[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)]
[PID: 1212 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1380 / SYSTEM][C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe] [VoyagerSoft, LLC, 3.0.299.5]
[PID: 1268 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2192 / Administrator][C:\WINDOWS\VM_STI.EXE] [BIGDOG, 4, 2, 610, 4]
[d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 17]
[PID: 2208 / Administrator][C:\WINDOWS\LHotkey.exe] [Chicony, 1. 0. 0. 1]
[C:\WINDOWS\HKNTDLL.dll] [N/A, ]
[d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 2264 / Administrator][D:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.23]
[D:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[D:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[D:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 20.0.0.0]
[D:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16]
[PID: 2280 / Administrator][D:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 20.0.01.19]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[D:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[D:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[D:\Program Files\Rising\Rav\recomp.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 38]
[D:\Program Files\Rising\Rav\refs.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17]
[D:\Program Files\Rising\Rav\viruslib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26]
[D:\Program Files\Rising\Rav\relibldr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[D:\Program Files\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0]
[D:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16]
[D:\Program Files\Rising\Rav\MonRule.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.29]
[D:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4]
[D:\Program Files\Rising\Rav\Rsguilib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 88]
[D:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0]
[PID: 2308 / Administrator][C:\WINDOWS\system32\Rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 17]
[PID: 2452 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 2576 / Administrator][C:\Program Files\eMule\eMule.exe] [
http://www.emule-project.net, 0.48.0.80313 Unicode]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\Program Files\eMule\config\antiLeech.dll] [
http://xtreme-mod.net, 31]
[C:\Program Files\eMule\lang\zh_CN.dll] [
http://www.emule-project.net, 0.48.0.80313]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 17]
[PID: 2884 / Administrator][C:\Program Files\QQ2007\TXPlatform.exe] [Tencent, 1, 0, 170, 0]
[d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 3344 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1172 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 17]
[PID: 2256 / Administrator][C:\Program Files\PPLive\PPLive.exe] [N/A, ]
[d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\Program Files\PPLive\UI.DLL] [, 1, 9, 0, 1]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)]
[C:\Program Files\PPLive\uilib.dll] [Synacast, 1, 0, 0, 1]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 17]
[C:\PROGRA~1\PPLive\common.dll] [, 1, 0, 0, 1]
[C:\Program Files\PPLive\NetTools.dll] [, 1.0.0.2]
[C:\Program Files\PPLive\PPK.DLL] [N/A, ]
[C:\PROGRA~1\PPLive\SYNACA~1.OCX] [, 1, 9, 0, 1]
[D:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[C:\PROGRA~1\PPLive\ETS.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)]
[C:\PROGRA~1\PPLive\SYNACA~2.OCX] [Synacast, 1, 9, 0, 2]
