瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 刚中奇怪病毒,已经重装,请分析一下sreng

1   1  /  1  页   跳转

[求助] 刚中奇怪病毒,已经重装,请分析一下sreng

刚中奇怪病毒,已经重装,请分析一下sreng

2011-01-07,21:39:24


System Repair Engineer 2.8.4.1331
Smallfrogs (http://www.KZTechs.com)


Windows 7 Ultimate Edition  (Build 7600) - 管理权限用户 - 完整功能


以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
    进程特权扫描
    计划任务
    Windows 安全更新检查
    API HOOK
    隐藏进程




启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <QQDownload><"C:\Program Files\Tencent\QQDownload\QQDownload.exe" autostart>  [File is missing]
    <Sidebar><C:\Program Files\Windows Sidebar\sidebar.exe /autoRun>  [(Verified)Microsoft Windows]
    <Google Update><"C:\Users\hp\AppData\Local\Google\Update\GoogleUpdate.exe" /c>  [(Verified)Google Inc]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <NvCplDaemon><RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup>  [(Verified)NVIDIA Corporation]
    <xntalk><D:\Program Files\RenRen\xntalk.exe /background>  [(Verified)beijing qianxianghulian kejifazhan youxiangongsi]
    <renrenservice><C:\Users\hp\AppData\Roaming\renren.com\renrenservice.exe>  [(Verified)beijing qianxianghulian kejifazhan youxiangongsi]
    <IME14 CHS Setup><C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHS /Log>  [(Verified)Microsoft Corporation]
    <QuickTime Task><"C:\Program Files\QuickTime\QTTask.exe" -atboottime>  [Apple Inc.]
    <iTunesHelper><"D:\Program Files\iTunes\iTunesHelper.exe">  [(Verified)Apple Inc.]
    <RISTRAY><"C:\Program Files\Rising\RIS\RSTRAY.EXE" -system>  [(Verified)Beijing Rising Information Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><explorer.exe>  [(Verified)Microsoft Windows]
    <Userinit><C:\Windows\system32\userinit.exe,>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <WebCheck><>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    <Microsoft Windows Media Player><%SystemRoot%\system32\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><C:\Windows\System32\ie4uinit.exe -UserIconConfig>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
    <Browser Customizations><"C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Windows><"%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
    <Windows Desktop Update><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    <Web Platform Customizations><C:\Windows\System32\ie4uinit.exe -BaseSettings>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
    <N/A><C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install>  [(Verified)Microsoft Corporation]


==================================
启动文件夹
N/A


==================================
服务
[Apple Mobile Device / Apple Mobile Device][Running/Auto Start]
  <"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"><Apple Inc.>
[Bonjour 服务 / Bonjour Service][Running/Auto Start]
  <"C:\Program Files\Bonjour\mDNSResponder.exe"><Apple Inc.>
[iPod 服务 / iPod Service][Running/Manual Start]
  <"C:\Program Files\iPod\bin\iPodService.exe"><Apple Inc.>
[NVIDIA Display Driver Service / nvsvc][Running/Auto Start]
  <C:\Windows\system32\nvvsvc.exe><NVIDIA Corporation>
[Rsd Service / RsMgrSvc][Running/Auto Start]
  <"C:\Program Files\Rising\RSD\RsMgrSvc.exe"><Beijing Rising Information Technology Co., Ltd.>
[RIS Service / RsRISMon][Running/Auto Start]
  <"C:\Program Files\Rising\RIS\RavMonD.exe"><Beijing Rising Information Technology Co., Ltd.>


==================================
驱动程序
[adp94xx / adp94xx][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\adp94xx.sys><Adaptec, Inc.>
[adpahci / adpahci][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\adpahci.sys><Adaptec, Inc.>
[adpu320 / adpu320][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\adpu320.sys><Adaptec, Inc.>
[aic78xx / aic78xx][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\djsvs.sys><Adaptec, Inc.>
[aliide / aliide][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[amdsata / amdsata][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\amdsata.sys><Advanced Micro Devices>
[amdsbs / amdsbs][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\amdsbs.sys><AMD Technologies Inc.>
[amdxata / amdxata][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\amdxata.sys><Advanced Micro Devices>
[arc / arc][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\arc.sys><Adaptec, Inc.>
[arcsas / arcsas][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\arcsas.sys><Adaptec, Inc.>
[Broadcom NetXtreme II VBD / b06bdrv][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\bxvbdx.sys><Broadcom Corporation>
[Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 / b57nd60x][Stopped/Manual Start]
  <system32\DRIVERS\b57nd60x.sys><Broadcom Corporation>
[Brother USB Mass-Storage Lower Filter Driver / BrFiltLo][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\BrFiltLo.sys><Brother Industries, Ltd.>
[Brother USB Mass-Storage Upper Filter Driver / BrFiltUp][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\BrFiltUp.sys><Brother Industries, Ltd.>
[Brother MFC Serial Port Interface Driver (WDM) / Brserid][Stopped/Manual Start]
  <\SystemRoot\System32\Drivers\Brserid.sys><Brother Industries Ltd.>
[Brother WDM Serial driver / BrSerWdm][Stopped/Manual Start]
  <\SystemRoot\System32\Drivers\BrSerWdm.sys><Brother Industries Ltd.>
[Brother MFC USB Fax Only Modem / BrUsbMdm][Stopped/Manual Start]
  <\SystemRoot\System32\Drivers\BrUsbMdm.sys><Brother Industries Ltd.>
[Brother MFC USB Serial WDM Driver / BrUsbSer][Stopped/Manual Start]
  <\SystemRoot\System32\Drivers\BrUsbSer.sys><Brother Industries Ltd.>
[cmdide / cmdide][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[Broadcom NetXtreme II 10 GigE VBD / ebdrv][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\evbdx.sys><Broadcom Corporation>
[elxstor / elxstor][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\elxstor.sys><Emulex>
[GEAR ASPI Filter Driver / GEARAspiWDM][Running/Manual Start]
  <system32\DRIVERS\GEARAspiWDM.sys><GEAR Software Inc.>
[Hauppauge Consumer Infrared Receiver / hcw85cir][Stopped/Manual Start]
  <\SystemRoot\system32\drivers\hcw85cir.sys><Hauppauge Computer Works, Inc.>
[hooksys / hooksys][Running/System Start]
  <\??\C:\Windows\system32\drivers\Hooksys.sys><Beijing Rising Information Technology Co., Ltd.>
[HookTdi / HookTdi][Running/System Start]
  <\??\C:\Windows\system32\drivers\HookTdi.sys><Beijing Rising Information Technology Co., Ltd.>
[HP Remote Control HID Device / HpqRemHid][Running/Manual Start]
  <system32\DRIVERS\HpqRemHid.sys><Hewlett-Packard Development Company, L.P.>
[HpSAMD / HpSAMD][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\HpSAMD.sys><Hewlett-Packard Company>
[HyperVM / HyperVM][Running/System Start]
  <\??\C:\Windows\system32\drivers\hvm.sys><Beijing Rising Information Technology Co., Ltd.>
[iaStorV / iaStorV][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\iaStorV.sys><Intel Corporation>
[iirsp / iirsp][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\iirsp.sys><Intel Corp./ICP vortex GmbH>
[LSI_FC / LSI_FC][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\lsi_fc.sys><LSI Corporation>
[LSI_SAS / LSI_SAS][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\lsi_sas.sys><LSI Corporation>
[LSI_SAS2 / LSI_SAS2][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\lsi_sas2.sys><LSI Corporation>
[LSI_SCSI / LSI_SCSI][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\lsi_scsi.sys><LSI Corporation>
[megasas / megasas][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\megasas.sys><LSI Corporation>
[MegaSR / MegaSR][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\MegaSR.sys><LSI Corporation, Inc.>
[适用于 Windows Vista 32 位的 Intel(R) Wireless WiFi 链接 5000 系列适配器驱动程序 / netw5v32][Running/Manual Start]
  <system32\DRIVERS\netw5v32.sys><Intel Corporation>
[nfrd960 / nfrd960][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\nfrd960.sys><IBM Corporation>
[nvlddmkm / nvlddmkm][Running/Manual Start]
  <system32\DRIVERS\nvlddmkm.sys><NVIDIA Corporation>
[nvraid / nvraid][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\nvraid.sys><NVIDIA Corporation>
[nvstor / nvstor][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\nvstor.sys><NVIDIA Corporation>
[ql2300 / ql2300][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\ql2300.sys><QLogic Corporation>
[ql40xx / ql40xx][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\ql40xx.sys><QLogic Corporation>
[Rising RfwARP Driver / RFWARP][Running/Auto Start]
  <system32\DRIVERS\rfwarp.sys><Beijing Rising Information Technology Co., Ltd.>
[Rising RfwNdis Driver / RFWNDIS][Running/System Start]
  <system32\DRIVERS\rfwndis.sys><Beijing Rising Information Technology Co., Ltd.>
[rfwtdi / rfwtdi][Running/Auto Start]
  <\??\C:\Program Files\Rising\RIS\rfwtdi.sys><Beijing Rising Information Technology Co., Ltd.>
[Ricoh xD-Picture Card Driver / rismxdp][Running/Auto Start]
  <system32\DRIVERS\rixdptsk.sys><REDC>
[rsfwdrv / rsfwdrv][Running/Auto Start]
  <\??\C:\Program Files\Rising\RIS\rsfwdrv.sys><Beijing Rising Information Technology Co., Ltd.>
[Realtek 8167 NT Driver / RTL8167][Running/Manual Start]
  <system32\DRIVERS\Rt86win7.sys><Realtek Corporation>
[SiSRaid2 / SiSRaid2][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\SiSRaid2.sys><Silicon Integrated Systems Corp.>
[SiSRaid4 / SiSRaid4][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\sisraid4.sys><Silicon Integrated Systems>
[smserial / smserial][Running/Manual Start]
  <system32\DRIVERS\smserial.sys><Motorola Inc.>
[stexstor / stexstor][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\stexstor.sys><Promise Technology>
[Apple Mobile USB Driver / USBAAPL][Running/Manual Start]
  <System32\Drivers\usbaapl.sys><Apple, Inc.>
[viaide / viaide][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\viaide.sys><VIA Technologies, Inc.>
[vsmraid / vsmraid][Stopped/Manual Start]
  <\SystemRoot\system32\DRIVERS\vsmraid.sys><VIA Technologies Inc.,Ltd>


==================================
浏览器加载项
[QQCycloneHelper Class]
  {00000000-12C9-4305-82F9-43058F20E8D2} <C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, (Signed) Tencent Technology (Shenzhen) Company Limited>
[Office Document Cache Handler]
  {B4F3A835-0E21-4959-BA22-42B3008E02FF} <D:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL, (Signed) Microsoft Corporation>
[Send to OneNote from Internet Explorer button]
  {2670000A-7350-4f3c-8081-5663EE0C6C49} <D:\Program Files\Microsoft Office\Office14\ONBttnIE.dll, (Signed) Microsoft Corporation>
[Linked Notes button]
  {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} <D:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll, (Signed) Microsoft Corporation>
[QQCycloneHelper Class]
  {00000000-12C9-4305-82F9-43058F20E8D2} <C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, (Signed) Tencent Technology (Shenzhen) Company Limited>
[InstallHelper Class]
  {1DABF8D5-8430-4985-9B7F-A30E53D709B3} <D:\Program Files\Tencent\QQ\Plugin\Com.Tencent.QQMusic\bin\QQMusic\MMInstaller.dll, (Signed) Tencent>
[]
  {2670000A-7350-4F3C-8081-5663EE0C6C49} <, >
[Google Update Plugin]
  {4536918A-95A8-498F-B542-CB906C561A43} <C:\Users\hp\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll, (Signed) Google Inc.>
[QQPYChecker Class]
  {5052B4D0-9DF7-45ef-88EF-F42C0EA33A43} <D:\Program Files\Tencent\QQPinyin\4.0.1023.400\QQImeChecker.dll, (Signed) Tencent>
[]
  {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} <, >
[QQDownload Class]
  {8AC3BC28-E145-4385-A694-8AAC128ACB16} <C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, (Signed) Tencent Technology (Shenzhen) Company Limited>
[Office Document Cache Handler]
  {B4F3A835-0E21-4959-BA22-42B3008E02FF} <D:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL, (Signed) Microsoft Corporation>
[Microsoft Url Search Hook]
  {CFBFAE00-17A6-11D0-99CB-00C04FD64497} <C:\Windows\System32\ieframe.dll, (Signed) Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\system32\Macromed\Flash\Flash10l.ocx, (Signed) Adobe Systems, Inc.>
[PlayerCtrl Class]
  {E05BC2A3-9A46-4a32-80C9-023A473F5B23} <D:\Program Files\Tencent\QQ\Plugin\Com.Tencent.QQMusic\bin\QQMusic\QzoneMusic.dll, (Signed) Tencent>
[XML HTTP Request]
  {ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XML HTTP]
  {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[&使用QQ旋风下载]
  <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
[&使用QQ旋风下载全部链接]
  <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
[&使用QQ旋风离线下载]
  <C:\Program Files\Tencent\QQDownload\xfofflinedown.htm, N/A>
[发送至 OneNote(&N)]
  <res://D:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105, N/A>
[导出到 Microsoft Excel(&X)]
  <res://D:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000, N/A>


