2008-08-22,15:26:28 System Repair Engineer 2.6.12.1018 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] (ctfmon.exe)(C:\WINDOWS\system32\ctfmon.exe) [(Verified)Microsoft Windows Publisher] (QQDownload)("D:\Program Files\QQDownload\QQDownload.exe" autostart) [File is missing] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] (RavTask)("C:\Program Files\Rising\Rav\RavTask.exe" -system) [(Verified)Beijing Rising Information Technology Corporation Limited] (akCheck)("H:\IE反劫持\AV终结者\1" -anti) [] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] (shell)(Explorer.exe) [(Verified)Microsoft Windows Publisher] (Userinit)(userinit.exe,) [(Verified)Microsoft Windows Publisher] (UIHost)(logonui.exe) [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] (WPDShServiceObj)(C:\WINDOWS\system32\WPDShServiceObj.dll) [(Verified)Microsoft Windows Component Publisher] (qtfstqywi)(C:\WINDOWS\system32\loanoltrd.dll) [File is missing] (dpvvoxmh.dll)(C:\WINDOWS\system32\dpvvoxmh.dll) [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] (WinlogonNotify: igfxcui)(igfxdev.dll) [(Verified)Microsoft Windows Hardware Compatibility Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] ({16B05A05-27C1-E38D-F49E-8D27C17C16B0})(C:\WINDOWS\system32\LQVAFK.dll) [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\){26923b43-4d38-484f-9b9e-de460746276c}] (Internet Explorer)(%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE) [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\){881dd1c5-3dcf-431b-b061-f3f88e8be88a}] (Outlook Express)(%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE) [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] (Themes Setup)(%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll) [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] (Microsoft Outlook Express 6)("%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install) [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] (NetMeeting 3.01)(rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT) [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] (Windows Messenger 4.7)(rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser) [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5c386e54-d4b0-2905-2905-e5c1f7edd34a}] (N/A)(C:\WINDOWS\system32\utovbti\svchost.exe /t) [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] (Microsoft Windows Media Player)(rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub) [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] (通讯簿 6)("%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install) [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] (IMJPMIG8.1)(; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32) [File is missing] (PHIME2002A)(; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName) [File is missing] (PHIME2002ASync)(; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32) [File is missing] -------------------------------------------------------------------------------- 启动文件夹 [腾讯QQ] (C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --) [File is missing])(N) -------------------------------------------------------------------------------- 服务 [Human Interface Device Access / HidServ][Stopped/Disabled] (C:\WINDOWS\System32\svchost.exe -k netsvcs--)%SystemRoot%\System32\hidserv.dll)(N/A) [Rising Process Communication Center / RsCCenter][Running/Auto Start] ("C:\Program Files\Rising\Rav\CCenter.exe")(Beijing Rising Information Technology Co., Ltd.) [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] ("C:\PROGRAM FILES\RISING\RAV\Ravmond.exe")(Beijing Rising Information Technology Co., Ltd.) -------------------------------------------------------------------------------- 驱动程序 [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start] (system32\drivers\ac97intc.sys)(Intel Corporation) [AliIde / AliIde][Running/Boot Start] (\SystemRoot\System32\DRIVERS\aliide.sys)(Acer Laboratories Inc.) [AMD K8 Processor Driver / AmdK8][Stopped/Manual Start] (System32\DRIVERS\amdk8.sys)(Advanced Micro Devices) [CmdIde / CmdIde][Running/Boot Start] (\SystemRoot\System32\DRIVERS\cmdide.sys)(CMD Technology, Inc.) [dohs / dohs][Stopped/Auto Start] (\??\C:\WINDOWS\TEMP\tmp21.tmp)(N/A) [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start] (system32\DRIVERS\fetnd5.sys)(VIA Technologies, Inc.) [fmsq / fmsq][Stopped/Auto Start] (\??\C:\WINDOWS\TEMP\tmp35.tmp)(N/A) [Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start] (system32\DRIVERS\HDAudBus.sys)(Windows (R) Server 2003 DDK provider) [HookCont / HookCont][Running/System Start] (\SystemRoot\system32\drivers\HookCont.sys)(Beijing Rising Information Technology Co., Ltd.) [HookNtos / HookNtos][Running/System Start] (\SystemRoot\system32\drivers\HookNtos.sys)(Beijing Rising Information Technology Co., Ltd.) [HookReg / HookReg][Running/System Start] (\SystemRoot\system32\drivers\HookReg.sys)(Beijing Rising Information Technology Co., Ltd.) [HookSys / HookSys][Running/System Start] (\SystemRoot\system32\drivers\HookSys.sys)(Beijing Rising Information Technology Co., Ltd.) [ialm / ialm][Running/Manual Start] (system32\DRIVERS\ialmnt5.sys)(Intel Corporation) [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start] (system32\drivers\RtkHDAud.sys)(Realtek Semiconductor Corp.) [mhfp / mhfp][Stopped/Auto Start] (\??\C:\WINDOWS\TEMP\tmp5.tmp)(N/A) [mnsf / mnsf][Stopped/Auto Start] (\??\C:\WINDOWS\TEMP\tmp43.tmp)(N/A) [npkcrypt / npkcrypt][Running/Auto Start] (\??\D:\Program Files\QQ2007\npkcrypt.sys)(INCA Internet Co., Ltd.) [nv / nv][Stopped/Manual Start] (system32\DRIVERS\nv4_mini.sys)(NVIDIA Corporation) [Direct Parallel Link Driver / Ptilink][Running/Manual Start] (system32\DRIVERS\ptilink.sys)(Parallel Technologies, Inc.) [RsNTGDI / RsNTGDI][Running/Boot Start] (\SystemRoot\system32\Drivers\RsNTGdi.sys)(Beijing Rising Information Technology Co., Ltd.) [Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Running/Manual Start] (system32\DRIVERS\Rtnicxp.sys)(Realtek Semiconductor Corporation) [Secdrv / Secdrv][Stopped/Manual Start] (system32\DRIVERS\secdrv.sys)(N/A) [zftp / zftp][Stopped/Auto Start] (\??\C:\WINDOWS\TEMP\tmpF.tmp)(N/A) [ASTTools / ASTTools][Running/Manual Start] (\??\H:\IE反劫持\FileForceKiller\ASTTools.sys)(DSW Lab) [360Killer / 360Killer][Running/] (2 - 系统找不到指定的文件。 )(N/A) -------------------------------------------------------------------------------- 浏览器加载项 [QQCycloneHelper Class] {00000000-12C9-4305-82F9-43058F20E8D2} (D:\Program Files\QQDownload\QQIEHelper01.dll, (Signed) 腾讯公司) [QQCycloneHelper Class] {00000000-12C9-4305-82F9-43058F20E8D2} (D:\Program Files\QQDownload\QQIEHelper01.dll, (Signed) 腾讯公司) [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, (Signed) Adobe Systems, Inc.) [] {FB5F1910-F110-11D2-BB9E-00C04F795683} (, ) [&使用超级旋风下载] (D:\Program Files\QQDownload\geturl.htm, N/A) [&使用超级旋风下载全部链接] (D:\Program Files\QQDownload\getAllurl.htm, N/A) [导出到 Microsoft Office Excel(&X)] (res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A) [添加到QQ表情] (D:\Program Files\QQ2007\AddEmotion.htm, N/A) -------------------------------------------------------------------------------- 正在运行的进程 [PID: 492 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 556 