- 最後登錄
- 2023-5-21
- 在線時間
- 2 小時
- 註冊時間
- 2007-7-18
- 閱讀權限
- 30
- 精華
- 0
- UID
- 1854034
- 帖子
- 139
- 積分
- 1921 點
- 潛水值
- 13727 米
| 本帖最後由 aassdd042000 於 2009-5-17 06:25 PM 編輯
- 2009-05-16,20:38:57
- System Repair Engineer 2.7.1.1261
- Smallfrogs (http://www.KZTechs.com)
- Windows 2000 Professional Service Pack 4 (Build 2195) - 管理許可權用戶 - 完整功能
- 以下內容被選中:
- 所有的啟動項目(包括註冊表、開機檔案夾、服務等)
- 流覽器載入項
- 正在運行的進程(包括進程模組資訊)
- 文件關聯
- Winsock 提供者
- Autorun.inf
- HOSTS 文件
- 進程特權掃描
- 計畫任務
- API HOOK
- 隱藏進程
- 啟動專案
- 註冊表
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- <ctfmon.exe><ctfmon.exe> [Microsoft Corporation]
- [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <load><> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- <Synchronization Manager><mobsync.exe /logon> [(Verified)Microsoft Windows 2000 Publisher]
- <IgfxTray><C:\WINNT\System32\igfxtray.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
- <HotKeysCmds><C:\WINNT\System32\hkcmd.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
- <OfficeScanNT Monitor><"C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow> [(Verified)"Trend Micro, Inc."]
- <WinVNC><"C:\Program Files\RealVNC\WinVNC\winvnc.exe" -servicehelper> [RealVNC Ltd.]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <shell><Explorer.exe> [(Verified)Microsoft Windows 2000 Publisher]
- <Userinit><C:\WINNT\system32\userinit.exe,> [(Verified)Microsoft Windows 2000 Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <AppInit_DLLs><> [N/A]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
- <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Windows 2000 Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
- <Network.ConnectionTray><C:\WINNT\system32\netshell.dll> [(Verified)Microsoft Windows 2000 Publisher]
- <WebCheck><%SystemRoot%\System32\webcheck.dll> [(Verified)Microsoft Windows Component Publisher]
- <SysTray><stobject.dll> [(Verified)Microsoft Windows 2000 Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
- <WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Windows 2000 Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
- <WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Windows 2000 Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
- <WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Windows 2000 Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\EFS]
- <WinlogonNotify: EFS><sclgntfy.dll> [(Verified)Microsoft Windows 2000 Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
- <WinlogonNotify: NavLogon><C:\WINNT\system32\NavLogon.dll> []
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
- <WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Windows 2000 Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
- <WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Windows 2000 Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
- <WinlogonNotify: wzcnotif><wzcdlg.dll> [(Verified)Microsoft Windows 2000 Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
- <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\System32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
- <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\System32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
- <Windows Media Player><C:\WINNT\system32\setup\wmpocm.exe /HideWMP> [(Verified)Microsoft Windows 2000 Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
- <Internet Explorer 存取><"C:\WINNT\system32\shmgrate.exe" OCInstallUserConfigIE> [File is missing]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
- <自訂瀏覽器><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
- <Outlook Express 存取><"C:\WINNT\system32\shmgrate.exe" OCInstallUserConfigOE> [File is missing]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
- <Microsoft Windows Media Player 6.4><rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\mplayer2.inf,PerUserStub.NT> [(Verified)Microsoft Windows 2000 Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
- <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
- <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows 2000 Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6A5110B5-E14B-4268-A065-EF89FF33C325}]
- <EnableRevocation><regsvr32.exe /s /n /i:"S 2 true 3 true 4 true 5 true 6 true 7 true" initpki.dll> [(Verified)Microsoft Windows 2000 Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
- <Address Book 5><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
- <Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll> [(Verified)Microsoft Windows 2000 Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
- <Internet Explorer 6><%SystemRoot%\System32\ie4uinit.exe> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
- <CRLUpdate><%SystemRoot%\System32\updcrl.exe -e -u %SystemRoot%\System32\verisignpub1.crl> [File is missing]
- ==================================
- 開機檔案夾
- [Microsoft Office]
- <C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\Microsoft Office.lnk --> C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [Microsoft Corporation]><N>
- ==================================
- 服務
- [Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
- <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
- [OfficeScanNT RealTime Scan / ntrtscan][Running/Auto Start]
- <"C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe"><Trend Micro Inc.>
- [OfficeScan NT Listener / tmlisten][Running/Auto Start]
- <"C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe"><Trend Micro Inc.>
- [OfficeScanNT 防火牆 / TmPfw][Stopped/Manual Start]
- <"C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe"><Trend Micro Inc.>
- [OfficeScan NT Proxy 服務 / TmProxy][Stopped/Manual Start]
- <"C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe"><Trend Micro Inc.>
- [VNC Server / winvnc][Running/Auto Start]
- <"C:\Program Files\RealVNC\WinVNC\winvnc.exe" -service><RealVNC Ltd.>
- ==================================
- 驅動程式
- [aeaudio / aeaudio][Running/Manual Start]
- <system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
- [Broadcom NetXtreme Gigabit Ethernet for hp / b57w2k][Running/Manual Start]
- <System32\DRIVERS\b57w2k.sys><Broadcom Corporation>
- [dmboot / dmboot][Stopped/Disabled]
- <System32\drivers\dmboot.sys><VERITAS Software Corp.>
- [邏輯磁碟管理員驅動程式 / dmio][Running/Boot Start]
- <\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
- [dmload / dmload][Running/Boot Start]
- <\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
- [ialm / ialm][Running/Manual Start]
- <System32\DRIVERS\ialmnt5.sys><Intel Corporation>
- [直接平行連接埠連結驅動程式 / Ptilink][Running/Manual Start]
- <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
- [Secdrv / Secdrv][Stopped/Manual Start]
- <\??\C:\WINNT\system32\drivers\SECDRV.SYS><N/A>
- [smwdm / smwdm][Running/Manual Start]
- <system32\drivers\smwdm.sys><Analog Devices, Inc.>
- [Trend Micro Common Firewall Service / tmcfw][Running/Manual Start]
- <system32\DRIVERS\TM_CFW.sys><Trend Micro Inc.>
- [tmcomm / tmcomm][Running/Auto Start]
- <\??\C:\WINNT\system32\drivers\tmcomm.sys><Trend Micro Inc.>
- [Trend Micro Filter / TmFilter][Running/Auto Start]
- <\??\C:\Program Files\Trend Micro\OfficeScan Client\TmFilter.sys><Trend Micro Inc.>
- [Trend Micro TDI Driver / tmtdi][Running/System Start]
- <system32\DRIVERS\tmtdi.sys><Trend Micro Inc.>
- [Trend Micro VSAPI NT / VSApiNt][Running/Auto Start]
- <\??\C:\Program Files\Trend Micro\OfficeScan Client\VSApiNt.sys><Trend Micro Inc.>
- [Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/Manual Start]
- <system32\drivers\ialmsbw.sys><Intel Corporation>
- [Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start]
- <system32\drivers\ialmkchw.sys><Intel Corporation>
- ==================================
- 流覽器載入項
- [AcroIEHlprObj Class]
- {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx, (Signed) >
- [@shdoclc.dll,-866]
- {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, >
- [收音機(&R)]
- {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\System32\msdxm.ocx, (Signed) Microsoft Corporation>
- [Java Plug-in 1.3.1_02]
- {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\npjava131_02.dll, JavaSoft / Sun Microsystems, Inc.>
- [Java Plug-in 1.3.1_02]
- {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} <C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\npjava131_02.dll, JavaSoft / Sun Microsystems, Inc.>
- [Shockwave Flash Object]
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash9.ocx, (Signed) Adobe Systems, Inc.>
- [匯出至 Microsoft Excel(&X)]
- <res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000, N/A>
- ==================================
- 正在運行的進程
- [PID: 160][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.00.2195.6601]
- [PID: 184][\??\C:\WINNT\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.00.2195.6601]
- [PID: 204][\??\C:\WINNT\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.00.2195.6898]
- [C:\WINNT\system32\NavLogon.dll] [N/A, ]
- [PID: 232][C:\WINNT\system32\services.exe] [(Verified) Microsoft Corporation, 5.00.2195.6700]
- [C:\WINNT\system32\dmserver.dll] [VERITAS Software Corp., 2195.6605.297.3]
- [PID: 244][C:\WINNT\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.00.2195.6902]
- [PID: 424][C:\WINNT\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.00.2134.1]
- [PID: 452][C:\WINNT\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.00.2195.6659]
- [PID: 516][C:\WINNT\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.00.2134.1]
- [PID: 632][C:\WINNT\system32\regsvc.exe] [(Verified) Microsoft Corporation, 5.00.2195.6701]
- [PID: 648][C:\WINNT\system32\MSTask.exe] [(Verified) Microsoft Corporation, 4.71.2195.6704]
- [PID: 916][C:\WINNT\System32\WBEM\WinMgmt.exe] [(Verified) Microsoft Corporation, 1.50.1085.0100]
- [PID: 928][C:\Program Files\RealVNC\WinVNC\winvnc.exe] [RealVNC Ltd., 3, 3, 7, 0]
- [C:\Program Files\RealVNC\WinVNC\VNCHooks.dll] [RealVNC Ltd., 3, 3, 7, 0]
- [C:\Program Files\RealVNC\WinVNC\othread2.dll] [N/A, ]
- [PID: 956][C:\WINNT\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.00.2134.1]
- [PID: 2244][C:\WINNT\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.00.2134.1]
- [PID: 1404][C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe] [Trend Micro Inc., 10.5.0.1046]
- [C:\Program Files\Trend Micro\OfficeScan Client\PSAPI.DLL] [Microsoft Corporation, 4.00]
- [C:\Program Files\Trend Micro\OfficeScan Client\VSAPI32.dll] [Trend Micro Inc., 8.700-1004]
- [C:\Program Files\Trend Micro\OfficeScan Client\FlowControl.dll] [Trend Micro Inc., 8.0.0.3113]
- [C:\Program Files\Trend Micro\OfficeScan Client\OfcDog.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInAPI.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\libCNTProdRes.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\TimeString.dll] [Trend Micro Inc., 10.5.0.1046]
- [C:\Program Files\Trend Micro\OfficeScan Client\TMBMCLI.dll] [Trend Micro Inc., 2.2.0.1018]
- [C:\Program Files\Trend Micro\OfficeScan Client\TmEngDrv.dll] [Trend Micro Inc., 2.2.0.1018]
- [C:\Program Files\Trend Micro\OfficeScan Client\NTSvcRes.dll] [Trend Micro Inc., 8.0.0.3113]
- [C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInMain.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInTray.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\ssapi32.dll] [Trend Micro Inc., 6.2.0.3009]
- [PID: 2952][C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe] [Trend Micro Inc., 10.5.0.1046]
- [C:\Program Files\Trend Micro\OfficeScan Client\VSAPI32.dll] [Trend Micro Inc., 8.700-1004]
- [C:\Program Files\Trend Micro\OfficeScan Client\FlowControl.dll] [Trend Micro Inc., 8.0.0.3113]
- [C:\Program Files\Trend Micro\OfficeScan Client\libTmCAV.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\Pwd.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwCommon.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\ZLib.dll] [Trend Micro Inc., 1.31.0.1708]
- [C:\Program Files\Trend Micro\OfficeScan Client\OfcDog.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\TmListen.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\TmListenShare.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInAPI.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\libNetCtrl.dll] [Trend Micro Inc., 10.5.0.1046]
- [C:\Program Files\Trend Micro\OfficeScan Client\TMSOCK.dll] [Trend Micro Inc., 10.5.0.1046]
- [C:\Program Files\Trend Micro\OfficeScan Client\PccWFWMo.dll] [Trend Micro Inc., 1.0.0.0]
- [C:\Program Files\Trend Micro\OfficeScan Client\loadhttp.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\TmPac.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\WINNT\System32\msxml3.dll] [Microsoft Corporation, 8.30.9926.0]
- [C:\Program Files\Trend Micro\OfficeScan Client\NTSvcRes.dll] [Trend Micro Inc., 8.0.0.3113]
- [C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInMain.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInTray.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\OfcTmProxy.dll] [Trend Micro Inc., 10.0.0.1192]
- [PID: 800][C:\WINNT\TEMP\SO9A21.EXE] [Trend Micro Inc., 10.5.0.1046]
- [C:\Program Files\Trend Micro\OfficeScan Client\NTSvcRes.dll] [Trend Micro Inc., 8.0.0.3113]
- [PID: 1064][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 3148][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1876][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1928][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 996][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 3272][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1992][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1968][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 3168][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1856][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1292][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 3200][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1512][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1964][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1888][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2008][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1144][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2076][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2084][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1860][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2016][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1572][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 612][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1364][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2544][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 3192][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 492][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1796][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1440][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 3092][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2032][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1536][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1844][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2048][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2820][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1948][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1988][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 680][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1940][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2088][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2184][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1832][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2188][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2524][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 3260][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2160][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 908][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2284][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2236][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 332][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2304][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1348][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 3032][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1864][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2248][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1852][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 3144][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1908][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1768][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2280][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2196][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1904][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2300][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2380][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2664][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2176][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2388][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2168][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2332][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2484][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2480][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2052][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2400][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2500][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2496][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1820][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2456][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2448][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2272][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1816][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1096][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2004][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2224][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2636][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2468][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2640][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2616][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2364][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2676][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2404][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2604][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2592][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2424][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2460][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2208][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2396][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2216][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2532][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2060][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2276][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2720][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 132][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1728][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2292][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2512][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2012][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2800][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2792][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2788][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2752][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2732][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2416][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2760][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2652][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1524][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2744][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2296][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2576][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2696][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2920][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2748][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2408][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2888][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1380][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2864][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2772][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2536][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2848][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2508][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2824][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2900][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2588][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1060][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2796][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 3084][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2912][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1900][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2392][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2688][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2884][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 3028][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2808][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2764][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 2596][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
- [PID: 1880][C:\WINNT\System32\hkcmd.exe] [Intel Corporation, 3,0,0,2104]
- [C:\WINNT\System32\hccutils.DLL] [Intel Corporation, 3,0,0,2104]
- [C:\WINNT\System32\igfxdev.dll] [Intel Corporation, 3,0,0,2104]
- [C:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- [C:\WINNT\System32\igfxsrvc.dll] [Intel Corporation, 3,0,0,2104]
- [C:\WINNT\System32\igfxhk.dll] [Intel Corporation, 3,0,0,2104]
- [C:\WINNT\System32\igfxres.dll] [Intel Corporation, 3,0,0,2104]
- [PID: 1712][C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe] [Trend Micro Inc., 8.0.0.3113]
- [C:\Program Files\Trend Micro\OfficeScan Client\VSAPI32.dll] [Trend Micro Inc., 8.700-1004]
- [C:\Program Files\Trend Micro\OfficeScan Client\TmPac.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\TimeString.dll] [Trend Micro Inc., 10.5.0.1046]
- [C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInAPI.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\loadhttp.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\Pwd.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\FlowControl.dll] [Trend Micro Inc., 8.0.0.3113]
