[CODE] 2008-11-21,20:02:02 System Repair Engineer 2.7.0.1210 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [] [(Verified)Microsoft Windows Hardware Compatibility Publisher] <360Safetray> [(Verified)Qizhi Software (beijing) Co. Ltd] <360Safebox><"D:\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd] [NMGameX] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] <"C:\Program Files\InstallShield Installation Information\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"> [(Verified)Kaspersky Lab] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AEB6717E-7E19-11d0-97EE-00C04FD91972}> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon] [(Verified)Kaspersky Lab] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] [(Verified)Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <浏览器自定义组件> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] <%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] [Microsoft Corporation] [HKEY_CURRENT_USER\Control Panel\Desktop] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [File is missing] <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [File is missing] <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [File is missing] <; C:\WINDOWS\system32\rundll32.exe "C:\PROGRA~1\StormII\StormSet.dll",CheckEnv> [File is missing] ================================== 启动文件夹 [Adobe Gamma Loader] C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [Adobe Systems, Inc.]> [QQ游戏启动加速程序] D:\QQgame\Accel.exe [深圳市腾讯计算机系统有限公司]> ================================== 服务 [3ware Controller Service / 3wareSrv][Stopped/Auto Start] [AMD-813x Hot-Plug Service / AmdShpcSrv][Running/Auto Start] [卡巴斯基反病毒软件 7.0 / AVP][Stopped/Auto Start] <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r><(File is missing)> [C-DillaCdaC11BA / C-DillaCdaC11BA][Running/Auto Start] [Contrl Center of Storm Media / ccosm][Running/Auto Start] <北京暴风网际科技有限公司> [Cmb WebProtect Support / CMBWPS][Running/Auto Start] [Help and Support / helpsvc][Stopped/Disabled] %WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Disabled] <(File is missing)> [NVIDIA Display Driver Service / NVSvc][Running/Auto Start] ================================== 驱动程序 [2310_00 / 2310_00][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\2310_00.sys> [3wareDrv / 3wareDrv][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\3wareDrv.sys> [3waregsm / 3waregsm][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\3waregsm.sys> [3wDrv100 / 3wDrv100][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\3wDrv100.sys> [3wFlt100 / 3wFlt100][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\3wFlt100.sys> [a320raid / a320raid][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\a320raid.sys> [aaatimeo / aaatimeo][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aaatimeo.sys> [Adaptec RAID Miniport Driver / aac][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aac.sys> [Adaptec SAS/SATA-II RAID Miniport Driver / aacsas][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aacsas.sys> [aarich / aarich][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aarich.sys> [adp94xx / adp94xx][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\adp94xx.sys> [adpu160m / adpu160m][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\adpu160m.sys> [adpu320 / adpu320][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\adpu320.sys> [ACARD AEC6210UF UltraDMA33 Controller / aec6210][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aec6210.sys> [ACARD AEC6260 UltraDMA-66 Controller / aec6260][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aec6260.sys> [aec6280 / aec6280][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aec6280.sys> [AEC6880 / AEC6880][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\AEC6880.sys> [aec6897 / aec6897][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aec6897.sys> [AFAMgt / AFAMgt][Running/Boot Start] <\SystemRoot\system32\DRIVERS\afamgt.sys> [ahcix86 / ahcix86][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ahcix86.sys> [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Stopped/Manual Start] [AliIde / AliIde][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aliide.sys> [AMD