==================================================
系统启动项:
ctfmon.exe |C:\WINDOWS\system32\ctfmon.exe|
Tok-Cirrhatus-3444 |"C:\Documents and Settings\Administrator\Local Settings\Application Data\br7911on.exe"|
Tok-Cirrhatus | |
!!QQKav |D:\qqkav.exe |
WSockDrv32 |C:\WINDOWS\zzdbmi.exe|
XiaoiDesktop |C:\Program Files\Incesoft\XiaoiAlerts\XiaoiUpdater.exe /hide|
pplkqmlu | |
TUTU |C:\Program Files\tublog\tublog.exe|
Vmlist |regsvr32 /s apphelps.dll|
zuoyue |C:\WINDOWS\system32\inf\svch0st.exe C:\WINDOWS\system32\lwizysys16_080107.dll start|
Empty.pif |C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\Empty.pif i|
系统进程列表:
[System Process] |
System |
\SystemRoot\System32\smss.exe|
\??\C:\WINDOWS\system32\csrss.exe|
\??\C:\WINDOWS\system32\winlogon.exe|
C:\WINDOWS\system32\services.exe|
C:\WINDOWS\system32\lsass.exe|
C:\WINDOWS\system32\svchost.exe|
C:\WINDOWS\system32\svchost.exe|
C:\WINDOWS\System32\svchost.exe|
C:\WINDOWS\system32\svchost.exe|
C:\WINDOWS\system32\svchost.exe|
C:\WINDOWS\system32\spoolsv.exe|
C:\WINDOWS\system32\spoolsv.exe|
C:\WINDOWS\system32\svchost.exe|
C:\WINDOWS\system32\taskmgr.exe|
C:\WINDOWS\system32\wuauclt.exe|
C:\WINDOWS\system32\wbem\wmiprvse.exe|
C:\WINDOWS\explorer.exe|
C:\WINDOWS\system32\inf\svch0st.exe|
D:\qqkav.exe |
C:\Program Files\tublog\tublog.exe|
C:\WINDOWS\system32\rundll32.exe|
C:\WINDOWS\system32\Ctfmon.exe|
C:\WINDOWS\system32\conime.exe|
C:\WINDOWS\System32\alg.exe|
D:\qqkav.exe |
未知IE加载项:
{00C104F7-0F5C-470C-ABCF-A5B2E70752F1}
|sosHlpr Class|C:\WINDOWS\system32\abskey.dll
{10072CEC-8CC1-11D1-986E-00A0C955B42E}
|PeerDraw Class|C:\Program Files\Common Files\Microsoft Shared\VGX\vgx.dll
{11F09AFD-75AD-4E51-AB43-E09E9351CE16}
|CAdLogic
Object|C:\Program Files\Common Files\CPUSH\cpush0.dll
{1B06AE9F-A9EE-4951-8B56-FFCAF7F897EF}
|AutoUpdateX Control|C:\WINDOWS\system32\AutoUpdate.ocx
{385AB8C6-FB22-4D17-8834-064E2BA0A6F0}
{385AB8C6-FB22-4D17-8834-064E2BA0A6F0}
{4DAE9566-953C-4DF1-8E9C-55B7890A3AE8}
||
{6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB}
|StormPlayer
Object|C:\Program Files\StormII\mps.dll
{9963387B-212E-4643-B207-82DAEA0E713D}
||
{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E}
||C:\Program Files\Internet Explorer\IEXPLORE32.win
{A85BED29-396E-49D4-9504-535E2F75DCED}
|Windows Live Toolbar v1.0.0.0922|C:\Program Files\tublog\win32livetoolkit.dll
{C5E87A05-F463-4841-B19E-DD3EC3862368}
||C:\Program Files\Internet Explorer\IEXPLORE32.Sys
{E3178E4E-0CCB-4C14-967A-99C4DE9D85E5}
|XyFrame Control|C:\WINDOWS\XyFrame50.ocx
{EE12D60D-AD9A-4095-B839-3BE6862679FD}
||C:\Program Files\Internet Explorer\IEXPLORE32.Dat
未知BHO插件:
{00C104F7-0F5C-470C-ABCF-A5B2E70752F1}
|sosHlpr Class|C:\WINDOWS\system32\abskey.dll
{11F09AFD-75AD-4E51-AB43-E09E9351CE16}
