2006-08-15,19:09:27
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [Microsoft Corporation]
<MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background> [Microsoft Corporation]
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [Microsoft Corporation]
<MSNShell><D:\程序安装\MSNShell\BIN\MSNShell.exe autorun> []
<eMuleAutoStart><D:\程序安装\eMule\eMule.exe -AutoStart> []
<caishowmanage><C:\Program Files\CaiShow Tech\CaiShow\UpdateManager.EXE> []
<WDSHOOK><C:\WINDOWS\XXXStarter.exe> []
<msnnt><C:\WINDOWS\Updateb.exe> []
<Microsoft System Saver><mssave.exe> []
<><RoleId.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices]
<Microsoft System Saver><mssave.exe> []
<><RoleId.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<HPDJ Taskbar Utility><C:\WINDOWS\System32\spool\drivers\w32x86\hpztsb04.exe> [HP]
<ccApp><C:\Program Files\Common Files\Symantec Shared\ccApp.exe> [Symantec Corporation]
<ccRegVfy><C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe> [Symantec Corporation]
<SSC_UserPrompt><C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe> [Symantec Corporation]
<BigDogPath><C:\WINDOWS\VM_STI.EXE USB PC Camera 301P> []
<WinampAgent><D:\程序安装\Winamp\winampa.exe> []
<NMGameX_AutoRun><C:\WINDOWS\System32\Rundll32.exe nmgamex.dll,LiveProcess /aa> [NMGameX]
<REGSHAVE><C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN> [FUJI PHOTO FILM CO., LTD.]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<Symantec NetDriver Monitor><C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer> [Symantec Corporation]
<CnsMHlp.exe><C:\WINDOWS\Downloaded Program files\CnsMHlp.exe> [3721.com]
<CnsMin><Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32> [北京三七二一科技有限公司]
<MSService_v1.0><C:\WINDOWS\system\realsched.exe> []
<WDSHOOK><C:\WINNT\XXXStarter.exe> []
<CdnCtr><C:\Program Files\CNNIC\Cdn\cdnup.exe> []
<SoundMam><C:\WINDOWS\System32\SVOHOST.exe> []
<Microsoft System Saver><mssave.exe> []
<><RoleId.exe> []
<Systems32><C:\WINDOWS\System32\Server.exe> []
<helper.dll><C:\WINDOWS\system32\rundll32.exe C:\PROGRA~121\helper.dll,Rundll32> []
<ourmini><C:\WINDOWS\System\svchost.exe> [MicroSoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<Microsoft System Saver><mssave.exe> []
<><RoleId.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<DTService><rundll32.exe C:\WINDOWS\system32\dtservic.dll,Load> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\System32\Userinit.exe> [Microsoft Corporation]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINDOWS\DOWNLO~1\CnsHook.dll> [北京三七二一科技有限公司]
<{288BD9BD-F0DC-46B1-81B5-2B61DF8077CE}><C:\WINDOWS\System32.dll> []
<{9DE65ACD-2184-4BA2-99AC-F04B1EE03C37}><C:\WINDOWS\System32\Directxms2.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<Vision><C:\PROGRA~1\MMSASS~1\Mmsass~1.dll> []
<stdup><C:\WINDOWS\SYSTEM32\stdup.dll> []
<DelayRun><C:\WINDOWS\system3ddb60.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
<WinlogonNotify: AtiExtEvent><Ati2evxx.dll> []
==================================
启动文件夹
[Microsoft Office]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk><N>
[Adobe Reader Speed Launch]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk><N>
[IE-Bar]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\IE-Bar.lnk><N>
[腾讯QQ]
<C:\Documents and Settings\a\「开始」菜单\程序\启动\腾讯QQ.lnk><N>
==================================
服务
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\System32\Ati2evxx.exe><N/A>
[ATI Smart / ATI Smart]
<C:\WINDOWS\system32\ati2sgag.exe><>
[Symantec Event Manager / ccEvtMgr]
<C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe><Symantec Corporation>
[Symantec Password Validation Service / ccPwdSvc]
<C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe><Symantec Corporation>
[Norton AntiVirus 自动防护服务 / navapsvc]
<C:\Program Files\Norton AntiVirus\navapsvc.exe><Symantec Corporation>
[PACSPTISVR / PACSPTISVR]
<C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe><Sony Corporation>
