[Serenum Filter Driver / serenum][Stopped/Manual Start]
<System32\DRIVERS\serenum.sys><Microsoft Corporation>
[Serial port driver / Serial][Stopped/System Start]
<System32\DRIVERS\serial.sys><Microsoft Corporation>
[SVKP / SVKP][Stopped/Auto Start]
<\??\C:\WINNT\system32\SVKP.sys><AntiCracking>
[Software Bus Driver / swenum][Running/Manual Start]
<System32\DRIVERS\swenum.sys><Microsoft Corporation>
[Microsoft Kernel GS Wavetable Synthesizer / swmidi][Stopped/Manual Start]
<system32\drivers\swmidi.sys><Microsoft Corporation>
[Microsoft System Audio Device / sysaudio][Stopped/Manual Start]
<system32\drivers\sysaudio.sys><Microsoft Corporation>
[ThinkPad DSP Driver Service / ThinkPadDSP][Stopped/Manual Start]
<System32\DRIVERS\mwwdm.sys><IBM Corporation>
[IBM PS/2 TrackPoint Filter Driver / TwoTrack][Running/Manual Start]
<System32\DRIVERS\TwoTrack.sys><Microsoft Corporation>
[Microsoft USB Universal Host Controller Driver / uhcd][Running/Manual Start]
<System32\DRIVERS\uhcd.sys><Microsoft Corporation>
[Microcode Update Driver / Update][Running/Manual Start]
<System32\DRIVERS\update.sys><Microsoft Corporation>
[Microsoft USB Standard Hub Driver / usbhub][Running/Manual Start]
<System32\DRIVERS\usbhub.sys><Microsoft Corporation>
[USB Scanner Driver / usbscan][Stopped/Manual Start]
<System32\DRIVERS\usbscan.sys><Microsoft Corporation>
[USB Mass Storage Driver / USBSTOR][Running/Manual Start]
<System32\DRIVERS\USBSTOR.SYS><Microsoft Corporation>
[vbppdryu / vbppdryu][Stopped/Manual Start]
<\??\C:\WINNT\system32\sosdrp.sys><N/A>
[VgaSave / VgaSave][Running/System Start]
<\SystemRoot\System32\drivers\vga.sys><Microsoft Corporation>
[Remote Access IP ARP Driver / Wanarp][Stopped/Manual Start]
<System32\DRIVERS\wanarp.sys><Microsoft Corporation>
[Microsoft WINMM WDM Audio Compatibility Driver / wdmaud][Stopped/Manual Start]
<system32\drivers\wdmaud.sys><Microsoft Corporation>
[Windows 套接字 2 .0 Non-IFS 服务提供程序支持环境 / WS2IFSL][Stopped/Auto Start]
<\SystemRoot\System32\drivers\ws2ifsl.sys><Microsoft Corporation>
[VIMICRO USB PC Camera 301x / ZSMC301b][Stopped/Manual Start]
<System32\Drivers\usbVM31b.sys><VM>
==================================
浏览器加载项
[Tencent Browser Helper]
{0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr.dll, Tencent>
[]
{53707962-6F74-2D53-2644-206D7942484F} <C:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[QQBrowserHelper
Object Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\qq\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[]
{669751ED-D558-49AE-B01A-3B374CC7910E} <C:\WINNT\system32\ssup.dll, TENCENT>
[Schedule Class]
{8B316DA1-9950-4926-B9EA-1AEC124AFA45} <C:\WINNT\system32\sscli.dll, >
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[Google Toolbar Helper]
{AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[CibaCtrl Class]
{8DE0FCD4-5EB5-11D3-AD25-00002100131B} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[JoyoCtrl Class]
{C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\qq\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\qq\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\System32\msdxm.ocx, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[PGEdit Class]
{2BFAA61B-5C83-4865-8281-D8BDBF863061} <C:\WINNT\Downloaded Program Files\PG_ATL_Edit.dll, 中国银联广州分公司>
[WebActivater Control]
{3D8F74EE-8692-4F8F-B8D2-7522E732519E} <C:\WINNT\system32\WEBACT~1.OCX, QQ>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINNT\system32\wuweb.dll, Microsoft Corporation>
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINNT\DOWNLO~1\INPUTC~1.DLL, >
[Shockwave Flash
Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[Ravonline]
{DA984A6D-508E-11D6-AA49-0050FF3C628D} <C:\WINNT\Downloaded Program Files\RsOnline.dll, Beijing Rising Tech. Co., Ltd.>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
<C:\Program Files\KuGoo3\KuGoo3DownX.htm, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\qq\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 108][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 136][\??\C:\WINNT\system32\csrss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 156][\??\C:\WINNT\SYSTEM32\winlogon.exe] [Microsoft Corporation, 5.00.2195.6997]
[C:\WINNT\SYSTEM32\APIHookDll.dll] [N/A, N/A]
[C:\WINNT\SYSTEM32\tssoft32.acm] [DSP GROUP, INC., 1.01]
[C:\WINNT\SYSTEM32\tsd32.dll] [N/A, N/A]
[C:\WINNT\SYSTEM32\iac25_32.ax] [Ligos Corporation, 2.05.54]
[C:\WINNT\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[C:\WINNT\SYSTEM32\sl_anet.acm] [Sipro Lab Telecom Inc., 3.02]
[C:\WINNT\SYSTEM32\vct3216.acm] [Voxware, Inc., 1.6.0.17]
[C:\WINNT\SYSTEM32\vct3216.dll] [Voxware, Inc., 1.6.0.12]
[C:\WINNT\system32\msms001.vwp] [Voxware, Inc., 2.0.2.61]
[C:\WINNT\system32\mvoice.vwp] [Voxware, Inc., 2.0.0.12.01]
[C:\WINNT\SYSTEM32\vorbis.acm] [HMS http://hp.vector.co.jp/authors/VA012897/, 0, 0, 3, 6]
[PID: 184][C:\WINNT\system32\services.exe] [Microsoft Corporation, 5.00.2195.7035]
[C:\WINNT\system32\APIHookDll.dll] [N/A, N/A]
[C:\WINNT\system32\dmserver.dll] [VERITAS Software Corp., 2195.6605.297.3]
[PID: 196][C:\WINNT\system32\lsass.exe] [Microsoft Corporation, 5.00.2195.7011]
[C:\WINNT\system32\APIHookDll.dll] [N/A, N/A]
[PID: 344][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\APIHookDll.dll] [N/A, N/A]
[PID: 384][C:\WINNT\System32\WBEM\WinMgmt.exe] [Microsoft Corporation, 1.50.1085.0100]
[C:\WINNT\SYSTEM32\APIHookDll.dll] [N/A, N/A]
[PID: 224][C:\WINNT\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690]
[C:\WINNT\system32\APIHookDll.dll] [N/A, N/A]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\WINNT\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 496][C:\软件\Sreng\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\WINNT\system32\APIHookDll.dll] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD Tcpip [UDP/IP]
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD Tcpip [RAW/IP]
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
RSVP UDP Service Provider
C:\WINNT\system32\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
RSVP TCP Service Provider
C:\WINNT\system32\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{C2C444B7-C8BC-43E8-8E41-B92B43EC04BB}] SEQPACKET 3
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{C2C444B7-C8BC-43E8-8E41-B92B43EC04BB}] DATAGRAM 3
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{5CDEA571-8E85-40D2-B9C6-5F8CD9B7DC20}] SEQPACKET 0
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{5CDEA571-8E85-40D2-B9C6-5F8CD9B7DC20}] DATAGRAM 0
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{EE5086E3-94B8-47C0-89A9-4EB68C2BE64A}] SEQPACKET 1
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{EE5086E3-94B8-47C0-89A9-4EB68C2BE64A}] DATAGRAM 1
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{F57F1890-3872-4A14-A892-B4808CE04882}] SEQPACKET 2
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{F57F1890-3872-4A14-A892-B4808CE04882}] DATAGRAM 2
C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================
API HOOK
N/A
==================================
[/CODE]