查看: 6732|回复: 19
收起左侧

[求助] 已解决、感谢大家★★这是什么情况,红伞报微软补丁★★

 关闭 [复制链接]
自然卷丨依佐
发表于 2012-5-9 12:51:13 | 显示全部楼层 |阅读模式
本帖最后由 自然卷丨依佐 于 2012-5-9 16:36 编辑

小白第一次遇见这问题,金山给出解释是误报,算是学习了,感谢各位!!各位参考金山论坛答复:

红伞误报.tdl文件,该文件为旋风下载引擎所产生的临时文件,举个不太恰当但是形象的例子,一个文件有abcd是个字符,该临时文件里面就改改下载了ac两个字符,而这两个字符正好是红伞的特征码,报了。
从你的描述中明显就能看出来,红伞误报的是没下载的完整的文件,而下载完整的文件是没有报毒的。

再说细点,可能你这一次报了,下一次再下载就不报,或者你在10%进度时报警,你下载到20%又可能不报。

另外你说的windows update不报警是因为下载机制的问题,红伞误报.tdl临时文件已经不是一例两例了。

http://bbs.duba.net/forum.php?mod=viewthread&tid=22698101&page=1#pid7575605


11楼主也是正解,感谢了:http://bbs.kafan.cn/forum.php?mo ... 7094&fromuid=734480

















有没有一样的情况??



今天下课回来开机看见金山漏洞然后修复



下载时红伞报office2010的excel一个补丁KB2597166:excel2010-kb2597166-fullfile-x86-glb.exe.tdl下载完成后为文件:excel2010-kb2597166-fullfile-x86-glb.exe

执行的操作:传输至扫描程序 ,这个应该是没问题吧,红伞默认认为这个是流氓恶意行为?

安装时毛豆监控会连接,这个是给微软报告??:
2012-05-09 12:25:41 C:\Program Files (x86)\ksafe\hotfix\excel2010-kb2597166-fullfile-x86-glb.exe 询问 TCP 125.82.145.202 49964 96.17.155.248 80


下载完后右键扫描不报、双击也不报???   


金山设置为在微软官方下载补丁!!!   现在补丁是打好了,关键是不知道后面系统扫描什么会不会出问题!!,另外如果报告给官方这个文件也太大了,50多M!!



导出的事件:

2012/5/9 12:16 [Realtime Protection] 发现恶意软件
      在文件“C:\Program Files
      (x86)\ksafe\hotfix\excel2010-kb2597166-fullfile-x86-glb.exe.tdl”中检测到病毒或
      恶意程序“TR/Crypt.XPACK.Gen2 [trojan]”。
      执行的操作:传输至扫描程序


下载时报:








下载完成后右键不报:





双击不报:




毛豆防火墙:









金山设置:






文件签名:







文件:











SREngLOG.log日志帮忙看看:


  1. 2012-05-09,16:02:17

  2. System Repair Engineer 2.8.4.1331
  3. Smallfrogs ([url]http://www.KZTechs.com[/url])

  4. Windows 7 Ultimate Edition Service Pack 1 (Build 7601) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描
  14.     计划任务
  15.     Windows 安全更新检查
  16.     API HOOK
  17.     隐藏进程


  18. 启动项目
  19. 注册表
  20. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  21.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows]
  22. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  23.     <load><>  [N/A]
  24. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  25.     <KSafeTray><"c:\program files (x86)\ksafe\KSafeTray.exe" -autorun>  [(Verified)Kingsoft Security Co.,Ltd]
  26.     <avgnt><"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min>  [(Verified)Avira Operations GmbH & Co. KG]
  27. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  28.     <shell><explorer.exe>  [(Infected) Microsoft Corporation]
  29.     <Userinit><C:\Windows\system32\userinit.exe,>  [(Verified)Microsoft Windows]
  30. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  31.     <AppInit_DLLs><        C:\Windows\SysWOW64\guard32.dll>  [(Verified)Comodo Security Solutions, Inc.]
  32. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  33.     <WebCheck><>  [N/A]
  34. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
  35.     <Microsoft Windows Media Player><%SystemRoot%\system32\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows]
  36. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  37.     <Internet Explorer><C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig>  [(Verified)Microsoft Windows]
  38. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
  39.     <Browser Customizations><"C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP>  [(Verified)Microsoft Windows]
  40. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  41.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  43.     <Microsoft Windows><"%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE>  [File is missing]
  44. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  45.     <Microsoft Windows Media Player><%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI>  [(Verified)Microsoft Windows]
  46. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
  47.     <Windows Desktop Update><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows]
  48. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
  49.     <Web Platform Customizations><C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings>  [(Verified)Microsoft Windows]
  50. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
  51.     <N/A><C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install>  [(Verified)Microsoft Corporation]

