==================================
启动文件夹
N/A
==================================
服务
[ASP.NET State Service / aspnet_state][Stopped/Disabled]
<C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
<C:\WINDOWS\System32\Ati2evxx.exe><>
[E313BD7A / E313BD7A][Stopped/Auto Start]
<><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[KVSrvXP / KVSrvXP][Running/Auto Start]
<E:\Program Files\JiangMin\AntiVirus\kvsrvxp.exe /Service><Jiangmin Co., Ltd.>
[ms_2fax / ms_2fax][Stopped/Auto Start]
<C:\WINDOWS\system32\e6991.exe><N/A>
[NetWork Service / nkserv][Stopped/Auto Start]
<c:\program files\common files\system\serv.exe -system><Microsoft Corporation>
[PnpWMmng / PnpWMmng][Stopped/Disabled]
<E:\PROGRA~2\wmxz\PnpWMmng.exe><完美卸载>
[Windows svcs RunThem / svcs][Stopped/Auto Start]
<><N/A>
[WebPrint / WebPrint][Stopped/Disabled]
<><N/A>
[Windows Live Setup Service / WLSetupSvc][Stopped/Disabled]
<"C:\Program Files\Windows Live\installer\WLSetupSvc.exe"><>
==================================
驱动程序
[68o054azn / 68o054azn][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\68o054azn.sys><N/A>
[ESS Allegro Audio Driver (WDM) / allegro][Running/Manual Start]
<system32\drivers\es198x.sys><ESS Technology, Inc.>
[标准 IDE/ESDI 硬盘控制器 / atapi][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\atapi.sys><N/A>
[ati2mtag / ati2mtag][Running/Manual Start]
<System32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[ClntMgmt.sys / ClntMgmt.sys][Running/System Start]
<\SystemRoot\System32\Drivers\ClntMgmt.sys><Compaq Computer Corp>
[d346bus / d346bus][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\d346bus.sys><>
[Intel(R) PRO Adapter Driver / E100B][Running/Manual Start]
<System32\DRIVERS\e100b325.sys><Intel Corporation>
[ezysynt85 / ezysynt85e][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\ezysynt85e.sys><N/A>
[Huawei DataCard USB Modem and USB Serial / hwdatacard][Running/Manual Start]
<System32\DRIVERS\ewusbmdm.sys><Huawei Technologies Co., Ltd.>
[KRegEx / KRegEx][Running/Auto Start]
<\??\E:\Program Files\JiangMin\antivirus\KRegEx.sys><Jiangmin Co. Ltd.>
[Jiangmin Antivirus Software - SysCall Services / KSysCall][Running/System Start]
<\??\E:\Program Files\JiangMin\common\KSysCall.sys><Jiangmin Co., Ltd.>
[Jiangmin Antivirus Software - System Monitor / KSysMon][Running/System Start]
<\??\E:\Program Files\JiangMin\AntiVirus\KSysMon.sys><Jiangmin Co., Ltd.>
[Jiangmin Antivirus Software - File Tracer / KSysTrace][Running/System Start]
<\??\E:\Program Files\JiangMin\AntiVirus\KSysTrace.sys><Jiangmin Co., Ltd.>
[LT Modem Driver / ltmodem5][Running/Manual Start]
<System32\DRIVERS\ltmdmnt.sys><LT>
[MS / MS][Stopped/Manual Start]
<\??\C:\DOCUME~1\XP\LOCALS~1\Temp\tmp12.tmp><N/A>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\E:\tools\CoralQQ_5.0_diy\npkcrypt.sys><INCA Internet Co., Ltd.>
[320 SPACEC@M / ovt519][Stopped/Manual Start]
<System32\Drivers\ov519vid.sys><N/A>
[PnpWmkDrv / PnpWmkDrv][Running/System Start]
<\??\C:\WINDOWS\System32\drivers\PnpWmkDrv.sys><Windows (R) 2000 DDK provider>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[ROCKEYNT / ROCKEYNT][Running/Auto Start]
