★路人甲★ - 2007-5-15 13:18:00
==================================
浏览器加载项
[上传到QQ网络硬盘]
<D:\工具\tencent\qq\AddToNetDisk.htm, N/A>
[使用Web迅雷下载]
<D:\工具\xunleixin\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
<D:\工具\xunleixin\GetAllUrl.htm, N/A>
[添加到QQ自定义面板]
<D:\工具\tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\工具\tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\工具\tencent\qq\SendMMS.htm, N/A>
[金山毒霸反钓鱼...]
<C:\KAV2006\KAF\ShowSet.htm, N/A>
==================================
正在运行的进程
[PID: 508][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 556][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 580][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 624][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 636][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 788][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 864][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 928][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1004][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1104][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1244][C:\KAV2006\KWatch.EXE] [Kingsoft Corporation, 2005, 9, 27, 51]
[C:\KAV2006\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\KAV2006\KAEPlat.DLL] [Kingsoft Corp., 2006, 8, 29, 60]
[C:\KAV2006\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\KAV2006\KAEUnpack.DAT] [Kingsoft Corp., 2007, 4, 12, 116]
[PID: 1308][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1356][C:\WINDOWS\System32\SCardSvr.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1492][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1516][C:\KAV2006\KPfwSvc.EXE] [Kingsoft Corporation, 2007, 2, 2, 31]
[PID: 1576][C:\WINDOWS\system32\pctspk.exe] [PCtel, Inc., 4.00]
[PID: 1708][C:\WINDOWS\system32\slserv.exe] [ , 2.80.00(24Apr2000)]
[PID: 1984][C:\Program Files\Windows Media Player\WMPNetwk.exe] [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
[PID: 192][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\fnygi.dll] [N/A, N/A]
[D:\工具\360safe\safemon\safemon.dll] [, 1, 0, 0, 1003]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[D:\工具\xunleixin\WebThunderBHO_016.dll] [Thunder Networking Technologies,LTD, 6, 0, 0, 5]
[D:\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.2285]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.2285]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.2285]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.2285]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3.0.0.2285]
[PID: 736][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 468][C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe] [Conexant Systems Inc., 2.099.085.000]
[C:\Program Files\Conexant\AccessRunner ADSL\CnxDslWz.dll] [Conexant Systems Inc., 2.099.085.000]
[C:\WINDOWS\system32\CnxHwIo.dll] [Conexant Systems Inc., 2.099.085.000]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[D:\工具\360safe\safemon\safemon.dll] [, 1, 0, 0, 1003]
[PID: 384][C:\WINDOWS\system32\igfxtray.exe] [Intel Corporation, 3.0.0.2285]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.2285]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3.0.0.2285]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.2285]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.2285]
[C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3.0.0.2285]
[D:\工具\360safe\safemon\safemon.dll] [, 1, 0, 0, 1003]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 500][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3.0.0.2285]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.2285]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3.0.0.2285]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.2285]
[C:\WINDOWS\system32\igfxhk.dll] [Intel Corporation, 3.0.0.2285]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.2285]
[D:\工具\360safe\safemon\safemon.dll] [, 1, 0, 0, 1003]
[PID: 212][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5.1.02]
[D:\工具\360safe\safemon\safemon.dll] [, 1, 0, 0, 1003]
[PID: 908][C:\KAV2006\KAVStart.exe] [Kingsoft Corporation, 2007, 5, 9, 272]
[C:\KAV2006\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\KAV2006\SvcTimer.DLL] [Kingsoft Corporation, 2006.12.22.84]
[C:\KAV2006\KAVPassp.dll] [Kingsoft Corporation, 2006, 12, 30, 271]
[C:\KAV2006\PopSprt3.dll] [Kingsoft Corporation, 2007, 1, 16, 45]
