==================================
正在运行的进程
[PID: 604][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 664][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 688][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 6.0.0.299]
[PID: 744][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[PID: 756][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[PID: 936][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[PID: 1012][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[PID: 1116][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[D:\新建文件夹\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
[PID: 1168][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[PID: 1228][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[PID: 1572][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[PID: 1816][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[C:\PROGRA~1\Yahoo!\ASSIST~1\yclickon.dll] [YAHOO Corporation Limited, 2, 0, 1, 1002]
[C:\WINDOWS\DOWNLO~1\CnsHook.dll] [北京三七二一科技有限公司, 1, 0, 4, 2]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll] [Yahoo! China, 2, 0, 4, 1007]
[C:\Program Files\Internet Explorer\PLUGINS\System8.sys] [N/A, N/A]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 4, 1]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[C:\PROGRA~1\3721\alrex.dll] [, 1, 0, 1, 1001]
[D:\新建文件夹\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
[C:\PROGRA~1\3721\autolive.dll] [, 1, 2, 0, 1330]
[C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll] [Yahoo! China, 1, 1, 3, 1035]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll] [Yahoo!, 2, 1, 9, 1049]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] [, 1, 2, 7, 1006]
[D:\迅雷\ComDlls\XunLeiBHO_002.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
[C:\WINDOWS\system32\zkbaidubho.dll] [baiduu, 1.02.0081]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[D:\新建文件夹\shellex.dll] [Kaspersky Lab, 6.0.0.299]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll] [N/A, 1, 0, 1, 1014]
[PID: 1864][C:\WINDOWS\system32\Rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 4, 1]
[C:\WINDOWS\DOWNLO~1\CnsMinIO.dll] [北京三七二一科技有限公司, 1, 0, 3, 7]
[C:\WINDOWS\DOWNLO~1\cnsio.dll] [北京三七二一科技有限公司, 1, 0, 2, 8]
[D:\新建文件夹\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
[C:\WINDOWS\DOWNLO~1\CnsMinEx.dll] [国风因特软件(北京)有限公司, 1, 0, 3, 5]
[C:\Program Files\Internet Explorer\PLUGINS\System8.sys] [N/A, N/A]
[PID: 180][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[PID: 1728][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[PID: 1400][C:\WINDOWS\system32\RunDll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[C:\WINDOWS\system\cmicnfg.cpl] [C-Media Corporation, 1, 0, 41, 25]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 4, 1]
[C:\Program Files\Internet Explorer\PLUGINS\System8.sys] [N/A, N/A]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[C:\WINDOWS\System32\udaprop.dll] [C-Media Corporation, 1.0.2.2]
[PID: 1664][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 4, 1]
[C:\Program Files\Internet Explorer\PLUGINS\System8.sys] [N/A, N/A]
[C:\PROGRA~1\3721\autolive.dll] [, 1, 2, 0, 1330]
[C:\PROGRA~1\3721\notifier.dll] [, 1, 0, 0, 5]
[D:\新建文件夹\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
[C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006]
[PID: 2080][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mhs2.exe] [N/A, N/A]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mhs2.dll] [N/A, N/A]
[PID: 2180][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rxzs.exe] [N/A, N/A]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rxzs.dll] [N/A, N/A]
[PID: 2232][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wlzs.exe] [N/A, N/A]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wlzs.dll] [N/A, N/A]
[PID: 2280][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\zts2.exe] [N/A, N/A]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\zts2.dll] [N/A, N/A]
[PID: 2364][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 4, 1]
[C:\Program Files\Internet Explorer\PLUGINS\System8.sys] [N/A, N/A]
[PID: 3928][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 4, 1]
[C:\Program Files\Internet Explorer\PLUGINS\System8.sys] [N/A, N/A]
[PID: 1644][D:\遨游\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 5, 8, 116]
[D:\遨游\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 4, 1]
[D:\遨游\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[D:\新建文件夹\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
[D:\新建文件夹\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299]
[D:\新建文件夹\klscav.dll] [Kaspersky Lab, 6.0.0.299]
[D:\新建文件夹\pr_remote.dll] [Kaspersky Lab, 6.0.0.299]
[D:\新建文件夹\prloader.dll] [Kaspersky Lab, 6.0.0.299]
[D:\新建文件夹\prkernel.ppl] [Kaspersky Lab, 6.0.0.304]
[d:\新建文件夹\params.ppl] [Kaspersky Lab, 6.0.0.299]
[d:\新建文件夹\pxstub.ppl] [Kaspersky Lab, 6.0.0.299]
[d:\新建文件夹\tempfile.ppl] [Kaspersky Lab, 6.0.0.299]
[d:\新建文件夹\nfio.ppl] [Kaspersky Lab, 6.0.0.299]
[d:\新建文件夹\fsdrvplgn.ppl] [Kaspersky Lab, 6.0.0.299]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[C:\Program Files\Internet Explorer\PLUGINS\System8.sys] [N/A, N/A]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll] [Yahoo! China, 2, 0, 4, 1007]
[PID: 2720][C:\WINDOWS\system32\Serverx.exe] [N/A, N/A]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[PID: 3816][C:\WINDOWS\svchost.exe] [1, 1.00]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 4, 1]
[C:\Program Files\Internet Explorer\PLUGINS\System8.sys] [N/A, N/A]
[PID: 2880][D:\新建文件夹 (2)\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\WINDOWS\455373M.BMP] [N/A, N/A]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 4, 1]
[C:\Program Files\Internet Explorer\PLUGINS\System8.sys] [N/A, N/A]
[D:\新建文件夹\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
[C:\]
[AutoRun]
open=tel.xls.exe
shellexecute=tel.xls.exe
shell\Auto\command=tel.xls.exe
shell=Auto
[D:\]
[AutoRun]
open=tel.xls.exe
shellexecute=tel.xls.exe
shell\Auto\command=tel.xls.exe
shell=Auto
[E:\]
[AutoRun]
open=tel.xls.exe
shellexecute=tel.xls.exe
shell\Auto\command=tel.xls.exe
shell=Auto
[F:\]
[AutoRun]
open=tel.xls.exe
shellexecute=tel.xls.exe
shell\Auto\command=tel.xls.exe
shell=Auto
==================================
HOSTS 文件
127.0.0.1 localhost
==================================