[C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.5510]
[PID: 3976 / Administrator][C:\Program Files\Common Files\Teleca Shared\Generic.exe] [Teleca Software Solutions, 1, 0, 3, 2]
[C:\Program Files\Common Files\Teleca Shared\Telecalib_logging.dll] [Teleca/Popwire AB, 1, 0, 2, 3]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Common Files\Teleca Shared\boost_log-vc71-mt-1_32.dll] [N/A, ]
[C:\WINDOWS\system32\msxml4.dll] [Microsoft Corporation, 4.20.9848.0]
[C:\Program Files\Common Files\Teleca Shared\TC Device Mgmt.dll] [Teleca Software Solutions, 1, 0, 1, 1]
[C:\WINDOWS\system32\jratl.dll] [N/A, ]
[C:\WINDOWS\system32\dthxatl.dll] [N/A, ]
[C:\WINDOWS\system32\dh3atl.dll] [N/A, ]
[C:\WINDOWS\system32\qqhxatl.dll] [N/A, ]
[C:\WINDOWS\system32\wdatl.dll] [N/A, ]
[C:\WINDOWS\system32\gjatl.dll] [N/A, ]
[C:\WINDOWS\system32\wlatl.dll] [N/A, ]
[C:\WINDOWS\system32\zxatl.dll] [N/A, ]
[C:\WINDOWS\system32\wmatl.dll] [N/A, ]
[C:\WINDOWS\system32\tlatl.dll] [N/A, ]
[C:\WINDOWS\system32\qjatl.dll] [N/A, ]
[C:\WINDOWS\system32\myatl.dll] [N/A, ]
[C:\WINDOWS\system32\zhtuatl.dll] [N/A, ]
[C:\Program Files\Sony Ericsson\Mobile2\Device Manager\SpecificMPM.dll] [SonyEricsson, 1, 0, 2, 1]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\anubisps.dll] [N/A, ]
[C:\Program Files\Common Files\Teleca Shared\SpecificUSB.dll] [Popwire AB, 1, 2, 1, 1]
[C:\Program Files\Common Files\Teleca Shared\tlib_log.dll] [Popwire AB, 1, 0, 3, 3]
[C:\Program Files\Common Files\Teleca Shared\boost_log-vc71-mt-1_33.dll] [N/A, ]
[PID: 208 / Administrator][C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe] [Sony Ericsson Mobile Communications AB, 1, 2, 0,1183]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ShowMfcDialog.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,115]
[C:\WINDOWS\system32\jratl.dll] [N/A, ]
[C:\WINDOWS\system32\dthxatl.dll] [N/A, ]
[C:\WINDOWS\system32\dh3atl.dll] [N/A, ]
[C:\WINDOWS\system32\qqhxatl.dll] [N/A, ]
[C:\WINDOWS\system32\wdatl.dll] [N/A, ]
[C:\WINDOWS\system32\gjatl.dll] [N/A, ]
[C:\WINDOWS\system32\wlatl.dll] [N/A, ]
[C:\WINDOWS\system32\zxatl.dll] [N/A, ]
[C:\WINDOWS\system32\wmatl.dll] [N/A, ]
[C:\WINDOWS\system32\tlatl.dll] [N/A, ]
[C:\WINDOWS\system32\qjatl.dll] [N/A, ]
[C:\WINDOWS\system32\myatl.dll] [N/A, ]
[C:\WINDOWS\system32\zhtuatl.dll] [N/A, ]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\anubisps.dll] [N/A, ]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\cellphone_
object.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,1187]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ecsmoddata.dll] [Sony Ericsson Mobile Communications AB, 1, 2, 0,302]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\msmeirsock_
object.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,938]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ms98irsock_
object.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,983]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\msirsock_
object.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,995]
[C:\WINDOWS\system32\msxml4.dll] [Microsoft Corporation, 4.20.9848.0]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\cabmain.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,1219]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\xpbtsock_2_
object.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,131]
[PID: 2072 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jratl.dll] [N/A, ]
[C:\WINDOWS\system32\dthxatl.dll] [N/A, ]
[C:\WINDOWS\system32\dh3atl.dll] [N/A, ]
[C:\WINDOWS\system32\qqhxatl.dll] [N/A, ]
[C:\WINDOWS\system32\wdatl.dll] [N/A, ]
[C:\WINDOWS\system32\gjatl.dll] [N/A, ]
[C:\WINDOWS\system32\wlatl.dll] [N/A, ]
[C:\WINDOWS\system32\zxatl.dll] [N/A, ]
[C:\WINDOWS\system32\wmatl.dll] [N/A, ]
[C:\WINDOWS\system32\tlatl.dll] [N/A, ]
[C:\WINDOWS\system32\qjatl.dll] [N/A, ]
[C:\WINDOWS\system32\myatl.dll] [N/A, ]
[C:\WINDOWS\system32\zhtuatl.dll] [N/A, ]
[PID: 3592 / Administrator][C:\Program Files\Tencent\QQ\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[C:\WINDOWS\system32\jratl.dll] [N/A, ]
