[CODE] 2009-02-03,09:59:36 System Repair Engineer 2.7.0.1210 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Infected) Microsoft Corporation] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] <%ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher] <"D:\新建文件夹\Rising\Rav\RsTray.exe" -system> [(Verified)Beijing Rising Information Technology Corporation Limited] <"D:\AntiSpyware\rstray.exe" /startup> [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce] [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] [] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] [File is missing] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AEB6717E-7E19-11d0-97EE-00C04FD91972}> [(Verified)Microsoft Windows Component Publisher] <{89C7A346-DBE8-43F4-8EEC-C6518079CA99}> [File is missing] <{FB675117-C180-457C-9EB0-67E8020B2D00}> [File is missing] <{65CEC182-D711-4001-97FB-5BDAB70364A4}> [File is missing] <{9AE3EDCB-BF79-45D1-BE7E-DB600804AA66}> [File is missing] <{478932A2-862F-4A34-A264-54A6EB998FDE}> [] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}> [(Verified)Beijing Rising Information Technology Corporation Limited] <{B3973132-8ECF-48E5-B6CF-20428CAD993F}> [File is missing] <{82E1ADCB-5E31-46C1-A081-9D92B4E281DF}> [File is missing] <{8F1A9FDB-2CD9-4E2E-895C-B4BE721A2E7A}> [File is missing] <{DFEFEB3F-227C-46B9-9B19-2EAAE7F0E198}> [File is missing] <{0DAB97C4-A5B7-44FB-856B-420D9354027E}> [File is missing] <{5CA240E8-383F-4FB4-B2D3-4E7FE34447D3}> [File is missing] <{3DF44ED8-FA6B-40BD-8CB4-DE51A58DA9A3}> [File is missing] <{A00545BE-937D-46B6-A24A-897B008139FF}> [File is missing] <{86A3BB5B-D337-4D4D-A478-80C01F7E3D2C}> [File is missing] <{55F85549-37C1-40A2-A474-47FC40A20A6A}> [File is missing] <{D0425323-9A14-484F-9BF9-E2F6BDCE7B1B}> [File is missing] <{0579385A-D97A-422B-8957-B7ED47032D90}> [File is missing] <{203A938B-4105-4FD9-8817-47E1F8C07D7D}> [File is missing] <{EC43A110-3951-4889-9E1B-76B06DF03CAB}> [File is missing] <{05DF4DE0-8529-4521-B89C-8C6E6F1AE252}> [File is missing] <{D8107CBF-7877-4065-BF36-587C514133C7}> [] <{BE891A18-1D8C-4228-8D2F-62795E5A948A}> [] <{81719002-D2A6-4B91-A9CA-42F29D52D3CD}> [] <{DE562204-B158-4B55-BEF2-D365CB4C112E}> [] <{0CE79DE5-1F92-48BC-ACE6-4D35F5E58DE8}> [] <{290BBA23-E832-4B65-AF7E-F038D541851D}> [] <{EB0FBA4E-A677-454C-8D7F-BBBAB5520971}> [] <{88462CD9-A249-4EA3-B874-C843F9359B35}> [] <{0384F453-5E9A-49C2-B85F-C602F6D8CA8D}> [] <{24A76EC1-8E65-4B06-B49C-CCA3F45447F5}> [] <{F8ABF6B2-9A9D-4F00-90BD-07AE4AED256B}> [] <{B64263BF-CFDB-41E4-A74F-38D6794275A5}> [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] <89C7A346> [File is missing] [File is missing] <65CEC182> [File is missing] <9AE3EDCB> [File is missing] [File is missing] <82E1ADCB> [File is missing] <8F1A9FDB> [File is missing] [File is missing] <0DAB97C4> [File is missing] <5CA240E8> [File is missing] <3DF44ED8> [File is missing] [File is missing] <86A3BB5B> [File is missing] <55F85549> [File is missing] [File is missing] <0579385A> [File is missing] <203A938B> [File is missing] [File is missing] <05DF4DE0> [File is missing] [] [] <81719002> [] [] <0CE79DE5> [] <290BBA23> [] [] <88462CD9> [] <0384F453> [] <24A76EC1> [] [] [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <浏览器自定义组件> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] <%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsAgent.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Thunder5.exe] [(Verified)Microsoft Windows Publisher] [HKEY_CURRENT_USER\Control Panel\Desktop] [(Verified)Microsoft Windows Publisher] ================================== 启动文件夹 N/A ================================== 服务 [Contrl Center of Storm Media / ccosm][Stopped/Disabled] <北京暴风网际科技有限公司> [Rav Process Communication Center / RavCCenter][Stopped/Auto Start] [Rising RavTask Manager / RavTask][Stopped/Auto Start] <"D:\新建文件夹\Rising\Rav\RavTask.exe" RavTask> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] [Rising Scan Service / RsScanSrv][Stopped/Auto Start] [SigmaTel