瑞星卡卡安全论坛

首页 » 技术交流区 » 系统软件 » 请高手帮我看看附件中进程哪个是监控的?谢谢!
fengzhejun - 2006-3-14 8:28:00
公司装了监控想知道是哪个,麻烦高手了!多谢了!
[smss.exe]
PID = 0x1c8
CommandLine =
    smss.exe
    0x48580000
    C:\WINDOWS\system32\smss.exe
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Windows NT Session Manager
    2003-03-15 08:00:00

    ntdll.dll
    0x77f50000
    C:\WINDOWS\system32\ntdll.dll
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    NT Layer DLL
    2003-03-15 08:00:00




[csrss.exe]
PID = 0x208
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
    csrss.exe
    0x4a680000
    c:\windows\system32\csrss.exe
    5.1.2600.0 (xpclient.010817-1148)
    Microsoft Corporation
    Client Server Runtime Process
    2003-03-15 08:00:00

    ntdll.dll
    0x77f50000
    C:\WINDOWS\system32\ntdll.dll
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    NT Layer DLL
    2003-03-15 08:00:00

    CSRSRV.dll
    0x75aa0000
    C:\WINDOWS\system32\csrsrv.dll
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Client Server Runtime Process
    2003-03-15 08:00:00

    basesrv.dll
    0x75ab0000
    C:\WINDOWS\system32\basesrv.dll
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Windows NT BASE API Server DLL
    2003-03-15 08:00:00

    winsrv.dll
    0x75ac0000
    C:\WINDOWS\system32\winsrv.dll
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Windows Server DLL
    2003-03-15 08:00:00

    USER32.dll
    0x77d10000
    C:\WINDOWS\system32\user32.dll
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Windows XP USER API Client DLL
    2003-03-15 08:00:00

    KERNEL32.dll
    0x77e40000
    C:\WINDOWS\system32\kernel32.dll
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Windows NT BASE API Client DLL
    2003-03-15 08:00:00

    GDI32.dll
    0x77c40000
    C:\WINDOWS\system32\gdi32.dll
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    GDI Client DLL
    2003-03-15 08:00:00

    ADVAPI32.dll
    0x77da0000
    C:\WINDOWS\system32\advapi32.dll
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Advanced Windows 32 Base API
    2003-03-15 08:00:00

    RPCRT4.dll
    0x78000000
    C:\WINDOWS\system32\rpcrt4.dll
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Remote Procedure Call Runtime
    2003-03-15 08:00:00

    LPK.DLL
    0x62c20000
    C:\WINDOWS\system32\lpk.dll
    5.1.2600.0 (xpclient.010817-1148)
    Microsoft Corporation
    Language Pack
    2003-03-15 08:00:00

    USP10.dll
    0x72f10000
    C:\WINDOWS\system32\usp10.dll
    1.0409.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Uniscribe Unicode script processor
    2003-03-15 08:00:00

    sxs.dll
    0x75e00000
    C:\WINDOWS\system32\sxs.dll
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Fusion 2.5
    2003-03-15 08:00:00
fengzhejun - 2006-3-14 8:29:00
【回复“fengzhejun”的帖子】

Interceptor.dll
0x2db0000
C:\WINDOWS\system32\Interceptor.dll
1, 0, 0, 29
Tenebril Inc.
API Interceptor
2005-10-25 12:49:18

InterceptHelper.dll
0x10000000
C:\WINDOWS\system32\InterceptHelper.dll
1, 0, 0, 29
Tenebril Inc.
Interception Helper
2005-10-25 12:49:14

MSVCP71.dll
0x7c3a0000
C:\WINDOWS\system32\msvcp71.dll
7.10.3077.0
Microsoft Corporation
Microsoft? C++ Runtime Library
2003-03-18 22:14:52

MSVCR71.dll
0x7c340000
C:\WINDOWS\system32\msvcr71.dll
7.10.3052.4
Microsoft Corporation
Microsoft? C Runtime Library
2003-02-21 04:42:22

SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\shlwapi.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2003-03-15 08:00:00

msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2003-03-15 08:00:00

VERSION.dll
0x77bd0000
C:\WINDOWS\system32\version.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Version Checking and File Installation Libraries
2003-03-15 08:00:00




[winlogon.exe]
PID = 0x220
CommandLine = winlogon.exe
winlogon.exe
0x1000000
c:\windows\system32\winlogon.exe
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT Logon Application
2003-03-15 08:00:00

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
NT Layer DLL
2003-03-15 08:00:00

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2003-03-15 08:00:00

msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2003-03-15 08:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2003-03-15 08:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Procedure Call Runtime
2003-03-15 08:00:00

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2003-03-15 08:00:00

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP USER API Client DLL
2003-03-15 08:00:00

USERENV.dll
0x759d0000
C:\WINDOWS\system32\userenv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Userenv
2003-03-15 08:00:00

NDdeApi.dll
0x758a0000
C:\WINDOWS\system32\nddeapi.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Network DDE Share Management APIs
2003-03-15 08:00:00

CRYPT32.dll
0x76230000
C:\WINDOWS\system32\crypt32.dll
5.131.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Crypto API32
2003-03-15 08:00:00

MSASN1.dll
0x76210000
C:\WINDOWS\system32\msasn1.dll
5.1.2600.0 (XPClient.010817-1148)
Microsoft Corporation
ASN.1 Runtime APIs
2003-03-15 08:00:00

Secur32.dll
0x76f60000
C:\WINDOWS\system32\secur32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Security Support Provider Interface
2003-03-15 08:00:00

WINSTA.dll
0x762d0000
C:\WINDOWS\system32\winsta.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Winstation Library
2003-03-15 08:00:00

PROFMAP.dll
0x75890000
C:\WINDOWS\system32\profmap.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Userenv
2003-03-15 08:00:00

NETAPI32.dll
0x71ba0000
C:\WINDOWS\system32\netapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Net Win32 API DLL
2003-03-15 08:00:00

REGAPI.dll
0x76b90000
C:\WINDOWS\system32\regapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Registry Configuration APIs
2003-03-15 08:00:00

WS2_32.dll
0x71a20000
C:\WINDOWS\system32\ws2_32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 32-Bit DLL
2003-03-15 08:00:00

WS2HELP.dll
0x71a10000
C:\WINDOWS\system32\ws2help.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 Helper for Windows NT
2003-03-15 08:00:00

AUTHZ.dll
0x76c90000
C:\WINDOWS\system32\authz.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Authorization Framework
2003-03-15 08:00:00

PSAPI.DLL
0x76bc0000
C:\WINDOWS\system32\psapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Process Status Helper
2003-03-15 08:00:00

VERSION.dll
0x77bd0000
C:\WINDOWS\system32\version.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Version Checking and File Installation Libraries
2003-03-15 08:00:00

SETUPAPI.dll
0x765e0000
C:\WINDOWS\system32\setupapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Setup API
2003-03-15 08:00:00
fengzhejun - 2006-3-14 8:30:00


IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2003-03-15 08:00:00

LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2003-03-15 08:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2003-03-15 08:00:00

interceptor.dll
0xd50000
C:\WINDOWS\system32\interceptor.dll
1, 0, 0, 29
Tenebril Inc.
API Interceptor
2005-10-25 12:49:18

InterceptHelper.dll
0x10000000
C:\WINDOWS\system32\InterceptHelper.dll
1, 0, 0, 29
Tenebril Inc.
Interception Helper
2005-10-25 12:49:14

MSVCP71.dll
0x7c3a0000
C:\WINDOWS\system32\msvcp71.dll
7.10.3077.0
Microsoft Corporation
Microsoft? C++ Runtime Library
2003-03-18 22:14:52

MSVCR71.dll
0x7c340000
C:\WINDOWS\system32\msvcr71.dll
7.10.3052.4
Microsoft Corporation
Microsoft? C Runtime Library
2003-02-21 04:42:22

SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\shlwapi.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2003-03-15 08:00:00

MSGINA.dll
0x758d0000
C:\WINDOWS\system32\msgina.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT Logon GINA DLL
2003-03-15 08:00:00

SHELL32.dll
0x773a0000
C:\WINDOWS\system32\shell32.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Shell Common Dll
2003-03-15 08:00:00

COMCTL32.dll
0x77310000
C:\WINDOWS\system32\comctl32.dll
5.82 (xpsp1.020828-1920)
Microsoft Corporation
Common Controls Library
2003-03-15 08:00:00

ODBC32.dll
0x1f7b0000
C:\WINDOWS\system32\odbc32.dll
3.520.9030.0
Microsoft Corporation
Microsoft Data Access - ODBC Driver Manager
2003-03-15 08:00:00

comdlg32.dll
0x76320000
C:\WINDOWS\system32\comdlg32.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Common Dialogs DLL
2003-03-15 08:00:00

comctl32.dll
0x78090000
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
6.0 (xpsp1.020828-1920)
Microsoft Corporation
User Experience Controls Library
2003-03-15 08:00:00

odbcint.dll
0x1f850000
C:\WINDOWS\system32\odbcint.dll
3.520.7713.0
Microsoft Corporation
Microsoft Data Access - ODBC Resources
2003-03-15 08:00:00

SHSVCS.dll
0x76ba0000
C:\WINDOWS\system32\shsvcs.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Shell Services Dll
2003-03-15 08:00:00

sfc.dll
0x76b80000
C:\WINDOWS\system32\sfc.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows File Protection
2003-03-15 08:00:00

sfc_os.dll
0x76c30000
C:\WINDOWS\system32\sfc_os.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows 文件保护
2003-03-15 08:00:00

WINTRUST.dll
0x76c00000
C:\WINDOWS\system32\wintrust.dll
5.131.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Trust Verification APIs
2003-03-15 08:00:00

ole32.dll
0xae0000
C:\WINDOWS\system32\ole32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft OLE for Windows
2003-03-15 08:00:00

IMAGEHLP.dll
0x76c60000
C:\WINDOWS\system32\imagehlp.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT Image Helper
2003-03-15 08:00:00

msctfime.ime
0xf60000
C:\WINDOWS\system32\MSCTFIME.IME
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft Text Frame Work Service IME
2003-03-15 08:00:00

WINSCARD.DLL
0x72360000
C:\WINDOWS\system32\winscard.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Smart Card API
2003-03-15 08:00:00

WTSAPI32.dll
0x76f20000
C:\WINDOWS\system32\wtsapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Terminal Server SDK APIs
2003-03-15 08:00:00

sxs.dll
0x75e00000
C:\WINDOWS\system32\sxs.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Fusion 2.5
2003-03-15 08:00:00

uxtheme.dll
0x5adc0000
C:\WINDOWS\system32\uxtheme.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft UxTheme Library
2003-03-15 08:00:00

WINMM.dll
0x76b10000
C:\WINDOWS\system32\winmm.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
MCI API DLL
2003-03-15 08:00:00

cscdll.dll
0x76570000
C:\WINDOWS\system32\cscdll.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Offline Network Agent
2003-03-15 08:00:00

WlNotify.dll
0x758b0000
C:\WINDOWS\system32\wlnotify.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Common DLL to receive Winlogon notifications
2003-03-15 08:00:00

WINSPOOL.DRV
0x72f70000
C:\WINDOWS\system32\winspool.drv
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Spooler Driver
2003-03-15 08:00:00

MPR.dll
0x71a90000
C:\WINDOWS\system32\mpr.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Multiple Provider Router DLL
2003-03-15 08:00:00

rsaenh.dll
0xffd0000
C:\WINDOWS\system32\rsaenh.dll
5.1.2600.1029 (xpsp1.020426-1800)
Microsoft Corporation
Microsoft Base Cryptographic Provider
2003-03-15 08:00:00

SAMLIB.dll
0x71b70000
C:\WINDOWS\system32\samlib.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
SAM Library DLL
2003-03-15 08:00:00

msv1_0.dll
0x76ce0000
C:\WINDOWS\system32\msv1_0.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft Authentication Package v1.0
2003-03-15 08:00:00

wldap32.dll
0x76f30000
C:\WINDOWS\system32\wldap32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Win32 LDAP API DLL
2003-03-15 08:00:00

WinWdg32.dll
0x14f0000
C:\WINDOWS\system32\WinWdg32.dll
2, 84, 2207, 0

WinWdg32 DLL
2000-01-10 20:00:00

winhafn.dll
0xff0000
C:\WINDOWS\system32\winhafn.dll



2005-09-21 12:51:12

winhason.dll
0x1460000
C:\WINDOWS\system32\winhason.dll



2005-09-15 16:59:54

WSOCK32.dll
0x71a40000
C:\WINDOWS\system32\wsock32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 32-Bit DLL
2003-03-15 08:00:00

MFC42.DLL
0x73d30000
C:\WINDOWS\system32\mfc42.dll
6.00.8665.0
Microsoft Corporation
MFCDLL Shared Library - Retail Version
2003-03-15 08:00:00

MFC42LOC.DLL
0x61be0000
C:\WINDOWS\system32\mfc42loc.dll
6.00.8665.0
Microsoft Corporation
MFC Language Specific Resources
2003-03-15 08:00:00

winhashn.dll
0x1510000
C:\WINDOWS\system32\winhashn.dll



2005-09-05 16:39:10

thooks.dll
0x1520000
C:\WINDOWS\system32\THooks.dll
2, 84, 2207, 0

THooks
2000-01-10 20:00:00

cscui.dll
0x76590000
C:\WINDOWS\system32\cscui.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Client Side Caching UI
2003-03-15 08:00:00

MPRAPI.dll
0x76d10000
C:\WINDOWS\system32\mprapi.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows NT MP Router Administration DLL
2003-03-15 08:00:00

ACTIVEDS.dll
0x76e10000
C:\WINDOWS\system32\activeds.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
ADs Router Layer DLL
2003-03-15 08:00:00

adsldpc.dll
0x76de0000
C:\WINDOWS\system32\adsldpc.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
ADs LDAP Provider C DLL
2003-03-15 08:00:00

ATL.DLL
0x76af0000
C:\WINDOWS\system32\atl.dll
3.00.9435
Microsoft Corporation
ATL Module for Windows NT (Unicode)
2003-03-15 08:00:00

OLEAUT32.dll
0x770f0000
C:\WINDOWS\system32\oleaut32.dll
3.50.5016.0
Microsoft Corporation
Microsoft OLE 3.50  for Windows NT(TM) and Windows 95(TM) Operating Systems
2003-03-15 08:00:00

rtutils.dll
0x76e50000
C:\WINDOWS\system32\rtutils.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Routing Utilities
2003-03-15 08:00:00

COMRes.dll
0x77020000
C:\WINDOWS\system32\comres.dll
2001.12.4414.42
Microsoft Corporation

2003-03-15 08:00:00

CLBCATQ.DLL
0x76fa0000
C:\WINDOWS\system32\clbcatq.dll
2001.12.4414.42
Microsoft Corporation

2003-03-15 08:00:00

NTMARTA.DLL
0x76cb0000
C:\WINDOWS\system32\ntmarta.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT MARTA provider
2003-03-15 08:00:00




[services.exe]
PID = 0x254
CommandLine = C:\WINDOWS\system32\services.exe
services.exe
0x1000000
C:\WINDOWS\system32\services.exe
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Services and Controller app
2003-03-15 08:00:00

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
NT Layer DLL
2003-03-15 08:00:00

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2003-03-15 08:00:00

msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2003-03-15 08:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2003-03-15 08:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Procedure Call Runtime
2003-03-15 08:00:00

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP USER API Client DLL
2003-03-15 08:00:00

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2003-03-15 08:00:00

USERENV.dll
0x759d0000
C:\WINDOWS\system32\userenv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Userenv
2003-03-15 08:00:00
fengzhejun - 2006-3-14 8:34:00


SCESRV.dll
0x75840000
C:\WINDOWS\system32\scesrv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Security Configuration Editor Engine
2003-03-15 08:00:00

AUTHZ.dll
0x76c90000
C:\WINDOWS\system32\authz.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Authorization Framework
2003-03-15 08:00:00

umpnpmgr.dll
0x75820000
C:\WINDOWS\system32\umpnpmgr.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
User-mode Plug-and-Play Service
2003-03-15 08:00:00

WINSTA.dll
0x762d0000
C:\WINDOWS\system32\winsta.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Winstation Library
2003-03-15 08:00:00

NCObjAPI.DLL
0x5f9a0000
C:\WINDOWS\system32\ncobjapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation

2003-03-15 08:00:00

IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2003-03-15 08:00:00

LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2003-03-15 08:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2003-03-15 08:00:00

interceptor.dll
0xd50000
C:\WINDOWS\system32\interceptor.dll
1, 0, 0, 29
Tenebril Inc.
API Interceptor
2005-10-25 12:49:18

InterceptHelper.dll
0x10000000
C:\WINDOWS\system32\InterceptHelper.dll
1, 0, 0, 29
Tenebril Inc.
Interception Helper
2005-10-25 12:49:14

MSVCP71.dll
0x7c3a0000
C:\WINDOWS\system32\msvcp71.dll
7.10.3077.0
Microsoft Corporation
Microsoft? C++ Runtime Library
2003-03-18 22:14:52

MSVCR71.dll
0x7c340000
C:\WINDOWS\system32\msvcr71.dll
7.10.3052.4
Microsoft Corporation
Microsoft? C Runtime Library
2003-02-21 04:42:22

SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\shlwapi.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2003-03-15 08:00:00

VERSION.dll
0x77bd0000
C:\WINDOWS\system32\version.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Version Checking and File Installation Libraries
2003-03-15 08:00:00

secur32.dll
0x76f60000
C:\WINDOWS\system32\secur32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Security Support Provider Interface
2003-03-15 08:00:00

eventlog.dll
0x75800000
C:\WINDOWS\system32\eventlog.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Event Logging Service
2003-03-15 08:00:00

WS2_32.dll
0x71a20000
C:\WINDOWS\system32\ws2_32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 32-Bit DLL
2003-03-15 08:00:00

WS2HELP.dll
0x71a10000
C:\WINDOWS\system32\ws2help.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 Helper for Windows NT
2003-03-15 08:00:00

PSAPI.DLL
0x76bc0000
C:\WINDOWS\system32\psapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Process Status Helper
2003-03-15 08:00:00

wtsapi32.dll
0x76f20000
C:\WINDOWS\system32\wtsapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Terminal Server SDK APIs
2003-03-15 08:00:00

netapi32.dll
0x71ba0000
C:\WINDOWS\system32\netapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Net Win32 API DLL
2003-03-15 08:00:00




[lsass.exe]
PID = 0x260
CommandLine = C:\WINDOWS\system32\lsass.exe
lsass.exe
0x1000000
C:\WINDOWS\system32\lsass.exe
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
LSA Shell (Export Version)
2003-03-15 08:00:00

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
NT Layer DLL
2003-03-15 08:00:00

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2003-03-15 08:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2003-03-15 08:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Procedure Call Runtime
2003-03-15 08:00:00

LSASRV.dll
0x74480000
C:\WINDOWS\system32\lsasrv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
LSA Server DLL
2003-03-15 08:00:00

msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2003-03-15 08:00:00

Secur32.dll
0x76f60000
C:\WINDOWS\system32\secur32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Security Support Provider Interface
2003-03-15 08:00:00

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP USER API Client DLL
2003-03-15 08:00:00

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2003-03-15 08:00:00

SAMSRV.dll
0x743a0000
C:\WINDOWS\system32\samsrv.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
SAM Server DLL
2003-03-15 08:00:00

cryptdll.dll
0x76760000
C:\WINDOWS\system32\cryptdll.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Cryptography Manager
2003-03-15 08:00:00

DNSAPI.dll
0x76ef0000
C:\WINDOWS\system32\dnsapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
DNS Client API DLL
2003-03-15 08:00:00

WS2_32.dll
0x71a20000
C:\WINDOWS\system32\ws2_32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 32-Bit DLL
2003-03-15 08:00:00

WS2HELP.dll
0x71a10000
C:\WINDOWS\system32\ws2help.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 Helper for Windows NT
2003-03-15 08:00:00

MSASN1.dll
0x76210000
C:\WINDOWS\system32\msasn1.dll
5.1.2600.0 (XPClient.010817-1148)
Microsoft Corporation
ASN.1 Runtime APIs
2003-03-15 08:00:00

NETAPI32.dll
0x71ba0000
C:\WINDOWS\system32\netapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Net Win32 API DLL
2003-03-15 08:00:00

SAMLIB.dll
0x71b70000
C:\WINDOWS\system32\samlib.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
SAM Library DLL
2003-03-15 08:00:00

MPR.dll
0x71a90000
C:\WINDOWS\system32\mpr.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Multiple Provider Router DLL
2003-03-15 08:00:00

NTDSAPI.dll
0x76770000
C:\WINDOWS\system32\ntdsapi.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
NT5DS
2003-03-15 08:00:00

WLDAP32.dll
0x76f30000
C:\WINDOWS\system32\wldap32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Win32 LDAP API DLL
2003-03-15 08:00:00

IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2003-03-15 08:00:00

LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2003-03-15 08:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2003-03-15 08:00:00

interceptor.dll
0xd50000
C:\WINDOWS\system32\interceptor.dll
1, 0, 0, 29
Tenebril Inc.
API Interceptor
2005-10-25 12:49:18

InterceptHelper.dll
0x10000000
C:\WINDOWS\system32\InterceptHelper.dll
1, 0, 0, 29
Tenebril Inc.
Interception Helper
2005-10-25 12:49:14

MSVCP71.dll
0x7c3a0000
C:\WINDOWS\system32\msvcp71.dll
7.10.3077.0
Microsoft Corporation
Microsoft? C++ Runtime Library
2003-03-18 22:14:52

MSVCR71.dll
0x7c340000
C:\WINDOWS\system32\msvcr71.dll
7.10.3052.4
Microsoft Corporation
Microsoft? C Runtime Library
2003-02-21 04:42:22
fengzhejun - 2006-3-14 8:35:00


SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\shlwapi.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2003-03-15 08:00:00

VERSION.dll
0x77bd0000
C:\WINDOWS\system32\version.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Version Checking and File Installation Libraries
2003-03-15 08:00:00

msprivs.dll
0x74310000
C:\WINDOWS\system32\msprivs.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Privilege Translations
2003-03-15 08:00:00

kerberos.dll
0x71c70000
C:\WINDOWS\system32\kerberos.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Kerberos Security Package
2003-03-15 08:00:00

msv1_0.dll
0x76ce0000
C:\WINDOWS\system32\msv1_0.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft Authentication Package v1.0
2003-03-15 08:00:00

netlogon.dll
0x74410000
C:\WINDOWS\system32\netlogon.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Net Logon Services DLL
2003-03-15 08:00:00

w32time.dll
0x76790000
C:\WINDOWS\system32\w32time.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Time Service
2003-03-15 08:00:00

MSVCP60.dll
0x75ff0000
C:\WINDOWS\system32\msvcp60.dll
6.00.8972.0
Microsoft Corporation
Microsoft (R) C++ Runtime Library
2003-03-15 08:00:00

iphlpapi.dll
0x76d30000
C:\WINDOWS\system32\iphlpapi.dll
5.1.2600.2 (xpsp1.020828-1920)
Microsoft Corporation
IP Helper API
2003-03-15 08:00:00

USERENV.dll
0x759d0000
C:\WINDOWS\system32\userenv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Userenv
2003-03-15 08:00:00

schannel.dll
0x767c0000
C:\WINDOWS\system32\schannel.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
TLS / SSL Security Provider
2003-03-15 08:00:00

CRYPT32.dll
0x76230000
C:\WINDOWS\system32\crypt32.dll
5.131.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Crypto API32
2003-03-15 08:00:00

wdigest.dll
0x742e0000
C:\WINDOWS\system32\wdigest.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Digest Access
2003-03-15 08:00:00

rsaenh.dll
0xffd0000
C:\WINDOWS\system32\rsaenh.dll
5.1.2600.1029 (xpsp1.020426-1800)
Microsoft Corporation
Microsoft Base Cryptographic Provider
2003-03-15 08:00:00

setupapi.dll
0x765e0000
C:\WINDOWS\system32\setupapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Setup API
2003-03-15 08:00:00

scecli.dll
0x74370000
C:\WINDOWS\system32\scecli.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Security Configuration Editor Client Engine
2003-03-15 08:00:00

OLEAUT32.dll
0x770f0000
C:\WINDOWS\system32\oleaut32.dll
3.50.5016.0
Microsoft Corporation
Microsoft OLE 3.50  for Windows NT(TM) and Windows 95(TM) Operating Systems
2003-03-15 08:00:00

OLE32.DLL
0xd80000
C:\WINDOWS\system32\ole32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft OLE for Windows
2003-03-15 08:00:00

shell32.dll
0x773a0000
C:\WINDOWS\system32\shell32.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Shell Common Dll
2003-03-15 08:00:00

comctl32.dll
0x78090000
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
6.0 (xpsp1.020828-1920)
Microsoft Corporation
User Experience Controls Library
2003-03-15 08:00:00

comctl32.dll
0x77310000
C:\WINDOWS\system32\comctl32.dll
5.82 (xpsp1.020828-1920)
Microsoft Corporation
Common Controls Library
2003-03-15 08:00:00

ipsecsvc.dll
0x74340000
C:\WINDOWS\system32\ipsecsvc.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows IPSec SPD Server DLL
2003-03-15 08:00:00

oakley.DLL
0x74530000
C:\WINDOWS\system32\oakley.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Oakley Key Manager
2003-03-15 08:00:00

WINIPSEC.DLL
0x742d0000
C:\WINDOWS\system32\winipsec.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows IPSec SPD Client DLL
2003-03-15 08:00:00

pstorsvc.dll
0x74300000
C:\WINDOWS\system32\pstorsvc.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Protected storage server
2003-03-15 08:00:00

mswsock.dll
0x719c0000
C:\WINDOWS\system32\mswsock.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Windows Sockets 2.0 Service Provider
2003-03-15 08:00:00

psbase.dll
0x74320000
C:\WINDOWS\system32\psbase.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Protected Storage default provider
2003-03-15 08:00:00

wshtcpip.dll
0x71a00000
C:\WINDOWS\system32\wshtcpip.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Sockets Helper DLL
2003-03-15 08:00:00

dssenh.dll
0xffa0000
C:\WINDOWS\system32\dssenh.dll
5.1.2600.1029 (xpsp1.020426-1800)
Microsoft Corporation
Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider
2003-03-15 08:00:00




[svchost.exe]
PID = 0x328
CommandLine = C:\WINDOWS\system32\svchost -k rpcss
svchost.exe
0x1000000
C:\WINDOWS\system32\svchost.exe
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Generic Host Process for Win32 Services
2003-03-15 08:00:00

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
NT Layer DLL
2003-03-15 08:00:00

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2003-03-15 08:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2003-03-15 08:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Procedure Call Runtime
2003-03-15 08:00:00

interceptor.dll
0xd50000
C:\WINDOWS\system32\interceptor.dll
1, 0, 0, 29
Tenebril Inc.
API Interceptor
2005-10-25 12:49:18

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP USER API Client DLL
2003-03-15 08:00:00

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2003-03-15 08:00:00

IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2003-03-15 08:00:00

LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2003-03-15 08:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2003-03-15 08:00:00

InterceptHelper.dll
0x10000000
C:\WINDOWS\system32\InterceptHelper.dll
1, 0, 0, 29
Tenebril Inc.
Interception Helper
2005-10-25 12:49:14

MSVCP71.dll
0x7c3a0000
C:\WINDOWS\system32\msvcp71.dll
7.10.3077.0
Microsoft Corporation
Microsoft? C++ Runtime Library
2003-03-18 22:14:52

MSVCR71.dll
0x7c340000
C:\WINDOWS\system32\msvcr71.dll
7.10.3052.4
Microsoft Corporation
Microsoft? C Runtime Library
2003-02-21 04:42:22

SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\shlwapi.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2003-03-15 08:00:00

msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2003-03-15 08:00:00

VERSION.dll
0x77bd0000
C:\WINDOWS\system32\version.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Version Checking and File Installation Libraries
2003-03-15 08:00:00

rpcss.dll
0x757b0000
c:\WINDOWS\system32\rpcss.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Distributed COM Services
2003-03-15 08:00:00

WS2_32.dll
0x71a20000
c:\WINDOWS\system32\ws2_32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 32-Bit DLL
2003-03-15 08:00:00

WS2HELP.dll
0x71a10000
c:\WINDOWS\system32\ws2help.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 Helper for Windows NT
2003-03-15 08:00:00

Secur32.dll
0x76f60000
c:\WINDOWS\system32\secur32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Security Support Provider Interface
2003-03-15 08:00:00

userenv.dll
0x759d0000
C:\WINDOWS\system32\userenv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Userenv
2003-03-15 08:00:00

mswsock.dll
0x719c0000
C:\WINDOWS\system32\mswsock.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Windows Sockets 2.0 Service Provider
2003-03-15 08:00:00

wshtcpip.dll
0x71a00000
C:\WINDOWS\system32\wshtcpip.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Sockets Helper DLL
2003-03-15 08:00:00

cdnns.dll
0x720000
C:\WINDOWS\system32\cdnns.dll
2, 0, 0, 0
CNNIC
cdnns
2005-06-14 17:07:48

Rnr20.dll
0x723e0000
C:\WINDOWS\system32\rnr20.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket2 NameSpace DLL
2003-03-15 08:00:00

