|
|
- , ?+ E: |, L) a
- 2008-05-22,20:37:43
9 D+ S1 S {4 n$ e$ g$ F - System Repair Engineer 2.5.16.900) c) b/ C. T0 l/ A# r7 S+ y
- Smallfrogs (http://www.KZTechs.com)
5 V& ~, \, i! _ - Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
( n3 e' A: l; X# J9 u: G - 以下内容被选中:) S3 L4 \9 S3 f+ E$ K$ o3 W
- 所有的启动项目(包括注册表、启动文件夹、服务等)8 _# e v- G# i" L% r$ C. {% S
- 浏览器加载项0 _8 y I3 z2 k3 y
- 正在运行的进程(包括进程模块信息)
2 ]' e& B" {+ ]' U - 文件关联
- O' k3 \$ f( M" e u& d( G - Winsock 提供者0 j1 l; X5 Z1 U3 H
- Autorun.inf. B5 E- b- H$ k) L; H) P+ y
- HOSTS 文件
4 x3 M+ p% K% @ - 进程特权扫描# L$ u5 \3 z, t
- . e% F2 B s q. w8 b
- 启动项目1 T" h: ]: h' A2 j5 ^
- 注册表
* @' `/ n* \4 f* U$ v" \ - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]* x9 d3 f. p$ r g( F
- <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]
/ {% ?' D8 r) m( k! E - [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
! G* ~9 N% Y7 e& y5 D' S+ g - <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]
6 E6 P* \# T$ V - <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]' D# r- O! U5 j" H
- <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]0 | Z+ Z4 Z8 z" Q" Q
- <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]
: R7 q$ a3 G( G7 \/ }# e9 @3 m - <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]
. Q- @& [( m: T3 Z, N1 N% W; [ - <PHIME2002A><; > [N/A]
1 q& e1 G5 x# l' l# [ - <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A] y; G* j1 Q- d
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]8 n* o* p8 e! M, ^ b# q
- <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]' Z' F' z* A4 _$ i2 n
- <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]5 s! _' a$ z- X& d3 `& u/ K
- <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]/ ?: r# z! \2 _1 {: B/ R& w
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]! R, J7 l' O7 h0 e
- <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]% e* Z. f. z( b% ]) o' E. {$ H. q
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
d; Y& q/ J" I( B# [ - <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
- [; B8 k6 O5 V! ^% ^3 c( T( s. e, M - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]* O6 e6 R+ H# X6 M0 f2 N: b: Q" `: o
- <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
" z& g4 H2 \ Z; R - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]- T0 F U# X7 u8 D+ ^
- <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]2 Q6 }% |3 u+ c
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]2 o( m# R/ N. \) ~
- <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]) I. i8 {/ @) }/ q
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
& P0 n4 [, G. z8 a1 O# R - <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]
! o5 I; A. P" U' g3 a- e1 w7 H. { - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
) a) O" s. X- `7 n! p6 j9 [0 r0 L& _ - <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
: |8 h5 f. E: | - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
% z- g0 L& B+ l' `( `4 T - <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]2 v% r. | K2 } A) H/ y. k
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
9 T/ X" A4 S/ k3 J' R! ?2 z2 p; N - <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]; E# F1 Y) v x$ ~( |* J+ ~" z3 q
- ==================================
) O; E5 Q" @% V0 g5 H) _# j - 启动文件夹0 b0 G; z& D* F- p' e
- N/A
. B: A" K: W2 r! M; s) _- M0 A' ^ - ==================================
0 A7 H% n/ {2 {- T. j - 服务3 K8 T2 l: p# n l' e2 e' j% n
- [3ware Controller Service / 3wareSrv][Stopped/Auto Start]8 |- X; J \6 Y5 W
- <C:\WINDOWS\System32\3wareSrv.exe><N/A>/ D4 w( Z( _2 r# A5 Q l+ X
- [Google Updater Service / gusvc][Stopped/Manual Start]4 u+ x J; U: l9 K5 U
- <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
/ f, F( {5 L3 w- K' H7 `. T - [Help and Support / helpsvc][Stopped/Disabled]* I9 U' ~% B6 S
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>1 n5 x! _+ G; t* i
- [Human Interface Device Access / HidServ][Stopped/Boot Start]
