[PID: 1276 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1612 / sony][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\pp\KSafe\ksfmon.dll] [Kingsoft Corporation., 1.6.0.1155]
[D:\pp\KSafe\kwsui.dll] [Kingsoft Corporation, 2010,10,11,2]
[D:\pp\KSafe\kswebshield.dll] [Kingsoft Corporation, 2010,10,11,2]
[PID: 620 / SYSTEM][C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe] [Apple Inc., 2.11.32.0]
[PID: 1472 / SYSTEM][C:\Program Files\Bonjour\mDNSResponder.exe] [Apple Inc., 1,0,5,11]
[PID: 292 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 576 / SYSTEM][C:\WINDOWS\system32\tcpsvcs.exe] [(Verified) Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Bonjour\mdnsNSP.dll] [Apple Inc., 1,0,5,11]
[PID: 1892 / SYSTEM][C:\WINDOWS\System32\snmp.exe] [(Verified) Microsoft Corporation, 5.1.2600.3038 (xpsp_sp2_gdr.061119-2303)]
[C:\Program Files\Bonjour\mdnsNSP.dll] [Apple Inc., 1,0,5,11]
[PID: 1084 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1780 / SYSTEM][C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\WDKeyMonitorCCB.exe] [ Beijing WatchData System Co., Ltd., 3, 2, 0, 0]
[C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\wdkmgr.dll] [Watchdata, 2, 1, 1, 40]
[PID: 2380 / SYSTEM][C:\WINDOWS\system32\MsPMSPSv.exe] [Microsoft Corporation, 7.01.00.3055]
[PID: 1972 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2100 / sony][D:\TdxW.exe] [(通达信)深圳市财富趋势科技有限责任公司, 1, 0, 0, 1]
[D:\TCalc.dll] [, 1, 0, 0, 1]
[D:\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[D:\Viewthem.dll] [, 1, 0, 0, 1]
[D:\invest.dll] [, 1.15]
[D:\Dbf.dll] [N/A, ]
[D:\TUserComm.dll] [, 1, 0, 0, 1]
[D:\TMarquee.dll] [, 1, 0, 0, 1]
[D:\TGear.dll] [, 1.00]
[D:\TJyaid.dll] [, 1.00]
[D:\TControl.dll] [, 1.00]
[D:\TDXImage.dll] [, 1, 0, 0, 1]
[D:\pp\KSafe\ksfmon.dll] [Kingsoft Corporation., 1.6.0.1155]
[D:\pp\KSafe\kwsui.dll] [Kingsoft Corporation, 2010,10,11,2]
[D:\pp\KSafe\kswebshield.dll] [Kingsoft Corporation, 2010,10,11,2]
[D:\calcer.dll] [, 1, 0, 0, 1]
[D:\res_std2.dll] [N/A, ]
[D:\TEncrypt.dll] [, 1, 0, 0, 1]
[D:\tc.dll] [深圳财富趋势科技有限公司, 6, 0, 0, 2]
[D:\MfcHlpr520.dll] [深圳财富趋势科技有限公司, 11, 2, 0, 0]
[D:\TcApi.dll] [深圳财富趋势科技有限公司, 6, 0, 0, 1]
[D:\clibhlpr.dll] [N/A, ]
[D:\WTCommLib.dll] [N/A, ]
[D:\TCPlugins\AddinUtility.dll] [深圳财富趋势科技有限公司, 6, 0, 0, 2]
[D:\TCPlugins\AddinCommonControl.dll] [深圳财富趋势科技有限公司, 6, 0, 0, 2]
[D:\TCPlugins\AddinSafeControl.dll] [深圳财富趋势科技有限公司, 6, 0, 0, 2]
[D:\TCPlugins\AddinTList.dll] [深圳财富趋势科技有限公司, 6, 0, 0, 2]
[D:\TCPlugins\AddinMiniQuote.dll] [深圳财富趋势科技有限公司, 6, 0, 0, 2]
[D:\TCPlugins\AddinStock.dll] [深圳财富趋势科技有限公司, 1, 0, 0, 1]
[D:\TCPlugins\AddinFund.dll] [深圳财富趋势科技有限公司, 1, 0, 0, 1]
[D:\TCPlugins\AddinPmxd.dll] [深圳财富趋势科技有限公司, 6, 0, 0, 2]
[D:\TCPlugins\AddinYzzz.dll] [深圳财富趋势科技有限公司, 1, 0, 0, 1]
[D:\GNPlugins\TE_Jiangen.dll] [, 1, 0, 0, 1]
[D:\GNPlugins\TE_Star.dll] [, 1, 0, 0, 1]
[PID: 3624 / sony][D:\pp\Bin\QQ.exe] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\Common.dll] [Tencent, 1, 50, 1720, 0]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.DLL] [Microsoft Corporation, 8.00.50727.4053]
[D:\pp\Bin\KernelUtil.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\GF.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\xGraphic32.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\AFUtil.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\KSafe\ksfmon.dll] [Kingsoft Corporation., 1.6.0.1155]
[D:\pp\KSafe\kwsui.dll] [Kingsoft Corporation, 2010,10,11,2]
[D:\pp\KSafe\kswebshield.dll] [Kingsoft Corporation, 2010,10,11,2]
[D:\pp\Bin\LoginPanel.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\IM.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\TaskTray.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\AppUtil.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\TXPFProxy.dll] [Tencent, 1, 50, 1720, 0]
[C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159]
[D:\pp\Bin\MainFrame.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\AppFramework.dll] [Tencent, 1, 50, 1720, 0]
[C:\Program Files\Common Files\Tencent\TXSSO\Bin\SSOPlatform.dll] [Tencent, 1.2.1.10]
[C:\Program Files\Common Files\Tencent\TXSSO\Bin\SSOCommon.DLL] [Tencent, 1.2.1.6]
[D:\pp\Bin\SkinMgr.dll] [Tencent, 1, 50, 1720, 0]
[C:\Program Files\Bonjour\mdnsNSP.dll] [Apple Inc., 1,0,5,11]
[D:\pp\Bin\AFCtrl.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\SystemMsg.dll] [Tencent, 1, 50, 1720, 0]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[D:\pp\Bin\ConfigCenter.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\ChatFrameApp.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\QInterLive.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\GroupApp.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\AppMisc.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\Contacts.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\InformationBox.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\ContactInfoFrame.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.PayCenter\Bin\PayCenter.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.QQVipMisc\Bin\QQVipMisc.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.NetBar\Bin\NetBar.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.VAS\Bin\VAS.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.Wireless\Bin\Wireless.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.PaiPaiGift\Bin\PaiPaiGift.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.QQShow\Bin\QQShow.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.Qzone\Bin\Qzone.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.CRM\Bin\CRM.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.AudioVideo\Bin\AudioVideo.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.Soso\Bin\Soso.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.Weather\Bin\Weather.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.Advertisement\Bin\Advertisement.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.Memo\Bin\Memo.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.QQVip\Bin\QQVip.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.MMOG\Bin\MMOG.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.QQGame\Bin\QQGame.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.QQMusic\Bin\QQMusic.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\Com.Tencent.Mail\Bin\Mail.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\com.tencent.snsapp\Bin\SNSApp.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\com.tencent.qbar\Bin\QBar.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\com.tencent.wenwen\Bin\WenWen.