211 - 未知模块:d:\木马杀客\MSCOMCTL.OCX
212 - 未知模块:d:\木马杀客\TABCTL32.OCX
213 - 未知模块:d:\木马杀客\ftcapi.dll
214 - 未知模块:d:\木马杀客\psapi.dll
215 - 未知模块:c:\program files\Rising\antispyware\ieprot.dll
216 - 未知模块:d:\木马杀客\FTCMon.dll
217 未知进程:d:\木马杀客\scandrive.exe 命令行: D:\木马杀客\Scandrive.exe
218 - 未知模块:d:\木马杀客\ftccompress.dll
219 - 未知模块:d:\木马杀客\ftcapi.dll
220 - 未知模块:d:\木马杀客\FTCMon.dll
221 - 未知模块:c:\program files\Rising\antispyware\ieprot.dll
222 (安全进程):c:\program files\internet explorer\iexplore.exe 命令行: "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
about:blank
223 - 未知模块:d:\木马杀客\FTCMon.dll
224 - 未知模块:c:\program files\Rising\antispyware\ieprot.dll
225 - 未知模块:c:\Program Files\Alisoft\Toolbar\Assist\yasbar.dll
226 - 未知模块:c:\Program Files\Alisoft\Toolbar\Assist\ysearch.dll
227 - 未知模块:c:\Program Files\Alisoft\Toolbar\Assist\alibtn.dll
228 - 未知模块:c:\Program Files\Alisoft\Toolbar\Assist\yasnoad.dll
229 - 未知模块:c:\Program Files\Alisoft\Toolbar\Assist\yzsnetproto.dll
230 - 未知模块:c:\Program Files\Alisoft\Toolbar\Assist\antivirus.dll
231 - 未知模块:c:\Program Files\Alisoft\Toolbar\Assist\yalistorerank.dll
232 - 未知模块:d:\讯雷5\ComDlls\tdatonce_now.dll
233 - 未知模块:c:\Program Files\Alisoft\Toolbar\Assist\yangling.dll
234 - 未知模块:d:\讯雷5\ComDlls\xunleibho_now.dll
235 - 未知模块:d:\讯雷5\components\resworker\DsBho_00.dll
236 - 未知模块:d:\讯雷5\components\resworker\dataprocessor_00.dll
237 - 未知模块:c:\program files\Alisoft\Toolbar\Assist\yassist.dll
238 - 未知模块:c:\WINDOWS\system32\RavExt.dll
239 (安全进程):c:\program files\internet explorer\iexplore.exe 命令行: "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
about:blank
240 - 未知模块:d:\木马杀客\FTCMon.dll
241 - 未知模块:c:\program files\Rising\antispyware\ieprot.dll
242 - 未知模块:c:\Program Files\Alisoft\Toolbar\Assist\yasbar.dll
243 - 未知模块:c:\Program Files\Alisoft\Toolbar\Assist\ysearch.dll
244 - 未知模块:c:\Program Files\Alisoft\Toolbar\Assist\alibtn.dll
245 - 未知模块:c:\Program Files\Alisoft\Toolbar\Assist\yasnoad.dll
246 - 未知模块:c:\Program Files\Alisoft\Toolbar\Assist\yzsnetproto.dll
247 - 未知模块:c:\Program Files\Alisoft\Toolbar\Assist\antivirus.dll
248 - 未知模块:c:\Program Files\Alisoft\Toolbar\Assist\yalistorerank.dll
249 - 未知模块:d:\讯雷5\ComDlls\tdatonce_now.dll
250 - 未知模块:c:\Program Files\Alisoft\Toolbar\Assist\yangling.dll
251 - 未知模块:d:\讯雷5\ComDlls\xunleibho_now.dll
252 - 未知模块:d:\讯雷5\components\resworker\DsBho_00.dll
253 - 未知模块:d:\讯雷5\components\resworker\dataprocessor_00.dll
254 - 未知模块:c:\program files\Alisoft\Toolbar\Assist\yassist.dll
255 未知进程:d:\木马杀客\fyganalyze.exe 命令行: D:\木马杀客\FygAnalyze.exe
256 - 未知模块:d:\木马杀客\FTCMon.dll
257 - 未知模块:c:\program files\Rising\antispyware\ieprot.dll
258 - 未知模块:d:\木马杀客\psapi.dll
启动信息:
259 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
260 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
261 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
262 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>
263 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>
264 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<SoundMan><SOUNDMAN.EXE>
265 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe>
266 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"D:\瑞星杀毒\Rising\Rav\RavTask.exe" -system>
267 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<RfwMain><"D:\瑞星防火墙\Rising\Rfw\rfwmain.exe" -Startup>
268 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Windows木马防火墙><D:\木马杀客\Trojanwall.exe>
269 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
<KKDelay><C:\Program Files\Rising\AntiSpyware\RunOnce.exe>
270 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
271 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Shell><Explorer.exe>
272 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
273 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe>
274 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
275 [C:\Documents and Settings\MaoWaiWai\「开始」菜单\程序\启动\]
<C:\Documents and Settings\MaoWaiWai\「开始」菜单\程序\启动\desktop.ini>
276 [C:\Documents and Settings\All Users\「开始」菜单\程序\启动\]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\desktop.ini>
IE辅助对象BHO信息:
277 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects]
<{01443AEC-0FD1-40fd-9C87-E93D1494C233}><D:\讯雷5\ComDlls\TDAtOnce_Now.dll>
278 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects]
<{38938D50-8A48-44C2-945F-D2F23F771410}><C:\PROGRA~1\Alisoft\Toolbar\assist\yangling.dll>
279 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects]
<{889D2FEB-5411-4565-8998-1DD2C5261283}><D:\讯雷5\ComDlls\xunleiBHO_Now.dll>
280 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects]
<{FE3FCAE7-0A37-4506-8A7D-3CC9A04D2CA8}><C:\Program Files\Alisoft\Toolbar\Assist\yassist.dll>
IE右键菜单信息:
281 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<使用迅雷下载><D:\讯雷5\Program\geturl.htm>
282 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<使用迅雷下载全部链接><D:\讯雷5\Program\getallurl.htm>
IE工具栏项信息:
283 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
<{09BA8F6D-CB54-424B-839C-C2A6C8E6B436}><D:\讯雷5\Thunder.exe>
284 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
<{FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444}><http://www.rising.com.cn/?u=RSTB>
285 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
<{FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445}><http://www.ikaka.com/?u=RSTB>
ActiveX对象DPF信息:
286 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<{D27CDB6E-AE6D-11CF-96B8-444553540000}><C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx>
网络服务SPI信息:
无可疑
系统服务信息:
287 [ Application Management | AppMgmt | 停用 ]
c:\windows\system32\svchost.exe - c:\windows\system32\appmgmts.dll
288 [ ASP.NET State Service | aspnet_state | 停用 ]
c:\windows\microsoft.net\framework\v1.1.4322\aspnet_state.exe
289 [ COM+ System Application | COMSysApp | 停用 ]
c:\windows\system32\dllhost.exe /processid:{02d4b3f1-fd88-11d1-960d-00805fc79235}
290 [ Human Interface Device Access | HidServ | 停用 ]
c:\windows\system32\svchost.exe - c:\windows\system32\hidserv.dll
291 [ NVIDIA Display Driver Service | NVSvc | 启动 ]
c:\windows\system32\nvsvc32.exe
292 [ Rising Process Communication Center | RsCCenter | 启动 ]
d:\瑞星杀毒\rising\rav\ccenter.exe
293 [ Rising RealTime Monitor | RsRavMon | 启动 ]
d:\瑞星杀毒\rising\rav\ravmond.exe
294 [ MS Software Shadow Copy Provider | SwPrv | 停用 ]
c:\windows\system32\dllhost.exe /processid:{08745577-4f3a-4d7c-a78a-106f62b6bda3}
295 [ Rising Proxy Service | RfwProxySrv | 启动 ]
d:\瑞星防火墙\rising\rfw\rfwproxy.exe
296 [ Rising Personal Firewall Service | RfwService | 启动 ]
d:\瑞星防火墙\rising\rfw\rfwsrv.exe
系统驱动信息:
297 [ Service for Realtek AC97 Audio (WDM) | ALCXWDM | 启动 ]
c:\windows\system32\drivers\alcxwdm.sys
298 [ HookCont | HookCont | 启动 ]
C:\WINDOWS\system32\drivers\hookcont.sys
299 [ HookNtos | HookNtos | 启动 ]
C:\WINDOWS\system32\drivers\hookntos.sys
300 [ HookReg | HookReg | 启动 ]
C:\WINDOWS\system32\drivers\hookreg.sys
301 [ HookSys | HookSys | 启动 ]
C:\WINDOWS\system32\drivers\hooksys.sys
302 [ nv | nv | 启动 ]
c:\windows\system32\drivers\nv4_mini.sys
303 [ RsAntiSpyware | RsAntiSpyware | 启动 ]
c:\windows\system32\drivers\rsboot.sys
304 [ RsNTGDI | RsNTGDI | 启动 ]
c:\windows\system32\drivers\rsntgdi.sys
305 [ TCP/IP Protocol Driver | Tcpip | 启动 ]
c:\windows\system32\drivers\tcpip.sys
306 [ Rising Rfwbase Driver | RfwBase | 启动 ]
c:\windows\system32\drivers\rfwbase.sys
307 [ RsFwDrv | RsFwDrv | 启动 ]
d:\瑞星防火墙\rising\rfw\rsfwdrv.sys
308 [ HookUrl | HookUrl | 启动 ]
d:\瑞星防火墙\rising\rfw\hookurl.sys
309 [ bootdrv | bootdrv | 停用 ]
c:\windows\system32\drivers\bootdrv.sys
310 [ FTCProtect | FTCProtect | 启动 ]
c:\windows\system32\drivers\ftcprotect.sys
311 [ FTCProTime | FTCProTime | 启动 ]
c:\windows\system32\drivers\ftcprotime.sys
已经加载的驱动信息:
312 C:\WINDOWS\system32\drivers\rsboot.sys
313 C:\WINDOWS\system32\drivers\rsntgdi.sys
314 C:\WINDOWS\system32\drivers\nv4_mini.sys
315 C:\WINDOWS\system32\drivers\alcxwdm.sys
316 C:\WINDOWS\system32\drivers\tcpip.sys
317 C:\WINDOWS\system32\drivers\hooksys.sys
318 C:\WINDOWS\system32\drivers\hookhelp.sys
319 C:\WINDOWS\system32\drivers\hookreg.sys
320 C:\WINDOWS\system32\drivers\hookntos.sys