==================================
正在运行的进程
[PID: 588 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 652 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 676 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 720 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\AppPatch\AcAdProc.dll] [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[PID: 732 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 884 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 952 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1080 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1128 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1180 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1500 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
[D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
[C:\WINDOWS\system32\WPDShServiceObj.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\PortableDeviceTypes.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[D:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.5.2005092300]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 1568 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1792 / Administrator][C:\WINDOWS\VM_STI.EXE] [VM., 4.2.610.4]
[D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\system32\VM31bPrp.Ax] [VM, 4.2.711.31]
[PID: 1820 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
[PID: 1896 / SYSTEM][C:\WINDOWS\system32\BoBoTurbo\BoBoTurbo.exe] [广州易播信息科技有限公司, 1, 4, 1011, 2]
[PID: 1960 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.9136]
[PID: 184 / SYSTEM][C:\Program Files\QvodPlayer\QvodTerminal.exe] [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 53]
[PID: 224 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1904 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1804 / Administrator][E:\Program Files\Tencent\qq\TXPlatform.exe] [Tencent, 1, 0, 170, 0]
[D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
[PID: 2004 / Administrator][F:\2008传美\qq\QQ.exe] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQBaseClassInDll.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQHelperDll.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\BasicCtrlDll.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[F:\2008传美\qq\MSIMG32.dll] [N/A, ]
[D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
[F:\2008传美\qq\FinePlus.dll] [N/A, ]
[F:\2008传美\qq\fphelper.dll] [N/A, ]
[F:\2008传美\qq\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[F:\2008传美\qq\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[F:\2008传美\qq\QQAPI.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\LoginCtrl.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\LoginCtrlRes.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQRes.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQMainFrame.dll] [N/A, ]
[F:\2008传美\qq\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[F:\2008传美\qq\QQPlugin.dll] [N/A, ]
[F:\2008传美\qq\UnReadMsgMgr.dll] [N/A, ]
[F:\2008传美\qq\CQQApplication.dll] [N/A, ]
[F:\2008传美\qq\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[F:\2008传美\qq\NewSkin.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\MailSummary.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQSpace.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\vbscript.dll] [N/A, ]
[F:\2008传美\qq\encode.dll] [Microsoft Corporation, 5.6.0.8825]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[F:\2008传美\qq\QQKnowledgeSearch.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\OEMApplication.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQGroupMng.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQAvatar.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[F:\2008传美\qq\QQAllInOne.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\SCCore.dll] [TENCENT, 1, 6, 0, 2]
[F:\2008传美\qq\CameraDll.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQSysMsgMng.dll] [N/A, ]
[F:\2008传美\qq\UserDefinedHead.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQConfigPlugin.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQCustomFace.dll] [N/A, ]
[F:\2008传美\qq\QRingMng.dll] [N/A, ]
[F:\2008传美\qq\QQPet.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\LongConnection.dll] [TENCENT, 8,0,776,1805]
[C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[F:\2008传美\qq\BQQApplication.dll] [N/A, ]
[F:\2008传美\qq\PersonalDesktop.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\CommercesMng.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 330]
[F:\2008传美\qq\QQSceneMng.dll] [N/A, ]
[F:\2008传美\qq\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 0, 1, 10]
[F:\2008传美\qq\QQLiveQMng.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\QQMagicFace.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\GroupConnection.dll] [TENCENT, 8,0,776,1805]
[F:\2008传美\qq\ImageOle.dll] [TENCENT, 8,0,776,1805]
[C:\WINDOWS\system32\JPWB.IME] [常诚研制, 4.00.950]
[PID: 1692 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
[F:\旋窝\QQIEHelper02.dll] [腾讯公司, 1, 1, 0, 5]
[C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
[D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.5.2005092300]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx] [Adobe Systems, Inc., 9,0,115,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1688 / Administrator][C:\Program Files\WinRAR\WinRAR.exe] [N/A, ]
[D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
[C:\WINDOWS\system32\wpdshext.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[PID: 3552 / Administrator][F:\系统文件\TT浏览器3.8\bin\TTraveler.exe] [Tencent, 4, 3, 0, 65]
[F:\系统文件\TT浏览器3.8\bin\TTUtilWidget.dll] [Tencent, 4, 3, 0, 65]
[F:\系统文件\TT浏览器3.8\bin\ATL80.DLL] [Microsoft Corporation, 8.00.50727.42]
[F:\系统文件\TT浏览器3.8\bin\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.42]
[F:\系统文件\TT浏览器3.8\bin\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42]
[F:\系统文件\TT浏览器3.8\bin\detoured.dll] [Microsoft Corporation, Express Version 2.1 Build_216]
[D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
[F:\系统文件\TT浏览器3.8\bin\TTStore.dll] [Tencent, 4, 3, 0, 65]
[F:\系统文件\TT浏览器3.8\bin\sqlite3.dll] [N/A, ]
[F:\系统文件\TT浏览器3.8\bin\PlatformWidget.dll] [Tencent, 4, 3, 0, 65]
[F:\系统文件\TT浏览器3.8\bin\TTMainFrame.dll] [Tencent, 4, 3, 0, 65]
[F:\系统文件\TT浏览器3.8\bin\TTMBrowser.dll] [Tencent, 4, 3, 0, 65]
[F:\系统文件\TT浏览器3.8\bin\TTabMgr.dll] [Tencent, 4, 3, 0, 65]
[F:\系统文件\TT浏览器3.8\bin\TTPluginMng.dll] [Tencent, 4, 3, 0, 65]
[F:\系统文件\TT浏览器3.8\Plugins\3TTWeather\TTWeather.dll] [TODO: <公司名>, 1.0.0.1]
[F:\系统文件\TT浏览器3.8\bin\TTSkin.dll] [Tencent, 4, 3, 0, 65]
[F:\系统文件\TT浏览器3.8\bin\vbscript.dll] [Microsoft Corporation, 5.7.0.16535]
[F:\系统文件\TT浏览器3.8\bin\FavoriteLogical.dll] [Tencent, 4, 3, 0, 65]
[F:\系统文件\TT浏览器3.8\bin\TTHtmlApp.dll] [Tencent, 4, 3, 0, 65]
[F:\系统文件\TT浏览器3.8\bin\TTFilter.dll] [Tencent, 4, 3, 0, 65]
[F:\系统文件\TT浏览器3.8\bin\TTNetwork.dll] [Tencent, 4, 3, 0, 65]
[F:\系统文件\TT浏览器3.8\bin\UpdateUtil.dll] [N/A, ]
[F:\系统文件\TT浏览器3.8\bin\TTSidebar.dll] [Tencent, 4, 3, 0, 65]
[F:\系统文件\TT浏览器3.8\bin\TSupport.dll] [TENCENT Inc., 1, 2, 11, 201]
[C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx] [Adobe Systems, Inc., 9,0,115,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 3592 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX03.594\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 5, 1001]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX03.594\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1
www.cike007.cn127.0.0.1
www.exiao01.com127.0.0.1 qqq.dzydhx.com
127.0.0.1 qqq.hao1658.com
127.0.0.1
www.333292.com127.0.0.1 down.18dd.net
127.0.0.1 xxx.m111.biz
127.0.0.1 1.jopenqc.com
127.0.0.1 xxx.j41m.com
127.0.0.1 3.joppnqq.com
127.0.0.1 d.93se.com
127.0.0.1 1.jopenkk.com
127.0.0.1 xxx.vh7.biz
127.0.0.1 new.749571.com
127.0.0.1 xtx.kv8.info
127.0.0.1 cao.kv8.info
127.0.0.1 1.jopmmqq.com
127.0.0.1 yu.8s7.net
127.0.0.1 1.jopanqc.com
127.0.0.1 2.joppnqq.com
127.0.0.1
www.868wg.com127.0.0.1 xxx.mmma.biz
127.0.0.1 ilove.com
127.0.0.1
www.22aaa.com127.0.0.1 xx.exiao01.com
127.0.0.1
www.exiao01.com127.0.0.1 tp.shpzhan.cn
127.0.0.1
www.tomwg.com127.0.0.1 wg.47255.com
127.0.0.1 1.joppnqq.com
127.0.0.1 171817.171817.com
127.0.0.1 d2.llsging.com
127.0.0.1 down.malasc.cn
127.0.0.1 llboss.com
127.0.0.1 nx.51ylb.cn
127.0.0.1 my.531jx.cn
127.0.0.1 up.22x44.com
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1792, C:\WINDOWS\VM_STI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1688, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]