[CODE] 2008-05-13,11:04:32 System Repair Engineer 2.5.16.900 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] <; "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background> [(Verified)Microsoft Corporation] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher] <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher] <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] <; SkyTel.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher] <; ALCMTR.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher] [] <; "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"> [Cyberlink Corp.] <; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE> [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] <; C:\WINDOWS\system32\igfxtray.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] <; "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"> [(Verified)"Sun Microsystems, Inc."] <; C:\WINDOWS\system32\SysMonitor.exe> [ ] <; C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 0> [N/A] <; C:\Acer\Empowering Technology\eLock\Monitor\LaunchMonitor.exe> [ ] <; "C:\Acer\LANScope Agent\awtray.exe"> [OSA Technologies Inc., An Avocent Company] [(Verified)Microsoft Corporation] <; SafeSignCertReg.exe> [A.E.T. Europe B.V.] [] <"C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"> [N/A] [] <%systemroot%\system32\dumprep 0 -k> [N/A] <"C:\Program Files\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Science and Technology Corporation Limited] <360Safetray> [(Verified)Qizhi Software (beijing) Co. Ltd] <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd] <"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"> [(Verified)"Adobe Systems, Incorporated"] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}> [(Verified)Beijing Rising Science and Technology Corporation Limited] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8b15971b-5355-4c82-8c07-7e181ea07608}] [(Verified)Microsoft Windows Publisher] ================================== 启动文件夹 [Acer Empowering Technology] C:\Acer\EMPOWE~1\ACEREM~1.EXE [Acer Inc.]> [Acer WLAN 11g USB Dongle] C:\PROGRA~1\ACERWL~1\ZDWlan.exe [X-Micro Technology Corp.]> [腾讯QQ] C:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]> [飞鸽传书] C:\PROGRA~1\IPMsg\ipmsg.exe [Azhi.Net]> ================================== 服务 [Memory Check Service / AcerMemUsageCheckService][Running/Auto Start] [ASP.NET State Service / aspnet_state][Stopped/Manual Start] [AdminWorks Agent X6 / AWService][Running/Auto Start] <"C:\Acer\LANScope Agent\awServ.exe"> [Contrl Center of Storm Media / ccosm][Running/Auto Start] <北京暴风网际科技有限公司> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [InstallDriver Table Manager / IDriverT][Stopped/Manual Start] <"C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"> [LightScribeService Direct Disc Labeling Service / LightScribeService][Running/Auto Start] <"c:\Program Files\Common Files\LightScribe\LSSrvc.exe"> [LiveUpdate / LiveUpdate][Stopped/Manual Start] <"C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE"> [LiveUpdate Notice Service / LiveUpdate Notice Service][Running/Auto Start] <"C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll"> [LockServ / LockServ][Running/Auto Start] [P4P Service / P4P Service][Running/Auto Start] [Rising Process Communication Center / RsCCenter][Running/Auto Start] <"C:\Program Files\Rising\Rav\CCenter.exe"> [Rising RealTime Monitor / RsRavMon][Running/Auto Start] <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"> [自动 LiveUpdate 调度程序 / 自动 LiveUpdate 调度程序][Running/Auto Start] <"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"> ================================== 驱动程序 [Symantec Eraser Control driver / eeCtrl][Running/System Start] <\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys> [eLock2BurnerLockDriver / eLock2BurnerLockDriver][Running/Auto Start] <\??\C:\WINDOWS\system32\eLock2BurnerLockDriver.sys> [eLock2FSCTLDriver / eLock2FSCTLDriver][Running/Auto Start] <\??\C:\WINDOWS\system32\eLock2FSCTLDriver.sys> [usb Card Device / ft2kEnum][Running/Manual Start] [USB Chip Holder Service / GDBaseSmc][Running/Manual Start] [USB Chip Service / GD_USB][Running/Manual Start] <> [Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start] [HookCont / HookCont][Running/System Start] <\SystemRoot\system32\drivers\HookCont.sys> [HookNtos / HookNtos][Running/System Start] <\SystemRoot\system32\drivers\HookNtos.sys> [HookReg / HookReg][Running/System Start] <\SystemRoot\system32\drivers\HookReg.sys> [HookSys / HookSys][Running/System Start] <\SystemRoot\system32\drivers\HookSys.sys> [ialm / ialm][Running/Manual Start] [int15 / int15][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\int15.sys> [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start] [NetMonitor Protocol / NETMNT][Stopped/Manual Start] [Upper Class Filter Driver / NTIDrvr][Running/Manual Start] [OsaFsLoc / OsaFsLoc][Running/System Start] <\??\C:\WINDOWS\system32\drivers\OsaFsLoc.sys> [osaio / osaio][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\osaio.sys> [osanbm / osanbm][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\osanbm.sys> [psdfilter / psdfilter][Stopped/Manual Start] <\??\C:\WINDOWS\system32\Drivers\psdfilter.sys> [psdvdisk / psdvdisk][Stopped/Manual Start] <\??\C:\WINDOWS\system32\Drivers\psdvdisk.sys> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [SmartCard Reader Device / Reader_Device][Running/Manual Start] [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [SafeBoxKrnl / SafeBoxKrnl][Running/System Start] <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心> [Secdrv / Secdrv][Stopped/Manual Start] [tvicport / tvicport][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\tvicport.sys> [NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller / yukonwxp][Running/Manual Start] [ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS) / ZD1211BU(ZyDAS)][Stopped/Manual Start] [ZyDAS ZD1211 IEEE 802.11b+g Wireless LAN Driver (USB)(ZyDAS) / ZD1211U(ZyDAS)][Stopped/Manual Start] [ZDPSp50 NDIS Protocol Driver / ZDPSp50][Running/Manual Start] [zntport / zntport][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\zntport.sys> ================================== 浏览器加载项 [Adobe PDF Reader Link Helper] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [QQToolbar] {29CF293A-1E7D-4069-9E11-E39698D0AF95} [超级兔子上网精灵] {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} [SSVHelper Class] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [Windows Live 登录帮助程序] {9030D464-4C02-4ABF-8ECC-5164760863C6} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [Java Plug-in 1.6.0_03] {08B0E5C0-4FCB-11CF-AAA5-00401C608501} [信息检索(&R)] {92780B25-18CC-41C8-B9BE-3C9C571A8263} [Messenger] {FB5F1910-F110-11d2-BB9E-00C04F795683} [Acer eDataSecurity Management] {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} [超级兔子上网精灵] {43869BB3-22FD-4F15-9B46-238106BA2F4E} [QQToolbar] {29CF293A-1E7D-4069-9E11-E39698D0AF95} [MMCPlayer Class] {05C1004E-2596-48E5-8E26-39362985EEB9} [PhotoDraw Class] {2375BEE5-F175-4F1C-81EC-8E4E2E72E2DD} [InstallCertListAx Control] {2C867EBE-A499-44FB-8B4C-CC854C767EED} [GDGetTokenInfo Class] {3AA9CF07-DF20-48FF-98BE-DED276E40146} [InfoSecNetSign Class] {5CB840B5-A94E-4AD9-B785-4866E3B04476} [FileTrsmt Control] {6015F138-FCA0-440F-B54E-05E88942234D} [AxInputControl Class] {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} [ICBCOCX Public Key Check] {7AEA10C5-B38F-4D72-A8F0-ED2D43D2A59E} [Java Plug-in 1.6.0_03] {8AD9C840-044E-11D1-B3E9-00805F499D93} [Java Plug-in 1.5.0_06] {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} [Java Plug-in 1.6.0_03] {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [Java Plug-in 1.6.0_03] {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [IcbcSslCacheCleanerCtrl Class] {E9707834-5BF7-4CFF-A639-398427DE1991} [MMCPlayer Class] {05C1004E-2596-48E5-8E26-39362985EEB9} [Adobe PDF Reader Link Helper] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [InfosecCertInstall Class] {0EB487C8-E9AC-43A6-8C4C-083999B0622F} [Windows Media Player] {22D6F312-B0F6-11D0-94AB-0080C74C7E95} [PhotoDraw Class] {2375BEE5-F175-4F1C-81EC-8E4E2E72E2DD} [QQToolbar] {29CF293A-1E7D-4069-9E11-E39698D0AF95} [InstallCertListAx Control] {2C867EBE-A499-44FB-8B4C-CC854C767EED} [DHTML Edit Control Safe for Scripting for IE5] {2D360201-FFF5-11D1-8D03-00A0C959BC0A} [HtmlDlgSafeHelper Class] {3050F819-98B5-11CF-BB82-00AA00BDCE0B} [GDGetTokenInfo Class] {3AA9CF07-DF20-48FF-98BE-DED276E40146} [超级兔子上网精灵] {43869BB3-22FD-4F15-9B46-238106BA2F4E} [Microsoft Office Control] {4453D895-F2A1-4A38-A285-1EF9BD3F6D5D} [XML Document] {48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, N/A> [InfoSecNetSign Class] {5CB840B5-A94E-4AD9-B785-4866E3B04476} [Acer eDataSecurity Management] {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} [FileTrsmt Control] {6015F138-FCA0-440F-B54E-05E88942234D} [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [Active Desktop Mover] {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A> [超级兔子上网精灵] {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} [AxInputControl Class] {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} [SSVHelper Class] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [ICBCOCX Public Key Check] {7AEA10C5-B38F-4D72-A8F0-ED2D43D2A59E} [360SafeLive] {87515F61-A66C-4319-A0E0-D416CB8059E3} [Microsoft Web 浏览器] {8856F961-340A-11D0-A96B-00C04FD705A2} [AxSubmitControl Class] {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} [Windows Live 登录帮助程序] {9030D464-4C02-4ABF-8ECC-5164760863C6} [SearchAssistantOC] {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A> [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [CSetLET Class] {C35D7AE1-0865-4A30-BF07-29FA29324155} [AUDIO__MP3 Moniker Class] {CD3AFA76-B84F-48F0-9393-7EDC34128127} [AUDIO__X_MS_WMA Moniker Class] {CD3AFA84-B84F-48F0-9393-7EDC34128127} [VIDEO__X_MS_WMV Moniker Class] {CD3AFA94-B84F-48F0-9393-7EDC34128127} [Windows Live 登录控制] {D2517915-48CE-4286-970F-921E881B8C5C} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [PasswordEditCtrl Class] {E787FD25-8D7C-4693-AE67-9406BC6E22DF} [IcbcSslCacheCleanerCtrl Class] {E9707834-5BF7-4CFF-A639-398427DE1991} [导出到 Microsoft Office Excel(&X)] [添加到QQ表情] ================================== 正在运行的进程 [PID: 636 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 700 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 724 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\aetcsss1.dll] [A.E.T. Europe B.V., 2.0.0.23] [C:\WINDOWS\system32\aetdlss1.dll] [A.E.T. Europe B.V., 2.0.0.15] [C:\WINDOWS\system32\aetpkss1.dll] [A.E.T. Europe B.V., 2.0.0.21] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 768 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 780 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 940 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1016 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1112 / SYSTEM][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26] [PID: 1128 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)] [PID: 1240 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1368 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1380 / SYSTEM][C:\PROGRAM FILES\RISING\RAV\Ravmond.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.53] [C:\PROGRAM FILES\RISING\RAV\BWList.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.4] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [C:\PROGRAM FILES\RISING\RAV\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16] [C:\PROGRAM FILES\RISING\RAV\RsLog.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.25] [C:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 18] [C:\PROGRAM FILES\RISING\RAV\MonRule.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.23] [C:\PROGRAM FILES\RISING\RAV\Hooksys.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 7] [C:\PROGRAM FILES\RISING\RAV\HookReg.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 2] [C:\PROGRAM FILES\RISING\RAV\HookNtos.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 2] [C:\PROGRAM FILES\RISING\RAV\rswalmon.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\RsStore.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.8] [C:\PROGRAM FILES\RISING\RAV\HookCont.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 1] [C:\Program Files\Rising\Rav\fakescan.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.13] [C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.32] [C:\Program Files\Rising\Rav\recomp.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 36] [C:\Program Files\Rising\Rav\refs.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\viruslib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26] [C:\Program Files\Rising\Rav\relibldr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [C:\PROGRAM FILES\RISING\RAV\HookWeb.