==================================
正在运行的进程
[PID: 1088 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1156 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1188 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4177]
[C:\Program Files\Lenovo\HOTKEY\tphklock.dll] [Lenovo Group Limited, 1.03]
[PID: 1232 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[PID: 1244 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[PID: 1400 / SYSTEM][C:\WINDOWS\system32\ibmpmsvc.exe] [Lenovo, 1.51]
[PID: 1428 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4199]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2513]
[C:\WINDOWS\system32\atipdlxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2535]
[PID: 1448 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1508 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1560 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\SYSTEM\msxml3.dll] [Microsoft Corporation, 8.20.8730.1]
[PID: 1696 / SYSTEM][C:\Program Files\Intel\WiFi\bin\S24EvMon.exe] [Intel(R) Corporation, 12, 1, 1, 9]
[C:\Program Files\Intel\WiFi\bin\IntStngs.dll] [Intel(R) Corporation, 12, 1, 1, 0]
[C:\Program Files\Intel\WiFi\bin\IWMSPROV.DLL] [N/A, ]
[C:\Program Files\Common Files\Intel\WirelessCommon\PsRegApi.dll] [Intel(R) Corporation, 12, 1, 1, 0]
[C:\Program Files\Common Files\Intel\WirelessCommon\TraceApi.dll] [Intel(R) Corporation, 12, 1, 1, 2]
[C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll] [The OpenSSL Project,
http://www.openssl.org/, 0.9.8]
[C:\Program Files\Intel\WiFi\bin\KmmdlPlugins\SupplicantPlugin.dll] [Intel(R) Corporation, 12, 1, 1, 12]
[C:\Program Files\Intel\WiFi\bin\KmmdlPlugins\WSCPlugin.dll] [Intel(R) Corporation, 12, 1, 1, 5]
[C:\Program Files\Intel\WiFi\bin\supplicant.dll] [Devicescape Software, Inc., 1, 0, 72, 0]
[PID: 1772 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1820 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 268 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4199]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2513]
[C:\WINDOWS\system32\atipdlxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2535]
[C:\WINDOWS\system32\ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4177]
[PID: 368 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:\WINDOWS\system32\bthcrp.dll] [Broadcom Corporation., 5.5.0.4300]
[C:\WINDOWS\system32\WidcommSdk.dll] [Broadcom Corporation., 5.5.0.4300]
[C:\WINDOWS\system32\wbtapi.dll] [Broadcom Corporation., 5.5.0.4300]
[PID: 420 / LOCAL SERVICE][C:\WINDOWS\System32\SCardSvr.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[PID: 804 / user][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 9.1.0.2009022700]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS] [, ]
[C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll] [, 2, 0, 0, 0]
[C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiamCHS.dll] [Advanced Micro Devices, Inc., 6.14.10.2001]
[C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll] [ESET, 3.0.684 ]
[d:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\WINDOWS\system32\btncopy.dll] [Broadcom Corporation., 5.5.0.4300]
[C:\Program Files\Lenovo\HOTKEY\hkvolkey.dll] [Lenovo Group Limited, 1.01]
[PID: 900 / user][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[PID: 924 / user][C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe] [Lenovo Group Ltd., 2, 3, 2, 0]
[C:\PROGRA~1\ThinkPad\UTILIT~1\SC\EzMApRes.dll] [Lenovo Group Ltd., 2, 3, 2, 0]
[PID: 948 / user][C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe] [Lenovo Group Limited, 3, 0, 0, 0]
[C:\PROGRA~1\THINKV~1\PrdCtr\SC\LPRESMGR.DLL] [Lenovo Group Limited, 3, 0, 0, 0]
[C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[C:\WINDOWS\SYSTEM\msxml3.dll] [Microsoft Corporation, 8.20.8730.1]
[PID: 956 / user][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL] [Lenovo Group Limited, 1, 0, 0, 0]
[C:\PROGRA~1\ThinkPad\UTILIT~1\SC\PWRMGRRT.DLL] [N/A, ]
[C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRIF.DLL] [N/A, ]
[C:\WINDOWS\system32\Sensor.dll] [Lenovo., 1.60.0.6]
[C:\WINDOWS\system32\OEMDSPIF.DLL] [ATI Technologies, Inc., 6.15.0402]
[C:\WINDOWS\system32\atipdlxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2535]
[C:\PROGRA~1\ThinkPad\UTILIT~1\ATM.DLL] [Lenovo Japan, 1, 3, 4, 0]
[PID: 928 / user][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] [Synaptics, Inc., 11.1.21.2 06Oct08]
[C:\WINDOWS\system32\SynCOM.dll] [Synaptics, Inc., 11.1.21.2 06Oct08]
[C:\WINDOWS\system32\SynTPAPI.dll] [Synaptics, Inc., 11.1.21.2 06Oct08]
[C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[PID: 604 / user][C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe] [Lenovo Group Limited, 1.04]
[C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.dll] [Lenovo Group Limited, 1.00]
[C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[C:\Program Files\Lenovo\HOTKEY\hkvolkey.dll] [Lenovo Group Limited, 1.01]
[PID: 1040 / user][C:\WINDOWS\system32\TpShocks.exe] [Lenovo., 1.61.0.1]
[C:\Program Files\ThinkPad\TpShocks\MUI\0804\TpShocks.dll] [, ]
[C:\WINDOWS\system32\Sensor.dll] [Lenovo., 1.60.0.6]
