爱 拼 才 会 WIN

ad-aware se professional log

   计算机2005-6-15 8:54
Ad-Aware SE Build 1.06r1
Logfile Created on:2005年6月10日 11:40:35
Using definitions file:SE1R49 31.05.2005
换换换换换换换换换换换换换换换换换换换换换换换换换?

References detected during the scan:
换换换换换换换换换换换换换换换换换换换?
Alexa(TAC index:5):8 total references
Tracking Cookie(TAC index:3):19 total references
换换换换换换换换换换换换换换换换换换换?

Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Ignore spanned files when scanning cab archives
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Block pop-ups aggressively
Set : Automatically select problematic objects in results lists
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Show splash screen
Set : Backup current definitions file before updating
Set : Play sound at scan completion if scan locates critical objects


2005-6-10 11:40:35 - Scan started. (Full System Scan)

Listing running processes
换换换换换换换换换换换换换换换换换换换

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 160
ThreadCreationTime : 2005-6-9 23:57:33
BasePriority : Normal


#:2 [csrss.exe]
FilePath : \??\C:\WINNT\system32\
ProcessID : 184
ThreadCreationTime : 2005-6-9 23:57:58
BasePriority : Normal


#:3 [winlogon.exe]
FilePath : \??\C:\WINNT\system32\
ProcessID : 204
ThreadCreationTime : 2005-6-9 23:58:01
BasePriority : High


#:4 [services.exe]
FilePath : C:\WINNT\system32\
ProcessID : 232
ThreadCreationTime : 2005-6-9 23:58:05
BasePriority : Normal
FileVersion : 5.00.2195.6700
ProductVersion : 5.00.2195.6700
ProductName : Microsoft(R) Windows (R) 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename : services.exe

#:5 [lsass.exe]
FilePath : C:\WINNT\system32\
ProcessID : 244
ThreadCreationTime : 2005-6-9 23:58:05
BasePriority : Normal
FileVersion : 5.00.2195.6902
ProductVersion : 5.00.2195.6902
ProductName : Microsoft(R) Windows (R) 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Executable and Server DLL (Export Version)
InternalName : lsasrv.dll and lsass.exe
LegalCopyright : Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename : lsasrv.dll and lsass.exe

#:6 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 440
ThreadCreationTime : 2005-6-9 23:58:14
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft(R) Windows (R) 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe

#:7 [spoolsv.exe]
FilePath : C:\WINNT\system32\
ProcessID : 484
ThreadCreationTime : 2005-6-9 23:58:18
BasePriority : Normal
FileVersion : 5.00.2195.6659
ProductVersion : 5.00.2195.6659
ProductName : Microsoft(R) Windows (R) 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolss.exe
LegalCopyright : Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename : spoolss.exe

#:8 [msdtc.exe]
FilePath : C:\WINNT\system32\
ProcessID : 516
ThreadCreationTime : 2005-6-9 23:58:20
BasePriority : Normal
FileVersion : 1999.9.3421.3
ProductVersion : 03.00.00.3421
ProductName : Microsoft Distributed Transaction Coordinator
CompanyName : Microsoft Corporation
FileDescription : MS DTC console program
InternalName : MSDTC.EXE
LegalCopyright : Copyright (C) Microsoft Corp. 1995-1999
LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation. Windows(TM) is a trademark of Microsoft Corporation

#:9 [tcpsvcs.exe]
FilePath : C:\WINNT\system32\
ProcessID : 632
ThreadCreationTime : 2005-6-9 23:58:31
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft(R) Windows (R) 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : TCP/IP Services Application
InternalName : TCPSVCS.EXE
LegalCopyright : Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename : TCPSVCS.EXE

#:10 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 648
ThreadCreationTime : 2005-6-9 23:58:31
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft(R) Windows (R) 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe

#:11 [llssrv.exe]
FilePath : C:\WINNT\System32\
ProcessID : 680
ThreadCreationTime : 2005-6-9 23:58:33
BasePriority : Normal
FileVersion : 5.00.2195.7021
ProductVersion : 5.00.2195.7021
ProductName : Microsoft(R) Windows (R) 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Microsoft? License Server
InternalName : llssrv.exe
LegalCopyright : Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename : llssrv.exe

#:12 [mdm.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\
ProcessID : 728
ThreadCreationTime : 2005-6-9 23:58:34
BasePriority : Normal
FileVersion : 7.00.9466
ProductVersion : 7.00.9466
ProductName : Microsoft? Visual Studio .NET
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
LegalCopyright : ? Microsoft Corporation. All rights reserved.
OriginalFilename : mdm.exe

#:13 [regsvc.exe]
FilePath : C:\WINNT\system32\
ProcessID : 800
ThreadCreationTime : 2005-6-9 23:58:36
BasePriority : Normal
FileVersion : 5.00.2195.6701
ProductVersion : 5.00.2195.6701
ProductName : Microsoft(R) Windows (R) 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Remote Registry Service
InternalName : regsvc
LegalCopyright : Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename : REGSVC.EXE

#:14 [mstask.exe]
FilePath : C:\WINNT\system32\
ProcessID : 828
ThreadCreationTime : 2005-6-9 23:58:37
BasePriority : Normal
FileVersion : 4.71.2195.6920
ProductVersion : 4.71.2195.6920
ProductName : Microsoft(R) Windows(R) Task Scheduler
CompanyName : Microsoft Corporation
FileDescription : Task Scheduler Engine
InternalName : TaskScheduler
LegalCopyright : Copyright (C) Microsoft Corp. 1997
OriginalFilename : mstask.exe

#:15 [snmp.exe]
FilePath : C:\WINNT\System32\
ProcessID : 868
ThreadCreationTime : 2005-6-9 23:58:39
BasePriority : Normal
FileVersion : 5.00.2195.6605
ProductVersion : 5.00.2195.6605
ProductName : Microsoft(R) Windows (R) 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : SNMP Service
InternalName : snmp.exe
LegalCopyright : Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename : snmp.exe

#:16 [winmgmt.exe]
FilePath : C:\WINNT\System32\WBEM\
ProcessID : 904
ThreadCreationTime : 2005-6-9 23:58:40
BasePriority : Normal
FileVersion : 1.50.1085.0100
ProductVersion : 1.50.1085.0100
ProductName : Windows Management Instrumentation
CompanyName : Microsoft Corporation
FileDescription : Windows Management Instrumentation
InternalName : WINMGMT
LegalCopyright : Copyright (C) Microsoft Corp. 1995-1999

#:17 [wins.exe]
FilePath : C:\WINNT\System32\
ProcessID : 956
ThreadCreationTime : 2005-6-9 23:58:42
BasePriority : Normal


#:18 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 996
ThreadCreationTime : 2005-6-9 23:58:43
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft(R) Windows (R) 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe

#:19 [dfssvc.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1028
ThreadCreationTime : 2005-6-9 23:58:44
BasePriority : Normal
FileVersion : 5.00.2195.6664
ProductVersion : 5.00.2195.6664
ProductName : Microsoft(R) Windows (R) 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows NT Distributed File System Service
InternalName : dfssvc.exe
LegalCopyright : Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename : dfssvc.exe

