瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 情帮帮忙分析一下 我的电脑有病毒 这是HijackThis扫描

1   1  /  1  页   跳转

情帮帮忙分析一下 我的电脑有病毒 这是HijackThis扫描

情帮帮忙分析一下 我的电脑有病毒 这是HijackThis扫描

Logfile of HijackThis v1.99.1
Scan saved at 16:29:44, on 2007-4-14
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\5F2BBB19.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\VTTimer.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\conime.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\sglai.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\Program Files\3web\3web.exe
C:\Program Files\FlashGet\flashget.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\NJStar Communicator\Njcom32.exe
C:\Program Files\NJStar Communicator\NJSIME.EXE
C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX00.328\HijackThis.exe

O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\kakatool.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] c:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [winform] C:\WINDOWS\winform.exe
O4 - HKLM\..\Run: [mppds] C:\WINDOWS\mppds.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\HP\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [sglai] C:\WINDOWS\sglai.exe /i
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
O4 - Startup: ìú??QQ.lnk
O4 - Startup: ??à×4.lnk
O4 - Startup: 腾讯QQ.lnk = C:\Documents and Settings\QQ2006\QQ.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Documents and Settings\QQ2006\AddToNetDisk.htm
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Documents and Settings\QQ2006\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Documents and Settings\QQ2006\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Documents and Settings\QQ2006\SendMMS.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O16 - DPF: {8686F2A6-DC01-4E8F-BDE3-DCC7DBBAD6AE} (163Uploader Control) - http://photo.163.com/163Uploader.cab
O16 - DPF: {C661F36D-DF85-4EF4-83C7-E107B83D04B1} (WebActivater Control) - http://dl_dir.qq.com/3dshow/3DShowVM.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{02E88C11-D44B-4006-AAA9-69B7D749ED1C}: NameServer = 209.195.95.95 209.197.128.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{02E88C11-D44B-4006-AAA9-69B7D749ED1C}: NameServer = 209.195.95.95 209.197.128.2
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: DLMon - {590498A3-4131-4D8F-BA4B-36791A0803B1} - C:\WINDOWS\System32\DLMain.dll (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe

最后编辑2007-04-15 12:13:51
分享到:
gototop
 

请下载SREng2 ,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来,,日志一次粘不完,分次粘完,
下载地址
http://download.kztechs.com/files/sreng2.zip
gototop
 

我是楼主 这是SREng2扫描 谢谢

[CODE]

2007-04-15,00:05:39

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 1 (Build 2600) - Administrative User - Completed Functions Allowed

Follow item(s) have been choosed:
    All Boot Items (Including Registry, Startup Folders, Services and so on)
    Browser Add-ons
    Runing Processes (Including process model information)
    File Associations
    Winsock Provider
    Autorun.Inf
    HOSTS File


Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Windows XP Publisher]
    <msnmsgr><"C:\Program Files\MSN Messenger\msnmsgr.exe" /background>  [Microsoft Corporation]
    <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Windows XP Publisher]
    <3dul4mb3yul><C:\DOCUME~1\Owner\LOCALS~1\Temp\iexpl0re.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <SunJavaUpdateSched><C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe>  []
    <hpsysdrv><c:\windows\system\hpsysdrv.exe>  [Hewlett-Packard Company]
    <HP Component Manager><"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe">  [Hewlett-Packard Company]
    <HPHUPD05><c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe>  [Hewlett-Packard]
    <HPHmon05><C:\WINDOWS\System32\hphmon05.exe>  [Hewlett-Packard]
    <KBD><C:\HP\KBD\KBD.EXE>  [Hewlett-Packard Company]
    <Recguard><C:\WINDOWS\SMINST\RECGUARD.EXE>  []
    <VTTimer><VTTimer.exe>  [(Verified)Microsoft Windows XP Publisher]
    <ccApp><"c:\Program Files\Common Files\Symantec Shared\ccApp.exe">  [(Verified)Symantec Corporation]
    <NAV CfgWiz><c:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT">  [(Verified)Symantec Corporation]
    <AGRSMMSG><AGRSMMSG.exe>  [(Verified)Microsoft Windows XP Publisher]
    <PS2><C:\WINDOWS\system32\ps2.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows XP Publisher]
    <MSPY2002><C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC>  [(Verified)Microsoft Windows XP Publisher]
    <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows XP Publisher]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows XP Publisher]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime>  [Apple Computer, Inc.]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [N/A]
    <winform><C:\WINDOWS\winform.exe>  [N/A]
    <mppds><C:\WINDOWS\mppds.exe>  []
    <HP Software Update><"C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe">  [Hewlett-Packard]
    <HPDJ Taskbar Utility><C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <DeviceDiscovery><C:\Program Files\HP\Digital Imaging\bin\hpotdd01.exe>  [Hewlett-Packard]
    <sglai><C:\WINDOWS\sglai.exe /i>  []
    <MSConfig><C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <twin><C:\WINDOWS\System32\ctfnom.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows XP Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows XP Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{27622928-28E4-115D-1070-0BBFE89C54D6}><C:\WINDOWS\System32\sovchot.dll>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <DLMon><C:\WINDOWS\System32\DLMain.dll>  [N/A]

==================================
Startup Folders
[HP Digital Imaging Monitor]
  <C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk --> C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [Hewlett-Packard Co.]><N>
[Quicken Scheduled Updates]
  <C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk --> C:\PROGRA~1\Quicken\bagent.exe [Intuit Inc.]><N>
[Updates from HP]
  <C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk --> C:\PROGRA~1\UPDATE~1\137903\Program\BACKWE~1.EXE [N/A]><N>
[IMStart]
  <C:\Documents and Settings\Owner\Start Menu\Programs\Startup\IMStart.lnk --> C:\PROGRA~1\INTERM~1\IMStart.exe [N/A]><N>
[ìú??QQ]
  <C:\Documents and Settings\Owner\Start Menu\Programs\Startup\ìú??QQ.lnk -->  [N/A]><N>
[??à×4]
  <C:\Documents and Settings\Owner\Start Menu\Programs\Startup\??à×4.lnk -->  [N/A]><N>
[腾讯QQ]
  <C:\Documents and Settings\Owner\Start Menu\Programs\Startup\腾讯QQ.lnk --> C:\DOCUME~1\QQ2006\QQ.exe [TENCENT]><N>

==================================
Services
[1CA5B74B / 1CA5B74B][Stopped/Auto Start]
  <C:\WINDOWS\System32\1CA5B74B.EXE -service><Microsoft Corporation>
[4440F7CE / 4440F7CE][Stopped/Auto Start]
  <C:\WINDOWS\System32\4440F7CE.EXE -service><Microsoft Corporation>
[Application Management / AppMgmt][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
  <C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Symantec Event Manager / ccEvtMgr][Stopped/Disabled]
  <"c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc][Stopped/Disabled]
  <"c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr][Stopped/Disabled]
  <"c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Win32 Debug Service / MSDebugsvc][Stopped/Auto Start]
  <C:\WINDOWS\System32\\rundll32.exe msdebug.dll,input><Microsoft Corporation>
[Norton AntiVirus Auto Protect Service / navapsvc][Running/Auto Start]
  <"c:\Program Files\Norton AntiVirus\navapsvc.exe"><Symantec Corporation>
[SAVScan / SAVScan][Stopped/Manual Start]
  <c:\Program Files\Norton AntiVirus\SAVScan.exe><Symantec Corporation>
[Windows SystemDown / Windows accecc][Stopped/Disabled]
  <C:\WINDOWS\System32\soversie.exe><N/A>
[Cackground Intelligent  / Windows Update][Stopped/Disabled]
  <C:\WINDOWS\SVCHOST.com><N/A>
[WinWLService / WinWLService][Stopped/Disabled]
  <C:\WINDOWS\System32\RAVWL.EXE><N/A>
[WinWMService / WinWMService][Stopped/Disabled]
  <C:\WINDOWS\System32\RAVWM.EXE><N/A>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\System32\mspmsnsv.dll><Microsoft Corporation>
gototop
 

==================================
Drivers
[Agere Systems Soft Modem / AgereSoftModem][Running/Manual Start]
  <System32\DRIVERS\AGRSM.sys><Agere Systems>
[Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
  <system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[fasttx2k / fasttx2k][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\fasttx2k.sys><Promise Technology, Inc.>
[VIA Rhine Family Fast Ethernet Adapter Driver Service / FETNDISB][Running/Manual Start]
  <System32\DRIVERS\fetnd5b.sys><VIA Technologies, Inc.>
[GEAR CDRom Filter / GEARAspiWDM][Running/Manual Start]
  <SYSTEM32\DRIVERS\GEARAspiWDM.sys><GEAR Software Inc.>
[ialm / ialm][Stopped/Manual Start]
  <System32\DRIVERS\ialmnt5.sys><Intel Corporation>
[NAVENG / NAVENG][Running/Manual Start]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20040304.008\NAVENG.Sys><Symantec Corporation>
[NAVEX15 / NAVEX15][Running/Manual Start]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20040304.008\NavEx15.Sys><Symantec Corporation>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\C:\Documents and Settings\QQ2006\npkcrypt.sys><INCA Internet Co., Ltd.>
[Padus ASPI Shell / Pfc][Running/Manual Start]
  <system32\drivers\pfc.sys><Padus, Inc.>
[Ps2 / Ps2][Running/Manual Start]
  <System32\DRIVERS\PS2.sys><Hewlett-Packard Company>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\PxHelp20.sys><Sonic Solutions>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  <\SystemRoot\System32\drivers\RsBoot.sys><Beijing Rising>
[Realtek RTL8139/810x Family Fast Ethernet NIC NT Driver / rtl8139][Stopped/Manual Start]
  <System32\DRIVERS\R8139n51.SYS><Realtek Semiconductor Corporation>
[SAVRT / SAVRT][Running/Manual Start]
  <\??\c:\Program Files\Norton AntiVirus\SAVRT.SYS><Symantec Corporation>
[SAVRTPEL / SAVRTPEL][Running/Auto Start]
  <\??\c:\Program Files\Norton AntiVirus\SAVRTPEL.SYS><Symantec Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><N/A>
[SiS315 / SiS315][Stopped/Manual Start]
  <System32\DRIVERS\sisgrp.sys><Silicon Integrated Systems Corporation>
[SiS AGP Filter / SISAGP][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\SISAGPX.sys><Silicon Integrated Systems Corporation>
[SiSkp / SiSkp][Running/System Start]
  <System32\DRIVERS\srvkp.sys><Silicon Integrated Systems Corporation>
[SymEvent / SymEvent][Running/Manual Start]
  <\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV][Stopped/Manual Start]
  <\??\C:\WINDOWS\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI][Running/Auto Start]
  <\??\C:\WINDOWS\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[VIA AGP Filter / viaagp1][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
[viagfx / viagfx][Running/Manual Start]
  <System32\DRIVERS\vtmini.sys><Copyright (C) VIA/S3 Graphics, Inc.>

==================================
Browser Add-ons
[Web Browser Applet Control]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\WINDOWS\System32\msjava.dll, N/A>
[&Research]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[&Radio]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, >
[HP view]
  {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} <c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll, Hewlett-Packard Company>
[163Uploader Control]
  {8686F2A6-DC01-4E8F-BDE3-DCC7DBBAD6AE} <C:\WINDOWS\System32\163UPL~1.OCX, 广州网易互动娱乐有限公司>
[Java Plug-in 1.4.2_03]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll, JavaSoft / Sun Microsystems, Inc.>
[WebActivater Control]
  {C661F36D-DF85-4EF4-83C7-E107B83D04B1} <C:\WINDOWS\System32\3DShowVM.ocx, QQ>
[Java Plug-in 1.4.2_03]
  {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} <C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll, JavaSoft / Sun Microsystems, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[E&xport to Microsoft Excel]
  <res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000, N/A>
[上传到QQ网络硬盘]
  <C:\Documents and Settings\QQ2006\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <C:\Documents and Settings\QQ2006\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Documents and Settings\QQ2006\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Documents and Settings\QQ2006\SendMMS.htm, N/A>
gototop
 

==================================
Running Processes
[PID: 572][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 620][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\1CA5B74B.DLL]  [Microsoft Corporation, ]
[PID: 644][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\1CA5B74B.DLL]  [Microsoft Corporation, ]
    [C:\WINDOWS\System32\4440F7CE.DLL]  [Microsoft Corporation, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 688][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\1CA5B74B.DLL]  [Microsoft Corporation, ]
[PID: 1420][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\System32\4440F7CE.DLL]  [Microsoft Corporation, ]
    [C:\WINDOWS\System32\1CA5B74B.DLL]  [Microsoft Corporation, ]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\mppds.dll]  [N/A, ]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\IadHide4.dll]  [BackWeb, Version 6.2.3 (Build 66R)]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [c:\Program Files\Norton AntiVirus\NavShExt.dll]  [Symantec Corporation, 10.00.109]
    [C:\WINDOWS\System32\MSVCP70.dll]  [Microsoft Corporation, 7.00.9466.0]
    [C:\WINDOWS\System32\MSVCR70.dll]  [Microsoft Corporation, 7.00.9466.0]
    [C:\WINDOWS\System32\icm32.dll]  [Microsoft Corporation, 5.00]
    [C:\WINDOWS\System32\LCODCCMP.DLL]  [LEAD Technologies, Inc., 1.0.0.013]
    [C:\WINDOWS\System32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
    [C:\WINDOWS\System32\igfxpph.dll]  [Intel Corporation, 3.0.0.3762]
    [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3.0.0.3762]
    [C:\WINDOWS\System32\igfxres.dll]  [Intel Corporation, 3.0.0.3762]
    [C:\WINDOWS\System32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.3762]
    [C:\WINDOWS\System32\igfxdev.dll]  [Intel Corporation, 3.0.0.3762]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Shfusion.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\LgSy1.dll]  [N/A, ]
[PID: 540][C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe]  [N/A, ]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
[PID: 336][C:\windows\system\hpsysdrv.exe]  [Hewlett-Packard Company, 1, 7, 0, 0]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
[PID: 560][C:\Program Files\HP\hpcoretech\hpcmpmgr.exe]  [Hewlett-Packard Company, 2.1.1.0]
    [C:\Program Files\HP\hpcoretech\HPVCR70.dll]  [Microsoft Corporation, 7.00.9466.0]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
    [C:\WINDOWS\System32\MSXML4.dll]  [Microsoft Corporation, 4.10.9404.0]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\IadHide4.dll]  [BackWeb, Version 6.2.3 (Build 66R)]
[PID: 588][C:\WINDOWS\System32\hphmon05.exe]  [Hewlett-Packard, 5,1,7]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
[PID: 600][C:\HP\KBD\KBD.EXE]  [Hewlett-Packard Company, 1.0.2.0]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
    [C:\HP\KBD\led.dll]  [Hewlett-Packard Company, 1.0.2.0]
    [C:\HP\KBD\USB.dll]  [Hewlett-Packard Company, 1.0.2.0]
    [C:\HP\KBD\ps2.dll]  [Hewlett-Packard Company, 1.0.2.2.911]
    [C:\HP\KBD\msg.dll]  [Hewlett-Packard Company, 1.0.2.2.911]
    [C:\HP\KBD\osd.dll]  [Hewlett-Packard Company, 1.0.2.1.815]
    [C:\HP\KBD\sct.dll]  [Hewlett-Packard Company, 1.0.2.1.514]
    [C:\HP\KBD\onl.dll]  [Hewlett-Packard Company, 1.0.2.1.109]
    [C:\HP\KBD\aol.dll]  [Hewlett-Packard Company, 1.0.2.0]
    [C:\HP\KBD\url.dll]  [Hewlett-Packard Company, 1.0.2.0]
    [C:\HP\KBD\cfg.dll]  [Hewlett-Packard Company, 1.0.2.1]
    [C:\HP\KBD\MSIKBDIF.DLL]  [Hewlett-Packard Company, 1.0.2.0]
[PID: 604][C:\WINDOWS\System32\VTTimer.exe]  [S3 Graphics, Inc., 1.100.2004.0115]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
[PID: 664][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