Audio Service / STacSV][Running/Auto Start] [XAudioService / XAudioService][Stopped/Auto Start] ================================== 驱动程序 [aaatimeo / aaatimeo][Running/Boot Start] <\SystemRoot\system32\DRIVERS\aaatimeo.sys> [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start] [AFAMgt / AFAMgt][Running/Boot Start] <\SystemRoot\system32\DRIVERS\afamgt.sys> [ahcix86 / ahcix86][Running/Boot Start] <\SystemRoot\system32\DRIVERS\ahcix86.sys> [AliIde / AliIde][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\aliide.sys> [AMD AGP Bus Filter Driver / amdagp][Running/Boot Start] <\SystemRoot\system32\DRIVERS\amdagp.sys> [amdbusdr / amdbusdr][Running/Boot Start] <\SystemRoot\system32\DRIVERS\amdbusdr.sys> [AMD EIDE 驱动程衼E / amdeide][Running/Boot Start] <\SystemRoot\system32\DRIVERS\AmdEide.sys> [AMD K8 Processor Driver / AmdK8][Stopped/Manual Start] [SiI-3112 SATALink Controller / ASH1205][Running/Boot Start] <\SystemRoot\system32\DRIVERS\ASH1205.sys> [ata1200a / ata1200a][Running/Boot Start] <\SystemRoot\system32\DRIVERS\ata1200a.sys> [atiide / atiide][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\atiide.sys> [Promise driver accelerator / bb-run][Running/Boot Start] <\SystemRoot\system32\DRIVERS\bb-run.sys> [Broadcom 802.11 网络适配器驱动程序 / BCM43XX][Stopped/Manual Start] [DELL CERC SATA 1.5/6ch RAID Miniport Driver / cercsr6][Running/Boot Start] <\SystemRoot\system32\DRIVERS\cercsr6.sys> [CmdIde / CmdIde][Running/Boot Start] <\SystemRoot\system32\DRIVERS\cmdide.sys> [Cpq32fs2 / Cpq32fs2][Running/Boot Start] <\SystemRoot\system32\DRIVERS\Cpq32fs2.sys> [Promise Removable Disk Control Driver / dontgo][Running/Boot Start] <\SystemRoot\system32\DRIVERS\DontGo.sys> [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start] [fttxr52P / fttxr52P][Running/Boot Start] <\SystemRoot\system32\DRIVERS\fttxr52P.sys> [Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start] [hookcont / hookcont][Running/System Start] [hooksys / hooksys][Stopped/Disabled] [HpCISSm2 / HpCISSm2][Running/Boot Start] <\SystemRoot\system32\DRIVERS\HpCISSm2.sys> [hptmv6 / hptmv6][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\hptmv6.sys> [HSFHWAZL / HSFHWAZL][Stopped/Manual Start] [HSF_DPV / HSF_DPV][Running/Manual Start] [HSXHWAZL / HSXHWAZL][Running/Manual Start] [ialm / ialm][Running/Manual Start] [Intel RAID Controller / iaStor55][Running/Boot Start] <\SystemRoot\system32\DRIVERS\iaStor55.sys> [Intel RAID Controller / iaStor70][Running/Boot Start] <\SystemRoot\system32\DRIVERS\iaStor70.sys> [Intel(R) High Definition Audio HDMI Service / IntcHdmiAddService][Running/Manual Start] [mdmxsdk / mdmxsdk][Running/Auto Start] [msiffei / msiffei][Stopped/Manual Start] [mv61xx / mv61xx][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\mv61xx.sys> [mvSata / mvSata][Running/Boot Start] <\SystemRoot\system32\DRIVERS\mvsata.sys> [nv / nv][Stopped/Manual Start] [nvgts / nvgts][Running/Boot Start] <\SystemRoot\system32\DRIVERS\nvgts.sys> [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start] <\SystemRoot\system32\DRIVERS\nvrd32.sys> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [ql2100 / ql2100][Running/Boot Start] <\SystemRoot\system32\DRIVERS\ql2100.sys> [ql2200 / ql2200][Running/Boot Start] <\SystemRoot\system32\DRIVERS\ql2200.sys> [rimmptsk / rimmptsk][Running/Manual Start] [rimsptsk / rimsptsk][Running/Manual Start] [Ricoh xD-Picture Card Driver / rismxdp][Running/Manual Start] [rr172x / rr172x][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\rr172x.sys> [rr174x / rr174x][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\rr174x.sys> [rr2340 / rr2340][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\rr2340.sys> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [Safe Mon 360 / SafeMon0][Running/System Start] <\??