[CODE] 2010-02-28,20:47:51 System Repair Engineer 2.8.2.1321 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 Windows 安全更新检查 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <; C:\WINDOWS\system32\NeroCheck.exe> [Ahead Software Gmbh] <"C:\Program Files\Rising\AntiSpyware\rstray.exe" /startup> [(Verified)Beijing Rising Information Technology Corporation Limited] <"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [(Verified)RealNetworks, Inc.] <360Safetray><"E:\Program Files\360safe\safemon\360tray.exe" /start> [(Verified)Qizhi Software (beijing) Co. Ltd] <; "C:\WINDOWS\system32\nap32.exe" /run> [Beijing Rising Information Technology Co., Ltd.] [(Verified)Microsoft Corporation] <"E:\Program Files\Rising\Ris\RsTray.exe" -system> [(Verified)Beijing Rising Information Technology Corporation Limited] <> [N/A] <"E:\Program Files\QQ医生 3.1\QQDoctorRTP.exe" /regrun> [(Verified)Tencent Technology(Shenzhen) Company Limited] <360Safebox><"E:\Program Files\360Safebox\SafeBoxTray.exe" /r> [(Verified)Qizhi Software (beijing) Co. Ltd] <; ALCMTR.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher] <; ALCWZRD.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher] <; Ati2mdxx.exe> [ATI Technologies, Inc.] <; "C:\Program Files\GridService\peer.exe" -n Grid> [FS2YOU] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy] <%SystemRoot%\System32\dimsntfy.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <浏览器自定义组件> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] [(Verified)Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; ALCMTR.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher] <; ALCWZRD.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher] <; Ati2mdxx.exe> [ATI Technologies, Inc.] <; "C:\Program Files\GridService\peer.exe" -n Grid> [FS2YOU] <; RTHDCPL.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher] <; SkyTel.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher] <; SOUNDMAN.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher] ================================== 启动文件夹 N/A ================================== 服务 [Adobe LM Service / Adobe LM Service][Stopped/Manual Start] <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"> [Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start] [Contrl Center of Storm Media / ccosm][Running/Auto Start] <北京暴风网际科技有限公司> [Display Desktop 32 Service / Display Desktop 32 Service][Stopped/Auto Start] [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start] <(File is missing)> [Ris Service / RsRisMon][Running/Auto Start] <"E:\Program Files\Rising\Ris\RavMonD.exe"> [System Restore Service / srservice][Stopped/Disabled] C:\WINDOWS\system32\srsvc.dll> [Tencent Software Update Service / TSUSVC][Stopped/Auto Start] <"C:\Program Files\Tencent\QQSoftMgr\1.0.318.203\TencentUpdateSvc.exe" -run> [主动防御 / ZhuDongFangYu][Running/Auto Start] <"E:\Program Files\360safe\deepscan\zhudongfangyu.exe"><360.cn> ================================== 驱动程序 [360SelfProtection / 360SelfProtection][Running/System Start] <360安全中心> [ati2mtag / ati2mtag][Running/Manual Start] [BAPIDRV / BAPIDRV][Running/System Start] <\??\C:\WINDOWS\system32\drivers\BAPIDRV.SYS><360.cn> [EfiSystemMon / EfiMon][Running/System Start] <奇虎网> [Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start] [hookcont / hookcont][Running/System Start] [HookPort / HookPort][Running/Boot Start] <\SystemRoot\System32\Drivers\Hookport.sys><360安全中心> [hooksys / hooksys][Running/System Start] [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start] [Netgroup Packet Filter / NPF][Stopped/Manual Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [Quantum DeepScanner Servers / qutmdserv][Running/System Start] <\??\C:\WINDOWS\system32\drivers\qutmdrv.sys><360.cn> [qutmipc / qutmipc][Running/System Start] <\??\C:\WINDOWS\system32\drivers\qutmipc.sys><360安全中心> [Rising RfwARP Driver / RFWARP][Running/Auto Start] [Rising RfwBase Driver / RfwBase9][Running/Manual Start] [rfwtdi / rfwtdi][Running/Auto Start] <\??\E:\Program Files\Rising\Ris\rfwtdi.sys> [rsassist / rsassist][Running/Auto Start] [rsfwdrv / rsfwdrv][Running/System Start] <\??\E:\Program Files\Rising\Ris\rsfwdrv.sys> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [SafeBoxKrnl / SafeBoxKrnl][Running/System Start] <\??\C:\WINDOWS\system32\drivers\SafeBoxKrnl.sys><360安全中心> [Secdrv / Secdrv][Stopped/Manual Start] [SATALink driver accelerator / SiFilter][Running/Boot Start] <\SystemRoot\system32\DRIVERS\SiWinAcc.sys> [System Restore Filter Driver / sr][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\sr.sys> [TCP/IP Protocol Driver / Tcpip][Running/System Start] [TSKSP / TSKSP][Running/Manual Start] <\??\E:\Program Files\QQ医生 3.1\TSKSP.sys> [NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller / yukonwxp][Running/Manual Start] ================================== 浏览器加载项 [QQCycloneHelper Class] {00000000-12C9-4305-82F9-43058F20E8D2} [WebThunder Browser Helper] {00000AAA-A363-466E-BEF5-9BB68697AA7F} [CTSWebSiteMon Class] {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} [Windows Live Sign-in Helper] {9030D464-4C02-4ABF-8ECC-5164760863C6} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [BlogThisToolbarButton Class] {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} [启动网页迅雷] {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} [] {e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, N/A> [IEFXZTool] {61F0024B-8278-4999-B7E6-2718426D9FE6} [NowStarter Control] {072039AB-2117-4ED5-A85F-9B9EB903E021} [iTrusPTA Class] {1E0DFFCF-27FF-4574-849B-55007349FEDA} [] {4C833081-D026-4FF8-968F-7EAB660D2FBA} <, > [UploadControl Control] {52FF336D-A05D-4A14-A3A1-7B6B4B427F88} [Slide Image Uploader Control] {55027008-315F-4F45-BBC3-8BE119764741} [163Uploader Control] {8686F2A6-DC01-4E8F-BDE3-DCC7DBBAD6AE} [NowStarter Control] {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} [UploadFilePartition Class] {A877BA28-1F7E-4876-B299-50B3199A1A5D} [PhotoUploadCtrlMini Control] {D9306BD1-2325-4C28-8632-B02330C1BB02} [] {E2883E8F-472F-4FB0-9522-AC9BF37916A7} <, > [QQCycloneHelper Class] {00000000-12C9-4305-82F9-43058F20E8D2} [WebThunder Browser Helper] {00000AAA-A363-466E-BEF5-9BB68697AA7F} [WebThunder Class] {03507A1A-E0C5-4404-AA26-205385C0892D} <, > [IE2EMBHO Class] {0A0DDBD3-6641-40B9-873F-BBDD26D6C14E} [InstallHelper Class] {1DABF8D5-8430-4985-9B7F-A30E53D709B3} [] {1F364306-AA45-47B5-9F9D-39A8B94E7EF1} <, > [] {219C3416-8CB2-491A-A3C7-D9FCDDC9D600} <, > [XML DOM Document] {2933BF90-7B36-11D2-B20E-00C04F983E60} [DHTML Edit Control Safe for Scripting for IE5] {2D360201-FFF5-11D1-8D03-00A0C959BC0A} [WebThunder DapPlayer] {2EEDA47E-8D5C-4d7e-B4B6-E16E19218555} [RealPlayer Download and Record Plugin for Internet Explorer] {3049C3E9-B461-4BC5-8870-4C09146192CA} [Zyzzyva] {30FA9641-9CFE-4D71-A3AA-DF8B6FA02FCC} <, > [] {43BEAFD9-E005-483D-A367-146BA6C8A32E} <, > [XML Document] {48123BC4-99D9-11D1-A6B3-00C04FD91555} [QQRightClick Class] {4836C333-208E-4BCE-B30B-00B9545B0F6E} [SkyDrive.Plugin.1] {4990272A-0655-4D80-90A7-C18D0FF7A4A9} [VnetCookie Class] {4E83D567-4697-4F7B-B1F0-A513B01DB89A} [] {61F0024B-8278-4999-B7E6-2718426D9FE6} <, > [XMP Class] {6483F145-A768-4C41-AACC-52D4D7845851} [XDRM] {693571CB-54A3-4E90-9D52-EEAE1334E2D3} [IEFXZHelper] {6A49F431-2A2E-41a5-9080-0F41D1A3AEC1} [IEFXZ] {6A49F431-2A2E-41A5-9080-0F41D1A3AEC2} [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [MUWebControl Class] {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [] {6EBF7485-159F-4BFF-A14F-B9E3AAC4465B} <, > [Active Desktop Mover] {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A> [CTSWebSiteMon Class] {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} [Peer Adapter] {80E18282-3716-48CA-B50C-F7B7F6A32791} <, > [163Uploader Control] {8686F2A6-DC01-4E8F-BDE3-DCC7DBBAD6AE} [360SafeLive] {87515F61-A66C-4319-A0E0-D416CB8059E3} [Microsoft Web Browser] {8856F961-340A-11D0-A96B-00C04FD705A2} [XML DOM Document 6.0] {88D96A05-F192-11D4-A65F-0040963251E5} [XML HTTP 6.0] {88D96A0A-F192-11D4-A65F-0040963251E5} [SSOForPTLogin Class] {8FC1EE75-72B3-4A23-B987-2B1C4C8A611B} [Windows Live Sign-in Helper] {9030D464-4C02-4ABF-8ECC-5164760863C6} [] {962EFB8E-2683-42D4-AC74-AAA4C759B9C6} <, > [OFrameObject Class] {9701758C-4373-482E-B13C-776C048EC890} [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [VersionDetector Class] {9EFF1953-9694-47B1-AEF6-B2A3FE8BFE9B} [APlayer Control] {A9322148-C691-4B9D-91FC-B9C461DBE9DD} [DapCtrl Class] {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [AUDIO__MP3 Moniker Class] {CD3AFA76-B84F-48F0-9393-7EDC34128127} [RealPlayer G2 Control] {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [PhotoUploadCtrlMini Control] {D9306BD1-2325-4C28-8632-B02330C1BB02} [] {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} <, > [] {E2E2DD38-D088-4134-82B7-F2BA38496583} <, > [XML HTTP Request] {ED8C108E-4349-11D2-91A4-00C04F7969E8} [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} [XML DOM Document 3.0] {F5078F32-C551-11D3-89B9-0000F81FE221} [Free Threaded XML DOM Document 3.0] {F5078F33-C551-11D3-89B9-0000F81FE221} [XML HTTP 3.0] {F5078F35-C551-11D3-89B9-0000F81FE221} [XSL Template 3.0] {F5078F36-C551-11D3-89B9-0000F81FE221} [XML HTTP] {F6D90F16-9C73-11D3-B32E-00C04F990BB4} [] {FB5F1910-F110-11D2-BB9E-00C04F795683} <, > [&U使用米人下载并收藏] [&U使用纳米机器人下载并收藏] [&使用QQ旋风下载] [&使用QQ旋风下载全部链接] [使用WEB迅雷下载] [使用WEB迅雷下载全部链接] [使用网页迅雷下载] [使用网页迅雷下载全部链接] [添加到QQ表情] <, > ================================== 正在运行的进程 [PID: 904 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 964 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 992 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4140] [C:\WINDOWS\system32\WgaLogon.dll] [, ] [PID: 1036 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)] [PID: 1048 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 1228 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4140] [C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2503] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 1248 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 1332 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [E:\Program Files\QQ医生 3.1\TSFilter.dll] [Tencent, 2010, 1, 15, 38] [PID: 1492 / SYSTEM][E:\Program Files\Rising\Ris\RavMonD.exe] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [E:\Program Files\Rising\Ris\combase.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 17] [E:\Program Files\Rising\Ris\cnt09.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [E:\Program Files\Rising\Ris\moncomm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 9] [E:\Program Files\Rising\Ris\MonBase.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [E:\Program Files\Rising\Ris\Rslog.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.41] [E:\Program Files\Rising\Ris\mondrv.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [E:\Program Files\Rising\Ris\defmon.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 46] [E:\Program Files\Rising\Ris\moncom08.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [E:\Program Files\Rising\Ris\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 10] [E:\Program Files\Rising\Ris\FileMon.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 29] [E:\Program Files\Rising\Ris\MailMon.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 22] [E:\Program Files\Rising\Ris\HookWeb.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 12] [E:\Program Files\Rising\Ris\rfwlog.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.15] [E:\Program Files\Rising\Ris\rfwrule.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [E:\Program Files\Rising\Ris\rfwsrv.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.2] [E:\Program Files\Rising\Ris\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [E:\Program Files\Rising\Ris\mPorts.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [E:\Program Files\Rising\Ris\rfwdrvc.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [E:\Program Files\Rising\Ris\Rfwdrv.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.5] [E:\Program Files\Rising\Ris\rsnetsvr.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [E:\Program Files\Rising\Ris\RfwArp.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.5] [E:\Program Files\Rising\Ris\urlrule.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [E:\Program Files\Rising\Ris\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [E:\Program Files\Rising\Ris\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [E:\Program Files\Rising\Ris\refs.