[C:\PROGRA~1\PPLive\AM.DLL] [, 2, 0, 0, 0]
[C:\WINDOWS\system32\MFPlat.DLL] [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
[C:\PROGRA~1\PPLive\OPlayer.ocx] [, 1, 0, 2, 1]
[C:\PROGRA~1\PPLive\FWUpnp.dll] [N/A, ]
[C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\system32\WMVDECOD.dll] [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\ffdshow.ax] [, 1.0.2.2028]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Ringz Studio\Storm Codec\Codecs\VSFilter.dll] [Gabest, 1, 0, 1, 3]
[C:\WINDOWS\system32\wmpeffects.dll] [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\wmpps.dll] [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
[PID: 2508 / Administrator][C:\Program Files\PPLive\PPLive.exe] [N/A, ]
[d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\Program Files\PPLive\MngModule.dll] [, 1, 7, 0, 2]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 17]
[PID: 2812 / Administrator][C:\Program Files\PPLive\PPLive.exe] [N/A, ]
[d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\Program Files\PPLive\pp\ppf.dll] [, 1, 0, 0, 5]
[C:\Program Files\PPLive\pp\PCP.dll] [, 1, 0, 1, 1]
[C:\Program Files\PPLive\pp\EROC.DLL] [Synacast Corp., 1, 2, 0, 1]
[C:\Program Files\PPLive\pp\TEN.DLL] [Synacast, 1, 1, 1, 0]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 17]
[C:\Program Files\PPLive\NetTools.dll] [, 1.0.0.2]
[PID: 480 / Administrator][C:\Program Files\PPLive\PPLive.exe] [N/A, ]
[d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\Program Files\PPLive\Live.dll] [Synacast, 1, 0, 0, 2]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)]
[C:\Program Files\PPLive\PP\kom.dll] [Synacast Corp., 1, 2, 0, 3]
[C:\Program Files\PPLive\PP\EROC.DLL] [Synacast Corp., 1, 2, 0, 1]
[C:\Program Files\PPLive\PP\TEN.DLL] [Synacast, 1, 1, 1, 0]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 17]
[C:\Program Files\PPLive\PP\mir.dll] [Synacast Corp., 1, 3, 4, 6]
[C:\Program Files\PPLive\PP\tpi.dll] [N/A, ]
[PID: 280 / Administrator][C:\Program Files\Mozilla Firefox\firefox.exe] [Mozilla Corporation, 1.8.1.14: 2008040413]
[C:\Program Files\Mozilla Firefox\js3250.dll] [Netscape Communications Corporation, 4.0]
[C:\Program Files\Mozilla Firefox\nspr4.dll] [Netscape Communications Corporation, 4.6.8]
[C:\Program Files\Mozilla Firefox\xpcom_core.dll] [Mozilla Foundation, 1.8.1.14: 2008040413]
[C:\Program Files\Mozilla Firefox\plc4.dll] [Netscape Communications Corporation, 4.6.8]
[C:\Program Files\Mozilla Firefox\plds4.dll] [Netscape Communications Corporation, 4.6.8]
[C:\Program Files\Mozilla Firefox\smime3.dll] [Mozilla Foundation, 3.11.5 Basic ECC]
[C:\Program Files\Mozilla Firefox\nss3.dll] [Mozilla Foundation, 3.11.5 Basic ECC]
[C:\Program Files\Mozilla Firefox\softokn3.dll] [Mozilla Foundation, 3.11.4 Basic ECC]
[C:\Program Files\Mozilla Firefox\ssl3.dll] [Mozilla Foundation, 3.11.5 Basic ECC]
[C:\Program Files\Mozilla Firefox\xpcom_compat.dll] [Mozilla Foundation, 1.8.1.14: 2008040413]
[d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 17]
[C:\Program Files\Mozilla Firefox\components\myspell.dll] [Mozilla Foundation, 1.8.1.14: 2008040413]
[C:\Program Files\Mozilla Firefox\components\jar50.dll] [Mozilla Foundation, 1.8.1.14: 2008040413]
[C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\eh040q75.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll] [N/A, ]
[C:\Program Files\Mozilla Firefox\xpcom.dll] [Mozilla Foundation, 1.8.1.14: 2008040413]
[C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\eh040q75.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll] [N/A, ]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)]
