geminillc - 2006-10-4 8:33:00
==================================
驱动程序
[adpu160m / adpu160m]
<C:\WINDOWS\SYSTEM32\DRIVERS\adpu160m.SYS><Adaptec, Inc.>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[Cdsys / Cdsys]
<\??\C:\WINDOWS\system32\cdcd.sys><N/A>
[cigdijig / cigdijig]
<\SystemRoot\system32\drivers\cigdijig.sys><中国互联网络信息中心(CNNIC)>
[ddhchjfg / ddhchjfg]
<\SystemRoot\system32\drivers\ddhchjfg.sys><中国互联网络信息中心(CNNIC)>
[dpti2o / dpti2o]
<C:\WINDOWS\SYSTEM32\DRIVERS\dpti2o.SYS><Adaptec, Inc.>
[ewido anti-spyware 4.0 driver / ewido anti-spyware 4.0 driver]
<\??\D:\杀毒软件\ewido_4.0.0.172c_3.32\ewido_4.0.0.172c_3.3\guard.sys><N/A>
[fsprot / fsprot]
<system32\drivers\fsprot.sys><Microsoft Corporation>
[iadahcfe / iadahcfe]
<\SystemRoot\system32\drivers\iadahcfe.sys><中国互联网络信息中心(CNNIC)>
[ifhbjacc / ifhbjacc]
<\SystemRoot\system32\drivers\ifhbjacc.sys><中国互联网络信息中心(CNNIC)>
[iijageef / iijageef]
<\SystemRoot\system32\drivers\iijageef.sys><中国互联网络信息中心(CNNIC)>
[KNetWch / KNetWch]
<\??\C:\KAV2006\KNetWch.SYS><Kingsoft Corporation>
[KWatch3 / KWatch3]
<\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
[laamrw / laamrw]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\laamrwria><N/A>
[moprot / moprot]
<system32\drivers\moprot.sys><Windows System Internal>
[mraid35x / mraid35x]
<C:\WINDOWS\SYSTEM32\DRIVERS\mraid35x.SYS><LSI Logic Corporation>
[npkcrypt / npkcrypt]
<\??\D:\QQ\npkcrypt.sys><N/A>
[nv / nv]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Service for NVIDIA(R) nForce(TM) MIDI UART / nvmpu401]
<system32\drivers\nvmpu401.sys><NVIDIA Corporation>
[nwlnksipx / nwlnksipx]
<\??\C:\WINDOWS\system32\drivers\nwlnksipx.sys><Microsoft Corporation>
[perc2 / perc2]
<C:\WINDOWS\SYSTEM32\DRIVERS\perc2.SYS><Adaptec, Inc.>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver / RTL8023xp]
<system32\DRIVERS\Rtlnicxp.sys><Realtek Semiconductor Corporation>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
<system32\DRIVERS\secdrv.sys><N/A>
[USB PC Camera (SNPSTD3) / SNPSTD3]
<system32\DRIVERS\snpstd3.sys><>
[TCP/IP Protocol Driver / Tcpip]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[ur / ur]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ursux><N/A>
==================================
浏览器加载项
[MonitorURL Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, N/A>
[CAdLogic Object]
{11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\CPUSH\cpush.dll, N/A>
[MyIEHelper Class]
{16B770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5107.dll, Microsoft Corporation>
[]
{2A4956FD-BE98-4104-ABEB-97029B3175BB} <C:\WINDOWS\system32\sys32dev.dll, N/A>
[google bar]
{3020C3F1-744B-4C9E-8404-DBCD3705D6A9} <C:\WINDOWS\Win32ef.dll, N/A>
[SYM]
{36BF6929-DCBC-4CCD-A620-C5E3BBA77B95} <C:\WINDOWS\system32\usercrd.dll, >
[SafeMe Internet Explorer Helper]
{3AE06CEE-58A6-4F5F-AF89-6C5350842F16} <C:\WINDOWS\system32\SafeHelper12.dll, LINKMEDIA Tech>
[raObject Class]
{46F194EB-B7DB-4B7A-BD42-5FF39FD17664} <C:\PROGRA~1\pcast\hbcast.dll, N/A>
[ShowBarEx Class]
{9411F42F-09FF-4FB5-ADD3-30ECAC43DC51} <C:\WINDOWS\system32\QQ3818~1.DLL, >
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[XBTP03129 Class]
{B07D1F6B-6B8C-4904-8EE8-5E5A2B4624B3} <C:\PROGRA~1\MICRSO~1\SEARCH~1.DLL, IE Toolbar>
[信息检索]
{CE7C3CF0-98A8-474D-B2B5-1ED7E2E3B004} <C:\WINDOWS\system32\IEHelper.dll, N/A>
[]
{FFFFFFFF-74CC-4B7C-B5F1-45913F368388} <C:\PROGRA~1\SYSTEM~1\SYSTEM~1.DLL, N/A>
[]
{1D901067-2529-4A9B-9B6B-7A1DB3A44CB5} <C:\Program Files\coolsign\coolsign.dll, Fengcent>
[易趣购物]
{DE607144-AC19-424e-861A-1D70ABDF119A} <http://click2.ad4all.net/url2/urlmanage/url.asp?id=5, N/A>
[5940.cn导航]
{6144F1E9-C6D4-4FF3-9008-AA43F3D287AC} <C:\WINDOWS\system32\QQ3818~1.DLL, >
[Micrsoft SearchBar]
{6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89} <C:\Program Files\Micrsoft SearchBar\SearchBar.dll, N/A>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[MonitorURL Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, N/A>
[CAdLogic Object]
{11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\CPUSH\cpush.dll, N/A>
[MyIEHelper Class]
{16B770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5107.dll, Microsoft Corporation>
[Windows Genuine Advantage]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.dll, Microsoft? Corporation>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[]
{2A4956FD-BE98-4104-ABEB-97029B3175BB} <C:\WINDOWS\system32\sys32dev.dll, N/A>
[google bar]
{3020C3F1-744B-4C9E-8404-DBCD3705D6A9} <C:\WINDOWS\Win32ef.dll, N/A>
[Tabular Data Control]
{333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[SYM]
{36BF6929-DCBC-4CCD-A620-C5E3BBA77B95} <C:\WINDOWS\system32\usercrd.dll, >
[SafeMe Internet Explorer Helper]
{3AE06CEE-58A6-4F5F-AF89-6C5350842F16} <C:\WINDOWS\system32\SafeHelper12.dll, LINKMEDIA Tech>
[raObject Class]
{46F194EB-B7DB-4B7A-BD42-5FF39FD17664} <C:\PROGRA~1\pcast\hbcast.dll, N/A>
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[5940.cn导航]
{6144F1E9-C6D4-4FF3-9008-AA43F3D287AC} <C:\WINDOWS\system32\QQ3818~1.DLL, >
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Micrsoft SearchBar]
{6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89} <C:\Program Files\Micrsoft SearchBar\SearchBar.dll, N/A>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[ShowBarEx Class]
{9411F42F-09FF-4FB5-ADD3-30ECAC43DC51} <C:\WINDOWS\system32\QQ3818~1.DLL, >
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[XBTP03129 Class]
{B07D1F6B-6B8C-4904-8EE8-5E5A2B4624B3} <C:\PROGRA~1\MICRSO~1\SEARCH~1.DLL, IE Toolbar>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[VIDEO__X_MS_ASF Moniker Class]
{CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
{CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[信息检索]
{CE7C3CF0-98A8-474D-B2B5-1ED7E2E3B004} <C:\WINDOWS\system32\IEHelper.dll, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\flash.ocx, Macromedia, Inc.>
[]
{FFFFFFFF-74CC-4B7C-B5F1-45913F368388} <C:\PROGRA~1\SYSTEM~1\SYSTEM~1.DLL, N/A>
[上传到QQ网络硬盘]
<D:\QQ\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
<C:\Program Files\KuGoo3\KuGoo3DownX.htm, N/A>
[导出到 Microsoft Excel(&x)]
<res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<D:\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\QQ\SendMMS.htm, N/A>
[用比特精灵下载(&B)]
<C:\Program Files\BitSpirit\bsurl.htm, N/A>
geminillc - 2006-10-4 8:34:00
==================================
正在运行的进程
[PID: 420][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 484][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 508][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 552][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 564][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[PID: 748][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 792][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[PID: 856][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[c:\windows\system32\acss.dll] [LINKMEDIA Tech, 1, 5, 0, 4]
[c:\windows\system32\nwsapagent.dll] [LINKMEDIA Tech, 1, 5, 0, 4]
[c:\windows\system32\wuauservs.dll] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[PID: 900][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[PID: 940][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1136][C:\KAV2006\KWatch.EXE] [Kingsoft Corporation, 2005, 9, 27, 51]
[C:\KAV2006\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\KAV2006\KAEPlat.DLL] [Kingsoft Corp., 2006, 5, 30, 59]
[C:\KAV2006\KAEMem.DAT] [Kingsoft, 2006, 5, 17, 14]
[C:\KAV2006\KAEUnpack.DAT] [Kingsoft Corp., 2006, 7, 27, 59]
[PID: 1264][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1592][C:\WINDOWS\system32\clipsvr.exe] [Microsoft Corporation, 5, 2, 3790, 0]
[PID: 1632][D:\杀毒软件\ewido_4.0.0.172c_3.32\ewido_4.0.0.172c_3.3\guard.exe] [Anti-Malware Development a.s., 4, 0, 0, 172]
[D:\杀毒软件\ewido_4.0.0.172c_3.32\ewido_4.0.0.172c_3.3\engine.dll] [Anti-Malware Development a.s., 4, 0, 0, 172]
[PID: 1644][C:\WINDOWS\Explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\杀毒软件\ewido_4.0.0.172c_3.32\ewido_4.0.0.172c_3.3\shellexecutehook.dll] [Anti-Malware Development a.s., 4, 0, 0, 172]
[C:\WINDOWS\system32\KB27861001.log] [N/A, N/A]
[C:\WINDOWS\system32\SystemInput.dll] [N/A, N/A]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\KAV2006\KMailOEBand.dll] [N/A, 2006, 5, 19, 118]
[C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.10.7181]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[C:\WINDOWS\system32\usercrd.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\IEHelper.dll] [N/A, 1, 0, 0, 1]
[C:\PROGRA~1\SYSTEM~1\SYSTEM~1.DLL] [N/A, N/A]
[C:\WINDOWS\system32\JPWB.IME] [常诚研制, 4.00.950]
[C:\WINDOWS\Win32ef.dll] [N/A, N/A]
[C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] [N/A, N/A]
[PID: 1692][c:\windows\powermsgr.exe] [Microsoft Corporation, 5.2.3790.1830]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 1864][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 460][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 468][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.7181]
[PID: 756][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[PID: 1356][c:\windows\system32\wbem\winlogon.exe] [Microsoft, 1.0.0.0]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[PID: 1484][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\sdmAgent20.dll] [LINKMEDIA Tech, 1, 5, 0, 7]
[C:\KAV2006\KMailOEBand.dll] [N/A, 2006, 5, 19, 118]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 1104][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5.1.0.34]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 1400][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3208]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 2092][C:\KAV2006\KAVStart.exe] [Kingsoft Corporation, 2006, 7, 6, 198]
[C:\KAV2006\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\KAV2006\PopSprt3.dll] [Kingsoft Corporation, 2005, 12, 6, 30]
[C:\KAV2006\KAVPassp.dll] [Kingsoft Corporation, 2006, 6, 7, 252]
[C:\KAV2006\KMailOEBand.dll] [N/A, 2006, 5, 19, 118]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[PID: 2428][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[PID: 2456][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\KAV2006\KMailOEBand.dll] [N/A, 2006, 5, 19, 118]
[PID: 2752][C:\KAV2006\KMailMon.EXE] [Kingsoft Corporation, 2006, 4, 12, 106]
[C:\KAV2006\KAntiSpm.dll] [N/A, 1, 0, 0, 2]
[C:\KAV2006\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\KAV2006\KAECall2.DLL] [Kingsoft Corporation, 2004, 12, 28, 7]
[C:\KAV2006\KAEPlat.DLL] [Kingsoft Corp., 2006, 5, 30, 59]
[C:\KAV2006\KAEMem.DAT] [Kingsoft, 2006, 5, 17, 14]
[C:\KAV2006\KAEUnpack.DAT] [Kingsoft Corp., 2006, 7, 27, 59]
[C:\KAV2006\KAConfig.DLL] [Kingsoft Corporation, 2005, 3, 23, 30]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\KAV2006\KMailOEBand.dll] [N/A, 2006, 5, 19, 118]
[PID: 3844][C:\Program Files\V-Gear BEE\VBService.exe] [Asiamajor Inc., 1.0.0.0]
[C:\Program Files\V-Gear BEE\VBShare.dll] [N/A, N/A]
[C:\KAV2006\KMailOEBand.dll] [N/A, 2006, 5, 19, 118]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\Program Files\V-Gear BEE\MIDAS.DLL] [Borland Software Corporation, 6.0.6.163]
[PID: 1916][C:\WINDOWS\system32\dsq.exe] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[PID: 984][C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\kuree_12000503.exe] [北京酷热科技有限公司, 1.0.2.8]
[C:\KAV2006\KMailOEBand.dll] [N/A, 2006, 5, 19, 118]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nstF.tmp\InstallOptions.dll] [N/A, N/A]
[PID: 3628][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\KAV2006\KMailOEBand.dll] [N/A, 2006, 5, 19, 118]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\Program Files\Micrsoft SearchBar\SearchBar.dll] [N/A, N/A]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[C:\Program Files\Common Files\CPUSH\cpush.dll] [N/A, 1.0.0.4]
[C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5107.dll] [Microsoft Corporation, 1, 3, 7, 0]
[C:\WINDOWS\Win32ef.dll] [N/A, N/A]
[C:\WINDOWS\system32\usercrd.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SafeHelper12.dll] [LINKMEDIA Tech, 2, 0, 0, 3]
[C:\WINDOWS\system32\QQ3818~1.DLL] [, 4, 0, 0, 1]
[C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] [N/A, N/A]
[C:\WINDOWS\system32\IEHelper.dll] [N/A, 1, 0, 0, 1]
[C:\PROGRA~1\SYSTEM~1\SYSTEM~1.DLL] [N/A, N/A]
[C:\KAV2006\KAScript.DLL] [Kingsoft Corporation, 2006, 2, 10, 60]
[C:\KAV2006\KAEPlat.DLL] [Kingsoft Corp., 2006, 5, 30, 59]
[C:\KAV2006\KAEMem.DAT] [Kingsoft, 2006, 5, 17, 14]
[C:\KAV2006\KAEUnpack.DAT] [Kingsoft Corp., 2006, 7, 27, 59]
[D:\杀毒软件\ewido_4.0.0.172c_3.32\ewido_4.0.0.172c_3.3\shellexecutehook.dll] [Anti-Malware Development a.s., 4, 0, 0, 172]
[PID: 4504][C:\Program Files\Internet Explorer\iedw.exe] [Microsoft Corporation, 5.1.2600.2937 (xpsp.060623-0011)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[PID: 4652][C:\WINDOWS\svchost.exe] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[PID: 4688][C:\WINDOWS\TEMP\IXP001.TMP\tool.exe] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[PID: 5636][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\KAV2006\KMailOEBand.dll] [N/A, 2006, 5, 19, 118]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\Program Files\Micrsoft SearchBar\SearchBar.dll] [N/A, N/A]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[C:\Program Files\Common Files\CPUSH\cpush.dll] [N/A, 1.0.0.4]
