122211231 - 2010-5-8 22:45:00
[CODE]
2010-05-08,22:42:21
System Repair Engineer 2.8.2.1321
Smallfrogs (
http://www.KZTechs.com)
Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
计划任务
Windows 安全更新检查
API HOOK
隐藏进程
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Component Publisher]
<KavPFW><"C:\Program Files\Kingsoft\Kingsoft Internet Security\KPFW32.EXE" -startup> [(Verified)Zhuhai Kingsoft Software Co.,Ltd]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
<KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security\KAVStart.exe" -startup> [(Verified)Zhuhai Kingsoft Software Co.,Ltd]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<WPDShServiceObj><C:\WINDOWS\system32\wpdshserviceobj.dll> [Microsoft Corporation]
<PostBootReminder><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher]
<CDBurn><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher]
<WebCheck><C:\WINDOWS\system32\webcheck.dll> [(Verified)Microsoft Windows]
<SysTray><C:\WINDOWS\system32\stobject.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
<WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
<WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
<WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
<WinlogonNotify: dimsntfy><%SystemRoot%\System32\dimsntfy.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
<WinlogonNotify: ScCertProp><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
<WinlogonNotify: Schedule><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
<WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
<WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
<WinlogonNotify: termsrv><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
<WinlogonNotify: wlballoon><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
<Internet Explorer 版本更新><C:\WINDOWS\system32\ieudinit.exe> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
<Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
<Browser Customizations><"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
<浏览器自定义组件><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
<Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
<Internet Explorer><C:\WINDOWS\system32\ie4uinit.exe -BaseSettings> [(Verified)Microsoft Windows Component Publisher]
==================================
启动文件夹
N/A
==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Stopped/Disabled]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[Event Log / Eventlog][Running/Auto Start]
<C:\WINDOWS\system32\services.exe><Microsoft Corporation>
[COM+ Event System / EventSystem][Running/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\es.dll><Microsoft Corporation>
[HID Input Service / HidServ][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Kingsoft Basic Service / kaccore][Stopped/Manual Start]
<"C:\Program Files\Kingsoft\KAC\Service\kaccore.exe"><Kingsoft Corporation>
[Kingsoft Antivirus WebShield Service / Kingsoft Antivirus WebShield Service][Running/Auto Start]
<C:\Program Files\Kingsoft\Kingsoft Internet Security\webshield\KSWebShield.exe><Kingsoft Corporation>
[Kingsoft Rescue Service / Kingsoft Rescue Service][Running/Auto Start]
<d:\Program Files\kingsoft\KSM3.0\ksmsvc.exe><>
[Kingsoft Internet Security Common Service / KISSvc][Running/Auto Start]
<C:\Program Files\Kingsoft\Kingsoft Internet Security\KISSvc.EXE><Kingsoft Corporation>
[Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
<"C:\Program Files\Kingsoft\Kingsoft Internet Security\KPfwSvc.EXE"><Kingsoft Corporation>
[Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
<"C:\Program Files\Kingsoft\Kingsoft Internet Security\KWatch.EXE"><Kingsoft Corporation>
[Intel(R) Management and Security Application Local Management Service / LMS][Running/Auto Start]
<C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe><Intel Corporation>
[Network Location Awareness (NLA) / Nla][Running/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\mswsock.dll><Microsoft Corporation>
[NVIDIA Display Driver Service / nvsvc][Running/Auto Start]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Plug and Play / PlugPlay][Running/Auto Start]
<C:\WINDOWS\system32\services.exe><Microsoft Corporation>
[ServiceLayer / ServiceLayer][Stopped/Manual Start]
<"C:\Program Files\PC Connectivity Solution\ServiceLayer.exe"><Nokia>
[Windows Firewall/Internet Connection Sharing (ICS) / SharedAccess][Running/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\ipnathlp.dll><Microsoft Corporation>
[Tencent Software Update Service / TSUSVC][Stopped/Auto Start]
<"C:\Program Files\Tencent\QQSoftMgr\1.0.338.203\TencentUpdateSvc.exe" -run><Tencent>
[Intel(R) Management & Security Application User Notification Service / UNS][Running/Auto Start]
<"C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"><Intel Corporation>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\mspmsnsv.dll><Microsoft Corporation>
[Windows Management Instrumentation Driver Extensions / Wmi][Stopped/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\advapi32.dll><Microsoft Corporation>
[Windows Media Player Network Sharing Service / WMPNetworkSvc][Stopped/Manual Start]
<"C:\Program Files\Windows Media Player\WMPNetwk.exe"><Microsoft Corporation>
用户系统信息:Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
122211231 - 2010-5-8 22:46:00
[d:\Program Files\kingsoft\KSM3.0\wss\kspfeng.dll] [Kingsoft Corporation, 2009,09,29,28]
[d:\Program Files\kingsoft\KSM3.0\wss\kae\kaecore.dat] [Kingsoft Corporation, 2010,03,18,77]
[d:\Program Files\kingsoft\KSM3.0\wss\ksejob.dll] [Kingsoft Corporation, 2009,09,29,28]
[PID: 540][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.5795 (xpsp_sp3_qfe.090415-1301)]
[C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5753 (xpsp_sp3_qfe.090203-1338)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\netapi32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_qfe.081015-1409)]
[C:\WINDOWS\System32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)]
[C:\WINDOWS\system32\win32spl.dll] [Microsoft Corporation, 5.1.2600.5664 (xpsp_sp3_qfe.080827-1301)]
[PID: 1132][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.5795 (xpsp_sp3_qfe.090415-1301)]
[C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5753 (xpsp_sp3_qfe.090203-1338)]
[C:\WINDOWS\system32\SHDOCVW.dll] [Microsoft Corporation, 6.00.2900.5803 (xpsp_sp3_qfe.090428-1347)]
[C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_qfe.081015-1409)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\webshield\kwsui.dll] [Kingsoft Corporation, 2010,03,31,16]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\webshield\kswebshield.dll] [Kingsoft Corporation, 2010,03,17,11]
[C:\WINDOWS\system32\wpdshserviceobj.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[D:\Program Files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll] [Nokia, 7, 1, 108, 0]
[D:\Program Files\Nokia\Nokia PC Suite 7\NGSCM.DLL] [Nokia, 7, 1, 156, 0]
[D:\Program Files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_chi-sc.nlr] [Nokia, 7, 1, 69, 0]
[D:\Program Files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr] [Nokia, 7, 1, 21, 0]
[C:\WINDOWS\system32\portabledevicetypes.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\portabledeviceapi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.11.8836]
[C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.11.8836]
[C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.8836]
[C:\WINDOWS\system32\nvshell.dll] [, ]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\ktaskbar.dll] [Kingsoft Corporation, 2009,08,03,993]
[C:\WINDOWS\system32\browselc.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[d:\Program Files\Thunder Network\Thunder\ComDlls\ATL71.DLL] [Microsoft Corporation, 7.10.6101.0]
[d:\Program Files\Thunder Network\Thunder\ComDlls\MSVCP71.dll] [Microsoft Corporation, 7.10.6030.0]
[d:\Program Files\Thunder Network\Thunder\ComDlls\MSVCR71.dll] [Microsoft Corporation, 7.10.6030.0]
[d:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [深圳市迅雷网络技术有限公司, 5,9,19,1390]
[d:\Program Files\Thunder Network\Thunder\ComDlls\zlib1.dll] [, 1.2.3]
