启动文件夹
[服务管理器]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\服务管理器.lnk --> C:\PROGRA~1\MICROS~3\80\Tools\Binn\sqlmangr.exe [Microsoft Corporation]><N>
==================================
服务
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[m42248.exe / m42248.exe][Stopped/Manual Start]
<\\10.4.8.119\Admin$\m11576.exe><(File is missing)>
[m61386.exe / m61386.exe][Stopped/Manual Start]
<\\10.4.8.119\Admin$\m68413.exe><(File is missing)>
[m64365.exe / m64365.exe][Stopped/Manual Start]
<\\10.4.8.119\Admin$\m80681.exe><(File is missing)>
[m85226.exe / m85226.exe][Stopped/Manual Start]
<\\10.4.8.119\Admin$\m04584.exe><(File is missing)>
[Microsoft Search / MSSEARCH][Running/Auto Start]
<"C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe"><Microsoft Corporation>
[MSSQL$RAVN / MSSQL$RAVN][Running/Auto Start]
<C:\Program Files\MSDE\MSSQL$RAVN\Binn\sqlservr.exe -sRAVN><Microsoft Corporation>
[MSSQLSERVER / MSSQLSERVER][Running/Auto Start]
<C:\PROGRA~1\MICROS~3\MSSQL\binn\sqlservr.exe><Microsoft Corporation>
[MSSQLServerADHelper / MSSQLServerADHelper][Stopped/Manual Start]
<C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe><Microsoft Corporation>
[RavAgent / RavAgent][Running/Auto Start]
<"e:\Program Files\Rising\Rav\RavAgent.exe"><Beijing Rising Information Technology Co., Ltd.>
[Rav Net Alert / RavAlert][Running/Auto Start]
<"e:\Program Files\Rising\Rav\RavAlert.exe"><Beijing Rising Information Technology Co., Ltd.>
[RavService / RavService][Running/Auto Start]
<"e:\Program Files\Rising\Rav\RavService.exe"><Beijing Rising Information Technology Co., Ltd.>
[RavUpdate / RavUpdate][Running/Auto Start]
<"e:\Program Files\Rising\Rav\RavUpdate.exe"><Beijing Rising Information Technology Co., Ltd.>
[RNReport / RNReport][Running/Auto Start]
<"e:\Program Files\Rising\Rav\RNReport.exe"><Beijing Rising Information Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Stopped/Auto Start]
<"e:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Information Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Stopped/Auto Start]
<"E:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Information Technology Co., Ltd.>
[SQLAgent$RAVN / SQLAgent$RAVN][Stopped/Manual Start]
<C:\Program Files\MSDE\MSSQL$RAVN\Binn\sqlagent.EXE -i RAVN><Microsoft Corporation>
[SQLSERVERAGENT / SQLSERVERAGENT][Running/Auto Start]
<C:\PROGRA~1\MICROS~3\MSSQL\binn\sqlagent.exe><Microsoft Corporation>
[VNC Server / winvnc][Stopped/Auto Start]
<><(File is missing)>
[WMDM PMSP Service / WMDM PMSP Service][Running/Auto Start]
<C:\WINNT\system32\mspmspsv.exe><Microsoft Corporation>
==================================
驱动程序
[360AntiArp / 360AntiArp][Stopped/System Start]
<\??\C:\WINNT\system32\drivers\360AntiArp.sys><N/A>
[dmboot / dmboot][Stopped/Disabled]
<System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
<\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload][Running/Boot Start]
<\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[HookCont / HookCont][Running/System Start]
<\SystemRoot\system32\drivers\HookCont.sys><Beijing Rising Information Technology Co., Ltd.>
[HookNtos / HookNtos][Running/System Start]
<\SystemRoot\system32\drivers\HookNtos.sys><Beijing Rising Information Technology Co., Ltd.>
[HookReg / HookReg][Running/System Start]
<\SystemRoot\system32\drivers\HookReg.sys><Beijing Rising Information Technology Co., Ltd.>
[HookSys / HookSys][Running/System Start]
<\SystemRoot\system32\drivers\HookSys.sys><Beijing Rising Information Technology Co., Ltd.>
[ialm / ialm][Running/Manual Start]
<System32\DRIVERS\ialmnt5.sys><Intel Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Information Technology Co., Ltd.>
[Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
<System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Sound Blaster AudioPCI 64V Driver (WDM) / sbpci][Running/Manual Start]
<system32\drivers\sbpci.sys><Creative Technology Ltd.>
[Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/Manual Start]
<system32\drivers\ialmsbw.sys><Intel Corporation>
[Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start]
<system32\drivers\ialmkchw.sys><Intel Corporation>
==================================
浏览器加载项
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, >
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, (Signed) Microsoft Corporation>
[TrendLine Control]
{4F03A197-65DA-487C-864A-9DDE6EACA166} <C:\WINNT\DOWNLO~1\TRENDL~1.OCX, >
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINNT\system32\wuweb.dll, (Signed) Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash9e.ocx, (Signed) Adobe Systems, Inc.>
[]
{03507A1A-E0C5-4404-AA26-205385C0892D} <, >
[]
{2EEDA47E-8D5C-4d7e-B4B6-E16E19218555} <, >
[XMP Class]