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [E:\Program Files\Rising\Ris\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [E:\Program Files\Rising\Ris\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [E:\Program Files\Rising\Ris\rfwproxy.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 67] [E:\Program Files\QQ医生 3.1\TSFilter.dll] [Tencent, 2010, 1, 15, 38] [E:\Program Files\Rising\Ris\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [E:\Program Files\Rising\Ris\rsindent.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 11] [E:\Program Files\Rising\Ris\taskplug.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 10] [E:\Program Files\Rising\Ris\scansrvp.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.7] [E:\Program Files\Rising\Ris\cnt08.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [E:\Program Files\Rising\Ris\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [E:\Program Files\Rising\Ris\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [E:\Program Files\Rising\Ris\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [E:\Program Files\Rising\Ris\Hooksys.dll] [Beijing Rising Information Technology Co., Ltd., 24, 0, 0, 3] [E:\Program Files\Rising\Ris\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [E:\Program Files\Rising\Ris\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [E:\Program Files\Rising\Ris\HookCont.dll] [Beijing Rising Information Technology Co., Ltd., 24, 0, 0, 1] [E:\Program Files\Rising\Ris\BACore.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 35] [E:\Program Files\Rising\Ris\bawhite.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [E:\Program Files\Rising\Ris\RSStore.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [E:\Program Files\Rising\Ris\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.22] [E:\Program Files\Rising\Ris\ScanAdd.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.4] [E:\Program Files\Rising\Ris\NComm2.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [E:\Program Files\Rising\Ris\rstask.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [E:\Program Files\Rising\Ris\rsstub.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [E:\Program Files\Rising\Ris\ScanSrv.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.3] [E:\Program Files\Rising\Ris\scanpe.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 10] [E:\Program Files\Rising\Ris\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [E:\Program Files\Rising\Ris\ur000.dat] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [E:\Program Files\Rising\Ris\urutils.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [E:\Program Files\Rising\Ris\revm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [E:\Program Files\Rising\Ris\ur001.dat] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [E:\Program Files\Rising\Ris\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [E:\Program Files\Rising\Ris\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [E:\Program Files\Rising\Ris\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [E:\Program Files\Rising\Ris\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [E:\Program Files\Rising\Ris\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 68] [E:\Program Files\Rising\Ris\scantj.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [E:\Program Files\Rising\Ris\methodex.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [E:\Program Files\Rising\Ris\heurex.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 16] [E:\Program Files\Rising\Ris\pecompd.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [E:\Program Files\Rising\Ris\ScanRavT.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.4] [E:\Program Files\Rising\Ris\ScanBT.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.19] [E:\Program Files\Rising\Ris\ScanStub.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [E:\Program Files\Rising\Ris\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [E:\Program Files\Rising\Ris\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [E:\Program Files\Rising\Ris\urllib.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [E:\Program Files\Rising\Ris\extarch.