瑞星卡卡安全论坛
玉雪飘零 - 2007-11-17 11:52:00
Trojan.upack113895是不是病毒,怎么样查杀?我的机器中了这个后,后退键不能使用,隐藏文件找不到,怎么办,高手执教
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
yangyue781 - 2007-11-17 12:45:00
一个名字就是呀!哪有这么多数字的文件呀!!!
用360试试吧
火影忍者 - 2007-11-17 12:49:00
下载 System Repair Engineer,
http://www.kztechs.com/sreng/download.html
1 解压缩sreng2.zip
2 运行SREngPS.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
玉雪飘零 - 2007-11-17 13:47:00
谢谢你们了
玉雪飘零 - 2007-11-17 13:59:00
[CODE]
2007-11-17,13:37:06
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
<High Definition Audio Property Page Shortcut><CHDAudPropShortcut.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<EnergyUtility><C:\Program Files\Lenovo\EnergyCut\utilty.exe> [TODO: <Company name>]
<EnergyCut><C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe> []
<QkOnBtn><C:\PROGRA~1\QBU\QkOnBtn.EXE> [Dritek System Inc.]
<SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<igfxtray><C:\WINDOWS\system32\igfxtray.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<igfxhkcmd><C:\WINDOWS\system32\hkcmd.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<igfxpers><C:\WINDOWS\system32\igfxpers.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<SmartAudio><C:\Program Files\CONEXANT\SmartAudio\SmartAudio.exe -c> [Conexant]
<RemoteControl><"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"> [Cyberlink Corp.]
<AnyComm_IncTray><"C:\Program Files\Lenovo\IGRS EasyShare\IncTray.exe"> [联想集团有限公司]
<IgrsPortal><"C:\Program Files\Lenovo\IGRS EasyShare\IgrsPortal.exe"> [Lenovo Group Limited]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<runeip><"C:\Program Files\Rising\AntiSpyware\runiep.exe" /startup> [Beijing Rising Technology Co., Ltd.]
<svchostzamj><C:\WINDOWS\system32\svchostzamj.exe> []
<WinSysM><C:\WINDOWS\IGM.exe> [N/A]
<Windows木马防火墙><D:\新建文件夹\an zhuang wei zhi\Trojanwall.exe> [风云谷]
<AVPSrv><C:\WINDOWS\AVPSrv.exE> [N/A]
<TrojanScanner><D:\新建文件夹 (2)\Trojan Remover\Trjscan.exe> [(Verified)Simply Super Software]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<KKDelay><C:\Program Files\Rising\AntiSpyware\RunOnce.exe> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<MSDEG32><LYLoader.exe> [N/A]
<MSDWG32><LYLoadbr.exe> [N/A]
<MSDCG32 ><LYLeador.exe> [N/A]
<MSDOG32><LYLoador.exe> [N/A]
<MSDSG32><LYLoadar.exe> [N/A]
<MSDMG32><LYLoadmr.exe> []
<MSDHG32><LYLoadhr.exe> [N/A]
<MSDQG32><LYLoadqr.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
<{990220B1-A1E6-42dd-9A94-2569E9C62A76}><C:\WINDOWS\system32\GUIMon02.dll> []
<{52B1B604-A461-42e0-9801-BE06A5B05362}><C:\WINDOWS\system32\SVCCtrl02.dll> []
<{D66DEF5B-BD09-4a7d-90A5-17FC9294322D}><C:\WINDOWS\system32\SQLLink02.dll> []
<{479C68D6-39CE-46a7-9D35-717561CF875B}><C:\WINDOWS\system32\BoldShl02.dll> []
<{A2AC7E3B-30BE-466f-8BAB-1FF9DADD8C7D}><C:\WINDOWS\system32\KVBatch01.dll> []
<{DF228CA0-1286-4228-A713-D56082FD03D1}><C:\WINDOWS\system32\BugReport02.dll> []
<{BE962490-5F61-4a5a-862B-14FA2E295024}><C:\WINDOWS\system32\MediaDrv01.dll> []
<{4DF4F122-943D-40f8-B3F2-72BD70E60D6C}><C:\WINDOWS\system32\ProcSvr01.dll> []
<{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
<WinlogonNotify: igfxcui><igfxdev.dll> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
玉雪飘零 - 2007-11-17 14:00:00
启动文件夹
[Adobe Reader Speed Launch]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk --> C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [Adobe Systems Incorporated]><N>
==================================
服务
[3707923F / 3707923F][Stopped/Auto Start]
<C:\WINDOWS\system32\88E80AD0.EXE -k><Microsoft Corporation>
[C-DillaCdaC11BA / C-DillaCdaC11BA][Running/Auto Start]
<C:\WINDOWS\system32\drivers\CDAC11BA.EXE><Macrovision>
[General Updater/AutoUpdater Service / GUA][Running/Auto Start]
<"C:\Program Files\lenovo\GUA\GUA.exe"><lenovo>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[IGRS / IGRS][Running/Auto Start]
<C:\Program Files\Lenovo\IGRS\IGRS.exe><联想集团有限公司>
[IGRSFILE / IGRSFILE][Running/Auto Start]
<C:\Program Files\lenovo\IGRS Profiles\File Profile\IgrsFile.exe><Lenovo Group Limited>
[IgrsFileShare / IgrsFileShare][Running/Auto Start]
<"C:\Program Files\Lenovo\IGRS EasyShare\FileShare.exe"><联想集团有限公司>
[IgrsMonitor / IgrsMonitor][Running/Auto Start]
<C:\WINDOWS\System32\IgrsSvcs.exe -k IgrsSvcs-->C:\Program Files\Lenovo\IGRS\Ext\IgrsMonitor.dll><联想集团有限公司>
[Intelligent Network Config / IncSvc][Running/Auto Start]
<C:\WINDOWS\System32\IgrsSvcs.exe -k IgrsSvcs-->C:\Program Files\Lenovo\IGRS\Ext\IncSvc.dll><联想集团有限公司>
[MicroGrid DirectRouter / MicroGrid.DirectRouter][Running/Auto Start]
<C:\WINDOWS\System32\IgrsSvcs.exe -k IgrsSvcs-->C:\Program Files\Lenovo\IGRS\Ext\router.dll><联想集团有限公司>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"D:\ruixing\瑞星安装位置\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon][Running/Auto Start]
<"D:\ruixing\瑞星安装位置\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
玉雪飘零 - 2007-11-17 14:00:00
驱动程序
[Lenovo Virtual Power Controller Driver / ACPIVPC][Running/Manual Start]
<system32\DRIVERS\AcpiVpc.sys><Lenovo Corporation>
[Broadcom 440x 10/100 Integrated Controller XP Driver / bcm4sbxp][Running/Manual Start]
<system32\DRIVERS\bcm4sbxp.sys><Broadcom Corporation>
[bootdrv / bootdrv][Running/Boot Start]
<\SystemRoot\System32\Drivers\bootdrv.sys><>
[CdaC15BA / CdaC15BA][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\CDAC15BA.SYS><Macrovision Europe Ltd>
[Serial Filter Driver / DiagSerial][Running/Manual Start]
<system32\DRIVERS\Geuf.sys><Elan Digital Systems Ltd>
[Dritek Keyboard Filter Driver / DKbFltr][Running/Manual Start]
<system32\DRIVERS\DKbFltr.sys><Dritek System Inc.>
[ExpScaner / ExpScaner][Stopped/Auto Start]
<\??\D:\ruixing\瑞星安装位置\Rising\Rav\ExpScan.sys><>
[Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService][Running/Manual Start]
<system32\drivers\CHDAud.sys><Conexant Systems Inc.>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HookCont / HookCont][Running/Auto Start]
<\??\D:\ruixing\瑞星安装位置\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\D:\ruixing\瑞星安装位置\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\D:\ruixing\瑞星安装位置\Rising\Rav\HookSys.sys><Rising>
[HSFHWAZL / HSFHWAZL][Running/Manual Start]
<system32\DRIVERS\HSFHWAZL.sys><Conexant Systems, Inc.>
[HSF_DPV / HSF_DPV][Running/Manual Start]
<system32\DRIVERS\HSF_DPV.sys><Conexant Systems, Inc.>
[ialm / ialm][Running/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[mdmxsdk / mdmxsdk][Running/Auto Start]
<system32\DRIVERS\mdmxsdk.sys><Conexant>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\D:\ruixing\瑞星安装位置\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Serial Driver / RasDialSerial][Running/Manual Start]
<system32\DRIVERS\Geserial.sys><Windows (R) 2000 DDK provider>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
<\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Stopped/Auto Start]
<\??\D:\ruixing\瑞星安装位置\Rising\Rav\RSPPSYS.sys><Rising>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
<system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[tifm21 / tifm21][Running/Manual Start]
<system32\drivers\tifm21.sys><Texas Instruments>
[Conexant Setup API / UIUSys][Stopped/Manual Start]
<system32\DRIVERS\UIUSYS.SYS><Conexant Systems, Inc>
[winachsf / winachsf][Running/Manual Start]
<system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
[Wireless Monitor & Config Protocol Driver / WMCDRV][Running/Auto Start]
<system32\DRIVERS\wmcdrv.sys><Lenovo Group Limited>
玉雪飘零 - 2007-11-17 14:03:00
浏览器加载项
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[联想]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.lenovo.com, N/A>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[闪联任意通]
{0C9B3AB9-DEDF-11D8-A2D4-0050FC464B19} <C:\Program Files\Lenovo\IGRS EasyShare\IgrsAnywhere.dll, 联想集团有限公司>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[闪联任意通]
{0C9B3AB9-DEDF-11D8-A2D4-0050FC464B19} <C:\Program Files\Lenovo\IGRS EasyShare\IgrsAnywhere.dll, 联想集团有限公司>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[XML Document]
{48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\flash.ocx, Macromedia, Inc.>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
==================================
正在运行的进程
[PID: 412 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 464 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 676 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 720 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 732 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 884 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 960 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 1000 / SYSTEM][D:\ruixing\瑞星安装位置\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 1016 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 1108 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 1136 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 1152 / SYSTEM][D:\ruixing\瑞星安装位置\Rising\Rav\Ravmond.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 43]
[D:\ruixing\瑞星安装位置\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[D:\ruixing\瑞星安装位置\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[D:\ruixing\瑞星安装位置\Rising\Rav\rfwctrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\ruixing\瑞星安装位置\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[D:\ruixing\瑞星安装位置\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[D:\ruixing\瑞星安装位置\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\ruixing\瑞星安装位置\Rising\Rav\RsLog.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 1396 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\cad\AutoCAD2004\AcSignIcon.dll] [Autodesk, 16.0.0.86]
[C:\Program Files\Lenovo\IGRS EasyShare\IgrsAnywhere.dll] [联想集团有限公司, 1, 0, 2, 65]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\WINDOWS\system32\GUIMon01.dll] [N/A, ]
[C:\WINDOWS\system32\SVCCtrl02.dll] [N/A, ]
[C:\WINDOWS\system32\SQLLink01.dll] [N/A, ]
[C:\WINDOWS\system32\BoldShl01.dll] [N/A, ]
[C:\WINDOWS\system32\KVBatch01.dll] [N/A, ]
[C:\WINDOWS\system32\BugReport02.dll] [N/A, ]
[C:\WINDOWS\system32\MediaDrv02.dll] [N/A, ]
[C:\WINDOWS\system32\ProcSvr01.dll] [N/A, ]
[C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\cad\AutoCAD2004\AcSignCore16.dll] [Autodesk, 16.0.0.86]
[C:\WINDOWS\system32\zamjdll.DLL] [N/A, ]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\WINDOWS\136741MM.DLL] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\zamjhook.dll] [N/A, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\Program Files\Lenovo\EnergyCut\HookLib.dll] [N/A, ]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4543]
[D:\ruixing\瑞星安装位置\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\WINDOWS\system32\LYMANGR.DLL] [N/A, ]
[C:\WINDOWS\system32\GUIMon02.dll] [N/A, ]
[C:\WINDOWS\system32\GenProtect.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\SQLLink02.dll] [N/A, ]
[C:\WINDOWS\system32\BoldShl02.dll] [N/A, ]
[C:\WINDOWS\system32\yjmtny.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\MsPrint32D.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\MediaDrv01.dll] [N/A, ]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[D:\新建文~2\TROJAN~1\Trshlex.dll] [Simply Super Software, 1.0.5.34]
[D:\新建文~1\ANZHUA~1\FTCCOM~1.DLL] [Fygsoft and Microsoft, 3.0.0.71]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.7.2006011200]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
玉雪飘零 - 2007-11-17 14:04:00
WINDOWS\system32\RunDLL32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SVCCtrl02.dll] [N/A, ]
[C:\WINDOWS\system32\ProcSvr01.dll] [N/A, ]
[C:\WINDOWS\system32\BugReport02.dll] [N/A, ]
[C:\WINDOWS\system32\KVBatch01.dll] [N/A, ]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\WINDOWS\system32\GenProtect.dll] [N/A, ]
[C:\WINDOWS\system32\GUIMon02.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\BoldShl02.dll] [N/A, ]
[C:\WINDOWS\system32\SQLLink02.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\yjmtny.dll] [N/A, ]
[C:\WINDOWS\system32\MediaDrv01.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\MsPrint32D.dll] [N/A, ]
[PID: 1444 / Administrator][C:\WINDOWS\system32\RunDLL32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\KVBatch01.dll] [N/A, ]
[C:\WINDOWS\system32\SVCCtrl02.dll] [N/A, ]
[C:\WINDOWS\system32\ProcSvr01.dll] [N/A, ]
[C:\WINDOWS\system32\BugReport02.dll] [N/A, ]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\WINDOWS\system32\GenProtect.dll] [N/A, ]
[C:\WINDOWS\system32\GUIMon02.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\BoldShl02.dll] [N/A, ]
[C:\WINDOWS\system32\SQLLink02.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\yjmtny.dll] [N/A, ]
[C:\WINDOWS\system32\MediaDrv01.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\MsPrint32D.dll] [N/A, ]
[PID: 1452 / Administrator][C:\WINDOWS\system32\RunDLL32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\BugReport02.dll] [N/A, ]
[C:\WINDOWS\system32\SVCCtrl02.dll] [N/A, ]
[C:\WINDOWS\system32\ProcSvr01.dll] [N/A, ]
[C:\WINDOWS\system32\KVBatch01.dll] [N/A, ]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\WINDOWS\system32\GenProtect.dll] [N/A, ]
[C:\WINDOWS\system32\GUIMon02.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\BoldShl02.dll] [N/A, ]
[C:\WINDOWS\system32\SQLLink02.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\yjmtny.dll] [N/A, ]
[C:\WINDOWS\system32\MediaDrv01.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\MsPrint32D.dll] [N/A, ]
[PID: 1472 / Administrator][C:\WINDOWS\system32\RunDLL32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ProcSvr01.dll] [N/A, ]
[C:\WINDOWS\system32\SVCCtrl02.dll] [N/A, ]
[C:\WINDOWS\system32\BugReport02.dll] [N/A, ]
[C:\WINDOWS\system32\KVBatch01.dll] [N/A, ]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\WINDOWS\system32\GenProtect.dll] [N/A, ]
[C:\WINDOWS\system32\GUIMon02.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\BoldShl02.dll] [N/A, ]
[C:\WINDOWS\system32\SQLLink02.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\yjmtny.dll] [N/A, ]
[C:\WINDOWS\system32\MediaDrv01.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\MsPrint32D.dll] [N/A, ]
[PID: 1660 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.1897.0]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.1897.0]
[PID: 1852 / SYSTEM][C:\WINDOWS\system32\drivers\CDAC11BA.EXE] [Macrovision, 4.20.020]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 1884 / SYSTEM][C:\Program Files\lenovo\GUA\GUA.exe] [lenovo, 1.0.0.21]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 1904 / SYSTEM][C:\Program Files\Lenovo\IGRS\IGRS.exe] [联想集团有限公司, 1.0.1.217]
[C:\Program Files\Lenovo\IGRS\framework.dll] [联想集团有限公司, 1.0.1.217]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Lenovo\IGRS\ReliablePlugin.dll] [联想集团有限公司, 1.0.1.217]
[C:\Program Files\Lenovo\IGRS\CorePlugin.dll] [联想集团有限公司, 1.0.1.217]
[C:\Program Files\Lenovo\IGRS\SocketPlugin.dll] [联想集团有限公司, 1.0.1.217]
[C:\Program Files\Lenovo\IGRS\BTComPlugin.dll] [联想集团有限公司, 1.0.1.217]
[C:\Program Files\Lenovo\IGRS\SerialPortMonitor.dll] [lenovo, 1, 0, 1, 19]
[C:\Program Files\Lenovo\IGRS\ProxyPlugin.dll] [联想集团有限公司, 1.0.1.217]
[C:\Program Files\Lenovo\IGRS\SvcHostPlugin.dll] [联想集团有限公司, 1.0.1.217]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 1924 / SYSTEM][C:\WINDOWS\System32\IgrsSvcs.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\program files\lenovo\igrs\ext\igrsmonitor.dll] [联想集团有限公司, 1, 2, 1, 21]
[C:\WINDOWS\system32\IgrsApi.dll] [Lenovo Group Limited, 1.0.1.195]
[c:\program files\lenovo\igrs\ext\incsvc.dll] [联想集团有限公司, 1, 0, 1, 14]
[C:\WINDOWS\system32\wmcdrv.dll] [Lenovo Group Limited, 3, 1, 0, 13]
[c:\program files\lenovo\igrs\ext\router.dll] [联想集团有限公司, 1, 5, 0, 17]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\Program Files\Lenovo\IGRS\Ext\IncDefExecutors.dll] [联想集团有限公司, 1.0.1.11]
[PID: 1956 / SYSTEM][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE] [Microsoft Corporation, 7.00.9466]
[C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\2052\mdmui.dll] [Microsoft Corporation, 7.00.9466]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MSDBG2.DLL] [Microsoft Corporation, 7.00.9466]
[PID: 588 / SYSTEM][C:\Program Files\lenovo\IGRS Profiles\File Profile\IgrsFile.exe] [Lenovo Group Limited, 1, 0, 0, 4]
[C:\WINDOWS\system32\IgrsApi.dll] [Lenovo Group Limited, 1.0.1.195]
[C:\Program Files\lenovo\IGRS Profiles\File Profile\Util.dll] [, 1, 0, 1, 1]
玉雪飘零 - 2007-11-17 14:05:00
1.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\lenovo\IGRS Profiles\File Profile\FrameWork.dll] [Lenovo, 1, 0, 1, 1]
[C:\Program Files\lenovo\IGRS Profiles\File Profile\FileProfileModule.dll] [Lenovo Group Limited, 2, 0, 2, 35]
[C:\Program Files\lenovo\IGRS Profiles\File Profile\BFileDialog.dll] [Lenovo Group Limited, 2, 0, 1, 32]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 1312 / SYSTEM][C:\Program Files\Lenovo\IGRS EasyShare\FileShare.exe] [联想集团有限公司, 1, 0, 2, 24]
[C:\Program Files\Lenovo\IGRS EasyShare\IGRSAVSDK.dll] [联想集团有限公司, 1, 0, 1, 50204]
[C:\WINDOWS\system32\IgrsApi.dll] [Lenovo Group Limited, 1.0.1.195]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Lenovo\IGRS EasyShare\QuickDB.dll] [N/A, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 1764 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 2232 / Administrator][C:\Program Files\Lenovo\EnergyCut\utilty.exe] [TODO: <Company name>, 1.0.0.1]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\WINDOWS\system32\SVCCtrl02.dll] [N/A, ]
[C:\WINDOWS\system32\ProcSvr01.dll] [N/A, ]
[C:\WINDOWS\system32\BugReport02.dll] [N/A, ]
[C:\WINDOWS\system32\KVBatch01.dll] [N/A, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\WINDOWS\system32\GenProtect.dll] [N/A, ]
[C:\WINDOWS\system32\GUIMon02.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\BoldShl02.dll] [N/A, ]
[C:\WINDOWS\system32\SQLLink02.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\yjmtny.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\MsPrint32D.dll] [N/A, ]
[C:\WINDOWS\system32\MediaDrv01.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[PID: 2240 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 2260 / SYSTEM][D:\ruixing\瑞星安装位置\Rising\Rav\RavStub.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
[D:\ruixing\瑞星安装位置\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[D:\ruixing\瑞星安装位置\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 2296 / Administrator][C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe] [N/A, ]
[C:\Program Files\Lenovo\EnergyCut\HookLib.dll] [N/A, ]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\WINDOWS\system32\SVCCtrl02.dll] [N/A, ]
[C:\WINDOWS\system32\ProcSvr01.dll] [N/A, ]
[C:\WINDOWS\system32\BugReport02.dll] [N/A, ]
[C:\WINDOWS\system32\KVBatch01.dll] [N/A, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\WINDOWS\system32\GenProtect.dll] [N/A, ]
[C:\WINDOWS\system32\GUIMon02.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\SQLLink02.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\BoldShl02.dll] [N/A, ]
[C:\WINDOWS\system32\yjmtny.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\MsPrint32D.dll] [N/A, ]
[C:\WINDOWS\system32\MediaDrv01.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[PID: 2312 / Administrator][C:\PROGRA~1\QBU\QkOnBtn.EXE] [Dritek System Inc., 1, 0, 0, 421]
[C:\PROGRA~1\QBU\ComFnUtl.dll] [Dritek System Inc., 1, 0, 0, 605]
[C:\PROGRA~1\QBU\Wnd2File.dll] [Dritek System Inc., 3.00]
[C:\PROGRA~1\QBU\SzUPFUtl.dll] [Dritek System Inc., 1.00]
[C:\PROGRA~1\QBU\OSDUtl.dll] [Dritek System Inc., 1, 1, 1, 309]
[C:\PROGRA~1\QBU\RgnMaker.dll] [Dritek System Inc., 12.07.1999 ( VC60 )]
[C:\PROGRA~1\QBU\CDRomUtl.dll] [Dritek System Inc., 1.00]
[C:\PROGRA~1\QBU\MixerUtl.dll] [Dritek System Inc., 1.00]
[C:\PROGRA~1\QBU\LgKCUtl.dll] [Dritek System Inc., 2, 0, 2, 1007]
[C:\PROGRA~1\QBU\MMDUtl.dll] [Dritek System Inc., 1, 2, 4, 4914]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\IGFXEXPS.DLL] [Intel Corporation, 3.0.0.4543]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\WINDOWS\system32\SVCCtrl02.dll] [N/A, ]
[C:\WINDOWS\system32\ProcSvr01.dll] [N/A, ]
[C:\WINDOWS\system32\BugReport02.dll] [N/A, ]
[C:\WINDOWS\system32\KVBatch01.dll] [N/A, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\WINDOWS\system32\GUIMon02.dll] [N/A, ]
[C:\WINDOWS\system32\GenProtect.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\SQLLink02.dll] [N/A, ]
[C:\WINDOWS\system32\BoldShl02.dll] [N/A, ]
[C:\WINDOWS\system32\yjmtny.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\MsPrint32D.dll] [N/A, ]
[C:\WINDOWS\system32\MediaDrv01.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[PID: 2348 / Administrator][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] [Synaptics, Inc., 8.0.9 20May05]
[C:\WINDOWS\system32\SynCOM.dll] [Synaptics, Inc., 8.0.9 20May05]
[C:\WINDOWS\system32\SVCCtrl02.dll] [N/A, ]
[C:\WINDOWS\system32\ProcSvr01.dll] [N/A, ]
[C:\WINDOWS\system32\BugReport02.dll] [N/A, ]
[C:\WINDOWS\system32\KVBatch01.dll] [N/A, ]
[C:\WINDOWS\system32\SynTPAPI.dll] [Synaptics, Inc., 8.0.9 20May05]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\WINDOWS\system32\GenProtect.dll] [N/A, ]
[C:\WINDOWS\system32\GUIMon02.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\BoldShl02.dll] [N/A, ]
[C:\WINDOWS\system32\SQLLink02.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\yjmtny.dll] [N/A, ]
[C:\WINDOWS\system32\MediaDrv01.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\MsPrint32D.dll] [N/A, ]
[PID: 2376 / Administrator][C:\WINDOWS\system32\igfxtray.exe] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\SVCCtrl02.dll] [N/A, ]
[C:\WINDOWS\system32\ProcSvr01.dll] [N/A, ]
[C:\WINDOWS\system32\BugReport02.dll] [N/A, ]
[C:\WINDOWS\system32\KVBatch01.dll] [N/A, ]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3.0.0.4543]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\WINDOWS\system32\GenProtect.dll] [N/A, ]
[C:\WINDOWS\system32\GUIMon02.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\BoldShl02.dll] [N/A, ]
[C:\WINDOWS\system32\SQLLink02.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\yjmtny.dll] [N/A, ]
[C:\WINDOWS\system32\MediaDrv01.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\MsPrint32D.dll] [N/A, ]
[PID: 2388 / Administrator][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4543]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\WINDOWS\system32\SVCCtrl02.dll] [N/A, ]
[C:\WINDOWS\system32\ProcSvr01.dll] [N/A, ]
[C:\WINDOWS\system32\BugReport02.dll] [N/A, ]
[C:\WINDOWS\system32\KVBatch01.dll] [N/A, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\WINDOWS\system32\GenProtect.dll] [N/A, ]
[C:\WINDOWS\system32\GUIMon02.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\BoldShl02.dll] [N/A, ]
[C:\WINDOWS\system32\SQLLink02.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\yjmtny.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\MediaDrv01.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\MsPrint32D.dll] [N/A, ]
[PID: 2396 / Administrator][C:\WINDOWS\system32\igfxpers.exe] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4543]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\WINDOWS\system32\SVCCtrl02.dll] [N/A, ]
[C:\WINDOWS\system32\ProcSvr01.dll] [N/A, ]
[C:\WINDOWS\system32\BugReport02.dll] [N/A, ]
[C:\WINDOWS\system32\KVBatch01.dll] [N/A, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
玉雪飘零 - 2007-11-17 14:08:00
[C:\WINDOWS\system32\GenProtect.dll] [N/A, ]
[C:\WINDOWS\system32\GUIMon02.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\BoldShl02.dll] [N/A, ]
[C:\WINDOWS\system32\SQLLink02.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\yjmtny.dll] [N/A, ]
[C:\WINDOWS\system32\MediaDrv01.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\MsPrint32D.dll] [N/A, ]
[PID: 1444 / Administrator][C:\WINDOWS\system32\RunDLL32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\KVBatch01.dll] [N/A, ]
[C:\WINDOWS\system32\SVCCtrl02.dll] [N/A, ]
[C:\WINDOWS\system32\ProcSvr01.dll] [N/A, ]
[C:\WINDOWS\system32\BugReport02.dll] [N/A, ]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\WINDOWS\system32\GenProtect.dll] [N/A, ]
[C:\WINDOWS\system32\GUIMon02.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\BoldShl02.dll] [N/A, ]
[C:\WINDOWS\system32\SQLLink02.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\yjmtny.dll] [N/A, ]
[C:\WINDOWS\system32\MediaDrv01.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\MsPrint32D.dll] [N/A, ]
[PID: 1452 / Administrator][C:\WINDOWS\system32\RunDLL32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\BugReport02.dll] [N/A, ]
[C:\WINDOWS\system32\SVCCtrl02.dll] [N/A, ]
[C:\WINDOWS\system32\ProcSvr01.dll] [N/A, ]
[C:\WINDOWS\system32\KVBatch01.dll] [N/A, ]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\WINDOWS\system32\GenProtect.dll] [N/A, ]