[ScriptBlocking Service / SBService]
<C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe><Symantec Corporation>
[Symantec Network Drivers Service / SNDSrvc]
<"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Sony SPTI Service / SPTISRV]
<C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe><Sony Corporation>
[SymWMI Service / SymWSC]
<C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe><Symantec Corporation>
[UpdateService / UpdateService]
<C:\WINDOWS\System32\UpdateService.exe><N/A>
[wint / wint]
<C:\WINDOWS\System32\RunDLL32.exe "C:\WINDOWS\System32\wint\wint.dll",Run -r><N/A>
==================================
浏览器加载项
[FltSetUp Class]
{1D49D58D-5C84-4B50-8359-D9809BEB2B32} <C:\Program Files\Internet Explorer\Connection Wizard\icwuti1.dll, Microsoft Corporation>
[BrbIvrig Class]
{5462B546-2E91-A6A2-C881-07A4654C50DC} <C:\WINDOWS\DOWNLO~1\bvajsty.dll, ggoefsoft>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <D:\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[ActiveBHO Class]
{63C55A7F-6E29-8D4F-5C76-4F850F28D13A} <C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll, >
[BHOImp Class]
{70AFF2CB-9DA2-499C-8D15-900729FCE83D} <C:\WINDOWS\system32\YHBO.dll, YHBO>
[WinSC Class]
{9ACEEE31-1440-471B-AA46-72B061FE7D61} <C:\WINDOWS\system32\WinSC32.dll, N/A>
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\PROGRA~1\KuGoo2\KUGOO3~1.OCX, N/A>
[Flash 8 ocx ]
{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} <C:\WINDOWS\System32\flash8.dll, N/A>
[CNavExtBho Class]
{BDF3E430-B101-42AD-A544-FADC6B084872} <C:\Program Files\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[IEHlprObj Class]
{CE7C3CF0-4B15-11D1-ABED-709549C10000} <C:\WINDOWS\System32\basela.dll, >
[CnsHook Class]
{D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\DOWNLO~1\CnsHook.dll, 北京三七二一科技有限公司>
[IEHlprObj Class]
{D424FE4E-CAF9-4fdd-BC5F-E6E6B91D53BF} <C:\Progra~1\NetMeeting\conf.dll, Microsoft Corporation>
[BHelper Class]
{F2E37336-BFDB-409B-8D0E-6F013C438B20} <C:\WINDOWS3odb60.dll, N/A>
[WMHlprObj Class]
{F5824EFB-728A-4726-A5A5-85A68B20EDC3} <C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll, CNNIC>
[Yahoo 1G电邮]
{507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A>
[寻宝乐趣多]
{59BC54A2-56B3-44a0-93E5-432D58746E26} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao, N/A>
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[雅虎助手]
{5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
[比较购物搜索(&C)]
{A36ABCF0-1C8F-46e7-A67C-0489DC21B9CC} <C:\WINDOWS\YayaBands.dll, Eastday Corporation>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\QQ\QQ.EXE, TENCENT>
[FlashGet]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <D:\程序安装\FLASHGET\flashget.exe, Amaze Soft>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[情景聊天]
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg, N/A>
[]
{ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
[新浪点点通]
{F60C7D81-8471-4D40-AAFE-56D318F34C2D} <D:\程序安装\UC\UCddt\DDTONG~1.DLL, 北京新浪信息技术有限公司>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\MSMSGS.EXE, Microsoft Corporation>
[]
{FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
[]
{974AD624-EA50-4831-A6C0-3040F6665396} <D:\程序安装\UC\UCddt\rssband.dll, 北京新浪信息技术有限公司>
[新浪点点通阅读器]
{F0646DC8-58CD-4C64-8F6B-525043914685} <D:\程序安装\UC\UCddt\rssband.dll, 北京新浪信息技术有限公司>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[Norton AntiVirus]
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} <C:\Program Files\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <D:\程绦序虬安沧装癨\FLASHGET\fgiebar.dll, N/A>
[新浪点点通]
{F60C7D81-8471-4D40-AAFE-56D318F34C2D} <D:\程序安装\UC\UCddt\DDTONG~1.DLL, 北京新浪信息技术有限公司>
[天下搜索]
{56A7DC70-E102-4408-A34A-AE06FEF01586} <C:\WINDOWS\Downloaded Program Files\iesmall24.dll, >
[系统标准按钮(&E)]
{6B2455FD-3669-4555-8DF8-69FD5BC846F8} <C:\WINDOWS\system32\SystemToolbar.dll, N/A>
[Checkers Class]
{00B71CFB-6864-4346-A978-C0A14556272C} <C:\WINDOWS\Downloaded Program Files\msgrchkr.dll, Microsoft Corporation>
[MessengerStatsClient Class]
{14B87622-7E19-4EA8-93B3-97215F77A6BC} <C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll, Microsoft Corporation>
[Shockwave ActiveX Control]
{166B1BCA-3F9C-11CF-8075-444553540000} <C:\WINDOWS\System32\macromed\Shockwave 10\Download.dll, Adobe Systems, Inc.>
[MSN Photo Upload Tool]
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[金山毒霸在线产品升级]
{52DF16E3-6C4F-4B22-8BAF-09263E463B48} <C:\WINDOWS\System32\kingsoft\KOS\KOSInit.ocx, N/A>
[天下搜索]
{56A7DC70-E102-4408-A34A-AE06FEF01586} <C:\WINDOWS\Downloaded Program Files\iesmall24.dll, >
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\System32\wuweb.dll, Microsoft Corporation>
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, >
[MessengerStatsClient Class]
{8E0D4DE5-3180-4024-A327-4DFAD1796A8D} <C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll, Microsoft Corporation>
[PhotoUploadCtrl Control]
{A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} <D:\QQ\QZone\PHOTOU~1.OCX, tencent>
[MsnMessengerSetupDownloadControl Class]
{B38870E4-7ECB-40DA-8C6A-595F0A5519FF} <C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx, Microsoft Corporation>
[ZoneIntro Class]
{B8BE5E93-A60C-4D26-A2DC-220313175592} <C:\WINDOWS\Downloaded Program Files\ZIntro.ocx, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[Ravonline]
{DA984A6D-508E-11D6-AA49-0050FF3C628D} <C:\WINDOWS\Downloaded Program Files\RsOnline.dll, Beijing Rising Tech. Co., Ltd.>
[CPasswordEditCtrl Object]
{E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\System32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[Solitaire Showdown Class]
{F6BF0D00-0B2A-4A75-BF7B-F385591623AF} <C:\WINDOWS\Downloaded Program Files\solitaireshowdown.dll, Microsoft Corporation>
[ >> 彩信发送 <<]
<res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm, N/A>
[ 发送到手机<彩信助手>]
<C:\WINDOWS\System32888.htm, N/A>
[>>彩信发送<<]
<res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm, N/A>
[上传到QQ网络硬盘]
<D:\QQ\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
<D:\PROGRA~1\KUGOO2\KuGoo3DownX.htm, N/A>
[使用彩信超级自写发送到手机]
<http://mms.sina.com.cn/mmsnews.html, N/A>
[使用新浪下载助手下载]
<D:\程序安装\UC\UCddt\sinadl.htm, N/A>
[使用网际快车下载]
<D:\程序安装\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<D:\程序安装\FlashGet\jc_all.htm, N/A>
[发送图片到手机(&M)]
<http://sms.sina.com.cn/diy/send.html?from=467, N/A>
[导出到 Microsoft Excel(&x)]
<res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000, N/A>
[收藏此页到ViVi]
<http://vivi.sina.com.cn/collect/click.php?agent=ddt, N/A>
[收藏此页到新浪ViVi]
<http://vivi.sina.com.cn/collect/click.php?agent=ddt, N/A>
[新浪搜索]
<http://cha.sina.com.cn/ddt.html, N/A>
[添加到QQ自定义面板]
<D:\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\QQ\AddEmotion.htm, N/A>
[添加到雅虎订阅(&Y)]
<res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT, N/A>
[用QQ彩信发送该图片]
<D:\QQ\SendMMS.htm, N/A>
[用炫彩图铃发送该图片]
<C:\Program Files\CaiShow Tech\CaiShow\SendMMS.htm, N/A>
[百度--MP3搜索]
<RES://C:\Progra~1\Baidu\bar\baidubar.dll/BAIDUMP3.HTM, N/A>
[百度--图片搜索]
<RES://C:\Progra~1\Baidu\bar\baidubar.dll/BAIDUIMG.HTM, N/A>
[百度--新闻搜索]
<RES://C:\Progra~1\Baidu\bar\baidubar.dll/BAIDUNEWS.HTM, N/A>
[百度--歌词搜索]
<RES://C:\Progra~1\Baidu\bar\baidubar.dll/BAIDULYRIC.HTM, N/A>
[百度--网页搜索]
<RES://C:\Progra~1\Baidu\bar\baidubar.dll/BAIDUSEARCH.HTM, N/A>
[百度--词典搜索]
<RES://C:\Progra~1\Baidu\bar\baidubar.dll/BAIDU_DIC.HTM, N/A>
[百度--贴吧搜索]
<RES://C:\Progra~1\Baidu\bar\baidubar.dll/BAIDUPOST.HTM, N/A>
[访问通用网址]
<C:\Program Files\CNNIC\Cdn\cnnic.htm, N/A>
[雅虎搜索]
<res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246, N/A>
==================================
正在运行的进程
[PID: 440][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 488][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 512][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.1557 (xpsp2_gdr.040517-1325)>
[C:\WINDOWS\system32\Ati2evxx.dll] <N/A><N/A>
[PID: 556][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\system32\UpdateModule.dll] <N/A><N/A>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[PID: 568][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 712][C:\WINDOWS\System32\Ati2evxx.exe] <N/A><N/A>
[PID: 760][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 812][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 980][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1020][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1152][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.1699 (xpsp2.050610-1533)>
[C:\WINDOWS\system32\hpzlnt04.dll] <HP><2,80,0,0>
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll] <Windows (R) 2000 DDK provider><5.00.2195.1620>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 1852][C:\WINDOWS\system32\Ati2evxx.exe] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[PID: 1904][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\WINDOWS\System32\wint\wint.dll] <N/A><N/A>
[C:\WINDOWS\system3ddb60.dll] <N/A><N/A>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\WINDOWS\System32\winscok.dll] <N/A><N/A>
[C:\PROGRA~121\alrex.dll] <><1, 0, 1, 1001>
[C:\WINDOWS\XXXHook.dll] <><1, 0, 0, 1>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><2, 0, 0, 2>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 4, 0, 1>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll] <N/A><1, 0, 1, 1014>
[D:\QQ\qdshm.dll] <><1, 0, 101, 20>
[D:\程序安装\rarext.dll] <N/A><N/A>
[C:\Program Files\Norton AntiVirus\NavShExt.dll] <Symantec Corporation><9.00.02>
[C:\WINDOWS\System32\ccTrust.dll] <Symantec Corporation><1.00.22>
[C:\WINDOWS\DOWNLO~1\CnsHook.dll] <北京三七二一科技有限公司><1, 0, 2, 7>
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 6>
[C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll] <><1, 0, 0, 1>
[C:\WINDOWS\System32\flash8.dll] <N/A><N/A>
[C:\WINDOWS\System32\basela.dll] <><1, 0, 0, 1>
[PID: 1228][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1328][C:\Program Files\Norton AntiVirus\navapsvc.exe] <Symantec Corporation><9.00.1106>
[C:\Program Files\Norton AntiVirus\SavRT32.dll] <Symantec Corporation><9.0.1.36>
[PID: 1620][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1680][C:\WINDOWS\System32\UpdateService.exe] <N/A><N/A>
[PID: 1716][C:\WINDOWS\System32\RunDLL32.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\System32\wint\wint.dll] <N/A><N/A>
[PID: 904][C:\WINDOWS\System32\winmer.exe] <N/A><N/A>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[PID: 992][C:\WINDOWS\System32\spool\drivers\w32x86\hpztsb04.exe] <HP><2,80,0,0>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\WINDOWS\System32\spool\drivers\w32x86\FZFR3204.DLL] <HP><2,34,0,0>
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 6>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[PID: 1280][C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe] <Symantec Corporation><2005.1.2.20>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[PID: 1408][C:\WINDOWS\VM_STI.EXE] <VM.><4.2.610.4>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[PID: 1428][D:\程序安装\Winamp\winampa.exe] <N/A><N/A>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 6>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[PID: 1500][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3208>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 6>
[C:\WINDOWS\System32\winscok.dll] <N/A><N/A>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[PID: 1512][C:\WINDOWS\system\realsched.exe] <N/A><N/A>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 6>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[PID: 1576][C:\Program Files\CNNIC\Cdn\cdnup.exe] <><2, 4, 0, 4>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 6>
[C:\WINDOWS\System32\winscok.dll] <N/A><N/A>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 4, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><2, 0, 0, 2>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdntdns.dll] <CNNIC><2, 2, 0, 3>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[PID: 1648][C:\WINDOWS\System32\SVOHOST.exe] <N/A><N/A>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\WINDOWS\System32\winscok.dll] <N/A><N/A>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[PID: 1796][C:\WINDOWS\System32\mssave.exe] <N/A><N/A>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[PID: 1812][C:\WINDOWS\System32\RoleId.exe] <N/A><N/A>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[PID: 1820][C:\WINDOWS\System32\Server.exe] <N/A><N/A>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[PID: 1888][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\WINDOWS\System32\winscok.dll] <N/A><N/A>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[PID: 2056][C:\Program Files\Messenger\msmsgs.exe] <Microsoft Corporation><4.7.2010>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\WINDOWS\System32\winscok.dll] <N/A><N/A>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 4, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><2, 0, 0, 2>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 1>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[PID: 2252][C:\Program Files\MSN Messenger\MsnMsgr.Exe] <Microsoft Corporation><7.0.0816>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\WINDOWS\System32\winscok.dll] <N/A><N/A>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><2, 0, 0, 2>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 4, 0, 1>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 6>
[PID: 2772][C:\WINDOWS\Updateb.exe] <><1, 0, 0, 14>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[PID: 1792][C:\WINDOWS\System32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[PID: 3760][C:\WINDOWS\System32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><2, 0, 0, 2>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 4, 0, 1>
[C:\WINDOWS\System32\winscok.dll] <N/A><N/A>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 972][C:\WINDOWS\System32\Rundll32.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 6>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><2, 0, 0, 2>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 4, 0, 1>
[C:\WINDOWS\System32\winscok.dll] <N/A><N/A>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\WINDOWS\DOWNLO~1\CnsMinIO.dll] <北京三七二一科技有限公司><1, 0, 3, 6>
[C:\WINDOWS\DOWNLO~1\cnsio.dll] <北京三七二一科技有限公司><1, 0, 2, 7>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[PID: 2780][C:\WINDOWS\System32\rundll32.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\DOCUME~1\a\TEMPLA~1\fe32b72.dll] <千橡互联><3, 0, 1, 0>
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 6>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><2, 0, 0, 2>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 4, 0, 1>
[C:\WINDOWS\System32\winscok.dll] <N/A><N/A>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\DOCUME~1\a\TEMPLA~1\fe32b72.dll] <千橡互联><3, 0, 1, 0>
[C:\DOCUME~1\a\TEMPLA~1\fe32b72.dll] <千橡互联><3, 0, 1, 0>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[PID: 2688][D:\程序安装\WinRAR.exe] <N/A><N/A>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 6>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><2, 0, 0, 2>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 4, 0, 1>
[C:\WINDOWS\System32\winscok.dll] <N/A><N/A>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
[PID: 2280][C:\DOCUME~1\a\LOCALS~1\Temp\Rar$EX00.182\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\WINDOWS\system32\KB896425.log] <N/A><N/A>
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 6>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><2, 0, 0, 2>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 4, 0, 1>
[C:\WINDOWS\System32\winscok.dll] <N/A><N/A>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\WINDOWS\System32\Directxms2.dll] <N/A><N/A>
[C:\WINDOWS\System32.dll] <N/A><N/A>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
