[CODE] 2009-09-08,18:19:30 System Repair Engineer 2.8.1.1279 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 Windows 安全更新检查 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Component Publisher] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] [(Verified)Adobe Systems Incorporated] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce] [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [(Infected) Microsoft Corporation] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] [File is missing] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AEB6717E-7E19-11d0-97EE-00C04FD91972}> [(Verified)Microsoft Windows Component Publisher] <{E3531A16-FFEA-416F-82DF-32FEDE02EABF}> [] <{AB8105BD-1B1B-40F3-8D3D-65FD7FC68CC5}> [] <{610B6886-2A1A-475A-A842-65A613C70460}> [] <{076FB645-17A5-4DE6-B23E-C90FAB741CB0}> [] <{765BA0B5-EBE4-4B1A-AFDA-5683606F626C}> [] <{B7D59563-AD35-4D2B-B174-7A61A0BC829B}> [] <{737858A9-9AEA-4838-9B49-54DA731F7F37}> [] <{CF2C613A-A0D9-4E5C-B1BB-6B03B269B054}> [] <{8A392489-BA80-4EE4-B4CB-B4F8516C307C}> [] <{A600E212-2A41-41BC-92F1-ED5C96B06185}> [] <{1E8C47B0-214A-45E5-868B-DA35C54B30F6}> [] <{51716C09-6B08-4CCF-B526-718E912C0573}> [] <{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}> [] <{87DE8A1A-96C5-4420-B222-EF998F697CE7}> [] <{5405A7B2-F3F5-446F-8715-2A4EF674E079}> [] <{704C3595-DB85-40F6-A601-8D6F346907BD}> [] <{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}> [] <{8708994F-1758-4C2C-9A3F-FA22D6CCCB41}> [] <{36AC68E6-0C26-4D39-B98E-54B49DAB6BAA}> [] <{CD478099-014D-4B3A-A4BB-B518F1019BC7}> [] <{76CBCF38-0583-44C7-A1AE-D463DFE625EC}> [] <{5B0C7E2C-3257-4619-8282-A173017B16E2}> [] <{93DA1E7D-7C46-4F90-8674-EC90511FCA72}> [] <{23DA65D2-C696-4EE4-BEE8-B4841DEC3E30}> [] <{2EF0D734-21FD-4225-A1A2-BCD296182AAF}> [] <{E5608703-D625-410D-B97E-6AB2D40D1A9F}> [] <{CE38B9E6-AF0C-4B93-AFAB-A20C2311FFD0}> [] <{1719B301-B494-4185-9379-242461F9CF02}> [] <{C5CB6C70-7185-4466-AB45-B1C34E7A37CA}> [] <{A5CA6C70-7185-4466-AB45-B1C34E7A37CA}> [] <{BE12C98F-645D-4566-B524-DC32040B7C8A}> [] <{ECC00636-8C3B-4D8D-B271-AAA6DF9505CD}> [] <{B9D0F4D7-C809-4C27-9CB4-63201DFB3D05}> [] <{41D2953A-CB90-485A-8673-6975088309F7}> [] <{93F33500-527E-4E33-AECA-69B15243A90E}> [] <{81BC0740-6E31-4BA4-81C8-EFF9ECEB3BA2}> [] <{72236771-3891-46BF-B185-1D816A09333F}> [] <{E9C84B05-22D2-4820-99B0-4AAAA7CD6A5D}> [] <{44F0085F-F868-4528-B15A-378BBAE66523}> [] <{7938BD2F-0143-4C46-991C-71069712D9D9}> [] <{7BCD75AC-7DF8-4B42-9B00-4FEA1CE14755}> [] <{24144CB8-10ED-4BFC-843F-68A9F3369947}> [] <{C1B34818-3883-4A0A-9665-189A8A39EAB0}> [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy] <%SystemRoot%\System32\dimsntfy.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <浏览器自定义组件> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] <%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360hotfix.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Safebox.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apvxdwin.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avengine.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avguard.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avltmain.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp32.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avtask.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdagent.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdwizreg.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\boxmod.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccapp.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccEvtMgr.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccregvfy.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSetMgr.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cqw32.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DrvAnti.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\enc98.EXE] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\extdb.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\frameworkservice.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\frwstub.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardfield.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kaccore.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kissvc.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\knownsvr.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvfw.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvmonxp.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvprescan.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\livesrv.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcagent.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcdash.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcdetect.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Mcshield.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mctskshd.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsescn.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsshld.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mghtml.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\naprdmgr.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navw32.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\oasclnt.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsrv51.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psctrls.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psimreal.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psimsvc.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwproxy.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rsmain.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rsnetsvr.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rssafety.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsTray.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safebank.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxTray.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ScanFrm.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sched.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\seccenter.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\secnotifier.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SetupLD.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shstat.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sndsrvc.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spbbcsvc.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbmon.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ulibcfg.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\updaterui.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vcr32.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vptray.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsserv.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vstskmgr.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webproxy.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xcommsvr.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xnlscn.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\修复工具.] [N/A] [HKEY_CURRENT_USER\Control Panel\Desktop] [] ================================== 启动文件夹 N/A ================================== 服务 [Contrl Center of Storm Media / ccosm][Stopped/Disabled] <北京暴风网际科技有限公司> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [6to4 / 6to4][Stopped/Auto Start] C:\WINDOWS\system32\6to4.dll> ================================== 驱动程序 [ADI UAA Function Driver for High Definition Audio Service / ADIHdAudAddService][Stopped/Manual Start] [AE Audio Service / AEAudio][Stopped/Manual Start] [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start] [AMD AGP Bus Filter Driver / amdagp][Running/Boot Start] <\SystemRoot\system32\DRIVERS\amdagp.sys> [Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Stopped/Manual Start] [hptpro / hptpro][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\hptpro.sys> [ialm / ialm][Running/Manual Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Running/Manual Start] [Secdrv / Secdrv][Stopped/Manual Start] [SenFilt Service / SenFiltService][Stopped/Manual Start] [SATALink driver accelerator / SiFilter][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SiWinAcc.sys> [SATALink External Device Filter / SiRemFil][Running/Boot Start] <\SystemRoot\system32\DRIVERS\SiRemFil.sys> [SIS AGP Bus Filter / sisagp][Running/Boot Start] <\SystemRoot\system32\DRIVERS\sisagp.sys> [TCP/IP Protocol Driver / Tcpip][Running/System Start] [vb / vb][Running/Manual Start] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~97171.dat> [WmiSvc / WmiSvc][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\WmiSvc.sys> [pcidump / pcidump][Running/Disabled] <\??\C:\WINDOWS\system32\drivers\pcidump.sys> [MintRoot / MintRoot][Running/Manual Start] <\??\C:\Program Files\Common Files\System\MintRoot.sys> ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [] {e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, (Signed) N/A> [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [360SafeLive] {87515F61-A66C-4319-A0E0-D416CB8059E3} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [] {E2E2DD38-D088-4134-82B7-F2BA38496583} <, > [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] ================================== 正在运行的进程 [PID: 556 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 620 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [PID: 652 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\COMRes.dll] [N/A, ] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [PID: 696 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [PID: 708 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [PID: 872 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\COMRes.dll] [N/A, ] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [PID: 940 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\COMRes.dll] [N/A, ] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [PID: 1032 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\System32\COMRes.dll] [N/A, ] [c:\windows\system32\6to4.dll] [N/A, ] [C:\WINDOWS\system32\emHnPuBAaF7XjuXBbdxSg.dll] [N/A, ] [C:\WINDOWS\Downloaded Program Files\ktEDQzfuNZk2SUAMgyAZz.cur] [N/A, ] [C:\WINDOWS\system32\SrNRKs5F7Rkv9hp.inf] [N/A, ] [C:\WINDOWS\system32\K7zkXuSVDPKyz63k3V.inf] [N/A, ] [C:\WINDOWS\system32\pj83ZgsqjcWUNwjrRp42tFw.dll] [N/A, ] [C:\WINDOWS\system32\3a5XTcKYzK7KZcrfRE.inf] [N/A, ] [C:\WINDOWS\system32\BMsg6pdMD4ht.dll] [N/A, ] [C:\WINDOWS\system32\rKPbzUHze58GK2VWcYUCt.inf] [N/A, ] [C:\WINDOWS\Downloaded Program Files\cPvsCcG32xgKmBUgbe4kt.cur] [N/A, ] [C:\WINDOWS\system32\sDV2mGwkejdKa74QJzsjw.inf] [N/A, ] [C:\WINDOWS\Tasks\BFe2kXdePDntQUqqjz.inf] [N/A, ] [C:\WINDOWS\system32\PERrGx5DkqSbQdwauCRQH.dll] [N/A, ] [C:\WINDOWS\system32\122B901E.dll] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\system32\rfpz9wwyy2np.dll] [N/A, ] [C:\WINDOWS\system32\704C3595.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\dhDhwS7fFW.dll] [N/A, ] [C:\WINDOWS\system32\SCEVFJRCmaB7.dll] [N/A, ] [C:\WINDOWS\system32\skcfujQ5EDN.dll] [N/A, ] [C:\WINDOWS\Downloaded Program Files\qvSPdARs5PQNKAzvezTuPcs.cur] [N/A, ] [C:\WINDOWS\system32\CDuAUVkGy9.dll] [N/A, ] [C:\WINDOWS\system32\B4yNKrEEhEerKFeeA4.inf] [N/A, ] [C:\WINDOWS\system32\ndxq9awMc.dll] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\WINDOWS\Tasks\KzuFUQHxezWBCenC2A.inf] [N/A, ] [C:\WINDOWS\system32\X5T4kV8DNmMbdRXAUx82K.inf] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.inf] [N/A, ] [C:\WINDOWS\system32\usbvmx.dll] [N/A, ] [C:\WINDOWS\system32\ed78ab9.dll] [N/A, ] [C:\WINDOWS\system32\eYNMAnskCCBQCc8Jp.dll] [N/A, ] [C:\WINDOWS\system32\Am274u6Rqq2cTzTpjCGKy.inf] [N/A, ] [C:\WINDOWS\Tasks\c2nH4numz9knY5zqnC.inf] [N/A, ] [C:\WINDOWS\system32\fRWSJda7RbSuR3jFSmMBy.inf] [N/A, ] [C:\WINDOWS\system32\cRsAQd4hw.dll] [N/A, ] [C:\WINDOWS\system32\pEcFwPj48y6DADf87r.inf] [N/A, ] [C:\WINDOWS\system32\CRZfQurd2g58gXVgHSDbNhU.inf] [N/A, ] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [C:\WINDOWS\Downloaded Program Files\6YYnDBbzHzrrmenHmv.cur] [N/A, ] [C:\WINDOWS\system32\DvpZDPd688jbuMdBxV.inf] [N/A, ] [C:\WINDOWS\system32\DMvJFcDsGe5Kccsmc6gZFjB.inf] [N/A, ] [C:\WINDOWS\Downloaded Program Files\CWWFj6tF7GvQjNsqc.cur] [N/A, ] [C:\WINDOWS\fonts\SD78dgC7hD2sktQHyAu.fon] [N/A, ] [PID: 1092 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [PID: 1208 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\COMRes.dll] [N/A, ] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [PID: 1340 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\COMRes.dll] [N/A, ] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [PID: 1624 / Administrator][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\COMRes.dll] [N/A, ] [C:\WINDOWS\system32\MSIMG32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\browselc.dll] [Microsoft Corporation, 6.00.2600.0000] [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 120] [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\Downloaded Program Files\ktEDQzfuNZk2SUAMgyAZz.cur] [N/A, ] [C:\WINDOWS\system32\SrNRKs5F7Rkv9hp.inf] [N/A, ] [C:\WINDOWS\system32\emHnPuBAaF7XjuXBbdxSg.dll] [N/A, ] [C:\WINDOWS\system32\K7zkXuSVDPKyz63k3V.inf] [N/A, ] [C:\WINDOWS\system32\pj83ZgsqjcWUNwjrRp42tFw.dll] [N/A, ] [C:\WINDOWS\system32\3a5XTcKYzK7KZcrfRE.inf] [N/A, ] [C:\WINDOWS\system32\BMsg6pdMD4ht.dll] [N/A, ] [C:\WINDOWS\Downloaded Program Files\cPvsCcG32xgKmBUgbe4kt.cur] [N/A, ] [C:\WINDOWS\Tasks\BFe2kXdePDntQUqqjz.inf] [N/A, ] [C:\WINDOWS\system32\PERrGx5DkqSbQdwauCRQH.dll] [N/A, ] [C:\WINDOWS\system32\122B901E.dll] [N/A, ] [C:\WINDOWS\system32\rfpz9wwyy2np.dll] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\system32\704C3595.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\dhDhwS7fFW.dll] [N/A, ] [C:\WINDOWS\system32\skcfujQ5EDN.dll] [N/A, ] [C:\WINDOWS\Downloaded Program Files\qvSPdARs5PQNKAzvezTuPcs.cur] [N/A, ] [C:\WINDOWS\system32\CDuAUVkGy9.dll] [N/A, ] [C:\WINDOWS\system32\B4yNKrEEhEerKFeeA4.inf] [N/A, ] [C:\WINDOWS\system32\ndxq9awMc.dll] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\WINDOWS\Tasks\KzuFUQHxezWBCenC2A.inf] [N/A, ] [C:\WINDOWS\system32\X5T4kV8DNmMbdRXAUx82K.inf] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.inf] [N/A, ] [C:\WINDOWS\system32\ed78ab9.dll] [N/A, ] [C:\WINDOWS\system32\eYNMAnskCCBQCc8Jp.dll] [N/A, ] [C:\WINDOWS\system32\Am274u6Rqq2cTzTpjCGKy.inf] [N/A, ] [C:\WINDOWS\Tasks\c2nH4numz9knY5zqnC.inf] [N/A, ] [C:\WINDOWS\system32\fRWSJda7RbSuR3jFSmMBy.inf] [N/A, ] [C:\WINDOWS\system32\cRsAQd4hw.dll] [N/A, ] [C:\WINDOWS\system32\pEcFwPj48y6DADf87r.inf] [N/A, ] [C:\WINDOWS\system32\CRZfQurd2g58gXVgHSDbNhU.inf] [N/A, ] [C:\WINDOWS\system32\rKPbzUHze58GK2VWcYUCt.inf] [N/A, ] [C:\WINDOWS\system32\sDV2mGwkejdKa74QJzsjw.inf] [N/A, ] [C:\WINDOWS\system32\SCEVFJRCmaB7.dll] [N/A, ] [C:\WINDOWS\system32\usbvmx.dll] [N/A, ] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [C:\WINDOWS\system32\DvpZDPd688jbuMdBxV.inf] [N/A, ] [C:\WINDOWS\system32\DMvJFcDsGe5Kccsmc6gZFjB.inf] [N/A, ] [C:\WINDOWS\Downloaded