[D:\Program Files\kingsoft\KSM\kae\kaearchb.dat] [Kingsoft Corporation, 2010,03,18,77]
[PID: 260 / SYSTEM][D:\Program Files\Kingsoft\SystemCleaner\kscsvc.exe] [Kingsoft Corporation, 2010,05,21,64]
[D:\Program Files\Kingsoft\SystemCleaner\kdump.dll] [Kingsoft Corporation, 2010,04,29,944]
[D:\Program Files\Kingsoft\SystemCleaner\kbccore.dll] [Kingsoft Corporation, 2010,05,21,64]
[D:\Program Files\Kingsoft\SystemCleaner\KIPC.dll] [Kingsoft Corporation, 2010,05,21,64]
[D:\Program Files\Kingsoft\SystemCleaner\ksscore.dll] [Kingsoft Corporation, 2010,05,14,1013]
[D:\Program Files\Kingsoft\SystemCleaner\kxebase.dll] [Kingsoft Corporation, 2009,11,20,309]
[D:\Program Files\Kingsoft\SystemCleaner\scom.dll] [Kingsoft Corporation, 2009,11,20,309]
[D:\Program Files\Kingsoft\SystemCleaner\kxecore\kxecore.dll] [Kingsoft Corporation, 2009,11,20,309]
[D:\Program Files\Kingsoft\SystemCleaner\KSE\ksecorex.dll] [Kingsoft Corporation, 2010,04,28,98]
[D:\Program Files\Kingsoft\SystemCleaner\KSE\kae\kaecore.dat] [Kingsoft Corporation, 2010,03,18,77]
[D:\Program Files\Kingsoft\SystemCleaner\kxesansp.dll] [Kingsoft Corporation, 2010,05,13,1000]
[D:\Program Files\Kingsoft\SystemCleaner\KSE\kae\karchive.dat] [Kingsoft Corporation, 2010,03,18,77]
[D:\Program Files\Kingsoft\SystemCleaner\KSE\kae\kaearcha.dat] [Kingsoft Corporation, 2010,03,18,77]
[D:\Program Files\Kingsoft\SystemCleaner\KSE\kae\kaeolea.dat] [Kingsoft Corporation, 2010,03,18,77]
[D:\Program Files\Kingsoft\SystemCleaner\KSE\kae\kaearchb.dat] [Kingsoft Corporation, 2010,03,18,77]
[PID: 484 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:\WINDOWS\system32\bthcrp.dll] [Broadcom Corporation., 5.5.0.4400]
[C:\WINDOWS\system32\WidcommSdk.dll] [Broadcom Corporation., 5.5.0.4400]
[C:\WINDOWS\system32\wbtapi.dll] [Broadcom Corporation., 5.5.0.4400]
[C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159]
[C:\WINDOWS\system32\CNMLM8R.DLL] [CANON INC., 2.10.2.11]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\CNMPD8R.DLL] [CANON INC., 2.10.2.10]
[PID: 940 / QinFei][C:\WINDOWS\system32\igfxtray.exe] [Intel Corporation, 6.14.10.4906]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 6.14.10.4906]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 6.14.10.4906]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 6.14.10.4906]
[C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 6.14.10.4906]
[PID: 976 / QinFei][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 6.14.10.4906]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 6.14.10.4906]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 6.14.10.4906]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 6.14.10.4906]
[PID: 1012 / QinFei][C:\Program Files\Elantech\ETDCtrl.exe] [ELANTECH Devices Corp., 7, 0, 4, 3]
[C:\Program Files\Elantech\ETDIsos.dll] [ELANTECH Devices Corp., 7, 0, 4, 0]
[C:\Program Files\Elantech\ETDApix.dll] [ELANTECH Devices Corp., 7, 0, 4, 4]
[C:\Program Files\Elantech\ETDCmds.dll] [ELANTECH Devices Corp., 7, 0, 4, 3]
[D:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 6]
[PID: 1008 / QinFei][C:\Program Files\EeePC\ACPI\AsTray.exe] [ASUSTeK Computer Inc., 5, 1, 1, 4008]
[C:\WINDOWS\system32\IGFXEXPS.DLL] [Intel Corporation, 6.14.10.4906]
[PID: 148 / QinFei][C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe] [ASUSTeK Computer Inc., 5, 1, 1, 4009]
[D:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 6]
[C:\WINDOWS\system32\IGFXEXPS.DLL] [Intel Corporation, 6.14.10.4906]
[PID: 1236 / QinFei][C:\Program Files\EeePC\ACPI\AsEPCMon.exe] [ASUSTeK Computer Inc., 5, 1, 1, 1002]
[PID: 1436 / QinFei][C:\WINDOWS\system32\igfxsrvc.exe] [Intel Corporation, 6.14.10.4906]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 6.14.10.4906]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 6.14.10.4906]
[PID: 1512 / QinFei][C:\WINDOWS\RTHDCPL.EXE] [Realtek Semiconductor Corp., 2.2.4.3]
[D:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 6]
[PID: 1708 / QinFei][D:\Program Files\Rising\AntiSpyware\rstray.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.29]
[D:\Program Files\Rising\AntiSpyware\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4]
[D:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 6]
[D:\Program Files\Rising\AntiSpyware\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2]
[D:\Program Files\Rising\AntiSpyware\ComServ.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.33]
