123   2  /  3  页   跳转

怀疑中招了 ~~`HELP~~

[C:\ftc\ftcapi.dll]  [fygsoft, 1.1.0.0]
    [C:\ftc\Filehook.dll]  [Fygsoft and Microsoft, 2.0.0.0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 464 / sky][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\ftc\Filehook.dll]  [Fygsoft and Microsoft, 2.0.0.0]
[PID: 300 / sky][C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe]  [Nero AG, 2,0,13,0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Common Files\Ahead\Lib\AdvrCntr2.dll]  [Nero AG, 9,4,2, 10850]
    [C:\Program Files\Common Files\Ahead\Lib\NMIndexingServicePS.dll]  [Nero AG, 2,0,13,0]
    [C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvrPS.dll]  [Nero AG, 2,0,13,0]
    [C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll]  [Nero AG, 2,0,13,0]
    [C:\ftc\Filehook.dll]  [Fygsoft and Microsoft, 2.0.0.0]
[PID: 972 / SYSTEM][C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe]  [Nero AG, 2,0,13,0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Common Files\Ahead\Lib\NMIndexingServicePS.dll]  [Nero AG, 2,0,13,0]
    [C:\Program Files\Common Files\Ahead\Lib\NMLogCxx.dll]  [Nero AG, 2,0,13,0]
    [C:\Program Files\Common Files\Ahead\Lib\log4cxx.dll]  [Nero AG, 1, 0, 0, 0]
    [C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll]  [Nero AG, 2,0,13,0]
    [C:\ftc\Filehook.dll]  [Fygsoft and Microsoft, 2.0.0.0]
    [C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvrPS.dll]  [Nero AG, 2,0,13,0]
[PID: 1404 / sky][C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe]  [Nero AG, 2,0,13,0]
    [C:\Program Files\Common Files\Ahead\Lib\NMSQLDB.dll]  [Nero AG, 2,0,13,0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Common Files\Ahead\Lib\NMLogCxx.dll]  [Nero AG, 2,0,13,0]
    [C:\Program Files\Common Files\Ahead\Lib\log4cxx.dll]  [Nero AG, 1, 0, 0, 0]
    [C:\Program Files\Common Files\Ahead\Lib\NMIndexingServicePS.dll]  [Nero AG, 2,0,13,0]
    [C:\Program Files\Common Files\Ahead\Lib\NMCoFoundation.dll]  [Nero AG, 2,0,13,0]
    [C:\Program Files\Common Files\Ahead\Lib\NMFullTextExtraction.dll]  [Nero AG, 2,0,13,0]
    [C:\Program Files\Common Files\Ahead\Lib\NMSearchPluginSimilarImages.dll]  [Nero AG, 2,0,13,0]
    [C:\Program Files\Common Files\Ahead\Lib\NeroIPP.dll]  [Nero AG, 4, 10, 5, 0]
    [C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll]  [Nero AG, 2,0,13,0]
    [C:\ftc\Filehook.dll]  [Fygsoft and Microsoft, 2.0.0.0]
    [C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvrPS.dll]  [Nero AG, 2,0,13,0]
[PID: 2988 / sky][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\ftc\Filehook.dll]  [Fygsoft and Microsoft, 2.0.0.0]
[PID: 3576 / sky][C:\Program Files\QQ2006\QQ.EXE]  [TENCENT, 0, 0, 0, 0]
    [C:\Program Files\QQ2006\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 370]
    [C:\Program Files\QQ2006\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\Program Files\QQ2006\MSVCP60.dll]  [Microsoft Corporation, 6.02.3104.0]
    [C:\Program Files\QQ2006\PYKer.dll]  [飘云 http://www.pyqq.cn, 飘云]
    [C:\Program Files\QQ2006\ipsearcher.dll]  [, 1.0.0.3]
    [C:\ftc\Filehook.dll]  [Fygsoft and Microsoft, 2.0.0.0]
    [C:\Program Files\QQ2006\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\Program Files\QQ2006\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
gototop
 

[C:\Program Files\QQ2006\QQAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\Program Files\QQ2006\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [C:\Program Files\QQ2006\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [C:\Program Files\QQ2006\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQMainFrame.dll]  [N/A, ]
    [C:\Program Files\QQ2006\CQQApplication.dll]  [N/A, ]
    [C:\Program Files\QQ2006\NewSkin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\HostingMgr.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\CameraDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\MailSummary.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\Program Files\QQ2006\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\GroupLive.dll]  [N/A, ]
    [C:\Program Files\QQ2006\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQPlugin.dll]  [N/A, ]
    [C:\Program Files\QQ2006\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQAvatar.dll]  [N/A, ]
    [C:\Program Files\QQ2006\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\Program Files\QQ2006\QRingMng.dll]  [N/A, ]
    [C:\Program Files\QQ2006\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\QQ2006\VPortal.dll]  [, 1, 0, 0, 4]
    [C:\Program Files\QQ2006\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [C:\Program Files\QQ2006\QQAllInOne.dll]  [N/A, ]
    [C:\Program Files\QQ2006\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [C:\Program Files\QQ2006\QQCustomFace.dll]  [N/A, ]
    [C:\Program Files\QQ2006\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\QQ2006\BQQApplication.dll]  [N/A, ]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [F:\Nokia PC Suite 6\PhoneBrowser.dll]  [Nokia, 6, 81, 46, 1]
    [F:\Nokia PC Suite 6\PCSCM.dll]  [Nokia, 6, 81, 68, 0]
    [C:\WINDOWS\system32\ConnAPI.DLL]  [Nokia., 6, 81, 62, 0]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [F:\Nokia PC Suite 6\Lang\PhoneBrowser_chi-sc.nlr]  [Nokia, 6, 81, 29, 0]
    [F:\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr]  [Nokia, 6, 81, 11, 0]
    [C:\Program Files\QQ2006\QQSceneMng.dll]  [N/A, ]
    [C:\Program Files\QQ2006\CommercesMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [C:\Program Files\QQ2006\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 240]
    [C:\Program Files\QQ2006\GroupConnection.dll]  [Tencent, 0, 3, 3, 5]
    [C:\Program Files\QQ2006\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 9, 93]
    [C:\Program Files\QQ2006\QQSysMsgMng.dll]  [N/A, ]
    [C:\Program Files\QQ2006\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [C:\Program Files\QQ2006\QQMagicFace.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\Program Files\QQ2006\QQZip.dll]  [tencent, 0, 3, 2, 4]
[PID: 3604 / sky][C:\Program Files\QQ2006\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [C:\ftc\Filehook.dll]  [Fygsoft and Microsoft, 2.0.0.0]
    [C:\Program Files\QQ2006\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 3184 / sky][C:\Program Files\TT\TTraveler.exe]  [腾讯公司, 3, 3, 200, 290]
    [C:\ftc\Filehook.dll]  [Fygsoft and Microsoft, 2.0.0.0]
    [C:\Program Files\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll]  [腾讯公司, 1, 1, 0, 5]
    [C:\Program Files\TT\Plugins\TWeather\TWeather.dll]  [, 1, 0, 0, 3]
    [C:\Program Files\TT\TTNetFavor.dll]  [N/A, ]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
[PID: 2516 / sky][C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe]  [Thunder Networking Technologies,LTD, 5, 6, 7, 326]
    [C:\ftc\Filehook.dll]  [Fygsoft and Microsoft, 2.0.0.0]
    [C:\Program Files\Thunder Network\Thunder\Program\TaskManager.dll]  [Thunder Networking Technologies,LTD, 1, 1, 2, 26]
    [C:\Program Files\Thunder Network\Thunder\Program\download_interface.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 46]
    [C:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
    [C:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 46]
    [C:\Program Files\Thunder Network\Thunder\Program\BHOStub.dll]  [Thunder Networking Technologies,LTD, 1, 1, 0, 8]
    [C:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DownAndPlay.dll]  [, 1, 0, 0, 18]
    [C:\Program Files\Thunder Network\Thunder\Program\iTargetAD.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 28]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll]  [ , 1, 0, 0, 19]
    [C:\Program Files\Thunder Network\Thunder\Components\Community\XLCommunity.dll]  [Thunder Networking Technologies,LTD, 1, 2, 1, 36]
    [C:\Program Files\Thunder Network\Thunder\Components\Security\ThunderSafe.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 17]
    [C:\Program Files\Thunder Network\Thunder\Components\Search\XLSearch.dll]  [Thunder Networking Technologies,LTD, 1, 1, 4, 15]
    [C:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll]  [Thunder Networking Technologies,LTD, 2, 2, 2, 55]
gototop
 

[C:\Program Files\Thunder Network\Thunder\Program\LiveUpdate.dll]  [Thunder Networking Technologies,LTD, 1, 2, 1, 20]
    [C:\Program Files\Thunder Network\Thunder\Components\ExplorerHelper\ExplorerHelper.dll]  [Thunder Networking Technologies,LTD, 1, 0, 4, 15]
    [C:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VPSHELL.dll]  [XunLei, 1, 2, 0, 10]
    [C:\Program Files\Thunder Network\Thunder\Components\UserExperience\UserExperience.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsXlCom.dll]  [, 1, 0, 0, 16]
    [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed10.dll]  [ , 3, 3, 1, 83]
    [C:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 13, 4, 58]
    [C:\Program Files\Thunder Network\Thunder\Program\MSVCIRT.dll]  [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Thunder Network\Thunder\Program\XLNet.Dll]  [Thunder Networking Technologies,LTD, 1, 2, 0, 8]
    [C:\Program Files\Thunder Network\Thunder\Plugins\GouGouTop\GouGouTop.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
    [C:\Program Files\Thunder Network\Thunder\Plugins\BhoAdv\bho_adv.dll]  [深圳市迅雷网络技术有限公司, 1.0.1.0]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 3, 20]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 3, 11]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.2.9]
    [C:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VideoPicture.dll]  [XunLei, 1, 2, 0, 11]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_01.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\MediaWorker.dll]  [Thunder Networking Technologies,LTD, 1, 2, 0, 18]
[PID: 2336 / sky][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
    [C:\ftc\Filehook.dll]  [Fygsoft and Microsoft, 2.0.0.0]
    [F:\Nokia PC Suite 6\PhoneBrowser.dll]  [Nokia, 6, 81, 46, 1]
    [F:\Nokia PC Suite 6\PCSCM.dll]  [Nokia, 6, 81, 68, 0]
    [C:\WINDOWS\system32\ConnAPI.DLL]  [Nokia., 6, 81, 62, 0]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [F:\Nokia PC Suite 6\Lang\PhoneBrowser_chi-sc.nlr]  [Nokia, 6, 81, 29, 0]
    [F:\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr]  [Nokia, 6, 81, 11, 0]
    [C:\WINDOWS\system32\wpdshext.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[PID: 1684 / sky][C:\DOCUME~1\sky\LOCALS~1\Temp\Rar$EX01.593\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\ftc\Filehook.dll]  [Fygsoft and Microsoft, 2.0.0.0]
    [C:\DOCUME~1\sky\LOCALS~1\Temp\Rar$EX01.593\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A
gototop
 

HOSTS 文件
127.0.0.1      localhost
0.0.0.0 182838.com
0.0.0.0 204.177.92.68
0.0.0.0 asiafriendfinder.com
0.0.0.0 asqin123.51.net
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0 www.jpbeauty.com
0.0.0.0 beautishow.com
0.0.0.0 goodmovies88.com
0.0.0.0 hothack.home.chinaren.com
0.0.0.0 hualiao.net
0.0.0.0 iplus.allyes.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 asqin123.51.net
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
219.153.32.215 auto.search.msn.com

gototop
 

进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1320, C:\PROGRAM FILES\COMMON FILES\SOGOU PXP\P2PSVR.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 1320, C:\PROGRAM FILES\COMMON FILES\SOGOU PXP\P2PSVR.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 468, C:\FTC\TROJANWALL.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 468, C:\FTC\TROJANWALL.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 468, C:\FTC\TROJANWALL.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 3576, C:\PROGRAM FILES\QQ2006\QQ.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3576, C:\PROGRAM FILES\QQ2006\QQ.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3576, C:\PROGRAM FILES\QQ2006\QQ.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 3604, C:\PROGRAM FILES\QQ2006\TIMPLATFORM.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3604, C:\PROGRAM FILES\QQ2006\TIMPLATFORM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3604, C:\PROGRAM FILES\QQ2006\TIMPLATFORM.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 3184, C:\PROGRAM FILES\TT\TTRAVELER.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3184, C:\PROGRAM FILES\TT\TTRAVELER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3184, C:\PROGRAM FILES\TT\TTRAVELER.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 2516, C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\THUNDER5.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2516, C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\THUNDER5.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2516, C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\THUNDER5.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 2336, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2336, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2336, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
gototop
 

==================================
API HOOK
入口点错误:FreeLibrary (危险等级: 高,  被下面模块所HOOK: 0x5F00002D)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

==================================
API HOOK
入口点错误:FreeLibrary (危险等级: 高,  被下面模块所HOOK: 0x5F00002D)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

API HOOK
入口点错误:FreeLibrary (危险等级: 高,  被下面模块所HOOK: 0x5F00002D)

隐藏进程
N/A

[/CODE]
gototop
 

用KILLBOX删除下面文件(KILLBOX有勾选 删除前结束explorer.exe进程)
C:\WINDOWS\system32\IEBHO.dll
C:\WINDOWS\system32\IETool.dll

KILLBOX(enao.ys168.com 下载)
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT