[CODE] 2008-12-08,00:34:53 System Repair Engineer 2.7.0.1210 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 API HOOK 隐藏进程 启动项目 注册表 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <"C:\Program Files\AutoGuarder2\arvmon.exe" /mini> [任软工作室] <"C:\Program Files\Rising\AntiSpyware\rstray.exe" /startup> [(Verified)Beijing Rising Information Technology Corporation Limited] [ Beijing WatchData System Co., Ltd.] <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Microsoft Windows Publisher] <360Safetray> [(Verified)Qizhi Software (beijing) Co. Ltd] <360Antiarp> [(Verified)Qizhi Software (beijing) Co. Ltd] <"C:\Program Files\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Information Technology Corporation Limited] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce] [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AEB6717E-7E19-11d0-97EE-00C04FD91972}> [(Verified)Microsoft Windows Publisher] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}> [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Publisher] <%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows XP Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows XP Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] <%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSDOS.bat] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntldr.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pagefile.pif] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sos.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sxs.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\test.exe] [N/A] [HKEY_CURRENT_USER\Control Panel\Desktop] [Multidmedia Limited] ================================== 启动文件夹 [瑞星监控中心] C:\PROGRA~1\Rising\Rav\RavMon.exe [Beijing Rising Information Technology Co., Ltd.]> ================================== 服务 [Discuz!EXP-DBS / Discuz!EXP-DBS][Running/Auto Start] <"D:\Program Files\DiscuzEXP\MySQL\bin\mysqld-nt.exe" "--defaults-file=D:\Program Files\DiscuzEXP\MySQL\my.ini" Discuz!EXP-DBS> [Discuz!EXP-WEB / Discuz!EXP-WEB][Running/Auto Start] <"D:\Program Files\DiscuzEXP\Apache2\bin\Apache.exe" -k runservice> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [ltdrv / ltdrv][Running/Auto Start] [Pml Driver HPZ12 / Pml Driver HPZ12][Stopped/Manual Start] [Rising Proxy Service / RfwProxySrv][Running/Auto Start] [Rising Personal Firewall Service / RfwService][Running/Auto Start] [Remote Packet Capture Protocol v.0 (experimental) / rpcapd][Stopped/Manual Start] <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"> [Rising Process Communication Center / RsCCenter][Running/Auto Start] <"C:\Program Files\Rising\Rav\CCenter.exe"> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"> [SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start] ================================== 驱动程序 [360AntiArp / 360AntiArp][Running/System Start] <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心> [HookCont / HookCont][Running/System Start] <\SystemRoot\system32\drivers\HookCont.sys> [HookNtos / HookNtos][Running/System Start] <\SystemRoot\system32\drivers\HookNtos.sys> [HookReg / HookReg][Running/System Start] <\SystemRoot\system32\drivers\HookReg.sys> [HookSys / HookSys][Running/System Start] <\SystemRoot\system32\drivers\HookSys.sys> [HookUrl / HookUrl][Running/Auto Start] <\??\C:\Program Files\Rising\Rfw\HookUrl.sys> [ialm / ialm][Running/Manual Start] [MidiSyn / MidiSyn][Stopped/Manual Start] [NetGroup Packet Filter Driver / NPF][Stopped/Manual Start] [DDK PACKET Protocol / Packet][Running/Manual Start] <360安全中心> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [RapidPort / RapidPort][Running/Auto Start] <\??\C:\WINDOWS\system32\Drivers\CAPLPTN.SYS> [Rising Rfwbase Driver / RfwBase][Running/Auto Start] [RsFwDrv / RsFwDrv][Running/System Start] <\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [Realtek RTL8139/810x/8169/8110 all in one NDIS NT Driver / RTL8023][Running/Manual Start] [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start] [SafeBoxKrnl / SafeBoxKrnl][Running/System Start] <\??\C:\WINDOWS\system32\drivers\SafeBoxKrnl.sys><360安全中心> [Secdrv / Secdrv][Stopped/Manual Start] [senfilt / senfilt][Running/Manual Start] [smwdm / smwdm][Running/Manual Start] [sptd / sptd][Running/Boot Start] <\SystemRoot\System32\Drivers\sptd.sys> [TCP/IP Protocol Driver / Tcpip][Running/System Start] [Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/Manual Start] [Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start] ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [IE2EMBHO Class] {0A0DDBD3-6641-40B9-873F-BBDD26D6C14E} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [启动迅雷5] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} [DAEMON Tools Toolbar] {32099AAC-C132-4136-9E9A-4E364A424E17} [] {00000AAA-A363-466E-BEF5-9BB68697AA7F} <, > [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [] {03507A1A-E0C5-4404-AA26-205385C0892D} <, > [] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, > [IE2EMBHO Class] {0A0DDBD3-6641-40B9-873F-BBDD26D6C14E} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [XMP Class] {6483F145-A768-4C41-AACC-52D4D7845851} [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [MediaComm Class] {7670648D-461B-42AF-BDFE-46D26AF5EFF2} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [DapCtrl Class] {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} [SearchAssistantOC] {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A> [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} [使用电驴下载] [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] [添加到QQ表情] ================================== 