[CODE] 2008-12-16,22:42:25 System Repair Engineer 2.7.0.1210 Smallfrogs (http://www.KZTechs.com) Windows Vista Home Premium Edition Service Pack 1 (Build 6001) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows] <金山清理专家实时保护><"G:\Kingsoft Antispy\monitor\kastray.exe"> [(Verified)"Zhuhai Kingsoft Software Co.,Ltd"] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <%ProgramFiles%\Windows Defender\MSASCui.exe -hide> [(Verified)Microsoft Windows] [File is missing] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Dritek System Inc.] [Lenovo(beijing) Limited] [Lenovo (Beijing) Limited] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [] [(Verified)Microsoft Corporation] <"C:\Program Files\Lenovo\ShuttleCenter\PCMService.exe"> [CyberLink Corp.] [(Verified)"Xi'an Saming Technology Co., Ltd."] <"C:\Program Files\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Information Technology Corporation Limited] <"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [(Verified)Beijing Rising Information Technology Corporation Limited] <"G:\AVG Anti-Spyware 7.5\avg.exe" /minimized> [GRISOFT s.r.o.] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] <"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"> [(Verified)"Adobe Systems, Incorporated"] <"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.] <"G:\ruising\rstray.exe" /startup> [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows] [(Verified)Microsoft Windows] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}> [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] [(Verified)Microsoft Windows] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] [(Verified)Microsoft Windows] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] [(Verified)Microsoft Windows] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] <%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI> [(Verified)Microsoft Windows] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] [(Verified)Microsoft Windows] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] [(Verified)Microsoft Windows] [HKEY_CURRENT_USER\Control Panel\Desktop] [(Verified)Microsoft Windows] ================================== 启动文件夹 [OneNote 2007 屏幕剪辑程序和启动程序] C:\PROGRA~1\MICROS~2\Office12\ONENOTEM.EXE [Microsoft Corporation]> [QQ游戏启动加速程序] G:\QQGame\Accel.exe [深圳市腾讯计算机系统有限公司]> [OneNote 2007 屏幕剪辑程序和启动程序] C:\PROGRA~1\MICROS~2\Office12\ONENOTEM.EXE [Microsoft Corporation]> [QQ游戏启动加速程序] G:\QQGame\Accel.exe [深圳市腾讯计算机系统有限公司]> ================================== 服务 [AnyComm.DirectRouter / AnyComm.DirectRouter][Running/Auto Start] C:\Program Files\Lenovo\AnyComm\common\router.dll><联想集团有限公司> [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start] [Contrl Center of Storm Media / ccosm][Running/Auto Start] <北京暴风网际科技有限公司> [IGRS / IGRS][Others/Auto Start] <"C:\Program Files\Lenovo\AnyComm\common\IGRS.exe"><联想集团有限公司> [AnyComm Network Monitor and Configuration / IncSvc][Stopped/Manual Start] C:\Program Files\Lenovo\AnyComm\IncSvc.dll> [Kingsoft Basic Service / kaccore][Running/Manual Start] <"C:\Program Files\Kingsoft\KAC\Service\kaccore.exe"> [AnyComm Presentation Space Helper Service / PS_MDP][Stopped/Manual Start] C:\Program Files\Lenovo\AnyComm\PS_MDP.dll> [Rising Proxy Service / RfwProxySrv][Running/Auto Start] [Rising Personal Firewall Service / RfwService][Running/Auto Start] [Cyberlink RichVideo Service(CRVS) / RichVideo][Running/Auto Start] <"C:\Program Files\Cyberlink\Shared files\RichVideo.exe"><> [Rising Process Communication Center / RsCCenter][Running/Auto Start] <"C:\Program Files\Rising\Rav\CCenter.exe"> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"> [Rising Vista Scanner / RsVScanner][Running/Auto Start] [AnyComm Software Update Mini Web Server / SHE.WEB][Stopped/Manual Start] C:\Program Files\Lenovo\AnyComm\common\MiniWeb.dll> [AnyComm Software Update / SheSvc][Running/Auto Start] C:\Program Files\Lenovo\AnyComm\common\SheSvc.dll> ================================== 驱动程序 [Lenovo Virtual Power Controller Driver / ACPIVPC][Running/Manual Start] [adp94xx / adp94xx][Stopped/Disabled] <\SystemRoot\system32\drivers\adp94xx.sys> [adpahci / adpahci][Stopped/Disabled] <\SystemRoot\system32\drivers\adpahci.sys> [adpu160m / adpu160m][Stopped/Disabled] <\SystemRoot\system32\drivers\adpu160m.sys> [adpu320 / adpu320][Stopped/Disabled] <\SystemRoot\system32\drivers\adpu320.sys> [aic78xx / aic78xx][Stopped/Disabled] <\SystemRoot\system32\drivers\djsvs.sys> [aliide / aliide][Stopped/Disabled] <\SystemRoot\system32\drivers\aliide.sys> [Alps Pointing-device Filter Driver / ApfiltrService][Running/Manual Start] [arc / arc][Stopped/Disabled] <\SystemRoot\system32\drivers\arc.sys> [arcsas / arcsas][Stopped/Disabled] <\SystemRoot\system32\drivers\arcsas.sys> [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start] <\??\G:\AVG Anti-Spyware 7.5\guard.sys> [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start] [Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 / b57nd60x][Running/Manual Start] [Broadcom 440x 10/100 Integrated Controller XP Driver / bcm4sbxp][Stopped/Manual Start] [blbdrive / blbdrive][Stopped/Disabled] <\SystemRoot\system32\drivers\blbdrive.sys> [Brother USB Mass-Storage Lower Filter Driver / BrFiltLo][Stopped/Manual Start] <\SystemRoot\system32\drivers\brfiltlo.sys> [Brother USB Mass-Storage Upper Filter Driver / BrFiltUp][Stopped/Manual Start] <\SystemRoot\system32\drivers\brfiltup.sys> [Brother MFC Serial Port Interface Driver (WDM) / Brserid][Stopped/Disabled] <\SystemRoot\system32\drivers\brserid.sys> [Brother WDM Serial driver / BrSerWdm][Stopped/Disabled] <\SystemRoot\system32\drivers\brserwdm.sys> [Brother MFC USB Fax Only Modem / BrUsbMdm][Stopped/Disabled] <\SystemRoot\system32\drivers\brusbmdm.sys> [Brother MFC USB Serial WDM Driver / BrUsbSer][Stopped/Manual Start] <\SystemRoot\system32\drivers\brusbser.sys> [蓝牙音频设备 / btwaudio][Stopped/Manual Start] [Bluetooth AVDT / btwavdt][Stopped/Manual Start] [btwrchid / btwrchid][Stopped/Manual Start] [cmdide / cmdide][Stopped/Disabled] <\SystemRoot\system32\drivers\cmdide.sys> [Dritek Keyboard Filter Driver / DKbFltr][Running/Manual Start] [Dritek General Port I/O / DritekPortIO][Running/System Start] <\??\C:\PROGRA~1\EzButton\DPortIO.sys> [Intel(R) PRO/1000 NDIS 6 Adapter Driver / E1G60][Stopped/Manual Start] [elxstor / elxstor][Stopped/Disabled] <\SystemRoot\system32\drivers\elxstor.sys> [HookNtos / HookNtos][Running/System Start] <\SystemRoot\system32\drivers\HookNtos.sys> [HookReg / HookReg][Running/System Start] <\SystemRoot\system32\drivers\HookReg.sys> [HookSys / HookSys][Running/System Start] <\SystemRoot\system32\drivers\HookSys.sys> [HookUrl / HookUrl][Running/Auto Start] <\??\C:\Program Files\Rising\Rfw\HookUrl.sys> [HpCISSs / HpCISSs][Stopped/Disabled] <\SystemRoot\system32\drivers\hpcisss.sys> [Intel RAID Controller Vista / iaStorV][Stopped/Disabled] <\SystemRoot\system32\drivers\iastorv.sys> [iirsp / iirsp][Stopped/Disabled] <\SystemRoot\system32\drivers\iirsp.sys> [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start] [IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start] [ITEATAPI_Service_Install / iteatapi][Stopped/Disabled] <\SystemRoot\system32\drivers\iteatapi.sys> [ITERAID_Service_Install / iteraid][Stopped/Disabled] <\SystemRoot\system32\drivers\iteraid.sys> [LSI_FC / LSI_FC][Stopped/Disabled] <\SystemRoot\system32\drivers\lsi_fc.sys> [LSI_SAS / LSI_SAS][Stopped/Disabled] <\SystemRoot\system32\drivers\lsi_sas.sys> [LSI_SCSI / LSI_SCSI][Stopped/Disabled] <\SystemRoot\system32\drivers\lsi_scsi.sys> [megasas / megasas][Stopped/Disabled] <\SystemRoot\system32\drivers\megasas.sys> [Mraid35x / Mraid35x][Stopped/Disabled] <\SystemRoot\system32\drivers\mraid35x.sys> [Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit / NETw3v32][Stopped/Manual Start] [Intel(R) Wireless WiFi Link 适配器驱动程序(适用于 Windows Vista 32 位) / NETw4v32][Running/Manual Start] [nfrd960 / nfrd960][Stopped/Disabled] <\SystemRoot\system32\drivers\nfrd960.sys> [N-trig HID Tablet Driver / ntrigdigi][Stopped/Disabled] <\SystemRoot\system32\drivers\ntrigdigi.sys> [nvlddmkm / nvlddmkm][Running/Manual Start] [nvraid / nvraid][Stopped/Disabled] <\SystemRoot\system32\drivers\nvraid.sys> [nvstor / nvstor][Stopped/Disabled] <\SystemRoot\system32\drivers\nvstor.sys> [IPX Traffic Filter Driver / NwlnkFlt][Stopped/Manual Start] [IPX Traffic Forwarder Driver / NwlnkFwd][Stopped/Manual Start] [QLogic Fibre Channel Miniport Driver / ql2300][Stopped/Disabled] <\SystemRoot\system32\drivers\ql2300.sys> [QLogic iSCSI Miniport Driver / ql40xx][Stopped/Disabled] <\SystemRoot\system32\drivers\ql40xx.sys> [R300 / R300][Stopped/Manual Start] [Rising RfwBase Driver / RfwBase][Running/System Start] [rimmptsk / rimmptsk][Running/Auto Start] [rimsptsk / rimsptsk][Running/Auto Start] [Ricoh xD-Picture Card Driver / rismxdp][Running/Auto Start] [RsFwDrv / RsFwDrv][Running/System Start] <\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [SamIo / SamIo][Running/System Start] <\??\C:\Program Files\Lenovo\MultiRecover\SamIo.sys> [Process creation detector. / SamPMon][Running/System Start] <\??\C:\Program Files\Lenovo\MultiRecover\SamPMon.sys><> [SiSRaid2 / SiSRaid2][Stopped/Disabled] <\SystemRoot\system32\drivers\sisraid2.sys> [SiSRaid4 / SiSRaid4][Stopped/Disabled] <\SystemRoot\system32\drivers\sisraid4.sys> [smserial / smserial][Running/Manual Start] [USB2.0 PC Camera (SNP2UVC) / SNP2UVC][Running/Manual Start] <> [Symc8xx / Symc8xx][Stopped/Disabled] <\SystemRoot\system32\drivers\symc8xx.sys> [Sym_hi / Sym_hi][Stopped/Disabled] <\SystemRoot\system32\drivers\sym_hi.sys> [Sym_u3 / Sym_u3][Stopped/Disabled] <\SystemRoot\system32\drivers\sym_u3.sys> [TesDrvPt / TesDrvPt][Stopped/Manual Start] <\??\C:\Windows\system32\TesDrvPt.sys> [TesSafe / TesSafe][Stopped/Manual Start] <\??\C:\Windows\system32\TesSafe.sys> [uliahci / uliahci][Stopped/Disabled] <\SystemRoot\system32\drivers\uliahci.sys> [UlSata / UlSata][Stopped/Disabled] <\SystemRoot\system32\drivers\ulsata.sys> [ulsata2 / ulsata2][Stopped/Disabled] <\SystemRoot\system32\drivers\ulsata2.sys> [viaide / viaide][Stopped/Disabled] <\SystemRoot\system32\drivers\viaide.sys> [vsmraid / vsmraid][Stopped/Disabled] <\SystemRoot\system32\drivers\vsmraid.sys> [Lenovo RMCT KbdMou Service / Wdkbdmou][Running/Boot Start] <\SystemRoot\system32\DRIVERS\Wdkbdmou.sys> [wdmirror / wdmirror][Running/Manual Start] [ArKdv / ArKdv][Running/Disabled] <\??