进程模块信息:
1 (安全进程):C:\WINDOWS\system32\smss.exe 命令行: \SystemRoot\System32\smss.exe
2 (安全进程):c:\WINDOWS\system32\winlogon.exe 命令行: winlogon.exe
3 (安全进程):c:\WINDOWS\system32\services.exe 命令行: C:\WINDOWS\system32\services.exe
4 (安全进程):c:\WINDOWS\system32\lsass.exe 命令行: C:\WINDOWS\system32\lsass.exe
5 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost -k DcomLaunch
6 (安全进程):c:\program files\Rising\Ris\CCenter.exe 命令行: "C:\Program Files\Rising\Ris\CCENTER.EXE" -Next
7 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\System32\svchost.exe -k netsvcs
8 (安全进程):c:\program files\Rising\Ris\RavMonD.exe 命令行: "C:\Program Files\Rising\Ris\RavMonD.exe" -Next
9 - 未知模块:c:\program files\Rising\Ris\MailMon.dll
10 - 未知模块:c:\program files\Rising\Ris\rfwsrv.dll
11 - 未知模块:c:\program files\Rising\Ris\rsnetsvr.dll
12 - 未知模块:c:\program files\Rising\Ris\urlrule.dll
13 - 未知模块:c:\program files\Rising\Ris\VirusLib.dll
14 - 未知模块:c:\program files\Rising\Ris\rfwproxy.dll
15 - 未知模块:c:\program files\Rising\Ris\CfgDll.dll
16 - 未知模块:c:\program files\Rising\Ris\bacore.dll
17 - 未知模块:c:\program files\Rising\Ris\RsStore.dll
18 - 未知模块:c:\program files\Rising\Ris\Scanner.dll
19 - 未知模块:c:\program files\Rising\Ris\scanexec.dll
20 - 未知模块:c:\program files\Rising\Ris\ScanEX.dll
21 - 未知模块:c:\program files\Rising\Ris\ExtFile.dll
22 - 未知模块:c:\program files\Rising\Ris\ScanSct.dll
23 - 未知模块:c:\program files\Rising\Ris\Urllib.dll
24 (安全进程):c:\WINDOWS\system32\spoolsv.exe 命令行: C:\WINDOWS\system32\spoolsv.exe
25 未知进程:d:\program files\StormII\stormliv.exe 命令行: "d:\Program Files\StormII\stormliv.exe" /asservice
26 - 未知模块:d:\program files\StormII\box\BoxLog.dll
27 (安全进程):c:\program files\common files\microsoft shared\VS7DEBUG\MDM.EXE 命令行: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
28 未知进程:c:\program files\Rising\Ris\RavTask.exe 命令行: "C:\Program Files\Rising\Ris\RavTask.exe" RisTask
29 - 未知模块:c:\program files\Rising\Ris\rsconf.dll
30 - 未知模块:c:\program files\Rising\Ris\CfgDll.dll
31 - 未知模块:c:\program files\Rising\Ris\RsTask.dll
32 (安全进程):c:\program files\Rising\Ris\ScanFrm.exe 命令行: "C:\Program Files\Rising\Ris\ScanFrm.exe" -Next
33 (安全进程):c:\program files\common files\VMware\vmware virtual image editing\vmount2.exe 命令行: "C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe"
34 (安全进程):c:\WINDOWS\explorer.exe 命令行: C:\WINDOWS\Explorer.EXE
35 - 未知模块:c:\program files\360\360Safe\safemon\safemon.dll
36 - 未知模块:d:\软件安装文件夹\应用软件\讯雷\components\resworker\DsBho_01.dll
37 - 未知模块:d:\软件安装文件夹\应用软件\讯雷\components\resworker\dataprocessor_01.dll
38 (安全进程):c:\WINDOWS\system32\vmnat.exe 命令行: C:\WINDOWS\system32\vmnat.exe
39 (安全进程):c:\WINDOWS\system32\vmnetdhcp.exe 命令行: C:\WINDOWS\system32\vmnetdhcp.exe
40 未知进程:c:\program files\Rising\Ris\rsnetsvr.exe 命令行: "C:\Program Files\Rising\Ris\rsnetsvr.exe"
41 未知进程:c:\program files\Rising\Ris\RsTray.exe 命令行: "C:\Program Files\Rising\Ris\RsTray.exe" -system
42 - 未知模块:c:\program files\Rising\Ris\comserv.dll
43 - 未知模块:c:\program files\Rising\Ris\rslang.dll
44 - 未知模块:c:\program files\Rising\Ris\monstate.dll
45 - 未知模块:c:\program files\Rising\Ris\RsGuiLib.dll
46 - 未知模块:c:\program files\Rising\Ris\rsconf.dll
47 - 未知模块:c:\program files\Rising\Ris\CfgDll.dll
48 - 未知模块:c:\program files\Rising\Ris\rspalvd.dll
49 - 未知模块:c:\program files\Rising\Ris\rsnetsvr.dll
50 - 未知模块:c:\program files\Rising\Ris\ravbintl.dll
51 - 未知模块:c:\program files\Rising\Ris\MonTray.dll
52 - 未知模块:c:\program files\Rising\Ris\ScanPrxy.dll
53 - 未知模块:c:\program files\Rising\Ris\rfwtray.dll
54 - 未知模块:c:\program files\Rising\Ris\rsmginfo.dll
