==================================
正在运行的进程
[PID: 568][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 688][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 748][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 848][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 860][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1064][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1148][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\avsda.dll] [Avira GmbH, 8.00.00.05]
[C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159]
[PID: 1268][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\System32\avsda.dll] [Avira GmbH, 8.00.00.05]
[PID: 1312][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\avsda.dll] [Avira GmbH, 8.00.00.05]
[PID: 1584][C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe] [Avira GmbH, 8.00.00.17]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\schedr.dll] [Avira GmbH, 8.00.03.00]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\avevtlog.dll] [Avira GmbH, 8.00.00.16]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\sqlite3.dll] [, 3.3.17.1]
[PID: 1988][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159]
[D:\Program Files\360\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1004]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\shlext.dll] [Avira GmbH, 7.00.00.15]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.34]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 120]
[PID: 416][C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe] [Avira GmbH, 8.00.70.02]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\cclib.dll] [Avira GmbH, 8.00.70.05]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[c:\program files\avira\antivir personaledition premium\ccgen.dll] [Avira GmbH, 8.00.70.04]
[c:\program files\avira\antivir personaledition premium\ccgenrc.dll] [Avira GmbH, 8.00.70.00]
[c:\program files\avira\antivir personaledition premium\ccguard.dll] [Avira GmbH, 8.00.70.04]
[c:\program files\avira\antivir personaledition premium\ccgrdrc.dll] [Avira GmbH, 8.00.72.00]
[c:\program files\avira\antivir personaledition premium\avipc.dll] [Avira GmbH, 1.0.6.0]
[c:\program files\avira\antivir personaledition premium\ccupdate.dll] [Avira GmbH, 8.00.70.02]
[c:\program files\avira\antivir personaledition premium\ccupdrc.dll] [Avira GmbH, 8.00.70.00]
[c:\program files\avira\antivir personaledition premium\cclic.dll] [Avira GmbH, 8.00.70.04]
[c:\program files\avira\antivir personaledition premium\cclicrc.dll] [Avira GmbH, 8.00.70.00]
[c:\program files\avira\antivir personaledition premium\ccmsg.dll] [Avira GmbH, 8.00.00.06]
[PID: 512][C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe] [Avira GmbH, 8.00.01.30]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\avevtlog.dll] [Avira GmbH, 8.00.00.16]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\guardmsg.dll] [Avira GmbH, 8.00.08.00]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\sqlite3.dll] [, 3.3.17.1]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVPREF.DLL] [Avira GmbH, 8.00.02.00]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\SMTPLIB.DLL] [Avira GmbH, 1.02.00.23]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVGIO.DLL] [Avira GmbH, 8.00.01.03]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aecore.dll] [Avira GmbH, 8.1.6.6]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aevdf.dll] [Avira GmbH, 8.1.1.0]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aescript.dll] [Avira GmbH, 8.1.1.63]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aescn.dll] [Avira GmbH, 8.1.1.8]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aerdl.dll] [Avira GmbH, 8.1.1.3]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aepack.dll] [Avira GmbH, 8.1.3.10]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\unacev2.dll] [N/A, ]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aeoffice.dll] [Avira GmbH, 8.1.0.36]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aeheur.dll] [Avira GmbH, 8.1.0.104]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aehelp.dll] [Avira GmbH, 8.1.2.2]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aegen.dll] [Avira GmbH, 8.1.1.28]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aeemu.dll] [Avira GmbH, 8.1.0.9]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aebb.dll] [Avira GmbH, 8.1.0.3]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\avipc.dll] [Avira GmbH, 1.0.6.0]
