[CODE] 2009-08-23,20:39:33 System Repair Engineer 2.7.1.1261 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [N/A] <"E:\ruixing\Rising\Ris\RsTray.exe" -system> [(Verified)Beijing Rising Information Technology Corporation Limited] <"E:\ruixing\rstray.exe" /startup> [(Verified)Beijing Rising Information Technology Corporation Limited] <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd] <360Safetray> [(Verified)Qizhi Software (beijing) Co. Ltd] <"C:\WINDOWS\system32\nap32.exe" /run> [Beijing Rising Information Technology Co., Ltd.] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce] [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] [File is missing] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AEB6717E-7E19-11d0-97EE-00C04FD91972}> [(Verified)Microsoft Windows Component Publisher] <{5FC5A1A4-F4DF-4D5F-BD03-42D398BB0C84}> [] <{F1455861-8C40-4095-ABD8-7BEAE5ADF92E}> [] <{762D618C-E2CB-4217-8275-03302A93073F}> [] <{B38E77C6-E3E1-4b0f-BC51-6A8352868C4C}> [File is missing] <{D6129F8A-6F6E-41D7-BBC9-AC7426759CED}> [File is missing] <{1719B301-B494-4185-9379-242461F9CF02}> [] <{24144CB8-10ED-4BFC-843F-68A9F3369947}> [] <{54DE8BF2-906A-445A-8575-CCB08E809495}> [] <{8708994F-1758-4C2C-9A3F-FA22D6CCCB41}> [] <{5405A7B2-F3F5-446F-8715-2A4EF674E079}> [File is missing] <{36AC68E6-0C26-4D39-B98E-54B49DAB6BAA}> [File is missing] <{23DA65D2-C696-4EE4-BEE8-B4841DEC3E30}> [File is missing] <{A761BE8E-C15A-4DDD-A777-2C683E9E96C8}> [File is missing] <{87DE8A1A-96C5-4420-B222-EF998F697CE7}> [] <{69B265A2-A172-4D27-BDF1-917E6D8B1DCC}> [] <{76CBCF38-0583-44C7-A1AE-D463DFE625EC}> [File is missing] <{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}> [File is missing] <{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}> [File is missing] <{427E02E6-39DB-4424-A49C-7553CD1331F5}> [] <{A23CA53C-731F-4033-92E8-C1DFB4E71D34}> [] <{7A713577-C200-4DD2-A00F-F596EAF2E93E}> [] <{53915AE3-2660-4870-B092-C9E5A292D327}> [] <{38FEFE05-702C-440D-AD5C-B796209A1CC5}> [File is missing] <{B4FBFDAA-D831-4CDA-BF0D-68815CE308F0}> [] <{1055CA44-51F8-486B-8CBD-DC7AD4213F1E}> [] <{CD478099-014D-4B3A-A4BB-B518F1019BC7}> [File is missing] <{A5CA6C70-7185-4466-AB45-B1C34E7A37CA}> [File is missing] <{62BED6A8-B183-40CC-B9BE-CCA593DF5D99}> [] <{7BCD75AC-7DF8-4B42-9B00-4FEA1CE14755}> [] <{CD95107F-52A5-42A4-9914-18949993E798}> [] <{51AA0D89-E9A9-4284-93E8-40C0FDD59304}> [] <{9AD1DE62-196C-4C01-9A2F-0BEDEF727C59}> [] <{704C3595-DB85-40F6-A601-8D6F346907BD}> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [File is missing] [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <浏览器自定义组件> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] <%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Publisher] [HKEY_CURRENT_USER\Control Panel\Desktop] [Microsoft] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher] <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [File is missing] <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [File is missing] <; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> [File is missing] ================================== 启动文件夹 [壁纸自动换] C:\WINDOWS\system32\bgswitch.exe [N/A]> ================================== 服务 [Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start] [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [Ris Process Communication Center / RisCCenter][Stopped/Auto Start] [Rising RisTask Manager / RisTask][Running/Auto Start] <"E:\ruixing\Rising\Ris\RavTask.exe" RisTask> [Rising Scan Service / RsScanSrv][Stopped/Auto Start] ================================== 驱动程序 [a320raid / a320raid][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\a320raid.sys> [AAC / AAC][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AAC.SYS> [aar1210 / aar1210][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aar1210.sys> [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start] [adpu320 / adpu320][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\adpu320.sys> [ACARD AEC6210UF UltraDMA33 Controller / aec6210][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aec6210.sys> [ACARD AEC6260 UltraDMA-66 Controller / aec6260][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aec6260.sys> [aec6280 / aec6280][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aec6280.sys> [AEC6290 / AEC6290][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AEC6290.SYS> [AEC67160 / AEC67160][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AEC67160.SYS> [AEC671X / AEC671X][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AEC671X.SYS> [AEC6880 / AEC6880][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AEC6880.SYS> [AEC6890 / AEC6890][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\AEC6890.sys> [aec68x5 / aec68x5][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\aec68x5.sys> [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start] [AliIde / AliIde][Running/Boot Start] <\SystemRoot\System32\DRIVERS\aliide.sys> [AMD K8 Processor Driver / AmdK8][Stopped/Manual Start] [arc / arc][Stopped/Boot Start] <\SystemRoot\system32\drivers\arc.sys> [asc / asc][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\asc.sys> [asc3550 / asc3550][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\asc3550.sys> [ati2mtag / ati2mtag][Running/Manual Start] [CmdIde / CmdIde][Running/Boot Start] <\SystemRoot\System32\DRIVERS\cmdide.sys> [dac2w2k / dac2w2k][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\dac2w2k.sys> [elxstor / elxstor][Stopped/Boot Start] <\SystemRoot\system32\drivers\elxstor.sys> [FASTSX / FASTSX][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\FASTSX.SYS> [fasttrak / fasttrak][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\fasttrak.sys> [fasttx2k / fasttx2k][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\fasttx2k.sys> [fasttx2k2 / fasttx2k2][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\fasttx2k2.sys> [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start] [HpCISSs / HpCISSs][Stopped/Boot Start] <\SystemRoot\system32\drivers\hpcisss.sys> [Hpt366 / Hpt366][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\Hpt366.sys> [HPT371 / HPT371][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\HPT371.sys> [hpt374 / hpt374][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\hpt374.sys> [hpt3xx / hpt3xx][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\hpt3xx.sys> [hptmv / hptmv][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\hptmv.sys> [hptpro / hptpro][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\hptpro.sys> [Intel Integrated RAID / iaStor][Stopped/Boot Start] <\SystemRoot\system32\drivers\iaStor.sys> [iirsp / iirsp][Stopped/Boot Start] <\SystemRoot\system32\drivers\iirsp.sys> [ITERAID_Service_Install / iteraid][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\iteraid.sys> [LSI_SAS / LSI_SAS][Stopped/Boot Start] <\SystemRoot\system32\drivers\lsi_sas.sys> [LSI_SCSI / LSI_SCSI][Stopped/Boot Start] <\SystemRoot\system32\drivers\lsi_scsi.sys> [m5228 / m5228][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\m5228.sys> [m5281 / m5281][Stopped/Boot Start] <\SystemRoot\system32\drivers\m5281.sys> [MegaIDE / MegaIDE][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\MegaIDE.sys> [megasas / megasas][Stopped/Boot Start] <\SystemRoot\system32\drivers\megasas.sys> [mraid2k / mraid2k][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\mraid2k.sys> [mraid35x / mraid35x][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\mraid35x.sys> [nfrd960 / nfrd960][Stopped/Boot Start] <\SystemRoot\system32\drivers\nfrd960.sys> [npkcrypt / npkcrypt][Stopped/Auto Start] <\??\C:\Program Files\QQ2005\npkcrypt.sys> [nv / nv][Stopped/Manual Start] [Intel SCSI Controller / NvAtaBus][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\NVATABUS.SYS> [NVIDIA nForce(tm) RAID Class Driver / nvraid][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\nvraid.sys> [PNP649R / PNP649R][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\PNP649R.SYS> [SiI 680 ATA Controller / Pnp680][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\pnp680.sys> [Silicon Image SiI 0680 Medley Raid Controller / Pnp680r][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\pnp680r.sys> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [ql1080 / ql1080][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ql1080.sys> [ql12160 / ql12160][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ql12160.sys> [ql1280 / ql1280][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ql1280.sys> [QLogic Fibre Channel SCSI Miniport Driver / ql2300][Stopped/Boot Start] <\SystemRoot\system32\drivers\ql2300.sys> [RAIDSRC / RAIDSRC][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\RAIDSRC.SYS> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Running/Manual Start] [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start] [S150SX8 / S150SX8][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\S150SX8.SYS> [Secdrv / Secdrv][Stopped/Manual Start] [SiI-3512 SATALink Controller / SI3112][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3112.sys> [Silicon Image SiI 3512 SATARaid Controller / SI3112r][Stopped/Boot Start] <\SystemRoot\system32\drivers\SI3112r.sys> [SiI-3114 SATALink Controller / SI3114][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3114.sys> [SiI-3114 SATARaid Controller / SI3114r][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3114R.sys> [SiI-3124 SATALink Controller / SI3124][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3124.sys> [SiI-3124 SATARaid Controller / SI3124r][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SI3124R.sys> [SATALink driver accelerator / SiFilter][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SiWinAcc.sys> [SISIDE / SISIDE][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SISIDE.SYS> [SiSRaid / SiSRaid][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SiSRaid.sys> [SiSRaid1 / SiSRaid1][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SiSRaid1.sys> [SISRAIDS / SISRAIDS][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SISRAIDS.SYS> [Sparrow / Sparrow][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\sparrow.sys> [sptrak / sptrak][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\sptrak.sys> [symc810 / symc810][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\symc810.sys> [symc8xx / symc8xx][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\symc8xx.sys> [SYMMPI / SYMMPI][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\SYMMPI.SYS> [sym_hi / sym_hi][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\sym_hi.sys> [sym_u3 / sym_u3][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\sym_u3.sys> [UlSata / UlSata][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ulsata.sys> [ULSATAS / ULSATAS][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ULSATAS.SYS> [ultra / ultra][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\ultra.sys> [ViaIde / ViaIde][Running/Boot Start] <\SystemRoot\system32\DRIVERS\viaidexp.sys> [viamraid / viamraid][Running/Boot Start] <\SystemRoot\system32\DRIVERS\viamraid.sys> [VIA ATA/ATAPI Host Controller / viapdsk][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\viapdsk.sys> [viaraid / viaraid][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\viaraid.sys> [viasraid / viasraid][Stopped/Boot Start] <\SystemRoot\system32\drivers\viasraid.sys> [vmscsi / vmscsi][Stopped/Boot Start] <\SystemRoot\system32\drivers\vmscsi.sys> ================================== 浏览器加载项 [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [微软] {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} [Windows Genuine Advantage Validation Tool] {17492023-C23A-453E-A040-C7C580BBF700} [] {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <, > [360SafeLive] {87515F61-A66C-4319-A0E0-D416CB8059E3} [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [] {C56CB6B0-0D96-11D6-8C65-B2868B609932} <, > [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [] {FB5F1910-F110-11D2-BB9E-00C04F795683} <, > [使用影音传送带下载] [使用影音传送带下载全部链接] [导出到 Microsoft Office Excel(&X)] ================================== 正在运行的进程 [PID: 556 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 628 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 656 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4124] [PID: 700 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [PID: 712 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [PID: 868 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4124] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2499] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 880 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [C:\WINDOWS\system32\nap32.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 1] [PID: 1000 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [PID: 1108 / SYSTEM][E:\ruixing\Rising\Ris\CCENTER.EXE] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [E:\ruixing\Rising\Ris\combase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [E:\ruixing\Rising\Ris\cnt09.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 37] [E:\ruixing\Rising\Ris\cnt08.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1116 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [C:\WINDOWS\system32\nap32.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 1] [PID: 1168 / SYSTEM][E:\ruixing\Rising\Ris\RavTask.exe] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 24] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [E:\ruixing\Rising\Ris\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [E:\ruixing\Rising\Ris\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [E:\ruixing\Rising\Ris\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [E:\ruixing\Rising\Ris\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.19] [E:\ruixing\Rising\Ris\rstask.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 36] [E:\ruixing\Rising\Ris\rsstub.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1252 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [C:\WINDOWS\system32\nap32.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 1] [PID: 1340 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [PID: 1628 / new][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4124] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2499] [C:\WINDOWS\system32\Y4npJWJNr.dll] [N/A, ] [C:\WINDOWS\fonts\UY9BAMKvGrn7yfjF.fon] [N/A, ] [C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\skcfujQ5EDN.dll] [N/A, ] [C:\WINDOWS\fonts\jUxfqJDwmfQEHcy2.fon] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.dll] [N/A, ] [C:\WINDOWS\system32\w7uds3zyayg9.dll] [N/A, ] [C:\WINDOWS\fonts\zEfE48cw9EmcFaR.fon] [N/A, ] [C:\WINDOWS\system32\704C3595.dll] [N/A, ] [C:\WINDOWS\system32\Rwad8sdv4e7V8xpKZ.dll] [N/A, ] [C:\WINDOWS\fonts\E2advSTs3Y7QbBJXYH26aYt.fon] [N/A, ] [PID: 1712 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [PID: 1732 / new][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [C:\WINDOWS\fonts\E2advSTs3Y7QbBJXYH26aYt.fon] [N/A, ] [C:\WINDOWS\system32\Rwad8sdv4e7V8xpKZ.dll] [N/A, ] [C:\WINDOWS\system32\704C3595.dll] [N/A, ] [C:\WINDOWS\fonts\zEfE48cw9EmcFaR.fon] [N/A, ] [C:\WINDOWS\system32\w7uds3zyayg9.dll] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.dll] [N/A, ] [C:\WINDOWS\fonts\SD78dgC7hD2sktQHyAu.fon] [N/A, ] [C:\WINDOWS\fonts\sbzjqregd6tch.fon] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\rfpz9wwyy2np.dll] [N/A, ] [C:\WINDOWS\system32\dhDhwS7fFW.dll] [N/A, ] [C:\WINDOWS\system32\ndxq9awMc.dll] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\fonts\jUxfqJDwmfQEHcy2.fon] [N/A, ] [C:\WINDOWS\system32\skcfujQ5EDN.dll] [N/A, ] [C:\WINDOWS\system32\122B901E.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\WcCtgJ4zcxHF.dll] [N/A, ] [C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ] [C:\WINDOWS\fonts\UY9BAMKvGrn7yfjF.fon] [N/A, ] [C:\WINDOWS\fonts\DGvbbtCNkQVHR6JNYgc.fon] [N/A, ] [C:\WINDOWS\system32\Y4npJWJNr.dll] [N/A, ] [C:\WINDOWS\system32\HFXBt3PgtnqwHXb.dll] [N/A, ] [C:\WINDOWS\fonts\bQgc5yHMSD4yd.fon] [N/A, ] [C:\WINDOWS\system32\SCEVFJRCmaB7.dll] [N/A, ] [C:\WINDOWS\system32\ed78ab9.dll] [N/A, ] [C:\WINDOWS\fonts\uXfWMFY2xWHBUnN.fon] [N/A, ] [C:\WINDOWS\fonts\CWWFj6tF7GvQjNsqc.fon] [N/A, ] [C:\WINDOWS\fonts\tY5UFS434YYd.fon] [N/A, ] [C:\WINDOWS\system32\eNyN5X48HrtXc.dll] [N/A, ] [C:\WINDOWS\system32\mFr9FPruEFZ9VNdrveJunw3.dll] [N/A, ] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [PID: 220 / new][C:\WINDOWS\system32\conime.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [C:\WINDOWS\system32\Y4npJWJNr.dll] [N/A, ] [C:\WINDOWS\fonts\UY9BAMKvGrn7yfjF.fon] [N/A, ] [C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\skcfujQ5EDN.dll] [N/A, ] [C:\WINDOWS\fonts\jUxfqJDwmfQEHcy2.fon] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.dll] [N/A, ] [C:\WINDOWS\system32\w7uds3zyayg9.dll] [N/A, ] [C:\WINDOWS\fonts\zEfE48cw9EmcFaR.fon] [N/A, ] [C:\WINDOWS\system32\704C3595.dll] [N/A, ] [C:\WINDOWS\system32\Rwad8sdv4e7V8xpKZ.dll] [N/A, ] [C:\WINDOWS\fonts\E2advSTs3Y7QbBJXYH26aYt.fon] [N/A, ] [PID: 300 / new][E:\ruixing\Rising\Ris\RsTray.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.22] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [E:\ruixing\Rising\Ris\ComServ.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.49] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [E:\ruixing\Rising\Ris\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 28] [E:\ruixing\Rising\Ris\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [E:\ruixing\Rising\Ris\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [E:\ruixing\Rising\Ris\rsxml.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [E:\ruixing\Rising\Ris\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [E:\ruixing\Rising\Ris\ScanEvnt.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.14] [E:\ruixing\Rising\Ris\rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 73] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [E:\ruixing\Rising\Ris\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [E:\ruixing\Rising\Ris\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [E:\ruixing\Rising\Ris\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.19] [E:\ruixing\Rising\Ris\rspalvd.