|
|
8 F. W6 z- T( x' ]0 s7 J3 e- 2008-05-22,20:37:43
& p' i! w# F! d8 \; @1 [ - System Repair Engineer 2.5.16.900
+ w6 ~+ X+ i. |2 c! I+ M - Smallfrogs (http://www.KZTechs.com)
1 q/ Y+ L$ L, ?. y+ T$ A' Q - Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
1 k J! m& B3 a% n1 f, ? - 以下内容被选中:! n9 n$ s6 v. T, f5 f0 Y
- 所有的启动项目(包括注册表、启动文件夹、服务等). F2 X& x* ^9 m6 j( V, P
- 浏览器加载项
+ j+ _ T- ?& Z* R - 正在运行的进程(包括进程模块信息)- y6 G. d2 l" E/ y0 W& ~: X
- 文件关联
. t- d" c1 t1 @2 R# Z" \& ~ - Winsock 提供者
* z) f, t* L2 s2 P% ~: z9 w7 I - Autorun.inf
+ D; U Q+ [, j7 ~. S - HOSTS 文件' F% O7 K8 n/ W6 v b! k4 d, `( t
- 进程特权扫描
8 V, {2 Q4 R+ h6 t+ K/ {0 O; e# ?' R y
6 A$ G: P+ {3 @- 启动项目
( @# n$ U* P$ Z) y5 x3 f! h, Z - 注册表6 E, }' V& c% `8 X0 i
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]$ B/ K; N5 S- Q7 M
- <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]
% g& _& _- H$ }5 [2 k' i - [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]: r b$ E/ \0 I% O2 K g
- <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]
2 O/ Y' ~8 ?- L, t' S, p - <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
7 u3 g6 Y+ x! c$ J1 d$ ^ - <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]9 n* K7 @4 l! ^% k
- <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]
: Q5 P$ m& t% t" W; u - <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A] ]1 ]/ o6 R- u0 n# n
- <PHIME2002A><; > [N/A]
1 _) {$ a- K, T3 _* H2 v" p - <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]" n$ i+ K. [, Q& o0 H2 I
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
( k" Z* {9 ~" y- m- k: ]3 b; T - <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]2 e) F/ o0 |" t$ l2 i4 Z
- <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]
0 F; i, V4 n' V/ w4 B$ I& L - <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher] ~; C, V9 o' k
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]' y4 w* \3 D% k6 F0 O! z
- <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]' F3 i9 d7 N8 t
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]- Y- W, a" [3 P/ g2 A4 y% b
- <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]: ~ B8 w7 I5 _0 e) E" D. m8 W
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
3 n( [+ h; o' j& X0 }$ \ - <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
9 n. z1 z5 O* G1 t - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]/ O! ~& i& E2 ^, o! F4 X
- <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]7 }4 r- i/ {/ ?0 c; K
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]5 U/ f7 | h6 w' ?, y4 y8 ~4 F
- <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
% v% j7 u% t% n- {3 T8 |# J - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]: w: s9 V% Y8 ~2 f, |9 j/ K
- <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]7 \; U$ [' X3 z* |+ K- N
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]' ]' u+ A% O5 T3 k: z
- <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
6 k8 c/ K1 l4 \$ G6 h# t2 ^ - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
9 F8 y4 B2 j8 ]3 T - <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
3 o$ ~! B* {! q) ~+ C7 j5 S! p) V! M - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]+ T. b$ h+ ?0 M' b
- <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
9 X: r: D0 e7 O% h - ==================================
' ]2 M3 B- S& X# V - 启动文件夹
! J5 M& G/ s6 a! g" T5 X3 n - N/A
( m, \/ @( R1 z - ==================================( T5 u( m2 k& q- v+ f
- 服务
6 a3 n/ n7 I" X; M1 [3 k; T3 ` - [3ware Controller Service / 3wareSrv][Stopped/Auto Start]6 \0 X- G+ r1 c1 D+ V9 |
- <C:\WINDOWS\System32\3wareSrv.exe><N/A>% M8 A. ]5 L" N! }3 h
- [Google Updater Service / gusvc][Stopped/Manual Start]
+ s7 e/ F! E& q! u - <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>4 I0 Z+ y- K4 C3 K$ c
- [Help and Support / helpsvc][Stopped/Disabled] ?% {7 p* A# C
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>
; V- N. n- e3 Q9 R( | - [Human Interface Device Access / HidServ][Stopped/Boot Start]1 `0 u# s6 s1 S0 u$ ^) H
- <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
: p0 ^7 \4 X+ q/ s/ r9 j - [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]: J' A" Y9 H8 _# y+ v1 K
- <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>
p. R, r) g8 }$ U - [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
* Z) J4 }0 t& C* B - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>( H) J( o% ^5 C. O1 X& {9 k T6 P
- [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]8 z( y! U2 Z$ z+ S( m- h+ R1 ?
