本帖最后由 shaojie_ 于 2010-5-17 12:14 编辑
百度搜到的一些方法看不太懂。如果有这方面的工具,请写个详细的使用步骤,因为我这里被这个软体祸害的人很多,相当的多。
- 2010-05-17,11:32:06
- SysLog Scanner 3.0 - build 20091220
- Arswp (http://www.arswp.com)
- Windows XP Professional Service Pack 3 (build 2600)
- ================================================================
- 注册项
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- <McAfeeUpdaterUI> <"C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey> [(Verified)McAfee, Inc., 4.0.0.1496]
- <ShStatEXE> <"C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE> [(Verified)McAfee, Inc., 8.7.0.767]
- <igfxtray> <C:\WINDOWS\system32\igfxtray.exe> [(Verified)Intel Corporation, 3.0.0.4396]
- <igfxhkcmd> <C:\WINDOWS\system32\hkcmd.exe> [(Verified)Intel Corporation, 3.0.0.4396]
- <UDS> <"C:\Program Files\ZTE UDS\TrayManager\ControlCenter.exe" -NotShowVPN> [ZTE Corporation, 1.0.0.1674]
- <VStart5.0> <"D:\工具软件\音速启动\VStart.exe"> [3L软件工作室(3LSoft), 5.08.1225]
- <Windows XPlan> <E:\工具\台历\TaskXP.exe> [N/A]
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
- <load> <> []
- [HKEY_CURRENT_USER\Control Panel\Desktop]
- <ScrnSAVE.EXE> <C:\WINDOWS\system32\yowindow.scr> [repkasoft, 1, 0, 0, 0]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
- <igfxcui> <igfxdev.dll> [(Verified)Intel Corporation, 3.0.0.4396]
- <ZTE UC> <D:\工具软件\IM9.0\ZTE IM9\IMHelper.dll> [N/A]
- ================================================================
- 启动组
- ================================================================
- 任务计划
- [GlaryOneClickOptimizer.job]
- <C:\WINDOWS\tasks\GlaryOneClickOptimizer.job> <"D:\工具软件\Glary Utilities\oneclickoptimizer.exe" /schedulestart> [(Verified)Glarysoft Ltd, 2.22.0.896]
- [GlaryInitialize.job]
- <C:\WINDOWS\tasks\GlaryInitialize.job> <"D:\工具软件\Glary Utilities\initialize.exe" > [(Verified)Glarysoft Ltd, 2.22.0.896]
- ================================================================
- 组件
- --------------------------------
- Shell Extension
- [Display Panning CPL Extension]
- <{42071714-76d4-11d1-8b24-00a0c9068ff3}> <deskpan.dll> []
- [任务栏和「开始」菜单]
- <{0DF44EAA-FF21-4412-828E-260A8728E7F1}> <> []
- [WinRAR shell extension]
- <{B41DB860-8EE4-11D2-9906-E49FADC173CA}> <D:\工具软件\压缩工具\rarext.dll> [N/A]
- [HashTab Property Page]
- <{8A56567E-A333-4843-B6E1-C3A262E41D8C}> <C:\WINDOWS\system32\HashTab32.dll> [Beeblebrox.org, 3.0.0.0]
- [UnlockerShellExtension]
- <{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}> <D:\工具软件\unlock\UnlockerCOM.dll> [N/A]
- [7-Zip Shell Extension]
- <{23170F69-40C1-278A-1000-000100020000}> <D:\工具软件\压缩工具\7-Zip\7-Zip.dll> [Igor Pavlov, 9.13 beta]
- [Glary Utilities Context Menu Shell Extension]
- <{72923739-5A47-40A3-9895-25AF0DFBB9E4}> <D:\工具软件\GLARYU~1\CONTEX~1.DLL> [(Verified)Glarysoft Ltd, 2.22.0.896]
- --------------------------------
- Context Menu
- [7-Zip]
- <{23170F69-40C1-278A-1000-000100020000}> <D:\工具软件\压缩工具\7-Zip\7-Zip.dll> [Igor Pavlov, 9.13 beta]
- [Glary Utilities]
- <{72923739-5A47-40A3-9895-25AF0DFBB9E4}> <D:\工具软件\GLARYU~1\CONTEX~1.DLL> [(Verified)Glarysoft Ltd, 2.22.0.896]
- [VirusScan]
- <{cda2863e-2497-4c49-9b89-06840e070a87}> <C:\Program Files\McAfee\VirusScan Enterprise\shext.dll> [(Verified)McAfee, Inc., 8.7.0.570]
- [WinRAR]
- <{B41DB860-8EE4-11D2-9906-E49FADC173CA}> <D:\工具软件\压缩工具\rarext.dll> [N/A]
- [UnlockerShellExtension]
- <{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}> <D:\工具软件\unlock\UnlockerCOM.dll> [N/A]
- [igfxcui]
- <{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4}> <C:\WINDOWS\system32\igfxpph.dll> [(Verified)Intel Corporation, 3.0.0.4396]
- --------------------------------
- BrowserHelperObject
- [scriptproxy]
- <{7DB2D5A0-7241-4E79-B68D-6309F01C5231}> <C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll> [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- --------------------------------
- ActiveX Extension
- [Edit Class]
- <{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D}> <C:\WINDOWS\system32\CMBEdit.dll> [(Verified)Copyright 2004, 1, 2, 0, 3]
- [scriptproxy]
- <{7DB2D5A0-7241-4E79-B68D-6309F01C5231}> <C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll> [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- [Shockwave Flash Object]
- <{D27CDB6E-AE6D-11CF-96B8-444553540000}> <C:\WINDOWS\system32\macromed\flash\Flash.ocx> [(Verified)Adobe Systems, Inc., 9,0,124,0]
- ================================================================
- 服务
- [Human Interface Device Access / HidServ][Stopped/Disabled]
- <%SystemRoot%\System32\svchost.exe -k netsvcs --> "%SystemRoot%\System32\hidserv.dll"> [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
- [Lotus Notes 诊断 / Lotus Notes Diagnostics][Stopped/Manual Start]
- <"C:\Program Files\IBM\Lotus\Notes\nsd.exe" -svcinvoke -ini "C:\Program Files\IBM\Lotus\Notes\notes.ini"> [(Verified)IBM, 8.5.10.9243 | N/A]
- [System Boot Service / SystemBootService][Running/Auto Start]
- <"C:\WINDOWS\system32\sysagboot.exe"> [3, 0, 0, 1214]
- [TCO!stream Client Service / TClientService][Running/Manual Start]
- <"C:\Program Files\TCOstream\Client\tclient.exe"> [Medialand, Inc., 6, 5, 8, 812]
- [TCO!stream Control Service / TControlService][Running/Auto Start]
- <"C:\Program Files\TCOstream\Client\tsrvctl_nt.exe"> [Medialand, Inc, 7, 0, 8, 527]
- [VRVWatchServer / VRVWatchServer][Running/Auto Start]
- <"C:\WINDOWS\system32\WatchClient.exe" -service> [6, 6, 24, 40]
- [McAfee Engine Service / McAfeeEngineService][/Auto Start]
- <"C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe"> [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- [McAfee Framework 服务 / McAfeeFramework][/Auto Start]
- <"C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart> [(Verified)McAfee, Inc., 4.0.0.1496]
- [McAfee McShield / McShield][/Auto Start]
- <"C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe"> [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- [McAfee Task Manager / McTaskManager][/Auto Start]
- <"C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe"> [(Verified)McAfee, Inc., 8.7.0.767]
- [McAfee Validation Trust Protection Service / mfevtp][/Auto Start]
- <C:\WINDOWS\system32\mfevtps.exe> [(Verified)McAfee, Inc., SYSCORE.14.1.0.615.x86]
- [Multi-user Cleanup Service / Multi-user Cleanup Service][Running/Auto Start]
- <"C:\Program Files\IBM\Lotus\Notes\ntmulti.exe"> [(Verified)IBM Corp, 8.5.10.9271]
- [Remote Packet Capture Protocol v.0 (experimental) / rpcapd][Stopped/Manual Start]
- <"%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini"> [(Verified)CACE Technologies, 4.0.0.755]
- [System Loader / SystemLoader][Stopped/Auto Start]
- <C:\WINDOWS\system32\SysLoader.exe> [(Verified)Medialand, Inc, 7, 1, 8, 805]
- ================================================================
- 驱动
- [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
- <system32\drivers\ALCXWDM.SYS> [Realtek Semiconductor Corp., 5.10.00.6300 built by: WinDDK]
- [Virtual Drive / VirtualDrive][Stopped/Manual Start]
- <\??\E:\装机必备\虚拟光驱U盘\vdd-x86.sys> [Towodo Software, 1.3.1]
- [ialm / ialm][Running/Manual Start]
- <system32\DRIVERS\ialmnt5.sys> [(Verified)Intel Corporation, 6.14.10.4396]
- [McAfee Inc. mfeapfk / mfeapfk][Running/Manual Start]
- <system32\drivers\mfeapfk.sys> [(Verified)McAfee, Inc., SYSCORE.14.1.0.615.x86]
- [McAfee Inc. mfeavfk / mfeavfk][Running/Manual Start]
- <system32\drivers\mfeavfk.sys> [(Verified)McAfee, Inc., SYSCORE.14.1.0.615.x86]
- [McAfee Inc. mfebopk / mfebopk][Stopped/Manual Start]
- <system32\drivers\mfebopk.sys> [(Verified)McAfee, Inc., SYSCORE.14.1.0.615.x86]
- [McAfee Inc. mfehidk / mfehidk][Running/Boot Start]
- <system32\drivers\mfehidk.sys> [(Verified)McAfee, Inc., SYSCORE.14.1.0.615.x86]
- [McAfee Inc. mferkdet / mferkdet][Stopped/Manual Start]
- <system32\drivers\mferkdet.sys> [(Verified)McAfee, Inc., SYSCORE.14.1.0.615.x86]
- [McAfee Inc. mfetdik / mfetdik][Running/System Start]
- <system32\drivers\mfetdik.sys> [(Verified)McAfee, Inc., SYSCORE.14.1.0.615.x86]
- [NetGroup Packet Filter Driver / NPF][Stopped/Manual Start]
- <system32\drivers\npf.sys> [(Verified)CACE Technologies, 4.0.0.755]
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
- <system32\DRIVERS\ptilink.sys> [(Verified)Parallel Technologies, Inc., 1.10 (XPClient.010817-1148)]
- [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
- <system32\DRIVERS\RTL8139.SYS> [(Verified)Realtek Semiconductor Corporation, 5.398.613.2003 built by: WinDDK]
- [Secdrv / Secdrv][Stopped/Manual Start]
- <system32\DRIVERS\secdrv.sys> [(Verified)Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., 4.03.086]
- ================================================================
- 活动进程
- [PID: 552 / SYSTEM] \??\C:\WINDOWS\system32\winlogon.exe [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
- C:\WINDOWS\system32\sfc_os.dll [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\vrvhook.dll [Microsoft Corporation, 9, 5, 25, 16]
- D:\工具软件\IM9.0\ZTE IM9\IMHelper.dll [N/A]
- C:\WINDOWS\system32\igfxdev.dll [(Verified)Intel Corporation, 3.0.0.4396]
- [PID: 608 / SYSTEM] C:\WINDOWS\system32\lsass.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
- C:\WINDOWS\system32\UxTheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 764 / SYSTEM] C:\WINDOWS\system32\svchost.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
- C:\WINDOWS\system32\UxTheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\vrvhook.dll [Microsoft Corporation, 9, 5, 25, 16]
- [PID: 812 / NETWORK SERVICE] C:\WINDOWS\system32\svchost.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
- C:\WINDOWS\system32\UxTheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\vrvhook.dll [Microsoft Corporation, 9, 5, 25, 16]
- [PID: 880 / SYSTEM] C:\WINDOWS\System32\svchost.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
- C:\WINDOWS\System32\UxTheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\vrvhook.dll [Microsoft Corporation, 9, 5, 25, 16]
- C:\WINDOWS\System32\sfc_os.dll [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
- [PID: 924 / NETWORK SERVICE] C:\WINDOWS\system32\svchost.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
- C:\WINDOWS\system32\UxTheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\vrvhook.dll [Microsoft Corporation, 9, 5, 25, 16]
- [PID: 1004 / LOCAL SERVICE] C:\WINDOWS\system32\svchost.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
- C:\WINDOWS\system32\UxTheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\vrvhook.dll [Microsoft Corporation, 9, 5, 25, 16]
- [PID: 1016 / SYSTEM] C:\WINDOWS\system32\WatchClient.exe [6, 6, 24, 40]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\vrvhook.dll [Microsoft Corporation, 9, 5, 25, 16]
- [PID: 1136 / SYSTEM] C:\WINDOWS\system32\vrvrf_c.exe [6, 6, 6, 48]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\vrvpwk.dll [版权所有 (C) 2005, 1, 0, 0, 1]
- C:\WINDOWS\system32\vrvedp_m.dll [版权所有 (C) 2007, 1, 0, 3, 0]
- C:\WINDOWS\system32\edpaudfliter.dll [版权所有 (C) 2006, 1, 0, 0, 1]
- [PID: 1144 / SYSTEM] C:\WINDOWS\system32\VrvEdp_m.exe [6, 6, 21, 3615]
- C:\WINDOWS\system32\maindll.dll [版权所有 (C) 2009, 6, 6, 1, 208]
- C:\WINDOWS\system32\TestPop.dll [版权所有 (C) 2009, 6, 6, 1, 208]
- C:\WINDOWS\system32\FileTypedll.dll [版权所有 (C) 2009, 6, 6, 1, 208]
- C:\WINDOWS\system32\unrar.dll [N/A]
- C:\WINDOWS\system32\LITEUNZIP.dll [0, 0, 0, 2]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\Cipherop.dll [Cipherop, 6, 6, 18, 17]
- [PID: 1176 / SYSTEM] C:\WINDOWS\system32\spoolsv.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
- C:\WINDOWS\system32\UxTheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\vrvhook.dll [Microsoft Corporation, 9, 5, 25, 16]
- C:\WINDOWS\system32\sfc_os.dll [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
- [PID: 1336 / SYSTEM] C:\WINDOWS\system32\vrvsafec.exe [edp, 9, 5, 25, 16]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\vrvhook.dll [Microsoft Corporation, 9, 5, 25, 16]
- [PID: 1596 / SYSTEM] C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\mytilus3_worker.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\mytilus3_server.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\LockDown.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\RES0402\McShield.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515]
- [PID: 1624 / SYSTEM] C:\Program Files\McAfee\Common Framework\FrameworkService.exe [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\nailog3.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\WINDOWS\system32\MSVCR71.dll [Microsoft Corporation, 7.10.3052.4]
- C:\Program Files\McAfee\Common Framework\naxml3_71.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\WINDOWS\system32\MSVCP71.dll [Microsoft Corporation, 7.10.3077.0]
- C:\Program Files\McAfee\Common Framework\naCmnLib3_71.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\applib.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\cryptocme2.dll [N/A]
- C:\Program Files\McAfee\Common Framework\0804\AgentRes.dll [McAfee, Inc., 4.0.0.1148]
- C:\Program Files\McAfee\Common Framework\Logging.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\UserSpace.Dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\SecureFrameworkFactory3.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\Management.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\naPolicyManager.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\UpdateSubSys.Dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\updater.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\ipcchannel.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\boost_thread-vc71-mt-1_32.dll [N/A]
- C:\Program Files\McAfee\Common Framework\mfeCmnLib71.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\Scheduler.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\Agent.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\nainet.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\mfecurl.dll [(Verified)McAfee, Inc., 1.0.0.151]
- C:\Program Files\McAfee\Common Framework\mfezlib.dll [(Verified)McAfee, Inc., 1.0.0.151]
- C:\Program Files\McAfee\Common Framework\inetmgr.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\naSPIPE.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\cmalib.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\ListenServer.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\Program Files\McAfee\Common Framework\TCSubSys.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\Genevtinf3.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- [PID: 1660 / SYSTEM] C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe [(Verified)McAfee, Inc., 8.7.0.767]
- C:\Program Files\McAfee\VirusScan Enterprise\LockDown.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\mytilus3_worker.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\shutil.dll [(Verified)McAfee, Inc., 8.7.0.747]
- C:\Program Files\McAfee\VirusScan Enterprise\wmain.dll [McAfee, Inc., 8.7.0.747]
- C:\Program Files\McAfee\VirusScan Enterprise\condl.dll [(Verified)McAfee, Inc., 8.7.0.570]
- C:\Program Files\McAfee\VirusScan Enterprise\RES0402\McShield.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515]
- C:\Program Files\McAfee\VirusScan Enterprise\MIDUtil.Dll [(Verified)McAfee, Inc., 8.7.0.133]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\Program Files\McAfee\VirusScan Enterprise\BBCpl.dll [(Verified)McAfee, Inc., 8.7.0.747]
- C:\Program Files\McAfee\VirusScan Enterprise\coptcpl.dll [(Verified)McAfee, Inc., 8.7.0.747]
- C:\Program Files\McAfee\VirusScan Enterprise\EmCfgCpl.dll [(Verified)McAfee, Inc., 8.7.0.747]
- C:\Program Files\McAfee\VirusScan Enterprise\nvpcpl.dll [(Verified)McAfee, Inc., 8.7.0.570]
- C:\Program Files\McAfee\VirusScan Enterprise\ftcfg.dll [(Verified)McAfee, Inc., 8.7.0.659]
- C:\Program Files\McAfee\VirusScan Enterprise\mytilus3.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\OASCpl.dll [(Verified)McAfee, Inc., 8.7.0.570]
- C:\Program Files\McAfee\VirusScan Enterprise\QuarCpl.dll [(Verified)McAfee, Inc., 8.7.0.659]
- C:\Program Files\McAfee\VirusScan Enterprise\vsodscpl.dll [(Verified)McAfee, Inc., 8.7.0.747]
- C:\Program Files\McAfee\VirusScan Enterprise\VsEvntUI.dll [(Verified)N/A]
- C:\Program Files\McAfee\VirusScan Enterprise\NAEvent.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\ftl.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\vsupdcpl.dll [(Verified)McAfee, Inc., 8.7.0.747]
- [PID: 1724 / SYSTEM] C:\WINDOWS\system32\mfevtps.exe [(Verified)McAfee, Inc., SYSCORE.14.1.0.615.x86]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 1744 / SYSTEM] C:\Program Files\McAfee\Common Framework\naPrdMgr.exe [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\naxml3_71.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\WINDOWS\system32\MSVCP71.dll [Microsoft Corporation, 7.10.3077.0]
- C:\WINDOWS\system32\MSVCR71.dll [Microsoft Corporation, 7.10.3052.4]
- C:\Program Files\McAfee\Common Framework\nailog3.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\naCmnLib3_71.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\applib.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\cryptocme2.dll [N/A]
