{B69F34DD-F0F9-42DC-9EDD-957187DA688D} [RDS.DataSpace] {BD96C556-65A3-11D0-983A-00C04FC29E36} [Tencent Safety Online Base Module] {C09B522F-8AED-4E21-A65C-DC1AB652BAEE} [AUDIO__X_MS_WMA Moniker Class] {CD3AFA84-B84F-48F0-9393-7EDC34128127} [Shockwave Flash
Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [&使用快车(FlashGet)下载] [&使用快车(FlashGet)下载全部链接] [&使用迅雷下载] [上传到QQ网络硬盘] [添加到QQ自定义面板] [添加到QQ表情] [用QQ彩信发送该图片] ================================== 正在运行的进程 [PID: 628][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 704][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 728][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\JPWB.IME] [常诚研制, 4.00.950] [PID: 772][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 956][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1040][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1160][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1236][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1468][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [PID: 1632][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)] [PID: 2000][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 688][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\JPWB.IME] [常诚研制, 4.00.950] [D:\My Documents\360safe\safemon\safemon.dll] [, 1, 0, 0, 1002] [C:\Program Files\WinRAR\rarext.dll] [N/A, N/A] [C:\Program Files\ewido anti-spyware 4.0\context.dll] [Anti-Malware Development a.s., 4, 0, 0, 172] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll] [Kaspersky Lab, 6.0.0.299] [PID: 244][D:\My Documents\360safe\safemon\360Tray.exe] [奇虎网, 1, 0, 1, 1002] [C:\WINDOWS\system32\JPWB.IME] [常诚研制, 4.00.950] [D:\My Documents\360safe\safemon\safemon.dll] [, 1, 0, 0, 1002] [D:\My Documents\360safe\safemon\SafeKrnl.dll] [奇虎网, 1, 0, 0, 1001] [D:\My Documents\360safe\AntiAdwa.dll] [360Safe.com, 2, 2, 2, 1000] [PID: 284][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [D:\My Documents\360safe\safemon\safemon.dll] [, 1, 0, 0, 1002] [C:\WINDOWS\system32\JPWB.IME] [常诚研制, 4.00.950] [PID: 1688][D:\Program Files\Opera9.10.3 优化正式版(免安装便携版)\Opera\Opera.exe] [Opera Software, 8679] [D:\Program Files\Opera9.10.3 优化正式版(免安装便携版)\Opera\Opera.dll] [Opera Software, 8679] [D:\My Documents\360safe\safemon\safemon.dll] [, 1, 0, 0, 1002] [C:\WINDOWS\system32\JPWB.IME] [常诚研制, 4.00.950] [PID: 1428][C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5, 5, 2, 252] [D:\My Documents\360safe\safemon\safemon.dll] [, 1, 0, 0, 1002] [C:\Program Files\Thunder Network\Thunder\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 10] [C:\Program Files\Thunder Network\Thunder\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 2, 11, 2, 22] [C:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031] [C:\Program Files\Thunder Network\Thunder\Program\log4cplus.dll] [, 1, 0, 2, 1] [C:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll] [Thunder Networking Technologies,LTD, 2, 11, 2, 22] [C:\WINDOWS\system32\JPWB.IME] [常诚研制, 4.00.950] [C:\Program Files\Thunder Network\Thunder\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 8] [C:\Program Files\Thunder Network\Thunder\Program\iTargetAD.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 12] [C:\WINDOWS\system32\macromed\flash\Flash85.ocx] [Macromedia, Inc., 8,5,0,133] [C:\Program Files\Thunder Network\Thunder\Components\DTAG\DTAG.dll] [, 1, 0, 0, 1] [C:\Program Files\Thunder Network\Thunder\Program\LiveUpdate.dll] [, 1, 0, 0, 9] [C:\Program Files\Thunder Network\Thunder\Program\UpdateDownload.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 8] [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll] [ , 1, 0, 0, 14] [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed07.dll] [ , 3, 1, 0, 58] [C:\Program Files\Thunder Network\Thunder\Program\msgmanage.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 15] [C:\Program Files\Thunder Network\Thunder\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 10] [C:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 2, 1, 42] [C:\Program Files\Thunder Network\Thunder\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1] [C:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 3] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll] [Kaspersky Lab, 6.0.0.299] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\pr_remote.dll] [Kaspersky Lab, 6.0.0.299] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll] [Kaspersky Lab, 6.0.0.299] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl] [Kaspersky Lab, 6.0.0.304] [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl] [Kaspersky Lab, 6.0.0.299] [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl] [Kaspersky Lab, 6.0.0.299] [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl] [Kaspersky Lab, 6.0.0.299] [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\nfio.ppl] [Kaspersky Lab, 6.0.0.299] [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\fsdrvplgn.ppl] [Kaspersky Lab, 6.0.0.299] [PID: 2828][d:\My Documents\扫描仪\SREng.EXE] [Smallfrogs Studio, 2.3.13.690] [D:\My Documents\360safe\safemon\safemon.dll] [, 1, 0, 0, 1002] [C:\WINDOWS\system32\JPWB.IME] [常诚研制, 4.00.950] ================================== 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost ================================== API HOOK 警告!System Repair Engineer 提醒你下面的函数内容与预期值不符,他们可能被一些恶意的软件所修改: RVA 错误: LoadLibraryA RVA 错误: LoadLibraryExA RVA 错误: LoadLibraryExW RVA 错误: LoadLibraryW 入口点错误:CreateProcessA 入口点错误:CreateProcessW ================================== [/CODE]