正在运行的进程
[PID: 472][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 528][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 552][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\winlib .dll] [N/A, N/A]
[PID: 596][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 608][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 752][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 812][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 848][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\windows\system32\webmail.dll] [, 1, 0, 0, 2]
[c:\windows\system32\ntxml.dll] [, 1, 0, 0, 1]
[PID: 896][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 948][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1244][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\mctet.dll] [, 5, 3, 1, 120]
[C:\WINDOWS\system32\vrcqt.dll] [N/A, N/A]
[C:\WINDOWS\system32\plisdpz.dll] [N/A, N/A]
[C:\WINDOWS\system32\cxuppos.dll] [N/A, N/A]
[C:\Windows\system32\TYEKTZGMTAH.DLL] [N/A, 1.0.0.1]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\xpdhcp.dll] [N/A, N/A]
[C:\PROGRA~1\bfda\fjhe.dll] [, 1, 2, 0, 8]
[C:\WINDOWS\system32\PVAHPVCIP.DLL] [N/A, N/A]
[C:\Program Files\AhnLab\V3\V3Bar.dll] [AhnLab, Inc., 6, 0, 0, 23]
[C:\Program Files\AhnLab\V3\NLS\bar0804.nls] [AhnLab, Inc., 6, 0, 0, 7]
[PID: 1276][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1412][C:\WINDOWS\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\umtcap.dll] [, 5.1.1800.2813]
[PID: 1548][C:\WINDOWS\system32\7B73C970.exe] [N/A, N/A]
[PID: 1588][C:\Program Files\AhnLab\Smart Update Utility\AhnSDsv.exe] [AhnLab, Inc., 5, 5, 0, 2]
[C:\Program Files\AhnLab\Smart Update Utility\NLS\ASD0804.nls] [AhnLab, Inc., 5, 0, 0, 5]
[PID: 1712][C:\PROGRA~1\AhnLab\V3\MonSvcNT.exe] [AhnLab, Inc., 6, 1, 0, 12]
[C:\PROGRA~1\AhnLab\V3\AhnGICF.dll] [AhnLab, Inc., 6, 0, 0, 2]
[C:\PROGRA~1\AhnLab\V3\V3DrEx.dll] [AhnLab, Inc., 7, 0, 0, 112]
[C:\PROGRA~1\AhnLab\V3\v3svcctr.dll] [AhnLab, Inc., 6, 1, 0, 1]
[C:\PROGRA~1\AhnLab\V3\V3CfgE.dll] [AhnLab, Inc., 6, 0, 0, 96]
[C:\PROGRA~1\AhnLab\V3\V3Flt.dll] [AhnLab, Inc., 6, 1, 0, 8]
[C:\PROGRA~1\AhnLab\V3\AhnCtlKD.dll] [AhnLab, Inc., 1, 0, 1, 7]
[C:\PROGRA~1\AhnLab\V3\v3if.dll] [AhnLab, Inc., 6, 1, 0, 3]
[C:\PROGRA~1\AhnLab\V3\V3STScan.dll] [AhnLab, Inc., 6, 1, 0, 2]
[C:\PROGRA~1\AhnLab\V3\AhnDMZ.dll] [AhnLab, Inc., 6, 0, 0, 73]
[C:\PROGRA~1\AhnLab\V3\V3Track.dll] [AhnLab, Inc., 6, 0, 0, 26]
[C:\PROGRA~1\AhnLab\V3\V3IMSvc.dll] [AhnLab, Inc., 6, 0, 0, 33]
[C:\PROGRA~1\AhnLab\V3\V3Ift.dll] [AhnLab, Inc., 6, 0, 0, 5]
[C:\PROGRA~1\AhnLab\V3\NLS\V3Dr0804.nls] [AhnLab, Inc., 7, 0, 0, 8]
[C:\PROGRA~1\AhnLab\V3\v3logex.dll] [AhnLab, Inc., 6, 1, 0, 2]
[C:\PROGRA~1\AhnLab\V3\V3NETINT.dll] [AhnLab, Inc., 6, 0, 0, 20]
[C:\PROGRA~1\AhnLab\V3\System\27\V3pro32e.dll] [AhnLab, Inc., 2007,01,31,03]
[C:\WINDOWS\system32\v3w32se2.dll] [Ahnlab, Inc., 2002, 12, 16, 1]
[C:\PROGRA~1\AhnLab\V3\V3SR32.dll] [AhnLab, Inc., 5, 0, 0, 2]
[PID: 1816][C:\Program Files\AhnLab\APC2\Policy Agent\pasvc.exe] [AhnLab, Inc., 2.5.5.76]
[C:\Program Files\AhnLab\APC2\Policy Agent\SLogW.dll] [AhnLab, 2, 1, 0, 0]
[C:\Program Files\AhnLab\APC2\Policy Agent\SSync.dll] [AhnLab, 2, 1, 0, 0]
[C:\Program Files\AhnLab\APC2\Policy Agent\IniRW.dll] [AhnLab, 2, 1, 0, 0]
[C:\Program Files\AhnLab\APC2\Policy Agent\TPool.dll] [AhnLab, 2, 1, 0, 0]
[C:\Program Files\AhnLab\APC2\Policy Agent\MaCfgRw.dll] [AhnLab, 2, 5, 5, 11]
[C:\Program Files\AhnLab\APC2\Policy Agent\SBase64.dll] [AhnLab, 2, 1, 0, 0]
[C:\Program Files\AhnLab\APC2\Policy Agent\PaNetApi.dll] [Ahnlab, Inc., 2, 5, 5, 90]
[PID: 364][C:\Windows\system32\RWBIQXEKRY.EXE] [N/A, N/A]
[PID: 432][C:\WINDOWS\SYSTEM32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 488][C:\WINDOWS\system32\win.exe] [N/A, N/A]
[PID: 876][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\bfda\imkh.dll] [, 1, 2, 0, 8]
[PID: 2132][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\system32\igfxhk.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3,0,0,2104]
[PID: 2140][C:\Program Files\AhnLab\Smart Update Utility\AhnSD.exe] [AhnLab, Inc., 5, 5, 0, 2]
[C:\Program Files\AhnLab\Smart Update Utility\NLS\ASD0804.nls] [AhnLab, Inc., 5, 0, 0, 5]
[PID: 2148][C:\WINDOWS\services.exe] [N/A, N/A]
[PID: 2184][C:\Program Files\AhnLab\V3\MonSysNT.exe] [AhnLab, Inc., 6, 1, 0, 91]
[C:\Program Files\AhnLab\V3\V3CfgE.dll] [AhnLab, Inc., 6, 0, 0, 96]
[C:\Program Files\AhnLab\V3\V3SSCtrl.dll] [AhnLab, Inc., 6, 0, 0, 100]
[C:\Program Files\AhnLab\V3\AhnI18N.dll] [AhnLab, Inc., 6, 0, 0, 18]
[C:\Program Files\AhnLab\V3\NLS\Mon0804.nls] [AhnLab, Inc., 6, 0, 0, 26]
[C:\Program Files\AhnLab\V3\AhnAlert.dll] [AhnLab, Inc., 6, 0, 0, 17]
[PID: 2192][C:\Program Files\AhnLab\V3\V3P3AT.exe] [AhnLab, Inc., 6, 1, 0, 201]
[C:\Program Files\AhnLab\V3\v3if.dll] [AhnLab, Inc., 6, 1, 0, 3]
[C:\Program Files\AhnLab\V3\V3CfgE.dll] [AhnLab, Inc., 6, 0, 0, 96]
[C:\Program Files\AhnLab\V3\V3DrEx.dll] [AhnLab, Inc., 7, 0, 0, 112]
[C:\Program Files\AhnLab\V3\V3P3ATHL.dll] [AhnLab, Inc., 6, 0, 0, 23]
[C:\Program Files\AhnLab\V3\AhnI18N.dll] [AhnLab, Inc., 6, 0, 0, 18]
[C:\Program Files\AhnLab\V3\V3MsgFlt.dll] [AhnLab, Inc., 6, 0, 0, 63]
[C:\Program Files\AhnLab\V3\V3NfCtl.dll] [AhnLab, Inc., 6, 0, 0, 3]
[C:\Program Files\AhnLab\V3\AnfdCtrl.dll] [AhnLab, Inc., 2, 0, 0, 12]
[C:\Program Files\AhnLab\V3\AhnCtlKD.dll] [AhnLab, Inc., 1, 0, 1, 7]
[C:\Program Files\AhnLab\V3\AhnIConv.dll] [AhnLab, Inc., 1, 0, 0, 1]
[C:\Program Files\AhnLab\V3\NLS\V3Dr0804.nls] [AhnLab, Inc., 7, 0, 0, 8]
[C:\Program Files\AhnLab\V3\NLS\V3MF0804.nls] [AhnLab, Inc., 6, 0, 0, 8]
[C:\Program Files\AhnLab\V3\v3logex.dll] [AhnLab, Inc., 6, 1, 0, 2]
[C:\Program Files\AhnLab\V3\NLS\p3at0804.nls] [AhnLab, Inc., 6, 0, 0, 14]
[C:\Program Files\AhnLab\V3\System\27\V3pro32e.dll] [AhnLab, Inc., 2007,01,31,03]
[C:\WINDOWS\system32\v3w32se2.dll] [Ahnlab, Inc., 2002, 12, 16, 1]
[C:\Program Files\AhnLab\V3\V3SR32.dll] [AhnLab, Inc., 5, 0, 0, 2]
[C:\Program Files\AhnLab\V3\V3azex.dll] [AhnLab, Inc., 5, 0, 0, 14]
[C:\Program Files\AhnLab\V3\AZMain.DLL] [ESTSoft Corp, 3.6.9.543]
[C:\Program Files\AhnLab\V3\V3MailDt.dll] [AhnLab, Inc., 6, 0, 0, 91]
[PID: 2200][C:\Program Files\AhnLab\V3\V3IMPro.exe] [AhnLab, Inc., 6, 0, 0, 33]
[C:\Program Files\AhnLab\V3\V3IM.dll] [AhnLab, Inc., 6, 0, 0, 47]
[C:\Program Files\AhnLab\V3\V3Ift.dll] [AhnLab, Inc., 6, 0, 0, 5]
[C:\Program Files\AhnLab\V3\AhnCtlKD.dll] [AhnLab, Inc., 1, 0, 1, 7]
[C:\Program Files\AhnLab\V3\NLS\V3IM0804.nls] [AhnLab, Inc., 6, 0, 0, 8]
[C:\Program Files\AhnLab\V3\V3CfgE.dll] [AhnLab, Inc., 6, 0, 0, 96]
[PID: 2316][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2652][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[PID: 2828][C:\Program Files\WinRAR\WinRAR.exe] [N/A, N/A]
[PID: 2852][C:\DOCUME~1\Boss\LOCALS~1\Temp\Rar$EX02.390\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
[/CODE]