瑞星卡卡安全论坛
自在自我 - 2005-11-24 16:02:00
在启动IE的时候总是弹出IE广告窗口,如:http://ilead.itrack.it/ 及上海协和医院的广告.
我用SRENG扫描了日志如下,请高手帮忙诊断,谢谢.
2005-11-24,15:50:13
System Repair Engineer 1.1.0.269
Windows XP Professional Service Pack 2 - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<msnmsgr><; "C:\Program Files\MSN Messenger\msnmsgr.exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Yahoo! Pager><; C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe -quiet>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<kuco download><"C:\Program Files\虚拟城市\setup\DD1.exe">
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ATIModeChange><Ati2mdxx.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Cpqset><C:\Program Files\HPQ\Default Settings\cpqset.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SynTPLpr><C:\Program Files\Synaptics\SynTP\SynTPLpr.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<hkss><C:\Program Files\Compaq\Hotkey Software\hkss.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<AGRSMMSG><AGRSMMSG.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<AClntUsr><C:\Program Files\Altiris\AClient\AClntUsr.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ChkAdmin><C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<eabconfg.cpl><C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<vptray><C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<POPO2004><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<yassistse><"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NeroFilterCheck><C:\WINDOWS\system32\NeroCheck.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<CertificateRegistration><SafeSignCertReg.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<sysupate><C:\WINDOWS\system32\NtSysUpdate.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<setup><C:\Program Files\虚拟城市\setup\gr80.exe 00020502>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<CPQDFWAG><C:\WINDOWS\Cpqdiag\CpqDfwAg.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
==================================
启动文件夹
[Microsoft Office]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk><N>
[娱乐心空]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\娱乐心空.lnk><N>
==================================
服务
[Altiris Client Service / AClient]
<C:\Program Files\Altiris\AClient\AClient.exe -service><Altiris, Inc.>
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\System32\Ati2evxx.exe><N/A>
[Insight Local Alerter / CPQALERT]
<C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe><Hewlett-Packard Company>
[cpqdmi / cpqdmi]
<C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe><Compaq Computer Corporation>
[Insight Web Agent / cpqWebDmi]
<C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe><Hewlett-Packard Company>
[DefWatch / DefWatch]
<"C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[Remote Diagnostics Enabling Agent / DfwWebAgent]
<C:\WINDOWS\Cpqdiag\Cpqdfwag.exe><Hewlett-Packard>
[Hibernation / Hibernation]
<C:\PROGRA~1\Compaq\COMPAQ~2\hibserv.exe><N/A>
[Macromedia Licensing Service / Macromedia Licensing Service]
<"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[Symantec AntiVirus Client / Norton AntiVirus Server]
<"C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>
[RegSrvc / RegSrvc]
<C:\WINDOWS\System32\RegSrvc.exe><Intel Corporation>
[Spectrum24 Event Monitor / S24EventMonitor]
<C:\WINDOWS\System32\S24EvMon.exe><Intel Corporation >
[SoundMAX Agent Service / SoundMAX Agent Service (default)]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[WIN32SL / WIN32SL]
<C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe><Intel>
自在自我 - 2005-11-24 16:04:00
==================================
浏览器加载项
[AcroIEHlprObj Class]
<C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll>
[i&Bar搜索引擎]
<C:\PROGRA~1\iBar\10002\iBar.dll>
[Yahoo!Photo]
<C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll>
[AntiFish Class]
<C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll>
[雅虎助手]
<C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll>
[WsftpBrowserHelper Class]
<C:\Program Files\Ipswitch\WS_FTP Pro\wsbho2k0.dll>
[DragSearch BHO]
<C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL>
[MMSAssist BHO]
<C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL>
[std software]
<C:\WINDOWS\system32\stdup.dll>
[IeCatch2 Class]
<C:\PROGRA~1\FLASHGET\jccatch.dll>
[]
<C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX>
[常用网址]
<C:\WINDOWS\system32\SHDOCVW.DLL>
[MMSAssistMenu]
<C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL>
[FlashGet]
<C:\PROGRA~1\FLASHGET\flashget.exe>
[Yahoo! Messenger]
<C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE>
[Messenger]
<C:\Program Files\Messenger\msmsgs.exe>
[FlashGet Bar]
<C:\PROGRA~1\FLASHGET\fgiebar.dll>
[BitCometBar]
<C:\Program Files\BitComet\BitCometBar\BitCometBar0.2.dll>
[雅虎助手]
<C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll>
[i&Bar搜索引擎]
<C:\PROGRA~1\iBar\10002\iBar.dll>
[Edit Class]
<C:\WINDOWS\system32\CMBEdit.dll>
[MSN Photo Upload Tool]
<C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll>
[Java Plug-in 1.4.2]
<C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll>
[Shockwave Flash Object]
<C:\WINDOWS\system32\macromed\flash\Flash.ocx>
[AcroIEHlprObj Class]
<C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll>
[Edit Class]
<C:\WINDOWS\system32\CMBEdit.dll>
[Windows Media Player]
<C:\WINDOWS\system32\wmpdxm.dll>
[i&Bar搜索引擎]
<C:\PROGRA~1\iBar\10002\iBar.dll>
[Tabular Data Control]
<C:\WINDOWS\System32\tdc.ocx>
[Yahoo!Photo]
<C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll>
[AntiFish Class]
<C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll>
[BitCometBar]
<C:\Program Files\BitComet\BitCometBar\BitCometBar0.2.dll>
[雅虎助手]
<C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll>
[MSN Photo Upload Tool]
<C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll>
[Shell Name Space]
<%SystemRoot%\System32\shdocvw.dll>
[AutoLive]
<C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll>
[WsftpBrowserHelper Class]
<C:\Program Files\Ipswitch\WS_FTP Pro\wsbho2k0.dll>
[DragSearch BHO]
<C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL>
[MMSAssist BHO]
<C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL>
[std software]
<C:\WINDOWS\system32\stdup.dll>
[Windows Media Player]
<C:\WINDOWS\system32\wmp.dll>
[Microsoft Web 浏览器]
<C:\WINDOWS\System32\shdocvw.dll>
[IeCatch2 Class]
<C:\PROGRA~1\FLASHGET\jccatch.dll>
[]
<C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX>
[Microsoft Scriptlet Component]
<C:\WINDOWS\System32\mshtml.dll>
[SearchAssistantOC]
<%SystemRoot%\System32\shdocvw.dll>
[Adobe Acrobat Control for ActiveX]
<C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\ActiveX\pdf.ocx>
[AUDIO__MP3 Moniker Class]
<C:\WINDOWS\system32\wmp.dll>
[AUDIO__WAV Moniker Class]
<C:\WINDOWS\system32\wmp.dll>
[Shockwave Flash Object]
<C:\WINDOWS\system32\macromed\flash\Flash.ocx>
[FlashGet Bar]
<C:\PROGRA~1\FLASHGET\fgiebar.dll>
[ >> 彩信发送 <<]
<res://C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL/mms.htm>
[使用KuGoo3下载(&K)]
<C:\Program Files\KuGoo3\KuGoo3DownX.htm>
[使用网际快车下载]
<C:\Program Files\FlashGet\jc_link.htm>
[使用网际快车下载全部链接]
<C:\Program Files\FlashGet\jc_all.htm>
[导出到 Microsoft Excel(&x)]
<res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000>
[雅虎搜索]
<res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246>
文雷 - 2005-11-24 16:06:00
用卡卡助手修复以下
自在自我 - 2005-11-24 16:06:00
==================================
正在运行的进程
[PID: 604][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 680][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 704][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\NavLogon.dll] <N/A><N/A>
[PID: 748][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 760][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 912][C:\WINDOWS\System32\Ati2evxx.exe] <N/A><N/A>
[PID: 924][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1004][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1096][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1140][C:\WINDOWS\System32\S24EvMon.exe] <Intel Corporation ><8, 1, 0, 49a>
[PID: 1236][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1348][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1800][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll] <N/A><2, 0, 3, 1028>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] < ><2, 0, 0, 1006>
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] <Adobe Systems Incorporated><6.0.0.2003051500>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll] <Yahoo! China><1, 0, 2, 1015>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll] <Yahoo!><2, 0, 3, 1023>
[C:\Program Files\Ipswitch\WS_FTP Pro\wsbho2k0.dll] <Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421><9,0,0,0>
[C:\Program Files\Ipswitch\WS_FTP Pro\wsftpext.dll] <Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421><9,0,0,0>
[C:\Program Files\Ipswitch\WS_FTP Pro\LIBEAY32.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\SSLEAY32.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\sslsvc.dll] <Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421><9,0,0,0>
[C:\Program Files\Ipswitch\WS_FTP Pro\wsftplib.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\wsfirscr.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\wshosts.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\ipspgp.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\res0409.dll] <Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421><9,0,0,0>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] <N/A><1, 2, 7, 1006>
[C:\PROGRA~1\FLASHGET\jccatch.dll] <Amaze Soft><1, 1, 4, 0>
[C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] <N/A><N/A>
[C:\Program Files\Compaq\Hotkey Software\hksshook.dll] <Compaq Computer Corporation><1.1.D3>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll] <N/A><1, 0, 0, 1013>
[C:\Program Files\Ipswitch\WS_FTP Pro\wsftpsi.dll] <Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421><9,0,0,0>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll] <Symantec Corporation><8.00.00.9374>
[C:\Program Files\Real\RealPlayer\rpshell.dll] <RealNetworks, Inc.><1.0.1.2021>
[C:\WINDOWS\system32\PNCRT.dll] <Real Networks, Inc><6.0.0.0>
[C:\Program Files\Real\RealPlayer\lang\rpext_cn.dll] <RealNetworks, Inc.><6.0.12.298>
[C:\Program Files\Tencent\TM\TMDlls\QQHook.dll] <N/A><N/A>
[PID: 1820][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll] <Windows (R) 2000 DDK provider><5.00.2195.1620>
[PID: 1892][C:\WINDOWS\System32\SCardSvr.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1988][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe] <ATI Technologies, Inc.><6.14.10.5072>
[C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll] <ATI Technologies, Inc.><6.14.10.5072>
[C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.CHS] <ATI Technologies, Inc.><6.14.10.5072>
[C:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll] <ATI Technologies, Inc.><6.14.10.5072>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[PID: 2008][C:\Program Files\Synaptics\SynTP\SynTPLpr.exe] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[PID: 2016][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\WINDOWS\System32\SynCOM.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\WINDOWS\system32\SynTPAPI.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[PID: 2024][C:\Program Files\Compaq\Hotkey Software\hkss.exe] <Compaq Computer Corporation><1.1.E1>
[C:\Program Files\Compaq\Hotkey Software\support.dll] <Compaq Computer Corporation><1.1.E1>
[C:\Program Files\Compaq\Hotkey Software\hksshook.dll] <Compaq Computer Corporation><1.1.D3>
[PID: 2032][C:\WINDOWS\AGRSMMSG.exe] <Agere Systems><2.1.28 2.1.28 03/31/2003 13:54:16>
[PID: 172][C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE] <Hewlett-Packard Company><5.0.9.1>
