==================================
正在运行的进程
[PID: 624][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 672 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 700 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 744 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 756 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 916 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\windows\system32\rpcss.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)]
[PID: 1016 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\windows\system32\rpcss.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)]
[PID: 1112 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1224 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1460 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.2696 (xpsp.050610-1527)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1636 / Administrator][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[F:\Program Files\ast\AST.dll] [超级巡警, 1.0.2.10]
[C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.11.6921]
[C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.6921]
[F:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 120]
[F:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_01.dll] [ShenZhen Thunder Networking Technologies,LTD, 1, 0, 0, 20]
[F:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_01.dll] [ShenZhen Thunder Networking Technologies,LTD, 1, 0, 0, 16]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\gdiplus.dll] [Microsoft Corporation, 5.1.3102.5581 (xpsp_sp3_qfe.080415-1416)]
[C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[F:\Program Files\StormII\spfa.dll] [北京暴风网际科技有限公司, 2, 7, 4, 2]
[C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[PID: 1804 / Administrator][F:\Program Files\ast\ast.exe] [超级巡警, 1, 8, 6, 119]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\MFC80CHS.DLL] [Microsoft Corporation, 8.00.50727.762]
[F:\Program Files\ast\common.dll] [超级巡警, 1, 4, 2, 32]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[F:\Program Files\ast\EngineSDK.dll] [超级巡警, 2, 2, 2, 61]
[F:\Program Files\ast\AST.dll] [超级巡警, 1.0.2.10]
[F:\Program Files\ast\AutoRun.dll] [超级巡警, 2, 2, 2, 26]
[F:\Program Files\ast\FileAnalyser.dll] [超级巡警, 1.0.1.11]
[F:\Program Files\ast\FileForceKiller.dll] [DSW Lab, 1, 0, 0, 1]
[F:\Program Files\ast\ManagerProcess.dll] [超级巡警, 1.3.4.13]
[F:\Program Files\ast\ManagerService.dll] [超级巡警, 1.0.6.4]
[F:\Program Files\ast\Monitor.dll] [超级巡警, 1, 7, 9, 42]
[F:\Program Files\ast\PortAssociate.dll] [超级巡警, 1.0.3.7]
[F:\Program Files\ast\StateViewer.dll] [超级巡警, 1, 0, 10, 18]
[F:\Program Files\ast\aScanCom.dll] [超级巡警, 2, 1, 2, 58]
[F:\Program Files\ast\ssdt.dll] [超级巡警, 1.0.2.4]
[F:\Program Files\ast\tIERepair.dll] [超级巡警, 1, 2, 2, 21]
[F:\Program Files\ast\tRubbishClear.dll] [超级巡警, 1, 5, 2, 25]
[F:\Program Files\ast\tSecurityOptimize.dll] [超级巡警, 1, 1, 2, 9]
[F:\Program Files\ast\zDiagnosticTool.dll] [超级巡警, 1.2.1.3]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[F:\Program Files\ast\KillModule.dll] [超级巡警, 1, 2, 2, 30]
[F:\Program Files\ast\MScaner.dll] [超级巡警, 1.0.0.26]
[F:\Program Files\ast\SKEngine.dll] [超级巡警, 1.6.5.12]
[F:\Program Files\ast\ScanAd.dll] [Secward Technologies, Inc., 1.0.1.2]
[F:\Program Files\ast\smart.dll] [超级巡警, 1.0.0.31]
[F:\Program Files\ast\unarc.dll] [超级巡警, 1.2.5]
[F:\Program Files\ast\SScanner.dll] [超级巡警, 1, 0, 6, 40]
[PID: 1884 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 184][C:\WINDOWS\system32\com\lsass.exe] [N/A, ]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[F:\Program Files\ast\AST.dll] [超级巡警, 1.0.2.10]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 1604][C:\WINDOWS\system32\com\smss.exe] [N/A, ]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[F:\Program Files\ast\AST.dll] [超级巡警, 1.0.2.10]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 2496 / SYSTEM][F:\Program Files\StormII\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 3, 15]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2668 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.11.6921]
[C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.6921]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 4060 / Administrator][F:\Program Files\StormII\Storm.exe] [北京暴风网际科技有限公司, 3, 8, 5, 15]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[F:\Program Files\ast\AST.dll] [超级巡警, 1.0.2.10]
[F:\Program Files\StormII\mps.dll] [北京暴风网际科技有限公司, 3, 8, 3, 27]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[F:\Program Files\StormII\MovieInfo.dll] [baofeng, 1, 0, 0, 1]
[F:\Program Files\StormII\jscript.dll] [Microsoft Corporation, 5.6.0.8831]
[F:\Program Files\StormII\media2.dll] [北京暴风网际科技有限公司, 5, 8, 7, 16]
[F:\Program Files\StormII\score.dll] [北京暴风网际科技有限公司, 2, 7, 9, 30]
[F:\Program Files\StormII\sexpert.dll] [北京暴风网际科技有限公司, 2, 7, 9, 30]
[F:\Program Files\StormII\sprobe.dll] [北京暴风网际科技有限公司, 3, 8, 2, 1]
[F:\Program Files\StormII\splayers.dll] [北京暴风网际科技有限公司, 3, 8, 3, 27]
[F:\Program Files\StormII\SubDecoder.dll] [北京暴风网际科技有限公司, 3, 8, 3, 27]
[F:\Program Files\StormII\rndrmgr.dll] [北京暴风网际科技有限公司, 3, 8, 4, 15]
[F:\PROGRA~1\StormII\Codec\DCBassSource.ax] [
http://www.dsp-worx.de, 1.1.1.0]
[F:\PROGRA~1\StormII\Codec\bass.dll] [Un4seen Developments, 2.3]
[F:\PROGRA~1\StormII\Codec\bass_aac.dll] [MaresWEB, 2.3.0.0]
[F:\PROGRA~1\StormII\Codec\bass_alac.dll] [MaresWEB, 2.3.0.0]
[F:\PROGRA~1\StormII\Codec\bass_ape.dll] [MaresWEB, 2.3.0.0]
[F:\PROGRA~1\StormII\Codec\bass_flac.dll] [Un4seen Developments, 2.3]
[F:\PROGRA~1\StormII\Codec\bass_mpc.dll] [MaresWEB, 2.3.0.0]
[F:\PROGRA~1\StormII\Codec\bass_tta.dll] [MaresWEB, 2.3.0.0]
[F:\PROGRA~1\StormII\Codec\bass_wv.dll] [MaresWEB, 2.3.0.0]
[PID: 3204 / Administrator][F:\Program Files\ZuoXiTong\srengs\SREngLdr.EXE] [Smallfrogs Studio, 2.7.1.1261]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[PID: 2316 / Administrator][F:\Program Files\ZuoXiTong\srengs\SRE796940c0.EXE] [Smallfrogs Studio, 2.7.1.1261]
[C:\WINDOWS\system32\dnsq.dll] [N/A, ]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[F:\Program Files\ast\AST.dll] [超级巡警, 1.0.2.10]
[F:\Program Files\ZuoXiTong\srengs\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 4060, F:\PROGRAM FILES\STORMII\STORM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3204, F:\PROGRAM FILES\ZUOXITONG\SRENGS\SRENGLDR.EXE]
==================================
计划任务
[已启用] SogouImeMgr.job
F:\PROGRA~1\SOGOUI~1\360~1.165\PinyinRepair.exe
==================================
API HOOK
入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: F:\Program Files\ast\AST.dll)
入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: F:\Program Files\ast\AST.dll)
入口点错误:OpenProcess (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\dnsq.dll)
==================================
隐藏进程
N/A
==================================
[/CODE]