正在运行的进程 [PID: 500 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 560 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 584 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 628 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 640 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 792 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 836 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 900 / SYSTEM][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.33] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 916 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 964 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1060 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1176 / SYSTEM][C:\PROGRAM FILES\RISING\RAV\ravmond.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.80] [C:\PROGRAM FILES\RISING\RAV\BWList.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.5] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [C:\PROGRAM FILES\RISING\RAV\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [C:\PROGRAM FILES\RISING\RAV\RsLog.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.36] [C:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.29] [C:\PROGRAM FILES\RISING\RAV\Hooksys.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 12] [C:\PROGRAM FILES\RISING\RAV\HookReg.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [C:\PROGRAM FILES\RISING\RAV\HookNtos.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [C:\PROGRAM FILES\RISING\RAV\rswalmon.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 24] [C:\PROGRAM FILES\RISING\RAV\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 41] [C:\PROGRAM FILES\RISING\RAV\refs.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 18] [C:\PROGRAM FILES\RISING\RAV\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\RsStore.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.9] [C:\PROGRAM FILES\RISING\RAV\HookCont.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [C:\Program Files\Rising\Rav\fakescan.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.14] [C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.39] [C:\PROGRAM FILES\RISING\RAV\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27] [C:\PROGRAM FILES\RISING\RAV\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\PROGRAM FILES\RISING\RAV\HookWeb.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.3] [C:\PROGRAM FILES\RISING\RAV\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7] [C:\PROGRAM FILES\RISING\RAV\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 22] [C:\PROGRAM FILES\RISING\RAV\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 6] [C:\PROGRAM FILES\RISING\RAV\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 99] [C:\PROGRAM FILES\RISING\RAV\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 8] [C:\PROGRAM FILES\RISING\RAV\extfile.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 32] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\PROGRAM FILES\RISING\RAV\scanpack.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [C:\PROGRAM FILES\RISING\RAV\revm.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 11] [C:\PROGRAM FILES\RISING\RAV\urutils.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7] [C:\PROGRAM FILES\RISING\RAV\ur000.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 22] [C:\PROGRAM FILES\RISING\RAV\scriptci.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 4] [C:\PROGRAM FILES\RISING\RAV\ur001.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [C:\PROGRAM FILES\RISING\RAV\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 11] [C:\PROGRAM FILES\RISING\RAV\extole.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 13] [C:\PROGRAM FILES\RISING\RAV\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [PID: 1204 / SYSTEM][c:\program files\rising\rfw\rfwsrv.exe] [Beijing Rising Information Technology Co., Ltd., 7.0.0.77] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [C:\Program Files\Rising\Rfw\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [c:\program files\rising\rfw\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [c:\program files\rising\rfw\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [c:\program files\rising\rfw\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [c:\program files\rising\rfw\RfwRule.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.17] [c:\program files\rising\rfw\rfwlog.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.16] [c:\program files\rising\rfw\Rfwdrv.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.50] [c:\program files\rising\rfw\ijt_ctrl.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.0] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [c:\program files\rising\rfw\unvdet.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.8] [c:\program files\rising\rfw\mPorts.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.6] [PID: 1304 / SYSTEM][c:\program files\rising\rfw\rfwproxy.exe] [Beijing Rising Information Technology Co., Ltd., 7.0.0.37] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [C:\Program Files\Rising\Rfw\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [c:\program files\rising\rfw\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [c:\program files\rising\rfw\RfwRule.