[C:\Program Files\Rising\Ris\MonState.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2]
[C:\Program Files\Rising\Ris\ScanEvnt.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.2]
[C:\Program Files\Rising\Ris\rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 52]
[C:\Program Files\Rising\Ris\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1]
[C:\Program Files\Rising\Ris\rfwrule.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1]
[C:\Program Files\Rising\Ris\rspalvd.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.6]
[C:\Program Files\Rising\Ris\rsnetsvr.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 1]
[C:\Program Files\Rising\Ris\ravbintl.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 18]
[C:\Program Files\Rising\Ris\mruleui.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6]
[C:\Program Files\Rising\Ris\MonTray.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.56]
[C:\Program Files\Rising\Ris\RavITray.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6]
[C:\Program Files\Rising\Ris\rfwtray.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 32]
[C:\Program Files\Rising\Ris\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2]
[C:\Program Files\Rising\Ris\scanleak.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4]
[C:\Program Files\Rising\Ris\ravppops.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 20]
[C:\Program Files\Rising\Ris\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0]
[C:\Program Files\Rising\Ris\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.0]
[C:\Program Files\Rising\Ris\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4]
[C:\Program Files\Rising\Ris\ScanPrxy.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1]
[C:\Program Files\Rising\Ris\rfwlog.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.12]
[PID: 272 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38]
[PID: 768 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 468 / SYSTEM][C:\Program Files\StormII\stormliv.exe] [北京暴风网际科技有限公司, 3, 9, 5, 29]
[C:\Program Files\StormII\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38]
[C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\StormII\bfoptdll.dll] [北京暴风网际科技有限公司, 3, 8, 7, 16]
[C:\Program Files\StormII\box\BoxLog.dll] [北京暴风网际科技有限公司, 3, 9, 5, 30]
[PID: 892 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.11.7474]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38]
[C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.7474]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1920 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38]
[C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[PID: 2096 / Administrator][C:\Program Files\Rising\Ris\RsAgent.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.19]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Rising\Ris\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Rising\Ris\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[C:\Program Files\Rising\Ris\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[C:\Program Files\Rising\Ris\ScanPrxy.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.1]
[C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159]
[PID: 556 / Administrator][C:\WINDOWS\msagent\AgentSvr.exe] [(Verified) Microsoft Corporation, 2.00.0.3427]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38]
[C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[D:\Program Files\360\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159]
[PID: 2396 / Administrator][C:\Program Files\Tencent\TT\bin\TTraveler.exe] [Tencent, 4, 19, 0, 13]
[C:\Program Files\Tencent\TT\bin\TTUtilWidget.dll] [Tencent, 4, 19, 0, 13]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38]
[C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[D:\Program Files\360\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[C:\Program Files\Tencent\TT\bin\PlatformWidget.dll] [Tencent, 4, 19, 0, 13]
[C:\Program Files\Tencent\TT\bin\TTMainFrame.dll] [Tencent, 4, 19, 0, 13]
[C:\Program Files\Tencent\TT\bin\UpdateUtil.dll] [N/A, ]
[C:\Program Files\Tencent\TT\bin\TTStore.dll] [Tencent, 4, 19, 0, 13]
[C:\Program Files\Tencent\TT\bin\sqlite3.dll] [N/A, ]
[C:\Program Files\Tencent\TT\bin\TTMBrowser.dll] [Tencent, 4, 19, 0, 13]
[C:\Program Files\Tencent\TT\bin\TTabMgr.dll] [Tencent, 4, 19, 0, 13]