AGP Bus Filter Driver / amdagp][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\amdagp.sys> [AMD NB AGP Bus Filter / amdagp8p][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\amdagp8p.sys> [amdbusdr / amdbusdr][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\amdbusdr.sys> [AMD EIDE 驱动程衼E / amdeide][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\AmdEide.sys> [AMD Processor Driver / AmdK8][Running/System Start] [AMD-813x Bus-Filter Driver / AmdPCI][Running/Boot Start] <\SystemRoot\system32\DRIVERS\AmdPci32.sys> [asc / asc][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\asc.sys> [asc3550 / asc3550][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\asc3550.sys> [atiide / atiide][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\atiide.sys> [Promise driver accelerator / bb-run][Running/Boot Start] <\SystemRoot\system32\DRIVERS\bb-run.sys> [ATI Cabo AGP Filter / caboagp][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\atisgkaf.sys> [cda1000 / cda1000][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\cda1000.sys> [CdaC15BA / CdaC15BA][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\CDAC15BA.SYS> [DELL CERC SATA 1.5/6ch RAID Miniport Driver / cercsr6][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\cercsr6.sys> [CMB8100 / CMB8100][Running/Auto Start] <\??\C:\WINDOWS\system32\Drivers\CertClient.dat> [CMBProtector / CMBProtector][Running/Auto Start] <\??\C:\WINDOWS\system32\Drivers\CMBProtector.dat> [CmdIde / CmdIde][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\cmdide.sys> [Cpq32fs2 / Cpq32fs2][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\Cpq32fs2.sys> [Creative SB16/AWE32/AWE64 Driver (WDM) / ctlsb16][Stopped/Manual Start] [dac2w2k / dac2w2k][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\dac2w2k.sys> [DC21x4 Based Network Adapter Driver / DC21x4][Stopped/Manual Start] [Promise Removable Disk Control Driver / dontgo][Running/Boot Start] <\SystemRoot\system32\DRIVERS\DontGo.sys> [EagleNT / EagleNT][Stopped/Manual Start] <\??\C:\WINDOWS\system32\drivers\EagleNT.sys> [FastSx / FastSx][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\FastSx.sys> [fasttrak / fasttrak][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\fasttrak.sys> [fasttx2k / fasttx2k][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\fasttx2k.sys> [fttxr52P / fttxr52P][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\fttxr52P.sys> [Fujitsu FUJ02B1 Device Driver / FUJ02B1][Stopped/Manual Start] [%FUJ02E1.DeviceDesc% / FUJ02E1][Stopped/Manual Start] [Fujitsu FUJ02E3 Device Driver / FUJ02E3][Stopped/Manual Start] [Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start] [Intel(R) Management Engine Interface / HECI][Stopped/Manual Start] [hpt374 / hpt374][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\hpt374.sys> [hpt3xx / hpt3xx][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\hpt3xx.sys> [hptmv / hptmv][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\hptmv.sys> [hptmv6 / hptmv6][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\hptmv6.sys> [hptpro / hptpro][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\hptpro.sys> [Intel RAID Controller / iaStor][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\iaStor.sys> [IFXTPM / IFXTPM][Stopped/Manual Start] [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start] [ITE CIR Driver / ITECIR][Stopped/Manual Start] [ITERAID_Service_Install / iteraid][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\iteraid.sys> [JMicron Hot-Plug Driver / JGOGO][Running/Boot Start] <\SystemRoot\system32\DRIVERS\JGOGO.sys> [JRAID / JRAID][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\jraid.sys> [kl1 / kl1][Running/Boot Start] <\SystemRoot\system32\drivers\kl1.sys> [klif / klif][Running/System Start] <\??