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 580 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 624 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\AppPatch\AcAdProc.dll] [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)] [PID: 636 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 784 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 828 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 900 / SYSTEM][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.33] [PID: 924 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 976 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1036 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1188 / SYSTEM][C:\PROGRAM FILES\RISING\RAV\ravmond.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.80] [C:\PROGRAM FILES\RISING\RAV\BWList.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.5] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [C:\PROGRAM FILES\RISING\RAV\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [C:\PROGRAM FILES\RISING\RAV\RsLog.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.36] [C:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.29] [C:\PROGRAM FILES\RISING\RAV\Hooksys.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 12] [C:\PROGRAM FILES\RISING\RAV\HookReg.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [C:\PROGRAM FILES\RISING\RAV\HookNtos.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [C:\PROGRAM FILES\RISING\RAV\rswalmon.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 24] [C:\PROGRAM FILES\RISING\RAV\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 40] [C:\PROGRAM FILES\RISING\RAV\refs.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 18] [C:\PROGRAM FILES\RISING\RAV\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 16] [C:\Program Files\Rising\Rav\RsStore.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.9] [C:\PROGRAM FILES\RISING\RAV\HookCont.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [C:\Program Files\Rising\Rav\fakescan.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.14] [C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.39] [C:\PROGRAM FILES\RISING\RAV\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27] [C:\PROGRAM FILES\RISING\RAV\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\PROGRAM FILES\RISING\RAV\HookWeb.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.3] [C:\PROGRAM FILES\RISING\RAV\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7] [C:\PROGRAM FILES\RISING\RAV\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 6] [C:\PROGRAM FILES\RISING\RAV\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 87] [C:\PROGRAM FILES\RISING\RAV\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 8] [C:\PROGRAM FILES\RISING\RAV\extfile.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 32] [C:\PROGRAM FILES\RISING\RAV\scanpack.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [C:\PROGRAM FILES\RISING\RAV\revm.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 11] [C:\PROGRAM FILES\RISING\RAV\urutils.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7] [C:\PROGRAM FILES\RISING\RAV\ur000.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 19] [C:\PROGRAM FILES\RISING\RAV\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [C:\PROGRAM FILES\RISING\RAV\scriptci.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 4] [C:\PROGRAM FILES\RISING\RAV\ur001.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 4] [C:\PROGRAM FILES\RISING\RAV\extole.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 13] [C:\PROGRAM FILES\RISING\RAV\uroutine.