正在运行的进程
[PID: 428 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 6.0.6002.18005 (lh_sp2rtm.090410-1830)]
[PID: 560 / SYSTEM][C:\Windows\system32\csrss.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 604 / SYSTEM][C:\Windows\system32\wininit.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 616 / SYSTEM][C:\Windows\system32\csrss.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 648 / SYSTEM][C:\Windows\system32\services.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 660 / SYSTEM][C:\Windows\system32\lsass.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 668 / SYSTEM][C:\Windows\system32\lsm.exe] [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 764 / SYSTEM][C:\Windows\system32\winlogon.exe] [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 856 / SYSTEM][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 916 / NETWORK SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\TcpIPDogL.dll] [城市热点资讯有限公司, 1, 0, 0, 164]
[PID: 952 / SYSTEM][C:\Windows\System32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1044 / LOCAL SERVICE][C:\Windows\System32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1068 / SYSTEM][C:\Windows\System32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\TcpIPDogL.dll] [城市热点资讯有限公司, 1, 0, 0, 164]
[PID: 1080 / SYSTEM][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\TcpIPDogL.dll] [城市热点资讯有限公司, 1, 0, 0, 164]
[PID: 1292 / NETWORK SERVICE][C:\Windows\system32\SLsvc.exe] [(Verified) Microsoft Corporation, 6.0.6002.18005 (lh_sp2rtm.090410-1830)]
[PID: 1356 / LOCAL SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1492 / NETWORK SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1636 / SYSTEM][C:\Windows\System32\spoolsv.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\TcpIPDogL.dll] [城市热点资讯有限公司, 1, 0, 0, 164]
[PID: 1660 / LOCAL SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\TcpIPDogL.dll] [城市热点资讯有限公司, 1, 0, 0, 164]
[PID: 1920 / NETWORK SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2004 / LOCAL SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 208 / SYSTEM][C:\Windows\System32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 344 / SYSTEM][C:\Windows\system32\SearchIndexer.exe] [(Verified) Microsoft Corporation, 7.00.6002.18005 (lh_sp2rtm.090410-1830)]
[PID: 840 / SYSTEM][C:\Windows\system32\taskeng.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2064 / YPing][C:\Windows\system32\taskeng.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\igfxTMM.dll] [Intel Corporation, 7.14.10.1666]
[PID: 2108 / YPing][C:\Windows\system32\Dwm.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\igdumdx32.dll] [Intel Corporation, 7.15.10.1666]
[C:\Windows\system32\igdumd32.dll] [Intel Corporation, 7.15.10.1666]
[PID: 2184 / YPing][C:\Windows\Explorer.EXE] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\igfxpph.dll] [Intel Corporation, 7.14.10.1666]
[C:\Windows\system32\hccutils.DLL] [Intel Corporation, 7.14.10.1666]
[C:\Windows\system32\igfxsrvc.dll] [Intel Corporation, 7.14.10.1666]
[C:\Windows\system32\igfxrCHS.lrc] [Intel Corporation, 7.14.10.1666]
[PID: 2352 / YPing][C:\Program Files\Windows Defender\MSASCui.exe] [Microsoft Corporation, 1.1.1600.0]
[C:\Windows\system32\TcpIPDogL.dll] [城市热点资讯有限公司, 1, 0, 0, 164]
[PID: 2364 / YPing][C:\Windows\System32\igfxtray.exe] [Intel Corporation, 7.14.10.1666]
[C:\Windows\System32\hccutils.DLL] [Intel Corporation, 7.14.10.1666]
[C:\Windows\system32\igfxsrvc.dll] [Intel Corporation, 7.14.10.1666]
[C:\Windows\system32\igfxrCHS.lrc] [Intel Corporation, 7.14.10.1666]
[C:\Windows\System32\igfxress.dll] [Intel Corporation, 7.14.10.1666]
[PID: 2376 / YPing][C:\Windows\System32\hkcmd.exe] [Intel Corporation, 7.14.10.1666]
[C:\Windows\System32\hccutils.DLL] [Intel Corporation, 7.14.10.1666]
[C:\Windows\system32\igfxsrvc.dll] [Intel Corporation, 7.14.10.1666]
[C:\Windows\system32\igfxrCHS.lrc] [Intel Corporation, 7.14.10.1666]
[PID: 2404 / YPing][C:\Windows\System32\igfxpers.exe] [Intel Corporation, 7.14.10.1666]
[C:\Windows\system32\igfxsrvc.dll] [Intel Corporation, 7.14.10.1666]
[PID: 2420 / YPing][C:\Program Files\Windows Sidebar\sidebar.exe] [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[C:\Windows\system32\icm32.dll] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\igdumdx32.dll] [Intel Corporation, 7.15.10.1666]
[C:\Windows\system32\igdumd32.dll] [Intel Corporation, 7.15.10.1666]
[PID: 2520 / YPing][C:\Windows\system32\igfxsrvc.exe] [Intel Corporation, 7.14.10.1666]
[C:\Windows\system32\igfxsrvc.dll] [Intel Corporation, 7.14.10.1666]
[C:\Windows\system32\igfxdev.dll] [Intel Corporation, 7.14.10.1666]
[PID: 3884 / SYSTEM][C:\Windows\system32\wbem\wmiprvse.exe] [(Verified) Microsoft Corporation, 6.0.6002.18005 (lh_sp2rtm.090410-1830)]
[PID: 1796 / YPing][D:\软件备份\wrar392sc.exe] [N/A, ]
[C:\Windows\system32\TcpIPDogL.dll] [城市热点资讯有限公司, 1, 0, 0, 164]
[PID: 3176 / YPing][D:\软件备份\wrar392sc.exe] [N/A, ]
[C:\Windows\system32\TcpIPDogL.dll] [城市热点资讯有限公司, 1, 0, 0, 164]
[PID: 2836 / YPing][D:\软件备份\wrar392sc.exe] [N/A, ]
[C:\Windows\system32\TcpIPDogL.dll] [城市热点资讯有限公司, 1, 0, 0, 164]
[PID: 2788 / YPing][D:\软件备份\wrar392sc.exe] [N/A, ]
[C:\Windows\system32\TcpIPDogL.dll] [城市热点资讯有限公司, 1, 0, 0, 164]
[PID: 3712 / YPing][C:\Program Files\深圳大学网络认证客户端\ishare_user.exe] [城市热点有限公司, 3, 73, 4, 3700]
[C:\Windows\system32\packet.dll] [CACE Technologies, Inc., 4.1.0.1753]
[C:\Windows\system32\TcpIPDogL.dll] [城市热点资讯有限公司, 1, 0, 0, 164]
[PID: 2800 / NETWORK SERVICE][C:\Windows\system32\wbem\wmiprvse.exe] [(Verified) Microsoft Corporation, 6.0.6002.18005 (lh_sp2rtm.090410-1830)]
[PID: 3728 / YPing][C:\Windows\system32\conime.exe] [(Verified) Microsoft Corporation, 6.0.6002.18005 (lh_sp2rtm.090410-1830)]
[PID: 3188 / YPing][C:\Program Files\Internet Explorer\ieuser.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 3036 / YPing][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 7.00.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\TcpIPDogL.dll] [城市热点资讯有限公司, 1, 0, 0, 164]
[C:\Windows\system32\igdumdx32.dll] [Intel Corporation, 7.15.10.1666]
[C:\Windows\system32\igdumd32.dll] [Intel Corporation, 7.15.10.1666]
[PID: 828 / SYSTEM][C:\Windows\system32\SearchProtocolHost.exe] [(Verified) Microsoft Corporation, 7.00.6002.18005 (lh_sp2rtm.090410-1830)]
[PID: 1228 / SYSTEM][C:\Windows\system32\SearchFilterHost.exe] [(Verified) Microsoft Corporation, 7.00.6002.18005 (lh_sp2rtm.090410-1830)]
[PID: 2252 / SYSTEM][C:\Windows\servicing\TrustedInstaller.exe] [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 1404 / YPing][C:\Users\YPing\AppData\Local\Temp\Temp1_sreng2.zip\SREngLdr.EXE] [Smallfrogs Studio, 2.8.2.1321]
[PID: 436 / YPing][C:\Users\YPing\AppData\Local\Temp\Temp1_sreng2.zip\SRE7ab5c406.EXE] [Smallfrogs Studio, 2.8.2.1321]
[C:\Windows\system32\TcpIPDogL.dll] [城市热点资讯有限公司, 1, 0, 0, 164]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["%SystemRoot%\hh.exe" %1]
.HLP OK. [%SystemRoot%\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. ["%SystemRoot%\System32\WScript.exe" "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
Dr.COM Client over [MSAFD Tcpip [TCP/IP]]
C:\Windows\system32\TcpIPDogL.dll(城市热点资讯有限公司, TcpIPDogL)
Dr.COM Client over [MSAFD Tcpip [UDP/IP]]
C:\Windows\system32\TcpIPDogL.dll(城市热点资讯有限公司, TcpIPDogL)
Dr.COM Client over [RSVP TCP 服务提供商]
C:\Windows\system32\TcpIPDogL.dll(城市热点资讯有限公司, TcpIPDogL)
Dr.COM Client over [RSVP UDP 服务提供商]
C:\Windows\system32\TcpIPDogL.dll(城市热点资讯有限公司, TcpIPDogL)
Dr.COM Client
C:\Windows\system32\TcpIPDogL.dll(城市热点资讯有限公司, TcpIPDogL)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
::1 localhost
==================================
进程特权扫描
N/A
==================================
计划任务
[已禁用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
N/A
[已启用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
N/A
[已启用] \Microsoft\Windows\Bluetooth\UninstallDeviceTask
BthUdTask.exe $(Arg0)
[已启用] \Microsoft\Windows\CertificateServicesClient\SystemTask
N/A
[已启用] \Microsoft\Windows\CertificateServicesClient\UserTask
N/A
[已启用] \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
N/A
[已启用] \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
%SystemRoot%\System32\wsqmcons.exe
[已启用] \Microsoft\Windows\Customer Experience Improvement Program\OptinNotification
%SystemRoot%\System32\wsqmcons.exe -n 0x1C577FA2B69CAD0
[已启用] \Microsoft\Windows\Defrag\ScheduledDefrag
%windir%\system32\defrag.exe -c -i
[已启用] \Microsoft\Windows\Media Center\ehDRMInit
%SystemRoot%\ehome\ehPrivJob.exe /DRMInit
[已启用] \Microsoft\Windows\Media Center\mcupdate
%SystemRoot%\ehome\mcupdate $(Arg0) -gc
[已启用] \Microsoft\Windows\Media Center\OCURActivate
%SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
[已启用] \Microsoft\Windows\Media Center\OCURDiscovery
%SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery
[已启用] \Microsoft\Windows\Media Center\UpdateRecordPath
%SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
[已启用] \Microsoft\Windows\MobilePC\HotStart
N/A
[已启用] \Microsoft\Windows\MobilePC\TMM
N/A
[已启用] \Microsoft\Windows\MUI\LPRemove
%windir%\system32\lpremove.exe
[已启用] \Microsoft\Windows\Multimedia\SystemSoundsService
N/A
[已启用] \Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
N/A
[已启用] \Microsoft\Windows\Shell\CrawlStartPages
N/A
[已禁用] \Microsoft\Windows\SideShow\AutoWake
N/A
[已启用] \Microsoft\Windows\SideShow\GadgetManager
N/A
[已禁用] \Microsoft\Windows\SideShow\SessionAgent
N/A
[已禁用] \Microsoft\Windows\SideShow\SystemDataProviders
N/A
[已启用] \Microsoft\Windows\SystemRestore\SR
%windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
[已启用] \Microsoft\Windows\Tcpip\IpAddressConflict1
rundll32 ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
[已启用] \Microsoft\Windows\Tcpip\IpAddressConflict2
rundll32 ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
[已启用] \Microsoft\Windows\UPnP\UPnPHostConfig
sc.exe config upnphost start= auto
[已启用] \Microsoft\Windows\Windows Error Reporting\QueueReporting
%windir%\system32\wermgr.exe -queuereporting
[已启用] \Microsoft\Windows\Wired\GatherWiredInfo
%windir%\system32\gatherWiredInfo.vbs
[已启用] \Microsoft\Windows\Wireless\GatherWirelessInfo
%windir%\system32\gatherWirelessInfo.vbs
==================================
Windows 安全更新检查
KB932926, BitLocker 和 EFS 增强
KB933713, Windows DreamScene
KB949479, Windows 声音方案
KB954320, Microsoft Tinker 提供的 Ultimate Extras Sounds
KB954955, Microsoft Tinker
KB928439, 用于 Windows Vista 的 Windows PowerShell 1.0 (KB928439)
KB961501, Windows Vista 安全更新程序 (KB961501) MS09-022
KB970238, Windows Vista 安全更新程序 (KB970238) MS09-026
KB943729, 用于 Windows Vista 的组策略首选项客户端扩展 (KB943729)
KB951847, Microsoft .NET Framework 3.5 Service Pack 1 和 .NET Framework 3.5 Family Update (KB951847) x86
KB971183, 阿拉伯语语言包
KB971183, 保加利亚语语言包
KB971183, 克罗地亚语语言包
KB971183, 捷克语语言包
KB971183, 丹麦语语言包
KB971183, 英语语言包
KB971183, 爱沙尼亚语语言包
KB971183, 芬兰语语言包
KB971183, 法语语言包
KB971183, 德语语言包
KB971183, 希腊语语言包
KB971183, 希伯来语语言包
KB971183, 匈牙利语语言包
KB971183, 意大利语语言包
KB971183, 西班牙语语言包
KB971183, 繁体中文语言包
KB971183, 荷兰语语言包
KB971183, 日语语言包
KB971183, 朝鲜语语言包
KB971183, 拉脱维亚语语言包
KB971183, 立陶宛语语言包
KB971183, 挪威语语言包
KB971183, 波兰语语言包
KB971183, 葡萄牙语(巴西)语言包
KB971183, 葡萄牙语(葡萄牙)语言包
KB971183, 罗马尼亚语语言包
KB971183, 俄语语言包
KB971183, 塞尔维亚语(拉丁语)语言包
KB971183, 斯洛伐克语语言包
KB971183, 斯洛文尼亚语语言包
KB971183, 瑞典语语言包
KB971183, 泰语语言包
KB971183, 土耳其语语言包
KB971183, 乌克兰语语言包
KB968389, Windows Vista 更新程序 (KB968389)
KB973540, Windows Vista 安全更新程序 (KB973540) MS09-037
KB956744, Windows Vista 安全更新程序 (KB956744) MS09-044
KB973507, Windows Vista 安全更新程序 (KB973507) MS09-037
KB971657, Windows Vista 安全更新程序 (KB971657) MS09-041
KB973768, Windows Vista 安全更新程序 (KB973768) MS09-037
KB967723, Windows Vista 安全更新程序 (KB967723) MS09-048
KB970710, Windows Vista 安全更新程序 (KB970710) MS09-049
KB971961, 用于 Windows Vista 的 Jscript 5.7 的安全更新程序 (KB971961) MS09-045
KB968816, 用于 Windows Vista 的 Windows Media Format Runtime 11 的安全更新程序 (KB968816) MS09-047
KB974470, 用于 Windows Vista Service Pack 2 和 Windows Server 2008 Service Pack 2 的 Microsoft .NET Framework 2.0 Service Pack 2 安全更新程序 (KB974470) MS09-061
KB975467, Windows Vista 安全更新程序 (KB975467) MS09-059
KB954155, 用于 Windows Vista 的 Windows Media Format Runtime 11 的安全更新程序 (KB954155) MS09-051
KB974571, Windows Vista 安全更新程序 (KB974571) MS09-056
KB974306, Media Center for Windows Vista 累积更新程序 (KB974306)
KB975517, Windows Vista 安全更新程序 (KB975517) MS09-050
KB972145, Windows Vista 更新程序 (KB972145)
KB971644, Windows Vista 平台更新程序 (KB971644)
KB969947, Windows Vista 安全更新程序 (KB969947) MS09-065
KB973565, Windows Vista 安全更新程序 (KB973565) MS09-063
KB973687, Windows Vista 更新程序 (KB973687)
KB976470, Windows Vista 更新程序 (KB976470)
KB974318, Windows Vista 安全更新程序 (KB974318) MS09-071
KB972270, Windows Vista 安全更新程序 (KB972270) MS10-001
KB975560, Windows Vista 安全更新程序 (KB975560) MS10-013
KB978262, 用于 Windows Vista 的 ActiveX Killbit 累积安全更新程序 (KB978262) MS10-008
KB971468, Windows Vista 安全更新程序 (KB971468) MS10-012
KB975929, Windows Vista 更新程序 (KB975929)
KB976264, Windows Vista 更新程序 (KB976264)
KB979306, Windows Vista 更新程序 (KB979306)
KB979099, Update for Rights Management Services Client for Windows Vista (KB979099)
KB975561, 用于 Windows Vista 的 Movie Maker 6.0 的安全更新程序 (KB975561) MS10-016
KB944036, 用于 Windows Vista 的 Internet Explorer 8
KB980182, 用于 Windows Vista 的 Internet Explorer 7 累积安全更新程序 (KB980182) MS10-018
KB973917, Windows Vista 更新程序 (KB973917)
KB980232, Windows Vista 安全更新程序 (KB980232) MS10-020
KB977816, Windows Vista 安全更新程序 (KB977816) MS10-026
KB979309, Windows Vista 安全更新程序 (KB979309) MS10-019
KB978338, Windows Vista 安全更新程序 (KB978338) MS10-029
KB905866, Windows Mail 垃圾邮件筛选器更新程序 [2010 年 4 月] (KB905866)
KB979683, Windows Vista 安全更新程序 (KB979683) MS10-021
KB890830, Windows 恶意软件删除工具 - 2010 年 4 月 (KB890830)
KB981349, Windows Vista 安全更新程序 (KB981349) MS10-022
KB978601, Windows Vista 安全更新程序 (KB978601) MS10-019
KB980248, Windows Vista 更新程序 (KB980248)
KB915597, Definition Update for Windows Defender - KB915597 (Definition 1.81.874.0)
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================[/code]