[C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ]
[C:\Program Files\Eset\pr_imon.dll] [N/A, ]
[PID: 196 / PEPSI][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4131]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2500]
[PID: 460 / PEPSI][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Eset\nodshex.dll] [N/A, ]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\aetsprov.dll] [A.E.T. Europe B.V., 2.3.0.9]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.3790.3646 built by: DNSRV(bld4act)]
[PID: 1044 / PEPSI][C:\Program Files\360safe\safemon\360tray.exe] [奇虎网, 3, 6, 4, 3002]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
[C:\Program Files\360safe\safemon\SafeKrnl.dll] [奇虎网, 3, 6, 0, 1001]
[C:\Program Files\360safe\AntiAdwa.dll] [360Safe.com, 3, 6, 3, 1001]
[C:\Program Files\360safe\live.dll] [360safe.com, 1, 0, 1, 1021]
[C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ]
[C:\Program Files\Eset\pr_imon.dll] [N/A, ]
[PID: 1048 / PEPSI][C:\Program Files\Eset\nod32kui.exe] [Eset , 2, 70, 39 ]
[C:\Program Files\Eset\nod32rui.dll] [N/A, ]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
[C:\Program Files\Eset\pu_amon.dll] [Eset , 2, 70, 39 ]
[C:\Program Files\Eset\pr_amon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pu_dmon.dll] [Eset , 2, 70, 39 ]
[C:\Program Files\Eset\pr_dmon.dll] [N/A, ]
[C:\Program Files\Eset\pu_emon.dll] [Eset , 2, 70, 39 ]
[C:\Program Files\Eset\pr_emon.dll] [N/A, ]
[C:\Program Files\Eset\pu_imon.dll] [Eset , 2, 70, 39 ]
[C:\Program Files\Eset\pr_imon.dll] [N/A, ]
[C:\Program Files\Eset\pu_nod32.dll] [Eset , 2, 70, 39 ]
[C:\Program Files\Eset\pr_nod32.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pu_upd.dll] [Eset , 2, 70, 39 ]
[C:\Program Files\Eset\pr_upd.dll] [N/A, ]
[PID: 1096 / PEPSI][C:\WINDOWS\system32\SafeSignCertReg.exe] [A.E.T. Europe B.V., 2.0.0.2]
[PID: 1176 / PEPSI][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
[PID: 2476 / PEPSI][C:\WINDOWS\system32\cmd.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2492 / PEPSI][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
[PID: 3444 / PEPSI][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
[E:\BT系列\电影\eREAD6.0\IEeREAD.dll] [, 1, 0, 0, 1]
[E:\BT系列\电影\eREAD6.0\MFC80U.DLL] [Microsoft Corporation, 8.00.50727.42]
[E:\BT系列\电影\eREAD6.0\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42]
[C:\Program Files\FlashGet\jccatch.dll] [www.flashget.com, 1, 8, 1, 1006]
[F:\bttt\BitComet\tools\BitCometBHO_1.1.11.30.dll] [BitComet, 20071130]
[E:\BT系列\电影\eREAD6.0\WebHook.dll] [, 1, 0, 0, 1]
[E:\BT系列\电影\eREAD6.0\MFC80.DLL] [Microsoft Corporation, 8.00.50727.42]
[E:\BT系列\电影\eREAD6.0\ATL80.DLL] [Microsoft Corporation, 8.00.50727.42]
[E:\BT系列\电影\eREAD6.0\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.42]
[C:\Program Files\FlashGet\getflash.dll] [www.flashget.com, 1, 8, 1, 1002]
[C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ]
[C:\Program Files\Eset\pr_imon.dll] [N/A, ]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\JPWB.IME] [常诚研制, 4.00.950]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\WINDOWS\system32\xpsp3res.dll] [Microsoft Corporation, 5.1.2600.3157 (xpsp_sp2_gdr.070614-0013)]
[C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.5510]
[PID: 1616 / PEPSI][F:\bttt\BitComet\BitComet.exe] [www.BitComet.com, 0.97]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
[C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ]
[C:\Program Files\Eset\pr_imon.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 276 / PEPSI][C:\Program Files\FlashGet\flashget.exe] [FlashGet.com, 1, 8, 2, 1001]
[C:\Program Files\FlashGet\FGBTCORE.dll] [, 1, 0, 0, 36]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
[C:\Program Files\FlashGet\fgupdate.dll] [www.flashget.com, 1, 8, 1, 1002]
[C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ]
[C:\Program Files\Eset\pr_imon.dll] [N/A, ]
[PID: 3188 / PEPSI][C:\Program Files\WinRAR\WinRAR.exe] [N/A, ]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.3790.3646 built by: DNSRV(bld4act)]
[PID: 2248 / PEPSI][C:\DOCUME~1\PEPSI\LOCALS~1\Temp\Rar$EX00.391\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
[C:\DOCUME~1\PEPSI\LOCALS~1\Temp\Rar$EX00.391\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[C:\WINDOWS\system32\aetsprov.dll] [A.E.T. Europe B.V., 2.3.0.9]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ]
[C:\Program Files\Eset\pr_imon.dll] [N/A, ]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
NOD32 protected [MSAFD Tcpip [TCP/IP]]
C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [MSAFD Tcpip [UDP/IP]]
C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [MSAFD Tcpip [RAW/IP]]
C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [RSVP UDP Service Provider]
C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [RSVP TCP Service Provider]
C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32
C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 locator.metadata.windowsmedia.com
127.0.0.1 onlinestore.smgbb.cn
127.127.127.127 gameon9.com
127.127.127.127 wanbaa.com
127.127.127.127 woyaowg.com
127.127.127.127 uowg.com
127.127.127.127 lll2.com
127.127.127.127 waiguadown.net
127.127.127.127 waiguachengshi.com
127.127.127.127 wg22.com
127.127.127.127 twt8.com
127.127.127.127 blog.sina.com.tw
127.127.127.127 361uc.com
127.127.127.127 pzcf.com
127.127.127.127 bbs.129.com.tw
127.127.127.127 www1.129.tw
127.127.127.127 www1.129.com.tw
127.127.127.127 129.tw
127.127.127.127 129.com.tw
127.127.127.127 www.129.com.tw
127.127.127.127 www.129.tw
127.127.127.127 www1.wgking.com
127.127.127.127 wgking.com
127.127.127.127 www.wgking.com
127.127.127.127 www.wgking.com.tw
127.127.127.127 bbs.wgking.com
127.127.127.127 yoyo-do.com
127.127.127.127 www.yoyo-do.com
127.127.127.127 www56.yoyo-do.com
127.127.127.127 www.wg88.net
127.127.127.127 www.8bot.net
127.127.127.127 www.cabww.com
127.127.127.127 cabww.com
127.127.127.127 bbs.cabww.com
127.127.127.127 126.com.tw
127.127.127.127 126.tw
127.127.127.127 twgamewg.com
127.127.127.127 hottw.com
127.127.127.127 hhoott.com
127.127.127.127 sealgame.com
127.127.127.127 onlinegamewg.com
127.127.127.127 tw-yahooo.com
127.127.127.127 wowgb.com
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 1044, C:\PROGRAM FILES\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 276, C:\PROGRAM FILES\FLASHGET\FLASHGET.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3188, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A