DNSAPI.dll
0x76ef0000
C:\WINDOWS\system32\dnsapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
DNS Client API DLL
2003-03-15 08:00:00
fengzhejun - 2006-3-14 8:36:00


iphlpapi.dll
0x76d30000
C:\WINDOWS\system32\iphlpapi.dll
5.1.2600.2 (xpsp1.020828-1920)
Microsoft Corporation
IP Helper API
2003-03-15 08:00:00

winrnr.dll
0x76f80000
C:\WINDOWS\system32\winrnr.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
LDAP RnR Provider DLL
2003-03-15 08:00:00

WLDAP32.dll
0x76f30000
C:\WINDOWS\system32\wldap32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Win32 LDAP API DLL
2003-03-15 08:00:00

rasadhlp.dll
0x76f90000
C:\WINDOWS\system32\rasadhlp.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Remote Access AutoDial Helper
2003-03-15 08:00:00

CLBCATQ.DLL
0x76fa0000
C:\WINDOWS\system32\clbcatq.dll
2001.12.4414.42
Microsoft Corporation

2003-03-15 08:00:00

ole32.dll
0x8b0000
C:\WINDOWS\system32\ole32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft OLE for Windows
2003-03-15 08:00:00

OLEAUT32.dll
0x770f0000
C:\WINDOWS\system32\oleaut32.dll
3.50.5016.0
Microsoft Corporation
Microsoft OLE 3.50  for Windows NT(TM) and Windows 95(TM) Operating Systems
2003-03-15 08:00:00

COMRes.dll
0x77020000
C:\WINDOWS\system32\comres.dll
2001.12.4414.42
Microsoft Corporation

2003-03-15 08:00:00

MFC42.DLL
0x73d30000
C:\WINDOWS\system32\mfc42.dll
6.00.8665.0
Microsoft Corporation
MFCDLL Shared Library - Retail Version
2003-03-15 08:00:00

MFC42LOC.DLL
0x61be0000
C:\WINDOWS\system32\mfc42loc.dll
6.00.8665.0
Microsoft Corporation
MFC Language Specific Resources
2003-03-15 08:00:00

comctl32.dll
0x78090000
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
6.0 (xpsp1.020828-1920)
Microsoft Corporation
User Experience Controls Library
2003-03-15 08:00:00

comctl32.dll
0x77310000
C:\WINDOWS\system32\comctl32.dll
5.82 (xpsp1.020828-1920)
Microsoft Corporation
Common Controls Library
2003-03-15 08:00:00

oblknet.dll
0xc00000
C:\WINDOWS\system32\oblknet.dll
2, 82, 415, 0

oblknet
2005-09-21 21:39:08

ippcap.dll
0xc10000
C:\WINDOWS\system32\ippcap.dll
3, 0, 0, 18
Politecnico di Torino
wpcap - Based on libpcap 0.7 snapshot feb 03, 2003
2004-06-27 17:10:36

IPpacket.dll
0xc50000
C:\WINDOWS\system32\ippacket.dll
3, 0, 0, 20
Politecnico di Torino
IPPack
2004-06-27 17:10:36

WSOCK32.dll
0x71a40000
C:\WINDOWS\system32\wsock32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 32-Bit DLL
2003-03-15 08:00:00




[CCenter.exe]
PID = 0x360
CommandLine = "C:\Program Files\Rising\Rav\CCenter.exe"
CCenter.exe
0x400000
C:\Program Files\Rising\Rav\CCenter.exe
18, 0, 0, 3
Beijing Rising Technology Co., Ltd.
CCenter
2006-01-19 14:49:06

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
NT Layer DLL
2003-03-15 08:00:00

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2003-03-15 08:00:00

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP USER API Client DLL
2003-03-15 08:00:00

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2003-03-15 08:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2003-03-15 08:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Procedure Call Runtime
2003-03-15 08:00:00

IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2003-03-15 08:00:00

LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2003-03-15 08:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2003-03-15 08:00:00

interceptor.dll
0xd50000
C:\WINDOWS\system32\interceptor.dll
1, 0, 0, 29
Tenebril Inc.
API Interceptor
2005-10-25 12:49:18

InterceptHelper.dll
0x10000000
C:\WINDOWS\system32\InterceptHelper.dll
1, 0, 0, 29
Tenebril Inc.
Interception Helper
2005-10-25 12:49:14
fengzhejun - 2006-3-14 8:36:00


MSVCP71.dll
0x7c3a0000
C:\WINDOWS\system32\msvcp71.dll
7.10.3077.0
Microsoft Corporation
Microsoft? C++ Runtime Library
2003-03-18 22:14:52

MSVCR71.dll
0x7c340000
C:\WINDOWS\system32\msvcr71.dll
7.10.3052.4
Microsoft Corporation
Microsoft? C Runtime Library
2003-02-21 04:42:22

SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\shlwapi.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2003-03-15 08:00:00

msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2003-03-15 08:00:00

VERSION.dll
0x77bd0000
C:\WINDOWS\system32\version.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Version Checking and File Installation Libraries
2003-03-15 08:00:00

uxtheme.dll
0x5adc0000
C:\WINDOWS\system32\uxtheme.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft UxTheme Library
2003-03-15 08:00:00




[svchost.exe]
PID = 0x378
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
0x1000000
C:\WINDOWS\system32\svchost.exe
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Generic Host Process for Win32 Services
2003-03-15 08:00:00

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
NT Layer DLL
2003-03-15 08:00:00

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2003-03-15 08:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2003-03-15 08:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Procedure Call Runtime
2003-03-15 08:00:00

interceptor.dll
0xd50000
C:\WINDOWS\system32\interceptor.dll
1, 0, 0, 29
Tenebril Inc.
API Interceptor
2005-10-25 12:49:18

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP USER API Client DLL
2003-03-15 08:00:00

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2003-03-15 08:00:00

IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2003-03-15 08:00:00

LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2003-03-15 08:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2003-03-15 08:00:00

InterceptHelper.dll
0x10000000
C:\WINDOWS\system32\InterceptHelper.dll
1, 0, 0, 29
Tenebril Inc.
Interception Helper
2005-10-25 12:49:14

MSVCP71.dll
0x7c3a0000
C:\WINDOWS\system32\msvcp71.dll
7.10.3077.0
Microsoft Corporation
Microsoft? C++ Runtime Library
2003-03-18 22:14:52

MSVCR71.dll
0x7c340000
C:\WINDOWS\system32\msvcr71.dll
7.10.3052.4
Microsoft Corporation
Microsoft? C Runtime Library
2003-02-21 04:42:22

SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\shlwapi.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2003-03-15 08:00:00

msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2003-03-15 08:00:00

VERSION.dll
0x77bd0000
C:\WINDOWS\system32\version.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Version Checking and File Installation Libraries
2003-03-15 08:00:00

ole32.dll
0x620000
C:\WINDOWS\system32\ole32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft OLE for Windows
2003-03-15 08:00:00

shsvcs.dll
0x76ba0000
c:\WINDOWS\system32\shsvcs.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Shell Services Dll
2003-03-15 08:00:00

shell32.dll
0x773a0000
C:\WINDOWS\system32\shell32.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Shell Common Dll
2003-03-15 08:00:00

comctl32.dll
0x78090000
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
6.0 (xpsp1.020828-1920)
Microsoft Corporation
User Experience Controls Library
2003-03-15 08:00:00

comctl32.dll
0x77310000
C:\WINDOWS\system32\comctl32.dll
5.82 (xpsp1.020828-1920)
Microsoft Corporation
Common Controls Library
2003-03-15 08:00:00

WINSTA.dll
0x762d0000
C:\WINDOWS\system32\winsta.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Winstation Library
2003-03-15 08:00:00

dhcpcsvc.dll
0x76d50000
c:\WINDOWS\system32\dhcpcsvc.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
DHCP Client Service
2003-03-15 08:00:00

DNSAPI.dll
0x76ef0000
c:\WINDOWS\system32\dnsapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
DNS Client API DLL
2003-03-15 08:00:00

WS2_32.dll
0x71a20000
c:\WINDOWS\system32\ws2_32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 32-Bit DLL
2003-03-15 08:00:00

WS2HELP.dll
0x71a10000
c:\WINDOWS\system32\ws2help.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 Helper for Windows NT
2003-03-15 08:00:00

iphlpapi.dll
0x76d30000
c:\WINDOWS\system32\iphlpapi.dll
5.1.2600.2 (xpsp1.020828-1920)
Microsoft Corporation
IP Helper API
2003-03-15 08:00:00

Secur32.dll
0x76f60000
c:\WINDOWS\system32\secur32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Security Support Provider Interface
2003-03-15 08:00:00

UxTheme.dll
0x5adc0000
C:\WINDOWS\system32\uxtheme.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft UxTheme Library
2003-03-15 08:00:00

rsaenh.dll
0xffd0000
C:\WINDOWS\system32\rsaenh.dll
5.1.2600.1029 (xpsp1.020426-1800)
Microsoft Corporation
Microsoft Base Cryptographic Provider
2003-03-15 08:00:00

wzcsvc.dll
0x77c80000
c:\WINDOWS\system32\wzcsvc.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Wireless Zero Configuration Service
2003-03-15 08:00:00

rtutils.dll
0x76e50000
c:\WINDOWS\system32\rtutils.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Routing Utilities
2003-03-15 08:00:00

WMI.dll
0x76d00000
c:\WINDOWS\system32\wmi.dll
5.1.2600.0 (XPClient.010817-1148)
Microsoft Corporation
WMI DC and DP functionality
2003-03-15 08:00:00

OLEAUT32.dll
0x770f0000
C:\WINDOWS\system32\oleaut32.dll
3.50.5016.0
Microsoft Corporation
Microsoft OLE 3.50  for Windows NT(TM) and Windows 95(TM) Operating Systems
2003-03-15 08:00:00

CRYPT32.dll
0x76230000
C:\WINDOWS\system32\crypt32.dll
5.131.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Crypto API32
2003-03-15 08:00:00

MSASN1.dll
0x76210000
C:\WINDOWS\system32\msasn1.dll
5.1.2600.0 (XPClient.010817-1148)
Microsoft Corporation
ASN.1 Runtime APIs
2003-03-15 08:00:00

WTSAPI32.dll
0x76f20000
c:\WINDOWS\system32\wtsapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Terminal Server SDK APIs
2003-03-15 08:00:00

ESENT.dll
0x69a20000
c:\WINDOWS\system32\esent.dll
5.1.2468.0 (Lab03_N(jliem).010306-1456)
Microsoft Corporation
服务器数据库存储引擎
2003-03-15 08:00:00

WLDAP32.dll
0x76f30000
C:\WINDOWS\system32\wldap32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Win32 LDAP API DLL
2003-03-15 08:00:00

NETAPI32.dll
0x71ba0000
c:\WINDOWS\system32\netapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Net Win32 API DLL
2003-03-15 08:00:00

rastls.dll
0x74e70000
C:\WINDOWS\system32\rastls.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Access PPP EAP-TLS
2003-03-15 08:00:00

ATL.DLL
0x76af0000
C:\WINDOWS\system32\atl.dll
3.00.9435
Microsoft Corporation
ATL Module for Windows NT (Unicode)
2003-03-15 08:00:00

CRYPTUI.dll
0x75430000
C:\WINDOWS\system32\cryptui.dll
5.131.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft Trust UI Provider
2003-03-15 08:00:00
fengzhejun - 2006-3-14 8:37:00


WINTRUST.dll
0x76c00000
C:\WINDOWS\system32\wintrust.dll
5.131.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Trust Verification APIs
2003-03-15 08:00:00

IMAGEHLP.dll
0x76c60000
C:\WINDOWS\system32\imagehlp.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT Image Helper
2003-03-15 08:00:00

WININET.dll
0x76170000
C:\WINDOWS\system32\wininet.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Internet Extensions for Win32
2003-03-15 08:00:00

MPRAPI.dll
0x76d10000
C:\WINDOWS\system32\mprapi.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows NT MP Router Administration DLL
2003-03-15 08:00:00

ACTIVEDS.dll
0x76e10000
C:\WINDOWS\system32\activeds.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
ADs Router Layer DLL
2003-03-15 08:00:00

adsldpc.dll
0x76de0000
C:\WINDOWS\system32\adsldpc.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
ADs LDAP Provider C DLL
2003-03-15 08:00:00

SAMLIB.dll
0x71b70000
C:\WINDOWS\system32\samlib.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
SAM Library DLL
2003-03-15 08:00:00

SETUPAPI.dll
0x765e0000
C:\WINDOWS\system32\setupapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Setup API
2003-03-15 08:00:00

RASAPI32.dll
0x76eb0000
C:\WINDOWS\system32\rasapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Access API
2003-03-15 08:00:00

rasman.dll
0x76e60000
C:\WINDOWS\system32\rasman.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Access Connection Manager
2003-03-15 08:00:00

TAPI32.dll
0x76e80000
C:\WINDOWS\system32\tapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft(R) Windows(TM) Telephony API Client DLL
2003-03-15 08:00:00

WINMM.dll
0x76b10000
C:\WINDOWS\system32\winmm.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
MCI API DLL
2003-03-15 08:00:00

SCHANNEL.dll
0x767c0000
C:\WINDOWS\system32\schannel.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
TLS / SSL Security Provider
2003-03-15 08:00:00

USERENV.dll
0x759d0000
C:\WINDOWS\system32\userenv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Userenv
2003-03-15 08:00:00

WinSCard.dll
0x72360000
C:\WINDOWS\system32\winscard.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Smart Card API
2003-03-15 08:00:00

raschap.dll
0x74f60000
C:\WINDOWS\system32\raschap.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Access PPP CHAP
2003-03-15 08:00:00

msv1_0.dll
0x76ce0000
C:\WINDOWS\system32\msv1_0.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft Authentication Package v1.0
2003-03-15 08:00:00

CLBCATQ.DLL
0x76fa0000
C:\WINDOWS\system32\clbcatq.dll
2001.12.4414.42
Microsoft Corporation

2003-03-15 08:00:00

COMRes.dll
0x77020000
C:\WINDOWS\system32\comres.dll
2001.12.4414.42
Microsoft Corporation

2003-03-15 08:00:00

schedsvc.dll
0x75130000
c:\WINDOWS\system32\schedsvc.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Task Scheduler Engine
2003-03-15 08:00:00

NTDSAPI.dll
0x76770000
c:\WINDOWS\system32\ntdsapi.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
NT5DS
2003-03-15 08:00:00

mswsock.dll
0x719c0000
C:\WINDOWS\system32\mswsock.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Windows Sockets 2.0 Service Provider
2003-03-15 08:00:00

wshtcpip.dll
0x71a00000
C:\WINDOWS\system32\wshtcpip.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Sockets Helper DLL
2003-03-15 08:00:00

MSIDLE.DLL
0x74eb0000
C:\WINDOWS\system32\msidle.dll
6.00.2600.0000 (xpclient.010817-1148)
Microsoft Corporation
User Idle Monitor
2003-03-15 08:00:00

NTMARTA.DLL
0x76cb0000
C:\WINDOWS\system32\ntmarta.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT MARTA provider
2003-03-15 08:00:00

wkssvc.dll
0x750d0000
c:\WINDOWS\system32\wkssvc.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Workstation Service DLL
2003-03-15 08:00:00

cryptsvc.dll
0x74f00000
c:\WINDOWS\system32\cryptsvc.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Cryptographic Services
2003-03-15 08:00:00

certcli.dll
0x752b0000
c:\WINDOWS\system32\certcli.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft(R) Certificate Services Client
2003-03-15 08:00:00

ersvc.dll
0x74ee0000
c:\WINDOWS\system32\ersvc.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Error Reporting Service
2003-03-15 08:00:00

es.dll
0x76b40000
c:\WINDOWS\system32\es.dll
2001.12.4414.46
Microsoft Corporation

2003-03-15 08:00:00

spted.dll
0x1530000
c:\WINDOWS\system32\spted.dll
3.525.1117.0
Microsoft Corporation
Microsoft Windows COM+ Stub
2006-02-20 14:40:04

urlmon.dll
0x76060000
C:\WINDOWS\system32\urlmon.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
OLE32 Extensions for Win32
2003-03-15 08:00:00

pchsvc.dll
0x74ea0000
c:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft PCHealth Service Holder
2003-03-15 08:00:00

srvsvc.dll
0x74ff0000
c:\WINDOWS\system32\srvsvc.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Server Service DLL
2003-03-15 08:00:00
fengzhejun - 2006-3-14 8:37:00


msgsvc.dll
0x74ec0000
c:\WINDOWS\system32\msgsvc.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
NT Messenger Service
2003-03-15 08:00:00

winspool.drv
0x72f70000
C:\WINDOWS\system32\winspool.drv
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Spooler Driver
2003-03-15 08:00:00

seclogon.dll
0x73c90000
c:\WINDOWS\system32\seclogon.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Secondary Logon Service DLL
2003-03-15 08:00:00

sens.dll
0x72260000
c:\WINDOWS\system32\sens.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
System Event Notification Service (SENS)
2003-03-15 08:00:00

srsvc.dll
0x75100000
c:\WINDOWS\system32\srsvc.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
System Restore Service
2003-03-15 08:00:00

POWRPROF.dll
0x74a30000
c:\WINDOWS\system32\powrprof.dll
6.00.2600.0000 (xpclient.010817-1148)
Microsoft Corporation
Power Profile Helper DLL
2003-03-15 08:00:00

trkwks.dll
0x74fd0000
c:\WINDOWS\system32\trkwks.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Distributed Link Tracking Client
2003-03-15 08:00:00

w32time.dll
0x76790000
c:\WINDOWS\system32\w32time.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Time Service
2003-03-15 08:00:00

MSVCP60.dll
0x75ff0000
c:\WINDOWS\system32\msvcp60.dll
6.00.8972.0
Microsoft Corporation
Microsoft (R) C++ Runtime Library
2003-03-15 08:00:00

wmisvc.dll
0x59470000
c:\WINDOWS\system32\wbem\wmisvc.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
WMI
2003-03-15 08:00:00

wbemcomn.dll
0x751f0000
c:\WINDOWS\system32\wbem\wbemcomn.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
WMI
2003-03-15 08:00:00

VSSAPI.DLL
0x75340000
C:\WINDOWS\system32\vssapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft? Volume Shadow Copy Requestor/Writer Services API DLL
2003-03-15 08:00:00

mspmspsv.dll
0x72430000
c:\WINDOWS\system32\mspmspsv.dll
8.0.1.20
Microsoft Corporation
Microsoft Media Device Service Provider
2003-03-15 08:00:00

SXS.DLL
0x75e00000
C:\WINDOWS\system32\sxs.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Fusion 2.5
2003-03-15 08:00:00

comsvcs.dll
0x75690000
C:\WINDOWS\system32\comsvcs.dll
2001.12.4414.46
Microsoft Corporation

2003-03-15 08:00:00

MTXCLU.DLL
0x75050000
C:\WINDOWS\system32\mtxclu.dll
2001.12.4414.42
Microsoft Corporation
MS DTC amd MTS clustering support DLL
2003-03-15 08:00:00

WSOCK32.dll
0x71a40000
C:\WINDOWS\system32\wsock32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 32-Bit DLL
2003-03-15 08:00:00

colbact.DLL
0x75090000
C:\WINDOWS\system32\colbact.dll
2001.12.4414.42
Microsoft Corporation

2003-03-15 08:00:00

CLUSAPI.DLL
0x74f20000
C:\WINDOWS\system32\clusapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Cluster API Library
2003-03-15 08:00:00

RESUTILS.DLL
0x75010000
C:\WINDOWS\system32\resutils.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Cluster Resource Utility DLL
2003-03-15 08:00:00

mtxoci.dll
0x75030000
C:\WINDOWS\system32\mtxoci.dll
2001.12.4414.42
Microsoft Corporation
Microsoft database support DLL for Oracle
2003-03-15 08:00:00

winoa32.dll
0x1e70000
C:\WINDOWS\system32\WINOA32.DLL
2, 84, 2207, 0

OAgent
2000-01-10 20:00:00

MFC42.DLL
0x73d30000
C:\WINDOWS\system32\mfc42.dll
6.00.8665.0
Microsoft Corporation
MFCDLL Shared Library - Retail Version
2003-03-15 08:00:00

MFC42LOC.DLL
0x61be0000
C:\WINDOWS\system32\mfc42loc.dll
6.00.8665.0
Microsoft Corporation
MFC Language Specific Resources
2003-03-15 08:00:00

thooks.dll
0x18d0000
C:\WINDOWS\system32\THooks.dll
2, 84, 2207, 0

THooks
2000-01-10 20:00:00

oblknet.dll
0x18e0000
C:\WINDOWS\system32\oblknet.dll
2, 82, 415, 0

oblknet
2005-09-21 21:39:08

ippcap.dll
0x1f20000
C:\WINDOWS\system32\ippcap.dll
3, 0, 0, 18
Politecnico di Torino
wpcap - Based on libpcap 0.7 snapshot feb 03, 2003
2004-06-27 17:10:36

IPpacket.dll
0x18f0000
C:\WINDOWS\system32\ippacket.dll
3, 0, 0, 20
Politecnico di Torino
IPPack
2004-06-27 17:10:36

orcsdll.dll
0x2080000
C:\WINDOWS\system32\orcsdll.dll
2, 81, 2322, 0

rcsdll
2005-03-22 13:49:12

orcshook.dll
0x20d0000
C:\WINDOWS\system32\orcshook.dll
2, 81, 2322, 0

ORCSHook
2005-03-22 20:11:10

browser.dll
0x74f40000
c:\WINDOWS\system32\browser.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Computer Browser Service DLL
2003-03-15 08:00:00

wbemprox.dll
0x74e50000
C:\WINDOWS\system32\wbem\wbemprox.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
WMI
2003-03-15 08:00:00

wbemcore.dll
0x753b0000
C:\WINDOWS\system32\wbem\wbemcore.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
WMI
2003-03-15 08:00:00

esscli.dll
0x75270000
C:\WINDOWS\system32\wbem\esscli.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
WMI
2003-03-15 08:00:00

FastProx.dll
0x755f0000
C:\WINDOWS\system32\wbem\fastprox.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
WMI
2003-03-15 08:00:00

wbemsvc.dll
0x74e30000
C:\WINDOWS\system32\wbem\wbemsvc.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
WMI
2003-03-15 08:00:00

wmiutils.dll
0x74f80000
C:\WINDOWS\system32\wbem\wmiutils.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
WMI
2003-03-15 08:00:00

repdrvfs.dll
0x75160000
C:\WINDOWS\system32\wbem\repdrvfs.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
WMI
2003-03-15 08:00:00

wmiprvsd.dll
0x594c0000
C:\WINDOWS\system32\wbem\wmiprvsd.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
WMI
2003-03-15 08:00:00

NCObjAPI.DLL
0x5f9a0000
C:\WINDOWS\system32\ncobjapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation

2003-03-15 08:00:00

wbemess.dll
0x752f0000
C:\WINDOWS\system32\wbem\wbemess.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
WMI
2003-03-15 08:00:00

winhafn.dll
0x2460000
C:\WINDOWS\system32\winhafn.dll



2005-09-21 12:51:12
fengzhejun - 2006-3-14 8:38:00


cfgmgr32.DLL
0x74a40000
C:\WINDOWS\system32\cfgmgr32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Configuration Manager Forwarder DLL
2003-03-15 08:00:00

PSAPI.DLL
0x76bc0000
C:\WINDOWS\system32\psapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Process Status Helper
2003-03-15 08:00:00

cdnns.dll
0x2670000
C:\WINDOWS\system32\cdnns.dll
2, 0, 0, 0
CNNIC
cdnns
2005-06-14 17:07:48

Rnr20.dll
0x723e0000
C:\WINDOWS\system32\rnr20.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket2 NameSpace DLL
2003-03-15 08:00:00

winrnr.dll
0x76f80000
C:\WINDOWS\system32\winrnr.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
LDAP RnR Provider DLL
2003-03-15 08:00:00

rasadhlp.dll
0x76f90000
C:\WINDOWS\system32\rasadhlp.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Remote Access AutoDial Helper
2003-03-15 08:00:00

ipddraw.DLL
0x2380000
C:\WINDOWS\system32\ipddraw.dll
2, 83, 829, 0

ipddraw DLL
2005-09-01 11:54:52

DDRAW.dll
0x51000000
C:\WINDOWS\system32\ddraw.dll
5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)
Microsoft Corporation
Microsoft DirectDraw
2004-07-09 04:27:28

DCIMAN32.dll
0x73b30000
C:\WINDOWS\system32\dciman32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
DCI Manager
2003-03-15 08:00:00

NETRAP.dll
0x71c00000
C:\WINDOWS\system32\netrap.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Net Remote Admin Protocol DLL
2003-03-15 08:00:00

termsrv.dll
0x75230000
c:\WINDOWS\system32\termsrv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Terminal Server Service
2003-03-15 08:00:00

ICAAPI.dll
0x74ed0000
c:\WINDOWS\system32\icaapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
DLL Interface to TermDD Device Driver
2003-03-15 08:00:00

AUTHZ.dll
0x76c90000
c:\WINDOWS\system32\authz.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Authorization Framework
2003-03-15 08:00:00

mstlsapi.dll
0x75070000
c:\WINDOWS\system32\mstlsapi.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft? Terminal Server Licensing
2003-03-15 08:00:00

REGAPI.dll
0x76b90000
C:\WINDOWS\system32\regapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Registry Configuration APIs
2003-03-15 08:00:00

netman.dll
0x76db0000
c:\WINDOWS\system32\netman.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Network Connections Manager
2003-03-15 08:00:00

NETSHELL.dll
0x75c60000
C:\WINDOWS\system32\netshell.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Network Connections Shell
2003-03-15 08:00:00

credui.dll
0x76bd0000
C:\WINDOWS\system32\credui.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Credential Manager User Interface
2003-03-15 08:00:00

upnp.dll
0x74fa0000
C:\WINDOWS\system32\upnp.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Universal Plug and Play API
2003-03-15 08:00:00

SSDPAPI.dll
0x74e60000
C:\WINDOWS\system32\ssdpapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
SSDP Client API DLL
2003-03-15 08:00:00

hnetcfg.dll
0x68b70000
C:\WINDOWS\system32\hnetcfg.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Home Networking Configuration Manager
2003-03-15 08:00:00

netcfgx.dll
0x75550000
C:\WINDOWS\system32\netcfgx.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Network Configuration Objects
2003-03-15 08:00:00

rasmans.dll
0x723f0000
C:\WINDOWS\system32\rasmans.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Access Connection Manager
2003-03-15 08:00:00

WINIPSEC.DLL
0x742d0000
C:\WINDOWS\system32\winipsec.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows IPSec SPD Client DLL
2003-03-15 08:00:00

tapisrv.dll
0x73350000
c:\WINDOWS\system32\tapisrv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft(R) Windows(TM) Telephony Server
2003-03-15 08:00:00

rastapi.dll
0x71ff0000
C:\WINDOWS\system32\rastapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Access TAPI Compliance Layer
2003-03-15 08:00:00

unimdm.tsp
0x57980000
C:\WINDOWS\system32\unimdm.tsp
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Unimodem 5 Service Provider
2003-03-15 08:00:00

uniplat.dll
0x71f90000
C:\WINDOWS\system32\uniplat.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Unimodem AT Mini Driver Platform Driver for Windows NT
2003-03-15 08:00:00

kmddsp.tsp
0x57a00000
C:\WINDOWS\system32\kmddsp.tsp
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
TAPI Kernel-Mode Service Provider
2003-03-15 08:00:00

ndptsp.tsp
0x579e0000
C:\WINDOWS\system32\ndptsp.tsp
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
NDIS Proxy TAPI Service Provider
2003-03-15 08:00:00

ipconf.tsp
0x57a10000
C:\WINDOWS\system32\ipconf.tsp
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Multicast Conference TAPI Service Provider
2003-03-15 08:00:00

h323.tsp
0x57a30000
C:\WINDOWS\system32\h323.tsp
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft H.323 Telephony Service Provider
2003-03-15 08:00:00

hidphone.tsp
0x57a20000
C:\WINDOWS\system32\hidphone.tsp
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft HID Phone TSP
2003-03-15 08:00:00

HID.DLL
0x68be0000
C:\WINDOWS\system32\hid.dll
5.1.2600.0 (XPClient.010817-1148)
Microsoft Corporation
Hid User Library
2003-03-15 08:00:00

rasppp.dll
0x721d0000
C:\WINDOWS\system32\rasppp.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Access PPP
2003-03-15 08:00:00

ntlsapi.dll
0x72420000
C:\WINDOWS\system32\ntlsapi.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft? License Server Interface DLL
2003-03-15 08:00:00

RASDLG.dll
0x754b0000
C:\WINDOWS\system32\rasdlg.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Access Common Dialog API
2003-03-15 08:00:00

ncprov.dll
0x5f970000
C:\WINDOWS\system32\wbem\ncprov.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Non-COM WMI Event Provision APIs
2003-03-15 08:00:00

sensapi.dll
0x72240000
C:\WINDOWS\system32\sensapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
SENS Connectivity API DLL
2003-03-15 08:00:00




[svchost.exe]
PID = 0x41c
CommandLine = C:\WINDOWS\System32\svchost.exe -k NetworkService
svchost.exe
0x1000000
C:\WINDOWS\system32\svchost.exe
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Generic Host Process for Win32 Services
2003-03-15 08:00:00

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
NT Layer DLL
2003-03-15 08:00:00

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2003-03-15 08:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2003-03-15 08:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Procedure Call Runtime
2003-03-15 08:00:00

interceptor.dll
0xd50000
C:\WINDOWS\system32\interceptor.dll
1, 0, 0, 29
Tenebril Inc.
API Interceptor
2005-10-25 12:49:18

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP USER API Client DLL
2003-03-15 08:00:00

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2003-03-15 08:00:00

IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2003-03-15 08:00:00

LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2003-03-15 08:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2003-03-15 08:00:00

uxtheme.dll
0x5adc0000
C:\WINDOWS\system32\uxtheme.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft UxTheme Library
2003-03-15 08:00:00

msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2003-03-15 08:00:00

InterceptHelper.dll
0x10000000
C:\WINDOWS\system32\InterceptHelper.dll
1, 0, 0, 29
Tenebril Inc.
Interception Helper
2005-10-25 12:49:14

MSVCP71.dll
0x7c3a0000
C:\WINDOWS\system32\msvcp71.dll
7.10.3077.0
Microsoft Corporation
Microsoft? C++ Runtime Library
2003-03-18 22:14:52

MSVCR71.dll
0x7c340000
C:\WINDOWS\system32\msvcr71.dll
7.10.3052.4
Microsoft Corporation
Microsoft? C Runtime Library
2003-02-21 04:42:22
fengzhejun - 2006-3-14 8:38:00


SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\shlwapi.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2003-03-15 08:00:00

VERSION.dll
0x77bd0000
C:\WINDOWS\system32\version.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Version Checking and File Installation Libraries
2003-03-15 08:00:00

dnsrslvr.dll
0x76740000
c:\WINDOWS\system32\dnsrslvr.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
DNS Caching Resolver Service
2003-03-15 08:00:00

DNSAPI.dll
0x76ef0000
c:\WINDOWS\system32\dnsapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
DNS Client API DLL
2003-03-15 08:00:00

WS2_32.dll
0x71a20000
c:\WINDOWS\system32\ws2_32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 32-Bit DLL
2003-03-15 08:00:00

WS2HELP.dll
0x71a10000
c:\WINDOWS\system32\ws2help.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 Helper for Windows NT
2003-03-15 08:00:00

iphlpapi.dll
0x76d30000
c:\WINDOWS\system32\iphlpapi.dll
5.1.2600.2 (xpsp1.020828-1920)
Microsoft Corporation
IP Helper API
2003-03-15 08:00:00

mswsock.dll
0x719c0000
C:\WINDOWS\system32\mswsock.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Windows Sockets 2.0 Service Provider
2003-03-15 08:00:00

wshtcpip.dll
0x71a00000
C:\WINDOWS\system32\wshtcpip.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Sockets Helper DLL
2003-03-15 08:00:00




[svchost.exe]
PID = 0x450
CommandLine = C:\WINDOWS\System32\svchost.exe -k LocalService
svchost.exe
0x1000000
C:\WINDOWS\system32\svchost.exe
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Generic Host Process for Win32 Services
2003-03-15 08:00:00

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
NT Layer DLL
2003-03-15 08:00:00

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2003-03-15 08:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2003-03-15 08:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Procedure Call Runtime
2003-03-15 08:00:00

interceptor.dll
0xd50000
C:\WINDOWS\system32\interceptor.dll
1, 0, 0, 29
Tenebril Inc.
API Interceptor
2005-10-25 12:49:18

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP USER API Client DLL
2003-03-15 08:00:00

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2003-03-15 08:00:00

IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2003-03-15 08:00:00

LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2003-03-15 08:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2003-03-15 08:00:00

uxtheme.dll
0x5adc0000
C:\WINDOWS\system32\uxtheme.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft UxTheme Library
2003-03-15 08:00:00

msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2003-03-15 08:00:00

InterceptHelper.dll
0x10000000
C:\WINDOWS\system32\InterceptHelper.dll
1, 0, 0, 29
Tenebril Inc.
Interception Helper
2005-10-25 12:49:14

MSVCP71.dll
0x7c3a0000
C:\WINDOWS\system32\msvcp71.dll
7.10.3077.0
Microsoft Corporation
Microsoft? C++ Runtime Library
2003-03-18 22:14:52

MSVCR71.dll
0x7c340000
C:\WINDOWS\system32\msvcr71.dll
7.10.3052.4
Microsoft Corporation
Microsoft? C Runtime Library
2003-02-21 04:42:22

SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\shlwapi.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2003-03-15 08:00:00

VERSION.dll
0x77bd0000
C:\WINDOWS\system32\version.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Version Checking and File Installation Libraries
2003-03-15 08:00:00

ole32.dll
0x620000
C:\WINDOWS\system32\ole32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft OLE for Windows
2003-03-15 08:00:00

lmhsvc.dll
0x74ba0000
c:\WINDOWS\system32\lmhsvc.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
TCPIP NetBios Transport Services DLL
2003-03-15 08:00:00

iphlpapi.dll
0x76d30000
c:\WINDOWS\system32\iphlpapi.dll
5.1.2600.2 (xpsp1.020828-1920)
Microsoft Corporation
IP Helper API
2003-03-15 08:00:00

WS2_32.dll
0x71a20000
c:\WINDOWS\system32\ws2_32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 32-Bit DLL
2003-03-15 08:00:00

WS2HELP.dll
0x71a10000
c:\WINDOWS\system32\ws2help.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 Helper for Windows NT
2003-03-15 08:00:00

webclnt.dll
0x5a720000
c:\WINDOWS\system32\webclnt.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Web DAV Service DLL
2003-03-15 08:00:00

WININET.dll
0x76170000
C:\WINDOWS\system32\wininet.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Internet Extensions for Win32
2003-03-15 08:00:00

CRYPT32.dll
0x76230000
C:\WINDOWS\system32\crypt32.dll
5.131.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Crypto API32
2003-03-15 08:00:00

MSASN1.dll
0x76210000
C:\WINDOWS\system32\msasn1.dll
5.1.2600.0 (XPClient.010817-1148)
Microsoft Corporation
ASN.1 Runtime APIs
2003-03-15 08:00:00

OLEAUT32.dll
0x770f0000
C:\WINDOWS\system32\oleaut32.dll
3.50.5016.0
Microsoft Corporation
Microsoft OLE 3.50  for Windows NT(TM) and Windows 95(TM) Operating Systems
2003-03-15 08:00:00

comctl32.dll
0x78090000
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
6.0 (xpsp1.020828-1920)
Microsoft Corporation
User Experience Controls Library
2003-03-15 08:00:00

shell32.dll
0x773a0000
C:\WINDOWS\system32\shell32.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Shell Common Dll
2003-03-15 08:00:00

comctl32.dll
0x77310000
C:\WINDOWS\system32\comctl32.dll
5.82 (xpsp1.020828-1920)
Microsoft Corporation
Common Controls Library
2003-03-15 08:00:00

Secur32.dll
0x76f60000
C:\WINDOWS\system32\secur32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Security Support Provider Interface
2003-03-15 08:00:00

wsock32.dll
0x71a40000
C:\WINDOWS\system32\wsock32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 32-Bit DLL
2003-03-15 08:00:00

regsvc.dll
0x74b80000
c:\WINDOWS\system32\regsvc.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Remote Registry Service
2003-03-15 08:00:00

ssdpsrv.dll
0x74b70000
c:\WINDOWS\system32\ssdpsrv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
SSDP Service DLL
2003-03-15 08:00:00

mswsock.dll
0x719c0000
C:\WINDOWS\system32\mswsock.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Windows Sockets 2.0 Service Provider
2003-03-15 08:00:00
fengzhejun - 2006-3-14 8:39:00


wshtcpip.dll
0x71a00000
C:\WINDOWS\system32\wshtcpip.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Sockets Helper DLL
2003-03-15 08:00:00

cdnns.dll
0xa00000
C:\WINDOWS\system32\cdnns.dll
2, 0, 0, 0
CNNIC
cdnns
2005-06-14 17:07:48

Rnr20.dll
0x723e0000
C:\WINDOWS\system32\rnr20.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket2 NameSpace DLL
2003-03-15 08:00:00

DNSAPI.dll
0x76ef0000
C:\WINDOWS\system32\dnsapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
DNS Client API DLL
2003-03-15 08:00:00

RASAPI32.DLL
0x76eb0000
C:\WINDOWS\system32\rasapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Access API
2003-03-15 08:00:00

rasman.dll
0x76e60000
C:\WINDOWS\system32\rasman.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Access Connection Manager
2003-03-15 08:00:00

NETAPI32.dll
0x71ba0000
C:\WINDOWS\system32\netapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Net Win32 API DLL
2003-03-15 08:00:00

TAPI32.dll
0x76e80000
C:\WINDOWS\system32\tapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft(R) Windows(TM) Telephony API Client DLL
2003-03-15 08:00:00

rtutils.dll
0x76e50000
C:\WINDOWS\system32\rtutils.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Routing Utilities
2003-03-15 08:00:00

WINMM.dll
0x76b10000
C:\WINDOWS\system32\winmm.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
MCI API DLL
2003-03-15 08:00:00

sensapi.dll
0x72240000
C:\WINDOWS\system32\sensapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
SENS Connectivity API DLL
2003-03-15 08:00:00

rasadhlp.dll
0x76f90000
C:\WINDOWS\system32\rasadhlp.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Remote Access AutoDial Helper
2003-03-15 08:00:00

winrnr.dll
0x76f80000
C:\WINDOWS\system32\winrnr.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
LDAP RnR Provider DLL
2003-03-15 08:00:00

WLDAP32.dll
0x76f30000
C:\WINDOWS\system32\wldap32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Win32 LDAP API DLL
2003-03-15 08:00:00




[RavMonD.exe]
PID = 0x468
CommandLine = "C:\Program Files\Rising\Rav\Ravmond.exe"
Ravmond.exe
0x400000
C:\Program Files\Rising\Rav\RavMonD.exe
18, 0, 1, 16
Beijing Rising Technology Co., Ltd.
RavMond
2006-03-13 09:09:36

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
NT Layer DLL
2003-03-15 08:00:00

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2003-03-15 08:00:00

BWList.dll
0x10000000
C:\Program Files\Rising\Rav\BWList.dll
18, 0, 0, 16
Beijing Rising Technology Co., Ltd.
BWList DLL
2006-01-19 14:46:26

MFC42.DLL
0x73d30000
C:\WINDOWS\system32\mfc42.dll
6.00.8665.0
Microsoft Corporation
MFCDLL Shared Library - Retail Version
2003-03-15 08:00:00

MSVCRT.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2003-03-15 08:00:00

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2003-03-15 08:00:00

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP USER API Client DLL
2003-03-15 08:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2003-03-15 08:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Procedure Call Runtime
2003-03-15 08:00:00

SHELL32.dll
0x773a0000
C:\WINDOWS\system32\shell32.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Shell Common Dll
2003-03-15 08:00:00

SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\shlwapi.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2003-03-15 08:00:00

MSVCP60.dll
0x75ff0000
C:\WINDOWS\system32\msvcp60.dll
6.00.8972.0
Microsoft Corporation
Microsoft (R) C++ Runtime Library
2003-03-15 08:00:00

WSOCK32.dll
0x71a40000
C:\WINDOWS\system32\wsock32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 32-Bit DLL
2003-03-15 08:00:00

WS2_32.dll
0x71a20000
C:\WINDOWS\system32\ws2_32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 32-Bit DLL
2003-03-15 08:00:00

WS2HELP.dll
0x71a10000
C:\WINDOWS\system32\ws2help.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 Helper for Windows NT
2003-03-15 08:00:00

OLEAUT32.dll
0x770f0000
C:\WINDOWS\system32\oleaut32.dll
3.50.5016.0
Microsoft Corporation
Microsoft OLE 3.50  for Windows NT(TM) and Windows 95(TM) Operating Systems
2003-03-15 08:00:00

OLE32.DLL
0x440000
C:\WINDOWS\system32\ole32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft OLE for Windows
2003-03-15 08:00:00

VERSION.dll
0x77bd0000
C:\WINDOWS\system32\version.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Version Checking and File Installation Libraries
2003-03-15 08:00:00

IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2003-03-15 08:00:00

LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2003-03-15 08:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2003-03-15 08:00:00

interceptor.dll
0xd50000
C:\WINDOWS\system32\interceptor.dll
1, 0, 0, 29
Tenebril Inc.
API Interceptor
2005-10-25 12:49:18

MFC42LOC.DLL
0x61be0000
C:\WINDOWS\system32\mfc42loc.dll
6.00.8665.0
Microsoft Corporation
MFC Language Specific Resources
2003-03-15 08:00:00

comctl32.dll
0x78090000
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
6.0 (xpsp1.020828-1920)
Microsoft Corporation
User Experience Controls Library
2003-03-15 08:00:00

comctl32.dll
0x77310000
C:\WINDOWS\system32\comctl32.dll
5.82 (xpsp1.020828-1920)
Microsoft Corporation
Common Controls Library
2003-03-15 08:00:00

uxtheme.dll
0x5adc0000
C:\WINDOWS\system32\uxtheme.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft UxTheme Library
2003-03-15 08:00:00

InterceptHelper.dll
0xa60000
C:\WINDOWS\system32\InterceptHelper.dll
1, 0, 0, 29
Tenebril Inc.
Interception Helper
2005-10-25 12:49:14

MSVCP71.dll
0x7c3a0000
C:\WINDOWS\system32\msvcp71.dll
7.10.3077.0
Microsoft Corporation
Microsoft? C++ Runtime Library
2003-03-18 22:14:52

MSVCR71.dll
0x7c340000
C:\WINDOWS\system32\msvcr71.dll
7.10.3052.4
Microsoft Corporation
Microsoft? C Runtime Library
2003-02-21 04:42:22

RsCommX.dll
0xad0000
C:\Program Files\Rising\Rav\RsCommX.dll
18, 0, 0, 1
rising
RsCommX
2006-01-19 14:49:07

RSAPPMGR.DLL
0xf80000
C:\Program Files\Rising\Rav\RsAppMgr.dll
18, 0, 0, 2
Beijing Rising Technology Co., Ltd.
Rising Application Manager
2006-01-19 14:46:28

CfgDll.dll
0x90a0000
C:\Program Files\Rising\Rav\CfgDll.dll
18, 0, 0, 6
Beijing Rising Technology Co., Ltd.
CfgDll
2006-01-19 14:46:28

RSCOMMON.DLL
0x23700000
C:\Program Files\Rising\Rav\RsCommon.dll
18, 0, 0, 4
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
2006-01-19 14:46:25

RsLog.dll
0x9330000
C:\Program Files\Rising\Rav\RsLog.dll
18, 0, 0, 18
Beijing Rising Technology Co., Ltd.
RsLog DLL
2006-01-19 14:49:06

HOOKSYS.dll
0x9340000
C:\Program Files\Rising\Rav\HOOKSYS.dll
18, 1, 0, 9
Rising
HOOKSYS Dynamic Link Library
2006-01-19 14:47:05

