[CODE] 2009-12-11,11:06:55 System Repair Engineer 2.8.1.1279 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 Windows 安全更新检查 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [NVIDIA Corporation] <"F:\瑞星\新建文件夹\Rising\Ris\RsTray.exe" -system> [(Verified)Beijing Rising Information Technology Corporation Limited] <360Safetray><"F:\360\新建文件夹\360safe\safemon\360tray.exe" /start> [(Verified)Qizhi Software (beijing) Co. Ltd] <"F:\瑞星\新建文件夹\Rising\Ris\rssafety.exe" /startup> [(Verified)Beijing Rising Information Technology Corporation Limited] <"C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"> [(Verified)"Adobe Systems, Incorporated"] <"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"> [(Verified)"Adobe Systems, Incorporated"] <; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit> [NVIDIA Corporation] <; nwiz.exe /install> [(Verified)NVIDIA Corporation] <; "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray> [Analog Devices, Inc.] <; C:\Program Files\Analog Devices\Core\smax4pnp.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher] <; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [File is missing] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [Microsoft Corporation] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\webcheck.dll> [Microsoft Corporation] [Microsoft Corporation] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy] <%SystemRoot%\System32\dimsntfy.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <浏览器自定义组件> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] <%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] [Microsoft Corporation] ================================== 启动文件夹 N/A ================================== 服务 [Kingsoft Basic Service / kaccore][Stopped/Manual Start] <"C:\Program Files\Kingsoft\KAC\Service\kaccore.exe"> [Windows Installer / MSIServer][Stopped/Manual Start] [NVIDIA Display Driver Service / nvsvc][Running/Auto Start] [Ris Service / RsRisMon][Running/Auto Start] <"F:\瑞星\新建文件夹\Rising\Ris\RavMonD.exe"> [主动防御 / ZhuDongFangYu][Running/Auto Start] <"F:\360\新建文件夹\360safe\deepscan\zhudongfangyu.exe"><360安全中心> ================================== 驱动程序 [360SelfProtection / 360SelfProtection][Running/System Start] <360安全中心> [ADI UAA Function Driver for High Definition Audio Service / ADIHdAudAddService][Running/Manual Start] [AE Audio Service / AEAudio][Running/Manual Start] [AsIO / AsIO][Running/System Start] [BFSDRV / BFSDRV][Running/System Start] <\??\C:\WINDOWS\system32\drivers\bfsdrv.sys><360安全中心> [BREGDRV / BREGDRV][Running/System Start] <\??\C:\WINDOWS\system32\drivers\bregdrv.sys><360安全中心> [EfiSystemMon / EfiMon][Running/System Start] <奇虎网> [Lavalys EVEREST Kernel Driver / EverestDriver][Stopped/Manual Start] <\??\D:\软件\检测软件\everestultimate_build_1053\kerneld.wnt> [Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start] [hookcont / hookcont][Running/System Start] [HookPort / HookPort][Running/Boot Start] <\SystemRoot\System32\Drivers\Hookport.sys><360安全中心> [hooksys / hooksys][Running/System Start] [JMicron Hot-Plug Driver / JGOGO][Running/Boot Start] <\SystemRoot\system32\DRIVERS\JGOGO.sys> [JRAID / JRAID][Running/Boot Start] <\SystemRoot\system32\DRIVERS\jraid.sys> [ATK0110 ACPI UTILITY / MTsensor][Running/Manual Start] <> [nv / nv][Running/Manual Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [Quantum DeepScanner Servers / qutmdserv][Running/Manual Start] <\??\C:\WINDOWS\system32\drivers\qutmdrv.sys><360安全中心> [Rising RfwARP Driver / RFWARP][Running/Auto Start] [Rising RfwBase Driver / RfwBase9][Running/Manual Start] [rfwtdi / rfwtdi][Running/Auto Start] <\??\F:\瑞星\新建文件夹\Rising\Ris\rfwtdi.sys> [rsassist / rsassist][Running/Auto Start] [rsfwdrv / rsfwdrv][Running/System Start] <\??\F:\瑞星\新建文件夹\Rising\Ris\rsfwdrv.sys> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [RsProtect / RsProtect][Running/System Start] [Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver / RTLE8023xp][Running/Manual Start] [Secdrv / Secdrv][Stopped/Manual Start] [SenFilt Service / SenFiltService][Running/Manual Start] [TCP/IP Protocol Driver / Tcpip][Running/System Start] [TOSHIBA UDF2.5 Reader File System Driver / thdudf][Running/Auto Start] ================================== 浏览器加载项 [Adobe PDF Link Helper] {18DF081C-E8AD-4283-A596-FA578C2EBDC3} [QvodExtend] {53AC8551-0DE0-4606-8A1E-A51AF20ADD60} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [信息检索(&R)] {92780B25-18CC-41C8-B9BE-3C9C571A8263} [QvodButton] {82D9671E-0B56-4285-92CD-15BC08B883BB} [InstallHelper Class] {1DABF8D5-8430-4985-9B7F-A30E53D709B3} [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [Adobe PDF Reader Link Helper] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, > [Player Class] {11F2A418-94B2-4e16-9B0C-B00C0435F903} [Adobe PDF Link Helper] {18DF081C-E8AD-4283-A596-FA578C2EBDC3} [InstallHelper Class] {1DABF8D5-8430-4985-9B7F-A30E53D709B3} [HallToolkit Class] {1E36C446-29F0-4773-A3FB-59C5501446EB} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [QvodExtend] {53AC8551-0DE0-4606-8A1E-A51AF20ADD60} [QQLiveFile Class] {6B232760-90F1-41c3-9902-C8552C1D8A72} [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [MUWebControl Class] {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [Active Desktop Mover] {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, (Signed) N/A> [MediaComm Class] {7670648D-461B-42AF-BDFE-46D26AF5EFF2} [] {82D9671E-0B56-4285-92CD-15BC08B883BB} <, > [360SafeLive] {87515F61-A66C-4319-A0E0-D416CB8059E3} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [] {92780B25-18CC-41C8-B9BE-3C9C571A8263} <, > [OFrameObject Class] {9701758C-4373-482E-B13C-776C048EC890} [VersionDetector Class] {9EFF1953-9694-47B1-AEF6-B2A3FE8BFE9B} [APlayer Control] {A9322148-C691-4B9D-91FC-B9C461DBE9DD} [DapCtrl Class] {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} [SearchAssistantOC] {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A> [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [QQLive Class] {D9EBCF5D-3F8F-4b6a-89BA-70577BE73C62} [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Excel(&X)] [查看 Exif 信息(&V)] [添加到QQ表情] ================================== 正在运行的进程 [PID: 856 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 916 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [PID: 940 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\system32\SETUPAPI.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\MSGINA.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\COMCTL32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\cscui.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 984 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [PID: 996 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)] [C:\WINDOWS\system32\setupapi.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1172 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.11.8618] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\system32\SETUPAPI.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\COMCTL32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)] [C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.8618] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1208 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [c:\windows\system32\SETUPAPI.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1276 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1400 / SYSTEM][F:\瑞星\新建文件夹\Rising\Ris\RavMonD.exe] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [F:\瑞星\新建文件夹\Rising\Ris\combase.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 17] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [F:\瑞星\新建文件夹\Rising\Ris\cnt09.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [F:\瑞星\新建文件夹\Rising\Ris\moncomm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 9] [F:\瑞星\新建文件夹\Rising\Ris\MonBase.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [F:\瑞星\新建文件夹\Rising\Ris\Rslog.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.41] [F:\瑞星\新建文件夹\Rising\Ris\mondrv.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [F:\瑞星\新建文件夹\Rising\Ris\defmon.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 45] [F:\瑞星\新建文件夹\Rising\Ris\moncom08.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [F:\瑞星\新建文件夹\Rising\Ris\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 10] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)] [F:\瑞星\新建文件夹\Rising\Ris\FileMon.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 29] [F:\瑞星\新建文件夹\Rising\Ris\MailMon.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 22] [F:\瑞星\新建文件夹\Rising\Ris\HookWeb.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 12] [F:\瑞星\新建文件夹\Rising\Ris\rfwlog.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.14] [F:\瑞星\新建文件夹\Rising\Ris\rfwrule.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [F:\瑞星\新建文件夹\Rising\Ris\rfwsrv.