[CODE] 2008-05-03,12:54:01 System Repair Engineer 2.5.16.900 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [] [(Verified)SHANGHAI ZHONGYUAN NETWORKS LIMITED] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [] [Promise Technology, Inc.] [Promise Technology,Inc.] [(Verified)Microsoft Windows Publisher] [N/A] [N/A] [N/A] [N/A] <"E:\Rising\Rfw\rfwmain.exe" -Startup> [(Verified)BEIJING RISING SCIENCE AND TECHNOLOGY CORPORATION LIMITED] <"E:\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Science and Technology Corporation Limited] <"E:\Rising\runiep.exe" /startup> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce] [Beijing Rising Technology Co., Ltd.] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] [Beijing Rising Technology Co., Ltd.] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{4A041F13-A111-12A3-B0CF-F99818AA68A4}> [] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}> [(Verified)Beijing Rising Science and Technology Corporation Limited] <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}> [Beijing Rising Technology Co., Ltd.] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] [(Verified)Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Logo1_.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Logo_1.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQLogin.exe] <"C:\WINDOWS\system32\qqxyd.exe"> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\XYD2.exe] <"C:\WINDOWS\system32\qqxyd.exe"> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [N/A] <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [N/A] <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [N/A] <; C:\WINDOWS\system32\rundll32.exe "C:\PROGRA~1\StormII\StormSet.dll",CheckEnv> [N/A] ================================== 启动文件夹 [PPS] C:\PROGRA~1\PPStream\PPStream.exe [PPStream Inc.]> ================================== 服务 [Contrl Center of Storm Media / ccosm][Running/Auto Start] <北京暴风网际科技有限公司> [Help and Support / helpsvc][Stopped/Disabled] %WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Disabled] [Rising Proxy Service / RfwProxySrv][Running/Auto Start] [Rising Personal Firewall Service / RfwService][Running/Auto Start] [Rising Process Communication Center / RsCCenter][Running/Auto Start] <"E:\Rising\Rav\CCenter.exe"> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] <"E:\RISING\RAV\Ravmond.exe"> ================================== 驱动程序 [2310_00 / 2310_00][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\2310_00.sys> [a320raid / a320raid][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\a320raid.sys> [aaatimeo / aaatimeo][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aaatimeo.sys> [Adaptec RAID Miniport Driver / aac][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aac.sys> [Adaptec SAS/SATA-II RAID Miniport Driver / aacsas][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aacsas.sys> [aarich / aarich][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aarich.sys> [adp94xx / adp94xx][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\adp94xx.sys> [adpu160m / adpu160m][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\adpu160m.sys> [adpu320 / adpu320][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\adpu320.sys> [adsrsvc / adsrsvc][Running/Boot Start] <\SystemRoot\system32\drivers\adsrsvc.SYS><> [ACARD AEC6210UF UltraDMA33 Controller / aec6210][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aec6210.sys> [ACARD AEC6260 UltraDMA-66 Controller / aec6260][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aec6260.sys> [aec6280 / aec6280][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aec6280.sys> [AEC6880 / AEC6880][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\AEC6880.sys> [aec6897 / aec6897][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aec6897.sys> [AFAMgt / AFAMgt][Running/Boot Start] <\SystemRoot\system32\DRIVERS\afamgt.sys> [ahcix86 / ahcix86][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ahcix86.sys> [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Stopped/Manual Start] [amdbusdr / amdbusdr][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\amdbusdr.sys> [AMD EIDE 驱动程衼E / amdeide][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\AmdEide.sys> [ati2mtag / ati2mtag][Running/Manual Start] [atiide / atiide][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\atiide.sys> [Promise driver accelerator / bb-run][Running/Boot Start] <\SystemRoot\system32\DRIVERS\bb-run.sys> [cda1000 / cda1000][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\cda1000.sys> [DELL CERC SATA 1.5/6ch RAID Miniport Driver / cercsr6][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\cercsr6.sys> [C-Media WDM Audio Interface / cmuda][Running/Manual Start] [Cpq32fs2 / Cpq32fs2][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\Cpq32fs2.sys> [cqit / cqit][Stopped/Auto Start] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp46.tmp> [Creative SB16/AWE32/AWE64 Driver (WDM) / ctlsb16][Stopped/Manual Start] [DC21x4 Based Network Adapter Driver / DC21x4][Stopped/Manual Start] [Promise Removable Disk Control Driver / dontgo][Running/Boot Start] <\SystemRoot\system32\DRIVERS\DontGo.sys> [FastSx / FastSx][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\FastSx.sys> [fasttrak / fasttrak][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\fasttrak.sys> [fasttx2k / fasttx2k][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\fasttx2k.sys> [fttxr52P / fttxr52P][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\fttxr52P.sys> [HookCont / HookCont][Running/System Start] <\SystemRoot\system32\drivers\HookCont.sys> [HookNtos / HookNtos][Running/System Start] <\SystemRoot\system32\drivers\HookNtos.sys> [HookReg / HookReg][Running/System Start] <\SystemRoot\system32\drivers\HookReg.sys> [HookSys / HookSys][Running/System Start] <\SystemRoot\system32\drivers\HookSys.sys> [HookUrl / HookUrl][Running/Auto Start] <\??