==================================
正在运行的进程
[PID: 464][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 596][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Windowsmmqdf\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.55]
[C:\Program Files\Windowsmmqdf\PassProtect.dll] [Fygsoft and Microsoft, 2.1.0.98]
[C:\Program Files\Windowsmmqdf\Filehook.dll] [Fygsoft and Microsoft, 2.1.0.0]
[C:\Program Files\Windowsmmqdf\SocketMon.dll] [Fygsoft and Microsoft, 1.1.1.0]
[PID: 1672][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Windowsmmqdf\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.55]
[C:\Program Files\Windowsmmqdf\PassProtect.dll] [Fygsoft and Microsoft, 2.1.0.98]
[C:\Program Files\Windowsmmqdf\Filehook.dll] [Fygsoft and Microsoft, 2.1.0.0]
[C:\Program Files\Windowsmmqdf\SocketMon.dll] [Fygsoft and Microsoft, 1.1.1.0]
[D:\FastCopy-v1.51H\fastext1.dll] [SHIROUZU Hiroaki, 1, 3, 0, 0]
[PID: 1800][C:\Program Files\Windowsmmqdf\Trojanwall.exe] [风云谷, 5.5.0.1916]
[C:\Program Files\Windowsmmqdf\ftcapi.dll] [fygsoft, 1.1.0.0]
[C:\Program Files\Windowsmmqdf\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.55]
[C:\Program Files\Windowsmmqdf\PassProtect.dll] [Fygsoft and Microsoft, 2.1.0.98]
[C:\Program Files\Windowsmmqdf\Filehook.dll] [Fygsoft and Microsoft, 2.1.0.0]
[C:\Program Files\Windowsmmqdf\SocketMon.dll] [Fygsoft and Microsoft, 1.1.1.0]
[C:\Program Files\Windowsmmqdf\PSAPI.dll] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1436][C:\Program Files\ppntv\ppntv.exe] [www.PPNTV.com, 3.0.0.7330]
[C:\Program Files\Windowsmmqdf\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.55]
[C:\Program Files\Windowsmmqdf\PassProtect.dll] [Fygsoft and Microsoft, 2.1.0.98]
[C:\Program Files\Windowsmmqdf\Filehook.dll] [Fygsoft and Microsoft, 2.1.0.0]
[C:\Program Files\Windowsmmqdf\SocketMon.dll] [Fygsoft and Microsoft, 1.1.1.0]
[C:\Program Files\KAV6\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299]
[C:\Program Files\KAV6\klscav.dll] [Kaspersky Lab, 6.0.0.299]
[C:\Program Files\Ringz Studio\Storm Codec\Codecs\VSFilter.dll] [Gabest, 1, 0, 1, 3]
[C:\WINDOWS\system32\msvcr71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\KAV6\prloader.dll] [Kaspersky Lab, 6.0.0.299]
[C:\Program Files\ppntv\Modules\itv\pCastCtl.dll] [, 1,0,0,95]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\DOWNLO~1\CONFLICT.1\KOOPLA~1.OCX] [Koos, 1, 0, 0, 66]
[PID: 268][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Windowsmmqdf\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.55]
[C:\Program Files\Windowsmmqdf\PassProtect.dll] [Fygsoft and Microsoft, 2.1.0.98]
[C:\Program Files\Windowsmmqdf\Filehook.dll] [Fygsoft and Microsoft, 2.1.0.0]
[C:\Program Files\Windowsmmqdf\SocketMon.dll] [Fygsoft and Microsoft, 1.1.1.0]
[C:\Program Files\KAV6\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299]
[C:\Program Files\KAV6\klscav.dll] [Kaspersky Lab, 6.0.0.299]
[C:\Program Files\KAV6\prloader.dll] [Kaspersky Lab, 6.0.0.299]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\WINDOWS\system32\UNISPIM5.IME] [北京紫光华宇软件股份有限公司, 5.0.0.5091]
[C:\WINDOWS\system32\CHENHU4.IME] [chenhu, 5.8]
[PID: 1444][C:\Program Files\Adobe\Photoshop CS\Photoshop.exe] [Adobe Systems, Incorporated, 8.0.1 (8.0x125)]
[C:\Program Files\Adobe\Photoshop CS\UID.mr.dll] [Adobe Systems, Inc., 1, 1, 0, 0]
[C:\Program Files\Adobe\Photoshop CS\AWSCommonUI.dll] [Adobe Systems, Incorporated, 3.0.0.432]
[C:\Program Files\Adobe\Photoshop CS\AWSSCL.dll] [Adobe Systems, 4.0.0.34]
[C:\Program Files\Adobe\Photoshop CS\WebAccessUtils.dll] [Adobe Systems, Incorporated, 3.0.0.432]
[C:\Program Files\Adobe\Photoshop CS\BIBUtils.dll] [Adobe Systems Incorporated, 1.00.0]
[C:\Program Files\Windowsmmqdf\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.55]
[C:\Program Files\Windowsmmqdf\PassProtect.dll] [Fygsoft and Microsoft, 2.1.0.98]
[C:\Program Files\Windowsmmqdf\Filehook.dll] [Fygsoft and Microsoft, 2.1.0.0]
[C:\Program Files\Windowsmmqdf\SocketMon.dll] [Fygsoft and Microsoft, 1.1.1.0]
