正在运行的进程
[PID: 432][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2096 (xpsp_sp2_rc1.040311-2315)>
[PID: 488][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2096 (xpsp_sp2_rc1.040311-2315)>
[PID: 512][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2096 (xpsp_sp2_rc1.040311-2315)>
[C:\WINDOWS\system32\NQWBX.IME] <念青:http://nq.yeah.net><2.00.03.05>
[PID: 556][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2096 (xpsp_sp2_rc1.040311-2315)>
[PID: 568][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2096 (xpsp_sp2_rc1.040311-2315)>
[PID: 744][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2096 (xpsp_sp2_rc1.040311-2315)>
[PID: 780][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2096 (xpsp_sp2_rc1.040311-2315)>
[PID: 844][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2096 (xpsp_sp2_rc1.040311-2315)>
[PID: 884][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2096 (xpsp_sp2_rc1.040311-2315)>
[PID: 968][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2096 (xpsp_sp2_rc1.040311-2315)>
[PID: 1296][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2096 (xpsp_sp2_rc1.040311-2315)>
[C:\WINDOWS\system32\CNMLM6e.DLL] <CANON INC.><1.80.2.50>
[C:\WINDOWS\system32\spool\PRTPROCS\W32X86\CNMPD6e.DLL] <CANON INC.><1.80.2.50>
[PID: 1420][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3510>
[C:\WINDOWS\system32\NQWBX.IME] <念青:http://nq.yeah.net><2.00.03.05>
[PID: 1436][C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe] <Analog Devices, Inc.><4, 0, 3, 6>
[C:\Program Files\Analog Devices\SoundMAX\SMWDMIF.dll] <Analog Device, Inc.><1, 0, 20, 1>
[C:\WINDOWS\system32\NQWBX.IME] <念青:http://nq.yeah.net><2.00.03.05>
[PID: 1444][C:\Program Files\Analog Devices\SoundMAX\Smax4.exe] <Analog Devices, Inc.><4, 0, 4, 11>
[C:\WINDOWS\system32\NQWBX.IME] <念青:http://nq.yeah.net><2.00.03.05>
[PID: 1452][C:\WINDOWS\VM_STI.EXE] <VM.><4.2.610.4>
[C:\WINDOWS\system32\msdmo.dll] <N/A><N/A>
[G:\KV2004\KV2004\KVMonXP.kxp] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\UpdateX.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\lang\Kvxp0804.lng] <N/A><N/A>
[C:\WINDOWS\system32\NQWBX.IME] <念青:http://nq.yeah.net><2.00.03.05>
[G:\KV2004\KV2004\GUIExt.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\lang\GUIExt0804.lng] <JiangMin Ltd.><7, 1, 0, 200>
[G:\KV2004\KV2004\KVEnhP.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\KvSpiPS.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\lang\PrivateCfg0804.lng] <TODO: <Company name>><1.0.0.1>
[PID: 1512][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2096 (xpsp_sp2_rc1.040311-2315)>
[C:\WINDOWS\system32\NQWBX.IME] <念青:http://nq.yeah.net><2.00.03.05>
[G:\KV2004\KV2004\KvXP.kxp] <Jiangmin software><8.0.0.309>
[G:\KV2004\KV2004\UpdateX.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\KVComm.dll] <JiangMin Ltd.><8.0.0.312>
[G:\KV2004\KV2004\FrogAgentPS.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\APIImpl.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\KvXpUw.dll] <jiangmin software><8.0.0.309>
[G:\KV2004\KV2004\KVEnhO.dll] <JiangMin Ltd.><8.0.0.314>
[G:\KV2004\KV2004\lang\Kvxp0804.lng] <N/A><N/A>
[G:\KV2004\KV2004\GUIExt.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\lang\GUIExt0804.lng] <JiangMin Ltd.><7, 1, 0, 200>
[C:\WINDOWS\system32\NQWBX.IME] <念青:http://nq.yeah.net><2.00.03.05>
[G:\KV2004\KV2004\KVWPSet.dll] <N/A><8.0.0.312>
[G:\KV2004\KV2004\KVEnhD.dll] <JiangMin Ltd.><8.0.0.311>
[G:\KV2004\KV2004\KVEnhC.DLL] <JiangMin Ltd.><8.0.0.311>
[G:\KV2004\KV2004\KVEnhS.dll] <JiangMin Ltd.><8.0.0.313>
[G:\KV2004\KV2004\KVEnhJ.dll] <JiangMin Ltd.><8.0.0.311>
[G:\KV2004\KV2004\KVExtCab.dll] <Jiangmin New Tech. Co. Ltd.><8.0.0.309>
[G:\KV2004\KV2004\KVExtEml.dll] <JiangMin Ltd.><8.0.0.312>
[G:\KV2004\KV2004\KVExtLZH.dll] <N/A><N/A>
[G:\KV2004\KV2004\KvExtRar.dll] <Jiangmin New Tech. Co. Ltd.><8.0.0.309>
[G:\KV2004\KV2004\KvExtZip.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\KVEnhK.dll] <JiangMin Ltd.><7, 1, 0, 307>
[G:\KV2004\KV2004\KVEnhM.dll] <JiangMin Ltd.><8.0.0.311>
[PID: 1632][C:\WINDOWS\system32\DllHost.exe] <Microsoft Corporation><5.1.2600.2096 (xpsp_sp2_rc1.040311-2315)>
[G:\KV2004\KV2004\FrogAgent.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\UpdateX.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\FrogAgentPS.dll] <JiangMin Ltd.><8.0.0.309>
[PID: 268][G:\KV2004\KV2004\KVSrvXP.exe] <JiangMin Ltd.><8.0.0.311>
[G:\KV2004\KV2004\UpdateX.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\KVEnhD.dll] <JiangMin Ltd.><8.0.0.311>
[G:\KV2004\KV2004\KvSPI.dll] <JiangMin Ltd.><8.0.0.312>
[G:\KV2004\KV2004\KVEnhP.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\KVEnhM.dll] <JiangMin Ltd.><8.0.0.311>
[C:\WINDOWS\system32\NQWBX.IME] <念青:http://nq.yeah.net><2.00.03.05>
[G:\KV2004\KV2004\KVEnhC.DLL] <JiangMin Ltd.><8.0.0.311>
[G:\KV2004\KV2004\KVEnhO.dll] <JiangMin Ltd.><8.0.0.314>
[G:\KV2004\KV2004\KVEnhS.dll] <JiangMin Ltd.><8.0.0.313>
[G:\KV2004\KV2004\KVEnhJ.dll] <JiangMin Ltd.><8.0.0.311>
[G:\KV2004\KV2004\KVExtCab.dll] <Jiangmin New Tech. Co. Ltd.><8.0.0.309>
[G:\KV2004\KV2004\KVExtEml.dll] <JiangMin Ltd.><8.0.0.312>
[G:\KV2004\KV2004\KVExtLZH.dll] <N/A><N/A>
[G:\KV2004\KV2004\KvExtRar.dll] <Jiangmin New Tech. Co. Ltd.><8.0.0.309>
[G:\KV2004\KV2004\KvExtZip.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\KVEnhK.dll] <JiangMin Ltd.><7, 1, 0, 307>
[G:\KV2004\KV2004\KvSpiPS.dll] <JiangMin Ltd.><8.0.0.309>
[PID: 340][G:\KV2004\KV2004\KVwsc.exe] <Jiangmin Co><1, 0, 0, 8>
[G:\KV2004\KV2004\KVEnhP.dll] <JiangMin Ltd.><8.0.0.309>
[PID: 396][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] <Analog Devices, Inc.><3, 2, 6, 0>
[PID: 412][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2096 (xpsp_sp2_rc1.040311-2315)>
[PID: 456][C:\WINDOWS\system32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 1072][C:\WINDOWS\system32\wuauclt.exe] <Microsoft Corporation><5.4.3790.2096 (xpsp_sp2_rc1.040311-2315)>
[PID: 3388][C:\WINDOWS\explorer.exe] <Microsoft Corporation><6.00.2900.2096 (xpsp_sp2_rc1.040311-2315)>
[C:\WINDOWS\system32\NQWBX.IME] <念青:http://nq.yeah.net><2.00.03.05>
[G:\KV2004\KV2004\UpdateX.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\GUIExt.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\lang\GUIExt0804.lng] <JiangMin Ltd.><7, 1, 0, 200>
[G:\KV2004\KV2004\KVComm.dll] <JiangMin Ltd.><8.0.0.312>
[G:\KV2004\KV2004\KvShell.dll] <JiangMin Lmt><8.0.0.309>
[G:\KV2004\KV2004\lang\Kvxp0804.lng] <N/A><N/A>
[G:\KV2004\KV2004\APIImpl.dll] <JiangMin Ltd.><8.0.0.309>
[G:\木马分析专家\hyMenu.dll] <水晶情缘工作室><2005.00>
[E:\视频转换工具\WinAVIVideoConverter\SimpleExt.dll] <ZJMedia><7, 5, 0, 0>
[F:\压缩工具WinRAR\rarext.dll] <N/A><N/A>
[PID: 3468][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2096 (xpsp_sp2_rc1.040311-2315)>
[C:\WINDOWS\system32\NQWBX.IME] <念青:http://nq.yeah.net><2.00.03.05>
[G:\KV2004\KV2004\KvShell.dll] <JiangMin Lmt><8.0.0.309>
[G:\KV2004\KV2004\UpdateX.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\lang\Kvxp0804.lng] <N/A><N/A>
[G:\KV2004\KV2004\KVComm.dll] <JiangMin Ltd.><8.0.0.312>
[G:\KV2004\KV2004\APIImpl.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\GUIExt.dll] <JiangMin Ltd.><8.0.0.309>
[G:\KV2004\KV2004\lang\GUIExt0804.lng] <JiangMin Ltd.><7, 1, 0, 200>
[C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[PID: 1832][G:\系统修复工程师\SREng.exe] <Smallfrogs Studio><2.0.12.350>
[C:\WINDOWS\system32\NQWBX.IME] <念青:http://nq.yeah.net><2.00.03.05>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================