查看: 6274|回复: 13
收起左侧

[求助] 发个样本和扫描记录,看看是中什么毒?

[复制链接]
mass3327
发表于 2013-5-31 08:37:15 | 显示全部楼层 |阅读模式
发个样本和扫描记录,看看是中什么毒?已全盘扫描杀毒,系统已还原过,前后用小A、诺顿、红伞、360卫士、清理助手扫描过,无毒,但还是不定时报毒,目前用小A网络版中,附图如下:


扫描记录如下:


  1. 2013-05-29,14:01:17

  2. System Repair Engineer 2.8.4.1331
  3. Smallfrogs (http://www.KZTechs.com)

  4. Windows 7 Ultimate Edition Service Pack 1 (Build 7601) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描
  14.     计划任务
  15.     Windows 安全更新检查
  16.     API HOOK
  17.     隐藏进程


  18. 启动项目
  19. 注册表
  20. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  21.     <XKToolBox><D:\Program Files\侠客工具盒\ToolBox.exe>  [恒古软件]
  22.     <Foxmail><"D:\Program Files\Foxmail\Foxmail.exe" -min>  [(Verified)Tencent Technology(Shenzhen) Company Limited]
  23.     <strokeit><D:\Program Files\StrokeIt\strokeit.exe>  []
  24.     <DesktopSprite><D:\Program Files\DesktopSprite2\DesktopSprite.exe>  [SnowFox Studio.]
  25. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  26.     <RtHDVCpl><C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s>  [(Verified)Realtek Semiconductor Corp]
  27.     <Microsoft Pinyin IME Migration><C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMESC\IMSCMIG.EXE /INSTALL>  [(Verified)Microsoft Corporation]
  28.     <avast><"C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui>  [(Verified)AVAST Software]
  29.     <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
  30. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  31.     <shell><explorer.exe>  [(Verified)Microsoft Windows]
  32.     <Userinit><C:\Windows\system32\userinit.exe,>  [(Verified)Microsoft Windows]
  33. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  34.     <AppInit_DLLs><>  [N/A]
  35. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  36.     <WebCheck><>  [N/A]
  37. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
  38.     <Microsoft Windows Media Player><%SystemRoot%\system32\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows]
  39. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  40.     <Internet Explorer><C:\Windows\System32\ie4uinit.exe -UserIconConfig>  [(Verified)Microsoft Windows]
  41. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
  42.     <Browser Customizations><"C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP>  [(Verified)Microsoft Corporation]
  43. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  44.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
  45. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  46.     <Microsoft Windows><"%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE>  [File is missing]
  47. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  48.     <Microsoft Windows Media Player><%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI>  [(Verified)Microsoft Windows]
  49. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
  50.     <Windows Desktop Update><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows]
  51. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
  52.     <Web Platform Customizations><C:\Windows\System32\ie4uinit.exe -BaseSettings>  [(Verified)Microsoft Windows]
  53. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
  54.     <N/A><C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install>  [(Verified)Microsoft Corporation]

  55. ==================================
  56. 启动文件夹
  57. [腾讯通RTX]
  58.   <C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\腾讯通RTX.lnk --> D:\PROGRA~1\Tencent\RTXC\RTX.exe [TENCENT]><N>
  59. [腾讯通RTX]
  60.   <C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\腾讯通RTX.lnk --> D:\PROGRA~1\Tencent\RTXC\RTX.exe [TENCENT]><N>

  61. ==================================
  62. 服务
  63. [Adobe Flash Player Update Service / AdobeFlashPlayerUpdateSvc][Stopped/Manual Start]
  64.   <C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe><Adobe Systems Incorporated>
  65. [avast! Antivirus / avast! Antivirus][Running/Auto Start]
  66.   <"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"><AVAST Software>
  67. [avast! Firewall / avast! Firewall][Running/Auto Start]
  68.   <"C:\Program Files\AVAST Software\Avast\afwServ.exe"><AVAST Software>
  69. [DTLService / DTLService][Running/Auto Start]
  70.   <D:\Program Files\DriveTheLife\DTLService.exe><深圳市驱动人生软件技术有限公司>
  71. [ForceWare Intelligent Application Manager (IAM) / ForceWare Intelligent Application Manager (IAM)][Running/Auto Start]
  72.   <C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe><>
  73. [KNBCenter / KNBCenter][Stopped/Disabled]
  74.   <"R:\Program Files\liebao\LBBrowser\KNBCenter.exe"><(File is missing)>
  75. [Kingsoft Common Content Service / KSDSVC][Stopped/Auto Start]
  76.   <D:\Program Files\Kingsoft\PowerWord PE\ksdsvc.exe><(File is missing)>
  77. [ForceWare IP service / nSvcIp][Running/Auto Start]
  78.   <C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe><>
  79. [NVIDIA Driver Helper Service / NVSvc][Running/Auto Start]
  80.   <C:\Windows\system32\nvvsvc.exe><NVIDIA Corporation>

  81. ==================================
  82. 驱动程序
  83. [adp94xx / adp94xx][Stopped/Manual Start]
  84.   <\SystemRoot\system32\drivers\adp94xx.sys><Adaptec, Inc.>
  85. [adpahci / adpahci][Stopped/Manual Start]
  86.   <\SystemRoot\system32\drivers\adpahci.sys><Adaptec, Inc.>
  87. [adpu320 / adpu320][Stopped/Manual Start]
  88.   <\SystemRoot\system32\drivers\adpu320.sys><Adaptec, Inc.>
  89. [aic78xx / aic78xx][Stopped/Manual Start]
  90.   <\SystemRoot\system32\drivers\djsvs.sys><Adaptec, Inc.>
  91. [aliide / aliide][Stopped/Manual Start]
  92.   <\SystemRoot\system32\drivers\aliide.sys><Acer Laboratories Inc.>
  93. [amdsata / amdsata][Stopped/Manual Start]
  94.   <\SystemRoot\system32\drivers\amdsata.sys><Advanced Micro Devices>
  95. [amdsbs / amdsbs][Stopped/Manual Start]
  96.   <\SystemRoot\system32\drivers\amdsbs.sys><AMD Technologies Inc.>
  97. [amdxata / amdxata][Running/Boot Start]
  98.   <\SystemRoot\system32\drivers\amdxata.sys><Advanced Micro Devices>
  99. [arc / arc][Stopped/Manual Start]
  100.   <\SystemRoot\system32\drivers\arc.sys><Adaptec, Inc.>
  101. [arcsas / arcsas][Stopped/Manual Start]
  102.   <\SystemRoot\system32\drivers\arcsas.sys><Adaptec, Inc.>
  103. [aswMonFlt / aswMonFlt][Running/Auto Start]
  104.   <\??\C:\Windows\system32\drivers\aswMonFlt.sys><AVAST Software>
  105. [avast! Firewall NDIS Filter Service / aswNdis][Running/Boot Start]
  106.   <\SystemRoot\system32\DRIVERS\aswNdis.sys><ALWIL Software>
  107. [aswRdr / aswRdr][Running/System Start]
  108.   <\SystemRoot\System32\Drivers\aswrdr2.sys><AVAST Software>
  109. [Broadcom NetXtreme II VBD / b06bdrv][Stopped/Manual Start]
  110.   <\SystemRoot\system32\drivers\bxvbdx.sys><Broadcom Corporation>
  111. [Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 / b57nd60x][Stopped/Manual Start]
  112.   <system32\DRIVERS\b57nd60x.sys><Broadcom Corporation>
  113. [Brother USB Mass-Storage Lower Filter Driver / BrFiltLo][Stopped/Manual Start]
  114.   <\SystemRoot\system32\drivers\BrFiltLo.sys><Brother Industries, Ltd.>
  115. [Brother USB Mass-Storage Upper Filter Driver / BrFiltUp][Stopped/Manual Start]
  116.   <\SystemRoot\system32\drivers\BrFiltUp.sys><Brother Industries, Ltd.>
  117. [Brother MFC Serial Port Interface Driver (WDM) / Brserid][Stopped/Manual Start]
  118.   <\SystemRoot\System32\Drivers\Brserid.sys><Brother Industries Ltd.>
  119. [Brother WDM Serial driver / BrSerWdm][Stopped/Manual Start]
  120.   <\SystemRoot\System32\Drivers\BrSerWdm.sys><Brother Industries Ltd.>
  121. [Brother MFC USB Fax Only Modem / BrUsbMdm][Stopped/Manual Start]
  122.   <\SystemRoot\System32\Drivers\BrUsbMdm.sys><Brother Industries Ltd.>
  123. [Brother MFC USB Serial WDM Driver / BrUsbSer][Stopped/Manual Start]
  124.   <\SystemRoot\System32\Drivers\BrUsbSer.sys><Brother Industries Ltd.>
  125. [cmdide / cmdide][Stopped/Manual Start]
  126.   <\SystemRoot\system32\drivers\cmdide.sys><CMD Technology, Inc.>
  127. [cpuz135 / cpuz135][Stopped/Manual Start]
  128.   <\??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz135\cpuz135_x32.sys><N/A>
  129. [DTLD48EC12D954B431e88684F32293ABA20 / DTLD48EC12D954B431e88684F32293ABA20][Running/System Start]
  130.   <\??\D:\Program Files\DriveTheLife\DtlSrvPro.dat><N/A>
  131. [Intel(R) PRO/1000 NDIS 6 Adapter Driver / E1G60][Stopped/Manual Start]
  132.   <system32\DRIVERS\E1G60I32.sys><Intel Corporation>
  133. [Broadcom NetXtreme II 10 GigE VBD / ebdrv][Stopped/Manual Start]
  134.   <\SystemRoot\system32\drivers\evbdx.sys><Broadcom Corporation>
  135. [elxstor / elxstor][Stopped/Manual Start]
  136.   <\SystemRoot\system32\drivers\elxstor.sys><Emulex>
  137. [Primo Ramdisk Controller / FancyRd][Running/Boot Start]
  138.   <\SystemRoot\system32\DRIVERS\fancyrd.sys><Romex Software>
  139. [Hauppauge Consumer Infrared Receiver / hcw85cir][Stopped/Manual Start]
  140.   <\SystemRoot\system32\drivers\hcw85cir.sys><Hauppauge Computer Works, Inc.>
  141. [HpSAMD / HpSAMD][Stopped/Manual Start]
  142.   <\SystemRoot\system32\drivers\HpSAMD.sys><Hewlett-Packard Company>
  143. [HWCore / HWCore][Running/Manual Start]
  144.   <\??\D:\Program Files\DriveTheLife\hwcore.sys><N/A>
  145. [iaStorV / iaStorV][Stopped/Manual Start]
  146.   <\SystemRoot\system32\drivers\iaStorV.sys><Intel Corporation>
  147. [iirsp / iirsp][Stopped/Manual Start]
  148.   <\SystemRoot\system32\drivers\iirsp.sys><Intel Corp./ICP vortex GmbH>
  149. [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
  150.   <system32\drivers\RTKVHDA.sys><Realtek Semiconductor Corp.>
  151. [KNBDrv / KNBDrv][Stopped/Manual Start]
  152.   <\??\C:\Windows\system32\drivers\KNBDrv.sys><Kingsoft Corporation>
  153. [LSI_FC / LSI_FC][Stopped/Manual Start]
  154.   <\SystemRoot\system32\drivers\lsi_fc.sys><LSI Corporation>
  155. [LSI_SAS / LSI_SAS][Stopped/Manual Start]
  156.   <\SystemRoot\system32\drivers\lsi_sas.sys><LSI Corporation>
  157. [LSI_SAS2 / LSI_SAS2][Stopped/Manual Start]
  158.   <\SystemRoot\system32\drivers\lsi_sas2.sys><LSI Corporation>
  159. [LSI_SCSI / LSI_SCSI][Stopped/Manual Start]
  160.   <\SystemRoot\system32\drivers\lsi_scsi.sys><LSI Corporation>
  161. [megasas / megasas][Stopped/Manual Start]
  162.   <\SystemRoot\system32\drivers\megasas.sys><LSI Corporation>
  163. [MegaSR / MegaSR][Stopped/Manual Start]
  164.   <\SystemRoot\system32\drivers\MegaSR.sys><LSI Corporation, Inc.>
  165. [Softlumos Multi-Platform / Mulsys][Running/Boot Start]
  166.   <\SystemRoot\System32\DRIVERS\Mulsys.SYS><Windows (R) Codename Longhorn DDK provider>
  167. [nfrd960 / nfrd960][Stopped/Manual Start]
  168.   <\SystemRoot\system32\drivers\nfrd960.sys><IBM Corporation>
  169. [NVIDIA nForce 网络控制器驱动程序 / NVENETFD][Stopped/Manual Start]
  170.   <system32\DRIVERS\nvm62x32.sys><NVIDIA Corporation>
  171. [nvlddmkm / nvlddmkm][Running/Manual Start]
  172.   <system32\DRIVERS\nvlddmkm.sys><NVIDIA Corporation>
  173. [NVIDIA nForce 10/100/1000 Mbps Ethernet  / NVNET][Running/Manual Start]
  174.   <system32\DRIVERS\nvmf6232.sys><NVIDIA Corporation>
  175. [nvraid / nvraid][Stopped/Manual Start]
  176.   <\SystemRoot\system32\drivers\nvraid.sys><NVIDIA Corporation>
  177. [nvstor / nvstor][Running/Boot Start]
  178.   <\SystemRoot\system32\drivers\nvstor.sys><NVIDIA Corporation>
  179. [ql2300 / ql2300][Stopped/Manual Start]
  180.   <\SystemRoot\system32\drivers\ql2300.sys><QLogic Corporation>
  181. [ql40xx / ql40xx][Stopped/Manual Start]
  182.   <\SystemRoot\system32\drivers\ql40xx.sys><QLogic Corporation>
  183. [Serial port driver / Serial][Running/System Start]
  184.   <system32\DRIVERS\serial.sys><Brother Industries Ltd.>
  185. [SiSRaid2 / SiSRaid2][Stopped/Manual Start]
  186.   <\SystemRoot\system32\drivers\SiSRaid2.sys><Silicon Integrated Systems Corp.>
  187. [SiSRaid4 / SiSRaid4][Stopped/Manual Start]
  188.   <\SystemRoot\system32\drivers\sisraid4.sys><Silicon Integrated Systems>
  189. [stexstor / stexstor][Stopped/Manual Start]
  190.   <\SystemRoot\system32\drivers\stexstor.sys><Promise Technology>
  191. [VirtualBox Service / VBoxDrv][Running/System Start]
  192.   <system32\DRIVERS\VBoxDrv.sys><Oracle Corporation>
  193. [VirtualBox Host-Only Ethernet Adapter / VBoxNetAdp][Running/Manual Start]
  194.   <system32\DRIVERS\VBoxNetAdp.sys><Oracle Corporation>
  195. [VirtualBox Bridged Networking Service / VBoxNetFlt][Running/Manual Start]
  196.   <system32\DRIVERS\VBoxNetFlt.sys><Oracle Corporation>
  197. [VirtualBox USB Monitor Driver / VBoxUSBMon][Running/System Start]
  198.   <system32\DRIVERS\VBoxUSBMon.sys><Oracle Corporation>
  199. [VGPU / VGPU][Stopped/Manual Start]
  200.   <System32\drivers\rdvgkmd.sys><N/A>
  201. [viaide / viaide][Stopped/Manual Start]
  202.   <\SystemRoot\system32\drivers\viaide.sys><VIA Technologies, Inc.>
  203. [vsmraid / vsmraid][Stopped/Manual Start]
  204.   <\SystemRoot\system32\drivers\vsmraid.sys><VIA Technologies Inc.,Ltd>
  205. [Virtual Device Driver / VxDevice][Running/Boot Start]
  206.   <\SystemRoot\System32\DRIVERS\VxDevice.SYS><N/A>

  207. ==================================
  208. 浏览器加载项
  209. [VideoUrlSniffer Class]
  210.   {00000ADA-7E0D-47C1-986C-F017D09C4304} <C:\Program Files\Common Files\Thunder Network\KanKan\VideoUrlSniffer.2.0.1.99.(782).dll, (Signed) 深圳市迅雷网络技术有限公司>
  211. [迅雷流媒体探测IE支持]
  212.   {01443AEC-0FD1-40fd-9C87-E93D1494C233} <, >
  213. [迅雷下载支持]
  214.   {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Program Files\Thunder\BHO\XunleiBHO7.2.90.92.dll, (Signed) 深圳市迅雷网络技术有限公司>
  215. []
  216.   {14c1d00e-0b92-4379-880b-444fa2d740dd} <, >
  217. [迅雷看看播放器]
  218.   {24c1d00e-0b92-4379-880b-444fa2d740dd} <, >
  219. [信息检索(&R)]
  220.   {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, (Signed) Microsoft Corporation>
  221. [Shockwave Flash Object]
  222.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\system32\Macromed\Flash\Flash32_11_7_700_202.ocx, (Signed) Adobe Systems, Inc.>
  223. [VideoUrlSniffer Class]
  224.   {00000ADA-7E0D-47C1-986C-F017D09C4304} <C:\Program Files\Common Files\Thunder Network\KanKan\VideoUrlSniffer.2.0.1.99.(782).dll, (Signed) 深圳市迅雷网络技术有限公司>
  225. [迅雷流媒体探测IE支持]
  226.   {01443AEC-0FD1-40FD-9C87-E93D1494C233} <, >
  227. [Agent Class]
  228.   {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <D:\Program Files\Thunder\BHO\ThunderAgent7.2.90.92.dll, (Signed) 深圳市迅雷网络技术有限公司>
  229. [QQPYChecker Class]
  230.   {5052B4D0-9DF7-45ef-88EF-F42C0EA33A43} <D:\Program Files\QQPinyin\4.5.1206.400\QQImeChecker.dll, (Signed) Tencent>
  231. [Windows Media Player]
  232.   {6BF52A52-394A-11D3-B153-00C04F79FAA6} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
  233. [Access UserInfo by Script]
  234.   {6EE9CD3E-A386-4DAE-9737-A759DBF927AE} <D:\Program Files\Thunder Network\Xmp\Program\UserAgent1.0.2.14.dll, (Signed) Thunder Networking Technologies,LTD>
  235. [迅雷下载支持]
  236.   {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Program Files\Thunder\BHO\XunleiBHO7.2.90.92.dll, (Signed) 深圳市迅雷网络技术有限公司>
  237. [OFrameObject Class]
  238.   {9701758C-4373-482E-B13C-776C048EC890} <, >
  239. [VersionDetector Class]
  240.   {9EFF1953-9694-47B1-AEF6-B2A3FE8BFE9B} <C:\Program Files\Common Files\Thunder Network\KanKan\vd.1.1.0.32.(999).dll, N/A>
  241. [APlayer Control]
  242.   {A9322148-C691-4B9D-91FC-B9C461DBE9DD} <, >
  243. [DapCtrl Class]
  244.   {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} <, >
  245. [LiveDapCtrl Class]
  246.   {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F9} <, >
  247. [Shockwave Flash Object]
  248.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\system32\Macromed\Flash\Flash32_11_7_700_202.ocx, (Signed) Adobe Systems, Inc.>
  249. [xoliimpl Class]
  250.   {DD5BF6D1-6663-47E0-9DFA-5C343CAF178E} <C:\Windows\xinstaller.dll, (Signed) 深圳市迅雷技术有限公司>
  251. []
  252.   {F3E70CEA-956E-49CC-B444-73AFE593AD7F} <, >
  253. [使用迅雷下载]
  254.   <D:\Program Files\Thunder\BHO\geturl.htm, N/A>
  255. [使用迅雷看看播放器播放]
  256.   <C:\ProgramData\Thunder Network\XMP4\core\program\XmpIEMenu.htm, N/A>
  257. [使用迅雷离线下载]
  258.   <D:\Program Files\Thunder\BHO\OfflineDownload.htm, N/A>
  259. [导出到 Microsoft Excel(&X)]
  260.   <res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000, N/A>