{6483F145-A768-4C41-AACC-52D4D7845851} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work, >
[XDRM]
{693571CB-54A3-4E90-9D52-EEAE1334E2D3} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xdrm.dll_1_work, >
[RMGetLicense Class]
{A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINNT\system32\msnetobj.dll, Microsoft Corporation>
[]
{EF1EA76E-5428-4e40-85A1-D4DD2893183A} <, >
[XPPlayer Class]
{F3E70CEA-956E-49CC-B444-73AFE593AD7F} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\pplayer.dll_1_work, (Signed) Thunder>
==================================
正在运行的进程
[PID: 168][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.00.2195.6601]
[PID: 192][\??\C:\WINNT\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.00.2195.6601]
[PID: 212][\??\C:\WINNT\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.00.2195.6997]
[PID: 240][C:\WINNT\system32\services.exe] [(Verified) Microsoft Corporation, 5.00.2195.7035]
[C:\WINNT\system32\dmserver.dll] [VERITAS Software Corp., 2195.6605.297.3]
[PID: 252][C:\WINNT\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.00.2195.7011]
[PID: 444][C:\WINNT\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.00.2134.1]
[PID: 488][C:\WINNT\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.00.2195.7059]
[PID: 520][C:\WINNT\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.00.2134.1]
[PID: 544][C:\WINNT\System32\llssrv.exe] [(Verified) Microsoft Corporation, 5.00.2195.7021]
[PID: 564][C:\Program Files\MSDE\MSSQL$RAVN\Binn\sqlservr.exe] [Microsoft Corporation, 2000.080.0760.00]
[C:\Program Files\MSDE\MSSQL$RAVN\Binn\OPENDS60.DLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\MSDE\MSSQL$RAVN\Binn\UMS.DLL] [Microsoft Corporation, 2000.080.0760.00]
[C:\Program Files\MSDE\MSSQL$RAVN\Binn\SQLSORT.DLL] [Microsoft Corporation, 2000.080.0760.00]
[C:\Program Files\MSDE\MSSQL$RAVN\Binn\Resources\1033\sqlevn70.RLL] [Microsoft Corporation, 2000.080.0760.00]
[C:\Program Files\MSDE\MSSQL$RAVN\binn\SSNETLIB.dll] [Microsoft Corporation, 2000.080.0766.00]
[C:\Program Files\MSDE\MSSQL$RAVN\binn\SSNMPN70.dll] [Microsoft Corporation, 2000.080.0534.00]
[C:\Program Files\MSDE\MSSQL$RAVN\Binn\SSmsLPCn.dll] [Microsoft Corporation, 2000.080.0760.00]
[PID: 692][C:\PROGRA~1\MICROS~3\MSSQL\binn\sqlservr.exe] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~3\MSSQL\binn\OPENDS60.DLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~3\MSSQL\binn\UMS.DLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~3\MSSQL\binn\SQLSORT.DLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~3\MSSQL\binn\Resources\2052\sqlevn70.RLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~3\MSSQL\binn\SSNETLIB.dll] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~3\MSSQL\binn\SSNMPN70.dll] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~3\MSSQL\binn\SSmsLPCn.dll] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~3\MSSQL\binn\SQLFTQRY.DLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\PROGRA~1\MICROS~3\MSSQL\binn\xpsqlbot.dll] [Microsoft Corporation, 2000.080.0194.00]
[PID: 324][e:\Program Files\Rising\Rav\RavAgent.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.28]
[C:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[e:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[e:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[e:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1]
[e:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19]
[e:\Program Files\Rising\Rav\Strategy.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 6]
[C:\WINNT\system32\DBmsLPCn.dll] [Microsoft Corporation, 2000.080.0760.00]
[PID: 804][e:\Program Files\Rising\Rav\RavAlert.exe] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 56]
[C:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[e:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[e:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[e:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17]
[e:\Program Files\Rising\Rav\PlugIn\RptMC.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 11]
[e:\Program Files\Rising\Rav\PlugIn\AltP936.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 6]
[e:\Program Files\Rising\Rav\PlugIn\MalAlrt.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7]
[e:\Program Files\Rising\Rav\PlugIn\TrpPlgIn.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 9]
[e:\Program Files\Rising\Rav\RsSnmp.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 3]
[e:\Program Files\Rising\Rav\PlugIn\MBPlgIn.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 8]
[e:\Program Files\Rising\Rav\PlugIn\NLPlgIn.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 6]
[e:\Program Files\Rising\Rav\PlugIn\SysLog.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 11]
