O4 - 安全 - HKLM\..\Run: [DAEMON Tools] [一款虚拟光驱工具。] ; "H:\DAEMON Tools\daemon.exe" -lang 2052
O4 - 安全 - HKLM\..\Run: [IMSCMig] [微软拼音输入法安装工具。 ] E:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - 安全 - HKLM\..\Run: [Acrobat Assistant 7.0] [adobe公司出品的acrobat distiller软件,用于打印pdf文档。] "E:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - 安全 - HKLM\..\Run: [ISUSPM Startup] [installshield安装包服务计划任务升级程序。] ; E:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - 安全 - HKLM\..\Run: [ISUSScheduler] [installshield 公司出品的相关软件。] ; "E:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - 安全 - HKCU\..\Run: [ctfmon.exe] [office xp输入法图标。] E:\WINDOWS\system32\ctfmon.exe
O4 - 安全 - HKCU\..\Run: [MsnMsgr] [微软msn即时通讯工具] "E:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - 安全 - Startup folder: [Adobe Acrobat Speed Launcher.lnk] [Adobe Reader启动项相关程序。] E:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Acrobat Speed Launcher.lnk
O8 - 安全 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://E:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - 安全 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (招商银行个人版) - https://site.cmbchina.com/download/CMBEdit.cab
O16 - 安全 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (Windows升级工具V5) - http://www.update.microsoft.com/ ... e.cab?1182280685218
O18 - 安全 - Protocol: OFFICE 相关 - {807553E5-5146-11D5-A672-00B0D022E945} - E:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O18 - 安全 - Protocol: OFFICE 相关 - {32505114-5902-49B2-880A-1F7738E5A384} - E:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
O23 - 安全 - Service: AVG Anti-Spyware Guard [一款杀毒软件AVG的相关服务。] - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe - (running)
O23 - 安全 - Service: MSSQLServerADHelper [sql server,microsoft开发的企业级数据库相关程序。] - "E:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe" - (not running)
O23 - 安全 - Service: NVSvc [是NVIDIA显示卡相关程序。] - E:\WINDOWS\system32\nvsvc32.exe - (running)
=======================================
O31 - 未知 - Folder Menu: {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} - "E:\Program Files\RedOffice 3.0\program\shlxthdl.dll" - - - - 0 -
O31 - 未知 - Folder Menu: {F9DB5320-233E-11D1-9F84-707F02C10627} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll - Adobe Systems, Inc. - PDF Shell Extension - 7.0.0.0 - 110592 - 4b0991cd076b617a2231b19a6663c1c9
O31 - 未知 - SEApproved: {42071714-76d4-11d1-8b24-00a0c9068ff3} - deskpan.dll - - - - 0 -
O31 - 未知 - SEApproved: 无效的CLSID:Shell extensions for file compression - - - - - 0 -
O31 - 未知 - SEApproved: 无效的CLSID:加密上下文菜单 - - - - - 0 -
O31 - 未知 - SEApproved: {0DF44EAA-FF21-4412-828E-260A8728E7F1} - - - - - 0 -
O31 - 未知 - SEApproved: {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} - - - - - 0 -
O31 - 未知 - SEApproved: {7A9D77BD-5403-11d2-8785-2E0420524153} - - - - - 0 -
O31 - 未知 - SEApproved: {1CDB2949-8F65-4355-8456-263E7C208A5D} - E:\WINDOWS\system32\nvshell.dll - - - 6.14.10.11060 - 466944 - 4450bbaf1b77f2b87ab9c5ee4e69532c
