发新话题
打印

[求助] 疑似感染强劲病毒,请帮助分析

疑似感染强劲病毒,请帮助分析

我的电脑在使用过别人的U盘后发现异常。表现为进入XP后系统超级缓慢,10分钟后基本仍无反应,打开“我的电脑”狂慢,数分钟无法打开。诺顿被禁用。网卡属性无法打开,无法DHCP获得地址,设置为固定IP后可上网,但是连ping都不正常,无法ping通局域网计算机。
安全模式查杀,无病毒。
使用金山毒霸在线查毒,无病毒
使用AVG anti-spyware查杀,有几个小流氓软件,已清除。故障仍存在。
看来只好重装,但是连病毒是谁都不知道,真TM郁闷。

TOP

请用 sreng2点这下载sreng2 扫描一个log贴上来。

  • a 解压缩sreng2.zip
  • b 双击SREng.exe运行
  • c 智能扫描--扫描--保存报告
  • d 把日志SREngLOG.log中的报告完整(Ctrl+a)[复制=>(Ctrl+c)] [粘贴=>(Ctrl+v)]上来,不要修改



友情提示:

  • 如果发现SREng.exe运行无反应或者不能运行或者扫描出错,你可以将SREng.exe重命名为SREng.com(SREng.scr\SREng.bat\SREng.pif)或者abc.exe运行.

  • 如果出现警告用户系统里面存在的安全隐患,请先阅读关于System Repair Engineer API HOOK 检测重要说明
    (点这查看)



  • 扫描前关闭所有手工打开的软件和窗口,扫描后将日志发上来.但请不要用附件形式贴.

  • 注意在没有进一步提示前,勿要胡乱修复,否则系统可能变的情况更糟.

  • 常见的SREng操作(点这查看)

         

    永远的hzqedison,永远的病毒人生
    如果问题已经解决,请自行修改标题为[已解决]标签.谢谢合作!
    病毒上报hzqedison@qq.com 请自行将文件压缩加密 密码为virus
    帮人不是图回报,而是希望受助者能和我一样去帮助其他有需要的人!
    海色の月空指针接过病毒求援的接力棒,担子很重!!

TOP

大侠请看
复制内容到剪贴板
代码:
2007-06-10,09:59:40

System Repair Engineer 2.4.12.806
Smallfrogs ([url]http://www.KZTechs.com[/url])

Windows XP Professional Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed

Follow item(s) have been choosed:
    All Boot Items (Including Registry, Startup Folders, Services and so on)
    Browser Add-ons
    Runing Processes (Including process model information)
    File Associations
    Winsock Provider
    Autorun.Inf
    HOSTS File


Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <MSCalsClocks><C:\Program Files\Microsoft Chinese Date & Time\ICalClk.exe>  [Microsoft Corporation]
    <H/PC Connection Agent><"C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE">  [Microsoft Corporation]
    <pdfSaver3><"C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe">  [Tracker Software Products Ltd.]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
    <WMPNSCFG><C:\Program Files\Windows Media Player\WMPNSCFG.exe>  [(Verified)Microsoft Windows Component Publisher]
    <SpyEmergency><"D:\0\Spy Emergency2006\Spy Emergency2006\SpyEmergency.exe">  [NETGATE]
    <Yahoo! Pager><"D:\Messenger\YahooMessenger.exe" -quiet>  [Yahoo! Inc.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <BluetoothAuthenticationAgent><; rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent>  [(Verified)Microsoft Windows Publisher]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <Apoint><; C:\Program Files\Apoint\Apoint.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <IntelZeroConfig><"C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe">  [Intel Corporation]
    <IntelWireless><"C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless>  [Intel Corporation]
    <Dell QuickSet><C:\Program Files\Dell\QuickSet\quickset.exe>  [Dell Inc]
    <SigmatelSysTrayApp><stsystra.exe>  [SigmaTel, Inc.]
    <DAEMON Tools-2052><"C:\Program Files\D-Tools\daemon.exe"  -lang 1033>  [DAEMON'S HOME]
    <Google Desktop Search><"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup>  [Google]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <MMReminderService><; C:\Program Files\Mindjet\MindManager 6\MMReminderService.exe>  [Mindjet]
    <NeroFilterCheck><; C:\WINDOWS\system32\NeroCheck.exe>  [Ahead Software Gmbh]
    <igfxtray><; C:\WINDOWS\system32\igfxtray.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <igfxhkcmd><C:\WINDOWS\system32\hkcmd.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <igfxpers><C:\WINDOWS\system32\igfxpers.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [N/A]
    <DU Meter><C:\Program Files\DU Meter\DUMeter.EXE>  [Hagel Technologies]
    <TotalRecorderScheduler><; "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe">  [High Criteria inc.]
    <Super Rabbit SafeEdit><; C:\Program Files\Super Rabbit\MagicSet\SRFC.EXE /Load>  [Super Rabbit Soft]
    <ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe">  [(Verified)Symantec Corporation]
    <vptray><C:\PROGRA~1\SYMANT~1\VPTray.exe>  [(Verified)Symantec Corporation]
    <UnlockerAssistant><"D:\Tools\Cleaner\UNLOCKERASSISTANT.EXE">  [N/A]
    <runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe>  [Beijing Rising Technology Co., Ltd.]
    <SrtWatch><C:\PROGRA~1\SJ2008\SrtWatch.exe>  []
    <Acrobat Assistant 7.0><"C:\Program Files\Adobe\Distillr\Acrotray.exe">  [Adobe Systems Inc.]
    <!AVG Anti-Spyware><"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized>  [Anti-Malware Development a.s.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{57B86673-276A-48B2-BAE7-C6DBB3020EB8}><C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll>  [Anti-Malware Development a.s.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]

==================================
Startup Folders
[Adobe Acrobat Speed Launcher]
  <C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk --> C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [N/A]><N>
[Program Neighborhood Agent]
  <C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Program Neighborhood Agent.lnk --> C:\PROGRA~1\Citrix\ICACLI~1\pnagent.exe [Citrix Systems, Inc.]><H>
[内存扫把]
  <C:\Documents and Settings\Jonathan_Zhao\Start Menu\Programs\Startup\内存扫把.lnk --> C:\PROGRA~1\内存扫把\ram.exe [jfzlnyf]><N>

