RT
每次重启都是这样,做系统恢复也是一样,现附上系统日志,请高手指教!
- 2002-01-01,01:57:43
- System Repair Engineer 2.5.16.900
- Smallfrogs (http://www.KZTechs.com)
- Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
- 以下内容被选中:
- 所有的启动项目(包括注册表、启动文件夹、服务等)
- 浏览器加载项
- 正在运行的进程(包括进程模块信息)
- 文件关联
- Winsock 提供者
- Autorun.inf
- HOSTS 文件
- 进程特权扫描
- 启动项目
- 注册表
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
- <联想认证><C:\Program Files\联想网络\802.1x客户端软件\1xClient.exe> []
- [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <load><> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- <avgnt><"C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min> [Avira GmbH]
- <360Safetray><C:\Program Files\360safe\safemon\360Tray.exe /start> [奇虎网]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
- <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <AppInit_DLLs><> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
- ==================================
- 启动文件夹
- N/A
- ==================================
- 服务
- [AntiVir PersonalEdition Classic Scheduler / AntiVirScheduler][Running/Auto Start]
- <C:\Program Files\AntiVir PersonalEdition Classic\sched.exe><Avira GmbH>
- [AntiVir PersonalEdition Classic Guard / AntiVirService][Running/Auto Start]
- <C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe><Avira GmbH>
- [Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
- <C:\WINDOWS\system32\Ati2evxx.exe><>
- [ATI Smart / ATI Smart][Stopped/Auto Start]
- <C:\WINDOWS\system32\ati2sgag.exe><>
- [Human Interface Device Access / HidServ][Stopped/Disabled]
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
- ==================================
- 驱动程序
- [Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
- <system32\drivers\ALCXSENS.SYS><Sensaura>
- [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
- <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
- [ati2mtag / ati2mtag][Running/Manual Start]
- <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
- [avgio / avgio][Running/System Start]
- <\??\C:\Program Files\AntiVir PersonalEdition Classic\avgio.sys><Avira GmbH>
- [avgntflt / avgntflt][Running/Manual Start]
- <\??\C:\Program Files\AntiVir PersonalEdition Classic\avgntflt.sys><Avira GmbH>
- [GMSIPCI / GMSIPCI][Stopped/Manual Start]
- <\??\H:\INSTALL\GMSIPCI.SYS><N/A>
- [Netgroup Packet Filter / NPF][Running/Manual Start]
- <system32\drivers\npf.sys><Politecnico di Torino>
- [Service for NVIDIA(R) nForce(TM) Audio Enumerator / nvax][Stopped/Manual Start]
- <system32\drivers\nvax.sys><NVIDIA Corporation>
- [NVIDIA nForce MCP Networking Controller Driver / NVENET][Running/Manual Start]
- <system32\DRIVERS\NVENET.sys><NVIDIA Corporation>
- [Service for NVIDIA(R) nForce(TM) Audio / nvnforce][Stopped/Manual Start]
- <system32\drivers\nvapu.sys><NVIDIA Corporation>
- [NVIDIA nForce AGP Bus Filter / nv_agp][Running/Boot Start]
- <\SystemRoot\system32\DRIVERS\nv_agp.sys><NVIDIA Corporation>
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
- [Secdrv / Secdrv][Stopped/Manual Start]
- <system32\DRIVERS\secdrv.sys><N/A>
- ==================================
- 浏览器加载项
- [NavigatMon Class]
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 奇虎网>
- [Recorder Control]
- {2423AB16-9F42-457B-A337-FE3B11964DB0} <C:\PROGRA~1\bluesky\BLUESK~1\recorder.ocx, Bluesky Studio (http://www.bluesky.cn)>
- [BlueskyVideo Control]
- {2EA6D939-4445-43F1-A12B-8CB3DDA8B855} <C:\PROGRA~1\bluesky\BLUESK~1\v2.ocx, Bluesky Studio (http://www.bluesky.cn)>
- [Ppd Control]
- {2F2BA87D-385E-4922-B41C-06E190B06AA9} <C:\PROGRA~1\bluesky\BLUESK~1\ppd.ocx, Bluesky Studio(http://www.bluesky.cn)>
- [Share Control]
- {3072B1F1-0C4D-4E76-A7C6-FBAF129DBCC9} <C:\PROGRA~1\bluesky\BLUESK~1\share.ocx, Bluesky Studio(http://www.bluesky.cn)>
- [Traceppd Control]
- {5910C66C-F9BA-4306-8175-C098B7F0ED62} <C:\PROGRA~1\bluesky\BLUESK~1\traceppd.ocx, BlueskyStudio(http://www.bluesky.cn)>
- [PP Control]
- {616DACC1-C5E6-4646-B36A-3FA4FC726BAD} <C:\PROGRA~1\bluesky\BLUESK~1\ppc.ocx, Bluesky Studio (http://www.bluesky.cn)>
- [Windows Media Player]
- {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
- [WBEM Scripting Sink]
- {75718C9A-F029-11D1-A1AC-00C04FB6C223} <C:\WINDOWS\system32\wbem\wbemdisp.dll, Microsoft Corporation>
- [Videohelp Control]
- {75B75D86-D88B-4BEA-BC59-BFD9D7300518} <C:\PROGRA~1\bluesky\BLUESK~1\VIDEOH~1.OCX, Bluesky Studio(http://www.bluesky.cn)>
- [WBEM Scripting Locator]
- {76A64158-CB41-11D1-8B02-00600806D9B6} <C:\WINDOWS\system32\wbem\wbemdisp.dll, Microsoft Corporation>
- [360SafeLive]
- {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360safe.com>
- [Microsoft Web 浏览器]
- {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
- [Filetran Control]
- {88734439-46D0-42C0-A13F-7E881EE550CF} <C:\PROGRA~1\bluesky\BLUESK~1\filetran.ocx, Bluesky Studio(http://www.bluesky.cn)>
- [Chat Control]
- {94EFE58C-E678-4808-AD65-24CE4B94C1FE} <C:\PROGRA~1\bluesky\BLUESK~1\chat.ocx, Bluesky Studio(http://www.bluesky.cn)>
- [Blueskyvoice Control]
- {991481A7-4669-4e15-8C24-100404E1F5CB} <C:\PROGRA~1\bluesky\BLUESK~1\BLUESK~1.OCX, Bluesky Studio (http://www.bluesky.cn)>
- [Display Control]
- {A1D97DB3-E564-4743-B2E7-6F5182CBF406} <C:\PROGRA~1\bluesky\BLUESK~1\display.ocx, Bluesky Studio (http://www.bluesky.cn)>
- [Tracechat Control]
- {A40335C4-D3D1-4E7B-9130-039CDA5B603C} <C:\PROGRA~1\bluesky\BLUESK~1\TRACEC~1.OCX, Bluesky Studio(http://www.bluesky.cn)>
- [PPChat Control]
- {AFB97F16-B7E8-4EB1-8133-FBD5AA2EBB3B} <C:\PROGRA~1\bluesky\BLUESK~1\ppchat.ocx, Bluesky Studio(http://www.bluesky.cn)>
- [NavigatMon Class]
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 奇虎网>
- [Blueskyvoice Control]
- {BA0F088C-72C1-475a-92F8-42391DEF6961} <C:\PROGRA~1\bluesky\BLUESK~1\BLUESK~2.OCX, 蓝天工作室(http://www.bluesky.cn)>
- [RDS.DataSpace]
- {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
- [Client Control]
- {C7B0C764-5D4E-433E-A854-591F28520577} <C:\PROGRA~1\bluesky\BLUESK~1\client.ocx, BlueskyStudio(http://www.bluesky.cn)>
- [Play Control]
- {CC20DDA1-9A21-4DEC-B5BE-E61E0351FCA9} <C:\PROGRA~1\bluesky\BLUESK~1\play.ocx, Bluesky Studio (http://www.bluesky.cn)>
- [Shockwave Flash Object]
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
- [导出到 Microsoft Office Excel(&X)]
- <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
- ==================================
- 正在运行的进程
- [PID: 384 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 640 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 664 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\Ati2evxx.dll] [, ]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 708 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 720 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 872 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [, ]
- [PID: 884 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 956 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1048 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1092 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1168 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1448 / yazi][C:\WINDOWS\system32\Ati2evxx.exe] [, ]
- [PID: 1520 / yazi][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
- [C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 1708 / yazi][C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe] [Avira GmbH, 7.02.00.16]
- [C:\Program Files\AntiVir PersonalEdition Classic\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
- [C:\Program Files\AntiVir PersonalEdition Classic\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
- [C:\Program Files\AntiVir PersonalEdition Classic\cclib.dll] [Avira GmbH, 7.02.00.03]
- [C:\Program Files\AntiVir PersonalEdition Classic\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
- [C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
- [c:\program files\antivir personaledition classic\ccgen.dll] [Avira GmbH, 7.02.00.10]
- [c:\program files\antivir personaledition classic\ccgenrc.dll] [Avira GmbH, 7.02.04.02]
- [c:\program files\antivir personaledition classic\ccguard.dll] [Avira GmbH, 7.00.01.35]
- [c:\program files\antivir personaledition classic\ccgrdrc.dll] [Avira GmbH, 7.00.06.00]
- [C:\Program Files\AntiVir PersonalEdition Classic\avipc.dll] [Avira GmbH, 1.00.00.04]
- [c:\program files\antivir personaledition classic\ccupdate.dll] [Avira GmbH, 7.02.00.04]
- [c:\program files\antivir personaledition classic\ccupdrc.dll] [Avira GmbH, 7.02.01.00]
- [c:\program files\antivir personaledition classic\cclic.dll] [Avira GmbH, 7.02.00.04]
- [c:\program files\antivir personaledition classic\cclicrc.dll] [Avira GmbH, 7.02.01.00]
- [c:\program files\antivir personaledition classic\ccmsg.dll] [Avira GmbH, 7.00.00.00]
- [PID: 1716 / yazi][C:\Program Files\360safe\safemon\360Tray.exe] [奇虎网, 3, 6, 4, 3002]
- [C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
- [C:\Program Files\360safe\safemon\SafeKrnl.dll] [奇虎网, 3, 6, 0, 1001]
- [C:\Program Files\360safe\AntiAdwa.dll] [360Safe.com, 3, 6, 3, 1001]
- [C:\Program Files\360safe\live.dll] [360safe.com, 1, 0, 1, 1021]
- [PID: 1724 / yazi][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1744 / yazi][C:\WINDOWS\system32\1xClient.dll] [联想网络, 2, 0, 0, 0]
- [C:\WINDOWS\system32\packet.dll] [Politecnico di Torino, 3, 0, 0, 18]
- [C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
- [PID: 1944 / SYSTEM][C:\Program Files\AntiVir PersonalEdition Classic\sched.exe] [Avira GmbH, 7.00.00.62]
- [C:\Program Files\AntiVir PersonalEdition Classic\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
- [C:\Program Files\AntiVir PersonalEdition Classic\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
- [C:\Program Files\AntiVir PersonalEdition Classic\schedr.dll] [Avira GmbH, 7.00.24.00]
- [C:\Program Files\AntiVir PersonalEdition Classic\avevtlog.dll] [Avira GmbH, 7.00.00.20]
- [C:\Program Files\AntiVir PersonalEdition Classic\sqlite3.dll] [, 3, 3, 17, 1]
- [C:\Program Files\AntiVir PersonalEdition Classic\avipc.dll] [Avira GmbH, 1.00.00.04]
- [PID: 1968 / SYSTEM][C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe] [Avira GmbH, 7.00.00.82]
- [C:\Program Files\AntiVir PersonalEdition Classic\avgio.dll] [Avira GmbH, 7.00.00.01]
- [C:\Program Files\AntiVir PersonalEdition Classic\avevtlog.dll] [Avira GmbH, 7.00.00.20]
- [C:\Program Files\AntiVir PersonalEdition Classic\guardmsg.dll] [Avira GmbH, 7.00.11.00]
- [C:\Program Files\AntiVir PersonalEdition Classic\sqlite3.dll] [, 3, 3, 17, 1]
- [C:\Program Files\AntiVir PersonalEdition Classic\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
- [C:\Program Files\AntiVir PersonalEdition Classic\AVPREF.DLL] [Avira GmbH, 7.00.02.02]
- [C:\Program Files\AntiVir PersonalEdition Classic\SMTPLIB.DLL] [Avira GmbH, 1.02.00.17]
- [C:\Program Files\AntiVir PersonalEdition Classic\AVPACK32.DLL] [Avira GmbH, 7.03.00.15]
- [C:\Program Files\AntiVir PersonalEdition Classic\unacev2.dll] [N/A, ]
- [C:\Program Files\AntiVir PersonalEdition Classic\AVEWIN32.DLL] [Avira GmbH, 7.6.0.34]
- [C:\Program Files\AntiVir PersonalEdition Classic\avipc.dll] [Avira GmbH, 1.00.00.04]
- [PID: 1488 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 188 / yazi][D:\QQ\QQ.exe] [TENCENT, 7,0,365,1701]
- [D:\QQ\QQBaseClassInDll.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\QQHelperDll.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\BasicCtrlDll.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
- [C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
- [D:\QQ\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
- [D:\QQ\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
- [D:\QQ\QQAPI.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
- [D:\QQ\LoginCtrl.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\LoginCtrlRes.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\QQRes.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\QQMainFrame.dll] [N/A, ]