#:20 [dns.exe]
FilePath : C:\WINNT\System32\
ProcessID : 1048
ThreadCreationTime : 2005-6-9 23:58:45
BasePriority : Normal
FileVersion : 5.00.2195.6715
ProductVersion : 5.00.2195.6715
ProductName : Microsoft(R) Windows (R) 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Domain Name System (DNS) Server
InternalName : dns.exe
LegalCopyright : Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename : dns.exe

#:21 [inetinfo.exe]
FilePath : C:\WINNT\system32\inetsrv\
ProcessID : 1068
ThreadCreationTime : 2005-6-9 23:58:46
BasePriority : Normal
FileVersion : 5.00.0984
ProductVersion : 5.00.0984
ProductName : Internet 信息服务
CompanyName : Microsoft Corporation
FileDescription : Internet 信息服务
InternalName : INETINFO.EXE
LegalCopyright : 版权所有 (C) Microsoft 公司。 1981-1999
OriginalFilename : INETINFO.EXE

#:22 [svchost.exe]
FilePath : C:\WINNT\System32\
ProcessID : 1652
ThreadCreationTime : 2005-6-9 23:59:46
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft(R) Windows (R) 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe

#:23 [explorer.exe]
FilePath : C:\WINNT\
ProcessID : 1680
ThreadCreationTime : 2005-6-10 0:12:35
BasePriority : Normal
FileVersion : 5.00.3700.6690
ProductVersion : 5.00.3700.6690
ProductName : Microsoft(R) Windows (R) 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename : EXPLORER.EXE

#:24 [ctfmon.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1136
ThreadCreationTime : 2005-6-10 0:12:42
BasePriority : Normal
FileVersion : 1.00.2409.34 built by: Lab06_N
ProductVersion : 1.00.2409.34
ProductName : Microsoft(R) Windows NT(R) Operating System
CompanyName : Microsoft Corporation
FileDescription : Cicero Loader
InternalName : CICLOAD
LegalCopyright : Copyright (C) Microsoft Corporation. 1981-2001
OriginalFilename : CICLOAD.EXE

#:25 [rtxc.exe]
FilePath : D:\Program Files\Tencent\RTX\
ProcessID : 940
ThreadCreationTime : 2005-6-10 0:12:44
BasePriority : Normal
FileVersion : 3,4,0,32
ProductVersion : 3,4,0,32
ProductName : RTX
CompanyName : Tencent
InternalName : RTXC

#:26 [conime.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1512
ThreadCreationTime : 2005-6-10 0:13:06
BasePriority : Normal
FileVersion : 5.00.2195.6655
ProductVersion : 5.00.2195.6655
ProductName : Microsoft(R) Windows (R) 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Console IME
InternalName : Console
LegalCopyright : Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename : CONIME.EXE

#:27 [ccenter.exe]
FilePath : C:\PROGRAM FILES\RISING\RAV\
ProcessID : 1828
ThreadCreationTime : 2005-6-10 1:53:14
BasePriority : Normal
FileVersion : 17, 0, 0, 1
ProductVersion : 17, 0, 0, 1
ProductName : Rising CCenter
CompanyName : rising
FileDescription : CCenter
InternalName : CCenter
LegalCopyright : Copyright Rising 2002
OriginalFilename : CCenter.exe

#:28 [ravmond.exe]
FilePath : C:\PROGRAM FILES\RISING\RAV\
ProcessID : 1740
ThreadCreationTime : 2005-6-10 1:53:21
BasePriority : Normal
FileVersion : 17, 0, 0, 95
ProductVersion : 17, 0, 0, 95
ProductName : rising RavMon
CompanyName : Beijing Rising Technology Co., Ltd.
FileDescription : RavMon
InternalName : Beijing Rising Technology Co., Ltd.
LegalCopyright : Copyright Rising Co. Ltd. 2002
OriginalFilename : RavMond.exe

#:29 [ravtimer.exe]
FilePath : C:\Program Files\rising\Rav\
ProcessID : 1236
ThreadCreationTime : 2005-6-10 1:53:42
BasePriority : Idle
FileVersion : 17, 0, 0, 30
ProductVersion : 17, 0, 0, 30
ProductName : rising
CompanyName : Beijing Rising Technology Co., Ltd.
FileDescription : RavTimer
InternalName : Beijing Rising Technology Co., Ltd.
LegalCopyright : Copyright 1995-2000
OriginalFilename : RavTimer.exe
Comments : 2003-01-20

#:30 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1372
ThreadCreationTime : 2005-6-10 3:39:02
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft(R) Windows (R) 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe

#:31 [ad-aware.exe]
FilePath : C:\PROGRA~1\Lavasoft\AD-AWA~1\
ProcessID : 1504
ThreadCreationTime : 2005-6-10 3:39:39
BasePriority : Normal
FileVersion : 6.2.0.238
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright ? Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

Memory scan result:
换换换换换换换换换换换换换换换换换换换
New critical objects: 0
Objects found so far: 0


Started registry scan
换换换换换换换换换换换换换换换换换换换

Alexa Object Recognized!
Type : Regkey
Data :
TAC Rating : 5
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}

Alexa Object Recognized!
Type : Regvalue
Data :
TAC Rating : 5
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
value : MenuStatusBar

Alexa Object Recognized!
Type : Regvalue
Data :
TAC Rating : 5
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
value : Script

Alexa Object Recognized!
Type : Regvalue
Data :
TAC Rating : 5
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
value : clsid

Alexa Object Recognized!
Type : Regvalue
Data :
TAC Rating : 5
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
value : Icon

Alexa Object Recognized!
Type : Regvalue
Data :
TAC Rating : 5
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
value : HotIcon

Alexa Object Recognized!
Type : Regvalue
Data :
TAC Rating : 5
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
value : ButtonText

Alexa Object Recognized!
Type : Regvalue
Data :
TAC Rating : 5
Category : Data Miner
Comment : "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
Rootkey : HKEY_USERS
Object : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\internet explorer\extensions\cmdmapping
value : {c95fe080-8f5d-11d2-a20b-00aa003c157a}

Registry Scan result:
换换换换换换换换换换换换换换换换换换换
New critical objects: 8
Objects found so far: 8


Started deep registry scan
换换换换换换换换换换换换换换换换换换换

Deep registry scan result:
换换换换换换换换换换换换换换换换换换换
New critical objects: 0
Objects found so far: 8


Started Tracking Cookie scan
换换换换换换换换换换换换换换换换换换换


Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@atdmt[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
value : Cookie:administrator@atdmt.com/
Expires : 2010-6-5 8:00:00
LastSync : Hits:2
UseCount : 0
Hits : 2

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@maxserving[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
value : Cookie:administrator@maxserving.com/
Expires : 2015-6-7 13:12:56
LastSync : Hits:1
UseCount : 0
Hits : 1

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@bluestreak[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
value : Cookie:administrator@bluestreak.com/
Expires : 2015-6-7 13:22:42
LastSync : Hits:3
UseCount : 0
Hits : 3

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@ehg-ciscosystems.hitbox[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:12
value : Cookie:administrator@ehg-ciscosystems.hitbox.com/
Expires : 2006-6-9 8:19:26
LastSync : Hits:12
UseCount : 0
Hits : 12

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@ehg-cisco.hitbox[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:12
value : Cookie:administrator@ehg-cisco.hitbox.com/
Expires : 2006-6-9 8:30:46
LastSync : Hits:12
UseCount : 0
Hits : 12

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@centrport[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
value : Cookie:administrator@centrport.net/
Expires : 2030-1-1 8:00:00
LastSync : Hits:2
UseCount : 0
Hits : 2

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@overture[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:130
value : Cookie:administrator@overture.com/
Expires : 2015-6-7 17:28:38
LastSync : Hits:130
UseCount : 0
Hits : 130

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@cgi-bin[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:6
value : Cookie:administrator@imrworldwide.com/cgi-bin
Expires : 2015-6-5 14:55:34
LastSync : Hits:6
UseCount : 0
Hits : 6

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@sexlist[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:15
value : Cookie:administrator@sexlist.com/
Expires : 2006-6-7 19:59:20
LastSync : Hits:15
UseCount : 0
Hits : 15

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@revenue[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
value : Cookie:administrator@revenue.net/
Expires : 2022-6-10 13:05:42
LastSync : Hits:2
UseCount : 0
Hits : 2

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@doubleclick[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:6
value : Cookie:administrator@doubleclick.net/
Expires : 2008-6-5 13:24:30
LastSync : Hits:6
UseCount : 0
Hits : 6

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@cgi-bin[3].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
value : Cookie:administrator@www.juxianshanzhuang.com/cgi-bin/
Expires : 2005-7-7 12:29:56
LastSync : Hits:2
UseCount : 0
Hits : 2

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@statcounter[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
value : Cookie:administrator@statcounter.com/
Expires : 2010-6-5 16:00:26
LastSync : Hits:1
UseCount : 0
Hits : 1

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@overstock[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:12
value : Cookie:administrator@overstock.com/
Expires : 2006-6-9 17:02:46
LastSync : Hits:12
UseCount : 0
Hits : 12

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@fastclick[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:5
value : Cookie:administrator@fastclick.net/
Expires : 2007-6-6 16:52:50
LastSync : Hits:5
UseCount : 0
Hits : 5

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@mediaplex[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:9
value : Cookie:administrator@mediaplex.com/
Expires : 2009-6-22 8:00:00
LastSync : Hits:9
UseCount : 0
Hits : 9

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@~~local~~[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
value : Cookie:administrator@~~local~~/
Expires : 2006-6-6 12:01:14
LastSync : Hits:4
UseCount : 0
Hits : 4

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@ads.pointroll[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:5
value : Cookie:administrator@ads.pointroll.com/
Expires : 2010-1-1 8:00:00
LastSync : Hits:5
UseCount : 0
Hits : 5

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:29
value : Cookie:administrator@hitbox.com/
Expires : 2006-6-9 8:30:46
LastSync : Hits:29
UseCount : 0
Hits : 29

Tracking cookie scan result:
换换换换换换换换换换换换换换换换换换换
New critical objects: 19
Objects found so far: 27



Deep scanning and examining files (C:)
换换换换换换换换换换换换换换换换换换换

Disk Scan Result for C:\
换换换换换换换换换换换换换换换换换换换
New critical objects: 0
Objects found so far: 27


Deep scanning and examining files (D:)
换换换换换换换换换换换换换换换换换换换
<STOP>

Disk Scan Result for D:\
换换换换换换换换换换换换换换换换换换换
New critical objects: 0
Objects found so far: 27


Deep scanning and examining files (E:)
换换换换换换换换换换换换换换换换换换换

Disk Scan Result for E:\
换换换换换换换换换换换换换换换换换换换
New critical objects: 0
Objects found so far: 27
11:46:56 Scan stopped by user

Summary Of This Scan
换换换换换换换换换换换换换换换换换换换
Total scanning time:00:06:20.998
Objects scanned:63812
Objects identified:27
Objects ignored:0
New critical objects:27




------------------------------------------------------

ad-aware se professional(lsp explorer).TXT

LSP Explorer export.
Created on:2005-6-15 8:25:40
---------------------------------------------

