[CODE] 2010-03-12,21:17:26 System Repair Engineer 2.8.2.1321 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 Windows 安全更新检查 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <360Safetray><"C:\Program Files\360safe\safemon\360tray.exe" /start> [(Verified)Qizhi Software (beijing) Co. Ltd] [] [(Verified)Microsoft Windows Component Publisher] [NVIDIA Corporation] [NVIDIA Corporation] [(Verified)Microsoft Windows Hardware Compatibility Publisher] <"C:\Program Files\Rising\Rfw\RsTray.exe" -system> [(Verified)Beijing Rising Information Technology Corporation Limited] [File is missing] [www.XDeskSoft.com] <"D:\瑞星\Rising\Rav\RsTray.exe" -system> [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce] [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Component Publisher] [Stardock.net, Inc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy] <%SystemRoot%\System32\dimsntfy.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}] [(Verified)Microsoft Windows] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] <"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <浏览器自定义组件> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] [(Verified)Microsoft Corporation] [HKEY_CURRENT_USER\Control Panel\Desktop] [] ================================== 启动文件夹 N/A ================================== 服务 [Adobe LM Service / Adobe LM Service][Stopped/Manual Start] <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"> [Application Interface Open Service / AOIS][Stopped/Auto Start] <(File is missing)> [Dopool_Schedule / Dopool_Schedule][Stopped/Manual Start] <(File is missing)> [getPlus(R) Helper / getPlus(R) Helper][Stopped/Manual Start] [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [ICBC Daemon Service / ICBC Daemon Service][Stopped/Manual Start] [InstallDriver Table Manager / IDriverT][Stopped/Manual Start] <"C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe"> [Kingsoft Basic Service / kaccore][Stopped/Manual Start] <"C:\Program Files\Kingsoft\KAC\Service\kaccore.exe"> [NVIDIA Display Driver Service / NVSvc][Running/Auto Start] [Private Folder Service / prfldsvc][Running/Auto Start] [Rav Service / RsRavMon][Running/Auto Start] <"D:\瑞星\Rising\Rav\RavMonD.exe"> [RFW Service / RsRFWMon][Running/Auto Start] <"C:\Program Files\Rising\Rfw\RavMonD.exe"> [Windows Live Setup Service / WLSetupSvc][Stopped/Manual Start] <"C:\Program Files\Windows Live\installer\WLSetupSvc.exe"> [主动防御 / ZhuDongFangYu][Stopped/Manual Start] <"C:\Program Files\360safe\deepscan\zhudongfangyu.exe"><360.cn> ================================== 驱动程序 [00044562 / 00044562][Stopped/Manual Start] <\??\C:\WINDOWS\system32\Drivers\00044562.sys> [360SelfProtection / 360SelfProtection][Running/System Start] <360安全中心> [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start] [AntiARP NDIS Protocol Driver / AntiArpNdisProt][Running/Auto Start] [BAPIDRV / BAPIDRV][Running/System Start] <\??\C:\WINDOWS\system32\drivers\BAPIDRV.SYS><360.cn> [BIOS / BIOS][Running/System Start] <\??\C:\WINDOWS\system32\drivers\BIOS.sys> [EagleNT / EagleNT][Stopped/Manual Start] <\??\C:\WINDOWS\system32\drivers\EagleNT.sys> [EfiSystemMon / EfiMon][Running/System Start] <奇虎网> [hookcont / hookcont][Running/System Start] [HookPort / HookPort][Running/Boot Start] <\SystemRoot\System32\Drivers\Hookport.sys><360安全中心> [hooksys / hooksys][Running/System Start] [iw5vjmm / iw5vjmm][Stopped/Auto Start] <\??\C:\WINDOWS\system32\drivers\iw5vjmm.sys> [nocashio / nocashio][Stopped/Manual Start] [NetGroup Packet Filter Driver / NPF][Stopped/Manual Start] [npkcrypt / npkcrypt][Stopped/Auto Start] <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys> [nv / nv][Running/Manual Start] [nvata / nvata][Running/Boot Start] <\SystemRoot\system32\DRIVERS\nvata.sys> [oreans32 / oreans32][Running/System Start] <\??\C:\WINDOWS\system32\drivers\oreans32.sys> [Prvflder / Prvflder][Running/Auto Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [PxHelp20 / PxHelp20][Running/Boot Start] <\SystemRoot\System32\Drivers\PxHelp20.sys> [qgd6n / qgd6ne][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\qgd6ne.sys> [Quantum DeepScanner Servers / qutmdserv][Running/System Start] <\??\C:\WINDOWS\system32\drivers\qutmdrv.sys><360.cn> [qutmipc / qutmipc][Running/System Start] <\??\C:\WINDOWS\system32\drivers\qutmipc.sys><360安全中心> [Rising RfwARP Driver / RFWARP][Running/Auto Start] [Rising RfwBase Driver / RfwBase9][Running/Manual Start] [rfwtdi / rfwtdi][Running/Auto Start] <\??