[C:\WINDOWS\system32\GUIMon02.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\BoldShl02.dll] [N/A, ]
[C:\WINDOWS\system32\SQLLink02.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\yjmtny.dll] [N/A, ]
[C:\WINDOWS\system32\MediaDrv01.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\MsPrint32D.dll] [N/A, ]
[PID: 1472 / Administrator][C:\WINDOWS\system32\RunDLL32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ProcSvr01.dll] [N/A, ]
[C:\WINDOWS\system32\SVCCtrl02.dll] [N/A, ]
[C:\WINDOWS\system32\BugReport02.dll] [N/A, ]
[C:\WINDOWS\system32\KVBatch01.dll] [N/A, ]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\WINDOWS\system32\GenProtect.dll] [N/A, ]
[C:\WINDOWS\system32\GUIMon02.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\BoldShl02.dll] [N/A, ]
[C:\WINDOWS\system32\SQLLink02.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\yjmtny.dll] [N/A, ]
[C:\WINDOWS\system32\MediaDrv01.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\MsPrint32D.dll] [N/A, ]
[PID: 1660 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.1897.0]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.1897.0]
[PID: 1852 / SYSTEM][C:\WINDOWS\system32\drivers\CDAC11BA.EXE] [Macrovision, 4.20.020]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 1884 / SYSTEM][C:\Program Files\lenovo\GUA\GUA.exe] [lenovo, 1.0.0.21]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 1904 / SYSTEM][C:\Program Files\Lenovo\IGRS\IGRS.exe] [联想集团有限公司, 1.0.1.217]
[C:\Program Files\Lenovo\IGRS\framework.dll] [联想集团有限公司, 1.0.1.217]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Lenovo\IGRS\ReliablePlugin.dll] [联想集团有限公司, 1.0.1.217]
[C:\Program Files\Lenovo\IGRS\CorePlugin.dll] [联想集团有限公司, 1.0.1.217]
[C:\Program Files\Lenovo\IGRS\SocketPlugin.dll] [联想集团有限公司, 1.0.1.217]
[C:\Program Files\Lenovo\IGRS\BTComPlugin.dll] [联想集团有限公司, 1.0.1.217]
[C:\Program Files\Lenovo\IGRS\SerialPortMonitor.dll] [lenovo, 1, 0, 1, 19]
[C:\Program Files\Lenovo\IGRS\ProxyPlugin.dll] [联想集团有限公司, 1.0.1.217]
[C:\Program Files\Lenovo\IGRS\SvcHostPlugin.dll] [联想集团有限公司, 1.0.1.217]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[PID: 1924 / SYSTEM][C:\WINDOWS\System32\IgrsSvcs.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\program files\lenovo\igrs\ext\igrsmonitor.dll] [联想集团有限公司, 1, 2, 1, 21]
[C:\WINDOWS\system32\IgrsApi.dll] [Lenovo Group Limited, 1.0.1.195]
[c:\program files\lenovo\igrs\ext\incsvc.dll] [联想集团有限公司, 1, 0, 1, 14]
[C:\WINDOWS\system32\wmcdrv.dll] [Lenovo Group Limited, 3, 1, 0, 13]
[c:\program files\lenovo\igrs\ext\router.dll] [联想集团有限公司, 1, 5, 0, 17]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\Program Files\Lenovo\IGRS\Ext\IncDefExecutors.dll] [联想集团有限公司, 1.0.1.11]
[PID: 1956 / SYSTEM][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE] [Microsoft Corporation, 7.00.9466]
[C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\2052\mdmui.dll] [Microsoft Corporation, 7.00.9466]
[C:\WINDOWS\system32\8EA99771.DLL] [Microsoft Corporation, ]
[D:\新建文件夹\an zhuang wei zhi\ProcessHook.dll] [Fygsoft and Microsoft, 1.1.0.102]
[C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MSDBG2.DLL] [Microsoft Corporation, 7.00.9466]
[PID: 588 / SYSTEM][C:\Program Files\lenovo\IGRS Profiles\File Profile\IgrsFile.exe] [Lenovo Group Limited, 1, 0, 0, 4]
[C:\WINDOWS\system32\IgrsApi.dll] [Lenovo Group Limited, 1.0.1.195]
[C:\Program Files\lenovo\IGRS Profiles\File Profile\Util.dll] [, 1, 0, 1, 1]
1
© 2000 - 2026 Rising Corp. Ltd.