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27] [C:\PROGRAM FILES\RISING\RAV\ur023.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 3] [C:\PROGRAM FILES\RISING\RAV\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [PID: 1412 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\LQVAFK.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WPDShServiceObj.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)] [C:\WINDOWS\system32\dpvvoxmh.dll] [N/A, ] [C:\WINDOWS\system32\PortableDeviceTypes.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)] [C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4396] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [H:\IE反劫持\FileForceKiller\FileForceKiller.dll] [DSW Lab, 1.0.0.5] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.18] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [PID: 1560 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [PID: 1680 / SYSTEM][C:\PROGRAM FILES\RISING\RAV\RavStub.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.10] [C:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [PID: 1948 / Administrator][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.24] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [PID: 1964 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\dpvvoxmh.dll] [N/A, ] [PID: 1996 / Administrator][C:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.01.24] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 40] [C:\Program Files\Rising\Rav\refs.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 18] [C:\Program Files\Rising\Rav\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27] [C:\Program Files\Rising\Rav\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [C:\Program Files\Rising\Rav\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.29] [C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [C:\Program Files\Rising\Rav\Rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 90] [C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [PID: 1076 / Administrator][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\LQVAFK.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\dpvvoxmh.dll] [N/A, ] [PID: 1864 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2940 / Administrator][E:\abcd\TdxW.exe] [, ] [E:\abcd\TCalc.dll] [, 1, 0, 0, 1] [E:\abcd\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0] [E:\abcd\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0] [E:\abcd\Viewthem.dll] [, 1, 0, 0, 1] [E:\abcd\invest.dll] [, 1.15] [E:\abcd\Dbf.dll] [N/A, ] [E:\abcd\Secure.dll] [通达信, 1.00.00] [E:\abcd\TTools.dll] [, 1.00] [E:\abcd\TList.dll] [, 1.00] [C:\WINDOWS\system32\dpvvoxmh.dll] [N/A, ] [E:\abcd\calcer.dll] [, 1, 0, 0, 1] [E:\abcd\Advhq.dll] [, 1, 0, 0, 1] [PID: 2596 / Administrator][H:\IE反劫持\FileForceKiller\FileForceKiller.exe] [DSW Lab, 1.0.0.5] [C:\WINDOWS\system32\dpvvoxmh.dll] [N/A, ] [H:\IE反劫持\FileForceKiller\FileForceKiller.dll] [DSW Lab, 1.0.0.5] [C:\WINDOWS\system32\wpdshext.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)] [C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)] [C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)] [PID: 2780 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\dpvvoxmh.dll] [N/A, ] [PID: 4032 / Administrator][H:\IE反劫持\AV终结者\请运行.exe] [N/A, ] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Newkernel32.dll] [Microsoft Corporation, 5.1.2600.2945 (xpsp_sp2_gdr.060704-2349)] [C:\WINDOWS\system32\dpvvoxmh.dll] [N/A, ] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fixfinal2.dll] [N/A, ] [H:\IE反劫持\AV终结者\xavengine.dll] [360.cn, 1, 0, 0, 1006] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\NewAdvapi32.