紫宸 - 2007-11-18 16:34:00
==================================
启动文件夹
N/A
==================================
服务
[Contrl Center of Storm Media / ccosm][Stopped/Auto Start]
<C:\Program Files\StormII\stormliv.exe /asservice><北京暴风网际科技有限公司>
[DriverStudio Remote Control / DriverStudio Remote Control][Running/Auto Start]
<C:\Program Files\Compuware\SoftICE Driver Suite\Common\Bin\DSRSvc.exe><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><>
[NOD32 Kernel Service / NOD32krn][Running/Auto Start]
<"C:\Program Files\Eset\nod32krn.exe"><Eset>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
<C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[Rising Proxy Service / RfwProxySrv][Stopped/Manual Start]
<c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\System32\mspmsnsv.dll><Microsoft Corporation>
==================================
驱动程序
[Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
<system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AMON / AMON][Running/Auto Start]
<\??\C:\WINDOWS\System32\drivers\amon.sys><Eset>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[HookUrl / HookUrl][Running/Auto Start]
<\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[ISO DVD/CD-ROM Device Driver / ISODrive][Running/System Start]
<\??\D:\应用程序\UltraISO\drivers\ISODrive.sys><EZB Systems, Inc.>
[jdy#hook / jdy#hook][Stopped/Manual Start]
<\??\C:\Program Files\按键精灵\hknm.sys><N/A>
[kmsinput / kmsinput][Stopped/Manual Start]
<\??\C:\WINDOWS\System32\drivers\kmsinput.sys><N/A>
[mProcRs / mProcRs][Running/Auto Start]
<\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[DriverStudio Device Filter / nmfilter][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\nmfilter.sys><Compuware Corporation - NuMega Lab>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
<system32\drivers\npf.sys><CACE Technologies>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\D:\应用程序\QQ2006\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
<System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[nvatabus / nvatabus][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\nvatabus.sys><NVIDIA Corporation>
[NVIDIA nForce MCP Networking Controller Driver / NVENET][Running/Manual Start]
<System32\DRIVERS\NVENET.sys><NVIDIA Corporation>
[nvidesm / nvidesm][Running/Boot Start]
<\SystemRoot\system32\drivers\nvidesm.sys><NVIDIA Corporation>
[NVIDIA nForce AGP Bus Filter / nv_agp][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\nv_agp.sys><NVIDIA Corporation>
[Padus ASPI Shell / pfc][Running/Manual Start]
<system32\drivers\pfc.sys><Padus, Inc.>
[PmDrv / PmDrv][Stopped/Manual Start]
<\??\E:\Process Monitor\PmDrv.sys><N/A>
[PortTalk / PortTalk][Stopped/Manual Start]
<System32\Drivers\PortTalk.sys><Beyond Logic http://www.beyondlogic.org>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[ReadSamer / ReadSamer][Stopped/Manual Start]
<\??\E:\readsam\reader.sys><N/A>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
<\SystemRoot\System32\drivers\RsBoot.sys><Beijing Rising Technology Co., Ltd.>
[RsFwDrv / RsFwDrv][Running/Auto Start]
<\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[Secdrv / Secdrv][Running/Auto Start]
<System32\DRIVERS\secdrv.sys><N/A>
[SiwvidStart / SiwvidStart][Stopped/Manual Start]
<\??\C:\Program Files\Compuware\SoftICE Driver Suite\Common\Binsiwvid.sys><N/A>
[vfdriver / vfdriver][Stopped/Manual Start]
<\??\E:\debuggy_unleashed\ptoolz\vfdriver.sys><N/A>
[WinDriver6 / WinDriver6][Stopped/Manual Start]
<system32\drivers\windrvr6.sys><Jungo>
==================================
浏览器加载项
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[快车]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\Program Files\FlashGet\FlashGet.exe, FlashGet.com>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[金山快译(&K)]
{6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <D:\应用程序\金山快译\IEBand.dll, >
[AlternaTIFF ActiveX]
{106E49CF-797A-11D2-81A2-00E02C015623} <C:\WINDOWS\Downloaded Program Files\alttiff.ocx, Medical Informatics Engineering, Inc.>
[iTrusPTA Class]
{1E0DFFCF-27FF-4574-849B-55007349FEDA} <C:\WINDOWS\System32\aliedit\pta.dll, >
[163Uploader Control]
{8686F2A6-DC01-4E8F-BDE3-DCC7DBBAD6AE} <C:\WINDOWS\System32\163UPL~1.OCX, 广州网易互动娱乐有限公司>
[SysMonOCX Control]
{9BDBC41E-C335-4263-83C0-ECE78EE28A33} <C:\WINDOWS\DOWNLO~1\SYSMON~1.OCX, AhnLab>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\DOWNLO~1\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[PasswordEditCtrl Class]
{E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\System32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[safe360AutoLive]
{E5212438-921F-44a3-8865-11C0B9BA4AF2} <C:\Program Files\safe360\autolive.dll, N/A>
[FGAutoLive]
{F90D830D-C175-4bbe-82C7-FF94669A4C42} <C:\Program Files\FlashGet\fgupdate.dll, www.flashget.com>
[FGCatchUrl]
{FB5DA724-162B-11D3-8B9B-AA70B4B0B524} <C:\Program Files\FlashGet\jccatch.dll, N/A>
[&使用快车(FlashGet)下载]
<C:\Program Files\FlashGet\jc_link.htm, N/A>
[&使用快车(FlashGet)下载全部链接]
<C:\Program Files\FlashGet\jc_all.htm, N/A>
[&使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ表情]
<D:\应用程序\QQ2006\AddEmotion.htm, N/A>
紫宸 - 2007-11-18 16:35:00
==================================
正在运行的进程
[PID: 692 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 776 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 800 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 844 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 856 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1020 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1168 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1292 / NETWORK SERVICE][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1404 / LOCAL SERVICE][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1452 / SYSTEM][c:\program files\rising\rfw\rfwsrv.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 35]
[c:\program files\rising\rfw\RfwRule.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 3]
[c:\program files\rising\rfw\rfwlog.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 2]
[c:\program files\rising\rfw\Rfwdrv.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 10]
[c:\program files\rising\rfw\psapi.dll] [Microsoft Corporation, 4.00]
[c:\program files\rising\rfw\MonDrv.dll] [rs, 1, 0, 0, 4]
[c:\program files\rising\rfw\ProcLib.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 5]
[c:\program files\rising\rfw\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[PID: 1612 / Administrator][C:\WINDOWS\Explorer.exe] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\WINDOWS\System32\nvshell.dll] [NVIDIA Corporation, 6.14.10.5216]
[C:\WINDOWS\System32\NVWRSZHC.DLL] [NVIDIA Corporation, 6.14.10.5216]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Eset\nodshex.dll] [N/A, ]
[C:\WINDOWS\System32\WINWB98.IME] [Microsoft Corporation, 4.00.950]
[PID: 1808 / Administrator][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5.1.11]
[PID: 1844 / Administrator][C:\Program Files\Rising\Rfw\rfwmain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 72]
[C:\Program Files\Rising\Rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[C:\Program Files\Rising\Rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[C:\Program Files\Rising\Rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\Rising\Rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 1852 / Administrator][C:\Program Files\Eset\nod32kui.exe] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\nod32rui.dll] [N/A, ]
[C:\Program Files\Eset\pu_amon.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\pr_amon.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\pu_dmon.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\pr_dmon.dll] [N/A, ]
[C:\Program Files\Eset\pu_emon.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\pr_emon.dll] [N/A, ]
[C:\Program Files\Eset\pu_imon.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\pr_imon.dll] [N/A, ]
[C:\Program Files\Eset\pu_mirr.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\pr_mirr.dll] [N/A, ]
[C:\Program Files\Eset\pu_nod32.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\pr_nod32.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\pu_upd.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\pr_upd.dll] [N/A, ]
[PID: 400 / SYSTEM][C:\Program Files\Compuware\SoftICE Driver Suite\Common\Bin\DSRSvc.exe] [N/A, ]
[C:\Program Files\Compuware\SoftICE Driver Suite\Common\Bin\DSCPanelServer.dss] [N/A, ]
[C:\Program Files\Compuware\SoftICE Driver Suite\Common\Bin\DSStatusServer.dss] [Compuware Corporation - NuMega Lab, 2.7.0 (Build 562)]
[C:\Program Files\Compuware\SoftICE Driver Suite\Common\Bin\DSRReboot.dll] [N/A, ]
[C:\Program Files\Compuware\SoftICE Driver Suite\SoftICE\Setup\SIInitServer.dss] [Compuware Corporation - NuMega Lab, 2.7.0 (Build 562)]
[PID: 676 / SYSTEM][C:\Program Files\Eset\nod32krn.exe] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\nod32krr.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\ps_amon.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\pr_amon.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\ps_dmon.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\pr_dmon.dll] [N/A, ]
[C:\Program Files\Eset\ps_emon.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\pr_emon.dll] [N/A, ]
[C:\WINDOWS\System32\imon.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\pr_imon.dll] [N/A, ]
[C:\Program Files\Eset\ps_mirr.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\pr_mirr.dll] [N/A, ]
[C:\Program Files\Eset\ps_nod32.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\pr_nod32.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\ps_upd.dll] [Eset , 2, 51, 26 ]
[C:\Program Files\Eset\pr_upd.dll] [N/A, ]
[PID: 724 / SYSTEM][C:\WINDOWS\System32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.5216]
[PID: 948 / Administrator][C:\Program Files\Maxthon\Max.exe] [Maxthon International Ltd., 1, 5, 3, 18]
[C:\Program Files\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[C:\Program Files\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\WINDOWS\System32\WINWB98.IME] [Microsoft Corporation, 4.00.950]
[PID: 1524 / SYSTEM][C:\WINDOWS\System32\wbem\wmiapsrv.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 540 / Administrator][C:\Program Files\Microsoft Visual Studio\VB98\vb6.exe] [Microsoft Corporation, 6.00.8176]
[C:\Program Files\Microsoft Visual Studio\VB98\VBA6.dll] [Microsoft Corporation, 6.0.8169]
[C:\Program Files\Microsoft Visual Studio\VB98\VB6IDE.DLL] [Microsoft Corporation, 6.00.8169]
[C:\Program Files\Common Files\Microsoft Shared\VBA\MSO97RT.DLL] [, ]
[C:\Program Files\Microsoft Visual Studio\VB98\DATAVIEW.DLL] [Microsoft Corp., 6.00.8178]
[C:\WINDOWS\System32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[C:\WINDOWS\System32\COMMTB32.dll] [Microsoft Corporation, 01.10]
[C:\Program Files\Microsoft Visual Studio\Common\Tools\VCM\VCMMGR.DLL] [Microsoft Corp., 6.00.8169]
[C:\Program Files\Common Files\DESIGNER\MSADDNDR.DLL] [Microsoft Corporation, 6.00.8169]
[C:\Program Files\Microsoft Visual Studio\VB98\Wizards\RESEDIT.DLL] [Microsoft Corporation, 6.00.8169]
[C:\Program Files\YFSoft\API浏览器.net\APIINEX.dll] [北京金日新事业技术有限公司, 1.00]
[C:\PROGRA~1\MICROS~4\VB98\VBSCC.DLL] [, 06.00.8142]
[C:\PROGRA~1\MICROS~4\VB98\AddSccus.dll] [, 06.00.8142]
[D:\应用程序\VB6.0企业版安装文件\vb6.0\vb6\VSS\win32\SSSCC.DLL] [, 06.00.8169]
[D:\应用程序\VB6.0企业版安装文件\vb6.0\vb6\VSS\win32\ssus.dll] [, 06.00.8163]
[C:\WINDOWS\System32\WINWB98.IME] [Microsoft Corporation, 4.00.950]
[PID: 1980 / Administrator][C:\Program Files\Microsoft Visual Studio\Common\Tools\Winapi\APILOAD.EXE] [Microsoft Corporation, 6.00.8169]
[C:\WINDOWS\System32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[C:\Program Files\Common Files\DESIGNER\MSADDNDR.DLL] [Microsoft Corporation, 6.00.8169]
[PID: 556 / Administrator][F:\VB学习文件\VB源码程序集和学习资料\PE文件标志软件\JiurlPedumpAver0.1.exe] [, 1, 0, 0, 1]
[PID: 1536 / Administrator][C:\WINDOWS\system32\calc.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1216 / Administrator][D:\应用程序\金山词霸\金山词霸程序\XDICT.EXE] [Kingsoft Co, Ltd., 8, 5, 0, 0]
[D:\应用程序\金山词霸\金山词霸程序\DicMngr.dll] [Kingsoft, 1, 0, 0, 0]
[D:\应用程序\金山词霸\金山词霸程序\doshow.dll] [N/A, ]
[D:\应用程序\金山词霸\金山词霸程序\ITextOut.dll] [Kingsoft, 1, 1, 0, 0]
[D:\应用程序\金山词霸\金山词霸程序\KPic10.dll] [N/A, ]
[D:\应用程序\金山词霸\金山词霸程序\ijl11.dll] [Intel Corporation, 1.1.2]
[D:\应用程序\金山词霸\金山词霸程序\NormGrab.DLL] [Kingsoft Co, Ltd., 6, 0, 0, 0]
[D:\应用程序\金山词霸\金山词霸程序\toTTSEngine50.dll] [Kingsoft Corporation, 1, 0, 0, 1]
[D:\应用程序\金山词霸\金山词霸程序\xfile.dll] [N/A, ]
[D:\应用程序\金山词霸\金山词霸程序\DBCore10.dll] [Kingsoft Corp., 1, 0, 0, 0]
[D:\应用程序\金山词霸\金山词霸程序\XdictGrb.dll] [Kingsoft Co, Ltd., 8, 5, 0, 0]
[PID: 1484 / Administrator][F:\手工清毒工具专用\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[F:\手工清毒工具专用\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
© 2000 - 2026 Rising Corp. Ltd.