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\WBlog.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\com.tencent.paipai\Bin\PaiPai.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\com.tencent.qqlive\Bin\QQLive.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\com.tencent.qqpet\Bin\QQPet.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\com.tencent.taotao\Bin\taotao.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\com.tencent.filetransfer\Bin\FileTransfer.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\MsgMgr.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\com.tencent.gamelife\Bin\GameLife.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\com.tencent.today\Bin\Today.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\com.tencent.qqring\Bin\QQRing.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\com.tencent.qqwebsite\Bin\QQWebsite.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\appcom.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\LongCnn.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\CustomFace.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\AddrSearch.dll] [Tencent, 2, 3, 12, 11]
[D:\pp\Bin\KernelMisc.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\Camera.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Bin\SCCore.dll] [Tencent, 1, 7, 1, 6]
[D:\pp\Plugin\com.tencent.sobar\Bin\SoBar.dll] [Tencent, 1, 50, 1720, 0]
[D:\pp\Plugin\com.tencent.qqshow\Bin\FlashAvatarDll.dll] [Tencent, 1.50.1720.0]
[C:\WINDOWS\system32\Macromed\Flash\Flash10d.ocx] [Adobe Systems, Inc., 10,0,42,34]
[PID: 4068 / sony][D:\pp\Bin\TXPlatform.exe] [Tencent, 1, 50, 1720, 0]
[D:\pp\KSafe\ksfmon.dll] [Kingsoft Corporation., 1.6.0.1155]
[D:\pp\KSafe\kwsui.dll] [Kingsoft Corporation, 2010,10,11,2]
[D:\pp\KSafe\kswebshield.dll] [Kingsoft Corporation, 2010,10,11,2]
[D:\pp\Bin\TXPFProxy.dll] [Tencent, 1, 50, 1720, 0]
[C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159]
[PID: 3264 / sony][C:\WINDOWS\system32\conime.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\pp\KSafe\ksfmon.dll] [Kingsoft Corporation., 1.6.0.1155]
[D:\pp\KSafe\kwsui.dll] [Kingsoft Corporation, 2010,10,11,2]
[D:\pp\KSafe\kswebshield.dll] [Kingsoft Corporation, 2010,10,11,2]
[PID: 2536 / sony][D:\MYIE2\Maxthon\maxthon.exe] [Maxthon International Ltd., 1, 6, 3, 80]
[D:\MYIE2\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[D:\pp\KSafe\ksfmon.dll] [Kingsoft Corporation., 1.6.0.1155]
[D:\pp\KSafe\kwsui.dll] [Kingsoft Corporation, 2010,10,11,2]
[D:\pp\KSafe\kswebshield.dll] [Kingsoft Corporation, 2010,10,11,2]
[D:\pp\KSafe\kswbc.dll] [Kingsoft Corporation, 2010,09,20,35]
[C:\Program Files\Bonjour\mdnsNSP.dll] [Apple Inc., 1,0,5,11]
[C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CorperfmonExt.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_perf.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159]
[D:\MYIE2\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
[PID: 300 / SYSTEM][D:\KSM\ksmsvc.exe] [, 2010,07,15,1223]
[D:\KSM\kdump.dll] [Kingsoft Corporation, 2010,10,11,1453]
[D:\KSM\kxestat.dll] [Kingsoft Corporation, 2009,11,20,309]
[D:\KSM\kxebase.dll] [Kingsoft Corporation, 2009,11,20,309]
[D:\KSM\scom.dll] [Kingsoft Corporation, 2009,11,20,309]
[D:\KSM\kxecore\kxelog.dll] [Kingsoft Corporation, 2009,11,20,309]
[D:\KSM\kxecore\kxecore.dll] [Kingsoft Corporation, 2010,5,12,402]
[D:\KSM\kxecore\kxestat.dll] [Kingsoft Corporation, 2009,11,20,309]
[D:\KSM\ksmcorex.dll] [Kingsoft Corporation, 2010,10,21,10]
[D:\KSM\kplugeng.dll] [Kingsoft Corporation., 1.5.2.1190]
[D:\KSM\sqlite.dll] [N/A, ]
[D:\KSM\ksmbrfix.dll] [Kingsoft Corporation, 2010,09,13,1403]
[D:\KSM\kavquara.dll] [Kingsoft Corporation, 2010,07,14,924]
[D:\KSM\ksecorex.dll] [Kingsoft Corporation, 2010,09,16,1206]
[D:\KSM\kae\kaecore.dat] [Kingsoft Corporation, 2010,06,30,436]
[D:\KSM\ksbwdet2.dll] [Kingsoft Corporation, 2010,08,26,1359]
[D:\KSM\kae\karchive.dat] [Kingsoft Corporation, 2010,06,30,436]
[D:\KSM\ksbwsspx.dll] [Kingsoft Corporation, 2010,05,27,1072]
[D:\KSM\kae\kaearcha.dat] [Kingsoft Corporation, 2010,06,30,436]
[D:\KSM\kae\kaeolea.dat] [Kingsoft Corporation, 2010,03,18,77]
[D:\KSM\kae\kaearchb.dat] [Kingsoft Corporation, 2010,06,30,436]
[D:\KSM\kcldrep.dll] [Kingsoft Corporation, 2010,10,19,1467]
[D:\KSM\kavifr.dll] [Kingsoft Corporation, 2010,05,25,74]
[D:\KSM\ksreng3.dll] [Kingsoft Corporation, 2010,10,25,78]
[D:\KSM\kscanner.dll] [Kingsoft Corporation, 2010,09,26,1432]
[PID: 4060 / sony][D:\KSM\kinstool.exe] [Kingsoft Corporation, 2010,04,28,935]
[PID: 2616 / sony][D:\KSM\ksmgui.exe] [, 2010,09,13,1403]
[D:\KSM\kdump.dll] [Kingsoft Corporation, 2010,10,11,1453]
[D:\KSM\kxestat.dll] [Kingsoft Corporation, 2009,11,20,309]
[D:\pp\KSafe\ksfmon.dll] [Kingsoft Corporation., 1.6.0.1155]
[D:\pp\KSafe\kwsui.dll] [Kingsoft Corporation, 2010,10,11,2]
[D:\pp\KSafe\kswebshield.dll] [Kingsoft Corporation, 2010,10,11,2]
[D:\KSM\kcldrep.dll] [Kingsoft Corporation, 2010,10,19,1467]
[D:\KSM\kavifr.dll] [Kingsoft Corporation, 2010,05,25,74]
[D:\KSM\COMRes.dll] [Microsoft Corporation, 2001.12.4414.258]
[PID: 2268 / sony][D:\书籍\SReng2.8.2.1321版\SReng2.8.2.1321版\sr-engldr.EXE] [Smallfrogs Studio, 2.8.2.1321]
[D:\pp\KSafe\ksfmon.dll] [Kingsoft Corporation., 1.6.0.1155]
[D:\pp\KSafe\kwsui.dll] [Kingsoft Corporation, 2010,10,11,2]
[D:\pp\KSafe\kswebshield.dll] [Kingsoft Corporation, 2010,10,11,2]
[D:\书籍\SReng2.8.2.1321版\SReng2.8.2.1321版\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR Error. []
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 548, C:\WINDOWS\SYSTEM32\WATCHDATA\WATCHDATA CCB CSP V3.2\WDCERTM_CCB.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1780, C:\WINDOWS\SYSTEM32\WATCHDATA\WATCHDATA CCB CSP V3.2\WDKEYMONITORCCB.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2100, D:\TDXW.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2536, D:\MYIE2\MAXTHON\MAXTHON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2536, D:\MYIE2\MAXTHON\MAXTHON.EXE]
==================================
计划任务
N/A
==================================
Windows 安全更新检查
N/A
==================================
API HOOK
入口点错误:LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: 0x015A02F1)
入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: 0x011902F1)
入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: 0x015602F1)
入口点错误:ShellExecuteExW (危险等级: 高, 被下面模块所HOOK: 0x015C02F1)
入口点错误:ShellExecuteW (危险等级: 高, 被下面模块所HOOK: 0x015B02F1)
==================================
隐藏进程
N/A
==================================
[/CODE]