发个样本和扫描记录,看看是中什么毒?已全盘扫描杀毒,系统已还原过,前后用小A、诺顿、红伞、360卫士、清理助手扫描过,无毒,但还是不定时报毒,目前用小A网络版中,附图如下:
扫描记录如下:
- 2013-05-29,14:01:17
- System Repair Engineer 2.8.4.1331
- Smallfrogs (http://www.KZTechs.com)
- Windows 7 Ultimate Edition Service Pack 1 (Build 7601) - 管理权限用户 - 完整功能
- 以下内容被选中:
- 所有的启动项目(包括注册表、启动文件夹、服务等)
- 浏览器加载项
- 正在运行的进程(包括进程模块信息)
- 文件关联
- Winsock 提供者
- Autorun.inf
- HOSTS 文件
- 进程特权扫描
- 计划任务
- Windows 安全更新检查
- API HOOK
- 隐藏进程
- 启动项目
- 注册表
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- <XKToolBox><D:\Program Files\侠客工具盒\ToolBox.exe> [恒古软件]
- <Foxmail><"D:\Program Files\Foxmail\Foxmail.exe" -min> [(Verified)Tencent Technology(Shenzhen) Company Limited]
- <strokeit><D:\Program Files\StrokeIt\strokeit.exe> []
- <DesktopSprite><D:\Program Files\DesktopSprite2\DesktopSprite.exe> [SnowFox Studio.]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- <RtHDVCpl><C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s> [(Verified)Realtek Semiconductor Corp]
- <Microsoft Pinyin IME Migration><C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMESC\IMSCMIG.EXE /INSTALL> [(Verified)Microsoft Corporation]
- <avast><"C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui> [(Verified)AVAST Software]
- <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <shell><explorer.exe> [(Verified)Microsoft Windows]
- <Userinit><C:\Windows\system32\userinit.exe,> [(Verified)Microsoft Windows]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <AppInit_DLLs><> [N/A]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
- <WebCheck><> [N/A]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
- <Microsoft Windows Media Player><%SystemRoot%\system32\unregmp2.exe /ShowWMP> [(Verified)Microsoft Windows]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
- <Internet Explorer><C:\Windows\System32\ie4uinit.exe -UserIconConfig> [(Verified)Microsoft Windows]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
- <Browser Customizations><"C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP> [(Verified)Microsoft Corporation]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
- <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
- <Microsoft Windows><"%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE> [File is missing]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
- <Microsoft Windows Media Player><%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI> [(Verified)Microsoft Windows]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
- <Windows Desktop Update><regsvr32.exe /s /n /i:U shell32.dll> [(Verified)Microsoft Windows]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
- <Web Platform Customizations><C:\Windows\System32\ie4uinit.exe -BaseSettings> [(Verified)Microsoft Windows]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
- <N/A><C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install> [(Verified)Microsoft Corporation]
- ==================================
- 启动文件夹
- [腾讯通RTX]
- <C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\腾讯通RTX.lnk --> D:\PROGRA~1\Tencent\RTXC\RTX.exe [TENCENT]><N>
- [腾讯通RTX]
- <C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\腾讯通RTX.lnk --> D:\PROGRA~1\Tencent\RTXC\RTX.exe [TENCENT]><N>
- ==================================
- 服务
- [Adobe Flash Player Update Service / AdobeFlashPlayerUpdateSvc][Stopped/Manual Start]
- <C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe><Adobe Systems Incorporated>
- [avast! Antivirus / avast! Antivirus][Running/Auto Start]
- <"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"><AVAST Software>
- [avast! Firewall / avast! Firewall][Running/Auto Start]
- <"C:\Program Files\AVAST Software\Avast\afwServ.exe"><AVAST Software>
- [DTLService / DTLService][Running/Auto Start]
- <D:\Program Files\DriveTheLife\DTLService.exe><深圳市驱动人生软件技术有限公司>
- [ForceWare Intelligent Application Manager (IAM) / ForceWare Intelligent Application Manager (IAM)][Running/Auto Start]
- <C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe><>
- [KNBCenter / KNBCenter][Stopped/Disabled]
- <"R:\Program Files\liebao\LBBrowser\KNBCenter.exe"><(File is missing)>
- [Kingsoft Common Content Service / KSDSVC][Stopped/Auto Start]
- <D:\Program Files\Kingsoft\PowerWord PE\ksdsvc.exe><(File is missing)>
- [ForceWare IP service / nSvcIp][Running/Auto Start]
- <C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe><>
- [NVIDIA Driver Helper Service / NVSvc][Running/Auto Start]
- <C:\Windows\system32\nvvsvc.exe><NVIDIA Corporation>
- ==================================
- 驱动程序
- [adp94xx / adp94xx][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\adp94xx.sys><Adaptec, Inc.>
- [adpahci / adpahci][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\adpahci.sys><Adaptec, Inc.>
- [adpu320 / adpu320][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\adpu320.sys><Adaptec, Inc.>
- [aic78xx / aic78xx][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\djsvs.sys><Adaptec, Inc.>
- [aliide / aliide][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\aliide.sys><Acer Laboratories Inc.>
- [amdsata / amdsata][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\amdsata.sys><Advanced Micro Devices>
- [amdsbs / amdsbs][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\amdsbs.sys><AMD Technologies Inc.>
- [amdxata / amdxata][Running/Boot Start]
- <\SystemRoot\system32\drivers\amdxata.sys><Advanced Micro Devices>
- [arc / arc][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\arc.sys><Adaptec, Inc.>
- [arcsas / arcsas][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\arcsas.sys><Adaptec, Inc.>
- [aswMonFlt / aswMonFlt][Running/Auto Start]
- <\??\C:\Windows\system32\drivers\aswMonFlt.sys><AVAST Software>
- [avast! Firewall NDIS Filter Service / aswNdis][Running/Boot Start]
- <\SystemRoot\system32\DRIVERS\aswNdis.sys><ALWIL Software>
- [aswRdr / aswRdr][Running/System Start]
- <\SystemRoot\System32\Drivers\aswrdr2.sys><AVAST Software>
- [Broadcom NetXtreme II VBD / b06bdrv][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\bxvbdx.sys><Broadcom Corporation>
- [Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 / b57nd60x][Stopped/Manual Start]
