遭遇Backdoor.Gpigeon.2007.ca,Trojan-PSW.Win32.QQRob.lg,Backdoor.Win32.Agent.bcn等2

endurer 原创
2007-06-21  第1

那晚太夜了,没弄好,第二天晚上继续,用 pe_xscan 扫描了 log 发现又多出几个

/---
pe_xscan 07-06-04 by Purple Endurer
2005-12-30 20:45:1
Windows XP Service Pack 2(5.1.2600)
管理员用户组

[System Process] * 0
    C:/PROGRA~1/3721/helper.dll | 2007-6-4 14:7:38 | 中文上网 | 2.5.0.1001 | Autolive_helper | 版权所有 (C) 2007 | 2.5.1.1004 | 北京三七二一科技有限公司 |  | Autolive_helper | Helper.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll

C:/WINDOWS/system32/csrss.exe * 548 | 2004-8-17 12:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Client Server Runtime Process | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | CSRSS.Exe | CSRSS.Exe
    C:/WINDOWS/system32/F0D78D11.DLL | 2005-12-30 19:10:12 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
C:/WINDOWS/system32/winlogon.exe * 572 | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Windows NT Logon Application | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | winlogon | WINLOGON.EXE
    C:/WINDOWS/system32/dix.dll | 2005-12-30 1:16:6
    C:/WINDOWS/system32/winlib .dll
    C:/WINDOWS/system32/45119F1B.DLL | 2005-12-30 19:10:12 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
    C:/WINDOWS/system32/F0D78D11.DLL | 2005-12-30 19:10:12 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
    C:/WINDOWS/system32/kusn433sd3.dll | 2005-12-30 19:10:16 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?

C:/WINDOWS/system32/services.exe * 616 | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Services and Controller app | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | services.exe | services.exe
    C:/WINDOWS/system32/F0D78D11.DLL | 2005-12-30 19:10:12 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?

C:/WINDOWS/system32/lsass.exe * 628 | 2004-8-17 12:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | LSA Shell (Export Version) | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | lsass.exe | lsass.exe
    C:/WINDOWS/system32/F0D78D11.DLL | 2005-12-30 19:10:12 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?

C:/WINDOWS/system32/svchost.exe * 780 | 2004-8-17 12:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe
    C:/WINDOWS/system32/F0D78D11.DLL | 2005-12-30 19:10:12 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
    C:/WINDOWS/system32/comwspn.dll | 2001-9-17 17:48:48

C:/WINDOWS/system32/svchost.exe * 828 | 2004-8-17 12:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe
    C:/WINDOWS/system32/F0D78D11.DLL | 2005-12-30 19:10:12 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?

C:/WINDOWS/System32/svchost.exe * 908 | 2004-8-17 12:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe
    C:/WINDOWS/System32/wshirda.dll | 2004-8-16 16:39:10 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Windows Sockets Helper DLL | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | wshirda.dll | wshirda.dll
    C:/WINDOWS/system32/F0D78D11.DLL | 2005-12-30 19:10:12 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
    c:/windows/system32/vwdht.dll | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.0 | szdj | Copyright (C) Microsoft Corporation 1990-2000 | 5.1.2600.0 | Microsoft Corporation| ? | szdj | szdj.dll

C:/WINDOWS/system32/svchost.exe * 1032 | 2004-8-17 12:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe
    C:/WINDOWS/system32/F0D78D11.DLL | 2005-12-30 19:10:12 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?

C:/WINDOWS/system32/svchost.exe * 1104 | 2004-8-17 12:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe
    C:/WINDOWS/system32/F0D78D11.DLL | 2005-12-30 19:10:12 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?

C:/WINDOWS/Explorer.EXE * 1228 | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 6.00.2900.2180 | Windows Explorer | (C) Microsoft Corporation. All rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | explorer | EXPLORER.EXE
    C:/WINDOWS/system32/45119F1B.DLL | 2005-12-30 19:10:12 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
    C:/WINDOWS/system32/F0D78D11.DLL | 2005-12-30 19:10:12 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
    C:/WINDOWS/system32/kusn433sd3.dll | 2005-12-30 19:10:16 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/PROGRA~1/WinKld/Winkld.dat | 2006-4-30 15:18:52 | WinKalendar | 2, 0, 0, 1 | WinKld | Copyright ? 2006 | 2, 0, 0, 1 | www.88dog.com |  | WinKld | WinKld.dll
    C:/PROGRA~1/3721/helper.dll | 2007-6-4 14:7:38 | 中文上网 | 2.5.0.1001 | Autolive_helper | 版权所有 (C) 2007 | 2.5.1.1004 | 北京三七二一科技有限公司 |  | Autolive_helper | Helper.dll
    C:/PROGRA~1/3721/alrex.dll | 2006-12-21 17:53:48 | alrex Module | 2.5.0.1002 | alrex Module | Copyright 2006 | 2.5.0.1002 |  |  | alrex | ALREX.DLL
    C:/PROGRA~1/3721/autolive.dll | 2007-6-4 14:8:16 | 中文上网 | 2.5.0.1001 | CnsMinAL | 版权所有 (C) 2007 | 2.5.4.1009 | 北京三七二一科技有限公司 |  | CnsMinAL | AutoLive.dll
    C:/PROGRA~1/3721/alLiveEx.dll | 2006-3-21 14:20:6 |   LiveEx | 1, 0, 3, 1006 | LiveEx | Copyright ? 2006 | 1, 0, 3, 1006 |   |  | LiveEx | alliveex.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/YAlive.dll | 2006-12-25 9:10:6 | YAlive Module | 2, 2, 0, 1050 | YAlive Module | Copyright 2005 | 2, 2, 0, 1050 |  |  | YAlive | YAlive.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yalliveex.dll | 2006-3-21 13:49:44 |   LiveEx | 2, 0, 1, 1007 | LiveEx | Copyright ? 2005 | 2, 0, 1, 1007 |   |  | LiveEx | LiveEx.dll

    C:/WINDOWS/DOWNLO~1/CnsHook.dll | 2007-5-11 16:31:38 | 中文上网 | 1.5.0.1001 | CnsHook | 版权所有 (C) 2007 | 2.5.1.5 | 北京三七二一科技有限公司 |  | CnsHook | CnsHook.dll

C:/Program Files/Internet Explorer/IEXPLORE.EXE * 1276 | 2004-8-17 20:0:0 | Microsoft(R) Windows(R) Operating System | 6.00.2900.2180 | Internet Explorer | (C) Microsoft Corporation. All rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | iexplore | IEXPLORE.EXE
    C:/Program Files/搜索栏(S)/tbu05944/sobar.dll | 2007-5-17 16:53:0 | IE Toolbar | 3,5,0,0 | IE Toolbar Engine | Copyright ? 2001-2007. All rights reserved. | 3, 5, 0, 1| ?| ? | tbcore3 | tbcore3.dll
    C:/Program Files/搜索栏(S)/tbu05944/tbhelper.dll | 2007-5-17 16:53:0 | IE Toolbar | 3, 5, 0, 1 | IE Toolbar Helper Module | Copyright ? 2001-2007. All rights reserved. | 3, 5, 0, 1| ?| ? | tbhelper | tbhelper.dll
    C:/Program Files/搜索栏(S)/tbu05944/alert_plugin.dll | 2007-4-27 11:12:0 | IE Toolbar | 3,5,0,0 | IE Toolbar Alert Plugin | Copyright ? 2007 | 3, 5, 0, 0 |  |  | alert_plugin | alert_plugin.dll
    C:/Program Files/搜索栏(S)/tbu05944/tabs_plugin.dll | 2007-4-27 12:2:0 | IE Toolbar | 3, 5, 0, 0 | IE Toolbar Tabs Plugin | Copyright ? 2007 | 3, 5, 0, 0 |  |  | tabs_plugin | tabs_plugin.dll
    C:/WINDOWS/system32/F0D78D11.DLL | 2005-12-30 19:10:12 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/yphtb.dll | 2006-3-21 13:51:24 | yPhtb | 1, 1, 3, 1035 | yPhtb | Copyright 2005 Yahoo! China | 1, 1, 3, 1035 | Yahoo! China |  |  | yPhtb.dll
    C:/Documents and Settings/All Users/Application Data/Microsoft/PCTools/pctools.dll | 2007-5-10 18:17:42 | Pctools Module | 2, 3, 0, 0 | Pctools Module | Copyright 2006 | 2, 3, 0, 0 | 金泰丰(广州)科技有限公司 |  | pctools | pctools.DLL
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/yangling.dll | 2007-4-24 9:42:56 | yangling Module | 1, 0, 9, 1010 | yangling.dll |  | 1, 0, 9, 1010 | Yahoo. | Yahoo! | yangling.dll | yAngling.DLL
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/yasbar.dll | 2006-12-26 17:23:8 | YAsBar | 2, 2, 0, 1050 | ToolBar | Copyright 2005 | 2, 2, 0, 1050 | Yahoo! |  | CoolBar | YAsBar.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/YDRAGS~1.DLL | 2007-3-9 16:59:54 | DragSearch | 1, 2, 8, 1009 | DragSearch | Copyright 2005 | 1, 2, 8, 1009 |  |  |  | ydragsearch.dll

    C:/WINDOWS/DOWNLO~1/CnsHook.dll | 2007-5-11 16:31:38 | 中文上网 | 1.5.0.1001 | CnsHook | 版权所有 (C) 2007 | 2.5.1.5 | 北京三七二一科技有限公司 |  | CnsHook | CnsHook.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/yscrblock.dll | 2006-5-18 16:53:24 | yScrBlock module | 1, 0, 2, 1002 | yScrBlock |  | 1, 0, 2, 1002 | Yahoo | Yahoo! | yScrBlock | yScrBlock.dll
    C:/WINDOWS/system32/dmspn.dll | 2001-9-17 17:48:48
    C:/WINDOWS/DOWNLO~1/CnsHint.dll | 2006-12-20 18:7:10 | 3721 CnsHint | 2, 5, 0, 2 | CnsHint | Copyright ? 2004 | 2, 5, 0, 2 | 3721 |  | CnsHint | CnsHint.dll
    C:/PROGRA~1/3721/helper.dll | 2007-6-4 14:7:38 | 中文上网 | 2.5.0.1001 | Autolive_helper | 版权所有 (C) 2007 | 2.5.1.1004 | 北京三七二一科技有限公司 |  | Autolive_helper | Helper.dll
    C:/PROGRA~1/3721/scrblock.dll | 2005-4-5 16:4:4 | 3721 ScrBlock | 1, 0, 1, 1000 | ScrBlock | Copyright ? 2004 | 1, 0, 1, 1000 | 3721 |  | ScrBlock | ScrBlock.dll
    C:/PROGRA~1/3721/alrex.dll | 2006-12-21 17:53:48 | alrex Module | 2.5.0.1002 | alrex Module | Copyright 2006 | 2.5.0.1002 |  |  | alrex | ALREX.DLL
    C:/PROGRA~1/3721/autolive.dll | 2007-6-4 14:8:16 | 中文上网 | 2.5.0.1001 | CnsMinAL | 版权所有 (C) 2007 | 2.5.4.1009 | 北京三七二一科技有限公司 |  | CnsMinAL | AutoLive.dll
    C:/PROGRA~1/3721/alLiveEx.dll | 2006-3-21 14:20:6 |   LiveEx | 1, 0, 3, 1006 | LiveEx | Copyright ? 2006 | 1, 0, 3, 1006 |   |  | LiveEx | alliveex.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/YAlive.dll | 2006-12-25 9:10:6 | YAlive Module | 2, 2, 0, 1050 | YAlive Module | Copyright 2005 | 2, 2, 0, 1050 |  |  | YAlive | YAlive.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yalliveex.dll | 2006-3-21 13:49:44 |   LiveEx | 2, 0, 1, 1007 | LiveEx | Copyright ? 2005 | 2, 0, 1, 1007 |   |  | LiveEx | LiveEx.dll


C:/WINDOWS/system32/spoolsv.exe * 1660 | 2005-6-11 7:53:32 | Microsoft? Windows? Operating System | 5.1.2600.2696 | Spooler SubSystem App | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519) | Microsoft Corporation| ? | spoolsv.exe | spoolsv.exe
    C:/WINDOWS/system32/F0D78D11.DLL | 2005-12-30 19:10:12 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?

C:/WINDOWS/System32/svchost.exe * 476 | 2004-8-17 12:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe
    c:/progra~1/evah/ofkr.dll | 2099-12-30 1:18:34 |   AdDm | 5, 0, 0, 4 | AdDm | Copyright ? 2006 | 5, 0, 0, 4 |   |  | AdDm | AdDm.exe
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll
    c:/progra~1/evah/tkpw.dll | 2099-12-30 1:18:36 |   stdvote | 5, 0, 0, 4 | stdvote | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdvote.dll
    c:/progra~1/evah/kbgn.dll | 2099-12-30 1:18:38 |  | 5, 0, 0, 2 | navseg | Copyright ? 2007 | 5, 0, 0, 2 |  |  | navseg |

C:/WINDOWS/system32/kernl32.exe * 544 | 2004-8-17 12:0:0

c:/temp/svchost.exe * 676 | 2099-12-30 1:19:40
    c:/temp/svchost.exe | 2099-12-30 1:19:40
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll

C:/WINDOWS/system32/dgd4bs.exe * 1200 | 2005-12-30 19:10:18
    C:/WINDOWS/system32/dgd4bs.exe | 2005-12-30 19:10:18
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll

C:/WINDOWS/system32/Rundll32.exe * 2168 | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Run a DLL as an App | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | rundll | RUNDLL.EXE
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll
    C:/WINDOWS/DOWNLO~1/CnsMinIO.dll | 2007-4-28 16:33:54 | 3721 CnsMinIO | 2, 5, 0, 4 | CnsMinIO | 版权所有 (C) 2001 - 2004 | 2, 5, 0, 4 | 北京三七二一科技有限公司 |  | CnsMinIO | CnsMinIO.dll
    C:/WINDOWS/DOWNLO~1/cnsio.dll | 2007-4-28 16:33:42 | 3721 CnsIO | 2, 5, 0, 3 | cnsio | 版权所有 (C) 2001 - 2004 | 2, 5, 0, 3 | 北京三七二一科技有限公司 |  | cnsio | cnsio.dll
    C:/PROGRA~1/3721/helper.dll | 2007-6-4 14:7:38 | 中文上网 | 2.5.0.1001 | Autolive_helper | 版权所有 (C) 2007 | 2.5.1.1004 | 北京三七二一科技有限公司 |  | Autolive_helper | Helper.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll

C:/WINDOWS/system32/nvsvc32.exe * 2432 | 2005-12-10 3:6:0 | NVIDIA Driver Helper Service, Version 81.98 | 6.14.10.8198 | NVIDIA Driver Helper Service, Version 81.98 | (C) NVIDIA Corporation. All rights reserved. | 6.14.10.8198 | NVIDIA Corporation| ? | NVSVC | nvsvc32.exe
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll
C:/WINDOWS/system32/Rem.exe * 2460 | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 5.2.3790.1830 | Generic Host Process for Win32 Services | (C) Microsoft Corporation. All rights reserved. | 5.2.3790.1830 | Microsoft Corporation |  | rpcs.exe | rpcs.exe

C:/WINDOWS/SYSTEM32/RUNDLLFOROUR.EXE * 2484 | 2004-8-17 12:0:0 | Microsoft(R) Windows (R) 2000 Operating System | 5.00.2134.1 | Run a DLL as an App | Copyright (C) Microsoft Corp. 1981-1999 | 5.00.2134.1 | Microsoft Corporation| ? | rundll | RUNDLL.EXE
    C:/WINDOWS/SYSTEM32/WBEM/QZOOF.DLL | 2004-8-17 12:0:0 | irJIT | 5, 1, 2600, 2709 | Microsoft irJIT Module | (C) Microsoft Corporation. All rights reserved. | 5, 1, 2600, 2709 | Microsoft Corporation| ? | IRJIT | IRJIT.dll

C:/WINDOWS/svchost.exe * 2628 | 2004-8-17 12:0:0

C:/WINDOWS/system32/wdfmgr.exe * 2668 | 2005-1-28 1:36:0 | Microsoft? Windows? Operating System | 5.2.3790.1230 | Windows User Mode Driver Manager | ? Microsoft Corporation. All rights reserved. | 5.2.3790.1230 built by: dnsrv(bld4act) | Microsoft Corporation| ? | WdfMgr | WdfMgr.exe
C:/WINDOWS/system32/xiaobo.exe * 2828 | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 5.2.3790.1830 | Generic Host Process for Win32 Services | (C) Microsoft Corporation. All rights reserved. | 5.2.3790.1830 | Microsoft Corporation |  | rpcs.exe | rpcs.exe
    C:/WINDOWS/system32/xiaobo.exe | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 5.2.3790.1830 | Generic Host Process for Win32 Services | (C) Microsoft Corporation. All rights reserved. | 5.2.3790.1830 | Microsoft Corporation |  | rpcs.exe | rpcs.exe

C:/PROGRA~1/Yahoo!/ASSIST~1/ylive.exe * 2948 | 2007-4-24 9:43:36 |   YLive | 2, 0, 7, 1010 | YLive | Copyright  2005 Yahoo! China | 2, 0, 7, 1010 | Yahoo! China |  | YLive | YLive.exe
    C:/PROGRA~1/Yahoo!/ASSIST~1/ylive.exe | 2007-4-24 9:43:36 |   YLive | 2, 0, 7, 1010 | YLive | Copyright  2005 Yahoo! China | 2, 0, 7, 1010 | Yahoo! China |  | YLive | YLive.exe
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/YAlive.dll | 2006-12-25 9:10:6 | YAlive Module | 2, 2, 0, 1050 | YAlive Module | Copyright 2005 | 2, 2, 0, 1050 |  |  | YAlive | YAlive.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yalliveex.dll | 2006-3-21 13:49:44 |   LiveEx | 2, 0, 1, 1007 | LiveEx | Copyright ? 2005 | 2, 0, 1, 1007 |   |  | LiveEx | LiveEx.dll

C:/WINDOWS/system32/ctfmon.exe * 3232 | 2004-8-17 12:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | CTF Loader | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | CTFMON | CTFMON.EXE
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll

C:/PROGRA~1/Yahoo!/ASSIST~1/YLive.exe * 3448 | 2007-4-24 9:43:36 |   YLive | 2, 0, 7, 1010 | YLive | Copyright  2005 Yahoo! China | 2, 0, 7, 1010 | Yahoo! China |  | YLive | YLive.exe
    C:/PROGRA~1/Yahoo!/ASSIST~1/YLive.exe | 2007-4-24 9:43:36 |   YLive | 2, 0, 7, 1010 | YLive | Copyright  2005 Yahoo! China | 2, 0, 7, 1010 | Yahoo! China |  | YLive | YLive.exe
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/YAlive.dll | 2006-12-25 9:10:6 | YAlive Module | 2, 2, 0, 1050 | YAlive Module | Copyright 2005 | 2, 2, 0, 1050 |  |  | YAlive | YAlive.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yalliveex.dll | 2006-3-21 13:49:44 |   LiveEx | 2, 0, 1, 1007 | LiveEx | Copyright ? 2005 | 2, 0, 1, 1007 |   |  | LiveEx | LiveEx.dll

C:/WINDOWS/system32/RUNDLL32.EXE * 3784 | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Run a DLL as an App | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | rundll | RUNDLL.EXE
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll


C:/WINDOWS/SOUNDMAN.EXE * 3984 | 2006-3-2 7:22:4 | Realtek Sound Manager | 5, 1, 0, 52 | Realtek Sound Manager | Copyright (c) 2001-2004 Realtek Semiconductor Corp. | 5, 1, 0, 52 | Realtek Semiconductor Corp. |  | ALSMTray | ALSMTray.exe
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll

C:/WINDOWS/system32/rundll32.exe * 4024 | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Run a DLL as an App | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | rundll | RUNDLL.EXE
    C:/PROGRA~1/3721/helper.dll | 2007-6-4 14:7:38 | 中文上网 | 2.5.0.1001 | Autolive_helper | 版权所有 (C) 2007 | 2.5.1.1004 | 北京三七二一科技有限公司 |  | Autolive_helper | Helper.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll
    C:/PROGRA~1/3721/autolive.dll | 2007-6-4 14:8:16 | 中文上网 | 2.5.0.1001 | CnsMinAL | 版权所有 (C) 2007 | 2.5.4.1009 | 北京三七二一科技有限公司 |  | CnsMinAL | AutoLive.dll
    C:/PROGRA~1/3721/alLiveEx.dll | 2006-3-21 14:20:6 |   LiveEx | 1, 0, 3, 1006 | LiveEx | Copyright ? 2006 | 1, 0, 3, 1006 |   |  | LiveEx | alliveex.dll

C:/WINDOWS/VM_STI.EXE * 4076 | 2005-2-28 17:53:4 | BIGDOG | 4, 2, 1124, 6 | Vimicro | Copyright (C) 2004 Vimicro Corporation | 4, 2, 1124, 6 | Vimicro | BIGDOG | BIGDOG | BigDog.exe
    C:/PROGRA~1/3721/helper.dll | 2007-6-4 14:7:38 | 中文上网 | 2.5.0.1001 | Autolive_helper | 版权所有 (C) 2007 | 2.5.1.1004 | 北京三七二一科技有限公司 |  | Autolive_helper | Helper.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll

C:/WINDOWS/system32/conime.exe * 2244 | 2004-8-17 12:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Console IME | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | Console | CONIME.EXE
    C:/PROGRA~1/3721/helper.dll | 2007-6-4 14:7:38 | 中文上网 | 2.5.0.1001 | Autolive_helper | 版权所有 (C) 2007 | 2.5.1.1004 | 北京三七二一科技有限公司 |  | Autolive_helper | Helper.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll

C:/Program Files/MSN Messenger/MsnMsgr.Exe * 2320 | 2007-1-19 12:55:14 | Messenger | 8.1.0178 | Messenger | Copyright (c) Microsoft Corporation.  All rights reserved. | 8.1.0178.00 | Microsoft Corporation| ? | msnmsgr.exe | msnmsgr.exe
    C:/PROGRA~1/3721/helper.dll | 2007-6-4 14:7:38 | 中文上网 | 2.5.0.1001 | Autolive_helper | 版权所有 (C) 2007 | 2.5.1.1004 | 北京三七二一科技有限公司 |  | Autolive_helper | Helper.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll
    C:/Program Files/MSN Messenger/msgslang.8.1.0178.00.dll | 2007-1-19 12:53:30 | Messenger | 8.1.0178 | Messenger Language Specific Resources | Copyright (c) Microsoft Corporation。保留所有权利。 | 8.1.0178.00 | Microsoft Corporation| ? | msgslang.dll | msgslang.dll
    C:/Program Files/MSN Messenger/msgsres.dll | 2007-1-19 12:54:22 | Messenger | 8.1.0178 | Messenger Resources | Copyright (c) Microsoft Corporation.  All rights reserved. | 8.1.0178.00 | Microsoft Corporation| ? | msgsres.dll | msgsres.dll
    C:/Program Files/MSN Messenger/custsat.dll | 2006-12-19 17:7:46 | Microsoft? Windows? Operating System | 9.0.3790.2428 | custsat | ? Microsoft Corporation. All rights reserved. | 9.0.3790.2428 (srv03_sp1_qfe.050422-1043) | Microsoft Corporation| ? | custsat | custsat.dll
    C:/Program Files/MSN Messenger/MSGSWCAM.dll | 2007-1-19 12:53:20 | Messenger | 8.1.0178 | Messenger WebCam Library | Copyright (c) Microsoft Corporation.  All rights reserved. | 8.1.0178.00 | Microsoft Corporation| ? | msgswcam.dll | msgswcam.dll
    C:/WINDOWS/system32/sirenacm.dll | 2007-1-19 12:53:4 | Messenger Audio Codec | 8.1.0178.00 | Messenger Audio Codec | Copyright (C) 1997 - 2006 Microsoft Corporation | 8.1.0178.00 | Microsoft Corp. | Microsoft(R) is a registered trademark of Microsoft Corporation in the U.S. and/or other countries. | sirenacm | sirenacm.dll
    C:/WINDOWS/SYSTEM32/WBEM/QZOOF.DLL | 2004-8-17 12:0:0 | irJIT | 5, 1, 2600, 2709 | Microsoft irJIT Module | (C) Microsoft Corporation. All rights reserved. | 5, 1, 2600, 2709 | Microsoft Corporation| ? | IRJIT | IRJIT.dll
    c:/windows/system32/vwdht.dll | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.0 | szdj | Copyright (C) Microsoft Corporation 1990-2000 | 5.1.2600.0 | Microsoft Corporation| ? | szdj | szdj.dll

C:/program files/internet explorer/iexplore.exe * 3000 | 2004-8-17 20:0:0 | Microsoft(R) Windows(R) Operating System | 6.00.2900.2180 | Internet Explorer | (C) Microsoft Corporation. All rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | iexplore | IEXPLORE.EXE
    C:/WINDOWS/system32/winsys32_070616.dll | 2005-12-30 19:12:4
    C:/PROGRA~1/3721/helper.dll | 2007-6-4 14:7:38 | 中文上网 | 2.5.0.1001 | Autolive_helper | 版权所有 (C) 2007 | 2.5.1.1004 | 北京三七二一科技有限公司 |  | Autolive_helper | Helper.dll
    C:/PROGRA~1/3721/scrblock.dll | 2005-4-5 16:4:4 | 3721 ScrBlock | 1, 0, 1, 1000 | ScrBlock | Copyright ? 2004 | 1, 0, 1, 1000 | 3721 |  | ScrBlock | ScrBlock.dll
    C:/PROGRA~1/3721/alrex.dll | 2006-12-21 17:53:48 | alrex Module | 2.5.0.1002 | alrex Module | Copyright 2006 | 2.5.0.1002 |  |  | alrex | ALREX.DLL
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/yscrblock.dll | 2006-5-18 16:53:24 | yScrBlock module | 1, 0, 2, 1002 | yScrBlock |  | 1, 0, 2, 1002 | Yahoo | Yahoo! | yScrBlock | yScrBlock.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    C:/WINDOWS/DOWNLO~1/CnsHint.dll | 2006-12-20 18:7:10 | 3721 CnsHint | 2, 5, 0, 2 | CnsHint | Copyright ? 2004 | 2, 5, 0, 2 | 3721 |  | CnsHint | CnsHint.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll

C:/PROGRA~1/Yahoo!/MESSEN~1/ymsgr_tray.exe * 2956 | 2007-3-7 17:36:24 | Yahoo! Messenger | 8,1,0,0 | Yahoo! Messenger Tray | (c) 1998-2007 Yahoo! Inc.  All rights reserved. | 8,1,0,0 | Yahoo! Inc.| ?| ?| ?
    C:/PROGRA~1/Yahoo!/MESSEN~1/ymsgr_tray.exe | 2007-3-7 17:36:24 | Yahoo! Messenger | 8,1,0,0 | Yahoo! Messenger Tray | (c) 1998-2007 Yahoo! Inc.  All rights reserved. | 8,1,0,0 | Yahoo! Inc.| ?| ?| ?
    C:/PROGRA~1/Yahoo!/MESSEN~1/MSVCP71.dll | 2007-3-7 16:13:32 | Microsoft? Visual Studio .NET | 7.10.3077.0 | Microsoft? C++ Runtime Library | ? Microsoft Corporation.  All rights reserved. | 7.10.3077.0 | Microsoft Corporation| ? | MSVCP71.DLL | MSVCP71.DLL
    C:/PROGRA~1/Yahoo!/MESSEN~1/MSVCR71.dll | 2007-3-7 16:13:32 | Microsoft? Visual Studio .NET | 7.10.3052.4 | Microsoft? C Runtime Library | ? Microsoft Corporation.  All rights reserved. | 7.10.3052.4 | Microsoft Corporation| ? | MSVCR71.DLL | MSVCR71.DLL
    C:/PROGRA~1/3721/helper.dll | 2007-6-4 14:7:38 | 中文上网 | 2.5.0.1001 | Autolive_helper | 版权所有 (C) 2007 | 2.5.1.1004 | 北京三七二一科技有限公司 |  | Autolive_helper | Helper.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll
    C:/Program Files/Yahoo!/Shared/YbSkin2.dll | 2007-3-7 16:13:44 | Yahoo! Skinning Object | 3, 0, 0, 0 | Yahoo! Skinning Object | (c) Yahoo! Inc.   All rights reserved. | 2006, 10, 11, 1 | Yahoo! Inc.| ? | YbSkin2.dll | YbSkin2.dll
    C:/PROGRA~1/Yahoo!/MESSEN~1/res_msgr.dll | 2007-4-27 10:3:6 | 雅虎通 | 8,5,0,1 | Resource Module | (c) 1998-2007 Yahoo! Inc.  All rights reserved. | 8,5,0,1 | Yahoo! Inc.| ?| ?| ?

C:/WINDOWS/system32/dgd4bs.exe * 1736 | 2005-12-30 19:10:18
    C:/PROGRA~1/3721/helper.dll | 2007-6-4 14:7:38 | 中文上网 | 2.5.0.1001 | Autolive_helper | 版权所有 (C) 2007 | 2.5.1.1004 | 北京三七二一科技有限公司 |  | Autolive_helper | Helper.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll

C:/Program Files/Internet Explorer/IEXPLORE.EXE * 1824 | 2004-8-17 20:0:0 | Microsoft(R) Windows(R) Operating System | 6.00.2900.2180 | Internet Explorer | (C) Microsoft Corporation. All rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | iexplore | IEXPLORE.EXE
    C:/PROGRA~1/3721/helper.dll | 2007-6-4 14:7:38 | 中文上网 | 2.5.0.1001 | Autolive_helper | 版权所有 (C) 2007 | 2.5.1.1004 | 北京三七二一科技有限公司 |  | Autolive_helper | Helper.dll
    C:/PROGRA~1/3721/scrblock.dll | 2005-4-5 16:4:4 | 3721 ScrBlock | 1, 0, 1, 1000 | ScrBlock | Copyright ? 2004 | 1, 0, 1, 1000 | 3721 |  | ScrBlock | ScrBlock.dll
    C:/PROGRA~1/3721/alrex.dll | 2006-12-21 17:53:48 | alrex Module | 2.5.0.1002 | alrex Module | Copyright 2006 | 2.5.0.1002 |  |  | alrex | ALREX.DLL
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/yscrblock.dll | 2006-5-18 16:53:24 | yScrBlock module | 1, 0, 2, 1002 | yScrBlock |  | 1, 0, 2, 1002 | Yahoo | Yahoo! | yScrBlock | yScrBlock.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    C:/WINDOWS/DOWNLO~1/CnsHint.dll | 2006-12-20 18:7:10 | 3721 CnsHint | 2, 5, 0, 2 | CnsHint | Copyright ? 2004 | 2, 5, 0, 2 | 3721 |  | CnsHint | CnsHint.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll
    C:/PROGRA~1/3721/autolive.dll | 2007-6-4 14:8:16 | 中文上网 | 2.5.0.1001 | CnsMinAL | 版权所有 (C) 2007 | 2.5.4.1009 | 北京三七二一科技有限公司 |  | CnsMinAL | AutoLive.dll
    C:/PROGRA~1/3721/alLiveEx.dll | 2006-3-21 14:20:6 |   LiveEx | 1, 0, 3, 1006 | LiveEx | Copyright ? 2006 | 1, 0, 3, 1006 |   |  | LiveEx | alliveex.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/YAlive.dll | 2006-12-25 9:10:6 | YAlive Module | 2, 2, 0, 1050 | YAlive Module | Copyright 2005 | 2, 2, 0, 1050 |  |  | YAlive | YAlive.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yalliveex.dll | 2006-3-21 13:49:44 |   LiveEx | 2, 0, 1, 1007 | LiveEx | Copyright ? 2005 | 2, 0, 1, 1007 |   |  | LiveEx | LiveEx.dll
    C:/WINDOWS/DOWNLO~1/cnsplus.dll | 2006-12-20 18:7:6 | 3721 CnsPlus | 2, 5, 0, 2 | CnsPlus | Copyright ? 2004 | 2, 5, 0, 2 | 3721 |  | CnsPlus | CnsPlus.dll
    C:/Program Files/搜索栏(S)/tbu05944/sobar.dll | 2007-5-17 16:53:0 | IE Toolbar | 3,5,0,0 | IE Toolbar Engine | Copyright ? 2001-2007. All rights reserved. | 3, 5, 0, 1| ?| ? | tbcore3 | tbcore3.dll
    C:/Program Files/搜索栏(S)/tbu05944/tbhelper.dll | 2007-5-17 16:53:0 | IE Toolbar | 3, 5, 0, 1 | IE Toolbar Helper Module | Copyright ? 2001-2007. All rights reserved. | 3, 5, 0, 1| ?| ? | tbhelper | tbhelper.dll
    C:/Program Files/搜索栏(S)/tbu05944/alert_plugin.dll | 2007-4-27 11:12:0 | IE Toolbar | 3,5,0,0 | IE Toolbar Alert Plugin | Copyright ? 2007 | 3, 5, 0, 0 |  |  | alert_plugin | alert_plugin.dll
    C:/Program Files/搜索栏(S)/tbu05944/tabs_plugin.dll | 2007-4-27 12:2:0 | IE Toolbar | 3, 5, 0, 0 | IE Toolbar Tabs Plugin | Copyright ? 2007 | 3, 5, 0, 0 |  |  | tabs_plugin | tabs_plugin.dll
    C:/WINDOWS/DOWNLO~1/CnsHook.dll | 2007-5-11 16:31:38 | 中文上网 | 1.5.0.1001 | CnsHook | 版权所有 (C) 2007 | 2.5.1.5 | 北京三七二一科技有限公司 |  | CnsHook | CnsHook.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/yphtb.dll | 2006-3-21 13:51:24 | yPhtb | 1, 1, 3, 1035 | yPhtb | Copyright 2005 Yahoo! China | 1, 1, 3, 1035 | Yahoo! China |  |  | yPhtb.dll
    C:/Documents and Settings/All Users/Application Data/Microsoft/PCTools/pctools.dll | 2007-5-10 18:17:42 | Pctools Module | 2, 3, 0, 0 | Pctools Module | Copyright 2006 | 2, 3, 0, 0 | 金泰丰(广州)科技有限公司 |  | pctools | pctools.DLL
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/yangling.dll | 2007-4-24 9:42:56 | yangling Module | 1, 0, 9, 1010 | yangling.dll |  | 1, 0, 9, 1010 | Yahoo. | Yahoo! | yangling.dll | yAngling.DLL
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/yasbar.dll | 2006-12-26 17:23:8 | YAsBar | 2, 2, 0, 1050 | ToolBar | Copyright 2005 | 2, 2, 0, 1050 | Yahoo! |  | CoolBar | YAsBar.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/YDRAGS~1.DLL | 2007-3-9 16:59:54 | DragSearch | 1, 2, 8, 1009 | DragSearch | Copyright 2005 | 1, 2, 8, 1009 |  |  |  | ydragsearch.dll

 

C:/Program Files/QQ2006/QQ.exe * 3172 | 2006-5-9 17:23:22 | TENCENT QQ | 0, 0, 0, 0 | QQ | Copyright ? 2005 | 0, 0, 0, 0 | TENCENT |  | COMQQD | QQ.exe
    C:/PROGRA~1/3721/helper.dll | 2007-6-4 14:7:38 | 中文上网 | 2.5.0.1001 | Autolive_helper | 版权所有 (C) 2007 | 2.5.1.1004 | 北京三七二一科技有限公司 |  | Autolive_helper | Helper.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll
    C:/WINDOWS/DOWNLO~1/CnsHook.dll | 2007-5-11 16:31:38 | 中文上网 | 1.5.0.1001 | CnsHook | 版权所有 (C) 2007 | 2.5.1.5 | 北京三七二一科技有限公司 |  | CnsHook | CnsHook.dll
C:/Program Files/QQ2006/TIMPlatform.exe * 3360 | 2006-4-25 16:13:36 | tencent TIMPlatform | 0, 3, 1, 8 | TIMPlatform | Copyright ? 2005 | 0, 3, 1, 8 | tencent |  | TIMPlatform | TIMPlatform.exe
    C:/PROGRA~1/3721/helper.dll | 2007-6-4 14:7:38 | 中文上网 | 2.5.0.1001 | Autolive_helper | 版权所有 (C) 2007 | 2.5.1.1004 | 北京三七二一科技有限公司 |  | Autolive_helper | Helper.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll
    C:/Program Files/QQ2006/TIMProxy.dll | 2006-4-25 17:9:56 | tencent QQMainCreatorProxy | 0, 3, 2, 4 | TIMProxy | Copyright ? 2004 | 0, 3, 2, 4 | tencent |  | TIMProxy | QQMainCreatorProxy.dll
C:/Program Files/Internet Explorer/IEXPLORE.EXE * 2024 | 2004-8-17 20:0:0 | Microsoft(R) Windows(R) Operating System | 6.00.2900.2180 | Internet Explorer | (C) Microsoft Corporation. All rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | iexplore | IEXPLORE.EXE
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/yscrblock.dll | 2006-5-18 16:53:24 | yScrBlock module | 1, 0, 2, 1002 | yScrBlock |  | 1, 0, 2, 1002 | Yahoo | Yahoo! | yScrBlock | yScrBlock.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/YAlive.dll | 2006-12-25 9:10:6 | YAlive Module | 2, 2, 0, 1050 | YAlive Module | Copyright 2005 | 2, 2, 0, 1050 |  |  | YAlive | YAlive.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yalliveex.dll | 2006-3-21 13:49:44 |   LiveEx | 2, 0, 1, 1007 | LiveEx | Copyright ? 2005 | 2, 0, 1, 1007 |   |  | LiveEx | LiveEx.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/yasbar.dll | 2006-12-26 17:23:8 | YAsBar | 2, 2, 0, 1050 | ToolBar | Copyright 2005 | 2, 2, 0, 1050 | Yahoo! |  | CoolBar | YAsBar.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/yphtb.dll | 2006-3-21 13:51:24 | yPhtb | 1, 1, 3, 1035 | yPhtb | Copyright 2005 Yahoo! China | 1, 1, 3, 1035 | Yahoo! China |  |  | yPhtb.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/yaswiper.dll | 2006-12-18 14:45:32 | Yahoo yTWiper | 1, 0, 2, 1005 | yTWiper | Copyright (C) 2004 | 1, 0, 2, 1005 | Yahoo |  | yTWiper | yTWiper.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/yasiesec.dll | 2007-4-30 14:59:42 | yIESecUI module | 1, 0, 4, 1005 | yIESecUI |  | 1, 0, 4, 1005 | Yahoo | Yahoo! | IESecUI | yIESecUI.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/yasnoad.dll | 2006-5-18 18:5:50 | ADKiller Module | 1, 1, 4, 1006 | ADKiller Module | Copyright 2004 | 1, 1, 4, 1006 |  |  | ADKiller | ADKiller.DLL
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/yzsNetProto.dll | 2005-9-13 16:28:4 | yzsNetProto Module | 1, 0, 0, 1 | yzsNetProto.dll | Yahoo! | 1, 0, 0, 1 | Yahoo| ? | yzsNetProto | yzsNetProto.DLL
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/yrss.dll | 2006-3-27 18:55:22 | yRss Module | 1, 0, 1, 1015 | yRss Module | Copyright 2005 | 1, 0, 1, 1015 | Yahoo! China |  | yRss | yRss.DLL
    C:/WINDOWS/DOWNLO~1/CnsHook.dll | 2007-5-11 16:31:38 | 中文上网 | 1.5.0.1001 | CnsHook | 版权所有 (C) 2007 | 2.5.1.5 | 北京三七二一科技有限公司 |  | CnsHook | CnsHook.dll
    C:/Program Files/搜索栏(S)/tbu05944/sobar.dll | 2007-5-17 16:53:0 | IE Toolbar | 3,5,0,0 | IE Toolbar Engine | Copyright ? 2001-2007. All rights reserved. | 3, 5, 0, 1| ?| ? | tbcore3 | tbcore3.dll
    C:/Program Files/搜索栏(S)/tbu05944/tbhelper.dll | 2007-5-17 16:53:0 | IE Toolbar | 3, 5, 0, 1 | IE Toolbar Helper Module | Copyright ? 2001-2007. All rights reserved. | 3, 5, 0, 1| ?| ? | tbhelper | tbhelper.dll
    C:/Program Files/搜索栏(S)/tbu05944/alert_plugin.dll | 2007-4-27 11:12:0 | IE Toolbar | 3,5,0,0 | IE Toolbar Alert Plugin | Copyright ? 2007 | 3, 5, 0, 0 |  |  | alert_plugin | alert_plugin.dll
    C:/Program Files/搜索栏(S)/tbu05944/tabs_plugin.dll | 2007-4-27 12:2:0 | IE Toolbar | 3, 5, 0, 0 | IE Toolbar Tabs Plugin | Copyright ? 2007 | 3, 5, 0, 0 |  |  | tabs_plugin | tabs_plugin.dll
    C:/Documents and Settings/All Users/Application Data/Microsoft/PCTools/pctools.dll | 2007-5-10 18:17:42 | Pctools Module | 2, 3, 0, 0 | Pctools Module | Copyright 2006 | 2, 3, 0, 0 | 金泰丰(广州)科技有限公司 |  | pctools | pctools.DLL
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/yangling.dll | 2007-4-24 9:42:56 | yangling Module | 1, 0, 9, 1010 | yangling.dll |  | 1, 0, 9, 1010 | Yahoo. | Yahoo! | yangling.dll | yAngling.DLL
    C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/YDRAGS~1.DLL | 2007-3-9 16:59:54 | DragSearch | 1, 2, 8, 1009 | DragSearch | Copyright 2005 | 1, 2, 8, 1009 |  |  |  | ydragsearch.dll
C:/Documents and Settings/Administrator/桌面/3.exe * 3092 | 2007-6-4 23:7:38
    C:/PROGRA~1/3721/helper.dll | 2007-6-4 14:7:38 | 中文上网 | 2.5.0.1001 | Autolive_helper | 版权所有 (C) 2007 | 2.5.1.1004 | 北京三七二一科技有限公司 |  | Autolive_helper | Helper.dll
    C:/PROGRA~1/Yahoo!/ASSIST~1/Yhelper.dll | 2006-9-22 10:49:8 | Helper Module | 2, 0, 9, 1027 | Helper Module | Copyright 2004 | 2, 0, 9, 1027 |  |  | Helper | Helper.dll
    C:/WINDOWS/DOWNLO~1/CnsMin.dll | 2007-6-8 17:41:58 | 中文上网 | 2.5.0.1001 | CnsMin | 版权所有 (C) 2007 | 2.5.0.9 | 国风因特软件(北京)有限公司 |  | CnsMin | CnsMin.dll
    c:/progra~1/evah/rinu.dll | 2099-12-30 1:18:34 | stdstub | 5, 0, 0, 4 | stdstub Module | Copyright 2005 | 5, 0, 0, 4 |  |  | stdstub |
    c:/progra~1/evah/wnsz.dll | 2099-12-30 1:18:36 |   stdplay | 5, 0, 0, 4 | stdplay | Copyright ? 2006 | 5, 0, 0, 4 |   |  | stdvote | stdplay.dll


F2 - REG: system.ini: UserInit=C:/WINDOWS/system32/userinit.exe,c:/WINDOWS/11191061761.exe


O2 - BHO Info cache - {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} - C:/Documents and Settings/All Users/Application Data/Microsoft/PCTools/pctools.dll
O2 - BHO TBSB04805 Class - {FA91DE7A-D85F-4F35-8204-4D7C957A154B} - C:/Program Files/搜索栏(S)/tbu05944/sobar.dll
O3 - IE工具栏:  - {42A2F05F-E171-4CEF-852F-02475F698C24} - C:/Program Files/搜索栏(S)/tbu05944/sobar.dll
O4 - HKCR/../Run: [ctfmon.exe] C:/WINDOWS/system32/ctfmon.exe
O4 - HKLM/../Run: [CnsMin] Rundll32.exe C:/WINDOWS/DOWNLO~1/CnsMin.dll,Rundll32
O4 - HKLM/../Run: [wallpaper] c:/windows/system32/壁纸自动换.exe
O4 - HKLM/../Run: [TinTSentp] C:/WINDOWS/system32/autoc0nv.exe
O4 - HKLM/../Run: [helper.dll] C:/WINDOWS/system32/rundll32.exe C:/PROGRA~1/3721/helper.dll,Rundll32
O4 - HKLM/../Run: [System] C:/Program Files/Common Files/system/Updaterun.exe
O4 - HKLM/../Run: [Mrxiaokan4] C:/Program Files/Internet Explorer/SPLOUE.exe
O4 - HKLM/../Policies/Explorer/Run: [Userinit] rundll32.exe C:/WINDOWS/system32/winsys16_070616.dll start

C:/autorun.inf
/-----
[AutoRun]
open=IO.pif
shellexecute=IO.pif
shell//Auto//command=IO.pif
-----/
D:/autorun.inf
/-----
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell//Auto//command=IO.pif
shell/Auto/command=rising.exe
-----/
E:/autorun.inf
/-----
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell//Auto//command=IO.pif
shell/Auto/command=rising.exe
-----/
F:/autorun.inf
/-----
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell//Auto//command=IO.pif
shell/Auto/command=rising.exe
-----/
O9 - IE工具栏扩展按钮HKLM:工具栏(T) - {42A2F05F-E171-4CEF-852F-02475F698C24} - C:/Program Files/搜索栏(S)/tbu05944/sobar.dll
O9 - IE工具菜单扩展项HKLM:工具栏(T) - {42A2F05F-E171-4CEF-852F-02475F698C24} - C:/Program Files/搜索栏(S)/tbu05944/sobar.dll

O21 - SSODL - SysTime(88Dog.Kalendar) - {724C75F1-B757-408D-A50A-4CF99DA35D73} = C:/PROGRA~1/WinKld/WinKld.dll

O23 - 服务: 3A452D83 (3A452D83) - C:/WINDOWS/system32/24E9F3BC.EXE -k | 2005-12-30 1:42:12 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?(自动)

O23 - 服务: 92ja2lr0q (92ja2lr0q) - System32/DRIVERS/92ja2lr0q.sys(引导)

O23 - 服务: AEA6EAEC (AEA6EAEC) - C:/WINDOWS/system32/2DD519ED.EXE -p | 2007-6-16 6:27:26 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?(自动)

O23 - 服务: B302EC43 (B302EC43) - C:/WINDOWS/system32/75D23BE4.EXE -d | 2099-12-30 1:43:2 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?(自动)

O23 - 服务: CnsMinKP (CnsMinKP) - system32/drivers/CnsMinKP.sys | KMD | 2.0.3.9 | KMD | Copyright (c) 3721 Corporation. | 2.0.3.9 | Copyright (C) 3721 Corporation.| ? | CnsMinKP.sys | CnsMinKP.sys(引导)

O23 - 服务: CnsStd (CnsStd) - C:/WINDOWS/System32/drivers/CnsStd.sys | 2005-6-10 16:48:18 | 中文上网 | 1, 0, 0, 1002| ?| ? | 1, 0, 0, 1002 | 北京三七二一科技有限公司| ?| ?| ?(自动)

O23 - 服务: FB000E3A (FB000E3A) - C:/WINDOWS/system32/F77B20D5.EXE -k | 2005-12-30 22:51:2 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?(自动)

O23 - 服务: gjk0 (gjk0) - C:/WINDOWS/system32/drivers/gjk0.sys | 2004-8-17 12:0:0(自动)

O23 - 服务: Investor (Remote Registry Protect) - C:/WINDOWS/System32/svchost.exe -k netsvcs -> C:/WINDOWS/system32/vwdht.dll | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.0 | szdj | Copyright (C) Microsoft Corporation 1990-2000 | 5.1.2600.0 | Microsoft Corporation| ? | szdj | szdj.dll(自动)

O23 - 服务: jafm (Windows jafm RunThem) - C:/WINDOWS/System32/svchost.exe -k netsvcs -> C:/PROGRA~1/evah/ofkr.dll | 2099-12-30 1:18:34 |   AdDm | 5, 0, 0, 4 | AdDm | Copyright ? 2006 | 5, 0, 0, 4 |   |  | AdDm | AdDm.exe(自动)

O23 - 服务: kdkfpdnd (kdkfpdnd) - C:/WINDOWS/System32/drivers/kdkfpdnd.sys | 2005-12-30 22:50:14 |  sys 应用程序 | 1, 0, 1, 3 | sys 应用程序 | 版权所有 (C) 2006 | 1, 0, 1, 3 | 北京三七二一科技有限公司| ? | sys | sys.exe(引导)

O23 - 服务: Keep Spooler (Keep Spooler) - C:/Program Files/Common Files/kim | 2005-6-11 22:12:6(禁用)

O23 - 服务: kernl32 (kernl32) - C:/WINDOWS/system32/kernl32.exe | 2004-8-17 12:0:0(自动)

O23 - 服务: kusn33sd (kusn33sd) - C:/WINDOWS/system32/kusn33sd.exe -j | 2005-12-30 22:50:30 | Microsoft(R) Windows(R) Operating System| ?| ? | (C) Microsoft Corporation. All rights reserved.| ? | Microsoft Corporation| ?| ?| ?(自动)

O23 - 服务: Messager (Messager) - c:/temp/svchost.exe | 2099-12-30 1:19:40(自动)

O23 - 服务: netlog (Net Login Helper) - C:/WINDOWS/system32/SCardSer.exe  | 2001-9-17 17:48:48(自动)

O23 - 服务: R2A (R2A) - C:/WINDOWS/system32a2.sys(禁用)

O23 - 服务: Rem (re Call System(RPCS)) - C:/WINDOWS/system32/Rem.exe | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 5.2.3790.1830 | Generic Host Process for Win32 Services | (C) Microsoft Corporation. All rights reserved. | 5.2.3790.1830 | Microsoft Corporation |  | rpcs.exe | rpcs.exe(自动)

O23 - 服务: SOCEESe (Intranet Messenger) - C:/WINDOWS/SYSTEM32/RUNDLLFOROUR.EXE C:/WINDOWS/SYSTEM32/WBEM/QZOOF.DLL,DllRegisterServer 1087(自动)

O23 - 服务: svchost (svchost) - C:/WINDOWS/svchost.exe | 2004-8-17 12:0:0(自动)

O23 - 服务: Vista         (Vista        ) - C:/WINDOWS/org.exe(自动)

O23 - 服务: Windows Firexwall (Windows Firewall) - C:/WINDOWS/G_Server1.23.exe(禁用)

O23 - 服务: windows_0 (Windows Accounts Driver) - C:/WINDOWS/system32/216.exe | 2005-6-11 11:5:34(禁用)

O23 - 服务: wljs0001.3322.org (wljs0001.3322.org) - C:/WINDOWS/system32/wljs0001.3322.org.exe | 2005-12-30 1:43:32(禁用)

O23 - 服务: xiaobo (xiaobo) - C:/WINDOWS/system32/xiaobo.exe | 2004-8-17 12:0:0 | Microsoft(R) Windows(R) Operating System | 5.2.3790.1830 | Generic Host Process for Win32 Services | (C) Microsoft Corporation. All rights reserved. | 5.2.3790.1830 | Microsoft Corporation |  | rpcs.exe | rpcs.exe(自动)

O25 - InsCom: {2bf41073-b2b1-21c1-b5c1-0701f4155588} = C:/Program Files/Common Files/Services/svchost.exe
---/

再试尝试 IceSword 来终止进程,依旧蓝屏~
只能在病毒进程活动的条件下进行修复~ 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

紫郢剑侠

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值