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1404 / Administrator][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\dpvvoxmh.dll] [N/A, ] [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] [C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)] [PID: 1032 / Administrator][H:\IE反劫持\新建文件夹\SREe89ec477.EXE] [Smallfrogs Studio, 2.6.12.1018] [C:\WINDOWS\system32\dpvvoxmh.dll] [N/A, ] [H:\IE反劫持\新建文件夹\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [C:\PROGRA~1\MICROS~2\OFFICE11\MCPS.DLL] [Microsoft Corporation, 11.0.6551] -------------------------------------------------------------------------------- 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] -------------------------------------------------------------------------------- Winsock 提供者 N/A -------------------------------------------------------------------------------- Autorun.inf N/A -------------------------------------------------------------------------------- HOSTS 文件 127.0.0.1 localhost 219.235.3.16 search.114.vnet.cn 219.235.3.16 keyword.vnet.cn 219.235.3.16 auto.search.msn.com 219.235.3.16 search.msn.com 219.235.3.16 cnweb.search.live.com 219.235.3.16 www.k369.com 219.235.3.16 www.5566.net 219.235.3.16 360safe.com 219.235.3.16 360.cn 219.235.3.16 360.qihoo.com 219.235.3.16 360safe.qihoo.com 219.235.3.16 forum.ikaka.com 219.235.3.16 www.ikaka.com 202.165.102.243 update.ikaka.com 219.235.3.16 forum.jiangmin.com 202.165.102.243 update.jiangmin.com 219.235.3.16 tieba.baidu.com 219.235.3.16 post.baidu.com 219.235.3.16 zhidao.baidu.com 219.235.3.16 www.baidu.com 202.165.102.243 update.rising.com.cn 219.235.3.16 online.rising.com.cn 202.165.102.243 center.rising.com.cn 219.235.3.16 up.duba.net 219.235.3.16 vi.duba.net 219.235.3.16 shadu.baidu.com 219.235.3.16 du.baidu.com 219.235.3.16 security.symantec.com 219.235.3.16 shadu.duba.net 219.235.3.16 bbs.duba.net 219.235.3.16 www.duba.net 219.235.3.16 online.jiangmin.com 219.235.3.16 cn.mcafee.com 219.235.3.16 www.ahn.com.cn 219.235.3.16 www.kaspersky.com.cn 219.235.3.16 www.pcav.cn 219.235.3.16 www.luosoft.com 219.235.3.16 www.im286.com 219.235.3.16 an.baidu.com 219.235.3.16 ma.baidu.com 219.235.3.16 bbs.htmlman.net 202.165.102.243 download.rising.com.cn 202.165.102.243 rsup08.rising.com.cn 219.235.3.16 10000.286er.com 219.235.3.16 im286.net 219.235.3.16 ju.qihoo.com 219.235.3.16 bbs.chinaz.com 219.235.3.16 www.qihoo.com 202.165.102.243 dnl-cn1.kaspersky-labs.com 202.165.102.243 dnl-cn2.kaspersky-labs.com 202.165.102.243 dnl-cn3.kaspersky-labs.com 202.165.102.243 dnl-cn4.kaspersky-labs.com 202.165.102.243 dnl-cn5.kaspersky-labs.com 202.165.102.243 dnl-cn6.kaspersky-labs.com 202.165.102.243 dnl-cn7.kaspersky-labs.com 202.165.102.243 dnl-cn8.kaspersky-labs.com 202.165.102.243 dnl-cn9.kaspersky-labs.com 202.165.102.243 dnl-cn10.kaspersky-labs.com 202.165.102.243 dnl-cn11.kaspersky-labs.com 202.165.102.243 dnl-cn12.kaspersky-labs.com 202.165.102.243 dnl-cn13.kaspersky-labs.com 202.165.102.243 dnl-cn14.kaspersky-labs.com 202.165.102.243 dnl-cn15.kaspersky-labs.com 202.165.102.243 dnl-eu1.kaspersky-labs.com 202.165.102.243 dnl-eu2.kaspersky-labs.com 202.165.102.243 dnl-eu3.kaspersky-labs.com 202.165.102.243 dnl-eu4.kaspersky-labs.com 202.165.102.243 dnl-eu5.kaspersky-labs.com 202.165.102.243 dnl-eu6.kaspersky-labs.com 202.165.102.243 dnl-eu7.kaspersky-labs.com 202.165.102.243 dnl-eu8.kaspersky-labs.com 202.165.102.243 dnl-eu9.kaspersky-labs.com 202.165.102.243 dnl-eu10.kaspersky-labs.com 202.165.102.243 dnl-eu11.kaspersky-labs.com 202.165.102.243 