On-line 发表于 2012-2-16 10:27 
扫描一份sreng日志上来看看。
- 2012-02-16,10:40:16
- System Repair Engineer 2.8.4.1331
- Smallfrogs (http://www.KZTechs.com)
- Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
- 以下内容被选中:
- 所有的启动项目(包括注册表、启动文件夹、服务等)
- 浏览器加载项
- 正在运行的进程(包括进程模块信息)
- 文件关联
- Winsock 提供者
- Autorun.inf
- HOSTS 文件
- 进程特权扫描
- 计划任务
- Windows 安全更新检查
- API HOOK
- 隐藏进程
- 启动项目
- 注册表
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- <AVP><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"> [Kaspersky Lab]
- <kxesc><"E:\program files\kingsoft\kingsoft antivirus\kxetray.exe" -autorun> [(Verified)Zhuhai Kingsoft Software Co.,Ltd]
- <D4Svr_ICBC.exe><D4Svr_ICBC.exe> [(Verified)Tendyron Corporation]
- <SoundMan><SOUNDMAN.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
- <Userinit><c:\windows\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <AppInit_DLLs><> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
- <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
- <PostBootReminder><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher]
- <CDBurn><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher]
- <WebCheck><%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Publisher]
- <SysTray><C:\WINDOWS\system32\stobject.dll> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
- <WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
- <WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
- <WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
- <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll> [Kaspersky Lab]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
- <WinlogonNotify: NavLogon><C:\WINDOWS\system32\NavLogon.dll> []
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
- <WinlogonNotify: ScCertProp><wlnotify.dll> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
- <WinlogonNotify: Schedule><wlnotify.dll> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
- <WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
- <WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
- <WinlogonNotify: termsrv><wlnotify.dll> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
- <WinlogonNotify: wlballoon><wlnotify.dll> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
- <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
- <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
- <Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
- <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
- <浏览器自定义组件><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
- <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
- <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
- <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
- <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
- <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
- <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
- <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
- <Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
- <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Publisher]
- ==================================
- 启动文件夹
- [DSLMON]
- <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\DSLMON.lnk --> C:\PROGRA~1\TCLCOM~1\TCLA11~1\DSLMON.exe []><N>
- ==================================
- 服务
- [360 杀毒实时防护加载服务 / 360rp][Stopped/Manual Start]
- <"E:\日常软件\360sd\360rps.exe"><360.cn>
- [Kaspersky Anti-Virus 6.0 / AVP][Running/Auto Start]
- <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
- [Human Interface Device Access / HidServ][Stopped/Disabled]
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
- [ICBC Daemon Service / ICBC Daemon Service][Running/Auto Start]
- <C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\ICBC_WIN32\IcbcDaemon.exe><N/A>
- [Kingsoft Core Service / kxescore][Running/Auto Start]
