==================================
浏览器加载项
[UMU Class]
{86450826-9507-44DC-9009-F92D2F5864EE} <C:\WINDOWS\system32\sysag.dll, N/A>
[联想]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.lenovo.com, N/A>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Shockwave Flash
Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[internet explorer helper]
{02C9B9AB-6372-46C5-B356-773FAF3B6B1E} <C:\WINDOWS\fonts\msshapi.dll, N/A>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, N/A>
[netup]
{0A44CDEC-87D0-4D4D-BF97-DE9AFB9B104A} <C:\WINDOWS\system32\netidp.dll, N/A>
[symndis]
{166DF856-08F0-4D1C-991D-7CE3DB5C26F5} <C:\WINDOWS\system32\rasacd.dll, N/A>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HHCtrl
Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[SrchHook Class]
{6E1BC898-505A-44F4-BC88-BCE43016AC96} <C:\WINDOWS\system32\SeaBar.dll, N/A>
[UMU Class]
{86450826-9507-44DC-9009-F92D2F5864EE} <C:\WINDOWS\system32\sysag.dll, N/A>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[卡卡上网安全助手]
{AFF6E516-CBE5-4F8A-9C2F-38A68013E766} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Adobe Acrobat 7.0 Browser Document]
{CA8A9780-280D-11CF-A24D-444553540000} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroPDF.dll, Adobe Systems, Inc.>
[AUDIO__MP3 Moniker Class]
{CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Shockwave Flash
Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
==================================
正在运行的进程
[PID: 676][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 732][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 756][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 800][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 812][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 972][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1032][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1128][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\program files\messenger\msnhost.dll] [N/A, N/A]
[PID: 1232][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1316][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1464][C:\kav2005\KWatch.EXE] [Kingsoft Corporation, 2006, 2, 22, 52]
[C:\kav2005\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\kav2005\KAEPlat.DLL] [Kingsoft Corp., 2004, 11, 26, 53]
[C:\kav2005\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[PID: 1524][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\ZLhp1020.DLL] [Zenographics, Inc., 5, 53, 3723, 0]
[C:\WINDOWS\system32\ZLM.dll] [Zenographics, Inc., 5, 50, 1416, 0]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\IMFPrint.DLL] [Zenographics, Inc., 5, 54, 330, 0]
[C:\WINDOWS\system32\Imf32.dll] [Zenographics, Inc., 5, 60, 1204, 0]
[C:\WINDOWS\system32\ZTAG32.dll] [Zenographics, Inc., 5, 60, 1210, 0]
[C:\WINDOWS\system32\ZSPOOL.dll] [Zenographics, Inc., 5, 51, 709, 0]
[PID: 1660][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\kav2005\KAVEXT.DLL] [Kingsoft Corporation, 2005, 2, 21, 13]
[C:\WINDOWS\system32\fileprotect.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[PID: 1844][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3.0.0.4396]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4396]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4396]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4396]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 1852][C:\WINDOWS\system32\igfxpers.exe] [Intel Corporation, 3.0.0.4396]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4396]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 1892][C:\kav2005\KAVStart.exe] [Kingsoft Corporation, 2005, 10, 10, 150]
[C:\kav2005\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\kav2005\KAVPassp.dll] [Kingsoft Corporation, 2006, 6, 7, 252]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 136][C:\WINDOWS\usblogon.exe] [N/A, N/A]
[PID: 256][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 460][C:\kav2005\KMailMon.EXE] [Kingsoft Corporation, 2005, 6, 30, 74]
[C:\kav2005\KAntiSpm.dll] [N/A, 1, 0, 0, 2]
[C:\kav2005\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\kav2005\KAECall2.DLL] [Kingsoft Corporation, 2004, 12, 28, 7]
[C:\kav2005\KAEPlat.DLL] [Kingsoft Corp., 2004, 11, 26, 53]
[C:\kav2005\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\kav2005\KAConfig.DLL] [Kingsoft Corporation, 2005, 3, 23, 30]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 560][C:\kav2005\Update.EXE] [Kingsoft Corporation, 2005, 9, 29, 542]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 1440][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1220][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\WINDOWS\system32\KakaTool.dll] [Beijing Rising Technology Co., Ltd., 2, 0, 2, 1]
[PID: 1620][C:\WINDOWS\regedit.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 1104][G:\新建文件夹 (2)\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\kav2005\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost