system.exe,alien32.exe,ftsKetNt.7ps,SysKetNt.Sys, iexpe.exe等1
endurer
2009-01-05 第1版
昨天中午,一位网友说他电脑中IE首页被强制修改为hxxp://,输入法无法切换,请偶帮忙检修。
使用pe_xscan 扫描log并分析,发现如下可疑项(进程模块部分有省略):
pe_xscan 08-12-29 by Purple Endurer
2008-12-5 6:20:15
Windows XP Service Pack 2(5.1.2600)
MSIE:6.0.2900.2180
管理员用户组
正常模式
[System Process] * 0
C:/WINDOWS/system32/HBmhly.dll | 2008-12-5 5:44:14
C:/WINDOWS/system32/HBXY2.dll | 2008-12-4 9:52:46
C:/WINDOWS/system32/HBZG.dll | 2008-12-4 17:26:54
C:/WINDOWS/system32/HBXMJ.dll | 2008-12-4 9:50:52
C:/WINDOWS/system32/C9B17E4E.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/E531B068.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/7F99099C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F7902582.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1BDB68CE.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/2A5479B5.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AF73E0FB.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1BE1B1E8.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/D83334D5.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/03A1D295.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/9998A2F1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/B2D304CA.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/CA66726A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F21511FC.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/515E5B45.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/56D809D2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/ED931691.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/D38C7BBA.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/143CE310.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/63F62981.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/518F57D3.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/7C0DFD7B.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/41F8FCF3.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/5A0F83A6.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/405BF191.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F5AFAFA3.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/4E0FA2F2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/C6098E7C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/715989E4.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/957E8C5A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F1BF7C7A.dll | 2008-8-14 21:42:28
C:/WINDOWS/System32/csrss.exe* 536 | 2004-8-16 8:39:14 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Client Server Runtime Process | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | CSRSS.Exe | CSRSS.Exe
C:/WINDOWS/system32/csrss.dll | 2008-12-5 3:30:7
C:/WINDOWS/system32/sh14038.dll | 2006-2-14 14:24:46
C:/WINDOWS/System32/winlogon.exe* 560 | 2004-8-16 8:39:24 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Windows NT Logon Application | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | winlogon | WINLOGON.EXE
C:/WINDOWS/system32/F1BF7C7A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/957E8C5A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/715989E4.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/C6098E7C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/4E0FA2F2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F5AFAFA3.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/405BF191.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/5A0F83A6.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/41F8FCF3.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/7C0DFD7B.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/518F57D3.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/63F62981.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/143CE310.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/D38C7BBA.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/ED931691.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/56D809D2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/515E5B45.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F21511FC.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/CA66726A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/B2D304CA.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/9998A2F1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/03A1D295.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/D83334D5.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1BE1B1E8.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AF73E0FB.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/2A5479B5.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1BDB68CE.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F7902582.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/7F99099C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/E531B068.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/C9B17E4E.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/0C008684.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/HBmhly.dll | 2008-12-5 5:44:14
C:/WINDOWS/system32/HBXY2.dll | 2008-12-4 9:52:46
C:/WINDOWS/system32/HBWULIN2.dll | 2008-12-4 17:26:34
C:/WINDOWS/system32/HBKDXY.dll | 2008-12-5 5:46:50
C:/WINDOWS/system32/HBASKTAO.dll | 2008-12-5 5:46:16
C:/WINDOWS/system32/HBZHUXIAN.dll | 2008-12-5 5:46:4
C:/WINDOWS/system32/HBWOW.dll | 2008-12-4 9:49:48
C:/WINDOWS/system32/HBCHIBI.dll | 2008-12-5 5:44:36
C:/WINDOWS/system32/HBZG.dll | 2008-12-4 17:26:54
C:/WINDOWS/system32/HBXMJ.dll | 2008-12-4 9:50:52
C:/WINDOWS/system32/78549EA1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1325C941.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/19A916DC.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/C406A026.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/58E4F255.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/6027FB67.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/52C1B2E2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AAF7C3FD.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/0E88951F.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AEA214BF.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/4A7C6D50.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/75F56ED4.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1D2317A1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/CE544718.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/EFE5D671.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/8D668351.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/B188DCF7.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/97FEF446.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/9AB77B8C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AC8EEE47.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/EB8F6190.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/727ED075.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/FDB30DD7.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/5CBCDC25.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/B8DFE7B0.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F68EF44D.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/E5437B5A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/0247AA90.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/986F4AAC.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/5D4913C9.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/9F5602BA.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AD8D7C15.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/CB91C558.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AEC603F1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/31BDF495.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/189F36EE.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/75548A73.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/521B449B.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/92BFE0C2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/62434D8C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/7650CBC7.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/89F95F77.dll | 2008-8-14 21:42:28
C:/WINDOWS/System32/services.exe* 604 | 2004-8-16 8:39:24 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Services and Controller app | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | services.exe | services.exe
C:/WINDOWS/system32/F1BF7C7A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/957E8C5A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/715989E4.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/C6098E7C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/4E0FA2F2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F5AFAFA3.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/405BF191.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/5A0F83A6.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/41F8FCF3.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/7C0DFD7B.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/518F57D3.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/63F62981.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/143CE310.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/D38C7BBA.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/ED931691.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/56D809D2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/515E5B45.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F21511FC.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/CA66726A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/B2D304CA.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/9998A2F1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/03A1D295.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/D83334D5.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1BE1B1E8.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AF73E0FB.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/2A5479B5.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1BDB68CE.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F7902582.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/7F99099C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/E531B068.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/C9B17E4E.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/0C008684.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/HBmhly.dll | 2008-12-5 5:44:14
C:/WINDOWS/system32/HBXY2.dll | 2008-12-4 9:52:46
C:/WINDOWS/system32/HBWULIN2.dll | 2008-12-4 17:26:34
C:/WINDOWS/system32/HBKDXY.dll | 2008-12-5 5:46:50
C:/WINDOWS/system32/HBASKTAO.dll | 2008-12-5 5:46:16
C:/WINDOWS/system32/HBZHUXIAN.dll | 2008-12-5 5:46:4
C:/WINDOWS/system32/HBWOW.dll | 2008-12-4 9:49:48
C:/WINDOWS/system32/HBCHIBI.dll | 2008-12-5 5:44:36
C:/WINDOWS/system32/HBZG.dll | 2008-12-4 17:26:54
C:/WINDOWS/system32/HBXMJ.dll | 2008-12-4 9:50:52
C:/WINDOWS/system32/78549EA1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1325C941.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/19A916DC.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/C406A026.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/58E4F255.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/6027FB67.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/52C1B2E2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AAF7C3FD.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/0E88951F.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AEA214BF.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/4A7C6D50.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/75F56ED4.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1D2317A1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/CE544718.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/EFE5D671.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/8D668351.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/B188DCF7.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/97FEF446.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/9AB77B8C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AC8EEE47.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/EB8F6190.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/727ED075.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/FDB30DD7.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/5CBCDC25.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/B8DFE7B0.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F68EF44D.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/E5437B5A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/0247AA90.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/986F4AAC.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/5D4913C9.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/9F5602BA.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AD8D7C15.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/CB91C558.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AEC603F1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/31BDF495.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/189F36EE.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/75548A73.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/521B449B.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/92BFE0C2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/62434D8C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/7650CBC7.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/89F95F77.dll | 2008-8-14 21:42:28
C:/WINDOWS/System32/lsass.exe* 616 | 2004-8-16 8:39:16 | Microsoft? Windows? Operating System | 5.1.2600.2180 | LSA Shell (Export Version) | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | lsass.exe | lsass.exe
C:/WINDOWS/system32/F1BF7C7A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/957E8C5A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/715989E4.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/C6098E7C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/4E0FA2F2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F5AFAFA3.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/405BF191.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/5A0F83A6.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/41F8FCF3.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/7C0DFD7B.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/518F57D3.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/63F62981.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/143CE310.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/D38C7BBA.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/ED931691.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/56D809D2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/515E5B45.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F21511FC.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/CA66726A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/B2D304CA.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/9998A2F1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/03A1D295.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/D83334D5.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1BE1B1E8.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AF73E0FB.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/2A5479B5.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1BDB68CE.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F7902582.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/7F99099C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/E531B068.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/C9B17E4E.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/0C008684.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/HBmhly.dll | 2008-12-5 5:44:14
C:/WINDOWS/system32/HBXY2.dll | 2008-12-4 9:52:46
C:/WINDOWS/system32/HBWULIN2.dll | 2008-12-4 17:26:34
C:/WINDOWS/system32/HBKDXY.dll | 2008-12-5 5:46:50
C:/WINDOWS/system32/HBASKTAO.dll | 2008-12-5 5:46:16
C:/WINDOWS/system32/HBZHUXIAN.dll | 2008-12-5 5:46:4
C:/WINDOWS/system32/HBWOW.dll | 2008-12-4 9:49:48
C:/WINDOWS/system32/HBCHIBI.dll | 2008-12-5 5:44:36
C:/WINDOWS/system32/HBZG.dll | 2008-12-4 17:26:54
C:/WINDOWS/system32/HBXMJ.dll | 2008-12-4 9:50:52
C:/WINDOWS/system32/78549EA1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1325C941.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/19A916DC.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/C406A026.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/58E4F255.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/6027FB67.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/52C1B2E2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AAF7C3FD.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/0E88951F.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AEA214BF.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/4A7C6D50.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/75F56ED4.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1D2317A1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/CE544718.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/EFE5D671.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/8D668351.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/B188DCF7.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/97FEF446.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/9AB77B8C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AC8EEE47.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/EB8F6190.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/727ED075.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/FDB30DD7.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/5CBCDC25.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/B8DFE7B0.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F68EF44D.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/E5437B5A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/0247AA90.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/986F4AAC.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/5D4913C9.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/9F5602BA.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AD8D7C15.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/CB91C558.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AEC603F1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/31BDF495.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/189F36EE.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/75548A73.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/521B449B.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/92BFE0C2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/62434D8C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/7650CBC7.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/89F95F77.dll | 2008-8-14 21:42:28
C:/WINDOWS/System32/svchost.exe* 788 | 2004-8-16 8:39:24 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe
C:/WINDOWS/system32/F1BF7C7A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/957E8C5A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/715989E4.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/C6098E7C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/4E0FA2F2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F5AFAFA3.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/405BF191.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/5A0F83A6.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/41F8FCF3.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/7C0DFD7B.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/518F57D3.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/63F62981.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/143CE310.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/D38C7BBA.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/ED931691.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/56D809D2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/515E5B45.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F21511FC.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/CA66726A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/B2D304CA.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/9998A2F1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/03A1D295.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/D83334D5.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1BE1B1E8.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AF73E0FB.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/2A5479B5.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1BDB68CE.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F7902582.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/7F99099C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/E531B068.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/C9B17E4E.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/0C008684.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/HBmhly.dll | 2008-12-5 5:44:14
C:/WINDOWS/system32/HBXY2.dll | 2008-12-4 9:52:46
C:/WINDOWS/system32/HBWULIN2.dll | 2008-12-4 17:26:34
C:/WINDOWS/system32/HBKDXY.dll | 2008-12-5 5:46:50
C:/WINDOWS/system32/HBASKTAO.dll | 2008-12-5 5:46:16
C:/WINDOWS/system32/HBZHUXIAN.dll | 2008-12-5 5:46:4
C:/WINDOWS/system32/HBWOW.dll | 2008-12-4 9:49:48
C:/WINDOWS/system32/HBCHIBI.dll | 2008-12-5 5:44:36
C:/WINDOWS/system32/HBZG.dll | 2008-12-4 17:26:54
C:/WINDOWS/system32/HBXMJ.dll | 2008-12-4 9:50:52
C:/WINDOWS/system32/78549EA1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1325C941.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/19A916DC.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/C406A026.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/58E4F255.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/6027FB67.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/52C1B2E2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AAF7C3FD.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/0E88951F.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AEA214BF.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/4A7C6D50.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/75F56ED4.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/1D2317A1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/CE544718.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/EFE5D671.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/8D668351.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/B188DCF7.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/97FEF446.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/9AB77B8C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AC8EEE47.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/EB8F6190.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/727ED075.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/FDB30DD7.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/5CBCDC25.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/B8DFE7B0.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/F68EF44D.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/E5437B5A.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/0247AA90.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/986F4AAC.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/5D4913C9.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/9F5602BA.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AD8D7C15.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/CB91C558.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/AEC603F1.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/31BDF495.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/189F36EE.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/75548A73.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/521B449B.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/92BFE0C2.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/62434D8C.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/7650CBC7.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/89F95F77.dll | 2008-8-14 21:42:28
C:/WINDOWS/system32/spcss.dll | 2006-2-14 14:24:46 | Microsoft? Windows? Operating System | 5.1.2600.2846 | Distributed COM Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2846 (xpsp.060213-1526) | Microsoft Corporation| ? | rpcss.dll | rpcss.dll
C:/WINDOWS/system32/alien32.dll
F2 - REG: system.ini: UserInit = <C:/WINDOWS/system32/Userinit.exe>
F3 - REG: win.ini: load=C:/WINDOWS/system3238C2.exe
O2 - BHO BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} =C:/PROGRA~1/baidu/bar/baidubar.dll | 2008-11-11 7:9:54
O2 - BHO - {7D182ECE-BFD3-4482-902F-035F4CE9A3C4} =C:/Program Files/Internet Explorer/ftsKetNt.7ps | 2008-12-4 17:19:22
O2 - BHO - {EF8EFC85-0038-479B-BB0E-B0A52A15CECA} =C:/Program Files/Internet Explorer/SysKetNt.Sys | 2008-12-4 9:54:44
O3 - IE工具栏: - {B580CF65-E151-49C3-B73F-70B13FCA8E86} =C:/PROGRA~1/baidu/bar/baidubar.dll | 2008-11-11 7:9:54
O4 - HKLM/../Run: [HBService32] System.exe
O4 - HKLM/../Policies/Explorer/Run: [nwiz] alien32.exe
O18 - 协议: qyl(Data Pluggable Protocol) - {C79BF22F-25C4-4D3D-8183-14149EAB9C0C} -C:/WINDOWS/system32/qylprotocol.dll | 2008-1-24 19:4:36
O20 - AppInit_DLLs = HBmhly.dll,HBXY2.dll,HBWULIN2.dll,HBKDXY.dll,HBASKTAO.dll,HBZHUXIAN.dll,HBWOW.dll,HBCHIBI.dll,HBZG.dll,HBXMJ.dll,78549EA1.dll,1325C941.dll,19A916DC.dll,C406A026.dll,58E4F255.dll,6027FB67.dll,52C1B2E2.dll,AAF7C3FD.dll,0E88951F.dll,AEA214BF.dll,4A7C6D50.dll,75F56ED4.dll,1D2317A1.dll,CE544718.dll,EFE5D671.dll,8D668351.dll,B188DCF7.dll,97FEF446.dll,9AB77B8C.dll,AC8EEE47.dll,EB8F6190.dll,727ED075.dll,FDB30DD7.dll,5CBCDC25.dll,B8DFE7B0.dll,F68EF44D.dll,E5437B5A.dll,0247AA90.dll,986F4AAC.dll,5D4913C9.dll,9F5602BA.dll,AD8D7C15.dll,CB91C558.dll,AEC603F1.dll,31BDF495.dll,189F36EE.dll,75548A73.dll,521B449B.dll,92BFE0C2.dll,62434D8C.dll,7650CBC7.dll,89F95F77.dll
O21 - SSODL - 1BE1B1E8(E) - {1BE1B1E8-63AB-4B1B-B3FE-EE1675C8C408} =C:/WINDOWS/system32/1BE1B1E8.dll | 2008-8-14 21:42:28
O21 - SSODL - D83334D5(8) - {D83334D5-7CDD-428C-8D1F-1805D1DD155A} =C:/WINDOWS/system32/D83334D5.dll | 2008-8-14 21:42:28
O21 - SSODL - 9998A2F1(F) - {9998A2F1-52FB-4330-B3B6-4F0BBD80F00F} =C:/WINDOWS/system32/9998A2F1.dll | 2008-8-14 21:42:28
O21 - SSODL - B2D304CA(F) - {B2D304CA-5F88-4FB1-87CA-FF4A72E24F02} =C:/WINDOWS/system32/B2D304CA.dll | 2008-8-14 21:42:28
O21 - SSODL - CA66726A(9) - {CA66726A-245F-4B1A-ADB9-299F0E5A2676} =C:/WINDOWS/system32/CA66726A.dll | 2008-8-14 21:42:28
O21 - SSODL - 515E5B45(1) - {515E5B45-71DE-4DB4-AF59-81187BC1A60F} =C:/WINDOWS/system32/515E5B45.dll | 2008-8-14 21:42:28
O21 - SSODL - ED931691(A) - {ED931691-2379-4685-961D-FA92630111CC} =C:/WINDOWS/system32/ED931691.dll | 2008-8-14 21:42:28
O21 - SSODL - D38C7BBA(3) - {D38C7BBA-15B4-47C4-BA2C-4355BE46220C} =C:/WINDOWS/system32/D38C7BBA.dll | 2008-8-14 21:42:28
O21 - SSODL - 03A1D295(5) - {03A1D295-333C-4A8B-A948-85F5C9A51E45} =C:/WINDOWS/system32/03A1D295.dll | 2008-8-14 21:42:28
O21 - SSODL - 143CE310(7) - {143CE310-9E32-40F6-982F-C7AE1AD85D7B} =C:/WINDOWS/system32/143CE310.dll | 2008-8-14 21:42:28
O21 - SSODL - F21511FC(F) - {F21511FC-3FB3-4753-80CE-DF2BA4109ECB} =C:/WINDOWS/system32/F21511FC.dll | 2008-8-14 21:42:28
O21 - SSODL - 5A0F83A6(B) - {5A0F83A6-2DC9-4756-9EA6-1BEF240872D6} =C:/WINDOWS/system32/5A0F83A6.dll | 2008-8-14 21:42:28
O21 - SSODL - 41F8FCF3(D) - {41F8FCF3-0590-47AA-82B8-9D5CB81D757D} =C:/WINDOWS/system32/41F8FCF3.dll | 2008-8-14 21:42:28
O21 - SSODL - 7C0DFD7B(C) - {7C0DFD7B-9330-45A7-B73D-9CEE56002905} =C:/WINDOWS/system32/7C0DFD7B.dll | 2008-8-14 21:42:28
O21 - SSODL - 518F57D3(A) - {518F57D3-E6E4-4BCC-89FF-CA01A0B9630C} =C:/WINDOWS/system32/518F57D3.dll | 2008-8-14 21:42:28
O21 - SSODL - 63F62981(1) - {63F62981-B224-44CB-A4D6-915DF9DC2792} =C:/WINDOWS/system32/63F62981.dll | 2008-8-14 21:42:28
O21 - SSODL - 56D809D2(D) - {56D809D2-CD6A-47E4-98AC-FDB84960CCDF} =C:/WINDOWS/system32/56D809D2.dll | 2008-8-14 21:42:28
O21 - SSODL - AF73E0FB(D) - {AF73E0FB-F97E-44C9-A525-2D8083B090FB} =C:/WINDOWS/system32/AF73E0FB.dll | 2008-8-14 21:42:28
O21 - SSODL - 2A5479B5(E) - {2A5479B5-5B77-42C3-9E10-6EF25FA1E9D2} =C:/WINDOWS/system32/2A5479B5.dll | 2008-8-14 21:42:28
O21 - SSODL - 1BDB68CE(9) - {1BDB68CE-E522-4E88-906C-E9DCEC79684F} =C:/WINDOWS/system32/1BDB68CE.dll | 2008-8-14 21:42:28
O21 - SSODL - 64DDF481(C) - {64DDF481-B0C5-4A54-8D79-4C1537AEA648} = t?
O21 - SSODL - F7902582(4) - {F7902582-CAE9-4DD6-B478-B4C27B274221} =C:/WINDOWS/system32/F7902582.dll | 2008-8-14 21:42:28
O21 - SSODL - 7F99099C(7) - {7F99099C-3F42-4F2E-B487-77F74AE419D2} =C:/WINDOWS/system32/7F99099C.dll | 2008-8-14 21:42:28
O21 - SSODL - 03B54254(D) - {03B54254-E3B2-48EF-9873-CDBA3BE868B1} = t?
O21 - SSODL - E531B068(5) - {E531B068-8EEE-453E-AD96-3573EDBB5464} =C:/WINDOWS/system32/E531B068.dll | 2008-8-14 21:42:28
O21 - SSODL - C9B17E4E(0) - {C9B17E4E-14D1-48F6-A892-406CCF8D80A9} =C:/WINDOWS/system32/C9B17E4E.dll | 2008-8-14 21:42:28
O21 - SSODL - 0C008684(7) - {0C008684-73DA-4651-AE4D-8753889720F0} =C:/WINDOWS/system32/0C008684.dll | 2008-8-14 21:42:28
O21 - SSODL - 405BF191(B) - {405BF191-0B75-40F0-8419-2B8673A17646} =C:/WINDOWS/system32/405BF191.dll | 2008-8-14 21:42:28
O21 - SSODL - F5AFAFA3(F) - {F5AFAFA3-51DE-4122-8297-5F3A26036C3F} =C:/WINDOWS/system32/F5AFAFA3.dll | 2008-8-14 21:42:28
O21 - SSODL - 4E0FA2F2(F) - {4E0FA2F2-23FD-4CEA-81C7-CFF52055A357} =C:/WINDOWS/system32/4E0FA2F2.dll | 2008-8-14 21:42:28
O21 - SSODL - C6098E7C(C) - {C6098E7C-9DF8-4050-99D5-FC179842648E} =C:/WINDOWS/system32/C6098E7C.dll | 2008-8-14 21:42:28
O21 - SSODL - 715989E4(4) - {715989E4-F1B1-476A-8916-54F1DAD1B5BC} =C:/WINDOWS/system32/715989E4.dll | 2008-8-14 21:42:28
O21 - SSODL - 957E8C5A(B) - {957E8C5A-7DFD-4024-A7F4-ABA78DFF6916} =C:/WINDOWS/system32/957E8C5A.dll | 2008-8-14 21:42:28
O21 - SSODL - F1BF7C7A(5) - {F1BF7C7A-5341-40AC-A748-F554B11C8922} =C:/WINDOWS/system32/F1BF7C7A.dll | 2008-8-14 21:42:28
O21 - SSODL - 8D668351(E) - {8D668351-A384-4DCF-BE57-7E6C6EA29C54} =C:/WINDOWS/system32/8D668351.dll | 2008-8-14 21:42:28
O21 - SSODL - EFE5D671(F) - {EFE5D671-281A-44DB-B093-6F315B0EEFEB} =C:/WINDOWS/system32/EFE5D671.dll | 2008-8-14 21:42:28
O21 - SSODL - CE544718(1) - {CE544718-D00D-4066-8445-21064C08227D} =C:/WINDOWS/system32/CE544718.dll | 2008-8-14 21:42:28
O21 - SSODL - 1D2317A1(A) - {1D2317A1-325C-469B-B6E5-FA6ED43B4F43} =C:/WINDOWS/system32/1D2317A1.dll | 2008-8-14 21:42:28
O21 - SSODL - FE9441A0(E) - {FE9441A0-7186-4D64-8980-4EA69C01AD45} =C:/WINDOWS/system32/75F56ED4.dll | 2008-8-14 21:42:28
O21 - SSODL - 75F56ED4(C) - {75F56ED4-7AF8-4F8C-ABBB-8C734A6F69E2} =C:/WINDOWS/system32/75F56ED4.dll | 2008-8-14 21:42:28
O21 - SSODL - 4A7C6D50(C) - {4A7C6D50-5BA2-420A-B9F9-CCEDEFDA2EDD} =C:/WINDOWS/system32/4A7C6D50.dll | 2008-8-14 21:42:28
O21 - SSODL - 9CF1EEA8(B) - {9CF1EEA8-2EE2-40DA-B3C2-DB17FE31E70A} =C:/WINDOWS/system32/F1BF7C7A.dll | 2008-8-14 21:42:28
O21 - SSODL - 78549EA1(0) - {78549EA1-53D5-42EA-817A-F0887953B9FD} =C:/WINDOWS/system32/78549EA1.dll | 2008-8-14 21:42:28
O21 - SSODL - 1325C941(6) - {1325C941-260C-488E-AE52-16612486890F} =C:/WINDOWS/system32/1325C941.dll | 2008-8-14 21:42:28
O21 - SSODL - 19A916DC(6) - {19A916DC-58AA-4E47-9095-567527D0FD73} =C:/WINDOWS/system32/19A916DC.dll | 2008-8-14 21:42:28
O21 - SSODL - C406A026(4) - {C406A026-243E-486C-873F-84F8FCDA3670} =C:/WINDOWS/system32/C406A026.dll | 2008-8-14 21:42:28
O21 - SSODL - 58E4F255(A) - {58E4F255-C6AC-4C0A-8202-8A623BFBFD4A} =C:/WINDOWS/system32/58E4F255.dll | 2008-8-14 21:42:28
O21 - SSODL - 6027FB67(5) - {6027FB67-872E-4389-8DDF-95A33EBCF4FF} =C:/WINDOWS/system32/6027FB67.dll | 2008-8-14 21:42:28
O21 - SSODL - 52C1B2E2(A) - {52C1B2E2-8635-4454-8A61-EA9BFDFA15E6} =C:/WINDOWS/system32/52C1B2E2.dll | 2008-8-14 21:42:28
O21 - SSODL - AAF7C3FD(E) - {AAF7C3FD-6C92-4031-925E-AE7D32CE04D4} =C:/WINDOWS/system32/AAF7C3FD.dll | 2008-8-14 21:42:28
O21 - SSODL - 0E88951F(6) - {0E88951F-CAB9-4590-9B85-E6B5C2AB84A7} =C:/WINDOWS/system32/0E88951F.dll | 2008-8-14 21:42:28
O21 - SSODL - AEA214BF(9) - {AEA214BF-0530-474C-821D-49FD7F11DDDF} =C:/WINDOWS/system32/AEA214BF.dll | 2008-8-14 21:42:28
O21 - SSODL - B188DCF7(B) - {B188DCF7-19D5-429F-A28E-EBF79F454DD4} =C:/WINDOWS/system32/B188DCF7.dll | 2008-8-14 21:42:28
O21 - SSODL - 97FEF446(D) - {97FEF446-831B-434E-9F88-5DE1C61D722F} =C:/WINDOWS/system32/97FEF446.dll | 2008-8-14 21:42:28
O21 - SSODL - 9AB77B8C(0) - {9AB77B8C-B9C1-4CD8-8C32-000385AB62AC} =C:/WINDOWS/system32/9AB77B8C.dll | 2008-8-14 21:42:28
O21 - SSODL - AC8EEE47(3) - {AC8EEE47-4BB8-4210-A8BF-1357848B60CF} =C:/WINDOWS/system32/AC8EEE47.dll | 2008-8-14 21:42:28
O21 - SSODL - EB8F6190(B) - {EB8F6190-8635-435C-AE1A-AB92826A2B5C} =C:/WINDOWS/system32/EB8F6190.dll | 2008-8-14 21:42:28
O21 - SSODL - 727ED075(0) - {727ED075-7F18-475E-ABC9-90BA952815AD} =C:/WINDOWS/system32/727ED075.dll | 2008-8-14 21:42:28
O21 - SSODL - FDB30DD7(9) - {FDB30DD7-8A50-4410-A1CC-095C9D916C89} =C:/WINDOWS/system32/FDB30DD7.dll | 2008-8-14 21:42:28
O21 - SSODL - 5CBCDC25(A) - {5CBCDC25-6ECF-4B35-BF7A-FA2600154328} =C:/WINDOWS/system32/5CBCDC25.dll | 2008-8-14 21:42:28
O21 - SSODL - B8DFE7B0(B) - {B8DFE7B0-764D-46FC-85D9-5B6544DB586B} =C:/WINDOWS/system32/B8DFE7B0.dll | 2008-8-14 21:42:28
O21 - SSODL - F68EF44D(3) - {F68EF44D-E585-4BA1-AA28-03AB65954236} =C:/WINDOWS/system32/F68EF44D.dll | 2008-8-14 21:42:28
O21 - SSODL - E5437B5A(7) - {E5437B5A-3179-490E-AAB7-079B492D1B76} =C:/WINDOWS/system32/E5437B5A.dll | 2008-8-14 21:42:28
O21 - SSODL - 0247AA90(3) - {0247AA90-6140-42CD-9227-F3A81E926100} =C:/WINDOWS/system32/0247AA90.dll | 2008-8-14 21:42:28
O21 - SSODL - 986F4AAC(8) - {986F4AAC-D856-4DA6-92B7-28FE500AF71F} =C:/WINDOWS/system32/986F4AAC.dll | 2008-8-14 21:42:28
O21 - SSODL - 5D4913C9(9) - {5D4913C9-ABB4-48E1-AC85-89B4C93AC936} =C:/WINDOWS/system32/5D4913C9.dll | 2008-8-14 21:42:28
O21 - SSODL - 9F5602BA(B) - {9F5602BA-A701-459E-989F-1BC6A773D9F4} =C:/WINDOWS/system32/9F5602BA.dll | 2008-8-14 21:42:28
O21 - SSODL - AD8D7C15(B) - {AD8D7C15-F896-46FE-A25B-6B517F916A3E} =C:/WINDOWS/system32/AD8D7C15.dll | 2008-8-14 21:42:28
O21 - SSODL - CB91C558(0) - {CB91C558-8657-48F8-BC17-3075822B42C7} =C:/WINDOWS/system32/CB91C558.dll | 2008-8-14 21:42:28
O21 - SSODL - AEC603F1(9) - {AEC603F1-C0C4-47C2-8B10-6912C8B84367} =C:/WINDOWS/system32/AEC603F1.dll | 2008-8-14 21:42:28
O21 - SSODL - 31BDF495(6) - {31BDF495-8A6D-4485-BE76-C69517456E68} =C:/WINDOWS/system32/31BDF495.dll | 2008-8-14 21:42:28
O21 - SSODL - 189F36EE(B) - {189F36EE-F3D8-4205-99A3-CB03E00D672E} =C:/WINDOWS/system32/189F36EE.dll | 2008-8-14 21:42:28
O21 - SSODL - 75548A73(4) - {75548A73-9F97-40E0-B4DB-6447DD3F739F} =C:/WINDOWS/system32/75548A73.dll | 2008-8-14 21:42:28
O21 - SSODL - 521B449B(2) - {521B449B-5819-4969-8196-424AD06D4988} =C:/WINDOWS/system32/521B449B.dll | 2008-8-14 21:42:28
O21 - SSODL - 92BFE0C2(B) - {92BFE0C2-0F39-4033-924D-8B8A4192695A} =C:/WINDOWS/system32/92BFE0C2.dll | 2008-8-14 21:42:28
O21 - SSODL - 62434D8C(6) - {62434D8C-DE20-4150-B52D-66A9E704B1B7} =C:/WINDOWS/system32/62434D8C.dll | 2008-8-14 21:42:28
O21 - SSODL - 7650CBC7(7) - {7650CBC7-36C2-49D8-9FFF-679E1DE97D7B} =C:/WINDOWS/system32/7650CBC7.dll | 2008-8-14 21:42:28
O21 - SSODL - 89F95F77(A) - {89F95F77-B8A8-4B65-B9B3-FAC09F44DE46} =C:/WINDOWS/system32/89F95F77.dll | 2008-8-14 21:42:28
O23 - 服务: 38C2A (38C2A) -C:/WINDOWS/system32/38C2A.exe (自动)
O23 - 服务: aliimz () - System32/Drivers/aliimz.sys (手动)
O23 - 服务: BdGuard (BdGuard) - system32/drivers/BDGuard.SYS | 2008-11-17 22:9:2(引导)
O23 - 服务: c6424110 (c6424110) -C:/WINDOWS/system32/c6424110.sys | 2008-12-4 9:54:22(手动)
O23 - 服务: dd3133sdd2 (dasd1s2d2) -C:/WINDOWS/system32/setup_1648.exe -r | 2008-11-9 3:55:52(禁用)
O23 - 服务: dd3143sdd2 (dasd4s2d2) -C:/WINDOWS/system32/setup_1560.exe -r | 2008-11-11 7:6:50(禁用)
O23 - 服务: dd3asdf33sdd2 (dasdf33s2d2) -C:/WINDOWS/Fonts/dd1fsd2.exe -r | 2008-11-11 7:6:50(禁用)
O23 - 服务: W32Time (Windows Time) C:/WINDOWS/system32/svchost.exe -k netsvcs | 2004-8-16 8:39:24 -> -c:/windows/system32/wins/virvzqrey.dll | 2008-12-4 8:35:22(自动)
O24 - ShlExecHook: [8] - {1BE1B1E8-63AB-4B1B-B3FE-EE1675C8C408} =C:/WINDOWS/system32/1BE1B1E8.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [A] - {D83334D5-7CDD-428C-8D1F-1805D1DD155A} =C:/WINDOWS/system32/D83334D5.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [F] - {9998A2F1-52FB-4330-B3B6-4F0BBD80F00F} =C:/WINDOWS/system32/9998A2F1.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [2] - {B2D304CA-5F88-4FB1-87CA-FF4A72E24F02} =C:/WINDOWS/system32/B2D304CA.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [6] - {CA66726A-245F-4B1A-ADB9-299F0E5A2676} =C:/WINDOWS/system32/CA66726A.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [F] - {515E5B45-71DE-4DB4-AF59-81187BC1A60F} =C:/WINDOWS/system32/515E5B45.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [C] - {ED931691-2379-4685-961D-FA92630111CC} =C:/WINDOWS/system32/ED931691.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [C] - {D38C7BBA-15B4-47C4-BA2C-4355BE46220C} =C:/WINDOWS/system32/D38C7BBA.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [E] - {08223B03-1B38-4A33-A83A-A4D3CC1D6E4E} = 08223B03.dll
O24 - ShlExecHook: [6] - {4FBFD5A4-5FE8-4444-8BD9-FD0FAFA64F96} = 4FBFD5A4.dll
O24 - ShlExecHook: [] - {EF8EFC85-0038-479B-BB0E-B0A52A15CECA} =C:/Program Files/Internet Explorer/SysKetNt.Sys | 2008-12-4 9:54:44
O24 - ShlExecHook: [5] - {03A1D295-333C-4A8B-A948-85F5C9A51E45} =C:/WINDOWS/system32/03A1D295.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [B] - {143CE310-9E32-40F6-982F-C7AE1AD85D7B} =C:/WINDOWS/system32/143CE310.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [B] - {F21511FC-3FB3-4753-80CE-DF2BA4109ECB} =C:/WINDOWS/system32/F21511FC.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [6] - {5A0F83A6-2DC9-4756-9EA6-1BEF240872D6} =C:/WINDOWS/system32/5A0F83A6.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [D] - {41F8FCF3-0590-47AA-82B8-9D5CB81D757D} =C:/WINDOWS/system32/41F8FCF3.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [5] - {7C0DFD7B-9330-45A7-B73D-9CEE56002905} =C:/WINDOWS/system32/7C0DFD7B.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [C] - {518F57D3-E6E4-4BCC-89FF-CA01A0B9630C} =C:/WINDOWS/system32/518F57D3.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [2] - {63F62981-B224-44CB-A4D6-915DF9DC2792} =C:/WINDOWS/system32/63F62981.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [] - {7D182ECE-BFD3-4482-902F-035F4CE9A3C4} =C:/Program Files/Internet Explorer/ftsKetNt.7ps | 2008-12-4 17:19:22
O24 - ShlExecHook: [F] - {56D809D2-CD6A-47E4-98AC-FDB84960CCDF} =C:/WINDOWS/system32/56D809D2.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [B] - {AF73E0FB-F97E-44C9-A525-2D8083B090FB} =C:/WINDOWS/system32/AF73E0FB.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [2] - {2A5479B5-5B77-42C3-9E10-6EF25FA1E9D2} =C:/WINDOWS/system32/2A5479B5.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [F] - {1BDB68CE-E522-4E88-906C-E9DCEC79684F} =C:/WINDOWS/system32/1BDB68CE.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [8] - {64DDF481-B0C5-4A54-8D79-4C1537AEA648} = t?
O24 - ShlExecHook: [1] - {F7902582-CAE9-4DD6-B478-B4C27B274221} =C:/WINDOWS/system32/F7902582.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [2] - {7F99099C-3F42-4F2E-B487-77F74AE419D2} =C:/WINDOWS/system32/7F99099C.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [1] - {03B54254-E3B2-48EF-9873-CDBA3BE868B1} = t?
O24 - ShlExecHook: [4] - {E531B068-8EEE-453E-AD96-3573EDBB5464} =C:/WINDOWS/system32/E531B068.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [9] - {C9B17E4E-14D1-48F6-A892-406CCF8D80A9} =C:/WINDOWS/system32/C9B17E4E.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [0] - {0C008684-73DA-4651-AE4D-8753889720F0} =C:/WINDOWS/system32/0C008684.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [6] - {405BF191-0B75-40F0-8419-2B8673A17646} =C:/WINDOWS/system32/405BF191.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [F] - {F5AFAFA3-51DE-4122-8297-5F3A26036C3F} =C:/WINDOWS/system32/F5AFAFA3.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [7] - {4E0FA2F2-23FD-4CEA-81C7-CFF52055A357} =C:/WINDOWS/system32/4E0FA2F2.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [E] - {C6098E7C-9DF8-4050-99D5-FC179842648E} =C:/WINDOWS/system32/C6098E7C.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [C] - {715989E4-F1B1-476A-8916-54F1DAD1B5BC} =C:/WINDOWS/system32/715989E4.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [6] - {957E8C5A-7DFD-4024-A7F4-ABA78DFF6916} =C:/WINDOWS/system32/957E8C5A.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [2] - {F1BF7C7A-5341-40AC-A748-F554B11C8922} =C:/WINDOWS/system32/F1BF7C7A.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [4] - {8D668351-A384-4DCF-BE57-7E6C6EA29C54} =C:/WINDOWS/system32/8D668351.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [B] - {EFE5D671-281A-44DB-B093-6F315B0EEFEB} =C:/WINDOWS/system32/EFE5D671.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [D] - {CE544718-D00D-4066-8445-21064C08227D} =C:/WINDOWS/system32/CE544718.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [3] - {1D2317A1-325C-469B-B6E5-FA6ED43B4F43} =C:/WINDOWS/system32/1D2317A1.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [5] - {FE9441A0-7186-4D64-8980-4EA69C01AD45} =C:/WINDOWS/system32/75F56ED4.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [2] - {75F56ED4-7AF8-4F8C-ABBB-8C734A6F69E2} =C:/WINDOWS/system32/75F56ED4.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [D] - {4A7C6D50-5BA2-420A-B9F9-CCEDEFDA2EDD} =C:/WINDOWS/system32/4A7C6D50.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [A] - {9CF1EEA8-2EE2-40DA-B3C2-DB17FE31E70A} =C:/WINDOWS/system32/F1BF7C7A.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [D] - {78549EA1-53D5-42EA-817A-F0887953B9FD} =C:/WINDOWS/system32/78549EA1.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [F] - {1325C941-260C-488E-AE52-16612486890F} =C:/WINDOWS/system32/1325C941.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [3] - {19A916DC-58AA-4E47-9095-567527D0FD73} =C:/WINDOWS/system32/19A916DC.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [0] - {C406A026-243E-486C-873F-84F8FCDA3670} =C:/WINDOWS/system32/C406A026.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [A] - {58E4F255-C6AC-4C0A-8202-8A623BFBFD4A} =C:/WINDOWS/system32/58E4F255.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [F] - {6027FB67-872E-4389-8DDF-95A33EBCF4FF} =C:/WINDOWS/system32/6027FB67.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [6] - {52C1B2E2-8635-4454-8A61-EA9BFDFA15E6} =C:/WINDOWS/system32/52C1B2E2.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [4] - {AAF7C3FD-6C92-4031-925E-AE7D32CE04D4} =C:/WINDOWS/system32/AAF7C3FD.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [7] - {0E88951F-CAB9-4590-9B85-E6B5C2AB84A7} =C:/WINDOWS/system32/0E88951F.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [F] - {AEA214BF-0530-474C-821D-49FD7F11DDDF} =C:/WINDOWS/system32/AEA214BF.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [4] - {B188DCF7-19D5-429F-A28E-EBF79F454DD4} =C:/WINDOWS/system32/B188DCF7.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [F] - {97FEF446-831B-434E-9F88-5DE1C61D722F} =C:/WINDOWS/system32/97FEF446.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [C] - {9AB77B8C-B9C1-4CD8-8C32-000385AB62AC} =C:/WINDOWS/system32/9AB77B8C.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [F] - {AC8EEE47-4BB8-4210-A8BF-1357848B60CF} =C:/WINDOWS/system32/AC8EEE47.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [C] - {EB8F6190-8635-435C-AE1A-AB92826A2B5C} =C:/WINDOWS/system32/EB8F6190.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [D] - {727ED075-7F18-475E-ABC9-90BA952815AD} =C:/WINDOWS/system32/727ED075.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [9] - {FDB30DD7-8A50-4410-A1CC-095C9D916C89} =C:/WINDOWS/system32/FDB30DD7.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [8] - {5CBCDC25-6ECF-4B35-BF7A-FA2600154328} =C:/WINDOWS/system32/5CBCDC25.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [B] - {B8DFE7B0-764D-46FC-85D9-5B6544DB586B} =C:/WINDOWS/system32/B8DFE7B0.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [6] - {F68EF44D-E585-4BA1-AA28-03AB65954236} =C:/WINDOWS/system32/F68EF44D.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [6] - {E5437B5A-3179-490E-AAB7-079B492D1B76} =C:/WINDOWS/system32/E5437B5A.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [0] - {0247AA90-6140-42CD-9227-F3A81E926100} =C:/WINDOWS/system32/0247AA90.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [F] - {986F4AAC-D856-4DA6-92B7-28FE500AF71F} =C:/WINDOWS/system32/986F4AAC.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [6] - {5D4913C9-ABB4-48E1-AC85-89B4C93AC936} =C:/WINDOWS/system32/5D4913C9.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [4] - {9F5602BA-A701-459E-989F-1BC6A773D9F4} =C:/WINDOWS/system32/9F5602BA.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [E] - {AD8D7C15-F896-46FE-A25B-6B517F916A3E} =C:/WINDOWS/system32/AD8D7C15.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [7] - {CB91C558-8657-48F8-BC17-3075822B42C7} =C:/WINDOWS/system32/CB91C558.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [7] - {AEC603F1-C0C4-47C2-8B10-6912C8B84367} =C:/WINDOWS/system32/AEC603F1.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [8] - {31BDF495-8A6D-4485-BE76-C69517456E68} =C:/WINDOWS/system32/31BDF495.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [E] - {189F36EE-F3D8-4205-99A3-CB03E00D672E} =C:/WINDOWS/system32/189F36EE.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [F] - {75548A73-9F97-40E0-B4DB-6447DD3F739F} =C:/WINDOWS/system32/75548A73.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [8] - {521B449B-5819-4969-8196-424AD06D4988} =C:/WINDOWS/system32/521B449B.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [A] - {92BFE0C2-0F39-4033-924D-8B8A4192695A} =C:/WINDOWS/system32/92BFE0C2.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [7] - {62434D8C-DE20-4150-B52D-66A9E704B1B7} =C:/WINDOWS/system32/62434D8C.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [B] - {7650CBC7-36C2-49D8-9FFF-679E1DE97D7B} =C:/WINDOWS/system32/7650CBC7.dll | 2008-8-14 21:42:28
O24 - ShlExecHook: [6] - {89F95F77-B8A8-4B65-B9B3-FAC09F44DE46} =C:/WINDOWS/system32/89F95F77.dll | 2008-8-14 21:42:28
O26 - IFEO: 360rpt.exe -> ntsd -d
O26 - IFEO: 360safe.exe -> TASKMAN.EXE
O26 - IFEO: 360safebox.exe -> TASKMAN.EXE
O26 - IFEO: 360safeup.exe -> TASKMAN.EXE
O26 - IFEO: 360tray.exe -> TASKMAN.EXE
O26 - IFEO: adam.exe -> ntsd -d
O26 - IFEO: AgentSvr.exe -> ntsd -d
O26 - IFEO: AntiArp.exe -> ntsd -d
O26 - IFEO: AppSvc32.exe -> ntsd -d
O26 - IFEO: arswp.exe -> ntsd -d
O26 - IFEO: AST.exe -> ntsd -d
O26 - IFEO: autoruns.exe -> ntsd -d
O26 - IFEO: avcenter.exe -> ntsd -d
O26 - IFEO: avconsol.exe -> ntsd -d
O26 - IFEO: avgnt.exe -> ntsd -d
O26 - IFEO: avgrssvc.exe -> ntsd -d
O26 - IFEO: AvMonitor.exe -> ntsd -d
O26 - IFEO: -> ntsd -d
O26 - IFEO: avp.exe -> TASKMAN.EXE
O26 - IFEO: CCenter.exe -> TASKMAN.EXE
O26 - IFEO: ccSvcHst.exe -> ntsd -d
O26 - IFEO: DrvAnti.exe -> ntsd -d
O26 - IFEO: EGHOST.exe -> ntsd -d
O26 - IFEO: egui.exe -> TASKMAN.EXE
O26 - IFEO: ekrn.exe -> TASKMAN.EXE
O26 - IFEO: esslibupdate.exe -> TASKMAN.EXE
O26 - IFEO: extdb.exe -> TASKMAN.EXE
O26 - IFEO: FileDsty.exe -> ntsd -d
O26 - IFEO: filemon.exe -> ntsd -d
O26 - IFEO: FTCleanerShell.exe -> ntsd -d
O26 - IFEO: FYFireWall.exe -> ntsd -d
O26 - IFEO: GFRing3.exe -> ntsd -d
O26 - IFEO: GFUpd.exe -> ntsd -d
O26 - IFEO: HijackThis.exe -> ntsd -d
O26 - IFEO: IceSword.exe -> ntsd -d
O26 - IFEO: iparmo.exe -> ntsd -d
O26 - IFEO: Iparmor.exe -> ntsd -d
O26 - IFEO: isPwdSvc.exe -> ntsd -d
O26 - IFEO: kabaload.exe -> ntsd -d
O26 - IFEO: KASMain.exe -> ntsd -d
O26 - IFEO: KASTask.exe -> ntsd -d
O26 - IFEO: KAV32.exe -> ntsd -d
O26 - IFEO: KAVDX.exe -> ntsd -d
O26 - IFEO: KAVPF.exe -> ntsd -d
O26 - IFEO: KAVPFW.exe -> ntsd -d
O26 - IFEO: KAVSetup.exe -> ntsd -d
O26 - IFEO: KAVStart.exe -> ntsd -d
O26 - IFEO: KISLnchr.exe -> ntsd -d
O26 - IFEO: KMailMon.exe -> ntsd -d
O26 - IFEO: KMFilter.exe -> ntsd -d
O26 - IFEO: KPFW32.exe -> ntsd -d
O26 - IFEO: KPFW32X.exe -> ntsd -d
O26 - IFEO: KPfwSvc.exe -> ntsd -d
O26 - IFEO: Kregex.exe -> ntsd -d
O26 - IFEO: -> ntsd -d
O26 - IFEO: KsLoader.exe -> ntsd -d
O26 - IFEO: KvDetect.exe -> ntsd -d
O26 - IFEO: KvfwMcl.exe -> ntsd -d
O26 - IFEO: kvol.exe -> ntsd -d
O26 - IFEO: kvolself.exe -> ntsd -d
O26 - IFEO: KVSrvXP.exe -> ntsd -d
O26 - IFEO: kvupload.exe -> ntsd -d
O26 - IFEO: kvwsc.exe -> ntsd -d
O26 - IFEO: KvXP.kxp -> ntsd -d
O26 - IFEO: KWatch.exe -> ntsd -d
O26 - IFEO: KWatch9x.exe -> ntsd -d
O26 - IFEO: KWatchX.exe -> ntsd -d
O26 - IFEO: MagicSet.exe -> ntsd -d
O26 - IFEO: mcconsol.exe -> ntsd -d
O26 - IFEO: McNASvc.exe -> ntsd -d
O26 - IFEO: McProxy.exe -> ntsd -d
O26 - IFEO: Mcshield.exe -> ntsd -d
O26 - IFEO: mcsysmon.exe -> ntsd -d
O26 - IFEO: mmqczj.exe -> ntsd -d
O26 - IFEO: mmsk.exe -> ntsd -d
O26 - IFEO: MpfSrv.exe -> ntsd -d
O26 - IFEO: Navapsvc.exe -> ntsd -d
O26 - IFEO: Navapw32.exe -> ntsd -d
O26 - IFEO: NAVSetup.exe -> ntsd -d
O26 - IFEO: nod32.exe -> ntsd -d
O26 - IFEO: nod32krn.exe -> TASKMAN.EXE
O26 - IFEO: nod32kui.exe -> TASKMAN.EXE
O26 - IFEO: NPFMntor.exe -> ntsd -d
O26 - IFEO: PFW.exe -> ntsd -d
O26 - IFEO: PFWLiveUpdate.exe -> ntsd -d
O26 - IFEO: ProcessSafe.exe -> ntsd -d
O26 - IFEO: procexp.exe -> ntsd -d
O26 - IFEO: QHSET.exe -> ntsd -d
O26 - IFEO: QQKav.exe -> ntsd -d
O26 - IFEO: ras.exe -> TASKMAN.EXE
O26 - IFEO: Rav.exe -> TASKMAN.EXE
O26 - IFEO: RavMon.exe -> TASKMAN.EXE
O26 - IFEO: RavMonD.exe -> TASKMAN.EXE
O26 - IFEO: RavStub.exe -> TASKMAN.EXE
O26 - IFEO: RavTask.exe -> TASKMAN.EXE
O26 - IFEO: RawCopy.exe -> ntsd -d
O26 - IFEO: RegClean.exe -> ntsd -d
O26 - IFEO: regmon.exe -> ntsd -d
O26 - IFEO: RegTool.exe -> ntsd -d
O26 - IFEO: rfwcfg.exe -> TASKMAN.EXE
O26 - IFEO: rfwmain.exe -> TASKMAN.EXE
O26 - IFEO: rfwProxy.exe -> TASKMAN.EXE
O26 - IFEO: rfwsrv.exe -> TASKMAN.EXE
O26 - IFEO: rfwstub.exe -> TASKMAN.EXE
O26 - IFEO: RsAgent.exe -> ntsd -d
O26 - IFEO: Rsaupd.exe -> TASKMAN.EXE
O26 - IFEO: RsMain.exe -> TASKMAN.EXE
O26 - IFEO: rsnetsvr.exe -> TASKMAN.EXE
O26 - IFEO: RSTray.exe -> TASKMAN.EXE
O26 - IFEO: rstrui.exe -> ntsd -d
O26 - IFEO: Rtvscan.exe -> ntsd -d
O26 - IFEO: runiep.exe -> TASKMAN.EXE
O26 - IFEO: safebank.exe -> TASKMAN.EXE
O26 - IFEO: safeboxTray.exe -> TASKMAN.EXE
O26 - IFEO: safeboxup.exe -> TASKMAN.EXE
O26 - IFEO: safelive.exe -> ntsd -d
O26 - IFEO: scan32.exe -> ntsd -d
O26 - IFEO: ScanFrm.exe -> TASKMAN.EXE
O26 - IFEO: shcfg32.exe -> ntsd -d
O26 - IFEO: SmartUp.exe -> TASKMAN.EXE
O26 - IFEO: SREng.exe -> ntsd -d
O26 - IFEO: SuperKiller.exe -> ntsd -d
O26 - IFEO: symlcsvc.exe -> ntsd -d
O26 - IFEO: SysSafe.exe -> ntsd -d
O26 - IFEO: taskmgr.exe -> ntsd -d
O26 - IFEO: TrojanDetector.exe -> ntsd -d
O26 - IFEO: Trojanwall.exe -> ntsd -d
O26 - IFEO: TrojDie.exe -> ntsd -d
O26 - IFEO: UIHost.exe -> ntsd -d
O26 - IFEO: UmxAgent.exe -> ntsd -d
O26 - IFEO: UmxAttachment.exe -> ntsd -d
O26 - IFEO: UmxCfg.exe -> ntsd -d
O26 - IFEO: UmxFwHlp.exe -> ntsd -d
O26 - IFEO: UmxPol.exe -> ntsd -d
O26 - IFEO: UpFile.exe -> TASKMAN.EXE
O26 - IFEO: upiea.exe -> ntsd -d
O26 - IFEO: UpLive.exe -> ntsd -d
O26 - IFEO: USBCleaner.exe -> ntsd -d
O26 - IFEO: vsstat.exe -> ntsd -d
O26 - IFEO: webscanx.exe -> ntsd -d
O26 - IFEO: WoptiClean.exe -> ntsd -d
O26 - IFEO: zxsweep.exe -> ntsd -d
O29 - HKCU-Start Page
O29 - HKLM-Start Page
(未完待续)