Program Files\CWWFj6tF7GvQjNsqc.cur] [N/A, ] [C:\WINDOWS\fonts\SD78dgC7hD2sktQHyAu.fon] [N/A, ] [C:\WINDOWS\Downloaded Program Files\6YYnDBbzHzrrmenHmv.cur] [N/A, ] [PID: 1776 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\Downloaded Program Files\ktEDQzfuNZk2SUAMgyAZz.cur] [N/A, ] [C:\WINDOWS\system32\SrNRKs5F7Rkv9hp.inf] [N/A, ] [C:\WINDOWS\system32\K7zkXuSVDPKyz63k3V.inf] [N/A, ] [C:\WINDOWS\system32\pj83ZgsqjcWUNwjrRp42tFw.dll] [N/A, ] [C:\WINDOWS\system32\3a5XTcKYzK7KZcrfRE.inf] [N/A, ] [C:\WINDOWS\system32\BMsg6pdMD4ht.dll] [N/A, ] [C:\WINDOWS\Downloaded Program Files\cPvsCcG32xgKmBUgbe4kt.cur] [N/A, ] [C:\WINDOWS\Tasks\BFe2kXdePDntQUqqjz.inf] [N/A, ] [C:\WINDOWS\system32\PERrGx5DkqSbQdwauCRQH.dll] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\system32\704C3595.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\skcfujQ5EDN.dll] [N/A, ] [C:\WINDOWS\system32\B4yNKrEEhEerKFeeA4.inf] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.inf] [N/A, ] [C:\WINDOWS\Tasks\c2nH4numz9knY5zqnC.inf] [N/A, ] [C:\WINDOWS\system32\fRWSJda7RbSuR3jFSmMBy.inf] [N/A, ] [C:\WINDOWS\system32\cRsAQd4hw.dll] [N/A, ] [C:\WINDOWS\system32\CRZfQurd2g58gXVgHSDbNhU.inf] [N/A, ] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [PID: 1876 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [PID: 1080 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\System32\COMRes.dll] [N/A, ] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [PID: 892 / Administrator][C:\WINDOWS\system32\conime.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\pj83ZgsqjcWUNwjrRp42tFw.dll] [N/A, ] [C:\WINDOWS\system32\K7zkXuSVDPKyz63k3V.inf] [N/A, ] [C:\WINDOWS\system32\SrNRKs5F7Rkv9hp.inf] [N/A, ] [C:\WINDOWS\Downloaded Program Files\ktEDQzfuNZk2SUAMgyAZz.cur] [N/A, ] [C:\WINDOWS\Downloaded Program Files\cPvsCcG32xgKmBUgbe4kt.cur] [N/A, ] [C:\WINDOWS\system32\BMsg6pdMD4ht.dll] [N/A, ] [C:\WINDOWS\system32\3a5XTcKYzK7KZcrfRE.inf] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\system32\PERrGx5DkqSbQdwauCRQH.dll] [N/A, ] [C:\WINDOWS\Tasks\BFe2kXdePDntQUqqjz.inf] [N/A, ] [C:\WINDOWS\system32\skcfujQ5EDN.dll] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\704C3595.dll] [N/A, ] [C:\WINDOWS\system32\CRZfQurd2g58gXVgHSDbNhU.inf] [N/A, ] [C:\WINDOWS\system32\cRsAQd4hw.dll] [N/A, ] [C:\WINDOWS\system32\fRWSJda7RbSuR3jFSmMBy.inf] [N/A, ] [C:\WINDOWS\Tasks\c2nH4numz9knY5zqnC.inf] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.inf] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\WINDOWS\system32\B4yNKrEEhEerKFeeA4.inf] [N/A, ] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [PID: 1640 / Administrator][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\TEMP\tmp.tmp] [N/A, ] [C:\WINDOWS\system32\pj83ZgsqjcWUNwjrRp42tFw.dll] [N/A, ] [C:\WINDOWS\system32\K7zkXuSVDPKyz63k3V.inf] [N/A, ] [C:\WINDOWS\system32\SrNRKs5F7Rkv9hp.inf] [N/A, ] [C:\WINDOWS\Downloaded Program Files\ktEDQzfuNZk2SUAMgyAZz.cur] [N/A, ] [C:\WINDOWS\system32\3a5XTcKYzK7KZcrfRE.inf] [N/A, ] [C:\WINDOWS\system32\BMsg6pdMD4ht.dll] [N/A, ] [C:\WINDOWS\Downloaded Program Files\cPvsCcG32xgKmBUgbe4kt.cur] [N/A, ] [C:\WINDOWS\Tasks\BFe2kXdePDntQUqqjz.inf] [N/A, ] [C:\WINDOWS\system32\PERrGx5DkqSbQdwauCRQH.dll] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\system32\704C3595.