接上楼!
==================================
正在运行的进程
[PID: 496 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 548 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 572 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[PID: 616 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[PID: 628 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[PID: 792 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[PID: 836 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[PID: 1004 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[PID: 1112 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[PID: 1212 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[PID: 1288 / SYSTEM][D:\金山网盾\KSWebShieldSVC\KSWebShield.exe] [Kingsoft Corporation, 2009,06,10,109]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[D:\金山网盾\KSWebShieldSVC\kwssp.dll] [Kingsoft Corporation, 2009,06,09,107]
[D:\金山网盾\KSWebShieldSVC\kswebshield.dll] [Kingsoft Corporation, 2009,06,04,99]
[D:\金山网盾\KSWebShieldSVC\kxestat.dll] [Kingsoft Corporation, 2009,06,15,24]
[PID: 1380 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762]
[PID: 1476 / 联想扬天][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[D:\金山网盾\KSWebShieldSVC\kswebshield.dll] [Kingsoft Corporation, 2009,06,04,99]
[D:\迅雷5特别版\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5.0.8.179]
[D:\迅雷5特别版\Thunder\ComDlls\TDAtOnce_Now.dll] [深圳市迅雷网络技术有限公司, 1.2.6.148]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.10.7184]
[C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 6.14.10.4820]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 6.14.10.4820]
[D:\WinRAR\rarext.dll] [N/A, ]
[D:\COMODO Internet Security Installer\Comodo\COMODO Internet Security\cavshell.dll] [N/A, ]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 6.14.10.4820]
[C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 6.14.10.4820]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 6.14.10.4820]
[PID: 1624 / 联想扬天][D:\金山网盾\KSWebShieldSVC\kwstray.exe] [Kingsoft Corporation, 2009,5,19,63]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[D:\金山网盾\KSWebShieldSVC\kswebshield.dll] [Kingsoft Corporation, 2009,06,04,99]
[PID: 2036 / 联想扬天][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[D:\金山网盾\KSWebShieldSVC\kswebshield.dll] [Kingsoft Corporation, 2009,06,04,99]
[PID: 400 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[PID: 412 / SYSTEM][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe] [Microsoft Corporation, 7.10.3077]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\2052\mdmui.dll] [Microsoft Corporation, 7.10.3077]
[D:\金山网盾\KSWebShieldSVC\kswebshield.dll] [Kingsoft Corporation, 2009,06,04,99]
[PID: 760 / SYSTEM][C:\PROGRA~1\LENOVO\MULTIR~1\mulservice.exe] [, 2, 0, 0, 1]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[PID: 1208 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:\WINDOWS\System32\guard32.dll] [N/A, ]
[PID: 2660 / 联想扬天][D:\360浏览器\360\360se\360SE.exe] [360安全中心, 2, 2, 0, 1]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[D:\金山网盾\KSWebShieldSVC\kswebshield.dll] [Kingsoft Corporation, 2009,06,04,99]
[D:\金山网盾\KSWebShieldSVC\KSWBC.dll] [Kingsoft Corporation, 2009,06,09,107]
[D:\金山网盾\KSWebShieldSVC\kwsui.dll] [Kingsoft Corporation, 2009,06,15,114]
[D:\360浏~1\360\360se\360\360core\360core.dll] [, 1, 0, 0, 8]
[D:\360浏~1\360\360se\360\searchcore\searchcore.dll] [, 1, 0, 1, 4]
[D:\360浏~1\360\360se\Plugin\Hidehelper\Hidehelper.dll] [, 1, 0, 0, 1]
[D:\360安全卫士\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1014]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.2.0.2654]
[D:\搜狗拼音输入法\SogouInput\4.2.0.2654\Resource.dll] [Sogou.com Inc., 4.2.0.2654]
[C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx] [Adobe Systems, Inc., 10,0,22,87]
[D:\迅雷5特别版\Thunder\ComDlls\ThunderAgent_Now.dll] [Thunder Networking Technologies,LTD, 6.0.4.179]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 2884 / 联想扬天][D:\迅雷5特别版\Thunder\program\Thunder.exe] [Xunlei Networking Technologies,LTD, 5.9.1.922]
[D:\迅雷5特别版\Thunder\program\BugReportU.dll] [深圳市迅雷网络技术有限公司, 1, 4, 1, 20]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[D:\迅雷5特别版\Thunder\program\libexpat.dll] [N/A, ]
[D:\迅雷5特别版\Thunder\program\liblua.dll] [N/A, ]
[D:\迅雷5特别版\Thunder\program\XLGraphic.dll] [N/A, ]
[D:\迅雷5特别版\Thunder\program\libpng13.dll] [, 1.2.34]
[D:\迅雷5特别版\Thunder\program\zlib1.dll] [, 1.2.3]
[D:\迅雷5特别版\Thunder\program\XLLuaRuntime.dll] [N/A, ]
[D:\迅雷5特别版\Thunder\program\sqlite3.dll] [N/A, ]
[D:\迅雷5特别版\Thunder\program\mini_unzip_dll.dll] [N/A, ]
[D:\迅雷5特别版\Thunder\program\HookEx.dll] [N/A, ]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[D:\金山网盾\KSWebShieldSVC\kswebshield.dll] [Kingsoft Corporation, 2009,06,04,99]
[D:\金山网盾\KSWebShieldSVC\kwsui.dll] [Kingsoft Corporation, 2009,06,15,114]
[D:\迅雷5特别版\Thunder\Program\XLGUIPlatform.dll] [TODO: <公司名>, 5.9.1.922]
[D:\迅雷5特别版\Thunder\program\ThunderStorage.dll] [, 1, 0, 0, 2]
[D:\迅雷5特别版\Thunder\program\XLWebDownload.dll] [深圳市迅雷网络技术有限公司, 5.9.1.722]
[D:\迅雷5特别版\Thunder\program\asyn_frame.dll] [深圳市迅雷网络技术有限公司, 1, 4, 2, 34]
[D:\迅雷5特别版\Thunder\program\mp.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 5]
[D:\迅雷5特别版\Thunder\program\Thunders.dll] [Xunlei Networking Technologies,LTD, 5.9.1.922]
[D:\迅雷5特别版\Thunder\program\download_interface.dll] [Thunder Networking Technologies,LTD, 3, 4, 2, 343]
[D:\迅雷5特别版\Thunder\program\backend_agent.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 31]
[D:\迅雷5特别版\Thunder\program\ptl.dll] [Thunder Networking Technologies,LTD, 3, 2, 2, 60]
[D:\迅雷5特别版\Thunder\program\dl_peer_id.dll] [深圳市迅雷网络技术有限公司, 3, 1, 2, 4]
[D:\迅雷5特别版\Thunder\program\xl_stat.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 7]
[D:\迅雷5特别版\Thunder\program\fs.dll] [深圳市迅雷网络技术有限公司, 1, 1, 2, 19]
[D:\迅雷5特别版\Thunder\program\p2p_upload.dll] [Thunder Networking Technologies,LTD, 1,1,2,16]
[D:\迅雷5特别版\Thunder\Components\SkinEngine\skinEngine.dll] [Xunlei Networking Technologies,LTD, 5.9.1.922]
[D:\迅雷5特别版\Thunder\program\SkinEngine2.dll] [TODO: <Company name>, 1.0.0.1]
[D:\迅雷5特别版\Thunder\Components\GougouSearch\GougouSearch.dll] [Xunlei Networking Technologies,LTD, 5.9.1.922]
[D:\迅雷5特别版\Thunder\Program\DllNewTask.DLL] [Xunlei Networking Technologies,LTD, 5.9.1.922]
[D:\迅雷5特别版\Thunder\Components\Config\ConfigPane.dll] [Xunlei Networking Technologies,LTD, 5.9.1.922]
[D:\迅雷5特别版\Thunder\Components\FloatPanel\FloatPanel.dll] [Xunlei Networking Technologies,LTD, 5.9.1.922]
[D:\迅雷5特别版\Thunder\program\XLGUIDevEnv.dll] [TODO: <公司名>, 5.9.1.922]
[D:\迅雷5特别版\Thunder\program\GBLCategory.dll] [Xunlei Networking Technologies,LTD, 5.9.1.922]
[D:\迅雷5特别版\Thunder\Components\BaseCommunity\BaseCommunity.dll] [Thunder Networking Technologies,LTD, 5.9.2.721]
[D:\迅雷5特别版\Thunder\program\libjpeg6b.dll] [N/A, ]
[D:\迅雷5特别版\Thunder\program\giflib4.dll] [N/A, ]
[D:\迅雷5特别版\Thunder\program\XLI18N.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 1]
[D:\迅雷5特别版\Thunder\program\p2p.dll] [Thunder Networking Technologies,LTD, 1,1,2,55]
[D:\迅雷5特别版\Thunder\program\stream.dll] [ShenZhen Thunder Networking Technologies,Ltd., 2, 1, 2, 1047]
[D:\迅雷5特别版\Thunder\program\p2sp.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 71]
[D:\迅雷5特别版\Thunder\program\down_dispatcher.dll] [Thunder Networking Technologies,LTD, 1,0,2,53]
[D:\迅雷5特别版\Thunder\program\p2p_local_res.dll] [深圳市迅雷网络技术有限公司, 1,1,2,18]
[D:\迅雷5特别版\Thunder\program\al.dll] [Thunder Networking Technologies,LTD, 1,1,2,38]
[D:\迅雷5特别版\Thunder\program\sl.dll] [深圳市迅雷网络技术有限公司, 1.0.2.2]
[D:\迅雷5特别版\Thunder\program\http.dll] [Thunder Networking Technologies,LTD, 1.0.2.5]
[D:\迅雷5特别版\Thunder\program\XLCP.dll] [Thunder Networking Technologies,LTD, 1.0.2.6]
[D:\迅雷5特别版\Thunder\program\XLUser.dll] [Thunder Networking Technologies,LTD, 1.0.2.15]
[D:\迅雷5特别版\Thunder\program\emule_shell.dll] [, 1, 0, 2, 13]
[D:\迅雷5特别版\Thunder\program\module_downloader.dll] [, 1, 0, 2, 9]
[D:\迅雷5特别版\Thunder\program\emule_id.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 12]
[D:\迅雷5特别版\Thunder\program\bd.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 20]
[PID: 1348 / 联想扬天][G:\迅雷下载\软件\SREngLdr.EXE] [Smallfrogs Studio, 2.7.1.1261]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[PID: 1316 / 联想扬天][G:\迅雷下载\软件\SREeb1fbb23.EXE] [Smallfrogs Studio, 2.7.1.1261]
[C:\WINDOWS\system32\guard32.dll] [N/A, ]
[D:\金山网盾\KSWebShieldSVC\kswebshield.dll] [Kingsoft Corporation, 2009,06,04,99]
[G:\迅雷下载\软件\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
------ 屏蔽迅雷看看广告 ------
0.0.0.0 pubstat.sandai.net
0.0.0.0 mcfg.sandai.net
0.0.0.0 biz5.sandai.net
0.0.0.0 float.sandai.net
0.0.0.0 recommend.xunlei.com
0.0.0.0 cl.kankan.xunlei.com
0.0.0.0 211.94.190.80
0.0.0.0 mtips.xunlei.com
0.0.0.0 211.94.190.80
0.0.0.0 mtips.xunlei.com
0.0.0.0 adsresult.joywell.com.cn
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 2884, D:\迅雷5特别版\THUNDER\PROGRAM\THUNDER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1348, G:\迅雷下载\软件\SRENGLDR.EXE]
==================================
计划任务
[已启用] User_Feed_Synchronization-{65D2D0C3-508D-4FCC-8331-42E3BE2AB97F}.job
C:\WINDOWS\system32\msfeedssync.exe
==================================
API HOOK
入口点错误:NtCreateFile (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:NtCreateProcess (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:NtCreateProcessEx (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:NtDeleteFile (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:NtLoadDriver (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:NtSetInformationProcess (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:ZwCreateFile (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:ZwCreateProcess (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:ZwCreateProcessEx (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:ZwDeleteFile (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:ZwOpenFile (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:ZwSetInformationProcess (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:CreateServiceA (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:CreateServiceW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:DeleteFileA (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:DeleteFileW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:LoadLibraryA (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:LoadLibraryExA (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:LoadLibraryW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:MoveFileA (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:MoveFileExA (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:MoveFileExW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:MoveFileW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:CreateFileA (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:CreateFileW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:CopyFileA (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:CopyFileExA (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:CopyFileExW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:CopyFileW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:GetProcAddress (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:ShellExecuteA (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:ShellExecuteEx (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:ShellExecuteExA (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:ShellExecuteExW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
入口点错误:ShellExecuteW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\guard32.dll)
==================================
隐藏进程
N/A
==================================
[/CODE] |