- <system32\DRIVERS\b57nd60x.sys><Broadcom Corporation>
- [Brother USB Mass-Storage Lower Filter Driver / BrFiltLo][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\BrFiltLo.sys><Brother Industries, Ltd.>
- [Brother USB Mass-Storage Upper Filter Driver / BrFiltUp][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\BrFiltUp.sys><Brother Industries, Ltd.>
- [Brother MFC Serial Port Interface Driver (WDM) / Brserid][Stopped/Manual Start]
- <\SystemRoot\System32\Drivers\Brserid.sys><Brother Industries Ltd.>
- [Brother WDM Serial driver / BrSerWdm][Stopped/Manual Start]
- <\SystemRoot\System32\Drivers\BrSerWdm.sys><Brother Industries Ltd.>
- [Brother MFC USB Fax Only Modem / BrUsbMdm][Stopped/Manual Start]
- <\SystemRoot\System32\Drivers\BrUsbMdm.sys><Brother Industries Ltd.>
- [Brother MFC USB Serial WDM Driver / BrUsbSer][Stopped/Manual Start]
- <\SystemRoot\System32\Drivers\BrUsbSer.sys><Brother Industries Ltd.>
- [cmdide / cmdide][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\cmdide.sys><CMD Technology, Inc.>
- [cpuz135 / cpuz135][Stopped/Manual Start]
- <\??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz135\cpuz135_x32.sys><N/A>
- [DTLD48EC12D954B431e88684F32293ABA20 / DTLD48EC12D954B431e88684F32293ABA20][Running/System Start]
- <\??\D:\Program Files\DriveTheLife\DtlSrvPro.dat><N/A>
- [Intel(R) PRO/1000 NDIS 6 Adapter Driver / E1G60][Stopped/Manual Start]
- <system32\DRIVERS\E1G60I32.sys><Intel Corporation>
- [Broadcom NetXtreme II 10 GigE VBD / ebdrv][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\evbdx.sys><Broadcom Corporation>
- [elxstor / elxstor][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\elxstor.sys><Emulex>
- [Primo Ramdisk Controller / FancyRd][Running/Boot Start]
- <\SystemRoot\system32\DRIVERS\fancyrd.sys><Romex Software>
- [Hauppauge Consumer Infrared Receiver / hcw85cir][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\hcw85cir.sys><Hauppauge Computer Works, Inc.>
- [HpSAMD / HpSAMD][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\HpSAMD.sys><Hewlett-Packard Company>
- [HWCore / HWCore][Running/Manual Start]
- <\??\D:\Program Files\DriveTheLife\hwcore.sys><N/A>
- [iaStorV / iaStorV][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\iaStorV.sys><Intel Corporation>
- [iirsp / iirsp][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\iirsp.sys><Intel Corp./ICP vortex GmbH>
- [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
- <system32\drivers\RTKVHDA.sys><Realtek Semiconductor Corp.>
- [KNBDrv / KNBDrv][Stopped/Manual Start]
- <\??\C:\Windows\system32\drivers\KNBDrv.sys><Kingsoft Corporation>
- [LSI_FC / LSI_FC][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\lsi_fc.sys><LSI Corporation>
- [LSI_SAS / LSI_SAS][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\lsi_sas.sys><LSI Corporation>
- [LSI_SAS2 / LSI_SAS2][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\lsi_sas2.sys><LSI Corporation>
- [LSI_SCSI / LSI_SCSI][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\lsi_scsi.sys><LSI Corporation>
- [megasas / megasas][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\megasas.sys><LSI Corporation>
- [MegaSR / MegaSR][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\MegaSR.sys><LSI Corporation, Inc.>
- [Softlumos Multi-Platform / Mulsys][Running/Boot Start]
- <\SystemRoot\System32\DRIVERS\Mulsys.SYS><Windows (R) Codename Longhorn DDK provider>
- [nfrd960 / nfrd960][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\nfrd960.sys><IBM Corporation>
- [NVIDIA nForce 网络控制器驱动程序 / NVENETFD][Stopped/Manual Start]
- <system32\DRIVERS\nvm62x32.sys><NVIDIA Corporation>
- [nvlddmkm / nvlddmkm][Running/Manual Start]
- <system32\DRIVERS\nvlddmkm.sys><NVIDIA Corporation>
- [NVIDIA nForce 10/100/1000 Mbps Ethernet / NVNET][Running/Manual Start]
- <system32\DRIVERS\nvmf6232.sys><NVIDIA Corporation>
- [nvraid / nvraid][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\nvraid.sys><NVIDIA Corporation>
- [nvstor / nvstor][Running/Boot Start]
- <\SystemRoot\system32\drivers\nvstor.sys><NVIDIA Corporation>
- [ql2300 / ql2300][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\ql2300.sys><QLogic Corporation>
- [ql40xx / ql40xx][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\ql40xx.sys><QLogic Corporation>
- [Serial port driver / Serial][Running/System Start]
- <system32\DRIVERS\serial.sys><Brother Industries Ltd.>
- [SiSRaid2 / SiSRaid2][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\SiSRaid2.sys><Silicon Integrated Systems Corp.>
- [SiSRaid4 / SiSRaid4][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\sisraid4.sys><Silicon Integrated Systems>
- [stexstor / stexstor][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\stexstor.sys><Promise Technology>
- [VirtualBox Service / VBoxDrv][Running/System Start]
- <system32\DRIVERS\VBoxDrv.sys><Oracle Corporation>
- [VirtualBox Host-Only Ethernet Adapter / VBoxNetAdp][Running/Manual Start]
- <system32\DRIVERS\VBoxNetAdp.sys><Oracle Corporation>
- [VirtualBox Bridged Networking Service / VBoxNetFlt][Running/Manual Start]
- <system32\DRIVERS\VBoxNetFlt.sys><Oracle Corporation>
- [VirtualBox USB Monitor Driver / VBoxUSBMon][Running/System Start]
- <system32\DRIVERS\VBoxUSBMon.sys><Oracle Corporation>
- [VGPU / VGPU][Stopped/Manual Start]
- <System32\drivers\rdvgkmd.sys><N/A>
- [viaide / viaide][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\viaide.sys><VIA Technologies, Inc.>
- [vsmraid / vsmraid][Stopped/Manual Start]
- <\SystemRoot\system32\drivers\vsmraid.sys><VIA Technologies Inc.,Ltd>
- [Virtual Device Driver / VxDevice][Running/Boot Start]
- <\SystemRoot\System32\DRIVERS\VxDevice.SYS><N/A>
- ==================================
- 浏览器加载项
- [VideoUrlSniffer Class]
- {00000ADA-7E0D-47C1-986C-F017D09C4304} <C:\Program Files\Common Files\Thunder Network\KanKan\VideoUrlSniffer.2.0.1.99.(782).dll, (Signed) 深圳市迅雷网络技术有限公司>
- [迅雷流媒体探测IE支持]
- {01443AEC-0FD1-40fd-9C87-E93D1494C233} <, >
- [迅雷下载支持]
- {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Program Files\Thunder\BHO\XunleiBHO7.2.90.92.dll, (Signed) 深圳市迅雷网络技术有限公司>
- []
- {14c1d00e-0b92-4379-880b-444fa2d740dd} <, >
- [迅雷看看播放器]
- {24c1d00e-0b92-4379-880b-444fa2d740dd} <, >
