服务
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"> [Adobe Systems, 2.67.010, C:2007-12-15 20:30 M:2007-12-15 20:30]
[Application Management / AppMgmt][Stopped/Manual Start]
<%SystemRoot%\system32\svchost.exe -k netsvcs --> "%SystemRoot%\System32\appmgmts.dll"> [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111), C:2001-09-05 20:00 M:2008-04-14 10:14]
[Ati HotKey Poller / Ati HotKey Poller][Stopped/Disabled]
<%SystemRoot%\System32\Ati2evxx.exe> [ATI Technologies Inc., 6.14.10.4155, C:2007-01-09 01:05 M:2007-01-09 01:05]
[Human Interface Device Access / HidServ][Stopped/Disabled]
<%SystemRoot%\System32\svchost.exe -k netsvcs --> "%SystemRoot%\System32\hidserv.dll"> [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111), C:2001-09-05 20:00 M:2008-04-14 10:14]
[Windows CardSpace / idsvc][/Manual Start]
<"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"> [Microsoft Corporation, 3.0.4506.648 (Winfxred.004506-0648), C:2007-10-11 09:55 M:2007-10-11 09:55]
[MSSQLServer / MSSQLServer][Running/Auto Start]
<D:\MSSQL7\binn\sqlservr.exe> [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-27 23:43]
[Net.Tcp Port Sharing Service / NetTcpPortSharing][Stopped/Disabled]
<"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"> [Microsoft Corporation, 3.0.4506.648 (Winfxred.004506-0648), C:2007-10-11 09:55 M:2007-10-11 09:55]
[pxjmlw / pxjmlw][Stopped/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k pxjmlw --> "%SystemRoot%\System32\pikumcmy.dll"> [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111), C:2001-09-05 20:00 M:2008-04-14 10:14]
[SQLServerAgent / SQLServerAgent][Running/Auto Start]
<D:\MSSQL7\binn\sqlagent.exe> [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-13 02:09]
[U8管理软件 / UFNet][Running/Auto Start]
<C:\WINDOWS\system32\ServerNT.EXE> [N/A, C:2007-12-25 21:08 M:2002-09-22 15:33]
[Autodesk Licensing Service / Autodesk Licensing Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"> [(Verified)Autodesk, 2.80.011, C:2007-12-15 15:37 M:2007-12-15 15:37]
[AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Stopped/Manual Start]
<D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe> [(Verified)GRISOFT s.r.o., 7, 5, 1, 22, C:2007-05-30 20:31 M:2007-05-30 20:31]
[Kaspersky Internet Security / AVP][Running/Auto Start]
<"D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" -r> [(Verified)Kaspersky Lab, 8.0.0.454, C:2008-07-29 20:20 M:2008-07-29 20:20]
[Contrl Center of Storm Media / ccosm][Running/Auto Start]
<d:\Program Files\StormII\stormliv.exe /asservice> [(Verified)北京暴风网际科技有限公司, 3, 8, 3, 15, C:2008-03-11 14:33 M:2008-03-11 14:33]
[Cmb WebProtect Support / CMBWPS][Running/Auto Start]
<C:\Program Files\CMBCHINA\WebProtect\WPService.exe /start> [(Verified)China Merchants Bank, 1, 0, 0, 1, C:2008-04-30 19:13 M:2007-08-27 16:35]
========================================
驱动
[ati2mtag / ati2mtag][Running/Manual Start]
<System32\DRIVERS\ati2mtag.sys> [ATI Technologies Inc., 6.14.10.6660, C:2007-01-09 01:12 M:2007-01-09 01:12]
[npkcrypt / npkcrypt][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\npkcrypt.sys> []
[npkycryp / npkycryp][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\npkycryp.sys> []
[rgga / rgga][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\rgga.sys> [SafeNet China Ltd., 2, 1, 3, 0, C:2007-12-20 17:57 M:2007-12-20 17:57]
[Sense3 / Sense3][Stopped/Auto Start]
<System32\drivers\sense3.sys> [Beijing Senselock, 1.10.00, C:2007-12-20 16:06 M:2007-12-25 21:10]
[Superk53 / Superk53][Running/Auto Start]
<\SystemRoot\System32\drivers\superk53.sys> [Microsoft Corporation, 3.51, C:2007-12-25 21:10 M:2000-09-08 16:20]
[360AntiArp / 360AntiArp][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\360AntiArp.sys> [(Verified)360安全中心, 1, 0, 1, 1007, C:2008-04-09 16:33 M:2008-04-09 16:33]
