瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中了Backdoor.Gpigeon.vpd,每次瑞星都能杀不掉

1234   3  /  4  页   跳转

中了Backdoor.Gpigeon.vpd,每次瑞星都能杀不掉


==================================
启动文件夹
N/A

==================================
服务
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
  <C:\WINNT\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Ati HotKey Poller / Ati HotKey Poller][Stopped/Auto Start]
  <C:\WINNT\system32\Ati2evxx.exe><>
[CA-License Client / CA_LIC_CLNT][Stopped/Manual Start]
  <C:\WINNT\Lic98Rmt.exe><N/A>
[CA-License Server / CA_LIC_SRVR][Stopped/Manual Start]
  <C:\WINNT\Lic98RmtD.exe><N/A>
[Cisco Systems, Inc. VPN Service / CVPND][Running/Auto Start]
  <c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe><Cisco Systems, Inc.>
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Google Updater Service / gusvc][Stopped/Manual Start]
  <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
[eTrust Antivirus RPC Server / InoRPC][Running/Auto Start]
  <"C:\Program Files\CA\eTrust Antivirus\InoRpc.exe"><Computer Associates International, Inc.>
[eTrust Antivirus Realtime Server / InoRT][Running/Auto Start]
  <"C:\Program Files\CA\eTrust Antivirus\InoRT.exe"><Computer Associates International, Inc.>
[eTrust Antivirus Job Server / InoTask][Running/Auto Start]
  <"C:\Program Files\CA\eTrust Antivirus\InoTask.exe"><Computer Associates International, Inc.>
[Event Log Watch / LogWatch][Running/Auto Start]
  <C:\WINNT\LogWatNT.exe><N/A>
[Netropa NHK Server / nhksrv][Running/Auto Start]
  <C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe><N/A>
[Unicenter Software Delivery / SDService][Running/Auto Start]
  <"C:\SYSMGT\TNGSD\BIN\SDSERV.EXE"><Computer Associates International, Inc.>
[WMDM PMSP Service / WMDM PMSP Service][Running/Auto Start]
  <C:\WINNT\System32\mspmspsv.exe><Microsoft Corporation>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\system32\mspmsnsv.dll><Microsoft Corporation>

==================================
驱动程序
[acpidisk / acpidisk][Running/Auto Start]
  <\??\C:\WINNT\system32\drivers\acpidisk.sys><N/A>
[aic78xx / aic78xx][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\aic78xx.sys><Microsoft Corporation>
[ati2mtag / ati2mtag][Stopped/Manual Start]
  <System32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Broadcom 570x Gigabit Integrated Controller / b57w2k][Running/Manual Start]
  <system32\DRIVERS\b57w2k.sys><Broadcom Corporation>
[Cirrus WDM Audio Codec Driver / cs429x][Stopped/Manual Start]
  <system32\drivers\cwawdm.sys><Cirrus Logic, Inc.>
[Cisco Systems VPN Adapter / CVirtA][Stopped/Manual Start]
  <system32\DRIVERS\CVirtA.sys><Cisco Systems, Inc.>
[Cisco Systems Inc. IPSec Driver / CVPNDRVA][Running/Auto Start]
  <\??\c:\WINNT\system32\Drivers\CVPNDRVA.sys><Cisco Systems, Inc.>
[d346bus / d346bus][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\d346bus.sys><>
[d346prt / d346prt][Running/Boot Start]
  <\SystemRoot\System32\Drivers\d346prt.sys><>
[TI UltraMedia CardBus Controller Filter Driver / DevUpper][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\tiumflt.sys><Texas Instruments Inc.>
[dmboot / dmboot][Stopped/Disabled]
  <System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload][Stopped/Disabled]
  <System32\drivers\dmload.sys><VERITAS Software Corp.>
[Deterministic Network Enhancer Miniport / DNE][Running/Manual Start]
  <system32\DRIVERS\dne2000.sys><Deterministic Networks, Inc.>
[3Com EtherLink XL B/C Adapter Driver / EL90BC][Stopped/Manual Start]
  <System32\DRIVERS\el90xbc5.sys><3Com Corporation>
[3Com 3C90X-BC Family PCI EtherLink Adapter / EL90Xbc][Stopped/Manual Start]
  <System32\DRIVERS\el90Xbc5.SYS><3Com Corporation>
[GTICARD / GTICARD][Running/Manual Start]
  <system32\DRIVERS\gticard.sys><Texas Instruments>
[HSFHWICH / HSFHWICH][Running/Manual Start]
  <system32\DRIVERS\HSFHWICH.sys><Conexant Systems, Inc.>
[HSF_DP / HSF_DP][Running/Manual Start]
  <system32\DRIVERS\HSF_DP.sys><Conexant Systems, Inc.>
[ialm / ialm][Running/Manual Start]
  <system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[INO_FLPY / INO_FLPY][Running/Boot Start]
  <\SystemRoot\system32\Drivers\ino_flpy.sys><Computer Associates>
[INO_FLTR / INO_FLTR][Running/Auto Start]
  <\??\C:\WINNT\system32\Drivers\ino_fltr.sys><Computer Associates>
[AEGIS Protocol (IEEE 802.1x) v1.4.0.13 / MDC8021X][Running/Auto Start]
  <system32\DRIVERS\mdc8021x.sys><Meetinghouse Data Communications>
[mdmxsdk / mdmxsdk][Running/Auto Start]
  <system32\DRIVERS\mdmxsdk.sys><Conexant>
[Multimedia Keyboard Filter Driver / msikbd2k][Running/System Start]
  <System32\DRIVERS\msikbd2k.sys><Netropa Corporation>
[mxdispdr / mxdispdr][Running/Auto Start]
  <\??\C:\WINNT\system32\drivers\mxdispdr.sys><N/A>
[O2Micro SmartCardBus Reader / O2SCBUS][Stopped/Manual Start]
  <system32\DRIVERS\ozscr.sys><O2Micro>
[OMCI WDM Device Driver / omci][Running/System Start]
  <System32\DRIVERS\omci.sys><Dell Computer Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[W2K Pctel Serial Device Driver / Ptserial][Stopped/Manual Start]
  <System32\DRIVERS\ptserial.sys><PCTEL, INC.>
[Level II Serial port driver / Serial][Running/System Start]
  <system32\DRIVERS\LEVELII.SYS><CARRIER>
[SMC IrCC Miniport Device Driver / SMCIRDA][Running/Manual Start]
  <System32\DRIVERS\smcirda.sys><SMC>
[Audio Driver (WDM) - SigmaTel CODEC / STAC97][Running/Manual Start]
  <system32\drivers\STAC97.sys><SigmaTel, Inc.>
[StreamDispatcher / StreamDispatcher][Running/Auto Start]
  <system32\DRIVERS\strmdisp.sys><Conexant Systems, Inc.>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
  <System32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[tiumfwl / tiumfwl][Running/Manual Start]
  <system32\drivers\tiumfwl.sys><Texas Instruments Inc.>
[W2k Vmodem / Vmodem][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\vmodem.sys><PCTEL, INC.>
[W2k Vpctcom / Vpctcom][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\vpctcom.sys><PCtel, Inc.>
[vsdatant / vsdatant][Stopped/Manual Start]
  <\??\C:\WINNT\system32\vsdatant.sys><Zone Labs Inc.>
[W2k Vvoice / Vvoice][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\vvoice.sys><PCtel, Inc.>
[winachsf / winachsf][Running/Manual Start]
  <system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Stopped/Manual Start]
  <system32\drivers\ialmsbw.sys><Intel Corporation>
[Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Stopped/Manual Start]
  <system32\drivers\ialmkchw.sys><Intel Corporation>
[AIM 3.0 Part 01 Codec Driver CH-7009-A/CH-7011 / {E2B953A6-195A-44F9-9BA3-3D5F4E32BB55}][Stopped/Manual Start]
  <system32\drivers\wA301a.sys><Intel Corporation>
[AIM 3.0 Part 01 Codec Driver CH-7009-B / {E2B953A7-195A-44F9-9BA3-3D5F4E32BB55}][Stopped/Manual Start]
  <system32\drivers\wA301b.sys><Intel Corporation>
gototop
 



==================================
浏览器加载项
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[CAdLogic Object]
  {11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\CPUSH\cpush.dll, >
[Info cache]
  {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <D:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, 金泰丰(广州)科技有限公司>
[Google Toolbar Helper]
  {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[AcroIEToolbarHelper Class]
  {AE7CD045-E861-484f-8273-0445EE161910} <C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll, N/A>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[Adobe PDF]
  {47833539-D0C5-4125-9FA8-0819E2EAAC93} <C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll, N/A>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 180][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.00.2195.6601]
[PID: 204][\??\C:\WINNT\system32\csrss.exe]  [Microsoft Corporation, 5.00.2195.6601]
[PID: 200][\??\C:\WINNT\system32\winlogon.exe]  [N/A, ]
    [C:\WINNT\system32\CSGina.dll]  [N/A, ]
    [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
    [C:\WINNT\system32\winlib .dll]  [N/A, ]
    [C:\WINNT\system32\msplrct.dll]  [N/A, ]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
    [C:\WINNT\system32\msacm32.drv]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.3889]
    [C:\WINNT\system32\hccutils.DLL]  [Intel Corporation, 3.0.0.3889]
[PID: 252][C:\WINNT\system32\services.exe]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\dmserver.dll]  [VERITAS Software Corp., 2191.1.296.2]
[PID: 264][C:\WINNT\system32\lsass.exe]  [Microsoft Corporation, 5.00.2184.1]
[PID: 392][C:\WINNT\System32\SCardSvr.exe]  [Microsoft Corporation, 5.00.2195.6609]
[PID: 464][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
[PID: 524][C:\WINNT\System32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\System32\unimdm.tsp]  [Microsoft Corporation, 5.00.2175.1]
    [C:\WINNT\System32\kmddsp.tsp]  [Microsoft Corporation, 5.00.2150.1]
    [C:\WINNT\System32\ndptsp.tsp]  [Microsoft Corporation, 5.00.2143.1]
    [C:\WINNT\System32\ipconf.tsp]  [Microsoft Corporation, 5.00.2143.1]
    [C:\WINNT\System32\h323.tsp]  [Microsoft Corporation, 5.00.2143.1]
[PID: 584][C:\WINNT\system32\spoolsv.exe]  [Microsoft Corporation, 5.00.2195.7059]
    [C:\WINNT\system32\AdobePDF.dll]  [Adobe Systems Incorporated., 6.0.000]
    [C:\Program Files\Adobe\Acrobat 6.0\Distillr\adistres.dll]  [Adobe Systems Incorporated., 6.0.0.2003040700]
[PID: 620][C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe]  [N/A, ]
[PID: 676][c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe]  [Cisco Systems, Inc., 4.0.2 (D)]
    [C:\WINNT\system32\vsdata.dll]  [Zone Labs Inc., 3.7.078.001]
[PID: 724][C:\Program Files\CA\eTrust Antivirus\InoRpc.exe]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\InConfig.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\InoOEM.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\INOCORE.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\SYSMGT\CA_APPSW\VIRUSSCAN\DistCfg.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\ScanLog.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\InocDB.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\wBkRsrc.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\secAddIn.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\InocAdn.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\InDrvCfg.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\secAPI.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\SYSMGT\CA_APPSW\VIRUSSCAN\InoScan.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\SYSMGT\CA_APPSW\VIRUSSCAN\ScanRes.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\poldecod.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\polAdn.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\RPCMtAdn.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\NameAPIX.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\RPCMtAPI.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\InoAlert.dll]  [Computer Associates International, Inc., 7.1.192.0]
[PID: 792][C:\Program Files\CA\eTrust Antivirus\InoRT.exe]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\ScanLog.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\InConfig.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\InoOEM.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\INOCORE.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\InocDB.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\SYSMGT\CA_APPSW\VIRUSSCAN\DistCfg.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\wBkRsrc.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\SYSMGT\CA_APPSW\VIRUSSCAN\InoScan.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\SYSMGT\CA_APPSW\VIRUSSCAN\ScanRes.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\SYSMGT\CA_APPSW\VIRUSSCAN\arclib.dll]  [Computer Associates International, Inc., 7.2.0.18]
    [C:\SYSMGT\CA_APPSW\VIRUSSCAN\VetE.dll]  [CA, Inc., Version 30.8.0.0]
gototop
 


[PID: 808][C:\Program Files\CA\eTrust Antivirus\InoTask.exe]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\InoAlert.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\ScanLog.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\InConfig.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\InoOEM.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\INOCORE.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\InocDB.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\RPCMtAPI.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\InDrvCfg.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\SYSMGT\CA_APPSW\VIRUSSCAN\DistCfg.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\secAPI.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\CA\eTrust Antivirus\wBkRsrc.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\SYSMGT\CA_APPSW\VIRUSSCAN\InoScan.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\SYSMGT\CA_APPSW\VIRUSSCAN\ScanRes.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\SYSMGT\CA_APPSW\VIRUSSCAN\arclib.dll]  [Computer Associates International, Inc., 7.2.0.18]
    [C:\SYSMGT\CA_APPSW\VIRUSSCAN\Avh32dll.dll]  [CA, Inc., Version 30.8.0.0]
[PID: 884][C:\WINNT\LogWatNT.exe]  [N/A, ]
    [C:\CA_LIC\lic98.dll]  [Computer Associates, 01.46]
[PID: 940][C:\WINNT\system32\regsvc.exe]  [Microsoft Corporation, 5.00.2195.6701]
[PID: 960][C:\WINNT\system32\MSTask.exe]  [Microsoft Corporation, 4.71.2137.1]
[PID: 996][C:\SYSMGT\TNGSD\BIN\SDSERV.EXE]  [Computer Associates International, Inc., 4, 0, 2102, 0]
[PID: 1064][C:\WINNT\System32\WBEM\WinMgmt.exe]  [Microsoft Corporation, 1.50.1085.0100]
[PID: 1144][C:\WINNT\System32\mspmspsv.exe]  [Microsoft Corporation, 7.10.00.3068]
[PID: 1156][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\msxml3.dll]  [Microsoft Corporation, 8.70.1113.0]
[PID: 1204][C:\SYSMGT\TNGSD\BIN\TRIGGAG.EXE]  [Computer Associates International, Inc., 4, 0, 2107, 0]
    [C:\SYSMGT\TNGSD\BIN\ACPORT32.dll]  [Computer Associates International, Inc., 4, 0, 2106, 0]
    [C:\SYSMGT\TNGSD\BIN\RDCNF.dll]  [Computer Associates International, Inc., 4, 0, 2102, 0]
    [C:\SYSMGT\TNGSD\BIN\SDStrCnv.dll]  [Computer Associates International, Inc., 4, 0, 2102, 0]
    [C:\SYSMGT\TNGSD\BIN\SDCAWIN.dll]  [Computer Associates International, Inc., 4, 0, 2102, 0]
    [C:\SYSMGT\TNGSD\BIN\SDWINAPI.dll]  [Computer Associates International, Inc., 4, 0, 2102, 0]
    [C:\SYSMGT\TNGSD\BIN\CTRLCOM.dll]  [Computer Associates International, Inc., 4, 0, 2107, 0]
    [C:\SYSMGT\TNGSD\BIN\SDWCHAR.dll]  [Computer Associates International, Inc., 4, 0, 2102, 0]
    [C:\SYSMGT\TNGSD\BIN\SDNLS.dll]  [Computer Associates International, Inc., 4, 0, 2102, 0]
    [C:\SYSMGT\TNGSD\BIN\SDOSAPI.dll]  [Computer Associates, 1, 0, 0, 1]
    [C:\SYSMGT\TNGSD\BIN\ASMCOM32.dll]  [Computer Associates International, Inc., 4, 0, 2106, 0]
    [C:\SYSMGT\TNGSD\BIN\NATFCL32.dll]  [Computer Associates International, Inc., 4, 0, 2102, 0]
    [C:\SYSMGT\TNGSD\BIN\SDLIC.dll]  [Computer Associates International, Inc., 4, 0, 2107, 0]
    [C:\SYSMGT\TNGSD\BIN\SDRES.dll]  [Computer Associates International, Inc., 4, 0, 2901, 0]
    [C:\SYSMGT\TNGSD\BIN\GENERAL.dll]  [Computer Associates International, Inc., 4, 0, 2106, 0]
    [C:\SYSMGT\TNGSD\BIN\COMPON.dll]  [Computer Associates International, Inc., 4, 0, 2107, 0]
    [C:\SYSMGT\TNGSD\BIN\sdevent.dll]  [Computer Associates International, Inc., 4, 0, 2106, 0]
    [C:\SYSMGT\TNGSD\BIN\SDINFOV.dll]  [Computer Associates International, Inc., 4, 0, 2102, 0]
    [C:\SYSMGT\TNGSD\BIN\SDFILSYS.dll]  [Computer Associates International, Inc., 4, 0, 2107, 0]
    [C:\SYSMGT\TNGSD\BIN\FILECOPY.dll]  [Computer Associates International, Inc., 4, 0, 2102, 0]
    [C:\SYSMGT\TNGSD\BIN\TRIGGAPI.dll]  [Computer Associates International, Inc., 4, 0, 2107, 0]
[PID: 1116][C:\WINNT\Explorer.EXE]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\WINNT\AppPatch\AcLayers.DLL]  [Microsoft Corporation, 5.00.2195.6717]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
    [C:\WINNT\system32\AcSignIcon.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  [Autodesk, 16.0.0.86]
    [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
    [C:\WINNT\system32\msacm32.drv]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\PROGRA~1\Dell\ACCESS~1\Dadkeyb.dll]  [N/A, ]
    [C:\WINNT\system32\hccutils.DLL]  [Intel Corporation, 3.0.0.3889]
    [C:\WINNT\system32\igfxres.dll]  [Intel Corporation, 3.0.0.3889]
    [C:\WINNT\system32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.3889]
    [C:\WINNT\system32\igfxdev.dll]  [Intel Corporation, 3.0.0.3889]
    [C:\Program Files\Internet Explorer\mui\0804\browselc.dll]  [Microsoft Corporation, 6.00.2800.1106]
    [C:\chenhu2\cqxms.dll]  [N/A, ]
    [C:\WINNT\system32\msadp32.acm]  [Microsoft Corporation, 5.00.2134.1]
    [C:\Program Files\Internet Explorer\mui\0804\shdoclc.dll]  [Microsoft Corporation, 6.00.2800.1106]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
    [C:\WINNT\system32\igfxpph.dll]  [Intel Corporation, 3.0.0.3889]
    [C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 6.0.0.2003040700]
    [C:\WINNT\system32\msimtf.dll]  [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\Program Files\Common Files\Autodesk Shared\Thumbnail\AcThumbnail16.dll]  [Autodesk, 16.0.0.86]
    [C:\PROGRA~1\WINZIP\WZSHLSTB.DLL]  [WinZip Computing, Inc., 3.0 (32-bit)]
    [C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL]  [Microsoft Corporation, 11.0.5510.0]
    [C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\pkmws.dll]  [Microsoft Corporation, 11.0.5510.0]
    [C:\Program Files\Common Files\Microsoft Shared\Web Folders\2052\nsextint.dll]  [, ]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\Program Files\CA\eTrust Antivirus\InoShell.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll]  [Adobe Systems Inc., 1.0.0.2003040700]
    [C:\WINNT\system32\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
gototop
 


[PID: 1412][C:\Program Files\Dell\AccessDirect\dadapp.exe]  [N/A, ]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
    [C:\PROGRA~1\Dell\ACCESS~1\Dadkeyb.dll]  [N/A, ]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
[PID: 1448][C:\Program Files\Synaptics\SynTP\SynTPLpr.exe]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
[PID: 1452][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
    [C:\WINNT\system32\SynTPAPI.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
[PID: 1468][C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe]  [Netropa Corp., 1.00]
    [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
    [C:\WINNT\system32\msiosd32.dll]  [N/A, ]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\system32\AcSignIcon.dll]  [Autodesk, 16.0.0.86]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
[PID: 1480][C:\WINNT\system32\PRPCUI.exe]  [Intel Corporation, 3.0.0.0]
    [C:\WINNT\system32\PRPCUI.dll]  [Intel Corporation, 3.0.0.0]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
    [C:\WINNT\system32\PRPCLANG.DLL]  [Intel Corp., 2.0.0.0]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
[PID: 1524][C:\Program Files\Netropa\Multimedia Keyboard\mmusbkb2.exe]  [Netropa Corporation, 1.70]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
[PID: 1532][C:\WINNT\system32\hkcmd.exe]  [Intel Corporation, 3.0.0.3889]
    [C:\WINNT\system32\hccutils.DLL]  [Intel Corporation, 3.0.0.3889]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\system32\igfxdev.dll]  [Intel Corporation, 3.0.0.3889]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
    [C:\WINNT\system32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.3889]
    [C:\WINNT\system32\igfxres.dll]  [Intel Corporation, 3.0.0.3889]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\igfxhk.dll]  [Intel Corporation, 3.0.0.3889]
[PID: 1576][C:\Program Files\Netropa\Onscreen Display\OSD.exe]  [Netropa Corp., 2.01]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
    [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
[PID: 1596][C:\PROGRA~1\CA\ETRUST~1\realmon.exe]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\PROGRA~1\CA\ETRUST~1\InConfig.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\PROGRA~1\CA\ETRUST~1\InoOEM.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\PROGRA~1\CA\ETRUST~1\INOCORE.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\PROGRA~1\CA\ETRUST~1\InDrvCfg.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\SYSMGT\CA_APPSW\VIRUSSCAN\DistCfg.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\PROGRA~1\CA\ETRUST~1\secAPI.dll]  [Computer Associates International, Inc., 7.1.192.0]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
    [C:\CA_LIC\lic98.dll]  [Computer Associates, 01.46]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
[PID: 1620][C:\chenhu2\chenqxms.exe]  [陈虎, 1.000]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
    [C:\PROGRA~1\COMMON~1\MICROS~1\Speech\sapi.dll]  [Microsoft Corporation, 5.1.4324.00  built by: lab06_n(spgbld)]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\chenhu2\cqxms.dll]  [N/A, ]
    [C:\WINNT\system32\AcSignIcon.dll]  [Autodesk, 16.0.0.86]
[PID: 1608][C:\SYSMGT\SxpInst\sxplog32.exe]  [Computer Associates International, Inc., 6.4/67]
    [C:\SYSMGT\SxpInst\SXPFILEC.dll]  [Computer Associates International, Inc., 6.4/67]
    [C:\Program Files\CA\DCS\CAWIN\CAWINEXF.dll]  [Computer Associates International, Inc., 1.20.18]
    [C:\SYSMGT\SxpInst\ccsTrc32.dll]  [Computer Associates International, Inc., 6.4/67]
    [C:\SYSMGT\TNGSD\BIN\SDStrCnv.dll]  [Computer Associates International, Inc., 4, 0, 2102, 0]
    [C:\SYSMGT\TNGSD\BIN\SDCAWIN.dll]  [Computer Associates International, Inc., 4, 0, 2102, 0]
    [C:\SYSMGT\SxpInst\CCSINI32.dll]  [Computer Associates International, Inc., 6.4/67]
    [C:\SYSMGT\SxpInst\CCSLCK32.dll]  [Computer Associates International, Inc., 6.4/67]
    [C:\SYSMGT\SxpInst\CCSTOO32.dll]  [Computer Associates International, Inc., 6.4/67]
    [C:\SYSMGT\SxpInst\SXPAAF32.dll]  [Computer Associates International, Inc., 6.4/67]
    [C:\SYSMGT\SxpInst\SXP2MSI.dll]  [Computer Associates International, Inc., 6.4/67]
    [C:\SYSMGT\SxpInst\CCSCMP32.dll]  [Computer Associates International, Inc., 6.4/67]
    [C:\SYSMGT\TNGSD\SD\NLS\sxplog32.ENU]  [Computer Associates International, Inc., 6.4/56]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
[PID: 1548][C:\WINNT\system32\ctfmon.exe]  [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\MSUTB.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
    [C:\WINNT\mui\fallback\0804\msutb.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
[PID: 1636][C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe]  [Google Inc., 1, 2, 1128, 5462]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\res_en.dll]  [Google Inc., 1, 2, 1128, 5462]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
    [C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\swg.dll]  [Google Inc., 1, 2, 1128, 5462]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
gototop
 


[PID: 1424][C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE]  [Microsoft Corporation, 9.0.6604]
    [C:\Program Files\Microsoft Office\Office\OUTLLIB.dll]  [Microsoft Corporation, 9.0.6627]
    [C:\Program Files\Microsoft Office\Office\MSO9.DLL]  [Microsoft Corporation, 9.0.7616]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\Program Files\Microsoft Office\Office\2052\outllibr.dll]  [Microsoft Corporation, 9.0.3821]
    [C:\Program Files\Common Files\System\MAPI\2052\nt\msmapi32.dll]  [Microsoft Corporation, 5.5.3121.0]
    [C:\Program Files\Common Files\System\MAPI\2052\nt\GAPI32.dll]  [Microsoft Corporation, 5.5.2803.0]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\Program Files\Common Files\System\MAPI\2052\nt\EMSABP32.DLL]  [Microsoft Corporation, 5.5.3121.0]
    [C:\Program Files\Common Files\System\MAPI\2052\nt\EMSUI32.DLL]  [Microsoft Corporation, 5.5.3121.0]
    [C:\Program Files\Common Files\System\MAPI\2052\nt\OUTEX.dll]  [Microsoft Corporation, 8.30.3122.0]
    [C:\Program Files\Microsoft Office\Office\OUTLRPC.dll]  [Microsoft Corporation, 9.0.3519]
    [C:\Program Files\Common Files\System\MAPI\2052\nt\mspst32.dll]  [Microsoft Corporation, 5.5.3121.0]
    [C:\Program Files\Common Files\System\MAPI\2052\nt\EMSMDB32.DLL]  [Microsoft Corporation, 5.5.3121.0]
    [C:\Program Files\Adobe\Acrobat 6.0\PDFMaker\Mail\Outlook\PDFMOutlook.dll]  [Adobe Systems Incorporated, 6.0.0.0]
    [C:\Program Files\Microsoft Office\Office\2052\fldpub.dll]  [Microsoft Corporation, 9.0]
    [C:\chenhu2\cqxms.dll]  [N/A, ]
    [C:\Program Files\Common Files\System\MAPI\2052\NT\ExSec32.dll]  [Microsoft Corporation, 5.5.3124.0]
    [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
    [C:\Program Files\Microsoft Office\Office\RTFHTML.dll]  [Microsoft Corporation, 9.0.6418]
    [C:\WINNT\system32\msimtf.dll]  [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N]
    [C:\PROGRA~1\Adobe\ACROBA~1.0\PDFMaker\Common\ADOBEP~1.DLL]  [, ]
    [C:\WINNT\system32\AcSignIcon.dll]  [Autodesk, 16.0.0.86]
    [C:\PROGRA~1\Dell\ACCESS~1\Dadkeyb.dll]  [N/A, ]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
    [C:\WINNT\system32\spool\DRIVERS\W32X86\3\HPBF252E.DLL]  [Hewlett-Packard Company, 4.14.0.13]
    [C:\Program Files\Common Files\System\MAPI\2052\nt\mapi32.dll]  [Microsoft Corporation, 1.0.2518.0]
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\Program Files\Internet Explorer\mui\0804\shdoclc.dll]  [Microsoft Corporation, 6.00.2800.1106]
    [C:\Program Files\Microsoft Office\Office\OUTLCTL.DLL]  [Microsoft Corporation, 9.0.2323]
[PID: 1752][C:\Program Files\Common Files\System\MAPI\2052\nt\MAPISP32.EXE]  [Microsoft Corporation, 5.5.3121.0]
    [C:\Program Files\Common Files\System\MAPI\2052\nt\msmapi32.dll]  [Microsoft Corporation, 5.5.3121.0]
    [C:\Program Files\Common Files\System\MAPI\2052\nt\GAPI32.dll]  [Microsoft Corporation, 5.5.2803.0]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\Program Files\Common Files\System\MAPI\2052\nt\EMSABP32.DLL]  [Microsoft Corporation, 5.5.3121.0]
    [C:\Program Files\Common Files\System\MAPI\2052\nt\EMSUI32.DLL]  [Microsoft Corporation, 5.5.3121.0]
    [C:\Program Files\Common Files\System\MAPI\2052\nt\OUTEX.dll]  [Microsoft Corporation, 8.30.3122.0]
    [C:\Program Files\Common Files\System\MAPI\2052\nt\EMSMDB32.DLL]  [Microsoft Corporation, 5.5.3121.0]
    [C:\Program Files\Common Files\System\MAPI\2052\nt\mspst32.dll]  [Microsoft Corporation, 5.5.3121.0]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\chenhu2\cqxms.dll]  [N/A, ]
[PID: 596][C:\DZH5\internet\hypwise.exe]  [N/A, ]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\DZH5\internet\olepro32.dll]  [Microsoft Corporation, 5.0.4275]
[PID: 1884][C:\Program Files\Microsoft Office\Office\EXCEL.EXE]  [Microsoft Corporation, 9.0.8216]
    [C:\Program Files\Microsoft Office\Office\MSO9.DLL]  [Microsoft Corporation, 9.0.7616]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\AcSignIcon.dll]  [Autodesk, 16.0.0.86]
    [C:\chenhu2\cqxms.dll]  [N/A, ]
    [C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL]  [Microsoft Corporation, 6.04.9969]
    [C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\2052\VBE6INTL.DLL]  [Microsoft Corporation, 6.03.9070]
    [C:\WINNT\system32\FM20.DLL]  [Microsoft Corporation, 11.0.5601]
    [C:\PROGRA~1\Adobe\ACROBA~1.0\PDFMaker\Common\ADOBEP~1.DLL]  [, ]
    [C:\PROGRA~1\Dell\ACCESS~1\Dadkeyb.dll]  [N/A, ]
    [C:\WINNT\system32\spool\DRIVERS\W32X86\3\HPBF252E.DLL]  [Hewlett-Packard Company, 4.14.0.13]
    [C:\WINNT\system32\spool\DRIVERS\W32X86\3\HPBF252G.DLL]  [Hewlett-Packard Company, 4.14.0.13]
[PID: 1896][C:\Program Files\Microsoft Office\Office\WINWORD.EXE]  [Microsoft Corporation, 9.0.8216]
    [C:\Program Files\Microsoft Office\Office\MSO9.DLL]  [Microsoft Corporation, 9.0.7616]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\AcSignIcon.dll]  [Autodesk, 16.0.0.86]
    [C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL]  [Microsoft Corporation, 6.04.9969]
    [C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\2052\VBE6INTL.DLL]  [Microsoft Corporation, 6.03.9070]
    [C:\PROGRA~1\Adobe\ACROBA~1.0\PDFMaker\Common\ADOBEP~1.DLL]  [, ]
    [C:\Program Files\Common Files\Microsoft Shared\Proof\MSSPELL3.DLL]  [Microsoft Corporation, 1.1.6215]
    [C:\chenhu2\cqxms.dll]  [N/A, ]
    [C:\Program Files\Common Files\Microsoft Shared\Proof\2052\MSGR2SC.DLL]  [Microsoft Corporation, 1.0]
    [C:\Program Files\Common Files\Microsoft Shared\Proof\2052\MSGR2EN.DLL]  [Microsoft Corporation, 2.0]
    [C:\Program Files\Common Files\Microsoft Shared\Proof\wdbrkchs.dll]  [Microsoft Corporation, 1.0]
    [C:\WINNT\system32\spool\DRIVERS\W32X86\3\HPBF252E.DLL]  [Hewlett-Packard Company, 4.14.0.13]
    [C:\WINNT\system32\spool\DRIVERS\W32X86\3\HPBF252G.DLL]  [Hewlett-Packard Company, 4.14.0.13]
    [C:\PROGRA~1\Dell\ACCESS~1\Dadkeyb.dll]  [N/A, ]
    [C:\WINNT\system32\CHENHU4.IME]  [chenhu, 5.8]
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  [Autodesk, 16.0.0.86]
gototop
 



[PID: 1348][C:\Program Files\Common Files\Autodesk Shared\WSCommCntr1.exe]  [Autodesk, Inc., 1.0.0.1]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\Program Files\Common Files\Autodesk Shared\WebServices1.dll]  [Autodesk, Inc., 1.0.0.1]
[PID: 544][C:\Program Files\AutoCAD LT 2004\aclt.exe]  [Autodesk, Inc., R16.00.086]
    [C:\Program Files\AutoCAD LT 2004\gdiplus.dll]  [Microsoft Corporation, 5.1.3097.0 (xpclient.010817-1148)]
    [C:\Program Files\Common Files\Autodesk Shared\ac1st16.dll]  [Autodesk, Inc., 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\MSVCR70.dll]  [Microsoft Corporation, 7.00.9466.0]
    [C:\Program Files\AutoCAD LT 2004\MSVCP70.dll]  [Microsoft Corporation, 7.00.9466.0]
    [C:\Program Files\Common Files\Autodesk Shared\acdb16.dll]  [Autodesk, Inc., 16.0.0.86]
    [C:\Program Files\Common Files\Autodesk Shared\AcGe16.dll]  [Autodesk, Inc., 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\MFC70.DLL]  [Microsoft Corporation, 7.00.9466.0]
    [C:\Program Files\AutoCAD LT 2004\acui16.dll]  [, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\ANav.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\adui16.dll]  [, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\dswhip.dll]  [Autodesk Inc., 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\heidi8.dll]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\dlint8.dll]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\SFTTABAC.dll]  [Softel vdm, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\UserData.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\adctrls.dll]  [Autodesk, Inc., 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\adui16res.dll]  [, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AnavRes.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\acui16res.dll]  [, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\DsWhipRes.dll]  [Autodesk Inc., 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\sfttabacRes.dll]  [Softel vdm, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\ADCtrlsRes.dll]  [Autodesk, Inc., 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\SCREE.DLL]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\acltres2.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\acltbtn.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\acltres.dll]  [Autodesk, Inc., 16.0.0.86]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\system32\msxml3.dll]  [Microsoft Corporation, 8.70.1113.0]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\Program Files\AutoCAD LT 2004\PrxyInet.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\PrxyInetRes.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\oleaprot.arx]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\colorRes.dll]  [, 16.0.0.86]
    [C:\WINNT\system32\AcSignIcon.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\drv\gdi8.hdi]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\drv\gdi8Res.dll]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\drv\szb8.hdi]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\drv\rblast8.hdi]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\drv\gdifont8.hdi]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\acgs.dll]  [Autodesk Inc., 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\acgsRes.dll]  [Autodesk Inc., 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\hcreg8.dll]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\hcreg8Res.dll]  [Autodesk, Inc., 8.0.16.86]
    [C:\chenhu2\cqxms.dll]  [N/A, ]
    [C:\Program Files\AutoCAD LT 2004\AcApp.arx]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcDblClkEdit.arx]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcDblClkEditPE.arx]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcDblClkEditRes.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\acdim.arx]  [, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\ShareAC.dll]  [Autodesk, Inc, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\ShareMFC.dll]  [Autodesk, Inc, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcDimRes.dll]  [, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\aceplotx.arx]  [Autodesk, 16.0.0.86]
    [c:\program files\common files\autodesk shared\achapi16.dbx]  [Autodesk, Inc., 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcEplotXRes.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\achlnkui.arx]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\achlnkuiRes.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcSign.arx]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcSignRes.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcSpaceTrans.arx]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcSpaceTransRes.dll]  [Autodesk, Inc., 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcTp.arx]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcTc.DLL]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcTcUi.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcTcRes.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcTcUiRes.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\whohas.arx]  [, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\whohasRes.dll]  [, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\acltStatusBar.arx]  [, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcSaveVp.arx]  [Autodesk, Inc., 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcSaveVpRes.dll]  [Autodesk, Inc., 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\WSCommCntrAcCon.arx]  [Autodesk, Inc., 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\WSCommCntrAcConRes.dll]  [Autodesk, 16.0.0.86]
    [C:\PROGRA~1\Dell\ACCESS~1\Dadkeyb.dll]  [N/A, ]
gototop
 


    [C:\Program Files\AutoCAD LT 2004\acmted.arx]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcMtedRes.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcTpCatalogRes.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\textedit.arx]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\TexteditRes.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcSecOpt.arx]  [Autodesk, Inc., 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcSecOptRes.dll]  [Autodesk, Inc., 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\apperr.dll]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\plotcfg8.dll]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\pctres8.dll]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\apperrRes.dll]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\plcfmgr.dll]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\MSVCI70.dll]  [Microsoft Corporation, 7.00.9466.0]
    [C:\Program Files\AutoCAD LT 2004\plcfmgrRes.dll]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\plcferr.dll]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\pm8.dll]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\pmres8.dll]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\pmutil8.dll]  [Autodesk, Inc., 8.0.16.86]
    [C:\Program Files\AutoCAD LT 2004\Acopm.arx]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\Acpi.arx]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\ATL70.DLL]  [Microsoft Corporation, 7.00.9466.0]
    [C:\Program Files\AutoCAD LT 2004\axdb16.dll]  [, ]
    [C:\Program Files\AutoCAD LT 2004\AcPiRes.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcOpmRes.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcObjClassImp.arx]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcOcSchemaUtil.arx]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcObjClassImpRes.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\ACOPMEXT.ARX]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcOpmExtRes.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcPEXCtlRes.dll]  [Autodesk Inc,., 16.0.0.86]
    [c:\program files\common files\autodesk shared\Ax16ENUres.dll]  [Autodesk, Inc, 16.0.0.86]
    [c:\program files\common files\autodesk shared\AcMPolygonObj16CHSRes.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\AcPEXCtl.arx]  [Autodesk Inc,., 16.0.0.86]
    [c:\program files\common files\autodesk shared\Ax16CHSres.dll]  [Autodesk, Inc, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\dwgaids.arx]  [Autodesk, 16.0.0.86]
    [C:\Program Files\AutoCAD LT 2004\Dwgaidsres.dll]  [Autodesk, 16.0.0.86]
[PID: 324][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2800.1106]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\Program Files\Internet Explorer\mui\0804\browselc.dll]  [Microsoft Corporation, 6.00.2800.1106]
    [C:\WINNT\system32\AcSignIcon.dll]  [Autodesk, 16.0.0.86]
    [c:\program files\google\googletoolbar2.dll]  [Google Inc., 4, 0, 1601, 4978]
    [C:\WINNT\system32\msxml3.dll]  [Microsoft Corporation, 8.70.1113.0]
    [C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll]  [N/A, ]
    [C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ATL.DLL]  [Microsoft Corporation, 3.00.8449]
    [C:\WINNT\system32\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
    [C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 6.0.0.2003040700]
    [C:\Program Files\Common Files\CPUSH\cpush.dll]  [, 1.0.4.3]
    [D:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll]  [金泰丰(广州)科技有限公司, 2, 3, 0, 0]
    [C:\Program Files\Internet Explorer\mui\0804\shdoclc.dll]  [Microsoft Corporation, 6.00.2800.1106]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\msimtf.dll]  [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N]
    [C:\Program Files\Common Files\Microsoft Shared\INK\PENCHS.DLL]  [Microsoft Corporation, 1.0.1038.0]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\chenhu2\cqxms.dll]  [N/A, ]
    [C:\PROGRA~1\Dell\ACCESS~1\Dadkeyb.dll]  [N/A, ]
    [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
    [C:\WINNT\system32\msacm32.drv]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\msadp32.acm]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
    [C:\WINNT\system32\Macromed\Common\SwSupport.dll]  [Macromedia, Inc., 8.5.1r102]
gototop
 


[PID: 1188][C:\Program Files\Tencent\QQ\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\BasicCtrlDll.dll]  [Tencent, 7, 0, 101, 80]
    [C:\Program Files\Tencent\QQ\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\WINNT\system32\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\Program Files\Tencent\QQ\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\Program Files\Tencent\QQ\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [C:\Program Files\Tencent\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\Program Files\Tencent\QQ\LoginCtrl.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [C:\Program Files\Tencent\QQ\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [C:\Program Files\Tencent\QQ\LoginCtrlRes.dll]  [, 1, 0, 0, 1]
    [C:\chenhu2\cqxms.dll]  [N/A, ]
    [C:\PROGRA~1\Dell\ACCESS~1\Dadkeyb.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\WizardCtrl.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQMainFrame.dll]  [N/A, ]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
    [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
    [C:\WINNT\system32\msacm32.drv]  [Microsoft Corporation, 5.00.2134.1]
    [C:\Program Files\Tencent\QQ\CQQApplication.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\NewSkin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\HostingMgr.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\CameraDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\MailSummary.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQKnowledgeSearch.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQAllInOne.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\GroupLive.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Tencent\QQ\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\vbscript.dll]  [Microsoft Corporation, 5.6.0.6626]
    [C:\WINNT\System32\devenum.dll]  [, ]
    [C:\WINNT\system32\msdmo.dll]  [, ]
    [C:\Program Files\Tencent\QQ\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQPlugin.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QRingMng.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\QQAvatar.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\Program Files\Tencent\QQ\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [C:\Program Files\Tencent\QQ\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [C:\Program Files\Tencent\QQ\QQPet.dll]  [, 1, 0, 0, 1]
    [C:\WINNT\system32\AcSignIcon.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\Tencent\QQ\BQQApplication.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  [N/A, ]
    [C:\Program Files\Internet Explorer\mui\0804\shdoclc.dll]  [Microsoft Corporation, 6.00.2800.1106]
    [C:\WINNT\system32\msimtf.dll]  [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N]
    [C:\WINNT\system32\msadp32.acm]  [Microsoft Corporation, 5.00.2134.1]
    [C:\Program Files\Tencent\QQ\QQCustomFace.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [C:\Program Files\Tencent\QQ\QQSceneMng.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQ\CommercesMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [C:\Program Files\Tencent\QQ\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 280]
    [C:\Program Files\Tencent\QQ\QQMagicFace.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\Tencent\QQ\QQFileTransfer.dll]  [Tencent, 0, 3, 3, 5]
    [C:\Program Files\Tencent\QQ\GroupConnection.dll]  [Tencent, 0, 3, 3, 5]
    [C:\Program Files\Tencent\QQ\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 9, 93]
[PID: 652][C:\Program Files\Tencent\QQ\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 2124][D:\Documents and Settings\mirh\Desktop\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\WINNT\system32\MSCTF.dll]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 6.7.4 01Aug02]
    [C:\WINNT\mui\fallback\0804\msctf.dll.mui]  [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
    [C:\chenhu2\cqxms.dll]  [N/A, ]
    [D:\Documents and Settings\mirh\Desktop\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
gototop
 



==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINNT\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 724, C:\PROGRAM FILES\CA\ETRUST ANTIVIRUS\INORPC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 792, C:\PROGRAM FILES\CA\ETRUST ANTIVIRUS\INORT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 808, C:\PROGRAM FILES\CA\ETRUST ANTIVIRUS\INOTASK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 884, C:\WINNT\LOGWATNT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 996, C:\SYSMGT\TNGSD\BIN\SDSERV.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1144, C:\WINNT\SYSTEM32\MSPMSPSV.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 1144, C:\WINNT\SYSTEM32\MSPMSPSV.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1204, C:\SYSMGT\TNGSD\BIN\TRIGGAG.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1412, C:\PROGRAM FILES\DELL\ACCESSDIRECT\DADAPP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1468, C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\MMKEYBD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1480, C:\WINNT\SYSTEM32\PRPCUI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1524, C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\MMUSBKB2.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1576, C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1596, C:\PROGRA~1\CA\ETRUST~1\REALMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1620, C:\CHENHU2\CHENQXMS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1608, C:\SYSMGT\SXPINST\SXPLOG32.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1548, C:\WINNT\SYSTEM32\CTFMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1424, C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OUTLOOK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1752, C:\PROGRAM FILES\COMMON FILES\SYSTEM\MAPI\2052\NT\MAPISP32.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 596, C:\DZH5\INTERNET\HYPWISE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1884, C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\EXCEL.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1896, C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\WINWORD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1188, C:\PROGRAM FILES\TENCENT\QQ\QQ.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 652, C:\PROGRAM FILES\TENCENT\QQ\TIMPLATFORM.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 



==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINNT\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 724, C:\PROGRAM FILES\CA\ETRUST ANTIVIRUS\INORPC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 792, C:\PROGRAM FILES\CA\ETRUST ANTIVIRUS\INORT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 808, C:\PROGRAM FILES\CA\ETRUST ANTIVIRUS\INOTASK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 884, C:\WINNT\LOGWATNT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 996, C:\SYSMGT\TNGSD\BIN\SDSERV.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1144, C:\WINNT\SYSTEM32\MSPMSPSV.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 1144, C:\WINNT\SYSTEM32\MSPMSPSV.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1204, C:\SYSMGT\TNGSD\BIN\TRIGGAG.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1412, C:\PROGRAM FILES\DELL\ACCESSDIRECT\DADAPP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1468, C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\MMKEYBD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1480, C:\WINNT\SYSTEM32\PRPCUI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1524, C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\MMUSBKB2.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1576, C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1596, C:\PROGRA~1\CA\ETRUST~1\REALMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1620, C:\CHENHU2\CHENQXMS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1608, C:\SYSMGT\SXPINST\SXPLOG32.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1548, C:\WINNT\SYSTEM32\CTFMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1424, C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OUTLOOK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1752, C:\PROGRAM FILES\COMMON FILES\SYSTEM\MAPI\2052\NT\MAPISP32.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 596, C:\DZH5\INTERNET\HYPWISE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1884, C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\EXCEL.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1896, C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\WINWORD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1188, C:\PROGRAM FILES\TENCENT\QQ\QQ.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 652, C:\PROGRAM FILES\TENCENT\QQ\TIMPLATFORM.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 
1234   3  /  4  页   跳转
页面顶部
Powered by Discuz!NT