[C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5107.dll] [Microsoft Corporation, 1, 3, 7, 0]
[C:\WINDOWS\Win32ef.dll] [N/A, N/A]
[C:\WINDOWS\system32\usercrd.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SafeHelper12.dll] [LINKMEDIA Tech, 2, 0, 0, 3]
[C:\WINDOWS\system32\QQ3818~1.DLL] [, 4, 0, 0, 1]
[C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] [N/A, N/A]
[C:\WINDOWS\system32\IEHelper.dll] [N/A, 1, 0, 0, 1]
[C:\PROGRA~1\SYSTEM~1\SYSTEM~1.DLL] [N/A, N/A]
[C:\KAV2006\KAScript.DLL] [Kingsoft Corporation, 2006, 2, 10, 60]
[C:\KAV2006\KAEPlat.DLL] [Kingsoft Corp., 2006, 5, 30, 59]
[C:\KAV2006\KAEMem.DAT] [Kingsoft, 2006, 5, 17, 14]
[C:\KAV2006\KAEUnpack.DAT] [Kingsoft Corp., 2006, 7, 27, 59]
[PID: 5968][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
geminillc - 2006-10-4 8:34:00
[D:\杀毒软件\ewido_4.0.0.172c_3.32\ewido_4.0.0.172c_3.3\shellexecutehook.dll] [Anti-Malware Development a.s., 4, 0, 0, 172]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[PID: 7736][C:\WINDOWS\system32\softbox.exe] [bcnet, 1.00]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[PID: 7900][C:\WINDOWS\system32\Teache.exe] [bcnet, 1.00]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[PID: 4156][C:\Program Files\Common Files\UPDATE2\Update.exe] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[PID: 10716][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[PID: 11060][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[C:\WINDOWS\Win32ef.dll] [N/A, N/A]
[C:\WINDOWS\system32\usercrd.dll] [, 1, 0, 0, 1]
[C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] [N/A, N/A]
[C:\WINDOWS\system32\IEHelper.dll] [N/A, 1, 0, 0, 1]
[C:\PROGRA~1\SYSTEM~1\SYSTEM~1.DLL] [N/A, N/A]
[PID: 11068][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[C:\WINDOWS\Win32ef.dll] [N/A, N/A]
[C:\WINDOWS\system32\usercrd.dll] [, 1, 0, 0, 1]
[C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] [N/A, N/A]
[C:\WINDOWS\system32\IEHelper.dll] [N/A, 1, 0, 0, 1]
[C:\PROGRA~1\SYSTEM~1\SYSTEM~1.DLL] [N/A, N/A]
[PID: 8508][C:\WINDOWS\system32\A4\baisob\novel.exe] [, 1, 0, 0, 2]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[PID: 8744][C:\WINDOWS\system32\A4\baisob\novel.exe] [, 1, 0, 0, 2]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[PID: 12528][C:\WINDOWS\system32\A4\baisob\novel.exe] [, 1, 0, 0, 2]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[PID: 12652][C:\WINDOWS\system32\A4\baisob\novel.exe] [, 1, 0, 0, 2]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[PID: 16340][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 16344][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 19456][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 19460][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 19548][C:\WINDOWS\TEMP\ad.exe.exe] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[PID: 20504][C:\WINDOWS\system32\A4\baisob\novel.exe] [, 1, 0, 0, 2]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[PID: 21848][C:\WINDOWS\system32\A4\baisob\novel.exe] [, 1, 0, 0, 2]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[PID: 24192][C:\WINDOWS\TEMP\Teache.exe] [bcnet, 1.00]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[PID: 24240][C:\WINDOWS\TEMP\windowoutnew.exe] [Solid, 1.00]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz] [N/A, N/A]
[PID: 27284][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\QQ3818~1.DLL] [, 4, 0, 0, 1]
[C:\Program Files\Common Files\CPUSH\cpush.dll] [N/A, 1.0.0.4]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5107.dll] [Microsoft Corporation, 1, 3, 7, 0]
[C:\WINDOWS\Win32ef.dll] [N/A, N/A]
[C:\WINDOWS\system32\usercrd.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SafeHelper12.dll] [LINKMEDIA Tech, 2, 0, 0, 3]
[C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] [N/A, N/A]
[C:\PROGRA~1\MICRSO~1\SEARCH~1.DLL] [IE Toolbar, 1, 0, 0, 4]
[C:\WINDOWS\system32\IEHelper.dll] [N/A, 1, 0, 0, 1]
[C:\PROGRA~1\SYSTEM~1\SYSTEM~1.DLL] [N/A, N/A]
[C:\KAV2006\KAScript.DLL] [Kingsoft Corporation, 2006, 2, 10, 60]
[C:\KAV2006\KAEPlat.DLL] [Kingsoft Corp., 2006, 5, 30, 59]
[C:\KAV2006\KAEMem.DAT] [Kingsoft, 2006, 5, 17, 14]
[C:\KAV2006\KAEUnpack.DAT] [Kingsoft Corp., 2006, 7, 27, 59]
[C:\WINDOWS\system32\Macromed\Flash\flash.ocx] [Macromedia, Inc., 8,0,22,0]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\PROGRA~1\Kuree\Codec\ffdshow.ax] [N/A, 1.0.2.1997]
[C:\PROGRA~1\Kuree\Codec\VSFilter.dll] [Gabest, 1, 0, 1, 3]
[C:\PROGRA~1\Kuree\Codec\TTL2Dec.dll] [N/A, N/A]
[C:\PROGRA~1\Kuree\Codec\Vid1Dec.dll] [N/A, N/A]
[C:\PROGRA~1\Kuree\Codec\empgdmx.ax] [Elecard Ltd., 1, 0, 19, 51017]
[D:\杀毒软件\ewido_4.0.0.172c_3.32\ewido_4.0.0.172c_3.3\shellexecutehook.dll] [Anti-Malware Development a.s., 4, 0, 0, 172]
[PID: 33072][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 47808][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\QQ3818~1.DLL] [, 4, 0, 0, 1]
[C:\Program Files\Common Files\CPUSH\cpush.dll] [N/A, 1.0.0.4]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5107.dll] [Microsoft Corporation, 1, 3, 7, 0]
[C:\WINDOWS\Win32ef.dll] [N/A, N/A]
[C:\WINDOWS\system32\usercrd.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SafeHelper12.dll] [LINKMEDIA Tech, 2, 0, 0, 3]
[C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] [N/A, N/A]
[C:\PROGRA~1\MICRSO~1\SEARCH~1.DLL] [IE Toolbar, 1, 0, 0, 4]
[C:\WINDOWS\system32\IEHelper.dll] [N/A, 1, 0, 0, 1]
[C:\PROGRA~1\SYSTEM~1\SYSTEM~1.DLL] [N/A, N/A]
[PID: 48628][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 48168][D:\杀毒软件\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\KAV2006\KMailOEBand.dll] [N/A, 2006, 5, 19, 118]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\WINDOWS\system32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP Error. [winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)
MSAFD Tcpip [UDP/IP]
C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)
MSAFD Tcpip [RAW/IP]
C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)
RSVP UDP Service Provider
C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)
RSVP TCP Service Provider
C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)
==================================
Autorun.inf
[C:\]
[AutoRun]
open=pagefile.pif
[D:\]
[autorun]
OPEN=D:\command.com
[E:\]
[AutoRun]
open=sxs.exe
shellexecute=sxs.exe
shell\Auto\command=sxs.exe
[F:\]
[AutoRun]
open=sxs.exe
shellexecute=sxs.exe
shell\Auto\command=sxs.exe
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
© 2000 - 2026 Rising Corp. Ltd.