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\RTKVAC.SYS> [(Verified)Realtek Semiconductor Corp., 6.0.1.6231 built by: WinDDK, C:2007-12-14 20:50 M:2007-03-08 16:59]
[AMD HwPState Processor Driver / AmdPPM][Running/System Start]
<system32\DRIVERS\AmdPPM.sys> [(Verified)Advanced Micro Devices, 1.0.0 built by: WinDDK, C:2007-04-16 21:46 M:2007-04-16 21:46]
[AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
<\??\D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys> [(Verified)N/A, C:2007-05-30 20:10 M:2007-05-30 20:10]
[AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
<System32\DRIVERS\AvgAsCln.sys> [(Verified)GRISOFT, s.r.o., 1.0.0.14, C:2008-01-04 18:11 M:2007-05-30 20:10]
[Kl1 / kl1][Running/Boot Start]
<system32\drivers\kl1.sys> [(Verified)Kaspersky Lab, 6.2.35.0, C:2008-07-21 18:34 M:2008-07-21 18:34]
[Kaspersky Lab Boot Guard Driver / klbg][Running/Boot Start]
<system32\drivers\klbg.sys> [(Verified)Kaspersky Lab, 8.0.6.2, C:2008-01-29 18:29 M:2008-01-29 18:29]
[Kaspersky Lab KLFltDev / KLFLTDEV][Running/Manual Start]
<system32\DRIVERS\klfltdev.sys> [(Verified)Kaspersky Lab, 8.0.0.17, C:2008-03-13 19:02 M:2008-03-13 19:02]
[Kaspersky Lab Driver / KLIF][Running/System Start]
<system32\DRIVERS\klif.sys> [(Verified)Kaspersky Lab, 8.1.0.100, C:2008-08-20 20:02 M:2008-08-20 20:02]
[Kaspersky Anti-Virus NDIS Filter / klim5][Running/Manual Start]
<system32\DRIVERS\klim5.sys> [(Verified)Kaspersky Lab, 6.1.28.0, C:2008-04-30 18:06 M:2008-04-30 18:06]
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys> [(Verified)Parallel Technologies, Inc., 1.10 (XPClient.010817-1148), C:2001-09-05 20:00 M:2001-09-05 20:00]
[Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver / RTLE8023xp][Running/Manual Start]
<System32\DRIVERS\Rtenicxp.sys> [(Verified)Realtek Semiconductor Corporation , 5.650.0616.2006 built by: WinDDK, C:2007-12-14 20:54 M:2006-06-17 20:36]
[SafeBoxKrnl / SafeBoxKrnl][Running/System Start]
<\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys> [(Verified)360安全中心, 2, 2, 1, 1001, C:2008-06-06 18:31 M:2008-06-06 18:31]
[Secdrv / Secdrv][Stopped/Manual Start]
<System32\DRIVERS\secdrv.sys> [(Verified)Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., 4.03.086, C:2001-09-05 20:00 M:2007-11-13 18:25]
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start]
<system32\DRIVERS\SONYPVU1.SYS> [(Verified)Sony Corporation, 1.3.0526.0 (XPClient.010817-1148), C:2008-07-07 13:12 M:2001-08-17 13:56]
========================================
进程
[PID: 916 / SYSTEM] \SystemRoot\System32\smss.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111), C:2001-09-05 20:00 M:2008-04-14 10:14]
[PID: 964 / SYSTEM] \??\C:\WINDOWS\system32\csrss.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111), C:2001-09-05 20:00 M:2008-04-14 10:13]
[PID: 992 / SYSTEM] \??\C:\WINDOWS\system32\winlogon.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113), C:2001-09-05 20:00 M:2008-04-14 10:14]
C:\WINDOWS\system32\Ati2evxx.dll [ATI Technologies Inc., 6.14.10.4155, C:2007-01-09 01:06 M:2007-01-09 01:06]
C:\WINDOWS\system32\klogon.dll [(Verified)Kaspersky Lab, 8.0.0.454, C:2008-07-29 20:21 M:2008-07-29 20:21]
[PID: 1036 / SYSTEM] C:\WINDOWS\system32\services.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111), C:2001-09-05 20:00 M:2008-04-14 10:14]
[PID: 1048 / SYSTEM] C:\WINDOWS\system32\lsass.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113), C:2001-09-05 20:00 M:2008-04-14 10:14]
[PID: 1216 / SYSTEM] C:\WINDOWS\system32\svchost.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111), C:2001-09-05 20:00 M:2008-04-14 10:14]
