) x6 g. g/ Y
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
# \/ P7 Y6 ?" E, e! h! f) E - [SafeMon Class]( P4 L5 R) a0 y
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
: p( g- A; w3 c2 y) I0 \ - [kingsoft browser shield]
3 {6 e" h7 I& `3 u% ?: h; {: K - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
0 `) _# }; Y5 w! T# Z7 S: q - [IEBuddyExtControl Class]) w, k9 O7 f- h2 I+ Q+ ^
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
& J! G; t; U; F1 s7 \ - [Zcom 杂志]
: _' [( S/ E# r+ S7 ]4 B1 ~ - {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>: }3 j. ~$ `: T9 ]$ l4 v$ N
- [&Google]0 m1 `& v1 l* l' U% X
- {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>- \0 R/ P! A1 Q6 s; b
- [KooPlayer Control]8 \' ?2 R1 C4 g k( q
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
% f5 f) U& \- h; G/ ^2 K, g - [Shockwave Flash Object]- ?3 s D4 G( _) p) `) W$ |9 f2 O5 g
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>( P! {: J) B5 t% T
- [KUpdateObj2 Class]
6 Y7 g) L* J8 R# z( D! P0 G" q - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
9 q* P2 Z4 k) x9 [( P6 n - [Google Script Object]
) P8 @- T Y! H9 ^, T! W - {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>0 I$ q+ D; Y1 Y# z2 ^' w4 g# C2 P" ^ B
- [EWA Control]7 d. ~6 H6 z8 H4 B- y5 d# e
- {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>( t. W, K: [! d6 @& {7 h8 N% i; G
- [Windows Media Player]2 a4 j: o. I) G* d
- {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>
. x7 F$ W: Z4 K - [&Google]
& W2 w+ _9 }" V5 {" ~# p# F: @7 i - {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
& |( Z3 z, h9 {7 r5 @ - [HTML Document]
0 ^; o ~/ {3 G u, Y/ D - {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
7 |+ o& n8 K, E( t" T5 k6 E- ^7 h/ m - [DHTML Edit Control Safe for Scripting for IE5]
f% O) V; A, h5 w9 S - {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>8 ]. S$ h$ M* P7 S
- [RealPlayer RAM Download Handler]
( W, I0 e7 Y& A/ ^; @ - {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
, l" t7 L$ T& z5 J& L8 B4 q4 S! B - [IEBuddyExtControl Class]1 C* y$ |# d8 q! O5 D% ?: l+ y
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
6 r- g. _1 a( q- M2 x, n9 h( \ - [XML Document]
- B* }$ R) l# y. {% i5 {! K- R6 \ - {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
! w% z6 v/ }6 L0 s7 ?4 r1 x - [HHCtrl Object]% n# U3 s2 ~; k; H
- {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
' g5 m! l8 W8 [' P - [Windows Media Player]- H1 W0 T* s+ w1 \; i9 y6 {/ `8 y( n
- {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
7 Q' ]% X6 t5 D( y: B - [Active Desktop Mover]
4 F+ p# ]% \ D/ r- V% E* I: X/ l - {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
% \4 Y s* r$ p3 j. P - [360SafeLive]3 c: g3 X$ d: @. }$ `- J
- {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>
) c# G' A( ^9 f$ a6 k - [Microsoft Web 浏览器]+ b% k) X$ [( x# {7 X) N& x
- {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation># M8 v* L1 z+ p: G3 i3 k# z$ ~
- [Browser Enhanced Objects]$ P x% Y/ W' v" g! i
- {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>
) u* k8 v* F0 Z) `+ R - [Google Toolbar Helper]
$ u7 J7 Z j) G - {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>- q7 ?7 }. n* U0 d# e( U
- [Microsoft Scriptlet Component]
) ?- U; C' i% Y) Q0 A - {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation> n1 X4 j/ v4 `4 R/ R8 a3 T
- [Google Toolbar Notifier BHO]
3 W/ ~; o H/ B/ M6 r8 p - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>* K4 F' O* D z1 \1 C. y
- [SearchAssistantOC]
7 V4 T6 h, f- @9 y0 q. S' w - {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>5 s( [8 J: r$ L& h2 I9 E
- [SafeMon Class]" D) q* `& W1 T% b9 Q$ C
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN> q' h; O! c4 T9 s$ z
- [RDS.DataSpace]
/ o) L# I, I( y* Z - {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>' Y% O/ `* t% P. K, U s: u! `3 c8 z/ M
- [KooPlayer Control]* c4 r2 w8 c& l ~. d3 V
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
) B, P& w6 W* s8 f. u6 J - [AUDIO__MID Moniker Class]
6 ]7 S8 ?& |2 V" i6 W8 R2 l - {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
, M+ U8 f+ I: Z; h - [AUDIO__MP3 Moniker Class]
6 B, N" L' S7 f3 p - {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>) f+ [. K9 q1 ?. L' r9 C6 X; o
- [AUDIO__X_MS_WMA Moniker Class]
m9 m& `, J3 y. F a; w - {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
! o" [7 H& }5 Z1 P& D$ `/ Q. d; O - [VIDEO__X_MS_WMV Moniker Class]
* z. P3 ?, y0 `! e2 V. z$ F - {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>5 B# n1 z/ X+ }4 o
- [RealPlayer G2 Control]
. ~- t0 x3 r3 l8 I; M) D6 u' S) [ - {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
0 |2 t& C5 B! i# B& }4 d5 U7 Q. a - [Shockwave Flash Object]
4 r) q" }: u+ K* z& [% F8 @ - {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
|( P7 u! F- b: C3 Z6 e+ q8 q - [KUpdateObj2 Class]* h# Y- x$ ~! S; V+ a
- {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
+ `" R: E7 `' i# a - [kingsoft browser shield]
+ n# B7 Q8 ~7 V - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
% R# ~* H. n6 k- @" u2 P6 [" o: \ - [PasswordEditCtrl Class]. p, h: q n5 K* G# ^; w0 ^
- {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>& Z3 x1 {* S' ?- v) o& S
- [QvodCtrl Class]
% ^& t# o1 z) ~, V, ^+ {- y - {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>, B& o, e" n6 u6 C
- [&使用超级旋风下载]: O" @& G. h. V
- <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
: T7 W3 C( m, d" W4 o9 m# | - [&使用超级旋风下载全部链接]4 `4 x \& Z9 G; F- Q
- <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
c K' j) P: T - [使用迅雷下载]
* M6 ]# m% m) K& \/ \ - <, N/A>
& K% ^- w1 u0 \ - [使用迅雷下载全部链接]. |, O4 d& v$ O3 Y3 ?7 r, J
- <, N/A>
6 t9 j+ g2 Z: ^" r& J' ]- C2 { - [导出到 Microsoft Office Excel(&X)]
2 [/ h( A X, t6 V* [9 t+ b4 T, I7 R$ U. y - <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>: S. t: a( I% @! p' u2 N0 ^1 N
- [添加到QQ表情]$ c" h- ?+ ^5 T. M
- <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>" s+ \) u/ A H# l5 v
- ==================================# @$ B: @# p8 C$ s7 q4 V/ [
- 正在运行的进程; H# s( \- U9 U, P8 d8 T
- [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
4 p2 h' f8 B. E- F. l, G$ S# T - [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]" n" T5 y: A! X. i1 g( z% |
- [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
8 c5 j6 P0 Z7 j8 X - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
; r8 j* r: v5 |1 D - [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]' ~4 w0 S; b: D% `( l
- [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]0 b4 `+ R/ ?; L2 v+ r9 I( B
- [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]2 \4 A) Q9 l! N5 Y; _
- [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]! e: m: r9 G1 J
- [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]! M% }, O9 U1 E: }+ B9 y6 D
- [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
& A$ W9 \- G, y* u) ~4 c - [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
* i. Q0 a W# `. P - [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]% G3 Y" ?8 D7 q% v1 m6 [
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
( O( q: V& u: Y - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
5 O- e7 K) b9 s0 q9 _4 {+ T - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]# }8 L, e, R3 I5 ], o
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
7 x. L/ G- ~, `0 d, I6 `( S2 j - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]
& A+ d5 M }7 H! r. U2 L - [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]
4 `3 D R$ T r, J4 k- l- m' } - [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
; z0 x( O' @+ M - [C:\Program Files\WinRAR\rarext.dll] [N/A, ]
% F$ c% {& N* X" ]: \* ] - [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
) f+ [' \2 O, V0 R& c! g+ q! y - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
1 c; y' e- X' j3 l$ p - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]! ?( l% S2 N. ^1 F
- [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]) ^) `! I' B' j9 C( Y, l( L
- [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]
% Z2 }! _- F# x; f& I9 g6 J9 t) E - [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]
6 D6 F% O& d, r7 A0 w( n+ G - [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008], N; R2 R ]" ]2 K& o, M
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
; l$ K) K4 U3 L% T - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
2 F X' W# V+ d, J! N - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
- ^3 i% m; N! M - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
% a/ [& Y. O) O+ O - [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]8 s5 [ g1 E9 h/ U# B8 g
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
7 v% F: j% ~; G2 W% M - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
: G+ J) l- a8 P# e - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]* R! L, l6 e) s, |+ a
- [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]
/ D; _" g. q, c3 B5 H$ O - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164] }( Y" x0 X; r! x/ H+ t8 q- Q
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]3 I8 K# ] T. L- w' { m
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]' H u' l# @) o* f6 h+ G
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]$ B" R7 p6 B# r' R
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
H+ P& r5 d/ d" W9 g - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]3 U; M$ m& c) x. o& W+ p8 q# Y& d
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]" h d* R' K& z5 X' ?
- [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]7 z! {+ x! @# }3 K. w0 l
- [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]8 }' |5 p. T7 d. b* M
- [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
. }7 n, Q+ R6 j# e+ M% \, t7 \ - [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
/ L% O! m% F5 H. o - [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]! s; g, s. U1 Q' o+ K$ A* s" h
- [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]% O- N9 R1 L- {$ u
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]) w+ {4 P1 |# o* ^( |: n& x$ O
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]) H; m8 N( h7 l. E# O
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]& ?% D. x7 M. I. }8 }# y# L' Q
- [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]+ ?0 F; s9 s6 d6 h# x
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]7 N+ X! P/ z1 `1 i% p
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]
2 E0 r% R. B' _' g1 R6 [8 t - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]
$ `! \7 [/ q6 r9 i4 k' b7 D6 p - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]8 g4 U7 \. F- g, `
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]
5 \# c$ F, C" A% }/ E - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78]7 c+ O6 i; T8 K7 a: S
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]1 P& N6 n# B8 q1 U" E
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]' O2 | N2 e& z8 ]7 T1 X2 z4 [
- [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
& W- Z1 z( g$ C - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
0 R# E( t2 @' {& M. _3 z: F - [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]- ^* a! x v1 k6 {) K: a
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1], p; M% h U4 w
- [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]
, F' g. P/ \6 N& d - [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]. b" ], q5 y8 m& X: ?3 I
- [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950]
6 E% o# t8 {/ r - [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]
5 a, S) n# ~4 }! H& D7 h - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
) b' k, v& e0 b - [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]1 T7 n8 w8 h/ H5 c9 r" A2 W