- [C:\Program Files\Trend Micro\OfficeScan Client\ntmonres.dll] [Trend Micro Inc., 8.0.0.3113]
- [C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInMain.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInTray.dll] [Trend Micro Inc., 10.0.0.1192]
- [C:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- [PID: 1736][C:\WINNT\system32\ctfmon.exe] [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
- [C:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- [C:\WINNT\system32\MSUTB.dll] [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
- [C:\WINNT\mui\fallback\0404\msutb.dll.mui] [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
- [C:\WINNT\mui\fallback\0404\msctf.dll.mui] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- [PID: 1264][C:\WINNT\system32\conime.exe] [(Verified) Microsoft Corporation, 5.00.2195.6655]
- [C:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- [PID: 1548][C:\WINNT\explorer.exe] [(Verified) Microsoft Corporation, 5.00.3700.6690]
- [C:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- [C:\WINNT\system32\msimtf.dll] [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
- [C:\WINNT\mui\fallback\0404\msctf.dll.mui] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- [C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] [, 1, 0, 0, 1]
- [C:\WINNT\system32\INPUT.CPL] [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
- [C:\WINNT\mui\fallback\0404\input.cpl.mui] [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
- [C:\WINNT\system32\igfxcpl.cpl] [Intel Corporation, 3,0,0,2104]
- [C:\WINNT\system32\hccutils.DLL] [Intel Corporation, 3,0,0,2104]
- [C:\WINNT\system32\igfxres.dll] [Intel Corporation, 3,0,0,2104]
- [C:\WINNT\system32\igfxress.dll] [Intel Corporation, 3,0,0,2104]
- [C:\WINNT\System32\igfxpph.dll] [Intel Corporation, 3,0,0,2104]
- [PID: 2384][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2800.1106]
- [C:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- [C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] [, 1, 0, 0, 1]
- [C:\WINNT\mui\fallback\0404\msctf.dll.mui] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\npjava131_02.dll] [JavaSoft / Sun Microsystems, Inc., 1, 3, 1, 2]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\beans.ocx] [JavaSoft / Sun Microsystems, 1, 3, 1, 2]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\jpishare.dll] [, 1, 3, 0, 0]
- [C:\PROGRA~1\JavaSoft\JRE\132DB1~1.1_0\bin\hotspot\jvm.dll] [N/A, ]
- [C:\PROGRA~1\JavaSoft\JRE\132DB1~1.1_0\bin\hpi.dll] [N/A, ]
- [C:\PROGRA~1\JavaSoft\JRE\132DB1~1.1_0\bin\verify.dll] [N/A, ]
- [C:\PROGRA~1\JavaSoft\JRE\132DB1~1.1_0\bin\java.dll] [N/A, ]
- [C:\PROGRA~1\JavaSoft\JRE\132DB1~1.1_0\bin\zip.dll] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\awt.dll] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\fontmanager.dll] [N/A, ]
- [C:\WINNT\system32\ialmgicd.dll] [Intel Corporation, 6.13.10.3510]
- [C:\WINNT\system32\ialmgdev.dll] [Intel Corporation, 6.13.10.3510]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\net.dll] [N/A, ]
- [PID: 1592][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2800.1106]
- [C:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- [C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] [, 1, 0, 0, 1]
- [C:\WINNT\mui\fallback\0404\msctf.dll.mui] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- [C:\WINNT\system32\msimtf.dll] [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\npjava131_02.dll] [JavaSoft / Sun Microsystems, Inc., 1, 3, 1, 2]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\beans.ocx] [JavaSoft / Sun Microsystems, 1, 3, 1, 2]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\jpishare.dll] [, 1, 3, 0, 0]
- [C:\PROGRA~1\JavaSoft\JRE\132DB1~1.1_0\bin\hotspot\jvm.dll] [N/A, ]
- [C:\PROGRA~1\JavaSoft\JRE\132DB1~1.1_0\bin\hpi.dll] [N/A, ]
- [C:\PROGRA~1\JavaSoft\JRE\132DB1~1.1_0\bin\verify.dll] [N/A, ]
- [C:\PROGRA~1\JavaSoft\JRE\132DB1~1.1_0\bin\java.dll] [N/A, ]
- [C:\PROGRA~1\JavaSoft\JRE\132DB1~1.1_0\bin\zip.dll] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\awt.dll] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\fontmanager.dll] [N/A, ]
- [C:\WINNT\system32\ialmgicd.dll] [Intel Corporation, 6.13.10.3510]
- [C:\WINNT\system32\ialmgdev.dll] [Intel Corporation, 6.13.10.3510]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\net.dll] [N/A, ]