<\??\C:\WINDOWS\System32\drivers\Rockeynt.sys><FeiTian Tech Co.,Ltd>
[Secdrv / Secdrv][Running/Auto Start]
<System32\DRIVERS\secdrv.sys><N/A>
[SMC IrCC Miniport Device Driver / SMCIRDA][Running/Manual Start]
<System32\DRIVERS\smcirda.sys><SMC>
[Jiangmin AntiVirus Software - System Guard / SysGuard][Running/Boot Start]
<\SystemRoot\system32\Drivers\SysGuard.sys><Jiangmin Co., Ltd.>
[TSP / TSP][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\klif.sys><N/A>
[U.S. Robotics 802.11g Wireless Turbo Adapter / USR11G][Stopped/Manual Start]
<System32\DRIVERS\USR11G.sys><N/A>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[Veo Mobile/Advanced Web Camera / XIRLINK][Stopped/Manual Start]
<System32\DRIVERS\ucdnt.sys><Xirlink, Inc>
[XPROTECTOR / XPROTECTOR][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\Oreans.sys><N/A>
[KVFileGuard From Jiangmin / KVFileGuard][Running/Manual Start]
<\??\E:\Program Files\JiangMin\AntiVirus\KVfg.sys><Jiangmin Co., Ltd.>
[KVREDIR / KVREDIR][Running/System Start]
<\??\E:\Program Files\JiangMin\AntiVirus\KVREDIR.sys><Jiangmin Co., Ltd.>
==================================
浏览器加载项
[Info cache]
{385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, 金泰丰(广州)科技有限公司>
[Invoke Class]
{5FB8C5D4-929F-4870-89E2-7E3EE26EE701} <C:\WINDOWS\system32\be61.dll, N/A>
[BrowseHelper Class]
{80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} <E:\Program Files\JiangMin\AntiVirus\KVshell.dll, Jiangmin Co.Ltd>
[]
{8F776B2A-72DF-40C1-BD69-EDB642A706D7} <C:\WINDOWS\system32\bho.dll, N/A>
[Adobe Common Objects]
{C86488AF-13D5-4FEF-9DDF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_7493.dll, Microsoft Corporation>
[RegisterHelper Class]
{FF354A24-B490-4D4F-8EEC-B3ACD6E681A4} <E:\Program Files\JiangMin\AntiVirus\UrlGuard.dll, Jiangmin Co., Ltd.>
[Flash2X Flash Hunter]
{77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} <, N/A>
[江民杀毒工具栏]
{B5A34A93-D538-43A7-8371-864CB6148D12} <E:\Program Files\JiangMin\AntiVirus\KVshell.dll, Jiangmin Co.Ltd>
[MSN Photo Upload Tool]
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\System32\wuweb.dll, Microsoft Corporation>
[IMCv1 Control]
{6924091F-CD97-41E1-B1D4-D9079409D413} <C:\WINDOWS\DOWNLO~1\imcv1.dll, 北京莲塘软件技术有限公司 Liantang Software Tech. Inc. (http://www.lotuspond.com.cn)>
[MUWebControl Class]
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\System32\muweb.dll, Microsoft Corporation>
[AxSubmitControl Class]
{8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} <C:\WINDOWS\DOWNLO~1\SUBMIT~1.DLL, >
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[Hotmail Attachments Control]
{F04A8AE2-A59D-11D2-8792-00C04F8EF29D} <C:\WINDOWS\Downloaded Program Files\HMAtchmt.ocx, Microsoft Corporation>
[Info cache]
{385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, 金泰丰(广州)科技有限公司>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <, N/A>
[Thunder5下载]
{54EBD53A-9BC1-480B-966A-843A333CA162} <C:\WINDOWS\ThunderBHONew.dll, N/A>
[Invoke Class]
{5FB8C5D4-929F-4870-89E2-7E3EE26EE701} <C:\WINDOWS\system32\be61.dll, N/A>
[BrowseHelper Class]
{80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} <E:\Program Files\JiangMin\AntiVirus\KVshell.dll, Jiangmin Co.Ltd>
[]
{8F776B2A-72DF-40C1-BD69-EDB642A706D7} <C:\WINDOWS\system32\bho.dll, N/A>
[]
{A0CB0C8A-BA9D-4B91-B659-5A6556C6F477} <C:\Program Files\scNine\Boos.dll, >
[江民杀毒工具栏]
{B5A34A93-D538-43A7-8371-864CB6148D12} <E:\Program Files\JiangMin\AntiVirus\KVshell.dll, Jiangmin Co.Ltd>
[Adobe Common Objects]
{C86488AF-13D5-4FEF-9DDF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_7493.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[RegisterHelper Class]
{FF354A24-B490-4D4F-8EEC-B3ACD6E681A4} <E:\Program Files\JiangMin\AntiVirus\UrlGuard.dll, Jiangmin Co., Ltd.>
[上传到QQ网络硬盘]
<E:\tools\CoralQQ_5.0_diy\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<E:\tools\CoralQQ_5.0_diy\AddPanel.htm, N/A>
[添加到QQ表情]
<E:\tools\CoralQQ_5.0_diy\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<E:\tools\CoralQQ_5.0_diy\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 684][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 772][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 800][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 848][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 864][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1060][C:\WINDOWS\System32\Ati2evxx.exe] [, ]
[PID: 1076][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1160][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1212][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1256][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1304][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1420][E:\Program Files\JiangMin\AntiVirus\kvsrvxp.exe] [Jiangmin Co., Ltd., 10, 0, 7, 1113]
[C:\WINDOWS\system32\HiveBase.dll] [Jiangmin Co., Ltd., 1, 0, 7, 717]
[C:\WINDOWS\system32\kvinstall.dll] [Jiangmin Co.,Ltd, 2, 0, 7, 831]
[E:\Program Files\JiangMin\AntiVirus\SvcSafe.dll] [Jiangmin Co., Ltd., 11, 0, 7, 1222]
[E:\Program Files\JiangMin\AntiVirus\lang\SvcSafe0804.lng] [N/A, ]
[E:\Program Files\JiangMin\Kernel\Scan.dll] [Jiangmin Co., Ltd., 2, 0, 7, 1104]
[E:\Program Files\JiangMin\Kernel\EngFace.dll] [Jiangmin Co., Ltd., 2, 0, 7, 1125]
[E:\Program Files\JiangMin\Kernel\UNACE.dll] [N/A, ]
[E:\Program Files\JiangMin\AntiVirus\FileGuardNT.dll] [Jiangmin Co., Ltd., 11, 2, 7, 1226]
[E:\Program Files\JiangMin\AntiVirus\NetGuard.dll] [Jiangmin Co., Ltd., 2, 0, 7, 1206]
[E:\Program Files\JiangMin\KVOL\autoUpdate.dll] [Jiangmin Co.Ltd, 2, 0, 7, 1218]
[E:\Program Files\JiangMin\common\KvTrustService.dll] [Jiangmin Co., Ltd., 10, 0, 7, 1224]
[E:\Program Files\JiangMin\common\KvTools.dll] [Jiangmin Co., Ltd., 2, 0, 7, 1205]
[E:\Program Files\JiangMin\common\KvTxd.dll] [Jiangmin Co., Ltd., 10.0.6.1106]
[E:\Program Files\JiangMin\antivirus\KVAutoLS.dll] [Jiangmin Co.Ltd, 2, 0, 7, 904]
[E:\Program Files\JiangMin\AntiVirus\GuardPS.dll] [Jiangmin Co., Ltd., 2, 0, 7, 822]
[E:\Program Files\JiangMin\common\KvTrust.dll] [Jiangmin Co., Ltd., 10, 0, 7, 1224]
[E:\Program Files\JiangMin\common\KvTrustServicePS.dll] [Jiangmin Co., Ltd., 10, 0, 7, 918]
[C:\WINDOWS\system32\MSCOREE.DLL] [Microsoft Corporation, 1.1.4322.573]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll] [Microsoft Corporation, 1.1.4322.573]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[E:\Program Files\JiangMin\KVOL\UpdatePlugIn.dll] [Jiangmin Co., Ltd., 1, 0, 6, 831]
