正在运行的进程
[PID: 584][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 656][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 684][\??\C:\WINDOWS\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4129]
[PID: 728][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 740][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 908][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4129]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2500]
[PID: 932][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 996][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1108][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1216][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 184][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 800][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 2020][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3220][E:\qq\TXPlatform.exe] [Tencent, 1, 5, 225, 0]
[PID: 3116][C:\WINDOWS\explorer.exe] [(Verified) Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[E:\迅雷\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.34]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.18]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17]
[C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll] [, 1, 0, 0, 1]
[PID: 2640][E:\qq\QQ.exe] [TENCENT, 8,0,978,1833]
[E:\qq\QQBaseClassInDll.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQHelperDll.dll] [TENCENT, 8,0,978,1833]
[E:\qq\BasicCtrlDll.dll] [TENCENT, 8,0,978,1833]
[E:\qq\PSAPI.DLL] [N/A, ]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[E:\qq\QQAPI.dll] [TENCENT, 8,0,978,1833]
[E:\qq\LoginCtrl.dll] [TENCENT, 8,0,978,1833]
[E:\qq\LoginCtrlRes.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQRes.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQMainFrame.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQPlugin.dll] [TENCENT, 8,0,978,1833]
[E:\qq\UnReadMsgMgr.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQAllInOne.dll] [TENCENT, 8,0,978,1833]
[E:\qq\SCCore.dll] [TENCENT, 1, 6, 0, 2]
[E:\qq\CameraDll.dll] [TENCENT, 8,0,978,1833]
[E:\qq\CQQApplication.dll] [TENCENT, 8,0,978,1833]
[E:\qq\FlashAvatarDll.dll] [, 1, 0, 0, 1]
[E:\qq\NewSkin.dll] [TENCENT, 8,0,978,1833]
[E:\qq\MailSummary.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQSpace.dll] [TENCENT, 8,0,978,1833]
[C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx] [Adobe Systems, Inc., 10,0,12,36]
[E:\qq\msdmo.dll] [, ]
[E:\qq\OEMApplication.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQAvatar.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQKnowledgeSearch.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQGroupMng.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQPet.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QRingMng.dll] [TENCENT, 8,0,978,1833]
[E:\qq\UserDefinedHead.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQCustomFace.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQConfigPlugin.dll] [TENCENT, 8,0,978,1833]
[E:\qq\LongConnection.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQFileTransfer.dll] [TENCENT, 8,0,978,1833]
[E:\qq\PhoneAPI.dll] [TENCENT, 8,0,978,1833]
