==================================
正在运行的进程
[PID: 588][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 648][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 672][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10042]
[PID: 716][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10042]
[PID: 728][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10042]
[PID: 892][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10042]
[PID: 1236][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10042]
[PID: 1388][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10042]
[PID: 1448][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10042]
[PID: 1552][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10042]
[PID: 1824][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10042]
[c:\documents and settings\administrator\application data\ppstream\bin\1.0.0.2\vodrc.dll] [ppstream.com, 1.0.0.2]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Filseclab\Twister\Twshlext.dll] [Filseclab Corp., 2, 0, 2, 1022]
[D:\PROGRA~1\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 2, 0, 0, 1]
[C:\WINDOWS\system32\dllMergeDict.dll] [N/A, ]
[D:\输入法\SogouInput2.0f\Plugin\SgImeWord.dll] [, 1, 0, 0, 31]
[PID: 260][C:\Program Files\Filseclab\Twister\twister.exe] [Filseclab Corporation, 7, 0, 7, 22971]
[C:\Program Files\Filseclab\Twister\Twshlext.DLL] [Filseclab Corp., 2, 0, 2, 1022]
[C:\Program Files\Filseclab\Twister\Quarantine.dll] [Filseclab Corp., 2, 0, 0, 581]
[C:\Program Files\Filseclab\Twister\W32Tools.dll] [Filseclab Corp., 2, 0, 3, 1949]
[C:\Program Files\Filseclab\Twister\virsubm.dll] [Filseclab Corp., 2, 0, 3, 533]
[C:\Program Files\Filseclab\Twister\psmgr.dll] [Filseclab Corp., 1, 0, 1, 1071]
[C:\Program Files\Filseclab\Twister\zipexp.dll] [Filseclab Corp., 1, 0, 2, 177]
[C:\Program Files\Filseclab\Twister\emlib.dll] [Filseclab Corp., 1, 0, 2, 1254]
[C:\Program Files\Filseclab\Twister\ctools.dll] [Filseclab Corp., 1, 0, 0, 19]
[C:\Program Files\Filseclab\Twister\Regpro.dll] [Filseclab Corp., 2, 0, 1, 1268]
[C:\Program Files\Filseclab\Twister\Schedule.dll] [Filseclab Corp., 1, 0, 1, 34]
[C:\Program Files\Filseclab\Twister\lsf.dll] [Filseclab Corp., 1, 0, 1, 286]
[C:\Program Files\Filseclab\Twister\falgorit.dll] [Filseclab Corp., 1, 0, 0, 446]
[C:\Program Files\Filseclab\Twister\message.dll] [Filseclab Corp., 1, 0, 1, 1598]
[C:\Program Files\Filseclab\Twister\fgui.dll] [Filseclab Corp., 1, 0, 1, 128]
[C:\Program Files\Filseclab\Twister\kdf.dll] [Filseclab Corp., 1, 0, 3, 1019]
[C:\Program Files\Filseclab\Twister\twsupd.dll] [Filseclab Corp., 2, 0, 1, 676]
[C:\Program Files\Filseclab\Twister\FAPIConv.dll] [Filseclab Corp., 1, 0, 0, 45]
[C:\Program Files\Filseclab\Twister\mdcoder.dll] [Filseclab Corp., 1, 0, 0, 21]
[C:\Program Files\Filseclab\Twister\Decexp.dll] [Filseclab Corp., 2, 0, 2, 2005]
[C:\Program Files\Filseclab\Twister\Unchm.dll] [Filseclab Corp., 1, 0, 2, 114]
[C:\Program Files\Filseclab\Twister\unrar.dll] [N/A, ]
[C:\Program Files\Filseclab\Twister\unemb.dll] [Filseclab Corp., 2, 0, 2, 528]
[C:\Program Files\Filseclab\Twister\unsevzip.dll] [Filseclab Corp., 2, 0, 2, 134]
[C:\Program Files\Filseclab\Twister\unmisc.dll] [Filseclab Corp., 1, 0, 1, 211]
[C:\Program Files\Filseclab\Twister\AntiRK.dll] [Filseclab Corporation, 2, 0, 0, 2245]
[C:\Program Files\Filseclab\Twister\filvss.dll] [Filseclab Corporation, 2, 0, 0, 841]
[C:\Program Files\Filseclab\Twister\tsc.dll] [Filseclab Corp., 2, 0, 1, 104]
[C:\Program Files\Filseclab\Twister\filau.dll] [Filseclab, 1, 0, 0, 10]
[C:\Program Files\Filseclab\Twister\unzip32.dll] [Info-ZIP, 5.52]
[C:\Program Files\Filseclab\Twister\unacev2.dll] [N/A, ]
[C:\Program Files\Filseclab\Twister\filvss.cn] [Filseclab Corporation, 2, 0, 0, 842]
[C:\Program Files\Filseclab\Twister\AntiRK.cn] [Filseclab Corporation, 2, 0, 0, 2246]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10042]
[C:\Program Files\Filseclab\Twister\plus.dll] [Filseclab Corporation, 2.0.502.1050]
[c:\documents and settings\administrator\application data\ppstream\bin\1.0.0.2\vodrc.dll] [ppstream.com, 1.0.0.2]
[PID: 1800][C:\Program Files\内存扫把\ram.exe] [Tax & Accounting Software Cor, 1.00]
[C:\Program Files\内存扫把\TrayForm.ocx] [Eduardo Morcillo, 1.03.0007]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10042]
[C:\Program Files\内存扫把\ProcBar.ocx] [SOTECH, 1.00]
[PID: 404][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1732][D:\QQ\QQ2007DIY1201\TXPlatform.exe] [Tencent, 1, 0, 170, 0]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10042]
[PID: 1268][D:\QQ\QQ2007DIY1201\QQ.exe] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\QQBaseClassInDll.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\QQHelperDll.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\BasicCtrlDll.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\MSIMG32.dll] [N/A, ]
[D:\QQ\QQ2007DIY1201\FinePlus.dll] [N/A, ]
[D:\QQ\QQ2007DIY1201\fphelper.dll] [N/A, ]
[D:\QQ\QQ2007DIY1201\QQAPI.dll] [TENCENT, 7,1,576,1763]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10042]
[D:\QQ\QQ2007DIY1201\LoginCtrl.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\LoginCtrlRes.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\QQRes.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\QQMainFrame.dll] [N/A, ]
[D:\QQ\QQ2007DIY1201\UnReadMsgMgr.dll] [N/A, ]
[D:\QQ\QQ2007DIY1201\CQQApplication.dll] [N/A, ]
[D:\QQ\QQ2007DIY1201\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[D:\QQ\QQ2007DIY1201\NewSkin.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\decode.dll] [N/A, ]
[D:\QQ\QQ2007DIY1201\aqing.dll] [Microsoft Corporation, 5.6.0.8825]
[D:\QQ\QQ2007DIY1201\MailSummary.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\QQSpace.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\vbscript.dll] [Microsoft Corporation, 5.6.0.8825]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[D:\QQ\QQ2007DIY1201\QQKnowledgeSearch.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\QQGroupMng.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\QQAllInOne.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\SCCore.dll] [TENCENT, 1, 6, 0, 2]
[D:\QQ\QQ2007DIY1201\CameraDll.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\QQPet.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\QQSysMsgMng.dll] [N/A, ]
[D:\QQ\QQ2007DIY1201\UserDefinedHead.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\QQPlugin.dll] [N/A, ]
[D:\QQ\QQ2007DIY1201\QQConfigPlugin.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\QQAvatar.dll] [N/A, ]
[D:\QQ\QQ2007DIY1201\QQCustomFace.dll] [N/A, ]
[D:\QQ\QQ2007DIY1201\QRingMng.dll] [N/A, ]
[D:\QQ\QQ2007DIY1201\LongConnection.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\PhoneAPI.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[D:\QQ\QQ2007DIY1201\PersonalDesktop.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\QQLiveQMng.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\ImageOle.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\BQQApplication.dll] [N/A, ]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 2, 0, 0, 1]
[C:\WINDOWS\system32\dllMergeDict.dll] [N/A, ]
[D:\输入法\SogouInput2.0f\Plugin\SgImeWord.dll] [, 1, 0, 0, 31]
[D:\QQ\QQ2007DIY1201\GroupConnection.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\CommercesMng.dll] [TENCENT, 7,1,576,1763]
[D:\QQ\QQ2007DIY1201\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 310]
[D:\QQ\QQ2007DIY1201\QQSceneMng.dll] [N/A, ]
[D:\QQ\QQ2007DIY1201\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 1, 9, 97]
[D:\QQ\QQ2007DIY1201\QQMagicFace.dll] [TENCENT, 7,1,576,1763]
[PID: 2964][D:\讯雷\Thunder-AyuConfig[xz]\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5.7.5.421]
[D:\讯雷\Thunder-AyuConfig[xz]\Program\ThunderEx.dll] [, 1, 2, 2, 18]
[D:\讯雷\Thunder-AyuConfig[xz]\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 3, 0, 52]
[D:\讯雷\Thunder-AyuConfig[xz]\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 2, 20, 2, 200]
[D:\讯雷\Thunder-AyuConfig[xz]\Program\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031]
[D:\讯雷\Thunder-AyuConfig[xz]\Program\asyn_dns.dll] [Thunder Networking Technologies,LTD, 2, 20, 2, 200]
[D:\讯雷\Thunder-AyuConfig[xz]\Program\streammedialib.dll] [, 1, 3, 2, 100]
[D:\讯雷\Thunder-AyuConfig[xz]\Program\al.dll] [, 1, 0, 1, 2]
[D:\讯雷\Thunder-AyuConfig[xz]\Program\xldc.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 11]
[D:\讯雷\Thunder-AyuConfig[xz]\Program\bd.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 3]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10042]
[D:\讯雷\Thunder-AyuConfig[xz]\Program\XLNet.Dll] [Thunder Networking Technologies,LTD, 1, 3, 2, 16]
[D:\讯雷\Thunder-AyuConfig[xz]\Program\iTargetAD.dll] [N/A, ]
[D:\讯雷\Thunder-AyuConfig[xz]\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 1, 0, 8]
[D:\讯雷\Thunder-AyuConfig[xz]\Components\DownAndPlay\DownAndPlay.dll] [, 1, 0, 8, 26]
[D:\讯雷\Thunder-AyuConfig[xz]\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 1, 5, 0, 13]
[D:\讯雷\Thunder-AyuConfig[xz]\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 16, 5, 63]
[D:\讯雷\Thunder-AyuConfig[xz]\Program\MSVCIRT.dll] [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\讯雷\Thunder-AyuConfig[xz]\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 1, 6, 20]
[D:\讯雷\Thunder-AyuConfig[xz]\Program\LiveUpdate.dll] [Thunder Networking Technologies,LTD, 1, 2, 1, 20]
[D:\讯雷\Thunder-AyuConfig[xz]\Plugins\BhoAdv\bho_adv.dll] [深圳市迅雷网络技术有限公司, 1.0.1.0]
[D:\讯雷\Thunder-AyuConfig[xz]\Components\ExplorerHelper\ExplorerHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 16]
[D:\讯雷\Thunder-AyuConfig[xz]\ComDlls\ThunderAgent_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 4, 23]
[D:\讯雷\Thunder-AyuConfig[xz]\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 44]
[D:\讯雷\Thunder-AyuConfig[xz]\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.16]
[D:\讯雷\Thunder-AyuConfig[xz]\Components\DownloadStat\DownloadStat.dll] [深圳市迅雷网络技术有限公司, 1, 3, 1, 4]
[PID: 2376][D:\优化系统\SRENG2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[D:\优化系统\SRENG2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10042]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 672, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 260, C:\PROGRAM FILES\FILSECLAB\TWISTER\TWISTER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 260, C:\PROGRAM FILES\FILSECLAB\TWISTER\TWISTER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1800, C:\PROGRAM FILES\内存扫把\RAM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2964, D:\讯雷\THUNDER-AYUCONFIG[XZ]\PROGRAM\THUNDER5.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE] |