操作系统为:WindowsXP 5.1.2600.2 Service Pack 2
Internet Explorer版本为:V4.0.0000 Build:62900.2180
总共内存为:502M 剩余内存为:296M
进程模块信息:
1 (安全进程):c:\WINDOWS\system32\csrss.exe 命令行: C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
2 未知进程:c:\WINDOWS\system32\WINLOGON.EXE 命令行: winlogon.exe
3 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\miscr3.dll
4 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
5 (安全进程):c:\WINDOWS\system32\services.exe 命令行: C:\WINDOWS\system32\services.exe
6 (安全进程):c:\WINDOWS\system32\lsass.exe 命令行: C:\WINDOWS\system32\lsass.exe
7 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
8 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\dnsq.dll
9 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\miscr3.dll
10 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\fssync.dll
11 - 未知模块:c:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
12 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost -k DcomLaunch
13 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
14 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost -k rpcss
15 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
16 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\dnsq.dll
17 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\System32\svchost.exe -k netsvcs
18 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
19 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\miscr3.dll
20 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\adialhk.dll
21 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost.exe -k NetworkService
22 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
23 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\miscr3.dll
24 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\fssync.dll
25 - 未知模块:c:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
26 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost.exe -k LocalService
27 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
28 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\miscr3.dll
29 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\fssync.dll
30 - 未知模块:c:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
31 (安全进程):c:\WINDOWS\explorer.exe 命令行: C:\WINDOWS\Explorer.EXE
32 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
33 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\miscr3.dll
34 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\fssync.dll
35 - 未知模块:c:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
36 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\scrchpg.dll
37 - 未知模块:d:\acrobat 7.0\ActiveX\pdfshell.dll
38 - 未知模块:d:\acrobat 7.0\ActiveX\pdfshell.CHS
39 - 未知模块:c:\WINDOWS\system32\loanoltrd.dll
40 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\dnsq.dll
41 - 未知模块:d:\WINZIP\WZSHLSTB.DLL
42 - 未知模块:c:\program files\WinRAR\RarExt.dll
43 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\shellex.dll
44 - 未知模块:c:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
45 - 未知模块:c:\WINDOWS\system32\BROWSELC.DLL
46 - 未知模块:c:\WINDOWS\system32\shdoclc.dll
47 - 未知模块:d:\acrobat 7.0\acrobat elements\contextmenu.dll
48 - 未知模块:c:\WINDOWS\system32\mfc71.dll
49 - 未知模块:c:\WINDOWS\system32\msvcr71.dll
50 - 未知模块:c:\WINDOWS\system32\msvcp71.dll
51 - 未知模块:c:\WINDOWS\system32\MFC71CHS.DLL
52 - 未知模块:d:\acrobat 7.0\acrobat elements\contextmenu.chs
53 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\adialhk.dll
54 - 未知模块:c:\program files\microsoft office\Office12\MSOHEVI.DLL
55 (安全进程):c:\WINDOWS\system32\ctfmon.exe 命令行: ctfmon.exe -n
56 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
57 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\miscr3.dll
58 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\fssync.dll
59 - 未知模块:c:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
60 - 未知模块:c:\WINDOWS\system32\loanoltrd.dll
61 (安全进程):c:\WINDOWS\system32\hkcmd.exe 命令行: "C:\WINDOWS\system32\hkcmd.exe"
62 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
63 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\miscr3.dll
64 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\fssync.dll
65 - 未知模块:c:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
66 - 未知模块:c:\WINDOWS\system32\loanoltrd.dll
67 (安全进程):c:\WINDOWS\system32\igfxpers.exe 命令行: "C:\WINDOWS\system32\igfxpers.exe"
68 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
69 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\miscr3.dll
70 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\fssync.dll
71 - 未知模块:c:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
72 - 未知模块:c:\WINDOWS\system32\loanoltrd.dll
73 未知进程:c:\program files\analog devices\SoundMAX\SMax4PNP.exe 命令行: "C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe"
74 - 未知模块:c:\program files\analog devices\SoundMAX\SMWDMIF.dll
75 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\miscr3.dll
76 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\fssync.dll
77 - 未知模块:c:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
78 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
79 - 未知模块:c:\WINDOWS\system32\loanoltrd.dll
80 未知进程:c:\program files\analog devices\SoundMAX\SMAgent.exe 命令行: "C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe"
81 (安全进程):c:\WINDOWS\system32\alg.exe 命令行: C:\WINDOWS\System32\alg.exe
82 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
83 (安全进程):c:\WINDOWS\system32\spoolsv.exe 命令行: C:\WINDOWS\system32\spoolsv.exe
84 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
85 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\dnsq.dll
86 - 未知模块:c:\WINDOWS\system32\AdobePDF.dll
87 - 未知模块:c:\WINDOWS\system32\msvcr71.dll
88 - 未知模块:d:\acrobat 7.0\Distillr\AdistRes.CHS
89 - 未知模块:c:\WINDOWS\system32\msonpmon.dll
90 - 未知模块:c:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
91 - 未知模块:c:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
92 未知进程:d:\acrobat 7.0\Distillr\acrotray.exe 命令行: "D:\ACROBAT 7.0\Distillr\acrotray.exe"
93 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\miscr3.dll
94 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
95 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\fssync.dll
96 - 未知模块:c:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
97 - 未知模块:d:\acrobat 7.0\Distillr\AcroTray.CHS
98 - 未知模块:c:\WINDOWS\system32\loanoltrd.dll
99 未知进程:c:\documents and settings\administrator\桌面\木马清道夫系统诊断分析\木马清道夫系统诊断分析.exe 命令行: "C:\Documents and Settings\Administrator\桌面\木马清道夫系统诊断分析\木马清道夫系统诊断分析.exe"
100 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
101 - 未知模块:c:\WINDOWS\system32\loanoltrd.dll
102 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\miscr3.dll
103 - 未知模块:c:\program files\kaspersky lab\kaspersky internet security 7.0\fssync.dll
104 - 未知模块:c:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
启动信息:
105 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<switch><c:\windows\system32\壁纸自动换.exe>
106 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<igfxhkcmd><C:\WINDOWS\system32\hkcmd.exe>
107 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<igfxpers><C:\WINDOWS\system32\igfxpers.exe>
108 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<SoundMAXPnP><C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe>
109 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<SoundMAX><C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray>
110 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start>
111 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Acrobat Assistant 7.0><"D:\ACROBAT 7.0\Distillr\Acrotray.exe">
112 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Microsoft Pinyin IME Migration><C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMESC\IMSCMIG.EXE /INSTALL>
113 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<AVP><"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe">
114 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
<Super Rabbit SRCK><"C:\Program Files\Super Rabbit\MagicSet\srck.exe" /autokill:32,15>
115 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
116 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Shell><Explorer.exe>
117 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
118 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe>
119 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
120 [C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\desktop.ini>
121 [C:\Documents and Settings\All Users\「开始」菜单\程序\启动\]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\desktop.ini>
122 [C:\Documents and Settings\All Users\「开始」菜单\程序\启动\]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Digital Line Detect.lnk>
123 [C:\Documents and Settings\All Users\「开始」菜单\程序\启动\]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Acrobat Speed Launcher.lnk>
IE辅助对象BHO信息:
124 [HKEY_LOCAL_MACHINESOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
<{AE7CD045-E861-484f-8273-0445EE161910}><D:\ACROBAT 7.0\Acrobat\AcroIEFavClient.dll>
IE右键菜单信息:
125 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<导出到 Microsoft Excel(&X)><res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000>
126 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<导出到 Microsoft Office Excel(&X)><res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000>
127 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<添加到QQ表情><d:\QQ\AddEmotion.htm>
128 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<转换为 Adobe PDF><res://D:\ACROBAT 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html>
129 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<转换为现有 PDF><res://D:\ACROBAT 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html>
130 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<转换选定的链接为 Adobe PDF><res://D:\ACROBAT 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html>
131 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<转换选定的链接为现有 PDF><res://D:\ACROBAT 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html>
132 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<转换选项为 Adobe PDF><res://D:\ACROBAT 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html>
133 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<转换选项为现有 PDF><res://D:\ACROBAT 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html>
134 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<转换链接目标为 Adobe PDF><res://D:\ACROBAT 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html>
135 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<转换链接目标为现有 PDF><res://D:\ACROBAT 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html>
IE工具栏项信息:
无可疑
ActiveX对象DPF信息:
136 [HKEY_LOCAL_MACHINESOFTWARE\Microsoft\Code Store Database\Distribution Units]
<Microsoft XML Parser for Java><>
网络服务SPI信息:
无可疑
系统服务信息:
137 [ Kaspersky Internet Security 7.0 | AVP | 停用 ]
c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
138 [ COM+ System Application | COMSysApp | 停用 ]
c:\windows\system32\dllhost.exe /processid:{02d4b3f1-fd88-11d1-960d-00805fc79235}
139 [ Human Interface Device Access | HidServ | 停用 ]
c:\windows\system32\svchost.exe - c:\windows\system32\hidserv.dll
140 [ Microsoft Office Diagnostics Service | odserv | 停用 ]
c:\program files\common files\microsoft shared\office12\odserv.exe
141 [ Office Source Engine | ose | 停用 ]
c:\program files\common files\microsoft shared\source engine\ose.exe
142 [ SoundMAX Agent Service | SoundMAX Agent Service (default) | 启动 ]
c:\program files\analog devices\soundmax\smagent.exe
143 [ MS Software Shadow Copy Provider | SwPrv | 停用 ]
c:\windows\system32\dllhost.exe /processid:{736153b1-b3b4-4faf-b875-c5aa11ccfbf6}
系统驱动信息:
144 [ Service for Realtek AC97 Audio (WDM) | ALCXWDM | 停用 ]
c:\windows\system32\drivers\alcxwdm.sys
145 [ AMD K8 Processor Driver | AmdK8 | 停用 ]
c:\windows\system32\drivers\amdk8.sys
146 [ Broadcom NetXtreme Gigabit Ethernet | b57w2k | 启动 ]
c:\windows\system32\drivers\b57xp32.sys
147 [ HSFHWICH | HSFHWICH | 停用 ]
c:\windows\system32\drivers\hsfhwich.sys
148 [ HSF_DPV | HSF_DPV | 停用 ]
c:\windows\system32\drivers\hsf_dpv.sys
149 [ kl1 | kl1 | 启动 ]
c:\windows\system32\drivers\kl1.sys
150 [ klif | klif | 启动 ]
c:\windows\system32\drivers\klif.sys
151 [ mdmxsdk | mdmxsdk | 停用 ]
c:\windows\system32\drivers\mdmxsdk.sys
152 [ TCP/IP Protocol Driver | Tcpip | 启动 ]
c:\windows\system32\drivers\tcpip.sys
153 [ TSKSP | TSKSP | 停用 ]
d:\qqdoctor\tsksp.sys
154 [ winachsf | winachsf | 停用 ]
c:\windows\system32\drivers\hsf_cnxt.sys
已经加载的驱动信息:
155 C:\WINDOWS\system32\drivers\kl1.sys
156 C:\WINDOWS\system32\drivers\b57xp32.sys
157 C:\WINDOWS\system32\drivers\tcpip.sys
158 c:\windows\system32\drivers\klif.sys