==================================
正在运行的进程
[PID: 664][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 732][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 756][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jelpjalp.dll] [N/A, ]
[C:\WINDOWS\system32\medeffkb.dll] [N/A, ]
[C:\WINDOWS\system32\BFD5A1ED.dll] [N/A, ]
[C:\WINDOWS\system32\iipnaaha.dll] [N/A, ]
[C:\WINDOWS\system32\nljbgicf.dll] [N/A, ]
[C:\WINDOWS\system32\8C7118DF.dll] [N/A, ]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 804][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\AppPatch\AcAdProc.dll] [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[C:\WINDOWS\system32\jelpjalp.dll] [N/A, ]
[C:\WINDOWS\system32\medeffkb.dll] [N/A, ]
[C:\WINDOWS\system32\BFD5A1ED.dll] [N/A, ]
[C:\WINDOWS\system32\iipnaaha.dll] [N/A, ]
[C:\WINDOWS\system32\nljbgicf.dll] [N/A, ]
[C:\WINDOWS\system32\8C7118DF.dll] [N/A, ]
[PID: 816][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jelpjalp.dll] [N/A, ]
[C:\WINDOWS\system32\medeffkb.dll] [N/A, ]
[C:\WINDOWS\system32\BFD5A1ED.dll] [N/A, ]
[C:\WINDOWS\system32\iipnaaha.dll] [N/A, ]
[C:\WINDOWS\system32\nljbgicf.dll] [N/A, ]
[C:\WINDOWS\system32\8C7118DF.dll] [N/A, ]
[PID: 1052][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\jelpjalp.dll] [N/A, ]
[C:\WINDOWS\System32\medeffkb.dll] [N/A, ]
[C:\WINDOWS\System32\BFD5A1ED.dll] [N/A, ]
[C:\WINDOWS\System32\iipnaaha.dll] [N/A, ]
[C:\WINDOWS\System32\nljbgicf.dll] [N/A, ]
[C:\WINDOWS\System32\8C7118DF.dll] [N/A, ]
[PID: 1092][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jelpjalp.dll] [N/A, ]
[C:\WINDOWS\system32\medeffkb.dll] [N/A, ]
[C:\WINDOWS\system32\BFD5A1ED.dll] [N/A, ]
[C:\WINDOWS\system32\iipnaaha.dll] [N/A, ]
[C:\WINDOWS\system32\nljbgicf.dll] [N/A, ]
[C:\WINDOWS\system32\8C7118DF.dll] [N/A, ]
[PID: 1252][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jelpjalp.dll] [N/A, ]
[C:\WINDOWS\system32\medeffkb.dll] [N/A, ]
[C:\WINDOWS\system32\BFD5A1ED.dll] [N/A, ]
[C:\WINDOWS\system32\iipnaaha.dll] [N/A, ]
[C:\WINDOWS\system32\nljbgicf.dll] [N/A, ]
[C:\WINDOWS\system32\8C7118DF.dll] [N/A, ]
[PID: 1328][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jelpjalp.dll] [N/A, ]
[C:\WINDOWS\system32\medeffkb.dll] [N/A, ]
[C:\WINDOWS\system32\BFD5A1ED.dll] [N/A, ]
[C:\WINDOWS\system32\iipnaaha.dll] [N/A, ]
[C:\WINDOWS\system32\nljbgicf.dll] [N/A, ]
[C:\WINDOWS\system32\8C7118DF.dll] [N/A, ]
[PID: 1496][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.9136]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1932][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jelpjalp.dll] [N/A, ]
[C:\WINDOWS\system32\medeffkb.dll] [N/A, ]
[C:\WINDOWS\system32\BFD5A1ED.dll] [N/A, ]
[C:\WINDOWS\system32\iipnaaha.dll] [N/A, ]
[C:\WINDOWS\system32\nljbgicf.dll] [N/A, ]
[C:\WINDOWS\system32\8C7118DF.dll] [N/A, ]
[D:\Program Files\Nokia\Nokia PC Suite 7\phonebrowser.dll] [Nokia, 7, 0, 103, 0]
[D:\Program Files\Nokia\Nokia PC Suite 7\NGSCM.DLL] [Nokia, 7, 0, 140, 6]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762]
[D:\Program Files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_chi-sc.nlr] [Nokia, 7, 0, 64, 0]
[D:\Program Files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr] [Nokia, 7, 0, 20, 0]
[D:\Program Files\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1004]
[C:\WINDOWS\system32\browselc.dll] [Microsoft Corporation, 6.00.2600.0000]
[C:\Program Files\PC Connectivity Solution\ConnAPI.dll] [Nokia., 7, 0, 13, 0]
[C:\Program Files\PC Connectivity Solution\DAAPI.dll] [Nokia, 7, 0, 15, 0]
[C:\Program Files\PC Connectivity Solution\PCCS_DBAPI.DLL] [Nokia, 7, 0, 1, 0]
[C:\Program Files\PC Connectivity Solution\VersitConverter.dll] [Nokia, 7, 0, 9, 0]
[C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll] [Nero AG, 2, 0, 0, 8]
[C:\Program Files\Common Files\Ahead\Lib\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Common Files\Ahead\Lib\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Common Files\Ahead\Lib\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll] [Nero AG, 2, 9, 1, 0]
[C:\Program Files\Nero\Nero 7\Nero BackItUp\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12]
[C:\WINDOWS\system32\YouKuDesktopShell.dll] [
www.youku.com, 1.2.7.1700]
[C:\Program Files\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll] [Nero AG, 2, 9, 1, 0]
[C:\WINDOWS\system32\nvshell.dll] [, ]
[PID: 2004][C:\WINDOWS\system32\conime.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\medeffkb.dll] [N/A, ]
[C:\WINDOWS\system32\jelpjalp.dll] [N/A, ]
[C:\WINDOWS\system32\BFD5A1ED.dll] [N/A, ]
[C:\WINDOWS\system32\iipnaaha.dll] [N/A, ]
[C:\WINDOWS\system32\nljbgicf.dll] [N/A, ]
[C:\WINDOWS\system32\8C7118DF.dll] [N/A, ]
[PID: 2028][C:\WINDOWS\system32\cmd.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jelpjalp.dll] [N/A, ]
[C:\WINDOWS\system32\medeffkb.dll] [N/A, ]
[C:\WINDOWS\system32\BFD5A1ED.dll] [N/A, ]
[C:\WINDOWS\system32\iipnaaha.dll] [N/A, ]
[C:\WINDOWS\system32\nljbgicf.dll] [N/A, ]
[C:\WINDOWS\system32\8C7118DF.dll] [N/A, ]
[PID: 1444][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jelpjalp.dll] [N/A, ]
[C:\WINDOWS\system32\medeffkb.dll] [N/A, ]
[C:\WINDOWS\system32\BFD5A1ED.dll] [N/A, ]
[C:\WINDOWS\system32\iipnaaha.dll] [N/A, ]
[C:\WINDOWS\system32\nljbgicf.dll] [N/A, ]
[C:\WINDOWS\system32\8C7118DF.dll] [N/A, ]
[PID: 1456][D:\Program Files\DAEMON Tools Lite\daemon.exe] [DT Soft Ltd, 4.30.1.0]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\8C7118DF.dll] [N/A, ]
[C:\WINDOWS\system32\nljbgicf.dll] [N/A, ]
[C:\WINDOWS\system32\iipnaaha.dll] [N/A, ]
[C:\WINDOWS\system32\BFD5A1ED.dll] [N/A, ]
[C:\WINDOWS\system32\medeffkb.dll] [N/A, ]
[C:\WINDOWS\system32\jelpjalp.dll] [N/A, ]
[D:\Program Files\DAEMON Tools Lite\DaemonPlugin.dll] [DT Soft Ltd, 4.12.0.0]
[D:\Program Files\DAEMON Tools Lite\daemon.dll] [DT Soft Ltd., 4.30.0.0]
[D:\Program Files\DAEMON Tools Lite\imgengine.dll] [DT Soft Ltd., 1.17.0.0]
[D:\Program Files\DAEMON Tools Lite\Lang\CHS.dll] [N/A, ]
[D:\Program Files\DAEMON Tools Lite\Lang\ENU.dll] [N/A, ]
[D:\Program Files\DAEMON Tools Lite\Plugins\ISOmaker.dll] [DT Soft Ltd, 1.0.0.0]
[D:\Program Files\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1004]
[PID: 1464][C:\Program Files\PPStream\ppsap.exe] [PPStream Inc, 1, 0, 11, 139]
[C:\WINDOWS\system32\jelpjalp.dll] [N/A, ]
[C:\WINDOWS\system32\medeffkb.dll] [N/A, ]
[C:\WINDOWS\system32\BFD5A1ED.dll] [N/A, ]
[C:\WINDOWS\system32\iipnaaha.dll] [N/A, ]
[C:\WINDOWS\system32\nljbgicf.dll] [N/A, ]
[C:\WINDOWS\system32\8C7118DF.dll] [N/A, ]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[d:\Program Files\PPStream\1.1.0.2640\vodnet.dll] [PPStream Inc., 1, 0, 11, 179]
[d:\Program Files\PPStream\1.1.0.2640\vodres.dll] [PPStream Inc., 1, 0, 11, 179]
[d:\Program Files\PPStream\1.1.0.2640\ppssg.dll] [PPStream Inc., 1, 0, 11, 179]
[d:\Program Files\PPStream\1.1.0.2640\fds.dll] [PPStream Inc., 1, 0, 0, 98]
[PID: 808][C:\Documents and Settings\Administrator\桌面\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210]
[C:\WINDOWS\system32\8C7118DF.dll] [N/A, ]
[C:\WINDOWS\system32\nljbgicf.dll] [N/A, ]
[C:\WINDOWS\system32\iipnaaha.dll] [N/A, ]
[C:\WINDOWS\system32\BFD5A1ED.dll] [N/A, ]
[C:\WINDOWS\system32\medeffkb.dll] [N/A, ]
[C:\WINDOWS\system32\jelpjalp.dll] [N/A, ]
[PID: 1760][C:\Documents and Settings\Administrator\桌面\SRE9b4eb966.EXE] [Smallfrogs Studio, 2.7.0.1210]
[C:\WINDOWS\system32\8C7118DF.dll] [N/A, ]
[C:\WINDOWS\system32\nljbgicf.dll] [N/A, ]
[C:\WINDOWS\system32\iipnaaha.dll] [N/A, ]
[C:\WINDOWS\system32\BFD5A1ED.dll] [N/A, ]
[C:\WINDOWS\system32\medeffkb.dll] [N/A, ]
[C:\WINDOWS\system32\jelpjalp.dll] [N/A, ]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1004]
[C:\Documents and Settings\Administrator\桌面\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 756, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 808, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\SRENGLDR.EXE]
==================================
计划任务
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================