[PID: 1708 / user][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[PID: 1856 / user][C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe] [Lenovo Group Limited, 5.01]
[C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[PID: 1892 / user][C:\Program Files\Lenovo\Zoom\TpScrex.exe] [Lenovo Group Limited, 2.03]
[C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[PID: 2004 / user][C:\Program Files\Synaptics\SynTP\SynTPLpr.exe] [Synaptics, Inc., 11.1.21.2 06Oct08]
[C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[C:\WINDOWS\system32\SynCOM.dll] [Synaptics, Inc., 11.1.21.2 06Oct08]
[PID: 1944 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 2060 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 2124 / SYSTEM][d:\Program Files\StormII\stormliv.exe] [北京暴风网际科技有限公司, 3, 9, 5, 22]
[C:\WINDOWS\SYSTEM\msxml3.dll] [Microsoft Corporation, 8.20.8730.1]
[d:\Program Files\StormII\bfoptdll.dll] [北京暴风网际科技有限公司, 3, 8, 7, 16]
[d:\Program Files\StormII\box\BoxLog.dll] [北京暴风网际科技有限公司, 3, 9, 6, 27]
[PID: 2144 / SYSTEM][C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe] [ESET, 3.0.684 ]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnScan.dll] [ESET, 3.0.684 ]
[C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnAmon.dll] [ESET, 3.0.684 ]
[C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnEmon.dll] [ESET, 3.0.684 ]
[C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnEpfw.dll] [ESET, 3.0.684 ]
[C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnUpdate.dll] [ESET, 3.0.684 ]
[C:\Program Files\ESET\ESET NOD32 Antivirus\updater.dll] [ESET, 3.0.684 ]
[C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnMailPlugins.dll] [ESET, 3.0.684 ]
[PID: 2164 / SYSTEM][C:\Program Files\Intel\WiFi\bin\EvtEng.exe] [Intel(R) Corporation, 12, 1, 1, 0]
[C:\Program Files\Intel\WiFi\bin\PfMgrApi.dll] [Intel(R) Corporation, 12, 1, 1, 2]
[C:\Program Files\Intel\WiFi\bin\MurocApi.dll] [Intel(R) Corporation, 12, 1, 1, 5]
[C:\Program Files\Intel\WiFi\bin\IntStngs.dll] [Intel(R) Corporation, 12, 1, 1, 0]
[C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll] [The OpenSSL Project,
http://www.openssl.org/, 0.9.8]
[C:\Program Files\Common Files\Intel\WirelessCommon\PsRegApi.dll] [Intel(R) Corporation, 12, 1, 1, 0]
[C:\Program Files\Common Files\Intel\WirelessCommon\TraceApi.dll] [Intel(R) Corporation, 12, 1, 1, 2]
[C:\Program Files\Intel\WiFi\bin\S24MUDLL.dll] [Intel(R) Corporation, 12, 1, 1, 1]
[PID: 2240 / SYSTEM][C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe] [Intel(R) Corporation, 12, 1, 1, 0]
[PID: 2656 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 2916 / SYSTEM][C:\WINDOWS\System32\TPHDEXLG.exe] [Lenovo., 1.60.0.6]
[PID: 2968 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 3012 / SYSTEM][C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE] [, 1, 0, 0, 1]
[C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRIF.DLL] [N/A, ]
[C:\WINDOWS\system32\Sensor.dll] [Lenovo., 1.60.0.6]
[PID: 3408 / SYSTEM][D:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe] [Broadcom Corporation., 5.5.0.4300]
[PID: 3880 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[PID: 1096 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe] [(Verified) Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[PID: 2548 / user][C:\WINDOWS\system32\conime.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[PID: 3996 / user][G:\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.7.1.1261]
[PID: 3812 / user][G:\sreng2\SRE73340a5.EXE] [Smallfrogs Studio, 2.7.1.1261]
[C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[G:\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[C:\WINDOWS\system32\aetsprov.dll] [A.E.T. Europe B.V., 2.3.0.9]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.6030.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
218.75.159.150
www.kzdh.com218.75.159.150
www.6781.com218.75.159.150
www.v2233.com218.75.159.150
www.iq123.com218.75.159.150
www.i2345.cn218.75.159.150
www.haokan123.com218.75.159.150
www.365wz.net218.75.159.150
www.5d5e.com218.75.159.150
www.112r.com218.75.159.150
www.32e.com218.75.159.150
www.77177.com218.75.159.150
www.daluobo.cn218.75.159.150
www.haha111.com218.75.159.150
www.haoz123.cn218.75.159.150
www.85vv.com218.75.159.150
www.ok100.net.cn218.75.159.150
www.ai1234.com218.75.159.150
www.15wz.com218.75.159.150
www.fm5566.com218.75.159.150
www.9798.net218.75.159.150
www.s565.com218.75.159.150
www.345s.com218.75.159.150
www.110wz.com218.75.159.150
www.6dh.com218.75.159.150
www.tt98.com218.75.159.150
www.85851.com218.75.159.150
www.66d8.cn218.75.159.150
www.baihu.cn218.75.159.150
www.hang123.com218.75.159.150
www.17909.com218.75.159.150
www.838.cc218.75.159.150
www.ee258.com218.75.159.150
www.gjj.cc==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1696, C:\PROGRAM FILES\INTEL\WIFI\BIN\S24EVMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2164, C:\PROGRAM FILES\INTEL\WIFI\BIN\EVTENG.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3996, G:\SRENG2\SRENGLDR.EXE]
==================================
计划任务
[已启用] SogouImeMgr.job
C:\PROGRA~1\SOGOUI~1\360~1.165\PinyinRepair.exe
[已禁用] PMTask.job
C:\PROGRA~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================