[C:\WINNT\system32\DBmsLPCn.dll] [Microsoft Corporation, 2000.080.0760.00]
[PID: 832][e:\Program Files\Rising\Rav\RavService.exe] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 77]
[C:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[e:\Program Files\Rising\Rav\DLCenter.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.11]
[e:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[e:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[PID: 876][e:\Program Files\Rising\Rav\RavUpdate.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.52]
[C:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[e:\Program Files\Rising\Rav\DLCenter.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.11]
[e:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[e:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[PID: 892][C:\WINNT\system32\regsvc.exe] [(Verified) Microsoft Corporation, 5.00.2195.6701]
[PID: 912][e:\Program Files\Rising\Rav\RNReport.exe] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 65]
[e:\Program Files\Rising\Rav\Chart.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.8]
[C:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[e:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[e:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[C:\WINNT\system32\DBmsLPCn.dll] [Microsoft Corporation, 2000.080.0760.00]
[PID: 1108][C:\WINNT\system32\MSTask.exe] [(Verified) Microsoft Corporation, 4.71.2195.6972]
[PID: 1144][C:\WINNT\System32\WBEM\WinMgmt.exe] [(Verified) Microsoft Corporation, 1.50.1085.0100]
[PID: 1180][C:\WINNT\system32\mspmspsv.exe] [Microsoft Corporation, 7.10.00.3059]
[PID: 1192][C:\WINNT\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.00.2134.1]
[PID: 1212][C:\WINNT\system32\Dfssvc.exe] [(Verified) Microsoft Corporation, 5.00.2195.6664]
[PID: 1232][C:\WINNT\System32\inetsrv\inetinfo.exe] [(Verified) Microsoft Corporation, 5.00.0984]
[C:\WINNT\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll] [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
[C:\WINNT\system32\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42]
[C:\WINNT\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll] [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
[C:\WINNT\Microsoft.NET\Framework\v2.0.50727\webengine.dll] [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
[PID: 1256][C:\WINNT\System32\msdtc.exe] [(Verified) Microsoft Corporation, 1999.9.3421.3]
[PID: 1332][C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe] [Microsoft Corporation, 9.107.5512.0]
[C:\Program Files\Common Files\System\MSSearch\Bin\mssws.dll] [Microsoft Corporation, 9.107.5512.0]
[C:\PROGRA~1\COMMON~1\System\MSSearch\Bin\mssrch.dll] [Microsoft Corporation, 9.107.5512.0]
[C:\Program Files\Common Files\System\MSSearch\Bin\tquery.dll] [Microsoft Corporation, 9.107.5512.0]
[C:\PROGRA~1\COMMON~1\System\MSSearch\Bin\propdefs.dll] [Microsoft Corporation, 9.107.5512.0]
[C:\PROGRA~1\COMMON~1\System\MSSearch\Bin\srchidx.dll] [Microsoft Corporation, 9.107.5512.0]
[PID: 1496][C:\WINNT\Explorer.EXE] [(Verified) Microsoft Corporation, 5.00.3700.6690]
[C:\WINNT\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.18]
[e:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[PID: 1640][C:\WINNT\system32\igfxtray.exe] [Intel Corporation, 3,0,0,1607]
[C:\WINNT\system32\hccutils.DLL] [Intel Corporation, 3,0,0,1607]
[C:\WINNT\system32\igfxdev.dll] [Intel Corporation, 3,0,0,1607]
[C:\WINNT\system32\igfxsrvc.dll] [Intel Corporation, 3,0,0,1607]
[C:\WINNT\system32\igfxres.dll] [Intel Corporation, 3,0,0,1607]
[C:\WINNT\system32\igfxress.dll] [Intel Corporation, 3,0,0,1607]
[PID: 1648][C:\WINNT\system32\hkcmd.exe] [Intel Corporation, 3,0,0,1607]
[C:\WINNT\system32\hccutils.DLL] [Intel Corporation, 3,0,0,1607]
[C:\WINNT\system32\igfxdev.dll] [Intel Corporation, 3,0,0,1607]
[C:\WINNT\system32\igfxsrvc.dll] [Intel Corporation, 3,0,0,1607]
[C:\WINNT\system32\igfxhk.dll] [Intel Corporation, 3,0,0,1607]
[C:\WINNT\system32\igfxres.dll] [Intel Corporation, 3,0,0,1607]
[PID: 1656][E:\Program Files\Rising\Rav\RavTray.exe] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 37]
[E:\Program Files\Rising\Rav\RavUILib.dll] [, 18, 0, 0, 1]
[C:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[E:\Program Files\Rising\Rav\RavTray936.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 37]
[E:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[E:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[PID: 1668][C:\WINNT\system32\internat.exe] [(Verified) Microsoft Corporation, 5.00.2920.0000]
[PID: 1700][C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe] [Microsoft Corporation, 2000.080.0760.00]
[C:\Program Files\Microsoft SQL Server\80\Tools\Binn\W95SCM.dll] [Microsoft Corporation, 2000.080.0760.00]