达人帮我看一下,卡巴主动防御注册表的问题
<P>2008-7-16 9:59:23 C:\WINDOWS\system32\msiexec.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SnapshotFile\shell\Open\command (Default) "C:\Program Files\Common Files\Microsoft Shared\Snapshot Viewer\SNAPVIEW.EXE" /dde 空结束的Unicode字符串 创建 被阻止 <BR></P><P>这个是什么意思啊?我禁止了.</P> 这个好像是要通过更改注册表来添加一个插件 SNAPVIEW.EXE。你阻止了,没有问题的(f%z4uk;[H/Y)NSg
[[i] 本帖最后由 数码先行 于 2008-7-16 13:43 编辑 [/i]] <P>这个是MS 里面的Access 里的报表快照。。楼主使用的应该是ofice2003吧。。</P>
<P><BR> 空结束的Unicode字符串 创建 被阻止。。楼主用的肯定是卡巴7.0版本。。</P>6]7Z/j'?a4i x
<P><BR>这个在主动防御里面我以前遇到过,若是楼主的Office2003更新到最新补丁的话,这个不该阻止的,</P>@.jt*G BI
<P> </P>
<P>要不然会导致数据库无法查看报表,或者Access出现问题。。。</P>!W,t-r/Z;j's }t:hU2l)P
<P> </P>
<P><BR><STRONG>引。。。。。。。。。。。。。。。。</STRONG></P><STRONG>'wl7\5b/f8A?
<P><BR></STRONG>关于报表快照和 Snapshot Viewer 报表快照报表快照是一个包含了高精度的各 Microsoft Access 报表页的文件(.snp 扩</P>
<P> </P>k'qM6FC_(n%g
<P>展名),并且其中保存了报表中的二维格式、图形和其他嵌入的对象。 Snapshot Viewer Snapshot Viewer 是一个用于</P>
<P> </P>*eE:J)iA
<P>观看、打印、和发送快照的程序,例如报表快照程序。</P> 楼上说的都对,但是我们局域网里现在木马泛滥,ARP攻击很多,我怀疑是不是木马导致让我安装这个阿,以前都不用安装的。)_+Yz.R5O]&e
trjMFm;R8b
我现在又用回NOD32了,卡巴太占内存了。SC5u}!_)]2u
时间 模块 对象 名称 病毒 操作 用户 信息
2008-7-16 14:24:12 网络监控 文件 [url]http://ww.xnibi.com/71.swf[/url] SWF/Exploit.CVE-2007-0071 木马 <P>[CODE]</P>
<P>2008-07-16,14:30:28</P>
<P>System Repair Engineer 2.6.12.1018<BR>Smallfrogs (<A href="http://www.KZTechs.com">http://www.KZTechs.com</A>)</P>"o#C&v0Ea7B2x
<P>Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能</P>
<P>以下内容被选中:<BR> 所有的启动项目(包括注册表、启动文件夹、服务等)<BR> 浏览器加载项<BR> 正在运行的进程(包括进程模块信息)<BR> 文件关联<BR> Winsock 提供者<BR> Autorun.inf<BR> HOSTS 文件<BR> 进程特权扫描</P>
<P><BR>启动项目<BR>注册表<BR>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<BR> <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]<BR> <load><> [N/A]<BR>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<BR> <Cmaudio><RunDll32 cmicnfg.cpl,CMICtrlWnd> [N/A]<BR> <nod32kui><"C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE> [Eset ]<BR> <SKYNET Personal FireWall><C:\PROGRA~1\SkyNet\FireWall\pfw.exe> [广州众达天网技术有限公司]<BR> <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]<BR> <Acrobat Assistant 7.0><"C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"> [Adobe Systems Inc.]<BR> <MSConfig><C:\WINDOWS\system32\msconfig.exe /auto> [(Verified)Microsoft Windows Publisher]<BR> <AntiARPStandalone><C:\Program Files\彩影软件\ARP防火墙单机版\AntiARP.exe> []<BR>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]<BR> <tzc02,0,tzchange.exe /F Pacific SA Standard Time /S 10 6 2 23 59 59 999 /E 3 6 2 23 59 59 999 /G><> [N/A]<BR>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]<BR> <shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]<BR> <Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]<BR> <AppInit_DLLs><> [N/A]<BR>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]<BR> <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]<BR> <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [Microsoft Corporation]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]<BR> <PostBootReminder><%SystemRoot%\system32\SHELL32.dll> [Microsoft Corporation]<BR> <CDBurn><%SystemRoot%\system32\SHELL32.dll> [Microsoft Corporation]<BR> <WebCheck><%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Publisher]<BR> <SysTray><C:\WINDOWS\system32\stobject.dll> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]<BR> <WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]<BR> <WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]<BR> <WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]<BR> <WinlogonNotify: ScCertProp><wlnotify.dll> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]<BR> <WinlogonNotify: Schedule><wlnotify.dll> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]<BR> <WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]<BR> <WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]<BR> <WinlogonNotify: termsrv><wlnotify.dll> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]<BR> <WinlogonNotify: wlballoon><wlnotify.dll> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]<BR> <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [Microsoft Corporation]<BR> <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [Microsoft Corporation]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]<BR> <Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP> [(Verified)Microsoft Windows Component Publisher]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]<BR> <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]<BR> <浏览器自定义组件><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]<BR> <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]<BR> <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]<BR> <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]<BR> <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> []<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]<BR> <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]<BR> <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]<BR> <Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]<BR> <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Publisher]<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<BR> <KernelFaultCheck><; %systemroot%\system32\dumprep 0 -k> [File is missing]</P>
<P>==================================<BR>启动文件夹<BR>N/A</P>!t9T!w/p P!F
<P>==================================<BR>服务<BR>[DCOM Server Process Launcher / DcomLaunch][Running/Auto Start]<BR> <C:\WINDOWS\system32\svchost -k DcomLaunch-->%SystemRoot%\system32\rpcss.dll><Microsoft Corporation><BR>[DHCP Client / Dhcp][Running/Auto Start]<BR> <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\dhcpcsvc.dll><Microsoft Corporation><BR>[COM+ Event System / EventSystem][Running/Manual Start]<BR> <C:\WINDOWS\system32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\es.dll><Microsoft Corporation><BR>[Fast User Switching Compatibility / FastUserSwitchingCompatibility][Stopped/Manual Start]<BR> <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\shsvcs.dll><Microsoft Corporation><BR>[Human Interface Device Access / HidServ][Stopped/Disabled]<BR> <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A><BR>[HuntmineSvr / HuntmineSvr][Running/Disabled]<BR> <D:\Program Files\Huntmine\HuntmineSvr.exe><N/A><BR>[Server / lanmanserver][Running/Auto Start]<BR> <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\srvsvc.dll><Microsoft Corporation><BR>[Workstation / lanmanworkstation][Running/Auto Start]<BR> <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\wkssvc.dll><Microsoft Corporation><BR>[Network Connections / Netman][Running/Manual Start]<BR> <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\netman.dll><Microsoft Corporation><BR>[NOD32 Kernel Service / NOD32krn][Running/Auto Start]<BR> <"C:\Program Files\Eset\nod32krn.exe"><Eset><BR>[Remote Access Connection Manager / RasMan][Stopped/Manual Start]<BR> <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\rasmans.dll><Microsoft Corporation><BR>[Remote Procedure Call (RPC) / RpcSs][Running/Auto Start]<BR> <C:\WINDOWS\system32\svchost -k rpcss-->%SystemRoot%\system32\rpcss.dll><Microsoft Corporation><BR>[Shell Hardware Detection / ShellHWDetection][Running/Auto Start]<BR> <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\shsvcs.dll><Microsoft Corporation><BR>[Print Spooler / Spooler][Running/Auto Start]<BR> <C:\WINDOWS\system32\spoolsv.exe><Microsoft Corporation><BR>[Windows Image Acquisition (WIA) / stisvc][Running/Manual Start]<BR> <C:\WINDOWS\system32\svchost.exe -k imgsvc-->%SystemRoot%\system32\wiaservc.dll><Microsoft Corporation><BR>[Telephony / TapiSrv][Stopped/Manual Start]<BR> <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\tapisrv.dll><Microsoft Corporation><BR>[Themes / Themes][Running/Auto Start]<BR> <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\shsvcs.dll><Microsoft Corporation><BR>[WebClient / WebClient][Running/Auto Start]<BR> <C:\WINDOWS\system32\svchost.exe -k LocalService-->%SystemRoot%\System32\webclnt.dll><Microsoft Corporation><BR>[ARP防火墙加载程序 / AntiARPClientLoader][Stopped/Auto Start]<BR> <"C:\Program Files\彩影软件\ARP防火墙单机版\AntiARPClientLoader.exe"><N/A></P>
<P>==================================<BR>驱动程序<BR>[Microsoft Kernel Acoustic Echo Canceller / aec][Stopped/Manual Start]<BR> <system32\drivers\aec.sys><Microsoft Corporation><BR>[AMON / AMON][Running/Auto Start]<BR> <\SystemRoot\system32\drivers\amon.sys><Eset><BR>[C-Media WDM Audio Interface / cmuda][Running/Manual Start]<BR> <system32\drivers\cmuda.sys><C-Media Inc><BR>[FltMgr / FltMgr][Running/Boot Start]<BR> <\SystemRoot\system32\DRIVERS\fltMgr.sys><Microsoft Corporation><BR>[HTTP / HTTP][Running/Manual Start]<BR> <System32\Drivers\HTTP.sys><Microsoft Corporation><BR>[IP Network Address Translator / IpNat][Running/Manual Start]<BR> <system32\DRIVERS\ipnat.sys><Microsoft Corporation><BR>[Microsoft Kernel Wave Audio Mixer / kmixer][Running/Manual Start]<BR> <system32\drivers\kmixer.sys><Microsoft Corporation><BR>[MRxSmb / MRxSmb][Running/System Start]<BR> <system32\DRIVERS\mrxsmb.sys><Microsoft Corporation><BR>[nod32drv / nod32drv][Running/System Start]<BR> <\SystemRoot\system32\drivers\nod32drv.sys><N/A><BR>[nv / nv][Running/Manual Start]<BR> <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation><BR>[NVIDIA nForce MCP Networking Controller Driver / NVENET][Running/Manual Start]<BR> <system32\DRIVERS\NVENET.sys><NVIDIA Corporation><BR>[nvidesm / nvidesm][Running/Boot Start]<BR> <\SystemRoot\system32\drivers\nvidesm.sys><NVIDIA Corporation><BR>[NVIDIA nForce AGP Bus Filter / nv_agp][Running/Boot Start]<BR> <\SystemRoot\system32\DRIVERS\nv_agp.sys><NVIDIA Corporation><BR>[Direct Parallel Link Driver / Ptilink][Running/Manual Start]<BR> <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.><BR>[Rdbss / Rdbss][Running/System Start]<BR> <system32\DRIVERS\rdbss.sys><Microsoft Corporation><BR>[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]<BR> <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation><BR>[Secdrv / Secdrv][Stopped/Manual Start]<BR> <system32\DRIVERS\secdrv.sys><N/A><BR>[SKNFW / SKNFW][Running/System Start]<BR> <\??\C:\WINDOWS\system32\Drivers\SKNFW.sys><N/A><BR>[SkyProcs / SkyProcs][Running/Manual Start]<BR> <\??\C:\PROGRA~1\SkyNet\FireWall\SkyProcs.sys><N/A><BR>[Microsoft Kernel Audio Splitter / splitter][Stopped/Manual Start]<BR> <system32\drivers\splitter.sys><Microsoft Corporation><BR>[sptd / sptd][Running/Boot Start]<BR> <\SystemRoot\System32\Drivers\sptd.sys><N/A><BR>[Srv / Srv][Running/Manual Start]<BR> <system32\DRIVERS\srv.sys><Microsoft Corporation><BR>[TCP/IP Protocol Driver / Tcpip][Running/System Start]<BR> <system32\DRIVERS\tcpip.sys><Microsoft Corporation><BR>[Microcode Update Driver / Update][Running/Manual Start]<BR> <system32\DRIVERS\update.sys><Microsoft Corporation><BR>[Microsoft WINMM WDM Audio Compatibility Driver / wdmaud][Running/Manual Start]<BR> <system32\drivers\wdmaud.sys><Microsoft Corporation><BR>[xAntiArpSpoof Service / xAntiArp][Running/Manual Start]<BR> <system32\DRIVERS\xAntiArp.sys><Windows (R) 2000 DDK provider><BR>[AntiARP NDIS Protocol Driver / AntiArpNdisProt][Running/Auto Start]<BR> <system32\DRIVERS\AntiArpNdisProt.sys><Windows (R) 2000 DDK provider><BR>[WinPcap Packet Driver (NPF) / NPF][Running/Manual Start]<BR> <system32\drivers\NPF.sys><CACE Technologies></P>%Qkf`3z)g^Zo
<P>==================================<BR>浏览器加载项<BR>[AcroIEHlprObj Class]<BR> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, (Signed) Adobe Systems Incorporated><BR>[AcroIEToolbarHelper Class]<BR> {AE7CD045-E861-484f-8273-0445EE161910} <C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated><BR>[信息检索(&R)]<BR> {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL, (Signed) Microsoft Corporation><BR>[Adobe PDF]<BR> {47833539-D0C5-4125-9FA8-0819E2EAAC93} <C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated><BR>[AcroIEHlprObj Class]<BR> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, (Signed) Adobe Systems Incorporated><BR>[Adobe PDF]<BR> {47833539-D0C5-4125-9FA8-0819E2EAAC93} <C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated><BR>[]<BR> {92780B25-18CC-41C8-B9BE-3C9C571A8263} <, ><BR>[AcroIEToolbarHelper Class]<BR> {AE7CD045-E861-484F-8273-0445EE161910} <C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated><BR>[SearchAssistantOC]<BR> {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A><BR>[Shockwave Flash Object]<BR> {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, (Signed) Adobe Systems, Inc.><BR>[导出到 Microsoft Office Excel(&X)]<BR> <res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A><BR>[转换为 Adobe PDF]<BR> <res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A><BR>[转换为现有 PDF]<BR> <res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A><BR>[转换选定的链接为 Adobe PDF]<BR> <res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html, N/A><BR>[转换选定的链接为现有 PDF]<BR> <res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html, N/A><BR>[转换选项为 Adobe PDF]<BR> <res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A><BR>[转换选项为现有 PDF]<BR> <res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A><BR>[转换链接目标为 Adobe PDF]<BR> <res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A><BR>[转换链接目标为现有 PDF]<BR> <res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A></P> <P>==================================<BR>正在运行的进程<BR>[PID: 448 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR>[PID: 752 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\winsrv.dll] [Microsoft Corporation, 5.1.2600.2751 (xpsp_sp2_gdr.050831-1520)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\KERNEL32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\sxs.dll] [Microsoft Corporation, 5.1.2600.3019 (xpsp_sp2_gdr.061019-0414)]<BR>[PID: 776 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\AUTHZ.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\COMCTL32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [C:\WINDOWS\system32\SHSVCS.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003)]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR>[PID: 824 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\AUTHZ.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\umpnpmgr.dll] [Microsoft Corporation, 5.1.2600.2744 (xpsp_sp2_gdr.050822-1647)]<BR> [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR>[PID: 844 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\LSASRV.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [C:\WINDOWS\system32\kerberos.dll] [Microsoft Corporation, 5.1.2600.2698 (xpsp_sp2_gdr.050614-1522)]<BR> [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003)]<BR> [C:\WINDOWS\system32\wdigest.dll] [Microsoft Corporation, 5.1.2600.2874 (xpsp_sp2_gdr.060323-1516)]<BR> [C:\WINDOWS\system32\AUTHZ.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_imon.dll] [N/A, ]<BR>[PID: 988 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [c:\windows\system32\rpcss.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [c:\windows\system32\AUTHZ.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR>[PID: 1036 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [c:\windows\system32\rpcss.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_imon.dll] [N/A, ]<BR> [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003)]<BR> [C:\WINDOWS\system32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR>[PID: 1108 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [C:\WINDOWS\System32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [c:\windows\system32\shsvcs.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [c:\windows\system32\dhcpcsvc.dll] [Microsoft Corporation, 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003)]<BR> [c:\windows\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [c:\windows\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003)]<BR> [c:\windows\system32\ESENT.dll] [Microsoft Corporation, 5.1.2468.0 (Lab03_N(jliem).010306-1456)]<BR> [C:\WINDOWS\System32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [c:\windows\system32\wkssvc.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [c:\windows\system32\es.dll] [Microsoft Corporation, 2001.12.4414.308]<BR> [c:\windows\system32\srvsvc.dll] [Microsoft Corporation, 5.1.2600.2577 (xpsp_sp2_gdr.041130-1729)]<BR> [c:\windows\system32\netman.dll] [Microsoft Corporation, 5.1.2600.2743 (xpsp_sp2_gdr.050819-1525)]<BR> [C:\WINDOWS\System32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_imon.dll] [N/A, ]<BR> [c:\windows\system32\AUTHZ.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\System32\SXS.DLL] [Microsoft Corporation, 5.1.2600.3019 (xpsp_sp2_gdr.061019-0414)]<BR> [C:\WINDOWS\system32\comsvcs.dll] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\colbact.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\MTXCLU.DLL] [Microsoft Corporation, 2001.12.4414.311]<BR> [C:\WINDOWS\System32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [C:\WINDOWS\System32\catsrvut.dll] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\System32\catsrv.dll] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.3072 (xpsp_sp2_gdr.070124-2319)]<BR>[PID: 1164 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [c:\windows\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [c:\windows\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003)]<BR> [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_imon.dll] [N/A, ]<BR>[PID: 1288 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [c:\windows\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003)]<BR> [c:\windows\system32\webclnt.dll] [Microsoft Corporation, 5.1.2600.2821 (xpsp_sp2_gdr.060103-1536)]<BR> [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_imon.dll] [N/A, ]<BR>[PID: 1440 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003)]<BR> [C:\WINDOWS\system32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\netapi32.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [C:\WINDOWS\system32\AdobePDF.dll] [Adobe Systems Incorporated., 7.0.0.00]<BR> [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]<BR> [C:\Program Files\Adobe\Acrobat 7.0\Distillr\AdistRes.CHS] [, ]<BR> [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR>[PID: 1568 / SYSTEM][D:\Program Files\Huntmine\HuntmineSvr.exe] [N/A, ]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [D:\Program Files\Huntmine\SSNBase.dll] [TODO: <Company name>, 1.0.0.1]<BR> [D:\Program Files\Huntmine\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]<BR> [D:\Program Files\Huntmine\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [D:\Program Files\Huntmine\LIBEAY32.dll] [N/A, ]<BR> [D:\Program Files\Huntmine\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]<BR> [D:\Program Files\Huntmine\LocalInfo.dll] [TODO: <Company name>, 1.0.0.1]<BR> [D:\Program Files\Huntmine\med.dll] [, 1, 0, 0, 1]<BR> [C:\WINDOWS\system32\COMCTL32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [D:\Program Files\Huntmine\VirtualSock.dll] [TODO: <Company name>, 1.0.0.1]<BR> [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003)]<BR> [D:\Program Files\Huntmine\FileTransfer.dll] [TODO: <Company name>, 1.0.0.1]<BR> [D:\Program Files\Huntmine\SSNCommand.dll] [TODO: <Company name>, 1.0.0.1]<BR> [D:\Program Files\Huntmine\SSNAccept.dll] [TODO: <Company name>, 1.0.0.1]<BR> [D:\Program Files\Huntmine\SSNCmdExecute.dll] [TODO: <Company name>, 1.0.0.1]<BR> [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]<BR> [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\netapi32.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.3072 (xpsp_sp2_gdr.070124-2319)]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_imon.dll] [N/A, ]<BR> [C:\Program Files\Common Files\System\ado\msado15.dll] [Microsoft Corporation, 2.81.1128.0 (xpsp_sp2_gdr.061226-0034)]<BR> [C:\WINDOWS\system32\comsvcs.dll] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\colbact.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\MTXCLU.DLL] [Microsoft Corporation, 2001.12.4414.311]<BR> [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [C:\WINDOWS\system32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR>[PID: 1600 / SYSTEM][C:\Program Files\Eset\nod32krn.exe] [Eset , 2, 70, 32 ]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\Program Files\Eset\nod32krr.dll] [Eset , 2, 70, 16 ]<BR> [C:\Program Files\Eset\ps_amon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_amon.dll] [Eset , 2, 70, 16 ]<BR> [C:\Program Files\Eset\ps_dmon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_dmon.dll] [N/A, ]<BR> [C:\Program Files\Eset\ps_emon.dll] [Eset , 2, 70, 32 ]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [C:\Program Files\Eset\pr_emon.dll] [N/A, ]<BR> [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_imon.dll] [N/A, ]<BR> [C:\Program Files\Eset\ps_nod32.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_nod32.dll] [Eset , 2, 70, 16 ]<BR> [C:\Program Files\Eset\ps_upd.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_upd.dll] [N/A, ]<BR> [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003)]<BR> [C:\WINDOWS\system32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR>[PID: 404 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [C:\WINDOWS\System32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\System32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_imon.dll] [N/A, ]<BR>[PID: 1648 / Astrnova][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR>[PID: 280 / Astrnova][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\BROWSEUI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\SHDOCVW.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\LINKINFO.dll] [Microsoft Corporation, 5.1.2600.2751 (xpsp_sp2_gdr.050831-1520)]<BR> [C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.3072 (xpsp_sp2_gdr.070124-2319)]<BR> [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003)]<BR> [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.0.2004121400]<BR> [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]<BR> [C:\WINDOWS\system32\SXS.DLL] [Microsoft Corporation, 5.1.2600.3019 (xpsp_sp2_gdr.061019-0414)]<BR> [C:\WINDOWS\system32\MLANG.dll] [Microsoft Corporation, 6.00.2900.2530 (xpsp.040919-1030)]<BR> [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]<BR> [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS] [Adobe Systems, Inc., 7.0.0.0]<BR> [C:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.chs] [Adobe Systems Inc., 7.0.0.2004121400\0]<BR> [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\Program Files\WinRAR\rarext.dll] [N/A, ]<BR> [C:\Program Files\Eset\nodshex.dll] [N/A, ]<BR> [C:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll] [Adobe Systems Inc., 7.0.0.2004121400\0]<BR> [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]<BR> [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]<BR> [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]<BR>[PID: 520 / Astrnova][C:\WINDOWS\system32\RunDll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [C:\WINDOWS\system\cmicnfg.cpl] [C-Media Corporation, 1, 0, 0, 30]<BR> [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR>[PID: 528 / Astrnova][C:\Program Files\Eset\nod32kui.exe] [Eset , 2, 70, 32 ]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\Program Files\Eset\nod32rui.dll] [N/A, ]<BR> [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\Program Files\Eset\pu_amon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_amon.dll] [Eset , 2, 70, 16 ]<BR> [C:\Program Files\Eset\pu_dmon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_dmon.dll] [N/A, ]<BR> [C:\Program Files\Eset\pu_emon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_emon.dll] [N/A, ]<BR> [C:\Program Files\Eset\pu_imon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_imon.dll] [N/A, ]<BR> [C:\Program Files\Eset\pu_nod32.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_nod32.dll] [Eset , 2, 70, 16 ]<BR> [C:\Program Files\Eset\pu_upd.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_upd.dll] [N/A, ]<BR> [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS] [Adobe Systems, Inc., 7.0.0.0]<BR> [C:\WINDOWS\system32\LINKINFO.dll] [Microsoft Corporation, 5.1.2600.2751 (xpsp_sp2_gdr.050831-1520)]<BR>[PID: 1420 / Astrnova][C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe] [Adobe Systems Inc., 6.0.1.2004121400]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\COMCTL32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.chs] [Adobe Systems Inc., 6.0.0.0]<BR>[PID: 560 / Astrnova][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR>[PID: 2796 / SYSTEM][C:\WINDOWS\system32\msiexec.exe] [Microsoft Corporation, 3.1.4000.1823]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\netapi32.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\LINKINFO.dll] [Microsoft Corporation, 5.1.2600.2751 (xpsp_sp2_gdr.050831-1520)]<BR>[PID: 3280 / Astrnova][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR>[PID: 2500 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [c:\windows\system32\wiaservc.dll] [Microsoft Corporation, 5.1.2600.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [c:\windows\system32\mscms.dll] [Microsoft Corporation, 5.1.2600.2709 (xpsp_sp2_gdr.050628-1518)]<BR> [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR>[PID: 1180 / Astrnova][C:\Program Files\DZH5\internet\hypwise.exe] [N/A, ]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\netapi32.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\shell32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\Program Files\DZH5\internet\olepro32.dll] [Microsoft Corporation, 5.0.4275]<BR> [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\shdocvw.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_imon.dll] [N/A, ]<BR> [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [C:\WINDOWS\system32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR>[PID: 4084 / Astrnova][C:\Program Files\DZH5\internet\hypmain.exe] [GreatWise, 5.4.5.3002]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\user32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\Program Files\DZH5\internet\borlndmm.dll] [Inprise Corporation, 5.0.6.18]<BR> [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [C:\WINDOWS\system32\shell32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\wininet.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.3072 (xpsp_sp2_gdr.070124-2319)]<BR> [C:\Program Files\DZH5\internet\tcpip.dll] [, 1, 0, 0, 1]<BR> [C:\Program Files\DZH5\wt\gtja\fy\bin\flyingfish.dll] [N/A, ]<BR> [C:\Program Files\DZH5\internet\investdll.dll] [, 1, 0, 0, 3]<BR> [C:\Program Files\DZH5\internet\wgdll.dll] [N/A, ]<BR> [C:\Program Files\DZH5\internet\zlib.dll] [N/A, ]<BR> [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\Program Files\DZH5\internet\olepro32.dll] [Microsoft Corporation, 5.0.4275]<BR> [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_imon.dll] [N/A, ]<BR> [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [C:\WINDOWS\system32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR>[PID: 4016 / Astrnova][D:\Program Files\Tencent\QQ\QQ.exe] [TENCENT, 7,0,431,1723]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [D:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] [TENCENT, 7,0,431,1723]<BR> [D:\Program Files\Tencent\QQ\QQHelperDll.dll] [TENCENT, 7,0,431,1723]<BR> [D:\Program Files\Tencent\QQ\BasicCtrlDll.dll] [TENCENT, 7, 0, 431, 1723]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\COMCTL32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003)]<BR> [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [D:\Program Files\Tencent\QQ\QQAPI.dll] [TENCENT, 7,0,431,1723]<BR> [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [D:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]<BR> [C:\WINDOWS\system32\SXS.DLL] [Microsoft Corporation, 5.1.2600.3019 (xpsp_sp2_gdr.061019-0414)]<BR> [D:\Program Files\Tencent\QQ\LoginCtrl.dll] [TENCENT, 7,0,431,1723]<BR> [D:\Program Files\Tencent\QQ\LoginCtrlRes.dll] [TENCENT, 7,0,431,1723]<BR> [D:\Program Files\Tencent\QQ\QQRes.dll] [TENCENT, 7,0,431,1723]<BR> [D:\Program Files\Tencent\QQ\QQMainFrame.dll] [N/A, ]<BR> [C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.3072 (xpsp_sp2_gdr.070124-2319)]<BR> [D:\Program Files\Tencent\QQ\UnReadMsgMgr.dll] [N/A, ]<BR> [D:\Program Files\Tencent\QQ\CQQApplication.dll] [N/A, ]<BR> [D:\Program Files\Tencent\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]<BR> [D:\Program Files\Tencent\QQ\NewSkin.dll] [TENCENT, 7,0,431,1723]<BR> [D:\Program Files\Tencent\QQ\MailSummary.dll] [TENCENT, 7,0,431,1723]<BR> [D:\Program Files\Tencent\QQ\QQKnowledgeSearch.dll] [TENCENT, 7,0,431,1723]<BR> [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_imon.dll] [N/A, ]<BR> [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [C:\WINDOWS\system32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [D:\Program Files\Tencent\QQ\QQAllInOne.dll] [TENCENT, 7,0,431,1723]<BR> [D:\Program Files\Tencent\QQ\SCCore.dll] [TENCENT, 1, 6, 0, 2]<BR> [D:\Program Files\Tencent\QQ\CameraDll.dll] [TENCENT, 7,0,431,1723]<BR> [D:\Program Files\Tencent\QQ\QQSpace.dll] [TENCENT, 7,0,431,1723]<BR> [C:\WINDOWS\system32\msdmo.dll] [, ]<BR> [D:\Program Files\Tencent\QQ\QQGroupMng.dll] [TENCENT, 7,0,431,1723]<BR> [D:\Program Files\Tencent\QQ\QQSysMsgMng.dll] [N/A, ]<BR> [D:\Program Files\Tencent\QQ\UserDefinedHead.dll] [TENCENT, 7,0,431,1723]<BR> [D:\Program Files\Tencent\QQ\QQPlugin.dll] [N/A, ]<BR> [D:\Program Files\Tencent\QQ\QQConfigPlugin.dll] [TENCENT, 7,0,431,1723]<BR> [D:\Program Files\Tencent\QQ\QQAvatar.dll] [N/A, ]<BR> [D:\Program Files\Tencent\QQ\QQCustomFace.dll] [N/A, ]<BR> [C:\WINDOWS\system32\shdocvw.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [D:\Program Files\Tencent\QQ\QRingMng.dll] [N/A, ]<BR> [D:\Program Files\Tencent\QQ\LongConnection.dll] [TENCENT, 7,0,431,1723]<BR> [C:\WINDOWS\system32\mlang.dll] [Microsoft Corporation, 6.00.2900.2530 (xpsp.040919-1030)]<BR> [D:\Program Files\Tencent\QQ\PhoneAPI.dll] [TENCENT, 7,0,431,1723]<BR> [D:\Program Files\Tencent\QQ\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]<BR> [D:\Program Files\Tencent\QQ\QQPet.dll] [TENCENT, 7,0,431,1723]<BR> [D:\Program Files\Tencent\QQ\BQQApplication.dll] [N/A, ]<BR> [D:\Program Files\Tencent\QQ\GroupConnection.dll] [TENCENT, 7,0,431,1723]<BR> [D:\Program Files\Tencent\QQ\CommercesMng.dll] [TENCENT, 7,0,431,1723]<BR> [D:\Program Files\Tencent\QQ\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]<BR> [D:\Program Files\Tencent\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 310]<BR> [D:\Program Files\Tencent\QQ\QQSceneMng.dll] [N/A, ]<BR> [D:\Program Files\Tencent\QQ\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 2, 1, 15]<BR> [C:\WINDOWS\system32\LINKINFO.dll] [Microsoft Corporation, 5.1.2600.2751 (xpsp_sp2_gdr.050831-1520)]<BR>[PID: 3116 / Astrnova][D:\Program Files\Tencent\QQ\TIMPlatform.exe] [TENCENT, 7,0,431,1723]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [D:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]<BR> [C:\WINDOWS\system32\SXS.DLL] [Microsoft Corporation, 5.1.2600.3019 (xpsp_sp2_gdr.061019-0414)]<BR> [C:\Program Files\DZH5\WT\GTJA\FY\bin\vcltrade.dll] [N/A, ]<BR>[PID: 1836 / Astrnova][C:\Program Files\Maxthon2\Maxthon.exe] [Maxthon International ltd., 2, 1, 2, 649]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003)]<BR> [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [C:\Program Files\Maxthon2\mxpp.dll] [Maxthon International ltd., 1, 0, 0, 117]<BR> [C:\Program Files\Maxthon2\MxSk.dll] [Maxthon, 1, 0, 0, 358]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.3072 (xpsp_sp2_gdr.070124-2319)]<BR> [C:\Program Files\Maxthon2\MxProxy2.dll] [Maxthon International ltd., 1, 0, 0, 4033]<BR> [C:\Program Files\Maxthon2\MxExt.dll] [N/A, ]<BR> [C:\Program Files\Maxthon2\MxUI.dll] [Maxthon International, 3, 3, 0, 3]<BR> [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\Program Files\Maxthon2\mxtool.dll] [, 1, 0, 0, 1]<BR> [C:\Program Files\Maxthon2\maxzlib.dll] [, 1.2.3]<BR> [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.308]<BR> [C:\WINDOWS\system32\RICHED20.dll] [Microsoft Corporation, 5.30.23.1228]<BR> [C:\WINDOWS\system32\msxml3.dll] [Microsoft Corporation, 8.70.1113.0]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\browseui.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\mlang.dll] [Microsoft Corporation, 6.00.2900.2530 (xpsp.040919-1030)]<BR> [C:\Program Files\Maxthon2\Modules\MxPageSearch\MxPageSearch.dll] [Maxthon International ltd., 1,0,0,1330]<BR> [C:\Program Files\Maxthon2\Modules\MxWebBoost\MxWebBoost.dll] [Maxthon, 1,0,2,1259]<BR> [C:\Program Files\Maxthon2\mxdb.dll] [Max, 3, 5, 3, 125]<BR> [C:\WINDOWS\system32\shdocvw.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\SXS.DLL] [Microsoft Corporation, 5.1.2600.3019 (xpsp_sp2_gdr.061019-0414)]<BR> [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_imon.dll] [N/A, ]<BR> [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [C:\WINDOWS\system32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [C:\Program Files\Maxthon2\Modules\MxHistory\MxHistory.dll] [Maxthon International ltd., 1, 0, 0, 7]<BR> [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\mshtml.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\jscript.dll] [Microsoft Corporation, 5.6.0.8831]<BR> [C:\Program Files\Common Files\System\msadc\msadco.dll] [Microsoft Corporation, 2.81.1124.0 (xpsp_sp2_gdr.060322-1613)]<BR> [C:\Program Files\Maxthon2\MxFav.dll] [Maxthon International ltd., 1, 0, 0, 257]<BR> [C:\WINDOWS\system32\pngfilt.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0]<BR> [C:\WINDOWS\system32\mshtmled.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\dxtrans.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\dxtmsft.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\quartz.dll] [Microsoft Corporation, 6.05.2600.2749]<BR> [C:\WINDOWS\system32\msdmo.dll] [, ]<BR> [C:\WINDOWS\system32\iepeers.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\winabc.ime] [PKUETI, 5.22.216]<BR> [C:\WINDOWS\system32\MSRATING.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR>[PID: 3464 / Astrnova][E:\软件\扫描日志工具\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.6.12.1018]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\user32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR>[PID: 3588 / Astrnova][E:\软件\扫描日志工具\sreng2\SRE906fb410.EXE] [Smallfrogs Studio, 2.6.12.1018]<BR> [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)]<BR> [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]<BR> [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.2818 (xpsp_sp2_gdr.051228-1427)]<BR> [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]<BR> [C:\WINDOWS\system32\oledlg.dll] [Microsoft Corporation, 1.0 (xpsp_sp2_gdr.061016-0148)]<BR> [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]<BR> [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.3059 (xpsp_sp2_gdr.070104-0050)]<BR> [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\RICHED20.DLL] [Microsoft Corporation, 5.30.23.1228]<BR> [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]<BR> [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]<BR> [C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.3072 (xpsp_sp2_gdr.070124-2319)]<BR> [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [C:\WINDOWS\system32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]<BR> [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 32 ]<BR> [C:\Program Files\Eset\pr_imon.dll] [N/A, ]<BR> [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]</P>JdW!K)eu#c5J
<P>==================================<BR>文件关联<BR>.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]<BR>.EXE OK. ["%1" %*]<BR>.COM OK. ["%1" %*]<BR>.PIF OK. ["%1" %*]<BR>.REG OK. [regedit.exe "%1"]<BR>.BAT OK. ["%1" %*]<BR>.SCR OK. ["%1" /S]<BR>.CHM OK. ["C:\WINDOWS\hh.exe" %1]<BR>.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]<BR>.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]<BR>.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]<BR>.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]<BR>.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]<BR>.LNK OK. [{00021401-0000-0000-C000-000000000046}]</P>Q1xE2Z+XYM
<P>==================================<BR>Winsock 提供者<BR>NOD32 protected [MSAFD Tcpip [TCP/IP]]<BR> C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)<BR>NOD32 protected [MSAFD Tcpip [UDP/IP]]<BR> C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)<BR>NOD32 protected [MSAFD Tcpip [RAW/IP]]<BR> C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)<BR>NOD32 protected [RSVP UDP Service Provider]<BR> C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)<BR>NOD32 protected [RSVP TCP Service Provider]<BR> C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)<BR>NOD32<BR> C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)</P>
<P>==================================<BR>Autorun.inf<BR>N/A</P>6CW6Z$i wvt:Jl!}
<P>==================================<BR>HOSTS 文件<BR>127.0.0.1 localhost</P>)QP`.h4|,{
<P>==================================<BR>进程特权扫描<BR>特殊特权被允许: SeLoadDriverPrivilege [PID = 1440, C:\WINDOWS\SYSTEM32\SPOOLSV.EXE]<BR>特殊特权被允许: SeLoadDriverPrivilege [PID = 1568, D:\PROGRAM FILES\HUNTMINE\HUNTMINESVR.EXE]<BR>特殊特权被允许: SeLoadDriverPrivilege [PID = 528, C:\PROGRAM FILES\ESET\NOD32KUI.EXE]<BR>特殊特权被允许: SeLoadDriverPrivilege [PID = 1420, C:\PROGRAM FILES\ADOBE\ACROBAT 7.0\DISTILLR\ACROTRAY.EXE]<BR>特殊特权被允许: SeLoadDriverPrivilege [PID = 1180, C:\PROGRAM FILES\DZH5\INTERNET\HYPWISE.EXE]<BR>特殊特权被允许: SeLoadDriverPrivilege [PID = 4084, C:\PROGRAM FILES\DZH5\INTERNET\HYPMAIN.EXE]<BR>特殊特权被允许: SeLoadDriverPrivilege [PID = 3464, E:\软件\扫描日志工具\SRENG2\SRENGLDR.EXE]</P>
<P>==================================<BR>API HOOK<BR>N/A</P>Qfb"nr{6qo
<P>==================================<BR>隐藏进程<BR>N/A</P>U+U2h \s
<P>==================================</P>@ ab tG.r7?
<P><BR>[/CODE]</P>+[&enf0bp.xuy@
<P> </P>A)o3XQ0e Juo+\
<P> </P>
<P> </P>Q3R Z kHx(]J
<P> </P>
<P>这个是我扫的日志</P> 楼主装了天网和ARP防火墙?装的安全软件太多了未必能起到很好的保护作用。:@28# <H3 style="MARGIN: auto 0cm"><SPAN lang=EN-US><FONT face=宋体 color=black size=3><SPAN lang=EN-US>[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]<BR> <load><> [N/A]<BR>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<BR> <Cmaudio><RunDll32 cmicnfg.cpl,CMICtrlWnd> [N/A]<BR>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]<BR> <AppInit_DLLs><> [N/A]<BR>楼主要注意以上键值地方,中木马后杀掉还有未修复的地方。你最好打开启动项查看下有无异常,<BR>打开运行——msconfig——查看启动里面有无异常,用楼主的那个软件SRE也可以查看下。<BR>楼主说的那个病毒下载链接我看过了,那个是漏洞利用型的木马链接,楼主电脑里面的补丁没有打<BR>全吧。比如 Adobe Flash Player、IE漏洞 。楼主那个office2003的数据报表漏洞是否被修不了?<BR>被病毒利用了漏洞。建议用360安全卫士检查系统漏洞情况。。。修补系统漏洞比安装杀软更重要啊<BR>EXP/Flash.Gen is a generic detection routine designed to detect the exploitati。。on of a remote code execution vulnerability in Adobe Flash Player. It was developed in order to detect unknown variants of malicious Flash content and will be continuously enhanced if needed。<BR>这段英文就描述了楼主连接木马的利用漏洞传播的。。。</SPAN></FONT></SPAN><SPAN lang=EN-US><FONT face=宋体 color=black size=3><SPAN lang=EN-US><BR>其实楼主的电脑里面现在装的东西并不多,nod32+天网防火墙+彩影ARP防火墙,这两个防火墙有那<BR>么一点冲突,我觉的金山的ARP防火墙很不错的,比360ARP防火墙强多了,相当于企业级了。。<BR>我推荐用。。因为我测试过了。。对于天网防火墙,我是觉得装了作用不是很大。。可以换其他的墙。<BR>楼主可以用ESS套装,或者装小红伞也不错。。。。。。<BR></H3></SPAN></FONT></SPAN>
p$X$vk.w
[[i] 本帖最后由 ngc0717 于 2008-7-16 16:05 编辑 [/i]] <P>不好意思。。上面的不知道怎么搞的。。弄成那样了。。。呵呵。。再发一遍。。。</P>!js\h.c/|L_
<P> </P> nW Q)rl6e\
<P> </P>
<P>[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]<BR> <load><> [N/A]<BR>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<BR> <Cmaudio><RunDll32 cmicnfg.cpl,CMICtrlWnd> [N/A]<BR>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]<BR> <AppInit_DLLs><> [N/A]</P>
<P><BR>楼主要注意以上键值地方,中木马后杀掉还有未修复的地方。你最好打开启动项查看下有无异常,</P>
<P><BR>打开运行——msconfig——查看启动里面有无异常,用楼主的那个软件SRE也可以查看下。</P>
<P><BR>楼主说的那个病毒下载链接我看过了,那个是漏洞利用型的木马链接,楼主电脑里面的补丁没有打</P>(n C1X3X:s C{
<P><BR>全吧。比如 Adobe Flash Player、IE漏洞 。楼主那个office2003的数据报表漏洞是否被修不了?</P>
<P><BR>被病毒利用了漏洞。建议用360安全卫士检查系统漏洞情况。。。修补系统漏洞比安装杀软更重要啊</P>
<P><BR>EXP/Flash.Gen is a generic detection routine designed to detect the exploitati。。on of a remote code execution </P>
<P> </P>[cPq+i*pM4W
<P>vulnerability in Adobe Flash Player. It was developed in order to detect unknown variants of malicious Flash content </P>
<P> </P>
<P>and will be continuously enhanced if needed。</P>
<P><BR>这段英文就描述了楼主连接木马的利用漏洞传播的。。。</P>QbD^B d!KL5WJ
<P><BR>其实楼主的电脑里面现在装的东西并不多,nod32+天网防火墙+彩影ARP防火墙,这两个防火墙有那</P>(SW \)}+a
<P><BR>么一点冲突,我觉的金山的ARP防火墙很不错的,比360ARP防火墙强多了,相当于企业级了。。</P>7w:TA}C{aGQ
<P><BR>我推荐用。。因为我测试过了。。对于天网防火墙,我是觉得装了作用不是很大。。可以换其他的墙。</P>n&N(ZRx$oQ
<P><BR>楼主可以用ESS套装,或者装小红伞也不错。。。。。。<BR></P> 呵呵 ,我以为那个是楼上特意那么发的呢还在想,是怎么发出来的呢, <P>当你打开论坛主页时。。会有如下图条出现。。</P>
<P> </P>
<P>[attach]48547[/attach]</P>
<P> </P>1B?bVwUu
<P>上面之所以会出现那样情况就是因为我是现在自己WORD里面写分析时,所用的字体恰好和这个图标里面的字体相匹</P>
<P> </P>
<P>配,而出现蓝色版面。。。由于排版就排成那样。。所以改不会来。。。呵呵。。</P>
<P> </P>%XzOIE+b1q J
<P> </P> 哦,是这回事呀,呵呵 ,学习了, 防ARP的软件其实都不起作用的,无非告你谁在冒充网关,对网速影响依然存在.%a1d6PD[
j.{+M8x K0Zx
像在家上网就不会有这种事,网管能定点关发包的端口
页:
[1]