[CODE] 2008-10-23,17:15:14 System Repair Engineer 2.7.0.1210 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AEB6717E-7E19-11d0-97EE-00C04FD91972}> [(Verified)Microsoft Windows Component Publisher] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}> [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <浏览器自定义组件> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] <%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Publisher] ================================== 启动文件夹 [2SMZK7YE] C:\WINDOWS\0XSMNT~1.EXE []> [Adobe Gamma Loader] C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [Adobe Systems, Inc.]> [OON332E8L] C:\WINDOWS\7R31X0~1.EXE []> [KPM62E0ID082] C:\WINDOWS\DNNG3PF2.exe []> [BPXY6] C:\WINDOWS\EJC76R~1.EXE []> [QJJHZ] C:\WINDOWS\9AGLZ.exe []> [AKCK4FID] C:\WINDOWS\RE41AMJ.exe []> [QEOO5Y] C:\WINDOWS\L1URE1~1.EXE []> [1NYF2] C:\WINDOWS\R6Y0RN3.exe []> [QF8L5GDD9BWY] C:\WINDOWS\HXXMH8.exe []> [DAGVV] C:\WINDOWS\BUXR8I.exe []> [W0Z7E] C:\WINDOWS\85824F.exe []> [18FPRWMDNZVK] C:\WINDOWS\GU2E5R~1.EXE []> [GT7UWKPFI55Q] C:\WINDOWS\NJW7KAX.exe []> [925HO7GJ6] C:\WINDOWS\4HRXBV~1.EXE []> [I2G6KZEY] C:\WINDOWS\UH9GK0.exe []> [SPXYRPUCZ] C:\WINDOWS\2DRQYYU.exe []> [O1O9CN2F7G] C:\WINDOWS\KZLWII.exe []> [K60TS96HX] C:\WINDOWS\W5LBO6.exe []> [3B2HDDH5RC] C:\WINDOWS\XX0DV6~1.EXE []> [24BFDUK5] C:\WINDOWS\03UQU5~1.EXE []> [CVVBJ] C:\WINDOWS\4MVZ0X~1.EXE []> [U8RJZFKD] C:\WINDOWS\SQ79FU~1.EXE []> [9CA0ZOGR] C:\WINDOWS\ZGCLJQR.exe []> [UAA7ADG7] C:\WINDOWS\KDEMRA.exe []> [OUE2DHXT9KNS] C:\WINDOWS\Q7P2TE~1.EXE []> [CXDDW] C:\WINDOWS\ULM9ZR~1.EXE []> [M2RV613] C:\WINDOWS\NVBQXY~1.EXE []> [FAODAI] C:\WINDOWS\H87V2.exe []> [IRQB3S] C:\WINDOWS\IOGGHM~1.EXE []> [J5LT53] C:\WINDOWS\3YPPFT~1.EXE []> [MEZ7D] [File is missing]> [4MYIXZ3MN6] [File is missing]> [QP5RWS3CH] [File is missing]> [LJ892LRWX4DQ] C:\WINDOWS\82J61C~1.EXE []> [AZKEGM1PYX] C:\WINDOWS\W75DHP~1.EXE []> [1NBP8S15VI] C:\WINDOWS\6DSU5Y~1.EXE []> [33K72VE] C:\WINDOWS\VHN8MU~1.EXE []> [KOO4IQ96WF9] C:\WINDOWS\0OHC14.exe []> [73MMDQ] C:\WINDOWS\10JNOB~1.EXE []> [3CAD30EZQQ5P] C:\WINDOWS\REQSK.exe []> [XL9LGRAY] C:\WINDOWS\JLJDO.exe []> [SICLN] C:\WINDOWS\7IGO497.exe []> [J5YTZ2I] C:\WINDOWS\M0KXXB~1.EXE []> [NXQTWK] C:\WINDOWS\WQ3X4Y~1.EXE []> [15BRHL] C:\WINDOWS\TY0Z7ERA.exe []> [X9GHSLB] C:\WINDOWS\WSVYF3~1.EXE []> [WLV2W2J0TFA] C:\WINDOWS\YA38MF8Z.exe []> [UACNCZMFCJ] C:\WINDOWS\55IEGO.exe []> [5DOJ5CG] C:\WINDOWS\A1L9M.exe []> [CNBR9PT6NE] C:\WINDOWS\B2001A~1.EXE []> [D3LV7GAE4] C:\WINDOWS\F8GD2WG.exe []> [JMIFS4BTE8V] C:\WINDOWS\2YOVI9~1.EXE []> [YWWX2XTF9Z] C:\WINDOWS\GRXLOF~1.EXE []> [18I80B70] C:\WINDOWS\VDSRAA.exe []> [RUSWKJ9IT] C:\WINDOWS\UTXYAP~1.EXE []> [LJ54E2TYNO51] C:\WINDOWS\3H6HWL~1.EXE []> [F0U19N329O] C:\WINDOWS\PBUVK4~1.EXE []> [CVG9NL] C:\WINDOWS\OSCPK0.exe []> [FJYB54LA3] C:\WINDOWS\4V2F6.exe []> [XI4GY2E] C:\WINDOWS\X54KLWY.exe []> [TFU5MTK1T29] C:\WINDOWS\EY17UK1.exe []> [HJPGZV4] C:\WINDOWS\QBT9RM~1.EXE []> [3I7MXYJV2ZRJ] C:\WINDOWS\VIMFK1~1.EXE []> [ON7TXSRP2J] C:\WINDOWS\N9ZYUHIQ.exe []> [1IPJ28ZV] C:\WINDOWS\AWWEH2~1.EXE []> [LYERKA3XQ1] C:\WINDOWS\811RHL~1.EXE []> [2KPSLCF] C:\WINDOWS\UZYBQW.exe []> [9IJ811SP825] C:\WINDOWS\Q45CI4~1.EXE []> [OAIRH9CF1DA] C:\WINDOWS\2ZXMV3~1.EXE []> [Y1EEQ3H] C:\WINDOWS\DT26VHB.exe []> [DZ6GZ2SC3] C:\WINDOWS\6HY91F~1.EXE []> [JY0WLT] C:\WINDOWS\KIHRR.exe []> [YN04DNID] C:\WINDOWS\4Q5RGCSO.exe []> [QERABUN3] C:\WINDOWS\ZJG75P.exe []> [868E98] C:\WINDOWS\L6PN1B~1.EXE []> [BAF6B1] C:\WINDOWS\BLYIEB~1.EXE []> [R2VG1] C:\WINDOWS\X2UBCE~1.EXE []> [TZSNUD6] C:\WINDOWS\IZXAM6OE.exe []> [24K18F] C:\WINDOWS\FAEYFL~1.EXE []> [7QXMV27L9NP4] C:\WINDOWS\39NMTO~1.EXE []> [MCDSU2XPL0] C:\WINDOWS\WCCPV.exe []> [O983Z0G] C:\WINDOWS\TOQV6B~1.EXE []> [9OT6J1HHX] C:\WINDOWS\WLOFTCX.exe []> [MZ5BDIGXV5U] C:\WINDOWS\0C4UA4~1.EXE []> [ZG5KYJU] C:\WINDOWS\JTYJF4~1.EXE []> [DDHJ1ORSZ] C:\WINDOWS\5JZ7P5~1.EXE []> [72RNQ2NV6] C:\WINDOWS\C3E1V3IV.exe []> [4TU86] C:\WINDOWS\32G23N2.exe []> [XM6C9] C:\WINDOWS\AF2T8D~1.EXE []> [MC1ESKXRH] C:\WINDOWS\KB8ILG~1.EXE []> [Q2NH12EOXC] C:\WINDOWS\HPBRR5~1.EXE []> [LU6ZLHB] C:\WINDOWS\DMW6H.exe []> [GLBKLGE2EW] C:\WINDOWS\XK1UU1~1.EXE []> [17YAEOCRU2KP] C:\WINDOWS\YVMPND.exe []> [X4UST] C:\WINDOWS\JLIQ8Y~1.EXE []> [JMQ1B6] C:\WINDOWS\OSB3J8~1.EXE []> [Q6JCE8591] C:\WINDOWS\ISPCYXQ.exe []> [2M1PBXGCV5] C:\WINDOWS\79DZ97~1.EXE []> [R7EJ3J178MB] C:\WINDOWS\7CR825~1.EXE []> [XB82U7E] C:\WINDOWS\92QR586.exe []> [RDZ2LGCW8214] C:\WINDOWS\0OGP00~1.EXE []> [4M3N9RRDMEO] C:\WINDOWS\EAYGYCD.exe []> [7YPPBVFWX2V] C:\WINDOWS\H48G5RX9.exe []> [7YPPBVFWX2V] [File is missing]> [VXJTT] C:\WINDOWS\CQDFOH~1.EXE []> [V6D5BYHVGCA] C:\WINDOWS\SW3K6Z~1.EXE []> ================================== 服务 [HN0SXZ22V / 03UQU56V9I8X][Running/Auto Start] <> [AIYBV / 048GNUGI][Running/Auto Start] <> [ZHX59 / 0C4UA4Z45A][Running/Auto Start] <> [FEDPVMPECS / 0CAWJU4EUBGH][Running/Auto Start] <> [5ENBJ / 0OGP00ZHFCRB][Running/Auto Start] <> [VG9O6VIFL / 0OHC14][Running/Auto Start] <> [30XFEX1G / 0XSMNTLIPG][Running/Auto Start] <> [CTQ80D9 / 10JNOBKN73O][Running/Auto Start] <> [CV30V8A18LK / 1DQ9HP][Running/Auto Start] <> [IRBQ05KHH37 / 1NMA57EP][Running/Auto Start] <> [6GCF8509 / 23L688NSQP][Running/Auto Start] <> [MLFBY / 28RGX6ZWY][Running/Auto Start] <> [6LFEEJ2UFNFU / 2DRQYYU][Running/Auto Start] <> [XP75UI1KK / 2E39H4CQIK][Running/Auto Start] <> [4MJZGE / 2YOVI9WF4VTT][Running/Auto Start] <> [HNCW4QIX / 2ZXMV31SG][Running/Auto Start] <> [TAXR2P07MI / 32G23N2][Running/Auto Start] <> [A67OUUKCV9R / 39NMTORARPN][Running/Auto Start] <> [NGD5AFS460T / 3H6HWLVY4][Running/Auto Start] <> [VIAC0IICGYN / 3Q8P5B9PX][Running/Auto Start] <> [2YKYIJPC / 3YPPFT456T7O][Running/Auto Start] <> [IKAPEH1LH / 44URXNFADIC][Running/Auto Start] <> [M6U4Y2SMPKIQ / 4HRXBVJT3][Running/Auto Start] <> [7O6PA3OS0 / 4MVZ0X557][Running/Auto Start] <> [R2EF7K / 4Q5RGCSO][Running/Auto Start] <> [34JJGBW5FATQ / 4S7C1BF][Running/Auto Start] <> [FS9ZSDF / 4V2F6][Running/Auto Start] <> [F76AQ / 4Y2NV45ZJQM][Running/Auto Start] <> [R8JZ5E23LT5 / 55IEGO][Running/Auto Start] <> [E4QPEQU3XZGB / 5JZ7P5730B4W][Running/Auto Start] <> [LAIPSI / 5PHMR5B][Running/Auto Start] <> [B7A8URJHNQ3J / 5U17V][Running/Auto Start] <> [TVJMCEV / 6AVRM][Running/Auto Start] <> [O7TAN / 6DSU5YINJ215][Running/Auto Start] <> [6XD6K1P6Q26 / 6GNJG][Running/Auto Start] <> [2TWNP3FYIE / 6HY91FUMNP6J][Running/Auto Start] <> [B7PGBTY5IEPW / 71A1OMFCCSQZ][Running/Auto Start] <> [6GQZS / 79DZ972O8][Running/Auto Start] <> [GJT0U / 7C6SJ1JR11W][Running/Auto Start] <> [V0TT2IIDX9 / 7CR825949N][Running/Auto Start] <> [Q0IF6ZC6ZQBI / 7IGO497][Running/Auto Start] <> [AV67XUC6DW / 7R31X0OGKEE][Running/Auto Start] <> [0PZIVV81Z3IB / 7UABW][Running/Auto Start] <> [WNIGQ / 7VQ16Y4G][Running/Auto Start] <> [CWBB8H / 807YOKW][Running/Auto Start] <> [WERTPZAYQFKO / 811RHLPIE][Running/Auto Start] <> [GBTFQN4MTSS / 82DXT][Running/Auto Start] <> [TVO9ZE8HYST / 82J61C740BU][Running/Auto Start] <> [W1FQUH85DOT / 85824F][Running/Auto Start] <> [2H4HWNAVVOAC / 92QR586][Running/Auto Start] <> [KWUVE / 93FKF7DB][Running/Auto Start] <> [DVBCQ77UF / 9AGLZ][Running/Auto Start] <> [1450YCB81Q0 / 9PB56][Running/Auto Start] <> [HT4WV / 9PWVUWPEV][Running/Auto Start] <> [72CZ7ZX7 / 9XDC15QSUVR][Running/Auto Start] <> [1YQHVHFT6 / A1L9M][Running/Auto Start] <> [E9T56F / A7WE6G][Running/Auto Start] <> [MJCUGYE / A8BHRVJAZUPX][Running/Auto Start] <> [Adobe LM Service / Adobe LM Service][Stopped/Manual Start] <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"> [0TD9JE / AF2T8DFWE8WG][Running/Auto Start] <> [U54CAD9AN / APZ4HO][Running/Auto Start] <> [Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start] [ZQDJBG393W6 / AWWEH2VLY8][Running/Auto Start] <> [AVMZB7ZYJ36 / B2001AP76][Running/Auto Start] <> [GY1K5OOTW70J / B234WHWTG6R][Running/Auto Start] <> [NYISWJD5 / BLYIEBPF20][Running/Auto Start] <> [416ZKOT2Q47Q / BOBRVHS7HX2Q][Running/Auto Start] <> [RRQJT7E / BUXR8I][Running/Auto Start] <> [C-DillaCdaC11BA / C-DillaCdaC11BA][Running/Auto Start] [ZSR60LTPLC / C3E1V3IV][Running/Auto Start] <> [C4HLPTV24MF / C3FJR3B46G][Running/Auto Start] <> [3CVOLFQI3TWB / CNKS6TK0RU5][Running/Auto Start] <> [Z54N23U4GIF7 / CPEK3BIE][Running/Auto Start] <> [G85M48D / CQDFOH7WJ][Running/Auto Start] <> [TEXI7 / DHPRG5R][Running/Auto Start] <> [XERXMLVR / DK7O6][Running/Auto Start] <> [3NU8VMQ09FG4 / DMW6H][Running/Auto Start] <> [XE7I4 / DNNG3PF2][Running/Auto Start] <> [7KWITIO / DT26VHB][Running/Auto Start] <> [OGT6CQYR7 / E3C7R][Running/Auto Start] <> [KOLYI / EAYGYCD][Running/Auto Start] <> [C8HR55MD / EFA30Q][Running/Auto Start] <> [N3VAPOZR7AI7 / EIN8ZYD4AR][Running/Auto Start] <> [D4RQH / EJC76RCECSYI][Running/Auto Start] <> [HUQ6PHM85XIV / EQREQWMX][Running/Auto Start] <> [VXOKR8NV / EY17UK1][Running/Auto Start] <> [2TM0ZQJHKQZS / F3V7UI][Running/Auto Start] <> [XGR23423C / F8GD2WG][Running/Auto Start] <> [DZSR5TG81Q / F9KDITE9O][Running/Auto Start] <> [5T1RBJD / FAEYFLDNA0MC][Running/Auto Start] <> [742MG1 / FF4RYL3][Running/Auto Start] <> [3WEE0H / G085Q8ODK5L][Running/Auto Start] <> [V8KI7 / G15E46Q8PJ8B][Running/Auto Start] <> [CKPD9GH3 / G8IF8YYK][Running/Auto Start] <> [BOI229UXLKAL / GGEKVHPI][Running/Auto Start] <> [XEOMKIYE8 / GRXLOFGLW2U6][Running/Auto Start] <> [HJGXC / GU2E5RRBX][Running/Auto Start] <> [ZFPWF7 / H87V2][Running/Auto Start] <> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [CN1NLM / HPBRR5BIAR][Running/Auto Start] <> [P69L4JG82Q / HSPED1G][Running/Auto Start] <> [HTTP - adsl / HTTP - adsl][Stopped/Auto Start] [WWBQ9R / HXXMH8][Running/Auto Start] <> [9MRRK / I29CH5GI7][Running/Auto Start] <> [1SFHBM / IGV5EX][Running/Auto Start] <> [5539QE / IL75XLP6BUDW][Running/Auto Start] <> [LPKA2WYLI / IOGGHMTF6][Running/Auto Start] <> [H36N8CQQ8 / ISPCYXQ][Running/Auto Start] <> [UEHV4PH / ITAFIP][Running/Auto Start] <> [A7U9MZB / IZXAM6OE][Running/Auto Start] <> [COKCUHJ27FE / JDJ2U02PV][Running/Auto Start] <> [JIP2FU9C0T6 / JFA5238XNP][Running/Auto Start] <> [FPLJ5L6JS9V / JJMJCDWD2][Running/Auto Start] <> [GZ0CN / JLIQ8YFQFO2][Running/Auto Start] <> [9JCUJ / JLJDO][Running/Auto Start] <> [CUXCFU / JQ6KM][Running/Auto Start] <> [VALSJ6W / JTYJF4VZ4J][Running/Auto Start] <> [GDEFN / K3NX9CW][Running/Auto Start] <> [XGPQMRVH / KB8ILGTEPM5][Running/Auto Start] <> [PLEYV5E / KCRNGQJR0N][Running/Auto Start] <> [FIC54Z1T / KDEMRA][Running/Auto Start] <> [M7MH7K69U0 / KIHRR][Running/Auto Start] <> [W1QSZLTR7JIF / KOTQJ7E][Running/Auto Start] <> [IDWMMZPJE00 / KWU3W][Running/Auto Start] <> [K4I5W5DTT / KZLWII][Running/Auto Start] <> [LIN1V3Z8LIUG / L1URE1USLG9][Running/Auto Start] <> [QKXH7TL / L6PN1BVHIO][Running/Auto Start] <> [XDG7G3O / LIQ5U][Running/Auto Start] <> [MDN26 / LWRRTY][Running/Auto Start] <> [QII0X5OL43L / M0KXXBW4E][Running/Auto Start] <> [Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start] <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><> [XZRCX / MOWG98G30ES][Running/Auto Start] <> [JZ3AIX5OH / MYQFFVM3ZNDL][Running/Auto Start] <> [9QSUB75GE36 / N11RB2FF][Running/Auto Start] <> [I0ZJY0VV / N42Y6][Running/Auto Start] <> [GJWYVA / N6BXLRZ58M][Running/Auto Start] <> [ETS420 / N9ZYUHIQ][Running/Auto Start] <> [7VGXWQY4 / NCCDS7EEDG85][Running/Auto Start] <> [95MKJIETU9 / NJW7KAX][Running/Auto Start] <> [ZA9N6RCC / NVBQXYZI1AX][Running/Auto Start] <> [H2RDJR2X1 / NVKK7JDWMV1V][Running/Auto Start] <> [DQM7XY5I1I / NW6YR4][Running/Auto Start] <> [AUR92S1NJ8M / OEIV4OKF][Running/Auto Start] <> [9X2GPCQN7YIP / OJB9STZPZZ9][Running/Auto Start] <> [TVK35J16 / OJC0CKI][Running/Auto Start] <> [931GWV7 / OSB3J8LTB7MR][Running/Auto Start] <> [BZ0DO / OSCPK0][Running/Auto Start] <> [3DQ3S / OYBENVGA3][Running/Auto Start] <> [QIV8SW3FW1JP / OZUSVAVUTS][Running/Auto Start] <> [WF1EKZG9 / PBUVK4EUZ8V][Running/Auto Start] <> [88J43S4ANY9 / PVM3YAIAF][Running/Auto Start] <> [47DTXS / PZ7VK][Running/Auto Start] <> [M1OV4 / Q45CI49WV8LX][Running/Auto Start] <> [F33ONW41 / Q7P2TEXNM40B][Running/Auto Start] <> [G0ULJFCVZBDV / Q7UDYVSQ][Running/Auto Start] <> [4I16TFE / Q8UW9DA6][Running/Auto Start] <> [UFMNOQF / QBT9RMTAJ][Running/Auto Start] <> [SSXE0 / QDA22PPYBY2M][Running/Auto Start] <> [9JP6W / QF77NM13N][Running/Auto Start] <> [G56RTPGB834 / QFGKETTV6VB2][Running/Auto Start] <> [M8A5ME / QQ8BO][Running/Auto Start] <> [ITRIKMPOYRNU / QVJ77Z28][Running/Auto Start] <> [7CFU7P1ASY / R5UUOG][Running/Auto Start] <> [10R4H53EUY2 / R6Y0RN3][Running/Auto Start] <> [YUZFY9V / RAOQQAK][Running/Auto Start] <> [IHL7B5E0V2F / RE41AMJ][Running/Auto Start] <> [MQRTSUWRSHM / REQSK][Running/Auto Start] <> [ZH9E964O8 / RJQZ0F][Running/Auto Start] <> [Rising Process Communication Center / RsCCenter][Running/Auto Start] <"C:\Program Files\Rising\Rav\CCenter.exe"> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"> [P51WXQVUU / SO48346P][Running/Auto Start] <> [WASH070JZMM / SQ79FUHZ6][Running/Auto Start] <> [361PUZJLP / TA40VYJOGKY][Running/Auto Start] <> [5Y2XFD16WUXF / TGRP1NKJEE][Running/Auto Start] <> [H7WUDJEWXWF6 / TOQV6BSVH8][Running/Auto Start] <> [5FJZTYQ0QFRN / TY0Z7ERA][Running/Auto Start] <> [RF00R2RI6UPU / UH9GK0][Running/Auto Start] <> [FVWANZSF9JT / ULM9ZR9N9][Running/Auto Start] <> [TS12OGK17 / ULV3WS0O50][Running/Auto Start] <> [VT1M0 / UMF7CQQDV6O][Running/Auto Start] <> [W11Z6WRZ5P2 / UTXYAPO7Y0EW][Running/Auto Start] <> [H6W0J495NDOV / UZYBQW][Running/Auto Start] <> [ECLG0T8QFRHM / V201ZZQV29N][Running/Auto Start] <> [VN5VYXIH99 / V2WVL][Running/Auto Start] <> [PKJDO1L8UFK1 / V8ENDKSG0][Running/Auto Start] <> [BDV94K / VDSRAA][Running/Auto Start] <> [T6A811 / VHN8MUHQT69J][Running/Auto Start] <> [OI3MWO / VIMFK1TWEJ][Running/Auto Start] <> [LCFJVAR / W5LBO6][Running/Auto Start] <> [16HYQPCF / W75DHP5AH][Running/Auto Start] <> [OQ169X02BH5 / WCCPV][Running/Auto Start] <> [1PC47COAW / WLOFTCX][Running/Auto Start] <> [ACFKZP8KNR9 / WMB80CGV50][Running/Auto Start] <> [FJ9FXFRI / WQ3X4Y7CDU5O][Running/Auto Start] <> [UZEV1T / WSVYF3D60KQ][Running/Auto Start] <> [JFEPJRY6W63X / WXPEF3K7C36][Running/Auto Start] <> [C7850F67 / X2UBCE9PB][Running/Auto Start] <> [TW7OSJSI / X54KLWY][Running/Auto Start] <> [TVXHGUS91FJG / XK1UU18GB][Running/Auto Start] <> [E8XSE5NUO6 / XX0DV6O218][Running/Auto Start] <> [VS959YIHZ8C / YA38MF8Z][Running/Auto Start] <> [A1QFD / YATBFGW3UAG][Running/Auto Start] <> [TKLVEQ / YMIQPGM8UV5L][Running/Auto Start] <> [OWJA1U / YUGF0BJ][Running/Auto Start] <> [ZVF2K9Z1AO / YVMPND][Running/Auto Start] <> [PXO53 / ZGCLJQR][Running/Auto Start] <> [3IBXF / ZJG75P][Running/Auto Start] <> [GVMH5QKF / ZM3H54BIWLA][Running/Auto Start] <> [MKEKNIF / SW3K6Z3WDF][Stopped/Auto Start] <> [X7NHKAJGTUI / Z0U26HFA][Stopped/Auto Start] <> [SF6U0ROSPU / F7FOWVTQ1][Stopped/Auto Start] <> [1RZ71GCEZT5 / YOS1L3BK02][Stopped/Auto Start] <> [W87VIP9 / 653TX4X1][Stopped/Auto Start] <> [DAKQ3ND2 / FUXWQ56Y][Stopped/Auto Start] <> [WFIBXCNY / BRASYQR7][Stopped/Auto Start] <> [XVRAUS8S8YI / HSOSH05K][Stopped/Auto Start] <> [JZUY3LX / 88OXAQGGL][Stopped/Auto Start] <> [ML10U8EA / HCAUQ3C][Stopped/Auto Start] <> [OW861ZK7OXDE / 4NJAC9T6P5Y][Stopped/Auto Start] <> [WN3MDFD1 / TAR3SOCGX][Stopped/Auto Start] <> [ANE750K / O6AWRV9CPL9][Stopped/Auto Start] <> [K0AW9VM04 / DGHOXUHAHK][Stopped/Auto Start] <> [TL1B7794I1AC / YWG74MT605][Stopped/Auto Start] <> [2LJRDE0UAS8 / GYZ8Q5I][Stopped/Auto Start] <> [M8M3C1VH1A8N / 82Y96NP8Z9][Stopped/Auto Start] <> [QZS2F99C2 / Z4O1LHKWJ][Stopped/Auto Start] <> [NP0VXQJJ0OX / 33G0O33][Stopped/Auto Start] <> [B8S9GLDNIKZY / 7AG6OIFXPD1][Stopped/Auto Start] <> [B1O7ST0TR / LXK361MW2Y][Stopped/Auto Start] <> [NE4KSNWHGEY / WDXPMBC08YX][Stopped/Auto Start] <> [D3RDQ6R / S9YU0][Stopped/Auto Start] <> [IRYZZ0U / MZ5VNIO][Stopped/Auto Start] <> [8UV0BCG / CX9B3KV0][Stopped/Auto Start] <> [U32DXNHI / 39WSCZ5PMRH][Stopped/Auto Start] <> [V6V8N / MPSYLA0][Stopped/Auto Start] <> [EROQY7HTR9SL / GZRELW][Stopped/Auto Start] <> [G19ZQ / QJK5I][Stopped/Auto Start] <> [9D0GTD5 / HHRPX3J2MB0][Stopped/Auto Start] <> [2ZXCFAAZ6D3 / A6O9X1I9][Stopped/Auto Start] <> [AB0GHLS683 / 5A74EWZEERC7][Stopped/Auto Start] <> [D8GM4O5R1SQ / 8OWVA7][Stopped/Auto Start] <> [L9J1ERAP2Q / 89PRC][Stopped/Auto Start] <> [NX1CT2LNP / CNCLG1][Stopped/Auto Start] <> [RWPLLE / 4J7TRN5GJ][Stopped/Auto Start] <> [A73RT / JASN2I17GY][Stopped/Auto Start] <> ================================== 驱动程序 [a347bus / a347bus][Running/Boot Start] <\SystemRoot\system32\DRIVERS\a347bus.sys><> [a347scsi / a347scsi][Running/Boot Start] <\SystemRoot\System32\Drivers\a347scsi.sys><> [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start] [AliIde / AliIde][Running/Boot Start] <\SystemRoot\System32\DRIVERS\aliide.sys> [AMD Processor Driver / AmdK8][Running/System Start] [askd / askd][Stopped/Manual Start] <\??\C:\WINDOWS\system32\drivers\askd.ahc> [标准 IDE/ESDI 硬盘控制器 / atapi][Running/Boot Start] <\SystemRoot\system32\DRIVERS\atapi.sys> [ati2mtag / ati2mtag][Running/Manual Start] [CdaC15BA / CdaC15BA][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\CDAC15BA.SYS> [CmdIde / CmdIde][Running/Boot Start] <\SystemRoot\System32\DRIVERS\cmdide.sys> [Dritek Keyboard Filter Driver / DKbFltr][Running/Manual Start] [Dritek General Port I/O / DritekPortIO][Running/Auto Start] <\??\C:\PROGRA~1\LAUNCH~1\DPortIO.sys> [EMSCR / EMSCR][Running/Manual Start] [ESDCR / ESDCR][Running/Manual Start] [ESMCR / ESMCR][Running/Manual Start] [Lavalys EVEREST Kernel Driver / EverestDriver][Stopped/Manual Start] <\??\C:\Program Files\装机人员工具\EVEREST Ultimate v3.50 增强版\kerneld.wnt> [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start] [Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start] [OLB8621HR / HGILRZPV4GXT][Stopped/Manual Start] <\??\C:\WINDOWS\YYEV4H5S.txt> [HookCont / HookCont][Running/System Start] <\SystemRoot\system32\drivers\HookCont.sys> [HookNtos / HookNtos][Running/System Start] <\SystemRoot\system32\drivers\HookNtos.sys> [HookReg / HookReg][Running/System Start] <\SystemRoot\system32\drivers\HookReg.sys> [HookSys / HookSys][Running/System Start] <\SystemRoot\system32\drivers\HookSys.sys> [HSFHWAZL / HSFHWAZL][Running/Manual Start] [HSF_DPV / HSF_DPV][Running/Manual Start] [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start] [mdmxsdk / mdmxsdk][Running/Auto Start] [3Com 3CRDAG675B Wireless LAN PCI Adapter Service / net5213][Stopped/Manual Start] <3Com Corporation> [nv / nv][Stopped/Manual Start] [OX16C95x Serial port driver / oxser][Stopped/System Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Running/Manual Start] [Secdrv / Secdrv][Running/Auto Start] [ATI-4379 Serial ATA Controller / SI3112r][Running/Boot Start] <\SystemRoot\System32\DRIVERS\SI3112r.sys> [Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start] [Synaptics TouchPad Driver / SynTP][Running/Manual Start] [winachsf / winachsf][Running/Manual Start] ================================== 浏览器加载项 [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [浩方电竞平台] {0A155D3C-68E2-4215-A47A-E800A446447A} [] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} <, > [] {0A155D3C-68E2-4215-A47A-E800A446447A} <, > [Windows Media Player] {22D6F312-B0F6-11D0-94AB-0080C74C7E95} [HTML Document] {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, (Signed) N/A> [DHTML Edit Control Safe for Scripting for IE5] {2D360201-FFF5-11D1-8D03-00A0C959BC0A} [RealPlayer RAM Download Handler] {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} [] {3049C3E9-B461-4BC5-8870-4C09146192CA} <, > [XML Document] {48123BC4-99D9-11D1-A6B3-00C04FD91555} [] {507F9113-CD77-4866-BA92-0E86DA3D0B97} <, > [Shell Name Space] {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A> [] {55FE8157-23FA-43C6-91A1-3E4094E9A38D} <, > [] {59BC54A2-56B3-44A0-93E5-432D58746E26} <, > [] {6354ABE6-05F1-49ED-B850-E423120EC338} <, > [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [] {77FEF28E-EB96-44FF-B511-3185DEA48697} <, > [] {7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2} <, > [Microsoft Web 浏览器] {8856F961-340A-11D0-A96B-00C04FD705A2} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [] {9A568672-D437-469E-86C2-F6E4A1156071} <, > [SearchAssistantOC] {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A> [] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <, > [RDS.DataSpace] {BD96C556-65A3-11D0-983A-00C04FC29E36} [IE搜索工具条] {BE830FD4-E393-417F-9F4B-CC70ABB3384C} [AUDIO__MP3 Moniker Class] {CD3AFA76-B84F-48F0-9393-7EDC34128127} [AUDIO__X_MS_WMA Moniker Class] {CD3AFA84-B84F-48F0-9393-7EDC34128127} [] {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <, > [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [] {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <, > [] {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <, > [] {ECF2E268-F28C-48D2-9AB7-8F69C11CCB71} <, > [] {F08555B0-9CC3-11D2-AA8E-000000000000} <, > [] {FB5F1910-F110-11D2-BB9E-00C04F795683} <, > [] {FD00D911-7529-4084-9946-A29F1BDF4FE5} <, > [中国搜索(&Z)] [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] [添加到QQ表情] <, > ================================== 正在运行的进程 [PID: 480 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 548 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 576 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4132] [PID: 620 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 632 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 788 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4132] [C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2500] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 800 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 876 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 952 / SYSTEM][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.33] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 968 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1016 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1088 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1140 / SYSTEM][C:\PROGRAM FILES\RISING\RAV\ravmond.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.80] [C:\PROGRAM FILES\RISING\RAV\BWList.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.5] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [C:\PROGRAM FILES\RISING\RAV\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [C:\PROGRAM FILES\RISING\RAV\RsLog.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.36] [C:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.29] [C:\PROGRAM FILES\RISING\RAV\Hooksys.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 12] [C:\PROGRAM FILES\RISING\RAV\HookReg.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [C:\PROGRAM FILES\RISING\RAV\HookNtos.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [C:\PROGRAM FILES\RISING\RAV\rswalmon.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 24] [C:\PROGRAM FILES\RISING\RAV\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 41] [C:\PROGRAM FILES\RISING\RAV\refs.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 18] [C:\PROGRAM FILES\RISING\RAV\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\RsStore.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.9] [C:\PROGRAM FILES\RISING\RAV\HookCont.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [C:\Program Files\Rising\Rav\fakescan.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.14] [C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.39] [C:\PROGRAM FILES\RISING\RAV\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27] [C:\PROGRAM FILES\RISING\RAV\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\PROGRAM FILES\RISING\RAV\HookWeb.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.3] [C:\PROGRAM FILES\RISING\RAV\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7] [C:\PROGRAM FILES\RISING\RAV\extfile.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 32] [C:\PROGRAM FILES\RISING\RAV\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 8] [C:\PROGRAM FILES\RISING\RAV\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 22] [C:\PROGRAM FILES\RISING\RAV\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 6] [C:\PROGRAM FILES\RISING\RAV\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 96] [C:\PROGRAM FILES\RISING\RAV\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 11] [C:\PROGRAM FILES\RISING\RAV\scanpack.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [C:\PROGRAM FILES\RISING\RAV\revm.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 11] [C:\PROGRAM FILES\RISING\RAV\urutils.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7] [C:\PROGRAM FILES\RISING\RAV\ur000.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 22] [C:\PROGRAM FILES\RISING\RAV\posttrt.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 25] [C:\PROGRAM FILES\RISING\RAV\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [PID: 1356 / SYSTEM][C:\PROGRAM FILES\RISING\RAV\RavStub.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.10] [C:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1504 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1564 / Administrator][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4132] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2500] [PID: 1628 / Administrator][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\browselc.dll] [Microsoft Corporation, 6.00.2600.0000] [C:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 2] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Common Files\Nero\Lib\NeroDigitalExt.dll] [Nero AG, 3, 1, 0, 8] [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80.DLL] [Microsoft Corporation, 8.00.50727.762] [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\MFC80CHS.DLL] [Microsoft Corporation, 8.00.50727.762] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.18] [PID: 1768 / SYSTEM][C:\WINDOWS\03UQU56V9I8X.exe] [, 6, 779, 0, 8] [PID: 1832 / SYSTEM][C:\WINDOWS\system32\NDV4D.exe] [, 6, 779, 0, 8] [PID: 1848 / SYSTEM][C:\WINDOWS\0C4UA4Z45A.exe] [, 6, 779, 0, 8] [PID: 1860 / SYSTEM][C:\WINDOWS\system32\3F139W2D1R6.exe] [, 6, 779, 0, 8] [PID: 1872 / SYSTEM][C:\WINDOWS\0OGP00ZHFCRB.exe] [, 6, 779, 0, 8] [PID: 1892 / SYSTEM][C:\WINDOWS\0OHC14.exe] [, 6, 779, 0, 8] [PID: 1916 / SYSTEM][C:\WINDOWS\0XSMNTLIPG.exe] [, 6, 779, 0, 8] [PID: 1944 / SYSTEM][C:\WINDOWS\10JNOBKN73O.exe] [, 6, 779, 0, 8] [PID: 1956 / SYSTEM][C:\WINDOWS\1DQ9HP.exe] [, 6, 779, 0, 8] [PID: 1968 / SYSTEM][C:\WINDOWS\system32\HG31KWCT2T.exe] [, 6, 779, 0, 8] [PID: 1984 / SYSTEM][C:\WINDOWS\system32\MR5XZ9MGB8K.exe] [, 6, 779, 0, 8] [PID: 1992 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2004 / SYSTEM][C:\WINDOWS\system32\6VOR8U.exe] [, 6, 779, 0, 8] [PID: 2020 / SYSTEM][C:\WINDOWS\2DRQYYU.exe] [, 6, 779, 0, 8] [PID: 192 / SYSTEM][C:\WINDOWS\system32\R0NQ43UUKFIP.exe] [, 6, 779, 0, 8] [PID: 344 / Administrator][C:\WINDOWS\system32\conime.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 384 / SYSTEM][C:\WINDOWS\2YOVI9WF4VTT.exe] [, 6, 779, 0, 8] [PID: 424 / SYSTEM][C:\WINDOWS\2ZXMV31SG.exe] [, 6, 779, 0, 8] [PID: 992 / SYSTEM][C:\WINDOWS\32G23N2.exe] [, 6, 779, 0, 8] [PID: 928 / SYSTEM][C:\WINDOWS\39NMTORARPN.exe] [, 6, 779, 0, 8] [PID: 1376 / SYSTEM][C:\WINDOWS\3H6HWLVY4.exe] [, 6, 779, 0, 8] [PID: 1696 / SYSTEM][C:\WINDOWS\system32\O3HOB6.exe] [, 6, 779, 0, 8] [PID: 1812 / SYSTEM][C:\WINDOWS\3YPPFT456T7O.exe] [, 6, 779, 0, 8] [PID: 908 / SYSTEM][C:\WINDOWS\system32\C4WU13RJF09T.exe] [, 6, 779, 0, 8] [PID: 2076 / SYSTEM][C:\WINDOWS\4HRXBVJT3.exe] [, 6, 779, 0, 8] [PID: 2136 / SYSTEM][C:\WINDOWS\4MVZ0X557.exe] [, 6, 779, 0, 8] [PID: 2204 / SYSTEM][C:\WINDOWS\4Q5RGCSO.exe] [, 6, 779, 0, 8] [PID: 2280 / SYSTEM][C:\WINDOWS\4S7C1BF.exe] [, 6, 779, 0, 8] [PID: 2312 / SYSTEM][C:\WINDOWS\4V2F6.exe] [, 6, 779, 0, 8] [PID: 2380 / SYSTEM][C:\WINDOWS\system32\9N77F.exe] [, 6, 779, 0, 8] [PID: 2400 / SYSTEM][C:\WINDOWS\55IEGO.exe] [, 6, 779, 0, 8] [PID: 2412 / SYSTEM][C:\WINDOWS\5JZ7P5730B4W.exe] [, 6, 779, 0, 8] [PID: 2424 / SYSTEM][C:\WINDOWS\system32\5HZV70FOK3.exe] [, 6, 779, 0, 8] [PID: 2436 / SYSTEM][C:\WINDOWS\system32\SHOJYIJ4I.exe] [, 6, 779, 0, 8] [PID: 2448 / SYSTEM][C:\WINDOWS\6AVRM.exe] [, 6, 779, 0, 8] [PID: 2460 / SYSTEM][C:\WINDOWS\6DSU5YINJ215.exe] [, 6, 779, 0, 8] [PID: 2472 / SYSTEM][C:\WINDOWS\system32\FFIYJCA9AV5.exe] [, 6, 779, 0, 8] [PID: 2484 / SYSTEM][C:\WINDOWS\6HY91FUMNP6J.exe] [, 6, 779, 0, 8] [PID: 2500 / SYSTEM][C:\WINDOWS\system32\A3NRA.exe] [, 6, 779, 0, 8] [PID: 2512 / SYSTEM][C:\WINDOWS\79DZ972O8.exe] [, 6, 779, 0, 8] [PID: 2528 / SYSTEM][C:\WINDOWS\system32\07MTK9LCE4.exe] [, 6, 779, 0, 8] [PID: 2540 / SYSTEM][C:\WINDOWS\7CR825949N.exe] [, 6, 779, 0, 8] [PID: 2552 / SYSTEM][C:\WINDOWS\7IGO497.exe] [, 6, 779, 0, 8] [PID: 2564 / SYSTEM][C:\WINDOWS\7R31X0OGKEE.exe] [, 6, 779, 0, 8] [PID: 2576 / SYSTEM][C:\WINDOWS\system32\SS84S7J.exe] [, 6, 779, 0, 8] [PID: 2588 / SYSTEM][C:\WINDOWS\system32\7AXNOGK5.exe] [, 6, 779, 0, 8] [PID: 2600 / SYSTEM][C:\WINDOWS\system32\XUOAX4T.exe] [, 6, 779, 0, 8] [PID: 2612 / SYSTEM][C:\WINDOWS\811RHLPIE.exe] [, 6, 779, 0, 8] [PID: 2624 / SYSTEM][C:\WINDOWS\system32\G6GK6S281UY.exe] [, 6, 779, 0, 8] [PID: 2636 / SYSTEM][C:\WINDOWS\82J61C740BU.exe] [, 6, 779, 0, 8] [PID: 2648 / SYSTEM][C:\WINDOWS\85824F.exe] [, 6, 779, 0, 8] [PID: 2660 / SYSTEM][C:\WINDOWS\92QR586.exe] [, 6, 779, 0, 8] [PID: 2692 / SYSTEM][C:\WINDOWS\system32\CEXX8AZKRB.exe] [, 6, 779, 0, 8] [PID: 2704 / SYSTEM][C:\WINDOWS\9AGLZ.exe] [, 6, 779, 0, 8] [PID: 2720 / SYSTEM][C:\WINDOWS\system32\6C5J3QS.exe] [, 6, 779, 0, 8] [PID: 2732 / SYSTEM][C:\WINDOWS\system32\W8VSJB4.exe] [, 6, 779, 0, 8] [PID: 2744 / SYSTEM][C:\WINDOWS\9XDC15QSUVR.exe] [, 6, 779, 0, 8] [PID: 2756 / SYSTEM][C:\WINDOWS\A1L9M.exe] [, 6, 779, 0, 8] [PID: 2768 / SYSTEM][C:\WINDOWS\A7WE6G.exe] [, 6, 779, 0, 8] [PID: 2780 / SYSTEM][C:\WINDOWS\system32\N5TDE5.exe] [, 6, 779, 0, 8] [PID: 2792 / SYSTEM][C:\WINDOWS\AF2T8DFWE8WG.exe] [, 6, 779, 0, 8] [PID: 2804 / SYSTEM][C:\WINDOWS\system32\TTHVQ9Z.exe] [, 6, 779, 0, 8] [PID: 2816 / SYSTEM][C:\WINDOWS\AWWEH2VLY8.exe] [, 6, 779, 0, 8] [PID: 2828 / SYSTEM][C:\WINDOWS\B2001AP76.exe] [, 6, 779, 0, 8] [PID: 2840 / SYSTEM][C:\WINDOWS\system32\T59YO7.exe] [, 6, 779, 0, 8] [PID: 2856 / SYSTEM][C:\WINDOWS\BLYIEBPF20.exe] [, 6, 779, 0, 8] [PID: 2868 / SYSTEM][C:\WINDOWS\system32\JHKSZM.exe] [, 6, 779, 0, 8] [PID: 2880 / SYSTEM][C:\WINDOWS\BUXR8I.exe] [, 6, 779, 0, 8] [PID: 2892 / SYSTEM][C:\WINDOWS\system32\drivers\CDAC11BA.EXE] [Macrovision, 4.20.030] [PID: 2920 / SYSTEM][C:\WINDOWS\C3E1V3IV.exe] [, 6, 779, 0, 8] [PID: 2932 / SYSTEM][C:\WINDOWS\C3FJR3B46G.exe] [, 6, 779, 0, 8] [PID: 2944 / SYSTEM][C:\WINDOWS\CNKS6TK0RU5.exe] [, 6, 779, 0, 8] [PID: 2956 / SYSTEM][C:\WINDOWS\system32\ZE2R4DO6L.exe] [, 6, 779, 0, 8] [PID: 2968 / SYSTEM][C:\WINDOWS\CQDFOH7WJ.exe] [, 6, 779, 0, 8] [PID: 2984 / SYSTEM][C:\WINDOWS\system32\LEWPIGHW.exe] [, 6, 779, 0, 8] [PID: 3000 / SYSTEM][C:\WINDOWS\system32\LD3XYJM.exe] [, 6, 779, 0, 8] [PID: 3016 / SYSTEM][C:\WINDOWS\DMW6H.exe] [, 6, 779, 0, 8] [PID: 3028 / SYSTEM][C:\WINDOWS\DNNG3PF2.exe] [, 6, 779, 0, 8] [PID: 3040 / SYSTEM][C:\WINDOWS\DT26VHB.exe] [, 6, 779, 0, 8] [PID: 3052 / SYSTEM][C:\WINDOWS\system32\MRWWP.exe] [, 6, 779, 0, 8] [PID: 3064 / SYSTEM][C:\WINDOWS\EAYGYCD.exe] [, 6, 779, 0, 8] [PID: 3076 / SYSTEM][C:\WINDOWS\system32\S3F6023SRZO.exe] [, 6, 779, 0, 8] [PID: 3088 / SYSTEM][C:\WINDOWS\system32\BSFQYAOEOI.exe] [, 6, 779, 0, 8] [PID: 3100 / SYSTEM][C:\WINDOWS\EJC76RCECSYI.exe] [, 6, 779, 0, 8] [PID: 3112 / SYSTEM][C:\WINDOWS\EQREQWMX.exe] [, 6, 779, 0, 8] [PID: 3128 / SYSTEM][C:\WINDOWS\EY17UK1.exe] [, 6, 779, 0, 8] [PID: 3140 / SYSTEM][C:\WINDOWS\system32\P40VRUAH.exe] [, 6, 779, 0, 8] [PID: 3152 / SYSTEM][C:\WINDOWS\F8GD2WG.exe] [, 6, 779, 0, 8] [PID: 3164 / SYSTEM][C:\WINDOWS\system32\CEEHY1QYNU.exe] [, 6, 779, 0, 8] [PID: 3176 / SYSTEM][C:\WINDOWS\FAEYFLDNA0MC.exe] [, 6, 779, 0, 8] [PID: 3188 / SYSTEM][C:\WINDOWS\system32\71Z1D36JDM.exe] [, 6, 779, 0, 8] [PID: 3200 / SYSTEM][C:\WINDOWS\system32\NC91SLCMVZC.exe] [, 6, 779, 0, 8] [PID: 3212 / SYSTEM][C:\WINDOWS\system32\DF3H9.exe] [, 6, 779, 0, 8] [PID: 3224 / SYSTEM][C:\WINDOWS\system32\RD3ESIQ3CWK9.exe] [, 6, 779, 0, 8] [PID: 3236 / SYSTEM][C:\WINDOWS\system32\WO0DUC3QY.exe] [, 6, 779, 0, 8] [PID: 3248 / SYSTEM][C:\WINDOWS\GRXLOFGLW2U6.exe] [, 6, 779, 0, 8] [PID: 3260 / SYSTEM][C:\WINDOWS\GU2E5RRBX.exe] [, 6, 779, 0, 8] [PID: 3272 / SYSTEM][C:\WINDOWS\H87V2.exe] [, 6, 779, 0, 8] [PID: 3284 / SYSTEM][C:\WINDOWS\HPBRR5BIAR.exe] [, 6, 779, 0, 8] [PID: 3296 / SYSTEM][C:\WINDOWS\system32\B0K3S.exe] [, 6, 779, 0, 8] [PID: 3324 / SYSTEM][C:\WINDOWS\HXXMH8.exe] [, 6, 779, 0, 8] [PID: 3332 / SYSTEM][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 3344 / SYSTEM][C:\WINDOWS\system32\U5KG7ITLFTOT.exe] [, 6, 779, 0, 8] [PID: 3356 / SYSTEM][C:\WINDOWS\system32\K8T3QDKIK1PP.exe] [, 6, 779, 0, 8] [PID: 3368 / SYSTEM][C:\WINDOWS\system32\inetsrv\inetinfo.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 3384 / SYSTEM][C:\WINDOWS\system32\WP3Z2.exe] [, 6, 779, 0, 8] [PID: 3416 / SYSTEM][C:\WINDOWS\IOGGHMTF6.exe] [, 6, 779, 0, 8] [PID: 3428 / SYSTEM][C:\WINDOWS\ISPCYXQ.exe] [, 6, 779, 0, 8] [PID: 3440 / SYSTEM][C:\WINDOWS\system32\CIOZMLO.exe] [, 6, 779, 0, 8] [PID: 3452 / SYSTEM][C:\WINDOWS\IZXAM6OE.exe] [, 6, 779, 0, 8] [PID: 3464 / SYSTEM][C:\WINDOWS\JDJ2U02PV.exe] [, 6, 779, 0, 8] [PID: 3484 / SYSTEM][C:\WINDOWS\system32\27C51SRELL.exe] [, 6, 779, 0, 8] [PID: 3496 / SYSTEM][C:\WINDOWS\system32\DPYVJC30TAVJ.exe] [, 6, 779, 0, 8] [PID: 3508 / SYSTEM][C:\WINDOWS\JLIQ8YFQFO2.exe] [, 6, 779, 0, 8] [PID: 3520 / SYSTEM][C:\WINDOWS\JLJDO.exe] [, 6, 779, 0, 8] [PID: 3532 / SYSTEM][C:\WINDOWS\system32\09G0965CYCF.exe] [, 6, 779, 0, 8] [PID: 3544 / SYSTEM][C:\WINDOWS\JTYJF4VZ4J.exe] [, 6, 779, 0, 8] [PID: 3560 / SYSTEM][C:\WINDOWS\system32\GTJKZ.exe] [, 6, 779, 0, 8] [PID: 3572 / SYSTEM][C:\WINDOWS\KB8ILGTEPM5.exe] [, 6, 779, 0, 8] [PID: 3584 / SYSTEM][C:\WINDOWS\system32\LTS7WK5D.exe] [, 6, 779, 0, 8] [PID: 3596 / SYSTEM][C:\WINDOWS\KDEMRA.exe] [, 6, 779, 0, 8] [PID: 3608 / SYSTEM][C:\WINDOWS\KIHRR.exe] [, 6, 779, 0, 8] [PID: 3616 / SYSTEM][C:\WINDOWS\03UQU56V9I8X.exe] [, 6, 779, 0, 8] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 3628 / SYSTEM][C:\WINDOWS\KOTQJ7E.exe] [, 6, 779, 0, 8] [PID: 3660 / SYSTEM][C:\WINDOWS\system32\9TYLI.exe] [, 6, 779, 0, 8] [PID: 3680 / SYSTEM][C:\WINDOWS\KZLWII.exe] [, 6, 779, 0, 8] [PID: 3692 / SYSTEM][C:\WINDOWS\L1URE1USLG9.exe] [, 6, 779, 0, 8] [PID: 3712 / SYSTEM][C:\WINDOWS\L6PN1BVHIO.exe] [, 6, 779, 0, 8] [PID: 3736 / SYSTEM][C:\WINDOWS\system32\JQJG8IVL.exe] [, 6, 779, 0, 8] [PID: 3752 / SYSTEM][C:\WINDOWS\LWRRTY.exe] [, 6, 779, 0, 8] [PID: 3780 / SYSTEM][C:\WINDOWS\M0KXXBW4E.exe] [, 6, 779, 0, 8] [PID: 3800 / SYSTEM][C:\WINDOWS\MOWG98G30ES.exe] [, 6, 779, 0, 8] [PID: 3816 / SYSTEM][C:\WINDOWS\MYQFFVM3ZNDL.exe] [, 6, 779, 0, 8] [PID: 3828 / SYSTEM][C:\WINDOWS\system32\4YIORAGJI4.exe] [, 6, 779, 0, 8] [PID: 3840 / SYSTEM][C:\WINDOWS\N42Y6.exe] [, 6, 779, 0, 8] [PID: 3864 / SYSTEM][C:\WINDOWS\system32\8RYKAF25.exe] [, 6, 779, 0, 8] [PID: 3888 / SYSTEM][C:\WINDOWS\N9ZYUHIQ.exe] [, 6, 779, 0, 8] [PID: 3908 / SYSTEM][C:\WINDOWS\system32\WJ8SC2ENK31U.exe] [, 6, 779, 0, 8] [PID: 3924 / SYSTEM][C:\WINDOWS\NJW7KAX.exe] [, 6, 779, 0, 8] [PID: 3936 / SYSTEM][C:\WINDOWS\NVBQXYZI1AX.exe] [, 6, 779, 0, 8] [PID: 3948 / SYSTEM][C:\WINDOWS\system32\93549B8C1.exe] [, 6, 779, 0, 8] [PID: 3960 / SYSTEM][C:\WINDOWS\system32\KN0JXCVCI60R.exe] [, 6, 779, 0, 8] [PID: 3972 / SYSTEM][C:\WINDOWS\system32\9NCLTM3JAA3.exe] [, 6, 779, 0, 8] [PID: 3984 / SYSTEM][C:\WINDOWS\OJB9STZPZZ9.exe] [, 6, 779, 0, 8] [PID: 3996 / SYSTEM][C:\WINDOWS\OJC0CKI.exe] [, 6, 779, 0, 8] [PID: 4008 / SYSTEM][C:\WINDOWS\OSB3J8LTB7MR.exe] [, 6, 779, 0, 8] [PID: 4020 / SYSTEM][C:\WINDOWS\OSCPK0.exe] [, 6, 779, 0, 8] [PID: 4036 / SYSTEM][C:\WINDOWS\system32\K8WFBPNISC4.exe] [, 6, 779, 0, 8] [PID: 4048 / SYSTEM][C:\WINDOWS\system32\H8DQAZ80OK7.exe] [, 6, 779, 0, 8] [PID: 4060 / SYSTEM][C:\WINDOWS\PBUVK4EUZ8V.exe] [, 6, 779, 0, 8] [PID: 4080 / SYSTEM][C:\WINDOWS\PVM3YAIAF.exe] [, 6, 779, 0, 8] [PID: 4092 / SYSTEM][C:\WINDOWS\system32\6TWLL1.exe] [, 6, 779, 0, 8] [PID: 336 / SYSTEM][C:\WINDOWS\Q45CI49WV8LX.exe] [, 6, 779, 0, 8] [PID: 372 / SYSTEM][C:\WINDOWS\Q7P2TEXNM40B.exe] [, 6, 779, 0, 8] [PID: 284 / SYSTEM][C:\WINDOWS\Q7UDYVSQ.exe] [, 6, 779, 0, 8] [PID: 1080 / SYSTEM][C:\WINDOWS\system32\P2QMBZATPJ.exe] [, 6, 779, 0, 8] [PID: 4100 / SYSTEM][C:\WINDOWS\QBT9RMTAJ.exe] [, 6, 779, 0, 8] [PID: 4116 / SYSTEM][C:\WINDOWS\system32\TTTSMTN3E1V4.exe] [, 6, 779, 0, 8] [PID: 4128 / SYSTEM][C:\WINDOWS\system32\OGRD8ABM.exe] [, 6, 779, 0, 8] [PID: 4140 / SYSTEM][C:\WINDOWS\system32\9VXO2.exe] [, 6, 779, 0, 8] [PID: 4152 / SYSTEM][C:\WINDOWS\system32\40TZ7MX3JLKV.exe] [, 6, 779, 0, 8] [PID: 4164 / SYSTEM][C:\WINDOWS\QVJ77Z28.exe] [, 6, 779, 0, 8] [PID: 4176 / SYSTEM][C:\WINDOWS\system32\X3H0E.exe] [, 6, 779, 0, 8] [PID: 4188 / SYSTEM][C:\WINDOWS\R6Y0RN3.exe] [, 6, 779, 0, 8] [PID: 4212 / SYSTEM][C:\WINDOWS\system32\JDJ60BMJ.exe] [, 6, 779, 0, 8] [PID: 4232 / SYSTEM][C:\WINDOWS\RE41AMJ.exe] [, 6, 779, 0, 8] [PID: 4248 / SYSTEM][C:\WINDOWS\REQSK.exe] [, 6, 779, 0, 8] [PID: 4260 / SYSTEM][C:\WINDOWS\system32\7MNPIO1RF.exe] [, 6, 779, 0, 8] [PID: 4284 / SYSTEM][C:\WINDOWS\SO48346P.exe] [, 6, 779, 0, 8] [PID: 4300 / SYSTEM][C:\WINDOWS\SQ79FUHZ6.exe] [, 6, 779, 0, 8] [PID: 4320 / SYSTEM][C:\WINDOWS\system32\D5B5KI4NOOM.exe] [, 6, 779, 0, 8] [PID: 4364 / SYSTEM][C:\WINDOWS\system32\HIBF22DFYW.exe] [, 6, 779, 0, 8] [PID: 4412 / SYSTEM][C:\WINDOWS\TOQV6BSVH8.exe] [, 6, 779, 0, 8] [PID: 4428 / SYSTEM][C:\WINDOWS\TY0Z7ERA.exe] [, 6, 779, 0, 8] [PID: 4444 / SYSTEM][C:\WINDOWS\UH9GK0.exe] [, 6, 779, 0, 8] [PID: 4456 / SYSTEM][C:\WINDOWS\ULM9ZR9N9.exe] [, 6, 779, 0, 8] [PID: 4468 / SYSTEM][C:\WINDOWS\system32\TIE88ET5APF.exe] [, 6, 779, 0, 8] [PID: 4480 / SYSTEM][C:\WINDOWS\system32\V98HSRD.exe] [, 6, 779, 0, 8] [PID: 4492 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)] [PID: 4520 / SYSTEM][C:\WINDOWS\UTXYAPO7Y0EW.exe] [, 6, 779, 0, 8] [PID: 4532 / SYSTEM][C:\WINDOWS\UZYBQW.exe] [, 6, 779, 0, 8] [PID: 4544 / SYSTEM][C:\WINDOWS\system32\N1KU2LYICQTV.exe] [, 6, 779, 0, 8] [PID: 4560 / SYSTEM][C:\WINDOWS\system32\OGSQCNL1EGW3.exe] [, 6, 779, 0, 8] [PID: 4572 / SYSTEM][C:\WINDOWS\system32\S4TFCBNO.exe] [, 6, 779, 0, 8] [PID: 4584 / SYSTEM][C:\WINDOWS\VDSRAA.exe] [, 6, 779, 0, 8] [PID: 4596 / SYSTEM][C:\WINDOWS\VHN8MUHQT69J.exe] [, 6, 779, 0, 8] [PID: 4608 / SYSTEM][C:\WINDOWS\VIMFK1TWEJ.exe] [, 6, 779, 0, 8] [PID: 4628 / SYSTEM][C:\WINDOWS\W5LBO6.exe] [, 6, 779, 0, 8] [PID: 4648 / SYSTEM][C:\WINDOWS\W75DHP5AH.exe] [, 6, 779, 0, 8] [PID: 4664 / SYSTEM][C:\WINDOWS\WCCPV.exe] [, 6, 779, 0, 8] [PID: 4692 / SYSTEM][C:\WINDOWS\WLOFTCX.exe] [, 6, 779, 0, 8] [PID: 4716 / SYSTEM][C:\WINDOWS\system32\NIHJK6R893L0.exe] [, 6, 779, 0, 8] [PID: 4732 / SYSTEM][C:\WINDOWS\WQ3X4Y7CDU5O.exe] [, 6, 779, 0, 8] [PID: 4748 / SYSTEM][C:\WINDOWS\WSVYF3D60KQ.exe] [, 6, 779, 0, 8] [PID: 4764 / SYSTEM][C:\WINDOWS\system32\QHC1QHS0AUS.exe] [, 6, 779, 0, 8] [PID: 4776 / SYSTEM][C:\WINDOWS\X2UBCE9PB.exe] [, 6, 779, 0, 8] [PID: 4788 / SYSTEM][C:\WINDOWS\X54KLWY.exe] [, 6, 779, 0, 8] [PID: 4800 / SYSTEM][C:\WINDOWS\XK1UU18GB.exe] [, 6, 779, 0, 8] [PID: 4812 / SYSTEM][C:\WINDOWS\XX0DV6O218.exe] [, 6, 779, 0, 8] [PID: 4824 / SYSTEM][C:\WINDOWS\YA38MF8Z.exe] [, 6, 779, 0, 8] [PID: 4836 / SYSTEM][C:\WINDOWS\system32\TPIY31ECX04.exe] [, 6, 779, 0, 8] [PID: 4848 / SYSTEM][C:\WINDOWS\system32\26YCBIV.exe] [, 6, 779, 0, 8] [PID: 4860 / SYSTEM][C:\WINDOWS\system32\1QPHV4JBF.exe] [, 6, 779, 0, 8] [PID: 4876 / SYSTEM][C:\WINDOWS\YVMPND.exe] [, 6, 779, 0, 8] [PID: 4888 / SYSTEM][C:\WINDOWS\ZGCLJQR.exe] [, 6, 779, 0, 8] [PID: 4904 / SYSTEM][C:\WINDOWS\ZJG75P.exe] [, 6, 779, 0, 8] [PID: 4916 / SYSTEM][C:\WINDOWS\system32\1C9CMPCSL.exe] [, 6, 779, 0, 8] [PID: 5136 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 5760 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2140 / SYSTEM][C:\WINDOWS\system32\wuauclt.exe] [(Verified) Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 5376 / Administrator][C:\Documents and Settings\Administrator\桌面\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210] [PID: 5452 / Administrator][C:\Documents and Settings\Administrator\桌面\sreng2\SRE9b4eb966.EXE] [Smallfrogs Studio, 2.7.0.1210] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Documents and Settings\Administrator\桌面\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 0.0.0.0 182838.com 0.0.0.0 asiafriendfinder.com 0.0.0.0 beautishow.com 0.0.0.0 hothack.home.chinaren.com 0.0.0.0 iplus.allyes.com 0.0.0.0 lingaonbvm.myrice.com 0.0.0.0 love7liao.com 0.0.0.0 lingaonbvm.myrice.com 0.0.0.0 love7liao.com 0.0.0.0 lingaonbvm.myrice.com 0.0.0.0 love7liao.com 219.153.32.215 auto.search.msn.com ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 3616, C:\WINDOWS\03UQU56V9I8X.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 5376, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\SRENG2\SRENGLDR.EXE] ================================== 计划任务 N/A ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]