[CODE] 2008-07-30,19:41:47 System Repair Engineer 2.6.12.1018 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <360Safetray> [(Verified)Qizhi Software (beijing) Co. Ltd] [(Verified)Microsoft Windows Hardware Compatibility Publisher] <"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [(Verified)"RealNetworks, Inc."] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] [File is missing] [File is missing] [File is missing] [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [(Verified)Microsoft Windows Hardware Compatibility Publisher] <; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [(Verified)"RealNetworks, Inc."] ================================== 启动文件夹 N/A ================================== 服务 [Adobe LM Service / Adobe LM Service][Stopped/Manual Start] <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"> [卡巴斯基反病毒软件 7.0 / AVP][Running/Manual Start] <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r> [Contrl Center of Storm Media / ccosm][Stopped/Auto Start] <北京暴风网际科技有限公司> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [NVIDIA Display Driver Service / NVSvc][Running/Auto Start] [PeanutHull DDNS Service / Peanuthull5Core][Running/Auto Start] <上海贝锐> [VMware Authorization Service / VMAuthdService][Running/Auto Start] [VMware DHCP Service / VMnetDHCP][Running/Auto Start] [VMware Virtual Mount Manager Extended / vmount2][Running/Auto Start] <"C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe"> [VMware NAT Service / VMware NAT Service][Running/Auto Start] ================================== 驱动程序 [AMD Processor Driver / AmdK8][Running/System Start] [AMD Low Level Device Driver / AmdLLD][Running/Manual Start] [d347bus / d347bus][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\d347bus.sys><> [d347prt / d347prt][Stopped/Boot Start] <\SystemRoot\System32\Drivers\d347prt.sys><> [EagleNT / EagleNT][Stopped/Manual Start] <\??\C:\WINDOWS\system32\drivers\EagleNT.sys> [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start] [VMware hcmon / hcmon][Running/Auto Start] <\??\C:\WINDOWS\system32\Drivers\hcmon.sys> [Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start] [Hdv32 / Hdv32][Stopped/Manual Start] <\??\C:\WINDOWS\system32\drivers\Hdv32_c.sys> [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start] [KAVBootC / KAVBootC][Running/Boot Start] <\SystemRoot\system32\Drivers\KAVBootC.sys> [kl1 / kl1][Running/Boot Start] <\SystemRoot\system32\drivers\kl1.sys> [klif / klif][Running/System Start] <\??\C:\WINDOWS\system32\drivers\klif.sys> [Kaspersky Anti-Virus NDIS Filter / klim5][Running/Manual Start] [ATK0110 ACPI UTILITY / MTsensor][Running/Manual Start] <> [WinPcap Packet Driver (NPF) / NPF][Stopped/Manual Start] [nv / nv][Running/Manual Start] [nvata / nvata][Running/Boot Start] <\SystemRoot\system32\DRIVERS\nvata.sys> [NVIDIA nForce Networking Controller Driver / NVENETFD][Running/Manual Start] [NVIDIA Network Bus Enumerator / nvnetbus][Running/Manual Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [SafeBoxKrnl / SafeBoxKrnl][Running/System Start] <\??\H:\360Safebox\SafeBoxKrnl.sys><360安全中心> [Secdrv / Secdrv][Stopped/Manual Start] [sptd / sptd][Running/Boot Start] <\SystemRoot\System32\Drivers\sptd.sys> [sysHostSvc / sysHostSvc][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\GuiHelp.sys> [TesSafe / TesSafe][Stopped/Manual Start] <\??\C:\WINDOWS\system32\TesSafe.sys> [TSKSP / TSKSP][Stopped/Manual Start] <\??\H:\QQ\QQDoctor\TSKSP.sys> [VMware Pointing Device / vmmouse][Running/Manual Start] [VMware Virtual Ethernet Adapter Driver / VMnetAdapter][Stopped/Manual Start] [VMware Bridge Protocol / VMnetBridge][Running/Auto Start] [VMware Network Application Interface / VMnetuserif][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\vmnetuserif.sys> [VMware VMparport / VMparport][Running/Auto Start] <\??\C:\WINDOWS\system32\Drivers\VMparport.sys> [VMware vmx86 / vmx86][Running/Auto Start] <\??\C:\WINDOWS\system32\Drivers\vmx86.sys> [Vstor2 Virtual Storage Driver / vstor2][Running/Auto Start] <\??