[CODE] 2008-06-23,00:10:59 System Repair Engineer 2.5.16.900 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [N/A] [(Verified)Google Inc] <"C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"> [Nero AG] <"e:\Tencent\QQDownload\QQDownload.exe" autostart> [N/A] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.] [ZSMCSNAP] [] [Motorola] [(Verified)Tencent Technology(Shenzhen) Company Limited] <"C:\Program Files\Rising\AntiSpyware\runiep.exe" /startup> [Beijing Rising Technology Co., Ltd.] [] <"D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [(Verified)BEIJING RISING SCIENCE AND TECHNOLOGY CORPORATION LIMITED] <"D:\Program Files\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Science and Technology Corporation Limited] [Nero AG] [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce] [Beijing Rising Technology Co., Ltd.] <"D:\Program Files\Rising\Rfw\Update\Setup.exe" /UPDATE /ONCE> [(Verified)BEIJING RISING SCIENCE AND TECHNOLOGY CORPORATION LIMITED] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}> [(Verified)Beijing Rising Science and Technology Corporation Limited] <{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><> [N/A] <{67f5889a-257e-4d49-a25e-da1cb5a6dac1}> [N/A] <{da635250-d178-455c-8e1c-a2bb3d06e107}> [N/A] <{e80fca64-83f0-4aaa-95cc-24a7002c8a09}> [N/A] <{03634aa6-1cae-47f7-8465-48472353249a}> [N/A] <{d5464c94-2030-4f7d-88ad-44354dba774b}> [N/A] <{28766E1C-74B0-4417-8C75-F12AE309EF35}> [] <{18e64250-19a8-4d10-828f-30e101a22291}> [N/A] <{461D2AB4-29A5-45C2-9134-D52272D3DE38}> [N/A] <{8AD0F1B1-990D-4F52-A33D-2837E43CEF58}> [N/A] <{d592daa6-9b5e-416d-973a-d76c53183e7e}> [N/A] <{DC3D30AE-0380-4151-8934-EE98A34B0370}> [] <{28EB3777-3E23-4E72-8449-A992D09D24C3}> [] <{c7c5224f-143b-4c7e-bc8a-a6b7e70f0f60}> [N/A] <{7C8D1401-A58D-A81C-CD24-A5915C4517C7}> [] <{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}> [] <{A9895933-6636-4281-BC58-EE6DE2AF96E3}> [] <{9490415F-65F8-B5C5-D8BA-9405FB120549}> [N/A] <{6FD45A54-9875-698F-E56E-65102358FDF6}> [] <{4F4F0064-71E0-4f0d-0003-708476C7815F}> [] <{84143967-B645-4BFF-B873-DA1DC886E9A7}> [] <{6A041F13-A111-12A3-B0CF-F99818AA68A6}><> [N/A] <{37AC9076-C898-B098-D098-A18319080973}> [N/A] <{32023698-6984-8541-9654-698745012523}> [] <{77FD640A-158F-48AC-FD14-1597F14A9777}> [] <{C0595A7E-2E2F-4B34-A83A-019270A0A464}> [] <{6629FF4F-ACDB-5C90-A098-FACB3456A266}> [N/A] <{F99DEFDD-200B-4410-B572-E90883D527D2}> [N/A] <{54FAE856-AD58-20CB-A025-CD4895FA6E45}> [] <{011DB9B9-44B4-44D9-B17E-BC7608F2E549}> [N/A] <{841529CB-7F77-4B99-A895-B5441E0D302F}> [] <{189F087F-4378-405F-85FA-37D955AD7A8C}> [] <{4F4F0064-71E0-4f0d-0012-708476C7815F}> [N/A] <{43512378-9874-5641-1025-985420368734}> [] <{8C41B7F7-3168-400D-A702-0E7EFE0BA304}> [] <{50940F85-F015-14F1-A05F-F69858AC6D05}> [] <{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC}> [N/A] <{3D698451-2015-6358-9871-2015987452D3}> [] <{4D165A2A-4BC1-4CA8-8299-08E05AAAB5A4}> [] <{55694105-5108-9405-3695-954187462155}> [] <{6E6CA8A1-81BC-4707-A54C-F4903DD70BAD}><> [N/A] <{7629FF4F-ACDB-5C90-A098-FACB3456A267}> [N/A] <{00120012-0012-0012-0012-00120012BB15}> [] <{74381DEC-D78B-43E4-BA5D-5244F669EBE4}> [] <{A490415F-65F8-B5C5-D8BA-9405FB12054A}> [] <{00010001-0001-0001-0001-00010001BB15}> [] <{22596546-2036-9451-6058-658402589722}><> [N/A] <{00050005-0005-0005-0005-00050005BB15}> [] <{00220022-0022-0022-0022-00220022BB15}> [N/A] <{35671234-7890-ABCD-CDEF-567801237653}> [] <{81AF1CF6-D1C9-4C6A-AC01-EDE54E71945B}> [] <{eaa21495-29ae-4e50-8ad9-a4f877c1ab85}> [] <{031B7024-4FC5-49B3-98EF-6B810FF12678}> [] <{7A041F13-A111-12A3-B0CF-F99818AA68A7}> [] <{37A924AF-1A5F-CF21-AB1D-1D5CF82A8A73}> [N/A] <{A629FF4F-ACDB-5C90-A098-FACB3456A26A}> [] <{5A069845-2036-6084-9054-6087502480A5}> [] <{4F4F0064-71E0-4f0d-0023-708476C7815F}> [] <{25FD6584-698F-BCD2-602C-698745210352}> [] <{4F4F0064-71E0-4f0d-0004-708476C7815F}> [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] [] [N/A] [] [] [] [N/A] [] [] [] [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctor.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctorMain.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SelfUpdate.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"> [N/A] <; D:\阿里巴巴\贸易通\AliTalk.EXE -hideframe> [Alibaba] <; C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe> [ATI Technologies, Inc.] <; C:\Program Files\VIAudioi\SBADeck\ADeck.exe> [VIA Technologies, Inc.] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; C:\WINDOWS\System32\ctfmon.exe> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; C:\WINDOWS\EzxMonitor.exe> [Motorola] <; C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32> [N/A] <; > [N/A] <; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher] <; rem C:\WINDOWS\temp\alitalk\alitalk.exe -hideframe> [N/A] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; "D:\KAV2005\KavPFW.exe"> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; > [N/A] <; "d:\KAV2005\KAVStart.exe" -startup> [N/A] <; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation] <; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher] <; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.] <; "e:\FarStone\VirtualDrive\vdtask.exe"> [] <; C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe> [N/A] <; C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe> [N/A] ================================== 启动文件夹 [QQ游戏启动加速程序] E:\Tencent\QQGame\Accel.exe [深圳市腾讯计算机系统有限公司]> [腾讯QQ] E:\Tencent\qq\QQ.exe [TENCENT]> ================================== 服务 [Acronis Scheduler2 Service / AcrSch2Svc][Stopped/Auto Start] <"C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe"> [Apple Mobile Device / Apple Mobile Device][Running/Auto Start] <"C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"> [Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start] <> [ATI Smart / ATI Smart][Stopped/Auto Start] <> [Google Updater Service / gusvc][Stopped/Manual Start] <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [InstallDriver Table Manager / IDriverT][Stopped/Manual Start] <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"> [iPod 服务 / iPod Service][Stopped/Manual Start] <"C:\Program Files\iPod\bin\iPodService.exe"> [NMIndexingService / NMIndexingService][Running/Manual Start] <"C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe"> [PlugServerD / PlugServer][Running/Auto Start] [Rising Proxy Service / RfwProxySrv][Stopped/Auto Start] [Rising Personal Firewall Service / RfwService][Stopped/Auto Start] [Rising Process Communication Center / RsCCenter][Running/Auto Start] <"D:\Program Files\Rising\Rav\CCenter.exe"> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] <"D:\PROGRAM FILES\RISING\RAV\Ravmond.exe"> [Ulead Burning Helper / UleadBurningHelper][Running/Auto Start] [WINS / WINS][Stopped/Auto Start] ================================== 驱动程序 [00 / 00][Stopped/Boot Start] <\SystemRoot\\SystemRoot\System32\drivers\3662165.sys> [0ac9dd641c8dcef5 / 0ac9dd641c8dcef5][Stopped/Manual Start] <\??\C:\0ac9dd641c8dcef5.dat> [113363 / 113363][Stopped/Boot Start] <\SystemRoot\System32\drivers\113363.sys> [128414 / 128414][Stopped/Boot Start] <\SystemRoot\System32\drivers\128414.sys> [129836 / 129836][Stopped/Boot Start] <\SystemRoot\System32\drivers\129836.sys> [18fbaf14ca38ae5e / 18fbaf14ca38ae5e][Stopped/Manual Start] <\??\C:\18fbaf14ca38ae5e.dat> [ADProt / ADProt][Running/System Start] <\SystemRoot\system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司> [ati2mtag / ati2mtag][Running/Manual Start] [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Running/Manual Start] [GEARAspiWDM / GEARAspiWDM][Running/Manual Start] [GMSIPCI / GMSIPCI][Stopped/Manual Start] <\??\F:\INSTALL\GMSIPCI.SYS> [Hdv32 / Hdv32][Stopped/Manual Start] <\??\C:\WINDOWS\system32\drivers\Hdv32_c.sys> [HookCont / HookCont][Running/System Start] <\SystemRoot\system32\drivers\HookCont.sys> [HookNtos / HookNtos][Running/System Start] <\SystemRoot\system32\drivers\HookNtos.sys> [HookReg / HookReg][Running/System Start] <\SystemRoot\system32\drivers\HookReg.sys> [HookSys / HookSys][Running/System Start] <\SystemRoot\system32\drivers\HookSys.sys> [HookUrl / HookUrl][Running/Auto Start] <\??\D:\Program Files\Rising\Rfw\HookUrl.sys> [Motorola USBLAN / Motorola USBLAN][Stopped/Manual Start] [npkcrypt / npkcrypt][Running/Auto Start] <\??\E:\Tencent\qq\npkcrypt.sys> [NTACCESS / NTACCESS][Stopped/Manual Start] <\??\F:\NTACCESS.sys> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [Rising Rfwbase Driver / RfwBase][Running/Auto Start] [RsAntiSpyware / RsAntiSpyware][Running/Boot Start] <\SystemRoot\system32\drivers\RsBoot.sys> [RsFwDrv / RsFwDrv][Running/System Start] <\??\D:\Program Files\Rising\Rfw\RsFwDrv.sys> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [Secdrv / Secdrv][Running/Auto Start] [SetupNTGLM7X / SetupNTGLM7X][Stopped/Manual Start] <\??\F:\NTGLM7X.sys> [SmartCd / SmartCd][Stopped/Manual Start] [USB PC Camera (SNPSTD3) / SNPSTD3][Stopped/Manual Start] <> [Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start] [SAMSUNG Mobile USB Device II 1.0 driver (WDM) / ssm_bus][Stopped/Manual Start] [SAMSUNG Mobile USB Modem II 1.0 Filter / ssm_mdfl][Stopped/Manual Start] [SAMSUNG Mobile USB Modem II 1.0 Drivers / ssm_mdm][Stopped/Manual Start] [VIA AGP Filter / viaagp1][Running/Boot Start] <\SystemRoot\System32\DRIVERS\viaagp1.sys> [ViaIde / ViaIde][Running/Boot Start] <\SystemRoot\System32\DRIVERS\viaide.sys> [viasraid / viasraid][Running/Boot Start] <\SystemRoot\System32\DRIVERS\viasraid.sys> [Vinyl AC'97 Audio Controller (WDM) / VIAudio][Running/Manual Start] [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start] [zctp / zctp][Stopped/Auto Start] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpC.tmp> [USB PC Camera (ZS0211) / ZSMC211][Stopped/Manual Start] [FAMETECH USB PC CAMERA / ZSMC301b][Stopped/Manual Start] ================================== 浏览器加载项 [QQCycloneHelper Class] {00000000-12C9-4305-82F9-43058F20E8D2} [WebThunder Browser