[C:\Program Files\Mozilla Firefox\freebl3.dll] [Mozilla Foundation, 3.11.4 Basic ECC]
[C:\Program Files\Mozilla Firefox\nssckbi.dll] [Mozilla Foundation, 1.65]
[C:\Program Files\Mozilla Firefox\components\spellchk.dll] [Mozilla Foundation, 1.8.1.14: 2008040413]
[C:\Program Files\Mozilla Firefox\components\ThunderComponent.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 7]
[C:\WINDOWS\HKNTDLL.dll] [N/A, ]
[C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll] [, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\wpdshext.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[PID: 2652 / Administrator][D:\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)]
[d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 17]
[D:\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 update.cpushpop.com
127.0.0.1 image.yahoo550.com
127.0.0.1 gs.chnsystem.com
127.0.0.1 msl.chnsystem.com
127.0.0.1 ssl.chnsystem.com
127.0.0.1
www.gagagaga.cn127.0.0.1 down.1024tb.com
127.0.0.1 xconf.coopen.cn
127.0.0.1 log.xplayer.coopen.cn
127.0.0.1 xfile.coopen.cn
127.0.0.1 loader.smartpv.cn
127.0.0.1 alerts.xiaoi.com
127.0.0.1 sports.yahoo550.com
127.0.0.1 update.cnnic.cn
127.0.0.1 jump.cnnic.cn
127.0.0.1 login.zuoyoukongjian.com
127.0.0.1 adfirefox.cn
127.0.0.1 3.wornm.cn
127.0.0.1 5.haokandi.cn
127.0.0.1 b.downadown.cn
127.0.0.1 update.iesuper.com
127.0.0.1 888.843call.cn
127.0.0.1 122.770304123.cn
127.0.0.1 110.770304123.cn
127.0.0.1 343.boolans.com
127.0.0.1 update.smartpv.cn
127.0.0.1 update146.smartpv.cn
127.0.0.1 js4.all4ad.net
127.0.0.1 click2.ad4all.net
127.0.0.1
www.papaop.com127.0.0.1 realname.webbrowser.smartpv.cn
127.0.0.1 login.webbrowser.smartpv.cn
127.0.0.1
www.cnphp5.com127.0.0.1
www.133c.cn127.0.0.1 zhoupk256.3322.org
127.0.0.1 udp.hjob123.com
127.0.0.1 d4.kkads.cn
127.0.0.1
www.zhaoyou8.com127.0.0.1
www.kkads.cn127.0.0.1 travel.yahoo550.com
127.0.0.1 soft.16990.com
127.0.0.1 livenews.265.com
127.0.0.1 bak.hjob123.com
127.0.0.1
www.jesuser.cn127.0.0.1 class.caiyi8.com
127.0.0.1 ownload.baofeng.com
127.0.0.1
www.177i.com127.0.0.1
www.81891111.com127.0.0.1 33.xingaide8.cn
127.0.0.1 444.916kk.com
127.0.0.1
www.916kk.com127.0.0.1 soft2.86sifu.com
127.0.0.1 google.netcdn.com
127.0.0.1 lm.9cdn.com
127.0.0.1
www.z88.com.cn127.0.0.1 adswin.unet.hk
127.0.0.1
www.borlander.com.cn127.0.0.1 cab.borlander.com.cn
127.0.0.1
www.333292.com127.0.0.1 net.jnnic.com
127.0.0.1
www.plunix.org127.0.0.1 ip.9cdn.com
127.0.0.1 test8.b190.west263.cn
127.0.0.1 yz.jz173.com
127.0.0.1
www.yy17173.cn127.0.0.1
www.daydayshop.cn127.0.0.1
www.yahoo550.com127.0.0.1 wifayy.51vip.biz
127.0.0.1 sss.969222.com
127.0.0.1 stats.ucantv.com
127.0.0.1 node1.ucantv.com
127.0.0.1 x5.ioeruwu.com
127.0.0.1 p.jfglass.net
127.0.0.1 x4.ioeruwu.com
127.0.0.1
www.tyw10.cn127.0.0.1 push.cpushpop.com
127.0.0.1 axcx.3322.org
127.0.0.1
www.our9988.cn127.0.0.1 update.borlander.cn
127.0.0.1
www.666888ip.cn127.0.0.1 pr.749571.com
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 2192, C:\WINDOWS\VM_STI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2192, C:\WINDOWS\VM_STI.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2208, C:\WINDOWS\LHOTKEY.EXE]
==================================
API HOOK
入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: 0x010A1FFD)
入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: 0x010A20E5)
==================================
隐藏进程
N/A
==================================
[/CODE]