\C:\Windows\system32\drivers\ArKdv.SYS> ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [Adobe PDF Reader Link Helper] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [IEMenuObject Class] {35948964-1BA1-4636-A99D-AAF62AB97268} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [Windows Live Toolbar Helper] {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} [kingsoft browser shield] {D963BE1A-6B35-47DB-B002-49FAE71D85CC} [启动迅雷5] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} [Send to OneNote from Internet Explorer button] {2670000A-7350-4f3c-8081-5663EE0C6C49} [IEBuddyExtControl Class] {3AECD3C1-7085-4731-96DC-47B6CF7EF749} [信息检索(&R)] {92780B25-18CC-41C8-B9BE-3C9C571A8263} [PPLive] {95B3F550-91C4-4627-BCC4-521288C52977} [@btrez.dll,-4015] {CCA281CA-C863-46ef-9331-5C8D4460577F} <, > [Windows Live Toolbar] {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [Adobe PDF Reader Link Helper] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, > [PhotoDraw Class] {2375BEE5-F175-4F1C-81EC-8E4E2E72E2DD} [] {2670000A-7350-4F3C-8081-5663EE0C6C49} <, > [XML DOM Document] {2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A> [IEMenuObject Class] {35948964-1BA1-4636-A99D-AAF62AB97268} [IEBuddyExtControl Class] {3AECD3C1-7085-4731-96DC-47B6CF7EF749} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [] {488A4255-3236-44B3-8F27-FA1AECAA8844} <, > [Shell Name Space] {55136805-B2DE-11D1-B9F2-00A0C98BC547} [XMP Class] {6483F145-A768-4C41-AACC-52D4D7845851} [XDRM] {693571CB-54A3-4E90-9D52-EEAE1334E2D3} [WangWangObj Class] {6E213FC7-DD5A-4115-B7E6-D4C7838C361E} [AxInputControl Class] {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} [MediaComm Class] {7670648D-461B-42AF-BDFE-46D26AF5EFF2} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [AxSubmitControl Class] {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} [] {92780B25-18CC-41C8-B9BE-3C9C571A8263} <, > [] {95B3F550-91C4-4627-BCC4-521288C52977} <, > [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [RMGetLicense Class] {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} [DapCtrl Class] {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} [RDS.DataSpace] {BD96C556-65A3-11D0-983A-00C04FC29E36} <%CommonProgramFiles%\System\msadc\msadco.dll, (Signed) N/A> [Windows Live Toolbar] {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} [Windows Live Toolbar Helper] {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} [] {CCA281CA-C863-46EF-9331-5C8D4460577F} <, > [RealPlayer G2 Control] {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [kingsoft browser shield] {D963BE1A-6B35-47DB-B002-49FAE71D85CC} [Microsoft Silverlight] {DFEAF541-F3E1-4C24-ACAC-99C30715084A} [PasswordEditCtrl Class] {E787FD25-8D7C-4693-AE67-9406BC6E22DF} [XML HTTP Request] {ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A> [Thunder DapPlayer] {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} [XML HTTP] {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A> [&U使用纳米机器人下载并收藏] [&Windows Live Search] [使用迅雷下载] [使用迅雷下载全部链接] [图像发送到 Bluetooth 设备(&B)...] [在Foxmail中添加该RSS频道/频道组] [导出到 Microsoft Excel(&X)] [导出到 Microsoft Office Excel(&X)] [导出当前页到超星阅览器(&A)] [导出选中部分到超星阅览器(&S)] [添加到QQ表情] [页面发送到 Bluetooth 设备(&B)...] ================================== 正在运行的进程 [PID: 448 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)] [PID: 536 / SYSTEM][C:\Windows\system32\csrss.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [PID: 588 / SYSTEM][C:\Windows\system32\wininit.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 600 / SYSTEM][C:\Windows\system32\csrss.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [PID: 632 / SYSTEM][C:\Windows\system32\services.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7] [PID: 644 / SYSTEM][C:\Windows\system32\lsass.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 652 / SYSTEM][C:\Windows\system32\lsm.exe] [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 808 / SYSTEM][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 872 / NETWORK SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 904 / SYSTEM][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.33] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 940 / SYSTEM][C:\Windows\System32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 980 / LOCAL SERVICE][C:\Windows\System32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\Windows\system32\RtkAPO.dll] [Realtek Semiconductor Corp., 11.0.6000.48 built by: WinDDK] [PID: 1016 / SYSTEM][C:\Windows\system32\winlogon.exe] [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)] [PID: 1060 / SYSTEM][C:\Windows\System32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7] [PID: 1076 / SYSTEM][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7] [PID: 1244 / NETWORK SERVICE][C:\Windows\system32\SLsvc.exe] [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)] [PID: 1316 / LOCAL SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1488 / NETWORK SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1520 / SYSTEM][C:\Program Files\Rising\Rfw\rfwsrv.exe] [Beijing Rising Information Technology Co., Ltd., 7.0.0.77] [C:\Windows\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Windows\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\Rfw\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rfw\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rfw\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [C:\Program Files\Rising\Rfw\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [C:\Program Files\Rising\Rfw\RfwRule.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.17] [C:\Program Files\Rising\Rfw\rfwlog.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.16] [C:\Program Files\Rising\Rfw\Rfwdrv.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.50] [C:\Program Files\Rising\Rfw\ijt_ctrl.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.0] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\Program Files\Rising\Rfw\unvdet.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.8] [C:\Program Files\Rising\Rfw\mPorts.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.6] [PID: 1616 / SYSTEM][C:\PROGRAM FILES\RISING\RAV\ravmond.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.80] [C:\PROGRAM FILES\RISING\RAV\BWList.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.5] [C:\Windows\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Windows\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [C:\PROGRAM FILES\RISING\RAV\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [C:\PROGRAM FILES\RISING\RAV\RsLog.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.36] [C:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.29] [C:\PROGRAM FILES\RISING\RAV\Hooksys.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 12] [C:\PROGRAM FILES\RISING\RAV\HookReg.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [C:\PROGRAM FILES\RISING\RAV\HookNtos.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [C:\PROGRAM FILES\RISING\RAV\rswalmon.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 24] [C:\PROGRAM FILES\RISING\RAV\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 41] [C:\PROGRAM FILES\RISING\RAV\refs.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 18] [C:\PROGRAM FILES\RISING\RAV\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\RsStore.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.9] [C:\PROGRAM FILES\RISING\RAV\HookCont.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.6] [C:\Program Files\Rising\Rav\fakescan.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.14] [C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.39] [C:\PROGRAM FILES\RISING\RAV\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27] [C:\PROGRAM FILES\RISING\RAV\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7] [C:\PROGRAM FILES\RISING\RAV\HookWeb.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.3] [C:\PROGRAM FILES\RISING\RAV\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7] [C:\PROGRAM FILES\RISING\RAV\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 22] [C:\PROGRAM FILES\RISING\RAV\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 6] [C:\PROGRAM FILES\RISING\RAV\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 1, 0] [C:\PROGRAM FILES\RISING\RAV\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 8] [C:\PROGRAM FILES\RISING\RAV\scanpack.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [C:\PROGRAM FILES\RISING\RAV\revm.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 11] [C:\PROGRAM FILES\RISING\RAV\urutils.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7] [C:\PROGRAM FILES\RISING\RAV\ur000.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 22] [C:\PROGRAM FILES\RISING\RAV\extfile.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 32] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\PROGRAM FILES\RISING\RAV\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [C:\PROGRAM FILES\RISING\RAV\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 11] [C:\PROGRAM FILES\RISING\RAV\extole.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 13] [C:\PROGRAM FILES\RISING\RAV\scriptci.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 4] [C:\PROGRAM FILES\RISING\RAV\ur001.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [PID: 1656 / SYSTEM][C:\Program Files\Rising\Rfw\rfwProxy.exe] [Beijing Rising Information Technology Co., Ltd., 7.0.0.38] [C:\Windows\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Windows\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\Rfw\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rfw\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rfw\RfwRule.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.17] [C:\Program Files\Rising\Rfw\urlrule.dll] [Beijing Rising Information Technology Co., Ltd., 1.0.0.15] [C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7] [C:\Program Files\Rising\Rfw\MonMid.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.6] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1800 / SYSTEM][C:\Program Files\Rising\Rfw\rfwstub.exe] [Beijing Rising Information Technology Co., Ltd., 7.0.0.12] [C:\Windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Rising\Rfw\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [PID: 200 / SYSTEM][C:\PROGRAM FILES\RISING\RAV\RavStub.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.10] [C:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [PID: 1072 / SYSTEM][C:\Windows\System32\spoolsv.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1276 / LOCAL SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 476 / SYSTEM][C:\Windows\System32\IgrsSvcs.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [c:\program files\lenovo\anycomm\common\router.dll] [联想集团有限公司, 3, 0, 0, 21] [C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7] [c:\program files\lenovo\anycomm\common\shesvc.dll] [Lenovo Group Limited, 3, 0, 21, 1208] [C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Lenovo\AnyComm\common\SheUtil.dll] [Lenovo Group Limited, 3, 0, 19, 1208] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1304 / LOCAL SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1972 / SYSTEM][C:\Program Files\StormII\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 6, 20] [C:\Program Files\StormII\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0] [C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 628 / SYSTEM][C:\Program Files\Lenovo\AnyComm\common\IGRS.exe] [联想集团有限公司, 1.0.1.253] [C:\Program Files\Lenovo\AnyComm\common\framework.dll] [联想集团有限公司, 1.0.1.253] [C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Lenovo\AnyComm\common\BTComPlugin.dll] [联想集团有限公司, 1.0.1.253] [C:\Windows\system32\SerialPortMonitor.dll] [lenovo, 1, 0, 1, 19] [C:\Program Files\Lenovo\AnyComm\common\CorePlugin.dll] [联想集团有限公司, 1.0.1.253] [C:\Program Files\Lenovo\AnyComm\common\ProxyPlugin.dll] [联想集团有限公司, 1.0.1.253] [C:\Program Files\Lenovo\AnyComm\common\ReliablePlugin.dll] [联想集团有限公司, 1.0.1.253] [C:\Program Files\Lenovo\AnyComm\common\SocketPlugin.dll] [联想集团有限公司, 1.0.1.253] [C:\Program Files\Lenovo\AnyComm\common\SvcHostPlugin.dll] [联想集团有限公司, 1.0.1.253] [C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 2096 / NETWORK SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 2120 / SYSTEM][C:\Program Files\Cyberlink\Shared files\RichVideo.exe] [, 2.0.0705 ] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 2180 / SYSTEM][C:\Program Files\Rising\Rav\scannerd.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.24] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 2248 / LOCAL SERVICE][C:\Windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 2336 / SYSTEM][C:\Windows\System32\svchost.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 2424 / SYSTEM][C:\Windows\system32\SearchIndexer.exe] [(Verified) Microsoft Corporation, 7.0.6001.16503 (longhorn(wmbla).080526-2159)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 3340 / lenovo][C:\Windows\system32\taskeng.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\Windows\system32\nvapi.dll] [NVIDIA Corporation, 7.15.11.0134] [C:\Windows\System32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0401] [PID: 3420 / SYSTEM][C:\Windows\system32\taskeng.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 3428 / lenovo][C:\Windows\system32\Dwm.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Windows\system32\nvd3dum.dll] [NVidia Corporation, 7.15.11.0134] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [PID: 3436 / lenovo][C:\Windows\Explorer.EXE] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Lenovo\VeriFace\IcnOvrly.dll] [N/A, ] [C:\Windows\System32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0401] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [C:\Windows\system32\btncopy.dll] [Broadcom Corporation., 6.0.1.4900] [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20] [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 8.0.0.2006102200] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\PROGRA~1\Lenovo\VeriFace\SIMPLE~1.DLL] [, 1, 0, 0, 1] [C:\Windows\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.18] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [G:\NamiRobot\Data\NamipanExt1.dll] [N/A, ] [C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [G:\AVG Anti-Spyware 7.5\context.dll] [GRISOFT s.r.o., 7, 5, 1, 36] [PID: 3464 / lenovo][C:\Program Files\Rising\Rfw\RfwMain.exe] [Beijing Rising Information Technology Co., Ltd., 7.0.1.70] [C:\Windows\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\Rfw\RsGuiLib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 90] [C:\Windows\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\Rfw\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rfw\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rfw\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [C:\Program Files\Rising\Rfw\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [C:\Program Files\Rising\Rfw\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rfw\RfwCtrl.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\Program Files\Rising\Rfw\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [C:\Program Files\Rising\Rfw\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [C:\Program Files\Rising\Rfw\RfwRule.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.17] [PID: 3012 / lenovo][C:\Program Files\Windows Defender\MSASCui.exe] [Microsoft Corporation, 1.1.1600.0] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7] [PID: 3008 / lenovo][C:\Windows\RtHDVCpl.exe] [Realtek Semiconductor, 1, 0, 0, 112] [PID: 3248 / lenovo][C:\Windows\vsnp2uvc.exe] [Sonix, 1, 0, 0, 1] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [PID: 3532 / lenovo][C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe] [Motorola Inc., 6.12.05] [C:\Program Files\Motorola\SMSERIAL\sm56eng.dll] [Motorola Inc., 6.12.05] [C:\Program Files\Motorola\SMSERIAL\sm56fra.dll] [, ] [C:\Program Files\Motorola\SMSERIAL\sm56brz.dll] [, ] [C:\Program Files\Motorola\SMSERIAL\sm56chs.dll] [, ] [C:\Program Files\Motorola\SMSERIAL\sm56cht.dll] [, ] [C:\Program Files\Motorola\SMSERIAL\sm56ger.dll] [, ] [C:\Program Files\Motorola\SMSERIAL\sm56ita.dll] [, ] [C:\Program Files\Motorola\SMSERIAL\sm56jpn.dll] [, ] [C:\Program Files\Motorola\SMSERIAL\sm56esp.dll] [, ] [C:\Program Files\Motorola\SMSERIAL\sm56kor.dll] [, ] [C:\Program Files\Motorola\SMSERIAL\sm56dnk.dll] [, ] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [PID: 3628 / lenovo][C:\Program Files\EzButton\EzButton.EXE] [Dritek System Inc., 1, 0, 5, 804] [C:\Program Files\EzButton\SzUPFUtl.dll] [Dritek System Inc., 1.00] [C:\Program Files\EzButton\OSDUtl.dll] [Dritek System Inc., 1, 1, 0, 306] [C:\Program Files\EzButton\RgnMaker.dll] [Dritek System Inc., 2, 0, 0, 1] [C:\Program Files\EzButton\CDRomUtl.dll] [Dritek System Inc., 1.00] [C:\Program Files\EzButton\MixerUtl.dll] [Dritek System Inc., 1.00] [C:\Program Files\EzButton\ComFnUtl.dll] [Dritek System Inc., 1, 0, 0, 711] [C:\Program Files\EzButton\LgKCUtl.dll] [Dritek System Inc., 2, 0, 2, 1007] [C:\Program Files\EzButton\Wnd2File.dll] [Dritek System Inc., 3.00] [C:\Program Files\EzButton\TkBarUtl.dll] [Dritek System Inc., 1.00] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [C:\Program Files\EzButton\VistaVol.DLL] [Dritek System Inc., 1, 0, 0, 514] [PID: 3456 / lenovo][C:\Program Files\Lenovo\EnergyCut\utilty.exe] [Lenovo(beijing) Limited, 2, 1, 2, 5] [C:\Program Files\Lenovo\EnergyCut\kbdhook.dll] [N/A, ] [PID: 3696 / lenovo][C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe] [Lenovo (Beijing) Limited, 2.1.2.5] [C:\Program Files\Lenovo\EnergyCut\HookLib.dll] [N/A, ] [PID: 3300 / lenovo][C:\Program Files\Apoint2K\Apoint.exe] [Alps Electric Co., Ltd., 7.0.1.260] [C:\Program Files\Apoint2K\Apoint.dll] [Alps Electric Co., Ltd., 5.5.1.380] [C:\Windows\system32\Vxdif.dll] [Alps Electric Co., Ltd., 6.0.3.17] [C:\Program Files\Apoint2K\EzAuto.dll] [Alps Electric Co., Ltd., 5.5.1.91] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [C:\Program Files\Apoint2K\EzLaunch.DLL] [Alps Electric Co., Ltd., 5.5.1.89] [PID: 3780 / lenovo][C:\Program Files\Lenovo\VeriFace\PManage.exe] [, 1, 0, 0, 49] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\DataOper.dll] [, 1, 0, 0, 23] [C:\Program Files\Lenovo\VeriFace\IUrOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [PID: 3944 / lenovo][C:\Program Files\Lenovo\ShuttleCenter\PCMService.exe] [CyberLink Corp., 5, 0, 0, 0] [C:\Program Files\Lenovo\ShuttleCenter\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Lenovo\ShuttleCenter\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Lenovo\ShuttleCenter\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Windows\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Lenovo\ShuttleCenter\Kernel\Common\CLRCEngine3.dll] [CyberLink Corp., 5.00.2115] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [PID: 4056 / SYSTEM][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.24] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [PID: 3688 / lenovo][C:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.01.27] [C:\Windows\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Windows\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 41] [C:\Program Files\Rising\Rav\refs.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 18] [C:\Program Files\Rising\Rav\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27] [C:\Program Files\Rising\Rav\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [C:\Program Files\Rising\Rav\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.29] [C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [C:\Program Files\Rising\Rav\Rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 90] [C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [PID: 1440 / LOCAL SERVICE][C:\Windows\System32\alg.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [PID: 2196 / lenovo][G:\AVG Anti-Spyware 7.5\avg.exe] [GRISOFT s.r.o., 7, 5, 1, 43] [G:\AVG Anti-Spyware 7.5\engine.dll] [GRISOFT s.r.o., 4, 2, 0, 19] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\IcnOvrly.dll] [N/A, ] [C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7] [PID: 4052 / lenovo][C:\Program Files\Windows Media Player\wmpnscfg.exe] [Microsoft Corporation, 11.0.6000.6324 (vista_rtm.061101-2205)] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [PID: 4164 / NETWORK SERVICE][C:\Program Files\Windows Media Player\wmpnetwk.exe] [Microsoft Corporation, 11.0.6000.6324 (vista_rtm.061101-2205)] [PID: 4212 / lenovo][C:\Windows\System32\rundll32.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Windows\system32\NvMcTray.dll] [NVIDIA Corporation, 7.15.11.0134] [C:\Windows\System32\nvapi.dll] [NVIDIA Corporation, 7.15.11.0134] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [PID: 4312 / lenovo][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3510] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [PID: 4368 / lenovo][G:\ruising\RSTray.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.16] [G:\ruising\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 8] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [G:\ruising\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [G:\ruising\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [G:\ruising\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [G:\ruising\ComServ.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.31] [G:\ruising\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [G:\ruising\rscommon.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.1.1] [G:\ruising\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [G:\ruising\pngdll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [G:\ruising\runiep.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.41] [G:\ruising\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.6] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [G:\ruising\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7] [PID: 4396 / lenovo][C:\Program Files\Apoint2K\ApMsgFwd.exe] [Alps Electric Co., Ltd., 7, 0, 0, 5] [PID: 4424 / lenovo][C:\Program Files\Windows Sidebar\sidebar.exe] [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [C:\Windows\system32\icm32.dll] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [PID: 4448 / lenovo][G:\Kingsoft Antispy\monitor\kastray.exe] [Kingsoft Corporation, 2008,11,14,88] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [G:\Kingsoft Antispy\monitor\kaspop.dll] [Kingsoft Corporation, 2008,11,14,93] [PID: 4484 / lenovo][C:\Windows\System32\rundll32.