qrzz - 2007-6-12 7:10:00
==================================
驱动程序
[abp480n5 / abp480n5][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ABP480N5.SYS><Microsoft Corporation>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
<system32\drivers\ac97intc.sys><Intel Corporation>
[ADI UAA Function Driver for High Definition Audio Service / ADIHdAudAddService][Running/Manual Start]
<system32\drivers\ADIHdAud.sys><Analog Devices, Inc.>
[adpu160m / adpu160m][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\adpu160m.sys><Microsoft Corporation>
[AEAudio Service / AEAudioService][Running/Manual Start]
<system32\drivers\AEAudio.sys><Andrea Electronics Corporation>
[AEGIS Protocol (IEEE 802.1x) v3.4.9.0 / AegisP][Running/Auto Start]
<system32\DRIVERS\AegisP.sys><Meetinghouse Data Communications>
[Aha154x / Aha154x][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\aha154x.sys><Microsoft Corporation>
[aic78u2 / aic78u2][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\aic78u2.sys><Microsoft Corporation>
[aic78xx / aic78xx][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\aic78xx.sys><Microsoft Corporation>
[AliIde / AliIde][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD AGP Bus Filter Driver / amdagp][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\amdagp.sys><Advanced Micro Devices, Inc.>
[ANC / ANC][Running/System Start]
<System32\drivers\ANC.SYS><IBM Corp.>
[ANCSQ / ANCSQ][Running/Boot Start]
<\SystemRoot\System32\drivers\ANCSQ.sys><IBM Corp.>
[asc / asc][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\asc.sys><Advanced System Products, Inc.>
[asc3350p / asc3350p][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\asc3350p.sys><Microsoft Corporation>
[asc3550 / asc3550][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\asc3550.sys><Advanced System Products, Inc.>
[atmeltpm / atmeltpm][Running/Manual Start]
<system32\DRIVERS\atmeltpm.sys><Atmel, Inc.>
[AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
<\??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys><N/A>
[AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
<System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
[cd20xrnt / cd20xrnt][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\cd20xrnt.sys><Microsoft Corporation>
[CmdIde / CmdIde][Stopped/Manual Start]
<\SystemRoot\system32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[d344bus / d344bus][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\d344bus.sys><>
[d344prt / d344prt][Running/Boot Start]
<\SystemRoot\System32\Drivers\d344prt.sys><>
[dac2w2k / dac2w2k][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\dac2w2k.sys><Mylex Corporation>
[DLABOIOM / DLABOIOM][Running/Auto Start]
<System32\DLA\DLABOIOM.SYS><Sonic Solutions>
[DLACDBHM / DLACDBHM][Running/System Start]
<System32\Drivers\DLACDBHM.SYS><Sonic Solutions>
[DLADResN / DLADResN][Running/Auto Start]
<System32\DLA\DLADResN.SYS><Sonic Solutions>
[DLAIFS_M / DLAIFS_M][Running/Auto Start]
<System32\DLA\DLAIFS_M.SYS><Sonic Solutions>
[DLAOPIOM / DLAOPIOM][Running/Auto Start]
<System32\DLA\DLAOPIOM.SYS><Sonic Solutions>
[DLAPoolM / DLAPoolM][Running/Auto Start]
<System32\DLA\DLAPoolM.SYS><Sonic Solutions>
[DLARTL_N / DLARTL_N][Running/System Start]
<System32\Drivers\DLARTL_N.SYS><Sonic Solutions>
[DLAUDFAM / DLAUDFAM][Running/Auto Start]
<System32\DLA\DLAUDFAM.SYS><Sonic Solutions>
[DLAUDF_M / DLAUDF_M][Running/Auto Start]
<System32\DLA\DLAUDF_M.SYS><Sonic Solutions>
[dpti2o / dpti2o][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\dpti2o.sys><Microsoft Corporation>
[DRVMCDB / DRVMCDB][Running/Boot Start]
<\SystemRoot\System32\Drivers\DRVMCDB.SYS><Sonic Solutions>
[DRVNDDM / DRVNDDM][Running/Auto Start]
<System32\Drivers\DRVNDDM.SYS><Sonic Solutions>
[Intel(R) PRO Adapter Driver / E100B][Stopped/Manual Start]
<system32\DRIVERS\e100b325.sys><Intel Corporation>
[Intel(R) PRO/1000 PCI Express Network Connection Driver / e1express][Running/Manual Start]
<system32\DRIVERS\e1e5132.sys><Intel Corporation>
[IBM eGatherer / EGATHDRV][Running/Auto Start]
<\??\C:\WINDOWS\SYSTEM32\EGATHDRV.SYS><IBM Corporation>
[F-Secure File System Filter / F-Secure Filter][Running/Auto Start]
<\??\C:\Program Files\F-Secure\Anti-Virus\Win2K\FSfilter.sys><>
[F-Secure Gatekeeper / F-Secure Gatekeeper][Running/Auto Start]
<\??\C:\Program Files\F-Secure\Anti-Virus\Win2K\FSgk.sys><>
[F-Secure File System Recognizer / F-Secure Recognizer][Running/Auto Start]
<\??\C:\Program Files\F-Secure\Anti-Virus\Win2K\FSrec.sys><>
[F-Secure Policy Manager / FSpm][Running/Auto Start]
<\??\C:\Program Files\F-Secure\Common\FSPM.SYS><F-Secure Corporation>
[GhostPciScanner / GhPciScan][Running/System Start]
<\??\D:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys><Symantec Corporation>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HSF_DPV / HSF_DPV][Running/Manual Start]
<system32\DRIVERS\hsx_dpv.sys><Conexant Systems, Inc.>
[HSXHWAZL / HSXHWAZL][Running/Manual Start]
<system32\DRIVERS\hsxhwazl.sys><Conexant Systems, Inc.>
[ialm / ialm][Running/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[Intel AHCI Controller / iaStor][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\iaStor.sys><Intel Corporation>
[ibmfilter / ibmfilter][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\ibmfilter.sys><IBM>
[IBMPMDRV / IBMPMDRV][Running/Manual Start]
<system32\DRIVERS\ibmpmdrv.sys><Lenovo.>
[IBMTPCHK / IBMTPCHK][Running/System Start]
<\??\C:\WINDOWS\system32\Drivers\IBMBLDID.sys><N/A>
[ini910u / ini910u][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ini910u.sys><Microsoft Corporation>
[mdmxsdk / mdmxsdk][Running/Auto Start]
<system32\DRIVERS\mdmxsdk.sys><Conexant>
[mraid35x / mraid35x][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\mraid35x.sys><American Megatrends Inc.>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[NSC Infrared Device Driver / NSCIRDA][Running/Manual Start]
<system32\DRIVERS\nscirda.sys><National Semiconductor Corporation>
[nv / nv][Stopped/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[pmem / pmem][Running/Auto Start]
<\??\C:\WINDOWS\System32\drivers\pmemnt.sys><Microsoft Corporation>
[PrivateDisk / PrivateDisk][Running/Auto Start]
<\??\C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\PrivateDiskM.sys><Utimaco Safeware AG>
[IPS Helper Driver / PROCDD][Running/Auto Start]
<system32\DRIVERS\PROCDD.SYS><Lenovo Group Limited>
[IBM PSA Access Driver / psadd][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\Drivers\psadd.sys><Lenovo>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[ql1080 / ql1080][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ql1080.sys><QLogic Corporation>
[Ql10wnt / Ql10wnt][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ql10wnt.sys><Microsoft Corporation>
[ql12160 / ql12160][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ql12160.sys><QLogic Corporation>
[ql1280 / ql1280][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ql1280.sys><QLogic Corporation>
[WLAN Transport / s24trans][Running/Auto Start]
<system32\DRIVERS\s24trans.sys><Intel Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[SIS AGP Bus Filter / sisagp][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\sisagp.sys><Silicon Integrated Systems Corporation>
[Smapint / Smapint][Running/System Start]
<System32\drivers\Smapint.sys><Microsoft Corporation>
[smi2 / smi2][Running/Auto Start]
<\??\C:\Program Files\SMI2\smi2.sys><IBM Corp.>
[Sparrow / Sparrow][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\sparrow.sys><Adaptec, Inc.>
[symc810 / symc810][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\symc810.sys><Symbios Logic Inc.>
[symc8xx / symc8xx][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\symc8xx.sys><LSI Logic>
[sym_hi / sym_hi][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\sym_hi.sys><LSI Logic>
