[CODE] 2008-08-25,19:27:22 System Repair Engineer 2.6.12.1018 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [] [] [(Verified)"INTER CHINA NETWORK SOFTWARE (BEIJING) CO., LTD"] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] <"D:\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{D157330A-9EF3-49F8-9A67-4141AC41ADD4}> [(Verified)"INTER CHINA NETWORK SOFTWARE (BEIJING) CO., LTD"] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}> [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] ================================== 启动文件夹 N/A ================================== 服务 [Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start] [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [Rising Process Communication Center / RsCCenter][Running/Auto Start] <"D:\Rising\Rav\CCenter.exe"> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] <"D:\RISING\RAV\Ravmond.exe"> [Stormser / Stormser][Running/Auto Start] <暴风网际> ================================== 驱动程序 [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start] [AliIde / AliIde][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aliide.sys> [AMD Processor Driver / AmdK8][Running/System Start] [ati2mtag / ati2mtag][Running/Manual Start] [CmdIde / CmdIde][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\cmdide.sys> [CnsMinKP / CnsMinKP][Running/Boot Start] <\SystemRoot\system32\drivers\CnsMinKP.sys><国风因特软件(北京)有限公司> [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start] [Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start] [HookCont / HookCont][Running/System Start] <\SystemRoot\system32\drivers\HookCont.sys> [HookNtos / HookNtos][Running/System Start] <\SystemRoot\system32\drivers\HookNtos.sys> [HookReg / HookReg][Running/System Start] <\SystemRoot\system32\drivers\HookReg.sys> [HookSys / HookSys][Running/System Start] <\SystemRoot\system32\drivers\HookSys.sys> [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start] [mhpfp / mhpfp][Running/Boot Start] <\SystemRoot\\SystemRoot\System32\drivers\mhpfp.sys> [npkcrypt / npkcrypt][Stopped/Auto Start] <\??\C:\Program Files\QQ2006\npkcrypt.sys> [nv / nv][Stopped/Manual Start] [nvata / nvata][Running/Boot Start] <\SystemRoot\system32\DRIVERS\nvata.sys> [NVIDIA nForce Networking Controller Driver / NVENETFD][Running/Manual Start] [NVIDIA Network Bus Enumerator / nvnetbus][Running/Manual Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [Secdrv / Secdrv][Stopped/Manual Start] [R2A / R2A][Stopped/Disabled] <\??\C:\WINDOWS\system32a2.sys> ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [CnsHook Class] {D157330A-9EF3-49F8-9A67-4141AC41ADD4} [SrchHook Class] {F08555B0-9CC3-11D2-AA8E-000000000000} [Yahoo 3.5G电邮] {507F9113-CD77-4866-BA92-0E86DA3D0B97} [名品折扣] {59BC54A2-56B3-44a0-93E5-432D58746E26} [雅虎助手] {5D73EE86-05F1-49ed-B850-E423120EC338} [雅虎WIDGET] {6354ABE6-05F1-49ed-B850-E423120EC338} [情景聊天] {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} [] {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} [] {FD00D911-7529-4084-9946-A29F1BDF4FE5} [IE搜索工具条] {BE830FD4-E393-417F-9F4B-CC70ABB3384C} [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [] {507F9113-CD77-4866-BA92-0E86DA3D0B97} <, > [] {59BC54A2-56B3-44A0-93E5-432D58746E26} <, > [] {5D73EE86-05F1-49ED-B850-E423120EC338} <, > [] {6354ABE6-05F1-49ED-B850-E423120EC338} <, > [AutoLive] {7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [IE搜索工具条] {BE830FD4-E393-417F-9F4B-CC70ABB3384C} [CnsHook Class] {D157330A-9EF3-49F8-9A67-4141AC41ADD4} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [] {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <, > [] {ECF2E268-F28C-48D2-9AB7-8F69C11CCB71} <, > [SrchHook Class] {F08555B0-9CC3-11D2-AA8E-000000000000} [] {FB5F1910-F110-11D2-BB9E-00C04F795683} <, > [] {FD00D911-7529-4084-9946-A29F1BDF4FE5} <, > [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] ================================== 正在运行的进程 [PID: 608 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 672 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 708 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4146] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 752 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 764 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 924 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4146] [C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2504] [PID: 940 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1040 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1148 / SYSTEM][D:\Rising\Rav\CCenter.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.33] [PID: 1164 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)] [D:\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [PID: 1208 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1288 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4146] [C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2504] [C:\WINDOWS\system32\ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4146] [PID: 1320 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1520 / SYSTEM][D:\RISING\RAV\ravmond.