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.2] [C:\Program Files\Rising\Rav\ffr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 13] [C:\Program Files\Rising\Rav\nvfile.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 6] [C:\Program Files\Rising\Rav\scanexec.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\unexe.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4] [C:\Program Files\Rising\Rav\scanex.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 65] [C:\Program Files\Rising\Rav\pearc.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5] [C:\Program Files\Rising\Rav\scanpack.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9] [C:\Program Files\Rising\Rav\revm.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 8] [C:\Program Files\Rising\Rav\urutils.dll] [, 20, 0, 0, 6] [C:\Program Files\Rising\Rav\ur000.dat] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 18] [C:\Program Files\Rising\Rav\scriptci.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [C:\Program Files\Rising\Rav\ur023.dat] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 1] [C:\Program Files\Rising\Rav\uroutine.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26] [C:\Program Files\Rising\Rav\ur001.dat] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [C:\Program Files\Rising\Rav\scansct.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9] [PID: 1672 / SYSTEM][C:\PROGRAM FILES\RISING\RAV\RavStub.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.9] [C:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 18] [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [PID: 1740 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\system32\HpTcpMon.dll] [Hewlett Packard, 6.01.00.007] [C:\WINDOWS\system32\hpzjrd01.dll] [Hewlett Packard, 2.01.00.004] [C:\WINDOWS\system32\HPTcpMUI.dll] [Microsoft Corporation, 6.01.00.007] [C:\WINDOWS\system32\hptcpmib.dll] [Hewlett Packard, 6.01.00.007] [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.1897.0] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.1897.0] [PID: 1796 / LOCAL SERVICE][C:\WINDOWS\System32\SCardSvr.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 188 / Ying Kuai][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006] [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 8.1.0.0] [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS] [Adobe Systems, Inc., 8.0.0.0] [C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.4624] [C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4624] [C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4624] [C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3.0.0.4624] [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4624] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [C:\WINDOWS\system32\eDSshellExt.dll] [HiTRUST, 2, 2, 0, 11] [C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 8.0.0.2006102200] [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] [PID: 236 / SYSTEM][C:\Acer\Empowering Technology\ePerformance\MemCheck.exe] [Acer Inc., 2.0.2008.0] [C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 2.0.50727.253 (QFE.050727-2500)] [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll] [Microsoft Corporation, 1.1.4322.2407] [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll] [Microsoft Corporation, 1.1.4322.2032] [c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll] [Microsoft Corporation, 1.1.4322.2407] [c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_69b6f980\mscorlib.dll] [N/A, ] [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll] [Microsoft Corporation, 1.1.4322.2407] [c:\windows\assembly\gac\mscorlib.resources\1.0.5000.0_zh-chs_b77a5c561934e089\mscorlib.resources.dll] [Microsoft Corporation, 1.1.4322.573] [c:\windows\assembly\gac\system.serviceprocess\1.0.5000.0__b03f5f7f11d50a3a\system.serviceprocess.dll] [Microsoft Corporation, 1.1.4322.2032] [c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll] [Microsoft Corporation, 1.1.4322.2407] [c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_0e4121a9\system.dll] [N/A, ] [c:\acer\empowering technology\eperformance\acer.empowering.shared.dll] [Acer Inc., 2.0.2322.27675] [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL] [Microsoft Corporation, 1.1.4322.2407] [c:\acer\empowering technology\eperformance\acermemusagecheckservinterface.dll] [ , 0.0.0.0] [c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll] [Microsoft Corporation, 1.1.4322.2032] [c:\windows\assembly\gac\system.serviceprocess.resources\1.0.5000.0_zh-chs_b03f5f7f11d50a3a\system.serviceprocess.resources.dll] [Microsoft Corporation, 1.1.4322.573] [PID: 456 / SYSTEM][C:\Acer\LANScope Agent\awServ.exe] [OSA Technologies Inc., An Avocent Company, 1.5.27.81] [C:\WINDOWS\system32\rtl70.bpl] [Borland Software Corporation, 7.0.8.1] [C:\WINDOWS\system32\vcl70.bpl] [Borland Software Corporation, 7.0.8.1] [C:\WINDOWS\system32\indy70.bpl] [N/A, ] [C:\WINDOWS\system32\soaprtl70.bpl] [Borland Software Corporation, 7.0.4.453] [C:\WINDOWS\system32\xmlrtl70.bpl] [Borland Software Corporation, 7.0.4.453] [C:\WINDOWS\system32\dbrtl70.bpl] [Borland Software Corporation, 7.0.8.1] [C:\WINDOWS\system32\inet70.bpl] [Borland Software Corporation, 7.0.4.453] [C:\WINDOWS\system32\dsnap70.bpl] [Borland Software Corporation, 7.0.8.1] [C:\WINDOWS\system32\TMSD7.bpl] [, 1.0.0.0] [C:\WINDOWS\system32\designide70.bpl] [Borland Software Corporation, 7.0.8.1] [C:\WINDOWS\system32\vclactnband70.bpl] [Borland Software Corporation, 7.0.4.453] [C:\WINDOWS\system32\vclx70.bpl] [Borland Software Corporation, 7.0.4.453] [C:\WINDOWS\system32\vcldb70.bpl] [Borland Software Corporation, 7.0.8.1] [C:\WINDOWS\system32\VclSmp70.bpl] [Borland Software Corporation, 7.0.0.188] [C:\WINDOWS\system32\vcljpg70.bpl] [Borland Software Corporation, 7.0.4.453] [C:\Acer\LANScope Agent\Provider\AcerManagePlug.dll] [OSA Technologies Inc., An Avocent Company, 1.5.9.8] [C:\Acer\LANScope Agent\OsaFsLoc.dll] [OSA Technologies Inc. Taiwan Branch, 2, 0, 0, 6] [C:\Acer\LANScope Agent\Provider\AlertChangPlug.dll] [OSA Technologies Inc., An Avocent Company, 1.5.14.17] [C:\Acer\LANScope Agent\Provider\ASensorPlug.dll] [OSA Technologies Inc., An Avocent Company, 1.5.9.12] [C:\Acer\LANScope Agent\osaiodll.dll] [OSA Technologies Inc. Taiwan Branch, 1, 1, 2, 16] [C:\Acer\LANScope Agent\Provider\DiscoverPlug.dll] [OSA Technologies Inc., An Avocent Company, 1.5.12.17] [C:\Acer\LANScope Agent\Provider\FileTransPlug.dll] [OSA Technologies Inc., An Avocent Company, 1.5.6.9] [C:\WINDOWS\system32\SUIPackD7.bpl] [N/A, ] [C:\Acer\LANScope Agent\Provider\FsLockPlug.dll] [OSA Technologies Inc., An Avocent Company, 1.5.7.12] [C:\Acer\LANScope Agent\Provider\NBPlug.dll] [OSA Technologies Inc., An Avocent Company, 1.5.3.4] [C:\Acer\LANScope Agent\NBAPI.dll] [Avocent Inc., 1, 0, 2, 3] [C:\Acer\LANScope Agent\Provider\NetMonitorPlug.dll] [OSA Technologies Inc., An Avocent Company, 1.2.3.5] [C:\Acer\LANScope Agent\NetMonitor.dll] [N/A, ] [C:\Acer\LANScope Agent\Provider\OptimizationPlug.dll] [OSA Technologies Inc., An Avocent Company, 1.5.5.6] [C:\Acer\LANScope Agent\Provider\SmbiosPlug.dll] [OSA Technologies Inc., An Avocent Company, 1.5.5.6] [C:\Acer\LANScope Agent\IpmiTrans.dll] [OSA Technologies Inc. Taiwan Branch, 1, 0, 3, 14] [C:\Acer\LANScope Agent\Provider\SystemPlug.dll] [OSA Technologies Inc., An Avocent Company, 1.5.7.9] [C:\Acer\LANScope Agent\SYSAPI.dll] [OSA Technologies Inc. Taiwan Branch, 1, 0, 5, 17] [C:\Acer\LANScope Agent\cpuid_dll.dll] [ OSA Technologies, Inc., 1, 0, 6, 13] [C:\Acer\LANScope Agent\Provider\WinActns.dll] [OSA Technologies, an Avocent Company, 1.5.9.16] [C:\Acer\LANScope Agent\Provider\WMIPlug.dll] [OSA Technologies Inc., An Avocent Company, 1.5.5.6] [C:\Acer\LANScope Agent\s_lm85m.dll] [OSA Technologies, An Avocent Company, 1, 2, 2, 5] [C:\Acer\LANScope Agent\s_smsc47m1.dll] [OSA Technologies, An Avocent Company, 1, 2, 4, 9] [C:\Acer\LANScope Agent\s_it87.dll] [OSA Technologies, An Avocent Company, 1, 2, 2, 3] [C:\WINDOWS\system32\msxml4.dll] [Microsoft Corporation, 4.20.9848.0] [PID: 532 / Ying Kuai][C:\WINDOWS\RTHDCPL.EXE] [Realtek Semiconductor Corp., 2.0.6.6] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006] [PID: 584 / Ying Kuai][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3.0.0.4624] [C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4624] [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4624] [C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4624] [PID: 