[CODE] 2008-06-01,13:04:54 System Repair Engineer 2.5.16.900 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [] [土豆网] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [N/A] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] <00PCTFW><"E:\PC Tools Firewall Plus\PC Tools Firewall Plus\FirewallGUI.exe" -s> [(Verified)PC Tools] <"C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE> [Eset ] <360Antiarp> [(Verified)Qizhi Software (beijing) Co. Ltd] <360Safetray> [(Verified)Qizhi Software (beijing) Co. Ltd] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A] ================================== 启动文件夹 N/A ================================== 服务 [Contrl Center of Storm Media / ccosm][Running/Auto Start] <北京暴风网际科技有限公司> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [NOD32 Kernel Service / NOD32krn][Running/Auto Start] <"C:\Program Files\Eset\nod32krn.exe"> [PC Tools Firewall Plus / PCToolsFirewallPlus][Running/Auto Start] [Windows User Mode Driver Framework / UMWdf][Stopped/Auto Start] ================================== 驱动程序 [2310_00 / 2310_00][Stopped/Boot Start] <\SystemRoot\System32\BIRD\2310_00.sys> [360AntiArp / 360AntiArp][Running/System Start] <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心> [3WAREDRV / 3WAREDRV][Stopped/Boot Start] <\SystemRoot\System32\BIRD\3WAREDRV.SYS> [3WAREGSM / 3WAREGSM][Stopped/Boot Start] <\SystemRoot\System32\BIRD\3waregsm.sys> [3WDRV100 / 3WDRV100][Stopped/Boot Start] <\SystemRoot\System32\BIRD\3WDRV100.SYS> [A320RAID / A320RAID][Stopped/Boot Start] <\SystemRoot\System32\BIRD\a320raid.sys> [AAC / AAC][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aac.sys> [AACSAS / AACSAS][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aacsas.sys> [AAR81XX / AAR81XX][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aar81xx.sys> [AARSI3X / AARSI3X][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aarsi3x.sys> [ADP94XX / ADP94XX][Stopped/Boot Start] <\SystemRoot\System32\BIRD\adp94xx.sys> [adpu160m / adpu160m][Stopped/Boot Start] <\SystemRoot\System32\BIRD\adpu160m.sys> [ADPU320 / ADPU320][Stopped/Boot Start] <\SystemRoot\System32\BIRD\adpu320.sys> [AEC6210 / AEC6210][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aec6210.sys> [AEC6260 / AEC6260][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aec6260.sys> [AEC6280 / AEC6280][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aec6280.sys> [AEC67160 / AEC67160][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aec67160.sys> [AEC67162 / AEC67162][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aec67162.sys> [AEC671X / AEC671X][Stopped/Boot Start] <\SystemRoot\System32\BIRD\AEC671X.sys> [AEC6880 / AEC6880][Stopped/Boot Start] <\SystemRoot\System32\BIRD\AEC6880.sys> [AEC6897 / AEC6897][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aec6897.sys> [AEC68X5 / AEC68X5][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aec68x5.sys> [aic78u2 / aic78u2][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aic78u2.sys> [aic78xx / aic78xx][Stopped/Boot Start] <\SystemRoot\System32\BIRD\aic78xx.sys> [AMON / AMON][Running/Auto Start] <\SystemRoot\system32\drivers\amon.sys> [ARCM_X86 / ARCM_X86][Stopped/Boot Start] <\SystemRoot\System32\BIRD\arcm_x86.sys> [asc / asc][Stopped/Boot Start] <\SystemRoot\System32\BIRD\asc.sys> [BCHTSW32 / BCHTSW32][Stopped/Boot Start] <\SystemRoot\System32\BIRD\bchtsw32.sys> [buslogic / buslogic][Stopped/Boot Start] <\SystemRoot\System32\bird\buslogic.sys> [CDA1000 / CDA1000][Stopped/Boot Start] <\SystemRoot\System32\BIRD\cda1000.sys> [CmdIde / CmdIde][Running/Boot Start] <\SystemRoot\System32\BIRD\cmdide.sys> [CPQARRY2 / CPQARRY2][Stopped/Boot Start] <\SystemRoot\System32\BIRD\cpqarry2.sys> [CPQCISSM / CPQCISSM][Stopped/Boot