Scanner.dll
0x9470000
C:\Program Files\Rising\Rav\Scanner.dll
18, 0, 0, 28
Beijing Rising Technology Co., Ltd.
RsScanner
2006-01-19 14:46:27
fengzhejun - 2006-3-14 8:40:00


libload.dll
0x13100000
C:\Program Files\Rising\Rav\libload.dll
18, 0, 0, 10
Beijing Rising Technology Co., Ltd.
LibLoad
2006-01-19 14:46:33

VirusLib.dll
0x95d0000
C:\Program Files\Rising\Rav\VirusLib.dll
18, 0, 0, 10
Beijing Rising Technology Co., Ltd.
VirusLib
2006-01-19 14:46:33

regmon.dll
0x9710000
C:\Program Files\Rising\Rav\RegMon.dll
18, 0, 0, 6
Beijing Rising Technology Co., Ltd.
regmon
2006-01-19 14:47:08

psapi.dll
0x731b0000
C:\Program Files\Rising\Rav\PsApi.DLL
4.00
Microsoft Corporation
Process Status Helper
2005-09-09 12:04:33

IMAGEHLP.dll
0x76c60000
C:\WINDOWS\system32\imagehlp.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT Image Helper
2003-03-15 08:00:00

HookWeb.dll
0x99a0000
C:\Program Files\Rising\Rav\HookWeb.dll
18, 0, 0, 1
rising
HookWeb
2006-01-19 14:49:05

MemMon.dll
0x99c0000
C:\Program Files\Rising\Rav\MemMon.dll
18, 0, 0, 8
Beijing Rising Technology Co., Ltd.
MemMon
2006-01-19 14:47:06

expscan.dll
0x99f0000
C:\Program Files\Rising\Rav\ExpScan.dll
18, 0, 0, 4
Beijing Rising Technology Co., Ltd.
ExpScan.dll
2006-01-19 14:47:09

mPorts.dll
0x9a10000
C:\Program Files\Rising\Rav\mPorts.dll
4, 0, 0, 3
Beijing Rising Technology Co., Ltd.
mPorts.dll
2006-01-19 14:47:09

iphlpapi.dll
0x76d30000
C:\WINDOWS\system32\iphlpapi.dll
5.1.2600.2 (xpsp1.020828-1920)
Microsoft Corporation
IP Helper API
2003-03-15 08:00:00

MailMon.dll
0x9c20000
C:\Program Files\Rising\Rav\MailMon.dll
18, 0, 0, 5
Beijing Rising Technology Co., Ltd.
mailmon
2006-01-19 14:46:43

SpamEng.dll
0x9c50000
C:\Program Files\Rising\Rav\SpamEng.dll
18, 0, 0, 4

SpamEng Dynamic Link Library
2006-01-19 14:46:44

engine.dll
0x13a80000
C:\Program Files\Rising\Rav\engine.dll
18, 0, 0, 26
Beijing Rising Technology Co., Ltd.
engine
2006-03-03 11:29:51

mswsock.dll
0x719c0000
C:\WINDOWS\system32\mswsock.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Windows Sockets 2.0 Service Provider
2003-03-15 08:00:00

wshtcpip.dll
0x71a00000
C:\WINDOWS\system32\wshtcpip.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Sockets Helper DLL
2003-03-15 08:00:00

PostTrt.dll
0xa640000
C:\Program Files\Rising\Rav\PostTrt.dll
18, 0, 0, 5
Beijing Rising Technology Co., Ltd.
PostTrt
2006-01-19 14:46:33

perfproc.dll
0x5e8e0000
C:\WINDOWS\system32\perfproc.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows System Process Performance Objects DLL
2003-03-15 08:00:00

UnExe.dll
0xada0000
C:\Program Files\Rising\Rav\Unexe.dll
18, 0, 0, 7
Beijing Rising Technology Co., Ltd.
UnExe
2006-03-03 11:29:43

ScanExec.dll
0x13ab0000
C:\Program Files\Rising\Rav\scanexec.dll
18, 0, 0, 7
Beijing Rising Technology Co., Ltd.
ScanExec
2006-03-03 11:29:43

ScanEx.dll
0xb410000
C:\Program Files\Rising\Rav\ScanEx.dll
18, 0, 0, 5
Beijing Rising Technology Co., Ltd.
ScanEX
2006-01-19 14:46:33

NvFile.dll
0xb1a0000
C:\Program Files\Rising\Rav\nvfile.dll
18, 0, 0, 7
Beijing Rising Technology Co., Ltd.
NVFile
2006-01-19 14:46:33

ScanMac.dll
0x13af0000
C:\Program Files\Rising\Rav\scanmac.dll
18, 0, 0, 7
Beijing Rising Technology Co., Ltd.
ScanMac
2006-01-19 14:46:30

ScanSct.dll
0xb3b0000
C:\Program Files\Rising\Rav\scansct.dll
18, 0, 0, 13
Beijing Rising Technology Co., Ltd.
ScanSct
2006-03-03 11:29:43

Unpacker.dll
0xb700000
C:\Program Files\Rising\Rav\unpacker.dll
18, 0, 0, 3
Beijing Rising Technology Co., Ltd.
UnPacker
2006-01-19 14:46:32

ExtOLE.dll
0xbaf0000
C:\Program Files\Rising\Rav\extole.dll
18, 0, 0, 5
Beijing Rising Technology Co., Ltd.
ExtOLE
2006-01-19 14:46:30




[spoolsv.exe]
PID = 0x4f4
CommandLine = C:\WINDOWS\system32\spoolsv.exe
spoolsv.exe
0x1000000
C:\WINDOWS\system32\spoolsv.exe
5.1.2600.0 (XPClient.010817-1148)
Microsoft Corporation
Spooler SubSystem App
2003-03-15 08:00:00

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
NT Layer DLL
2003-03-15 08:00:00

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2003-03-15 08:00:00

msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2003-03-15 08:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2003-03-15 08:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Procedure Call Runtime
2003-03-15 08:00:00

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2003-03-15 08:00:00

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP USER API Client DLL
2003-03-15 08:00:00

IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2003-03-15 08:00:00

LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2003-03-15 08:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2003-03-15 08:00:00

interceptor.dll
0xd50000
C:\WINDOWS\system32\interceptor.dll
1, 0, 0, 29
Tenebril Inc.
API Interceptor
2005-10-25 12:49:18

uxtheme.dll
0x5adc0000
C:\WINDOWS\system32\uxtheme.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft UxTheme Library
2003-03-15 08:00:00

InterceptHelper.dll
0x10000000
C:\WINDOWS\system32\InterceptHelper.dll
1, 0, 0, 29
Tenebril Inc.
Interception Helper
2005-10-25 12:49:14

MSVCP71.dll
0x7c3a0000
C:\WINDOWS\system32\msvcp71.dll
7.10.3077.0
Microsoft Corporation
Microsoft? C++ Runtime Library
2003-03-18 22:14:52

MSVCR71.dll
0x7c340000
C:\WINDOWS\system32\msvcr71.dll
7.10.3052.4
Microsoft Corporation
Microsoft? C Runtime Library
2003-02-21 04:42:22
fengzhejun - 2006-3-14 8:40:00


SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\shlwapi.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2003-03-15 08:00:00

VERSION.dll
0x77bd0000
C:\WINDOWS\system32\version.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Version Checking and File Installation Libraries
2003-03-15 08:00:00

SPOOLSS.DLL
0x74240000
C:\WINDOWS\system32\spoolss.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Spooler SubSystem DLL
2003-03-15 08:00:00

WS2_32.dll
0x71a20000
C:\WINDOWS\system32\ws2_32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 32-Bit DLL
2003-03-15 08:00:00

WS2HELP.dll
0x71a10000
C:\WINDOWS\system32\ws2help.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 Helper for Windows NT
2003-03-15 08:00:00

MSWSOCK.dll
0x719c0000
C:\WINDOWS\system32\mswsock.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Windows Sockets 2.0 Service Provider
2003-03-15 08:00:00

DNSAPI.dll
0x76ef0000
C:\WINDOWS\system32\dnsapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
DNS Client API DLL
2003-03-15 08:00:00

rasadhlp.dll
0x76f90000
C:\WINDOWS\system32\rasadhlp.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Remote Access AutoDial Helper
2003-03-15 08:00:00

localspl.dll
0x74280000
C:\WINDOWS\system32\localspl.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Local Spooler DLL
2003-03-15 08:00:00

ole32.dll
0xbb0000
C:\WINDOWS\system32\ole32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft OLE for Windows
2003-03-15 08:00:00

OLEAUT32.dll
0x770f0000
C:\WINDOWS\system32\oleaut32.dll
3.50.5016.0
Microsoft Corporation
Microsoft OLE 3.50  for Windows NT(TM) and Windows 95(TM) Operating Systems
2003-03-15 08:00:00

Secur32.dll
0x76f60000
C:\WINDOWS\system32\secur32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Security Support Provider Interface
2003-03-15 08:00:00

sfc_os.dll
0x76c30000
C:\WINDOWS\system32\sfc_os.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows 文件保护
2003-03-15 08:00:00

WINTRUST.dll
0x76c00000
C:\WINDOWS\system32\wintrust.dll
5.131.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Trust Verification APIs
2003-03-15 08:00:00

CRYPT32.dll
0x76230000
C:\WINDOWS\system32\crypt32.dll
5.131.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Crypto API32
2003-03-15 08:00:00

MSASN1.dll
0x76210000
C:\WINDOWS\system32\msasn1.dll
5.1.2600.0 (XPClient.010817-1148)
Microsoft Corporation
ASN.1 Runtime APIs
2003-03-15 08:00:00

IMAGEHLP.dll
0x76c60000
C:\WINDOWS\system32\imagehlp.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT Image Helper
2003-03-15 08:00:00

USERENV.dll
0x759d0000
C:\WINDOWS\system32\userenv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Userenv
2003-03-15 08:00:00

winspool.drv
0x72f70000
C:\WINDOWS\system32\winspool.drv
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Spooler Driver
2003-03-15 08:00:00

netapi32.dll
0x71ba0000
C:\WINDOWS\system32\netapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Net Win32 API DLL
2003-03-15 08:00:00

AdobePDF.dll
0x50400000
C:\WINDOWS\system32\AdobePDF.dll
7.0.0.00
Adobe Systems Incorporated.
Acrobat ? PDF Port
2004-12-14 02:12:06

AdistRes.CHS
0x1010000
D:\Adobe\Acrobat 7.0\Distillr\AdistRes.CHS



2004-12-21 22:58:24

cnbjmon.dll
0x74200000
C:\WINDOWS\system32\cnbjmon.dll
5.1.2503.0 (Lab06_N.010129-0357)
Microsoft Corporation
Langage Monitor for Canon Bubble-Jet Printer
2003-03-15 08:00:00

CNMLM3y.DLL
0x66f40000
C:\WINDOWS\system32\CNMLM3y.DLL
1.52.2.0
CANON INC.
BJ Language Monitor
2002-02-12 05:00:00

COMCTL32.dll
0x77310000
C:\WINDOWS\system32\comctl32.dll
5.82 (xpsp1.020828-1920)
Microsoft Corporation
Common Controls Library
2003-03-15 08:00:00

pjlmon.dll
0x741e0000
C:\WINDOWS\system32\pjlmon.dll
5.1.2600.0 (XPClient.010817-1148)
Microsoft Corporation
PJL Language monitor
2003-03-15 08:00:00
fengzhejun - 2006-3-14 8:41:00


tcpmon.dll
0x72390000
C:\WINDOWS\system32\tcpmon.dll
5.1.2600.0 (XPClient.010817-1148)
Microsoft Corporation
Standard TCP/IP Port Monitor DLL
2003-03-15 08:00:00

usbmon.dll
0x72380000
C:\WINDOWS\system32\usbmon.dll
5.1.2600.0 (XPClient.010817-1148)
Microsoft Corporation
Standard Dynamic Printing Port Monitor DLL
2003-03-15 08:00:00

CNMPD3y.DLL
0xfe0000
C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD3y.DLL
1.52.2.0
CANON INC.
Canon BJ Print Processor Dispatcher
2002-02-12 05:00:00

cdnns.dll
0xff0000
C:\WINDOWS\system32\cdnns.dll
2, 0, 0, 0
CNNIC
cdnns
2005-06-14 17:07:48

Rnr20.dll
0x723e0000
C:\WINDOWS\system32\rnr20.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket2 NameSpace DLL
2003-03-15 08:00:00

winrnr.dll
0x76f80000
C:\WINDOWS\system32\winrnr.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
LDAP RnR Provider DLL
2003-03-15 08:00:00

WLDAP32.dll
0x76f30000
C:\WINDOWS\system32\wldap32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Win32 LDAP API DLL
2003-03-15 08:00:00

win32spl.dll
0x74210000
C:\WINDOWS\system32\win32spl.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
32-bit Spooler API DLL
2003-03-15 08:00:00

NETRAP.dll
0x71c00000
C:\WINDOWS\system32\netrap.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Net Remote Admin Protocol DLL
2003-03-15 08:00:00

CLBCATQ.DLL
0x76fa0000
C:\WINDOWS\system32\clbcatq.dll
2001.12.4414.42
Microsoft Corporation

2003-03-15 08:00:00

COMRes.dll
0x77020000
C:\WINDOWS\system32\comres.dll
2001.12.4414.42
Microsoft Corporation

2003-03-15 08:00:00

inetpp.dll
0x74260000
C:\WINDOWS\system32\inetpp.dll
5.1.2600.0 (XPClient.010817-1148)
Microsoft Corporation
Internet Print Provider DLL
2003-03-15 08:00:00

icmp.dll
0x741f0000
C:\WINDOWS\system32\icmp.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
ICMP DLL
2003-03-15 08:00:00

iphlpapi.DLL
0x76d30000
C:\WINDOWS\system32\iphlpapi.dll
5.1.2600.2 (xpsp1.020828-1920)
Microsoft Corporation
IP Helper API
2003-03-15 08:00:00




[RavStub.exe]
PID = 0x54c
CommandLine = "C:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND
RavStub.exe
0x400000
C:\Program Files\Rising\Rav\RavStub.exe
18, 0, 0, 12
Beijing Rising Technology Co., Ltd.
Rising RavStub
2006-01-19 14:47:06

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
NT Layer DLL
2003-03-15 08:00:00

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2003-03-15 08:00:00

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP USER API Client DLL
2003-03-15 08:00:00

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2003-03-15 08:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2003-03-15 08:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Procedure Call Runtime
2003-03-15 08:00:00

NETAPI32.dll
0x71ba0000
C:\WINDOWS\system32\netapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Net Win32 API DLL
2003-03-15 08:00:00

msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2003-03-15 08:00:00

USERENV.dll
0x759d0000
C:\WINDOWS\system32\userenv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Userenv
2003-03-15 08:00:00

