[PID: 2752 / GOOD][E:\实用软件\uusee\UUSeePlayer.exe] [, 3, 0, 1, 6]
[C:\windows\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\windows\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16473 (vista_gdr.070420-1500)]
[C:\Program Files\FengYun\fymon.dll] [www.218.cc, 1.2.3.75]
[E:\实用软件\uusee\UUPlayer.DLL] [, 3, 0, 1, 4]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16473 (vista_gdr.070420-1500)]
[C:\windows\system32\avsda.dll] [Avira GmbH, 7.0.0.5]
[C:\windows\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[E:\实用软件\uusee\UUPlayer.ocx] [, 1, 0, 0, 1]
[E:\实用软件\uusee\ARMP.ocx] [UUSEE, 7, 8, 2, 0]
[C:\windows\system32\MFPlat.DLL] [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
[E:\实用软件\uusee\MultiVMR9.dll] [uusee, 9.00]
[C:\windows\system32\rmoc3260.dll] [RealNetworks, Inc., 6.0.9.2568]
[C:\windows\system32\PNCRT.dll] [Real Networks, Inc, 6.0.0.0]
[C:\Program Files\Common Files\Real\Common\pngu3267.dll] [RealNetworks, Inc., 6.7.0.2962]
[C:\windows\system32\msdmo.dll] [, ]
[C:\windows\system32\WMVDECOD.dll] [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
[C:\windows\system32\ffdshow.ax] [, 1.0.2.2028]
[C:\windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\StormII\Codec\VSFilter.dll] [Gabest, 1, 0, 1, 3]
[C:\windows\system32\wmpeffects.dll] [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
[C:\Program Files\Common Files\Real\rpplugins\embd3260.dll] [RealNetworks, Inc., 6.0.12.1739]
[C:\Program Files\Common Files\Real\Common\pnrs3260.dll] [RealNetworks, Inc., 6.0.9.4317]
[C:\Program Files\Common Files\Real\Common\objb3201.dll] [RealNetworks, Inc., 0.1.0.6726]
[C:\Program Files\Common Files\Real\rpplugins\rpcl3260.dll] [RealNetworks, Inc., 6.0.9.3362]
[C:\Program Files\Common Files\Real\rpplugins\rput3260.dll] [RealNetworks, Inc., 6.0.9.3338]
[C:\Program Files\Common Files\Real\Common\pnen3260.dll] [RealNetworks, Inc., 10.0.0.1283]
[C:\Program Files\Common Files\Real\Plugins\vidsite.dll] [RealNetworks, Inc., 10.0.0.1253]
[C:\Program Files\Common Files\Real\Plugins\zipf3260.dll] [RealNetworks, Inc., 6.0.8.2799]
[C:\Program Files\Common Files\Real\Plugins\vsrlocal.dll] [RealNetworks, Inc., 10.1.0.1180]
[C:\Program Files\Common Files\Real\Plugins\clntxres.dll] [RealNetworks, Inc., 10.0.0.4181]
[C:\Program Files\Common Files\Real\Plugins\memfsys.dll] [RealNetworks, Inc., 10.0.0.1219]
[E:\实用软件\uusee\in_psp.dll] [www.uusee.com, 1.0.7.727]
[E:\实用软件\uusee\out_mmshttp.dll] [uusee.com, 2.2.0.15]
[PID: 3180 / GOOD][C:\Program Files\Tencent\qq\QQ.exe] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\CoralAssist.dll] [Coral Team, 5.0.0 build 20060829]
[C:\Program Files\Tencent\qq\CoralQQ.dll] [Coral Team, 5.0.1a Build 20070620]
[C:\Program Files\Tencent\qq\kql.dll] [Coral Team, 5.0.1a build 20070620]
[C:\Program Files\Tencent\qq\mfc42.dll] [Microsoft Corporation, 6.00.8665.0]
[C:\windows\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16473 (vista_gdr.070420-1500)]
[C:\Program Files\Tencent\qq\ipsearcher.dll] [, 1.0.0.3]
[C:\windows\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\Program Files\Tencent\qq\QQBaseClassInDll.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\QQHelperDll.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\BasicCtrlDll.dll] [TENCENT, 7, 0, 225, 1651]
[C:\Program Files\Tencent\qq\NoDisturbFilter.cqx] [Coral Team, 1.0]
[C:\Program Files\Tencent\qq\ConfigHotkey.cqx] [Coral Team, 1.0]
[C:\Program Files\FengYun\fymon.dll] [www.218.cc, 1.2.3.75]
[C:\Program Files\Tencent\qq\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[C:\Program Files\Tencent\qq\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[C:\Program Files\Tencent\qq\QQAPI.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[C:\Program Files\Tencent\qq\AutoReconnect.cqx] [Coral Team, 1.0.0]
