-
- ==================================
- 正在运行的进程
- [PID: 896 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 956 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 984 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\WINDOWS\system32\WgaLogon.dll] [Microsoft Corporation, 1.7.0018.5]
- [C:\WINDOWS\system32\msplrct.dll] [N/A, ]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 1036 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\AppPatch\AcAdProc.dll] [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
- [C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\loader.dll] [N/A, ]
- [PID: 1048 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1208 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1276 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1420 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1544 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1616 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1948 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
- [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.1897.0]
- [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.1897.0]
- [PID: 580 / SYSTEM][C:\Program Files\Common Files\LightScribe\LSSrvc.exe] [Hewlett-Packard Company, 1.4.74.1]
- [C:\Program Files\Common Files\LightScribe\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
- [C:\Program Files\Common Files\LightScribe\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
- [PID: 772 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1484 / appleapple][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
- [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
- [C:\WINDOWS\system32\WPDShServiceObj.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [C:\WINDOWS\system32\PortableDeviceTypes.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
- [C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.4543]
- [C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4543]
- [C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4543]
- [C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3.0.0.4543]
- [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4543]
- [PID: 1692 / SYSTEM][C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe] [Hewlett-Packard Development Company, L.P., 2, 0, 1, 8]
- [PID: 2040 / appleapple][C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe] [Sun Microsystems, Inc., 6.0.30.5]
- [PID: 172 / appleapple][C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe] [Hewlett-Packard Development Company, L.P., 2, 0, 5, 1]
- [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [PID: 2008 / appleapple][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3.0.0.4543]
- [C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4543]
- [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4543]
- [C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4543]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [PID: 248 / appleapple][C:\WINDOWS\system32\igfxpers.exe] [Intel Corporation, 3.0.0.4543]
- [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4543]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [PID: 276 / appleapple][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] [Synaptics, Inc., 8.2.23 31Mar06]
- [C:\WINDOWS\system32\SynCOM.dll] [Synaptics, Inc., 8.2.23 31Mar06]
- [C:\WINDOWS\system32\SynTPAPI.dll] [Synaptics, Inc., 8.2.23 31Mar06]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [PID: 304 / appleapple][C:\Program Files\HP\QuickPlay\QPService.exe] [CyberLink Corp., 4.5.0.0000]
- [C:\Program Files\HP\QuickPlay\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
- [C:\Program Files\HP\QuickPlay\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
- [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
- [C:\Program Files\HP\QuickPlay\helper.dll] [CyberLink Corp., 3.00.4021 ]
- [C:\Program Files\HP\QuickPlay\Kernel\common\CLDataSync.dll] [, 1, 0, 0, 1]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [PID: 376 / appleapple][C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe] [ Hewlett-Packard Development Company, L.P., 6, 0, 5, 1]
- [C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBSERVICE.dll] [Hewlett-Packard Development Company, L.P., 6, 0, 5, 1]
- [C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\hpqExec.dll] [Hewlett-Packard Company, 6, 0, 5, 1]
- [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [PID: 400 / appleapple][C:\WINDOWS\VM_STI.EXE] [VM., 4.2.610.4]
- [C:\WINDOWS\system32\msdmo.dll] [, ]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [PID: 548 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 608 / appleapple][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3018]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [PID: 1092 / appleapple][C:\Program Files\Thunder Network\WebThunder\WebThunder.exe] [深圳市迅雷网络技术有限公司, 1, 11, 1, 188]
- [C:\Program Files\Thunder Network\WebThunder\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
- [C:\Program Files\Thunder Network\WebThunder\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 2, 4, 38]
- [C:\Program Files\Thunder Network\WebThunder\download_interface.dll] [Thunder Networking Technologies,LTD, 2, 19, 2, 178]
- [C:\Program Files\Thunder Network\WebThunder\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031]
- [C:\Program Files\Thunder Network\WebThunder\asyn_dns.dll] [Thunder Networking Technologies,LTD, 2, 19, 2, 178]
- [C:\Program Files\Thunder Network\WebThunder\streammedialib.dll] [, 1, 2, 0, 78]
- [C:\Program Files\Thunder Network\WebThunder\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 16, 5, 61]
- [C:\Program Files\Thunder Network\WebThunder\CacheServer.dll] [, 1, 0, 0, 1]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
- [C:\Program Files\Thunder Network\WebThunder\XLSafe\SafeInfo.dll] [深圳市迅雷网络技术有限公司, 1, 0, 1, 0]
- [C:\Program Files\Thunder Network\WebThunder\XLNet.Dll] [Thunder Networking Technologies,LTD, 1, 2, 1, 9]
- [C:\Program Files\Thunder Network\WebThunder\DownAndPlay\WebDownAndPlay.dll] [ShenZhen Thunder Networking Technologies Ltd., 1, 0, 2, 20]
- [C:\Program Files\Thunder Network\WebThunder\XLStatistic\XLStatisticAddin.dll] [深圳市迅雷网络技术有限公司, 1, 3, 0, 4]
- [PID: 648 / appleapple][C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe] [Hewlett-Packard, 80, 1, 0, 0]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [PID: 676 / appleapple][C:\Program Files\OCINS\idnsvr.exe] [中国互联网信息中心(CNNIC), 2, 6, 0, 1]
- [C:\Program Files\OCINS\idnsvr.dll] [中国互联网信息中心(CNNIC), 2, 6, 0, 2]
- [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [PID: 732][C:\Program Files\木马专杀大师\木马专杀大师.exe] [木马专杀大师, 2.1.1.0]
- [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [PID: 740 / appleapple][C:\Program Files\Unlocker\UnlockerAssistant.exe] [N/A, ]
- [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [PID: 844 / appleapple][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [PID: 1312 / appleapple][C:\Program Files\Zcom\E-Space.exe] [智通无限, 0.0.1]
- [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
- [C:\Program Files\Zcom\PlugIns\zfun_httpd.dll] [N/A, ]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.5510]
- [C:\Program Files\Zcom\PlugIns\zfun_stat.dll] [N/A, ]
- [PID: 3392 / appleapple][C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE] [, 1, 0, 0, 7]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
- [PID: 3400 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 3256 / appleapple][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
- [c:\program files\google\googletoolbar4.dll] [Google Inc., 4, 0, 1601, 4978]
- [C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
- [C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 46]
- [C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.1.2003110300]
- [C:\PROGRA~1\OCINS\ieaux.dll] [中国互联网络信息中心(CNNIC), 2, 6, 0, 9]
- [C:\PROGRA~1\OCINS\idnsvr.dll] [中国互联网信息中心(CNNIC), 2, 6, 0, 2]
- [C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll] [Sun Microsystems, Inc., 6.0.30.5]
- [C:\Program Files\Java\jre1.6.0_03\bin\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
- [F:\xunkei\ComDlls\XunLeiBHO_002.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
- [C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\yVqWXzrSfC.dll] [Microsoft Corporation, 3, 0, 8, 0]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\pr_remote.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl] [Kaspersky Lab, 6.0.0.304]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl] [Kaspersky Lab, 6.0.0.299]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl] [Kaspersky Lab, 6.0.0.299]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl] [Kaspersky Lab, 6.0.0.299]
- [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
- [C:\WINDOWS\system32\xpsp3res.dll] [Microsoft Corporation, 5.1.2600.3199 (xpsp_sp2_gdr.070821-1257)]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\nfio.ppl] [Kaspersky Lab, 6.0.0.299]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\fsdrvplgn.ppl] [Kaspersky Lab, 6.0.0.299]
- [C:\WINDOWS\system32\msdmo.dll] [, ]
- [C:\Program Files\Common Files\muvee Technologies\MainConcept\mcspmpeg.ax] [MainConcept AG, 1, 0, 0, 58]
- [C:\Program Files\Common Files\muvee Technologies\MainConcept\mpegin.dll] [MainConcept AG, official release build]
- [PID: 1356 / appleapple][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
- [c:\program files\google\googletoolbar4.dll] [Google Inc., 4, 0, 1601, 4978]
- [C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
- [C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 46]
- [C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.1.2003110300]
- [C:\PROGRA~1\OCINS\ieaux.dll] [中国互联网络信息中心(CNNIC), 2, 6, 0, 9]
- [C:\PROGRA~1\OCINS\idnsvr.dll] [中国互联网信息中心(CNNIC), 2, 6, 0, 2]
- [C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll] [Sun Microsystems, Inc., 6.0.30.5]
- [C:\Program Files\Java\jre1.6.0_03\bin\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
- [F:\xunkei\ComDlls\XunLeiBHO_002.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
- [C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\yVqWXzrSfC.dll] [Microsoft Corporation, 3, 0, 8, 0]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\pr_remote.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl] [Kaspersky Lab, 6.0.0.304]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl] [Kaspersky Lab, 6.0.0.299]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl] [Kaspersky Lab, 6.0.0.299]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl] [Kaspersky Lab, 6.0.0.299]
- [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
- [C:\WINDOWS\system32\xpsp3res.dll] [Microsoft Corporation, 5.1.2600.3199 (xpsp_sp2_gdr.070821-1257)]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\nfio.ppl] [Kaspersky Lab, 6.0.0.299]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\fsdrvplgn.ppl] [Kaspersky Lab, 6.0.0.299]
- [PID: 1832 / appleapple][C:\Program Files\WinRAR\WinRAR.exe] [N/A, ]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
- [C:\WINDOWS\system32\wpdshext.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
- [C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
- [C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
- [PID: 3216 / appleapple][C:\DOCUME~1\APPLEA~1\LOCALS~1\Temp\Rar$EX18.594\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
- [C:\Program Files\木马专杀大师\Sockethook.dll] [N/A, ]
- [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
- [C:\DOCUME~1\APPLEA~1\LOCALS~1\Temp\Rar$EX18.594\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
- ==================================
- 文件关联
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .EXE OK. ["%1" %*]
- .COM OK. ["%1" %*]
- .PIF OK. ["%1" %*]
- .REG OK. [regedit.exe "%1"]
- .BAT OK. ["%1" %*]
- .SCR OK. ["%1" /S]
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]
- .HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- ==================================
- Winsock 提供者
- N/A
- ==================================
- Autorun.inf
- N/A
- ==================================
- HOSTS 文件
- 127.0.0.1 localhost
- ==================================
- 进程特权扫描
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 172, C:\PROGRAM FILES\HPQ\HP WIRELESS ASSISTANT\HP WIRELESS ASSISTANT.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 304, C:\PROGRAM FILES\HP\QUICKPLAY\QPSERVICE.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 376, C:\PROGRAM FILES\HEWLETT-PACKARD\HP QUICK LAUNCH BUTTONS\QLBCTRL.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 400, C:\WINDOWS\VM_STI.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 608, C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE]
- 特殊特权被允许: SeDebugPrivilege [PID = 732, C:\PROGRAM FILES\木马专杀大师\木马专杀大师.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 732, C:\PROGRAM FILES\木马专杀大师\木马专杀大师.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 1312, C:\PROGRAM FILES\ZCOM\E-SPACE.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 1832, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
- ==================================
- API HOOK
- RVA 错误: LoadLibraryA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
- RVA 错误: LoadLibraryExA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
- RVA 错误: LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
- RVA 错误: LoadLibraryW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
- RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
- ==================================
- 隐藏进程
- [733] C:\Program Files\木马专杀大师\木马专杀大师.exe
- ==================================
复制代码 |