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 8] [E:\Program Files\Rising\Ris\extcomp.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [E:\Program Files\Rising\Ris\extsfx.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [PID: 1524 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [E:\Program Files\QQ医生 3.1\TSFilter.dll] [Tencent, 2010, 1, 15, 38] [PID: 1684 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [E:\Program Files\QQ医生 3.1\TSFilter.dll] [Tencent, 2010, 1, 15, 38] [PID: 1764 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4140] [C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2503] [C:\WINDOWS\system32\ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4140] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 1864 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 1892 / SYSTEM][E:\Program Files\360safe\deepscan\zhudongfangyu.exe] [360.cn, 3, 2, 0, 1001] [E:\Program Files\360safe\deepscan\CloudCom2.dll] [360.cn, 3, 2, 1, 1003] [E:\Program Files\360safe\deepscan\heavygate.dll] [360.cn, 3, 6, 21, 0] [E:\Program Files\360safe\SoftMgr\360SoftMgrS.dll] [奇虎网, 2, 1, 5, 1010] [E:\Program Files\360safe\deepscan\qutmload.dll] [360.cn, 6, 2, 0, 1007] [PID: 2032 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 504 / Administrator][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [E:\Program Files\alzip\ALZip\AZCTM.dll] [ESTsoft Corp., 9, 1, 7, 0] [E:\Program Files\QQ医生 3.1\TSVulMon.DAT] [Tencent, 2010, 2, 25, 28] [E:\Program Files\WebThunder\WebThunderBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 121] [E:\Program Files\360safe\safemon\safemon.dll] [360安全中心, 5, 2, 0, 1005] [C:\WINDOWS\system32\ShExplzh.dll] [pon software, 3.11.1] [C:\Program Files\Tencent\QQSoftMgr\1.0.318.203\QQSoftExt.dll] [Tencent, 1, 0, 0, 1] [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [C:\WINDOWS\system32\kakaext.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [E:\Program Files\NamiRobot\Data\NamipanExt1.dll] [N/A, ] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\TudouUpload.dll] [www.Tudou.com, 1.1.0.0] [C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305] [PID: 576 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [E:\Program Files\QQ医生 3.1\TSVulMon.DAT] [Tencent, 2010, 2, 25, 28] [PID: 940 / Administrator][C:\Program Files\Rising\AntiSpyware\rstray.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.27] [C:\Program Files\Rising\AntiSpyware\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\Rising\AntiSpyware\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [C:\Program Files\Rising\AntiSpyware\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\AntiSpyware\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Rising\AntiSpyware\ComServ.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.31] [C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\Program Files\Rising\AntiSpyware\rscommon.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.1.1] [C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [C:\Program Files\Rising\AntiSpyware\pngdll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [C:\Program Files\Rising\AntiSpyware\runiep.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.44] [C:\Program Files\Rising\AntiSpyware\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.11] [C:\Program Files\Rising\AntiSpyware\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\AntiSpyware\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [E:\Program Files\QQ医生 3.1\TSFilter.dll] [Tencent, 2010, 1, 15, 38] [PID: 968 / Administrator][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.1.68] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [E:\Program Files\QQ医生 3.1\TSVulMon.DAT] [Tencent, 2010, 2, 25, 28] [PID: 1268 / Administrator][E:\Program Files\Rising\Ris\RsTray.exe] [Beijing Rising Information Technology Co., Ltd., 22.0.0.10] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [E:\Program Files\Rising\Ris\comserv.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.15] [E:\Program Files\Rising\Ris\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [E:\Program Files\Rising\Ris\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [E:\Program Files\Rising\Ris\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [E:\Program Files\Rising\Ris\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [E:\Program Files\Rising\Ris\rsxml.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [E:\Program Files\Rising\Ris\MonState.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [E:\Program Files\Rising\Ris\ScanEvnt.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.3] [E:\Program Files\Rising\Ris\rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 57] [E:\Program Files\Rising\Ris\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [E:\Program Files\Rising\Ris\rfwrule.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [E:\Program Files\Rising\Ris\rspalvd.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.7] [E:\Program Files\Rising\Ris\rsnetsvr.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [E:\Program Files\Rising\Ris\ravbintl.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 22] [E:\Program Files\Rising\Ris\mruleui.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 7] [E:\Program Files\Rising\Ris\MonTray.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.74] [E:\Program Files\Rising\Ris\RavITray.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [E:\Program Files\Rising\Ris\rfwtray.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 39] [E:\Program Files\Rising\Ris\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [E:\Program Files\Rising\Ris\scanleak.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [E:\Program Files\Rising\Ris\ravppops.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 21] [E:\Program Files\Rising\Ris\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [E:\Program Files\Rising\Ris\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [E:\Program Files\Rising\Ris\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [E:\Program Files\Rising\Ris\ScanPrxy.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.4] [E:\Program Files\Rising\Ris\rfwlog.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.15] [E:\Program Files\QQ医生 3.1\TSFilter.dll] [Tencent, 2010, 1, 15, 38] [PID: 1412 / Administrator][E:\Program Files\QQ医生 3.1\QQDoctorRTP.exe] [Tencent, 3, 2, 102, 400] [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\MFC80U.DLL] [Microsoft Corporation, 8.00.50727.4053] [E:\Program Files\QQ医生 3.1\SafeCommon.dll] [Tencent, 1, 40, 1370, 0] [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.DLL] [Microsoft Corporation, 8.00.50727.4053] [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\MFC80CHS.DLL] [Microsoft Corporation, 8.00.50727.4053] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [E:\Program Files\QQ医生 3.1\TSFSEngine.dat] [Tencent, 2009, 3, 11, 7] [E:\Program Files\QQ医生 3.1\TSFileFilter.dat] [tencent, 2007, 12, 5, 01] [E:\Program Files\QQ医生 3.1\TSVulMon.DAT] [Tencent, 2010, 2, 25, 28] [E:\Program Files\QQ医生 3.1\TSFilter.dll] [Tencent, 2010, 1, 15, 38] [E:\Program Files\QQ医生 3.1\TSKSPLIB.dat] [Tencent, 2009, 9, 25, 20] [E:\Program Files\QQ医生 3.1\TSWebMon.dat] [Tencent, 2009, 12, 11, 10] [PID: 584 / Administrator][E:\Program Files\Rising\Ris\RsAgent.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.19] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [E:\Program Files\Rising\Ris\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [E:\Program Files\Rising\Ris\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [E:\Program Files\Rising\Ris\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [E:\Program Files\Rising\Ris\ScanPrxy.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.4] [C:\WINDOWS\msagent\AgentMPx.dll] [Microsoft Corporation, 2.00.0.2115] [PID: 2204 / Administrator][C:\WINDOWS\msagent\AgentSvr.exe] [Microsoft Corporation, 2.00.0.2202] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [E:\Program Files\QQ医生 3.1\TSVulMon.DAT] [Tencent, 2010, 2, 25, 28] [C:\WINDOWS\msagent\AgentDP2.dll] [Microsoft Corporation, 2.00.0.2115] [E:\Program Files\360safe\safemon\safemon.dll] [360安全中心, 5, 2, 0, 1005] [PID: 3120 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [E:\Program Files\QQ医生 3.1\TSFilter.dll] [Tencent, 2010, 1, 15, 38] [PID: 3152 / SYSTEM][E:\Program