- <"E:\program files\kingsoft\kingsoft antivirus\kxescore.exe" /service kxescore><Kingsoft Corporation>
- [OnKey Service _ICBC / OnKey Service _ICBC][Running/Auto Start]
- <C:\WINDOWS\system32\D4Ser_ICBC.exe><Tendyron Corporation>
- [CLCV0 / UTSCSI][Stopped/Manual Start]
- <C:\WINDOWS\system32\UTSCSI.EXE><>
- [主动防御 / ZhuDongFangYu][Running/Auto Start]
- <"E:\日常软件\360safe\deepscan\zhudongfangyu.exe"><360.cn>
- ==================================
- 驱动程序
- [360AvFlt mini-filter driver / 360AvFlt][Running/System Start]
- <system32\DRIVERS\360AvFlt.sys><360.cn>
- [360Box mini-filter driver / 360Box][Stopped/Manual Start]
- <system32\DRIVERS\360Box.sys><360安全中心>
- [360netmon / 360netmon][Running/System Start]
- <\??\C:\WINDOWS\system32\drivers\360netmon.sys><360.cn>
- [360SelfProtection / 360SelfProtection][Running/System Start]
- <system32\drivers\360SelfProtection.sys><360安全中心>
- [General Purpose USB Driver (adildr.sys) / ADILOADER][Stopped/Auto Start]
- <System32\Drivers\adildr.sys><Analog Deivces>
- [USB ADSL LAN Adapter / adiusbae][Running/Manual Start]
- <system32\DRIVERS\adiusbae.sys><Analog Devices Inc.>
- [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
- <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
- [BAPIDRV / BAPIDRV][Running/System Start]
- <\??\C:\WINDOWS\system32\drivers\BAPIDRV.SYS><360.cn>
- [BC / BC][Running/Boot Start]
- <\SystemRoot\system32\Drivers\BC.sys><Kingsoft Corporation>
- [bootsafe / bootsafe][Running/Boot Start]
- <\SystemRoot\system32\Drivers\bootsafe.sys><>
- [EfiSystemMon / EfiMon][Running/System Start]
- <System32\Drivers\Efimon.sys><360安全中心>
- [HookPort / HookPort][Running/Boot Start]
- <\SystemRoot\System32\Drivers\Hookport.sys><360安全中心>
- [kavbootc / kavbootc][Running/Boot Start]
- <\SystemRoot\system32\drivers\kavbootc.sys><Kingsoft Corporation>
- [KDHacker / KDHacker][Running/System Start]
- <\??\E:\program files\kingsoft\kingsoft antivirus\security\kxescan\kdhacker.sys><Kingsoft Corporation>
- [kisknl / kisknl][Running/Auto Start]
- <\??\C:\WINDOWS\system32\drivers\kisknl.sys><Kingsoft Corporation>
- [kl1 / kl1][Running/Boot Start]
- <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
- [klif / klif][Running/System Start]
- <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
- [ksapi / ksapi][Running/Manual Start]
- <\??\C:\WINDOWS\system32\drivers\ksapi.sys><Kingsoft Corporation>
- [NAVAP / NAVAP][Stopped/Manual Start]
- <\??\C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVAP.sys><N/A>
- [NAVAPEL / NAVAPEL][Stopped/Auto Start]
- <\??\C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPEL.SYS><N/A>
- [NAVENG / NAVENG][Stopped/Manual Start]
- <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20040901.016\NAVENG.sys><Symantec Corporation>
- [NAVEX15 / NAVEX15][Stopped/Manual Start]
- <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20040901.016\NAVEX15.sys><Symantec Corporation>
- [nv / nv][Running/Manual Start]
- <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
- [StarForce Protection Environment Driver v6 / prodrv06][Running/System Start]
- <\SystemRoot\System32\drivers\prodrv06.sys><StarForce Technologies, Inc.>
- [StarForce Protection Helper Driver v2 / prohlp02][Running/Boot Start]
- <\SystemRoot\System32\drivers\prohlp02.sys><StarForce Technologies, Inc.>
- [StarForce Protection Synchronization Driver v1 / prosync1][Running/Boot Start]
- <\SystemRoot\System32\drivers\prosync1.sys><StarForce Technologies, Inc.>
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
- [PxHelp20 / PxHelp20][Running/Boot Start]
- <\SystemRoot\system32\DRIVERS\PxHelp20.sys><Sonic Solutions>
- [Quantum DeepScanner Servers / qutmdserv][Running/System Start]
- <\??\C:\WINDOWS\system32\drivers\qutmdrv.sys><360.cn>
- [qutmipc / qutmipc][Running/System Start]
