101 - 未知模块:c:\program files\Rising\Rfw\ijt_base.dll
102 - 未知模块:c:\program files\Rising\Rfw\olemon.dll
103 - 未知模块:c:\program files\Rising\Rfw\MonMid.dll
104 未知进程:c:\program files\Rising\Rfw\rfwstub.exe 命令行: "rfwstub.exe" -rfwsrv
105 - 未知模块:c:\WINDOWS\system32\msvcp71.dll
106 - 未知模块:c:\WINDOWS\system32\msvcr71.dll
107 - 未知模块:c:\program files\Rising\Rfw\RsCommon.dll
108 - 未知模块:c:\program files\Rising\Rfw\ijt_base.dll
109 - 未知模块:c:\program files\Rising\Rfw\olemon.dll
110 (安全进程):c:\WINDOWS\explorer.exe 命令行: C:\WINDOWS\Explorer.EXE
111 - 未知模块:c:\program files\Rising\Rfw\ijt_base.dll
112 - 未知模块:c:\program files\Rising\Rfw\olemon.dll
113 - 未知模块:c:\program files\Rising\Rav\RavScrch.dll
114 - 未知模块:c:\program files\thunder network\Thunder\components\resworker\DsBho_01.dll
115 - 未知模块:c:\program files\thunder network\Thunder\components\resworker\dataprocessor_01.dll
116 - 未知模块:c:\program files\Rising\Rav\RsCommon.dll
117 未知进程:c:\program files\Rising\Rav\RavStub.exe 命令行: "C:\PROGRAM FILES\RISING\RAV\RavStub.exe" /RAVMOND=1023
118 - 未知模块:c:\program files\Rising\Rfw\ijt_base.dll
119 - 未知模块:c:\program files\Rising\Rfw\olemon.dll
120 - 未知模块:c:\program files\Rising\Rav\ProcCom.dll
121 - 未知模块:c:\program files\Rising\Rav\RsCommX2.dll
122 - 未知模块:c:\program files\Rising\Rav\RsCommon.dll
123 (安全进程):c:\WINDOWS\system32\spoolsv.exe 命令行: C:\WINDOWS\system32\spoolsv.exe
124 - 未知模块:c:\program files\Rising\Rfw\ijt_base.dll
125 - 未知模块:c:\program files\Rising\Rfw\olemon.dll
126 未知进程:c:\program files\Rising\Rfw\rfwmain.exe 命令行: -StartUp
127 - 未知模块:c:\WINDOWS\system32\mfc71.dll
128 - 未知模块:c:\WINDOWS\system32\msvcr71.dll
129 - 未知模块:c:\WINDOWS\system32\msvcp71.dll
130 - 未知模块:c:\program files\Rising\Rfw\RsGuiLib.dll
131 - 未知模块:c:\program files\Rising\Rfw\ProcCom.dll
132 - 未知模块:c:\program files\Rising\Rfw\RsCommX2.dll
133 - 未知模块:c:\program files\Rising\Rfw\RsAppMgr.dll
134 - 未知模块:c:\program files\Rising\Rfw\CfgDll.dll
135 - 未知模块:c:\program files\Rising\Rfw\RsCommon.dll
136 - 未知模块:c:\program files\Rising\Rfw\RfwCtrl.dll
137 - 未知模块:c:\program files\Rising\Rfw\RsXML.dll
138 - 未知模块:c:\program files\Rising\Rfw\PngDll.dll
139 - 未知模块:c:\program files\Rising\Rfw\ijt_base.dll
140 - 未知模块:c:\program files\Rising\Rfw\olemon.dll
141 - 未知模块:c:\program files\Rising\Rfw\RfwRule.dll
142 (安全进程):c:\WINDOWS\system32\ctfmon.exe 命令行: "C:\WINDOWS\system32\ctfmon.exe"
143 未知进程:c:\program files\Rising\Rav\RavMon.exe 命令行: "C:\Program Files\Rising\Rav\RavMon.exe"
144 - 未知模块:c:\WINDOWS\system32\mfc71.dll
145 - 未知模块:c:\WINDOWS\system32\msvcr71.dll
146 - 未知模块:c:\WINDOWS\system32\msvcp71.dll
147 - 未知模块:c:\program files\Rising\Rav\ProcCom.dll
148 - 未知模块:c:\program files\Rising\Rav\RsCommX2.dll
149 - 未知模块:c:\program files\Rising\Rav\RsCommon.dll
150 - 未知模块:c:\program files\Rising\Rav\recomp.dll
151 - 未知模块:c:\program files\Rising\Rav\refs.dll
152 - 未知模块:c:\program files\Rising\Rav\VirusLib.dll
153 - 未知模块:c:\program files\Rising\Rav\relibldr.dll
154 - 未知模块:c:\program files\Rising\Rav\RsAppMgr.dll
155 - 未知模块:c:\program files\Rising\Rav\CfgDll.dll
156 - 未知模块:c:\program files\Rising\Rav\MonRule.dll
157 - 未知模块:c:\program files\Rising\Rav\PngDll.dll
158 - 未知模块:c:\program files\Rising\Rav\RsGuiLib.dll
159 - 未知模块:c:\program files\Rising\Rav\RsXML.dll
160 (安全进程):c:\WINDOWS\system32\alg.exe 命令行: C:\WINDOWS\System32\alg.exe
161 - 未知模块:c:\program files\Rising\Rfw\ijt_base.dll
162 - 未知模块:c:\program files\Rising\Rfw\olemon.dll
