==================================
正在运行的进程
[PID: 688 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 752 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 784 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4176]
[PID: 828 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[PID: 840 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1012 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4188]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2513]
[C:\WINDOWS\system32\atipdlxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2527]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1028 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1100 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1132 / SYSTEM][C:\Program Files\锐捷网络\Ruijie Supplicant\SuService.exe] [tendychen, 1, 0, 0, 1]
[PID: 1236 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\System32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1416 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1468 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1548 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4188]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2513]
[C:\WINDOWS\system32\atipdlxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2527]
[C:\WINDOWS\system32\ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4176]
[PID: 1864 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1916 / Administrator][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\KMailOEBand.DLL] [Kingsoft Corporation, 2009,02,13,759]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\kis.dll] [Kingsoft Corporation, 2009,02,13,759]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\MFC80CHS.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\Program Files\360\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1012]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\ktaskbar.dll] [Kingsoft Corporation, 2009,03,11,790]
[C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[E:\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5.0.8.179]
[E:\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 22]
[E:\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 17]
[E:\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.2.6.179]
[C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.6041.0]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\KAVEXT.DLL] [Kingsoft Corporation, 2008,07,09,459]
[PID: 740 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 664 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 2980 / SYSTEM][C:\Program Files\锐捷网络\Ruijie Supplicant\8021x.exe] [锐捷网络, 3, 50, 0, 0]
[C:\Program Files\锐捷网络\Ruijie Supplicant\W32N55.dll] [Printing Communications Assoc., Inc. (PCAUSA), 5.5.18.05]
[C:\Program Files\锐捷网络\Ruijie Supplicant\ArpGuard.dll] [锐捷网络, 1, 2, 0, 2]
[C:\Program Files\锐捷网络\Ruijie Supplicant\Vz_API.dll] [锐捷网络, 1, 2, 0, 2]
[C:\Program Files\锐捷网络\Ruijie Supplicant\Vd_API.dll] [锐捷网络, 1, 1, 0, 1]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\PROGRA~1\锐捷网络\RUIJIE~1\EXRGPA~1.OCX] [锐捷网络, 1, 2, 1, 2]
[C:\PROGRA~1\锐捷网络\RUIJIE~1\HIDetect.dll] [锐捷网络, 1, 5, 0, 1]
[C:\PROGRA~1\锐捷网络\RUIJIE~1\Vy_API.dll] [锐捷网络, 1, 2, 0, 1]
[C:\PROGRA~1\锐捷网络\RUIJIE~1\WuClientAPI.dll] [锐捷网络, 1.2.0.2]
[C:\PROGRA~1\锐捷网络\RUIJIE~1\Vx_API.dll] [锐捷网络, 1, 1, 0, 2]
[C:\PROGRA~1\锐捷网络\RUIJIE~1\VirusDefenderCheck.dll] [, 1, 3, 0, 1]
[C:\Program Files\锐捷网络\Ruijie Supplicant\GetKVInfo.dll] [Jiangmin Co., Ltd., 1, 0, 8, 905]
[PID: 2212 / Administrator][C:\Program Files\TTPlayer\TTPlayer.exe] [Alen Soft, 5, 1, 0, 0]
[C:\Program Files\TTPlayer\ttpcomm.dll] [N/A, ]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\KMailOEBand.DLL] [Kingsoft Corporation, 2009,02,13,759]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\kis.dll] [Kingsoft Corporation, 2009,02,13,759]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\MFC80CHS.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\Program Files\360\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1012]
[C:\Program Files\TTPlayer\ttpres.dll] [Alen Soft, 5, 1, 0, 0]
[C:\Program Files\TTPlayer\msdmo.dll] [Microsoft Corporation, 6.03.01.0400]
[C:\Program Files\TTPlayer\AddIn\ttp_lrcsh.dll] [N/A, ]
[PID: 3792 / Administrator][C:\Program Files\TheWorld 3\TheWorld.exe] [Phoenix Studio, 3, 0, 2, 8]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\KMailOEBand.DLL] [Kingsoft Corporation, 2009,02,13,759]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\kis.dll] [Kingsoft Corporation, 2009,02,13,759]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\MFC80CHS.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\Program Files\360\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1012]
[C:\PROGRA~1\THEWOR~1\Extensions\ExtAddons\ExtAddons.dll] [Phoenix Studio, 1, 0, 1, 1]
[C:\PROGRA~1\THEWOR~1\Extensions\ExtAdfilter\ExtAdfilter.dll] [, 1, 0, 0, 6]
[C:\PROGRA~1\THEWOR~1\Extensions\ExtDownload\ExtDownload.dll] [Phoenix Studio, 1, 0, 1, 0]
[C:\PROGRA~1\THEWOR~1\Extensions\ExtMinibar\ExtMinibar.dll] [Phoenix Studio, 1, 0, 0, 9]
[C:\PROGRA~1\THEWOR~1\Extensions\ExtPages\ExtPages.dll] [Phoenix Studio, 1, 0, 1, 0]
[PID: 3216 / Administrator][C:\Program Files\TheWorld 3\TheWorld.exe] [Phoenix Studio, 3, 0, 2, 8]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\KMailOEBand.DLL] [Kingsoft Corporation, 2009,02,13,759]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\kis.dll] [Kingsoft Corporation, 2009,02,13,759]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\MFC80CHS.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\Program Files\360\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1012]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\KASBrowserShield.DLL] [Kingsoft Corporation, 2009,04,13,824]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\IEBuddy.dll] [Kingsoft Corporation, 2009,05,14,886]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\IEBuddyExt.DLL] [Kingsoft Corporation, 2008,12,12,694]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\KANTray.dll] [Kingsoft Corporation, 2008,06,26,421]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\KAVAFish.DLL] [Kingsoft Corporation, 2008,06,26,421]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\kisfree.dll] [Kingsoft Corporation, 2009,05,26,901]
[C:\PROGRA~1\THEWOR~1\Extensions\ExtAdfilter\ExtAdfilter.dll] [, 1, 0, 0, 6]
[C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx] [Adobe Systems, Inc., 10,0,12,36]
[PID: 1256 / Administrator][E:\TDDOWNLOAD\srend\SREngLdr.EXE] [Smallfrogs Studio, 2.7.1.1261]
[PID: 616 / Administrator][E:\TDDOWNLOAD\srend\SRE7f32c210.EXE] [Smallfrogs Studio, 2.7.1.1261]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\KMailOEBand.DLL] [Kingsoft Corporation, 2009,02,13,759]
[C:\Program Files\Kingsoft\Kingsoft Internet Security\kis.dll] [Kingsoft Corporation, 2009,02,13,759]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\MFC80CHS.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\Program Files\360\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1012]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[E:\TDDOWNLOAD\srend\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[PID: 2768 / NETWORK SERVICE][C:\WINDOWS\system32\wbem\wmiprvse.exe] [(Verified) Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
==================================
文件关联
.TXT Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. [C:\WINDOWS\hh.exe %1]
.HLP Error. [C:\WINDOWS\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 3929.cn
127.0.0.1 aaa.369678.cn
127.0.0.1 about-blank.cc
127.0.0.1 anjdyazj.cn
127.0.0.1 caiyi8.com
127.0.0.1 hao.allxun.com
127.0.0.1 kzxf.com
127.0.0.1 scvip.com
127.0.0.1 vod.mmdy.org
127.0.0.1
www.123wa.com127.0.0.1
www.369678.cn127.0.0.1
www.3929.cn127.0.0.1
www.4199.com127.0.0.1
www.71791.com127.0.0.1
www.7939.com127.0.0.1
www.9505.com127.0.0.1
www.anjdyazj.cn127.0.0.1
www.caiyi8.com127.0.0.1
www.feixue.net127.0.0.1
www.kzxf.com127.0.0.1
www.my123.com127.0.0.1
www.piaoxue.com127.0.0.1
www.scvip.com127.0.0.1
www.xfkz.com127.0.0.1 xfkz.com
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1012, C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1548, C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2980, C:\PROGRAM FILES\锐捷网络\RUIJIE SUPPLICANT\8021X.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2212, C:\PROGRAM FILES\TTPLAYER\TTPLAYER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1256, E:\TDDOWNLOAD\SREND\SRENGLDR.EXE]
==================================
计划任务
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]