==================================
正在运行的进程
[PID: 268 / SYSTEM][\SystemRoot\System32\smss.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 372 / SYSTEM][C:\Windows\system32\csrss.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 420 / SYSTEM][C:\Windows\system32\wininit.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 428 / SYSTEM][C:\Windows\system32\csrss.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 476 / SYSTEM][C:\Windows\system32\services.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 488 / SYSTEM][C:\Windows\system32\lsass.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 500 / SYSTEM][C:\Windows\system32\lsm.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 584 / SYSTEM][C:\Windows\system32\winlogon.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 644 / SYSTEM][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 708 / SYSTEM][C:\Windows\system32\nvvsvc.exe]  [NVIDIA Corporation, 8.16.11.8766]
[PID: 748 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 876 / SYSTEM][C:\Program Files\Rising\RIS\RavMonD.exe]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 9]
    [C:\Program Files\Rising\RIS\combase.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 13]
    [C:\Program Files\Rising\RIS\rsconf.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.4]
    [C:\Program Files\Rising\RIS\scansrvp.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.12]
    [C:\Program Files\Rising\RIS\cnt09.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 1]
    [C:\Program Files\Rising\RIS\moncomm.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.3]
    [C:\Program Files\Rising\RIS\MonBase.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 1]
    [C:\Program Files\Rising\RIS\Rslog.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.19]
    [C:\Program Files\Rising\RIS\RsStore.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 11]
    [C:\Program Files\Rising\RIS\mondrvd.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 11]
    [C:\Program Files\Rising\RIS\defmon.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 57]
    [C:\Program Files\Rising\RIS\moncom08.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.2]
    [C:\Program Files\Rising\RIS\taskplug.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.2]
    [C:\Program Files\Rising\RIS\mondrvm.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 8]
    [C:\Program Files\Rising\RIS\MonRule.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 31]
    [C:\Program Files\Rising\RIS\FileMon.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 32]
    [C:\Program Files\Rising\RIS\MailMon.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 54]
    [C:\Program Files\Rising\RIS\rfwlog.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.6]
    [C:\Program Files\Rising\RIS\rfwrule.dll]  [Beijing Rising Information Technology Co., Ltd., 22.0.0.1]
    [C:\Windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Rising\RIS\rfwsrv.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.85]
    [C:\Program Files\Rising\RIS\Syslay.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.1]
    [C:\Program Files\Rising\RIS\mPorts.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.7]
    [C:\Program Files\Rising\RIS\rfwdrvc.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.0]
    [C:\Program Files\Rising\RIS\fishweb.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 25]
    [C:\Program Files\Rising\RIS\rsindent.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.1.0]
    [C:\Program Files\Rising\RIS\cnt08.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 1]
    [C:\Program Files\Rising\RIS\proccomm.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.1]
    [C:\Program Files\Rising\RIS\comx3.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.4]
    [C:\Program Files\Rising\RIS\Hooksys.dll]  [Beijing Rising Information Technology Co., Ltd., 25, 0, 0, 8]
    [C:\Program Files\Rising\RIS\ProcCom.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\Program Files\Rising\RIS\RsCommX2.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\Program Files\Rising\RIS\rstask.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 7]
    [C:\Program Files\Rising\RIS\rsstub.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.1]
    [C:\Program Files\Rising\RIS\rslang.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.1]
    [C:\Program Files\Rising\RIS\hookTdi.dll]  [Beijing Rising Information Technology Co., Ltd., 25, 0, 0, 9]
    [C:\Program Files\Rising\RIS\BACore.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 41]
    [C:\Program Files\Rising\RIS\recomp.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 12]
    [C:\Program Files\Rising\RIS\refs.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 3]
    [C:\Program Files\Rising\RIS\viruslib.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 2]
    [C:\Program Files\Rising\RIS\relibldr.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 1]
    [C:\Program Files\Rising\RIS\rsnetsvr.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.12]
    [C:\Program Files\Rising\RIS\bawhite.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 5]
    [C:\Program Files\Rising\RIS\ScanAdd.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.31]
    [C:\Program Files\Rising\RIS\Scanner.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 68]
    [C:\Program Files\Rising\RIS\fwfish.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 4]
    [C:\Program Files\Rising\RIS\fwcomp.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 11]
    [C:\Program Files\Rising\RIS\fwfs.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 5]
    [C:\Program Files\Rising\RIS\fwvirlib.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 5]
    [C:\Program Files\Rising\RIS\fwlibldr.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 3]
    [C:\Program Files\Rising\RIS\Rfwdrv.dll]  [Beijing Rising Information Technology Co., Ltd., 25.0.0.5]
    [C:\Program Files\Rising\RIS\RfwArp.dll]  [Beijing Rising Information Technology Co., Ltd., 25.0.0.1]
    [C:\Program Files\Rising\RIS\urlrule.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.2]
    [C:\Program Files\Rising\RIS\rfwproxy.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 70]
    [C:\Program Files\Rising\RIS\ScanSrv.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 17]
    [C:\Program Files\Rising\RIS\scanpe.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 26]
    [C:\Program Files\Rising\RIS\pearc.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 7]
    [C:\Program Files\Rising\RIS\engext.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 8]
    [C:\Program Files\Rising\RIS\vmicore.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 17]
    [C:\Program Files\Rising\RIS\ffr.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 2]
    [C:\Program Files\Rising\RIS\nvfile.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 7]
    [C:\Program Files\Rising\RIS\scantj.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 9]
