[CODE] 2009-01-12,14:34:57 System Repair Engineer 2.7.0.1210 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AEB6717E-7E19-11d0-97EE-00C04FD91972}> [(Verified)Microsoft Windows Component Publisher] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}> [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy] <%SystemRoot%\System32\dimsntfy.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <浏览器自定义组件> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] <%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] [Microsoft Corporation] [HKEY_CURRENT_USER\Control Panel\Desktop] [] ================================== 启动文件夹 N/A ================================== 服务 [2WMCMEX0G / 3WLQLLI][Stopped/Auto Start] <(File is missing)> [A64GVZ6UN5L / A64GVZ6UN5L][Stopped/Auto Start] [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Stopped/Auto Start] <><(File is missing)> [Background Intelligent Transfer Service / BITS][Stopped/Auto Start] C:\WINDOWS\system32\RxmytrC.dll> [Contrl Center of Storm Media / ccosm][Running/Auto Start] <北京暴风网际科技有限公司> [ETPQVKWY / DROLP5][Stopped/Auto Start] [FLEXlm License Manager / FLEXlm License Manager][Stopped/Auto Start] <"D:\Program Files\Rational\common\lmgrd.exe"> [FUK99R2F / FUK99R2F][Stopped/Auto Start] <(File is missing)> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [Iprip / Ias][Stopped/Auto Start] C:\WINDOWS\system32\pluginn.dll> [IEED93Q9 / IEED93Q9][Stopped/Auto Start] <(File is missing)> [JN5K6 / JN5K6][Stopped/Auto Start] <(File is missing)> [jnfijt / jnfijt][Stopped/Auto Start] %SystemRoot%\System32\pplvbn.dll> [Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start] <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><> [Rational ClearQuest Mail Service / MailService][Stopped/Auto Start] <"D:\Program Files\Rational\ClearQuest\mailservice.exe"> [MD92ZO / MD92ZO][Stopped/Auto Start] [msarcomts svcRsrvi / msarcomts svcRsrvi tedxij][Stopped/Auto Start] [MSSQLSERVER / MSSQLSERVER][Running/Manual Start] [NuTCRACKERService / NuTCRACKERService][Running/Auto Start] [NVIDIA Display Driver Service / NVSvc][Stopped/Auto Start] <(File is missing)> [N3J73IRV323 / O1KE2QAMN][Stopped/Auto Start] [OracleMTSRecoveryService / OracleMTSRecoveryService][Running/Auto Start] [OracleOraHome92ClientCache / OracleOraHome92ClientCache][Stopped/Manual Start] [OW3JILVR / OW3JILVR][Stopped/Auto Start] <(File is missing)> [PFFG8 / PFFG8][Stopped/Auto Start] <(File is missing)> [ProxyServer Service / ProxyServerService][Stopped/Manual Start] <"D:\Program Files\Rational\Rational Test\rtpxsr.exe"> [Rational Test Agent Service / RationalTestAgentService][Stopped/Manual Start] <"D:\Program Files\Rational\Rational Test\rtpsvc.exe"> [Rav Process Communication Center / RavCCenter][Stopped/Auto Start] [Rising RavTask Manager / RavTask][Running/Auto Start] <"C:\Program Files\Rising\Rav\RavTask.exe" RavTask> [Rfw Process Communication Center / RfwCCenter][Stopped/Auto Start] [Rising Personal Firewall Service / RfwService][Stopped/Auto Start] [Rising RfwTask Manager / RfwTask][Running/Auto Start] <"C:\Program Files\Rising\Rfw\RavTask.exe" RfwTask> [Cyberlink RichVideo Service(CRVS) / RichVideo][Running/Auto Start] <"C:\Program Files\Cyberlink\Shared files\RichVideo.exe"><> [Remote Packet Capture Protocol v.0 (experimental) / rpcapd][Stopped/Manual Start] <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] [Rising Scan Service / RsScanSrv][Stopped/Auto Start] [R3WLYSPRMF / S3UZX1AR][Stopped/Auto Start] <(File is missing)> [ServiceLayer / ServiceLayer][Stopped/Manual Start] <"C:\Program Files\PC Connectivity Solution\ServiceLayer.exe"> [SQLSERVERAGENT / SQLSERVERAGENT][Running/Auto Start] [Apache Tomcat / Tomcat5][Stopped/Manual Start] [UHJRYGFS / UHJRYGFS][Stopped/Auto Start] <(File is missing)> [VVY7P8Q3 / VVY7P8Q3][Stopped/Auto Start] <(File is missing)> [系统音频驱动文件 / Windows Audio Driver][Stopped/Auto Start] C:\WINDOWS\system32\Audio's.dll> [Automatic Uppdates / wuauservs][Stopped/Auto Start] <><(File is missing)> [W70WK / X51JYUT4XIJ][Stopped/Auto Start] <(File is missing)> [YD6SXEV / YD6SXEV][Stopped/Auto Start] <(File is missing)> [DRE3KYYV2EPC / CRDAG6JLXN][Stopped/Auto Start] [KMQ9ORS6A6 / KMQ9ORS6A6][Stopped/Auto Start] ================================== 驱动程序 [360AntiArp / 360AntiArp][Running/System Start] <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心> [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start] [AliIde / AliIde][Running/Boot Start] <\SystemRoot\System32\DRIVERS\aliide.sys> [AMD K8 Processor Driver / AmdK8][Stopped/Manual Start] [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Stopped/System Start] <\??\C:\Downloads\AVG+Anti-Spyware\AVG Anti-Spyware\guard.sys> [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start] [CmdIde / CmdIde][Running/Boot Start] <\SystemRoot\System32\DRIVERS\cmdide.sys> [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start] [FTCkillfile / FTCkillfile][Stopped/Manual Start] <风云谷科技> [FTCProtect / FTCProtect][Stopped/Manual Start] <风云谷科技> [Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start] [hookcont / hookcont][Running/System Start] [hooksys / hooksys][Running/System Start] [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start] [KAVSafe / KAVSafe][Stopped/Auto Start] <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys> [Nokia USB Phone Parent / nmwcd][Stopped/Manual Start] [Nokia USB Generic / nmwcdc][Stopped/Manual Start] [Nokia USB Modem / nmwcdcm][Stopped/Manual Start] [npkcrypt / npkcrypt][Stopped/Auto Start] <\??\C:\Program Files\QQ2006\npkcrypt.sys> [nv / nv][Running/Manual Start] [DDK PACKET Protocol / Packet][Stopped/Manual Start] <360安全中心> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [Rising RfwBase Driver / RfwBase9][Running/Manual Start] [rfwtdi / rfwtdi][Running/Auto Start] <\??\C:\Program Files\Rising\Rfw\rfwtdi.sys> [RsAntiSpyware / RsAntiSpyware][Running/Boot Start] <\SystemRoot\system32\drivers\RsBoot.sys> [rsfwdrv / rsfwdrv][Running/System Start] <\??\C:\Program Files\Rising\Rfw\rsfwdrv.sys> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver / RTLE8023xp][Running/Manual Start] [SafeBoxKrnl / SafeBoxKrnl][Running/System Start] <\??\C:\WINDOWS\system32\drivers\SafeBoxKrnl.sys><360安全中心> [Secdrv / Secdrv][Stopped/Manual Start] [TCP/IP Protocol Driver / Tcpip][Running/System Start] [VMware Pointing Device / vmmouse][Running/Manual Start] [{95808DC4-FA4A-4C74-92FE-5B863F82066B} / {95808DC4-FA4A-4C74-92FE-5B863F82066B}][Running/Auto Start] <\??\d:\Program Files\CyberLink\PowerDVD\000.fcl> ================================== 浏览器加载项 [HelperObject Class] {00C6482D-C502-44C8-8409-FCE54AD9C208} [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [Adobe PDF Reader Link Helper] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [@shdoclc.dll,-866] {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, > [HelperObject Class] {00C6482D-C502-44C8-8409-FCE54AD9C208} [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [] {03507A1A-E0C5-4404-AA26-205385C0892D} <, > [ActiveMovieControl Object] {05589FA1-C356-11CE-BF01-00AA0055595A} [Adobe PDF Reader Link Helper] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [Web Browser Applet Control] {08B0E5C0-4FCB-11CF-AAA5-00401C608501} [Windows Media Player] {22D6F312-B0F6-11D0-94AB-0080C74C7E95} [DHTML Edit Control Safe for Scripting for IE5] {2D360201-FFF5-11D1-8D03-00A0C959BC0A} [XML Document] {48123BC4-99D9-11D1-A6B3-00C04FD91555} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [EditCtrl Class] {488A4255-3236-44B3-8F27-FA1AECAA8844} [Microsoft Terminal Services Client Control (redist)] {4eb89ff4-7f78-4a0f-8b8d-2bf02e94e4b2} <%systemroot%\system32\mstscax.dll, (Signed) N/A> [Microsoft Terminal Services Client Control (redist)] {4EDCB26C-D24C-4e72-AF07-B576699AC0DE} <%systemroot%\system32\mstscax.dll, (Signed) N/A> [StormPlayer Object] {6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB} [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [Microsoft Terminal Services Client Control (redist)] {7390f3d8-0439-4c05-91e3-cf5cb290c3d0} <%systemroot%\system32\mstscax.dll, (Signed) N/A> [Microsoft Terminal Services Client Control (redist)] {7584c670-2274-4efb-b00b-d6aaba6d3850} <%systemroot%\system32\mstscax.dll, (Signed) N/A> [MediaComm Class] {7670648D-461B-42AF-BDFE-46D26AF5EFF2} [Microsoft Web 浏览器] {8856F961-340A-11D0-A96B-00C04FD705A2} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [Microsoft Terminal Services Client Control (redist)] {9059f30f-4eb1-4bd2-9fdc-36f43a218f4a} <%systemroot%\system32\mstscax.dll, (Signed) N/A> [Microsoft Scriptlet Component] {AE24FDAE-03C6-11D1-8B76-0080C744F389} [SearchAssistantOC] {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A> [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [RDS.DataSpace] {BD96C556-65A3-11D0-983A-00C04FC29E36} [] {C95FE080-8F5D-11D2-A20B-00AA003C157A} <, > [AUDIO__MP3 Moniker Class] {CD3AFA76-B84F-48F0-9393-7EDC34128127} [RealPlayer G2 Control] {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [AgControl Class] {DFEAF541-F3E1-4C24-ACAC-99C30715084A} [PlayerCtrl Class] {E05BC2A3-9A46-4A32-80C9-023A473F5B23} [Thunder DapPlayer] {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} [] {FB5F1910-F110-11D2-BB9E-00C04F795683} <, > [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] [添加到QQ表情] [用比特精灵下载(&B)] ================================== 正在运行的进程 [PID: 1236 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 1296 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 1320 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [PID: 1364 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 1376 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [PID: 1540 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 1620 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 1744 / SYSTEM][C:\Program Files\Rising\Rav\CCENTER.EXE] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [C:\Program Files\Rising\Rav\combase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [C:\Program Files\Rising\Rav\cnt09.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 37] [C:\Program Files\Rising\Rav\cnt08.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7] [PID: 1764 / SYSTEM][C:\Program Files\Rising\Rfw\CCENTER.EXE] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [C:\Program Files\Rising\Rfw\combase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [C:\Program Files\Rising\Rfw\cnt09.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 37] [PID: 1772 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [d:\oracle\ora92\bin\oci.dll] [Oracle Corporation, 9.2.0.1.0] [PID: 1812 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 160 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 188 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 248 / SYSTEM][C:\Program Files\Rising\Rfw\rfwsrv.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [C:\Program Files\Rising\Rfw\combase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Rising\Rfw\MonBase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5] [C:\Program Files\Rising\Rfw\MonComm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [C:\Program Files\Rising\Rfw\rfwlog.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 9] [C:\Program Files\Rising\Rfw\rfwrule.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.25] [C:\Program Files\Rising\Rfw\rfwsrv.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.75] [C:\Program Files\Rising\Rfw\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\Program Files\Rising\Rfw\mPorts.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.0] [C:\Program Files\Rising\Rfw\rfwdrvc.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.3] [C:\Program Files\Rising\Rfw\Rfwdrv.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.5] [C:\Program Files\Rising\Rfw\rsnetsvr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 13] [C:\Program Files\Rising\Rfw\urlrule.dll] [Beijing Rising Information Technology Co., Ltd., 1.0.0.18] [C:\Program Files\Rising\Rfw\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [C:\Program Files\Rising\Rfw\refs.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [C:\Program Files\Rising\Rfw\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [C:\Program Files\Rising\Rfw\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [C:\Program Files\Rising\Rfw\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [C:\Program Files\Rising\Rfw\rfwproxy.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.24] [C:\Program Files\Rising\Rfw\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [C:\Program Files\Rising\Rfw\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.13] [C:\Program Files\Rising\Rfw\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [C:\Program Files\Rising\Rfw\urllib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [PID: 276 / SYSTEM][C:\Program Files\Rising\Rav\RavMonD.exe] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [C:\Program Files\Rising\Rav\combase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Rising\Rav\moncomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [C:\Program Files\Rising\Rav\MonBase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5] [C:\Program Files\Rising\Rav\Rslog.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.32] [C:\Program Files\Rising\Rav\mondrv.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7] [C:\Program Files\Rising\Rav\defmon.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 29] [C:\Program Files\Rising\Rav\moncom08.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [C:\Program Files\Rising\Rav\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 9] [C:\Program Files\Rising\Rav\FileMon.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 21] [C:\Program Files\Rising\Rav\MailMon.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 23] [C:\Program Files\Rising\Rav\HookWeb.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [C:\Program Files\Rising\Rav\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [C:\Program Files\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.13] [C:\Program Files\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [C:\Program Files\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\Program Files\Rising\Rav\Hooksys.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 18] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\HookCont.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 11] [C:\Program Files\Rising\Rav\rsnetsvr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 13] [C:\Program Files\Rising\Rav\BACore.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 17] [C:\Program Files\Rising\Rav\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [C:\Program Files\Rising\Rav\refs.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [C:\Program Files\Rising\Rav\RSStore.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 9] [C:\Program Files\Rising\Rav\ScanAdd.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.14] [C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.32] [C:\Program Files\Rising\Rav\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [C:\Program Files\Rising\Rav\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [C:\Program Files\Rising\Rav\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [C:\Program Files\Rising\Rav\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [C:\Program Files\Rising\Rav\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [C:\Program Files\Rising\Rav\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [C:\Program Files\Rising\Rav\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 17] [C:\Program Files\Rising\Rav\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [C:\Program Files\Rising\Rav\scanpe.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7] [C:\Program Files\Rising\Rav\ur000.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5] [C:\Program Files\Rising\Rav\revm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [C:\Program Files\Rising\Rav\scriptci.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [C:\Program Files\Rising\Rav\urutils.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [C:\Program Files\Rising\Rav\uroutine.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [C:\Program Files\Rising\Rav\extfile.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [C:\Program Files\Rising\Rav\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [C:\Program Files\Rising\Rav\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [PID: 448 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\ZLMhp1.DLL] [Zenographics, 1, 0, 63902, 1] [C:\WINDOWS\system32\ZLM.dll] [Zenographics, Inc., 5, 50, 1416, 0] [C:\WINDOWS\system32\ZPJL.dll] [Zenographics, Inc., 1, 0, 1410, 1] [C:\WINDOWS\system32\ZSPOOL.dll] [Zenographics, Inc., 5, 51, 709, 0] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\IMFPrint.DLL] [Zenographics, Inc., 5, 50, 1606, 0] [C:\WINDOWS\system32\Imf32.dll] [Zenographics, Inc., 5, 51, 405, 0] [C:\WINDOWS\system32\ZTAG32.dll] [Zenographics, Inc., 5, 50, 1725, 0] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\ZPPPCL.DLL] [Zenographics, Inc., 5, 51, 710, 0] [C:\WINDOWS\system32\ZPP.dll] [Zenographics, Inc., 