[C:\WINDOWS\system32\csdlocalmon.dll] [N/A, ]
[PID: 1332 / user][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\zxmsawin.dll] [N/A, ]
[C:\WINDOWS\system32\mpwdbapi.dll] [N/A, ]
[C:\WINDOWS\system32\ptjhchlp.dll] [N/A, ]
[C:\WINDOWS\system32\ttCBDCBD1049.dll] [N/A, ]
[C:\WINDOWS\system32\yxcsbhlp.dll] [N/A, ]
[C:\WINDOWS\system32\zjydcx.dll] [N/A, ]
[C:\WINDOWS\system32\dqDABDAB1071.dll] [N/A, ]
[C:\WINDOWS\system32\dqBAIBAI1067.dll] [N/A, ]
[C:\WINDOWS\system32\dqMYSMYS1049.dll] [N/A, ]
[C:\WINDOWS\system32\dqSHYSHY1053.dll] [N/A, ]
[C:\WINDOWS\system32\dqQACQAC1044.dll] [N/A, ]
[C:\WINDOWS\system32\dqHADHAD1069.dll] [N/A, ]
[C:\WINDOWS\system32\dqSADSAD1042.dll] [N/A, ]
[C:\WINDOWS\system32\dqWLVWLV1014.dll] [N/A, ]
[C:\WINDOWS\system32\ttKAFKAF1072.dll] [N/A, ]
[C:\WINDOWS\system32\dqDLQDLQ1007.dll] [N/A, ]
[C:\WINDOWS\system32\ttDXYDXY1013.dll] [N/A, ]
[C:\WINDOWS\system32\ypcqchlp.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys] [N/A, ]
[C:\WINDOWS\system32\dqDXYDXY1006.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[c:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[PID: 1836 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.13.10.3082]
[PID: 1876 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1896 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 736 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 936 / user][C:\WINPENJR\Win32\pphidpad.exe] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys] [N/A, ]
[C:\WINDOWS\system32\yxcsbhlp.dll] [N/A, ]
[C:\WINDOWS\system32\ypcqchlp.dll] [N/A, ]
[C:\WINDOWS\system32\zxmsawin.dll] [N/A, ]
[C:\WINDOWS\system32\zjydcx.dll] [N/A, ]
[PID: 976 / user][C:\WINDOWS\VM_STI.EXE] [VM., 4.2.610.4]
[C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys] [N/A, ]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\system32\ypcqchlp.dll] [N/A, ]
[C:\WINDOWS\system32\zjydcx.dll] [N/A, ]
[C:\WINDOWS\system32\yxcsbhlp.dll] [N/A, ]
[C:\WINDOWS\system32\zxmsawin.dll] [N/A, ]
[PID: 684 / user][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3208]
[C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys] [N/A, ]
[C:\WINDOWS\system32\zxmsawin.dll] [N/A, ]
[C:\WINDOWS\system32\ypcqchlp.dll] [N/A, ]
[C:\WINDOWS\system32\yxcsbhlp.dll] [N/A, ]
[C:\WINDOWS\system32\zjydcx.dll] [N/A, ]
[PID: 1128 / user][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys] [N/A, ]
[C:\WINDOWS\system32\zxmsawin.dll] [N/A, ]
[C:\WINDOWS\system32\ypcqchlp.dll] [N/A, ]
[C:\WINDOWS\system32\yxcsbhlp.dll] [N/A, ]
[C:\WINDOWS\system32\zjydcx.dll] [N/A, ]
[PID: 1152 / user][C:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 20.0.01.19]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[C:\Program Files\Rising\Rav\recomp.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 35]
[C:\Program Files\Rising\Rav\refs.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 15]
[C:\Program Files\Rising\Rav\viruslib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26]
[C:\Program Files\Rising\Rav\relibldr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 14]
[C:\Program Files\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16]
[C:\Program Files\Rising\Rav\MonRule.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.29]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4]
