=================================
正在运行的进程
[PID: 380][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 436][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 460][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4117]
[C:\WINDOWS\system32\JJN.IME] [加加在线, 3.11.0.0]
[PID: 504][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 516][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 676][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4117]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2497]
[PID: 688][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 752][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 828][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 884][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 916][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1140][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1308][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4117]
[C:\WINDOWS\system32\JJN.IME] [加加在线, 3.11.0.0]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2497]
[PID: 1408][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\JJN.IME] [加加在线, 3.11.0.0]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll] [Anti-Malware Development a.s., 7, 5, 0, 49]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[PID: 1492][C:\Program Files\JJOL\IME\JJSvr.EXE] [加加在线, 3.11.0.1]
[C:\WINDOWS\system32\JJN.IME] [加加在线, 3.11.0.0]
[PID: 1572][D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe] [Anti-Malware Development a.s., 7, 5, 0, 47]
[D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll] [Anti-Malware Development a.s., 4, 2, 0, 15]
[PID: 1620][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\JJN.IME] [加加在线, 3.11.0.0]
[PID: 1724][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 2032][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\JJN.IME] [加加在线, 3.11.0.0]
[PID: 3860][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\JJN.IME] [加加在线, 3.11.0.0]
[C:\WINDOWS\system32\macromed\flash\Flash85.ocx] [Macromedia, Inc., 8,5,0,133]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[PID: 908][C:\DOCUME~1\cyt\LOCALS~1\Temp\mhh.exe] [N/A, N/A]
[C:\DOCUME~1\cyt\LOCALS~1\Temp\mhs2.dll] [N/A, N/A]
[PID: 2656][C:\DOCUME~1\cyt\LOCALS~1\Temp\ztt.exe] [N/A, N/A]
[C:\DOCUME~1\cyt\LOCALS~1\Temp\zts2.dll] [N/A, N/A]
[PID: 3120][C:\DOCUME~1\cyt\LOCALS~1\Temp\wll.exe] [N/A, N/A]
[C:\DOCUME~1\cyt\LOCALS~1\Temp\wlzs.dll] [N/A, N/A]
[PID: 3780][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\JJN.IME] [加加在线, 3.11.0.0]
[PID: 1508][C:\DOCUME~1\cyt\LOCALS~1\Temp\ztt.exe] [N/A, N/A]
[PID: 1064][C:\DOCUME~1\cyt\LOCALS~1\Temp\mhh.exe] [N/A, N/A]
[PID: 3636][C:\DOCUME~1\cyt\LOCALS~1\Temp\wll.exe] [N/A, N/A]
[PID: 4424][C:\DOCUME~1\cyt\LOCALS~1\Temp\ztt.exe] [N/A, N/A]
[PID: 4536][C:\DOCUME~1\cyt\LOCALS~1\Temp\mhh.exe] [N/A, N/A]
[PID: 956][C:\DOCUME~1\cyt\LOCALS~1\Temp\wll.exe] [N/A, N/A]
[PID: 3168][C:\DOCUME~1\cyt\LOCALS~1\Temp\ztt.exe] [N/A, N/A]
[PID: 3568][C:\DOCUME~1\cyt\LOCALS~1\Temp\wll.exe] [N/A, N/A]
[PID: 1680][C:\DOCUME~1\cyt\LOCALS~1\Temp\mhh.exe] [N/A, N/A]
[PID: 4456][C:\DOCUME~1\cyt\LOCALS~1\Temp\wll.exe] [N/A, N/A]
[PID: 5364][C:\DOCUME~1\cyt\LOCALS~1\Temp\ztt.exe] [N/A, N/A]
[PID: 5572][C:\DOCUME~1\cyt\LOCALS~1\Temp\mhh.exe] [N/A, N/A]
[PID: 3040][C:\DOCUME~1\cyt\LOCALS~1\Temp\mhh.exe] [N/A, N/A]
[PID: 3528][C:\DOCUME~1\cyt\LOCALS~1\Temp\ztt.exe] [N/A, N/A]
[PID: 4796][C:\DOCUME~1\cyt\LOCALS~1\Temp\wll.exe] [N/A, N/A]
[PID: 2188][C:\DOCUME~1\cyt\LOCALS~1\Temp\mhh.exe] [N/A, N/A]
[PID: 836][C:\DOCUME~1\cyt\LOCALS~1\Temp\wll.exe] [N/A, N/A]
[PID: 5872][C:\DOCUME~1\cyt\LOCALS~1\Temp\ztt.exe] [N/A, N/A]
[PID: 1052][C:\WINDOWS\system32\Thunder5.exe] [N/A, N/A]
[PID: 2632][C:\DOCUME~1\cyt\LOCALS~1\Temp\mhh.exe] [N/A, N/A]
[PID: 2572][C:\DOCUME~1\cyt\LOCALS~1\Temp\ztt.exe] [N/A, N/A]
[PID: 3232][C:\DOCUME~1\cyt\LOCALS~1\Temp\wll.exe] [N/A, N/A]
[PID: 1276][C:\DOCUME~1\cyt\LOCALS~1\Temp\kap.exe] [N/A, N/A]
[PID: 3600][C:\WINDOWS\system32\drivers\spcolsv.exe] [N/A, N/A]
[C:\WINDOWS\system32\SrvDll.dll] [N/A, N/A]
[PID: 1784][C:\WINDOWS\system32\Thunder5.exe] [N/A, N/A]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[PID: 3888][C:\Program Files\WinRAR\WinRAR.exe] [N/A, N/A]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\JJN.IME] [加加在线, 3.11.0.0]
[PID: 5884][C:\DOCUME~1\cyt\LOCALS~1\Temp\Rar$EX00.500\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\JJN.IME] [加加在线, 3.11.0.0]
[C:\WINDOWS\system32\SrvDll.dll] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
IP
C:\WINDOWS\system32\SrvDll.dll(N/A, N/A)
UDP_CHAIN
C:\WINDOWS\system32\SrvDll.dll(N/A, N/A)
==================================
Autorun.inf
[C:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
[D:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
[E:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
[F:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe