正在运行的进程
[PID: 1340 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1400 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1424 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\adialhk.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258]
[PID: 1480 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\adialhk.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[PID: 1492 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\adialhk.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[PID: 1656 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\adialhk.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258]
[PID: 1716 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\adialhk.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258]
[PID: 1912 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\adialhk.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\System32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258]
[PID: 280 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\adialhk.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258]
[PID: 628 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\adialhk.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258]
[PID: 876 / Binwoo][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\adialhk.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86]
[C:\WINDOWS\Fonts\avxzjbgx.dll] [, 1, 0, 0, 1]
[C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] [Autodesk, 16.0.0.86]
[C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 8.1.0.0]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.10.8421]
[C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.10.8421]
[C:\WINDOWS\system32\nvshell.dll] [, ]
[D:\Unlocker\UnlockerCOM.dll] [N/A, ]
[D:\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 120]
[D:\WinRAR\rarext.dll] [N/A, ]
[D:\Kaspersky Lab\Kaspersky Internet Security 2009\ShellEx.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762]
[D:\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.34]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 952 / Binwoo][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\adialhk.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\Fonts\avxzjbgx.dll] [, 1, 0, 0, 1]
[PID: 492 / SYSTEM][C:\WINDOWS\system32\drivers\CDAC11BA.EXE] [Macrovision, 4.20.020]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[PID: 540 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.8421]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 568 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\adialhk.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258]
[PID: 992 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\adialhk.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[PID: 2368 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\adialhk.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\System32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258]
[PID: 3216 / Binwoo][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\adialhk.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\Fonts\avxzjbgx.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86]
[D:\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.34]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[D:\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762]
[D:\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 120]
[D:\Kaspersky Lab\Kaspersky Internet Security 2009\scrchpg.dll] [Kaspersky Lab, 8.0.0.506]
[D:\Kaspersky Lab\Kaspersky Internet Security 2009\klscav.dll] [Kaspersky Lab, 8.0.0.506]
[D:\Kaspersky Lab\Kaspersky Internet Security 2009\prremote.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762]
[D:\Kaspersky Lab\Kaspersky Internet Security 2009\prloader.dll] [Kaspersky Lab, 8.0.0.506]
[D:\Kaspersky Lab\Kaspersky Internet Security 2009\prkernel.ppl] [Kaspersky Lab, 8.0.0.506]
[d:\kaspersky lab\kaspersky internet security 2009\params.ppl] [Kaspersky Lab, 8.0.0.506]
[d:\kaspersky lab\kaspersky internet security 2009\pxstub.ppl] [Kaspersky Lab, 8.0.0.506]
[d:\kaspersky lab\kaspersky internet security 2009\tempfile.ppl] [Kaspersky Lab, 8.0.0.506]
[d:\kaspersky lab\kaspersky internet security 2009\nfio.ppl] [Kaspersky Lab, 8.0.0.512]
[d:\kaspersky lab\kaspersky internet security 2009\fsdrvplg.ppl] [Kaspersky Lab, 8.0.0.506]
[d:\kaspersky lab\kaspersky internet security 2009\fssync.dll] [Kaspersky Lab, 8.0.5.506]
[d:\kaspersky lab\kaspersky internet security 2009\basegui.ppl] [Kaspersky Lab, 8.0.0.506]
[d:\kaspersky lab\kaspersky internet security 2009\thpimpl.ppl] [Kaspersky Lab, 8.0.0.506]
[d:\kaspersky lab\kaspersky internet security 2009\winreg.ppl] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx] [Adobe Systems, Inc., 10,0,12,36]
[PID: 1084 / Binwoo][C:\DOCUME~1\Binwoo\LOCALS~1\Temp\Rar$EX01.453\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\adialhk.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[PID: 1868 / Binwoo][C:\DOCUME~1\Binwoo\LOCALS~1\Temp\Rar$EX01.453\SRE78cbe452.EXE] [Smallfrogs Studio, 2.7.0.1210]
[D:\KASPER~1\KASPER~1\mzvkbd.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\mzvkbd3.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\adialhk.dll] [Kaspersky Lab, 8.0.0.506]
[D:\KASPER~1\KASPER~1\kloehk.dll] [Kaspersky Lab, 8.0.0.506]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\Fonts\avxzjbgx.dll] [, 1, 0, 0, 1]
[C:\DOCUME~1\Binwoo\LOCALS~1\Temp\Rar$EX01.453\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1084, C:\DOCUME~1\BINWOO\LOCALS~1\TEMP\RAR$EX01.453\SRENGLDR.EXE]
==================================
计划任务
[已启用] SogouImeMgr.job
d:\SOGOUI~1\413~1.239\PinyinRepair.exe
==================================
API HOOK
N/A
==================================
隐藏进程
[2617] D:\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
==================================
[/CODE]