\E:\Rising\Rfw\HookUrl.sys> [hpt374 / hpt374][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\hpt374.sys> [hpt3xx / hpt3xx][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\hpt3xx.sys> [hptmv / hptmv][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\hptmv.sys> [hptmv6 / hptmv6][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\hptmv6.sys> [hptpro / hptpro][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\hptpro.sys> [Intel RAID Controller / iaStor][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\iaStor.sys> [ITERAID_Service_Install / iteraid][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\iteraid.sys> [JMicron Hot-Plug Driver / JGOGO][Running/Boot Start] <\SystemRoot\system32\DRIVERS\JGOGO.sys> [JRAID / JRAID][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\jraid.sys> [m5281 / m5281][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\m5281.sys> [m5287 / m5287][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\m5287.sys> [m5288 / m5288][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\m5288.sys> [m5289 / m5289][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\m5289.sys> [MegaIDE / MegaIDE][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\MegaIDE.sys> [mraid35x / mraid35x][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\Mraid35x.sys> [mv61xx / mv61xx][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\mv61xx.sys> [IBM ServeRAID 4M/4L/4Mx/4Lx/5i/6M/6i/7k Device Driver / nfrd960][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\nfrd960.sys> [NPF / NPF][Stopped/Manual Start] <\??\C:\WINDOWS\system32\drivers\C.tmp> [ping / ping][Stopped/Auto Start] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp44.tmp> [CMD IDE Raid Controller / Pnp649r][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\pnp649r.sys> [SiI 680 ATA Controller / Pnp680][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\pnp680.sys> [Silicon Image SiI 0680 Medley Raid Controller / Pnp680r][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\pnp680r.sys> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [ql12160 / ql12160][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ql12160.sys> [ql2100 / ql2100][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ql2100.sys> [ql2200 / ql2200][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ql2200.sys> [raidsrc / raidsrc][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\raidsrc.sys> [Rising Rfwbase Driver / RfwBase][Running/Auto Start] [rr232x / rr232x][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\rr232x.sys> [RsAntiSpyware / RsAntiSpyware][Running/Boot Start] <\SystemRoot\system32\drivers\RsBoot.sys> [RsFwDrv / RsFwDrv][Running/System Start] <\??\E:\Rising\Rfw\RsFwDrv.sys> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Running/Manual Start] [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start] [S150sx8 / S150sx8][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\S150sx8.sys> [Secdrv / Secdrv][Stopped/Manual Start] [SiI-3512 SATALink Controller / SI3112][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SI3112.sys> [ATI-437A Serial ATA Controller / SI3112r][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SI3112r.sys> [SiI-3114 SATALink Controller / SI3114][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SI3114.sys> [SiI-3114 SATARaid Controller / SI3114r][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SI3114R.sys> [SiI-3114 SoftRaid 5 Controller / Si3114r5][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\Si3114r5.sys> [SiI-3124 SATALink Controller / SI3124][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SI3124.sys> [SiI-3124 SATARaid Controller / SI3124r][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SI3124R.sys> [SiI-3124 SoftRaid 5 Controller / Si3124r5][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\Si3124r5.sys> [SiI-3132 SATALink Controller / SI3132][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SI3132.sys> [SiI-3132 SoftRaid 5 Controller / Si3132r5][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\Si3132r5.sys> [SATALink driver accelerator / SiFilter][Running/Boot Start] <\SystemRoot\system32\DRIVERS\SiWinAcc.sys> [SATALink External Device Filter / SiRemFil][Running/Boot Start] <\SystemRoot\system32\DRIVERS\SiRemFil.sys> [SIS AGP Bus Filter / sisagp][Running/Boot Start] <\SystemRoot\system32\DRIVERS\sisagp.sys> [SiSide / SiSide][Running/Boot Start] <\SystemRoot\system32\DRIVERS\siside.sys> [SiSRaid / SiSRaid][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SiSRaid.sys> [SiSRaid2 / SiSRaid2][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SiSRaid2.sys> [snpshot / snpshot][Stopped/Manual Start] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\23.tmp> [sptrak / sptrak][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\sptrak.sys> [Symmpi / Symmpi][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\symmpi.sys> [TesSafe / TesSafe][Stopped/Manual Start] <\??\C:\WINDOWS\system32\TesSafe.sys> [UlSata / UlSata][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ulsata.sys> [ulsata2 / ulsata2][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ulsata2.sys> [ultra / ultra][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ultra.sys> [viamraid / viamraid][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\viamraid.sys> [VIA ATA/ATAPI Host Controller / viapdsk][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\viapdsk.sys> [videX32 / videX32][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\videX32.sys> [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start] <\SystemRoot\system32\DRIVERS\xfilt.sys> ================================== 浏览器加载项 [WebThunder Browser Helper] {00000AAA-A363-466E-BEF5-9BB68697AA7F} [Thunder Browser Helper] {02496EBC-8455-48DB-B3C7-5DAC97D9F5A7} [BdSearchHook Class] {02496EBD-8455-48db-B3C7-5DAC97D9F5A7} [] {4A041F13-A111-12A3-B0CF-F99818AA68A4} [百度首页] {02496EBD-8455-48db-B3C7-5DAC97D9F5A7} [启动WEB迅雷] {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} [访问瑞星网站] {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} [访问卡卡社区] {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} [卡卡上网安全助手] {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} [RealPlayer G2 Control] {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} [WebThunder Browser Helper] {00000AAA-A363-466E-BEF5-9BB68697AA7F} [Thunder Browser Helper] {02496EBC-8455-48DB-B3C7-5DAC97D9F5A7} [BdSearchHook Class] {02496EBD-8455-48DB-B3C7-5DAC97D9F5A7} [WebThunder Class] {03507A1A-E0C5-4404-AA26-205385C0892D} <, N/A> [WebThunder DapPlayer] {2EEDA47E-8D5C-4d7e-B4B6-E16E19218555} [] {4A041F13-A111-12A3-B0CF-F99818AA68A4} [XMP Class] {6483F145-A768-4C41-AACC-52D4D7845851} [XDRM] {693571CB-54A3-4E90-9D52-EEAE1334E2D3} [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [RMGetLicense Class] {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} [Thunder DapCtrl] {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} [使用WEB迅雷下载] [使用WEB迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] [添加到QQ表情] ================================== 正在运行的进程 [PID: 416 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 488 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 512 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17] [C:\WINDOWS\system32\WgaLogon.dll] [Microsoft Corporation, 1.7.0018.5] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 560 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 572 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 728 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 784 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 852 / SYSTEM][E:\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.28] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 868 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 7.0.6000.374 (winmain(wmbla).070416-2057)] [PID: 940 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 1040 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 1252 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17] [c:\documents and settings\administrator\application data\ppstream\bin\1.0.0.2\vodrc.dll] [ppstream.com, 1.0.0.2] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\WINDOWS\system32\zxmsawin.dll] [N/A, ] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17] [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\PROGRA~1\baidu\iexp\BDSrHook.dll] [, 1, 0, 0, 45] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [E:\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305] [G:\WEB讯雷\WebThunderBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 75] [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] [PID: 1292 / SYSTEM][E:\RISING\RAV\ravmond.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.76] [E:\RISING\RAV\BWList.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.4] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [E:\RISING\RAV\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [E:\RISING\RAV\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16] [E:\RISING\RAV\RsLog.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.34] [E:\RISING\RAV\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [E:\RISING\RAV\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [E:\RISING\RAV\MonRule.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.29] [E:\RISING\RAV\Hooksys.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 9] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [E:\RISING\RAV\HookReg.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 4] [E:\RISING\RAV\HookNtos.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 2] [E:\RISING\RAV\rswalmon.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 22] [E:\RISING\RAV\recomp.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 35] [E:\RISING\RAV\refs.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 15] [E:\RISING\RAV\ffr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 13] [E:\Rising\Rav\RsStore.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.8] [E:\RISING\RAV\HookCont.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 1] [E:\Rising\Rav\fakescan.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.13] [E:\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.36] [E:\RISING\RAV\viruslib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26] [E:\RISING\RAV\relibldr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 14] [E:\RISING\RAV\HookWeb.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.2] [E:\RISING\RAV\nvfile.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5] [E:\RISING\RAV\scanexec.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17] [E:\RISING\RAV\unexe.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4] [E:\RISING\RAV\scanex.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 59] [E:\RISING\RAV\pearc.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5] [E:\RISING\RAV\extfile.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 29] [E:\RISING\RAV\scanpack.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9] [E:\RISING\RAV\revm.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 8] [E:\RISING\RAV\urutils.dll] [, 20, 0, 0, 5] [E:\RISING\RAV\ur000.dat] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 18] [E:\RISING\RAV\scriptci.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [E:\RISING\RAV\uroutine.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26] [E:\RISING\RAV\ur001.dat] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [E:\RISING\RAV\scansct.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 8] [E:\RISING\RAV\posttrt.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [E:\RISING\RAV\ur023.dat] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0] [E:\RISING\RAV\extmail.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9] [PID: 1308 / SYSTEM][E:\Rising\Rfw\rfwsrv.exe] [Beijing Rising Technology Co., Ltd., 7.0.0.68] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [E:\Rising\Rfw\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [E:\Rising\Rfw\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [E:\Rising\Rfw\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [E:\Rising\Rfw\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16] [E:\Rising\Rfw\RfwRule.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.13] [E:\Rising\Rfw\rfwlog.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.12] [E:\Rising\Rfw\Rfwdrv.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.41] [E:\Rising\Rfw\ijt_ctrl.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.0] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [E:\Rising\Rfw\unvdet.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.5] [E:\Rising\Rfw\mPorts.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.3] [PID: 1412 / SYSTEM][E:\Rising\Rfw\rfwProxy.exe] [Beijing Rising Technology Co., Ltd., 7.0.0.32] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [E:\Rising\Rfw\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [E:\Rising\Rfw\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [E:\Rising\Rfw\RfwRule.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.13] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [E:\Rising\Rfw\MonMid.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.4] [PID: 1636 / SYSTEM][E:\Rising\Rfw\rfwstub.exe] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17] [E:\Rising\Rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 1896 / SYSTEM][E:\RISING\RAV\RavStub.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.9] [E:\RISING\RAV\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [E:\RISING\RAV\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [E:\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 1992 / Administrator][E:\Rising\Rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 7.0.1.65] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [E:\Rising\Rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 88] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [E:\Rising\Rfw\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [E:\Rising\Rfw\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [E:\Rising\Rfw\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [E:\Rising\Rfw\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16] [E:\Rising\Rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [E:\Rising\Rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.7] [E:\Rising\Rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0] [E:\Rising\Rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [E:\Rising\Rfw\RfwRule.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.13] [PID: 2000 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 1176 / Administrator][C:\WINDOWS\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\PROGRA~1\baidu\iexp\BDSrHook.dll] [, 1, 0, 0, 45] [C:\WINDOWS\system32\zxmsawin.dll] [N/A, ] [PID: 1328 / Administrator][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5, 1, 0, 59] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\PROGRA~1\baidu\iexp\BDSrHook.dll] [, 1, 0, 0, 45] [C:\WINDOWS\system32\zxmsawin.dll] [N/A, ] [PID: 1436 / Administrator][E:\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.23] [E:\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [E:\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [E:\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [E:\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [E:\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16] [PID: 1480 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\PROGRA~1\baidu\iexp\BDSrHook.dll] [, 1, 0, 0, 45] [C:\WINDOWS\system32\zxmsawin.dll] [N/A, ] [PID: 1616 / Administrator][E:\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 20.0.01.19] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [E:\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [E:\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [E:\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [E:\Rising\Rav\recomp.