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.24] [E:\ruixing\Rising\Ris\rsnetsvr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 14] [E:\ruixing\Rising\Ris\ravbintl.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 28] [E:\ruixing\Rising\Ris\MonTray.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.1.0] [E:\ruixing\Rising\Ris\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [E:\ruixing\Rising\Ris\RavITray.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 23] [E:\ruixing\Rising\Ris\ScanPrxy.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.16] [E:\ruixing\Rising\Ris\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [C:\WINDOWS\system32\Y4npJWJNr.dll] [N/A, ] [C:\WINDOWS\fonts\UY9BAMKvGrn7yfjF.fon] [N/A, ] [C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\skcfujQ5EDN.dll] [N/A, ] [C:\WINDOWS\fonts\jUxfqJDwmfQEHcy2.fon] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.dll] [N/A, ] [C:\WINDOWS\system32\w7uds3zyayg9.dll] [N/A, ] [C:\WINDOWS\fonts\zEfE48cw9EmcFaR.fon] [N/A, ] [C:\WINDOWS\system32\704C3595.dll] [N/A, ] [C:\WINDOWS\system32\Rwad8sdv4e7V8xpKZ.dll] [N/A, ] [C:\WINDOWS\fonts\E2advSTs3Y7QbBJXYH26aYt.fon] [N/A, ] [C:\WINDOWS\system32\HFXBt3PgtnqwHXb.dll] [N/A, ] [PID: 308 / new][E:\ruixing\rstray.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.17] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [E:\ruixing\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [E:\ruixing\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [E:\ruixing\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [E:\ruixing\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [E:\ruixing\ComServ.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.31] [E:\ruixing\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [E:\ruixing\rscommon.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.1.1] [E:\ruixing\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [E:\ruixing\pngdll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [E:\ruixing\runiep.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.43] [E:\ruixing\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.11] [E:\ruixing\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [E:\ruixing\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\WINDOWS\system32\Y4npJWJNr.dll] [N/A, ] [C:\WINDOWS\fonts\UY9BAMKvGrn7yfjF.fon] [N/A, ] [C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\skcfujQ5EDN.dll] [N/A, ] [C:\WINDOWS\fonts\jUxfqJDwmfQEHcy2.fon] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.dll] [N/A, ] [C:\WINDOWS\system32\w7uds3zyayg9.dll] [N/A, ] [C:\WINDOWS\fonts\zEfE48cw9EmcFaR.fon] [N/A, ] [C:\WINDOWS\system32\704C3595.dll] [N/A, ] [C:\WINDOWS\system32\Rwad8sdv4e7V8xpKZ.dll] [N/A, ] [C:\WINDOWS\fonts\E2advSTs3Y7QbBJXYH26aYt.fon] [N/A, ] [C:\WINDOWS\fonts\SD78dgC7hD2sktQHyAu.fon] [N/A, ] [C:\WINDOWS\fonts\sbzjqregd6tch.fon] [N/A, ] [C:\WINDOWS\system32\WcCtgJ4zcxHF.dll] [N/A, ] [C:\WINDOWS\fonts\DGvbbtCNkQVHR6JNYgc.fon] [N/A, ] [C:\WINDOWS\system32\HFXBt3PgtnqwHXb.dll] [N/A, ] [C:\WINDOWS\fonts\bQgc5yHMSD4yd.fon] [N/A, ] [C:\WINDOWS\fonts\uXfWMFY2xWHBUnN.fon] [N/A, ] [C:\WINDOWS\fonts\CWWFj6tF7GvQjNsqc.fon] [N/A, ] [C:\WINDOWS\fonts\tY5UFS434YYd.fon] [N/A, ] [C:\WINDOWS\system32\eNyN5X48HrtXc.dll] [N/A, ] [C:\WINDOWS\system32\mFr9FPruEFZ9VNdrveJunw3.dll] [N/A, ] [PID: 368 / new][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [C:\WINDOWS\system32\Y4npJWJNr.dll] [N/A, ] [C:\WINDOWS\fonts\UY9BAMKvGrn7yfjF.fon] [N/A, ] [C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\skcfujQ5EDN.dll] [N/A, ] [C:\WINDOWS\fonts\jUxfqJDwmfQEHcy2.fon] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.dll] [N/A, ] [C:\WINDOWS\system32\w7uds3zyayg9.dll] [N/A, ] [C:\WINDOWS\fonts\zEfE48cw9EmcFaR.fon] [N/A, ] [C:\WINDOWS\system32\704C3595.dll] [N/A, ] [C:\WINDOWS\system32\Rwad8sdv4e7V8xpKZ.dll] [N/A, ] [C:\WINDOWS\fonts\E2advSTs3Y7QbBJXYH26aYt.fon] [N/A, ] [PID: 540 / SYSTEM][E:\ruixing\Rising\Ris\ScanFrm.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.11] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [E:\ruixing\Rising\Ris\combase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [E:\ruixing\Rising\Ris\moncomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [E:\ruixing\Rising\Ris\scansrvp.