[PID: 1468][C:\Program Files\PeanutHull3\PhCore.exe] <广东网域><1, 0, 0, 13>
[C:\Program Files\PeanutHull3\PhAlive.dll] <广东网域><1, 0, 1, 26>
[PID: 1548][C:\WINNT\system32\regsvc.exe] <Microsoft Corporation><5.00.2195.6701>
[PID: 1560][C:\WINNT\system32\locator.exe] <Microsoft Corporation><5.00.2195.6619>
[PID: 1600][C:\WINNT\system32\MSTask.exe] <Microsoft Corporation><4.71.2195.6972>
[PID: 1620][C:\Program Files\Symantec AntiVirus\Rtvscan.exe] <Symantec Corporation><9.0.0.338>
[C:\WINNT\system32\CBA.DLL] <Intel? Corporation><6.12.0.112 E>
[C:\WINNT\system32\MsgSys.dll] <Intel? Corporation><6.12.0.112 E>
[C:\WINNT\system32\NTS.dll] <Intel? Corporation><6.12.0.112 E>
[C:\WINNT\system32\PDS.DLL] <Intel? Corporation><6.12.0.112 E>
[C:\Program Files\Symantec AntiVirus\NAVLU.dll] <Symantec Corporation><9.0.0.338>
[C:\Program Files\Symantec AntiVirus\I2ldvp3.dll] <Symantec Corporation><9.0.0.338>
[C:\Program Files\Symantec AntiVirus\ecmldr32.DLL] <Symantec Corp.><1.1.0.3>
[C:\Program Files\Symantec AntiVirus\SAVRT32.DLL] <Symantec Corporation><9.3.0.28>
[C:\Program Files\Symantec AntiVirus\NAVNTUTL.DLL] <Symantec Corporation><9.0.0.338>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060906.017\ecmsvr32.dll] <Symantec Corporation><61.2.1.10>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060906.017\NAVEX32a.DLL] <Symantec Corporation><20061.2.0.26>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060906.017\NAVENG32.DLL] <Symantec Corporation><20061.2.0.26>
[C:\Program Files\Symantec AntiVirus\DecSDK.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2ID.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2ZIP.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2SS.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2GZIP.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2CAB.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2LHA.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2ARJ.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2TNEF.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2LZ.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2AMG.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2TAR.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2RTF.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2Text.dll] <Symantec Corporation><3.02.11.32>
[PID: 1704][C:\WINNT\System32\WBEM\WinMgmt.exe] <Microsoft Corporation><1.50.1085.0100>
[PID: 1720][C:\WINNT\System32\wins.exe] <Microsoft Corporation><5.00.2195.7005>
[PID: 1740][C:\WINNT\system32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 1768][C:\WINNT\System32\dns.exe] <Microsoft Corporation><5.00.2195.6715>
[PID: 1796][C:\WINNT\system32\inetsrv\inetinfo.exe] <Microsoft Corporation><5.00.0984>
[PID: 1960][e:\MYOA\IMA\IMAServer.exe] <N/A><N/A>
[e:\MYOA\IMA\crypt.dll] <N/A><N/A>
[e:\MYOA\IMA\CC3260MT.DLL] <Borland Corporation><0.0.0.0 (informal build)>
[e:\MYOA\IMA\libmysql.dll] <N/A><N/A>
[PID: 1988][E:\MYOA\bin\apache.exe] <Apache Software Foundation><2.0.55>
[E:\MYOA\bin\libapr.dll] <Apache Software Foundation><0.9.7>
[E:\MYOA\bin\libaprutil.dll] <Apache Software Foundation><0.9.7>
[E:\MYOA\bin\libapriconv.dll] <Apache Software Foundation><0.9.7>
[E:\MYOA\bin\libhttpd.dll] <Apache Software Foundation><2.0.55>
[E:\MYOA\modules\mod_access.so] <Apache Software Foundation><2.0.55>
[E:\MYOA\modules\mod_actions.so] <Apache Software Foundation><2.0.55>
[E:\MYOA\modules\mod_alias.so] <Apache Software Foundation><2.0.55>
[E:\MYOA\modules\mod_asis.so] <Apache Software Foundation><2.0.55>
[E:\MYOA\modules\mod_auth.so] <Apache Software Foundation><2.0.55>
[E:\MYOA\modules\mod_autoindex.so] <Apache Software Foundation><2.0.55>
[E:\MYOA\modules\mod_dir.so] <Apache Software Foundation><2.0.55>
[E:\MYOA\modules\mod_env.so] <Apache Software Foundation><2.0.55>
[E:\MYOA\modules\mod_include.so] <Apache Software Foundation><2.0.55>
[E:\MYOA\modules\mod_log_config.so] <Apache Software Foundation><2.0.55>
[E:\MYOA\modules\mod_mime.so] <Apache Software Foundation><2.0.55>
[E:\MYOA\modules\mod_negotiation.so] <Apache Software Foundation><2.0.55>
[E:\MYOA\modules\mod_setenvif.so] <Apache Software Foundation><2.0.55>
[E:\MYOA\modules\mod_cgi.so] <Apache Software Foundation><2.0.55>
[E:\MYOA\modules\mod_isapi.so] <Apache Software Foundation><2.0.55>
[E:\MYOA\bin\sapi\php4apache2.dll] <N/A><N/A>
[E:\MYOA\bin\php4ts.dll] <The PHP Group><4.3.10.10>
[E:\MYOA\bin\mmcache.dll] <N/A><N/A>
[E:\MYOA\bin\ZendOptimizer.dll] <N/A><N/A>
[E:\MYOA\bin\php_gd2.dll] <N/A><N/A>
[E:\MYOA\bin\php_iconv.dll] <N/A><N/A>
[E:\MYOA\bin\iconv.dll] <Free Software Foundation><1.9>
[PID: 3112][C:\WINNT\System32\ismserv.exe] <Microsoft Corporation><5.00.2195.6684>
[PID: 3124][C:\WINNT\system32\msdtc.exe] <Microsoft Corporation><1999.9.3421.3>
[PID: 3228][C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe] <Microsoft Corporation><9.107.5512.0>
[PID: 3388][C:\WINNT\system32\WINDOW~1\Server\nspm.exe] <Microsoft Corporation><4.1.00.3917>
[C:\WINNT\system32\tssoft32.acm] <DSP GROUP, INC.><1.01>
[C:\WINNT\system32\tsd32.dll] <N/A><N/A>
[C:\WINNT\system32\l3codeca.acm] <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
[C:\WINNT\system32\iac25_32.ax] <Intel Corporation><2.05.53>
[PID: 3448][C:\WINNT\system32\WINDOW~1\Server\nsum.exe] <Microsoft Corporation><4.1.00.3930>
[PID: 712][C:\WINNT\system32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 3892][C:\WINNT\System32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 1852][\??\C:\WINNT\system32\csrss.exe] <Microsoft Corporation><5.00.2195.6601>
[PID: 3376][\??\C:\WINNT\system32\winlogon.exe] <Microsoft Corporation><5.00.2195.6997>
[C:\WINNT\system32\NavLogon.dll] <Symantec Corporation><9.0.0.338>
[PID: 3704][C:\WINNT\system32\rdpclip.exe] <Microsoft Corporation><5.00.2174.1>
[PID: 3336][C:\WINNT\Explorer.EXE] <Microsoft Corporation><5.00.3700.6690>
[PID: 3956][C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe] <Crawler.com><1.1.0.316>
[PID: 3748][C:\WINNT\system32\internat.exe] <Microsoft Corporation><5.00.2920.0000>
[PID: 3732][C:\Program Files\PeanutHull3\Phmain.exe] <广东网域><3, 1, 0, 42>
[C:\Program Files\PeanutHull3\PhRes.dll] <广东网域><1, 0, 8, 1>
[C:\Program Files\PeanutHull3\PhService.dll] <广东网域><1, 0, 1, 21>
[C:\Program Files\PeanutHull3\iconv.dll] <Free Software Foundation><1.9>
[C:\WINNT\PhIDNA.dll] <广东网域><1, 0, 0, 2>
[PID: 3708][C:\WINNT\system32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[PID: 3628][C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe] <Microsoft Corporation><2000.080.0194.00>
[PID: 3620][E:\MYOA\bin\monitor.exe] <N/A><N/A>
[PID: 3604][C:\WINNT\system32\dllhost.exe] <Microsoft Corporation><5.00.2195.6692>
[PID: 4292][C:\WINNT\system32\conime.exe] <Microsoft Corporation><5.00.2195.6655>
[PID: 564][C:\Documents and Settings\Administrator\桌面\专杀工具\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================