[PID: 1020][C:\WINDOWS\AGRSMMSG.exe]  [Agere Systems, 2.1.37 2.1.37 01/16/2004 12:34:37]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1396][C:\WINDOWS\System32\conime.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
[PID: 1120][C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe]  [Hewlett-Packard, 1, 0, 0, 2]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
[PID: 1904][C:\Program Files\HP\Digital Imaging\bin\hpotdd01.exe]  [Hewlett-Packard, 1, 0, 0, 1]
    [C:\Program Files\HP\Digital Imaging\bin\hpodvd08.dll]  [Hewlett-Packard, 40.0.105.000]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
    [c:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll]  [Hewlett-Packard Co., 40.0.105.000]
[PID: 1936][C:\WINDOWS\sglai.exe]  [N/A, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\sglai.dll]  [N/A, ]
[PID: 2264][C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe]  [N/A, ]
    [C:\Program Files\BackWeb\BackWeb Client\6.2.3.66\Program\BackWeb.dll]  [BackWeb Technologies Inc., Version 6.2.3 (Build 66R)]
    [C:\Program Files\BackWeb\BackWeb Client\6.2.3.66\Program\clntutil.dll]  [N/A, ]
    [C:\Program Files\BackWeb\BackWeb Client\6.2.3.66\Program\bwsec.dll]  [BackWeb, Version 6.2.3 (Build 66R)]
    [C:\PROGRA~1\BackWeb\BACKWE~1\623~1.66\program\EN\ClientRC.dll]  [BackWeb Technologies Inc., Version 6.2.3 (Build 66R)]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
    [C:\Program Files\Updates from HP\137903\Program\BWfiles-137903.dll]  [N/A, ]
    [C:\Program Files\BackWeb\BackWeb Client\6.2.3.66\Program\BWfiles.dll]  [, Version 6.2.3 (Build 66R)]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\IadHide4.dll]  [BackWeb, Version 6.2.3 (Build 66R)]
    [C:\Program Files\Updates from HP\137903\Program\frext-137903.dll]  [N/A, ]
    [C:\Program Files\BackWeb\BackWeb Client\6.2.3.66\Program\frext.dll]  [, Version 6.2.3 (Build 66R)]
    [C:\Program Files\Updates from HP\137903\Program\HPClientExt.dll]  [, 1, 0, 0, 1]
[PID: 3396][C:\Program Files\FlashGet\flashget.exe]  [Amaze Soft, 1, 6, 0, 0]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\IadHide4.dll]  [BackWeb, Version 6.2.3 (Build 66R)]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\LgSy1.dll]  [N/A, ]
[PID: 3836][C:\Program Files\3web\3web.exe]  [Cybersurf Corp., 3.41.0.0]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\IadHide4.dll]  [BackWeb, Version 6.2.3 (Build 66R)]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1164][C:\Documents and Settings\QQ2006\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [C:\Documents and Settings\QQ2006\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 160]
    [C:\Documents and Settings\QQ2006\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\IadHide4.dll]  [BackWeb, Version 6.2.3 (Build 66R)]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\Documents and Settings\QQ2006\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [C:\Documents and Settings\QQ2006\QQAPI.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ 2005\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\Documents and Settings\QQ2006\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 3, 2, 1]
    [C:\Documents and Settings\QQ2006\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\LgSy1.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\WizardCtrl.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\QQMainFrame.dll]  [N/A, ]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Documents and Settings\QQ2006\CQQApplication.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\NewSkin.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\HostingMgr.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\CameraDll.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\MailSummary.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
    [C:\WINDOWS\System32\devenum.dll]  [, ]
    [C:\WINDOWS\System32\msdmo.dll]  [, ]
gototop
 

[C:\Documents and Settings\QQ2006\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\GroupLive.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [C:\Documents and Settings\QQ2006\QQPlugin.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\QQAllInOne.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\SCCore.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\QQCustomFace.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Documents and Settings\QQ2006\QQAvatar.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\Documents and Settings\QQ2006\QQSysMsgMng.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\QRingMng.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [C:\Documents and Settings\QQ2006\QQPet.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\BQQApplication.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\CommercesMng.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [C:\Documents and Settings\QQ2006\QQUdpGetFileLib.dll]  [tencent, 0, 2, 2, 3]
    [C:\Documents and Settings\QQ2006\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 200]
    [C:\Documents and Settings\QQ2006\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [C:\Documents and Settings\QQ2006\QQSceneMng.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\GroupConnection.dll]  [Tencent, 5, 0, 202, 170]
    [C:\Documents and Settings\QQ2006\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 6, 60]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
[PID: 1336][C:\Documents and Settings\QQ 2005\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\IadHide4.dll]  [BackWeb, Version 6.2.3 (Build 66R)]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
    [C:\Documents and Settings\QQ 2005\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 2784][C:\Documents and Settings\QQ2006\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [C:\Documents and Settings\QQ2006\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 160]
    [C:\Documents and Settings\QQ2006\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\IadHide4.dll]  [BackWeb, Version 6.2.3 (Build 66R)]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\Documents and Settings\QQ2006\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [C:\Documents and Settings\QQ2006\QQAPI.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ 2005\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\Documents and Settings\QQ2006\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 3, 2, 1]
    [C:\Documents and Settings\QQ2006\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\LgSy1.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\QQMainFrame.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\CQQApplication.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\NewSkin.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\HostingMgr.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\CameraDll.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\MailSummary.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
    [C:\WINDOWS\System32\devenum.dll]  [, ]
    [C:\WINDOWS\System32\msdmo.dll]  [, ]
    [C:\Documents and Settings\QQ2006\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\GroupLive.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\QQPlugin.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\QQSysMsgMng.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\QRingMng.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Documents and Settings\QQ2006\QQAllInOne.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\SCCore.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [C:\Documents and Settings\QQ2006\QQAvatar.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\Documents and Settings\QQ2006\QQPet.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\QQCustomFace.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Documents and Settings\QQ2006\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [C:\Documents and Settings\QQ2006\BQQApplication.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\CommercesMng.dll]  [, 1, 0, 0, 1]
    [C:\Documents and Settings\QQ2006\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [C:\Documents and Settings\QQ2006\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 200]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\Documents and Settings\QQ2006\QQSceneMng.dll]  [N/A, ]
    [C:\Documents and Settings\QQ2006\GroupConnection.dll]  [Tencent, 5, 0, 202, 170]
    [C:\Documents and Settings\QQGame\GamePublic.dll]  [N/A, ]
    [C:\Documents and Settings\QQGame\Common\Utility.dll]  [N/A, ]
    [C:\Documents and Settings\QQGame\Factory.dll]  [N/A, ]
    [C:\Documents and Settings\QQGame\Logic\UIStyle.dll]  [N/A, ]
    [C:\Documents and Settings\QQGame\ProtHand\QQProt.dll]  [N/A, ]
    [C:\Documents and Settings\QQGame\Socket\NetMod.dll]  [N/A, ]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
[PID: 248][C:\Program Files\Windows Media Player\wmplayer.exe]  [Microsoft Corporation, 9.00.00.2980]
    [C:\WINDOWS\System32\wmp.dll]  [Microsoft Corporation, 9.00.00.3008]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\IadHide4.dll]  [BackWeb, Version 6.2.3 (Build 66R)]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
    [C:\WINDOWS\System32\quartz.dll]  [, ]
    [C:\WINDOWS\System32\msdmo.dll]  [, ]
    [C:\WINDOWS\System32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
    [C:\WINDOWS\System32\devenum.dll]  [, ]
    [C:\Program Files\Allok AVI MPEG Converter\ac3filter.ax]  [, 1.01a]
    [C:\Program Files\StormPlayer2\codecs\ffdshow.ax]  [, 1.0.2.1997]
    [C:\Program Files\StormPlayer2\codecs\vsfilter.dll]  [Gabest, 1, 0, 1, 2]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\LgSy1.dll]  [N/A, ]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
[PID: 2032][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\IadHide4.dll]  [BackWeb, Version 6.2.3 (Build 66R)]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\LgSy1.dll]  [N/A, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
[PID: 1256][C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX00.516\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\IadHide4.dll]  [BackWeb, Version 6.2.3 (Build 66R)]
    [C:\WINDOWS\System32\sovchot.dll]  [N/A, ]
    [C:\DOCUME~1\Owner\LOCALS~1\Temp\LgSy1.dll]  [N/A, ]
gototop
 

==================================
File Associations
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================


[/CODE]
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT