查看: 3952|回复: 11
收起左侧

[已解决] 我的日志

[复制链接]
xnthc
发表于 2007-2-5 18:00:29 | 显示全部楼层 |阅读模式
2007-02-05,17:58:27

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件

启动项目


注册表

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
(ctfmon.exe)(; C:\WINDOWS\system32\ctfmon.exe) [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(load)() [N/A]
(run)() [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
(KAVPersonal50)("d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize) [Kaspersky Lab]
(BigDogPath)(; C:\WINDOWS\VM_STI.EXE Vimicro USB PC Camera (ZC0301PL)) [N/A]
(IMJPMIG8.1)(; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32) [(Verified)Microsoft Corporation]
(miniqqlive)(; "C:\Program Files\Tencent\QQLive\MiniQQLive.exe") [Tencent]
(PHIME2002A)(; ) [N/A]
(PHIME2002ASync)(; ) [N/A]
(StormCodec_Helper)(; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti) [N/A]
(TkBellExe)(; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot) [RealNetworks, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(shell)(Explorer.exe) [(Verified)Microsoft Corporation]
(Userinit)(C:\WINDOWS\system32\userinit.exe,) [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(AppInit_DLLs)() [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(UIHost)(logonui.exe) [(Verified)Microsoft Corporation]

启动文件夹

N/A

服务

[Human Interface Device Access / HidServ][Stopped/Disabled]
(C:\WINDOWS\System32\svchost.exe -k netsvcs--)%SystemRoot%\System32\hidserv.dll)(N/A)
[kavsvc / kavsvc][Running/Auto Start]
("d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe")(Kaspersky Lab)
[LexBce Server / LexBceS][Running/Auto Start]
(C:\WINDOWS\system32\LEXBCES.EXE)(Lexmark International, Inc.)
[SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
(C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe)(Analog Devices, Inc.)
[SVCH0ST / SVCH0ST][Stopped/Auto Start]
(C:\WINDOWS\NeroCheck.exe)(N/A)
[Microsoft Apache for Windows / Windows Apache Service][Stopped/Auto Start]
("C:\WINDOWS\wpablin.exe")(N/A)

驱动程序

[a320raid / a320raid][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\a320raid.sys)(Adaptec, Inc.)
[AAC / AAC][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\AAC.SYS)(Adaptec, Inc.)
[aar1210 / aar1210][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\aar1210.sys)(Adaptec, Inc.)
[abp480n5 / abp480n5][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\abp480n5.sys)(Microsoft Corporation)
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
(system32\drivers\ac97intc.sys)(Intel Corporation)
[adpu160m / adpu160m][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\adpu160m.sys)(Microsoft Corporation)
[adpu320 / adpu320][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\adpu320.sys)(Adaptec, Inc.)
[aeaudio / aeaudio][Running/Manual Start]
(system32\drivers\aeaudio.sys)(Andrea Electronics Corporation)
[ACARD AEC6210UF UltraDMA33 Controller / aec6210][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\aec6210.sys)(ACARD Technology Corp.)
[ACARD AEC6260 UltraDMA-66 Controller / aec6260][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\aec6260.sys)(ACARD Technology Corp.)
[aec6280 / aec6280][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\aec6280.sys)(ACARD Technology Corp.)
[AEC6290 / AEC6290][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\AEC6290.SYS)(ACARD Technology Corp.)
[AEC67160 / AEC67160][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\AEC67160.SYS)(ACARD Technology Corp.)
[AEC671X / AEC671X][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\AEC671X.SYS)(ACARD Technology Corp.)
[AEC6880 / AEC6880][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\AEC6880.SYS)(ACARD Technology Corp.)
[AEC6890 / AEC6890][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\AEC6890.sys)(ACARD Technology Corp.)
[aec68x5 / aec68x5][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\aec68x5.sys)(ACARD Technology Corp.)
[Aha154x / Aha154x][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\aha154x.sys)(Microsoft Corporation)
[aic78u2 / aic78u2][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\aic78u2.sys)(Microsoft Corporation)
[aic78xx / aic78xx][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\aic78xx.sys)(Microsoft Corporation)
[AliIde / AliIde][Running/Boot Start]
(\SystemRoot\System32\DRIVERS\aliide.sys)(Acer Laboratories Inc.)
[AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
(System32\DRIVERS\amdk8.sys)(Microsoft Corporation)
[arc / arc][Stopped/Boot Start]
(\SystemRoot\system32\drivers\arc.sys)(Adaptec, Inc.)
[asc / asc][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\asc.sys)(Advanced System Products, Inc.)
[asc3550 / asc3550][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\asc3550.sys)(Advanced System Products, Inc.)
[ati2mtag / ati2mtag][Running/Manual Start]
(system32\DRIVERS\ati2mtag.sys)(ATI Technologies Inc.)
[CmdIde / CmdIde][Running/Boot Start]
(\SystemRoot\System32\DRIVERS\cmdide.sys)(CMD Technology, Inc.)
[dac2w2k / dac2w2k][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\dac2w2k.sys)(Mylex Corporation)
[dpti2o / dpti2o][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\dpti2o.sys)(Microsoft Corporation)
[EagleNT / EagleNT][Stopped/Manual Start]
(\??\C:\WINDOWS\system32\drivers\EagleNT.sys)(N/A)
[elxstor / elxstor][Stopped/Boot Start]
(\SystemRoot\system32\drivers\elxstor.sys)(Emulex)
[FASTSX / FASTSX][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\FASTSX.SYS)(Promise Technology, Inc.)
[fasttrak / fasttrak][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\fasttrak.sys)(Promise Technology, Inc.)
[fasttx2k / fasttx2k][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\fasttx2k.sys)(Promise Technology, Inc.)
[fasttx2k2 / fasttx2k2][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\fasttx2k2.sys)(Promise Technology, Inc.)
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
(system32\DRIVERS\fetnd5.sys)(VIA Technologies, Inc.)
[HpCISSs / HpCISSs][Stopped/Boot Start]
(\SystemRoot\system32\drivers\hpcisss.sys)(Hewlett-Packard Company)
[Hpt366 / Hpt366][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\Hpt366.sys)(Microsoft Corporation)
[HPT371 / HPT371][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\HPT371.sys)(HighPoint Technologies, Inc.)
[hpt374 / hpt374][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\hpt374.sys)(HighPoint Technologies, Inc.)
[hpt3xx / hpt3xx][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\hpt3xx.sys)(HighPoint Technologies, Inc.)
[hptmv / hptmv][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\hptmv.sys)(HighPoint Technologies, Inc.)
[hptpro / hptpro][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\hptpro.sys)(HighPoint Technologies, Inc.)
[Intel Integrated RAID / iaStor][Stopped/Boot Start]
(\SystemRoot\system32\drivers\iaStor.sys)(Intel Corporation)
[iirsp / iirsp][Stopped/Boot Start]
(\SystemRoot\system32\drivers\iirsp.sys)(Intel Corp./ICP vortex GmbH)
[ini910u / ini910u][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\ini910u.sys)(Microsoft Corporation)
[ITERAID_Service_Install / iteraid][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\iteraid.sys)(Integrated Technology Express, Inc.)
[Kl1 / Kl1][Running/Boot Start]
(\SystemRoot\System32\drivers\kl1.sys)(Kaspersky Lab)
[Klif / Klif][Running/System Start]
(System32\drivers\klif.sys)(Kaspersky Labs)
[Klmc / Klmc][Running/System Start]
(System32\drivers\klmc.sys)(Kaspersky Lab)
[LSI_SAS / LSI_SAS][Stopped/Boot Start]
(\SystemRoot\system32\drivers\lsi_sas.sys)(LSI Logic)
[LSI_SCSI / LSI_SCSI][Stopped/Boot Start]
(\SystemRoot\system32\drivers\lsi_scsi.sys)(LSI Logic)
[m5228 / m5228][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\m5228.sys)(ALi Corporation.)
[m5281 / m5281][Stopped/Boot Start]
(\SystemRoot\system32\drivers\m5281.sys)(ALi Corporation)
[MegaIDE / MegaIDE][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\MegaIDE.sys)(LSI Logic Corporation.)
[megasas / megasas][Stopped/Boot Start]
(\SystemRoot\system32\drivers\megasas.sys)(LSI Logic Corporation)
[mraid2k / mraid2k][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\mraid2k.sys)(American Megatrends, Inc.)
[mraid35x / mraid35x][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\mraid35x.sys)(American Megatrends Inc.)
[nfrd960 / nfrd960][Stopped/Boot Start]
(\SystemRoot\system32\drivers\nfrd960.sys)(IBM Corporation)
[npkcrypt / npkcrypt][Running/Auto Start]
(\??\C:\Program Files\Tencent\QQ\npkcrypt.sys)(INCA Internet Co., Ltd.)
[nv / nv][Stopped/Manual Start]
(system32\DRIVERS\nv4_mini.sys)(NVIDIA Corporation)
[Intel SCSI Controller / NvAtaBus][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\NVATABUS.SYS)(NVIDIA Corporation)
[NVIDIA nForce(tm) RAID Class Driver / nvraid][Stopped/Boot Start]
(\SystemRoot\system32\DRIVERS\nvraid.sys)(NVIDIA Corporation)
[PNP649R / PNP649R][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\PNP649R.SYS)(CMD Technology, Inc.)
[SiI 680 ATA Controller / Pnp680][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\pnp680.sys)(Silicon Image, Inc.)
[Silicon Image SiI 0680 Medley Raid Controller / Pnp680r][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\pnp680r.sys)(Silicon Image, Inc)
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
(system32\DRIVERS\ptilink.sys)(Parallel Technologies, Inc.)
[ql1080 / ql1080][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\ql1080.sys)(QLogic Corporation)
[Ql10wnt / Ql10wnt][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\ql10wnt.sys)(Microsoft Corporation)
[ql12160 / ql12160][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\ql12160.sys)(QLogic Corporation)
[ql1280 / ql1280][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\ql1280.sys)(QLogic Corporation)
[QLogic Fibre Channel SCSI Miniport Driver / ql2300][Stopped/Boot Start]
(\SystemRoot\system32\drivers\ql2300.sys)(QLogic Corporation)
[RAIDSRC / RAIDSRC][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\RAIDSRC.SYS)(Intel/ICP)
[Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Stopped/Manual Start]
(system32\DRIVERS\Rtnicxp.sys)(Realtek Semiconductor Corporation)
[Realtek RTL8139/810x Family Fast Ethernet NIC NT Driver / rtl8139][Running/Manual Start]
(system32\DRIVERS\R8139n51.SYS)(Realtek Semiconductor Corporation)
[S150SX8 / S150SX8][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\S150SX8.SYS)(Promise Technology, Inc.)
[Secdrv / Secdrv][Stopped/Manual Start]
(system32\DRIVERS\secdrv.sys)(N/A)
[SiI-3512 SATALink Controller / SI3112][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\SI3112.sys)(Silicon Image, Inc.)
[Silicon Image SiI 3512 SATARaid Controller / SI3112r][Stopped/Boot Start]
(\SystemRoot\system32\drivers\SI3112r.sys)(Silicon Image, Inc)
[SiI-3114 SATALink Controller / SI3114][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\SI3114.sys)(Silicon Image, Inc.)
[SiI-3114 SATARaid Controller / SI3114r][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\SI3114R.sys)(Silicon Image, Inc)
[SiI-3124 SATALink Controller / SI3124][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\SI3124.sys)(Silicon Image, Inc.)
[SiI-3124 SATARaid Controller / SI3124r][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\SI3124R.sys)(Silicon Image, Inc)
[SATALink driver accelerator / SiFilter][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\SiWinAcc.sys)(Silicon Image, Inc.)
[SISIDE / SISIDE][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\SISIDE.SYS)(Silicon Integrated Systems Corp.)
[SiSRaid / SiSRaid][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\SiSRaid.sys)(Silicon Integrated Systems)
[SiSRaid1 / SiSRaid1][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\SiSRaid1.sys)(Silicon Integrated Systems)
[SISRAIDS / SISRAIDS][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\SISRAIDS.SYS)(Silicon Integrated Systems Corp)
[smwdm / smwdm][Running/Manual Start]
(system32\drivers\smwdm.sys)(Analog Devices, Inc.)
[Sparrow / Sparrow][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\sparrow.sys)(Adaptec, Inc.)
[sptrak / sptrak][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\sptrak.sys)(Promise Technology, Inc.)
[symc810 / symc810][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\symc810.sys)(Symbios Logic Inc.)
[symc8xx / symc8xx][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\symc8xx.sys)(LSI Logic)
[SYMMPI / SYMMPI][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\SYMMPI.SYS)(LSI Logic)
[sym_hi / sym_hi][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\sym_hi.sys)(LSI Logic)
[sym_u3 / sym_u3][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\sym_u3.sys)(LSI Logic)
[TosIde / TosIde][Running/Boot Start]
(\SystemRoot\System32\DRIVERS\toside.sys)(Microsoft Corporation)
[UlSata / UlSata][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\ulsata.sys)(Promise Technology, Inc.)
[ULSATAS / ULSATAS][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\ULSATAS.SYS)(Promise Technology, Inc.)
[ultra / ultra][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\ultra.sys)(Promise Technology, Inc.)
[UnlockerDriver4 Driver / UnlockerDriver4][Stopped/Manual Start]
(\??\C:\Program Files\Unlocker\UnlockerDriver4.sys)(N/A)
[ViaIde / ViaIde][Running/Boot Start]
(\SystemRoot\System32\DRIVERS\viaide.sys)(Microsoft Corporation)
[viamraid / viamraid][Stopped/Boot Start]
(\SystemRoot\system32\DRIVERS\viamraid.sys)(VIA Technologies inc,.ltd)
[VIA ATA/ATAPI Host Controller / viapdsk][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\viapdsk.sys)(VIA Technologies, Inc.)
[viaraid / viaraid][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\viaraid.sys)(VIA Technologies inc,.ltd)
[viasraid / viasraid][Stopped/Boot Start]
(\SystemRoot\system32\drivers\viasraid.sys)(VIA Technologies inc,.ltd)
[vmscsi / vmscsi][Stopped/Boot Start]
(\SystemRoot\system32\drivers\vmscsi.sys)(VMware, Inc.)
[wlbl#01 / wlbl#01][Stopped/Manual Start]
(\??\C:\WINDOWS\system32\ttyufzplusdtwlbl.sys)(N/A)
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
(system32\DRIVERS\WSTCODEC.SYS)(Microsoft Corporation)
[Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Running/Manual Start]
(System32\Drivers\usbVM31b.sys)(VM)

[ 本帖最后由 xnthc 于 2007-2-6 22:03 编辑 ]
xnthc
 楼主| 发表于 2007-2-5 18:01:04 | 显示全部楼层
浏览器加载项

[Thunder Browser Helper]
{54EBD539-9BC1-480B-966A-843A333CA162} (D:\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD)
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} (C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司)
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} (D:\Thunder\Thunder.exe, Thunder Networking Technologies,LTD)
[微软]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} (http://www.microsoft.com/china/index.htm, N/A)
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} (C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT)
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} (C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司)
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} (C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft? Corporation)
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.)
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} (C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation)
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} (C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司)
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} (%SystemRoot%\system32\SHELL32.dll, N/A)
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} (C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation)
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} (D:\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD)
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} (C:\WINDOWS\system32\Mshtml.dll, Microsoft Corporation)
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} (%SystemRoot%\system32\shdocvw.dll, N/A)
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} (C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation)
[AUDIO__MP3 Moniker Class]
{CD3AFA76-B84F-48F0-9393-7EDC34128127} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[VIDEO__X_MS_WMV Moniker Class]
{CD3AFA94-B84F-48F0-9393-7EDC34128127} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} (C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.)
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.)
[&使用迅雷下载]
(D:\Thunder\Program\geturl.htm, N/A)
[&使用迅雷下载全部链接]
(D:\Thunder\Program\getallurl.htm, N/A)
[上传到QQ网络硬盘]
(C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A)
[使用影音传送带下载]
(, N/A)
[使用影音传送带下载全部链接]
(, N/A)
[导出到 Microsoft Office Excel(&X)]
(res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A)
[添加到QQ自定义面板]
(C:\Program Files\Tencent\QQ\AddPanel.htm, N/A)
[添加到QQ表情]
(C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A)
[用QQ彩信发送该图片]
(C:\Program Files\Tencent\QQ\SendMMS.htm, N/A)



