2007-04-30,14:42:20
System Repair Engineer 2.2.6.605
Smallfrogs (
http://www.KZTechs.com)
Windows Server 2003 Enterprise Edition Service Pack 1 (Build 3790)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<swg><C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe> [(Verified)Google Inc.]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<360Safetray><C:\Program Files\360safe\safemon\360Tray.exe /start> [奇虎网]
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<IMEKRMIG6.1><; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE> [(Verified)Microsoft Corporation]
<KavStart><"C:\KAV2007\KAVStart.exe" -startup> [Kingsoft Corporation]
<VStart5.0><G:\bog\暗组2007\Anzu.exe> [3L软件工作室(3LSoft)]
<Windows木马防火墙><D:\Program Files\Windows木马清道夫\Trojanwall.exe> [风云谷]
<nwizqjsj><C:\WINDOWS\system32\nwizqjsj.exe> [N/A]
<tejkjlg><C:\Program Files\Realtek Sound Manager\tejkjlg.exe> [N/A]
<Super Rabbit Desktop Set><D:\Program Files\MagicSet\DS.EXE /Load> [Super Rabbit Software]
<winform><C:\WINDOWS\winform.exe> [N/A]
<cmdbcs><C:\WINDOWS\cmdbcs.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<360Safe><Rundll32.exe C:\PROGRA~1\360safe\AntiAdwa.dll,KillAdware> [360Safe.com]
<Super Rabbit SRCK><"D:\Program Files\MagicSet\SRCK.exe" /autokill:299> [Super Rabbit Soft]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\Userinit.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><%SystemRoot%\system32\logonui.exe> [(Verified)Microsoft Corporation]
==================================
启动文件夹
[yhfifi]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\yhfifi.lnk --> C:\PROGRA~1\WINDOW~3\yhfifid.exe [N/A]><N>
==================================
服务
[8FF3DFBA / 8FF3DFBA]
<C:\WINDOWS\system32\8FF3DFBA.EXE -d><Microsoft Corporation>
[DNS Clisent / DNS Clisent]
<C:\SNOWTEST\System32\RaV.exe><N/A>
[Google Updater Service / gusvc]
<"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
[Human Interface Device Access / HidServ]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Kingsoft Personal Firewall Service / KPfwSvc]
<"C:\KAV2007\KPfwSvc.EXE"><Kingsoft Corporation>
[Kingsoft Antivirus KWatch Service / KWatchSvc]
<C:\KAV2007\KWatch.EXE><Kingsoft Corporation>
[Windows vqfd RunThem / vqfd]
<2 - 系统找不到指定的文件。
><N/A>
[Fast Client / fast]
<2 - 系统找不到指定的文件。
><N/A>
[Automatic / Automatic ]
<C:\Program Files\msn\msn.cc><N/A>
[Security Center / Security Center]
<C:\Program Files\Common Files\Real\Update_OB\realschd><N/A>
[Gray_Pigeon_Server1.23 / GrayPigeonServer1.23]
<2 - 系统找不到指定的文件。
><N/A>
[Intranet Messenger / BUZOR]
<C:\WINDOWS\SYSTEM32\RUNDLL2KXP.EXE C:\WINDOWS\SYSTEM32\WBEM\INNVL.DLL,Export 1087><N/A>
[System Security / Indtry]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\eeejx.dll><N/A>
==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[IP in IP Tunnel Driver / IpInIp]
<system32\DRIVERS\ipinip.sys><N/A>
[king001 / king001]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xpe.sys><N/A>
[KNetWch / KNetWch]
<\??\C:\KAV2007\KNetWch.SYS><Kingsoft Corporation>
[KWatch3 / KWatch3]
<\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
<system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
==================================
浏览器加载项
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, N/A>
[Google Script Object]
{00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar1.dll, N/A>
[ThunderAtOnce Class]
{01443AEC-0FD1-40FD-9C87-E93D1494C233} <D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[&Google]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, N/A>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <D:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[Jpeg Class]
{4970DA77-DB06-4EB9-AAB5-77AF0CC77310} <C:\WINDOWS\system32\a3a7.dll, TODO: <公司名>>
[Thunder Browser Helper]
{55302804-482E-470E-8A57-6795A1487F90} <D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[CBrowseStakeout Class]
{55302805-482E-470E-8A57-6795A1487F90} <C:\KAV2007\KAVAFish.DLL, Kingsoft Corporation>
[MediaComm Class]
{7670648D-461B-42AF-BDFE-46D26AF5EFF2} <C:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin12.dll, Thunder Networking Technologies,LTD>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[Google Toolbar Helper]
{AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, N/A>
[NavigatMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\KAV2007\Flash.OCX, Macromedia, Inc.>
[XML HTTP Request]
{ED8C108E-4349-11D2-91A4-00C04F7969E8} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用迅雷下载]
<D:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
<D:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
[金山毒霸反钓鱼...]
<C:\KAV2007\KAF\ShowSet.htm, N/A>
==================================
正在运行的进程
[PID: 380][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[C:\WINDOWS\system32\a79e.dll] [N/A, N/A]
[C:\WINDOWS\system32\1a3a.dll] [ , 1, 0, 0, 3]
[PID: 404][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\l.dll] [N/A, N/A]
[C:\WINDOWS\system32\a79e.dll] [N/A, N/A]
[C:\WINDOWS\system32\1a3a.dll] [ , 1, 0, 0, 3]
[PID: 448][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\WINDOWS\system32\a79e.dll] [N/A, N/A]
[C:\WINDOWS\system32\1a3a.dll] [ , 1, 0, 0, 3]
[PID: 460][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[C:\WINDOWS\system32\a79e.dll] [N/A, N/A]
[C:\WINDOWS\system32\1a3a.dll] [ , 1, 0, 0, 3]
[PID: 636][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\WINDOWS\system32\a79e.dll] [N/A, N/A]
[C:\WINDOWS\system32\1a3a.dll] [ , 1, 0, 0, 3]
[PID: 720][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\WINDOWS\system32\a79e.dll] [N/A, N/A]
[PID: 760][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\WINDOWS\system32\a79e.dll] [N/A, N/A]
[C:\WINDOWS\system32\1a3a.dll] [ , 1, 0, 0, 3]
[PID: 808][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\WINDOWS\system32\a79e.dll] [N/A, N/A]
[PID: 824][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\WINDOWS\system32\a79e.dll] [N/A, N/A]
[PID: 912][C:\KAV2007\KWatch.EXE] [Kingsoft Corporation, 2007, 2, 12, 84]
[C:\KAV2007\KAVIPC2.DLL] [Kingsoft Corporation, 2007, 1, 15, 30]
[C:\KAV2007\KAEPlat.DLL] [Kingsoft Corp., 2007, 2, 4, 61]
[C:\KAV2007\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\KAV2007\KAEUnpack.DAT] [Kingsoft Corp., 2007, 3, 12, 114]
[C:\KAV2007\KAVQuara.DLL] [Kingsoft Corporation, 2007, 1, 25, 1]
[C:\WINDOWS\system32\a79e.dll] [N/A, N/A]
[C:\WINDOWS\system32\1a3a.dll] [ , 1, 0, 0, 3]
[PID: 1112][C:\WINDOWS\system32\msdtc.exe] [Microsoft Corporation, 2001.12.4720.1830 (srv03_sp1_rtm.050324-1447)]
[C:\WINDOWS\system32\a79e.dll] [N/A, N/A]
[PID: 1488][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\WINDOWS\system32\a79e.dll] [N/A, N/A]
[PID: 1972][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\WINDOWS\system32\a79e.dll] [N/A, N/A]
[C:\WINDOWS\system32\1a3a.dll] [ , 1, 0, 0, 3]
[PID: 1996][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\WINDOWS\system32\a79e.dll] [N/A, N/A]
[C:\WINDOWS\system32\1a3a.dll] [ , 1, 0, 0, 3]
[PID: 1656][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\WINDOWS\system32\a79e.dll] [N/A, N/A]
[C:\WINDOWS\system32\1a3a.dll] [ , 1, 0, 0, 3]
[PID: 3180][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 1936][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 3516][C:\Program Files\360safe\safemon\360Tray.exe] [奇虎网, 3, 3, 0, 1004]
[C:\Program Files\360safe\safemon\SafeKrnl.dll] [奇虎网, 3, 2, 0, 1001]
[C:\Program Files\360safe\AntiAdwa.dll] [360Safe.com, 3, 3, 0, 1004]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\l.dll] [N/A, N/A]
[C:\Program Files\360safe\live.dll] [360safe.COM, 1, 0, 0, 1012]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Gjzo0.dll] [N/A, N/A]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, N/A]
[C:\WINDOWS\system32\winform.dll] [N/A, N/A]
[PID: 1692][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.3790.1830 (srv03_sp1_rtm.050324-1447)]
[D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.0.4]
[D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 2, 17]
[C:\KAV2007\KAScript.DLL] [Kingsoft Corporation, 2007, 3, 6, 75]
[C:\KAV2007\KAEPlat.DLL] [Kingsoft Corp., 2007, 2, 4, 61]
[C:\KAV2007\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\KAV2007\KAEUnpack.DAT] [Kingsoft Corp., 2007, 3, 12, 114]
[C:\KAV2007\Flash.OCX] [Macromedia, Inc., 7,0,19,0]
[C:\Program Files\Thunder Network\Thunder\Components\VPShell\RealMediaSplitter.ax] [Gabest, 1, 0, 1, 0]
[C:\WINDOWS\system32\mpg2splt.ax] [N/A, N/A]
[C:\WINDOWS\system32\winform.dll] [N/A, N/A]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, N/A]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Gjzo0.dll] [N/A, N/A]
[D:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 2, 17]
[PID: 2652][D:\Program Files\Tencent\QQ\QQ.exe] [TENCENT, 0, 0, 0, 0]
[D:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] [, 1, 0, 0, 1]
[D:\Program Files\Tencent\QQ\QQHelperDll.dll] [, 1, 0, 0, 1]
[D:\Program Files\Tencent\QQ\BasicCtrlDll.dll] [Tencent, 7, 0, 101, 80]
[D:\Program Files\Tencent\QQ\QQAPI.dll] [, 1, 0, 0, 1]
[d:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[D:\Program Files\Tencent\QQ\LoginCtrl.dll] [N/A, N/A]
[D:\Program Files\Tencent\QQ\LoginCtrlRes.dll] [, 1, 0, 0, 1]
[D:\Program Files\Tencent\QQ\QQRes.dll] [tencent, 1, 0, 0, 1]
[D:\Program Files\Tencent\QQ\QQMainFrame.dll] [N/A, N/A]
[D:\Program Files\Tencent\QQ\CQQApplication.dll] [N/A, N/A]
[D:\Program Files\Tencent\QQ\NewSkin.dll] [, 1, 0, 0, 1]
[D:\Program Files\Tencent\QQ\HostingMgr.dll] [, 1, 0, 0, 1]
[D:\Program Files\Tencent\QQ\CameraDll.dll] [, 1, 0, 0, 1]
[D:\Program Files\Tencent\QQ\MailSummary.dll] [, 1, 0, 0, 1]
[D:\Program Files\Tencent\QQ\QQKnowledgeSearch.dll] [, 1, 0, 0, 1]
[D:\Program Files\Tencent\QQ\QQAllInOne.dll] [N/A, N/A]
[D:\Program Files\Tencent\QQ\GroupLive.dll] [N/A, N/A]
[D:\Program Files\Tencent\QQ\SCCore.dll] [TENCENT, 2, 0, 0, 1]
[D:\Program Files\Tencent\QQ\QQSpace.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[D:\Program Files\Tencent\QQ\QQGroupMng.dll] [, 1, 0, 0, 1]
[D:\Program Files\Tencent\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[D:\Program Files\Tencent\QQ\QQAvatar.dll] [N/A, N/A]
[D:\Program Files\Tencent\QQ\QQSysMsgMng.dll] [N/A, N/A]
[D:\Program Files\Tencent\QQ\UserDefinedHead.dll] [, 1, 0, 0, 1]
[D:\Program Files\Tencent\QQ\QQPlugin.dll] [N/A, N/A]
[D:\Program Files\Tencent\QQ\QQConfigPlugin.dll] [, 1, 0, 0, 1]
[D:\Program Files\Tencent\QQ\LongConnection.dll] [tencent, 5, 0, 200, 160]
[D:\Program Files\Tencent\QQ\QRingMng.dll] [N/A, N/A]
[D:\Program Files\Tencent\QQ\QQFileTransfer.dll] [Tencent, 0, 3, 3, 5]
[D:\Program Files\Tencent\QQ\PhoneAPI.dll] [, 1, 0, 0, 1]
[D:\Program Files\Tencent\QQ\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[D:\Program Files\Tencent\QQ\QQPet.dll] [, 1, 0, 0, 1]
[D:\Program Files\Tencent\QQ\BQQApplication.dll] [N/A, N/A]
[D:\Program Files\Tencent\QQ\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
[D:\Program Files\Tencent\QQ\CommercesMng.dll] [, 1, 0, 0, 1]
[D:\Program Files\Tencent\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 280]
[D:\Program Files\Tencent\QQ\npkcntc.dll] [INCA Internet Co., Ltd., 2006, 6, 27, 1]
[D:\Program Files\Tencent\QQ\npkpdb.dll] [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[D:\Program Files\Tencent\QQ\QQSceneMng.dll] [N/A, N/A]
[D:\Program Files\Tencent\QQ\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 1, 8, 81]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Gjzo0.dll] [N/A, N/A]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, N/A]
[C:\WINDOWS\system32\winform.dll] [N/A, N/A]
[D:\Program Files\Tencent\QQ\QQCustomFace.dll] [N/A, N/A]
[D:\Program Files\Tencent\QQ\ImageOle.dll] [TODO: <Company name>, 1.0.0.1]
[C:\KAV2007\KAScript.DLL] [Kingsoft Corporation, 2007, 3, 6, 75]
[D:\Program Files\Tencent\QQ\GroupConnection.dll] [Tencent, 0, 3, 3, 5]
[PID: 2004][d:\Program Files\Tencent\QQ\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[d:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 2816][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\l.dll] [N/A, N/A]
[C:\WINDOWS\system32\winform.dll] [N/A, N/A]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, N/A]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Gjzo0.dll] [N/A, N/A]
[C:\WINDOWS\system32\qjsj100.dll] [N/A, N/A]
[C:\KAV2007\KAVEXT.DLL] [Kingsoft Corporation, 2005, 8, 5, 16]
[D:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[d:\PROGRA~1\WINDOW~1\FTCCOM~1.DLL] [Fygsoft and Microsoft, 3.0.0.71]
[C:\KAV2007\KAScript.DLL] [Kingsoft Corporation, 2007, 3, 6, 75]
[C:\KAV2007\KAEPlat.DLL] [Kingsoft Corp., 2007, 2, 4, 61]
[C:\KAV2007\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\KAV2007\KAEUnpack.DAT] [Kingsoft Corp., 2007, 3, 12, 114]
[D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 2, 17]
[PID: 1884][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 680][C:\WINDOWS\system32\temp2.exe] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\C2ECBB6B.dll] [N/A, N/A]
[PID: 3272][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 1696][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 1528][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\WINDOWS\TEMP\my.dll] [N/A, N/A]
[PID: 2320][D:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5, 6, 1, 292]
[D:\Program Files\Thunder Network\Thunder\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 1, 0, 20]
[D:\Program Files\Thunder Network\Thunder\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 2, 14, 2, 77]
[D:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031]
[D:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll] [Thunder Networking Technologies,LTD, 2, 14, 2, 77]
[D:\Program Files\Thunder Network\Thunder\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 1, 0, 8]
[D:\Program Files\Thunder Network\Thunder\Program\FloatBar.dll] [Giganology Inc., 1, 0, 0, 2]
[D:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DownAndPlay.dll] [, 1, 0, 0, 2]
[D:\Program Files\Thunder Network\Thunder\Program\iTargetAD.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 26]
[C:\KAV2007\Flash.OCX] [Macromedia, Inc., 7,0,19,0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Gjzo0.dll] [N/A, N/A]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, N/A]
[C:\WINDOWS\system32\winform.dll] [N/A, N/A]
[D:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll] [ , 1, 0, 0, 17]
[D:\Program Files\Thunder Network\Thunder\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 1, 0, 6, 26]
[D:\Program Files\Thunder Network\Thunder\Program\LiveUpdate.dll] [Thunder Networking Technologies,LTD, 1, 1, 1, 20]
[D:\Program Files\Thunder Network\Thunder\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 1, 1, 10]
[D:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll] [Thunder Networking Technologies,LTD, 2, 2, 1, 46]
[D:\Program Files\Thunder Network\Thunder\Components\DiagnoseHelper\DiagnoseHelper.dll] [Thunder Networking Technologies,LTD, 1, 1, 1, 16]
[D:\Program Files\Thunder Network\Thunder\Components\ExplorerHelper\ExplorerHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 15]
[D:\Program Files\Thunder Network\Thunder\Components\Tips\TipsClient.dll] [Thunder Networking Technologies,LTD, 2, 1, 3, 58]
[D:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VPSHELL.dll] [XunLei, 1, 2, 0, 8]
[D:\Program Files\Thunder Network\Thunder\Components\UserExperience\UserExperience.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
[D:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsXlCom.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 4]
[C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed09.dll] [ , 3, 3, 0, 80]
[D:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 13, 2, 61]
[D:\Program Files\Thunder Network\Thunder\Plugins\BhoAdv\bho_adv.dll] [深圳市迅雷网络技术有限公司, 1.0.1.0]
[C:\KAV2007\KAScript.DLL] [Kingsoft Corporation, 2007, 3, 6, 75]
[D:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VideoPicture.dll] [XunLei, 1, 2, 0, 9]
[D:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
[D:\Program Files\Thunder Network\Thunder\Program\XLNet.Dll] [Thunder Networking Technologies,LTD, 1, 2, 0, 8]
[D:\Program Files\Thunder Network\Thunder\Components\ResWorker\MediaWorker.dll] [Thunder Networking Technologies,LTD, 1, 2, 0, 8]
[PID: 356][C:\Documents and Settings\Administrator\桌面\42006113122516\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Gjzo0.dll] [N/A, N/A]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, N/A]
[C:\WINDOWS\system32\winform.dll] [N/A, N/A]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\l.dll] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP Error. [winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 popwin.9983.com
61.152.169.246
www.npjxjy.com61.152.169.246 quxiuu.com
61.152.169.246
www.23b.cn61.152.169.246
www.baidulink.com61.152.169.246
www.ookkw.com61.152.169.246
www.wu7x.cn61.152.169.246 d.qbbd.com
61.152.169.246 w.qbbd.com
61.152.169.246 web.77276.com
61.152.169.246
www.77276.com61.152.169.246
www.npjxjy.com61.152.169.246
www.baidulink.com61.152.169.246
www.ookkw.com61.152.169.246
www.wu7x.cn61.152.169.246
www.wwwlm.net61.152.169.246 dm1.yiall.com
61.152.169.246
www.my6688.cn61.152.169.246
www.union123.com61.152.169.246
www.ktan.cn61.152.169.246
www.2t2t.cn61.152.169.246
www.cq530.com61.152.169.246
www.365tc.com61.152.169.246 ad.qucha.net
61.152.169.246
www.tan8.cn61.152.169.246
www.itjj.net61.152.169.246
www.start188.com61.152.169.246
www.at58.cn61.152.169.246 union.yxad.com
61.152.169.246
www.iptan.com61.152.169.246
www.ip2008.net61.152.169.246
www.yqif.com61.152.169.246
www.2t2t.cn61.152.169.246
www.688ip.com61.152.169.246
www.17tc.com61.152.169.246 www1.6tan.com
61.152.169.246 www2.6tan.com
61.152.169.246
www.6tan.com61.152.169.246
www.zztan.com61.152.169.246
www.5tanip.com61.152.169.246
www.16tc.com61.152.169.246
www.163se.net61.152.169.246
www.168080.com61.152.169.246
www.baidu8.org61.152.169.246
www.nze21.com61.152.169.246
www.437799.com61.152.169.246
www.168080.com61.152.169.246 new2.jixie123.cn
61.152.169.246
www.18dmm.com61.152.169.246
www.souxse.cn61.152.169.246 x.vvcyin.com
61.152.169.246 dm1.yiall.com
61.152.169.246
www.168080.com61.152.169.246
www.nze21.com61.152.169.246
www.puma163.com61.152.169.246
www.138505.com61.152.169.246
www.hyap98.com61.152.169.246 x.vvcyin.com
61.152.169.246
www.puma163.com61.152.169.246
www.51liulan.cn61.152.169.246 s.gcuj.com
61.152.169.246 long.down988.cn
61.152.169.246 0.82211.net
61.152.169.246 x.vvcyin.com
61.152.169.246 w.vvcyin.com
61.152.169.246 cc.wzxqy.com
61.152.169.246 008.cn
61.152.169.246 ultimate-best-hgh.0my.net
61.152.169.246
www.139500.com61.152.169.246
www.1yin.net61.152.169.246
www.37021.com61.152.169.246
www.47555.net61.152.169.246
www.511ring.com61.152.169.246 me.5e163.com
61.152.169.246
www.777888.com61.152.169.246
www.77ttt.com61.152.169.246
www.9p.cn61.152.169.246 abcdesign.ru
61.152.169.246 gutemine.wu-wien.ac.at
61.152.169.246 math.kobe-u.ac.jp
61.152.169.246
www.aifind.info61.152.169.246
www.allyes.com61.152.169.246
www.aogo.net61.152.169.246 baltnet.ru
61.152.169.246 quotes.barchart.com
61.152.169.246 free.bestialityhost.com
61.152.169.246 cctv1.net
61.152.169.246 cctv8.net
61.152.169.246
www.cctv8.net61.152.169.246 ciachoo.pl
61.152.169.246
www.play.cn.gs61.152.169.246
www.cnqb.net61.152.169.246
www.feixue.net61.152.169.246
www.xiliao.com.cn61.152.169.246 alexey.pioneers.com.ru
61.152.169.246
www.coolcdrom.com61.152.169.246
www.coolseach.com61.152.169.246 puldk490gj.da.ru
61.152.169.246 dicto.ru
61.152.169.246
www.dj3344.com61.152.169.246
www.donttrip.org61.152.169.246
www.ehomeday.com61.152.169.246 elemental.ru
61.152.169.246 errorguard.com
61.152.169.246 friendlygreeting.com
61.152.169.246 zhp.gdynia.pl
61.152.169.246
www.gg888.net61.152.169.246 gin.ru
61.152.169.246
www.girlchinese.com61.152.169.246 glass-master.ru
61.152.169.246 photo.gornet.ru
61.152.169.246 relay.great.ru
61.152.169.246 hack-gegen-rechts.com
61.152.169.246 hgrstrailer.com
61.152.169.246
www.homepage.com61.152.169.246 hotbar.com
61.152.169.246 intellect.lvc
61.152.169.246 interfoodtd.ru
61.152.169.246 jewishgen.org
61.152.169.246
www.jixian.net61.152.169.246 k2kapital.com
61.152.169.246 security.kolla.de
61.152.169.246
www.kuliao.com61.152.169.246 laugh-mail.net
61.152.169.246 7b.com.cn
61.152.169.246 9505.com
61.152.169.246
www.piaoxue.com61.152.169.246 marketscore.com
61.152.169.246
www.mir0.com61.152.169.246 momentum.ru
61.152.169.246
www.mtv51.com61.152.169.246
www.mydj2005.com61.152.169.246 nefkom.net
61.152.169.246 no-abi2003.de
61.152.169.246 tdi-router.opola.pl
61.152.169.246 packages.debian.or.jp
61.152.169.246 perfectgirls.net
61.152.169.246 peterstar.ru
61.152.169.246 pgipearls.com
61.152.169.246 phg.pl
61.152.169.246 vip.pnet.pl
61.152.169.246 sec.polbox.pl
61.152.169.246 polobeer.de
61.152.169.246 porno-mania.net
61.152.169.246 home.profootball.ru
61.152.169.246 qianbai.com
61.152.169.246 ad.qingyule.com
61.152.169.246
www.qq168.net61.152.169.246
www.qq3344.com61.152.169.246
www.qq92.com61.152.169.246
www.qqwz.com61.152.169.246
www.qu123.com61.152.169.246 republika.pl
61.152.169.246
www.richfind.com61.152.169.246 rollenspielzirkel.de
61.152.169.246 safer-networking.org
61.152.169.246 sdsauto.ru
61.152.169.246
www.searchpage.cc61.152.169.246
www.seekeasysoft.net61.152.169.246 shadkhan.ru
61.152.169.246 slavarik.ru
61.152.169.246 sovea.de
61.152.169.246 spybot.info
61.152.169.246
www.start-page.info61.152.169.246 lars-s.privat.t-online.de
61.152.169.246 u.t2cn.com
61.152.169.246
www.7939.com61.152.169.246
www.4199.com61.152.169.246
www.3448.com61.152.169.246
www.6781.com61.152.169.246 it.trendmicro-europe.com
61.152.169.246 trendmicro.it
61.152.169.246 truefriends.net
61.152.169.246
www.tthao.com61.152.169.246
www.ttrx.net61.152.169.246 tuhart.net
61.152.169.246
www.unionsky.cn61.152.169.246
www.unionsky.com61.152.169.246
www.unionsky.net61.152.169.246 vconsole.net
61.152.169.246 virtumonde.com
61.152.169.246 gamma.vyborg.ru
61.152.169.246 financial.washingtonpost.com
61.152.169.246 webpark.pl
61.152.169.246 wishken.com
61.152.169.246
www.yeapple.com61.152.169.246
www.yibinren.com61.152.169.246
www.youmiss.com61.152.169.246
www.yysky.net61.152.169.246 zelnet.ru
61.152.169.246
www.zhengdian.com61.152.169.246 abc.265.com
61.152.169.246 555.265.com
61.152.169.246
www.baidu345.com61.152.169.246
www.37ss.com61.152.169.246 my123.com
61.152.169.246 mmm.caifu18.net
61.152.169.246
www.5117music.com61.152.169.246
www.union123.com61.152.169.246
www.wu7x.cn61.152.169.246
www.97725.com61.152.169.246 down.97725.com
61.152.169.246 ip.315hack.com
61.152.169.246 ip.54liumang.com
61.152.169.246
www.41ip.com61.152.169.246 xulao.com
61.152.169.246
www.heixiou.com61.152.169.246
www.9cyy.com61.152.169.246
www.hunll.com61.152.169.246
www.down.hunll.com61.152.169.246 do.77276.com
61.152.169.246
www.baidulink.com61.152.169.246 adnx.yygou.cn
61.152.169.246 222.73.220.45
61.152.169.246
www.f5game.com61.152.169.246
www.guazhan.cn61.152.169.246 wm,103715.com
61.152.169.246
www.my6688.cn61.152.169.246 i.96981.com
61.152.169.246 d.77276.com
61.152.169.246 www1.cw988.cn
61.152.169.246 cool.47555.com
61.152.169.246
www.asdwc.com61.152.169.246 55880.cn
61.152.169.246 cc.wzxqy.com
61.152.169.246
www.54699.com61.152.169.246 ceoww.com
61.152.169.246 boolom.com
61.152.169.246
www.boolom.com61.152.169.246 adult-novel.cn
61.152.169.246 ll.chinasese.net
61.152.169.246
www.tellumore.com61.152.169.246
www.o1wg.com61.152.169.246
www.qq756.com61.152.169.246 ll.chinasese.net
==================================