\C:\WINDOWS\system32\drivers\klif.sys> [Kaspersky Anti-Virus NDIS Filter / klim5][Running/Manual Start] [m5281 / m5281][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\m5281.sys> [m5287 / m5287][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\m5287.sys> [m5288 / m5288][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\m5288.sys> [m5289 / m5289][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\m5289.sys> [MegaIDE / MegaIDE][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\MegaIDE.sys> [mraid35x / mraid35x][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\mraid35x.sys> [mv61xx / mv61xx][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\mv61xx.sys> [IBM ServeRAID 4M/4L/4Mx/4Lx/5i/6M/6i/7k Device Driver / nfrd960][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\nfrd960.sys> [npkcrypt / npkcrypt][Stopped/Manual Start] <\??\C:\WINDOWS\system32\npkcrypt.sys> [npkycryp / npkycryp][Stopped/Manual Start] <\??\C:\WINDOWS\system32\npkycryp.sys> [nv / nv][Running/Manual Start] [CMD IDE Raid Controller / Pnp649r][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\pnp649r.sys> [SiI 680 ATA Controller / Pnp680][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\pnp680.sys> [Silicon Image SiI 0680 Medley Raid Controller / Pnp680r][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\pnp680r.sys> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [ql1080 / ql1080][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ql1080.sys> [ql12160 / ql12160][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ql12160.sys> [ql1280 / ql1280][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ql1280.sys> [ql2100 / ql2100][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ql2100.sys> [ql2200 / ql2200][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ql2200.sys> [raidsrc / raidsrc][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\raidsrc.sys> [rr232x / rr232x][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\rr232x.sys> [Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Stopped/Manual Start] [Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver / RTLE8023xp][Stopped/Manual Start] [S150sx8 / S150sx8][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\S150sx8.sys> [SafeBoxKrnl / SafeBoxKrnl][Running/System Start] <\??\C:\WINDOWS\system32\drivers\SafeBoxKrnl.sys><360安全中心> [Secdrv / Secdrv][Running/Auto Start] [SiI-3512 SATALink Controller / SI3112][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SI3112.sys> [ATI-437A Serial ATA Controller / SI3112r][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SI3112r.sys> [SiI-3114 SATALink Controller / SI3114][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SI3114.sys> [SiI-3114 SATARaid Controller / SI3114r][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SI3114R.sys> [SiI-3114 SoftRaid 5 Controller / Si3114r5][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\Si3114r5.sys> [SiI-3124 SATALink Controller / SI3124][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SI3124.sys> [SiI-3124 SATARaid Controller / SI3124r][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SI3124R.sys> [SiI-3124 SoftRaid 5 Controller / Si3124r5][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\Si3124r5.sys> [SiI-3132 SATALink Controller / SI3132][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SI3132.sys> [SiI-3132 SoftRaid 5 Controller / Si3132r5][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\Si3132r5.sys> [SATALink driver accelerator / SiFilter][Running/Boot Start] <\SystemRoot\system32\DRIVERS\SiWinAcc.sys> [SATALink External Device Filter / SiRemFil][Running/Boot Start] <\SystemRoot\system32\DRIVERS\SiRemFil.sys> [SiS AGP Filter / SISAGP][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SISAGPX.sys> [SiSRaid / SiSRaid][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SiSRaid.sys> [SiSRaid2 / SiSRaid2][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SiSRaid2.sys> [Sparrow / Sparrow][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\sparrow.sys> [sptrak / sptrak][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\sptrak.sys> [symc8xx / symc8xx][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\symc8xx.sys> [Symmpi / Symmpi][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\symmpi.sys> [sym_hi / sym_hi][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\sym_hi.sys> [sym_u3 / sym_u3][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\sym_u3.sys> [sysHostSvc / sysHostSvc][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\GuiHelp.sys> [TCP/IP Protocol Driver / Tcpip][Running/System Start] [TesSafe / TesSafe][Stopped/Manual Start] <\??