" C0 @0 f5 x- x - <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>. H1 q p5 M1 h( x
- [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]9 E+ Z1 E* f" W( p
- <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>
& i6 H, m: f, T2 t6 ?, `/ B! G - [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]" s- r; ~+ W9 L+ ^
- <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>
3 i' C) \5 f, q3 ?3 u% ~0 L - [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
( Q2 H! j3 d) e( \( b$ J - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>3 ~! ~. f" `# h3 V
- [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]
5 m$ l. D! [$ p! W) t o - <><N/A>
) M9 v8 H! M# s% i - [Qvod Terminal / Qvod Terminal][Running/Auto Start]
* P6 W+ r' a5 v7 O5 B - <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>" W+ z) |& s" b; L# m* A' [) Y
- ==================================: R4 t1 t! X& Q$ ]
- 驱动程序
* f$ e2 ~6 s! p; O( K/ r% O - [22j / 22jn][Stopped/Boot Start]/ d X% u8 |# A; I
- <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>
$ m! w. U, N L! w/ o - [360AntiArp / 360AntiArp][Running/System Start]" \" v+ a/ C$ l7 g) \6 _+ ^
- <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
, V3 A ^) k% Y4 |7 q" y. E8 U; s - [43ec / 43ecu][Stopped/Boot Start]
% C7 z5 o; O% O - <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>
. e& K" R3 `+ A4 l% D% K - [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]- `# o; T: J/ b* e* V5 n; |/ [
- <system32\drivers\ac97intc.sys><Intel Corporation>5 X; k- W9 ~# @" D! H+ \1 @. r
- [Promise driver accelerator / bb-run][Running/Boot Start]; N; U; u$ D1 m* q1 t
- <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.>- J8 `5 I0 B8 u' G; M% t
- [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]- p6 l! ^1 O% c P
- <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>8 O6 B# Y; Y4 y3 \% ~3 O' T
- [KAVBase / KAVBase][Running/Auto Start]
/ I7 x0 L! M+ p3 C0 \* C - <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
2 G- E9 P! ^8 g; n - [KAVBootC / KAVBootC][Running/Boot Start]+ c; Q9 K/ J9 J/ O9 |& |6 T- W6 E
- <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>$ e' K( H5 z- o. `$ @2 Z2 }
- [KAVSafe / KAVSafe][Running/Auto Start]
# f' l8 S% Z/ n. N8 E9 b - <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>
6 W2 h+ J8 D* K - [KNetWch / KNetWch][Running/System Start]5 x; O$ |0 t5 h. l) T( H% \# j
- <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
* t- ^- L9 u) v6 W" t: {& y9 C5 M* @ - [KWatch3 / KWatch3][Running/Auto Start]+ u: o+ o9 O* x
- <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>8 |" W. J; I$ G5 v, z
- [ntptdb / ntptdb][Stopped/Auto Start]
8 G2 ?4 B- E' y! L: q - <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>9 {7 g) X+ S, q' _) O4 `
- [nv / nv][Running/Manual Start]
- ]6 c) [# o! | - <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>+ p+ L5 Z f0 V( T+ f
- [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]
5 i9 c( o5 d' d P - <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>" D: k' [" I* s) s/ d" k
- [DDK PACKET Protocol / Packet][Running/Manual Start], S9 p; ^& T) Q% c' L
- <system32\DRIVERS\ProtoDrv.sys><360安全中心>
; P* d2 y* e6 Y' b. n* @ y [ - [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]- h6 u! x& d' u: u7 O' W
- <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>
% _. m' J. Y* L! K - [Direct Parallel Link Driver / Ptilink][Running/Manual Start]' w" g9 N N7 ]4 q/ v
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
9 h* E4 O! |9 {& j V - [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]
( F0 F# Z* A- h' d& ] - <\SystemRoot\system32\drivers\RsBoot.sys><N/A>
0 _1 E2 o0 T7 Z# e7 ?( Z/ C/ H; ^% r - [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
- i) r6 \0 C8 i+ [% n/ H/ M! _ - <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
$ ^- Q; w/ M: f! `9 L) `+ m - [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]) a" E& }; ^/ g$ s) m% Y( q
- <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>
' o1 ^! ?' X. g - [Secdrv / Secdrv][Stopped/Manual Start]
" b+ O4 V/ h- W6 W4 n, i - <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
% i" y! V( X# i! X$ ~. T6 J - [SATALink External Device Filter / SiRemFil][Running/Boot Start]2 \, e/ k: y$ S a6 {) t
- <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>
1 }( D @$ M+ F5 t - [System Restore Filter Driver / sr][Stopped/Disabled]2 ?; G2 \ T. z: l
- <system32\DRIVERS\sr.sys><N/A>
4 Y4 x, s8 @; Y2 K3 | - [TesSafe / TesSafe][Stopped/Manual Start]7 k- D& g8 U, R/ e4 ^
- <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>9 ]* |2 Z! A+ i; G$ U8 f
- [System Services / unzxzsrs][Stopped/Boot Start]
, V8 @5 o4 M' e9 X" l% a2 O- u - <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>
+ b2 N$ _# l: l r - [ViBus / ViBus][Stopped/Boot Start]1 B! H! W; W& O" q) u9 _/ X E
- <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>: I2 o" k7 Q4 K1 I: p- r1 c
- [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
6 l c2 Z4 W" J0 } - <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
" c0 ^* m2 D6 l: { g; Z( k6 { - [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]
+ U/ s+ @" S" l" ] - <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>( X2 m# y R6 |, k' }
- [ATI Extend / zhibmaso][Stopped/Boot Start]! G2 D5 V: D0 F( V6 @: I" `) j
- <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>
2 }4 X0 ~- y; l4 b - [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]) {, ]# g2 h+ H
- <System32\Drivers\usbVM31b.sys><Vimicro Corporation>
& {4 H! c1 e, c1 ^ - ==================================
3 J0 a+ z9 @- e3 p o8 A% @ - 浏览器加载项
# w& M0 }8 y6 \3 P8 l - [Google Toolbar Helper]
+ q6 @$ l: c0 ^5 f - {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>: @( ^; `% A- L' U# A$ [. c
- [Google Toolbar Notifier BHO]3 s* Z' m: Z) B7 A# L
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
" [! ~( N( q) _6 h - [SafeMon Class]
, i6 n8 z7 e& |: \, Q, g( G+ L! o$ O - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>% C# ]8 u! j. i! z; l4 `
- [kingsoft browser shield]( f5 e1 L$ ~) Y- S
- {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
9 Z" k' c3 q2 y, U3 I" y* ~ - [IEBuddyExtControl Class], K2 E' V; L* x5 v1 u, i1 y
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
: I* f; R+ |* @: F" n) Q1 z& g - [Zcom 杂志]
8 y% `# T8 u9 F$ k4 K8 J - {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>
. D; q! l M1 X) Z; S - [&Google]& `9 Z: G" C9 ]6 _
- {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
R+ v5 n; \( ~ - [KooPlayer Control]+ @( Z! I* C' b p
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
! C( [ D0 _8 Y - [Shockwave Flash Object]4 ]+ i& b& J7 y _
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
1 I5 \" I# U! @ - [KUpdateObj2 Class]
, \' ^3 c5 g7 M5 ?- h" F& N - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
) D& D" i+ O& w5 X/ f2 D. e - [Google Script Object]. l5 |* r6 {# G& h5 \
- {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
0 y9 H" @6 `' j$ F' r+ {* k. P - [EWA Control]
7 ~$ T& h5 j) O0 S1 t - {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>; ]5 @/ Q) b# U- c
- [Windows Media Player]* d9 `+ P, ]* z8 a/ w: s1 |2 e0 i
- {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>" ]$ q3 j6 r: b @# m# q
- [&Google]. R! O% T0 p$ R+ z1 Y
- {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>' H. L7 c0 z8 F9 M. ^
- [HTML Document]! o8 ~- j9 D/ Y m0 k
- {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>$ {5 P$ F- |5 S' C8 t0 }& p
- [DHTML Edit Control Safe for Scripting for IE5]
: f3 J- }: P+ W% ]& O - {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
8 d5 Y* z& m3 h - [RealPlayer RAM Download Handler] W# T7 H, y2 C4 E3 q+ U
- {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
1 K; w: S" g* k3 N& M5 F- C8 s - [IEBuddyExtControl Class]
, v/ o* q& ~2 X) U U# @( V. C - {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>& f0 n& q1 `, l* S8 m+ ?
