正在运行的进程
[PID: 560][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 632][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\winsrv.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp.050301-1521)]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp.050301-1521)]
[PID: 1232][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2620 (xpsp.050225-1825)]
[C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2595 (xpsp.041130-1728)]
[C:\WINDOWS\system32\BROWSEUI.dll] [Microsoft Corporation, 6.00.2900.2627 (xpsp.050309-1719)]
[C:\WINDOWS\system32\SHDOCVW.dll] [Microsoft Corporation, 6.00.2900.2627 (xpsp.050309-1719)]
[C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.2627 (xpsp.050309-1719)]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 17.0.54.0]
[C:\WINDOWS\system32\themeui.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Kaspersky Internet Security 6.0\scrchpg.dll] [Kaspersky Lab, 6.0.2.621]
[C:\WINDOWS\system32\ntshrui.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] [Autodesk, 17.0.54.110]
[C:\WINDOWS\system32\MLANG.dll] [Microsoft Corporation, 6.00.2900.2530 (xpsp.040919-1030)]
[C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.2627 (xpsp.050309-1719)]
[C:\WINDOWS\BricoPacks\Vista Inspirat\
ObjectDock\DockShellHook.dll] [N/A, ]
[e:\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\wmpshell.dll] [Microsoft Corporation, 10.00.00.3802]
[C:\WINDOWS\system32\WMASF.DLL] [Microsoft Corporation, 10.00.00.3802 built by: dnsrv(bld4act)]
[F:\Nero 7\Nero BackItUp\NBShell.dll] [Nero AG, 2, 2, 11, 3]
[F:\Nero 7\Nero BackItUp\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
[F:\Nero 7\Nero BackItUp\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[F:\Nero 7\Nero BackItUp\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[D:\WinRAR\rarext.dll] [N/A, ]
[F:\TUNEUP~1\SDShelEx-win32.dll] [TuneUp Software GmbH, 2.0.0.2]
[D:\Kaspersky Internet Security 6.0\ShellEx.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Common Files\Autodesk shared\dwf common\DWFShellExtension.dll] [Autodesk, Inc., 1.1.0.278]
[C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[C:\WINDOWS\system32\qasf.dll] [Microsoft Corporation, 10.00.00.3802 built by: dnsrv(bld4act)]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\system32\ffdshow.ax] [, 1.0.2.2028]
[F:\暴风影音\Codecs\VSFilter.dll] [Gabest, 1, 0, 1, 3]
[F:\暴风影音\Codecs\TTL2Dec.dll] [N/A, ]
[C:\WINDOWS\system32\mydocs.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1464][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp.050301-1521)]
[C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2595 (xpsp.041130-1728)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2620 (xpsp.050225-1825)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2627 (xpsp.050309-1719)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1484][C:\WINDOWS\BricoPacks\Vista Inspirat\
ObjectDock\
ObjectDock.exe] [Stardock, v1.11.517u]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp.050301-1521)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2627 (xpsp.050309-1719)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2620 (xpsp.050225-1825)]
[C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2595 (xpsp.041130-1728)]
[C:\WINDOWS\BricoPacks\Vista Inspirat\
ObjectDock\CrashRpt.dll] [, 3.0.2.2]
[C:\WINDOWS\BricoPacks\Vista Inspirat\
ObjectDock\dbghelp.dll] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\BricoPacks\Vista Inspirat\
ObjectDock\zlib.dll] [, 1.1.3]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 17.0.54.0]
[C:\WINDOWS\BricoPacks\Vista Inspirat\
ObjectDock\ODImg.dll] [N/A, ]
[C:\WINDOWS\BricoPacks\Vista Inspirat\
ObjectDock\DockShellHook.dll] [N/A, ]
[C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.2627 (xpsp.050309-1719)]
[C:\WINDOWS\system32\msdebug.dll] [N/A, ]
[C:\WINDOWS\system32\WMIApiSrv.dll] [N/A, ]
[C:\WINDOWS\system32\netsrvcs.dll] [N/A, ]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\BricoPacks\Vista Inspirat\
ObjectDock\DockShellHook.dll] [N/A, ]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.2627 (xpsp.050309-1719)]
[D:\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.2.621]
[C:\WINDOWS\system32\ntshrui.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
RVA 错误: LoadLibraryA (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0xF5A13AF0)
RVA 错误: LoadLibraryExA (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0xF5A13CD0)
RVA 错误: LoadLibraryExW (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0xF5A13E30)
RVA 错误: LoadLibraryW (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0xF5A13BE0)
RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: Dest Addr: 0xF5A13DE0)