[CODE] 2009-05-10,09:47:02 System Repair Engineer 2.7.1.1261 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Component Publisher] [File is missing] [(Verified)"Alibaba Software(Shanghai)Co,. Ltd"] [(Verified)Google Inc] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [NVIDIA Corporation] <"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice> [(Verified)"ESET, spol. s r.o."] <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd] <360Safetray> [(Verified)Qizhi Software (beijing) Co. Ltd] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AEB6717E-7E19-11d0-97EE-00C04FD91972}> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy] <%SystemRoot%\System32\dimsntfy.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <浏览器自定义组件> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] <%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Component Publisher] [HKEY_CURRENT_USER\Control Panel\Desktop] [(Verified)Microsoft Windows Component Publisher] ================================== 启动文件夹 [QQ游戏启动加速程序] C:\PROGRA~1\Tencent\QQGAME\Accel.exe [深圳市腾讯计算机系统有限公司]> ================================== 服务 [Eset HTTP Server / EhttpSrv][Stopped/Manual Start] <"C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe"> [Eset Service / ekrn][Running/Auto Start] <"C:\Program Files\ESET\ESET Smart Security\ekrn.exe"> [Google Updater Service / gusvc][Stopped/Manual Start] <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><(File is missing)> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [Network Location Awareness (NLA) / Nla][Running/Manual Start] %SystemRoot%\System32\mswsock.dll> [NVIDIA Display Driver Service / NVSvc][Running/Auto Start] ================================== 驱动程序 [360procmon / 360procmon][Running/Manual Start] <\??\C:\Program Files\360safe\safemon\360procmon.sys><> [ADMtek ADM8511/AN986 USB To Fast Ethernet Converter / ADM8511][Stopped/Manual Start] [AMD Processor Driver / AmdK8][Running/System Start] [Broadcom 802.11 网络适配器驱动程序 / BCM43XX][Stopped/Manual Start] [eabfiltr / eabfiltr][Stopped/Manual Start] [eamon / eamon][Running/Auto Start] [ehdrv / ehdrv][Running/System Start] [epfw / epfw][Running/Auto Start] [Eset Personal Firewall / Epfwndis][Running/Manual Start] [epfwtdi / epfwtdi][Running/System Start] [Creative AudioPCI (ES1371,ES1373) (WDM) / es1371][Stopped/Manual Start] [HBtnKey / HBtnKey][Running/Manual Start] [Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService][Running/Manual Start] [Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start] [nv / nv][Running/Manual Start] [NVIDIA nForce Networking Controller Driver / NVENETFD][Running/Manual Start] [NVIDIA Network Bus Enumerator / nvnetbus][Running/Manual Start] [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start] <\SystemRoot\system32\DRIVERS\nvrd32.sys> [nvsmu / nvsmu][Running/Manual Start] [AMD PCNET Compatable Adapter Driver / PCnet][Stopped/Manual Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [SafeBoxKrnl / SafeBoxKrnl][Running/System Start] <\??\C:\WINDOWS\system32\drivers\SafeBoxKrnl.sys><360安全中心> [Secdrv / Secdrv][Stopped/Manual Start] [SATALink driver accelerator / SiFilter][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SiWinAcc.sys> [TCP/IP Protocol Driver / Tcpip][Running/System Start] [Conexant Setup API / UIUSys][Stopped/Manual Start] [viamraid / viamraid][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\viamraid.sys> ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [SearchHook Class] {635A7AFA-FB22-4A4E-8AB8-C85CFAB14626} <, > [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [Google Toolbar Helper] {AA58ED58-01DD-4d91-8333-CF10577473F7} [Google Toolbar Notifier BHO] {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [Google Dictionary Compression sdch] {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} [PPLive] {95B3F550-91C4-4627-BCC4-521288C52977} [很快视频搜索] {998A88A0-A355-809B-831C-B83A80000991} [启动UUSee 网络电视] {998A88A0-A355-809B-831C-B83A80000992} [] {e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, (Signed) N/A> [Google Toolbar] {2318C2B1-4965-11d4-9B18-009027A5CD4F} [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [Google Toolbar] {2318C2B1-4965-11D4-9B18-009027A5CD4F} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [WangWangX Class] {5D09DD40-CDC4-4C56-B615-0D1E3B357C2B} [SearchHook Class] {635A7AFA-FB22-4A4E-8AB8-C85CFAB14626} <, > [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [] {95B3F550-91C4-4627-BCC4-521288C52977} <, > [] {998A88A0-A355-809B-831C-B83A80000991} <, > [] {998A88A0-A355-809B-831C-B83A80000992} <, > [Google Toolbar Helper] {AA58ED58-01DD-4D91-8333-CF10577473F7} [Google Toolbar Notifier BHO] {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [Google Dictionary Compression sdch] {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [] {E2E2DD38-D088-4134-82B7-F2BA38496583} <, > [UPlayer Control] {EAB7A1CC-C77B-45E5-9AC2-AD037D047BCC} [使用UUSee下载] [使用UUSee加速播放] [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] [添加到QQ表情] ================================== 正在运行的进程 [PID: 856 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 904 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 932 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 976 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)] [PID: 988 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [PID: 1152 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 1200 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [PID: 1324 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [c:\windows\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\System32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 1420 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [c:\windows\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [PID: 1512 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [PID: 1740 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\E_FLB8WP.DLL] [SEIKO EPSON CORPORATION, 2, 4, 0, 0] [C:\WINDOWS\System32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [PID: 1880 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\FreeLaunchBar\flb.dll] [TrueSoft, 1.0.0.0] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1007] [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\Program Files\AliWangWang\AliIMExt.dll] [Alibaba software (Shanghai) Corporation., 1.0.0.1] [C:\Program Files\ESET\ESET Smart Security\shellExt.dll] [ESET, 4.0.68 BETA] [PID: 176 / Administrator][C:\Program Files\ESET\ESET Smart Security\egui.exe] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\MFC80U.DLL] [Microsoft Corporation, 8.00.50727.762] [C:\Program Files\ESET\ESET Smart Security\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\ESET\ESET Smart Security\eguiScan.dll] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\eguiAmon.dll] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\eguiEmon.dll] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\eguiDmon.dll] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\eguiEpfw.dll] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\eguiSmon.dll] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\eguiUpdate.dll] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\eguiMailPlugins.dll] [ESET, 4.0.68 BETA] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1007] [C:\WINDOWS\System32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [PID: 208 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 228 / Administrator][C:\Program Files\AliWangWang\aliim.exe] [Alibaba software (Shanghai) Corporation., 1, 0, 0, 1] [C:\Program Files\AliWangWang\ATL80.DLL] [Microsoft Corporation, 8.00.50727.762] [C:\Program Files\AliWangWang\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\Program Files\AliWangWang\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\Program Files\AliWangWang\RvCore.DLL] [AliSoft, 1.0.0.1] [C:\Program Files\AliWangWang\logger.dll] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\AliWangWang\uicontrols\UiBrowser.dll] [TODO: <公司名>, 1.0.0.1] [C:\Program Files\AliWangWang\GUIBase.dll] [N/A, ] [C:\Program Files\AliWangWang\wwutils.DLL] [Alibaba software (Shanghai) Corporation., 1.0.0.1] [C:\Program Files\AliWangWang\wwparams.dll] [N/A, ] [C:\Program Files\AliWangWang\uicontrols\WWUIUnits.dll] [N/A, ] [C:\Program Files\AliWangWang\uicontrols\rvnw.dll] [N/A, ] [C:\Program Files\AliWangWang\uicontrols\rvwindow.dll] [N/A, ] [C:\Program Files\AliWangWang\UpdateAssist.dll] [N/A, ] [C:\Program Files\AliWangWang\xparam.dll] [N/A, ] [C:\Program Files\AliWangWang\imbiz.dll] [Alibaba software (Shanghai) Corporation., 1.0.0.1] [C:\Program Files\AliWangWang\protocol.dll] [N/A, ] [C:\Program Files\AliWangWang\imnet.dll] [Alibaba software (Shanghai) Corporation., 1.0.0.1] [C:\Program Files\AliWangWang\GUICore.dll] [TODO: <公司名>, 1.0.0.1] [C:\Program Files\AliWangWang\WWApplication.dll] [Alibaba software (Shanghai) Corporation., 1.0.0.1] [C:\Program Files\AliWangWang\imdb.dll] [Alibaba software (Shanghai) Corporation., 1.0.0.1] [C:\Program Files\AliWangWang\rvcomlib.dll] [Alibaba software (Shanghai) Corporation., 1.0.0.1] [C:\Program Files\AliWangWang\wwsdkcom.dll] [Alibaba software (Shanghai) Corporation., 1.0.0.1] [C:\Program Files\AliWangWang\wwsdk.dll] [Alibaba software (Shanghai) Corporation., 1, 0, 0, 1000] [C:\WINDOWS\system32\aliedit\aliedit.dll] [, 2, 1, 2, 3] [C:\Program Files\AliWangWang\SysNotify.dll] [Alibaba software (Shanghai) Corporation., 1.0.0.1] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\System32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\Program Files\AliWangWang\alinet.dll] [N/A, ] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1007] [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\jscript.dll] [Microsoft Corporation, 5.7.0.18066] [C:\Program Files\AliWangWang\LIBEAY32.dll] [The OpenSSL Project, http://www.openssl.org/, 0.9.8e] [C:\Program Files\AliWangWang\filetransbiz.dll] [Alibaba software (Shanghai) Corporation., 1.0.0.4] [C:\Program Files\AliWangWang\ww_network2.dll] [Alibaba software (Shanghai) Corporation., 2, 1, 0, 4] [C:\Program Files\AliWangWang\P2PBiz.dll] [Alibaba software (Shanghai) Corporation., 1, 0, 0, 1] [C:\Program Files\AliWangWang\wwimport.dll] [Alibaba software (Shanghai) Corporation., 1.0.0.1] [C:\Program Files\AliWangWang\plugins\8001\YahooEmail.dll] [N/A, ] [C:\Program Files\AliWangWang\plugins\8003\GraffitiGUI.dll] [Alibaba software (Shanghai) Corporation., 1.0.0.0] [C:\Program Files\AliWangWang\plugins\11460\wwMailer.dll] [21builder, 1.00.0004] [C:\Program Files\AliWangWang\plugins\17411\WWKWPlugin.dll] [酷我科技, 1.0.0.1] [C:\Program Files\AliWangWang\zlibwapi.dll] [, 1.2.1.0] [C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx] [Adobe Systems, Inc., 10,0,22,87] [PID: 292 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 4, 1, 509, 1944] [C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\gtn.dll] [Google Inc., 5, 1, 1309, 3572] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll] [Google Inc., 5, 1, 1309, 3572] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1007] [PID: 384 / Administrator][C:\Program Files\AliWangWang\AliUpdate.exe] [Alibaba software (Shanghai) Corporation., 1.0.0.1] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\System32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [PID: 132 / SYSTEM][C:\Program Files\ESET\ESET Smart Security\ekrn.exe] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\Program Files\ESET\ESET Smart Security\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\Program Files\ESET\ESET Smart Security\ekrnScan.dll] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\ekrnAmon.dll] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\ekrnEmon.dll] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\ekrnDmon.dll] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\ekrnEpfw.dll] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\ekrnSmon.dll] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\ekrnUpdate.dll] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\updater.dll] [ESET, 4.0.68 BETA] [C:\Program Files\ESET\ESET Smart Security\ekrnMailPlugins.dll] [ESET, 4.0.68 BETA] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [PID: 1308 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.11.7431] [C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.7431] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 1560 