- C:\WINDOWS\system32\VrvHook.dll [Microsoft Corporation, 9, 5, 25, 16]
- C:\Program Files\McAfee\Common Framework\0804\AgentRes.dll [McAfee, Inc., 4.0.0.1148]
- C:\Program Files\McAfee\Common Framework\agentplugin.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\mfeCmnLib71.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\VirusScan Enterprise\VsPlugin.dll [(Verified)McAfee, Inc., 8.7.0.747]
- C:\Program Files\McAfee\Common Framework\pcrplug.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\UpdPlug.Dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\SecureFrameworkFactory3.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- [PID: 1784 / SYSTEM] C:\Program Files\IBM\Lotus\Notes\ntmulti.exe [(Verified)IBM Corp, 8.5.10.9271]
- [PID: 1976 / SYSTEM] C:\WINDOWS\system32\sysagboot.exe [3, 0, 0, 1214]
- [PID: 2036 / SYSTEM] C:\Program Files\TCOstream\Client\tsrvctl_nt.exe [Medialand, Inc, 7, 0, 8, 527]
- [PID: 196 / SYSTEM] C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\LockDown.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\mytilus3.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\mytilus3_worker.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\mytilus3_server.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\RES0402\McShield.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515]
- C:\Program Files\McAfee\VirusScan Enterprise\FTL.Dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\Program Files\McAfee\VirusScan Enterprise\mfehida.dll [(Verified)McAfee, Inc., SYSCORE.14.1.0.615.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\mfeavfa.dll [(Verified)McAfee, Inc., SYSCORE.14.1.0.615.x86]
- C:\Program Files\Common Files\McAfee\Engine\mcscan32.dll [McAfee, Inc., 5.4.00]
- C:\Program Files\McAfee\VirusScan Enterprise\mfeapfa.dll [(Verified)McAfee, Inc., SYSCORE.14.1.0.615.x86]
- [PID: 256 / SYSTEM] C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\LockDown.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\naiann.dll [(Verified)McAfee, Inc., 8.7.0.659]
- C:\Program Files\McAfee\VirusScan Enterprise\mytilus3.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\mytilus3_worker.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\VsEvntUI.dll [(Verified)N/A]
- C:\Program Files\McAfee\VirusScan Enterprise\NAEvent.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\shutil.dll [(Verified)McAfee, Inc., 8.7.0.747]
- C:\Program Files\McAfee\VirusScan Enterprise\wmain.dll [McAfee, Inc., 8.7.0.747]
- C:\Program Files\McAfee\VirusScan Enterprise\RES0402\McShield.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515]
- C:\Program Files\McAfee\Common Framework\Genevtinf3.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- [PID: 1380 / SYSTEM] C:\Program Files\TCOstream\Client\tclient.exe [Medialand, Inc., 6, 5, 8, 812]
- C:\Program Files\TCOstream\Client\tchatcli.dll [Medialand, Inc., 4.6.1.423]
- C:\Program Files\TCOstream\Client\tsmproc.dll [Medialand, Inc., 7, 0, 8, 401]
- C:\Program Files\TCOstream\Client\tsmul.dll [Medialand, Inc., 4.5.2.620]
- C:\Program Files\TCOstream\Client\Tsmhook.dll [N/A]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\vrvhook.dll [Microsoft Corporation, 9, 5, 25, 16]
- [PID: 1480 / LOCAL SERVICE] C:\WINDOWS\System32\alg.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
- C:\WINDOWS\System32\UxTheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 2612 / dark] C:\WINDOWS\Explorer.EXE [(Verified)Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\UxTheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\VrvHook.dll [Microsoft Corporation, 9, 5, 25, 16]
- C:\Program Files\McAfee\Common Framework\JrMac.dll [(Verified)McAfee, Inc., 1.0.0.129]
- C:\WINDOWS\system32\maindll.dll [版权所有 (C) 2009, 6, 6, 1, 208]
- C:\WINDOWS\system32\TestPop.dll [版权所有 (C) 2009, 6, 6, 1, 208]
- C:\WINDOWS\system32\FileTypedll.dll [版权所有 (C) 2009, 6, 6, 1, 208]
- C:\WINDOWS\system32\unrar.dll [N/A]
- C:\WINDOWS\system32\LITEUNZIP.dll [0, 0, 0, 2]
- C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\mytilus3.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\mytilus3_worker.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\RES0402\McShield.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515]
- C:\WINDOWS\system32\SOGOUPY.IME [(Verified)Sogou.com Inc., 4.3.1.3416]
- C:\WINDOWS\system32\GOOGLEPINYIN2.IME [(Verified)Google Inc., 2.1.10.65]
- D:\工具软件\unlock\UnlockerCOM.dll [N/A]
- D:\工具软件\压缩工具\rarext.dll [N/A]
- C:\Program Files\McAfee\VirusScan Enterprise\shext.dll [(Verified)McAfee, Inc., 8.7.0.570]
- D:\工具软件\GLARYU~1\CONTEX~1.DLL [(Verified)Glarysoft Ltd, 2.22.0.896]
- D:\工具软件\GLARYU~1\rtl70.bpl [Borland Software Corporation, 7.0.4.453]
- D:\工具软件\GLARYU~1\vcl70.bpl [Borland Software Corporation, 7.0.4.453]
- D:\工具软件\压缩工具\7-Zip\7-Zip.dll [Igor Pavlov, 9.13 beta]
- C:\WINDOWS\system32\igfxpph.dll [(Verified)Intel Corporation, 3.0.0.4396]
- C:\WINDOWS\system32\hccutils.DLL [(Verified)Intel Corporation, 3.0.0.4396]
- C:\WINDOWS\system32\igfxres.dll [(Verified)Intel Corporation, 3.0.0.4396]
- C:\WINDOWS\system32\igfxress.dll [(Verified)Intel Corporation, 3.0.0.4396]
- C:\WINDOWS\system32\igfxsrvc.dll [(Verified)Intel Corporation, 3.0.0.4396]
- C:\WINDOWS\system32\shdoclc.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 2968 / dark] C:\Program Files\McAfee\Common Framework\udaterui.exe [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\nailog3.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\WINDOWS\system32\MSVCR71.dll [Microsoft Corporation, 7.10.3052.4]
- C:\Program Files\McAfee\Common Framework\naCmnLib3_71.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\naxml3_71.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\WINDOWS\system32\MSVCP71.dll [Microsoft Corporation, 7.10.3077.0]
- C:\Program Files\McAfee\Common Framework\applib.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\cmalib.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- C:\Program Files\McAfee\Common Framework\cryptocme2.dll [N/A]
- C:\WINDOWS\system32\VrvHook.dll [Microsoft Corporation, 9, 5, 25, 16]
- C:\Program Files\McAfee\Common Framework\0804\UpdRes.dll [McAfee, Inc., 4.0.0.1148]
- C:\Program Files\McAfee\Common Framework\0804\AgentRes.dll [McAfee, Inc., 4.0.0.1148]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\Program Files\McAfee\Common Framework\SecureFrameworkFactory3.dll [(Verified)McAfee, Inc., 4.0.0.1496]
- [PID: 2992 / dark] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE [(Verified)McAfee, Inc., 8.7.0.767]
- C:\Program Files\McAfee\VirusScan Enterprise\LockDown.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\ftcfg.dll [(Verified)McAfee, Inc., 8.7.0.659]
- C:\Program Files\McAfee\VirusScan Enterprise\mytilus3.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\mytilus3_worker.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515.x86]
- C:\Program Files\McAfee\VirusScan Enterprise\wmain.dll [McAfee, Inc., 8.7.0.747]
- C:\Program Files\McAfee\VirusScan Enterprise\shutil.dll [(Verified)McAfee, Inc., 8.7.0.747]
- C:\Program Files\McAfee\VirusScan Enterprise\RES0402\McShield.dll [(Verified)McAfee, Inc., VSCORE.14.1.0.515]
- C:\WINDOWS\system32\VrvHook.dll [Microsoft Corporation, 9, 5, 25, 16]
- C:\Program Files\McAfee\VirusScan Enterprise\Graphics.dll [(Verified)McAfee, Inc., 8.7.0.570]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 3096 / dark] C:\WINDOWS\system32\hkcmd.exe [(Verified)Intel Corporation, 3.0.0.4396]
- C:\WINDOWS\system32\hccutils.DLL [(Verified)Intel Corporation, 3.0.0.4396]
- C:\WINDOWS\system32\VrvHook.dll [Microsoft Corporation, 9, 5, 25, 16]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\igfxsrvc.dll [(Verified)Intel Corporation, 3.0.0.4396]
- C:\WINDOWS\system32\igfxres.dll [(Verified)Intel Corporation, 3.0.0.4396]
- [PID: 3204 / dark] D:\工具软件\音速启动\VStart.exe [3L软件工作室(3LSoft), 5.08.1225]
- C:\WINDOWS\system32\VrvHook.dll [Microsoft Corporation, 9, 5, 25, 16]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 3224 / dark] C:\WINDOWS\system32\ctfmon.exe [(Verified)Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\UxTheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\VrvHook.dll [Microsoft Corporation, 9, 5, 25, 16]
- [PID: 3240 / dark] C:\Program Files\McAfee\Common Framework\McTray.exe [(Verified)McAfee, Inc., 1.0.0.129]
- C:\Program Files\McAfee\Common Framework\JrMac.dll [(Verified)McAfee, Inc., 1.0.0.129]
- C:\WINDOWS\system32\VrvHook.dll [Microsoft Corporation, 9, 5, 25, 16]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 3032 / dark] e:\装机必备\系统增强(优化、清理)\系统修复\windows清理助手\arswp3.exe [(Verified)Windows 清理助手, 3.0.15.0309]
- C:\WINDOWS\system32\VrvHook.dll [Microsoft Corporation, 9, 5, 25, 16]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- C:\WINDOWS\system32\Zte_Proxy.dll [ , 1.5.0.0]
- [PID: 2956 / dark] D:\工具软件\FSCapture5.3\FSCapture.exe [N/A]
- C:\WINDOWS\system32\VrvHook.dll [Microsoft Corporation, 9, 5, 25, 16]
- C:\WINDOWS\system32\uxtheme.dll [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- ================================================================
- 文件关联
- ================================================================
- Autorun.Inf
- ================================================================
- Winsock提供者
- [MSAFD Tcpip [TCP/IP]]
- <%SYSTEMROOT%\system32\Zte_Proxy.dll> [ , 1.5.0.0]
- [MSAFD Tcpip [UDP/IP]]
- <%SYSTEMROOT%\system32\Zte_Proxy.dll> [ , 1.5.0.0]
- [MSAFD Tcpip [RAW/IP]]
- <%SYSTEMROOT%\system32\Zte_Proxy.dll> [ , 1.5.0.0]
- [RSVP UDP Service Provider]
- <%SYSTEMROOT%\system32\Zte_Proxy.dll> [ , 1.5.0.0]
- [RSVP TCP Service Provider]
- <%SYSTEMROOT%\system32\Zte_Proxy.dll> [ , 1.5.0.0]
- ================================================================
- 隐藏进程
- ================================================================
- 可疑文件
- ================================================================
- HOSTS
- 127.0.0.1 localhost
- 127.0.0.1 858656.com
- 127.0.0.1 my123.com
- 127.0.0.1 8749.com
- 127.0.0.1 4199.com
- 127.0.0.1 7379.com
- 127.0.0.1 7255.com
- 127.0.0.1 3448.com
- 127.0.0.1 7939.com
- 127.0.0.1 8009.com
- 127.0.0.1 piaoxue.com
- 127.0.0.1 kzdh.com
- 127.0.0.1 about.blank.la
- 127.0.0.1 6781.com
- 127.0.0.1 7322.com
复制代码 |