瑞星卡卡安全论坛
茶茶77 - 2008-12-16 11:30:00
我朋友说我资源管理器感染了,但我想确定一下谁教我怎么确定啊
最近网老是自动断,电脑也有点卡
找朋友远程给我看了看,说我的资源管理器感染了
要我重装系统,但我的VISTA里没有原出厂的那个系统了,重装必须要光盘,但我没盘啊
他说GHOST版的VISTA找不到集成驱动,要我重装个GHOST版的XP,但我查了查,把原本是vista的笔记本弄成XP的好像有不好的地方
而且我也很喜欢VISTA不想换
但是笔记本里一个杀毒的都没有,就一个360,我希望哪位高手推荐我一款不错的免费杀毒软件,让我查查毒
顺便教我如何确定我的资源管理器的确感染了
我的QQ120943151,如果我没出现请加我发我邮件
120943151@qq.com谢谢了




帖子后面也跟有日志,请尽快答复,谢谢各位高手们
附件:
3rdUpdLog.TXT 附件:
SREngLOG.log
帅哥阿福 - 2008-12-16 11:42:00
茶茶77 - 2008-12-16 11:50:00
[CODE]
2008-12-16,11:48:48
System Repair Engineer 2.7.0.1210
Smallfrogs (
http://www.KZTechs.com)
Windows Vista Home Premium Edition Service Pack 1 (Build 6001) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
计划任务
API HOOK
隐藏进程
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<WMPNSCFG><C:\Program Files\Windows Media Player\WMPNSCFG.exe> [(Verified)Microsoft Windows]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<ISBMgr.exe><"C:\Program Files\Sony\ISB Utility\ISBMgr.exe"> [(Verified)Sony Corporation]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<Google IME Autoupdater><"C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe"> [(Verified)Google Inc]
<RtHDVCpl><RtHDVCpl.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<Adobe Reader Speed Launcher><; "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"> [File is missing]
<NMGameX_AutoRun><C:\Windows\system32\Rundll32.exe NMGameX.dll,LiveProcess /aa> [NMGameX]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><explorer.exe> [(Verified)Microsoft Windows]
<Userinit><C:\Windows\system32\userinit.exe,> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<WebCheck><C:\Windows\system32\webcheck.dll> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
<WinlogonNotify: igfxcui><igfxdev.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\VESWinlogon]
<WinlogonNotify: VESWinlogon><VESWinlogon.dll> [Sony Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
<Microsoft Windows Media Player><C:\Windows\system32\unregmp2.exe /ShowWMP> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><C:\Windows\system32\ie4uinit.exe -UserIconConfig> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
<Browser Customizations><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Windows Mail 7><"%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
<Windows Desktop Update><regsvr32.exe /s /n /i:U shell32.dll> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
<Internet Explorer><C:\Windows\system32\ie4uinit.exe -BaseSettings> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install> [(Verified)Microsoft Windows]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\Windows\system32\logon.scr> [(Verified)Microsoft Windows]
==================================
启动文件夹
[CCC]
<C:\Users\wzql\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CCC.lnk --> C:\PROGRA~1\ATITEC~1\ATI.ACE\CORE-S~1\CCC.exe [ATI Technologies Inc.]><N>
[CCC]
<C:\Users\wzql\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CCC.lnk --> C:\PROGRA~1\ATITEC~1\ATI.ACE\CORE-S~1\CCC.exe [ATI Technologies Inc.]><N>
==================================
服务
[Ati External Event Utility / Ati External Event Utility][Running/Auto Start]
<C:\Windows\system32\Ati2evxx.exe><ATI Technologies Inc.>
[Google Updater Service / gusvc][Stopped/Manual Start]
<"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe"><Macrovision Corporation>
[IviRegMgr / IviRegMgr][Stopped/Auto Start]
<C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe><(File is missing)>
[Kingsoft Uplive Service / kaccore][Stopped/Auto Start]
<"C:\Program Files\Kingsoft\KAC\Service\kaccore.exe"><(File is missing)>
[MSCSPTISRV / MSCSPTISRV][Stopped/Manual Start]
<C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe><Sony Corporation>
[PACSPTISVR / PACSPTISVR][Stopped/Manual Start]
<C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe><>
[PnpWMmng / PnpWMmng][Stopped/Auto Start]
<?E><(File is missing)>
[ServiceLayer / ServiceLayer][Stopped/Manual Start]
<"C:\Program Files\PC Connectivity Solution\ServiceLayer.exe"><Nokia.>
[Sony SPTI Service / SPTISRV][Stopped/Manual Start]
<C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe><Sony Corporation>
[VAIO Entertainment TV Device Arbitration Service / VAIO Entertainment TV Device Arbitration Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe"><Sony Corporation>
[VAIO Event Service / VAIO Event Service][Running/Auto Start]
<C:\Program Files\Sony\VAIO Event Service\VESMgr.exe><Sony Corporation>
[VAIO Media Integrated Server / VAIOMediaPlatform-IntegratedServer-AppServer][Stopped/Manual Start]
<C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe><Sony Corporation>
[VAIO Media Integrated Server (HTTP) / VAIOMediaPlatform-IntegratedServer-HTTP][Stopped/Manual Start]
<"C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP"><Sony Corporation>
[VAIO Media Integrated Server (UPnP) / VAIOMediaPlatform-IntegratedServer-UPnP][Stopped/Manual Start]
<C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe><Sony Corporation>
[VAIO Media Gateway Server / VAIOMediaPlatform-Mobile-Gateway][Stopped/Manual Start]
<"C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server"><Sony Corporation>
[VAIO Media Content Collection / VAIOMediaPlatform-UCLS-AppServer][Stopped/Manual Start]
<C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe><Sony Corporation>
[VAIO Media Content Collection (HTTP) / VAIOMediaPlatform-UCLS-HTTP][Stopped/Manual Start]
<"C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-UCLS-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\UCLS\HTTP"><Sony Corporation>
[VAIO Media Content Collection (UPnP) / VAIOMediaPlatform-UCLS-UPnP][Stopped/Manual Start]
<C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe><Sony Corporation>
[VAIO Content Metadata Intelligent Analyzing Manager / VcmIAlzMgr][Stopped/Manual Start]
<"C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe"><Sony Corporation>
[VAIO Content Metadata XML Interface / VcmXmlIfHelper][Stopped/Manual Start]
<"C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe"><Sony Corporation>
[VAIO Entertainment UPnP Client Adapter / Vcsw][Running/Manual Start]
<C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe -RunBySCM><Sony Corporation>
[VAIO Entertainment Database Service / VzCdbSvc][Running/Auto Start]
<"C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe"><Sony Corporation>
[VAIO Entertainment File Import Service / VzFw][Running/Auto Start]
<C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe><Sony Corporation>
[Windows Live Setup Service / WLSetupSvc][Stopped/Manual Start]
<"C:\Program Files\Windows Live\installer\WLSetupSvc.exe"><Microsoft Corporation>
[XAudioService / XAudioService][Running/Auto Start]
<C:\Windows\system32\DRIVERS\xaudio.exe><Conexant Systems, Inc.>
茶茶77 - 2008-12-16 11:52:00
==================================
驱动程序
[adp94xx / adp94xx][Stopped/Disabled]
<\SystemRoot\system32\drivers\adp94xx.sys><Adaptec, Inc.>
[adpahci / adpahci][Stopped/Disabled]
<\SystemRoot\system32\drivers\adpahci.sys><Adaptec, Inc.>
[adpu160m / adpu160m][Stopped/Disabled]
<\SystemRoot\system32\drivers\adpu160m.sys><Adaptec, Inc.>
[adpu320 / adpu320][Stopped/Disabled]
<\SystemRoot\system32\drivers\adpu320.sys><Adaptec, Inc.>
[aic78xx / aic78xx][Stopped/Disabled]
<\SystemRoot\system32\drivers\djsvs.sys><Adaptec, Inc.>
[AlcwWmDrv / AlcwWmDrv][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\AlcwWmDrv.sys><N/A>
[aliide / aliide][Stopped/Disabled]
<\SystemRoot\system32\drivers\aliide.sys><Acer Laboratories Inc.>
[arc / arc][Stopped/Disabled]
<\SystemRoot\system32\drivers\arc.sys><Adaptec, Inc.>
[arcsas / arcsas][Stopped/Disabled]
<\SystemRoot\system32\drivers\arcsas.sys><Adaptec, Inc.>
[atikmdag / atikmdag][Running/Manual Start]
<system32\DRIVERS\atikmdag.sys><ATI Technologies Inc.>
[Brother USB Mass-Storage Lower Filter Driver / BrFiltLo][Stopped/Manual Start]
<\SystemRoot\system32\drivers\brfiltlo.sys><Brother Industries, Ltd.>
[Brother USB Mass-Storage Upper Filter Driver / BrFiltUp][Stopped/Manual Start]
<\SystemRoot\system32\drivers\brfiltup.sys><Brother Industries, Ltd.>
[Brother MFC Serial Port Interface Driver (WDM) / Brserid][Stopped/Disabled]
<\SystemRoot\system32\drivers\brserid.sys><Brother Industries Ltd.>
[Brother WDM Serial driver / BrSerWdm][Stopped/Disabled]
<\SystemRoot\system32\drivers\brserwdm.sys><Brother Industries Ltd.>
[Brother MFC USB Fax Only Modem / BrUsbMdm][Stopped/Disabled]
<\SystemRoot\system32\drivers\brusbmdm.sys><Brother Industries Ltd.>
[Brother MFC USB Serial WDM Driver / BrUsbSer][Stopped/Manual Start]
<\SystemRoot\system32\drivers\brusbser.sys><Brother Industries Ltd.>
[cmdide / cmdide][Stopped/Disabled]
<\SystemRoot\system32\drivers\cmdide.sys><CMD Technology, Inc.>
[Sony DMI Call service / DMICall][Running/System Start]
<system32\DRIVERS\DMICall.sys><Sony Corporation>
[Intel(R) PRO/1000 NDIS 6 Adapter Driver / E1G60][Stopped/Manual Start]
<system32\DRIVERS\E1G60I32.sys><Intel Corporation>
[EagleNT / EagleNT][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\EagleNT.sys><N/A>
[elxstor / elxstor][Stopped/Disabled]
<\SystemRoot\system32\drivers\elxstor.sys><Emulex>
[HpCISSs / HpCISSs][Stopped/Disabled]
<\SystemRoot\system32\drivers\hpcisss.sys><Hewlett-Packard Company>
[HSFHWAZL / HSFHWAZL][Stopped/Manual Start]
<system32\DRIVERS\VSTAZL3.SYS><Conexant Systems, Inc.>
[HSF_DPV / HSF_DPV][Running/Manual Start]
<system32\DRIVERS\HSX_DPV.sys><Conexant Systems, Inc.>
[HSXHWAZL / HSXHWAZL][Running/Manual Start]
<system32\DRIVERS\HSXHWAZL.sys><Conexant Systems, Inc.>
[Intel RAID Controller Vista / iaStorV][Stopped/Disabled]
<\SystemRoot\system32\drivers\iastorv.sys><Intel Corporation>
[Symantec Intrusion Prevention Driver / IDSvix86][Stopped/Manual Start]
<\??\C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20070108.003\IDSvix86.sys><Symantec Corporation>
[IGALIVE / IGALIVE][Running/Auto Start]
<\??\C:\Program Files\IGALIVE\IGALIVE.sys><N/A>
[iirsp / iirsp][Stopped/Disabled]
<\SystemRoot\system32\drivers\iirsp.sys><Intel Corp./ICP vortex GmbH>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
<system32\drivers\RTKVHDA.sys><Realtek Semiconductor Corp.>
[ITEATAPI_Service_Install / iteatapi][Stopped/Disabled]
<\SystemRoot\system32\drivers\iteatapi.sys><Integrated Technology Express, Inc.>
[ITERAID_Service_Install / iteraid][Stopped/Disabled]
<\SystemRoot\system32\drivers\iteraid.sys><Integrated Technology Express, Inc.>
[jdy#hook / jdy#hook][Stopped/Manual Start]
<\??\C:\TDDOWNLOAD\新建文件夹\ppbl\hknm.sys><N/A>
[KAVBootC / KAVBootC][Running/Boot Start]
<\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>
[KernelCheck / KernelCheck][Stopped/Manual Start]
<\??\C:\Users\wzql\AppData\Local\Temp\KpCheck.sys><N/A>
[LSI_FC / LSI_FC][Stopped/Disabled]
<\SystemRoot\system32\drivers\lsi_fc.sys><LSI Logic>
[LSI_SAS / LSI_SAS][Stopped/Disabled]
<\SystemRoot\system32\drivers\lsi_sas.sys><LSI Logic>
[LSI_SCSI / LSI_SCSI][Stopped/Disabled]
<\SystemRoot\system32\drivers\lsi_scsi.sys><LSI Logic>
[mdmxsdk / mdmxsdk][Running/Auto Start]
<system32\DRIVERS\mdmxsdk.sys><Conexant>
[megasas / megasas][Stopped/Disabled]
<\SystemRoot\system32\drivers\megasas.sys><LSI Logic Corporation>
[Mraid35x / Mraid35x][Stopped/Disabled]
<\SystemRoot\system32\drivers\mraid35x.sys><LSI Logic Corporation>
[NAVENG / NAVENG][Stopped/Manual Start]
<\??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20070110.052\NAVENG.SYS><Symantec Corporation>
[NAVEX15 / NAVEX15][Stopped/Manual Start]
<\??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20070110.052\NAVEX15.SYS><Symantec Corporation>
[Intel(R) Wireless WiFi Link 适配器驱动程序(适用于 Windows Vista 32 位) / NETw4v32][Running/Manual Start]
<system32\DRIVERS\NETw4v32.sys><Intel Corporation>
[nfrd960 / nfrd960][Stopped/Disabled]
<\SystemRoot\system32\drivers\nfrd960.sys><IBM Corporation>
[npkcrypt / npkcrypt][Stopped/Auto Start]
<\??\C:\Nexon\MapleStory\npkcrypt.sys><N/A>
[N-trig HID Tablet Driver / ntrigdigi][Stopped/Disabled]
<\SystemRoot\system32\drivers\ntrigdigi.sys><N-trig Innovative Technologies>
[nvraid / nvraid][Stopped/Disabled]
<\SystemRoot\system32\drivers\nvraid.sys><NVIDIA Corporation>
[nvstor / nvstor][Stopped/Disabled]
<\SystemRoot\system32\drivers\nvstor.sys><NVIDIA Corporation>
[PnpWmkDrv / PnpWmkDrv][Running/System Start]
<\??\C:\Windows\system32\drivers\PnpWmkDrv.sys><Windows (R) 2000 DDK provider>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[QKeyServiceDisplay / QKeyService][Running/Boot Start]
<\SystemRoot\system32\KeyCrypt.sys><Tencent Technology (Shenzhen) Company Limited>
[QLogic Fibre Channel Miniport Driver / ql2300][Stopped/Disabled]
<\SystemRoot\system32\drivers\ql2300.sys><QLogic Corporation>
[QLogic iSCSI Miniport Driver / ql40xx][Stopped/Disabled]
<\SystemRoot\system32\drivers\ql40xx.sys><QLogic Corporation>
[R5U870 UVC Lower Filter / R5U870FLx86][Running/Manual Start]
<System32\Drivers\R5U870FLx86.sys><Ricoh>
[R5U870 UVC Upper Filter / R5U870FUx86][Running/Manual Start]
<System32\Drivers\R5U870FUx86.sys><Ricoh>
[regi / regi][Running/Auto Start]
<system32\drivers\regi.sys><InterVideo>
[Realtek 8169 NT Driver / RTL8169][Running/Manual Start]
<system32\DRIVERS\Rtlh86.sys><Realtek Corporation>
[SafeBoxKrnl / SafeBoxKrnl][Running/System Start]
<\??\C:\Windows\system32\drivers\SafeBoxKrnl.sys><360安全中心>
[SiSRaid2 / SiSRaid2][Stopped/Disabled]
<\SystemRoot\system32\drivers\sisraid2.sys><Silicon Integrated Systems Corp.>
[SiSRaid4 / SiSRaid4][Stopped/Disabled]
<\SystemRoot\system32\drivers\sisraid4.sys><Silicon Integrated Systems>
[Sony Firmware Extension Parser Device / SNC][Running/Manual Start]
<System32\Drivers\SonyNC.sys><Sony Corporation>
[SRTSP / SRTSP][Stopped/Manual Start]
<System32\Drivers\SRTSP.SYS><Symantec Corporation>
[SRTSPL / SRTSPL][Stopped/Manual Start]
<System32\Drivers\SRTSPL.SYS><Symantec Corporation>
[SRTSPX / SRTSPX][Running/System Start]
<System32\Drivers\SRTSPX.SYS><Symantec Corporation>
[Symc8xx / Symc8xx][Stopped/Disabled]
<\SystemRoot\system32\drivers\symc8xx.sys><LSI Logic>
[SymEvent / SymEvent][Stopped/Manual Start]
<\??\C:\Windows\system32\Drivers\SYMEVENT.SYS><Symantec Corporation>
[Sym_hi / Sym_hi][Stopped/Disabled]
<\SystemRoot\system32\drivers\sym_hi.sys><LSI Logic>
[Sym_u3 / Sym_u3][Stopped/Disabled]
<\SystemRoot\system32\drivers\sym_u3.sys><LSI Logic>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
<system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[sysHostSvc / sysHostSvc][Running/Auto Start]
<\??\C:\Windows\system32\drivers\GuiHelp.sys><Microsoft Corporation>
[TC USB Kernel Driver / TcUsb][Stopped/Manual Start]
<System32\Drivers\tcusb.sys><UPEK Inc.>
[TesDrvPt / TesDrvPt][Stopped/Manual Start]
<\??\C:\Windows\system32\TesDrvPt.sys><TENCENT>
[TesSafe / TesSafe][Stopped/Manual Start]
<\??\C:\Windows\system32\TesSafe.sys><TENCENT>
[ti21sony / ti21sony][Running/Manual Start]
<system32\drivers\ti21sony.sys><Texas Instruments>
[Bluetooth COM Port / tosporte][Stopped/Manual Start]
<system32\DRIVERS\tosporte.sys><TOSHIBA Corporation>
[Bluetooth RFBUS / tosrfbd][Stopped/Manual Start]
<system32\DRIVERS\tosrfbd.sys><TOSHIBA CORPORATION>
[Bluetooth RFBNEP / tosrfbnp][Stopped/Manual Start]
<System32\Drivers\tosrfbnp.sys><TOSHIBA Corporation>
[Bluetooth RFCOMM / Tosrfcom][Stopped/Manual Start]
<System32\Drivers\tosrfcom.sys><TOSHIBA Corporation>
[Bluetooth RFHID / Tosrfhid][Stopped/Manual Start]
<system32\DRIVERS\Tosrfhid.sys><TOSHIBA Corporation.>
[Bluetooth Personal Area Network / tosrfnds][Stopped/Manual Start]
<system32\DRIVERS\tosrfnds.sys><TOSHIBA Corporation.>
[Bluetooth Audio / TosRfSnd][Stopped/Manual Start]
<system32\drivers\tosrfsnd.sys><TOSHIBA Corporation>
[Bluetooth USB Controller / tosrfusb][Stopped/Manual Start]
<system32\DRIVERS\tosrfusb.sys><TOSHIBA CORPORATION>
[uliahci / uliahci][Stopped/Disabled]
<\SystemRoot\system32\drivers\uliahci.sys><ULi Electronics Inc.>
[UlSata / UlSata][Stopped/Disabled]
<\SystemRoot\system32\drivers\ulsata.sys><Promise Technology, Inc.>
[ulsata2 / ulsata2][Stopped/Disabled]
<\SystemRoot\system32\drivers\ulsata2.sys><Promise Technology, Inc.>
[viaide / viaide][Stopped/Disabled]
<\SystemRoot\system32\drivers\viaide.sys><VIA Technologies, Inc.>
[vsmraid / vsmraid][Stopped/Disabled]
<\SystemRoot\system32\drivers\vsmraid.sys><VIA Technologies Inc.,Ltd>
[winachsf / winachsf][Running/Manual Start]
<system32\DRIVERS\HSX_CNXT.sys><Conexant Systems, Inc.>
[WmRegProDrv / WmRegProDrv][Stopped/Manual Start]
<System32\Drivers\WmRegProDrv.sys><Windows (R) 2000 DDK provider>
[XAudio / XAudio][Running/Auto Start]
<system32\DRIVERS\xaudio.sys><Conexant Systems, Inc.>
[XDva200 / XDva200][Stopped/Manual Start]
<\??\C:\Windows\system32\XDva200.sys><N/A>
[XDva221 / XDva221][Stopped/Manual Start]
<\??\C:\Windows\system32\XDva221.sys><N/A>
[XPROTECTOR / XPROTECTOR][Running/Auto Start]
<\??\C:\Windows\system32\drivers\Xprotector.sys><N/A>
茶茶77 - 2008-12-16 11:53:00
==================================
浏览器加载项
[QQCycloneHelper Class]
{00000000-12C9-4305-82F9-43058F20E8D2} <C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, (Signed) 腾讯公司>
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[Adobe PDF Link Helper]
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll, (Signed) Adobe Systems Incorporated>
[QQToolbar]
{29CF293A-1E7D-4069-9E11-E39698D0AF95} <C:\Program Files\Tencent\QQToolbar\IEBar.dll, (Signed) TENCENT>
[]
{669751ED-D558-49AE-B01A-3B374CC7910E} <, >
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[Windows Live 登录帮助程序]
{9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, (Signed) Microsoft Corporation>
[SafeMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, (Signed) 360.CN>
[Windows Live Toolbar Helper]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, (Signed) Microsoft Corporation>
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, (Signed) Thunder Networking Technologies,LTD>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, (Signed) Microsoft Corporation>
[QQToolbar]
{29CF293A-1E7D-4069-9E11-E39698D0AF95} <C:\Program Files\Tencent\QQToolbar\IEBar.dll, (Signed) TENCENT>
[Windows Live Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, (Signed) Microsoft Corporation>
[]
{18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <, >
[Game Class]
{19CC8AC3-7B26-40FF-8389-AB2460E647A9} <%ProgramFiles%\Kingsoft\KGame\kegame.dll, (Signed) N/A>
[PhotoDraw Class]
{2375BEE5-F175-4F1C-81EC-8E4E2E72E2DD} <C:\Program Files\Tencent\Qzone\QQPhotoDraw.dll, (Signed) TENCENT>
[DownStarter Control]
{36A4B20A-2B75-4101-86CE-F9B03CA4B91C} <C:\Windows\DOWNLO~1\DOWNST~1.OCX, (Signed) Nowcom, Co. LTD.>
[MLauncher Class]
{7417F730-7BAB-409E-8BB7-6936D361B869} <C:\Windows\Downloaded Program Files\MLauncher.dll, >
[]
{9C3C2C08-C494-4F52-AE94-85156A447D43} <, >
[WebActivater Control]
{C661F36D-DF85-4EF4-83C7-E107B83D04B1} <C:\Windows\system32\3DShowVM.ocx, QQ>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\system32\Macromed\Flash\Flash10a.ocx, (Signed) Adobe Systems, Inc.>
[QQCycloneHelper Class]
{00000000-12C9-4305-82F9-43058F20E8D2} <C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, (Signed) 腾讯公司>
[]
{00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <, >
[ThunderAtOnce Class]
{01443AEC-0FD1-40FD-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, (Signed) Adobe Systems Incorporated>
[]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, >
[GerneralPeerID Class]
{0A47E819-F82E-4D5D-B806-6A9EA94D68CD} <C:\Program Files\Thunder Network\Thunder\Components\InMedia\peerid.dll, >
[]
{0C7C23EF-A848-485B-873C-0ED954731014} <, >
[]
{0E1230F8-EA50-42A9-983C-E33ABC2EED3D} <, >
[]
{116BA71C-8187-4F15-9A1F-C9D6289155D1} <, >
[Adobe PDF Link Helper]
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll, (Signed) Adobe Systems Incorporated>
[]
{1E8A6170-7264-4D0F-BEAE-D42A53123C75} <, >
[]
{1F364306-AA45-47B5-9F9D-39A8B94E7EF1} <, >
[]
{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <, >
[]
{22BF413B-C6D2-4D91-82A9-A0F997BA588C} <, >
[]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} <, >
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <C:\Windows\system32\mshtml.dll, (Signed) Microsoft Corporation>
[XML DOM Document]
{2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[]
{2974C985-8151-4DE5-B23C-B875F0A8522F} <, >
[QQToolbar]
{29CF293A-1E7D-4069-9E11-E39698D0AF95} <C:\Program Files\Tencent\QQToolbar\IEBar.dll, (Signed) TENCENT>
[IETag Factory]
{38481807-CA0E-42D2-BF39-B33AF135CC4D} <C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\IETAG.DLL, (Signed) Microsoft Corporation>
[]
{3AECD3C1-7085-4731-96DC-47B6CF7EF749} <, >
[XML Document]
{48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[QQRightClick Class]
{4836C333-208E-4BCE-B30B-00B9545B0F6E} <C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, (Signed) 腾讯公司>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <, >
[XMP Class]
{6483F145-A768-4C41-AACC-52D4D7845851} <C:\ProgramData\Thunder Network\KanKan\xplayer.dll_1_work, Xunlei Networking Technologies,LTD>
[]
{669751ED-D558-49AE-B01A-3B374CC7910E} <, >
[XDRM]
{693571CB-54A3-4E90-9D52-EEAE1334E2D3} <C:\ProgramData\Thunder Network\KanKan\xdrm.dll_1_work, >
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[]
{72578201-3A99-4164-88E9-9799393159C8} <, >
[MediaComm Class]
{7670648D-461B-42AF-BDFE-46D26AF5EFF2} <C:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin18.dll, (Signed) Thunder Networking Technologies,LTD>
[]
{77BF5300-1474-4EC7-9980-D32B190E9B07} <, >
[]
{7E853D72-626A-48EC-A868-BA8D5E23E045} <, >
[360SafeLive]
{87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, (Signed) 360.cn>
[Microsoft Web Browser]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\Windows\system32\ieframe.dll, (Signed) Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[XML DOM Document 4.0]
{88D969C0-F192-11D4-A65F-0040963251E5} <c:\Windows\system32\msxml4.dll, (Signed) Microsoft Corporation>
[XML DOM 文档 5.0]
{88D969E5-F192-11D4-A65F-0040963251E5} <C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSXML5.DLL, (Signed) Microsoft Corporation>
[XML DOM Document 6.0]
{88D96A05-F192-11D4-A65F-0040963251E5} <%SystemRoot%\System32\msxml6.dll, (Signed) N/A>
[]
{90222687-F593-4738-B738-FBEE9C7B26DF} <, >
[Windows Live 登录帮助程序]
{9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, (Signed) Microsoft Corporation>
[]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <, >
[]
{95B3F550-91C4-4627-BCC4-521288C52977} <, >
[]
{A412E581-59B2-485E-834F-C5F0C0268C79} <, >
[]
{A986E409-30CC-4185-89BB-AB212C104524} <, >
[RMGetLicense Class]
{A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\Windows\System32\msnetobj.dll, (Signed) Microsoft Corporation>
[]
{AA58ED58-01DD-4D91-8333-CF10577473F7} <, >
[DapCtrl Class]
{ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} <C:\Program Files\Common Files\Thunder Network\KanKan\DapCtrl.2.3.5807.112.(894).dll, (Signed) ShenZhen Thunder Networking Technologies Ltd.>
[]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <, >
[]
{B070D3E3-FEC0-47D9-8E8A-99D4EEB3D3B0} <, >
[SafeMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, (Signed) 360.CN>
[Windows Live Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, (Signed) Microsoft Corporation>
[Windows Live Toolbar Helper]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, (Signed) Microsoft Corporation>
[]
{C5428486-50A0-4A02-9D20-520B59A9F9B2} <, >
[]
{C5428486-50A0-4A02-9D20-520B59A9F9B3} <, >
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\Program Files\StormII\Codec\rmoc3260.dll, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\system32\Macromed\Flash\Flash10a.ocx, (Signed) Adobe Systems, Inc.>
[]
{D963BE1A-6B35-47DB-B002-49FAE71D85CC} <, >
[Microsoft Silverlight]
{DFEAF541-F3E1-4C24-ACAC-99C30715084A} <c:\Program Files\Microsoft Silverlight\2.0.31005.0\npctrl.dll, (Signed) Microsoft Corporation>
[VWRCCtrl Class]
{E58A1E83-ED4D-4525-A9E2-3C9BA06CC4A9} <C:\Program Files\Sony\VAIO Registration Client\VWRClient.dll, (Signed) Sony Corporation>
[TimwpDll.TimwpCheck]
{ED4CA2E5-0EEA-44C1-AD7E-74A07A7507A4} <C:\PROGRA~1\Tencent\QQ2009\Bin\Timwp.dll, (Signed) TENCENT>
[XML HTTP Request]
{ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[Thunder DapPlayer]
{EEDD6FF9-13DE-496B-9A1C-D78B3215E266} <C:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DapPlayer3.0.5712.71.84.dll, ShenZhen Thunder Networking Technologies Ltd.>
[XPPlayer Class]
{F3E70CEA-956E-49CC-B444-73AFE593AD7F} <C:\Program Files\Common Files\Thunder Network\KanKan\PPlayer.2.1.5880.234.(895).dll, (Signed) Xunlei Networking Technologies,LTD>
[XML DOM Document 3.0]
{F5078F32-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[Free Threaded XML DOM Document 3.0]
{F5078F33-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XML HTTP 3.0]
{F5078F35-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XSL Template 3.0]
{F5078F36-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XML DOM Document]
{F6D90F11-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[]
{FB5DA724-162B-11D3-8B9B-AA70B4B0B524} <, >
[]
{FB5DA724-162B-11D3-8B9B-AA70B4B0B525} <, >
[&Windows Live Search]
<res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm, N/A>
[&ê1ó?3???Dy·?????]
<, >
[&ê1ó?3???Dy·?????è?2?á′?ó]
<, >
[&使用超级旋风下载]
<C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
[&使用超级旋风下载全部链接]
<C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
[&使用超级旋风下载本页视频]
<C:\Program Files\Tencent\QQDownload\geturlflv.htm, N/A>
[ìí?óμ?QQ±í?é]
<, >
[íê?à°2è??úê?]
<, >
[使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ表情]
<G:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
茶茶77 - 2008-12-16 11:58:00
==================================
正在运行的进程
[PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 564 / SYSTEM][C:\Windows\system32\csrss.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 616 / SYSTEM][C:\Windows\system32\wininit.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 628 / SYSTEM][C:\Windows\system32\csrss.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 660 / SYSTEM][C:\Windows\system32\services.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 672 / SYSTEM][C:\Windows\system32\lsass.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 680 / SYSTEM][C:\Windows\system32\lsm.exe] [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 724 / SYSTEM][C:\Windows\system32\winlogon.exe] [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 884 / SYSTEM][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 944 / NETWORK SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 984 / SYSTEM][C:\Windows\System32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1072 / SYSTEM][C:\Windows\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4167]
[PID: 1136 / LOCAL SERVICE][C:\Windows\System32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\RtkAPO.dll] [Realtek Semiconductor Corp., 11.0.6000.31 built by: WinDDK]
[PID: 1168 / SYSTEM][C:\Windows\System32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1188 / SYSTEM][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1288 / NETWORK SERVICE][C:\Windows\system32\SLsvc.exe] [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 1340 / LOCAL SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1484 / NETWORK SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1604 / SYSTEM][C:\Windows\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4167]
[C:\Windows\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2511]
[C:\Windows\system32\atipdlxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2519]
[C:\Windows\system32\ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4162]
[PID: 1808 / SYSTEM][C:\Windows\System32\spoolsv.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1832 / LOCAL SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2020 / SYSTEM][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE] [Microsoft Corporation, 7.00.9466]
[C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\2052\mdmui.dll] [Microsoft Corporation, 7.00.9466]
[PID: 632 / NETWORK SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 676 / LOCAL SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1840 / SYSTEM][C:\Program Files\Sony\VAIO Event Service\VESMgr.exe] [Sony Corporation, 3.1.00.13250]
[C:\Program Files\Sony\VAIO Event Service\MSVCR70.dll] [Microsoft Corporation, 7.00.9466.0]
[C:\Program Files\Sony\VAIO Event Service\VESSuEvent.dll] [Sony Corporation, 3.2.00.07060]
[C:\Program Files\Sony\VAIO Event Service\VESBasePS.dll] [N/A, ]
[C:\Program Files\Common Files\Sony Shared\Sony Utilities\SnyUtils.dll] [Sony Corporation, 4.0.00.06270]
[C:\Program Files\Sony\VAIO Event Service\VESWndMsg.dll] [Sony Corporation, 3.2.00.05220]
[C:\Program Files\Sony\VAIO Event Service\VESTransform.dll] [Sony Corporation, 3.2.00.07240]
[C:\Program Files\Sony\VAIO Control Center\SUSCommonSetting.dll] [Sony Corporation, 3.0.00.07110]
[C:\Program Files\Sony\VAIO Power Management\VESPowerMgr.dll] [Sony Corporation, 3.2.00.05280]
[C:\Program Files\Sony\VAIO Event Service\VESSemiPnP.dll] [Sony Corporation, 3.0.00.11220]
[C:\Program Files\Sony\VAIO Event Service\VESSuPerform.dll] [Sony Corporation, 3.2.00.07090]
[C:\Program Files\Sony\VAIO Event Service\VESVideo.dll] [Sony Corporation, 3.2.00.07100]
[C:\Program Files\Sony\VAIO Event Service\VESPerform.dll] [Sony Corporation, 3.2.00.06290]
[C:\Program Files\Sony\VAIO Launcher\VESAVModeButton.dll] [Sony Corporation, 2.0.00.15210]
[C:\Program Files\Sony\VAIO Launcher\MSVCR71.dll] [Microsoft Corporation, 7.10.6004.4]
[C:\Program Files\Sony\VAIO Event Service\VESBCF.dll] [Sony Corporation, 3.2.00.04260]
[C:\Program Files\Sony\VAIO Event Service\VESHKWndCommon.dll] [Sony Corporation, 3.2.00.06210]
[C:\Program Files\Sony\VAIO Event Service\VESSetGamma.dll] [Sony Corporation, 3.2.00.07110]
[C:\Program Files\Sony\Setting Utility Series\BatteryCare.dll] [Sony Corporation, 1.2.00.03160]
[C:\Program Files\Sony\VAIO Event Service\VESMgrSubPS.dll] [N/A, ]
[PID: 2000 / SYSTEM][C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe] [Sony Corporation, 2.0.00.08230]
[C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\sonyuppc.dll] [Sony Corporation, 7.0.00.35270]
[C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\UPnPCtrl.dll] [Sony Corporation, 2, 0, 1, 10010]
[C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSWEXEps.dll] [Sony Corporation, 2.0.00.08230]
[PID: 424 / SYSTEM][C:\Windows\System32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2060 / SYSTEM][C:\Windows\system32\SearchIndexer.exe] [(Verified) Microsoft Corporation, 7.0.6001.16503 (longhorn(wmbla).080526-2159)]
[PID: 2104 / SYSTEM][C:\Windows\system32\DRIVERS\xaudio.exe] [Conexant Systems, Inc., 1.02]
[PID: 2140 / SYSTEM][C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe] [Sony Corporation, 3.0.00.06260]
[C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbVcds.dll] [Sony Corporation, 3.0.00.06260]
[C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSsDB.dll] [Sony Corporation, 3.0.00.06260]
[C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbLocalDB.dll] [Sony Corporation, 3.0.00.06260]
[C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSWEXEps.dll] [Sony Corporation, 2.0.00.08230]
[C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvcPS.dll] [Sony Corporation, 3.0.00.06260]
[PID: 2208 / SYSTEM][C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe] [Sony Corporation, 3.0.00.06260]
[C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFwImport.dll] [Sony Corporation, 3.0.00.06260]
[C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdb.dll] [Sony Corporation, 3.0.00.06260]
[C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvcPS.dll] [Sony Corporation, 3.0.00.06260]
[C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCs.dll] [Sony Corporation, 2.1.00.04250]
[PID: 2284 / LOCAL SERVICE][C:\Windows\system32\WUDFHost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2472 / SYSTEM][C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe] [Sony Corporation, 2.3.00.03190]
[C:\Program Files\Sony\VAIO Event Service\MSVCR70.dll] [Microsoft Corporation, 7.00.9466.0]
[C:\Program Files\Sony\VAIO Event Service\VESMgrSubPS.dll] [N/A, ]
[C:\Program Files\Sony\VAIO Event Service\VESWndMsg.dll] [Sony Corporation, 3.2.00.05220]
[C:\Program Files\Sony\VAIO Event Service\VESBasePS.dll] [N/A, ]
[C:\Program Files\Sony\VAIO Power Management\VESPowerMgr.dll] [Sony Corporation, 3.2.00.05280]
[C:\Program Files\Common Files\Sony Shared\Sony Utilities\SnyUtils.dll] [Sony Corporation, 4.0.00.06270]
[C:\Program Files\Sony\VAIO Event Service\VESVideo.dll] [Sony Corporation, 3.2.00.07100]
[C:\Program Files\Sony\VAIO Event Service\VESPerform.dll] [Sony Corporation, 3.2.00.06290]
[C:\Program Files\Sony\VAIO Event Service\VESWndMsgHook.dll] [Sony Corporation, 2.2.00.05200]
[C:\Program Files\Sony\VAIO Launcher\VESAVModeButton.dll] [Sony Corporation, 2.0.00.15210]
[C:\Program Files\Sony\VAIO Launcher\MSVCR71.dll] [Microsoft Corporation, 7.10.6004.4]
[C:\Program Files\Sony\VAIO Event Service\VESHKWndCommon.dll] [Sony Corporation, 3.2.00.06210]
[C:\Program Files\Sony\VAIO Event Service\VESSetGamma.dll] [Sony Corporation, 3.2.00.07110]
[C:\Windows\system32\Atipdlxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2519]
[PID: 2884 / wzql][C:\Windows\system32\taskeng.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[C:\Windows\system32\atitmmxx.dll] [, 6, 14, 11, 17]
[C:\Windows\system32\atipdlxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2519]
[PID: 2916 / wzql][C:\Windows\system32\Dwm.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2992 / wzql][C:\Windows\Explorer.EXE] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll] [, 2, 0, 0, 0]
[C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 120]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Kingsoft\Powerword 2007 for VAIO\Grabgdip.dll] [Kingsoft Co, Ltd., 1, 0, 0, 1]
[PID: 3116 / SYSTEM][C:\Windows\system32\taskeng.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 3196 / wzql][C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe] [Sony Corporation, 3.0.02.04160]
[C:\Program Files\Sony\VAIO Update 3\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Sony\VAIO Update 3\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Sony\VAIO Update 3\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Windows\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Windows\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[C:\Program Files\Sony\VAIO Update 3\VURes.dll] [Sony Corporation, 3.0.02.04160]
[PID: 3228 / wzql][C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe] [Sony Corporation, 3.6.00.18140]
[C:\Program Files\Sony\Wireless Switch Setting Utility\Frn.dll] [Sony Corporation, 1,2,0,07250]
[C:\Program Files\Sony\Wireless Switch Setting Utility\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Sony\Wireless Switch Setting Utility\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Sony\Wireless Switch Setting Utility\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Windows\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Sony\Wireless Switch Setting Utility\SwitcherLocale.dll] [Sony Corporation, 3.6.00.17280]
[C:\Program Files\Common Files\Sony Shared\Sony Utilities\SnyUtils.dll] [Sony Corporation, 4.0.00.06270]
[C:\Windows\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[PID: 3236 / SYSTEM][C:\Program Files\Sony\VAIO Power Management\SPMgr.exe] [Sony Corporation, 2.2.00.06080]
[C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131\MFC80CHS.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\Windows\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[C:\Program Files\Sony\VAIO Power Management\SPMDAM.dll] [Sony Corporation, 2.2.00.05110]
[C:\Program Files\Common Files\Sony Shared\Sony Utilities\SnyUtils.dll] [Sony Corporation, 4.0.00.06270]
[C:\Program Files\Sony\VAIO Power Management\SPMRes.dll] [Sony Corporation, 2.2.00.05150]
[C:\Program Files\Sony\VAIO Event Service\VESBasePS.dll] [N/A, ]
[C:\Program Files\Sony\VAIO Event Service\MSVCR70.dll] [Microsoft Corporation, 7.00.9466.0]
[C:\Program Files\Sony\VAIO Power Management\SPMDrv.dll] [Sony Corporation, 2.2.00.06080]
[C:\Program Files\Sony\VAIO Power Management\Volcontrl.dll] [Sony Corporation, 2.0.00.10050]
[PID: 3436 / wzql][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] [Synaptics, Inc., 9.1.13 26Jan07]
[C:\Windows\system32\SynCOM.dll] [Synaptics, Inc., 9.1.13 26Jan07]
[C:\Windows\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[C:\Windows\system32\SynTPAPI.dll] [Synaptics, Inc., 9.1.13 26Jan07]
[PID: 3444 / wzql][C:\Program Files\Sony\ISB Utility\ISBMgr.exe] [Sony Corporation, 2.2.00.06110]
[C:\Windows\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[C:\Program Files\Common Files\Sony Shared\Sony Utilities\SnyUtils.dll] [Sony Corporation, 4.0.00.06270]
[PID: 3460 / wzql][C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe] [Google Inc., 1, 0, 0, 1]
[C:\Windows\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[PID: 3520 / wzql][C:\Program Files\Windows Media Player\wmpnscfg.exe] [Microsoft Corporation, 11.0.6000.6324 (vista_rtm.061101-2205)]
[C:\Windows\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[PID: 3800 / NETWORK SERVICE][C:\Program Files\Windows Media Player\wmpnetwk.exe] [Microsoft Corporation, 11.0.6000.6324 (vista_rtm.061101-2205)]
[PID: 3180 / wzql][C:\Program Files\Tencent\QQ2009\Bin\QQ.exe] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Bin\Common.dll] [Tencent, 1, 15, 305, 0]
[C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c\ATL80.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\Program Files\Tencent\QQ2009\Bin\KernelUtil.dll] [Tencent, 1, 15, 305, 0]
[C:\Program Files\Tencent\QQ2009\Bin\GF.dll] [Tencent, 1, 15, 305, 0]
[C:\Program Files\Tencent\QQ2009\Bin\AppUtil.dll] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Bin\MainFrame.dll] [Tencent, 1, 21, 520, 0]
[C:\Windows\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[C:\Program Files\Tencent\QQ2009\Bin\TaskTray.dll] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Bin\AppMisc.dll] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Bin\ChatFrame.dll] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Bin\ConfigCenter.dll] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Bin\CustomFace.dll] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Bin\IM.dll] [Tencent, 1, 15, 305, 0]
[C:\Program Files\Tencent\QQ2009\Bin\KernelMisc.dll] [Tencent, 1, 15, 305, 0]
[C:\Program Files\Tencent\QQ2009\Bin\LongCnn.dll] [Tencent, 1, 15, 305, 0]
[C:\Program Files\Tencent\QQ2009\Bin\ContactInfoFrame.dll] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Bin\MsgMgr.dll] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Bin\SkinMgr.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Bin\QInterLive.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Bin\AppCtrl.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Bin\SystemMsg.dll] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Common Files\Tencent\TXSSO\Bin\SSOPlatform.dll] [Tencent, 1.0.1.14]
[C:\Program Files\Tencent\QQ2009\Plugin\Com.Tencent.AudioVideo\Bin\AudioVideo.dll] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\Com.Tencent.PaiPai\Bin\PaiPai.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\Com.Tencent.Soso\Bin\Soso.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\Com.Tencent.SoBar\Bin\SoBar.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\Com.Tencent.QQShow\Bin\FlashAvatarDll.dll] [TODO: <Company name>, 1.0.0.1]
[C:\Windows\system32\Macromed\Flash\Flash10a.ocx] [Adobe Systems, Inc., 10,0,12,36]
[C:\Program Files\Tencent\QQ2009\Plugin\Com.Tencent.Qzone\Bin\Qzone.dll] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\Com.Tencent.Weather\Bin\Weather.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\Com.Tencent.MMOG\Bin\MMOG.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.paipaigift\Bin\PaiPaiGift.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.qqchat\Bin\QQChat.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.qqgame\Bin\QQGame.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.qqlive\Bin\QQLive.dll] [TODO: <Company name>, 1, 21, 520, 0]
茶茶77 - 2008-12-16 11:59:00
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.qqmusic\Bin\QQMusic.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.paycenter\Bin\PayCenter.dll] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.qqpet\Bin\QQPet.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.qqshow\Bin\QQShow.dll] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.qqring\Bin\QQRing.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.filetransfer\Bin\FileTransfer.dll] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.advertisement\Bin\Advertisement.dll] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.snsapp\Bin\SNSApp.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.taotao\Bin\taotao.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.wenwen\Bin\WenWen.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.wireless\Bin\Wireless.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.mail\Bin\Mail.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.qbar\Bin\QBar.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.today\Bin\Today.dll] [Tencent, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.qqwebsite\Bin\QQWebsite.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Plugin\com.tencent.winks\Bin\Winks.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Tencent\QQ2009\Bin\appcom.dll] [TODO: <Company name>, 1, 21, 520, 0]
[C:\Program Files\Kingsoft\Powerword 2007 for VAIO\Grabgdip.dll] [Kingsoft Co, Ltd., 1, 0, 0, 1]
[PID: 3508 / wzql][G:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 5, 225, 0]
[PID: 3472 / wzql][C:\Program Files\Tencent\QQDownload\QQDownload.exe] [Tencent Technology (Shenzhen) Company Limited, 1, 9, 241, 241]
[C:\Windows\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[C:\Program Files\Tencent\QQDownload\xmain.dll] [Tencent Technology (Shenzhen) Company Limited, 1.9.242.242]
[C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c\ATL80.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\Program Files\Tencent\QQDownload\VideoParser.dll] [, 1, 9, 2, 201]
[C:\Program Files\Tencent\QQDownload\xcore.dll] [Tencent Technology(Shenzhen) Company Limited, 2, 1, 101, 90]
[PID: 2716 / wzql][C:\Windows\explorer.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.34]
[C:\Windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 120]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
[C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1007]
[PID: 4084 / wzql][C:\Program Files\Kingsoft\Powerword 2007 for VAIO\xdict.exe] [Kingsoft Co, Ltd., 10, 0, 1, 0]
[C:\Program Files\Kingsoft\Powerword 2007 for VAIO\AccountActivate.dll] [N/A, ]
[C:\Program Files\Kingsoft\Powerword 2007 for VAIO\ITextOut.dll] [Kingsoft Co, Ltd. , 1, 1, 0, 1]
[C:\Program Files\Kingsoft\Powerword 2007 for VAIO\KPic10.dll] [N/A, ]
[C:\Program Files\Kingsoft\Powerword 2007 for VAIO\ijl11.dll] [Intel Corporation, 1.1.2]
[C:\Program Files\Kingsoft\Powerword 2007 for VAIO\NormGrab.DLL] [Kingsoft Co, Ltd., 9, 0, 0, 1]
[C:\Program Files\Kingsoft\Powerword 2007 for VAIO\statistics.dll] [N/A, ]
[C:\Program Files\Kingsoft\Powerword 2007 for VAIO\toTTSEngine50.dll] [Kingsoft Co, Ltd. , 1, 0, 0, 1]
[C:\Program Files\Kingsoft\Powerword 2007 for VAIO\xfile.dll] [Kingsoft Co, Ltd. , 1, 0, 0, 1]
[C:\Windows\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[C:\Program Files\Kingsoft\Powerword 2007 for VAIO\DBCore10.dll] [Kingsoft Co, Ltd., 1, 5, 0, 1]
[C:\Program Files\Kingsoft\Powerword 2007 for VAIO\XdictGrb.dll] [Kingsoft Co, Ltd., 9, 0, 0, 2]
[C:\Program Files\Kingsoft\Powerword 2007 for VAIO\DictionaryManager.dll] [Kingsoft Co, Ltd., 1, 0, 0, 1]
[C:\Program Files\Kingsoft\Powerword 2007 for VAIO\Xml2Xdata.dll] [Kingsoft Co, Ltd., 1, 0, 0, 1]
[C:\Program Files\Kingsoft\Powerword 2007 for VAIO\Grabgdip.dll] [Kingsoft Co, Ltd., 1, 0, 0, 1]
[PID: 3516 / wzql][C:\Program Files\Tencent\TT\bin\TTraveler.exe] [Tencent, 4, 18, 0, 13]
[C:\Program Files\Tencent\TT\bin\TTUtilWidget.dll] [Tencent, 4, 18, 0, 13]
[C:\Program Files\Tencent\TT\bin\PlatformWidget.dll] [Tencent, 4, 18, 0, 13]
[C:\Program Files\Tencent\TT\bin\TTMainFrame.dll] [Tencent, 4, 18, 0, 13]
[C:\Program Files\Tencent\TT\bin\UpdateUtil.dll] [N/A, ]
[C:\Windows\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[C:\Program Files\Tencent\TT\bin\TTStore.dll] [Tencent, 4, 18, 0, 13]
[C:\Program Files\Tencent\TT\bin\sqlite3.dll] [N/A, ]
[C:\Program Files\Tencent\TT\bin\TTMBrowser.dll] [Tencent, 4, 18, 0, 13]
[C:\Program Files\Tencent\TT\bin\TTabMgr.dll] [Tencent, 4, 18, 0, 13]
[C:\Program Files\Tencent\TT\bin\TTSkin.dll] [Tencent, 4, 18, 0, 13]
[C:\Program Files\Tencent\TT\bin\TTPluginMng.dll] [Tencent, 4, 18, 0, 13]
[C:\Program Files\Tencent\TT\Plugins\3TTWeather\TTWeather.dll] [Tencent, 1.0.0.1]
[C:\Program Files\Tencent\TT\Plugins\WebInfo\WebToolbar.dll] [Tencent, 1.0.0.1]
[C:\Program Files\Tencent\TT\bin\TTHtmlApp.dll] [Tencent, 4, 18, 0, 13]
[C:\Program Files\Tencent\TT\bin\TTFilter.dll] [Tencent, 4, 18, 0, 13]
[C:\Program Files\Tencent\TT\bin\TTNetwork.dll] [Tencent, 4, 18, 0, 13]
[C:\Program Files\Tencent\TT\bin\FavoriteLogical.dll] [Tencent, 4, 18, 0, 13]
[C:\Program Files\Kingsoft\Powerword 2007 for VAIO\Grabgdip.dll] [Kingsoft Co, Ltd., 1, 0, 0, 1]
[C:\Windows\system32\Macromed\Flash\Flash10a.ocx] [Adobe Systems, Inc., 10,0,12,36]
[C:\Windows\system32\atiumdag.dll] [ATI Technologies Inc. , 7.14.10.0496]
[C:\Windows\system32\atiumdva.dll] [ATI Technologies Inc. , 7.14.10.0155]
[PID: 908 / SYSTEM][C:\Windows\system32\SearchProtocolHost.exe] [(Verified) Microsoft Corporation, 7.0.6001.16503 (longhorn(wmbla).080526-2159)]
[PID: 2676 / SYSTEM][C:\Windows\system32\SearchFilterHost.exe] [(Verified) Microsoft Corporation, 7.0.6001.16503 (longhorn(wmbla).080526-2159)]
[PID: 2396 / wzql][C:\Users\wzql\Desktop\game\making\新建文件夹\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210]
[PID: 3640 / wzql][C:\Users\wzql\Desktop\game\making\新建文件夹\SREa7051757.EXE] [Smallfrogs Studio, 2.7.0.1210]
[C:\Windows\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[C:\Users\wzql\Desktop\game\making\新建文件夹\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT Error. [C:\Windows\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["%SystemRoot%\hh.exe" %1]
.HLP Error. []
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS Error. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
::1 localhost
==================================
进程特权扫描
N/A
==================================
计划任务
[已启用] \\{6715268D-9CB8-4B63-8D6C-32BC3BC4DAAD}
C:\Windows\system32\pcalua.exe -a C:\Users\wzql\Desktop\新建文件夹\xiazai\DUBA07IS0813.100.132.EXE -d C:\Users\wzql\Desktop\新建文件夹\xiazai
