|
ÎÒÂòÁËA8¼¸¸öÔÂÁË ·¢ÏֱʼDZ¾µÄËÙ¶ÈÒ»Ö±¶¼²»ÊǺܿì ctrl+alt+del²é¿´½ø³Ì ÏÅÒ»Ìø ¾¹È»ÓÐ63¸ö½ø³Ì ¹Ö²»µÃÄÇô¿¨ Ïò¸ßÊÖÇë½ÌÈçºÎ¹Ø±ÕЩ²»ÐèÒªµÄ½ø³ÌºÍһЩÌá¿ìµçÄÔÔËÐÐËٶȵķ½·¨ ллÀ!
´ËÏÂÊÇÎÒµÄÕï¶Ï±¨¸æ:¸÷λ¸ßÊÖ£º
·Ç³£¸ÐлÄúÁôÐÄÎÒÕâ·ÝϵͳÕï¶Ï±¨¸æ£¬Ð¡²ËÄñÊ®Íò»ð¼±µÈ´ýÄúµÄ°ïÖú£¡
¸ÃÕï¶Ï±¨¸æÓÉ360°²È«ÎÀÊ¿Ìṩ http://www.360safe.com
Õï¶Ïʱ¼ä: 2007-10-29 22:11:39
Õï¶Ïƽ̨: Microsoft Windows XP Service Pack 2
IE°æ±¾: Internet Explorer V6.0.2900.2180 Build:62900.2180
¼ÆËã»úÎïÀíÄÚ´æ:1023.23MB - µ±Ç°¿ÉÓÃÄÚ´æ:488.27MB
100 - δ֪ - Process: PIFSvc.exe [LiveUpdate Notice Service] - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
100 - δ֪ - Process: StkCSrv.exe [Syntek Hardware Snapshot Launch Application Services] - C:\WINDOWS\System32\StkCSrv.exe
100 - δ֪ - Process: wcourier.exe [Wireless Console 2] - C:\Program Files\Wireless Console 2\wcourier.exe
100 - δ֪ - Process: DMedia.exe [DMedia] - C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
100 - δ֪ - Process: ACMON.exe [ACMON ] - C:\Program Files\ASUS\Splendid\ACMON.exe
100 - δ֪ - Process: ASScrPro.exe [] - C:\WINDOWS\ASScrPro.exe
100 - δ֪ - Process: PowerForPhone.exe [PowerForPhone] - C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe
100 - δ֪ - Process: sm56hlpr.exe [Application executable file] - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
100 - δ֪ - Process: ACEngSvr.exe [ACEngSvr Module] - C:\WINDOWS\system32\ACEngSvr.exe -Embedding
100 - δ֪ - Process: Mult.exe [ASUS Mult] - C:\Program Files\ASUS\Asus Mult\Mult.exe
100 - δ֪ - Process: SetPoint.exe [Logitech SetPoint Event Manager (UNICODE)] - C:\Program Files\SetPoint\SetPoint.exe
100 - δ֪ - Process: KHALMNPR.EXE [Logitech KHAL Main Process] - C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
100 - δ֪ - Process: QQ.exe [QQ] - D:\Program Files\Tencent\qq\QQ.exe
100 - δ֪ - Process: TIMPlatform.exe [TIMPlatform] - D:\Program Files\Tencent\qq\TIMPlatform.exe
R0 - δ֪ - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page=http://securityresponse.symantec.com/avcenter/fix_homepage/
R0 - δ֪ - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.hao123.com/
R0 - δ֪ - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL=http://securityresponse.symantec.com/avcenter/fix_homepage/
O2 - δ֪ - BHO: (ThunderAtOnce Class) - [ѸÀ×ä¯ÀÀÆ÷¸ß¼¶ÌØÐÔÖ§³ÖÄ£¿é] - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll
O2 - δ֪ - BHO: (IEyeOnIE Class) - [OpacPlugIn Module] - {AEC6C206-8B4A-4203-A5E2-F16174D46422} - C:\PROGRA~1\EMLib3\OPACPL~1.DLL
O4 - δ֪ - HKLM\..\Run: [Wireless Console 2] [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - δ֪ - HKLM\..\Run: [ATKMEDIA] [DMedia] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - δ֪ - HKLM\..\Run: [ACMON] [ACMON ] C:\Program Files\ASUS\Splendid\ACMON.exe
O4 - δ֪ - HKLM\..\Run: [ASUS Screen Saver Protector] [] C:\WINDOWS\ASScrPro.exe