  52. ==================================
  53. 启动文件夹
  54. N/A

  55. ==================================
  56. 服务
  57. [Adobe Flash Player Update Service / AdobeFlashPlayerUpdateSvc][Stopped/Manual Start]
  58.   <C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe><Adobe Systems Incorporated>
  59. [Application Experience / AeLookupSvc][Running/Manual Start]
  60.   <C:\Windows\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\aelupsvc.dll><Microsoft Corporation>
  61. [Avira 计划程序 / AntiVirSchedulerService][Running/Auto Start]
  62.   <"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"><Avira Operations GmbH & Co. KG>
  63. [Avira Realtime Protection / AntiVirService][Running/Auto Start]
  64.   <"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"><Avira Operations GmbH & Co. KG>
  65. [Application Identity / AppIDSvc][Stopped/Manual Start]
  66.   <C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation-->%SystemRoot%\System32\appidsvc.dll><Microsoft Corporation>
  67. [Application Information / Appinfo][Running/Manual Start]
  68.   <C:\Windows\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appinfo.dll><Microsoft Corporation>
  69. [Windows Audio Endpoint Builder / AudioEndpointBuilder][Running/Auto Start]
  70.   <C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted-->%SystemRoot%\System32\Audiosrv.dll><Microsoft Corporation>
  71. [Windows Audio / AudioSrv][Running/Auto Start]
  72.   <C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted-->%SystemRoot%\System32\Audiosrv.dll><Microsoft Corporation>
  73. [ActiveX Installer (AxInstSV) / AxInstSV][Stopped/Manual Start]
  74.   <C:\Windows\system32\svchost.exe -k AxInstSVGroup-->%SystemRoot%\System32\AxInstSV.dll><Microsoft Corporation>
  75. [BitLocker Drive Encryption Service / BDESVC][Stopped/Manual Start]
  76.   <C:\Windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\bdesvc.dll><Microsoft Corporation>
  77. [Base Filtering Engine / BFE][Running/Auto Start]
  78.   <C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork-->%SystemRoot%\System32\bfe.dll><Microsoft Corporation>
  79. [Background Intelligent Transfer Service / BITS][Stopped/Manual Start]
  80.   <C:\Windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\qmgr.dll><Microsoft Corporation>
  81. [Computer Browser / Browser][Running/Manual Start]
  82.   <C:\Windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\browser.dll><Microsoft Corporation>
  83. [Bluetooth Support Service / bthserv][Stopped/Manual Start]
  84.   <C:\Windows\system32\svchost.exe -k bthsvcs-->%SystemRoot%\system32\bthserv.dll><Microsoft Corporation>
  85. [Certificate Propagation / CertPropSvc][Stopped/Manual Start]
  86.   <C:\Windows\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\certprop.dll><Microsoft Corporation>
  87. [COMODO Internet Security Helper Service / cmdAgent][Running/Auto Start]
  88.   <"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"><COMODO>
  89. [Offline Files / CscService][Stopped/Manual Start]
  90.   <C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted-->%SystemRoot%\System32\cscsvc.dll><Microsoft Corporation>
  91. [DCOM Server Process Launcher / DcomLaunch][Running/Auto Start]
  92.   <C:\Windows\system32\svchost.exe -k DcomLaunch-->%SystemRoot%\system32\rpcss.dll><Microsoft Corporation>
  93. [Disk Defragmenter / defragsvc][Stopped/Manual Start]
  94.   <C:\Windows\system32\svchost.exe -k defragsvc-->%Systemroot%\System32\defragsvc.dll><Microsoft Corporation>
  95. [DNS Client / Dnscache][Running/Auto Start]
  96.   <C:\Windows\system32\svchost.exe -k NetworkService-->%SystemRoot%\System32\dnsrslvr.dll><Microsoft Corporation>
  97. [Wired AutoConfig / dot3svc][Stopped/Manual Start]
  98.   <C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted-->%SystemRoot%\System32\dot3svc.dll><Microsoft Corporation>
  99. [Diagnostic Policy Service / DPS][Running/Auto Start]
  100.   <C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork-->%SystemRoot%\system32\dps.dll><Microsoft Corporation>
  101. [Extensible Authentication Protocol / EapHost][Running/Manual Start]
  102.   <C:\Windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\eapsvc.dll><Microsoft Corporation>
  103. [HDZB Comm Service For V3.0 / HZ_CommSrv][Running/Auto Start]
  104.   <C:\Windows\SysWOW64\HZ_CommSrv.exe><华大智宝电子系统有限公司>
  105. [Intel(R) Rapid Storage Technology / IAStorDataMgrSvc][Stopped/Manual Start]
  106.   <"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"><Intel Corporation>
  107. [IKE and AuthIP IPsec Keying Modules / IKEEXT][Running/Auto Start]
  108.   <C:\Windows\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\ikeext.dll><Microsoft Corporation>
  109. [Intel(R) Capability Licensing Service Interface / Intel(R) Capability Licensing Service Interface][Stopped/Manual Start]
  110.   <"C:\Program Files\Intel\iCLS Client\HeciServer.exe"><Intel(R) Corporation>
  111. [PnP-X IP Bus Enumerator / IPBusEnum][Stopped/Manual Start]
  112.   <C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted-->%SystemRoot%\system32\ipbusenum.dll><Microsoft Corporation>
  113. [IP Helper / iphlpsvc][Stopped/Manual Start]
  114.   <C:\Windows\System32\svchost.exe -k NetSvcs-->%SystemRoot%\System32\iphlpsvc.dll><Microsoft Corporation>
  115. [KMService / KMService][Stopped/Manual Start]
  116.   <C:\Windows\system32\srvany.exe><(File is missing)>
  117. [KSafe service / KSafeSvc][Running/Auto Start]
  118.   <"c:\program files (x86)\ksafe\KSafeSvc.exe" -svc><Kingsoft Corporation>
  119. [KtmRm for Distributed Transaction Coordinator / KtmRm][Stopped/Manual Start]
  120.   <C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation-->%systemroot%\system32\msdtckrm.dll><Microsoft Corporation>
  121. [Server / LanmanServer][Running/Manual Start]
  122.   <C:\Windows\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\srvsvc.dll><Microsoft Corporation>
  123. [Workstation / LanmanWorkstation][Running/Auto Start]
  124.   <C:\Windows\System32\svchost.exe -k NetworkService-->%SystemRoot%\System32\wkssvc.dll><Microsoft Corporation>
  125. [Link-Layer Topology Discovery Mapper / lltdsvc][Stopped/Manual Start]
  126.   <C:\Windows\System32\svchost.exe -k LocalService-->%SystemRoot%\System32\lltdsvc.dll><Microsoft Corporation>
  127. [TCP/IP NetBIOS Helper / lmhosts][Running/Manual Start]
  128.   <C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted-->%SystemRoot%\System32\lmhsvc.dll><Microsoft Corporation>
  129. [Intel(R) Management and Security Application Local Management Service / LMS][Stopped/Manual Start]
  130.   <C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe><Intel Corporation>
  131. [Media Center Extender Service / Mcx2Svc][Stopped/Disabled]
  132.   <C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation-->%SystemRoot%\system32\Mcx2Svc.dll><Microsoft Corporation>
  133. [Multimedia Class Scheduler / MMCSS][Running/Manual Start]
  134.   <C:\Windows\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\mmcss.dll><Microsoft Corporation>
  135. [Windows Firewall / MpsSvc][Stopped/Manual Start]
  136.   <C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork-->%SystemRoot%\system32\mpssvc.dll><Microsoft Corporation>
  137. [NVIDIA Display Driver Service / nvsvc][Stopped/Manual Start]
  138.   <C:\Windows\system32\nvvsvc.exe><NVIDIA Corporation>
  139. [Peer Networking Identity Manager / p2pimsvc][Stopped/Manual Start]
  140.   <C:\Windows\System32\svchost.exe -k LocalServicePeerNet-->%SystemRoot%\system32\pnrpsvc.dll><Microsoft Corporation>
  141. [Peer Networking Grouping / p2psvc][Stopped/Manual Start]
  142.   <C:\Windows\System32\svchost.exe -k LocalServicePeerNet-->%SystemRoot%\system32\p2psvc.dll><Microsoft Corporation>
  143. [Program Compatibility Assistant Service / PcaSvc][Stopped/Manual Start]
  144.   <C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted-->%SystemRoot%\System32\pcasvc.dll><Microsoft Corporation>
  145. [BranchCache / PeerDistSvc][Stopped/Manual Start]
  146.   <C:\Windows\System32\svchost.exe -k PeerDist-->%SystemRoot%\system32\peerdistsvc.dll><Microsoft Corporation>
  147. [Plug and Play / PlugPlay][Running/Auto Start]
  148.   <C:\Windows\system32\svchost.exe -k DcomLaunch-->%SystemRoot%\system32\umpnpmgr.dll><Microsoft Corporation>
  149. [PnkBstrA / PnkBstrA][Stopped/Manual Start]
  150.   <C:\Windows\system32\PnkBstrA.exe><N/A>
  151. [PNRP Machine Name Publication Service / PNRPAutoReg][Stopped/Manual Start]
  152.   <C:\Windows\System32\svchost.exe -k LocalServicePeerNet-->%SystemRoot%\system32\pnrpauto.dll><Microsoft Corporation>
  153. [Peer Name Resolution Protocol / PNRPsvc][Stopped/Manual Start]
  154.   <C:\Windows\System32\svchost.exe -k LocalServicePeerNet-->%SystemRoot%\system32\pnrpsvc.dll><Microsoft Corporation>
  155. [IPsec Policy Agent / PolicyAgent][Stopped/Disabled]
  156.   <C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted-->%SystemRoot%\System32\ipsecsvc.dll><Microsoft Corporation>
  157. [Power / Power][Running/Manual Start]
  158.   <C:\Windows\system32\svchost.exe -k DcomLaunch-->%SystemRoot%\system32\umpo.dll><Microsoft Corporation>
  159. [User Profile Service / ProfSvc][Running/Auto Start]
  160.   <C:\Windows\system32\svchost.exe -k netsvcs-->%systemroot%\system32\profsvc.dll><Microsoft Corporation>
  161. [NVIDIA Stereoscopic 3D Driver Service / Stereo Service][Stopped/Manual Start]
  162.   <C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe><NVIDIA Corporation>
  163. [Windows Image Acquisition (WIA) / stisvc][Stopped/Disabled]
  164.   <C:\Windows\system32\svchost.exe -k imgsvc-->%SystemRoot%\System32\wiaservc.dll><Microsoft Corporation>
  165. [Microsoft Software Shadow Copy Provider / swprv][Running/Manual Start]
  166.   <C:\Windows\System32\svchost.exe -k swprv-->%Systemroot%\System32\swprv.dll><Microsoft Corporation>
  167. [Superfetch / SysMain][Running/Auto Start]
  168.   <C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted-->%systemroot%\system32\sysmain.dll><Microsoft Corporation>
  169. [Tablet PC Input Service / TabletInputService][Stopped/Manual Start]
  170.   <C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted-->%SystemRoot%\System32\TabSvc.dll><Microsoft Corporation>
  171. [TPM Base Services / TBS][Stopped/Manual Start]
  172.   <C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation-->%SystemRoot%\System32\tbssvc.dll><Microsoft Corporation>
  173. [Remote Desktop Services / TermService][Stopped/Manual Start]
  174.   <C:\Windows\System32\svchost.exe -k NetworkService-->%SystemRoot%\System32\termsrv.dll><Microsoft Corporation>
  175. [Themes / Themes][Running/Auto Start]
  176.   <C:\Windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\system32\themeservice.dll><Microsoft Corporation>
  177. [Thread Ordering Server / THREADORDER][Stopped/Manual Start]
  178.   <C:\Windows\system32\svchost.exe -k LocalService-->%SystemRoot%\system32\mmcss.dll><Microsoft Corporation>
  179. [Distributed Link Tracking Client / TrkWks][Stopped/Manual Start]
  180.   <C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted-->%SystemRoot%\System32\trkwks.dll><Microsoft Corporation>
  181. [Intel(R) Management and Security Application User Notification Service / UNS][Stopped/Manual Start]
  182.   <"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"><Intel Corporation>
  183. [Desktop Window Manager Session Manager / UxSms][Running/Auto Start]
  184.   <C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted-->%SystemRoot%\System32\uxsms.dll><Microsoft Corporation>
  185. [VMware Authorization Service / VMAuthdService][Stopped/Manual Start]
  186.   <"D:\Program Files\VMware Workstation\VMware\vmware-authd.exe"><VMware, Inc.>
  187. [VMware DHCP Service / VMnetDHCP][Stopped/Manual Start]
  188.   <C:\Windows\system32\vmnetdhcp.exe><VMware, Inc.>
  189. [VMware USB Arbitration Service / VMUSBArbService][Stopped/Manual Start]
  190.   <"C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe"><VMware, Inc.>
  191. [VMware NAT Service / VMware NAT Service][Stopped/Manual Start]
  192.   <C:\Windows\system32\vmnat.exe><VMware, Inc.>
  193. [WatchData ccb V3.2 / WDMonitorCCB][Running/Auto Start]
  194.   <C:\Windows\SysWOW64\WatchData\Watchdata CCB CSP v3.2\WDKeyMonitorCCB.exe><Beijing WatchData System Co., Ltd.>
  195. [Windows Event Collector / Wecsvc][Stopped/Manual Start]
  196.   <C:\Windows\system32\svchost.exe -k NetworkService-->%SystemRoot%\system32\wecsvc.dll><Microsoft Corporation>
  197. [Problem Reports and Solutions Control Panel Support / wercplsupport][Stopped/Manual Start]
  198.   <C:\Windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\wercplsupport.dll><Microsoft Corporation>
  199. [Windows Error Reporting Service / WerSvc][Stopped/Disabled]
  200.   <C:\Windows\System32\svchost.exe -k WerSvcGroup-->%SystemRoot%\System32\WerSvc.dll><Microsoft Corporation>
  201. [Windows Defender / WinDefend][Stopped/Disabled]
  202.   <C:\Windows\System32\svchost.exe -k secsvcs-->%ProgramFiles%\Windows Defender\mpsvc.dll><N/A>
  203. [Windows Management Instrumentation / Winmgmt][Running/Auto Start]
  204.   <C:\Windows\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\wbem\WMIsvc.dll><Microsoft Corporation>
  205. [WLAN AutoConfig / Wlansvc][Running/Auto Start]
  206.   <C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted-->%SystemRoot%\System32\wlansvc.dll><Microsoft Corporation>

