返回列表 发帖

..神仙哥哥.又中毒了.郁闷到家啦.............


昨天好了.今天又中毒了....当时我在玩网络游戏........毒就开始乱跳了.郁闷啦........继续发日志


  1. 2007-09-14,20:20:07

  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs ([url]http://www.KZTechs.com[/url])

  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描


  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  18.     <bgswitch><; C:\WINDOWS\system32\bgswitch.exe>  []
  19. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
  20.     <w><%SystemRoot%\WinRaR.exe>  [N/A]
  21.     <wm><%SystemRoot%\winlogor.exe>  [N/A]
  22.     <wl><%SystemRoot%\intent.exe>  [N/A]
  23.     <mm><%SystemRoot%\sourro.exe>  []
  24.     <zx><%SystemRoot%\winadr.exe>  [N/A]
  25.     <rx><%SystemRoot%\winnt.exe>  []
  26.     <aa><%SystemRoot%\SVchont.exe>  [N/A]
  27. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  28.     <ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>  [ATI Technologies, Inc.]
  29.     <!AVG Anti-Spyware><; "F:\AVG\新建文件夹\AVG Anti-Spyware 7.5\avgas.exe" /minimized>  [(Verified)GRISOFT LTD]
  30. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
  31.     <RavRuneip><C:\WINDOWS\system32\RacvSvc.EXE bjsyntahov.dll,HFanMa>  [N/A]
  32. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  33.     <shell><Explorer.exe>  [(Verified)Tencent Technology(Shenzhen) Company Limited]
  34.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  35. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  36.     <AppInit_DLLs><kaqhczy.dll>  []
  37. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  38.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  39. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  40.     <{57B86673-276A-48B2-BAE7-C6DBB3020EB8}><F:\AVG\新建文件夹\AVG Anti-Spyware 7.5\shellexecutehook.dll>  [(Verified)GRISOFT LTD]
  41.     <{1D561258-45F3-A451-F908-A258458226D1}><C:\WINDOWS\system32\kvdxsama.dll>  [N/A]
  42.     <{1598FF45-DA60-F48A-BC43-10AC47853D51}><C:\WINDOWS\system32\rarjapi.dll>  [N/A]
  43.     <{134345F1-DACF-3452-CB7D-4620F34A1531}><>  [N/A]
  44.     <{2C87A354-ABC3-DEDE-FF33-3213FD7447C2}><C:\WINDOWS\system32\kvdxbma.dll>  []
  45.     <{5D83AD9C-3BFC-43F5-979D-2904DBC54A8E}><C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys>  []
  46.     <{3D47B341-43DF-4563-753F-345FFA3157D3}><C:\WINDOWS\system32\kvmxcma.dll>  []
  47.     <{1E32FA58-3453-FA2D-BC49-F340348ACCE1}><C:\WINDOWS\system32\rsmyapm.dll>  []
  48.     <{1960356A-458E-DE24-BD50-268F589A56A1}><C:\WINDOWS\system32\avwlamn.dll>  []
  49.     <{12FAACDE-34DA-CCD4-AB4D-DA34485A3421}><C:\WINDOWS\system32\rsjzapm.dll>  []
  50.     <{1859245F-345D-BC13-AC4F-145D47DA34F1}><C:\WINDOWS\system32\avzxamn.dll>  []
  51.     <{37D81718-1314-5200-2597-587901018073}><C:\WINDOWS\system32\kaqhczy.dll>  []
  52. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  53.     <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]
  54. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  55.     <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
  56. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  57.     <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
  58. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  59.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  60. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  61.     <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
  62. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  63.     <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
  64. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  65.     <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub>  [(Verified)Microsoft Windows XP Publisher]
  66. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  67.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]

  68. ==================================
  69. 启动文件夹
  70. [QQ游戏启动加速程序]
  71.   <C:\Documents and Settings\jh1jcka\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk --> F:\QQGame\Accel.exe [深圳市腾讯计算机系统有限公司]><N>

  72. ==================================
  73. 服务
  74. [Ati HotKey Poller / Ati HotKey Poller][Stopped/Auto Start]
  75.   <C:\WINDOWS\system32\Ati2evxx.exe><>
  76. [ATI Smart / ATI Smart][Stopped/Auto Start]
  77.   <C:\WINDOWS\system32\ati2sgag.exe><>
  78. [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Stopped/Auto Start]
  79.   <F:\AVG\新建文件夹\AVG Anti-Spyware 7.5\guard.exe><GRISOFT s.r.o.>
  80. [DCOM Server Process Launcher / DcomLaunch][Running/Auto Start]
  81.   <C:\WINDOWS\system32\svchost -k DcomLaunch-->%SystemRoot%\system32\rpcss.dll><Microsoft Corporation>
  82. [Help and Support / helpsvc][Stopped/Auto Start]
  83.   <C:\WINDOWS\system32\inetres.exe-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><Microsoft Corporation>
  84. [Human Interface Device Access / HidServ][Stopped/Disabled]
  85.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  86. [Remote Procedure Call (RPC) / RpcSs][Running/Auto Start]
  87.   <C:\WINDOWS\system32\svchost -k rpcss-->%SystemRoot%\system32\rpcss.dll><>
  88. [Terminal Services / TermService][Running/Manual Start]
  89.   <C:\WINDOWS\System32\svchost -k DComLaunch-->%SystemRoot%\System32\termsrv.dll><Microsoft Corporation>
  90. [Windows Media Connect Service / WMConnectCDS][Stopped/Manual Start]
  91.   <C:\Program Files\Windows Media Connect 2\wmccds.exe><Microsoft Corporation>
  92. [Windows Driver Foundation - User-mode Driver Framework / WudfSvc][Stopped/Manual Start]
  93.   <C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup-->%SystemRoot%\System32\WUDFSvc.dll><Microsoft Corporation>
  94. [KVSrvXP / KVSrvXP][Running/Auto Start]
  95.   <F:\江民\JiangMin\AntiVirus\kvsrvxp.exe /Service><Jiangmin Co., Ltd.>

  96. ==================================
  97. 驱动程序
  98. [54609 / 54609][Stopped/Manual Start]
  99.   <\??\C:\WINDOWS\system32\Drivers\54578.sys><Driver>
  100. [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
  101.   <system32\drivers\ac97intc.sys><Intel Corporation>
  102. [ati2mtag / ati2mtag][Running/Manual Start]
  103.   <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
  104. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  105.   <\??\F:\AVG\新建文件夹\AVG Anti-Spyware 7.5\guard.sys><N/A>
  106. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  107.   <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
  108. [ BsDeamon Application - BsDeamon Application / BsDeamon][Running/System Start]
  109.   <\??\F:\江民\JiangMin\ANTIVI~1\BsDeamon.sys><Jiangmin Co., Ltd.>
  110. [KRegEx / KRegEx][Running/Auto Start]
  111.   <\??\F:\江民\JiangMin\antivirus\KRegEx.sys><Jiangmin Co. Ltd.>
  112. [KVFileGuard From Jiangmin / KVFileGuard][Running/Disabled]
  113.   <\??\F:\江民\JiangMin\AntiVirus\KVfg.sys><Jiangmin Co., Ltd.>
  114. [KVRedir From Jiangmin / KVRedir][Running/System Start]
  115.   <\??\F:\江民\JiangMin\AntiVirus\KVREDIR.SYS><Jiangmin Co., Ltd.>
  116. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  117.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  118. [Realtek RTL8029(AS)-based PCI Ethernet Adapter NT Driver / rtl8029][Running/Manual Start]
  119.   <system32\DRIVERS\RTL8029.SYS><Realtek Semiconductor Corporation>
  120. [Secdrv / Secdrv][Stopped/Manual Start]
  121.   <system32\DRIVERS\secdrv.sys><N/A>
  122. [Jiangmin AntiVirus Software - System Guard / SysGuard][Running/Boot Start]
  123.   <\SystemRoot\system32\Drivers\SysGuard.sys><Jiangmin Co., Ltd.>
  124. [Windows Driver Foundation - User-mode Driver Framework Platform Driver / WudfPf][Stopped/Manual Start]
  125.   <system32\DRIVERS\WudfPf.sys><Microsoft Corporation>
  126. [Windows Driver Foundation - User-mode Driver Framework Reflector / WudfRd][Stopped/Manual Start]
  127.   <system32\DRIVERS\wudfrd.sys><Microsoft Corporation>
  128. [Jiangmin Antivirus Software - SysCall Services / KSysCall][Running/System Start]
  129.   <\??\F:\江民\JiangMin\common\KSysCall.sys><Jiangmin Co.,  Ltd.>

  130. ==================================
  131. 浏览器加载项
  132. [ThunderAtOnce Class]
  133.   {01443AEC-0FD1-40fd-9C87-E93D1494C233} <F:\迅雷\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
  134. [Thunder Browser Helper]
  135.   {80BF4636-D65B-43F3-BB60-C5DD3D5FB7B9} <F:\迅雷\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  136. [BrowseHelper Class]
  137.   {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} <F:\江民\JiangMin\AntiVirus\KVshell.dll, Jiangmin Co.Ltd>
  138. [RegisterHelper Class]
  139.   {FF354A24-B490-4D4F-8EEC-B3ACD6E681A4} <F:\江民\JiangMin\AntiVirus\UrlGuard.dll, Jiangmin Co., Ltd.>
  140. [启动迅雷5]
  141.   {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <F:\迅雷\Thunder.exe, Thunder Networking Technologies,LTD>
  142. [番茄花园]
  143.   {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <[url]http://www.tomatolei.com[/url], N/A>
  144. [江民杀毒工具栏]
  145.   {B5A34A93-D538-43A7-8371-864CB6148D12} <F:\江民\JiangMin\AntiVirus\KVshell.dll, Jiangmin Co.Ltd>
  146. [ThunderAtOnce Class]
  147.   {01443AEC-0FD1-40FD-9C87-E93D1494C233} <F:\迅雷\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
  148. [Thunder Agent Class]
  149.   {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <F:\迅雷\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
  150. [Thunder Browser Helper]
  151.   {80BF4636-D65B-43F3-BB60-C5DD3D5FB7B9} <F:\迅雷\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  152. [BrowseHelper Class]
  153.   {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} <F:\江民\JiangMin\AntiVirus\KVshell.dll, Jiangmin Co.Ltd>
  154. [360SafeLive]
  155.   {87515F61-A66C-4319-A0E0-D416CB8059E3} <F:\360\360safe\live.dll, 360safe.com>
  156. [Thunder Browser Helper]
  157.   {889D2FEB-5411-4565-8998-1DD2C5261283} <F:\迅雷\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  158. [江民杀毒工具栏]
  159.   {B5A34A93-D538-43A7-8371-864CB6148D12} <F:\江民\JiangMin\AntiVirus\KVshell.dll, Jiangmin Co.Ltd>
  160. [RegisterHelper Class]
  161.   {FF354A24-B490-4D4F-8EEC-B3ACD6E681A4} <F:\江民\JiangMin\AntiVirus\UrlGuard.dll, Jiangmin Co., Ltd.>
  162. [使用迅雷下载]
  163.   <F:\迅雷\Program\geturl.htm, N/A>
  164. [使用迅雷下载全部链接]
  165.   <F:\迅雷\Program\getallurl.htm, N/A>

