[PID: 3704 / Administrator][E:\Tencent\QQ\QQ.exe] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\QQBaseClassInDll.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\QQHelperDll.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\BasicCtrlDll.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[E:\Tencent\QQ\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[E:\Tencent\QQ\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[E:\Tencent\QQ\QQAPI.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\LoginCtrl.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\LoginCtrlRes.dll] [TENCENT, 7,0,365,1701]
[C:\WINDOWS\ifc222.dll] [N/A, ]
[E:\Tencent\QQ\QQRes.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\WizardCtrl.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\QQMainFrame.dll] [N/A, ]
[E:\Tencent\QQ\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[E:\Tencent\QQ\CQQApplication.dll] [N/A, ]
[E:\Tencent\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[E:\Tencent\QQ\NewSkin.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\HostingMgr.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\CameraDll.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\MailSummary.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\QQKnowledgeSearch.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\QQAllInOne.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\SCCore.dll] [TENCENT, 1, 6, 0, 2]
[E:\Tencent\QQ\QQSpace.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\vbscript.dll] [Microsoft Corporation, 5.6.0.7426]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[E:\Tencent\QQ\QQGroupMng.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\QQSysMsgMng.dll] [N/A, ]
[E:\Tencent\QQ\UserDefinedHead.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\QQPlugin.dll] [N/A, ]
[E:\Tencent\QQ\QQConfigPlugin.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\QQAvatar.dll] [N/A, ]
[E:\Tencent\QQ\QQCustomFace.dll] [N/A, ]
[E:\Tencent\QQ\QRingMng.dll] [N/A, ]
[E:\Tencent\QQ\LongConnection.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\PhoneAPI.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[E:\Tencent\QQ\QQPet.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\BQQApplication.dll] [N/A, ]
[E:\Tencent\QQ\CommercesMng.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
[E:\Tencent\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 320]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[E:\Tencent\QQ\ImageOle.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\QQLiveQMng.dll] [TENCENT, 7,0,365,1701]
[F:\卡巴\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299]
[F:\卡巴\klscav.dll] [Kaspersky Lab, 6.0.0.299]
[F:\卡巴\pr_remote.dll] [Kaspersky Lab, 6.0.0.299]
[F:\卡巴\prloader.dll] [Kaspersky Lab, 6.0.0.299]
[F:\卡巴\prkernel.ppl] [Kaspersky Lab, 6.0.0.304]
[f:\卡巴\params.ppl] [Kaspersky Lab, 6.0.0.299]
[f:\卡巴\pxstub.ppl] [Kaspersky Lab, 6.0.0.299]
[f:\卡巴\tempfile.ppl] [Kaspersky Lab, 6.0.0.299]
[E:\Tencent\QQ\GroupConnection.dll] [TENCENT, 7,0,365,1701]
[E:\Tencent\QQ\QQSceneMng.dll] [N/A, ]
[E:\Tencent\QQ\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 1, 9, 95]
[E:\Tencent\QQ\QQFileTransfer.dll] [TENCENT, 7,0,365,1701]
[C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx] [Adobe Systems, Inc., 9,0,45,0]
[PID: 3224 / Administrator][E:\Tencent\TT\TTraveler.exe] [腾讯公司, 3.2.200.275]
[E:\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll] [腾讯公司, 1, 1, 0, 5]
[E:\Tencent\TT\Plugins\TWeather\TWeather.dll] [, 1, 0, 0, 3]
[C:\WINDOWS\ifc222.dll] [N/A, ]
[E:\Tencent\TT\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 4]
[F:\卡巴\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299]
[F:\卡巴\klscav.dll] [Kaspersky Lab, 6.0.0.299]
[F:\卡巴\pr_remote.dll] [Kaspersky Lab, 6.0.0.299]
[F:\卡巴\prloader.dll] [Kaspersky Lab, 6.0.0.299]
[F:\卡巴\prkernel.ppl] [Kaspersky Lab, 6.0.0.304]
[f:\卡巴\params.ppl] [Kaspersky Lab, 6.0.0.299]
[f:\卡巴\pxstub.ppl] [Kaspersky Lab, 6.0.0.299]
[f:\卡巴\tempfile.ppl] [Kaspersky Lab, 6.0.0.299]
[f:\卡巴\nfio.ppl] [Kaspersky Lab, 6.0.0.299]
[f:\卡巴\fsdrvplgn.ppl] [Kaspersky Lab, 6.0.0.299]
[C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx] [Adobe Systems, Inc., 9,0,45,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\UNISPIM5.IME] [北京紫光华宇软件股份有限公司, 5.0.0.5091]
[PID: 3436 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sreng2.zip 的临时目录 1\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\ifc222.dll] [N/A, ]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
218.6.9.218 bbs.65522.com
61.128.173.210 www.988199.net
218.6.9.194 www.hkyzx.com
219.153.55.68 www.zst001.com
203.120.112.200 www.singaporepools.com.sg
220.162.238.187 www.fjtc.com.cn
125.91.11.19 bbs.lllfff.com
204.16.192.11 k1122.cn
222.76.216.142 fj1.liaob.net
218.6.12.67 bbs.190hk.com
218.6.12.81 www.sss000.com
210.51.170.64 www.tm2007.net
219.153.34.100 www.bai66.com
125.64.92.207 www.zggpw.com
125.91.12.231 www.5959888.com
219.238.235.101 forum.ikaka.com
58.218.202.212 www.qqgexing.com
58.61.39.224 blog.xunlei.com
61.129.76.78 movieso.xunlei.com
58.61.39.224 blog.xunlei.com
61.152.238.179 sscn.tqiu.com
221.233.134.12 www.foxgas.com
125.90.207.68 space.ouou.com
219.153.18.140 www.sunaa.com
125.90.204.163 www.56.com
125.90.204.163 www.56.com
125.90.204.163 www.56.com
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 3224, E:\TENCENT\TT\TTRAVELER.EXE]
==================================
API HOOK
RVA 错误: LoadLibraryA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: LoadLibraryExA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: LoadLibraryW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
==================================
隐藏进程
N/A
==================================
[/CODE]