==================================
浏览器加载项
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <E:\讯雷5\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <E:\讯雷5\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <, N/A>
[一键恢复]
{12F5C784-5373-48C9-8416-7FE0794C83FE} <c:\mscd\一键恢复系统.cmd, N/A>
[网上报修]
{CF8BCD7E-DFD9-4643-B401-D6863121A411} <http://www.syte.cn/bx/, N/A>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[ScreenCapture Class]
{BFB79EE1-04AE-4D4A-B85E-27EE5F30C095} <C:\WINDOWS\system32\TXGYMailActiveX.dll, Tencent Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[ThunderAtOnce Class]
{01443AEC-0FD1-40FD-9C87-E93D1494C233} <E:\讯雷5\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <E:\讯雷5\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <E:\讯雷5\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[使用迅雷下载]
<E:\讯雷5\Thunder\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
<E:\讯雷5\Thunder\Program\getallurl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ表情]
<, N/A>
==================================
正在运行的进程
[PID: 388 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 452 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 476 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 520 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\AppPatch\AcAdProc.dll] [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[PID: 532 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 680 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 736 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 788 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 864 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 896 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1148 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1300 / SYSTEM][E:\StormII\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 1, 13]
[E:\StormII\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0]
[PID: 1356 / Administrator][C:\Program Files\MALATA\MAE-301U\CnxDslTb.exe] [Conexant Systems, Inc., 040.001.014.000]
[E:\风云防火墙\FengYun\FYMon.dll] [www.218.cc, 1.2.3.238]
[PID: 1364 / Administrator][E:\费尔托斯特杀毒软件\twister.exe] [Filseclab Corporation, 7, 3, 1, 23211]
[E:\费尔托斯特杀毒软件\Twshlext.DLL] [Filseclab Corp., 2, 0, 2, 1058]
[E:\费尔托斯特杀毒软件\Quarantine.dll] [Filseclab Corp., 2, 0, 0, 581]
[E:\费尔托斯特杀毒软件\W32Tools.dll] [Filseclab Corp., 2, 0, 3, 2136]
[E:\费尔托斯特杀毒软件\virsubm.dll] [Filseclab Corp., 2, 0, 3, 533]
[E:\费尔托斯特杀毒软件\psmgr.dll] [Filseclab Corp., 1, 0, 1, 1071]
[E:\费尔托斯特杀毒软件\zipexp.dll] [Filseclab Corp., 1, 0, 2, 177]
[E:\费尔托斯特杀毒软件\emlib.dll] [Filseclab Corp., 1, 0, 2, 1254]
[E:\费尔托斯特杀毒软件\ctools.dll] [Filseclab Corp., 1, 0, 0, 19]
[E:\费尔托斯特杀毒软件\Regpro.dll] [Filseclab Corp., 2, 0, 1, 1268]
[E:\费尔托斯特杀毒软件\Schedule.dll] [Filseclab Corp., 1, 0, 1, 34]
[E:\费尔托斯特杀毒软件\lsf.dll] [Filseclab Corp., 1, 0, 1, 286]
[E:\费尔托斯特杀毒软件\falgorit.dll] [Filseclab Corp., 1, 0, 0, 446]
[E:\费尔托斯特杀毒软件\message.dll] [Filseclab Corp., 1, 0, 1, 1598]
[E:\费尔托斯特杀毒软件\fgui.dll] [Filseclab Corp., 1, 0, 1, 128]
[E:\费尔托斯特杀毒软件\kdf.dll] [Filseclab Corp., 1, 0, 3, 1019]
[E:\费尔托斯特杀毒软件\twsupd.dll] [Filseclab Corp., 2, 0, 1, 705]
[E:\费尔托斯特杀毒软件\FAPIConv.dll] [Filseclab Corp., 1, 0, 0, 45]
[E:\费尔托斯特杀毒软件\mdcoder.dll] [Filseclab Corp., 1, 0, 0, 21]
[E:\费尔托斯特杀毒软件\Decexp.dll] [Filseclab Corp., 2, 0, 2, 2050]
[E:\费尔托斯特杀毒软件\Unchm.dll] [Filseclab Corp., 1, 0, 3, 124]
[E:\费尔托斯特杀毒软件\unrar.dll] [N/A, ]
[E:\费尔托斯特杀毒软件\unemb.dll] [Filseclab Corp., 2, 0, 2, 528]
[E:\费尔托斯特杀毒软件\unsevzip.dll] [Filseclab Corp., 2, 0, 2, 134]
[E:\费尔托斯特杀毒软件\unmisc.dll] [Filseclab Corp., 1, 0, 1, 211]
[E:\费尔托斯特杀毒软件\AntiRK.dll] [Filseclab Corporation, 2, 0, 0, 2719]
[E:\费尔托斯特杀毒软件\filvss.dll] [Filseclab Corporation, 2, 0, 0, 847]
[E:\费尔托斯特杀毒软件\tsc.dll] [Filseclab Corp., 2, 0, 1, 104]
[E:\费尔托斯特杀毒软件\filau.dll] [Filseclab, 2, 0, 0, 21]
[E:\费尔托斯特杀毒软件\fvistask.dll] [Filseclab Corporation, 2, 0, 0, 0]
[E:\费尔托斯特杀毒软件\unzip32.dll] [Info-ZIP, 5.52]
[E:\费尔托斯特杀毒软件\unacev2.dll] [N/A, ]
[E:\费尔托斯特杀毒软件\filvss.cn] [Filseclab Corporation, 2, 0, 0, 848]
[E:\费尔托斯特杀毒软件\AntiRK.cn] [Filseclab Corporation, 2, 0, 0, 2720]
[E:\风云防火墙\FengYun\FYMon.dll] [www.218.cc, 1.2.3.238]
[E:\费尔托斯特杀毒软件\plus.dll] [Filseclab Corporation, 2.0.502.1050]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1376 / Administrator][E:\风云防火墙\FengYun\FYFireWall.exe] [www.218.cc, 1.2.7.10]
[E:\风云防火墙\FengYun\ArpInfo.dll] [N/A, ]
[E:\风云防火墙\FengYun\FYMon.dll] [www.218.cc, 1.2.3.238]
[PID: 1384 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[E:\风云防火墙\FengYun\FYMon.dll] [www.218.cc, 1.2.3.238]
[PID: 1428 / Administrator][C:\Program Files\Common Files\Filseclab\FilMsg.exe] [费尔安全实验室, 4, 0, 7, 1047]
[C:\Program Files\Common Files\Filseclab\twsupd.dll] [Filseclab Corp., 2, 0, 1, 705]
[C:\Program Files\Common Files\Filseclab\W32Tools.dll] [Filseclab Corp., 2, 0, 3, 2136]
[C:\Program Files\Common Files\Filseclab\FAPIConv.dll] [Filseclab Corp., 1, 0, 0, 45]
[C:\Program Files\Common Files\Filseclab\mdcoder.dll] [Filseclab Corp., 1, 0, 0, 21]
[E:\风云防火墙\FengYun\FYMon.dll] [www.218.cc, 1.2.3.238]
[PID: 1992 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 444 / Administrator][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2527 (xpsp.040919-1030)]
[E:\风云防火墙\FengYun\FYMon.dll] [www.218.cc, 1.2.3.238]
[C:\WINDOWS\system32\WPDShServiceObj.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\PortableDeviceTypes.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[E:\费尔托斯特杀毒软件\Twshlext.dll] [Filseclab Corp., 2, 0, 2, 1058]
[E:\Windows优化大师\WoptiEncryptModule.dll] [共软网络, 1.0.8.103]
[C:\WINDOWS\system32\wpdshext.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[E:\StormII\spfa.dll] [北京暴风网际科技有限公司, 2, 7, 4, 2]
[PID: 2716 / Administrator][E:\Tencent\QQ\QQ.exe] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\QQBaseClassInDll.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\QQHelperDll.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\BasicCtrlDll.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[E:\风云防火墙\FengYun\FYMon.dll] [www.218.cc, 1.2.3.238]
[E:\Tencent\QQ\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[E:\Tencent\QQ\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[E:\Tencent\QQ\QQAPI.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\LoginCtrl.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\LoginCtrlRes.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\QQRes.dll] [TENCENT, 7,0,431,1723]
[E:\Tencent\QQ\QQMainFrame.dll] [N/A, ]
[E:\Tencent\QQ\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[E:\Tencent\QQ\QQPlugin.dll] [N/A, ]
[E:\Tencent\QQ\UnReadMsgMgr.dll] [N/A, ]
[E:\Tencent\QQ\CQQApplication.dll] [N/A, ]
[E:\Tencent\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[E:\Tencent\QQ\NewSkin.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\MailSummary.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\QQSpace.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\vbscript.dll] [Microsoft Corporation, 5.6.0.7426]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[E:\Tencent\QQ\OEMApplication.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\QQGroupMng.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\QQAvatar.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[E:\Tencent\QQ\QQAllInOne.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\SCCore.dll] [TENCENT, 1, 6, 0, 2]
[E:\Tencent\QQ\CameraDll.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\UserDefinedHead.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\QQCustomFace.dll] [N/A, ]
[C:\WINDOWS\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[E:\Tencent\QQ\QQSysMsgMng.dll] [N/A, ]
[E:\Tencent\QQ\QQConfigPlugin.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\ImageOle.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\QQMagicFace.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\GroupConnection.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\LongConnection.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\QQFileTransfer.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\PersonalDesktop.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 330]
[C:\WINDOWS\system32\WINABCX.IME] [PKUETI, 5.22.216]
[E:\Tencent\QQ\CommercesMng.dll] [TENCENT, 7,1,638,1773]
[E:\Tencent\QQ\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 1, 9, 97]
[PID: 2740 / Administrator][E:\Tencent\QQ\TXPlatform.exe] [Tencent, 1, 0, 170, 0]
[E:\风云防火墙\FengYun\FYMon.dll] [www.218.cc, 1.2.3.238]
[PID: 2600 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[E:\风云防火墙\FengYun\FYMon.dll] [www.218.cc, 1.2.3.238]
[PID: 3832 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.281\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[E:\风云防火墙\FengYun\FYMon.dll] [www.218.cc, 1.2.3.238]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.281\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP Error. [winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeSystemtimePrivilege [PID = 1356, C:\PROGRAM FILES\MALATA\MAE-301U\CNXDSLTB.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1356, C:\PROGRAM FILES\MALATA\MAE-301U\CNXDSLTB.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1356, C:\PROGRAM FILES\MALATA\MAE-301U\CNXDSLTB.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 1364, E:\费尔托斯特杀毒软件\TWISTER.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1364, E:\费尔托斯特杀毒软件\TWISTER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1364, E:\费尔托斯特杀毒软件\TWISTER.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 1376, E:\风云防火墙\FENGYUN\FYFIREWALL.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1376, E:\风云防火墙\FENGYUN\FYFIREWALL.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1376, E:\风云防火墙\FENGYUN\FYFIREWALL.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 1428, C:\PROGRAM FILES\COMMON FILES\FILSECLAB\FILMSG.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1428, C:\PROGRAM FILES\COMMON FILES\FILSECLAB\FILMSG.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1428, C:\PROGRAM FILES\COMMON FILES\FILSECLAB\FILMSG.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE] |