[PID: 192][C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe] <Hewlett-Packard ><4, 10, 4, 1>
[C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL] <Hewlett-Packard ><4, 10, 4, 1>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\Program Files\HPQ\Quick Launch Buttons\HPQQL.DLL] <Hewlett-Packard><4, 0, 2, 1>
[C:\Program Files\HPQ\Quick Launch Buttons\HPQPWR.DLL] <Hewlett-Packard><4, 10, 1, 2>
[C:\Program Files\HPQ\Quick Launch Buttons\HPQPRES.DLL] <Hewlett-Packard><4, 10, 3, 2>
[PID: 208][C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe] <Symantec Corporation><8.00.00.9374>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Cliscan.dll] <Symantec Corporation><8.00.00.9374>
[C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVNTUTL.DLL] <Symantec/Peter Norton Group><1, 0, 0, 1>
[PID: 220][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3292>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[PID: 244][C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe] < ><2, 0, 0, 1002>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll] <N/A><2, 0, 3, 1028>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] < ><2, 0, 0, 1006>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[PID: 184][C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe] <Yahoo!><1, 0, 1, 1001>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\PROGRA~1\Yahoo!\Assistant\shell\yAssecblk.dll] <Yahoo><1, 0, 1, 1001>
[C:\PROGRA~1\Yahoo!\Assistant\shell\yAsMenu.dll] <Yahoo><1, 0, 1, 1006>
自在自我 - 2005-11-24 16:07:00
[C:\PROGRA~1\Yahoo!\Assistant\shell\yIEAngel.dll] <Yahoo><1, 0, 1, 1001>
[C:\PROGRA~1\Yahoo!\Assistant\shell\yMenuInfo.dll] <Yahoo><1, 0, 0, 2>
[PID: 284][C:\WINDOWS\system32\SafeSignCertReg.exe] <A.E.T. Europe B.V.><2.0.0.2>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[PID: 292][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[PID: 884][C:\Program Files\Altiris\AClient\AClient.exe] <Altiris, Inc.><5.6.72>
[PID: 968][C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe] <Hewlett-Packard Company><5.0.9.1>
[C:\Program Files\Compaq\Compaq Management Agents\CPQHCI.DLL] <Compaq Computer Corporation><5.0.9.1>
[C:\Program Files\Compaq\Compaq Management Agents\CPQDMSC.DLL] <Compaq Computer Corporation><5.0.9.1>
[PID: 1044][C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe] <Hewlett-Packard Company><5.0.9.1>
[C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\DMIAGENT.dll] <Hewlett-Packard Company><5.0.9.1>
[C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WCDMI.dll] <Intel><2, 0, 0, 54>
[C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WDMIUTIL.dll] <Intel><2, 0, 0, 54>
[C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\CpqHMMO.dll] <Compaq Computer Corp.><3.7.0>
[PID: 1060][C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe] <Symantec Corporation><8.00.00.9374>
[PID: 1084][C:\WINDOWS\Cpqdiag\Cpqdfwag.exe] <Hewlett-Packard><3.02.2005>
[C:\WINDOWS\Cpqdiag\CPQHMMO.DLL] <Compaq Computer Corp.><3.7.0>
[PID: 1188][C:\PROGRA~1\Compaq\COMPAQ~2\hibserv.exe] <N/A><4.10.3.1>
[PID: 1388][C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe] <Symantec Corporation><8.00.00.9374>
[C:\WINDOWS\system32\CBA.DLL] <Intel? Corporation><6.12.0.71 E>
[C:\WINDOWS\system32\MsgSys.dll] <Intel? Corporation><6.12.0.71 E>
[C:\WINDOWS\system32\NTS.dll] <Intel? Corporation><6.12.0.71 E>
[C:\WINDOWS\system32\PDS.DLL] <Intel? Corporation><6.12.0.71 E>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVLU.dll] <Symantec Corporation><8.00.00.9374>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVNTUTL.DLL] <Symantec/Peter Norton Group><1, 0, 0, 1>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\i2ldvp3.dll] <Symantec Corporation><8.00.00.9374>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPI32.DLL] <Symantec Corp.><4.1.0.15>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20051116.024\NAVEX32a.DLL] <Symantec Corporation><20051.3.0.16>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20051116.024\NAVENG32.DLL] <Symantec Corporation><20051.3.0.16>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAP32.DLL] <Symantec Corporation><9.0.0.14>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vpmsece.dll] <Symantec Corporation><8.00.00.9374>
[PID: 1424][C:\WINDOWS\System32\RegSrvc.exe] <Intel Corporation><8, 1, 0, 49a>
[PID: 476][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] <Analog Devices, Inc.><3, 2, 6, 0>
[PID: 492][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 496][C:\WINDOWS\system32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 596][C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe] <Intel><2, 0, 0, 54>
[C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\WSDMIDCE.DLL] <Intel><2, 0, 0, 54>
[C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\WDMIUTIL.dll] <Intel><2, 0, 0, 54>
[C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\WDMI2API.dll] <Intel><2, 0, 0, 54>
[C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\DMIAPI32.DLL] <N/A><2, 0, 0, 54>
[PID: 2168][C:\WINDOWS\system32\wscntfy.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[PID: 2280][C:\Program Files\Altiris\AClient\AClntUsr.exe] <N/A><5, 6, 0, 50>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[PID: 2296][C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe] <Compaq Computer Corporation><5.0.9.1>
[C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\Bin\DMIAPI32.dll] <N/A><2, 0, 0, 54>
[C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\Bin\WCDMI.dll] <Intel><2, 0, 0, 54>
[C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\Bin\WDMIUTIL.dll] <Intel><2, 0, 0, 54>
[C:\PROGRA~1\Compaq\COMPAQ~1\CPQHCI.DLL] <Compaq Computer Corporation><5.0.9.1>
[C:\PROGRA~1\Compaq\COMPAQ~1\CPQDMSC.DLL] <Compaq Computer Corporation><5.0.9.1>
[C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\Bin\WDMI2API.DLL] <Intel><2, 0, 0, 54>
[C:\PROGRA~1\Compaq\COMPAQ~1\CPQCI.DLL] <Compaq Computer Corporation><5.0.9.1>
[C:\PROGRA~1\Compaq\COMPAQ~1\CPQVID.DLL] <Compaq Computer Corporation><5.0.9.1>
[C:\PROGRA~1\Compaq\COMPAQ~1\CpqAoLAN.DLL] <N/A><N/A>
[PID: 2608][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3264][C:\Program Files\MSN Messenger\msnmsgr.exe] <Microsoft Corporation><7.5.0311>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\Program Files\Compaq\Hotkey Software\hksshook.dll] <Compaq Computer Corporation><1.1.D3>
[C:\WINDOWS\system32\msdmo.dll] <N/A><N/A>
[C:\Program Files\Tencent\TM\TMDlls\QQHook.dll] <N/A><N/A>
[C:\WINDOWS\system32\JPWB.IME] <常诚研制><4.00.950>
[PID: 1688][C:\Program Files\Netease\popo2004\popo.exe] <网易(163.com)><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\XGDI.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\XFile.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\P2PMgr.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\XComm.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\Trace.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\Updater.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\UNZIP32.dll] <Info-ZIP><5.5>
[C:\Program Files\Netease\popo2004\ResLoc.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\MailChecker.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\ExtraEditor.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\XMP.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\fmod.dll] <Firelight Technologies Pty, Ltd><3.73>
[C:\Program Files\Netease\popo2004\UrlObj.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\Bobo.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\SOX.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\share.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\XVideo.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\VCodec.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\XVoice.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\XEmotion.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\MsgHis.dll] <N/A><1, 0, 0, 1>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\Program Files\Netease\popo2004\plugins\MSN.DLL] <N/A><1, 0, 0, 1>
[C:\Program Files\Netease\popo2004\plugins\LIBCURL.dll] <N/A><N/A>
[C:\Program Files\Netease\popo2004\plugins\SSLEAY32.dll] <N/A><N/A>
[C:\Program Files\Netease\popo2004\plugins\LIBEAY32.dll] <N/A><N/A>
[C:\Program Files\Tencent\TM\TMDlls\QQHook.dll] <N/A><N/A>
[C:\Program Files\Compaq\Hotkey Software\hksshook.dll] <Compaq Computer Corporation><1.1.D3>
[C:\WINDOWS\system32\JPWB.IME] <常诚研制><4.00.950>
[PID: 456][C:\Program Files\Tencent\TM\TMDLLs\TIMPlatform.exe] <tencent><2.05>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\Program Files\Tencent\TM\TMDLLs\TIMProxy.dll] <tencent><2.05>
[PID: 524][C:\Program Files\虚拟城市\setup\DD1.exe] <N/A><N/A>
[PID: 2740][C:\Program Files\Tencent\TM\TMDlls\TM.exe] <N/A><N/A>
[C:\Program Files\Tencent\TM\TMDlls\BasicCtrlDll.dll] <Tencent><2.08>
[C:\Program Files\Tencent\TM\TMDlls\QQBaseClassInDll.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Tencent\TM\TMDlls\QQHelperDll.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Tencent\TM\TMDlls\QQZip.dll] <tencent><2.05>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\Program Files\Tencent\TM\TMDlls\ImageOle.dll] <TODO: <Company name>><1.0.0.1>
[C:\Program Files\Tencent\TM\TMDlls\QQAPI.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Tencent\TM\TMDLLs\TIMProxy.dll] <tencent><2.05>
[C:\Program Files\Tencent\TM\TMDlls\QQRes.dll] <N/A><N/A>
[C:\Program Files\Tencent\TM\TMDlls\LoginCtrl.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Tencent\TM\TMDlls\HostingMgr.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Compaq\Hotkey Software\hksshook.dll] <Compaq Computer Corporation><1.1.D3>
自在自我 - 2005-11-24 16:07:00
[C:\Program Files\Tencent\TM\TMDlls\WizardCtrl.dll] <Tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\TM\TMDlls\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\TM\TMDlls\LongConnection.dll] <tencent><2.08>
[C:\Program Files\Tencent\TM\TMDlls\QQConfigPlugin.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Tencent\TM\TMDlls\CameraDll.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Tencent\TM\TMDlls\RemoteHelp.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Tencent\TM\TMDlls\CommercesMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\TM\TMDlls\QQAllInOne.dll] <N/A><N/A>
[C:\Program Files\Tencent\TM\TMDlls\QQGroupMng.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Tencent\TM\TMDlls\GroupConnection.dll] <Tencent><2.08>
[C:\Program Files\Tencent\TM\TMDlls\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\TM\TMDlls\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\TM\TMDlls\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\TM\TMDlls\NewSkin.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Tencent\TM\TMDlls\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\Program Files\Tencent\TM\TMDlls\FrameBar.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Tencent\TM\TMDlls\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\TM\TMDlls\ShareDoc.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Tencent\TM\TMDlls\QQHook.dll] <N/A><N/A>
[C:\Program Files\Tencent\TM\TMDlls\VideoDevice.dll] <Tencent><1.3.7.8>
[C:\Program Files\Tencent\TM\TMDlls\InPlus.dll] <Tencent><1.3.7.8>
[C:\WINDOWS\system32\msdmo.dll] <N/A><N/A>
[C:\WINDOWS\system32\JPWB.IME] <常诚研制><4.00.950>
[C:\Program Files\Tencent\TM\TMDlls\UserFinger.dll] <N/A><1, 0, 0, 1>
[C:\Program Files\Tencent\TM\TMDlls\QQFileTransfer.dll] <Tencent><2.08>
[C:\Program Files\Tencent\TM\TMDlls\MUserApplication.dll] <N/A><N/A>
[PID: 2600][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll] <Yahoo><1, 0, 1, 1000>
[C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll] <N/A><2, 0, 3, 1028>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] < ><2, 0, 0, 1006>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll] <Yahoo!><2, 0, 3, 1023>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yaswiper.dll] <Yahoo><1, 0, 1, 1004>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasiesec.dll] <Yahoo><1, 0, 1, 1000>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll] <N/A><1, 0, 0, 9>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yzsNetProto.dll] <Yahoo><1, 0, 0, 1>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll] <Yahoo! China><1, 0, 2, 1015>
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] <Adobe Systems Incorporated><6.0.0.2003051500>
[C:\PROGRA~1\iBar\10002\iBar.dll] <N/A><N/A>
[C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll] <Yahoo.><1, 0, 1, 1001>
[C:\Program Files\Ipswitch\WS_FTP Pro\wsbho2k0.dll] <Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421><9,0,0,0>
[C:\Program Files\Ipswitch\WS_FTP Pro\wsftpext.dll] <Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421><9,0,0,0>
[C:\Program Files\Ipswitch\WS_FTP Pro\LIBEAY32.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\SSLEAY32.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\sslsvc.dll] <Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421><9,0,0,0>
[C:\Program Files\Ipswitch\WS_FTP Pro\wsftplib.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\wsfirscr.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\wshosts.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\ipspgp.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\res0409.dll] <Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421><9,0,0,0>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] <N/A><1, 2, 7, 1006>
[C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL] <N/A><1, 1, 0, 1>
[C:\WINDOWS\System32\stdup.dll] <AOL Corp.><3, 1, 0, 1>
[C:\PROGRA~1\FLASHGET\jccatch.dll] <Amaze Soft><1, 1, 4, 0>
[C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] <N/A><N/A>
[C:\Program Files\Tencent\TM\TMDlls\QQHook.dll] <N/A><N/A>
[C:\Program Files\Compaq\Hotkey Software\hksshook.dll] <Compaq Computer Corporation><1.1.D3>
[c:\progra~1\yahoo!\assist~1\assist\yadfil~1.dll] < ><1, 0, 1, 6>
[C:\PROGRA~1\yahoo!\assistant\Shell\yAssecblk.dll] <Yahoo><1, 0, 1, 1001>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yoptimum.dll] <Yahoo><1, 0, 1, 1001>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrepair.dll] <Yahoo><1, 0, 4, 1001>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasfsks.dll] <3721.com><2, 1, 1, 87>
[C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll] <JavaSoft / Sun Microsystems, Inc.><1, 4, 2, 0>
[C:\Program Files\Java\j2re1.4.2\bin\jpiexp32.dll] <JavaSoft / Sun Microsystems><1, 4, 2, 0>
[C:\Program Files\Java\j2re1.4.2\bin\jpishare.dll] <N/A><1, 4, 2, 0>
自在自我 - 2005-11-24 16:08:00
[C:\PROGRA~1\Java\J2RE14~1.2\bin\client\jvm.dll] <N/A><N/A>
[C:\PROGRA~1\Java\J2RE14~1.2\bin\hpi.dll] <N/A><N/A>
[C:\PROGRA~1\Java\J2RE14~1.2\bin\verify.dll] <N/A><N/A>
[C:\PROGRA~1\Java\J2RE14~1.2\bin\java.dll] <N/A><N/A>
[C:\PROGRA~1\Java\J2RE14~1.2\bin\zip.dll] <N/A><N/A>
[C:\Program Files\Java\j2re1.4.2\bin\awt.dll] <N/A><N/A>
[C:\Program Files\Java\j2re1.4.2\bin\fontmanager.dll] <N/A><N/A>
[C:\Program Files\Java\j2re1.4.2\bin\jpicom32.dll] <N/A><1, 4, 2, 0>
[PID: 3160][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll] <Yahoo><1, 0, 1, 1000>
[C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll] <N/A><2, 0, 3, 1028>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] < ><2, 0, 0, 1006>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll] <Yahoo!><2, 0, 3, 1023>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yaswiper.dll] <Yahoo><1, 0, 1, 1004>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasiesec.dll] <Yahoo><1, 0, 1, 1000>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll] <N/A><1, 0, 0, 9>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yzsNetProto.dll] <Yahoo><1, 0, 0, 1>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll] <Yahoo! China><1, 0, 2, 1015>
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] <Adobe Systems Incorporated><6.0.0.2003051500>
[C:\PROGRA~1\iBar\10002\iBar.dll] <N/A><N/A>
[C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll] <Yahoo.><1, 0, 1, 1001>
[C:\Program Files\Ipswitch\WS_FTP Pro\wsbho2k0.dll] <Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421><9,0,0,0>
[C:\Program Files\Ipswitch\WS_FTP Pro\wsftpext.dll] <Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421><9,0,0,0>
[C:\Program Files\Ipswitch\WS_FTP Pro\LIBEAY32.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\SSLEAY32.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\sslsvc.dll] <Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421><9,0,0,0>
[C:\Program Files\Ipswitch\WS_FTP Pro\wsftplib.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\wsfirscr.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\wshosts.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\ipspgp.dll] <N/A><N/A>
[C:\Program Files\Ipswitch\WS_FTP Pro\res0409.dll] <Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421><9,0,0,0>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] <N/A><1, 2, 7, 1006>
[C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL] <N/A><1, 1, 0, 1>
[C:\WINDOWS\system32\stdup.dll] <AOL Corp.><3, 1, 0, 1>
[C:\PROGRA~1\FLASHGET\jccatch.dll] <Amaze Soft><1, 1, 4, 0>
[C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] <N/A><N/A>
[C:\Program Files\Tencent\TM\TMDlls\QQHook.dll] <N/A><N/A>
[C:\Program Files\Compaq\Hotkey Software\hksshook.dll] <Compaq Computer Corporation><1.1.D3>
[C:\WINDOWS\system32\JPWB.IME] <常诚研制><4.00.950>
[C:\Program Files\Yahoo!\Assistant\Assist\yeheocx.dll] <N/A><9, 0, 0, 9>
[c:\progra~1\yahoo!\assist~1\assist\yadfil~1.dll] < ><1, 0, 1, 6>
[C:\PROGRA~1\yahoo!\assistant\Shell\yAssecblk.dll] <Yahoo><1, 0, 1, 1001>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yoptimum.dll] <Yahoo><1, 0, 1, 1001>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrepair.dll] <Yahoo><1, 0, 4, 1001>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasfsks.dll] <3721.com><2, 1, 1, 87>
[PID: 2368][C:\Program Files\FlashGet\flashget.exe] <Amaze Soft><0, 1, 1, 0>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\WINDOWS\system32\CD_Clint.dll] < ><3, 2, 1, 6>
[C:\Program Files\Tencent\TM\TMDlls\QQHook.dll] <N/A><N/A>
[C:\Program Files\Compaq\Hotkey Software\hksshook.dll] <Compaq Computer Corporation><1.1.D3>
[PID: 1168][C:\Program Files\GlobalSCAPE\CuteFTP Pro\cftppro.exe] <GlobalSCAPE, Inc.><3, 0, 0, 3>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\Program Files\GlobalSCAPE\CuteFTP Pro\TE\Compress.dll] <GlobalSCAPE, Inc.><3, 0, 0, 3>
[C:\Program Files\Tencent\TM\TMDlls\QQHook.dll] <N/A><N/A>
[C:\Program Files\Compaq\Hotkey Software\hksshook.dll] <Compaq Computer Corporation><1.1.D3>
[PID: 148][C:\Program Files\GlobalSCAPE\CuteFTP Pro\TE\ftpte.exe] <GlobalSCAPE, Inc.><3, 0, 0, 3>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\Program Files\GlobalSCAPE\CuteFTP Pro\TE\FolderMonitor.dll] <GlobalSCAPE, Inc.><3, 0, 0, 3>
[C:\Program Files\GlobalSCAPE\CuteFTP Pro\TE\SiteBackup.dll] <GlobalSCAPE, Inc.><3, 0, 0, 1>
[C:\Program Files\Tencent\TM\TMDlls\QQHook.dll] <N/A><N/A>
[PID: 3556][E:\software\工具\SREng.exe] <Smallfrogs Studio><1.1.0.269>
[C:\WINDOWS\system32\SynTPFcs.dll] <Synaptics, Inc.><7.5.18.1 15Jul03>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <N/A><2, 0, 0, 1013>
[C:\Program Files\Tencent\TM\TMDlls\QQHook.dll] <N/A><N/A>
==================================
文件关联
.TXT OK. [C:\WINDOWS\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [C:\WINDOWS\system32\winhlp32.exe %1]
.INI OK. [C:\WINDOWS\system32\NOTEPAD.EXE %1]
.INF OK. [C:\WINDOWS\system32\NOTEPAD.EXE %1]
==================================
airplane - 2005-11-24 17:00:00
中广告类的木马啦,用微点主动防御软件试试
下载地址:http://download.micropoint.com.cn
hihiu - 2005-11-26 11:15:00
1
© 2000 - 2026 Rising Corp. Ltd.