|
|
% y& j/ |. ?7 U( e, s4 y# [4 ~- 2008-05-22,20:37:439 u* z8 b8 ^1 G0 ]4 x. \
- System Repair Engineer 2.5.16.900! e2 A ~# Z* u$ R q: b
- Smallfrogs (http://www.KZTechs.com)
& S- I# d' v2 \+ M6 B5 _ - Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
8 S# x. i8 |# w5 V& M/ a - 以下内容被选中:
0 B/ a9 m9 I. ]# P. d: F# y+ z - 所有的启动项目(包括注册表、启动文件夹、服务等)) |5 G h& ~ g% v- W: X
- 浏览器加载项( n+ P4 Q; q# P9 `( u0 ^& e( R% h# V
- 正在运行的进程(包括进程模块信息): [+ ]- X% L; C5 [) G/ l
- 文件关联
% d4 S# A3 [" ? - Winsock 提供者
' X( G, u1 E$ w7 b0 F' R6 @ - Autorun.inf
2 ^) ]8 n" |4 j9 m6 `: X - HOSTS 文件
5 ~1 d, _ o: r. ?5 B - 进程特权扫描
& k0 s. V' _% m; @
6 m) s& b1 Y" S, k- 启动项目; |2 e: F7 w4 e( [3 o7 E6 q
- 注册表 p( v7 q E" e2 A( Y+ Y% T) A
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
% `$ r: N' y6 v$ O1 H - <ctfmon.exe><C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher]
& K/ _4 n! F, B! G' ] - [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
/ U1 I1 f/ o6 f! Z - <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd]
* l, x9 @: {. Y, L2 W& F - <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]7 P. v5 K, h' E( T B* e
- <360Antiarp><C:\Program Files\360safe\AntiArp\AntiArp.exe /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
9 a( i* P, |8 O5 G$ \' v - <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup> [(Verified)KINGSOFT CORPORATION]
" P- [& U$ b V3 l* s7 c8 L/ f - <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]
, T4 Q" C( L! m' A; s& v - <PHIME2002A><; > [N/A]8 ]/ @' v1 r* u6 T u4 o$ f
- <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [N/A]3 v) R" l& d& B
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]) A9 e; Q- m8 R6 u2 a5 d* W
- <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]$ E5 E; C G1 N. u e
- <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]
5 c2 b+ R( [5 u - <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]# r% D! g6 V( Z' `8 E9 Y
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
9 \/ \9 i5 J b1 e# l1 x( p - <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]
" y4 }" k6 r3 t% p& N - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
& K( s7 F0 h, M2 c% c - <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]) V9 I& L; t& H6 z/ {
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]7 {- f/ v, o D, ~# D9 t
- <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
" P5 L4 o D9 C+ Q8 K - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
d+ N% q p' M; o5 s! K - <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]9 k- M4 l. m3 f: ]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]$ u# [- O) v0 [7 m
- <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
" `5 n* x) M D& ` - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]6 F; y) y+ Y7 E9 {2 V
- <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]$ m, d" q8 p1 x8 R+ A, Y* W
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]- t- r4 h7 `& n1 P2 v! q% a, N
- <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
" R" @) ^$ v, U, ~ - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]) S1 n( E7 s% l) B. ?
- <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
9 g. F5 S5 v/ A" t - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
. D/ `0 t! L; `# d" |. |" i - <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]3 B# Q5 H; x9 ?. D5 E v& w5 Q
- ==================================
, m& N7 M P# H& `. }+ V - 启动文件夹
4 ]( e! `+ n$ I7 g - N/A9 t& r, u5 o5 N( |: U
- ==================================
4 Z/ b0 `1 Y% [) K' ^ - 服务, l) E0 E. r3 i8 E
- [3ware Controller Service / 3wareSrv][Stopped/Auto Start]
( ]: p! z, Y' v( [, t+ P - <C:\WINDOWS\System32\3wareSrv.exe><N/A>
1 N# r, h+ }. n2 @9 ~9 | - [Google Updater Service / gusvc][Stopped/Manual Start]( l- T* | m- s5 j3 T0 n3 N& v+ c3 z
- <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>" e# [% ~9 v K! h5 l
- [Help and Support / helpsvc][Stopped/Disabled]2 Z% H2 f: Z6 h
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>. K0 H3 v$ i b' M; ]" s4 l: b S0 F
- [Human Interface Device Access / HidServ][Stopped/Boot Start]/ Q( ]* G" ]% R# C0 g+ g
- <\SystemRoot\C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
( q9 d5 z& B+ d0 M7 _) V$ @# g/ N - [Kingsoft Internet Security Common Service / KISSvc][Stopped/Auto Start]
" [9 h5 v' l7 D# X3 D; ` - <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>
' {, o8 U1 p1 D9 v: P - [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
3 m: n4 a! t( B - <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>7 ]+ c8 s6 X# S! J0 M4 Z
- [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]2 Y# h7 ] k1 ^) s4 T1 T! k
- <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>; E, V' @8 |; A
- [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]
& R! j8 ]/ b; m7 \# S. K - <><N/A>
1 w4 K$ H* y# p. [4 V% _" | - [Qvod Terminal / Qvod Terminal][Running/Auto Start]
3 e# }$ h2 r; w% n/ S) U - <C:\Program Files\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>
6 S+ {4 X% @* s - ==================================
4 x5 k& B+ x. @ j, y - 驱动程序
% s4 R$ X6 G7 S% ~# P - [22j / 22jn][Stopped/Boot Start]
1 R1 Q1 W, G( x* A7 n8 D - <\SystemRoot\System32\DRIVERS\22jn.sys><N/A>; r9 w% h% u6 g3 M# Q
- [360AntiArp / 360AntiArp][Running/System Start]. Y' R% B" }, W: t% S7 M* H
- <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
_' p9 S9 Q7 B2 r - [43ec / 43ecu][Stopped/Boot Start]
F4 x! p5 V2 M G; [" M - <\SystemRoot\System32\DRIVERS\43ecu.sys><N/A>
& |2 V. N! K& l' T* i - [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]9 x* S. S0 ?) Q) D: M
- <system32\drivers\ac97intc.sys><Intel Corporation>
0 Y3 k' h/ T6 k" W5 Q* \9 |* B6 C1 a - [Promise driver accelerator / bb-run][Running/Boot Start]: d4 Q) T3 h# p: T2 ~* `1 e0 {
- <\SystemRoot\system32\DRIVERS\bb-run.sys><Promise Technology, Inc.> p: |+ f; t1 n* Q; Q* j
- [Promise Removable Disk Control Driver / dontgo][Running/Boot Start]
1 [" a7 |3 ^4 _+ R - <\SystemRoot\system32\DRIVERS\DontGo.sys><Promise Technology, Inc.>" `9 w }$ o4 q6 u- U* L1 r! Y/ E
- [KAVBase / KAVBase][Running/Auto Start], `+ t, I% S$ ?& ]: l4 n$ R& p
- <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
" Q6 z) h9 D1 }: T - [KAVBootC / KAVBootC][Running/Boot Start]1 `# @- c6 B+ ?) H$ P
- <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation> \0 ]1 S- P; t- I
- [KAVSafe / KAVSafe][Running/Auto Start]
8 O" a1 K6 w. D. Q- K - <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>
2 Y4 p% k' w. d- |' [! U - [KNetWch / KNetWch][Running/System Start]( r3 W$ l% p! x
- <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
2 X7 ]7 t/ u& J) g - [KWatch3 / KWatch3][Running/Auto Start]
2 |$ b( N" W8 s0 T5 M3 @$ P - <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
7 S. Q$ b% _( ~) D9 r) M - [ntptdb / ntptdb][Stopped/Auto Start]) Q% s h' l- T- Q
- <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>2 J- e2 D% ]/ H# P
- [nv / nv][Running/Manual Start], [8 L4 J; u( n- o- D