[E:\qq\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[E:\qq\ImageOle.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQMagicFace.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQLiveQMng.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQSceneMng.dll] [TENCENT, 8,0,978,1833]
[E:\qq\GroupConnection.dll] [TENCENT, 8,0,978,1833]
[E:\qq\BQQApplication.dll] [TENCENT, 8,0,978,1833]
[E:\qq\CommercesMng.dll] [TENCENT, 8,0,978,1833]
[E:\qq\PersonalDesktop.dll] [TENCENT, 8,0,978,1833]
[E:\qq\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 330]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5]
[E:\qq\QQSysMsgMng.dll] [TENCENT, 8,0,978,1833]
[E:\qq\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 2, 1, 17]
[PID: 2168][C:\WINDOWS\system32\conime.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1972][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 7.00.6000.16735 (vista_gdr.080820-1506)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[E:\迅雷\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.34]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\UrlFilter.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 15]
[E:\kaka\UrlRule.dll] [Beijing Rising Information Technology Co., Ltd., 1.0.0.15]
[E:\ast\SecAddons.dll] [超级巡警, 1, 0, 3, 4]
[C:\Program Files\Sucop\SecPlugin\SecPlugin.dll] [超级巡警, 1, 0, 9, 8]
[C:\Program Files\Sucop\SecPlugin\SScanner.dll] [超级巡警, 1, 0, 6, 0]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5]
[C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx] [Adobe Systems, Inc., 10,0,12,36]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.6.0.1653]
[PID: 2652][E:\sr\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210]
[PID: 1748][E:\sr\SRE6eec824a.EXE] [Smallfrogs Studio, 2.7.0.1210]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[E:\sr\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 v.onondown.com.cn
127.0.0.2 ymsdasdw1.cn
127.0.0.3 h96b.info
127.0.0.0
www.bypk.com127.0.0.1 va9sdhun23.cn
127.0.0.2 bnasnd83nd.cn
127.0.0.0
www.gamehacker.com.cn127.0.0.0 gamehacker.com.cn
127.0.0.3 adlaji.cn
127.0.0.1 858656.com
127.1.1.1 bnasnd83nd.cn
127.0.0.1 my123.com
127.0.0.0 user1.12-27.net
127.0.0.1 8749.com
127.0.0.0 fengent.cn
127.0.0.1 4199.com
127.0.0.1 user1.16-22.net
127.0.0.1 7379.com
127.0.0.1 2be37c5f.3f6e2cc5f0b.com
127.0.0.1 7255.com
127.0.0.1 user1.23-12.net
127.0.0.1 3448.com
127.0.0.1
www.guccia.net127.0.0.1 7939.com
127.0.0.1 a.o1o1o1.nEt
127.0.0.1 8009.com
127.0.0.1 user1.12-73.cn
127.0.0.1 piaoxue.com
127.0.0.1 3n8nlasd.cn
127.0.0.1 kzdh.com
127.0.0.0
www.sony888.cn127.0.0.1 about.blank.la
127.0.0.0 user1.asp-33.cn
127.0.0.1 6781.com
127.0.0.0
www.netkwek.cn127.0.0.1 7322.com
127.0.0.0 ymsdkad6.cn
127.0.0.1 localhost
127.0.0.0
www.lkwueir.cn127.0.0.1 06.jacai.com
127.0.1.1 user1.23-17.net
127.0.0.1 1.jopenkk.com
127.0.0.0 upa.luzhiai.net
127.0.0.1 1.jopenqc.com
127.0.0.0
www.guccia.net127.0.0.1 1.joppnqq.com
127.0.0.0 4m9mnlmi.cn
127.0.0.1 1.xqhgm.com
127.0.0.0 mm119mkssd.cn
127.0.0.1 100.332233.com
127.0.0.0 61.128.171.115:8080
127.0.0.1 121.11.90.79
127.0.0.0
www.1119111.com127.0.0.1 121565.net
127.0.0.0 win.nihao69.cn
127.0.0.1 125.90.88.38