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.17] [c:\program files\rising\rfw\urlrule.dll] [Beijing Rising Information Technology Co., Ltd., 1.0.0.15] [c:\program files\rising\rfw\MonMid.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.6] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1492 / SYSTEM][C:\PROGRAM FILES\RISING\RAV\RavStub.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.10] [C:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1732 / Administrator][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.18] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [D:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 120] [D:\Program Files\Thunder\Components\ResWorker\DsBho_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20] [D:\Program Files\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [C:\WINDOWS\system32\msdmo.dll] [, ] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [D:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.34] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.2331] [C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.2331] [PID: 1792 / SYSTEM][c:\program files\rising\rfw\rfwstub.exe] [Beijing Rising Information Technology Co., Ltd., 7.0.0.12] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [c:\program files\rising\rfw\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1896 / Administrator][C:\PROGRAM FILES\RISING\RAV\RavMon.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.01.27] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\PROGRAM FILES\RISING\RAV\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 41] [C:\PROGRAM FILES\RISING\RAV\refs.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 18] [C:\PROGRAM FILES\RISING\RAV\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27] [C:\PROGRAM FILES\RISING\RAV\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [C:\PROGRAM FILES\RISING\RAV\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [C:\PROGRAM FILES\RISING\RAV\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.29] [C:\PROGRAM FILES\RISING\RAV\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [C:\PROGRAM FILES\RISING\RAV\Rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 90] [C:\PROGRAM FILES\RISING\RAV\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 244 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\WINDOWS\system32\CAPMONK.DLL] [CANON INC., 1.00.1.012] [C:\WINDOWS\system32\CAPSMK.DLL] [CANON INC., 1.00.1.012] [C:\WINDOWS\system32\CAPPTMN.DLL] [CANON INC., 1.00.1.012] [C:\WINDOWS\system32\HPBMMON.DLL] [Hewlett-Packard, 10.00.15] [C:\WINDOWS\system32\hppamon0.dll] [HP, 5, 0, 5, 0] [C:\WINDOWS\system32\hpdomon.dll] [Hewlett-Packard, 03.42.00] [C:\WINDOWS\system32\HPBHealr.dll] [N/A, ] [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.1897.0] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\IMFPrint.DLL] [Zenographics, Inc., 5, 54, 330, 0] [C:\WINDOWS\system32\Imf32.dll] [Zenographics, Inc., 5, 60, 1204, 0] [C:\WINDOWS\system32\ZTAG32.dll] [Zenographics, Inc., 5, 60, 1210, 0] [C:\WINDOWS\system32\ZSPOOL.dll] [Zenographics, Inc., 5, 51, 709, 0] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.1897.0] [C:\WINDOWS\system32\CAP1EMN.DLL] [CANON INC., 1.00.1.012] [PID: 460 / Administrator][c:\program files\rising\rfw\RfwMain.exe] [Beijing Rising Information Technology Co., Ltd., 7.0.1.70] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [c:\program files\rising\rfw\RsGuiLib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 90] [C:\Program Files\Rising\Rfw\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [c:\program files\rising\rfw\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [c:\program files\rising\rfw\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [c:\program files\rising\rfw\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [c:\program files\rising\rfw\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [c:\program files\rising\rfw\RfwCtrl.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [c:\program files\rising\rfw\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [c:\program files\rising\rfw\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [c:\program files\rising\rfw\RfwRule.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.17] [PID: 1516 / SYSTEM][D:\Program Files\DiscuzEXP\MySQL\bin\mysqld-nt.exe] [N/A, ] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [PID: 1552 / SYSTEM][D:\Program Files\DiscuzEXP\Apache2\bin\Apache.exe] [Apache Software Foundation, 2.0.55] [D:\Program Files\DiscuzEXP\Apache2\bin\libapr.dll] [Apache Software Foundation, 0.9.7] [D:\Program Files\DiscuzEXP\Apache2\bin\libaprutil.dll] [Apache Software Foundation, 0.9.7] [D:\Program Files\DiscuzEXP\Apache2\bin\libapriconv.dll] [Apache Software Foundation, 0.9.7] [D:\Program Files\DiscuzEXP\Apache2\bin\libhttpd.dll] [Apache Software Foundation, 2.0.55] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_access.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_actions.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_alias.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_asis.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_auth.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_autoindex.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_cgi.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_dir.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_env.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_expires.