tlz8899 - 2007-9-29 18:57:00
==================================
驱动程序
[BsDeamon / BsDeamon][Stopped/System Start]
<\??\D:\工具软件\JiangMin\ANTIVI~1\BsDeamon.sys><N/A>
[C-Media WDM Audio Interface / cmuda][Running/Manual Start]
<system32\drivers\cmuda.sys><C-Media Inc>
[KAnalyser / KAnalyser][Stopped/System Start]
<\??\D:\工具软件\JiangMin\ANTIVI~1\KANALY~1.SYS><N/A>
[kl1 / kl1][Running/Boot Start]
<\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[Kaspersky Anti-Virus NDIS Filter / klim5][Running/Manual Start]
<system32\DRIVERS\klim5.sys><Kaspersky Lab>
[KPGuard / KPGuard][Stopped/System Start]
<\??\D:\工具软件\JiangMin\ANTIVI~1\KPGuard.sys><N/A>
[KRegEx / KRegEx][Stopped/System Start]
<\??\D:\工具软件\JiangMin\ANTIVI~1\KRegEx.sys><N/A>
[Jiangmin Antivirus Software / KSysCall][Stopped/System Start]
<\??\D:\工具软件\JiangMin\common\KSysCall.sys><N/A>
[KSysFilter / KSysFilter][Running/Boot Start]
<\SystemRoot\System32\Drivers\KSysFilt.sys><Jiangmin Co. Ltd.>
[KSysMon / KSysMon][Stopped/System Start]
<\??\D:\工具软件\JiangMin\ANTIVI~1\KSysMon.sys><N/A>
[KVDP / KVDP][Stopped/Manual Start]
<\??\D:\工具软件\JiangMin\AntiVirus\KVDP.sys><N/A>
[KVREDIR / KVREDIR][Stopped/System Start]
<\??\D:\工具软件\JiangMin\AntiVirus\KVREDIR.sys><N/A>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[nvatabus / nvatabus][Running/Boot Start]
<\SystemRoot\system32\drivers\nvatabus.sys><NVIDIA Corporation>
[NVIDIA nForce Networking Controller Driver / NVENET][Running/Manual Start]
<system32\DRIVERS\NVENET.sys><NVIDIA Corporation>
[Service for NVIDIA(R) nForce(TM) MIDI UART / nvmpu401][Running/Manual Start]
<system32\drivers\nvmpu401.sys><NVIDIA Corporation>
[NVIDIA nForce AGP Bus Filter / nv_agp][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\nv_agp.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Stopped/Manual Start]
<system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[System Restore Filter Driver / Sr][Stopped/Boot Start]
<\SystemRoot\system32\DRIVERS\sr.sys><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[AVG Anti-Spyware Clean Driver / AvgAsCln][Stopped/System Start]
<System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
[AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
<\??\D:\工具软件\AVG.Anti-Spyware.V7.5.1.43.by.nzone.09.23\AVG Anti-Spyware\guard.sys><N/A>
==================================
浏览器加载项
[FGCatchUrl]
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <C:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
[FlashGet GetFlash Class]
{F156768E-81EF-470C-9057-481BA8380DBA} <C:\Program Files\FlashGet\getflash.dll, www.flashget.com>
[Web 防护 统计]
{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <D:\Kaspersky Anti-Virus Personal\SCIEPlgn.dll, Kaspersky Lab>
[快车]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\Program Files\FlashGet\flashget.exe, FlashGet.com>
[YlmF]
{524072D4-61F6-45A7-A2CA-BB6819B56343} <http://www.ylmf.com, N/A>
[FGCatchUrl]
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <C:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[BrowseHelper Class]
{80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} <D:\工具软件\JiangMin\AntiVirus\KVshell.dll, N/A>
[360SafeLive]
{87515F61-A66C-4319-A0E0-D416CB8059E3} <E:\360safe_3.11134f\360safe_3.11134f\360safe_3.11134f\live.dll, N/A>
[江民杀毒工具栏]
{B5A34A93-D538-43A7-8371-864CB6148D12} <D:\工具软件\JiangMin\AntiVirus\KVshell.dll, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[FlashGet GetFlash Class]
{F156768E-81EF-470C-9057-481BA8380DBA} <C:\Program Files\FlashGet\getflash.dll, www.flashget.com>
[FGCatchUrl]
{FB5DA724-162B-11D3-8B9B-AA70B4B0B524} <C:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
[&使用快车(FlashGet)下载]
<C:\Program Files\FlashGet\jc_link.htm, N/A>
[&使用快车(FlashGet)下载全部链接]
<C:\Program Files\FlashGet\jc_all.htm, N/A>
tlz8899 - 2007-9-29 18:59:00
==================================
正在运行的进程