[sym_u3 / sym_u3][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\sym_u3.sys><LSI Logic>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
<system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[TDSMAPI / TDSMAPI][Running/System Start]
<System32\drivers\TDSMAPI.SYS><N/A>
[TosIde / TosIde][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\toside.sys><Microsoft Corporation>
[TPPWRIF / TPPWRIF][Running/System Start]
<System32\drivers\Tppwrif.sys><N/A>
[TSMAPIP / TSMAPIP][Running/System Start]
<System32\drivers\TSMAPIP.SYS><N/A>
[ultra / ultra][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ultra.sys><Promise Technology, Inc.>
[ViaIde / ViaIde][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[Intel(R) PRO/Wireless 3945ABG Adapter Driver / w39n51][Running/Manual Start]
<system32\DRIVERS\w39n51.sys><Intel? Corporation>
[winachsf / winachsf][Running/Manual Start]
<system32\DRIVERS\hsx_cnxt.sys><Conexant Systems, Inc.>
qrzz - 2007-6-12 7:10:00
浏览器加载项
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[ThunderAtOnce Class]
{01443AEC-0FD1-40FD-9C87-E93D1494C233} <D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>
[Skype add-on (mastermind)]
{22BF413B-C6D2-4D91-82A9-A0F997BA588C} <C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll, Skype Technologies S.A.>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[XML DOM Document]
{2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\system32\msxml3.dll, N/A>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <D:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <d:\Program Files\Tencent\QQ\QQIEHelper.dll, N/A>
[DriveLetterAccess]
{5CA3D70E-1895-11CF-8E15-001234567890} <C:\WINDOWS\System32\DLA\DLASHX_W.DLL, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[MediaComm Class]
{7670648D-461B-42AF-BDFE-46D26AF5EFF2} <D:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin12.dll, Thunder Networking Technologies,LTD>
[Skype add-on (button)]
{77BF5300-1474-4EC7-9980-D32B190E9B07} <C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll, Skype Technologies S.A.>
[Microsoft Web Browser]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, N/A>
[XML DOM Document 4.0]
{88D969C0-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml4.dll, Microsoft Corporation>
[NavigatMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\Program Files\360safe\safemon\safemon.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Adobe PDF Reader]
{CA8A9780-280D-11CF-A24D-444553540000} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroPDF.dll, Adobe Systems, Inc.>
[d:\Program Files\Tencent\QQ\QQPlayerSvr.exe]
{CD108273-D434-43E6-AA90-1469F97EB398} <, N/A>
[AUDIO__MP3 Moniker Class]
{CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[XML HTTP Request]
{ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\system32\msxml3.dll, N/A>
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\system32\msxml3.dll, N/A>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用迅雷下载]
<D:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[使用迅雷下载全部链接]
<D:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
qrzz - 2007-6-12 7:11:00
正在运行的进程
[PID: 856][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 904][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 928][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2645 (xpsp.050331-1524)]
[C:\WINDOWS\system32\WgaLogon.dll] [Microsoft Corporation, 1.7.0018.5]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 972][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 984][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\IBM ThinkVantage\Client Security Solution\csspwntfy.dll] [Lenovo Group Limited, 6.01.0044.00]
[C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtsp.dll] [IBM, 1,1,2,009]
[C:\Program Files\IBM ThinkVantage\Client Security Solution\tcsrpc.dll] [IBM, 1,1,2,009]
[C:\Program Files\IBM ThinkVantage\Client Security Solution\cssuserdatadispatcher.dll] [Lenovo Group Limited, 6.01.0044.00]
[PID: 1352][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[C:\WINDOWS\system32\Sysup32.dll] [N/A, ]
[C:\PROGRA~1\WINDOW~2\wmpband.dll] [Microsoft Corporation, 10.00.00.3646]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[C:\WINDOWS\system32\SynTPFcs.dll] [Synaptics, Inc., 7.5.17.18 15Sep05]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\TEMP\IadHide4.dll] [BackWeb, Version 6.1.4 (Build 58R)]
[C:\Program Files\Internet Explorer\mui\0804\browselc.dll] [Microsoft Corporation, 6.00.2600.0000 (xpclient.010817-1148)]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.9.2006121800]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 1, 0, 0, 0]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[PID: 1460][C:\Program Files\Synaptics\SynTP\SynTPLpr.exe] [Synaptics, Inc., 7.5.17.18 15Sep05]
[C:\WINDOWS\system32\SynTPFcs.dll] [Synaptics, Inc., 7.5.17.18 15Sep05]
[PID: 1552][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] [Synaptics, Inc., 7.5.17.18 15Sep05]
[C:\WINDOWS\system32\SynCOM.dll] [Synaptics, Inc., 7.5.17.18 15Sep05]
[C:\WINDOWS\system32\SynTPAPI.dll] [Synaptics, Inc., 7.5.17.18 15Sep05]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[C:\WINDOWS\system32\SynTPFcs.dll] [Synaptics, Inc., 7.5.17.18 15Sep05]
[PID: 1600][C:\WINDOWS\system32\TpShocks.exe] [Lenovo, Ltd. and IBM Corporation., 1, 3, 4, 0]
[C:\Program Files\ThinkPad\TpShocks\MUI\0804\TpShocks.dll] [Lenovo, Ltd. and IBM Corporation., 1, 3, 3, 0]
[C:\WINDOWS\system32\Sensor.dll] [Lenovo., 1.40]
[PID: 1668][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3.0.0.4436]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4436]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4436]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4436]
[PID: 1672][C:\WINDOWS\system32\igfxpers.exe] [Intel Corporation, 3.0.0.4436]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4436]
[C:\WINDOWS\system32\SynTPFcs.dll] [Synaptics, Inc., 7.5.17.18 15Sep05]
[PID: 1704][C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe] [Lenovo Group Limited, 1, 0, 0, 0]
[C:\PROGRA~1\ThinkPad\UTILIT~1\SC\EzMApRes.dll] [N/A, ]
[PID: 1744][C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe] [N/A, ]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\Oemdspif.dll] [Intel Corporation, 3.0.0.4436]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3.0.0.4436]
[C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\tpfnf7.dll] [N/A, ]
[PID: 1712][C:\Program Files\Analog Devices\Core\smax4pnp.exe] [Analog Devices, Inc., 6, 0, 0, 20]
[C:\Program Files\Analog Devices\Core\SMWDMIF.dll] [Analog Devices, Inc., 6, 0, 4200, 014]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1860][C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe] [N/A, ]
[PID: 1868][C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe] [Lenovo Group Limited, 1.16]
[PID: 1888][C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe] [Lenovo Group Limited, 1, 0, 0, 1]
[C:\PROGRA~1\THINKV~1\PrdCtr\SC\LPRESMGR.DLL] [N/A, ]
[C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 1, 0, 0, 0]
[C:\WINDOWS\TEMP\IadHide4.dll] [BackWeb, Version 6.1.4 (Build 58R)]
[C:\WINDOWS\system32\SynTPFcs.dll] [Synaptics, Inc., 7.5.17.18 15Sep05]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\TrayRes.dll] [Lenovo, 4, 0, 0, 0]
[PID: 1892][C:\Program Files\ThinkVantage\AMSG\Amsg.exe] [LENOVO, 1, 0, 0, 0]
[C:\Program Files\ThinkVantage\AMSG\AHLPRUNL.dll] [N/A, ]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[C:\PROGRA~1\THINKV~1\AMSG\AcpPollingEngine.dll] [, 1, 0, 0, 7]
[C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 1, 0, 0, 0]
[C:\WINDOWS\TEMP\IadHide4.dll] [BackWeb, Version 6.1.4 (Build 58R)]
[C:\WINDOWS\system32\SynTPFcs.dll] [Synaptics, Inc., 7.5.17.18 15Sep05]
[PID: 1908][C:\WINDOWS\System32\DLA\DLACTRLW.EXE] [Sonic Solutions, 5.10.15a]
[C:\WINDOWS\system32\DLAAPI_W.DLL] [Sonic Solutions, 5.10.15a]
[C:\WINDOWS\System32\DLA\DLACResW.dll] [Sonic Solutions, 5.10.15a]
[PID: 1948][C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe] [InstallShield Software Corporation, 3, 10, 100, 1155]
[PID: 1980][C:\Program Files\Picasa2\PicasaMediaDetector.exe] [Google Inc., 2.1.0]
[PID: 252][C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe] [Lenovo, 4, 11, 0, 0]
[C:\Program Files\ThinkPad\ConnectUtilities\AcLocSettings.dll] [N/A, ]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\ThinkPad\ConnectUtilities\ACGUIHlpr.dll] [Lenovo, 4, 11, 0, 0]
[C:\Program Files\ThinkPad\ConnectUtilities\AcSvcStub.dll] [N/A, ]
[C:\Program Files\ThinkPad\ConnectUtilities\ACHelper.dll] [N/A, ]
[C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgr.dll] [N/A, ]
[C:\Program Files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll] [N/A, ]
[C:\WINDOWS\system32\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\GUIHlprRes.dll] [Lenovo, 4, 0, 0, 0]
[C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\TrayRes.dll] [Lenovo, 4, 0, 0, 0]
[C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 1, 0, 0, 0]
[C:\WINDOWS\TEMP\IadHide4.dll] [BackWeb, Version 6.1.4 (Build 58R)]
[C:\WINDOWS\system32\SynTPFcs.dll] [Synaptics, Inc., 7.5.17.18 15Sep05]
[PID: 432][C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe] [Lenovo, 4, 11, 0, 0]
[C:\Program Files\ThinkPad\ConnectUtilities\AcLocSettings.dll] [N/A, ]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\ThinkPad\ConnectUtilities\ACGUIHlpr.dll] [Lenovo, 4, 11, 0, 0]
[C:\Program Files\ThinkPad\ConnectUtilities\AcSvcStub.dll] [N/A, ]
[C:\Program Files\ThinkPad\ConnectUtilities\ACHelper.dll] [N/A, ]
[C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgr.dll] [N/A, ]
[C:\Program Files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll] [N/A, ]
[C:\WINDOWS\system32\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\GUIHlprRes.dll] [Lenovo, 4, 0, 0, 0]
[C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\IconRes.dll] [Lenovo, 4, 0, 0, 0]
[C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 1, 0, 0, 0]
[C:\WINDOWS\TEMP\IadHide4.dll] [BackWeb, Version 6.1.4 (Build 58R)]
[C:\WINDOWS\system32\SynTPFcs.dll] [Synaptics, Inc., 7.5.17.18 15Sep05]
[PID: 448][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL] [Lenovo Group Limited, 1, 0, 0, 0]
[C:\PROGRA~1\ThinkPad\UTILIT~1\SC\PWRMGRRT.DLL] [N/A, ]
[C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRIF.DLL] [N/A, ]
[C:\WINDOWS\system32\Sensor.dll] [Lenovo., 1.40]
[C:\WINDOWS\system32\OEMDSPIF.DLL] [Intel Corporation, 3.0.0.4436]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3.0.0.4436]
qrzz - 2007-6-12 7:12:00
[PID: 536][C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe] [Lenovo Group Limited, 6.01.0044.00]
[C:\Program Files\IBM ThinkVantage\Client Security Solution\cssuserdatadispatcher.dll] [Lenovo Group Limited, 6.01.0044.00]
[C:\Program Files\IBM ThinkVantage\Client Security Solution\csswait.dll] [Lenovo Group Limited, 6.01.0044.00]
[C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtsp.dll] [IBM, 1,1,2,009]
[C:\Program Files\IBM ThinkVantage\Client Security Solution\tcsrpc.dll] [IBM, 1,1,2,009]
[C:\Program Files\IBM ThinkVantage\Client Security Solution\cssdlgpwentry.dll] [Lenovo Group Limited, 6.01.0044.00]
[C:\Program Files\IBM ThinkVantage\Client Security Solution\dlganswerprompt.dll] [Lenovo Group Limited, 6.01.0044.00]
[C:\WINDOWS\system32\SynTPFcs.dll] [Synaptics, Inc., 7.5.17.18 15Sep05]
[C:\WINDOWS\TEMP\IadHide4.dll] [BackWeb, Version 6.1.4 (Build 58R)]
[PID: 560][C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe] [Utimaco Safeware AG, 1.10.2.1]
[C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\PDLib.dll] [Utimaco Safeware AG, 1.10.2.1]
[C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\PDLib0804.dll] [Utimaco Safeware AG, 1.10.2.1]
[C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice0804.dll] [Utimaco Safeware AG, 1.10.2.1]