- <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>6 J% F: K$ A3 i: e% h& |0 ?
- [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]( W3 q: E( W) j5 e5 j/ B! y
- <><N/A>+ v2 e" E* F5 W3 q
- [Qvod Terminal / Qvod Terminal][Running/Auto Start]
, Y- ~' e$ Q& S/ L6 t* z$ ?/ T, _9 ~2 v - <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>
% |# O9 N! d: t+ ~: O - ==================================! H" t: s( i& F0 J
- 驱动程序
8 B' u) f) i7 s - [22j / 22jn][Stopped/Boot Start]( T7 G) L' b' @% `3 O3 L# \
- <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>) n# E3 W6 {" p% w* ~+ j
- [360AntiArp / 360AntiArp][Running/System Start]
1 J# o% `$ T$ i9 F7 w- A - <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>, p( l% \. L1 ?
- [43ec / 43ecu][Stopped/Boot Start]* t; m( q, V6 ]. S3 G
- <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>( _2 O5 s1 Y# v6 X) [
- [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start], e) A- X; S+ D8 i
- <system32\drivers\ac97intc.sys><Intel Corporation>
6 j! n: g) F3 Z - [Promise driver accelerator / bb-run][Running/Boot Start]' P' Y+ o' t6 l3 f# W+ r2 A
- <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.>
/ L3 J! b/ V% M9 U# ^ S/ B8 m - [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]
# v. Q# Q" ?, z8 |8 \2 T1 r% Y - <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>1 W! f w, p9 i5 ~. A& x
- [KAVBase / KAVBase][Running/Auto Start]$ B/ s6 ]' _' P5 f n7 g$ m- [* P
- <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>3 q A; M1 E/ x7 y6 p
- [KAVBootC / KAVBootC][Running/Boot Start]
0 r$ l7 z# j/ F4 g c - <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>
! S& L3 P" }- o' L - [KAVSafe / KAVSafe][Running/Auto Start]: M- i) A" L; K, j
- <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>
8 {9 Z- ^6 E. N, e - [KNetWch / KNetWch][Running/System Start], u% `3 W. A1 ]- D: Q6 B& ^3 I6 T4 I
- <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
# M q4 |# R; h. i - [KWatch3 / KWatch3][Running/Auto Start]
# j. v3 D% N+ t - <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
. ~% ~7 M8 U0 W& R - [ntptdb / ntptdb][Stopped/Auto Start]
i9 X, u0 n3 L' U - <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>
4 e. l* E0 f. ` [% k7 h - [nv / nv][Running/Manual Start]
( ~0 C: s. b( j - <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>* U+ b$ Z6 f& [0 }
- [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]
) Q2 z9 M4 W7 Q* P" _6 G% K - <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>
( c: w6 P3 P& I$ O9 k - [DDK PACKET Protocol / Packet][Running/Manual Start]
3 J8 g: |# x. @3 @ j2 f4 e - <system32\DRIVERS\ProtoDrv.sys><360安全中心>
0 L3 G" e' ^* j6 k$ ?3 p; f - [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]1 C% v+ U) [4 K8 { U8 k; x% \$ h
- <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>
) \6 g* `& V( ^/ B2 c8 J - [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
: G& `' H' |% A' E6 G0 B - <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.> ?) Q, @/ q) V" m& e
- [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]
1 E/ f. ?4 G6 B, e W! f% W6 k - <\SystemRoot\system32\drivers\RsBoot.sys><N/A>
6 I" h8 O6 k4 H0 J8 ` - [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
. f8 Z; g9 X3 Z& v( Z8 g - <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>9 g7 ^: w0 Y `* {4 y8 z
- [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]- I# q8 q+ a7 @ t; N$ l
- <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>; t( m) @, m* H% t L+ e$ z# V
- [Secdrv / Secdrv][Stopped/Manual Start]
- J! _" `* q0 }* A7 F - <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
' K& W$ l: C: A - [SATALink External Device Filter / SiRemFil][Running/Boot Start]
& U) A9 c! V7 n' V$ P; `3 r$ z - <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>
/ V: |- G8 t4 k! N& L" I - [System Restore Filter Driver / sr][Stopped/Disabled]* a4 A( n5 V2 G. S
- <system32\DRIVERS\sr.sys><N/A>
6 q' w! s: l/ s# a' x - [TesSafe / TesSafe][Stopped/Manual Start]
! h4 t6 c. H9 ?7 k+ W - <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>: Z7 r4 A! ^) m0 t9 U0 Q& A0 ]
- [System Services / unzxzsrs][Stopped/Boot Start]
& ?. m) G) x% f7 c - <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>
: w7 U% ]" N- E' p, Y - [ViBus / ViBus][Stopped/Boot Start]
/ F8 O& J& D. B# b* b6 z& L0 f - <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>
' g$ S9 s/ L' z& e6 E5 t/ I - [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]7 ?5 V6 b9 F) h
- <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
- D# {4 f) k+ u& _ - [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]* b- o$ |4 M! s1 p$ `( a) v4 `
- <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>
+ z' u' t! p% l F1 @" I - [ATI Extend / zhibmaso][Stopped/Boot Start]. g) X, q# T1 @2 h9 F X
- <\SystemRoot\system32\drivers\zhibmaso.sys><N/A> {6 `8 x6 N6 d$ c0 q
- [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]) R# e- f. w3 d* A
- <System32\Drivers\usbVM31b.sys><Vimicro Corporation>9 X/ V5 x8 |1 u! P. C8 F
- ==================================
) e3 s2 r$ l0 J& d9 h& @( l - 浏览器加载项! X* ~9 ]1 {/ V7 F- k% L
- [Google Toolbar Helper]& j! b3 X4 |" B C6 s5 ^( W! C
- {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
" i- K: |, Q, c - [Google Toolbar Notifier BHO], g1 w7 ?' S) X( d6 c) z
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
) m2 W$ B; ~- {& a/ U$ j - [SafeMon Class]
* {2 Q( \0 X0 Q - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
* X! H2 e4 a, s4 F7 h7 f( c1 o# c# } - [kingsoft browser shield]
2 r. O4 Y o! q. J$ s - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>& B b1 C; e8 M( x& i, I. F, U. |
- [IEBuddyExtControl Class]6 z0 e& I0 ^# C7 _
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation> A* B% n) c3 H7 i2 w" U+ G
- [Zcom 杂志]
- { X# E- P8 ~3 \3 I" w - {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>1 J- Z2 S) B& ], r3 b! V
- [&Google]
- d. g2 Z2 ]8 Q: `! u! l r - {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>' C7 x7 f, _0 U g
- [KooPlayer Control]" C/ {/ T; L1 T5 L1 j8 R% g
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>- s' q- f' E0 c" l) g" w+ @
- [Shockwave Flash Object]; n6 z. {1 |' F% P9 @$ H
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
2 K- V/ D. k x5 G3 V$ p) _ - [KUpdateObj2 Class]) _6 M; w# d3 q! L) _2 R
- {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
# D) _4 _/ k8 _* A7 ?: L$ y - [Google Script Object]; \. |+ s: D( ~" j* t, `
- {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>9 I" a; }, l% {% H3 A0 i
- [EWA Control]
# g# \5 y3 O, p8 b* z+ j: C+ d - {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>
: l% D! p1 L4 j) l - [Windows Media Player] X( L, g ^; e+ Y6 r
- {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>/ g+ Z9 l5 ?# B; C5 d' o
- [&Google]4 s( A7 r2 P! T9 q3 f( Z
- {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>( {( n i' |( E/ E, a
- [HTML Document]; I% Z3 y6 _8 Z2 \ V
- {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>2 ]# M0 i9 \$ s- z
- [DHTML Edit Control Safe for Scripting for IE5]& t8 u9 q4 k& E5 _& N
- {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
( {; x( a9 B3 S- O - [RealPlayer RAM Download Handler]
9 P- z3 w+ X r - {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
( @! q& ~+ E" c - [IEBuddyExtControl Class]
* F8 z9 W5 g9 `: C: v - {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>5 w9 ^/ E- ^) E3 Z
- [XML Document]' _6 `4 ? p# K0 K4 Y- r
- {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>/ N" q% }- t3 S _4 d2 M+ m6 S# ?0 g
- [HHCtrl Object]- Y: ~+ t. b" ?8 J
- {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
+ E, d5 l" g3 `% s* Q" T( `8 F - [Windows Media Player]
" D9 b+ h+ K5 \. p* Q - {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>0 `8 a3 g* `* ]: t! s8 _
- [Active Desktop Mover]! o9 x8 P& X1 u0 w7 @) a
- {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>( p8 T+ y* g. I \
- [360SafeLive]
- } C. {! q3 i - {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>7 J5 R; d9 L1 R3 _5 N
- [Microsoft Web 浏览器]$ @: D+ d! b' C! e* x( I/ m% X
- {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>' e: a" O* l- I, a4 u1 ?$ T- @( z
- [Browser Enhanced Objects]7 P2 h! ]! S5 v' @# n
- {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>
/ }+ N' E, ?. J - [Google Toolbar Helper]
$ C* I( n0 m2 c - {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
6 |% l; J" M/ s. c% a: w - [Microsoft Scriptlet Component]
: F' z% h/ T+ y) h1 m* Q% | - {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
^+ l8 y3 I; X# a - [Google Toolbar Notifier BHO]
( w4 {% r' I% { - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
4 y, d0 h# g2 C J ? - [SearchAssistantOC]2 T- R0 m/ a' ?
- {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
3 U( b, Y% |6 r# V4 ? - [SafeMon Class]9 }( A V0 Z& U5 G# {, W0 {( h# h8 a
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>% f9 X# ~/ ?7 o. p9 E0 n8 A
- [RDS.DataSpace]" G% t4 z0 L) k+ z+ E6 Z
- {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>- \, a6 q0 N( }! [! q
- [KooPlayer Control]
& m$ @. K/ l( n: c2 f - {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>
- f/ k- X. t* M" P5 N - [AUDIO__MID Moniker Class]1 R/ F/ `/ d% k
- {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>, k- ], a2 i) T2 V- N4 `
- [AUDIO__MP3 Moniker Class]: L8 K& W' n5 R, k
- {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
) Z" r, d5 c, t# k4 ^9 \2 x, F* w, J/ s - [AUDIO__X_MS_WMA Moniker Class]8 ?8 i. d- v0 o/ `+ f
- {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>) A+ N9 H' e- B* u; B
- [VIDEO__X_MS_WMV Moniker Class]
5 e, m4 @: Y8 O5 s( c9 m - {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
0 J7 D/ v& \7 _. Z8 K" ~: G: u7 N - [RealPlayer G2 Control]4 j* W& u4 Z# |$ M T
- {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
2 b6 l) s) Y; `1 Z O - [Shockwave Flash Object]: S6 W; |' c# d% [" X) @1 d
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>; u: Y' L; r4 U$ E! n
- [KUpdateObj2 Class]% [! U* G% w4 W: y, _1 p( u
- {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>* m/ K( ~& I* p3 A, J% e
- [kingsoft browser shield]
7 Y( k# E( S7 E- h: A9 c2 k! n/ a - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation> _' G0 k/ r& ]
- [PasswordEditCtrl Class], y* \1 Y% {& W# t1 m# W K
- {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>' A, U$ g8 @# a; M* t( a
- [QvodCtrl Class]$ C; B+ d2 M4 A
- {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>
8 D% ~) K0 h1 p& n3 F( d& y3 q- U9 g - [&使用超级旋风下载]# G4 y# k; F9 {
- <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>5 N8 c' _4 o3 d% o
- [&使用超级旋风下载全部链接]
2 `+ V, t6 f3 B" A/ f - <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>0 {# N0 C) V! Z( b
- [使用迅雷下载]
0 H9 z; Y ^9 z$ V: s - <, N/A>
- ^1 e( S! N0 ~! J2 F - [使用迅雷下载全部链接]
# M! A- ~+ ~/ q$ Q/ J1 G - <, N/A>
% r) `. [+ G$ H7 @ - [导出到 Microsoft Office Excel(&X)]
: X) b* o6 q7 c ~ - <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
% x6 \) Y, q5 \ - [添加到QQ表情]/ w1 b/ h9 U3 [) G3 p
- <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>8 d: \% W3 n+ Q. o) j: i& n# ^
- ==================================
0 ?7 Z% K* u8 |! I5 e6 O7 y - 正在运行的进程0 r# } y+ o% W' F+ S
- [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
, W# g" g+ N) \, ]7 ~ - [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]) r( P4 `% Z; X' w
- [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]" I; M) t& ~; m
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]$ M+ [4 Z4 p7 C! @4 G9 N5 p
- [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]3 y" `$ b7 ^. D h2 e* J' E& ~
- [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]9 `; t4 J) F( [& P* g
- [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]( n3 z; a( K1 r( u& V+ ~
- [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
9 R* T v+ q4 L; a) { - [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
, B2 X: E# p8 y4 r& ?; Y - [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
' E' ~9 j$ b# s( E2 r& e - [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
% O+ s+ P! X, A% z - [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]! c' f# d# o6 f0 q" ?( a n" n
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]7 ^9 Y; B; x9 E
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
) V& H- ^# _( ?! ] D+ A - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]. ]6 M$ Y. H+ S9 l' E
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]4 A. Y" E+ f% H, u t8 z8 U9 b
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]
7 |) I" ~0 ^& a5 M9 p2 o$ L - [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]! `* _, t+ U6 w, s9 ?. T
