瑞星卡卡安全论坛
长风飘飘 - 2008-1-6 13:17:00
这个是我朋友电脑的日志``他中毒了连字也打不了``所以我把他发日志上来``帮忙看看谢谢了
[CODE]
2005-01-06,12:25:58
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<swg><C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe> [(Verified)Google Inc]
<KavPFW><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPFW32.EXE"> [(Verified)KINGSOFT CORPORATION]
<QQDownload><"D:\Program Files\QQDownload\QQDownload.exe" autostart> [N/A]
<wsctf.exe><wsctf.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<switch><c:\windows\system32\壁纸自动换.exe> []
<Vistadrvrt><C:\Program Files\Vista风格美化\Vistadrive\vsdrvrt.exe> []
<Vistadrv><C:\Program Files\Vista风格美化\Vistadrive\vsdrv.exe> []
<ATICCC><"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay> [N/A]
<RTHDCPL><RTHDCPL.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<Alcmtr><ALCMTR.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<XOSD><C:\Program Files\XOSD\XOSD.exe> []
<WebThunder><C:\Program Files\Thunder Network\WebThunder\WebThunder.exe> [(Verified)ShenZhen Thunder Networking Technologies Ltd.]
<runeip><"D:\我的游戏\卡卡\runiep.exe" /startup> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><C:\WINDOWS\system32\XPSTYLE_ThemePackage\Logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{E159854F-6971-3456-6941-10235412974E}><C:\WINDOWS\Fonts\hookhelp.dll> []
<{4A57CAD1-412F-9547-713F-9641FA3FC7A4}><C:\WINDOWS\system32\okmhdzy.dll> []
<{C7D81718-1314-5200-2597-58790101807C}><C:\WINDOWS\system32\kaqhlzy.dll> []
<{D859245F-345D-BC13-AC4F-145D47DA34FD}><C:\WINDOWS\system32\avzxmmn.dll> []
<{CD561258-45F3-A451-F908-A258458226DC}><C:\WINDOWS\system32\kvdxslma.dll> [N/A]
<{CC87A354-ABC3-DEDE-FF33-3213FD7447CC}><C:\WINDOWS\system32\kvdxlma.dll> [N/A]
<{9960356A-458E-DE24-BD50-268F589A56A9}><C:\WINDOWS\system32\avwlimn.dll> [N/A]
<{98907901-1416-3389-9981-372178569989}><C:\WINDOWS\system32\kawdizy.dll> []
<{3FA10261-B890-F432-A453-69F1023513F3}><C:\WINDOWS\system32\gjcscyc.dll> [N/A]
<{1D908534-AD45-920F-AC89-4024FA9D26D1}><C:\WINDOWS\system32\gjfhayc.dll> [N/A]
<{8A1247C1-53DA-FF43-ABD3-345F323A48D8}><C:\WINDOWS\system32\avwghmn.dll> []
<{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]
<{DD561258-45F3-A451-F908-A258458226DD}><C:\WINDOWS\system32\kvdxsmma.dll> []
<{778A7521-FA87-34AB-34C2-4893F3AD34C7}><C:\WINDOWS\system32\swrcfzc.dll> [N/A]
<{792FADFA-BCDE-ACDF-CDEF-21054865CBA7}><C:\WINDOWS\system32\wsmsezx.dll> []
<{AE32FA58-3453-FA2D-BC49-F340348ACCEA}><C:\WINDOWS\system32\rsmyjpm.dll> []
<{47650011-3344-6688-4899-345FABCD1574}><C:\WINDOWS\system32\ratbspi.dll> []
<{A960356A-458E-DE24-BD50-268F589A56AA}><C:\WINDOWS\Fonts\avwljmn.dll> []
<{5598FF45-DA60-F48A-BC43-10AC47853D55}><C:\WINDOWS\system32\rarjepi.dll> []
<{878A7521-FA87-34AB-34C2-4893F3AD34C8}><C:\WINDOWS\Fonts\swrcgzc.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
<WinlogonNotify: WgaLogon><WgaLogon.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install> [Microsoft Corporation]
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; TencentTraveler )
长风飘飘 - 2008-1-6 13:17:00
==================================
启动文件夹
[Ralink Wireless Utility]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Ralink Wireless Utility.lnk --> C:\PROGRA~1\RALINK\Common\RaUI.exe [Ralink Technology, Corp.]><N>
[腾讯QQ]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --> D:\PROGRA~1\QQ2007\QQ.exe [TENCENT]><N>
[QQ游戏启动加速程序]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk --> C:\PROGRA~1\Tencent\QQGAME\Accel.exe [深圳市腾讯计算机系统有限公司]><N>
==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[Google Updater Service / gusvc][Stopped/Manual Start]
<"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"><Macrovision Corporation>
[Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
<"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>
[O2Micro Flash Memory / O2Flash][Running/Auto Start]
<C:\WINDOWS\system32\o2flash.exe><N/A>
==================================
驱动程序
[3n5yjrzwy / 3n5yjrzwy9][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\3n5yjrzwy9.sys><N/A>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
<system32\drivers\ac97intc.sys><Intel Corporation>
[AEGIS Protocol (IEEE 802.1x) v3.4.3.0 / AegisP][Running/Auto Start]
<system32\DRIVERS\AegisP.sys><Meetinghouse Data Communications>
[AliIde / AliIde][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
<System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
[ati2mtag / ati2mtag][Running/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[CmdIde / CmdIde][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
<system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[GJ / GJ][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp16.tmp><N/A>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
<system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
[KAVBase / KAVBase][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
[KAVBootC / KAVBootC][Running/Boot Start]
<\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>
[KAVSafe / KAVSafe][Running/Auto Start]
<\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>
[KNetWch / KNetWch][Running/System Start]
<\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
[KWatch3 / KWatch3][Running/Auto Start]
<\??\C:\WINDOWS\system32\Drivers\KWatch3.sys><Kingsoft Corporation>
[MS / MS][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp13.tmp><N/A>
[npkcrypt / npkcrypt][Stopped/Auto Start]
<\??\D:\Program Files\QQ2007\npkcrypt.sys><N/A>
[nv / nv][Stopped/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[O2MDRDR / O2MDRDR][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\o2media.sys><O2Micro>
[O2SDRDR / O2SDRDR][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\o2sd.sys><O2Micro>
[PciHardDisk / PciHardDisk][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\fat32.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
<\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising Technology Co., Ltd.>
[Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Running/Manual Start]
<system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[TesSafe / TesSafe][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>
[WD / WD][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp10.tmp><N/A>
[ZHTU / ZHTU][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpD.tmp><N/A>
长风飘飘 - 2008-1-6 13:18:00
==================================
浏览器加载项
[QQCycloneHelper Class]
{00000000-12C7-4305-82F9-43058F20E8D2} <D:\Program Files\QQDownload\QQIEHelper02.dll, 腾讯公司>
[Thunder Browser Helper]
{00000000-12C8-4305-82F9-43058F20E8D2} <C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll, N/A>
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_Now.dll, Thunder Networking Technologies,LTD>
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll, N/A>
[Kingsoft Trojan Webshield]
{4E8A5278-C04E-4FE3-BF78-8A7CCD6EF333} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\Antispy\IEBuddy.DLL, Kingsoft Corporation>
[Google Toolbar Helper]
{AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[Google Toolbar Notifier BHO]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
[NavigatMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\D盘内容(软件)\⑤杀毒软件\360安全卫士\safemon\safemon.dll, >
[IEBuddyExtControl Class]
{3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\Antispy\IEBuddyExt.DLL, Kingsoft Corporation>
[启动WEB迅雷]
{962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[快捷工具条3.1.5]
{BE830FD4-E393-417F-9F4B-CC70ABB3384C} <C:\WINDOWS\system32\IETool.dll, N/A>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[QQCycloneHelper Class]
{00000000-12C7-4305-82F9-43058F20E8D2} <D:\Program Files\QQDownload\QQIEHelper02.dll, 腾讯公司>
[Thunder Browser Helper]
{00000000-12C8-4305-82F9-43058F20E8D2} <C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll, N/A>
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_Now.dll, Thunder Networking Technologies,LTD>
[Google Script Object]
{00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[ThunderAtOnce Class]
{01443AEC-0FD1-40FD-9C87-E93D1494C233} <C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll, N/A>
[WebThunder Class]
{03507A1A-E0C5-4404-AA26-205385C0892D} <, N/A>
[Web Browser Applet Control]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\WINDOWS\system32\msjava.dll, Microsoft Corporation>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[WebThunder DapPlayer]
{2EEDA47E-8D5C-4d7e-B4B6-E16E19218555} <C:\Program Files\Thunder Network\WebThunder\DownAndPlay\DapPlayer3.0.41.65.166.dll, ShenZhen Thunder Networking Technologies Ltd.>
[IEBuddyExtControl Class]
{3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\Antispy\IEBuddyExt.DLL, Kingsoft Corporation>
[XML Document]
{48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, N/A>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <C:\Program Files\Thunder\ComDlls\ThunderAgent_Now.dll, N/A>
[Kingsoft Trojan Webshield]
{4E8A5278-C04E-4FE3-BF78-8A7CCD6EF333} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\Antispy\IEBuddy.DLL, Kingsoft Corporation>
[XMP Class]
{6483F145-A768-4C41-AACC-52D4D7845851} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work, >
[XDRM]
{693571CB-54A3-4E90-9D52-EEAE1334E2D3} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xdrm.dll_1_work, >
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[MediaComm Class]
{7670648D-461B-42AF-BDFE-46D26AF5EFF2} <C:\Program Files\Thunder Network\WebThunder\InMedia\MediaAddin13.dll, Thunder Networking Technologies,LTD>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[RMGetLicense Class]
{A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation>
[Google Toolbar Helper]
{AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[Google Toolbar Notifier BHO]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[NavigatMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\D盘内容(软件)\⑤杀毒软件\360安全卫士\safemon\safemon.dll, >
[快捷工具条3.1.5]
{BE830FD4-E393-417F-9F4B-CC70ABB3384C} <C:\WINDOWS\system32\IETool.dll, N/A>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
长风飘飘 - 2008-1-6 13:18:00
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[Thunder DapCtrl]
{EF1EA76E-5428-4e40-85A1-D4DD2893183A} <C:\Program Files\Thunder Network\WebThunder\DownAndPlay\DapCtrl1.2.13.16.166.dll, ShenZhen Thunder Networking Technologies Ltd.>
[XPPlayer Class]
{F3E70CEA-956E-49CC-B444-73AFE593AD7F} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\pplayer.dll_1_work, Thunder>
[&使用超级旋风下载]
<D:\Program Files\QQDownload\geturl.htm, N/A>
[&使用超级旋风下载全部链接]
<D:\Program Files\QQDownload\getAllurl.htm, N/A>
[使用WEB迅雷下载]
<C:\Program Files\Thunder Network\WebThunder\GetUrl.htm, N/A>
[使用WEB迅雷下载全部链接]
<C:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ表情]
<D:\Program Files\QQ2007\AddEmotion.htm, N/A>
==================================
正在运行的进程
[PID: 616 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 680 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 712 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4131]
[PID: 756 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 768 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 944 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4131]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2500]
[PID: 964 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1064 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1152 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1248 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1320 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1440 / SYSTEM][C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE] [Kingsoft Corporation, 2007,12,24,165]
[C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2007,11,29,128]
[PID: 1548 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1700 / SYSTEM][C:\WINDOWS\system32\o2flash.exe] [N/A, ]
[PID: 292 / Administrator][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4131]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2500]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[D:\我的游戏\卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[D:\Program Files\QQ2007\DShared.dll] [Tencent, 1, 6, 0, 3]
[PID: 484 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[C:\WINDOWS\system32\okmhdzy.dll] [N/A, ]
[C:\WINDOWS\system32\kaqhlzy.dll] [N/A, ]
[C:\WINDOWS\system32\avzxmmn.dll] [N/A, ]
[C:\WINDOWS\system32\kawdizy.dll] [N/A, ]
[C:\WINDOWS\system32\avwghmn.dll] [N/A, ]
[C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[C:\WINDOWS\system32\wsmsezx.dll] [N/A, ]
[C:\WINDOWS\system32\rsmyjpm.dll] [N/A, ]
[C:\WINDOWS\system32\ratbspi.dll] [N/A, ]
[C:\WINDOWS\Fonts\avwljmn.dll] [N/A, ]
[C:\WINDOWS\system32\rarjepi.dll] [N/A, ]
[C:\WINDOWS\Fonts\swrcgzc.dll] [N/A, ]
[D:\我的游戏\卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll] [, 1, 0, 0, 1]
长风飘飘 - 2008-1-6 13:19:00
[C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 52]
[D:\D盘内容(软件)\⑤杀毒软件\360安全卫士\safemon\safemon.dll] [, 3, 2, 0, 1001]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[PID: 1144 / Administrator][C:\Program Files\Vista风格美化\Vistadrive\vsdrvrt.exe] [, 3, 1, 0, 15]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[D:\我的游戏\卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 1196 / Administrator][C:\Program Files\ATI Technologies\ATI.ACE\cli.exe] [ATI Technologies Inc., 1.11.0.0]
[C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\522148948b03169dcf7dc956777574ec\mscorlib.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\1d8494594e7b5f662f51dcf07521989a\System.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\ca657264e48233ba0015c070ff03612e\System.Drawing.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\0e079d53067580a69d5383ad5db0ee33\System.Windows.Forms.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Implementation.dll] [ATI Technologies Inc., 1.2.2285.36958]
[C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.dll] [ATI Technologies Inc., 1.2.2208.29985]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Foundation.dll] [ATI Technologies Inc., 1.2.2208.29986]
[C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.Service.dll] [ATI Technologies Inc., 1.2.2285.37107]
[C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.Shared.dll] [ATI Technologies Inc., 1.2.2208.29991]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Foundation.XManifestation.dll] [ATI Technologies Inc., 1.2.2285.37108]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\94d3c69432102270d2fdc71ad3b0ab76\System.Xml.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\05305a0e0bfa46d01209154df8565e90\System.Configuration.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Component.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37108]
[C:\Program Files\ATI Technologies\ATI.ACE\ATICCCom.dll] [ATI Technologies Inc., 1.0.0.0]
[C:\Program Files\ATI Technologies\ATI.ACE\AEM.Foundation.dll] [ATI Technologies Inc., 1.2.2208.29985]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Caste.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29987]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Caste.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37103]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Component.Runtime.Shared.dll] [ATI Technologies Inc., 1.2.2208.29988]
[C:\Program Files\ATI Technologies\ATI.ACE\DEM.Foundation.dll] [ATI Technologies Inc., 1.11.0.0]
[C:\Program Files\ATI Technologies\ATI.ACE\DEM.Graphics.I0601.dll] [ATI Technologies Inc., 1.11.0.0]
[C:\Program Files\ATI Technologies\ATI.ACE\ACE.Graphics.DisplaysManager.Shared.dll] [ATI Technologies Inc., 1.11.0.0]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\b9cd39bcef1ded7c1292a7fe39f623f1\System.Web.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\system32\ATIDEMGR.dll] [ATI Technologies Inc., 1.2.2285.36943]
[C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll] [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MultiVPU2.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.36992]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MultiVPU2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29991]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MultiVPU.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37012]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MultiVPU.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.30001]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VeryLargeDesktop.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.36992]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VeryLargeDesktop.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29993]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.Radeon3D.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37029]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.Radeon3DLegacy.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37026]
长风飘飘 - 2008-1-6 13:19:00
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.36996]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.30007]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysColour.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37057]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysColour.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29990]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MMVideo.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37042]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MMVideo.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.30001]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VideoOverlay.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37108]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VideoOverlay.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29989]