[C:\Program Files\Rising\Rav\Rsguilib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 88]
[C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0]
[C:\WINDOWS\system32\ypcqchlp.dll] [N/A, ]
[C:\WINDOWS\system32\yxcsbhlp.dll] [N/A, ]
[C:\WINDOWS\system32\zxmsawin.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys] [N/A, ]
[C:\WINDOWS\system32\zjydcx.dll] [N/A, ]
[C:\WINDOWS\system32\mpwdbapi.dll] [N/A, ]
[C:\WINDOWS\system32\ptjhchlp.dll] [N/A, ]
[PID: 3000 / user][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17]
[C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys] [N/A, ]
[C:\WINDOWS\system32\zxmsawin.dll] [N/A, ]
[C:\WINDOWS\system32\yxcsbhlp.dll] [N/A, ]
[C:\WINDOWS\system32\ypcqchlp.dll] [N/A, ]
[C:\WINDOWS\system32\zjydcx.dll] [N/A, ]
[PID: 3016 / user][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17]
[C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys] [N/A, ]
[C:\WINDOWS\system32\xunleibho_v11.dll] [Thunder Networking Technologies,LTD, 4, 6, 0, 48]
[C:\WINDOWS\system32\yxcsbhlp.dll] [N/A, ]
[C:\WINDOWS\system32\mpwdbapi.dll] [N/A, ]
[C:\WINDOWS\system32\ptjhchlp.dll] [N/A, ]
[C:\WINDOWS\system32\ypcqchlp.dll] [N/A, ]
[C:\WINDOWS\system32\zxmsawin.dll] [N/A, ]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[c:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0]
[c:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\JPWB.IME] [长江软件工作室, 4.00.950]
[C:\WINDOWS\system32\zjydcx.dll] [N/A, ]
[C:\WINDOWS\system32\ttCBDCBD1049.dll] [N/A, ]
[C:\WINDOWS\system32\dqDABDAB1071.dll] [N/A, ]
[C:\WINDOWS\system32\dqBAIBAI1067.dll] [N/A, ]
[C:\WINDOWS\system32\dqMYSMYS1049.dll] [N/A, ]
[C:\WINDOWS\system32\dqSHYSHY1053.dll] [N/A, ]
[C:\WINDOWS\system32\dqQACQAC1044.dll] [N/A, ]
[C:\WINDOWS\system32\dqHADHAD1069.dll] [N/A, ]
[C:\WINDOWS\system32\dqSADSAD1042.dll] [N/A, ]
[C:\WINDOWS\system32\dqWLVWLV1014.dll] [N/A, ]
[C:\WINDOWS\system32\ttKAFKAF1072.dll] [N/A, ]
[C:\WINDOWS\system32\dqDLQDLQ1007.dll] [N/A, ]
[C:\WINDOWS\system32\ttDXYDXY1013.dll] [N/A, ]
[C:\WINDOWS\system32\dqDXYDXY1006.dll] [N/A, ]
[PID: 3820 / user][C:\Program Files\Thunder Network\Thunder\Thunder.exe] [Thunder Networking Technologies,LTD, 5.1.1.157]
[C:\Program Files\Thunder Network\Thunder\UpdateDownload.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
[C:\Program Files\Thunder Network\Thunder\download_intexxxce.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 39]
[C:\Program Files\Thunder Network\Thunder\log4cplus.dll] [, 1, 0, 2, 1]
[C:\Program Files\Thunder Network\Thunder\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031]
[C:\Program Files\Thunder Network\Thunder\historyinfo_manage.dll] [Thunder Networking Technologies,LTD, 5, 2, 0, 148]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17]
[C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys] [N/A, ]
[C:\Program Files\Thunder Network\Thunder\iEmbed.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 12]
[C:\Program Files\Thunder Network\Thunder\RegisterDll.dll] [Thunder Networking Technologies,LTD, 1, 2, 0, 4]
[C:\Program Files\Thunder Network\Thunder\FloatBar.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
[C:\Program Files\Thunder Network\Thunder\Plugins\TingTing\TingTing.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 7]