\C:\Program Files\Rising\Rfw\rfwtdi.sys> [rsassist / rsassist][Running/Auto Start] [rsfwdrv / rsfwdrv][Running/System Start] <\??\C:\Program Files\Rising\Rfw\rsfwdrv.sys> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Running/Manual Start] [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start] [SafeBoxKrnl / SafeBoxKrnl][Running/System Start] <\??\C:\WINDOWS\system32\drivers\SafeBoxKrnl.sys><360安全中心> [Secdrv / Secdrv][Stopped/Manual Start] [sptd / sptd][Stopped/Disabled] [TCP/IP Protocol Driver / Tcpip][Running/System Start] [TesSafe / TesSafe][Stopped/Manual Start] <\??\C:\WINDOWS\system32\TesSafe.sys> [TSKSP / TSKSP][Stopped/Manual Start] <\??\C:\Program Files\Tencent\QQ\QQDoctor\TSKSP.sys> [Virtual CD-ROM Device Driver / vcdrom][Stopped/System Start] <\??\F:\新建文件夹\WinxpVirtualCDControlPanel\VCdRom.sys> [vcs / vcs][Stopped/Auto Start] <\??\F:\倚天\新建文件夹\语音变声器 V3.0\AV VCS 3.0\vcs.sys> [xAntiArpSpoof Service / xAntiArp][Running/Manual Start] [微软-中星微联合实验室提供 / ZSMC301b][Stopped/Manual Start] [360FkAdv / 360FkAdv][Stopped/] <2 - 系统找不到指定的文件。 > [64109 / 64109][Stopped/] <2 - 系统找不到指定的文件。 > ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [Adobe PDF Reader Link Helper] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [Adobe PDF Link Helper] {18DF081C-E8AD-4283-A596-FA578C2EBDC3} [FG2CatchUrl] {1F364306-AA45-47B5-9F9D-39A8B94E7EF1} [RealPlayer Download and Record Plugin for Internet Explorer] {3049C3E9-B461-4BC5-8870-4C09146192CA} [WebDetectorBHO Class] {43BEAFD9-E005-483D-A367-146BA6C8A32E} [QvodExtend] {53AC8551-0DE0-4606-8A1E-A51AF20ADD60} [helper Class] {59BCCD49-3755-4EFA-96B5-727E619CF859} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [Download_Bho Class] {A986E409-30CC-4185-89BB-AB212C104524} [FlashGetBHO] {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [ICBC Anti-Phishing class] {BB4491A2-D11A-4c6b-91C0-B53246A3122B} [WanWanCom Class] {E7C5259E-52D0-459B-AA9D-41AD25E79AFD} [BlogThisToolbarButton Class] {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} [中国移动手机桌面助理] {8806E443-0E06-4ed9-86D3-0C2D959F83DD} [PPLive] {95B3F550-91C4-4627-BCC4-521288C52977} [启动UUSee 网络电视] {998A88A0-A355-809B-831C-B83A80000992} [] {e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, (Signed) N/A> [Messenger] {FB5F1910-F110-11d2-BB9E-00C04F795683} [波波虎下载播放列表] {4907A6EA-67FC-4466-83A0-FCDEF915A820} [QvodButton] {82D9671E-0B56-4285-92CD-15BC08B883BB} [MMCPlayer Class] {05C1004E-2596-48E5-8E26-39362985EEB9} [PhotoDrawEx Class] {05F5F404-7C24-4B39-B5CC-340CEDEB9C0D} [] {070CA17A-4BD2-4612-83B4-32B1B9159B47} <, > [Windows Genuine Advantage Validation Tool] {17492023-C23A-453E-A040-C7C580BBF700} [updatePanelX Control] {43E839C5-E10F-443A-BC1F-F09CFD2ABC77} [WEBChatRoomOCX Control] {448A5F6B-8C03-4B54-A338-F00237C508AD} [XIsOro Control] {48FE89A0-486C-48DF-9DEC-BED22BDC6057} [XPPIECtrl Class] {5AB1EF72-6CC6-4090-9030-8E0ACF7E6D3E} [ICBC Security Ctrl] {5AB9367B-DD7F-411D-A030-DF7DE5E17AAE} [] {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} <, > [] {72B15B25-2EC8-4CDD-B284-C89A5F8E8D5F} <, > [DLoader Class] {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} [Java Plug-in 1.6.0_04] {8AD9C840-044E-11D1-B3E9-00805F499D93} [AxSubmitControl Class] {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} [] {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <, > [fish Class] {9F87D0DE-5D4F-421E-8B48-AE6C56AE2DBD} [UploadFilePartition Class] {A877BA28-1F7E-4876-B299-50B3199A1A5D} [CCTVUpdateInstall] {AC414988-E5BB-4C2C-873B-EA53D2F3D23A} [InfoSecICBCNetSign Class] {B1FBC1AD-5644-4084-882A-0F8BA85E7506} [ScreenCapture Class] {B4D9857D-8A55-4442-A577-6B3ED5D4E41B} [Tencent Safety Online Base Module] {C09B522F-8AED-4E21-A65C-DC1AB652BAEE} [Java Plug-in 1.6.0_04] {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} [Java Plug-in 1.6.0_04] {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [get_atlcom Class] {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [金山毒霸在线产品升级] {E847C78C-C210-4195-8799-FBF3BF89797D} [ForceP2PPlayer Object] {FCD61199-E187-4ADD-88E5-9AF238486D11} [] {00000000-12C9-4305-82F9-43058F20E8D2} <, > [] {00000AAA-A363-466E-BEF5-9BB68697AA7F} <, > [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [] {03507A1A-E0C5-4404-AA26-205385C0892D} <, > [Adobe PDF Reader Link