==================================
驱动程序
[aeaudio / aeaudio][Running/Manual Start]
<system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[dmboot / dmboot][Stopped/Disabled]
<System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
<\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload][Running/Boot Start]
<\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[Intel(R) PRO Adapter Driver / E100B][Stopped/Manual Start]
<System32\DRIVERS\e100bnt5.sys><N/A>
[ialm / ialm][Running/Manual Start]
<System32\DRIVERS\ialmnt5.sys><Intel Corporation>
[ialmp / ialmp][Running/System Start]
<System32\DRIVERS\pmaware.sys><Intel Corporation>
[NAVAP / NAVAP][Running/Manual Start]
<\??\D:\PROGRA~1\SYMANT~1\SYMANT~1\NAVAP.sys><Symantec Corporation>
[NAVAPEL / NAVAPEL][Running/Auto Start]
<\??\D:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPEL.SYS><Symantec Corporation>
[NAVENG / NAVENG][Running/Manual Start]
<\??\D:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070610.006\NAVENG.sys><Symantec Corporation>
[NAVEX15 / NAVEX15][Running/Manual Start]
<\??\D:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070610.006\NAVEX15.sys><Symantec Corporation>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[smwdm / smwdm][Running/Manual Start]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[SymEvent / SymEvent][Running/Manual Start]
<\??\D:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[{02FCD261-7775-11D5-81D0-0008C76212F8} / {02FCD261-7775-11D5-81D0-0008C76212F8}][Stopped/Manual Start]
<System32\Drivers\a309.sys><Intel Corporation>
[{24050028-D1E3-49FA-88A4-2B7F41AB023C} / {24050028-D1E3-49FA-88A4-2B7F41AB023C}][Stopped/Manual Start]
<System32\Drivers\a304.sys><Intel Corporation>
[{40867A83-9E92-474c-A921-20AA73EAE42F} / {40867A83-9E92-474c-A921-20AA73EAE42F}][Stopped/Manual Start]
<System32\Drivers\a303.sys><Intel Corporation>
[{5C8B2B62-A385-11d5-A78B-00104B672758} / {5C8B2B62-A385-11d5-A78B-00104B672758}][Stopped/Manual Start]
<System32\Drivers\a311.sys><Intel Corporation>
[{5C8B2B65-A385-11d5-A78B-00104B672758} / {5C8B2B65-A385-11d5-A78B-00104B672758}][Stopped/Manual Start]
<System32\Drivers\a310.sys><Intel Corporation>
[Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/System Start]
<system32\drivers\ialmsbw.sys><Intel Corporation>
[{69F517A1-B8FA-11d5-99B7-00B0D0800CD5} / {69F517A1-B8FA-11d5-99B7-00B0D0800CD5}][Stopped/Manual Start]
<System32\Drivers\a312.sys><Intel Corporation>
[{6D08DE66-D457-4d38-A7F5-D88CCB81EE00} / {6D08DE66-D457-4d38-A7F5-D88CCB81EE00}][Stopped/Manual Start]
<System32\Drivers\a305.sys><Intel Corporation>
[{6D08DE67-D457-4d38-A7F5-D88CCB81EE00} / {6D08DE67-D457-4d38-A7F5-D88CCB81EE00}][Stopped/Manual Start]
<System32\Drivers\a306.sys><Intel Corporation>
[{A7E39B01-B403-11d4-BD18-00D0B7A1821E} / {A7E39B01-B403-11d4-BD18-00D0B7A1821E}][Stopped/Manual Start]
<System32\Drivers\Vch.sys><Intel Corporation>
[{BAEE00C0-028A-11d5-8222-000347433250} / {BAEE00C0-028A-11d5-8222-000347433250}][Stopped/Manual Start]
<System32\Drivers\a307.sys><Intel Corporation>
[Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start]
<system32\drivers\ialmkchw.sys><Intel Corporation>
[{E2B953A6-195A-44F9-9BA3-3D5F4E32BB55} / {E2B953A6-195A-44F9-9BA3-3D5F4E32BB55}][Stopped/Manual Start]
<System32\Drivers\a301.sys><Intel Corporation>
[{E2B953A7-195A-44F9-9BA3-3D5F4E32BB55} / {E2B953A7-195A-44F9-9BA3-3D5F4E32BB55}][Stopped/Manual Start]
<System32\Drivers\a301.sys><Intel Corporation>
[{E6759E0C-470B-44DC-A4A1-627E68BB3A85} / {E6759E0C-470B-44DC-A4A1-627E68BB3A85}][Stopped/Manual Start]
<System32\Drivers\a302.sys><Intel Corporation>
[{FE3AC900-723B-11d5-A8DE-000002005D88} / {FE3AC900-723B-11d5-A8DE-000002005D88}][Stopped/Manual Start]
<System32\Drivers\a308.sys><Intel Corporation>
==================================
浏览器加载项
[QQCycloneHelper Class]
{00000000-12C9-4305-82F9-43058F20E8D2} <D:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, 腾讯公司>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx, >
[Tencent Browser Helper]
{0C7C23EF-A848-485B-873C-0ED954731014} <D:\Program Files\TENCENT\SSPlus\SAddr.dll, Tencent>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <D:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <D:\WINNT\system32\wuweb.dll, Microsoft Corporation>
[Shockwave Flash
Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <D:\WINNT\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[&使用超级旋风下载]
<D:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
[&使用超级旋风下载全部链接]
<D:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 184][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 208][\??\D:\WINNT\system32\csrss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 916][D:\WINNT\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690]
[D:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 1, 17]
[D:\Program Files\TENCENT\SSPlus\SAddr.dll] [Tencent, 5, 0, 1, 17]
[D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] [, 1, 0, 0, 1]
[D:\Program Files\WinRAR\rarext.dll] [N/A, ]
[PID: 1084][D:\WINNT\System32\hkcmd.exe] [Intel Corporation, 3,0,0,1773]
[D:\WINNT\System32\hccutils.DLL] [Intel Corporation, 3,0,0,1773]
[D:\WINNT\System32\igfxdev.dll] [Intel Corporation, 3,0,0,1773]
[D:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 1, 17]
[D:\WINNT\System32\igfxsrvc.dll] [Intel Corporation, 3,0,0,1773]
[D:\WINNT\System32\igfxhk.dll] [Intel Corporation, 3,0,0,1773]
[D:\WINNT\System32\igfxres.dll] [Intel Corporation, 3,0,0,1773]
[PID: 1092][D:\WINNT\System32\igfxtray.exe] [Intel Corporation, 3,0,0,1773]
[D:\WINNT\System32\hccutils.DLL] [Intel Corporation, 3,0,0,1773]
[D:\WINNT\System32\igfxdev.dll] [Intel Corporation, 3,0,0,1773]
[D:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 1, 17]
[D:\WINNT\System32\igfxsrvc.dll] [Intel Corporation, 3,0,0,1773]
[D:\WINNT\System32\igfxres.dll] [Intel Corporation, 3,0,0,1773]
[D:\WINNT\System32\igfxress.dll] [Intel Corporation, 3,0,0,1773]
[PID: 1104][D:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe] [Symantec Corporation, 8.1.0.821]
[D:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Cliproxy.dll] [Symantec Corporation, 8.1.0.821]
[D:\PROGRA~1\SYMANT~1\SYMANT~1\NAVNTUTL.DLL] [Symantec/Peter Norton Group, 1, 0, 0, 1]
[D:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Cliscan.dll] [Symantec Corporation, 8.1.0.821]
[D:\WINNT\system32\SFC.DLL] [Microsoft Corporation, 5.00.2195.6673]
[PID: 1116][D:\WINNT\system32\Rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[D:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 1, 17]
[PID: 1140][D:\WINNT\notepad.exe] [Microsoft Corporation, 5.00.2140.1]
[D:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 1, 17]
[PID: 1184][D:\Program Files\WinRAR\WinRAR.exe] [N/A, ]
[D:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 1, 17]
[PID: 1152][D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.703\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[D:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 1, 17]
[D:\WINNT\system32\sfc.dll] [Microsoft Corporation, 5.00.2195.6673]
==================================
文件关联
.TXT Error. [D:\WINNT\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["D:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [D:\WINNT\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]