大侠7 - 2007-7-4 12:34:00
浏览器加载项
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <D:\工具\Thunder Network\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\工具\Thunder Network\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <D:\工具\Thunder Network\Thunder.exe, Thunder Networking Technologies,LTD>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <H:\Windows\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[ThunderAtOnce Class]
{01443AEC-0FD1-40FD-9C87-E93D1494C233} <D:\工具\Thunder Network\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <D:\工具\Thunder Network\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\工具\Thunder Network\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <%CommonProgramFiles%\System\msadc\msadco.dll, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <H:\Windows\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[使用迅雷下载]
<D:\工具\Thunder Network\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
<D:\工具\Thunder Network\Program\getallurl.htm, N/A>
==================================
正在运行的进程
[PID: 352 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 436 / SYSTEM][H:\Windows\system32\csrss.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 484 / SYSTEM][H:\Windows\system32\csrss.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 492 / SYSTEM][H:\Windows\system32\wininit.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 536 / SYSTEM][H:\Windows\system32\services.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[PID: 548 / SYSTEM][H:\Windows\system32\lsass.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 556 / SYSTEM][H:\Windows\system32\lsm.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 604 / SYSTEM][H:\Windows\system32\winlogon.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 756 / SYSTEM][H:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 812 / NETWORK SERVICE][H:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[PID: 864 / SYSTEM][H:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 960 / SYSTEM][H:\Windows\System32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 996 / LOCAL SERVICE][H:\Windows\System32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1020 / SYSTEM][H:\Windows\System32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[PID: 1036 / SYSTEM][H:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[PID: 1140 / NETWORK SERVICE][H:\Windows\system32\SLsvc.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1260 / SYSTEM][H:\PROGRAM FILES\RISING\RAV\Ravmond.exe] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 54]
[H:\PROGRAM FILES\RISING\RAV\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 0]
[H:\PROGRAM FILES\RISING\RAV\RsCommX.dll] [rising, 18, 0, 0, 1]
[H:\PROGRAM FILES\RISING\RAV\rfwctrl.dll] [Beijing Rising Technology Co., Ltd., 6, 0, 0, 0]
[H:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 1]
[H:\PROGRAM FILES\RISING\RAV\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 3]
[H:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[H:\PROGRAM FILES\RISING\RAV\RsLog.dll] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 0]
[H:\PROGRAM FILES\RISING\RAV\HOOKSYS.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
[H:\Program Files\Rising\Rav\fakescan.dll] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 6]
[H:\PROGRAM FILES\RISING\RAV\Scanner.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[H:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[H:\PROGRAM FILES\RISING\RAV\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[H:\PROGRAM FILES\RISING\RAV\regmon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[H:\PROGRAM FILES\RISING\RAV\HookWeb.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[H:\PROGRAM FILES\RISING\RAV\HookCont.dll] [Rising, 19, 0, 0, 1]
[H:\Program Files\Rising\Rav\SpamEng.dll] [, 18, 0, 0, 6]
[H:\Program Files\Rising\Rav\engine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 30]
[H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[H:\Program Files\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[H:\Program Files\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[H:\Program Files\Rising\Rav\ExtFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
[H:\Program Files\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 64]
[H:\Program Files\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[H:\Program Files\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[H:\Program Files\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
[H:\Program Files\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
[H:\Program Files\Rising\Rav\ScanPack.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 23]
[H:\Program Files\Rising\Rav\RsVM.dll] [, 19, 0, 0, 17]
[H:\Program Files\Rising\Rav\Uroutine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 40]
[H:\Program Files\Rising\Rav\ExtOLE.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
[H:\Program Files\Rising\Rav\ScanNet.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[H:\Program Files\Rising\Rav\Uscript.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[H:\Program Files\Rising\Rav\ScanElf.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[H:\Program Files\Rising\Rav\ExtMail.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
[PID: 1344 / LOCAL SERVICE][H:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[PID: 1496 / SYSTEM][H:\program files\rising\rav\cfgload.exe] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 2]
[H:\program files\rising\rav\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 1]
[H:\program files\rising\rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 3]
[PID: 1516 / NETWORK SERVICE][H:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1532 / LOCAL SERVICE][H:\Windows\system32\svchost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1600 / SYSTEM][H:\Program Files\Common Files\Rising\vsapisrv.exe] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 13]
[PID: 1620 / SYSTEM][H:\program files\rising\rav\scannerd.exe] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 9]