    [C:\Program Files\Rising\RIS\extsfx.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 8]
    [C:\Program Files\Rising\RIS\scanexec.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 5]
    [C:\Program Files\Rising\RIS\unexe.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 0]
    [C:\Program Files\Rising\RIS\scanex.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 7]
    [C:\Program Files\Rising\RIS\urllib.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 1]
    [C:\Program Files\Rising\RIS\extarch.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 8]
    [C:\Program Files\Rising\RIS\extcomp.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 4]
    [C:\Program Files\Rising\RIS\ur029.dat]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 2]
    [C:\Program Files\Rising\RIS\ScanRavT.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.64]
    [C:\Program Files\Rising\RIS\ScanBT.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 95]
    [C:\Program Files\Rising\RIS\ScanStub.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 26]
    [C:\Program Files\Rising\RIS\scansct.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 1]
    [C:\Program Files\Rising\RIS\extole.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 0]
[PID: 932 / LOCAL SERVICE][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 964 / SYSTEM][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 1000 / SYSTEM][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.4.0]
[PID: 1132 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.4.0]
[PID: 1248 / SYSTEM][C:\Windows\system32\nvvsvc.exe]  [NVIDIA Corporation, 8.16.11.8766]
    [C:\Windows\system32\NVSVC.DLL]  [NVIDIA Corporation, 8.16.11.8766]
    [C:\Windows\system32\nvapi.dll]  [NVIDIA Corporation, 8.16.11.8766]
[PID: 1320 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.4.0]
[PID: 1456 / SYSTEM][C:\Windows\System32\spoolsv.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.4.0]
[PID: 1488 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 1604 / SYSTEM][C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe]  [Apple Inc., 17.64.0.5]
    [C:\Program Files\Common Files\Apple\Apple Application Support\ASL.dll]  [Apple, Inc., 1, 0, 0, 25]
    [C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService_main.dll]  [Apple Inc., 17.64.0.5]
    [C:\Program Files\Common Files\Apple\Apple Application Support\CoreFoundation.dll]  [Apple Inc., 1,550,36,0]
    [C:\Program Files\Common Files\Apple\Apple Application Support\pthreadVC2.dll]  [Open Source Software community project, 2, 7, 0, 11200]
    [C:\Program Files\Common Files\Apple\Apple Application Support\objc.dll]  [Apple Inc., 1,435,14,19]
    [C:\Program Files\Common Files\Apple\Apple Application Support\libdispatch.dll]  [Apple Inc., 1,109,4,13]
    [C:\Program Files\Common Files\Apple\Apple Application Support\icuin40.dll]  [IBM Corporation and others, 4, 0, 0, 3205]
    [C:\Program Files\Common Files\Apple\Apple Application Support\icuuc40.dll]  [IBM Corporation and others, 4, 0, 0, 3205]
    [C:\Program Files\Common Files\Apple\Apple Application Support\icudt40.dll]  [IBM Corporation and others, 4, 0, 0, 3205]
    [C:\Program Files\Common Files\Apple\Mobile Device Support\MobileDevice.dll]  [Apple Inc., 416.0.0.59]
    [C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll]  [, 1.2.3]
    [C:\Program Files\Common Files\Apple\Apple Application Support\CFNetwork.dll]  [Apple, Inc., 1, 454, 11, 5]
    [C:\Program Files\Common Files\Apple\Apple Application Support\SQLite3.dll]  [Apple Inc., 3.6.12 (74.2)]
    [C:\Program Files\Common Files\Apple\Mobile Device Support\SSLEAY32.dll]  [The OpenSSL Project, http://www.openssl.org/, 0.9.8d]
    [C:\Program Files\Common Files\Apple\Mobile Device Support\LIBEAY32.dll]  [The OpenSSL Project, http://www.openssl.org/, 0.9.8d]
[PID: 1696 / SYSTEM][C:\Program Files\Bonjour\mDNSResponder.exe]  [Apple Inc., 2.0.4.0]
[PID: 1736 / SYSTEM][C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE]  [Microsoft Corporation, 14.0.4734.1000]
[PID: 1796 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 1256 / SYSTEM][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 1960 / hp][C:\Windows\system32\taskhost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
    [C:\Windows\System32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0401]
[PID: 2056 / hp][C:\Windows\system32\Dwm.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
    [C:\Windows\system32\nvwgf2um.dll]  [NVIDIA Corporation, 8.16.11.8766]
[PID: 2104 / hp][C:\Windows\Explorer.EXE]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
    [C:\Windows\System32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0401]
    [C:\Windows\system32\FXSAPI.dll]  [Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
    [C:\Program Files\WinRAR\rarext.dll]  [, ]
    [C:\Windows\system32\ravext.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 3]
[PID: 2900 / hp][D:\Program Files\RenRen\xntalk.exe]  [千橡互动, 4.016]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.4.0]
    [C:\Windows\system32\QQPINYIN.IME]  [Tencent, 4.0.1023.400]
[PID: 2920 / hp][C:\Users\hp\AppData\Roaming\renren.com\RenRenService.exe]  [, 1.002]
[PID: 2972 / hp][D:\Program Files\iTunes\iTunesHelper.exe]  [Apple Inc., 10.1.1.4]
    [D:\Program Files\iTunes\iTunesHelper.dll]  [Apple Inc., 10.1.1.4]
    [C:\Program Files\Common Files\Apple\Apple Application Support\CoreFoundation.dll]  [Apple Inc., 1,550,36,0]
    [C:\Program Files\Common Files\Apple\Apple Application Support\pthreadVC2.dll]  [Open Source Software community project, 2, 7, 0, 11200]
    [C:\Program Files\Common Files\Apple\Apple Application Support\objc.dll]  [Apple Inc., 1,435,14,19]
    [C:\Program Files\Common Files\Apple\Apple Application Support\libdispatch.dll]  [Apple Inc., 1,109,4,13]
    [C:\Program Files\Common Files\Apple\Apple Application Support\icuin40.dll]  [IBM Corporation and others, 4, 0, 0, 3205]
    [C:\Program Files\Common Files\Apple\Apple Application Support\icuuc40.dll]  [IBM Corporation and others, 4, 0, 0, 3205]
    [C:\Program Files\Common Files\Apple\Apple Application Support\icudt40.dll]  [IBM Corporation and others, 4, 0, 0, 3205]
    [C:\Program Files\Common Files\Apple\Apple Application Support\ASL.dll]  [Apple, Inc., 1, 0, 0, 25]
    [D:\Program Files\iTunes\iTunesHelper.Resources\zh_CN.lproj\iTunesHelperLocalized.DLL]  [Apple Inc., 10.1.0.24]
    [D:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.DLL]  [Apple Inc., 10.1.1.4]
    [C:\Program Files\QuickTime\QTSystem\QuickTime.qts]  [Apple Inc., 7.6.9 (1680.9)]
    [C:\Program Files\QuickTime\QTSystem\QTCF.dll]  [Apple Inc., 7.6.9 (1680.9)]
    [C:\Program Files\Common Files\Apple\Apple Application Support\CFNetwork.DLL]  [Apple, Inc., 1, 454, 11, 5]
    [C:\Program Files\Common Files\Apple\Apple Application Support\SQLite3.dll]  [Apple Inc., 3.6.12 (74.2)]
    [C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll]  [, 1.2.3]
    [C:\Program Files\Common Files\Apple\Mobile Device Support\iTunesMobileDevice.dll]  [Apple Inc., 416.0.0.5]
[PID: 3000 / hp][C:\Program Files\Rising\RIS\RsTray.exe]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.10]
    [C:\Program Files\Rising\RIS\comserv.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.13]
    [C:\Program Files\Rising\RIS\rslang.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.1]
    [C:\Program Files\Rising\RIS\comx3.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.4]
    [C:\Program Files\Rising\RIS\Syslay.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.1]
    [C:\Program Files\Rising\RIS\ProcComm.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.1]
    [C:\Program Files\Rising\RIS\rsxml.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.2]
    [C:\Program Files\Rising\RIS\MonState.dll]  [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2]
    [C:\Program Files\Rising\RIS\ScanEvnt.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.10]
    [C:\Program Files\Rising\RIS\rsguilib.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.11]
    [C:\Program Files\Rising\RIS\rsconf.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.4]
    [C:\Program Files\Rising\RIS\rfwrule.dll]  [Beijing Rising Information Technology Co., Ltd., 22.0.0.1]
    [C:\Windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Rising\RIS\rspalvd.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.7]
    [C:\Program Files\Rising\RIS\rsnetsvr.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.12]
    [C:\Program Files\Rising\RIS\mruleui.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 10]
    [C:\Program Files\Rising\RIS\MonTray.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.78]
    [C:\Program Files\Rising\RIS\rfwtray.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 47]
    [C:\Program Files\Rising\RIS\rsmginfo.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.5]
    [C:\Program Files\Rising\RIS\UsbServ.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 3]
    [C:\Program Files\Rising\RIS\ScanTray.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.52]
    [C:\Program Files\Rising\RIS\PngDll.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 3]
    [C:\Program Files\Rising\RIS\dfw.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.65]
    [C:\Program Files\Rising\RIS\ScanPrxy.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.30]
    [C:\Program Files\Rising\RIS\GCompt.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.47]
    [C:\Program Files\Rising\RIS\Isol.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.14]
    [C:\Program Files\Rising\RIS\rsstore.dll]  [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 11]
    [C:\Program Files\Rising\RIS\RavScrCh.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.4]
    [C:\Program Files\Rising\RIS\rfwlog.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.6]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.4.0]
    [C:\Windows\System32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0401]
    [C:\Windows\system32\nvd3dum.dll]  [NVIDIA Corporation, 8.16.11.8766]
[PID: 3024 / hp][C:\Program Files\Tencent\QQDownload\QQDownload.exe]  [Tencent Technology (Shenzhen) Company Limited, 3, 0, 672, 402]
    [C:\Program Files\Tencent\QQDownload\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.4.0]
    [C:\Program Files\Tencent\QQDownload\xmain.dll]  [Tencent Technology (Shenzhen) Company Limited, 1.9.290.290]
    [C:\Program Files\Tencent\QQDownload\QQDownloadSkin.dll]  [TODO: <Company name>, 1.0.0.1]
    [C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d1c738ec43578ea1\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.4053]
    [C:\Program Files\Tencent\QQDownload\VBScript.dll]  [Microsoft Corporation, 5.6.0.7426]
    [C:\Program Files\Common Files\Tencent\TXSSO\Bin\SSOLUIControl.dll]  [Tencent, 1.0.1.8]
    [C:\Program Files\Common Files\Tencent\TXSSO\Bin\SSOCommon.DLL]  [Tencent, 1.2.1.9]
    [C:\Program Files\Common Files\Tencent\TXSSO\Bin\SSOPlatform.dll]  [Tencent, 1.2.1.14]
    [C:\Program Files\Tencent\QQDownload\Win7Feature.dll]  [, 2, 7, 625, 301]
    [C:\Program Files\Tencent\QQDownload\xdownload.dll]  [Tencent, 1, 9, 363, 402]
    [C:\Program Files\Tencent\QQDownload\xcore.dll]  [Tencent Technology(Shenzhen) Company Limited, 2, 1, 101, 90]
    [C:\Program Files\Rising\RIS\RavScrCh.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.4]
    [C:\Windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Windows\system32\nvd3dum.dll]  [NVIDIA Corporation, 8.16.11.8766]
    [C:\Windows\system32\Macromed\Flash\Flash10l.ocx]  [Adobe Systems, Inc., 10,1,102,64]
[PID: 3148 / hp][C:\Program Files\Windows Sidebar\sidebar.exe]  [Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
    [C:\Program Files\Rising\RIS\RavScrCh.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.4]
    [C:\Windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Windows\system32\nvd3dum.dll]  [NVIDIA Corporation, 8.16.11.8766]
[PID: 3520 / SYSTEM][C:\Windows\system32\SearchIndexer.exe]  [(Verified) Microsoft Corporation, 7.00.7600.16385 (win7_rtm.090713-1255)]
[PID: 3808 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 4040 / SYSTEM][C:\Program Files\iPod\bin\iPodService.exe]  [Apple Inc., 10.1.1.4]
    [C:\Program Files\iPod\bin\iPodService.Resources\zh_CN.lproj\iPodServiceLocalized.DLL]  [Apple Inc., 10.1.0.24]
    [C:\Program Files\iPod\bin\iPodService.Resources\iPodService.DLL]  [Apple Inc., 10.1.1.4]
[PID: 4080 / NETWORK SERVICE][C:\Program Files\Windows Media Player\wmpnetwk.exe]  [Microsoft Corporation, 12.0.7600.16385 (win7_rtm.090713-1255)]
[PID: 3052 / SYSTEM][C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe]  [(Verified) Microsoft Corporation, 2.0.50727.4927 (NetFXspW7.050727-4900)]
[PID: 828 / hp][C:\Users\hp\AppData\Local\Google\Chrome\Application\chrome.exe]  [Google Inc., 0.0.0.0]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\chrome.dll]  [Google Inc., 8.0.552.224]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\icudt42.dll]  [IBM Corporation and others, 4, 2, 1, 0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.4.0]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\gears.dll]  [Google Inc., 0.5.33.0]
    [C:\Windows\system32\QQPINYIN.IME]  [Tencent, 4.0.1023.400]
[PID: 108 / hp][C:\Users\hp\AppData\Local\Google\Chrome\Application\chrome.exe]  [Google Inc., 0.0.0.0]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\chrome.dll]  [Google Inc., 8.0.552.224]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\icudt42.dll]  [IBM Corporation and others, 4, 2, 1, 0]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\pdf.dll]  [, 1, 0, 0, 1]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\avcodec-52.dll]  [N/A, ]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\avutil-50.dll]  [N/A, ]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\avformat-52.dll]  [N/A, ]
[PID: 2188 / hp][C:\Users\hp\AppData\Local\Google\Chrome\Application\chrome.exe]  [Google Inc., 0.0.0.0]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\chrome.dll]  [Google Inc., 8.0.552.224]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\icudt42.dll]  [IBM Corporation and others, 4, 2, 1, 0]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\gcswf32.dll]  [, ]
[PID: 1144 / SYSTEM][C:\Program Files\Rising\RSD\RsMgrSvc.exe]  [Beijing Rising Information Technology Co., Ltd., 1.0.0.22]
    [C:\Program Files\Rising\RSD\comx3.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.4]
    [C:\Program Files\Rising\RSD\Syslay.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.1]
[PID: 3936 / hp][C:\Users\hp\AppData\Local\Google\Chrome\Application\chrome.exe]  [Google Inc., 0.0.0.0]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\chrome.dll]  [Google Inc., 8.0.552.224]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\icudt42.dll]  [IBM Corporation and others, 4, 2, 1, 0]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\pdf.dll]  [, 1, 0, 0, 1]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\avcodec-52.dll]  [N/A, ]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\avutil-50.dll]  [N/A, ]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\avformat-52.dll]  [N/A, ]
[PID: 3508 / hp][C:\Users\hp\Downloads\ifunbox_sc\iFunBox.exe]  [i-Funbox.com, V1.2 BUILD427.421]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.4.0]
    [C:\Program Files\Rising\RIS\RavScrCh.dll]  [Beijing Rising Information Technology Co., Ltd., 23.0.0.4]
    [C:\Windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Windows\system32\nvd3dum.dll]  [NVIDIA Corporation, 8.16.11.8766]
    [C:\Program Files\Common Files\Apple\Mobile Device Support\iTunesMobileDevice.dll]  [Apple Inc., 416.0.0.5]
    [C:\Program Files\Common Files\Apple\Apple Application Support\ASL.dll]  [Apple, Inc., 1, 0, 0, 25]
    [C:\Program Files\Common Files\Apple\Apple Application Support\CoreFoundation.dll]  [Apple Inc., 1,550,36,0]
    [C:\Program Files\Common Files\Apple\Apple Application Support\pthreadVC2.dll]  [Open Source Software community project, 2, 7, 0, 11200]
    [C:\Program Files\Common Files\Apple\Apple Application Support\objc.dll]  [Apple Inc., 1,435,14,19]
    [C:\Program Files\Common Files\Apple\Apple Application Support\libdispatch.dll]  [Apple Inc., 1,109,4,13]
    [C:\Program Files\Common Files\Apple\Apple Application Support\icuin40.dll]  [IBM Corporation and others, 4, 0, 0, 3205]
    [C:\Program Files\Common Files\Apple\Apple Application Support\icuuc40.dll]  [IBM Corporation and others, 4, 0, 0, 3205]
    [C:\Program Files\Common Files\Apple\Apple Application Support\icudt40.dll]  [IBM Corporation and others, 4, 0, 0, 3205]
    [C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll]  [, 1.2.3]
    [C:\Program Files\Common Files\Apple\Apple Application Support\CFNetwork.dll]  [Apple, Inc., 1, 454, 11, 5]
    [C:\Program Files\Common Files\Apple\Apple Application Support\SQLite3.dll]  [Apple Inc., 3.6.12 (74.2)]
[PID: 2636 / LOCAL SERVICE][C:\Windows\system32\WUDFHost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 2284 / hp][C:\Users\hp\AppData\Local\Google\Chrome\Application\chrome.exe]  [Google Inc., 0.0.0.0]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\chrome.dll]  [Google Inc., 8.0.552.224]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\icudt42.dll]  [IBM Corporation and others, 4, 2, 1, 0]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\pdf.dll]  [, 1, 0, 0, 1]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\avcodec-52.dll]  [N/A, ]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\avutil-50.dll]  [N/A, ]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\avformat-52.dll]  [N/A, ]
[PID: 2896 / hp][C:\Users\hp\AppData\Local\Google\Chrome\Application\chrome.exe]  [Google Inc., 0.0.0.0]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\chrome.dll]  [Google Inc., 8.0.552.224]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\icudt42.dll]  [IBM Corporation and others, 4, 2, 1, 0]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\pdf.dll]  [, 1, 0, 0, 1]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\avcodec-52.dll]  [N/A, ]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\avutil-50.dll]  [N/A, ]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\avformat-52.dll]  [N/A, ]
[PID: 3620 / hp][C:\Users\hp\AppData\Local\Google\Chrome\Application\chrome.exe]  [Google Inc., 0.0.0.0]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\chrome.dll]  [Google Inc., 8.0.552.224]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\icudt42.dll]  [IBM Corporation and others, 4, 2, 1, 0]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\libglesv2.dll]  [N/A, ]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\libegl.dll]  [N/A, ]
    [C:\Windows\system32\nvd3dum.dll]  [NVIDIA Corporation, 8.16.11.8766]
[PID: 1072 / hp][C:\Users\hp\AppData\Local\Google\Chrome\Application\chrome.exe]  [Google Inc., 0.0.0.0]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\chrome.dll]  [Google Inc., 8.0.552.224]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\icudt42.dll]  [IBM Corporation and others, 4, 2, 1, 0]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\pdf.dll]  [, 1, 0, 0, 1]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\avcodec-52.dll]  [N/A, ]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\avutil-50.dll]  [N/A, ]
    [C:\Users\hp\AppData\Local\Google\Chrome\Application\8.0.552.224\avformat-52.dll]  [N/A, ]
[PID: 3156 / hp][D:\QQDownload\QQ2010SP3.1.exe]  [, 1, 57, 1961, 0]
[PID: 3536 / SYSTEM][C:\Windows\system32\msiexec.exe]  [(Verified) Microsoft Corporation, 5.0.7600.16385 (win7_rtm.090713-1255)]
[PID: 1900 / hp][C:\Users\hp\AppData\Roaming\Tencent\QQ\STemp\SetupEx~0\QQSetupEx.exe]  [Tencent, 1, 57, 1961, 0]
    [C:\Users\hp\AppData\Roaming\Tencent\QQ\STemp\SetupEx~0\vqqsdl.dll]  [Tencent Technology (Shenzhen) Company Limited, 5, 0, 4, 22]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.4.0]
[PID: 1956 / SYSTEM][C:\Windows\servicing\TrustedInstaller.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
[PID: 4568 / hp][C:\Users\hp\Downloads\picasaweb-current-setup.exe]  [Google Inc., 2.7.37.64]
[PID: 4604 / hp][C:\Users\hp\AppData\Local\Temp\picasaupdate_7778.exe]  [Google Inc., 2.7.37.64]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.4.0]
[PID: 4664 / hp][C:\Users\hp\AppData\Local\Temp\picasaupdate_77f4.exe]  [N/A, ]
    [C:\Users\hp\AppData\Local\Temp\nsaF78A.tmp\NSIS_Picasa.dll]  [N/A, ]
[PID: 5104 / SYSTEM][C:\Windows\system32\SearchProtocolHost.exe]  [(Verified) Microsoft Corporation, 7.00.7600.16401 (win7_gdr.090727-1504)]
[PID: 5128 / SYSTEM][C:\Windows\system32\SearchFilterHost.exe]  [(Verified) Microsoft Corporation, 7.00.7600.16401 (win7_gdr.090727-1504)]
[PID: 5268 / hp][C:\Users\hp\Downloads\sreng2\SREngLdr.EXE]  [Smallfrogs Studio, 2.8.4.1331]
[PID: 5276 / hp][C:\Users\hp\Downloads\sreng2\SRE12edf5e4.EXE]  [Smallfrogs Studio, 2.8.4.1331]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.4.0]


==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["%SystemRoot%\hh.exe" %1]
.HLP  OK. [%SystemRoot%\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. ["%SystemRoot%\System32\WScript.exe" "%1" %*]
.JS  Error. [C:\Windows\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]


==================================
Winsock 提供者
N/A


==================================
Autorun.inf
N/A


==================================
HOSTS 文件
N/A


==================================
进程特权扫描
N/A


==================================
计划任务
[已启用] \\GoogleUpdateTaskUserS-1-5-21-2407859531-2370204629-2242477275-1000Core
        C:\Users\hp\AppData\Local\Google\Update\GoogleUpdate.exe /c
[已启用] \\GoogleUpdateTaskUserS-1-5-21-2407859531-2370204629-2242477275-1000UA
        C:\Users\hp\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
[已启用] \Apple\AppleSoftwareUpdate
        C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task
[已禁用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
        N/A
[已启用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
        N/A
[已禁用] \Microsoft\Windows\AppID\PolicyConverter
        %windir%\system32\appidpolicyconverter.exe
[已禁用] \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
        %windir%\system32\appidcertstorecheck.exe
[已启用] \Microsoft\Windows\Application Experience\AitAgent
        aitagent
[已启用] \Microsoft\Windows\Application Experience\ProgramDataUpdater
        %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate
[已启用] \Microsoft\Windows\Autochk\Proxy
        %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
[已启用] \Microsoft\Windows\Bluetooth\UninstallDeviceTask
        BthUdTask.exe $(Arg0)
[已启用] \Microsoft\Windows\CertificateServicesClient\SystemTask
        N/A
[已启用] \Microsoft\Windows\CertificateServicesClient\UserTask
        N/A
[已禁用] \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
        N/A
[已启用] \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
        %SystemRoot%\System32\wsqmcons.exe
[已启用] \Microsoft\Windows\Defrag\ScheduledDefrag
        %windir%\system32\defrag.exe -c
[已启用] \Microsoft\Windows\Location\Notifications
        %windir%\System32\LocationNotifications.exe
[已启用] \Microsoft\Windows\Maintenance\WinSAT
        N/A
[已启用] \Microsoft\Windows\Media Center\ActivateWindowsSearch
        %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
[已启用] \Microsoft\Windows\Media Center\ConfigureInternetTimeService
        %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
[已启用] \Microsoft\Windows\Media Center\DispatchRecoveryTasks
        %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
[已启用] \Microsoft\Windows\Media Center\ehDRMInit
        %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
[已启用] \Microsoft\Windows\Media Center\InstallPlayReady
        %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
[已启用] \Microsoft\Windows\Media Center\mcupdate
        %SystemRoot%\ehome\mcupdate $(Arg0)
[已启用] \Microsoft\Windows\Media Center\MediaCenterRecoveryTask
        %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
[已启用] \Microsoft\Windows\Media Center\MediaCenterRecoveryTask
        %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
[已启用] \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
        %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
[已启用] \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
        %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
[已启用] \Microsoft\Windows\Media Center\OCURActivate
        %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
[已启用] \Microsoft\Windows\Media Center\OCURDiscovery
        %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
[已启用] \Microsoft\Windows\Media Center\PBDADiscovery
        %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
[已启用] \Microsoft\Windows\Media Center\PBDADiscoveryW1
        %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
[已启用] \Microsoft\Windows\Media Center\PBDADiscoveryW2
        %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
[已禁用] \Microsoft\Windows\Media Center\PeriodicScanRetry
        %windir%\ehome\MCUpdate.exe -pscn 0
[已启用] \Microsoft\Windows\Media Center\PvrRecoveryTask
        %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
[已启用] \Microsoft\Windows\Media Center\PvrRecoveryTask
        %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
[已启用] \Microsoft\Windows\Media Center\PvrScheduleTask
        %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
[已启用] \Microsoft\Windows\Media Center\PvrScheduleTask
        %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
[已禁用] \Microsoft\Windows\Media Center\RecordingRestart
        %SystemRoot%\ehome\ehrec /RestartRecording
[已启用] \Microsoft\Windows\Media Center\RegisterSearch
        %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
[已启用] \Microsoft\Windows\Media Center\ReindexSearchRoot
        %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
[已启用] \Microsoft\Windows\Media Center\SqlLiteRecoveryTask
        %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
[已启用] \Microsoft\Windows\Media Center\SqlLiteRecoveryTask
        %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
[已启用] \Microsoft\Windows\Media Center\UpdateRecordPath
        %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
[已启用] \Microsoft\Windows\MobilePC\HotStart
        N/A
[已启用] \Microsoft\Windows\MUI\LPRemove
        %windir%\system32\lpremove.exe
[已启用] \Microsoft\Windows\Multimedia\SystemSoundsService
        N/A
[已启用] \Microsoft\Windows\NetTrace\GatherNetworkInfo
        %windir%\system32\gatherNetworkInfo.vbs
[已禁用] \Microsoft\Windows\Offline Files\Background Synchronization
        N/A
[已禁用] \Microsoft\Windows\Offline Files\Logon Synchronization
        N/A
[已启用] \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
        %SystemRoot%\System32\powercfg.exe -energy -auto
[已启用] \Microsoft\Windows\Ras\MobilityManager
        N/A
[已禁用] \Microsoft\Windows\SideShow\AutoWake
        N/A
[已启用] \Microsoft\Windows\SideShow\GadgetManager
        N/A
[已禁用] \Microsoft\Windows\SideShow\SessionAgent
        N/A
[已禁用] \Microsoft\Windows\SideShow\SystemDataProviders
        N/A
[已启用] \Microsoft\Windows\SystemRestore\SR
        %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
[已启用] \Microsoft\Windows\Tcpip\IpAddressConflict1
        %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
[已启用] \Microsoft\Windows\Tcpip\IpAddressConflict2
        %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
[已启用] \Microsoft\Windows\Time Synchronization\SynchronizeTime
        %windir%\system32\sc.exe start w32time task_started
[已启用] \Microsoft\Windows\UPnP\UPnPHostConfig
        sc.exe config upnphost start= auto
[已禁用] \Microsoft\Windows\User Profile Service\HiveUploadTask
        N/A
[已启用] \Microsoft\Windows\Windows Error Reporting\QueueReporting
        %windir%\system32\wermgr.exe -queuereporting
[已启用] \Microsoft\Windows\Windows Media Sharing\UpdateLibrary
        "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
[已启用] \Microsoft\Windows\WindowsBackup\ConfigNotification
        %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
[已禁用] \Microsoft\Windows\WindowsColorSystem\Calibration Loader
        N/A


==================================
Windows 安全更新检查
KB972813,  西班牙语语言包 - Windows 7 (KB972813)
KB972813,  希腊语语言包 - Windows 7 (KB972813)
KB972813,  立陶宛语语言包 - Windows 7 (KB972813)
KB972813,  阿拉伯语语言包 - Windows 7 (KB972813)
KB972813,  瑞典语语言包 - Windows 7 (KB972813)
KB972813,  德语语言包 - Windows 7 (KB972813)
KB972813,  斯洛伐克语语言包 - Windows 7 (KB972813)
KB972813,  乌克兰语语言包 - Windows 7 (KB972813)
KB972813,  繁体中文语言包 - Windows 7 (KB972813)
KB972813,  挪威语语言包 - Windows 7 (KB972813)
KB972813,  爱沙尼亚语语言包 - Windows 7 (KB972813)
KB972813,  捷克语语言包 - Windows 7 (KB972813)
KB972813,  斯洛文尼亚语语言包 - Windows 7 (KB972813)
KB972813,  日语语言包 - Windows 7 (KB972813)
KB972813,  法语语言包 - Windows 7 (KB972813)
KB972813,  英语语言包 - Windows 7 (KB972813)
KB972813,  罗马尼亚语语言包 - Windows 7 (KB972813)
KB972813,  波兰语语言包 - Windows 7 (KB972813)
KB972813,  泰语语言包 - Windows 7 (KB972813)
KB972813,  保加利亚语语言包 - Windows 7 (KB972813)
KB972813,  俄语语言包 - Windows 7 (KB972813)
KB972813,  克罗地亚语语言包 - Windows 7 (KB972813)
KB972813,  塞尔维亚语(拉丁语)语言包 - Windows 7 (KB972813)
KB972813,  葡萄牙语(葡萄牙)语言包 - Windows 7 (KB972813)
KB972813,  朝鲜语语言包 - Windows 7 (KB972813)
KB972813,  意大利语语言包 - Windows 7 (KB972813)
KB972813,  匈牙利语语言包 - Windows 7 (KB972813)
KB972813,  土耳其语语言包 - Windows 7 (KB972813)
KB972813,  丹麦语语言包 - Windows 7 (KB972813)
KB972813,  芬兰语语言包 - Windows 7 (KB972813)
KB972813,  拉脱维亚语语言包 - Windows 7 (KB972813)
KB972813,  希伯来语语言包 - Windows 7 (KB972813)
KB972813,  荷兰语语言包 - Windows 7 (KB972813)
KB972813,  葡萄牙语(巴西)语言包 - Windows 7 (KB972813)
KB976422,  Windows 7 更新程序 (KB976422)
KB2202188,  Microsoft Office 2010 更新 (KB2202188) 32 位版本
KB2289116,  Outlook Social Connector 更新 (KB2289116) 32 位版本
KB2345000,  Microsoft Word 2010 安全更新 (KB2345000) 32 位版本 MS10-079
KB2345000,  Windows Live Essentials 2011 (KB2434419)
KB2416427,  Microsoft Silverlight (KB2416427)
KB2289161,  Microsoft Office 2010 安全更新 (KB2289161) 32 位版本 MS10-087
KB982670,  用于 Windows 7 x86 的 Microsoft .NET Framework 4 Client Profile (KB982670)
KB2413186,  Microsoft Office 2010 文件验证更新 (KB2413186) 32 位版本
KB2289078,  Microsoft Office 2010 安全更新 (KB2289078) 32 位版本 MS10-105
KB982726,  Microsoft Office 2010 定义更新 (KB982726) 32 位版本
KB2433299,  Microsoft OneNote 2010 更新 (KB2433299),32 位版本
KB2409055,  Microsoft Publisher 2010 安全更新 (KB2409055) 32 位版本 MS10-103


==================================
API HOOK
N/A


==================================
隐藏进程
N/A


==================================


用户系统信息:Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10
分享到:
gototop
 

回复: 刚中奇怪病毒,已经重装,请分析一下sreng

就是计算机成黑屏,没有菜单等等应该有的东西,只有一个文件夹,可以通过文件夹运行程序。。。重装后仍然有这些奇怪项
gototop
 

回复:刚中奇怪病毒,已经重装,请分析一下sreng

楼主是Windows 7 系统

下面进程是些楼主自己运行的吧?
==================================
正在运行的进程
[PID: 4604 / hp][C:\Users\hp\AppData\Local\Temp\picasaupdate_7778.exe]  [Google Inc., 2.7.37.64]
[PID: 4664 / hp][C:\Users\hp\AppData\Local\Temp\picasaupdate_77f4.exe]  [N/A, ]
    [C:\Users\hp\AppData\Local\Temp\nsaF78A.tmp\NSIS_Picasa.dll]  [N/A, ]

日志没看出什么,建议楼主重装系统使用原始安装光盘安装,不要使用ghost版本的安装光盘。

并且进入新系统后,绝不安装任何非微软的程序,绝不使用原本保存在其他盘的任意程序,包括安装驱动也绝不使用保存在其他盘的驱动文件

然后观察看是否还继续黑屏
最后编辑天月来了 最后编辑于 2011-01-07 22:08:35
百年以后,你的墓碑旁 刻着的名字不是我
gototop
 

回复:刚中奇怪病毒,已经重装,请分析一下sreng

正版盗版?
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT