2002301140 - 2007-10-8 11:01:00
<\??\C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\RISING\RAV\MEMSCAN.sys><N/A>
[mProcRs / mProcRs][Stopped/Auto Start]
<\??\C:\Documents and Settings\Administrator\桌面\Rising\Rfw\mProcRs.sys><N/A>
[mraid35x / mraid35x][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\mraid35x.sys><LSI Logic Corporation>
[NFRD960 / NFRD960][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\nfrd960.sys><IBM Corporation>
[npkcrypt / npkcrypt][Stopped/Auto Start]
<\??\D:\qq2007\npkcrypt.sys><N/A>
[nv / nv][Stopped/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[NVATABUS / NVATABUS][Running/Boot Start]
<\SystemRoot\System32\BIRD\NVATABUS.SYS><NVIDIA Corporation>
[Service for NVIDIA(R) nForce(TM) MIDI UART / nvmpu401][Running/Manual Start]
<system32\drivers\nvmpu401.sys><NVIDIA Corporation>
[NVRAID / NVRAID][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\NVRAID.SYS><NVIDIA Corporation>
[perc2 / perc2][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\perc2.sys><Adaptec, Inc.>
[Padus ASPI Shell / pfc][Running/Manual Start]
<system32\drivers\pfc.sys><Padus, Inc.>
[Philips DF2000 GSM Handset Composite Device driver (WDM) / pgsmbus][Stopped/Manual Start]
<system32\DRIVERS\pgsmbus.sys><MCCI>
[Philips DF2000 GSM Handset Modem Filter / pgsmmdfl][Stopped/Manual Start]
<system32\DRIVERS\pgsmmdfl.sys><MCCI>
[Philips DF2000 GSM Handset Modem Drivers / pgsmmdm][Stopped/Manual Start]
<system32\DRIVERS\pgsmmdm.sys><MCCI>
[PNP649R / PNP649R][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\pnp649r.sys><CMD Technology, Inc.>
[PNP680 / PNP680][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\pnp680.sys><Silicon Image, Inc.>
[PNP680R / PNP680R][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\pnp680r.sys><Silicon Image, Inc>
[PnpWmkDrv / PnpWmkDrv][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\PnpWmkDrv.sys><Windows (R) 2000 DDK provider>
[Parallel Port Joystick Bus device driver / PPJoyBus][Running/Manual Start]
<system32\drivers\PPJoyBus.sys><Deon van der Westhuysen>
[Parallel Port Joystick device driver / PPortJoystick][Running/Manual Start]
<system32\drivers\PPortJoy.sys><Deon van der Westhuysen>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[ql1080 / ql1080][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\ql1080.sys><QLogic Corporation>
[Ql10wnt / Ql10wnt][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\ql10wnt.sys><Microsoft Corporation>
[ql12160 / ql12160][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\ql12160.sys><QLogic Corporation>
[ql1280 / ql1280][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\ql1280.sys><QLogic Corporation>
[RAIDSRC / RAIDSRC][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\raidsrc.sys><Intel/ICP>
[SmartCard Reader Device / Reader_Device][Running/Manual Start]
<system32\DRIVERS\usbic2k.sys><OEM>
[RR232X / RR232X][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\rr232x.sys><HighPoint Technologies, Inc.>
[RsFwDrv / RsFwDrv][Stopped/Auto Start]
<\??\C:\Documents and Settings\Administrator\桌面\Rising\Rfw\RsFwDrv.sys><N/A>
[RsNTGDI / RsNTGDI][Stopped/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><N/A>
[RSPPSYS / RSPPSYS][Stopped/Auto Start]
<\??\C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\RISING\RAV\RSPPSYS.sys><N/A>
[Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver / RTL8023xp][Running/Manual Start]
<system32\DRIVERS\Rtlnicxp.sys><Realtek Semiconductor Corporation>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[S150SX8 / S150SX8][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\S150sx8.sys><Promise Technology, Inc.>
[Secdrv / Secdrv][Running/Auto Start]
<system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[SI3112 / SI3112][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\SI3112.sys><Silicon Image, Inc.>
[SI3112R / SI3112R][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\SI3112r.sys><Silicon Image, Inc>
[SI3114 / SI3114][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\SI3114.sys><Silicon Image, Inc.>
[SI3114R / SI3114R][Stopped/Boot Start]
<\SystemRoot\SYSTEM32\BIRD\SI3114R.sys><Silicon Image, Inc>
[SI3114R5 / SI3114R5][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\Si3114r5.sys><Silicon Image, Inc>
[SI3124 / SI3124][Stopped/Boot Start]
<\SystemRoot\SYSTEM32\BIRD\SI3124.sys><Silicon Image, Inc.>
[SI3124R / SI3124R][Stopped/Boot Start]
<\SystemRoot\SYSTEM32\BIRD\SI3124R.sys><Silicon Image, Inc>
[SI3124R5 / SI3124R5][Stopped/Boot Start]
<\SystemRoot\SYSTEM32\BIRD\Si3124r5.sys><Silicon Image, Inc>
[SI3132 / SI3132][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\SI3132.sys><Silicon Image, Inc.>
[SI3132R5 / SI3132R5][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\Si3132r5.sys><Silicon Image, Inc>
[SISRAID / SISRAID][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\SiSRaid.sys><Silicon Integrated Systems>
[SISRAID2 / SISRAID2][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\SiSRaid2.sys><Silicon Integrated Systems Corp>
[SISRAID4 / SISRAID4][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\SiSRaid4.sys><Silicon Integrated Systems>
[sptd / sptd][Running/Boot Start]
<\SystemRoot\System32\Drivers\sptd.sys><N/A>
[SPTRAK / SPTRAK][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\sptrak.sys><Promise Technology, Inc.>
[ST8350 / ST8350][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\st8350.sys><Promise Technology, Inc.>
[symc810 / symc810][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\symc810.sys><Symbios Logic Inc.>
[symc8xx / symc8xx][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\symc8xx.sys><LSI Logic>
[SYMMPI / SYMMPI][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\symmpi.sys><LSI Logic>
[sym_hi / sym_hi][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\sym_hi.sys><LSI Logic>
[sym_u3 / sym_u3][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\sym_u3.sys><LSI Logic>
[TRM3X5 / TRM3X5][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\trm3x5.sys><Tekram Technology Co., Ltd.>
[ULSATA / ULSATA][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\ulsata.sys><Promise Technology, Inc.>
[ULSATA2 / ULSATA2][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\ulsata2.sys><Promise Technology, Inc.>
[ULTIMA / ULTIMA][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\Ultima.sys><Aralion INC.>
[ULTIMARX / ULTIMARX][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\UltimaRX.sys><Aralion INC.>
[ultra / ultra][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\ultra.sys><Promise Technology, Inc.>
[vaxscsi / vaxscsi][Running/Manual Start]
<\SystemRoot\System32\Drivers\vaxscsi.sys><N/A>
[ViaIde / ViaIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[VIAMRAID / VIAMRAID][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\viamraid.sys><VIA Technologies inc,.ltd>
[vmfilter303 / vmfilter303][Stopped/Manual Start]
<system32\drivers\vmfilter303.sys><Vimicro Corporation>
[W2KADV / W2KADV][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\w2kadv.sys><ConnectCom Solutions, Inc.>
[WD7296A / WD7296A][Stopped/Boot Start]
<\SystemRoot\System32\BIRD\wd7296a.sys><Western Digital Corporation>
[WINIO / WINIO][Stopped/Manual Start]
<\??\G:\winio.sys><N/A>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[TOPSPEED 303 PC Camera(Vimicro301 Neptune) / ZSMC303][Stopped/Manual Start]
<System32\Drivers\usbVM303.sys><Vimicro Corporation>
[25781 / 25781][Running/]
<2 - 系统找不到指定的文件。
><N/A>
==================================
2002301140 - 2007-10-8 11:01:00
浏览器加载项
[Kingsoft Trojan Webshield]
{4E8A5278-C04E-4FE3-BF78-8A7CCD6EF333} <C:\Program Files\Kingsoft Antispy\IEBuddy.DLL, Kingsoft Corporation>
[NavigatMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\应用软件\系统安全·杀毒\360安全卫士\safemon\safemon.dll, >
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <D:\应用软件\网络工具\迅雷5\Thunder.exe, Thunder Networking Technologies,LTD>
[IEBuddyExtControl Class]
{3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft Antispy\IEBuddyExt.DLL, Kingsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[WebThunder Class]
{03507A1A-E0C5-4404-AA26-205385C0892D} <, N/A>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[IEBuddyExtControl Class]
{3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft Antispy\IEBuddyExt.DLL, Kingsoft Corporation>
[Microsoft Office Control]
{4453D895-F2A1-4A38-A285-1EF9BD3F6D5D} <C:\PROGRA~1\MICROS~2\OFFICE11\AUTHZAX.DLL, Microsoft Corporation>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <D:\应用软件\网络工具\迅雷5\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[Kingsoft Trojan Webshield]
{4E8A5278-C04E-4FE3-BF78-8A7CCD6EF333} <C:\Program Files\Kingsoft Antispy\IEBuddy.DLL, Kingsoft Corporation>
[InfoSecNetSign Class]
{62B938C4-4190-4F37-8CF0-A92B0A91CC77} <C:\WINDOWS\system32\NetSign.dll, Infosec Technologies Co., Ltd.>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\system32\INPUTC~1.DLL, >
[360SafeLive]
{87515F61-A66C-4319-A0E0-D416CB8059E3} <D:\应用软件\系统安全·杀毒\360安全卫士\live.dll, 360safe.com>
[MSVPS System]
{88418AA3-16F5-4FC2-A9D8-90B1266DF841} <C:\WINDOWS\nsduo.dll, N/A>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\应用软件\网络工具\迅雷5\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[AxSubmitControl Class]
{8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} <C:\WINDOWS\system32\SUBMIT~1.DLL, >
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Thunder Browser Helper]
{B69F34DC-F0F9-42DC-9EDD-957187DA688D} <D:\应用软件\网络工具\迅雷5\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[NavigatMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\应用软件\系统安全·杀毒\360安全卫士\safemon\safemon.dll, >
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[Vod Class]
{EEDD6FF9-13DE-496B-9A1C-D78B3215E266} <D:\应用软件\网络工具\迅雷5\Components\DownAndPlay\DapPlayer_Now.dll, XunLei>
[&使用BitComet下载]
<res://D:\应用软件\网络工具\BitComet\BitComet.exe/AddLink.htm, N/A>
[&使用BitComet下载全部链接]
<res://D:\应用软件\网络工具\BitComet\BitComet.exe/AddAllLink.htm, N/A>
[&使用BitComet下载本页视频]
<res://D:\应用软件\网络工具\BitComet\BitComet.exe/AddVideo.htm, N/A>
[上传到QQ网络硬盘]
<D:\应用软件\网络工具\qq2007\AddToNetDisk.htm, N/A>
[使用迅雷下载]
<D:\应用软件\网络工具\迅雷5\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
<D:\应用软件\网络工具\迅雷5\Program\getallurl.htm, N/A>
[金山毒霸反钓鱼...]
<C:\KAV2007\KAF\ShowSet.htm, N/A>
2002301140 - 2007-10-8 11:02:00
正在运行的进程
[PID: 492 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 552 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 580 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4119]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 624 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 636 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 784 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4119]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2497]
[PID: 796 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 880 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 944 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 988 / SYSTEM][D:\应用软件\系统安全·杀毒\完美卸载\wmxz-v26.07\PnpWMmng.exe] [完美卸载, 5.1.2600.2937 ]
[PID: 1068 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1116 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1268 / SYSTEM][C:\KAV2007\KWatch.EXE] [Kingsoft Corporation, 2007, 8, 13, 78]
[C:\KAV2007\KAVIPC2.DLL] [Kingsoft Corporation, 2007, 1, 15, 30]
[C:\KAV2007\KAEPlat.DLL] [Kingsoft Corp., 2007, 6, 19, 64]
[C:\KAV2007\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\KAV2007\KAEUnpack.DAT] [Kingsoft Corp., 2007, 9, 17, 134]
[C:\KAV2007\KAVQuara.DLL] [Kingsoft Corporation, 2007, 6, 15, 4]
[PID: 1368 / Administrator][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4119]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2497]
[PID: 1428 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2007, 3, 18, 241]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Media Player Classic\Codecs\mmfinfo.dll] [N/A, ]
[C:\Program Files\Media Player Classic\Codecs\mkunicode.dll] [N/A, ]
[D:\应用软件\系统安全·杀毒\360安全卫士\safemon\safemon.dll] [, 3, 6, 1, 1001]
[D:\应用软件\播放器\adberdr\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\KAV2007\KAVEXT.DLL] [Kingsoft Corporation, 2007, 6, 21, 29]
[PID: 1484 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1524 / LOCAL SERVICE][C:\WINDOWS\System32\SCardSvr.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 236 / SYSTEM][C:\WINDOWS\system32\bgsvcgen.exe] [B.H.A Corporation, 1, 0, 0, 1]
[PID: 308 / SYSTEM][C:\KAV2007\KPfwSvc.EXE] [Kingsoft Corporation, 2007, 8, 17, 39]
[PID: 448 / SYSTEM][C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe] [Rocket Division Software, 2.6.1 Build 0x20050401]
[PID: 348 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1300 / SYSTEM][C:\program files\internet explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1328 / SYSTEM][C:\Program Files\Canon\CAL\CALMAIN.exe] [Canon Inc., 8, 1, 0, 14]
[PID: 1188 / Administrator][C:\KAV2007\KAVStart.exe] [Kingsoft Corporation, 2007, 8, 15, 289]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KAVIPC2.DLL] [Kingsoft Corporation, 2007, 1, 15, 30]
[C:\KAV2007\SvcTimer.DLL] [Kingsoft Corporation, 2006.12.22.84]
[C:\KAV2007\PopSprt3.dll] [Kingsoft Corporation, 2007, 3, 20, 48]
[C:\KAV2007\KAVPassp.dll] [Kingsoft Corporation, 2006, 12, 30, 271]
[PID: 864 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2028 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2100 / Administrator][C:\KAV2007\KMailMon.EXE] [Kingsoft Corporation, 2007, 8, 16, 967]
[C:\KAV2007\KAntiSpm.dll] [Kingsoft Corporation, 2007, 2, 25, 129]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KAVIPC2.DLL] [Kingsoft Corporation, 2007, 1, 15, 30]
[C:\KAV2007\KAECall2.DLL] [Kingsoft Corporation, 2004, 12, 28, 7]
[C:\KAV2007\KAEPlat.DLL] [Kingsoft Corp., 2007, 6, 19, 64]
[C:\KAV2007\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\KAV2007\KAEUnpack.DAT] [Kingsoft Corp., 2007, 9, 17, 134]