127.0.0.1 16888.6to23.com
127.0.0.1 2.joppnqq.com
127.0.0.0 puc.lianxiac.net
127.0.0.1 204.177.92.68
127.0.0.0 pud.lianxiac.net
127.0.0.1 210.74.145.236
127.0.0.0 210.76.0.133
127.0.0.1 219.129.239.220
127.0.0.0 61.166.32.2
127.0.0.1 219.153.40.221
127.0.0.0 218.92.186.27
127.0.0.1 219.153.46.27
127.0.0.0
www.fsfsfag.cn127.0.0.1 219.153.52.123
127.0.0.0 ovo.ovovov.cn
127.0.0.1 221.195.42.71
127.0.0.0 dw.com.com
127.0.0.1 222.73.218.115
127.0.0.1 203.110.168.233:80
127.0.0.1 3.joppnqq.com
127.0.0.1 203.110.168.221:80
127.0.0.1 363xx.com
127.0.0.1 www1.ip10086.com.cm
127.0.0.1 4199.com
127.0.0.1 blog.ip10086.com.cn
127.0.0.1 43242.com
127.0.0.1
www.ccji68.cn127.0.0.1 5.xqhgm.com
127.0.0.0 t.myblank.cn
127.0.0.1 520.mm5208.com
127.0.0.0 x.myblank.cn
127.0.0.1 59.34.131.54
127.0.0.1 210.51.45.5
127.0.0.1 59.34.198.228
127.0.0.1
www.ew1q.cn127.0.0.1 59.34.198.88
127.0.0.1 59.34.198.97
127.0.0.1 60.190.114.101
127.0.0.1 60.190.218.34
127.0.0.0 qq-xing.com.cn
127.0.0.1 60.191.124.252
127.0.0.1 61.145.117.212
127.0.0.1 61.157.109.222
127.0.0.1 75.126.3.216
127.0.0.1 75.126.3.217
127.0.0.1 75.126.3.218
127.0.0.0 59.125.231.177:17777
127.0.0.1 75.126.3.220
127.0.0.1 75.126.3.221
127.0.0.1 75.126.3.222
127.0.0.1 772630.com
127.0.0.1 832823.cn
127.0.0.1 8749.com
127.0.0.1 888.jopenqc.com
127.0.0.1 89382.cn
127.0.0.1 8v8.biz
127.0.0.1 97725.com
127.0.0.1 9gg.biz
127.0.0.1
www.9000music.com127.0.0.1 test.591jx.com
127.0.0.1 a.topxxxx.cn
127.0.0.1 picon.chinaren.com
127.0.0.1
www.5566.net127.0.0.1 p.qqkx.com
127.0.0.1 news.netandtv.com
127.0.0.1 z.neter888.cn
127.0.0.1 b.myblank.cn
127.0.0.1 wvw.wokutu.com
127.0.0.1 unionch.qyule.com
127.0.0.1
www.qyule.com127.0.0.1 it.itjc.cn
127.0.0.1
www.linkwww.com127.0.0.1 vod.kaicn.com
127.0.0.1
www.tx8688.com127.0.0.1 b.neter888.cn
127.0.0.1 promote.huanqiu.com
127.0.0.1
www.huanqiu.com127.0.0.1
www.haokanla.com127.0.0.1 play.unionsky.cn
127.0.0.1
www.52v.com127.0.0.1
www.gghka.cn127.0.0.1 icon.ajiang.net
127.0.0.1 new.ete.cn
127.0.0.1
www.stiae.cn127.0.0.1 o.neter888.cn
127.0.0.1 comm.jinti.com
127.0.0.1
www.google-analytics.com127.0.0.1 hz.mmstat.com
127.0.0.1
www.game175.cn127.0.0.1 x.neter888.cn
127.0.0.1 z.neter888.cn
127.0.0.1 p.etimes888.com
127.0.0.1 hx.etimes888.com
127.0.0.1 abc.qqkx.com
127.0.0.1 dm.popdm.cn
127.0.0.1
www.yl9999.com127.0.0.1
www.dajiadoushe.cn127.0.0.1 v.onondown.com.cn
127.0.0.1
www.interoo.net127.0.0.1 bally1.bally-bally.net
127.0.0.1
www.bao5605509.cn127.0.0.1
www.rty456.cn127.0.0.1
www.werqwer.cn127.0.0.1 1.360-1.cn
127.0.0.1 user1.23-16.net
127.0.0.1
www.guccia.net127.0.0.1
www.interoo.net127.0.0.1 upa.netsool.net
127.0.0.1 js.users.51.la
127.0.0.1 vip2.51.la
127.0.0.1 web.51.la
127.0.0.1 qq.gong2008.com
127.0.0.1 2008tl.copyip.com
127.0.0.1 tla.laozihuolaile.cn
127.0.0.1
www.tx6868.cn127.0.0.1 p001.tiloaiai.com
127.0.0.1 s1.tl8tl.com
127.0.0.1 s1.gong2008.com
127.0.0.1 4b3ce56f9g.3f6e2cc5f0b.com
127.0.0.1 2be37c5f.3f6e2cc5f0b.com
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 2652, E:\SR\SRENGLDR.EXE]
==================================
计划任务
[已启用] SogouImeMgr.job
E:\SOGOUI~1\360~1.165\PinyinRepair.exe
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]