  207. ==================================
  208. 驱动程序
  209. [adp94xx / adp94xx][Stopped/Manual Start]
  210.   <\SystemRoot\system32\drivers\adp94xx.sys><Adaptec, Inc.>
  211. [adpahci / adpahci][Stopped/Manual Start]
  212.   <\SystemRoot\system32\drivers\adpahci.sys><Adaptec, Inc.>
  213. [adpu320 / adpu320][Stopped/Manual Start]
  214.   <\SystemRoot\system32\drivers\adpu320.sys><Adaptec, Inc.>
  215. [aliide / aliide][Stopped/Manual Start]
  216.   <\SystemRoot\system32\drivers\aliide.sys><Acer Laboratories Inc.>
  217. [amdsata / amdsata][Stopped/Manual Start]
  218.   <\SystemRoot\system32\drivers\amdsata.sys><Advanced Micro Devices>
  219. [amdsbs / amdsbs][Stopped/Manual Start]
  220.   <\SystemRoot\system32\drivers\amdsbs.sys><AMD Technologies Inc.>
  221. [amdxata / amdxata][Running/Boot Start]
  222.   <\SystemRoot\system32\drivers\amdxata.sys><Advanced Micro Devices>
  223. [arc / arc][Stopped/Manual Start]
  224.   <\SystemRoot\system32\drivers\arc.sys><Adaptec, Inc.>
  225. [arcsas / arcsas][Stopped/Manual Start]
  226.   <\SystemRoot\system32\drivers\arcsas.sys><Adaptec, Inc.>
  227. [Qualcomm Atheros Extensible Wireless LAN device driver / athr][Running/Manual Start]
  228.   <system32\DRIVERS\athrx.sys><Qualcomm Atheros Communications, Inc.>
  229. [avgntflt / avgntflt][Running/Auto Start]
  230.   <system32\DRIVERS\avgntflt.sys><Avira GmbH>
  231. [avipbb / avipbb][Running/System Start]
  232.   <system32\DRIVERS\avipbb.sys><Avira GmbH>
  233. [avkmgr / avkmgr][Running/System Start]
  234.   <system32\DRIVERS\avkmgr.sys><Avira GmbH>
  235. [Broadcom NetXtreme II VBD / b06bdrv][Stopped/Manual Start]
  236.   <\SystemRoot\system32\drivers\bxvbda.sys><Broadcom Corporation>
  237. [Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 / b57nd60a][Stopped/Manual Start]
  238.   <system32\DRIVERS\b57nd60a.sys><Broadcom Corporation>
  239. [Brother USB Mass-Storage Lower Filter Driver / BrFiltLo][Stopped/Manual Start]
  240.   <\SystemRoot\system32\drivers\BrFiltLo.sys><Brother Industries, Ltd.>
  241. [Brother USB Mass-Storage Upper Filter Driver / BrFiltUp][Stopped/Manual Start]
  242.   <\SystemRoot\system32\drivers\BrFiltUp.sys><Brother Industries, Ltd.>
  243. [Brother MFC Serial Port Interface Driver (WDM) / Brserid][Stopped/Manual Start]
  244.   <\SystemRoot\System32\Drivers\Brserid.sys><Brother Industries Ltd.>
  245. [Brother WDM Serial driver / BrSerWdm][Stopped/Manual Start]
  246.   <\SystemRoot\System32\Drivers\BrSerWdm.sys><Brother Industries Ltd.>
  247. [Brother MFC USB Fax Only Modem / BrUsbMdm][Stopped/Manual Start]
  248.   <\SystemRoot\System32\Drivers\BrUsbMdm.sys><Brother Industries Ltd.>
  249. [Brother MFC USB Serial WDM Driver / BrUsbSer][Stopped/Manual Start]
  250.   <\SystemRoot\System32\Drivers\BrUsbSer.sys><Brother Industries Ltd.>
  251. [COMODO Internet Security Sandbox Driver / cmdGuard][Running/System Start]
  252.   <System32\DRIVERS\cmdguard.sys><COMODO>
  253. [COMODO Internet Security Helper Driver / cmdHlp][Running/System Start]
  254.   <System32\DRIVERS\cmdhlp.sys><COMODO>
  255. [cmdide / cmdide][Stopped/Manual Start]
  256.   <\SystemRoot\system32\drivers\cmdide.sys><CMD Technology, Inc.>
  257. [cpuz135 / cpuz135][Stopped/Manual Start]
  258.   <\??\C:\Users\ADMINI~1\AppData\Local\Temp\DTL135\DTL135_x64.sys><N/A>
  259. [Realtek Turbo Disk Filter Driver / diskperf64][Running/Manual Start]
  260.   <System32\Drivers\diskperf64.sys><Realtek Semiconductor Corp.>
  261. [Broadcom NetXtreme II 10 GigE VBD / ebdrv][Stopped/Manual Start]
  262.   <\SystemRoot\system32\drivers\evbda.sys><Broadcom Corporation>
  263. [elxstor / elxstor][Stopped/Manual Start]
  264.   <\SystemRoot\system32\drivers\elxstor.sys><Emulex>
  265. [ELAN PS/2 Port Input Device / ETD][Running/Manual Start]
  266.   <system32\DRIVERS\ETD.sys><ELAN Microelectronic Corp.>
  267. [VMware hcmon / hcmon][Running/Auto Start]
  268.   <\??\C:\Windows\system32\drivers\hcmon.sys><VMware, Inc.>
  269. [Hauppauge Consumer Infrared Receiver / hcw85cir][Stopped/Manual Start]
  270.   <\SystemRoot\system32\drivers\hcw85cir.sys><Hauppauge Computer Works, Inc.>
  271. [HpSAMD / HpSAMD][Stopped/Manual Start]
  272.   <\SystemRoot\system32\drivers\HpSAMD.sys><Hewlett-Packard Company>
  273. [HWCore / HWCore][Stopped/Manual Start]
  274.   <\??\D:\安装软件\驱动人生\DriveTheLife2012\hwcore.sys><N/A>
  275. [HWiNFO32/64 Kernel Driver / HWiNFO32][Stopped/System Start]
  276.   <\??\C:\Users\ADMINI~1\AppData\Local\Temp\Mydrivers64A.SYS><N/A>
  277. [Intel AHCI Controller / iaStor][Running/Boot Start]
  278.   <\SystemRoot\system32\DRIVERS\iaStor.sys><Intel Corporation>
  279. [iaStorV / iaStorV][Stopped/Manual Start]
  280.   <\SystemRoot\system32\drivers\iaStorV.sys><Intel Corporation>
  281. [iirsp / iirsp][Stopped/Manual Start]
  282.   <\SystemRoot\system32\drivers\iirsp.sys><Intel Corp./ICP vortex GmbH>
  283. [COMODO Internet Security Firewall Driver / inspect][Running/System Start]
  284.   <system32\DRIVERS\inspect.sys><COMODO>
  285. [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
  286.   <system32\drivers\RTKVHD64.sys><Realtek Semiconductor Corp.>
  287. [Keyboard Filter / kbfiltr][Running/Manual Start]
  288.   <system32\DRIVERS\kbfiltr.sys><>
  289. [kmodurl / kmodurl][Running/System Start]
  290.   <\??\c:\program files (x86)\ksafe\kmodurl64.sys><Kingsoft Corporation>
  291. [ksfmonsys / ksfmonsys][Running/Manual Start]
  292.   <\??\c:\program files (x86)\ksafe\ksfmonsys64.sys><Kingsoft Corporation>
  293. [LSI_FC / LSI_FC][Stopped/Manual Start]
  294.   <\SystemRoot\system32\drivers\lsi_fc.sys><LSI Corporation>
  295. [LSI_SAS / LSI_SAS][Stopped/Manual Start]
  296.   <\SystemRoot\system32\drivers\lsi_sas.sys><LSI Corporation>
  297. [LSI_SAS2 / LSI_SAS2][Stopped/Manual Start]
  298.   <\SystemRoot\system32\drivers\lsi_sas2.sys><LSI Corporation>
  299. [LSI_SCSI / LSI_SCSI][Stopped/Manual Start]
  300.   <\SystemRoot\system32\drivers\lsi_scsi.sys><LSI Corporation>
  301. [megasas / megasas][Stopped/Manual Start]
  302.   <\SystemRoot\system32\drivers\megasas.sys><LSI Corporation>
  303. [MegaSR / MegaSR][Stopped/Manual Start]
  304.   <\SystemRoot\system32\drivers\MegaSR.sys><LSI Corporation, Inc.>
  305. [Intel(R) Management Engine Interface  / MEIx64][Running/Manual Start]
  306.   <system32\DRIVERS\HECIx64.sys><Intel Corporation>
  307. [nfrd960 / nfrd960][Stopped/Manual Start]
  308.   <\SystemRoot\system32\drivers\nfrd960.sys><IBM Corporation>
  309. [WinPcap Packet Driver (NPF) / NPF][Stopped/Manual Start]
  310.   <system32\drivers\NPF.sys><N/A>
  311. [Service for NVIDIA High Definition Audio Driver / NVHDA][Running/Manual Start]
  312.   <system32\drivers\nvhda64v.sys><NVIDIA Corporation>
  313. [nvlddmkm / nvlddmkm][Running/Manual Start]
  314.   <system32\DRIVERS\nvlddmkm.sys><NVIDIA Corporation>
  315. [nvraid / nvraid][Stopped/Manual Start]
  316.   <\SystemRoot\system32\drivers\nvraid.sys><NVIDIA Corporation>
  317. [nvstor / nvstor][Stopped/Manual Start]
  318.   <\SystemRoot\system32\drivers\nvstor.sys><NVIDIA Corporation>
  319. [ql2300 / ql2300][Stopped/Manual Start]
  320.   <\SystemRoot\system32\drivers\ql2300.sys><QLogic Corporation>
  321. [ql40xx / ql40xx][Stopped/Manual Start]
  322.   <\SystemRoot\system32\drivers\ql40xx.sys><QLogic Corporation>
  323. [RtsUVStor.Sys Realtek USB Card Reader / RSUSBVSTOR][Running/Manual Start]
  324.   <System32\Drivers\RtsUVStor.sys><Realtek Semiconductor Corp.>
  325. [Realtek 8167 NT Driver / RTL8167][Running/Manual Start]
  326.   <system32\DRIVERS\Rt64win7.sys><Realtek>
  327. [Serial / Serial][Stopped/Manual Start]
  328.   <\SystemRoot\system32\drivers\serial.sys><Brother Industries Ltd.>
  329. [SiSRaid2 / SiSRaid2][Stopped/Manual Start]
  330.   <\SystemRoot\system32\drivers\SiSRaid2.sys><Silicon Integrated Systems Corp.>
  331. [SiSRaid4 / SiSRaid4][Stopped/Manual Start]
  332.   <\SystemRoot\system32\drivers\sisraid4.sys><Silicon Integrated Systems>
  333. [stexstor / stexstor][Stopped/Manual Start]
  334.   <\SystemRoot\system32\drivers\stexstor.sys><Promise Technology>
  335. [TesSafe / TesSafe][Stopped/Manual Start]
  336.   <\??\C:\Windows\system32\TesSafe.sys><TENCENT>
  337. [TweakCubeVD / TweakCubeVD][Stopped/Manual Start]
  338.   <system32\drivers\TweakCubeVD.sys><青岛软媒网络科技有限公司>
  339. [VGPU / VGPU][Stopped/Manual Start]
  340.   <System32\drivers\rdvgkmd.sys><N/A>
  341. [viaide / viaide][Stopped/Manual Start]
  342.   <\SystemRoot\system32\drivers\viaide.sys><VIA Technologies, Inc.>
  343. [VMware VMCI Bus Driver / vmci][Running/Boot Start]
  344.   <\SystemRoot\system32\DRIVERS\vmci.sys><VMware, Inc.>
  345. [VMware kbd / vmkbd][Stopped/Manual Start]
  346.   <\??\C:\Windows\system32\drivers\VMkbd.sys><VMware, Inc.>
  347. [VMware Virtual Ethernet Adapter Driver / VMnetAdapter][Running/Manual Start]
  348.   <system32\DRIVERS\vmnetadapter.sys><VMware, Inc.>
  349. [VMware Network Application Interface / VMnetuserif][Running/Auto Start]
  350.   <\??\C:\Windows\system32\drivers\vmnetuserif.sys><VMware, Inc.>
  351. [VMware USB Client Driver / vmusb][Stopped/Manual Start]
  352.   <System32\Drivers\vmusb.sys><VMware, Inc.>
  353. [VMware vmx86 / vmx86][Running/Auto Start]
  354.   <\??\C:\Windows\system32\drivers\vmx86.sys><VMware, Inc.>
  355. [vsmraid / vsmraid][Stopped/Manual Start]
  356.   <\SystemRoot\system32\drivers\vsmraid.sys><VIA Technologies Inc.,Ltd>
  357. [Vstor2 MntApi 1.0 Driver (shared) / vstor2-mntapi10-shared][Running/Auto Start]
  358.   <\??\C:\Windows\SysWOW64\drivers\vstor2-mntapi10-shared.sys><VMware, Inc.>

