[CODE]
2007-03-27,23:13:31
System Repair Engineer 2.4.12.806 Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - ¹ÜÀíȨÏÞÓû§ - ÍêÕû¹¦ÄÜ
ÒÔÏÂÄÚÈݱ»Ñ¡ÖУº ËùÓÐµÄÆô¶¯ÏîÄ¿£¨°üÀ¨×¢²á±í¡¢Æô¶¯Îļþ¼Ð¡¢·þÎñµÈ£© ä¯ÀÀÆ÷¼ÓÔØÏî ÕýÔÚÔËÐеĽø³Ì£¨°üÀ¨½ø³ÌÄ£¿éÐÅÏ¢£© Îļþ¹ØÁª Winsock ÌṩÕß Autorun.inf HOSTS Îļþ
Æô¶¯ÏîÄ¿ ×¢²á±í [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <load><> [N/A] <run><> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <!AVG Anti-Spyware><"F:\EWido\AVG\AVG Anti-Spyware 7.5\avgas.exe" /minimized> [Anti-Malware Development a.s.] <cmdbcs><C:\WINDOWS\cmdbcs.exe> [] <upxdnd><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\update3.exe> [N/A] <mppds><C:\WINDOWS\mppds.exe> [] <kis><"F:\¿¨°Í\kis600307.sch\avp.exe"> [Kaspersky Lab] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] <twin><C:\WINDOWS\system32\twunk32.exe> [Microsoft Corporation] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] <shell><Explorer.exe> [(Verified)Microsoft Windows Publisher] <Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <AppInit_DLLs><608769M.BMP> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{54D9498B-CF93-414F-8984-8CE7FDE0D391}><F:\EWido\EWIDO3.5\shellhook.dll> [N/A] <{A6011F8F-A7F8-49AA-9ADA-49127D43138F}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.rxk> [] <{57B86673-276A-48B2-BAE7-C6DBB3020EB8}><F:\EWido\AVG\AVG Anti-Spyware 7.5\shellexecutehook.dll> [Anti-Malware Development a.s.] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon] <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll> [Kaspersky Lab] [HKEY_CURRENT_USER\Control Panel\Desktop] <SCRNSAVE.EXE><C:\DOCUME~1\ADMINI~1\×ÀÃæ\xdelbox1.2\XDELBO~1.SCR> [½£Ã˼¼ÊõÍŶÓ] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <!AVG Anti-Spyware><; "F:\EWido\AVG\AVG Anti-Spyware 7.5\avgas.exe" /minimized> [Anti-Malware Development a.s.] <!ewido><; "F:\ewido\ewido anti-spyware 4.0\ewido.exe" /minimized> [N/A] <compmgmt><; C:\WINDOWS\system32\compmgmt.exe> [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <ctfmon.exe><; C:\WINDOWS\system32\CTFMON.EXE> [(Verified)Microsoft Windows Publisher] <iz46z07lw><; C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\crasos.exe> [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <kernelmh><; C:\WINDOWS\Kernelmh.exe> [] <kis><; "F:\¿¨°Í\kis600307.sch\avp.exe"> [Kaspersky Lab] <mppds><; C:\WINDOWS\mppds.exe> [] <ntmsoprq><; C:\WINDOWS\system32\ntmsoprq.exe> [Microsoft Corporation] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <qt3ii85kvbfc><; C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Servere.exe> [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <scrnsave><; C:\WINDOWS\system32\prnmngr.exe> [Microsoft Corporation] <StormCodec_Helper><; "F:\±©·çÓ°Òô\Storm Codec\StormSet.exe" /S /opti> [] <upxdnd><; C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\update3.exe> [N/A] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <viq88><; C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rundl132.exe> [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <wsttrs><; C:\WINDOWS\wsttrs.exe> [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <yi4jgw1ff><; C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\iexpl0re.exe> []
================================== Æô¶¯Îļþ¼Ð [Ðǿռ«ËÙ] <C:\Documents and Settings\All Users\¡¸¿ªÊ¼¡¹²Ëµ¥\³ÌÐò\Æô¶¯\Ðǿռ«ËÙ.lnk --> C:\PROGRA~1\ChinaNet\VNETCL~1.EXE []><N>
