D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\eHome\ehRecvr.exe
D:\WINDOWS\eHome\ehSched.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\ZoneLabs\vsmon.exe
D:\WINDOWS\ehome\ehtray.exe
D:\WINDOWS\SOUNDMAN.EXE
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
D:\PROGRA~1\Win2\Mouse\Amoumain.exe
D:\WINDOWS\eHome\ehmsas.exe
D:\Program Files\ASUS\Asus Probe\AsusProb.exe
D:\WINDOWS\VM_STI.EXE
D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
D:\Program Files\D-Tools\daemon.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CP.EXE
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Super Rabbit\MagicSet\SRCDNoti.exe
D:\Program Files\ChinaNet\VnetClient.exe
D:\WINDOWS\system32\dllhost.exe
D:\Program Files\Tencent\QQ.exe
D:\Program Files\Tencent\TIMPlatform.exe
D:\Program Files\Yanicsoft\WinXP总管\WinXP Manager.exe
D:\Program Files\Yanicsoft\WinXP总管\ProcessManager.exe
D:\Program Files\Maxthon\Maxthon.exe
F:\4483172005624221516\HijackThis1991zww.exe
F2 - REG:system.ini: UserInit=d:\windows\system32\userinit.exe
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - D:\WINDOWS\system32\xunleibho_v8.dll
O2 - BHO: Shockwave Flash BrowserHelp
Object - {1002C84D-A326-2D3C-13F3-2C2474392A91} - D:\WINDOWS\system32\FlashHlp.dll
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - d:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - BHO: (no name) - {77FEF28E-EB96-44FF-B511-3185DEA48697} - (no file)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - D:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - IE工具栏增项: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
O3 - IE工具栏增项: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - D:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [ehTray] D:\WINDOWS\ehome\ehtray.exe
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [nTrayFw] D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
O4 - 启动项HKLM\\Run: [WheelMouse] D:\PROGRA~1\Win2\Mouse\Amoumain.exe
O4 - 启动项HKLM\\Run: [ASUS Probe] D:\Program Files\ASUS\Asus Probe\AsusProb.exe
O4 - 启动项HKLM\\Run: [BigDogPath] D:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - 启动项HKLM\\Run: [ATIPTA] "D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - 启动项HKLM\\Run: [DAEMON Tools-1033] "D:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - 启动项HKLM\\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [KAVPersonal50] "D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [EPSON Stylus Photo RX430 Series] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CP.EXE /P31 "EPSON Stylus Photo RX430 Series" /O6 "USB001" /M "Stylus Photo RX430"
O4 - 启动项HKLM\\Run: [Zone Labs Client] D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - 启动项HKLM\\Run: [Super Rabbit SRRestore] D:\Program Files\Super Rabbit\MagicSet\srrest.exe /autosave
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Super Rabbit CDNotify] D:\Program Files\Super Rabbit\MagicSet\SRCDNoti.exe /LOAD
O4 - Global Startup: EPSON Online Register.lnk = ?
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - D:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - D:\Program Files\Thunder Network\Thunder\getAllurl.htm
O8 - IE右键菜单中的新增项目: 用比特精灵下载(&B) - D:\Program Files\BitSpirit\bsurl.htm
O9 - 浏览器额外的按钮: Script Checker - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\WINDOWS\system32\shdocvw.dll
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O10 - 未知的文件在 Winsock LSP: d:\windows\system32\nvappfilter.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{C8C4C362-6A38-4AAF-8088-77BD861F8E53}: NameServer = 202.101.224.69 202.101.226.68
O20 - Winlogon Notify: klogon - D:\WINDOWS\
O23 - NT 服务: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - NT 服务: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - NT 服务: ForceWare Intelligent Application Manager (IAM) - Unknown owner - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - NT 服务: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - NT 服务: kavsvc - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - NT 服务: ForceWare IP service (nSvcIp) - NVIDIA - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - NT 服务: ForceWare user log service (nSvcLog) - NVIDIA - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - NT 服务: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINDOWS\system32\ZoneLabs\vsmon.exe