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\skcfujQ5EDN.dll] [N/A, ] [C:\WINDOWS\system32\B4yNKrEEhEerKFeeA4.inf] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.inf] [N/A, ] [C:\WINDOWS\Tasks\c2nH4numz9knY5zqnC.inf] [N/A, ] [C:\WINDOWS\system32\fRWSJda7RbSuR3jFSmMBy.inf] [N/A, ] [C:\WINDOWS\system32\cRsAQd4hw.dll] [N/A, ] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [PID: 1836 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\DvpZDPd688jbuMdBxV.inf] [N/A, ] [C:\WINDOWS\Tasks\BFe2kXdePDntQUqqjz.inf] [N/A, ] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\browselc.dll] [Microsoft Corporation, 6.00.2600.0000] [C:\WINDOWS\system32\COMRes.dll] [N/A, ] [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.34] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 120] [C:\WINDOWS\system32\CRZfQurd2g58gXVgHSDbNhU.inf] [N/A, ] [C:\WINDOWS\system32\cRsAQd4hw.dll] [N/A, ] [C:\WINDOWS\system32\fRWSJda7RbSuR3jFSmMBy.inf] [N/A, ] [C:\WINDOWS\Tasks\c2nH4numz9knY5zqnC.inf] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.inf] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\WINDOWS\system32\B4yNKrEEhEerKFeeA4.inf] [N/A, ] [C:\WINDOWS\system32\skcfujQ5EDN.dll] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\704C3595.dll] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\system32\PERrGx5DkqSbQdwauCRQH.dll] [N/A, ] [C:\WINDOWS\Downloaded Program Files\cPvsCcG32xgKmBUgbe4kt.cur] [N/A, ] [C:\WINDOWS\system32\BMsg6pdMD4ht.dll] [N/A, ] [C:\WINDOWS\system32\3a5XTcKYzK7KZcrfRE.inf] [N/A, ] [C:\WINDOWS\system32\pj83ZgsqjcWUNwjrRp42tFw.dll] [N/A, ] [C:\WINDOWS\system32\K7zkXuSVDPKyz63k3V.inf] [N/A, ] [C:\WINDOWS\system32\SrNRKs5F7Rkv9hp.inf] [N/A, ] [C:\WINDOWS\Downloaded Program Files\ktEDQzfuNZk2SUAMgyAZz.cur] [N/A, ] [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx] [Adobe Systems, Inc., 10,0,12,36] [C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll] [Thunder Networking Technologies,LTD, 6, 0, 5, 47] [C:\WINDOWS\system32\emHnPuBAaF7XjuXBbdxSg.dll] [N/A, ] [C:\WINDOWS\system32\rKPbzUHze58GK2VWcYUCt.inf] [N/A, ] [C:\WINDOWS\system32\sDV2mGwkejdKa74QJzsjw.inf] [N/A, ] [C:\WINDOWS\system32\122B901E.dll] [N/A, ] [C:\WINDOWS\system32\rfpz9wwyy2np.dll] [N/A, ] [C:\WINDOWS\system32\dhDhwS7fFW.dll] [N/A, ] [C:\WINDOWS\system32\SCEVFJRCmaB7.dll] [N/A, ] [C:\WINDOWS\Downloaded Program Files\qvSPdARs5PQNKAzvezTuPcs.cur] [N/A, ] [C:\WINDOWS\system32\CDuAUVkGy9.dll] [N/A, ] [C:\WINDOWS\system32\ndxq9awMc.dll] [N/A, ] [C:\WINDOWS\Tasks\KzuFUQHxezWBCenC2A.inf] [N/A, ] [C:\WINDOWS\system32\X5T4kV8DNmMbdRXAUx82K.inf] [N/A, ] [C:\WINDOWS\system32\usbvmx.dll] [N/A, ] [C:\WINDOWS\system32\ed78ab9.dll] [N/A, ] [C:\WINDOWS\system32\eYNMAnskCCBQCc8Jp.dll] [N/A, ] [C:\WINDOWS\system32\Am274u6Rqq2cTzTpjCGKy.inf] [N/A, ] [C:\WINDOWS\system32\pEcFwPj48y6DADf87r.inf] [N/A, ] [C:\WINDOWS\Downloaded Program Files\6YYnDBbzHzrrmenHmv.cur] [N/A, ] [C:\WINDOWS\system32\DMvJFcDsGe5Kccsmc6gZFjB.inf] [N/A, ] [C:\WINDOWS\Downloaded Program Files\CWWFj6tF7GvQjNsqc.cur] [N/A, ] [C:\WINDOWS\fonts\SD78dgC7hD2sktQHyAu.fon] [N/A, ] [PID: 3368 / Administrator][C:\Documents and Settings\Administrator\桌面\SREngLdr.EXE] [Smallfrogs Studio, 2.8.1.1279] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [C:\WINDOWS\system32\DvpZDPd688jbuMdBxV.inf] [N/A, ] [C:\WINDOWS\Tasks\BFe2kXdePDntQUqqjz.inf] [N/A, ] [PID: 3080 / Administrator][C:\Documents and Settings\Administrator\桌面\SREc981193a.EXE] [Smallfrogs