- <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
$ n, @5 }( A; O' ~ - [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start]
; j& K( Z; a0 ` - <\SystemRoot\system32\DRIVERS\nvrd32.sys><NVIDIA Corporation>4 a6 S5 o% M% T$ q- o( a" P
- [DDK PACKET Protocol / Packet][Running/Manual Start]
- ]* E4 X& i% D) F0 k$ q+ K9 E - <system32\DRIVERS\ProtoDrv.sys><360安全中心>1 L: V0 B5 A3 J7 a
- [pnduojtwbt / pnduojtwbt][Stopped/Boot Start]
) Z* L1 S( [/ X - <\SystemRoot\system32\drivers\pnduojtwbt.sys><N/A>' S+ b3 e, S, g6 @- i" z
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
3 i/ M% h5 w/ g& x - <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
& K5 G _* W9 E9 \4 h8 O& E - [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]- |( x$ ?! G7 ? a V
- <\SystemRoot\system32\drivers\RsBoot.sys><N/A> m: {+ z# ?7 X4 Y2 g, U* Y
- [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
6 q8 q$ D. r4 U6 \# q/ t$ [ - <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>: p5 s5 f8 l2 L5 l2 d2 k/ d8 {
- [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]
% a2 [1 k8 w$ |/ l3 H1 v! [4 O - <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>% S- v1 d7 k8 q: q' j& z- a: |
- [Secdrv / Secdrv][Stopped/Manual Start]
% q! s2 A3 x2 x4 o4 C - <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>" P' Y, E' f& U5 g) m
- [SATALink External Device Filter / SiRemFil][Running/Boot Start]
1 d! d F- f/ | - <\SystemRoot\system32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>) n/ G) a* I3 i+ ]
- [System Restore Filter Driver / sr][Stopped/Disabled]6 M& b& o; x F+ g" s
- <system32\DRIVERS\sr.sys><N/A>5 d; f/ B' P, O9 u" i# H
- [TesSafe / TesSafe][Stopped/Manual Start]
7 u, ^0 `( G3 `# u - <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>9 i# ]8 y- T' z4 s4 E
- [System Services / unzxzsrs][Stopped/Boot Start]
$ J, |- J2 x* m - <\SystemRoot\system32\drivers\unzxzsrs.sys><N/A>
% h3 e$ @# B4 _# l - [ViBus / ViBus][Stopped/Boot Start]
/ B3 l+ Q4 _! ]% Q - <\SystemRoot\system32\DRIVERS\ViBus.sys><N/A>
- y9 _5 a/ p& V4 t. Y8 o h - [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]1 Z* A4 f& w& V% L! d. U' h0 w
- <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
* V- K% H) m% k6 o$ g - [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]) l0 g3 r0 @. T- U# { p7 T
- <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>8 O% }; c* ?* J" J# n: a6 R
- [ATI Extend / zhibmaso][Stopped/Boot Start]; |1 k4 {/ g+ B; F9 w0 V' d1 Y
- <\SystemRoot\system32\drivers\zhibmaso.sys><N/A>
t) ?* \; Z9 u, }* ` - [Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]
" G3 I q1 r2 i& f - <System32\Drivers\usbVM31b.sys><Vimicro Corporation>/ \& \" F9 g. t# X
- ==================================: j8 @8 g+ j+ r9 I7 g
- 浏览器加载项
% }* T1 g+ N7 [* ? - [Google Toolbar Helper]
/ F( {1 S5 x9 \% @ - {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
+ a3 o0 O/ w6 J% m8 \5 _7 S - [Google Toolbar Notifier BHO]
& } a' p; e# C- N0 s - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>; O. @0 @: [2 y. Y3 @/ v
- [SafeMon Class]' k7 H6 @0 W1 V5 O3 Q
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>' t$ g* M5 K0 u1 N
- [kingsoft browser shield]
! `7 B1 l. o7 ^: {9 J - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>" K# Z f5 _9 o: J/ d I
- [IEBuddyExtControl Class]/ G& k$ s0 ^- o2 V7 @
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
7 A( w: V/ `' J3 A2 P+ S1 X - [Zcom 杂志]' ]# H x; q" A4 `7 J
- {4045D313-1D5E-4fe4-93A0-A34630B6A00B} <C:\Zcom\E-Space.exe, N/A>
& K! p. B( D7 i& q; F5 {4 H+ N$ j/ B/ d - [&Google]: k+ ?& \* \' F) r$ H5 U o; U
- {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>- M! C1 q g2 E/ X6 s6 ^0 H
- [KooPlayer Control]3 E5 M. m( g! J- p2 S) B: k
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>! R4 ^& N7 x$ y
- [Shockwave Flash Object]! B, z; }9 @; M+ E# s
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>% }5 H& e1 N3 c; Y
