- 2010-12-22,11:29:07
- System Repair Engineer 2.8.2.1321
- Smallfrogs ([url=http://www.KZTechs.com]http://www.KZTechs.com[/url])
- Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能
- 以下内容被选中:
- 所有的启动项目(包括注册表、启动文件夹、服务等)
- 浏览器加载项
- 正在运行的进程(包括进程模块信息)
- 文件关联
- Winsock 提供者
- Autorun.inf
- HOSTS 文件
- 进程特权扫描
- 计划任务
- Windows 安全更新检查
- API HOOK
- 隐藏进程
- 启动项目
- 注册表
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- <360Safetray><"C:\Program Files\360\360Safe\safemon\360tray.exe" /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
- <VMUserServices><C:\Program Files\Virtual Machine Additions\vmusrvc.exe> [(Verified)Microsoft Corporation]
- <Rvsystem><C:\PROGRA~1\Returnil\Returnil.exe> [Returnil SIA]
- <360NetFireWall><"C:\Program Files\360\360netfw\360nfw.exe" /start> [(Verified)Qizhi Software (beijing) Co. Ltd]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
- <Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <AppInit_DLLs><> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <UIHost><logonui.exe> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
- <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
- <PostBootReminder><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher]
- <CDBurn><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher]
- <WebCheck><%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Component Publisher]
- <SysTray><C:\WINDOWS\system32\stobject.dll> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
- <WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
- <WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
- <WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
- <WinlogonNotify: dimsntfy><%SystemRoot%\System32\dimsntfy.dll> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
- <WinlogonNotify: ScCertProp><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
- <WinlogonNotify: Schedule><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
- <WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
- <WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
- <WinlogonNotify: termsrv><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
- <WinlogonNotify: wlballoon><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
- <Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
- <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
- <浏览器自定义组件><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
- <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
- <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
- <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
- <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> []
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
- <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
- <Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll> [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
- <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Component Publisher]
- ==================================
- 启动文件夹
- N/A
- ==================================
- 服务
- [360网络防火墙 云安全防护服务 / 360fwrp][Running/Auto Start]
- <C:\Program Files\360\360netfw\360fwrp.exe><360.cn>
- [Human Interface Device Access / HidServ][Stopped/Disabled]
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
- [Sandboxie Service / SbieSvc][Running/Auto Start]
- <"C:\Program Files\Sandboxie\SbieSvc.exe"><SANDBOXIE L.T.D>
- [主动防御 / ZhuDongFangYu][Running/Auto Start]
- <"C:\Program Files\360\360Safe\deepscan\zhudongfangyu.exe"><360.cn>
- ==================================
- 驱动程序
- [360netmon / 360netmon][Running/System Start]
- <\??\C:\WINDOWS\system32\drivers\360netmon.sys><360.cn>
- [360SelfProtection / 360SelfProtection][Running/System Start]
- <system32\drivers\360SelfProtection.sys><360安全中心>
- [Agnitum firewall driver / afw][Running/Manual Start]
