==================================
启动文件夹
[IE-Bar]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\IE-Bar.lnk><H>
==================================
服务
[TP-LINK 配置服务 / ACS]
<C:\WINDOWS\system32\acs.exe><N/A>
[DefWatch / DefWatch]
<"C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[Symantec AntiVirus Client / Norton AntiVirus Server]
<"C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>
[SmartLinkService / SLService]
<slserv.exe><Smart Link>
[windowslogo / windowslogo]
<C:\WINDOWS\Winlogo.exe><N/A>
==================================
浏览器加载项
[ThunderMini Browser Helper]
{8E6C1C49-F9CE-4311-9FB4-D70E8B0AEAEB} <C:\Program Files\Thunder Network\ThunderMini\ComDlls\XunLeiMiniBHO_001.dll, Thunder Networking Technologies,LTD>
[Windows Live Sign-in Helper]
{9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
[NTIECatcher Class]
{C56CB6B0-0D96-11D6-8C65-B2868B609932} <C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll, Xi>
[BHelper Class]
{F2E37336-BFDB-409B-8D0E-6F013C438B20} <C:\WINDOWS\940o3aa0.dll, N/A>
[微软]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.microsoft.com/china/index.htm, N/A>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft? Corporation>
[CEditCtrl
Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\AliEdit.dll, www.alipay.com>
[CPasswordEditCtrl
Object]
{E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[Web Browser Applet Control]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\WINDOWS\system32\msjava.dll, Microsoft Corporation>
[BitComet工具栏]
{3F1ABCDB-A875-46C1-8345-B72A4567E486} <C:\Program Files\BitComet\BitCometBar\BitCometBar0.6.dll, N/A>
[ThunderMini Browser Helper]
{8E6C1C49-F9CE-4311-9FB4-D70E8B0AEAEB} <C:\Program Files\Thunder Network\ThunderMini\ComDlls\XunLeiMiniBHO_001.dll, Thunder Networking Technologies,LTD>
[Windows Live Sign-in Helper]
{9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[NTIECatcher Class]
{C56CB6B0-0D96-11D6-8C65-B2868B609932} <C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll, Xi>
[Shockwave Flash
Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\Flash85.ocx, Macromedia, Inc.>
[BHelper Class]
{F2E37336-BFDB-409B-8D0E-6F013C438B20} <C:\WINDOWS\940o3aa0.dll, N/A>
[&使用迷你迅雷下载]
<C:\Program Files\Thunder Network\ThunderMini\Program\GetUrl.htm, N/A>
[上传到QQ网络硬盘]
<C:\Program Files\QQ2005\AddToNetDisk.htm, N/A>
[使用影音传送带下载]
<C:\Program Files\Xi\NetTransport 2\NTAddLink.html, N/A>
[使用影音传送带下载全部链接]
<C:\Program Files\Xi\NetTransport 2\NTAddList.html, N/A>
[在Foxmail中添加该RSS频道/频道组]
<res://C:\WINDOWS\system32\fmrsslink.dll/201, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ表情]
<C:\Program Files\QQ2005\AddEmotion.htm, N/A>
==================================
正在运行的进程
[PID: 428][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 476][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 500][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\NavLogon.dll] <N/A><N/A>
[PID: 544][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 556][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 704][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 752][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 808][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 908][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 936][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1160][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\940d3aa0.dll] <N/A><N/A>
[C:\Program Files\Thunder Network\ThunderMini\ComDlls\XunLeiMiniBHO_001.dll] <Thunder Networking Technologies,LTD><2, 0, 0, 1>
[PID: 1248][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[C:\WINDOWS\system32\EBPMON24.DLL] <SEIKO EPSON CORPORATION><5, 4, 0, 0>
[PID: 1304][C:\WINDOWS\system32\acs.exe] <N/A><N/A>
[C:\WINDOWS\system32\athcfg11.dll] <Atheros><4.1.2.25>
[C:\WINDOWS\system32\athcfg11Res.dll] <Atheros Communications, Inc.><4.1.2.25>
