[C:\Program Files\QBU\ComFnUtl.dll] [Dritek System Inc., 1.00]
[C:\Program Files\QBU\Wnd2File.dll] [Dritek System Inc., 3.00]
[C:\Program Files\QBU\SzUPFUtl.dll] [Dritek System Inc., 1.00]
[C:\Program Files\QBU\OSDUtl.dll] [Dritek System Inc., 1, 0, 0, 312]
[C:\Program Files\QBU\RgnMaker.dll] [Dritek System Inc., 12.07.1999 ( VC60 )]
[C:\Program Files\QBU\CDRomUtl.dll] [Dritek System Inc., 1.00]
[C:\Program Files\QBU\MixerUtl.dll] [Dritek System Inc., 1.00]
[C:\Program Files\QBU\LgKCUtl.dll] [Dritek System Inc., 2, 0, 1, 1]
[C:\Program Files\QBU\MMDUtl.dll] [Dritek System Inc., 1, 2, 3, 2719]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 3216][D:\SOFT\Google Pinyin\GooglePinyinDaemon.exe] [Google Inc., 1, 0, 0, 1]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[C:\WINDOWS\system32\GooglePinyin.ime] [Google Inc., ]
[PID: 3228][C:\Program Files\AVC Finger-sensing Pad Driver\fscp.exe] [N/A, ]
[PID: 3244][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3252][C:\Program Files\Messenger\msmsgs.exe] [Microsoft Corporation, 4.7.3001]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[PID: 3292][D:\SOFT\Yahoo! Widget Engine\YahooWidgetEngine.exe] [Yahoo! Inc., 3.1.4]
[D:\SOFT\Yahoo! Widget Engine\js32.dll] [N/A, ]
[D:\SOFT\Yahoo! Widget Engine\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[D:\SOFT\Yahoo! Widget Engine\LIBEAY32.dll] [The OpenSSL Project, http://www.openssl.org/, 0.9.8a]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[PID: 3436][D:\SOFT\Yahoo! Widget Engine\YahooWidgetEngine.exe] [Yahoo! Inc., 3.1.4]
[D:\SOFT\Yahoo! Widget Engine\js32.dll] [N/A, ]
[D:\SOFT\Yahoo! Widget Engine\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[D:\SOFT\Yahoo! Widget Engine\LIBEAY32.dll] [The OpenSSL Project, http://www.openssl.org/, 0.9.8a]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[D:\SOFT\Yahoo! Widget Engine\WLive.dll] [, 1, 0, 0, 1001]
[PID: 3448][D:\SOFT\Yahoo! Widget Engine\YahooWidgetEngine.exe] [Yahoo! Inc., 3.1.4]
[D:\SOFT\Yahoo! Widget Engine\js32.dll] [N/A, ]
[D:\SOFT\Yahoo! Widget Engine\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[D:\SOFT\Yahoo! Widget Engine\LIBEAY32.dll] [The OpenSSL Project, http://www.openssl.org/, 0.9.8a]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[D:\SOFT\Yahoo! Widget Engine\WLive.dll] [, 1, 0, 0, 1001]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[E:\music\KuGoo3\mp3parse.dll] [ , 1, 0, 2, 1]
[E:\music\KuGoo3\kgmpg.dll] [ , 1, 0, 4, 1]
[PID: 3456][D:\SOFT\Yahoo! Widget Engine\YahooWidgetEngine.exe] [Yahoo! Inc., 3.1.4]
[D:\SOFT\Yahoo! Widget Engine\js32.dll] [N/A, ]
[D:\SOFT\Yahoo! Widget Engine\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[D:\SOFT\Yahoo! Widget Engine\LIBEAY32.dll] [The OpenSSL Project, http://www.openssl.org/, 0.9.8a]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[D:\SOFT\Yahoo! Widget Engine\WLive.dll] [, 1, 0, 0, 1001]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 3680][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3036][C:\Program Files\锐捷网络\Ruijie Supplicant\8021x.exe] [锐捷网络, 3, 2, 0, 0]
[C:\WINDOWS\system32\W32N50.dll] [Printing Communications Assoc., Inc. (PCAUSA), 5.03.16.54]
[C:\PROGRA~1\锐捷网络\RUIJIE~1\EXRGPA~1.OCX] [锐捷网络, 1, 0, 0, 1]
[C:\PROGRA~1\锐捷网络\RUIJIE~1\HIDetect.dll] [锐捷网络, 1, 0, 0, 1]
[C:\PROGRA~1\锐捷网络\RUIJIE~1\Vx_API.dll] [锐捷网络, 1, 0, 0, 1]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[PID: 2544][D:\SOFT\Tencent\QQ\TMDlls\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[D:\SOFT\Tencent\QQ\TMDlls\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 236][D:\SOFT\Maxthon2.0\Maxthon.exe] [Maxthon International ltd., 2, 0, 2, 615]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[D:\SOFT\Maxthon2.0\mxpp.dll] [Maxthon, 1, 0, 0, 50]
[D:\SOFT\Maxthon2.0\MxSk.dll] [Maxthon, 1, 0, 0, 119]
[D:\SOFT\Maxthon2.0\MxProxy2.dll] [, 1, 0, 0, 3115]
[D:\SOFT\Maxthon2.0\MxFav.dll] [Maxthon, 1, 0, 0, 186]
[D:\SOFT\Maxthon2.0\maxzlib.dll] [, 1.2.3]
[D:\SOFT\Kingsoft\Powerword 2007\atl.dll] [Microsoft Corporation, 3.00.9435]
[D:\SOFT\Maxthon2.0\mxtool.dll] [, 1, 0, 0, 1]
[D:\SOFT\Maxthon2.0\mxfeedU.dll] [, 1, 0, 45, 45]
[C:\WINDOWS\system32\msxml4.dll] [Microsoft Corporation, 4.20.9818.0]
[C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Internet Explorer\ieproxy.dll] [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[PID: 652][C:\Program Files\360safe\360Safe.exe] [奇虎网, 3, 4, 0, 1002]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\Program Files\360safe\AntiAdwa.dll] [360Safe.com, 3, 4, 0, 1001]
[C:\Program Files\360safe\AntiEng.dll] [360Safe.com, 3, 4, 0, 1001]
[C:\Program Files\360safe\Antispy.dll] [奇虎网, 3, 4, 0, 1001]
[C:\Program Files\360safe\LeakCheck.dll] [360Safe.com, 3, 4, 0, 1002]
[C:\Program Files\360safe\CleanHis.dll] [奇虎网, 3, 0, 2, 1000]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[C:\Program Files\360safe\AntiActi.dll] [360Safe.com, 2, 0, 0, 3000]
[C:\Program Files\360safe\live.dll] [360safe.com, 1, 0, 1, 1015]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 2440][D:\SOFT\sreng2.4\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
[3645] C:\Program Files\Tencent\QQ\QQ.exe
==================================
[/CODE]
隐藏进程???
XK5C+&dotÑÀbbs.ikaka.comïÝÓM3ØB«îu