[PID: 1376 / SYSTEM][E:\工具\迅雷7\Program\DctSer.exe] [深圳市迅雷网络技术有限公司, 1.0.1.81]
[PID: 1400 / Administrator][C:\Program Files\Rising\AntiSpyware\rstray.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.32]
[C:\Program Files\Rising\AntiSpyware\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 5.2.0.5374]
[C:\Program Files\SogouInput\5.2.0.5374\Resource.dll] [Sogou.com Inc., 5.2.0.5374]
[C:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 7]
[C:\Program Files\Rising\AntiSpyware\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2]
[C:\Program Files\Rising\AntiSpyware\ComServ.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.33]
[C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[C:\Program Files\Rising\AntiSpyware\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Rising\AntiSpyware\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Rising\AntiSpyware\rscommon.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.1.1]
[C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[C:\Program Files\Rising\AntiSpyware\rsxml1.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2]
[C:\Program Files\Rising\AntiSpyware\pngdll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5]
[C:\Program Files\Rising\AntiSpyware\runiep.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.78]
[C:\Program Files\Rising\AntiSpyware\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.11]
[C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[C:\Program Files\Rising\AntiSpyware\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[PID: 1416 / Administrator][C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\WDCertM_CCB.exe] [ Beijing WatchData System Co., Ltd., 3, 2, 0, 0]
[C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\TokenMgr.dll] [ Beijing WatchData System Co., Ltd., 3, 6, 3, 2]
[C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\WDAlg.DLL] [ Beijing WatchData System C0., Ltd., 3, 5, 12, 20]
[C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\wdkmgr.dll] [Watchdata, 2, 1, 1, 40]
[C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\WDPKCS.dll] [ Beijing WatchData System Co., Ltd., 3, 6, 2, 15]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 5.2.0.5374]
[C:\Program Files\SogouInput\5.2.0.5374\Resource.dll] [Sogou.com Inc., 5.2.0.5374]
[C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\WDEvent.dll] [ Beijing WatchData System Co., Ltd., 3, 2, 5, 0]
[C:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 7]
[PID: 1436 / Administrator][C:\Program Files\Rising\Rav\RSTRAY.EXE] [Beijing Rising Information Technology Co., Ltd., 23.0.0.10]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Rising\Rav\comserv.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.13]
[C:\Program Files\Rising\Rav\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.1]
[C:\Program Files\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.4]
[C:\Program Files\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.1]
[C:\Program Files\Rising\Rav\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.1]
[C:\Program Files\Rising\Rav\rsxml.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.2]
[C:\Program Files\Rising\Rav\MonState.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2]
[C:\Program Files\Rising\Rav\ScanEvnt.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.10]
[C:\Program Files\Rising\Rav\rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.11]
[C:\Program Files\Rising\Rav\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.4]
[C:\Program Files\Rising\Rav\rspalvd.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.7]
[C:\Program Files\Rising\Rav\mruleui.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 10]
[C:\Program Files\Rising\Rav\MonTray.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.88]
[C:\Program Files\Rising\Rav\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.6]
[C:\Program Files\Rising\Rav\UsbServ.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 3]
[C:\Program Files\Rising\Rav\ScanTray.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.54]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 3]
[C:\Program Files\Rising\Rav\dfw.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.66]
[C:\Program Files\Rising\Rav\ScanPrxy.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.30]
[C:\Program Files\Rising\Rav\GCompt.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.49]
[C:\Program Files\Rising\Rav\Isol.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.14]
[C:\Program Files\Rising\Rav\rsstore.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.12]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.10]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 1312 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 7]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 5.2.0.5374]
[C:\Program Files\SogouInput\5.2.0.5374\Resource.dll] [Sogou.com Inc., 5.2.0.5374]
[PID: 1328 / Administrator][C:\Program Files\Netcore\Netcore 11BG PCI&Cardbus Wireless LAN Utility\RtWLan.exe] [Realtek Semiconductor Corp., 500, 1516, 219, 2008]
[C:\Program Files\Netcore\Netcore 11BG PCI&Cardbus Wireless LAN Utility\RtlICS.dll] [Realtek, 1, 0, 320, 2007]
[C:\Program Files\Netcore\Netcore 11BG PCI&Cardbus Wireless LAN Utility\EnumDevLib.dll] [, 400, 1030, 1026, 2006]
[C:\Program Files\Netcore\Netcore 11BG PCI&Cardbus Wireless LAN Utility\RtlLib.dll] [Realtek Semiconductor Corp., 402, 1308, 102, 2008]
[C:\Program Files\Netcore\Netcore 11BG PCI&Cardbus Wireless LAN Utility\acAuth.dll] [, 4.0.2.0 2005-07-19 16:52:58]
[C:\Program Files\Netcore\Netcore 11BG PCI&Cardbus Wireless LAN Utility\LIBEAY32.dll] [The OpenSSL Project,
http://www.openssl.org/, 0.9.8b]
[C:\Program Files\Netcore\Netcore 11BG PCI&Cardbus Wireless LAN Utility\IpLib.dll] [TODO: <Company name>, 1.0.0.1]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 7]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 5.2.0.5374]
[C:\Program Files\SogouInput\5.2.0.5374\Resource.dll] [Sogou.com Inc., 5.2.0.5374]
[PID: 3724 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 516 / Administrator][D:\我的文档\桌面\平台测试客户端\VSCLIENT.EXE] [广州唯思软件有限公司, 3, 1, 6, 130]
[D:\我的文档\桌面\平台测试客户端\CSDT.dll] [vs, 6, 5, 125, 1526]
[D:\我的文档\桌面\平台测试客户端\VSIPC.dll] [vs, 5, 3, 1006, 2147]
[D:\我的文档\桌面\平台测试客户端\WYClientDataAPI.dll] [vs, 8, 0, 127, 2242]
[D:\我的文档\桌面\平台测试客户端\iconv.dll] [Free Software Foundation, 1.9]
[D:\我的文档\桌面\平台测试客户端\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[D:\我的文档\桌面\平台测试客户端\dbghelp.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\我的文档\桌面\平台测试客户端\LiveCtrl.dll] [weisi, 3, 7, 1011, 1910]
[D:\我的文档\桌面\平台测试客户端\MapSource.dll] [vs, 2, 3, 112, 1649]
[D:\我的文档\桌面\平台测试客户端\SCLiveDT.dll] [weisi, 1, 3, 1011, 1916]
[D:\我的文档\桌面\平台测试客户端\scscdt.dll] [vs, 2, 5, 125, 1529]
[D:\我的文档\桌面\平台测试客户端\VSFace.dll] [vs, 1, 4, 504, 1631]
[D:\我的文档\桌面\平台测试客户端\VSGI.dll] [, 1, 0, 0, 1]
[D:\我的文档\桌面\平台测试客户端\VSIM.dll] [N/A, ]
[D:\我的文档\桌面\平台测试客户端\VSSGDT.dll] [weisi, 1, 0, 127, 2206]
[D:\我的文档\桌面\平台测试客户端\War3KeyTool.dll] [, 1, 8, 310, 1628]
[D:\我的文档\桌面\平台测试客户端\WARDT.dll] [vs, 7, 0, 125, 1532]
[D:\我的文档\桌面\平台测试客户端\WEDT.dll] [vs, 3, 0, 125, 1533]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 7]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 5.2.0.5374]
[C:\Program Files\SogouInput\5.2.0.5374\Resource.dll] [Sogou.com Inc., 5.2.0.5374]
[D:\我的文档\桌面\平台测试客户端\VSRes.dll] [vs, 2, 5, 1201, 53]
[D:\我的文档\桌面\平台测试客户端\VSPICRes.dll] [N/A, ]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.10]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 1728 / Administrator][C:\WINDOWS\system32\conime.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 7]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 5.2.0.5374]
[C:\Program Files\SogouInput\5.2.0.5374\Resource.dll] [Sogou.com Inc., 5.2.0.5374]
[C:\Program Files\SogouInput\5.2.0.5374\ZipLib.dll] [Sogou.com Inc., 1.0.0.0000]
[PID: 176 / Administrator][D:\游戏\魔兽争霸\Warcraft III\War3.exe] [Blizzard Entertainment, 1, 24, 2, 6378]
[D:\游戏\魔兽争霸\Warcraft III\Storm.dll] [Blizzard Entertainment, 1.09]
[D:\游戏\魔兽争霸\Warcraft III\mss32.dll] [N/A, ]
[D:\我的文档\桌面\平台测试客户端\VSIPC.dll] [vs, 5, 3, 1006, 2147]
[D:\我的文档\桌面\平台测试客户端\UDP_P2P.dll] [vs, 2, 0, 112, 1958]
[D:\我的文档\桌面\平台测试客户端\VSMsgHelper.dll] [vs, 1, 1, 120, 1206]
[D:\我的文档\桌面\平台测试客户端\WarRPGHook.dll] [vs, 2, 7, 115, 1048]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 7]
[D:\我的文档\桌面\平台测试客户端\info\game.dll] [Blizzard Entertainment, 1, 24, 4, 6387]
[D:\游戏\魔兽争霸\Warcraft III\ijl15.dll] [Intel Corporation, 1,5,4,36]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 5.2.0.5374]
[C:\Program Files\SogouInput\5.2.0.5374\Resource.dll] [Sogou.com Inc., 5.2.0.5374]
[D:\游戏\魔兽争霸\Warcraft III\redist\miles\Mp3dec.asi] [N/A, ]
[D:\游戏\魔兽争霸\Warcraft III\redist\miles\Mssdolby.m3d] [N/A, ]
[D:\游戏\魔兽争霸\Warcraft III\redist\miles\Msseax2.m3d] [N/A, ]
[D:\游戏\魔兽争霸\Warcraft III\redist\miles\Mssfast.m3d] [N/A, ]
[D:\游戏\魔兽争霸\Warcraft III\redist\miles\Reverb3.flt] [N/A, ]
[PID: 3412 / Administrator][d:\我的文档\桌面\SREngLdr.EXE] [Smallfrogs Studio, 2.8.4.1331]
[PID: 3056 / Administrator][d:\我的文档\桌面\SRE9c3a6868.EXE] [Smallfrogs Studio, 2.8.4.1331]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 7]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 5.2.0.5374]
[C:\Program Files\SogouInput\5.2.0.5374\Resource.dll] [Sogou.com Inc., 5.2.0.5374]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 2008, C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\DATACARDSERVICE\DCSERVICE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 792, C:\WINDOWS\SYSTEM32\WATCHDATA\WATCHDATA CCB CSP V3.2\WDKEYMONITORCCB.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1304, C:\WINDOWS\SYSTEM32\GP_CLT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1416, C:\WINDOWS\SYSTEM32\WATCHDATA\WATCHDATA CCB CSP V3.2\WDCERTM_CCB.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1328, C:\PROGRAM FILES\NETCORE\NETCORE 11BG PCI&CARDBUS WIRELESS LAN UTILITY\RTWLAN.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 516, D:\我的文档\桌面\平台测试客户端\VSCLIENT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 516, D:\我的文档\桌面\平台测试客户端\VSCLIENT.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 176, D:\游戏\魔兽争霸\WARCRAFT III\WAR3.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 176, D:\游戏\魔兽争霸\WARCRAFT III\WAR3.EXE]
==================================
计划任务
[已启用] User_Feed_Synchronization-{5E3783DE-7103-413E-A7B9-FAB30CAEAE21}.job
C:\WINDOWS\system32\msfeedssync.exe
[已启用] SogouImeMgr.job
C:\PROGRA~1\SOGOUI~1\520~1.537\SGTool.exe
[已启用] GoogleUpdateTaskMachineUA.job
C:\Program Files\Google\Update\GoogleUpdate.exe
[已启用] GoogleUpdateTaskMachineCore.job
C:\Program Files\Google\Update\GoogleUpdate.exe
==================================
Windows 安全更新检查
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
N/A