- <\??\C:\WINDOWS\system32\drivers\qutmipc.sys><360.cn>
- [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
- <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
- [Secdrv / Secdrv][Stopped/Manual Start]
- <system32\DRIVERS\secdrv.sys><N/A>
- [StarForce Protection Helper Driver / sfhlp01][Running/Boot Start]
- <\SystemRoot\System32\drivers\sfhlp01.sys><StarForce Technologies, Inc.>
- [SogouNetopt / SogouNetopt][Running/Auto Start]
- <\??\E:\日常软件\SogouExplorer\sogounetopt.sys><Sogou.com>
- [SymEvent / SymEvent][Stopped/Manual Start]
- <\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
- ==================================
- 浏览器加载项
- [SafeMon Class]
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <E:\日常软件\360safe\safemon\safemon.dll, (Signed) 360.cn>
- [ICBC Anti-Phishing class]
- {BB4491A2-D11A-4c6b-91C0-B53246A3122B} <C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\ICBC_WIN32\Icbc_AntiPhishing.dll, (Signed) 中国工商银行>
- [TDRDV Class]
- {060CA154-DF25-4F03-98AA-FBCDE9D27382} <C:\WINDOWS\system32\ICBC_TDRDV.dll, (Signed) <Tendyron Corporation>>
- [InfosecCertInstall Class]
- {0EB487C8-E9AC-43A6-8C4C-083999B0622F} <C:\WINDOWS\system32\certInStall.dll, (Signed) >
- [WUWebControl Class]
- {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, (Signed) Microsoft Corporation>
- [Token Class]
- {746E471A-B6E4-44E3-8F3C-2A09B3A030B4} <C:\WINDOWS\system32\icbc_tdrusbkey.dll, (Signed) Tendyron Corporation>
- [AxSubmitControl Class]
- {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} <C:\WINDOWS\system32\SubmitControl.dll, (Signed) >
- [InfoSecICBCNetSign Class]
- {B1FBC1AD-5644-4084-882A-0F8BA85E7506} <C:\WINDOWS\system32\ICBC_N~1.DLL, (Signed) Infosec Technologies Co., Ltd.>
- [PlayCtrl Class]
- {02E2D748-67F8-48B4-8AB4-0A085374BB99} <E:\日常软件\BaiduPlayer\1.0.27.128\Xbdyy.dll, (Signed) >
- [TDRDV Class]
- {060CA154-DF25-4F03-98AA-FBCDE9D27382} <C:\WINDOWS\system32\ICBC_TDRDV.dll, (Signed) <Tendyron Corporation>>
- [InfosecCertInstall Class]
- {0EB487C8-E9AC-43A6-8C4C-083999B0622F} <C:\WINDOWS\system32\certInStall.dll, (Signed) >
- [InstallHelper Class]
- {1DABF8D5-8430-4985-9B7F-A30E53D709B3} <C:\WINDOWS\system32\MMInstaller.dll, (Signed) Tencent>
- []
- {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <, >
- [HTML Document]
- {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, (Signed) N/A>
- [DHTML Edit Control Safe for Scripting for IE5]
- {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, (Signed) Microsoft Corporation>
- []
- {3049C3E9-B461-4BC5-8870-4C09146192CA} <, >
- [XML Document]
- {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, (Signed) Microsoft Corporation>
- [QQPYChecker Class]
- {5052B4D0-9DF7-45ef-88EF-F42C0EA33A43} <E:\日常软件\QQPinyin\1.0.1094.400\QQImeChecker.dll, (Signed) Tencent>
- [Shell Name Space]
- {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A>
- []
- {5C4500A9-0BE9-434E-B807-118E6E5EA3B6} <, >
- [Windows Media Player]
- {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
- [AxInputControl Class]
- {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\system32\InputControl.dll, (Signed) >
- [Token Class]
- {746E471A-B6E4-44E3-8F3C-2A09B3A030B4} <C:\WINDOWS\system32\icbc_tdrusbkey.dll, (Signed) Tendyron Corporation>
- [AxAssistComm Class]
- {84894428-B1F9-4C88-8A45-D6B8524E53B3} <C:\Program Files\ICBCEbankTools\ICBCSetupIntegration\IcbcAssistComm.dll, (Signed) Industrial and Commercial Bank of China>
- []
- {87515F61-A66C-4319-A0E0-D416CB8059E3} <, >
- [Microsoft Web 浏览器]
- {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, (Signed) Microsoft Corporation>
- [AxSubmitControl Class]
- {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} <C:\WINDOWS\system32\SubmitControl.dll, (Signed) >
- [RMGetLicense Class]
- {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, (Signed) Microsoft Corporation>
- [Microsoft Scriptlet Component]
- {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, (Signed) Microsoft Corporation>
- [InfoSecICBCNetSign Class]
- {B1FBC1AD-5644-4084-882A-0F8BA85E7506} <C:\WINDOWS\system32\ICBC_N~1.DLL, (Signed) Infosec Technologies Co., Ltd.>
- [SearchAssistantOC]
- {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A>
- [SafeMon Class]
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <E:\日常软件\360safe\safemon\safemon.dll, (Signed) 360.cn>
- [ICBC Anti-Phishing class]
- {BB4491A2-D11A-4C6B-91C0-B53246A3122B} <C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\ICBC_WIN32\Icbc_AntiPhishing.dll, (Signed) 中国工商银行>
- [AUDIO__MP3 Moniker Class]
- {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
- [AUDIO__X_MS_WMA Moniker Class]
- {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
- [Shockwave Flash Object]
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash11e.ocx, (Signed) Adobe Systems, Inc.>
- []
- {D6E814A0-E0C5-11D4-8D29-0050BA6940E3} <, >
- [PlayerCtrl Class]
- {E05BC2A3-9A46-4a32-80C9-023A473F5B23} <E:\Game\新建文件夹 (2)\QzoneMusic.dll, (Signed) Tencent>
- []
- {E0E899AB-F487-11D5-8D29-0050BA6940E3} <, >
- []
- {EEA17418-02F2-4278-B6B4-E9ED642CE26A} <, >
- []
- {FB5F1910-F110-11D2-BB9E-00C04F795683} <, >
- []
- {FDAEAB93-6DC0-4A63-81C6-95C88ED36F6A} <, >
- ==================================
- 正在运行的进程
- [PID: 712][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 840][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 864][\??\C:\WINDOWS\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 6.0.1.411]
- [C:\WINDOWS\system32\NavLogon.dll] [N/A, ]
- [PID: 908][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.3520 (xpsp_sp2_gdr.090206-1233)]
- [PID: 920][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1072][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1148][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1272][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1368][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1492][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1512][E:\日常软件\360safe\deepscan\zhudongfangyu.exe] [360.cn, 3, 2, 2, 1040]
- [E:\日常软件\360safe\deepscan\CloudCom2.dll] [360.cn, 3, 2, 7, 6051]
- [E:\日常软件\360safe\deepscan\heavygate.dll] [360.cn, 3, 7, 4, 0]
- [E:\日常软件\360safe\deepscan\qutmload.dll] [360.cn, 6, 9, 0, 1033]
- [PID: 2012][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll] [Kaspersky Lab, 1.0.6.411]
- [E:\program files\kingsoft\kingsoft antivirus\kwsui.dll] [Kingsoft Corporation, 2011,12,28,56]
- [E:\program files\kingsoft\kingsoft antivirus\kswebshield.dll] [Kingsoft Corporation, 2012,02,07,124]
- [E:\日常软件\360sd\MenuEx.dll] [360.cn, 2, 1, 0, 2071]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\ShellEx.dll] [Kaspersky Lab, 6.0.1.411]
- [E:\日常软件\HaoZip\HaoZipExt.dll] [好压软件工作室, 2.6.1.8336]
- [PID: 336][C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\ICBC_WIN32\IcbcDaemon.exe] [N/A, ]
- [PID: 432][C:\WINDOWS\system32\D4Svr_ICBC.exe] [Tendyron Corporation, 2, 5, 1, 10]
- [C:\WINDOWS\system32\D4Token_icbc.dll] [Tendyron Corporation, 2, 5, 3, 36]
- [C:\WINDOWS\system32\D4CSP_ICBC.dll] [Tendyron Corporation, 3, 5, 2, 29]
- [C:\WINDOWS\system32\D4Pinpad_ICBC.dll] [Tendyron Corporation, 4, 3, 2, 29]
- [C:\WINDOWS\system32\D4DevEx01_ICBC.dll] [Tendyron Corporation, 2, 5, 2, 22]
- [E:\program files\kingsoft\kingsoft antivirus\kwsui.dll] [Kingsoft Corporation, 2011,12,28,56]
- [PID: 448][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5.1.05]
- [E:\program files\kingsoft\kingsoft antivirus\kwsui.dll] [Kingsoft Corporation, 2011,12,28,56]
- [PID: 456][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [E:\program files\kingsoft\kingsoft antivirus\kwsui.dll] [Kingsoft Corporation, 2011,12,28,56]
- [PID: 480][C:\WINDOWS\system32\D4Ser_ICBC.exe] [Tendyron Corporation, 1, 0, 0, 1]
- [PID: 508][C:\WINDOWS\system32\D4MON_ICBC.exe] [Tendyron Corporation, 1, 0, 0, 1]
- [PID: 596][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 664][C:\Program Files\TCL communication equipment\TCL A1100U\dslmon.exe] [, 1, 0, 0, 1]
- [C:\Program Files\TCL communication equipment\TCL A1100U\Languages\ChineseSimp.dll] [, 1, 0, 0, 1]
- [E:\program files\kingsoft\kingsoft antivirus\kwsui.dll] [Kingsoft Corporation, 2011,12,28,56]
- [PID: 2428][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1660][C:\Program Files\Tencent\TM2009\Bin\TM.exe] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Bin\Common.dll] [Tencent, 1, 40, 1130, 0]
- [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.DLL] [Microsoft Corporation, 8.00.50727.4053]
- [C:\Program Files\Tencent\TM2009\Bin\KernelUtil.dll] [Tencent, 1, 40, 1130, 0]
- [C:\Program Files\Tencent\TM2009\Bin\GF.dll] [Tencent, 1, 40, 1130, 0]
- [C:\Program Files\Tencent\TM2009\Bin\xGraphic32.dll] [Tencent, 1, 40, 1130, 0]
- [C:\Program Files\Tencent\TM2009\Bin\AppUtil.dll] [Tencent, 1, 41, 1260, 0]
- [E:\program files\kingsoft\kingsoft antivirus\kwsui.dll] [Kingsoft Corporation, 2011,12,28,56]
- [E:\program files\kingsoft\kingsoft antivirus\kswebshield.dll] [Kingsoft Corporation, 2012,02,07,124]
- [C:\Program Files\Tencent\TM2009\Bin\MainFrame.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Bin\IM.dll] [Tencent, 1, 40, 1130, 0]
- [C:\Program Files\Tencent\TM2009\Bin\TaskTray.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Bin\TXPFProxy.dll] [Tencent, 1, 40, 1130, 0]
- [C:\Program Files\Tencent\TM2009\Bin\KernelMisc.dll] [Tencent, 1, 40, 1130, 0]
- [C:\Program Files\Tencent\TM2009\Bin\AppMisc.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Bin\AppCtrl.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Bin\ChatFrame.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Bin\ConfigCenter.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Bin\CustomFace.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Bin\LongCnn.dll] [Tencent, 1, 40, 1130, 0]
- [C:\Program Files\Tencent\TM2009\Bin\ContactInfoFrame.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Bin\MsgMgr.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Bin\SkinMgr.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Bin\QInterLive.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Bin\SystemMsg.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Plugin\Com.Tencent.AudioVideo\Bin\AudioVideo.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Plugin\Com.Tencent.Weather\Bin\Weather.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Common Files\Tencent\TXSSO\Bin\SSOPlatform.dll] [Tencent, 1.2.1.23]
- [C:\Program Files\Common Files\Tencent\TXSSO\Bin\SSOCommon.DLL] [Tencent, 1.2.1.10]
- [C:\WINDOWS\system32\msdmo.dll] [, ]
- [C:\Program Files\Tencent\TM2009\Bin\GroupApp.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll] [Kaspersky Lab, 1.0.6.411]
- [C:\Program Files\Tencent\TM2009\Plugin\com.tencent.paycenter\Bin\PayCenter.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Plugin\com.tencent.soso\Bin\Soso.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Plugin\com.tencent.wireless\Bin\Wireless.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Bin\InformationBox.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Plugin\com.tencent.crm\Bin\CRM.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Plugin\com.tencent.memo\Bin\Memo.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Plugin\com.tencent.qqgame\Bin\QQGame.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Plugin\com.tencent.tmmisc\Bin\TMMisc.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Plugin\com.tencent.filetransfer\Bin\FileTransfer.