  359. ==================================
  360. 浏览器加载项
  361. [迅雷FLV视频嗅探及下载支持]
  362.   {0EA37B17-6B8B-4085-8257-F3A4AA69C27A} <D:\安装软件\迅雷\BHO\XlBrowserAddin1.0.7.70.dll, (Signed) 深圳市迅雷网络技术有限公司>
  363. [迅雷下载支持]
  364.   {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\安装软件\迅雷\BHO\XunleiBHO7.2.6.3428.dll, (Signed) 深圳市迅雷网络技术有限公司>
  365. [Office Document Cache Handler]
  366.   {B4F3A835-0E21-4959-BA22-42B3008E02FF} <D:\安装软件\office\Office14\URLREDIR.DLL, (Signed) Microsoft Corporation>
  367. []
  368.   {002AE4F2-96AB-4dfa-AE2E-605217F8A84C} <, >
  369. []
  370.   {004B0726-A010-4ABF-8556-FCDB7F1FCA1E} <, >
  371. [迅雷FLV视频嗅探及下载支持代{过}{滤}理]
  372.   {0C27ADC4-E826-4620-A3A7-990D7E05545F} <D:\安装软件\迅雷\BHO\XlBrowserAddin1.0.7.70.dll, (Signed) 深圳市迅雷网络技术有限公司>
  373. [迅雷FLV视频嗅探及下载支持]
  374.   {0EA37B17-6B8B-4085-8257-F3A4AA69C27A} <D:\安装软件\迅雷\BHO\XlBrowserAddin1.0.7.70.dll, (Signed) 深圳市迅雷网络技术有限公司>
  375. []
  376.   {1663ED61-23EB-11D2-B92F-008048FDD814} <, >
  377. [iTrusPTA Class]
  378.   {1E0DFFCF-27FF-4574-849B-55007349FEDA} <C:\Windows\SysWow64\aliedit\2.5.0.3\pta.dll, (Signed) iTruschina Co., Ltd.>
  379. [InfoScan Control]
  380.   {1F14548F-6975-40F1-AE24-6E2D1D449B2F} <C:\PROGRA~2\CCBCOM~1\Detector\InfoScan.dll, CCB>
  381. [Windows Media Player]
  382.   {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\Windows\SysWOW64\wmpdxm.dll, (Signed) Microsoft Corporation>
  383. [HTML Document]
  384.   {25336920-03F9-11CF-8FD0-00AA00686F13} <C:\Windows\SysWOW64\mshtml.dll, (Signed) Microsoft Corporation>
  385. [Agent Class]
  386.   {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <D:\安装软件\迅雷\BHO\ThunderAgent7.2.6.3428.dll, (Signed) 深圳市迅雷网络技术有限公司>
  387. [EditCtrl Class]
  388.   {488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\Windows\SysWow64\aliedit\2.5.0.3\aliedit.dll, (Signed) >
  389. [HHCtrl Object]
  390.   {52A2AAAE-085D-4187-97EA-8C30DB990436} <%SystemRoot%\System32\hhctrl.ocx, (Signed) N/A>
  391. [迅雷发行IE支持]
  392.   {5FFF24BC-DC02-4808-B4E0-A8E2C93FE407} <D:\安装软件\迅雷\BHO\xlfxctrl1.0.1.64.dll, (Signed) 深圳市迅雷网络技术有限公司>
  393. [Windows Media Player]
  394.   {6BF52A52-394A-11D3-B153-00C04F79FAA6} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
  395. [Access UserInfo by Script]
  396.   {6EE9CD3E-A386-4DAE-9737-A759DBF927AE} <D:\安装软件\迅雷\BHO\UserAgent1.0.2.10.dll, (Signed) 深圳市迅雷网络技术有限公司>
  397. [CertEnroll Class]
  398.   {7978461C-CC22-48F2-BC69-02220D3E101D} <C:\Windows\SysWow64\aliedit\2.5.0.3\itrusenroll.dll, (Signed) iTruschina Co., Ltd.>
  399. [XunleiBHO Class]
  400.   {802F530B-A8F6-4631-AE49-6BACAAC6373E} <D:\安装软件\迅雷\BHO\XunleiBHO7.2.6.3428.dll, (Signed) 深圳市迅雷网络技术有限公司>
  401. []
  402.   {87515F61-A66C-4319-A0E0-D416CB8059E3} <, >
  403. [Microsoft Web Browser]
  404.   {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\Windows\SysWOW64\ieframe.dll, (Signed) Microsoft Corporation>
  405. [迅雷下载支持]
  406.   {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\安装软件\迅雷\BHO\XunleiBHO7.2.6.3428.dll, (Signed) 深圳市迅雷网络技术有限公司>
  407. [迅雷资源关键字嗅探]
  408.   {9AA238FE-8298-48C9-B188-05B6AEE76C3A} <, >
  409. [Office Document Cache Handler]
  410.   {B4F3A835-0E21-4959-BA22-42B3008E02FF} <D:\安装软件\office\Office14\URLREDIR.DLL, (Signed) Microsoft Corporation>
  411. []
  412.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <, >
  413. [InfosecCCBNetSign Class]
  414.   {BC96F5A4-C930-4226-ADAB-59349AE585E9} <C:\Program Files (x86)\CCBComponents\Detector\CCBNetSignCom.dll, (Signed) Infosec Technologies Co., Ltd.>
  415. [Google Update Plugin]
  416.   {C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D} <C:\Users\Administrator\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll, (Signed) Google Inc.>
  417. [Google Update Plugin]
  418.   {C442AC41-9200-4770-8CC0-7CDB4F245C55} <C:\Users\Administrator\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll, (Signed) Google Inc.>
  419. [AUDIO__MID Moniker Class]
  420.   {CD3AFA74-B84F-48F0-9393-7EDC34128127} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
  421. [WDCCBCtrl Class]
  422.   {CE0460F5-48BD-4DC1-A046-0BDCB5A06CEB} <C:\Windows\SysWow64\wdccb.dll, (Signed) >
  423. [Shockwave Flash Object]
  424.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\SysWOW64\Macromed\Flash\Flash32_11_2_202_235.ocx, (Signed) Adobe Systems, Inc.>
  425. [SSOForPTLogin2 Class]
  426.   {EAAED308-7322-4B9B-965E-171933ADD473} <D:\安装软件\腾讯\qq\bin\npSSOAxCtrlForPTLogin.dll, (Signed) >
  427. [XML HTTP Request]
  428.   {ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
  429. [XML HTTP]
  430.   {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
  431. [webmod Class]
  432.   {FEE3C8C5-9BEA-4079-AB36-63ECABFC7392} <C:\Windows\SysWow64\aliedit\2.5.0.3\alidcp.dll, (Signed) Alipay.com Co.,Ltd>
  433. [使用迅雷下载]
  434.   <D:\安装软件\迅雷\BHO\geturl.htm, N/A>
  435. [使用迅雷下载全部链接]
  436.   <D:\安装软件\迅雷\BHO\GetAllUrl.htm, N/A>