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.80] [D:\RISING\RAV\BWList.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.5] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [D:\RISING\RAV\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [D:\RISING\RAV\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [D:\RISING\RAV\RsLog.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.36] [D:\RISING\RAV\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\RISING\RAV\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\RISING\RAV\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.29] [D:\RISING\RAV\Hooksys.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 12] [D:\RISING\RAV\HookReg.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [D:\RISING\RAV\HookNtos.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [D:\RISING\RAV\rswalmon.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 24] [D:\RISING\RAV\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 41] [D:\RISING\RAV\refs.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 18] [D:\RISING\RAV\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 16] [D:\Rising\Rav\RsStore.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.9] [D:\RISING\RAV\HookCont.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [D:\Rising\Rav\fakescan.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.14] [D:\Rising\Rav\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.39] [D:\RISING\RAV\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27] [D:\RISING\RAV\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [D:\RISING\RAV\HookWeb.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.3] [D:\RISING\RAV\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7] [D:\RISING\RAV\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\RISING\RAV\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 6] [D:\RISING\RAV\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 89] [D:\RISING\RAV\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 8] [D:\RISING\RAV\extfile.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 32] [D:\RISING\RAV\scanpack.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [D:\RISING\RAV\revm.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 11] [D:\RISING\RAV\urutils.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7] [D:\RISING\RAV\ur000.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 19] [D:\RISING\RAV\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [D:\RISING\RAV\posttrt.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 24] [D:\RISING\RAV\scriptci.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 4] [D:\RISING\RAV\ur001.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 4] [D:\RISING\RAV\ur023.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 3] [D:\RISING\RAV\uroutine.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27] [D:\RISING\RAV\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [PID: 1640 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [PID: 1884 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\DOWNLO~1\CnsHook.dll] [国风因特软件(北京)有限公司, 2.5.1.9] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.18] [C:\WINDOWS\DOWNLO~1\CnsMin.dll] [国风因特软件(北京)有限公司, 2.5.1.6] [C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327] [C:\PROGRA~1\3721\alrex.dll] [, 1, 0, 1, 1001] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [D:\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\PROGRA~1\3721\autolive.dll] [, 1, 1, 9, 1329] [C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006] [D:\迅雷\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [D:\迅雷\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [D:\迅雷\Components\ResWorker\DsBho_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20] [D:\迅雷\Components\ResWorker\DataProcessor_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] [PID: 2004 / SYSTEM][D:\RISING\RAV\RavStub.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.10] [D:\RISING\RAV\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\RISING\RAV\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [PID: 176 / Administrator][C:\WINDOWS\system32\Rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\DOWNLO~1\CnsMin.dll] [国风因特软件(北京)有限公司, 2.5.1.6] [C:\WINDOWS\DOWNLO~1\CnsMinIO.dll] [国风因特软件(北京)有限公司, 2.5.0.9] [C:\WINDOWS\DOWNLO~1\cnsio.dll] [国风因特软件(北京)有限公司, 2.5.0.6] [C:\WINDOWS\DOWNLO~1\CnsMinEx.dll] [国风因特软件(北京)有限公司, 2.5.0.6] [PID: 496 / SYSTEM][D:\Storm Codec\Stormser.exe] [暴风网际, 1, 0, 0, 11] [D:\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [PID: 548 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)] [PID: 384 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 668 / Administrator][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327] [C:\WINDOWS\DOWNLO~1\CnsMin.dll] [国风因特软件(北京)有限公司, 2.5.1.6] [C:\PROGRA~1\3721\autolive.dll] [, 1, 1, 9, 1329] [C:\PROGRA~1\3721\notifier.dll] [国风因特软件(北京)有限公司, 2.5.2.1004] [C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006] [PID: 2140 / Administrator][C:\WINDOWS\RTHDCPL.EXE] [Realtek Semiconductor Corp., 2.0.8.7] [C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327] [C:\WINDOWS\DOWNLO~1\CnsMin.dll] [国风因特软件(北京)有限公司, 2.5.1.6] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 2268 / Administrator][D:\Rising\Rav\RavTask.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.24] [D:\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [D:\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [D:\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [PID: 2316 / Administrator][D:\Rising\Rav\Ravmon.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.01.24] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [D:\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [D:\Rising\Rav\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 41] [D:\Rising\Rav\refs.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 18] [D:\Rising\Rav\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27] [D:\Rising\Rav\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [D:\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [D:\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [D:\Rising\Rav\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.29] [D:\Rising\Rav\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [D:\Rising\Rav\Rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 90] [D:\Rising\Rav\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [PID: 2460 / Administrator][C:\WINDOWS\system32\CTFMON.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327] [C:\WINDOWS\DOWNLO~1\CnsMin.dll] [国风因特软件(北京)有限公司, 2.5.1.6] [PID: 2104 / Administrator][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)] [C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327] [C:\WINDOWS\DOWNLO~1\CnsMin.dll] [国风因特软件(北京)有限公司, 2.5.1.6] [C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)] [PID: 3876 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327] [C:\WINDOWS\DOWNLO~1\CnsMin.dll] [国风因特软件(北京)有限公司, 2.5.1.6] [PID: 2052 / Administrator][D:\Rising\Rav\RsAgent.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.10] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [D:\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [PID: 1056 / Administrator][C:\WINDOWS\msagent\AgentSvr.exe] [Microsoft Corporation, 2.00.0.3424] [C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327] [C:\WINDOWS\DOWNLO~1\CnsMin.dll] [国风因特软件(北京)有限公司, 2.5.1.6] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 576 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327] [C:\PROGRA~1\3721\scrblock.dll] [3721, 1, 0, 1, 1000] [C:\PROGRA~1\3721\alrex.dll] [, 1, 0, 1, 1001] [C:\WINDOWS\DOWNLO~1\CnsMin.dll] [国风因特软件(北京)有限公司, 2.5.1.6] [C:\WINDOWS\DOWNLO~1\CnsHint.dll] [国风因特软件(北京)有限公司, 2.5.0.7] [C:\PROGRA~1\3721\autolive.dll] [, 1, 1, 9, 1329] [C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006] [C:\WINDOWS\DOWNLO~1\cnsplus.dll] [国风因特软件(北京)有限公司, 2.5.0.4] [C:\WINDOWS\system32\IETool.dll] [N/A, ] [D:\迅雷\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [D:\迅雷\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [D:\迅雷\Components\ResWorker\DsBho_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20] [D:\迅雷\Components\ResWorker\DataProcessor_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [C:\WINDOWS\DOWNLO~1\CnsHook.dll] [国风因特软件(北京)有限公司, 2.5.1.9] [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] [D:\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\WINDOWS\system32\xpsp3res.dll] [Microsoft Corporation, 5.1.2600.3016 (xpsp_sp2_gdr.061016-0148)] [C:\WINDOWS\DOWNLO~1\CnsMinIO.dll] [国风因特软件(北京)有限公司, 2.5.0.9] [C:\WINDOWS\DOWNLO~1\cnsio.dll] [国风因特软件(北京)有限公司, 2.5.0.6] [PID: 1204 / SYSTEM][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)] [C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)] [PID: 3552 / Administrator][D:\Rising\Rav\Rav.exe] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 72] [D:\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\Rising\Rav\Rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 90] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [D:\Rising\Rav\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [D:\Rising\Rav\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [D:\Rising\Rav\RsCommon.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [D:\Rising\Rav\ravpagem.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 1, 9] [D:\Rising\Rav\htmllib.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.17] [C:\WINDOWS\DOWNLO~1\CnsHook.dll] [国风因特软件(北京)有限公司, 2.5.1.9] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.18] [D:\Rising\Rav\ravpagew.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 89] [D:\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [D:\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [D:\Rising\Rav\fakescan.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.14] [D:\Rising\Rav\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.39] [D:\Rising\Rav\BWList.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.5] [D:\Rising\Rav\SysMail.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.11] [D:\Rising\Rav\RsLog.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.36] [D:\Rising\Rav\RsStore.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.9] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [D:\Rising\Rav\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 41] [D:\Rising\Rav\refs.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 18] [D:\Rising\Rav\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27] [D:\Rising\Rav\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [D:\Rising\Rav\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 16] [D:\Rising\Rav\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7] [D:\Rising\Rav\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\Rising\Rav\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 6] [D:\Rising\Rav\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 89] [D:\Rising\Rav\extole.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 13] [D:\Rising\Rav\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [D:\Rising\Rav\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [D:\Rising\Rav\extfile.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 32] [D:\Rising\Rav\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 8] [D:\Rising\Rav\scanpack.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [D:\Rising\Rav\revm.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 11] [D:\Rising\Rav\urutils.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7] [D:\Rising\Rav\ur000.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 19] [D:\Rising\Rav\posttrt.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 24] [PID: 3676 / Administrator][D:\winrar\WinRAR.exe] [N/A, ] [C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327] [C:\WINDOWS\DOWNLO~1\CnsMin.dll] [国风因特软件(北京)有限公司, 2.5.1.6] [C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.3802.3802 built by: dnsrv(bld4act)] [PID: 2872 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.734\SREngLdr.EXE] [Smallfrogs Studio, 2.6.12.1018] [PID: 3352 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.734\SRE9b4eb966.EXE] [Smallfrogs Studio, 2.6.12.1018] [C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327] [C:\WINDOWS\DOWNLO~1\CnsMin.dll] [国风因特软件(北京)有限公司, 2.5.1.6] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.734\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [C:\PROGRA~1\MICROS~2\OFFICE11\MCPS.DLL] [Microsoft Corporation, 11.0.6551] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 0.0.0.0 182838.com 0.0.0.0 204.177.92.68 0.0.0.0 asiafriendfinder.com 0.0.0.0 asqin123.51.net 0.0.0.0 babe520.5188.org 0.0.0.0 music.feifa.com 0.0.0.0 music.v111.com 0.0.0.0 www.jpbeauty.com 0.0.0.0 beautishow.com 0.0.0.0 goodmovies88.com 0.0.0.0 hothack.home.chinaren.com 0.0.0.0 hualiao.net 0.0.0.0 iplus.allyes.com 0.0.0.0 jjkafei.longcity.net 0.0.0.0 kaomm.8m.cn 0.0.0.0 l3iaoliao.com 0.0.0.0 lingaonbvm.myrice.com 0.0.0.0 lovejava.boy.net.cn 0.0.0.0 love7liao.com 0.0.0.0 asqin123.51.net 0.0.0.0 babe520.5188.org 0.0.0.0 music.feifa.com 0.0.0.0 jjkafei.longcity.net 0.0.0.0 kaomm.8m.cn 0.0.0.0 l3iaoliao.com 0.0.0.0 l3iaoliao.com 0.0.0.0 lingaonbvm.myrice.com 0.0.0.0 lovejava.boy.net.cn 0.0.0.0 love7liao.com 0.0.0.0 babe520.5188.org 0.0.0.0 music.feifa.com 0.0.0.0 music.v111.com 0.0.0.0 babe520.5188.org 0.0.0.0 music.feifa.com 0.0.0.0 jjkafei.longcity.net 0.0.0.0 kaomm.8m.cn 0.0.0.0 l3iaoliao.com 0.0.0.0 l3iaoliao.com 0.0.0.0 lingaonbvm.myrice.com 0.0.0.0 lovejava.boy.net.cn 0.0.0.0 love7liao.com 0.0.0.0 babe520.5188.org 0.0.0.0 music.feifa.com 0.0.0.0 music.v111.com 219.153.32.215 auto.search.msn.com ================================== 进程特权扫描 特殊特权被允许: SeDebugPrivilege [PID = 3676, D:\WINRAR\WINRAR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3676, D:\WINRAR\WINRAR.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 2872, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RAR$EX00.734\SRENGLDR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2872, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RAR$EX00.734\SRENGLDR.EXE] ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]