[C:\Program Files\Tencent\qq\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 1, 9, 93]
[PID: 3604 / qiuxiaoning][C:\Program Files\Tencent\TM\TMDlls\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[C:\WINDOWS\system32\VrvHook.dll] [Microsoft Corporation, 6, 12, 18, 15]
[C:\Program Files\Tencent\TM\TMDlls\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 3960 / qiuxiaoning][C:\Documents and Settings\qiuxiaoning\桌面\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\system32\VrvHook.dll] [Microsoft Corporation, 6, 12, 18, 15]
[C:\WINDOWS\system32\VrvKeyBoard.dll] [, 1, 0, 0, 1]
[C:\Documents and Settings\qiuxiaoning\桌面\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[C:\Program Files\Permeo\Security Driver\s5spi.dll] [Permeo Technologies Inc., 4, 2, 0, 0]
==================================
文件关联
.TXT Error. [notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG Error. [regedit.exe %1]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [notepad.exe %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
Permeo TCP
C:\Program Files\Permeo\Security Driver\s5spi.dll(Permeo Technologies Inc., Security Driver Loader)
Permeo UDP
C:\Program Files\Permeo\Security Driver\s5spi.dll(Permeo Technologies Inc., Security Driver Loader)
Permeo RSVP TCP
C:\Program Files\Permeo\Security Driver\s5spi.dll(Permeo Technologies Inc., Security Driver Loader)
Permeo RSVP UDP
C:\Program Files\Permeo\Security Driver\s5spi.dll(Permeo Technologies Inc., Security Driver Loader)
RSVP UDP Service Provider
C:\WINDOWS\VMailDog.dll(北信源, Vmaildog)
RSVP TCP Service Provider
C:\WINDOWS\VMailDog.dll(北信源, Vmaildog)
Permeo Security Driver
C:\Program Files\Permeo\Security Driver\s5spi.dll(Permeo Technologies Inc., Security Driver Loader)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 236, C:\WINDOWS\SYSTEM32\VRVEDP_M.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 404, C:\WINDOWS\SYSTEM32\VRVSAFEC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1984, C:\PROGRAM FILES\JAVA\JRE1.5.0_07\BIN\JUSCHED.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1048, E:\PROGRAM FILES\RISING\RAVTASK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1240, E:\PROGRAM FILES\RISING\RAVMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2148, C:\PROGRAM FILES\PERMEO\SECURITY DRIVER\EBICON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2788, C:\PROGRAM FILES\TENCENT\TT\TTRAVELER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3512, C:\PROGRAM FILES\TENCENT\QQ\QQ.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3604, C:\PROGRAM FILES\TENCENT\TM\TMDLLS\TIMPLATFORM.EXE]
==================================
API HOOK
入口点错误:NtOpenProcess (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:NtQuerySystemInformation (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:NtTerminateProcess (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:ZwOpenProcess (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:ZwTerminateProcess (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:RegOpenKeyExW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:RegDeleteKeyW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:EnumServicesStatusW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:FindFirstFileExW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:FindFirstFileW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:FindNextFileW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
==================================
隐藏进程
N/A
==================================
[/CODE]