瑞星卡卡安全论坛
随便说说 - 2007-5-15 18:10:00
我电脑是XP系统的,最近网上下的东西都不能安装,或者出现NSIS ERROE或者安装好了出错不能运行.现在的系统是以前做GHOST还原的,如果用常规的系统盘装到一半会出错,瑞星杀毒到一半会自动重起,郁闷啊!!以下是扫描的日志,帮我看看有问题不,谢谢.
System Information Collect Tool - Designed By Smallfrogs
20070515-17:41
Windows XP Service Pack 2
Internet Explorer: 6.0.2900.2180
*****************************************************************
Runing Processes information
*****************************************************************
=====================================================
PROCESS NAME: System
-----------------------------------------------------
Process ID = 0x00000004
Thread count= 60
Parent process ID = 0
Priority Class = 32
Modules:
------------------------------------
=====================================================
PROCESS NAME: smss.exe
-----------------------------------------------------
Process ID = 0x000001ec
Thread count= 3
Parent process ID = 4
Priority Class = 32
Modules:
------------------------------------
\SystemRoot\System32\smss.exe (0x48580000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
=====================================================
PROCESS NAME: csrss.exe
-----------------------------------------------------
WARNING: OpenProcess failed with error 5 ()
Process ID = 0x00000244
Thread count= 10
Parent process ID = 492
Modules:
------------------------------------
=====================================================
PROCESS NAME: winlogon.exe
-----------------------------------------------------
Process ID = 0x0000025c
Thread count= 18
Parent process ID = 492
Priority Class = 128
Modules:
------------------------------------
\??\C:\WINDOWS\system32\winlogon.exe (0x01000000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\AUTHZ.dll (0x77FE0000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\CRYPT32.dll (0x765E0000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\MSASN1.dll (0x76DB0000)
C:\WINDOWS\system32\NDdeApi.dll (0x758A0000)
C:\WINDOWS\system32\PROFMAP.dll (0x75890000)
C:\WINDOWS\system32\NETAPI32.dll (0x5FDD0000)
C:\WINDOWS\system32\USERENV.dll (0x759D0000)
C:\WINDOWS\system32\PSAPI.DLL (0x76BC0000)
C:\WINDOWS\system32\REGAPI.dll (0x76B90000)
C:\WINDOWS\system32\Secur32.dll (0x77FC0000)
C:\WINDOWS\system32\SETUPAPI.dll (0x76060000)
C:\WINDOWS\system32\VERSION.dll (0x77BD0000)
C:\WINDOWS\system32\WINSTA.dll (0x762D0000)
C:\WINDOWS\system32\WINTRUST.dll (0x76C00000)
C:\WINDOWS\system32\IMAGEHLP.dll (0x76C60000)
C:\WINDOWS\system32\WS2_32.dll (0x71A20000)
C:\WINDOWS\system32\WS2HELP.dll (0x71A10000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\system32\MSGINA.dll (0x758D0000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\COMCTL32.dll (0x5D170000)
C:\WINDOWS\system32\ODBC32.dll (0x73540000)
C:\WINDOWS\system32\comdlg32.dll (0x76320000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\WINDOWS\system32\odbcint.dll (0x20000000)
C:\WINDOWS\system32\SHSVCS.dll (0x76E10000)
C:\WINDOWS\system32\sfc.dll (0x76B80000)
C:\WINDOWS\system32\sfc_os.dll (0x76C30000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\WINDOWS\system32\Apphelp.dll (0x76D70000)
C:\WINDOWS\system32\msctfime.ime (0x73640000)
C:\WINDOWS\system32\WINSCARD.DLL (0x72360000)
C:\WINDOWS\system32\WTSAPI32.dll (0x76F20000)
C:\WINDOWS\system32\sxs.dll (0x75E00000)
C:\WINDOWS\system32\WINMM.dll (0x76B10000)
C:\WINDOWS\system32\uxtheme.dll (0x5ADC0000)
C:\WINDOWS\system32\cscdll.dll (0x76570000)
C:\WINDOWS\system32\WlNotify.dll (0x758B0000)
C:\WINDOWS\system32\WINSPOOL.DRV (0x72F70000)
C:\WINDOWS\system32\MPR.dll (0x71A90000)
C:\WINDOWS\system32\rsaenh.dll (0x0FFD0000)
C:\WINDOWS\system32\SAMLIB.dll (0x71B70000)
C:\WINDOWS\system32\cscui.dll (0x76590000)
C:\WINDOWS\system32\xpsp2res.dll (0x015D0000)
C:\WINDOWS\system32\NTMARTA.DLL (0x76CB0000)
C:\WINDOWS\system32\WLDAP32.dll (0x76F30000)
C:\WINDOWS\system32\msv1_0.dll (0x77C40000)
C:\WINDOWS\system32\iphlpapi.dll (0x76D30000)
C:\WINDOWS\system32\wdmaud.drv (0x72C90000)
C:\WINDOWS\system32\msacm32.drv (0x72C80000)
C:\WINDOWS\system32\MSACM32.dll (0x77BB0000)
C:\WINDOWS\system32\midimap.dll (0x77BA0000)
C:\WINDOWS\system32\COMRes.dll (0x77020000)
C:\WINDOWS\system32\OLEAUT32.dll (0x770F0000)
C:\WINDOWS\system32\CLBCATQ.DLL (0x76FA0000)
随便说说 - 2007-5-15 18:11:00
=====================================================
PROCESS NAME: services.exe
-----------------------------------------------------
Process ID = 0x0000028c
Thread count= 16
Parent process ID = 604
Priority Class = 32
Modules:
------------------------------------
C:\WINDOWS\system32\services.exe (0x01000000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\USERENV.dll (0x759D0000)
C:\WINDOWS\system32\SCESRV.dll (0x75840000)
C:\WINDOWS\system32\AUTHZ.dll (0x77FE0000)
C:\WINDOWS\system32\umpnpmgr.dll (0x7E1E0000)
C:\WINDOWS\system32\WINSTA.dll (0x762D0000)
C:\WINDOWS\system32\NETAPI32.dll (0x5FDD0000)
C:\WINDOWS\system32\NCObjAPI.DLL (0x5F9A0000)
C:\WINDOWS\system32\MSVCP60.dll (0x75FF0000)
C:\WINDOWS\system32\ShimEng.dll (0x5CC30000)
C:\WINDOWS\AppPatch\AcGenral.DLL (0x58FB0000)
C:\WINDOWS\system32\WINMM.dll (0x76B10000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\WINDOWS\system32\OLEAUT32.dll (0x770F0000)
C:\WINDOWS\system32\MSACM32.dll (0x77BB0000)
C:\WINDOWS\system32\VERSION.dll (0x77BD0000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\UxTheme.dll (0x5ADC0000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\WINDOWS\system32\comctl32.dll (0x5D170000)
C:\WINDOWS\system32\secur32.dll (0x77FC0000)
C:\WINDOWS\system32\Apphelp.dll (0x76D70000)
C:\WINDOWS\system32\eventlog.dll (0x76CE0000)
C:\WINDOWS\system32\WS2_32.dll (0x71A20000)
C:\WINDOWS\system32\WS2HELP.dll (0x71A10000)
C:\WINDOWS\system32\PSAPI.DLL (0x76BC0000)
C:\WINDOWS\system32\wtsapi32.dll (0x76F20000)
=====================================================
PROCESS NAME: lsass.exe
-----------------------------------------------------
Process ID = 0x00000298
Thread count= 18
Parent process ID = 604
Priority Class = 32
Modules:
------------------------------------
C:\WINDOWS\system32\lsass.exe (0x01000000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\LSASRV.dll (0x74480000)
C:\WINDOWS\system32\MPR.dll (0x71A90000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\MSASN1.dll (0x76DB0000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\NETAPI32.dll (0x5FDD0000)
C:\WINDOWS\system32\NTDSAPI.dll (0x76770000)
C:\WINDOWS\system32\DNSAPI.dll (0x76EF0000)
C:\WINDOWS\system32\WS2_32.dll (0x71A20000)
C:\WINDOWS\system32\WS2HELP.dll (0x71A10000)
C:\WINDOWS\system32\WLDAP32.dll (0x76F30000)
C:\WINDOWS\system32\Secur32.dll (0x77FC0000)
C:\WINDOWS\system32\SAMLIB.dll (0x71B70000)
C:\WINDOWS\system32\SAMSRV.dll (0x743A0000)
C:\WINDOWS\system32\cryptdll.dll (0x76760000)
C:\WINDOWS\system32\ShimEng.dll (0x5CC30000)
C:\WINDOWS\AppPatch\AcGenral.DLL (0x58FB0000)
C:\WINDOWS\system32\WINMM.dll (0x76B10000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\WINDOWS\system32\OLEAUT32.dll (0x770F0000)
C:\WINDOWS\system32\MSACM32.dll (0x77BB0000)
C:\WINDOWS\system32\VERSION.dll (0x77BD0000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\USERENV.dll (0x759D0000)
C:\WINDOWS\system32\UxTheme.dll (0x5ADC0000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\WINDOWS\system32\comctl32.dll (0x5D170000)