================================== ·þÎñ [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start] <F:\EWido\AVG\AVG Anti-Spyware 7.5\guard.exe><Anti-Malware Development a.s.> [¿¨°Í˹»ù»¥ÁªÍø°²È«Ì××° 6.0 / AVP][Running/Auto Start] <F:\¿¨°Í\kis600307.sch\avp.exe -r><Kaspersky Lab> [ewido security suite guard / ewido security suite guard][Stopped/Auto Start] <F:\EWido\EWIDO3.5\ewidoguard.exe><N/A> [Human Interface Device Access / HidServ][Stopped/Disabled] <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A> [Remote Procedure Call System(RPCS) / RpcS][Running/Auto Start] <C:\WINDOWS\system32\RpcS.exe><Microsoft Corporation> [Windows SystemDown / WindowsDown][Stopped/Auto Start] <C:\WINDOWS\system32\servet.exe><N/A>
================================== Çý¶¯³ÌÐò [aeaudio / aeaudio][Running/Manual Start] <system32\drivers\aeaudio.sys><Andrea Electronics Corporation> [AliIde / AliIde][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aliide.sys><N/A> [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start] <\??\F:\EWido\AVG\AVG Anti-Spyware 7.5\guard.sys><N/A> [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start] <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.> [CmdIde / CmdIde][Running/Boot Start] <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.> [ewido security suite driver / ewido security suite driver][Stopped/System Start] <\??\F:\EWido\EWIDO3.5\guard.sys><N/A> [kl1 / kl1][Running/Boot Start] <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab> [klif / klif][Running/System Start] <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab> [MegaIDE / MegaIDE][Running/Boot Start] <\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.> [Netgroup Packet Filter / NPF][Stopped/Manual Start] <system32\drivers\npf.sys><Politecnico di Torino> [npkcrypt / npkcrypt][Running/Auto Start] <\??\D:\QQ\npkcrypt.sys><INCA Internet Co., Ltd.> [nv / nv][Running/Manual Start] <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.> [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start] <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation> [Secdrv / Secdrv][Stopped/Manual Start] <system32\DRIVERS\secdrv.sys><N/A> [smwdm / smwdm][Running/Manual Start] <system32\drivers\smwdm.sys><Analog Devices, Inc.> [TSP / TSP][Stopped/Manual Start] <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab> [ViaIde / ViaIde][Running/Boot Start] <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation> [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start] <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation> [VIMICRO USB PC Camera / ZSMC301b][Running/Manual Start] <System32\Drivers\usbVM31b.sys><VM>
================================== ä¯ÀÀÆ÷¼ÓÔØÏî [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD> [Æô¶¯Ñ¸À×5] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD> [FANSÒôÀÖ] {1934091F-CD97-51E1-B1D4-D23794813092} <http://music.fans.com.cn?1116, N/A> [FANS] {1934091F-CD97-51E1-B1D4-D96794013092} <http://bbs.fans.com.cn?1115, N/A> [Web·´²¡¶¾±£»¤] {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <F:\¿¨°Í\kis600307.sch\scieplugin.dll, Kaspersky Lab> [JUJUè] {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.jujumao.net, N/A> [QQ] {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\QQ\QQ.EXE, TENCENT> [Messenger] {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation> [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.> [HTML Document] {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A> [Thunder Browser Helper] {4E83D566-4697-4F7B-B1F0-A513B01DB89A} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD> [VnetCookie Class] {4E83D567-4697-4F7B-B1F0-A513B01DB89A} <, N/A> [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD> [RDS.DataSpace] {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation> [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.> [&ʹÓÃѸÀ×ÏÂÔØ] <C:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A> [&ʹÓÃѸÀ×ÏÂÔØÈ«²¿Á´½Ó] <C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A> [ÉÏ´«µ½QQÍøÂçÓ²ÅÌ] <D:\QQ\AddToNetDisk.htm, N/A> [ʹÓÃÍø¼Ê¿ì³µÏÂÔØ] <, N/A> [ʹÓÃÍø¼Ê¿ì³µÏÂÔØÈ«²¿Á´½Ó] <, N/A> [µ¼³öµ½ Microsoft Office Excel(&X)] <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A> [Ìí¼Óµ½QQ×Ô¶¨ÒåÃæ°å] <D:\QQ\AddPanel.htm, N/A> [Ìí¼Óµ½QQ±íÇé] <D:\QQ\AddEmotion.htm, N/A> [ÓÃQQ²ÊÐÅ·¢Ë͸ÃͼƬ] <D:\QQ\SendMMS.htm, N/A>
================================== ÕýÔÚÔËÐеĽø³Ì [PID: 504][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 572][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 596][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\608769M.BMP] [N/A, ] [C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 6.0.0.299] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 648][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\608769M.BMP] [N/A, ] [PID: 660][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\608769M.BMP] [N/A, ] [PID: 828][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\608769M.BMP] [N/A, ] [PID: 884][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\608769M.BMP] [N/A, ] [PID: 968][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\608769M.BMP] [N/A, ] [F:\¿¨°Í\kis600307.sch\adialhk.dll] [Kaspersky Lab, 6.0.0.299] [PID: 1032][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\608769M.BMP] [N/A, ] [PID: 1088][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\608769M.BMP] [N/A, ] [PID: 1416][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\608769M.BMP] [N/A, ] [C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.rxk] [N/A, ] [C:\WINDOWS\system32\mppds.dll] [N/A, ] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.dll] [N/A, ] [C:\WINDOWS\system32\cmdbcs.dll] [N/A, ] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [F:\¿¨°Í\kis600307.sch\shellex.dll] [Kaspersky Lab, 6.0.0.299] [F:\EWido\AVG\AVG Anti-Spyware 7.5\context.dll] [Anti-Malware Development a.s., 7, 5, 0, 49] [F:\EWido\AVG\AVG Anti-Spyware 7.5\shellexecutehook.dll] [Anti-Malware Development a.s., 7, 5, 0, 47] [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4] [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] [F:\¿¨°Í\kis600307.sch\adialhk.dll] [Kaspersky Lab, 6.0.0.299] [PID: 1716][F:\EWido\AVG\AVG Anti-Spyware 7.5\avgas.exe] [Anti-Malware Development a.s., 7, 5, 0, 50] [F:\EWido\AVG\AVG Anti-Spyware 7.5\engine.dll] [Anti-Malware Development a.s., 4, 2, 0, 15] [C:\WINDOWS\608769M.BMP] [N/A, ] [PID: 352][C:\Program Files\ChinaNet\VnetClient.exe] [, 2005, 11, 14, 1] [C:\Program Files\ChinaNet\Communicate.dll] [0, 2005, 3, 3, 1] [C:\Program Files\ChinaNet\DialModule.dll] [GDCN, 2006, 6, 26, 10] [C:\Program Files\ChinaNet\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0] [C:\WINDOWS\608769M.BMP] [N/A, ] [F:\¿¨°Í\kis600307.sch\adialhk.dll] [Kaspersky Lab, 6.0.0.299] [C:\PROGRA~1\ChinaNet\CLIENT~1.DLL] [, 2004, 2, 28, 1] [C:\PROGRA~1\ChinaNet\PLUGIN~1.OCX] [, 2005, 7, 27, 1] [C:\PROGRA~1\ChinaNet\sign.dll] [0, 2004, 12, 1, 1] [C:\PROGRA~1\ChinaNet\PostPlug.dll] [, 2004, 12, 16, 2] [C:\PROGRA~1\ChinaNet\ADVERT~1.OCX] [, 2005, 10, 13, 1] [C:\PROGRA~1\ChinaNet\Gif89a.dll] [, 2005, 6, 21, 1] [C:\PROGRA~1\ChinaNet\VnetBs.ocx] [, 2004, 11, 18, 1] [C:\PROGRA~1\ChinaNet\ACCOUN~2.DLL] [, 2005, 11, 14, 1] [C:\PROGRA~1\ChinaNet\AccountMgr.dll] [, 2005, 11, 14, 17] [C:\PROGRA~1\ChinaNet\VnetSkin.ocx] [GDDC, 2005, 11, 14, 1] [C:\PROGRA~1\ChinaNet\DialogStyle.dll] [, 1, 0, 0, 1] [C:\PROGRA~1\ChinaNet\Timer.ocx] [, 2005, 10, 9, 14] [C:\PROGRA~1\ChinaNet\PLUGIN~2.OCX] [, 2005, 2, 24, 1] [C:\PROGRA~1\ChinaNet\NEWMES~1.DLL] [, 2005, 8, 26, 1] [C:\PROGRA~1\ChinaNet\PassCtrl.dll] [, 1, 0, 0, 1] [C:\WINDOWS\system32\wpcap.dll] [Politecnico di Torino, 3, 0, 0, 18] [C:\WINDOWS\system32\pthreadVC.dll] [N/A, ] [C:\WINDOWS\system32\packet.dll] [Politecnico di Torino, 3, 0, 0, 18] [C:\PROGRA~1\ChinaNet\PlugPush.dll] [, 2004, 12, 21, 1] [C:\PROGRA~1\ChinaNet\ALLINT~1.DLL] [, 2004, 11, 23, 1] [C:\PROGRA~1\ChinaNet\VNetLog.ocx] [, 2005, 10, 9, 1] [C:\PROGRA~1\ChinaNet\StatNum.dll] [, 2004, 11, 18, 1] [C:\PROGRA~1\ChinaNet\VNETON~1.OCX] [, 2005, 3, 2, 1] [C:\PROGRA~1\ChinaNet\ALLFUN~1.DLL] [GDCN, 2005, 10, 9, 1] [C:\PROGRA~1\ChinaNet\VnetOptLog.dll] [, 2005, 9, 13, 9] [F:\¿¨°Í\kis600307.sch\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299] [F:\¿¨°Í\kis600307.sch\klscav.dll] [Kaspersky Lab, 6.0.0.299] [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [F:\¿¨°Í\kis600307.sch\prloader.dll] [Kaspersky Lab, 6.0.0.299] [C:\PROGRA~1\ChinaNet\DlgSkin.ocx] [, 2005, 11, 14, 1] [F:\¿¨°Í\kis600307.sch\pr_remote.dll] [Kaspersky Lab, 6.0.0.299] [F:\¿¨°Í\kis600307.sch\prkernel.ppl] [Kaspersky Lab, 6.0.0.304] [f:\¿¨°Í\kis600307.sch\params.ppl] [Kaspersky Lab, 6.0.0.299] [f:\¿¨°Í\kis600307.sch\pxstub.ppl] [Kaspersky Lab, 6.0.0.299] [f:\¿¨°Í\kis600307.sch\tempfile.ppl] [Kaspersky Lab, 6.0.0.299] [PID: 1384][C:\WINDOWS\regedit.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 3548][F:\åÛÓÎ\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 5, 9, 80] [F:\åÛÓÎ\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2] [C:\WINDOWS\system32\odbcbcp.dll] [Microsoft Corporation, 2000.085.1117.00 (xpsp_sp2_rtm.040803-2158)] [F:\¿¨°Í\kis600307.sch\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299] [F:\¿¨°Í\kis600307.sch\klscav.dll] [Kaspersky Lab, 6.0.0.299] [F:\¿¨°Í\kis600307.sch\pr_remote.dll] [Kaspersky Lab, 6.0.0.299] [F:\¿¨°Í\kis600307.sch\prloader.dll] [Kaspersky Lab, 6.0.0.299] [F:\¿¨°Í\kis600307.sch\prkernel.ppl] [Kaspersky Lab, 6.0.0.304] [f:\¿¨°Í\kis600307.sch\params.ppl] [Kaspersky Lab, 6.0.0.299] [f:\¿¨°Í\kis600307.sch\pxstub.ppl] [Kaspersky Lab, 6.0.0.299] [f:\¿¨°Í\kis600307.sch\tempfile.ppl] [Kaspersky Lab, 6.0.0.299] [F:\åÛÓÎ\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1] [F:\¿¨°Í\kis600307.sch\adialhk.dll] [Kaspersky Lab, 6.0.0.299] [f:\¿¨°Í\kis600307.sch\nfio.ppl] [Kaspersky Lab, 6.0.0.299] [f:\¿¨°Í\kis600307.sch\fsdrvplgn.ppl] [Kaspersky Lab, 6.0.0.299] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [PID: 3096][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\update7.exe] [N/A, ] [PID: 3904][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\update8.exe] [N/A, ] [PID: 3516][C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5, 5, 6, 274] [C:\Program Files\Thunder Network\Thunder\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 14] [C:\Program Files\Thunder Network\Thunder\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 2, 12, 2, 56] [C:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll] [Thunder Networking Technologies,LTD, 2, 12, 2, 56] [C:\Program Files\Thunder Network\Thunder\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 8] [C:\Program Files\Thunder Network\Thunder\Program\FloatBar.dll] [Giganology Inc., 1, 0, 0, 2] [C:\Program Files\Thunder Network\Thunder\Program\iTargetAD.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 16] [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [F:\¿¨°Í\kis600307.sch\adialhk.dll] [Kaspersky Lab, 6.0.0.299] [C:\Program Files\Thunder Network\Thunder\Components\DiagnoseHelper\DiagnoseHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 10] [C:\Program Files\Thunder Network\Thunder\Components\PortVerify\PortVerify.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1] [C:\Program Files\Thunder Network\Thunder\Components\ExplorerHelper\ExplorerHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1] [C:\Program Files\Thunder Network\Thunder\Components\DTAG\DTAG.dll] [Thunder Networking Technologies,LTD, 1, 1, 0, 2] [C:\Program Files\Thunder Network\Thunder\Components\DTAG\ExtractMediaTag.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1] [C:\Program Files\Thunder Network\Thunder\Program\LiveUpdate.dll] [, 1, 0, 1, 17] [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll] [¡¡, 1, 0, 0, 15] [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed08.dll] [¡¡, 3, 2, 0, 63] [C:\Program Files\Thunder Network\Thunder\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 15] [C:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 2, 1, 43] [C:\Program Files\Thunder Network\Thunder\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 7] [C:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 14] [C:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VPSHELL.dll] [, 1, 1, 0, 4] [C:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VideoPicture.dll] [XunLei, 1, 1, 0, 4] [C:\Program Files\Thunder Network\Thunder\Components\Tips\TipsClient.dll] [Thunder Networking Technologies,LTD, 2, 1, 1, 50] [F:\¿¨°Í\kis600307.sch\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299] [F:\¿¨°Í\kis600307.sch\klscav.dll] [Kaspersky Lab, 6.0.0.299] [F:\¿¨°Í\kis600307.sch\pr_remote.dll] [Kaspersky Lab, 6.0.0.299] [F:\¿¨°Í\kis600307.sch\prloader.dll] [Kaspersky Lab, 6.0.0.299] [F:\¿¨°Í\kis600307.sch\prkernel.ppl] [Kaspersky Lab, 6.0.0.304] [f:\¿¨°Í\kis600307.sch\params.ppl] [Kaspersky Lab, 6.0.0.299] [f:\¿¨°Í\kis600307.sch\pxstub.ppl] [Kaspersky Lab, 6.0.0.299] [f:\¿¨°Í\kis600307.sch\tempfile.ppl] [Kaspersky Lab, 6.0.0.299] [f:\¿¨°Í\kis600307.sch\nfio.ppl] [Kaspersky Lab, 6.0.0.299] [f:\¿¨°Í\kis600307.sch\fsdrvplgn.ppl] [Kaspersky Lab, 6.0.0.299] [C:\Program Files\Thunder Network\Thunder\Plugins\BhoAdv\bho_adv.dll] [ÉîÛÚÊÐѸÀ×ÍøÂç¼¼ÊõÓÐÏÞ¹«Ë¾, 1.0.1.0] [PID: 3804][C:\Program Files\WinRAR\WinRAR.exe] [N/A, ] [C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.3790.3646 built by: DNSRV(bld4act)] [PID: 1204][C:\Documents and Settings\Administrator\×ÀÃæ\SREng.EXE] [Smallfrogs Studio, 2.4.12.806] [F:\¿¨°Í\kis600307.sch\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
================================== Îļþ¹ØÁª .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}]
================================== Winsock ÌṩÕß N/A
================================== Autorun.inf N/A
================================== HOSTS Îļþ 127.0.0.1 localhost
================================== API HOOK RVA ´íÎó£º LoadLibraryA (ΣÏյȼ¶: Ò»°ã, ±»ÏÂÃæÄ£¿éËùHOOK: Dest Addr: 0xF6C44B25) RVA ´íÎó£º LoadLibraryExA (ΣÏյȼ¶: Ò»°ã, ±»ÏÂÃæÄ£¿éËùHOOK: Dest Addr: 0xF6C44D67) RVA ´íÎó£º LoadLibraryExW (ΣÏյȼ¶: Ò»°ã, ±»ÏÂÃæÄ£¿éËùHOOK: Dest Addr: 0xF6C44F0B) RVA ´íÎó£º LoadLibraryW (ΣÏյȼ¶: Ò»°ã, ±»ÏÂÃæÄ£¿éËùHOOK: Dest Addr: 0xF6C44C49) RVA ´íÎó£º GetProcAddress (ΣÏյȼ¶: ¸ß, ±»ÏÂÃæÄ£¿éËùHOOK: Dest Addr: 0xF6C44E8F)
================================== Òþ²Ø½ø³Ì N/A
==================================
[/CODE]
|