·¢Ð»°Ìâ
´òÓ¡

[ÇóÖú] JS.Downloader.fv.582

¹ÜÏþÀ×ÀÏʦ£¬ÎÒ°ÑÎÒµÄɨÃ豨¸æÒ²·¢ÉÏ£¬Äã°ïÎÒ¿´Ò»¿´£¬ÎÒÒ²ÊÇÕâ¸ö²¡¶¾¡£»¹ÓÐÎÒÓÃÎҵĽðɽͨÐÐÖ¤ÔõôÉϲ»À´ÁË£¬ËµÓû§Ãû»òÕßÃÜÂë´íÎó£¿ÎÒ¶Ô¼ÆËã»ú²»Ì«Ã÷°×£¬Ò²²»»á´«Ê²Ã´¸½¼þ£¬¸´ÖƵ½ÏÂÃæ£¬Âé·³ÄãÁË¡£
¸´ÖÆÄÚÈݵ½¼ôÌù°å
´úÂë:
2008-08-10,15:36:08

System Repair Engineer 2.6.12.1018
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 2 (Build 2600) - ¹ÜÀíȨÏÞÓû§ - ÍêÕû¹¦ÄÜ

ÒÔÏÂÄÚÈݱ»Ñ¡ÖУº
    ËùÓÐµÄÆô¶¯ÏîÄ¿£¨°üÀ¨×¢²á±í¡¢Æô¶¯Îļþ¼Ð¡¢·þÎñµÈ£©
    ä¯ÀÀÆ÷¼ÓÔØÏî
    ÕýÔÚÔËÐеĽø³Ì£¨°üÀ¨½ø³ÌÄ£¿éÐÅÏ¢£©
    Îļþ¹ØÁª
    Winsock ÌṩÕß
    Autorun.inf
    HOSTS Îļþ
    ½ø³ÌÌØÈ¨É¨Ãè


Æô¶¯ÏîÄ¿
×¢²á±í
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
    <Super Rabbit IEPro><C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD>  [Super Rabbit Soft]
    <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <ÁªÏë±ê×¼¹¦ÄܼüÅÌ Ver1.0.0.3><C:\Program Files\ÁªÏë\ÁªÏë±ê×¼¹¦ÄܼüÅÌ\SkDaemond.exe>  [ÁªÏë]
    <StateChange><C:\Program Files\lenovo\StateChange\QuakeII.exe>  [ÁªÏë]
    <ZSSnp211><C:\WINDOWS\ZSSnp211.exe>  [ZSMCSNAP]
    <Domino><C:\WINDOWS\Domino.exe>  []
    <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup>  [(Verified)"Zhuhai  Kingsoft Software Co.,Ltd"]
    <9158CamMonitor><C:\Program Files\9158VirtualCamera\9158Notify.EXE>  []
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Component Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <ͨѶ²¾ 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\ºÀ½Ü¶à~1.SCR>  []

==================================
Æô¶¯Îļþ¼Ð
[VIA RAID TOOL]
  <C:\Documents and Settings\All Users\¡¸¿ªÊ¼¡¹²Ëµ¥\³ÌÐò\Æô¶¯\VIA RAID TOOL.lnk --> C:\PROGRA~1\VIA\RAID\RAID_T~1.EXE [VIA Technologies]><N>
[QQÓÎÏ·Æô¶¯¼ÓËÙ³ÌÐò]
  <C:\Documents and Settings\Owner\¡¸¿ªÊ¼¡¹²Ëµ¥\³ÌÐò\Æô¶¯\QQÓÎÏ·Æô¶¯¼ÓËÙ³ÌÐò.lnk --> C:\PROGRA~1\Tencent\QQGAME\Accel.exe [ÉîÛÚÊÐÌÚѶ¼ÆËã»úϵͳÓÐÏÞ¹«Ë¾]><N>
[ÌÚѶQQ]
  <C:\Documents and Settings\Owner\¡¸¿ªÊ¼¡¹²Ëµ¥\³ÌÐò\Æô¶¯\ÌÚѶQQ.lnk --> C:\PROGRA~1\Tencent\qq\QQ.exe [TENCENT]><N>

==================================
·þÎñ
[Application Management / AppMgmt][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Contrl Center of Storm Media / ccosm][Running/Auto Start]
  <C:\Program Files\StormII\stormliv.exe /asservice><±±¾©±©·çÍø¼Ê¿Æ¼¼ÓÐÏÞ¹«Ë¾>
[AMD PowerNow! (tm) Technology Service / GemServ][Running/Auto Start]
  <C:\Program Files\AMD\Cool'n'Quiet\GemServ.exe><Advanced Micro Devices>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Kingsoft Internet Security Common Service / KISSvc][Running/Auto Start]
  <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>
[Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
  <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>
[Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
  <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>

==================================
Çý¶¯³ÌÐò
[9158cap, WDM Video Capture / 9158CAP][Running/Auto Start]
  <system32\DRIVERS\9158cap.sys><www.9158.com>
[Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
  <system32\drivers\ALCXSENS.SYS><Sensaura>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AMD PowerNow! (tm) Technology / gemwdm][Running/System Start]
  <system32\DRIVERS\gemwdm.sys><Advanced Micro Devices>
[KAVBase / KAVBase][Running/Auto Start]
  <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
[KAVBootC / KAVBootC][Running/Boot Start]
  <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>
[KAVSafe / KAVSafe][Running/Auto Start]
  <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>
[KNetWch / KNetWch][Running/System Start]
  <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
[KWatch3 / KWatch3][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
[npkcrypt / npkcrypt][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\npkcrypt.sys><N/A>
[npkycryp / npkycryp][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\npkycryp.sys><N/A>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[PNDIO / PNDIO][Stopped/Manual Start]
  <\??\C:\Program Files\lenovo\StateChange\pndio.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[PS/2 Keyboard Filter Driver for WindowsXP / Skpskb][Running/Manual Start]
  <system32\DRIVERS\Skpskb.sys><Silitek Corp.>
[viamraid / viamraid][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\viamraid.sys><VIA Technologies inc,.ltd>
[USB PC Camera (ZS0211) / ZSMC211][Running/Manual Start]
  <System32\Drivers\ZS211.sys><ZSMC Corporation>