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_headers.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_include.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_info.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_isapi.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_log_config.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_mime.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_negotiation.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_setenvif.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_rewrite.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\PHP\php4apache2.dll] [N/A, ] [D:\Program Files\DiscuzEXP\PHP\php4ts.dll] [The PHP Group, 4.4.2.2] [D:\Program Files\DiscuzEXP\Zend\lib\ZendExtensionManager.dll] [N/A, ] [D:\Program Files\DiscuzEXP\PHP\extensions\php_mbstring.dll] [N/A, ] [D:\Program Files\DiscuzEXP\PHP\extensions\php_gd2.dll] [N/A, ] [D:\Program Files\DiscuzEXP\PHP\extensions\php_sockets.dll] [N/A, ] [D:\Program Files\DiscuzEXP\PHP\extensions\php_w32api.dll] [N/A, ] [D:\Program Files\DiscuzEXP\Zend\lib\Optimizer-2.6.2\php-4.4.x\ZendOptimizer.dll] [N/A, ] [PID: 1676 / SYSTEM][c:\ltdrv\srvany.exe] [N/A, ] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [PID: 2060 / SYSTEM][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] [Analog Devices, Inc., 3, 2, 6, 0] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [PID: 2348 / SYSTEM][D:\Program Files\DiscuzEXP\Apache2\bin\Apache.exe] [Apache Software Foundation, 2.0.55] [D:\Program Files\DiscuzEXP\Apache2\bin\libapr.dll] [Apache Software Foundation, 0.9.7] [D:\Program Files\DiscuzEXP\Apache2\bin\libaprutil.dll] [Apache Software Foundation, 0.9.7] [D:\Program Files\DiscuzEXP\Apache2\bin\libapriconv.dll] [Apache Software Foundation, 0.9.7] [D:\Program Files\DiscuzEXP\Apache2\bin\libhttpd.dll] [Apache Software Foundation, 2.0.55] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_access.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_actions.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_alias.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_asis.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_auth.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_autoindex.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_cgi.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_dir.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_env.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_expires.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_headers.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_include.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_info.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_isapi.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_log_config.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_mime.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_negotiation.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_setenvif.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\Apache2\modules\mod_rewrite.so] [Apache Software Foundation, 2.0.52] [D:\Program Files\DiscuzEXP\PHP\php4apache2.dll] [N/A, ] [D:\Program Files\DiscuzEXP\PHP\php4ts.dll] [The PHP Group, 4.4.2.2] [D:\Program Files\DiscuzEXP\Zend\lib\ZendExtensionManager.dll] [N/A, ] [D:\Program Files\DiscuzEXP\PHP\extensions\php_mbstring.dll] [N/A, ] [D:\Program Files\DiscuzEXP\PHP\extensions\php_gd2.dll] [N/A, ] [D:\Program Files\DiscuzEXP\PHP\extensions\php_sockets.dll] [N/A, ] [D:\Program Files\DiscuzEXP\PHP\extensions\php_w32api.dll] [N/A, ] [D:\Program Files\DiscuzEXP\Zend\lib\Optimizer-2.6.2\php-4.4.x\ZendOptimizer.dll] [N/A, ] [PID: 3476 / SYSTEM][C:\WINDOWS\system32\CAPRPCSK.EXE] [CANON INC., 1.00.1.012] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 3580 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [PID: 3600 / SYSTEM][C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE] [CANON INC., 1.00.1.012] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP1PMN.DLL] [CANON INC., 1.00.1.012] [C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPSMK.DLL] [CANON INC., 1.00.1.012] [PID: 3628 / Administrator][C:\Program Files\AutoGuarder2\arvmon.exe] [任软工作室, 2.3.3.180] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\Program Files\AutoGuarder2\Vdata.dll] [任软工作室, 2, 3, 0, 124] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [PID: 3644 / Administrator][C:\Program Files\Rising\AntiSpyware\rstray.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.16] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [C:\Program Files\Rising\AntiSpyware\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 8] [C:\Program Files\Rising\AntiSpyware\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [C:\Program Files\Rising\AntiSpyware\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\AntiSpyware\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Rising\AntiSpyware\ComServ.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.31] [C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\Program Files\Rising\AntiSpyware\rscommon.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.1.1] [C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [C:\Program Files\Rising\AntiSpyware\pngdll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [C:\Program Files\Rising\AntiSpyware\runiep.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.41] [C:\Program Files\Rising\AntiSpyware\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.6] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\AntiSpyware\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.18] [PID: 3652 / Administrator][C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\wdcertm_ccb.exe] [ Beijing WatchData System Co., Ltd., 3, 2, 0, 0] [C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\TokenMgr.dll] [ Beijing WatchData System Co., Ltd., 3, 6, 3, 2] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\WDAlg.DLL] [ Beijing WatchData System C0., Ltd., 3, 5, 12, 20] [C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\wdudk.dll] [北京握奇数据系统有限公司, 7, 0, 3, 1] [C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\wdcrwv.dll] [Watchdata System Co., Ltd., 5, 0, 3, 0] [C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\wdpkcs.dll] [ Beijing WatchData System Co., Ltd., 3, 6, 2, 15] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 3712 / Administrator][C:\Program Files\360safe\antiarp\AntiArp.exe] [360安全中心, 2, 0, 0, 1008] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [PID: 3728 / Administrator][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.24] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [PID: 2340 / Administrator][C:\WINDOWS\system32\conime.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [PID: 408 / Administrator][C:\Program Files\Shiqiang\wnwb\wnwb.exe] [深圳世强软件开发部 www.wn51.com , 2007, 10, 24, 1] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [PID: 1980 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [D:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.34] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [D:\Program Files\eMule\modules\IE2EM.dll] [VeryCD.com, 1.0.0.1] [D:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 120] [D:\Program Files\Thunder\Components\ResWorker\DsBho_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20] [D:\Program Files\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [C:\WINDOWS\system32\urlFilter.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 15] [C:\Program Files\Rising\AntiSpyware\UrlRule.dll] [Beijing Rising Information Technology Co., Ltd., 1.0.0.15] [C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx] [Adobe Systems, Inc., 10,0,12,36] [PID: 784 / Administrator][C:\WINDOWS\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 6088 / Administrator][C:\WINDOWS\SREc0047c54.EXE] [Smallfrogs Studio, 2.7.0.1210] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [PID: 5516 / Administrator][C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE] [Microsoft Corporation, 11.0.5612] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [c:\program files\rising\rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [c:\program files\rising\rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [C:\Program Files\Microsoft Office\OFFICE11\GdiPlus.DLL] [Microsoft Corporation, 6.0.3260.0] [C:\Program Files\Common Files\Microsoft Shared\office11\riched20.dll] [Microsoft Corporation, 5.50.30.2002] [C:\Program Files\Rising\Rav\RsPlugIn.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.20] [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CAP1UIK.DLL] [Canon Inc., 1.00.1.012] [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CAP1K.DLL] [Canon Inc., 0.3.0.0] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS Error. [] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 127.0.0.1 c0mo.com 127.0.0.1 gxgxy.net 127.0.0.1 444.gmwo07.com 127.0.0.1 333.gmwo07.com 127.0.0.1 222.gmwo07.com 127.0.0.1 111.gmwo07.com 127.0.0.1 haha.yaoyao09.com 127.0.0.1 www.noseqing.cn 127.0.0.1 fg.pvs360.com 127.0.0.1 cw.pvs360.com 127.0.0.1 ta.pvs360.com 127.0.0.1 dl.pvs360.com 127.0.0.1 ok.sl8cjs.cn 127.0.0.1 nc.mskess.com 127.0.0.1 idc.windowsupdeta.cn 127.0.0.1 pvs360.com 127.0.0.1 sl8cjs.cn 127.0.0.1 windowsupdeta.cn 127.0.0.1 up.22x44.com 127.0.0.1 my.531jx.cn 127.0.0.1 nx.51ylb.cn 127.0.0.1 llboss.com 127.0.0.1 down.malasc.cn 127.0.0.1 d2.llsging.com 127.0.0.1 171817.171817.com 127.0.0.1 wg.47255.com 127.0.0.1 www.tomwg.com 127.0.0.1 tp.shpzhan.cn 127.0.0.1 1.joppnqq.com 127.0.0.1 xx.exiao01.com 127.0.0.1 www.22aaa.com 127.0.0.1 ilove.com 127.0.0.1 xxx.mmma.biz 127.0.0.1 www.868wg.com 127.0.0.1 2.joppnqq.com 127.0.0.1 1.jopanqc.com 127.0.0.1 yu.8s7.net 127.0.0.1 1.jopmmqq.com 127.0.0.1 cao.kv8.info 127.0.0.1 xtx.kv8.info 127.0.0.1 new.749571.com 127.0.0.1 xxx.vh7.biz 127.0.0.1 1.jopenkk.com 127.0.0.1 d.93se.com 127.0.0.1 3.joppnqq.com 127.0.0.1 xxx.j41m.com 127.0.0.1 1.jopenqc.com 127.0.0.1 xxx.m111.biz 127.0.0.1 down.18dd.net 127.0.0.1 www.333292.com 127.0.0.1 qqq.hao1658.com 127.0.0.1 qqq.dzydhx.com 127.0.0.1 www.exiao01.com 127.0.0.1 www.cike007.cn ================================== 进程特权扫描 特殊特权被允许: SeDebugPrivilege [PID = 3628, C:\PROGRAM FILES\AUTOGUARDER2\ARVMON.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 3652, C:\WINDOWS\SYSTEM32\WATCHDATA\WATCHDATA CCB CSP V3.2\WDCERTM_CCB.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3652, C:\WINDOWS\SYSTEM32\WATCHDATA\WATCHDATA CCB CSP V3.2\WDCERTM_CCB.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 784, C:\WINDOWS\SRENGLDR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 784, C:\WINDOWS\SRENGLDR.EXE] ================================== 计划任务 N/A ================================== API HOOK 入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: 0x00EA1FFD) 入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: 0x00EA20E5) ================================== 隐藏进程 N/A ================================== [/CODE]