==================================
Services
[54DDB6B0 / 54DDB6B0][Stopped/Auto Start]
  <><N/A>
[AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
  <C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe><Anti-Malware Development a.s.>
[C9BAA70 / C9BAA70][Stopped/Auto Start]
  <><N/A>
[Symantec Event Manager / ccEvtMgr][Running/Auto Start]
  <"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr][Running/Auto Start]
  <"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[Symantec AntiVirus Definition Watcher / DefWatch][Running/Auto Start]
  <"C:\Program Files\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[Intel(R) PROSet/Wireless Event Log / EvtEng][Running/Auto Start]
  <C:\Program Files\Intel\Wireless\Bin\EvtEng.exe><Intel Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
  <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[iPod 服务 / iPod Service][Stopped/Manual Start]
  <"C:\Program Files\iPod\bin\iPodService.exe"><N/A>
[Replication Manager SE / IRCCD][Running/Auto Start]
  <C:\Program Files\EMC\Replication Manager SE\Bin\irccd.exe><EMC Corporation>
[kavsvc / kavsvc][Stopped/Auto Start]
  <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe"><N/A>
[Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><Macromedia>
[NICCONFIGSVC / NICCONFIGSVC][Running/Auto Start]
  <C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe><Dell Inc.>
[Intel(R) PROSet/Wireless Registry Service / RegSrvc][Running/Auto Start]
  <C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe><Intel Corporation>
[Intel(R) PROSet/Wireless Service / S24EventMonitor][Running/Auto Start]
  <C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe><Intel Corporation>
[SavRoam / SavRoam][Running/Auto Start]
  <"C:\Program Files\Symantec AntiVirus\SavRoam.exe"><symantec>
[Symantec Protection Agent 5.1 / SmcService][Running/Auto Start]
  <C:\Program Files\Symantec\SPA\smc.exe><Symantec Corporation>
[Symantec NAC Service / SNAC][Running/Auto Start]
  <C:\Program Files\Symantec\SPA\snac.exe><Symantec Corporation>
[Symantec SPBBCSvc / SPBBCSvc][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"><Symantec Corporation>
[Symantec AntiVirus / Symantec AntiVirus][Running/Auto Start]
  <"C:\Program Files\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>
[Intel(R) PROSet/Wireless SSO Service / WLANKEEPER][Running/Auto Start]
  <C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe><Intel(R) Corporation>

==================================
Drivers
[AEGIS Protocol (IEEE 802.1x) v3.4.9.0 / AegisP][Running/Auto Start]
  <system32\DRIVERS\AegisP.sys><Meetinghouse Data Communications>
[Alps Touch Pad Filter Driver for Windows 2000/XP / ApfiltrService][Running/Manual Start]
  <system32\DRIVERS\Apfiltr.sys><Alps Electric Co., Ltd.>
[APPDRV / APPDRV][Running/System Start]
  <\SystemRoot\SYSTEM32\DRIVERS\APPDRV.SYS><Dell Inc>
[Standard IDE/ESDI Hard Disk Controller / atapi][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\atapi.sys><N/A>
[ATSpy / ATSpy][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\ATSpy.sys><N/A>
[AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  <\??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys><N/A>
[AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
[Broadcom NetXtreme Gigabit Ethernet / b57w2k][Running/Manual Start]
  <system32\DRIVERS\b57xp32.sys><Broadcom Corporation>
[BCOREUSB.Sys CSR test driver / BCOREUSB][Stopped/Manual Start]
  <System32\Drivers\BCOREUSB.sys><CSR>
[cglptnt / cglptnt][Stopped/Manual Start]
  <\??\D:\Tools\totalcmd\totalcmd\cglptnt.sys><C. Ghisler & Co.>
[Centrino Hardware Control NT Driver / chcNT_driver][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\drivers\chcNT.sys><N/A>
[CMB8100 / CMB8100][Running/Auto Start]
  <\??\C:\WINDOWS\system32\Drivers\CertClient.dat><N/A>
[CMBProtector / CMBProtector][Running/Auto Start]
  <\??\C:\WINDOWS\system32\Drivers\CMBProtector.dat><N/A>
[d346bus / d346bus][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\d346bus.sys><>
[d346prt / d346prt][Running/Boot Start]
  <\SystemRoot\System32\Drivers\d346prt.sys><>
[Symantec Eraser Control driver / eeCtrl][Running/System Start]
  <\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys><Symantec Corporation>
[enstart_ / enstart_][Running/System Start]
  <\??\C:\WINDOWS\system32\enstart_.sys><Guidance Software Inc.>
[Eplpdx02 / Eplpdx02][Running/Manual Start]
  <\??\C:\WINDOWS\system32\Drivers\EPLPDX02.SYS><MK Systems CO., LTD.>
[EraserUtilRebootDrv / EraserUtilRebootDrv][Running/Manual Start]
  <\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys><Symantec Corporation>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
  <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HSF_DPV / HSF_DPV][Stopped/Manual Start]
  <system32\DRIVERS\HSX_DPV.sys><Conexant Systems, Inc.>
[HSXHWAZL / HSXHWAZL][Stopped/Manual Start]
  <system32\DRIVERS\HSXHWAZL.sys><Conexant Systems, Inc.>
[ialm / ialm][Running/Manual Start]
  <system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[Kl1 / Kl1][Running/Boot Start]
  <\SystemRoot\System32\drivers\kl1.sys><Kaspersky Lab>
[Klmc / Klmc][Running/System Start]
  <System32\drivers\klmc.sys><Kaspersky Lab>
[mdmxsdk / mdmxsdk][Running/Auto Start]
  <system32\DRIVERS\mdmxsdk.sys><Conexant>
[NAVENG / NAVENG][Running/Manual Start]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070607.024\naveng.sys><Symantec Corporation>
[NAVEX15 / NAVEX15][Running/Manual Start]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070607.024\navex15.sys><Symantec Corporation>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
  <system32\DRIVERS\npf.sys><CACE Technologies>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\C:\Program Files\Tencent\npkcrypt.sys><INCA Internet Co., Ltd.>
[SJ2008 Serial port driver / oxser][Running/System Start]
  <system32\DRIVERS\SRT6000.sys><OEM>
[Motorola USB Device / P2k][Stopped/Manual Start]
  <system32\DRIVERS\P2k.sys><Motorola Inc>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[WLAN Transport / s24trans][Running/Auto Start]
  <system32\DRIVERS\s24trans.sys><Intel Corporation>
[SAVRT / SAVRT][Running/System Start]
  <\??\C:\Program Files\Symantec AntiVirus\savrt.sys><Symantec Corporation>
[SAVRTPEL / SAVRTPEL][Running/System Start]
  <\??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys><Symantec Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[SERIALOX / SERIALOX][Stopped/Manual Start]
  <system32\DRIVERS\SERIALOX.sys><N/A>
[%USBFilterString% / serport][Stopped/Manual Start]
  <system32\DRIVERS\BfbBusb.sys><N/A>
[StarForce Protection Environment Driver (version 1.x) / sfdrv01][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfdrv01.sys><Protection Technology>
[StarForce Protection Helper Driver (version 2.x) / sfhlp02][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfhlp02.sys><Protection Technology>
[StarForce Protection Synchronization Driver (version 4.x) / sfsync04][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfsync04.sys><Protection Technology>
[SMC IrCC Miniport Device Driver / SMCIRDA][Running/Manual Start]
  <system32\DRIVERS\smcirda.sys><SMC>
[SPBBCDrv / SPBBCDrv][Stopped/Manual Start]
  <\??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys><Symantec Corporation>
[Spy Emergency Driver / SpyEmrg][Stopped/System Start]
  <System32\Drivers\spyemrg.sys><N/A>
[SAMSUNG Mobile USB Device II 1.0 driver (WDM) / ssm_bus][Stopped/Manual Start]
  <system32\DRIVERS\ssm_bus.sys><MCCI>
[SAMSUNG Mobile USB Modem II 1.0 Filter / ssm_mdfl][Stopped/Manual Start]
  <system32\DRIVERS\ssm_mdfl.sys><MCCI>
[SAMSUNG Mobile USB Modem II 1.0 Drivers / ssm_mdm][Stopped/Manual Start]
  <system32\DRIVERS\ssm_mdm.sys><MCCI>
[SigmaTel High Definition Audio CODEC / STHDA][Running/Manual Start]
  <system32\drivers\sthda.sys><SigmaTel, Inc.>
[SymEvent / SymEvent][Running/Manual Start]
  <\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[TAP-Win32 Adapter V8 (coLinux) / tap0801co][Stopped/Manual Start]
  <system32\DRIVERS\tap0801co.sys><The OpenVPN Project>
[Teefer for NT / Teefer][Running/Boot Start]
  <\SystemRoot\SYSTEM32\Drivers\Teefer.sys><Sygate Technologies, Inc.>
[TOSHIBA Bluetooth HID port driver / toshidpt][Stopped/Manual Start]
  <system32\drivers\Toshidpt.sys><TOSHIBA Corporation.>
[Bluetooth Port Driver from Toshiba / tosporte][Stopped/Manual Start]
  <system32\DRIVERS\tosporte.sys><TOSHIBA Corporation>
[Bluetooth RFBUS from TOSHIBA / Tosrfbd][Stopped/Manual Start]
  <System32\Drivers\tosrfbd.sys><TOSHIBA CORPORATION>
[Bluetooth RFBNEP from TOSHIBA / Tosrfbnp][Stopped/Manual Start]
  <System32\Drivers\tosrfbnp.sys><TOSHIBA Corporation>
[Bluetooth RFCOMM from TOSHIBA / Tosrfcom][Stopped/System Start]
  <System32\Drivers\tosrfcom.sys><TOSHIBA Corporation>
[Bluetooth RFHID from TOSHIBA / Tosrfhid][Stopped/Manual Start]
  <system32\DRIVERS\Tosrfhid.sys><TOSHIBA Corporation.>
[Bluetooth Personal Area Network from TOSHIBA / tosrfnds][Stopped/Manual Start]
  <system32\DRIVERS\tosrfnds.sys><TOSHIBA Corporation.>
[Bluetooth Audio Device (WDM) from TOSHIBA / TosRfSnd][Stopped/Manual Start]
  <system32\drivers\TosRfSnd.sys><TOSHIBA Corporation>
[Bluetooth USB Controller / Tosrfusb][Stopped/Manual Start]
  <System32\Drivers\tosrfusb.sys><TOSHIBA CORPORATION>
[Conexant Setup API / UIUSys][Stopped/Manual Start]
  <system32\DRIVERS\UIUSYS.SYS><N/A>
[Intel(R) PRO/Wireless 3945ABG Adapter Driver / w39n51][Running/Manual Start]
  <system32\DRIVERS\w39n51.sys><Intel? Corporation>
[SyGate for NT, wg3n / wg3n][Running/Auto Start]
  <\SystemRoot\SYSTEM32\Drivers\wg3n.sys><Sygate Technologies, Inc.>
[SyGate for NT, wg4n / wg4n][Running/Auto Start]
  <\SystemRoot\SYSTEM32\Drivers\wg4n.sys><Sygate Technologies, Inc.>
[SyGate for NT, wg5n / wg5n][Running/Auto Start]
  <\SystemRoot\SYSTEM32\Drivers\wg5n.sys><Sygate Technologies, Inc.>
[SyGate for NT, wg6n / wg6n][Running/Auto Start]
  <\SystemRoot\SYSTEM32\Drivers\wg6n.sys><Sygate Technologies, Inc.>
[Extend WG Protocol Driver / WGX][Running/Auto Start]
  <\SystemRoot\SYSTEM32\Drivers\WGX.sys><Symantec Corporation>
[WIBU-KEY Kernel Driver / WIBUKEY][Running/Auto Start]
  <SYSTEM32\DRIVERS\Wibukey.sys><WIBU-SYSTEMS AG>
[winachsf / winachsf][Stopped/Manual Start]
  <system32\DRIVERS\HSX_CNXT.sys><Conexant Systems, Inc.>
[wpsdrvnt / wpsdrvnt][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys><Sygate Technologies, Inc.>
[xFileMgr / xFileMgr][Stopped/System Start]
  <\??\C:\WINDOWS\system32\Drivers\xFileMgr.sys><N/A>