163 (安全进程):c:\WINDOWS\system32\conime.exe 命令行: C:\WINDOWS\system32\conime.exe
164 (安全进程):c:\program files\internet explorer\iexplore.exe 命令行: "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
about:blank
165 - 未知模块:c:\program files\thunder network\Thunder\ComDlls\tdatonce_now.dll
166 - 未知模块:c:\program files\thunder network\Thunder\ComDlls\xunleibho_now.dll
167 - 未知模块:c:\program files\thunder network\Thunder\components\resworker\DsBho_01.dll
168 - 未知模块:c:\program files\thunder network\Thunder\components\resworker\dataprocessor_01.dll
169 未知进程:e:\木马杀客\ftcleaner.exe 命令行: E:\木马杀客\FTCleaner.exe
170 - 未知模块:e:\木马杀客\MSVBVM60.DLL
171 - 未知模块:e:\木马杀客\VB6CHS.DLL
172 - 未知模块:c:\WINDOWS\system32\mscomctl.ocx
173 - 未知模块:e:\木马杀客\TABCTL32.OCX
174 - 未知模块:e:\木马杀客\ftcapi.dll
175 - 未知模块:e:\木马杀客\psapi.dll
176 未知进程:e:\木马杀客\fyganalyze.exe 命令行: E:\木马杀客\FygAnalyze.exe
177 - 未知模块:e:\木马杀客\psapi.dll
启动信息:
178 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Windows木马防火墙><E:\木马杀客\Trojanwall.exe>
179 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
180 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Shell><Explorer.exe>
181 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
182 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe>
183 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
184 [C:\Documents and Settings\zhangxiao\「开始」菜单\程序\启动\]
<C:\Documents and Settings\zhangxiao\「开始」菜单\程序\启动\desktop.ini>
185 [C:\Documents and Settings\All Users\「开始」菜单\程序\启动\]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\desktop.ini>
IE辅助对象BHO信息:
186 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects]
<?{9963387B-212E-4643-B207-82DAEA0E713D}><>
187 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects]
<{01443AEC-0FD1-40fd-9C87-E93D1494C233}><C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll>
188 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects]
<{889D2FEB-5411-4565-8998-1DD2C5261283}><C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll>
189 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects]
<{B69F34DD-F0F9-42DC-9EDD-957187DA688D}><>
IE右键菜单信息:
190 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<使用迅雷下载><C:\Program Files\Thunder Network\Thunder\Program\geturl.htm>
191 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<使用迅雷下载全部链接><C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm>
192 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<导出到 Microsoft Office Excel(&X)><res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000>
IE工具栏项信息:
无可疑
ActiveX对象DPF信息:
193 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<DirectAnimation Java Classes><>
194 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<Internet Explorer Classes for Java><>
195 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<Microsoft XML Parser for Java><>
网络服务SPI信息:
无可疑
系统服务信息:
196 [ Application Management | AppMgmt | 停用 ]
c:\windows\system32\svchost.exe - c:\windows\system32\appmgmts.dll
197 [ ATI Smart | ATI Smart | 停用 ]
c:\windows\system32\ati2sgag.exe
198 [ COM+ System Application | COMSysApp | 停用 ]
c:\windows\system32\dllhost.exe /processid:{02d4b3f1-fd88-11d1-960d-00805fc79235}
199 [ Human Interface Device Access | HidServ | 停用 ]
c:\windows\system32\svchost.exe - c:\windows\system32\hidserv.dll
200 [ Office Source Engine | ose | 停用 ]
c:\program files\common files\microsoft shared\source engine\ose.exe