\C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys> ================================== 浏览器加载项 [QQCycloneHelper Class] {00000000-12C9-4305-82F9-43058F20E8D2} [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [启动迅雷5] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} [浩方对战平台] {0A155D3C-68E2-4215-A47A-E800A446447A} [WUWebControl Class] {6414512B-B978-451D-A0D8-FCFDF33E833C} [ActiveScan Installer Class] {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} [RavOnline Class] {9FAFB576-6933-4CCC-AB3D-B988EC43D04E} [KVFileUpdate Class] {CA234A53-E68D-44D5-A07C-481C051D0C7B} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [KUpdateObj2 Class] {D82303B7-A754-4DCB-8AFC-8CF99435AACE} [Rising Web Scan Object] {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} [PasswordEditCtrl Class] {E787FD25-8D7C-4693-AE67-9406BC6E22DF} [QQCycloneHelper Class] {00000000-12C9-4305-82F9-43058F20E8D2} [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [XMP Class] {6483F145-A768-4C41-AACC-52D4D7845851} [XDRM] {693571CB-54A3-4E90-9D52-EEAE1334E2D3} [MediaComm Class] {7670648D-461B-42AF-BDFE-46D26AF5EFF2} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [DapCtrl Class] {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [Thunder DapPlayer] {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} [&使用超级旋风下载] [&使用超级旋风下载全部链接] [使用迅雷下载] [使用迅雷下载全部链接] [添加到QQ表情] ================================== 正在运行的进程 [PID: 628 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 700 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 724 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll] [Kaspersky Lab, 7.0.1.325] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 768 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 780 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\fssync.dll] [Kaspersky Lab, 7.0.5.325] [PID: 924 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1012 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\fssync.dll] [Kaspersky Lab, 7.0.5.325] [PID: 1112 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll] [Kaspersky Lab, 7.0.1.325] [PID: 1268 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\fssync.dll] [Kaspersky Lab, 7.0.5.325] [PID: 1708 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\fssync.dll] [Kaspersky Lab, 7.0.5.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\scrchpg.dll] [Kaspersky Lab, 7.0.1.325] [H:\360kaba\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [H:\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [H:\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [H:\Thunder\Components\ResWorker\DsBho_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20] [H:\Thunder\Components\ResWorker\DataProcessor_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\ShellEx.dll] [Kaspersky Lab, 7.0.1.325] [H:\winrar\rarext.dll] [N/A, ] [C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.3802.3802 built by: dnsrv(bld4act)] [C:\WINDOWS\system32\CmdLineExt.dll] [Sony DADC Austria AG., 1,1,221,0] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\klscav.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prremote.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prloader.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prkernel.ppl] [Kaspersky Lab, 7.0.1.325] [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\params.ppl] [Kaspersky Lab, 7.0.1.325] [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\pxstub.ppl] [Kaspersky Lab, 7.0.1.325] [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\tempfile.ppl] [Kaspersky Lab, 7.0.1.325] [C:\WINDOWS\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1820 / Administrator][H:\360kaba\safemon\360Tray.exe] [奇虎网, 4, 1, 8, 1004] [H:\360kaba\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [H:\360kaba\safemon\SafeKrnl.dll] [奇虎网, 4, 2, 0, 1001] [H:\360kaba\AntiAdwa.dll] [360Safe.com, 4, 2, 0, 1001] [H:\360kaba\live.dll] [360.cn, 1, 0, 1, 1027] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\fssync.dll] [Kaspersky Lab, 7.0.5.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\scrchpg.dll] [Kaspersky Lab, 7.0.1.325] [PID: 1852 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1928 / SYSTEM][C:\WINDOWS\system32\netdde.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1984 / SYSTEM][C:\WINDOWS\system32\netdde.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 172 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.11.6250] [C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.6250] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll] [Kaspersky Lab, 7.0.1.325] [PID: 168 / SYSTEM][H:\花生壳\PhCore.exe] [上海贝锐, 1, 0, 0, 23] [H:\花生壳\PhAlive.dll] [上海贝锐, 1, 0, 0, 28] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll] [Kaspersky Lab, 7.0.1.325] [PID: 264 / SYSTEM][H:\VM虚拟机\vmware-authd.exe] [VMware, Inc., 5.5.3 build-34685] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll] [Kaspersky Lab, 7.0.1.325] [PID: 656 / SYSTEM][C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe] [VMware, Inc., 5.5.3 build-34685] [C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmxScsiLib.dll] [VMware, Inc., 5.5.3 build-34685] [C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll] [Kaspersky Lab, 7.0.1.325] [PID: 1072 / SYSTEM][C:\WINDOWS\system32\vmnat.exe] [VMware, Inc., 5.5.3 build-34685] [PID: 1196 / SYSTEM][C:\WINDOWS\system32\vmnetdhcp.exe] [VMware, Inc., 5.5.3 build-34685] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [PID: 1424 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 440 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1376 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 6112 / Administrator][H:\QQ2008\QQ.exe] [TENCENT, 8,0,978,1833] [H:\QQ2008\QQBaseClassInDll.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\QQHelperDll.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\BasicCtrlDll.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0] [H:\360kaba\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [H:\QQ2008\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1] [H:\QQ2008\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218] [H:\QQ2008\QQAPI.dll] [TENCENT, 8,0,978,1833] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\fssync.dll] [Kaspersky Lab, 7.0.5.325] [H:\QQ2008\LoginCtrl.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\LoginCtrlRes.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\QQRes.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\QQMainFrame.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)] [H:\QQ2008\UnReadMsgMgr.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\QQAllInOne.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\SCCore.dll] [TENCENT, 1, 6, 0, 2] [H:\QQ2008\CameraDll.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\QQPlugin.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\CQQApplication.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\FlashAvatarDll.dll] [, 1, 0, 0, 1] [H:\QQ2008\NewSkin.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\MailSummary.dll] [TENCENT, 8,0,978,1833] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll] [Kaspersky Lab, 7.0.1.325] [H:\QQ2008\QQSpace.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\vbscript.dll] [Microsoft Corporation, 5.6.0.7426] [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\WINDOWS\system32\Macromed\Common\SwSupport.dll] [Adobe Systems, Inc., 10.2r22] [C:\WINDOWS\system32\msdmo.dll] [, ] [H:\QQ2008\OEMApplication.dll] [TENCENT, 8,0,978,1833] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\scrchpg.dll] [Kaspersky Lab, 7.0.1.325] [H:\QQ2008\QQAvatar.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\QQKnowledgeSearch.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\QQGroupMng.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\QQPet.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\UserDefinedHead.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\QRingMng.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\QQSysMsgMng.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\QQConfigPlugin.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\QQCustomFace.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\LongConnection.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\PhoneAPI.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\DialerAllinOne.dll] [tencent, 1, 4, 0, 0] [H:\QQ2008\ImageOle.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\QQLiveQMng.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\BQQApplication.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\PersonalDesktop.dll] [TENCENT, 8,0,978,1833] [C:\WINDOWS\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [H:\QQ2008\QQMagicFace.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\CommercesMng.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 330] [H:\QQ2008\QQSceneMng.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\GroupConnection.dll] [TENCENT, 8,0,978,1833] [H:\QQ2008\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 2, 1, 15] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\klscav.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prremote.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prloader.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prkernel.ppl] [Kaspersky Lab, 7.0.1.325] [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\params.ppl] [Kaspersky Lab, 7.0.1.325] [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\pxstub.ppl] [Kaspersky Lab, 7.0.1.325] [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\tempfile.ppl] [Kaspersky Lab, 7.0.1.325] [PID: 2176 / Administrator][H:\QQ2008\TXPlatform.exe] [Tencent, 1, 5, 225, 0] [H:\360kaba\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\fssync.dll] [Kaspersky Lab, 7.0.5.325] [PID: 8236 / Administrator][E:\KuGou2008\KuGoo.exe] [酷狗音乐, 5.2.0.524] [H:\360kaba\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [E:\KuGou2008\InExtend\kg_ksout.dll] [N/A, ] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [E:\KuGou2008\kgplaycomm.dll] [N/A, ] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\scrchpg.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\fssync.dll] [Kaspersky Lab, 7.0.5.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll] [Kaspersky Lab, 7.0.1.325] [E:\KuGou2008\cdread.dll] [N/A, ] [E:\KuGou2008\SkinRes.dll] [N/A, ] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\klscav.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prremote.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prloader.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prkernel.ppl] [Kaspersky Lab, 7.0.1.325] [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\params.ppl] [Kaspersky Lab, 7.0.1.325] [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\pxstub.ppl] [Kaspersky Lab, 7.0.1.325] [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\tempfile.ppl] [Kaspersky Lab, 7.0.1.325] [PID: 9316 / Administrator][H:\TheWorld 2.0\TheWorld.exe] [Phoenix Studio, 2, 2, 0, 0] [H:\360kaba\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\fssync.dll] [Kaspersky Lab, 7.0.5.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\scrchpg.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\klscav.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prremote.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prloader.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prkernel.ppl] [Kaspersky Lab, 7.0.1.325] [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\params.ppl] [Kaspersky Lab, 7.0.1.325] [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\pxstub.ppl] [Kaspersky Lab, 7.0.1.325] [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\tempfile.ppl] [Kaspersky Lab, 7.0.1.325] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0] [C:\WINDOWS\system32\Macromed\Common\SwSupport.dll] [Adobe Systems, Inc., 10.2r22] [PID: 5756 / Administrator][H:\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.6.12.1018] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\fssync.dll] [Kaspersky Lab, 7.0.5.325] [PID: 11728 / Administrator][H:\sreng2\SRE6c3c71fe.EXE] [Smallfrogs Studio, 2.6.12.1018] [H:\360kaba\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [H:\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\fssync.dll] [Kaspersky Lab, 7.0.5.325] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll] [Kaspersky Lab, 7.0.1.325] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\system32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 127.0.0.1 c0mo.com 127.0.0.1 gxgxy.net 127.0.0.1 444.gmwo07.com 127.0.0.1 333.gmwo07.com 127.0.0.1 222.gmwo07.com 127.0.0.1 111.gmwo07.com 127.0.0.1 haha.yaoyao09.com 127.0.0.1 www.noseqing.cn 127.0.0.1 fg.pvs360.com 127.0.0.1 cw.pvs360.com 127.0.0.1 ta.pvs360.com 127.0.0.1 dl.pvs360.com 127.0.0.1 ok.sl8cjs.cn 127.0.0.1 nc.mskess.com 127.0.0.1 idc.windowsupdeta.cn 127.0.0.1 pvs360.com 127.0.0.1 sl8cjs.cn 127.0.0.1 windowsupdeta.cn 127.0.0.1 up.22x44.com 127.0.0.1 my.531jx.cn 127.0.0.1 nx.51ylb.cn 127.0.0.1 llboss.com 127.0.0.1 down.malasc.cn 127.0.0.1 d2.llsging.com 127.0.0.1 171817.171817.com 127.0.0.1 wg.47255.com 127.0.0.1 www.tomwg.com 127.0.0.1 tp.shpzhan.cn 127.0.0.1 1.joppnqq.com 127.0.0.1 xx.exiao01.com 127.0.0.1 www.22aaa.com 127.0.0.1 ilove.com 127.0.0.1 xxx.mmma.biz 127.0.0.1 www.868wg.com 127.0.0.1 2.joppnqq.com 127.0.0.1 1.jopanqc.com 127.0.0.1 yu.8s7.net 127.0.0.1 1.jopmmqq.com 127.0.0.1 cao.kv8.info 127.0.0.1 xtx.kv8.info 127.0.0.1 new.749571.com 127.0.0.1 xxx.vh7.biz 127.0.0.1 1.jopenkk.com 127.0.0.1 d.93se.com 127.0.0.1 3.joppnqq.com 127.0.0.1 xxx.j41m.com 127.0.0.1 1.jopenqc.com 127.0.0.1 xxx.m111.biz 127.0.0.1 down.18dd.net 127.0.0.1 www.333292.com 127.0.0.1 qqq.hao1658.com 127.0.0.1 qqq.dzydhx.com 127.0.0.1 www.exiao01.com 127.0.0.1 www.cike007.cn ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 8236, E:\KUGOU2008\KUGOO.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 9316, H:\THEWORLD 2.0\THEWORLD.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2528, H:\THUNDER\PROGRAM\THUNDER5.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 5756, H:\SRENG2\SRENGLDR.EXE] ================================== API HOOK RVA 错误: LoadLibraryA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) RVA 错误: LoadLibraryExA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) RVA 错误: LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) RVA 错误: LoadLibraryW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) ================================== 隐藏进程 N/A ================================== [/CODE]