Helper] {00000AAA-A363-466E-BEF5-9BB68697AA7F} [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [Tencent Browser Helper] {0C7C23EF-A848-485B-873C-0ED954731014} [] {25FD6584-698F-BCD2-602C-698745210352} [] {32023698-6984-8541-9654-698745012523} [] {35671234-7890-ABCD-CDEF-567801237653} [] {37A924AF-1A5F-CF21-AB1D-1D5CF82A8A73} [] {37AC9076-C898-B098-D098-A18319080973} [BitComet Helper] {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} [] {3D698451-2015-6358-9871-2015987452D3} [] {43512378-9874-5641-1025-985420368734} [] {50940F85-F015-14F1-A05F-F69858AC6D05} [] {54FAE856-AD58-20CB-A025-CD4895FA6E45} [] {55694105-5108-9405-3695-954187462155} [] {5A069845-2036-6084-9054-6087502480A5} [] {6629FF4F-ACDB-5C90-A098-FACB3456A266} [] {669751ED-D558-49AE-B01A-3B374CC7910E} [] {6FD45A54-9875-698F-E56E-65102358FDF6} [] {74381DEC-D78B-43E4-BA5D-5244F669EBE4} [] {7629FF4F-ACDB-5C90-A098-FACB3456A267} [] {77FD640A-158F-48AC-FD14-1597F14A9777} [] {7A041F13-A111-12A3-B0CF-F99818AA68A7} [] {7C8D1401-A58D-A81C-CD24-A5915C4517C7} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [] {8AD0F1B1-990D-4F52-A33D-2837E43CEF58} [Windows Live Sign-in Helper] {9030D464-4C02-4ABF-8ECC-5164760863C6} [] {9490415F-65F8-B5C5-D8BA-9405FB120549} [] {A490415F-65F8-B5C5-D8BA-9405FB12054A} [IeCatch2 Class] {A5366673-E8CA-11D3-9CD9-0090271D075B} [] {A629FF4F-ACDB-5C90-A098-FACB3456A26A} [Google Toolbar Helper] {AA58ED58-01DD-4d91-8333-CF10577473F7} [Google Toolbar Notifier BHO] {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [启动迅雷5] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} [雅虎助手] {5D73EE86-05F1-49ed-B850-E423120EC338} [启动WEB迅雷] {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} [BitComet] {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} <, N/A> [Messenger] {FB5F1910-F110-11d2-BB9E-00C04F795683} [&Google] {2318C2B1-4965-11d4-9B18-009027A5CD4F} [卡卡上网安全助手] {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} [Edit Class] {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} [PowerPlr Control] {2354A44B-3CEB-4829-9940-545B03103538} [CEditCtrl Object] {488A4255-3236-44B3-8F27-FA1AECAA8844} [CCtInf Class] {6DBB2904-082D-4DB0-944A-21C22BA121F4} [AxInputControl Class] {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} [AxSubmitControl Class] {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [KATScan Control] {DDA166FA-B3EA-4A3B-8EE2-4F552CDEEE81} [QQCycloneHelper Class] {00000000-12C9-4305-82F9-43058F20E8D2} [WebThunder Browser Helper] {00000AAA-A363-466E-BEF5-9BB68697AA7F} [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [WebThunder Class] {03507A1A-E0C5-4404-AA26-205385C0892D} <, N/A> [Tencent Browser Helper] {0C7C23EF-A848-485B-873C-0ED954731014} [Windows Media Player] {22D6F312-B0F6-11D0-94AB-0080C74C7E95} [&Google] {2318C2B1-4965-11D4-9B18-009027A5CD4F} [] {25FD6584-698F-BCD2-602C-698745210352} [] {32023698-6984-8541-9654-698745012523} [] {35671234-7890-ABCD-CDEF-567801237653} [] {37A924AF-1A5F-CF21-AB1D-1D5CF82A8A73} [] {37AC9076-C898-B098-D098-A18319080973} [BitComet Helper] {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} [] {3D698451-2015-6358-9871-2015987452D3} [] {43512378-9874-5641-1025-985420368734} [GDCCBCtrl Class] {478AB5EE-5C92-41C3-8339-CFC5BA639733} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [] {50940F85-F015-14F1-A05F-F69858AC6D05} [] {54FAE856-AD58-20CB-A025-CD4895FA6E45} [] {55694105-5108-9405-3695-954187462155} [] {5A069845-2036-6084-9054-6087502480A5} [] {6629FF4F-ACDB-5C90-A098-FACB3456A266} [] {669751ED-D558-49AE-B01A-3B374CC7910E} [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [] {6FD45A54-9875-698F-E56E-65102358FDF6} [Active Desktop Mover] {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A> [] {74381DEC-D78B-43E4-BA5D-5244F669EBE4} [] {7629FF4F-ACDB-5C90-A098-FACB3456A267} [] {77FD640A-158F-48AC-FD14-1597F14A9777} [] {7A041F13-A111-12A3-B0CF-F99818AA68A7} [] {7C8D1401-A58D-A81C-CD24-A5915C4517C7} [Microsoft Web 浏览器] {8856F961-340A-11D0-A96B-00C04FD705A2} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [] {8AD0F1B1-990D-4F52-A33D-2837E43CEF58} [Windows Live Sign-in Helper] {9030D464-4C02-4ABF-8ECC-5164760863C6} [] {9490415F-65F8-B5C5-D8BA-9405FB120549} [Submit Class] {A3CD7F74-93C9-4BC4-B892-CCDF1514F714} [] {A490415F-65F8-B5C5-D8BA-9405FB12054A} [IeCatch2 Class] {A5366673-E8CA-11D3-9CD9-0090271D075B} [] {A629FF4F-ACDB-5C90-A098-FACB3456A26A} [Google Toolbar Helper] {AA58ED58-01DD-4D91-8333-CF10577473F7} [Google Toolbar Notifier BHO] {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [SearchAssistantOC] {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\System32\shdocvw.dll, N/A> [RDS.DataSpace] {BD96C556-65A3-11D0-983A-00C04FC29E36} [RealPlayer G2 Control] {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [卡卡上网安全助手] {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} [safeInput Class] {ECCBA956-80E5-11D3-9285-0080ADB811C9} [&使用BitComet下载] [&使用BitComet下载全部链接] [&使用BitComet下载本页视频] [&使用超级旋风下载] [&使用超级旋风下载全部链接] [使用Web迅雷下载] [使用Web迅雷下载全部链接] [使用网际快车下载] [使用网际快车下载全部链接] [使用迅雷下载] [使用迅雷下载全部链接] [添加到QQ表情] ================================== 正在运行的进程 [PID: 560 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 652 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 676 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 724 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 740 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 888 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 968 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 1064 / SYSTEM][D:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.28] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 1080 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)] [PID: 1128 / NETWORK SERVICE][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 1228 / LOCAL SERVICE][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 1320 / SYSTEM][D:\PROGRAM FILES\RISING\RAV\ravmond.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.76] [D:\PROGRAM FILES\RISING\RAV\BWList.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.4] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [D:\PROGRAM FILES\RISING\RAV\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [D:\PROGRAM FILES\RISING\RAV\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.18] [D:\PROGRAM FILES\RISING\RAV\RsLog.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.35] [D:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\PROGRAM FILES\RISING\RAV\MonRule.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.29] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [D:\PROGRAM FILES\RISING\RAV\Hooksys.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 9] [D:\PROGRAM FILES\RISING\RAV\HookReg.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 4] [D:\PROGRAM FILES\RISING\RAV\HookNtos.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 2] [D:\PROGRAM FILES\RISING\RAV\rswalmon.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 22] [D:\PROGRAM FILES\RISING\RAV\recomp.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 39] [D:\PROGRAM FILES\RISING\RAV\refs.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17] [D:\PROGRAM FILES\RISING\RAV\ffr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 15] [D:\Program Files\Rising\Rav\RsStore.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.8] [D:\PROGRAM FILES\RISING\RAV\HookCont.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 1] [D:\Program Files\Rising\Rav\fakescan.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.13] [D:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.36] [D:\PROGRAM FILES\RISING\RAV\viruslib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26] [D:\PROGRAM FILES\RISING\RAV\extfile.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 29] [D:\PROGRAM FILES\RISING\RAV\relibldr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [D:\PROGRAM FILES\RISING\RAV\pearc.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5] [D:\PROGRAM FILES\RISING\RAV\HookWeb.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.2] [D:\PROGRAM FILES\RISING\RAV\nvfile.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 6] [D:\PROGRAM FILES\RISING\RAV\scanexec.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\PROGRAM FILES\RISING\RAV\unexe.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5] [D:\PROGRAM FILES\RISING\RAV\scanex.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 77] [D:\PROGRAM FILES\RISING\RAV\scanpack.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9] [D:\PROGRAM FILES\RISING\RAV\revm.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 8] [D:\PROGRAM FILES\RISING\RAV\urutils.dll] [, 20, 0, 0, 6] [D:\PROGRAM FILES\RISING\RAV\ur000.dat] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 18] [D:\PROGRAM FILES\RISING\RAV\scriptci.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [D:\PROGRAM FILES\RISING\RAV\uroutine.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26] [D:\PROGRAM FILES\RISING\RAV\posttrt.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 22] [D:\PROGRAM FILES\RISING\RAV\scansct.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9] [PID: 1932 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 276 / SYSTEM][D:\PROGRAM FILES\RISING\RAV\RavStub.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.9] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [D:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 528 / SYSTEM][C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe] [Apple, Inc., 1, 12, 0, 0] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 576 / SYSTEM][C:\WINDOWS\System32\Ati2evxx.exe] [, ] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 912 / SYSTEM][C:\Program Files\StarSec\PlugServer.exe] [GDChina, 1, 1, 0, 2] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\Program Files\StarSec\plugins\plugstarkey220.dll] [GDChina, 1, 1, 0, 1] [PID: 360 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\yzztjmsn.dll] [N/A, ] [PID: 384 / SYSTEM][C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe] [Ulead Systems, Inc., 1, 0, 0, 4] [PID: 200 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [PID: 1048 / Administrator][C:\WINDOWS\conime.exe] [N/A, ] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\WINDOWS\system32\oswxdttb.dll] [N/A, ] [C:\WINDOWS\system32\zxmsdwin.dll] [N/A, ] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\mnmhgsrv.