416 / Ying Kuai][C:\WINDOWS\system32\igfxpers.exe] [Intel Corporation, 3.0.0.4624] [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4624] [PID: 704 / Ying Kuai][C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe] [Symantec Corporation, 1.2.0.18] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll] [Symantec Corporation, 1.2.0.18] [C:\PROGRA~1\COMMON~1\SYMANT~1\PIF\{B8E1D~1\AlertUi.dll] [Symantec Corporation, 1.2.0.18] [PID: 784 / Ying Kuai][E:\日历\TaskXP.exe] [N/A, ] [PID: 936 / Ying Kuai][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.19] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 18] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16] [PID: 1056 / Ying Kuai][C:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.92] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 18] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [C:\Program Files\Rising\Rav\recomp.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 36] [C:\Program Files\Rising\Rav\refs.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\viruslib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26] [C:\Program Files\Rising\Rav\relibldr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [C:\Program Files\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16] [C:\Program Files\Rising\Rav\MonRule.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.23] [C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [C:\Program Files\Rising\Rav\Rsguilib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 72] [C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0] [PID: 1300 / SYSTEM][C:\Program Files\StormII\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 3, 15] [C:\Program Files\StormII\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0] [PID: 1388 / Ying Kuai][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006] [PID: 1736 / Ying Kuai][C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe] [X-Micro Technology Corp., 2, 21, 0, 0] [C:\Program Files\Acer WLAN 11g USB Dongle\dot1x_dll.dll] [, 2, 12, 0, 0] [C:\Program Files\Acer WLAN 11g USB Dongle\W32N55.dll] [Printing Communications Assoc., Inc. (PCAUSA), 5.5.18.03] [C:\Program Files\Acer WLAN 11g USB Dongle\SSLEAY32.dll] [N/A, ] [C:\Program Files\Acer WLAN 11g USB Dongle\LIBEAY32.dll] [N/A, ] [C:\Program Files\Acer WLAN 11g USB Dongle\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Acer WLAN 11g USB Dongle\ZDWLAN.dll] [, 2, 21, 0, 0] [C:\Program Files\Acer WLAN 11g USB Dongle\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006] [PID: 1872 / SYSTEM][c:\Program Files\Common Files\LightScribe\LSSrvc.exe] [Hewlett-Packard Company, 1.4.74.1] [c:\Program Files\Common Files\LightScribe\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [c:\Program Files\Common Files\LightScribe\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [PID: 2096 / SYSTEM][C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe] [Symantec Corporation, 1.2.0.18] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll] [Symantec Corporation, 1.2.0.18] [C:\PROGRA~1\COMMON~1\SYMANT~1\PIF\{B8E1D~1\PollMgr.dll] [Symantec Corporation, 1.2.0.18] [PID: 2112 / Ying Kuai][C:\Program Files\IPMsg\ipmsg.exe] [Azhi.Net, 2.06] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006] [PID: 2132 / SYSTEM][C:\Acer\Empowering Technology\eLock\LockServ.exe] [N/A, ] [C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 2.0.50727.253 (QFE.050727-2500)] [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll] [Microsoft Corporation, 1.1.4322.2407] [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll] [Microsoft Corporation, 1.1.4322.2032] [c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll] [Microsoft Corporation, 1.1.4322.2407] [c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_69b6f980\mscorlib.dll] [N/A, ] [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll] [Microsoft Corporation, 1.1.4322.2407] [c:\windows\assembly\gac\mscorlib.resources\1.0.5000.0_zh-chs_b77a5c561934e089\mscorlib.resources.dll] [Microsoft Corporation, 1.1.4322.573] [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL] [Microsoft Corporation, 1.1.4322.2407] [PID: 2348 / SYSTEM][C:\Program Files\Common