\C:\WINDOWS\system32\TesSafe.sys> [Transmeta TM 8000 AGP Filter Driver / tmagp][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\tmagp.sys> [ULi AGP Controller Bus Filter Driver / ULiAGP][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ULiAGP.sys> [ULi AGP Bus Filter Driver / uliagpkx][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\agpkx.sys> [UlSata / UlSata][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ulsata.sys> [ulsata2 / ulsata2][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ulsata2.sys> [ultra / ultra][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ultra.sys> [VIA AGP Filter / viaagp1][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\viaagp1.sys> [viamraid / viamraid][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\viamraid.sys> [VIA ATA/ATAPI Host Controller / viapdsk][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\viapdsk.sys> [videX32 / videX32][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\videX32.sys> [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start] <\SystemRoot\system32\DRIVERS\xfilt.sys> [NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller / yukonwxp][Running/Manual Start] ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [IESuper] {1A49F431-2A2E-41a5-9080-0F41D1A3AEC2} [WebProtect] {53763D1D-9CA8-4C7C-9756-A8E6B8FC063B} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [启动迅雷5] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} [浩方对战平台] {0A155D3C-68E2-4215-A47A-E800A446447A} [Web 反病毒统计] {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} [EditCtrl Class] {488A4255-3236-44B3-8F27-FA1AECAA8844} [RavOnline Class] {9FAFB576-6933-4CCC-AB3D-B988EC43D04E} [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [] {02496EBC-8455-48DB-B3C7-5DAC97D9F5A7} <, > [] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, > [] {0A155D3C-68E2-4215-A47A-E800A446447A} <, > [GerneralPeerID Class] {0A47E819-F82E-4D5D-B806-6A9EA94D68CD} [Edit Class] {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} [IESuperHelper] {1A49F431-2A2E-41A5-9080-0F41D1A3AEC1} [IESuper] {1A49F431-2A2E-41A5-9080-0F41D1A3AEC2} [iTrusPTA Class] {1E0DFFCF-27FF-4574-849B-55007349FEDA} [] {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <, > [Windows Media Player] {22D6F312-B0F6-11D0-94AB-0080C74C7E95} [HTML Document] {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, (Signed) N/A> [DHTML Edit Control Safe for Scripting for IE5] {2D360201-FFF5-11D1-8D03-00A0C959BC0A} [] {348AA067-D6BC-4385-A833-08E308D35782} <, > [XML Document] {48123BC4-99D9-11D1-A6B3-00C04FD91555} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [EditCtrl Class] {488A4255-3236-44B3-8F27-FA1AECAA8844} [Thunder Browser Helper] {53763D1C-9CA8-4C7C-9756-A8E6B8FC063B} [WebProtect] {53763D1D-9CA8-4C7C-9756-A8E6B8FC063B} [Shell Name Space] {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A> [XMP Class] {6483F145-A768-4C41-AACC-52D4D7845851} [XDRM] {693571CB-54A3-4E90-9D52-EEAE1334E2D3} [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [WangWangObj Class] {6E213FC7-DD5A-4115-B7E6-D4C7838C361E} [Active Desktop Mover] {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, (Signed) N/A> [AxInputControl Class] {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} [MediaComm Class] {7670648D-461B-42AF-BDFE-46D26AF5EFF2} [] {77FEF28E-EB96-44FF-B511-3185DEA48697} <, > [360SafeLive] {87515F61-A66C-4319-A0E0-D416CB8059E3} [Microsoft Web 浏览器] {8856F961-340A-11D0-A96B-00C04FD705A2} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [AxSubmitControl Class] {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} [RavOnline Class] {9FAFB576-6933-4CCC-AB3D-B988EC43D04E} [RMGetLicense Class] {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} [DapCtrl Class] {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} [SearchAssistantOC] {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A> [] {B580CF65-E151-49C3-B73F-70B13FCA8E86} <, > [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [RDS.DataSpace] {BD96C556-65A3-11D0-983A-00C04FC29E36} [ScreenCapture Class] {BFB79EE1-04AE-4D4A-B85E-27EE5F30C095} [AUDIO__MP3 