==============================================================
金山清理专家系统诊断报告
该诊断报告由金山清理专家提供
http://www.duba.net
==============================================================
诊断时间: 2008-07-04, 13:30
诊断平台: Windows XP [5.1.2600] Service Pack 2
IE版本: Internet Explorer V6.0.2180.2900
计算机物理内存: 2047(MB)
当前可用内存: 1204(MB)
硬盘总大小: 148(GB)
硬盘可用空间: 131(GB)
清理专家版本: 2008.06.13.404
恶意软件库版本: 2008.06.30.1
漏洞库版本: 2008.06.26.1
==============================================================
常规启动项
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
[OrderReminder] <C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe>
文件路径: C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [分析中]
[HpMessage] <C:\Program Files\NCX-2000-XP\KmMsg.exe>
文件路径: C:\Program Files\NCX-2000-XP\KmMsg.exe [分析中]
[lan] <C:\start.bat>
文件路径: C:\start.bat [未知]
==============================================================
登陆加载项
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
[KmWinLog] <Kmlogon.dll>
文件路径: C:\WINDOWS\system32\Kmlogon.dll [分析中]
==============================================================
启动文件夹位置
==============================================================
Common Startup: C:\Documents and Settings\All Users\「开始」菜单\程序\启动
Startup: C:\Documents and Settings\admin\「开始」菜单\程序\启动
Common Startup: %ALLUSERSPROFILE%\「开始」菜单\程序\启动
==============================================================
Autorun.inf
==============================================================
该项来源: I:\Autorun.inf
[Open] <I:\pagefile.pif>
文件路径: I:\pagefile.pif [可疑的]
该项来源: J:\Autorun.inf
[Open] <J:\pagefile.pif>
==============================================================
Host File
==============================================================
127.0.0.1 localhost
==============================================================
系统服务
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
[HidServ] [已禁用] <%SystemRoot%\System32\hidserv.dll>
[HpService] [已启用] <System32\KmServc.exe>
文件路径: C:\WINDOWS\system32\\KmServc.exe [分析中]
[Iprip] [已启用] <C:\WINDOWS\system32\niprp.dll>
文件路径: C:\WINDOWS\system32\niprp.dll [可疑的]
[NVSvc] [已启用] <%SystemRoot%\system32\nvsvc32.exe>
文件路径: C:\WINDOWS\system32\nvsvc32.exe [分析中]
==============================================================
驱动程序
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32
[VIDC.FFDS] [已启用] <ff_vfw.dll>
[msacm.avis] [已启用] <ff_acm.acm>
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
[BaseTDI] [已启用] <System32\DRIVERS\BaseTDI.SYS>
文件路径: C:\WINDOWS\system32\DRIVERS\BaseTDI.SYS [分析中]
[CdaC15BA] [已启用] <\??\C:\WINDOWS\system32\drivers\CdaC15BA.SYS>
文件路径: C:\WINDOWS\system32\drivers\CdaC15BA.SYS [分析中]
[HidUsb] [已启用] <system32\drivers\HidUsb.sys>
[HpHelper] [已启用] <System32\drivers\KmHlprk.sys>
文件路径: C:\WINDOWS\system32\drivers\KmHlprk.sys [分析中]
[HpLegacyKeyboard] [已启用] <System32\drivers\KmJBox.sys>
文件路径: C:\WINDOWS\system32\drivers\KmJBox.sys [分析中]
[HpPciVga] [已启用] <System32\drivers\KmWpsMs.sys>
文件路径: C:\WINDOWS\system32\drivers\KmWpsMs.sys [分析中]
[HpStore] [已启用] <System32\drivers\KmStore.sys>
文件路径: C:\WINDOWS\system32\drivers\KmStore.sys [分析中]
[HpUsbKeyboard] [已启用] <System32\drivers\KmKbdCls.sys>
文件路径: C:\WINDOWS\system32\drivers\KmKbdCls.sys [分析中]
[HpUsbMouse] [已启用] <System32\drivers\KmMouCls.sys>
文件路径: C:\WINDOWS\system32\drivers\KmMouCls.sys [分析中]
[HpXpHidCls] [已启用] <System32\drivers\KmHidCls.sys>
文件路径: C:\WINDOWS\system32\drivers\KmHidCls.sys [分析中]
[HpXpKbdPnp] [已启用] <System32\drivers\KmKbdPnp.sys>
文件路径: C:\WINDOWS\system32\drivers\KmKbdPnp.sys [分析中]
[HpXpMouPnp] [已启用] <System32\drivers\KmMouPnp.sys>
文件路径: C:\WINDOWS\system32\drivers\KmMouPnp.sys [分析中]
[htsxhci] [已启用] <system32\DRIVERS\htsxhci.sys>
[MouHid] [已启用] <system32\drivers\MouHid.sys>
[WINIO] [已启用] <\??\H:\winio.sys>
[X300] [已启用] <system32\DRIVERS\X300M.sys>
文件路径: C:\WINDOWS\system32\DRIVERS\X300M.sys [分析中]
[X300Audio] [已启用] <system32\DRIVERS\X3HAudio.sys>
文件路径: C:\WINDOWS\system32\DRIVERS\X3HAudio.sys [分析中]
[x300bus] [已启用] <system32\DRIVERS\x300bus.sys>
文件路径: C:\WINDOWS\system32\DRIVERS\x300bus.sys [分析中]
==============================================================
BHO
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll>
[PowerFlash Class]
{DC888631-57F5-4AF4-86B3-BDE5F854DCBF} <C:\WINDOWS\system32\pwfsh.dll>
文件路径: C:\WINDOWS\system32\pwfsh.dll [病毒程序]
==============================================================
当前进程
==============================================================
名称: KmServc.exe [已启用]
命令行: System32\KmServc.exe
文件路径: C:\WINDOWS\System32\KmServc.exe [分析中] (NComputing Co..Ltd. - Korea)
模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\WS2_32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\WS2HELP.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ADVAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\PSAPI.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\WINMM.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\SETUPAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\HID.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\VERSION.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\comdlg32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\COMCTL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\WINSPOOL.DRV (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ole32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\OLEAUT32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\LPK.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\USP10.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\uxtheme.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\DNSAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\iphlpapi.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\winrnr.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WLDAP32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\rasadhlp.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\hnetcfg.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\wshtcpip.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINTRUST.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\CRYPT32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MSASN1.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMAGEHLP.dll (Microsoft Corporation)
名称: nvsvc32.exe [已启用]
文件路径: C:\WINDOWS\system32\nvsvc32.exe [分析中] (NVIDIA Corporation)
模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ADVAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USERENV.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\POWRPROF.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\wtsapi32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINSTA.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\NETAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ole32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\COMCTL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\OLEAUT32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\nvapi.dll (NVIDIA Corporation)
模块文件: C:\WINDOWS\system32\SETUPAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\uxtheme.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msctfime.ime (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINWB98.IME (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\comdlg32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINTRUST.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\CRYPT32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MSASN1.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMAGEHLP.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WS2_32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WS2HELP.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\iphlpapi.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Apphelp.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\VERSION.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\NTMARTA.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WLDAP32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SAMLIB.dll (Microsoft Corporation)
名称: OrderReminder.exe [已启用]
命令行: "C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe"
文件路径: C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [分析中] (Hewlett-Packard)
模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINSPOOL.DRV (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ADVAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\comctl32.dll (Microsoft Corporation)
名称: KmMsg.exe [已启用]
命令行: "C:\Program Files\NCX-2000-XP\KmMsg.exe"
文件路径: C:\Program Files\NCX-2000-XP\KmMsg.exe [分析中] (NComputing Co..Ltd. - Korea)
模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ADVAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\COMCTL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SETUPAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\uxtheme.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msctfime.ime (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ole32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINWB98.IME (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\comdlg32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WS2_32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WS2HELP.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\iphlpapi.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\DNSAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\rasadhlp.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINTRUST.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\CRYPT32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MSASN1.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMAGEHLP.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MSCTF.dll (Microsoft Corporation)
名称: OrderReminder.exe [已启用]
命令行: "C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe"
文件路径: C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [分析中] (Hewlett-Packard)
模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINSPOOL.DRV (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ADVAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\comctl32.dll (Microsoft Corporation)
名称: KmMsg.exe [已启用]
命令行: "C:\Program Files\NCX-2000-XP\KmMsg.exe"
文件路径: C:\Program Files\NCX-2000-XP\KmMsg.exe [分析中] (NComputing Co..Ltd. - Korea)
模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ADVAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\COMCTL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SETUPAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\uxtheme.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msctfime.ime (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ole32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WS2_32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WS2HELP.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\iphlpapi.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\DNSAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\rasadhlp.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MSCTF.dll (Microsoft Corporation)
名称: OrderReminder.exe [已启用]
命令行: "C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe"
文件路径: C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [分析中] (Hewlett-Packard)
模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINSPOOL.DRV (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ADVAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\comctl32.dll (Microsoft Corporation)
名称: KmMsg.exe [已启用]
命令行: "C:\Program Files\NCX-2000-XP\KmMsg.exe"
文件路径: C:\Program Files\NCX-2000-XP\KmMsg.exe [分析中] (NComputing Co..Ltd. - Korea)
模块文件: C:\WINDOWS\system32\ntdll.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USER32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\GDI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ADVAPI32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RPCRT4.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Secur32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msvcrt.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHLWAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\COMCTL32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SETUPAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMM32.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\LPK.DLL (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USP10.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msctfime.ime (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ole32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WS2_32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WS2HELP.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\iphlpapi.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\DNSAPI.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\rasadhlp.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MSCTF.dll (Microsoft Corporation)