[C:\WINDOWS\system32\NvMcTray.dll] [NVIDIA Corporation, 6.14.11.5827]
[C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.5827]
[C:\KAV2007\KMailOEBand.DLL] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.11.5827]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2007, 3, 18, 241]
[PID: 1952 / Administrator][C:\WINDOWS\VM_STI.EXE] [Vimicro, 4, 2, 1124, 6]
[C:\KAV2007\KMailOEBand.DLL] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2007, 3, 18, 241]
[PID: 1964 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\KAV2007\KMailOEBand.DLL] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2007, 3, 18, 241]
[PID: 196 / Administrator][C:\KAV2007\KMailMon.EXE] [Kingsoft Corporation, 2007, 8, 16, 967]
[C:\KAV2007\KAntiSpm.dll] [Kingsoft Corporation, 2007, 2, 25, 129]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KAVIPC2.DLL] [Kingsoft Corporation, 2007, 1, 15, 30]
[C:\KAV2007\KAECall2.DLL] [Kingsoft Corporation, 2004, 12, 28, 7]
[C:\KAV2007\KAEPlat.DLL] [Kingsoft Corp., 2007, 6, 19, 64]
[C:\KAV2007\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\KAV2007\KAEUnpack.DAT] [Kingsoft Corporation, 2007,10,16,148]
[C:\KAV2007\KMailOEBand.DLL] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\KAV2007\KAConfig.DLL] [Kingsoft Corporation, 2007, 1, 11, 41]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2007, 3, 18, 241]
[PID: 208 / Administrator][C:\KAV2007\KPFW32.EXE] [Kingsoft Corporation, 2007, 8, 17, 726]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KMailOEBand.DLL] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2007, 3, 18, 241]
[C:\KAV2007\KAVIPC2.DLL] [Kingsoft Corporation, 2007, 1, 15, 30]
[C:\KAV2007\KAConfig.DLL] [Kingsoft Corporation, 2007, 1, 11, 41]
[C:\KAV2007\FiltList.dll] [N/A, ]
[C:\KAV2007\KAVPassp.DLL] [Kingsoft Corporation, 2006, 12, 30, 271]
[C:\KAV2007\KAScript.DLL] [Kingsoft Corporation, 2007, 3, 6, 75]
[PID: 696 / SYSTEM][C:\KAV2007\KPfwSvc.EXE] [Kingsoft Corporation, 2007, 8, 17, 39]
[PID: 116 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.11.5827]
[C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.5827]
[PID: 1068 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2056 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3644 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\KAV2007\KMailOEBand.DLL] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2007, 3, 18, 241]
[C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.16]
[c:\PROGRA~1\chinanet\VNETTR~1.DLL] [, 2004, 2, 21, 1]
[c:\PROGRA~1\chinanet\Communicate.dll] [0, 2005, 3, 3, 1]
[C:\PROGRA~1\ChinaNet\CLIENT~1.DLL] [, 2004, 2, 28, 1]
[C:\KAV2007\KAVAFish.DLL] [Kingsoft Corporation, 2006, 10, 25, 27]
[C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 44]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 12]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 13]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\KAV2007\KAScript.DLL] [Kingsoft Corporation, 2007, 3, 6, 75]
[C:\KAV2007\KAEPlat.DLL] [Kingsoft Corp., 2007, 6, 19, 64]
[C:\KAV2007\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\KAV2007\KAEUnpack.DAT] [Kingsoft Corporation, 2007,10,16,148]
[C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.8164]
[C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[PID: 3912 / Administrator][F:\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\KAV2007\KMailOEBand.DLL] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2007, 3, 18, 241]
[F:\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 www.130sf.com
127.0.0.1 idc.130sf.com
127.0.0.1 www.17ez.com
127.0.0.1 www.7j4f.com
127.0.0.1 www.350w.com
127.0.0.1 www.921ok.com
127.0.0.1 www.123ggg.com
127.0.0.1 www.444mu.com
127.0.0.1 www.31mu.com
127.0.0.1 www.85mu.com
127.0.0.1 www.690mu.com
127.0.0.1 www.500mu.com
127.0.0.1 www.34mu.com
127.0.0.1 www.770mu.com
127.0.0.1 www.590mu.com
127.0.0.1 www.260mu.com
127.0.0.1 www.650mu.com
127.0.0.1 www.190mu.com
127.0.0.1 www.590mu.com
127.0.0.1 www.270mu.com
127.0.0.1 www.290mu.com
127.0.0.1 www.65mu.com
127.0.0.1 www.83mu.com
127.0.0.1 www.81mu.com
127.0.0.1 www.855mu.com
127.0.0.1 www.mu175.com
127.0.0.1 www.150mu.com
127.0.0.1 www.87mu.com
127.0.0.1 www.111mu.com
127.0.0.1 www.mu180.com
127.0.0.1 www.180mu.com
127.0.0.1 www.700mu.com
127.0.0.1 bd.700mu.com
127.0.0.1 bd.31mu.com
127.0.0.1 bbs.130sf.com
127.0.0.1 www.06mu.com
127.0.0.1 www.895mu.com
127.0.0.1 www.200mu.com
127.0.0.1 bd.200mu.com
127.0.0.1 www.710mu.com
127.0.0.1 www.899mu.com
127.0.0.1 mu.899mu.com
127.0.0.1 www.fytmu.com
127.0.0.1 zx1.17ez.net
127.0.0.1 www.17pkmu.com
127.0.0.1 www.400mu.com
127.0.0.1 www.290mu.com
127.0.0.1 www.622mu.cn
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1824, C:\KAV2007\KAVSTART.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 196, C:\KAV2007\KMAILMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 196, C:\KAV2007\KMAILMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 208, C:\KAV2007\KPFW32.EXE]
==================================
API HOOK
入口点错误:LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: C:\KAV2007\KASocket.dll)
==================================
隐藏进程
N/A
==================================
[/CODE]