  261. ==================================
  262. 正在运行的进程
  263. [PID: 308 / SYSTEM][\SystemRoot\System32\smss.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  264. [PID: 468 / SYSTEM][C:\Windows\system32\csrss.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  265. [PID: 528 / SYSTEM][C:\Windows\system32\wininit.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  266. [PID: 584 / SYSTEM][C:\Windows\system32\services.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  267. [PID: 600 / SYSTEM][C:\Windows\system32\lsass.exe]  [(Verified) Microsoft Corporation, 6.1.7601.17725 (win7sp1_gdr.111116-1503)]
  268. [PID: 608 / SYSTEM][C:\Windows\system32\lsm.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  269. [PID: 756 / SYSTEM][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  270. [PID: 844 / SYSTEM][C:\Windows\system32\nvvsvc.exe]  [NVIDIA Corporation, 8.17.12.6300]
  271.     [C:\Program Files\NVIDIA Corporation\Display\NVXDBat.dll]  [NVIDIA Corporation, 7.17.12.6300]
  272. [PID: 884 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  273. [PID: 960 / LOCAL SERVICE][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  274.     [C:\Windows\system32\MBWrp32.dll]  [Creative Technology Ltd., 1.0.0.200]
  275.     [C:\Windows\system32\RtkAPO.dll]  [Realtek Semiconductor Corp., 11, 0, 6000, 298]
  276. [PID: 1020 / SYSTEM][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  277. [PID: 1060 / SYSTEM][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  278. [PID: 1196 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  279. [PID: 1364 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  280. [PID: 1504 / SYSTEM][C:\Program Files\AVAST Software\Avast\AvastSvc.exe]  [AVAST Software, 8.0.1489.300]
  281.     [C:\Program Files\AVAST Software\Avast\aswCmnBS.dll]  [AVAST Software, 8.0.1489.300]
  282.     [C:\Program Files\AVAST Software\Avast\aswCmnOS.dll]  [AVAST Software, 8.0.1489.300]
  283.     [C:\Program Files\AVAST Software\Avast\aswCmnIS.dll]  [AVAST Software, 8.0.1489.300]
  284.     [C:\Program Files\AVAST Software\Avast\ashBase.dll]  [AVAST Software, 8.0.1489.300]
  285.     [C:\Program Files\AVAST Software\Avast\aswEngLdr.dll]  [AVAST Software, 8.0.1489.300]
  286.     [C:\Program Files\AVAST Software\Avast\2052\Base.dll]  [AVAST Software, 8.0.1489.300]
  287.     [C:\Program Files\AVAST Software\Avast\ashServ.dll]  [AVAST Software, 8.0.1489.300]
  288.     [C:\Program Files\AVAST Software\Avast\aswAux.dll]  [AVAST Software, 8.0.1489.300]
  289.     [C:\Program Files\AVAST Software\Avast\ashTask.dll]  [AVAST Software, 8.0.1489.300]
  290.     [C:\Program Files\AVAST Software\Avast\ashTaskEx.dll]  [AVAST Software, 8.0.1489.300]
  291.     [C:\Program Files\AVAST Software\Avast\aswLog.dll]  [AVAST Software, 8.0.1489.300]
  292.     [C:\Program Files\AVAST Software\Avast\aswSqLt.dll]  [AVAST Software, 8.0.1489.300]
  293.     [C:\Program Files\AVAST Software\Avast\aswProperty.dll]  [AVAST Software, 8.0.1489.300]
  294.     [C:\Program Files\AVAST Software\Avast\AavmRpch.dll]  [AVAST Software, 8.0.1489.300]
  295.     [C:\Program Files\AVAST Software\Avast\Aavm4h.dll]  [AVAST Software, 8.0.1489.300]
  296.     [C:\Program Files\AVAST Software\Avast\avastIP.dll]  [AVAST Software, 8.0.1489.300]
  297.     [C:\Program Files\AVAST Software\Avast\aswIdle.dll]  [AVAST Software, 8.0.1489.300]
  298.     [C:\Program Files\AVAST Software\Avast\aswDld.dll]  [AVAST Software, 8.0.1489.300]
  299.     [C:\Program Files\AVAST Software\Avast\aswStrm.dll]  [AVAST Software, 8.0.1489.300]
  300.     [C:\Program Files\AVAST Software\Avast\AhResNS.dll]  [AVAST Software, 8.0.1489.300]
  301.     [C:\Program Files\AVAST Software\Avast\AhResStd.dll]  [AVAST Software, 8.0.1489.300]
  302.     [C:\Program Files\AVAST Software\Avast\AhResWS.dll]  [AVAST Software, 8.0.1489.300]
  303.     [C:\Program Files\AVAST Software\Avast\ashWebSv.dll]  [AVAST Software, 8.0.1489.300]
  304.     [C:\Program Files\AVAST Software\Avast\ashWsFtr.dll]  [AVAST Software, 8.0.1489.300]
  305.     [C:\Program Files\AVAST Software\Avast\defs\13052801\aswEngin.dll]  [AVAST Software, 7.0.1488.137]
  306.     [C:\Program Files\AVAST Software\Avast\defs\13052801\aswCmnIS.dll]  [AVAST Software, 7.0.1483.117]
  307.     [C:\Program Files\AVAST Software\Avast\defs\13052801\aswCmnOS.dll]  [AVAST Software, 7.0.1485.125]
  308.     [C:\Program Files\AVAST Software\Avast\defs\13052801\aswCmnBS.dll]  [AVAST Software, 7.0.1488.137]
  309.     [C:\Program Files\AVAST Software\Avast\defs\13052801\aswScan.dll]  [AVAST Software, 7.0.1485.125]
  310.     [C:\Program Files\AVAST Software\Avast\defs\13052801\aswRep.dll]  [AVAST Software, 7.0.1488.138]
  311.     [C:\Program Files\AVAST Software\Avast\defs\13052801\aswFiDb.dll]  [AVAST Software, 7.0.1484.119]
  312.     [C:\Program Files\AVAST Software\Avast\defs\13052801\algo.dll]  [N/A, ]
  313.     [C:\Program Files\AVAST Software\Avast\defs\13052801\aswCleanerDLL.dll]  [AVAST Software, 1, 0, 212, 0]
  314. [PID: 1640 / SYSTEM][C:\Program Files\AVAST Software\Avast\afwServ.exe]  [AVAST Software, 8.0.1489.300]
  315.     [C:\Program Files\AVAST Software\Avast\afwCore.dll]  [AVAST Software, 8.0.1489.300]
  316.     [C:\Program Files\AVAST Software\Avast\Aavm4h.dll]  [AVAST Software, 8.0.1489.300]
  317.     [C:\Program Files\AVAST Software\Avast\AavmRpch.dll]  [AVAST Software, 8.0.1489.300]
  318.     [C:\Program Files\AVAST Software\Avast\ashBase.dll]  [AVAST Software, 8.0.1489.300]
  319.     [C:\Program Files\AVAST Software\Avast\aswEngLdr.dll]  [AVAST Software, 8.0.1489.300]
  320.     [C:\Program Files\AVAST Software\Avast\aswCmnOS.dll]  [AVAST Software, 8.0.1489.300]
  321.     [C:\Program Files\AVAST Software\Avast\aswCmnIS.dll]  [AVAST Software, 8.0.1489.300]
  322.     [C:\Program Files\AVAST Software\Avast\aswCmnBS.dll]  [AVAST Software, 8.0.1489.300]
  323.     [C:\Program Files\AVAST Software\Avast\ashTask.dll]  [AVAST Software, 8.0.1489.300]
  324.     [C:\Program Files\AVAST Software\Avast\aswAux.dll]  [AVAST Software, 8.0.1489.300]
  325.     [C:\Program Files\AVAST Software\Avast\aswProperty.dll]  [AVAST Software, 8.0.1489.300]
  326.     [C:\Program Files\AVAST Software\Avast\avastIP.dll]  [AVAST Software, 8.0.1489.300]
  327.     [C:\Program Files\AVAST Software\Avast\aswLog.dll]  [AVAST Software, 8.0.1489.300]
  328.     [C:\Program Files\AVAST Software\Avast\aswSqLt.dll]  [AVAST Software, 8.0.1489.300]
  329.     [C:\Program Files\AVAST Software\Avast\afwCoreServ.dll]  [AVAST Software, 8.0.1489.300]