- [XML Document]
; d3 x9 e! ]" k; d1 w p - {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>' H) b; R1 R/ M( L n% L: s% e- H
- [HHCtrl Object], Z+ |- a0 d! W, r
- {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>, P! Z* g' }. Z: m$ A
- [Windows Media Player]) N5 D W- w/ u: g' n/ P `
- {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
! T3 w- O ]# O/ ~: B, C5 E/ z - [Active Desktop Mover]- I. b; m N9 U4 ]
- {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>7 {- g, y% X$ S n
- [360SafeLive]8 E9 {6 Y" b$ K3 X' @% ~; `5 f
- {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>- N* q v' R9 [9 L% W
- [Microsoft Web 浏览器]# _7 p2 Q# Y- I2 }% @& P6 ]
- {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
, R# ?- [% }4 v& _; t - [Browser Enhanced Objects]8 T8 p) k9 S) ]3 u" y3 b' q6 D2 [
- {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>, \% x% K& z6 E
- [Google Toolbar Helper]
4 K* u5 n0 K3 t/ D0 K. l - {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
. }) q- B& N* ]$ p) Y - [Microsoft Scriptlet Component]
4 N9 X* \5 U% M& `" s: ] E - {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>3 L" `. l( v: g
- [Google Toolbar Notifier BHO]
' V+ |5 R0 n, @ - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
1 X( N( z3 o) b" B3 s8 m - [SearchAssistantOC]
7 P! U; i* V8 v( J6 c - {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>1 S% J; ~! n1 r% L$ {
- [SafeMon Class]
/ E, B& [( v7 ?, ^ - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>/ n7 P5 W$ e- A" u
- [RDS.DataSpace]
7 ~- \, L5 x2 E' x3 f - {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>, O2 K, [; n/ j0 g- N
- [KooPlayer Control]1 o$ v- O2 s, Q5 b
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>: _5 Y6 m1 Q; f9 y$ i3 N; z
- [AUDIO__MID Moniker Class]) P5 d* K, T; i' X; g
- {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>5 p) S8 W% z \8 T
- [AUDIO__MP3 Moniker Class]
# K/ r$ g2 B: z, y7 Q/ W - {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
" |, j6 S+ e7 [8 T' b3 Q$ t* g - [AUDIO__X_MS_WMA Moniker Class]
# [0 o+ F; r- q( `- g6 _ - {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>/ k! ]4 X+ e, @9 N- `& ~ Y
- [VIDEO__X_MS_WMV Moniker Class]5 {5 W/ X* B+ k
- {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>9 K6 G- K; y. `( P
- [RealPlayer G2 Control]$ g9 j/ {' l, q2 F# {* |( J
- {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>) ~! ]% L! R* p' b$ B
- [Shockwave Flash Object], ^! G! l) W' I, g8 {
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
' Z# b) K( D% m3 J - [KUpdateObj2 Class]
1 D; L- k7 E" r4 N2 T/ h$ h - {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>% T8 I, P) S$ k+ j% [3 A
- [kingsoft browser shield]0 T) }: j1 M, K3 E) H8 P. j3 z! R
- {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>: K* i O& C2 q9 I
- [PasswordEditCtrl Class]
6 w" A* `+ i i - {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>: u2 b# W% u o
- [QvodCtrl Class]
6 ]2 s9 T. h) B - {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>/ ]1 b9 F& |" V6 P* Q& @5 f# w
- [&使用超级旋风下载]# y3 X) S! q0 D0 H1 n
- <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>+ m, b0 d/ l/ k* j
- [&使用超级旋风下载全部链接]
6 L5 \% [$ i5 O0 U - <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>1 L- a& J- J! Y) g6 P! L
- [使用迅雷下载]. M, M, Z6 N l3 G& s D9 F, |
- <, N/A>. Z. ~2 o3 z5 f- y, N! C
- [使用迅雷下载全部链接]3 h9 Z. a% z: P! A( W" U. _
- <, N/A>* T* @, n# l/ r
- [导出到 Microsoft Office Excel(&X)]+ m* Q. x* [, v& P
- <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
8 ]2 Z. a7 t1 s# u; q; M' L6 T: Z - [添加到QQ表情]
4 e/ W: F. I5 t% J - <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>9 V) Z$ `; d( Z. K) Q
- ==================================: a) f# \) T" O: w3 G4 v4 v
- 正在运行的进程
$ \: o5 d7 [" o# W* ~ - [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]7 R7 {$ a7 e2 y1 b0 b5 ~& A
- [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
( ~" Z! A8 N. z! ~' L" ? f. A8 m6 r% N - [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]: _9 j9 W" {3 Y- F
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
9 Y( Q, U9 ~, ^ B7 u4 Z+ ? - [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
! Q& U' I! h7 O. ^8 e( Q - [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
z% e: x. f$ H4 O - [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
) {' U8 H- C& a' L# N - [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]: R+ A/ Q/ T7 \+ }: V( T
- [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
' q t e: k- t0 h0 P" u3 K - [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
; H9 h; F+ ]: X" {& U; J - [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
) p' A# I6 W5 v) V - [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]! r1 }( _/ R- b5 U1 z+ S
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
: e1 i* }$ \. o4 ^$ H - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
6 y' s7 k" H: l# {* [# k% g - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]3 B, N. N4 n r! |8 z" N
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
5 g6 X* N$ ^3 m. ]& ] - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]
$ F- A, K1 e; R - [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]' O% _8 n* P( c J
- [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]; W% T) W; n" y5 J4 i- P
- [C:\Program Files\WinRAR\rarext.dll] [N/A, ]5 O( P6 R" K1 u2 C. e( _/ a% Y) O
- [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]$ ? x4 {' r% w& Y% M
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
1 j4 |- F9 ~. Z4 h# k" k4 b - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]0 R& K2 {- J+ z7 [8 W
- [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
9 q& y* Z% H8 h. t - [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]9 x# ~& ` L7 y* R0 J; f
- [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]7 S9 |7 T! q2 C( S# Z# @. Z
- [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008]' { K% n) T7 E7 H' y; b+ I8 s! E
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]7 r" S* W; V5 f9 m* z, v
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]& h3 H$ s- K9 `& V3 V* H, b' k
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364] C$ r0 f8 |& Z ~
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
# F& \6 H( o( O& E T- u! d6 g. r4 ^ - [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]( T# E6 c1 j1 T" P" G5 d3 G
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]9 T1 O5 M1 w4 B- |% G
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]" ]( U1 D" y' k* g1 U& T1 L
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
|/ E$ W' [5 d - [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]
9 n9 i# k3 c0 n6 i - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]% }( S5 g: r9 B7 L }% m
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
0 t: }2 ~1 ~% n9 m, g3 o* | - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
& I% F$ D. M- z9 Q - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]3 `& ?/ ~: ^$ Y' l
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
9 B. O" G8 i: X0 K: H1 C - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
, ^* \2 r: x+ o8 |4 _7 ?3 q - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
, O. X) ^8 L$ O- t6 R. b - [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]& R9 K3 I) b+ O4 h6 t; W8 e
- [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]
2 W( b& `" Z7 I( c! r* o - [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
4 A! W, _7 |+ d - [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]( z# `) `3 [0 }/ N4 |: y0 c
- [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]$ R/ V2 N5 H) Z) C
- [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]- c0 z" ^0 Q) t/ t& O
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
/ r z: ^- @/ e - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
8 M+ |3 Y* A1 ^' {8 d5 E9 |0 w - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
^7 ]8 n1 ]3 w, }$ E - [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]
" U; ?$ T: u% m3 _( l0 f - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
T0 s9 X$ x) c - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]
) G' r& y( I$ h, j0 K - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2], _" U1 z" e' E9 f+ y8 k
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]
3 ]* _- _# Y8 R2 [* T7 y: Q - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]# u2 z! {" f- ~' o2 o% q
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78]
# B* \- N, o- J, b& r6 e - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]( s# m- r9 D6 C
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]# \, i: |2 `' l3 G% t
- [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]) u' h R: o2 s5 v6 [# @
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]' E; \9 T' j0 l$ V) r, m
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]7 g# Q. ?! h# r5 c" H
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
0 s" ]; q' `$ l - [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]
, h S3 o$ g+ P - [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]0 H# _0 {. C4 j3 i, ~
- [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950]
7 l1 @: q+ V: m# ^% H8 {" K - [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]! Q+ r+ N5 F d* b4 E
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
4 W$ P% O9 a$ d, n/ q) k3 g. o - [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]& ^; |+ Q' k; s" {9 G
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
* Y) I. d5 c2 m - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
1 o/ X: k) F v) ~ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]' v" s( `9 ]7 z3 P
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]* ^/ N( U% v' o. y& s$ L5 k+ J
- [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]; ~+ `+ i4 @- k8 W6 @, D
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
" O+ E9 ?. Y: B; J M - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]0 F2 G! R8 p- U% n4 [
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
- i: ~: i) V1 a% K- L - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
, ?4 B$ d' n8 i - [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]% S. W# `) J- u4 j# f9 `& s
- [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]
2 {0 @- d- G! g) C - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
7 C/ _( w7 [- Q6 a8 |% J! l - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
. U% E0 T- x7 P1 B% `$ b% j( `( B - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
! h) S0 ?% l' r/ H } - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]& F2 `. i; Q+ ?