Files\Storm\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 3, 15] [E:\Program Files\Storm\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [E:\Program Files\QQ医生 3.1\TSFilter.dll] [Tencent, 2010, 1, 15, 38] [PID: 3508 / SYSTEM][C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe] [Microsoft Corp., 1.2.123.0] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 3368 / Administrator][E:\Program Files\QQ软件系列\TT\bin\TTraveler.exe] [Tencent, 4, 8, 0, 733] [E:\Program Files\QQ软件系列\TT\bin\TTUtilWidget.dll] [Tencent, 4, 8, 0, 733] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [E:\Program Files\360safe\safemon\safemon.dll] [360安全中心, 5, 2, 0, 1005] [E:\Program Files\QQ医生 3.1\TSVulMon.DAT] [Tencent, 2010, 2, 25, 28] [E:\Program Files\QQ软件系列\TT\bin\PlatformWidget.dll] [Tencent, 4, 8, 0, 733] [E:\Program Files\QQ软件系列\TT\bin\TTMainFrame.dll] [Tencent, 4, 8, 0, 733] [E:\Program Files\QQ软件系列\TT\bin\TTMBrowser.dll] [Tencent, 4, 8, 0, 733] [E:\Program Files\QQ软件系列\TT\bin\TTabMgr.dll] [Tencent, 4, 8, 0, 733] [E:\Program Files\QQ软件系列\TT\bin\TTStore.dll] [Tencent, 4, 8, 0, 733] [E:\Program Files\QQ软件系列\TT\bin\TTSkin.dll] [Tencent, 4, 8, 0, 733] [E:\Program Files\QQ医生 3.1\TSFilter.dll] [Tencent, 2010, 1, 15, 38] [E:\Program Files\QQ软件系列\TT\bin\TTPluginMng.dll] [Tencent, 4, 8, 0, 733] [E:\Program Files\QQ软件系列\TT\Plugins\3TTWeather\TTWeather.dll] [Tencent, 1.0.0.1] [E:\Program Files\360safe\safemon\urlproc.dll] [360.CN, 1, 0, 0, 1006] [E:\Program Files\QQ软件系列\TT\bin\TTFilter.dll] [Tencent, 4, 8, 0, 733] [E:\Program Files\QQ软件系列\TT\bin\TTNetwork.dll] [Tencent, 4, 8, 0, 733] [E:\Program Files\QQ软件系列\TT\bin\sqlite3.dll] [N/A, ] [C:\WINDOWS\system32\Macromed\Flash\Flash10d.ocx] [Adobe Systems, Inc., 10,0,42,34] [E:\Program Files\QQ软件系列\TT\bin\FavoriteLogical.dll] [Tencent, 4, 8, 0, 733] [C:\WINDOWS\system32\SHDOCLC.DLL] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\JPWB.IME] [常诚研制, 4.00.950] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.1.3416] [E:\Program Files\QQ软件系列\TT\bin\TTHtmlApp.dll] [Tencent, 4, 8, 0, 733] [C:\Program Files\Common Files\Tencent\TXSSO\Bin\SSOPlatform.dll] [Tencent, 1.2.0.23] [C:\Program Files\Common Files\Tencent\TXSSO\Bin\SSOCommon.DLL] [Tencent, 1.2.0.3] [E:\Program Files\QQ软件系列\TT\bin\TSupport.dll] [TENCENT Inc., 1, 2, 11, 201] [PID: 764 / Administrator][C:\Program Files\Rising\AntiSpyware\knownsvr.exe] [Beijing Rising Information Technology Co., Ltd., 6.0.0.14] [C:\Program Files\Rising\AntiSpyware\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.11] [C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [PID: 3040 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [PID: 2796 / Administrator][H:\Temporary File\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.8.2.1321] [PID: 1204 / Administrator][H:\Temporary File\sreng2\SRE9eb05836.EXE] [Smallfrogs Studio, 2.8.2.1321] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [E:\Program Files\360safe\safemon\safemon.dll] [360安全中心, 5, 2, 0, 1005] [E:\Program Files\QQ医生 3.1\TSVulMon.DAT] [Tencent, 2010, 2, 25, 28] [H:\Temporary File\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 TSFilter [TCP/IP] E:\Program Files\QQ医生 3.1\TSFilter.dll(Tencent, Tencent TSFilter) TSFilter [UDP/IP] E:\Program Files\QQ医生 3.1\TSFilter.dll(Tencent, Tencent TSFilter) TSFilter [RAW/IP] E:\Program Files\QQ医生 3.1\TSFilter.dll(Tencent, Tencent TSFilter) TSFilter E:\Program Files\QQ医生 3.1\TSFilter.dll(Tencent, Tencent TSFilter) ================================== Autorun.inf N/A ================================== HOSTS 文件 203.208.39.104 picadaweb.google.com 203.208.39.104 lh1.ggpht.com 203.208.39.104 lh2.ggpht.com 203.208.39.104 lh3.ggpht.com 203.208.39.104 lh4.ggpht.com 203.208.39.104 lh5.ggpht.com 203.208.39.104 lh6.ggpht.com ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 992, C:\WINDOWS\SYSTEM32\WINLOGON.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2204, C:\WINDOWS\MSAGENT\AGENTSVR.EXE] ================================== 计划任务 [已启用] SogouImeMgr.job E:\PROGRA~1\SOGOUI~1\431~1.341\PinyinRepair.exe ================================== Windows 安全更新检查 N/A ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]