|CAdLogic
Object|C:\Program Files\Common Files\CPUSH\cpush0.dll
{385AB8C6-FB22-4D17-8834-064E2BA0A6F0}
{385AB8C6-FB22-4D17-8834-064E2BA0A6F0}
{9963387B-212E-4643-B207-82DAEA0E713D}
||
{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E}
||C:\Program Files\Internet Explorer\IEXPLORE32.win
{A85BED29-396E-49D4-9504-535E2F75DCED}
|Windows Live Toolbar v1.0.0.0922|C:\Program Files\tublog\win32livetoolkit.dll
{C5E87A05-F463-4841-B19E-DD3EC3862368}
||C:\Program Files\Internet Explorer\IEXPLORE32.Sys
{EE12D60D-AD9A-4095-B839-3BE6862679FD}
||C:\Program Files\Internet Explorer\IEXPLORE32.Dat
未知系统Hooks插件:
{A8907901-1416-3389-9981-37217856998A}
||C:\WINDOWS\Fonts\kawdjzy.dll
{778A7521-FA87-34AB-34C2-4893F3AD34C7}
||C:\WINDOWS\system32\swrcfzc.dll
{1D098345-9012-8750-8910-9128098134D1}
||C:\WINDOWS\system32\jsqxayc.dll
{DD561258-45F3-A451-F908-A258458226DD}
||C:\WINDOWS\system32\kvdxsmma.dll
{9A1247C1-53DA-FF43-ABD3-345F323A48D9}
||C:\WINDOWS\Fonts\avwgimn.dll
{D859245F-345D-BC13-AC4F-145D47DA34FD}
||C:\WINDOWS\system32\avzxmmn.dll
{4bcb7a90-b0ab-498e-81ab-9c6f50f0d977}
||C:\WINDOWS\system32\IGB_DJOL_1007.dll
{A960356A-458E-DE24-BD50-268F589A56AA}
||C:\WINDOWS\Fonts\avwljmn.dll
{4FA10261-B890-F432-A453-69F1023513F4}
||C:\WINDOWS\Fonts\gjcsdyc.dll
{C4783410-4F90-34A0-7820-3230ACD05F4C}
||C:\WINDOWS\Fonts\raqjlpi.dll
{9A321487-4977-D98A-C8D5-6488257545A9}
||C:\WINDOWS\Fonts\kapjizy.dll
{2D908534-AD45-920F-AC89-4024FA9D26D2}
||C:\WINDOWS\Fonts\gjfhbyc.dll
{792FADFA-BCDE-ACDF-CDEF-21054865CBA7}
||C:\WINDOWS\system32\wsmsezx.dll
{C5E87A05-F463-4841-B19E-DD3EC3862368}
||C:\Program Files\Internet Explorer\IEXPLORE32.Sys
{EE12D60D-AD9A-4095-B839-3BE6862679FD}
||C:\Program Files\Internet Explorer\IEXPLORE32.Dat
{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E}
||C:\Program Files\Internet Explorer\IEXPLORE32.win
未知系统服务:
9D8F8526 |C:\WINDOWS\system32\50D96B79.EXE -g|
Contrl Center of Storm Media|C:\Program Files\StormII\stormliv.exe /asservice|
Servicedvdhelp |C:\WINDOWS\system32\dvdplays.exe|
C:\WINDOWS\system32\wcheck.dll
C:\WINDOWS\system32\wincheck071229.dll
C:\WINDOWS\system32\wincheck071229.exe
C:\WINDOWS\system32\XYHHGHEFHILKL.EXE
C:\WINDOWS\system32\RunSetup.exe
C:\WINDOWS\system32\tempaq
C:\WINDOWS\25084.exe
C:\WINDOWS\tcnyvr.exe
C:\WINDOWS\omtxdv.exe
C:\WINDOWS\system32\mwiszyys32_080107.dll
C:\WINDOWS\system32\9D8F8526.DLL
C:\WINDOWS\system32\WSockDrv32.dll
C:\WINDOWS\system32\ntfs.dll
C:\WINDOWS\system32\~.exe
C:\WINDOWS\system32\dvdhelp.exe
C:\WINDOWS\system32\avzxmst.exe
C:\WINDOWS\system32\kvdxsmis.exe
C:\WINDOWS\system32\jsqxazc.exe
C:\WINDOWS\system32\IGB_DJOL_1007.exe
C:\WINDOWS\system32\dvdshow.dll
C:\WINDOWS\system32\ovfnbipdj.dll
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)