Moniker Class] {CD3AFA76-B84F-48F0-9393-7EDC34128127} [AUDIO__X_MS_WMA Moniker Class] {CD3AFA84-B84F-48F0-9393-7EDC34128127} [VIDEO__X_MS_WMV Moniker Class] {CD3AFA94-B84F-48F0-9393-7EDC34128127} [RealPlayer G2 Control] {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [Thunder DapPlayer] {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} [&V使用Vagaa哇嘎下载] [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] [添加到QQ表情] ================================== 正在运行的进程 [PID: 600 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 672 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 696 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 7.0.1.325] [PID: 740 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [PID: 752 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [PID: 900 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [PID: 980 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [PID: 1020 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [PID: 1172 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [PID: 1204 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [PID: 1404 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [PID: 1656 / Administrator][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86] [C:\Program Files\InstallShield Installation Information\Kaspersky Lab\Kaspersky Anti-Virus 7.0\scrchpg.dll] [Kaspersky Lab, 7.0.1.325] [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] [Autodesk, 16.0.0.86] [D:\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [D:\360safe\Antispy.dll] [奇虎网, 4, 2, 0, 1006] [D:\xunlei\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [D:\xunlei\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [D:\xunlei\Components\ResWorker\DsBho_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20] [D:\xunlei\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\Program Files\InstallShield Installation Information\Kaspersky Lab\Kaspersky Anti-Virus 7.0\ShellEx.dll] [Kaspersky Lab, 7.0.1.325] [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762] [PID: 1840 / SYSTEM][C:\WINDOWS\system32\AmdHpSrv.exe] [AMD, Inc., 1.3.9] [PID: 1856 / SYSTEM][C:\WINDOWS\system32\drivers\CDAC11BA.EXE] [Macrovision, 4.20.020] [PID: 1876 / SYSTEM][D:\baofeng\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 10, 29] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [D:\baofeng\bfoptdll.dll] [北京暴风网际科技有限公司, 3, 8, 7, 16] [PID: 1888 / SYSTEM][C:\Program Files\CMBCHINA\WebProtect\WPService.exe] [China Merchants Bank, 1, 0, 0, 1] [C:\Program Files\CMBCHINA\WebProtect\WebProtectPlus.dll] [China Merchants Bank, 1, 0, 0, 1] [PID: 1928 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.11.5822] [C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.5822] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [PID: 1972 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)] [PID: 288 / Administrator][C:\WINDOWS\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [C:\WINDOWS\system32\NvMcTray.dll] [NVIDIA Corporation, 6.14.11.5822] [C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.5822] [C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.11.5822] [PID: 324 / Administrator][C:\WINDOWS\RTHDCPL.EXE] [Realtek Semiconductor Corp., 2.2.0.2] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [D:\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [PID: 872 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [D:\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [C:\Program Files\InstallShield Installation Information\Kaspersky Lab\Kaspersky Anti-Virus 7.0\scrchpg.dll] [Kaspersky Lab, 7.0.1.325] [C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86] [D:\xunlei\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [F:\IESuper\iesuper.dll] [IESuper.com, 1, 1, 1, 0] [C:\Program Files\CMBCHINA\WebProtect\WebProtect.dll] [China Merchants Bank, 1, 0, 0, 1] [D:\xunlei\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [D:\xunlei\Components\ResWorker\DsBho_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20] [D:\xunlei\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx] [Adobe Systems, Inc., 10,0,12,36] [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\Program