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.2] [F:\瑞星\新建文件夹\Rising\Ris\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [F:\瑞星\新建文件夹\Rising\Ris\mPorts.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [F:\瑞星\新建文件夹\Rising\Ris\rfwdrvc.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [F:\瑞星\新建文件夹\Rising\Ris\Rfwdrv.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.5] [F:\瑞星\新建文件夹\Rising\Ris\rsnetsvr.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [F:\瑞星\新建文件夹\Rising\Ris\RfwArp.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.5] [F:\瑞星\新建文件夹\Rising\Ris\urlrule.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [F:\瑞星\新建文件夹\Rising\Ris\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [F:\瑞星\新建文件夹\Rising\Ris\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [F:\瑞星\新建文件夹\Rising\Ris\refs.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [F:\瑞星\新建文件夹\Rising\Ris\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [F:\瑞星\新建文件夹\Rising\Ris\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [F:\瑞星\新建文件夹\Rising\Ris\rfwproxy.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 55] [F:\瑞星\新建文件夹\Rising\Ris\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [F:\瑞星\新建文件夹\Rising\Ris\rsindent.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 11] [F:\瑞星\新建文件夹\Rising\Ris\taskplug.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 10] [F:\瑞星\新建文件夹\Rising\Ris\scansrvp.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.7] [F:\瑞星\新建文件夹\Rising\Ris\cnt08.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [F:\瑞星\新建文件夹\Rising\Ris\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [F:\瑞星\新建文件夹\Rising\Ris\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [F:\瑞星\新建文件夹\Rising\Ris\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [F:\瑞星\新建文件夹\Rising\Ris\Hooksys.dll] [Beijing Rising Information Technology Co., Ltd., 24, 0, 0, 3] [F:\瑞星\新建文件夹\Rising\Ris\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\瑞星\新建文件夹\Rising\Ris\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\瑞星\新建文件夹\Rising\Ris\HookCont.dll] [Beijing Rising Information Technology Co., Ltd., 24, 0, 0, 1] [F:\瑞星\新建文件夹\Rising\Ris\BACore.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 31] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [F:\瑞星\新建文件夹\Rising\Ris\bawhite.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [F:\瑞星\新建文件夹\Rising\Ris\RSStore.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [F:\瑞星\新建文件夹\Rising\Ris\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.17] [F:\瑞星\新建文件夹\Rising\Ris\ScanAdd.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.4] [F:\瑞星\新建文件夹\Rising\Ris\NComm2.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [F:\瑞星\新建文件夹\Rising\Ris\rstask.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [F:\瑞星\新建文件夹\Rising\Ris\rsstub.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [F:\瑞星\新建文件夹\Rising\Ris\ScanSrv.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.3] [F:\瑞星\新建文件夹\Rising\Ris\scanpe.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 10] [F:\瑞星\新建文件夹\Rising\Ris\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [F:\瑞星\新建文件夹\Rising\Ris\ur000.dat] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [F:\瑞星\新建文件夹\Rising\Ris\urutils.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [F:\瑞星\新建文件夹\Rising\Ris\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [F:\瑞星\新建文件夹\Rising\Ris\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [F:\瑞星\新建文件夹\Rising\Ris\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [F:\瑞星\新建文件夹\Rising\Ris\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [F:\瑞星\新建文件夹\Rising\Ris\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 50] [F:\瑞星\新建文件夹\Rising\Ris\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [F:\瑞星\新建文件夹\Rising\Ris\revm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [F:\瑞星\新建文件夹\Rising\Ris\urllib.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [F:\瑞星\新建文件夹\Rising\Ris\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [F:\瑞星\新建文件夹\Rising\Ris\ur025.dat] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [F:\瑞星\新建文件夹\Rising\Ris\extole.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [F:\瑞星\新建文件夹\Rising\Ris\extarch.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 7] [F:\瑞星\新建文件夹\Rising\Ris\extcomp.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [F:\瑞星\新建文件夹\Rising\Ris\scantj.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [F:\瑞星\新建文件夹\Rising\Ris\methodex.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [F:\瑞星\新建文件夹\Rising\Ris\heurex.