[CODE] 2009-02-04,07:27:30 System Repair Engineer 2.7.0.1210 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] <; C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [Sun Microsystems, Inc.] <360Safebox><"d:\360safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd] <360Safetray> [(Verified)Qizhi Software (beijing) Co. Ltd] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AEB6717E-7E19-11d0-97EE-00C04FD91972}> [(Verified)Microsoft Windows Component Publisher] <{B652C184-9068-42AA-846B-8D6341E9F1AC}><> [N/A] <{ADD44BC8-3E7E-4822-A3E2-507D335C2FEE}><> [N/A] <{9DF5CECB-60DB-4029-83E9-1E73656DB842}><> [N/A] <{32597D13-5305-48A0-BE61-214FDE23D0BD}><> [N/A] <{69F30E53-7F2F-44DE-A363-42D628EB7050}><> [N/A] <{4DF86A05-9B4E-49D0-A855-8EFC7D654DF1}><> [N/A] <{090805BC-23CA-4ED8-8FBD-12FC5D0E9A29}><> [N/A] <{D403ADAD-C69E-4471-9D43-0069C990C4B0}><> [N/A] <{060CEEC8-9107-4E96-B813-63D119E63509}><> [N/A] <{C79A0D88-898B-4336-B1BB-40872EACCE50}><> [N/A] <{2F162549-D18E-4535-BED1-61A0324DE3E9}><> [N/A] <{84D79F96-7E85-4AFB-A721-9D7274AAC659}><> [N/A] <{7606F664-D5BB-41A9-88D0-9D2752290070}><> [N/A] <{780BB67A-15C8-488A-9A7F-AF6089ADC182}> [File is missing] <{827993B3-0E3F-439B-9B2D-097C99080FDC}> [File is missing] <{C9DAFBF8-11D2-4BCC-8EF8-E5DDE9A9E935}> [File is missing] <{EF3B5506-CC08-4E93-8CEA-A06804780D61}><> [N/A] <{4A8EAA8E-A53B-41AF-8D02-4236A53E5EAC}> [File is missing] <{DD8429D1-BEF0-4ED2-8E31-FDCBC71BCECD}> [File is missing] <{1FD5E4DF-614A-4385-AA4C-8BE68B3DA882}> [File is missing] <{C2606FD3-6D1D-42EF-975A-FAA5E0CAB439}><> [N/A] <{05889F9C-2584-4BA2-BAC9-A0BC842BEA77}><> [N/A] <{E9391147-59F0-4572-B8CC-7C495A7DC3D6}> [File is missing] <{E6490874-3B59-4031-8383-79E4C8275ECF}> [File is missing] <{F31E52E7-95E3-41B1-9AD3-349AF0358F49}><> [N/A] <{5158C4B8-B8A9-4CE6-B34F-CF2AA2F3FA2B}> [File is missing] <{1CB13AE7-47F5-4050-A0A3-FF0959641BEB}> [File is missing] <{D6BB97EA-340B-4474-9735-54AF63B335CD}><> [N/A] <{F5B12292-56D9-4347-95AF-66D6C3A69543}> [File is missing] <{73510123-FD3C-4BDE-ADFF-DE174151929A}><> [N/A] <{BE199C7D-5D3A-4116-8A32-EE6D6C9CE098}><> [N/A] <{E5EBD82F-ED36-4324-972B-9B404B1DD8B3}> [File is missing] <{A141A449-09C8-4468-97B2-B02A79BB307A}> [File is missing] <{E9379EE9-DA54-44C2-9057-A2AAD82C5232}><> [N/A] <{10FB8E4E-5491-4218-925A-262F9D3A6D70}><> [N/A] <{005E7007-2840-4B56-A0BE-7B8522DAC5B5}> [File is missing] <{CA21B5C6-6C1F-4CE8-B58C-AEF4CCB7A58F}> [File is missing] <{DBE8EAE5-82BB-463C-9C6E-5234324DA25C}> [File is missing] <{AC8A72AC-BE5E-4A84-8FF5-800536BA1928}> [File is missing] <{A0C4A2B7-1A08-4D57-AEF5-3CB5A3611363}> [File is missing] <{9880FF50-6CCB-43F8-B1C3-678FBEC8AA87}> [File is missing] <{85E6EC8B-C9C5-491D-B793-88BC38B500AE}> [File is missing] <{63442F2C-E6D6-48AA-B016-55F9A14D8147}> [File is missing] <{15249D88-58F5-446D-BF83-CBAE847692F0}><> [N/A] <{E32C101A-28B4-44BB-9297-A458B7F16351}> [File is missing] <{E454E45A-8297-4C6E-B425-F453D0978609}> [File is missing] <{6A055262-A4AA-488E-97EE-B7162C35AABC}> [File is missing] <{94C5BB89-C8CF-4EC9-B11D-38097E485A8D}> [File is missing] <{895BA6A7-EB7C-4DF4-849D-045940506B64}> [File is missing] <{8CB08957-7B3F-4D0B-BC95-413E2E5E72F2}> [File is missing] <{55630C74-A4A9-4284-AEB6-82FC80694A31}> [File is missing] <{F215DF9E-EC77-4321-BB8A-7EA97F1ECFEA}> [File is missing] <{F7689326-CC81-42D2-B518-740384FD6A1E}> [File is missing] <{0D4CF9F5-6D88-412D-9305-ABF0750259E0}> [File is missing] <{BD2A61FA-A481-434B-BCB1-4C430824E0EA}><> [N/A] <{7971947D-2F18-462C-BD4B-CC2CC7CDEC5F}> [File is missing] <{DB9A0807-EF61-42CF-B95E-74CFE565E1E4}> [File is missing] <{8CC2557E-5C34-490F-B98B-D6C090B26430}> [File is missing] <{7656B0F6-A1B8-4C7C-9348-59218F55A3EC}> [File is missing] <{9BE92604-4818-44DC-9465-0A92E7D23827}> [File is missing] <{43538A4C-D2DB-4CE9-AAB8-0C9DBF03BE5C}> [File is missing] <{563EC114-0115-49D6-9A4C-FBC80F3B9EBE}> [File is missing] <{875B5218-10E3-40F0-AB7F-D471E4A09B6D}> [File is missing] <{CCF2FC55-80B5-429B-9D99-CF9754D950A4}><> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] <827993B3> [File is missing] <4A8EAA8E> [File is missing] [File is missing] <1CB13AE7> [File is missing] <1FD5E4DF> [File is missing] [File is missing] [File is missing] [File is missing] <780BB67A> [File is missing] <5158C4B8> [File is missing] [File is missing] [File is missing] [File is missing] [File is missing] [File is missing] <9880FF50> [File is missing] <85E6EC8B> [File is missing] <63442F2C> [File is missing] [File is missing] [File is missing] <6A055262> [File is missing] <94C5BB89> [File is missing] <895BA6A7> [File is missing] <55630C74> [File is missing] <8CB08957> [File is missing] [File is missing] <0D4CF9F5> [File is missing] [File is missing] <7971947D> [File is missing] [File is missing] <7656B0F6> [File is missing] <8CC2557E> [File is missing] <9BE92604> [File is missing] <43538A4C> [File is missing] <875B5218> [File is missing] <563EC114> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy] <%SystemRoot%\System32\dimsntfy.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon] [(Verified)Kaspersky Lab] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <浏览器自定义组件> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5084F01D-458E-45EB-A6FD-692D4C9D2789}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] <%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Component Publisher] [HKEY_CURRENT_USER\Control Panel\Desktop] [(Verified)Microsoft Windows Component Publisher] ================================== 启动文件夹 N/A ================================== 服务 [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Stopped/Auto Start] [Kaspersky Anti-Virus / AVP][Stopped/Manual Start] <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r> [Contrl Center of Storm Media / ccosm][Stopped/Disabled] <北京暴风网际科技有限公司> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [NVIDIA Display Driver Service / NVSvc][Stopped/Disabled] [Oracle OLAP 9.0.1.0.1 / OLAPServer][Stopped/Manual Start] [Oracle OLAP Agent / Oracle OLAP Agent][Stopped/Manual Start] [OracleMTSRecoveryService / OracleMTSRecoveryService][Stopped/Auto Start] <(File is missing)> [Oracleoracle9PagingServer / Oracleoracle9PagingServer][Stopped/Manual Start] [OracleOraHome90Agent / OracleOraHome90Agent][Stopped/Auto Start] <(File is missing)> [OracleOraHome90ClientCache / OracleOraHome90ClientCache][Stopped/Manual Start] <(File is missing)> [OracleOraHome90HTTPServer / OracleOraHome90HTTPServer][Stopped/Auto Start] <"H:\oracle\ora90\Apache\Apache\apache.exe" --ntservice><(File is missing)> [OracleOraHome90PagingServer / OracleOraHome90PagingServer][Stopped/Manual Start] <(File is missing)> [OracleOraHome90SNMPPeerEncapsulator / OracleOraHome90SNMPPeerEncapsulator][Stopped/Manual Start] <(File is missing)> [OracleOraHome90SNMPPeerMasterAgent / OracleOraHome90SNMPPeerMasterAgent][Stopped/Manual Start] <(File is missing)> [OracleOraHome90TNSListener / OracleOraHome90TNSListener][Stopped/Auto Start] <(File is missing)> [OracleServiceTIMSHAWN / OracleServiceTIMSHAWN][Stopped/Auto Start] <(File is missing)> [Apache Tomcat / Tomcat6][Stopped/Manual Start] [PC Tools Auxiliary Service / sdAuxService][Stopped/Auto Start] [PC Tools Security Service / sdCoreService][Stopped/Auto Start] ================================== 驱动程序 [360procmon / 360procmon][Stopped/Disabled] <\??\D:\360Safe\safemon\360procmon.sys><> [AMD Processor Driver / AmdK8][Stopped/System Start] [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Stopped/System Start] <\??\d:\AVG Anti-Spyware\guard.sys> [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start] [BFSDRV / BFSDRV][Stopped/Manual Start] <\??\C:\Documents and Settings\Administrator\桌面\360compkill\BFSDRV.sys> [Creative AudioPCI (ES1371,ES1373) (WDM) / es1371][Stopped/Manual Start] [Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start] [Intel AHCI Controller / iaStor7][Running/Boot Start] <\SystemRoot\system32\drivers\iastor7.sys> [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Stopped/Manual Start] [kl1 / kl1][Stopped/Boot Start] <\SystemRoot\system32\drivers\kl1.sys> [Kaspersky Lab Boot Guard Driver / klbg][Stopped/Boot Start] <\SystemRoot\system32\drivers\klbg.sys> [Kaspersky Lab Driver / KLIF][Stopped/System Start] [Kaspersky Anti-Virus NDIS Filter / klim5][Running/Manual Start] [msiffei / msiffei][Stopped/Manual Start] [nv / nv][Stopped/Manual Start] [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start] <\SystemRoot\system32\DRIVERS\nvrd32.sys> [AMD PCNET Compatable Adapter Driver / PCnet][Stopped/Manual Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start] [SafeBoxKrnl / SafeBoxKrnl][Stopped/System Start] <\??