  330.     [C:\Program Files\AVAST Software\Avast\afwRpc.dll]  [AVAST Software, 8.0.1489.300]
  331.     [C:\Program Files\AVAST Software\Avast\afwCoreClient.dll]  [AVAST Software, 8.0.1489.300]
  332.     [C:\Program Files\AVAST Software\Avast\afwGeoIP.dll]  [AVAST Software, 8.0.1489.300]
  333.     [C:\Program Files\AVAST Software\Avast\2052\Base.dll]  [AVAST Software, 8.0.1489.300]
  334.     [C:\Program Files\AVAST Software\Avast\defs\13052801\aswEngin.dll]  [AVAST Software, 7.0.1488.137]
  335.     [C:\Program Files\AVAST Software\Avast\defs\13052801\aswCmnIS.dll]  [AVAST Software, 7.0.1483.117]
  336.     [C:\Program Files\AVAST Software\Avast\defs\13052801\aswCmnOS.dll]  [AVAST Software, 7.0.1485.125]
  337.     [C:\Program Files\AVAST Software\Avast\defs\13052801\aswCmnBS.dll]  [AVAST Software, 7.0.1488.137]
  338.     [C:\Program Files\AVAST Software\Avast\defs\13052801\aswScan.dll]  [AVAST Software, 7.0.1485.125]
  339.     [C:\Program Files\AVAST Software\Avast\defs\13052801\aswRep.dll]  [AVAST Software, 7.0.1488.138]
  340.     [C:\Program Files\AVAST Software\Avast\defs\13052801\aswFiDb.dll]  [AVAST Software, 7.0.1484.119]
  341.     [C:\Program Files\AVAST Software\Avast\defs\13052801\fwAux.dll]  [AVAST Software, 7.0.1481.100]
  342. [PID: 1804 / SYSTEM][C:\Windows\System32\spoolsv.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  343.     [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSDNT5UI.DLL]  [Zenographics, Inc., 0, 3, 2911, 1]
  344.     [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSDDM.DLL]  [Zenographics, Inc., 6, 20, 1611, 0]
  345.     [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSPOOL.dll]  [Zenographics, Inc., 6, 1, 1, 0]
  346.     [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZGDI.dll]  [Zenographics, Inc., 5, 60, 709, 0]
  347.     [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZTAG.dll]  [Zenographics, Inc., 5, 60, 1210, 0]
  348.     [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSDDMUI.DLL]  [Zenographics, Inc., 6, 2, 411, 0]
  349.     [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSR.dll]  [Zenographics, Inc., 6, 20, 1625, 0]
  350. [PID: 1832 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  351. [PID: 1952 / SYSTEM][D:\Program Files\DriveTheLife\DTLService.exe]  [深圳市驱动人生软件技术有限公司, 1, 0, 1, 32]
  352.     [D:\Program Files\DriveTheLife\PipeProtocol.dll]  [N/A, ]
  353.     [D:\Program Files\DriveTheLife\dtlupdater\checkupdate.dll]  [深圳市驱动人生软件技术有限公司, 1, 0, 1, 15]
  354.     [D:\Program Files\DriveTheLife\substat.dll]  [深圳市驱动人生软件技术有限公司, 1, 0, 0, 21]
  355.     [D:\Program Files\DriveTheLife\tipsdll.dll]  [, 1, 0, 1, 17]
  356.     [D:\Program Files\DriveTheLife\drvs.dll]  [深圳市驱动人生软件技术有限公司, 1, 0, 1, 32]
  357.     [D:\Program Files\DriveTheLife\DstUdp.dll]  [深圳市驱动人生软件技术有限公司, 1, 0, 1, 20]
  358.     [D:\Program Files\DriveTheLife\utility.dll]  [深圳市驱动人生软件技术有限公司, 1, 0, 0, 10]
  359.     [D:\Program Files\DriveTheLife\udp.dll]  [深圳市驱动人生软件技术有限公司, 1, 0, 0, 7]
  360.     [D:\Program Files\DriveTheLife\hdenum.dll]  [深圳市驱动人生软件技术有限公司, 2, 3, 3, 7]
  361.     [D:\Program Files\DriveTheLife\bios.dll]  [深圳市驱动人生软件技术有限公司, 1.1.16.0]
  362. [PID: 1868 / SYSTEM][C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe]  [, 1, 0, 1, 0]
  363.     [C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\NMI.dll]  [NVIDIA Corporation, 2, 2, 0, 7325]
  364.     [C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll]  [N/A, ]
  365.     [C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll]  [N/A, ]
  366. [PID: 1544 / SYSTEM][C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe]  [, 2, 2, 0, 7325]
  367.     [C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll]  [N/A, ]
  368.     [C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\NMI.dll]  [NVIDIA Corporation, 2, 2, 0, 7325]
  369.     [C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll]  [N/A, ]
  370. [PID: 2200 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  371. [PID: 3108 / SYSTEM][C:\Windows\system32\SearchIndexer.exe]  [(Verified) Microsoft Corporation, 7.00.7600.16385 (win7_rtm.090713-1255)]
  372. [PID: 3544 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  373. [PID: 3640 / SYSTEM][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  374. [PID: 1612 / SYSTEM][C:\Windows\system32\SearchProtocolHost.exe]  [(Verified) Microsoft Corporation, 7.00.7601.17610 (win7sp1_gdr.110503-1502)]
  375. [PID: 1220 / SYSTEM][C:\Windows\system32\csrss.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  376. [PID: 3528 / SYSTEM][C:\Windows\system32\winlogon.exe]  [(Verified) Microsoft Corporation, 6.1.7601.17514 (win7sp1_rtm.101119-1850)]
  377. [PID: 792 / SYSTEM][C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe]  [NVIDIA Corporation, 7.17.12.6300]
  378.     [C:\Program Files\NVIDIA Corporation\Display\NVXDApiX.dll]  [NVIDIA Corporation, 7.17.12.6300]
  379.     [C:\Program Files\NVIDIA Corporation\Display\NvUI.dll]  [NVIDIA Corporation, 7.17.12.6300]
  380.     [C:\Windows\system32\nvapi.dll]  [NVIDIA Corporation, 8.17.12.6300]
  381.     [C:\Program Files\NVIDIA Corporation\Display\NVXDBat.dll]  [NVIDIA Corporation, 7.17.12.6300]
  382.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  383. [PID: 1788 / SYSTEM][C:\Windows\system32\nvvsvc.exe]  [NVIDIA Corporation, 8.17.12.6300]
  384.     [C:\Windows\system32\NVSVC.DLL]  [NVIDIA Corporation, 8.17.12.6300]
  385.     [C:\Windows\system32\nvapi.dll]  [NVIDIA Corporation, 8.17.12.6300]
  386.     [C:\Windows\system32\NVSVCR.DLL]  [NVIDIA Corporation, 8.17.12.6300]
  387.     [C:\Program Files\NVIDIA Corporation\Display\NVXDBat.dll]  [NVIDIA Corporation, 7.17.12.6300]
  388.     [C:\Program Files\NVIDIA Corporation\Display\NVXDPlcy.dll]  [NVIDIA Corporation, 7.17.12.6300]
  389. [PID: 2876 / Administrator][C:\Windows\system32\Dwm.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  390.     [C:\Windows\system32\nvd3dum.dll]  [NVIDIA Corporation, 8.17.12.6300]
  391. [PID: 2156 / Administrator][C:\Windows\Explorer.EXE]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  392.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  393.     [C:\Program Files\AVAST Software\Avast\ashShell.dll]  [AVAST Software, 8.0.1489.300]
  394.     [D:\Program Files\NetSpeedMonitorX86\nsm.dll]  [Florian Gilles, 2, 5, 4, 0]
  395.     [C:\Windows\System32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0401]
  396.     [C:\Windows\system32\FXSAPI.dll]  [Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  397.     [C:\Windows\system32\nvshext.dll]  [NVIDIA Corporation, 263.00]