C:\WINDOWS\system32\msprivs.dll (0x20000000)
C:\WINDOWS\system32\kerberos.dll (0x71C70000)
C:\WINDOWS\system32\msv1_0.dll (0x77C40000)
C:\WINDOWS\system32\iphlpapi.dll (0x76D30000)
C:\WINDOWS\system32\netlogon.dll (0x74410000)
C:\WINDOWS\system32\w32time.dll (0x76790000)
C:\WINDOWS\system32\MSVCP60.dll (0x75FF0000)
C:\WINDOWS\system32\schannel.dll (0x767C0000)
C:\WINDOWS\system32\CRYPT32.dll (0x765E0000)
C:\WINDOWS\system32\wdigest.dll (0x742E0000)
C:\WINDOWS\system32\rsaenh.dll (0x0FFD0000)
C:\WINDOWS\system32\scecli.dll (0x74370000)
C:\WINDOWS\system32\SETUPAPI.dll (0x76060000)
C:\WINDOWS\system32\ipsecsvc.dll (0x74340000)
C:\WINDOWS\system32\AUTHZ.dll (0x77FE0000)
C:\WINDOWS\system32\oakley.DLL (0x73ED0000)
C:\WINDOWS\system32\WINIPSEC.DLL (0x742D0000)
C:\WINDOWS\system32\pstorsvc.dll (0x74300000)
C:\WINDOWS\system32\mswsock.dll (0x719C0000)
C:\WINDOWS\system32\psbase.dll (0x74320000)
C:\WINDOWS\system32\hnetcfg.dll (0x60FD0000)
C:\WINDOWS\System32\wshtcpip.dll (0x71A00000)
C:\WINDOWS\system32\dssenh.dll (0x68100000)
=====================================================
PROCESS NAME: svchost.exe
-----------------------------------------------------
Process ID = 0x00000338
Thread count= 16
Parent process ID = 652
Priority Class = 32
Modules:
------------------------------------
C:\WINDOWS\system32\svchost.exe (0x01000000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\ShimEng.dll (0x5CC30000)
C:\WINDOWS\AppPatch\AcGenral.DLL (0x58FB0000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\WINMM.dll (0x76B10000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\OLEAUT32.dll (0x770F0000)
C:\WINDOWS\system32\MSACM32.dll (0x77BB0000)
C:\WINDOWS\system32\VERSION.dll (0x77BD0000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\USERENV.dll (0x759D0000)
C:\WINDOWS\system32\UxTheme.dll (0x5ADC0000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\WINDOWS\system32\comctl32.dll (0x5D170000)
C:\WINDOWS\system32\NTMARTA.DLL (0x76CB0000)
C:\WINDOWS\system32\WLDAP32.dll (0x76F30000)
C:\WINDOWS\system32\SAMLIB.dll (0x71B70000)
c:\windows\system32\rpcss.dll (0x76230000)
c:\windows\system32\Secur32.dll (0x77FC0000)
c:\windows\system32\WS2_32.dll (0x71A20000)
c:\windows\system32\WS2HELP.dll (0x71A10000)
C:\WINDOWS\system32\xpsp2res.dll (0x20000000)
C:\WINDOWS\system32\CLBCATQ.DLL (0x76FA0000)
C:\WINDOWS\system32\COMRes.dll (0x77020000)
c:\windows\system32\termsrv.dll (0x761C0000)
c:\windows\system32\ICAAPI.dll (0x74ED0000)
c:\windows\system32\SETUPAPI.dll (0x76060000)
C:\WINDOWS\system32\WINTRUST.dll (0x76C00000)
C:\WINDOWS\system32\CRYPT32.dll (0x765E0000)
C:\WINDOWS\system32\MSASN1.dll (0x76DB0000)
C:\WINDOWS\system32\IMAGEHLP.dll (0x76C60000)
c:\windows\system32\AUTHZ.dll (0x77FE0000)
c:\windows\system32\mstlsapi.dll (0x75070000)
c:\windows\system32\ACTIVEDS.dll (0x77C90000)
c:\windows\system32\adsldpc.dll (0x76DE0000)
C:\WINDOWS\system32\NETAPI32.dll (0x5FDD0000)
c:\windows\system32\ATL.DLL (0x76AF0000)
C:\WINDOWS\system32\REGAPI.dll (0x76B90000)
C:\WINDOWS\system32\rsaenh.dll (0x0FFD0000)
随便说说 - 2007-5-15 18:12:00
=====================================================
PROCESS NAME: svchost.exe
-----------------------------------------------------
WARNING: OpenProcess failed with error 5 ()
Process ID = 0x00000374
Thread count= 10
Parent process ID = 652
Modules:
------------------------------------
=====================================================
PROCESS NAME: CCenter.exe
-----------------------------------------------------
Process ID = 0x000003c4
Thread count= 3
Parent process ID = 652
Priority Class = 32
Modules:
------------------------------------
C:\Program Files\Rising\Rav\CCenter.exe (0x00400000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\uxtheme.dll (0x5ADC0000)
=====================================================
PROCESS NAME: svchost.exe
-----------------------------------------------------
Process ID = 0x000003d8
Thread count= 59
Parent process ID = 652
Priority Class = 32
Modules:
------------------------------------
C:\WINDOWS\System32\svchost.exe (0x01000000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\System32\ShimEng.dll (0x5CC30000)
C:\WINDOWS\AppPatch\AcGenral.DLL (0x58FB0000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\System32\WINMM.dll (0x76B10000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\OLEAUT32.dll (0x770F0000)
C:\WINDOWS\System32\MSACM32.dll (0x77BB0000)
C:\WINDOWS\system32\VERSION.dll (0x77BD0000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\USERENV.dll (0x759D0000)
C:\WINDOWS\System32\UxTheme.dll (0x5ADC0000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\System32\LPK.DLL (0x62C20000)
C:\WINDOWS\System32\USP10.dll (0x73FA0000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\WINDOWS\system32\comctl32.dll (0x5D170000)
C:\WINDOWS\System32\NTMARTA.DLL (0x76CB0000)
C:\WINDOWS\system32\WLDAP32.dll (0x76F30000)
C:\WINDOWS\System32\SAMLIB.dll (0x71B70000)
C:\WINDOWS\System32\xpsp2res.dll (0x20000000)
c:\windows\system32\shsvcs.dll (0x76E10000)
C:\WINDOWS\System32\WINSTA.dll (0x762D0000)
C:\WINDOWS\system32\NETAPI32.dll (0x5FDD0000)
c:\windows\system32\dhcpcsvc.dll (0x76D50000)
c:\windows\system32\DNSAPI.dll (0x76EF0000)
c:\windows\system32\WS2_32.dll (0x71A20000)
c:\windows\system32\WS2HELP.dll (0x71A10000)
c:\windows\system32\iphlpapi.dll (0x76D30000)
c:\windows\system32\Secur32.dll (0x77FC0000)
C:\WINDOWS\System32\rsaenh.dll (0x0FFD0000)
c:\windows\system32\wzcsvc.dll (0x77290000)
c:\windows\system32\rtutils.dll (0x76E50000)
c:\windows\system32\WMI.dll (0x76D00000)
C:\WINDOWS\system32\CRYPT32.dll (0x765E0000)
C:\WINDOWS\system32\MSASN1.dll (0x76DB0000)
c:\windows\system32\WTSAPI32.dll (0x76F20000)
c:\windows\system32\ESENT.dll (0x5DF20000)
c:\windows\system32\ATL.DLL (0x76AF0000)
C:\WINDOWS\System32\rastls.dll (0x75DB0000)
C:\WINDOWS\system32\CRYPTUI.dll (0x75430000)
C:\WINDOWS\system32\WINTRUST.dll (0x76C00000)
C:\WINDOWS\system32\IMAGEHLP.dll (0x76C60000)
C:\WINDOWS\system32\WININET.dll (0x76680000)
C:\WINDOWS\System32\MPRAPI.dll (0x76D10000)
C:\WINDOWS\System32\ACTIVEDS.dll (0x77C90000)
C:\WINDOWS\System32\adsldpc.dll (0x76DE0000)
C:\WINDOWS\System32\SETUPAPI.dll (0x76060000)
C:\WINDOWS\System32\RASAPI32.dll (0x76EB0000)
C:\WINDOWS\System32\rasman.dll (0x76E60000)
C:\WINDOWS\System32\TAPI32.dll (0x76E80000)
C:\WINDOWS\System32\SCHANNEL.dll (0x767C0000)
C:\WINDOWS\System32\WinSCard.dll (0x72360000)
C:\WINDOWS\System32\raschap.dll (0x75D90000)
C:\WINDOWS\system32\msv1_0.dll (0x77C40000)
C:\WINDOWS\System32\CLBCATQ.DLL (0x76FA0000)
C:\WINDOWS\System32\COMRes.dll (0x77020000)
c:\windows\system32\schedsvc.dll (0x76B40000)
c:\windows\system32\NTDSAPI.dll (0x76770000)
C:\WINDOWS\System32\MSIDLE.DLL (0x74EB0000)
c:\windows\system32\audiosrv.dll (0x70DE0000)
c:\windows\system32\wkssvc.dll (0x76850000)
c:\windows\system32\qmgr.dll (0x69AB0000)
C:\WINDOWS\system32\MPR.dll (0x71A90000)
c:\windows\system32\SHFOLDER.dll (0x76750000)
c:\windows\system32\WINHTTP.dll (0x4A410000)
c:\windows\system32\wuauserv.dll (0x50000000)
c:\windows\system32\wbem\wmisvc.dll (0x67180000)
C:\WINDOWS\system32\VSSAPI.DLL (0x75340000)
C:\WINDOWS\system32\wuaueng.dll (0x50040000)
C:\WINDOWS\System32\ADVPACK.dll (0x751C0000)
C:\WINDOWS\System32\WINSPOOL.DRV (0x72F70000)
C:\WINDOWS\System32\Cabinet.dll (0x750B0000)
C:\WINDOWS\System32\mspatcha.dll (0x602D0000)
C:\WINDOWS\System32\sfc.dll (0x76B80000)
C:\WINDOWS\System32\sfc_os.dll (0x76C30000)
c:\windows\system32\w32time.dll (0x76790000)
c:\windows\system32\MSVCP60.dll (0x75FF0000)
c:\windows\system32\trkwks.dll (0x74FD0000)
C:\WINDOWS\system32\es.dll (0x768A0000)
C:\WINDOWS\system32\mswsock.dll (0x719C0000)
C:\WINDOWS\System32\hnetcfg.dll (0x60FD0000)
C:\WINDOWS\System32\wshtcpip.dll (0x71A00000)
c:\windows\system32\srsvc.dll (0x75100000)
c:\windows\system32\POWRPROF.dll (0x74A30000)
c:\windows\system32\seclogon.dll (0x73C90000)
c:\windows\system32\netman.dll (0x77CD0000)
c:\windows\system32\netshell.dll (0x74770000)
c:\windows\system32\credui.dll (0x76BD0000)
c:\windows\system32\WZCSAPI.DLL (0x72FA0000)
c:\windows\system32\srvsvc.dll (0x74FF0000)
c:\windows\pchealth\helpctr\binaries\pchsvc.dll (0x74EA0000)
c:\windows\system32\ersvc.dll (0x74EE0000)
c:\windows\system32\dmserver.dll (0x74EF0000)
C:\WINDOWS\System32\winrnr.dll (0x76F80000)
c:\windows\system32\cryptsvc.dll (0x75EB0000)
c:\windows\system32\certcli.dll (0x752B0000)
c:\windows\system32\wscsvc.dll (0x4C1A0000)
c:\windows\system32\msi.dll (0x01F60000)
c:\windows\system32\ipnathlp.dll (0x66700000)
c:\windows\system32\AUTHZ.dll (0x77FE0000)
c:\windows\system32\sens.dll (0x72260000)
C:\WINDOWS\system32\wbem\wbemcomn.dll (0x751F0000)
C:\WINDOWS\System32\Wbem\wbemcore.dll (0x75D00000)
C:\WINDOWS\System32\Wbem\esscli.dll (0x75270000)
C:\WINDOWS\System32\Wbem\FastProx.dll (0x755F0000)
C:\WINDOWS\System32\SXS.DLL (0x75E00000)
C:\WINDOWS\system32\wbem\wmiutils.dll (0x74F80000)
C:\WINDOWS\system32\wbem\repdrvfs.dll (0x75160000)
C:\WINDOWS\system32\wbem\wmiprvsd.dll (0x594C0000)
C:\WINDOWS\system32\NCObjAPI.DLL (0x5F9A0000)
C:\WINDOWS\system32\wbem\wbemess.dll (0x752F0000)
C:\WINDOWS\system32\wbem\ncprov.dll (0x5F970000)
c:\windows\system32\browser.dll (0x76BA0000)
C:\WINDOWS\system32\upnp.dll (0x76540000)
C:\WINDOWS\system32\SSDPAPI.dll (0x74E60000)
C:\WINDOWS\system32\comsvcs.dll (0x75690000)
C:\WINDOWS\system32\colbact.DLL (0x75090000)
C:\WINDOWS\system32\MTXCLU.DLL (0x75050000)
C:\WINDOWS\system32\WSOCK32.dll (0x71A40000)
C:\WINDOWS\System32\CLUSAPI.DLL (0x762A0000)
C:\WINDOWS\System32\RESUTILS.DLL (0x75010000)
C:\WINDOWS\System32\rasadhlp.dll (0x76F90000)
C:\WINDOWS\System32\RASDLG.dll (0x754B0000)
C:\WINDOWS\system32\Apphelp.dll (0x76D70000)
C:\WINDOWS\system32\wups.dll (0x50640000)
随便说说 - 2007-5-15 18:13:00
=====================================================
PROCESS NAME: svchost.exe
-----------------------------------------------------
WARNING: OpenProcess failed with error 5 ()
Process ID = 0x0000041c
Thread count= 6
Parent process ID = 652
Modules:
------------------------------------
=====================================================
PROCESS NAME: svchost.exe
-----------------------------------------------------
WARNING: OpenProcess failed with error 5 ()
Process ID = 0x0000047c
Thread count= 14
Parent process ID = 652
Modules:
------------------------------------
=====================================================
PROCESS NAME: RavMonD.exe
-----------------------------------------------------
Process ID = 0x000004a8
Thread count= 25
Parent process ID = 652
Priority Class = 32
Modules:
------------------------------------
C:\Program Files\Rising\Rav\Ravmond.exe (0x00400000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\Program Files\Rising\Rav\BWList.dll (0x10000000)
C:\WINDOWS\system32\MFC42.DLL (0x73D30000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\MSVCP60.dll (0x75FF0000)
C:\WINDOWS\system32\WSOCK32.dll (0x71A40000)
C:\WINDOWS\system32\WS2_32.dll (0x71A20000)
C:\WINDOWS\system32\WS2HELP.dll (0x71A10000)
C:\WINDOWS\system32\OLEAUT32.dll (0x770F0000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\WINDOWS\system32\VERSION.dll (0x77BD0000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\system32\MFC42LOC.DLL (0x61BE0000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\WINDOWS\system32\comctl32.dll (0x5D170000)
C:\Program Files\Rising\Rav\RsCommX.dll (0x00740000)
C:\Program Files\Rising\Rav\rfwctrl.dll (0x00B70000)
C:\WINDOWS\system32\USERENV.dll (0x759D0000)
C:\Program Files\Rising\Rav\RsPPsys.dll (0x00B80000)
C:\Program Files\Rising\Rav\RSAPPMGR.DLL (0x00DB0000)
C:\Program Files\Rising\Rav\CfgDll.dll (0x08DD0000)
C:\Program Files\Rising\Rav\RSCOMMON.DLL (0x23700000)
C:\Program Files\Rising\Rav\RsLog.dll (0x09070000)
C:\Program Files\Rising\Rav\HOOKSYS.dll (0x09080000)
C:\Program Files\Rising\Rav\Scanner.dll (0x091B0000)
C:\Program Files\Rising\Rav\libload.dll (0x13100000)
C:\Program Files\Rising\Rav\VirusLib.dll (0x09310000)
C:\Program Files\Rising\Rav\regmon.dll (0x09450000)
C:\Program Files\Rising\Rav\psapi.dll (0x731B0000)
C:\WINDOWS\system32\IMAGEHLP.dll (0x76C60000)
C:\Program Files\Rising\Rav\HookWeb.dll (0x096A0000)
C:\Program Files\Rising\Rav\MemMon.dll (0x097C0000)
C:\Program Files\Rising\Rav\expscan.dll (0x097F0000)
C:\Program Files\Rising\Rav\mPorts.dll (0x09810000)
C:\WINDOWS\system32\iphlpapi.dll (0x76D30000)
C:\Program Files\Rising\Rav\HookCont.dll (0x09A20000)
C:\Program Files\Rising\Rav\SpamEng.dll (0x09A40000)
C:\Program Files\Rising\Rav\engine.dll (0x09AE0000)
C:\WINDOWS\system32\mswsock.dll (0x719C0000)
C:\WINDOWS\system32\hnetcfg.dll (0x60FD0000)
C:\WINDOWS\System32\wshtcpip.dll (0x71A00000)
C:\WINDOWS\system32\uxtheme.dll (0x5ADC0000)
C:\Program Files\Rising\Rav\PostTrt.dll (0x0A470000)
C:\Program Files\Rising\Rav\UnExe.dll (0x0A7B0000)
C:\Program Files\Rising\Rav\ScanExec.dll (0x13AB0000)
C:\Program Files\Rising\Rav\ScanEx.dll (0x0A6D0000)
C:\Program Files\Rising\Rav\ExtFile.dll (0x0ACE0000)
C:\Program Files\Rising\Rav\NvFile.dll (0x0A770000)
C:\Program Files\Rising\Rav\ScanMac.dll (0x13AF0000)
C:\Program Files\Rising\Rav\ScanSct.dll (0x0AD90000)
C:\WINDOWS\system32\CLBCATQ.DLL (0x76FA0000)
C:\WINDOWS\system32\COMRes.dll (0x77020000)
C:\WINDOWS\system32\xpsp2res.dll (0x20000000)
C:\WINDOWS\system32\perfproc.dll (0x5E8E0000)
C:\Program Files\Rising\Rav\Unpacker.dll (0x0E450000)
C:\Program Files\Rising\Rav\ScanPack.dll (0x0E4B0000)
C:\Program Files\Rising\Rav\RsVM.dll (0x0E730000)
C:\Program Files\Rising\Rav\Uroutine.dll (0x0E9F0000)
随便说说 - 2007-5-15 18:13:00
=====================================================
PROCESS NAME: Explorer.EXE
-----------------------------------------------------
Process ID = 0x00000534
Thread count= 16
Parent process ID = 1316
Priority Class = 32
Modules:
------------------------------------
C:\WINDOWS\Explorer.EXE (0x01000000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\WINDOWS\system32\OLEAUT32.dll (0x770F0000)
C:\WINDOWS\system32\BROWSEUI.dll (0x75EF0000)
C:\WINDOWS\system32\SHDOCVW.dll (0x7E550000)
C:\WINDOWS\system32\CRYPT32.dll (0x765E0000)
C:\WINDOWS\system32\MSASN1.dll (0x76DB0000)
C:\WINDOWS\system32\CRYPTUI.dll (0x75430000)
C:\WINDOWS\system32\WINTRUST.dll (0x76C00000)
C:\WINDOWS\system32\IMAGEHLP.dll (0x76C60000)
C:\WINDOWS\system32\NETAPI32.dll (0x5FDD0000)
C:\WINDOWS\system32\WININET.dll (0x76680000)
C:\WINDOWS\system32\WLDAP32.dll (0x76F30000)
C:\WINDOWS\system32\VERSION.dll (0x77BD0000)
C:\WINDOWS\system32\UxTheme.dll (0x5ADC0000)
C:\WINDOWS\system32\ShimEng.dll (0x5CC30000)
C:\WINDOWS\AppPatch\AcGenral.DLL (0x58FB0000)
C:\WINDOWS\system32\WINMM.dll (0x76B10000)
C:\WINDOWS\system32\MSACM32.dll (0x77BB0000)
C:\WINDOWS\system32\USERENV.dll (0x759D0000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\WINDOWS\system32\comctl32.dll (0x5D170000)
C:\WINDOWS\system32\msctfime.ime (0x73640000)
C:\WINDOWS\system32\appHelp.dll (0x76D70000)
C:\WINDOWS\system32\CLBCATQ.DLL (0x76FA0000)
C:\WINDOWS\system32\COMRes.dll (0x77020000)
C:\WINDOWS\System32\cscui.dll (0x76590000)
C:\WINDOWS\System32\CSCDLL.dll (0x76570000)
C:\WINDOWS\system32\themeui.dll (0x5B680000)
C:\WINDOWS\system32\Secur32.dll (0x77FC0000)
C:\WINDOWS\system32\MSIMG32.dll (0x762F0000)
C:\WINDOWS\system32\xpsp2res.dll (0x20000000)
C:\WINDOWS\system32\Actxprxy.dll (0x71CC0000)
C:\WINDOWS\system32\msutb.dll (0x5FE40000)
C:\WINDOWS\system32\MSCTF.dll (0x74680000)
C:\WINDOWS\system32\urlmon.dll (0x75C60000)
C:\WINDOWS\system32\LINKINFO.dll (0x76950000)
C:\WINDOWS\system32\ntshrui.dll (0x76960000)
C:\WINDOWS\system32\ATL.DLL (0x76AF0000)
C:\Program Files\Rising\AntiSpyware\ieprot.dll (0x10000000)
C:\WINDOWS\system32\msi.dll (0x01680000)
C:\WINDOWS\system32\WINSTA.dll (0x762D0000)
C:\WINDOWS\system32\webcheck.dll (0x74A90000)
C:\WINDOWS\system32\WSOCK32.dll (0x71A40000)
C:\WINDOWS\system32\WS2_32.dll (0x71A20000)
C:\WINDOWS\system32\WS2HELP.dll (0x71A10000)
C:\Program Files\360safe\safemon\safemon.dll (0x01600000)
C:\WINDOWS\system32\stobject.dll (0x74A60000)
C:\WINDOWS\system32\BatMeter.dll (0x74A50000)
C:\WINDOWS\system32\POWRPROF.dll (0x74A30000)
C:\WINDOWS\system32\SETUPAPI.dll (0x76060000)
C:\WINDOWS\system32\WTSAPI32.dll (0x76F20000)
C:\WINDOWS\system32\wdmaud.drv (0x72C90000)
C:\WINDOWS\system32\msacm32.drv (0x72C80000)
C:\WINDOWS\system32\midimap.dll (0x77BA0000)
C:\WINDOWS\system32\NETSHELL.dll (0x74770000)
C:\WINDOWS\system32\rtutils.dll (0x76E50000)
C:\WINDOWS\system32\credui.dll (0x76BD0000)
C:\WINDOWS\system32\iphlpapi.dll (0x76D30000)
C:\Program Files\WinRAR\rarext.dll (0x01990000)
C:\WINDOWS\system32\RavExt.dll (0x01B00000)
C:\Program Files\Rising\Rav\RSCOMMON.DLL (0x23700000)
C:\WINDOWS\system32\rsaenh.dll (0x0FFD0000)
C:\WINDOWS\system32\SXS.DLL (0x75E00000)
C:\WINDOWS\system32\shdoclc.dll (0x025D0000)
C:\WINDOWS\system32\MPR.dll (0x71A90000)
C:\WINDOWS\System32\drprov.dll (0x75ED0000)
C:\WINDOWS\System32\ntlanman.dll (0x71B90000)
C:\WINDOWS\System32\NETUI0.dll (0x71C50000)
C:\WINDOWS\System32\NETUI1.dll (0x71C10000)
C:\WINDOWS\System32\NETRAP.dll (0x71C00000)
C:\WINDOWS\System32\SAMLIB.dll (0x71B70000)
C:\WINDOWS\System32\davclnt.dll (0x75EE0000)
C:\WINDOWS\system32\browselc.dll (0x01560000)
C:\WINDOWS\system32\DUSER.dll (0x6C520000)
随便说说 - 2007-5-15 18:14:00
=====================================================
PROCESS NAME: spoolsv.exe
-----------------------------------------------------
Process ID = 0x000005bc
Thread count= 11
Parent process ID = 652
Priority Class = 32
Modules:
------------------------------------
C:\WINDOWS\system32\spoolsv.exe (0x01000000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\ShimEng.dll (0x5CC30000)
C:\WINDOWS\AppPatch\AcGenral.DLL (0x58FB0000)
C:\WINDOWS\system32\WINMM.dll (0x76B10000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\WINDOWS\system32\OLEAUT32.dll (0x770F0000)
C:\WINDOWS\system32\MSACM32.dll (0x77BB0000)
C:\WINDOWS\system32\VERSION.dll (0x77BD0000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\USERENV.dll (0x759D0000)
C:\WINDOWS\system32\UxTheme.dll (0x5ADC0000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\WINDOWS\system32\comctl32.dll (0x5D170000)
C:\WINDOWS\system32\SPOOLSS.DLL (0x74240000)
C:\WINDOWS\system32\WS2_32.dll (0x71A20000)
C:\WINDOWS\system32\WS2HELP.dll (0x71A10000)
C:\WINDOWS\system32\DNSAPI.dll (0x76EF0000)
C:\WINDOWS\system32\rasadhlp.dll (0x76F90000)
C:\WINDOWS\system32\localspl.dll (0x74C10000)
C:\WINDOWS\system32\Secur32.dll (0x77FC0000)
C:\WINDOWS\system32\sfc_os.dll (0x76C30000)
C:\WINDOWS\system32\WINTRUST.dll (0x76C00000)
C:\WINDOWS\system32\CRYPT32.dll (0x765E0000)
C:\WINDOWS\system32\MSASN1.dll (0x76DB0000)
C:\WINDOWS\system32\IMAGEHLP.dll (0x76C60000)
C:\WINDOWS\system32\winspool.drv (0x72F70000)
C:\WINDOWS\system32\netapi32.dll (0x5FDD0000)
C:\WINDOWS\system32\cnbjmon.dll (0x74200000)
C:\WINDOWS\system32\hpdcmon.dll (0x10000000)
C:\WINDOWS\system32\pjlmon.dll (0x741E0000)
C:\WINDOWS\system32\tcpmon.dll (0x72390000)
C:\WINDOWS\system32\usbmon.dll (0x72380000)
C:\WINDOWS\System32\mswsock.dll (0x719C0000)
C:\WINDOWS\System32\winrnr.dll (0x76F80000)
C:\WINDOWS\system32\WLDAP32.dll (0x76F30000)
C:\WINDOWS\system32\win32spl.dll (0x75AC0000)
C:\WINDOWS\system32\NETRAP.dll (0x71C00000)
C:\WINDOWS\system32\NTDSAPI.dll (0x76770000)
C:\WINDOWS\system32\CLBCATQ.DLL (0x76FA0000)
C:\WINDOWS\system32\COMRes.dll (0x77020000)
C:\WINDOWS\system32\inetpp.dll (0x74260000)
C:\WINDOWS\system32\xpsp2res.dll (0x20000000)
=====================================================
PROCESS NAME: KBD.EXE
-----------------------------------------------------
Process ID = 0x00000644
Thread count= 14
Parent process ID = 1332
Priority Class = 128
Modules:
------------------------------------
C:\HP\KBD\KBD.EXE (0x63000000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\WINDOWS\system32\comctl32.dll (0x5D170000)
C:\WINDOWS\system32\uxtheme.dll (0x5ADC0000)
C:\WINDOWS\system32\msctfime.ime (0x73640000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\HP\KBD\led.dll (0x63080000)
C:\HP\KBD\USB.dll (0x63190000)
C:\WINDOWS\system32\CFGMGR32.dll (0x74A40000)
C:\WINDOWS\system32\setupapi.dll (0x76060000)
C:\WINDOWS\system32\HID.DLL (0x68BE0000)
C:\HP\KBD\ps2.dll (0x63130000)
C:\HP\KBD\msg.dll (0x630A0000)
C:\HP\KBD\osd.dll (0x63110000)
C:\WINDOWS\system32\WINMM.dll (0x76B10000)
C:\HP\KBD\sct.dll (0x63150000)
C:\WINDOWS\system32\OLEAUT32.dll (0x770F0000)
C:\HP\KBD\onl.dll (0x630E0000)
C:\HP\KBD\aol.dll (0x63020000)
C:\WINDOWS\system32\WININET.dll (0x76680000)
C:\WINDOWS\system32\CRYPT32.dll (0x765E0000)
C:\WINDOWS\system32\MSASN1.dll (0x76DB0000)
C:\HP\KBD\url.dll (0x63170000)
C:\HP\KBD\cfg.dll (0x63040000)
C:\WINDOWS\system32\sensapi.dll (0x72240000)
C:\WINDOWS\system32\WINTRUST.dll (0x76C00000)
C:\WINDOWS\system32\IMAGEHLP.dll (0x76C60000)
C:\WINDOWS\system32\CLBCATQ.DLL (0x76FA0000)
C:\WINDOWS\system32\COMRes.dll (0x77020000)
C:\WINDOWS\system32\VERSION.dll (0x77BD0000)
C:\HP\KBD\MSIKBDIF.DLL (0x630C0000)
C:\WINDOWS\system32\MSVCIRT.dll (0x01580000)
C:\Program Files\Rising\AntiSpyware\ieprot.dll (0x10000000)
C:\WINDOWS\system32\MSCTF.dll (0x74680000)
随便说说 - 2007-5-15 18:14:00
=====================================================
PROCESS NAME: SoundMan.exe
-----------------------------------------------------
Process ID = 0x0000064c
Thread count= 3
Parent process ID = 1332
Priority Class = 32
Modules:
------------------------------------
C:\WINDOWS\SOUNDMAN.EXE (0x00400000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\SETUPAPI.dll (0x76060000)
C:\WINDOWS\system32\WINMM.dll (0x76B10000)
C:\WINDOWS\system32\HID.DLL (0x68BE0000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\WINDOWS\system32\comctl32.dll (0x5D170000)
C:\WINDOWS\system32\uxtheme.dll (0x5ADC0000)
C:\WINDOWS\system32\msctfime.ime (0x73640000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\WINDOWS\system32\WINTRUST.dll (0x76C00000)
C:\WINDOWS\system32\CRYPT32.dll (0x765E0000)
C:\WINDOWS\system32\MSASN1.dll (0x76DB0000)
C:\WINDOWS\system32\IMAGEHLP.dll (0x76C60000)
C:\WINDOWS\system32\MSCTF.dll (0x74680000)
C:\Program Files\Rising\AntiSpyware\ieprot.dll (0x10000000)
=====================================================
PROCESS NAME: RavTask.exe
-----------------------------------------------------
Process ID = 0x00000654
Thread count= 4
Parent process ID = 1332
Priority Class = 64
Modules:
------------------------------------
C:\Program Files\Rising\Rav\RavTask.exe (0x00400000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\COMCTL32.dll (0x5D170000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\Program Files\Rising\Rav\RSCOMMON.DLL (0x23700000)
C:\Program Files\Rising\Rav\RSAPPMGR.DLL (0x10000000)
C:\Program Files\Rising\Rav\CfgDll.dll (0x08A10000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\WINDOWS\system32\OLEAUT32.dll (0x770F0000)
C:\Program Files\Rising\Rav\RsCommX.dll (0x08CA0000)
C:\WINDOWS\system32\uxtheme.dll (0x5ADC0000)
C:\WINDOWS\system32\msctfime.ime (0x73640000)
C:\Program Files\Rising\AntiSpyware\ieprot.dll (0x08E50000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\WINDOWS\system32\MSCTF.dll (0x74680000)
C:\WINDOWS\system32\ODBC32.dll (0x73540000)
C:\WINDOWS\system32\comdlg32.dll (0x76320000)
C:\WINDOWS\system32\odbcint.dll (0x20000000)
C:\WINDOWS\system32\odbccp32.dll (0x4D3D0000)
C:\WINDOWS\system32\VERSION.dll (0x77BD0000)
C:\WINDOWS\system32\Secur32.dll (0x77FC0000)
C:\WINDOWS\system32\CLBCATQ.DLL (0x76FA0000)
C:\WINDOWS\system32\COMRes.dll (0x77020000)
C:\WINDOWS\system32\VBAJET32.DLL (0x0F9A0000)
随便说说 - 2007-5-15 18:14:00
=====================================================
PROCESS NAME: runiep.exe
-----------------------------------------------------
Process ID = 0x0000066c
Thread count= 4
Parent process ID = 1332
Priority Class = 32
Modules:
------------------------------------
C:\Program Files\Rising\AntiSpyware\runiep.exe (0x00400000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\MFC42.DLL (0x73D30000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\system32\MFC42LOC.DLL (0x61BE0000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\WINDOWS\system32\comctl32.dll (0x5D170000)
C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll (0x10000000)
C:\Program Files\Rising\AntiSpyware\ieprot.dll (0x00AA0000)
C:\WINDOWS\system32\uxtheme.dll (0x5ADC0000)
C:\WINDOWS\system32\MSCTF.dll (0x74680000)
C:\WINDOWS\system32\msctfime.ime (0x73640000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
=====================================================
PROCESS NAME: 360Tray.exe
-----------------------------------------------------
Process ID = 0x00000680
Thread count= 3
Parent process ID = 1332
Priority Class = 32
Modules:
------------------------------------
C:\Program Files\360safe\safemon\360Tray.exe (0x00400000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\MFC42.DLL (0x73D30000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\COMCTL32.dll (0x5D170000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\WINDOWS\system32\OLEAUT32.dll (0x770F0000)
C:\WINDOWS\system32\urlmon.dll (0x75C60000)
C:\WINDOWS\system32\VERSION.dll (0x77BD0000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\system32\MFC42LOC.DLL (0x61BE0000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\WINDOWS\system32\uxtheme.dll (0x5ADC0000)
C:\WINDOWS\system32\RICHED32.DLL (0x73250000)
C:\WINDOWS\system32\RICHED20.dll (0x74D90000)
C:\WINDOWS\system32\msctfime.ime (0x73640000)
C:\Program Files\360safe\safemon\safemon.dll (0x10000000)
C:\Program Files\360safe\safemon\SafeKrnl.dll (0x00A20000)
C:\Program Files\360safe\AntiAdwa.dll (0x00AB0000)
C:\WINDOWS\system32\WININET.dll (0x76680000)
C:\WINDOWS\system32\CRYPT32.dll (0x765E0000)
C:\WINDOWS\system32\MSASN1.dll (0x76DB0000)
C:\WINDOWS\system32\WS2_32.dll (0x71A20000)
C:\WINDOWS\system32\WS2HELP.dll (0x71A10000)
C:\WINDOWS\system32\psapi.dll (0x76BC0000)
C:\Program Files\Rising\AntiSpyware\ieprot.dll (0x011C0000)
C:\WINDOWS\system32\MSCTF.dll (0x74680000)
随便说说 - 2007-5-15 18:15:00
=====================================================
PROCESS NAME: ctfmon.exe
-----------------------------------------------------
Process ID = 0x00000698
Thread count= 2
Parent process ID = 1332
Priority Class = 32
Modules:
------------------------------------
C:\WINDOWS\system32\ctfmon.exe (0x00400000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\MSCTF.dll (0x74680000)
C:\WINDOWS\system32\MSUTB.dll (0x5FE40000)
C:\WINDOWS\system32\ShimEng.dll (0x5CC30000)
C:\WINDOWS\AppPatch\AcGenral.DLL (0x58FB0000)
C:\WINDOWS\system32\WINMM.dll (0x76B10000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\WINDOWS\system32\OLEAUT32.dll (0x770F0000)
C:\WINDOWS\system32\MSACM32.dll (0x77BB0000)
C:\WINDOWS\system32\VERSION.dll (0x77BD0000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\USERENV.dll (0x759D0000)
C:\WINDOWS\system32\UxTheme.dll (0x5ADC0000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\Program Files\360safe\safemon\safemon.dll (0x10000000)
C:\WINDOWS\system32\msctfime.ime (0x73640000)
C:\Program Files\Rising\AntiSpyware\ieprot.dll (0x00A60000)
=====================================================
PROCESS NAME: RavMon.exe
-----------------------------------------------------
Process ID = 0x000006e4
Thread count= 8
Parent process ID = 1620
Priority Class = 32
Modules:
------------------------------------
C:\Program Files\Rising\Rav\Ravmon.exe (0x00400000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\Program Files\Rising\Rav\RsGuiLib.dll (0x26600000)
C:\WINDOWS\system32\MFC42.DLL (0x73D30000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\COMCTL32.dll (0x5D170000)
C:\WINDOWS\system32\MSVCP60.dll (0x75FF0000)
C:\Program Files\Rising\Rav\BWList.dll (0x10000000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\WSOCK32.dll (0x71A40000)
C:\WINDOWS\system32\WS2_32.dll (0x71A20000)
C:\WINDOWS\system32\WS2HELP.dll (0x71A10000)
C:\WINDOWS\system32\VERSION.dll (0x77BD0000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\system32\MFC42LOC.DLL (0x61BE0000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\Program Files\Rising\Rav\RSAPPMGR.DLL (0x003F0000)
C:\Program Files\Rising\Rav\CfgDll.dll (0x08A20000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\WINDOWS\system32\OLEAUT32.dll (0x770F0000)
C:\Program Files\Rising\Rav\RSCOMMON.DLL (0x23700000)
C:\Program Files\Rising\Rav\RsCommX.dll (0x08CC0000)
C:\Program Files\Rising\Rav\RsXML.dll (0x23800000)
C:\Program Files\Rising\Rav\PngDll.dll (0x23900000)
C:\WINDOWS\system32\uxtheme.dll (0x5ADC0000)
C:\Program Files\360safe\safemon\safemon.dll (0x092F0000)
C:\WINDOWS\system32\MSCTF.dll (0x74680000)
C:\WINDOWS\system32\msctfime.ime (0x73640000)
C:\WINDOWS\system32\perfproc.dll (0x5E8E0000)
C:\WINDOWS\system32\wtsapi32.dll (0x76F20000)
C:\WINDOWS\system32\WINSTA.dll (0x762D0000)
C:\WINDOWS\system32\NETAPI32.dll (0x5FDD0000)
C:\Program Files\Rising\AntiSpyware\ieprot.dll (0x09A30000)
随便说说 - 2007-5-15 18:15:00
=====================================================
PROCESS NAME: wscntfy.exe
-----------------------------------------------------
Process ID = 0x00000660
Thread count= 2
Parent process ID = 984
Priority Class = 32
Modules:
------------------------------------
C:\WINDOWS\system32\wscntfy.exe (0x01000000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\WINDOWS\system32\xpsp2res.dll (0x20000000)
C:\WINDOWS\system32\uxtheme.dll (0x5ADC0000)
C:\Program Files\360safe\safemon\safemon.dll (0x10000000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\WINDOWS\system32\OLEAUT32.dll (0x770F0000)
C:\WINDOWS\system32\MSCTF.dll (0x74680000)
C:\WINDOWS\system32\msctfime.ime (0x73640000)
C:\Program Files\Rising\AntiSpyware\ieprot.dll (0x008C0000)
=====================================================
PROCESS NAME: alg.exe
-----------------------------------------------------
WARNING: OpenProcess failed with error 5 ()
Process ID = 0x00000508
Thread count= 6
Parent process ID = 652
Modules:
------------------------------------
=====================================================
PROCESS NAME: IEXPLORE.EXE
-----------------------------------------------------
Process ID = 0x00000880
Thread count= 19
Parent process ID = 1332
Priority Class = 32
随便说说 - 2007-5-15 18:15:00
Modules:
------------------------------------
C:\Program Files\Internet Explorer\IEXPLORE.EXE (0x00400000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\SHDOCVW.dll (0x7E550000)
C:\WINDOWS\system32\CRYPT32.dll (0x765E0000)
C:\WINDOWS\system32\MSASN1.dll (0x76DB0000)
C:\WINDOWS\system32\CRYPTUI.dll (0x75430000)
C:\WINDOWS\system32\WINTRUST.dll (0x76C00000)
C:\WINDOWS\system32\IMAGEHLP.dll (0x76C60000)
C:\WINDOWS\system32\OLEAUT32.dll (0x770F0000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\WINDOWS\system32\NETAPI32.dll (0x5FDD0000)
C:\WINDOWS\system32\WININET.dll (0x76680000)
C:\WINDOWS\system32\WLDAP32.dll (0x76F30000)
C:\WINDOWS\system32\VERSION.dll (0x77BD0000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\comctl32.dll (0x5D170000)
C:\WINDOWS\system32\uxtheme.dll (0x5ADC0000)
C:\Program Files\360safe\safemon\safemon.dll (0x10000000)
C:\WINDOWS\system32\MSCTF.dll (0x74680000)
C:\WINDOWS\system32\BROWSEUI.dll (0x75EF0000)
C:\WINDOWS\system32\browselc.dll (0x20000000)
C:\WINDOWS\system32\appHelp.dll (0x76D70000)
C:\WINDOWS\system32\CLBCATQ.DLL (0x76FA0000)
C:\WINDOWS\system32\COMRes.dll (0x77020000)
C:\WINDOWS\system32\msctfime.ime (0x73640000)
C:\WINDOWS\system32\Secur32.dll (0x77FC0000)
C:\WINDOWS\System32\cscui.dll (0x76590000)
C:\WINDOWS\System32\CSCDLL.dll (0x76570000)
C:\WINDOWS\system32\SETUPAPI.dll (0x76060000)
C:\WINDOWS\system32\urlmon.dll (0x75C60000)
C:\WINDOWS\system32\SXS.DLL (0x75E00000)
C:\WINDOWS\system32\shdoclc.dll (0x00F90000)
C:\WINDOWS\system32\xpsp2res.dll (0x01200000)
C:\WINDOWS\system32\mlang.dll (0x74CF0000)
C:\WINDOWS\system32\wsock32.dll (0x71A40000)
C:\WINDOWS\system32\WS2_32.dll (0x71A20000)
C:\WINDOWS\system32\WS2HELP.dll (0x71A10000)
C:\WINDOWS\system32\mswsock.dll (0x719C0000)
C:\WINDOWS\system32\hnetcfg.dll (0x60FD0000)
C:\WINDOWS\System32\wshtcpip.dll (0x71A00000)
C:\WINDOWS\system32\RASAPI32.DLL (0x76EB0000)
C:\WINDOWS\system32\rasman.dll (0x76E60000)
C:\WINDOWS\system32\TAPI32.dll (0x76E80000)
C:\WINDOWS\system32\rtutils.dll (0x76E50000)
C:\WINDOWS\system32\WINMM.dll (0x76B10000)
C:\WINDOWS\system32\sensapi.dll (0x72240000)
C:\WINDOWS\system32\USERENV.dll (0x759D0000)
C:\WINDOWS\system32\DNSAPI.dll (0x76EF0000)
C:\WINDOWS\System32\winrnr.dll (0x76F80000)
C:\Program Files\Rising\AntiSpyware\ieprot.dll (0x01050000)
C:\WINDOWS\system32\rasadhlp.dll (0x76F90000)
C:\WINDOWS\system32\iphlpapi.dll (0x76D30000)
C:\WINDOWS\system32\Mshtml.dll (0x7E210000)
C:\WINDOWS\system32\msls31.dll (0x74620000)
C:\WINDOWS\system32\PSAPI.DLL (0x76BC0000)
C:\WINDOWS\system32\msimtf.dll (0x74650000)
C:\WINDOWS\system32\jscript.dll (0x75BC0000)
C:\WINDOWS\system32\wdmaud.drv (0x72C90000)
C:\WINDOWS\system32\msacm32.drv (0x72C80000)
C:\WINDOWS\system32\MSACM32.dll (0x77BB0000)
C:\WINDOWS\system32\midimap.dll (0x77BA0000)
C:\WINDOWS\system32\iepeers.dll (0x67140000)
C:\WINDOWS\system32\WINSPOOL.DRV (0x72F70000)
C:\WINDOWS\system32\ImgUtil.dll (0x66B50000)
C:\WINDOWS\system32\pngfilt.dll (0x5E400000)
C:\WINDOWS\system32\msxml3.dll (0x5DD50000)
C:\WINDOWS\system32\mshtmled.dll (0x753B0000)
C:\WINDOWS\system32\winpy.ime (0x4CA50000)
C:\WINDOWS\system32\comdlg32.dll (0x76320000)
C:\WINDOWS\system32\winzm.ime (0x4BFE0000)
C:\WINDOWS\system32\winabc.ime (0x4A3E0000)
C:\WINDOWS\system32\Actxprxy.dll (0x71CC0000)
C:\WINDOWS\system32\vbscript.dll (0x73270000)
C:\WINDOWS\system32\MFC42.DLL (0x73D30000)
C:\WINDOWS\system32\MFC42LOC.DLL (0x61BE0000)
C:\WINDOWS\system32\Macromed\Flash\Flash6.ocx (0x03F90000)
C:\WINDOWS\system32\ddrawex.dll (0x6D7C0000)
C:\WINDOWS\system32\DDRAW.dll (0x736D0000)
C:\WINDOWS\system32\DCIMAN32.dll (0x73B30000)
C:\WINDOWS\system32\MSRATING.dll (0x60150000)
C:\WINDOWS\system32\msratelc.dll (0x60180000)
C:\WINDOWS\system32\ntshrui.dll (0x76960000)
C:\WINDOWS\system32\ATL.DLL (0x76AF0000)
C:\WINDOWS\system32\LINKINFO.dll (0x76950000)
C:\WINDOWS\system32\wuapi.dll (0x506A0000)
C:\WINDOWS\system32\sfc_os.dll (0x76C30000)
=====================================================
PROCESS NAME: SysInfoCollect.EXE
-----------------------------------------------------
Process ID = 0x00000ff0
Thread count= 2
Parent process ID = 1332
Priority Class = 32
随便说说 - 2007-5-15 18:16:00
Modules:
------------------------------------
C:\Documents and Settings\fcbfcb\桌面\System Information Collect Tool\SysInfoCollect.EXE (0x00400000)
C:\WINDOWS\system32\ntdll.dll (0x7C920000)
C:\WINDOWS\system32\kernel32.dll (0x7C800000)
C:\WINDOWS\system32\PSAPI.DLL (0x76BC0000)
C:\WINDOWS\system32\MFC42.DLL (0x73D30000)
C:\WINDOWS\system32\msvcrt.dll (0x77BE0000)
C:\WINDOWS\system32\GDI32.dll (0x77EF0000)
C:\WINDOWS\system32\USER32.dll (0x77D10000)
C:\WINDOWS\system32\ADVAPI32.dll (0x77DA0000)
C:\WINDOWS\system32\RPCRT4.dll (0x77E50000)
C:\WINDOWS\system32\SHELL32.dll (0x7D590000)
C:\WINDOWS\system32\SHLWAPI.dll (0x77F40000)
C:\WINDOWS\system32\IMM32.DLL (0x76300000)
C:\WINDOWS\system32\LPK.DLL (0x62C20000)
C:\WINDOWS\system32\USP10.dll (0x73FA0000)
C:\WINDOWS\system32\MFC42LOC.DLL (0x61BE0000)
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (0x77180000)
C:\WINDOWS\system32\uxtheme.dll (0x5ADC0000)
C:\Program Files\360safe\safemon\safemon.dll (0x10000000)
C:\WINDOWS\system32\ole32.dll (0x76990000)
C:\WINDOWS\system32\OLEAUT32.dll (0x770F0000)
C:\WINDOWS\system32\MSCTF.dll (0x74680000)
C:\WINDOWS\system32\msctfime.ime (0x73640000)
C:\Program Files\Rising\AntiSpyware\ieprot.dll (0x00B30000)
*****************************************************************
Local Win32 Service information
*****************************************************************
Alerter [Alerter ] <Stopped>, Binpath = C:\WINDOWS\system32\svchost.exe -k LocalService
Application Layer Gateway Service [ALG ] <Running>, Binpath = C:\WINDOWS\System32\alg.exe
Application Management [AppMgmt ] <Stopped>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Windows Audio [AudioSrv ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
Background Intelligent Transfer Service [BITS ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Computer Browser [Browser ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Indexing Service [CiSvc ] <Stopped>, Binpath = C:\WINDOWS\system32\cisvc.exe
ClipBook [ClipSrv ] <Stopped>, Binpath = C:\WINDOWS\system32\clipsrv.exe
COM+ System Application [COMSysApp ] <Stopped>, Binpath = C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Cryptographic Services [CryptSvc ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
DCOM Server Process Launcher [DcomLaunch ] <Running>, Binpath = C:\WINDOWS\system32\svchost -k DcomLaunch
DHCP Client [Dhcp ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Logical Disk Manager Administrative Service [dmadmin ] <Stopped>, Binpath = C:\WINDOWS\System32\dmadmin.exe /com
Logical Disk Manager [dmserver ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
DNS Client [Dnscache ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k NetworkService
Error Reporting Service [ERSvc ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
Event Log [Eventlog ] <Running>, Binpath = C:\WINDOWS\system32\services.exe
COM+ Event System [EventSystem ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Fast User Switching Compatibility [FastUserSwitchingCompatibility ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
Help and Support [helpsvc ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
Human Interface Device Access [HidServ ] <Stopped>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
HTTP SSL [HTTPFilter ] <Stopped>, Binpath = C:\WINDOWS\System32\svchost.exe -k HTTPFilter
IMAPI CD-Burning COM Service [ImapiService ] <Stopped>, Binpath = C:\WINDOWS\system32\imapi.exe
Server [lanmanserver ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Workstation [lanmanworkstation ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
TCP/IP NetBIOS Helper [LmHosts ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k LocalService
Messenger [Messenger ] <Stopped>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
NetMeeting Remote Desktop Sharing [mnmsrvc ] <Stopped>, Binpath = C:\WINDOWS\system32\mnmsrvc.exe
Distributed Transaction Coordinator [MSDTC ] <Stopped>, Binpath = C:\WINDOWS\system32\msdtc.exe
Windows Installer [MSIServer ] <Stopped>, Binpath = C:\WINDOWS\system32\msiexec.exe /V
Network DDE [NetDDE ] <Stopped>, Binpath = C:\WINDOWS\system32\netdde.exe
Network DDE DSDM [NetDDEdsdm ] <Stopped>, Binpath = C:\WINDOWS\system32\netdde.exe
随便说说 - 2007-5-15 18:16:00
Net Logon [Netlogon ] <Stopped>, Binpath = C:\WINDOWS\system32\lsass.exe
Network Connections [Netman ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
Network Location Awareness (NLA) [Nla ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
NT LM Security Support Provider [NtLmSsp ] <Stopped>, Binpath = C:\WINDOWS\system32\lsass.exe
Removable Storage [NtmsSvc ] <Stopped>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Plug and Play [PlugPlay ] <Running>, Binpath = C:\WINDOWS\system32\services.exe
IPSEC Services [PolicyAgent ] <Running>, Binpath = C:\WINDOWS\system32\lsass.exe
Protected Storage [ProtectedStorage ] <Running>, Binpath = C:\WINDOWS\system32\lsass.exe
Remote Access Auto Connection Manager [RasAuto ] <Stopped>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Remote Access Connection Manager [RasMan ] <Stopped>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Remote Desktop Help Session Manager [RDSessMgr ] <Stopped>, Binpath = C:\WINDOWS\system32\sessmgr.exe
Routing and Remote Access [RemoteAccess ] <Stopped>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Remote Registry [RemoteRegistry ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k LocalService
Remote Procedure Call (RPC) Locator [RpcLocator ] <Stopped>, Binpath = C:\WINDOWS\system32\locator.exe
Remote Procedure Call (RPC) [RpcSs ] <Running>, Binpath = C:\WINDOWS\system32\svchost -k rpcss
Rising Process Communication Center [RsCCenter ] <Running>, Binpath = "C:\Program Files\Rising\Rav\CCenter.exe"
Rising RealTime Monitor [RsRavMon ] <Running>, Binpath = "C:\Program Files\Rising\Rav\Ravmond.exe"
QoS RSVP [RSVP ] <Stopped>, Binpath = C:\WINDOWS\system32\rsvp.exe
Security Accounts Manager [SamSs ] <Running>, Binpath = C:\WINDOWS\system32\lsass.exe
Smart Card [SCardSvr ] <Stopped>, Binpath = C:\WINDOWS\System32\SCardSvr.exe
Task Scheduler [Schedule ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
Secondary Logon [seclogon ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
System Event Notification [SENS ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Windows Firewall/Internet Connection Sharing (ICS) [SharedAccess ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Shell Hardware Detection [ShellHWDetection ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
Print Spooler [Spooler ] <Running>, Binpath = C:\WINDOWS\system32\spoolsv.exe
System Restore Service [srservice ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
SSDP Discovery Service [SSDPSRV ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k LocalService
Windows Image Acquisition (WIA) [stisvc ] <Stopped>, Binpath = C:\WINDOWS\system32\svchost.exe -k imgsvc
MS Software Shadow Copy Provider [SwPrv ] <Stopped>, Binpath = C:\WINDOWS\system32\dllhost.exe /Processid:{F3A969B3-D332-4B66-B184-DF945DD8B514}
Performance Logs and Alerts [SysmonLog ] <Stopped>, Binpath = C:\WINDOWS\system32\smlogsvc.exe
Telephony [TapiSrv ] <Stopped>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
Terminal Services [TermService ] <Running>, Binpath = C:\WINDOWS\System32\svchost -k DComLaunch
Themes [Themes ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
Telnet [TlntSvr ] <Stopped>, Binpath = C:\WINDOWS\system32\tlntsvr.exe
Distributed Link Tracking Client [TrkWks ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Universal Plug and Play Device Host [upnphost ] <Stopped>, Binpath = C:\WINDOWS\system32\svchost.exe -k LocalService
Uninterruptible Power Supply [UPS ] <Stopped>, Binpath = C:\WINDOWS\System32\ups.exe
Volume Shadow Copy [VSS ] <Stopped>, Binpath = C:\WINDOWS\System32\vssvc.exe
Windows Time [W32Time ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
WebClient [WebClient ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k LocalService
Windows Management Instrumentation [winmgmt ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Portable Media Serial Number Service [WmdmPmSN ] <Stopped>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
Windows Management Instrumentation Driver Extensions [Wmi ] <Stopped>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
WMI Performance Adapter [WmiApSrv ] <Stopped>, Binpath = C:\WINDOWS\system32\wbem\wmiapsrv.exe
Security Center [wscsvc ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
Automatic Updates [wuauserv ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Wireless Zero Configuration [WZCSVC ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
随便说说 - 2007-5-15 18:17:00
*****************************************************************
IE BHOs
