[D:\Program Files\Tencent\QQ\MSIMG32.dll] [N/A, ]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[f:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[f:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[D:\Program Files\CaihongIP\CaiHong.dll] [N/A, ]
[D:\Program Files\CaihongIP\Reporter.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[D:\Program Files\Tencent\QQ\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[D:\Program Files\Tencent\QQ\QQAPI.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\LoginCtrl.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\LoginCtrlRes.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\QQRes.dll] [TENCENT, 8,0,978,1833]
[D:\Program Files\Tencent\QQ\QQMainFrame.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\Tencent\QQ\UnReadMsgMgr.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\QQAllInOne.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\SCCore.dll] [TENCENT, 1, 6, 0, 2]
[D:\Program Files\Tencent\QQ\CameraDll.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\CQQApplication.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\FlashAvatarDll.dll] [, 1, 0, 0, 1]
[D:\Program Files\Tencent\QQ\NewSkin.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\MailSummary.dll] [TENCENT, 8,0,1234,1851]
[D:\Program Files\Tencent\QQ\vbscript.dll] [Microsoft Corporation, 5.6.0.7426]
[D:\Program Files\Tencent\QQ\QQSpace.dll] [TENCENT, 8,0,1249,1853]
[C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[D:\Program Files\Tencent\QQ\QQAvatar.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\OEMApplication.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\QQKnowledgeSearch.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\QQGroupMng.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\QQPlugin.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\QQPet.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\QRingMng.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\LongConnection.dll] [TENCENT, 8,0,1249,1851]
[D:\Program Files\Tencent\QQ\UserDefinedHead.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\QQConfigPlugin.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\QQCustomFace.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\PhoneAPI.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[D:\Program Files\Tencent\QQ\BQQApplication.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\CommercesMng.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\PersonalDesktop.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 330]
[D:\Program Files\Tencent\QQ\QQSceneMng.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 0, 1, 10]
[D:\Program Files\Tencent\QQ\QQSysMsgMng.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\QQMagicFace.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\ImageOle.dll] [TENCENT, 8,0,1249,1853]
[C:\Documents and Settings\Administrator\桌面\歌曲\12\jscript.dll] [Microsoft Corporation, 5.6.0.8831]
[D:\Program Files\Tencent\QQ\QQLiveQMng.dll] [TENCENT, 8,0,1249,1853]
[D:\Program Files\Tencent\QQ\GroupConnection.dll] [TENCENT, 8,0,1249,1851]
[C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.5510]
[D:\Program Files\Tencent\QQ\QQSettingCtrl.dll] [TENCENT, ]
[C:\WINDOWS\system32\freeime.ime] [极点五笔工作室, 6.2.2.0]
[D:\Program Files\Tencent\QQ\QQFileTransfer.dll] [TENCENT, 8,0,1249,1851]
[PID: 2952][d:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 5, 225, 0]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33]
[f:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[f:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[PID: 2480][C:\WINDOWS\system32\wbem\wmiprvse.exe] [(Verified) Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\WINDOWS\system32\msvcp60.dll] [Microsoft Corporation, 6.00.8972.0]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33]
[f:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[f:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[PID: 752][F:\Xunlei\Maxthonyh\Maxthon2.0\Maxthon.exe] [Maxthon International Ltd., 1, 6, 3, 80]
[F:\Xunlei\Maxthonyh\Maxthon2.0\maxzlib.dll] [ , 1, 0, 0, 2]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33]
[f:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[f:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[F:\Xunlei\Maxthonyh\Maxthon2.0\Plugin\MoreOptions\MoreOptions.dll] [abc, 1.00]
[C:\WINDOWS\system32\VB6CHS.DLL] [Microsoft Corporation, 6.00.8988]
[C:\PROGRA~1\COMMON~1\System\MSSearch\Bin\msscntrs.dll] [Microsoft Corporation, 9.107.8320.0]
[C:\PROGRA~1\MICROS~1\MSSQL$U8\BINN\SQLCTR80.DLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~1\MSSQL\BINN\SQLCTR80.DLL] [Microsoft Corporation, 2000.080.0534.00]
[C:\WINDOWS\System32\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[C:\Documents and Settings\Administrator\桌面\歌曲\12\jscript.dll] [Microsoft Corporation, 5.6.0.8831]
[F:\Xunlei\Maxthonyh\Maxthon2.0\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\freeime.ime] [极点五笔工作室, 6.2.2.0]
[C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96]
[PID: 3976][C:\WINDOWS\system32\dllhost.exe] [(Verified) Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33]
[f:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[f:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[PID: 3620][C:\Documents and Settings\Administrator\桌面\DataUploader.exe] [, 1, 0, 1, 10]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33]
[f:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[f:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 888][C:\WINDOWS\system32\wbem\wmiprvse.exe] [(Verified) Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\WINDOWS\system32\msvcp60.dll] [Microsoft Corporation, 6.00.8972.0]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33]
[f:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[f:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[PID: 2880][C:\Program Files\Kingsoft\KAC\Service\kaccore.exe] [Kingsoft Corporation, 2008,10,20,303]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33]
[f:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[f:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[C:\Program Files\Kingsoft\KAC\Service\corehelper.dll] [Kingsoft Corporation, 2008,10,20,303]
[PID: 4012][C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5.7.9.466]
[C:\Program Files\Thunder Network\Thunder\Program\BugReport.dll] [Thunder Networking Technologies,LTD, 1, 2, 0, 15]
[C:\WINDOWS\system32\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33]
[f:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[f:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[C:\Program Files\Thunder Network\Thunder\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 3, 4, 62]
[C:\Program Files\Thunder Network\Thunder\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 3, 0, 2, 307]
[C:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031]
[C:\Program Files\Thunder Network\Thunder\Program\asyn_frame.dll] [, 1, 0, 2, 7]
[C:\Program Files\Thunder Network\Thunder\Program\backend_agent.dll] [, 1, 0, 2, 11]
[C:\Program Files\Thunder Network\Thunder\Program\ptl.dll] [Thunder Networking Technologies, LTD, 1, 0, 2, 12]
[C:\Program Files\Thunder Network\Thunder\Program\p2p_upload.dll] [, 1, 0, 2, 7]
[C:\Program Files\Thunder Network\Thunder\Program\fs.dll] [, 1, 0, 2, 7]
[C:\Program Files\Thunder Network\Thunder\Program\p2p.dll] [, 1, 0, 2, 12]
[C:\Program Files\Thunder Network\Thunder\Program\p2p_local_res.dll] [, 1, 0, 2, 7]
[C:\Program Files\Thunder Network\Thunder\Program\p2sp.dll] [, 1, 0, 2, 13]
[C:\Program Files\Thunder Network\Thunder\Program\down_dispatcher.dll] [, 1, 0, 2, 12]
[C:\Program Files\Thunder Network\Thunder\Program\xldc.dll] [Thunder Networking Technologies,LTD, 1, 5, 2, 9]
[C:\Program Files\Thunder Network\Thunder\Program\bd.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 16]
[C:\Program Files\Thunder Network\Thunder\Program\stream.dll] [, 2, 0, 2, 308]
[C:\Program Files\Thunder Network\Thunder\Program\al.dll] [, 1, 1, 2, 9]
[C:\Program Files\Thunder Network\Thunder\Program\emule_id.dll] [, 1, 0, 2, 6]
[C:\Program Files\Thunder Network\Thunder\Program\emule.dll] [, 1, 0, 2, 7]
[C:\Program Files\Thunder Network\Thunder\Program\XLNet.Dll] [Thunder Networking Technologies,LTD, 1, 4, 5, 21]
[C:\Program Files\Thunder Network\Thunder\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 1, 1, 10]
[C:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DownAndPlay.dll] [, 1, 0, 11, 29]
[C:\Program Files\Thunder Network\Thunder\Program\iTargetAD.dll] [Thunder Networking Technologies,LTD, 1, 0, 3, 34]
[f:\Program Files\Kingsoft\Kingsoft Internet Security\Flash.OCX] [Adobe Systems, Inc., 9,0,124,0]
[C:\Documents and Settings\Administrator\桌面\歌曲\12\jscript.dll] [Microsoft Corporation, 5.6.0.8831]
[C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll] [ , 1, 0, 2, 24]
[C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed16.dll] [Thunder Networking Technologies,LTD, 3, 4, 7, 103]
[C:\Program Files\Thunder Network\Thunder\Components\InMedia\PlayerHelper.dll] [thunder, 1, 1, 5, 41]
[C:\Program Files\Thunder Network\Thunder\Components\InMedia\XLIPC.DLL] [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
[C:\Program Files\Thunder Network\Thunder\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 1, 5, 0, 16]
[C:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 17, 0, 67]
[C:\Program Files\Thunder Network\Thunder\Program\MSVCIRT.dll] [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Thunder Network\Thunder\Components\Security\ThunderSafe.dll] [深圳市迅雷网络技术有限公司, 1, 0, 7, 77]
[C:\Program Files\Thunder Network\Thunder\Program\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Thunder Network\Thunder\Components\Security\XLSafeUI.dll] [深圳市迅雷网络技术有限公司, 1, 0, 7, 77]
[C:\Program Files\Thunder Network\Thunder\Program\LiveUpdate.dll] [Thunder Networking Technologies,LTD, 1, 2, 3, 25]
[C:\Program Files\Thunder Network\Thunder\Plugins\KanKanTop\KanKanTop.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 4]
[C:\Program Files\Thunder Network\Thunder\Components\ExplorerHelper\ExplorerHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 18]
[C:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VPSHELL.dll] [迅雷网络, 3, 0, 1, 33]
[C:\Program Files\Thunder Network\Thunder\Components\UserExperience\UserExperience.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 3]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsXlCom.dll] [, 1, 0, 0, 29]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\MediaWorker.dll] [Thunder Networking Technologies,LTD, 1, 2, 0, 22]
[C:\Program Files\Thunder Network\Thunder\Components\DownloadStat\DownloadStat.dll] [Thunder Networking Technologies,LTD, 1, 4, 1, 6]
[PID: 3096][C:\Documents and Settings\Administrator\桌面\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210]
[PID: 3180][C:\Documents and Settings\Administrator\桌面\sreng2\SRE5cd9d1f6.EXE] [Smallfrogs Studio, 2.7.0.1210]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Documents and Settings\Administrator\桌面\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS Error. []
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 yu.8s7.net
127.0.0.1 1.jopanqc.com
127.0.0.1 2.joppnqq.com
127.0.0.1 wg.47255.com
127.0.0.1 1.joppnqq.com
127.0.0.1 xxx.m111.biz
127.0.0.1 1.jopenqc.com
127.0.0.1 1.jopenkk.com
127.0.0.1 xxx.vh7.biz
127.0.0.1 xxx.j41m.com
127.0.0.1 3.joppnqq.com
127.0.0.1 d.93se.com
127.0.0.1
www.868wg.com127.0.0.1 xxx.mmma.biz
127.0.0.1 ilove.com
127.0.0.1 tp.shpzhan.cn
127.0.0.1
www.tomwg.com127.0.0.1
www.cike007.cn127.0.0.1
www.22aaa.com127.0.0.1 xx.exiao01.com
127.0.0.1
www.exiao01.com127.0.0.1
www.exiao01.com127.0.0.1 new.749571.com
127.0.0.1 xtx.kv8.info
127.0.0.1 cao.kv8.info
127.0.0.1 1.jopmmqq.com
127.0.0.1 171817.171817.com
127.0.0.1 d2.llsging.com
127.0.0.1 down.malasc.cn
127.0.0.1 llboss.com
127.0.0.1 nx.51ylb.cn
127.0.0.1 my.531jx.cn
127.0.0.1 qqq.dzydhx.com
127.0.0.1 qqq.hao1658.com
127.0.0.1
www.333292.com127.0.0.1 down.18dd.net
127.0.0.1 up.22x44.com
127.0.0.1 aaa.faba01.com
127.0.0.1 bad.tqdlt.cn
127.0.0.1 1.chsipo.com
127.0.0.1 c3.aishangai.net
127.0.0.1 c2.aishangai.net
127.0.0.1 xxx.188dm.com
127.0.0.1 x2.1a2b3c1.com
127.0.0.1 d1.163500.net
127.0.0.1 down.google-serv.cn
192.168.99.2 zbsrv
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 2140, D:\PROGRAM FILES\TENCENT\QQ\QQ.EXE]
==================================
计划任务
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
N/A