==================================
正在运行的进程
[PID: 600][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 664][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 696][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 740][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 752][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 900][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 996][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1096][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\windows\system32\acss.dll] [LINKMEDIA Tech, 1, 5, 0, 4]
[c:\windows\system32\jetspeed.dll] [, 1, 0, 0, 1]
[c:\windows\system32\nwsapagent.dll] [LINKMEDIA Tech, 1, 5, 0, 4]
[PID: 1188][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1296][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1368][C:\kav2005\KWatch.EXE] [Kingsoft Corporation, 2006, 2, 22, 52]
[C:\kav2005\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\kav2005\KAEPlat.DLL] [Kingsoft Corp., 2004, 11, 26, 53]
[C:\kav2005\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[PID: 1472][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\hpzsnt09.dll] [HP, 2.240.0.0]
[PID: 1564][d:\Program Files\汉化\AVG Anti-Spyware\guard.exe] [Anti-Malware Development a.s., 7, 5, 0, 47]
[d:\Program Files\汉化\AVG Anti-Spyware\engine.dll] [Anti-Malware Development a.s., 4, 2, 0, 15]
[PID: 1580][C:\WINDOWS\SYSTEM32\RUNDLL.EXE] [Microsoft Corporation, 5.00.2134.1]
[PID: 1628][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\MMSASS~1\MMSSVER.DLL] [, 1, 2, 0, 6]
[PID: 1688][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.8340]
[PID: 412][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[d:\Program Files\汉化\AVG Anti-Spyware\shellexecutehook.dll] [Anti-Malware Development a.s., 7, 5, 0, 47]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.10.8340]
[C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.10.8340]
[C:\WINDOWS\system32\nvshell.dll] [N/A, N/A]
[C:\WINDOWS\system32\sysag.dll] [, 1, 0, 0, 1]
[d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
[C:\kav2005\KAVEXT.DLL] [Kingsoft Corporation, 2005, 2, 21, 13]
[C:\Herosoft\HeroV8\VCvtShell.dll] [herosoft, 1, 0, 0, 1]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[d:\Program Files\汉化\AVG Anti-Spyware\context.dll] [Anti-Malware Development a.s., 7, 5, 0, 49]
[PID: 1908][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 260][C:\WINDOWS\system32\VTTimer.exe] [S3 Graphics, Inc., 2.00.01-0307]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 336][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5.1.0.42]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 364][C:\Program Files\Lenovo\功能键盘\HotKeyB.exe] [联想电脑公司, 2, 2, 0, 1]
[C:\Program Files\Lenovo\功能键盘\kbddrv.dll] [N/A, N/A]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 372][C:\kav2005\KAVStart.exe] [Kingsoft Corporation, 2005, 10, 10, 150]
[C:\kav2005\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\kav2005\KAVPassp.dll] [Kingsoft Corporation, 2006, 6, 7, 252]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 380][C:\WINDOWS\VM303_STI.EXE] [Vimicro, 4, 3, 625, 61]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\WINDOWS\system32\VM303Prp.Ax] [Vimicro, 4.3. 625.61]
[PID: 432][C:\WINDOWS\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\NvMcTray.dll] [NVIDIA Corporation, 6.14.10.8340]
[C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.10.8340]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 440][C:\Program Files\HP\hpcoretech\hpcmpmgr.exe] [Hewlett-Packard Company, 2.1.1.0]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 448][C:\Program Files\Common Files\updat\Update.exe] [N/A, N/A]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 472][C:\Program Files\ipwins\ipwins.exe] [N/A, N/A]
[C:\Program Files\ipwins\Services.dll] [N/A, N/A]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\kav2005\KAScript.DLL] [Kingsoft Corporation, 2005, 4, 1, 53]
[C:\kav2005\KAEPlat.DLL] [Kingsoft Corp., 2004, 11, 26, 53]
[C:\kav2005\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[PID: 500][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 512][C:\WINDOWS\system32\pcsoi.exe] [N/A, N/A]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 524][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 668][C:\kav2005\KMailMon.EXE] [Kingsoft Corporation, 2005, 6, 30, 74]
[C:\kav2005\KAntiSpm.dll] [N/A, 1, 0, 0, 2]
[C:\kav2005\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\kav2005\KAECall2.DLL] [Kingsoft Corporation, 2004, 12, 28, 7]
[C:\kav2005\KAEPlat.DLL] [Kingsoft Corp., 2004, 11, 26, 53]
[C:\kav2005\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\kav2005\KAConfig.DLL] [Kingsoft Corporation, 2005, 3, 23, 30]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 2500][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\sdmAgent22.dll] [LINKMEDIA Tech, 1, 5, 0, 7]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 2932][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3440][C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe] [Google Inc., 1, 2, 908, 5008]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\res_en.dll] [Google Inc., 1, 2, 908, 5008]
[C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\swg.dll] [Google Inc., 1, 2, 908, 5008]
[PID: 2964][C:\WINDOWS\system32\NOTEPAD.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\WINDOWS\system32\JPWB.IME] [常诚研制, 4.00.950]
[PID: 672][C:\kav2005\KATMain.EXE] [Kingsoft Corporation, 2006, 7, 12, 266]
[C:\kav2005\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[d:\Program Files\汉化\AVG Anti-Spyware\shellexecutehook.dll] [Anti-Malware Development a.s., 7, 5, 0, 47]
[PID: 4084][C:\Program Files\山东铁通宽带认证软件\HNMainUI.exe] [N/A, 2, 3, 0, 1]
[C:\Program Files\山东铁通宽带认证软件\HNKernel.dll] [HelloNet, 2.2.0.1]
[C:\Program Files\山东铁通宽带认证软件\HNUtils.dll] [N/A, 2, 2, 0, 1]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\Program Files\山东铁通宽带认证软件\HNRes_0804.dll] [N/A, 2, 2, 0, 1]
[C:\Program Files\山东铁通宽带认证软件\plugins\Diagnose.dll] [HelloNet, 2.2.0.1]
[PID: 3168][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\WINDOWS\DOWNLO~1\BaiDuBar.dll] [, 2, 0, 0, 0]
[c:\program files\google\googletoolbar3.dll] [Google Inc., 4, 0, 1020, 2544]
[C:\WINDOWS\system32\kakatool.dll] [Beijing Rising Technology Co., Ltd., 2, 0, 0, 9]
[C:\Program Files\DeskAdTop\deskipn.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\netidp.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SafeHelper12.dll] [LINKMEDIA Tech, 2, 0, 0, 3]
[C:\PROGRA~1\MMSASS~1\mmsass~1.dll] [, 1, 2, 0, 6]
[C:\WINDOWS\system32\BarSea.dll] [N/A, 1, 0, 0, 1]
[C:\WINDOWS\system32\sysag.dll] [, 1, 0, 0, 1]
[d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
[C:\WINDOWS\system32\Inte32.dll] [N/A, N/A]
[C:\kav2005\KAScript.DLL] [Kingsoft Corporation, 2005, 4, 1, 53]
[C:\kav2005\KAEPlat.DLL] [Kingsoft Corp., 2004, 11, 26, 53]
[C:\kav2005\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[PID: 3420][D:\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
[D:\]
[autorun]
OPEN=D:\command.com
==================================
HOSTS 文件
127.0.0.1 localhost
==================================