[C:\KAV2007\KAConfig.DLL] [Kingsoft Corporation, 2007, 1, 11, 41]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2007, 3, 18, 241]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[PID: 2612 / Administrator][D:\应用软件\系统安全·杀毒\360安全卫士\360Safe.exe] [奇虎网, 3, 6, 1, 1001]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2007, 3, 18, 241]
[D:\应用软件\系统安全·杀毒\360安全卫士\AntiAdwa.dll] [360Safe.com, 3, 6, 1, 1001]
[D:\应用软件\系统安全·杀毒\360安全卫士\AntiEng.dll] [360Safe.com, 3, 6, 1, 1001]
[D:\应用软件\系统安全·杀毒\360安全卫士\LeakCheck.dll] [360Safe.com, 3, 6, 1, 1002]
[D:\应用软件\系统安全·杀毒\360安全卫士\CleanHis.dll] [奇虎网, 3, 0, 2, 1000]
[D:\应用软件\系统安全·杀毒\360安全卫士\safemon\safemon.dll] [, 3, 6, 1, 1001]
[PID: 2672 / Administrator][D:\应用软件\系统安全·杀毒\360安全卫士\safemon\360Tray.exe] [奇虎网, 3, 6, 1, 1001]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2007, 3, 18, 241]
[D:\应用软件\系统安全·杀毒\360安全卫士\safemon\safemon.dll] [, 3, 6, 1, 1001]
[D:\应用软件\系统安全·杀毒\360安全卫士\safemon\SafeKrnl.dll] [奇虎网, 3, 6, 0, 1001]
[D:\应用软件\系统安全·杀毒\360安全卫士\AntiAdwa.dll] [360Safe.com, 3, 6, 1, 1001]
[D:\应用软件\系统安全·杀毒\360安全卫士\live.dll] [360safe.com, 1, 0, 1, 1020]
[PID: 2980 / Administrator][C:\KAV2007\KPFW32.EXE] [Kingsoft Corporation, 2007, 8, 17, 726]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
[D:\应用软件\系统安全·杀毒\360安全卫士\safemon\safemon.dll] [, 3, 6, 1, 1001]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2007, 3, 18, 241]
[C:\KAV2007\KAVIPC2.DLL] [Kingsoft Corporation, 2007, 1, 15, 30]
[C:\KAV2007\KAConfig.DLL] [Kingsoft Corporation, 2007, 1, 11, 41]
[C:\KAV2007\FiltList.dll] [N/A, ]
[C:\KAV2007\KAVPassp.DLL] [Kingsoft Corporation, 2006, 12, 30, 271]
2002301140 - 2007-10-8 11:02:00
[PID: 3772 / SYSTEM][C:\WINDOWS\system32\ratbftl.exe] [N/A, ]
[PID: 3832 / SYSTEM][C:\WINDOWS\system32\kvdxcis.exe] [N/A, ]
[PID: 3884 / SYSTEM][C:\WINDOWS\system32\rsjzbsp.exe] [N/A, ]
[PID: 3936 / SYSTEM][C:\WINDOWS\system32\kvdxsbis.exe] [N/A, ]
[PID: 392 / Administrator][D:\应用软件\网络工具\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 5, 6, 42]
[D:\应用软件\网络工具\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[D:\应用软件\系统安全·杀毒\360安全卫士\safemon\safemon.dll] [, 3, 6, 1, 1001]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2007, 3, 18, 241]
[C:\WINDOWS\system32\odbcbcp.dll] [Microsoft Corporation, 2000.085.1117.00 (xpsp_sp2_rtm.040803-2158)]
[D:\应用软件\网络工具\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx] [Adobe Systems, Inc., 9,0,45,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2308 / Administrator][C:\WINDOWS\system32\NOTEPAD.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\应用软件\系统安全·杀毒\360安全卫士\safemon\safemon.dll] [, 3, 6, 1, 1001]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2007, 3, 18, 241]
[PID: 428 / Administrator][D:\应用软件安装备份\sreng\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[D:\应用软件\系统安全·杀毒\360安全卫士\safemon\safemon.dll] [, 3, 6, 1, 1001]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2007, 3, 18, 241]
[D:\应用软件安装备份\sreng\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP Error. [winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 2100, C:\KAV2007\KMAILMON.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2612, D:\应用软件\系统安全·杀毒\360安全卫士\360SAFE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2612, D:\应用软件\系统安全·杀毒\360安全卫士\360SAFE.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2672, D:\应用软件\系统安全·杀毒\360安全卫士\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2672, D:\应用软件\系统安全·杀毒\360安全卫士\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2980, C:\KAV2007\KPFW32.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 392, D:\应用软件\网络工具\MAXTHON\MAXTHON.EXE]
==================================
API HOOK
入口点错误:LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: C:\KAV2007\KASocket.dll)
==================================
隐藏进程
N/A
==================================
[/CODE]
© 2000 - 2026 Rising Corp. Ltd.