Browser Add-ons
[Helper
Object Class]
{00C6482D-C502-44C8-8409-FCE54AD9C208} (D:\Program Files\TechSmith\SnagIt 88\SnagItBHO.dll, TechSmith Corporation)
[wmpdrm]
{0E674588-66B7-4E19-9D0E-2053B800F69F} (C:\WINDOWS\System32\wmpdrm.dll, N/A)
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!)
[QQBrowserHelper
Object Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} (D:\Program Files\Tencent\qq\QQIEHelper.dll, ??????????????)
[DriveLetterAccess]
{5CA3D70E-1895-11CF-8E15-001234567890} (C:\WINDOWS\system32\dla\tfswshx.dll, Sonic Solutions)
[&Research]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} (D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation)
[闪客精灵]
{E19ADC6E-3909-43E4-9A89-B7B676377EE3} (, N/A)
[????????]
{EF72500A-C234-46C4-BF0A-9AA6913DDF34} (C:\Program Files\KOS\KOSIEBar.dll, ??????????)
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!)
[SnagIt]
{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} (D:\Program Files\TechSmith\SnagIt 88\SnagItIEAddin.dll, TechSmith Corporation)
[Office Update Installation Engine]
{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (C:\WINDOWS\opuc.dll, Microsoft Corporation)
[&??????]
(8E405-C6DE-49FF-83AE-41EE9F4C36CE}, N/A)
[&??????????]
(, N/A)
[Add to QQ Customized Panel]
(D:\Program Files\Tencent English version\qq\AddPanel.htm, N/A)
[Add to QQ Emoticons]
(D:\Program Files\Tencent English version\qq\AddEmotion.htm, N/A)
[Send picture by MMS]
(D:\Program Files\Tencent English version\qq\SendMMS.htm, N/A)
[Send the Picture by QQ MMS]
(D:\Program Files\Tencent English version\qq\SendMMS.htm, N/A)
[闪客精灵]
(d:\Program Files\SourceTec\sothinkflash\InternetExplorer.htm, N/A)
[使用网际快车下载]
(D:\Program Files\FlashGet\jc_link.htm, N/A)
[使用网际快车下载全部链接]
(D:\Program Files\FlashGet\jc_all.htm, N/A)
[???QQ????]
(, N/A)
[????????]
(, N/A)
[????????????]
(, N/A)
[??? Microsoft Excel(&x)]
(, N/A)
[???QQ?????]
(, N/A)
[???QQ??]
(, N/A)
[?QQ???????]
(, N/A)
--------------------------------------------------------------------------------
Running Processes
[PID: 772][\SystemRoot\System32\smss.exe] (Microsoft Corporation)(5.1.2600.1106 (xpsp1.020828-1920))
[PID: 856][\??\C:\WINDOWS\system32\csrss.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 896][\??\C:\WINDOWS\system32\winlogon.exe] (Microsoft Corporation)(5.1.2600.1557 (xpsp2_gdr.040517-1325))
[C:\WINDOWS\System32\vrlogon.dll] (UPEK Inc.)(4.5.3.167)
[C:\Program Files\IBM fingerprint software\ExtVapi.dll] (UPEK Inc.)(4.5.3.167)
[C:\Program Files\Common Files\Virtual Token\psutil.dll] (UPEK Inc.)(4.5.3.167)
[C:\Program Files\Common Files\Virtual Token\resmgr.dll] (UPEK Inc.)(4.5.3.167)
[C:\Program Files\Common Files\Virtual Token\Remote.dll] (UPEK Inc.)(4.5.3.167)
[C:\WINDOWS\system32\tphklock.dll] (N/A)(N/A)
[C:\Program Files\Common Files\Virtual Token\passport.dll] (UPEK Inc.)(4.5.3.167)
[C:\Program Files\Common Files\Virtual Token\psdlg.dll] (UPEK Inc.)(4.5.3.167)
[PID: 940][C:\WINDOWS\system32\services.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 976][C:\WINDOWS\system32\lsass.exe] (Microsoft Corporation)(5.1.2600.1106 (xpsp1.020828-1920))
[PID: 1140][C:\Program Files\Common Files\Virtual Token\vtserver.exe] (UPEK Inc.)(4.5.3.167)
[C:\Program Files\Common Files\Virtual Token\psutil.dll] (UPEK Inc.)(4.5.3.167)
[C:\Program Files\Common Files\Virtual Token\passport.dll] (UPEK Inc.)(4.5.3.167)
[C:\Program Files\Common Files\Virtual Token\DevTc.dll] (UPEK Inc.)(4.5.3.167)
[C:\Program Files\Common Files\Virtual Token\BTcVer.dll] (UPEK Inc.)(4.5.3.167)
[C:\Program Files\Common Files\Virtual Token\Remote.dll] (UPEK Inc.)(4.5.3.167)
[C:\Program Files\Common Files\Virtual Token\config.dll] (UPEK Inc.)(4.5.3.167)
[C:\Program Files\Common Files\Virtual Token\LocPass.dll] (UPEK Inc.)(4.5.3.167)
[C:\Program Files\Common Files\Virtual Token\SBioPass.dll] (UPEK Inc.)(4.5.3.167)
[C:\Program Files\Common Files\Virtual Token\AlgVer.dll] (UPEK Inc.)(4.5.3.167)
[PID: 1160][C:\WINDOWS\System32\ibmpmsvc.exe] (N/A)(N/A)
[PID: 1188][C:\WINDOWS\System32\Ati2evxx.exe] (ATI Technologies Inc.)(6.14.10.4110)
[C:\WINDOWS\System32\Ati2edxx.dll] (ATI Technologies, Inc.)(6, 14, 10, 2495)
[PID: 1224][C:\WINDOWS\system32\svchost.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 1268][C:\Program Files\Rising\Rav\CCenter.exe] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 3)
[PID: 1284][C:\WINDOWS\System32\svchost.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 1384][C:\WINDOWS\System32\S24EvMon.exe] (Intel Corporation )(8, 1, 0, 49a)
[PID: 1968][C:\WINDOWS\System32\svchost.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 2008][C:\WINDOWS\System32\svchost.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 2024][C:\Program Files\Rising\Rav\Ravmond.exe] (Beijing Rising Technology Co., Ltd.)(18, 0, 1, 29)
[C:\Program Files\Rising\Rav\BWList.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 19)
[C:\Program Files\Rising\Rav\RsCommX.dll] (rising)(18, 0, 0, 1)
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 2)
[C:\Program Files\Rising\Rav\CfgDll.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 11)
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[C:\Program Files\Rising\Rav\RsLog.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 20)
[C:\Program Files\Rising\Rav\HOOKSYS.dll] (Rising)(18, 1, 0, 9)
[C:\Program Files\Rising\Rav\Scanner.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 30)
[C:\Program Files\Rising\Rav\libload.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 10)
[C:\Program Files\Rising\Rav\VirusLib.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 10)
[C:\Program Files\Rising\Rav\regmon.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 6)
[C:\Program Files\Rising\Rav\HookWeb.dll] (rising)(18, 0, 0, 2)
[C:\Program Files\Rising\Rav\MemMon.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 9)
[C:\Program Files\Rising\Rav\expscan.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[C:\Program Files\Rising\Rav\mPorts.dll] (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 3)
[C:\Program Files\Rising\Rav\MailMon.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 5)
[C:\Program Files\Rising\Rav\SpamEng.dll] (N/A)(18, 0, 0, 6)
[C:\Program Files\Rising\Rav\engine.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 30)
[C:\Program Files\Rising\Rav\PostTrt.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 9)
[C:\Program Files\Rising\Rav\UnExe.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 11)
[C:\Program Files\Rising\Rav\ScanExec.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 11)
[C:\Program Files\Rising\Rav\ScanEx.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 11)
[C:\Program Files\Rising\Rav\NvFile.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 7)
[C:\Program Files\Rising\Rav\ScanMac.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 8)
[C:\Program Files\Rising\Rav\ScanSct.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 17)
[C:\Program Files\Rising\Rav\Unpacker.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 3)
[C:\Program Files\Rising\Rav\ExtOLE.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 6)
[PID: 236][d:\program files\rising\rfw\rfwsrv.exe] (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 32)
[d:\program files\rising\rfw\RfwRule.dll] (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 13)
[d:\program files\rising\rfw\rfwlog.dll] (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 6)
[d:\program files\rising\rfw\Rfwdrv.dll] (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 21)
[d:\program files\rising\rfw\MonDrv.dll] (rs)(1, 0, 0, 4)
[d:\program files\rising\rfw\ProcLib.dll] (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 9)
[PID: 604][C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe] (Symantec Corporation)(2.2.2.008)
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] (Symantec Corporation)(2.2.2.008)
[C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll] (Symantec Corporation)(2.2.2.008)
[PID: 656][C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe] (Symantec Corporation)(2.2.2.008)
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] (Symantec Corporation)(2.2.2.008)
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCSETEVT.DLL] (Symantec Corporation)(2.2.2.008)
[PID: 688][C:\Program Files\Rising\Rav\RavStub.exe] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 16)
[C:\Program Files\Rising\Rav\RsCommX.dll] (rising)(18, 0, 0, 1)
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[PID: 1908][C:\WINDOWS\Explorer.EXE] (Microsoft Corporation)(6.00.2800.1221 (xpsp2.030511-1403))
[C:\WINDOWS\Downloaded Program Files\swflash.dll] (N/A)(N/A)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll] (Yahoo!)(2, 1, 8, 1048)
[C:\WINDOWS\system32\dla\tfswshx.dll] (Sonic Solutions)(1.04.07a)
[C:\WINDOWS\System32\tfswapi.dll] (Sonic Solutions)(1.04.07a)
[C:\WINDOWS\system32\dla\tfswcres.dll] (Sonic Solutions)(1.04.07a)
[C:\WINDOWS\system32\RavExt.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 21)
[PID: 2040][C:\WINDOWS\System32\ctfmon.exe] (Microsoft Corporation)(5.1.2600.1106 (xpsp1.020828-1920))
[PID: 1784][C:\WINDOWS\system32\spoolsv.exe] (Microsoft Corporation)(5.1.2600.1699 (xpsp2.050610-1533))
[C:\WINDOWS\system32\bthcrp.dll] (WIDCOMM, Inc.)(1.4.2 Build 18)
[C:\WINDOWS\system32\WidcommSdk.dll] (WIDCOMM, Inc.)(1.4.2 Build 18)
[C:\WINDOWS\system32\wbtapi.dll] (WIDCOMM, Inc.)(1.4.2 Build 18)