- <system32\DRIVERS\afw.sys><Agnitum Ltd.>
- [Agnitum Firewall Core Driver / afwcore][Running/Manual Start]
- <\??\C:\WINDOWS\system32\drivers\afwcore.sys><Agnitum Ltd.>
- [BAPIDRV / BAPIDRV][Running/System Start]
- <\??\C:\WINDOWS\system32\drivers\BAPIDRV.SYS><360.cn>
- [Creative SB16/AWE32/AWE64 Driver (WDM) / ctlsb16][Running/Manual Start]
- <system32\drivers\ctlsb16.sys><Copyright (C) Creative Technology Ltd. 1994-2001>
- [DC21x4 Based Network Adapter Driver / DC21x4][Running/Manual Start]
- <system32\DRIVERS\dc21x4.sys><Intel Corporation.>
- [EfiSystemMon / EfiMon][Running/System Start]
- <System32\Drivers\Efimon.sys><奇虎网>
- [Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Stopped/Manual Start]
- <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
- [HookPort / HookPort][Running/Boot Start]
- <\SystemRoot\System32\Drivers\Hookport.sys><360安全中心>
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
- [Quantum DeepScanner Servers / qutmdserv][Running/System Start]
- <\??\C:\WINDOWS\system32\drivers\qutmdrv.sys><360.cn>
- [qutmipc / qutmipc][Running/System Start]
- <\??\C:\WINDOWS\system32\drivers\qutmipc.sys><360安全中心>
- [RVFsSec / RVFsSec][Running/Boot Start]
- <\SystemRoot\system32\Drivers\RVFsSec.sys><Returnil SIA>
- [RVSDISK / RVSDISK][Running/Boot Start]
- <\SystemRoot\system32\Drivers\RVSDISK.sys><N/A>
- [RVSYSTEM / RVSYSTEM][Running/Boot Start]
- <\SystemRoot\system32\Drivers\RVSYSTEM.sys><Returnil SIA>
- [SbieDrv / SbieDrv][Running/Manual Start]
- <\??\C:\Program Files\Sandboxie\SbieDrv.sys><SANDBOXIE L.T.D>
- [Secdrv / Secdrv][Stopped/Manual Start]
- <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
- [SATALink driver accelerator / SiFilter][Running/Boot Start]
- <\SystemRoot\system32\drivers\SiWinAcc.sys><Silicon Image, Inc.>
- [TCP/IP Protocol Driver / Tcpip][Running/System Start]
- <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
- [VMware Pointing Device / vmmouse][Stopped/Manual Start]
- <system32\DRIVERS\vmmouse.sys><VMware, Inc.>
- [vpc-s3 / vpc-s3][Running/Manual Start]
- <system32\DRIVERS\vpc-s3.sys><Microsoft Corporation>
- [WMDrive / WMDrive][Running/System Start]
- <\??\C:\WINDOWS\system32\drivers\WMDrive.sys><WinMount International Inc>
- [truecrypt / truecrypt][Running/Disabled]
- <\??\C:\Program Files\TrueCrypt\truecrypt.sys><TrueCrypt Foundation>
- ==================================
- 浏览器加载项
- [QQCycloneHelper Class]
- {00000000-12C9-4305-82F9-43058F20E8D2} <C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, (Signed) Tencent Technology (Shenzhen) Company Limited>
- [ThunderAtOnce Class]
- {01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD>
- [Thunder Browser Helper]
- {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD>
- [Java(tm) Plug-In 2 SSV Helper]
- {DBC80044-A445-435b-BC74-9C25C1C588A9} <C:\Program Files\Java\jre6\bin\jp2ssv.dll, (Signed) Sun Microsystems, Inc.>
- [JQSIEStartDetectorImpl Class]
- {E7E6F031-17CE-4C07-BC86-EABFE594F69C} <C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll, (Signed) Sun Microsystems, Inc.>
- [启动迅雷5]
- {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, (Signed) 深圳市迅雷网络技术有限公司>
- []
- {61F0024B-8278-4999-B7E6-2718426D9FE6} <, >
- [Java Plug-in 1.6.0_22]
- {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre6\bin\jp2iexp.dll, (Signed) >
- [Java Plug-in 1.6.0_22]
- {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} <C:\Program Files\Java\jre6\bin\jp2iexp.dll, (Signed) >
- [Java Plug-in 1.6.0_22]
- {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre6\bin\npjpi160_22.dll, (Signed) Sun Microsystems, Inc.>
- [QQCycloneHelper Class]
- {00000000-12C9-4305-82F9-43058F20E8D2} <C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, (Signed) Tencent Technology (Shenzhen) Company Limited>