- [PID: 1260][C:\WINNT\system32\javaw.exe] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\hotspot\jvm.dll] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\hpi.dll] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\verify.dll] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\java.dll] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\zip.dll] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\awt.dll] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\fontmanager.dll] [N/A, ]
- [C:\WINNT\system32\ialmgicd.dll] [Intel Corporation, 6.13.10.3510]
- [C:\WINNT\system32\ialmgdev.dll] [Intel Corporation, 6.13.10.3510]
- [C:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- [C:\WINNT\mui\fallback\0404\msctf.dll.mui] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- [PID: 1596][C:\WINNT\system32\javaw.exe] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\hotspot\jvm.dll] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\hpi.dll] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\verify.dll] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\java.dll] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\zip.dll] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\awt.dll] [N/A, ]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\fontmanager.dll] [N/A, ]
- [C:\WINNT\system32\ialmgicd.dll] [Intel Corporation, 6.13.10.3510]
- [C:\WINNT\system32\ialmgdev.dll] [Intel Corporation, 6.13.10.3510]
- [C:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- [C:\WINNT\mui\fallback\0404\msctf.dll.mui] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- [C:\Program Files\JavaSoft\JRE\1.3.1_02\bin\net.dll] [N/A, ]
- [PID: 2620][C:\WINNT\Cursors\Licence\SREng 報表製作 + 上傳 - 病毒防駭\SREngPS123.EXE] [Smallfrogs Studio, 2.7.1.1261]
- [PID: 3016][C:\WINNT\Cursors\Licence\SREng 報表製作 + 上傳 - 病毒防駭\SRE1818df3f.EXE] [Smallfrogs Studio, 2.7.1.1261]
- [C:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- [C:\WINNT\mui\fallback\0404\msctf.dll.mui] [Microsoft Corporation, 1.00.2409.8 built by: Lab06_N]
- ==================================
- 文件關聯
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .EXE OK. ["%1" %*]
- .COM OK. ["%1" %*]
- .PIF OK. ["%1" %*]
- .REG OK. [regedit.exe "%1"]
- .BAT OK. ["%1" %*]
- .SCR OK. ["%1" /S]
- .CHM OK. ["C:\WINNT\hh.exe" %1]
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
- .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
- .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- ==================================
- Winsock 提供者
- N/A
- ==================================
- Autorun.inf
- N/A
- ==================================
- HOSTS 文件
- 127.0.0.1 localhost
- 172.28.28.77 ntserver07
- ==================================
- 進程特權掃描
- 特殊特權被允許: SeLoadDriverPrivilege [PID = 928, C:\PROGRAM FILES\REALVNC\WINVNC\WINVNC.EXE]
- 特殊特權被允許: SeLoadDriverPrivilege [PID = 1736, C:\WINNT\SYSTEM32\CTFMON.EXE]
- 特殊特權被允許: SeLoadDriverPrivilege [PID = 1260, C:\WINNT\SYSTEM32\JAVAW.EXE]
- 特殊特權被允許: SeLoadDriverPrivilege [PID = 1596, C:\WINNT\SYSTEM32\JAVAW.EXE]
- 特殊特權被允許: SeLoadDriverPrivilege [PID = 2620, C:\WINNT\CURSORS\LICENCE\SRENG 報表製作 + 上傳 - 病毒防駭\SRENGPS123.EXE]
- ==================================
- 計畫任務
- [已啟用] At102.job
- rundll32.exe
- [已啟用] At101.job
- rundll32.exe
- [已啟用] At100.job
- rundll32.exe
- [已啟用] At10.job
- rundll32.exe
- [已啟用] At1.job
- rundll32.exe
- [已啟用] At107.job
- rundll32.exe
- [已啟用] At106.job
- rundll32.exe
- [已啟用] At105.job
- rundll32.exe
- [已啟用] At104.job
- rundll32.exe
- [已啟用] At103.job
- rundll32.exe
- [已啟用] At111.job
- rundll32.exe
- [已啟用] At110.job
- rundll32.exe
- [已啟用] At11.job
- rundll32.exe
- [已啟用] At109.job
- rundll32.exe
- [已啟用] At108.job
- rundll32.exe
- [已啟用] At116.job
- rundll32.exe
- [已啟用] At115.job
- rundll32.exe
- [已啟用] At114.job
- rundll32.exe
- [已啟用] At113.job
- rundll32.exe
- [已啟用] At112.job
- rundll32.exe
- [已啟用] At120.job
- rundll32.exe
- [已啟用] At12.job
- rundll32.exe
- [已啟用] At119.job
- rundll32.exe
- [已啟用] At118.job
- rundll32.exe
- [已啟用] At117.job
- rundll32.exe
- [已啟用] At125.job
- rundll32.exe
- [已啟用] At124.job
- rundll32.exe
- [已啟用] At123.job
- rundll32.exe
- [已啟用] At122.job
- rundll32.exe
- [已啟用] At121.job
- rundll32.exe
- [已啟用] At13.job
- rundll32.exe
- [已啟用] At129.job
- rundll32.exe
- [已啟用] At128.job
- rundll32.exe
- [已啟用] At127.job
- rundll32.exe
- [已啟用] At126.job
- rundll32.exe
- [已啟用] At134.job
- rundll32.exe
- [已啟用] At133.job
- rundll32.exe
- [已啟用] At132.job
- rundll32.exe
- [已啟用] At131.job
- rundll32.exe
- [已啟用] At130.job
- rundll32.exe
- [已啟用] At139.job
- rundll32.exe
- [已啟用] At138.job
- rundll32.exe
- [已啟用] At137.job
- rundll32.exe
- [已啟用] At136.job
- rundll32.exe
- [已啟用] At135.job
- rundll32.exe