Files\Sogou PXP\p2psvr.exe] [Sohu.com Inc., 2, 0, 0, 33] [C:\Program Files\Sogou PXP\vodsvr.dll] [Sohu.com Inc., 3, 0, 0, 35] [C:\Program Files\Sogou PXP\pxpnet.dll] [Sohu.com Inc., 2, 0, 0, 18] [C:\Program Files\Sogou PXP\p2pclient.dll] [Sohu.com Inc., 2, 9, 1, 20] [PID: 2420 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2468 / SYSTEM][C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe] [Symantec Corporation, 3.0.0.171] [C:\Program Files\Symantec\LiveUpdate\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Symantec\LiveUpdate\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [PID: 3212 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 3652 / Ying Kuai][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006] [PID: 3432 / Ying Kuai][C:\Documents and Settings\Ying Kuai\桌面\arswp2(1)\arswp2\arswp.exe] [ArSwp.com, 2, 7, 0, 415] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006] [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.5510] [C:\Documents and Settings\Ying Kuai\桌面\arswp2(1)\arswp2\plugin\ArFix.dll] [ArSwp.Com, 2, 5, 0, 0] [PID: 652 / Ying Kuai][C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE] [Microsoft Corporation, 11.0.5510] [C:\Program Files\Microsoft Office\OFFICE11\OUTLLIB.dll] [Microsoft Corporation, 11.0.5608] [C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll] [Microsoft Corporation, 11.0.5606] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006] [C:\Program Files\Microsoft Office\OFFICE11\2052\outllibr.dll] [Microsoft Corporation, 11.0.5516] [C:\Program Files\Common Files\System\MSMAPI\2052\msmapi32.dll] [Microsoft Corporation, 11.0.5601] [C:\Program Files\Common Files\System\MSMAPI\2052\mapi32.dll] [Microsoft Corporation, 1.0.2536.0] [C:\Program Files\Common Files\SYSTEM\MSMAPI\2052\MAPIR.DLL] [Microsoft Corporation, 11.0.5516] [C:\Program Files\Common Files\SYSTEM\MSMAPI\2052\contab32.dll] [Microsoft Corporation, 11.0.5510] [C:\Program Files\Common Files\SYSTEM\MSMAPI\2052\EMSABP32.DLL] [Microsoft Corporation, 11.0.5510] [C:\Program Files\Common Files\SYSTEM\MSMAPI\2052\EMSUI32.DLL] [Microsoft Corporation, 11.0.5510] [C:\Program Files\Common Files\SYSTEM\MSMAPI\2052\EMSMDB32.DLL] [Microsoft Corporation, 11.0.5604] [C:\Program Files\Common Files\SYSTEM\MSMAPI\2052\MSPST32.DLL] [Microsoft Corporation, 11.0.5604] [C:\Program Files\Common Files\Microsoft Shared\office11\riched20.dll] [Microsoft Corporation, 5.50.30.2002] [C:\Program Files\Microsoft Office\OFFICE11\Intldate.dll] [Microsoft Corporation, 11.0.5510] [C:\WINDOWS\system32\OAddin.dll] [TODO: <公司名>, 1.0.0.1] [C:\WINDOWS\system32\sysenv.dll] [HiTRUST, 2, 2, 0, 44] [C:\WINDOWS\system32\ShowErrMsg.dll] [HiTRUST, 2, 2, 0, 13] [C:\WINDOWS\system32\CryptoAPI.dll] [HiTRUST, 2, 2, 0, 11] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\UIVCL.dll] [, 2.2.0.17] [C:\Program Files\Microsoft Office\OFFICE11\OUTLRPC.dll] [Microsoft Corporation, 11.0.5510] [C:\Program Files\Microsoft Office\OFFICE11\exsec32.dll] [Microsoft Corporation, 11.0.5523] [C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\IETAG.DLL] [Microsoft Corporation, 11.0.5510] [C:\PROGRA~1\MICROS~2\OFFICE11\OUTLACCT.DLL] [Microsoft Corporation, 11.0.5510] [C:\Program Files\Microsoft Office\OFFICE11\SENDTO.DLL] [Microsoft Corporation, 11.0.5510] [C:\Program Files\Microsoft Office\OFFICE11\outlph.dll] [Microsoft Corporation, 11.0.5510] [C:\Program Files\Microsoft Office\OFFICE11\msostyle.dll] [Microsoft Corporation, 11.0.5510] [C:\Program Files\Microsoft Office\OFFICE11\RTFHTML.DLL] [Microsoft Corporation, 11.0.5515] [C:\Program Files\Microsoft Office\OFFICE11\GdiPlus.DLL] [Microsoft Corporation, 6.0.3260.0] [C:\Program Files\Common Files\SYSTEM\MSMAPI\2052\outex.dll] [Microsoft Corporation, 11.0.5525] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\UNIDRVUI.DLL] [Microsoft Corporation, 5.2.3790.120 (srv03_qfe.031205-1652)] [PID: 904 / Ying Kuai][C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE] [Microsoft Corporation, 11.0.5604] [C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll] [Microsoft Corporation, 11.0.5606] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006] [C:\Program Files\Common Files\Microsoft Shared\office11\riched20.dll] [Microsoft Corporation, 