<\SystemRoot\system32\DRIVERS\SiWinAcc.sys><Silicon Image, Inc.>
[SiSRaid / SiSRaid][Stopped/]
<2 - 系统找不到指定的文件。
><N/A>
[SiSRaid2 / SiSRaid2][Stopped/]
<2 - 系统找不到指定的文件。
><N/A>
[SiSRaid4 / SiSRaid4][Stopped/]
<2 - 系统找不到指定的文件><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[viamraid / viamraid][Stopped/Boot Start]
<\SystemRoot\system32\DRIVERS\viamraid.sys><VIA Technologies inc,.ltd>
[vmscsi / vmscsi][Stopped/]
<2 - 系统找不到指定的文件。
><N/A>
==================================
浏览器加载项
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[法拉金牌网址]
{6096E38F-5AC1-1200-8EC4-75DFA92FB32F} <
http://wz.fala123.cn, N/A>
[百度一下,你就知道]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <
http://s.fala123.cn, N/A>
[]
{e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, N/A>
[]
{6AD31948-2ED9-4A2B-85EA-105DD4F656B4} <, >
[ThunderAtOnce Class]
{01443AEC-0FD1-40FD-9C87-E93D1494C233} <C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[]
{6096E38F-5AC1-1200-8EC4-75DFA92FB32F} <, >
[]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <, >
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
[360SafeLive]
{87515F61-A66C-4319-A0E0-D416CB8059E3} <D:\Program Files\360safe\live.dll, N/A>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <, >
[]
{E2E2DD38-D088-4134-82B7-F2BA38496583} <, >
[]
{FB5F1910-F110-11D2-BB9E-00C04F795683} <, >
[使用迅雷下载]
<C:\Program Files\Thunder\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
<C:\Program Files\Thunder\Program\getallurl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
正在运行的进程
[PID: 440 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 500 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 700 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 744 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 756 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 916 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 984 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1024 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[c:\windows\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159]
[PID: 1108 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1140 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1316 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159]
[PID: 1488 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 1748 / Administrator][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\FreeLaunchBar\flb.dll] [TrueSoft, 1.0.0.0]
[C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159]
[C:\WINDOWS\system32\browselc.dll] [Microsoft Corporation, 6.00.2600.0000]
[C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 120]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\tssoft32.acm] [DSP GROUP, INC., 1.01]
[C:\WINDOWS\system32\tsd32.dll] [, ]
[C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.34]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.6.0.1653]
[C:\WINDOWS\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1996 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 524 / Administrator][C:\WINDOWS\RTHDCPL.EXE] [Realtek Semiconductor Corp., 2.1.7.0]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 3540 / Administrator][C:\WINDOWS\system32\mmc.exe] [(Verified) Microsoft Corporation, 5.2.3790.4136 (srv03_sp2_qfe.070821-1204)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 3920 / Administrator][C:\WINDOWS\system32\DfrgFat.exe] [(Verified) Microsoft Corp. and Executive Software International, Inc., 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 3552 / Administrator][C:\WINDOWS\system32\taskmgr.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 2424 / Administrator][C:\Program Files\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5.8.6.600]
[C:\Program Files\Thunder\Program\BugReport.dll] [Thunder Networking Technologies,LTD, 1, 4, 1, 20]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\Program Files\Thunder\Program\ThunderEx.dll] [, 1, 2, 8, 28]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Thunder\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 3, 10, 72]
[C:\Program Files\Thunder\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 3, 3, 2, 325]
[C:\Program Files\Thunder\Program\mp.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 2]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Thunder\Program\asyn_frame.dll] [Thunder Networking Technologies,LTD, 1, 3, 2, 28]
[C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.6041.0]
[C:\Program Files\Thunder\Program\XLNet.Dll] [Thunder Networking Technologies,LTD, 1, 5, 2, 25]
[C:\Program Files\Thunder\Program\dl_peer_id.dll] [Thunder Networking Technologies,LTD, 3, 1, 2, 3]
[C:\Program Files\Thunder\Program\iTargetAD.dll] [N/A, ]
[C:\Program Files\Thunder\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 1, 1, 10]
[C:\Program Files\Thunder\Program\backend_agent.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 25]
[C:\Program Files\Thunder\Program\zlib1.dll] [, 1.2.3]
[C:\Program Files\Thunder\Components\DownAndPlay\DownAndPlay.dll] [, 1, 0, 12, 30]
[C:\Program Files\Thunder\Program\ptl.dll] [Thunder Networking Technologies,LTD, 3, 2, 2, 35]
[C:\Program Files\Thunder\Program\xl_stat.dll] [, 1, 1, 2, 6]
[C:\Program Files\Thunder\Program\p2p_network_com.dll] [, 1, 0, 2, 25]
[C:\Program Files\Thunder\Program\p2p_upload.dll] [Thunder Networking Technologies,LTD, 1,1,2,13]
[C:\Program Files\Thunder\Program\p2p.dll] [Thunder Networking Technologies,LTD, 1,1,2,37]
[C:\Program Files\Thunder\Program\fs.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 13]
[C:\Program Files\Thunder\Program\xldc.dll] [Thunder Networking Technologies,LTD, 3, 6, 2, 23]
[C:\Program Files\Thunder\Program\stream.dll] [Thunder Networking Technologies,LTD, 2, 1, 2, 397]
[C:\Program Files\Thunder\Program\p2sp.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 43]
[C:\Program Files\Thunder\Program\down_dispatcher.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 29]
[C:\Program Files\Thunder\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 2, 5, 0, 90]
[C:\Program Files\Thunder\Program\XLCommunityEx.dll] [N/A, ]
[C:\Program Files\Thunder\Program\p2p_local_res.dll] [Thunder Networking Technologies,LTD, 1,1,2,18]
[C:\Program Files\Thunder\Program\al.dll] [Thunder Networking Technologies,LTD, 1,1,2,23]
[C:\Program Files\Thunder\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 17, 0, 67]
[C:\Program Files\Thunder\Program\imdt.dll] [Thunder Networking Technologies,LTD, 1.2.0.21]
[C:\Program Files\Thunder\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 1, 7, 25]
[C:\Program Files\Thunder\Program\emule_id.dll] [, 1, 0, 2, 11]
[C:\Program Files\Thunder\Components\ExplorerHelper\ExplorerHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 19]
[C:\Program Files\Thunder\Components\DownloadStat\DownloadStat.dll] [Thunder Networking Technologies,LTD, 1, 4, 1, 6]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.6.0.1653]
[C:\Program Files\Thunder\Program\bd.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 19]
[C:\Program Files\Thunder\Program\FloatBar.dll] [Giganology Inc., 1, 0, 0, 2]
[PID: 3464 / Administrator][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 2296 / Administrator][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 2148 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.375\arswp2\ArSwp.exe] [ArSwp.com, 2, 8, 2, 1115]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.375\arswp2\plugin\ArFix.dll] [ArSwp.Com, 2, 5, 0, 0]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.6.0.1653]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 120]
[C:\Program Files\Thunder\ComDlls\ThunderAgent_Now.dll] [Thunder Networking Technologies,LTD, 6, 0, 4, 42]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 2840 / Administrator][C:\WINDOWS\system32\CTFMON.EXE] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 3692 / Administrator][C:\Program Files\专业工具\deepinms.exe] [
www.deepin.org, 1.6.5.0]
[C:\WINDOWS\system32\shell32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.6.0.1653]
[PID: 3640 / Administrator][d:\Program Files\Maxthon2\Maxthon.exe] [Maxthon International ltd., 2, 5, 1, 4751]
[d:\Program Files\Maxthon2\mxpp.dll] [Maxthon International ltd., 1, 0, 0, 276]
[d:\Program Files\Maxthon2\MxSk.dll] [Maxthon, 1, 0, 0, 426]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[d:\Program Files\Maxthon2\MxProxy2.dll] [Maxthon International ltd., 1, 0, 0, 4121]
[d:\Program Files\Maxthon2\MxUI.dll] [Maxthon International Ltd., 3, 3, 1, 8]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.6.0.1653]
[d:\Program Files\Maxthon2\mxtool.dll] [, 1, 0, 0, 1]
[d:\Program Files\Maxthon2\maxzlib.dll] [, 1.2.3]
[d:\Program Files\Maxthon2\Modules\MxWebBoost\MxWebBoost.dll] [Maxthon, 1,0,2,1267]
[d:\Program Files\Maxthon2\mxdb.dll] [Max, 3, 5, 3, 125]
[d:\Program Files\Maxthon2\Modules\MxHistory\MxHistory.dll] [Maxthon International ltd., 1, 0, 0, 302]
[d:\Program Files\Maxthon2\Modules\MxPageSearch\MxPageSearch.dll] [Maxthon International ltd., 1,0,0,1892]
[C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3304 / Administrator][C:\Program Files\WinRAR\WinRAR.exe] [N/A, ]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.6.0.1653]
[PID: 2276 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.406\ArFix.exe] [arswp, 1, 0, 0, 1]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.6.0.1653]
[PID: 1804 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.203\SREngLdr.EXE] [Smallfrogs Studio, 2.7.1.1261]
[PID: 2472 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.203\SREc021e65a.EXE] [Smallfrogs Studio, 2.7.1.1261]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3241 (xpsp_sp2_gdr.071025-1248)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.6.0.1653]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.203\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描特殊特权被允许: SeLoadDriverPrivilege [PID = 700, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2424, C:\PROGRAM FILES\THUNDER\PROGRAM\THUNDER5.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2148, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RAR$EX00.375\ARSWP2\ARSWP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2148, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RAR$EX00.375\ARSWP2\ARSWP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3692, C:\PROGRAM FILES\专业工具\DEEPINMS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3304, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]特殊特权被允许: SeLoadDriverPrivilege [PID = 2276, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RAR$EX00.406\ARFIX.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1804, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RAR$EX00.203\SRENGLDR.EX
计划任务[已启用] SogouImeMgr.job
C:\PROGRA~1\SOGOUI~1\360~1.165\PinyinRepair.exe
API HOOKN/A 隐藏进程N/Acode][localimg