COMCTL32.dll
0x77310000
C:\WINDOWS\system32\comctl32.dll
5.82 (xpsp1.020828-1920)
Microsoft Corporation
Common Controls Library
2003-03-15 08:00:00

IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2003-03-15 08:00:00

LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2003-03-15 08:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2003-03-15 08:00:00

interceptor.dll
0xd50000
C:\WINDOWS\system32\interceptor.dll
1, 0, 0, 29
Tenebril Inc.
API Interceptor
2005-10-25 12:49:18

uxtheme.dll
0x5adc0000
C:\WINDOWS\system32\uxtheme.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft UxTheme Library
2003-03-15 08:00:00

InterceptHelper.dll
0x10000000
C:\WINDOWS\system32\InterceptHelper.dll
1, 0, 0, 29
Tenebril Inc.
Interception Helper
2005-10-25 12:49:14

MSVCP71.dll
0x7c3a0000
C:\WINDOWS\system32\msvcp71.dll
7.10.3077.0
Microsoft Corporation
Microsoft? C++ Runtime Library
2003-03-18 22:14:52

MSVCR71.dll
0x7c340000
C:\WINDOWS\system32\msvcr71.dll
7.10.3052.4
Microsoft Corporation
Microsoft? C Runtime Library
2003-02-21 04:42:22

SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\shlwapi.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2003-03-15 08:00:00

VERSION.dll
0x77bd0000
C:\WINDOWS\system32\version.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Version Checking and File Installation Libraries
2003-03-15 08:00:00

RsCommX.dll
0x8d0000
C:\Program Files\Rising\Rav\RsCommX.dll
18, 0, 0, 1
rising
RsCommX
2006-01-19 14:49:07

RSCOMMON.DLL
0x23700000
C:\Program Files\Rising\Rav\RsCommon.dll
18, 0, 0, 4
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
2006-01-19 14:46:25

perfproc.dll
0x5e8e0000
C:\WINDOWS\system32\perfproc.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows System Process Performance Objects DLL
2003-03-15 08:00:00

winhafn.dll
0xce0000
C:\WINDOWS\system32\winhafn.dll



2005-09-21 12:51:12

winhason.dll
0xcf0000
C:\WINDOWS\system32\winhason.dll



2005-09-15 16:59:54

WSOCK32.dll
0x71a40000
C:\WINDOWS\system32\wsock32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 32-Bit DLL
2003-03-15 08:00:00

WS2_32.dll
0x71a20000
C:\WINDOWS\system32\ws2_32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 32-Bit DLL
2003-03-15 08:00:00

WS2HELP.dll
0x71a10000
C:\WINDOWS\system32\ws2help.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 Helper for Windows NT
2003-03-15 08:00:00

MFC42.DLL
0x73d30000
C:\WINDOWS\system32\mfc42.dll
6.00.8665.0
Microsoft Corporation
MFCDLL Shared Library - Retail Version
2003-03-15 08:00:00

MFC42LOC.DLL
0x61be0000
C:\WINDOWS\system32\mfc42loc.dll
6.00.8665.0
Microsoft Corporation
MFC Language Specific Resources
2003-03-15 08:00:00

winhashn.dll
0xd00000
C:\WINDOWS\system32\winhashn.dll



2005-09-05 16:39:10

MPR.dll
0x71a90000
C:\WINDOWS\system32\mpr.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Multiple Provider Router DLL
2003-03-15 08:00:00

thooks.dll
0xd10000
C:\WINDOWS\system32\THooks.dll
2, 84, 2207, 0

THooks
2000-01-10 20:00:00
fengzhejun - 2006-3-14 8:42:00





[CDANTSRV.EXE]
PID = 0x5cc
CommandLine = C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
CDANTSRV.EXE
0x400000
C:\WINDOWS\system32\drivers\CDANTSRV.EXE
3.23.000
C-Dilla Ltd
C-Dilla RTS Service
2001-04-06 21:24:54

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
NT Layer DLL
2003-03-15 08:00:00

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2003-03-15 08:00:00

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP USER API Client DLL
2003-03-15 08:00:00

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2003-03-15 08:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2003-03-15 08:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Procedure Call Runtime
2003-03-15 08:00:00

IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2003-03-15 08:00:00

LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2003-03-15 08:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2003-03-15 08:00:00

interceptor.dll
0xd50000
C:\WINDOWS\system32\interceptor.dll
1, 0, 0, 29
Tenebril Inc.
API Interceptor
2005-10-25 12:49:18

msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2003-03-15 08:00:00

uxtheme.dll
0x5adc0000
C:\WINDOWS\system32\uxtheme.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft UxTheme Library
2003-03-15 08:00:00

InterceptHelper.dll
0x10000000
C:\WINDOWS\system32\InterceptHelper.dll
1, 0, 0, 29
Tenebril Inc.
Interception Helper
2005-10-25 12:49:14

MSVCP71.dll
0x7c3a0000
C:\WINDOWS\system32\msvcp71.dll
7.10.3077.0
Microsoft Corporation
Microsoft? C++ Runtime Library
2003-03-18 22:14:52

MSVCR71.dll
0x7c340000
C:\WINDOWS\system32\msvcr71.dll
7.10.3052.4
Microsoft Corporation
Microsoft? C Runtime Library
2003-02-21 04:42:22

SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\shlwapi.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2003-03-15 08:00:00

VERSION.dll
0x77bd0000
C:\WINDOWS\system32\version.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Version Checking and File Installation Libraries
2003-03-15 08:00:00




[rundll32.exe]
PID = 0x614
CommandLine = C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087
RUNDLL32.EXE
0x1000000
C:\WINDOWS\system32\rundll32.exe
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Run a DLL as an App
2003-03-15 08:00:00

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
NT Layer DLL
2003-03-15 08:00:00

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2003-03-15 08:00:00

msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2003-03-15 08:00:00

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2003-03-15 08:00:00

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP USER API Client DLL
2003-03-15 08:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2003-03-15 08:00:00
fengzhejun - 2006-3-14 8:42:00


RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Procedure Call Runtime
2003-03-15 08:00:00

IMAGEHLP.dll
0x76c60000
C:\WINDOWS\system32\imagehlp.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT Image Helper
2003-03-15 08:00:00

IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2003-03-15 08:00:00

LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2003-03-15 08:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2003-03-15 08:00:00

interceptor.dll
0xd50000
C:\WINDOWS\system32\interceptor.dll
1, 0, 0, 29
Tenebril Inc.
API Interceptor
2005-10-25 12:49:18

uxtheme.dll
0x5adc0000
C:\WINDOWS\system32\uxtheme.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft UxTheme Library
2003-03-15 08:00:00

InterceptHelper.dll
0x10000000
C:\WINDOWS\system32\InterceptHelper.dll
1, 0, 0, 29
Tenebril Inc.
Interception Helper
2005-10-25 12:49:14

MSVCP71.dll
0x7c3a0000
C:\WINDOWS\system32\msvcp71.dll
7.10.3077.0
Microsoft Corporation
Microsoft? C++ Runtime Library
2003-03-18 22:14:52

MSVCR71.dll
0x7c340000
C:\WINDOWS\system32\msvcr71.dll
7.10.3052.4
Microsoft Corporation
Microsoft? C Runtime Library
2003-02-21 04:42:22

SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\shlwapi.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2003-03-15 08:00:00

VERSION.dll
0x77bd0000
C:\WINDOWS\system32\version.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Version Checking and File Installation Libraries
2003-03-15 08:00:00

IRJIT.DLL
0x760000
C:\WINDOWS\system32\wbem\IRJIT.DLL
5, 1, 2600, 2709
Microsoft Corporation
Microsoft irJIT Module
2004-06-06 13:16:00

SHELL32.dll
0x773a0000
C:\WINDOWS\system32\shell32.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Shell Common Dll
2003-03-15 08:00:00

ole32.dll
0x7a0000
C:\WINDOWS\system32\ole32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft OLE for Windows
2003-03-15 08:00:00

OLEAUT32.dll
0x770f0000
C:\WINDOWS\system32\oleaut32.dll
3.50.5016.0
Microsoft Corporation
Microsoft OLE 3.50  for Windows NT(TM) and Windows 95(TM) Operating Systems
2003-03-15 08:00:00

NETAPI32.dll
0x71ba0000
C:\WINDOWS\system32\netapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Net Win32 API DLL
2003-03-15 08:00:00

WININET.dll
0x76170000
C:\WINDOWS\system32\wininet.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Internet Extensions for Win32
2003-03-15 08:00:00

CRYPT32.dll
0x76230000
C:\WINDOWS\system32\crypt32.dll
5.131.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Crypto API32
2003-03-15 08:00:00

MSASN1.dll
0x76210000
C:\WINDOWS\system32\msasn1.dll
5.1.2600.0 (XPClient.010817-1148)
Microsoft Corporation
ASN.1 Runtime APIs
2003-03-15 08:00:00

USERENV.dll
0x759d0000
C:\WINDOWS\system32\userenv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Userenv
2003-03-15 08:00:00

urlmon.dll
0x76060000
C:\WINDOWS\system32\urlmon.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
OLE32 Extensions for Win32
2003-03-15 08:00:00

comctl32.dll
0x78090000
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
6.0 (xpsp1.020828-1920)
Microsoft Corporation
User Experience Controls Library
2003-03-15 08:00:00

comctl32.dll
0x77310000
C:\WINDOWS\system32\comctl32.dll
5.82 (xpsp1.020828-1920)
Microsoft Corporation
Common Controls Library
2003-03-15 08:00:00




[explorer.exe]
PID = 0x1d0
CommandLine = C:\WINDOWS\Explorer.EXE
Explorer.EXE
0x1000000
C:\WINDOWS\explorer.exe
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Explorer
2003-03-15 08:00:00

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
NT Layer DLL
2003-03-15 08:00:00

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2003-03-15 08:00:00
fengzhejun - 2006-3-14 8:43:00


msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2003-03-15 08:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2003-03-15 08:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Procedure Call Runtime
2003-03-15 08:00:00

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2003-03-15 08:00:00

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP USER API Client DLL
2003-03-15 08:00:00

SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\shlwapi.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2003-03-15 08:00:00

SHELL32.dll
0x773a0000
C:\WINDOWS\system32\shell32.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Shell Common Dll
2003-03-15 08:00:00

ole32.dll
0x2c0000
C:\WINDOWS\system32\ole32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft OLE for Windows
2003-03-15 08:00:00

OLEAUT32.dll
0x770f0000
C:\WINDOWS\system32\oleaut32.dll
3.50.5016.0
Microsoft Corporation
Microsoft OLE 3.50  for Windows NT(TM) and Windows 95(TM) Operating Systems
2003-03-15 08:00:00

BROWSEUI.dll
0x75ef0000
C:\WINDOWS\system32\browseui.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Browser UI Library
2003-03-15 08:00:00

SHDOCVW.dll
0x76990000
C:\WINDOWS\system32\shdocvw.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Doc Object and Control Library
2003-03-15 08:00:00

UxTheme.dll
0x5adc0000
C:\WINDOWS\system32\uxtheme.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft UxTheme Library
2003-03-15 08:00:00

IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2003-03-15 08:00:00

LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2003-03-15 08:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2003-03-15 08:00:00

interceptor.dll
0xd50000
C:\WINDOWS\system32\interceptor.dll
1, 0, 0, 29
Tenebril Inc.
API Interceptor
2005-10-25 12:49:18

comctl32.dll
0x78090000
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
6.0 (xpsp1.020828-1920)
Microsoft Corporation
User Experience Controls Library
2003-03-15 08:00:00

comctl32.dll
0x77310000
C:\WINDOWS\system32\comctl32.dll
5.82 (xpsp1.020828-1920)
Microsoft Corporation
Common Controls Library
2003-03-15 08:00:00

InterceptHelper.dll
0x10000000
C:\WINDOWS\system32\InterceptHelper.dll
1, 0, 0, 29
Tenebril Inc.
Interception Helper
2005-10-25 12:49:14

MSVCP71.dll
0x7c3a0000
C:\WINDOWS\system32\msvcp71.dll
7.10.3077.0
Microsoft Corporation
Microsoft? C++ Runtime Library
2003-03-18 22:14:52

MSVCR71.dll
0x7c340000
C:\WINDOWS\system32\msvcr71.dll
7.10.3052.4
Microsoft Corporation
Microsoft? C Runtime Library
2003-02-21 04:42:22

VERSION.dll
0x77bd0000
C:\WINDOWS\system32\version.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Version Checking and File Installation Libraries
2003-03-15 08:00:00

msctfime.ime
0xa80000
C:\WINDOWS\system32\MSCTFIME.IME
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft Text Frame Work Service IME
2003-03-15 08:00:00

appHelp.dll
0x75eb0000
C:\WINDOWS\system32\apphelp.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Application Compatibility Client Library
2003-03-15 08:00:00

CLBCATQ.DLL
0x76fa0000
C:\WINDOWS\system32\clbcatq.dll
2001.12.4414.42
Microsoft Corporation

2003-03-15 08:00:00

COMRes.dll
0x77020000
C:\WINDOWS\system32\comres.dll
2001.12.4414.42
Microsoft Corporation

2003-03-15 08:00:00

cscui.dll
0x76590000
C:\WINDOWS\system32\cscui.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Client Side Caching UI
2003-03-15 08:00:00

CSCDLL.dll
0x76570000
C:\WINDOWS\system32\cscdll.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Offline Network Agent
2003-03-15 08:00:00

themeui.dll
0x5b680000
C:\WINDOWS\system32\themeui.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Theme API
2003-03-15 08:00:00

Secur32.dll
0x76f60000
C:\WINDOWS\system32\secur32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Security Support Provider Interface
2003-03-15 08:00:00

MSIMG32.dll
0x762f0000
C:\WINDOWS\system32\msimg32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDIEXT Client DLL
2003-03-15 08:00:00

USERENV.dll
0x759d0000
C:\WINDOWS\system32\userenv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Userenv
2003-03-15 08:00:00

Msimtf.dll
0x74650000
C:\WINDOWS\system32\MSIMTF.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Active IMM Server DLL
2003-03-15 08:00:00

MSCTF.dll
0x74680000
C:\WINDOWS\system32\MSCTF.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
MSCTF Server DLL
2003-03-15 08:00:00

actxprxy.dll
0x71cc0000
C:\WINDOWS\system32\actxprxy.dll
6.00.2600.0000 (XPClient.010817-1148)
Microsoft Corporation
ActiveX Interface Marshaling Library
2003-03-15 08:00:00

msutb.dll
0x5fe40000
C:\WINDOWS\system32\msutb.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
MSUTB Server DLL
2003-03-15 08:00:00

netapi32.dll
0x71ba0000
C:\WINDOWS\system32\netapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Net Win32 API DLL
2003-03-15 08:00:00