- [D:\QQ\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
- [D:\QQ\CQQApplication.dll] [N/A, ]
- [D:\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]
- [D:\QQ\NewSkin.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\HostingMgr.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\CameraDll.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\MailSummary.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\QQKnowledgeSearch.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\QQAllInOne.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\SCCore.dll] [TENCENT, 1, 6, 0, 2]
- [D:\QQ\QQSpace.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\vbscript.dll] [N/A, ]
- [D:\QQ\aqing.dll] [Microsoft Corporation, 5.6.0.8825]
- [C:\WINDOWS\system32\msdmo.dll] [, ]
- [D:\QQ\QQGroupMng.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\QQSettingCtrl.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\QQSysMsgMng.dll] [N/A, ]
- [D:\QQ\UserDefinedHead.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\QQPlugin.dll] [N/A, ]
- [D:\QQ\QQConfigPlugin.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\QQAvatar.dll] [N/A, ]
- [D:\QQ\QQCustomFace.dll] [N/A, ]
- [D:\QQ\QRingMng.dll] [N/A, ]
- [D:\QQ\LongConnection.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\QQPet.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\ImageOle.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\QQLiveQMng.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\QQSceneMng.dll] [N/A, ]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [D:\QQ\OEMApplication.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\BQQApplication.dll] [N/A, ]
- [D:\QQ\QQMagicFace.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\CommercesMng.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
- [D:\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 320]
- [D:\QQ\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 1, 9, 97]
- [D:\QQ\GroupConnection.dll] [TENCENT, 7,0,365,1701]
- [D:\QQ\QQZip.dll] [TENCENT, 7,0,365,1701]
- [PID: 628 / yazi][D:\QQ\TIMPlatform.exe] [TENCENT, 7,0,365,1701]
- [C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
- [D:\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
- [PID: 1432 / yazi][D:\QQ\QZone\Qzone.exe] [腾讯公司, 1, 9, 103, 20]
- [D:\QQ\QZone\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
- [C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
- [PID: 276 / yazi][D:\系统工具\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
- [C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
- ==================================
- 文件关联
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .EXE OK. ["%1" %*]
- .COM OK. ["%1" %*]
- .PIF OK. ["%1" %*]
- .REG OK. [regedit.exe "%1"]
- .BAT OK. ["%1" %*]
- .SCR OK. ["%1" /S]
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]
- .HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- ==================================
- Winsock 提供者
- N/A
- ==================================
- Autorun.inf
- N/A
- ==================================
- HOSTS 文件
- 127.0.0.1 localhost
- ==================================
- 进程特权扫描
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 1708, C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\AVGNT.EXE]
- 特殊特权被允许: SeDebugPrivilege [PID = 1716, C:\PROGRAM FILES\360SAFE\SAFEMON\360TRAY.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 1716, C:\PROGRAM FILES\360SAFE\SAFEMON\360TRAY.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 1744, C:\WINDOWS\SYSTEM32\1XCLIENT.DLL]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 1968, C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\AVGUARD.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 188, D:\QQ\QQ.EXE]
- ==================================
- API HOOK
- N/A
- ==================================
- 隐藏进程
- N/A
- ==================================
复制代码 |