[C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1008 / 龙龙][f:\Program Files\Tencent\qq\QQ.exe] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQBaseClassInDll.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQHelperDll.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\BasicCtrlDll.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[f:\Program Files\Tencent\qq\MSIMG32.dll] [N/A, ]
[F:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006]
[C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[f:\Program Files\Tencent\qq\FinePlus.dll] [N/A, ]
[f:\Program Files\Tencent\qq\fphelper.dll] [N/A, ]
[f:\Program Files\Tencent\qq\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[f:\Program Files\Tencent\qq\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[f:\Program Files\Tencent\qq\QQAPI.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\LoginCtrl.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\LoginCtrlRes.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQRes.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQMainFrame.dll] [N/A, ]
[f:\Program Files\Tencent\qq\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[f:\Program Files\Tencent\qq\UnReadMsgMgr.dll] [N/A, ]
[f:\Program Files\Tencent\qq\QQPlugin.dll] [N/A, ]
[f:\Program Files\Tencent\qq\CQQApplication.dll] [N/A, ]
[f:\Program Files\Tencent\qq\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[f:\Program Files\Tencent\qq\NewSkin.dll] [TENCENT, 8,0,713,1791]
[f:\Program Files\Tencent\qq\MailSummary.dll] [TENCENT, 8,0,775,1803]
[C:\Program Files\Bonjour\mdnsNSP.dll] [Apple Inc., 1,0,4,12]
[f:\Program Files\Tencent\qq\QQSpace.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\vbscript.dll] [N/A, ]
[f:\Program Files\Tencent\qq\encode.dll] [Microsoft Corporation, 5.6.0.8825]
[C:\WINDOWS\system32\xunyount.dll] [N/A, ]
[f:\Program Files\Tencent\qq\msdmo.dll] [, ]
[f:\Program Files\Tencent\qq\QQKnowledgeSearch.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\OEMApplication.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQGroupMng.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQAvatar.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[f:\Program Files\Tencent\qq\QQAllInOne.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\SCCore.dll] [TENCENT, 1, 6, 0, 2]
[f:\Program Files\Tencent\qq\CameraDll.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQPet.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQSysMsgMng.dll] [N/A, ]
[f:\Program Files\Tencent\qq\UserDefinedHead.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQConfigPlugin.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQCustomFace.dll] [N/A, ]
[f:\Program Files\Tencent\qq\QRingMng.dll] [N/A, ]
[f:\Program Files\Tencent\qq\LongConnection.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\PhoneAPI.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[f:\Program Files\Tencent\qq\BQQApplication.dll] [N/A, ]
[f:\Program Files\Tencent\qq\PersonalDesktop.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\ImageOle.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQLiveQMng.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQSceneMng.dll] [N/A, ]
[f:\Program Files\Tencent\qq\GroupConnection.dll] [TENCENT, 8,0,775,1803]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]
[C:\Program Files\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]
[f:\Program Files\Tencent\qq\CommercesMng.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 330]
[C:\WINDOWS\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[f:\Program Files\Tencent\qq\QQMagicFace.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 0, 1, 10]
[f:\Program Files\Tencent\qq\QQDoctor\TSVulMdw.dat] [TENCENT, 2007, 12, 18, 3]
