[C:\Program Files\Trend Micro\OfficeScan Client\TmUpdate.dll] [Trend Micro Inc., 1,81,0,1043]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInMain.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInTray.dll] [Trend Micro Inc., 6.5.0.1106]
[PID: 916][C:\WINNT\System32\WBEM\WinMgmt.exe] [Microsoft Corporation, 1.50.1085.0100]
[PID: 968][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 1088][C:\WINNT\TEMP\PPF2D9.EXE] [N/A, N/A]
[PID: 1416][C:\WINNT\system32\hkcmd.exe] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\hccutils.DLL] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\igfxdev.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\igfxsrvc.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\igfxhk.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\igfxres.dll] [Intel Corporation, 3,0,0,2104]
[PID: 1428][C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe] [Trend Micro Inc., 6.5.0.1303]
[C:\Program Files\Trend Micro\OfficeScan Client\loadhttp.dll] [Trend Micro Inc., 6.5.0.1303]
[C:\Program Files\Trend Micro\OfficeScan Client\Pwd.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInAPI.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] [N/A, N/A]
[C:\Program Files\Trend Micro\OfficeScan Client\TimeString.dll] [N/A, N/A]
[C:\Program Files\Trend Micro\OfficeScan Client\ntmonres.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInMain.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInTray.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[PID: 1444][C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe] [Hewlett-Packard, 2, 1, 1, 29]
[PID: 1460][C:\Program Files\360safe\safemon\360Tray.exe] [奇虎网, 1, 0, 1, 1004]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\360safe\safemon\SafeKrnl.dll] [奇虎网, 1, 0, 0, 3001]
[C:\Program Files\360safe\AntiAdwa.dll] [360Safe.com, 2, 2, 5, 1000]
[PID: 1468][C:\WINNT\system32\Internat.exe] [Microsoft Corporation, 5.00.2920.0000]
[PID: 1508][C:\Program Files\Agilent\IO Libraries\bin\iprocsvr.exe] [Agilent Technologies, L.02.01.00]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[PID: 1536][C:\Program Files\Agilent\IO Libraries\bin\iproc82357.exe] [Agilent Technologies, L.02.01.00]
[C:\WINNT\system32\SICL32.dll] [Agilent Technologies, L.02.01.00]
[C:\WINNT\system32\82357IPT.dll] [Agilent Technologies, L.02.01.00]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[PID: 1420][C:\Program Files\Tencent\Foxmail\Foxmail.exe] [Tencent Inc., 6.03.103.21]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Tencent\Foxmail\FoxAntiSpam.dll] [N/A, N/A]
[C:\Program Files\Tencent\Foxmail\pcre.dll] [N/A, N/A]
[C:\Program Files\Tencent\Foxmail\3rdParty\punylib.dll] [CNNIC, 1, 0, 0, 3]
[PID: 1284][C:\WINNT\explorer.exe] [Microsoft Corporation, 5.00.3700.6690]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] [, 1, 0, 0, 1]
[C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 1]
[C:\WINNT\system32\niRoot.nce] [National Instruments Corporation, 1.1, Build 49]
[C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]
[C:\PROGRA~1\ULTRAE~1\ue32ctmn.dll] [, 1, 0, 0, 1]
[PID: 508][E:\software\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 mmm.caifu18.net
127.0.0.1 www.18dmm.com
127.0.0.1 d.qbbd.com
127.0.0.1 www.5117music.com
127.0.0.1 www.union123.com
127.0.0.1 www.wu7x.cn
127.0.0.1 www.54699.com
127.0.0.1 60.169.0.66
127.0.0.1 60.169.1.29
127.0.0.1 www.97725.com
127.0.0.1 down.97725.com
127.0.0.1 ip.315hack.com
127.0.0.1 ip.54liumang.com
127.0.0.1 www.41ip.com
127.0.0.1 xulao.com
127.0.0.1 www.heixiou.com
127.0.0.1 www.9cyy.com
127.0.0.1 www.hunll.com
127.0.0.1 www.down.hunll.com
127.0.0.1 do.77276.com
127.0.0.1 www.baidulink.com
==================================