[C:\Program Files\ATI Technologies\ATI.ACE\ACE.Graphics.VideoOverlay.Shared.dll] [ATI Technologies Inc., 1.11.0.0]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.SmartGart.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37023]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VPURecover.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37017]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VPURecover.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29988]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.WorkstationConfig.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37015]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37076]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCRT.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2236.29147]
长风飘飘 - 2008-1-6 13:20:00
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCRT2.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37001]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCRT2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2236.29162]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37067]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceLCD.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29994]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceLCD2.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.36996]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceLCD2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29993]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCV.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37072]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCV.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2236.29179]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.CustomFormats.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2236.29132]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCV2.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37004]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCV2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2236.29197]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceTV2.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37064]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceTV.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37060]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37069]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceDFP.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2236.29212]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceDFP2.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.36998]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceDFP2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2236.29221]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.OverDrive3.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37035]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.OverDrive3.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2231.27329]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.OverDrive2.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37040]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.PowerPlay3.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37032]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.PowerPlay3.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29989]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37051]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.IntegratedUMAFrameBuffer.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37046]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.InfoCentre.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37048]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.InfoCentre.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29990]
长风飘飘 - 2008-1-6 13:20:00
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37007]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.30002]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.Radeon3D.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2232.28756]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.Radeon3DLegacy.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2232.28758]
[C:\Program Files\ATI Technologies\ATI.ACE\DEM.Graphics.I0600.dll] [ATI Technologies Inc., 1.11.0.0]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.SmartGart.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29990]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.WorkstationConfig.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29988]
[C:\Program Files\ATI Technologies\ATI.ACE\DEM.Graphics.I0602.dll] [ATI Technologies Inc., 1.11.0.0]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceProperty.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29987]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceProperty2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29986]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceTV2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.30001]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceTV.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29993]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[D:\我的游戏\卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.OverDrive2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29989]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29993]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.IntegratedUMAFrameBuffer.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29988]
