浏览器加载项
[Yahoo!Photo]
{33BBE430-0E42-4f12-B075-8D21ACB10DCB} (C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll, Yahoo! China)
[DragSearch BHO]
{62EED7C6-9F02-42f9-B634-98E2899E147B} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, yahoo! china)
[assist]
{FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} (C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yassist.dll, Yahoo! China)
[Yahoo 3.5G电邮]
{507F9113-CD77-4866-BA92-0E86DA3D0B97} (http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A)
[雅虎WIDGET]
{6354ABE6-05F1-49ed-B850-E423120EC338} (http://cn.widget.yahoo.com/index.htm?source=Cns, N/A)
[情景聊天]
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} (http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg, N/A)
[&使用迅雷下载]
(D:\Program Files\Thunder Network\Thunder\geturl.htm, N/A)
[&使用迅雷下载全部链接]
(D:\Program Files\Thunder Network\Thunder\getAllurl.htm, N/A)
[添加到雅虎订阅(&Y)]
(res://C:\Program Files\Yahoo!\Assistant\Assist\yrss.dll/YRSSMENUEXT, N/A)
[雅虎搜索]
(res://C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll/203, N/A)
--------------------------------------------------------------------------------
正在运行的进程
[PID: 144][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 168][\??\C:\WINNT\system32\csrss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 164][\??\C:\WINNT\system32\winlogon.exe] [Microsoft Corporation, 5.00.2195.6898]
[PID: 216][C:\WINNT\system32\services.exe] [Microsoft Corporation, 5.00.2195.6700]
[C:\WINNT\system32\dmserver.dll] [VERITAS Software Corp., 2195.6605.297.3]
[PID: 228][C:\WINNT\system32\lsass.exe] [Microsoft Corporation, 5.00.2195.6902]
[PID: 416][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 444][C:\WINNT\system32\spoolsv.exe] [Microsoft Corporation, 5.00.2195.6659]
[PID: 476][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 516][C:\WINNT\system32\MSTask.exe] [Microsoft Corporation, 4.71.2195.6704]
[PID: 608][C:\WINNT\system32\slserv.exe] [ , 2.80.00(24Apr2000)]
[PID: 304][C:\WINNT\System32\WBEM\WinMgmt.exe] [Microsoft Corporation, 1.50.1085.0100]
[PID: 664][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 808][C:\WINNT\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\15391EDE.dll] [N/A, N/A]
[C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll] [Yahoo! China, 3, 0, 4, 1006]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] [yahoo! china, 3, 0, 1, 1001]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yassist.dll] [Yahoo! China, 3, 1, 0, 1015]
[D:\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\KAV2007\KAVEXT.DLL] [Kingsoft Corporation, 2005, 8, 5, 16]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll] [Yahoo! China, 3, 0, 1, 1001]
[D:\Program Files\Tencent\QQ20066\qdshm.dll] [, 1, 0, 101, 20]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[D:\Program Files\Kingsoft\KnightV\KSKNIGHT.dll] [金山软件股份有限公司, 5, 0, 0, 0]
[C:\WINNT\system32\KPic10.dll] [N/A, N/A]
[C:\WINNT\system32\ijl11.dll] [Intel Corporation, 1.1.2]
[PID: 796][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2800.1106]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\15391EDE.dll] [N/A, N/A]
[C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll] [Yahoo! China, 3, 0, 4, 1006]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] [yahoo! china, 3, 0, 1, 1001]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yassist.dll] [Yahoo! China, 3, 1, 0, 1015]
[C:\WINNT\system32\UNISPIM.IME] [北京清华紫光软件股份有限公司, 3.0.0.3045]
[C:\WINNT\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[D:\Program Files\Kingsoft\KnightV\KSKNIGHT.dll] [金山软件股份有限公司, 5, 0, 0, 0]
[C:\WINNT\system32\KPic10.dll] [N/A, N/A]
[C:\WINNT\system32\ijl11.dll] [Intel Corporation, 1.1.2]
[C:\WINNT\system32\upengine.dll] [北京清华紫光软件股份有限公司, 3.0.0.3045]
[PID: 732][C:\WINNT\system32\mdm.exe] [Microsoft Corporation, 6.00.8149]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\15391EDE.dll] [N/A, N/A]
[PID: 1016][D:\download\AntiVirus\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\15391EDE.dll] [N/A, N/A]
[D:\Program Files\Kingsoft\KnightV\KSKNIGHT.dll] [金山软件股份有限公司, 5, 0, 0, 0]
[C:\WINNT\system32\KPic10.dll] [N/A, N/A]
[C:\WINNT\system32\ijl11.dll] [Intel Corporation, 1.1.2]
[PID: 1088][D:\Program Files\Kingsoft\KnightV\KnightV.exe] [金山软件股份有限公司, 5, 0, 0, 0]
[D:\Program Files\Kingsoft\KnightV\KSKNIGHT.dll] [金山软件股份有限公司, 5, 0, 0, 0]
[C:\WINNT\system32\KPic10.dll] [N/A, N/A]
[C:\WINNT\system32\ijl11.dll] [Intel Corporation, 1.1.2]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\15391EDE.dll] [N/A, N/A]
[PID: 812][C:\WINNT\system32\mspaint.exe] [Microsoft Corporation, 5.00.2195.6601]
[D:\Program Files\Kingsoft\KnightV\KSKNIGHT.dll] [金山软件股份有限公司, 5, 0, 0, 0]
[C:\WINNT\system32\KPic10.dll] [N/A, N/A]
[C:\WINNT\system32\ijl11.dll] [Intel Corporation, 1.1.2]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\15391EDE.dll] [N/A, N/A]
[PID: 288][C:\WINNT\system32\mspaint.exe] [Microsoft Corporation, 5.00.2195.6601]
[D:\Program Files\Kingsoft\KnightV\KSKNIGHT.dll] [金山软件股份有限公司, 5, 0, 0, 0]
[C:\WINNT\system32\KPic10.dll] [N/A, N/A]
[C:\WINNT\system32\ijl11.dll] [Intel Corporation, 1.1.2]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\15391EDE.dll] [N/A, N/A]
[PID: 1136][C:\WINNT\regedit.exe] [Microsoft Corporation, 5.00.2195.6707]
[D:\Program Files\Kingsoft\KnightV\KSKNIGHT.dll] [金山软件股份有限公司, 5, 0, 0, 0]
[C:\WINNT\system32\KPic10.dll] [N/A, N/A]
[C:\WINNT\system32\ijl11.dll] [Intel Corporation, 1.1.2]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\15391EDE.dll] [N/A, N/A]
--------------------------------------------------------------------------------
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
--------------------------------------------------------------------------------
Winsock 提供者
N/A
--------------------------------------------------------------------------------
Autorun.inf
N/A
--------------------------------------------------------------------------------
HOSTS 文件
N/A
--------------------------------------------------------------------------------