浏览器加载项
[QQCycloneHelper Class]
{00000000-12C9-4305-82F9-43058F20E8D2} <D:\QQDownload\QQIEHelper01.dll, 腾讯公司>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx, >
[]
{21334231-6DED-436B-9E63-E45AAA9DA107} <C:\WINDOWS\system32\mazpafavca.dll, Microsoft Inc.>
[]
{296E2539-1A71-44AE-9864-9C083517BD36} <C:\WINDOWS\system32\ssstxqludztqt.dll, N/A>
[]
{9B753C26-9E77-4C96-B7A8-4ACB70025974} <C:\WINDOWS\system32\rvhjuwelpq.dll, Microsoft Inc.>
[解霸]
{367E0A21-8601-4986-9C9A-153BF5ACA118} <C:\HEROSOFT\Hero3000\MPLAYER.EXE, N/A>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[金山快译(&K)]
{6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <C:\PROGRA~1\Kingsoft\FASTAI~1\IEBand.dll, >
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\System32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[EditCtrl Class]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\System32\aliedit\aliedit.dll, >
[IEAnimBehaviorFactory Class]
{A4639D2F-774E-11D3-A490-00C04F6843FB} <C:\PROGRA~1\COMMON~1\MICROS~1\MSORun\MSORUN.DLL, Microsoft Corporation>
[XMP Class]
{6483F145-A768-4C41-AACC-52D4D7845851} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work, >
[XDRM]
{693571CB-54A3-4E90-9D52-EEAE1334E2D3} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xdrm.dll_1_work, >
[WangWangObj Class]
{6E213FC7-DD5A-4115-B7E6-D4C7838C361E} <D:\淘宝网\淘宝旺旺\WangWangX4.dll, 阿里软件(中国)有限公司>
[RMGetLicense Class]
{A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\System32\msnetobj.dll, Microsoft Corporation>
[XPPlayer Class]
{F3E70CEA-956E-49CC-B444-73AFE593AD7F} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\pplayer.dll_1_work, Thunder>
[&使用超级旋风下载]
<D:\QQDownload\geturl.htm, N/A>
[&使用超级旋风下载全部链接]
<D:\QQDownload\getAllurl.htm, N/A>
[导出到 Microsoft Excel(&x)]
<res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000, N/A>
[添加到QQ表情]
<D:\QQDownload\AddEmotion.htm, N/A>
[解霸实时播放]
<C:\HEROSOFT\Hero3000\MPURLGET.HTM, N/A>
==================================
正在运行的进程
[PID: 780][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 896][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 924][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1557 (xpsp2_gdr.040517-1325)]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[C:\WINDOWS\system32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 976][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 988][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[PID: 1156][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[PID: 1324][E:\殺毒\Rising\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.28]
[PID: 1352][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[PID: 952][E:\殺毒\Rising\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.23]
[E:\殺毒\Rising\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[E:\殺毒\Rising\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[E:\殺毒\Rising\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[E:\殺毒\Rising\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 20.0.0.0]
[E:\殺毒\Rising\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.18]
[PID: 1252][E:\殺毒\Rising\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 20.0.01.20]
[C:\WINDOWS\System32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\System32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\System32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[E:\殺毒\Rising\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[E:\殺毒\Rising\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[E:\殺毒\Rising\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[E:\殺毒\Rising\Rising\Rav\recomp.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 39]
[E:\殺毒\Rising\Rising\Rav\refs.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17]