- [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
D. \$ ]/ _: q8 }2 C( R% O* S" C - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
6 h' a* Y D( L* [; X - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]* R$ p! f& i2 K. a( K
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
" }& k$ N9 p( I: h: L b8 o - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]' O: j7 A5 Q8 j( ]1 m7 X
- [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
$ B: E5 u- m, Y3 w" b2 y1 ] - ==================================: \" @. O/ z; {* C1 C! e, r
- 文件关联
& K, @2 j9 D, t - .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]$ w$ Q; [, n, x( f) R# _
- .EXE OK. ["%1" %*]4 H' q5 F* k3 I! g+ i& E. M
- .COM OK. ["%1" %*]8 `& R) y& `* U' U4 L/ w- }. R
- .PIF OK. ["%1" %*]
# A8 b" E, w9 @ - .REG OK. [regedit.exe "%1"]
2 y, X$ O; H6 j" n. Q! r - .BAT OK. ["%1" %*]" b* q2 E7 h4 a4 t. D) r& R8 x6 M: r
- .SCR OK. ["%1" /S]; f) z! G( E' A6 \) F2 P
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]2 r( R: D( I& q+ ]5 [6 ^8 I
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]7 N! p/ k% Q" H. {* n: R8 m
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
$ b* y- s1 j# O, s - .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
5 V# @7 a3 |7 F1 [9 j( z' m1 ^ - .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]+ b- \' s4 V0 O( e" n$ ?0 k1 f; r
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]) g5 ]% c+ H8 j1 `7 X
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]4 ~) e; U& V, u7 Y& a
- ==================================
p" K8 z7 M w2 r+ o! ]0 n - Winsock 提供者
8 G3 Z: h. `/ f* f - N/A. L: e/ u6 d$ @1 i0 G: N J
- ==================================- ?* z# u) B3 m0 b! v4 `
- Autorun.inf' H/ B! P, B& E; I" u% y
- N/A% `0 T1 s$ F. \* b5 ]8 ~3 y
- ==================================3 n" ^" |! L m$ P) z
- HOSTS 文件. S6 K' {+ I$ @: |
- N/A4 v, w% x9 }+ a3 B8 o6 s) F) p
- ==================================
. @: b% n( x3 f - 进程特权扫描* L) T6 I8 w9 {& X
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
0 t# y% _1 w+ a5 S6 I( L1 e8 t9 | - 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]
1 c, u2 [; u3 A+ I) o' j7 Y; i - 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]
4 E+ W7 N9 s! E8 V" i7 e - 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]
, {& H* b& x9 V" E$ j) p - 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]' O5 ]; e, q; I) \, [; G5 L8 ]
- ==================================
2 q, ?: _* {4 R9 v% s% |# V - API HOOK
7 f0 ]' q. \$ l6 `1 N - N/A j, J5 u7 o' h9 C8 @
- ==================================
, S0 O L# X$ y5 i8 `; \: X+ v - 隐藏进程
+ ~$ o8 j1 t4 V# u - N/A- w0 K7 m1 Z2 z" ?) {, ~# z
- ==================================
, j5 g8 U' R! {5 D) h3 u! ]$ Q - # e$ z# j- z% Q' @
复制代码 |
|