5.50.30.2002] [C:\PROGRA~1\MICROS~2\OFFICE11\ADDINS\SYMINPUT.DLL] [Microsoft Corporation, 1.02] [C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690] [C:\WINDOWS\system32\VB6CHS.DLL] [Microsoft Corporation, 6.00.8988] [C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL] [Microsoft Corporation, 1.1.6215] [C:\Program Files\Common Files\Microsoft Shared\PROOF\mslid.dll] [Microsoft Corporation, 1.0.2305] [C:\Program Files\Common Files\Microsoft Shared\PROOF\2052\MSGR3EN.DLL] [Microsoft Corporation, 3.1.2303] [C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527] [C:\Program Files\Microsoft Office\OFFICE11\msostyle.dll] [Microsoft Corporation, 11.0.5510] [C:\Program Files\Microsoft Office\OFFICE11\SENDTO.DLL] [Microsoft Corporation, 11.0.5510] [C:\Program Files\Microsoft Office\OFFICE11\ENVELOPE.DLL] [Microsoft Corporation, 11.0.5530] [C:\Program Files\Microsoft Office\OFFICE11\2052\envelopr.dll] [Microsoft Corporation, 11.0.5510] [C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\INTLNAME.DLL] [Microsoft Corporation, 11.0.5315] [C:\Program Files\Common Files\Microsoft Shared\Smart Tag\CHDATEST.DLL] [Microsoft Corporation, 2.00] [C:\Program Files\Common Files\Microsoft Shared\Smart Tag\Chinese Measurement Converter\CHMETCNV.DLL] [Microsoft Corp., 1.00] [C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\FNAME.DLL] [Microsoft Corporation, 11.0.5510] [C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\2052\stintl.dll] [Microsoft Corporation, 11.0.5510] [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\UNIDRVUI.DLL] [Microsoft Corporation, 5.2.3790.120 (srv03_qfe.031205-1652)] [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\UNIDRV.DLL] [Microsoft Corporation, 5.2.3790.184 (srv03_qfe.040410-1236)] [C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL] [Microsoft Corporation, 6.04.9969] [C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\2052\VBE6INTL.DLL] [Microsoft Corporation, 6.03.9070] [C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL] [Microsoft Corporation, 9.0.5510.0] [C:\Program Files\Common Files\Microsoft Shared\PROOF\2052\MSGR3SC.DLL] [Microsoft Corporation, 3.0.1707.0] [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS] [Adobe Systems, Inc., 8.0.0.0] [PID: 2640 / Ying Kuai][C:\Documents and Settings\Ying Kuai\桌面\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 1, 0, 1006] [C:\Documents and Settings\Ying Kuai\桌面\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 127.0.0.1 yu.8s7.net 127.0.0.1 1.jopanqc.com 127.0.0.1 2.joppnqq.com 127.0.0.1 wg.47255.com 127.0.0.1 1.joppnqq.com 127.0.0.1 xxx.m111.biz 127.0.0.1 1.jopenqc.com 127.0.0.1 1.jopenkk.com 127.0.0.1 xxx.vh7.biz 127.0.0.1 xxx.j41m.com 127.0.0.1 3.joppnqq.com 127.0.0.1 d.93se.com 127.0.0.1 www.868wg.com 127.0.0.1 xxx.mmma.biz 127.0.0.1 ilove.com 127.0.0.1 tp.shpzhan.cn 127.0.0.1 www.tomwg.com 127.0.0.1 www.cike007.cn 127.0.0.1 www.22aaa.com 127.0.0.1 xx.exiao01.com 127.0.0.1 www.exiao01.com 127.0.0.1 www.exiao01.com 127.0.0.1 new.749571.com 127.0.0.1 xtx.kv8.info 127.0.0.1 cao.kv8.info 127.0.0.1 1.jopmmqq.com 127.0.0.1 171817.171817.com 127.0.0.1 d2.llsging.com 127.0.0.1 down.malasc.cn 127.0.0.1 llboss.com 127.0.0.1 nx.51ylb.cn 127.0.0.1 my.531jx.cn 127.0.0.1 qqq.dzydhx.com 127.0.0.1 qqq.hao1658.com 127.0.0.1 www.333292.com 127.0.0.1 down.18dd.net 127.0.0.1 up.22x44.com 127.0.0.1 aaa.faba01.com 127.0.0.1 bad.tqdlt.cn 127.0.0.1 1.chsipo.com 127.0.0.1 c3.aishangai.net 127.0.0.1 c2.aishangai.net 127.0.0.1 xxx.188dm.com 127.0.0.1 x2.1a2b3c1.com 127.0.0.1 d1.163500.net 127.0.0.1 down.google-serv.cn 127.0.0.1 gxgxy.net 127.0.0.1 c0mo.com ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 456, C:\ACER\LANSCOPE AGENT\AWSERV.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 784, E:\日历\TASKXP.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1736, C:\PROGRAM FILES\ACER WLAN 11G USB DONGLE\ZDWLAN.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2112, C:\PROGRAM FILES\IPMSG\IPMSG.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2132, C:\ACER\EMPOWERING TECHNOLOGY\ELOCK\LOCKSERV.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3432, C:\DOCUMENTS AND SETTINGS\YING KUAI\桌面\ARSWP2(1)\ARSWP2\ARSWP.EXE] ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]