Start] <\SystemRoot\System32\BIRD\cpqcissm.sys> [CSB6IDE / CSB6IDE][Running/Boot Start] <\SystemRoot\System32\BIRD\csb6ide.sys> [dac2w2k / dac2w2k][Stopped/Boot Start] <\SystemRoot\System32\BIRD\dac2w2k.sys> [DMX3191 / DMX3191][Stopped/Boot Start] <\SystemRoot\System32\BIRD\DMX3191.sys> [DMX3194 / DMX3194][Stopped/Boot Start] <\SystemRoot\System32\BIRD\dmx3194.sys> [dpti2o / dpti2o][Stopped/Boot Start] <\SystemRoot\System32\BIRD\dpti2o.sys> [DPTSCSI / DPTSCSI][Stopped/Boot Start] <\SystemRoot\System32\BIRD\dptscsi.sys> [FASTSX / FASTSX][Stopped/Boot Start] <\SystemRoot\System32\BIRD\fastsx.sys> [FASTTRAK / FASTTRAK][Stopped/Boot Start] <\SystemRoot\System32\BIRD\fasttrak.sys> [FASTTX2K / FASTTX2K][Stopped/Boot Start] <\SystemRoot\System32\BIRD\fasttx2k.sys> [fd16_700 / fd16_700][Stopped/Boot Start] <\SystemRoot\System32\BIRD\fd16_700.sys> [fireport / fireport][Stopped/Boot Start] <\SystemRoot\System32\BIRD\fireport.sys> [flashpnt / flashpnt][Stopped/Boot Start] <\SystemRoot\System32\BIRD\flashpnt.sys> [FT8300 / FT8300][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ft8300.sys> [FTSATA2 / FTSATA2][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ftsata2.sys> [GD31244 / GD31244][Stopped/Boot Start] <\SystemRoot\System32\BIRD\gd31244.sys> [HPCISSS2 / HPCISSS2][Stopped/Boot Start] <\SystemRoot\System32\BIRD\hpcisss2.sys> [HPT371 / HPT371][Stopped/Boot Start] <\SystemRoot\System32\BIRD\HPT371.sys> [HPT374 / HPT374][Stopped/Boot Start] <\SystemRoot\System32\BIRD\hpt374.sys> [HPT3XX / HPT3XX][Stopped/Boot Start] <\SystemRoot\System32\BIRD\hpt3xx.sys> [IASTOR / IASTOR][Running/Boot Start] <\SystemRoot\System32\BIRD\iaStor.sys> [IFT2000 / IFT2000][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ift2000.sys> [ini910u / ini910u][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ini910u.sys> [INIA100 / INIA100][Stopped/Boot Start] <\SystemRoot\System32\BIRD\INIA100.sys> [IPSRAIDN / IPSRAIDN][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ipsraidn.sys> [ITERAID / ITERAID][Stopped/Boot Start] <\SystemRoot\System32\BIRD\iteraid.sys> [JRAID / JRAID][Stopped/Boot Start] <\SystemRoot\System32\BIRD\JRAID.SYS> [M5228 / M5228][Stopped/Boot Start] <\SystemRoot\System32\BIRD\m5228.sys> [M5281 / M5281][Stopped/Boot Start] <\SystemRoot\System32\BIRD\m5281.sys> [M5287 / M5287][Stopped/Boot Start] <\SystemRoot\System32\BIRD\m5287.sys> [M5288 / M5288][Stopped/Boot Start] <\SystemRoot\System32\BIRD\m5288.sys> [M5289 / M5289][Stopped/Boot Start] <\SystemRoot\System32\BIRD\m5289.sys> [MEGAIDE / MEGAIDE][Stopped/Boot Start] <\SystemRoot\System32\BIRD\MegaIDE.sys> [mraid35x / mraid35x][Stopped/Boot Start] <\SystemRoot\System32\BIRD\mraid35x.sys> [NFRD960 / NFRD960][Stopped/Boot Start] <\SystemRoot\System32\BIRD\nfrd960.sys> [nod32drv / nod32drv][Running/System Start] <\SystemRoot\system32\drivers\nod32drv.sys> [npkcrypt / npkcrypt][Running/Auto Start] <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys> [nv / nv][Running/Manual Start] [NVATABUS / NVATABUS][Running/Boot Start] <\SystemRoot\System32\BIRD\NVATABUS.SYS> [NVRAID / NVRAID][Stopped/Boot Start] <\SystemRoot\System32\BIRD\NVRAID.SYS> [pctfw2 / pctfw2][Running/System Start] <\??\C:\WINDOWS\system32\drivers\pctfw2.sys> [PC Tools Firewall Memory Protection Driver / pctmp][Running/System Start] [PC Tools Security Suite IPC Driver / pctssipc][Running/System Start] [perc2 / perc2][Stopped/Boot Start] <\SystemRoot\System32\BIRD\perc2.sys> [PNP649R / PNP649R][Stopped/Boot Start] <\SystemRoot\System32\BIRD\pnp649r.sys> [PNP680 / PNP680][Stopped/Boot Start] <\SystemRoot\System32\BIRD\pnp680.sys> [PNP680R / PNP680R][Stopped/Boot Start] <\SystemRoot\System32\BIRD\pnp680r.sys> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [ql1080 / ql1080][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ql1080.sys> [Ql10wnt / Ql10wnt][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ql10wnt.sys> [ql12160 / ql12160][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ql12160.sys> [ql1280 / ql1280][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ql1280.sys> [RAIDSRC / RAIDSRC][Stopped/Boot Start] <\SystemRoot\System32\BIRD\raidsrc.sys> [RR232X / RR232X][Stopped/Boot Start] <\SystemRoot\System32\BIRD\rr232x.sys> [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start] [S150SX8 / S150SX8][Stopped/Boot Start] <\SystemRoot\System32\BIRD\S150sx8.sys> [Secdrv / Secdrv][Stopped/Manual Start] [PCTools Driver / SFilter][Running/Manual Start] [SI3112 / SI3112][Stopped/Boot Start] <\SystemRoot\System32\BIRD\SI3112.sys> [SI3112R / SI3112R][Stopped/Boot Start] <\SystemRoot\System32\BIRD\SI3112r.sys> [SI3114 / SI3114][Stopped/Boot Start] <\SystemRoot\System32\BIRD\SI3114.sys> [SI3114R / SI3114R][Stopped/Boot Start] <\SystemRoot\SYSTEM32\BIRD\SI3114R.sys> [SI3114R5 / SI3114R5][Stopped/Boot Start] <\SystemRoot\System32\BIRD\Si3114r5.sys> [SI3124 / SI3124][Stopped/Boot Start] <\SystemRoot\SYSTEM32\BIRD\SI3124.sys> [SI3124R / SI3124R][Stopped/Boot Start] <\SystemRoot\SYSTEM32\BIRD\SI3124R.sys> [SI3124R5 / SI3124R5][Stopped/Boot Start] <\SystemRoot\SYSTEM32\BIRD\Si3124r5.sys> [SI3132 / SI3132][Stopped/Boot Start] <\SystemRoot\System32\BIRD\SI3132.sys> [SI3132R5 / SI3132R5][Stopped/Boot Start] <\SystemRoot\System32\BIRD\Si3132r5.sys> [SIS AGP Bus Filter / sisagp][Running/Boot Start] <\SystemRoot\system32\DRIVERS\sisagp.sys> [SISRAID / SISRAID][Stopped/Boot Start] <\SystemRoot\System32\BIRD\SiSRaid.sys> [SISRAID2 / SISRAID2][Stopped/Boot Start] <\SystemRoot\System32\BIRD\SiSRaid2.sys> [SISRAID4 / SISRAID4][Stopped/Boot Start] <\SystemRoot\System32\BIRD\SiSRaid4.sys> [SPTRAK / SPTRAK][Stopped/Boot Start] <\SystemRoot\System32\BIRD\sptrak.sys> [ST8350 / ST8350][Stopped/Boot Start] <\SystemRoot\System32\BIRD\st8350.sys> [symc810 / symc810][Stopped/Boot Start] <\SystemRoot\System32\BIRD\symc810.sys> [symc8xx / symc8xx][Stopped/Boot Start] <\SystemRoot\System32\BIRD\symc8xx.sys> [SYMMPI / SYMMPI][Stopped/Boot Start] <\SystemRoot\System32\BIRD\symmpi.sys> [sym_hi / sym_hi][Stopped/Boot Start] <\SystemRoot\System32\BIRD\sym_hi.sys> [sym_u3 / sym_u3][Stopped/Boot Start] <\SystemRoot\System32\BIRD\sym_u3.sys> [TRM3X5 / TRM3X5][Stopped/Boot Start] <\SystemRoot\System32\BIRD\trm3x5.sys> [ULSATA / ULSATA][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ulsata.sys> [ULSATA2 / ULSATA2][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ulsata2.sys> [ULTIMA / ULTIMA][Stopped/Boot Start] <\SystemRoot\System32\BIRD\Ultima.sys> [ULTIMARX / ULTIMARX][Stopped/Boot Start] <\SystemRoot\System32\BIRD\UltimaRX.sys> [ultra / ultra][Stopped/Boot Start] <\SystemRoot\System32\BIRD\ultra.sys> [ViaIde / ViaIde][Running/Boot Start] <\SystemRoot\system32\DRIVERS\viaide.sys> [VIAMRAID / VIAMRAID][Stopped/Boot Start] <\SystemRoot\System32\BIRD\viamraid.sys> [Vinyl AC'97 Audio Controller (WDM) / VIAudio][Running/Manual Start] [W2KADV / W2KADV][Stopped/Boot Start] <\SystemRoot\System32\BIRD\w2kadv.sys> [WD7296A / WD7296A][Stopped/Boot Start] <\SystemRoot\System32\BIRD\wd7296a.sys> [DDK PACKET Protocol / Packet][Running/Manual Start] <360安全中心> [xAntiArpSpoof Service / xAntiArp][Stopped/Manual Start] ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [启动迅雷5] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} [浩方对战平台] {0A155D3C-68E2-4215-A47A-E800A446447A} [JUJU猫] {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} [Messenger] {FB5F1910-F110-11d2-BB9E-00C04F795683} [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [GerneralPeerID Class] {0A47E819-F82E-4D5D-B806-6A9EA94D68CD} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [Shell Name Space] {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A> [XMP Class] {6483F145-A768-4C41-AACC-52D4D7845851} [XDRM] {693571CB-54A3-4E90-9D52-EEAE1334E2D3} [MediaComm Class] {7670648D-461B-42AF-BDFE-46D26AF5EFF2} [360SafeLive] {87515F61-A66C-4319-A0E0-D416CB8059E3} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [RMGetLicense Class] {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} [DapCtrl COM Module] {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [Thunder DapPlayer] {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} [使用iTudou下载节目] [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] [添加到QQ表情] ================================== 正在运行的进程 [PID: 652 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 704 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 728 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 772 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 784 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 940 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1000 / SYSTEM][E:\PC Tools Firewall Plus\PC Tools Firewall Plus\FWService.exe] [PC Tools, 3, 0, 1, 13] [E:\PC Tools Firewall Plus\PC Tools Firewall Plus\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [E:\PC Tools Firewall Plus\PC Tools Firewall Plus\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [E:\PC Tools Firewall Plus\PC Tools Firewall Plus\FirewallWrapper.dll] [PC Tools, 3, 0, 1, 14] [E:\PC Tools Firewall Plus\PC Tools Firewall Plus\Objects.dll] [PC Tools, 3, 0, 1, 14] [E:\PC Tools Firewall Plus\PC Tools Firewall Plus\Comms.dll] [PC Tools, 3, 0, 1, 13] [E:\PC Tools Firewall Plus\PC Tools Firewall Plus\PCTWSC.dll] [PC Tools, 1, 0, 0, 12] [E:\PC Tools Firewall Plus\PC Tools Firewall Plus\FwMemProtect.dll] [PC Tools Pty Ltd, 1.0.0.17] [PID: 1084 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 1220 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)] [PID: 1276 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 1552 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 1860 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll] [Windows (R) 2000 DDK provider, 5.00.2195.1620] [PID: 1980 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\Program Files\Media Player Classic\Codecs\mmfinfo.dll] [N/A, ] [C:\Program Files\Media Player Classic\Codecs\mkunicode.dll] [N/A, ] [D:\迅雷\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [D:\迅雷\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [D:\迅雷\Components\ResWorker\DsBho_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 19] [D:\迅雷\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [E:\360safe_2.3\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\Program Files\Eset\nodshex.dll] [N/A, ] [C:\WINDOWS\system32\msdmo.dll] [, ] [C:\Program Files\Media Player Classic\Codecs\vsfilter.dll] [Gabest, 1, 0, 0, 9] [C:\WINDOWS\system32\RealMediaSplitter.ax] [Gabest, 1, 0, 1, 1] [C:\Program Files\Media Player Classic\codecs\empgdmx.ax] [Elecard Ltd., 1, 0, 19, 51017] [C:\Program Files\Media Player Classic\Codecs\ffdshow.ax] [, 1.0.2.2605] [C:\Program Files\Media Player Classic\codecs\TTL2Dec.dll] [N/A, ] [C:\WINDOWS\system32\xvid.ax] [N/A, ] [C:\Program Files\Media Player Classic\Codecs\splitter.ax] [, 1.6.87.20] [C:\Program Files\Media Player Classic\Codecs\mkzlib.dll] [N/A, ] [C:\Program Files\Media Player Classic\Codecs\mkx.dll] [N/A, ] [PID: 260 / Administrator][E:\PC Tools Firewall Plus\PC Tools Firewall Plus\FirewallGUI.exe] [PC Tools, 3, 0, 1, 14] [E:\PC Tools Firewall Plus\PC Tools Firewall Plus\Objects.dll] [PC Tools, 3, 0, 1, 14] [E:\PC Tools Firewall Plus\PC Tools Firewall Plus\Comms.dll] [PC Tools, 3, 0, 1, 13] [E:\PC Tools Firewall Plus\PC Tools Firewall Plus\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [E:\PC Tools Firewall Plus\PC Tools Firewall Plus\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [E:\PC Tools Firewall Plus\PC Tools Firewall Plus\FirewallPlugin.dll] [PC Tools, 3, 0, 1, 13] [E:\360safe_2.3\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001] [PID: 268 / Administrator][C:\Program Files\Eset\nod32kui.exe] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\nod32rui.dll] [N/A, ] [C:\Program Files\Eset\pu_amon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_amon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pu_dmon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_dmon.dll] [N/A, ] [C:\Program Files\Eset\pu_emon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_emon.dll] [N/A, ] [C:\Program Files\Eset\pu_imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [C:\Program Files\Eset\pu_nod32.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_nod32.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pu_upd.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_upd.dll] [N/A, ] [PID: 284 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 424 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 548 / SYSTEM][E:\暴风影音\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 3, 15] [E:\暴风影音\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 1616 / SYSTEM][C:\Program Files\Eset\nod32krn.exe] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\nod32krr.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\ps_amon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_amon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\ps_dmon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_dmon.dll] [N/A, ] [C:\Program Files\Eset\ps_emon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_emon.dll] [N/A, ] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [C:\Program Files\Eset\ps_nod32.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_nod32.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\ps_upd.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_upd.dll] [N/A, ] [PID: 1912 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 3984 / Administrator][E:\360safe_2.3\360safe\safemon\360Tray.exe] [奇虎网, 4, 1, 8, 1002] [E:\360safe_2.3\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001] [E:\360safe_2.3\360safe\safemon\SafeKrnl.dll] [奇虎网, 4, 1, 8, 1001] [E:\360safe_2.3\360safe\AntiAdwa.dll] [360Safe.com, 4, 1, 5, 1001] [E:\360safe_2.3\360safe\live.dll] [360.cn, 1, 0, 1, 1027] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 3608 / Administrator][E:\360safe_2.3\360safe\antiarp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008] [E:\360safe_2.3\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001] [PID: 1264 / Administrator][F:\反病毒软件\293_System Repair Engineer V2.3\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900] [E:\360safe_2.3\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001] [F:\反病毒软件\293_System Repair Engineer V2.3\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 27 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 NOD32 protected [MSAFD Tcpip [TCP/IP]] C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) NOD32 protected [MSAFD Tcpip [UDP/IP]] C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) NOD32 protected [MSAFD Tcpip [RAW/IP]] C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) NOD32 protected [RSVP UDP Service Provider] C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) NOD32 protected [RSVP TCP Service Provider] C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) NOD32 C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 268, C:\PROGRAM FILES\ESET\NOD32KUI.EXE] ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]