  166. ==================================
  167. 正在运行的进程
  168. [PID: 436 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  169. [PID: 492 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  170. [PID: 516 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  171.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  172. [PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  173. [PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  174. [PID: 744 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  175. [PID: 828 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  176. [PID: 896 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  177. [PID: 980 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  178. [PID: 1064 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  179. [PID: 1232 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
  180. [PID: 1320 / jh1jcka][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  181.     [C:\WINDOWS\system32\WPDShServiceObj.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
  182.     [C:\WINDOWS\system32\PortableDeviceTypes.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
  183.     [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
  184.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  185.     [F:\江民\JiangMin\AntiVirus\KVshell.dll]  [Jiangmin Co.Ltd, 2, 0, 7, 905]
  186.     [C:\WINDOWS\system32\HiveBase.dll]  [Jiangmin Co., Ltd., 1, 0, 7, 717]
  187.     [C:\WINDOWS\system32\kvinstall.dll]  [Jiangmin Co.,Ltd, 2, 0, 7, 831]
  188.     [F:\江民\JiangMin\AntiVirus\lang\kvxp0804.lng]  [N/A, ]
  189.     [F:\江民\JiangMin\common\GUIEXT.DLL]  [Jiangmin Co.Ltd, 2, 0, 7, 828]
  190.     [F:\江民\JiangMin\common\lang\guiext0804.lng]  [JiangMin Ltd., 7, 1, 0, 200]
  191.     [F:\AVG\新建文件夹\AVG Anti-Spyware 7.5\shellexecutehook.dll]  [GRISOFT s.r.o., 7, 5, 1, 36]
  192.     [F:\迅雷\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.5.15]
  193.     [F:\迅雷\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 8, 18]
  194.     [F:\rar\rarext.dll]  [N/A, ]
  195.     [F:\AVG\新建文件夹\AVG Anti-Spyware 7.5\context.dll]  [GRISOFT s.r.o., 7, 5, 1, 36]
  196.     [C:\WINDOWS\system32\kvdxbma.dll]  [N/A, ]
  197.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys]  [N/A, ]
  198.     [C:\WINDOWS\system32\kvmxcma.dll]  [N/A, ]
  199.     [C:\WINDOWS\system32\rsmyapm.dll]  [N/A, ]
  200.     [C:\WINDOWS\video.dll]  [N/A, ]
  201.     [C:\WINDOWS\rx.dll]  [N/A, ]
  202.     [C:\WINDOWS\system32\avwlamn.dll]  [N/A, ]
  203.     [C:\WINDOWS\system32\rsjzapm.dll]  [N/A, ]
  204.     [C:\WINDOWS\system32\avzxamn.dll]  [N/A, ]
  205.     [C:\WINDOWS\system32\kaqhczy.dll]  [N/A, ]
  206.     [C:\Program Files\NetMeeting\ravwdmon.dat]  [N/A, ]
  207. [PID: 1516 / jh1jcka][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe]  [ATI Technologies, Inc., 6.14.10.5120]
  208.     [C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll]  [ATI Technologies, Inc., 6.14.10.5120]
  209.     [C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.CHS]  [ATI Technologies, Inc., 6.14.10.5120]
  210.     [C:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll]  [ATI Technologies, Inc., 6.14.10.5120]
  211.     [C:\WINDOWS\system32\kvdxbma.dll]  [N/A, ]
  212.     [C:\WINDOWS\system32\rsmyapm.dll]  [N/A, ]
  213.     [C:\WINDOWS\system32\kvmxcma.dll]  [N/A, ]
  214.     [C:\WINDOWS\video.dll]  [N/A, ]
  215.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys]  [N/A, ]
  216.     [C:\WINDOWS\system32\avwlamn.dll]  [N/A, ]
  217.     [C:\WINDOWS\rx.dll]  [N/A, ]
  218.     [C:\WINDOWS\system32\rsjzapm.dll]  [N/A, ]
  219.     [C:\WINDOWS\system32\avzxamn.dll]  [N/A, ]
  220.     [C:\WINDOWS\system32\kaqhczy.dll]  [N/A, ]
  221. [PID: 1540 / jh1jcka][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  222.     [C:\WINDOWS\system32\kvdxbma.dll]  [N/A, ]
  223.     [C:\WINDOWS\system32\rsmyapm.dll]  [N/A, ]
  224.     [C:\WINDOWS\system32\kvmxcma.dll]  [N/A, ]
  225.     [C:\WINDOWS\video.dll]  [N/A, ]
  226.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys]  [N/A, ]
  227.     [C:\WINDOWS\system32\avwlamn.dll]  [N/A, ]
  228.     [C:\WINDOWS\rx.dll]  [N/A, ]
  229.     [C:\WINDOWS\system32\avzxamn.dll]  [N/A, ]
  230.     [C:\WINDOWS\system32\rsjzapm.dll]  [N/A, ]
  231.     [C:\WINDOWS\system32\kaqhczy.dll]  [N/A, ]
  232.     [C:\Program Files\NetMeeting\ravwdmon.dat]  [N/A, ]
  233. [PID: 1820 / SYSTEM][C:\WINDOWS\Explorer.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  234.     [F:\AVG\新建文件夹\AVG Anti-Spyware 7.5\shellexecutehook.dll]  [GRISOFT s.r.o., 7, 5, 1, 36]
  235.     [C:\WINDOWS\system32\WPDShServiceObj.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
  236.     [C:\WINDOWS\system32\PortableDeviceTypes.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
  237.     [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
  238.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  239.     [F:\江民\JiangMin\AntiVirus\KVshell.dll]  [Jiangmin Co.Ltd, 2, 0, 7, 905]
  240.     [C:\WINDOWS\system32\HiveBase.dll]  [Jiangmin Co., Ltd., 1, 0, 7, 717]
  241.     [C:\WINDOWS\system32\kvinstall.dll]  [Jiangmin Co.,Ltd, 2, 0, 7, 831]
  242.     [F:\江民\JiangMin\AntiVirus\lang\kvxp0804.lng]  [N/A, ]
  243.     [F:\江民\JiangMin\common\GUIEXT.DLL]  [Jiangmin Co.Ltd, 2, 0, 7, 828]
  244.     [F:\江民\JiangMin\common\lang\guiext0804.lng]  [JiangMin Ltd., 7, 1, 0, 200]
  245.     [F:\迅雷\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.5.15]
  246.     [F:\迅雷\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 8, 18]
  247.     [F:\迅雷\Components\ResWorker\DsBho_00.dll]  [, 1, 0, 0, 11]
  248.     [F:\迅雷\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 12]
  249. [PID: 1408 / jh1jcka][F:\QQ\QQ.exe]  [TENCENT, 7,0,365,1701]
  250.     [F:\QQ\QQBaseClassInDll.dll]  [TENCENT, 7,0,365,1701]
  251.     [F:\QQ\QQHelperDll.dll]  [TENCENT, 7,0,365,1701]
  252.     [F:\QQ\BasicCtrlDll.dll]  [TENCENT, 7,0,365,1701]
  253.     [F:\QQ\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
  254.     [F:\QQ\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
  255.     [F:\QQ\RICHED20.dll]  [Jiangmin Co., Ltd., 10, 0, 7, 720]
  256.     [F:\QQ\riched20_.dll]  [Microsoft Corporation, 5.31.23.1218]
  257.     [C:\WINDOWS\system32\HiveBase.dll]  [Jiangmin Co., Ltd., 1, 0, 7, 717]
  258.     [C:\WINDOWS\system32\kvinstall.dll]  [Jiangmin Co.,Ltd, 2, 0, 7, 831]
  259.     [F:\江民\JiangMin\antivirus\lang\JmIMProtect0804.lng]  [Jiangmin Co., Ltd., 10, 0, 7, 726]
  260.     [F:\QQ\QQAPI.dll]  [TENCENT, 7,0,365,1701]
  261.     [F:\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
  262.     [F:\QQ\LoginCtrl.dll]  [TENCENT, 7,0,365,1701]
  263.     [F:\QQ\LoginCtrlRes.dll]  [TENCENT, 7,0,365,1701]
  264.     [F:\QQ\QQRes.dll]  [TENCENT, 7,0,365,1701]
  265.     [F:\QQ\QQMainFrame.dll]  [N/A, ]
  266.     [F:\QQ\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
  267.     [F:\QQ\CQQApplication.dll]  [N/A, ]
  268.     [F:\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
  269.     [F:\QQ\NewSkin.dll]  [TENCENT, 7,0,365,1701]