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)] [PID: 2140 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\MSWSOCK.DLL] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 2484 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 2540 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1007] [C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll] [Google Inc., 6, 1, 1518, 856] [C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_6D0D6FD66D664927.dll] [Google Inc., 6, 1, 1518, 856] [C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_zh-TW_AB21B6B290BAC0C6.dll] [Google Inc., 6, 1, 1518, 856] [C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll] [Google Inc., 5, 1, 1309, 3572] [C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll] [Google Inc., 1, 0, 610, 27482] [C:\WINDOWS\system32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\jscript.dll] [Microsoft Corporation, 5.7.0.18066] [C:\WINDOWS\system32\vbscript.dll] [Microsoft Corporation, 5.7.0.18066] [C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx] [Adobe Systems, Inc., 10,0,22,87] [PID: 344 / Administrator][C:\Program Files\AliWangWang\plugins\11460\wwMail.exe] [苏晓璐, 2.0.0.18] [C:\Program Files\AliWangWang\plugins\11460\pcre.dll] [RenatoMancuso.com, 4, 5, 0, 0] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1007] [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [PID: 2176 / Administrator][C:\Program Files\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5.8.2.515] [C:\Program Files\Thunder\Program\BugReport.dll] [Thunder Networking Technologies,LTD, 1, 5, 1, 22] [C:\Program Files\Thunder\Program\ThunderEx.dll] [, 1, 2, 5, 24] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1007] [C:\Program Files\Thunder\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 3, 6, 66] [C:\Program Files\Thunder\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 3, 1, 2, 315] [C:\Program Files\Thunder\Program\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Thunder\Program\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Thunder\Program\asyn_frame.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 17] [C:\WINDOWS\system32\MSWSOCK.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\Program Files\Thunder\Program\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Thunder\Program\emule_id.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 7] [C:\Program Files\Thunder\Program\backend_agent.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 19] [C:\Program Files\Thunder\Program\ptl.dll] [Thunder Networking Technologies,LTD, 3, 1, 2, 22] [C:\Program Files\Thunder\Program\xl_stat.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 3] [C:\Program Files\Thunder\Program\fs.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 10] [C:\Program Files\Thunder\Program\XLNet.Dll] [Thunder Networking Technologies,LTD, 1, 5, 1, 24] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\Program Files\Thunder\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 1, 1, 10] [C:\Program Files\Thunder\Components\DownAndPlay\DownAndPlay.dll] [, 1, 0, 12, 30] [C:\Program Files\Thunder\Program\emule.dll] [, 1, 1, 2, 12] [C:\Program Files\Thunder\Program\down_dispatcher.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 17] [C:\Program Files\Thunder\Program\p2p_upload.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 8] [C:\Program Files\Thunder\Program\p2sp.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 25] [C:\Program Files\Thunder\Program\iTargetAD.dll] [N/A, ] [C:\Program Files\Thunder\Program\p2p.dll] [Thunder Networking Technologies,LTD, 1,1,2,24] [C:\Program Files\Thunder\Program\xldc.dll] [Thunder Networking Technologies,LTD, 3, 6, 2, 15] [C:\Program Files\Thunder\Program\stream.dll] [Thunder Networking Technologies,LTD, 2, 1, 2, 375] [C:\Program Files\Thunder\Program\p2p_local_res.dll] [Thunder Networking Technologies,LTD, 1,1,2,12] [C:\Program Files\Thunder\Program\al.dll] [Thunder Networking Technologies,LTD, 1,1,2,15] [C:\Program Files\Thunder\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 2, 3, 0, 59] [C:\Program Files\Thunder\Program\XLCommunityEx.dll] [N/A, ] [C:\Program Files\Thunder\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 17, 0, 67] [C:\Program Files\Thunder\Program\MSVCIRT.dll] [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Thunder\Program\imdt.dll] [TODO: , 1.0.2.5] [C:\Program Files\Thunder\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 1, 6, 21] [C:\Program Files\Thunder\Plugins\GouGouTop\GouGouTop.