[C:\Program Files\Common Files\Teleca Shared\Telecalib_logging.dll] [Teleca/Popwire AB, 1, 0, 2, 3]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Common Files\Teleca Shared\boost_log-vc71-mt-1_32.dll] [N/A, ]
[C:\WINDOWS\system32\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
[c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[c:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application LauncherLg.dll] [Sony Ericsson Mobile Communications AB, 1.0.6.1]
[C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application LauncherBmp.dll] [Sony Ericsson Mobile Communications AB, 1.0.6.1]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\midimapzx.dll] [N/A, ]
[C:\WINDOWS\system32\midimapwl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapjr.dll] [N/A, ]
[C:\WINDOWS\system32\midimappt.dll] [N/A, ]
[C:\WINDOWS\system32\midimaptl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapcb.dll] [N/A, ]
[C:\WINDOWS\system32\midimapmy.dll] [N/A, ]
[C:\Program Files\Sony Ericsson\Mobile2\InstSupport\TC Device Mgmt.dll] [Teleca Software Solutions, 1, 0, 1, 1]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[PID: 1108 / Administrator][C:\Program Files\Unlocker\UnlockerAssistant.exe] [N/A, ]
[c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[c:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\midimapzx.dll] [N/A, ]
[C:\WINDOWS\system32\midimapwl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapjr.dll] [N/A, ]
[C:\WINDOWS\system32\midimappt.dll] [N/A, ]
[C:\WINDOWS\system32\midimaptl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapcb.dll] [N/A, ]
[C:\WINDOWS\system32\midimapmy.dll] [N/A, ]
[PID: 1180 / Administrator][C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe] [Popwire AB, 1.2.0.70]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Common Files\Teleca Shared\tlib_log.dll] [Popwire AB, 1, 0, 3, 3]
[C:\Program Files\Common Files\Teleca Shared\boost_log-vc71-mt-1_33.dll] [N/A, ]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[c:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\midimapzx.dll] [N/A, ]
[C:\WINDOWS\system32\midimapwl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapjr.dll] [N/A, ]
[C:\WINDOWS\system32\midimappt.dll] [N/A, ]
[C:\WINDOWS\system32\midimaptl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapcb.dll] [N/A, ]
[C:\WINDOWS\system32\midimapmy.dll] [N/A, ]
[C:\WINDOWS\system32\msxml4.dll] [Microsoft Corporation, 4.20.9818.0]
[PID: 1324 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 3280 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[PID: 3296 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[c:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\midimapzx.dll] [N/A, ]
[C:\WINDOWS\system32\midimapwl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapjr.dll] [N/A, ]
[C:\WINDOWS\system32\midimappt.dll] [N/A, ]
[C:\WINDOWS\system32\midimaptl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapcb.dll] [N/A, ]
[C:\WINDOWS\system32\midimapmy.dll] [N/A, ]
[E:\web讯雷\WebThunderBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 75]
[C:\WINDOWS\system32\opshbbty.dll] [N/A, ]
[C:\WINDOWS\system32\ozfyebyt.dll] [N/A, ]
[C:\WINDOWS\system32\oohxdbyt.dll] [N/A, ]
[C:\WINDOWS\system32\zxmscwin.dll] [N/A, ]
[C:\WINDOWS\system32\mnmhgsrv.dll] [N/A, ]
[C:\WINDOWS\system32\ypdjfbmp.dll] [N/A, ]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx] [Adobe Systems, Inc., 9,0,115,0]
[PID: 3812 / Administrator][C:\Program Files\Common Files\Teleca Shared\Generic.exe] [Teleca Software Solutions, 1, 0, 3, 2]
[C:\Program Files\Common Files\Teleca Shared\Telecalib_logging.dll] [Teleca/Popwire AB, 1, 0, 2, 3]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Common Files\Teleca Shared\boost_log-vc71-mt-1_32.dll] [N/A, ]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[c:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\WINDOWS\system32\msxml4.dll] [Microsoft Corporation, 4.20.9818.0]
[C:\Program Files\Sony Ericsson\Mobile2\InstSupport\TC Device Mgmt.dll] [Teleca Software Solutions, 1, 0, 1, 1]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\midimapzx.dll] [N/A, ]
[C:\WINDOWS\system32\midimapwl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapjr.dll] [N/A, ]
[C:\WINDOWS\system32\midimappt.dll] [N/A, ]
[C:\WINDOWS\system32\midimaptl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapcb.dll] [N/A, ]
[C:\WINDOWS\system32\midimapmy.dll] [N/A, ]
[C:\Program Files\Sony Ericsson\Mobile2\Device Manager\SpecificMPM.dll] [SonyEricsson, 1, 0, 2, 1]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\anubisps.dll] [N/A, ]
[C:\Program Files\Common Files\Teleca Shared\SpecificUSB.dll] [Popwire AB, 1, 2, 1, 1]
[C:\Program Files\Common Files\Teleca Shared\tlib_log.dll] [Popwire AB, 1, 0, 3, 3]
[C:\Program Files\Common Files\Teleca Shared\boost_log-vc71-mt-1_33.dll] [N/A, ]
[PID: 3912 / Administrator][C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe] [Sony Ericsson Mobile Communications AB, 1, 2, 0,1190]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ShowMfcDialog.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,122]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[c:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\midimapzx.dll] [N/A, ]
[C:\WINDOWS\system32\midimapwl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapjr.dll] [N/A, ]
[C:\WINDOWS\system32\midimappt.dll] [N/A, ]
[C:\WINDOWS\system32\midimaptl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapcb.dll] [N/A, ]