[d:\Program Files\Thunder Network\Thunder\userdata\Components\ResWorker\DsBho_00.dll] [深圳市迅雷网络技术有限公司, 1, 0, 0, 31]
[d:\Program Files\Thunder Network\Thunder\userdata\Components\ResWorker\DataProcessor_00.dll] [深圳市迅雷网络技术有限公司, 1, 0, 1, 5]
[C:\WINDOWS\system32\msxml3.dll] [Microsoft Corporation, 8.100.1048.0]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\system32\vsnp2uvc.dll] [Sonix, 1, 3, 2, 0]
[C:\WINDOWS\system32\quartz.dll] [Microsoft Corporation, 6.05.2600.5731]
[C:\WINDOWS\system32\wiasf.ax] [, ]
[d:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [深圳市迅雷网络技术有限公司, 5,9,19,1390]
[d:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent5.9.19.1390.dll] [深圳市迅雷网络技术有限公司, 5,9,19,1390]
[PID: 1676][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.5795 (xpsp_sp3_qfe.090415-1301)]
[C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5753 (xpsp_sp3_qfe.090203-1338)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\webshield\kwsui.dll] [Kingsoft Corporation, 2010,03,31,16]
[PID: 1808][C:\Program Files\ChinaNet\VnetClient.exe] [江苏电信, 2008, 6, 23, 17]
[C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\Program Files\ChinaNet\Communicate.dll] [GDCN, 2008, 1, 16, 15]
[C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.5795 (xpsp_sp3_qfe.090415-1301)]
[C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5753 (xpsp_sp3_qfe.090203-1338)]
[C:\Program Files\ChinaNet\DialModule.dll] [GDCN, 2008, 8, 14, 18]
[C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_qfe.081015-1409)]
[C:\Program Files\ChinaNet\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\webshield\kwsui.dll] [Kingsoft Corporation, 2010,03,31,16]
[C:\PROGRA~1\ChinaNet\CLIENT~1.DLL] [, 2004, 2, 28, 1]
[C:\PROGRA~1\ChinaNet\PLUGIN~1.OCX] [, 2007, 1, 24, 9]
[C:\PROGRA~1\ChinaNet\sign.dll] [0, 2004, 12, 1, 1]
[C:\PROGRA~1\ChinaNet\ADVERT~1.OCX] [, 2007, 4, 20, 15]
[C:\PROGRA~1\ChinaNet\VnetBs.ocx] [, 2004, 11, 18, 1]
[C:\PROGRA~1\ChinaNet\BDSearch.ocx] [gdcn, 2007, 7, 6, 14]
[C:\PROGRA~1\ChinaNet\PageFram.ocx] [Workgroup, 2008, 2, 28, 17]
[C:\PROGRA~1\ChinaNet\PlugIns\PLUGIN~1\TestCtrl.ocx] [gdcn, 1, 0, 0, 1]
[C:\PROGRA~1\ChinaNet\PlugIns\PLUGIN~1\AddrWnd.dll] [GDCN, 1, 0, 9, 1013]
[C:\PROGRA~1\ChinaNet\PlugIns\PLUGIN~1\AddrTable.dll] [, 1, 0, 0, 1]
[C:\PROGRA~1\ChinaNet\PlugIns\PLUGIN~1\zlib.dll] [, 1.1.3]
[C:\PROGRA~1\ChinaNet\PlugIns\PLUGIN~1\IMClientMsg.dll] [, 1, 0, 0, 1]
[C:\PROGRA~1\ChinaNet\PlugIns\PLUGIN~1\IMShowImage.dll] [, 1, 0, 0, 1]
[C:\PROGRA~1\ChinaNet\PlugIns\PLUGIN~1\IMWnd.dll] [, 1, 0, 0, 1]
[C:\PROGRA~1\ChinaNet\PlugIns\PLUGIN~1\FriendManager.dll] [, 1, 0, 0, 1]
[C:\PROGRA~1\ChinaNet\PlugIns\PLUGIN~1\ModBase.dll] [, 1, 2, 0, 1]
[C:\PROGRA~1\ChinaNet\PlugIns\PLUGIN~1\CrashRpt.dll] [, 3, 0, 2007, 715]
[C:\PROGRA~1\ChinaNet\PlugIns\PLUGIN~1\dbghelp.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\ChinaNet\PlugIns\PLUGIN~1\EMailLib.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\System32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)]
[C:\PROGRA~1\ChinaNet\ACCOUN~1.OCX] [Workgroup, 2008, 6, 10, 15]
[C:\PROGRA~1\ChinaNet\AccountMgr.dll] [, 2006, 11, 19, 14]
[C:\Program Files\ChinaNet\NetFunction.dll] [N/A, ]
[C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)]
[C:\PROGRA~1\ChinaNet\IcosBar.ocx] [Workgroup, 2007, 4, 29, 15]
[C:\PROGRA~1\ChinaNet\VnetSkin.ocx] [GDDC, 2008, 3, 10, 17]
[C:\PROGRA~1\ChinaNet\DialogStyle.dll] [, 1, 0, 0, 1]
[C:\PROGRA~1\ChinaNet\PlugIns\PLUGIN~1\MUdpNative.dll] [, 1, 2, 0, 1]
[C:\PROGRA~1\ChinaNet\PlugIns\PLUGIN~1\sip_file_dll.dll] [, 1, 0, 0, 1]
[C:\PROGRA~1\ChinaNet\Timer.ocx] [, 2008, 8, 14, 18]
[C:\PROGRA~1\ChinaNet\PLUGIN~2.OCX] [, 2006, 4, 4, 1]
[C:\Program Files\ChinaNet\NewMessage.dll] [, 2008, 1, 16, 10]
[C:\PROGRA~1\ChinaNet\PlugPush.dll] [, 2004, 12, 21, 1]
[C:\Program Files\ChinaNet\AllInterface.dll] [, 2008, 8, 14, 18]
[C:\PROGRA~1\ChinaNet\VNETLO~1.OCX] [, 2006, 11, 19, 14]
[C:\Program Files\ChinaNet\StatNum.dll] [, 2008, 5, 16, 11]
[C:\PROGRA~1\ChinaNet\VNETON~1.OCX] [GDCN, 2008, 11, 30, 15]
[C:\Program Files\ChinaNet\AllFunctions.dll] [GDCN, 2008, 5, 13, 10]
[C:\Program Files\ChinaNet\VnetOptLog.dll] [ , 2008, 3, 7, 15]
[C:\PROGRA~1\ChinaNet\VNETSE~1.OCX] [, 2008, 7, 3, 14]
[C:\PROGRA~1\ChinaNet\Weather.ocx] [Microsoft, 2007, 10, 25, 12]
[C:\PROGRA~1\ChinaNet\SetArea.dll] [, 2007, 5, 28, 15]
[C:\PROGRA~1\ChinaNet\IPHelper.dll] [, 2008, 8, 20, 10]
[C:\Program Files\ChinaNet\GatewayConfig.dll] [, 1, 0, 0, 1]
[C:\Program Files\ChinaNet\VnetBusinessAutoLogin.dll] [, 2008, 1, 22, 15]
[C:\WINDOWS\system32\Macromed\Flash\Flash10h.ocx] [Adobe Systems, Inc., 10,1,53,21]
[C:\WINDOWS\system32\schannel.dll] [Microsoft Corporation, 5.1.2600.5721 (xpsp_sp3_qfe.081204-1849)]
[C:\Program Files\ChinaNet\Base64.dll] [N/A, ]
[C:\PROGRA~1\ChinaNet\DlgSkin.ocx] [, 2005, 11, 14, 1]
[PID: 400][C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe] [Intel Corporation, 6.0.0.1184]
[C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.5795 (xpsp_sp3_qfe.090415-1301)]
[C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5753 (xpsp_sp3_qfe.090203-1338)]
[C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)]
[PID: 644][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.5795 (xpsp_sp3_qfe.090415-1301)]
[C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5753 (xpsp_sp3_qfe.090203-1338)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[c:\windows\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_qfe.081015-1409)]
[PID: 652][C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe] [Intel Corporation, 6.0.0.1184]
[C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.5795 (xpsp_sp3_qfe.090415-1301)]
[C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5753 (xpsp_sp3_qfe.090203-1338)]
[C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\StatusStrings.dll] [Intel Corporation, 3.0.0.1]
[C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\xerces-c_2_7.dll] [Apache Software Foundation, 2, 7, 0]
[C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\DTMessageLib.dll] [Intel Corporation, 6.0.0.0]
[C:\WINDOWS\system32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)]
[C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)]
[PID: 2324][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.5795 (xpsp_sp3_qfe.090415-1301)]
[C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5753 (xpsp_sp3_qfe.090203-1338)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)]
[PID: 2900][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.5795 (xpsp_sp3_qfe.090415-1301)]
[C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5753 (xpsp_sp3_qfe.090203-1338)]
[C:\WINDOWS\System32\MSWSOCK.DLL] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 2656][C:\WINDOWS\system32\conime.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.5795 (xpsp_sp3_qfe.090415-1301)]
[C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5753 (xpsp_sp3_qfe.090203-1338)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\webshield\kwsui.dll] [Kingsoft Corporation, 2010,03,31,16]
[PID: 1332][d:\Program Files\Tencent\QQ\Bin\TXPlatform.exe] [Tencent, 1, 48, 1690, 0]
122211231 - 2010-5-8 22:47:00
[C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.5795 (xpsp_sp3_qfe.090415-1301)]
[C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5753 (xpsp_sp3_qfe.090203-1338)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\webshield\kwsui.dll] [Kingsoft Corporation, 2010,03,31,16]
[d:\Program Files\Tencent\QQ\Bin\TXPFProxy.dll] [Tencent, 1, 48, 1690, 0]
[PID: 3552][D:\Program Files\Tencent\QQ\Bin\QQ.exe] [Tencent, 1, 48, 1700, 0]
[C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.5795 (xpsp_sp3_qfe.090415-1301)]
[C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5753 (xpsp_sp3_qfe.090203-1338)]
[D:\Program Files\Tencent\QQ\Bin\Common.dll] [Tencent, 1, 48, 1690, 0]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.DLL] [Microsoft Corporation, 8.00.50727.4053]
[C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_qfe.081015-1409)]
[D:\Program Files\Tencent\QQ\Bin\KernelUtil.dll] [Tencent, 1, 48, 1690, 0]
[D:\Program Files\Tencent\QQ\Bin\GF.dll] [Tencent, 1, 48, 1690, 0]
[D:\Program Files\Tencent\QQ\Bin\xGraphic32.dll] [Tencent, 1, 48, 1690, 0]
[D:\Program Files\Tencent\QQ\Bin\AppUtil.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\AFUtil.dll] [Tencent, 1, 48, 1700, 0]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\webshield\kwsui.dll] [Kingsoft Corporation, 2010,03,31,16]
[C:\WINDOWS\system32\msxml3.dll] [Microsoft Corporation, 8.100.1048.0]
[D:\Program Files\Tencent\QQ\Bin\AppFramework.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\MainFrame.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\AFCtrl.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\IM.dll] [Tencent, 1, 48, 1690, 0]
[D:\Program Files\Tencent\QQ\Bin\TaskTray.dll] [Tencent, 1, 48, 1700, 0]
[d:\Program Files\Tencent\QQ\Bin\TXPFProxy.dll] [Tencent, 1, 48, 1690, 0]
[D:\Program Files\Tencent\QQ\Plugin\Com.Tencent.QQShow\Bin\FlashAvatarDll.dll] [Tencent, 1.48.1.48]
[D:\Program Files\Tencent\QQ\Bin\KernelMisc.dll] [Tencent, 1, 48, 1690, 0]
[D:\Program Files\Tencent\QQ\Bin\AppMisc.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\ChatFrame.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\ConfigCenter.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\CustomFace.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\LongCnn.dll] [Tencent, 1, 48, 1690, 0]
[D:\Program Files\Tencent\QQ\Bin\ContactInfoFrame.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\MsgMgr.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\SkinMgr.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\QInterLive.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\SystemMsg.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\Com.Tencent.PaiPai\Bin\PaiPai.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\Com.Tencent.AudioVideo\Bin\AudioVideo.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\Com.Tencent.MMOG\Bin\MMOG.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\Com.Tencent.Soso\Bin\Soso.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\Com.Tencent.Qzone\Bin\Qzone.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\Com.Tencent.Weather\Bin\Weather.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\Com.Tencent.SoBar\Bin\SoBar.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\Com.Tencent.PaiPaiGift\Bin\PaiPaiGift.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\Com.Tencent.QQLive\Bin\QQLive.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\Com.Tencent.QQMusic\Bin\QQMusic.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\Com.Tencent.taotao\Bin\Taotao.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\BasicCtrlDll.dll] [TENCENT, 8,0,773,1801]
[C:\Program Files\Common Files\Tencent\TXSSO\Bin\SSOPlatform.dll] [Tencent, 1.2.1.6]
[C:\Program Files\Common Files\Tencent\TXSSO\Bin\SSOCommon.DLL] [Tencent, 1.2.1.5]
[C:\WINDOWS\system32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)]
[C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[D:\Program Files\Tencent\QQ\Bin\InformationBox.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\GroupApp.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.snsapp\Bin\SNSApp.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.paycenter\Bin\PayCenter.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.qbar\Bin\QBar.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqvipmisc\Bin\QQVipMisc.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.wenwen\Bin\WenWen.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\WBlog.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\Contacts.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.netbar\Bin\NetBar.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.vas\Bin\VAS.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.wireless\Bin\Wireless.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqshow\Bin\QQShow.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.crm\Bin\CRM.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqpet\Bin\QQPet.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqgame\Bin\QQGame.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.mail\Bin\Mail.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqvip\Bin\QQVip.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqring\Bin\QQRing.dll] [Tencent, 1, 48, 1700, 0]
