{D0A29C6C-AA71-4423-8C4A-5998B774C448} <C:\WINDOWS\system32\GLIEDown2.dll, 联众公司>
[Shockwave Flash
Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\flash.ocx, Macromedia, Inc.>
[Vod Class]
{EEDD6FF9-13DE-496B-9A1C-D78B3215E266} <C:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DapPlayer1.0.0.41.dll, XunLei>
[!搜一搜]
<res://C:\Program Files\yisou\yisou.dll/232, N/A>
[!搜一搜(&S)]
<res://C:\Program Files\yisou\yisou.dll/232, N/A>
[使用影音传送带下载]
<C:\Program Files\Xi\NetTransport 2\NTAddLink.html, N/A>
[使用影音传送带下载全部链接]
<C:\Program Files\Xi\NetTransport 2\NTAddList.html, N/A>
[使用迅雷下载]
<E:\新建文件夹 (7)\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
<E:\新建文件夹 (7)\Program\getallurl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ表情]
<C:\Program Files\QQ2005\AddEmotion.htm, N/A>
[添加到雅虎订阅(&Y)]
<res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT, N/A>
[雅虎搜索]
<res://C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll/246, N/A>
==================================
正在运行的进程
[PID: 448][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 516][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 540][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 584][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\LYMANGR.DLL] [N/A, N/A]
[PID: 596][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 740][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 800][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 880][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 940][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1028][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1196][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Ravasktao.dll] [N/A, N/A]
[C:\WINDOWS\system32\nwiztlbb.dll] [N/A, N/A]
[C:\WINDOWS\system32\ztinetzt.dll] [N/A, N/A]
[C:\WINDOWS\system32\dh2104.dll] [N/A, N/A]
[C:\WINDOWS\system32\nwizwlwzs.dll] [N/A, N/A]
[C:\WINDOWS\system32\nwizwmgjs.dll] [N/A, N/A]
[C:\WINDOWS\system32\nwizhx2.dll] [N/A, N/A]
[C:\WINDOWS\RichDll.dll] [N/A, N/A]
[E:\新建文件夹 (7)\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.0.7]
[E:\新建文件夹 (7)\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 2, 10]
[E:\新建文件夹 (7)\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 4]
[E:\新建文件夹 (7)\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
[C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll] [Xi, 1.91.12]
[PID: 1276][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1748][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5.1.0.34]
[PID: 1796][C:\Program Files\Starsoftcomm\StarCenter\alert.exe] [, 1, 0, 0, 150]
[C:\WINDOWS\system32\ztinetzt.dll] [N/A, N/A]
[PID: 1828][C:\Program Files\Starsoftcomm\StarCenter\StarCenter.exe] [starsoftcomm, 1, 0, 0, 139]
[C:\Program Files\Starsoftcomm\StarCenter\SmartBackup.dll] [SSC, 1, 0, 1, 168]
[C:\Program Files\Starsoftcomm\StarCenter\drvKernel.dll] [, 1, 0, 0, 142]
[C:\Program Files\Starsoftcomm\StarCenter\SC_SystemProtect.DLL] [N/A, N/A]
[C:\Program Files\Starsoftcomm\StarCenter\Asset.DLL] [, 1, 0, 0, 136]
[C:\Program Files\Starsoftcomm\StarCenter\DrvMonitor.DLL] [, 1, 0, 0, 137]
[C:\WINDOWS\system32\ztinetzt.dll] [N/A, N/A]
[C:\Program Files\Starsoftcomm\StarCenter\HookMgr.dll] [, 1, 0, 0, 135]
[C:\Program Files\Starsoftcomm\StarCenter\SSCRegAc.dll] [, 1, 0, 0, 135]
[C:\Program Files\Starsoftcomm\StarCenter\SoftFunc.dll] [, 1, 0, 0, 134]
[C:\Program Files\Starsoftcomm\StarCenter\Encrypt.dll] [N/A, N/A]
[C:\Program Files\Starsoftcomm\StarCenter\sscac.dll] [N/A, N/A]
[PID: 240][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\ztinetzt.dll] [N/A, N/A]
[PID: 1672][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\ztinetzt.dll] [N/A, N/A]
[PID: 2076][C:\WINDOWS\system32\cmd.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[PID: 2100][C:\WINDOWS\Logo1_.exe] [, 1.0.0.0]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\ztinetzt.dll] [N/A, N/A]
[PID: 2144][E:\工具\工具\SREng\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\ztinetzt.dll] [N/A, N/A]
[PID: 464][E:\工具\工具\SREng\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\ztinetzt.dll] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================