[PID: 636][D:\Program Files\D-Tools\daemon.exe] [DAEMON'S HOME, 3.44.0.0]
[C:\WINDOWS\daemon.dll] [, 3.44.0.0]
[D:\Program Files\D-Tools\PFCTOC.DLL] [Padus(R), Inc., 1, 0, 0, 12]
[D:\Program Files\D-Tools\Plugins\Images\bw5mount.dll] [, 1.0.1.0]
[D:\Program Files\D-Tools\Plugins\Images\ccdmount.dll] [GENERIC, 1.02.0.0]
[D:\Program Files\D-Tools\Plugins\Images\mdsmount.dll] [GENERIC, 1.01.0.0]
[D:\Program Files\D-Tools\Plugins\Images\nrgmount.dll] [GENERIC, 1.02.0.0]
[D:\Program Files\D-Tools\Plugins\Images\pdimount.dll] [GENERIC, 1.01.0.0]
[PID: 640][D:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe] [Symantec Corporation, 2003.775]
[PID: 648][C:\Program Files\F-Secure\Common\FSM32.EXE] [F-Secure Corporation, 5.00.5420 ]
[C:\Program Files\F-Secure\Common\FSPMAPI.dll] [F-Secure Corporation, 5.00.5420 ]
[C:\Program Files\F-Secure\Common\FSMA32.dll] [F-Secure Corporation, 5.00.5420 ]
[C:\Program Files\F-Secure\Common\FSLD32.dll] [F-Secure Corporation, 5.00.5420 ]
[C:\Program Files\F-Secure\Common\FSABOUT.dll] [F-Secure Corporation, 5.00.5420 ]
[C:\Program Files\F-Secure\Common\fsexc.dll] [F-Secure Corporation, 5.00.5420 ]
[C:\Program Files\F-Secure\Common\fsmres.eng] [F-Secure Corporation, 5.00.5420 ]
[C:\WINDOWS\TEMP\IadHide4.dll] [BackWeb, Version 6.1.4 (Build 58R)]
[C:\WINDOWS\system32\SynTPFcs.dll] [Synaptics, Inc., 7.5.17.18 15Sep05]
[C:\Program Files\F-Secure\Anti-Virus\fsmuiav.dll] [F-Secure Corporation, 5.42.10220]
[C:\Program Files\F-Secure\Anti-Virus\FSAVURES.ENG] [N/A, ]
[C:\Program Files\F-Secure\BackWeb\7681197\Program\fsbwui.dll] [F-Secure Corporation, 6.20.285]
[C:\Program Files\F-Secure\Common\fsmaui32.dll] [F-Secure Corporation, 5.00.5420 ]
[C:\Program Files\F-Secure\Common\fsmaures.eng] [F-Secure Corporation, 5.00.5420 ]
[C:\Program Files\F-Secure\Common\fsabtres.eng] [F-Secure Corporation, 5.00.5420 ]
[C:\Program Files\F-Secure\Anti-Virus\FSTSM.DLL] [F-Secure Corporation, 5.42.9450]
[C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 1, 0, 0, 0]
[C:\Program Files\F-Secure\Anti-Virus\FSAVDW.DLL] [, 5.40.8400]
[PID: 652][C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe] [GRISOFT s.r.o., 7, 5, 1, 36]
[C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll] [GRISOFT s.r.o., 4, 2, 0, 19]
[C:\WINDOWS\TEMP\IadHide4.dll] [BackWeb, Version 6.1.4 (Build 58R)]
[C:\WINDOWS\system32\SynTPFcs.dll] [Synaptics, Inc., 7.5.17.18 15Sep05]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[PID: 660][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 672][D:\Program Files\jj4\jiajiasr.exe] [加加工作组, 4, 1, 0, 47]
[C:\WINDOWS\system32\SynTPFcs.dll] [Synaptics, Inc., 7.5.17.18 15Sep05]
[PID: 728][C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe] [Adobe Systems Incorporated, 7.0.5.2005092300]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 784][C:\Program Files\Digital Line Detect\DLG.exe] [BVRP Software, 1, 0, 0, 1]
[C:\Program Files\Digital Line Detect\BVRPDIAG.dll] [BVRP Software, 1.0]
[C:\WINDOWS\system32\MdmXSdk.dll] [Conexant, 1.0.2.010]
[PID: 1036][C:\Program Files\WinRAR\WinRAR.exe] [N/A, ]
[C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 1, 0, 0, 0]
[C:\WINDOWS\TEMP\IadHide4.dll] [BackWeb, Version 6.1.4 (Build 58R)]
[C:\WINDOWS\system32\SynTPFcs.dll] [Synaptics, Inc., 7.5.17.18 15Sep05]
[C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.3790.3646 built by: DNSRV(bld4act)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[PID: 4296][C:\DOCUME~1\LAI\LOCALS~1\Temp\Rar$EX00.407\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16441 (vista_gdr.070219-1500)]
[C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 1, 0, 0, 0]
[C:\WINDOWS\TEMP\IadHide4.dll] [BackWeb, Version 6.1.4 (Build 58R)]
[C:\WINDOWS\system32\SynTPFcs.dll] [Synaptics, Inc., 7.5.17.18 15Sep05]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
隐藏进程
[1964] C:\WINDOWS\system32\xcopy.exe
==================================
[/CODE]
© 2000 - 2026 Rising Corp. Ltd.