[C:\WINDOWS\system32\yxcsbhlp.dll] [N/A, ]
[C:\WINDOWS\system32\ypcqchlp.dll] [N/A, ]
[C:\WINDOWS\system32\zxmsawin.dll] [N/A, ]
[C:\Program Files\Thunder Network\Thunder\iTargetAd.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 46]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0]
[C:\WINDOWS\system32\ptjhchlp.dll] [N/A, ]
[C:\WINDOWS\system32\mpwdbapi.dll] [N/A, ]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17]
[C:\WINDOWS\system32\ttCBDCBD1049.dll] [N/A, ]
[C:\WINDOWS\system32\zjydcx.dll] [N/A, ]
[C:\WINDOWS\system32\dqDABDAB1071.dll] [N/A, ]
[C:\WINDOWS\system32\dqBAIBAI1067.dll] [N/A, ]
[C:\WINDOWS\system32\dqMYSMYS1049.dll] [N/A, ]
[C:\WINDOWS\system32\dqSHYSHY1053.dll] [N/A, ]
[C:\WINDOWS\system32\dqQACQAC1044.dll] [N/A, ]
[C:\WINDOWS\system32\dqHADHAD1069.dll] [N/A, ]
[C:\WINDOWS\system32\dqSADSAD1042.dll] [N/A, ]
[C:\WINDOWS\system32\dqWLVWLV1014.dll] [N/A, ]
[C:\WINDOWS\system32\ttKAFKAF1072.dll] [N/A, ]
[C:\WINDOWS\system32\dqDLQDLQ1007.dll] [N/A, ]
[C:\WINDOWS\system32\ttDXYDXY1013.dll] [N/A, ]
[C:\WINDOWS\system32\dqDXYDXY1006.dll] [N/A, ]
[PID: 3536 / user][D:\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17]
[C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys] [N/A, ]
[C:\WINDOWS\system32\zxmsawin.dll] [N/A, ]
[C:\WINDOWS\system32\ypcqchlp.dll] [N/A, ]
[C:\WINDOWS\system32\yxcsbhlp.dll] [N/A, ]
[C:\WINDOWS\system32\zjydcx.dll] [N/A, ]
[C:\WINDOWS\system32\ptjhchlp.dll] [N/A, ]
[C:\WINDOWS\system32\mpwdbapi.dll] [N/A, ]
[D:\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 yu.8s7.net
127.0.0.1 1.jopanqc.com
127.0.0.1 2.joppnqq.com
127.0.0.1 wg.47255.com
127.0.0.1 1.joppnqq.com
127.0.0.1 xxx.m111.biz
127.0.0.1 1.jopenqc.com
127.0.0.1 1.jopenkk.com
127.0.0.1 xxx.vh7.biz
127.0.0.1 xxx.j41m.com
127.0.0.1 3.joppnqq.com
127.0.0.1 d.93se.com
127.0.0.1
www.868wg.com127.0.0.1 xxx.mmma.biz
127.0.0.1 ilove.com
127.0.0.1 tp.shpzhan.cn
127.0.0.1
www.tomwg.com127.0.0.1
www.cike007.cn127.0.0.1
www.22aaa.com127.0.0.1 xx.exiao01.com
127.0.0.1
www.exiao01.com127.0.0.1
www.exiao01.com127.0.0.1 new.749571.com
127.0.0.1 xtx.kv8.info
127.0.0.1 cao.kv8.info
127.0.0.1 1.jopmmqq.com
127.0.0.1 171817.171817.com
127.0.0.1 d2.llsging.com
127.0.0.1 down.malasc.cn
127.0.0.1 llboss.com
127.0.0.1 nx.51ylb.cn
127.0.0.1 my.531jx.cn
127.0.0.1 qqq.dzydhx.com
127.0.0.1 qqq.hao1658.com
127.0.0.1
www.333292.com127.0.0.1 down.18dd.net
127.0.0.1 up.22x44.com
127.0.0.1 gxgxy.net
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 936, C:\WINPENJR\WIN32\PPHIDPAD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 976, C:\WINDOWS\VM_STI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 684, C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3820, C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\THUNDER.EXE]
==================================
API HOOK
入口点错误:NtCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003C3E0D)
入口点错误:NtWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003C3EAD)
入口点错误:ZwCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003C3E0D)
入口点错误:ZwWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003C3EAD)
==================================
隐藏进程
N/A
==================================
[/CODE]