[C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\Program Files\Alwil Software\Avast4\aswCmnB.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\Program Files\Alwil Software\Avast4\aswCmnS.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\Program Files\Alwil Software\Avast4\Aavm4h.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\Program Files\Alwil Software\Avast4\AavmRpch.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\Program Files\Alwil Software\Avast4\ashTask.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\Program Files\Alwil Software\Avast4\aswAux.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\Program Files\Alwil Software\Avast4\ChineseS\Base.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\Program Files\Alwil Software\Avast4\aswEngin.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\Program Files\Alwil Software\Avast4\aswScan.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\Program Files\Alwil Software\Avast4\ashWsFtr.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\AhResWs.dll] [ALWIL Software, 4, 8, 1287, 0]
[PID: 2176 / SYSTEM][C:\Program Files\PC Connectivity Solution\ServiceLayer.exe] [Nokia., 7, 0, 13, 0]
[C:\Program Files\PC Connectivity Solution\PCCS_DBEngine.dll] [Nokia, 7, 0, 0, 0]
[C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 8, 1287, 0]
[PID: 2612 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\AppPatch\AcGenral.DLL] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2932 / SYSTEM][C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe] [, 7, 0, 5, 0]
[C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 8, 1287, 0]
[PID: 2960 / SYSTEM][C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe] [, 7, 0, 1, 0]
[C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 8, 1287, 0]
[PID: 3428 / jxslglgs][D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQ.exe] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQHelperDll.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\BasicCtrlDll.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\MSIMG32.dll] [N/A, ]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQBaseClassInDll.dll] [TENCENT, 8,0,775,1803]
[C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 8, 1287, 0]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\FinePlus.dll] [N/A, ]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\fphelper.dll] [N/A, ]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQAPI.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQRes.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\WizardCtrl.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQMainFrame.dll] [N/A, ]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\LoginCtrl.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\LoginCtrlRes.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQPlugin.dll] [N/A, ]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\UnReadMsgMgr.dll] [N/A, ]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\CQQApplication.dll] [N/A, ]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\NewSkin.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\MailSummary.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQSpace.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\vbscript.dll] [N/A, ]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\aqing.dll] [Microsoft Corporation, 5.6.0.8825]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQKnowledgeSearch.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\OEMApplication.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQGroupMng.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQAllInOne.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\SCCore.dll] [TENCENT, 1, 6, 0, 2]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\CameraDll.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQPet.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQSysMsgMng.dll] [N/A, ]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\UserDefinedHead.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQConfigPlugin.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQCustomFace.dll] [N/A, ]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QRingMng.dll] [N/A, ]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQAvatar.dll] [N/A, ]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\LongConnection.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\PhoneAPI.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\ImageOle.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQLiveQMng.dll] [TENCENT, 8,0,775,1803]
[C:\Program Files\Alwil Software\Avast4\AhAScr.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\Aavm4h.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\AavmRpch.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\PROGRA~1\ALWILS~1\Avast4\ashBase.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\PROGRA~1\ALWILS~1\Avast4\aswCmnOS.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\aswCmnB.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\aswCmnS.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\ashTask.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\aswAux.dll] [ALWIL Software, 4, 8, 1287, 0]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\GroupConnection.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\BQQApplication.dll] [N/A, ]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\PersonalDesktop.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQSceneMng.dll] [N/A, ]
[C:\WINDOWS\system32\CHENHU4.IME] [chenhu, 5.8]
[C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部
www.wn51.com, 2008, 3, 20, 1]
[C:\Program Files\ShiQiang\wnime\Dll32\wnpy_StatusWnd.dll] [深圳世强软件开发部
www.wn51.com, 2008, 3, 20, 1]
[C:\Program Files\ShiQiang\wnime\Dll32\wnpy_CompWnd.dll] [深圳世强软件开发部
www.wn51.com, 2008, 3, 20, 1]
[C:\Program Files\ShiQiang\wnime\Dll32\wnpy_Query.dll] [深圳世强软件开发部
www.wn51.com, 2008, 3, 20, 1]
[C:\Program Files\ShiQiang\wnime\dll32\UserActionInfo.dll] [深圳世强软件开发部
www.wn51.com, 2008.6.20.1]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\CommercesMng.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 330]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQMagicFace.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\QQFileTransfer.dll] [TENCENT, 8,0,775,1803]
[D:\杂件\HFQQ2008-0415\HFQQ2008-0415\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 0, 1, 10]
[C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1007]
[C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx] [Adobe Systems, Inc., 10,0,22,87]
[PID: 3488 / jxslglgs][D:\杂件\HFQQ2008-0415\HFQQ2008-0415\TXPlatform.exe] [Tencent, 1, 0, 170, 0]
[C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 8, 1287, 0]
[PID: 3700 / jxslglgs][E:\下载软件\江南证券大智慧\internet\hypwise.exe] [大智慧, 1, 0, 0, 1]
[E:\下载软件\江南证券大智慧\internet\MFC42.DLL] [Microsoft Corporation, 6.00.8447.0]
[C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 8, 1287, 0]
[PID: 1200 / jxslglgs][C:\Program Files\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 6, 5, 18]
[C:\Program Files\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1007]
[C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\Program Files\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[C:\Program Files\Alwil Software\Avast4\AhAScr.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\Aavm4h.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\AavmRpch.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\PROGRA~1\ALWILS~1\Avast4\ashBase.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\PROGRA~1\ALWILS~1\Avast4\aswCmnOS.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\aswCmnB.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\aswCmnS.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\ashTask.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\aswAux.dll] [ALWIL Software, 4, 8, 1287, 0]
[C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx] [Adobe Systems, Inc., 10,0,22,87]
[PID: 1884 / jxslglgs][E:\下载软件\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210]
[PID: 1612 / jxslglgs][E:\下载软件\sreng2\SREb9cde47b.EXE] [Smallfrogs Studio, 2.7.0.1210]
[C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1007]
[C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 8, 1287, 0]
[E:\下载软件\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 yu.8s7.net
127.0.0.1 2.joppnqq.com
127.0.0.1 wg.47255.com
127.0.0.1 1.joppnqq.com
127.0.0.1 xxx.m111.biz
127.0.0.1 1.jopenqc.com
127.0.0.1 1.jopenkk.com
127.0.0.1 xxx.vh7.biz
127.0.0.1 xxx.j41m.com
127.0.0.1 3.joppnqq.com
127.0.0.1 d.93se.com
127.0.0.1
www.868wg.com127.0.0.1 xxx.mmma.biz
127.0.0.1 ilove.com
127.0.0.1 tp.shpzhan.cn
127.0.0.1
www.tomwg.com127.0.0.1
www.cike007.cn127.0.0.1
www.22aaa.com127.0.0.1 xx.exiao01.com
127.0.0.1
www.exiao01.com127.0.0.1
www.exiao01.com127.0.0.1 new.749571.com
127.0.0.1 xtx.kv8.info
127.0.0.1 cao.kv8.info
127.0.0.1 down.malasc.cn
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 252, C:\PROGRAM FILES\LENOVO\ENERGYCUT\UTILTY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2932, C:\PROGRAM FILES\PC CONNECTIVITY SOLUTION\TRANSPORTS\NCLUSBSRV.EXE]