Studio, 2.8.1.1279] [C:\Program Files\Common Files\system\abbhelp.dll] [梦想工作室, 2.0.0.0] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\CRZfQurd2g58gXVgHSDbNhU.inf] [N/A, ] [C:\WINDOWS\system32\cRsAQd4hw.dll] [N/A, ] [C:\WINDOWS\system32\fRWSJda7RbSuR3jFSmMBy.inf] [N/A, ] [C:\WINDOWS\Tasks\c2nH4numz9knY5zqnC.inf] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.inf] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\WINDOWS\system32\B4yNKrEEhEerKFeeA4.inf] [N/A, ] [C:\WINDOWS\system32\skcfujQ5EDN.dll] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\704C3595.dll] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\system32\PERrGx5DkqSbQdwauCRQH.dll] [N/A, ] [C:\WINDOWS\Tasks\BFe2kXdePDntQUqqjz.inf] [N/A, ] [C:\WINDOWS\Downloaded Program Files\cPvsCcG32xgKmBUgbe4kt.cur] [N/A, ] [C:\WINDOWS\system32\BMsg6pdMD4ht.dll] [N/A, ] [C:\WINDOWS\system32\3a5XTcKYzK7KZcrfRE.inf] [N/A, ] [C:\WINDOWS\system32\pj83ZgsqjcWUNwjrRp42tFw.dll] [N/A, ] [C:\WINDOWS\system32\K7zkXuSVDPKyz63k3V.inf] [N/A, ] [C:\WINDOWS\system32\SrNRKs5F7Rkv9hp.inf] [N/A, ] [C:\WINDOWS\Downloaded Program Files\ktEDQzfuNZk2SUAMgyAZz.cur] [N/A, ] [C:\Documents and Settings\Administrator\桌面\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [C:\WINDOWS\system32\COMRes.dll] [N/A, ] ================================== 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf [C:\] [autorun] Open=1.exe [D:\] [autorun] Open=1.exe [E:\] [autorun] Open=1.exe [F:\] [autorun] Open=1.exe [G:\] [autorun] Open=1.exe ================================== HOSTS 文件 127.0.0.1 v.onondown.com.cn 127.0.0.2 ymsdasdw1.cn 127.0.0.3 h96b.info 127.0.0.0 fuck.zttwp.cn 127.0.0.0 www.hackerbf.cn 127.0.0.0 geekbyfeng.cn 127.0.0.0 121.14.101.68 127.0.0.0 ppp.etimes888.com 127.0.0.0 www.bypk.com 127.0.0.0 CSC3-2004-crl.verisign.com 127.0.0.1 va9sdhun23.cn 127.0.0.0 udp.hjob123.com 127.0.0.2 bnasnd83nd.cn 127.0.0.0 www.gamehacker.com.cn 127.0.0.0 gamehacker.com.cn 127.0.0.3 adlaji.cn 127.0.0.1 858656.com 127.1.1.1 bnasnd83nd.cn 127.0.0.1 my123.com 127.0.0.0 user1.12-27.net 127.0.0.1 8749.com 127.0.0.0 fengent.cn 127.0.0.1 4199.com 127.0.0.1 user1.16-22.net 127.0.0.1 7379.com 127.0.0.1 2be37c5f.3f6e2cc5f0b.com 127.0.0.1 7255.com 127.0.0.1 user1.23-12.net 127.0.0.1 3448.com 127.0.0.1 www.guccia.net 127.0.0.1 7939.com 127.0.0.1 a.o1o1o1.nEt 127.0.0.1 8009.com 127.0.0.1 user1.12-73.cn 127.0.0.1 piaoxue.com 127.0.0.1 3n8nlasd.cn 127.0.0.1 kzdh.com 127.0.0.0 www.sony888.cn 127.0.0.1 about.blank.la 127.0.0.0 user1.asp-33.cn 127.0.0.1 6781.com 127.0.0.0 www.netkwek.cn 127.0.0.1 7322.com 127.0.0.0 ymsdkad6.cn 127.0.0.1 localhost 127.0.0.0 www.lkwueir.cn 127.0.0.1 06.jacai.com 127.0.1.1 user1.23-17.net 127.0.0.1 1.jopenkk.com 127.0.0.0 upa.luzhiai.net 127.0.0.1 1.jopenqc.com 127.0.0.0 www.guccia.net 127.0.0.1 1.joppnqq.com 127.0.0.0 4m9mnlmi.cn 127.0.0.1 1.xqhgm.com 127.0.0.0 mm119mkssd.cn 127.0.0.1 100.332233.com 127.0.0.0 61.128.171.115:8080 127.0.0.1 121.11.90.79 127.0.0.0 www.1119111.com 127.0.0.1 121565.net 127.0.0.0 win.nihao69.cn 127.0.0.1 125.90.88.38 127.0.0.1 16888.6to23.com 127.0.0.1 2.joppnqq.com 127.0.0.0 puc.lianxiac.net 127.0.0.1 204.177.92.68 127.0.0.0 pud.lianxiac.net 127.0.0.1 210.74.145.236 127.0.0.0 210.76.0.133 127.0.0.1 219.129.239.220 127.0.0.0 61.166.32.2 127.0.0.1 219.153.40.221 127.0.0.0 218.92.186.27 127.0.0.1 219.153.46.27 127.0.0.0 www.fsfsfag.cn 127.0.0.1 219.153.52.123 127.0.0.0 ovo.ovovov.cn 127.0.0.1 221.195.42.71 127.0.0.0 dw.com.com 127.0.0.1 222.73.218.115 127.0.0.1 203.110.168.233:80 127.0.0.1 3.joppnqq.com 127.0.0.1 203.110.168.221:80 127.0.0.1 363xx.com 127.0.0.1 www1.ip10086.com.cm 