[CODE] 2008-05-15,19:28:43 System Repair Engineer 2.5.16.900 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [N/A] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] <00PCTFW><"E:\PC Tools Firewall Plus\FirewallGUI.exe" -s> [(Verified)PC Tools] <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd] <"C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE> [Eset ] <360Antiarp> [(Verified)Qizhi Software (beijing) Co. Ltd] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [N/A] <%systemroot%\system32\dumprep 0 -k> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A] ================================== 启动文件夹 [IEPlus] [N/A]> ================================== 服务 [Contrl Center of Storm Media / ccosm][Running/Auto Start] <北京暴风网际科技有限公司> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [NOD32 Kernel Service / NOD32krn][Running/Auto Start] <"C:\Program Files\Eset\nod32krn.exe"> [NVIDIA Driver Helper Service / NVSvc][Running/Auto Start] [PC Tools Firewall Plus / PCToolsFirewallPlus][Running/Auto Start] [Windows User Mode Driver Framework / UMWdf][Stopped/Auto Start] ================================== 驱动程序 [0xfq1 / 0xfq1][Stopped/Boot Start] <\SystemRoot\system32\drivers\0xfq1.sys> [2310_00 / 2310_00][Stopped/Boot Start] <\SystemRoot\System32\BIRD\2310_00.sys> [360AntiArp / 360AntiArp][Running/System Start] <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心> [3WAREDRV / 3WAREDRV][Stopped/Boot Start] <\SystemRoot\System32\BIRD\3WAREDRV.SYS> [3WAREGSM / 3WAREGSM][Stopped/Boot Start] <\SystemRoot\System32\BIRD\3waregsm.sys> [3WDRV100 / 3WDRV100][Stopped/Boot Start] <\SystemRoot\System32\BIRD\3WDRV100.SYS> [A320RAID / A320RAID][Stopped/Boot Start] <\SystemRoot\System32\BIRD\a320raid.sys> [AAC / AAC][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aac.sys> [AACSAS / AACSAS][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aacsas.sys> [AAR81XX / AAR81XX][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aar81xx.sys> [AARSI3X / AARSI3X][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aarsi3x.sys> [ADP94XX / ADP94XX][Stopped/Boot Start] <\SystemRoot\System32\BIRD\adp94xx.sys> [adpu160m / adpu160m][Stopped/Boot Start] <\SystemRoot\System32\BIRD\adpu160m.sys> [ADPU320 / ADPU320][Stopped/Boot Start] <\SystemRoot\System32\BIRD\adpu320.sys> [AEC6210 / AEC6210][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aec6210.sys> [AEC6260 / AEC6260][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aec6260.sys> [AEC6280 / AEC6280][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aec6280.sys> [AEC67160 / AEC67160][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aec67160.sys> [AEC67162 / AEC67162][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aec67162.sys> [AEC671X / AEC671X][Stopped/Boot Start] <\SystemRoot\System32\BIRD\AEC671X.sys> [AEC6880 / AEC6880][Stopped/Boot Start] <\SystemRoot\System32\BIRD\AEC6880.sys> [AEC6897 / AEC6897][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aec6897.sys> [AEC68X5 / AEC68X5][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aec68x5.sys> [aic78u2 / aic78u2][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aic78u2.sys> [aic78xx / aic78xx][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aic78xx.sys> [AMON / AMON][Running/Auto Start] <\SystemRoot\system32\drivers\amon.sys> [ARCM_X86 / ARCM_X86][Stopped/Boot Start] <\SystemRoot\System32\BIRD\arcm_x86.sys> [asc / asc][Stopped/Boot Start] <\SystemRoot\System32\BIRD\asc.sys> [BCHTSW32 / BCHTSW32][Stopped/Boot Start] <\SystemRoot\System32\BIRD\bchtsw32.sys> [buslogic / buslogic][Stopped/Boot Start] <\SystemRoot\System32\bird\buslogic.sys> [CDA1000 / CDA1000][Stopped/Boot Start] <\SystemRoot\System32\BIRD\cda1000.sys> [CmdIde / CmdIde][Running/Boot Start] <\SystemRoot\System32\BIRD\cmdide.sys> [CPQARRY2 / CPQARRY2][Stopped/Boot Start] <\SystemRoot\System32\BIRD\cpqarry2.sys> [CPQCISSM / CPQCISSM][Stopped/Boot Start] <\SystemRoot\System32\BIRD\cpqcissm.sys> [CSB6IDE / CSB6IDE][Running/Boot Start] <\SystemRoot\System32\BIRD\csb6ide.sys> [dac2w2k / dac2w2k][Stopped/Boot Start] <\SystemRoot\System32\BIRD\dac2w2k.sys> [DMX3191 / DMX3191][Stopped/Boot Start] <\SystemRoot\System32\BIRD\DMX3191.sys> [DMX3194 / DMX3194][Stopped/Boot Start] <\SystemRoot\System32\BIRD\dmx3194.sys> [dpti2o / dpti2o][Stopped/Boot Start] <\SystemRoot\System32\BIRD\dpti2o.sys> [DPTSCSI / DPTSCSI][Stopped/Boot Start] <\SystemRoot\System32\BIRD\dptscsi.sys> [FASTSX / FASTSX][Stopped/Boot Start] <\SystemRoot\System32\BIRD\fastsx.sys> [FASTTRAK / FASTTRAK][Stopped/Boot Start] <\SystemRoot\System32\BIRD\fasttrak.sys> [FASTTX2K / FASTTX2K][Stopped/Boot Start] <\SystemRoot\System32\BIRD\fasttx2k.sys> [fd16_700 / fd16_700][Stopped/Boot Start] <\SystemRoot\System32\BIRD\fd16_700.sys> [fireport / fireport][Stopped/Boot Start] <\SystemRoot\System32\BIRD\fireport.sys> [flashpnt / flashpnt][Stopped/Boot Start] <\SystemRoot\System32\BIRD\flashpnt.sys> [FT8300 / FT8300][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ft8300.sys> [FTSATA2 / FTSATA2][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ftsata2.sys> [GD31244 / GD31244][Stopped/Boot Start] <\SystemRoot\System32\BIRD\gd31244.sys> [HPCISSS2 / HPCISSS2][Stopped/Boot Start] <\SystemRoot\System32\BIRD\hpcisss2.sys> [HPT371 / HPT371][Stopped/Boot Start] <\SystemRoot\System32\BIRD\HPT371.sys> [HPT374 / HPT374][Stopped/Boot Start] <\SystemRoot\System32\BIRD\hpt374.sys> [HPT3XX / HPT3XX][Stopped/Boot Start] <\SystemRoot\System32\BIRD\hpt3xx.sys> [IASTOR / IASTOR][Running/Boot Start] <\SystemRoot\System32\BIRD\iaStor.sys> [IFT2000 / IFT2000][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ift2000.sys> [ini910u / ini910u][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ini910u.sys> [INIA100 / INIA100][Stopped/Boot Start] <\SystemRoot\System32\BIRD\INIA100.sys> [IPSRAIDN / IPSRAIDN][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ipsraidn.sys> [ITERAID / ITERAID][Stopped/Boot Start] <\SystemRoot\System32\BIRD\iteraid.sys> [JRAID / JRAID][Stopped/Boot Start] <\SystemRoot\System32\BIRD\JRAID.SYS> [M5228 / M5228][Stopped/Boot Start] <\SystemRoot\System32\BIRD\m5228.sys> [M5281 / M5281][Stopped/Boot Start] <\SystemRoot\System32\BIRD\m5281.sys> [M5287 / M5287][Stopped/Boot Start] <\SystemRoot\System32\BIRD\m5287.sys> [M5288 / M5288][Stopped/Boot Start] <\SystemRoot\System32\BIRD\m5288.sys> [M5289 / M5289][Stopped/Boot Start] <\SystemRoot\System32\BIRD\m5289.sys> [MEGAIDE / MEGAIDE][Stopped/Boot Start] <\SystemRoot\System32\BIRD\MegaIDE.sys> [mraid35x / mraid35x][Stopped/Boot Start] <\SystemRoot\System32\BIRD\mraid35x.sys> [NFRD960 / NFRD960][Stopped/Boot Start] <\SystemRoot\System32\BIRD\nfrd960.sys> [nod32drv / nod32drv][Running/System Start] <\SystemRoot\system32\drivers\nod32drv.sys> [npkcrypt / npkcrypt][Running/Auto Start] <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys> [nv / nv][Running/Manual Start] [NVATABUS / NVATABUS][Running/Boot Start] <\SystemRoot\System32\BIRD\NVATABUS.SYS> [NVRAID / NVRAID][Stopped/Boot Start] <\SystemRoot\System32\BIRD\NVRAID.SYS> [DDK PACKET Protocol / Packet][Running/Manual Start] <360安全中心> [pctfw2 / pctfw2][Running/System Start] <\??\C:\WINDOWS\system32\drivers\pctfw2.sys> [PC Tools Firewall Memory Protection Driver / pctmp][Running/System Start] [PC Tools Security Suite IPC Driver / pctssipc][Running/System Start] [perc2 / perc2][Stopped/Boot Start] <\SystemRoot\System32\BIRD\perc2.sys> [PNP649R / PNP649R][Stopped/Boot Start] <\SystemRoot\System32\BIRD\pnp649r.sys> [PNP680 / PNP680][Stopped/Boot Start] <\SystemRoot\System32\BIRD\pnp680.sys> [PNP680R / PNP680R][Stopped/Boot Start] <\SystemRoot\System32\BIRD\pnp680r.sys> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [ql1080 / ql1080][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ql1080.sys> [Ql10wnt / Ql10wnt][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ql10wnt.sys> [ql12160 / ql12160][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ql12160.sys> [ql1280 / ql1280][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ql1280.sys> [qo46 / qo46][Stopped/Boot Start] <\SystemRoot\system32\drivers\qo46.sys> [RAIDSRC / RAIDSRC][Stopped/Boot Start] <\SystemRoot\System32\BIRD\raidsrc.sys> [RR232X / RR232X][Stopped/Boot Start] <\SystemRoot\System32\BIRD\rr232x.sys> [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start] [S150SX8 / S150SX8][Stopped/Boot Start] <\SystemRoot\System32\BIRD\S150sx8.sys> [SafeBoxKrnl / SafeBoxKrnl][Running/System Start] <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心> [Secdrv / Secdrv][Stopped/Manual Start] [PCTools Driver / SFilter][Running/Manual Start] [SI3112 / SI3112][Stopped/Boot Start] <\SystemRoot\System32\BIRD\SI3112.sys> [SI3112R / SI3112R][Stopped/Boot Start] <\SystemRoot\System32\BIRD\SI3112r.sys> [SI3114 / SI3114][Stopped/Boot Start] <\SystemRoot\System32\BIRD\SI3114.sys> [SI3114R / SI3114R][Stopped/Boot Start] <\SystemRoot\SYSTEM32\BIRD\SI3114R.sys> [SI3114R5 / SI3114R5][Stopped/Boot Start] <\SystemRoot\System32\BIRD\Si3114r5.sys> [SI3124 / SI3124][Stopped/Boot Start] <\SystemRoot\SYSTEM32\BIRD\SI3124.sys> [SI3124R / SI3124R][Stopped/Boot Start] <\SystemRoot\SYSTEM32\BIRD\SI3124R.sys> [SI3124R5 / SI3124R5][Stopped/Boot Start] <\SystemRoot\SYSTEM32\BIRD\Si3124r5.sys> [SI3132 / SI3132][Stopped/Boot Start] <\SystemRoot\System32\BIRD\SI3132.sys> [SI3132R5 / SI3132R5][Stopped/Boot Start] <\SystemRoot\System32\BIRD\Si3132r5.sys> [SIS AGP Bus Filter / sisagp][Running/Boot Start] <\SystemRoot\system32\DRIVERS\sisagp.sys> [SISRAID / SISRAID][Stopped/Boot Start] <\SystemRoot\System32\BIRD\SiSRaid.sys> [SISRAID2 / SISRAID2][Stopped/Boot Start] <\SystemRoot\System32\BIRD\SiSRaid2.sys> [SISRAID4 / SISRAID4][Stopped/Boot Start] <\SystemRoot\System32\BIRD\SiSRaid4.sys> [SPTRAK / SPTRAK][Stopped/Boot Start] <\SystemRoot\System32\BIRD\sptrak.sys> [ST8350 / ST8350][Stopped/Boot Start] <\SystemRoot\System32\BIRD\st8350.sys> [symc810 / symc810][Stopped/Boot Start] <\SystemRoot\System32\BIRD\symc810.sys> [symc8xx / symc8xx][Stopped/Boot Start] <\SystemRoot\System32\BIRD\symc8xx.sys> [SYMMPI / SYMMPI][Stopped/Boot Start] <\SystemRoot\System32\BIRD\symmpi.sys> [sym_hi / sym_hi][Stopped/Boot Start] <\SystemRoot\System32\BIRD\sym_hi.sys> [sym_u3 / sym_u3][Stopped/Boot Start] <\SystemRoot\System32\BIRD\sym_u3.sys> [TRM3X5 / TRM3X5][Stopped/Boot Start] <\SystemRoot\System32\BIRD\trm3x5.sys> [ULSATA / ULSATA][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ulsata.sys> [ULSATA2 / ULSATA2][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ulsata2.sys> [ULTIMA / ULTIMA][Stopped/Boot Start] <\SystemRoot\System32\BIRD\Ultima.sys> [ULTIMARX / ULTIMARX][Stopped/Boot Start] <\SystemRoot\System32\BIRD\UltimaRX.sys> [ultra / ultra][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ultra.sys> [ViaIde / ViaIde][Running/Boot Start] <\SystemRoot\system32\DRIVERS\viaide.sys> [VIAMRAID / VIAMRAID][Stopped/Boot Start] <\SystemRoot\System32\BIRD\viamraid.sys> [Vinyl AC'97 Audio Controller (WDM) / VIAudio][Running/Manual Start] [W2KADV / W2KADV][Stopped/Boot Start] <\SystemRoot\System32\BIRD\w2kadv.sys> [WD7296A / WD7296A][Stopped/Boot Start] <\SystemRoot\System32\BIRD\wd7296a.sys> [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start] [新泰超级摄像头 / ZSMC301b][Running/Manual Start] [kgri0ap / kgri0ap][Stopped/Boot Start] <\SystemRoot\system32\drivers\kgri0ap.sys> [o5im3 / o5im3][Stopped/Boot Start] <\SystemRoot\system32\drivers\o5im3.sys> ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [知识库] {06926B30-424E-4f1c-8EE3-543CD96573DC} [启动迅雷5] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} [浩方对战平台] {0A155D3C-68E2-4215-A47A-E800A446447A} [JUJU猫] {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} [Messenger] {FB5F1910-F110-11d2-BB9E-00C04F795683} [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [GerneralPeerID Class] {0A47E819-F82E-4D5D-B806-6A9EA94D68CD} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [XMP Class] {6483F145-A768-4C41-AACC-52D4D7845851} [XDRM] {693571CB-54A3-4E90-9D52-EEAE1334E2D3} [MediaComm Class] {7670648D-461B-42AF-BDFE-46D26AF5EFF2} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [RMGetLicense Class] {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} [DapCtrl COM Module] {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} [RDS.DataSpace] {BD96C556-65A3-11D0-983A-00C04FC29E36} [AUDIO__MP3 Moniker Class] {CD3AFA76-B84F-48F0-9393-7EDC34128127} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [Thunder DapPlayer] {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] [添加到QQ表情] ================================== 正在运行的进程 [PID: 652 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 704 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 728 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 772 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 784 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 940 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1000 / SYSTEM][E:\PC Tools Firewall Plus\FWService.exe] [PC Tools, 3, 0, 1, 13] [E:\PC Tools Firewall Plus\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [E:\PC Tools Firewall Plus\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [E:\PC Tools Firewall Plus\FirewallWrapper.dll] [PC Tools, 3, 0, 1, 13] [E:\PC Tools Firewall Plus\Objects.dll] [PC Tools, 3, 0, 1, 13] [E:\PC Tools Firewall Plus\Comms.dll] [PC Tools, 3, 0, 1, 13] [E:\PC Tools Firewall Plus\PCTWSC.dll] [PC Tools, 1, 0, 0, 12] [E:\PC Tools Firewall Plus\FwMemProtect.dll] [PC Tools Pty Ltd, 1.0.0.17] [PID: 1084 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 1220 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)] [PID: 1276 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 1492 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 1956 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\Program Files\Media Player Classic\Codecs\mmfinfo.dll] [N/A, ] [C:\Program Files\Media Player Classic\Codecs\mkunicode.dll] [N/A, ] [D:\迅雷\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [D:\迅雷\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [D:\迅雷\Components\ResWorker\DsBho_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 19] [D:\迅雷\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] [PID: 1996 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll] [Windows (R) 2000 DDK provider, 5.00.2195.1620] [PID: 296 / Administrator][E:\PC Tools Firewall Plus\FirewallGUI.exe] [PC Tools, 3, 0, 1, 14] [E:\PC Tools Firewall Plus\Objects.dll] [PC Tools, 3, 0, 1, 13] [E:\PC Tools Firewall Plus\Comms.dll] [PC Tools, 3, 0, 1, 13] [E:\PC Tools Firewall Plus\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [E:\PC Tools Firewall Plus\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [E:\PC Tools Firewall Plus\FirewallPlugin.dll] [PC Tools, 3, 0, 1, 13] [PID: 312 / Administrator][C:\Program Files\Eset\nod32kui.exe] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\nod32rui.dll] [N/A, ] [C:\Program Files\Eset\pu_amon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_amon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pu_dmon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_dmon.dll] [N/A, ] [C:\Program Files\Eset\pu_emon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_emon.dll] [N/A, ] [C:\Program Files\Eset\pu_imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [C:\Program Files\Eset\pu_nod32.