[C:\WINDOWS\system32\midimapmy.dll] [N/A, ]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\anubisps.dll] [N/A, ]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\cellphone_object.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,1194]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ecsmoddata.dll] [Sony Ericsson Mobile Communications AB, 1, 2, 0,309]
[C:\WINDOWS\system32\msxml4.dll] [Microsoft Corporation, 4.20.9818.0]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\Capires0804.DLL] [Popwire AB, 1, 0, 0,2018]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\msmeirsock_object.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,946]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ms98irsock_object.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,991]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\msirsock_object.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,1003]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\cabmain.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,1226]
[PID: 4052 / Administrator][C:\Program Files\锐捷网络\Ruijie Supplicant\8021x.exe] [锐捷网络, 3, 2, 0, 0]
[C:\WINDOWS\system32\W32N50.dll] [Printing Communications Assoc., Inc. (PCAUSA), 5.03.16.54]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[c:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\midimapzx.dll] [N/A, ]
[C:\WINDOWS\system32\midimapwl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapjr.dll] [N/A, ]
[C:\WINDOWS\system32\midimappt.dll] [N/A, ]
[C:\WINDOWS\system32\midimaptl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapcb.dll] [N/A, ]
[C:\WINDOWS\system32\midimapmy.dll] [N/A, ]
[C:\PROGRA~1\锐捷网络\RUIJIE~1\EXRGPA~1.OCX] [锐捷网络, 1, 0, 0, 1]
[C:\PROGRA~1\锐捷网络\RUIJIE~1\HIDetect.dll] [锐捷网络, 1, 0, 0, 1]
[C:\PROGRA~1\锐捷网络\RUIJIE~1\Vx_API.dll] [锐捷网络, 1, 0, 0, 1]
[C:\WINDOWS\system32\ozfyebyt.dll] [N/A, ]
[C:\WINDOWS\system32\opshbbty.dll] [N/A, ]
[C:\WINDOWS\system32\oohxdbyt.dll] [N/A, ]
[C:\WINDOWS\system32\mnmhgsrv.dll] [N/A, ]
[C:\WINDOWS\system32\zxmscwin.dll] [N/A, ]
[C:\WINDOWS\system32\ypdjfbmp.dll] [N/A, ]
[PID: 2424 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\midimapzx.dll] [N/A, ]
[C:\WINDOWS\system32\midimapwl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapjr.dll] [N/A, ]
[C:\WINDOWS\system32\midimappt.dll] [N/A, ]
[C:\WINDOWS\system32\midimaptl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapcb.dll] [N/A, ]
[C:\WINDOWS\system32\midimapmy.dll] [N/A, ]
[PID: 2892 / Administrator][F:\Xunlei\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[c:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\midimapzx.dll] [N/A, ]
[C:\WINDOWS\system32\midimapwl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapjr.dll] [N/A, ]
[C:\WINDOWS\system32\midimappt.dll] [N/A, ]
[C:\WINDOWS\system32\midimaptl.dll] [N/A, ]
[C:\WINDOWS\system32\midimapcb.dll] [N/A, ]
[C:\WINDOWS\system32\midimapmy.dll] [N/A, ]
[F:\Xunlei\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
0.0.0.0 182838.com
0.0.0.0 204.177.92.68
0.0.0.0 asiafriendfinder.com
0.0.0.0 asqin123.51.net
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0
www.jpbeauty.com0.0.0.0 beautishow.com
0.0.0.0 goodmovies88.com
0.0.0.0 hothack.home.chinaren.com
0.0.0.0 hualiao.net
0.0.0.0 iplus.allyes.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 asqin123.51.net
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
219.153.32.215 auto.search.msn.com
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 588, C:\PROGRAM FILES\RISING\KAKATOOLBAR\RUNIEP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 588, C:\PROGRAM FILES\RISING\KAKATOOLBAR\RUNIEP.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1088, C:\PROGRAM FILES\SONY ERICSSON\MOBILE2\APPLICATION LAUNCHER\APPLICATION LAUNCHER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1088, C:\PROGRAM FILES\SONY ERICSSON\MOBILE2\APPLICATION LAUNCHER\APPLICATION LAUNCHER.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1108, C:\PROGRAM FILES\UNLOCKER\UNLOCKERASSISTANT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1108, C:\PROGRAM FILES\UNLOCKER\UNLOCKERASSISTANT.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1180, C:\PROGRAM FILES\COMMON FILES\TELECA SHARED\CAPABILITYMANAGER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1180, C:\PROGRAM FILES\COMMON FILES\TELECA SHARED\CAPABILITYMANAGER.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3812, C:\PROGRAM FILES\COMMON FILES\TELECA SHARED\GENERIC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3812, C:\PROGRAM FILES\COMMON FILES\TELECA SHARED\GENERIC.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3912, C:\PROGRAM FILES\SONY ERICSSON\MOBILE2\MOBILE PHONE MONITOR\EPMWORKER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3912, C:\PROGRAM FILES\SONY ERICSSON\MOBILE2\MOBILE PHONE MONITOR\EPMWORKER.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 4052, C:\PROGRAM FILES\锐捷网络\RUIJIE SUPPLICANT\8021X.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 4052, C:\PROGRAM FILES\锐捷网络\RUIJIE SUPPLICANT\8021X.EXE]
==================================
API HOOK
入口点错误:NtCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003D4355)
入口点错误:NtWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003D43F5)
入口点错误:ZwCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003D4355)
入口点错误:ZwWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003D43F5)
入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: 0x00F91FFD)
入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: 0x00F920E5)
==================================
隐藏进程
N/A
==================================
[/CODE]