  437. ==================================
  438. 正在运行的进程
  439. [PID: 1292 / SYSTEM][C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe]  [Avira Operations GmbH & Co. KG, 12.1.0.18]
  440.     [C:\Windows\SysWOW64\guard32.dll]  [COMODO, 5, 10, 228257, 2253]
  441.     [C:\Program Files (x86)\Avira\AntiVir Desktop\grdcore.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.20]
  442.     [c:\program files (x86)\avira\antivir desktop\cfglib.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  443.     [c:\program files (x86)\avira\antivir desktop\gpgen.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.18]
  444.     [c:\program files (x86)\avira\antivir desktop\gpgrd.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  445.     [c:\program files (x86)\avira\antivir desktop\gpipc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  446.     [c:\program files (x86)\avira\antivir desktop\gpavgio.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.18]
  447.     [c:\program files (x86)\avira\antivir desktop\gpgui.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  448.     [c:\program files (x86)\avira\antivir desktop\gplegacy.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  449.     [c:\program files (x86)\avira\antivir desktop\gpgenrep.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.20]
  450.     [c:\program files (x86)\avira\antivir desktop\onlcfg.dll]  [Avira Operations GmbH & Co. KG, 12.1.1.17]
  451.     [C:\Program Files (x86)\Avira\AntiVir Desktop\avevtlog.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  452.     [C:\Program Files (x86)\Avira\AntiVir Desktop\guardmsg.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.18]
  453.     [C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll]  [, 3.07.00.00]
  454.     [C:\Program Files (x86)\Avira\AntiVir Desktop\avipc.dll]  [Avira Operations GmbH & Co. KG, 12.1.6.4]
  455.     [C:\Program Files (x86)\Avira\AntiVir Desktop\AVGIO.DLL]  [Avira Operations GmbH & Co. KG, 12.1.19.17]
  456.     [c:\program files (x86)\avira\antivir desktop\avpref.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  457.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aecore.dll]  [Avira Operations GmbH & Co. KG, 8.1.25.6]
  458.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aevdf.dll]  [Avira Operations GmbH & Co. KG, 8.1.2.2]
  459.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aescript.dll]  [Avira Operations GmbH & Co. KG, 8.1.4.18]
  460.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aescn.dll]  [Avira Operations GmbH & Co. KG, 8.1.8.2]
  461.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aesbx.dll]  [Avira Operations GmbH & Co. KG, 8.2.5.5]
  462.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aerdl.dll]  [Avira GmbH, 8.1.9.15]
  463.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aepack.dll]  [Avira Operations GmbH & Co. KG, 8.2.16.12]
  464.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aeoffice.dll]  [Avira Operations GmbH & Co. KG, 8.1.2.28]
  465.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aeheur.dll]  [Avira Operations GmbH & Co. KG, 8.1.4.23]
  466.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aehelp.dll]  [Avira Operations GmbH & Co. KG, 8.1.20.0]
  467.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aegen.dll]  [Avira Operations GmbH & Co. KG, 8.1.5.28]
  468.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aeexp.dll]  [Avira Operations GmbH & Co. KG, 8.1.0.35]
  469.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aeemu.dll]  [Avira GmbH, 8.1.3.0]
  470.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aebb.dll]  [Avira GmbH, 8.1.1.0]
  471.     [c:\program files (x86)\avira\antivir desktop\avesvc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  472.     [c:\program files (x86)\avira\antivir desktop\avesvcr.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  473.     [c:\program files (x86)\avira\antivir desktop\webcat.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  474.     [C:\Program Files (x86)\Avira\AntiVir Desktop\webcatrc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  475.     [c:\program files (x86)\avira\antivir desktop\avreg.dll]  [Avira Operations GmbH, 12.3.0.15]
  476. [PID: 1380 / SYSTEM][c:\program files (x86)\ksafe\KSafeSvc.exe]  [Kingsoft Corporation, 3.6.2.2500]
  477.     [c:\program files (x86)\ksafe\json.dll]  [N/A, ]
  478.     [C:\Windows\SysWOW64\guard32.dll]  [COMODO, 5, 10, 228257, 2253]
  479.     [c:\program files (x86)\ksafe\kdump.dll]  [Kingsoft Corporation, 2011,05,31,2002]
  480.     [c:\program files (x86)\ksafe\kxebase.dll]  [Kingsoft Corporation, 2010,5,12,402]
  481.     [c:\program files (x86)\ksafe\scom.dll]  [Kingsoft Corporation, 2010,5,12,402]
  482.     [c:\program files (x86)\ksafe\kxecore\kxecore.dll]  [Kingsoft Corporation, 2010,5,12,402]
  483.     [c:\program files (x86)\ksafe\kexectrl.dll]  [Kingsoft Corporation, 2010,09,18,1422]
  484.     [c:\program files (x86)\ksafe\kwssp.dll]  [Kingsoft Corporation, 2012.04.13.2500]
  485.     [c:\program files (x86)\ksafe\netstat.dll]  [Kingsoft Corporation, 3.6.2.2500]
  486.     [c:\program files (x86)\ksafe\fwproxy.dll]  [Kingsoft Corporation, 3.6.2.2500]
  487.     [c:\program files (x86)\ksafe\kse\ksecansp.dll]  [Kingsoft Corporation, 2011,04,21,1878]
  488.     [c:\program files (x86)\ksafe\kse\ksecorex.dll]  [Kingsoft Corporation, 2011,10,20,1846]
  489.     [c:\program files (x86)\ksafe\KEng\kae\kaecore.dat]  [Kingsoft Corporation, 2011,11,17,1887]
  490.     [c:\program files (x86)\ksafe\kse\wfs.dll]  [Kingsoft Corporation, 2010,08,23,1070]
  491.     [c:\program files (x86)\ksafe\kse\sqlite.dll]  [Kingsoft Corporation, 2010,03,30,781]
  492.     [c:\program files (x86)\ksafe\kse\ksbwdet2.dll]  [Kingsoft Corporation, 2012,04,09,2807]
  493.     [c:\program files (x86)\ksafe\KEng\kae\karchive.dat]  [Kingsoft Corporation, 2011,07,29,1746]
  494.     [c:\program files (x86)\ksafe\KEng\kae\kaearcha.dat]  [Kingsoft Corporation, 2010,11,19,1407]
  495.     [c:\program files (x86)\ksafe\KEng\kae\kaeolea.dat]  [Kingsoft Corporation, 2011,10,20,1847]
  496.     [c:\program files (x86)\ksafe\KEng\kae\kaearchb.dat]  [Kingsoft Corporation, 2011,09,23,1813]
  497.     [c:\program files (x86)\ksafe\kse\ksbcommsp.dll]  [Kingsoft Corporation, 2011,07,26,2126]
  498.     [c:\program files (x86)\ksafe\kse\BKReScan.dll]  [Kingsoft Corporation, 2011,04,27,1917]
  499. [PID: 1816 / SYSTEM][C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe]  [Avira Operations GmbH & Co. KG, 12.1.0.18]
  500.     [C:\Windows\SysWOW64\guard32.dll]  [COMODO, 5, 10, 228257, 2253]
  501.     [C:\Program Files (x86)\Avira\AntiVir Desktop\grdcore.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.20]
  502.     [c:\program files (x86)\avira\antivir desktop\cfglib.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  503.     [c:\program files (x86)\avira\antivir desktop\gpipc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  504.     [c:\program files (x86)\avira\antivir desktop\gpgen.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.18]
  505.     [c:\program files (x86)\avira\antivir desktop\gpschd.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.18]
  506.     [C:\Program Files (x86)\Avira\AntiVir Desktop\avevtlog.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  507.     [C:\Program Files (x86)\Avira\AntiVir Desktop\schedr.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  508.     [C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll]  [, 3.07.00.00]
  509.     [C:\Program Files (x86)\Avira\AntiVir Desktop\avipc.dll]  [Avira Operations GmbH & Co. KG, 12.1.6.4]
  510. [PID: 1916 / SYSTEM][C:\Windows\SysWOW64\HZ_CommSrv.exe]  [华大智宝电子系统有限公司, 1, 2, 0, 3]
  511.     [C:\Windows\SysWOW64\guard32.dll]  [COMODO, 5, 10, 228257, 2253]
  512. [PID: 1972 / SYSTEM][C:\Windows\SysWOW64\WatchData\Watchdata CCB CSP v3.2\WDKeyMonitorCCB.exe]  [ Beijing WatchData System Co., Ltd., 3, 2, 0, 0]
  513.     [C:\Windows\SysWOW64\guard32.dll]  [COMODO, 5, 10, 228257, 2253]
  514.     [C:\Windows\SysWOW64\WatchData\Watchdata CCB CSP v3.2\wdkmgr.dll]  [Watchdata, 2, 1, 1, 40]
  515. [PID: 3036 / Administrator][C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  516.     [C:\Windows\SysWOW64\guard32.dll]  [COMODO, 5, 10, 228257, 2253]
  517.     [C:\Program Files (x86)\Avira\AntiVir Desktop\ccwkrlib.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.19]
  518.     [c:\program files (x86)\avira\antivir desktop\cfglib.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  519.     [C:\Windows\system32\SOGOUPY.IME]  [Sogou.com Inc., 6.1.0.6953]
  520.     [C:\Program Files (x86)\SogouInput\6.1.0.6953\Resource.dll]  [Sogou.com Inc., 6.1.0.6953]
  521.     [c:\program files (x86)\avira\antivir desktop\ccguard.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  522.     [c:\program files (x86)\avira\antivir desktop\ccgrdrc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  523.     [c:\program files (x86)\avira\antivir desktop\ccgrdw.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  524.     [C:\Program Files (x86)\Avira\AntiVir Desktop\grdcore.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.20]
  525.     [c:\program files (x86)\avira\antivir desktop\gpipc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  526.     [C:\Program Files (x86)\Avira\AntiVir Desktop\avipc.dll]  [Avira Operations GmbH & Co. KG, 12.1.6.4]
  527.     [c:\program files (x86)\avira\antivir desktop\ccwgrd.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  528.     [c:\program files (x86)\avira\antivir desktop\ccgen.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.18]
  529.     [c:\program files (x86)\avira\antivir desktop\ccgenrc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  530.     [c:\program files (x86)\ksafe\ksfmon.dll]  [Kingsoft Corporation, 3.6.2.2500]
  531.     [c:\program files (x86)\avira\antivir desktop\ccupdate.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.20]
  532.     [c:\program files (x86)\avira\antivir desktop\ccupdrc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  533.     [c:\program files (x86)\avira\antivir desktop\cclic.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.18]
  534.     [c:\program files (x86)\avira\antivir desktop\cclicrc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  535.     [c:\program files (x86)\avira\antivir desktop\ccmsg.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  536.     [c:\program files (x86)\avira\antivir desktop\ccmsgrc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  537.     [c:\program files (x86)\avira\antivir desktop\ccmainrc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  538.     [C:\Program Files (x86)\Avira\AntiVir Desktop\rcimage.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.13]
  539. [PID: 3060 / Administrator][C:\Program Files (x86)\ksafe\ksafetray.exe]  [Kingsoft Corporation, 3.6.2.2519]
  540.     [C:\Program Files (x86)\ksafe\json.dll]  [N/A, ]
  541.     [C:\Windows\SysWOW64\guard32.dll]  [COMODO, 5, 10, 228257, 2253]
  542.     [c:\program files (x86)\ksafe\ksfmon.dll]  [Kingsoft Corporation, 3.6.2.2500]
  543.     [c:\program files (x86)\ksafe\kdump.dll]  [Kingsoft Corporation, 2011,05,31,2002]
  544.     [C:\Windows\system32\SOGOUPY.IME]  [Sogou.com Inc., 6.1.0.6953]
  545.     [C:\Program Files (x86)\SogouInput\6.1.0.6953\Resource.dll]  [Sogou.com Inc., 6.1.0.6953]
  546.     [c:\program files (x86)\ksafe\ksafedb.dll]  [Kingsoft Corporation, 3.6.2.2500]
  547.     [c:\program files (x86)\ksafe\khistory.dll]  [Kingsoft Corporation, 2011,08,26,2224]
  548.     [c:\program files (x86)\ksafe\kwsctrl.dll]  [Kingsoft Corporation, 3.6.2.2500]
  549.     [C:\Program Files (x86)\ksafe\ksafeup.dll]  [Kingsoft Corporation, 3.6.2.2500]
  550.     [c:\program files (x86)\ksafe\zlib1.dll]  [, 1.2.3]
  551.     [C:\Program Files (x86)\ksafe\krunopt.dll]  [Kingsoft Corporation, 3.6.2.2500]
  552.     [c:\program files (x86)\ksafe\kse\bkrescan.dll]  [Kingsoft Corporation, 2011,04,27,1917]
  553.     [c:\program files (x86)\ksafe\kse\sqlite.dll]  [Kingsoft Corporation, 2010,03,30,781]
  554.     [c:\program files (x86)\ksafe\KEng\ksignup.dll]  [Kingsoft Corporation, 1.1.0.2500]
  555.     [c:\program files (x86)\ksafe\KEng\KSGMerge.DLL]  [Kingsoft Corporation, 2011,05,12,1656]
  556. [PID: 968 / Administrator][C:\Program Files (x86)\CCBComponents\DMWZ\CCBCertificate.exe]  [, 2, 1, 7, 8]
  557.     [C:\Windows\SysWOW64\guard32.dll]  [COMODO, 5, 10, 228257, 2253]
  558.     [c:\program files (x86)\ksafe\ksfmon.dll]  [Kingsoft Corporation, 3.6.2.2500]
  559.     [C:\Windows\system32\SOGOUPY.IME]  [Sogou.com Inc., 6.1.0.6953]
  560.     [C:\Program Files (x86)\SogouInput\6.1.0.6953\Resource.dll]  [Sogou.com Inc., 6.1.0.6953]
  561.     [C:\Windows\system32\CCBKCSP.dll]  [, 1, 0, 0, 1]
  562.     [C:\Windows\system32\CCBKCAPI.dll]  [北京大明五洲科技有限公司, 2, 1, 7, 31]
  563. [PID: 3112 / Administrator][C:\Program Files (x86)\CCBComponents\HDZB\USBKeyTools.exe]  [北京华大智宝电子系统有限公司, 1, 6, 0, 35]
  564.     [C:\Windows\SysWOW64\guard32.dll]  [COMODO, 5, 10, 228257, 2253]
  565.     [C:\Windows\system32\ccb_hdcsp.dll]  [CIDC, 1, 4, 3, 49]
  566.     [c:\program files (x86)\ksafe\ksfmon.dll]  [Kingsoft Corporation, 3.6.2.2500]
  567.     [C:\Windows\system32\SOGOUPY.IME]  [Sogou.com Inc., 6.1.0.6953]
  568.     [C:\Program Files (x86)\SogouInput\6.1.0.6953\Resource.dll]  [Sogou.com Inc., 6.1.0.6953]
  569. [PID: 3144 / Administrator][D:\安装软件\联网客户端\ChinaNetSn\bin\NetKeeper.exe]  [XI AN XINLI SOFTWARE TECHNOLOGY CO.,LTD, 1, 0, 5, 5]
  570.     [D:\安装软件\联网客户端\ChinaNetSn\bin\8021x.dll]  [HarbourNetworks, 1, 0, 4, 5]
  571.     [D:\安装软件\联网客户端\ChinaNetSn\bin\W32N50_Proxy.dll]  [xinli, 1, 0, 4, 6]
  572.     [C:\Windows\system32\wpcap.dll]  [CACE Technologies, Inc., 4.1.0.1753]
  573.     [C:\Windows\system32\packet.dll]  [CACE Technologies, Inc., 4.1.0.1753]
  574.     [D:\安装软件\联网客户端\ChinaNetSn\bin\StringList.dll]  [N/A, ]
  575.     [C:\Windows\SysWOW64\guard32.dll]  [COMODO, 5, 10, 228257, 2253]
  576.     [c:\program files (x86)\ksafe\ksfmon.dll]  [Kingsoft Corporation, 3.6.2.2500]
  577.     [C:\Windows\system32\SOGOUPY.IME]  [Sogou.com Inc., 6.1.0.6953]
  578.     [C:\Program Files (x86)\SogouInput\6.1.0.6953\Resource.dll]  [Sogou.com Inc., 6.1.0.6953]
  579.     [C:\Windows\SysWOW64\Macromed\Flash\Flash32_11_2_202_235.ocx]  [Adobe Systems, Inc., 11,2,202,235]
  580.     [C:\Windows\system32\nvd3dum.dll]  [NVIDIA Corporation, 8.17.12.9610]
  581. [PID: 2136 / SYSTEM][C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe]  [(Verified) Microsoft Corporation, 2.0.50727.4927 (NetFXspW7.050727-4900)]
  582.     [C:\Windows\SysWOW64\guard32.dll]  [COMODO, 5, 10, 228257, 2253]
  583. [PID: 3568 / Administrator][C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe]  [Avira Operations GmbH & Co. KG, 12.1.0.18]
  584.     [C:\Windows\SysWOW64\guard32.dll]  [COMODO, 5, 10, 228257, 2253]
  585.     [C:\Program Files (x86)\Avira\AntiVir Desktop\ccwkrlib.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.19]
  586.     [c:\program files (x86)\avira\antivir desktop\ccmainrc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  587.     [c:\program files (x86)\avira\antivir desktop\cfglib.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  588.     [c:\program files (x86)\ksafe\ksfmon.dll]  [Kingsoft Corporation, 3.6.2.2500]
  589.     [C:\Windows\system32\SOGOUPY.IME]  [Sogou.com Inc., 6.1.0.6953]
  590.     [C:\Program Files (x86)\SogouInput\6.1.0.6953\Resource.dll]  [Sogou.com Inc., 6.1.0.6953]
  591.     [c:\program files (x86)\avira\antivir desktop\ccgen.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.18]
  592.     [c:\program files (x86)\avira\antivir desktop\ccgenrc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  593.     [c:\program files (x86)\avira\antivir desktop\ccprofil.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  594.     [c:\program files (x86)\avira\antivir desktop\ccscanrc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  595.     [c:\program files (x86)\avira\antivir desktop\ccguard.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  596.     [c:\program files (x86)\avira\antivir desktop\ccgrdrc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  597.     [c:\program files (x86)\avira\antivir desktop\ccgrdw.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  598.     [C:\Program Files (x86)\Avira\AntiVir Desktop\grdcore.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.20]
  599.     [c:\program files (x86)\avira\antivir desktop\gpipc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  600.     [C:\Program Files (x86)\Avira\AntiVir Desktop\avipc.dll]  [Avira Operations GmbH & Co. KG, 12.1.6.4]
  601.     [c:\program files (x86)\avira\antivir desktop\ccwgrd.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  602.     [c:\program files (x86)\avira\antivir desktop\ccquamgr.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  603.     [c:\program files (x86)\avira\antivir desktop\ccquarc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  604.     [c:\program files (x86)\avira\antivir desktop\ccsched.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  605.     [c:\program files (x86)\avira\antivir desktop\ccscherc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  606.     [c:\program files (x86)\avira\antivir desktop\ccreport.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  607.     [c:\program files (x86)\avira\antivir desktop\ccreporc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  608.     [c:\program files (x86)\avira\antivir desktop\ccev.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.19]
  609.     [c:\program files (x86)\avira\antivir desktop\ccevrc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  610.     [c:\program files (x86)\avira\antivir desktop\ccupdate.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.20]
  611.     [c:\program files (x86)\avira\antivir desktop\ccupdrc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  612.     [c:\program files (x86)\avira\antivir desktop\ccschedw.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  613.     [C:\Program Files (x86)\Avira\AntiVir Desktop\ccupdw.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  614.     [c:\program files (x86)\avira\antivir desktop\cclic.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.18]
  615.     [c:\program files (x86)\avira\antivir desktop\cclicrc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  616.     [c:\program files (x86)\avira\antivir desktop\cclicw.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  617.     [c:\program files (x86)\avira\antivir desktop\ccmsg.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  618.     [c:\program files (x86)\avira\antivir desktop\ccmsgrc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  619.     [c:\program files (x86)\avira\antivir desktop\ccevw.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  620.     [C:\Program Files (x86)\Avira\AntiVir Desktop\avevtlog.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  621.     [C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll]  [, 3.07.00.00]
  622.     [C:\Program Files (x86)\SogouExtension\sogouflash\1.0.0.117\SogouFlashDll.dll]  [Sogou.com Inc., 1.0.0.117]
  623.     [c:\program files (x86)\avira\antivir desktop\guardmsg.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.18]
  624.     [c:\program files (x86)\avira\antivir desktop\avesvcr.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  625.     [c:\program files (x86)\avira\antivir desktop\schedr.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  626.     [c:\program files (x86)\avira\antivir desktop\updaterc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  627.     [c:\program files (x86)\avira\antivir desktop\avscan.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.18]
  628.     [c:\program files (x86)\avira\antivir desktop\ccrepow.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  629.     [c:\program files (x86)\avira\antivir desktop\ccquaw.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  630.     [C:\Program Files (x86)\Avira\AntiVir Desktop\avpref.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  631. [PID: 2112 / Administrator][C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe]  [Avira Operations GmbH & Co. KG, 12.1.0.20]
  632.     [C:\Windows\SysWOW64\guard32.dll]  [COMODO, 5, 10, 228257, 2253]
  633.     [C:\Program Files (x86)\Avira\AntiVir Desktop\AVSCAN.DLL]  [Avira Operations GmbH & Co. KG, 12.1.0.18]
  634.     [C:\Program Files (x86)\Avira\AntiVir Desktop\AVWINLL.DLL]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  635.     [C:\Program Files (x86)\Avira\AntiVir Desktop\LUKE.DLL]  [Avira Operations GmbH & Co. KG, 12.1.0.19]
  636.     [C:\Program Files (x86)\Avira\AntiVir Desktop\ExtDlG{过}F{滤}W.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  637.     [C:\Program Files (x86)\Avira\AntiVir Desktop\ccwkrlib.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.19]
  638.     [c:\program files (x86)\avira\antivir desktop\cfglib.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  639.     [c:\program files (x86)\avira\antivir desktop\ccavscanex.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  640.     [c:\program files (x86)\avira\antivir desktop\ccavscanexrc.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  641.     [c:\program files (x86)\ksafe\ksfmon.dll]  [Kingsoft Corporation, 3.6.2.2500]
  642.     [C:\Windows\system32\SOGOUPY.IME]  [Sogou.com Inc., 6.1.0.6953]
  643.     [C:\Program Files (x86)\SogouInput\6.1.0.6953\Resource.dll]  [Sogou.com Inc., 6.1.0.6953]
  644.     [C:\Program Files (x86)\Avira\AntiVir Desktop\AVREP.DLL]  [Avira Operations GmbH & Co. KG, 12.3.0.15]
  645.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aecore.dll]  [Avira Operations GmbH & Co. KG, 8.1.25.6]
  646.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aevdf.dll]  [Avira Operations GmbH & Co. KG, 8.1.2.2]
  647.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aescript.dll]  [Avira Operations GmbH & Co. KG, 8.1.4.18]
  648.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aescn.dll]  [Avira Operations GmbH & Co. KG, 8.1.8.2]
  649.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aesbx.dll]  [Avira Operations GmbH & Co. KG, 8.2.5.5]
  650.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aerdl.dll]  [Avira GmbH, 8.1.9.15]
  651.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aepack.dll]  [Avira Operations GmbH & Co. KG, 8.2.16.12]
  652.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aeoffice.dll]  [Avira Operations GmbH & Co. KG, 8.1.2.28]
  653.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aeheur.dll]  [Avira Operations GmbH & Co. KG, 8.1.4.23]
  654.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aehelp.dll]  [Avira Operations GmbH & Co. KG, 8.1.20.0]
  655.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aegen.dll]  [Avira Operations GmbH & Co. KG, 8.1.5.28]
  656.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aeexp.dll]  [Avira Operations GmbH & Co. KG, 8.1.0.35]
  657.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aeemu.dll]  [Avira GmbH, 8.1.3.0]
  658.     [C:\Program Files (x86)\Avira\AntiVir Desktop\aebb.dll]  [Avira GmbH, 8.1.1.0]
  659.     [C:\Program Files (x86)\Avira\AntiVir Desktop\AVPREF.DLL]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  660.     [C:\Program Files (x86)\Avira\AntiVir Desktop\avevtlog.dll]  [Avira Operations GmbH & Co. KG, 12.1.0.17]
  661.     [C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll]  [, 3.07.00.00]
  662.     [C:\Program Files (x86)\Avira\AntiVir Desktop\AVSCPLR.DLL]  [Avira GmbH, 12.3.0.14]
  663.     [C:\Program Files (x86)\Avira\AntiVir Desktop\AVREG.DLL]  [Avira Operations GmbH, 12.3.0.15]
  664.     [C:\Program Files (x86)\Avira\AntiVir Desktop\AVARKT.DLL]  [Avira Operations GmbH & Co. KG, 12.1.0.23]
  665.     [C:\Program Files (x86)\Avira\AntiVir Desktop\avipc.dll]  [Avira Operations GmbH & Co. KG, 12.1.6.4]
  666. [PID: 4036 / Administrator][F:\资料百科\电脑\软件\安全\【SREng日志扫描】System Repair Engineer\SREngLdr.EXE]  [Smallfrogs Studio, 2.8.4.1331]
  667.     [C:\Windows\SysWOW64\guard32.dll]  [COMODO, 5, 10, 228257, 2253]
  668. [PID: 4044 / Administrator][F:\资料百科\电脑\软件\安全\【SREng日志扫描】System Repair Engineer\SREeeb58be3.EXE]  [Smallfrogs Studio, 2.8.4.1331]
  669.     [C:\Windows\SysWOW64\guard32.dll]  [COMODO, 5, 10, 228257, 2253]
  670.     [c:\program files (x86)\ksafe\ksfmon.dll]  [Kingsoft Corporation, 3.6.2.2500]
  671.     [C:\Windows\system32\SOGOUPY.IME]  [Sogou.com Inc., 6.1.0.6953]
  672.     [C:\Program Files (x86)\SogouInput\6.1.0.6953\Resource.dll]  [Sogou.com Inc., 6.1.0.6953]
  673.     [C:\Program Files (x86)\SogouExtension\sogouflash\1.0.0.117\SogouFlashDll.dll]  [Sogou.com Inc., 1.0.0.117]

