[PID: 1080 / SYSTEM][C:\WINNT\system32\regsvc.exe] [(Verified) Microsoft Corporation, 5.00.2195.6701]
[PID: 1276 / SYSTEM][C:\WINNT\system32\MSTask.exe] [(Verified) Microsoft Corporation, 4.71.2195.6972]
[PID: 1340 / SYSTEM][C:\WINNT\System32\snmp.exe] [(Verified) Microsoft Corporation, 5.00.2195.7112]
[PID: 1356 / SYSTEM][C:\WINNT\system32\lserver.exe] [(Verified) Microsoft Corporation, 5.00.2195.6701]
[PID: 1416 / SYSTEM][C:\WINNT\System32\WBEM\WinMgmt.exe] [(Verified) Microsoft Corporation, 1.50.1085.0100]
[PID: 1428 / SYSTEM][C:\WINNT\System32\wins.exe] [(Verified) Microsoft Corporation, 5.00.2195.7155]
[PID: 1452 / SYSTEM][C:\WINNT\system32\Dfssvc.exe] [(Verified) Microsoft Corporation, 5.00.2195.6664]
[PID: 1488 / SYSTEM][C:\WINNT\System32\dns.exe] [(Verified) Microsoft Corporation, 5.00.2195.6715]
[PID: 1536 / SYSTEM][C:\WINNT\system32\inetsrv\inetinfo.exe] [(Verified) Microsoft Corporation, 5.00.0984]
[PID: 1596 / SYSTEM][C:\WINNT\system32\sfmsvc.exe] [(Verified) Microsoft Corporation, 5.00.2195.6684]
[PID: 1676 / SYSTEM][C:\WINNT\system32\msdtc.exe] [(Verified) Microsoft Corporation, 1999.9.3421.3]
[C:\oracle\ora81\bin\ociw32.dll] [Oracle Corporation, 8.1.7.0.0]
[PID: 1996 / SYSTEM][C:\oracle\ora81\Apache\jdk\bin\java.exe] [N/A, ]
[C:\oracle\ora81\Apache\jdk\jre\bin\classic\jvm.dll] [N/A, ]
[C:\oracle\ora81\Apache\jdk\jre\bin\hpi.dll] [N/A, ]
[C:\oracle\ora81\Apache\jdk\jre\bin\java.dll] [N/A, ]
[C:\oracle\ora81\Apache\jdk\jre\bin\zip.dll] [N/A, ]
[C:\oracle\ora81\Apache\jdk\jre\bin\symcjit.dll] [Symantec Corporation
http://www.symantec.com, 3.10.107]
[C:\oracle\ora81\Apache\jdk\jre\bin\net.dll] [N/A, ]
[PID: 2008 / SYSTEM][C:\oracle\ora81\Apache\Apache\Apache.exe] [N/A, ]
[C:\oracle\ora81\Apache\Apache\ApacheCore.dll] [N/A, ]
[c:\oracle\ora81\apache\apache\modules\ApacheModuleMimeMagic.dll] [N/A, ]
[c:\oracle\ora81\apache\apache\modules\ApacheModuleAuthAnon.dll] [N/A, ]
[c:\oracle\ora81\apache\apache\modules\ApacheModuleCERNMeta.dll] [N/A, ]
[c:\oracle\ora81\apache\apache\modules\ApacheModuleDigest.dll] [N/A, ]
[c:\oracle\ora81\apache\apache\modules\ApacheModuleExpires.dll] [N/A, ]
[c:\oracle\ora81\apache\apache\modules\ApacheModuleHeaders.dll] [N/A, ]
[c:\oracle\ora81\apache\apache\modules\ApacheModuleProxy.dll] [N/A, ]
[c:\oracle\ora81\apache\apache\modules\ApacheModuleRewrite.dll] [N/A, ]
[c:\oracle\ora81\apache\apache\modules\ApacheModuleSpeling.dll] [N/A, ]
[c:\oracle\ora81\apache\apache\modules\ApacheModuleStatus.dll] [N/A, ]
[c:\oracle\ora81\apache\apache\modules\ApacheModuleUserTrack.dll] [N/A, ]
[c:\oracle\ora81\apache\apache\modules\ApacheModulePerl.DLL] [N/A, ]
[C:\oracle\ora81\Apache\Perl\5.00503\bin\mswin32-x86\Perl.dll] [N/A, ]
[c:\oracle\ora81\apache\apache\modules\ApacheModuleSSL.DLL] [N/A, ]
[C:\oracle\ora81\Apache\Jserv\ApacheModuleJServ.dll] [N/A, ]
[c:\oracle\ora81\apache\apache\modules\orajipa8i.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\oran8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\oranl8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\oranldap8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\orannzsbb8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\oracore8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\oranls8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\orageneric8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\oracommon8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\oraclient8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\oravsn8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\orawtc8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\oranro8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\orapls8.dll] [Oracle Corporation, 8]
[C:\oracle\ora81\bin\oraslax8.dll] [Oracle Corporation, 8]
[C:\oracle\ora81\bin\orasql8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\oraldapclnt8.dll] [Oracle Corporation, 8.1.5.0.0]
[C:\oracle\ora81\bin\ORATRACE8.dll] [N/A, ]
[C:\oracle\ora81\bin\orancrypt8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\oranhost8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\oranoname8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\orancds8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\orantns8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\orannds8.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\oranms.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\oranmsp.dll] [Oracle Corporation, 8.1.7.0.0]
[C:\oracle\ora81\bin\modplsql.dll] [N/A, ]
[C:\oracle\ora81\bin\OCI.dll] [Oracle Corporation, 8.1.7.0.0]
[PID: 464 / SYSTEM][\??\C:\WINNT\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.00.2195.6601]
[PID: 1504 / SYSTEM][\??\C:\WINNT\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.00.2195.6997]
[PID: 1092 / SYSTEM][\??\C:\WINNT\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.00.2195.6601]
[PID: 2352 / SYSTEM][\??\C:\WINNT\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.00.2195.6997]
[PID: 2656 / SYSTEM][C:\WINNT\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\nap32.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 1]
[PID: 2692 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 1044 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2420 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 1268 / Administrator][C:\WINNT\system32\conime.exe] [(Verified) Microsoft Corporation, 5.00.2195.6655]
[PID: 1400 / Administrator][C:\WINNT\Explorer.EXE] [(Verified) Microsoft Corporation, 5.00.3700.6690]
[C:\Program Files\360\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.77]
[C:\WINNT\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINNT\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\WINNT\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12]
[PID: 2640 / Administrator][C:\WINNT\system32\internat.exe] [(Verified) Microsoft Corporation, 5.00.2920.0000]
[PID: 348 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 1016 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2624 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2376 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2676 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2852 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2844 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2560 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 160 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2464 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 1924 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2920 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2596 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 1220 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2408 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2380 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2412 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 388 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3012 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2628 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3068 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2564 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2976 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2988 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2860 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3040 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2832 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3044 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2908 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2896 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2356 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3056 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2372 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2404 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3000 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2884 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2956 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2392 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2972 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 1256 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2980 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 524 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2872 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2992 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2984 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3084 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3080 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3092 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3124 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3108 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3032 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3024 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3096 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3100 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3172 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2900 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3132 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3196 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3136 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3208 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3148 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3156 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3152 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3076 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3256 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3220 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3240 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3268 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3244 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 1248 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3288 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3104 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3308 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3276 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 820 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3228 / SYSTEM][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 3348 / Administrator][C:\WINNT\system32\mdm.exe] [Microsoft Corporation, 6.00.8424]
[C:\Program Files\360\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[PID: 3392 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 5.00.2920.0000]
[C:\Program Files\360\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.77]
[C:\WINNT\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINNT\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 3376 / Administrator][D:\sreng2[1].8.1.1279版\sr-engldr.EXE] [Smallfrogs Studio, 2.8.1.1279]
[PID: 3316 / Administrator][D:\sreng2[1].8.1.1279版\SREa9ec57a5.EXE] [Smallfrogs Studio, 2.8.1.1279]
[C:\Program Files\360\360safe\safemon\safemon.dll] [360.CN, 5, 0, 0, 1021]
[D:\sreng2[1].8.1.1279版\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 764, C:\ORACLE\ORA81\BIN\DBSNMP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 888, C:\ORACLE\ORA81\BIN\VPPDC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 900, C:\ORACLE\ORA81\APACHE\APACHE\APACHE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 956, C:\ORACLE\ORA81\BIN\TNSLSNR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1008, C:\ORACLE\ORA81\BIN\ORACLE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1996, C:\ORACLE\ORA81\APACHE\JDK\BIN\JAVA.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2008, C:\ORACLE\ORA81\APACHE\APACHE\APACHE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3376, D:\SRENG2[1].8.1.1279版\SR-ENGLDR.EXE]