- [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
/ E6 ~, X7 o f& ` - [C:\Program Files\WinRAR\rarext.dll] [N/A, ]$ N7 f. w G! v6 [) _# M
- [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]! l3 h) q3 }( K* ~
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]0 u; t6 a6 F4 A- n: u
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]! e2 _9 v4 \; |1 S
- [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]; {* v; O0 o, { F7 D
- [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]0 r/ _. Y* z% V& K' ]
- [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]
; R+ w9 Y3 C- o5 h - [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008]
9 n( M, S _; E1 f: J' j' C* ? - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
7 h; t% V) ], i9 }4 y - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
( u# u5 k2 ~7 X! R- b$ s6 ` - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]& Q4 R P, J; x( q( i& D* z& x: p
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
) Y6 }" h; B' k L5 ] - [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
0 u" k* J* f0 I3 h - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]7 S/ n( L% @* W$ j/ i% F8 I, u: k
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
4 k4 R- Z% X4 h% Q t - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
: y- X1 q# q$ y3 s# v" d$ L! G - [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]8 X' [* R; h0 N# M0 D# g8 u/ f0 ^7 y
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]" }# @- {) w3 `3 A: E$ _0 V# Z
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
$ n' t; M) C# A' z' T - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]+ A/ {7 n6 m' H# I5 [5 Q
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]+ Z$ l" k4 u# f. x9 x3 c
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
0 a8 a, N+ o2 c8 d1 ?+ N% u/ \5 d7 K - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]: V {( q6 i0 C- C, i$ g# d% H0 l
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
r: [2 E# a6 e: a. { - [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
( i9 r/ _/ `/ C5 p- m: p - [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]0 ?- A( P! m. I
- [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
! D2 }. _* A$ K: K8 F - [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
, r6 @/ M7 Z6 }' ?; S - [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
& E! r7 Z$ g& }# E$ y( E - [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]- ~% Y( F$ v4 K& i
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]( H- p0 p) S& f5 _8 [' P3 k
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]" O- |( _ t7 k+ B" i7 U
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]( |/ e: f S; _8 q
- [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]) {" K3 v- u: S2 o2 s/ @
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]% m Q& ]2 W$ R0 X/ O8 I
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]
: X: x, r* }5 { - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]5 Q' Z$ K0 p$ t: t6 }* [3 g
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]7 {) h D3 G& X, @7 [3 b- Z
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]
/ q' H; X/ L$ t6 b' j7 m" b6 W - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78]
& ]0 X$ x' X; L- K - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
. c- W6 e( t+ R2 _: k: Z4 C" l% V - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
4 n3 r& G- S- A2 ^2 `9 n- }7 H' u - [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]. }5 O+ A& X3 K
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1], E: M6 H, j4 e) @2 v
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]8 O: y. `0 b( s" \3 z4 Z; D7 x
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]
0 `7 H; C5 E$ p - [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]8 z& j8 t/ u/ H' h
- [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]! F) R3 }3 e+ m; k/ }6 _
- [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950]& p; Z$ {; H: z; r! p9 l
- [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]
0 k* P5 b, \) x2 \0 J; }9 S' a - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]" \( _# l! v' m( z+ i& D" f
- [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]- W3 J \: t% B( q% ?
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]8 O' v. `' |6 Y' ^5 i$ z
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]6 n5 B) W+ ~$ F. P) |
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]# _8 z: B I. L8 h, u$ [
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0], V8 g( X7 @2 e) a. Q# w/ G
- [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]4 ]9 X0 I% C! _* r( X" Z, s+ F7 P" A/ A6 m
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]6 g% {: W) J& ]; S" ~
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]) A# b3 V& V4 p B4 n1 K, T! W
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]+ L/ s4 L% [5 v8 b; |7 D8 ]
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]6 o$ j, n2 _& T& L" L' d
- [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]
! l+ J( P# ?% M - [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]) @4 v; s* J9 F% D( X8 y
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
# u7 W6 e7 h* K i* n/ @/ d6 G - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]4 G5 W" H1 \4 o& {/ W
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
6 l( B: }7 g e5 f; k - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
c" Y0 \9 f5 T3 g S - [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]9 @3 ?" ~7 r( @
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]9 Z0 J4 a6 n, _ [. X7 a! Q* f P
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
6 k% c" I0 ], s* K9 @" w - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
. J1 J+ m; e+ B. u6 v' t, { - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
1 A8 Y) z7 ^: S9 d - [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]" c0 g4 h. L, s+ a* Y& f# M
- ==================================
5 D; }) K, ?! i* r$ t- ^ - 文件关联2 Q8 H- g0 M; d/ k+ ? J
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
6 ~8 L5 J; S/ X - .EXE OK. ["%1" %*]
5 ~2 D+ T @- l& k5 |1 M1 Y8 v - .COM OK. ["%1" %*]" u$ E0 S4 x F: H5 o& y7 {
- .PIF OK. ["%1" %*]4 Z7 _% e$ s/ I1 t w
- .REG OK. [regedit.exe "%1"]
! t9 q, T, W1 |- E$ {" b1 S- x - .BAT OK. ["%1" %*]
# \8 }8 n1 C7 f% T, s; h - .SCR OK. ["%1" /S]
& Y# p% R, D+ p! R4 H - .CHM OK. ["C:\WINDOWS\hh.exe" %1]
1 u) h& J+ q1 b7 S& z - .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
5 G. P) ~3 ]+ E, t6 n - .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
8 X7 Y' b# I$ Y5 O; e - .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]- G( a7 v" E$ e* z) Q
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]. ]6 A0 R e1 |0 m0 S' p
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
" p. B2 y Q2 T - .LNK OK. [{00021401-0000-0000-C000-000000000046}]$ | l, R, P, O0 N) t- g* N/ H
- ==================================
, P+ t' f: F) V3 |4 l - Winsock 提供者
3 L( |5 I, q) Y3 ?1 j - N/A
/ U, J2 I0 z* E/ b; | - ==================================% a1 c7 f1 t" p: {* o3 _
- Autorun.inf! @" s6 Q7 P0 E. m8 n4 w. p
- N/A
" p) d' \# w9 V ~2 r% e. { - ==================================
) i# {$ p3 x& `: ?9 {% ? - HOSTS 文件$ z2 }# g% `# \+ o+ p {
- N/A
- ^4 e/ G \& X( R. D9 C: ~ - ==================================
( x: S0 @8 ~+ H0 |. _8 N" G - 进程特权扫描9 E" i9 |: |( H8 I W4 }
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
5 n n( Y6 K" O - 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]
4 Q; A" v4 g1 L; j1 [ - 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE]$ E1 O. N7 |# Y+ G
- 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]/ _2 `) N- E) z7 X+ p: B
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]$ m$ U: o+ U8 h/ |
- ==================================6 O, C/ j) T0 Q, a
- API HOOK
9 r) P. ^& t8 L# [3 s% @ - N/A7 c: B! t& W1 {3 V6 v- [
- ==================================
$ r: [7 Q c: s - 隐藏进程 k4 [6 t1 G+ g2 E. m% t
- N/A+ o% S( C% P/ U
- ==================================' F4 K; K& m9 I; D5 C' q: K9 U) ~3 j
- 9 y u& ], F T- o8 t8 }% Q0 e
复制代码 |
|