瑞星卡卡安全论坛
ogim - 2007-8-11 14:46:00
[CODE]
2006-08-11,10:53:06
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<8tjsr><; C:\DOCUME~1\888\LOCALS~1\Temp\winlog0n.exe> [N/A]
<lq9k3dc><; C:\DOCUME~1\888\LOCALS~1\Temp\Servera.exe> [N/A]
<lr1svi3k8ruhd><; C:\DOCUME~1\888\LOCALS~1\Temp\c0nime.exe> [N/A]
<lw6dyc><; C:\DOCUME~1\888\LOCALS~1\Temp\crasos.exe> [N/A]
<MsnMsgr><; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><; ?
?粒?粒粒?
?
??
?粓?> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Apoint><; C:\Program Files\Apoint\Apoint.exe> [(Verified)Microsoft Windows Publisher]
<HKSERV.EXE><; C:\Program Files\Sony\HotKey Utility\HKserv.exe> [Sony Corporation]
<RAVMSMON><C:\WINDOWS\system32\RAVMSMON.exe> []
<RAVZTMON><C:\WINDOWS\Fonts\RAVZTMON.exe> []
<RAVQJMON><C:\WINDOWS\system32\RAVQJMON.exe> []
<RAVCHDMON><C:\WINDOWS\system32\RAVCHDMON.exe> []
<RAV009F><C:\WINDOWS\system32\RAV009F.exe> []
<AVPDH><; C:\WINDOWS\system32\AVPDH.exe> []
<BluetoothAuthenticationAgent><; rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent> [(Verified)Microsoft Windows Publisher]
<fdbcs><; C:\WINDOWS\fdbcs.exe> [N/A]
<HotKeysCmds><; C:\WINDOWS\system32\hkcmd.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<IgfxTray><; C:\WINDOWS\system32\igfxtray.exe> [(Verified)Microsoft Windows Publisher]
<IMEKRMIG6.1><; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE> [(Verified)Microsoft Windows Publisher]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<ISBMgr.exe><; C:\Program Files\Sony\ISB Utility\ISBMgr.exe> [Sony Corporation]
<KernelFaultCheck><; %systemroot%\system32\dumprep 0 -k> [N/A]
<MSPY2002><; C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC> [(Verified)Microsoft Windows Publisher]
<NVDispDrv><; C:\WINDOWS\NVDispDrv.exe> []
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
<RAV008C><; C:\WINDOWS\system32\RAV008C.exe> [N/A]
<RAV0095><; C:\WINDOWS\system32\RAV0095.exe> [N/A]
<RAV009B><; C:\WINDOWS\system32\RAV009B.exe> [N/A]
<RAV00A0><; C:\WINDOWS\system32\RAV00A0.exe> [N/A]
<RAV00AE><; C:\WINDOWS\system32\RAV00AE.exe> []
<RAV00CF><; C:\WINDOWS\system32\RAV00CF.exe> []
<RAV012F><; C:\WINDOWS\system32\RAV012F.exe> [N/A]
<RAVCQMON><; C:\WINDOWS\system32\RAVCQMON.exe> []
<RAVWLMON><; C:\WINDOWS\system32\RAVWLMON.exe> []
<SonyPowerCfg><; C:\Program Files\Sony\VAIO Power Management\SPMgr.exe> [Sony Corporation]
<Switcher.exe><; C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe> [Sony Corporation]
<Symantec NetDriver Monitor><; C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer> [(Verified)Symantec Corporation]
<winform><; C:\WINDOWS\winform.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<MSDEG32 ><; LYLoader.exe> [N/A]
<WinAutoUp><; C:\WINDOWS\AutoUp.exe> []
<adsnt><; C:\WINDOWS\AdsNT.exe> []
<minver><C:\WINDOWS\system32\minver32.exe> []
<visin><C:\WINDOWS\system32\visin.exe> [Microsoft Corporation]
<usrinit><; C:\WINDOWS\system32\usrinit.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><qhbpri.dll> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{A6011F8F-A7F8-49AA-9ADA-49127D43138F}><> [N/A]
<{729B6C61-BDC5-4C09-A1DE-A296BA0B89EC}><> [N/A]
<{2133B3FD-315E-4523-BD1A-22F723DFBCA3}><C:\WINDOWS\system32\jpqpri.dll> [N/A]
<{131AB311-16F1-F13B-1E43-11A24B51AFD1}><C:\WINDOWS\system32\gdipri.dll> [N/A]
<{8D8357F8-F053-42ec-B632-CEB8AC12745C}><c:\program files\common files\symantec shared\tydlzsrs.dll> [N/A]
<{014A26F5-FBAD-4549-9CA1-C38210704BD1}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\System16.ins> []
<{613AF41A-21B1-131B-1BFC-D2A90DF4A2B6}><C:\WINDOWS\system32\xyepri.dll> [N/A]
<{40117B96-998D-4D80-8F89-5E9DBD9F3460}><C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys> []
<{2562452F-FA36-BA4F-892A-FF5FBBAC5312}><C:\WINDOWS\system32\mybpri.dll> []
<{252D2432-37A2-324F-2A54-21BF5CF2F1A2}><C:\WINDOWS\system32\jhapri.dll> []
<{26368135-64FA-BC34-DA32-DCF4FD431C92}><C:\WINDOWS\system32\qhbpri.dll> []
<{54123FF1-8371-9834-9021-184518451FA5}><C:\WINDOWS\system32\qjepri.dll> [N/A]
<{459AFD5B-159F-ACD8-954C-ACD545FA6584}><C:\WINDOWS\system32\jzdpri.dll> [N/A]
<{3562452F-FA36-BA4F-892A-FF5FBBAC5313}><C:\WINDOWS\system32\mycpri.dll> [N/A]
<{559AFD5B-159F-ACD8-954C-ACD545FA6585}><C:\WINDOWS\system32\jzepri.dll> []
<{913AF41A-21B1-131B-1BFC-D2A90DF4A2B9}><C:\WINDOWS\system32\xyhpri.dll> []
<{1182C1EB-375C-573D-1F5E-234552345211}><C:\WINDOWS\system32\wldpri.dll> []
<{2F12545B-1212-1314-5679-4512ACEF8902}><C:\WINDOWS\system32\wdbpri.dll> []
<{4562452F-FA36-BA4F-892A-FF5FBBAC5314}><C:\WINDOWS\system32\mydpri.dll> []
<{759AFD5B-159F-ACD8-954C-ACD545FA6587}><C:\WINDOWS\system32\jzgpri.dll> []
<{32311A42-AC1B-158F-FD32-5674345F23A3}><C:\WINDOWS\system32\dhcpri.dll> []
<{3F12545B-1212-1314-5679-4512ACEF8903}><C:\WINDOWS\system32\wdcpri.dll> []
<{5EF04A55-4A55-EF08-55EF-A55F0A55EF08}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\4A55EF08.dll> []