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\ozfyebyt.dll] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\WINDOWS\system32\mpwdeapi.dll] [N/A, ] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\apzhctde.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\s2da2f323.dll] [N/A, ] [C:\WINDOWS\system32\rijxbkin.dll] [N/A, ] [C:\WINDOWS\system32\skqncbib.dll] [N/A, ] [C:\WINDOWS\system32\MMHADPQG1097.dll] [N/A, ] [C:\WINDOWS\system32\mndsgsrv.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\apsgfjba.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\pjjxedwd.dll] [N/A, ] [C:\WINDOWS\system32\yxcschlp.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\zptlcsys.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 2116 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2168 / Administrator][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 2488 / Administrator][C:\WINDOWS\system32\Explorer.exe] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\oswxdttb.dll] [N/A, ] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\WINDOWS\system32\zxmsdwin.dll] [N/A, ] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\mnmhgsrv.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\ozfyebyt.dll] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\WINDOWS\system32\mpwdeapi.dll] [N/A, ] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\apzhctde.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\s2da2f323.dll] [N/A, ] [C:\WINDOWS\system32\rijxbkin.dll] [N/A, ] [C:\WINDOWS\system32\skqncbib.dll] [N/A, ] [C:\WINDOWS\system32\mndsgsrv.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\apsgfjba.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\pjjxedwd.dll] [N/A, ] [C:\WINDOWS\system32\yxcschlp.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\zptlcsys.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [C:\WINDOWS\downlo~1\Mugxz.dll] [Tencent, 5, 0, 7, 10] [d:\Thunder Network\WebThunder\WebThunderBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 75] [D:\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.16] [D:\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 55] [D:\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 12] [D:\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 13] [C:\PROGRA~1\FLASHGET\jccatch.dll] [Amaze Soft, 1, 1, 4, 0] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [D:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [C:\WINDOWS\system32\MMHADPQG1097.dll] [N/A, ] [PID: 2592 / Administrator][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3427] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 2616 / Administrator][C:\WINDOWS\Domino.exe] [, 3, 6, 818, 7] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\WINDOWS\system32\msdmo.dll] [, ] [PID: 2640 / Administrator][C:\WINDOWS\system32\Rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 2648 / Administrator][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 5.0.0.16] [C:\Program Files\Rising\AntiSpyware\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\AntiSpyware\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [C:\WINDOWS\system32\mnmhgsrv.dll] [N/A, ] [C:\WINDOWS\system32\apsgfjba.dll] [N/A, ] [C:\WINDOWS\system32\skqncbib.dll] [N/A, ] [C:\WINDOWS\system32\mndsgsrv.dll] [N/A, ] [C:\WINDOWS\system32\pjjxedwd.dll] [N/A, ] [C:\WINDOWS\system32\oswxdttb.dll] [N/A, ] [C:\WINDOWS\system32\zptlcsys.dll] [N/A, ] [C:\WINDOWS\system32\apzhctde.dll] [N/A, ] [C:\WINDOWS\system32\mpwdeapi.dll] [N/A, ] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [C:\WINDOWS\system32\yxcschlp.dll] [N/A, ] [C:\WINDOWS\system32\MMHADPQG1097.dll] [N/A, ] [C:\WINDOWS\system32\zxmsdwin.dll] [N/A, ] [C:\WINDOWS\system32\s2da2f323.dll] [N/A, ] [C:\WINDOWS\system32\ozfyebyt.dll] [N/A, ] [C:\WINDOWS\system32\rijxbkin.dll] [N/A, ] [PID: 2656 / Administrator][C:\Program Files\StarSec\ssMgr_ccb.exe] [, 1, 0, 5, 1026] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\WINDOWS\system32\SSP11_CCB.dll] [GDChina, 1, 0, 0, 2] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 2676 / Administrator][D:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.23] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [D:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [D:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [D:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.18] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 2704 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 2712 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164] [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 2748 / Administrator][C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe] [Nero AG, 1, 5, 13, 0] [C:\Program Files\Common Files\Ahead\Lib\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Common Files\Ahead\Lib\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\Program Files\Common Files\Ahead\Lib\AdvrCntr2.dll] [Nero AG, 5,22,2, 10400] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvrPS.dll] [Nero AG, 1, 5, 13, 0] [C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll] [Nero AG, 1, 5, 13, 0] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 2844 / Administrator][D:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 20.0.01.19] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [D:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [D:\Program Files\Rising\Rav\recomp.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 39] [D:\Program Files\Rising\Rav\refs.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17] [D:\Program Files\Rising\Rav\viruslib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26] [D:\Program Files\Rising\Rav\relibldr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [D:\Program Files\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [D:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.18] [D:\Program Files\Rising\Rav\MonRule.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.29] [D:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [D:\Program Files\Rising\Rav\Rsguilib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 89] [D:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 2968 / Administrator][C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe] [Nero AG, 1, 5, 13, 0] [C:\Program Files\Common Files\Ahead\Lib\NMSQLDB.dll] [Nero AG, 1, 5, 13, 0] [C:\Program Files\Common Files\Ahead\Lib\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Common Files\Ahead\Lib\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\Program Files\Common Files\Ahead\Lib\NMLogCxx.dll] [Nero AG, 1, 5, 13, 0] [C:\Program Files\Common Files\Ahead\Lib\log4cxx.dll] [Nero AG, 1, 0, 0, 0] [C:\Program Files\Common Files\Ahead\Lib\NMCoFoundation.dll] [Nero AG, 1, 5, 13, 0] [C:\Program Files\Common Files\Ahead\Lib\NMPluginBase.dll] [Nero AG, 1, 5, 13, 0] [C:\Program Files\Common Files\Ahead\Lib\NMFullTextExtraction.dll] [Nero AG, 1, 5, 13, 0] [C:\Program Files\Common Files\Ahead\Lib\NMSearchPluginSimilarImages.dll] [Nero AG, 1, 5, 13, 0] [C:\Program Files\Common Files\Ahead\Lib\NeroIPP.dll] [Nero AG, 4,5,17,1] [C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll] [Nero AG, 1, 5, 13, 0] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\Program Files\Common Files\Ahead\Lib\NMIndexingServicePS.dll] [Nero AG, 1, 5, 13, 0] [C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvrPS.dll] [Nero AG, 1, 5, 13, 0] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 3384 / Administrator][C:\Program Files\Rising\AntiSpyware\Ras.exe] [Beijing Rising Technology Co., Ltd., 5.0.0.67] [C:\Program Files\Rising\AntiSpyware\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\AntiSpyware\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Rising\AntiSpyware\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\AntiSpyware\TopSoft.dll] [Beijing Rising Technology Co., Ltd., 5.0.0.2] [C:\Program Files\Rising\AntiSpyware\NComm.dll] [Beijing Rising Technology Co., Ltd., 1.0.0.4] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19] [C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [D:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\Program Files\Rising\AntiSpyware\RasGui.dll] [Beijing Rising Technology Co., Ltd., 2, 0, 0, 53] [C:\Program Files\Rising\AntiSpyware\rsxml.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 1] [C:\Program Files\Rising\AntiSpyware\ktrojan.dll] [Beijing Rising Technology Co., Ltd., 1.0.0.13] [C:\Program Files\Rising\AntiSpyware\engine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 25] [C:\Program Files\Rising\AntiSpyware\rsdialog.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\Program Files\Rising\AntiSpyware\scanunv.dll] [, 5, 0, 0, 4] [C:\Program Files\Rising\AntiSpyware\SecScan.dll] [Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited, 1, 0, 0, 15] [C:\Program Files\Rising\AntiSpyware\SecEx.dll] [Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited, 1, 0, 0, 8] [C:\Program Files\Rising\AntiSpyware\zip.dll] [rising, 13, 0, 0, 1] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [D:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17] [C:\WINDOWS\system32\mnmhgsrv.dll] [N/A, ] [C:\WINDOWS\system32\apsgfjba.dll] [N/A, ] [C:\WINDOWS\system32\skqncbib.dll] [N/A, ] [C:\WINDOWS\system32\mndsgsrv.dll] [N/A, ] [C:\WINDOWS\system32\pjjxedwd.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\oswxdttb.dll] [N/A, ] [C:\WINDOWS\system32\apzhctde.dll] [N/A, ] [C:\WINDOWS\system32\mpwdeapi.dll] [N/A, ] [C:\WINDOWS\system32\yxcschlp.dll] [N/A, ] [C:\WINDOWS\system32\MMHADPQG1097.dll] [N/A, ] [C:\WINDOWS\system32\zxmsdwin.dll] [N/A, ] [C:\WINDOWS\system32\s2da2f323.dll] [N/A, ] [C:\WINDOWS\system32\ozfyebyt.dll] [N/A, ] [C:\WINDOWS\system32\rijxbkin.