55 (安全进程):d:\program files\Rising\antispyware\RSTray.exe 命令行: "D:\Program Files\Rising\AntiSpyware\rstray.exe" /startup
56 - 未知模块:d:\program files\Rising\antispyware\rsmginfo.dll
57 (安全进程):c:\program files\360\360safebox\safeboxtray.exe 命令行: "C:\Program Files\360\360safebox\safeboxTray.exe" /r
58 未知进程:c:\program files\360\360Safe\safemon\360tray.exe 命令行: "C:\Program Files\360\360Safe\safemon\360tray.exe" /start
59 - 未知模块:c:\program files\360\360Safe\safemon\360procmon.dll
60 - 未知模块:c:\program files\360\360Safe\safemon\360compro.dll
61 - 未知模块:c:\program files\360\360Safe\safemon\safemon.dll
62 - 未知模块:c:\program files\360\360Safe\safemon\urlproc.dll
63 - 未知模块:c:\program files\360\360Safe\safemon\360webpro.dll
64 (安全进程):c:\WINDOWS\system32\ctfmon.exe 命令行: "C:\WINDOWS\system32\ctfmon.exe"
65 (安全进程):d:\软件安装文件夹\系统安全\windows木马清道夫\ftcleaner.exe 命令行: "D:\软件安装文件夹\系统安全\Windows木马清道夫\FTCleaner.exe"
66 - 未知模块:c:\program files\360\360Safe\safemon\safemon.dll
67 (安全进程):c:\WINDOWS\system32\conime.exe 命令行: C:\WINDOWS\system32\conime.exe
68 - 未知模块:c:\program files\360\360Safe\safemon\safemon.dll
69 (安全进程):d:\软件安装文件夹\系统安全\windows木马清道夫\fyganalyze.exe 命令行: D:\软件安装文件夹\系统安全\Windows木马清道夫\FygAnalyze.exe
70 - 未知模块:c:\program files\360\360Safe\safemon\safemon.dll
启动信息:
71 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<RisTray><"C:\Program Files\Rising\Ris\RsTray.exe" -system>
72 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<runeip><"d:\Program Files\Rising\AntiSpyware\rstray.exe" /startup>
73 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<360Safebox><"C:\Program Files\360\360safebox\safeboxTray.exe" /r>
74 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<360Safetray><C:\Program Files\360\360Safe\safemon\360tray.exe /start>
75 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
<KKDelay><D:\Program Files\Rising\AntiSpyware\RunOnce.exe>
76 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
77 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Shell><Explorer.exe>
78 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
79 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe>
80 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><kmon.dll>
IE辅助对象BHO信息:
81 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
<{B69F34DD-F0F9-42DC-9EDD-957187DA688D}><C:\Program Files\360\360Safe\safemon\safemon.dll>
IE右键菜单信息:
82 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<使用迅雷下载><D:\软件安装文件夹\应用软件\讯雷\Program\geturl.htm>
83 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<使用迅雷下载全部链接><D:\软件安装文件夹\应用软件\讯雷\Program\getallurl.htm>
84 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<添加到QQ表情><d:\Program Files\Tencent\QQ\AddEmotion.htm>
IE工具栏项信息:
无可疑
ActiveX对象DPF信息:
无可疑
网络服务SPI信息:
无可疑
映像劫持IFEO信息:
无可疑
系统服务信息:
85 [ Contrl Center of Storm Media | ccosm | 启动 ]
d:\program files\stormii\stormliv.exe
86 [ Kingsoft Basic Service | kaccore | 停用 ]
c:\program files\kingsoft\kac\service\kaccore.exe
87 [ Rising RisTask Manager | RisTask | 启动 ]
c:\program files\rising\ris\ravtask.exe
系统驱动信息:
88 [ hooksys | hooksys | 启动 ]
c:\windows\system32\drivers\hooksys.sys
89 [ rsfwdrv | rsfwdrv | 启动 ]
c:\program files\rising\ris\rsfwdrv.sys
90 [ SafeBoxKrnl | SafeBoxKrnl | 启动 ]
c:\windows\system32\drivers\safeboxkrnl.sys
已经加载的驱动信息:
91 c:\windows\system32\drivers\safeboxkrnl.sys
92 c:\program files\rising\ris\rsfwdrv.sys
93 c:\program files\rising\ris\rfwhelp.sys
94 C:\WINDOWS\system32\drivers\hooksys.sys
95 C:\WINDOWS\system32\drivers\hookhelp.sys
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; MAXTHON 2.0)