<{3182C1EB-375C-573D-1F5E-234552345213}><C:\WINDOWS\system32\wlfpri.dll> []
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
ogim - 2007-8-11 14:48:00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
<WinlogonNotify: NavLogon><C:\WINDOWS\system32\NavLogon.dll> [(Verified)Symantec Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe]
<IFEO[360rpt.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Safe.exe]
<IFEO[360Safe.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe]
<IFEO[360tray.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adam.exe]
<IFEO[adam.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AgentSvr.exe]
<IFEO[AgentSvr.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppSvc32.exe]
<IFEO[AppSvc32.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoruns.exe]
<IFEO[autoruns.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrssvc.exe]
<IFEO[avgrssvc.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvMonitor.exe]
<IFEO[AvMonitor.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.com]
<IFEO[avp.com]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe]
<IFEO[avp.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe]
<IFEO[CCenter.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe]
<IFEO[ccSvcHst.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FileDsty.exe]
<IFEO[FileDsty.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FTCleanerShell.exe]
<IFEO[FTCleanerShell.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HijackThis.exe]
<IFEO[HijackThis.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IceSword.exe]
<IFEO[IceSword.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iparmo.exe]
<IFEO[iparmo.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iparmor.exe]
<IFEO[Iparmor.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\isPwdSvc.exe]
<IFEO[isPwdSvc.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kabaload.exe]
<IFEO[kabaload.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KaScrScn.SCR]
<IFEO[KaScrScn.SCR]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASMain.exe]
<IFEO[KASMain.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASTask.exe]
<IFEO[KASTask.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAV32.exe]
<IFEO[KAV32.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVDX.exe]
<IFEO[KAVDX.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPFW.exe]
<IFEO[KAVPFW.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVSetup.exe]
<IFEO[KAVSetup.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
ogim - 2007-8-11 14:48:00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVStart.exe]
<IFEO[KAVStart.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KISLnchr.exe]
<IFEO[KISLnchr.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMailMon.exe]
<IFEO[KMailMon.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMFilter.exe]
<IFEO[KMFilter.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32.exe]
<IFEO[KPFW32.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32X.exe]
<IFEO[KPFW32X.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFWSvc.exe]
<IFEO[KPFWSvc.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRegEx.exe]
<IFEO[KRegEx.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\krepair.COM]
<IFEO[krepair.COM]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KsLoader.exe]
<IFEO[KsLoader.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVCenter.kxp]
<IFEO[KVCenter.kxp]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvDetect.exe]
<IFEO[KvDetect.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvfwMcl.exe]
<IFEO[KvfwMcl.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP.kxp]
<IFEO[KVMonXP.kxp]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP_1.kxp]
<IFEO[KVMonXP_1.kxp]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvol.exe]
<IFEO[kvol.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvolself.exe]
<IFEO[kvolself.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvReport.kxp]
<IFEO[KvReport.kxp]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVScan.kxp]
<IFEO[KVScan.kxp]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVSrvXP.exe]
<IFEO[KVSrvXP.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVStub.kxp]
<IFEO[KVStub.kxp]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvupload.exe]
<IFEO[kvupload.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvwsc.exe]
<IFEO[kvwsc.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP.kxp]
<IFEO[KvXP.kxp]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP_1.kxp]
<IFEO[KvXP_1.kxp]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch.exe]
<IFEO[KWatch.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch9x.exe]
<IFEO[KWatch9x.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatchX.exe]
