- [C:\WINDOWS\system32\xunleibho_v4.dll] [, 4, 3, 2, 29]
- [D:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
- [PID: 1948 / Administrator][C:\windows\RTHDCPL.EXE] [Realtek Semiconductor Corp., 2.0.2.1]
- [C:\windows\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 1964 / Administrator][C:\HP\KBD\KBD.EXE] [Hewlett-Packard Company, 1.0.2.2.20205]
- [C:\HP\KBD\led.dll] [Hewlett-Packard Company, 1.0.2.0]
- [C:\HP\KBD\USB.dll] [Hewlett-Packard Company, 1.0.2.2.071205]
- [C:\HP\KBD\ps2.dll] [Hewlett-Packard Company, 1.0.2.2.112404]
- [C:\HP\KBD\msg.dll] [Hewlett-Packard Company, 1.0.2.2.112404]
- [C:\HP\KBD\osd.dll] [Hewlett-Packard Company, 1.0.2.2.071105]
- [C:\HP\KBD\sct.dll] [Hewlett-Packard Company, 1.0.2.2.32205]
- [C:\HP\KBD\onl.dll] [Hewlett-Packard Company, 1.0.2.2.052705]
- [C:\HP\KBD\aol.dll] [Hewlett-Packard Company, 1.0.2.2.071105]
- [C:\HP\KBD\url.dll] [Hewlett-Packard Company, 1.0.2.2.071105]
- [C:\HP\KBD\cfg.dll] [Hewlett-Packard Company, 1.0.2.1]
- [C:\HP\KBD\MSIKBDIF.DLL] [Hewlett-Packard Company, 1.0.2.0]
- [PID: 2016 / Administrator][E:\软件\脱兔\Tuotu\Tuotu.exe] [Tuotu.com, 2.1.0.64]
- [E:\软件\脱兔\Tuotu\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0]
- [E:\软件\脱兔\Tuotu\emule.dll] [http://www.emule-project.net, 0.47.0 Unicode]
- [E:\软件\卡巴杀软\adialhk.dll] [Kaspersky Lab, 6.0.2.621]
- [PID: 144 / Administrator][C:\windows\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1608 / SYSTEM][C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe] [Autodesk, 2.66.000]
- [PID: 2980 / LOCAL SERVICE][C:\windows\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1916 / Administrator][E:\软件\QQ\QQ.exe] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\QQBaseClassInDll.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\QQHelperDll.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\BasicCtrlDll.dll] [TENCENT, 7, 0, 225, 1651]
- [E:\软件\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
- [E:\软件\QQ\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
- [E:\软件\QQ\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
- [E:\软件\QQ\QQAPI.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
- [E:\软件\QQ\LoginCtrl.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\LoginCtrlRes.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\QQRes.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\MailSummary.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\QQMainFrame.dll] [N/A, ]
- [E:\软件\QQ\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
- [E:\软件\QQ\CQQApplication.dll] [N/A, ]
- [E:\软件\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]
- [E:\软件\QQ\NewSkin.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\HostingMgr.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\CameraDll.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\QQKnowledgeSearch.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\QQAllInOne.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\SCCore.dll] [TENCENT, 1, 6, 0, 2]
- [E:\软件\QQ\QQSpace.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\vbscript.dll] [Microsoft Corporation, 5.6.0.7426]
- [C:\windows\system32\msdmo.dll] [, ]
- [E:\软件\卡巴杀软\adialhk.dll] [Kaspersky Lab, 6.0.2.621]
- [E:\软件\QQ\QQGroupMng.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\UserDefinedHead.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\QQPlugin.dll] [N/A, ]
- [E:\软件\QQ\QQConfigPlugin.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\QQAvatar.dll] [N/A, ]
- [E:\软件\卡巴杀软\scrchpg.dll] [Kaspersky Lab, 6.0.2.621]
- [E:\软件\QQ\QRingMng.dll] [N/A, ]
- [E:\软件\QQ\LongConnection.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\PhoneAPI.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
- [C:\windows\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [E:\软件\QQ\QQPet.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\QQSysMsgMng.dll] [N/A, ]
- [E:\软件\QQ\QQCustomFace.dll] [N/A, ]
- [E:\软件\QQ\GroupConnection.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\BQQApplication.dll] [N/A, ]
- [C:\windows\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [E:\软件\QQ\CommercesMng.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
- [E:\软件\QQ\ImageOle.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\QQLiveQMng.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\卡巴杀软\klscav.dll] [Kaspersky Lab, 6.0.2.621]
- [E:\软件\卡巴杀软\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42]
- [E:\软件\卡巴杀软\prremote.dll] [Kaspersky Lab, 6.0.2.621]
- [E:\软件\卡巴杀软\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.42]
- [E:\软件\卡巴杀软\prloader.dll] [Kaspersky Lab, 6.0.2.621]
- [E:\软件\卡巴杀软\prkernel.ppl] [Kaspersky Lab, 6.0.2.621]
- [e:\软件\卡巴杀软\params.ppl] [Kaspersky Lab, 6.0.2.621]
- [e:\软件\卡巴杀软\pxstub.ppl] [Kaspersky Lab, 6.0.2.621]
- [e:\软件\卡巴杀软\tempfile.ppl] [Kaspersky Lab, 6.0.2.621]
- [E:\软件\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 300]
- [E:\软件\QQ\QQSceneMng.dll] [N/A, ]
- [E:\软件\QQ\QQZip.dll] [TENCENT, 7,0,225,1651]
- [E:\软件\QQ\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 1, 9, 96]
- [E:\软件\QQ\QQMsgFriendMng.dll] [N/A, ]
- [E:\软件\QQ\QQMagicFace.dll] [TENCENT, 7,0,225,1651]
- [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx] [Adobe Systems, Inc., 9,0,45,0]
- [E:\软件\QQ\QQFileTransfer.dll] [TENCENT, 7,0,225,1651]
- [PID: 2964 / Administrator][E:\软件\QQ\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
- [E:\软件\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
- [PID: 2160 / Administrator][E:\软件\淘宝旺旺\WangWang.exe] [阿里巴巴软件(上海)有限公司, 5, 5, 0, 2]
- [E:\软件\淘宝旺旺\AliViewCtrl.dll] [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 2]
- [E:\软件\淘宝旺旺\VLNetwork.dll] [阿里巴巴软件(上海)有限公司, 1, 0, 0, 6]
- [E:\软件\淘宝旺旺\MFC80.DLL] [Microsoft Corporation, 8.00.50727.762]
- [E:\软件\淘宝旺旺\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762]
- [E:\软件\淘宝旺旺\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762]
- [E:\软件\淘宝旺旺\AliViewMedia.dll] [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 2]
- [E:\软件\淘宝旺旺\VideoCap.dll] [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 4]
- [E:\软件\淘宝旺旺\VLAudio.dll] [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 5]
- [E:\软件\淘宝旺旺\JsmShow.dll] [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 4]
- [E:\软件\淘宝旺旺\AliSkin.dll] [阿里巴巴软件(上海)有限公司, 1.0.0.1]
- [E:\软件\淘宝旺旺\PngLib.dll] [阿里巴巴软件(上海)有限公司, 1, 0, 0, 1]
- [E:\软件\淘宝旺旺\zlib.dll] [, 1.2.3]
- [E:\软件\淘宝旺旺\ww_network.dll] [阿里巴巴软件(上海)有限公司, 1, 0, 2, 2]
- [E:\软件\淘宝旺旺\MFC80CHS.DLL] [Microsoft Corporation, 8.00.50727.762]
- [E:\软件\淘宝旺旺\Ali_Res.DLL] [N/A, ]
- [E:\软件\卡巴杀软\scrchpg.dll] [Kaspersky Lab, 6.0.2.621]
- [E:\软件\卡巴杀软\adialhk.dll] [Kaspersky Lab, 6.0.2.621]
- [E:\软件\淘宝旺旺\WangWangX4.dll] [阿里巴巴软件(上海)有限公司, 1, 0, 0, 1]
- [E:\软件\淘宝旺旺\RICHED32.DLL] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [E:\软件\淘宝旺旺\RICHED20.dll] [Microsoft Corporation, 5.30.23.1221]
- [E:\软件\淘宝旺旺\RichOne.dll] [阿里巴巴软件(上海)有限公司, 1.0.0.1]
- [E:\软件\淘宝旺旺\TBProgress.dll] [阿里巴巴软件(上海)有限公司, 1.0.0.1]
- [E:\软件\淘宝旺旺\MessageNotify.dll] [, 1, 0, 0, 1]
- [E:\软件\卡巴杀软\klscav.dll] [Kaspersky Lab, 6.0.2.621]
- [E:\软件\卡巴杀软\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42]
- [E:\软件\卡巴杀软\prremote.dll] [Kaspersky Lab, 6.0.2.621]
- [E:\软件\卡巴杀软\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.42]
- [E:\软件\卡巴杀软\prloader.dll] [Kaspersky Lab, 6.0.2.621]
- [E:\软件\卡巴杀软\prkernel.ppl] [Kaspersky Lab, 6.0.2.621]
- [e:\软件\卡巴杀软\params.ppl] [Kaspersky Lab, 6.0.2.621]
- [e:\软件\卡巴杀软\pxstub.ppl] [Kaspersky Lab, 6.0.2.621]
- [e:\软件\卡巴杀软\tempfile.ppl] [Kaspersky Lab, 6.0.2.621]
- [C:\windows\system32\msdmo.dll] [, ]
- [C:\windows\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 3620 / Administrator][D:\Program Files\Tencent\TT\TTraveler.exe] [腾讯公司, 3.2.200.275]
- [C:\windows\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx] [Adobe Systems, Inc., 9,0,45,0]
- [PID: 3540 / Administrator][E:\软件安装包\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
- [E:\软件安装包\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
- [E:\软件\卡巴杀软\adialhk.dll] [Kaspersky Lab, 6.0.2.621]
- ==================================
- 文件关联
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .EXE OK. ["%1" %*]
- .COM OK. ["%1" %*]
- .PIF OK. ["%1" %*]
- .REG OK. [regedit.exe "%1"]
- .BAT OK. ["%1" %*]
- .SCR OK. ["%1" /S]
- .CHM OK. ["C:\windows\hh.exe" %1]
- .HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- ==================================
- Winsock 提供者
- N/A
- ==================================
- Autorun.inf
- N/A
- ==================================
- HOSTS 文件
- N/A
- ==================================
- 进程特权扫描
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 1964, C:\HP\KBD\KBD.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 2016, E:\软件\脱兔\TUOTU\TUOTU.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 1916, E:\软件\QQ\QQ.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 2964, E:\软件\QQ\TIMPLATFORM.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 2160, E:\软件\淘宝旺旺\WANGWANG.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 3620, D:\PROGRAM FILES\TENCENT\TT\TTRAVELER.EXE]
- ==================================
- API HOOK
- RVA 错误: LoadLibraryA (危险等级: 高, 被下面模块所HOOK: \??\C:\windows\system32\drivers\klif.sys)
- RVA 错误: LoadLibraryExA (危险等级: 高, 被下面模块所HOOK: \??\C:\windows\system32\drivers\klif.sys)
- RVA 错误: LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: \??\C:\windows\system32\drivers\klif.sys)
- RVA 错误: LoadLibraryW (危险等级: 高, 被下面模块所HOOK: \??\C:\windows\system32\drivers\klif.sys)
- RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: \??\C:\windows\system32\drivers\klif.sys)
- ==================================
- 隐藏进程
- N/A
- ==================================
复制代码 |