[C:\WINDOWS\system32\Macromed\Flash\Flash10h.ocx] [Adobe Systems, Inc., 10,1,53,21]
[C:\WINDOWS\system32\schannel.dll] [Microsoft Corporation, 5.1.2600.5721 (xpsp_sp3_qfe.081204-1849)]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.filetransfer\Bin\FileTransfer.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.memo\Bin\Memo.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.advertisement\Bin\Advertisement.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Bin\vqqsdl.dll] [Tencent, 5, 0, 3, 24]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.today\Bin\Today.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqwebsite\Bin\QQWebsite.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.gamelife\Bin\GameLife.dll] [Tencent, 1, 48, 1700, 0]
[D:\Program Files\Tencent\QQ\Plugin\com.tencent.winks\Bin\Winks.dll] [Tencent, 1, 48, 1700, 0]
[C:\WINDOWS\system32\wbem\fastprox.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 5.0.0.3888]
[C:\WINDOWS\system32\quartz.dll] [Microsoft Corporation, 6.05.2600.5731]
[C:\WINDOWS\system32\vsnp2uvc.dll] [Sonix, 1, 3, 2, 0]
[PID: 904][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)]
[C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.5795 (xpsp_sp3_qfe.090415-1301)]
[C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5753 (xpsp_sp3_qfe.090203-1338)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\webshield\kwsui.dll] [Kingsoft Corporation, 2010,03,31,16]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\webshield\kswebshield.dll] [Kingsoft Corporation, 2010,03,17,11]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\webshield\kswbc.dll] [Kingsoft Corporation, 2010,03,17,11]
[C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_qfe.081015-1409)]
[PID: 3892][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)]
[C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.5795 (xpsp_sp3_qfe.090415-1301)]
[C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5753 (xpsp_sp3_qfe.090203-1338)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\webshield\kwsui.dll] [Kingsoft Corporation, 2010,03,31,16]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\webshield\kswebshield.dll] [Kingsoft Corporation, 2010,03,17,11]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\webshield\kswbc.dll] [Kingsoft Corporation, 2010,03,17,11]
[d:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [深圳市迅雷网络技术有限公司, 5,9,19,1390]
[d:\Program Files\Thunder Network\Thunder\ComDlls\ATL71.DLL] [Microsoft Corporation, 7.10.6101.0]
[d:\Program Files\Thunder Network\Thunder\ComDlls\MSVCP71.dll] [Microsoft Corporation, 7.10.6030.0]
[d:\Program Files\Thunder Network\Thunder\ComDlls\MSVCR71.dll] [Microsoft Corporation, 7.10.6030.0]
[d:\Program Files\Thunder Network\Thunder\Program\EmbedDetectNow.dll] [Xunlei, 1, 0, 1, 34]
[C:\Program Files\ChinaNet\VnetTransfer.dll] [, 2008, 2, 29, 16]
[C:\Program Files\ChinaNet\Communicate.dll] [GDCN, 2008, 1, 16, 15]
[C:\PROGRA~1\ChinaNet\CLIENT~1.DLL] [, 2004, 2, 28, 1]
[C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_qfe.081015-1409)]
[d:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [深圳市迅雷网络技术有限公司, 5,9,19,1390]
[d:\Program Files\Thunder Network\Thunder\ComDlls\zlib1.dll] [, 1.2.3]
[d:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent5.9.19.1390.dll] [深圳市迅雷网络技术有限公司, 5,9,19,1390]
[d:\Program Files\Thunder Network\Thunder\userdata\Components\ResWorker\DsBho_00.dll] [深圳市迅雷网络技术有限公司, 1, 0, 0, 31]
[d:\Program Files\Thunder Network\Thunder\userdata\Components\ResWorker\DataProcessor_00.dll] [深圳市迅雷网络技术有限公司, 1, 0, 1, 5]
[C:\WINDOWS\system32\msxml3.dll] [Microsoft Corporation, 8.100.1048.0]
[C:\WINDOWS\system32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)]