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 5] [C:\Program Files\Thunder\Components\ExplorerHelper\ExplorerHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 19] [C:\Program Files\Thunder\ComDlls\ThunderAgent_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 4, 23] [C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [C:\Program Files\Thunder\Components\DownloadStat\DownloadStat.dll] [Thunder Networking Technologies,LTD, 1, 4, 1, 6] [C:\Program Files\Thunder\Program\bd.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 17] [PID: 3068 / Administrator][C:\Documents and Settings\Administrator\桌面\SREngLdr.EXE] [Smallfrogs Studio, 2.7.1.1261] [PID: 3088 / Administrator][C:\Documents and Settings\Administrator\桌面\SREcec25149.EXE] [Smallfrogs Studio, 2.7.1.1261] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1007] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\Documents and Settings\Administrator\桌面\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [C:\WINDOWS\System32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 MSAFD Tcpip [TCP/IP] C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD Tcpip [UDP/IP] C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD Tcpip [RAW/IP] C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{56645FC8-E8C1-429B-AE04-CAC19104A2A3}] SEQPACKET 7 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{56645FC8-E8C1-429B-AE04-CAC19104A2A3}] DATAGRAM 7 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{BEF9D5CB-6A0F-4ACD-B3A1-C74C7089FE44}] SEQPACKET 6 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{BEF9D5CB-6A0F-4ACD-B3A1-C74C7089FE44}] DATAGRAM 6 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{652F2B8E-9D21-4ABB-A8B8-4F6E03D47C2F}] SEQPACKET 3 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{652F2B8E-9D21-4ABB-A8B8-4F6E03D47C2F}] DATAGRAM 3 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{485B3247-EABF-4E88-913A-13179C9ED56E}] SEQPACKET 0 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{485B3247-EABF-4E88-913A-13179C9ED56E}] DATAGRAM 0 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{F6C60E97-F8D3-4E62-9FA2-A9D685B07D97}] SEQPACKET 1 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{F6C60E97-F8D3-4E62-9FA2-A9D685B07D97}] DATAGRAM 1 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{90284CC5-9E19-496E-A350-36F5EAF0B47E}] SEQPACKET 2 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{90284CC5-9E19-496E-A350-36F5EAF0B47E}] DATAGRAM 2 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{966DE22B-8951-4ED2-8B3C-43498E53F0CA}] SEQPACKET 4 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{966DE22B-8951-4ED2-8B3C-43498E53F0CA}] DATAGRAM 4 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{49D28C3E-A589-4C8F-9178-AAFEBA370C4E}] SEQPACKET 5 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{49D28C3E-A589-4C8F-9178-AAFEBA370C4E}] DATAGRAM 5 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 127.0.0.1 858656.com 127.0.0.1 my123.com 127.0.0.1 8749.com 127.0.0.1 4199.com 127.0.0.1 7379.com 127.0.0.1 7255.com 127.0.0.1 3448.com 127.0.0.1 7939.com 127.0.0.1 8009.com 127.0.0.1 piaoxue.com 127.0.0.1 kzdh.com 127.0.0.1 about.blank.la 127.0.0.1 6781.com 127.0.0.1 7322.com 127.0.0.1 9991.com ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 1308, C:\WINDOWS\SYSTEM32\NVSVC32.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 344, C:\PROGRAM FILES\ALIWANGWANG\PLUGINS\11460\WWMAIL.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2176, C:\PROGRAM FILES\THUNDER\PROGRAM\THUNDER5.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3068, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\SRENGLDR.EXE] ================================== 计划任务 N/A ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]