- [ThunderAtOnce Class]
- {01443AEC-0FD1-40FD-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD>
- []
- {2D90D33C-DE76-42D0-9040-E4466DDC24AC} <, >
- [Thunder Agent Class]
- {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, (Signed) Thunder Networking Technologies,LTD>
- []
- {548BF84E-9665-47F9-B635-7380F8943E90} <, >
- []
- {61F0024B-8278-4999-B7E6-2718426D9FE6} <, >
- [360SafeLive]
- {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360\360Safe\Safelive.dll, (Signed) 360.cn>
- [Thunder Browser Helper]
- {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD>
- []
- {9701758C-4373-482E-B13C-776C048EC890} <, >
- []
- {9EFF1953-9694-47B1-AEF6-B2A3FE8BFE9B} <, >
- [HallToolkit Class]
- {A24E6133-404F-4431-A296-2DE576FC5AEE} <C:\Program Files\Common Files\Thunder Network\XLGame\HallTool.1.0.0.5.(207).dll, (Signed) 深圳市迅雷网络技术有限公司>
- [APlayer Control]
- {A9322148-C691-4B9D-91FC-B9C461DBE9DD} <C:\Program Files\Common Files\Thunder Network\APlayer\APlayer_001.dll, (Signed) ShenZhen Thunder Networking Technologies, LTD>
- []
- {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} <, >
- [Java(tm) Plug-In 2 SSV Helper]
- {DBC80044-A445-435B-BC74-9C25C1C588A9} <C:\Program Files\Java\jre6\bin\jp2ssv.dll, (Signed) Sun Microsystems, Inc.>
- [JQSIEStartDetectorImpl Class]
- {E7E6F031-17CE-4C07-BC86-EABFE594F69C} <C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll, (Signed) Sun Microsystems, Inc.>
- []
- {F3E70CEA-956E-49CC-B444-73AFE593AD7F} <, >
- [&使用QQ旋风下载]
- <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
- [&使用QQ旋风下载全部链接]
- <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
- [&使用QQ旋风离线下载]
- <C:\Program Files\Tencent\QQDownload\xfofflinedown.htm, N/A>
- ==================================
- 正在运行的进程
- [PID: 420 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
- [PID: 524 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
- [PID: 548 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
- [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 592 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)]
- [PID: 604 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
- [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 764 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
- [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 1060 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
- [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 1156 / SYSTEM][C:\Program Files\Sandboxie\SbieSvc.exe] [SANDBOXIE L.T.D, 3.49.04]
- [C:\Program Files\Sandboxie\SbieDll.dll] [SANDBOXIE L.T.D, 3.49.04]
- [PID: 1176 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
- [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 1360 / SYSTEM][C:\Program Files\360\360netfw\360fwrp.exe] [360.cn, 1, 0, 0, 1003]
- [PID: 1536 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
- [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 1612 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
- [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 1628 / SYSTEM][C:\Program Files\360\360Safe\deepscan\zhudongfangyu.exe] [360.cn, 3, 2, 2, 1002]
- [C:\Program Files\360\360Safe\SoftMgr\360SoftMgrS.dll] [360.cn, 2, 1, 6, 1032]
- [C:\Program Files\360\360Safe\deepscan\CloudCom2.dll] [360.cn, 3, 2, 5, 5101]
- [C:\Program Files\360\360Safe\deepscan\heavygate.dll] [360.cn, 3, 6, 21, 0]
- [C:\Program Files\360\360Safe\deepscan\qutmload.dll] [360安全中心, 6, 7, 0, 1001]
- [PID: 1652 / Administrator][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [C:\Program Files\360\360Safe\safemon\safemon.dll] [360.cn, 6, 7, 6, 1002]
- [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 120]
- [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\icm32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
- [C:\WINDOWS\system32\msdmo.dll] [, ]
- [C:\Program Files\WinRAR\rarext.dll] [N/A, ]
- [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.34]
- [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
- [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
- [PID: 1808 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.6024 (xpsp_sp3_gdr.100817-1626)]
- [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 1864 / SYSTEM][C:\Program Files\Virtual Machine Additions\vmsrvc.exe] [Microsoft Corporation, 013.820]
- [PID: 1924 / SYSTEM][C:\Program Files\Virtual Machine Additions\vpcmap.exe] [Microsoft Corporation, 013.820]
- [PID: 452 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
- [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 472 / Administrator][C:\Program Files\Virtual Machine Additions\vmusrvc.exe] [Microsoft Corporation, 013.820]
- [C:\Program Files\360\360Safe\safemon\safemon.dll] [360.cn, 6, 7, 6, 1002]
- [PID: 512 / Administrator][C:\PROGRA~1\Returnil\Returnil.exe] [Returnil SIA, 2.0.0.7058]
- [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [C:\Program Files\360\360Safe\safemon\safemon.dll] [360.cn, 6, 7, 6, 1002]
- [PID: 732 / Administrator][C:\Program Files\360\360netfw\360nfw.exe] [360.cn, 1, 0, 0, 1005]
- [C:\Program Files\360\360netfw\DumpUper.exe] [360安全中心, 1, 1, 0, 1101]
- [C:\Program Files\360\360netfw\MiniUI9.dll] [360.cn, 7, 3, 0, 1002]
- [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [C:\Program Files\360\360netfw\360fwctl.dll] [360.cn, 1, 0, 0, 1004]
- [C:\Program Files\360\360netfw\360netview.dll] [360.cn, 1, 0, 0, 1003]
- [C:\Program Files\360\360netfw\deepscan\Cloudcom2.dll] [360.cn, 3, 2, 3, 1006]
- [C:\Program Files\360\360netfw\deepscan\deepscan.dll] [360.cn, 3, 2, 3, 1022]
- [C:\Program Files\360\360netfw\Fwapi.dll] [360.cn, 1, 0, 0, 1004]
- [C:\Program Files\360\360netfw\nfwlive.dll] [360.cn, 1, 0, 0, 1004]
- [C:\Program Files\360\360netfw\safelive.dll] [360.cn, 1, 0, 0, 1007]
- [C:\Program Files\360\360netfw\pdown.dll] [360.cn, 1, 2, 0, 1016]
- [C:\Program Files\360\360netfw\nfwconn.dll] [360.cn, 1, 0, 0, 1004]
- [C:\Program Files\360\360netfw\nfwids.dll] [360.cn, 1, 0, 0, 1004]
- [C:\Program Files\360\360netfw\nfwcontrl.dll] [360.cn, 1, 0, 0, 1004]
- [C:\Program Files\360\360netfw\nfwnetr.dll] [360.cn, 1, 0, 0, 1004]
- [C:\Program Files\360\360netfw\nfwLog.dll] [360.cn, 1, 0, 0, 1004]
- [C:\Program Files\360\360Safe\safemon\safemon.dll] [360.cn, 6, 7, 6, 1002]
- [PID: 780 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
- [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 324 / Administrator][C:\Program Files\TrueCrypt\TrueCrypt.exe] [TrueCrypt Foundation, 7.0]
- [C:\Program Files\360\360Safe\safemon\safemon.dll] [360.cn, 6, 7, 6, 1002]
- [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [PID: 2824 / Administrator][C:\Program Files\360\360Se\360se3\360SE.exe] [360.cn, 3, 5, 0, 7]
- [C:\Program Files\360\360Se\360se3\Extensions\SafeCentral\SafeCentral.dll] [360.cn, 1, 3, 1, 1054]
- [C:\Program Files\360\360Safe\safemon\safemon.dll] [360.cn, 6, 7, 6, 1002]
- [C:\Program Files\360\360Se\360se3\Extensions\Favorites\Favorites.dll] [360.cn, 2, 0, 2, 1050]
- [C:\Program Files\360\360Se\360se3\Extensions\LoginEnrol\LoginEnrol.dll] [360.cn, 2, 0, 2, 1050]
- [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [C:\Program Files\360\360Safe\safemon\iNetSafe.dll] [360.cn, 1, 0, 0, 1008]
- [C:\Program Files\360\360Safe\safemon\AppFltr.dll] [, 1, 0, 0, 1001]
- [C:\Program Files\360\360Se\360se3\sqlite3.dll] [N/A, ]
- [C:\PROGRA~1\360\360Se\360se3\Extensions\UICenter\UICenter.dll] [360.cn, 1, 1, 0, 1006]
- [C:\Program Files\360\360Safe\safemon\LoadWDUI.dll] [360.cn, 1, 0, 0, 1018]
- [C:\PROGRA~1\360\360Se\360se3\Extensions\ExtAddons\ExtAddons.dll] [360.cn, 1, 0, 5, 1005]
- [C:\PROGRA~1\360\360Se\360se3\Extensions\ExtAdfilter\ExtAdfilter.dll] [360.cn, 1, 1, 0, 1040]
- [C:\Program Files\360\360Safe\Safemon\adfilter.dll] [360.cn, 1, 0, 0, 1007]
- [C:\PROGRA~1\360\360Se\360se3\Extensions\ExtBank\ExtBank.dll] [360.cn, 1, 0, 2, 1003]
- [C:\PROGRA~1\360\360Se\360se3\Extensions\ExtDoctor\ExtDoctor.dll] [360.cn, 1, 0, 0, 1013]
- [C:\Documents and Settings\Administrator\Application Data\360se\extensions\ExtDoctor\doctor.dll] [360.cn, 1, 0, 1, 1014]
- [C:\PROGRA~1\360\360Se\360se3\Extensions\ExtDownload\ExtDownload.dll] [360.cn, 1, 0, 4, 1004]
- [C:\PROGRA~1\360\360Se\360se3\Extensions\ExtPages\ExtPages.dll] [360.cn, 1, 0, 7, 1001]
- [C:\PROGRA~1\360\360Se\360se3\Extensions\ExtProxy\ExtProxy.dll] [360.cn, 1, 0, 2, 1004]
- [C:\PROGRA~1\360\360Se\360se3\Extensions\ExtSafeAddress\ExtSafeAddress.dll] [360.cn, 1, 0, 1, 1005]
- [C:\PROGRA~1\360\360Se\360se3\Extensions\ExtSuggest\ExtSuggest.dll] [360SE, 1, 0, 1, 2]
- [C:\PROGRA~1\360\360Se\360se3\Extensions\ExtUrlQuery\ExtUrlQuery.dll] [360.cn, 1, 0, 0, 1001]
- [C:\PROGRA~1\360\360Se\360se3\Extensions\onlinefav\onlinefav.dll] [360.cn, 3, 1, 0, 1001]
- [C:\PROGRA~1\360\360Se\360se3\Extensions\SnapPlugin\SnapPlugin.dll] [360.cn, 1, 1, 0, 1003]
- [C:\PROGRA~1\360\360Se\360se3\Extensions\TranslatorPlugin\TranslatorPlugin.dll] [360.cn, 2, 0, 0, 1012]
- [C:\Program Files\360\360Safe\safemon\urlproc.dll] [360.cn, 1, 2, 5, 1001]
- [C:\Program Files\360\360Safe\safemon\urlprocnet.dll] [360.cn, 1, 2, 2, 1001]
- [C:\Program Files\360\360Safe\deepscan\heavygate.dll] [360.cn, 3, 6, 21, 0]
- [C:\Program Files\360\360Safe\360common.dll] [360.cn, 7, 3, 0, 1014]
- [C:\Program Files\360\360Safe\safemon\sepro.dll] [360.cn, 1, 2, 0, 1003]
- [C:\WINDOWS\system32\Macromed\Flash\Flash10l.ocx] [Adobe Systems, Inc., 10,1,102,64]
- [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 3308 / Administrator][C:\Program Files\360\360Se\360se3\Extensions\SafeCentral\urlproc.exe] [360.cn, 1.0.0.1002]
- [C:\Program Files\360\360Se\360se3\Extensions\SafeCentral\urlproc.dll] [360.cn, 1, 2, 0, 1004]
- [C:\Program Files\360\360Se\360se3\Extensions\SafeCentral\urlprocnet.dll] [360.cn, 1, 1, 0, 1005]
- [C:\Program Files\360\360Safe\safemon\safemon.dll] [360.cn, 6, 7, 6, 1002]
- [PID: 268 / Administrator][C:\Program Files\腾讯游戏\QQGAME\QQGame.exe] [深圳市腾讯计算机系统有限公司, 2, 4, 106, 60]
- [C:\Program Files\360\360Safe\safemon\safemon.dll] [360.cn, 6, 7, 6, 1002]
- [C:\Program Files\腾讯游戏\QQGAME\Common\Utility.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\HelpDll.dll] [, 1, 0, 0, 1]
- [C:\Program Files\腾讯游戏\QQGAME\ResEx.dll] [深圳市腾讯计算机系统有限公司, 0, 10, 0, 0]
- [C:\Program Files\腾讯游戏\QQGAME\factory.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\ComAsyn.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\StartUp.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Res\ErrorDes.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\UI\CommonUI.dll] [, 1, 0, 0, 1]
- [C:\Program Files\腾讯游戏\QQGAME\Tenio\TenFact.dll] [Tencent, 0, 1, 6, 1]
- [C:\Program Files\腾讯游戏\QQGAME\Tenio\TenHall.dll] [Tencent, 0, 1, 6, 1]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\MainLogi.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\AdBanner.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\UIStyle.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Res\QGString.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\Login.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\ProtHand\QQProt.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\DlImpl.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\DlProxy.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\LafDown.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\ProtHand\BaseProt.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Common\ProcMsg.dll] [, 1, 0, 0, 1]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\SelfInfo.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Common\Compress.dll] [N/A, ]