Layered Service Providers
MSAFD Tcpip [TCP/IP]
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1001
Address Family : internetwork: UDP, TCP, etc.
Provider : {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Service Flags 1 : $00020066
XP1_GUARANTEED_DELIVERY
XP1_GUARANTEED_ORDER
XP1_GRACEFUL_CLOSE
XP1_EXPEDITED_DATA
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : $00000008
PFL_MATCHES_PROTOCOL_ZERO
Maximum Message Size : {logcontent}
Security Sheme : 0
Byte Order : Big Endian
Protocol : 6
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000010
Max Socket Address : $00000010
Socket Type : Stream
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
MSAFD Tcpip [UDP/IP]
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1002
Address Family : internetwork: UDP, TCP, etc.
Provider : {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Service Flags 1 : $00020609
XP1_CONNECTIONLESS
XP1_MESSAGE_ORIENTED
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_MULTIPOINT
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : $00000008
PFL_MATCHES_PROTOCOL_ZERO
Maximum Message Size : {logcontent}FFBB
Security Sheme : 0
Byte Order : Big Endian
Protocol : 17
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000010
Max Socket Address : $00000010
Socket Type : Datagram
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
MSAFD Tcpip [RAW/IP]
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1003
Address Family : internetwork: UDP, TCP, etc.
Provider : {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Service Flags 1 : $00020609
XP1_CONNECTIONLESS
XP1_MESSAGE_ORIENTED
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_MULTIPOINT
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : {logcontent}C
PFL_HIDDEN
PFL_MATCHES_PROTOCOL_ZERO
Maximum Message Size : {logcontent}FFBB
Security Sheme : 0
Byte Order : Big Endian
Protocol : 0
Protocol MaxOffset : {logcontent}FF
Min Socket Address : $00000010
Max Socket Address : $00000010
Socket Type : Unknown
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
RSVP UDP Service Provider
Filename : C:\WINNT\system32\rsvpsp.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Rsvp 1.0 Service Provider
File version : 5.00.2195.6611
Internal name : rsvpsp.dll
Original filename : rsvpsp.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6611
Version : 4
Catalog Entry : 1004
Address Family : internetwork: UDP, TCP, etc.
Provider : {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Service Flags 1 : $00022609
XP1_CONNECTIONLESS
XP1_MESSAGE_ORIENTED
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_MULTIPOINT
XP1_QOS_SUPPORTED
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : $00000008
PFL_MATCHES_PROTOCOL_ZERO
Maximum Message Size : {logcontent}FFBB
Security Sheme : 0
Byte Order : Big Endian
Protocol : 17
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000010
Max Socket Address : $00000010
Socket Type : Datagram
Protocol Chain length : 1
Protocol Chain Entry (0) : 1775647788
RSVP TCP Service Provider
Filename : C:\WINNT\system32\rsvpsp.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Rsvp 1.0 Service Provider
File version : 5.00.2195.6611
Internal name : rsvpsp.dll
Original filename : rsvpsp.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6611
Version : 4
Catalog Entry : 1005
Address Family : internetwork: UDP, TCP, etc.
Provider : {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Service Flags 1 : $00022066
XP1_GUARANTEED_DELIVERY
XP1_GUARANTEED_ORDER
XP1_GRACEFUL_CLOSE
XP1_EXPEDITED_DATA
XP1_QOS_SUPPORTED
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : $00000008
PFL_MATCHES_PROTOCOL_ZERO
Maximum Message Size : {logcontent}
Security Sheme : 0
Byte Order : Big Endian
Protocol : 6
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000010
Max Socket Address : $00000010
Socket Type : Stream
Protocol Chain length : 1
Protocol Chain Entry (0) : 6553707
MSAFD NetBIOS [\Device\NetBT_Tcpip_{7BD5FF36-87E0-46F3-8190-D45716B680A4}] SEQPACKET 0
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1006
Address Family : NetBios-style addresses
Provider : {8D5F1830-C273-11CF-95C8-00805F48A192}
Service Flags 1 : $0002000E
XP1_GUARANTEED_DELIVERY
XP1_GUARANTEED_ORDER
XP1_MESSAGE_ORIENTED
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : $00000008
PFL_MATCHES_PROTOCOL_ZERO
Maximum Message Size : {logcontent}FA00
Security Sheme : 0
Byte Order : Big Endian
Protocol : -2147483648
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000014
Max Socket Address : $00000014
Socket Type : Unknown
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
MSAFD NetBIOS [\Device\NetBT_Tcpip_{7BD5FF36-87E0-46F3-8190-D45716B680A4}] DATAGRAM 0
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1007
Address Family : NetBios-style addresses
Provider : {8D5F1830-C273-11CF-95C8-00805F48A192}
Service Flags 1 : $00020209
XP1_CONNECTIONLESS
XP1_MESSAGE_ORIENTED
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_BROADCAST
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : $00000008
PFL_MATCHES_PROTOCOL_ZERO
Maximum Message Size : {logcontent}FA00
Security Sheme : 0
Byte Order : Big Endian
Protocol : -2147483648
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000014
Max Socket Address : $00000014
Socket Type : Datagram
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
MSAFD NetBIOS [\Device\NetBT_Tcpip_{9C9DE15C-6251-4967-AE62-AF47F25CB702}] SEQPACKET 1
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1008
Address Family : NetBios-style addresses
Provider : {8D5F1830-C273-11CF-95C8-00805F48A192}
Service Flags 1 : $0002000E
XP1_GUARANTEED_DELIVERY
XP1_GUARANTEED_ORDER
XP1_MESSAGE_ORIENTED
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : {logcontent}
Maximum Message Size : {logcontent}FA00
Security Sheme : 0
Byte Order : Big Endian
Protocol : -1
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000014
Max Socket Address : $00000014
Socket Type : Unknown
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
MSAFD NetBIOS [\Device\NetBT_Tcpip_{9C9DE15C-6251-4967-AE62-AF47F25CB702}] DATAGRAM 1
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1009
Address Family : NetBios-style addresses
Provider : {8D5F1830-C273-11CF-95C8-00805F48A192}
Service Flags 1 : $00020209
XP1_CONNECTIONLESS
XP1_MESSAGE_ORIENTED
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_BROADCAST
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : {logcontent}
Maximum Message Size : {logcontent}FA00
Security Sheme : 0
Byte Order : Big Endian
Protocol : -1
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000014
Max Socket Address : $00000014
Socket Type : Datagram
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
MSAFD NetBIOS [\Device\NetBT_Tcpip_{B74F13B8-12F6-496E-A935-C26C824B212F}] SEQPACKET 2
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1010
Address Family : NetBios-style addresses
Provider : {8D5F1830-C273-11CF-95C8-00805F48A192}
Service Flags 1 : $0002000E
XP1_GUARANTEED_DELIVERY
XP1_GUARANTEED_ORDER
XP1_MESSAGE_ORIENTED
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : {logcontent}
Maximum Message Size : {logcontent}FA00
Security Sheme : 0
Byte Order : Big Endian
Protocol : -2
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000014
Max Socket Address : $00000014
Socket Type : Unknown
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
MSAFD NetBIOS [\Device\NetBT_Tcpip_{B74F13B8-12F6-496E-A935-C26C824B212F}] DATAGRAM 2
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1011
Address Family : NetBios-style addresses
Provider : {8D5F1830-C273-11CF-95C8-00805F48A192}
Service Flags 1 : $00020209
XP1_CONNECTIONLESS
XP1_MESSAGE_ORIENTED
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_BROADCAST
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : {logcontent}
Maximum Message Size : {logcontent}FA00
Security Sheme : 0
Byte Order : Big Endian
Protocol : -2
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000014
Max Socket Address : $00000014
Socket Type : Datagram
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
Name Space Providers
Description : Tcpip
Filename : C:\WINNT\system32\rnr20.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Windows Socket2 NameSpace DLL
File version : 5.00.2195.6603
Internal name : rnr20.dll
Original filename : rnr20.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6603
NameSpace : NS_DNS
Active : Yes
Protocol Version : 0
Provider : {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Description : NTDS
Filename : C:\WINNT\system32\winrnr.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : LDAP RnR Provider DLL
File version : 5.00.2160.1
Internal name : winrnr
Original filename : winrnr
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2160.1
NameSpace : NS_NTDS
Active : Yes
Protocol Version : 0
Provider : {3B2637EE-E580-11CF-A555-00C04FD8D4AC}




------------------------------------------------------




ArchiveData(auto-quarantine- 2005-06-15 08-41-38.bckp)
Referencefile : SE1R50 13.06.2005
======================================================

MRU LIST
换换换换换换换换换换换换换换换换换换换
obj[0]=MRU FileReference : C:\Documents and Settings\Administrator\Application Data\microsoft\office\recent\b070201.LNK
obj[1]=MRU FileReference : C:\Documents and Settings\Administrator\recent\ad-aware se professional(lsp explorer).TXT.lnk
obj[2]=MRU FileReference : C:\Documents and Settings\Administrator\recent\d.TXT.lnk
obj[3]=MRU FileReference : C:\Documents and Settings\Administrator\recent\Desktop.ini
obj[4]=MRU FileReference : C:\Documents and Settings\Administrator\recent\i.TXT.lnk
obj[5]=MRU FileReference : C:\Documents and Settings\Administrator\recent\l.TXT.lnk
obj[6]=MRU FileReference : C:\Documents and Settings\Administrator\recent\negligible objects.TXT.lnk
obj[7]=MRU FileReference : C:\Documents and Settings\Administrator\recent\scan log.TXT.lnk
obj[8]=MRU FileReference : C:\Documents and Settings\Administrator\Application Data\microsoft\office\recent\培训讲义.LNK
obj[9]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\*
obj[10]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\recentdocs\.TXT
obj[11]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\doc
obj[12]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows media\wmsdk\general computername
obj[13]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\winrar\dialogedithistory\extrpath
obj[14]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\gif
obj[15]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\htm
obj[16]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\jpg
obj[17]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\MSI
obj[18]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\pdf
obj[19]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\ppt
obj[20]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\rar
obj[21]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\tpp
obj[22]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\txt
obj[23]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\vbs
obj[24]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\wdq
obj[25]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\xls
obj[26]=MRU RegReference : S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\zip



---------------------------------------------------------


Ad-Aware SE Scanning Result, 2005-6-15 8:40:48
换换换换换换换换换换换换换换换换换换换?
Type Description Location No. Items
MRU List list of recently opened documents using microsoft office C:\Documents and Settings\Administrator\Application Data\microsoft\office\recent 15
MRU List list of recently opened documents C:\Documents and Settings\Administrator\recent 5
MRU List most recent application to use microsoft directdraw HKEY_LOCAL_MACHINE:software\microsoft\directdraw\mostrecentapplication\ 1
MRU List last download directory used in microsoft internet explorer HKEY_USERS:S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\internet explorer\ 1
MRU List last save directory used in microsoft internet explorer HKEY_USERS:S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\internet explorer\main\ 1
MRU List list of recently entered addresses in microsoft internet explorer HKEY_USERS:S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\internet explorer\typedurls\ 3
MRU List list of recent snap-ins used in the microsoft management console HKEY_USERS:S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\microsoft management console\recent file list\ 4
MRU List list of recently used typefaces in microsoft powerpoint HKEY_USERS:S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\office\11.0\powerpoint\recent typeface list\ 2
MRU List list of recent programs opened HKEY_USERS:S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru\ 10
MRU List list of recently saved files, stored according to file extension HKEY_USERS:S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\ 18
MRU List list of recent documents opened HKEY_USERS:S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows\currentversion\explorer\recentdocs\ 1
MRU List windows media sdk HKEY_USERS:S-1-5-21-1390067357-1682526488-1957994488-500\software\microsoft\windows media\wmsdk\general\{0} 1
MRU List winrar "extract-to" history HKEY_USERS:S-1-5-21-1390067357-1682526488-1957994488-500\software\winrar\dialogedithistory\extrpath\ 3



-------------------------------------------------------


LSP Explorer export.
Created on:2005-6-15 8:27:10
---------------------------------------------

Layered Service Providers
MSAFD Tcpip [TCP/IP]
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1001
Address Family : internetwork: UDP, TCP, etc.
Provider : {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Service Flags 1 : $00020066
XP1_GUARANTEED_DELIVERY
XP1_GUARANTEED_ORDER
XP1_GRACEFUL_CLOSE
XP1_EXPEDITED_DATA
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : $00000008
PFL_MATCHES_PROTOCOL_ZERO
Maximum Message Size : {logcontent}
Security Sheme : 0
Byte Order : Big Endian
Protocol : 6
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000010
Max Socket Address : $00000010
Socket Type : Stream
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
MSAFD Tcpip [UDP/IP]
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1002
Address Family : internetwork: UDP, TCP, etc.
Provider : {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Service Flags 1 : $00020609
XP1_CONNECTIONLESS
XP1_MESSAGE_ORIENTED
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_MULTIPOINT
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : $00000008
PFL_MATCHES_PROTOCOL_ZERO
Maximum Message Size : {logcontent}FFBB
Security Sheme : 0
Byte Order : Big Endian
Protocol : 17
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000010
Max Socket Address : $00000010
Socket Type : Datagram
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
MSAFD Tcpip [RAW/IP]
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1003
Address Family : internetwork: UDP, TCP, etc.
Provider : {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Service Flags 1 : $00020609
XP1_CONNECTIONLESS
XP1_MESSAGE_ORIENTED
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_MULTIPOINT
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : {logcontent}C
PFL_HIDDEN
PFL_MATCHES_PROTOCOL_ZERO
Maximum Message Size : {logcontent}FFBB
Security Sheme : 0
Byte Order : Big Endian
Protocol : 0
Protocol MaxOffset : {logcontent}FF
Min Socket Address : $00000010
Max Socket Address : $00000010
Socket Type : Unknown
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
RSVP UDP Service Provider
Filename : C:\WINNT\system32\rsvpsp.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Rsvp 1.0 Service Provider
File version : 5.00.2195.6611
Internal name : rsvpsp.dll
Original filename : rsvpsp.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6611
Version : 4
Catalog Entry : 1004
Address Family : internetwork: UDP, TCP, etc.
Provider : {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Service Flags 1 : $00022609
XP1_CONNECTIONLESS
XP1_MESSAGE_ORIENTED
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_MULTIPOINT
XP1_QOS_SUPPORTED
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : $00000008
PFL_MATCHES_PROTOCOL_ZERO
Maximum Message Size : {logcontent}FFBB
Security Sheme : 0
Byte Order : Big Endian
Protocol : 17
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000010
Max Socket Address : $00000010
Socket Type : Datagram
Protocol Chain length : 1
Protocol Chain Entry (0) : 1775647788
RSVP TCP Service Provider
Filename : C:\WINNT\system32\rsvpsp.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Rsvp 1.0 Service Provider
File version : 5.00.2195.6611
Internal name : rsvpsp.dll
Original filename : rsvpsp.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6611
Version : 4
Catalog Entry : 1005
Address Family : internetwork: UDP, TCP, etc.
Provider : {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Service Flags 1 : $00022066
XP1_GUARANTEED_DELIVERY
XP1_GUARANTEED_ORDER
XP1_GRACEFUL_CLOSE
XP1_EXPEDITED_DATA
XP1_QOS_SUPPORTED
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : $00000008
PFL_MATCHES_PROTOCOL_ZERO
Maximum Message Size : {logcontent}
Security Sheme : 0
Byte Order : Big Endian
Protocol : 6
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000010
Max Socket Address : $00000010
Socket Type : Stream
Protocol Chain length : 1
Protocol Chain Entry (0) : 6553707
MSAFD NetBIOS [\Device\NetBT_Tcpip_{7BD5FF36-87E0-46F3-8190-D45716B680A4}] SEQPACKET 0
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1006
Address Family : NetBios-style addresses
Provider : {8D5F1830-C273-11CF-95C8-00805F48A192}
Service Flags 1 : $0002000E
XP1_GUARANTEED_DELIVERY
XP1_GUARANTEED_ORDER
XP1_MESSAGE_ORIENTED
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : $00000008
PFL_MATCHES_PROTOCOL_ZERO
Maximum Message Size : {logcontent}FA00
Security Sheme : 0
Byte Order : Big Endian
Protocol : -2147483648
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000014
Max Socket Address : $00000014
Socket Type : Unknown
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
MSAFD NetBIOS [\Device\NetBT_Tcpip_{7BD5FF36-87E0-46F3-8190-D45716B680A4}] DATAGRAM 0
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1007
Address Family : NetBios-style addresses
Provider : {8D5F1830-C273-11CF-95C8-00805F48A192}
Service Flags 1 : $00020209
XP1_CONNECTIONLESS
XP1_MESSAGE_ORIENTED
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_BROADCAST
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : $00000008
PFL_MATCHES_PROTOCOL_ZERO
Maximum Message Size : {logcontent}FA00
Security Sheme : 0
Byte Order : Big Endian
Protocol : -2147483648
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000014
Max Socket Address : $00000014
Socket Type : Datagram
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
MSAFD NetBIOS [\Device\NetBT_Tcpip_{9C9DE15C-6251-4967-AE62-AF47F25CB702}] SEQPACKET 1
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1008
Address Family : NetBios-style addresses
Provider : {8D5F1830-C273-11CF-95C8-00805F48A192}
Service Flags 1 : $0002000E
XP1_GUARANTEED_DELIVERY
XP1_GUARANTEED_ORDER
XP1_MESSAGE_ORIENTED
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : {logcontent}
Maximum Message Size : {logcontent}FA00
Security Sheme : 0
Byte Order : Big Endian
Protocol : -1
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000014
Max Socket Address : $00000014
Socket Type : Unknown
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
MSAFD NetBIOS [\Device\NetBT_Tcpip_{9C9DE15C-6251-4967-AE62-AF47F25CB702}] DATAGRAM 1
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1009
Address Family : NetBios-style addresses
Provider : {8D5F1830-C273-11CF-95C8-00805F48A192}
Service Flags 1 : $00020209
XP1_CONNECTIONLESS
XP1_MESSAGE_ORIENTED
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_BROADCAST
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : {logcontent}
Maximum Message Size : {logcontent}FA00
Security Sheme : 0
Byte Order : Big Endian
Protocol : -1
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000014
Max Socket Address : $00000014
Socket Type : Datagram
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
MSAFD NetBIOS [\Device\NetBT_Tcpip_{B74F13B8-12F6-496E-A935-C26C824B212F}] SEQPACKET 2
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1010
Address Family : NetBios-style addresses
Provider : {8D5F1830-C273-11CF-95C8-00805F48A192}
Service Flags 1 : $0002000E
XP1_GUARANTEED_DELIVERY
XP1_GUARANTEED_ORDER
XP1_MESSAGE_ORIENTED
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : {logcontent}
Maximum Message Size : {logcontent}FA00
Security Sheme : 0
Byte Order : Big Endian
Protocol : -2
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000014
Max Socket Address : $00000014
Socket Type : Unknown
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
MSAFD NetBIOS [\Device\NetBT_Tcpip_{B74F13B8-12F6-496E-A935-C26C824B212F}] DATAGRAM 2
Filename : C:\WINNT\system32\msafd.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Microsoft Windows Sockets 2.0 Service Provider
File version : 5.00.2195.6602
Internal name : msafd.dll
Original filename : msafd.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6602
Version : 2
Catalog Entry : 1011
Address Family : NetBios-style addresses
Provider : {8D5F1830-C273-11CF-95C8-00805F48A192}
Service Flags 1 : $00020209
XP1_CONNECTIONLESS
XP1_MESSAGE_ORIENTED
XP1_SUPPORT_BROADCAST
XP1_SUPPORT_BROADCAST
XP1_IFS_HANDLES
Service Flags 2 : {logcontent}
Service Flags 3 : {logcontent}
Service Flags 4 : {logcontent}
Provider Flags : {logcontent}
Maximum Message Size : {logcontent}FA00
Security Sheme : 0
Byte Order : Big Endian
Protocol : -2
Protocol MaxOffset : {logcontent}
Min Socket Address : $00000014
Max Socket Address : $00000014
Socket Type : Datagram
Protocol Chain length : 1
Protocol Chain Entry (0) : 0
Name Space Providers
Description : Tcpip
Filename : C:\WINNT\system32\rnr20.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : Windows Socket2 NameSpace DLL
File version : 5.00.2195.6603
Internal name : rnr20.dll
Original filename : rnr20.dll
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2195.6603
NameSpace : NS_DNS
Active : Yes
Protocol Version : 0
Provider : {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Description : NTDS
Filename : C:\WINNT\system32\winrnr.dll
Legal copyright : Copyright (C) Microsoft Corp. 1981-1999
Company name : Microsoft Corporation
File desicription : LDAP RnR Provider DLL
File version : 5.00.2160.1
Internal name : winrnr
Original filename : winrnr
Product name : Microsoft(R) Windows (R) 2000 Operating System
Product version : 5.00.2160.1
NameSpace : NS_NTDS
Active : Yes
Protocol Version : 0
Provider : {3B2637EE-E580-11CF-A555-00C04FD8D4AC}