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Windows\System32\NVSVC.DLL] [NVIDIA Corporation, 7.15.11.0134] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [C:\Windows\System32\nvapi.dll] [NVIDIA Corporation, 7.15.11.0134] [PID: 4504 / lenovo][C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE] [Microsoft Corporation, 12.0.6300.5000] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [PID: 4580 / lenovo][C:\Program Files\Apoint2K\Apntex.exe] [Alps Electric Co., Ltd., 7.0.1.26] [C:\Windows\system32\VXDIF.DLL] [Alps Electric Co., Ltd., 6.0.3.17] [C:\Program Files\Apoint2K\Apoint.DLL] [Alps Electric Co., Ltd., 5.5.1.380] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [PID: 4676 / SYSTEM][C:\Program Files\Kingsoft\KAC\Service\kaccore.exe] [Kingsoft Corporation, 2008,12,03,369] [C:\Program Files\Kingsoft\KAC\Service\corehelper.dll] [Kingsoft Corporation, 2008,10,20,303] [C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7] [G:\Kingsoft Antispy\ksa\ksaengine.dll] [Kingsoft Corporation, 2008,11,19,79] [G:\Kingsoft Antispy\ksa\tuotu_p2sp.dll] [Tuotu.com, 1, 0, 0, 2] [PID: 4856 / lenovo][G:\KINGSO~1\monitor\kudiskmon.exe] [Kingsoft Corporation, 2008,11,10,55] [PID: 5612 / lenovo][G:\KINGSO~1\kasmain.exe] [Kingsoft Corporation, 2008,11,18,98] [C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL] [Microsoft Corporation, 8.00.50727.762] [G:\KINGSO~1\kis.dll] [Kingsoft Corporation, 2008,08,12,55] [C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131\MFC80CHS.DLL] [Microsoft Corporation, 8.00.50727.762] [G:\KINGSO~1\KAVDevC.dll] [Kingsoft Corporation, 2008,04,28,112] [G:\KINGSO~1\infoc.dll] [Kingsoft Corporation, 1, 0, 0, 96] [G:\KINGSO~1\KAO\KAOExtend.dll] [, 2008,06,16,525] [G:\KINGSO~1\KAEAutorunEx.DLL] [Kingsoft Corporation, 2008,05,15,287] [G:\KINGSO~1\RICHED20.DLL] [Microsoft Corporation, 5.30.23.1221] [G:\KINGSO~1\UpLive.DLL] [Kingsoft Corporation, 2008,10,30,31] [G:\KINGSO~1\kacc.dll] [Kingsoft Corporation, 1, 0, 0, 1] [C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7] [PID: 3364 / lenovo][C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE] [Microsoft Corporation, 11.0.8237] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [C:\Program Files\Rising\Rav\RsPlugIn.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.20] [C:\Windows\system32\btsendto_office.dll] [Broadcom Corporation., 6.0.1.4900] [C:\Windows\system32\btosif.dll] [Broadcom Corporation., 6.0.1.4900] [C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80.DLL] [Microsoft Corporation, 8.00.50727.762] [C:\Windows\system32\btsendto.dll] [Broadcom Corporation., 6.0.1.4900] [C:\Windows\system32\BtWdSdk.dll] [Broadcom Corporation., 6.0.1.4900] [C:\Windows\system32\btwapi.dll] [Broadcom Corporation., 6.0.1.4900] [C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL] [Microsoft Corporation, 8.00.50727.762] [C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131\MFC80CHS.DLL] [Microsoft Corporation, 8.00.50727.762] [C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL] [Microsoft Corporation, 1.1.6215] [C:\Windows\system32\UNISPIM6.IME] [北京紫光华宇软件股份有限公司, 6.1.0.6223] [C:\Program Files\Microsoft Office\OFFICE11\GdiPlus.DLL] [Microsoft Corporation, 11.0.8230] [PID: 4728 / lenovo][G:\Kingsoft Antispy\ksa\ksamain.exe] [Kingsoft Corporation, 2008,11,17,66] [C:\Program Files\Kingsoft\KAC\Service\kacctl.dll] [Kingsoft Corporation, 2008,10,15,297] [PID: 5316 / SYSTEM][C:\Program Files\Rising\Rav\Smartup.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.46] [C:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 90] [C:\Windows\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Windows\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [PID: 5564 / lenovo][G:\caj\CAJViewer.EXE] [Tongfang Knowledge Network Technology(Beijing) Co., Ltd., 7, 0,608, 2] [G:\caj\mail.dll] [Tsinghua Tongfang Knowledge Network Technology(Beijing) Co., Ltd., 1.0.24.0] [C:\Windows\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [G:\caj\WHelper.dll] [Tongfang Knowledge Network Technology(Beijing) Co., Ltd., 1,0,37,0] [G:\caj\ui.dll] [Tsinghua Tongfang Knowledge Network Technology(Beijing) Co., Ltd., 2, 0,1259, 0] [C:\Program Files\Common Files\TTKN\Bin\ReaderEx.dll] [Tongfang Knowledge Network Technology(Beijing) Co., Ltd., 2, 0,2358, 0] [C:\Program Files\Common Files\TTKN\Bin\sysinfo.dll] [Tsinghua Tongfang Knowledge Network Technology(Beijing) Co., Ltd., 1, 0, 13, 0] [C:\Windows\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\IcnOvrly.dll] [N/A, ] [C:\Program Files\Common Files\TTKN\Bin\ijl15.dll] [Intel Corporation, 1,51,12,44] [PID: 4292 / lenovo][G:\SSREADER36\ssreader.exe] [读天下软件工作室, 3.9.0.610] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [C:\Windows\System32\pdg2.dll] [, 4, 0, 0, 0] [PID: 4556 / lenovo][G:\SSREADER36\SsReader.exe] [读天下软件工作室, 3.9.0.610] [C:\Program Files\Lenovo\VeriFace\HookWnd.dll] [, 1, 0, 0, 158] [C:\Program Files\Lenovo\VeriFace\IGetSkin.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\FaceVerify.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\MainOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\VideoOp.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Image.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\Momo.dll] [N/A, ] [C:\Program Files\Lenovo\VeriFace\facev.dll] [N/A, ] [G:\SSREADER36\HistoryRecord.dll] [N/A, ] [C:\Windows\System32\pdg2.dll] [, 4, 0, 0, 0] [G:\SSREADER36\Anno_ant.dll] [, 3, 7, 2, 3] [G:\SSREADER36\anno_acc.dll] [, 3, 6, 2, 4] [G:\SSREADER36\Anno_cvs.dll] [, ] [G:\SSREADER36\Anno_dm.dll] [, 3, 7, 2, 3] [G:\SSREADER36\Anno_rmt.dll] [N/A, ] [PID: 4264 / SYSTEM][C:\Windows\servicing\TrustedInstaller.exe] [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)] [PID: 4140 / LOCAL SERVICE][C:\Windows\system32\taskeng.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)] [C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 4320 / lenovo][G:\专杀工具\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210] [PID: 4672 / lenovo][G:\专杀工具\sreng2\SREb5dca715.EXE] [Smallfrogs Studio, 2.7.0.1210] [G:\专杀工具\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] ================================== 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["%SystemRoot%\hh.exe" %1] .HLP OK. [%SystemRoot%\winhlp32.exe %1] .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .VBS OK. ["%SystemRoot%\System32\WScript.exe" "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 Rising Net Filter over [MSAFD Tcpip [TCP/IP]] C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Information Technology Co., Ltd., HookSpi Dll) Rising Net Filter over [RSVP TCP 服务提供商] C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Information Technology Co., Ltd., HookSpi Dll) Rising Net Filter C:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Information Technology Co., Ltd., HookSpi Dll) ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost ::1 localhost ================================== 进程特权扫描 N/A ================================== 计划任务 [已启用] \\OGADaily C:\Windows\system32\OGAVerify.exe [已启用] \\OGALogon C:\Windows\system32\OGAVerify.exe [已启用] \\TaskAt900328 G:\qq\QQ.exe [已启用] \\{3EDB93D6-79E9-4CB4-A628-A218CB58ACAC} C:\Windows\system32\pcalua.exe -a G:\setup_ax.exe -d G:\ [已启用] \\{6FECC5E0-A053-4388-A39B-184109E49D17} C:\Windows\system32\pcalua.exe -a G:\eMule0.47c-Installer.exe -d G:\ [已启用] \\{D0E4B08A-5008-432D-A7D3-D038DFCA721E} C:\Windows\system32\pcalua.exe -a F:\[柯林斯COBUILD英语词典].collins3\setup.exe -d F:\[柯林斯COBUILD英语词典].collins3 [已启用] \\{EE8E71BA-38D0-447F-BCD6-DB0D4E7DD03B} C:\Windows\system32\pcalua.exe -a G:\tt\TTraveler.exe -d G:\tt [已启用] \\{FC80ADA6-DDDA-4EE0-81C1-80EDD14E6010} C:\Windows\system32\pcalua.exe -a D:\神龙祖玛\uninst.exe -d D:\神龙祖玛 [已启用] \\查看 Windows Live Toolbar 更新 C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE -a D:\神龙祖玛\uninst.exe -d D:\神龙祖玛 [已禁用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated) N/A [已启用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual) N/A [已启用] \Microsoft\Windows\Bluetooth\UninstallDeviceTask BthUdTask.exe $(Arg0) [已启用] \Microsoft\Windows\CertificateServicesClient\SystemTask N/A [已启用] \Microsoft\Windows\CertificateServicesClient\UserTask N/A [已启用] \Microsoft\Windows\CertificateServicesClient\UserTask-Roam N/A [已启用] \Microsoft\Windows\Customer Experience Improvement Program\Consolidator %SystemRoot%\System32\wsqmcons.exe [已启用] \Microsoft\Windows\Customer Experience Improvement Program\OptinNotification %SystemRoot%\System32\wsqmcons.exe -n 0x1C577FA2B69CAD0 [已启用] \Microsoft\Windows\Defrag\ManualDefrag %windir%\system32\defrag.exe \\?\Volume{1357f82b-f6f6-11dc-958c-806e6f6e6963}\ \\?\Volume{6a1f0e17-f70b-11dc-9f38-001e4ccfed94}\ \\?\Volume{f193a4aa-0ea4-11dd-8428-001e4ccfed94}\ \\?\Volume{f193a4b2-0ea4-11dd-8428-001e4ccfed94}\ [已启用] \Microsoft\Windows\Defrag\ScheduledDefrag %windir%\system32\defrag.exe -c -i [已启用] \Microsoft\Windows\Media Center\ehDRMInit %SystemRoot%\ehome\ehPrivJob.exe /DRMInit [已启用] \Microsoft\Windows\Media Center\mcupdate %SystemRoot%\ehome\mcupdate $(Arg0) -gc [已启用] \Microsoft\Windows\Media Center\OCURActivate %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate [已启用] \Microsoft\Windows\Media Center\OCURDiscovery %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery [已启用] \Microsoft\Windows\Media Center\UpdateRecordPath %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) [已启用] \Microsoft\Windows\MobilePC\HotStart N/A [已启用] \Microsoft\Windows\MobilePC\TMM N/A [已启用] \Microsoft\Windows\MUI\LPRemove %windir%\system32\lpremove.exe [已启用] \Microsoft\Windows\MUI\Mcbuilder C:\Windows\System32\mcbuilder.exe [已启用] \Microsoft\Windows\Multimedia\SystemSoundsService N/A [已启用] \Microsoft\Windows\NetworkAccessProtection\NAPStatus UI N/A [已启用] \Microsoft\Windows\Shell\CrawlStartPages N/A [已禁用] \Microsoft\Windows\SideShow\AutoWake N/A [已启用] \Microsoft\Windows\SideShow\GadgetManager N/A [已禁用] \Microsoft\Windows\SideShow\SessionAgent N/A [已禁用] \Microsoft\Windows\SideShow\SystemDataProviders N/A [已启用] \Microsoft\Windows\SystemRestore\SR %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation [已启用] \Microsoft\Windows\Tcpip\IpAddressConflict1 rundll32 ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem [已启用] \Microsoft\Windows\Tcpip\IpAddressConflict2 rundll32 ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem [已启用] \Microsoft\Windows\UPnP\UPnPHostConfig sc.exe config upnphost start= auto [已启用] \Microsoft\Windows\Windows Error Reporting\QueueReporting %windir%\system32\wermgr.exe -queuereporting [已启用] \Microsoft\Windows\Wired\GatherWiredInfo %windir%\system32\gatherWiredInfo.vbs [已启用] \Microsoft\Windows\Wireless\GatherWirelessInfo %windir%\system32\gatherWirelessInfo.vbs ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]