[C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)]
[C:\WINDOWS\system32\Macromed\Flash\Flash10h.ocx] [Adobe Systems, Inc., 10,1,53,21]
[C:\WINDOWS\system32\schannel.dll] [Microsoft Corporation, 5.1.2600.5721 (xpsp_sp3_qfe.081204-1849)]
[C:\WINDOWS\system32\wmploc.dll] [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\MFPlat.DLL] [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\quartz.dll] [Microsoft Corporation, 6.05.2600.5731]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0306]
[C:\WINDOWS\system32\wmpeffects.dll] [Microsoft Corporation, 11.0.5721.5252 (WMP_11.080624-1050)]
[C:\WINDOWS\system32\wmnetmgr.dll] [Microsoft Corporation, 11.0.5721.5251 (WMP_11.080617-2149)]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 5.0.0.3888]
[PID: 3624][D:\Program Files\sreng\SREngLdr.EXE] [Smallfrogs Studio, 2.8.2.1321]
[C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.5795 (xpsp_sp3_qfe.090415-1301)]
[C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5753 (xpsp_sp3_qfe.090203-1338)]
[PID: 2112][D:\Program Files\sreng\SREab2eaa61.EXE] [Smallfrogs Studio, 2.8.2.1321]
[C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.5795 (xpsp_sp3_qfe.090415-1301)]
[C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5753 (xpsp_sp3_qfe.090203-1338)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\webshield\kwsui.dll] [Kingsoft Corporation, 2010,03,31,16]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[D:\Program Files\sreng\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[C:\WINDOWS\system32\netapi32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_qfe.081015-1409)]
[C:\WINDOWS\System32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)]
[C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD Tcpip [UDP/IP]
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD Tcpip [RAW/IP]
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{0EFEEACD-9D34-4E8D-B2A5-5B2B6B93D042}] SEQPACKET 6
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{0EFEEACD-9D34-4E8D-B2A5-5B2B6B93D042}] DATAGRAM 6
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{68DBBAE4-3B40-4359-87F2-9359C0B24800}] SEQPACKET 3
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{68DBBAE4-3B40-4359-87F2-9359C0B24800}] DATAGRAM 3
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D7654D72-7244-42EE-84CA-29F8622DC636}] SEQPACKET 0
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D7654D72-7244-42EE-84CA-29F8622DC636}] DATAGRAM 0
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{50796ADA-B8CD-4D50-9C74-83BF43B69FC5}] SEQPACKET 1
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{50796ADA-B8CD-4D50-9C74-83BF43B69FC5}] DATAGRAM 1
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{32F4BDF5-6E14-43B0-9908-B94AEEFFBFD4}] SEQPACKET 2
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{32F4BDF5-6E14-43B0-9908-B94AEEFFBFD4}] DATAGRAM 2
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{1BF4BB6D-1CA2-4A93-B379-E3969DD34D3E}] SEQPACKET 4
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{1BF4BB6D-1CA2-4A93-B379-E3969DD34D3E}] DATAGRAM 4
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{A0F44FE2-E197-4C1B-9FF8-582458B3DD2C}] SEQPACKET 5
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{A0F44FE2-E197-4C1B-9FF8-582458B3DD2C}] DATAGRAM 5
C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 920, C:\WINDOWS\SYSTEM32\SERVICES.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1112, C:\WINDOWS\SYSTEM32\NVSVC32.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1808, C:\PROGRAM FILES\CHINANET\VNETCLIENT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 400, C:\PROGRAM FILES\INTEL\INTEL(R) MANAGEMENT ENGINE COMPONENTS\LMS\LMS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 652, C:\PROGRAM FILES\INTEL\INTEL(R) MANAGEMENT ENGINE COMPONENTS\UNS\UNS.EXE]
==================================
计划任务
N/A
==================================
Windows 安全更新检查
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
© 2000 - 2025 Rising Corp. Ltd.