Helper] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, > [] {100EB1FD-D03E-47FD-81F3-EE91287F9465} <, > [IFlashGetNetscapeEx Class] {116BA71C-8187-4F15-9A1F-C9D6289155D1} [Fade] {16B280C5-EE70-11D1-9066-00C04FD9189D} [Adobe PDF Link Helper] {18DF081C-E8AD-4283-A596-FA578C2EBDC3} [PIPI Link Helper] {1A3440C6-F123-4CAB-84EE-C814E1AE0D8F} [InstallHelper Class] {1DABF8D5-8430-4985-9B7F-A30E53D709B3} [] {1E1B2878-88FF-11D2-8D96-D7ACAC953D1F} <, > [] {1E1B2879-88FF-11D2-8D96-D7ACAC95951F} <, > [] {1E1B2879-88FF-11D2-8D96-D7ACAC95953C} <, > [PIPI Link Helper] {1E315374-71A5-471A-B683-4C4ADB5C588B} [HallToolkit Class] {1E36C446-29F0-4773-A3FB-59C5501446EB} [FG2CatchUrl] {1F364306-AA45-47B5-9F9D-39A8B94E7EF1} [] {219C3416-8CB2-491A-A3C7-D9FCDDC9D600} <, > [] {2318C2B1-4965-11D4-9B18-009027A5CD4F} <, > [HTML Document] {25336920-03F9-11CF-8FD0-00AA00686F13} [XML DOM Document] {2933BF90-7B36-11D2-B20E-00C04F983E60} [JetCarNetscape Class] {2974c985-8151-4de5-b23c-b875f0a8522f} [DHTML Edit Control Safe for Scripting for IE5] {2D360201-FFF5-11D1-8D03-00A0C959BC0A} [Vod Class] {2EEDA47E-8D5C-4d7e-B4B6-E16E19218555} [RealPlayer Download and Record Plugin for Internet Explorer] {3049C3E9-B461-4BC5-8870-4C09146192CA} [] {367E0A21-8601-4986-9C9A-153BF5ACA118} <, > [] {38928D4F-8A48-44C2-945F-D2F23F771410} <, > [] {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <, > [WebDetectorBHO Class] {43BEAFD9-E005-483D-A367-146BA6C8A32E} [XML Document] {48123BC4-99D9-11D1-A6B3-00C04FD91555} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [] {4907A6EA-67FC-4466-83A0-FCDEF915A820} <, > [Microsoft Terminal Services Client Control (redist)] {4eb89ff4-7f78-4a0f-8b8d-2bf02e94e4b2} <%systemroot%\system32\mstscax.dll, (Signed) N/A> [Microsoft Terminal Services Client Control (redist)] {4EDCB26C-D24C-4e72-AF07-B576699AC0DE} <%systemroot%\system32\mstscax.dll, (Signed) N/A> [VaCom.Application] {51E88884-1306-4444-B22D-C34119E44232} [QvodExtend] {53AC8551-0DE0-4606-8A1E-A51AF20ADD60} [isInstalled Class] {5852F5ED-8BF4-11D4-A245-0080C6F74284} [helper Class] {59BCCD49-3755-4EFA-96B5-727E619CF859} [Jfchk Class] {632C6705-17AB-4407-9281-F60D0A7726BE} [XMP Class] {6483F145-A768-4C41-AACC-52D4D7845851} [XDRM] {693571CB-54A3-4E90-9D52-EEAE1334E2D3} [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [Microsoft Terminal Services Client Control (redist)] {7390f3d8-0439-4c05-91e3-cf5cb290c3d0} <%systemroot%\system32\mstscax.dll, (Signed) N/A> [AxInputControl Class] {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} [Microsoft Terminal Services Client Control (redist)] {7584c670-2274-4efb-b00b-d6aaba6d3850} <%systemroot%\system32\mstscax.dll, (Signed) N/A> [] {77FEF28D-EB96-44FF-B511-3185DEA48697} <, > [] {77FEF28E-EB96-44FF-B511-3185DEA48697} <, > [DLoader Class] {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} [] {7E853D72-626A-48EC-A868-BA8D5E23E045} <, > [XDownloaddManager Class] {802F530B-A8F6-4631-AE49-6BACAAC6373E} [] {82D9671E-0B56-4285-92CD-15BC08B883BB} <, > [] {83B80A9C-D91A-4F22-8DCF-EA7204039F79} <, > [360SafeLive] {87515F61-A66C-4319-A0E0-D416CB8059E3} [] {8806E443-0E06-4ED9-86D3-0C2D959F83DD} <, > [Microsoft Web Browser] {8856F961-340A-11D0-A96B-00C04FD705A2} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [XML DOM Document 6.0] {88D96A05-F192-11D4-A65F-0040963251E5} [AxSubmitControl Class] {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} [SSOForPTLogin Class] {8FC1EE75-72B3-4A23-B987-2B1C4C8A611B} [Windows Live 登录帮助程序] {9030D464-4C02-4ABF-8ECC-5164760863C6} [Microsoft Terminal Services Client Control (redist)] {9059f30f-4eb1-4bd2-9fdc-36f43a218f4a} <%systemroot%\system32\mstscax.dll, (Signed) N/A> [] {95B3F550-91C4-4627-BCC4-521288C52977} <, > [] {962EFB8E-2683-42D4-AC74-AAA4C759B9C6} <, > [FGDownMgr] {97F14F61-B206-4F9E-B6A4-318E80B13440} [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [] {998A88A0-A355-809B-831C-B83A80000991} <, > [] {998A88A0-A355-809B-831C-B83A80000992} <, > [VersionDetector Class] {9EFF1953-9694-47B1-AEF6-B2A3FE8BFE9B} [fish Class] {9F87D0DE-5D4F-421E-8B48-AE6C56AE2DBD} [] {A26ABCF0-1C8F-46E7-A67C-0489DC21B9CE} <, > [] {A26ABCF0-1C8F-46E7-A67C-0489DC21B9EE} <, > [] {A412E581-59B2-485E-834F-C5F0C0268C79} <, > [] {A5366673-E8CA-11D3-9CD9-0090271D075B} <, > [] {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EF} <, > [APlayer Control] {A9322148-C691-4B9D-91FC-B9C461DBE9DD} [Download_Bho Class] {A986E409-30CC-4185-89BB-AB212C104524} [RMGetLicense Class] {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} [] {AA58ED58-01DD-4D91-8333-CF10577473F7} <, > [DapCtrl Class] {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} [] {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <, > [] {AFF6E516-CBE5-4F8A-9C2F-38A68013E766} <, > [FlashGetBHO] {B070D3E3-FEC0-47D9-8E8A-99D4EEB3D3B0} [InfoSecICBCNetSign Class] {B1FBC1AD-5644-4084-882A-0F8BA85E7506} [] {B580CF65-E151-49C3-B73F-70B13FCA8E86} <, > [] {B69F34DC-F0F9-42DC-9EDD-957187DA688D} <, > [SafeMon Class] {B69F34DD-F0F9-42DC-9EDD-957187DA688D} [ICBC Anti-Phishing class] {BB4491A2-D11A-4C6B-91C0-B53246A3122B} [] {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <, > [] {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <, > [] {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} <, > [] {C5428486-50A0-4A02-9D20-520B59A9F9B2} <, > [] {C5428486-50A0-4A02-9D20-520B59A9F9B3} <, > [] {C95FE080-8F5D-11D2-A20B-00AA003C157B} <, > [Microsoft Url Search Hook] {CFBFAE00-17A6-11D0-99CB-00C04FD64497} [] {D18A0B52-D63C-4ED0-AFC6-C1E3DC1AF43A} <, > [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [OfficeObj Class] {D2BD7935-05FC-11D2-9059-00C04FD7A1BD} <, > [] {D6E814A0-E0C5-11D4-8D29-0050BA6940E3} <, > [] {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <, > [] {DEDEB80D-FA35-45D9-9460-4983E5A8AFE6} <, > [Microsoft Silverlight] {DFEAF541-F3E1-4C24-ACAC-99C30715084A} [] {E0E899AB-F487-11D5-8D29-0050BA6940E3} <, > [] {E2E2DD38-D088-4134-82B7-F2BA38496583} <, > [] {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <, > [WanWanCom Class] {E7C5259E-52D0-459B-AA9D-41AD25E79AFD} [TimwpDll.TimwpCheck] {ED4CA2E5-0EEA-44C1-AD7E-74A07A7507A4} [XML HTTP Request] {ED8C108E-4349-11D2-91A4-00C04F7969E8} [PPLive Lite Class] {EF0D1A14-1033-41A2-A589-240C01EDC078} [XML HTTP] {F6D90F16-9C73-11D3-B32E-00C04F990BB4} [] {FB5F1910-F110-11D2-BB9E-00C04F795683} <, > [&A使用波波虎流畅播放] [&A加入波波虎下载播放列表] [使用迅雷下载] [使用迅雷下载全部链接] ================================== 正在运行的进程 [PID: 1124 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 1304 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 1328 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [PID: 1372 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)] [PID: 1384 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [PID: 1556 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.11.9062] [C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.9062] [PID: 1604 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 1708 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 1864 / SYSTEM][D:\瑞星\Rising\Rav\RavMonD.exe] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [D:\瑞星\Rising\Rav\combase.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 17] [D:\瑞星\Rising\Rav\cnt09.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [D:\瑞星\Rising\Rav\moncomm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 9] [D:\瑞星\Rising\Rav\MonBase.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [D:\瑞星\Rising\Rav\Rslog.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.41] [D:\瑞星\Rising\Rav\mondrv.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [D:\瑞星\Rising\Rav\defmon.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 46] [D:\瑞星\Rising\Rav\moncom08.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [D:\瑞星\Rising\Rav\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 10] [D:\瑞星\Rising\Rav\FileMon.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 29] [D:\瑞星\Rising\Rav\MailMon.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 22] [D:\瑞星\Rising\Rav\HookWeb.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 12] [D:\瑞星\Rising\Rav\rsindent.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 11] [D:\瑞星\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [D:\瑞星\Rising\Rav\taskplug.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 10] [D:\瑞星\Rising\Rav\scansrvp.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.7] [D:\瑞星\Rising\Rav\cnt08.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [D:\瑞星\Rising\Rav\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [D:\瑞星\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [D:\瑞星\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [D:\瑞星\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [D:\瑞星\Rising\Rav\Hooksys.dll] [Beijing Rising Information Technology Co., Ltd., 24, 0, 0, 3] [D:\瑞星\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\瑞星\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\瑞星\Rising\Rav\HookCont.dll] [Beijing Rising Information Technology Co., Ltd., 24, 0, 0, 1] [D:\瑞星\Rising\Rav\BACore.