火影恶战病毒小强 - 2007-5-13 12:24:00
家里电脑中了病毒,之前就只觉得网络有问题,2人共用的电信,都只开1个QQ网络ping就达1800ms+,后来杀毒发现杀不掉,现把System Repair Engineer检测出来的帖哈,高手帮忙分析哈啊,十万火急!!!



启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<0h><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\c0nime.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
<IgfxTray><C:\WINDOWS\system32\igfxtray.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<HotKeysCmds><C:\WINDOWS\system32\hkcmd.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<BigDogPath><C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera> [N/A]
<mppds><C:\WINDOWS\mppds.exe> []
<winform><C:\WINDOWS\winform.exe> []
<upxdnd><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.exe> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<testrun><C:\WINDOWS\testexe.exe> []
<VSOCheckTask><"C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask> [McAfee, Inc.]
<VirusScan Online><C:\Program Files\McAfee.com\VSO\mcvsshld.exe> [McAfee, Inc.]
<OASClnt><C:\Program Files\McAfee.com\VSO\oasclnt.exe> [McAfee, Inc.]
<MCAgentExe><c:\PROGRA~1\mcafee.com\agent\mcagent.exe> [McAfee, Inc]
<MCUpdateExe><C:\PROGRA~1\mcafee.com\agent\McUpdate.exe> [McAfee, Inc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{754FB7D8-B8FE-4810-B363-A788CD060F1F}><C:\Program Files\Internet Explorer\PLUGINS\System64.sys> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<KuGoo3><; D:\PROGRA~1\KUGOO3\KUGOO.EXE> []
<SoundMan><; SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [(Verified)"RealNetworks, Inc."]
<WebThunder><; d:\Program Files\Thunder Network\WebThunder\WebThunder.exe> [(Verified)ShenZhen Thunder Networking Technologies Ltd.]
火影恶战病毒小强 - 2007-5-13 12:25:00
==================================
启动文件夹
N/A
==================================
服务
[997FED0 / 997FED0][Stopped/Auto Start]
<C:\WINDOWS\system32\387CA968.EXE -k><Microsoft Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[McAfee WSC Integration / McDetect.exe][Running/Auto Start]
<c:\program files\mcafee.com\agent\mcdetect.exe><McAfee, Inc>
[McAfee.com McShield / McShield][Running/Auto Start]
<c:\PROGRA~1\mcafee.com\vso\mcshield.exe><McAfee Inc.>
[McAfee Task Scheduler / McTskshd.exe][Running/Auto Start]
<c:\PROGRA~1\mcafee.com\agent\mctskshd.exe><McAfee, Inc>
[McAfee SecurityCenter Update Manager / mcupdmgr.exe][Stopped/Manual Start]
<C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe><McAfee, Inc>
==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[ialm / ialm][Running/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[NaiAvFilter1 / NaiAvFilter1][Running/Manual Start]
<system32\drivers\naiavf5x.sys><McAfee Inc.>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
<system32\DRIVERS\npf.sys><CACE Technologies>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[VIMICRO USB PC Camera / ZSMC302][Running/Manual Start]
<System32\Drivers\usbVM31b.sys><VM>
[Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/System Start]
<system32\drivers\ialmsbw.sys><Intel Corporation>
[Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start]
<system32\drivers\ialmkchw.sys><Intel Corporation>
==================================
浏览器加载项
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <d:\Program Files\Thunder Network\WebThunder\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
[启动Web迅雷]
{962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[McAfee 病毒扫描]
{BA52B914-B692-46c4-B683-905236F6F655} <c:\progra~1\mcafee.com\vso\mcvsshl.dll, McAfee, Inc.>
[McAfee.com Operating System Class]
{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} <C:\WINDOWS\system32\mcinsctl.dll, McAfee, Inc>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <d:\Program Files\Thunder Network\WebThunder\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
[WebThunder Class]
{03507A1A-E0C5-4404-AA26-205385C0892D} <, N/A>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[McAfee.com Download+Installer Class]
{36C417C6-13C6-448B-9784-DD73A93B0582} <C:\WINDOWS\system32\mcinsctl.dll, McAfee, Inc>
[McAfee.com Registry Class]
{4C29D864-C55A-46DD-865C-17A1B7CC1A1A} <C:\WINDOWS\system32\mcinsctl.dll, McAfee, Inc>
[McAfee.com Operating System Class]
{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} <C:\WINDOWS\system32\mcinsctl.dll, McAfee, Inc>
[Microsoft Licensed Class Manager 1.0]
{5220CB21-C88D-11CF-B347-00AA00A28331} <C:\WINDOWS\system32\licmgr10.dll, Microsoft Corporation>
[McAfee.com File System Class]
{5940894F-4BA9-4FAC-ACFD-2F56F7CE0E3B} <C:\WINDOWS\system32\mcinsctl.dll, McAfee, Inc>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[McAfee 病毒扫描]
{BA52B914-B692-46C4-B683-905236F6F655} <c:\progra~1\mcafee.com\vso\mcvsshl.dll, McAfee, Inc.>
[DwnldGroupMgr Class]
{BCC0FF27-31D9-4614-A68E-C18E1ADA4389} <C:\WINDOWS\system32\mcgdmgr.dll, McAfee, Inc>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[McAfee.com Shell Helper Class]
{CA145D71-4BCB-461D-BCBE-C01C42867380} <C:\WINDOWS\system32\mcinsctl.dll, McAfee, Inc>
[AUDIO__MP3 Moniker Class]
{CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[McAfee.com Application Helper Class]
{D2D8D3C0-C750-4703-A6AD-75D6B578FFE6} <C:\WINDOWS\system32\mcinsctl.dll, McAfee, Inc>
[上传到QQ网络硬盘]
<E:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用Web迅雷下载]
<d:\Program Files\Thunder Network\WebThunder\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
<d:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm, N/A>
[添加到QQ自定义面板]
<E:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<E:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<E:\Program Files\Tencent\qq\SendMMS.htm, N/A>
火影恶战病毒小强 - 2007-5-13 12:25:00
==================================
正在运行的进程
[PID: 428][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 484][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\77E8B670.DLL] [Microsoft Corporation, ]
[PID: 508][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\77E8B670.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 552][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\77E8B670.DLL] [Microsoft Corporation, ]
[PID: 564][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\77E8B670.DLL] [Microsoft Corporation, ]
[PID: 712][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\77E8B670.DLL] [Microsoft Corporation, ]
[PID: 756][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\77E8B670.DLL] [Microsoft Corporation, ]
[PID: 792][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\77E8B670.DLL] [Microsoft Corporation, ]
[PID: 844][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\77E8B670.DLL] [Microsoft Corporation, ]
[PID: 936][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\77E8B670.DLL] [Microsoft Corporation, ]
[PID: 1116][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\77E8B670.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\testdll.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\WINDOWS\system32\mshtmlbe.dll] [Microsoft Corporation, 6.2900.2802]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690]
[c:\progra~1\mcafee.com\vso\mcvsshl.dll] [McAfee, Inc., 10, 0, 0, 19]
[c:\progra~1\mcafee.com\vso\ShlRes.dll] [McAfee, Inc., 10, 0, 0, 19]
[C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\winform.dll] [N/A, ]
[C:\WINDOWS\system32\nwizAsktao.dll] [N/A, ]
[PID: 1192][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\77E8B670.DLL] [Microsoft Corporation, ]
[PID: 1512][c:\program files\mcafee.com\agent\mcdetect.exe] [McAfee, Inc, 6, 0, 0, 19]
[PID: 1576][c:\PROGRA~1\mcafee.com\vso\mcshield.exe] [McAfee Inc., 11.0.0.151]
[c:\PROGRA~1\mcafee.com\vso\RES00\McShield.DLL] [McAfee Inc., 11.0.0.141]
[c:\PROGRA~1\mcafee.com\vso\FTL.Dll] [McAfee Inc., 11.0.0.151]
[c:\PROGRA~1\mcafee.com\vso\naiann.dll] [McAfee, Inc., 10, 0, 0, 21]
[c:\PROGRA~1\mcafee.com\vso\mytilus.dll] [McAfee Inc., 11.0.0.151]
[C:\Program Files\McAfee.com\VSO\MCSCAN32.DLL] [McAfee, Inc., 5.1.00]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\naiannps.dll] [McAfee, Inc, 10, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\mcvsps.dll] [McAfee, Inc, 10, 0, 0, 17]
[c:\program files\mcafee.com\vso\vsoupd.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 1652][c:\PROGRA~1\mcafee.com\agent\mctskshd.exe] [McAfee, Inc, 6, 0, 0, 13]
[PID: 1716][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1780][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 1812][c:\PROGRA~1\mcafee.com\vso\OasClnt.exe] [McAfee, Inc., 10, 0, 0, 24]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\naiannps.dll] [McAfee, Inc, 10, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\mcvsps.dll] [McAfee, Inc, 10, 0, 0, 17]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 144][c:\program files\mcafee.com\vso\mcvsshld.exe] [McAfee, Inc., 10, 0, 0, 22]
[C:\Program Files\McAfee.com\VSO\VsCfgW32.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\program files\mcafee.com\vso\ashldres.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\program files\mcafee.com\agent\submgr\6,0,0,16\mcsubmgr.dll] [McAfee, Inc, 6, 0, 0, 16]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\mcvsps.dll] [McAfee, Inc, 10, 0, 0, 17]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\program files\mcafee.com\shared\mcuicfg\6,0,0,4\mcuicfg.dll] [McAfee, Inc, 6, 0, 0, 4]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\testdll.dll] [N/A, ]
[C:\WINDOWS\system32\winform.dll] [N/A, ]
[PID: 204][c:\program files\mcafee.com\agent\mcagent.exe] [McAfee, Inc, 6, 0, 0, 16]
[c:\program files\mcafee.com\agent\SCRes.dll] [McAfee, Inc, 6, 0, 0, 7]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\program files\mcafee.com\agent\submgr\6,0,0,16\mcsubmgr.dll] [McAfee, Inc, 6, 0, 0, 16]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\testdll.dll] [N/A, ]
[C:\WINDOWS\system32\winform.dll] [N/A, ]
[PID: 244][c:\progra~1\mcafee.com\vso\mcvsescn.exe] [McAfee, Inc., 10, 0, 0, 20]
[c:\progra~1\mcafee.com\vso\ashldres.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\progra~1\mcafee.com\vso\EmScnRes.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\program files\mcafee.com\vso\vsoupd.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\progra~1\mcafee.com\vso\McVsWorm.dll] [McAfee, Inc., 10, 0, 0, 19]
[C:\Program Files\McAfee.com\VSO\VsCfgW32.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\progra~1\mcafee.com\vso\WormRes.dll] [McAfee, Inc., 10, 0, 0, 19]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[PID: 368][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\testdll.dll] [N/A, ]
[PID: 456][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 876][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3,0,0,1847]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[C:\WINDOWS\system32\igfxhk.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3,0,0,1847]
[PID: 1068][C:\WINDOWS\VM_STI.EXE] [BIGDOG, 4, 2, 610, 4]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\system32\VM31bPrp.Ax] [Vimicro, 1.00.01.00]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 2196][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 944][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 3168][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[d:\Program Files\Thunder Network\WebThunder\WebThunderBHO_016.dll] [Thunder Networking Technologies,LTD, 6, 0, 0, 5]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[C:\WINDOWS\system32\winform.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\testdll.dll] [N/A, ]
[C:\WINDOWS\system32\HYJT.IME] [衡阳水晶情缘工作室, 4.00.950]
[C:\WINDOWS\system32\HYFT.IME] [衡阳水晶情缘工作室, 4.00.950]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx] [Adobe Systems, Inc., 9,0,45,0]
[PID: 3320][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX05.047\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[C:\WINDOWS\system32\winform.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\testdll.dll] [N/A, ]
==================================
文件关联
.TXT Error. [NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
© 2000 - 2026 Rising Corp. Ltd.