[PID: 1304 / NETWORK SERVICE] C:\WINDOWS\system32\svchost.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111), C:2001-09-05 20:00 M:2008-04-14 10:14]
[PID: 1416 / SYSTEM] C:\WINDOWS\System32\svchost.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111), C:2001-09-05 20:00 M:2008-04-14 10:14]
[PID: 1572 / LOCAL SERVICE] C:\WINDOWS\System32\svchost.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111), C:2001-09-05 20:00 M:2008-04-14 10:14]
[PID: 1780 / SYSTEM] C:\WINDOWS\system32\spoolsv.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852), C:2001-09-05 20:00 M:2008-04-14 10:14]
C:\WINDOWS\System32\spool\PRTPROCS\W32X86\filterpipelineprintproc.dll [Microsoft Corporation, 6.0.5824.16384 (winmain(wmbla).060911-0725), C:2007-12-15 02:21 M:2006-10-14 16:43]
[PID: 132 / 御龙氏] C:\WINDOWS\Explorer.EXE [(Verified)Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105), C:2001-09-05 20:00 M:2008-04-14 10:14]
C:\WINDOWS\system32\AcSignIcon.dll [(Verified)Autodesk, Inc., 17.1.51.0, C:2007-02-12 06:12 M:2007-02-12 06:12]
C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\MFC80U.DLL [Microsoft Corporation, 8.00.50727.42, C:2005-09-23 10:16 M:2005-09-23 10:16]
C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\MFC80CHS.DLL [Microsoft Corporation, 8.00.50727.42, C:2005-09-23 09:58 M:2005-09-23 09:58]
C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll [(Verified)Autodesk, Inc., 17.1.51.0, C:2007-02-12 06:06 M:2007-02-12 06:06]
D:\Program Files\360safe\safemon\safemon.dll [(Verified)360.CN, 4, 2, 0, 1005, C:2008-07-10 17:42 M:2008-07-10 17:42]
C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [(Verified)Autodesk, 17.1.51.0, C:2007-02-12 06:06 M:2007-02-12 06:06]
C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.DLL [Microsoft Corporation, 8.00.50727.42, C:2005-09-23 08:49 M:2005-09-23 08:49]
[PID: 412 / 御龙氏] C:\WINDOWS\system32\ctfmon.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105), C:2001-09-05 20:00 M:2008-04-14 10:13]
[PID: 808 / SYSTEM] d:\Program Files\StormII\stormliv.exe [(Verified)北京暴风网际科技有限公司, 3, 8, 3, 15, C:2008-03-11 14:33 M:2008-03-11 14:33]
[PID: 844 / SYSTEM] C:\Program Files\CMBCHINA\WebProtect\WPService.exe [(Verified)China Merchants Bank, 1, 0, 0, 1, C:2008-04-30 19:13 M:2007-08-27 16:35]
C:\Program Files\CMBCHINA\WebProtect\WebProtectPlus.dll [(Verified)China Merchants Bank, 1, 0, 0, 1, C:2008-04-30 19:13 M:2007-08-20 16:16]
[PID: 936 / SYSTEM] C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [(Verified)Microsoft Corporation, 7.00.9466, C:2003-06-19 23:25 M:2003-06-19 23:25]
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\2052\mdmui.dll [Microsoft Corporation, 7.00.9466, C:2002-01-29 15:06 M:2002-01-29 15:06]
[PID: 1400 / SYSTEM] D:\MSSQL7\binn\sqlservr.exe [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-27 23:43]
D:\MSSQL7\binn\opends60.dll [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-13 04:25]
D:\MSSQL7\binn\ums.dll [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-13 04:25]
D:\MSSQL7\binn\sqlevn70.dll [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-13 04:22]
D:\MSSQL7\binn\COMNEVNT.DLL [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:58 M:1998-11-13 04:22]
D:\MSSQL7\binn\SQLTrace.DLL [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-13 04:22]
D:\MSSQL7\binn\SSNMPN70.dll [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-13 04:25]
D:\MSSQL7\binn\SSMSSO70.dll [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-13 04:25]
D:\MSSQL7\binn\SSMSRP70.dll [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-13 04:25]
D:\MSSQL7\binn\SQLRGSTR.DLL [N/A, C:2007-12-25 20:58 M:1998-11-13 04:22]
D:\MSSQL7\binn\xpsqlbot.dll [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-13 04:25]