==================================
ä¯ÀÀÆ÷¼ÓÔØÏî
[ThunderAtOnce Class]
  {01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[°Ù¶ÈËѰÔ]
  {B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\WINDOWS\DOWNLO~1\BaiDuBar.dll, >
[kingsoft browser shield]
  {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, (Signed) Kingsoft Corporation>
[Æô¶¯Ñ¸À×5]
  {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[ºÀ½Ü³¬¼¶½â°ÔV8]
  {367E0A21-8601-4986-9C9A-153BF5ACA118} <C:\Herosoft\HeroV8\STHSDVD.EXE, N/A>
[IEBuddyExtControl Class]
  {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, (Signed) Kingsoft Corporation>
[ÁªÏë]
  {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.lenovo.com, N/A>
[ÐÅÏ¢¼ìË÷(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, (Signed) Microsoft Corporation>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, (Signed) Microsoft Corporation>
[°Ù¶ÈËѰÔ]
  {B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\WINDOWS\DOWNLO~1\BaiDuBar.dll, >
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, (Signed) Adobe Systems, Inc.>
[ThunderAtOnce Class]
  {01443AEC-0FD1-40FD-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[]
  {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, >
[InstallHelper Class]
  {1DABF8D5-8430-4985-9B7F-A30E53D709B3} <C:\Program Files\Tencent\QQLive\QQLiveInstaller.dll, N/A>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, (Signed) Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, (Signed) N/A>
[DHTML Edit Control Safe for Scripting for IE5]
  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, (Signed) Microsoft Corporation>
[Tabular Data Control]
  {333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, (Signed) Microsoft Corporation>
[]
  {367E0A21-8601-4986-9C9A-153BF5ACA118} <, >
[IEBuddyExtControl Class]
  {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, (Signed) Kingsoft Corporation>
[]
  {43869BB3-22FD-4F15-9B46-238106BA2F4E} <, >
[XML Document]
  {48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, (Signed) N/A>
[Thunder Agent Class]
  {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[]
  {4E8A5277-C04E-4FE3-BF78-8A7CCD6EF333} <, >
[Kingsoft Trojan Webshield]
  {4E8A5278-C04E-4FE3-BF78-8A7CCD6EF333} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll, (Signed) Kingsoft Corporation>
[HHCtrl Object]
  {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, (Signed) Microsoft Corporation>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A>
[]
  {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <, >
[XMP Class]
  {6483F145-A768-4C41-AACC-52D4D7845851} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work, >
[XDRM]
  {693571CB-54A3-4E90-9D52-EEAE1334E2D3} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xdrm.dll_1_work, >
[StormPlayer Object]
  {6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB} <C:\Program Files\StormII\mps.dll, (Signed) ±±¾©±©·çÍø¼Ê¿Æ¼¼ÓÐÏÞ¹«Ë¾>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
[Active Desktop Mover]
  {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, (Signed) N/A>
[]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <, >
[MediaComm Class]
  {7670648D-461B-42AF-BDFE-46D26AF5EFF2} <C:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin17.dll, Thunder Networking Technologies,LTD>
[BROWSERToUC Class]
  {77AE4780-75E0-4CB0-A162-D1BBE3D50384} <C:\Program Files\sina\UC\ActiveX\BROWSER2UC.dll, N/A>
[Microsoft Web ä¯ÀÀÆ÷]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, (Signed) Microsoft Corporation>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <, >
[RMGetLicense Class]
  {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, (Signed) Microsoft Corporation>
[DapCtrl Class]
  {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} <C:\Program Files\Common Files\Thunder Network\KanKan\DapCtrl.2.1.5803.60.(209).dll, ShenZhen Thunder Networking Technologies Ltd.>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, (Signed) Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A>
[°Ù¶ÈËѰÔ]
  {B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\WINDOWS\DOWNLO~1\BaiDuBar.dll, >
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, (Signed) Microsoft Corporation>
[AUDIO__MP3 Moniker Class]
  {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
[VIDEO__X_MS_ASF Moniker Class]
  {CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, (Signed) RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, (Signed) Adobe Systems, Inc.>
[kingsoft browser shield]
  {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, (Signed) Kingsoft Corporation>
[Thunder DapPlayer]
  {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} <C:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DapPlayer3.0.5712.71.209.dll, ShenZhen Thunder Networking Technologies Ltd.>
[XPPlayer Class]
  {F3E70CEA-956E-49CC-B444-73AFE593AD7F} <C:\Program Files\Common Files\Thunder Network\KanKan\PPlayer.2.0.0.181.(210).dll, Xunlei Networking Technologies,LTD>
[]
  {FB5F1910-F110-11D2-BB9E-00C04F795683} <, >
[ʹÓÃѸÀ×ÏÂÔØ]
  <C:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
[ʹÓÃѸÀ×ÏÂÔØÈ«²¿Á´½Ó]
  <C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
[µ¼³öµ½ Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[Ìí¼Óµ½QQ±íÇé]
  <C:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[°Ù¶ÈFlashËÑË÷]
  <res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/FLASHSEARCH.HTM, N/A>
[°Ù¶Èmp3ËÑË÷]
  <res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUMP3.HTM, N/A>
[°Ù¶ÈÐÅÏ¢¿ìµÝËÑË÷]
  <res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUIE.HTM, N/A>
[°Ù¶ÈͼƬËÑË÷]
  <res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUIMG.HTM, N/A>
[°Ù¶ÈËÑË÷]
  <res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUSEARCH.HTM, N/A>
[°Ù¶ÈÐÂÎÅËÑË÷]
  <res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUNEWS.HTM, N/A>
[ºÀ½Ü³¬¼¶½â°ÔV8ʵʱ²¥·Å]
  <C:\Herosoft\HeroV8\MPURLGET.HTM, N/A>

==================================
ÕýÔÚÔËÐеĽø³Ì
[PID: 448 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 504 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 528 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UNISPIM6.IME]  [±±¾©×Ϲ⻪ÓîÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾, 6.0.0.6138]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 572 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 584 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 728 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 780 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 844 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\wups2.dll]  [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)]
[PID: 900 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 972 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1272 / Owner][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
    [C:\WINDOWS\system32\UNISPIM6.IME]  [±±¾©×Ϲ⻪ÓîÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾, 6.0.0.6138]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\Program Files\Ucxgglb2008\UC\UCIdleHook.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 0, 1, 0]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.5.29]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 8, 96]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_01.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 20]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_01.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
    [C:\WINDOWS\DOWNLO~1\BaiDuBar.dll]  [, 2, 0, 0, 0]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEXT.DLL]  [Kingsoft Corporation, 2008,05,07,373]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
[PID: 1360 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
    [C:\WINDOWS\system32\mdimon.dll]  [Microsoft Corporation, 11.3.8166.2]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll]  [Microsoft Corporation, 11.3.8166.2]
[PID: 1624 / Owner][C:\Program Files\ÁªÏë\ÁªÏë±ê×¼¹¦ÄܼüÅÌ\SkDaemond.exe]  [ÁªÏë, 1, 0, 0, 1]
    [C:\Program Files\ÁªÏë\ÁªÏë±ê×¼¹¦ÄܼüÅÌ\Ctrdev.dll]  [-, 1, 0, 0, 0]
    [C:\Program Files\ÁªÏë\ÁªÏë±ê×¼¹¦ÄܼüÅÌ\SKUtil.DLL]  [Silitek Corp., 1, 0, 7, 0]
    [C:\WINDOWS\system32\UNISPIM6.IME]  [±±¾©×Ϲ⻪ÓîÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾, 6.0.0.6138]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
[PID: 1640 / Owner][C:\WINDOWS\ZSSnp211.exe]  [ZSMCSNAP, 3, 6, 818, 7]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\WINDOWS\system32\ZS211Prp.Ax]  [ZSMC, 3, 6, 703, 15]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
[PID: 1648 / Owner][C:\WINDOWS\Domino.exe]  [, 3, 6, 818, 7]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
[PID: 1688 / Owner][C:\Program Files\9158VirtualCamera\9158Notify.EXE]  [, 1, 0, 0, 1]
    [C:\Program Files\9158VirtualCamera\MFC42u.DLL]  [Microsoft Corporation, 6.00.8447.0]
[PID: 1728 / Owner][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\WINDOWS\system32\UNISPIM6.IME]  [±±¾©×Ϲ⻪ÓîÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾, 6.0.0.6138]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
[PID: 1744 / Owner][C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE]  [Super Rabbit Soft, 8.00]
    [C:\WINDOWS\system32\MSVBVM60.DLL]  [Microsoft Corporation, 6.00.9690]
    [C:\WINDOWS\system32\vb6chs.dll]  [Microsoft Corporation, 6.00.8988]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\WINDOWS\system32\UNISPIM6.IME]  [±±¾©×Ϲ⻪ÓîÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾, 6.0.0.6138]
    [C:\PROGRA~1\SUPERR~1\MagicSet\shlobj71.ocx]  [Sky Software (http://www.ssware.com), 7, 1, 0, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCIdleHook.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 0, 1, 0]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
[PID: 1752 / Owner][C:\Program Files\Messenger\msmsgs.exe]  [Microsoft Corporation, 4.7.3001]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\WINDOWS\system32\UNISPIM6.IME]  [±±¾©×Ϲ⻪ÓîÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾, 6.0.0.6138]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
[PID: 1796 / Owner][C:\Program Files\VIA\RAID\raid_tool.exe]  [VIA Technologies, 4, 0, 4, 0]
    [C:\Program Files\VIA\RAID\drvInterface.dll]  [VIA, 4, 0, 4, 0]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\WINDOWS\system32\UNISPIM6.IME]  [±±¾©×Ϲ⻪ÓîÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾, 6.0.0.6138]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
[PID: 1016 / SYSTEM][C:\Program Files\StormII\stormliv.exe]  [±±¾©±©·çÍø¼Ê¿Æ¼¼ÓÐÏÞ¹«Ë¾, 3, 8, 6, 20]
    [C:\Program Files\StormII\MSVCP60.dll]  [Microsoft Corporation, 6.02.3104.0]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.8164]
[PID: 1044 / SYSTEM][C:\Program Files\AMD\Cool'n'Quiet\GemServ.exe]  [Advanced Micro Devices, 3, 0, 6, 0]
[PID: 1144 / SYSTEM][C:\Program Files\AMD\Cool'n'Quiet\gemback.exe]  [Advanced Micro Devices, 3, 1, 0, 0]
[PID: 1568 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.7184]
    [C:\WINDOWS\system32\UNISPIM6.IME]  [±±¾©×Ϲ⻪ÓîÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾, 6.0.0.6138]
    [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.7184]
[PID: 1620 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2160 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 564 / Owner][C:\Program Files\Ucxgglb2008\UC\UC2008Ðǹâ¹ÜÀí°æ.exe]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 6.0.0.60]
    [C:\Program Files\Ucxgglb2008\UC\vcl60.bpl]  [Borland Software Corporation, 6.0.6.240]
    [C:\Program Files\Ucxgglb2008\UC\rtl60.bpl]  [Borland Software Corporation, 6.0.6.243]
    [C:\Program Files\Ucxgglb2008\UC\vclx60.bpl]  [Borland Software Corporation, 6.0.6.163]
    [C:\Program Files\Ucxgglb2008\UC\vclie60.bpl]  [Borland Software Corporation, 6.0.6.163]
    [C:\Program Files\Ucxgglb2008\UC\bcbie60.bpl]  [N/A, ]
    [C:\Program Files\Ucxgglb2008\UC\BORLNDMM.DLL]  [Borland Software Corporation, 6.0.10.157]
    [C:\Program Files\Ucxgglb2008\UC\CC3260MT.DLL]  [Borland Corporation, 0.0.0.0 (informal build)]
    [C:\Program Files\Ucxgglb2008\UC\UCAvatar.bpl]  [Beijing Sina Information Technology Co.,Ltd, 1.1.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCChatRoom.bpl]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.3.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCHm.bpl]  [Beijing Sina Information Technology Co.,Ltd, 1.4.0.0]
    [C:\Program Files\Ucxgglb2008\UC\LANGUAGERES.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.1.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCDControl.bpl]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.2.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCUI.bpl]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.4.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCSkin.bpl]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.3.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCUDPMESSAGER.DLL]  [Beijing Sina Information Technology Co.,Ltd
, 1.2.0.0]
    [C:\Program Files\Ucxgglb2008\UC\STLPMT45.DLL]  [N/A, ]
    [C:\Program Files\Ucxgglb2008\UC\UCAPI.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.1.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCRES.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.4.1.0]
    [C:\Program Files\Ucxgglb2008\UC\UCDATAMANAGER.DLL]  [Beijing Sina Information Technology Co.,Ltd, 1.2.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCMARGIN.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.2.0.0]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\WINDOWS\system32\UNISPIM6.IME]  [±±¾©×Ϲ⻪ÓîÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾, 6.0.0.6138]
    [C:\Program Files\Ucxgglb2008\UC\RICHED20.DLL]  [N/A, ]
    [C:\Program Files\Ucxgglb2008\UC\Riched20bak.dll]  [Microsoft Corporation, 5.30.23.1205]
    [C:\Program Files\Ucxgglb2008\UC\UCPlugin.dll]  [·ÉÌ칤×÷ÊÒ, 1, 0, 0, 1]
    [C:\Program Files\Ucxgglb2008\UC\ipsearch.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Ucxgglb2008\UC\riched32.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\Program Files\Ucxgglb2008\UC\UCIdleHook.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 0, 1, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCHttpDl.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 1, 9, 0]
    [C:\Program Files\Ucxgglb2008\UC\HelpEx.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.1.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCEmtMgr.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.2.0.0]
    [C:\PROGRA~1\UCXGGL~1\UC\LIVECH~1.OCX]  [sina, 1.0.0.9]
    [C:\Program Files\Ucxgglb2008\UC\BlogCheckDll.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.0.0.0]
    [C:\Program Files\Ucxgglb2008\UC\xmlrtl60.bpl]  [Borland Software Corporation, 6.0.6.240]
    [C:\Program Files\Ucxgglb2008\UC\UTNTyper.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 1, 0, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCBugCatch.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 2, 8, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCSocket.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 1, 21, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCDDP.dll]  [Beijing Sina Information Technology Co.,Ltd, 1.1.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCVideo.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 4, 6, 3, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCProcess.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 0, 0, 1]
    [C:\Program Files\Ucxgglb2008\UC\UCTransfer.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 0, 4, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCUDPFT.dll]  [Beijing Sina Information Technology Co.,Ltd, 2, 5, 0, 0]
    [C:\Program Files\Ucxgglb2008\UC\ActiveX\AvatarDisplay.dll]  [N/A, ]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
[PID: 3856 / Owner][C:\Program Files\Ucxgglb2008\UC\UC2008Ðǹâ¹ÜÀí°æ.exe]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 6.0.0.60]
    [C:\Program Files\Ucxgglb2008\UC\vcl60.bpl]  [Borland Software Corporation, 6.0.6.240]
    [C:\Program Files\Ucxgglb2008\UC\rtl60.bpl]  [Borland Software Corporation, 6.0.6.243]
    [C:\Program Files\Ucxgglb2008\UC\vclx60.bpl]  [Borland Software Corporation, 6.0.6.163]
    [C:\Program Files\Ucxgglb2008\UC\vclie60.bpl]  [Borland Software Corporation, 6.0.6.163]
    [C:\Program Files\Ucxgglb2008\UC\bcbie60.bpl]  [N/A, ]
    [C:\Program Files\Ucxgglb2008\UC\BORLNDMM.DLL]  [Borland Software Corporation, 6.0.10.157]
    [C:\Program Files\Ucxgglb2008\UC\CC3260MT.DLL]  [Borland Corporation, 0.0.0.0 (informal build)]
    [C:\Program Files\Ucxgglb2008\UC\UCAvatar.bpl]  [Beijing Sina Information Technology Co.,Ltd, 1.1.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCChatRoom.bpl]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.3.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCHm.bpl]  [Beijing Sina Information Technology Co.,Ltd, 1.4.0.0]
    [C:\Program Files\Ucxgglb2008\UC\LANGUAGERES.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.1.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCDControl.bpl]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.2.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCUI.bpl]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.4.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCSkin.bpl]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.3.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCUDPMESSAGER.DLL]  [Beijing Sina Information Technology Co.,Ltd
, 1.2.0.0]
    [C:\Program Files\Ucxgglb2008\UC\STLPMT45.DLL]  [N/A, ]
    [C:\Program Files\Ucxgglb2008\UC\UCAPI.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.1.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCRES.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.4.1.0]
    [C:\Program Files\Ucxgglb2008\UC\UCDATAMANAGER.DLL]  [Beijing Sina Information Technology Co.,Ltd, 1.2.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCMARGIN.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.2.0.0]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\WINDOWS\system32\UNISPIM6.IME]  [±±¾©×Ϲ⻪ÓîÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾, 6.0.0.6138]
    [C:\Program Files\Ucxgglb2008\UC\RICHED20.DLL]  [N/A, ]
    [C:\Program Files\Ucxgglb2008\UC\Riched20bak.dll]  [Microsoft Corporation, 5.30.23.1205]
    [C:\Program Files\Ucxgglb2008\UC\UCPlugin.dll]  [·ÉÌ칤×÷ÊÒ, 1, 0, 0, 1]
    [C:\Program Files\Ucxgglb2008\UC\ipsearch.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Ucxgglb2008\UC\riched32.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\Program Files\Ucxgglb2008\UC\UCIdleHook.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 0, 1, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCHttpDl.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 1, 9, 0]
    [C:\Program Files\Ucxgglb2008\UC\HelpEx.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.1.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCEmtMgr.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.2.0.0]
    [C:\PROGRA~1\UCXGGL~1\UC\LIVECH~1.OCX]  [sina, 1.0.0.9]
    [C:\Program Files\Ucxgglb2008\UC\BlogCheckDll.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.0.0.0]
    [C:\Program Files\Ucxgglb2008\UC\xmlrtl60.bpl]  [Borland Software Corporation, 6.0.6.240]
    [C:\Program Files\Ucxgglb2008\UC\UTNTyper.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 1, 0, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCBugCatch.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 2, 8, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCSocket.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 1, 21, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCDDP.dll]  [Beijing Sina Information Technology Co.,Ltd, 1.1.0.0]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.8164]
    [C:\Program Files\Ucxgglb2008\UC\UCVideo.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 4, 6, 3, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCProcess.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 0, 0, 1]
    [C:\Program Files\Ucxgglb2008\UC\UCTransfer.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 0, 4, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCUDPFT.dll]  [Beijing Sina Information Technology Co.,Ltd, 2, 5, 0, 0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
[PID: 2892 / Owner][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\WINDOWS\system32\UNISPIM6.IME]  [±±¾©×Ϲ⻪ÓîÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾, 6.0.0.6138]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.5.29]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 8, 96]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_01.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 20]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_01.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
    [C:\WINDOWS\DOWNLO~1\BaiDuBar.dll]  [, 2, 0, 0, 0]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL]  [Kingsoft Corporation, 2008,04,15,2]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll]  [Kingsoft Corporation, 2008,08,01,516]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL]  [Kingsoft Corporation, 2008,06,24,415]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll]  [Kingsoft Corporation, 2008,06,24,415]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL]  [Kingsoft Corporation, 2008,06,24,415]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Ucxgglb2008\UC\UCIdleHook.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 0, 1, 0]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx]  [Adobe Systems, Inc., 9,0,124,0]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 4, 22]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
[PID: 1356 / Owner][C:\Program Files\Ucxgglb2008\UC\UCChatRoom.exe]  [N/A, ]
    [C:\Program Files\Ucxgglb2008\UC\vcl60.bpl]  [Borland Software Corporation, 6.0.6.240]
    [C:\Program Files\Ucxgglb2008\UC\rtl60.bpl]  [Borland Software Corporation, 6.0.6.243]
    [C:\Program Files\Ucxgglb2008\UC\vclie60.bpl]  [Borland Software Corporation, 6.0.6.163]
    [C:\Program Files\Ucxgglb2008\UC\bcbie60.bpl]  [N/A, ]
    [C:\Program Files\Ucxgglb2008\UC\BORLNDMM.DLL]  [Borland Software Corporation, 6.0.10.157]
    [C:\Program Files\Ucxgglb2008\UC\CC3260MT.DLL]  [Borland Corporation, 0.0.0.0 (informal build)]
    [C:\Program Files\Ucxgglb2008\UC\LANGUAGERES.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.1.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCUDPMESSAGER.DLL]  [Beijing Sina Information Technology Co.,Ltd
, 1.2.0.0]
    [C:\Program Files\Ucxgglb2008\UC\STLPMT45.DLL]  [N/A, ]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\WINDOWS\system32\UNISPIM6.IME]  [±±¾©×Ϲ⻪ÓîÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾, 6.0.0.6138]
    [C:\Program Files\Ucxgglb2008\UC\UCTCPMESSAGER.DLL]  [Beijing Sina Information Technology Co.,Ltd, 1.1.0.0]
    [C:\Program Files\Ucxgglb2008\UC\UCAPI.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1.1.0.0]
    [C:\Program Files\Ucxgglb2008\UC\RICHED20.DLL]  [N/A, ]
    [C:\Program Files\Ucxgglb2008\UC\Riched20bak.dll]  [Microsoft Corporation, 5.30.23.1205]
    [C:\Program Files\Ucxgglb2008\UC\UCPlugin.dll]  [·ÉÌ칤×÷ÊÒ, 1, 0, 0, 1]
    [C:\Program Files\Ucxgglb2008\UC\ipsearch.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Ucxgglb2008\UC\UCSocket.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 1, 21, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCHttpDl.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 1, 9, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCIdleHook.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 0, 1, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCAudioChat.dll]  [Beijing Sina Information Technology Co.,Ltd, 2007, 6, 5, 0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Ucxgglb2008\UC\UcMediaPlayer.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 2, 3, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCMediaPlayer2.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 0, 0, 1]
    [C:\Program Files\Ucxgglb2008\UC\UCVideo.DLL]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 4, 6, 3, 0]
    [C:\Program Files\Ucxgglb2008\UC\UCProcess.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 0, 0, 1]
    [C:\Program Files\Ucxgglb2008\UC\UCMediaSaver.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 2, 0, 0]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
[PID: 3792 / Owner][F:\Downloads\sreng2\SREngLdr.EXE]  [Smallfrogs Studio, 2.6.12.1018]
[PID: 3804 / Owner][F:\Downloads\sreng2\SREbc2bb490.EXE]  [Smallfrogs Studio, 2.6.12.1018]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
    [C:\WINDOWS\system32\UNISPIM6.IME]  [±±¾©×Ϲ⻪ÓîÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾, 6.0.0.6138]
    [C:\Program Files\Ucxgglb2008\UC\UCIdleHook.dll]  [±±¾©ÐÂÀËÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾, 1, 0, 1, 0]
    [F:\Downloads\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    [C:\PROGRA~1\MICROS~2\OFFICE11\MCPS.DLL]  [Microsoft Corporation, 11.0.8164]

==================================
Îļþ¹ØÁª
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock ÌṩÕß
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS Îļþ
127.0.0.1       localhost

==================================
½ø³ÌÌØÈ¨É¨Ãè
ÌØÊâÌØÈ¨±»ÔÊÐí£º SeLoadDriverPrivilege [PID = 1624, C:\PROGRAM FILES\ÁªÏë\ÁªÏë±ê×¼¹¦ÄܼüÅÌ\SKDAEMOND.EXE]
ÌØÊâÌØÈ¨±»ÔÊÐí£º SeLoadDriverPrivilege [PID = 1640, C:\WINDOWS\ZSSNP211.EXE]
ÌØÊâÌØÈ¨±»ÔÊÐí£º SeLoadDriverPrivilege [PID = 1648, C:\WINDOWS\DOMINO.EXE]
ÌØÊâÌØÈ¨±»ÔÊÐí£º SeLoadDriverPrivilege [PID = 1688, C:\PROGRAM FILES\9158VIRTUALCAMERA\9158NOTIFY.EXE]
ÌØÊâÌØÈ¨±»ÔÊÐí£º SeLoadDriverPrivilege [PID = 1744, C:\PROGRAM FILES\SUPER RABBIT\MAGICSET\SRIECLI.EXE]
ÌØÊâÌØÈ¨±»ÔÊÐí£º SeLoadDriverPrivilege [PID = 1796, C:\PROGRAM FILES\VIA\RAID\RAID_TOOL.EXE]
ÌØÊâÌØÈ¨±»ÔÊÐí£º SeLoadDriverPrivilege [PID = 564, C:\PROGRAM FILES\UCXGGLB2008\UC\UC2008Ðǹâ¹ÜÀí°æ.EXE]
ÌØÊâÌØÈ¨±»ÔÊÐí£º SeLoadDriverPrivilege [PID = 3856, C:\PROGRAM FILES\UCXGGLB2008\UC\UC2008Ðǹâ¹ÜÀí°æ.EXE]
ÌØÊâÌØÈ¨±»ÔÊÐí£º SeLoadDriverPrivilege [PID = 1356, C:\PROGRAM FILES\UCXGGLB2008\UC\UCCHATROOM.EXE]
ÌØÊâÌØÈ¨±»ÔÊÐí£º SeLoadDriverPrivilege [PID = 3792, F:\DOWNLOADS\SRENG2\SRENGLDR.EXE]

==================================
API HOOK
N/A

==================================
Òþ²Ø½ø³Ì
N/A

==================================

TOP

°ßÖñÃŶ¼À´¿´¿´``````
ÓÐû°ì·¨°ïÎÒÃǰ¡``

TOP

»Ø¸´ 41Â¥ µÄÌû×Ó

ÎÒ²»ÊÇÀÏʦ
ÎÒÊǸöÐÂÊÖ
ÄãÌ«¸ß̧ÎÒÁ˰É

TOP

ÐÂÊÖÒ²ºÃ¹ýÎÒÃÇÕâЩС°×°¡`````

TOP

¸ñÅÌ֨װ£¬Ã»°ì·¨¾ÍÕâ¾ÍÕâÑù
ÄãµÄÄÇÒ»½££¬´ÌµÄÌ«Éî¡­¡­

TOP

²»ÊǰÉ````ÕâÑùÌ«²ÐÈÌÁË````
ÎÒ»áËÀµÄºÜ²ÒµÄ```

TOP

ÎҵIJ¡¶¾Ô­À´Ò»½øÈëUCÁÄÌìÊҾͳöÏÖ²¡¶¾£¬ÏÔʾ½Å±¾´íÎ󣬺óÀ´ÎÒ°ÑUCͨͨɾ³ýÁË£¬ÖØÐÂÏÂÔØ£¬¾ÍûÓÐÁË¡£Õ⼸Ì죬Õâ¸ö²¡¶¾£¬ÔÚÎÒ´ò¿ª9158ÐéÄâÊÓÆµµÄʱºò¾Í³öÏÖÁË£¬ÇóÖú¸ßÊ־ȾÈÎÒÃǰ¡¡£

TOP

Ïȱð֨װ
ÊÔ¹ý 21Â¥µÄ·½·¨ÁËÂð£¿

TOP

ÊÔ¹ýÁË```ûÓÃ````
³¬¼¶ÍçÇ¿µÄ²¡¶¾``````ɱ²»ËÀµÄСǿ`````

TOP

³¢ÊÔDOSɱ¶¾
Èý·ÖÖÓÇáËÉѧ»áDOSÏÂɱ¶¾
¡¡¡¡Èç¹ûÄã»áDOSɱ¶¾£¬ÇëÌø¹ý±¾Ìû±ð¿´£¬ÕâÑù¿ÉÒÔ½ÚÔ¼ÄãµÄʱ¼ä£¬Èç¹ûÄã²»»áDOS£¬ÓÃÁ˺ܾõÄkv»¹Ã»Óп´µ½¹ýËüµÄDOSɱ¶¾½çÃæ£¬ÄÇôÏÂÃæµÄÎÄ×Ö¿ÉÒÔ°ïÉÏÄãµÄ棬ѧ»áDOSɱ¶¾£¬ÕâÖ»ÒªÈý·ÖÖÓµÄʱ¼ä£¬¾ÍÕâô¼òµ¥£¡
¡¡¡¡¼òµ¥¸ÅÄDOS,DISKOPERATESYSTEMµÄËõд,È«Ãû½Ð´ÅÅ̲Ù×÷ϵͳ¡£
¡¡¡¡µÚÒ»²½£º½øµÃÈ¥³öµÃÀ´
¡¡¡¡½øÈëDOS:ÓÐÁ½¸ö°ì·¨£º1.µã¡¾¿ªÊ¼¡¿¡¢¡¾¹Ø±Õϵͳ¡¿¡¢Ñ¡¡¾ÖØÐÂÆô¶¯ÏµÍ³²¢Çл»µ½MS-DOS·½Ê½¡¿2.Æô¶¯¼ÆËã»úµÄʱºò°´×¡Ctrl¼ü²»·Å£¬µÈÑ¡Ôñ½çÃæ³öÀ´ºó£¬°´¼üÅÌÉϵÄÉÏÏ·½Ïò¼ü£¬Ñ¡CommandPromptonly£¬»Ø³µ¡£ËµÃ÷£ºÈç¹ûÄãÓõÄÊÇwin2000ºÍwinxp£¬ÒªÏȽøÈëwin98²ÅÐС£
¡¡¡¡×îºÃµÄ°ì·¨£¬¾ÍÊÇÔÚϵͳ¸É¾»µÄʱºò(»ò±ðµÄ»úÆ÷£¬×öÒ»ÕÅDOSÆô¶¯ÅÌ£¬ÓÃËüÆô¶¯ÏµÍ³£¬¿ÉÒÔ±£Ö¤Äãɱ¶¾µÄÍêÃÀЧ¹û£¡Ò²¾ÍÊÇ˵£¬ÀûÓÃÓ²ÅÌÆô¶¯µÄʱºò£¬ÇÐÈëDOS²Ù×÷ϵͳ£¨±ÈÉÏÃæ£ºµÈÑ¡Ôñ½çÃæ³öÀ´ºó£¬°´¼üÅÌÉϵÄÉÏÏ·½Ïò¼ü£¬Ñ¡CommandPromptonly£¬»Ø³µ¡££©ÒªÓÐЧµØ¶à£¡
¡¡¡¡Í˳öDOS:¸Õ²ÅÎÒÃǽøÈëÁËDOS£¬Äã¿´µ½µÄ¿ÉÄÜÊÇc:\WINDOWS>,ËüµÄÒâ˼ÊÇÄãÏÖÔÚµÄλÖÃÔÚcÅ̵ÄWINDOWSĿ¼ÏÂ(Èç¹ûÄãÓÃÉÏÃæµÚ¶þ¸ö·½·¨½øÈëdos£¬Äã¿´µ½µÄ»áÊÇc:\>),ÏÖÔÚÔÚËüºóÃæ½ô¸ú×ÅÊäÈë¸öÃüÁîwin£¬ÏµÍ³¾Í»áÍ˳öDOS·µ»Øµ½ÄãÊìϤµÄwindows½çÃæ¡£×¢Ò⣬µ±ÄãÊäÈëÁËwinºó¿ÉÄÜ¿´µ½µçÄÔûʲô·´Ó¦£¬²»ÓÃ׿±£¬µçÄÔû»µ£¬±£³ÖÄÍÐĶàµÈµÈ¾ÍÐÐÁË¡£winÕâ¸öÃüÁîºÜºÃ¼Ç£¬win¾ÍÊÇwindowsÊÇËõд¡£
¡¡¡¡µ½´ËÄãÒѾ­»á½øÈëºÍÍ˳öDOSÁË£¬ÐÄÀïÓе×ÁË£¬¹§Ï²£¡ÄãÒѾ­³É¹¦ÁË50£¥£¡
¡¡¡¡µÚ¶þ²½£ºÔÚdosϵ÷³ökvµÄdosɱ¶¾³ÌÐò½øÐÐɱ¶¾
¡¡¡¡1.ÔÚwindowsÏ£¬ÕÒµ½ÄãkvµÄdosɱ¶¾³ÌÐòµÄλÖã¬ËüÔÚÄãkvɱ¶¾Èí¼þµÄ°²×°Ä¿Â¼Ï£¬kv2005dosɱ¶¾³ÌÐòµÄÎļþÃû½ÐKVDOS.exe£¬ÎÒÃÇÿ¸öÈ˰²×°kvµÄλÖò»Ò»Ñù£¬Ä¬ÈÏÔÚ°²×°ÔÚcÅÌ£¬×Ô¶¨Ò尲װλÖÃÿÈË×°µÄ²»Ò»Ñù£¬±ÈÈç˵ÎÒ°²×°ÔÚGÅÌ£¬ÄÇôKVDOS.exeµÄλÖþÍÊÇG:\KV2005\KVDOS.exe£¬ÏÖÔÚÄñʼÇÏÂÕâ¸öλÖá£
¡¡¡¡2.ÓÃÉÏÃæËµµÄ°ì·¨½øÈëDOS,ÔÚ¹â±êÌáʾ·ûºÅÏÂÊäÈë¸Õ²Å¼ÇϵÄλÖ㬻سµ£¬Äã»á¿´µ½dosÔÚ¼ÓÔØkvµÄdosɱ¶¾³ÌÐò£¬¼¸ÃëÖÓÖ®ÄÚÄã¾Í¿ÉÒÔ½øÈëkvµÄdosɱ¶¾½çÃæ£¬Ñ¡ÔñҪɱ¶¾µÄÅÌ»òҪɱ¶¾µÄÎļþ¼Ð¡¢Îļþ¾Í¿ÉÒÔ¿ªÊ¼É±¶¾ÁË¡£dosÏÂɱ¶¾¿ÉÒ԰Ѷ¾É±µÃ¸ü³¹µ×£¬¹§Ï²Ä㣬ÏÖÔÚ¿ÉÒÔÔÚdosÏÂɱ¶¾ÁË¡£
ÄãµÄÄÇÒ»½££¬´ÌµÄÌ«Éî¡­¡­

TOP

ÖØÆôһϣ¬¿´ÓÐʲôЧ¹û
×¢Òâ¶¾°ÔµÄÇÀɱ

TOP

Çý¶¯£¨°²È«Ä£Ê½ÏÂɾ³ý£©

C:\WINDOWS\system32\drivers\fhzl.ahc

C:\WINDOWS\system32\drivers\shine.ahc

¾­°ÑÕâÁ½Ïî©ÁË {yct55} »¹ÊÇÐÂÊÖ°¢£¡°¦

TOP

ÓôÃÆ`````»¹ÊÇɱ²»ËÀ`````
ÉúÃüÁ¦ºÃÍçÇ¿````

TOP

............
ÕÒÆäËûÔ­Òò°É
ÐÞ¸´ÏÂlsp
¿´ÓÐÔÚºǫ́ÔËÐеÄä¯ÀÀÆ÷ûÓÐ
¶¾°ÔµÄÇÀɱÈÕÖÁ£¿£¿£¿

TOP

ÇÀɱÈÕÖ¾£º
²¡¶¾        2008-08-09  19:14:19        C:\WINDOWS\system32\wbzonebar.dll        SpyWare        Çå³ý³É¹¦       
²¡¶¾        2008-08-09  18:48:41        C:\WINDOWS\system32\BoBoTurbo\1.KAB        SpyWare        Çå³ý³É¹¦       
²¡¶¾        2008-08-09  18:48:41        C:\WINDOWS\system32\BoBoTurbo\BoBoTurbo.exe        SpyWare        Çå³ý³É¹¦       
²¡¶¾        2008-08-08  17:37:18        C:\WINDOWS\system32\wbzonebar.dll        SpyWare        Çå³ý³É¹¦       
²¡¶¾        2008-08-08  09:58:23        C:\WINDOWS\system32\wbzonebar.dll        SpyWare        Çå³ý³É¹¦       
²¡¶¾        2008-08-08  08:50:36        C:\WINDOWS\system32\drivers\ybuolya.sys        Win32.Troj.AgentT.ab.49088        Çå³ý³É¹¦       
²¡¶¾        2008-08-07  22:04:42        C:\WINDOWS\SYSTEM32\TYBPQUHM.DLL        Win32.Troj.BhoT.ab.159744        Çå³ý³É¹¦

TOP

½ðɽɱ²»ÁËɱÁË»¹ÔÚ...

²¡¶¾        2008-08-09  20:51:03        C:\System Volume Information\_restore{F3E41B89-0B5F-4CAA-BE79-B310608D5707}\RP165\A0114996.exe\$TEMP\59_7833.exe        Win32.Troj.JunkUndefT.hg.163840        ·¢ÏÖ²¡¶¾       
²¡¶¾        2008-08-09  20:51:03        C:\System Volume Information\_restore{F3E41B89-0B5F-4CAA-BE79-B310608D5707}\RP165\A0114996.exe\$TEMP\$TEMP\63.exe        Win32.Troj.RootKitT.xd.89980        ·¢ÏÖ²¡¶¾       
²¡¶¾        2008-08-10  20:00:09        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\IGPY27V4\flashCA065P48.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-10  20:00:08        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\8TIGDISG\17[1].htmÖР       JS.Agent.mv.1880        ´¦Àí³É¹¦£¨²Ù×÷£ºÇå³ý£©       
²¡¶¾        2008-08-10  20:00:08        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\8TIGDISG\17[1].htmÖР       JS.Agent.mv.1880        ´¦Àí³É¹¦£¨²Ù×÷£ºÇå³ý£©       
²¡¶¾        2008-08-10  20:00:06        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\8TIGDISG\flashCAU0KM2M.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
ÐÅÏ¢        2008-08-10  19:59:49        ½ðɽ¶¾°ÔÎļþʵʱ·À¶¾±»Í¨ÖªÖØÆô                       
²¡¶¾        2008-08-10  19:58:35        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\V9LO128R\flashCAMY280W.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-10  19:58:35        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\V9LO128R\flashCA1409SV.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-10  19:58:34        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\V9LO128R\17[1].htmÖР       JS.Agent.mv.1880        ´¦Àí³É¹¦£¨²Ù×÷£ºÇå³ý£©       
²¡¶¾        2008-08-10  19:58:30        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\IGPY27V4\flashCA8XO6OA.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-10  19:58:30        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\8TIGDISG\flashCA4HSB8G.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-10  19:58:30        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\8TIGDISG\17[1].htmÖР       JS.Agent.mv.1880        ´¦Àí³É¹¦£¨²Ù×÷£ºÇå³ý£©       
²¡¶¾        2008-08-10  19:58:26        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\V9LO128R\flashCASE2TK7.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-10  19:58:26        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\IGPY27V4\flashCAKQUKQ4.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-10  19:58:26        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\IGPY27V4\17[2].htmÖР       JS.Agent.mv.1880        ´¦Àí³É¹¦£¨²Ù×÷£ºÇå³ý£©       
²¡¶¾        2008-08-10  19:58:22        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\IGPY27V4\17[1].htmÖР       JS.Agent.mv.1880        ´¦Àí³É¹¦£¨²Ù×÷£ºÇå³ý£©       
²¡¶¾        2008-08-10  19:58:20        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\IGPY27V4\17[2].htmÖР       JS.Agent.mv.1880        ´¦Àí³É¹¦£¨²Ù×÷£ºÇå³ý£©       
²¡¶¾        2008-08-10  19:58:18        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\MUH6ICRL\flashCAFJ25EA.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-10  19:58:18        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\MUH6ICRL\flashCAC7IQF2.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-10  19:58:18        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\IGPY27V4\17[1].htmÖР       JS.Agent.mv.1880        ´¦Àí³É¹¦£¨²Ù×÷£ºÇå³ý£©       
²¡¶¾        2008-08-10  19:58:16        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\IGPY27V4\flashCAM0KRJZ.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-10  19:58:16        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\MUH6ICRL\flashCA3UBR3E.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-10  19:58:16        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\8TIGDISG\17[1].htmÖР       JS.Agent.mv.1880        ´¦Àí³É¹¦£¨²Ù×÷£ºÇå³ý£©       
²¡¶¾        2008-08-10  19:58:12        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\V9LO128R\flashCAFMEPZV.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-10  19:58:12        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\IGPY27V4\flashCAOBR76A.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-10  19:58:10        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\V9LO128R\17[2].htmÖР       JS.Agent.mv.1880        ´¦Àí³É¹¦£¨²Ù×÷£ºÇå³ý£©       
ÐÅÏ¢        2008-08-10  19:56:35        KWatch3.SYS¿ªÊ¼ÔËÐР                      
ÐÅÏ¢        2008-08-10  19:56:35        KAEngine³õʼ»¯³É¹¦                       
ÐÅÏ¢        2008-08-10  19:55:57        KWatch3.SYS³õʼ»¯³É¹¦                       
ÐÅÏ¢        2008-08-10  19:55:57        KWatch3.SYS¿ªÊ¼¼ÓÔØ                       
ÐÅÏ¢        2008-08-10  19:55:57        KAVIPC¿ªÊ¼ÔËÐР                      
ÐÅÏ¢        2008-08-10  19:55:57        KAVIPC³õʼ»¯³É¹¦                       
ÐÅÏ¢        2008-08-10  19:55:57        KAVIPC¿ªÊ¼¼ÓÔØ                       
ÐÅÏ¢        2008-08-10  19:55:57        Windows Security Center³õʼ»¯³É¹¦                       
ÐÅÏ¢        2008-08-10  19:55:57        Restore-Module³õʼ»¯³É¹¦                       
ÐÅÏ¢        2008-08-10  19:55:57        Windows Logon Splash³õʼ»¯³É¹¦                       
ÐÅÏ¢        2008-08-10  19:55:57        ½ðɽ¶¾°ÔÎļþʵʱ·À¶¾¿ªÊ¼¼ÓÔØ                       
²¡¶¾        2008-08-09  22:14:13        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\V9LO128R\flashCACI6C8C.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-09  22:14:13        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\V9LO128R\flashCAW36KFU.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-09  22:14:13        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\V9LO128R\17[1].htmÖР       JS.Agent.mv.1880        ´¦Àí³É¹¦£¨²Ù×÷£ºÇå³ý£©       
²¡¶¾        2008-08-09  22:14:06        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\MUH6ICRL\flashCAU9SYPI.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-09  22:14:06        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\MUH6ICRL\flashCALXCRVY.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-09  22:14:05        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\IGPY27V4\17[1].htmÖР       JS.Agent.mv.1880        ´¦Àí³É¹¦£¨²Ù×÷£ºÇå³ý£©       
²¡¶¾        2008-08-09  22:12:44        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\8TIGDISG\flashCACOEY73.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-09  22:12:44        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\MUH6ICRL\flashCAJJULDO.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-09  22:12:44        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\MUH6ICRL\17[2].htmÖР       JS.Agent.mv.1880        ´¦Àí³É¹¦£¨²Ù×÷£ºÇå³ý£©       
²¡¶¾        2008-08-09  22:12:07        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\8TIGDISG\flashCAP9IH7E.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-09  22:12:07        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\8TIGDISG\flashCAPRQBQX.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-09  22:12:06        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\MUH6ICRL\17[1].htmÖР       JS.Agent.mv.1880        ´¦Àí³É¹¦£¨²Ù×÷£ºÇå³ý£©       
²¡¶¾        2008-08-09  22:10:00        ²¡¶¾ÔÚÎļþC:\Documents and Settings\cbkj\Local Settings\Temporary Internet Files\Content.IE5\V9LO128R\flashCAI149FI.htmÖР       JS.Downloader.fv.582        ´¦Àí³É¹¦£¨²Ù×÷£ºÉ¾³ý£©       
²¡¶¾        2008-08-09  22:09:59        ²¡¶¾ÔÚÎļ