\C:\WINDOWS\system32\drivers\SafeBoxKrnl.sys><360安全中心> [Secdrv / Secdrv][Stopped/Manual Start] [SATALink driver accelerator / SiFilter][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SiWinAcc.sys> [sptd / sptd][Stopped/Boot Start] <\SystemRoot\System32\Drivers\sptd.sys> [TCP/IP Protocol Driver / Tcpip][Running/System Start] [viamraid / viamraid][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\viamraid.sys> [File Security Driver / IKFileSec][Stopped/Boot Start] <\SystemRoot\system32\drivers\ikfilesec.sys> [System Filter Driver / IKSysFlt][Stopped/System Start] [System Security Driver / IKSysSec][Stopped/System Start] ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [IEVkbdBHO Class] {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [Java Plug-in 1.5.0_04] {08B0E5C0-4FCB-11CF-AAA5-00401C608501} [启动迅雷5] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} [Web 流量保护状态] {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} [Edit with Altova X&MLSpy] {2222EF56-F49E-4d07-A14E-8D2B08766958} <, > [] {e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, (Signed) N/A> [PhotoDrawEx Class] {05F5F404-7C24-4B39-B5CC-340CEDEB9C0D} [Java Plug-in 1.5.0_04] {8AD9C840-044E-11D1-B3E9-00805F499D93} [Java Plug-in 1.5.0_04] {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [PhotoDrawEx Class] {05F5F404-7C24-4B39-B5CC-340CEDEB9C0D} [Web Browser Applet Control] {08B0E5C0-4FCB-11CF-AAA5-00401C608501} [] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, > [GerneralPeerID Class] {0A47E819-F82E-4D5D-B806-6A9EA94D68CD} [Windows Genuine Advantage Validation Tool] {17492023-C23A-453E-A040-C7C580BBF700} [] {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <, > [] {2222EF56-F49E-4D07-A14E-8D2B08766958} <, > [DHTML Edit Control Safe for Scripting for IE5] {2D360201-FFF5-11D1-8D03-00A0C959BC0A} [] {478932A2-862F-4A34-A264-54A6EB998FDE} [XML Document] {48123BC4-99D9-11D1-A6B3-00C04FD91555} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [IEVkbdBHO Class] {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} [WUWebControl Class] {6414512B-B978-451D-A0D8-FCFDF33E833C} [XMP Class] {6483F145-A768-4C41-AACC-52D4D7845851} [XDRM] {693571CB-54A3-4E90-9D52-EEAE1334E2D3} [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [MediaComm Class] {7670648D-461B-42AF-BDFE-46D26AF5EFF2} [360SafeLive] {87515F61-A66C-4319-A0E0-D416CB8059E3} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [] {95B3F550-91C4-4627-BCC4-521288C52977} <, > [OFrameObject Class] {9701758C-4373-482E-B13C-776C048EC890} [RMGetLicense Class] {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} [DapCtrl Class] {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} [Microsoft Scriptlet Component] {AE24FDAE-03C6-11D1-8B76-0080C744F389} [SearchAssistantOC] {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A> [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [AUDIO__MP3 Moniker Class] {CD3AFA76-B84F-48F0-9393-7EDC34128127} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [PlayerCtrl Class] {E05BC2A3-9A46-4A32-80C9-023A473F5B23} [] {E2E2DD38-D088-4134-82B7-F2BA38496583} <, > [] {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} <, > [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} [Edit with Altova X&MLSpy] [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] [添加到QQ表情] ================================== 正在运行的进程 [PID: 628 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 676 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 700 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 8.0.0.454] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258] [PID: 744 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 756 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 912 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258] [PID: 980 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\TcpIpDog0.dll] [N/A, ] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258] [PID: 1084 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\TcpIpDog0.dll] [N/A, ] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258] [PID: 1132 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 1476 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ShellEx.dll] [Kaspersky Lab, 8.0.0.454] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762] [D:\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1005] [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\IDM Computer Solutions\UltraEdit-32\ue32ctmn.dll] [, 1, 0, 0, 2] [d:\AVG Anti-Spyware\context.dll] [GRISOFT s.r.o., 7, 5, 1, 36] [PID: 408 / Administrator][C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe] [Kaspersky Lab, 8.0.0.454] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\prremote.dll] [Kaspersky Lab, 8.0.0.454] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\fssync.dll] [Kaspersky Lab, 8.0.5.454] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\Ushata.dll] [Kaspersky Lab, 8.0.0.454] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\CLLDR.DLL] [Kaspersky Lab, 8.0.0.454] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\prloader.dll] [Kaspersky Lab, 8.0.0.454] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\prkernel.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\pxstub.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\params.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\winreg.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\mkavio.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\tempfile.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\tm.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\nfio.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\fsdrvplg.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\bl.ppl] [Kaspersky Lab, 8.0.0.459] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\wmihlpr.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\regmap.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\ndetect.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\crpthlpr.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\dtreg.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\sfdb.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\schedule.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\timer.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\thpimpl.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\lic.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\report.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\reportdb.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\hashmd5.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\avs.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\vmarea.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\avlib.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\avspm.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\procmon.ppl] [Kaspersky Lab, 8.0.0.461] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\qb.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\propmap.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\filemap.ppl] [Kaspersky Lab, 8.0.0.454] [C:\WINDOWS\system32\TcpIpDog0.dll] [N/A, ] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\syswatch.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\avpgui.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\basegui.ppl] [Kaspersky Lab, 8.0.0.454] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\ods.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\wdiskio.ppl] [Kaspersky Lab, 8.0.0.454] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avzkrnl.dll] [, 4.30.0.10] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\ichk2.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\ichksa.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\buffer.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\memscan.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\memmodsc.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\ntfsstrm.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\uniarc.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\minizip.