[E:\殺毒\Rising\Rising\Rav\viruslib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26]
[E:\殺毒\Rising\Rising\Rav\relibldr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[E:\殺毒\Rising\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0]
[E:\殺毒\Rising\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.18]
[E:\殺毒\Rising\Rising\Rav\MonRule.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.29]
[E:\殺毒\Rising\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4]
[E:\殺毒\Rising\Rising\Rav\Rsguilib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 89]
[E:\殺毒\Rising\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0]
[PID: 284][C:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[E:\殺毒\新建文件夹\FTCMon.dll] [木马清道夫监控模块, 4.2.0.0]
[PID: 2604][C:\WINDOWS\System32\taskmgr.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[E:\殺毒\新建文件夹\FTCMon.dll] [木马清道夫监控模块, 4.2.0.0]
[PID: 2988][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[E:\殺毒\新建文件夹\FTCMon.dll] [木马清道夫监控模块, 4.2.0.0]
[C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17]
[C:\WINDOWS\System32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
[C:\WINDOWS\System32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\mazpafavca.dll] [Microsoft Inc., 1.0.0.0]
[C:\WINDOWS\system32\rvhjuwelpq.dll] [Microsoft Inc., 1.0.0.0]
[E:\殺毒\Rising\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll] [Symantec Corporation, 8.1.0.821]
[E:\殺毒\新建文件夹\FTCCommenu.dll] [Fygsoft and Microsoft, 3.0.0.71]
[PID: 2296][C:\WINDOWS\System32\conime.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[E:\殺毒\新建文件夹\FTCMon.dll] [木马清道夫监控模块, 4.2.0.0]
[PID: 2896][E:\殺毒\Maxthon2\Maxthon.exe] [Maxthon International ltd., 2, 1, 2, 649]
[E:\殺毒\Maxthon2\mxpp.dll] [Maxthon International ltd., 1, 0, 0, 117]
[E:\殺毒\Maxthon2\MxSk.dll] [Maxthon, 1, 0, 0, 358]
[E:\殺毒\Maxthon2\MxProxy2.dll] [Maxthon International ltd., 1, 0, 0, 4033]
[E:\殺毒\Maxthon2\MxExt.dll] [N/A, ]
[E:\殺毒\Maxthon2\MxUI.dll] [Maxthon International, 3, 3, 0, 3]
[C:\WINDOWS\System32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[E:\殺毒\新建文件夹\FTCMon.dll] [木马清道夫监控模块, 4.2.0.0]
[E:\殺毒\Maxthon2\mxtool.dll] [, 1, 0, 0, 1]
[E:\殺毒\Maxthon2\maxzlib.dll] [, 1.2.3]
[E:\殺毒\Maxthon2\Modules\MxPageSearch\MxPageSearch.dll] [Maxthon International ltd., 1,0,0,1330]
[E:\殺毒\Maxthon2\Modules\MxWebBoost\MxWebBoost.dll] [Maxthon, 1,0,2,1259]
[E:\殺毒\Maxthon2\mxdb.dll] [Max, 3, 5, 3, 125]
[C:\WINDOWS\System32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[E:\殺毒\Maxthon2\Modules\MxHistory\MxHistory.dll] [Maxthon International ltd., 1, 0, 0, 7]
[E:\殺毒\Rising\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[C:\WINDOWS\System32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0]
[C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\UNISPIM.IME] [北京清华紫光软件股份有限公司, 3.0.0.3045]
[D:\QQDownload\QQIEHelper01.dll] [腾讯公司, 1, 1, 0, 5]
[PID: 2592][E:\殺毒\SRE9d2c65c3\修改的2.4版SREng.EXE] [1111, 2..4]
[E:\殺毒\新建文件夹\FTCMon.dll] [木马清道夫监控模块, 4.2.0.0]
[C:\WINDOWS\System32\ESPI11.dll] [DYWT, 1, 1, 0, 0]
[E:\殺毒\Rising\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
C:\WINDOWS\System32\ESPI11.dll(DYWT, ESPI)
MSAFD Tcpip [UDP/IP]
C:\WINDOWS\System32\ESPI11.dll(DYWT, ESPI)
MSAFD Tcpip [RAW/IP]
C:\WINDOWS\System32\ESPI11.dll(DYWT, ESPI)
RSVP UDP Service Provider
C:\WINDOWS\System32\ESPI11.dll(DYWT, ESPI)
RSVP TCP Service Provider
C:\WINDOWS\System32\ESPI11.dll(DYWT, ESPI)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================
API HOOK
入口点错误:FreeLibrary (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0x5F000031)
==================================
隐藏进程
[373] E:\殺毒\新建文件夹\Trojanwall.exe
==================================
[/CODE]