  270.     [F:\QQ\HostingMgr.dll]  [TENCENT, 7,0,365,1701]
  271.     [F:\QQ\CameraDll.dll]  [TENCENT, 7,0,365,1701]
  272.     [F:\QQ\MailSummary.dll]  [TENCENT, 7,0,365,1701]
  273.     [F:\QQ\QQKnowledgeSearch.dll]  [TENCENT, 7,0,365,1701]
  274.     [F:\QQ\QQAllInOne.dll]  [TENCENT, 7,0,365,1701]
  275.     [F:\QQ\SCCore.dll]  [TENCENT, 1, 6, 0, 2]
  276.     [F:\QQ\QQSpace.dll]  [TENCENT, 7,0,365,1701]
  277.     [F:\QQ\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
  278.     [C:\WINDOWS\system32\msdmo.dll]  [, ]
  279.     [F:\QQ\QQGroupMng.dll]  [TENCENT, 7,0,365,1701]
  280.     [F:\QQ\UserDefinedHead.dll]  [TENCENT, 7,0,365,1701]
  281.     [F:\QQ\QQPlugin.dll]  [N/A, ]
  282.     [F:\QQ\QQCustomFace.dll]  [N/A, ]
  283.     [F:\QQ\QQPet.dll]  [TENCENT, 7,0,365,1701]
  284.     [F:\QQ\QQSysMsgMng.dll]  [N/A, ]
  285.     [F:\QQ\QQConfigPlugin.dll]  [TENCENT, 7,0,365,1701]
  286.     [F:\QQ\QQAvatar.dll]  [N/A, ]
  287.     [F:\QQ\QRingMng.dll]  [N/A, ]
  288.     [F:\QQ\ImageOle.dll]  [TENCENT, 7,0,365,1701]
  289.     [F:\QQ\QQLiveQMng.dll]  [TENCENT, 7,0,365,1701]
  290.     [F:\QQ\QQMagicFace.dll]  [TENCENT, 7,0,365,1701]
  291.     [F:\QQ\QQSceneMng.dll]  [N/A, ]
  292.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  293.     [F:\QQ\LongConnection.dll]  [TENCENT, 7,0,365,1701]
  294.     [F:\QQ\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 320]
  295.     [F:\QQ\PhoneAPI.dll]  [TENCENT, 7,0,365,1701]
  296.     [F:\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
  297.     [F:\QQ\BQQApplication.dll]  [N/A, ]
  298.     [F:\QQ\CommercesMng.dll]  [TENCENT, 7,0,365,1701]
  299.     [F:\QQ\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
  300.     [F:\江民\JiangMin\AntiVirus\UrlGuard.dll]  [Jiangmin Co., Ltd., 1, 0, 7, 913]
  301.     [F:\江民\JiangMin\Kernel\EngFace.dll]  [Jiangmin Co., Ltd., 2, 0, 7, 911]
  302.     [F:\江民\JiangMin\Kernel\UNACE.dll]  [N/A, ]
  303.     [F:\QQ\AddrSearch.dll]  [腾讯科技(深圳)有限公司, 2, 1, 9, 95]
  304.     [F:\QQ\GroupConnection.dll]  [TENCENT, 7,0,365,1701]
  305.     [F:\QQ\QQZip.dll]  [TENCENT, 7,0,365,1701]
  306.     [F:\QQ\QQFileTransfer.dll]  [TENCENT, 7,0,365,1701]
  307.     [C:\WINDOWS\system32\DirectX10.dll]  [Microsoft Corporation, 6.00.2900.2904 (xpsp_sp2_gdr.060509-0218)]
  308.     [C:\WINDOWS\system32\kvdxbma.dll]  [N/A, ]
  309.     [C:\WINDOWS\system32\kvmxcma.dll]  [N/A, ]
  310.     [C:\WINDOWS\system32\rsmyapm.dll]  [N/A, ]
  311.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys]  [N/A, ]
  312.     [C:\WINDOWS\video.dll]  [N/A, ]
  313.     [C:\WINDOWS\system32\avwlamn.dll]  [N/A, ]
  314.     [C:\WINDOWS\rx.dll]  [N/A, ]
  315.     [C:\WINDOWS\system32\rsjzapm.dll]  [N/A, ]
  316.     [C:\WINDOWS\system32\avzxamn.dll]  [N/A, ]
  317.     [C:\WINDOWS\system32\kaqhczy.dll]  [N/A, ]
  318.     [C:\Program Files\NetMeeting\ravwdmon.dat]  [N/A, ]
  319. [PID: 1952 / jh1jcka][F:\QQ\TIMPlatform.exe]  [TENCENT, 7,0,365,1701]
  320.     [F:\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
  321. [PID: 2792 / jh1jcka][C:\WINDOWS\system32\taskmgr.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  322.     [C:\WINDOWS\system32\kvdxbma.dll]  [N/A, ]
  323.     [C:\WINDOWS\system32\kvmxcma.dll]  [N/A, ]
  324.     [C:\WINDOWS\system32\rsmyapm.dll]  [N/A, ]
  325.     [C:\WINDOWS\video.dll]  [N/A, ]
  326.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys]  [N/A, ]
  327.     [C:\WINDOWS\system32\avwlamn.dll]  [N/A, ]
  328.     [C:\WINDOWS\rx.dll]  [N/A, ]
  329.     [C:\WINDOWS\system32\avzxamn.dll]  [N/A, ]
  330.     [C:\WINDOWS\system32\rsjzapm.dll]  [N/A, ]
  331.     [C:\WINDOWS\system32\kaqhczy.dll]  [N/A, ]
  332.     [C:\Program Files\NetMeeting\ravwdmon.dat]  [N/A, ]
  333. [PID: 3164 / jh1jcka][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  334.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys]  [N/A, ]
  335.     [C:\WINDOWS\system32\kvmxcma.dll]  [N/A, ]
  336.     [C:\WINDOWS\system32\avwlamn.dll]  [N/A, ]
  337.     [C:\WINDOWS\rx.dll]  [N/A, ]
  338.     [C:\WINDOWS\video.dll]  [N/A, ]
  339.     [C:\WINDOWS\system32\rsmyapm.dll]  [N/A, ]
  340.     [C:\WINDOWS\system32\kvdxbma.dll]  [N/A, ]
  341.     [C:\WINDOWS\system32\avzxamn.dll]  [N/A, ]
  342.     [C:\WINDOWS\system32\kaqhczy.dll]  [N/A, ]
  343.     [C:\WINDOWS\system32\rsjzapm.dll]  [N/A, ]
  344. [PID: 3328 / jh1jcka][C:\WINDOWS\system32\notepad.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  345.     [C:\WINDOWS\system32\rsjzapm.dll]  [N/A, ]
  346.     [C:\Program Files\NetMeeting\ravwdmon.dat]  [N/A, ]
  347.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys]  [N/A, ]
  348.     [C:\WINDOWS\system32\kvmxcma.dll]  [N/A, ]
  349.     [C:\WINDOWS\system32\kaqhczy.dll]  [N/A, ]
  350.     [C:\WINDOWS\system32\avzxamn.dll]  [N/A, ]
  351.     [C:\WINDOWS\system32\avwlamn.dll]  [N/A, ]
  352.     [C:\WINDOWS\system32\kvdxbma.dll]  [N/A, ]
  353.     [C:\WINDOWS\system32\rsmyapm.dll]  [N/A, ]
  354.     [C:\WINDOWS\rx.dll]  [N/A, ]
  355.     [C:\WINDOWS\video.dll]  [N/A, ]
  356. [PID: 3600 / jh1jcka][F:\日志\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
  357.     [C:\WINDOWS\system32\kvmxcma.dll]  [N/A, ]
  358.     [C:\Program Files\NetMeeting\ravwdmon.dat]  [N/A, ]
  359.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys]  [N/A, ]
  360.     [C:\WINDOWS\system32\avzxamn.dll]  [N/A, ]
  361.     [C:\WINDOWS\system32\avwlamn.dll]  [N/A, ]
  362.     [C:\WINDOWS\system32\kaqhczy.dll]  [N/A, ]
  363.     [C:\WINDOWS\system32\rsjzapm.dll]  [N/A, ]
  364.     [C:\WINDOWS\rx.dll]  [N/A, ]
  365.     [C:\WINDOWS\video.dll]  [N/A, ]
  366.     [C:\WINDOWS\system32\rsmyapm.dll]  [N/A, ]
  367.     [C:\WINDOWS\system32\kvdxbma.dll]  [N/A, ]
  368.     [F:\日志\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

  369. ==================================
  370. 文件关联
  371. .TXT  Error. [C:\WINDOWS\system32\notep.exe %1]
  372. .EXE  OK. ["%1" %*]
  373. .COM  OK. ["%1" %*]
  374. .PIF  OK. ["%1" %*]
  375. .REG  OK. [regedit.exe "%1"]
  376. .BAT  OK. ["%1" %*]
  377. .SCR  OK. ["%1" /S]
  378. .CHM  Error. ["hh.exe" %1]
  379. .HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
  380. .INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
  381. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  382. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  383. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  384. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  385. ==================================
  386. Winsock 提供者
  387. N/A

  388. ==================================
  389. Autorun.inf
  390. N/A

  391. ==================================
  392. HOSTS 文件
  393. N/A

  394. ==================================
  395. 进程特权扫描
  396. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1516, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE]

  397. ==================================
  398. API HOOK
  399. N/A

  400. ==================================
  401. 隐藏进程
  402. N/A

  403. ==================================
复制代码

返回列表