490 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\TempFile.ppl
491 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\CAB.ppl
492 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\Arj.ppl
493 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\rar.ppl
494 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\mdb.ppl
495 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\msoe.ppl
496 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\miscr3.dll
497 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\fssync.dll
498 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\msvcr80.dll
499 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\iwgen.ppl
500 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\UnStored.ppl
501 未知进程:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\scanningprocess.exe 命令行: "D:\迅雷5\Plugins\XLSafeHost\ThunderKAV\bin\ScanningProcess.exe" 3740 0 D:\迅雷5\Plugins\XLSafeHost\ThunderKAV\bin\bases\avp_ext.set
502 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\prloader.dll
503 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
504 - 未知模块:d:\program files\360safe\safemon\safemon.dll
505 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\PrKernel.ppl
506 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\prefetch.ppl
507 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\AvpMgr.ppl
508 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\WDiskIO.ppl
509 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\nfio.ppl
510 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\avlib.ppl
511 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\dtreg.ppl
512 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\PrUtil.ppl
513 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\Avp1.ppl
514 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\L_llio.ppl
515 - 未知模块:d:\迅雷5\Plugins\xlsafehost\thunderkav\bin\ichstrms.ppl
516 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\miscr3.dll
517 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\fssync.dll
518 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\msvcr80.dll
519 未知进程:c:\program files\sogouinput\PinyinUp.exe 命令行: "C:\Program Files\SogouInput\PinyinUp.exe" /S
520 - 未知模块:c:\program files\sogouinput\hwsignature.dll
521 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\miscr3.dll
522 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\fssync.dll
523 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\msvcr80.dll
524 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
525 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\dnsq.dll
526 - 未知模块:d:\program files\360safe\safemon\safemon.dll
527 (安全进程):c:\WINDOWS\explorer.exe 命令行: C:\WINDOWS\explorer.exe
528 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
529 - 未知模块:d:\program files\360safe\safemon\safemon.dll
530 - 未知模块:c:\WINDOWS\system32\SogouPY.ime
531 - 未知模块:c:\program files\sogouinput\plugin\sgimeword.dll
532 - 未知模块:c:\documents and settings\administrator\application data\PPStream\bin\1.0.0.2\vodrc.dll
533 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\miscr3.dll
534 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\fssync.dll
535 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\msvcr80.dll
536 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\scrchpg.dll
537 - 未知模块:c:\WINDOWS\system32\BROWSELC.DLL
538 - 未知模块:d:\迅雷5\ComDlls\tdatonce_now.dll
539 - 未知模块:d:\迅雷5\ComDlls\xunleibho_now.dll
540 - 未知模块:d:\迅雷5\components\resworker\DsBho_00.dll
541 - 未知模块:d:\迅雷5\components\resworker\dataprocessor_00.dll
542 - 未知模块:c:\WINDOWS\system32\shdoclc.dll
543 - 未知模块:c:\program files\WinRAR\RarExt.dll
544 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\shellex.dll
545 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\msvcp80.dll
546 - 未知模块:f:\nokia\nokia pc suite 6\phonebrowser.dll
547 - 未知模块:f:\nokia\nokia pc suite 6\PCSCM.dll
548 - 未知模块:c:\WINDOWS\system32\msvcp71.dll
549 - 未知模块:c:\WINDOWS\system32\msvcr71.dll
550 - 未知模块:f:\nokia\nokia pc suite 6\Lang\phonebrowser_chi-sc.nlr
551 - 未知模块:f:\nokia\nokia pc suite 6\Resource\phonebrowser_nokia.ngr
552 - 未知模块:d:\木马清道夫\ftccommenu.dll
553 未知进程:c:\program files\pc connectivity solution\servicelayer.exe 命令行: "C:\Program Files\PC Connectivity Solution\ServiceLayer.exe"
554 - 未知模块:c:\program files\pc connectivity solution\NclTools.dll
555 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
556 - 未知模块:c:\WINDOWS\system32\SogouPY.ime
557 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\miscr3.dll
558 - 未知模块:c:\program files\pc connectivity solution\transports\nclirdamm.dll
559 - 未知模块:c:\program files\pc connectivity solution\transports\NCLRSMM.dll
560 - 未知模块:c:\program files\pc connectivity solution\transports\NCLUSBMM.dll
561 - 未知模块:c:\program files\pc connectivity solution\transports\nclmsbtmm.dll
562 未知进程:d:\木马清道夫\patchfile\windowsxp-kb951072-x86-chs.exe 命令行: D:\木马清道夫\PatchFile\WindowsXP-KB951072-x86-CHS.exe /passive /norestart
563 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\miscr3.dll
564 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\fssync.dll
565 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\msvcr80.dll
566 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
567 - 未知模块:d:\program files\360safe\safemon\safemon.dll
568 - 未知模块:c:\WINDOWS\system32\SogouPY.ime
569 - 未知模块:c:\program files\sogouinput\plugin\sgimeword.dll
570 未知进程:d:\e0666551be5dfedfae\update\update.exe 命令行: d:\e0666551be5dfedfae\update\update.exe /passive /norestart
571 - 未知模块:d:\e0666551be5dfedfae\update\updspapi.dll
572 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\miscr3.dll
573 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\fssync.dll
574 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\msvcr80.dll
575 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
576 - 未知模块:d:\program files\360safe\safemon\safemon.dll
577 - 未知模块:c:\WINDOWS\system32\SogouPY.ime
578 - 未知模块:c:\program files\sogouinput\plugin\sgimeword.dll
579 (安全进程):d:\e0666551be5dfedfae\SP2GDR\tzchange.exe 命令行: d:\e0666551be5dfedfae\\SP2GDR\tzchange.exe /A "Central Standard Time (Mexico)" /S 4 0 1 2 0 0 0 /E 10 0 5 2 0 0 0 /D -60 /R 0 /B 360 /T "中部标准时间(墨西哥)" /L "中部夏令时(墨西哥)" /N "(GMT-06:00) 瓜达拉哈拉,墨西哥城,蒙特雷(新)" /G /I 2147483715
580 - 未知模块:d:\木马清道夫\FTCMon.dll
581 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\miscr3.dll
582 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\fssync.dll
583 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\msvcr80.dll
584 未知进程:d:\木马清道夫\ftcleaner.exe 命令行: "D:\木马清道夫\FTCleaner.exe"
585 - 未知模块:d:\木马清道夫\MSVBVM60.DLL
586 - 未知模块:d:\木马清道夫\VB6CHS.DLL
587 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
588 - 未知模块:d:\program files\360safe\safemon\safemon.dll
589 - 未知模块:c:\WINDOWS\system32\SogouPY.ime
590 - 未知模块:c:\program files\sogouinput\plugin\sgimeword.dll
591 - 未知模块:d:\木马清道夫\ftcapi.dll
592 - 未知模块:d:\木马清道夫\ftcapi3.dll
593 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\miscr3.dll
594 - 未知模块:d:\木马清道夫\ftcapi2.dll
595 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\fssync.dll
596 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\msvcr80.dll
597 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\dnsq.dll
598 未知进程:d:\木马清道夫\trojanwall.exe 命令行: D:\木马清道夫\Trojanwall.exe C:\
599 - 未知模块:d:\木马清道夫\ftccompress.dll
600 - 未知模块:d:\木马清道夫\ftcapi2.dll
601 - 未知模块:d:\木马清道夫\ftcapi3.dll
602 - 未知模块:d:\木马清道夫\ftcapi.dll
603 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
604 - 未知模块:d:\program files\360safe\safemon\safemon.dll
605 - 未知模块:c:\WINDOWS\system32\SogouPY.ime
606 - 未知模块:c:\program files\sogouinput\plugin\sgimeword.dll
607 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\miscr3.dll
608 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\fssync.dll
609 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\msvcr80.dll
610 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\scrchpg.dll
611 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\dnsq.dll
612 - 未知模块:c:\documents and settings\administrator\application data\PPStream\bin\1.0.0.2\vodrc.dll
613 - 未知模块:f:\nokia\nokia pc suite 6\phonebrowser.dll
614 - 未知模块:f:\nokia\nokia pc suite 6\PCSCM.dll
615 - 未知模块:c:\WINDOWS\system32\msvcp71.dll
616 - 未知模块:c:\WINDOWS\system32\msvcr71.dll
617 - 未知模块:f:\nokia\nokia pc suite 6\Lang\phonebrowser_chi-sc.nlr
618 - 未知模块:f:\nokia\nokia pc suite 6\Resource\phonebrowser_nokia.ngr
619 - 未知模块:c:\program files\pc connectivity solution\ConnAPI.dll
620 - 未知模块:c:\program files\pc connectivity solution\DAAPI.dll
621 - 未知模块:c:\program files\pc connectivity solution\contentadapter.dll
622 - 未知模块:c:\program files\pc connectivity solution\pccs_dbapi.dll
623 - 未知模块:c:\program files\pc connectivity solution\versitconverter.dll
624 - 未知模块:c:\program files\pc connectivity solution\confserver.dll
625 - 未知模块:c:\program files\common files\microsoft shared\OFFICE11\MSOXMLMF.DLL
626 未知进程:d:\木马清道夫\fyganalyze.exe 命令行: D:\木马清道夫\FygAnalyze.exe
627 - 未知模块:c:\WINDOWS\system32\UXTHEME.DLL
628 - 未知模块:d:\program files\360safe\safemon\safemon.dll
629 - 未知模块:c:\WINDOWS\system32\SogouPY.ime
630 - 未知模块:c:\program files\sogouinput\plugin\sgimeword.dll
631 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\miscr3.dll
632 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\fssync.dll
633 - 未知模块:c:\program files\kaspersky lab\kaspersky anti-virus 7.0\msvcr80.dll
634 - 未知模块:c:\documents and settings\administrator\application data\PPStream\bin\1.0.0.2\vodrc.dll
启动信息:
635 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<AVP><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe">
636 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<360Safetray><D:\Program Files\360safe\safemon\360Tray.exe /start>
637 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Windows木马防火墙><D:\木马清道夫\Trojanwall.exe>
638 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
639 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Shutter><F:\Shutter\Shutter>
640 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Shell><Explorer.exe>
641 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
642 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe>
643 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
644 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
<klogon><C:\WINDOWS\system32\klogon.dll>
645 [C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\desktop.ini>
646 [C:\Documents and Settings\All Users\「开始」菜单\程序\启动\]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\desktop.ini>
IE辅助对象BHO信息:
647 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
<{01443AEC-0FD1-40fd-9C87-E93D1494C233}><D:\迅雷5\ComDlls\TDAtOnce_Now.dll>
648 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
<{889D2FEB-5411-4565-8998-1DD2C5261283}><D:\迅雷5\ComDlls\xunleiBHO_Now.dll>
649 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
<{B69F34DD-F0F9-42DC-9EDD-957187DA688D}><D:\Program Files\360safe\safemon\safemon.dll>
IE右键菜单信息:
650 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<使用迅雷下载><D:\迅雷5\Program\GetUrl.htm>
651 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<使用迅雷下载全部链接><D:\迅雷5\Program\GetAllUrl.htm>
652 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<导出到 Microsoft Office Excel(&X)><res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000>
IE工具栏项信息:
653 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
<{09BA8F6D-CB54-424B-839C-C2A6C8E6B436}><D:\迅雷5\Thunder.exe>
654 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
<{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}><>
655 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
<{4045D313-1D5E-4fe4-93A0-A34630B6A00B}><>
ActiveX对象DPF信息:
656 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<Microsoft XML Parser for Java><>
网络服务SPI信息:
无可疑
映像劫持IFEO信息:
657 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
<Your Image File Name Here without a path><C:\WINDOWS\system32\ntsd -d>
系统服务信息:
658 [ 卡巴斯基反病毒软件 7.0 | AVP | 启动 ]
c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe
659 [ Contrl Center of Storm Media | ccosm | 停用 ]
c:\program files\stormii\stormliv.exe
660 [ COM+ System Application | COMSysApp | 停用 ]
c:\windows\system32\dllhost.exe /processid:{02d4b3f1-fd88-11d1-960d-00805fc79235}
661 [ Human Interface Device Access | HidServ | 停用 ]
c:\windows\system32\svchost.exe - c:\windows\system32\hidserv.dll
662 [ Office Source Engine | ose | 停用 ]
c:\program files\common files\microsoft shared\source engine\ose.exe
663 [ ServiceLayer | ServiceLayer | 启动 ]
c:\program files\pc connectivity solution\servicelayer.exe
664 [ MS Software Shadow Copy Provider | SwPrv | 停用 ]
c:\windows\system32\dllhost.exe /processid:{736153b1-b3b4-4faf-b875-c5aa11ccfbf6}
系统驱动信息:
665 [ AMD K8 Processor Driver | AmdK8 | 停用 ]
c:\windows\system32\drivers\amdk8.sys
666 [ Service for Realtek HD Audio (WDM) | IntcAzAudAddService | 启动 ]
c:\windows\system32\drivers\rtkhdaud.sys
667 [ kl1 | kl1 | 启动 ]
c:\windows\system32\drivers\kl1.sys
668 [ klif | klif | 启动 ]
c:\windows\system32\drivers\klif.sys
669 [ TCP/IP Protocol Driver | Tcpip | 启动 ]
c:\windows\system32\drivers\tcpip.sys
670 [ TesSafe | TesSafe | 停用 ]
c:\windows\system32\tessafe.sys
671 [ usbfs | usbfs | 停用 ]
\drivers\usbfs.sys
672 [ FXDrv32 | FXDrv32 | 启动 ]
g:\fxdrv32.sys
673 [ FTCProtect | FTCProtect | 停用 ]
c:\windows\system32\drivers\ftcprotect.sys
674 [ FTCProTime | FTCProTime | 停用 ]
c:\windows\system32\drivers\ftcprotime.sys
675 [ FTCkillfile | FTCkillfile | 停用 ]
c:\windows\system32\drivers\ftckillfile.sys
已经加载的驱动信息:
676 C:\WINDOWS\system32\drivers\kl1.sys
677 C:\WINDOWS\system32\drivers\rtkhdaud.sys
678 C:\WINDOWS\system32\drivers\tcpip.sys
679 c:\windows\system32\drivers\klif.sys
680 C:\WINDOWS\system32\drivers\isdrv122.sys
681 g:\fxdrv32.sys