==================================
正在运行的进程
[PID: 1384][C:\WINNT\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690]
[C:\WINNT\system32\igfxpph.dll] [Intel Corporation, 3.0.0.3889]
[C:\WINNT\system32\hccutils.DLL] [Intel Corporation, 3.0.0.3889]
[C:\WINNT\system32\igfxres.dll] [Intel Corporation, 3.0.0.3889]
[C:\WINNT\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.3889]
[C:\WINNT\system32\igfxdev.dll] [Intel Corporation, 3.0.0.3889]
[C:\WINNT\system32\igfxress.dll] [Intel Corporation, 3.0.0.3889]
[C:\WINNT\system32\igfxcpl.cpl] [Intel Corporation, 3.0.0.3889]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[PID: 1388][C:\Program Files\Common Files\Symantec Shared\ccApp.exe] [Symantec Corporation, 103.5.7.3]
[C:\Program Files\Common Files\Symantec Shared\ccL35.dll] [Symantec Corporation, 103.5.7.3]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 103.5.7.3]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCALERT.DLL] [Symantec Corporation, 103.5.7.3]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCEMLPXY.DLL] [Symantec Corporation, 103.5.7.3]
[C:\WINNT\system32\SYMREDIR.DLL] [Symantec Corporation, 6.0.1.105]
[C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 103.5.7.3]
[C:\Program Files\Common Files\Symantec Shared\ccProSub.dll] [Symantec Corporation, 103.5.7.3]
[C:\Program Files\Symantec AntiVirus\SavEmail.dll] [Symantec Corporation, 10.0.2.2000]
[PID: 1276][C:\PROGRA~1\SYMANT~1\VPTray.exe] [Symantec Corporation, 10.0.2.2000]
[C:\Program Files\Symantec AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.7.0.10]
[C:\Program Files\Symantec AntiVirus\Cliproxy.dll] [Symantec Corporation, 10.0.2.2000]
[C:\PROGRA~1\SYMANT~1\NAVNTUTL.DLL] [Symantec Corporation, 10.0.2.2000]
[c:\program files\common files\symantec shared\ssc\ScsComms.dll] [Symantec Corporation, 10.0.2.2000]
[C:\WINNT\system32\nts.dll] [LANDesk Software Ltd., 6.12.0.141 E]
[C:\WINNT\system32\cba.dll] [LANDesk Software Ltd., 6.12.0.140 E]
[C:\WINNT\system32\MsgSys.dll] [LANDesk Software Ltd., 6.12.0.140 E]
[C:\WINNT\system32\PDS.DLL] [LANDesk Software Ltd., 6.12.0.140 E]
[PID: 1148][C:\WINNT\system32\NILaunch.exe] [N/A, N/A]
[PID: 1256][C:\WINNT\system32\hkcmd.exe] [Intel Corporation, 3.0.0.3889]
[C:\WINNT\system32\hccutils.DLL] [Intel Corporation, 3.0.0.3889]
[C:\WINNT\system32\igfxdev.dll] [Intel Corporation, 3.0.0.3889]
[C:\WINNT\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.3889]
[C:\WINNT\system32\igfxhk.dll] [Intel Corporation, 3.0.0.3889]
[C:\WINNT\system32\igfxres.dll] [Intel Corporation, 3.0.0.3889]
[PID: 1440][C:\WINNT\system32\internat.exe] [Microsoft Corporation, 5.00.2920.0000]
[PID: 1556][C:\EXceed37\EXceed37CLT\program files\EXETechnologies\WorkStation\exceed3.exe] [N/A, N/A]
[C:\Program Files\EXETechnologies\PB8LIB\PBVM80.dll] [Sybase Inc., 8.0.1.9056]
[C:\Program Files\EXETechnologies\PB8LIB\libjcc.dll] [N/A, N/A]
[C:\Program Files\EXETechnologies\PB8LIB\pbdwe80.dll] [Sybase Inc., 8.0.1.9056]
[C:\Program Files\EXETechnologies\PB8LIB\icssock.dll] [N/A, N/A]
[C:\Program Files\EXETechnologies\PB8LIB\PBNTPRN.DLL] [N/A, N/A]
[C:\Program Files\EXETechnologies\PB8LIB\pbO7380.dll] [Sybase Inc., 8.0.1.9056]
[c:\oracle\ora81\bin\OCIW32.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\ORACLIENT8.DLL] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\oracore8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\oranls8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\oravsn8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\oracommon8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\orageneric8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\oranl8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\oran8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\orancrypt8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\oranro8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\orannzsbb8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\oranldap8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\oraldapclnt8.dll] [Oracle Corporation, 8.1.5.0.0]
[c:\oracle\ora81\bin\oranhost8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\oranoname8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\orancds8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\orantns8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\orannds8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\oranms.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\oranmsp.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\ORATRACE8.dll] [N/A, N/A]
[c:\oracle\ora81\bin\orapls8.dll] [Oracle Corporation, 8]
[c:\oracle\ora81\bin\oraslax8.dll] [Oracle Corporation, 8]
[c:\oracle\ora81\bin\orawtc8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\orasql8.dll] [Oracle Corporation, 8.1.7.0.0]
[c:\oracle\ora81\bin\orantcp8.dll] [Oracle Corporation, 8.1.7.0.0]
[PID: 1240][C:\Program Files\lotus\notes\NLNOTES.EXE] [N/A, N/A]
[C:\Program Files\lotus\notes\nnotesws.dll] [N/A, N/A]
[C:\Program Files\lotus\notes\nnotes.dll] [N/A, N/A]
[C:\Program Files\lotus\notes\nxmlpar.dll] [N/A, N/A]
[C:\Program Files\lotus\notes\nxmlcommon.dll] [N/A, N/A]
[C:\Program Files\lotus\notes\js32.dll] [N/A, N/A]
[C:\Program Files\lotus\notes\NLSCCSTR.DLL] [N/A, N/A]
[C:\Program Files\lotus\notes\ndgts.dll] [N/A, N/A]
[C:\Program Files\lotus\notes\LTOUIN22.dll] [Lotus Development Corporation., 2.2.0.8911]
[C:\Program Files\lotus\notes\nplugins.dll] [N/A, N/A]
[C:\Program Files\lotus\notes\NSTRINGS.DLL] [N/A, N/A]
[C:\Program Files\lotus\notes\namhook.DLL] [N/A, N/A]
[C:\Program Files\lotus\notes\nTCP.DLL] [N/A, N/A]
[C:\Program Files\lotus\notes\nNETBIOS.DLL] [N/A, N/A]
[C:\Program Files\lotus\notes\nstclientu.dll] [N/A, N/A]
[C:\Program Files\lotus\notes\nimuiu.dll] [N/A, N/A]
[C:\Program Files\lotus\notes\nimuires.dll] [, 3, 1, 0, 1]
[C:\Program Files\lotus\notes\nNTCP.DLL] [N/A, N/A]
[C:\Program Files\lotus\notes\nlsxbe.DLL] [N/A, N/A]
[C:\Program Files\lotus\notes\nDBNotes.DLL] [N/A, N/A]
[C:\Program Files\lotus\notes\naldaemn.DLL] [N/A, N/A]
[C:\Program Files\lotus\notes\ninfobox.dll] [Lotus Development Corporation, 1.0.0.0]
[PID: 936][C:\Program Files\lotus\notes\ntaskldr.EXE] [N/A, N/A]
[C:\Program Files\lotus\notes\nnotes.dll] [N/A, N/A]
[C:\Program Files\lotus\notes\nxmlpar.dll] [N/A, N/A]
[C:\Program Files\lotus\notes\nxmlcommon.dll] [N/A, N/A]
[C:\Program Files\lotus\notes\js32.dll] [N/A, N/A]
[C:\Program Files\lotus\notes\NLSCCSTR.DLL] [N/A, N/A]
[C:\Program Files\lotus\notes\ndgts.dll] [N/A, N/A]
[C:\Program Files\lotus\notes\NSTRINGS.DLL] [N/A, N/A]
[C:\Program Files\lotus\notes\nhkdaemn.DLL] [N/A, N/A]
[C:\Program Files\lotus\notes\nhldaemn.DLL] [N/A, N/A]
[C:\Program Files\lotus\notes\namhook.DLL] [N/A, N/A]
[C:\Program Files\lotus\notes\nTCP.DLL] [N/A, N/A]
[C:\Program Files\lotus\notes\nNETBIOS.DLL] [N/A, N/A]
[PID: 1360][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2800.1106]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.7.2006011200]
[C:\WINNT\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[PID: 476][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2800.1106]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.7.2006011200]
[C:\WINNT\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[PID: 1596][C:\Program Files\WinRAR\WinRAR.exe] [Alexander Roshal, 3.40]
[PID: 212][C:\DOCUME~1\dajun\LOCALS~1\Temp\Rar$EX00.734\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
192.168.1.18 ad_fileserver
192.168.1.8 filebackup
192.168.1.99 intranet
192.168.1.98 ishmail
192.168.5.95 arsvr
192.168.5.95 archive
192.168.6.35 server
192.168.1.66 newserver
192.168.5.16 IHS
192.168.1.3 SYMANTEC
192.168.1.55 Idxserver
192.168.1.11 cisco
192.168.1.41 Csportal
202.96.154.164 pop3.ishsz.com.cn
202.96.154.159 smtp.ishsz.com.cn
192.168.1.99 mail.ish.com.cn
==================================
API HOOK
N/A
==================================
[/CODE]