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Plugin\com.tencent.mail\Bin\Mail.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll] [Kaspersky Lab, 6.0.1.411]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prremote.dll] [Kaspersky Lab, 6.0.1.411]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll] [Kaspersky Lab, 6.0.1.411]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl] [Kaspersky Lab, 6.0.1.411]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl] [Kaspersky Lab, 6.0.1.411]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl] [Kaspersky Lab, 6.0.1.411]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl] [Kaspersky Lab, 6.0.1.411]
- [C:\Program Files\Tencent\TM2009\Bin\AddrSearch.dll] [Tencent, 2, 3, 12, 11]
- [C:\Program Files\Tencent\TM2009\Bin\Camera.dll] [Tencent, 1, 41, 1260, 0]
- [C:\Program Files\Tencent\TM2009\Bin\SCCore.dll] [Tencent, 1, 7, 1, 6]
- [PID: 2740][C:\Program Files\Tencent\TM2009\Bin\TXPlatform.exe] [Tencent, 1, 40, 1130, 0]
- [E:\program files\kingsoft\kingsoft antivirus\kwsui.dll] [Kingsoft Corporation, 2011,12,28,56]
- [E:\program files\kingsoft\kingsoft antivirus\kswebshield.dll] [Kingsoft Corporation, 2012,02,07,124]
- [C:\Program Files\Tencent\TM2009\Bin\TXPFProxy.dll] [Tencent, 1, 40, 1130, 0]
- [PID: 3108][E:\日常软件\SogouExplorer\sogouexplorer.exe] [Sogou.com, 3.1.0.3846]
- [E:\日常软件\SogouExplorer\SogouExplorer.dll] [Sogou.com, 3.1.0.3846]
- [E:\日常软件\SogouExplorer\Dynamark.dll] [Sogou.com, 3.1.0.3846]
- [E:\日常软件\SogouExplorer\SEFramework.dll] [Sogou.com, 3.1.0.3846]
- [E:\日常软件\SogouExplorer\sogounet.dll] [Sogou.com, 3.1.0.3846]
- [E:\日常软件\SogouExplorer\sogouipfilter.dll] [Sogou.com, 3.1.0.3846]
- [E:\日常软件\SogouExplorer\bseapi.dll] [Keniu Network Technology., 1.1.0.1130]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll] [Kaspersky Lab, 1.0.6.411]
- [E:\日常软件\SogouExplorer\bseupd.dll] [Keniu Network Technology., 1.1.0.1130]
- [E:\日常软件\SogouExplorer\bsecore.dll] [Keniu Network Technology., 1.1.0.1131]
- [E:\日常软件\SogouExplorer\MetaSearch.dll] [Sogou.com, 3.1.0.3846]
- [E:\日常软件\SogouExplorer\Download.dll] [Sogou.com, 3.1.0.3846]
- [E:\日常软件\SogouExplorer\SEMenu.dll] [Sogou.com, 3.1.0.3846]
- [PID: 1976][E:\日常软件\SogouExplorer\sogouexplorer.exe] [Sogou.com, 3.1.0.3846]
- [E:\日常软件\SogouExplorer\SogouExplorer.dll] [Sogou.com, 3.1.0.3846]
- [E:\日常软件\SogouExplorer\WebkitCore.dll] [Sogou.com, 3, 1, 0, 1359]
- [E:\日常软件\SogouExplorer\SEParser.dll] [Sogou.com, 3.1.0.3846]
- [C:\Documents and Settings\User\Application Data\SogouExplorer\Bin\icudt.dll] [The ICU Project, 4, 6, 0, 0]
- [PID: 2880][E:\日常软件\SogouExplorer\sogouexplorer.exe] [Sogou.com, 3.1.0.3846]
- [E:\日常软件\SogouExplorer\SogouExplorer.dll] [Sogou.com, 3.1.0.3846]
- [E:\日常软件\SogouExplorer\WebkitCore.dll] [Sogou.com, 3, 1, 0, 1359]
- [E:\日常软件\SogouExplorer\SEParser.dll] [Sogou.com, 3.1.0.3846]
- [C:\Documents and Settings\User\Application Data\SogouExplorer\Bin\icudt.dll] [The ICU Project, 4, 6, 0, 0]
- [E:\日常软件\SogouExplorer\avcodec-52.dll] [N/A, ]
- [E:\日常软件\SogouExplorer\avutil-50.dll] [N/A, ]
- [E:\日常软件\SogouExplorer\avformat-52.dll] [N/A, ]
- [E:\日常软件\SogouExplorer\Extension.dll] [Sogou.com, 3.1.0.3846]
- [C:\Documents and Settings\User\Application Data\SogouExplorer\Extension\com.sogou.snapTaker\0.4.2\npPrintScreen.dll] [Sogou.com, 1, 0, 0, 1]
- [PID: 3720][E:\日常软件\SogouExplorer\sogouexplorer.exe] [Sogou.com, 3.1.0.3846]
- [E:\日常软件\SogouExplorer\SogouExplorer.dll] [Sogou.com, 3.1.0.3846]