\C:\WINDOWS\system32\9076B7BC.dat> [Secdrv / Secdrv][Stopped/Manual Start] [Sonic Focus Plugin for Sigmatel HDA / sfng32][Stopped/Manual Start] [SATALink External Device Filter / SiRemFil][Running/Boot Start] <\SystemRoot\system32\DRIVERS\SiRemFil.sys> [SIS AGP Bus Filter / sisagp][Running/Boot Start] <\SystemRoot\system32\DRIVERS\sisagp.sys> [sisraidx / sisraidx][Running/Boot Start] <\SystemRoot\system32\DRIVERS\sisraidx.sys> [Audio Driver (WDM) - SigmaTel CODEC / STAC97][Stopped/Manual Start] [SigmaTel High Definition Audio CODEC / STHDA][Running/Manual Start] [SymEvent / SymEvent][Stopped/Manual Start] <\??\C:\Program Files\Symantec\SYMEVENT.SYS> [ViBus / ViBus][Running/Boot Start] <\SystemRoot\system32\DRIVERS\ViBus.sys> [videX32 / videX32][Running/Boot Start] <\SystemRoot\system32\DRIVERS\videX32.sys> [VIA SATA IDE Device Driver / ViPrt][Running/Boot Start] <\SystemRoot\system32\DRIVERS\ViPrt.sys> [winachsf / winachsf][Running/Manual Start] [XAudio / XAudio][Running/Auto Start] [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start] <\SystemRoot\system32\DRIVERS\xfilt.sys> [NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller / yukonwxp][Running/Manual Start] [io / io][Running/] <2 - 系统找不到指定的文件。 > ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [] {478932A2-862F-4A34-A264-54A6EB998FDE} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [] {27B4851A-3207-45A2-B947-BE8AFE6163AB} <, > [DHTML Edit Control Safe for Scripting for IE5] {2D360201-FFF5-11D1-8D03-00A0C959BC0A} [] {478932A2-862F-4A34-A264-54A6EB998FDE} [XML Document] {48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, (Signed) N/A> [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [] {7DB2D5A0-7241-4E79-B68D-6309F01C5231} <, > [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [] {FB5F1910-F110-11D2-BB9E-00C04F795683} <, > [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] ================================== 正在运行的进程 [PID: 824 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 888 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [PID: 916 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 964 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [PID: 976 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [PID: 1144 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [C:\WINDOWS\system32\anymie360.dll] [N/A, ] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat] [N/A, ] [C:\Program Files\Internet Explorer\PowerNt.Onz] [N/A, ] [PID: 1228 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [PID: 1344 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\System32\clagpadi.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [PID: 1508 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [PID: 1608 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [PID: 1872 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [PID: 1984 / SYSTEM][D:\新建文件夹\Rising\Rav\rsnetsvr.exe] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [D:\新建文件夹\Rising\Rav\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.9] [D:\新建文件夹\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [D:\新建文件夹\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [D:\新建文件夹\Rising\Rav\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 420 / Administrator][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [C:\Program Files\Internet Explorer\PowerNt.Onz] [N/A, ] [C:\WINDOWS\system32\dgjfbckg.dll] [N/A, ] [C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 6.14.10.4864] [C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 6.14.10.4864] [C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 6.14.10.4864] [C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 6.14.10.4864] [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 6.14.10.4864] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat] [N/A, ] [C:\WINDOWS\system32\dohgncbf.dll] [N/A, ] [C:\WINDOWS\system32\beophaho.dll] [N/A, ] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [C:\WINDOWS\system32\ohnhpggi.dll] [N/A, ] [C:\WINDOWS\system32\delmiigk.dll] [N/A, ] [C:\WINDOWS\system32\gcenpdel.dll] [N/A, ] [C:\WINDOWS\system32\anymie360.dll] [N/A, ] [C:\WINDOWS\system32\ipgbbaij.dll] [N/A, ] [C:\WINDOWS\system32\ebgfbake.dll] [N/A, ] [D:\Program Files\QQ\qdshm.dll] [, 1, 0, 101, 20] [D:\Program Files\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\ookmicdp.dll] [N/A, ] [C:\WINDOWS\system32\gjokfklj.dll] [N/A, ] [C:\WINDOWS\system32\ikanmech.dll] [N/A, ] [C:\WINDOWS\system32\foabfmbi.dll] [N/A, ] [C:\WINDOWS\system32\bmkimjbf.dll] [N/A, ] [C:\WINDOWS\system32\browselc.dll] [Microsoft Corporation, 6.00.2600.0000] [PID: 496 / Administrator][C:\WINDOWS\system32\conime.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [C:\Program Files\Internet Explorer\PowerNt.Onz] [N/A, ] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat] [N/A, ] [PID: 740 / SYSTEM][D:\新建文件夹\Rising\Rav\ScanFrm.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.11] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [D:\新建文件夹\Rising\Rav\combase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [D:\新建文件夹\Rising\Rav\moncomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [D:\新建文件夹\Rising\Rav\scansrvp.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.11] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [D:\新建文件夹\Rising\Rav\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [D:\新建文件夹\Rising\Rav\ScanSrv.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.9] [D:\新建文件夹\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [D:\新建文件夹\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [D:\新建文件夹\Rising\Rav\ScanRavT.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.23] [D:\新建文件夹\Rising\Rav\ScanBT.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.38] [D:\新建文件夹\Rising\Rav\ScanStub.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.8] [D:\新建文件夹\Rising\Rav\RsLog.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.32] [D:\新建文件夹\Rising\Rav\ScanAdd.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.14] [D:\新建文件夹\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [D:\新建文件夹\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.18] [D:\新建文件夹\Rising\Rav\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.33] [D:\新建文件夹\Rising\Rav\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [D:\新建文件夹\Rising\Rav\refs.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [D:\新建文件夹\Rising\Rav\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [D:\新建文件夹\Rising\Rav\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [D:\新建文件夹\Rising\Rav\SysMail.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.5] [D:\新建文件夹\Rising\Rav\mvengine.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [D:\新建文件夹\Rising\Rav\posttrt.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [D:\新建文件夹\Rising\Rav\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [D:\新建文件夹\Rising\Rav\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [D:\新建文件夹\Rising\Rav\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [D:\新建文件夹\Rising\Rav\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [D:\新建文件夹\Rising\Rav\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 17] [D:\新建文件夹\Rising\Rav\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [D:\新建文件夹\Rising\Rav\scanpe.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7] [D:\新建文件夹\Rising\Rav\ur000.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5] [D:\新建文件夹\Rising\Rav\revm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [D:\新建文件夹\Rising\Rav\scriptci.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [D:\新建文件夹\Rising\Rav\urutils.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [D:\新建文件夹\Rising\Rav\uroutine.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [D:\新建文件夹\Rising\Rav\extfile.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [D:\新建文件夹\Rising\Rav\rsstore.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 9] [D:\新建文件夹\Rising\Rav\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [D:\新建文件夹\Rising\Rav\extole.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [D:\新建文件夹\Rising\Rav\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [D:\新建文件夹\Rising\Rav\ur001.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [D:\新建文件夹\Rising\Rav\ur025.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [D:\新建文件夹\Rising\Rav\scanmac.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [D:\新建文件夹\Rising\Rav\ur023.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [D:\新建文件夹\Rising\Rav\ur027.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [PID: 764 / SYSTEM][C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v133\WDM\STacSV.exe] [SigmaTel, Inc., 1.0.5515.0 nd596 cp1] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\stacapi.dll] [SigmaTel, Inc., 1.0.5515.0 nd596 cp1] [PID: 1596 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [D:\新建文件夹\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.60] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [PID: 236 / Administrator][C:\WINDOWS\system32\igfxtray.exe] [Intel Corporation, 6.14.10.4864] [C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 6.14.10.4864] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 6.14.10.4864] [C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 6.14.10.4864] [C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 6.14.10.4864] [C:\Program Files\Internet Explorer\PowerNt.Onz] [N/A, ] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat] [N/A, ] [PID: 316 / Administrator][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 6.14.10.4864] [C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 6.14.10.4864] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 6.14.10.4864] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 6.14.10.4864] [C:\Program Files\Internet Explorer\PowerNt.Onz] [N/A, ] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat] [N/A, ] [PID: 332 / Administrator][C:\WINDOWS\system32\igfxsrvc.exe] [Intel Corporation, 6.14.10.4864] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 6.14.10.4864] [C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 6.14.10.4864] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [C:\Program Files\Internet Explorer\PowerNt.Onz] [N/A, ] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat] [N/A, ] [PID: 396 / Administrator][C:\WINDOWS\system32\igfxpers.exe] [Intel Corporation, 6.14.10.4864] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 6.14.10.4864] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [C:\Program Files\Internet Explorer\PowerNt.Onz] [N/A, ] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat] [N/A, ] [PID: 636 / Administrator][C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe] [SigmaTel, Inc., 1.0.5515.0 nd596 cp1] [C:\Program Files\SigmaTel\C-Major Audio\WDM\STLang.dll] [SigmaTel, Inc., 1.0.5469.0 nd575 cp1] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Internet Explorer\PowerNt.Onz] [N/A, ] [C:\WINDOWS\system32\stacapi.dll] [SigmaTel, Inc., 1.0.5515.0 nd596 cp1] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat] [N/A, ] [PID: 1284 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [(Infected) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\system32\dgjfbckg.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [C:\Program Files\Internet Explorer\PowerNt.Onz] [N/A, ] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat] [N/A, ] [PID: 2424 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\System32\clagpadi.dll] [N/A, ] [C:\WINDOWS\System32\dgjfbckg.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [PID: 3604 / Administrator][D:\新建文件夹\Rising\Rav\rsmain.exe] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\clagpadi.dll] [N/A, ] [C:\WINDOWS\system32\dgjfbckg.dll] [N/A, ] [C:\WINDOWS\system32\llihldfh.dll] [N/A, ] [C:\WINDOWS\system32\dohgncbf.dll] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Internet Explorer\PowerNt.Onz] [N/A, ] [D:\新建文件夹\Rising\Rav\rspalmgr.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.29] [D:\新建文件夹\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [D:\新建文件夹\Rising\Rav\RSXML.DLL] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [D:\新建文件夹\Rising\Rav\RsGuiLib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 70] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [D:\新建文件夹\Rising\Rav\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 27] [D:\新建文件夹\Rising\Rav\ravbmenu.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 15] [D:\新建文件夹\Rising\Rav\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [D:\新建文件夹\Rising\Rav\rspalvd.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.21] [D:\新建文件夹\Rising\Rav\ravppops.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [D:\新建文件夹\Rising\Rav\ravbintl.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 25] [D:\新建文件夹\Rising\Rav\ravpsafe.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.24] [D:\新建文件夹\Rising\Rav\MonState.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7] [D:\新建文件夹\Rising\Rav\ScanPrxy.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.14] [D:\新建文件夹\Rising\Rav\psafecfg.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.18] [D:\新建文件夹\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [D:\新建文件夹\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.18] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [D:\新建文件夹\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [D:\新建文件夹\Rising\Rav\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [D:\新建文件夹\Rising\Rav\ravxpage.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 81] [D:\新建文件夹\Rising\Rav\ravxmons.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 24] [D:\新建文件夹\Rising\Rav\ravptool.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.20] [D:\新建文件夹\Rising\Rav\log2file.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.5] [D:\新建文件夹\Rising\Rav\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat] [N/A, ] [D:\新建文件夹\Rising\Rav\htmllib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [C:\WINDOWS\system32\beophaho.dll] [N/A, ] [D:\新建文件夹\Rising\Rav\rsvrinfo.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5] [D:\新建文件夹\Rising\Rav\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [D:\新建文件夹\Rising\Rav\refs.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [D:\新建文件夹\Rising\Rav\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [D:\新建文件夹\Rising\Rav\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [C:\WINDOWS\system32\ohnhpggi.dll] [N/A, ] [C:\WINDOWS\system32\delmiigk.dll] [N/A, ] [C:\WINDOWS\system32\ebgfbake.dll] [N/A, ] [C:\WINDOWS\system32\ipgbbaij.dll] [N/A, ] [C:\WINDOWS\system32\gcenpdel.dll] [N/A, ] [PID: 4072 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\system32\dgjfbckg.dll] [N/A, ] [C:\WINDOWS\system32\llihldfh.dll] [N/A, ] [C:\WINDOWS\system32\pfdikkec.dll] [N/A, ] [C:\WINDOWS\system32\dohgncbf.dll] [N/A, ] [C:\WINDOWS\system32\pgcmmdin.dll] [N/A, ] [C:\WINDOWS\system32\jmmmjmge.dll] [N/A, ] [C:\WINDOWS\system32\ainkbcdj.dll] [N/A, ] [C:\WINDOWS\system32\beophaho.dll] [N/A, ] [C:\WINDOWS\system32\gebflnfd.dll] [N/A, ] [C:\WINDOWS\system32\ohnhpggi.dll] [N/A, ] [C:\WINDOWS\system32\delmiigk.dll] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Internet Explorer\PowerNt.Onz] [N/A, ] [C:\WINDOWS\system32\browselc.dll] [Microsoft Corporation, 6.00.2600.0000] [C:\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.16] [C:\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 55] [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\ctm04004.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [D:\新建文件夹\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.60] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\gcenpdel.dll] [N/A, ] [C:\WINDOWS\system32\ipgbbaij.dll] [N/A, ] [C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx] [Adobe Systems, Inc., 9,0,115,0] [C:\WINDOWS\system32\ebgfbake.dll] [N/A, ] [C:\WINDOWS\system32\UrlFilter.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 15] [D:\AntiSpyware\UrlRule.dll] [Beijing Rising Information Technology Co., Ltd., 1.0.0.15] [C:\WINDOWS\system32\ookmicdp.dll] [N/A, ] [C:\WINDOWS\system32\ikanmech.dll] [N/A, ] [C:\WINDOWS\system32\gjokfklj.dll] [N/A, ] [C:\WINDOWS\system32\foabfmbi.dll] [N/A, ] [C:\WINDOWS\system32\bmkimjbf.dll] [N/A, ] [C:\Thunder\ComDlls\ThunderAgent_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 4, 23] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [PID: 2388 / Administrator][C:\Documents and Settings\Administrator\桌面\新建文件夹\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210] [C:\WINDOWS\system32\ookmicdp.dll] [N/A, ] [C:\WINDOWS\system32\gjokfklj.dll] [N/A, ] [C:\WINDOWS\system32\ikanmech.dll] [N/A, ] [C:\WINDOWS\system32\ohnhpggi.dll] [N/A, ] [C:\WINDOWS\system32\dohgncbf.dll] [N/A, ] [C:\WINDOWS\system32\ebgfbake.dll] [N/A, ] [C:\WINDOWS\system32\delmiigk.dll] [N/A, ] [C:\WINDOWS\system32\gcenpdel.dll] [N/A, ] [C:\WINDOWS\system32\bmkimjbf.dll] [N/A, ] [C:\WINDOWS\system32\ipgbbaij.dll] [N/A, ] [C:\WINDOWS\system32\foabfmbi.dll] [N/A, ] [C:\WINDOWS\system32\beophaho.dll] [N/A, ] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\ctm04004.ttf] [N/A, ] [C:\WINDOWS\fonts\ctm09003.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [PID: 3892 / Administrator][C:\Documents and Settings\Administrator\桌面\新建文件夹\SRE9b4eb966.EXE] [Smallfrogs Studio, 2.7.0.1210] [C:\WINDOWS\system32\ookmicdp.dll] [N/A, ] [C:\WINDOWS\system32\gjokfklj.dll] [N/A, ] [C:\WINDOWS\system32\ikanmech.dll] [N/A, ] [C:\WINDOWS\system32\ohnhpggi.dll] [N/A, ] [C:\WINDOWS\system32\dohgncbf.dll] [N/A, ] [C:\WINDOWS\system32\ebgfbake.dll] [N/A, ] [C:\WINDOWS\system32\delmiigk.dll] [N/A, ] [C:\WINDOWS\system32\gcenpdel.dll] [N/A, ] [C:\WINDOWS\system32\bmkimjbf.dll] [N/A, ] [C:\WINDOWS\system32\ipgbbaij.dll] [N/A, ] [C:\WINDOWS\system32\foabfmbi.dll] [N/A, ] [C:\WINDOWS\system32\beophaho.dll] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\CtmRes.dll] [N/A, ] [C:\Program Files\Internet Explorer\PowerNt.Onz] [N/A, ] [C:\WINDOWS\fonts\ctm01025.ttf] [N/A, ] [C:\WINDOWS\fonts\ctm04004.ttf] [N/A, ] [C:\WINDOWS\fonts\ctm09003.ttf] [N/A, ] [C:\WINDOWS\fonts\CTM11008.TTF] [N/A, ] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat] [N/A, ] [C:\Documents and Settings\Administrator\桌面\新建文件夹\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] ================================== 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 v.onondown.com.cn 127.0.0.2 ymsdasdw1.cn 127.0.0.3 h96b.info 127.0.0.0 fuck.zttwp.cn 127.0.0.0 www.hackerbf.cn 127.0.0.0 ww.popdm.cn 127.1.1.1 bbt.etimes888.com 127.0.0.0 zzz.2008wyt.net 127.1.1.1 999.2005wyt.com 127.1.1.1 219.147.13.53 127.1.1.1 dl.360safe.com 127.1.1.1 20068080.cn 127.1.1.1 l.neter888.cn 127.1.1.1 stat.untang.com 127.1.1.1 www.ikdy.cn 127.0.0.0 geekbyfeng.cn 127.0.0.0 121.14.101.68 127.0.0.0 ppp.etimes888.com 127.0.0.0 www.bypk.com 127.0.0.0 CSC3-2004-crl.verisign.com 127.0.0.1 va9sdhun23.cn 127.0.0.0 udp.hjob123.com 127.1.1.1 999.hfdy2828.com 127.1.1.1 www.hfdy2929.com 127.1.1.1 www.xiazaide1.cn 127.1.1.1 www.vuf51579.cn 127.1.1.1 wm.eo2q.cn 127.1.1.1 d.www-263.com 127.1.1.1 www.ssy1688.cn 127.1.1.1 121.12.173.218 127.1.1.1 qq.18i16.net 127.1.1.1 a.baidu-6661.com 127.1.1.1 www.vuf51579.cn 127.1.1.1 www.1079223105.cn 127.1.1.1 home.xzx6.cn 127.1.1.1 top.fgc3.cn 127.1.1.1 165.246.44.228 127.1.1.1 wwww.ttfafa.com 127.1.1.1 pa.tt-09.com 127.0.0.2 bnasnd83nd.cn 127.0.0.0 www.gamehacker.com.cn 127.0.0.0 gamehacker.com.cn 127.1.1.1 www.cctv-100008.cn 127.1.1.1 222.73.208.141 127.0.0.3 adlaji.cn 127.1.1.1 aiyyw.com 127.0.0.1 858656.com 127.1.1.1 bnasnd83nd.cn 127.0.0.1 my123.com 127.0.0.0 user1.12-27.net 127.0.0.1 8749.com 127.0.0.0 fengent.cn 127.0.0.1 4199.com 127.0.0.1 user1.16-22.net 127.0.0.1 7379.com 127.0.0.1 2be37c5f.3f6e2cc5f0b.com 127.0.0.1 7255.com 127.0.0.1 user1.23-12.net 127.0.0.1 3448.com 127.0.0.1 www.guccia.net 127.0.0.1 7939.com 127.0.0.1 a.o1o1o1.nEt 127.0.0.1 8009.com 127.0.0.1 user1.12-73.cn 127.0.0.1 piaoxue.com 127.0.0.1 3n8nlasd.cn 127.0.0.1 kzdh.com 127.0.0.0 www.sony888.cn 127.0.0.1 about.blank.la 127.0.0.0 user1.asp-33.cn 127.0.0.1 6781.com 127.0.0.0 www.netkwek.cn 127.0.0.1 7322.com 127.0.0.0 ymsdkad6.cn 127.0.0.1 localhost 127.0.0.0 www.lkwueir.cn 127.0.0.1 06.jacai.com 127.0.1.1 user1.23-17.net 127.0.0.1 1.jopenkk.com 127.0.0.0 upa.luzhiai.net 127.0.0.1 1.jopenqc.com 127.0.0.0 www.guccia.net 127.0.0.1 1.joppnqq.com 127.0.0.0 4m9mnlmi.cn 127.0.0.1 1.xqhgm.com 127.0.0.0 mm119mkssd.cn 127.0.0.1 100.332233.com 127.0.0.0 61.128.171.115:8080 127.0.0.1 121.11.90.79 127.0.0.0 www.1119111.com 127.0.0.1 121565.net 127.0.0.0 win.nihao69.cn 127.0.0.1 125.90.88.38 127.0.0.1 16888.6to23.com 127.0.0.1 2.joppnqq.com 127.0.0.0 puc.lianxiac.net 127.0.0.1 204.177.92.68 127.0.0.0 pud.lianxiac.net 127.0.0.1 210.74.145.236 127.0.0.0 210.76.0.133 127.0.0.1 219.129.239.220 127.0.0.0 61.166.32.2 127.0.0.1 219.153.40.221 127.0.0.0 218.92.186.27 127.0.0.1 219.153.46.27 127.0.0.0 www.fsfsfag.cn 127.0.0.1 219.153.52.123 127.0.0.0 ovo.ovovov.cn 127.0.0.1 221.195.42.71 127.0.0.0 dw.com.com 127.0.0.1 222.73.218.115 127.0.0.1 203.110.168.233:80 127.0.0.1 3.joppnqq.com 127.0.0.1 203.110.168.221:80 127.0.0.1 363xx.com 127.0.0.1 www1.ip10086.com.cm 127.0.0.1 4199.com 127.0.0.1 blog.ip10086.com.cn 127.0.0.1 43242.com 127.0.0.1 www.ccji68.cn 127.0.0.1 5.xqhgm.com 127.0.0.0 t.myblank.cn 127.0.0.1 520.mm5208.com 127.0.0.0 x.myblank.cn 127.0.0.1 59.34.131.54 127.0.0.1 210.51.45.5 127.0.0.1 59.34.198.228 127.0.0.1 www.ew1q.cn 127.0.0.1 59.34.198.88 127.0.0.1 59.34.198.97 127.0.0.1 60.190.114.101 127.0.0.1 60.190.218.34 127.0.0.0 qq-xing.com.cn 127.0.0.1 60.191.124.252 127.0.0.1 61.145.117.212 127.0.0.1 61.157.109.222 127.0.0.1 75.126.3.216 127.0.0.1 220.250.64.21 127.0.0.1 75.126.3.217 127.0.0.1 75.126.3.218 127.0.0.0 59.125.231.177:17777 127.0.0.1 75.126.3.220 127.0.0.1 75.126.3.221 127.0.0.1 75.126.3.222 127.0.0.1 772630.com 127.0.0.1 832823.cn 127.0.0.1 8749.com 127.0.0.1 888.jopenqc.com 127.0.0.1 89382.cn 127.0.0.1 8v8.biz 127.0.0.1 97725.com 127.0.0.1 9gg.biz 127.0.0.1 www.9000music.com 127.0.0.1 test.591jx.com 127.0.0.1 a.topxxxx.cn 127.0.0.1 picon.chinaren.com 127.0.0.1 www.5566.net 127.0.0.1 p.qqkx.com 127.0.0.1 news.netandtv.com 127.0.0.1 z.neter888.cn 127.0.0.1 b.myblank.cn 127.0.0.1 wvw.wokutu.com 127.0.0.1 unionch.qyule.com 127.0.0.1 www.qyule.com 127.0.0.1 it.itjc.cn 127.0.0.1 www.linkwww.com 127.0.0.1 vod.kaicn.com 127.0.0.1 www.tx8688.com 127.0.0.1 b.neter888.cn 127.0.0.1 promote.huanqiu.com 127.0.0.1 www.huanqiu.com 127.0.0.1 www.haokanla.com 127.0.0.1 play.unionsky.cn 127.0.0.1 www.52v.com 127.0.0.1 www.gghka.cn 127.0.0.1 icon.ajiang.net 127.0.0.1 new.ete.cn 127.0.0.1 www.stiae.cn 127.0.0.1 o.neter888.cn 127.0.0.1 comm.jinti.com 127.0.0.1 www.google-analytics.com 127.0.0.1 hz.mmstat.com 127.0.0.1 www.game175.cn 127.0.0.1 x.neter888.cn 127.0.0.1 z.neter888.cn 127.0.0.1 p.etimes888.com 127.0.0.1 hx.etimes888.com 127.0.0.1 abc.qqkx.com 127.0.0.1 dm.popdm.cn 127.0.0.1 www.yl9999.com 127.0.0.1 www.dajiadoushe.cn 127.0.0.1 v.onondown.com.cn 127.0.0.1 www.interoo.net 127.0.0.1 bally1.bally-bally.net 127.0.0.1 www.bao5605509.cn 127.0.0.1 www.rty456.cn 127.0.0.1 www.werqwer.cn 127.0.0.1 1.360-1.cn 127.0.0.1 user1.23-16.net 127.0.0.1 www.guccia.net 127.0.0.1 www.interoo.net 127.0.0.1 upa.netsool.net 127.0.0.1 js.users.51.la 127.0.0.1 vip2.51.la 127.0.0.1 web.51.la 127.0.0.1 qq.gong2008.com 127.0.0.1 2008tl.copyip.com 127.0.0.1 tla.laozihuolaile.cn 127.0.0.1 www.tx6868.cn 127.0.0.1 p001.tiloaiai.com 127.0.0.1 s1.tl8tl.com 127.0.0.1 s1.gong2008.com 127.0.0.1 4b3ce56f9g.3f6e2cc5f0b.com 127.0.0.1 2be37c5f.3f6e2cc5f0b.com ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 916, C:\WINDOWS\SYSTEM32\WINLOGON.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 1284, C:\WINDOWS\SYSTEM32\CTFMON.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1284, C:\WINDOWS\SYSTEM32\CTFMON.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 2388, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\新建文件夹\SRENGLDR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2388, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\新建文件夹\SRENGLDR.EXE] ================================== 计划任务 N/A ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]