[已启用] \\{7930A0C3-F780-4192-940F-8792D0B58ECD}
C:\Windows\system32\pcalua.exe -a "I:\要带走的\PPLive 1.8.exe" -d I:\要带走的
[已启用] \\{86B586FC-82CB-4FB8-8BE7-09207E19F6B9}
C:\Windows\system32\pcalua.exe -a I:\要带走的\Lava-Lava2007.exe -d I:\要带走的
[已启用] \\{A11DF1AF-8468-469B-8B3A-33CD9AE45550}
C:\Windows\system32\pcalua.exe -a C:\Windows\三星奥运桌面精灵\uninstall.exe -c "/U:C:\Program Files\三星奥运桌面精灵\Uninstall\uninstall.xml"
[已启用] \\{E61ACD02-B562-4B4D-B8CD-0F7D34B25D02}
C:\Windows\system32\pcalua.exe -a "C:\Users\wzql\Desktop\新建文件夹\新建文件夹 (2)\qq2007kb.exe" -d "C:\Users\wzql\Desktop\新建文件夹\新建文件夹 (2)"
[已启用] \\{F1D60FE0-D3D2-4D49-871F-AE18AEB788B6}
C:\Windows\system32\pcalua.exe -a "C:\Program Files\íê?àD???V2008\unins000.exe" -d "C:\Program Files\íê?àD???V2008"
[已禁用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
N/A
[已启用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
N/A
[已启用] \Microsoft\Windows\Bluetooth\UninstallDeviceTask
BthUdTask.exe $(Arg0)
[已启用] \Microsoft\Windows\CertificateServicesClient\SystemTask
N/A
[已启用] \Microsoft\Windows\CertificateServicesClient\UserTask
N/A
[已启用] \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
N/A
[已启用] \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
%SystemRoot%\System32\wsqmcons.exe
[已启用] \Microsoft\Windows\Customer Experience Improvement Program\OptinNotification
%SystemRoot%\System32\wsqmcons.exe -n 0x1C577FA2B69CAD0
[已启用] \Microsoft\Windows\Customer Experience Improvement Program\Uploader
%windir%\system32\WSqmCons.exe -u
[已启用] \Microsoft\Windows\Defrag\ScheduledDefrag
%windir%\system32\defrag.exe -c -i
[已启用] \Microsoft\Windows\Media Center\ehDRMInit
%SystemRoot%\ehome\ehPrivJob.exe /DRMInit
[已启用] \Microsoft\Windows\Media Center\mcupdate
%SystemRoot%\ehome\mcupdate $(Arg0) -gc
[已启用] \Microsoft\Windows\Media Center\OCURActivate
%SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
[已启用] \Microsoft\Windows\Media Center\OCURDiscovery
%SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery
[已启用] \Microsoft\Windows\Media Center\UpdateRecordPath
%SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
[已启用] \Microsoft\Windows\MobilePC\HotStart
N/A
[已启用] \Microsoft\Windows\MobilePC\TMM
N/A
[已启用] \Microsoft\Windows\MUI\LPRemove
%windir%\system32\lpremove.exe
[已启用] \Microsoft\Windows\Multimedia\SystemSoundsService
N/A
[已启用] \Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
N/A
[已启用] \Microsoft\Windows\Shell\CrawlStartPages
N/A
[已禁用] \Microsoft\Windows\SideShow\AutoWake
N/A
[已启用] \Microsoft\Windows\SideShow\GadgetManager
N/A
[已禁用] \Microsoft\Windows\SideShow\SessionAgent
N/A
[已禁用] \Microsoft\Windows\SideShow\SystemDataProviders
N/A
[已启用] \Microsoft\Windows\SystemRestore\SR
%windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
[已启用] \Microsoft\Windows\Tcpip\IpAddressConflict1
rundll32 ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
[已启用] \Microsoft\Windows\Tcpip\IpAddressConflict2
rundll32 ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
[已启用] \Microsoft\Windows\UPnP\UPnPHostConfig
sc.exe config upnphost start= auto
[已启用] \Microsoft\Windows\Windows Error Reporting\QueueReporting
%windir%\system32\wermgr.exe -queuereporting
[已启用] \Microsoft\Windows\Wired\GatherWiredInfo
%windir%\system32\gatherWiredInfo.vbs
[已启用] \Microsoft\Windows\Wireless\GatherWirelessInfo
%windir%\system32\gatherWirelessInfo.vbs
[已启用] \SONY\VAIO Update\VAIO Update
"C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe" /Stationary
[已启用] \SONY\WSSU\WSSU
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
茶茶77 - 2008-12-16 12:00:00
快帮我看看有啥病毒,最主要看我资源管理器是不是感染了,我朋友是用Wsyscheck给我看出我资源管理器感染了,说还有2个不确定是不是病毒,谢谢了,急
茶茶77 - 2008-12-16 12:04:00
上传了SRENG日志的帖子
http://bbs.ikaka.com/showtopic-8575006.aspx
附件: SREngLOG.log (2008-12-16 12:21:00, 61.47 K)
该附件被下载次数 236
附件: 3rdUpdLog.TXT (2008-12-16 12:21:00, 2.43 K)
该附件被下载次数 297
茶茶77 - 2008-12-16 12:08:00
70012 C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DATAPROCESSOR_00.DLL
70000 C:\PROGRA~1\COMMON~1\SONYSH~1\VAIOEN~1\VCSW\VCSW.EXE
70000 C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\DRIVER\1150\INTEL 32\IDRIVERT.EXE
70005 C:\PROGRA~1\ATITEC~1\ATI.ACE\CORE-S~1\CCC.EXE
70023 C:\WINDOWS\SYSTEM32\VESWINLOGON.DLL
70000 C:\PROGRA~1\COMMON~1\SONYSH~1\AVLIB\MSCSPT~1.EXE
70011 C:\WINDOWS\SYSTEM32\RTKAPO.DLL
70000 C:\PROGRAM FILES\SONY\VAIO MEDIA INTEGRATED SERVER\PLATFORM\SV_HTTPD.EXE
70000 C:\PROGRAM FILES\COMMON FILES\SONY SHARED\VCMXML\VCMXMLIFHELPER.EXE
70012 C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DSBHO_00.DLL
70000 C:\PROGRAM FILES\COMMON FILES\SONY SHARED\VAIO ENTERTAINMENT PLATFORM\VZCS\VZHARDWARERESOURCEMANAGER\VZHARDWARERESOURCEMANAGER.EXE
70000 C:\PROGRAM FILES\PC CONNECTIVITY SOLUTION\SERVICELAYER.EXE
70000 C:\PROGRAM FILES\WINDOWS LIVE\INSTALLER\WLSETUPSVC.EXE
70004 C:\PROGRAM FILES\GOOGLE\GOOGLE PINYIN\GOOGLEPINYINDAEMON.EXE
70004 C:\WINDOWS\RTHDVCPL.EXE
70000 C:\PROGRA~1\COMMON~1\SONYSH~1\AVLIB\PACSPT~1.EXE
70012 C:\WINDOWS\SYSTEM32\GOOGLEPINYIN.IME
70000 C:\PROGRAM FILES\SONY\VCM INTELLIGENT ANALYZING MANAGER\VCMIALZMGR.EXE
70012 C:\WINDOWS\SYSTEM32\MSVCP71.DLL
70004 C:\PROGRAM FILES\SONY\ISB UTILITY\ISBMGR.EXE
70000 C:\PROGRA~1\SONY\VAIOME~2\PLATFORM\UPNPFR~1.EXE
70000 C:\WINDOWS\SYSTEM32\DRIVERS\XAUDIO.EXE
70000 C:\PROGRA~1\SONY\VAIOME~2\UCLS.EXE
70000 C:\PROGRA~1\COMMON~1\SONYSH~1\VAIOEN~1\VZCDB\VZFW.EXE
70012 C:\PROGRAM FILES\360SAFE\SAFEMON\SAFEMON.DLL
70000 C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
70012 C:\PROGRAM FILES\WINRAR\RAREXT.DLL
70000 C:\PROGRA~1\SONY\VAIOEV~1\VESMGR.EXE
70012 C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_NOW.DLL
70000 C:\PROGRAM FILES\SONY\VAIO MEDIA INTEGRATED SERVER\PLATFORM\VMGATEWAY.EXE
70012 C:\PROGRAM FILES\KINGSOFT\POWERWORD 2007 FOR VAIO\GRABGDIP.DLL
70012 C:\WINDOWS\SYSTEM32\MSVCR71.DLL
70000 C:\PROGRA~1\SONY\VAIOME~2\VMISRV.EXE
70012 C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\ATIACMXX.DLL
70000 C:\PROGRA~1\COMMON~1\SONYSH~1\AVLIB\SPTISRV.EXE
70000 C:\PROGRAM FILES\GOOGLE\COMMON\GOOGLE UPDATER\GOOGLEUPDATERSERVICE.EXE
70004 C:\WINDOWS\SYSTEM32\NMGAMEX.DLL
70000 C:\WINDOWS\SYSTEM32\SVCHOST.EXE
70004 C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
70000 C:\PROGRAM FILES\COMMON FILES\SONY SHARED\VAIO ENTERTAINMENT PLATFORM\VZCDB\VZCDBSVC.EXE
70012 C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\TDATONCE_NOW.DLL
帅哥阿福 - 2008-12-16 12:10:00
楼主需要将日志作为附件发到这里来,这样看会死人哒!:default3:
茶茶77 - 2008-12-16 12:16:00
这是我的sreng日志附件
附件: 3rdUpdLog.TXT (2008-12-16 12:16:14, 2.43 K)
该附件被下载次数 157
附件: SREngLOG.log (2008-12-16 12:16:14, 61.47 K)
该附件被下载次数 144
帅哥阿福 - 2008-12-16 12:32:00
C:\Users\wzql\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CCC.lnk
启动项里面有两个这个快捷方式,不知是否正常,只保留一个可否?
C:\TDDOWNLOAD\新建文件夹\ppbl\hknm.sys
C:\Users\wzql\AppData\Local\Temp\KpCheck.sys
提交到这里,或者提交给瑞星,地址如下:
http://mailcenter.rising.com.cn/index.shtml其他没有什么异常情况,楼主可使用卡卡助手-高级工具-启动项管理-ie浏览器插件,里面有几个乱码的不知是什么,可清理一下。
电脑迷途菜鸟 - 2008-12-16 12:41:00
说实话。我没耐心看完这个该死的日志~~~。但是我看到一半。我可以说你中标了。。进程注入
茶茶77 - 2008-12-16 20:37:00
能帮我仔细看看吗?
茶茶77 - 2008-12-16 20:58:00
vista进程不是本来就很多吗
茶茶77 - 2008-12-17 5:23:00
为啥没人告诉我啊
1
© 2000 - 2026 Rising Corp. Ltd.