- [信息检索(&R)]
- {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, (Signed) Microsoft Corporation>
- [Shockwave Flash Object]
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\system32\Macromed\Flash\Flash32_11_7_700_202.ocx, (Signed) Adobe Systems, Inc.>
- [VideoUrlSniffer Class]
- {00000ADA-7E0D-47C1-986C-F017D09C4304} <C:\Program Files\Common Files\Thunder Network\KanKan\VideoUrlSniffer.2.0.1.99.(782).dll, (Signed) 深圳市迅雷网络技术有限公司>
- [迅雷流媒体探测IE支持]
- {01443AEC-0FD1-40FD-9C87-E93D1494C233} <, >
- [Agent Class]
- {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <D:\Program Files\Thunder\BHO\ThunderAgent7.2.90.92.dll, (Signed) 深圳市迅雷网络技术有限公司>
- [QQPYChecker Class]
- {5052B4D0-9DF7-45ef-88EF-F42C0EA33A43} <D:\Program Files\QQPinyin\4.5.1206.400\QQImeChecker.dll, (Signed) Tencent>
- [Windows Media Player]
- {6BF52A52-394A-11D3-B153-00C04F79FAA6} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
- [Access UserInfo by Script]
- {6EE9CD3E-A386-4DAE-9737-A759DBF927AE} <D:\Program Files\Thunder Network\Xmp\Program\UserAgent1.0.2.14.dll, (Signed) Thunder Networking Technologies,LTD>
- [迅雷下载支持]
- {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Program Files\Thunder\BHO\XunleiBHO7.2.90.92.dll, (Signed) 深圳市迅雷网络技术有限公司>
- [OFrameObject Class]
- {9701758C-4373-482E-B13C-776C048EC890} <, >
- [VersionDetector Class]
- {9EFF1953-9694-47B1-AEF6-B2A3FE8BFE9B} <C:\Program Files\Common Files\Thunder Network\KanKan\vd.1.1.0.32.(999).dll, N/A>
- [APlayer Control]
- {A9322148-C691-4B9D-91FC-B9C461DBE9DD} <, >
- [DapCtrl Class]
- {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} <, >
- [LiveDapCtrl Class]
- {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F9} <, >
- [Shockwave Flash Object]
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\system32\Macromed\Flash\Flash32_11_7_700_202.ocx, (Signed) Adobe Systems, Inc.>
- [xoliimpl Class]
- {DD5BF6D1-6663-47E0-9DFA-5C343CAF178E} <C:\Windows\xinstaller.dll, (Signed) 深圳市迅雷技术有限公司>
- []
- {F3E70CEA-956E-49CC-B444-73AFE593AD7F} <, >
- [使用迅雷下载]
- <D:\Program Files\Thunder\BHO\geturl.htm, N/A>
- [使用迅雷看看播放器播放]
- <C:\ProgramData\Thunder Network\XMP4\core\program\XmpIEMenu.htm, N/A>
- [使用迅雷离线下载]
- <D:\Program Files\Thunder\BHO\OfflineDownload.htm, N/A>
- [导出到 Microsoft Excel(&X)]
- <res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000, N/A>
- ==================================
- 正在运行的进程
- [PID: 308 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 468 / SYSTEM][C:\Windows\system32\csrss.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 528 / SYSTEM][C:\Windows\system32\wininit.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 584 / SYSTEM][C:\Windows\system32\services.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 600 / SYSTEM][C:\Windows\system32\lsass.exe] [(Verified) Microsoft Corporation, 6.1.7601.17725 (win7sp1_gdr.111116-1503)]
- [PID: 608 / SYSTEM][C:\Windows\system32\lsm.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 756 / SYSTEM][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 844 / SYSTEM][C:\Windows\system32\nvvsvc.exe] [NVIDIA Corporation, 8.17.12.6300]
- [C:\Program Files\NVIDIA Corporation\Display\NVXDBat.dll] [NVIDIA Corporation, 7.17.12.6300]
- [PID: 884 / NETWORK SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 960 / LOCAL SERVICE][C:\Windows\System32\svchost.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [C:\Windows\system32\MBWrp32.dll] [Creative Technology Ltd., 1.0.0.200]
- [C:\Windows\system32\RtkAPO.dll] [Realtek Semiconductor Corp., 11, 0, 6000, 298]
- [PID: 1020 / SYSTEM][C:\Windows\System32\svchost.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 1060 / SYSTEM][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 1196 / LOCAL SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 1364 / NETWORK SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 1504 / SYSTEM][C:\Program Files\AVAST Software\Avast\AvastSvc.exe] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswCmnBS.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswCmnOS.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswCmnIS.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\ashBase.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswEngLdr.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\2052\Base.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\ashServ.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswAux.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\ashTask.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\ashTaskEx.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswLog.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswSqLt.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswProperty.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\AavmRpch.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\Aavm4h.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\avastIP.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswIdle.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswDld.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswStrm.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\AhResNS.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\AhResStd.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\AhResWS.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\ashWebSv.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\ashWsFtr.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\aswEngin.dll] [AVAST Software, 7.0.1488.137]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\aswCmnIS.dll] [AVAST Software, 7.0.1483.117]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\aswCmnOS.dll] [AVAST Software, 7.0.1485.125]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\aswCmnBS.dll] [AVAST Software, 7.0.1488.137]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\aswScan.dll] [AVAST Software, 7.0.1485.125]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\aswRep.dll] [AVAST Software, 7.0.1488.138]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\aswFiDb.dll] [AVAST Software, 7.0.1484.119]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\algo.dll] [N/A, ]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\aswCleanerDLL.dll] [AVAST Software, 1, 0, 212, 0]
- [PID: 1640 / SYSTEM][C:\Program Files\AVAST Software\Avast\afwServ.exe] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\afwCore.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\Aavm4h.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\AavmRpch.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\ashBase.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswEngLdr.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswCmnOS.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswCmnIS.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswCmnBS.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\ashTask.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswAux.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswProperty.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\avastIP.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswLog.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswSqLt.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\afwCoreServ.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\afwRpc.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\afwCoreClient.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\afwGeoIP.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\2052\Base.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\aswEngin.dll] [AVAST Software, 7.0.1488.137]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\aswCmnIS.dll] [AVAST Software, 7.0.1483.117]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\aswCmnOS.dll] [AVAST Software, 7.0.1485.125]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\aswCmnBS.dll] [AVAST Software, 7.0.1488.137]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\aswScan.dll] [AVAST Software, 7.0.1485.125]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\aswRep.dll] [AVAST Software, 7.0.1488.138]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\aswFiDb.dll] [AVAST Software, 7.0.1484.119]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\fwAux.dll] [AVAST Software, 7.0.1481.100]
- [PID: 1804 / SYSTEM][C:\Windows\System32\spoolsv.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSDNT5UI.DLL] [Zenographics, Inc., 0, 3, 2911, 1]
- [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSDDM.DLL] [Zenographics, Inc., 6, 20, 1611, 0]
- [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSPOOL.dll] [Zenographics, Inc., 6, 1, 1, 0]
- [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZGDI.dll] [Zenographics, Inc., 5, 60, 709, 0]
- [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZTAG.dll] [Zenographics, Inc., 5, 60, 1210, 0]
- [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSDDMUI.DLL] [Zenographics, Inc., 6, 2, 411, 0]
- [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSR.dll] [Zenographics, Inc., 6, 20, 1625, 0]
- [PID: 1832 / LOCAL SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 1952 / SYSTEM][D:\Program Files\DriveTheLife\DTLService.exe] [深圳市驱动人生软件技术有限公司, 1, 0, 1, 32]
- [D:\Program Files\DriveTheLife\PipeProtocol.dll] [N/A, ]
- [D:\Program Files\DriveTheLife\dtlupdater\checkupdate.dll] [深圳市驱动人生软件技术有限公司, 1, 0, 1, 15]
- [D:\Program Files\DriveTheLife\substat.dll] [深圳市驱动人生软件技术有限公司, 1, 0, 0, 21]
- [D:\Program Files\DriveTheLife\tipsdll.dll] [, 1, 0, 1, 17]
- [D:\Program Files\DriveTheLife\drvs.dll] [深圳市驱动人生软件技术有限公司, 1, 0, 1, 32]
- [D:\Program Files\DriveTheLife\DstUdp.dll] [深圳市驱动人生软件技术有限公司, 1, 0, 1, 20]
- [D:\Program Files\DriveTheLife\utility.dll] [深圳市驱动人生软件技术有限公司, 1, 0, 0, 10]
- [D:\Program Files\DriveTheLife\udp.dll] [深圳市驱动人生软件技术有限公司, 1, 0, 0, 7]
- [D:\Program Files\DriveTheLife\hdenum.dll] [深圳市驱动人生软件技术有限公司, 2, 3, 3, 7]
- [D:\Program Files\DriveTheLife\bios.dll] [深圳市驱动人生软件技术有限公司, 1.1.16.0]
- [PID: 1868 / SYSTEM][C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe] [, 1, 0, 1, 0]
- [C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\NMI.dll] [NVIDIA Corporation, 2, 2, 0, 7325]
- [C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll] [N/A, ]
- [C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll] [N/A, ]
- [PID: 1544 / SYSTEM][C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe] [, 2, 2, 0, 7325]
- [C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll] [N/A, ]
- [C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\NMI.dll] [NVIDIA Corporation, 2, 2, 0, 7325]
- [C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll] [N/A, ]
- [PID: 2200 / NETWORK SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 3108 / SYSTEM][C:\Windows\system32\SearchIndexer.exe] [(Verified) Microsoft Corporation, 7.00.7600.16385 (win7_rtm.090713-1255)]
- [PID: 3544 / LOCAL SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 3640 / SYSTEM][C:\Windows\System32\svchost.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 1612 / SYSTEM][C:\Windows\system32\SearchProtocolHost.exe] [(Verified) Microsoft Corporation, 7.00.7601.17610 (win7sp1_gdr.110503-1502)]
- [PID: 1220 / SYSTEM][C:\Windows\system32\csrss.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 3528 / SYSTEM][C:\Windows\system32\winlogon.exe] [(Verified) Microsoft Corporation, 6.1.7601.17514 (win7sp1_rtm.101119-1850)]
- [PID: 792 / SYSTEM][C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe] [NVIDIA Corporation, 7.17.12.6300]
- [C:\Program Files\NVIDIA Corporation\Display\NVXDApiX.dll] [NVIDIA Corporation, 7.17.12.6300]
- [C:\Program Files\NVIDIA Corporation\Display\NvUI.dll] [NVIDIA Corporation, 7.17.12.6300]
- [C:\Windows\system32\nvapi.dll] [NVIDIA Corporation, 8.17.12.6300]
- [C:\Program Files\NVIDIA Corporation\Display\NVXDBat.dll] [NVIDIA Corporation, 7.17.12.6300]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [PID: 1788 / SYSTEM][C:\Windows\system32\nvvsvc.exe] [NVIDIA Corporation, 8.17.12.6300]
- [C:\Windows\system32\NVSVC.DLL] [NVIDIA Corporation, 8.17.12.6300]
- [C:\Windows\system32\nvapi.dll] [NVIDIA Corporation, 8.17.12.6300]
- [C:\Windows\system32\NVSVCR.DLL] [NVIDIA Corporation, 8.17.12.6300]
- [C:\Program Files\NVIDIA Corporation\Display\NVXDBat.dll] [NVIDIA Corporation, 7.17.12.6300]
- [C:\Program Files\NVIDIA Corporation\Display\NVXDPlcy.dll] [NVIDIA Corporation, 7.17.12.6300]
- [PID: 2876 / Administrator][C:\Windows\system32\Dwm.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [C:\Windows\system32\nvd3dum.dll] [NVIDIA Corporation, 8.17.12.6300]
- [PID: 2156 / Administrator][C:\Windows\Explorer.EXE] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [C:\Program Files\AVAST Software\Avast\ashShell.dll] [AVAST Software, 8.0.1489.300]
- [D:\Program Files\NetSpeedMonitorX86\nsm.dll] [Florian Gilles, 2, 5, 4, 0]
- [C:\Windows\System32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0401]
- [C:\Windows\system32\FXSAPI.dll] [Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [C:\Windows\system32\nvshext.dll] [NVIDIA Corporation, 263.00]
- [C:\Program Files\NVIDIA Corporation\Display\NVXDBat.dll] [NVIDIA Corporation, 7.17.12.6300]
- [C:\Program Files\NVIDIA Corporation\Display\NVXDPlcy.dll] [NVIDIA Corporation, 7.17.12.6300]
- [C:\Program Files\360\360zip\360ZipExt.dll] [360.cn, 2, 0, 0, 1071]
- [D:\Program Files\Tencent\RTXC\RTXShlMenu.dll] [Tencent, 1, 0, 0, 1]
- [D:\Program Files\侠客工具盒\TBoxExt.dll] [恒古软件, 6, 0, 0, 0]
- [D:\Program Files\StrokeIt\mhook.dll] [N/A, ]
- [PID: 2484 / Administrator][C:\Windows\system32\taskhost.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [C:\Windows\System32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0401]
- [PID: 2776 / Administrator][C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe] [Realtek Semiconductor, 1, 0, 0, 821]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [PID: 716 / Administrator][C:\Program Files\AVAST Software\Avast\AvastUI.exe] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswUtil.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\ashBase.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswEngLdr.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswCmnOS.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswCmnIS.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswCmnBS.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\ashTask.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswAux.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\avastIP.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswProperty.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\AavmRpch.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswLog.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswSqLt.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\2052\Base.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\afwGeoIP.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\aswData.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\ashTaskEx.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\Aavm4h.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\afwCore.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\afwCoreClient.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\afwRpc.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\2052\UILangRes.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\AVAST Software\Avast\CommonRes.dll] [AVAST Software, 8.0.1489.300]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [C:\Program Files\AVAST Software\Avast\defs\13052801\uiExt.dll] [AVAST Software, 7.0.1485.126]
- [C:\Windows\System32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0401]
- [C:\Program Files\AVAST Software\Avast\ashShell.dll] [AVAST Software, 8.0.1489.300]
- [PID: 3980 / Administrator][D:\Program Files\侠客工具盒\ToolBox.exe] [恒古软件, 6, 0, 0, 0]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [D:\Program Files\StrokeIt\mhook.dll] [N/A, ]
- [PID: 4080 / Administrator][D:\Program Files\Foxmail\Foxmail.exe] [Tencent Inc., 7.0.1.91]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [D:\Program Files\Foxmail\FoxNote.dll] [N/A, ]
- [D:\Program Files\Foxmail\rfri.dll] [Tencent Inc., 1, 0, 0, 1]
- [D:\Program Files\Foxmail\nspi.dll] [TENCENT, 1, 0, 0, 1]
- [D:\Program Files\Foxmail\emsmdb.dll] [Tencent Inc., 1, 0, 0, 1]
- [D:\Program Files\Foxmail\Skin\TXScrollbar.dll] [N/A, ]
- [C:\Program Files\AVAST Software\Avast\ashShell.dll] [AVAST Software, 8.0.1489.300]
- [D:\Program Files\Foxmail\libeay32.dll] [N/A, ]
- [D:\Program Files\Foxmail\ssleay32.dll] [N/A, ]
- [PID: 3992 / Administrator][D:\Program Files\StrokeIt\strokeit.exe] [, Pro .9.7]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [D:\Program Files\StrokeIt\Plugins\exec.dll] [N/A, ]
- [D:\Program Files\StrokeIt\Plugins\keys.dll] [N/A, ]
- [D:\Program Files\StrokeIt\Plugins\msg.dll] [N/A, ]
- [D:\Program Files\StrokeIt\Plugins\multimon.dll] [N/A, ]
- [D:\Program Files\StrokeIt\Plugins\OSD.dll] [N/A, ]
- [D:\Program Files\StrokeIt\Plugins\siControl.dll] [N/A, ]
- [D:\Program Files\StrokeIt\Plugins\utilities.dll] [N/A, ]
- [D:\Program Files\StrokeIt\Plugins\win.dll] [N/A, ]
- [D:\Program Files\StrokeIt\mhook.dll] [N/A, ]
- [PID: 3728 / Administrator][D:\Program Files\DesktopSprite2\DesktopSprite.exe] [SnowFox Studio., 2.5.3.52]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [PID: 3964 / Administrator][D:\Program Files\Tencent\RTXC\RTX.exe] [TENCENT, 8.1.446.202]
- [D:\Program Files\Tencent\RTXC\UIU.dll] [Tencent, 4,0,0,55]
- [D:\Program Files\Tencent\RTXC\Localization.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\HelperU.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\Crypt.dll] [N/A, ]
- [D:\Program Files\Tencent\RTXC\TBarDll.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\InfoSvrApi.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\OutSupportNW.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\RTXRes.dll] [N/A, ]
- [D:\Program Files\Tencent\RTXC\MainFrameRes.dll] [, 1, 0, 0, 1]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [D:\Program Files\Tencent\RTXC\NewSkin.dll] [, 1, 0, 0, 1]
- [D:\PROGRA~1\Tencent\RTXC\RTXImage.ocx] [tencent, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\rtxcapi.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\RTXNetClient.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\StoreComp.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\rtxstore.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\sqlite3.dll] [N/A, ]
- [D:\Program Files\Tencent\RTXC\RTXP2P.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\P2P.Dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\QQNW.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\SessionClient.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\DisGroup.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\RTXCPro.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\BqqZip.dll] [N/A, ]
- [D:\Program Files\Tencent\RTXC\ClientObjects.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\RTXCSDK.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\FileTransfer.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\FileCom.dll] [Tencent, 4,0,0,7]
- [D:\Program Files\Tencent\RTXC\OrgStruct.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\IM.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\RTXSMS.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\LocalTabManager.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\OffMsgModule.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\Config.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\Watcher.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\ClientRightMgr.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\TAPD.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\RCAStoreComp.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\RCAModule.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\RCAIM.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\RCAUserProfile.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\EPortal.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\RTXLogin.dll] [, 1, 0, 0, 1]
- [D:\PROGRA~1\Tencent\RTXC\RTXOrg.ocx] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\UserSelector.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\UserProfile.dll] [, 1, 0, 0, 1]
- [D:\PROGRA~1\Tencent\RTXC\RTXMOB~1.OCX] [MS User, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\RTXOLAss.dll] [Tencent, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\UpdateModule.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\SearchUsers.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\Alert.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\BroadCast.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\Plugins\bizmailclient\ExMailClient.dll] [, 1, 0, 0, 8]
- [D:\Program Files\Tencent\RTXC\UserDefineWizard.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\RTXPhone.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\RTXPluginMgr.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\AddRCAUser.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Tencent\RTXC\ImExtraInfo.dll] [, 2, 1, 0, 15]
- [D:\Program Files\Tencent\RTXC\rtxskin.dll] [Tencent, 3,4,0,32]
- [D:\PROGRA~1\Tencent\RTXC\Plugins\BIZMAI~1\config\Setting.ocx] [, 1, 0, 0, 3]
- [C:\Program Files\AVAST Software\Avast\ashShell.dll] [AVAST Software, 8.0.1489.300]
- [PID: 2036 / NETWORK SERVICE][C:\Program Files\Windows Media Player\wmpnetwk.exe] [Microsoft Corporation, 12.0.7600.16385 (win7_rtm.090713-1255)]
- [PID: 2580 / LOCAL SERVICE][C:\Windows\system32\WUDFHost.exe] [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
- [PID: 1568 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [PID: 3380 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [C:\Windows\system32\nvd3dum.dll] [NVIDIA Corporation, 8.17.12.6300]
- [C:\Windows\system32\Macromed\Flash\Flash32_11_7_700_202.ocx] [Adobe Systems, Inc., 11,7,700,202]
- [PID: 5492 / Administrator][C:\Program Files\Microsoft Office\Office12\EXCEL.EXE] [Microsoft Corporation, 12.0.4518.1014]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSDNT5UI.DLL] [Zenographics, Inc., 0, 3, 2911, 1]
- [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSDDM.DLL] [Zenographics, Inc., 6, 20, 1611, 0]
- [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSPOOL.dll] [Zenographics, Inc., 6, 1, 1, 0]
- [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZGDI.dll] [Zenographics, Inc., 5, 60, 709, 0]
- [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZTAG.dll] [Zenographics, Inc., 5, 60, 1210, 0]
- [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSDDMUI.DLL] [Zenographics, Inc., 6, 2, 411, 0]
- [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSR.dll] [Zenographics, Inc., 6, 20, 1625, 0]
- [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZIMFDRV.DLL] [Zenographics, Inc., 0, 3, 5209, 0]
- [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZIMF.dll] [Zenographics, Inc., 5, 70, 616, 0]
- [C:\Program Files\AVAST Software\Avast\ashShell.dll] [AVAST Software, 8.0.1489.300]
- [C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL] [, ]
- [C:\Program Files\Microsoft Office\Office12\USP10.DLL] [Microsoft Corporation, 1.0626.5756.0 (vista_rtm.061008-1400)]
- [PID: 5412 / Administrator][D:\Program Files\Thunder\Program\Thunder.exe] [深圳市迅雷网络技术有限公司, 7,2,90,92]
- [D:\Program Files\Thunder\Program\XLUE.dll] [深圳市迅雷网络技术有限公司, 0.9.0.422]
- [D:\Program Files\Thunder\Program\XLGraphic.dll] [深圳市迅雷网络技术有限公司, 0.9.0.422]
- [D:\Program Files\Thunder\Program\libpng13.dll] [, 1.2.38]
- [D:\Program Files\Thunder\Program\zlib1.dll] [, 1.2.5]
- [C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.6030.0]
- [D:\Program Files\Thunder\Program\MSIMG32.dll] [N/A, ]
- [D:\Program Files\Thunder\Program\XLFSIO.dll] [深圳市迅雷网络技术有限公司, 0.9.0.422]
- [C:\Windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.6030.0]
- [D:\Program Files\Thunder\Program\XLLuaRuntime.dll] [深圳市迅雷网络技术有限公司, 0.9.0.412]
- [D:\Program Files\Thunder\Program\ATL71.DLL] [Microsoft Corporation, 7.10.6101.0]
- [D:\Program Files\Thunder\Program\libexpat.dll] [N/A, ]
- [D:\Program Files\Thunder\Program\XLBugHandler.dll] [, 2, 2, 0, 11]
- [D:\Program Files\Thunder\Program\minizip.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Thunder\Program\XLIPC.dll] [N/A, ]
- [D:\Program Files\Thunder\Program\xlstat.dll] [深圳市迅雷网络技术有限公司, 2.0.2.10]
- [D:\Program Files\Thunder\Program\InstallProtect.dll] [N/A, ]
- [D:\Program Files\Thunder\Program\sqlite3.dll] [, 3, 6, 22, 0]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [D:\Program Files\Thunder\Program\xl_data.dll] [深圳市迅雷网络技术有限公司, 1, 12, 5, 38]
- [D:\Program Files\Thunder\Program\DownloadKernel.dll] [深圳市迅雷网络技术有限公司, 7,2,90,92]
- [D:\Program Files\Thunder\Program\asyn_download_interface.dll] [深圳市迅雷网络技术有限公司, 1,1,2,54]
- [D:\Program Files\Thunder\Program\tp_proxy.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 22]
- [C:\Program Files\AVAST Software\Avast\ashShell.dll] [AVAST Software, 8.0.1489.300]
- [D:\Program Files\Thunder\Program\XLUserAX.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 84]
- [D:\Program Files\Thunder\Program\dl_peer_id.dll] [深圳市迅雷网络技术有限公司, 3, 2, 2, 17]
- [D:\Program Files\Thunder\Program\BaseCommunity.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 186]
- [D:\Program Files\Thunder\Program\xl_client.dll] [深圳市迅雷网络技术有限公司, 1, 14, 2, 35]
- [D:\Program Files\Thunder\Program\asyn_frame.dll] [深圳市迅雷网络技术有限公司, 1,6,2,22]
- [D:\Program Files\Thunder\Program\dl_uac_tool.dll] [N/A, ]
- [D:\Program Files\Thunder\Program\mp.dll] [深圳市迅雷网络技术有限公司, 1, 1, 2, 10]
- [D:\Program Files\Thunder\Addins\Community\XLCPAddinManager.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 21]
- [D:\Program Files\Thunder\Addins\community\Community.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 113]
- [D:\Program Files\Thunder\Addins\VipService\VipService.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 391]
- [D:\Program Files\Thunder\Program\Win7Trait.dll] [N/A, ]
- [PID: 5236 / Administrator][D:\Program Files\Thunder\Program\ThunderPlatform.exe] [深圳市迅雷网络技术有限公司, 1, 1, 2, 124]
- [D:\Program Files\Thunder\Program\minizip.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Thunder\Program\zlib1.dll] [, 1.2.5]
- [C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.6030.0]
- [C:\Windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.6030.0]
- [D:\Program Files\Thunder\Program\xlbughandler.dll] [, 2, 2, 0, 11]
- [D:\Program Files\Thunder\Program\dl_uac_tool.dll] [N/A, ]
- [D:\Program Files\Thunder\Program\download_engine.dll] [深圳市迅雷网络技术有限公司, 3, 7, 2, 20]
- [D:\Program Files\Thunder\Program\mp.dll] [深圳市迅雷网络技术有限公司, 1, 1, 2, 10]
- [D:\Program Files\Thunder\Program\XLCrypto.dll] [N/A, ]
- [D:\Program Files\Thunder\Program\asyn_frame.dll] [深圳市迅雷网络技术有限公司, 1,6,2,22]
- [D:\Program Files\Thunder\Program\ts.dll] [深圳市迅雷网络技术有限公司, 1,1,2,35]
- [D:\Program Files\Thunder\Program\ta.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 105]
- [D:\Program Files\Thunder\Program\ATL71.DLL] [Microsoft Corporation, 7.10.6101.0]
- [D:\Program Files\Thunder\Program\xl_data.dll] [深圳市迅雷网络技术有限公司, 1, 12, 5, 38]
- [D:\Program Files\Thunder\Program\XLLuaRuntime.dll] [深圳市迅雷网络技术有限公司, 0.9.0.412]
- [D:\Program Files\Thunder\Program\XLFSIO.dll] [深圳市迅雷网络技术有限公司, 0.9.0.422]
- [D:\Program Files\Thunder\Program\libexpat.dll] [N/A, ]
- [D:\Program Files\Thunder\Program\xl_client.dll] [深圳市迅雷网络技术有限公司, 1, 14, 2, 35]
- [D:\Program Files\Thunder\Program\backend_agent.dll] [深圳市迅雷网络技术有限公司, 1, 2, 2, 68]
- [D:\Program Files\Thunder\Program\ptl.dll] [深圳市迅雷网络技术有限公司, 3, 3, 2, 123]
- [D:\Program Files\Thunder\Program\dl_peer_id.dll] [深圳市迅雷网络技术有限公司, 3, 2, 2, 17]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [D:\Program Files\Thunder\Program\MSIMG32.dll] [N/A, ]
- [D:\Program Files\Thunder\Program\fs.dll] [深圳市迅雷网络技术有限公司, 1, 3, 2, 11]
- [D:\Program Files\Thunder\Program\al.dll] [深圳市迅雷网络技术有限公司, 1, 3, 2, 114]
- [D:\Program Files\Thunder\Program\p2p_upload.dll] [深圳市迅雷网络技术有限公司, 1, 2, 2, 32]
- [D:\Program Files\Thunder\Program\down_dispatcher.dll] [深圳市迅雷网络技术有限公司, 1, 2, 2, 143]
- [D:\Program Files\Thunder\Program\p2p.dll] [深圳市迅雷网络技术有限公司, 1, 2, 2, 186]
- [D:\Program Files\Thunder\Program\p2p_local_res.dll] [深圳市迅雷网络技术有限公司, 1, 2, 2, 31]
- [D:\Program Files\Thunder\Program\bt_kernel.dll] [深圳市迅雷网络技术有限公司, 1, 2, 2, 90]
- [D:\Program Files\Thunder\Program\emule_kernel.dll] [深圳市迅雷网络技术有限公司, 1, 4, 2, 21]
- [D:\Program Files\Thunder\Program\p2sp.dll] [深圳市迅雷网络技术有限公司, 1, 3, 2, 226]
- [PID: 4872 / Administrator][Z:\Program Files\opera10\Opera.exe] [Opera Software, 1893]
- [Z:\Program Files\opera10\Opera.dll] [Opera Software, 1893]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [C:\Program Files\AVAST Software\Avast\ashShell.dll] [AVAST Software, 8.0.1489.300]
- [PID: 1700 / Administrator][D:\Program Files\雨林木风工具箱\实用软件\FastStone Capture.exe] [N/A, ]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [D:\Program Files\StrokeIt\mhook.dll] [N/A, ]
- [C:\Program Files\AVAST Software\Avast\ashShell.dll] [AVAST Software, 8.0.1489.300]
- [PID: 1384 / Administrator][D:\Program Files\雨林木风工具箱\杀毒防毒\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.8.4.1331]
- [PID: 5196 / Administrator][D:\Program Files\雨林木风工具箱\杀毒防毒\sreng2\SREbf4b2b31.EXE] [Smallfrogs Studio, 2.8.4.1331]
- [C:\Windows\system32\freeime.ime] [极点五笔工作室, 6.5.0.0]
- [D:\Program Files\StrokeIt\mhook.dll] [N/A, ]
- [D:\Program Files\雨林木风工具箱\杀毒防毒\sreng2\Plugins\FILEDSV.SRE] [Smallfrogs Studio, 1, 1, 0, 20]
- [D:\Program Files\雨林木风工具箱\杀毒防毒\sreng2\Plugins\NTFSTREAM.SRE] [Smallfrogs Studio, 1, 0, 0, 5]
- [D:\Program Files\雨林木风工具箱\杀毒防毒\sreng2\Plugins\NWMON.SRE] [Smallfrogs Studio, 1, 0, 0, 8]
- [PID: 3624 / SYSTEM][C:\Windows\system32\SearchFilterHost.exe] [(Verified) Microsoft Corporation, 7.00.7601.17610 (win7sp1_gdr.110503-1502)]
- ==================================
- 文件关联
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .EXE OK. ["%1" %*]
- .COM OK. ["%1" %*]
- .PIF OK. ["%1" %*]
- .REG OK. [regedit.exe "%1"]
- .BAT OK. ["%1" %*]
- .SCR OK. ["%1" /S]
- .CHM OK. ["%SystemRoot%\hh.exe" %1]
- .HLP OK. [%SystemRoot%\winhlp32.exe %1]
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .VBS OK. ["%SystemRoot%\System32\WScript.exe" "%1" %*]
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- ==================================
- Winsock 提供者
- N/A
- ==================================
- Autorun.inf
- N/A
- ==================================
- HOSTS 文件
- N/A
- ==================================
- 进程特权扫描
- N/A
- ==================================
- 计划任务
- [已启用] \\Adobe Flash Player Updater
- C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
- [已禁用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
- N/A
- [已启用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
- N/A
- [已禁用] \Microsoft\Windows\AppID\PolicyConverter
- %windir%\system32\appidpolicyconverter.exe
- [已禁用] \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
- %windir%\system32\appidcertstorecheck.exe
- [已启用] \Microsoft\Windows\Application Experience\AitAgent
- aitagent
- [已启用] \Microsoft\Windows\Application Experience\ProgramDataUpdater
- %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate
- [已启用] \Microsoft\Windows\Autochk\Proxy
- %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
- [已启用] \Microsoft\Windows\Bluetooth\UninstallDeviceTask
- BthUdTask.exe $(Arg0)
- [已启用] \Microsoft\Windows\CertificateServicesClient\SystemTask
- N/A
- [已启用] \Microsoft\Windows\CertificateServicesClient\UserTask
- N/A
- [已禁用] \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
- N/A
- [已启用] \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
- %SystemRoot%\System32\wsqmcons.exe
- [已启用] \Microsoft\Windows\Defrag\ScheduledDefrag
- %windir%\system32\defrag.exe -c
- [已启用] \Microsoft\Windows\Location\Notifications
- %windir%\System32\LocationNotifications.exe
- [已启用] \Microsoft\Windows\Maintenance\WinSAT
- N/A
- [已启用] \Microsoft\Windows\Media Center\ActivateWindowsSearch
- %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
- [已启用] \Microsoft\Windows\Media Center\ConfigureInternetTimeService
- %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
- [已启用] \Microsoft\Windows\Media Center\DispatchRecoveryTasks
- %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
- [已启用] \Microsoft\Windows\Media Center\ehDRMInit
- %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
- [已启用] \Microsoft\Windows\Media Center\InstallPlayReady
- %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
- [已启用] \Microsoft\Windows\Media Center\mcupdate
- %SystemRoot%\ehome\mcupdate $(Arg0)
- [已启用] \Microsoft\Windows\Media Center\MediaCenterRecoveryTask
- %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
- [已启用] \Microsoft\Windows\Media Center\MediaCenterRecoveryTask
- %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
- [已启用] \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
- %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
- [已启用] \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
- %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
- [已启用] \Microsoft\Windows\Media Center\OCURActivate
- %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
- [已启用] \Microsoft\Windows\Media Center\OCURDiscovery
- %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
- [已启用] \Microsoft\Windows\Media Center\PBDADiscovery
- %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
- [已启用] \Microsoft\Windows\Media Center\PBDADiscoveryW1
- %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
- [已启用] \Microsoft\Windows\Media Center\PBDADiscoveryW2
- %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
- [已禁用] \Microsoft\Windows\Media Center\PeriodicScanRetry
- %windir%\ehome\MCUpdate.exe -pscn 0
- [已启用] \Microsoft\Windows\Media Center\PvrRecoveryTask
- %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
- [已启用] \Microsoft\Windows\Media Center\PvrRecoveryTask
- %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
- [已启用] \Microsoft\Windows\Media Center\PvrScheduleTask
- %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
- [已启用] \Microsoft\Windows\Media Center\PvrScheduleTask
- %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
- [已禁用] \Microsoft\Windows\Media Center\RecordingRestart
- %SystemRoot%\ehome\ehrec /RestartRecording
- [已启用] \Microsoft\Windows\Media Center\RegisterSearch
- %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
- [已启用] \Microsoft\Windows\Media Center\ReindexSearchRoot
- %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
- [已启用] \Microsoft\Windows\Media Center\SqlLiteRecoveryTask
- %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
- [已启用] \Microsoft\Windows\Media Center\SqlLiteRecoveryTask
- %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
- [已启用] \Microsoft\Windows\Media Center\UpdateRecordPath
- %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
- [已启用] \Microsoft\Windows\MobilePC\HotStart
- N/A
- [已启用] \Microsoft\Windows\MUI\LPRemove
- %windir%\system32\lpremove.exe
- [已启用] \Microsoft\Windows\Multimedia\SystemSoundsService
- N/A
- [已启用] \Microsoft\Windows\NetTrace\GatherNetworkInfo
- %windir%\system32\gatherNetworkInfo.vbs
- [已禁用] \Microsoft\Windows\Offline Files\Background Synchronization
- N/A
- [已禁用] \Microsoft\Windows\Offline Files\Logon Synchronization
- N/A
- [已启用] \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
- %SystemRoot%\System32\powercfg.exe -energy -auto
- [已启用] \Microsoft\Windows\Ras\MobilityManager
- N/A
- [已禁用] \Microsoft\Windows\SideShow\AutoWake
- N/A
- [已启用] \Microsoft\Windows\SideShow\GadgetManager
- N/A
- [已禁用] \Microsoft\Windows\SideShow\SessionAgent
- N/A
- [已禁用] \Microsoft\Windows\SideShow\SystemDataProviders
- N/A
- [已禁用] \Microsoft\Windows\SystemRestore\SR
- %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
- [已启用] \Microsoft\Windows\Tcpip\IpAddressConflict1
- %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
- [已启用] \Microsoft\Windows\Tcpip\IpAddressConflict2
- %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
- [已启用] \Microsoft\Windows\Time Synchronization\SynchronizeTime
- %windir%\system32\sc.exe start w32time task_started
- [已启用] \Microsoft\Windows\UPnP\UPnPHostConfig
- sc.exe config upnphost start= auto
- [已禁用] \Microsoft\Windows\User Profile Service\HiveUploadTask
- N/A
- [已启用] \Microsoft\Windows\Windows Error Reporting\QueueReporting
- %windir%\system32\wermgr.exe -queuereporting
- [已启用] \Microsoft\Windows\Windows Media Sharing\UpdateLibrary
- "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
- [已启用] \Microsoft\Windows\WindowsBackup\ConfigNotification
- %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
- [已禁用] \Microsoft\Windows\WindowsColorSystem\Calibration Loader
- N/A
- ==================================
- Windows 安全更新检查
- N/A
- ==================================
- API HOOK
- N/A
- ==================================
- 隐藏进程
- N/A
- ==================================
复制代码 |