127.0.0.1 4199.com 127.0.0.1 blog.ip10086.com.cn 127.0.0.1 43242.com 127.0.0.1 www.ccji68.cn 127.0.0.1 5.xqhgm.com 127.0.0.0 t.myblank.cn 127.0.0.1 520.mm5208.com 127.0.0.0 x.myblank.cn 127.0.0.1 59.34.131.54 127.0.0.1 210.51.45.5 127.0.0.1 59.34.198.228 127.0.0.1 www.ew1q.cn 127.0.0.1 59.34.198.88 127.0.0.1 59.34.198.97 127.0.0.1 60.190.114.101 127.0.0.1 60.190.218.34 127.0.0.0 qq-xing.com.cn 127.0.0.1 60.191.124.252 127.0.0.1 61.145.117.212 127.0.0.1 61.157.109.222 127.0.0.1 75.126.3.216 127.0.0.1 75.126.3.217 127.0.0.1 75.126.3.218 127.0.0.0 59.125.231.177:17777 127.0.0.1 75.126.3.220 127.0.0.1 75.126.3.221 127.0.0.1 75.126.3.222 127.0.0.1 772630.com 127.0.0.1 832823.cn 127.0.0.1 8749.com 127.0.0.1 888.jopenqc.com 127.0.0.1 89382.cn 127.0.0.1 8v8.biz 127.0.0.1 97725.com 127.0.0.1 9gg.biz 127.0.0.1 www.9000music.com 127.0.0.1 test.591jx.com 127.0.0.1 a.topxxxx.cn 127.0.0.1 picon.chinaren.com 127.0.0.1 www.5566.net 127.0.0.1 p.qqkx.com 127.0.0.1 news.netandtv.com 127.0.0.1 z.neter888.cn 127.0.0.1 b.myblank.cn 127.0.0.1 wvw.wokutu.com 127.0.0.1 unionch.qyule.com 127.0.0.1 www.qyule.com 127.0.0.1 it.itjc.cn 127.0.0.1 www.linkwww.com 127.0.0.1 vod.kaicn.com 127.0.0.1 www.tx8688.com 127.0.0.1 b.neter888.cn 127.0.0.1 promote.huanqiu.com 127.0.0.1 www.huanqiu.com 127.0.0.1 www.haokanla.com 127.0.0.1 play.unionsky.cn 127.0.0.1 www.52v.com 127.0.0.1 www.gghka.cn 127.0.0.1 icon.ajiang.net 127.0.0.1 new.ete.cn 127.0.0.1 www.stiae.cn 127.0.0.1 o.neter888.cn 127.0.0.1 comm.jinti.com 127.0.0.1 www.google-analytics.com 127.0.0.1 hz.mmstat.com 127.0.0.1 www.game175.cn 127.0.0.1 x.neter888.cn 127.0.0.1 z.neter888.cn 127.0.0.1 p.etimes888.com 127.0.0.1 hx.etimes888.com 127.0.0.1 abc.qqkx.com 127.0.0.1 dm.popdm.cn 127.0.0.1 www.yl9999.com 127.0.0.1 www.dajiadoushe.cn 127.0.0.1 v.onondown.com.cn 127.0.0.1 www.interoo.net 127.0.0.1 bally1.bally-bally.net 127.0.0.1 www.bao5605509.cn 127.0.0.1 www.rty456.cn 127.0.0.1 www.werqwer.cn 127.0.0.1 1.360-1.cn 127.0.0.1 user1.23-16.net 127.0.0.1 www.guccia.net 127.0.0.1 www.interoo.net 127.0.0.1 upa.netsool.net 127.0.0.1 js.users.51.la 127.0.0.1 vip2.51.la 127.0.0.1 web.51.la 127.0.0.1 qq.gong2008.com 127.0.0.1 2008tl.copyip.com 127.0.0.1 tla.laozihuolaile.cn 127.0.0.1 www.tx6868.cn 127.0.0.1 p001.tiloaiai.com 127.0.0.1 s1.tl8tl.com 127.0.0.1 s1.gong2008.com 127.0.0.1 4b3ce56f9g.3f6e2cc5f0b.com 127.0.0.1 2be37c5f.3f6e2cc5f0b.com ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 652, C:\WINDOWS\SYSTEM32\WINLOGON.EXE] 特殊特权被允许: SeSystemtimePrivilege [PID = 652, C:\WINDOWS\SYSTEM32\WINLOGON.EXE] 特殊特权被允许: SeSystemtimePrivilege [PID = 840, F:\卡卡.七龙纪自动狩猎插件V3.1\卡卡.七龙纪自动狩猎插件V3.1\GREENBROWSER.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 840, F:\卡卡.七龙纪自动狩猎插件V3.1\卡卡.七龙纪自动狩猎插件V3.1\GREENBROWSER.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 840, F:\卡卡.七龙纪自动狩猎插件V3.1\卡卡.七龙纪自动狩猎插件V3.1\GREENBROWSER.EXE] 特殊特权被允许: SeSystemtimePrivilege [PID = 3368, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\SRENGLDR.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 3368, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\SRENGLDR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3368, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\SRENGLDR.EXE] ================================== 计划任务 [已启用] SogouImeMgr.job C:\PROGRA~1\SOGOUI~1\400~1.209\PinyinRepair.exe ================================== Windows 安全更新检查 N/A ================================== API HOOK 入口点错误:FreeLibrary (危险等级: 高, 被下面模块所HOOK: 0x5F00002D) ================================== 隐藏进程 [3124] C:\Program Files\Common Files\System\QQa3l7.exe ================================== [/CODE]