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 3960 / SYSTEM][C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe] [Nero AG, 1, 5, 13, 0] [C:\Program Files\Common Files\Ahead\Lib\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Common Files\Ahead\Lib\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19] [C:\Program Files\Common Files\Ahead\Lib\NMIndexingServicePS.dll] [Nero AG, 1, 5, 13, 0] [C:\Program Files\Common Files\Ahead\Lib\NMLogCxx.dll] [Nero AG, 1, 5, 13, 0] [C:\Program Files\Common Files\Ahead\Lib\log4cxx.dll] [Nero AG, 1, 0, 0, 0] [C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll] [Nero AG, 1, 5, 13, 0] [PID: 4080 / Administrator][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\downlo~1\Mugxz.dll] [Tencent, 5, 0, 7, 10] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [c:\program files\google\googletoolbar1.dll] [Google Inc., 4, 0, 1606, 6690] [E:\Tencent\QQDownload\QQIEHelper01.dll] [腾讯公司, 1, 1, 0, 5] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [d:\Thunder Network\WebThunder\WebThunderBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 75] [D:\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.16] [C:\Program Files\TENCENT\SSPlus\SAddr1.dll] [Tencent, 5, 0, 7, 10] [E:\BitComet\tools\BitCometBHO_1.2.2.28.dll] [BitComet, 20080228] [C:\WINDOWS\system32\oswxdttb.dll] [N/A, ] [C:\WINDOWS\system32\SSup.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\zxmsdwin.dll] [N/A, ] [D:\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 55] [D:\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 12] [D:\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 13] [C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll] [Microsoft Corporation, 4.100.313.1] [C:\Program Files\Common Files\Microsoft Shared\Windows Live\msidcrl40.dll] [Microsoft Corporation, 4.100.313.1] [C:\PROGRA~1\FLASHGET\jccatch.dll] [Amaze Soft, 1, 1, 4, 0] [C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164] [D:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [C:\WINDOWS\system32\rijxbkin.dll] [N/A, ] [C:\WINDOWS\system32\skqncbib.dll] [N/A, ] [C:\WINDOWS\system32\yxcschlp.dll] [N/A, ] [C:\WINDOWS\system32\apzhctde.dll] [N/A, ] [C:\WINDOWS\system32\zptlcsys.dll] [N/A, ] [C:\WINDOWS\system32\pjjxedwd.dll] [N/A, ] [C:\WINDOWS\system32\mpwdeapi.dll] [N/A, ] [C:\WINDOWS\system32\ozfyebyt.dll] [N/A, ] [C:\WINDOWS\system32\apsgfjba.dll] [N/A, ] [C:\WINDOWS\system32\mndsgsrv.dll] [N/A, ] [C:\WINDOWS\system32\mnmhgsrv.dll] [N/A, ] [C:\WINDOWS\system32\s2da2f323.dll] [N/A, ] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17] [C:\WINDOWS\system32\MMHADPQG1097.dll] [N/A, ] [PID: 1520 / Administrator][C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe] [Microsoft Corporation, 4.100.313.1] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\Program Files\Common Files\Microsoft Shared\Windows Live\msidcrl40.dll] [Microsoft Corporation, 4.100.313.1] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 2340 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 3316 / Administrator][C:\WINDOWS\system32\alxw9.exe] [N/A, ] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 1356 / Administrator][d:\program files\rising\rfw\CopyRun\RavCopy.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.1] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19] [D:\PROGRAM FILES\RISING\RFW\COPYRUN\Update.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.25] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 2224 / Administrator][D:\PROGRAM FILES\RISING\RFW\Update\Setup.exe] [Beijing Rising Technology Co., Ltd., 20.0.1.17] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19] [C:\WINDOWS\system32\skqncbib.dll] [N/A, ] [D:\PROGRAM FILES\RISING\RFW\Update\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\PROGRAM FILES\RISING\RFW\Update\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [D:\PROGRAM FILES\RISING\RFW\Update\Setup.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.31] [D:\PROGRAM FILES\RISING\RFW\Update\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [PID: 1736 / Administrator][C:\WINDOWS\system32\woasickk.exe] [N/A, ] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19] [C:\WINDOWS\system32\skqncbib.dll] [N/A, ] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [PID: 3496 / Administrator][d:\program files\rising\rfw\ScanBD.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.9] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19] [C:\WINDOWS\system32\skqncbib.dll] [N/A, ] [d:\program files\rising\rfw\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [d:\program files\rising\rfw\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [D:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [d:\program files\rising\rfw\BDEngine.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.2] [d:\program files\rising\rfw\libload.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16] [d:\program files\rising\rfw\BDEX.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.4] [d:\program files\rising\rfw\BDLib.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.1] [PID: 3988 / Administrator][E:\Tencent\QQDownload\QQDownload.exe] [Tencent Technology (Shenzhen) Company Limited, 1, 8, 201, 201] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19] [C:\WINDOWS\system32\skqncbib.dll] [N/A, ] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [E:\Tencent\QQDownload\xmain.dll] [Tencent Technology (Shenzhen) Company Limited, 1, 8, 202, 202] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [D:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [E:\Tencent\QQDownload\xcore.dll] [Tencent Technology(Shenzhen) Company Limited, 2, 1, 101, 90] [C:\WINDOWS\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 3884 / Administrator][D:\Downloads\软件\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900] [C:\WINDOWS\system32\yzztjmsn.dll] [N/A, ] [C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19] [C:\WINDOWS\system32\skqncbib.dll] [N/A, ] [d:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.18] [d:\program files\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6] [C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll] [TENCENT, 5, 0, 4, 10] [C:\WINDOWS\system32\kbdswjr.dll] [N/A, ] [C:\WINDOWS\system32\midimapwl.dll] [N/A, ] [C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ] [C:\WINDOWS\system32\midimapgj.dll] [N/A, ] [C:\WINDOWS\system32\adsntzt.dll] [N/A, ] [C:\WINDOWS\system32\midimapcq.dll] [N/A, ] [C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys] [N/A, ] [C:\WINDOWS\system32\mfdesy.dll] [N/A, ] [C:\WINDOWS\system32\cedafb.dll] [N/A, ] [C:\WINDOWS\system32\ddserh.dll] [N/A, ] [C:\WINDOWS\system32\jfrwdh.dll] [N/A, ] [C:\WINDOWS\system32\sgrefg.dll] [N/A, ] [C:\WINDOWS\system32\mtewdh.dll] [N/A, ] [C:\WINDOWS\system32\zefdst.dll] [N/A, ] [C:\WINDOWS\system32\wzcfsw.dll] [N/A, ] [C:\WINDOWS\system32\hhrdxd.dll] [N/A, ] [C:\WINDOWS\system32\tdggrz.dll] [N/A, ] [C:\WINDOWS\system32\sjhrdh.dll] [N/A, ] [C:\WINDOWS\system32\tdffdl.dll] [N/A, ] [C:\WINDOWS\system32\jfdses.dll] [N/A, ] [D:\Downloads\软件\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP Error. [winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 528, C:\PROGRAM FILES\COMMON FILES\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 912, C:\PROGRAM FILES\STARSEC\PLUGSERVER.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 1048, C:\WINDOWS\CONIME.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1048, C:\WINDOWS\CONIME.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 2592, C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2592, C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 2616, C:\WINDOWS\DOMINO.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2616, C:\WINDOWS\DOMINO.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 2648, C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2648, C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 2656, C:\PROGRAM FILES\STARSEC\SSMGR_CCB.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2656, C:\PROGRAM FILES\STARSEC\SSMGR_CCB.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 2748, C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\NMBGMONITOR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2748, C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\NMBGMONITOR.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 2968, C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\NMINDEXSTORESVR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2968, C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\NMINDEXSTORESVR.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 3384, C:\PROGRAM FILES\RISING\ANTISPYWARE\RAS.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3384, C:\PROGRAM FILES\RISING\ANTISPYWARE\RAS.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 3316, C:\WINDOWS\SYSTEM32\ALXW9.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3316, C:\WINDOWS\SYSTEM32\ALXW9.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 1736, C:\WINDOWS\SYSTEM32\WOASICKK.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1736, C:\WINDOWS\SYSTEM32\WOASICKK.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 3988, E:\TENCENT\QQDOWNLOAD\QQDOWNLOAD.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3988, E:\TENCENT\QQDOWNLOAD\QQDOWNLOAD.EXE] ================================== API HOOK 入口点错误:NtCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003E4415) 入口点错误:NtWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003E44B5) 入口点错误:ZwCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003E4415) 入口点错误:ZwWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003E44B5) 入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: 0x011C1FFD) 入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: 0x011C20E5) ================================== 隐藏进程 N/A ================================== [/CODE]