[C:\Program Files\Adobe\Photoshop CS\Photoshop.dll] [, ]
[C:\Program Files\Adobe\Photoshop CS\PSViews.dll] [Adobe Systems, Incorporated, 8.0.1 (8.0x125)]
[C:\Program Files\Adobe\Photoshop CS\PSArt.dll] [Adobe Systems, Incorporated, 8.0.1 (8.0x125)]
[C:\Program Files\Adobe\Photoshop CS\asn.er.dll] [Adobe Systems Incorporated, 1.51x3, EndUser, Release]
[C:\Program Files\Adobe\Photoshop CS\ExtendScriptIDE.dll] [Adobe Systems, Incorporated, 3.2.21]
[C:\Program Files\Adobe\Photoshop CS\ExtendScript.dll] [Adobe Systems, Incorporated, 3.2.21]
[C:\Program Files\Adobe\Photoshop CS\ScCore.dll] [Adobe Systems, Incorporated, 3.2.21]
[C:\Program Files\Adobe\Photoshop CS\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[C:\Program Files\Adobe\Photoshop CS\Plug-Ins\扩展\FastCore.8BX] [Adobe Systems, Incorporated, 8.0.1 (8.0x126)]
[C:\Program Files\Adobe\Photoshop CS\PLUGIN.dll] [Adobe Systems, Incorporated, 8.0.1 (8.0x125)]
[C:\Program Files\Adobe\Photoshop CS\Plug-Ins\扩展\MMXCore.8BX] [Adobe Systems, Incorporated, 8.0.1 (8.0x126)]
[C:\Program Files\Adobe\Photoshop CS\Required\ADMPlugin.apl] [Adobe Systems Incorporated, 2.84pe69a 02.06.17-00:03:36h]
[C:\Program Files\Adobe\Photoshop CS\Required\PNGIcons.apl] [Adobe Systems Incorporated, 1.21x7 2001.12.14-1602h.21s]
[C:\Program Files\Adobe\Photoshop CS\Required\ASDataStream.apl] [Adobe Systems Incorporated, 1.02x7 02.02.15-01:45:06h]
[C:\Program Files\Adobe\Photoshop CS\Plug-Ins\解析程序\PDF 增效工具.8BI] [Adobe Systems, Incorporated, 8.0.1 (8.0x126)]
[C:\Program Files\Adobe\Photoshop CS\BIB.dll] [Adobe Systems Incorporated, 1.1.16]
[C:\Program Files\Adobe\Photoshop CS\JP2KLib.dll] [Adobe systems Incorporated, 1.0.28706]
[C:\Program Files\Adobe\Photoshop CS\Plug-Ins\文件格式\Camera Raw.8BI] [Adobe Systems Incorporated, 2.0]
[C:\Program Files\Adobe\Photoshop CS\ACE.dll] [Adobe Systems Incorporated, 2.05.16]
[C:\Program Files\Adobe\Photoshop CS\AGM.dll] [Adobe Systems Incorporated, 4.12.36]
[C:\Program Files\Adobe\Photoshop CS\CoolType.dll] [Adobe Systems Incorporated, 4.14.20]
[C:\WINDOWS\system32\ATMLIB.dll] [Adobe Systems, 5.1 Build 226]
[C:\Program Files\Adobe\Photoshop CS\AWSCommonSymbols.dll] [Adobe Systems, Incorporated, 3.0.0.432]
[C:\Program Files\Adobe\Photoshop CS\ARM.dll] [Adobe Systems, Incorporated, 3.0.0.432]
[C:\Program Files\Adobe\Photoshop CS\shfolder.dll] [Microsoft Corporation, 5.50.4027.300]
[C:\Program Files\Adobe\Photoshop CS\FileInfo.dll] [Adobe Systems, Incorporated, 3.0.0.432]
[C:\Program Files\Adobe\Photoshop CS\Plug-Ins\Adobe Photoshop Only\自动\脚本支持.8li] [Adobe Systems Incorporated, 8.0]
[C:\Program Files\Adobe\Photoshop CS\Tw10122.dat] [Adobe Systems, Incorporated, 8.0.1 (8.0x125)]
[PID: 3808][C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE] [Microsoft Corporation, 11.0.8106]
[C:\Program Files\Windowsmmqdf\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.55]
[C:\Program Files\Windowsmmqdf\PassProtect.dll] [Fygsoft and Microsoft, 2.1.0.98]
[C:\Program Files\Windowsmmqdf\Filehook.dll] [Fygsoft and Microsoft, 2.1.0.0]
[C:\Program Files\Windowsmmqdf\SocketMon.dll] [Fygsoft and Microsoft, 1.1.1.0]
[C:\WINDOWS\system32\CHENHU4.IME] [chenhu, 5.8]
[C:\Program Files\Microsoft Office\OFFICE11\GdiPlus.DLL] [Microsoft Corporation, 6.0.3275.0]
[C:\Program Files\Common Files\Microsoft Shared\PROOF\mslid.dll] [Microsoft Corporation, 1.0.2305]
[C:\Program Files\Common Files\Microsoft Shared\PROOF\2052\MSGR3EN.DLL] [Microsoft Corporation, 3.1.2303]
[PID: 840][d:\Temp\Rar$EX00.885\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\Program Files\Windowsmmqdf\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.55]
[C:\Program Files\Windowsmmqdf\PassProtect.dll] [Fygsoft and Microsoft, 2.1.0.98]
[C:\Program Files\Windowsmmqdf\Filehook.dll] [Fygsoft and Microsoft, 2.1.0.0]
[C:\Program Files\Windowsmmqdf\SocketMon.dll] [Fygsoft and Microsoft, 1.1.1.0]
==================================
文件关联
N/A
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
隐藏进程
[1880] c:\windows\system32\webpnt.exe