LINKINFO.dll
0x76950000
C:\WINDOWS\system32\linkinfo.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Volume Tracking
2003-03-15 08:00:00

ntshrui.dll
0x76960000
C:\WINDOWS\system32\ntshrui.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell extensions for sharing
2003-03-15 08:00:00

ATL.DLL
0x76af0000
C:\WINDOWS\system32\atl.dll
3.00.9435
Microsoft Corporation
ATL Module for Windows NT (Unicode)
2003-03-15 08:00:00

winhafn.dll
0xc10000
C:\WINDOWS\system32\winhafn.dll



2005-09-21 12:51:12
fengzhejun - 2006-3-14 8:43:00


winhason.dll
0xc20000
C:\WINDOWS\system32\winhason.dll



2005-09-15 16:59:54

WSOCK32.dll
0x71a40000
C:\WINDOWS\system32\wsock32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 32-Bit DLL
2003-03-15 08:00:00

WS2_32.dll
0x71a20000
C:\WINDOWS\system32\ws2_32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 32-Bit DLL
2003-03-15 08:00:00

WS2HELP.dll
0x71a10000
C:\WINDOWS\system32\ws2help.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 Helper for Windows NT
2003-03-15 08:00:00

MFC42.DLL
0x73d30000
C:\WINDOWS\system32\mfc42.dll
6.00.8665.0
Microsoft Corporation
MFCDLL Shared Library - Retail Version
2003-03-15 08:00:00

MFC42LOC.DLL
0x61be0000
C:\WINDOWS\system32\mfc42loc.dll
6.00.8665.0
Microsoft Corporation
MFC Language Specific Resources
2003-03-15 08:00:00

winhashn.dll
0xc40000
C:\WINDOWS\system32\winhashn.dll



2005-09-05 16:39:10

MPR.dll
0x71a90000
C:\WINDOWS\system32\mpr.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Multiple Provider Router DLL
2003-03-15 08:00:00

thooks.dll
0xc50000
C:\WINDOWS\system32\THooks.dll
2, 84, 2207, 0

THooks
2000-01-10 20:00:00

SETUPAPI.dll
0x765e0000
C:\WINDOWS\system32\setupapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Setup API
2003-03-15 08:00:00

msow32cn.dll
0xc80000
C:\WINDOWS\system32\MSOW32CN.DLL
2, 84, 2207, 0

OWatcher Module
2000-01-10 20:00:00

NETSHELL.dll
0x75c60000
C:\WINDOWS\system32\netshell.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Network Connections Shell
2003-03-15 08:00:00

credui.dll
0x76bd0000
C:\WINDOWS\system32\credui.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Credential Manager User Interface
2003-03-15 08:00:00

iphlpapi.dll
0x76d30000
C:\WINDOWS\system32\iphlpapi.dll
5.1.2600.2 (xpsp1.020828-1920)
Microsoft Corporation
IP Helper API
2003-03-15 08:00:00

RavExt.dll
0x11d0000
C:\WINDOWS\system32\RavExt.dll
18, 0, 0, 13
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
2006-01-19 14:46:25

urlmon.dll
0x76060000
C:\WINDOWS\system32\urlmon.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
OLE32 Extensions for Win32
2003-03-15 08:00:00

msi.dll
0x19b0000
C:\WINDOWS\system32\msi.dll
2.0.2600.1106
Microsoft Corporation
Windows Installer
2003-03-15 08:00:00

cdnspie.dll
0x12c0000
C:\Program Files\CNNIC\Cdn\cdnspie.dll
2, 1, 0, 0

cdnspie
2006-02-21 11:10:21

imaoe.dll
0x12f0000
C:\Program Files\CNNIC\Cdn\imaoe.dll
2, 2, 0, 1
CNNIC
CNNIC IDN Mail for Windows
2006-02-21 11:10:17

cdnforie.dll
0x1310000
C:\Program Files\CNNIC\Cdn\cdnforie.dll
1, 0, 0, 6
CNNIC
CdnForIE
2006-03-04 08:46:07

WININET.dll
0x76170000
C:\WINDOWS\system32\wininet.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Internet Extensions for Win32
2003-03-15 08:00:00

CRYPT32.dll
0x76230000
C:\WINDOWS\system32\crypt32.dll
5.131.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Crypto API32
2003-03-15 08:00:00

MSASN1.dll
0x76210000
C:\WINDOWS\system32\msasn1.dll
5.1.2600.0 (XPClient.010817-1148)
Microsoft Corporation
ASN.1 Runtime APIs
2003-03-15 08:00:00

cdndet.dll
0x14f0000
C:\Program Files\CNNIC\Cdn\cdndet.dll
2, 2, 0, 3
CNNIC
cdndet
2006-03-04 08:46:06

Yhelper.dll
0x53000000
C:\Program Files\Yahoo!\Assistant\yhelper.dll
2, 0, 0, 1013

Helper Module
2005-11-14 19:34:30

WINSTA.dll
0x762d0000
C:\WINDOWS\system32\winsta.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Winstation Library
2003-03-15 08:00:00

shlcn32.dll
0x2010000
C:\WINDOWS\system32\shlcn32.dll
2, 84, 2207, 0

shlcn32 DLL
2006-02-07 17:34:26

WINSPOOL.DRV
0x72f70000
C:\WINDOWS\system32\winspool.drv
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Spooler Driver
2003-03-15 08:00:00

winimhs.dll
0x2080000
C:\WINDOWS\system32\winimhs.dll
2, 83, 1110, 0

winimhs DLL
2005-11-10 18:04:36

winimhc.dll
0x20b0000
C:\WINDOWS\system32\winimhc.dll
2, 83, 1110, 0

winimhc DLL
2005-11-10 18:04:16

OLEACC.dll
0x74be0000
C:\WINDOWS\system32\oleacc.dll
4.2.5406.0 (xpclient.010817-1148)
Microsoft Corporation
Active Accessibility Core Component
2003-03-15 08:00:00

MSVCP60.dll
0x75ff0000
C:\WINDOWS\system32\msvcp60.dll
6.00.8972.0
Microsoft Corporation
Microsoft (R) C++ Runtime Library
2003-03-15 08:00:00
fengzhejun - 2006-3-14 8:43:00



YAlive.dll
0x2110000
C:\Program Files\Yahoo!\Assistant\YAlive.dll
2, 0, 4, 1030

YAlive Module
2005-11-14 19:35:24

webcheck.dll
0x74a90000
C:\WINDOWS\system32\webcheck.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Web Site Monitor
2003-03-15 08:00:00

stobject.dll
0x74a60000
C:\WINDOWS\system32\stobject.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Systray shell service object
2003-03-15 08:00:00

BatMeter.dll
0x74a50000
C:\WINDOWS\system32\batmeter.dll
6.00.2600.0000 (xpclient.010817-1148)
Microsoft Corporation
Battery Meter Helper DLL
2003-03-15 08:00:00

POWRPROF.dll
0x74a30000
C:\WINDOWS\system32\powrprof.dll
6.00.2600.0000 (xpclient.010817-1148)
Microsoft Corporation
Power Profile Helper DLL
2003-03-15 08:00:00

WTSAPI32.dll
0x76f20000
C:\WINDOWS\system32\wtsapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Terminal Server SDK APIs
2003-03-15 08:00:00

WINMM.dll
0x76b10000
C:\WINDOWS\system32\winmm.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
MCI API DLL
2003-03-15 08:00:00

WINTRUST.dll
0x76c00000
C:\WINDOWS\system32\wintrust.dll
5.131.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Trust Verification APIs
2003-03-15 08:00:00

IMAGEHLP.dll
0x76c60000
C:\WINDOWS\system32\imagehlp.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT Image Helper
2003-03-15 08:00:00

rsaenh.dll
0xffd0000
C:\WINDOWS\system32\rsaenh.dll
5.1.2600.1029 (xpsp1.020426-1800)
Microsoft Corporation
Microsoft Base Cryptographic Provider
2003-03-15 08:00:00

msgsc.dll
0x750d0000
C:\Program Files\Messenger\msgsc.dll
4.7.3000
Microsoft Corporation
Messenger Service
2004-08-16 16:51:00

SXS.DLL
0x75e00000
C:\WINDOWS\system32\sxs.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Fusion 2.5
2003-03-15 08:00:00

printui.dll
0x74ae0000
C:\WINDOWS\system32\printui.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Print UI DLL
2003-03-15 08:00:00

ACTIVEDS.dll
0x76e10000
C:\WINDOWS\system32\activeds.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
ADs Router Layer DLL
2003-03-15 08:00:00

adsldpc.dll
0x76de0000
C:\WINDOWS\system32\adsldpc.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
ADs LDAP Provider C DLL
2003-03-15 08:00:00

WLDAP32.dll
0x76f30000
C:\WINDOWS\system32\wldap32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Win32 LDAP API DLL
2003-03-15 08:00:00

CFGMGR32.dll
0x74a40000
C:\WINDOWS\system32\cfgmgr32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Configuration Manager Forwarder DLL
2003-03-15 08:00:00

PDFShell.dll
0x1540000
D:\Adobe\Acrobat 7.0\ActiveX\pdfshell.dll
7.0.0.0
Adobe Systems, Inc.
PDF Shell Extension
2004-12-14 02:20:02

PDFShell.CHS
0x15d0000
D:\Adobe\Acrobat 7.0\ActiveX\pdfshell.CHS
7.0.0.0
Adobe Systems, Inc.
PDF Shell Extension
2004-12-21 23:00:20

drprov.dll
0x75ed0000
C:\WINDOWS\system32\drprov.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Terminal Server Network Provider
2003-03-15 08:00:00

ntlanman.dll
0x71b90000
C:\WINDOWS\system32\ntlanman.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft(R) Lan Manager
2003-03-15 08:00:00

NETUI0.dll
0x71c50000
C:\WINDOWS\system32\netui0.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
NT LM UI Common Code - GUI Classes
2003-03-15 08:00:00

NETUI1.dll
0x71c10000
C:\WINDOWS\system32\netui1.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
NT LM UI Common Code - Networking classes
2003-03-15 08:00:00

NETRAP.dll
0x71c00000
C:\WINDOWS\system32\netrap.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Net Remote Admin Protocol DLL
2003-03-15 08:00:00

SAMLIB.dll
0x71b70000
C:\WINDOWS\system32\samlib.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
SAM Library DLL
2003-03-15 08:00:00

davclnt.dll
0x75ee0000
C:\WINDOWS\system32\davclnt.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Web DAV Client DLL
2003-03-15 08:00:00

shdoclc.dll
0x760e0000
C:\WINDOWS\system32\shdoclc.dll
6.00.2600.0000 (xpclient.010817-1148)
Microsoft Corporation
Shell Doc Object and Control Library
2003-03-15 08:00:00

asfsipc.dll
0x70f20000
C:\WINDOWS\system32\asfsipc.dll
1.1.00.3917
Microsoft Corporation
ASFSipc Object
2003-03-15 08:00:00

MSISIP.DLL
0x60820000
C:\WINDOWS\system32\msisip.dll
2.0.2600.0
Microsoft Corporation
MSI Signature SIP Provider
2003-03-15 08:00:00
fengzhejun - 2006-3-14 8:44:00


wshext.dll
0x74e00000
C:\WINDOWS\system32\wshext.dll
5.6.0.6626
Microsoft Corporation
Microsoft (r) Shell Extension for Windows Script Host
2003-03-15 08:00:00

comdlg32.dll
0x76320000
C:\WINDOWS\system32\comdlg32.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Common Dialogs DLL
2003-03-15 08:00:00

wshCHS.DLL
0x58a30000
C:\WINDOWS\system32\wshchs.dll
5.6.0.6626
Microsoft Corporation
Microsoft (r) Windows Script Host International Resources
2003-03-15 08:00:00




[acrotray.exe]
PID = 0x63c
CommandLine = "D:\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
Acrotray.exe
0x400000
D:\Adobe\Acrobat 7.0\Distillr\acrotray.exe
6.0.1.2004121400
Adobe Systems Inc.
AcroTray
2004-12-14 02:12:02

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
NT Layer DLL
2003-03-15 08:00:00

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2003-03-15 08:00:00

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP USER API Client DLL
2003-03-15 08:00:00

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2003-03-15 08:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2003-03-15 08:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Remote Procedure Call Runtime
2003-03-15 08:00:00

WINSPOOL.DRV
0x72f70000
C:\WINDOWS\system32\winspool.drv
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Spooler Driver
2003-03-15 08:00:00

msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2003-03-15 08:00:00

SHELL32.dll
0x773a0000
C:\WINDOWS\system32\shell32.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Shell Common Dll
2003-03-15 08:00:00

SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\shlwapi.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2003-03-15 08:00:00

COMCTL32.dll
0x77310000
C:\WINDOWS\system32\comctl32.dll
5.82 (xpsp1.020828-1920)
Microsoft Corporation
Common Controls Library
2003-03-15 08:00:00

OLEACC.dll
0x74be0000
C:\WINDOWS\system32\oleacc.dll
4.2.5406.0 (xpclient.010817-1148)
Microsoft Corporation
Active Accessibility Core Component
2003-03-15 08:00:00

MSVCP60.dll
0x75ff0000
C:\WINDOWS\system32\msvcp60.dll
6.00.8972.0
Microsoft Corporation
Microsoft (R) C++ Runtime Library
2003-03-15 08:00:00

ole32.dll
0x480000
C:\WINDOWS\system32\ole32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft OLE for Windows
2003-03-15 08:00:00

OLEAUT32.dll
0x770f0000
C:\WINDOWS\system32\oleaut32.dll
3.50.5016.0
Microsoft Corporation
Microsoft OLE 3.50  for Windows NT(TM) and Windows 95(TM) Operating Systems
2003-03-15 08:00:00

comdlg32.dll
0x76320000
C:\WINDOWS\system32\comdlg32.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Common Dialogs DLL
2003-03-15 08:00:00

IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2003-03-15 08:00:00

LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2003-03-15 08:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2003-03-15 08:00:00

interceptor.dll
0xd50000
C:\WINDOWS\system32\interceptor.dll
1, 0, 0, 29
Tenebril Inc.
API Interceptor
2005-10-25 12:49:18

comctl32.dll
0x78090000
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
6.0 (xpsp1.020828-1920)
Microsoft Corporation
User Experience Controls Library
2003-03-15 08:00:00
不言放弃 - 2006-3-14 8:45:00
【回复“fengzhejun”的帖子】
晕死
楼主想干什么啊?

C:\Program Files\Rising\就是瑞星的安装文件夹
fengzhejun - 2006-3-14 8:53:00
【回复“不言放弃”的帖子】
对不起!我想叫高手分析一下我的进程,可是太多了,我上传不了,想问有没有好的方法,直接复制一下。我用卡卡导出进程信息的。谢谢拉!
1
查看完整版本: 请高手帮我看看附件中进程哪个是监控的?谢谢!