==================================
正在运行的进程
[PID: 652 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 764 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 852 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 960 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\AppPatch\AcAdProc.dll] [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[PID: 972 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1164 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1244 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1356 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1448 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1548 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1808 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 180 / Chenshi][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\me95sqi3.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.10.9147]
[C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.10.9147]
[C:\WINDOWS\system32\nvapi.dll] [N/A, ]
[C:\WINDOWS\system32\nvshell.dll] [, ]
[C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[PID: 712 / SYSTEM][C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\OPENDS60.DLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\UMS.DLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\SQLSORT.DLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\Resources\2052\sqlevn70.RLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\SSNETLIB.dll] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\SSNMPN70.dll] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\SSmsLPCn.dll] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Common Files\System\Ole DB\sqloledb.dll] [Microsoft Corporation, 2000.085.1117.00 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\xpsqlbot.dll] [Microsoft Corporation, 2000.080.0194.00]
[PID: 904 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.9147]
[C:\WINDOWS\system32\nvapi.dll] [N/A, ]
[PID: 928 / SYSTEM][C:\WINDOWS\system32\PnkBstrA.exe] [N/A, ]
[PID: 1868 / SYSTEM][C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlagent.exe] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\SQLRESLD.dll] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\SQLSVC.dll] [Microsoft Corporation, 2000.080.0194.00]
[C:\WINDOWS\system32\odbcbcp.dll] [Microsoft Corporation, 2000.085.1117.00 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\W95SCM.dll] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\SEMMAP.dll] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\Resources\2052\SQLSVC.RLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\Resources\2052\SEMMAP.RLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\Resources\2052\sqlagent.RLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\SQLAGENT.DLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Microsoft SQL Server\MSSQL\BINN\SQLCMDSS.DLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Microsoft SQL Server\MSSQL\BINN\Resources\2052\SQLCMDSS.RLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Microsoft SQL Server\MSSQL\BINN\SQLREPSS.DLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Microsoft SQL Server\MSSQL\BINN\Resources\2052\SQLREPSS.RLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Microsoft SQL Server\MSSQL\BINN\SQLATXSS.DLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Microsoft SQL Server\MSSQL\BINN\Resources\2052\SQLATXSS.RLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Microsoft SQL Server\80\Tools\BINN\AXSCPHST.DLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Microsoft SQL Server\80\Tools\BINN\Resources\2052\AXSCPHST.RLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\WINDOWS\system32\SQLSRV32.dll] [Microsoft Corporation, 2000.085.1117.00 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\sqlsrv32.rll] [Microsoft Corporation, 2000.085.1117.00 built by: (_sqlbld)]
[C:\WINDOWS\system32\DBmsLPCn.dll] [Microsoft Corporation, 2000.080.0194.00]
[PID: 2840 / Chenshi][C:\Program Files\Maxthon2\Maxthon.exe] [Maxthon International ltd., 2, 0, 4, 5799]
[C:\Program Files\Maxthon2\MxExt.dll] [N/A, ]
[C:\Program Files\Maxthon2\mxpp.dll] [Maxthon, 1, 0, 0, 61]
[C:\Program Files\Maxthon2\MxSk.dll] [Maxthon, 1, 0, 0, 339]
[C:\Program Files\Maxthon2\MxProxy2.dll] [, 1, 0, 0, 3564]
[C:\Program Files\Maxthon2\IMxWebBoost.dll] [Maxthon, 1, 0, 0, 1]
[C:\Program Files\Maxthon2\mxdb.dll] [Max, 1, 0, 0, 1]
[C:\Program Files\Maxthon2\mxsafe.dll] [Maxthon, 1, 0, 0, 610]
[C:\Program Files\Maxthon2\MxFav.dll] [Maxthon, 1, 0, 0, 220]
[C:\Program Files\Maxthon2\maxzlib.dll] [, 1.2.3]
[C:\Program Files\Maxthon2\mxtool.dll] [, 1, 0, 0, 1]
[C:\Program Files\Maxthon2\mxfeedU.dll] [, 1, 0, 45, 82]
[C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\Macromed\Flash\FlDbg9c.ocx] [Adobe Systems, Inc., 9,0,45,0]
[C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 1.1.4322.573]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorie.dll] [Microsoft Corporation, 1.1.4322.573]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorld.dll] [Microsoft Corporation, 1.1.4322.573]
[E:\工具\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 3, 11]
[E:\工具\Thunder\ComDlls\ThunderAgent_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 3, 20]
[PID: 2152 / Chenshi][E:\工具\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[E:\工具\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 www.krvkr.com
127.0.0.1 www.scad.cn
127.0.0.1 www.ironmail.cn
127.0.0.1 www.ok458888.com
127.0.0.1 www.gd001.net
127.0.0.1 www.beecool.net
127.0.0.1 www.ok458888.com
127.0.0.1 www.scad.cn
127.0.0.1 www.iloveck.com
127.0.0.1 www.wmsjsf.com
127.0.0.1 www.wangzheqiaodan.com
127.0.0.1 www.v0day.com
127.0.0.1 www.i5460.net
127.0.0.1 www.xxx.com
127.0.0.1 www.hackeroo.com
127.0.0.1 www.18dmm.com
127.0.0.1 www.xxx.com
127.0.0.1 5y5.us
127.0.0.1 16a.us
127.0.0.1 35561.com
==================================
进程特权扫描
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================