==================================
正在运行的进程
[PID: 668 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 740 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 764 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 6.0.2.621]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 808 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 820 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 984 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1052 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1148 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.2.621]
[C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 7.0.6000.374 (winmain(wmbla).070416-2057)]
[PID: 1200 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1320 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1640 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\AdobePDF.dll] [Adobe Systems Incorporated., 7.0.0.00]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Adobe\Acrobat 7.0\Distillr\adistres.dll] [Adobe Systems Incorporated., 7.0.0.2004121400]
[C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.1897.0]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.1897.0]
[PID: 1780 / uu][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1788 / uu][C:\Program Files\MSN Messenger\MsnMsgr.Exe] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\MSNCore.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\msidcrl40.dll] [Microsoft Corporation, 4.100.313.1]
[C:\Program Files\MSN Messenger\ContactsUX.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\msgslang.8.1.0178.00.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\msgsres.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\MSGSWCAM.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\WINDOWS\system32\sirenacm.dll] [Microsoft Corp., 8.1.0178.00]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\Program Files\MSN Messenger\lmcdata.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scrchpg.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\MSN Messenger\dfsr.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\abssm.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\usnsvcps.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\custsat.dll] [Microsoft Corporation, 9.0.3790.2428 (srv03_sp1_qfe.050422-1043)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 4, 1007]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[C:\Program Files\MSN Messenger\contact.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll] [Microsoft Corporation, 8.1.0178.00]
[PID: 476 / SYSTEM][D:\RSI\IDL63\bin\bin.x86\idl_dicomexstorscp.exe] [N/A, ]
[D:\RSI\IDL63\bin\bin.x86\MC3ADV.dll] [Merge eFilm 1126 S. 70th Street Milwaukee, WI 53214-3151 (414)977-4000, 3.4.0 IB8]
[D:\RSI\IDL63\bin\bin.x86\PICN20.dll] [Pegasus Imaging Corp., 1.0.0.92]
[D:\RSI\IDL63\bin\bin.x86\idl.dll] [Research Systems, Inc., 6.3]
[D:\RSI\IDL63\bin\bin.x86\UG3220.dll] [, 2.0]
[D:\RSI\IDL63\bin\bin.x86\MesaGLU6_2.dll] [N/A, ]
[D:\RSI\IDL63\bin\bin.x86\MSVCR70.dll] [Microsoft Corporation, 7.00.9466.0]
[D:\RSI\IDL63\bin\bin.x86\MesaGL6_2.dll] [N/A, ]
[D:\RSI\IDL63\bin\bin.x86\osmesa6_2.dll] [N/A, ]
[D:\RSI\IDL63\bin\bin.x86\freetype2_1_3.dll] [N/A, ]
[D:\RSI\IDL63\bin\bin.x86\xerces-c_2_6_0.dll] [Apache Software Foundation, 2, 6, 0]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mdiui.dll] [Microsoft Corporation, 11.3.1897.0]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mdigraph.dll] [Microsoft Corporation, 11.3.1897.0]
[C:\Program Files\FlashGet\debugrpt.dll] [flashget, 1, 0, 0, 1006]
[C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scrchpg.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 4, 1007]
[C:\Program Files\FlashGet\fgupdate.dll] [www.flashget.com, 1, 8, 1, 1003]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1488 / uu][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 4, 1007]
[C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scrchpg.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.0.2004121400]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll] [Adobe Systems Inc., 7.0.0.2004121400\0]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Adobe\Acrobat 7.0\Distillr\ADIST32.dll] [Adobe Systems Incorporated., 7.0.0.0]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[D:\Program Files\AVG Anti-Spyware\shellexecutehook.dll] [GRISOFT s.r.o., 7, 5, 1, 36]
[C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 2, 10]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\UltraEdit\ue32ctmn.dll] [, 1.0]
[C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\ShellEx.dll] [Kaspersky Lab, 6.0.2.621]
[D:\Program Files\AVG Anti-Spyware\context.dll] [GRISOFT s.r.o., 7, 5, 1, 36]
[C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.2.621]
[PID: 568 / uu][D:\Program Files\MATLAB71\bin\win32\MATLAB.exe] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\libmat.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\libmx.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\icuuc32.dll] [IBM Corporation and others, 3, 2, 0, 0]
[D:\Program Files\MATLAB71\bin\win32\icudt32.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[D:\Program Files\MATLAB71\bin\win32\libz.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\libut.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\icuin32.dll] [IBM Corporation and others, 3, 2, 0, 0]
[D:\Program Files\MATLAB71\bin\win32\icuio32.dll] [IBM Corporation and others, 3, 2, 0, 0]
[D:\Program Files\MATLAB71\bin\win32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[D:\Program Files\MATLAB71\bin\win32\libmwservices.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\mpath.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\libmex.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\mvalue.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\m_dispatcher.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\xerces-c_2_6.dll] [Apache Software Foundation, 2, 6, 0]
[D:\Program Files\MATLAB71\bin\win32\datasvcs.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\mcr.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\m_interpreter.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\mcos.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\mlib.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\m_parser.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\ir_xfmr.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\m_ir.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\m_pcodegen.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\m_pcodeio.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\udd_mi.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\udd.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\jmi.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\bridge.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\libmwgui.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\mwoles05.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\comcli.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\uiw.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\libuij.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\libmwhardcopy.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\uinone.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[D:\Program Files\MATLAB71\bin\win32\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0]
[D:\Program Files\MATLAB71\bin\win32\mlautoregister.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\hg.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\numerics.dll] [The MathWorks Inc., 7.1.0.144]
[D:\Program Files\MATLAB71\bin\win32\libmwamd.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\libfftw3.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\libfftw3f.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\libmwlapack.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\libmwumfpackv4.3.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
[D:\Program Files\MATLAB71\bin\win32\atlas_Athlon.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\lapack.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\DFORMD.DLL] [Compaq Computer Corporation, 6.6 - 893 (Update A)]
[C:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 4, 1007]
[D:\Program Files\MATLAB71\sys\java\jre\win32\jre1.5.0\bin\client\jvm.dll] [Sun Microsystems, Inc., 1.5.0.0]
[D:\Program Files\MATLAB71\sys\java\jre\win32\jre1.5.0\bin\hpi.dll] [Sun Microsystems, Inc., 1.5.0.0]
[D:\Program Files\MATLAB71\sys\java\jre\win32\jre1.5.0\bin\verify.dll] [Sun Microsystems, Inc., 1.5.0.0]
[D:\Program Files\MATLAB71\sys\java\jre\win32\jre1.5.0\bin\java.dll] [Sun Microsystems, Inc., 1.5.0.0]
[D:\Program Files\MATLAB71\sys\java\jre\win32\jre1.5.0\bin\zip.dll] [Sun Microsystems, Inc., 1.5.0.0]
[D:\Program Files\MATLAB71\bin\win32\jmi_mi.dll] [N/A, ]
[D:\Program Files\MATLAB71\sys\java\jre\win32\jre1.5.0\bin\awt.dll] [Sun Microsystems, Inc., 1.5.0.0]
[D:\Program Files\MATLAB71\bin\win32\nativejava.dll] [N/A, ]
[D:\Program Files\MATLAB71\sys\java\jre\win32\jre1.5.0\bin\fontmanager.dll] [Sun Microsystems, Inc., 1.5.0.0]
[D:\Program Files\MATLAB71\sys\java\jre\win32\jre1.5.0\bin\net.dll] [Sun Microsystems, Inc., 1.5.0.0]
[D:\Program Files\MATLAB71\sys\java\jre\win32\jre1.5.0\bin\nio.dll] [Sun Microsystems, Inc., 1.5.0.0]
[D:\Program Files\MATLAB71\bin\win32\nativeservices.dll] [N/A, ]
[D:\Program Files\MATLAB71\bin\win32\nativelex.dll] [N/A, ]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mdiui.dll] [Microsoft Corporation, 11.3.1897.0]
[D:\Program Files\MATLAB71\bin\win32\libmwbuiltins.dll] [The MathWorks Inc., 7.1.0.144]
[C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scrchpg.dll] [Kaspersky Lab, 6.0.2.621]
[PID: 524 / uu][C:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE] [Microsoft Corporation, 11.0.6361]
[C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll] [Microsoft Corporation, 11.0.6360]
[C:\Program Files\Microsoft Office\OFFICE11\2052\ppintl.dll] [Microsoft Corporation, 11.0.6355]
[C:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 4, 1007]
[C:\Program Files\Microsoft Office\OFFICE11\GdiPlus.DLL] [Microsoft Corporation, 6.0.3264.0]
[C:\PROGRA~1\MICROS~3\OFFICE11\ADDINS\SYMINPUT.DLL] [Microsoft Corporation, 1.02]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690]
[C:\Program Files\Common Files\Microsoft Shared\office11\riched20.dll] [Microsoft Corporation, 5.50.99.2009]
[C:\Program Files\Adobe\Acrobat 7.0\PDFMaker\Office\PDFMOfficeAddin.dll] [Adobe Systems Incorporated, 7, 0, 0, 0]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Adobe\Acrobat 7.0\Distillr\adist32.dll] [Adobe Systems Incorporated., 7.0.0.0]
[C:\Program Files\Adobe\Acrobat 7.0\PDFMaker\Common\AdobePDFMakerX.dll] [, ]
[C:\Program Files\Common Files\Microsoft Shared\PROOF\2052\MSGR3SC.DLL] [Microsoft Corporation, 3.0.1707.0]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[C:\Program Files\Microsoft Office\OFFICE11\msostyle.dll] [Microsoft Corporation, 11.0.5510]
[PID: 1668 / uu][D:\Program Files\MyIEGB\MyIE.exe] [MoreQuick, 1, 0, 0, 0]
[C:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 4, 1007]
[C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scrchpg.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\klscav.dll] [Kaspersky Lab, 6.0.2.621]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 3864 / uu][C:\Program Files\WinRAR\WinRAR.exe] [N/A, ]
[C:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 4, 1007]
[C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll] [Microsoft Corporation, 8.1.0178.00]
[PID: 2220 / uu][C:\DOCUME~1\uu\LOCALS~1\Temp\Rar$EX00.824\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 4, 1007]
[C:\DOCUME~1\uu\LOCALS~1\Temp\Rar$EX00.824\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.2.621]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
NuTCRACKER Unix domain sockets (STREAM)
C:\WINDOWS\system32\nutafun4.dll(DataFocus, Inc., NuTCRACKER AF_UNIX WinSock2 provider)
NuTCRACKER Unix domain sockets (DGRAM)
C:\WINDOWS\system32\nutafun4.dll(DataFocus, Inc., NuTCRACKER AF_UNIX WinSock2 provider)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 www.88889999.info
127.0.0.1 xz.88889999.info
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 616, C:\PROGRAM FILES\FLASHGET\FLASHGET.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 568, D:\PROGRAM FILES\MATLAB71\BIN\WIN32\MATLAB.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1668, D:\PROGRAM FILES\MYIEGB\MYIE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3864, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1700, C:\PROGRAM FILES\ULTRAEDIT\UEDIT32.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3488, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
==================================
API HOOK
RVA 错误: LoadLibraryA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: LoadLibraryExA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: LoadLibraryW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
==================================
隐藏进程
N/A
==================================
[/CODE] |