dnl-eu12.kaspersky-labs.com 202.165.102.243 dnl-eu13.kaspersky-labs.com 202.165.102.243 dnl-eu14.kaspersky-labs.com 202.165.102.243 dnl-eu15.kaspersky-labs.com 202.165.102.243 dnl-us1.kaspersky-labs.com 202.165.102.243 dnl-us2.kaspersky-labs.com 202.165.102.243 dnl-us3.kaspersky-labs.com 202.165.102.243 dnl-us4.kaspersky-labs.com 202.165.102.243 dnl-us5.kaspersky-labs.com 202.165.102.243 dnl-us6.kaspersky-labs.com 202.165.102.243 dnl-us7.kaspersky-labs.com 202.165.102.243 dnl-us8.kaspersky-labs.com 202.165.102.243 dnl-us9.kaspersky-labs.com 202.165.102.243 dnl-us10.kaspersky-labs.com 202.165.102.243 dnl-us11.kaspersky-labs.com 202.165.102.243 dnl-us12.kaspersky-labs.com 202.165.102.243 dnl-us13.kaspersky-labs.com 202.165.102.243 dnl-us14.kaspersky-labs.com 202.165.102.243 dnl-us15.kaspersky-labs.com 202.165.102.243 dnl-ru1.kaspersky-labs.com 202.165.102.243 dnl-ru2.kaspersky-labs.com 202.165.102.243 dnl-ru3.kaspersky-labs.com 202.165.102.243 dnl-ru4.kaspersky-labs.com 202.165.102.243 dnl-ru5.kaspersky-labs.com 202.165.102.243 dnl-ru6.kaspersky-labs.com 202.165.102.243 dnl-ru7.kaspersky-labs.com 202.165.102.243 dnl-ru8.kaspersky-labs.com 202.165.102.243 dnl-ru9.kaspersky-labs.com 202.165.102.243 dnl-ru10.kaspersky-labs.com 202.165.102.243 dnl-ru11.kaspersky-labs.com 202.165.102.243 dnl-ru12.kaspersky-labs.com 202.165.102.243 dnl-ru13.kaspersky-labs.com 202.165.102.243 dnl-ru14.kaspersky-labs.com 202.165.102.243 dnl-ru15.kaspersky-labs.com 202.165.102.243 dnl-jp1.kaspersky-labs.com 202.165.102.243 dnl-jp2.kaspersky-labs.com 202.165.102.243 dnl-jp3.kaspersky-labs.com 202.165.102.243 dnl-jp4.kaspersky-labs.com 202.165.102.243 dnl-jp5.kaspersky-labs.com 202.165.102.243 dnl-jp6.kaspersky-labs.com 202.165.102.243 dnl-jp7.kaspersky-labs.com 202.165.102.243 dnl-jp8.kaspersky-labs.com 202.165.102.243 dnl-jp9.kaspersky-labs.com 202.165.102.243 dnl-jp10.kaspersky-labs.com 202.165.102.243 dnl-jp11.kaspersky-labs.com 202.165.102.243 dnl-jp12.kaspersky-labs.com 202.165.102.243 dnl-jp13.kaspersky-labs.com 202.165.102.243 dnl-jp14.kaspersky-labs.com 202.165.102.243 dnl-jp15.kaspersky-labs.com 202.165.102.243 dnl-kr1.kaspersky-labs.com 202.165.102.243 dnl-kr2.kaspersky-labs.com 202.165.102.243 dnl-kr3.kaspersky-labs.com 202.165.102.243 dnl-kr4.kaspersky-labs.com 202.165.102.243 dnl-kr5.kaspersky-labs.com 202.165.102.243 dnl-kr6.kaspersky-labs.com 202.165.102.243 dnl-kr7.kaspersky-labs.com 202.165.102.243 dnl-kr8.kaspersky-labs.com 202.165.102.243 dnl-kr9.kaspersky-labs.com 202.165.102.243 dnl-kr10.kaspersky-labs.com 202.165.102.243 dnl-kr11.kaspersky-labs.com 202.165.102.243 dnl-kr12.kaspersky-labs.com 202.165.102.243 dnl-kr13.kaspersky-labs.com 202.165.102.243 dnl-kr14.kaspersky-labs.com 202.165.102.243 dnl-kr15.kaspersky-labs.com 202.165.102.243 dnl-cd1.kaspersky-labs.com 202.165.102.243 dnl-cd2.kaspersky-labs.com 202.165.102.243 dnl-cd3.kaspersky-labs.com 202.165.102.243 dnl-cd4.kaspersky-labs.com 202.165.102.243 dnl-cd5.kaspersky-labs.com 202.165.102.243 dnl-cd6.kaspersky-labs.com 202.165.102.243 dnl-cd7.kaspersky-labs.com 202.165.102.243 dnl-cd8.kaspersky-labs.com 202.165.102.243 dnl-cd9.kaspersky-labs.com 202.165.102.243 dnl-cd10.kaspersky-labs.com 202.165.102.243 dnl-cd11.kaspersky-labs.com 202.165.102.243 dnl-cd12.kaspersky-labs.com 202.165.102.243 dnl-cd13.kaspersky-labs.com 202.165.102.243 dnl-cd14.kaspersky-labs.com 202.165.102.243 dnl-cd15.kaspersky-labs.com 202.165.102.243 downloads1.kaspersky-labs.com 202.165.102.243 downloads2.kaspersky-labs.com 202.165.102.243 downloads3.kaspersky-labs.com 202.165.102.243 downloads4.kaspersky-labs.com 202.165.102.243 downloads5.kaspersky-labs.com 219.235.3.16 ishare.sina.com.cn 219.235.3.16 search.cn.yahoo.com 219.235.3.16 www.google.com 219.235.3.16 google.com 219.235.3.16 www.google.cn 219.235.3.16 www.yahoo.com.cn 219.235.3.16 cn.yahoo.com 219.235.3.16 search.tom.com 219.235.3.16 zhuansha.duba.net 219.235.3.16 buy.duba.net 219.235.3.16 kad.www.duba.net 219.235.3.16 cu001.www.duba.net 219.235.3.16 cu002.www.duba.net 219.235.3.16 cu003.www.duba.net 219.235.3.16 cu004.www.duba.net 219.235.3.16 cu005.www.duba.net 219.235.3.16 cu010.www.duba.net 219.235.3.16 client.download.duba.net 219.235.3.16 page.so.163.com 219.235.3.16 www.soso.com 219.235.3.16 sou.china.com 219.235.3.16 test.591jx.com 219.235.3.16 a.topxxxx.cn 219.235.3.16 picon.chinaren.com 219.235.3.16 www.5566.net 127.0.0.1 p.qqkx.com 127.0.0.1 news.netandtv.com 127.0.0.1 z.neter888.cn 127.0.0.1 b.myblank.cn 127.0.0.1 wvw.wokutu.com 127.0.0.1 unionch.qyule.com 127.0.0.1 www.qyule.com 127.0.0.1 it.itjc.cn 127.0.0.1 www.linkwww.com 127.0.0.1 vod.kaicn.com 127.0.0.1 www.tx8688.com 127.0.0.1 b.neter888.cn 127.0.0.1 promote.huanqiu.com 127.0.0.1 www.huanqiu.com 127.0.0.1 www.haokanla.com 127.0.0.1 play.unionsky.cn 127.0.0.1 www.52v.com 127.0.0.1 www.gghka.cn 127.0.0.1 icon.ajiang.net 127.0.0.1 new.ete.cn 127.0.0.1 www.stiae.cn 127.0.0.1 o.neter888.cn 127.0.0.1 comm.jinti.com 127.0.0.1 www.google-analytics.com 127.0.0.1 hz.mmstat.com 127.0.0.1 www.game175.cn 127.0.0.1 x.neter888.cn 127.0.0.1 z.neter888.cn 127.0.0.1 p.etimes888.com 127.0.0.1 hx.etimes888.com 127.0.0.1 abc.qqkx.com 127.0.0.1 dm.popdm.cn 127.0.0.1 www.yl9999.com 127.0.0.1 www.dajiadoushe.cn 127.0.0.1 down.nihao29.cn 127.0.0.1 v.onondown.com.cn 127.0.0.1 www.interoo.net 127.0.0.1 bally1.bally-bally.net 127.0.0.1 www.bao5605509.cn 127.0.0.1 down.nihao29.cn 127.0.0.1 www.mzd020.cn 127.0.0.1 jzm015.cn 127.0.0.1 down.hs7yue.cn 127.0.0.1 new.doups.cn 127.0.0.1 w.qq-uc.cn 127.0.0.1 down.nihao69.cn 127.0.0.1 www.rty456.cn 127.0.0.1 www.werqwer.cn 127.0.0.1 www.jjyyzmj.cn 127.0.0.1 1.360-1.cn 127.0.0.1 5.360-5.cn 127.0.0.1 user1.23-16.net 127.0.0.1 user1.23-18.net 127.0.0.1 www.guccia.net 127.0.0.1 www.interoo.net 127.0.0.1 upa.netsool.net 127.0.0.1 pua.lianxiac.net 127.0.0.1 js.users.51.la 127.0.0.1 vip2.51.la 127.0.0.1 web.51.la 127.0.0.1 qq.gong2008.com 127.0.0.1 2008tl.copyip.com 127.0.0.1 tla.laozihuolaile.cn 127.0.0.1 www.tx6868.cn 127.0.0.1 p001.tiloaiai.com 127.0.0.1 s1.tl8tl.com 127.0.0.1 s1.gong2008.com 127.0.0.1 mm1.laozihuolaile.cn 127.0.0.1 mm2.laozihuolaile.cn 127.0.0.1 tlbm2.laozihuolaile.cn 127.0.0.1 tlbm3.laozihuolaile.cn 127.0.0.1 www.6161q1.cn 127.0.0.1 www.6161q2.cn 127.0.0.1 www.6161h1.cn 127.0.0.1 www.6161h2.cn 127.0.0.1 user1.23-21.net 127.0.0.1 www.skpoot.net 127.0.0.1 user1.kao-360.net 127.0.0.1 user1.23-22.net 127.0.0.1 www.keysooa.net -------------------------------------------------------------------------------- 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 2940, E:\ABCD\TDXW.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 2596, H:\IE反劫持\FILEFORCEKILLER\FILEFORCEKILLER.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2596, H:\IE反劫持\FILEFORCEKILLER\FILEFORCEKILLER.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 4032, H:\IE反劫持\AV终结者\请运行.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 4032, H:\IE反劫持\AV终结者\请运行.EXE] -------------------------------------------------------------------------------- API HOOK N/A -------------------------------------------------------------------------------- 隐藏进程 N/A --------------------------------------------------------------------------------