[CODE] 2009-03-14,00:48:57 System Repair Engineer 2.7.0.1210 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [Realtek Semiconductor Corp.] <"G:\新建文件夹\rstray.exe" /startup> [(Verified)Beijing Rising Information Technology Corporation Limited] <"G:\新建文件夹 (2)\Rising\Ris\RsTray.exe" -system> [(Verified)Beijing Rising Information Technology Corporation Limited] [(Verified)"ShenZhen DaChengTianXia Information Technology Co., Ltd."] <"C:\WINDOWS\system32\nap32.exe" /run> [Beijing Rising Information Technology Co., Ltd.] <; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher] <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [File is missing] <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [File is missing] <; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> [] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AEB6717E-7E19-11d0-97EE-00C04FD91972}> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <浏览器自定义组件> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] <%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Publisher] [HKEY_CURRENT_USER\Control Panel\Desktop] [Microsoft] ================================== 启动文件夹 [壁纸自动换] C:\WINDOWS\system32\bgswitch.exe [N/A]> ================================== 服务 [Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start] [ATI Smart / ATI Smart][Stopped/Auto Start] <> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [Ris Process Communication Center / RisCCenter][Stopped/Auto Start] [Rising RisTask Manager / RisTask][Running/Auto Start] <"G:\新建文件夹 (2)\Rising\Ris\RavTask.exe" RisTask> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] [Rising Scan Service / RsScanSrv][Stopped/Auto Start] [SDK QoS Server / SDK QoS Server][Stopped/Auto Start] <(File is missing)> ================================== 驱动程序 [a320raid / a320raid][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\a320raid.sys> [AAC / AAC][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AAC.SYS> [aar1210 / aar1210][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aar1210.sys> [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start] [adpu320 / adpu320][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\adpu320.sys> [ACARD AEC6210UF UltraDMA33 Controller / aec6210][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aec6210.sys> [ACARD AEC6260 UltraDMA-66 Controller / aec6260][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aec6260.sys> [aec6280 / aec6280][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aec6280.sys> [AEC6290 / AEC6290][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AEC6290.SYS> [AEC67160 / AEC67160][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AEC67160.SYS> [AEC671X / AEC671X][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AEC671X.SYS> [AEC6880 / AEC6880][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AEC6880.SYS> [AEC6890 / AEC6890][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AEC6890.sys> [aec68x5 / aec68x5][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aec68x5.sys> [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start] [AliIde / AliIde][Running/Boot Start] <\SystemRoot\System32\DRIVERS\aliide.sys> [AMD K8 Processor Driver / AmdK8][Stopped/Manual Start] [arc / arc][Stopped/Boot Start] <\SystemRoot\system32\drivers\arc.sys> [asc / asc][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\asc.sys> [asc3550 / asc3550][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\asc3550.sys> [ati2mtag / ati2mtag][Running/Manual Start] [CmdIde / CmdIde][Running/Boot Start] <\SystemRoot\System32\DRIVERS\cmdide.sys> [dac2w2k / dac2w2k][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\dac2w2k.sys> [elxstor / elxstor][Stopped/Boot Start] <\SystemRoot\system32\drivers\elxstor.sys> [FASTSX / FASTSX][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\FASTSX.SYS> [fasttrak / fasttrak][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\fasttrak.sys> [fasttx2k / fasttx2k][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\fasttx2k.sys> [fasttx2k2 / fasttx2k2][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\fasttx2k2.sys> [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start] [hookcont / hookcont][Running/System Start] [hooksys / hooksys][Running/System Start] [HpCISSs / HpCISSs][Stopped/Boot Start] <\SystemRoot\system32\drivers\hpcisss.sys> [Hpt366 / Hpt366][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\Hpt366.sys> [HPT371 / HPT371][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\HPT371.sys> [hpt374 / hpt374][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\hpt374.sys> [hpt3xx / hpt3xx][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\hpt3xx.sys> [hptmv / hptmv][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\hptmv.sys> [hptpro / hptpro][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\hptpro.sys> [Intel Integrated RAID / iaStor][Stopped/Boot Start] <\SystemRoot\system32\drivers\iaStor.sys> [iirsp / iirsp][Stopped/Boot Start] <\SystemRoot\system32\drivers\iirsp.sys> [ITERAID_Service_Install / iteraid][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\iteraid.sys> [LSI_SAS / LSI_SAS][Stopped/Boot Start] <\SystemRoot\system32\drivers\lsi_sas.sys> [LSI_SCSI / LSI_SCSI][Stopped/Boot Start] <\SystemRoot\system32\drivers\lsi_scsi.sys> [m5228 / m5228][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\m5228.sys> [m5281 / m5281][Stopped/Boot Start] <\SystemRoot\system32\drivers\m5281.sys> [MegaIDE / MegaIDE][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\MegaIDE.sys> [megasas / megasas][Stopped/Boot Start] <\SystemRoot\system32\drivers\megasas.sys> [mraid2k / mraid2k][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\mraid2k.sys> [mraid35x / mraid35x][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\mraid35x.sys> [nfrd960 / nfrd960][Stopped/Boot Start] <\SystemRoot\system32\drivers\nfrd960.sys> [npkcrypt / npkcrypt][Stopped/Auto Start] <\??\C:\Program Files\QQ2005\npkcrypt.sys> [nv / nv][Stopped/Manual Start] [Intel SCSI Controller / NvAtaBus][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\NVATABUS.SYS> [NVIDIA nForce(tm) RAID Class Driver / nvraid][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\nvraid.sys> [PNP649R / PNP649R][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\PNP649R.SYS> [SiI 680 ATA Controller / Pnp680][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\pnp680.sys> [Silicon Image SiI 0680 Medley Raid Controller / Pnp680r][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\pnp680r.sys> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [ql1080 / ql1080][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ql1080.sys> [ql12160 / ql12160][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ql12160.sys> [ql1280 / ql1280][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ql1280.sys> [QLogic Fibre Channel SCSI Miniport Driver / ql2300][Stopped/Boot Start] <\SystemRoot\system32\drivers\ql2300.sys> [RAIDSRC / RAIDSRC][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\RAIDSRC.SYS> [Rising RfwBase Driver / RfwBase9][Running/Manual Start] [rfwtdi / rfwtdi][Running/Auto Start] <\??\G:\新建文件夹 (2)\Rising\Ris\rfwtdi.sys> [rsfwdrv / rsfwdrv][Running/System Start] <\??\G:\新建文件夹 (2)\Rising\Ris\rsfwdrv.sys> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Running/Manual Start] [S150SX8 / S150SX8][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\S150SX8.SYS> [Secdrv / Secdrv][Stopped/Manual Start] [SiI-3512 SATALink Controller / SI3112][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3112.sys> [Silicon Image SiI 3512 SATARaid Controller / SI3112r][Stopped/Boot Start] <\SystemRoot\system32\drivers\SI3112r.sys> [SiI-3114 SATALink Controller / SI3114][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3114.sys> [SiI-3114 SATARaid Controller / SI3114r][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3114R.sys> [SiI-3124 SATALink Controller / SI3124][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3124.sys> [SiI-3124 SATARaid Controller / SI3124r][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3124R.sys> [SATALink driver accelerator / SiFilter][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SiWinAcc.sys> [SISIDE / SISIDE][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SISIDE.SYS> [SiSRaid / SiSRaid][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SiSRaid.sys> [SiSRaid1 / SiSRaid1][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SiSRaid1.sys> [SISRAIDS / SISRAIDS][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SISRAIDS.SYS> [Sparrow / Sparrow][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\sparrow.sys> [sptrak / sptrak][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\sptrak.sys> [symc810 / symc810][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\symc810.sys> [symc8xx / symc8xx][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\symc8xx.sys> [SYMMPI / SYMMPI][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SYMMPI.SYS> [sym_hi / sym_hi][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\sym_hi.sys> [sym_u3 / sym_u3][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\sym_u3.sys> [TCP/IP Protocol Driver / Tcpip][Running/System Start] [UlSata / UlSata][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ulsata.sys> [ULSATAS / ULSATAS][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ULSATAS.SYS> [ultra / ultra][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ultra.sys> [viamraid / viamraid][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\viamraid.sys> [VIA ATA/ATAPI Host Controller / viapdsk][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\viapdsk.sys> [viaraid / viaraid][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\viaraid.sys> [viasraid / viasraid][Stopped/Boot Start] <\SystemRoot\system32\drivers\viasraid.sys> [vmscsi / vmscsi][Stopped/Boot Start] <\SystemRoot\system32\drivers\vmscsi.sys> [ASTDriver / ASTDriver][Running/Manual Start] <\??