正在运行的进程
[PID: 812 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 876 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 900 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 6.0.2.621]
[PID: 948 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 960 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1116 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1180 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1336 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1444 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1660 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1752 / JUJUMAO][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll] [Kaspersky Lab, 6.0.2.621]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\ShellEx.dll] [Kaspersky Lab, 6.0.2.621]
[D:\360safe\safemon\safemon.dll] [, 3, 6, 1, 1001]
[PID: 2004 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 380 / JUJUMAO][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3760]
[PID: 388 / JUJUMAO][C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe] [Nokia, 6, 84, 78, 3]
[C:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll] [Nokia, 6, 84, 100, 4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Nokia\Nokia PC Suite 6\PCSSupportSetup.DLL] [Nokia, 6, 84, 20, 3]
[C:\Program Files\PC Connectivity Solution\ConnAPI.DLL] [Nokia., 6, 84, 89, 1]
[C:\WINDOWS\system32\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\PC Connectivity Solution\ConfServer.dll] [Nokia, 6, 84, 37, 0]
[C:\Program Files\Nokia\Nokia PC Suite 6\Lang\LaunchApplication_chi-hk.NLR] [Nokia, 6, 84, 81, 2]
[PID: 528 / JUJUMAO][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 616 / SYSTEM][C:\APACHE\Apache.exe] [N/A, ]
[C:\APACHE\ApacheCore.dll] [N/A, ]
[C:\APACHE\Win9xConHook.dll] [N/A, ]
[PID: 680 / SYSTEM][d:\BlueSoleil\BTNtService.exe] [N/A, ]
[PID: 720 / SYSTEM][C:\APACHE\Apache.exe] [N/A, ]
[C:\APACHE\ApacheCore.dll] [N/A, ]
[C:\APACHE\Win9xConHook.dll] [N/A, ]
[PID: 1412 / SYSTEM][C:\WINDOWS\system32\UAService7.exe] [N/A, ]
[PID: 1472 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\windows\system32\wntprosup.dll] [Microsoft Corporation, 6.6.3791.1832]
[C:\WINDOWS\system32\msxml4.dll] [Microsoft Corporation, 4.20.9848.0]
[D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll] [Kaspersky Lab, 6.0.2.621]
[d:\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\scrchpg.dll] [Kaspersky Lab, 5.0.1.18]
[d:\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\scrch_ag.dll] [Kaspersky Lab, 5.0.388.1]
[d:\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\FSSync.dll] [Kaspersky Lab, 5.0.388.0]
[d:\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\pr_rmt.dll] [Kaspersky Lab, 5.0.388.0]
[d:\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\ccclient.dll] [Kaspersky Lab, 5.0.388.1]
[d:\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\klipc.dll] [Kaspersky Lab, 5.0.388.0]
[d:\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\KLUtil.dll] [Kaspersky Lab, 5.0.388.1]
[d:\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\rpt.dll] [Kaspersky Lab, 5.0.388.2]
[d:\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\CCIFACE.dll] [Kaspersky Lab, 5.0.388.1]
[d:\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\prloader.dll] [Kaspersky Lab, 5.0.388.0]
[d:\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\prkernel.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\kaspersky lab\kaspersky anti-virus personal pro\prstring.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\kaspersky lab\kaspersky anti-virus personal pro\pr_srv.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\kaspersky lab\kaspersky anti-virus personal pro\pr_clnt.ppl] [Kaspersky Lab, 5.0.388.0]
[PID: 1700 / SYSTEM][C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe] [Symantec Corporation, 3.2.0.41]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 476 / SYSTEM][C:\Program Files\PC Connectivity Solution\ServiceLayer.exe] [Nokia., 6, 84, 83, 3]
[C:\Program Files\PC Connectivity Solution\NclTools.dll] [Nokia, 6, 84, 33, 0]
[C:\Program Files\PC Connectivity Solution\Transports\NCLIrDAMM.dll] [Nokia Corp., 6, 84, 33, 0]
[C:\Program Files\PC Connectivity Solution\Transports\NCLRSMM.dll] [Nokia Corp., 6, 84, 41, 0]
[C:\Program Files\PC Connectivity Solution\Transports\NCLUSBMM.dll] [Nokia Corp., 6, 84, 55, 1]
[C:\Program Files\PC Connectivity Solution\Transports\NclIVTBTMM.dll] [Nokia, 6, 84, 37, 1]
[C:\WINDOWS\system32\btfunc.dll] [IVT Corporation, 1, 2, 0, 0]
[C:\Program Files\PC Connectivity Solution\Transports\NclMSBTMM.dll] [Nokia Corp., 6, 84, 55, 0]
[PID: 2144 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2892 / SYSTEM][d:\BlueSoleil\BlueSoleil.exe] [IVT Corporation, 1, 6, 1, 4]
[d:\BlueSoleil\btpcfg.dll] [IVT Corporation, 1, 6, 1, 0]
[d:\BlueSoleil\setup.dll] [IVT Corporation, 1, 4, 9, 4]
[d:\BlueSoleil\btwin.dll] [, 1, 1, 0, 0]
[d:\BlueSoleil\versit.dll] [Versit Consortium (Apple Computer, AT&T, IBM and Siemens), 1, 0, 0, 1]
[d:\BlueSoleil\hcicmd.dll] [N/A, ]
[d:\BlueSoleil\btpres.dll] [IVT Corporation, 1, 6, 2, 0]
[d:\BlueSoleil\Driver\USB\btcusb.dll] [IVT Corporation, 1, 2, 1, 0]
[C:\WINDOWS\system32\l3codeca.ax] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[C:\WINDOWS\system32\tssoft32.acm] [DSP GROUP, INC., 1.01]
[C:\WINDOWS\system32\tsd32.dll] [, ]
[C:\WINDOWS\system32\sl_anet.acm] [Sipro Lab Telecom Inc., 3.02]
[C:\WINDOWS\system32\iac25_32.ax] [Intel Corporation, 2.05.53]
[PID: 696 / JUJUMAO][D:\11111\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[D:\11111\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 900, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 680, D:\BLUESOLEIL\BTNTSERVICE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1412, C:\WINDOWS\SYSTEM32\UASERVICE7.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 1412, C:\WINDOWS\SYSTEM32\UASERVICE7.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 476, C:\PROGRAM FILES\PC CONNECTIVITY SOLUTION\SERVICELAYER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2892, D:\BLUESOLEIL\BLUESOLEIL.EXE]
==================================
API HOOK
RVA 错误: LoadLibraryA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: LoadLibraryExA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: LoadLibraryW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
==================================
隐藏进程
N/A
==================================