[D:\工具\360safe\safemon\safemon.dll] [, 1, 0, 0, 1003]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[PID: 924][D:\工具\d-tools\daemon.exe] [DAEMON'S HOME, 3.47.0.0]
[C:\WINDOWS\daemon.dll] [N/A, 3.47.0.0]
[D:\工具\d-tools\PFCTOC.DLL] [Padus(R), Inc., 1, 0, 0, 12]
[D:\工具\d-tools\Plugins\Images\ccdmount.dll] [GENERIC, 1.02.0.0]
[D:\工具\d-tools\Plugins\Images\mdsmount.dll] [GENERIC, 1.01.0.0]
[D:\工具\d-tools\Plugins\Images\pdimount.dll] [GENERIC, 1.01.0.0]
[D:\工具\d-tools\Plugins\Images\nrgmount.dll] [GENERIC, 1.02.0.0]
[D:\工具\d-tools\Plugins\Images\bw5mount.dll] [N/A, 1.0.2.0]
[D:\工具\360safe\safemon\safemon.dll] [, 1, 0, 0, 1003]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 1392][C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe] [InstallShield Software Corporation, 3, 10, 100, 1146]
[D:\工具\360safe\safemon\safemon.dll] [, 1, 0, 0, 1003]
[PID: 1428][D:\工具\KMplayer\Real Player\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3208]
[D:\工具\360safe\safemon\safemon.dll] [, 1, 0, 0, 1003]
[PID: 312][D:\工具\xunleixin\WebThunder.exe] [深圳市迅雷网络技术有限公司, 1, 7, 2, 107]
[D:\工具\xunleixin\taskmanage.dll] [Thunder Networking Technologies,LTD, 1, 7, 2, 107]
[D:\工具\xunleixin\download_interface.dll] [Thunder Networking Technologies,LTD, 2, 14, 2, 79]
[D:\工具\xunleixin\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031]
[D:\工具\xunleixin\asyn_dns.dll] [Thunder Networking Technologies,LTD, 2, 14, 2, 79]
[D:\工具\xunleixin\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 13, 4, 58]
[D:\工具\xunleixin\historyinfo_manage.dll] [Thunder Networking Technologies,LTD, 5, 3, 0, 228]
[C:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[D:\工具\xunleixin\iEmbedShell.dll] [ , 1, 0, 0, 17]
[D:\工具\xunleixin\iEmbed09.dll] [ , 3, 3, 0, 78]
[D:\工具\360safe\safemon\safemon.dll] [, 1, 0, 0, 1003]
[PID: 1456][C:\Program Files\GlobalSCAPE\tlgefkh.exe] [N/A, N/A]
[PID: 1620][D:\工具\360safe\safemon\360tray.exe] [奇虎网, 1, 0, 1, 1004]
[D:\工具\360safe\safemon\safemon.dll] [, 1, 0, 0, 1003]
[D:\工具\360safe\safemon\SafeKrnl.dll] [奇虎网, 1, 0, 0, 3001]
[D:\工具\360safe\AntiAdwa.dll] [360Safe.com, 2, 2, 5, 1000]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 1660][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
★路人甲★ - 2007-5-15 13:19:00
[D:\工具\360safe\safemon\safemon.dll] [, 1, 0, 0, 1003]
[PID: 1972][C:\KAV2006\KMailMon.EXE] [Kingsoft Corporation, 2007, 2, 25, 948]
[C:\KAV2006\KAntiSpm.dll] [Kingsoft Corporation, 2007, 2, 25, 129]
[C:\KAV2006\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\KAV2006\KAECall2.DLL] [Kingsoft Corporation, 2004, 12, 28, 7]
[C:\KAV2006\KAEPlat.DLL] [Kingsoft Corp., 2006, 8, 29, 60]
[C:\KAV2006\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\KAV2006\KAEUnpack.DAT] [Kingsoft Corp., 2007, 4, 12, 116]
[C:\KAV2006\KAConfig.DLL] [Kingsoft Corporation, 2007, 1, 11, 41]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[D:\工具\360safe\safemon\safemon.dll] [, 1, 0, 0, 1003]
[PID: 2176][C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe] [Google Inc., 1, 2, 1128, 5462]
[C:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\res_zh-CN.dll] [Google Inc., 1, 2, 1128, 5462]
[C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\swg.dll] [Google Inc., 1, 2, 1128, 5462]
[D:\工具\360safe\safemon\safemon.dll] [, 1, 0, 0, 1003]
[PID: 3404][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1601, 4978]
[D:\工具\BitComet\BitCometBar\BitCometBar0.6.dll] [N/A, 0.6]
[D:\工具\xunleixin\WebThunderBHO_016.dll] [Thunder Networking Technologies,LTD, 6, 0, 0, 5]
[D:\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] [, 1, 0, 0, 1]
[C:\KAV2006\KAVAFish.DLL] [Kingsoft Corporation, 2006, 10, 25, 27]
[D:\工具\360safe\safemon\safemon.dll] [, 1, 0, 0, 1003]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0]
[C:\WINDOWS\system32\dllMergeDict.dll] [Sogou.com Inc., 3, 0, 0, 0]
[C:\Documents and Settings\Administrator.4CE9F3A06C89466\My Documents\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[PID: 3944][D:\工具\sreng2_zip~\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[D:\工具\360safe\safemon\safemon.dll] [, 1, 0, 0, 1003]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0]
[C:\WINDOWS\system32\dllMergeDict.dll] [Sogou.com Inc., 3, 0, 0, 0]
[C:\Documents and Settings\Administrator.4CE9F3A06C89466\My Documents\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
入口点错误:LoadLibraryExW
入口点错误:CreateProcessA
入口点错误:CreateProcessW
==================================
[/CODE]
© 2000 - 2026 Rising Corp. Ltd.