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_nod32.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pu_upd.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_upd.dll] [N/A, ] [PID: 320 / Administrator][E:\360safe_2.3\360safe_2.3\antiarp\antiarp.exe] [360安全中心, 2, 0, 0, 1008] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 340 / Administrator][C:\WINDOWS\VM_STI.EXE] [Vimicro, 4, 2, 1225, 6] [C:\WINDOWS\system32\msdmo.dll] [, ] [C:\WINDOWS\system32\VM31bPrp.Ax] [Vimicro, 1.00.01.00] [PID: 464 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 496 / Administrator][C:\WINDOWS\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\NVMCTRAY.DLL] [NVIDIA Corporation, 6.14.10.4523] [PID: 552 / SYSTEM][E:\暴风影音\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 3, 15] [E:\暴风影音\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 1724 / SYSTEM][C:\Program Files\Eset\nod32krn.exe] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\nod32krr.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\ps_amon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_amon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\ps_dmon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_dmon.dll] [N/A, ] [C:\Program Files\Eset\ps_emon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_emon.dll] [N/A, ] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [C:\Program Files\Eset\ps_nod32.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_nod32.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\ps_upd.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_upd.dll] [N/A, ] [PID: 1764 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.4523] [PID: 240 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2148 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 2072 / Administrator][E:\AVIConverter\AVIConverter.exe] [N/A, ] [C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.3802.3802 built by: dnsrv(bld4act)] [PID: 2360 / Administrator][C:\WINDOWS\system32\cmd.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2716 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2944 / Administrator][E:\AVIConverter\mencoder.exe] [, Sherpya-MinGW-20060312-4.1.0] [E:\AVIConverter\drv43260.dll] [RealNetworks, Inc., 6.0.7.2389] [E:\AVIConverter\PNCRT.dll] [Real Networks, Inc, 6.0.0.0] [PID: 2460 / Administrator][F:\反病毒软件\293_System Repair Engineer V2.3\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900] [F:\反病毒软件\293_System Repair Engineer V2.3\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] ================================== 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 NOD32 protected [MSAFD Tcpip [TCP/IP]] C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) NOD32 protected [MSAFD Tcpip [UDP/IP]] C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) NOD32 protected [MSAFD Tcpip [RAW/IP]] C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) NOD32 protected [RSVP UDP Service Provider] C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) NOD32 protected [RSVP TCP Service Provider] C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) NOD32 C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 312, C:\PROGRAM FILES\ESET\NOD32KUI.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 340, C:\WINDOWS\VM_STI.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2072, E:\AVICONVERTER\AVICONVERTER.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2944, E:\AVICONVERTER\MENCODER.EXE] ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]