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
0 O$ {- A% g3 p2 u! n; h - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]4 @4 E7 Q: @7 ?+ T7 U) \
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]0 K1 ` Y2 a/ y$ n9 G0 W
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]$ T. c1 ]7 N( U5 J% z
- [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]7 `6 r7 F; g6 z& Q% x8 u y$ ^
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]( g6 Q$ U8 p: K
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]8 i1 A: a$ z0 Y4 Z
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
8 A2 A$ j3 u' A1 R2 I - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]+ m" S! M2 W- G. x) f: i
- [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]
6 J3 F+ S3 W! g: q! _ - [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]4 K/ m: ^& }7 S' l5 P/ A
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
& e7 X+ y+ i5 {6 X6 r3 R - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]! p4 h2 u) A# e
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
9 D: g! n. i+ ?; E2 N" _ - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
2 [4 F5 \& W' v/ Q5 B9 q4 t' ? - [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]* _. E" o% q6 W$ t% s# g K
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
" K$ L7 l. S! ? - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]/ q* k1 B" T* s1 h9 X
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
/ s+ @4 Z! W* {: C. E0 Y" v1 C3 H - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
5 X4 I% t1 G6 i& F' K3 {6 i - [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]' M8 O$ X' `1 x2 v1 O. U
- ==================================. u* M; b' v1 m% l5 g: g, `% l
- 文件关联
) i7 T: ^# c& O1 ?+ Y# `5 i# t3 X - .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]- @' d4 J% v. ?8 m) V
- .EXE OK. ["%1" %*]; Q, @4 m+ l5 o" u, V* |( m
- .COM OK. ["%1" %*]
8 b+ n* P2 O" N6 t - .PIF OK. ["%1" %*]
# K' K4 Z+ S9 l# | i+ E" B; K& ~ - .REG OK. [regedit.exe "%1"]
8 U, T4 G) {/ ~ - .BAT OK. ["%1" %*]; }: K# j0 a0 R: U6 n7 e' I6 @
- .SCR OK. ["%1" /S]
4 _3 Y: A f# r- w - .CHM OK. ["C:\WINDOWS\hh.exe" %1]
2 D: g( o0 K0 P' W- t - .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]* i P- W5 e% l7 w5 a
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
4 V7 G4 K: ~: |: R# e6 H# ^9 J+ e( } - .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
( A: }& [7 B4 [* _% U# C" { - .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]/ F, m6 @" F6 O
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
3 n0 z, R7 A! _" g9 t) I) M - .LNK OK. [{00021401-0000-0000-C000-000000000046}]& C. i9 R. w* G7 C# O K# M
- ==================================: [1 v+ v% Y# W. u) r
- Winsock 提供者
. o+ x$ K0 j# L+ m a - N/A
+ n" r: ^( V* m; n' Y - ==================================
: X, ]' ^! }+ P - Autorun.inf
6 n7 m& \# w# @2 o, U - N/A
# K% M3 e" d, i( b1 q9 g t$ } - ==================================
5 f0 t$ \0 T2 l3 }3 A8 X - HOSTS 文件
( J3 b; C( d! B3 ]3 _ J - N/A' k! T* ~; {3 Z
- ==================================
) a* P# U% L9 a7 n& @( l - 进程特权扫描3 ~- g. S7 [9 n. k
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
2 J8 J) y, ~9 d - 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]2 B, B* T1 p$ \" E3 u
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]
8 z! D* c9 o: p4 ]2 k; ? - 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]
# L3 ^% W/ O: E9 |5 y+ i! V; [5 B - 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]. Y [0 m5 }$ y1 p- l
- ==================================
" X! x8 c- y2 f% Y" H - API HOOK
. x1 `9 t$ P% E2 N - N/A: }; S. M7 @; i$ U6 R* @! D, i
- ==================================
* z! G5 G) ?/ q+ @1 J! w - 隐藏进程& Q- R" z$ [ d( `: C) S/ `
- N/A
& @- `+ W9 X/ y2 c$ {8 i9 v - ==================================4 \+ V. Y0 }6 y$ n: B
- - w) z, b" }/ M8 H( B
复制代码 |
|