[C:\Program Files\Tencent\qq\LoginCtrl.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\LoginCtrlRes.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\QQRes.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\MailSummary.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\QQMainFrame.dll] [N/A, ]
[C:\Program Files\Tencent\qq\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Tencent\qq\CQQApplication.dll] [N/A, ]
[C:\Program Files\Tencent\qq\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[C:\Program Files\Tencent\qq\NewSkin.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\HostingMgr.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\CameraDll.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\CoralHotkey.cqx] [Coral Team, 1.0]
[C:\Program Files\Tencent\qq\QQKnowledgeSearch.dll] [TENCENT, 7,0,313,1681]
[C:\windows\system32\avsda.dll] [Avira GmbH, 7.0.0.5]
[C:\Program Files\Tencent\qq\QQAllInOne.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\SCCore.dll] [TENCENT, 1, 6, 0, 2]
[C:\Program Files\Tencent\qq\QQSpace.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\vbscript.dll] [Microsoft Corporation, 5.6.0.7426]
[C:\windows\system32\msdmo.dll] [, ]
[C:\Program Files\Tencent\qq\QQGroupMng.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\UserDefinedHead.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\QQPlugin.dll] [N/A, ]
[C:\Program Files\Tencent\qq\QQConfigPlugin.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\QQCustomFace.dll] [N/A, ]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16473 (vista_gdr.070420-1500)]
[C:\Program Files\Tencent\qq\QQAvatar.dll] [N/A, ]
[C:\Program Files\Tencent\qq\QRingMng.dll] [N/A, ]
[C:\Program Files\Tencent\qq\LongConnection.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\QQPet.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\QQSysMsgMng.dll] [N/A, ]
[C:\Program Files\Tencent\qq\BQQApplication.dll] [N/A, ]
[C:\Program Files\Tencent\qq\CommercesMng.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\PersonalDesktop.dll] [TENCENT, 7,0,313,1681]
[C:\Program Files\Tencent\qq\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 310]
[C:\Program Files\Tencent\qq\QQSceneMng.dll] [N/A, ]
[C:\Program Files\Tencent\qq\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 1, 9, 95]
[C:\windows\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Tencent\qq\QQSettingCtrl.dll] [TENCENT, 7,0,313,1681]
[PID: 2952 / GOOD][C:\Program Files\Tencent\qq\TIMPlatform.exe] [TENCENT, 7,0,313,1681]
[C:\Program Files\FengYun\fymon.dll] [www.218.cc, 1.2.3.75]
[C:\Program Files\Tencent\qq\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 3020 / GOOD][E:\实用软件\uusee\UUSeePlayer.exe] [, 3, 0, 1, 6]
[C:\windows\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\windows\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16473 (vista_gdr.070420-1500)]
[C:\Program Files\FengYun\fymon.dll] [www.218.cc, 1.2.3.75]
[E:\实用软件\uusee\UUPlayer.DLL] [, 3, 0, 1, 4]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16473 (vista_gdr.070420-1500)]
[C:\windows\system32\avsda.dll] [Avira GmbH, 7.0.0.5]
[C:\windows\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[E:\实用软件\uusee\UUPlayer.ocx] [, 1, 0, 0, 1]
[E:\实用软件\uusee\ARMP.ocx] [UUSEE, 7, 8, 2, 0]
[C:\windows\system32\MFPlat.DLL] [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
[E:\实用软件\uusee\MultiVMR9.dll] [uusee, 9.00]
[C:\windows\system32\rmoc3260.dll] [RealNetworks, Inc., 6.0.9.2568]
[C:\windows\system32\PNCRT.dll] [Real Networks, Inc, 6.0.0.0]
[C:\windows\system32\msdmo.dll] [, ]
[C:\windows\system32\WMVDECOD.dll] [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
[C:\windows\system32\ffdshow.ax] [, 1.0.2.2028]
[C:\windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\StormII\Codec\VSFilter.dll] [Gabest, 1, 0, 1, 3]