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.12] [E:\ruixing\Rising\Ris\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [E:\ruixing\Rising\Ris\ScanSrv.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.10] [E:\ruixing\Rising\Ris\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [E:\ruixing\Rising\Ris\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [E:\ruixing\Rising\Ris\ScanRavT.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.25] [E:\ruixing\Rising\Ris\ScanBT.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.44] [E:\ruixing\Rising\Ris\ScanStub.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.9] [E:\ruixing\Rising\Ris\RsLog.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.36] [E:\ruixing\Rising\Ris\ScanAdd.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.17] [E:\ruixing\Rising\Ris\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [E:\ruixing\Rising\Ris\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.19] [E:\ruixing\Rising\Ris\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.36] [E:\ruixing\Rising\Ris\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [E:\ruixing\Rising\Ris\refs.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [E:\ruixing\Rising\Ris\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [E:\ruixing\Rising\Ris\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [E:\ruixing\Rising\Ris\SysMail.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.5] [E:\ruixing\Rising\Ris\mvengine.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [E:\ruixing\Rising\Ris\posttrt.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [E:\ruixing\Rising\Ris\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [E:\ruixing\Rising\Ris\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [E:\ruixing\Rising\Ris\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5] [E:\ruixing\Rising\Ris\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [E:\ruixing\Rising\Ris\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 34] [E:\ruixing\Rising\Ris\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [E:\ruixing\Rising\Ris\scanpe.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [E:\ruixing\Rising\Ris\ur000.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [E:\ruixing\Rising\Ris\urutils.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [E:\ruixing\Rising\Ris\extfile.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 13] [E:\ruixing\Rising\Ris\revm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [E:\ruixing\Rising\Ris\rsstore.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 10] [E:\ruixing\Rising\Ris\extole.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [E:\ruixing\Rising\Ris\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [E:\ruixing\Rising\Ris\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5] [E:\ruixing\Rising\Ris\ur001.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7] [E:\ruixing\Rising\Ris\ur011.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [E:\ruixing\Rising\Ris\ur023.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5] [PID: 588 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [PID: 2224 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ] [C:\WINDOWS\System32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [E:\ruixing\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [E:\ruixing\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [PID: 2284 / new][C:\WINDOWS\system32\wscntfy.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [E:\ruixing\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [E:\ruixing\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\Y4npJWJNr.dll] [N/A, ] [C:\WINDOWS\fonts\UY9BAMKvGrn7yfjF.fon] [N/A, ] [C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\skcfujQ5EDN.dll] [N/A, ] [C:\WINDOWS\fonts\jUxfqJDwmfQEHcy2.fon] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.dll] [N/A, ] [C:\WINDOWS\system32\w7uds3zyayg9.dll] [N/A, ] [C:\WINDOWS\fonts\zEfE48cw9EmcFaR.fon] [N/A, ] [C:\WINDOWS\system32\704C3595.dll] [N/A, ] [C:\WINDOWS\system32\Rwad8sdv4e7V8xpKZ.dll] [N/A, ] [C:\WINDOWS\fonts\E2advSTs3Y7QbBJXYH26aYt.fon] [N/A, ] [PID: 3300 / new][E:\ruixing\Rising\Ris\RsMain.exe] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [E:\ruixing\Rising\Ris\rspalmgr.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.29] [E:\ruixing\Rising\Ris\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [E:\ruixing\Rising\Ris\RSXML.DLL] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [E:\ruixing\Rising\Ris\RsGuiLib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 73] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [E:\ruixing\Rising\Ris\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 28] [E:\ruixing\Rising\Ris\ravbmenu.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 16] [E:\ruixing\Rising\Ris\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [E:\ruixing\Rising\Ris\rspalvd.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.24] [E:\ruixing\Rising\Ris\ravppops.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 15] [E:\ruixing\Rising\Ris\ravbintl.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 28] [E:\ruixing\Rising\Ris\ravpsafe.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.25] [E:\ruixing\Rising\Ris\ScanPrxy.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.16] [E:\ruixing\Rising\Ris\psafecfg.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.19] [E:\ruixing\Rising\Ris\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [E:\ruixing\Rising\Ris\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.19] [C:\WINDOWS\fonts\E2advSTs3Y7QbBJXYH26aYt.fon] [N/A, ] [C:\WINDOWS\system32\Rwad8sdv4e7V8xpKZ.dll] [N/A, ] [C:\WINDOWS\fonts\zEfE48cw9EmcFaR.fon] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.dll] [N/A, ] [C:\WINDOWS\fonts\SD78dgC7hD2sktQHyAu.fon] [N/A, ] [C:\WINDOWS\fonts\sbzjqregd6tch.fon] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\fonts\jUxfqJDwmfQEHcy2.fon] [N/A, ] [C:\WINDOWS\system32\WcCtgJ4zcxHF.dll] [N/A, ] [C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ] [C:\WINDOWS\fonts\UY9BAMKvGrn7yfjF.fon] [N/A, ] [C:\WINDOWS\fonts\DGvbbtCNkQVHR6JNYgc.fon] [N/A, ] [C:\WINDOWS\system32\HFXBt3PgtnqwHXb.dll] [N/A, ] [C:\WINDOWS\fonts\bQgc5yHMSD4yd.fon] [N/A, ] [C:\WINDOWS\fonts\uXfWMFY2xWHBUnN.fon] [N/A, ] [C:\WINDOWS\fonts\CWWFj6tF7GvQjNsqc.fon] [N/A, ] [C:\WINDOWS\fonts\tY5UFS434YYd.fon] [N/A, ] [C:\WINDOWS\system32\eNyN5X48HrtXc.dll] [N/A, ] [C:\WINDOWS\system32\mFr9FPruEFZ9VNdrveJunw3.dll] [N/A, ] [E:\ruixing\Rising\Ris\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [E:\ruixing\Rising\Ris\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [E:\ruixing\Rising\Ris\ravxpage.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 86] [E:\ruixing\Rising\Ris\ravptool.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.20] [E:\ruixing\Rising\Ris\log2file.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.10] [E:\ruixing\Rising\Ris\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [E:\ruixing\Rising\Ris\htmllib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [E:\ruixing\NtLib.dll] [Beijing Rising Information Technology Co., Ltd., 3, 0, 0, 19] [E:\ruixing\SecEx.dll] [Beijing Rising Information Technology Co., Ltd., 3, 0, 0, 15] [E:\ruixing\Rising\Ris\rsvrinfo.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5] [E:\ruixing\Rising\Ris\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [E:\ruixing\Rising\Ris\refs.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [E:\ruixing\Rising\Ris\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [E:\ruixing\Rising\Ris\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [PID: 3616 / new][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [E:\ruixing\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [E:\ruixing\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UrlFilter.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 15] [E:\ruixing\UrlRule.dll] [Beijing Rising Information Technology Co., Ltd., 1.0.0.15] [D:\应用程序\360\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [C:\WINDOWS\fonts\UY9BAMKvGrn7yfjF.fon] [N/A, ] [C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ] [C:\WINDOWS\fonts\jUxfqJDwmfQEHcy2.fon] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.dll] [N/A, ] [C:\WINDOWS\fonts\zEfE48cw9EmcFaR.fon] [N/A, ] [C:\WINDOWS\system32\Rwad8sdv4e7V8xpKZ.dll] [N/A, ] [C:\WINDOWS\fonts\E2advSTs3Y7QbBJXYH26aYt.fon] [N/A, ] [C:\WINDOWS\system32\macromed\flash\Flash85.ocx] [Macromedia, Inc., 8,5,0,133] [C:\WINDOWS\system32\HFXBt3PgtnqwHXb.dll] [N/A, ] [PID: 3512 / new][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [E:\ruixing\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [E:\ruixing\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UrlFilter.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 15] [E:\ruixing\UrlRule.dll] [Beijing Rising Information Technology Co., Ltd., 1.0.0.15] [D:\应用程序\360\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005] [C:\WINDOWS\fonts\UY9BAMKvGrn7yfjF.fon] [N/A, ] [C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ] [C:\WINDOWS\fonts\jUxfqJDwmfQEHcy2.fon] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.dll] [N/A, ] [C:\WINDOWS\fonts\zEfE48cw9EmcFaR.fon] [N/A, ] [C:\WINDOWS\system32\Rwad8sdv4e7V8xpKZ.dll] [N/A, ] [C:\WINDOWS\fonts\E2advSTs3Y7QbBJXYH26aYt.fon] [N/A, ] [C:\WINDOWS\system32\HFXBt3PgtnqwHXb.dll] [N/A, ] [PID: 3500 / new][E:\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.7.1.1261] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [PID: 3936 / new][E:\sreng2\SREcb03e107.EXE] [Smallfrogs Studio, 2.7.1.1261] [C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38] [E:\ruixing\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [E:\ruixing\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\fonts\UY9BAMKvGrn7yfjF.fon] [N/A, ] [C:\WINDOWS\system32\JBn2ypqY23vWX.dll] [N/A, ] [C:\WINDOWS\fonts\jUxfqJDwmfQEHcy2.fon] [N/A, ] [C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.dll] [N/A, ] [C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ] [C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.dll] [N/A, ] [C:\WINDOWS\fonts\zEfE48cw9EmcFaR.fon] [N/A, ] [C:\WINDOWS\system32\Rwad8sdv4e7V8xpKZ.dll] [N/A, ] [C:\WINDOWS\fonts\E2advSTs3Y7QbBJXYH26aYt.fon] [N/A, ] [E:\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [C:\WINDOWS\system32\HFXBt3PgtnqwHXb.dll] [N/A, ] ================================== 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 222.189.239.213 www.568.com 222.189.239.213 www.qq5.com 222.189.239.213 www.haokan123.com 222.189.239.213 www.369.com 222.189.239.213 daohang.google.cn 222.189.239.213 www.7345.com 222.189.239.213 www.6700.cn 222.189.239.213 www.1166.com 222.189.239.213 www.tt98.com 222.189.239.213 www.th123.com 222.189.239.213 www.kk8000.com 222.189.239.213 www.go2000.cn 222.189.239.213 www.v2233.com 222.189.239.213 www.7999.com 222.189.239.213 www.kuku123.com 222.189.239.213 site.baidu.com 222.189.239.213 abc.qq.com 222.189.239.213 www.9991.com 222.189.239.213 www.5566.net 222.189.239.213 www.1ting.com 222.189.239.213 www.cococ.com 222.189.239.213 www.duowan.com 222.189.239.213 xiaonei.com 222.189.239.213 www.51mole.com 222.189.239.213 www.zhulang.com 222.189.239.213 www.9ku.com 222.189.239.213 www.qqjia.com 222.189.239.213 www.1616.net 222.189.239.213 www.265.com 222.189.239.213 hao123.com 222.189.239.213 www.dd360.com 222.189.239.213 www.9348.cn 222.189.239.213 www.2345.com 222.189.239.213 www.zhaodao123.com 222.189.239.213 www.readnovel.com 222.189.239.213 www.kaixin001.com 222.189.239.213 www.7k7k.com 222.189.239.213 www.qidian.com 222.189.239.213 www.4399.com 222.189.239.213 www.hao123.com 222.189.238.32 minix.soso.com 222.189.238.32 hallcenter.ourgame.com 222.189.238.32 music.qq.com 222.189.238.32 adsclick.qq.com 222.189.238.32 adsfile.qq.com 222.189.238.32 adsview.qq.com 222.189.238.32 ic.qzone.qq.com 222.189.238.32 minigame.qq.com 222.189.238.32 www2.im.alisoft.com 222.189.238.32 bbs1.qq.com 222.189.238.32 www.yxnpc.com 222.189.238.32 mag.xunlei.com 222.189.238.32 biz4.sandai.net 222.189.238.32 biz5.sandai.net 222.189.238.32 biz5c.sandai.net 127.0.0.1 localhost ================================== 进程特权扫描 特殊特权被允许: SeDebugPrivilege [PID = 3500, E:\SRENG2\SRENGLDR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3500, E:\SRENG2\SRENGLDR.EXE] ================================== 计划任务 N/A ================================== API HOOK 入口点错误:NtCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003C5A15) 入口点错误:NtCreateKey (危险等级: 高, 被下面模块所HOOK: 0x003C5BB5) 入口点错误:NtLoadDriver (危险等级: 高, 被下面模块所HOOK: 0x003C6305) 入口点错误:NtSetValueKey (危险等级: 高, 被下面模块所HOOK: 0x003C5C85) 入口点错误:NtWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003C5AE5) 入口点错误:ZwCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003C5A15) 入口点错误:ZwCreateKey (危险等级: 高, 被下面模块所HOOK: 0x003C5BB5) 入口点错误:ZwSetValueKey (危险等级: 高, 被下面模块所HOOK: 0x003C5C85) 入口点错误:ZwWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003C5AE5) 入口点错误:CreateServiceA (危险等级: 高, 被下面模块所HOOK: 0x003C5FC5) 入口点错误:CreateServiceW (危险等级: 高, 被下面模块所HOOK: 0x003C6095) 入口点错误:LoadLibraryA (危险等级: 高, 被下面模块所HOOK: 0x003C6CC5) 入口点错误:LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: 0x003C58AD) 入口点错误:CreateFileW (危险等级: 高, 被下面模块所HOOK: 0x003C67E5) 入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: 0x003C6BF5) 入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: 0x003C6A55) ================================== 隐藏进程 N/A ================================== [/CODE]