[PID: 644][C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe] [Avira GmbH, 8.00.02.00]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.dll] [Avira GmbH, 8.00.02.02]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvcr.dll] [Avira GmbH, 8.00.02.00]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\avipc.dll] [Avira GmbH, 1.0.6.0]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\avpref.dll] [Avira GmbH, 8.00.02.00]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aecore.dll] [Avira GmbH, 8.1.6.6]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aevdf.dll] [Avira GmbH, 8.1.1.0]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aescript.dll] [Avira GmbH, 8.1.1.63]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aescn.dll] [Avira GmbH, 8.1.1.8]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aerdl.dll] [Avira GmbH, 8.1.1.3]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aepack.dll] [Avira GmbH, 8.1.3.10]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\unacev2.dll] [N/A, ]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aeoffice.dll] [Avira GmbH, 8.1.0.36]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aeheur.dll] [Avira GmbH, 8.1.0.104]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aehelp.dll] [Avira GmbH, 8.1.2.2]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aegen.dll] [Avira GmbH, 8.1.1.28]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aeemu.dll] [Avira GmbH, 8.1.0.9]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\aebb.dll] [Avira GmbH, 8.1.0.3]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\webcat.dll] [Avira GmbH, 1.00.10.00]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[PID: 680][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 876][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.7189]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1412][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 1236][C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe] [Avira GmbH, 8.00.00.45]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailcr.dll] [Avira GmbH, 8.00.13.00]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\avevtlog.dll] [Avira GmbH, 8.00.00.16]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\sqlite3.dll] [, 3.3.17.1]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\mgrs.dll] [Avira GmbH, 7.02.14.00]
[C:\WINDOWS\system32\avsda.dll] [Avira GmbH, 8.00.00.05]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\avipc.dll] [Avira GmbH, 1.0.6.0]
[PID: 1656][C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE] [Avira GmbH, 8.0.15.0]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\avipc.dll] [Avira GmbH, 1.0.6.0]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\msgclient.dll] [Avira GmbH, 8.00.00.00]
[C:\Program Files\Avira\AntiVir PersonalEdition Premium\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\avsda.dll] [Avira GmbH, 8.00.00.05]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1980][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\avsda.dll] [Avira GmbH, 8.00.00.05]
[PID: 1600][C:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE] [Microsoft Corporation, 11.0.8227]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[D:\Program Files\360\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1004]
[C:\Program Files\Microsoft Office\OFFICE11\GdiPlus.DLL] [Microsoft Corporation, 11.0.8230]
[C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159]
[C:\WINDOWS\system32\icm32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[PID: 1736][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\System32\avsda.dll] [Avira GmbH, 8.00.00.05]
[PID: 1436][C:\Program Files\TheWorld 2.0\TheWorld.exe] [Phoenix Studio, 2, 3, 2, 1]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[D:\Program Files\360\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1004]
[C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\avsda.dll] [Avira GmbH, 8.00.00.05]
[C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx] [Adobe Systems, Inc., 10,0,12,36]
[PID: 3832][D:\绿色软件\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210]
[PID: 3236][D:\绿色软件\sreng2\SRE3028f091.EXE] [Smallfrogs Studio, 2.7.0.1210]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[D:\Program Files\360\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1004]
[D:\绿色软件\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[C:\WINDOWS\system32\avsda.dll] [Avira GmbH, 8.00.00.05]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
AVSDA over [MSAFD Tcpip [TCP/IP]]
avsda.dll(Avira GmbH, AntiVir layered service provider)
AVSDA over [MSAFD Tcpip [UDP/IP]]
avsda.dll(Avira GmbH, AntiVir layered service provider)
AVSDA
avsda.dll(Avira GmbH, AntiVir layered service provider)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 748, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1584, C:\PROGRAM FILES\AVIRA\ANTIVIR PERSONALEDITION PREMIUM\SCHED.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 416, C:\PROGRAM FILES\AVIRA\ANTIVIR PERSONALEDITION PREMIUM\AVGNT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 512, C:\PROGRAM FILES\AVIRA\ANTIVIR PERSONALEDITION PREMIUM\AVGUARD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3832, D:\绿色软件\SRENG2\SRENGLDR.EXE]
==================================
计划任务
[已启用] SogouImeMgr.job
C:\PROGRA~1\SOGOUI~1\400~1.209\PinyinRepair.exe
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE] |