\E:\ast\ASTDriver.sys> ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [SecAddons Class] {AF69627B-8489-41C2-971A-B927DF7A5B0F} [启动迅雷5] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} [微软] {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} [Windows Genuine Advantage Validation Tool] {17492023-C23A-453E-A040-C7C580BBF700} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, > [GerneralPeerID Class] {0A47E819-F82E-4D5D-B806-6A9EA94D68CD} [DHTML Edit Control Safe for Scripting for IE5] {2D360201-FFF5-11D1-8D03-00A0C959BC0A} [XML Document] {48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, (Signed) N/A> [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [] {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <, > [XMP Class] {6483F145-A768-4C41-AACC-52D4D7845851} [XDRM] {693571CB-54A3-4E90-9D52-EEAE1334E2D3} [MediaComm Class] {7670648D-461B-42AF-BDFE-46D26AF5EFF2} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [RMGetLicense Class] {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} [Thunder DapCtrl] {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} [SecAddons Class] {AF69627B-8489-41C2-971A-B927DF7A5B0F} [] {C56CB6B0-0D96-11D6-8C65-B2868B609932} <, > [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [Thunder DapPlayer] {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} [] {FB5F1910-F110-11D2-BB9E-00C04F795683} <, > [使用影音传送带下载全部链接] [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] ================================== 正在运行的进程 [PID: 816 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 880 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 908 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4129] [PID: 952 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 964 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1124 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4129] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2500] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1148 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1236 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1388 / SYSTEM][G:\新建文件夹 (2)\Rising\Ris\CCENTER.EXE] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [G:\新建文件夹 (2)\Rising\Ris\combase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [G:\新建文件夹 (2)\Rising\Ris\cnt09.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 37] [G:\新建文件夹 (2)\Rising\Ris\cnt08.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1396 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1540 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1600 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1712 / SYSTEM][G:\新建文件夹 (2)\Rising\Ris\RavMonD.exe] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [G:\新建文件夹 (2)\Rising\Ris\combase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [G:\新建文件夹 (2)\Rising\Ris\moncomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [G:\新建文件夹 (2)\Rising\Ris\MonBase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 6] [G:\新建文件夹 (2)\Rising\Ris\Rslog.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.34] [G:\新建文件夹 (2)\Rising\Ris\mondrv.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 8] [G:\新建文件夹 (2)\Rising\Ris\defmon.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 30] [G:\新建文件夹 (2)\Rising\Ris\moncom08.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [G:\新建文件夹 (2)\Rising\Ris\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 9] [G:\新建文件夹 (2)\Rising\Ris\FileMon.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 22] [G:\新建文件夹 (2)\Rising\Ris\MailMon.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 24] [G:\新建文件夹 (2)\Rising\Ris\HookWeb.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [G:\新建文件夹 (2)\Rising\Ris\rfwlog.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 9] [G:\新建文件夹 (2)\Rising\Ris\rfwrule.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.25] [G:\新建文件夹 (2)\Rising\Ris\rfwsrv.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.80] [G:\新建文件夹 (2)\Rising\Ris\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [G:\新建文件夹 (2)\Rising\Ris\mPorts.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.0] [G:\新建文件夹 (2)\Rising\Ris\rfwdrvc.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.3] [G:\新建文件夹 (2)\Rising\Ris\Rfwdrv.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.5] [G:\新建文件夹 (2)\Rising\Ris\rsnetsvr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 13] [G:\新建文件夹 (2)\Rising\Ris\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [G:\新建文件夹 (2)\Rising\Ris\urlrule.dll] [Beijing Rising Information Technology Co., Ltd., 1.0.0.18] [G:\新建文件夹 (2)\Rising\Ris\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [G:\新建文件夹 (2)\Rising\Ris\refs.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [G:\新建文件夹 (2)\Rising\Ris\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [G:\新建文件夹 (2)\Rising\Ris\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [G:\新建文件夹 (2)\Rising\Ris\rfwproxy.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.25] [G:\新建文件夹 (2)\Rising\Ris\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [G:\新建文件夹 (2)\Rising\Ris\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [G:\新建文件夹 (2)\Rising\Ris\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.18] [G:\新建文件夹 (2)\Rising\Ris\Hooksys.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 18] [G:\新建文件夹 (2)\Rising\Ris\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [G:\新建文件夹 (2)\Rising\Ris\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [G:\新建文件夹 (2)\Rising\Ris\HookCont.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 12] [G:\新建文件夹 (2)\Rising\Ris\BACore.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 20] [G:\新建文件夹 (2)\Rising\Ris\RSStore.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 9] [G:\新建文件夹 (2)\Rising\Ris\ScanAdd.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.15] [G:\新建文件夹 (2)\Rising\Ris\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.33] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [G:\新建文件夹 (2)\Rising\Ris\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [G:\新建文件夹 (2)\Rising\Ris\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [G:\新建文件夹 (2)\Rising\Ris\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5] [G:\新建文件夹 (2)\Rising\Ris\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [G:\新建文件夹 (2)\Rising\Ris\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 25] [G:\新建文件夹 (2)\Rising\Ris\extfile.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 13] [G:\新建文件夹 (2)\Rising\Ris\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [G:\新建文件夹 (2)\Rising\Ris\scanpe.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7] [G:\新建文件夹 (2)\Rising\Ris\ur000.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 10] [G:\新建文件夹 (2)\Rising\Ris\urutils.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [G:\新建文件夹 (2)\Rising\Ris\urllib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [G:\新建文件夹 (2)\Rising\Ris\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [G:\新建文件夹 (2)\Rising\Ris\posttrt.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [G:\新建文件夹 (2)\Rising\Ris\revm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [G:\新建文件夹 (2)\Rising\Ris\ur009.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [G:\新建文件夹 (2)\Rising\Ris\ur001.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7] [G:\新建文件夹 (2)\Rising\Ris\ur025.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [G:\新建文件夹 (2)\Rising\Ris\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [PID: 1888 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1992 / new][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4129] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2500] [PID: 164 / new][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [E:\ast\AST.dll] [超级巡警, 1.0.2.10] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.27] [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 18] [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [PID: 284 / new][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5, 1, 0, 48] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 316 / new][G:\新建文件夹\rstray.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.16] [G:\新建文件夹\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [G:\新建文件夹\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [G:\新建文件夹\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [G:\新建文件夹\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [G:\新建文件夹\ComServ.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.31] [G:\新建文件夹\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [G:\新建文件夹\rscommon.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.1.1] [G:\新建文件夹\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [G:\新建文件夹\pngdll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [G:\新建文件夹\runiep.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.42] [G:\新建文件夹\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.11] [G:\新建文件夹\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [G:\新建文件夹\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [PID: 324 / new][G:\新建文件夹 (2)\Rising\Ris\RsTray.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.22] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [G:\新建文件夹 (2)\Rising\Ris\ComServ.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.49] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [G:\新建文件夹 (2)\Rising\Ris\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 28] [G:\新建文件夹 (2)\Rising\Ris\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [G:\新建文件夹 (2)\Rising\Ris\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [G:\新建文件夹 (2)\Rising\Ris\rsxml.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [G:\新建文件夹 (2)\Rising\Ris\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [G:\新建文件夹 (2)\Rising\Ris\MonState.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7] [G:\新建文件夹 (2)\Rising\Ris\ScanEvnt.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.12] [G:\新建文件夹 (2)\Rising\Ris\rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 71] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [G:\新建文件夹 (2)\Rising\Ris\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [G:\新建文件夹 (2)\Rising\Ris\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [G:\新建文件夹 (2)\Rising\Ris\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.18] [G:\新建文件夹 (2)\Rising\Ris\rfwrule.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.25] [G:\新建文件夹 (2)\Rising\Ris\rspalvd.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.21] [G:\新建文件夹 (2)\Rising\Ris\rsnetsvr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 13] [G:\新建文件夹 (2)\Rising\Ris\ravbintl.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 28] [G:\新建文件夹 (2)\Rising\Ris\mruleui.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 10] [G:\新建文件夹 (2)\Rising\Ris\MonTray.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.93] [G:\新建文件夹 (2)\Rising\Ris\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [G:\新建文件夹 (2)\Rising\Ris\RavITray.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 19] [G:\新建文件夹 (2)\Rising\Ris\ScanPrxy.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.15] [G:\新建文件夹 (2)\Rising\Ris\rfwtray.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 1, 9] [G:\新建文件夹 (2)\Rising\Ris\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [G:\新建文件夹 (2)\Rising\Ris\rfwlog.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 9] [PID: 336 / new][E:\ast\ast.exe] [超级巡警, 1, 8, 6, 118] [E:\ast\MFC80.DLL] [Microsoft Corporation, 8.00.50727.762] [E:\ast\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [E:\ast\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [E:\ast\common.dll] [超级巡警, 1, 4, 2, 32] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [E:\ast\EngineSDK.dll] [超级巡警, 2, 2, 2, 61] [E:\ast\aScanCom.dll] [超级巡警, 2, 1, 2, 58] [E:\ast\AST.dll] [超级巡警, 1.0.2.10] [E:\ast\AutoRun.dll] [超级巡警, 2, 2, 2, 26] [E:\ast\FileAnalyser.dll] [超级巡警, 1.0.1.11] [E:\ast\FileForceKiller.dll] [DSW Lab, 1, 0, 0, 1] [E:\ast\ManagerProcess.dll] [超级巡警, 1.3.4.13] [E:\ast\ManagerService.dll] [超级巡警, 1.0.6.4] [E:\ast\Monitor.dll] [超级巡警, 1, 7, 9, 42] [E:\ast\PortAssociate.dll] [超级巡警, 1.0.3.7] [E:\ast\ssdt.dll] [超级巡警, 1.0.2.4] [E:\ast\StateViewer.dll] [超级巡警, 1, 0, 10, 18] [E:\ast\TIERepair.dll] [超级巡警, 1, 2, 2, 20] [E:\ast\tRubbishClear.dll] [超级巡警, 1, 5, 2, 24] [E:\ast\tSecurityOptimize.dll] [超级巡警, 1, 1, 2, 9] [E:\ast\zDiagnosticTool.dll] [超级巡警, 1.2.1.3] [E:\ast\KillModule.dll] [超级巡警, 1, 2, 2, 30] [E:\ast\MScaner.dll] [超级巡警, 1.0.0.26] [E:\ast\ScanAd.dll] [Secward Technologies, Inc., 1.0.1.2] [E:\ast\SKEngine.dll] [超级巡警, 1.6.5.12] [E:\ast\smart.dll] [超级巡警, 1.0.0.31] [E:\ast\unarc.dll] [超级巡警, 1.2.5] [E:\ast\SScanner.dll] [超级巡警, 1, 0, 6, 19] [PID: 404 / new][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [PID: 524 / new][G:\新建文件夹 (2)\Rising\Ris\rsnetsvr.exe] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 14] [G:\新建文件夹 (2)\Rising\Ris\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.9] [G:\新建文件夹 (2)\Rising\Ris\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [G:\新建文件夹 (2)\Rising\Ris\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [G:\新建文件夹 (2)\Rising\Ris\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1084 / SYSTEM][G:\新建文件夹 (2)\Rising\Ris\RavTask.exe] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 23] [G:\新建文件夹 (2)\Rising\Ris\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [G:\新建文件夹 (2)\Rising\Ris\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [G:\新建文件夹 (2)\Rising\Ris\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.18] [G:\新建文件夹 (2)\Rising\Ris\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [G:\新建文件夹 (2)\Rising\Ris\rsstub.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [G:\新建文件夹 (2)\Rising\Ris\rstask.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 36] [PID: 1320 / SYSTEM][G:\新建文件夹 (2)\Rising\Ris\ScanFrm.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.11] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [G:\新建文件夹 (2)\Rising\Ris\combase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [G:\新建文件夹 (2)\Rising\Ris\moncomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [G:\新建文件夹 (2)\Rising\Ris\scansrvp.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.11] [G:\新建文件夹 (2)\Rising\Ris\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [G:\新建文件夹 (2)\Rising\Ris\ScanSrv.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.9] [G:\新建文件夹 (2)\Rising\Ris\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [G:\新建文件夹 (2)\Rising\Ris\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1332 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [G:\新建文件夹\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [G:\新建文件夹\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [PID: 744 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [G:\新建文件夹\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [G:\新建文件夹\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [PID: 2556 / new][G:\新建文件夹\knownsvr.exe] [Beijing Rising Information Technology Co., Ltd., 6.0.0.14] [G:\新建文件夹\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.11] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [G:\新建文件夹\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [G:\新建文件夹\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [PID: 2820 / new][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [G:\新建文件夹\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [G:\新建文件夹\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [E:\ast\AST.dll] [超级巡警, 1.0.2.10] [C:\WINDOWS\system32\UrlFilter.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 15] [G:\新建文件夹\UrlRule.dll] [Beijing Rising Information Technology Co., Ltd., 1.0.0.15] [E:\ast\SecAddons.dll] [超级巡警, 1, 0, 3, 4] [G:\新建文件夹 (2)\Rising\Ris\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.62] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx] [Adobe Systems, Inc., 10,0,22,87] [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.27] [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 18] [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [PID: 2896 / new][C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5.7.9.466] [C:\Program Files\Thunder Network\Thunder\Program\BugReport.dll] [Thunder Networking Technologies,LTD, 1, 2, 0, 15] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [G:\新建文件夹\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [G:\新建文件夹\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [E:\ast\AST.dll] [超级巡警, 1.0.2.10] [C:\Program Files\Thunder Network\Thunder\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 3, 4, 62] [C:\Program Files\Thunder Network\Thunder\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 3, 0, 2, 307] [C:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031] [C:\Program Files\Thunder Network\Thunder\Program\asyn_frame.dll] [, 1, 0, 2, 7] [C:\Program Files\Thunder Network\Thunder\Program\backend_agent.dll] [, 1, 0, 2, 11] [C:\Program Files\Thunder Network\Thunder\Program\ptl.dll] [Thunder Networking Technologies, LTD, 1, 0, 2, 12] [C:\Program Files\Thunder Network\Thunder\Program\p2p_upload.dll] [, 1, 0, 2, 7] [C:\Program Files\Thunder Network\Thunder\Program\fs.dll] [, 1, 0, 2, 7] [C:\Program Files\Thunder Network\Thunder\Program\p2p.dll] [, 1, 0, 2, 12] [C:\Program Files\Thunder Network\Thunder\Program\p2p_local_res.dll] [, 1, 0, 2, 7] [C:\Program Files\Thunder Network\Thunder\Program\p2sp.dll] [, 1, 0, 2, 13] [C:\Program Files\Thunder Network\Thunder\Program\down_dispatcher.dll] [, 1, 0, 2, 12] [C:\Program Files\Thunder Network\Thunder\Program\xldc.dll] [Thunder Networking Technologies,LTD, 1, 5, 2, 9] [C:\Program Files\Thunder Network\Thunder\Program\bd.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 16] [C:\Program Files\Thunder Network\Thunder\Program\stream.dll] [, 2, 0, 2, 308] [C:\Program Files\Thunder Network\Thunder\Program\al.dll] [, 1, 1, 2, 9] [C:\Program Files\Thunder Network\Thunder\Program\emule_id.dll] [, 1, 0, 2, 6] [C:\Program Files\Thunder Network\Thunder\Program\XLNet.Dll] [Thunder Networking Technologies,LTD, 1, 4, 5, 21] [C:\Program Files\Thunder Network\Thunder\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 1, 1, 10] [C:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DownAndPlay.dll] [, 1, 0, 11, 29] [C:\Program Files\Thunder Network\Thunder\Program\iTargetAD.dll] [Thunder Networking Technologies,LTD, 1, 0, 3, 34] [C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx] [Adobe Systems, Inc., 10,0,22,87] [G:\新建文件夹 (2)\Rising\Ris\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.62] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll] [ , 1, 0, 2, 24] [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed16.dll] [Thunder Networking Technologies,LTD, 3, 4, 7, 103] [C:\Program Files\Thunder Network\Thunder\Components\InMedia\PlayerHelper.dll] [thunder, 1, 1, 5, 41] [C:\Program Files\Thunder Network\Thunder\Components\InMedia\XLIPC.DLL] [Thunder Networking Technologies,LTD, 1, 0, 0, 2] [C:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll] [Thunder Networking Technologies,LTD, 2, 2, 5, 70] [C:\Program Files\Thunder Network\Thunder\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 1, 5, 0, 16] [C:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 16, 5, 63] [C:\Program Files\Thunder Network\Thunder\Program\MSVCIRT.dll] [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Thunder Network\Thunder\Components\Security\ThunderSafe.dll] [深圳市迅雷网络技术有限公司, 1, 0, 7, 77] [C:\Program Files\Thunder Network\Thunder\Program\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Thunder Network\Thunder\Components\Security\XLSafeUI.dll] [深圳市迅雷网络技术有限公司, 1, 0, 7, 77] [C:\Program Files\Thunder Network\Thunder\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 1, 6, 21] [C:\Program Files\Thunder Network\Thunder\Program\LiveUpdate.dll] [Thunder Networking Technologies,LTD, 1, 2, 3, 25] [C:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin16.dll] [Thunder Networking Technologies,LTD, 3, 1, 4, 76] [C:\Program Files\Thunder Network\Thunder\Plugins\XLSafeHost\XLSafeHost.dll] [深圳市迅雷网络技术有限公司, 1, 0, 7, 59] [C:\Program Files\Thunder Network\Thunder\Plugins\KanKanTop\KanKanTop.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 4] [C:\Program Files\Thunder Network\Thunder\Components\ExplorerHelper\ExplorerHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 18] [C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 4, 23] [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.27] [C:\Program Files\Thunder Network\Thunder\Components\Tips\TipsClient.dll] [Thunder Networking Technologies,LTD, 2, 2, 11, 106] [C:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VPSHELL.dll] [迅雷网络, 3, 0, 1, 33] [C:\Program Files\Thunder Network\Thunder\Components\UserExperience\UserExperience.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 3] [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsXlCom.dll] [, 1, 0, 0, 29] [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\MediaWorker.dll] [Thunder Networking Technologies,LTD, 1, 2, 0, 22] [C:\Program Files\Thunder Network\Thunder\Components\Tips\XLIPC.DLL] [Thunder Networking Technologies,LTD, 1, 0, 0, 2] [C:\Program Files\Thunder Network\Thunder\Components\DownloadStat\DownloadStat.dll] [Thunder Networking Technologies,LTD, 1, 4, 1, 6] [PID: 3484 / new][C:\Documents and Settings\new\桌面\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210] [PID: 3248 / new][C:\Documents and Settings\new\桌面\SREcb03e107.EXE] [Smallfrogs Studio, 2.7.0.1210] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [E:\ast\AST.dll] [超级巡警, 1.0.2.10] [C:\Documents and Settings\new\桌面\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] ================================== 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 127.0.0.1 www.tgxzs.com 127.0.0.1 89382.cn 127.0.0.1 97725.com 127.0.0.1 43242.com 127.0.0.1 gualeifafksajof.43242.com 127.0.0.1 jiaofei123.140.tofor.com 127.0.0.1 ben666888.www1.910idc.com 127.0.0.1 pchorne.com 127.0.0.1 www.ctv163.com 127.0.0.1 www.aiaiso.com 127.0.0.1 cool.47555.com 127.0.0.1 guajfskajiw.43242.com 127.0.0.1 www.3448.com 127.0.0.1 pkdown.3322.org 127.0.0.1 ddos2.sz45.com 127.0.0.1 www.113678.com 127.0.0.1 www.1861.sh 127.0.0.1 www.x44.cn 127.0.0.1 youlove.3322.net 127.0.0.1 tty.yyun.net 127.0.0.1 www.pixpox.com 127.0.0.1 www.k163.com 127.0.0.1 www.9000music.com ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 284, C:\WINDOWS\SOUNDMAN.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2896, C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\THUNDER5.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3484, C:\DOCUMENTS AND SETTINGS\NEW\桌面\SRENGLDR.EXE] ================================== 计划任务 N/A ================================== API HOOK 入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: E:\ast\AST.dll) 入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: E:\ast\AST.dll) ================================== 隐藏进程 N/A ================================== [/CODE]