[D:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[D:\Program Files\Rising\AntiSpyware\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[D:\Program Files\Rising\AntiSpyware\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[D:\Program Files\Rising\AntiSpyware\rscommon.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.1.1]
[D:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[D:\Program Files\Rising\AntiSpyware\rsxml1.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2]
[D:\Program Files\Rising\AntiSpyware\pngdll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5]
[D:\Program Files\Rising\AntiSpyware\runiep.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.65]
[D:\Program Files\Rising\AntiSpyware\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.11]
[D:\Program Files\Rising\AntiSpyware\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[D:\Program Files\Rising\AntiSpyware\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
[PID: 1768 / QinFei][D:\Program Files\Rising\Ris\RsTray.exe] [Beijing Rising Information Technology Co., Ltd., 22.0.0.11]
[D:\Program Files\Rising\Ris\comserv.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.15]
[D:\Program Files\Rising\Ris\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1]
[D:\Program Files\Rising\Ris\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[D:\Program Files\Rising\Ris\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[D:\Program Files\Rising\Ris\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4]
[D:\Program Files\Rising\Ris\rsxml.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2]
[D:\Program Files\Rising\Ris\MonState.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2]
[D:\Program Files\Rising\Ris\ScanEvnt.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.3]
[D:\Program Files\Rising\Ris\rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 57]
[D:\Program Files\Rising\Ris\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1]
[D:\Program Files\Rising\Ris\rfwrule.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.6030.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.6030.0]
[D:\Program Files\Rising\Ris\rspalvd.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.7]
[D:\Program Files\Rising\Ris\rsnetsvr.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3]
[D:\Program Files\Rising\Ris\ravbintl.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 22]
[D:\Program Files\Rising\Ris\mruleui.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 7]
[D:\Program Files\Rising\Ris\MonTray.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.74]
[D:\Program Files\Rising\Ris\RavITray.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6]
[D:\Program Files\Rising\Ris\rfwtray.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 39]
[D:\Program Files\Rising\Ris\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4]
[D:\Program Files\Rising\Ris\scanleak.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6]
[D:\Program Files\Rising\Ris\ravppops.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 21]
[D:\Program Files\Rising\Ris\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0]
[D:\Program Files\Rising\Ris\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0]
[D:\Program Files\Rising\Ris\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4]
[D:\Program Files\Rising\Ris\ScanPrxy.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.4]
[D:\Program Files\Rising\Ris\rfwlog.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.15]
[PID: 584 / QinFei][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[D:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 6]
[PID: 648 / QinFei][D:\Program Files\DAEMON Tools Lite\daemon.exe] [DT Soft Ltd, 4.30.4.0027]
[D:\Program Files\DAEMON Tools Lite\DTCommonRes.dll] [DT Soft Ltd, 4.30.4.0027]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\MFC80U.DLL] [Microsoft Corporation, 8.00.50727.4053]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\MFC80CHS.DLL] [Microsoft Corporation, 8.00.50727.4053]
[D:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 6]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll] [Microsoft Corporation, 2.0.50727.3603 (GDR.050727-3600)]
[C:\Program Files\ASUS\Eee Storage\XPClient.dll] [Ecareme, 1.0.0.0]
[D:\Program Files\DAEMON Tools Lite\Engine.dll] [DT Soft Ltd, 4.30.4.0027]
[D:\Program Files\DAEMON Tools Lite\imgengine.dll] [DT Soft Ltd., 1.17.0.0]
[PID: 808 / QinFei][C:\WINDOWS\system32\igfxext.exe] [Intel Corporation, 6.14.10.4906]
[D:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 6]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 6.14.10.4906]
[C:\WINDOWS\system32\IGFXEXPS.DLL] [Intel Corporation, 6.14.10.4906]
[PID: 1612 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1868 / SYSTEM][C:\Program Files\CMBCHINA\WebProtect\WPService.exe] [China Merchants Bank, 1, 0, 0, 1]
[C:\Program Files\CMBCHINA\WebProtect\WebProtectPlus.dll] [China Merchants Bank, 1, 0, 0, 1]
[PID: 2232 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 3100 / SYSTEM][C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe] [Broadcom Corporation., 5.5.0.4400]
[PID: 3428 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[PID: 2908 / QinFei][D:\Program Files\Rising\AntiSpyware\knownsvr.exe] [Beijing Rising Information Technology Co., Ltd., 6.0.0.14]
[D:\Program Files\Rising\AntiSpyware\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.11]
[D:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[D:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[D:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 6]
[PID: 2924 / QinFei][D:\Program Files\Maxthon2\Maxthon.exe] [Maxthon International ltd., 2, 5, 9, 2246]
[D:\Program Files\Maxthon2\MxProxy2.dll] [Maxthon International ltd., 1, 0, 0, 4339]
[D:\Program Files\Maxthon2\MxUI.dll] [Maxthon International ltd., 3, 3, 1, 30]
[D:\Program Files\Maxthon2\MxAccount.dll] [Maxthon International ltd., 1, 0, 0, 27]
[D:\Program Files\Maxthon2\MxHttpRq.dll] [Maxthon International ltd., 1, 0, 0, 8]
[D:\Program Files\Maxthon2\MxTool.dll] [, 1, 0, 0, 3]
[D:\Program Files\Maxthon2\maxzlib.dll] [, 1.2.3]
[D:\Program Files\Maxthon2\MxPp.dll] [Maxthon International ltd., 1, 0, 0, 323]
[D:\Program Files\Maxthon2\MxSk.dll] [Maxthon, 1, 0, 0, 569]
[D:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 6]
[D:\Program Files\Maxthon2\mxtool2.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll] [Microsoft Corporation, 2.0.50727.3603 (GDR.050727-3600)]
[C:\Program Files\ASUS\Eee Storage\XPClient.dll] [Ecareme, 1.0.0.0]
[D:\Program Files\Maxthon2\MxFav.dll] [Maxthon International ltd., 2, 0, 0, 169]
[C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159]
[C:\WINDOWS\system32\Macromed\Flash\Flash10e.ocx] [Adobe Systems, Inc., 10,0,45,2]
[C:\Program Files\Elantech\ETDApix.dll] [ELANTECH Devices Corp., 7, 0, 4, 4]
[D:\Program Files\AliWangWang\AliIMX.dll] [Alibaba software (Shanghai) Corporation., 1.0.0.1]
[D:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll] [深圳市迅雷网络技术有限公司, 5,9,20,1418]
[D:\Program Files\Thunder\ComDlls\MSVCP71.dll] [Microsoft Corporation, 7.10.6030.0]
[D:\Program Files\Thunder\ComDlls\MSVCR71.dll] [Microsoft Corporation, 7.10.6030.0]
[D:\Program Files\Thunder\ComDlls\ATL71.DLL] [Microsoft Corporation, 7.10.6101.0]
[D:\Program Files\Thunder\ComDlls\zlib1.dll] [, 1.2.3]
[PID: 3324 / QinFei][D:\Program Files\WinRAR\WinRAR.exe] [, ]
[D:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 6]
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll] [Microsoft Corporation, 2.0.50727.3603 (GDR.050727-3600)]
[C:\Program Files\ASUS\Eee Storage\XPClient.dll] [Ecareme, 1.0.0.0]
[C:\Program Files\Elantech\ETDApix.dll] [ELANTECH Devices Corp., 7, 0, 4, 4]
[PID: 2304 / QinFei][C:\Documents and Settings\QinFei\桌面\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.8.2.1321]
[PID: 1296 / QinFei][C:\Documents and Settings\QinFei\桌面\sreng2\SREb3a20106.EXE] [Smallfrogs Studio, 2.8.2.1321]
[D:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 6]
[C:\Documents and Settings\QinFei\桌面\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1008, C:\PROGRAM FILES\EEEPC\ACPI\ASTRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 148, C:\PROGRAM FILES\EEEPC\ACPI\ASACPISVR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3324, D:\PROGRAM FILES\WINRAR\WINRAR.EXE]
==================================
计划任务
N/A
==================================
Windows 安全更新检查
Microsoft .NET Framework 版本 1.1 简体中文语言包
KB829019, Microsoft .NET Framework 2.0 语言包:x86 (KB829019)
KB892130, Windows 正版增值验证工具 (KB892130)
KB940157, 用于 Windows XP 的 Windows 搜索 4.0 (KB940157)
KB928416, Microsoft .NET Framework 3.0: x86 语言包 (KB928416)
KB909520, Microsoft 基本智能卡加密服务提供程序包: x86 (KB909520)
KB951847, Microsoft .NET Framework 3.5 Service Pack 1 (KB951847) x86 语言包
KB971513, Windows XP 更新程序 (KB971513)
KB976569, 用于 Windows Server 2003 和 Windows XP x86 的 Microsoft .NET Framework 2.0 Service Pack 2 更新程序 (KB976569)
KB931125, 根证书更新程序 [2010 年 5 月] (KB931125)
KB982632, 用于 Windows XP 的 Internet Explorer 8 兼容性视图列表的更新程序 (KB982632)
KB890830, Windows 恶意软件删除工具 - 2010 年 6 月 (KB890830)
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]