浏览器加载项
[Adobe PDF Link Helper]
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll, (Signed) Adobe Systems Incorporated>
[BitComet Helper]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <E:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll, (Signed) BitComet>
[CBBrowerBuddy Class]
{A412E581-59B2-485E-834F-C5F0C0268C79} <E:\Program Files\Kingsoft\PowerWord Lite\CBEBand.dll, (Signed) Copyright (c) Kingsoft Corporation Limited. All rights reserved.>
[SafeMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <E:\Program Files\360safe\safemon\safemon.dll, (Signed) 360.CN>
[BitComet Helper]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <E:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll, (Signed) BitComet>
[]
{98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} <, >
[SafeMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <E:\Program Files\360safe\safemon\safemon.dll, (Signed) 360.CN>
[]
{D18A0B52-D63C-4ED0-AFC6-C1E3DC1AF43A} <, >
[&使用BitComet下载]
<res://E:\Program Files\BitComet\BitComet.exe/AddLink.htm, N/A>
[&使用BitComet下载全部链接]
<res://E:\Program Files\BitComet\BitComet.exe/AddAllLink.htm, N/A>
[&使用BitComet下载本页视频]
<res://E:\Program Files\BitComet\BitComet.exe/AddVideo.htm, N/A>
[导出到 Microsoft Excel(&X)]
<res://E:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000, N/A>
==================================
正在运行的进程
[PID: 2740 / Polly][C:\Windows\system32\Dwm.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\igdumdx32.dll] [Intel Corporation, 7.15.10.1537]
[C:\Windows\system32\igdumd32.dll] [Intel Corporation, 7.15.10.1537]
[E:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005]
[PID: 2780 / Polly][C:\Windows\Explorer.EXE] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\system32\igfxpph.dll] [Intel Corporation, 7.14.10.1537]
[C:\Windows\system32\hccutils.DLL] [Intel Corporation, 7.14.10.1537]
[C:\Windows\system32\igfxsrvc.dll] [Intel Corporation, 7.14.10.1537]
[C:\Windows\system32\igfxrCHS.lrc] [Intel Corporation, 7.14.10.1537]
[E:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005]
[C:\Windows\system32\icm32.dll] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[E:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Windows\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.18]
[E:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17]
[PID: 3004 / Polly][E:\Program Files\Rising\Rising\Rfw\RfwMain.exe] [Beijing Rising Information Technology Co., Ltd., 7.0.1.70]
[C:\Windows\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[E:\Program Files\Rising\Rising\Rfw\RsGuiLib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 90]
[C:\Windows\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
[E:\Program Files\Rising\Rising\Rfw\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[E:\Program Files\Rising\Rising\Rfw\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[E:\Program Files\Rising\Rising\Rfw\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1]
[E:\Program Files\Rising\Rising\Rfw\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19]
[E:\Program Files\Rising\Rising\Rfw\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17]
[E:\Program Files\Rising\Rising\Rfw\RfwCtrl.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9]
[E:\Program Files\Rising\Rising\Rfw\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2]
[E:\Program Files\Rising\Rising\Rfw\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5]
[E:\Program Files\Rising\Rising\Rfw\RfwRule.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.17]
[E:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005]
[E:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7]
[PID: 3268 / Polly][C:\Windows\system32\taskeng.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[E:\Program Files\Rising\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21]
[E:\Program Files\Rising\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9]
[C:\Windows\system32\igfxTMM.dll] [Intel Corporation, 7.14.10.1537]
[C:\Windows\system32\igfxdev.dll] [Intel Corporation, 7.14.10.1537]
[PID: 3972 / Polly][C:\Program Files\Windows Defender\MSASCui.exe] [Microsoft Corporation, 1.1.1505.0]
[PID: 2364 / Polly][E:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.01.27]
[C:\Windows\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Windows\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
[E:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[E:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[E:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17]
[E:\Program Files\Rising\Rav\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 41]
[E:\Program Files\Rising\Rav\refs.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 18]
[E:\Program Files\Rising\Rav\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27]
[E:\Program Files\Rising\Rav\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17]
[E:\Program Files\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1]
[E:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19]
[E:\Program Files\Rising\Rav\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.29]
[E:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5]
[E:\Program Files\Rising\Rav\Rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 90]
[E:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2]
[PID: 3140 / Polly][C:\Windows\ehome\ehtray.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 3420 / Polly][C:\Windows\ehome\ehmsas.exe] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[E:\Program Files\Rising\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21]
[E:\Program Files\Rising\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9]
[PID: 2592 / Polly][E:\Program Files\Tencent\QQ2009\Bin\TXPlatform.exe] [Tencent, 1, 15, 305, 0]
[E:\Program Files\Rising\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21]
[E:\Program Files\Rising\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9]
[E:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005]
[E:\Program Files\Tencent\QQ2009\Bin\TXPFProxy.dll] [N/A, ]
[PID: 3060 / Polly][E:\Program Files\BitComet\BitComet.exe] [
www.BitComet.com, 1.05]
[E:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005]
[E:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7]
[PID: 1336 / Polly][E:\Program Files\Mozilla Firefox\firefox.exe] [Mozilla Corporation, 1.9]
[E:\Program Files\Mozilla Firefox\xul.dll] [Mozilla Foundation, 1.9]
[E:\Program Files\Mozilla Firefox\sqlite3.dll] [sqlite.org, 3.5.4.1]
[E:\Program Files\Mozilla Firefox\MOZCRT19.dll] [Mozilla Foundation, 8.00.0000]
[E:\Program Files\Mozilla Firefox\js3250.dll] [Netscape Communications Corporation, 4.0]
[E:\Program Files\Mozilla Firefox\nspr4.dll] [Mozilla Foundation, 4.7.1]
[E:\Program Files\Mozilla Firefox\smime3.dll] [Mozilla Foundation, 3.12.0.3 Basic ECC]
[E:\Program Files\Mozilla Firefox\nss3.dll] [Mozilla Foundation, 3.12.0.3 Basic ECC]
[E:\Program Files\Mozilla Firefox\nssutil3.dll] [Mozilla Foundation, 3.12.0.3 Basic ECC]
[E:\Program Files\Mozilla Firefox\plc4.dll] [Mozilla Foundation, 4.7.1]
[E:\Program Files\Mozilla Firefox\plds4.dll] [Mozilla Foundation, 4.7.1]
[E:\Program Files\Mozilla Firefox\ssl3.dll] [Mozilla Foundation, 3.12.0.3 Basic ECC]
[E:\Program Files\Mozilla Firefox\xpcom.dll] [Mozilla Foundation, 1.9]
[E:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005]
[E:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7]
[E:\Program Files\Mozilla Firefox\components\browserdirprovider.dll] [Mozilla Foundation, 1.9]
[E:\Program Files\Mozilla Firefox\components\brwsrcmp.dll] [Mozilla Foundation, 1.9]
[C:\Users\Polly\AppData\Roaming\Mozilla\Firefox\Profiles\pzg1cgch.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll] [N/A, ]
[E:\Program Files\Mozilla Firefox\softokn3.dll] [Mozilla Foundation, 3.12.0.3 Basic ECC]
[E:\Program Files\Mozilla Firefox\nssdbm3.dll] [Mozilla Foundation, 3.12.0.3 Basic ECC]
[E:\Program Files\Mozilla Firefox\freebl3.dll] [Mozilla Foundation, 3.12.0.3 Basic ECC]
[E:\Program Files\Mozilla Firefox\nssckbi.dll] [Mozilla Foundation, 1.70]
[C:\Windows\system32\Macromed\Flash\NPSWF32.dll] [, ]
[E:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[E:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[PID: 3768 / Polly][E:\Program Files\WinRAR\WinRAR.exe] [N/A, ]
[E:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005]
[PID: 1716 / Polly][C:\Users\Polly\AppData\Local\Temp\Rar$EX00.072\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210]
[PID: 4028 / Polly][C:\Users\Polly\AppData\Local\Temp\Rar$EX00.072\SRE1d8474b.EXE] [Smallfrogs Studio, 2.7.0.1210]
[E:\Program Files\360safe\safemon\safemon.dll] [360.CN, 4, 2, 0, 1005]
[C:\Users\Polly\AppData\Local\Temp\Rar$EX00.072\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[E:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.7]
==================================
文件关联
.TXT Error. [C:\Windows\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["%SystemRoot%\hh.exe" %1]
.HLP OK. [%SystemRoot%\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. ["%SystemRoot%\System32\WScript.exe" "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
Rising Net Filter over [MSAFD Tcpip [TCP/IP]]
E:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Information Technology Co., Ltd., HookSpi Dll)
Rising Net Filter over [RSVP TCP 服务提供商]
E:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Information Technology Co., Ltd., HookSpi Dll)
Rising Net Filter
E:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Information Technology Co., Ltd., HookSpi Dll)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
::1 localhost
==================================
进程特权扫描
N/A
==================================
计划任务
[已启用] \Microsoft\Windows\Bluetooth\UninstallDeviceTask
BthUdTask.exe $(Arg0)
[已启用] \Microsoft\Windows\CertificateServicesClient\UserTask
N/A
[已启用] \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
N/A
[已启用] \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
%SystemRoot%\System32\wsqmcons.exe
[已启用] \Microsoft\Windows\Customer Experience Improvement Program\OptinNotification
%SystemRoot%\System32\wsqmcons.exe -n 0x1C577FA2B69CAD0
[已启用] \Microsoft\Windows\Defrag\ManualDefrag
%windir%\system32\defrag.exe -c
[已启用] \Microsoft\Windows\Defrag\ScheduledDefrag
%windir%\system32\defrag.exe -c -i
[已启用] \Microsoft\Windows\Media Center\ehDRMInit
%SystemRoot%\ehome\ehPrivJob.exe /DRMInit
[已启用] \Microsoft\Windows\Media Center\mcupdate
%SystemRoot%\ehome\mcupdate $(Arg0) -gc
[已启用] \Microsoft\Windows\Media Center\OCURActivate
%SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
[已启用] \Microsoft\Windows\Media Center\OCURDiscovery
%SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery
[已启用] \Microsoft\Windows\Media Center\UpdateRecordPath
%SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
[已启用] \Microsoft\Windows\MobilePC\HotStart
N/A
[已启用] \Microsoft\Windows\MobilePC\TMM
N/A
[已启用] \Microsoft\Windows\MUI\LPRemove
%windir%\system32\lpremove.exe
[已启用] \Microsoft\Windows\MUI\Mcbuilder
C:\Windows\System32\mcbuilder.exe
[已启用] \Microsoft\Windows\Multimedia\SystemSoundsService
N/A
[已启用] \Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
N/A
[已启用] \Microsoft\Windows\Shell\CrawlStartPages
N/A
[已禁用] \Microsoft\Windows\SideShow\AutoWake
N/A
[已启用] \Microsoft\Windows\SideShow\GadgetManager
N/A
[已禁用] \Microsoft\Windows\SideShow\SessionAgent
N/A
[已禁用] \Microsoft\Windows\SideShow\SystemDataProviders
N/A
[已启用] \Microsoft\Windows\SystemRestore\SR
%windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
[已启用] \Microsoft\Windows\Tcpip\IpAddressConflict1
rundll32 ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
[已启用] \Microsoft\Windows\Tcpip\IpAddressConflict2
rundll32 ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
[已启用] \Microsoft\Windows\UPnP\UPnPHostConfig
sc.exe config upnphost start= auto
[已启用] \Microsoft\Windows\Windows Error Reporting\QueueReporting
%windir%\system32\wermgr.exe -queuereporting
[已启用] \Microsoft\Windows\Wired\GatherWiredInfo
%windir%\system32\gatherWiredInfo.vbs
[已启用] \Microsoft\Windows\Wireless\GatherWirelessInfo
%windir%\system32\gatherWirelessInfo.vbs
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================