Rising Information Technology Co., Ltd., 7.0.0.9]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.6.0.1653]
[PID: 2892 / Administrator][C:\Program Files\arswp\ArSwp.exe] [ArSwp.com, 2, 8, 2, 1115]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33]
[F:\瑞星\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[F:\瑞星\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21]
[C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9]
[D:\Backup\我的文档\000\杀软2\KPP\KPPShellEx.dll] [Kingsoft Corporation, 2008,03,10,1183]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.6.0.1653]
[C:\Program Files\arswp\plugin\ArFix.dll] [ArSwp.Com, 2, 5, 0, 0]
[PID: 2076 / Administrator][F:\瑞星\knownsvr.exe] [Beijing Rising Information Technology Co., Ltd., 6.0.0.12]
[F:\瑞星\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.6]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33]
[F:\瑞星\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[F:\瑞星\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[PID: 3632 / Administrator][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 7.00.6000.16735 (vista_gdr.080820-1506)]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33]
[F:\瑞星\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[F:\瑞星\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21]
[C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.6.0.1653]
[D:\Backup\我的文档\000\杀软2\KPP\KPPShellEx.dll] [Kingsoft Corporation, 2008,03,10,1183]
[D:\Backup\我的文档\000\杀软2\KPP\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0]
[C:\WINDOWS\system32\KakaTool.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 3]
[C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29]
[C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
[C:\WINDOWS\system32\UrlFilter.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 15]
[F:\瑞星\UrlRule.dll] [Beijing Rising Information Technology Co., Ltd., 1.0.0.15]
[F:\金山词霸\PowerWord Lite\CBEBand.dll] [Copyright (c) Kingsoft Corporation Limited. All rights reserved., 0.0.1.2]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5]
[C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx] [Adobe Systems, Inc., 10,0,12,36]
[C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xmvsource.dll_1_work] [XunLei, 1, 0, 0, 5]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[C:\Program Files\Samsung\Samsung PC Studio 3\FunVideoCodecFilter.ax] [Mobile Leader, 1.06]
[C:\Program Files\Samsung\Samsung PC Studio 3\MSLUR71.dll] [MobileLeader, Inc., 7.10.0000]
[C:\Program Files\Samsung\Samsung PC Studio 3\FunAudioCodecFilter.ax] [Mobile Leader, 1.02]
[F:\快乐影音\KLPlayer\Codecs\ffdshow.ax] [, 1.0.5.2055]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\voxmsdec.ax] [Voxware, Inc., 1.0.0.012]
[C:\WINDOWS\system32\voxmvdec.ax] [Voxware, Inc., 1.0.0.011]
[C:\Program Files\StormII\Codec\VideoTune.ax] [CHINA, 1, 0, 0, 1]
[C:\WINDOWS\system32\l3codecx.ax] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 5, 0, 50]
[F:\快乐影音\KLPlayer\Codecs\vsfilter.dll] [Gabest, 1, 0, 1, 3]
[C:\WINDOWS\system32\TTL2Dec.dll] [N/A, ]
[C:\WINDOWS\system32\acelpdec.ax] [Sipro Lab Telecom Inc., 1.40]
[C:\Program Files\PowerInfo\DreamPlayer\H264DecFilter.ax] [VVSky, 1.00]
[C:\WINDOWS\system32\Vid1Dec.dll] [N/A, ]
[C:\WINDOWS\system32\xvid.ax] [N/A, ]
[C:\WINDOWS\system32\CoreAAC.ax] [, 1, 2, 0, 573]
[C:\WINDOWS\system32\DivX_c32.ax] [Hacked With Joy ! , 4.DivX.3917]
[C:\Program Files\PowerInfo\DreamPlayer\DreamMDV.ax] [PowerInfo, 3, 0, 0, 1]
[C:\Program Files\PowerInfo\DreamPlayer\DreamMDA.ax] [PowerInfo, 3, 0, 0, 1]
[C:\Program Files\PowerInfo\DreamPlayer\DreamMDX.ax] [PowerInfo, 3, 0, 0, 1]
[C:\WINDOWS\system32\ir41_32.ax] [Intel Corporation, 4.51.16.03]
[C:\WINDOWS\system32\ir50_32.dll] [Intel Corporation, R.5.10.15.2.55]
[C:\Program Files\Common Files\Sonic Shared\CinemasterAudio.dll] [Sonic Solutions, 4, 3, 0, 169]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[F:\快乐影音\KLPlayer\Codecs\CLVSD.ax] [CyberLink Corp., 8.2.530 ]
[F:\快乐影音\KLPlayer\Codecs\CoreAVCDecoder.ax] [CoreCodec, Inc., 1, 5, 0, 0]
[F:\快乐影音\KLPlayer\Codecs\mxrender.dll] [Collegesoft Co., Ltd., 1, 2, 0, 0]
[F:\快乐影音\KLPlayer\Codecs\MDSSND.dll] [Collegesoft Co., Ltd., 1, 6, 2602, 1]
[F:\快乐影音\KLPlayer\Codecs\mtcontrol.dll] [Collegesoft Co., Ltd., 1, 4, 2602, 1]
[F:\快乐影音\KLPlayer\Codecs\mtcontain.dll] [Collegesoft Co., Ltd., 1.4.0.0]
[F:\快乐影音\KLPlayer\Codecs\wtlvcl.dll] [Collegesoft Co.,Ltd., 1.4.0.0]
[F:\快乐影音\KLPlayer\Codecs\mdssockc.dll] [Collegesoft Co., Ltd., 5, 20, 2509, 0]
[F:\快乐影音\KLPlayer\Codecs\mcucltu.dll] [Collegesoft Co., Ltd., 2, 0, 2602, 1]
[F:\快乐影音\KLPlayer\Codecs\mxshmaiu.dll] [Collegesoft Co., Ltd., 1, 2, 2572, 0]
[F:\快乐影音\KLPlayer\Codecs\mxbitmap.dll] [N/A, ]
[F:\快乐影音\KLPlayer\Codecs\mxcurhk.dll] [N/A, ]
[F:\快乐影音\KLPlayer\Codecs\PmpSplitter.ax] [cooleyes, 1, 0, 1, 1]
[F:\快乐影音\KLPlayer\RadGtSplitter.ax] [Gabest, 1, 0, 0, 0]
[F:\快乐影音\KLPlayer\Codecs\AviSplitter.ax] [Gabest, 1, 1, 0, 0]
[C:\Program Files\Samsung\Samsung PC Studio 3\FunConvFilter.ax] [Mobile Leader, 1.01]
[F:\快乐影音\KLPlayer\Codecs\mpeg2dmx.ax] [Moonlight Cordless Ltd., 3, 1, 200, 50117]
[C:\WINDOWS\system32\mpeg2data.ax] [, ]
[C:\WINDOWS\system32\encdec.dll] [, ]
[F:\快乐影音\KLPlayer\Codecs\xebdec.ax] [ratDVD, 0, 5, 0, 16]
[F:\快乐影音\KLPlayer\Codecs\WavPackDSSplitter.ax] [-, 1, 1, 0, 319]
[C:\WINDOWS\system32\RealMediaSplitter.ax] [Gabest, 1, 0, 1, 1]
[F:\快乐影音\KLPlayer\Codecs\TTADSSplitter.ax] [-, 1, 0, 0, 197]
[F:\快乐影音\KLPlayer\Codecs\VgmAudioDecX.ax] [DS USA, Inc., 1, 0, 6, 9]
[C:\WINDOWS\system32\DmoDec.dll] [Microsoft Corporation, 8.10]
[F:\快乐影音\KLPlayer\Codecs\TRLDRP6.AX] [, 4, 7, 2, 9]
[C:\WINDOWS\system32\mpg2splt.ax] [, ]
[F:\快乐影音\KLPlayer\Codecs\FLVSplitter.ax] [Gabest, 1, 1, 0, 0]
[F:\快乐影音\KLPlayer\Codecs\WavPackDSDecoder.ax] [-, 1, 1, 0, 482]
[C:\Program Files\Samsung\Samsung PC Studio 3\FunAviSplitter.ax] [Gabest, 1, 0, 0, 7]
[F:\快乐影音\KLPlayer\Codecs\vgmv2k2dx.ax] [DS USA, Inc, 1, 0, 11, 14]
[F:\快乐影音\KLPlayer\Codecs\TTADSDecoder.ax] [-, 1, 0, 0, 157]
[F:\快乐影音\KLPlayer\Codecs\madFlac.ax] [
www.madshi.net, 1.7.0.0]
[F:\快乐影音\KLPlayer\Codecs\libFlac.dll] [N/A, ]
[C:\WINDOWS\system32\Mpeg4VideoDecoder.ax] [Institute for Information Industry (III), 1, 0, 305, 19]
[C:\WINDOWS\system32\III_AMR_DecoderFilter.ax] [N/A, ]
[F:\快乐影音\KLPlayer\Codecs\VgmSplt.ax] [DS USA, Inc, 1, 0, 11, 19]
[C:\WINDOWS\system32\III_AMR_EncoderFilter.ax] [N/A, ]
[C:\WINDOWS\system32\Mpeg4Splitter.ax] [Institute for Information Industry (III), 1, 0, 305, 19]
[C:\WINDOWS\system32\iac25_32.ax] [Intel Corporation, 2.05.53]
[F:\快乐影音\KLPlayer\Codecs\vgmbgr.ax] [DS USA, Inc., 1, 0, 3, 4]
[C:\WINDOWS\system32\aac_parser.ax] [, 1.1]
[F:\快乐影音\KLPlayer\Codecs\splitter.ax] [, 1.7.401.3]
[F:\快乐影音\KLPlayer\Codecs\mkzlib.dll] [N/A, ]
[F:\快乐影音\KLPlayer\Codecs\mkunicode.dll] [N/A, ]
[PID: 4000 / SYSTEM][C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE] [Microsoft Corporation, 11.0.5525]
[PID: 3484 / Administrator][F:\新建文件夹\S\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210]
[C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33]
[C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9]
[PID: 3464 / Administrator][F:\新建文件夹\S\SRE46903132.EXE] [Smallfrogs Studio, 2.7.0.1210]
[C:\Program Files\Rising\Rfw\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21]
[C:\Program Files\Rising\Rfw\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.6.0.1653]
[F:\新建文件夹\S\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 976, C:\WINDOWS\ZSSNP211.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 976, C:\WINDOWS\ZSSNP211.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2892, C:\PROGRAM FILES\ARSWP\ARSWP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2892, C:\PROGRAM FILES\ARSWP\ARSWP.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3484, F:\新建文件夹\S\SRENGLDR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3484, F:\新建文件夹\S\SRENGLDR.EXE]
==================================
计划任务
[已启用] SogouImeMgr.job
D:\DOWNLO~1\SOFT_N~1\SOGOUI~1\360~1.165\PinyinRepair.exe
==================================
API HOOK
入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: 0x01011FFD)
入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: 0x010120E5)
==================================
隐藏进程
N/A
==================================