- [KUpdateObj2 Class]: C0 {7 O% L5 g7 b3 H% a1 s
- {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>
: a( V* G7 J8 B% |( ` - [Google Script Object]
% K5 j4 I5 a" v4 M$ E - {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
. e+ y! r5 u5 y* ] - [EWA Control]
- o) F; A! z" O' t5 _0 L4 W( G% @ - {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\PPLive\SYNACA~2.OCX, Synacast>
4 @& n! T; ]7 n - [Windows Media Player]/ ?$ b$ ]7 t q+ H4 k& O8 u
- {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>
6 ~. N; y! g- l3 V, Q8 r2 _/ N - [&Google]
9 L; `1 I# A1 O3 ~ - {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
/ H% M: c1 `6 M! l) T - [HTML Document]" v+ O" j" D5 \: \$ g
- {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
( U% s! T% d* V- `$ E - [DHTML Edit Control Safe for Scripting for IE5]- L& ]/ _% Z+ o$ ?
- {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>: o% F- z2 ^" g* z
- [RealPlayer RAM Download Handler]
% a h- {5 f" g - {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
# V' v. v& ^5 H3 m) {9 t" O - [IEBuddyExtControl Class]# r6 @5 P4 |8 ]0 B
- {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
7 Q" P# {2 A3 X5 t; q- [$ @5 ^ - [XML Document], [% q# e1 G* ^0 I% v0 N
- {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
, D1 I5 i: s$ k( g0 @ - [HHCtrl Object]
- D7 _4 d9 t5 N7 L - {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
* ]2 p6 B) K4 g, h& ^ - [Windows Media Player]( R- S+ Q9 K2 @. k2 L
- {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>7 H( M3 f; R4 V7 a
- [Active Desktop Mover]" g" B/ @0 e4 V
- {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
# V6 F: O& i7 c1 A, i$ q0 V2 @ - [360SafeLive]: B0 V, N6 v2 E
- {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360.cn>
) e1 f% q/ Y0 C0 s# Y - [Microsoft Web 浏览器]8 S0 d5 w$ x+ T- y0 Q$ }
- {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
5 U/ }3 f7 w& c& v* o - [Browser Enhanced Objects]
# l/ X0 }$ z# r/ X* p4 w - {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2011.dll, N/A>
# M" k! E/ Q7 n) y/ ?, D - [Google Toolbar Helper]$ P+ s0 \1 B6 T1 I
- {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
3 V3 T7 f/ @) Z2 r5 [9 {8 L - [Microsoft Scriptlet Component]8 m/ p/ |( r D4 C7 h/ j- V
- {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>; N' }' j% J3 V' S6 C5 J( E" |/ g
- [Google Toolbar Notifier BHO]: c( J3 k H6 Y& f
- {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>; B: Q2 v6 f1 p v* o
- [SearchAssistantOC]
& m6 E" S" q2 I- a# G% u - {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
0 i* V4 U8 |5 X( J0 d - [SafeMon Class]
' N7 c4 m) b1 x* g( z6 e - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
" f. a5 ~8 B4 F. |5 e. M - [RDS.DataSpace]2 s+ n) H0 {: ^' W
- {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>6 Q. B3 y& A) }$ J4 A
- [KooPlayer Control]7 e, o8 h! M P5 l% k
- {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <C:\WINDOWS\system32\CCTVKO~1.OCX, Koos>. b8 b4 R; v2 c$ S g) e
- [AUDIO__MID Moniker Class]8 D/ P( \1 _+ a8 _; \
- {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>3 f% Y) K; G& A1 v! x
- [AUDIO__MP3 Moniker Class]
1 X$ i# Q6 n* q - {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
) i; m1 S! l3 E4 S9 { - [AUDIO__X_MS_WMA Moniker Class]
* v/ q7 U, k7 d# K - {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation> Q. r t. G. k
- [VIDEO__X_MS_WMV Moniker Class]9 }9 L; i* b# L
- {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>; K' p& z& w/ n+ B7 O
- [RealPlayer G2 Control]
% v! @* f# O! H$ e: w0 @( h - {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
, r( r4 j/ \3 E/ c - [Shockwave Flash Object] j! d( f: k; y
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
9 o8 d& p1 N' A7 g1 j - [KUpdateObj2 Class]3 i1 Q- {5 w8 A5 E# o m( l
- {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <C:\WINDOWS\system32\KingSoft\KOS\UpdateOcx2.dll, Kingsoft Corporation>0 _* c7 F! K: b2 c- k
- [kingsoft browser shield]
3 q) O( @* @( H+ r; R% {2 g - {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>8 p! o! |% t2 |1 S* N- i4 ^8 g
- [PasswordEditCtrl Class]
q" f. x6 l: e, k7 t ? - {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
1 c2 g5 r2 {6 D1 @ - [QvodCtrl Class]3 j0 e B0 k8 r/ u) U
- {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>* Y, p J6 \2 H
- [&使用超级旋风下载]
! j# f% H9 ~' ?' N, j! g2 V - <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
1 z! @! s D0 V, ?, d - [&使用超级旋风下载全部链接]6 W2 @' L# ~$ _, ]- X8 y
- <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
% M7 i5 |. U( F - [使用迅雷下载]
# S# p8 `& e3 _' R - <, N/A>3 S2 P; a+ ~& ]2 y5 A
- [使用迅雷下载全部链接]
2 b! K$ }: n' U7 n# y- s. V4 q+ t# R2 H - <, N/A>
' b6 E" e/ R" M8 h! H - [导出到 Microsoft Office Excel(&X)]9 J X7 A7 {5 X- ]4 |/ ?7 w2 ~# I
- <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>* a% M" ~9 R% ~1 S# M6 D$ y9 [4 Y3 [% n* i
- [添加到QQ表情]
) m+ y5 R8 E% X( L$ W( T# q - <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
/ @% ]0 w8 Q/ ~$ L - ==================================
, m* c3 D2 k$ S3 R: ~ V - 正在运行的进程
3 _9 ~, `0 r5 L$ o$ _ - [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
1 a& E4 t9 ?- c- N! g+ o; k) y; ~6 e - [PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
% P" l% q% L J: w - [PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
% `1 n. d- B% N1 n* B! u/ g0 F/ ? - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
* k# ~" `8 j7 Z/ F7 ~) J - [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
+ D8 F+ T& }+ B* F- Z' ~) S - [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]% X7 V* X! ?9 a
- [PID: 720 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]) Y4 L( V, ?* @" s4 |
- [PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]; m* ` B. h: ]. K3 i' Q
- [PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
5 u, T [: s0 ^7 t2 U1 C5 Y - [PID: 944 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
" W* g# H& g( }5 Q - [PID: 1012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)], ]2 d9 r/ {; E
- [PID: 1236 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]
0 o% Z$ ]( D5 n T5 B - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
3 ? @( E5 b! S5 D - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
$ }) S0 P/ V3 q# O6 R! @* m+ n, x - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]) i* v, _4 w; B# ] q
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]9 A) S% V! Q7 L4 W. E
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL] [Kingsoft Corporation, 2008,05,07,373]
- A$ g- J' F% M5 l" p - [C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20] W x& S8 [& f2 G3 g2 x, U5 A
- [C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
9 I$ ]3 e: G7 h( p - [C:\Program Files\WinRAR\rarext.dll] [N/A, ]
; x5 O( K' v5 u+ |. w: j. N" A - [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]/ T3 E9 D/ u6 v5 C; m5 f" g" j
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
' P5 I/ ^6 K* E R- j) }; U7 ] - [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
2 j" l5 J- L/ |2 P& u - [PID: 1332 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]% |( ^4 L0 T) R- R5 x% y
- [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]# M8 ]# T7 r9 S8 C- q3 d, x# E
- [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]
: W7 r' y7 z D4 V3 F1 s - [PID: 1540 / Administrator][C:\Program Files\360safe\AntiArp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008]) a' G/ `! i& ? M2 Z: u6 o9 Y
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
( u0 [: K$ K# V7 ] - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]5 k6 Q* e3 O9 k
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]% ~ K" S! h, j
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]% S( W7 Z3 W3 ~- R. h4 k4 N
- [PID: 1560 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
9 i" z. s l T' U/ D - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
; r2 g' V$ N! J3 T. @% }0 w - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
. X3 p3 v7 Q2 P/ B4 |0 i* H- Z' V - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]& E* O" ]* h ~
- [PID: 1576 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]
. C$ x. Z A% a0 O7 b" c - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]
) p2 u# p' Z& |% } G7 ~ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]3 k; E3 N7 K1 f2 |6 Q$ Y$ W
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]9 d3 I( E$ a! m4 A. v
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]
$ [ O, [) p: W! O' J" S/ v - [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
, a7 l; x7 d! a+ i! K* _ - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
: L, N' ^2 T0 }+ D/ v/ H( G8 e# U - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
* B/ Y9 x U/ a5 {1 F5 z - [PID: 1648 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]' C. H/ R6 B9 _, s4 ]8 \
- [PID: 1744 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]
! D7 K7 Z7 b) T4 g5 J L6 C - [PID: 1860 / SYSTEM][C:\WINDOWS\system32\skeys.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]$ v, l* q6 ^5 g3 h: f0 M* K
- [PID: 1908 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
3 C r0 h, s+ ?' R$ c6 d, H - [PID: 1964 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]; @) ^ m+ Q2 {- ?7 G. {- ^, g
- [PID: 2772 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]+ J! ?$ [0 v; v% @; ]+ R& W0 |& O: [2 e5 F
- [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
( J6 w" D$ ?+ Q1 f - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
- T" ]" N9 Q% \' ^4 y i; j - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
1 A+ ~7 P6 [5 N$ O0 O - [c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1606, 6690]3 u; y. a5 C. W& x. P m. R6 P( R
- [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]( D: T4 H0 j2 i2 ?
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL] [Kingsoft Corporation, 2008,04,15,2]6 n- W% u$ H: R
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll] [Kingsoft Corporation, 2008,04,15,2]5 D% }2 W0 Y( x. {3 ?
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,05,14,83]1 u& ?8 m e- M" [
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll] [Kingsoft Corporation, 2008,04,15,2]
3 s4 P3 S$ m6 r d5 A - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL] [Kingsoft Corporation, 2008,05,13,78]) D( y ~, }# Q4 J% ?
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
& W& N) ?, \6 `& ?6 z+ ~ - [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
: z, S/ m3 a/ o( Y! S" L - [C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1], ^7 ?8 B" A! @: {8 Q
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]4 D, M$ w+ _ `! a3 i
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]$ d! c: {# B0 n1 Z
- [C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部 www.wn51.com, 2008, 3, 20, 1]7 K5 C3 h% Q6 T \% Z k
- [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]! Q! j5 y5 a9 ~* X* }
- [C:\Documents and Settings\Administrator\My Documents\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]9 t" \5 U. J$ W% B3 }6 T! r; N
- [C:\WINDOWS\system32\WINWB98.IME] [Microsoft Corporation, 4.00.950], f& p0 b+ _! u" m' Q& |$ A' J
- [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] p) J. D2 S |: b
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
' O) V( @3 D6 M$ O - [PID: 1124 / Administrator][C:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]
4 J; j' Q2 n4 ^ - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
1 D5 b0 o: \/ B# O/ c - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
! L3 E9 D9 [7 S/ t! X# [ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
% b+ h- o l7 Y' e R- T. D - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
( i' Z+ z: n2 s2 ^& q7 ^; { - [PID: 928 / Administrator][F:\arvmon.exe] [任软工作室, 2.2.5.201]
/ P" E4 p2 [7 @. W/ D- u6 ~ - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
- }0 Q& ?: p* `9 O: I' Y - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]0 n9 [9 c/ N, _' b7 i: M
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
$ A n! T a7 I2 p1 Z, w8 m - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
: X5 m) x# f- }; | - [F:\Vdata.dll] [任软工作室, 2, 2, 1, 94]- j+ x8 e* j/ u) X2 {0 n
- [PID: 2540 / Administrator][F:\AutoGuarder.exe] [任软工作室, 2.2.5.201]
: p# E: A4 x% x0 z4 l# ? - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]& F- ^; L0 y+ H* F* {/ [
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5]
4 I" a9 q6 ^ c# ~7 x( ^ - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]' N1 b* \0 g* s' g ^" q
- [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]
, w. V) V' j p+ r* b - [PID: 2476 / Administrator][d:\我的文档\桌面\系统检测修复\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
( K3 g: l+ W' }% Y4 @& T - [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
* Y6 ]2 E# @" G6 d( n( _( P - [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2008,04,02,5] D2 K' J6 @/ ?) ?7 Q E, D$ H
- [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2008,04,22,364]
, x e6 V f3 O* ]# i+ d - [C:\Program Files\Tencent\QQ\DShared.dll] [Tencent, 2, 1, 0, 0]. n B# \5 W& i, E
- [d:\我的文档\桌面\系统检测修复\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]; g6 A0 i7 u0 E# h* |3 S/ D
- ================================== d4 g$ `$ X7 O2 L: N
- 文件关联
0 A% _8 v& i1 J$ \: V( _% y - .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
+ Z; F9 f* ~" g F& c* x9 i - .EXE OK. ["%1" %*]
3 b9 _" ]/ I3 ?9 ` - .COM OK. ["%1" %*]4 ?- T/ \+ H% e* H
- .PIF OK. ["%1" %*]2 s, K- ~- O3 ~9 G& L6 a: }! h
- .REG OK. [regedit.exe "%1"]
% g* I& F8 Z8 I% w6 Z* F4 j - .BAT OK. ["%1" %*]9 j- P7 T5 Z" @" X5 o1 e# s3 c/ |3 p
- .SCR OK. ["%1" /S]0 m0 n# X3 B' n0 B% _
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]9 q7 B* l ?" M" |: W9 W
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]. o/ h) y- d2 B9 \7 r6 t
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
8 N2 D- E2 [% H( k3 D) ~$ W; F - .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]; b! F5 x0 @3 Z: J& q: S8 F! Z1 m- ~
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
5 N" l; ~5 y4 P - .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]9 @& e8 \% Y5 q/ C5 H; Z
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
* v$ P% }5 G# S1 X# d - ==================================) O" R) M; t2 q6 d, a
- Winsock 提供者4 B* e: L/ Z8 \3 }' I3 v- R" w
- N/A+ t( b2 l+ \4 O1 w' P
- ==================================
* P2 j7 L. g! ~5 {: j4 r1 i3 ? - Autorun.inf
b* A& q7 v$ d5 l' `$ T! _9 Z- K - N/A: D3 b' T% e& N- v
- ==================================
0 S0 @. g+ q( U7 c, @ - HOSTS 文件( f8 g* m* I, U |. B
- N/A( z. b! W* W- t$ d
- ==================================
" p' q8 t/ y- a - 进程特权扫描1 P. j* a% \$ @: V5 v
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 520, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]* x3 {' @& l% x+ q% q! o
- 特殊特权被允许: SeDebugPrivilege [PID = 928, F:\ARVMON.EXE]' r9 `3 E. m5 W2 X
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 928, F:\ARVMON.EXE] R9 @8 }) W3 K
- 特殊特权被允许: SeDebugPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]
4 _4 @8 p+ c/ a; M4 U - 特殊特权被允许: SeLoadDriverPrivilege [PID = 2540, F:\AUTOGUARDER.EXE]
; [8 g) A0 K+ T - ==================================& A# ^: d: a% w9 h9 d. I# \5 o
- API HOOK
( W( f. @( ^' M* V; Y) n; H& L - N/A# W5 u; h# w) v W; [6 ?9 j
- ==================================
y! d% W+ ^4 i. `8 w# r - 隐藏进程
' W$ P+ ~1 P4 d& M5 [ - N/A4 N0 P, ^" P0 P4 Z) z
- ==================================, W$ W+ y# I! ]! k2 d! m) \
: l8 \4 o- _3 `6 m- E; G- t o( O
复制代码 |
|