- [已啟用] At143.job
- rundll32.exe
- [已啟用] At142.job
- rundll32.exe
- [已啟用] At141.job
- rundll32.exe
- [已啟用] At140.job
- rundll32.exe
- [已啟用] At14.job
- rundll32.exe
- [已啟用] At148.job
- rundll32.exe
- [已啟用] At147.job
- rundll32.exe
- [已啟用] At146.job
- rundll32.exe
- [已啟用] At145.job
- rundll32.exe
- [已啟用] At144.job
- rundll32.exe
- [已啟用] At152.job
- rundll32.exe
- [已啟用] At151.job
- rundll32.exe
- [已啟用] At150.job
- rundll32.exe
- [已啟用] At15.job
- rundll32.exe
- [已啟用] At149.job
- rundll32.exe
- [已啟用] At157.job
- rundll32.exe
- [已啟用] At156.job
- rundll32.exe
- [已啟用] At155.job
- rundll32.exe
- [已啟用] At154.job
- rundll32.exe
- [已啟用] At153.job
- rundll32.exe
- [已啟用] At161.job
- rundll32.exe
- [已啟用] At160.job
- rundll32.exe
- [已啟用] At16.job
- rundll32.exe
- [已啟用] At159.job
- rundll32.exe
- [已啟用] At158.job
- rundll32.exe
- [已啟用] At166.job
- rundll32.exe
- [已啟用] At165.job
- rundll32.exe
- [已啟用] At164.job
- rundll32.exe
- [已啟用] At163.job
- rundll32.exe
- [已啟用] At162.job
- rundll32.exe
- [已啟用] At170.job
- rundll32.exe
- [已啟用] At17.job
- rundll32.exe
- [已啟用] At169.job
- rundll32.exe
- [已啟用] At168.job
- rundll32.exe
- [已啟用] At167.job
- rundll32.exe
- [已啟用] At175.job
- rundll32.exe
- [已啟用] At174.job
- rundll32.exe
- [已啟用] At173.job
- rundll32.exe
- [已啟用] At172.job
- rundll32.exe
- [已啟用] At171.job
- rundll32.exe
- [已啟用] At18.job
- rundll32.exe
- [已啟用] At179.job
- rundll32.exe
- [已啟用] At178.job
- rundll32.exe
- [已啟用] At177.job
- rundll32.exe
- [已啟用] At176.job
- rundll32.exe
- [已啟用] At20.job
- rundll32.exe
- [已啟用] At2.job
- rundll32.exe
- [已啟用] At19.job
- rundll32.exe
- [已啟用] At181.job
- rundll32.exe
- [已啟用] At180.job
- rundll32.exe
- [已啟用] At25.job
- rundll32.exe
- [已啟用] At24.job
- rundll32.exe
- [已啟用] At23.job
- rundll32.exe
- [已啟用] At22.job
- rundll32.exe
- [已啟用] At21.job
- rundll32.exe
- [已啟用] At3.job
- rundll32.exe
- [已啟用] At29.job
- rundll32.exe
- [已啟用] At28.job
- rundll32.exe
- [已啟用] At27.job
- rundll32.exe
- [已啟用] At26.job
- rundll32.exe
- [已啟用] At34.job
- rundll32.exe
- [已啟用] At33.job
- rundll32.exe
- [已啟用] At32.job
- rundll32.exe
- [已啟用] At31.job
- rundll32.exe
- [已啟用] At30.job
- rundll32.exe
- [已啟用] At39.job
- rundll32.exe
- [已啟用] At38.job
- rundll32.exe
- [已啟用] At37.job
- rundll32.exe
- [已啟用] At36.job
- rundll32.exe
- [已啟用] At35.job
- rundll32.exe
- [已啟用] At43.job
- rundll32.exe
- [已啟用] At42.job
- rundll32.exe
- [已啟用] At41.job
- rundll32.exe
- [已啟用] At40.job
- rundll32.exe
- [已啟用] At4.job
- rundll32.exe
- [已啟用] At48.job
- rundll32.exe
- [已啟用] At47.job
- rundll32.exe
- [已啟用] At46.job
- rundll32.exe
- [已啟用] At45.job
- rundll32.exe
- [已啟用] At44.job
- rundll32.exe
- [已啟用] At52.job
- rundll32.exe
- [已啟用] At51.job
- rundll32.exe
- [已啟用] At50.job
- rundll32.exe
- [已啟用] At5.job
- rundll32.exe
- [已啟用] At49.job
- rundll32.exe
- [已啟用] At57.job
- rundll32.exe
- [已啟用] At56.job
- rundll32.exe
- [已啟用] At55.job
- rundll32.exe
- [已啟用] At54.job
- rundll32.exe
- [已啟用] At53.job
- rundll32.exe
- [已啟用] At61.job
- rundll32.exe
- [已啟用] At60.job
- rundll32.exe
- [已啟用] At6.job
- rundll32.exe
- [已啟用] At59.job
- rundll32.exe
- [已啟用] At58.job
- rundll32.exe
- [已啟用] At66.job
- rundll32.exe
- [已啟用] At65.job
- rundll32.exe
- [已啟用] At64.job
- rundll32.exe
- [已啟用] At63.job
- rundll32.exe
- [已啟用] At62.job
- rundll32.exe
- [已啟用] At70.job
- rundll32.exe
- [已啟用] At7.job
- rundll32.exe
- [已啟用] At69.job
- rundll32.exe
- [已啟用] At68.job
- rundll32.exe
- [已啟用] At67.job
- rundll32.exe
- [已啟用] At75.job
- rundll32.exe
- [已啟用] At74.job
- rundll32.exe
- [已啟用] At73.job
- rundll32.exe
- [已啟用] At72.job
- rundll32.exe
- [已啟用] At71.job
- rundll32.exe
- [已啟用] At8.job
- rundll32.exe
- [已啟用] At79.job
- rundll32.exe
- [已啟用] At78.job
- rundll32.exe
- [已啟用] At77.job
- rundll32.exe
- [已啟用] At76.job
- rundll32.exe
- [已啟用] At84.job
- rundll32.exe
- [已啟用] At83.job
- rundll32.exe
- [已啟用] At82.job
- rundll32.exe
- [已啟用] At81.job
- rundll32.exe
- [已啟用] At80.job
- rundll32.exe
- [已啟用] At89.job
- rundll32.exe
- [已啟用] At88.job
- rundll32.exe
- [已啟用] At87.job
- rundll32.exe
- [已啟用] At86.job
- rundll32.exe
- [已啟用] At85.job
- rundll32.exe
- [已啟用] At93.job
- rundll32.exe
- [已啟用] At92.job
- rundll32.exe
- [已啟用] At91.job
- rundll32.exe
- [已啟用] At90.job
- rundll32.exe
- [已啟用] At9.job
- rundll32.exe
- [已啟用] At98.job
- rundll32.exe
- [已啟用] At97.job
- rundll32.exe
- [已啟用] At96.job
- rundll32.exe
- [已啟用] At95.job
- rundll32.exe
- [已啟用] At94.job
- rundll32.exe
- [已啟用] At99.job
- rundll32.exe
- ==================================
- API HOOK
- N/A
- ==================================
- 隱藏進程
- N/A
- ==================================
複製代碼 ... |
|