[C:\WINDOWS\system32\dthxatl.dll] [N/A, ]
[C:\WINDOWS\system32\dh3atl.dll] [N/A, ]
[C:\WINDOWS\system32\qqhxatl.dll] [N/A, ]
[C:\WINDOWS\system32\wdatl.dll] [N/A, ]
[C:\WINDOWS\system32\gjatl.dll] [N/A, ]
[C:\WINDOWS\system32\wlatl.dll] [N/A, ]
[C:\WINDOWS\system32\zxatl.dll] [N/A, ]
[C:\WINDOWS\system32\wmatl.dll] [N/A, ]
[C:\WINDOWS\system32\tlatl.dll] [N/A, ]
[C:\WINDOWS\system32\qjatl.dll] [N/A, ]
[C:\WINDOWS\system32\myatl.dll] [N/A, ]
[C:\WINDOWS\system32\zhtuatl.dll] [N/A, ]
[C:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 3080 / Administrator][C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE] [Microsoft Corporation, 11.0.6359]
[C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll] [Microsoft Corporation, 11.0.6360]
[C:\WINDOWS\system32\jratl.dll] [N/A, ]
[C:\WINDOWS\system32\dthxatl.dll] [N/A, ]
[C:\WINDOWS\system32\dh3atl.dll] [N/A, ]
[C:\WINDOWS\system32\qqhxatl.dll] [N/A, ]
[C:\WINDOWS\system32\wdatl.dll] [N/A, ]
[C:\WINDOWS\system32\gjatl.dll] [N/A, ]
[C:\WINDOWS\system32\wlatl.dll] [N/A, ]
[C:\WINDOWS\system32\zxatl.dll] [N/A, ]
[C:\WINDOWS\system32\wmatl.dll] [N/A, ]
[C:\WINDOWS\system32\tlatl.dll] [N/A, ]
[C:\WINDOWS\system32\qjatl.dll] [N/A, ]
[C:\WINDOWS\system32\myatl.dll] [N/A, ]
[C:\WINDOWS\system32\zhtuatl.dll] [N/A, ]
[C:\Program Files\Common Files\Microsoft Shared\office11\riched20.dll] [Microsoft Corporation, 5.50.99.2009]
[D:\Program Files\Rising\Rav\RsPlugIn.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17]
[C:\PROGRA~1\MICROS~2\OFFICE11\ADDINS\SYMINPUT.DLL] [Microsoft Corporation, 1.02]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690]
[C:\WINDOWS\system32\VB6CHS.DLL] [Microsoft Corporation, 6.00.8169]
[C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL] [Microsoft Corporation, 1.1.6215]
[C:\Program Files\Common Files\Microsoft Shared\PROOF\mslid.dll] [Microsoft Corporation, 1.0.2305]
[C:\Program Files\Common Files\Microsoft Shared\PROOF\1033\MSGR3EN.DLL] [Microsoft Corporation, 3.1.2303]
[C:\Program Files\Microsoft Office\OFFICE11\msostyle.dll] [Microsoft Corporation, 11.0.5510]
[PID: 3116 / Administrator][D:\Program Files\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\system32\jratl.dll] [N/A, ]
[C:\WINDOWS\system32\dthxatl.dll] [N/A, ]
[C:\WINDOWS\system32\dh3atl.dll] [N/A, ]
[C:\WINDOWS\system32\qqhxatl.dll] [N/A, ]
[C:\WINDOWS\system32\wdatl.dll] [N/A, ]
[C:\WINDOWS\system32\gjatl.dll] [N/A, ]
[C:\WINDOWS\system32\wlatl.dll] [N/A, ]
[C:\WINDOWS\system32\zxatl.dll] [N/A, ]
[C:\WINDOWS\system32\wmatl.dll] [N/A, ]
[C:\WINDOWS\system32\tlatl.dll] [N/A, ]
[C:\WINDOWS\system32\qjatl.dll] [N/A, ]
[C:\WINDOWS\system32\myatl.dll] [N/A, ]
[C:\WINDOWS\system32\zhtuatl.dll] [N/A, ]
[D:\Program Files\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MSAPI Tcpip [TCP/IP]
C:\WINDOWS\system32\sqmapi32.dll(, N/A)
MSAPI Tcpip [TCP/IP]
C:\WINDOWS\system32\sqmapi32.dll(, N/A)
MSAPI Tcpip [UDP/IP]
C:\WINDOWS\system32\sqmapi32.dll(, N/A)
==================================
Autorun.inf
[C:\]
[AutoRun]
OPEN=SVCHOST.exe
shellexecute=SVCHOST.exe
shell\打开\command=SVCHOST.exe
[D:\]
[AutoRun]
OPEN=SVCHOST.exe
shellexecute=SVCHOST.exe
shell\打开\command=SVCHOST.exe
[E:\]
[AutoRun]
OPEN=SVCHOST.exe
shellexecute=SVCHOST.exe
shell\打开\command=SVCHOST.exe
[F:\]
[AutoRun]
OPEN=SVCHOST.exe
shellexecute=SVCHOST.exe
shell\打开\command=SVCHOST.exe
==================================
HOSTS 文件
N/A
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 2520, C:\PROGRAM FILES\SONY ERICSSON\MOBILE2\APPLICATION LAUNCHER\APPLICATION LAUNCHER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3008, C:\PROGRAM FILES\COMMON FILES\TELECA SHARED\CAPABILITYMANAGER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3976, C:\PROGRAM FILES\COMMON FILES\TELECA SHARED\GENERIC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 208, C:\PROGRAM FILES\SONY ERICSSON\MOBILE2\MOBILE PHONE MONITOR\EPMWORKER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3592, C:\PROGRAM FILES\TENCENT\QQ\TIMPLATFORM.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]