[C:\Program Files\360\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[D:\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
[PID: 1196][C:\Program Files\360\360safe\safemon\360Tray.exe] [360安全中心, 5, 0, 0, 1020]
[C:\Program Files\360\360safe\safemon\360compro.dll] [360安全中心, 1, 0, 0, 1009]
[C:\Program Files\360\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[C:\Program Files\360\360safe\safemon\urlproc.dll] [360.CN, 1, 0, 0, 1006]
[C:\Program Files\360\360safe\safemon\SafeKrnl.dll] [奇虎网, 5, 0, 0, 1004]
[C:\Program Files\360\360safe\AntiAdwa.dll] [360Safe.com, 4, 2, 0, 1002]
[C:\Program Files\360\360safe\safemon\360webpro.dll] [360.CN, 1, 0, 0, 1008]
[C:\Program Files\360\360safe\live.dll] [360.cn, 1, 0, 2, 1007]
[C:\Program Files\360\360safe\Antieng.dll] [360Safe.com, 5, 0, 0, 1002]
[C:\Program Files\360\360safe\pdown.dll] [360Safe.com, 1, 1, 0, 0]
[C:\Program Files\360\360safe\LiveUpd360.dll] [360Safe.com, 1, 1, 0, 1007]
[C:\Program Files\360\360safe\360net.dll] [奇虎网, 1, 1, 3, 1006]
[PID: 1236][C:\WINNT\System32\internat.exe] [(Verified) Microsoft Corporation, 5.00.2920.0000]
[PID: 892][C:\WINNT\System32\conime.exe] [(Verified) Microsoft Corporation, 5.00.2180.1]
[C:\Program Files\360\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[PID: 864][C:\WINNT\System32\dllhost.exe] [(Verified) Microsoft Corporation, 5.00.2195.2815]
[c:\Oracle\Ora81\bin\ociw32.dll] [Oracle Corporation, 8.0.5.0.0]
[PID: 1296][C:\zxbf\sreng2[1].8.1.1279版\sr-engldr.EXE] [Smallfrogs Studio, 2.8.1.1279]
[PID: 1480][C:\zxbf\sreng2[1].8.1.1279版\SRE248f5e71.EXE] [Smallfrogs Studio, 2.8.1.1279]
[C:\Program Files\360\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[C:\zxbf\sreng2[1].8.1.1279版\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
10.43.113.195 ttaserver ttaserver.tta.com.cn
144.40.16.23
www.360safe.com144.40.16.23 my.360safe.com
144.40.16.23 dl.360safe.com
144.40.16.23 update.360safe.com
144.40.16.23 updatem.360safe.com
144.40.16.23 boxinst.360safe.com
144.40.16.23 softm.update.360safe.com
144.40.16.23 baike.360.cn
144.40.16.23 bimg.360.cn
144.40.16.23 img.360.cn
144.40.16.23 soft.360.cn
144.40.16.23 360.qihoo.com
144.40.16.23 pimg.qihoo.com
144.40.16.23 uimg.qihoo.com
144.40.16.23 aimg.qihoo.com
144.40.16.23 ardownload.adobe.com
144.40.16.23 fpdownload.macromedia.com
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 684, C:\ORACLE\ORA81\BIN\TNSLSNR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 764, C:\ORACLE\ORA81\BIN\ORACLE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 788, C:\ORACLE\ORA81\BIN\OWASTSVR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1296, C:\ZXBF\SRENG2[1].8.1.1279版\SR-ENGLDR.EXE]
==================================
计划任务
N/A
==================================
Windows 安全更新检查
N/A
==================================
API HOOK
入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: C:\Program Files\360\360safe\safemon\safemon.dll)
入口点错误:SHBrowseForFolder (危险等级: 高, 被下面模块所HOOK: 0x4483F5C8)
入口点错误:SHBrowseForFolderA (危险等级: 高, 被下面模块所HOOK: 0x4483F5C8)
==================================
隐藏进程
N/A