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 35] [E:\Rising\Rav\refs.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 15] [E:\Rising\Rav\viruslib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26] [E:\Rising\Rav\relibldr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 14] [E:\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [E:\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16] [E:\Rising\Rav\MonRule.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.29] [E:\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4] [E:\Rising\Rav\Rsguilib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 88] [E:\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0] [PID: 2228 / SYSTEM][C:\Program Files\StormII\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 3, 1] [C:\Program Files\StormII\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17] [PID: 2400 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17] [PID: 3068 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17] [PID: 2964 / Administrator][E:\Rising\Rav\RsAgent.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.7] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [E:\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [E:\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [PID: 2356 / Administrator][C:\WINDOWS\msagent\AgentSvr.exe] [Microsoft Corporation, 2.00.0.2202] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\PROGRA~1\baidu\iexp\BDSrHook.dll] [, 1, 0, 0, 45] [C:\WINDOWS\system32\zxmsawin.dll] [N/A, ] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 3388 / Administrator][F:\Program Files\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 6, 2, 60] [F:\Program Files\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17] [C:\PROGRA~1\baidu\iexp\BDSrHook.dll] [, 1, 0, 0, 45] [c:\documents and settings\administrator\application data\ppstream\bin\1.0.0.2\vodrc.dll] [ppstream.com, 1.0.0.2] [C:\WINDOWS\system32\zxmsawin.dll] [N/A, ] [F:\Program Files\Maxthon\Plugin\FloatBar\FloatBar.dll] [, 1, 9, 0, 0] [F:\Program Files\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1] [E:\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx] [Adobe Systems, Inc., 9,0,115,0] [PID: 3676 / Administrator][E:\Rising\arswp2\ArSwp.exe] [ArSwp.com, 2, 7, 0, 415] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\PROGRA~1\baidu\iexp\BDSrHook.dll] [, 1, 0, 0, 45] [c:\documents and settings\administrator\application data\ppstream\bin\1.0.0.2\vodrc.dll] [ppstream.com, 1.0.0.2] [C:\WINDOWS\system32\zxmsawin.dll] [N/A, ] [E:\Rising\arswp2\plugin\ArFix.dll] [ArSwp.Com, 2, 5, 0, 0] [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.8164] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [E:\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [PID: 1276 / Administrator][E:\新建文件夹\123.com.EXE] [Smallfrogs Studio, 2.5.16.900] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17] [E:\Rising\Rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10] [E:\Rising\Rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\PROGRA~1\baidu\iexp\BDSrHook.dll] [, 1, 0, 0, 45] [C:\WINDOWS\system32\zxmsawin.dll] [N/A, ] [E:\新建文件夹\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 124.238.254.113 www.10280011.com 124.238.254.113 10280011.com 124.238.254.113 www.10289900.com 124.238.254.113 10289900.com 124.238.254.113 www.78877788.com 124.238.254.113 78877788.com 124.238.254.113 www.11051122.com 124.238.254.113 11051122.com 124.238.254.113 1.ehai01.com 124.238.254.113 da.ehai01.com 124.238.254.113 ehai01.com 124.238.254.113 2008.sekart.cn 124.238.254.113 www.sekart.cn 124.238.254.113 sekart.cn 124.238.254.113 www.11309988.com 124.238.254.113 www.12100088.com 124.238.254.113 www.12108899.com 124.238.254.113 d2.llsging.com 124.238.254.113 llsging.com 124.238.254.113 dd.749571.com 124.238.254.113 749571.com 124.238.254.113 pr.749571.com 124.238.254.113 txwm1204.com 124.238.254.113 www.txwm1204.com ================================== 进程特权扫描 特殊特权被允许: SeDebugPrivilege [PID = 2356, C:\WINDOWS\MSAGENT\AGENTSVR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2356, C:\WINDOWS\MSAGENT\AGENTSVR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3388, F:\PROGRAM FILES\MAXTHON\MAXTHON.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 3676, E:\RISING\ARSWP2\ARSWP.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3676, E:\RISING\ARSWP2\ARSWP.EXE] ================================== API HOOK 入口点错误:NtCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003D3ACD) 入口点错误:NtWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003D3B6D) 入口点错误:ZwCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003D3ACD) 入口点错误:ZwWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003D3B6D) 入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: 0x00FA1FFD) 入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: 0x00FA20E5) ================================== 隐藏进程 N/A ================================== [/CODE]