  398.     [C:\Program Files\NVIDIA Corporation\Display\NVXDBat.dll]  [NVIDIA Corporation, 7.17.12.6300]
  399.     [C:\Program Files\NVIDIA Corporation\Display\NVXDPlcy.dll]  [NVIDIA Corporation, 7.17.12.6300]
  400.     [C:\Program Files\360\360zip\360ZipExt.dll]  [360.cn, 2, 0, 0, 1071]
  401.     [D:\Program Files\Tencent\RTXC\RTXShlMenu.dll]  [Tencent, 1, 0, 0, 1]
  402.     [D:\Program Files\侠客工具盒\TBoxExt.dll]  [恒古软件, 6, 0, 0, 0]
  403.     [D:\Program Files\StrokeIt\mhook.dll]  [N/A, ]
  404. [PID: 2484 / Administrator][C:\Windows\system32\taskhost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  405.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  406.     [C:\Windows\System32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0401]
  407. [PID: 2776 / Administrator][C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe]  [Realtek Semiconductor, 1, 0, 0, 821]
  408.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  409. [PID: 716 / Administrator][C:\Program Files\AVAST Software\Avast\AvastUI.exe]  [AVAST Software, 8.0.1489.300]
  410.     [C:\Program Files\AVAST Software\Avast\aswUtil.dll]  [AVAST Software, 8.0.1489.300]
  411.     [C:\Program Files\AVAST Software\Avast\ashBase.dll]  [AVAST Software, 8.0.1489.300]
  412.     [C:\Program Files\AVAST Software\Avast\aswEngLdr.dll]  [AVAST Software, 8.0.1489.300]
  413.     [C:\Program Files\AVAST Software\Avast\aswCmnOS.dll]  [AVAST Software, 8.0.1489.300]
  414.     [C:\Program Files\AVAST Software\Avast\aswCmnIS.dll]  [AVAST Software, 8.0.1489.300]
  415.     [C:\Program Files\AVAST Software\Avast\aswCmnBS.dll]  [AVAST Software, 8.0.1489.300]
  416.     [C:\Program Files\AVAST Software\Avast\ashTask.dll]  [AVAST Software, 8.0.1489.300]
  417.     [C:\Program Files\AVAST Software\Avast\aswAux.dll]  [AVAST Software, 8.0.1489.300]
  418.     [C:\Program Files\AVAST Software\Avast\avastIP.dll]  [AVAST Software, 8.0.1489.300]
  419.     [C:\Program Files\AVAST Software\Avast\aswProperty.dll]  [AVAST Software, 8.0.1489.300]
  420.     [C:\Program Files\AVAST Software\Avast\AavmRpch.dll]  [AVAST Software, 8.0.1489.300]
  421.     [C:\Program Files\AVAST Software\Avast\aswLog.dll]  [AVAST Software, 8.0.1489.300]
  422.     [C:\Program Files\AVAST Software\Avast\aswSqLt.dll]  [AVAST Software, 8.0.1489.300]
  423.     [C:\Program Files\AVAST Software\Avast\2052\Base.dll]  [AVAST Software, 8.0.1489.300]
  424.     [C:\Program Files\AVAST Software\Avast\afwGeoIP.dll]  [AVAST Software, 8.0.1489.300]
  425.     [C:\Program Files\AVAST Software\Avast\aswData.dll]  [AVAST Software, 8.0.1489.300]
  426.     [C:\Program Files\AVAST Software\Avast\ashTaskEx.dll]  [AVAST Software, 8.0.1489.300]
  427.     [C:\Program Files\AVAST Software\Avast\Aavm4h.dll]  [AVAST Software, 8.0.1489.300]
  428.     [C:\Program Files\AVAST Software\Avast\afwCore.dll]  [AVAST Software, 8.0.1489.300]
  429.     [C:\Program Files\AVAST Software\Avast\afwCoreClient.dll]  [AVAST Software, 8.0.1489.300]
  430.     [C:\Program Files\AVAST Software\Avast\afwRpc.dll]  [AVAST Software, 8.0.1489.300]
  431.     [C:\Program Files\AVAST Software\Avast\2052\UILangRes.dll]  [AVAST Software, 8.0.1489.300]
  432.     [C:\Program Files\AVAST Software\Avast\CommonRes.dll]  [AVAST Software, 8.0.1489.300]
  433.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  434.     [C:\Program Files\AVAST Software\Avast\defs\13052801\uiExt.dll]  [AVAST Software, 7.0.1485.126]
  435.     [C:\Windows\System32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0401]
  436.     [C:\Program Files\AVAST Software\Avast\ashShell.dll]  [AVAST Software, 8.0.1489.300]
  437. [PID: 3980 / Administrator][D:\Program Files\侠客工具盒\ToolBox.exe]  [恒古软件, 6, 0, 0, 0]
  438.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  439.     [D:\Program Files\StrokeIt\mhook.dll]  [N/A, ]
  440. [PID: 4080 / Administrator][D:\Program Files\Foxmail\Foxmail.exe]  [Tencent Inc., 7.0.1.91]
  441.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  442.     [D:\Program Files\Foxmail\FoxNote.dll]  [N/A, ]
  443.     [D:\Program Files\Foxmail\rfri.dll]  [Tencent Inc., 1, 0, 0, 1]
  444.     [D:\Program Files\Foxmail\nspi.dll]  [TENCENT, 1, 0, 0, 1]
  445.     [D:\Program Files\Foxmail\emsmdb.dll]  [Tencent Inc., 1, 0, 0, 1]
  446.     [D:\Program Files\Foxmail\Skin\TXScrollbar.dll]  [N/A, ]
  447.     [C:\Program Files\AVAST Software\Avast\ashShell.dll]  [AVAST Software, 8.0.1489.300]
  448.     [D:\Program Files\Foxmail\libeay32.dll]  [N/A, ]
  449.     [D:\Program Files\Foxmail\ssleay32.dll]  [N/A, ]
  450. [PID: 3992 / Administrator][D:\Program Files\StrokeIt\strokeit.exe]  [, Pro .9.7]
  451.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  452.     [D:\Program Files\StrokeIt\Plugins\exec.dll]  [N/A, ]
  453.     [D:\Program Files\StrokeIt\Plugins\keys.dll]  [N/A, ]
  454.     [D:\Program Files\StrokeIt\Plugins\msg.dll]  [N/A, ]
  455.     [D:\Program Files\StrokeIt\Plugins\multimon.dll]  [N/A, ]
  456.     [D:\Program Files\StrokeIt\Plugins\OSD.dll]  [N/A, ]
  457.     [D:\Program Files\StrokeIt\Plugins\siControl.dll]  [N/A, ]
  458.     [D:\Program Files\StrokeIt\Plugins\utilities.dll]  [N/A, ]
  459.     [D:\Program Files\StrokeIt\Plugins\win.dll]  [N/A, ]
  460.     [D:\Program Files\StrokeIt\mhook.dll]  [N/A, ]
  461. [PID: 3728 / Administrator][D:\Program Files\DesktopSprite2\DesktopSprite.exe]  [SnowFox Studio., 2.5.3.52]
  462.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  463. [PID: 3964 / Administrator][D:\Program Files\Tencent\RTXC\RTX.exe]  [TENCENT, 8.1.446.202]
  464.     [D:\Program Files\Tencent\RTXC\UIU.dll]  [Tencent, 4,0,0,55]
  465.     [D:\Program Files\Tencent\RTXC\Localization.dll]  [, 1, 0, 0, 1]
  466.     [D:\Program Files\Tencent\RTXC\HelperU.dll]  [, 1, 0, 0, 1]
  467.     [D:\Program Files\Tencent\RTXC\Crypt.dll]  [N/A, ]
  468.     [D:\Program Files\Tencent\RTXC\TBarDll.dll]  [, 1, 0, 0, 1]
  469.     [D:\Program Files\Tencent\RTXC\InfoSvrApi.dll]  [, 1, 0, 0, 1]
  470.     [D:\Program Files\Tencent\RTXC\OutSupportNW.dll]  [, 1, 0, 0, 1]
  471.     [D:\Program Files\Tencent\RTXC\RTXRes.dll]  [N/A, ]
  472.     [D:\Program Files\Tencent\RTXC\MainFrameRes.dll]  [, 1, 0, 0, 1]
  473.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  474.     [D:\Program Files\Tencent\RTXC\NewSkin.dll]  [, 1, 0, 0, 1]
  475.     [D:\PROGRA~1\Tencent\RTXC\RTXImage.ocx]  [tencent, 1, 0, 0, 1]
  476.     [D:\Program Files\Tencent\RTXC\rtxcapi.dll]  [, 1, 0, 0, 1]