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 13] [F:\瑞星\新建文件夹\Rising\Ris\pecompd.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [F:\瑞星\新建文件夹\Rising\Ris\extsfx.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [F:\瑞星\新建文件夹\Rising\Ris\ScanRavT.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.4] [F:\瑞星\新建文件夹\Rising\Ris\ScanBT.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.18] [F:\瑞星\新建文件夹\Rising\Ris\ScanStub.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [PID: 1440 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)] [C:\WINDOWS\System32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\SETUPAPI.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [c:\windows\system32\netshell.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\RASDLG.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 1564 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)] [PID: 1680 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1744 / SYSTEM][F:\360\新建文件夹\360safe\deepscan\zhudongfangyu.exe] [360安全中心, 1, 0, 0, 1010] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [F:\360\新建文件夹\360safe\deepscan\CloudCom2.dll] [360安全中心, 3, 0, 0, 1009] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)] [F:\360\新建文件夹\360safe\SoftMgr\360SoftMgrS.dll] [奇虎网, 2, 1, 5, 1010] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [F:\360\新建文件夹\360safe\deepscan\heavygate.dll] [360安全中心, 3, 6, 11, 0] [F:\360\新建文件夹\360safe\deepscan\qutmload.dll] [360.CN, 1, 0, 0, 1002] [PID: 1992 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 280 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)] [C:\WINDOWS\System32\cscui.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\themeui.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SETUPAPI.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\webcheck.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\stobject.dll] [Microsoft Corporation, 5.1.2600.2135 (xpsp.040518-1812)] [C:\WINDOWS\system32\BatMeter.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\mydocs.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\NETSHELL.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 9.1.0.2009022700] [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS] [, ] [C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.11.8618] [C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.11.8618] [C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.8618] [C:\WINDOWS\system32\nvshell.dll] [, ] [F:\360\新建文件夹\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1022] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [D:\快播\新建文件夹\QvodPlayer\QvodBand.dll] [Shenzhen QVOD Technology Co.,Ltd, 3, 0, 0, 0] [C:\WINDOWS\system32\browselc.dll] [Microsoft Corporation, 6.00.2900.2135 (xpsp.040518-1812)] [PID: 1000 / Administrator][F:\瑞星\新建文件夹\Rising\Ris\RsTray.exe] [Beijing Rising Information Technology Co., Ltd., 22.0.0.10] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [F:\瑞星\新建文件夹\Rising\Ris\comserv.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.15] [F:\瑞星\新建文件夹\Rising\Ris\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [F:\瑞星\新建文件夹\Rising\Ris\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [F:\瑞星\新建文件夹\Rising\Ris\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [F:\瑞星\新建文件夹\Rising\Ris\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [F:\瑞星\新建文件夹\Rising\Ris\rsxml.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [F:\瑞星\新建文件夹\Rising\Ris\MonState.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [F:\瑞星\新建文件夹\Rising\Ris\ScanEvnt.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.3] [F:\瑞星\新建文件夹\Rising\Ris\rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 55] [F:\瑞星\新建文件夹\Rising\Ris\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [F:\瑞星\新建文件夹\Rising\Ris\rfwrule.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [F:\瑞星\新建文件夹\Rising\Ris\rspalvd.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.7] [F:\瑞星\新建文件夹\Rising\Ris\rsnetsvr.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [F:\瑞星\新建文件夹\Rising\Ris\ravbintl.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 21] [F:\瑞星\新建文件夹\Rising\Ris\mruleui.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 7] [F:\瑞星\新建文件夹\Rising\Ris\MonTray.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.72] [F:\瑞星\新建文件夹\Rising\Ris\RavITray.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [F:\瑞星\新建文件夹\Rising\Ris\rfwtray.