[CODE] 2008-11-03,18:13:38 System Repair Engineer 2.7.0.1210 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [(Verified)Google Inc] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)"INTER CHINA NETWORK SOFTWARE (BEIJING) CO., LTD"] [(Verified)"INTER CHINA NETWORK SOFTWARE (BEIJING) CO., LTD"] [(Verified)Tencent Technology(Shenzhen) Company Limited] [File is missing] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [NMGameX] [(Verified)Microsoft Windows Hardware Compatibility Publisher] <%systemroot%\system32\dumprep 0 -k> [File is missing] <"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"> [(Verified)Kaspersky Lab] [(Verified)ShenZhen Thunder Networking Technologies Ltd.] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] [File is missing] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AEB6717E-7E19-11d0-97EE-00C04FD91972}> [(Verified)Microsoft Windows Component Publisher] <{D7B21266-AA85-44b8-B516-3B1A69827400}> [(Verified)"INTER CHINA NETWORK SOFTWARE (BEIJING) CO., LTD"] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon] [(Verified)Kaspersky Lab] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}] [(Verified)Microsoft Windows] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] [(Verified)Microsoft Windows] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] [(Verified)Microsoft Windows] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <浏览器自定义组件> [(Verified)Microsoft Windows] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] [(Verified)Microsoft Windows] ================================== 启动文件夹 N/A ================================== 服务 [卡巴斯基互联网安全套装 7.0 / AVP][Running/Auto Start] <"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" -r> [Contrl Center of Storm Media / ccosm][Running/Auto Start] <北京暴风网际科技有限公司> [Google Updater Service / gusvc][Stopped/Manual Start] <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [MSSQLSERVER / MSSQLSERVER][Running/Auto Start] [MSSQLServerADHelper / MSSQLServerADHelper][Stopped/Manual Start] [OracleMTSRecoveryService / OracleMTSRecoveryService][Running/Auto Start] [OracleOraHome92Agent / OracleOraHome92Agent][Running/Auto Start] [OracleOraHome92ClientCache / OracleOraHome92ClientCache][Stopped/Manual Start] [OracleOraHome92HTTPServer / OracleOraHome92HTTPServer][Stopped/Auto Start] <"D:\oracle\ora92\Apache\Apache\apache.exe" --ntservice> [OracleOraHome92PagingServer / OracleOraHome92PagingServer][Stopped/Manual Start] [OracleOraHome92SNMPPeerEncapsulator / OracleOraHome92SNMPPeerEncapsulator][Stopped/Manual Start] [OracleOraHome92SNMPPeerMasterAgent / OracleOraHome92SNMPPeerMasterAgent][Stopped/Manual Start] [OracleOraHome92TNSListener / OracleOraHome92TNSListener][Running/Disabled] [OracleServiceTS0045 / OracleServiceTS0045][Running/Auto Start] [P4P Service / P4P Service][Running/Auto Start] [SQLSERVERAGENT / SQLSERVERAGENT][Stopped/Disabled] [MSSQL$TYHBDB / TYHBDB][Stopped/Auto Start] <><(File is missing)> [Windows 用户模式驱动框架 / UMWdf][Stopped/Manual Start] ================================== 驱动程序 [2310_00 / 2310_00][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\2310_00.sys> [3WAREDRV / 3WAREDRV][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\3WAREDRV.SYS> [3WAREGSM / 3WAREGSM][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\3waregsm.sys> [3WDRV100 / 3WDRV100][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\3WDRV100.SYS> [A320RAID / A320RAID][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\a320raid.sys> [AAC / AAC][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AAC.SYS> [AACSAS / AACSAS][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aacsas.sys> [AARSI3X / AARSI3X][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aarsi3x.sys> [ADProt / ADProt][Running/System Start] <\SystemRoot\system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司> [adpu160m / adpu160m][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\adpu160m.sys> [ADPU320 / ADPU320][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\adpu320.sys> [ACARD AEC6210UF UltraDMA33 Controller / AEC6210][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aec6210.sys> [ACARD AEC6260 UltraDMA-66 Controller / AEC6260][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aec6260.sys> [AEC6280 / AEC6280][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aec6280.sys> [AEC67160 / AEC67160][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AEC67160.SYS> [AEC67162 / AEC67162][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aec67162.sys> [AEC671X / AEC671X][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AEC671X.SYS> [AEC6880 / AEC6880][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AEC6880.SYS> [AEC6890 / AEC6890][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AEC6890.sys> [AEC6897 / AEC6897][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aec6897.sys> [AEC68X5 / AEC68X5][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aec68x5.sys> [Agere Systems Soft Modem / AgereSoftModem][Running/Manual Start] [aic78u2 / aic78u2][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aic78u2.sys> [aic78xx / aic78xx][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aic78xx.sys> [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start] [AliIde / AliIde][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aliide.sys> [AMD K8 Processor Driver / AmdK8][Stopped/Manual Start] [apefjwyb / apefjwyb][Running/Boot Start] <\SystemRoot\System32\DRIVERS\apefjwyb.sys> [arc / arc][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ARC.SYS> [ARCM_X86 / ARCM_X86][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\arcm_x86.sys> [asc / asc][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\asc.sys> [asc3550 / asc3550][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\asc3550.sys> [BCHTSW32 / BCHTSW32][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\bchtsw32.sys> [BCRAID / BCRAID][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\BCRAID.sys> [CmdIde / CmdIde][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\cmdide.sys> [CNRNDV / CNRNDV][Running/Boot Start] <\SystemRoot\system32\drivers\CNRNDV.sys><国风因特软件(北京)有限公司> [Cpqarray / Cpqarray][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\cpqarray.sys> [CPQARRY2 / CPQARRY2][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\cpqarry2.sys> [CPQCISSM / CPQCISSM][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\cpqcissm.sys> [CSB6IDE / CSB6IDE][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\csb6ide.sys> [dac2w2k / dac2w2k][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\dac2w2k.sys> [dac960nt / dac960nt][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\dac960nt.sys> [DgiVecp / DgiVecp][Running/Auto Start] <\??\C:\WINDOWS\system32\Drivers\DgiVecp.sys> [dpti2o / dpti2o][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\dpti2o.sys> [elxstor / elxstor][Stopped/Boot Start] <\SystemRoot\system32\drivers\elxstor.sys> [FASTSX / FASTSX][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\FASTSX.SYS> [FASTTRAK / FASTTRAK][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\fasttrak.sys> [FASTTX2K / FASTTX2K][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\fasttx2k.sys> [FT8300 / FT8300][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ft8300.sys> [FTSATA2 / FTSATA2][Running/Boot Start] <\SystemRoot\System32\DRIVERS\ftsata2.sys> [GD31244 / GD31244][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\gd31244.sys> [HpCISSs / HpCISSs][Stopped/Boot Start] <\SystemRoot\system32\drivers\hpcisss.sys> [HPCISSS2 / HPCISSS2][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\hpcisss2.sys> [HPT371 / HPT371][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\HPT371.sys> [HPT374 / HPT374][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\hpt374.sys> [HPT3XX / HPT3XX][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\hpt3xx.sys> [i2omp / i2omp][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\i2omp.sys> [Intel Integrated RAID / IASTOR][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\iaStor.sys> [INIA100 / INIA100][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\INIA100.sys> [IPSRAIDN / IPSRAIDN][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ipsraidn.sys> [ITERAID / ITERAID][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\iteraid.sys> [JRAID / JRAID][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\JRAID.SYS> [kl1 / kl1][Running/Boot Start] <\SystemRoot\system32\drivers\kl1.sys> [klif / klif][Running/System Start] <\??\C:\WINDOWS\system32\drivers\klif.sys> [Kaspersky Anti-Virus NDIS Filter / klim5][Running/Manual Start] [LSI_FC / LSI_FC][Stopped/Boot Start] <\SystemRoot\system32\drivers\lsi_fc.sys> [LSI_SCSI / LSI_SCSI][Stopped/Boot Start] <\SystemRoot\system32\drivers\lsi_scsi.sys> [M5228 / M5228][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\m5228.sys> [M5281 / M5281][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\m5281.sys> [M5287 / M5287][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\m5287.sys> [M5288 / M5288][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\m5288.sys> [M5289 / M5289][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\m5289.sys> [MEGAIDE / MEGAIDE][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\MegaIDE.sys> [megasas / megasas][Stopped/Boot Start] <\SystemRoot\system32\drivers\megasas.sys> [mraid2k / mraid2k][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\mraid2k.sys> [mraid35x / mraid35x][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\mraid35x.sys> [NFRD960 / NFRD960][Stopped/Boot Start] <\SystemRoot\system32\drivers\nfrd960.sys> [npkcrypt / npkcrypt][Stopped/Manual Start] <\??\C:\WINDOWS\system32\npkcrypt.sys> [npkycryp / npkycryp][Stopped/Manual Start] <\??\C:\WINDOWS\system32\npkycryp.sys> [NVATABUS / NVATABUS][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\NVATABUS.SYS> [NVIDIA nForce(tm) RAID Class Driver / NVRAID][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\nvraid.sys> [perc2 / perc2][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\perc2.sys> [PNP649R / PNP649R][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\PNP649R.SYS> [SiI 680 ATA Controller / PNP680][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\pnp680.sys> [Silicon Image SiI 0680 Medley Raid Controller / PNP680R][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\pnp680r.sys> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [ql1080 / ql1080][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ql1080.sys> [Ql10wnt / Ql10wnt][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ql10wnt.sys> [ql12160 / ql12160][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ql12160.sys> [ql1240 / ql1240][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ql1240.sys> [ql1280 / ql1280][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ql1280.sys> [QLogic Fibre Channel SCSI Miniport Driver / ql2300][Stopped/Boot Start] <\SystemRoot\system32\drivers\ql2300.sys> [RAIDSRC / RAIDSRC][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\RAIDSRC.SYS> [RR232X / RR232X][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\rr232x.sys> [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start] [S150SX8 / S150SX8][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\S150SX8.SYS> [Secdrv / Secdrv][Stopped/Manual Start] [SiI-3512 SATALink Controller / SI3112][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3112.sys> [Silicon Image SiI 3512 SATARaid Controller / SI3112R][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3112r.sys> [SiI-3114 SATALink Controller / SI3114][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3114.sys> [SiI-3114 SATARaid Controller / SI3114R][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3114R.sys> [SI3114R5 / SI3114R5][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\Si3114r5.sys> [SiI-3124 SATALink Controller / SI3124][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3124.sys> [SiI-3124 SATARaid Controller / SI3124R][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3124R.sys> [SI3124R5 / SI3124R5][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\Si3124r5.sys> [SI3132 / SI3132][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3132.sys> [SI3132R5 / SI3132R5][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\Si3132r5.sys> [SATALink driver accelerator / SiFilter][Running/Boot Start] <\SystemRoot\System32\DRIVERS\SiWinAcc.sys> [SISIDE / SISIDE][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SISIDE.SYS> [SISRAID / SISRAID][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SiSRaid.sys> [SISRAID2 / SISRAID2][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SiSRaid2.sys> [SISRAID4 / SISRAID4][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SiSRaid4.sys> [Sparrow / Sparrow][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\sparrow.sys> [SPTRAK / SPTRAK][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\sptrak.sys> [SSPORT / SSPORT][Stopped/Auto Start] <\??\C:\WINDOWS\system32\Drivers\SSPORT.sys> [ST8350 / ST8350][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\st8350.sys> [symc810 / symc810][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\symc810.sys> [symc8xx / symc8xx][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\symc8xx.sys> [SYMMPI / SYMMPI][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SYMMPI.SYS> [sym_hi / sym_hi][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\sym_hi.sys> [sym_u3 / sym_u3][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\sym_u3.sys> [TCP/IP Protocol Driver / Tcpip][Running/System Start] [TesSafe / TesSafe][Stopped/Manual Start] <\??\C:\WINDOWS\system32\TesSafe.sys> [TRM3X5 / TRM3X5][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\trm3x5.sys> [TwoTrack Compatible Device / TwoTrack][Stopped/Manual Start] [ULSATA / ULSATA][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ulsata.sys> [ULSATA2 / ULSATA2][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ulsata2.sys> [ULTIMA / ULTIMA][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\Ultima.sys> [ULTIMARX / ULTIMARX][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\UltimaRX.sys> [ultra / ultra][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ultra.sys> [viagfx / viagfx][Running/Manual Start] [VIAMRAID / VIAMRAID][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\viamraid.sys> [VIA ATA/ATAPI Host Controller / viapdsk][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\viapdsk.sys> [viaraid / viaraid][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\viaraid.sys> [viasraid / viasraid][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\viasraid.sys> [vmscsi / vmscsi][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\vmscsi.sys> [WD7296A / WD7296A][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\wd7296a.sys> [yaskp / yaskp][Running/Manual Start] <2 - 系统找不到指定的文件。 > [R2A / R2A][Stopped/Disabled] <\??\C:\WINDOWS\system32a2.sys> ================================== 浏览器加载项 [Tencent Browser Helper] {0C7C23EF-A848-485B-873C-0ED954731014} [Yahoo!Photo] {33BBE430-0E42-4f12-B075-8D21ACB10DCB} [AntiFish Class] {38928D50-8A48-44C2-945F-D2F23F771410} [VnetCookie Class] {4E83D567-4697-4F7B-B1F0-A513B01DB89A} [DragSearch BHO] {62EED7C6-9F02-42f9-B634-98E2899E147B} [] {669751ED-D558-49AE-B01A-3B374CC7910E} [Google Toolbar Helper] {AA58ED58-01DD-4d91-8333-CF10577473F7} [Google Toolbar Notifier BHO] {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [] {D7B21266-AA85-44b8-B516-3B1A69827400} [yFlashDl Class] {F166BC04-3C84-44cc-A6E9-2315EC4844B9} [assist] {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} [] {110F6354-E9E3-4f8c-95DD-8487ED86C73D} [Web 反病毒统计] {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} [名品 折扣] {30778C27-54C7-437e-946A-F04CBB8C460F} [Yahoo 3.5G 电邮] {4C4A96EA-D26D-4ab1-9D7C-BEA7D3312B6F} [] {4D985980-695A-4b42-8B11-34D8D3385676} [雅虎助手] {5D73EE86-05F1-49ed-B850-E423120EC338} [雅虎 WIDGET] {6C32C266-E0C3-447c-B1A1-650640D550D0} [情景 聊天] {7035F492-7EAE-4213-A159-7C4E1E216C12} [我的订阅] {8755CE6E-0BF7-4441-8751-FB728941B0B4} [信息检索(&R)] {92780B25-18CC-41C8-B9BE-3C9C571A8263} [启动WEB迅雷] {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} [搜狗工具条] {DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} [雅虎助手] {406F94F0-504F-4A40-8DFD-58B0666ABEBD} [&Google] {2318C2B1-4965-11d4-9B18-009027A5CD4F} [iReportPlugin Control] {99C9F0B9-4397-49ED-AF4A-F98924ADECE6} [ScreenCapture Class] {BFB79EE1-04AE-4D4A-B85E-27EE5F30C095} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [] {00000000-12C9-4305-82F9-43058F20E8D2} <, > [Google Script Object] {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} [WebThunder Class] {03507A1A-E0C5-4404-AA26-205385C0892D} <, > [] {0C7C23EE-A848-485B-873C-0ED954731014} <, > [Tencent Browser Helper] {0C7C23EF-A848-485B-873C-0ED954731014} [] {110F6354-E9E3-4F8C-95DD-8487ED86C73D} <, > [] {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <, > [Windows Media Player] {22D6F312-B0F6-11D0-94AB-0080C74C7E95} [&Google] {2318C2B1-4965-11D4-9B18-009027A5CD4F} [XML DOM Document] {2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\system32\msxml3.dll, (Signed) N/A> [] {29CF293A-1E7D-4069-9E11-E39698D0AF95} <, > [WebThunder DapPlayer] {2EEDA47E-8D5C-4d7e-B4B6-E16E19218555} [] {30778C27-54C7-437E-946A-F04CBB8C460F} <, > [Yahoo!Photo] {33BBE430-0E42-4F12-B075-8D21ACB10DCB} [AntiFish Class] {38928D50-8A48-44C2-945F-D2F23F771410} [雅虎助手] {406F94F0-504F-4A40-8DFD-58B0666ABEBD} [XML Document] {48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, (Signed) N/A> [] {4C4A96EA-D26D-4AB1-9D7C-BEA7D3312B6F} <, > [] {4D985980-695A-4B42-8B11-34D8D3385676} <, > [VnetCookie Class] {4E83D567-4697-4F7B-B1F0-A513B01DB89A} [Shell Name Space] {55136805-B2DE-11D1-B9F2-00A0C98BC547} [] {5D73EE86-05F1-49ED-B850-E423120EC338} <, > [DragSearch BHO] {62EED7C6-9F02-42F9-B634-98E2899E147B} [XMP Class] {6483F145-A768-4C41-AACC-52D4D7845851} [] {669751ED-D558-49AE-B01A-3B374CC7910E} [XDRM] {693571CB-54A3-4E90-9D52-EEAE1334E2D3} [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [] {6C32C266-E0C3-447C-B1A1-650640D550D0} <, > [] {7035F492-7EAE-4213-A159-7C4E1E216C12} <, > [我的订阅] {8755CE6E-0BF7-4441-8751-FB728941B0B4} [XML DOM 文档 5.0] {88D969E5-F192-11D4-A65F-0040963251E5} [] {92780B25-18CC-41C8-B9BE-3C9C571A8263} <, > [] {962EFB8E-2683-42D4-AC74-AAA4C759B9C6} <, > [iReportPlugin Control] {99C9F0B9-4397-49ED-AF4A-F98924ADECE6} [UploadFilePartition Class] {A877BA28-1F7E-4876-B299-50B3199A1A5D} [Google Toolbar Helper] {AA58ED58-01DD-4D91-8333-CF10577473F7} [DapCtrl Class] {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} [Google Toolbar Notifier BHO] {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [ScreenCapture Class] {BFB79EE1-04AE-4D4A-B85E-27EE5F30C095} [QQPlayerCtrl Class] {CD108273-D434-43E6-AA90-1469F97EB398} [AUDIO__MID Moniker Class] {CD3AFA74-B84F-48F0-9393-7EDC34128127} [AUDIO__MP3 Moniker Class] {CD3AFA76-B84F-48F0-9393-7EDC34128127} [AUDIO__X_MS_WMA Moniker Class] {CD3AFA84-B84F-48F0-9393-7EDC34128127} [VIDEO__X_MS_WMV Moniker Class] {CD3AFA94-B84F-48F0-9393-7EDC34128127} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [] {D7B21266-AA85-44B8-B516-3B1A69827400} [搜狗工具条] {DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} [PlayerCtrl Class] {E05BC2A3-9A46-4A32-80C9-023A473F5B23} [PasswordEditCtrl Class] {E787FD25-8D7C-4693-AE67-9406BC6E22DF} [TimwpDll.TimwpCheck] {ED4CA2E5-0EEA-44C1-AD7E-74A07A7507A4} [XML HTTP Request] {ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\system32\msxml3.dll, (Signed) N/A> [yFlashDl Class] {F166BC04-3C84-44CC-A6E9-2315EC4844B9} [QvodCtrl Class] {F3D0D36F-23F8-4682-A195-74C92B03D4AF} [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} [XML DOM Document 3.0] {F5078F32-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\system32\msxml3.dll, (Signed) N/A> [XML HTTP] {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\system32\msxml3.dll, (Signed) N/A> [assist] {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} [使用WEB迅雷下载] [使用WEB迅雷下载全部链接] [使用搜狗直通车下载] [发送图片到手机] [导出到 Microsoft Office Excel(&X)] [添加到QQ表情] [添加到“我的订阅”] [添加到反广告条] [添加到雅虎订阅(&Y)] [雅虎搜索] ================================== 正在运行的进程 [PID: 760 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 816 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 840 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 7.0.0.125] [PID: 888 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 900 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll] [Kaspersky Lab, 7.0.0.125] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [PID: 1060 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1128 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll] [Kaspersky Lab, 7.0.0.125] [PID: 1216 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll] [Kaspersky Lab, 7.0.0.125] [D:\oracle\ora92\bin\oci.dll] [Oracle Corporation, 9.2.0.1.0] [PID: 1296 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [PID: 1416 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [PID: 1644 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\scrchpg.dll] [Kaspersky Lab, 7.0.0.125] [C:\PROGRA~1\CNRN\RNHelper.dll] [国风因特软件(北京)有限公司, 2.0.3.1020] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 14] [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [N/A, ] [C:\PROGRA~1\CNRN\CNRN.dll] [国风因特软件(北京)有限公司, 2.1.0.1048] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll] [Kaspersky Lab, 7.0.0.125] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ShellEx.dll] [Kaspersky Lab, 7.0.0.125] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.42] [C:\PROGRA~1\Yahoo!\ASSIST~1\yalive.dll] [N/A, ] [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] [N/A, ] [C:\PROGRA~1\CNRN\RNLive.dll] [国风因特软件(北京)有限公司, 2.0.3.1021] [C:\PROGRA~1\CNRN\RNAxtF.dll] [国风因特软件(北京)有限公司, 2.0.1.1016] [C:\WINDOWS\downlo~1\Qjemo.dll] [Tencent, 5, 0, 7, 20] [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll] [N/A, ] [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] [N/A, ] [C:\PROGRA~1\CNRN\RNEvent.dll] [国风因特软件(北京)有限公司, 2.0.3.1018] [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll] [N/A, ] [PID: 1780 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll] [Kaspersky Lab, 7.0.0.125] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1984 / Administrator][C:\PROGRA~1\CNRN\RNMain.exe] [国风因特软件(北京)有限公司, 2.0.3.1018] [C:\PROGRA~1\CNRN\RNHelper.dll] [国风因特软件(北京)有限公司, 2.0.3.1020] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\PROGRA~1\CNRN\RNLive.dll] [国风因特软件(北京)有限公司, 2.0.3.1021] [C:\PROGRA~1\CNRN\RNAxtF.dll] [国风因特软件(北京)有限公司, 2.0.1.1016] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll] [Kaspersky Lab, 7.0.0.125] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 14] [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [N/A, ] [C:\PROGRA~1\CNRN\RNNtfy.dll] [国风因特软件(北京)有限公司, 2.0.1.1016] [C:\PROGRA~1\CNRN\CNRN.dll] [国风因特软件(北京)有限公司, 2.1.0.1048] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll] [Kaspersky Lab, 7.0.0.125] [PID: 1992 / Administrator][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5, 1, 0, 51] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\PROGRA~1\CNRN\RNHelper.dll] [国风因特软件(北京)有限公司, 2.0.3.1020] [C:\PROGRA~1\CNRN\CNRN.dll] [国风因特软件(北京)有限公司, 2.1.0.1048] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 14] [PID: 2000 / Administrator][C:\PROGRA~1\CNRN\RNMain.exe] [国风因特软件(北京)有限公司, 2.0.3.1018] [C:\PROGRA~1\CNRN\CNRN.dll] [国风因特软件(北京)有限公司, 2.1.0.1048] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll] [Kaspersky Lab, 7.0.0.125] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 14] [C:\PROGRA~1\CNRN\RNList.dll] [国风因特软件(北京)有限公司, 2.0.8.1028] [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [N/A, ] [C:\PROGRA~1\CNRN\RNHelper.dll] [国风因特软件(北京)有限公司, 2.0.3.1020] [PID: 180 / Administrator][C:\WINDOWS\system32\Rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SoDAHK.DLL] [Sogou.com Inc., 1, 0, 1, 5] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 14] [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [N/A, ] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [C:\PROGRA~1\CNRN\RNHelper.dll] [国风因特软件(北京)有限公司, 2.0.3.1020] [C:\PROGRA~1\CNRN\CNRN.dll] [国风因特软件(北京)有限公司, 2.1.0.1048] [PID: 264 / Administrator][C:\WINDOWS\system32\VTtrayp.exe] [S3 Graphics Co., Ltd., 2.00.41-1031] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [N/A, ] [C:\PROGRA~1\CNRN\RNHelper.dll] [国风因特软件(北京)有限公司, 2.0.3.1020] [C:\WINDOWS\system32\VTDisply.dll] [S3 Graphics Co., Ltd., 2.00.58-0523] [C:\WINDOWS\system32\VTGamma2.dll] [S3 Graphics Co., Ltd., 2.00.28-1128] [C:\WINDOWS\system32\VTInfo2.dll] [S3 Graphics Co., Ltd., 2.00.35-1031] [C:\WINDOWS\system32\VTOvrlay.dll] [S3 Graphics Co., Ltd., 2.00.38-1117B] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 14] [C:\PROGRA~1\CNRN\CNRN.dll] [国风因特软件(北京)有限公司, 2.1.0.1048] [PID: 276 / Administrator][C:\WINDOWS\system32\VTTimer.exe] [S3 Graphics, Inc., 2.00.01-0307] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [N/A, ] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [C:\PROGRA~1\CNRN\RNHelper.dll] [国风因特软件(北京)有限公司, 2.0.3.1020] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 14] [C:\PROGRA~1\CNRN\CNRN.dll] [国风因特软件(北京)有限公司, 2.1.0.1048] [PID: 336 / Administrator][C:\WINDOWS\AGRSMMSG.exe] [Agere Systems, 2.1.33 2.1.33 08/20/2003 13:18:33] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 14] [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [N/A, ] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [C:\PROGRA~1\CNRN\RNHelper.dll] [国风因特软件(北京)有限公司, 2.0.3.1020] [C:\PROGRA~1\CNRN\CNRN.dll] [国风因特软件(北京)有限公司, 2.1.0.1048] [PID: 452 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 14] [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [N/A, ] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [C:\PROGRA~1\CNRN\RNHelper.dll] [国风因特软件(北京)有限公司, 2.0.3.1020] [C:\PROGRA~1\CNRN\CNRN.dll] [国风因特软件(北京)有限公司, 2.1.0.1048] [PID: 500 / SYSTEM][C:\Program Files\StormII\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 6, 20] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll] [Kaspersky Lab, 7.0.0.125] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [PID: 552 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654] [C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\gtn.dll] [Google Inc., 3, 1, 807, 1746] [C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll] [Kaspersky Lab, 7.0.0.125] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 14] [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [N/A, ] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [C:\PROGRA~1\CNRN\RNHelper.dll] [国风因特软件(北京)有限公司, 2.0.3.1020] [C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll] [Google Inc., 3, 1, 807, 1746] [C:\PROGRA~1\CNRN\CNRN.dll] [国风因特软件(北京)有限公司, 2.1.0.1048] [PID: 732 / SYSTEM][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE] [Microsoft Corporation, 7.00.9466] [C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\2052\mdmui.dll] [Microsoft Corporation, 7.00.9466] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [PID: 804 / SYSTEM][e:\MICROS~1\MSSQL\binn\sqlservr.exe] [Microsoft Corporation, 2000.080.0194.00] [e:\MICROS~1\MSSQL\binn\OPENDS60.DLL] [Microsoft Corporation, 2000.080.0194.00] [e:\MICROS~1\MSSQL\binn\UMS.DLL] [Microsoft Corporation, 2000.080.0194.00] [e:\MICROS~1\MSSQL\binn\SQLSORT.DLL] [Microsoft Corporation, 2000.080.0194.00] [e:\MICROS~1\MSSQL\binn\Resources\2052\sqlevn70.RLL] [Microsoft Corporation, 2000.080.0194.00] [e:\MICROS~1\MSSQL\binn\SSNETLIB.dll] [Microsoft Corporation, 2000.080.0194.00] [e:\MICROS~1\MSSQL\binn\SSNMPN70.dll] [Microsoft Corporation, 2000.080.0194.00] [e:\MICROS~1\MSSQL\binn\SSmsLPCn.dll] [Microsoft Corporation, 2000.080.0194.00] [PID: 1724 / SYSTEM][D:\oracle\ora92\bin\omtsreco.exe] [Oracle Corporation, 9.2.0.1.0] [D:\oracle\ora92\bin\OCI.dll] [Oracle Corporation, 9.2.0.1.0] [D:\oracle\ora92\bin\OraClient9.Dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\oracore9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oraunls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oravsn9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\oracommon9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\orageneric9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\oraxml9.dll] [Oracle Corporation, ] [D:\oracle\ora92\bin\oraxsd9.dll] [Oracle Corporation, ] [D:\oracle\ora92\bin\orannzsbb9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oran9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranl9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranldap9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oraldapclnt9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orancrypt9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\ORATRACE9.dll] [N/A, ] [D:\oracle\ora92\bin\oranro9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranhost9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranoname9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orancds9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orantns9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranms.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oranmsp.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\orapls9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\oraslax9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orasnls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orawtc9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\orasql9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\omtsrecomsgZHS.dll] [Oracle Corporation, 9.0.0.0.0] [D:\oracle\ora92\bin\omtsrecomsgus.dll] [Oracle Corporation, 9.2.0.0.1] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [PID: 1432 / SYSTEM][D:\oracle\ora92\bin\agntsrvc.exe] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oranmi.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oraclient9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\oracore9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oraunls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oravsn9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\oracommon9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\orageneric9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\oraxml9.dll] [Oracle Corporation, ] [D:\oracle\ora92\bin\oraxsd9.dll] [Oracle Corporation, ] [D:\oracle\ora92\bin\orannzsbb9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oran9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranl9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranldap9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oraldapclnt9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orancrypt9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\ORATRACE9.dll] [N/A, ] [D:\oracle\ora92\bin\oranro9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranhost9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranoname9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orancds9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orantns9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranms.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oranmsp.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\orapls9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\oraslax9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orasnls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orawtc9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\orasql9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oravppdc.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oranmd.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oranmt.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oranml.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\tcl82.dll] [Scriptics Corporation, 8.2.3] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll] [Kaspersky Lab, 7.0.0.125] [D:\oracle\ora92\bin\orantcp9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [PID: 2072 / SYSTEM][C:\WINDOWS\system32\cmd.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2264 / SYSTEM][D:\oracle\ora92\BIN\TNSLSNR.exe] [N/A, ] [D:\oracle\ora92\BIN\oransgr9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\oran9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\oranl9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\oranldap9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\orannzsbb9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\oracore9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\oranls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\oraunls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\orageneric9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\BIN\oracommon9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\BIN\oraclient9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\BIN\oravsn9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\BIN\orawtc9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\BIN\orancrypt9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\oranro9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\orapls9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\BIN\oraslax9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\orasnls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\orasql9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\oraxml9.dll] [Oracle Corporation, ] [D:\oracle\ora92\BIN\oraxsd9.dll] [Oracle Corporation, ] [D:\oracle\ora92\BIN\oraldapclnt9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\ORATRACE9.dll] [N/A, ] [D:\oracle\ora92\BIN\oranhost9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\oranoname9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\orancds9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\orantns9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\BIN\oranms.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\BIN\oranmsp.dll] [Oracle Corporation, 9.2.0.0.0] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [D:\oracle\ora92\bin\orantcp9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll] [Kaspersky Lab, 7.0.0.125] [D:\oracle\ora92\bin\oranipc9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [PID: 2316 / SYSTEM][d:\oracle\ora92\bin\ORACLE.EXE] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\oraclient9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\oracore9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oraunls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oravsn9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\oracommon9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\orageneric9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\oraxml9.dll] [Oracle Corporation, ] [d:\oracle\ora92\bin\oraxsd9.dll] [Oracle Corporation, ] [d:\oracle\ora92\bin\orannzsbb9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oran9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranl9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranldap9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oraldapclnt9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orancrypt9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\ORATRACE9.dll] [N/A, ] [d:\oracle\ora92\bin\oranro9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranhost9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranoname9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orancds9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orantns9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranms.dll] [Oracle Corporation, 9.2.0.0.0] [d:\oracle\ora92\bin\oranmsp.dll] [Oracle Corporation, 9.2.0.0.0] [d:\oracle\ora92\bin\orapls9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\oraslax9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orasnls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orawtc9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\orasql9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oraodm9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\oraplp9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\orajox9.dll] [N/A, ] [d:\oracle\ora92\bin\oransgr9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orawwg9.dll] [Oracle Corporation, 8.1.7.0.0] [d:\oracle\ora92\bin\ocijdbc9.dll] [N/A, ] [D:\oracle\ora92\BIN\ORAIMR9.Dll] [Oracle Corporation, 9.2.0.1.0] [D:\oracle\ora92\bin\oranbeq9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orannts9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orantcp9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll] [Kaspersky Lab, 7.0.0.125] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2444 / SYSTEM][D:\oracle\ora92\bin\dbsnmp.exe] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oranmi.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oraclient9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\oracore9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oraunls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oravsn9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\oracommon9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\orageneric9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\oraxml9.dll] [Oracle Corporation, ] [D:\oracle\ora92\bin\oraxsd9.dll] [Oracle Corporation, ] [D:\oracle\ora92\bin\orannzsbb9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oran9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranl9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranldap9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oraldapclnt9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orancrypt9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\ORATRACE9.dll] [N/A, ] [D:\oracle\ora92\bin\oranro9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranhost9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranoname9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orancds9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orantns9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oranms.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oranmsp.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\orapls9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\oraslax9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orasnls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\orawtc9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [D:\oracle\ora92\bin\orasql9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oravppdc.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oranmd.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oranmt.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oranml.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\tcl82.dll] [Scriptics Corporation, 8.2.3] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll] [Kaspersky Lab, 7.0.0.125] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [D:\oracle\ora92\bin\orantcp9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [D:\oracle\ora92\bin\oravpnt.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oravpxdba.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oravpxeap.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oravpsqlsrv.dll] [Oracle Corporation, 9.2.0.0.0] [D:\oracle\ora92\bin\oravpxoafnd.dll] [Oracle Corporation, 9.2.0.0.0] [PID: 2448 / SYSTEM][C:\Program Files\Common Files\Sogou PXP\p2psvr.exe] [Sohu.com Inc., 2, 0, 0, 28] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\P4P\tbupdate.dll] [Sogou.com Inc., 1, 0, 1, 2] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll] [Kaspersky Lab, 7.0.0.125] [C:\Program Files\P4P\p4pipc.dll] [Sogou.com Inc., 1, 0, 0, 13] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll] [Kaspersky Lab, 7.0.0.125] [PID: 556 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\PROGRA~1\CNRN\CNRN.dll] [国风因特软件(北京)有限公司, 2.1.0.1048] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 14] [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [N/A, ] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [C:\PROGRA~1\CNRN\RNHelper.dll] [国风因特软件(北京)有限公司, 2.0.3.1020] [PID: 616 / Administrator][E:\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [PID: 2208 / Administrator][E:\SRE8617b097.EXE] [Smallfrogs Studio, 2.7.0.1210] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\PROGRA~1\CNRN\CNRN.dll] [国风因特软件(北京)有限公司, 2.1.0.1048] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 14] [C:\PROGRA~1\CNRN\RNHelper.dll] [国风因特软件(北京)有限公司, 2.0.3.1020] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [E:\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll] [Kaspersky Lab, 7.0.0.125] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll] [Kaspersky Lab, 7.0.0.125] [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll] [Kaspersky Lab, 7.0.0.125] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 840, C:\WINDOWS\SYSTEM32\WINLOGON.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 500, C:\PROGRAM FILES\STORMII\STORMLIV.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1724, D:\ORACLE\ORA92\BIN\OMTSRECO.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1432, D:\ORACLE\ORA92\BIN\AGNTSRVC.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2264, D:\ORACLE\ORA92\BIN\TNSLSNR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2316, D:\ORACLE\ORA92\BIN\ORACLE.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2444, D:\ORACLE\ORA92\BIN\DBSNMP.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2448, C:\PROGRAM FILES\COMMON FILES\SOGOU PXP\P2PSVR.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 616, E:\SRENGLDR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 616, E:\SRENGLDR.EXE] ================================== 计划任务 N/A ================================== API HOOK RVA 错误: LoadLibraryA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) RVA 错误: LoadLibraryExA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) RVA 错误: LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) RVA 错误: LoadLibraryW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) ================================== 隐藏进程 N/A ================================== [/CODE]