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 36] [D:\瑞星\Rising\Rav\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [D:\瑞星\Rising\Rav\refs.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [D:\瑞星\Rising\Rav\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [D:\瑞星\Rising\Rav\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [D:\瑞星\Rising\Rav\rsnetsvr.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [D:\瑞星\Rising\Rav\bawhite.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [D:\瑞星\Rising\Rav\RSStore.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [D:\瑞星\Rising\Rav\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.22] [D:\瑞星\Rising\Rav\ScanAdd.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.4] [D:\瑞星\Rising\Rav\rstask.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [D:\瑞星\Rising\Rav\rsstub.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [D:\瑞星\Rising\Rav\ScanSrv.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.3] [D:\瑞星\Rising\Rav\scanpe.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 10] [D:\瑞星\Rising\Rav\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [D:\瑞星\Rising\Rav\ur000.dat] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [D:\瑞星\Rising\Rav\urutils.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [D:\瑞星\Rising\Rav\revm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [D:\瑞星\Rising\Rav\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [D:\瑞星\Rising\Rav\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [D:\瑞星\Rising\Rav\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [D:\瑞星\Rising\Rav\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [D:\瑞星\Rising\Rav\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 69] [D:\瑞星\Rising\Rav\scantj.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [D:\瑞星\Rising\Rav\methodex.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [D:\瑞星\Rising\Rav\heurex.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 16] [D:\瑞星\Rising\Rav\pecompd.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [D:\瑞星\Rising\Rav\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [D:\瑞星\Rising\Rav\ur001.dat] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [D:\瑞星\Rising\Rav\ur025.dat] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [D:\瑞星\Rising\Rav\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [D:\瑞星\Rising\Rav\ScanRavT.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.4] [D:\瑞星\Rising\Rav\ScanBT.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.19] [D:\瑞星\Rising\Rav\ScanStub.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [D:\瑞星\Rising\Rav\ur023.dat] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [D:\瑞星\Rising\Rav\extsfx.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [PID: 1880 / SYSTEM][C:\Program Files\Rising\Rfw\RavMonD.exe] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [C:\Program Files\Rising\Rfw\combase.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 17] [C:\Program Files\Rising\Rfw\cnt09.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [C:\Program Files\Rising\Rfw\MonBase.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [C:\Program Files\Rising\Rfw\MonComm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 9] [C:\Program Files\Rising\Rfw\rfwlog.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.15] [C:\Program Files\Rising\Rfw\rfwrule.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Rising\Rfw\rfwsrv.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.2] [C:\Program Files\Rising\Rfw\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\Program Files\Rising\Rfw\mPorts.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [C:\Program Files\Rising\Rfw\rfwdrvc.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [C:\Program Files\Rising\Rfw\Rfwdrv.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.5] [C:\Program Files\Rising\Rfw\RfwArp.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.5] [C:\Program Files\Rising\Rfw\rsnetsvr.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [C:\Program Files\Rising\Rfw\urlrule.