[C:\windows\system32\wmpeffects.dll] [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
[C:\Program Files\Common Files\Real\rpplugins\embd3260.dll] [RealNetworks, Inc., 6.0.12.1739]
[C:\Program Files\Common Files\Real\Common\pngu3267.dll] [RealNetworks, Inc., 6.7.0.2962]
[C:\Program Files\Common Files\Real\Common\pnrs3260.dll] [RealNetworks, Inc., 6.0.9.4317]
[C:\Program Files\Common Files\Real\Common\objb3201.dll] [RealNetworks, Inc., 0.1.0.6726]
[C:\Program Files\Common Files\Real\rpplugins\rpcl3260.dll] [RealNetworks, Inc., 6.0.9.3362]
[C:\Program Files\Common Files\Real\rpplugins\rput3260.dll] [RealNetworks, Inc., 6.0.9.3338]
[C:\Program Files\Common Files\Real\Common\pnen3260.dll] [RealNetworks, Inc., 10.0.0.1283]
[C:\Program Files\Common Files\Real\Plugins\vidsite.dll] [RealNetworks, Inc., 10.0.0.1253]
[C:\Program Files\Common Files\Real\Plugins\zipf3260.dll] [RealNetworks, Inc., 6.0.8.2799]
[C:\Program Files\Common Files\Real\Plugins\vsrlocal.dll] [RealNetworks, Inc., 10.1.0.1180]
[C:\Program Files\Common Files\Real\Plugins\clntxres.dll] [RealNetworks, Inc., 10.0.0.4181]
[C:\Program Files\Common Files\Real\Plugins\memfsys.dll] [RealNetworks, Inc., 10.0.0.1219]
[E:\实用软件\uusee\in_psp.dll] [www.uusee.com, 1.0.7.727]
[E:\实用软件\uusee\out_mmshttp.dll] [uusee.com, 2.2.0.15]
[PID: 2136 / GOOD][C:\opera.v9.228807fx\opera\opera.exe] [Opera Software, 8807]
[C:\Program Files\FengYun\fymon.dll] [www.218.cc, 1.2.3.75]
[C:\windows\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16473 (vista_gdr.070420-1500)]
[C:\opera.v9.228807fx\opera\Opera.dll] [Opera Software, 8807]
[C:\windows\system32\avsda.dll] [Avira GmbH, 7.0.0.5]
[C:\windows\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0]
[C:\windows\system32\dllMergeDict.dll] [Sogou.com Inc., 3, 0, 0, 0]
[C:\Program Files\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31]
[PID: 3168 / GOOD][D:\download\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\windows\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\windows\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16473 (vista_gdr.070420-1500)]
[C:\Program Files\FengYun\fymon.dll] [www.218.cc, 1.2.3.75]
[D:\download\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[C:\windows\system32\avsda.dll] [Avira GmbH, 7.0.0.5]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR Error. [AutoCADScriptFile]
.CHM OK. ["C:\windows\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
AVSDA over [MSAFD Tcpip [TCP/IP]]
avsda.dll(Avira GmbH, AntiVir layered service provider)
AVSDA over [MSAFD Tcpip [UDP/IP]]
avsda.dll(Avira GmbH, AntiVir layered service provider)
AVSDA
avsda.dll(Avira GmbH, AntiVir layered service provider)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1252, C:\PROGRAM FILES\ANTIVIR PERSONALEDITION PREMIUM\AVGUARD.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1504, E:\实用软件\WALLPAPER RADAR\WALLRADA.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1504, E:\实用软件\WALLPAPER RADAR\WALLRADA.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1524, C:\PROGRAM FILES\FENGYUN\FYFIREWALL.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1524, C:\PROGRAM FILES\FENGYUN\FYFIREWALL.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1532, C:\PROGRAM FILES\ANTIVIR PERSONALEDITION PREMIUM\AVGNT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1532, C:\PROGRAM FILES\ANTIVIR PERSONALEDITION PREMIUM\AVGNT.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3376, C:\DZH\INTERNET\HYPWISE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3376, C:\DZH\INTERNET\HYPWISE.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2136, C:\OPERA.V9.228807FX\OPERA\OPERA.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2136, C:\OPERA.V9.228807FX\OPERA\OPERA.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE] |