正在运行的进程
[PID: 344][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 456][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 480][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.1557 (xpsp2_gdr.040517-1325)>
[C:\WINDOWS\System32\klogon.dll] <Kaspersky Lab><6.0.0.299>
[PID: 524][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 536][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 696][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 760][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 840][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 872][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1072][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.1699 (xpsp2.050610-1533)>
[PID: 1240][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1288][C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE] <C-Dilla Ltd><3.25.010>
[PID: 1328][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE] <Microsoft Corporation><7.00.9466>
[PID: 1360][C:\WINDOWS\System32\nvsvc32.exe] <NVIDIA Corporation><6.14.10.5303>
[PID: 1424][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\WINDOWS\System32\nvshell.dll] <NVIDIA Corporation><6.14.10.5303>
[C:\WINDOWS\System32\NVWRSZHC.DLL] <NVIDIA Corporation><6.14.10.5303>
[C:\PROGRA~1\baidu\bar\baidubar.dll] <Baidu.com, Inc.><2, 0, 2, 99>
[PID: 1308][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 432][F:\angelgao wg\木马杀客\木马杀客\mmsk.exe] <木马杀客><2,0,0,6>
[F:\angelgao wg\木马杀客\木马杀客\krnln.fnr] <><1, 0, 0, 1>
[F:\angelgao wg\木马杀客\木马杀客\iext2.fne] <><1, 0, 0, 1>
[F:\angelgao wg\木马杀客\木马杀客\iext.fne] <><1, 0, 0, 1>
[F:\angelgao wg\木马杀客\木马杀客\HYExtLib.fne] <N/A><N/A>
[F:\angelgao wg\木马杀客\木马杀客\HtmlView.fne] <><1, 0, 0, 1>
[F:\angelgao wg\木马杀客\木马杀客\TrayIcon.fne] <><1, 0, 0, 1>
[F:\angelgao wg\木马杀客\木马杀客\iext3.fne] <><1, 0, 0, 1>
[F:\angelgao wg\木马杀客\木马杀客\xplib.fne] <N/A><N/A>
[F:\angelgao wg\木马杀客\木马杀客\mmskskin.dll] <><2, 0, 0, 6>
[F:\angelgao wg\木马杀客\木马杀客\SkinPPWTL.dll] <http://www.skinplusplus.com><2, 1, 0, 0>
[F:\angelgao wg\木马杀客\木马杀客\shell.fne] <N/A><N/A>
[F:\angelgao wg\木马杀客\木马杀客\EThread.fne] <N/A><N/A>
[F:\angelgao wg\木马杀客\木马杀客\dp1.fne] <N/A><N/A>
[F:\angelgao wg\木马杀客\木马杀客\eAPI.fne] <><1, 0, 0, 1>
[E:\卡巴斯基\Kaspersky Anti-Virus Personal\scr_ch_pg.dll] <Kaspersky Lab><1.0.6.299>
[E:\卡巴斯基\Kaspersky Anti-Virus Personal\klscav.dll] <Kaspersky Lab><6.0.0.299>
[E:\卡巴斯基\Kaspersky Anti-Virus Personal\pr_remote.dll] <Kaspersky Lab><6.0.0.299>
[E:\卡巴斯基\Kaspersky Anti-Virus Personal\prloader.dll] <Kaspersky Lab><6.0.0.299>
[E:\卡巴斯基\Kaspersky Anti-Virus Personal\prkernel.ppl] <Kaspersky Lab><6.0.0.299>
[e:\卡巴斯基\kaspersky anti-virus personal\params.ppl] <Kaspersky Lab><6.0.0.299>
[e:\卡巴斯基\kaspersky anti-virus personal\pxstub.ppl] <Kaspersky Lab><6.0.0.299>
[e:\卡巴斯基\kaspersky anti-virus personal\tempfile.ppl] <Kaspersky Lab><6.0.0.299>
[e:\卡巴斯基\kaspersky anti-virus personal\nfio.ppl] <Kaspersky Lab><6.0.0.299>
[e:\卡巴斯基\kaspersky anti-virus personal\fsdrvplgn.ppl] <Kaspersky Lab><6.0.0.299>
[PID: 1032][F:\anycal soft\foobar\foobar2000\foobar2000.exe] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\utf8api.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_ui_std.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_input_std.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_output_std.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_vis_manager.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_ui_columns.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_uie_tabs.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_uie_albumlist.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_uie_dbexplorer.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_uie_volume.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_uie_simple_spectrum.dll] < ><0, 1, 6, 1>
[F:\anycal soft\foobar\foobar2000\components\foo_cdda.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_flac.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_ape.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_wavpack.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_speex.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_dumb.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_wma.dll] <><1.0.9>
[F:\anycal soft\foobar\foobar2000\components\foo_spc.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_ac3.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_nez.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_matroska.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_ofr.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\OptimFROG.dll] <Florin Ghido, FlorinGhido@yahoo.com><1.100>
[F:\anycal soft\foobar\foobar2000\components\foo_out_dsound_ex.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_out_dsound_ex2.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_out_ks.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_console.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_read_http.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_rgscan.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_albumlist.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_masstag.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_codepage_action.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_infobox.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_shuffle.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_unpack.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_id3v2.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_burninate.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_syfm.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_freedb.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_scheduler.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_playlistgen.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_dsp_extra.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_dsp_soundtouch.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_dsp_pause.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_convolve.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_diskwriter.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_m
onkey.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_faac.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_clienc.dll] <N/A><N/A>
[F:\anycal soft\foobar\foobar2000\components\foo_shell.dll] <N/A><N/A>
[PID: 2784][C:\WINDOWS\System32\rundll32.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\DOCUME~1\BLUEWA~1\TEMPLA~1\2f8c51d\1.dll] <千橡互联><3, 0, 1, 0>
[C:\DOCUME~1\BLUEWA~1\TEMPLA~1\2f8c51d\3.dll] <千橡互联><3, 0, 1, 0>
[C:\DOCUME~1\BLUEWA~1\TEMPLA~1\2f8c51d\4.dll] <千橡互联><3, 0, 1, 0>
[PID: 2840][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 3068][F:\angelgao wg\System Repair Engineer\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS Error. ["E:\asp\Dreamweaver MX\Dreamweaver.exe" "%1"]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]