==================================
Browser Add-ons
[IDMIEHlprObj Class]
  {0055C089-8582-441B-A0BF-17B458C2A3A8} <C:\Program Files\Internet Download Manager\IDMIECC.dll, Tonec Inc.>
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Skype add-on (mastermind)]
  {22BF413B-C6D2-4d91-82A9-A0F997BA588C} <C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll, Skype Technologies S.A.>
[Solid Converter PDF]
  {259F616C-A300-44F5-B04A-ED001A26C85C} <C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll, VoyagerSoft, LLC>
[AcroIEToolbarHelper Class]
  {AE7CD045-E861-484f-8273-0445EE161910} <C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[MenuHelper Class]
  {685ec120-f786-4498-a8f0-794d47916161} <C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll, Microsoft Corporation>
[Skype add-on (button)]
  {77BF5300-1474-4EC7-9980-D32B190E9B07} <C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll, Skype Technologies S.A.>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[ViewerHelper Class]
  {aede78a6-42b6-4c3c-96eb-5ae6dbec4859} <C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll, Microsoft Corporation>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, N/A>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\PROGRA~1\FlashGet\fgiebar.dll, Amaze Soft>
[Adobe PDF]
  {47833539-D0C5-4125-9FA8-0819E2EAAC93} <C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[SnagIt]
  {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} <C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll, TechSmith Corporation>
[Solid Converter PDF]
  {259F616C-A300-44F5-B04A-ED001A26C85C} <C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll, VoyagerSoft, LLC>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <, N/A>
[ILINCInstall80 Class]
  {03A89EFD-E023-8000-A22D-45F77558EB4C} <C:\WINDOWS\Downloaded Program Files\ilinci80.dll, iLinc Communications, Inc.>
[Office Genuine Advantage Validation Tool]
  {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} <C:\WINDOWS\system32\OGACheckControl.DLL, Microsoft Corporation>
[Edit Class]
  {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
[Macromedia Authorware Web Player Control]
  {15B782AF-55D8-11D1-B477-006097098764} <C:\WINDOWS\system32\macromed\authorwa\awswax.ocx, Macromedia, Inc.>
[CMBSafeHelper Class]
  {26BCA338-BB94-4E8F-A082-3E5735875B79} <C:\WINDOWS\system32\CMBGUARD.dll, >
[jfEnvelope Class]
  {292CBB36-AC91-11D1-B911-080009EF1192} <C:\WINDOWS\Downloaded Program Files\jfITEnvelopeCtrl.dll, Adobe Systems Inc.>
[TeleControl Class]
  {29EF91B9-7120-477C-A5CB-2D67F2FD088C} <, N/A>
[Microsoft Virtual Server VMRC Advanced Control]
  {4EFA317A-8569-4788-B175-5BAF9731A549} <C:\WINDOWS\Downloaded Program Files\VMRCActiveXClient.dll, Microsoft Corporation>
[Java Plug-in 1.4.2_08]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\j2re1.4.2_08\bin\npjpi142_08.dll, JavaSoft / Sun Microsystems, Inc.>
[AxSubmitControl Class]
  {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} <C:\WINDOWS\DOWNLO~1\SUBMIT~1.DLL, >
[WebDraw Class]
  {B234C268-A755-49A1-8A52-C8408A99AD7C} <C:\WINDOWS\system32\photon\support\webutil.dll, >
[JInitiator 1.3.1.25]
  {CAFECAFE-0013-0001-0025-ABCDEFABCDEF} <C:\Program Files\Oracle\JInitiator 1.3.1.25\bin\npjinit13125.dll, Oracle Corporation>
[Java Plug-in 1.4.0]
  {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} <, N/A>
[Java Plug-in 1.4.2_08]
  {CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA} <C:\Program Files\Java\j2re1.4.2_08\bin\npjpi142_08.dll, JavaSoft / Sun Microsystems, Inc.>
[GpcContainer Class]
  {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} <, N/A>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[KvScanOnline Control]
  {EF6205C1-3F17-4829-BCB5-1336ED89E356} <C:\WINDOWS\system32\KvDown.ocx, dreamersoft>
[IDMIEHlprObj Class]
  {0055C089-8582-441B-A0BF-17B458C2A3A8} <C:\Program Files\Internet Download Manager\IDMIECC.dll, Tonec Inc.>
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Skype add-on (mastermind)]
  {22BF413B-C6D2-4D91-82A9-A0F997BA588C} <C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll, Skype Technologies S.A.>
[Solid Converter PDF]
  {259F616C-A300-44F5-B04A-ED001A26C85C} <C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll, VoyagerSoft, LLC>
[Adobe PDF]
  {47833539-D0C5-4125-9FA8-0819E2EAAC93} <C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[WangWangObj Class]
  {6E213FC7-DD5A-4115-B7E6-D4C7838C361E} <C:\Program Files\淘宝网\淘宝旺旺\WangWangX4.dll, 阿里软件(中国)有限公司>
[超级兔子上网精灵]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <, N/A>
[Skype add-on (button)]
  {77BF5300-1474-4EC7-9980-D32B190E9B07} <C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll, Skype Technologies S.A.>
[ViewerHelper Class]
  {78104A01-8E71-4F30-9A36-3793799615B4} <C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll, Microsoft Corporation>
[SnagIt]
  {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} <C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll, TechSmith Corporation>
[CmjBrowserHelperObject Object]
  {AC41D38F-B56D-40AD-94E0-B493D130C959} <C:\Program Files\Mindjet\MindManager 6\Mm6InternetExplorer.dll, Mindjet>
[AcroIEToolbarHelper Class]
  {AE7CD045-E861-484F-8273-0445EE161910} <C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[Java Plug-in 1.4.2_08]
  {CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA} <C:\Program Files\Java\j2re1.4.2_08\bin\npjpi142_08.dll, JavaSoft / Sun Microsystems, Inc.>
[Microsoft Live Meeting Console Launcher]
  {CC2AA3AF-4E14-46DD-90E5-9D315F0AFA0F} <, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[MessengerChecker Class]
  {DA4F543C-C8A9-4E88-9A79-548CBB46F18F} <D:\Messenger\YPagerChecker.dll, Yahoo! Inc.>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <, N/A>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\PROGRA~1\FlashGet\fgiebar.dll, Amaze Soft>
[Convert link target to Adobe PDF]
  <res://C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[Convert link target to existing PDF]
  <res://C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[Convert selected links to Adobe PDF]
  <res://C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html, N/A>
[Convert selected links to existing PDF]
  <res://C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html, N/A>
[Convert selection to Adobe PDF]
  <res://C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[Convert selection to existing PDF]
  <res://C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[Convert to Adobe PDF]
  <res://C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[Convert to existing PDF]
  <res://C:\Program Files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[上传到QQ网络硬盘]
  <, N/A>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <, N/A>
[添加到QQ表情]
  <, N/A>
[用QQ彩信发送该图片]
  <, N/A>

==================================
Running Processes
[PID: 740][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 788][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 812][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 856][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\AppPatch\AcAdProc.dll]  [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[PID: 868][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1036][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1116][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1156][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Symantec\SPA\SymRasMan.dll]  [Symantec Corporation, 11.0.0.254]
    [C:\Program Files\Symantec\SPA\RasSymEap.dll]  [Symantec Corporation, 11.0.0.254]
[PID: 1240][C:\Program Files\Intel\Wireless\Bin\EvtEng.exe]  [Intel Corporation, 10, 1, 0, 1]
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  [Intel Corporation, 10, 1, 0, 2]
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  [Intel Corporation, 10, 1, 0, 5]
    [C:\Program Files\SJ2008\msado15.dll]  [Microsoft Corporation, 2.81.1117.0 (xpsp_sp2_rtm.040803-2158)]
[PID: 1284][C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe]  [Intel Corporation , 10, 1, 0, 33]
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  [Intel Corporation, 10, 1, 0, 5]
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  [Intel Corporation, 10, 1, 0, 2]
    [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll]  [N/A, ]
    [C:\Program Files\Intel\Wireless\Bin\IntStngs.dll]  [, 10, 1, 0, 3]
    [C:\Program Files\Intel\Wireless\Bin\IWMSPROV.DLL]  [N/A, ]
    [C:\WINDOWS\system32\MFC42LOC.DLL]  [Microsoft Corporation, 6.00.8168.0]
[PID: 1344][C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe]  [Intel(R) Corporation, 10, 1, 0, 27]
    [C:\Program Files\Intel\Wireless\Bin\PfMgrApi.dll]  [Intel Corporation, 10, 1, 0, 46]
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  [Intel Corporation, 10, 1, 0, 5]
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  [Intel Corporation, 10, 1, 0, 2]
    [C:\Program Files\Intel\Wireless\Bin\DbEngine.dll]  [Intel Corporation, 10, 1, 0, 13]
    [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll]  [N/A, ]
    [C:\Program Files\Intel\Wireless\Bin\IntStngs.dll]  [, 10, 1, 0, 3]
    [C:\Program Files\Intel\Wireless\Bin\MurocApi.dll]  [Intel Corporation, 10, 1, 0, 37]
    [C:\Program Files\Intel\Wireless\Bin\S24MUDLL.dll]  [Intel Corporation, 10, 1, 0, 1]
    [C:\WINDOWS\system32\MFC42LOC.DLL]  [Microsoft Corporation, 6.00.8168.0]
[PID: 1432][C:\Program Files\Symantec\SPA\smc.exe]  [Symantec Corporation, 6.6.00.6523]
    [C:\Program Files\Symantec\SPA\Trident.dll]  [Sygate Technologies, Inc., 6, 0, 0, 0]
    [C:\Program Files\Symantec\SPA\SyLog.dll]  [Sygate Technologies, Inc., 5. 5. 0. 0]
    [C:\Program Files\Symantec\SPA\SyLink.dll]  [Sygate Technologies, Inc., 5, 5, 0, 0]
    [C:\Program Files\Symantec\SPA\DataMan.dll]  [Sygate Technologies, Inc., 5. 5. 0. 0]
    [C:\Program Files\Symantec\SPA\tfman.dll]  [Sygate Technologies, Inc., 1.62.1200.0]
    [C:\Program Files\Symantec\SPA\tse.dll]  [Sygate Technologies, Inc.,, 5, 5, 0, 0]
    [C:\Program Files\Symantec\SPA\PSSensor.dll]  [Sygate Technologies, Inc., 5. 5. 0. 0]
    [C:\WINDOWS\system32\SSSensor.dll]  [Sygate Technologies, Inc., 5. 5. 0. 5]
    [C:\Program Files\Symantec\SPA\SpNet.dll]  [Sygate Technologies, Inc., 5. 5. 0. 0]
    [C:\Program Files\Symantec\SPA\IdsTrafficPipe.dll]  [Sygate Technologies, Inc., 5. 5. 0. 0]
    [C:\Program Files\Symantec\SPA\wpsman.dll]  [Sygate Technologies, Inc., 5, 5, 0, 0]
    [C:\Program Files\Symantec\SPA\wsman.dll]  [Sygate Technologies, Inc., 5, 5, 0, 0]
    [C:\Program Files\Symantec\SPA\SgHI.dll]  [sygate, 1, 0, 0, 1]
    [C:\Program Files\Symantec\SPA\wgman.dll]  [Sygate Technologies, Inc., 1.01.1222]
    [C:\Program Files\Symantec\SPA\Netport.dll]  [Sygate Technologies, Inc., 5, 5, 0, 0]
    [C:\Program Files\Symantec\SPA\devman.plg]  [sygate, 1, 0, 0, 1]
    [C:\Program Files\Symantec\SPA\NacManager.plg]  [N/A, ]
    [C:\Program Files\Symantec\SPA\sfman.plg]  [, 1, 0, 0, 1]
    [C:\Program Files\Symantec\SPA\sgman.plg]  [, 1, 0, 0, 1]
[PID: 1604][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1664][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2036][C:\Program Files\Symantec\SPA\snac.exe]  [Symantec Corporation, 11.0.0.254]
    [C:\Program Files\Symantec\SPA\WGXMAN.DLL]  [Symantec Corporation, 11.0.0.254]
    [C:\Program Files\Symantec\SPA\SnacNp.dll]  [, 11, 0, 0, 1]
    [C:\Program Files\Symantec\SPA\SymRasMan.dll]  [Symantec Corporation, 11.0.0.254]
    [C:\Program Files\Symantec\SPA\RasSymEap.dll]  [Symantec Corporation, 11.0.0.254]
[PID: 1520][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WPDShServiceObj.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\PortableDeviceTypes.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll]  [VoyagerSoft, LLC, 2.2.143.0]
    [C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ConverterCore.dll]  [VoyagerSoft, LLC, 2.2.143.0]
    [C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidCore.dll]  [VoyagerSoft, LLC, 2.2.143.0]
    [C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\MSLUP71.dll]  [Sample Corporation, 7.10.0000]
    [C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\MSLUR71.dll]  [Sample Corporation, 7.10.0000]
    [C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\MFC71LU.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MFC71ENU.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Internet Download Manager\IDMIECC.dll]  [Tonec Inc., 4, 0, 0, 1]
    [C:\Program Files\Adobe\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.5.2005092300]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Internet Download Manager\idmmkb.dll]  [Tonec Inc., 4, 0, 0, 1]
    [C:\WINDOWS\system32\dfshim.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\Program Files\Symantec\SPA\SnacNp.dll]  [, 11, 0, 0, 1]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [D:\0\Spy Emergency2006\Spy Emergency2006\SpyEmergencyExt.dll]  [NETGATE, 3, 0, 190, 0]
    [C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll]  [Symantec Corporation, 10.0.2.2021]
    [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll]  [Anti-Malware Development a.s., 7, 5, 0, 47]
    [C:\Program Files\Adobe\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\Program Files\WIBU-SYSTEMS\System\WibuShellExt.dll]  [WIBU-SYSTEMS AG, Version 1.01 of 2001-Nov-28]
[PID: 1692][C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe]  [Intel Corporation, 10, 1, 0, 42]
    [C:\Program Files\Intel\Wireless\bin\PfMgrApi.dll]  [Intel Corporation, 10, 1, 0, 46]
    [C:\Program Files\Intel\Wireless\bin\TraceAPI.DLL]  [Intel Corporation, 10, 1, 0, 5]
    [C:\Program Files\Intel\Wireless\bin\PsRegApi.dll]  [Intel Corporation, 10, 1, 0, 2]
    [C:\Program Files\Intel\Wireless\bin\DbEngine.dll]  [Intel Corporation, 10, 1, 0, 13]
    [C:\Program Files\Intel\Wireless\bin\LIBEAY32.dll]  [N/A, ]
    [C:\Program Files\Intel\Wireless\bin\IntStngs.dll]  [, 10, 1, 0, 3]
    [C:\Program Files\Intel\Wireless\bin\MurocApi.dll]  [Intel Corporation, 10, 1, 0, 37]
    [C:\Program Files\Intel\Wireless\bin\S24MUDLL.dll]  [Intel Corporation, 10, 1, 0, 1]
    [C:\WINDOWS\system32\MFC42LOC.DLL]  [Microsoft Corporation, 6.00.8168.0]
    [C:\Program Files\Intel\Wireless\Bin\ZcSvcCHS.dll]  [Intel Corporation, 10, 1, 0, 42]
[PID: 1872][C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe]  [Intel Corporation, 10, 1, 0, 17]
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  [Intel Corporation, 10, 1, 0, 2]
    [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll]  [N/A, ]
    [C:\Program Files\Intel\Wireless\Bin\IntStngs.dll]  [, 10, 1, 0, 3]
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  [Intel Corporation, 10, 1, 0, 5]
    [C:\WINDOWS\system32\DrvTrNTm.dll]  [High Criteria inc., 6.0]
    [C:\WINDOWS\system32\DrvTrNTl.dll]  [High Criteria inc., 6.0]
    [C:\WINDOWS\system32\MFC42LOC.DLL]  [Microsoft Corporation, 6.00.8168.0]
    [C:\Program Files\Intel\Wireless\Bin\FrWrkCHS.dll]  [Intel Corporation, 10, 1, 0, 17]
    [C:\Program Files\Intel\Wireless\Bin\FrameworkPlugins\ConnMgr.dll]  [Intel Corporation, 10, 1, 1, 162]
    [C:\Program Files\Intel\Wireless\Bin\MurocApi.dll]  [Intel Corporation, 10, 1, 0, 37]
    [C:\Program Files\Intel\Wireless\Bin\S24MUDLL.dll]  [Intel Corporation, 10, 1, 0, 1]
    [C:\Program Files\Intel\Wireless\Bin\PfMgrApi.dll]  [Intel Corporation, 10, 1, 0, 46]
    [C:\Program Files\Intel\Wireless\Bin\DbEngine.dll]  [Intel Corporation, 10, 1, 0, 13]
    [C:\Program Files\Intel\Wireless\Bin\IntWACHS.dll]  [Intel Corporation, 10, 1, 1, 162]
    [C:\Program Files\SJ2008\msado15.dll]  [Microsoft Corporation, 2.81.1117.0 (xpsp_sp2_rtm.040803-2158)]
[PID: 1912][C:\Program Files\Dell\QuickSet\quickset.exe]  [Dell Inc, 7, 1, 8, 0]
    [C:\Program Files\Dell\QuickSet\IWH9.dll]  [Dell Inc, 7, 1, 8, 0]
    [C:\Program Files\Dell\QuickSet\IWH10.dll]  [Dell Inc, 7, 1, 8, 0]
    [C:\WINDOWS\system32\DrvTrNTm.dll]  [High Criteria inc., 6.0]
    [C:\WINDOWS\system32\DrvTrNTl.dll]  [High Criteria inc., 6.0]
    [C:\Program Files\Intel\Wireless\Bin\MurocApi.dll]  [Intel Corporation, 10, 1, 0, 37]
    [C:\Program Files\Intel\Wireless\Bin\S24MUDLL.dll]  [Intel Corporation, 10, 1, 0, 1]
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  [Intel Corporation, 10, 1, 0, 2]
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  [Intel Corporation, 10, 1, 0, 5]
    [C:\Program Files\Intel\Wireless\Bin\IntStngs.dll]  [, 10, 1, 0, 3]
    [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll]  [N/A, ]
    [C:\WINDOWS\system32\MFC42LOC.DLL]  [Microsoft Corporation, 6.00.8168.0]
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  [N/A, ]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1920][C:\WINDOWS\stsystra.exe]  [SigmaTel, Inc., 1.0.4823.0  nd322 cp1]
    [C:\WINDOWS\system32\DrvTrNTm.dll]  [High Criteria inc., 6.0]
    [C:\WINDOWS\system32\DrvTrNTl.dll]  [High Criteria inc., 6.0]
    [C:\WINDOWS\system32\stacapi.dll]  [SigmaTel, Inc., 1.0.4823.0  nd322 cp1]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 356][C:\Program Files\D-Tools\daemon.exe]  [DAEMON'S HOME, 3.46.0.0]
    [C:\WINDOWS\daemon.dll]  [, 3.46.0.0]
    [C:\Program Files\D-Tools\PFCTOC.DLL]  [Padus(R), Inc., 1, 0, 0, 12]
    [C:\Program Files\D-Tools\Plugins\Images\bw5mount.dll]  [, 1.0.2.0]
    [C:\Program Files\D-Tools\Plugins\Images\ccdmount.dll]  [GENERIC, 1.02.0.0]
    [C:\Program Files\D-Tools\Plugins\Images\mdsmount.dll]  [GENERIC, 1.01.0.0]
    [C:\Program Files\D-Tools\Plugins\Images\nrgmount.dll]  [GENERIC, 1.02.0.0]
    [C:\Program Files\D-Tools\Plugins\Images\pdimount.dll]  [GENERIC, 1.01.0.0]
    [C:\WINDOWS\system32\DrvTrNTm.dll]  [High Criteria inc., 6.0]
    [C:\WINDOWS\system32\DrvTrNTl.dll]  [High Criteria inc., 6.0]
[PID: 996][C:\WINDOWS\system32\hkcmd.exe]  [Intel Corporation, 3.0.0.4446]
    [C:\WINDOWS\system32\hccutils.DLL]  [Intel Corporation, 3.0.0.4446]
    [C:\WINDOWS\system32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.4446]
    [C:\WINDOWS\system32\igfxres.dll]  [Intel Corporation, 3.0.0.4446]
[PID: 1060][C:\WINDOWS\system32\igfxpers.exe]  [Intel Corporation, 3.0.0.4446]
    [C:\WINDOWS\system32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.4446]
[PID: 956][C:\Program Files\DU Meter\DUMeter.EXE]  [Hagel Technologies, 3.06 Build 174]
    [C:\Program Files\DU Meter\dudata.dll]  [Hagel Technologies, 3.06 Build 174]
    [C:\WINDOWS\system32\DrvTrNTm.dll]  [High Criteria inc., 6.0]
    [C:\WINDOWS\system32\DrvTrNTl.dll]  [High Criteria inc., 6.0]
[PID: 1072][C:\WINDOWS\system32\igfxsrvc.exe]  [Intel Corporation, 3.0.0.4446]
    [C:\WINDOWS\system32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.4446]
    [C:\WINDOWS\system32\igfxdev.dll]  [Intel Corporation, 3.0.0.4446]
[PID: 1308][C:\Program Files\Common Files\Symantec Shared\ccApp.exe]  [Symantec Corporation, 103.5.7.3]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Common Files\Symantec Shared\ccL35.dll]  [Symantec Corporation, 103.5.7.3]
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 103.5.7.3]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCALERT.DLL]  [Symantec Corporation, 103.5.7.3]
[PID: 1388][C:\PROGRA~1\SYMANT~1\VPTray.exe]  [Symantec Corporation, 10.0.2.2021]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Symantec AntiVirus\SAVRT32.DLL]  [Symantec Corporation, 9.7.1.4]
    [C:\Program Files\Symantec AntiVirus\Cliscan.dll]  [Symantec Corporation, 10.0.2.2021]
    [C:\PROGRA~1\SYMANT~1\NAVNTUTL.DLL]  [Symantec Corporation, 10.0.2.2021]
    [C:\Program Files\Symantec AntiVirus\Cliproxy.dll]  [Symantec Corporation, 10.0.2.2021]
[PID: 1504][C:\PROGRA~1\SJ2008\SrtWatch.exe]  [N/A, ]
    [C:\PROGRA~1\SJ2008\MFC42.DLL]  [Microsoft Corporation, 6.00.9586.0]
    [C:\WINDOWS\system32\MFC42LOC.DLL]  [Microsoft Corporation, 6.00.8168.0]
    [C:\PROGRA~1\SJ2008\SRT.DLL]  [N/A, ]
    [C:\WINDOWS\system32\DrvTrNTm.dll]  [High Criteria inc., 6.0]
    [C:\WINDOWS\system32\DrvTrNTl.dll]  [High Criteria inc., 6.0]
[PID: 1544][C:\Program Files\Adobe\Distillr\Acrotray.exe]  [Adobe Systems Inc., 7.0.1.2005092300]
[PID: 1868][C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe]  [Anti-Malware Development a.s., 7, 5, 0, 50]
    [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll]  [Anti-Malware Development a.s., 4, 2, 0, 15]
    [C:\WINDOWS\system32\DrvTrNTm.dll]  [High Criteria inc., 6.0]
    [C:\WINDOWS\system32\DrvTrNTl.dll]  [High Criteria inc., 6.0]
[PID: 1904][C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE]  [Microsoft Corporation, 3.7.1.4034]
    [C:\WINDOWS\system32\CEUTIL.dll]  [Microsoft Corporation, 3.7.1.4034]
    [C:\WINDOWS\system32\RAPI.dll]  [Microsoft Corporation, 3.7.1.4034]
    [C:\Program Files\Microsoft ActiveSync\TCP2UDP.dll]  [Microsoft Corporation, 3.7.1.4034]
    [C:\WINDOWS\system32\DrvTrNTm.dll]  [High Criteria inc., 6.0]
    [C:\WINDOWS\system32\DrvTrNTl.dll]  [High Criteria inc., 6.0]
[PID: 1632][C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe]  [Tracker Software Products Ltd., 3.30.0063]
    [C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\dscrt30.dll]  [Tracker Software Products Ltd., 3.30.0063]
    [C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\ixclib30.dll]  [Tracker Software Products, 3.30.0063]
    [C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\xccdx30.dll]  [Tracker Software Products, 3.30.0063]
    [C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\PXCLIB30.DLL]  [Tracker Software Products, 3.30.0063]
    [C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\fm30base.dll]  [Tracker Software Products Ltd., 3.30.0063]
    [C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\Fm30Tiff.dll]  [Tracker Software, 3.30.0063]
    [C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\fm30xmf.dll]  [N/A, ]
    [C:\WINDOWS\system32\DrvTrNTm.dll]  [High Criteria inc., 6.0]
    [C:\WINDOWS\system32\DrvTrNTl.dll]  [High Criteria inc., 6.0]
    [C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\xcloc30.dll]  [Tracker Software Products Ltd., 3.30.0063]
    [C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\xcpro30.dll]  [Tracker Software Products, 3.30.0063]
    [C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\xcpars30.dll]  [Tracker Software Products, 3.30.0063]
[PID: 1928][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\DrvTrNTm.dll]  [High Criteria inc., 6.0]
    [C:\WINDOWS\system32\DrvTrNTl.dll]  [High Criteria inc., 6.0]
[PID: 2212][C:\Program Files\Adobe\Acrobat\acrobat_sl.exe]  [Adobe Systems Incorporated, 7.0.5.2005092300]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 2220][C:\Program Files\内存扫把\ram.exe]  [jfzlnyf, 1.09.0005]
    [C:\WINDOWS\system32\MSVBVM60.DLL]  [Microsoft Corporation, 6.00.9782]
    [C:\WINDOWS\system32\vb6chs.dll]  [Microsoft Corporation, 6.00.8988]
    [C:\Program Files\内存扫把\Command.ocx]  [随想软件工作室 Capricciososoft, 3.00.0915]
    [C:\WINDOWS\system32\MSCOMCTL.OCX]  [Microsoft Corporation, 6.01.9782]
    [C:\Program Files\内存扫把\TrayForm.ocx]  [Eduardo Morcillo, 1.03.0007]
[PID: 2288][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\DrvTrNTm.dll]  [High Criteria inc., 6.0]
    [C:\WINDOWS\system32\DrvTrNTl.dll]  [High Criteria inc., 6.0]
[PID: 3676][C:\Program Files\Symantec\SPA\SmcGui.exe]  [Symantec Corporation., 6.6.00.6523]
    [C:\Program Files\Symantec\SPA\SpNet.dll]  [Sygate Technologies, Inc., 5. 5. 0. 0]
    [C:\Program Files\Symantec\SPA\SyLog.dll]  [Sygate Technologies, Inc., 5. 5. 0. 0]
    [C:\Program Files\Symantec\SPA\tse.dll]  [Sygate Technologies, Inc.,, 5, 5, 0, 0]
    [C:\Program Files\Symantec\SPA\DataMan.dll]  [Sygate Technologies, Inc., 5. 5. 0. 0]
    [C:\Program Files\Symantec\SPA\PSSensor.dll]  [Sygate Technologies, Inc., 5. 5. 0. 0]
    [C:\WINDOWS\system32\SSSensor.dll]  [Sygate Technologies, Inc., 5. 5. 0. 5]
    [C:\Program Files\Symantec\SPA\IdsTrafficPipe.dll]  [Sygate Technologies, Inc., 5. 5. 0. 0]
    [C:\Program Files\Symantec\SPA\wpsman.dll]  [Sygate Technologies, Inc., 5, 5, 0, 0]
    [C:\Program Files\Symantec\SPA\tfman.dll]  [Sygate Technologies, Inc., 1.62.1200.0]
    [C:\Program Files\Symantec\SPA\wsman.dll]  [Sygate Technologies, Inc., 5, 5, 0, 0]
[PID: 1448][C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe]  [Intel Corporation, 10, 1, 0, 79]
    [C:\PROGRA~1\Intel\Wireless\Bin\acAuth.dll]  [, 4.0.15.0 2005-11-16 13:05:02]
    [C:\PROGRA~1\Intel\Wireless\Bin\C1XStngs.dll]  [Intel Corporation, 10, 1, 0, 31]
    [C:\PROGRA~1\Intel\Wireless\Bin\PsRegApi.dll]  [Intel Corporation, 10, 1, 0, 2]
    [C:\PROGRA~1\Intel\Wireless\Bin\IntStngs.dll]  [, 10, 1, 0, 3]
    [C:\PROGRA~1\Intel\Wireless\Bin\TraceAPI.DLL]  [Intel Corporation, 10, 1, 0, 5]
    [C:\PROGRA~1\Intel\Wireless\Bin\IWMSPROV.DLL]  [N/A, ]
    [C:\WINDOWS\system32\MFC42LOC.DLL]  [Microsoft Corporation, 6.00.8168.0]
    [C:\Program Files\Intel\Wireless\Bin\C8021CHS.dll]  [Intel Corporation, 10, 1, 0, 31]
    [C:\PROGRA~1\Intel\Wireless\Bin\LSAWRAPI.dll]  [Intel Corporation, 10, 1, 0, 1]
    [C:\PROGRA~1\Intel\Wireless\Bin\PfMgrApi.dll]  [Intel Corporation, 10, 1, 0, 46]
    [C:\PROGRA~1\Intel\Wireless\Bin\DbEngine.dll]  [Intel Corporation, 10, 1, 0, 13]
    [C:\PROGRA~1\Intel\Wireless\Bin\LIBEAY32.dll]  [N/A, ]
[PID: 2756][C:\Documents and Settings\Jonathan_Zhao\Desktop\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\WINDOWS\system32\DrvTrNTm.dll]  [High Criteria inc., 6.0]
    [C:\WINDOWS\system32\DrvTrNTl.dll]  [High Criteria inc., 6.0]

==================================
File Associations
.TXT  Error. []
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1       localhost

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================

TOP

发新话题