Files\InstallShield Installation Information\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prloader.dll] [Kaspersky Lab, 7.0.1.325] [PID: 892 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [D:\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [PID: 1604 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [PID: 3300 / Administrator][D:\xunlei\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5.8.5.595] [D:\xunlei\Program\BugReport.dll] [Thunder Networking Technologies,LTD, 1, 4, 1, 20] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [D:\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [D:\xunlei\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 3, 9, 71] [D:\xunlei\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 3, 100, 2, 322] [D:\xunlei\Program\mp.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 2] [D:\xunlei\Program\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [D:\xunlei\Program\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [D:\xunlei\Program\asyn_frame.dll] [Thunder Networking Technologies,LTD, 1, 2, 2, 25] [D:\xunlei\Program\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0] [D:\xunlei\Program\fs.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 12] [D:\xunlei\Program\XLNet.Dll] [Thunder Networking Technologies,LTD, 1, 5, 2, 25] [D:\xunlei\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 1, 1, 10] [D:\xunlei\Components\DownAndPlay\DownAndPlay.dll] [, 1, 0, 12, 30] [D:\xunlei\Program\backend_agent.dll] [Thunder Networking Technologies,LTD, 1, 2, 2, 24] [D:\xunlei\Program\zlib1.dll] [, 1.2.3] [C:\Program Files\InstallShield Installation Information\Kaspersky Lab\Kaspersky Anti-Virus 7.0\scrchpg.dll] [Kaspersky Lab, 7.0.1.325] [D:\xunlei\Program\emule.dll] [, 1, 1, 2, 27] [D:\xunlei\Program\down_dispatcher.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 24] [D:\xunlei\Program\ptl.dll] [Thunder Networking Technologies,LTD, 3,2,2,31] [D:\xunlei\Program\dl_peer_id.dll] [Thunder Networking Technologies,LTD, 3, 1, 2, 2] [D:\xunlei\Program\xl_stat.dll] [, 1, 1, 2, 6] [D:\xunlei\Program\p2p_upload.dll] [Thunder Networking Technologies,LTD, 1,2,2,12] [D:\xunlei\Program\p2sp.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 39] [D:\xunlei\Program\iTargetAD.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 35] [C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx] [Adobe Systems, Inc., 10,0,12,36] [D:\xunlei\Program\p2p.dll] [Thunder Networking Technologies,LTD, 1,2,2,34] [D:\xunlei\Program\xldc.dll] [Thunder Networking Technologies,LTD, 2, 6, 2, 18] [D:\xunlei\Program\stream.dll] [Thunder Networking Technologies,LTD, 2, 1, 2, 399] [D:\xunlei\Program\p2p_local_res.dll] [Thunder Networking Technologies,LTD, 1,2,2,16] [D:\xunlei\Program\al.dll] [Thunder Networking Technologies,LTD, 1,2,2,22] [D:\xunlei\Program\p2p_network_com.dll] [, 1, 0, 2, 25] [C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86] [D:\xunlei\Components\InMedia\iEmbedShell.dll] [ , 1, 0, 2, 25] [D:\xunlei\Components\InMedia\iEmbed19.dll] [Thunder Networking Technologies,LTD, 3, 4, 10, 116] [D:\xunlei\Components\InMedia\PlayerHelper.dll] [thunder, 1, 2, 7, 61] [D:\xunlei\Components\InMedia\XLIPC.DLL] [Thunder Networking Technologies,LTD, 1, 0, 0, 2] [D:\xunlei\Components\P4PClient\P4PClient.dll] [Thunder Networking Technologies,LTD, 2, 2, 5, 70] [D:\xunlei\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 2, 5, 0, 90] [D:\xunlei\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 17, 0, 67] [D:\xunlei\Program\MSVCIRT.dll] [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)] [D:\xunlei\Program\imdt.dll] [Thunder Networking Technologies,LTD, 1.2.2.18] [D:\xunlei\Components\Security\ThunderSafe.dll] [深圳市迅雷网络技术有限公司, 2, 1, 3, 97] [D:\xunlei\Components\Security\ConfigManager.dll] [深圳市迅雷网络技术有限公司, 1, 0, 0, 1] [D:\xunlei\Components\Security\SafeManager.dll] [Xunlei Networking Technologies,LTD, 1, 0, 5, 20] [D:\xunlei\Components\Security\SafeStatistic.dll] [Xunlei Networking Technologies,LTD, 1, 0, 0, 1] [D:\xunlei\Program\XLNetU.Dll] [Thunder Networking Technologies,LTD, 1, 5, 1, 24] [D:\xunlei\Plugins\XLSafeHost\XLSafeHost.dll] [深圳市迅雷网络技术有限公司, 1, 2, 5, 82] [D:\xunlei\Plugins\XLSafeHost\AutoHelp.dll] [Beijing Rising Technology Co., Ltd., 6.0.0.5] [D:\xunlei\Components\Community\audioCtrl.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 2] [D:\xunlei\Components\Community\xlaudio.dll] [, 1, 0, 2, 4] [D:\xunlei\Program\xlvdt.dll] [Thunder Networking Technologies,LTD, 1.0.2.6] [D:\xunlei\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 1, 7, 25] [D:\xunlei\Program\LiveUpdate.dll] [Thunder Networking Technologies,LTD, 1, 2, 4, 26] [D:\xunlei\Components\XLSoftBase\XLSoftwareBase.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 3] [D:\xunlei\Plugins\GouGouTop\GouGouTop.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 5] [D:\xunlei\Plugins\KanKanTop\KanKanTop.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 4] [D:\xunlei\Components\ExplorerHelper\ExplorerHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 19] [D:\xunlei\ComDlls\ThunderAgent_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 4, 23] [D:\xunlei\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [D:\xunlei\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [D:\xunlei\Components\Tips\TipsClient.dll] [Thunder Networking Technologies,LTD, 2, 2, 14, 120] [D:\xunlei\Components\VPSHELL\VPSHELL.dll] [迅雷网络, 4, 0, 0, 38] [D:\xunlei\Program\emule_id.dll] [, 1, 0, 2, 11] [D:\xunlei\Components\UserExperience\UserExperience.dll] [Thunder Networking Technologies,LTD, 1, 0, 3, 5] [D:\xunlei\Components\ResWorker\DsXlCom.dll] [, 1, 0, 0, 30] [D:\xunlei\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [D:\xunlei\Components\ResWorker\MediaWorker.dll] [Thunder Networking Technologies,LTD, 1, 2, 0, 22] [D:\xunlei\Components\Tips\XLIPC.DLL] [Thunder Networking Technologies,LTD, 1, 0, 0, 2] [D:\xunlei\Components\DownloadStat\DownloadStat.dll] [Thunder Networking Technologies,LTD, 1, 4, 1, 6] [D:\xunlei\Program\p2sp_pd.dll] [Thunder Networking Technologies,LTD, 1, 100, 2, 4] [D:\xunlei\Program\bd.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 18] [PID: 3896 / Administrator][F:\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210] [PID: 3904 / Administrator][F:\sreng2\SRE13d9b9dc.EXE] [Smallfrogs Studio, 2.7.0.1210] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)] [D:\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [F:\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 127.0.0.1 yu.8s7.net 127.0.0.1 1.jopanqc.com 127.0.0.1 2.joppnqq.com 127.0.0.1 wg.47255.com 127.0.0.1 1.joppnqq.com 127.0.0.1 xxx.m111.biz 127.0.0.1 1.jopenqc.com 127.0.0.1 1.jopenkk.com 127.0.0.1 xxx.vh7.biz 127.0.0.1 xxx.j41m.com 127.0.0.1 3.joppnqq.com 127.0.0.1 d.93se.com 127.0.0.1 www.868wg.com 127.0.0.1 xxx.mmma.biz 127.0.0.1 ilove.com 127.0.0.1 tp.shpzhan.cn 127.0.0.1 www.tomwg.com 127.0.0.1 www.cike007.cn 127.0.0.1 www.22aaa.com 127.0.0.1 xx.exiao01.com 127.0.0.1 www.exiao01.com 127.0.0.1 www.exiao01.com 127.0.0.1 new.749571.com 127.0.0.1 xtx.kv8.info 127.0.0.1 cao.kv8.info 127.0.0.1 1.jopmmqq.com 127.0.0.1 171817.171817.com 127.0.0.1 d2.llsging.com 127.0.0.1 down.malasc.cn 127.0.0.1 llboss.com 127.0.0.1 nx.51ylb.cn 127.0.0.1 my.531jx.cn 127.0.0.1 qqq.dzydhx.com 127.0.0.1 qqq.hao1658.com 127.0.0.1 www.333292.com 127.0.0.1 down.18dd.net 127.0.0.1 up.22x44.com 127.0.0.1 aaa.faba01.com 127.0.0.1 bad.tqdlt.cn 127.0.0.1 1.chsipo.com 127.0.0.1 c3.aishangai.net 127.0.0.1 c2.aishangai.net 127.0.0.1 xxx.188dm.com 127.0.0.1 x2.1a2b3c1.com 127.0.0.1 d1.163500.net 127.0.0.1 down.google-serv.cn ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 1840, C:\WINDOWS\SYSTEM32\AMDHPSRV.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3300, D:\XUNLEI\PROGRAM\THUNDER5.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3896, F:\SRENG2\SRENGLDR.EXE] ================================== 计划任务 N/A ================================== API HOOK RVA 错误: LoadLibraryA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) RVA 错误: LoadLibraryExA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) RVA 错误: LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) RVA 错误: LoadLibraryW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) ================================== 隐藏进程 N/A ================================== [/CODE]