5, 51, 709, 0] [C:\WINDOWS\system32\ZGDI32.dll] [Zenographics, Inc., 5, 51, 628, 0] [PID: 476 / SYSTEM][C:\Program Files\Rising\Rav\rsnetsvr.exe] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [C:\Program Files\Rising\Rav\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.9] [C:\Program Files\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\Program Files\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [C:\Program Files\Rising\Rav\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [PID: 928 / SYSTEM][d:\Program Files\StormII\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 3, 15] [PID: 1160 / lix][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20] [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS] [Adobe Systems, Inc., 8.0.0.0] [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 8.0.0.2006102200] [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [D:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 8.1.0.0] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [E:\新建文件夹 (2)\Unlocker1.8.5\UnlockerCOM.dll] [N/A, ] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [C:\ftc2008\FTCCommenu.dll] [Fygsoft and Microsoft, 3.0.0.71] [d:\PROGRA~1\Wopti\WOPTIE~1.DLL] [共软网络, 1.0.8.103] [d:\Program Files\EditPlus 2\EPPSHELL.DLL] [N/A, ] [D:\Program Files\Rational\ClearCase\bin\ccshelxb.dll] [N/A, ] [D:\Program Files\Rational\ClearCase\bin\libatriaview.dll] [IBM Corporation, 6.0.0.389] [D:\Program Files\Rational\ClearCase\bin\LIBRPCSVC.dll] [N/A, ] [D:\Program Files\Rational\ClearCase\bin\LIBATRIANT.dll] [N/A, ] [D:\Program Files\Rational\ClearCase\bin\LIBATRIAADM.dll] [IBM Corporation, 6.0.0.389] [D:\Program Files\Rational\ClearCase\bin\libatriavob.dll] [IBM Corporation, 6.0.0.389] [D:\Program Files\Rational\ClearCase\bin\libatriaccfs.dll] [IBM Corporation, 6.0.0.389] [D:\Program Files\Rational\ClearCase\bin\libatriaxdr.dll] [IBM Corporation, 6.0.0.389] [D:\Program Files\Rational\ClearCase\bin\libatriacredmap.dll] [IBM Corporation, 6.0.0.389] [D:\Program Files\Rational\ClearCase\bin\LIBATRIATBS.dll] [IBM Corporation, 6.0.0.389] [D:\Program Files\Rational\ClearCase\bin\libatriamvfs.dll] [IBM Corporation, 6.0.0.389] [D:\Program Files\Rational\ClearCase\bin\libatriaks.dll] [IBM Corporation, 6.0.0.389] [D:\Program Files\Rational\ClearCase\bin\LIBEZRPC.dll] [N/A, ] [D:\Program Files\Rational\ClearCase\bin\LIBATRIADBRPC.dll] [IBM Corporation, 6.0.0.389] [D:\Program Files\Rational\ClearCase\bin\libatriacm.dll] [IBM Corporation, 6.0.0.389] [C:\WINDOWS\system32\nvshell.dll] [, ] [PID: 1568 / SYSTEM][C:\WINDOWS\287Y2K721D.exe] [N/A, ] [PID: 1604 / lix][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [PID: 1928 / SYSTEM][C:\WINDOWS\system32\cmd.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 1956 / SYSTEM][C:\WINDOWS\system32\inetsrv\inetinfo.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)] [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [PID: 1104 / SYSTEM][C:\WINDOWS\explorer.exe] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 1300 / NETWORK SERVICE][C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe] [Microsoft Corporation, 2005.090.1399.00] [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\Resources\1033\sqlevn70.RLL] [Microsoft Corporation, 2005.090.1399.00] [C:\WINDOWS\system32\MSCOREE.DLL] [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)] [PID: 1256 / SYSTEM][d:\PROGRA~1\MICROS~2\MSSQL\binn\sqlservr.exe] [Microsoft Corporation, 2000.080.0760.00] [d:\PROGRA~1\MICROS~2\MSSQL\binn\OPENDS60.DLL] [Microsoft Corporation, 2000.080.0194.00] [d:\PROGRA~1\MICROS~2\MSSQL\binn\UMS.DLL] [Microsoft Corporation, 2000.080.0760.00] [d:\PROGRA~1\MICROS~2\MSSQL\binn\SQLSORT.DLL] [Microsoft Corporation, 2000.080.0760.00] [d:\PROGRA~1\MICROS~2\MSSQL\binn\Resources\2052\sqlevn70.RLL] [Microsoft Corporation, 2000.080.0760.00] [d:\Program Files\Microsoft SQL Server\MSSQL\binn\SSNETLIB.dll] [Microsoft Corporation, 2000.080.0766.00] [d:\Program Files\Microsoft SQL Server\MSSQL\binn\SSNMPN70.dll] [Microsoft Corporation, 2000.080.0534.00] [d:\PROGRA~1\MICROS~2\MSSQL\binn\SSmsLPCn.dll] [Microsoft Corporation, 2000.080.0760.00] [d:\PROGRA~1\MICROS~2\MSSQL\binn\xpsqlbot.dll] [Microsoft Corporation, 2000.080.0194.00] [PID: 1668 / SYSTEM][C:\WINDOWS\system32\nutsrv4.exe] [DataFocus, Inc., 4.50.0000] [C:\WINDOWS\system32\nutmsg4.dll] [DataFocus, Inc., 4.50.0000] [PID: 1968 / SYSTEM][d:\oracle\ora92\bin\omtsreco.exe] [Oracle Corporation, 9.2.0.1.0] [d:\oracle\ora92\bin\OCI.dll] [Oracle Corporation, 9.2.0.1.0] [d:\oracle\ora92\bin\OraClient9.Dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\oracore9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oraunls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oravsn9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\oracommon9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\orageneric9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\oraxml9.dll] [Oracle Corporation, ] [d:\oracle\ora92\bin\oraxsd9.dll] [Oracle Corporation, ] [d:\oracle\ora92\bin\orannzsbb9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oran9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranl9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranldap9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oraldapclnt9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orancrypt9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\ORATRACE9.dll] [N/A, ] [d:\oracle\ora92\bin\oranro9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranhost9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranoname9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orancds9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orantns9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranms.dll] [Oracle Corporation, 9.2.0.0.0] [d:\oracle\ora92\bin\oranmsp.dll] [Oracle Corporation, 9.2.0.0.0] [d:\oracle\ora92\bin\orapls9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\oraslax9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orasnls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orawtc9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\orasql9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\omtsrecomsgZHS.dll] [Oracle Corporation, 9.0.0.0.0] [d:\oracle\ora92\bin\omtsrecomsgus.dll] [Oracle Corporation, 9.2.0.0.1] [PID: 2144 / SYSTEM][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 22] [C:\Program Files\Rising\Rav\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [C:\Program Files\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.13] [C:\Program Files\Rising\Rav\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\Rav\rsstub.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [C:\Program Files\Rising\Rav\rstask.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 35] [PID: 2160 / SYSTEM][C:\Program Files\Rising\Rfw\RavTask.exe] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 22] [C:\Program Files\Rising\Rfw\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [C:\Program Files\Rising\Rfw\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [C:\Program Files\Rising\Rfw\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.13] [C:\Program Files\Rising\Rfw\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\Rfw\rsstub.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [C:\Program Files\Rising\Rfw\rstask.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 35] [PID: 2188 / SYSTEM][C:\Program Files\Cyberlink\Shared files\RichVideo.exe] [, 2.0.0425 ] [PID: 2244 / NETWORK SERVICE][C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe] [Microsoft Corporation, 2005.090.1399.00] [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [PID: 2248 / SYSTEM][C:\Program Files\Rising\Rav\ScanFrm.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.11] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Rising\Rav\combase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [C:\Program Files\Rising\Rav\moncomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [C:\Program Files\Rising\Rav\scansrvp.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.11] [C:\Program Files\Rising\Rav\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [C:\Program Files\Rising\Rav\ScanSrv.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.9] [C:\Program Files\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [C:\Program Files\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [PID: 2272 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 3508 / SYSTEM][d:\PROGRA~1\MICROS~2\MSSQL\binn\sqlagent.exe] [Microsoft Corporation, 2000.080.0760.00] [d:\PROGRA~1\MICROS~2\MSSQL\binn\SQLRESLD.dll] [Microsoft Corporation, 2000.080.0382.00] [d:\PROGRA~1\MICROS~2\MSSQL\binn\SQLSVC.dll] [Microsoft Corporation, 2000.080.0760.00] [d:\PROGRA~1\MICROS~2\MSSQL\binn\W95SCM.dll] [Microsoft Corporation, 2000.080.0760.00] [d:\PROGRA~1\MICROS~2\MSSQL\binn\SEMMAP.dll] [Microsoft Corporation, 2000.080.0760.00] [d:\PROGRA~1\MICROS~2\MSSQL\binn\Resources\2052\SQLSVC.RLL] [Microsoft Corporation, 2000.080.0194.00] [d:\PROGRA~1\MICROS~2\MSSQL\binn\Resources\2052\SEMMAP.RLL] [Microsoft Corporation, 2000.080.0194.00] [d:\PROGRA~1\MICROS~2\MSSQL\binn\Resources\2052\sqlagent.RLL] [Microsoft Corporation, 2000.080.0760.00] [d:\PROGRA~1\MICROS~2\MSSQL\binn\SQLAGENT.DLL] [Microsoft Corporation, 2000.080.0760.00] [d:\Program Files\Microsoft SQL Server\MSSQL\BINN\SQLCMDSS.DLL] [Microsoft Corporation, 2000.080.0760.00] [d:\Program Files\Microsoft SQL Server\MSSQL\BINN\Resources\2052\SQLCMDSS.RLL] [Microsoft Corporation, 2000.080.0760.00] [d:\Program Files\Microsoft SQL Server\MSSQL\BINN\SQLREPSS.DLL] [Microsoft Corporation, 2000.080.0760.00] [d:\Program Files\Microsoft SQL Server\MSSQL\BINN\Resources\2052\SQLREPSS.RLL] [Microsoft Corporation, 2000.080.0760.00] [d:\Program Files\Microsoft SQL Server\MSSQL\BINN\SQLATXSS.DLL] [Microsoft Corporation, 2000.080.0760.00] [d:\Program Files\Microsoft SQL Server\MSSQL\BINN\Resources\2052\SQLATXSS.RLL] [Microsoft Corporation, 2000.080.0194.00] [C:\Program Files\Microsoft SQL Server\80\Tools\BINN\AXSCPHST.DLL] [Microsoft Corporation, 2000.080.0194.00] [C:\Program Files\Microsoft SQL Server\80\Tools\BINN\Resources\2052\AXSCPHST.RLL] [Microsoft Corporation, 2000.080.0194.00] [C:\WINDOWS\system32\DBmsLPCn.dll] [Microsoft Corporation, 2000.080.0760.00] [PID: 1048 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [PID: 2116 / lix][D:\Program Files\PLSQL Developer\PLSQLDev.exe] [Allround Automations, 5.1.2.682] [d:\oracle\ora92\bin\oci.dll] [Oracle Corporation, 9.2.0.1.0] [d:\oracle\ora92\bin\OraClient9.Dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\oracore9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oraunls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oravsn9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\oracommon9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\orageneric9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\oraxml9.dll] [Oracle Corporation, ] [d:\oracle\ora92\bin\oraxsd9.dll] [Oracle Corporation, ] [d:\oracle\ora92\bin\orannzsbb9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oran9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranl9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranldap9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oraldapclnt9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orancrypt9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\ORATRACE9.dll] [N/A, ] [d:\oracle\ora92\bin\oranro9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranhost9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranoname9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orancds9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orantns9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\oranms.dll] [Oracle Corporation, 9.2.0.0.0] [d:\oracle\ora92\bin\oranmsp.dll] [Oracle Corporation, 9.2.0.0.0] [d:\oracle\ora92\bin\orapls9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\oraslax9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orasnls9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orawtc9.dll] [Oracle Corporation, 9.2.0.1.0 Production ] [d:\oracle\ora92\bin\orasql9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [d:\oracle\ora92\bin\orantcp9.dll] [Oracle Corporation, 9.2.0.1.0 Production] [PID: 3744 / lix][D:\eclipse\eclipse.exe] [N/A, ] [PID: 1972 / lix][C:\j2sdk1.4.2_05\bin\javaw.exe] [N/A, ] [C:\j2sdk1.4.2_05\jre\bin\client\jvm.dll] [Sun Microsystems, Inc., 1.4.2.50] [C:\j2sdk1.4.2_05\jre\bin\hpi.dll] [N/A, ] [C:\j2sdk1.4.2_05\jre\bin\verify.dll] [N/A, ] [C:\j2sdk1.4.2_05\jre\bin\java.dll] [N/A, ] [C:\j2sdk1.4.2_05\jre\bin\zip.dll] [N/A, ] [C:\j2sdk1.4.2_05\jre\bin\net.dll] [N/A, ] [C:\j2sdk1.4.2_05\jre\bin\nio.dll] [N/A, ] [D:\eclipse\plugins\org.eclipse.swt.win32_3.1.0\os\win32\x86\swt-win32-3101.dll] [Eclipse Foundation, 3.101] [D:\eclipse\plugins\org.eclipse.core.resources.win32_3.0.0\os\win32\x86\core_2_1_0b.dll] [N/A, ] [PID: 608 / lix][C:\Program Files\Altova\XML Spy Suite\XMLSpy.exe] [Altova, Inc., 4, 4, 0, 0] [C:\Program Files\Altova\XML Spy Suite\XMLSpyLicMan.dll] [, 1, 0, 0, 1] [C:\Program Files\Altova\XML Spy Suite\SSCE5332.dll] [Wintertree Software Inc., 5.14.10.0] [PID: 264 / lix][C:\PROGRA~1\Altova\XMLSPY~1\XMLSPY~1.EXE] [Altova, Inc., 1, 3, 0, 0] [PID: 2996 / lix][C:\j2sdk1.4.2_05\bin\javaw.exe] [N/A, ] [C:\j2sdk1.4.2_05\jre\bin\client\jvm.dll] [Sun Microsystems, Inc., 1.4.2.50] [C:\j2sdk1.4.2_05\jre\bin\hpi.dll] [N/A, ] [C:\j2sdk1.4.2_05\jre\bin\verify.dll] [N/A, ] [C:\j2sdk1.4.2_05\jre\bin\java.dll] [N/A, ] [C:\j2sdk1.4.2_05\jre\bin\zip.dll] [N/A, ] [C:\j2sdk1.4.2_05\jre\bin\jdwp.dll] [N/A, ] [C:\Program Files\Oracle\jre\1.3.1\bin\dt_socket.dll] [N/A, ] [C:\j2sdk1.4.2_05\jre\bin\net.dll] [N/A, ] [PID: 4004 / lix][C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE] [Microsoft Corporation, 11.0.8117] [C:\Program Files\Microsoft Office\OFFICE11\GdiPlus.DLL] [Microsoft Corporation, 11.0.8230] [C:\WINDOWS\system32\VB6CHS.DLL] [Microsoft Corporation, 6.00.8988] [C:\Program Files\TechSmith\SnagIt 7\SnagItOfficeAddin.dll] [TechSmith 公司, 1.0.6] [C:\Program Files\TechSmith\SnagIt 7\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Rising\Rav\RsPlugIn.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.14] [PID: 3404 / lix][C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE] [Microsoft Corporation, 11.0.8117] [C:\Program Files\Microsoft Office\OFFICE11\GdiPlus.DLL] [Microsoft Corporation, 11.0.8230] [C:\WINDOWS\system32\VB6CHS.DLL] [Microsoft Corporation, 6.00.8988] [C:\Program Files\TechSmith\SnagIt 7\SnagItOfficeAddin.dll] [TechSmith 公司, 1.0.6] [C:\Program Files\TechSmith\SnagIt 7\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Rising\Rav\RsPlugIn.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.14] [C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL] [Microsoft Corporation, 6.04.9972] [C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\2052\VBE6INTL.DLL] [Microsoft Corporation, 6.03.9070] [PID: 3392 / lix][C:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\OFFPROV.EXE] [Microsoft Corporation, 9.00.3226] [C:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\MSIOFF9.OCX] [Microsoft Corporation, 9.00.3226] [PID: 2808 / lix][C:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\OFFPRV10.EXE] [Microsoft Corporation, 10.00.1509] [C:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\MSIOFF10.OCX] [Microsoft Corporation, 10.00.1509] [PID: 2372 / lix][C:\Documents and Settings\lix\桌面\ss\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210] [PID: 1080 / lix][C:\Documents and Settings\lix\桌面\ss\SRE9b4eb966.EXE] [Smallfrogs Studio, 2.7.0.1210] [C:\Documents and Settings\lix\桌面\ss\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] ================================== 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\system32\winhlp32.exe %1] .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 aaa.369678.cn 127.0.0.1 about-blank.cc 127.0.0.1 anjdyazj.cn 127.0.0.1 hao.allxun.com 127.0.0.1 kzxf.com 127.0.0.1 scvip.com 127.0.0.1 vod.mmdy.org 127.0.0.1 www.123wa.com 127.0.0.1 www.369678.cn 127.0.0.1 www.4199.com 127.0.0.1 www.71791.com 127.0.0.1 www.7939.com 127.0.0.1 www.9505.com 127.0.0.1 www.anjdyazj.cn 127.0.0.1 www.feixue.net 127.0.0.1 www.kzxf.com 127.0.0.1 www.my123.com 127.0.0.1 www.piaoxue.com 127.0.0.1 www.scvip.com 127.0.0.1 www.xfkz.com 127.0.0.1 xfkz.com ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 2116, D:\PROGRAM FILES\PLSQL DEVELOPER\PLSQLDEV.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3744, D:\ECLIPSE\ECLIPSE.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1972, C:\J2SDK1.4.2_05\BIN\JAVAW.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 608, C:\PROGRAM FILES\ALTOVA\XML SPY SUITE\XMLSPY.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 264, C:\PROGRA~1\ALTOVA\XMLSPY~1\XMLSPY~1.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2996, C:\J2SDK1.4.2_05\BIN\JAVAW.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2372, C:\DOCUMENTS AND SETTINGS\LIX\桌面\SS\SRENGLDR.EXE] ================================== 计划任务 N/A ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]