O31 - 未知 - SEApproved: {1E9B04FB-F9E5-4718-997B-B8DA88302A47} - E:\WINDOWS\system32\nvshell.dll - - - 6.14.10.11060 - 466944 - 4450bbaf1b77f2b87ab9c5ee4e69532c
O31 - 未知 - SEApproved: {1E9B04FB-F9E5-4718-997B-B8DA88302A48} - E:\WINDOWS\system32\nvshell.dll - - - 6.14.10.11060 - 466944 - 4450bbaf1b77f2b87ab9c5ee4e69532c
O31 - 未知 - SEApproved: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - E:\Program Files\WinRAR\rarext.dll - - - - 129024 - de449c94c4c9e3db84e32029f20dd989
O31 - 未知 - SEApproved: 无效的CLSID:Portable Media Devices - - - - - 0 -
O31 - 未知 - SEApproved: 无效的CLSID:Portable Media Devices Menu - - - - - 0 -
O31 - 未知 - SEApproved: {AD392E40-428C-459F-961E-9B147782D099} - E:\Program Files\UltraISO\isoshell.dll - EZB Systems, Inc. - ISOShell - 1.0.0.1 - 53248 - 48344c676169e401508673c794598f26
O31 - 未知 - SEApproved: {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} - E:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll - Adobe Systems Inc. - Adobe Acrobat Context Menu - 7.0.7.142 - 581632 - f72f179a6a23c77988f31cee8c5d2326
O31 - 未知 - SEApproved: {e82a2d71-5b2f-43a0-97b8-81be15854de8} - E:\WINDOWS\system32\dfshim.dll - Microsoft Corporation - Application Deployment Support Library - 2.0.50727.42 - 83456 - b3511383c8be3a8c5b88a78971fc1141
O31 - 未知 - SEApproved: {E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} - E:\WINDOWS\system32\dfshim.dll - Microsoft Corporation - Application Deployment Support Library - 2.0.50727.42 - 83456 - b3511383c8be3a8c5b88a78971fc1141
O31 - 未知 - SEApproved: {e7593602-124b-47c9-9f73-a69308edc973} - M:\green software test\DrWeb4\drwsxtn.dll - Doctor Web, Ltd. - Dr.Web ? Shell Extension - 4.44.0.8080 - 65536 - b305e0404d805053ab8fc8f578b01966
O31 - 未知 - SEApproved: {F49C55B9-D417-45A1-A6E7-D6E057946280} - E:\Program Files\Free Download Manager\FUM\fumshext.dll - - - 600.0.0.2 - 86016 - 9a1fa2881372b0b2c09af7e128c43fee
O31 - 未知 - SEApproved: {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} - E:\Program Files\PowerISO\PWRISOSH.DLL - PowerISO Computing, Inc. - PowerISOShell DLL - 3.4.0.0 - 200704 - f7e17e04c770e7802cba5452ca4d4c5b
O31 - 未知 - SEApproved: {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} - "E:\Program Files\RedOffice 3.0\program\shlxthdl.dll" - - - - 0 -
O31 - 未知 - SEApproved: {087B3AE3-E237-4467-B8DB-5A38AB959AC9} - "E:\Program Files\RedOffice 3.0\program\shlxthdl.dll" - - - - 0 -
O31 - 未知 - SEApproved: {63542C48-9552-494A-84F7-73AA6A7C99C1} - "E:\Program Files\RedOffice 3.0\program\shlxthdl.dll" - - - - 0 -
O31 - 未知 - SEApproved: {3B092F0C-7696-40E3-A80F-68D74DA84210} - "E:\Program Files\RedOffice 3.0\program\shlxthdl.dll" - - - - 0 -
O31 - 未知 - Directory Menu: {e7593602-124b-47c9-9f73-a69308edc973} - M:\green software test\DrWeb4\drwsxtn.dll - Doctor Web, Ltd. - Dr.Web ? Shell Extension - 4.44.0.8080 - 65536 - b305e0404d805053ab8fc8f578b01966
O31 - 未知 - Directory Menu: {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} - E:\Program Files\PowerISO\PWRISOSH.DLL - PowerISO Computing, Inc. - PowerISOShell DLL - 3.4.0.0 - 200704 - f7e17e04c770e7802cba5452ca4d4c5b
O31 - 未知 - Directory Menu: {45AC2688-0253-4ED8-97DE-B5370FA7D48A} - M:\AntiVir PersonalEdition Classic\shlext.dll - Avira GmbH - ShlExt.dll - 7.0.0.10 - 61480 - 985d428316105bae82b9c0eb4f91a191
O31 - 未知 - Directory Menu: {AD392E40-428C-459F-961E-9B147782D099} - E:\Program Files\UltraISO\isoshell.dll - EZB Systems, Inc. - ISOShell - 1.0.0.1 - 53248 - 48344c676169e401508673c794598f26
O31 - 未知 - Directory Menu: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - E:\Program Files\WinRAR\rarext.dll - - - - 129024 - de449c94c4c9e3db84e32029f20dd989
O31 - 未知 - BootExecute: - - - - 0 -
O31 - 未知 - LSA: Security Packages - sv1_0.dll - - - - 0 -
O31 - 未知 - LSA: Security Packages - channel.dll - - - - 0 -
=======================================
O40 - lsass.exe - Doctor Web, Ltd. - E:\WINDOWS\system32\DRWEBSP.DLL - Dr.Web Winsock Provider Hook - a9eb7f70fe7ac3954594189269695427
O40 - lsass.exe - DYWT - E:\WINDOWS\system32\ESPI11.dll - ESPI - a40c0fe0f88b36893388aab3dbaf629c
O40 - svchost.exe - Doctor Web, Ltd. - E:\WINDOWS\system32\DRWEBSP.DLL - Dr.Web Winsock Provider Hook - a9eb7f70fe7ac3954594189269695427
O40 - svchost.exe - DYWT - E:\WINDOWS\system32\ESPI11.dll - ESPI - a40c0fe0f88b36893388aab3dbaf629c
O40 - svchost.exe - Doctor Web, Ltd. - E:\WINDOWS\system32\DRWEBSP.DLL - Dr.Web Winsock Provider Hook - a9eb7f70fe7ac3954594189269695427
O40 - svchost.exe - DYWT - E:\WINDOWS\system32\ESPI11.dll - ESPI - a40c0fe0f88b36893388aab3dbaf629c
O40 - svchost.exe - Doctor Web, Ltd. - E:\WINDOWS\system32\DRWEBSP.DLL - Dr.Web Winsock Provider Hook - a9eb7f70fe7ac3954594189269695427
O40 - svchost.exe - DYWT - E:\WINDOWS\system32\ESPI11.dll - ESPI - a40c0fe0f88b36893388aab3dbaf629c
O40 - svchost.exe - Doctor Web, Ltd. - E:\WINDOWS\system32\DRWEBSP.DLL - Dr.Web Winsock Provider Hook - a9eb7f70fe7ac3954594189269695427
O40 - svchost.exe - DYWT - E:\WINDOWS\system32\ESPI11.dll - ESPI - a40c0fe0f88b36893388aab3dbaf629c
O40 - Explorer.EXE - Sun Microsystems, Inc. - E:\Program Files\RedOffice 3.0\program\shlxthdl.dll - - df71293879104c5006a682ee2d4e9d7d
O40 - Explorer.EXE - Sun Microsystems, Inc. - E:\Program Files\RedOffice 3.0\program\uwinapi.dll - - 0bd4dc5c9de80a81f1c2dae4946490e7
O40 - Explorer.EXE - Microsoft Corporation - E:\Program Files\RedOffice 3.0\program\MSVCR71.dll - Microsoft? C Runtime Library - 2d6e1bfc465cf826c8e21e6adacbbd53
O40 - Explorer.EXE - STLport Consulting, Inc. - E:\Program Files\RedOffice 3.0\program\stlport_vc7145.dll - STLport - 94a27e31cb08dfb4e7bcdcecbfe99f7b
O40 - Explorer.EXE - Microsoft Corporation - E:\Program Files\RedOffice 3.0\program\MSVCP71.dll - Microsoft? C++ Runtime Library - b8af461f6c66932e1ac554ad162164c5
O40 - Explorer.EXE - Adobe Systems, Inc. - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll - PDF Shell Extension - 4b0991cd076b617a2231b19a6663c1c9 |