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\cab.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\arj.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\rar.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\lha.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\dmap.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\stenum2.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\inifile.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\btimages.ppl] [Kaspersky Lab, 8.0.0.454] [c:\program files\kaspersky lab\kaspersky anti-virus 2009\prutil.ppl] [Kaspersky Lab, 8.0.0.454] [PID: 1040 / Administrator][D:\360Safe\safemon\360Tray.exe] [360安全中心, 5, 0, 0, 1011] [D:\360Safe\safemon\360procmon.dll] [360.CN, 1, 0, 0, 1005] [C:\WINDOWS\system32\TcpIpDog0.dll] [N/A, ] [D:\360Safe\safemon\360compro.dll] [360安全中心, 1, 0, 0, 1004] [D:\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1005] [D:\360Safe\safemon\urlproc.dll] [360.CN, 1, 0, 0, 1002] [D:\360Safe\safemon\SafeKrnl.dll] [奇虎网, 4, 3, 0, 1004] [D:\360Safe\AntiAdwa.dll] [360Safe.com, 4, 2, 0, 1002] [D:\360Safe\safemon\360webpro.dll] [360.CN, 1, 0, 0, 1006] [D:\360Safe\live.dll] [360.cn, 1, 0, 1, 1029] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 1376 / Administrator][D:\360Safe\360hotfix.exe] [奇虎网, 4, 5, 0, 1004] [D:\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1005] [D:\360Safe\LeakCheck.dll] [360Safe.com, 4, 5, 0, 1004] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\TcpIpDog0.dll] [N/A, ] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258] [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\scrchpg.dll] [Kaspersky Lab, 8.0.0.454] [PID: 328 / Administrator][D:\Program Files\Dr.COM\Dr.COM客户端.exe] [N/A, ] [D:\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1005] [C:\WINDOWS\system32\TcpIpDog0.dll] [N/A, ] [PID: 1964 / Administrator][C:\Program Files\The World 2.1\TheWorld.exe] [Phoenix Studio, 2, 1, 2, 4] [D:\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1005] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258] [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\TcpIpDog0.dll] [N/A, ] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\scrchpg.dll] [Kaspersky Lab, 8.0.0.454] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\klscav.dll] [Kaspersky Lab, 8.0.0.454] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0] [d:\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 120] [PID: 1568 / Administrator][d:\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5.8.9.662] [d:\Thunder\Program\BugReport.dll] [Thunder Networking Technologies,LTD, 1, 4, 1, 20] [D:\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1005] [d:\Thunder\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 3, 10, 73] [d:\Thunder\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 3, 4, 2, 333] [d:\Thunder\Program\mp.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 5] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258] [d:\Thunder\Program\asyn_frame.dll] [Thunder Networking Technologies,LTD, 1, 3, 2, 32] [d:\Thunder\Program\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\TcpIpDog0.dll] [N/A, ] [d:\Thunder\Program\XLNet.Dll] [Thunder Networking Technologies,LTD, 1, 5, 2, 25] [d:\Thunder\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 1, 1, 12] [d:\Thunder\Components\DownAndPlay\DownAndPlay.dll] [, 1, 0, 12, 30] [d:\Thunder\Program\backend_agent.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 27] [d:\Thunder\Program\zlib1.dll] [, 1.2.3] [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [d:\Thunder\Program\p2sp.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 59] [d:\Thunder\Program\fs.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 17] [d:\Thunder\Program\down_dispatcher.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 42] [d:\Thunder\Program\ptl.dll] [Thunder Networking Technologies,LTD, 3, 2, 2, 54] [d:\Thunder\Program\dl_peer_id.dll] [Thunder Networking Technologies,LTD, 3, 1, 2, 4] [d:\Thunder\Program\xl_stat.dll] [, 1, 0, 2, 7] [d:\Thunder\Program\p2p_network_com.dll] [, 1, 0, 2, 25] [d:\Thunder\Program\iTargetAD.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 35] [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\scrchpg.dll] [Kaspersky Lab, 8.0.0.454] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\klscav.dll] [Kaspersky Lab, 8.0.0.454] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [d:\Thunder\Program\p2p_upload.dll] [Thunder Networking Technologies,LTD, 1,1,2,13] [d:\Thunder\Program\p2p.dll] [Thunder Networking Technologies,LTD, 1,1,2,48] [d:\Thunder\Program\xldc.dll] [Thunder Networking Technologies,LTD, 4, 0, 2, 25] [d:\Thunder\Program\stream.dll] [ShenZhen Thunder Networking Technologies,Ltd., 2, 1, 2, 1025] [d:\Thunder\Program\p2p_local_res.dll] [Thunder Networking Technologies,LTD, 1,1,2,18] [d:\Thunder\Program\al.dll] [Thunder Networking Technologies,LTD, 1,1,2,31] [d:\Thunder\Program\media_data.dll] [, 1, 0, 2, 7] [d:\Thunder\Program\sl.dll] [Thunder Networking Technologies,LTD, 1.0.2.2] [d:\Thunder\Program\p2sp_pd.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 5] [d:\Thunder\Components\InMedia\iEmbedShell.dll] [ , 3, 4, 11, 118] [d:\Thunder\Components\InMedia\iEmbed20.dll] [Thunder Networking Technologies,LTD, 3, 4, 11, 118] [d:\Thunder\Components\InMedia\XLIPC.DLL] [Thunder Networking Technologies,LTD, 1, 0, 0, 2] [d:\Thunder\Components\P4PClient\P4PClient.dll] [Thunder Networking Technologies,LTD, 2, 2, 5, 70] [d:\Thunder\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 2, 6, 0, 104] [d:\Thunder\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 17, 0, 67] [d:\Thunder\Program\MSVCIRT.dll] [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)] [d:\Thunder\Program\XLNetU.Dll] [Thunder Networking Technologies,LTD, 1, 5, 1, 24] [d:\Thunder\Program\imdt.dll] [Thunder Networking Technologies,LTD, 1.2.0.21] [d:\Thunder\Components\Security\ThunderSafe.dll] [Xunlei Networking Technologies,LTD, 2, 1, 8, 106] [d:\Thunder\Components\Security\ConfigManager.dll] [深圳市迅雷网络技术有限公司, 1, 0, 0, 1] [d:\Thunder\Components\Security\SafeManager.dll] [Xunlei Networking Technologies,LTD, 1, 0, 5, 20] [d:\Thunder\Components\Security\SafeStatistic.dll] [Xunlei Networking Technologies,LTD, 1, 0, 0, 1] [d:\Thunder\Components\InMedia\MediaAddin18.dll] [Thunder Networking Technologies,LTD, 3, 1, 6, 81] [d:\Thunder\Plugins\XLSafeHost\XLSafeHost.dll] [深圳市迅雷网络技术有限公司, 1, 2, 19, 106] [d:\Thunder\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 1, 7, 25] [d:\Thunder\Program\LiveUpdate.dll] [Thunder Networking Technologies,LTD, 1, 2, 4, 26] [d:\Thunder\Program\xldcsubtask.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 5] [d:\Thunder\Components\ExplorerHelper\ExplorerHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 26] [d:\Thunder\Components\Tips\TipsClient.dll] [Thunder Networking Technologies,LTD, 3, 0, 2, 131] [d:\Thunder\Components\Tips\XLSkin.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 2] [d:\Thunder\Components\VPSHELL\VPSHELL.dll] [迅雷网络, 4, 0, 0, 38] [d:\Thunder\Components\UserExperience\UserExperience.dll] [Thunder Networking Technologies,LTD, 1, 0, 3, 5] [d:\Thunder\Components\ResWorker\DsXlCom.dll] [, 1, 0, 0, 30] [d:\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [d:\Thunder\Components\ResWorker\MediaWorker.dll] [Thunder Networking Technologies,LTD, 1, 2, 0, 22] [d:\Thunder\Components\DownloadStat\DownloadStat.dll] [Thunder Networking Technologies,LTD, 1, 4, 1, 6] [d:\Thunder\Program\emule_id.dll] [, 1, 0, 2, 12] [d:\Thunder\Components\Tips\XLIPC.DLL] [Thunder Networking Technologies,LTD, 1, 0, 0, 2] [d:\Thunder\Program\bd.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 20] [PID: 1472 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [D:\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1005] [PID: 1412 / Administrator][D:\Spyware Doctor\pctsTray.exe] [PC Tools, 6.0.0.13] [D:\Spyware Doctor\rtl100.bpl] [CodeGear, 11.0.2902.10471] [D:\Spyware Doctor\vcl100.bpl] [CodeGear, 11.0.2902.10471] [D:\Spyware Doctor\SysAccess.dll] [PC Tools, 6.0.0.1] [D:\Spyware Doctor\ikdll.dll] [PCTools Research Pty Ltd., 5.0.2.1041 built by: WinDDK] [D:\Spyware Doctor\CommOM.dll] [PC Tools, 6.0.0.13] [D:\Spyware Doctor\CommLib.dll] [PC Tools, 6.0.0.0] [D:\Spyware Doctor\PCToolsComponents.bpl] [PC Tools, 6.0.0.0] [D:\Spyware Doctor\sdinfo.sdp] [PC Tools, 6.0.0.7] [D:\Spyware Doctor\cdialogs.dll] [PC Tools, 6.0.0.6] [D:\Spyware Doctor\pwindow.dll] [PC Tools, 6.0.0.2] [D:\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1005] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 1920 / Administrator][D:\Spyware Doctor\pctsGui.exe] [PC Tools, 6.0.0.386] [D:\Spyware Doctor\rtl100.bpl] [CodeGear, 11.0.2902.10471] [D:\Spyware Doctor\vcl100.bpl] [CodeGear, 11.0.2902.10471] [D:\Spyware Doctor\CommOM.dll] [PC Tools, 6.0.0.13] [D:\Spyware Doctor\SysAccess.dll] [PC Tools, 6.0.0.1] [D:\Spyware Doctor\ikdll.dll] [PCTools Research Pty Ltd., 5.0.2.1041 built by: WinDDK] [D:\Spyware Doctor\CommLib.dll] [PC Tools, 6.0.0.0] [D:\Spyware Doctor\PCToolsComponents.bpl] [PC Tools, 6.0.0.0] [D:\Spyware Doctor\sdinfo.sdp] [PC Tools, 6.0.0.7] [D:\Spyware Doctor\cdialogs.dll] [PC Tools, 6.0.0.6] [D:\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1005] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258] [PID: 644 / Administrator][C:\Documents and Settings\Administrator\桌面\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210] [PID: 236 / Administrator][C:\Documents and Settings\Administrator\桌面\sreng2\SRE7f32c210.EXE] [Smallfrogs Studio, 2.7.0.1210] [D:\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1005] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\Documents and Settings\Administrator\桌面\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [C:\WINDOWS\system32\TcpIpDog0.dll] [N/A, ] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258] ================================== 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\system32\winhlp32.exe %1] .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 MSAFD Tcpip [TCP/IP] C:\WINDOWS\system32\TcpIpDog0.dll(, N/A) MSAFD Tcpip [UDP/IP] C:\WINDOWS\system32\TcpIpDog0.dll(, N/A) MSAFD Tcpip [RAW/IP] C:\WINDOWS\system32\TcpIpDog0.dll(, N/A) RSVP UDP Service Provider C:\WINDOWS\system32\TcpIpDogR0.dll(, N/A) RSVP TCP Service Provider C:\WINDOWS\system32\TcpIpDogR0.dll(, N/A) ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 v.onondown.com.cn 127.0.0.2 ymsdasdw1.cn 127.0.0.3 h96b.info 127.0.0.0 fuck.zttwp.cn 127.0.0.0 www.hackerbf.cn 127.0.0.0 ww.popdm.cn 127.1.1.1 bbt.etimes888.com 127.0.0.0 zzz.2008wyt.net 127.1.1.1 999.2005wyt.com 127.1.1.1 219.147.13.53 127.1.1.1 20068080.cn 127.1.1.1 l.neter888.cn 127.1.1.1 stat.untang.com 127.1.1.1 www.ikdy.cn 127.0.0.0 geekbyfeng.cn 127.0.0.0 121.14.101.68 127.0.0.0 ppp.etimes888.com 127.0.0.0 www.bypk.com 127.0.0.0 CSC3-2004-crl.verisign.com 127.0.0.1 va9sdhun23.cn 127.0.0.0 udp.hjob123.com 127.1.1.1 999.hfdy2828.com 127.1.1.1 www.hfdy2929.com 127.1.1.1 www.xiazaide1.cn 127.1.1.1 www.vuf51579.cn 127.1.1.1 wm.eo2q.cn 127.1.1.1 d.www-263.com 127.1.1.1 www.ssy1688.cn 127.1.1.1 121.12.173.218 127.1.1.1 qq.18i16.net 127.1.1.1 a.baidu-6661.com 127.1.1.1 www.vuf51579.cn 127.1.1.1 www.1079223105.cn 127.1.1.1 home.xzx6.cn 127.1.1.1 top.fgc3.cn 127.1.1.1 165.246.44.228 127.1.1.1 wwww.ttfafa.com 127.1.1.1 pa.tt-09.com 127.0.0.2 bnasnd83nd.cn 127.0.0.0 www.gamehacker.com.cn 127.0.0.0 gamehacker.com.cn 127.1.1.1 www.cctv-100008.cn 127.1.1.1 222.73.208.141 127.0.0.3 adlaji.cn 127.1.1.1 aiyyw.com 127.0.0.1 858656.com 127.1.1.1 bnasnd83nd.cn 127.0.0.1 my123.com 127.0.0.0 user1.12-27.net 127.0.0.1 8749.com 127.0.0.0 fengent.cn 127.0.0.1 4199.com 127.0.0.1 user1.16-22.net 127.0.0.1 7379.com 127.0.0.1 2be37c5f.3f6e2cc5f0b.com 127.0.0.1 7255.com 127.0.0.1 user1.23-12.net 127.0.0.1 3448.com 127.0.0.1 www.guccia.net 127.0.0.1 7939.com 127.0.0.1 a.o1o1o1.nEt 127.0.0.1 8009.com 127.0.0.1 user1.12-73.cn 127.0.0.1 piaoxue.com 127.0.0.1 3n8nlasd.cn 127.0.0.1 kzdh.com 127.0.0.0 www.sony888.cn 127.0.0.1 about.blank.la 127.0.0.0 user1.asp-33.cn 127.0.0.1 6781.com 127.0.0.0 www.netkwek.cn 127.0.0.1 7322.com 127.0.0.0 ymsdkad6.cn 127.0.0.1 localhost 127.0.0.0 www.lkwueir.cn 127.0.0.1 06.jacai.com 127.0.1.1 user1.23-17.net 127.0.0.1 1.jopenkk.com 127.0.0.0 upa.luzhiai.net 127.0.0.1 1.jopenqc.com 127.0.0.0 www.guccia.net 127.0.0.1 1.joppnqq.com 127.0.0.0 4m9mnlmi.cn 127.0.0.1 1.xqhgm.com 127.0.0.0 mm119mkssd.cn 127.0.0.1 100.332233.com 127.0.0.0 61.128.171.115:8080 127.0.0.1 121.11.90.79 127.0.0.0 www.1119111.com 127.0.0.1 121565.net 127.0.0.0 win.nihao69.cn 127.0.0.1 125.90.88.38 127.0.0.1 16888.6to23.com 127.0.0.1 2.joppnqq.com 127.0.0.0 puc.lianxiac.net 127.0.0.1 204.177.92.68 127.0.0.0 pud.lianxiac.net 127.0.0.1 210.74.145.236 127.0.0.0 210.76.0.133 127.0.0.1 219.129.239.220 127.0.0.0 61.166.32.2 127.0.0.1 219.153.40.221 127.0.0.0 218.92.186.27 127.0.0.1 219.153.46.27 127.0.0.0 www.fsfsfag.cn 127.0.0.1 219.153.52.123 127.0.0.0 ovo.ovovov.cn 127.0.0.1 221.195.42.71 127.0.0.0 dw.com.com 127.0.0.1 222.73.218.115 127.0.0.1 203.110.168.233:80 127.0.0.1 3.joppnqq.com 127.0.0.1 203.110.168.221:80 127.0.0.1 363xx.com 127.0.0.1 www1.ip10086.com.cm 127.0.0.1 4199.com 127.0.0.1 blog.ip10086.com.cn 127.0.0.1 43242.com 127.0.0.1 www.ccji68.cn 127.0.0.1 5.xqhgm.com 127.0.0.0 t.myblank.cn 127.0.0.1 520.mm5208.com 127.0.0.0 x.myblank.cn 127.0.0.1 59.34.131.54 127.0.0.1 210.51.45.5 127.0.0.1 59.34.198.228 127.0.0.1 www.ew1q.cn 127.0.0.1 59.34.198.88 127.0.0.1 59.34.198.97 127.0.0.1 60.190.114.101 127.0.0.1 60.190.218.34 127.0.0.0 qq-xing.com.cn 127.0.0.1 60.191.124.252 127.0.0.1 61.145.117.212 127.0.0.1 61.157.109.222 127.0.0.1 75.126.3.216 127.0.0.1 220.250.64.21 127.0.0.1 75.126.3.217 127.0.0.1 75.126.3.218 127.0.0.0 59.125.231.177:17777 127.0.0.1 75.126.3.220 127.0.0.1 75.126.3.221 127.0.0.1 75.126.3.222 127.0.0.1 772630.com 127.0.0.1 832823.cn 127.0.0.1 8749.com 127.0.0.1 888.jopenqc.com 127.0.0.1 89382.cn 127.0.0.1 8v8.biz 127.0.0.1 97725.com 127.0.0.1 9gg.biz 127.0.0.1 www.9000music.com 127.0.0.1 test.591jx.com 127.0.0.1 a.topxxxx.cn 127.0.0.1 picon.chinaren.com 127.0.0.1 www.5566.net 127.0.0.1 p.qqkx.com 127.0.0.1 news.netandtv.com 127.0.0.1 z.neter888.cn 127.0.0.1 b.myblank.cn 127.0.0.1 wvw.wokutu.com 127.0.0.1 unionch.qyule.com 127.0.0.1 www.qyule.com 127.0.0.1 it.itjc.cn 127.0.0.1 www.linkwww.com 127.0.0.1 vod.kaicn.com 127.0.0.1 www.tx8688.com 127.0.0.1 b.neter888.cn 127.0.0.1 promote.huanqiu.com 127.0.0.1 www.huanqiu.com 127.0.0.1 www.haokanla.com 127.0.0.1 play.unionsky.cn 127.0.0.1 www.52v.com 127.0.0.1 www.gghka.cn 127.0.0.1 icon.ajiang.net 127.0.0.1 new.ete.cn 127.0.0.1 www.stiae.cn 127.0.0.1 o.neter888.cn 127.0.0.1 comm.jinti.com 127.0.0.1 www.google-analytics.com 127.0.0.1 hz.mmstat.com 127.0.0.1 www.game175.cn 127.0.0.1 x.neter888.cn 127.0.0.1 z.neter888.cn 127.0.0.1 p.etimes888.com 127.0.0.1 hx.etimes888.com 127.0.0.1 abc.qqkx.com 127.0.0.1 dm.popdm.cn 127.0.0.1 www.yl9999.com 127.0.0.1 www.dajiadoushe.cn 127.0.0.1 v.onondown.com.cn 127.0.0.1 www.interoo.net 127.0.0.1 bally1.bally-bally.net 127.0.0.1 www.bao5605509.cn 127.0.0.1 www.rty456.cn 127.0.0.1 www.werqwer.cn 127.0.0.1 1.360-1.cn 127.0.0.1 user1.23-16.net 127.0.0.1 www.guccia.net 127.0.0.1 www.interoo.net 127.0.0.1 upa.netsool.net 127.0.0.1 js.users.51.la 127.0.0.1 vip2.51.la 127.0.0.1 web.51.la 127.0.0.1 qq.gong2008.com 127.0.0.1 2008tl.copyip.com 127.0.0.1 tla.laozihuolaile.cn 127.0.0.1 www.tx6868.cn 127.0.0.1 p001.tiloaiai.com 127.0.0.1 s1.tl8tl.com 127.0.0.1 s1.gong2008.com 127.0.0.1 4b3ce56f9g.3f6e2cc5f0b.com 127.0.0.1 2be37c5f.3f6e2cc5f0b.com ================================== 进程特权扫描 特殊特权被允许: SeSystemtimePrivilege [PID = 328, D:\PROGRAM FILES\DR.COM\DR.COM客户端.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 328, D:\PROGRAM FILES\DR.COM\DR.COM客户端.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 328, D:\PROGRAM FILES\DR.COM\DR.COM客户端.EXE] 特殊特权被允许: SeSystemtimePrivilege [PID = 1964, C:\PROGRAM FILES\THE WORLD 2.1\THEWORLD.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 1964, C:\PROGRAM FILES\THE WORLD 2.1\THEWORLD.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1964, C:\PROGRAM FILES\THE WORLD 2.1\THEWORLD.EXE] 特殊特权被允许: SeSystemtimePrivilege [PID = 644, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\SRENG2\SRENGLDR.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 644, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\SRENG2\SRENGLDR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 644, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\SRENG2\SRENGLDR.EXE] ================================== 计划任务 N/A ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]