- [E:\日常软件\SogouExplorer\TridentCore.dll] [Sogou.com, 3.1.0.3846]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll] [Kaspersky Lab, 1.0.6.411]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll] [Kaspersky Lab, 6.0.1.411]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prremote.dll] [Kaspersky Lab, 6.0.1.411]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll] [Kaspersky Lab, 6.0.1.411]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl] [Kaspersky Lab, 6.0.1.411]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl] [Kaspersky Lab, 6.0.1.411]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl] [Kaspersky Lab, 6.0.1.411]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl] [Kaspersky Lab, 6.0.1.411]
- [C:\Documents and Settings\User\Application Data\SogouExplorer\Bin\flash_ie.ocx] [Adobe Systems, Inc., 10,3,181,26]
- [E:\日常软件\SogouExplorer\DialogCore.dll] [Sogou.com, 3.1.0.3846]
- [PID: 2692][E:\日常软件\SogouExplorer\sogouexplorer.exe] [Sogou.com, 3.1.0.3846]
- [E:\日常软件\SogouExplorer\SogouExplorer.dll] [Sogou.com, 3.1.0.3846]
- [E:\日常软件\SogouExplorer\WebkitCore.dll] [Sogou.com, 3, 1, 0, 1359]
- [E:\日常软件\SogouExplorer\SEParser.dll] [Sogou.com, 3.1.0.3846]
- [C:\Documents and Settings\User\Application Data\SogouExplorer\Bin\icudt.dll] [The ICU Project, 4, 6, 0, 0]
- [E:\日常软件\SogouExplorer\avcodec-52.dll] [N/A, ]
- [E:\日常软件\SogouExplorer\avutil-50.dll] [N/A, ]
- [E:\日常软件\SogouExplorer\avformat-52.dll] [N/A, ]
- [E:\日常软件\SogouExplorer\DialogCore.dll] [Sogou.com, 3.1.0.3846]
- [C:\WINDOWS\system32\QQPINYIN.IME] [Tencent, 1.0.1094.400]
- [PID: 1848][C:\Documents and Settings\User\桌面\SREngLdr.EXE] [Smallfrogs Studio, 2.8.4.1331]
- [PID: 3596][C:\Documents and Settings\User\桌面\SRE22ad2f5e.EXE] [Smallfrogs Studio, 2.8.4.1331]
- [E:\program files\kingsoft\kingsoft antivirus\kwsui.dll] [Kingsoft Corporation, 2011,12,28,56]
- [E:\program files\kingsoft\kingsoft antivirus\kswebshield.dll] [Kingsoft Corporation, 2012,02,07,124]
- ==================================
- 文件关联
- .TXT Error. [C:\WINDOWS\notepad.exe %1]
- .EXE OK. ["%1" %*]
- .COM OK. ["%1" %*]
- .PIF OK. ["%1" %*]
- .REG OK. [regedit.exe "%1"]
- .BAT OK. ["%1" %*]
- .SCR OK. ["%1" /S]
- .CHM Error. ["hh.exe" %1]
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
- .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
- .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- ==================================
- Winsock 提供者
- N/A
- ==================================
- Autorun.inf
- N/A
- ==================================
- HOSTS 文件
- 127.0.0.1 localhost
- ==================================
- 进程特权扫描
- N/A
- ==================================
- 计划任务
- [已启用] KsafeDelay.job
- E:\program files\ksafe\KSafeTray.exe -delayruncheck
- [已启用] RealUpgradeLogonTaskS-1-5-21-1177238915-920026266-839522115-1003.job
- C:\Program Files\Real\RealUpgrade\realupgrade.exe
- [已启用] RealUpgradeScheduledTaskS-1-5-21-1177238915-920026266-839522115-1003.job
- C:\Program Files\Real\RealUpgrade\realupgrade.exe
- ==================================
- Windows 安全更新检查
- Microsoft .NET Framework 版本 1.1,简体中文版
- KB891122, 启用了 WMDRM 的 Media Player 更新程序 (KB891122)
- KB925850, Windows Media Player 11
- KB940157, 用于 Windows XP 的 Windows 搜索 4.0 (KB940157)
- KB909520, Microsoft 基本智能卡加密服务提供程序包: x86 (KB909520)
- KB936929, Windows XP Service Pack 3 (KB936929)
- KB951847, Microsoft .NET Framework 3.5 Service Pack 1 和 .NET Framework 3.5 Family Update (KB951847) x86
- KB980195, 用于 Windows XP 的 ActiveX Killbit 累积安全更新程序 (KB980195) MS10-034
- KB890830, Windows 恶意软件删除工具 - 2012 年 2 月 (KB890830)
- ==================================
- API HOOK
- RVA 错误: LoadLibraryA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
- RVA 错误: LoadLibraryExA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
- RVA 错误: LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
- RVA 错误: LoadLibraryW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
- RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
- ==================================
- 隐藏进程
- N/A
- ==================================
复制代码 |