--------------------------------------------------


Ad-Aware SE Process Snapshot 2005-6-15 8:32:47
------------------------------------------------
HWND ClassName Process ID Thread ID Filename Threads Parent Priority Command Line
66602 /$1042A QQIEFloarBarHost 1812 /$0714 1888 /$0760 C:\Program Files\Internet Explorer\iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" -nohome C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe Normal 12
66588 /$1041C tooltips_class32 1812 /$0714 1888 /$0760 C:\Program Files\Internet Explorer\iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" -nohome C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe Normal 12
66582 /$10416 Auto-Suggest Dropdown 1812 /$0714 1888 /$0760 C:\Program Files\Internet Explorer\iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" -nohome C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe Normal 12
66576 /$10410 ComboLBox 1812 /$0714 1888 /$0760 C:\Program Files\Internet Explorer\iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" -nohome C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe Normal 12
66544 /$103F0 DDEMLEvent 1812 /$0714 1888 /$0760 C:\Program Files\Internet Explorer\iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" -nohome C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe Normal 12
66450 /$10392 ComboLBox 1468 /$05BC 1692 /$069C C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" C:\WINNT\Explorer.EXE Normal 7
66446 /$1038E TPUtilWindow 1468 /$05BC 1692 /$069C C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" C:\WINNT\Explorer.EXE Normal 7
66444 /$1038C ComboLBox 1468 /$05BC 1692 /$069C C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" C:\WINNT\Explorer.EXE Normal 7
66440 /$10388 TPUtilWindow 1468 /$05BC 1692 /$069C C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" C:\WINNT\Explorer.EXE Normal 7
66378 /$1034A Internet Explorer_Hidden 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
66364 /$1033C Afx:6560000:0 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
66354 /$10332 Afx:6540000:0 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
66336 /$10320 Afx:5240000:0 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
66334 /$1031E Afx:1840000:0 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
66294 /$102F6 ACListClass 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
66190 /$1028E Afx:400000:0 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
66116 /$10244 Afx:1840000:0 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
66114 /$10242 Afx:1bb0000:0 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
66104 /$10238 Afx:1840000:0 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
66102 /$10236 Afx:1840000:0 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
66100 /$10234 Afx:1840000:0 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
66096 /$10230 Afx:1840000:0 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
65990 /$101C6 tooltips_class32 1436 /$059C 1796 /$0704 C:\WINNT\Explorer.EXE C:\WINNT\Explorer.EXE [System] Normal 14
65924 /$10184 TPUtilWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
65922 /$10182 TPUtilWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
65916 /$1017C TPUtilWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
65914 /$1017A TPUtilWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
65912 /$10178 TPUtilWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
65910 /$10176 TPUtilWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
65908 /$10174 TPUtilWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
65906 /$10172 TPUtilWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
65904 /$10170 TPUtilWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
65902 /$1016E TPUtilWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
65900 /$1016C TPUtilWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
65898 /$1016A TPUtilWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
65896 /$10168 TPUtilWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
65894 /$10166 TPUtilWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
65796 /$10104 TPUtilWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
65794 /$10102 TPUtilWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
65692 /$1009C CTrayIconWndClass 1216 /$04C0 1600 /$0640 C:\WINNT\system32\ctfmon.exe "C:\WINNT\system32\ctfmon.exe" C:\WINNT\Explorer.EXE Normal 1
65688 /$10098 CicLoaderWndClass 1216 /$04C0 1600 /$0640 C:\WINNT\system32\ctfmon.exe "C:\WINNT\system32\ctfmon.exe" C:\WINNT\Explorer.EXE Normal 1
65682 /$10092 ThunderRT6Main 1376 /$0560 1052 /$041C C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE "C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE" /load C:\WINNT\Explorer.EXE Normal 7
65654 /$10076 tooltips_class32 1436 /$059C 1344 /$0540 C:\WINNT\Explorer.EXE C:\WINNT\Explorer.EXE [System] Normal 14
65640 /$10068 BaseBar 1436 /$059C 1652 /$0674 C:\WINNT\Explorer.EXE C:\WINNT\Explorer.EXE [System] Normal 14
525136 /$80350 TVirtualTreeHintWindow 1468 /$05BC 1692 /$069C C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" C:\WINNT\Explorer.EXE Normal 7
197580 /$303CC IME 1812 /$0714 1888 /$0760 C:\Program Files\Internet Explorer\iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" -nohome C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe Normal 12
196698 /$3005A DDEMLMom 1436 /$059C 1344 /$0540 C:\WINNT\Explorer.EXE C:\WINNT\Explorer.EXE [System] Normal 14
196652 /$3002C tooltips_class32 1436 /$059C 1652 /$0674 C:\WINNT\Explorer.EXE C:\WINNT\Explorer.EXE [System] Normal 14
132074 /$203EA DDEMLMom 1812 /$0714 1888 /$0760 C:\Program Files\Internet Explorer\iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" -nohome C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe Normal 12
132046 /$203CE Internet Explorer_Hidden 1812 /$0714 1888 /$0760 C:\Program Files\Internet Explorer\iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" -nohome C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe Normal 12
131630 /$2022E TPUtilWindow 1468 /$05BC 1692 /$069C C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" C:\WINNT\Explorer.EXE Normal 7
131626 /$2022A TPUtilWindow 1468 /$05BC 1692 /$069C C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" C:\WINNT\Explorer.EXE Normal 7
131614 /$2021E TPUtilWindow 1468 /$05BC 1692 /$069C C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" C:\WINNT\Explorer.EXE Normal 7
131610 /$2021A TPUtilWindow 1468 /$05BC 1692 /$069C C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" C:\WINNT\Explorer.EXE Normal 7
131606 /$20216 TPUtilWindow 1468 /$05BC 1692 /$069C C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" C:\WINNT\Explorer.EXE Normal 7
131602 /$20212 TPUtilWindow 1468 /$05BC 1692 /$069C C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" C:\WINNT\Explorer.EXE Normal 7
131598 /$2020E TPUtilWindow 1468 /$05BC 1692 /$069C C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" C:\WINNT\Explorer.EXE Normal 7
131594 /$2020A TPUtilWindow 1468 /$05BC 1692 /$069C C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" C:\WINNT\Explorer.EXE Normal 7
131590 /$20206 TPUtilWindow 1468 /$05BC 1692 /$069C C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" C:\WINNT\Explorer.EXE Normal 7
131206 /$20086 VBMsoStdCompMgr 1376 /$0560 1052 /$041C C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE "C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE" /load C:\WINNT\Explorer.EXE Normal 7
131158 /$20056 DDEMLEvent 1436 /$059C 1344 /$0540 C:\WINNT\Explorer.EXE C:\WINNT\Explorer.EXE [System] Normal 14
131152 /$20050 WorkerW 1436 /$059C 1344 /$0540 C:\WINNT\Explorer.EXE C:\WINNT\Explorer.EXE [System] Normal 14
131150 /$2004E Shell_TrayWnd 1436 /$059C 1652 /$0674 C:\WINNT\Explorer.EXE C:\WINNT\Explorer.EXE [System] Normal 14
Ad-Aware SE 131274 /$200CA TApplication 1468 /$05BC 1692 /$069C C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" C:\WINNT\Explorer.EXE Normal 7
Auto Update Client Window 131344 /$20110 Auto Update Client Window 1572 /$0624 1448 /$05A8 C:\WINNT\system32\wuauclt.exe "C:\WINNT\system32\wuauclt.exe" C:\WINNT\system32\svchost.exe Normal 5
CAsyncSocketEx Helper Window 66348 /$1032C CAsyncSocketEx Helper Window 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
Connections Tray 65660 /$1007C Connections Tray 1436 /$059C 1456 /$05B0 C:\WINNT\Explorer.EXE C:\WINNT\Explorer.EXE [System] Normal 14
DDE Server Window 66606 /$1042E OleDdeWndClass 1812 /$0714 1888 /$0760 C:\Program Files\Internet Explorer\iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" -nohome C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe Normal 12
DDE Server Window 66178 /$10282 OleDdeWndClass 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
DDE Server Window 131154 /$20052 OleDdeWndClass 1436 /$059C 1344 /$0540 C:\WINNT\Explorer.EXE C:\WINNT\Explorer.EXE [System] Normal 14
Emoticon Window 66300 /$102FC Afx:400000:3:10011:0:0 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
GDI+ Window 66298 /$102FA GDI+ Hook Window Class 1800 /$0708 1460 /$05B4 D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
IMMIF UI 197588 /$303D4 IMMIF UI 1812 /$0714 1888 /$0760 C:\Program Files\Internet Explorer\iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" -nohome C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe Normal 12
Lavasoft - Microsoft Internet Explorer 132072 /$203E8 IEFrame 1812 /$0714 1888 /$0760 C:\Program Files\Internet Explorer\iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" -nohome C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe Normal 12
Lavasoft Ad-Watch 65696 /$100A0 TApplication 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
MCI command handling window 328512 /$50340 #43 1436 /$059C 1852 /$073C C:\WINNT\Explorer.EXE C:\WINNT\Explorer.EXE [System] Normal 14
MM Notify Callback 65564 /$1001C MM Notify Callback 204 /{logcontent}CC 284 /$011C \??\C:\WINNT\system32\winlogon.exe winlogon.exe \SystemRoot\System32\smss.exe High 19
MS_WebcheckMonitor 65658 /$1007A MS_WebcheckMonitor 1436 /$059C 1652 /$0674 C:\WINNT\Explorer.EXE C:\WINNT\Explorer.EXE [System] Normal 14
NetDDE Agent 65562 /$1001A NDDEAgnt 204 /{logcontent}CC 268 /$010C \??\C:\WINNT\system32\winlogon.exe winlogon.exe \SystemRoot\System32\smss.exe High 19
Process filter. Shows all recognized, but allowed processes. 65998 /$101CE THintWindow 1788 /$06FC 784 /$0310 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" C:\WINNT\Explorer.EXE Normal 7
Program Manager 65638 /$10066 Progman 1436 /$059C 1344 /$0540 C:\WINNT\Explorer.EXE C:\WINNT\Explorer.EXE [System] Normal 14
Proxy Notification Sink 66106 /$1023A Simple Window 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
Socket Notification Sink 131794 /$202D2 Afx:1840000:0 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
SockTimer Wnd 66352 /$10330 Simple Window 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
SockTimer Wnd 66350 /$1032E Simple Window 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
SockTimer Wnd 66346 /$1032A Simple Window 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11
SysFader 66566 /$10406 SysFader 1812 /$0714 1888 /$0760 C:\Program Files\Internet Explorer\iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" -nohome C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe Normal 12
SYSTEM AGENT COM WINDOW 65588 /$10034 SAGEWINDOWCLASS 908 /$038C 952 /$03B8 C:\WINNT\system32\MSTask.exe C:\WINNT\system32\MSTask.exe C:\WINNT\system32\services.exe Normal 7
传真监视器 65974 /$101B6 FaxStatWinClass 1436 /$059C 1796 /$0704 C:\WINNT\Explorer.EXE C:\WINNT\Explorer.EXE [System] Normal 14
电源表 65666 /$10082 SystemTray_Main 1436 /$059C 1796 /$0704 C:\WINNT\Explorer.EXE C:\WINNT\Explorer.EXE [System] Normal 14
腾讯通(未注册) 66180 /$10284 #32770 1800 /$0708 1740 /$06CC D:\Program Files\Tencent\RTX\rtxc.exe "D:\Program Files\Tencent\RTX\rtxc.exe" C:\WINNT\Explorer.EXE Normal 11


---------------------------------------------------



Ad-Aware SE Module Snapshot 2005-6-15 8:34:16
------------------------------------------------
Path BaseAddress Size
iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe
ntdll.dll C:\WINNT\system32\ntdll.dll
KERNEL32.dll C:\WINNT\system32\KERNEL32.dll
USER32.dll C:\WINNT\system32\USER32.dll
GDI32.dll C:\WINNT\system32\GDI32.dll
SHLWAPI.dll C:\WINNT\system32\SHLWAPI.dll
ADVAPI32.dll C:\WINNT\system32\ADVAPI32.dll
RPCRT4.DLL C:\WINNT\system32\RPCRT4.DLL
IMM32.DLL C:\WINNT\system32\IMM32.DLL
LPK.DLL C:\WINNT\system32\LPK.DLL
USP10.dll C:\WINNT\system32\USP10.dll
shdocvw.dll C:\WINNT\system32\shdocvw.dll
COMCTL32.dll C:\WINNT\system32\COMCTL32.dll
SHELL32.dll C:\WINNT\system32\SHELL32.dll
ole32.dll C:\WINNT\system32\ole32.dll
MSCTF.dll C:\WINNT\system32\MSCTF.dll
BROWSEUI.dll C:\WINNT\system32\BROWSEUI.dll
CLBCATQ.DLL C:\WINNT\system32\CLBCATQ.DLL
OLEAUT32.dll C:\WINNT\system32\OLEAUT32.dll
MSVCRT.dll C:\WINNT\system32\MSVCRT.dll
browselc.dll C:\WINNT\system32\browselc.dll
WININET.DLL C:\WINNT\system32\WININET.DLL
cscui.dll C:\WINNT\system32\cscui.dll
CSCDLL.DLL C:\WINNT\system32\CSCDLL.DLL
xunleibho_v2.dll C:\WINNT\system32\xunleibho_v2.dll
MFC42.DLL C:\WINNT\system32\MFC42.DLL
MFC42LOC.DLL C:\WINNT\system32\MFC42LOC.DLL
QQIEHelper.dll d:\Program Files\Tencent\QQ\QQIEHelper.dll
OLEACC.dll C:\WINNT\system32\OLEACC.dll
VERSION.dll C:\WINNT\system32\VERSION.dll
LZ32.DLL C:\WINNT\system32\LZ32.DLL
jccatch.dll C:\PROGRA~1\FlashGet\jccatch.dll
msctf.dll.mui C:\WINNT\mui\fallback\0804\msctf.dll.mui
URLMON.DLL C:\WINNT\system32\URLMON.DLL
shdoclc.dll C:\WINNT\system32\shdoclc.dll
mlang.dll C:\WINNT\system32\mlang.dll
wsock32.dll C:\WINNT\system32\wsock32.dll
WS2_32.DLL C:\WINNT\system32\WS2_32.DLL
WS2HELP.DLL C:\WINNT\system32\WS2HELP.DLL
msafd.dll C:\WINNT\system32\msafd.dll
RASAPI32.DLL C:\WINNT\system32\RASAPI32.DLL
RASMAN.DLL C:\WINNT\system32\RASMAN.DLL
TAPI32.DLL C:\WINNT\system32\TAPI32.DLL
RTUTILS.DLL C:\WINNT\system32\RTUTILS.DLL
sensapi.dll C:\WINNT\system32\sensapi.dll
wshtcpip.dll C:\WINNT\System32\wshtcpip.dll
USERENV.DLL C:\WINNT\system32\USERENV.DLL
netapi32.dll C:\WINNT\system32\netapi32.dll
Secur32.dll C:\WINNT\system32\Secur32.dll
NTDSAPI.dll C:\WINNT\system32\NTDSAPI.dll
DNSAPI.DLL C:\WINNT\system32\DNSAPI.DLL
WLDAP32.DLL C:\WINNT\system32\WLDAP32.DLL
NETRAP.dll C:\WINNT\system32\NETRAP.dll
SAMLIB.dll C:\WINNT\system32\SAMLIB.dll
rnr20.dll C:\WINNT\System32\rnr20.dll
iphlpapi.dll C:\WINNT\system32\iphlpapi.dll
ICMP.DLL C:\WINNT\system32\ICMP.DLL
MPRAPI.DLL C:\WINNT\system32\MPRAPI.DLL
ACTIVEDS.DLL C:\WINNT\system32\ACTIVEDS.DLL
ADSLDPC.DLL C:\WINNT\system32\ADSLDPC.DLL
SETUPAPI.DLL C:\WINNT\system32\SETUPAPI.DLL
DHCPCSVC.DLL C:\WINNT\system32\DHCPCSVC.DLL
winrnr.dll C:\WINNT\System32\winrnr.dll
rasadhlp.dll C:\WINNT\system32\rasadhlp.dll
BQQHook.dll D:\Program Files\Tencent\RTX\BQQHook.dll
mshtml.dll C:\WINNT\system32\mshtml.dll
PDM.DLL C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\PDM.DLL
mdmui.dll C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\2052\mdmui.dll
MSDBG2.DLL C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MSDBG2.DLL
msimtf.dll C:\WINNT\system32\msimtf.dll
msohev.dll C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
RavScrCh.dll C:\Program Files\rising\Rav\RavScrCh.dll
vbscript.dll C:\WINNT\system32\vbscript.dll
jscript.dll C:\WINNT\system32\jscript.dll
MSLS31.DLL C:\WINNT\system32\MSLS31.DLL
SHFOLDER.DLL C:\WINNT\system32\SHFOLDER.DLL
标签集:TAGS:
回复Comments()点击Count()

回复Comments

{commenttime}{commentauthor}

{CommentUrl}
{commentcontent}
Categories
Links
New Comments
Counter
RSS
我的 Blog:
ghostcn 最新的 20 条日志
[思想]
[计算机]
[视觉]
[触觉]
[会计]
[网络资源]
[采集]
[情感]
[游戏外挂]
[赤裸HUMOUR]
全站 Blog:
全站最新的 20 条日志
Calendar