[PID: 3212][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3644][C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE] <Symantec Corporation><2006.1.1.2>
[C:\PROGRA~1\COMMON~1\SYMANT~1\SECURI~1\NSCSRVPS.DLL] <Symantec Corporation><2006.1.1.2>
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] <Symantec Corporation><104.0.4.3>
[C:\Program Files\Common Files\Symantec Shared\ccL40.dll] <Symantec Corporation><104.0.4.3>
[C:\Program Files\Common Files\Symantec Shared\ccSet.dll] <Symantec Corporation><104.0.4.3>
[C:\PROGRA~1\COMMON~1\SYMANT~1\SECURI~1\NSCUIBL.DLL] <Symantec Corporation><2006.1.1.2>
[C:\PROGRA~1\COMMON~1\SYMANT~1\SECURI~1\NSCUICOR.LOC] <Symantec Corporation><2006.1.1.2>
[C:\PROGRA~1\COMMON~1\SYMANT~1\SECURI~1\NSCJSBL.DLL] <Symantec Corporation><2006.1.1.2>
[C:\Program Files\Norton Internet Security\Norton AntiVirus\avFPXY.dll] <Symantec Corporation><2006.1.0.107>
[C:\Program Files\Norton Internet Security\isFtMst.dll] <Symantec Corporation><2006.1.1.2>
[C:\Program Files\Norton Internet Security\nscNISpi.dll] <Symantec Corporation><9.0.0.73>
[C:\PROGRA~1\NORTON~1\NORTON~1\avNSCPlg.dll] <Symantec Corporation><12.0.0.94>
[C:\PROGRA~1\NORTON~1\NORTON~1\avNSCPlg.loc] <Symantec Corporation><12.0.0.94>
[C:\Program Files\Common Files\Symantec Shared\Security Console\NSC_WSCR.DLL] <Symantec Corporation><2006.1.1.2>
[C:\Program Files\Common Files\Symantec Shared\Security Console\NSC_WSCR.LOC] <Symantec Corporation><2006.1.1.2>
[C:\Program Files\Common Files\Symantec Shared\Security Console\NSC_Hlpr.dll] <Symantec Corporation><2006.1.1.2>
[C:\Program Files\Norton Internet Security\isFtPxy.dll] <Symantec Corporation><2006.1.1.2>
[C:\Program Files\Norton Internet Security\NISRes.dll] <Symantec Corporation><9.0.0.73>
[C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll] <Symantec Corporation><104.0.4.3>
[C:\Program Files\Common Files\Symantec Shared\ccProSub.dll] <Symantec Corporation><104.0.4.3>
[C:\Program Files\Norton Internet Security\nisProd.dll] <Symantec Corporation><9.0.0.73>
[C:\Program Files\Common Files\Symantec Shared\AntiSpam\asFtPxy.dll] <Symantec Corporation><2006.1.0.107>
[C:\Program Files\Common Files\Symantec Shared\AntiSpam\asNSCPlg.dll] <Symantec Corporation><2006.2.00.153>
[C:\Program Files\Common Files\Symantec Shared\Options\asOpts.dll] <Symantec Corporation><2006.2.00.153>
[C:\Program Files\Common Files\Symantec Shared\ccLogin.dll] <Symantec Corporation><104.0.4.3>
[C:\Program Files\Common Files\Symantec Shared\AdBlocking\adFtPxy.dll] <Symantec Corporation><2006.1.0.107>
[C:\Program Files\Common Files\Symantec Shared\AdBlocking\adNscPlg.dll] <Symantec Corporation><2006.2.00.150>
[C:\Program Files\Common Files\Symantec Shared\Options\SymAd.dll] <Symantec Corporation><2006.2.00.150>
[PID: 1744][C:\Program Files\Tencent\QQ\TIMPlatform.exe] <tencent><0, 3, 1, 8>
[C:\PROGRA~1\COMMON~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] <Symantec Corporation><2006.2.00.153>
[C:\Program Files\Common Files\Symantec Shared\ccL40.dll] <Symantec Corporation><104.0.4.3>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 0, 1013>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
[C:\Program Files\Tencent\QQ\TIMProxy.dll] <tencent><0, 3, 2, 4>
[PID: 4508][C:\WINDOWS\system32\cidaemon.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 4772][C:\WINDOWS\system32\cidaemon.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 2596][C:\Program Files\KuGoo2\KuGoo.exe] <><3.2.0.76>
[C:\DOCUME~1\KAI~1.82C\LOCALS~1\Temp\IadHide5.dll] <BackWeb><Version 7.2.0 (Build 157R)>
[C:\PROGRA~1\COMMON~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] <Symantec Corporation><2006.2.00.153>
[C:\Program Files\Common Files\Symantec Shared\ccL40.dll] <Symantec Corporation><104.0.4.3>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 0, 1013>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[PID: 2988][C:\Program Files\Tencent\TT\TTraveler.exe] <腾讯公司><3.0.0.250>
[C:\DOCUME~1\KAI~1.82C\LOCALS~1\Temp\IadHide5.dll] <BackWeb><Version 7.2.0 (Build 157R)>
[C:\PROGRA~1\COMMON~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] <Symantec Corporation><2006.2.00.153>
[C:\Program Files\Common Files\Symantec Shared\ccL40.dll] <Symantec Corporation><104.0.4.3>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 0, 1013>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
[C:\PROGRA~1\3721\autolive.dll] <><1, 1, 4, 1026>
[C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll] <><2, 0, 5, 1031>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] < ><2, 0, 1, 1007>
[C:\PROGRA~1\3721\alLiveEx.dll] < ><1, 0, 3, 1006>
[C:\Program Files\Tencent\TT\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[PID: 4688][C:\Program Files\3721\木马助手\trojanassistant.exe] <Yahoo! CN><2.1.2.1003>
[C:\DOCUME~1\KAI~1.82C\LOCALS~1\Temp\IadHide5.dll] <BackWeb><Version 7.2.0 (Build 157R)>
[C:\PROGRA~1\COMMON~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] <Symantec Corporation><2006.2.00.153>
[C:\Program Files\Common Files\Symantec Shared\ccL40.dll] <Symantec Corporation><104.0.4.3>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 0, 1013>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
[C:\Program Files\3721\木马助手\fsk.dll] <3721.com><2, 1, 2, 1030>
[C:\Program Files\3721\木马助手\wmpns.dll] <---><1, 1, 8, 1324>
[PID: 4268][C:\Program Files\WinRAR\WinRAR.exe] <N/A><N/A>
[C:\DOCUME~1\KAI~1.82C\LOCALS~1\Temp\IadHide5.dll] <BackWeb><Version 7.2.0 (Build 157R)>
[C:\PROGRA~1\COMMON~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] <Symantec Corporation><2006.2.00.153>
[C:\Program Files\Common Files\Symantec Shared\ccL40.dll] <Symantec Corporation><104.0.4.3>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 0, 1013>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
[PID: 4548][C:\DOCUME~1\KAI~1.82C\LOCALS~1\Temp\Rar$EX00.485\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\DOCUME~1\KAI~1.82C\LOCALS~1\Temp\IadHide5.dll] <BackWeb><Version 7.2.0 (Build 157R)>
[C:\PROGRA~1\COMMON~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] <Symantec Corporation><2006.2.00.153>
[C:\Program Files\Common Files\Symantec Shared\ccL40.dll] <Symantec Corporation><104.0.4.3>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 0, 1013>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
[C:\DOCUME~1\KAI~1.82C\LOCALS~1\Temp\Rar$EX00.485\SREng2\Plugins\SREngPluginDemo.SRE] <Smallfrogs Studio><1, 1, 1, 0>
[PID: 3268][C:\Program Files\Messenger\msmsgs.exe] <Microsoft Corporation><4.7.3001>
[C:\DOCUME~1\KAI~1.82C\LOCALS~1\Temp\IadHide5.dll] <BackWeb><Version 7.2.0 (Build 157R)>
[C:\PROGRA~1\COMMON~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL] <Symantec Corporation><2006.2.00.153>
[C:\Program Files\Common Files\Symantec Shared\ccL40.dll] <Symantec Corporation><104.0.4.3>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 0, 1013>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]