*****************************************************************
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} Safemon.NavigatMon.1 C:\Program Files\360safe\safemon\safemon.dll
*****************************************************************
Boot items in Registry
*****************************************************************
------------------------------------------------------------
0:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
------------------------------------------------------------
ctfmon.exe……C:\WINDOWS\system32\ctfmon.exe
------------------------------------------------------------
1:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
------------------------------------------------------------
------------------------------------------------------------
2:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
------------------------------------------------------------
------------------------------------------------------------
3:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices
------------------------------------------------------------
------------------------------------------------------------
4:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
------------------------------------------------------------
------------------------------------------------------------
5:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows 键值名称:load
------------------------------------------------------------
------------------------------------------------------------
6:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows 键值名称:run
------------------------------------------------------------
------------------------------------------------------------
7:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System 键值名称:Shell
------------------------------------------------------------
------------------------------------------------------------
8:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
------------------------------------------------------------
------------------------------------------------------------
9:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
------------------------------------------------------------
IMJPMIG8.1……"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
PHIME2002ASync……C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A……C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
KBD……C:\HP\KBD\KBD.EXE
SoundMan……SOUNDMAN.EXE
RavTask……"C:\Program Files\Rising\Rav\RavTask.exe" -system
runeip……C:\Program Files\Rising\AntiSpyware\runiep.exe
360Safetray……C:\Program Files\360safe\safemon\360Tray.exe /start
------------------------------------------------------------
10:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
------------------------------------------------------------
随便说说 - 2007-5-15 18:17:00
------------------------------------------------------------
11:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
------------------------------------------------------------
------------------------------------------------------------
12:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunService
------------------------------------------------------------
------------------------------------------------------------
13:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServiceOnce
------------------------------------------------------------
------------------------------------------------------------
14:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
------------------------------------------------------------
------------------------------------------------------------
15:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon 键值名称:Shell
------------------------------------------------------------
Shell……Explorer.exe
------------------------------------------------------------
16:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon 键值名称:Userinit
------------------------------------------------------------
Userinit……C:\WINDOWS\system32\userinit.exe,
------------------------------------------------------------
17:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows 键值名称:AppInit_DLLs
------------------------------------------------------------
*****************************************************************
File association information
*****************************************************************
------------------------------------------------------------
0:HKEY_CLASSES_ROOT\.exe
------------------------------------------------------------
<DEFAULT> = exefile, 正常!
------------------------------------------------------------
1:HKEY_CLASSES_ROOT\exefile\shell\open\command
------------------------------------------------------------
<DEFAULT> = "%1" %*, 正常!
------------------------------------------------------------
2:HKEY_CLASSES_ROOT\exefile\shell\runas\command
------------------------------------------------------------
<DEFAULT> = "%1" %*, 正常!
------------------------------------------------------------
3:HKEY_CLASSES_ROOT\.txt
------------------------------------------------------------
<DEFAULT> = txtfile, 正常!
------------------------------------------------------------
4:HKEY_CLASSES_ROOT\txtfile\shell\open\command
------------------------------------------------------------
<DEFAULT> = %SystemRoot%\system32\NOTEPAD.EXE %1, 正常!
------------------------------------------------------------
5:HKEY_CLASSES_ROOT\.reg
------------------------------------------------------------
<DEFAULT> = regfile, 正常!
------------------------------------------------------------
6:HKEY_CLASSES_ROOT\regfile\shell\open\command
------------------------------------------------------------
<DEFAULT> = regedit.exe "%1", 正常!
------------------------------------------------------------
7:HKEY_CLASSES_ROOT\.bat
------------------------------------------------------------
<DEFAULT> = batfile, 正常!
------------------------------------------------------------
8:HKEY_CLASSES_ROOT\batfile\shell\open\command
------------------------------------------------------------
<DEFAULT> = "%1" %*, 正常!
------------------------------------------------------------
9:HKEY_CLASSES_ROOT\.com
------------------------------------------------------------
<DEFAULT> = comfile, 正常!
------------------------------------------------------------
10:HKEY_CLASSES_ROOT\comfile\shell\open\command
------------------------------------------------------------
<DEFAULT> = "%1" %*, 正常!
------------------------------------------------------------
11:HKEY_CLASSES_ROOT\.scr
------------------------------------------------------------
<DEFAULT> = scrfile, 正常!
------------------------------------------------------------
12:HKEY_CLASSES_ROOT\scrfile\shell\open\command
------------------------------------------------------------
<DEFAULT> = "%1" /S, 正常!
------------------------------------------------------------
13:HKEY_CLASSES_ROOT\.pif
------------------------------------------------------------
<DEFAULT> = piffile, 正常!
------------------------------------------------------------
随便说说 - 2007-5-15 18:17:00
14:HKEY_CLASSES_ROOT\piffile\shell\open\command
------------------------------------------------------------
<DEFAULT> = "%1" %*, 正常!
1
© 2000 - 2026 Rising Corp. Ltd.