[PID: 1404 / 龙龙][f:\Program Files\Tencent\qq\QQ.exe] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQBaseClassInDll.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQHelperDll.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\BasicCtrlDll.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[f:\Program Files\Tencent\qq\MSIMG32.dll] [N/A, ]
[F:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006]
[C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[f:\Program Files\Tencent\qq\FinePlus.dll] [N/A, ]
[f:\Program Files\Tencent\qq\fphelper.dll] [N/A, ]
[f:\Program Files\Tencent\qq\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[f:\Program Files\Tencent\qq\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[f:\Program Files\Tencent\qq\QQAPI.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\LoginCtrl.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\LoginCtrlRes.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQRes.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQMainFrame.dll] [N/A, ]
[f:\Program Files\Tencent\qq\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[f:\Program Files\Tencent\qq\QQPlugin.dll] [N/A, ]
[f:\Program Files\Tencent\qq\UnReadMsgMgr.dll] [N/A, ]
[f:\Program Files\Tencent\qq\CQQApplication.dll] [N/A, ]
[f:\Program Files\Tencent\qq\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[f:\Program Files\Tencent\qq\NewSkin.dll] [TENCENT, 8,0,713,1791]
[f:\Program Files\Tencent\qq\MailSummary.dll] [TENCENT, 8,0,775,1803]
[C:\Program Files\Bonjour\mdnsNSP.dll] [Apple Inc., 1,0,4,12]
[f:\Program Files\Tencent\qq\QQSpace.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\vbscript.dll] [N/A, ]
[f:\Program Files\Tencent\qq\encode.dll] [Microsoft Corporation, 5.6.0.8825]
[C:\WINDOWS\system32\xunyount.dll] [N/A, ]
[f:\Program Files\Tencent\qq\msdmo.dll] [, ]
[f:\Program Files\Tencent\qq\QQKnowledgeSearch.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\OEMApplication.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQGroupMng.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQAvatar.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[f:\Program Files\Tencent\qq\QQAllInOne.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\SCCore.dll] [TENCENT, 1, 6, 0, 2]
[f:\Program Files\Tencent\qq\CameraDll.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQPet.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQSysMsgMng.dll] [N/A, ]
[f:\Program Files\Tencent\qq\UserDefinedHead.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQConfigPlugin.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQCustomFace.dll] [N/A, ]
[f:\Program Files\Tencent\qq\QRingMng.dll] [N/A, ]
[f:\Program Files\Tencent\qq\LongConnection.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\PhoneAPI.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[f:\Program Files\Tencent\qq\BQQApplication.dll] [N/A, ]
[f:\Program Files\Tencent\qq\PersonalDesktop.dll] [TENCENT, 8,0,775,1803]
[C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[f:\Program Files\Tencent\qq\ImageOle.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQLiveQMng.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\GroupConnection.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\CommercesMng.dll] [TENCENT, 8,0,775,1803]
[f:\Program Files\Tencent\qq\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 330]
[f:\Program Files\Tencent\qq\QQSceneMng.dll] [N/A, ]
[PID: 3036 / 龙龙][f:\Program Files\Tencent\qq\TXPlatform.exe] [Tencent, 1, 0, 170, 0]
[C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[F:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006]
[PID: 3624 / 龙龙][G:\网站\工具\CuteFTP8\CuteFTP8\cuteftppro.exe] [GlobalSCAPE Texas, LP., 8,0,0,0]
[G:\网站\工具\CuteFTP8\CuteFTP8\filecryptik.dll] [N/A, ]
[C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[F:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[G:\网站\工具\CuteFTP8\CuteFTP8\Default.lng] [GlobalSCAPE Texas, LP., 8,0,2,0]
[G:\网站\工具\CuteFTP8\CuteFTP8\Compress.dll] [GlobalSCAPE Texas, LP., 8,0,2,0]
[PID: 3692 / 龙龙][G:\网站\工具\CuteFTP8\CuteFTP8\ftpte.exe] [GlobalSCAPE Texas, LP., 8,0,2,0]
[G:\网站\工具\CuteFTP8\CuteFTP8\filecryptik.dll] [N/A, ]
[C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[F:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[G:\网站\工具\CuteFTP8\CuteFTP8\Default.lng] [GlobalSCAPE Texas, LP., 8,0,2,0]
[G:\网站\工具\CuteFTP8\CuteFTP8\FolderMonitor.dll] [GlobalSCAPE Texas, LP., 8,0,2,0]
[G:\网站\工具\CuteFTP8\CuteFTP8\SiteBackup.dll] [GlobalSCAPE Texas, LP., 8,0,2,0]
[C:\WINDOWS\system32\xunyount.dll] [N/A, ]
[PID: 344 / 龙龙][C:\Program Files\Internet Explorer\IExplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[F:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006]
[F:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.16]
[f:\Program Files\FlashGet Network\Flashget\ComDlls\bhoCATCH.dll] [FlashGet, 2, 0, 2, 1011]
[C:\Program Files\CMBCHINA\WebProtect\WebProtect.dll] [China Merchants Bank, 1, 0, 0, 1]
[F:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 61]
[F:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 17]
[F:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
[C:\WINDOWS\system32\xunyount.dll] [N/A, ]
[C:\Program Files\Bonjour\mdnsNSP.dll] [Apple Inc., 1,0,4,12]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]
[C:\Program Files\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]
[PID: 680 / 龙龙][C:\WINDOWS\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[F:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006]
[C:\WINDOWS\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[C:\Program Files\Bonjour\mdnsNSP.dll] [Apple Inc., 1,0,4,12]
[C:\WINDOWS\system32\xunyount.dll] [N/A, ]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
xunyou over MSAFD Tcpip [TCP/IP]
C:\WINDOWS\system32\xunyount.dll(, N/A)
xunyou over MSAFD Tcpip [UDP/IP]
C:\WINDOWS\system32\xunyount.dll(, N/A)
xunyou over MSAFD Tcpip [RAW/IP]
C:\WINDOWS\system32\xunyount.dll(, N/A)
xunyou
C:\WINDOWS\system32\xunyount.dll(, N/A)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 yu.8s7.net
127.0.0.1 1.jopanqc.com
127.0.0.1 2.joppnqq.com
127.0.0.1 wg.47255.com
127.0.0.1 1.joppnqq.com
127.0.0.1 xxx.m111.biz
127.0.0.1 1.jopenqc.com
127.0.0.1 1.jopenkk.com
127.0.0.1 xxx.vh7.biz
127.0.0.1 xxx.j41m.com
127.0.0.1 3.joppnqq.com
127.0.0.1 d.93se.com
127.0.0.1
www.868wg.com127.0.0.1 xxx.mmma.biz
127.0.0.1 ilove.com
127.0.0.1 tp.shpzhan.cn
127.0.0.1
www.tomwg.com127.0.0.1
www.cike007.cn127.0.0.1
www.22aaa.com127.0.0.1 xx.exiao01.com
127.0.0.1
www.exiao01.com127.0.0.1
www.exiao01.com127.0.0.1 new.749571.com
127.0.0.1 xtx.kv8.info
127.0.0.1 cao.kv8.info
127.0.0.1 1.jopmmqq.com
127.0.0.1 171817.171817.com
127.0.0.1 d2.llsging.com
127.0.0.1 down.malasc.cn
127.0.0.1 llboss.com
127.0.0.1 nx.51ylb.cn
127.0.0.1 my.531jx.cn
127.0.0.1 qqq.dzydhx.com
127.0.0.1 qqq.hao1658.com
127.0.0.1
www.333292.com127.0.0.1 down.18dd.net
127.0.0.1 up.22x44.com
127.0.0.1 aaa.faba01.com
127.0.0.1 bad.tqdlt.cn
127.0.0.1 1.chsipo.com
127.0.0.1 c3.aishangai.net
127.0.0.1 c2.aishangai.net
127.0.0.1 xxx.188dm.com
127.0.0.1 x2.1a2b3c1.com
127.0.0.1 d1.163500.net
127.0.0.1 down.google-serv.cn
127.0.0.1 gxgxy.net
127.0.0.1 c0mo.com
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 540, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 244, C:\PROGRAM FILES\COMMON FILES\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3624, G:\网站\工具\CUTEFTP8\CUTEFTP8\CUTEFTPPRO.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3624, G:\网站\工具\CUTEFTP8\CUTEFTP8\CUTEFTPPRO.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3692, G:\网站\工具\CUTEFTP8\CUTEFTP8\FTPTE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3692, G:\网站\工具\CUTEFTP8\CUTEFTP8\FTPTE.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]