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [C:\Program Files\Rising\Rfw\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [C:\Program Files\Rising\Rfw\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [C:\Program Files\Rising\Rfw\refs.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [C:\Program Files\Rising\Rfw\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [C:\Program Files\Rising\Rfw\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [C:\Program Files\Rising\Rfw\rfwproxy.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 69] [C:\Program Files\Rising\Rfw\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [C:\Program Files\Rising\Rfw\rsindent.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 11] [C:\Program Files\Rising\Rfw\taskplug.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 10] [C:\Program Files\Rising\Rfw\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [C:\Program Files\Rising\Rfw\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [C:\Program Files\Rising\Rfw\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [C:\Program Files\Rising\Rfw\NComm2.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [C:\Program Files\Rising\Rfw\rstask.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [C:\Program Files\Rising\Rfw\rsstub.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [C:\Program Files\Rising\Rfw\urllib.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [PID: 1904 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [c:\windows\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159] [PID: 264 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 400 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 616 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\fppmon2.dll] [FinePrint Software, LLC, 2.10] [C:\WINDOWS\system32\fppr232.dll] [FinePrint Software, LLC, 2.10] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll] [Windows (R) 2000 DDK provider, 5.00.2195.1620] [PID: 864 / Shang][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [C:\WINDOWS\system32\Ku6Kss.dll] [酷6网(北京)信息技术有限公司, 1, 0, 0, 1] [c:\documents and settings\shang\application data\ppstream\bin\1.0.0.2\vodrc.dll] [ppstream.com, 1.0.0.2] [D:\Program Files\ShellExt.dll] [Microsoft Corporation, 1.0.1495.0] [C:\WINDOWS\system32\PFLib.dll] [Microsoft Corporation, 1.0.1495.0] [D:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll] [Stardock.net, Inc, 3.10.00] [C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159] [C:\Program Files\360safe\safemon\safemon.dll] [360安全中心, 6, 3, 1, 1010] [PID: 948 / Shang][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\Ku6Kss.dll] [酷6网(北京)信息技术有限公司, 1, 0, 0, 1] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [C:\WINDOWS\system32\Macromed\Flash\Flash10d.ocx] [Adobe Systems, Inc., 10,0,42,34] [PID: 1408 / SYSTEM][D:\Program Files\PrfldSvc.exe] [N/A, ] [PID: 132 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 1928 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [PID: 944 / Shang][C:\WINDOWS\system32\wscntfy.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [PID: 2368 / Shang][C:\Program Files\广电嘉和\济南广电嘉和认证客户端\广电认证.exe] [N/A, ] [D:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll] [Stardock.net, Inc, 3.10.00] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [C:\Program Files\360safe\safemon\safemon.dll] [360安全中心, 6, 3, 1, 1010] [PID: 2444 / Shang][C:\WINDOWS\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\NvMcTray.dll] [NVIDIA Corporation, 6.14.11.9062] [C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.9062] [D:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll] [Stardock.net, Inc, 3.10.00] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.11.9062] [PID: 2468 / Shang][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5, 1, 0, 59] [D:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll] [Stardock.net, Inc, 3.10.00] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [PID: 2480 / Shang][C:\Program Files\Rising\Rfw\RsTray.exe] [Beijing Rising Information Technology Co., Ltd., 22.0.0.10] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [C:\Program Files\Rising\Rfw\comserv.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.15] [C:\Program Files\Rising\Rfw\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [C:\Program Files\Rising\Rfw\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [C:\Program Files\Rising\Rfw\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\Program Files\Rising\Rfw\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [C:\Program Files\Rising\Rfw\rsxml.