==================================
正在运行的进程
[PID: 540 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 616 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 648 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4175]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 692 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\AppPatch\AcAdProc.dll] [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[PID: 704 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 844 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4176]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2512]
[C:\WINDOWS\system32\atipdlxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2522]
[PID: 884 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 968 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1064 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)]
[PID: 1116 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1260 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1376 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4176]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2512]
[C:\WINDOWS\system32\atipdlxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2522]
[C:\WINDOWS\system32\ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4175]
[PID: 1516 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1628 / SYSTEM][D:\Program Files\StormII\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 3, 15]
[D:\Program Files\StormII\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0]
[PID: 1664 / SYSTEM][C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe] [Microsoft Corporation, 2000.080.2039.00]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\opends60.dll] [Microsoft Corporation, 2000.080.2039.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlsort.dll] [Microsoft Corporation, 2000.080.2039.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\ums.dll] [Microsoft Corporation, 2000.080.2039.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\Resources\2052\sqlevn70.RLL] [Microsoft Corporation, 2000.080.2039.00]
[C:\Program Files\Microsoft SQL Server\MSSQL\binn\SSNETLIB.dll] [Microsoft Corporation, 2000.080.2039.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\SSmsLPCn.dll] [Microsoft Corporation, 2000.080.2039.00]
[C:\PROGRA~1\MICROS~4\MSSQL\binn\SSnmPN70.dll] [Microsoft Corporation, 2000.080.2039.00]
[PID: 200 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1164 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 4, 0, 3, 1003]
[C:\WINDOWS\system32\WPDShServiceObj.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\PortableDeviceTypes.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[D:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 17]
[D:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.16]
[D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 61]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[PID: 1580 / Administrator][C:\Program Files\360safe\antiarp\antiarp.exe] [奇虎网, 2, 0, 0, 1004]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 4, 0, 3, 1003]
[PID: 1648 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 4, 0, 3, 1003]
[PID: 2564 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 4, 0, 3, 1003]
[PID: 2388 / Administrator][D:\Program Files\iSpeak\iSpeak.exe] [上海勤和互联网技术软件开发有限公司, 5, 0, 8, 125]
[D:\Program Files\iSpeak\MxUtilities.dll] [上海勤和互联网技术软件开发有限公司, 5, 0, 8, 27]
[D:\Program Files\iSpeak\Emoticon.DLL] [上海勤和互联网技术软件开发有限公司, 5, 0, 8, 27]
[D:\Program Files\iSpeak\MixWave.dll] [上海勤和互联网技术软件开发有限公司, 5, 0, 8, 27]
[D:\Program Files\iSpeak\MxAudio.dll] [上海勤和互联网技术软件开发有限公司, 5, 0, 8, 125]
[D:\Program Files\iSpeak\MxProtocol.dll] [上海勤和互联网技术软件开发有限公司, 5, 0, 8, 125]
[D:\Program Files\iSpeak\MxChannel.dll] [上海勤和互联网技术软件开发有限公司, 5, 0, 8, 27]
[D:\Program Files\iSpeak\MxSocket.dll] [N/A, ]
[D:\Program Files\iSpeak\imUpdate.dll] [, 1, 0, 0, 1]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 4, 0, 3, 1003]
[D:\Program Files\iSpeak\iSActiveX.ocx] [上海勤和互联网技术软件开发有限公司, 5, 0, 8, 27]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\imaadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msg711.acm] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\msgsm32.acm] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 4844 / Administrator][C:\WINDOWS\system32\cmd.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1544 / Administrator][C:\WINDOWS\system32\ping.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 5708 / Administrator][F:\CNTOOL v1.3.exe] [N/A, ]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 4, 0, 3, 1003]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 5620 / Administrator][F:\完美世界\element\elementclient.exe] [N/A, ]
[F:\完美世界\element\zlibwapi.dll] [, 1.2.2]
[F:\完美世界\element\ElementSkill.dll] [N/A, ]
[F:\完美世界\element\SpeedTreeRT.dll] [N/A, ]
[F:\完美世界\element\FTDriver.dll] [N/A, ]
[F:\完美世界\element\ImmWrapper.dll] [N/A, ]
[F:\完美世界\element\IFC22.dll] [Immersion Corporation, 2.2.8]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 4, 0, 3, 1003]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 356 / Administrator][F:\完美世界\element\reportbugs\pwprotector.exe] [N/A, ]
[PID: 3264 / Administrator][D:\Program Files\Tencent\QQ\QQ.exe] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\QQHelperDll.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\BasicCtrlDll.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 4, 0, 3, 1003]
[D:\Program Files\Tencent\QQ\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[D:\Program Files\Tencent\QQ\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[D:\Program Files\Tencent\QQ\QQAPI.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\LoginCtrl.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\LoginCtrlRes.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\QQRes.dll] [TENCENT, 8,0,776,1805]
[D:\Program Files\Tencent\QQ\QQMainFrame.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\Tencent\QQ\QQPlugin.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\UnReadMsgMgr.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\CQQApplication.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[D:\Program Files\Tencent\QQ\NewSkin.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\MailSummary.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\QQSpace.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\vbscript.dll] [Microsoft Corporation, 5.6.0.7426]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[D:\Program Files\Tencent\QQ\QQKnowledgeSearch.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\OEMApplication.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\QQGroupMng.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\UserDefinedHead.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\QQAllInOne.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\SCCore.dll] [TENCENT, 1, 6, 0, 2]
[D:\Program Files\Tencent\QQ\CameraDll.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\QQCustomFace.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[D:\Program Files\Tencent\QQ\QQPet.dll] [TENCENT, 8,0,777,1805]
[C:\WINDOWS\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\Tencent\QQ\QRingMng.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\QQSysMsgMng.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\QQConfigPlugin.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\ImageOle.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\QQLiveQMng.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\QQMagicFace.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\QQSceneMng.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\QQAvatar.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\LongConnection.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\PhoneAPI.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[D:\Program Files\Tencent\QQ\GroupConnection.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\BQQApplication.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\CommercesMng.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\PersonalDesktop.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 330]
[D:\Program Files\Tencent\QQ\VqqModule.dll] [TENCENT, 8,0,777,1805]
[D:\Program Files\Tencent\QQ\VqqAllInOne.dll] [Tencent, 2, 1, 0, 0]
[D:\Program Files\Tencent\QQ\tencent-proto1.dll] [tencent, 2, 1, 0, 0]
[D:\Program Files\Tencent\QQ\tencent-comlib.dll] [tencent, 2, 1, 0, 0]
[D:\Program Files\Tencent\QQ\tencent-proto2.dll] [tencent, 2, 1, 0, 0]
[D:\Program Files\Tencent\QQ\InPlus.dll] [Tencent, 2, 1, 0, 0]
[D:\Program Files\Tencent\QQ\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 2, 1, 15]
[C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0]
[D:\Program Files\Tencent\QQ\QQFileTransfer.dll] [TENCENT, 8,0,777,1805]
[PID: 1324 / Administrator][D:\Program Files\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 4, 0, 3, 1003]
[PID: 2796 / Administrator][D:\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 4, 0, 3, 1003]
[D:\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 yu.8s7.net
127.0.0.1 1.jopanqc.com
127.0.0.1 2.joppnqq.com
127.0.0.1 wg.47255.com
127.0.0.1 1.joppnqq.com
127.0.0.1 xxx.m111.biz
127.0.0.1 1.jopenqc.com
127.0.0.1 1.jopenkk.com
127.0.0.1 xxx.vh7.biz
127.0.0.1 xxx.j41m.com
127.0.0.1 3.joppnqq.com
127.0.0.1 d.93se.com
127.0.0.1
www.868wg.com127.0.0.1 xxx.mmma.biz
127.0.0.1 ilove.com
127.0.0.1 tp.shpzhan.cn
127.0.0.1
www.tomwg.com127.0.0.1
www.cike007.cn127.0.0.1
www.22aaa.com127.0.0.1 xx.exiao01.com
127.0.0.1
www.exiao01.com127.0.0.1
www.exiao01.com127.0.0.1 new.749571.com
127.0.0.1 xtx.kv8.info
127.0.0.1 cao.kv8.info
127.0.0.1 1.jopmmqq.com
127.0.0.1 171817.171817.com
127.0.0.1 d2.llsging.com
127.0.0.1 down.malasc.cn
127.0.0.1 llboss.com
127.0.0.1 nx.51ylb.cn
127.0.0.1 my.531jx.cn
127.0.0.1 qqq.dzydhx.com
127.0.0.1 qqq.hao1658.com
127.0.0.1
www.333292.com127.0.0.1 down.18dd.net
127.0.0.1 up.22x44.com
127.0.0.1 aaa.faba01.com
127.0.0.1 bad.tqdlt.cn
127.0.0.1 1.chsipo.com
127.0.0.1 c3.aishangai.net
127.0.0.1 c2.aishangai.net
127.0.0.1 xxx.188dm.com
127.0.0.1 x2.1a2b3c1.com
127.0.0.1 d1.163500.net
127.0.0.1 down.google-serv.cn
127.0.0.1 idc.windowsupdeta.cn
127.0.0.1 nc.mskess.com
127.0.0.1 ok.sl8cjs.cn
127.0.0.1 dl.pvs360.com
127.0.0.1 ta.pvs360.com
127.0.0.1 cw.pvs360.com
127.0.0.1 fg.pvs360.com
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 648, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1580, C:\PROGRAM FILES\360SAFE\ANTIARP\ANTIARP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2388, D:\PROGRAM FILES\ISPEAK\ISPEAK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 5708, F:\CNTOOL V1.3.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 5620, F:\完美世界\ELEMENT\ELEMENTCLIENT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 356, F:\完美世界\ELEMENT\REPORTBUGS\PWPROTECTOR.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================