[C:\Program Files\ATI Technologies\ATI.ACE\APM.Foundation.dll] [ATI Technologies Inc., 1.2.2208.30002]
[C:\WINDOWS\system32\okmhdzy.dll] [N/A, ]
[C:\WINDOWS\system32\kaqhlzy.dll] [N/A, ]
[C:\WINDOWS\system32\avzxmmn.dll] [N/A, ]
[C:\WINDOWS\system32\kawdizy.dll] [N/A, ]
[C:\WINDOWS\system32\avwghmn.dll] [N/A, ]
[C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
[C:\WINDOWS\system32\wsmsezx.dll] [N/A, ]
[C:\WINDOWS\system32\rsmyjpm.dll] [N/A, ]
[C:\WINDOWS\system32\ratbspi.dll] [N/A, ]
[C:\WINDOWS\Fonts\avwljmn.dll] [N/A, ]
[C:\WINDOWS\system32\rarjepi.dll] [N/A, ]
[C:\WINDOWS\Fonts\swrcgzc.dll] [N/A, ]
[D:\Program Files\QQ2007\DShared.dll] [Tencent, 1, 6, 0, 3]
[PID: 1192 / Administrator][C:\WINDOWS\RTHDCPL.EXE] [Realtek Semiconductor Corp., 2.0.4.4]
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[D:\我的游戏\卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 1408 / Administrator][C:\Program Files\XOSD\XOSD.exe] [N/A, ]
[D:\我的游戏\卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[C:\Program Files\XOSD\keydll.dll] [N/A, ]
[C:\WINDOWS\Fonts\swrcgzc.dll] [N/A, ]
[C:\WINDOWS\Fonts\avwljmn.dll] [N/A, ]
[C:\WINDOWS\system32\rarjepi.dll] [N/A, ]
[C:\WINDOWS\system32\ratbspi.dll] [N/A, ]
[C:\WINDOWS\system32\rsmyjpm.dll] [N/A, ]
[C:\WINDOWS\system32\wsmsezx.dll] [N/A, ]
[C:\WINDOWS\system32\avwghmn.dll] [N/A, ]
[C:\WINDOWS\system32\kawdizy.dll] [N/A, ]
[C:\WINDOWS\system32\avzxmmn.dll] [N/A, ]
[C:\WINDOWS\system32\kaqhlzy.dll] [N/A, ]
[C:\WINDOWS\system32\okmhdzy.dll] [N/A, ]
[PID: 1416 / Administrator][C:\Program Files\Thunder Network\WebThunder\WebThunder.exe] [深圳市迅雷网络技术有限公司, 1, 11, 2, 200]
[C:\Program Files\Thunder Network\WebThunder\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Thunder Network\WebThunder\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 3, 0, 52]
[C:\Program Files\Thunder Network\WebThunder\download_interface.dll] [Thunder Networking Technologies,LTD, 2, 20, 2, 201]
[C:\Program Files\Thunder Network\WebThunder\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031]
[C:\Program Files\Thunder Network\WebThunder\asyn_dns.dll] [Thunder Networking Technologies,LTD, 2, 20, 2, 201]
[C:\Program Files\Thunder Network\WebThunder\streammedialib.dll] [, 1, 3, 2, 103]
[C:\Program Files\Thunder Network\WebThunder\xldc.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 11]
[C:\Program Files\Thunder Network\WebThunder\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 16, 5, 63]
[C:\Program Files\Thunder Network\WebThunder\CacheServer.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[D:\我的游戏\卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\Program Files\Thunder Network\WebThunder\XLSafe\SafeInfo.dll] [深圳市迅雷网络技术有限公司, 1, 0, 1, 0]
[C:\Program Files\Thunder Network\WebThunder\XLNet.Dll] [Thunder Networking Technologies,LTD, 1, 3, 2, 16]
[C:\Program Files\Thunder Network\WebThunder\DownAndPlay\WebDownAndPlay.dll] [ShenZhen Thunder Networking Technologies Ltd., 1, 0, 3, 21]
[C:\Program Files\Thunder Network\WebThunder\XLStatistic\XLStatisticAddin.dll] [深圳市迅雷网络技术有限公司, 1, 3, 0, 4]
[PID: 1424 / Administrator][D:\我的游戏\卡卡\runiep.exe] [Beijing Rising Technology Co., Ltd., 4.0.0.19]
[D:\我的游戏\卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
长风飘飘 - 2008-1-6 13:21:00
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[C:\WINDOWS\system32\okmhdzy.dll] [N/A, ]
[C:\WINDOWS\system32\kaqhlzy.dll] [N/A, ]
[C:\WINDOWS\system32\avzxmmn.dll] [N/A, ]
[C:\WINDOWS\system32\kawdizy.dll] [N/A, ]
[C:\WINDOWS\system32\avwghmn.dll] [N/A, ]
[C:\WINDOWS\system32\wsmsezx.dll] [N/A, ]
[C:\WINDOWS\system32\rsmyjpm.dll] [N/A, ]
[C:\WINDOWS\system32\ratbspi.dll] [N/A, ]
[C:\WINDOWS\Fonts\avwljmn.dll] [N/A, ]
[C:\WINDOWS\system32\rarjepi.dll] [N/A, ]
[C:\WINDOWS\Fonts\swrcgzc.dll] [N/A, ]
[D:\Program Files\QQ2007\DShared.dll] [Tencent, 1, 6, 0, 3]
[PID: 1752 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[D:\我的游戏\卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 1800 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]
[C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]
[C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]
[C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[D:\我的游戏\卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 1300 / Administrator][C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPFW32.EXE] [Kingsoft Corporation, 2007,12,24,165]
[C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll] [Kingsoft Corporation, 2007,11,29,128]
[C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEvent.DLL] [Kingsoft Corporation, 2007,11,29,128]
[C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVIPC2.DLL] [Kingsoft Corporation, 2007,11,29,128]
[C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAConfig.DLL] [Kingsoft Corporation, 2007, 1, 11, 41]
[C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\FiltList.dll] [N/A, ]
[C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVPassp.DLL] [Kingsoft Corporation, 2007,12,29,171]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[D:\我的游戏\卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[PID: 2320 / Administrator][C:\Program Files\RALINK\Common\RaUI.exe] [Ralink Technology, Corp., 1, 1, 9, 0]
[C:\Program Files\RALINK\Common\AegisE5.dll] [Meetinghouse Data Communications, 3, 3, 10, 0]
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
长风飘飘 - 2008-1-6 13:21:00
[D:\我的游戏\卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 3912 / Administrator][C:\Program Files\ATI Technologies\ATI.ACE\cli.exe] [ATI Technologies Inc., 1.11.0.0]
[C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\522148948b03169dcf7dc956777574ec\mscorlib.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\1d8494594e7b5f662f51dcf07521989a\System.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\ca657264e48233ba0015c070ff03612e\System.Drawing.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\0e079d53067580a69d5383ad5db0ee33\System.Windows.Forms.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Implementation.dll] [ATI Technologies Inc., 1.2.2285.36958]
[C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.dll] [ATI Technologies Inc., 1.2.2208.29985]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Foundation.dll] [ATI Technologies Inc., 1.2.2208.29986]
[C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.Service.dll] [ATI Technologies Inc., 1.2.2285.37107]
[C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.Shared.dll] [ATI Technologies Inc., 1.2.2208.29991]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Foundation.XManifestation.dll] [ATI Technologies Inc., 1.2.2285.37108]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\94d3c69432102270d2fdc71ad3b0ab76\System.Xml.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\05305a0e0bfa46d01209154df8565e90\System.Configuration.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Component.Systemtray.dll] [ATI Technologies Inc., 1.2.2285.37085]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Caste.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29987]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Component.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37108]
[C:\Program Files\ATI Technologies\ATI.ACE\ATICCCom.dll] [ATI Technologies Inc., 1.0.0.0]
[C:\Program Files\ATI Technologies\ATI.ACE\ACE.Graphics.DisplaysManager.Shared.dll] [ATI Technologies Inc., 1.11.0.0]
[C:\Program Files\ATI Technologies\ATI.ACE\AEM.Foundation.dll] [ATI Technologies Inc., 1.2.2208.29985]
[C:\Program Files\ATI Technologies\ATI.ACE\APM.Foundation.dll] [ATI Technologies Inc., 1.2.2208.30002]
[C:\Program Files\ATI Technologies\ATI.ACE\zh-CHS\CLI.Component.Systemtray.resources.dll] [ATI Technologies Inc., 1.2.2285.37085]
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[D:\我的游戏\卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\b9cd39bcef1ded7c1292a7fe39f623f1\System.Web.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[D:\Program Files\QQ2007\DShared.dll] [Tencent, 1, 6, 0, 3]
[PID: 3924 / Administrator][C:\Program Files\ATI Technologies\ATI.ACE\cli.exe] [ATI Technologies Inc., 1.11.0.0]
[C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\522148948b03169dcf7dc956777574ec\mscorlib.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\1d8494594e7b5f662f51dcf07521989a\System.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\ca657264e48233ba0015c070ff03612e\System.Drawing.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\0e079d53067580a69d5383ad5db0ee33\System.Windows.Forms.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Implementation.dll] [ATI Technologies Inc., 1.2.2285.36958]
[C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.dll] [ATI Technologies Inc., 1.2.2208.29985]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Foundation.dll] [ATI Technologies Inc., 1.2.2208.29986]
[C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.Service.dll] [ATI Technologies Inc., 1.2.2285.37107]
[C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.Shared.dll] [ATI Technologies Inc., 1.2.2208.29991]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Foundation.XManifestation.dll] [ATI Technologies Inc., 1.2.2285.37108]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\94d3c69432102270d2fdc71ad3b0ab76\System.Xml.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\05305a0e0bfa46d01209154df8565e90\System.Configuration.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Component.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37111]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Foundation.Clients.dll] [ATI Technologies Inc., 1.2.2208.29986]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Component.Dashboard.Shared.dll] [ATI Technologies Inc., 1.2.2208.29987]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Component.Runtime.dll] [ATI Technologies Inc., 1.2.2285.37108]
[C:\Program Files\ATI Technologies\ATI.ACE\ATICCCom.dll] [ATI Technologies Inc., 1.0.0.0]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Caste.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29987]
[C:\Program Files\ATI Technologies\ATI.ACE\AEM.Foundation.dll] [ATI Technologies Inc., 1.2.2208.29985]
[C:\Program Files\ATI Technologies\ATI.ACE\ACE.Graphics.DisplaysManager.Shared.dll] [ATI Technologies Inc., 1.11.0.0]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Caste.Local.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37113]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Caste.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37105]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Caste.Graphics.Dashboard.Shared.dll] [ATI Technologies Inc., 1.2.2208.29990]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.Welcome.Local.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37013]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37049]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37055]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VeryLargeDesktop.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.36989]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37051]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37076]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCRT2.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37002]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37067]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceLCD2.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.36996]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCV.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37073]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCV2.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37005]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceTV2.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37065]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37061]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37070]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceDFP2.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.36999]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37030]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.Radeon3DLegacy.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37027]
[C:\Program Files\ATI
长风飘飘 - 2008-1-6 13:21:00
Technologies\ATI.ACE\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.36994]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysColour.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37058]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MMVideo.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37044]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VideoOverlay.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37021]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.PowerPlay3.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37033]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.SmartGart.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37024]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VPURecover.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37017]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.WorkstationConfig.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37015]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.OverDrive3.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37038]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.OverDrive2.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37040]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.IntegratedUMAFrameBuffer.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37046]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MultiVPU2.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.36955]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MultiVPU.Graphics.Dashboard.dll] [ATI Technologies Inc., 1.2.2285.37008]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.InfoCentre.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29990]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.30002]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VeryLargeDesktop.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29993]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29993]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCRT.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2236.29147]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceProperty.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29987]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCRT2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2236.29162]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceProperty2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29986]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceLCD.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29994]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceLCD2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29993]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCV.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2236.29179]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCV2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2236.29197]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceTV2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.30001]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceTV.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29993]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceDFP.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2236.29212]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceDFP2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2236.29221]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.Radeon3D.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2232.28756]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.Radeon3DLegacy.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2232.28758]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.30007]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysColour.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29990]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MMVideo.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.30001]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VideoOverlay.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29989]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.PowerPlay3.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29989]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.SmartGart.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29990]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VPURecover.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29988]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.WorkstationConfig.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29988]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.OverDrive3.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2231.27329]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.OverDrive2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29989]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.IntegratedUMAFrameBuffer.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29988]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MultiVPU2.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.29991]
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MultiVPU.Graphics.Shared.dll] [ATI Technologies Inc., 1.2.2208.30001]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\b9cd39bcef1ded7c1292a7fe39f623f1\System.Web.ni.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[D:\我的游戏\卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 2412 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[D:\我的游戏\卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[D:\Program Files\QQ2007\DShared.dll] [Tencent, 1, 6, 0, 3]
[PID: 2216 / Administrator][D:\我的游戏\扫日志的\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[D:\我的游戏\卡卡\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\WINDOWS\Fonts\swrcgzc.dll] [N/A, ]
[C:\WINDOWS\system32\rarjepi.dll] [N/A, ]
[C:\WINDOWS\Fonts\avwljmn.dll] [N/A, ]
[C:\WINDOWS\system32\ratbspi.dll] [N/A, ]
[C:\WINDOWS\system32\rsmyjpm.dll] [N/A, ]
[C:\WINDOWS\system32\wsmsezx.dll] [N/A, ]
[C:\WINDOWS\system32\avwghmn.dll] [N/A, ]
[C:\WINDOWS\system32\kawdizy.dll] [N/A, ]
[C:\WINDOWS\system32\avzxmmn.dll] [N/A, ]
[C:\WINDOWS\system32\kaqhlzy.dll] [N/A, ]
[C:\WINDOWS\system32\okmhdzy.dll] [N/A, ]
[D:\我的游戏\扫日志的\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 1144, C:\PROGRAM FILES\VISTA风格美化\VISTADRIVE\VSDRVRT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1144, C:\PROGRAM FILES\VISTA风格美化\VISTADRIVE\VSDRVRT.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1196, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1196, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1408, C:\PROGRAM FILES\XOSD\XOSD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1408, C:\PROGRAM FILES\XOSD\XOSD.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1424, D:\我的游戏\卡卡\RUNIEP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1424, D:\我的游戏\卡卡\RUNIEP.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2320, C:\PROGRAM FILES\RALINK\COMMON\RAUI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2320, C:\PROGRAM FILES\RALINK\COMMON\RAUI.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3912, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3912, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3924, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3924, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
长风飘飘 - 2008-1-6 13:25:00
他的电脑时间也被修改了
aclangzi1314 - 2008-1-6 13:31:00
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[C:\WINDOWS\system32\okmhdzy.dll] [N/A, ]
[C:\WINDOWS\system32\kaqhlzy.dll] [N/A, ]
[C:\WINDOWS\system32\avzxmmn.dll] [N/A, ]
[C:\WINDOWS\system32\kawdizy.dll] [N/A, ]
[C:\WINDOWS\system32\avwghmn.dll] [N/A, ]
[C:\WINDOWS\system32\wsmsezx.dll] [N/A, ]
[C:\WINDOWS\system32\rsmyjpm.dll] [N/A, ]
[C:\WINDOWS\system32\ratbspi.dll] [N/A, ]
[C:\WINDOWS\Fonts\avwljmn.dll] [N/A, ]
[C:\WINDOWS\system32\rarjepi.dll] [N/A, ]
[C:\WINDOWS\Fonts\swrcgzc.dll] [N/A, ]
-----------------------------------------
如果判断没错的话 上面几个文件应该是木马
你可以到baidu上搜索上面的文件名
长风飘飘 - 2008-1-6 13:52:00
那还有人帮忙没
aclangzi1314 - 2008-1-6 13:56:00
参考资料http://bbs.iyaya.com/99/884171.htm
长风飘飘 - 2008-1-17 21:12:00
解决不了
agee - 2008-1-17 22:19:00
删除以下启动项
<wsctf.exe><wsctf.exe> [N/A]
<{E159854F-6971-3456-6941-10235412974E}><C:\WINDOWS\Fonts\hookhelp.dll> []
<{4A57CAD1-412F-9547-713F-9641FA3FC7A4}><C:\WINDOWS\system32\okmhdzy.dll> []
<{C7D81718-1314-5200-2597-58790101807C}><C:\WINDOWS\system32\kaqhlzy.dll> []
<{D859245F-345D-BC13-AC4F-145D47DA34FD}><C:\WINDOWS\system32\avzxmmn.dll> []
<{CD561258-45F3-A451-F908-A258458226DC}><C:\WINDOWS\system32\kvdxslma.dll> [N/A]
<{CC87A354-ABC3-DEDE-FF33-3213FD7447CC}><C:\WINDOWS\system32\kvdxlma.dll> [N/A]
<{9960356A-458E-DE24-BD50-268F589A56A9}><C:\WINDOWS\system32\avwlimn.dll> [N/A]
<{98907901-1416-3389-9981-372178569989}><C:\WINDOWS\system32\kawdizy.dll> []
<{3FA10261-B890-F432-A453-69F1023513F3}><C:\WINDOWS\system32\gjcscyc.dll> [N/A]
<{1D908534-AD45-920F-AC89-4024FA9D26D1}><C:\WINDOWS\system32\gjfhayc.dll> [N/A]
<{8A1247C1-53DA-FF43-ABD3-345F323A48D8}><C:\WINDOWS\system32\avwghmn.dll> []
<{DD561258-45F3-A451-F908-A258458226DD}><C:\WINDOWS\system32\kvdxsmma.dll> []
<{778A7521-FA87-34AB-34C2-4893F3AD34C7}><C:\WINDOWS\system32\swrcfzc.dll> [N/A]
<{792FADFA-BCDE-ACDF-CDEF-21054865CBA7}><C:\WINDOWS\system32\wsmsezx.dll> []
<{AE32FA58-3453-FA2D-BC49-F340348ACCEA}><C:\WINDOWS\system32\rsmyjpm.dll> []
<{47650011-3344-6688-4899-345FABCD1574}><C:\WINDOWS\system32\ratbspi.dll> []
<{A960356A-458E-DE24-BD50-268F589A56AA}><C:\WINDOWS\Fonts\avwljmn.dll> []
<{5598FF45-DA60-F48A-BC43-10AC47853D55}><C:\WINDOWS\system32\rarjepi.dll> []
<{878A7521-FA87-34AB-34C2-4893F3AD34C8}><C:\WINDOWS\Fonts\swrcgzc.dll> []
删除以下驱动
[3n5yjrzwy / 3n5yjrzwy9][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\3n5yjrzwy9.sys><N/A>
[GJ / GJ][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp16.tmp><N/A>
[MS / MS][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp13.tmp><N/A>
[PciHardDisk / PciHardDisk][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\fat32.sys><N/A>
[WD / WD][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp10.tmp><N/A>
[ZHTU / ZHTU][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpD.tmp><N/A>
并删除以下文件
[C:\WINDOWS\Fonts\hookhelp.dll] [N/A, ]
[C:\WINDOWS\system32\okmhdzy.dll] [N/A, ]
[C:\WINDOWS\system32\kaqhlzy.dll] [N/A, ]
[C:\WINDOWS\system32\avzxmmn.dll] [N/A, ]
[C:\WINDOWS\system32\kawdizy.dll] [N/A, ]
[C:\WINDOWS\system32\avwghmn.dll] [N/A, ]
[C:\WINDOWS\system32\kvdxsmma.dll] [N/A, ]
[C:\WINDOWS\system32\wsmsezx.dll] [N/A, ]
[C:\WINDOWS\system32\rsmyjpm.dll] [N/A, ]
[C:\WINDOWS\system32\ratbspi.dll] [N/A, ]
[C:\WINDOWS\Fonts\avwljmn.dll] [N/A, ]
[C:\WINDOWS\system32\rarjepi.dll] [N/A, ]
[C:\WINDOWS\Fonts\swrcgzc.dll] [N/A, ]
还有上面提到的未列出的,统统都删了,太多了,懒得贴了-_-!!
清空IE缓存
1
© 2000 - 2026 Rising Corp. Ltd.