<IFEO[KWatchX.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
ogim - 2007-8-11 14:49:00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\loaddll.exe]
<IFEO[loaddll.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MagicSet.exe]
<IFEO[MagicSet.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcconsol.exe]
<IFEO[mcconsol.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmqczj.exe]
<IFEO[mmqczj.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmsk.exe]
<IFEO[mmsk.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVSetup.exe]
<IFEO[NAVSetup.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32krn.exe]
<IFEO[nod32krn.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32kui.exe]
<IFEO[nod32kui.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFW.exe]
<IFEO[PFW.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFWLiveUpdate.exe]
<IFEO[PFWLiveUpdate.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QHSET.exe]
<IFEO[QHSET.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ras.exe]
<IFEO[Ras.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rav.exe]
<IFEO[Rav.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMon.exe]
<IFEO[RavMon.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe]
<IFEO[RavMonD.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStub.exe]
<IFEO[RavStub.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe]
<IFEO[RavTask.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegClean.exe]
<IFEO[RegClean.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwcfg.exe]
<IFEO[rfwcfg.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RfwMain.exe]
<IFEO[RfwMain.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwProxy.exe]
<IFEO[rfwProxy.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe]
<IFEO[rfwsrv.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsAgent.exe]
<IFEO[RsAgent.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rsaupd.exe]
<IFEO[Rsaupd.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe]
<IFEO[runiep.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safelive.exe]
<IFEO[safelive.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe]
<IFEO[scan32.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shcfg32.exe]
<IFEO[shcfg32.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmartUp.exe]
<IFEO[SmartUp.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SREng.exe]
<IFEO[SREng.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe]
<IFEO[symlcsvc.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SysSafe.exe]
<IFEO[SysSafe.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojanDetector.exe]
<IFEO[TrojanDetector.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
ogim - 2007-8-11 14:50:00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Trojanwall.exe]
<IFEO[Trojanwall.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojDie.kxp]
<IFEO[TrojDie.kxp]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UIHost.exe]
<IFEO[UIHost.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAgent.exe]
<IFEO[UmxAgent.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAttachment.exe]
<IFEO[UmxAttachment.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxCfg.exe]
<IFEO[UmxCfg.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxFwHlp.exe]
<IFEO[UmxFwHlp.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxPol.exe]
<IFEO[UmxPol.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UpLive.EXE.exe]
<IFEO[UpLive.EXE.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WoptiClean.exe]
<IFEO[WoptiClean.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zxsweep.exe]
<IFEO[zxsweep.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
ogim - 2007-8-11 14:50:00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Trojanwall.exe]
<IFEO[Trojanwall.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojDie.kxp]
<IFEO[TrojDie.kxp]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UIHost.exe]
<IFEO[UIHost.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAgent.exe]
<IFEO[UmxAgent.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAttachment.exe]
<IFEO[UmxAttachment.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxCfg.exe]
<IFEO[UmxCfg.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxFwHlp.exe]
<IFEO[UmxFwHlp.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxPol.exe]
<IFEO[UmxPol.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UpLive.EXE.exe]
<IFEO[UpLive.EXE.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WoptiClean.exe]
<IFEO[WoptiClean.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zxsweep.exe]
<IFEO[zxsweep.exe]><C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\4A55EF08.dat> []
ogim - 2007-8-11 14:54:00
=================================
启动文件夹
N/A
==================================
服务
[831E1E90 / 831E1E90][Stopped/Disabled]
<C:\WINDOWS\system32\831E1E90.EXE -d><N/A>
[Application Management / AppMgmt][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Symantec Event Manager / ccEvtMgr][Stopped/Disabled]
<"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Network Proxy / ccProxy][Stopped/Disabled]
<"C:\Program Files\Common Files\Symantec Shared\ccProxy.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc][Stopped/Disabled]
<"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr][Stopped/Disabled]
<"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[CoolWare / CoolWare][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\duce.dll><>
[Windows ctbd RunThem / ctbd][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\xowy\hygi.dll><>
[Symantec AntiVirus Definition Watcher / DefWatch][Stopped/Disabled]
<"C:\Program Files\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[EvtEng / EvtEng][Running/Auto Start]
<C:\Program Files\Intel\Wireless\Bin\EvtEng.exe><Intel Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[ISSVC / ISSVC][Stopped/Disabled]
<"C:\Program Files\Norton Internet Security\ISSVC.exe"><Symantec Corporation>
[Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><>
[MSCSPTISRV / MSCSPTISRV][Stopped/Manual Start]
<"C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe"><Sony Corporation>
[PACSPTISVR / PACSPTISVR][Stopped/Manual Start]
<"C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe"><Sony Corporation>
[RegSrvc / RegSrvc][Stopped/Auto Start]
<C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe><Intel Corporation>
[Spectrum24 Event Monitor / S24EventMonitor][Stopped/Auto Start]
<C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe><Intel Corporation>
[SavRoam / SavRoam][Stopped/Disabled]
<"C:\Program Files\Symantec AntiVirus\SavRoam.exe"><symantec>
[Symantec Network Drivers Service / SNDSrvc][Stopped/Disabled]
<"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[Symantec SPBBCSvc / SPBBCSvc][Stopped/Disabled]
<"C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"><Symantec Corporation>
[Sony SPTI Service / SPTISRV][Stopped/Manual Start]
<"C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe"><Sony Corporation>
[SonicStage SCSI Service / SSScsiSV][Stopped/Manual Start]
<C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe><Sony Corporation>
[Symantec AntiVirus / Symantec AntiVirus][Stopped/Disabled]
<"C:\Program Files\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>
[VAIO Entertainment Aggregation and Control Service / VAIO Entertainment Aggregation and Control Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe"><Sony Corporation>
[VAIO Entertainment Task Scheduler / VAIO Entertainment Task Scheduler][Stopped/Manual Start]
<"C:\Program Files\Sony\VAIO Entertainment\VzTaskScheduler.exe"><Sony Corporation>
[VAIO Entertainment TV Device Arbitration Service / VAIO Entertainment TV Device Arbitration Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe"><Sony Corporation>
[VAIO Media Integrated Server / VAIOMediaPlatform-IntegratedServer-AppServer][Stopped/Manual Start]
<C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe><Sony Corporation>
[VAIO Media Integrated Server (HTTP) / VAIOMediaPlatform-IntegratedServer-HTTP][Stopped/Manual Start]
<"C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP"><Sony Corporation>
[VAIO Media Integrated Server (UPnP) / VAIOMediaPlatform-IntegratedServer-UPnP][Stopped/Manual Start]
<C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe><Sony Corporation>
[VAIO Media Gateway Server / VAIOMediaPlatform-Mobile-Gateway][Stopped/Manual Start]
<"C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server"><Sony Corporation>
[VAIO Entertainment UPnP Client Adapter / Vcsw][Stopped/Manual Start]
<C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe -RunBySCM><Sony Corporation>
[NetworSVA / Visual Windows][Stopped/Auto Start]
<C:\WINDOWS\system32\wnipsvr.exe -Run><Microsoft Corporation>
[VAIO Entertainment Database Service / VzCdbSvc][Stopped/Auto Start]
<"C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe"><Sony Corporation>
[VAIO Entertainment File Import Service / VzFw][Stopped/Auto Start]
<C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe><Sony Corporation>
==================================
驱动程序
[aeaudio / aeaudio][Running/Manual Start]
<system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[AEGIS Protocol (IEEE 802.1x) v3.1.6.0 / AegisP][Running/Auto Start]
<system32\DRIVERS\AegisP.sys><Meetinghouse Data Communications>
ogim - 2007-8-11 14:54:00
[Alps Pointing-device Filter Driver / ApfiltrService][Running/Manual Start]
<system32\DRIVERS\Apfiltr.sys><Alps Electric Co., Ltd.>
[Sony DMI Call service / DMICall][Running/System Start]
<system32\DRIVERS\DMICall.sys><Sony Corporation>
[Intel(R) PRO Adapter Driver / E100B][Running/Manual Start]
<system32\DRIVERS\e100b325.sys><Intel Corporation>
[Extended Baud Rate Filter Driver / elExBaud][Running/Manual Start]
<system32\DRIVERS\elexbaud.sys><Windows (R) 2000 DDK provider>
[HSFHWICH / HSFHWICH][Running/Manual Start]
<system32\DRIVERS\HSFHWICH.sys><Conexant Systems, Inc.>
[HSF_DP / HSF_DP][Running/Manual Start]
<system32\DRIVERS\HSF_DP.sys><Conexant Systems, Inc.>
[ialm / ialm][Running/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[kirboao / kirboao][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\kirboao.sys><N/A>
[mdmxsdk / mdmxsdk][Running/Auto Start]
<system32\DRIVERS\mdmxsdk.sys><Conexant>
[NAVENG / NAVENG][Stopped/Disabled]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070809.033\naveng.sys><Symantec Corporation>
[NAVEX15 / NAVEX15][Stopped/Disabled]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070809.033\navex15.sys><Symantec Corporation>
[NetGroup Packet Filter Driver / NPF][Stopped/Manual Start]
<system32\drivers\npf.sys><CACE Technologies>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[WLAN Transport / s24trans][Running/Auto Start]
<system32\DRIVERS\s24trans.sys><Intel Corporation>
[SAVRT / SAVRT][Stopped/Disabled]
<\??\C:\Program Files\Symantec AntiVirus\savrt.sys><Symantec Corporation>
[SAVRTPEL / SAVRTPEL][Stopped/Disabled]
<\??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys><Symantec Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[smwdm / smwdm][Running/Manual Start]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[Sony Notebook Control Device / SNC][Running/Manual Start]
<System32\Drivers\SonyNC.sys><Sony Corporation>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start]
<system32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[SPBBCDrv / SPBBCDrv][Stopped/Disabled]
<\??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys><Symantec Corporation>
[Sony Programmable I/O Control Device / SPI][Running/Manual Start]
<system32\DRIVERS\SonyPI.sys><Sony Corporation>
[SYMDNS / SYMDNS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMDNS.SYS><Symantec Corporation>
[SymEvent / SymEvent][Running/Disabled]
<\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[SYMFW / SYMFW][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMFW.SYS><Symantec Corporation>
[SYMIDS / SYMIDS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMIDS.SYS><Symantec Corporation>
[SYMIDSCO / SYMIDSCO][Running/Disabled]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\idsdefs\20060322.078\symidsco.sys><Symantec Corporation>
[SYMNDIS / SYMNDIS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMNDIS.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI][Running/System Start]
<\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[tifmsony / tifmsony][Running/Manual Start]
<system32\drivers\tifmsony.sys><Texas Instruments>
[用于 Windows XP 的英特尔(R) PRO/无线 2200BG 网络连接驱动程序 / w29n51][Running/Manual Start]
<system32\DRIVERS\w29n51.sys><Intel? Corporation>
[winachsf / winachsf][Running/Manual Start]
<system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
==================================
浏览器加载项
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Windows Live Toolbar Helper]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, Microsoft Corporation>
[Java Plug-in 1.5.0_01]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll, Sun Microsystems, Inc.>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Java Plug-in 1.5.0_01]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.5.0_01]
{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll, Sun Microsystems, Inc.>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Windows Live Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, Microsoft Corporation>
[Windows Live Toolbar Helper]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\Flash.ocx, Macromedia, Inc.>
[&Windows Live Search]
<res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
==================================
ogim - 2007-8-11 14:55:00
正在运行的进程
[PID: 1144 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1304 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1328 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2505 (xpsp.040806-1825)]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[C:\WINDOWS\system32\NavLogon.dll] [Symantec Corporation, 9.0.1.1000]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1376 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[PID: 1388 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[PID: 1528 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[C:\WINDOWS\system32\wlfpri.dll] [N/A, ]
[C:\WINDOWS\system32\dhcpri.dll] [N/A, ]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\4A55EF08.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, ]
[PID: 1592 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[C:\WINDOWS\system32\isapir.dll] [N/A, ]
[PID: 1632 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\qhbpri.dll] [N/A, ]
[c:\windows\system32\duce.dll] [, 1, 0, 0, 5]
[C:\WINDOWS\system32\isapir.dll] [N/A, ]
[PID: 1684 / SYSTEM][C:\Program Files\Intel\Wireless\Bin\EvtEng.exe] [Intel Corporation, 9, 0, 1, 12]
[C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll] [Intel Corporation, 9, 0, 1, 14]
[C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL] [Intel Corporation, 9, 0, 1, 22]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[PID: 1916 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[PID: 2012 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[PID: 492 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[C:\WINDOWS\system32\adimon.dll] [Autodesk, Inc., 3,0,14,176]
[C:\WINDOWS\system32\heidi3.dll] [Autodesk, Inc., 3,0,14,176]
[C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.1897.0]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.1897.0]
[PID: 632 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\qhbpri.dll] [N/A, ]
[c:\progra~1\xowy\hygi.dll] [, 5, 0, 0, 8]
[c:\progra~1\xowy\kbjl.dll] [, 5, 0, 0, 8]
[c:\progra~1\xowy\pgoq.dll] [, 5, 0, 0, 8]
[c:\progra~1\xowy\mdln.dll] [, 5, 0, 0, 8]
[c:\progra~1\xowy\duce.dll] [, 5, 0, 0, 8]
[C:\WINDOWS\system32\isapir.dll] [N/A, ]
[PID: 720 / SYSTEM][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] [Analog Devices, Inc., 3, 2, 6, 0]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[PID: 760 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[PID: 2720 / 888][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\wldpri.dll] [N/A, ]
[c:\progra~1\xowy\kbjl.dll] [, 5, 0, 0, 8]
[c:\progra~1\xowy\pgoq.dll] [, 5, 0, 0, 8]
[C:\WINDOWS\system32\wlfpri.dll] [N/A, ]
[C:\WINDOWS\system32\dhcpri.dll] [N/A, ]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\4A55EF08.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, ]
[PID: 2876 / 888][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\progra~1\xowy\kbjl.dll] [, 5, 0, 0, 8]
[c:\progra~1\xowy\pgoq.dll] [, 5, 0, 0, 8]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\4A55EF08.dll] [N/A, ]
[C:\WINDOWS\system32\wlfpri.dll] [N/A, ]
[C:\WINDOWS\system32\dhcpri.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, ]
[PID: 2196 / 888][C:\WINDOWS\system32\mmc.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\progra~1\xowy\kbjl.dll] [, 5, 0, 0, 8]
[c:\progra~1\xowy\pgoq.dll] [, 5, 0, 0, 8]
[C:\WINDOWS\system32\wlfpri.dll] [N/A, ]
[C:\WINDOWS\system32\dhcpri.dll] [N/A, ]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\4A55EF08.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, ]
[PID: 4004 / 888][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\mydpri.dll] [N/A, ]
[c:\progra~1\xowy\kbjl.dll] [, 5, 0, 0, 8]
[c:\progra~1\xowy\pgoq.dll] [, 5, 0, 0, 8]
[C:\WINDOWS\system32\wlfpri.dll] [N/A, ]
[C:\WINDOWS\system32\dhcpri.dll] [N/A, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Windows Live Toolbar\msntb.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\zh-cn\mtbres.dll.mui] [Microsoft Corporation, 03.00.0001.2012]
[C:\Program Files\Windows Live Toolbar\mtbres.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\macromed\flash\Flash.ocx] [Macromedia, Inc., 7,0,19,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\isapir.dll] [N/A, ]
[C:\Program Files\Windows Live Toolbar\Tem.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\zh-cn\searchboxRes.dll.mui] [Microsoft Corporation, 03.00.0001.2012]
[C:\Program Files\Windows Live Toolbar\searchboxRes.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\zh-cn\CMRes.dll.mui] [Microsoft Corporation, 03.00.0001.2032]
[C:\Program Files\Windows Live Toolbar\CMRes.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\zh-cn\msn_slrs.DLL.mui] [Microsoft Corporation, 03.00.0001.2012]
[C:\Program Files\Windows Live Toolbar\msn_slrs.DLL] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\zh-cn\CBRes.dll.mui] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\CBRes.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\searchbox.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\stmain.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\cm.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\msn_slps.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\CB.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\WINDOWS\system32\xpsp3res.dll] [Microsoft Corporation, 5.1.2600.3121 (xpsp_sp2_gdr.070418-0032)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\4A55EF08.dll] [N/A, ]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, ]
[C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\wdcpri.dll] [N/A, ]
[C:\WINDOWS\system32\jzgpri.dll] [N/A, ]
[C:\WINDOWS\system32\wdbpri.dll] [N/A, ]
[C:\WINDOWS\system32\wldpri.dll] [N/A, ]
[C:\WINDOWS\system32\xyhpri.dll] [N/A, ]
[C:\WINDOWS\system32\jzepri.dll] [N/A, ]
[C:\WINDOWS\system32\mybpri.dll] [N/A, ]
[C:\WINDOWS\system32\RAVCHDMON.DAT] [N/A, ]
[C:\WINDOWS\system32\RAVQJMON.DAT] [N/A, ]
[C:\WINDOWS\Fonts\RAVZTMON.DAT] [N/A, ]
[C:\WINDOWS\system32\RAVMSMON.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV009F.DAT] [N/A, ]
ogim - 2007-8-11 14:58:00
[PID: 3372 / 888][C:\WINDOWS\system32\mydins.exe] [N/A, ]
[C:\WINDOWS\system32\wldpri.dll] [N/A, ]
[C:\WINDOWS\system32\mydpri.dll] [N/A, ]
[PID: 244 / 888][C:\WINDOWS\system32\dhcins.exe] [N/A, ]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[C:\WINDOWS\system32\dhcpri.dll] [N/A, ]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\4A55EF08.dll] [N/A, ]
[C:\WINDOWS\system32\wlfpri.dll] [N/A, ]
[C:\WINDOWS\system32\wdcpri.dll] [N/A, ]
[C:\WINDOWS\system32\jzgpri.dll] [N/A, ]
[C:\WINDOWS\system32\mydpri.dll] [N/A, ]
[C:\WINDOWS\system32\wdbpri.dll] [N/A, ]
[C:\WINDOWS\system32\wldpri.dll] [N/A, ]
[C:\WINDOWS\system32\xyhpri.dll] [N/A, ]
[C:\WINDOWS\system32\jzepri.dll] [N/A, ]
[C:\WINDOWS\system32\mybpri.dll] [N/A, ]
[PID: 1656 / 888][C:\WINDOWS\system32\wlfins.exe] [N/A, ]
[C:\WINDOWS\system32\wdcpri.dll] [N/A, ]
[C:\WINDOWS\system32\wlfpri.dll] [N/A, ]
[C:\WINDOWS\system32\dhcpri.dll] [N/A, ]
[PID: 1088 / 888][C:\WINDOWS\system32\jzgins.exe] [N/A, ]
[C:\WINDOWS\system32\jzgpri.dll] [N/A, ]
[PID: 1164 / 888][C:\DOCUME~1\888\LOCALS~1\Temp\Rar$EX00.263\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\system32\wlfpri.dll] [N/A, ]
[c:\progra~1\xowy\kbjl.dll] [, 5, 0, 0, 8]
[c:\progra~1\xowy\pgoq.dll] [, 5, 0, 0, 8]
[C:\WINDOWS\system32\dhcpri.dll] [N/A, ]
[C:\DOCUME~1\888\LOCALS~1\Temp\Rar$EX00.263\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[C:\WINDOWS\system32\isapir.dll] [N/A, ]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\4A55EF08.dll] [N/A, ]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, ]
[C:\WINDOWS\system32\wdcpri.dll] [N/A, ]
[C:\WINDOWS\system32\jzgpri.dll] [N/A, ]
[C:\WINDOWS\system32\mydpri.dll] [N/A, ]
[C:\WINDOWS\system32\wdbpri.dll] [N/A, ]
[C:\WINDOWS\system32\wldpri.dll] [N/A, ]
[C:\WINDOWS\system32\xyhpri.dll] [N/A, ]
[C:\WINDOWS\system32\jzepri.dll] [N/A, ]
[C:\WINDOWS\system32\mybpri.dll] [N/A, ]
[C:\WINDOWS\system32\RAVMSMON.DAT] [N/A, ]
[C:\WINDOWS\Fonts\RAVZTMON.DAT] [N/A, ]
[C:\WINDOWS\system32\RAVQJMON.DAT] [N/A, ]
[C:\WINDOWS\system32\RAVCHDMON.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV009F.DAT] [N/A, ]
[C:\PROGRA~1\MICROS~2\OFFICE11\MCPS.DLL] [Microsoft Corporation, 11.0.5510]
[PID: 3636 / 888][C:\WINDOWS\system32\taskmgr.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jzepri.dll] [N/A, ]
[c:\progra~1\xowy\kbjl.dll] [, 5, 0, 0, 8]
[c:\progra~1\xowy\pgoq.dll] [, 5, 0, 0, 8]
[C:\WINDOWS\system32\wlfpri.dll] [N/A, ]
[C:\WINDOWS\system32\dhcpri.dll] [N/A, ]
[C:\WINDOWS\system32\mybpri.dll] [N/A, ]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[C:\WINDOWS\system32\xyhpri.dll] [N/A, ]
[C:\WINDOWS\system32\wldpri.dll] [N/A, ]
[C:\WINDOWS\system32\wdbpri.dll] [N/A, ]
[C:\WINDOWS\system32\mydpri.dll] [N/A, ]
[C:\WINDOWS\system32\jzgpri.dll] [N/A, ]
[C:\WINDOWS\system32\wdcpri.dll] [N/A, ]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\4A55EF08.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, ]
[C:\WINDOWS\system32\RAVQJMON.DAT] [N/A, ]
[C:\WINDOWS\Fonts\RAVZTMON.DAT] [N/A, ]
[C:\WINDOWS\system32\RAVMSMON.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV009F.DAT] [N/A, ]
[C:\WINDOWS\system32\RAVCHDMON.DAT] [N/A, ]
[PID: 3748 / 888][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\4A55EF08.dll] [N/A, ]
[c:\progra~1\xowy\kbjl.dll] [, 5, 0, 0, 8]
[c:\progra~1\xowy\pgoq.dll] [, 5, 0, 0, 8]
[C:\WINDOWS\system32\wlfpri.dll] [N/A, ]
[C:\WINDOWS\system32\dhcpri.dll] [N/A, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\System16.ins] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, ]
[C:\WINDOWS\system32\mybpri.dll] [N/A, ]
[C:\WINDOWS\system32\jzepri.dll] [N/A, ]
[C:\WINDOWS\system32\xyhpri.dll] [N/A, ]
[C:\WINDOWS\system32\wldpri.dll] [N/A, ]
[C:\WINDOWS\system32\wdbpri.dll] [N/A, ]
[C:\WINDOWS\system32\mydpri.dll] [N/A, ]
[C:\WINDOWS\system32\jzgpri.dll] [N/A, ]
[C:\WINDOWS\system32\wdcpri.dll] [N/A, ]
[C:\WINDOWS\system32\isapir.dll] [N/A, ]
[C:\WINDOWS\system32\RAVMSMON.DAT] [N/A, ]
[C:\WINDOWS\Fonts\RAVZTMON.DAT] [N/A, ]
[C:\WINDOWS\system32\RAVQJMON.DAT] [N/A, ]
[C:\WINDOWS\system32\RAVCHDMON.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV009F.DAT] [N/A, ]
[PID: 3400 / 888][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\wdcpri.dll] [N/A, ]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\4A55EF08.dll] [N/A, ]
[c:\progra~1\xowy\kbjl.dll] [, 5, 0, 0, 8]
[c:\progra~1\xowy\pgoq.dll] [, 5, 0, 0, 8]
[C:\Program Files\Windows Live Toolbar\msntb.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\zh-cn\mtbres.dll.mui] [Microsoft Corporation, 03.00.0001.2012]
[C:\Program Files\Windows Live Toolbar\mtbres.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\Tem.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\zh-cn\searchboxRes.dll.mui] [Microsoft Corporation, 03.00.0001.2012]
[C:\Program Files\Windows Live Toolbar\searchboxRes.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\zh-cn\CMRes.dll.mui] [Microsoft Corporation, 03.00.0001.2032]
[C:\Program Files\Windows Live Toolbar\CMRes.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\zh-cn\msn_slrs.DLL.mui] [Microsoft Corporation, 03.00.0001.2012]
[C:\Program Files\Windows Live Toolbar\msn_slrs.DLL] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\zh-cn\CBRes.dll.mui] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\CBRes.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\WINDOWS\system32\dhcpri.dll] [N/A, ]
[C:\WINDOWS\system32\wlfpri.dll] [N/A, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Windows Live Toolbar\searchbox.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\stmain.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\cm.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\msn_slps.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Windows Live Toolbar\CB.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.5510]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\jzgpri.dll] [N/A, ]
[C:\WINDOWS\system32\mydpri.dll] [N/A, ]
[C:\WINDOWS\system32\wdbpri.dll] [N/A, ]
[C:\WINDOWS\system32\wldpri.dll] [N/A, ]
[C:\WINDOWS\system32\xyhpri.dll] [N/A, ]
[C:\WINDOWS\system32\jzepri.dll] [N/A, ]
[C:\WINDOWS\system32\mybpri.dll] [N/A, ]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[C:\WINDOWS\system32\macromed\flash\Flash.ocx] [Macromedia, Inc., 7,0,19,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\isapir.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, ]
[C:\WINDOWS\system32\RAVMSMON.DAT] [N/A, ]
[C:\WINDOWS\Fonts\RAVZTMON.DAT] [N/A, ]
[C:\WINDOWS\system32\RAVQJMON.DAT] [N/A, ]
[C:\WINDOWS\system32\RAVCHDMON.DAT] [N/A, ]
[C:\WINDOWS\system32\RAV009F.DAT] [N/A, ]
[PID: 872 / 888][C:\Program Files\Windows Live Toolbar\msn_sl.exe] [Microsoft Corporation, 03.01.0000.0068]
[C:\WINDOWS\system32\dhcpri.dll] [N/A, ]
[C:\Program Files\Windows Live Toolbar\MSN_SLrs.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\4A55EF08.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, ]
[c:\progra~1\xowy\kbjl.dll] [, 5, 0, 0, 8]
[c:\progra~1\xowy\pgoq.dll] [, 5, 0, 0, 8]
[C:\Program Files\Windows Live Toolbar\msn_slps.dll] [Microsoft Corporation, 03.01.0000.0068]
[C:\WINDOWS\system32\wlfpri.dll] [N/A, ]
[C:\WINDOWS\system32\isapir.dll] [N/A, ]
[PID: 2036 / 888][C:\WINDOWS\system32\mydins.exe] [N/A, ]
[C:\WINDOWS\system32\dhcpri.dll] [N/A, ]
[C:\WINDOWS\system32\mydpri.dll] [N/A, ]
[PID: 3304 / 888][C:\WINDOWS\system32\dhcins.exe] [N/A, ]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[C:\WINDOWS\system32\dhcpri.dll] [N/A, ]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\4A55EF08.dll] [N/A, ]
[C:\WINDOWS\system32\wdcpri.dll] [N/A, ]
[C:\WINDOWS\system32\jzgpri.dll] [N/A, ]
[C:\WINDOWS\system32\mydpri.dll] [N/A, ]
[C:\WINDOWS\system32\wdbpri.dll] [N/A, ]
[C:\WINDOWS\system32\wldpri.dll] [N/A, ]
[C:\WINDOWS\system32\xyhpri.dll] [N/A, ]
[C:\WINDOWS\system32\jzepri.dll] [N/A, ]
[C:\WINDOWS\system32\mybpri.dll] [N/A, ]
[C:\WINDOWS\system32\wlfpri.dll] [N/A, ]
[PID: 940 / 888][C:\WINDOWS\system32\wlfins.exe] [N/A, ]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[C:\WINDOWS\system32\wlfpri.dll] [N/A, ]
==================================
ogim - 2007-8-11 15:01:00
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR Error. [AutoCADScript]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MSAFD ICMP
C:\WINDOWS\system32\isapir.dll(, N/A)
MSAFD ICMP
C:\WINDOWS\system32\isapir.dll(, N/A)
==================================
Autorun.inf
[D:\]
[AutoRun]
open=4A55EF08.exe
shell\open=打开(&O)
shell\open\Command=4A55EF08.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=4A55EF08.exe
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 3372, C:\WINDOWS\SYSTEM32\MYDINS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 244, C:\WINDOWS\SYSTEM32\DHCINS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1656, C:\WINDOWS\SYSTEM32\WLFINS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1088, C:\WINDOWS\SYSTEM32\JZGINS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2036, C:\WINDOWS\SYSTEM32\MYDINS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3304, C:\WINDOWS\SYSTEM32\DHCINS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 940, C:\WINDOWS\SYSTEM32\WLFINS.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
[2560] C:\WINDOWS\system32\usrinit.exe
==================================
[/CODE]
1
© 2000 - 2026 Rising Corp. Ltd.