进程模块信息:
1 (安全进程):C:\WINDOWS\system32\smss.exe 命令行: \SystemRoot\System32\smss.exe
2 (安全进程):c:\WINDOWS\system32\csrss.exe 命令行: C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
3 (安全进程):c:\WINDOWS\system32\winlogon.exe 命令行: winlogon.exe
4 (安全进程):c:\WINDOWS\system32\services.exe 命令行: C:\WINDOWS\system32\services.exe
5 (安全进程):c:\WINDOWS\system32\lsass.exe 命令行: C:\WINDOWS\system32\lsass.exe
6 未知进程:c:\WINDOWS\system32\nvsvc32.exe 命令行: C:\WINDOWS\system32\nvsvc32.exe
7 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost -k DcomLaunch
8 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost -k rpcss
9 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\System32\svchost.exe -k netsvcs
10 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost.exe -k NetworkService
11 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost.exe -k LocalService
12 (安全进程):c:\WINDOWS\system32\spoolsv.exe 命令行: C:\WINDOWS\system32\spoolsv.exe
13 (安全进程):c:\WINDOWS\explorer.exe 命令行: C:\WINDOWS\Explorer.EXE
14 - 未知模块:c:\WINDOWS\system32\nvcpl.dll
15 - 未知模块:c:\WINDOWS\system32\nvrszhc.dll
16 - 未知模块:c:\WINDOWS\system32\SogouPy.ime
17 - 未知模块:c:\program files\sogouinput\4.2.3.2810\Resource.dll
18 (安全进程):c:\WINDOWS\vm303_sti.exe 命令行: "C:\WINDOWS\VM303_STI.EXE" VIMICRO USB PC Camera (ZC030X)
19 (安全进程):c:\WINDOWS\VMSnap3.exe 命令行: "C:\WINDOWS\VMSnap3.exe"
20 (安全进程):c:\WINDOWS\Domino.exe 命令行: "C:\WINDOWS\Domino.exe"
21 (安全进程):c:\WINDOWS\SOUNDMAN.EXE 命令行: "C:\WINDOWS\SOUNDMAN.EXE"
22 (安全进程):c:\program files\联想\联想标准功能键盘\skdaemond.exe 命令行: "C:\Program Files\联想\联想标准功能键盘\SkDaemond.exe"
23 (安全进程):c:\WINDOWS\system32\rundll32.exe 命令行: "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
24 - 未知模块:c:\WINDOWS\system32\nvmctray.dll
25 - 未知模块:c:\WINDOWS\system32\nvrszhc.dll
26 (安全进程):c:\WINDOWS\system32\ctfmon.exe 命令行: "C:\WINDOWS\system32\ctfmon.exe"
27 未知进程:c:\program files\duowan\yy\duospeak.exe 命令行: "C:\Program Files\duowan\yy\DuoSpeak.exe" -l
28 - 未知模块:c:\program files\duowan\yy\PUBFUNC.dll
29 - 未知模块:c:\program files\duowan\yy\LCtrl.dll
30 - 未知模块:c:\program files\duowan\yy\xgdi.dll
31 - 未知模块:c:\program files\duowan\yy\Timer.dll
32 - 未知模块:c:\program files\duowan\yy\XEditor.dll
33 - 未知模块:c:\program files\duowan\yy\XUUID.dll
34 - 未知模块:c:\program files\duowan\yy\audiocodec.dll
35 - 未知模块:c:\program files\duowan\yy\audio.dll
36 - 未知模块:c:\program files\duowan\yy\messagehistroy.dll
37 - 未知模块:c:\program files\duowan\yy\DB.dll
38 - 未知模块:c:\program files\duowan\yy\httpfileuploader.dll
39 - 未知模块:c:\program files\duowan\yy\layoutwrapper.dll
40 - 未知模块:c:\program files\duowan\yy\LayoutUI.dll
41 - 未知模块:c:\program files\duowan\yy\XML.dll
42 - 未知模块:c:\program files\duowan\yy\statistics.dll
43 - 未知模块:c:\program files\duowan\yy\audioengine.dll
44 - 未知模块:c:\program files\duowan\yy\lvdownloader.dll
45 - 未知模块:c:\program files\duowan\yy\advert.dll
46 - 未知模块:c:\program files\duowan\yy\Smile.dll
47 - 未知模块:c:\program files\duowan\yy\protocol.dll
48 - 未知模块:c:\program files\duowan\yy\keyhook.dll
49 - 未知模块:c:\WINDOWS\system32\QQPinyin.ime
50 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost.exe -k LocalService
51 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost.exe -k imgsvc
52 (安全进程):c:\WINDOWS\system32\alg.exe 命令行: C:\WINDOWS\System32\alg.exe
53 未知进程:c:\program files\Tencent\QQ\Bin\QQ.exe 命令行: "C:\Program Files\Tencent\QQ\Bin\QQ.exe"
54 - 未知模块:c:\program files\Tencent\QQ\Bin\Common.dll
55 - 未知模块:c:\program files\Tencent\QQ\Bin\kernelutil.dll
56 - 未知模块:c:\program files\Tencent\QQ\Bin\GF.dll
57 - 未知模块:c:\program files\Tencent\QQ\Bin\AppUtil.dll
58 - 未知模块:c:\program files\Tencent\QQ\Bin\mainframe.dll
59 - 未知模块:c:\program files\Tencent\QQ\Bin\msvcp60.dll
60 - 未知模块:c:\program files\Tencent\QQ\Bin\IM.dll
61 - 未知模块:c:\program files\common files\Tencent\TXSSO\Bin\ssoplatform.dll
62 - 未知模块:c:\program files\common files\Tencent\TXSSO\Bin\ssocommon.dll
63 - 未知模块:c:\program files\Tencent\QQ\Bin\basicctrldll.dll
64 - 未知模块:c:\program files\Tencent\QQ\Bin\txpfproxy.dll
65 - 未知模块:c:\program files\Tencent\QQ\Bin\TaskTray.dll
66 - 未知模块:c:\program files\Tencent\QQ\Bin\SkinMgr.dll
67 - 未知模块:c:\program files\Tencent\QQ\Bin\AppCtrl.dll
68 - 未知模块:c:\program files\Tencent\QQ\Bin\kernelmisc.dll
69 - 未知模块:c:\program files\Tencent\QQ\Bin\AppMisc.dll
70 - 未知模块:c:\program files\Tencent\QQ\Bin\qinterlive.dll
71 - 未知模块:c:\program files\Tencent\QQ\Bin\systemmsg.dll
72 - 未知模块:c:\program files\Tencent\QQ\Bin\chatframe.dll
73 - 未知模块:c:\program files\Tencent\QQ\Bin\GroupApp.dll
74 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.snsapp\bin\SNSApp.dll
75 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.paycenter\bin\paycenter.dll
76 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.qbar\bin\QBar.dll
77 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.qqvipmisc\bin\qqvipmisc.dll
78 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.wenwen\bin\WenWen.dll
79 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.soso\bin\Soso.dll
80 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.netbar\bin\NetBar.dll
81 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.paipai\bin\PaiPai.dll
82 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.wireless\bin\Wireless.dll
83 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.paipaigift\bin\paipaigift.dll
84 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.qqshow\Bin\QQShow.dll
85 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.qzone\bin\Qzone.dll
86 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.audiovideo\bin\audiovideo.dll
87 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.weather\bin\Weather.dll
88 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.vas\bin\VAS.dll
89 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.mmog\bin\MMOG.dll
90 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.qqgame\bin\QQGame.dll
91 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.qqlive\bin\QQLive.dll
92 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.qqmusic\bin\QQMusic.dll
93 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.qqpet\bin\QQPet.dll
94 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.taotao\bin\Taotao.dll
95 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.mail\bin\Mail.dll
96 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.crm\bin\CRM.dll
97 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.qqvip\bin\QQVip.dll
98 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.qqshow\Bin\flashavatardll.dll
99 - 未知模块:c:\WINDOWS\system32\Macromed\Flash\Flash10c.ocx
100 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.memo\bin\Memo.dll
101 - 未知模块:c:\program files\Tencent\QQ\Bin\informationbox.dll
102 - 未知模块:c:\program files\Tencent\QQ\Bin\contactinfoframe.dll
103 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.filetransfer\bin\filetransfer.dll
104 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.advertisement\bin\advertisement.dll
105 - 未知模块:c:\program files\Tencent\QQ\Bin\vqqsdl.dll
106 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.today\bin\Today.dll
107 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.qqring\bin\QQRing.dll
108 - 未知模块:c:\program files\Tencent\QQ\Plugin\com.tencent.qqwebsite\bin\qqwebsite.dll
109 - 未知模块:c:\documents and settings\administrator\application data\Tencent\QQ\SafeBase\tseh.dat
110 未知进程:c:\program files\Tencent\QQ\Bin\txplatform.exe 命令行: "C:\Program Files\Tencent\QQ\Bin\TXPlatform.exe" -Embedding
111 - 未知模块:c:\program files\Tencent\QQ\Bin\txpfproxy.dll
112 未知进程:c:\ftc2009\ftcleaner.exe 命令行: "C:\ftc2009\FTCleaner.exe"
113 (安全进程):c:\ftc2009\fyganalyze.exe 命令行: C:\ftc2009\FygAnalyze.exe
启动信息:
114 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<RTHDCPL><RTHDCPL.EXE>
115 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<BigDog303><C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC030X)>
116 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<amd_dc_opt><C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe>
117 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<VMSnap3><C:\WINDOWS\VMSnap3.exe>
118 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Domino><C:\WINDOWS\Domino.exe>
119 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<SoundMan><SOUNDMAN.EXE>
120 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<联想标准功能键盘 Ver1.0.0.4><C:\Program Files\联想\联想标准功能键盘\SkDaemond.exe>
121 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<XLSoftmgrTray><C:\Program Files\Thunder Network\SoftManager\Program\XLSoftmgrTray.exe /sysstart>