[CODE] 2008-06-07,18:33:15 System Repair Engineer 2.6.8.980 Smallfrogs (http://www.KZTechs.com) Windows XP Home Edition Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [File is missing] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [Lenovo Group Limited] [] [Lenovo Group Limited] [Lenovo] [Lenovo, Ltd. and IBM Corporation.] [] [Lenovo Group Limited] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [Analog Devices, Inc.] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [Lenovo Group Limited] [Sun Microsystems, Inc.] [Lenovo Group Limited] [Lenovo Group Limited] <"C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"> [Diskeeper Corporation] [] [] [Google Inc.] <"C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe"> [Utimaco Safeware AG] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [] <"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"> [Cyberlink Corp.] <"C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"> [] [(Verified)Microsoft Windows Hardware Compatibility Publisher] <"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.] [Hewlett-Packard] <"C:\Program Files\QuickTime\QTTask.exe" -atboottime> [Apple Inc.] [Hewlett-Packard] <"C:\Program Files\Rising\AntiSpyware\runiep.exe" /startup> [Beijing Rising Technology Co., Ltd.] <"C:\Program Files\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Science and Technology Corporation Limited] [File is missing] [File is missing] [File is missing] [File is missing] [File is missing] [File is missing] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce] [Beijing Rising Technology Co., Ltd.] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] [Beijing Rising Technology Co., Ltd.] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}> [(Verified)Beijing Rising Science and Technology Corporation Limited] <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}> [Beijing Rising Technology Co., Ltd.] [N/A] <> [N/A] <> [N/A] <> [N/A] <> [N/A] [N/A] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ACNotify] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AwayNotify] [Lenovo Group Limited] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tpfnf2] [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tphotkey] [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] [(Verified)Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctorMain.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SelfUpdate.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path] [N/A] ================================== 启动文件夹 [Adobe Reader Speed Launch] C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [Adobe Systems Incorporated]> [Digital Line Detect] C:\PROGRA~1\DIGITA~1\DLG.exe [BVRP Software]> ================================== 服务 [Ac Profile Manager Service / AcPrfMgrSvc][Running/Auto Start] [Access Connections Main Service / AcSvc][Running/Auto Start] [Apple Mobile Device / Apple Mobile Device][Running/Auto Start] <"C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"> [Application Management / AppMgmt][Stopped/Manual Start] %SystemRoot%\System32\appmgmts.dll> [Diskeeper / Diskeeper][Running/Auto Start] <"C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe"> [Intel(R) PROSet/Wireless Event Log / EvtEng][Running/Auto Start] [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [ThinkPad PM Service / IBMPMSVC][Running/Auto Start] <> [InstallDriver Table Manager / IDriverT][Stopped/Manual Start] <"C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe"> [IPS 核心服务 / IPSSVC][Running/Auto Start] [Office Source Engine / ose][Stopped/Manual Start] <"C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"> [IBM PSA Access Driver Control / PsaSrv][Stopped/Manual Start] [Intel(R) PROSet/Wireless Registry Service / RegSrvc][Running/Auto Start] [Cyberlink RichVideo Service(CRVS) / RichVideo][Running/Auto Start] <"C:\Program Files\CyberLink\Shared files\RichVideo.exe"><> [Rising Process Communication Center / RsCCenter][Running/Auto Start] <"C:\Program Files\Rising\Rav\CCenter.exe"> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"> [Intel(R) PROSet/Wireless Service / S24EventMonitor][Running/Auto Start] [System Update / SUService][Running/Auto Start] <> [ThinkVantage Registry Monitor Service / ThinkVantage Registry Monitor Service][Running/Auto Start] <"C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe"><> [ThinkPad HDD APS Logging Service / TPHDEXLGSVC][Running/Auto Start] <(File is missing)> [IBM KCU Service / TpKmpSVC][Running/Auto Start] [TSS Core Service / TSSCoreService][Running/Auto Start] <"C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe"> [TVT Backup Service / TVT Backup Service][Running/Auto Start] <"C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe"> [TVT Scheduler / TVT Scheduler][Running/Auto Start] <"C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe"> [tvtnetwk / tvtnetwk][Running/Auto Start] [Windows Media Connect Service / WMConnectCDS][Stopped/Manual Start] ================================== 驱动程序 [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start] [ADI UAA Function Driver for High Definition Audio Service / ADIHdAudAddService][Running/Manual Start] [AEAudio Service / AEAudioService][Running/Manual Start] [AEGIS Protocol (IEEE 802.1x) v3.5.3.0 / AegisP][Running/Auto Start] [AliIde / AliIde][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aliide.sys> [AMD AGP Bus Filter Driver / amdagp][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\amdagp.sys> [ANC / ANC][Running/System Start] [asc / asc][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\asc.sys> [asc3550 / asc3550][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\asc3550.sys> [atmeltpm / atmeltpm][Running/Manual Start] [CmdIde / CmdIde][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\cmdide.sys> [dac2w2k / dac2w2k][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\dac2w2k.sys> [Intel(R) PRO Adapter Driver / E100B][Stopped/Manual Start] [Intel(R) PRO/1000 PCI Express Network Connection Driver / e1express][Running/Manual Start] [IBM eGatherer / EGATHDRV][Running/Auto Start] <\??\C:\WINDOWS\SYSTEM32\EGATHDRV.SYS> [Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start] [HookCont / HookCont][Running/System Start] <\SystemRoot\system32\drivers\HookCont.sys> [HookNtos / HookNtos][Running/System Start] <\SystemRoot\system32\drivers\HookNtos.sys> [HookReg / HookReg][Running/System Start] <\SystemRoot\system32\drivers\HookReg.sys> [HookSys / HookSys][Running/System Start] <\SystemRoot\system32\drivers\HookSys.sys> [HSF_DPV / HSF_DPV][Running/Manual Start] [HSXHWAZL / HSXHWAZL][Running/Manual Start] [ialm / ialm][Running/Manual Start] [Intel AHCI Controller / iaStor][Running/Boot Start] <\SystemRoot\system32\DRIVERS\iaStor.sys> [IBMPMDRV / IBMPMDRV][Running/Manual Start] [IBMTPCHK / IBMTPCHK][Running/System Start] <\??\C:\WINDOWS\system32\Drivers\IBMBLDID.sys> [mdmxsdk / mdmxsdk][Running/Auto Start] [mraid35x / mraid35x][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\mraid35x.sys> [用于 Windows XP 32 Bit 版的英特尔(R) PRO/无线 3945ABG 适配器驱动程序 / NETw3x32][Running/Manual Start] [non / non][Stopped/Manual Start] <\??\C:\WINDOWS\system32\drivers\non.sys> [NSC Infrared Device Driver / NSCIRDA][Running/Manual Start] [nv / nv][Stopped/Manual Start] [pmem / pmem][Running/Auto Start] <\??\C:\WINDOWS\System32\drivers\pmemnt.sys> [PrivateDisk / PrivateDisk][Running/Auto Start] <\??\C:\Program Files\Lenovo\SafeGuard PrivateDisk\PrivateDiskM.sys> [IPS 帮助器驱动程序 / PROCDD][Running/Auto Start] [IBM PSA Access Driver / psadd][Stopped/Manual Start] <\??\C:\WINDOWS\system32\Drivers\psadd.sys> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [PxHelp20 / PxHelp20][Running/Boot Start] <\SystemRoot\System32\Drivers\PxHelp20.sys> [ql1080 / ql1080][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ql1080.sys> [ql12160 / ql12160][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ql12160.sys> [ql1280 / ql1280][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ql1280.sys> [RsAntiSpyware / RsAntiSpyware][Running/Boot Start] <\SystemRoot\system32\drivers\RsBoot.sys> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [WLAN Transport / s24trans][Running/Auto Start] [sagnkc / sagnkc][Stopped/Manual Start] <\??\C:\WINDOWS\system32\drivers\sagnkc.sys> [Secdrv / Secdrv][Stopped/Manual Start] [SIS AGP Bus Filter / sisagp][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\sisagp.sys> [Smapint / Smapint][Running/System Start] [smi2 / smi2][Running/Auto Start] <\??\C:\Program Files\SMI2\smi2.sys> [Sparrow / Sparrow][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\sparrow.sys> [symc810 / symc810][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\symc810.sys> [symc8xx / symc8xx][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\symc8xx.sys> [sym_hi / sym_hi][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\sym_hi.sys> [sym_u3 / sym_u3][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\sym_u3.sys> [TDSMAPI / TDSMAPI][Running/System Start] [PS/2 TrackPoint Driver / Tp4Track][Running/Manual Start] [TPPWRIF / TPPWRIF][Running/System Start] [TSMAPIP / TSMAPIP][Running/System Start] [tvtfilter / tvtfilter][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\tvtfilter.sys> [TVT Packet Filter Service / TVTPktFilter][Running/Manual Start] [ultra / ultra][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\ultra.sys> [winachsf / winachsf][Running/Manual Start] ================================== 浏览器加载项 [AcroIEHlprObj Class] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [FGCatchUrl] {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} [SSVHelper Class] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [CPwmIEBrowserHelper Object] {F040E541-A427-4CF7-85D8-75E3E0F476C5} [FlashGet GetFlash Class] {F156768E-81EF-470C-9057-481BA8380DBA} [] {e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, N/A> [卡卡上网安全助手] {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} [Edit Class] {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} [iTrusPTA Class] {1E0DFFCF-27FF-4574-849B-55007349FEDA} [Java Plug-in] {8AD9C840-044E-11D1-B3E9-00805F499D93} [Java Plug-in] {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} [Java Plug-in 1.5.0_06] {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [AcroIEHlprObj Class] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [Fade] {16B280C5-EE70-11D1-9066-00C04FD9189D} [Windows Media Player] {22D6F312-B0F6-11D0-94AB-0080C74C7E95} [HTML Document] {25336920-03F9-11CF-8FD0-00AA00686F13} [DHTML Edit Control Safe for Scripting for IE5] {2D360201-FFF5-11D1-8D03-00A0C959BC0A} [FGCatchUrl] {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} [RealPlayer RAM Download Handler] {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} [XML Document] {48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, N/A> [Shell Name Space] {55136805-B2DE-11D1-B9F2-00A0C98BC547} [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [SSVHelper Class] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [Microsoft Web Browser] {8856F961-340A-11D0-A96B-00C04FD705A2} [SearchAssistantOC] {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A> [RDS.DataSpace] {BD96C556-65A3-11D0-983A-00C04FC29E36} [RealPlayer G2 Control] {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [卡卡上网安全助手] {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} [CPwmIEBrowserHelper Object] {F040E541-A427-4CF7-85D8-75E3E0F476C5} [FlashGet GetFlash Class] {F156768E-81EF-470C-9057-481BA8380DBA} [FGCatchUrl] {FB5DA724-162B-11D3-8B9B-AA70B4B0B524} [&使用快车(FlashGet)下载] [&使用快车(FlashGet)下载全部链接] [导出到 Microsoft Office Excel(&X)] [添加到QQ表情] [解霸实时播放] ================================== 正在运行的进程 [PID: 1224 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1292 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1320 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2645 (xpsp.050331-1524)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcSvcStub.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcLocSettings.dll] [N/A, ] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\ThinkPad\ConnectUtilities\ACHelper.dll] [N/A, ] [C:\WINDOWS\system32\tphklock.dll] [N/A, ] [C:\Program Files\Lenovo\AwayTask\AwayNotify.dll] [Lenovo Group Limited, 2, 0, 0, 0] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 1368 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1380 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\ThinkPad\ConnectUtilities\ACGina.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\ACHelper.dll] [N/A, ] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\ThinkPad\ConnectUtilities\AcSvcStub.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcLocSettings.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\ACON.dll] [N/A, ] [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)] [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)] [C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgr.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\ACTurinSupport.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcAdaptersInfo.dll] [N/A, ] [PID: 1536 / SYSTEM][C:\WINDOWS\system32\ibmpmsvc.exe] [, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [PID: 1568 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1720 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1760 / SYSTEM][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.28] [PID: 1776 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)] [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)] [C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)] [PID: 1880 / SYSTEM][C:\Program Files\Intel\Wireless\Bin\EvtEng.exe] [Intel Corporation, 10.5.0.20 ] [C:\Program Files\Intel\Wireless\Bin\PfMgrApi.dll] [Intel Corporation, 10.5.0.2 ] [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL] [Intel Corporation, 10.5.0.2] [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll] [Intel Corporation, 10.5.0.5 ] [C:\Program Files\Intel\Wireless\Bin\DbEngine.dll] [Intel Corporation, 10.5.0.2 ] [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll] [The OpenSSL Project, http://www.openssl.org/, 0.9.8] [C:\Program Files\Intel\Wireless\Bin\IntStngs.dll] [, 10.5.0.2 ] [C:\Program Files\Intel\Wireless\Bin\MurocApi.dll] [Intel Corporation, 10.5.0.7] [C:\Program Files\Intel\Wireless\Bin\S24MUDLL.dll] [Intel Corporation, 10.5.0.1 ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [PID: 1948 / SYSTEM][C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe] [Intel Corporation , 10.5.0.34 ] [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL] [Intel Corporation, 10.5.0.2] [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll] [Intel Corporation, 10.5.0.5 ] [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll] [The OpenSSL Project, http://www.openssl.org/, 0.9.8] [C:\Program Files\Intel\Wireless\Bin\IntStngs.dll] [, 10.5.0.2 ] [C:\Program Files\Intel\Wireless\Bin\IWMSPROV.DLL] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [PID: 176 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 236 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)] [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)] [PID: 292 / SYSTEM][C:\PROGRAM FILES\RISING\RAV\ravmond.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.76] [C:\PROGRAM FILES\RISING\RAV\BWList.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.4] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [C:\PROGRAM FILES\RISING\RAV\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16] [C:\PROGRAM FILES\RISING\RAV\RsLog.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.34] [C:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\PROGRAM FILES\RISING\RAV\MonRule.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.29] [C:\PROGRAM FILES\RISING\RAV\Hooksys.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 9] [C:\PROGRAM FILES\RISING\RAV\HookReg.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 4] [C:\PROGRAM FILES\RISING\RAV\HookNtos.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 2] [C:\PROGRAM FILES\RISING\RAV\rswalmon.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 22] [C:\PROGRAM FILES\RISING\RAV\recomp.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 39] [C:\PROGRAM FILES\RISING\RAV\refs.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17] [C:\PROGRAM FILES\RISING\RAV\ffr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 14] [C:\Program Files\Rising\Rav\RsStore.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.8] [C:\PROGRAM FILES\RISING\RAV\HookCont.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 1] [C:\Program Files\Rising\Rav\fakescan.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.13] [C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.36] [C:\PROGRAM FILES\RISING\RAV\viruslib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26] [C:\PROGRAM FILES\RISING\RAV\relibldr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [C:\PROGRAM FILES\RISING\RAV\extfile.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 29] [C:\PROGRAM FILES\RISING\RAV\pearc.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5] [C:\PROGRAM FILES\RISING\RAV\HookWeb.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.2] [C:\PROGRAM FILES\RISING\RAV\nvfile.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 6] [C:\PROGRAM FILES\RISING\RAV\scanexec.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17] [C:\PROGRAM FILES\RISING\RAV\unexe.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5] [C:\PROGRAM FILES\RISING\RAV\scanex.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 75] [C:\PROGRAM FILES\RISING\RAV\scanpack.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9] [C:\PROGRAM FILES\RISING\RAV\revm.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 8] [C:\PROGRAM FILES\RISING\RAV\urutils.dll] [, 20, 0, 0, 6] [C:\PROGRAM FILES\RISING\RAV\ur000.dat] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 18] [C:\PROGRAM FILES\RISING\RAV\extmail.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9] [C:\PROGRAM FILES\RISING\RAV\scriptci.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [C:\PROGRAM FILES\RISING\RAV\ur001.dat] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [C:\PROGRAM FILES\RISING\RAV\scansct.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9] [PID: 808 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\ZLhp1020.DLL] [Zenographics, Inc., 5, 53, 3723, 0] [C:\WINDOWS\system32\ZLM.dll] [Zenographics, Inc., 5, 50, 1416, 0] [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.2175.0] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\IMFPrint.DLL] [Zenographics, Inc., 5, 54, 330, 0] [C:\WINDOWS\system32\Imf32.dll] [Zenographics, Inc., 5, 60, 1204, 0] [C:\WINDOWS\system32\ZTAG32.dll] [Zenographics, Inc., 5, 60, 1210, 0] [C:\WINDOWS\system32\ZSPOOL.dll] [Zenographics, Inc., 5, 51, 709, 0] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.2175.0] [PID: 1092 / SYSTEM][C:\WINDOWS\system32\IPSSVC.EXE] [Lenovo Group Limited, 2, 0, 5, 2] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\Program Files\Lenovo\AwayTask\AwayDB.DLL] [Lenovo Group Limited, 2, 0, 0, 0] [PID: 1172 / SYSTEM][C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcLocSettings.dll] [N/A, ] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgr.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\ACHelper.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\ACON.dll] [N/A, ] [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)] [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)] [C:\Program Files\ThinkPad\ConnectUtilities\ACTurinSupport.dll] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\Program Files\ThinkPad\ConnectUtilities\AcAdaptersInfo.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcLocMigrator.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\ThinQCon.dll] [N/A, ] [PID: 1220 / SYSTEM][C:\PROGRAM FILES\RISING\RAV\RavStub.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.9] [C:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [PID: 628 / SYSTEM][C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe] [Apple, Inc., 1, 14, 0, 0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [PID: 732 / SYSTEM][C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe] [Diskeeper Corporation, 9.0.541.0] [C:\Program Files\Diskeeper Corporation\Diskeeper\DkLib.dll] [Diskeeper Corporation, 9.0.541.0] [C:\Program Files\Diskeeper Corporation\Diskeeper\Tab.dll] [Executive Software International, Inc., 1.0.34.0] [C:\Program Files\Diskeeper Corporation\Diskeeper\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Diskeeper Corporation\Diskeeper\GetFATExtents.dll] [Diskeeper Corporation, 9.0.541.0] [C:\WINDOWS\system32\odbcbcp.dll] [Microsoft Corporation, 2000.085.1117.00 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\Program Files\Diskeeper Corporation\Diskeeper\2052\DkRes.dll] [Diskeeper Corporation, 9.0.541.0] [C:\Program Files\Diskeeper Corporation\Diskeeper\DkTabProvider.dll] [Diskeeper Corporation, 9.0.541.0] [PID: 1016 / SYSTEM][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE] [Microsoft Corporation, 7.00.9466] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\2052\mdmui.dll] [Microsoft Corporation, 7.00.9466] [PID: 1612 / SYSTEM][C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe] [Intel Corporation, 10.5.0.4 ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [PID: 1704 / SYSTEM][C:\Program Files\CyberLink\Shared files\RichVideo.exe] [, 1.1.0808 ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [PID: 1864 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1900 / SYSTEM][c:\program files\lenovo\system update\suservice.exe] [ , 0.0.0.0] [C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 2.0.50727.1433 (REDBITS.050727-1400)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll] [Microsoft Corporation, 1.1.4322.2407] [c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll] [Microsoft Corporation, 1.1.4322.2032] [c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll] [Microsoft Corporation, 1.1.4322.2407] [c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_cab255ee\mscorlib.dll] [N/A, ] [c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll] [Microsoft Corporation, 1.1.4322.2407] [c:\windows\assembly\gac\mscorlib.resources\1.0.5000.0_zh-chs_b77a5c561934e089\mscorlib.resources.dll] [Microsoft Corporation, 1.1.4322.573] [c:\windows\assembly\gac\system.serviceprocess\1.0.5000.0__b03f5f7f11d50a3a\system.serviceprocess.dll] [Microsoft Corporation, 1.1.4322.2032] [c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll] [Microsoft Corporation, 1.1.4322.2407] [c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_029b6830\system.dll] [N/A, ] [c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL] [Microsoft Corporation, 1.1.4322.2407] [c:\program files\lenovo\system update\tvsuservicecommon.dll] [ , 0.0.0.0] [c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\diasymreader.dll] [Microsoft Corporation, 7.10.3052.4] [c:\windows\assembly\gac\system.serviceprocess.resources\1.0.5000.0_zh-chs_b03f5f7f11d50a3a\system.serviceprocess.resources.dll] [Microsoft Corporation, 1.1.4322.573] [PID: 188 / SYSTEM][C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe] [, 1, 0, 0, 1] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [PID: 1684 / SYSTEM][C:\WINDOWS\System32\TPHDEXLG.EXE] [Lenovo., 1.40] [C:\WINDOWS\System32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [PID: 488 / SYSTEM][C:\WINDOWS\system32\TpKmpSVC.exe] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [PID: 516 / NETWORK SERVICE][C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe] [IBM, 1,1,3,006] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [PID: 544 / SYSTEM][C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe] [Lenovo Group Limited, 3,10,17,0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Lenovo\Rescue and Recovery\rr_res.dll] [Lenovo Limited Group Corporation, 3,10,17,0] [C:\WINDOWS\system32\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Lenovo\Rescue and Recovery\pui.dll] [Lenovo Limited Group Corporation, 3,10,17,0] [C:\Program Files\Lenovo\Rescue and Recovery\ui.dll] [Lenovo Group Limited, 3,10,17,0] [C:\Program Files\Lenovo\Rescue and Recovery\CDRecord.dll] [N/A, ] [C:\Program Files\Lenovo\Rescue and Recovery\zlib.dll] [Lenovo Group Limited, 3,10,17,0] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [PID: 268 / SYSTEM][C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe] [Lenovo Group Limited, 3,10,8,0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [PID: 620 / SYSTEM][C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe] [N/A, ] [PID: 688 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [PID: 1044 / SYSTEM][C:\Program Files\Common Files\Lenovo\Logger\logmon.exe] [N/A, ] [C:\WINDOWS\system32\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [PID: 1008 / SYSTEM][C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe] [Lenovo, 4, 21, 0, 0] [C:\Program Files\ThinkPad\ConnectUtilities\AcLocSettings.dll] [N/A, ] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgr.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\ACHelper.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\ACON.dll] [N/A, ] [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)] [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)] [C:\Program Files\ThinkPad\ConnectUtilities\ACTurinSupport.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcSvcHlpr.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcAdaptersInfo.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\ANCA.dll] [IBM Corp., 8.3] [C:\Program Files\ThinkPad\ConnectUtilities\ANC.dll] [IBM Corp., 8.3] [C:\Program Files\ThinkPad\ConnectUtilities\AcSvcStub.dll] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [C:\Program Files\ThinkPad\ConnectUtilities\ACGolan.DLL] [N/A, ] [C:\Program Files\Intel\Wireless\Bin\PfMgrApi.dll] [Intel Corporation, 10.5.0.2 ] [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL] [Intel Corporation, 10.5.0.2] [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll] [Intel Corporation, 10.5.0.5 ] [C:\Program Files\Intel\Wireless\Bin\DbEngine.dll] [Intel Corporation, 10.5.0.2 ] [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll] [The OpenSSL Project, http://www.openssl.org/, 0.9.8] [C:\Program Files\Intel\Wireless\Bin\IntStngs.dll] [, 10.5.0.2 ] [C:\Program Files\Intel\Wireless\Bin\MurocAPI.dll] [Intel Corporation, 10.5.0.7] [C:\Program Files\Intel\Wireless\Bin\S24MUDLL.dll] [Intel Corporation, 10.5.0.1 ] [PID: 2692 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [PID: 3284 / SYSTEM][C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcLocSettings.dll] [N/A, ] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgr.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\ACHelper.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcSvcStub.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\ACGUIHlpr.dll] [N/A, ] [C:\WINDOWS\system32\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\ThinkPad\ConnectUtilities\AcAdaptersInfo.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\ACON.dll] [N/A, ] [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)] [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)] [C:\Program Files\ThinkPad\ConnectUtilities\ACTurinSupport.dll] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\GUIHlprRes.dll] [Lenovo, 4, 0, 0, 0] [C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\SvcHlprRes.dll] [Lenovo, 4, 0, 0, 0] [PID: 3448 / hh][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [PID: 3668 / hh][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)] [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)] [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17] [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9] [C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL] [Lenovo Group Limited, 1, 0, 0, 0] [C:\PROGRA~1\ThinkPad\UTILIT~1\SC\PWRMGRRT.DLL] [N/A, ] [C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRIF.DLL] [N/A, ] [C:\WINDOWS\system32\Sensor.dll] [Lenovo., 1.40] [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.0.2004121400] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdshell.dll] [Utimaco Safeware AG, 1.19.0.1] [C:\Program Files\Lenovo\SafeGuard PrivateDisk\PDLib.dll] [Utimaco Safeware AG, 1.19.0.1] [C:\WINDOWS\system32\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Lenovo\SafeGuard PrivateDisk\PDLib0804.dll] [Utimaco Safeware AG, 1.19.0.1] [C:\Program Files\Lenovo\SafeGuard PrivateDisk\PDShell0804.dll] [Utimaco Safeware AG, 1.19.0.1] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [PID: 4092 / hh][C:\WINDOWS\system32\tp4serv.exe] [Lenovo Group Limited, 3.55] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\tp4uires.dll] [N/A, ] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [PID: 276 / hh][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL] [Lenovo Group Limited, 1, 0, 0, 0] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [C:\PROGRA~1\ThinkPad\UTILIT~1\SC\PWRMGRRT.DLL] [N/A, ] [C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRIF.DLL] [N/A, ] [C:\WINDOWS\system32\Sensor.dll] [Lenovo., 1.40] [C:\WINDOWS\system32\OEMDSPIF.DLL] [Intel Corporation, 3.0.0.4648] [C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3.0.0.4648] [PID: 2032 / hh][C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe] [Lenovo Group Limited, 1, 0, 0, 0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\PROGRA~1\ThinkPad\UTILIT~1\SC\EzMApRes.dll] [N/A, ] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [PID: 2192 / hh][C:\WINDOWS\system32\TpShocks.exe] [Lenovo, Ltd. and IBM Corporation., 1, 4, 1, 0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\Program Files\ThinkPad\TpShocks\MUI\0804\TpShocks.dll] [Lenovo, Ltd. and IBM Corporation., 1, 4, 1, 0] [C:\WINDOWS\system32\Sensor.dll] [Lenovo., 1.40] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [PID: 2316 / hh][C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\WINDOWS\system32\Oemdspif.dll] [Intel Corporation, 3.0.0.4648] [C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3.0.0.4648] [C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\tpfnf7.dll] [N/A, ] [PID: 260 / hh][C:\Program Files\Analog Devices\Core\smax4pnp.exe] [Analog Devices, Inc., 6, 0, 0, 20] [C:\Program Files\Analog Devices\Core\SMWDMIF.dll] [Analog Devices, Inc., 6, 0, 4200, 014] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 2532 / hh][C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [PID: 2716 / hh][C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe] [Lenovo Group Limited, 1.17] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [PID: 2960 / hh][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3.0.0.4648] [C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4648] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4648] [C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4648] [PID: 3036 / hh][C:\WINDOWS\system32\igfxpers.exe] [Intel Corporation, 3.0.0.4648] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4648] [PID: 3052 / hh][C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe] [Lenovo Group Limited, 1, 0, 0, 1] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [C:\PROGRA~1\THINKV~1\PrdCtr\SC\LPRESMGR.DLL] [N/A, ] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\TrayRes.dll] [Lenovo, 4, 0, 0, 0] [PID: 3096 / hh][C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe] [Sun Microsystems, Inc., 5.0.60.5] [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)] [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [PID: 3060 / hh][C:\Program Files\Lenovo\AwayTask\AwaySch.EXE] [Lenovo Group Limited, 2, 0, 5, 1] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [C:\Program Files\Lenovo\AwayTask\AwayAPI.dll] [Lenovo Group Limited, 2, 0, 5, 2] [C:\Program Files\Lenovo\AwayTask\AwayDB.dll] [Lenovo Group Limited, 2, 0, 0, 0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [PID: 3164 / hh][C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe] [Lenovo Group Limited, 3,10,8,0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [PID: 3248 / hh][C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe] [Diskeeper Corporation, 9.0.541.0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\Program Files\Diskeeper Corporation\Diskeeper\2052\DkRes.dll] [Diskeeper Corporation, 9.0.541.0] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [PID: 3364 / hh][C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcLocSettings.dll] [N/A, ] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\ThinkPad\ConnectUtilities\ACGUIHlpr.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcSvcStub.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\ACHelper.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgr.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll] [N/A, ] [C:\WINDOWS\system32\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\GUIHlprRes.dll] [Lenovo, 4, 0, 0, 0] [C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\TrayRes.dll] [Lenovo, 4, 0, 0, 0] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [PID: 3428 / hh][C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcLocSettings.dll] [N/A, ] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\ThinkPad\ConnectUtilities\ACGUIHlpr.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcSvcStub.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\ACHelper.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgr.dll] [N/A, ] [C:\Program Files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll] [N/A, ] [C:\WINDOWS\system32\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\GUIHlprRes.dll] [Lenovo, 4, 0, 0, 0] [C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\IconRes.dll] [Lenovo, 4, 0, 0, 0] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [PID: 3492 / hh][C:\Program Files\Picasa2\PicasaMediaDetector.exe] [Google Inc., 2.1.0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [PID: 3692 / hh][C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe] [Utimaco Safeware AG, 1.19.0.1] [C:\Program Files\Lenovo\SafeGuard PrivateDisk\PDLib.dll] [Utimaco Safeware AG, 1.19.0.1] [C:\WINDOWS\system32\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [C:\Program Files\Lenovo\SafeGuard PrivateDisk\PDLib0804.dll] [Utimaco Safeware AG, 1.19.0.1] [C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice0804.dll] [Utimaco Safeware AG, 1.19.0.1] [PID: 3824 / hh][C:\Ruier\Win32\pphidpad.exe] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [PID: 3796 / hh][C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe] [Cyberlink Corp., 5.00.0910] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [C:\Program Files\CyberLink\PowerDVD\CLRCEngine3.dll] [CyberLink Corp., 4, 5, 0, 1711] [C:\Program Files\CyberLink\PowerDVD\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [PID: 3876 / hh][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3536] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [PID: 1676 / hh][C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe] [Hewlett-Packard, 2, 0, 1, 26] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [PID: 4044 / hh][C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe] [Hewlett-Packard, 2,3,0,0\?162] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [C:\Program Files\Hewlett-Packard\HP Share-to-Web\S2WNSRES.DLL] [Hewlett-Packard, 2, 6, 0,?62] [C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnfps.dll] [N/A, ] [PID: 2052 / hh][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 5.0.0.16] [C:\Program Files\Rising\AntiSpyware\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\AntiSpyware\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)] [PID: 2124 / hh][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.23] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16] [PID: 2084 / hh][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [PID: 2272 / hh][C:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 20.0.01.19] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [C:\Program Files\Rising\Rav\recomp.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 39] [C:\Program Files\Rising\Rav\refs.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\viruslib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26] [C:\Program Files\Rising\Rav\relibldr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [C:\Program Files\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16] [C:\Program Files\Rising\Rav\MonRule.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.29] [C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4] [C:\Program Files\Rising\Rav\Rsguilib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 89] [C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0] [PID: 956 / hh][C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe] [, 2, 6, 0,?162] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [C:\Program Files\Hewlett-Packard\HP Share-to-Web\S2WNSRES.DLL] [Hewlett-Packard, 2, 6, 0,?62] [C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnfps.dll] [N/A, ] [PID: 2840 / hh][C:\Program Files\Digital Line Detect\DLG.exe] [BVRP Software, 1, 0, 0, 1] [C:\Program Files\Digital Line Detect\BVRPDIAG.dll] [BVRP Software, 1.0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\MdmXSdk.dll] [Conexant, 1.0.2.010] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [PID: 2088 / SYSTEM][C:\WINDOWS\system32\msiexec.exe] [Microsoft Corporation, 3.1.4000.1823] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [PID: 848 / hh][C:\Program Files\Rising\Rav\Rav.exe] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 71] [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)] [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\Program Files\Rising\Rav\Rsguilib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 89] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0] [C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4] [C:\Program Files\Rising\Rav\RsCommon.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [C:\Program Files\Rising\Rav\ravpagem.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 1, 5] [C:\Program Files\Rising\Rav\htmllib.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17] [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9] [PID: 4008 / hh][C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE] [Microsoft Corporation, 11.0.8134] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll] [Microsoft Corporation, 11.0.8132] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] [C:\Program Files\Common Files\Microsoft Shared\office11\riched20.dll] [Microsoft Corporation, 5.50.99.2010] [C:\Program Files\Rising\Rav\RsPlugIn.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.19] [C:\PROGRA~1\MICROS~2\OFFICE11\ADDINS\SYMINPUT.DLL] [Microsoft Corporation, 1.02] [C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690] [C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL] [Microsoft Corporation, 1.1.6215] [C:\Program Files\Common Files\Microsoft Shared\PROOF\mslid.dll] [Microsoft Corporation, 1.0.2305] [C:\Program Files\Common Files\Microsoft Shared\PROOF\2052\MSGR3EN.DLL] [Microsoft Corporation, 3.1.2303] [C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527] [C:\Program Files\Microsoft Office\OFFICE11\msostyle.dll] [Microsoft Corporation, 11.0.5510] [C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL] [Microsoft Corporation, 9.0.5510.0] [C:\Program Files\Common Files\Microsoft Shared\PROOF\2052\MSGR3SC.DLL] [Microsoft Corporation, 3.0.1708.0] [C:\Program Files\Common Files\Microsoft Shared\Smart Tag\CHDATEST.DLL] [Microsoft Corporation, 2.00] [C:\Program Files\Common Files\Microsoft Shared\Smart Tag\Chinese Measurement Converter\CHMETCNV.DLL] [Microsoft Corp., 1.00] [C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\FNAME.DLL] [Microsoft Corporation, 11.0.5510] [C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\2052\stintl.dll] [Microsoft Corporation, 11.0.5510] [C:\WINDOWS\system32\freeime.ime] [极点五笔工作室, 6.10.950] [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDNT5UI.DLL] [Zenographics, Inc., 5.60.709.0] [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDDM32.DLL] [Zenographics, Inc., 5, 60, 2629, 0] [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZSPOOL.dll] [Zenographics, Inc., 5, 51, 709, 0] [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZGDI32.dll] [Zenographics, Inc., 5, 60, 709, 0] [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZTAG32.dll] [Zenographics, Inc., 5, 60, 1210, 0] [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDDMUI.DLL] [Zenographics, Inc., 6, 1, 524, 0] [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SR32.dll] [Zenographics, Inc., 6, 1, 520, 1] [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\IMFNT5.DLL] [Zenographics, Inc., 0, 3, 3508, 0] [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\Imf32.dll] [Zenographics, Inc., 5, 60, 1204, 0] [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)] [PID: 1840 / hh][C:\w\tool2\SRE9d2c65c3.EXE] [Smallfrogs Studio, 2.6.8.980] [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)] [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16640 (vista_gdr.080213-1606)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18] [C:\WINDOWS\system32\PROCHLP.DLL] [Lenovo Group Limited, 2, 0, 6, 0] ================================== 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 127.0.0.1 tttt.591jx.com 127.0.0.1 jx.llzjz.cn 127.0.0.1 eee.avpkav.com 127.0.0.1 fff.tesekl.info 127.0.0.1 www.dj8910.com 127.0.0.1 test.591jx.com 127.0.0.1 1.9797aiai.com 127.0.0.1 2.9797aiai.com 127.0.0.1 3.9797aiai.com 127.0.0.1 4.9797aiai.com 127.0.0.1 5.9797aiai.com 127.0.0.1 2.kv8.info 127.0.0.1 www.88feel.cn 127.0.0.1 feel.88feel.cn 127.0.0.1 exe.xinniankl.com 127.0.0.1 the.microgood.net 127.0.0.1 xin.xinniankl.com 127.0.0.1 xxx.wofala.info 127.0.0.1 aaa.wd03.info 127.0.0.1 xxx.wd01.info 127.0.0.1 www.ip580.com 127.0.0.1 url.hao365.org 127.0.0.1 xxx.huilaiba.info 127.0.0.1 bankdiyed.cn 127.0.0.1 59.vc 127.0.0.1 086199.service-google.cn 127.0.0.1 bt.etimes888.com 127.0.0.1 www.hua28.com 127.0.0.1 www.wg771.com 127.0.0.1 www.2323938.com 127.0.0.1 xxx.llsj123.com 127.0.0.1 a.topxxxx.cn 127.0.0.1 picon.chinaren.com 127.0.0.1 blog.wcad.cn 127.0.0.1 s101-cnzz.com 127.0.0.1 a.bkyes.com 127.0.0.1 yoooooooo.bkyes.com 127.0.0.1 vestb.lu158.cn 127.0.0.1 xiazai.cpushpop.com 127.0.0.1 iii.chsip.net 127.0.0.1 d.wacsy.com 127.0.0.1 web.haoliuliang.com 127.0.0.1 ad.haoliuliang.com 127.0.0.1 mm.haoliuliang.com 127.0.0.1 www.hao12321.cn 127.0.0.1 www.likeall.cn 127.0.0.1 asdfasdf.88y.net 127.0.0.1 down.laladan.cn 127.0.0.1 psp.kalengzi.cn 127.0.0.1 xxx.zttwp.cn 127.0.0.1 ce.laladan.cn 127.0.0.1 xxx.laladan.cn 127.0.0.1 udd.yooosky.com 127.0.0.1 uee.yooosky.com 127.0.0.1 uff.yooosky.com 127.0.0.1 cc.fockfock.com ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 1948, C:\PROGRAM FILES\INTEL\WIRELESS\BIN\S24EVMON.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 628, C:\PROGRAM FILES\COMMON FILES\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 544, C:\PROGRAM FILES\LENOVO\RESCUE AND RECOVERY\RRSERVICE.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 268, C:\PROGRAM FILES\COMMON FILES\LENOVO\SCHEDULER\TVTSCHED.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1044, C:\PROGRAM FILES\COMMON FILES\LENOVO\LOGGER\LOGMON.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1008, C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACSVC.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3284, C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\SVCGUIHLPR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2032, C:\PROGRA~1\THINKPAD\UTILIT~1\EZEJMNAP.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2316, C:\PROGRA~1\LENOVO\PKGMGR\HOTKEY\TPHKMGR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2532, C:\PROGRAM FILES\LENOVO\PKGMGR\HOTKEY\TPONSCR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2716, C:\PROGRAM FILES\LENOVO\PKGMGR\HOTKEY_1\TPSCREX.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3052, C:\PROGRA~1\THINKV~1\PRDCTR\LPMGR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3096, C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\JUSCHED.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3060, C:\PROGRAM FILES\LENOVO\AWAYTASK\AWAYSCH.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 3164, C:\PROGRAM FILES\COMMON FILES\LENOVO\SCHEDULER\SCHEDULER_PROXY.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3164, C:\PROGRAM FILES\COMMON FILES\LENOVO\SCHEDULER\SCHEDULER_PROXY.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3248, C:\PROGRAM FILES\DISKEEPER CORPORATION\DISKEEPER\DKICON.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3364, C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACTRAY.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3428, C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACWLICON.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3492, C:\PROGRAM FILES\PICASA2\PICASAMEDIADETECTOR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3692, C:\PROGRAM FILES\LENOVO\SAFEGUARD PRIVATEDISK\PDSERVICE.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3824, C:\RUIER\WIN32\PPHIDPAD.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3796, C:\PROGRAM FILES\CYBERLINK\POWERDVD\PDVDSERV.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3876, C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1676, C:\PROGRAM FILES\HEWLETT-PACKARD\ORDERREMINDER\ORDERREMINDER.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 4044, C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WND.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2052, C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 956, C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2840, C:\PROGRAM FILES\DIGITAL LINE DETECT\DLG.EXE] ================================== API HOOK 入口点错误:NtCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003D4555) 入口点错误:NtWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003D45F5) 入口点错误:ZwCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003D4555) 入口点错误:ZwWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003D45F5) ================================== 隐藏进程 N/A ================================== [/CODE]