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [C:\Program Files\Rising\Rfw\MonState.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [C:\Program Files\Rising\Rfw\rfwrule.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Rising\Rfw\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [C:\Program Files\Rising\Rfw\rspalvd.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.7] [C:\Program Files\Rising\Rfw\rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 57] [C:\Program Files\Rising\Rfw\ravbintl.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 22] [C:\Program Files\Rising\Rfw\rsnetsvr.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [C:\Program Files\Rising\Rfw\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [C:\Program Files\Rising\Rfw\rfwtray.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 39] [C:\Program Files\Rising\Rfw\ravppops.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 21] [C:\Program Files\Rising\Rfw\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [C:\Program Files\Rising\Rfw\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [C:\Program Files\Rising\Rfw\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [C:\Program Files\Rising\Rfw\rfwlog.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.15] [PID: 2576 / Shang][D:\youxi\桌面天气秀\XDeskWeather.exe] [www.XDeskSoft.com, 5.0.0.305] [D:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll] [Stardock.net, Inc, 3.10.00] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [C:\Program Files\360safe\safemon\safemon.dll] [360安全中心, 6, 3, 1, 1010] [PID: 2700 / Shang][D:\瑞星\Rising\Rav\RsTray.exe] [Beijing Rising Information Technology Co., Ltd., 22.0.0.10] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [D:\瑞星\Rising\Rav\comserv.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.15] [D:\瑞星\Rising\Rav\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1] [D:\瑞星\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [D:\瑞星\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [D:\瑞星\Rising\Rav\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [D:\瑞星\Rising\Rav\rsxml.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [D:\瑞星\Rising\Rav\MonState.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [D:\瑞星\Rising\Rav\ScanEvnt.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.3] [D:\瑞星\Rising\Rav\rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 57] [D:\瑞星\Rising\Rav\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [D:\瑞星\Rising\Rav\rspalvd.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.7] [D:\瑞星\Rising\Rav\ravbintl.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 22] [D:\瑞星\Rising\Rav\mruleui.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 7] [D:\瑞星\Rising\Rav\MonTray.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.74] [D:\瑞星\Rising\Rav\RavITray.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [D:\瑞星\Rising\Rav\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [D:\瑞星\Rising\Rav\scanleak.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [D:\瑞星\Rising\Rav\ravppops.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 21] [D:\瑞星\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [D:\瑞星\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0] [D:\瑞星\Rising\Rav\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [D:\瑞星\Rising\Rav\ScanPrxy.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.4] [PID: 2756 / Shang][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [D:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll] [Stardock.net, Inc, 3.10.00] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [PID: 3044 / Shang][C:\WINDOWS\system32\taskmgr.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\Program Files\360safe\safemon\safemon.dll] [360安全中心, 6, 3, 1, 1010] [D:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll] [Stardock.net, Inc, 3.10.00] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [PID: 4892 / Shang][D:\Program Files\Caihong\CHGreenBrowser.exe] [, 2, 0, 0, 1] [C:\Program Files\360safe\safemon\safemon.dll] [360安全中心, 6, 3, 1, 1010] [D:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll] [Stardock.net, Inc, 3.10.00] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [D:\Program Files\Caihong\bin\wmdll3.dll] [N/A, ] [D:\瑞星\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 17] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [PID: 2960 / Shang][C:\WINDOWS\explorer.exe] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\360safe\safemon\safemon.dll] [360安全中心, 6, 3, 1, 1010] [D:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll] [Stardock.net, Inc, 3.10.00] [C:\WINDOWS\system32\Ku6Kss.dll] [酷6网(北京)信息技术有限公司, 1, 0, 0, 1] [c:\documents and settings\shang\application data\ppstream\bin\1.0.0.2\vodrc.dll] [ppstream.com, 1.0.0.2] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS] [, ] [D:\Program Files\rarext.dll] [N/A, ] [C:\WINDOWS\ContextBG.dll] [Grigri, 1, 0, 0, 1] [D:\应用程序\AliIMExt.dll] [Alibaba software (Shanghai) Corporation., 1.0.0.1] [C:\Documents and Settings\Shang\Application Data\Foxy\LinkMaker.dll] [, 1, 1, 1, 0] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1] [C:\WINDOWS\system32\kakaext.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.4] [PID: 3884 / Shang][F:\新建文件夹\SREngLdr.EXE] [Smallfrogs Studio, 2.8.2.1321] [PID: 5308 / Shang][F:\新建文件夹\SREf7e3ff6b.EXE] [Smallfrogs Studio, 2.8.2.1321] [C:\Program Files\360safe\safemon\safemon.dll] [360安全中心, 6, 3, 1, 1010] [D:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll] [Stardock.net, Inc, 3.10.00] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [F:\新建文件夹\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [PID: 1988 / Shang][D:\Program Files\Tango3\tango3.exe] [北京糖果网络技术有限公司, 3, 0, 0, 1] [C:\Program Files\360safe\safemon\safemon.dll] [360安全中心, 6, 3, 1, 1010] [D:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll] [Stardock.net, Inc, 3.10.00] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [D:\Program Files\Tango3\bin\wmdll3.dll] [N/A, ] [PID: 212 / Shang][D:\Program Files\Tango3\bin\TangoWeb.exe] [北京糖果网络技术有限公司, 3.0.0.1] [C:\Program Files\360safe\safemon\safemon.dll] [360安全中心, 6, 3, 1, 1010] [D:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll] [Stardock.net, Inc, 3.10.00] [C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 4.3.0.3315] [D:\瑞星\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 17] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\Macromed\Flash\Flash10d.ocx] [Adobe Systems, Inc., 10,0,42,34] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\system32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 1556, C:\WINDOWS\SYSTEM32\NVSVC32.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2368, C:\PROGRAM FILES\广电嘉和\济南广电嘉和认证客户端\广电认证.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2576, D:\YOUXI\桌面天气秀\XDESKWEATHER.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 4892, D:\PROGRAM FILES\CAIHONG\CHGREENBROWSER.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1988, D:\PROGRAM FILES\TANGO3\TANGO3.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 212, D:\PROGRAM FILES\TANGO3\BIN\TANGOWEB.EXE] ================================== 计划任务 [已启用] User_Feed_Synchronization-{91B6C640-AF9C-4E9B-B888-CAF7FC4C01FE}.job C:\WINDOWS\system32\msfeedssync.exe ================================== Windows 安全更新检查 Microsoft .NET Framework 版本 1.1,简体中文版 KB829019, Microsoft .NET Framework 2.0 语言包:x86 (KB829019) KB892130, Windows 正版增值验证工具 (KB892130) KB925850, Windows Media Player 11 KB940157, 用于 Windows XP 的 Windows 搜索 4.0 (KB940157) KB967912, Windows Live 登录助手更新 (KB 967912) KB926140, 用于 Windows XP 的 Windows PowerShell 1.0 (KB926140) KB905474, Windows Genuine Advantage 通知 (KB905474) KB909520, Microsoft 基本智能卡加密服务提供程序包: x86 (KB909520) KB973923, Microsoft Visual C++ 2005 Service Pack 1 Redistributable Package 的安全更新 (KB973923) MS09-035 KB973923, Windows Live 软件包 KB951847, Microsoft .NET Framework 3.5 Service Pack 1 和用于 .NET 版本 2.0 至 3.5 的 .NET Framework 3.5 Family Update (KB951847) x86 KB973687, Windows XP 更新程序 (KB973687) KB931125, 根证书更新 [2009 年 11 月] (KB931125) KB970430, Windows XP 更新程序 (KB970430) KB971737, Windows XP 更新程序 (KB971737) KB955759, Windows XP 更新程序 (KB955759) KB973688, Microsoft XML Core Services 4.0 Service Pack 2 更新程序 (KB973688) KB971513, Windows XP 更新程序 (KB971513) KB978506, 用于 Windows XP 的 Internet Explorer 8 兼容性视图列表的更新程序 (KB978506) KB976662, Windows XP 更新程序 (KB976662) KB979306, Windows XP 更新程序 (KB979306) KB890830, Windows 恶意软件删除工具 - 2010 年 3 月 (KB890830) ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]