O4 - δ֪ - HKLM\..\Run: [ABLKSR] [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
O4 - δ֪ - HKLM\..\Run: [PowerForPhone] [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe
O4 - δ֪ - HKLM\..\Run: [Symantec PIF AlertEng] [LiveUpdate Notice Service] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - δ֪ - HKLM\..\Run: [Storm2Set] [] C:\WINDOWS\system32\rundll32.exe "D:\PROGRA~1\StormII\StormSet.dll",CheckEnv
O4 - δ֪ - Startup folder: [Mult.lnk] [] C:\Documents and Settings\All Users\¡¸¿ªÊ¼¡¹²Ëµ¥\³ÌÐò\Æô¶¯\Mult.lnk
O8 - δ֪ - Extra context menu item: ʹÓÃѸÀ×ÏÂÔØ - D:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - δ֪ - Extra context menu item: ʹÓÃѸÀ×ÏÂÔØÈ«²¿Á´½Ó - D:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O9 - δ֪ - Extra button: Æô¶¯Ñ¸À×5(HKLM) - D:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - δ֪ - Extra button: ºÆ·½¶Ôսƽ̨(HKLM) - D:\Program Files\HFGameOPT\GameClient.exe
O14 - δ֪ - IERESET.INF: START_PAGE_URL=http://www.asus.com
O22 - δ֪ - Filename Extention: .scr - "C:\WINDOWS\notepad.exe" "%1"
O23 - δ֪ - Service: ccISPwdSvc [User account management service] - "c:\Program Files\Norton Internet Security\ccPwdSvc.exe" - (not running)
O23 - δ֪ - Service: comHost [COM aggregation host service] - "c:\Program Files\Norton Internet Security\comHost.exe" - (not running)
O23 - δ֪ - Service: hvlj [Windows hvlj RunThem] - C:\PROGRA~1\cqge\maqo.dll - (not running)
O23 - δ֪ - Service: LiveUpdate Notice Service [¹ÜÀí Norton ²úƷ֪ͨ] - "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll" - (running)
O23 - δ֪ - Service: PDEngine [PDEngine] - "C:\Program Files\Raxco\PerfectDisk\PDEngine.exe" - (not running)
O23 - δ֪ - Service: PDSched [PDScheduler] - "C:\Program Files\Raxco\PerfectDisk\PDSched.exe" - (running)
O23 - δ֪ - Service: StkSSrv [Syntek AVStream USB2.0 WebCam Service] - C:\WINDOWS\System32\StkCSrv.exe - (running)
O23 - δ֪ - Service: ×Ô¶¯ LiveUpdate µ÷¶È³ÌÐò [¹ÜÀí¶Ô×Ô¶¯ LiveUpdate »á»°µÄµ÷¶È] - "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" - (running)
=======================================
100 - °²È« - Process: smss.exe [½ø³ÌΪ»á»°¹ÜÀí×ÓϵͳÓÃÒÔ³õʼ»¯ÏµÍ³±äÁ¿£¬ms-dosÇý¶¯Ãû³ÆÀàËÆlpt1ÒÔ¼°com£¬µ÷ÓÃwin32¿Ç×ÓϵͳºÍÔËÐÐÔÚwindowsµÇ½¹ý³Ì¡£] - C:\WINDOWS\System32\smss.exe
100 - °²È« - Process: csrss.exe [¿Í»§¶Ë·þÎñ×Óϵͳ£¬ÓÃÒÔ¿ØÖÆwindowsͼÐÎÏà¹Ø×Óϵͳ¡£] - C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=base
100 - °²È« - Process: winlogon.exe [windows ntÓû§µÇ½³ÌÐò¡£] - C:\WINDOWS\system32\winlogon.exe
100 - °²È« - Process: services.exe [ÓÃÓÚ¹ÜÀíwindows·þÎñϵͳ½ø³Ì¡£] - C:\WINDOWS\system32\services.exe
100 - °²È« - Process: lsass.exe [±¾µØ°²È«È¨ÏÞ·þÎñ¿ØÖÆwindows°²È«»úÖÆ¡£] - C:\WINDOWS\system32\lsass.exe
100 - °²È« - Process: ati2evxx.exe [atiÏÔ¿¨Ïà¹Øºǫ́³ÌÐò¡£] - C:\WINDOWS\system32\Ati2evxx.exe
100 - °²È« - Process: svchost.exe [service host processÊÇÒ»¸ö±ê×¼µÄ¶¯Ì¬Á¬½Ó¿âÖ÷»ú´¦Àí·þÎñ¡£] - C:\WINDOWS\system32\svchost -k DcomLaunch
100 - °²È« - Process: svchost.exe [service host processÊÇÒ»¸ö±ê×¼µÄ¶¯Ì¬Á¬½Ó¿âÖ÷»ú´¦Àí·þÎñ¡£] - C:\WINDOWS\system32\svchost -k rpcss
100 - °²È« - Process: svchost.exe [service host processÊÇÒ»¸ö±ê×¼µÄ¶¯Ì¬Á¬½Ó¿âÖ÷»ú´¦Àí·þÎñ¡£] - C:\WINDOWS\System32\svchost.exe -k netsvcs
100 - °²È« - Process: ati2evxx.exe [atiÏÔ¿¨Ïà¹Øºǫ́³ÌÐò¡£] - C:\WINDOWS\system32\Ati2evxx.exe
100 - °²È« - Process: EvtEng.exe [Ó¢ÌØ¶û¹«Ë¾³öÆ·µÄÏà¹Ø²úÆ·¡£] - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
100 - °²È« - Process: explorer.exe [windows program manager»òÕßwindows explorerÓÃÓÚ¿ØÖÆwindowsͼÐÎshell£¬°üÀ¨¿ªÊ¼²Ëµ¥¡¢ÈÎÎñÀ¸£¬×ÀÃæºÍÎļþ¹ÜÀí¡£] - C:\WINDOWS\Explorer.EXE
100 - °²È« - Process: S24EvMon.exe [ÎÞÏßÍø¿¨Ïà¹ØÇý¶¯³ÌÐò£¬ÓÃÓÚʼþ¼à¿Ø¡£] - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
100 - °²È« - Process: svchost.exe [service host processÊÇÒ»¸ö±ê×¼µÄ¶¯Ì¬Á¬½Ó¿âÖ÷»ú´¦Àí·þÎñ¡£] - C:\WINDOWS\system32\svchost.exe -k NetworkService
100 - °²È« - Process: ccSetMgr.exe [Symantec¹«Ë¾ÍøÂ簲ȫÌ××°µÄÒ»²¿·Ö¡£] - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
100 - °²È« - Process: ccEvtMgr.exe [Norton Internet SecurityÍøÂ簲ȫÌ××°µÄÒ»²¿·Ö,¸Ã½ø³Ì»áͬ·´²¡¶¾Óë·À»ðǽ³ÌÐòͬʱ°²×°¡£] - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
100 - °²È« - Process: ccProxy.exe [Symantec Internet SecurityÍøÂ簲ȫÌ××°µÄÒ»²¿·Ö¡£ ] - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
100 - °²È« - Process: SNDSrvc.exe [symantec pop3ɨÃèÍøÂçÇý¶¯³ÌÐò¡£] - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
100 - °²È« - Process: SPBBCSvc.exe [ÈüÃÅÌú¿Ë¹«Ë¾³öÆ·µÄÏà¹ØÈí¼þµÄÒ»²¿·Ö¡£] - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
100 - °²È« - Process: symlcsvc.exe [ÈüÃÅÌú¿Ë¹«Ë¾Èí¼þ²úÆ·µÄÒ»²¿·Ö¡£] - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
100 - °²È« - Process: spoolsv.exe [windows´òÓ¡ÈÎÎñ¿ØÖƳÌÐò£¬ÓÃÒÔ´òÓ¡»ú¾ÍÐ÷¡£] - C:\WINDOWS\system32\spoolsv.exe
100 - °²È« - Process: svchost.exe [service host processÊÇÒ»¸ö±ê×¼µÄ¶¯Ì¬Á¬½Ó¿âÖ÷»ú´¦Àí·þÎñ¡£] - C:\WINDOWS\system32\svchost.exe -k LocalService
100 - °²È« - Process: alg.exe [ÕâÊÇÒ»¸öÓ¦ÓòãÍø¹Ø·þÎñÓÃÓÚÍøÂç¹²Ïí¡£] - C:\WINDOWS\System32\alg.exe
100 - °²È« - Process: LSSrvc.exe [Ò»¿îÃûΪLightScribe(¹âµñ¼¼Êõ)µÄ¿Ì¼»ú£¬¿ÉÒÔÔÚ¹âÅÌÉϹâµñ¸öÐÔ»¯Í¼°¸¡£] - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
100 - °²È« - Process: NAVAPSVC.EXE [norton anti-virusɨÃèÄãµÄÎļþºÍemailÖеIJ¡¶¾¡£] - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
100 - °²È« - Process: RegSrvc.exe [intel¹«Ë¾³öÆ·µÄ°²ÖÃÔÚÍø¿¨Çý¶¯³ÌÐò(intel proset)ÅÔ£¬ÓÃÒÔͨÐÅ·þÎñ¡£] - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
100 - °²È« - Process: svchost.exe [service host processÊÇÒ»¸ö±ê×¼µÄ¶¯Ì¬Á¬½Ó¿âÖ÷»ú´¦Àí·þÎñ¡£] - C:\WINDOWS\system32\svchost.exe -k imgsvc
100 - °²È« - Process: ALUSchedulerSvc.exe [ÈüÃÅÌú¿Ë³öÆ·µÄ·À²¡¶¾Èí¼þ¡£] - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
100 - °²È« - Process: PDSched.exe [´ÅÅÌË鯬ÕûÀí¹¤¾ß¡£] - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
100 - °²È« - Process: HControl.exe [asus»ªË¶±Ê¼Ç±¾µçÄÔÏà¹ØÇý¶¯³ÌÐò¡£] - C:\WINDOWS\ATK0100\HControl.exe
100 - °²È« - Process: PDVDServ.exe [cyberlink corpѸÁ¬¿Æ¼¼³öÆ·µÄ²¥·ÅÆ÷Ïà¹Ø³ÌÐò¡£] - C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe
100 - °²È« - Process: ccApp.exe [symantec¹«ÓÃÓ¦Óÿͻ§¶Ë°üº¬ÔÚnorton antivirus 2003ºÍnorton personal firewall 2003¡£] - C:\Program Files\Common Files\Symantec Shared\ccApp.exe
100 - °²È« - Process: CLI.exe [ati¹«Ë¾²úÆ·µÄÏà¹Ø²úÆ·¡£] - C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
100 - °²È« - Process: SynTPEnh.exe [ÃÀ¹úÐÂ˼¹«Ë¾³ö°æµÄ´¥Ãþ°åÇý¶¯³ÌÐòµÄÒ»²¿·Ö¡£] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
100 - °²È« - Process: ZCfgSvc.exe [intelÎÞÏßÍø¿¨Ïà¹Ø³ÌÐò¡£] - C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
100 - °²È« - Process: ATKOSD.exe [»ªË¶³öÆ·µÄ±Ê¼Ç±¾µçÄÔatk0100Çý¶¯³ÌÐò¡£] - C:\WINDOWS\ATK0100\ATKOSD.exe
100 - °²È« - Process: iFrmewrk.exe [Ó¢ÌØ¶û¹«Ë¾²úÆ·µÄÎÞÏß¾ÖÓòÍøÏà¹Ø³ÌÐò¡£] - C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
100 - °²È« - Process: BatteryLife.exe [»ªË¶±Ê¼Ç±¾µçÄÔµÄpower4 gearÊ¡µçÇл»³ÌÐò¡£] - C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
100 - °²È« - Process: 360tray.exe [360°²È«ÎÀʿʵʱ±£»¤Ä£¿é] - D:\Program Files\360safe\safemon\360Tray.exe
100 - °²È« - Process: ctfmon.exe [office xpÊäÈ뷨ͼ±ê¡£] - C:\WINDOWS\system32\ctfmon.exe
100 - °²È« - Process: NSCSRVCE.EXE [ŵ¶Ù2006Ïà¹Ø·þÎñ] - c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
100 - °²È« - Process: CLI.exe [ati¹«Ë¾²úÆ·µÄÏà¹Ø²úÆ·¡£] - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
100 - °²È« - Process: CLI.exe [ati¹«Ë¾²úÆ·µÄÏà¹Ø²úÆ·¡£] - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
100 - °²È« - Process: IEXPLORE.EXE [microsoft internet explorerä¯ÀÀÆ÷ÓÃÓÚä¯ÀÀÍøÒ³¡£] - C:\Program Files\Internet Explorer\iexplore.exe
100 - °²È« - Process: IEXPLORE.EXE [microsoft internet explorerä¯ÀÀÆ÷ÓÃÓÚä¯ÀÀÍøÒ³¡£] - C:\Program Files\Internet Explorer\iexplore.exe
100 - °²È« - Process: msmsgs.exe [microsoft³öÆ·µÄmsn messenger¼´Ê±Í¨Ñ¶Èí¼þ¡£] - C:\Program Files\Messenger\msmsgs.exe
100 - °²È« - Process: 360Safe.exe [360°²È«ÎÀÊ¿] - D:\Program Files\360safe\360safe.exe
R1 - °²È« - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm
R1 - °²È« - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm
O2 - °²È« - BHO: (AcroIEHlprObj Class) - [Adobe Reader£¬ ²é¿´ºÍ´òÓ¡ Adobe ±ãЯÎĵµ¸ñʽ (PDF) Îļþ¡£] - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - °²È« - BHO: (Thunder Browser Helper) - [ѸÀ׸½´øÏÂÔØ¼àÊÓÆ÷Ïà¹ØÎļþ¡£] - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll
O2 - °²È« - BHO: (CNisExtBho Class) - [ÈüÃÅÌú¿Ëɱ¶¾Èí¼þÏà¹ØÎļþ¡£] - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - °²È« - BHO: (CNavExtBho Class) - [ŵ¶Ù2006Ïà¹Ø·þÎñ] - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - °²È« - Toolbar: (Norton Internet Security 2006) - [ÈüÃÅÌú¿Ëɱ¶¾Èí¼þÏà¹Ø³ÌÐò¡£] - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - °²È« - Toolbar: (Norton AntiVirus) - [ŵ¶Ù2006Ïà¹Ø·þÎñ] - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - °²È« - HKLM\..\Run: [HControl] [»ªË¶±Ê¼Ç±¾µçÄԵĶàýÌåÈȼüÏà¹ØÇý¶¯³ÌÐò¡£] C:\WINDOWS\ATK0100\HControl.exe
O4 - °²È« - HKLM\..\Run: [RemoteControl] [ѶÁ¬¿Æ¼¼³öÆ·µÄpowerdvdÊÓÆµ²¥·ÅÈí¼þ¡£] "C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe"
O4 - °²È« - HKLM\..\Run: [NeroFilterCheck] [nero cd/dvd¿Ì¼Èí¼þ¡£] C:\WINDOWS\system32\NeroCheck.exe
O4 - °²È« - HKLM\..\Run: [ccApp] [ŵ¶Ùɱ¶¾»òŵ¶Ù·À»ðǽ¿Í»§¶ËÈí¼þ] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - °²È« - HKLM\..\Run: [ATICCC] [atiÏÔʾ¿¨Ó²¼þÇý¶¯³ÌÐò¡£] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - °²È« - HKLM\..\Run: [High Definition Audio ÊôÐÔÒ³¿ì½Ý·½Ê½] [Ò»¿îÒôЧ¿ØÖÆÏà¹Ø³ÌÐò¡£] HDAShCut.exe
O4 - °²È« - HKLM\..\Run: [SynTPEnh] [ÐÂ˼ÊÖд°å£¬¶àÓÃÓÚ¸÷ÖֱʼDZ¾´¥Ãþ°åÇý¶¯³ÌÐòÉèÖÃ] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - °²È« - HKLM\..\Run: [IntelZeroConfig] [intelÁãÅäÖÃmfc³ÌÐò¡£] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - °²È« - HKLM\..\Run: [IntelWireless] [intelÎÞÏßÍø¿¨Ïà¹ØÈí¼þ¡£] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - °²È« - HKLM\..\Run: [ASUS Live Update] [»ªË¶³öÆ·µÄ±Ê¼Ç±¾µçÄÔʵʱ¸üгÌÐò¡£] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
O4 - °²È« - HKLM\..\Run: [Power_Gear] [»ªË¶±Ê¼Ç±¾µçÄÔÏà¹Ø³ÌÐò¡£] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - °²È« - HKLM\..\Run: [SMSERIAL] [ĦÍÐÂÞÀmotorola sm56µ÷ÖÆ½âµ÷Æ÷Çý¶¯³ÌÐò¡£] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - °²È« - HKLM\..\Run: [Logitech Hardware Abstraction Layer] [ÂÞ¼¼¶àýÌå²úÆ·Ïà¹Ø³ÌÐò¡£] KHALMNPR.EXE
O4 - °²È« - HKLM\..\Run: [TkBellExe] [ÊÇReal Networks²úÆ·¶¨Ê±Éý¼¶¼ì²â³ÌÐò¡£] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - °²È« - HKLM\..\Run: [360Safetray] [360safeʵʱ±£»¤¹¦ÄÜÄ£¿é¡£] D:\Program Files\360safe\safemon\360Tray.exe /start
O4 - °²È« - HKCU\..\Run: [ctfmon.exe] [office xpÊäÈ뷨ͼ±ê¡£] C:\WINDOWS\system32\ctfmon.exe
O4 - °²È« - HKCU\..\Run: [Skype] [Ò»¿îÓïÒôÁÄÌìÈí¼þ¡£] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - °²È« - HKCU\..\Run: [MSMSGS] [ÊÇMSN MessengerÍøÂçÁÄÌ칤¾ßµÄÖ÷³ÌÐò] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - °²È« - Startup folder: [Logitech SetPoint.lnk] [ÂÞ¼¼logitech setpointʼþ¹ÜÀíÆ÷Ïà¹Ø³ÌÐò¡£] C:\Documents and Settings\All Users\¡¸¿ªÊ¼¡¹²Ëµ¥\³ÌÐò\Æô¶¯\Logitech SetPoint.lnk
O4 - °²È« - Startup folder: [Adobe Reader Speed Launch.lnk] [adobe¹«Ë¾³öÆ·µÄpdf´¦ÀíÈí¼þµÄÏà¹Ø³ÌÐò¡£] C:\Documents and Settings\All Users\¡¸¿ªÊ¼¡¹²Ëµ¥\³ÌÐò\Æô¶¯\Adobe Reader Speed Launch.lnk
O9 - °²È« - Extra button: Windows Messenger(HKLM) - C:\Program Files\Messenger\msmsgs.exe
O16 - °²È« - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Flash²¥·ÅÆ÷) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O23 - °²È« - Service: Ati HotKey Poller [atiÏÔ¿¨Ïà¹Øºǫ́³ÌÐò¡£] - C:\WINDOWS\system32\Ati2evxx.exe - (running)
O23 - °²È« - Service: ccEvtMgr [ŵ¶Ù·À²¡¶¾Èí¼þÏà¹Ø³ÌÐò¡£] - "c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" - (running)
O23 - °²È« - Service: ccProxy [Symantec Internet SecurityÍøÂ簲ȫÌ××°µÄÒ»²¿·Ö¡£] - "c:\Program Files\Common Files\Symantec Shared\ccProxy.exe" - (running)
O23 - °²È« - Service: ccSetMgr [ŵ¶Ù·À²¡¶¾Èí¼þÏà¹Ø³ÌÐò¡£] - "c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" - (running)
O23 - °²È« - Service: EvtEng [EvtEngÏà¹ØÄ£¿é£¬ÓÃÓÚÖ§³ÖIntelÎÞÏßÍøÂçÁ¬½ÓÓ²¼þ¡£] - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe - (running)
O23 - °²È« - Service: LightScribeService [Ò»¸öÀ´×Ôdvd¿Ì¼»ú\\\"¹âµñ\\\"Èí¼þµÄÏà¹Ø³ÌÐò,ͨ¹ýÓû§Ðí¿ÉÐÒé°²×°¡£] - "c:\Program Files\Common Files\LightScribe\LSSrvc.exe" - (running)
O23 - °²È« - Service: LiveUpdate [ŵ¶Ù2006Ïà¹Ø·þÎñ] - "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE" - (not running)
O23 - °²È« - Service: navapsvc [ÊÇNorton AntiVirus·´²¡¶¾Èí¼þµÄÒ»²¿·Ö¡£¸Ã½ø³Ì»áÔÚºǫ́±£»¤ÏµÍ³°²È«¡£ ] - "c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe" - (running)
O23 - °²È« - Service: NSCService [ŵ¶Ù2006Ïà¹Ø·þÎñ] - "c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE" - (running)
O23 - °²È« - Service: RegSrvc [IntelÍøÂçͨѶÈí¼þÏà¹Ø³ÌÐò¡£ ] - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe - (running)
O23 - °²È« - Service: S24EventMonitor [ÎÞÏßÍø¿¨ÅäÖúÍÕï¶Ï³ÌÐò¡£] - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe - (running)
O23 - °²È« - Service: SAVScan [ÊÇSymantec Norton Antivirus·´²¡¶¾Ì××°µÄÒ»²¿·Ö£¬ÓÃÓÚ±£»¤ÄãµÄ¼ÆËã»úÃâÊÜÍøÂ簲ȫÍþв¡£] - "c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe" - (not running)
O23 - °²È« - Service: SNDSrvc [ŵ¶Ù·À¶¾Èí¼þÏà¹Ø³ÌÐò¡£] - "c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe" - (running)
O23 - °²È« - Service: SPBBCSvc [ŵ¶Ù·À¶¾Èí¼þÏà¹Ø³ÌÐò¡£] - "c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe" - (running)
O23 - °²È« - Service: Symantec Core LC [ŵ¶Ù2006Ïà¹Ø·þÎñ] - "C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe" - (running)
=======================================
O31 - δ֪ - Folder Menu: {F9DB5320-233E-11D1-9F84-707F02C10627} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll - Adobe Systems, Inc. - PDF Shell Extension - 7.0.0.0 - 110592 - 4b0991cd076b617a2231b19a6663c1c9
O31 - δ֪ - SEApproved: {42071714-76d4-11d1-8b24-00a0c9068ff3} - deskpan.dll - - - - 0 -
O31 - δ֪ - SEApproved: ÎÞЧµÄCLSID£ºShell extensions for file compression - - - - - 0 -
O31 - δ֪ - SEApproved: ÎÞЧµÄCLSID£º¼ÓÃÜÉÏÏÂÎIJ˵¥ - - - - - 0 -
O31 - δ֪ - SEApproved: {0DF44EAA-FF21-4412-828E-260A8728E7F1} - - - - - 0 -
O31 - δ֪ - SEApproved: {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} - - - - - 0 -
O31 - δ֪ - SEApproved: {7A9D77BD-5403-11d2-8785-2E0420524153} - - - - - 0 -
O31 - δ֪ - SEApproved: {e82a2d71-5b2f-43a0-97b8-81be15854de8} - C:\WINDOWS\system32\dfshim.dll - Microsoft Corporation - Application Deployment Support Library - 2.0.50727.42 - 83456 - b3511383c8be3a8c5b88a78971fc1141
O31 - δ֪ - SEApproved: {E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} - C:\WINDOWS\system32\dfshim.dll - Microsoft Corporation - Application Deployment Support Library - 2.0.50727.42 - 83456 - b3511383c8be3a8c5b88a78971fc1141
O31 - δ֪ - SEApproved: {5E2121EE-0300-11D4-8D3B-444553540000} - C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll - - ACE Context Menu - 1.0.0.1 - 73728 - 649e3ab705eb0f3af213dcd4378515cf
O31 - δ֪ - SEApproved: {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} - D:\Program Files\Real\RealPlayer\rpshell.dll - RealNetworks, Inc. - RealPlayer Shell Extensions - 1.0.1.1783 - 49198 - f73cb998b4c7f6050d99822d4150a456
O31 - δ֪ - SEApproved: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - D:\Program Files\WinRAR\rarext.dll - - - - 119808 - cba174006f01d116676d696018687256
O31 - δ֪ - SEApproved: {ABC70703-32AF-11d4-90C4-D483A70F4825} - D:\Program Files\ϵͳÃÀ»¯×¨¼Ò\data\CMExt.dll - - - - 0 -
O31 - δ֪ - Directory Menu: {ABC70703-32AF-11d4-90C4-D483A70F4825} - D:\Program Files\ϵͳÃÀ»¯×¨¼Ò\data\CMExt.dll - - - - 0 -
O31 - δ֪ - Directory Menu: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - D:\Program Files\WinRAR\rarext.dll - - - - 119808 - cba174006f01d116676d696018687256
O31 - δ֪ - BootExecute: C:\WINDOWS\system32\PDBoot.exe - Raxco Software, Inc. - PerfectDisk Boot Time Defragmentation - 7.0.0.42 - 102984 - 62385b21fe0bdadb64f5f4dd2711a6df
O31 - δ֪ - BootExecute: utocheck autochk * - - - - 0 -
O31 - δ֪ - LSA: Security Packages - sv1_0.dll - - - - 0 -
O31 - δ֪ - LSA: Security Packages - channel.dll - - - - 0 -
=======================================
O40 - Explorer.EXE - ppstream.com - c:\documents and settings\zhanglong\application data\ppstream\bin\1.0.0.2\vodrc.dll - vodrc - 712283e809cc29e0deda932c17b10ea3
O40 - Explorer.EXE - Microsoft Corporation - C:\WINDOWS\system32\MSVCR71.dll - Microsoft? C Runtime Library - 86f1895ae8c5e8b17d99ece768a70732
O40 - Explorer.EXE - Microsoft Corporation - C:\WINDOWS\system32\MSVCP71.dll - Microsoft? C++ Runtime Library - 561fa2abb31dfa8fab762145f81667c2
O40 - Explorer.EXE - - C:\Program Files\ASUS\Asus Mult\HookTitle.dll - - 2913c4cf5c0da630244211a816d53b67
O40 - Explorer.EXE - Logitech Inc. - C:\Program Files\SetPoint\lgscroll.dll - Logitech Scroll Enabler (UNICODE) - 5b2e4673375b176170a3da61f02a8f47
O40 - Explorer.EXE - Adobe Systems, Inc. - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll - PDF Shell Extension - 4b0991cd076b617a2231b19a6663c1c9
O40 - Explorer.EXE - - C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll - ACE Context Menu - 649e3ab705eb0f3af213dcd4378515cf
O40 - Explorer.EXE - - D:\Program Files\WinRAR\rarext.dll - - cba174006f01d116676d696018687256
=======================================
O41 - AegisP - IEEE 802.1X Protocol Driver - C:\WINDOWS\system32\drivers\AegisP.sys - (running) - IEEE 802.1X Protocol Driver - Meetinghouse Data Communications - 375eb0b97e3950adef3633c27a82438b
O41 - CdaC15BA - Macrovision SECURITY Driver - C:\WINDOWS\system32\drivers\CdaC15BA.SYS - (running) - Macrovision SECURITY Driver - Macrovision Europe Ltd - 08f60f40d1a2a95a1f12eddbd9f25c1c
O41 - s24trans - Intel WLAN Packet Driver - C:\WINDOWS\system32\drivers\s24trans.sys - (running) - Intel WLAN Packet Driver - Intel Corporation - daef68fc328342d219de928c8ee610b2
O41 - ipswuio - NDIS User mode I/O Driver - C:\WINDOWS\system32\drivers\ipswuio.sys - (not running) - NDIS User mode I/O Driver - Windows (R) 2000 DDK provider - ee8cc26924a6f07972bbf04487ebd552
=======================================
360Safe.exe=3.6.4.3003
AntiAdwa.dll=3.6.3.1001
AntiEng.dll=3.6.4.1001
AntiActi.dll=2.0.0.3000
CleanHis.dll=3.0.2.1000
live.dll=1.0.1.1021
=======================================
²Ù×÷ÀúÊ·±¨¸æ£º
----------ÇåÀí¶ñÆÀ¼°ÏµÍ³²å¼þÀúÊ·----------
2007-09-21 11:34
ÇåÀí¶ñÆÀÈí¼þ - »Ò¸ë×Ó±äÖÖ0005 -
ÇåÀí¶ñÆÀÈí¼þ - δ֪×Ô¶¯ÔËÐгÌÐò(Autorun) -
2007-09-20 23:42
ÇåÀí¶ñÆÀ²å¼þ - »Ò¸ë×Ó±äÖÖ0005 - C:\WINDOWS\svchost.exe
ÇåÀí¶ñÆÀ²å¼þ - δ֪×Ô¶¯ÔËÐгÌÐò(Autorun) - C:\autorun.inf
ÇåÀí¶ñÆÀ²å¼þ - aatievv.exe - C:\WINDOWS\SVCHOST.EXE
ÇåÀí¶ñÆÀ²å¼þ - Power - C:\WINDOWS\svchost.exe
ÇåÀí¶ñÆÀ²å¼þ - ÍòÄÜÏÂÔØÆ÷ - C:\WINDOWS\SVCHOST.EXE
ÇåÀí¶ñÆÀ²å¼þ - GsServer - C:\WINDOWS\svchost.exe
ÇåÀí¶ñÆÀ²å¼þ - webacc²å¼þ - C:\WINDOWS\SVCHOST.EXE
2007-09-20 23:50
ÇåÀí¶ñÆÀ²å¼þ - »Ò¸ë×Ó±äÖÖ0005 - C:\WINDOWS\svchost.exe
ÇåÀí¶ñÆÀ²å¼þ - δ֪×Ô¶¯ÔËÐгÌÐò(Autorun) - C:\autorun.inf
ÇåÀí¶ñÆÀ²å¼þ - aatievv.exe - C:\WINDOWS\SVCHOST.EXE
ÇåÀí¶ñÆÀ²å¼þ - Power - C:\WINDOWS\svchost.exe
ÇåÀí¶ñÆÀ²å¼þ - ÍòÄÜÏÂÔØÆ÷ - C:\WINDOWS\SVCHOST.EXE
ÇåÀí¶ñÆÀ²å¼þ - GsServer - C:\WINDOWS\svchost.exe
ÇåÀí¶ñÆÀ²å¼þ - webacc²å¼þ - C:\WINDOWS\SVCHOST.EXE
2007-10-24 17:56
ÇåÀí¶ñÆÀ²å¼þ - CnnicÎÞÓÇÉÏÍø¹¤¾ßÌõ -
----------È«ÃæÕï¶ÏÐÞ¸´ÀúÊ·----------
2007-09-20 23:55
O4 - ΣÏÕ - SVCHOST - C:\WINDOWS\MDM.EXE
=======================================
360°²È«ÎÀÊ¿£¬³¹µ×²éɱ¸÷ÖÖÁ÷Ã¥Èí¼þ,È«Ãæ±£»¤ÏµÍ³°²È«,²¢ÔùËÍÕý°æ¿¨°Í˹»ù7.0
×îÐÂÃâ·ÑÏÂÔØ£ºhttp://www.360safe.com
|