[PID: 1640 / SYSTEM][H:\Program Files\Common Files\Rising\rsupd.exe] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 2]
[PID: 1688 / SYSTEM][H:\Windows\system32\SearchIndexer.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1948 / Administrator][H:\Windows\system32\Dwm.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2020 / Administrator][H:\Windows\Explorer.EXE] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[H:\Program Files\WinRAR\rarext.dll] [N/A, ]
[H:\Windows\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 9]
[H:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 360 / SYSTEM][H:\Windows\system32\taskeng.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 416 / Administrator][H:\Windows\system32\taskeng.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 752 / Administrator][H:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 3]
大侠7 - 2007-7-4 12:35:00
[H:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[H:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 1]
[H:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 3]
[H:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[PID: 780 / Administrator][H:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 60]
[H:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 34]
[H:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 0]
[H:\Program Files\Rising\Rav\jmpapi.dll] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 11]
[H:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 1]
[H:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 3]
[H:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[H:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[H:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 2]
[H:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 19, 2, 0, 5]
[PID: 2216 / Administrator][H:\Program Files\Windows Media Player\wmpnscfg.exe] [Microsoft Corporation, 11.0.6000.6324 (vista_rtm.061101-2205)]
[PID: 2412 / Administrator][H:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 7.00.6000.16386 (vista_rtm.061101-2205)]
[D:\工具\Thunder Network\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.2.9]
[D:\工具\Thunder Network\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 3, 11]
[D:\工具\Thunder Network\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 4]
[D:\工具\Thunder Network\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
[H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[H:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[H:\Windows\system32\Macromed\Flash\Flash9c.ocx] [Adobe Systems, Inc., 9,0,45,0]
[H:\Windows\system32\nvd3dum.dll] [NVidia Corporation, 7.15.10.9686]
[PID: 3104 / SYSTEM][H:\Windows\system32\SearchProtocolHost.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 3016 / SYSTEM][H:\Windows\servicing\TrustedInstaller.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1848 / NETWORK SERVICE][H:\Windows\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2964 / Administrator][E:\软件\安全\AVG Anti-Spyware\avgas.exe] [GRISOFT s.r.o., 7, 5, 1, 43]
[E:\软件\安全\AVG Anti-Spyware\engine.dll] [GRISOFT s.r.o., 4, 2, 0, 19]
[H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[PID: 1912 / Administrator][E:\软件\扫描\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[E:\软件\扫描\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["%SystemRoot%\hh.exe" %1]
.HLP OK. [%SystemRoot%\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. ["%SystemRoot%\System32\WScript.exe" "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
Rising Net Filter over [MSAFD Tcpip [TCP/IP]]
H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Technology Co., Ltd., HookSpi)
Rising Net Filter over [MSAFD Tcpip [UDP/IP]]
H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Technology Co., Ltd., HookSpi)
Rising Net Filter over [MSAFD Tcpip [RAW/IP]]
H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Technology Co., Ltd., HookSpi)
Rising Net Filter over [MSAFD Tcpip [TCP/IPv6]]
H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Technology Co., Ltd., HookSpi)
Rising Net Filter over [MSAFD Tcpip [UDP/IPv6]]
H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Technology Co., Ltd., HookSpi)
Rising Net Filter over [MSAFD Tcpip [RAW/IPv6]]
H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Technology Co., Ltd., HookSpi)
Rising Net Filter over [RSVP TCPv6 服务提供商]
H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Technology Co., Ltd., HookSpi)
Rising Net Filter over [RSVP TCP 服务提供商]
H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Technology Co., Ltd., HookSpi)
Rising Net Filter over [RSVP UDPv6 服务提供商]
H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Technology Co., Ltd., HookSpi)
Rising Net Filter over [RSVP UDP 服务提供商]
H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Technology Co., Ltd., HookSpi)
Rising Net Filter over [MSAFD NetBIOS [\Device\NetBT_Tcpip_{10BE8295-D23C-4B8A-B055-9E3D643BA1A4}] SEQPACKET 2]
H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Technology Co., Ltd., HookSpi)
Rising Net Filter over [MSAFD NetBIOS [\Device\NetBT_Tcpip_{10BE8295-D23C-4B8A-B055-9E3D643BA1A4}] DATAGRAM 2]
H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Technology Co., Ltd., HookSpi)
Rising Net Filter over [MSAFD NetBIOS [\Device\NetBT_Tcpip6_{10BE8295-D23C-4B8A-B055-9E3D643BA1A4}] SEQPACKET 3]
H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Technology Co., Ltd., HookSpi)
Rising Net Filter over [MSAFD NetBIOS [\Device\NetBT_Tcpip6_{10BE8295-D23C-4B8A-B055-9E3D643BA1A4}] DATAGRAM 3]
H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Technology Co., Ltd., HookSpi)
Rising Net Filter
H:\PROGRAM FILES\RISING\RAV\HOOKSPI.DLL(Beijing Rising Technology Co., Ltd., HookSpi)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
::1 localhost
==================================
进程特权扫描
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
[2356] H:\Windows\System32\wuapp.exe
==================================
© 2000 - 2026 Rising Corp. Ltd.