- <C:\WINDOWS\AppPatch\AcGenral.DLL>[5.1.2600.5512 (xpsp.080413-2105), Microsoft Corporation]
- <C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll>[6.0 (xpsp.080413-2105), Microsoft Corporation]
- <C:\WINDOWS\system32\mdimon.dll>[11.3.8166.2, Microsoft Corporation]
- <C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll>[11.3.8166.2, Microsoft Corporation]
* [PID:520]<nvsvc32.exe><C:\WINDOWS\system32\nvsvc32.exe>[6.14.11.7813, NVIDIA Corporation]
- <C:\WINDOWS\system32\kmon.dll>[1, 0, 0, 33, Beijing Rising Information Technology Co., Ltd.]
- <D:\Program Files\kaka\comx3.dll>[21.0.0.37, Beijing Rising Information Technology Co., Ltd.]
- <D:\Program Files\kaka\Syslay.dll>[21.0.0.6, Beijing Rising Information Technology Co., Ltd.]
- <C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll>[6.0 (xpsp.080413-2105), Microsoft Corporation]
- <C:\WINDOWS\system32\nvapi.dll>[6.14.11.7813, NVIDIA Corporation]
* [PID:600]<svchost.exe><C:\WINDOWS\system32\svchost.exe>[5.1.2600.5512 (xpsp.080413-2111), Microsoft Corporation]
* [PID:704]<alg.exe><C:\WINDOWS\System32\alg.exe>[5.1.2600.5512 (xpsp.080413-0852), Microsoft Corporation]
- <C:\WINDOWS\AppPatch\AcGenral.DLL>[5.1.2600.5512 (xpsp.080413-2105), Microsoft Corporation]
- <C:\WINDOWS\System32\kmon.dll>[1, 0, 0, 33, Beijing Rising Information Technology Co., Ltd.]
- <C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll>[6.0 (xpsp.080413-2105), Microsoft Corporation]
- <D:\Program Files\kaka\comx3.dll>[21.0.0.37, Beijing Rising Information Technology Co., Ltd.]
- <D:\Program Files\kaka\Syslay.dll>[21.0.0.6, Beijing Rising Information Technology Co., Ltd.]
* [PID:2020]<Explorer.EXE><C:\WINDOWS\Explorer.EXE>[6.00.2900.5512 (xpsp.080413-2105), Microsoft Corporation]
- <C:\WINDOWS\AppPatch\AcGenral.DLL>[5.1.2600.5512 (xpsp.080413-2105), Microsoft Corporation]
- <C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll>[6.0 (xpsp.080413-2105), Microsoft Corporation]
- <C:\Program Files\FreeLaunchBar\flb.dll>[1.0.0.0, TrueSoft]
- <C:\WINDOWS\system32\dot3api.dll>[5.1.2600.5512 (xpsp.080413-0852), Microsoft Corporation]
- <C:\WINDOWS\system32\dot3dlg.dll>[5.1.2600.5512 (xpsp.080413-0852), Microsoft Corporation]
- <C:\WINDOWS\system32\OneX.DLL>[5.1.2600.5512 (xpsp.080413-0852), Microsoft Corporation]
- <C:\WINDOWS\system32\eappcfg.dll>[5.1.2600.5512 (xpsp.080413-0852), Microsoft Corporation]
- <C:\WINDOWS\system32\eappprxy.dll>[5.1.2600.5512 (xpsp.080413-0852), Microsoft Corporation]
- <C:\WINDOWS\system32\nvcpl.dll>[6.14.11.7813, NVIDIA Corporation]
- <C:\WINDOWS\system32\NVRSZHC.DLL>[6.14.11.7813, NVIDIA Corporation]
- <C:\WINDOWS\system32\nvapi.dll>[6.14.11.7813, NVIDIA Corporation]
- <C:\WINDOWS\system32\nvshell.dll>[, ]
- <C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll>[1.0.5.29, Thunder Networking Technologies,LTD]
- <C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll>[5, 0, 8, 96, Thunder Networking Technologies,LTD]
- <C:\WINDOWS\system32\sti.dll>[5.1.2600.5512 (xpsp.080413-0852), Microsoft Corporation]
- <C:\Program Files\Rising\Ris\RavScrCh.dll>[21.0.0.69, Beijing Rising Information Technology Co., Ltd.]
- <C:\WINDOWS\system32\vbscript.dll>[5.7.0.18066, Microsoft Corporation]
- <C:\WINDOWS\system32\PRINTUI.dll>[5.1.2600.5512 (xpsp.080413-0852), Microsoft Corporation]
- <C:\WINDOWS\system32\wmdmlog.dll>[10.0.3790.3802, Microsoft Corporation]
* [PID:3004]<RUNDLL32.EXE><C:\WINDOWS\system32\RUNDLL32.EXE>[5.1.2600.5512 (xpsp.080413-2105), Microsoft Corporation]
- <C:\WINDOWS\AppPatch\AcGenral.DLL>[5.1.2600.5512 (xpsp.080413-2105), Microsoft Corporation]
- <C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll>[6.0 (xpsp.080413-2105), Microsoft Corporation]
- <C:\WINDOWS\system32\NvMcTray.dll>[6.14.11.7813, NVIDIA Corporation]
- <C:\WINDOWS\system32\nvapi.dll>[6.14.11.7813, NVIDIA Corporation]
- <C:\WINDOWS\system32\NVRSZHC.DLL>[6.14.11.7813, NVIDIA Corporation]
* [PID:3736]<RSTray.exe><D:\Program Files\kaka\rstray.exe>[21.0.0.16, Beijing Rising Information Technology Co., Ltd.]
* [PID:3672]<CTFMON.EXE><C:\WINDOWS\system32\ctfmon.exe>[5.1.2600.5512 (xpsp.080413-2105), Microsoft Corporation]
- <C:\WINDOWS\AppPatch\AcGenral.DLL>[5.1.2600.5512 (xpsp.080413-2105), Microsoft Corporation]
- <C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll>[6.0 (xpsp.080413-2105), Microsoft Corporation]
* [PID:476]<knownsvr.exe><D:\Program Files\kaka\knownsvr.exe>[6.0.0.14, Beijing Rising Information Technology Co., Ltd.]
- <D:\Program Files\kaka\NComm.dll>[6.0.0.11, Beijing Rising Information Technology Co., Ltd.]
- <C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll>[6.0 (xpsp.080413-2105), Microsoft Corporation]
- <D:\Program Files\kaka\comx3.dll>[21.0.0.37, Beijing Rising Information Technology Co., Ltd.]
- <D:\Program Files\kaka\Syslay.dll>[21.0.0.6, Beijing Rising Information Technology Co., Ltd.]
* [PID:3220]<CCenter.exe><C:\Program Files\Rising\Ris\CCENTER.EXE>[21, 0, 0, 2, Beijing Rising Information Technology Co., Ltd.]
* [PID:1888]<RavTask.exe><C:\Program Files\Rising\Ris\RavTask.exe>[21, 0, 0, 24, Beijing Rising Information Technology Co., Ltd.]
* [PID:2972]<ScanFrm.exe><C:\Program Files\Rising\Ris\ScanFrm.exe>[21.0.0.11, Beijing Rising Information Technology Co., Ltd.]
* [PID:4024]<conime.exe><C:\WINDOWS\system32\conime.exe>[5.1.2600.5512 (xpsp.080413-2105), Microsoft Corporation]
- <C:\WINDOWS\AppPatch\AcGenral.DLL>[5.1.2600.5512 (xpsp.080413-2105), Microsoft Corporation]
- <C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll>[6.0 (xpsp.080413-2105), Microsoft Corporation]
* [PID:3612]<RsTray.exe><C:\PROGRAM FILES\RISING\RIS\RSTRAY.EXE>[21.0.0.22, Beijing Rising Information Technology Co., Ltd.]
* [PID:436]<rsnetsvr.exe><C:\PROGRAM FILES\RISING\RIS\RSNETSVR.EXE>[21, 0, 0, 15, Beijing Rising Information Technology Co., Ltd.]
* [PID:332]<RavMonD.exe><C:\Program Files\Rising\Ris\RavMonD.exe>[21, 0, 0, 1, Beijing Rising Information Technology Co., Ltd.]
* [PID:3384]<RegGuide.exe><C:\Program Files\Rising\Ris\RegGuide.exe>[21.0.0.12, Beijing Rising Information Technology Co., Ltd.]
* [PID:2712]<QQ.exe><D:\Program Files\新建文件夹\QQ.exe>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\QQBaseClassInDll.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\QQHelperDll.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\BasicCtrlDll.dll>[8,0,1248,1851, TENCENT]
- <C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.dll>[6.0 (xpsp.080413-2105), Microsoft Corporation]
- <D:\Program Files\新建文件夹\MFC42.DLL>[6.00.8665.0, Microsoft Corporation]
- <D:\Program Files\新建文件夹\RICHED32.DLL>[5.00.2134.1, Microsoft Corporation]
- <D:\Program Files\新建文件夹\RICHED20.dll>[5.31.23.1218, Microsoft Corporation]
- <D:\Program Files\新建文件夹\QQAPI.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\LoginCtrl.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\LoginCtrlRes.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\QQRes.dll>[8,0,978,1833, TENCENT]
- <D:\Program Files\新建文件夹\QQMainFrame.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\gdiplus.dll>[5.1.3102.2180 (xpsp_sp2_rtm.040803-2158), Microsoft Corporation]
- <D:\Program Files\新建文件夹\UnReadMsgMgr.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\QQAllInOne.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\SCCore.dll>[1, 6, 0, 2, TENCENT]
- <D:\Program Files\新建文件夹\CameraDll.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\CQQApplication.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\FlashAvatarDll.dll>[1, 0, 0, 1, ]
- <D:\Program Files\新建文件夹\NewSkin.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\MailSummary.dll>[8,0,1234,1851, TENCENT]
- <D:\Program Files\新建文件夹\QQSpace.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\UserDefinedHead.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\QQPlugin.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\vbscript.dll>[5.6.0.7426, Microsoft Corporation]
- <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx>[9,0,124,0, Adobe Systems, Inc.]
- <C:\WINDOWS\system32\msdmo.dll>[, ]
- <D:\Program Files\新建文件夹\QQAvatar.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\OEMApplication.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\QQKnowledgeSearch.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\QQGroupMng.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\QQPet.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\QQCustomFace.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\LongConnection.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\QQConfigPlugin.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\QQMagicFace.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\ImageOle.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\QRingMng.dll>[8,0,1300,1881, TENCENT]
- <C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL>[11.0.8164, Microsoft Corporation]
- <D:\Program Files\新建文件夹\QQLiveQMng.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\PhoneAPI.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\DialerAllinOne.dll>[1, 4, 0, 0, tencent]
- <D:\Program Files\新建文件夹\GroupConnection.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\BQQApplication.dll>[8,0,1300,1881, TENCENT]
- <C:\WINDOWS\system32\winabc.ime>[5.1.2600.5512, Microsoft Corporation]
- <D:\Program Files\新建文件夹\CommercesMng.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\PersonalDesktop.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\QQAddr.dll>[5, 0, 101, 330, 深圳市腾讯计算机系统有限公司]
- <D:\Program Files\新建文件夹\QQSceneMng.dll>[8,0,1300,1881, TENCENT]
- <D:\Program Files\新建文件夹\AddrSearch.dll>[2, 3, 10, 12, Tencent]
- <D:\Program Files\新建文件夹\QQSysMsgMng.dll>[8,0,1300,1881, TENCENT]
- <C:\WINDOWS\system32\dot3api.dll>[5.1.2600.5512 (xpsp.080413-0852), Microsoft Corporation]
- <C:\WINDOWS\system32\dot3dlg.dll>[5.1.2600.5512 (xpsp.080413-0852), Microsoft Corporation]
- <C:\WINDOWS\system32\OneX.DLL>[5.1.2600.5512 (xpsp.080413-0852), Microsoft Corporation]
- <C:\WINDOWS\system32\eappcfg.dll>[5.1.2600.5512 (xpsp.080413-0852), Microsoft Corporation]
- <C:\WINDOWS\system32\eappprxy.dll>[5.1.2600.5512 (xpsp.080413-0852), Microsoft Corporation]
- <C:\WINDOWS\system32\WINWB86.IME>[4.00.950, Microsoft Corporation]
- <C:\Program Files\Rising\Ris\RavScrCh.dll>[21.0.0.69, Beijing Rising Information Technology Co., Ltd.]
- <C:\WINDOWS\system32\vbscript.dll>[5.7.0.18066, Microsoft Corporation]
* [PID:452]<TXPlatform.exe><D:\Program Files\新建文件夹\TXPlatform.exe>[1, 5, 225, 0, Tencent]
* [PID:2396]<arvmon.exe><D:\TDDOWNLOAD\新建文件夹 (3)\arvmon.exe>[2.3.3.180, 任软工作室]
- <C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.dll>[6.0 (xpsp.080413-2105), Microsoft Corporation]
- <D:\TDDOWNLOAD\新建文件夹 (3)\Vdata.dll>[2, 4, 0, 138, 任软工作室]
* [PID:272]<AutoGuarder.exe><D:\TDDOWNLOAD\新建文件夹 (3)\AutoGuarder.exe>[2.3.3.180, 任软工作室]
- <C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.dll>[6.0 (xpsp.080413-2105), Microsoft Corporation]
- <C:\Program Files\Rising\Ris\RavScrCh.dll>[21.0.0.69, Beijing Rising Information Technology Co., Ltd.]
- <C:\WINDOWS\system32\vbscript.dll>[5.7.0.18066, Microsoft Corporation]
- <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx>[9,0,124,0, Adobe Systems, Inc.]
* [PID:3356]<iexplore.exe><C:\Program Files\Internet Explorer\iexplore.exe>[6.00.2900.5512 (xpsp.080413-2105), Microsoft Corporation]
- <C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll>[6.0 (xpsp.080413-2105), Microsoft Corporation]
- <C:\WINDOWS\system32\KakaTool.dll>[6, 0, 0, 3, Beijing Rising Information Technology Co., Ltd.]
- <D:\Program Files\kaka\syslay.dll>[21.0.0.6, Beijing Rising Information Technology Co., Ltd.]
- <D:\Program Files\kaka\comx3.dll>[21.0.0.37, Beijing Rising Information Technology Co., Ltd.]
- <C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll>[1.0.5.29, Thunder Networking Technologies,LTD]
- <C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll>[5, 0, 8, 96, Thunder Networking Technologies,LTD]
- <C:\WINDOWS\system32\UrlFilter.dll>[6, 0, 0, 15, Beijing Rising Information Technology Co., Ltd.]
- <D:\Program Files\kaka\UrlRule.dll>[1.0.0.15, Beijing Rising Information Technology Co., Ltd.]
- <C:\Program Files\Microsoft Office\OFFICE11\msohev.dll>[11.0.5510, Microsoft Corporation]
- <C:\Program Files\Rising\Ris\RavScrCh.dll>[21.0.0.69, Beijing Rising Information Technology Co., Ltd.]
- <C:\WINDOWS\system32\vbscript.dll>[5.7.0.18066, Microsoft Corporation]
- <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx>[9,0,124,0, Adobe Systems, Inc.]
文件类型关联
======================================================
.exe文件:正常。["%1" %*]
.com文件:正常。["%1" %*]
.pif文件:正常。["%1" %*]
.bat文件:正常。["%1" %*]
.scr文件:正常。["%1" /S]
.vbs文件:正常。[%SystemRoot%\System32\WScript.exe "%1" %*]
.txt文件:正常。[C:\WINDOWS\notepad.exe %1]
.ini文件:正常。[C:\WINDOWS\System32\NOTEPAD.EXE %1]
.inf文件:正常。[%SystemRoot%\system32\NOTEPAD.EXE %1]
.hlp文件:正常。[%SystemRoot%\System32\winhlp32.exe %1]
.chm文件:正常。["hh.exe" %1]
.reg文件:正常。[regedit.exe "%1"]
.lnk文件:正常。[{00021401-0000-0000-C000-000000000046}]
IE浏览器相关设置
======================================================
当前IE主页:
http://www.baidu.com/当前IE搜索页:
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch禁止IE主页修改:否
浏览器BHO
======================================================
[ThunderAtOnce Class]
<{01443AEC-0FD1-40fd-9C87-E93D1494C233}><C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll>[1.0.5.29, Thunder Networking Technologies,LTD]
[Thunder Browser Helper]
<{889D2FEB-5411-4565-8998-1DD2C5261283}><C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll>[5, 0, 8, 96, Thunder Networking Technologies,LTD]
[卡卡上网安全助手]
<{98B7C13A-E9CD-4959-8B46-FBEAB41E42A8}><C:\WINDOWS\system32\UrlFilter.dll>[6, 0, 0, 15, Beijing Rising Information Technology Co., Ltd.]
资源管理器HOOK项
======================================================
[URL 执行挂钩]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>[6.00.2900.5512 (xpsp.080413-2105), Microsoft Corporation]
IFEO映像劫持
======================================================
<N/A>
Hosts文件
======================================================
127.0.0.1 localhost
Autorun.inf文件及指向文件
======================================================
本地磁盘C: - 没有发现
本地磁盘D: - 没有发现
本地磁盘E: - 没有发现
本地磁盘F: - 没有发现