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 38] [F:\瑞星\新建文件夹\Rising\Ris\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [F:\瑞星\新建文件夹\Rising\Ris\scanleak.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [F:\瑞星\新建文件夹\Rising\Ris\ravppops.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 21] [C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [F:\瑞星\新建文件夹\Rising\Ris\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [F:\瑞星\新建文件夹\Rising\Ris\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [F:\瑞星\新建文件夹\Rising\Ris\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [F:\瑞星\新建文件夹\Rising\Ris\ScanPrxy.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.4] [F:\瑞星\新建文件夹\Rising\Ris\rfwlog.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.14] [C:\WINDOWS\system32\SETUPAPI.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1624 / Administrator][F:\瑞星\新建文件夹\Rising\Ris\rssafety.exe] [Beijing Rising Information Technology Co., Ltd., 4.0.0.38] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1768 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 328 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)] [C:\WINDOWS\System32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2416 / Administrator][D:\腾迅TT\新建文件夹\bin\TTraveler.exe] [Tencent, 4, 44, 0, 8] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [D:\腾迅TT\新建文件夹\bin\TTUtilWidget.dll] [Tencent, 4, 44, 0, 8] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [F:\360\新建文件夹\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1022] [C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [D:\腾迅TT\新建文件夹\bin\PlatformWidget.dll] [Tencent, 4, 44, 0, 8] [D:\腾迅TT\新建文件夹\bin\TTMainFrame.dll] [Tencent, 4, 44, 0, 8] [D:\腾迅TT\新建文件夹\bin\TTStore.dll] [Tencent, 4, 44, 0, 8] [D:\腾迅TT\新建文件夹\bin\TTSkin.dll] [Tencent, 4, 44, 0, 8] [D:\腾迅TT\新建文件夹\bin\TTabMgr.dll] [Tencent, 4, 44, 0, 8] [D:\腾迅TT\新建文件夹\bin\TTMBrowser.dll] [Tencent, 4, 44, 0, 8] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SETUPAPI.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [D:\腾迅TT\新建文件夹\bin\FavoriteLogical.dll] [Tencent, 4, 44, 0, 8] [D:\腾迅TT\新建文件夹\bin\sqlite3.dll] [N/A, ] [D:\腾迅TT\新建文件夹\bin\TTPluginMng.dll] [Tencent, 4, 44, 0, 8] [D:\腾迅TT\新建文件夹\Plugins\3TTWeather\TTWeather.dll] [Tencent, 1.0.0.1] [D:\腾迅TT\新建文件夹\bin\TTFilter.dll] [Tencent, 4, 44, 0, 8] [D:\腾迅TT\新建文件夹\bin\TTNetwork.dll] [Tencent, 4, 44, 0, 8] [F:\瑞星\新建文件夹\Rising\Ris\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 16] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\Macromed\Flash\Flash10d.ocx] [Adobe Systems, Inc., 10,0,42,34] [D:\迅雷\ComDlls\xunleiBHO_Now.dll] [深圳市迅雷网络技术有限公司, 5,9,11,1168] [C:\WINDOWS\system32\ATL71.DLL] [Microsoft Corporation, 7.10.6101.0] [PID: 2268 / Administrator][C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\ThunderService.exe] [深圳市迅雷网络技术有限公司, 1, 0, 2, 56] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp.060825-0040)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [F:\360\新建文件夹\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1022] [C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\XLBugHandler.dll] [, 2, 1, 0, 8] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\UpdateCtrl.dll] [, 2, 5, 2, 215] [C:\WINDOWS\system32\SETUPAPI.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\download_engine.dll] [Thunder Networking Technologies,LTD, 3, 4, 2, 363] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\mp.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 7] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\XLCrypto.dll] [N/A, ] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\UACTool.dll] [N/A, ] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\asyn_frame.dll] [Thunder Networking Technologies,LTD, 1, 4, 2, 39] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\backend_agent.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 40] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\zlib1.dll] [, 1.2.3] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\ptl.dll] [Thunder Networking Technologies,LTD, 3, 2, 2, 79] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\dl_peer_id.dll] [Thunder Networking Technologies,LTD, 3, 1, 2, 7] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\p2p_upload.dll] [Thunder Networking Technologies,LTD, 1,1,2,16] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\p2p.dll] [Thunder Networking Technologies,LTD, 1,1,2,81] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\fs.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 21] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\stream.dll] [ShenZhen Thunder Networking Technologies,Ltd., 2, 1, 2, 1085] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\p2sp.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 97] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\down_dispatcher.dll] [Thunder Networking Technologies,LTD, 1,0,2,53] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\p2p_local_res.dll] [Thunder Networking Technologies,LTD, 1,1,2,22] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\al.dll] [Thunder Networking Technologies,LTD, 1,1,2,47] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\media_data.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 10] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\task_report.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 6] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\module_downloader.dll] [, 1, 0, 2, 16] [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.56\mini_unzip_dll.dll] [N/A, ] [PID: 3012 / SYSTEM][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\system32\wuaucpl.cpl] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 3824 / Administrator][C:\Documents and Settings\Administrator\桌面\sreng2(1)\SREngLdr.EXE] [Smallfrogs Studio, 2.8.1.1279] [C:\WINDOWS\system32\user32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [PID: 3844 / Administrator][C:\Documents and Settings\Administrator\桌面\sreng2(1)\SREa2f45f7e.EXE] [Smallfrogs Studio, 2.8.1.1279] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [F:\360\新建文件夹\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1022] [C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\Documents and Settings\Administrator\桌面\sreng2(1)\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [C:\WINDOWS\system32\SETUPAPI.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 127.0.0.1 858656.com 127.0.0.1 my123.com 127.0.0.1 8749.com 127.0.0.1 4199.com 127.0.0.1 7379.com 127.0.0.1 7255.com 127.0.0.1 3448.com 127.0.0.1 7939.com 127.0.0.1 8009.com 127.0.0.1 piaoxue.com 127.0.0.1 kzdh.com 127.0.0.1 about.blank.la 127.0.0.1 6781.com 127.0.0.1 7322.com ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 940, C:\WINDOWS\SYSTEM32\WINLOGON.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1172, C:\WINDOWS\SYSTEM32\NVSVC32.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 280, C:\WINDOWS\EXPLORER.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3012, C:\WINDOWS\SYSTEM32\WUAUCLT.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3824, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\SRENG2(1)\SRENGLDR.EXE] ================================== 计划任务 N/A ================================== Windows 安全更新检查 Microsoft .NET Framework 版本 1.1,简体中文版 KB829019, Microsoft .NET Framework 2.0 语言包:x86 (KB829019) KB941569, 用于附带 Windows Media Format Runtime 9.5 和 11 的 Windows XP 的安全更新程序 (KB941569) MS07-068 KB925850, Windows Media Player 11 KB940157, 用于 Windows XP 的 Windows 搜索 4.0 (KB940157) KB929399, 用于 Windows XP 的 Windows Media Format 11 SDK 更新程序 (KB929399) KB949810, Office 正版增值计划通知 (KB949810)-CHS KB926140, 用于 Windows XP 的 Windows PowerShell 1.0 (KB926140) KB905474, Windows Genuine Advantage 通知 (KB905474) KB909520, Microsoft 基本智能卡加密服务提供程序包: x86 (KB909520) KB967642, 2007 Microsoft Office system 更新 (KB967642) KB963678, Microsoft Office Excel 2007 帮助更新 (KB963678) KB963677, Microsoft Office Outlook 2007 帮助更新 (KB963677) KB963669, Microsoft Office PowerPoint 2007 帮助更新 (KB963669) KB963665, Microsoft Office Word 2007 帮助更新 (KB963665) KB953195, 2007 Microsoft Office 套件 Service Pack 2 (SP2) KB969693, Microsoft Office Publisher 2007 安全更新 (KB969693) MS09-030 KB944036, 用于 Windows XP 的 Internet Explorer 8 KB974331, Microsoft Silverlight (KB974331) KB974331, Windows Live 软件包 KB974234, 2007 Microsoft Office system 安全更新 (KB974234) MS09-060 KB973709, Microsoft Office Visio Viewer 2007 安全更新 (KB973709) MS09-060 KB951847, Microsoft .NET Framework 3.5 Service Pack 1 和用于 .NET 版本 2.0 至 3.5 的 .NET Framework 3.5 Family Update (KB951847) x86 KB952069, Windows XP Service Pack 3 安全更新程序 (KB952069) MS08-076 KB931125, 根证书更新 [2009 年 11 月] (KB931125) KB970430, Windows XP 更新程序 (KB970430) KB971737, Windows XP 更新程序 (KB971737) KB955759, Windows XP 更新程序 (KB955759) KB976416, Microsoft Office InfoPath 2007 更新 (KB976416) ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]