--------------------------------------------------------------------------------



正在运行的进程

[PID: 496][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 544][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 568][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 612][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 624][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 780][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 840][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 920][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 988][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1044][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1240][C:\WINDOWS\system32\LEXBCES.EXE] [Lexmark International, Inc., 9.47]
[C:\WINDOWS\system32\lexp2p32.dll] [Lexmark International, Inc., 9.47]
[C:\WINDOWS\system32\lex2kusb.dll] [Lexmark International, Inc., 9.47]
[PID: 1316][C:\WINDOWS\system32\LEXPPS.EXE] [Lexmark International, Inc., 9.46]
[C:\WINDOWS\system32\LEXBCE.DLL] [Lexmark International, Inc., 9.47]
[PID: 1328][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\system32\LEXLMPM.DLL] [Lexmark International, Inc., 96.9.42]
[C:\WINDOWS\system32\LexBce.dll] [Lexmark International, Inc., 9.47]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\LVBCPP5C.dll] [Lenovo (Beijing) Ltd., 1.0.2.2]
[C:\WINDOWS\system32\LVBCpwr.dll] [Lenovo (Beijing) Ltd., 1, 0, 1, 0]
[PID: 1476][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\shellex.dll] [Kaspersky Lab, 5.0.388.1]
[PID: 1548][C:\WINDOWS\VM_STI.EXE] [Vimicro, 4, 2, 1124, 6]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\WINDOWS\system32\VM31bPrp.Ax] [Vimicro, 1.00.01.00]
[PID: 1608][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1804][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] [Analog Devices, Inc., 3, 2, 6, 0]
[PID: 1820][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1980][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 972][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 2504][D:\Program Files\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 5, 6, 42]
[D:\Program Files\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[D:\Thunder\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
[D:\Program Files\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\scrchpg.dll] [Kaspersky Lab, 5.0.1.18]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\scrch_ag.dll] [Kaspersky Lab, 5.0.388.1]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\FSSync.dll] [Kaspersky Lab, 5.0.388.0]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\pr_rmt.dll] [Kaspersky Lab, 5.0.388.0]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\ccclient.dll] [Kaspersky Lab, 5.0.388.1]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\klipc.dll] [Kaspersky Lab, 5.0.388.0]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\KLUtil.dll] [Kaspersky Lab, 5.0.388.1]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\rpt.dll] [Kaspersky Lab, 5.0.388.2]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\CCIFACE.dll] [Kaspersky Lab, 5.0.388.1]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\prloader.dll] [Kaspersky Lab, 5.0.388.0]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\prkernel.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\program files\kaspersky lab\kaspersky anti-virus personal pro\prstring.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\program files\kaspersky lab\kaspersky anti-virus personal pro\pr_srv.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\program files\kaspersky lab\kaspersky anti-virus personal pro\pr_clnt.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\program files\kaspersky lab\kaspersky anti-virus personal pro\tempfile.ppl] [Kaspersky Lab, 5.0.388.0]
[PID: 2936][D:\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5, 5, 4, 266]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[D:\Thunder\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 14]
[D:\Thunder\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 2, 12, 2, 44]
[D:\Thunder\Program\asyn_dns.dll] [Thunder Networking Technologies,LTD, 2, 12, 2, 44]
[D:\Thunder\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 8]
[D:\Thunder\Program\iTargetAD.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 13]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[D:\Thunder\Components\DiagnoseHelper\DiagnoseHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 10]
[D:\Thunder\Components\PortVerify\PortVerify.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
[D:\Thunder\Components\ExplorerHelper\ExplorerHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
[D:\Thunder\Components\DTAG\DTAG.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
[D:\Thunder\Program\LiveUpdate.dll] [, 1, 0, 1, 17]
[D:\Thunder\Components\InMedia\iEmbedShell.dll] [ , 1, 0, 0, 15]
[D:\Thunder\Components\InMedia\iEmbed08.dll] [ , 3, 2, 0, 63]
[D:\Thunder\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 1, 0, 3, 14]
[D:\Thunder\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 2, 1, 43]
[D:\Thunder\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 6]
[D:\Thunder\Components\P4PClient\P4PClient.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 13]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\scrchpg.dll] [Kaspersky Lab, 5.0.1.18]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\scrch_ag.dll] [Kaspersky Lab, 5.0.388.1]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\FSSync.dll] [Kaspersky Lab, 5.0.388.0]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\pr_rmt.dll] [Kaspersky Lab, 5.0.388.0]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\ccclient.dll] [Kaspersky Lab, 5.0.388.1]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\klipc.dll] [Kaspersky Lab, 5.0.388.0]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\KLUtil.dll] [Kaspersky Lab, 5.0.388.1]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\rpt.dll] [Kaspersky Lab, 5.0.388.2]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\CCIFACE.dll] [Kaspersky Lab, 5.0.388.1]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\prloader.dll] [Kaspersky Lab, 5.0.388.0]
[d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\prkernel.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\program files\kaspersky lab\kaspersky anti-virus personal pro\prstring.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\program files\kaspersky lab\kaspersky anti-virus personal pro\pr_srv.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\program files\kaspersky lab\kaspersky anti-virus personal pro\pr_clnt.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\program files\kaspersky lab\kaspersky anti-virus personal pro\tempfile.ppl] [Kaspersky Lab, 5.0.388.0]
[PID: 2824][C:\DOCUME~1\new\LOCALS~1\Temp\Rar$EX02.375\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]



--------------------------------------------------------------------------------



文件关联

.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]



--------------------------------------------------------------------------------



Winsock 提供者

N/A



--------------------------------------------------------------------------------



Autorun.inf

N/A



--------------------------------------------------------------------------------



HOSTS 文件

127.0.0.1 localhost



--------------------------------------------------------------------------------



API HOOK

警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
RVA 错误: LoadLibraryA
RVA 错误: LoadLibraryExA
RVA 错误: LoadLibraryExW
RVA 错误: LoadLibraryW
jimmyleo
发表于 2007-2-5 18:02:47 | 显示全部楼层
有什么问题吗 电脑
xnthc
 楼主| 发表于 2007-2-5 18:07:01 | 显示全部楼层
过一会就断网PING 的通
xnthc
 楼主| 发表于 2007-2-5 18:07:44 | 显示全部楼层
C:\WINDOWS\NeroCheck.exe)(N/A)
[Microsoft Apache for Windows / Windows Apache Service][Stopped/Auto Start]
("C:\WINDOWS\wpablin.exe")(N/A)
这两个我删了,
wangjay1980
发表于 2007-2-5 20:09:32 | 显示全部楼层
恩,那两个有问题,楼主的驱动太多拉,看的我眼都花了
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(load)() [N/A]
(run)() [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(AppInit_DLLs)() [N/A]
你可以看看这几项,后面都应该是什么也没有,有的话删除,然后用WINDOWS清理助手查一遍
jimmyleo
发表于 2007-2-6 15:22:36 | 显示全部楼层
断网 貌似是魔波的影响吧

到微软安全公告里找找06-040

http://www.microsoft.com/china/technet/security/current.mspx

打下补丁试试
xnthc
 楼主| 发表于 2007-2-6 19:09:07 | 显示全部楼层
2007-02-06,19:07:35

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件


启动项目


注册表

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
(ctfmon.exe)(C:\windows\system32\ctfmon.exe) [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(load)() [N/A]
(run)() [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
(KvMonXP)("D:\KV2006\KVMonXP_1.kxp" /auto) [Jiangmin Co.Ltd]
(RfwMain)("E:\Program Files\Rising\Rfw\rfwmain.exe" -Startup) [Beijing Rising Technology Co., Ltd.]
(KVautoupdate )(D:\KV2006\kvol.exe /silent) [Jiangmin Co.Ltd]
(!AVG Anti-Spyware)("D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized) [Anti-Malware Development a.s.]
(runeip)(d:\Program Files\Rising\AntiSpyware\runiep.exe) [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
(KKDelay)(d:\Program Files\Rising\AntiSpyware\RunOnce.exe) [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(shell)(Explorer.exe) [(Verified)Microsoft Corporation]
(Userinit)(C:\WINDOWS\system32\userinit.exe,) [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(AppInit_DLLs)() [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(UIHost)(logonui.exe) [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
({57B86673-276A-48B2-BAE7-C6DBB3020EB8})(d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll) [Anti-Malware Development a.s.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
(High Definition Audio Property Page Shortcut)(; HDAShCut.exe) [(Verified)Windows (R) Server 2003 DDK provider]
(IMJPMIG8.1)(; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32) [(Verified)Microsoft Corporation]
(IMSCMig)(; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload) [(Verified)Microsoft Corporation]
(LHotkey)(; LHotkey.exe) [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
(MSMSGS)(; "C:\Program Files\Messenger\msmsgs.exe" /background) [(Verified)Microsoft Corporation]
(msnmsgr)(; ) [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
(NvCplDaemon)(; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup) [(Verified)NVIDIA Corporation]
(nwiz)(; nwiz.exe /installquiet /keeploaded /nodetect) [N/A]
(PHIME2002A)(; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName) [(Verified)Microsoft Corporation]
(PHIME2002ASync)(; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC) [(Verified)Microsoft Corporation]
(RunShadowTip)(; C:\WINDOWS\system32\shadow\ShadowTip.exe) [PowerShadow]
(StormCodec_Helper)(; "d:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti) [N/A]
(TkBellExe)(; ) [N/A]




--------------------------------------------------------------------------------



启动文件夹

[核新SSL通讯安全代理]
(C:\Documents and Settings\All Users\「开始」菜单\程序\启动\核新SSL通讯安全代理.lnk --) E:\PROGRA~1\hexin\sslproxy\SSLCnt.exe [杭州核新软件技术有限公司])(N)



--------------------------------------------------------------------------------



服务

[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
("C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe")(Adobe Systems)
[AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
(d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe)(Anti-Malware Development a.s.)
[Human Interface Device Access / HidServ][Stopped/Disabled]
(C:\windows\System32\svchost.exe -k netsvcs--)%SystemRoot%\System32\hidserv.dll)(N/A)
[KVSrvXP / KVSrvXP][Running/Auto Start]
(D:\KV2006\KVSrvXP.exe /Service)(Jiangmin Co. Ltd)
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
(C:\windows\system32\nvsvc32.exe)(NVIDIA Corporation)
[Rising Proxy Service / RfwProxySrv][Stopped/Manual Start]
(e:\program files\rising\rfw\rfwproxy.exe)(Beijing Rising Technology Co., Ltd.)
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
(e:\program files\rising\rfw\rfwsrv.exe)(Beijing Rising Technology Co., Ltd.)
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd][Stopped/Manual Start]
("C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini")(N/A)
[Shadow System Service / ShadowSystemService][Running/Auto Start]
(C:\WINDOWS\system32\shadow\ShadowService.exe)(N/A)
[KVWSC / KVWSC][Running/Auto Start]
("D:\KV2006\kvwsc.exe")(Jiangmin Co.Ltd)



--------------------------------------------------------------------------------



驱动程序

[ADI UAA Function Driver for High Definition Audio Service / ADIHdAudAddService][Stopped/Manual Start]
(system32\drivers\ADIHdAud.sys)(N/A)
[AEAudio Service / AEAudioService][Stopped/Manual Start]
(system32\drivers\AEAudio.sys)(N/A)
[AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
(\??\d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys)(N/A)
[AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
(System32\DRIVERS\AvgAsCln.sys)(GRISOFT, s.r.o.)
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
(System32\DRIVERS\BaseTDI.SYS)(Beijing Rising Technology Co., Ltd.)
[Broadcom 440x 10/100 Integrated Controller XP Driver / bcm4sbxp][Running/Manual Start]
(system32\DRIVERS\bcm4sbxp.sys)(Broadcom Corporation)
[CALLKEY_IO / CALLKEY_IO][Stopped/Manual Start]
(\??\I:\CALLKEY.sys)(N/A)
[Cdsys / Cdsys][Stopped/Manual Start]
(\??\C:\WINDOWS\system32\cdcd.sys)(N/A)
[Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService][Running/Manual Start]
(system32\drivers\HdAudio.sys)(Windows (R) Server 2003 DDK provider)
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
(system32\DRIVERS\HDAudBus.sys)(Windows (R) Server 2003 DDK provider)
[HookUrl / HookUrl][Running/Auto Start]
(\??\E:\Program Files\Rising\Rfw\HookUrl.sys)(Beijing Rising Technology Co., Ltd.)
[KRegEx / KRegEx][Running/System Start]
(\??\D:\KV2006\KRegEx.sys)(Jiangmin Co. Ltd.)
[KSysCall Service / KSysCall][Running/System Start]
(\??\D:\KV2006\KSysCall.sys)(Jiangmin Co. Ltd.)
[KVDP_1 / KVDP_1][Running/Manual Start]
(\??\D:\KV2006\KVDP_1.sys)(Jiangmin Co., Ltd.)
[KvMemon / KvMemon][Running/Manual Start]
(\??\D:\KV2006\KvMemon.sys)(Jiangmin Co. Ltd.)
[KVREDIR / KVREDIR][Running/System Start]
(\??\D:\KV2006\KVREDIR.sys)(Jiangmin Co. Ltd)
[mProcRs / mProcRs][Running/Auto Start]
(\??\e:\program files\rising\rfw\mProcRs.sys)(Beijing Rising Technology Co., Ltd.)
[NetGroup Packet Filter Driver / NPF][Stopped/Manual Start]
(system32\drivers\npf.sys)(Politecnico di Torino)
[npkcrypt / npkcrypt][Running/Auto Start]
(\??\E:\Program Files\Tencent\QQ1\npkcrypt.sys)(INCA Internet Co., Ltd.)
[npkycryp / npkycryp][Stopped/Manual Start]
(\??\D:\Program Files\Tencent\QQ\npkycryp.sys)(N/A)
[nv / nv][Running/Manual Start]
(system32\DRIVERS\nv4_mini.sys)(NVIDIA Corporation)
[PProtect / PProtect][Running/System Start]
(\??\D:\KV2006\PProtect.sys)(Jiangmin Co. Ltd.)
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
(system32\DRIVERS\ptilink.sys)(Parallel Technologies, Inc.)
[RsFwDrv / RsFwDrv][Running/Auto Start]
(\??\E:\Program Files\Rising\Rfw\RsFwDrv.sys)(Beijing Rising Technology Co., Ltd.)
[Secdrv / Secdrv][Stopped/Manual Start]
(system32\DRIVERS\secdrv.sys)(N/A)
[SenFilt Service / SenFiltService][Stopped/Manual Start]
(system32\drivers\Senfilt.sys)(N/A)
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
(system32\DRIVERS\tcpip.sys)(Microsoft Corporation)
[UnlockerDriver4 Driver / UnlockerDriver4][Stopped/Manual Start]
(\??\C:\Program Files\Unlocker\UnlockerDriver4.sys)(N/A)
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
(system32\DRIVERS\WSTCODEC.SYS)(Microsoft Corporation)
[XPROTECTOR / XPROTECTOR][Running/Auto Start]
(\??\C:\WINDOWS\system32\drivers\XPROTECTOR.SYS)(N/A)
[VIMICRO USB PC Camera (ZC0301PLH) / ZSMC303][Running/Manual Start]
(System32\Drivers\usbVM303.sys)(Vimicro Corporation)
[RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]
(\SystemRoot\system32\drivers\RsBoot.sys)(Beijing Rising)
xnthc
 楼主| 发表于 2007-2-6 19:09:48 | 显示全部楼层
浏览器加载项

[Thunder Browser Helper]
{06849E9E-C8D7-4D59-B87D-784B7D6BE0B3} (D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD)
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (d:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated)
[VnetCookie Class]
{4E83D567-4697-4F7B-B1F0-A513B01DB89A} (c:\PROGRA~1\chinanet\VNETTR~1.DLL, )
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} (D:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD)
[新浪UC]
{2253922F-1B26-4C74-8B57-E3AEE748DBB8} (, N/A)
[联想]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} (http://www.lenovo.com, N/A)
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} (D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation)
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} (E:\Program Files\Tencent\QQ1\QQ.EXE, TENCENT)
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} (e:\Program Files\Tencent\QQ\QQIEHelper.dll, N/A)
[]
{e2e2dd38-d088-4134-82b7-f2ba38496583} (%windir%\Network Diagnostic\xpnetdiag.exe, N/A)
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} (C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation)
[江民杀毒工具栏]
{B5A34A93-D538-43A7-8371-864CB6148D12} (D:\KV2006\KvShell.dll, Jiangmin Co.Ltd)
[金山快译(&K)]
{6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} (d:\Program Files\Kingsoft\FastAIT 2006\IEBand.dll, 金山软件股份有限公司)
[PowerPlr Control]
{2354A44B-3CEB-4829-9940-545B03103538} (D:\PowerPlr.ocx, Powerise Digital)
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} (C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation)
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\windows\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.)
[Thunder Browser Helper]
{06849E9E-C8D7-4D59-B87D-784B7D6BE0B3} (D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD)
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (d:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated)
[Fade]
{16B280C5-EE70-11D1-9066-00C04FD9189D} (C:\windows\system32\Dxtmsft.dll, Microsoft Corporation)
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} (C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation)
[PowerPlr Control]
{2354A44B-3CEB-4829-9940-545B03103538} (D:\PowerPlr.ocx, Powerise Digital)
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} (C:\windows\system32\mshtml.dll, Microsoft Corporation)
[XML DOM Document]
{2933BF90-7B36-11D2-B20E-00C04F983E60} (%SystemRoot%\system32\msxml3.dll, N/A)
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} (C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation)
[Tabular Data Control]
{333C7BC4-460F-11D0-BC04-0080C7055A83} (C:\windows\system32\tdc.ocx, Microsoft Corporation)
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} (D:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_007.dll, Thunder Networking Technologies,LTD)
[VnetCookie Class]
{4E83D567-4697-4F7B-B1F0-A513B01DB89A} (c:\PROGRA~1\chinanet\VNETTR~1.DLL, )
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} (C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation)
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} (C:\windows\system32\ieframe.dll, Microsoft Corporation)
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} (C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation)
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[金山快译(&K)]
{6C3797D2-3FEF-4CD4-B654-D3AE55B4128C} (d:\Program Files\Kingsoft\FastAIT 2006\IEBand.dll, 金山软件股份有限公司)
[MediaComm Class]
{7670648D-461B-42AF-BDFE-46D26AF5EFF2} (D:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin11.dll, Thunder Networking Technologies,LTD)
[Microsoft Web Browser]
{8856F961-340A-11D0-A96B-00C04FD705A2} (C:\windows\system32\ieframe.dll, Microsoft Corporation)
[RMGetLicense Class]
{A9FC132B-096D-460B-B7D5-1DB0FAE0C062} (C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation)
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} (%SystemRoot%\system32\shdocvw.dll, N/A)
[江民杀毒工具栏]
{B5A34A93-D538-43A7-8371-864CB6148D12} (D:\KV2006\KvShell.dll, Jiangmin Co.Ltd)
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} (C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation)
[E:\Program Files\Tencent\QQ12\qqplayerproxy.dll]
{CD108273-D434-43E6-AA90-1469F97EB398} (E:\PROGRA~1\Tencent\QQ12\QQPLAY~1.DLL, Tencent)
[AUDIO__MP3 Moniker Class]
{CD3AFA76-B84F-48F0-9393-7EDC34128127} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[VIDEO__X_MS_WMV Moniker Class]
{CD3AFA94-B84F-48F0-9393-7EDC34128127} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} (C:\windows\system32\rmoc3260.dll, RealNetworks, Inc.)
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\windows\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.)
[XML HTTP Request]
{ED8C108E-4349-11D2-91A4-00C04F7969E8} (%SystemRoot%\system32\msxml3.dll, N/A)
[XML DOM Document]
{F6D90F11-9C73-11D3-B32E-00C04F990BB4} (%SystemRoot%\system32\msxml3.dll, N/A)
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} (%SystemRoot%\system32\msxml3.dll, N/A)
[ 添加到新浪点点通阅读器]
(res://D:\Program Files\Sina\RssReader\rssreader.exe/RSSFEED.js, N/A)
[&使用迅雷下载]
(D:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A)
[&使用迅雷下载全部链接]
(D:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A)
[导出到 Microsoft Office Excel(&X)]
(res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A)
[用比特精灵下载(&B)]
(D:\Program Files\BitSpirit\bsurl.htm, N/A)



--------------------------------------------------------------------------------



正在运行的进程

[PID: 328][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 448][\??\C:\windows\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 472][\??\C:\windows\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 516][C:\windows\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 528][C:\windows\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 696][C:\windows\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 748][C:\windows\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 788][C:\windows\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 940][C:\windows\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 960][C:\windows\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 996][e:\program files\rising\rfw\rfwsrv.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 33]
[e:\program files\rising\rfw\RfwRule.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 3]
[e:\program files\rising\rfw\rfwlog.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 2]
[e:\program files\rising\rfw\Rfwdrv.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 10]
[e:\program files\rising\rfw\MonDrv.dll] [rs, 1, 0, 0, 4]
[e:\program files\rising\rfw\ProcLib.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 5]
[e:\program files\rising\rfw\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[PID: 1232][C:\windows\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1432][C:\windows\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[d:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.10.8415]
[C:\windows\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.10.8415]
[D:\KV2006\KvShell.dll] [Jiangmin Co.Ltd, 9, 0, 5, 830]
[D:\KV2006\UpdateX.dll] [JiangMin Co.Ltd., 9, 0, 5, 831]
[D:\KV2006\lang\Kvxp0804.lng] [N/A, N/A]
[D:\KV2006\APIImpl.dll] [JiangMin Ltd., 9.0.0.500]
[C:\WINDOWS\system32\nvshell.dll] [N/A, N/A]
[D:\KV2006\KVHookG.dll] [Jiangmin Co.Ltd, 9.0.0.1226]
[d:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\windows\system32\KIme.ime] [金山软件公司, 1, 0, 0, 1]
[C:\windows\system32\FREEWB.IME] [Delphi Fan Studio, 5.1]
[d:\Program Files\freewb\plugin\date.plg] [, 1, 0, 0, 1]
[d:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
[d:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.7.2006011200]
[d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll] [Anti-Malware Development a.s., 7, 5, 0, 49]
[d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll] [Anti-Malware Development a.s., 7, 5, 0, 47]
[PID: 1500][e:\program files\rising\rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 70]
[e:\program files\rising\rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[e:\program files\rising\rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[e:\program files\rising\rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[e:\program files\rising\rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[e:\program files\rising\rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[D:\KV2006\KVHookG.dll] [Jiangmin Co.Ltd, 9.0.0.1226]
[d:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1636][D:\KV2006\KVSrvXP.exe] [Jiangmin Co. Ltd, 9.2.0.50822]
[D:\KV2006\UpdateX.dll] [JiangMin Co.Ltd., 9, 0, 5, 831]
[D:\KV2006\SvcSafe.dll] [Jiangmin Co. Ltd, 9, 2, 0, 51107]
[D:\KV2006\lang\SvcSafe0804.lng] [N/A, N/A]
[D:\KV2006\RegProt.dll] [Jiangmin Co.Ltd, 9, 0, 5, 1212]
[D:\KV2006\Scan_1.dll] [Jiangmin Co., Ltd., 1.0.6.07110]
[D:\KV2006\FileGD.dll] [Jiangmin Co.Ltd, 9.2.0.50809]
[D:\KV2006\KvSPI.dll] [Jiangmin Co. Ltd., 1.0.6.1024]
[D:\KV2006\lang\KvSPI0804.lng] [N/A, N/A]
[D:\KV2006\ScanHost.dll] [Jiangmin Co. Ltd, 9, 2, 0, 50822]
[D:\KV2006\KVWPSet.dll] [Jiangmin Co.Ltd, 9, 0, 0, 60220]
[D:\KV2006\EngPS.dll] [Jiangmin Co.Ltd, 9, 2, 0, 50817]
[D:\KV2006\KVEnhS.dll] [Jiangmin Co., Ltd., 9, 2, 6, 02040]
[D:\KV2006\KVEnhJ.dll] [Jiangmin Co.Ltd, 9, 1, 0, 50822]
[D:\KV2006\KVExtCab.dll] [JiangMin Co. Ltd, 9, 2, 0, 50822]
[D:\KV2006\KVExtLZH.dll] [JiangMin Co. Ltd., 9, 2, 6, 0316]
[D:\KV2006\KvExtRar.dll] [JiangMin Co. Ltd., 9, 2, 6, 04020]
[D:\KV2006\KvExtZip.dll] [JiangMin Co Ltd., 9, 2, 0, 50822]
[D:\KV2006\KVExtZ.dll] [Jiangmin Co. Ltd, 9.2.0.503]
[D:\KV2006\KVExtTar.dll] [Jiangmin Co. Ltd, 9, 2, 0, 50822]
[D:\KV2006\KVExtEml_1.dll] [Jiangmin Co. Ltd., 9, 2, 6, 07050]
[D:\KV2006\KVExtGz_1.dll] [Jiangmin Co. Ltd, 9, 0, 6, 04200]
[D:\KV2006\KVEnhK.dll] [Jiangmin Co.Ltd, 9, 1, 0, 51209]
[D:\KV2006\Fix_1.dll] [Jiangmin Co.Ltd, 9, 2, 6, 07110]
[D:\KV2006\KvCkMail.dll] [N/A, 9, 0, 6, 619]
[D:\KV2006\lang\KvMailRes0804.lng] [N/A, N/A]
[D:\KV2006\lang\PrivateCfg0804.lng] [TODO: (Company name), 1.0.0.1]
[PID: 1768][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE] [Microsoft Corporation, 7.00.9466]
[PID: 1800][C:\windows\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.8415]
[PID: 1832][C:\WINDOWS\system32\shadow\ShadowService.exe] [N/A, N/A]
[PID: 1856][C:\windows\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1884][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[D:\KV2006\KVMonXP_1.kxp] [Jiangmin Co.Ltd, 9, 2, 0, 60905]
[D:\KV2006\UpdateX.dll] [JiangMin Co.Ltd., 9, 0, 5, 831]
[D:\KV2006\lang\Kvxp0804.lng] [N/A, N/A]
[D:\KV2006\GUIExt.dll] [Jiangmin Co.Ltd, 9, 0, 5, 927]
[D:\KV2006\lang\GUIExt0804.lng] [JiangMin Ltd., 7, 1, 0, 200]
[D:\KV2006\EngFace.dll] [Jiangmin Co.Ltd, 9.0.0.50809]
[D:\KV2006\EngPS.dll] [Jiangmin Co.Ltd, 9, 2, 0, 50817]
[D:\KV2006\KvMemory.dll] [Jiangmin Co. Ltd., 9, 0, 6, 0214]
[D:\KV2006\KvOffice.dll] [JiangMin New Tech., 9.0.0.1213]
[D:\KV2006\lang\KVOffice0804.lng] [N/A, N/A]
[D:\KV2006\VirusUpload.dll] [N/A, 2, 16, 6, 7260]
[D:\KV2006\KVHookG.dll] [Jiangmin Co.Ltd, 9.0.0.1226]
[D:\KV2006\PProtect.dll] [Jiangmin Co. Ltd., 9.0.0.921]
[d:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 272][D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe] [Anti-Malware Development a.s., 7, 5, 0, 50]
[D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll] [Anti-Malware Development a.s., 4, 2, 0, 15]
[D:\KV2006\KVHookG.dll] [Jiangmin Co.Ltd, 9.0.0.1226]
[d:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 280][C:\WINDOWS\VM303_STI.EXE] [Vimicro, 4, 3, 625, 61]
[C:\windows\system32\msdmo.dll] [N/A, N/A]
[C:\windows\system32\VM303Prp.Ax] [Vimicro, 4.3. 625.61]
[D:\KV2006\KVHookG.dll] [Jiangmin Co.Ltd, 9.0.0.1226]
[d:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 396][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3760]
[D:\KV2006\KVHookG.dll] [Jiangmin Co.Ltd, 9.0.0.1226]
[d:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 404][C:\windows\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\KV2006\KVHookG.dll] [Jiangmin Co.Ltd, 9.0.0.1226]
[d:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2056][C:\windows\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\KV2006\TrojDie.kxp] [Jiangmin Co.Ltd, 9.0.6.0413]
[D:\KV2006\UpdateX.dll] [JiangMin Co.Ltd., 9, 0, 5, 831]
[D:\KV2006\lang\TrojDie0804.lng] [Jiangmin Co.Ltd, 9.0.0.0813]
[D:\KV2006\GUIExt.dll] [Jiangmin Co.Ltd, 9, 0, 5, 927]
[D:\KV2006\lang\GUIExt0804.lng] [JiangMin Ltd., 7, 1, 0, 200]
[D:\KV2006\PProtect.dll] [Jiangmin Co. Ltd., 9.0.0.921]
[D:\KV2006\KVHookG.dll] [Jiangmin Co.Ltd, 9.0.0.1226]
[D:\KV2006\ComUIPS.dll] [Jiangmin Ltd., 9. 5. 5. 20]
[d:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[D:\KV2006\KVWPSet.dll] [Jiangmin Co.Ltd, 9, 0, 0, 60220]
[PID: 2588][D:\KV2006\KRegEx.exe] [Jiangmin Co.Ltd, 9.0.6.210]
[D:\KV2006\KRegEx.dll] [Jiangmin Co. Ltd., 9.0.6.0119]
[D:\KV2006\KRegTrust.dll] [Jiangmin Co. Ltd., 9.0.0.825]
[D:\KV2006\KVHookG.dll] [Jiangmin Co.Ltd, 9.0.0.1226]
[d:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2728][D:\KV2006\UIHost.exe] [Jiangmin Co. Ltd, 9.2.0.50822]
[D:\KV2006\KVHookG.dll] [Jiangmin Co.Ltd, 9.0.0.1226]
[D:\KV2006\UpdateX.dll] [JiangMin Co.Ltd., 9, 0, 5, 831]
[D:\KV2006\ComUI.dll] [Jiangmin Ltd., 9. 0. 0.509]
[D:\KV2006\ComUIPS.dll] [Jiangmin Ltd., 9. 5. 5. 20]
[D:\KV2006\GUIExt.dll] [Jiangmin Co.Ltd, 9, 0, 5, 927]
[D:\KV2006\lang\GUIExt0804.lng] [JiangMin Ltd., 7, 1, 0, 200]
[d:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 632][D:\KV2006\kvwsc.exe] [Jiangmin Co.Ltd, 9, 0, 5, 908]
[D:\KV2006\EngPS.dll] [Jiangmin Co.Ltd, 9, 2, 0, 50817]
[D:\KV2006\EngFace.dll] [Jiangmin Co.Ltd, 9.0.0.50809]
[D:\KV2006\UpdateX.dll] [JiangMin Co.Ltd., 9, 0, 5, 831]
[PID: 2268][d:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
[d:\Program Files\Rising\AntiSpyware\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[d:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[D:\KV2006\KVHookG.dll] [Jiangmin Co.Ltd, 9.0.0.1226]
[PID: 3516][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
[D:\KV2006\KVHookG.dll] [Jiangmin Co.Ltd, 9.0.0.1226]
[d:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
[d:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.7.2006011200]
[c:\PROGRA~1\chinanet\VNETTR~1.DLL] [, 2005, 4, 6, 1]
[c:\PROGRA~1\chinanet\Communicate.dll] [0, 2005, 3, 3, 1]
[C:\PROGRA~1\ChinaNet\CLIENT~1.DLL] [, 2004, 2, 28, 1]
[C:\windows\system32\KIme.ime] [金山软件公司, 1, 0, 0, 1]
[C:\windows\system32\FREEWB.IME] [Delphi Fan Studio, 5.1]
[d:\Program Files\freewb\plugin\date.plg] [, 1, 0, 0, 1]
[PID: 3496][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sreng2.zip 的临时目录 1\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[D:\KV2006\KVHookG.dll] [Jiangmin Co.Ltd, 9.0.0.1226]
[d:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]



--------------------------------------------------------------------------------



文件关联

.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]



--------------------------------------------------------------------------------



Winsock 提供者

N/A



--------------------------------------------------------------------------------



Autorun.inf

N/A



--------------------------------------------------------------------------------



HOSTS 文件

127.0.0.1 localhost



--------------------------------------------------------------------------------



API HOOK

警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
入口点错误:CreateRemoteThread
xnthc
 楼主| 发表于 2007-2-6 19:31:30 | 显示全部楼层
原帖由 jimmyleo 于 2007-2-6 15:22 发表
断网 貌似是魔波的影响吧

到微软安全公告里找找06-040

http://www.microsoft.com/china/technet/security/current.mspx

打下补丁试试

不是补丁是("C:\WINDOWS\wpablin.exe")(N/A)
删了就好了!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-8 07:28 , Processed in 0.130100 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表