接上正在运行的进程
[PID: 560][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 584][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 628][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 640][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 800][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 848][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 928][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\windows\system32\dbkdpfxu.dll] [N/A, N/A]
[PID: 1012][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1116][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1556][C:\wt2ksrv\bin\Apache.exe] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\bin\libapr.dll] [Apache Software Foundation, 0.0.0.0]
[C:\wt2ksrv\bin\libaprutil.dll] [Apache Software Foundation, 0.0.0.0]
[C:\wt2ksrv\bin\libapriconv.dll] [Apache Software Foundation, 0.0.0.0]
[C:\wt2ksrv\bin\libhttpd.dll] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_access.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_actions.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_alias.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_asis.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_auth.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_autoindex.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_cern_meta.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_cgi.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_dir.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_env.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_expires.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_file_cache.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_headers.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_imap.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_include.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_isapi.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_log_config.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_mime.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_negotiation.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_rewrite.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_setenvif.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_userdir.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\bin\php4apache2.dll] [N/A, N/A]
[C:\wt2ksrv\bin\php4ts.dll] [The PHP Group, 4.3.4.4]
[C:\wt2ksrv\bin\ZendExtensionManager.dll] [N/A, N/A]
[c:\wt2ksrv\bin\php-4.3.x\ZendOptimizer.dll] [N/A, N/A]
[PID: 1688][C:\wt2ksrv\bin\Apache.exe] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\bin\libapr.dll] [Apache Software Foundation, 0.0.0.0]
[C:\wt2ksrv\bin\libaprutil.dll] [Apache Software Foundation, 0.0.0.0]
[C:\wt2ksrv\bin\libapriconv.dll] [Apache Software Foundation, 0.0.0.0]
[C:\wt2ksrv\bin\libhttpd.dll] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_access.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_actions.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_alias.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_asis.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_auth.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_autoindex.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_cern_meta.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_cgi.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_dir.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_env.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_expires.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_file_cache.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_headers.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_imap.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_include.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_isapi.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_log_config.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_mime.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_negotiation.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_rewrite.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_setenvif.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\modules\mod_userdir.so] [Apache Software Foundation, 2.0.48]
[C:\wt2ksrv\bin\php4apache2.dll] [N/A, N/A]
[C:\wt2ksrv\bin\php4ts.dll] [The PHP Group, 4.3.4.4]
[C:\wt2ksrv\bin\ZendExtensionManager.dll] [N/A, N/A]
[c:\wt2ksrv\bin\php-4.3.x\ZendOptimizer.dll] [N/A, N/A]
[PID: 1580][C:\wt2ksrv\bin\mysqld-opt.exe] [N/A, N/A]
[PID: 2568][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\RRLTFT.DAT] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[PID: 2416][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2860][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\HPBMMON.DLL] [Hewlett-Packard, 10.00.16]
[C:\WINDOWS\system32\hpdomon.dll] [Hewlett-Packard, 03.42.00]
[C:\WINDOWS\system32\HPBHealr.dll] [N/A, N/A]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\IMFPrint.DLL] [Zenographics, Inc., 5, 54, 330, 0]
[C:\WINDOWS\system32\Imf32.dll] [Zenographics, Inc., 5, 60, 1204, 0]
[C:\WINDOWS\system32\ZTAG32.dll] [Zenographics, Inc., 5, 60, 1210, 0]
[C:\WINDOWS\system32\ZSPOOL.dll] [Zenographics, Inc., 5, 51, 709, 0]
[PID: 2388][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\RRLTFT.DAT] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[c:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\shellex.dll] [Kaspersky Lab, 5.0.527.1]
[C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]
[C:\Program Files\ewido anti-spyware 4.0\context.dll] [Anti-Malware Development a.s., 4, 0, 0, 172]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll] [Anti-Malware Development a.s., 4, 0, 0, 172]
[PID: 3064][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[C:\WINDOWS\System32\RRLTFT.DAT] [N/A, N/A]
[C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx] [Macromedia, Inc., 8,0,24,0]
[PID: 3936][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[C:\WINDOWS\System32\RRLTFT.DAT] [N/A, N/A]
[C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx] [Macromedia, Inc., 8,0,24,0]
[PID: 3180][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[C:\WINDOWS\System32\RRLTFT.DAT] [N/A, N/A]
[C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx] [Macromedia, Inc., 8,0,24,0]
[PID: 3244][C:\Program Files\WinRAR\WinRAR.exe] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[C:\WINDOWS\System32\RRLTFT.DAT] [N/A, N/A]
[PID: 3564][C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX00.781\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[C:\WINDOWS\System32\RRLTFT.DAT] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================