[E:\卡巴斯基\shadu\Kaspersky Anti-Virus Personal\ccclient.dll] [Kaspersky Lab, 5.0.388.1]
[E:\卡巴斯基\shadu\Kaspersky Anti-Virus Personal\klipc.dll] [Kaspersky Lab, 5.0.388.0]
[E:\卡巴斯基\shadu\Kaspersky Anti-Virus Personal\KLUtil.dll] [Kaspersky Lab, 5.0.388.1]
[E:\卡巴斯基\shadu\Kaspersky Anti-Virus Personal\rpt.dll] [Kaspersky Lab, 5.0.388.2]
[E:\卡巴斯基\shadu\Kaspersky Anti-Virus Personal\CCIFACE.dll] [Kaspersky Lab, 5.0.388.1]
[E:\卡巴斯基\shadu\Kaspersky Anti-Virus Personal\prloader.dll] [Kaspersky Lab, 5.0.388.0]
[E:\卡巴斯基\shadu\Kaspersky Anti-Virus Personal\prkernel.ppl] [Kaspersky Lab, 5.0.388.0]
[e:\卡巴斯基\shadu\kaspersky anti-virus personal\prstring.ppl] [Kaspersky Lab, 5.0.388.0]
[e:\卡巴斯基\shadu\kaspersky anti-virus personal\pr_srv.ppl] [Kaspersky Lab, 5.0.388.0]
[e:\卡巴斯基\shadu\kaspersky anti-virus personal\pr_clnt.ppl] [Kaspersky Lab, 5.0.388.0]
[e:\卡巴斯基\shadu\kaspersky anti-virus personal\tempfile.ppl] [Kaspersky Lab, 5.0.388.0]
[PID: 1692][E:\卡巴斯基\Kaspersky Anti-Hacker\KAVPF.exe] [Kaspersky Lab, 1.8.0.180]
[E:\卡巴斯基\Kaspersky Anti-Hacker\BCGCB59.dll] [BCGSoft Ltd, 5, 84, 0, 0]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 1, 9]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [Yahoo! China, 3, 0, 3, 1021]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll] [Yahoo! China, 3, 1, 3, 1019]
[E:\卡巴斯基\Kaspersky Anti-Hacker\perfiloc.dll] [Kaspersky Lab, 1.5.0.0]
[E:\卡巴斯基\Kaspersky Anti-Hacker\BCGCBRes.dll] [BCGSoft Ltd, 5, 84, 0, 0]
[E:\卡巴斯基\Kaspersky Anti-Hacker\wcswmi.dll] [Kaspersky Lab, 5.0.201.1]
[PID: 856][C:\Program Files\UPHClean\uphclean.exe] [Microsoft Corporation, 1.5.5.21]
[PID: 1996][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\aelupsvc32.dll] [, 4, 1, 0, 0]
[PID: 3076][C:\Program Files\QQ2005\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 1, 9]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [Yahoo! China, 3, 0, 3, 1021]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll] [Yahoo! China, 3, 1, 3, 1019]
[C:\Program Files\QQ2005\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 1492][C:\WINDOWS\QQ2005\QQ.exe] [TENCENT, 0, 0, 0, 0]
[C:\WINDOWS\QQ2005\QQBaseClassInDll.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\QQ2005\QQHelperDll.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\QQ2005\BasicCtrlDll.dll] [Tencent, 5, 0, 200, 160]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 1, 9]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [Yahoo! China, 3, 0, 3, 1021]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll] [Yahoo! China, 3, 1, 3, 1019]
[C:\WINDOWS\QQ2005\QQAPI.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2005\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[C:\WINDOWS\QQ2005\LoginCtrl.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\QQ2005\npkcntc.dll] [INCA Internet Co., Ltd., 2006, 3, 2, 1]
[C:\WINDOWS\QQ2005\npkpdb.dll] [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[C:\WINDOWS\QQ2005\QQRes.dll] [tencent, 1, 0, 0, 1]
[C:\WINDOWS\QQ2005\QQMainFrame.dll] [N/A, N/A]
[C:\WINDOWS\QQ2005\CQQApplication.dll] [N/A, N/A]
[C:\WINDOWS\system32\w2pxdrv.dll] [Proxy Labs, 3, 0, 0, 3]
[C:\WINDOWS\system32\aelupsvc32.dll] [, 4, 1, 0, 0]
[C:\WINDOWS\QQ2005\NewSkin.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\QQ2005\HostingMgr.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\QQ2005\CameraDll.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\QQ2005\MailSummary.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\QQ2005\QQSpace.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\WINDOWS\QQ2005\QQGroupMng.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\QQ2005\GroupLive.dll] [N/A, N/A]
[C:\WINDOWS\QQ2005\QQSysMsgMng.dll] [N/A, N/A]
[C:\WINDOWS\QQ2005\UserDefinedHead.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\QQ2005\QQPlugin.dll] [N/A, N/A]
[C:\WINDOWS\QQ2005\QQConfigPlugin.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\QQ2005\QRingMng.dll] [N/A, N/A]
[C:\WINDOWS\QQ2005\PhoneAPI.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\QQ2005\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[C:\WINDOWS\QQ2005\QQAvatar.dll] [N/A, N/A]
[C:\WINDOWS\QQ2005\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[C:\WINDOWS\QQ2005\LongConnection.dll] [tencent, 5, 0, 200, 160]
[C:\WINDOWS\QQ2005\QQPet.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\QQ2005\BQQApplication.dll] [N/A, N/A]
[C:\WINDOWS\QQ2005\QQAllInOne.dll] [N/A, N/A]
[C:\WINDOWS\QQ2005\SCCore.dll] [N/A, N/A]
[C:\WINDOWS\QQ2005\QQCustomFace.dll] [N/A, N/A]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[C:\WINDOWS\QQ2005\QQSceneMng.dll] [N/A, N/A]
[C:\WINDOWS\QQ2005\CommercesMng.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\QQ2005\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
[C:\WINDOWS\QQ2005\QQUdpGetFileLib.dll] [tencent, 0, 2, 2, 3]
[C:\WINDOWS\QQ2005\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 200]
[C:\WINDOWS\QQ2005\QQMagicFace.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\QQ2005\ImageOle.dll] [TODO: <Company name>, 1.0.0.1]
[C:\WINDOWS\QQ2005\QQFileTransfer.dll] [Tencent, 5, 0, 202, 180]
[PID: 3608][C:\WINDOWS\QQ2005\366289316\MyRecvFiles\sreng\sreng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 1, 9]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [Yahoo! China, 3, 0, 3, 1021]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll] [Yahoo! China, 3, 1, 3, 1019]
[C:\WINDOWS\system32\w2pxdrv.dll] [Proxy Labs, 3, 0, 0, 3]
[C:\WINDOWS\system32\aelupsvc32.dll] [, 4, 1, 0, 0]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MSTCPChain Provider
C:\WINDOWS\system32\aelupsvc32.dll(, MFClDLL)
PROXYCAP MSAFD Tcpip [TCP/IP]
w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP MSAFD Tcpip [UDP/IP]
w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP MSAFD Tcpip [RAW/IP]
w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP RSVP UDP Service Provider
w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP RSVP TCP Service Provider
w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP LSP
w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
MSTCP Provider
C:\WINDOWS\system32\aelupsvc32.dll(, MFClDLL)
==================================
Autorun.inf
[D:\]
[AutoRun]
open=sxs.exe
shellexecute=sxs.exe
shell\Auto\command=sxs.exe
[E:\]
[AutoRun]
open=sxs.exe
shellexecute=sxs.exe
shell\Auto\command=sxs.exe
[F:\]
[AutoRun]
open=sxs.exe
shellexecute=sxs.exe
shell\Auto\command=sxs.exe
==================================
HOSTS 文件
127.0.0.1 localhost
==================================