[PID: 1528][c:\program files\common files\microsoft shared\vgx\smss.exe] [Microsoft Corporation, 1.4576.2353]
[C:\WINDOWS\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[PID: 1844][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 244][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 492][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe] [ATI Technologies, Inc., 6.14.10.5062]
[C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll] [ATI Technologies, Inc., 6.14.10.5062]
[C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.CHS] [ATI Technologies, Inc., 6.14.10.5062]
[C:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll] [ATI Technologies, Inc., 6.14.10.5062]
[PID: 500][C:\Program Files\Compaq\Hotkey Software\hkss.exe] [Compaq Computer Corporation, 1.1.D3]
[C:\Program Files\Compaq\Hotkey Software\support.dll] [Compaq Computer Corporation, 1.1.D3]
[C:\Program Files\Compaq\Hotkey Software\hksshook.dll] [Compaq Computer Corporation, 1.1.D3]
[PID: 528][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1116][G:\PhoneConnectorVMC.exe] [Vodafone, 2, 1, 6, 1]
[G:\xerces-c_2_7.dll] [Apache Software Foundation, 2, 7, 0]
[PID: 1392][G:\vmc.exe] [Vodafone, 2.01.0006]
[C:\WINDOWS\system32\VB6CHS.DLL] [Microsoft Corporation, 6.00.8988]
[C:\PROGRA~1\Vodafone\VMCLite\UniBox10.ocx] [Woodbury Associates Limited, 1.0.3.64]
[C:\Program Files\Vodafone\VMCLite\UniBoxVB12.ocx] [Woodbury Associates Limited, 1.02.0033]
[C:\PROGRA~1\Vodafone\VMCLite\CODEJO~3.OCX] [Codejock Software, 10, 2, 0, 0]
[C:\PROGRA~1\Vodafone\VMCLite\CODEJO~1.OCX] [Codejock Software, 10, 2, 0, 0]
[C:\PROGRA~1\Vodafone\VMCLite\CODEJO~2.OCX] [Codejock Software, 10, 2, 0, 0]
[G:\LanguageManagerDll.dll] [TODO: <Company name>, 1.0.0.1]
[C:\Program Files\Compaq\Hotkey Software\hksshook.dll] [Compaq Computer Corporation, 1.1.D3]
[PID: 2472][C:\Documents and Settings\XP\桌面\sreng\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\Documents and Settings\XP\桌面\sreng\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[PID: 3900][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[E:\Program Files\JiangMin\AntiVirus\KsPec.dll] [Jiangmin Co., Ltd., 1, 0, 7, 903]
[E:\Program Files\JiangMin\common\KvTrust.dll] [Jiangmin Co., Ltd., 10, 0, 7, 1224]
[E:\Program Files\JiangMin\common\KvTools.dll] [Jiangmin Co., Ltd., 2, 0, 7, 1205]
[C:\WINDOWS\system32\HiveBase.dll] [Jiangmin Co., Ltd., 1, 0, 7, 717]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS Error. []
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 492, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 500, C:\PROGRAM FILES\COMPAQ\HOTKEY SOFTWARE\HKSS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1116, G:\PHONECONNECTORVMC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1392, G:\VMC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 232, C:\DOCUMENTS AND SETTINGS\XP\桌面\WORK\THEWORLD.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
[513] E:\Program Files\JiangMin\AntiVirus\KVMonXP.kxp
[1520] c:\windows\system32\com\services.exe
==================================
[/CODE] |