- [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\CAAddins\MGRoom.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\ProtHand\ScatProt.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\MRoomMgr.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\ShopMgr.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\ItemShop.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\ScripEng.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\python24.dll] [Python Software Foundation, 2.4.1]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\ChanAdd\DirChn.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\QQAvDld.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\GAvatar.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\CAAddins\GLaunch.dll] [, 1, 0, 0, 1]
- [C:\Program Files\腾讯游戏\QQGAME\UI\SocialUI.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Storage\MiscStor.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Socket\NetMod.dll] [N/A, ]
- [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [C:\WINDOWS\system32\icm32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
- [C:\WINDOWS\system32\Macromed\Flash\Flash10l.ocx] [Adobe Systems, Inc., 10,1,102,64]
- [PID: 684 / Administrator][C:\Program Files\腾讯游戏\QQGAME\QQGameDl.exe] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Common\Utility.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\factory.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\ComAsyn.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\DlImpl.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Logic\DlProxy.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Common\ProcMsg.dll] [, 1, 0, 0, 1]
- [C:\Program Files\腾讯游戏\QQGAME\ProtHand\BaseProt.dll] [N/A, ]
- [C:\Program Files\腾讯游戏\QQGAME\Socket\NetMod.dll] [N/A, ]
- [PID: 2424 / Administrator][C:\WINDOWS\system32\NOTEPAD.EXE] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
- [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [C:\Program Files\360\360Safe\safemon\safemon.dll] [360.cn, 6, 7, 6, 1002]
- [PID: 3104 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.963\SREngLdr.EXE] [Smallfrogs Studio, 2.8.2.1321]
- [PID: 3976 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.963\SRE5e459eae.EXE] [Smallfrogs Studio, 2.8.2.1321]
- [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
- [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.963\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
- ==================================
- 文件关联
- .TXT Error. [C:\WINDOWS\system32\NOTEPAD.EXE %1]
- .EXE OK. ["%1" %*]
- .COM OK. ["%1" %*]
- .PIF OK. ["%1" %*]
- .REG OK. [regedit.exe "%1"]
- .BAT OK. ["%1" %*]
- .SCR OK. ["%1" /S]
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
- .INI Error. [C:\WINDOWS\system32\NOTEPAD.EXE %1]
- .INF Error. [C:\WINDOWS\system32\NOTEPAD.EXE %1]
- .VBS Error. ["C:\WINDOWS\System32\WScript.exe" "%1" %*]
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- ==================================
- Winsock 提供者
- N/A
- ==================================
- Autorun.inf
- N/A
- ==================================
- HOSTS 文件
- 127.0.0.1 localhost
- ==================================
- 进程特权扫描
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 548, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 512, C:\PROGRA~1\RETURNIL\RETURNIL.EXE]
- ==================================
- 计划任务
- N/A
- ==================================
- Windows 安全更新检查
- N/A
- ==================================
- API HOOK
- N/A
- ==================================
- 隐藏进程
- N/A
- ==================================
复制代码
|