[C:\WINDOWS\system32\athcfg11resloc.dll] <TP-LINK TECHNOLOGIES CO., LTD.><4.1.2.25>
[C:\WINDOWS\system32\AegisE5.dll] <Meetinghouse Data Communications><3, 0, 16, 0>
[PID: 1424][C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe] <Symantec Corporation><8.00.00.9374>
[PID: 1512][C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe] <Symantec Corporation><8.00.00.9374>
[C:\WINDOWS\system32\CBA.DLL] <Intel? Corporation><6.12.0.71 E>
[C:\WINDOWS\system32\MsgSys.dll] <Intel? Corporation><6.12.0.71 E>
[C:\WINDOWS\system32\NTS.dll] <Intel? Corporation><6.12.0.71 E>
[C:\WINDOWS\system32\PDS.DLL] <Intel? Corporation><6.12.0.71 E>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVLU.dll] <Symantec Corporation><8.00.00.9374>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVNTUTL.DLL] <Symantec/Peter Norton Group><1, 0, 0, 1>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\i2ldvp3.dll] <Symantec Corporation><8.00.00.9374>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPI32.DLL] <Symantec Corp.><4.1.0.15>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060809.018\NAVEX32a.DLL] <Symantec Corporation><20061.2.0.26>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060809.018\NAVENG32.DLL] <Symantec Corporation><20061.2.0.26>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAP32.DLL] <Symantec Corporation><9.0.0.14>
[PID: 1572][C:\WINDOWS\system32\slserv.exe] <Smart Link><3.80.01MC15>
[PID: 1604][C:\WINDOWS\system32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 1908][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 860][C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe] <Symantec Corporation><8.00.00.9374>
[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Cliscan.dll] <Symantec Corporation><8.00.00.9374>
[C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVNTUTL.DLL] <Symantec/Peter Norton Group><1, 0, 0, 1>
[PID: 1148][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3427>
[PID: 1436][C:\Program Files\TP-LINK\TWCU\TWCU.exe] <TP-LINK TECHNOLOGIES CO., LTD><4.1.2.25>
[C:\WINDOWS\system32\wcapi.dll] <Atheros><4.1.2.25>
[C:\WINDOWS\system32\athcfg11.dll] <Atheros><4.1.2.25>
[C:\WINDOWS\system32\athcfg11Res.dll] <Atheros Communications, Inc.><4.1.2.25>
[C:\WINDOWS\system32\wgapi.dll] <TP-LINK TECHNOLOGIES CO., LTD><4.1.2.25>
[C:\WINDOWS\system32\wgapiloc.dll] <TP-LINK><4.1.2.25>
[C:\Program Files\TP-LINK\TWCU\TWCUloc.dll] <TP-LINK TECHNOLOGIES CO., LTD.><4.1.2.25>
[C:\Program Files\TP-LINK\TWCU\oemresloc.dll] <TP-LINK TECHNOLOGIES CO., LTD.><4.1.2.25>
[PID: 1456][C:\Program Files\Thunder Network\ThunderMini\program\ThunderMini.exe] <Thunder Networking Technologies,LTD><2, 0, 0, 29>
[C:\Program Files\Thunder Network\ThunderMini\program\download_interface.dll] <N/A><N/A>
[C:\Program Files\Thunder Network\ThunderMini\program\UpdateDownload.dll] <Thunder Networking Technologies,LTD><1, 0, 1, 6>
[C:\Program Files\Thunder Network\ThunderMini\Components\InMedia\iEmbedShell.dll] < ><1, 0, 0, 6>
[C:\Program Files\Thunder Network\ThunderMini\Components\InMedia\iEmbed.dll] < ><2, 1, 0, 30>
[PID: 1560][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1728][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1508][C:\WINDOWS\system32\rundll32.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\DOCUME~1\new\TEMPLA~1\18a5393\1.dll] <千橡互联><3, 0, 1, 0>
[C:\DOCUME~1\new\TEMPLA~1\18a5393\3.dll] <千橡互联><3, 0, 1, 0>
[C:\DOCUME~1\new\TEMPLA~1\18a5393\4.dll] <千橡互联><3, 0, 1, 0>
[PID: 2464][C:\WINDOWS\system32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[PID: 2252][C:\Documents and Settings\new\桌面\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[PID: 2516][D:\Program Files\Maxthon\Maxthon.exe] <Maxthon International Ltd.><1, 5, 6, 42>
[D:\Program Files\Maxthon\maxzlib.dll] < ><1, 0, 0, 2>
[D:\Program Files\Maxthon\Services\RealTime\real_time.dll] <><1, 0, 0, 1>
==================================