  477.     [D:\Program Files\Tencent\RTXC\RTXNetClient.dll]  [, 1, 0, 0, 1]
  478.     [D:\Program Files\Tencent\RTXC\StoreComp.dll]  [, 1, 0, 0, 1]
  479.     [D:\Program Files\Tencent\RTXC\rtxstore.dll]  [, 1, 0, 0, 1]
  480.     [D:\Program Files\Tencent\RTXC\sqlite3.dll]  [N/A, ]
  481.     [D:\Program Files\Tencent\RTXC\RTXP2P.dll]  [, 1, 0, 0, 1]
  482.     [D:\Program Files\Tencent\RTXC\P2P.Dll]  [, 1, 0, 0, 1]
  483.     [D:\Program Files\Tencent\RTXC\QQNW.dll]  [, 1, 0, 0, 1]
  484.     [D:\Program Files\Tencent\RTXC\SessionClient.dll]  [, 1, 0, 0, 1]
  485.     [D:\Program Files\Tencent\RTXC\DisGroup.dll]  [, 1, 0, 0, 1]
  486.     [D:\Program Files\Tencent\RTXC\RTXCPro.dll]  [, 1, 0, 0, 1]
  487.     [D:\Program Files\Tencent\RTXC\BqqZip.dll]  [N/A, ]
  488.     [D:\Program Files\Tencent\RTXC\ClientObjects.dll]  [, 1, 0, 0, 1]
  489.     [D:\Program Files\Tencent\RTXC\RTXCSDK.dll]  [, 1, 0, 0, 1]
  490.     [D:\Program Files\Tencent\RTXC\FileTransfer.dll]  [, 1, 0, 0, 1]
  491.     [D:\Program Files\Tencent\RTXC\FileCom.dll]  [Tencent, 4,0,0,7]
  492.     [D:\Program Files\Tencent\RTXC\OrgStruct.dll]  [, 1, 0, 0, 1]
  493.     [D:\Program Files\Tencent\RTXC\IM.dll]  [, 1, 0, 0, 1]
  494.     [D:\Program Files\Tencent\RTXC\RTXSMS.dll]  [, 1, 0, 0, 1]
  495.     [D:\Program Files\Tencent\RTXC\LocalTabManager.dll]  [, 1, 0, 0, 1]
  496.     [D:\Program Files\Tencent\RTXC\OffMsgModule.dll]  [, 1, 0, 0, 1]
  497.     [D:\Program Files\Tencent\RTXC\Config.dll]  [, 1, 0, 0, 1]
  498.     [D:\Program Files\Tencent\RTXC\Watcher.dll]  [, 1, 0, 0, 1]
  499.     [D:\Program Files\Tencent\RTXC\ClientRightMgr.dll]  [, 1, 0, 0, 1]
  500.     [D:\Program Files\Tencent\RTXC\TAPD.dll]  [, 1, 0, 0, 1]
  501.     [D:\Program Files\Tencent\RTXC\RCAStoreComp.dll]  [, 1, 0, 0, 1]
  502.     [D:\Program Files\Tencent\RTXC\RCAModule.dll]  [, 1, 0, 0, 1]
  503.     [D:\Program Files\Tencent\RTXC\RCAIM.dll]  [, 1, 0, 0, 1]
  504.     [D:\Program Files\Tencent\RTXC\RCAUserProfile.dll]  [, 1, 0, 0, 1]
  505.     [D:\Program Files\Tencent\RTXC\EPortal.dll]  [, 1, 0, 0, 1]
  506.     [D:\Program Files\Tencent\RTXC\RTXLogin.dll]  [, 1, 0, 0, 1]
  507.     [D:\PROGRA~1\Tencent\RTXC\RTXOrg.ocx]  [, 1, 0, 0, 1]
  508.     [D:\Program Files\Tencent\RTXC\UserSelector.dll]  [, 1, 0, 0, 1]
  509.     [D:\Program Files\Tencent\RTXC\UserProfile.dll]  [, 1, 0, 0, 1]
  510.     [D:\PROGRA~1\Tencent\RTXC\RTXMOB~1.OCX]  [MS User, 1, 0, 0, 1]
  511.     [D:\Program Files\Tencent\RTXC\RTXOLAss.dll]  [Tencent, 1, 0, 0, 1]
  512.     [D:\Program Files\Tencent\RTXC\UpdateModule.dll]  [, 1, 0, 0, 1]
  513.     [D:\Program Files\Tencent\RTXC\SearchUsers.dll]  [, 1, 0, 0, 1]
  514.     [D:\Program Files\Tencent\RTXC\Alert.dll]  [, 1, 0, 0, 1]
  515.     [D:\Program Files\Tencent\RTXC\BroadCast.dll]  [, 1, 0, 0, 1]
  516.     [D:\Program Files\Tencent\RTXC\Plugins\bizmailclient\ExMailClient.dll]  [, 1, 0, 0, 8]
  517.     [D:\Program Files\Tencent\RTXC\UserDefineWizard.dll]  [, 1, 0, 0, 1]
  518.     [D:\Program Files\Tencent\RTXC\RTXPhone.dll]  [, 1, 0, 0, 1]
  519.     [D:\Program Files\Tencent\RTXC\RTXPluginMgr.dll]  [, 1, 0, 0, 1]
  520.     [D:\Program Files\Tencent\RTXC\AddRCAUser.dll]  [, 1, 0, 0, 1]
  521.     [D:\Program Files\Tencent\RTXC\ImExtraInfo.dll]  [, 2, 1, 0, 15]
  522.     [D:\Program Files\Tencent\RTXC\rtxskin.dll]  [Tencent, 3,4,0,32]
  523.     [D:\PROGRA~1\Tencent\RTXC\Plugins\BIZMAI~1\config\Setting.ocx]  [, 1, 0, 0, 3]
  524.     [C:\Program Files\AVAST Software\Avast\ashShell.dll]  [AVAST Software, 8.0.1489.300]
  525. [PID: 2036 / NETWORK SERVICE][C:\Program Files\Windows Media Player\wmpnetwk.exe]  [Microsoft Corporation, 12.0.7600.16385 (win7_rtm.090713-1255)]
  526. [PID: 2580 / LOCAL SERVICE][C:\Windows\system32\WUDFHost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  527. [PID: 1568 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)]
  528.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  529. [PID: 3380 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)]
  530.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  531.     [C:\Windows\system32\nvd3dum.dll]  [NVIDIA Corporation, 8.17.12.6300]
  532.     [C:\Windows\system32\Macromed\Flash\Flash32_11_7_700_202.ocx]  [Adobe Systems, Inc., 11,7,700,202]
  533. [PID: 5492 / Administrator][C:\Program Files\Microsoft Office\Office12\EXCEL.EXE]  [Microsoft Corporation, 12.0.4518.1014]
  534.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  535.     [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSDNT5UI.DLL]  [Zenographics, Inc., 0, 3, 2911, 1]
  536.     [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSDDM.DLL]  [Zenographics, Inc., 6, 20, 1611, 0]
  537.     [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSPOOL.dll]  [Zenographics, Inc., 6, 1, 1, 0]
  538.     [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZGDI.dll]  [Zenographics, Inc., 5, 60, 709, 0]
  539.     [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZTAG.dll]  [Zenographics, Inc., 5, 60, 1210, 0]
  540.     [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSDDMUI.DLL]  [Zenographics, Inc., 6, 2, 411, 0]
  541.     [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZSR.dll]  [Zenographics, Inc., 6, 20, 1625, 0]
  542.     [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZIMFDRV.DLL]  [Zenographics, Inc., 0, 3, 5209, 0]
  543.     [C:\Windows\system32\spool\DRIVERS\W32X86\3\ZIMF.dll]  [Zenographics, Inc., 5, 70, 616, 0]
  544.     [C:\Program Files\AVAST Software\Avast\ashShell.dll]  [AVAST Software, 8.0.1489.300]
  545.     [C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL]  [, ]
  546.     [C:\Program Files\Microsoft Office\Office12\USP10.DLL]  [Microsoft Corporation, 1.0626.5756.0 (vista_rtm.061008-1400)]
  547. [PID: 5412 / Administrator][D:\Program Files\Thunder\Program\Thunder.exe]  [深圳市迅雷网络技术有限公司, 7,2,90,92]
  548.     [D:\Program Files\Thunder\Program\XLUE.dll]  [深圳市迅雷网络技术有限公司, 0.9.0.422]
  549.     [D:\Program Files\Thunder\Program\XLGraphic.dll]  [深圳市迅雷网络技术有限公司, 0.9.0.422]
  550.     [D:\Program Files\Thunder\Program\libpng13.dll]  [, 1.2.38]
  551.     [D:\Program Files\Thunder\Program\zlib1.dll]  [, 1.2.5]
  552.     [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
  553.     [D:\Program Files\Thunder\Program\MSIMG32.dll]  [N/A, ]
  554.     [D:\Program Files\Thunder\Program\XLFSIO.dll]  [深圳市迅雷网络技术有限公司, 0.9.0.422]
  555.     [C:\Windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.6030.0]
  556.     [D:\Program Files\Thunder\Program\XLLuaRuntime.dll]  [深圳市迅雷网络技术有限公司, 0.9.0.412]
  557.     [D:\Program Files\Thunder\Program\ATL71.DLL]  [Microsoft Corporation, 7.10.6101.0]
  558.     [D:\Program Files\Thunder\Program\libexpat.dll]  [N/A, ]
  559.     [D:\Program Files\Thunder\Program\XLBugHandler.dll]  [, 2, 2, 0, 11]
  560.     [D:\Program Files\Thunder\Program\minizip.dll]  [, 1, 0, 0, 1]
  561.     [D:\Program Files\Thunder\Program\XLIPC.dll]  [N/A, ]
  562.     [D:\Program Files\Thunder\Program\xlstat.dll]  [深圳市迅雷网络技术有限公司, 2.0.2.10]
  563.     [D:\Program Files\Thunder\Program\InstallProtect.dll]  [N/A, ]
  564.     [D:\Program Files\Thunder\Program\sqlite3.dll]  [, 3, 6, 22, 0]
  565.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  566.     [D:\Program Files\Thunder\Program\xl_data.dll]  [深圳市迅雷网络技术有限公司, 1, 12, 5, 38]
  567.     [D:\Program Files\Thunder\Program\DownloadKernel.dll]  [深圳市迅雷网络技术有限公司, 7,2,90,92]
  568.     [D:\Program Files\Thunder\Program\asyn_download_interface.dll]  [深圳市迅雷网络技术有限公司, 1,1,2,54]
  569.     [D:\Program Files\Thunder\Program\tp_proxy.dll]  [深圳市迅雷网络技术有限公司, 1, 0,  2,  22]
  570.     [C:\Program Files\AVAST Software\Avast\ashShell.dll]  [AVAST Software, 8.0.1489.300]
  571.     [D:\Program Files\Thunder\Program\XLUserAX.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 84]
  572.     [D:\Program Files\Thunder\Program\dl_peer_id.dll]  [深圳市迅雷网络技术有限公司, 3, 2,  2,  17]
  573.     [D:\Program Files\Thunder\Program\BaseCommunity.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 186]
  574.     [D:\Program Files\Thunder\Program\xl_client.dll]  [深圳市迅雷网络技术有限公司, 1, 14, 2, 35]
  575.     [D:\Program Files\Thunder\Program\asyn_frame.dll]  [深圳市迅雷网络技术有限公司, 1,6,2,22]
  576.     [D:\Program Files\Thunder\Program\dl_uac_tool.dll]  [N/A, ]
  577.     [D:\Program Files\Thunder\Program\mp.dll]  [深圳市迅雷网络技术有限公司, 1, 1,  2,  10]
  578.     [D:\Program Files\Thunder\Addins\Community\XLCPAddinManager.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 21]
  579.     [D:\Program Files\Thunder\Addins\community\Community.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 113]
  580.     [D:\Program Files\Thunder\Addins\VipService\VipService.dll]  [Thunder Networking Technologies,LTD, 1, 1, 2, 391]
  581.     [D:\Program Files\Thunder\Program\Win7Trait.dll]  [N/A, ]
  582. [PID: 5236 / Administrator][D:\Program Files\Thunder\Program\ThunderPlatform.exe]  [深圳市迅雷网络技术有限公司, 1, 1,  2,  124]
  583.     [D:\Program Files\Thunder\Program\minizip.dll]  [, 1, 0, 0, 1]
  584.     [D:\Program Files\Thunder\Program\zlib1.dll]  [, 1.2.5]
  585.     [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
  586.     [C:\Windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.6030.0]
  587.     [D:\Program Files\Thunder\Program\xlbughandler.dll]  [, 2, 2, 0, 11]
  588.     [D:\Program Files\Thunder\Program\dl_uac_tool.dll]  [N/A, ]
  589.     [D:\Program Files\Thunder\Program\download_engine.dll]  [深圳市迅雷网络技术有限公司, 3, 7,  2,  20]
  590.     [D:\Program Files\Thunder\Program\mp.dll]  [深圳市迅雷网络技术有限公司, 1, 1,  2,  10]
  591.     [D:\Program Files\Thunder\Program\XLCrypto.dll]  [N/A, ]
  592.     [D:\Program Files\Thunder\Program\asyn_frame.dll]  [深圳市迅雷网络技术有限公司, 1,6,2,22]
  593.     [D:\Program Files\Thunder\Program\ts.dll]  [深圳市迅雷网络技术有限公司, 1,1,2,35]
  594.     [D:\Program Files\Thunder\Program\ta.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 105]
  595.     [D:\Program Files\Thunder\Program\ATL71.DLL]  [Microsoft Corporation, 7.10.6101.0]
  596.     [D:\Program Files\Thunder\Program\xl_data.dll]  [深圳市迅雷网络技术有限公司, 1, 12, 5, 38]
  597.     [D:\Program Files\Thunder\Program\XLLuaRuntime.dll]  [深圳市迅雷网络技术有限公司, 0.9.0.412]
  598.     [D:\Program Files\Thunder\Program\XLFSIO.dll]  [深圳市迅雷网络技术有限公司, 0.9.0.422]
  599.     [D:\Program Files\Thunder\Program\libexpat.dll]  [N/A, ]
  600.     [D:\Program Files\Thunder\Program\xl_client.dll]  [深圳市迅雷网络技术有限公司, 1, 14, 2, 35]
  601.     [D:\Program Files\Thunder\Program\backend_agent.dll]  [深圳市迅雷网络技术有限公司, 1, 2,  2,  68]
  602.     [D:\Program Files\Thunder\Program\ptl.dll]  [深圳市迅雷网络技术有限公司, 3, 3,  2,  123]
  603.     [D:\Program Files\Thunder\Program\dl_peer_id.dll]  [深圳市迅雷网络技术有限公司, 3, 2,  2,  17]
  604.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  605.     [D:\Program Files\Thunder\Program\MSIMG32.dll]  [N/A, ]
  606.     [D:\Program Files\Thunder\Program\fs.dll]  [深圳市迅雷网络技术有限公司, 1, 3,  2,  11]
  607.     [D:\Program Files\Thunder\Program\al.dll]  [深圳市迅雷网络技术有限公司, 1, 3,  2,  114]
  608.     [D:\Program Files\Thunder\Program\p2p_upload.dll]  [深圳市迅雷网络技术有限公司, 1, 2,  2,  32]
  609.     [D:\Program Files\Thunder\Program\down_dispatcher.dll]  [深圳市迅雷网络技术有限公司, 1, 2,  2,  143]
  610.     [D:\Program Files\Thunder\Program\p2p.dll]  [深圳市迅雷网络技术有限公司, 1, 2,  2,  186]
  611.     [D:\Program Files\Thunder\Program\p2p_local_res.dll]  [深圳市迅雷网络技术有限公司, 1, 2,  2,  31]
  612.     [D:\Program Files\Thunder\Program\bt_kernel.dll]  [深圳市迅雷网络技术有限公司, 1, 2,  2, 90]
  613.     [D:\Program Files\Thunder\Program\emule_kernel.dll]  [深圳市迅雷网络技术有限公司, 1, 4,  2,  21]
  614.     [D:\Program Files\Thunder\Program\p2sp.dll]  [深圳市迅雷网络技术有限公司, 1, 3,  2,  226]
  615. [PID: 4872 / Administrator][Z:\Program Files\opera10\Opera.exe]  [Opera Software, 1893]
  616.     [Z:\Program Files\opera10\Opera.dll]  [Opera Software, 1893]
  617.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  618.     [C:\Program Files\AVAST Software\Avast\ashShell.dll]  [AVAST Software, 8.0.1489.300]
  619. [PID: 1700 / Administrator][D:\Program Files\雨林木风工具箱\实用软件\FastStone Capture.exe]  [N/A, ]
  620.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  621.     [D:\Program Files\StrokeIt\mhook.dll]  [N/A, ]
  622.     [C:\Program Files\AVAST Software\Avast\ashShell.dll]  [AVAST Software, 8.0.1489.300]
  623. [PID: 1384 / Administrator][D:\Program Files\雨林木风工具箱\杀毒防毒\sreng2\SREngLdr.EXE]  [Smallfrogs Studio, 2.8.4.1331]
  624. [PID: 5196 / Administrator][D:\Program Files\雨林木风工具箱\杀毒防毒\sreng2\SREbf4b2b31.EXE]  [Smallfrogs Studio, 2.8.4.1331]
  625.     [C:\Windows\system32\freeime.ime]  [极点五笔工作室, 6.5.0.0]
  626.     [D:\Program Files\StrokeIt\mhook.dll]  [N/A, ]
  627.     [D:\Program Files\雨林木风工具箱\杀毒防毒\sreng2\Plugins\FILEDSV.SRE]  [Smallfrogs Studio, 1, 1, 0, 20]
  628.     [D:\Program Files\雨林木风工具箱\杀毒防毒\sreng2\Plugins\NTFSTREAM.SRE]  [Smallfrogs Studio, 1, 0, 0, 5]
  629.     [D:\Program Files\雨林木风工具箱\杀毒防毒\sreng2\Plugins\NWMON.SRE]  [Smallfrogs Studio, 1, 0, 0, 8]
  630. [PID: 3624 / SYSTEM][C:\Windows\system32\SearchFilterHost.exe]  [(Verified) Microsoft Corporation, 7.00.7601.17610 (win7sp1_gdr.110503-1502)]

  631. ==================================
  632. 文件关联
  633. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  634. .EXE  OK. ["%1" %*]
  635. .COM  OK. ["%1" %*]
  636. .PIF  OK. ["%1" %*]
  637. .REG  OK. [regedit.exe "%1"]
  638. .BAT  OK. ["%1" %*]
  639. .SCR  OK. ["%1" /S]
  640. .CHM  OK. ["%SystemRoot%\hh.exe" %1]
  641. .HLP  OK. [%SystemRoot%\winhlp32.exe %1]
  642. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  643. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  644. .VBS  OK. ["%SystemRoot%\System32\WScript.exe" "%1" %*]
  645. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  646. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  647. ==================================
  648. Winsock 提供者
  649. N/A

  650. ==================================
  651. Autorun.inf
  652. N/A

  653. ==================================
  654. HOSTS 文件
  655. N/A

  656. ==================================
  657. 进程特权扫描
  658. N/A

  659. ==================================
  660. 计划任务
  661. [已启用] \\Adobe Flash Player Updater
  662.         C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
  663. [已禁用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
  664.         N/A
  665. [已启用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
  666.         N/A
  667. [已禁用] \Microsoft\Windows\AppID\PolicyConverter
  668.         %windir%\system32\appidpolicyconverter.exe
  669. [已禁用] \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
  670.         %windir%\system32\appidcertstorecheck.exe
  671. [已启用] \Microsoft\Windows\Application Experience\AitAgent
  672.         aitagent
  673. [已启用] \Microsoft\Windows\Application Experience\ProgramDataUpdater
  674.         %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate
  675. [已启用] \Microsoft\Windows\Autochk\Proxy
  676.         %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
  677. [已启用] \Microsoft\Windows\Bluetooth\UninstallDeviceTask
  678.         BthUdTask.exe $(Arg0)
  679. [已启用] \Microsoft\Windows\CertificateServicesClient\SystemTask
  680.         N/A
  681. [已启用] \Microsoft\Windows\CertificateServicesClient\UserTask
  682.         N/A
  683. [已禁用] \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
  684.         N/A
  685. [已启用] \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
  686.         %SystemRoot%\System32\wsqmcons.exe
  687. [已启用] \Microsoft\Windows\Defrag\ScheduledDefrag
  688.         %windir%\system32\defrag.exe -c
  689. [已启用] \Microsoft\Windows\Location\Notifications
  690.         %windir%\System32\LocationNotifications.exe
  691. [已启用] \Microsoft\Windows\Maintenance\WinSAT
  692.         N/A
  693. [已启用] \Microsoft\Windows\Media Center\ActivateWindowsSearch
  694.         %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
  695. [已启用] \Microsoft\Windows\Media Center\ConfigureInternetTimeService
  696.         %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
  697. [已启用] \Microsoft\Windows\Media Center\DispatchRecoveryTasks
  698.         %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
  699. [已启用] \Microsoft\Windows\Media Center\ehDRMInit
  700.         %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
  701. [已启用] \Microsoft\Windows\Media Center\InstallPlayReady
  702.         %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
  703. [已启用] \Microsoft\Windows\Media Center\mcupdate
  704.         %SystemRoot%\ehome\mcupdate $(Arg0)
  705. [已启用] \Microsoft\Windows\Media Center\MediaCenterRecoveryTask
  706.         %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
  707. [已启用] \Microsoft\Windows\Media Center\MediaCenterRecoveryTask
  708.         %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
  709. [已启用] \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
  710.         %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
  711. [已启用] \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
  712.         %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
  713. [已启用] \Microsoft\Windows\Media Center\OCURActivate
  714.         %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
  715. [已启用] \Microsoft\Windows\Media Center\OCURDiscovery
  716.         %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
  717. [已启用] \Microsoft\Windows\Media Center\PBDADiscovery
  718.         %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
  719. [已启用] \Microsoft\Windows\Media Center\PBDADiscoveryW1
  720.         %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
  721. [已启用] \Microsoft\Windows\Media Center\PBDADiscoveryW2
  722.         %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
  723. [已禁用] \Microsoft\Windows\Media Center\PeriodicScanRetry
  724.         %windir%\ehome\MCUpdate.exe -pscn 0
  725. [已启用] \Microsoft\Windows\Media Center\PvrRecoveryTask
  726.         %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
  727. [已启用] \Microsoft\Windows\Media Center\PvrRecoveryTask
  728.         %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
  729. [已启用] \Microsoft\Windows\Media Center\PvrScheduleTask
  730.         %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
  731. [已启用] \Microsoft\Windows\Media Center\PvrScheduleTask
  732.         %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
  733. [已禁用] \Microsoft\Windows\Media Center\RecordingRestart
  734.         %SystemRoot%\ehome\ehrec /RestartRecording
  735. [已启用] \Microsoft\Windows\Media Center\RegisterSearch
  736.         %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
  737. [已启用] \Microsoft\Windows\Media Center\ReindexSearchRoot
  738.         %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
  739. [已启用] \Microsoft\Windows\Media Center\SqlLiteRecoveryTask
  740.         %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
  741. [已启用] \Microsoft\Windows\Media Center\SqlLiteRecoveryTask
  742.         %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
  743. [已启用] \Microsoft\Windows\Media Center\UpdateRecordPath
  744.         %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
  745. [已启用] \Microsoft\Windows\MobilePC\HotStart
  746.         N/A
  747. [已启用] \Microsoft\Windows\MUI\LPRemove
  748.         %windir%\system32\lpremove.exe
  749. [已启用] \Microsoft\Windows\Multimedia\SystemSoundsService
  750.         N/A
  751. [已启用] \Microsoft\Windows\NetTrace\GatherNetworkInfo
  752.         %windir%\system32\gatherNetworkInfo.vbs
  753. [已禁用] \Microsoft\Windows\Offline Files\Background Synchronization
  754.         N/A
  755. [已禁用] \Microsoft\Windows\Offline Files\Logon Synchronization
  756.         N/A
  757. [已启用] \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
  758.         %SystemRoot%\System32\powercfg.exe -energy -auto
  759. [已启用] \Microsoft\Windows\Ras\MobilityManager
  760.         N/A
  761. [已禁用] \Microsoft\Windows\SideShow\AutoWake
  762.         N/A
  763. [已启用] \Microsoft\Windows\SideShow\GadgetManager
  764.         N/A
  765. [已禁用] \Microsoft\Windows\SideShow\SessionAgent
  766.         N/A
  767. [已禁用] \Microsoft\Windows\SideShow\SystemDataProviders
  768.         N/A
  769. [已禁用] \Microsoft\Windows\SystemRestore\SR
  770.         %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
  771. [已启用] \Microsoft\Windows\Tcpip\IpAddressConflict1
  772.         %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
  773. [已启用] \Microsoft\Windows\Tcpip\IpAddressConflict2
  774.         %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
  775. [已启用] \Microsoft\Windows\Time Synchronization\SynchronizeTime
  776.         %windir%\system32\sc.exe start w32time task_started
  777. [已启用] \Microsoft\Windows\UPnP\UPnPHostConfig
  778.         sc.exe config upnphost start= auto
  779. [已禁用] \Microsoft\Windows\User Profile Service\HiveUploadTask
  780.         N/A
  781. [已启用] \Microsoft\Windows\Windows Error Reporting\QueueReporting
  782.         %windir%\system32\wermgr.exe -queuereporting
  783. [已启用] \Microsoft\Windows\Windows Media Sharing\UpdateLibrary
  784.         "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
  785. [已启用] \Microsoft\Windows\WindowsBackup\ConfigNotification
  786.         %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
  787. [已禁用] \Microsoft\Windows\WindowsColorSystem\Calibration Loader
  788.         N/A

  789. ==================================
  790. Windows 安全更新检查
  791. N/A

  792. ==================================
  793. API HOOK
  794. N/A

  795. ==================================
  796. 隐藏进程
  797. N/A

  798. ==================================


复制代码

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
z2009
发表于 2013-5-31 08:41:21 | 显示全部楼层
eav拦截
yejian9237
发表于 2013-5-31 08:51:23 | 显示全部楼层


最好发往样本区,再链接过来

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
CIA
发表于 2013-5-31 09:30:27 | 显示全部楼层
根据我的    分析    你中毒了
maomao110
发表于 2013-5-31 09:38:55 | 显示全部楼层
去样本区求助吧
sdupyb
发表于 2013-5-31 10:27:55 | 显示全部楼层
镇楼

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
mikefan21
发表于 2013-5-31 10:39:12 | 显示全部楼层
这是一个系统漏洞攻击,打补丁,装防火墙
辽宁大连~~小海
发表于 2013-5-31 14:22:38 | 显示全部楼层
360报毒
wefiwhfve
发表于 2013-5-31 15:03:53 | 显示全部楼层
sdupyb 发表于 2013-5-31 10:27
镇楼

我看到,,这个网站声誉极差
留侯
发表于 2013-5-31 16:07:34 | 显示全部楼层
大蜘蛛侦测到是高级蠕虫病毒:
样本\rundl132.exe - infected with Win32.HLLW.Gavir.54
样本\logo1_.exe - infected with Win32.HLLW.Gavir.54

我没有找到大蜘蛛对此病毒的定义,但是包含有对应其他反病毒软件对此病毒的名称定义:
http://vms.drweb.com/search/?q=Win32.HLLW.Gavir.54
建议楼主使用Dr.Web CureIt!执行一下全盘扫描吧!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-17 13:36 , Processed in 0.167013 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表