回复 5楼 zhou0197 的帖子
多谢你的回复,有时间请给看下日志
计划任务
Windows 安全更新检查
API HOOK
隐藏进程
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<FlashPlayerUpdate><C:\WINDOWS\system32\Macromed\Flash\FlashUtil10k_ActiveX.exe -update activex> [(Verified)Adobe Systems Incorporated]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<WPDShServiceObj><C:\WINDOWS\system32\wpdshserviceobj.dll> [(Verified)Microsoft Windows Component Publisher]
<PostBootReminder><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher]
<CDBurn><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher]
<WebCheck><%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Component Publisher]
<SysTray><C:\WINDOWS\system32\stobject.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
<WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
<WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
<WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
<WinlogonNotify: dimsntfy><%SystemRoot%\System32\dimsntfy.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
<WinlogonNotify: ScCertProp><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
<WinlogonNotify: Schedule><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
<WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
<WinlogonNotify: termsrv><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
<WinlogonNotify: wlballoon><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
<Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
<浏览器自定义组件><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
<Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
<Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install> [Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\WINDOWS\system32\logon.scr> [(Verified)Microsoft Windows Component Publisher]
==================================
启动文件夹
N/A
==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[XLDoctor Services / XLDoctor Services][Running/Auto Start]
<C:\Program Files\Thunder Network\Thunder\Program\DctSer.exe><深圳市迅雷网络技术有限公司>
==================================
驱动程序
[C-Media WDM Audio Interface / cmuda][Stopped/Manual Start]
<system32\drivers\cmuda.sys><C-Media Inc>
[Creative AudioPCI (ES1371,ES1373) (WDM) / es1371][Running/Manual Start]
<system32\drivers\es1371mp.sys><Creative Technology Ltd.>
[VIA Rhine-Family Fast-Ethernet Adapter Driver Service / FET5X86V][Stopped/Manual Start]
<system32\DRIVERS\fetnd5bv.sys><VIA Technologies, Inc.>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
<system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[AMD PCNET Compatable Adapter Driver / PCnet][Stopped/Manual Start]
<system32\DRIVERS\pcntpci5.sys><AMD Inc.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Running/Manual Start]
<system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[SATALink driver accelerator / SiFilter][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\SiWinAcc.sys><Silicon Image, Inc.>
[System Restore Filter Driver / Sr][Stopped/Boot Start]
<\SystemRoot\system32\DRIVERS\sr.sys><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[VIA AGP Filter / viaagp1][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
[viamraid / viamraid][Stopped/Boot Start]
<\SystemRoot\system32\DRIVERS\viamraid.sys><VIA Technologies inc,.ltd>
[videX32 / videX32][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\videX32.sys><VIA Technologies, Inc.>
[VMware VMCI Bus Driver / vmci][Stopped/Manual Start]
<system32\DRIVERS\vmci.sys><VMware, Inc.>
[vmx_svga / vmx_svga][Stopped/Manual Start]
<system32\DRIVERS\vmx_svga.sys><VMware, Inc.>
==================================
浏览器加载项
[迅雷下载支持]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\BHO\XunleiBHO7.1.4.2082.dll, (Signed) 深圳市迅雷网络技术有限公司>
[]
{e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, (Signed) N/A>
[]
{01443AEC-0FD1-40FD-9C87-E93D1494C233} <, >
[KuGoo3Down Control]
{162AF25B-5A2A-448E-A842-194653EF3E05} <C:\WINDOWS\system32\KuGoo3DownXControl.ocx, (Signed) N/A>
[Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <C:\Program Files\Thunder Network\Thunder\BHO\ThunderAgent7.1.4.2082.dll, (Signed) 深圳市迅雷网络技术有限公司>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, (Signed) Microsoft Corporation>
[迅雷下载支持]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\BHO\XunleiBHO7.1.4.2082.dll, (Signed) 深圳市迅雷网络技术有限公司>
[OFrameObject Class]
{9701758C-4373-482E-B13C-776C048EC890} <C:\Program Files\Common Files\Thunder Network\KanKan\DapCtrl.2.3.7104.322.(345).dll, (Signed) ShenZhen Thunder Networking Technologies Ltd.>
[VersionDetector Class]
{9EFF1953-9694-47B1-AEF6-B2A3FE8BFE9B} <C:\Program Files\Common Files\Thunder Network\KanKan\vd.1.1.0.32.(150).dll, (Signed) ShenZhen Thunder Networking Technologies,Ltd.>
[APlayer Control]
{A9322148-C691-4B9D-91FC-B9C461DBE9DD} <C:\Program Files\Common Files\Thunder Network\APlayer\APlayer_001.dll, (Signed) ShenZhen Thunder Networking Technologies, LTD>
[DapCtrl Class]
{ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} <C:\Program Files\Common Files\Thunder Network\KanKan\DapCtrl.2.3.7104.322.(345).dll, (Signed) ShenZhen Thunder Networking Technologies Ltd.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash10k.ocx, (Signed) Adobe Systems, Inc.>
[xoliimpl Class]
{DD5BF6D1-6663-47E0-9DFA-5C343CAF178E} <C:\WINDOWS\system32\xoli3.dll, (Signed) 深圳市迅雷技术有限公司>
[]
{E2E2DD38-D088-4134-82B7-F2BA38496583} <, >
[Xunlei Digital Video DRM Control]
{E577393C-3468-4911-9DA0-484C3F4C47D7} <C:\Program Files\Common Files\Thunder Network\APlayer\Codecs\xlvsource.ax, >
[]
{F3E70CEA-956E-49CC-B444-73AFE593AD7F} <, >
[使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\BHO\geturl.htm, N/A>
[使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\BHO\GetAllUrl.htm, N/A>
==================================
正在运行的进程
[PID: 388 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 448 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 480 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 524 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[PID: 536 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 688 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 912 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 984 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\System32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1080 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1248 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1280 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\WinRAR\rarext.dll] [, ]
[PID: 1376 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.6024 (xpsp_sp3_qfe.100817-1627)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1448 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1608 / SYSTEM][C:\Program Files\Thunder Network\Thunder\Program\DctSer.exe] [深圳市迅雷网络技术有限公司, 1.0.1.81]
[PID: 1848 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1996 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 344 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 712 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Thunder Network\Thunder\BHO\XunleiBHO7.1.4.2082.dll] [深圳市迅雷网络技术有限公司, 7,1,4,2082]
[C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.6101.0]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Thunder Network\Thunder\BHO\xldb.7.1.4.2082.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 5]
[C:\Program Files\Thunder Network\Thunder\BHO\xldp.7.1.4.2082.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 23]
[C:\WINDOWS\system32\Macromed\Flash\Flash10k.ocx] [Adobe Systems, Inc., 10,1,85,3]
[C:\Program Files\Thunder Network\Thunder\BHO\ThunderAgent7.1.4.2082.dll] [深圳市迅雷网络技术有限公司, 7,1,4,2082]
[C:\WINDOWS\system32\WN.IME] [深圳世强软件开发部 www.wn51.com, 8, 0, 2, 9]
[C:\Program Files\shiqiang\wnime\plugin\WnPlugin.dll] [深圳世强软件开发部 www.wn51.com, 8, 0, 2, 9]
[C:\Program Files\shiqiang\wnime\plugin\ResPlugin.dll] [深圳世强软件开发部 www.wn51.com, 8, 0, 2, 9]
[C:\Program Files\shiqiang\wnime\plugin\UIPlugin.dll] [深圳世强软件开发部 www.wn51.com, 8, 0, 2, 9]
[C:\Program Files\shiqiang\wnime\plugin\FnPlugin.dll] [深圳世强软件开发部 www.wn51.com, 8, 0, 2, 9]
[C:\Program Files\shiqiang\wnime\plugin\WnOperateMB.dll] [深圳世强软件开发部 www.wn51.com, 8, 0, 2, 9]
[C:\Program Files\shiqiang\wnime\plugin\KBPlugin.dll] [深圳世强软件开发部 www.wn51.com, 8, 0, 2, 9]
[PID: 1020 / Administrator][C:\Program Files\Thunder Network\Thunder\Program\Thunder.exe] [深圳市迅雷网络技术有限公司, 7,1,4,2082]
[C:\Program Files\Thunder Network\Thunder\Program\XLUE.dll] [深圳市迅雷网络技术有限公司, 0.8.0.134]
[C:\Program Files\Thunder Network\Thunder\Program\XLGraphic.dll] [深圳市迅雷网络技术有限公司, 0.8.0.134]
[C:\Program Files\Thunder Network\Thunder\Program\libpng13.dll] [, 1.2.38]
[C:\Program Files\Thunder Network\Thunder\Program\zlib1.dll] [, 1.2.3]
[C:\Program Files\Thunder Network\Thunder\Program\MSVCR71.dll] [Microsoft Corporation, 7.10.6030.0]
[C:\Program Files\Thunder Network\Thunder\Program\minizip.dll] [N/A, ]
[C:\Program Files\Thunder Network\Thunder\Program\MSVCP71.dll] [Microsoft Corporation, 7.10.6030.0]
[C:\Program Files\Thunder Network\Thunder\Program\XLLuaRuntime.dll] [深圳市迅雷网络技术有限公司, 0.8.0.130]
[C:\Program Files\Thunder Network\Thunder\Program\libexpat.dll] [N/A, ]
[C:\Program Files\Thunder Network\Thunder\Program\ATL71.DLL] [Microsoft Corporation, 7.10.6101.0]
[C:\Program Files\Thunder Network\Thunder\Program\DownloadKernel.dll] [深圳市迅雷网络技术有限公司, 7,1,4,2082]
[C:\Program Files\Thunder Network\Thunder\Program\sqlite3.dll] [, 3, 6, 22, 0]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Thunder Network\Thunder\Program\xl_data.dll] [深圳市迅雷网络技术有限公司, 1, 11, 5, 33]
[C:\Program Files\Thunder Network\Thunder\Program\asyn_download_interface.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 53]
[C:\Program Files\Thunder Network\Thunder\Program\tp_proxy.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 18]
[C:\Program Files\Thunder Network\Thunder\Program\XLUserAX.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 42]
[C:\Program Files\Thunder Network\Thunder\Program\SuperDownloadInfo.dll] [深圳市迅雷网络技术有限公司, 7,1,4,2082]
[C:\Program Files\Thunder Network\Thunder\Program\dl_peer_id.dll] [深圳市迅雷网络技术有限公司, 3, 2, 2, 16]
[C:\Program Files\Thunder Network\Thunder\Program\xl_client.dll] [深圳市迅雷网络技术有限公司, 1, 13, 2, 32]
[C:\Program Files\Thunder Network\Thunder\Program\asyn_frame.dll] [深圳市迅雷网络技术有限公司, 1, 5, 2, 42]
[C:\Program Files\Thunder Network\Thunder\Program\dl_uac_tool.dll] [N/A, ]
[C:\Program Files\Thunder Network\Thunder\Program\mp.dll] [深圳市迅雷网络技术有限公司, 1, 1, 2, 9]
[C:\Program Files\Thunder Network\Thunder\Program\xl_stat_client.dll] [深圳市迅雷网络技术有限公司, 1.1.0.60]
[C:\Program Files\Thunder Network\Thunder\Addins\Community\XLCPAddinManager.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 19]
[C:\Program Files\Thunder Network\Thunder\Addins\community\Community.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 58]
[C:\Program Files\Thunder Network\Thunder\Addins\Community\http.dll] [深圳市迅雷网络技术有限公司, 1.0.2.15]
[C:\Program Files\Thunder Network\Thunder\Addins\Community\XLCP.dll] [Thunder Networking Technologies,LTD, 1.0.1.22]
[C:\Program Files\Thunder Network\Thunder\Addins\Community\BaseIM.dll] [TODO: <Company name>, 1.0.2.13]
[C:\Program Files\Thunder Network\Thunder\Addins\Community\TipsManager.dll] [Thunder Networking Technologies,LTD, 1.0.2.24]
[C:\Program Files\Thunder Network\Thunder\Addins\community\VipService.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 102]
[C:\Program Files\Thunder Network\Thunder\Addins\DoctorAddin\DoctorAddin.dll] [深圳市迅雷网络技术有限公司, 1.0.1.79]
[C:\Program Files\Thunder Network\Thunder\XLDoctor\7.1.4.2082_1\Program\XLDoctor.dll] [深圳市迅雷网络技术有限公司, 1.0.1.85]
[C:\Program Files\Thunder Network\Thunder\Addins\GougouSearch\SearchFun.dll] [TODO: <公司名>, 1.0.0.4]
[C:\Program Files\Thunder Network\Thunder\XLDoctor\7.1.4.2082_1\Program\tp_proxy.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 18]
[C:\Program Files\Thunder Network\Thunder\Addins\MallAddin\MallAddin.dll] [TODO: <Company name>, 1.0.0.78]
[C:\Program Files\Thunder Network\Thunder\Addins\InMediaAddin\iEmbed.dll] [Thunder Networking Technologies,LTD, 4, 0, 1, 19]
[C:\Program Files\Thunder Network\Thunder\Addins\community\SnickersAd.dll] [深圳市迅雷网络技术有限公司, 1.0.2.6]
[C:\Program Files\Thunder Network\Thunder\Addins\WalkboxAddin\WalkboxAddin.dll] [ShenZhen Thunder Networking Technologies,LTD, 1, 0, 2, 10]
[C:\Program Files\Thunder Network\Thunder\Addins\MobileAddin\MobileLite.dll] [Thunder Networking Technologies,LTD, 1.0.2.32]
[PID: 1188 / Administrator][c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\thunderplatform.exe] [深圳市迅雷网络技术有限公司, 1, 1, 2, 42]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\minizip.dll] [N/A, ]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\zlib1.dll] [, 1.2.3]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\MSVCR71.dll] [Microsoft Corporation, 7.10.6030.0]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\MSVCP71.dll] [Microsoft Corporation, 7.10.6030.0]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\XLBugHandler.dll] [深圳市迅雷网络技术有限公司, 2, 2, 0, 7]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\dl_uac_tool.dll] [N/A, ]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\download_engine.dll] [深圳市迅雷网络技术有限公司, 3, 5, 2, 396]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\mp.dll] [深圳市迅雷网络技术有限公司, 1, 1, 2, 9]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\XLCrypto.dll] [N/A, ]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\asyn_frame.dll] [深圳市迅雷网络技术有限公司, 1, 5, 2, 42]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\ATL71.DLL] [Microsoft Corporation, 7.10.6101.0]
[C:\Documents and Settings\All Users\Application Data\Thunder Network\ThunderPlatform\ThunderPlatform_1.1.2.42_1111_a\Components\DownloadLibDll\md_p_1.0.239\emule_id.dll] [深圳市迅雷网络技术有限公司, 1, 1, 2, 21]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\backend_agent.dll] [深圳市迅雷网络技术有限公司, 1, 2, 2, 46]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\ptl.dll] [深圳市迅雷网络技术有限公司, 3, 3, 2, 95]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\dl_peer_id.dll] [深圳市迅雷网络技术有限公司, 3, 2, 2, 16]
[C:\Documents and Settings\All Users\Application Data\Thunder Network\ThunderPlatform\ThunderPlatform_1.1.2.42_1111_a\Components\DownloadLibDll\md_p_1.0.239\xl_stat.dll] [深圳市迅雷网络技术有限公司, 1, 1, 2, 10]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\ts.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 26]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\ta.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 60]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\xl_data.dll] [深圳市迅雷网络技术有限公司, 1, 11, 5, 33]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\XLLuaRuntime.dll] [深圳市迅雷网络技术有限公司, 0.8.0.130]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\libexpat.dll] [N/A, ]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\xl_client.dll] [深圳市迅雷网络技术有限公司, 1, 13, 2, 32]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\fs.dll] [深圳市迅雷网络技术有限公司, 1, 2, 2, 26]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\p2sp.dll] [深圳市迅雷网络技术有限公司, 1, 2, 2, 140]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\down_dispatcher.dll] [深圳市迅雷网络技术有限公司, 1, 2, 2, 76]
[C:\Documents and Settings\All Users\Application Data\Thunder Network\ThunderPlatform\ThunderPlatform_1.1.2.42_1111_a\Components\DownloadLibDll\md_p_1.0.239\member_stat.dll] [深圳市迅雷网络技术有限公司, 1, 1, 2, 12]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\al.dll] [深圳市迅雷网络技术有限公司, 1, 2, 2, 95]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\p2p_upload.dll] [深圳市迅雷网络技术有限公司, 1, 2, 2, 20]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\xlnet_manager.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 34]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\UACTool.dll] [N/A, ]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\p2p.dll] [深圳市迅雷网络技术有限公司, 1, 2, 2, 136]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\stream.dll] [深圳市迅雷网络技术有限公司, 2, 1, 2, 1145]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\dphubt.dll] [深圳市迅雷网络技术有限公司, 1, 1, 2, 41]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\p2p_local_res.dll] [深圳市迅雷网络技术有限公司, 1, 2, 2, 28]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\media_data.dll] [深圳市迅雷网络技术有限公司, 1, 1, 2, 12]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\sl.dll] [深圳市迅雷网络技术有限公司, 1, 1, 2, 8]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\task_report.dll] [深圳市迅雷网络技术有限公司, 1, 1, 2, 7]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\p2p_session_com.dll] [深圳市迅雷网络技术有限公司, 1, 1, 2, 90]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\dtnet.dll] [深圳市迅雷网络技术有限公司, 1.0.1.13]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\p2ptl2.dll] [深圳市迅雷网络技术有限公司, 1, 3, 2, 16]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\module_downloader.dll] [深圳市迅雷网络技术有限公司, 1, 1, 2, 18]
[c:\program files\common files\thunder network\tp\ver1\1.1.2.42_1111\mini_unzip_dll.dll] [N/A, ]
[C:\Documents and Settings\All Users\Application Data\Thunder Network\ThunderPlatform\ThunderPlatform_1.1.2.42_1111_a\Components\DownloadLibDll\md_p_1.0.239\bd.dll] [深圳市迅雷网络技术有限公司, 1, 1, 2, 26]
[PID: 1964 / Administrator][C:\Program Files\Thunder Network\Thunder\Addins\InMediaAddin\ThunderMinisite.exe] [Thunder Networking Technologies,LTD, 2, 0, 1, 19]
[C:\Program Files\Thunder Network\Thunder\Program\XLGraphic.dll] [深圳市迅雷网络技术有限公司, 0.8.0.134]
[C:\Program Files\Thunder Network\Thunder\Program\libpng13.dll] [, 1.2.38]
[C:\Program Files\Thunder Network\Thunder\Program\zlib1.dll] [, 1.2.3]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Thunder Network\Thunder\Program\minizip.dll] [N/A, ]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Thunder Network\Thunder\Program\libexpat.dll] [N/A, ]
[C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.6101.0]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Common Files\Thunder Network\KanKan\DapCtrl.2.3.7104.322.(345).dll] [ShenZhen Thunder Networking Technologies Ltd., 2, 3, 7104, 322]
[C:\WINDOWS\system32\Macromed\Flash\Flash10k.ocx] [Adobe Systems, Inc., 10,1,85,3]
[PID: 3760 / Administrator][E:\TDdownload\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.8.2.1321]
[PID: 3784 / Administrator][E:\TDdownload\sreng2\SRE4cff8751.EXE] [Smallfrogs Studio, 2.8.2.1321]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[E:\TDdownload\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 480, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
==================================
计划任务
N/A
==================================
Windows 安全更新检查
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
|