  674. ==================================
  675. 文件关联
  676. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  677. .EXE  OK. ["%1" %*]
  678. .COM  OK. ["%1" %*]
  679. .PIF  OK. ["%1" %*]
  680. .REG  OK. [regedit.exe "%1"]
  681. .BAT  OK. ["%1" %*]
  682. .SCR  OK. ["%1" /S]
  683. .CHM  OK. ["%SystemRoot%\hh.exe" %1]
  684. .HLP  OK. [%SystemRoot%\winhlp32.exe %1]
  685. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  686. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  687. .VBS  OK. ["%SystemRoot%\System32\WScript.exe" "%1" %*]
  688. .JS   Error. [C:\Windows\System32\WScript.exe "%1" %*]
  689. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  690. ==================================
  691. Winsock 提供者
  692. VMCI sockets DGRAM
  693.     C:\Windows\system32\vsocklib.dll(VMware, Inc., VSockets Library)
  694. VMCI sockets STREAM
  695.     C:\Windows\system32\vsocklib.dll(VMware, Inc., VSockets Library)

  696. ==================================
  697. Autorun.inf
  698. N/A

  699. ==================================
  700. HOSTS 文件
  701. N/A

  702. ==================================
  703. 进程特权扫描
  704. N/A

  705. ==================================
  706. 计划任务
  707. [已禁用] \\adobe flash player updater
  708.         C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
  709. [已禁用] \\GoogleUpdateTaskUserS-1-5-21-3261666655-1295086780-3108116568-500Core
  710.         C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe /c
  711. [已禁用] \\GoogleUpdateTaskUserS-1-5-21-3261666655-1295086780-3108116568-500UA
  712.         C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
  713. [已启用] \\KsafeDelay
  714.         C:\Program Files (x86)\ksafe\KSafeTray.exe -delayruncheck /ua /installsource scheduler
  715. [已禁用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
  716.         N/A
  717. [已启用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
  718.         N/A
  719. [已禁用] \Microsoft\Windows\AppID\PolicyConverter
  720.         %windir%\system32\appidpolicyconverter.exe
  721. [已禁用] \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
  722.         %windir%\system32\appidcertstorecheck.exe
  723. [已禁用] \Microsoft\Windows\Application Experience\AitAgent
  724.         aitagent
  725. [已禁用] \Microsoft\Windows\Application Experience\ProgramDataUpdater
  726.         %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate
  727. [已禁用] \Microsoft\Windows\Autochk\Proxy
  728.         %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
  729. [已禁用] \Microsoft\Windows\Bluetooth\UninstallDeviceTask
  730.         BthUdTask.exe $(Arg0)
  731. [已启用] \Microsoft\Windows\CertificateServicesClient\SystemTask
  732.         N/A
  733. [已启用] \Microsoft\Windows\CertificateServicesClient\UserTask
  734.         N/A
  735. [已禁用] \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
  736.         N/A
  737. [已禁用] \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
  738.         %SystemRoot%\System32\wsqmcons.exe
  739. [已启用] \Microsoft\Windows\Defrag\ScheduledDefrag
  740.         %windir%\system32\defrag.exe -c
  741. [已禁用] \Microsoft\Windows\Location\Notifications
  742.         %windir%\System32\LocationNotifications.exe
  743. [已启用] \Microsoft\Windows\Maintenance\WinSAT
  744.         N/A
  745. [已禁用] \Microsoft\Windows\Media Center\ActivateWindowsSearch
  746.         %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
  747. [已禁用] \Microsoft\Windows\Media Center\ConfigureInternetTimeService
  748.         %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
  749. [已禁用] \Microsoft\Windows\Media Center\DispatchRecoveryTasks
  750.         %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
  751. [已禁用] \Microsoft\Windows\Media Center\ehDRMInit
  752.         %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
  753. [已禁用] \Microsoft\Windows\Media Center\InstallPlayReady
  754.         %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
  755. [已禁用] \Microsoft\Windows\Media Center\mcupdate
  756.         %SystemRoot%\ehome\mcupdate $(Arg0)
  757. [已禁用] \Microsoft\Windows\Media Center\MediaCenterRecoveryTask
  758.         %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
  759. [已禁用] \Microsoft\Windows\Media Center\MediaCenterRecoveryTask
  760.         %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
  761. [已禁用] \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
  762.         %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
  763. [已禁用] \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
  764.         %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
  765. [已禁用] \Microsoft\Windows\Media Center\OCURActivate
  766.         %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
  767. [已禁用] \Microsoft\Windows\Media Center\OCURDiscovery
  768.         %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
  769. [已禁用] \Microsoft\Windows\Media Center\PBDADiscovery
  770.         %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
  771. [已禁用] \Microsoft\Windows\Media Center\PBDADiscoveryW1
  772.         %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
  773. [已禁用] \Microsoft\Windows\Media Center\PBDADiscoveryW2
  774.         %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
  775. [已禁用] \Microsoft\Windows\Media Center\PeriodicScanRetry
  776.         %windir%\ehome\MCUpdate.exe -pscn 0
  777. [已禁用] \Microsoft\Windows\Media Center\PvrRecoveryTask
  778.         %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
  779. [已禁用] \Microsoft\Windows\Media Center\PvrRecoveryTask
  780.         %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
  781. [已禁用] \Microsoft\Windows\Media Center\PvrScheduleTask
  782.         %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
  783. [已禁用] \Microsoft\Windows\Media Center\PvrScheduleTask
  784.         %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
  785. [已禁用] \Microsoft\Windows\Media Center\RecordingRestart
  786.         %SystemRoot%\ehome\ehrec /RestartRecording
  787. [已禁用] \Microsoft\Windows\Media Center\RegisterSearch
  788.         %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
  789. [已禁用] \Microsoft\Windows\Media Center\ReindexSearchRoot
  790.         %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
  791. [已禁用] \Microsoft\Windows\Media Center\SqlLiteRecoveryTask
  792.         %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
  793. [已禁用] \Microsoft\Windows\Media Center\SqlLiteRecoveryTask
  794.         %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
  795. [已禁用] \Microsoft\Windows\Media Center\UpdateRecordPath
  796.         %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
  797. [已启用] \Microsoft\Windows\MobilePC\HotStart
  798.         N/A
  799. [已启用] \Microsoft\Windows\MUI\LPRemove
  800.         %windir%\system32\lpremove.exe
  801. [已启用] \Microsoft\Windows\Multimedia\SystemSoundsService
  802.         N/A
  803. [已启用] \Microsoft\Windows\NetTrace\GatherNetworkInfo
  804.         %windir%\system32\gatherNetworkInfo.vbs
  805. [已禁用] \Microsoft\Windows\Offline Files\Background Synchronization
  806.         N/A
  807. [已禁用] \Microsoft\Windows\Offline Files\Logon Synchronization
  808.         N/A
  809. [已启用] \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
  810.         %SystemRoot%\System32\powercfg.exe -energy -auto
  811. [已启用] \Microsoft\Windows\Ras\MobilityManager
  812.         N/A
  813. [已禁用] \Microsoft\Windows\SideShow\AutoWake
  814.         N/A
  815. [已启用] \Microsoft\Windows\SideShow\GadgetManager
  816.         N/A
  817. [已禁用] \Microsoft\Windows\SideShow\SessionAgent
  818.         N/A
  819. [已禁用] \Microsoft\Windows\SideShow\SystemDataProviders
  820.         N/A
  821. [已禁用] \Microsoft\Windows\SystemRestore\SR
  822.         %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
  823. [已启用] \Microsoft\Windows\Tcpip\IpAddressConflict1
  824.         %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
  825. [已启用] \Microsoft\Windows\Tcpip\IpAddressConflict2
  826.         %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
  827. [已启用] \Microsoft\Windows\Time Synchronization\SynchronizeTime
  828.         %windir%\system32\sc.exe start w32time task_started
  829. [已启用] \Microsoft\Windows\UPnP\UPnPHostConfig
  830.         sc.exe config upnphost start= auto
  831. [已禁用] \Microsoft\Windows\User Profile Service\HiveUploadTask
  832.         N/A
  833. [已启用] \Microsoft\Windows\Windows Error Reporting\QueueReporting
  834.         %windir%\system32\wermgr.exe -queuereporting
  835. [已禁用] \Microsoft\Windows\Windows Media Sharing\UpdateLibrary
  836.         "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
  837. [已禁用] \Microsoft\Windows\WindowsBackup\ConfigNotification
  838.         %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
  839. [已启用] \Microsoft\Windows\WindowsColorSystem\Calibration Loader
  840.         N/A

  841. ==================================
  842. Windows 安全更新检查
  843. KB2483139,  拉脱维亚语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  844. KB2483139,  捷克语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  845. KB2483139,  俄语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  846. KB2483139,  英语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  847. KB2483139,  丹麦语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  848. KB2483139,  意大利语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  849. KB2483139,  匈牙利语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  850. KB2483139,  朝鲜语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  851. KB2483139,  瑞典语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  852. KB2483139,  波兰语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  853. KB2483139,  克罗地亚语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  854. KB2483139,  乌克兰语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  855. KB2483139,  挪威语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  856. KB2483139,  希腊语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  857. KB2483139,  保加利亚语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  858. KB2483139,  葡萄牙语(葡萄牙)语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  859. KB2483139,  荷兰语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  860. KB2483139,  葡萄牙语(巴西)语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  861. KB2483139,  西班牙语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  862. KB2483139,  斯洛文尼亚语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  863. KB2483139,  繁体中文语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  864. KB2483139,  日语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  865. KB2483139,  泰国语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  866. KB2483139,  德语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  867. KB2483139,  爱沙尼亚语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  868. KB2483139,  立陶宛语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  869. KB2483139,  斯洛伐克语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  870. KB2483139,  芬兰语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  871. KB2483139,  阿拉伯语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  872. KB2483139,  希伯来语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  873. KB2483139,  塞尔维亚语(拉丁语)语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  874. KB2483139,  罗马尼亚语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  875. KB2483139,  法语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  876. KB2483139,  土耳其语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  877. KB2484033,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2484033)
  878. KB2505438,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2505438)
  879. KB2511250,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2511250)
  880. KB2515325,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2515325)
  881. KB2506928,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2506928)
  882. KB2492386,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2492386)
  883. KB2522422,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2522422)
  884. KB2533552,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2533552)
  885. KB2541014,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2541014)
  886. KB2488113,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2488113)
  887. KB2545698,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2545698)
  888. KB2547666,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2547666)
  889. KB2552343,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2552343)
  890. KB2532531,  用于基于 x64 的系统的 Windows 7 安全更新程序 (KB2532531) MS11-053
  891. KB2563227,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2563227)
  892. KB982670,  用于基于 x64 的系统的 Windows 7 的 Microsoft .NET Framework 4 Client Profile (KB982670)
  893. KB2598845,  用于基于 x64 的系统的 Windows 7 的 Internet Explorer 8 兼容性视图列表的更新程序 (KB2598845)
  894. KB2603229,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2603229)
  895. KB2607576,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2607576)
  896. KB2633952,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2633952)
  897. KB982861,  用于基于 x64 的系统的 Windows 7 的 Windows Internet Explorer 9
  898. KB2660075,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2660075)
  899. KB2640148,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2640148)
  900. KB2679255,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2679255)
  901. KB2659262,  用于基于 x64 的系统的 Windows 7 安全更新程序 (KB2659262) MS12-034
  902. KB2658846,  用于基于 x64 的系统的 Windows 7 安全更新程序 (KB2658846) MS12-034
  903. KB2676562,  用于基于 x64 的系统的 Windows 7 安全更新程序 (KB2676562) MS12-034
  904. KB2660649,  用于基于 x64 的系统的 Windows 7 安全更新程序 (KB2660649) MS12-034
  905. KB890830,  Windows 恶意软件删除工具 x64 - 2012 年 5 月 (KB890830)
  906. KB2656411,  用于 x64 系统的 Windows 7 和 Windows Server 2008 R2 SP1 上的 Microsoft .NET Framework 3.5.1 的安全更新程序 (KB2656411) MS12-034

  907. ==================================
  908. API HOOK
  909. 入口点错误:NtCreateFile (危险等级: 一般,  被下面模块所HOOK: C:\Windows\SysWOW64\guard32.dll)
  910. 入口点错误:NtCreateThread (危险等级: 一般,  被下面模块所HOOK: C:\Windows\SysWOW64\guard32.dll)
  911. 入口点错误:NtLoadDriver (危险等级: 一般,  被下面模块所HOOK: C:\Windows\SysWOW64\guard32.dll)
  912. 入口点错误:NtSetSystemInformation (危险等级: 一般,  被下面模块所HOOK: C:\Windows\SysWOW64\guard32.dll)
  913. 入口点错误:NtTerminateProcess (危险等级: 一般,  被下面模块所HOOK: C:\Windows\SysWOW64\guard32.dll)
  914. 入口点错误:NtTerminateThread (危险等级: 一般,  被下面模块所HOOK: C:\Windows\SysWOW64\guard32.dll)
  915. 入口点错误:ZwCreateFile (危险等级: 一般,  被下面模块所HOOK: C:\Windows\SysWOW64\guard32.dll)
  916. 入口点错误:ZwCreateThread (危险等级: 一般,  被下面模块所HOOK: C:\Windows\SysWOW64\guard32.dll)
  917. 入口点错误:ZwOpenFile (危险等级: 一般,  被下面模块所HOOK: C:\Windows\SysWOW64\guard32.dll)
  918. 入口点错误:ZwSetSystemInformation (危险等级: 一般,  被下面模块所HOOK: C:\Windows\SysWOW64\guard32.dll)
  919. 入口点错误:ZwShutdownSystem (危险等级: 一般,  被下面模块所HOOK: C:\Windows\SysWOW64\guard32.dll)
  920. 入口点错误:ZwTerminateProcess (危险等级: 一般,  被下面模块所HOOK: C:\Windows\SysWOW64\guard32.dll)
  921. 入口点错误:ZwTerminateThread (危险等级: 一般,  被下面模块所HOOK: C:\Windows\SysWOW64\guard32.dll)
  922. 入口点错误:FindFirstFileA (危险等级: 高,  被下面模块所HOOK: 0xBA32DDB6)
  923. 入口点错误:LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: \SystemRoot\System32\Drivers\usbvideo.sys)
  924. 入口点错误:CreateProcessA (危险等级: 高,  被下面模块所HOOK: 0x029102F1)
  925. 入口点错误:CreateProcessW (危险等级: 高,  被下面模块所HOOK: 0x029802F1)
  926. 入口点错误:GetModuleFileNameW (危险等级: 高,  被下面模块所HOOK: \SystemRoot\System32\Drivers\usbvideo.sys)

  927. ==================================
  928. 隐藏进程
  929. N/A

  930. ==================================


复制代码

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
明月丶舞白衣
发表于 2012-5-9 13:16:28 | 显示全部楼层
不好意思,本人一直用Windows update更新微软漏洞补丁的,小红伞无此情况
建议:首先上报金山客服:联系QQ1517410148,如果可以的话上报小红伞。
------------------------------------------------------------------------------------------
补充:你是否开了金山卫士的P2P,就是在金山卫士的设置里面,如果是这样,不排除是真的病毒。
仯釕↘①訜執著
发表于 2012-5-9 13:26:43 | 显示全部楼层
从未发生此类事故。。
自然卷丨依佐
 楼主| 发表于 2012-5-9 13:30:51 | 显示全部楼层
cs52089757 发表于 2012-5-9 13:16
不好意思,本人一直用Windows update更新微软漏洞补丁的,小红伞无此情况
建议:首先上报金山客服:联系QQ ...

是打开了p2p的

悲催了??我现在都装好了。。。。。

红伞不能上报吧  这么大文件

我全盘扫描一下


明月丶舞白衣
发表于 2012-5-9 13:31:49 | 显示全部楼层
自然卷丨依佐 发表于 2012-5-9 13:30
是打开了p2p的

悲催了??我现在都装好了。。。。。

不是给你了金山客服的QQ?找他去啊   开了P2P有时候会有问题
自然卷丨依佐
 楼主| 发表于 2012-5-9 13:32:50 | 显示全部楼层
cs52089757 发表于 2012-5-9 13:31
不是给你了金山客服的QQ?找他去啊   开了P2P有时候会有问题

恩、加了的  正在问、它可能在睡觉  还没有加上
贾君鹏的妈妈
发表于 2012-5-9 13:33:58 来自手机 | 显示全部楼层
奇怪了,我怎么没遇到?
yc513847
发表于 2012-5-9 13:35:42 | 显示全部楼层
一直用的是windows update打补丁的,没有出现这种情况。
aaa839
发表于 2012-5-9 13:37:51 | 显示全部楼层
本帖最后由 aaa839 于 2012-5-9 13:43 编辑

用Windows Update更新補丁,勿用金山
AVIRA對於原版UPDATE是不會作出任何警報
假若該補丁是人為修改後放出,可能會引發警報
解決方法
1.先記下KB號碼,再從微軟官方下載頁面搜尋並下載有關補丁
http://www.microsoft.com/downloads/zh-cn/

tdl亦告訴你
是因為p2p影響
不過我仍建議打補丁請使用windows update
官方網站原網址下載沒有任何問題

评分

参与人数 1经验 +2 收起 理由
明月丶舞白衣 + 2 感谢解答: )

查看全部评分

luojuna
发表于 2012-5-9 14:22:33 | 显示全部楼层
是呢,剛更新,沒這問題,一般打補丁還是用系統自帶的比較好,第三方軟件更新補丁若非不得已建議建議別用。。。。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-6-10 12:11 , Processed in 0.146715 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表