[PID: 976 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1044 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1072 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Kaspersky Anti-Virus Personal\miscr3.dll] [Kaspersky Lab, 7.0.0.125]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 7.0.0.125]
[PID: 1116 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[PID: 1128 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[D:\Kaspersky Anti-Virus Personal\dnsq.dll] [Kaspersky Lab, 7.0.0.125]
[D:\Kaspersky Anti-Virus Personal\miscr3.dll] [Kaspersky Lab, 7.0.0.125]
[PID: 1272 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[PID: 1392 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[D:\Kaspersky Anti-Virus Personal\dnsq.dll] [Kaspersky Lab, 7.0.0.125]
[PID: 1552 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[D:\Kaspersky Anti-Virus Personal\miscr3.dll] [Kaspersky Lab, 7.0.0.125]
[C:\WINDOWS\System32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1620 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[D:\Kaspersky Anti-Virus Personal\miscr3.dll] [Kaspersky Lab, 7.0.0.125]
[PID: 1756 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[D:\Kaspersky Anti-Virus Personal\miscr3.dll] [Kaspersky Lab, 7.0.0.125]
[PID: 1940 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp.050610-1527)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[D:\Kaspersky Anti-Virus Personal\dnsq.dll] [Kaspersky Lab, 7.0.0.125]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 360 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[c:\documents and settings\administrator\application data\ppstream\bin\1.0.0.2\vodrc.dll] [ppstream.com, 1.0.0.2]
[D:\Kaspersky Anti-Virus Personal\miscr3.dll] [Kaspersky Lab, 7.0.0.125]
[D:\Kaspersky Anti-Virus Personal\scrchpg.dll] [Kaspersky Lab, 7.0.0.125]
[C:\WINDOWS\system32\nvshell.dll] [, ]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[D:\Kaspersky Anti-Virus Personal\ShellEx.dll] [Kaspersky Lab, 7.0.0.125]
[D:\Kaspersky Anti-Virus Personal\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42]
[D:\Kaspersky Anti-Virus Personal\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.42]
[C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\工具软件\AVG.Anti-Spyware.V7.5.1.43.by.nzone.09.23\AVG Anti-Spyware\shellexecutehook.dll] [GRISOFT s.r.o., 7, 5, 1, 36]
[D:\工具软件\AVG.Anti-Spyware.V7.5.1.43.by.nzone.09.23\AVG Anti-Spyware\context.dll] [GRISOFT s.r.o., 7, 5, 1, 36]
[PID: 1040 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.9136]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[PID: 1132 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 596 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[PID: 2004 / Administrator][C:\WINDOWS\system32\CTFMON.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[PID: 1356 / Administrator][C:\Program Files\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 6, 1, 50]
[C:\Program Files\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[D:\Kaspersky Anti-Virus Personal\miscr3.dll] [Kaspersky Lab, 7.0.0.125]
[c:\documents and settings\administrator\application data\ppstream\bin\1.0.0.2\vodrc.dll] [ppstream.com, 1.0.0.2]
[D:\Kaspersky Anti-Virus Personal\scrchpg.dll] [Kaspersky Lab, 7.0.0.125]
[D:\Kaspersky Anti-Virus Personal\dnsq.dll] [Kaspersky Lab, 7.0.0.125]
[C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Kaspersky Anti-Virus Personal\klscav.dll] [Kaspersky Lab, 7.0.0.125]
[D:\Kaspersky Anti-Virus Personal\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42]
[D:\Kaspersky Anti-Virus Personal\prremote.dll] [Kaspersky Lab, 7.0.0.125]
[D:\Kaspersky Anti-Virus Personal\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.42]
[D:\Kaspersky Anti-Virus Personal\prloader.dll] [Kaspersky Lab, 7.0.0.125]
[D:\Kaspersky Anti-Virus Personal\prkernel.ppl] [Kaspersky Lab, 7.0.0.125]
[d:\kaspersky anti-virus personal\params.ppl] [Kaspersky Lab, 7.0.0.125]
[d:\kaspersky anti-virus personal\pxstub.ppl] [Kaspersky Lab, 7.0.0.125]
[d:\kaspersky anti-virus personal\tempfile.ppl] [Kaspersky Lab, 7.0.0.125]
[d:\kaspersky anti-virus personal\nfio.ppl] [Kaspersky Lab, 7.0.0.125]
[d:\kaspersky anti-virus personal\fsdrvplg.ppl] [Kaspersky Lab, 7.0.0.125]
[d:\kaspersky anti-virus personal\basegui.ppl] [Kaspersky Lab, 7.0.0.125]
[d:\kaspersky anti-virus personal\thpimpl.ppl] [Kaspersky Lab, 7.0.0.125]
[d:\kaspersky anti-virus personal\FSSync.dll] [Kaspersky Lab, 7.0.5.125]
[d:\kaspersky anti-virus personal\winreg.ppl] [Kaspersky Lab, 7.0.0.125]
[C:\WINDOWS\system32\CHENHU4.IME] [chenhu, 5.6]
[C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx] [Adobe Systems, Inc., 9,0,47,0]
[C:\Program Files\FlashGet\jccatch.dll] [www.flashget.com, 1, 8, 4, 1007]
[C:\WINDOWS\system32\vbscript.dll] [Microsoft Corporation, 5.6.0.8825]
[PID: 3096 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[PID: 2148 / Administrator][D:\QQ2005\qq\QQ.exe] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\CoralAssist.dll] [Coral Team, 5.0.0 build 20060829]
[D:\QQ2005\qq\CoralQQ.dll] [Coral Team, 5.0.2 Build 20070703]
[D:\QQ2005\qq\kql.dll] [Coral Team, 5.0.1a build 20070621]
[D:\QQ2005\qq\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.42]
[D:\QQ2005\qq\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42]
[D:\QQ2005\qq\ipsearcher.dll] [狂人之家, 1, 0, 0, 1]
[D:\QQ2005\qq\QQBaseClassInDll.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\QQHelperDll.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\BasicCtrlDll.dll] [TENCENT, 7, 0, 225, 1651]
[D:\Kaspersky Anti-Virus Personal\miscr3.dll] [Kaspersky Lab, 7.0.0.125]
[D:\QQ2005\qq\NoDisturbFilter.cqx] [Coral Team, 1.0]
[D:\QQ2005\qq\ConfigHotkey.cqx] [Coral Team, 1.0]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[D:\QQ2005\qq\QQAPI.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[D:\QQ2005\qq\AutoReconnect.cqx] [Coral Team, 1.0.0]
[D:\QQ2005\qq\LoginCtrl.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\LoginCtrlRes.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\QQRes.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\WizardCtrl.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\QQMainFrame.dll] [N/A, ]
[D:\Kaspersky Anti-Virus Personal\dnsq.dll] [Kaspersky Lab, 7.0.0.125]
[D:\QQ2005\qq\CQQApplication.dll] [N/A, ]
[D:\QQ2005\qq\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[D:\QQ2005\qq\NewSkin.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\HostingMgr.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\CameraDll.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\MailSummary.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\CoralHotkey.cqx] [Coral Team, 1.0]
[D:\QQ2005\qq\QQKnowledgeSearch.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\QQAllInOne.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\SCCore.dll] [TENCENT, 1, 6, 0, 2]
[D:\QQ2005\qq\QQSpace.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\vbscript.dll] [Microsoft Corporation, 5.6.0.8825]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[D:\QQ2005\qq\QQGroupMng.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\UserDefinedHead.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\QQPlugin.dll] [N/A, ]
[D:\QQ2005\qq\QQConfigPlugin.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\QQAvatar.dll] [N/A, ]
[D:\Kaspersky Anti-Virus Personal\scrchpg.dll] [Kaspersky Lab, 7.0.0.125]
[D:\QQ2005\qq\QRingMng.dll] [N/A, ]
tlz8899 - 2007-9-29 19:00:00
[D:\QQ2005\qq\QQCustomFace.dll] [N/A, ]
[D:\QQ2005\qq\GroupConnection.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\LongConnection.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\QQSysMsgMng.dll] [N/A, ]
[D:\QQ2005\qq\QQSettingCtrl.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\CommercesMng.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\PersonalDesktop.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 310]
[D:\QQ2005\qq\QQSceneMng.dll] [N/A, ]
[D:\QQ2005\qq\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 1, 9, 95]
[D:\QQ2005\qq\QQMsgFriendMng.dll] [N/A, ]
[D:\QQ2005\qq\QQZip.dll] [TENCENT, 7,0,313,1681]
[D:\QQ2005\qq\ImageOle.dll] [TENCENT, 7,0,313,1681]
[PID: 2804 / Administrator][D:\QQ2005\qq\TIMPlatform.exe] [TENCENT, 7,0,313,1681]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[D:\QQ2005\qq\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 3464 / Administrator][D:\QQ2005\qq\ChatRoomDll\BugReport.exe] [Tencent, 0, 2, 2, 4]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[PID: 3688 / Administrator][D:\工具软件\卡卡助手\Ras.exe] [Beijing Rising Technology Co., Ltd., 4.0.0.62]
[D:\工具软件\卡卡助手\TopSoft.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.3]
[D:\工具软件\卡卡助手\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[D:\工具软件\卡卡助手\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[D:\工具软件\卡卡助手\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[D:\工具软件\卡卡助手\RasGui.dll] [Beijing Rising Technology Co., Ltd., 2, 0, 0, 14]
[D:\Kaspersky Anti-Virus Personal\dnsq.dll] [Kaspersky Lab, 7.0.0.125]
[D:\Kaspersky Anti-Virus Personal\scrchpg.dll] [Kaspersky Lab, 7.0.0.125]
[D:\Kaspersky Anti-Virus Personal\miscr3.dll] [Kaspersky Lab, 7.0.0.125]
[C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\工具软件\卡卡助手\engine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 24]
[D:\工具软件\卡卡助手\zip.dll] [rising, 13, 0, 0, 1]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\documents and settings\administrator\application data\ppstream\bin\1.0.0.2\vodrc.dll] [ppstream.com, 1.0.0.2]
[D:\Kaspersky Anti-Virus Personal\klscav.dll] [Kaspersky Lab, 7.0.0.125]
[D:\Kaspersky Anti-Virus Personal\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42]
[C:\WINDOWS\system32\CHENHU4.IME] [chenhu, 5.6]
[PID: 264 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.328\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.328\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[D:\Kaspersky Anti-Virus Personal\miscr3.dll] [Kaspersky Lab, 7.0.0.125]
[D:\Kaspersky Anti-Virus Personal\dnsq.dll] [Kaspersky Lab, 7.0.0.125]
[c:\documents and settings\administrator\application data\ppstream\bin\1.0.0.2\vodrc.dll] [ppstream.com, 1.0.0.2]
[D:\Kaspersky Anti-Virus Personal\scrchpg.dll] [Kaspersky Lab, 7.0.0.125]
[PID: 3248 / Administrator][C:\Documents and Settings\Administrator\桌面\NimayaKiller.scr] [Beijing Rising Technology Co., Ltd., 1, 10, 0, 1]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2845 (xpsp.060210-1526)]
[D:\Kaspersky Anti-Virus Personal\scrchpg.dll] [Kaspersky Lab, 7.0.0.125]
[D:\Kaspersky Anti-Virus Personal\miscr3.dll] [Kaspersky Lab, 7.0.0.125]
[D:\Kaspersky Anti-Virus Personal\dnsq.dll] [Kaspersky Lab, 7.0.0.125]
[C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Kaspersky Anti-Virus Personal\klscav.dll] [Kaspersky Lab, 7.0.0.125]
[D:\Kaspersky Anti-Virus Personal\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1356, C:\PROGRAM FILES\MAXTHON\MAXTHON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3464, D:\QQ2005\QQ\CHATROOMDLL\BUGREPORT.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3688, D:\工具软件\卡卡助手\RAS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3688, D:\工具软件\卡卡助手\RAS.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3248, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\NIMAYAKILLER.SCR]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3248, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\NIMAYAKILLER.SCR]
==================================
API HOOK
RVA 错误: LoadLibraryA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: LoadLibraryExA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: LoadLibraryW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
==================================
隐藏进程
N/A
==================================
[/CODE]
© 2000 - 2026 Rising Corp. Ltd.