D:\MSSQL7\binn\sqlboot.dll [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-13 04:25]
[PID: 1720 / SYSTEM] C:\WINDOWS\System32\svchost.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111), C:2001-09-05 20:00 M:2008-04-14 10:14]
[PID: 1840 / SYSTEM] C:\WINDOWS\system32\ServerNT.EXE [N/A, C:2007-12-25 21:08 M:2002-09-22 15:33]
C:\WINDOWS\system32\UMiscell.dll [版权所有 (C) 2000, 1, 0, 0, 1, C:2007-12-25 21:05 M:2002-08-13 20:17]
C:\WINDOWS\system32\sgv.dll [版权所有 (C) 2002, 8, 2, 0, 0, C:2007-12-25 21:05 M:2002-01-18 17:24]
C:\WINDOWS\system\Sense3.dll [N/A, C:2007-12-20 16:06 M:2007-12-25 21:10]
C:\WINDOWS\system32\SecuComm.dll [N/A, C:2007-12-25 21:05 M:2001-02-20 14:42]
[PID: 1636 / SYSTEM] D:\MSSQL7\binn\sqlagent.exe [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-13 02:09]
D:\MSSQL7\binn\SQLWID.dll [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:58 M:1998-11-13 04:25]
D:\MSSQL7\binn\SQLSVC.dll [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:58 M:1998-11-13 04:22]
D:\MSSQL7\binn\SQLRESLD.dll [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:58 M:1998-11-13 04:22]
D:\MSSQL7\binn\W95SCM.dll [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:58 M:1998-11-13 04:22]
D:\MSSQL7\binn\COMNEVNT.dll [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:58 M:1998-11-13 04:22]
D:\MSSQL7\binn\SEMMAP.dll [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:58 M:1998-11-13 04:22]
D:\MSSQL7\binn\Resources\1033\SQLSVC.RLL [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:58 M:1998-11-13 04:22]
D:\MSSQL7\binn\Resources\1033\SEMMAP.RLL [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:58 M:1998-11-13 04:22]
D:\MSSQL7\binn\SQLAGENT.DLL [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-13 04:22]
D:\MSSQL7\BINN\SQLCMDSS.DLL [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-13 04:22]
D:\MSSQL7\BINN\SQLREPSS.DLL [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-13 04:22]
D:\MSSQL7\BINN\SQLATXSS.DLL [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:57 M:1998-11-13 04:22]
D:\MSSQL7\binn\AXSCPHST.DLL [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:58 M:1998-11-13 04:22]
D:\MSSQL7\binn\Resources\1033\AXSCPHST.RLL [Microsoft Corporation, 1998.11.13, C:2007-12-25 20:58 M:1998-11-13 04:22]
[PID: 2824 / LOCAL SERVICE] C:\WINDOWS\System32\alg.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852), C:2001-09-05 20:00 M:2008-04-14 10:13]
[PID: 3848 / 御龙氏] D:\Program Files\arswp\ArSwp.exe [(Verified)ArSwp.com, 2, 8, 1, 815, C:2008-10-09 23:11 M:2008-08-15 22:25]
D:\Program Files\360safe\safemon\safemon.dll [(Verified)360.CN, 4, 2, 0, 1005, C:2008-07-10 17:42 M:2008-07-10 17:42]
C:\WINDOWS\system32\AcSignIcon.dll [(Verified)Autodesk, Inc., 17.1.51.0, C:2007-02-12 06:12 M:2007-02-12 06:12]
C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\MFC80U.DLL [Microsoft Corporation, 8.00.50727.42, C:2005-09-23 10:16 M:2005-09-23 10:16]
C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\MFC80CHS.DLL [Microsoft Corporation, 8.00.50727.42, C:2005-09-23 09:58 M:2005-09-23 09:58]
D:\Program Files\arswp\plugin\ArFix.dll [(Verified)ArSwp.Com, 2, 5, 0, 0, C:2008-10-09 23:11 M:2007-11-28 15:19]
[PID: 3940 / SYSTEM] C:\WINDOWS\system32\wuauclt.exe [(Verified)Microsoft Corporation, 7.2.6001.784 (winmain_oob/wu_wsuswlc(wmbla).080718-1904), C:2007-12-14 20:32 M:2008-07-18 22:10]
[PID: 348 / NETWORK SERVICE] C:\WINDOWS\System32\wbem\wmiprvse.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108), C:2007-12-14 20:32 M:2008-04-14 10:14]
========================================
文件关联
========================================
AutoRun.INF
========================================
Winsock提供者
========================================
HOSTS
127.0.0.1 localhost
[/CODE]