[C:\Program Files\Tencent\TT\bin\TTSkin.dll] [Tencent, 4, 19, 0, 13]
[E:\TT\bin\PlatformWidget.dll] [Tencent, 4, 31, 0, 1]
[C:\Program Files\Tencent\TT\bin\TTHtmlApp.dll] [Tencent, 4, 19, 0, 13]
[C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159]
[C:\Program Files\Tencent\TT\bin\TTFilter.dll] [Tencent, 4, 19, 0, 13]
[C:\Program Files\Tencent\TT\bin\TTNetwork.dll] [Tencent, 4, 19, 0, 13]
[C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\Program Files\Tencent\TT\bin\TTPluginMng.dll] [Tencent, 4, 19, 0, 13]
[C:\Program Files\Tencent\TT\Plugins\3TTWeather\TTWeather.dll] [Tencent, 1.0.0.1]
[C:\Program Files\Tencent\TT\Plugins\WebInfo\WebToolbar.dll] [Tencent, 1.0.0.1]
[C:\Program Files\Rising\Ris\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\Macromed\Flash\Flash10c.ocx] [Adobe Systems, Inc., 10,0,32,18]
[PID: 2272 / Administrator][C:\Program Files\ACD Systems\ACDSee\5.0\ACDSee5.exe] [ACD Systems, Ltd., 5, 0, 1, 6]
[C:\Program Files\Common Files\ACD Systems\EN\ACDAppInfo.dll] [ACD Systems Inc., 3, 0, 0, 9]
[C:\Program Files\Common Files\ACD Systems\EN\ACDInTouch.dll] [ACD Systems Inc., 3, 0, 0, 9]
[C:\Program Files\Common Files\ACD Systems\EN\ipwssl5.dll] [/n software inc. -
www.nsoftware.com, 5.0.0.852]
[C:\Program Files\Common Files\ACD Systems\ShellIntMgr.dll] [ACD Systems Ltd., 1, 0, 2, 24]
[C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159]
[C:\Program Files\Common Files\ACD Systems\EN\ACDCLClient.dll] [ACD SYSTEMS, 1, 0, 0, 6]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38]
[C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[D:\Program Files\360\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[C:\Program Files\Common Files\ACD Systems\PlugIns\IDE_ACDStd.apl] [ACD Systems, Ltd., 1, 3, 6, 6]
[C:\Program Files\Common Files\ACD Systems\IDBSvrps.dll] [ACD Systems Ltd., 1, 0, 0, 23]
[PID: 3236 / Administrator][C:\Program Files\Common Files\ACD Systems\IDBSvr.exe] [ACD Systems Ltd., 1, 0, 3, 3]
[C:\Program Files\Common Files\ACD Systems\ExtDB.dll] [ACD Systems Ltd., 1, 0, 3, 1]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38]
[C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[D:\Program Files\360\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22159]
[C:\Program Files\Common Files\ACD Systems\IDBSvrps.dll] [ACD Systems Ltd., 1, 0, 0, 23]
[PID: 700 / Administrator][F:\33333\sr-engldr.EXE] [Smallfrogs Studio, 2.7.1.1261]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38]
[PID: 2676 / Administrator][F:\33333\SRE5adef2a7.EXE] [Smallfrogs Studio, 2.7.1.1261]
[C:\WINDOWS\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 38]
[C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[D:\Program Files\360\360Safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[F:\33333\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 948, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 892, C:\WINDOWS\SYSTEM32\NVSVC32.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2272, C:\PROGRAM FILES\ACD SYSTEMS\ACDSEE\5.0\ACDSEE5.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3236, C:\PROGRAM FILES\COMMON FILES\ACD SYSTEMS\IDBSVR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 700, F:\33333\SR-ENGLDR.EXE]
==================================
计划任务
N/A
==================================
API HOOK
入口点错误:NtCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003C56F5)
入口点错误:NtCreateKey (危险等级: 高, 被下面模块所HOOK: 0x003C5895)
入口点错误:NtLoadDriver (危险等级: 高, 被下面模块所HOOK: 0x003C5FE5)
入口点错误:NtSetValueKey (危险等级: 高, 被下面模块所HOOK: 0x003C5965)
入口点错误:NtWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003C57C5)
入口点错误:ZwCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003C56F5)
入口点错误:ZwCreateKey (危险等级: 高, 被下面模块所HOOK: 0x003C5895)
入口点错误:ZwSetValueKey (危险等级: 高, 被下面模块所HOOK: 0x003C5965)
入口点错误:ZwWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003C57C5)
入口点错误:CreateServiceA (危险等级: 高, 被下面模块所HOOK: 0x003C5CA5)
入口点错误:CreateServiceW (危险等级: 高, 被下面模块所HOOK: 0x003C5D75)
入口点错误:LoadLibraryA (危险等级: 高, 被下面模块所HOOK: 0x003C69A5)
入口点错误:LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: 0x003C558D)
入口点错误:CreateFileW (危险等级: 高, 被下面模块所HOOK: 0x003C64C5)
入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: 0x003C68D5)
入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: 0x003C6735)
==================================
隐藏进程
N/A
==================================
[/CODE]