==================================
正在运行的进程
[PID: 588 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 656 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 680 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 724 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\AppPatch\AcAdProc.dll] [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[PID: 736 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 876 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 972 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1092 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1144 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1248 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1456 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1676 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
[D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
[C:\WINDOWS\system32\WPDShServiceObj.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\PortableDeviceTypes.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[D:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.5.2005092300]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 1800 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1896 / SYSTEM][C:\WINDOWS\system32\BoBoTurbo\BoBoTurbo.exe] [广州易播信息科技有限公司, 1, 4, 1011, 2]
[PID: 1956 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.9136]
[PID: 168 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]
[PID: 368 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1220 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 728 / Administrator][F:\2008传美\qq\QQ.exe] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQBaseClassInDll.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQHelperDll.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\BasicCtrlDll.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[F:\2008传美\qq\MSIMG32.dll] [N/A, ]
[D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
[F:\2008传美\qq\FinePlus.dll] [N/A, ]
[F:\2008传美\qq\fphelper.dll] [N/A, ]
[F:\2008传美\qq\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[F:\2008传美\qq\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[F:\2008传美\qq\QQAPI.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\LoginCtrl.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\LoginCtrlRes.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQRes.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQMainFrame.dll] [N/A, ]
[F:\2008传美\qq\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[F:\2008传美\qq\QQPlugin.dll] [N/A, ]
[F:\2008传美\qq\UnReadMsgMgr.dll] [N/A, ]
[F:\2008传美\qq\CQQApplication.dll] [N/A, ]
[F:\2008传美\qq\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[F:\2008传美\qq\NewSkin.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\MailSummary.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQSpace.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\vbscript.dll] [N/A, ]
[F:\2008传美\qq\encode.dll] [Microsoft Corporation, 5.6.0.8825]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[F:\2008传美\qq\QQKnowledgeSearch.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\OEMApplication.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQGroupMng.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQAvatar.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[F:\2008传美\qq\QQAllInOne.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\SCCore.dll] [TENCENT, 1, 6, 0, 2]
[F:\2008传美\qq\CameraDll.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQPet.dll] [TENCENT, 8,0,776,1805]
[C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[F:\2008传美\qq\QRingMng.dll] [N/A, ]
[F:\2008传美\qq\QQSysMsgMng.dll] [N/A, ]
[F:\2008传美\qq\UserDefinedHead.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQConfigPlugin.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQCustomFace.dll] [N/A, ]
[F:\2008传美\qq\LongConnection.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQFileTransfer.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\PersonalDesktop.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\BQQApplication.dll] [N/A, ]
[F:\2008传美\qq\CommercesMng.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 330]
[F:\2008传美\qq\QQSceneMng.dll] [N/A, ]
[F:\2008传美\qq\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 0, 1, 10]
[PID: 1620 / Administrator][E:\Program Files\Tencent\qq\TXPlatform.exe] [Tencent, 1, 0, 170, 0]
[D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
[PID: 3684 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
[F:\旋窝\QQIEHelper02.dll] [腾讯公司, 1, 1, 0, 5]
[C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
[C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.0.4]
[D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.5.2005092300]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx] [Adobe Systems, Inc., 9,0,115,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1532 / Administrator][F:\旋窝\QQDownload.exe] [Tencent Technology (Shenzhen) Company Limited, 1, 8, 194, 194]
[D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
[F:\旋窝\xmain.dll] [Tencent Technology (Shenzhen) Company Limited, 1, 8, 194, 194]
[F:\旋窝\xcore.dll] [Tencent Technology(Shenzhen) Company Limited, 2, 1, 101, 90]
[C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2984 / Administrator][C:\Program Files\WinRAR\WinRAR.exe] [N/A, ]
[D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
[C:\WINDOWS\system32\wpdshext.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[PID: 3264 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.078\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.078\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 yu.8s7.net
127.0.0.1 1.jopanqc.com
127.0.0.1 2.joppnqq.com
127.0.0.1 wg.47255.com
127.0.0.1 1.joppnqq.com
127.0.0.1 xxx.m111.biz
127.0.0.1 1.jopenqc.com
127.0.0.1 1.jopenkk.com
127.0.0.1 xxx.vh7.biz
127.0.0.1 xxx.j41m.com
127.0.0.1 3.joppnqq.com
127.0.0.1 d.93se.com
127.0.0.1
www.868wg.com127.0.0.1 xxx.mmma.biz
127.0.0.1 ilove.com
127.0.0.1 tp.shpzhan.cn
127.0.0.1
www.tomwg.com127.0.0.1
www.cike007.cn127.0.0.1
www.22aaa.com127.0.0.1 xx.exiao01.com
127.0.0.1
www.exiao01.com127.0.0.1
www.exiao01.com127.0.0.1 new.749571.com
127.0.0.1 xtx.kv8.info
127.0.0.1 cao.kv8.info
127.0.0.1 1.jopmmqq.com
127.0.0.1 171817.171817.com
127.0.0.1 d2.llsging.com
127.0.0.1 down.malasc.cn
127.0.0.1 llboss.com
127.0.0.1 nx.51ylb.cn
127.0.0.1 my.531jx.cn
127.0.0.1 qqq.dzydhx.com
127.0.0.1 qqq.hao1658.com
127.0.0.1
www.333292.com127.0.0.1 down.18dd.net
127.0.0.1 up.22x44.com
127.0.0.1 aaa.faba01.com
127.0.0.1 bad.tqdlt.cn
127.0.0.1 1.chsipo.com
127.0.0.1 c3.aishangai.net
127.0.0.1 c2.aishangai.net
127.0.0.1 xxx.188dm.com
127.0.0.1 x2.1a2b3c1.com
127.0.0.1 d1.163500.net
127.0.0.1 down.google-serv.cn
127.0.0.1 idc.windowsupdeta.cn
127.0.0.1 nc.mskess.com
127.0.0.1 ok.sl8cjs.cn
127.0.0.1 dl.pvs360.com
127.0.0.1 ta.pvs360.com
127.0.0.1 cw.pvs360.com
127.0.0.1 fg.pvs360.com
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 2984, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]