[CODE] 2009-03-14,19:27:02 System Repair Engineer 2.7.0.1210 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Google Inc] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [File is missing] <"d:\我的文档\桌面\Rising\Rav\RsTray.exe" -system> [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] [] [] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AEB6717E-7E19-11d0-97EE-00C04FD91972}> [(Verified)Microsoft Windows Component Publisher] <{FA9B58AA-6759-4C02-B37F-572FC2F1A231}> [N/A] <{91C7DF6D-AEF5-4136-9252-AF030D7A5931}> [File is missing] <{56BC86C7-0692-4F94-A2C1-6CF1DBF8096C}><56BC86C7.dll> [N/A] <{F65BDEC7-4BF3-4512-840F-68B166B6D7AC}> [] <{76B9BA7A-81D0-4979-8598-8471F2AB5186}><76B9BA7A.dll> [N/A] <{201476D0-2B18-462E-AB9F-3E2B0CC8732B}> [File is missing] <{695C5A80-18A5-4CD2-A911-4DBEBE92F18D}> [File is missing] <{7E94C114-C874-4112-9922-054D8E5546E2}> [File is missing] <{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8}> [N/A] <{E4814792-EFA3-4C20-93D0-8B130A59F9A8}> [] <{C7029C5D-96D1-4FA4-A441-822BFB230785}> [] <{1957817A-94B2-4CAC-B113-A331809B5730}><1957817A.dll> [] <{DDFDCED2-075A-4910-986E-B2BDA2B0E916}> [] <{704C3595-DB85-40F6-A601-8D6F346907BD}> [File is missing] <{CC80F0B4-04D7-44D0-8DB9-9109B5B72141}> [File is missing] <{08CBFE20-8DC8-4195-B8E2-DD66F860469D}> [File is missing] <{36B53F22-B8DB-4177-AD3A-BE9E8E915A70}> [File is missing] <{41D71686-1E31-455F-AF11-DBB30101CC3B}> [File is missing] <{ADBFEEB3-18CD-4B0C-A839-FD1C5531E62A}> [] <{5BB96341-365F-4C1B-8E77-15900BE47DE5}> [File is missing] <{E388D9F2-919B-412A-BB5B-CBDEB8CE4729}> [File is missing] <{616E233C-DA80-4FA5-A035-82E206EB3120}> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [File is missing] [File is missing] [File is missing] [File is missing] [File is missing] [File is missing] <36B53F22> [File is missing] <41D71686> [File is missing] [] <5BB96341> [File is missing] [File is missing] <616E233C> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <浏览器自定义组件> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] <%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Publisher] [HKEY_CURRENT_USER\Control Panel\Desktop] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [File is missing] <; > [N/A] <; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [File is missing] ================================== 启动文件夹 N/A ================================== 服务 [3ware Controller Service / 3wareSrv][Stopped/Auto Start] [Contrl Center of Storm Media / ccosm][Running/Auto Start] <北京暴风网际科技有限公司> [Help and Support / helpsvc][Stopped/Disabled] %WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll> [Human Interface Device Access / HidServ][Stopped/Boot Start] <\SystemRoot\C:\windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll> [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start] <><(File is missing)> [Rav Process Communication Center / RavCCenter][Stopped/Auto Start] [Rising RavTask Manager / RavTask][Running/Auto Start] <"d:\我的文档\桌面\Rising\Rav\RavTask.exe" RavTask> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] [Rising Scan Service / RsScanSrv][Stopped/Auto Start] ================================== 驱动程序 [aeaudio / aeaudio][Running/Manual Start] [aliimz / aliimz][Stopped/Manual Start] [Promise driver accelerator / bb-run][Running/Boot Start] <\SystemRoot\system32\DRIVERS\bb-run.sys> [Dritek Keyboard Filter Driver / DKbFltr][Running/Manual Start] [Promise Removable Disk Control Driver / dontgo][Running/Boot Start] <\SystemRoot\system32\DRIVERS\DontGo.sys> [GanDiao / GanDiao][Stopped/Manual Start] <\??\C:\windows\system32\drivers\GanDiao.sys> [hookcont / hookcont][Running/System Start] [hooksys / hooksys][Stopped/Disabled] [ialm / ialm][Running/Manual Start] [Service for NVIDIA(R) nForce(TM) MIDI UART / nvmpu401][Running/Manual Start] [NVIDIA nForce RAID Driver / nvrd32][Running/Boot Start] <\SystemRoot\system32\DRIVERS\nvrd32.sys> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Running/Manual Start] [Secdrv / Secdrv][Stopped/Manual Start] [SATALink External Device Filter / SiRemFil][Running/Boot Start] <\SystemRoot\system32\DRIVERS\SiRemFil.sys> [smwdm / smwdm][Running/Manual Start] [System Restore Filter Driver / sr][Stopped/Disabled] [TCP/IP Protocol Driver / Tcpip][Running/System Start] [ViBus / ViBus][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\ViBus.sys> [wmpobj / wmpobj][Running/Auto Start] <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Media Player\obj\wmpobj.sys> [VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start] <\SystemRoot\system32\DRIVERS\xfilt.sys> [VIMICRO USB PC Camera (ZC0301PLH) / ZSMC303][Running/Manual Start] ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [] {08CBFE20-8DC8-4195-B8E2-DD66F860469D} [CAdLogic Object] {11F09AFD-75AD-4E51-AB43-E09E9351CE16} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [Google Toolbar Helper] {AA58ED58-01DD-4d91-8333-CF10577473F7} [Google Toolbar Notifier BHO] {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [&Google] {2318C2B1-4965-11d4-9B18-009027A5CD4F} [ChinaExcelWeb Control] {15261F9B-22CC-4692-9089-0C40ACBDFDD8} [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [] {08CBFE20-8DC8-4195-B8E2-DD66F860469D} [CAdLogic Object] {11F09AFD-75AD-4E51-AB43-E09E9351CE16} [&Google] {2318C2B1-4965-11D4-9B18-009027A5CD4F} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [Microsoft Web 浏览器] {8856F961-340A-11D0-A96B-00C04FD705A2} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [Google Toolbar Helper] {AA58ED58-01DD-4D91-8333-CF10577473F7} [Google Toolbar Notifier BHO] {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] ================================== 正在运行的进程 [PID: 596 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 676 / SYSTEM][\??\C:\windows\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 700 / SYSTEM][\??\C:\windows\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\adbfeebj.dll] [N/A, ] [C:\windows\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\vioFly32.dll] [N/A, ] [PID: 744 / SYSTEM][C:\windows\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\adbfeebj.dll] [N/A, ] [PID: 756 / SYSTEM][C:\windows\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\adbfeebj.dll] [N/A, ] [PID: 904 / SYSTEM][C:\windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\adbfeebj.dll] [N/A, ] [PID: 984 / NETWORK SERVICE][C:\windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\adbfeebj.dll] [N/A, ] [PID: 1104 / SYSTEM][d:\我的文档\桌面\Rising\Rav\CCENTER.EXE] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [d:\我的文档\桌面\Rising\Rav\combase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [C:\windows\system32\adbfeebj.dll] [N/A, ] [d:\我的文档\桌面\Rising\Rav\cnt09.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 37] [d:\我的文档\桌面\Rising\Rav\cnt08.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7] [C:\windows\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1112 / SYSTEM][C:\windows\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\System32\adbfeebj.dll] [N/A, ] [PID: 1220 / NETWORK SERVICE][C:\windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\adbfeebj.dll] [N/A, ] [PID: 1312 / LOCAL SERVICE][C:\windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\adbfeebj.dll] [N/A, ] [PID: 1444 / SYSTEM][d:\我的文档\桌面\Rising\Rav\RavMonD.exe] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [d:\我的文档\桌面\Rising\Rav\combase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [C:\windows\system32\adbfeebj.dll] [N/A, ] [C:\windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [d:\我的文档\桌面\Rising\Rav\moncomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [d:\我的文档\桌面\Rising\Rav\MonBase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 6] [d:\我的文档\桌面\Rising\Rav\Rslog.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.34] [d:\我的文档\桌面\Rising\Rav\mondrv.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 8] [d:\我的文档\桌面\Rising\Rav\defmon.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 30] [d:\我的文档\桌面\Rising\Rav\moncom08.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [d:\我的文档\桌面\Rising\Rav\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 9] [d:\我的文档\桌面\Rising\Rav\FileMon.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 22] [d:\我的文档\桌面\Rising\Rav\MailMon.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 24] [d:\我的文档\桌面\Rising\Rav\HookWeb.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [d:\我的文档\桌面\Rising\Rav\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [d:\我的文档\桌面\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [d:\我的文档\桌面\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.18] [d:\我的文档\桌面\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [d:\我的文档\桌面\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [d:\我的文档\桌面\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [d:\我的文档\桌面\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [d:\我的文档\桌面\Rising\Rav\HookCont.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 12] [d:\我的文档\桌面\Rising\Rav\rsnetsvr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 13] [d:\我的文档\桌面\Rising\Rav\ScanAdd.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.15] [d:\我的文档\桌面\Rising\Rav\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.33] [C:\windows\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [d:\我的文档\桌面\Rising\Rav\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [d:\我的文档\桌面\Rising\Rav\refs.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [d:\我的文档\桌面\Rising\Rav\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [d:\我的文档\桌面\Rising\Rav\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [PID: 1512 / Administrator][C:\windows\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)] [C:\windows\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\adbfeebj.dll] [N/A, ] [C:\windows\system32\F65BDEC7.dll] [N/A, ] [C:\windows\system32\E4814792.dll] [N/A, ] [C:\windows\system32\C7029C5D.dll] [N/A, ] [C:\windows\system32\1957817A.dll] [N/A, ] [C:\windows\system32\rBWN2dra.dll] [N/A, ] [C:\windows\system32\dopdy.dll] [, 4.3.5.0] [C:\windows\system32\vioFly32.dll] [N/A, ] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\windows\system32\browselc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [PID: 1572 / SYSTEM][C:\windows\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\windows\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\adbfeebj.dll] [N/A, ] [PID: 1860 / SYSTEM][d:\我的文档\桌面\Rising\Rav\rsnetsvr.exe] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 14] [d:\我的文档\桌面\Rising\Rav\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.9] [d:\我的文档\桌面\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\windows\system32\adbfeebj.dll] [N/A, ] [d:\我的文档\桌面\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [d:\我的文档\桌面\Rising\Rav\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [C:\windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\windows\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1868 / Administrator][C:\WINDOWS\VM303_STI.EXE] [Vimicro, 3, 5, 1216, 10] [C:\windows\system32\adbfeebj.dll] [N/A, ] [C:\windows\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\msdmo.dll] [, ] [C:\windows\system32\VM303Prp.Ax] [Vimicro, 3.5.1118. 9] [PID: 1892 / Administrator][D:\我的文档\桌面\Rising\Rav\RsTray.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.22] [C:\windows\system32\adbfeebj.dll] [N/A, ] [C:\windows\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [D:\我的文档\桌面\Rising\Rav\ComServ.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.49] [C:\windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [D:\我的文档\桌面\Rising\Rav\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 28] [D:\我的文档\桌面\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [D:\我的文档\桌面\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [D:\我的文档\桌面\Rising\Rav\rsxml.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [D:\我的文档\桌面\Rising\Rav\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [D:\我的文档\桌面\Rising\Rav\MonState.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7] [D:\我的文档\桌面\Rising\Rav\ScanEvnt.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.12] [D:\我的文档\桌面\Rising\Rav\rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 70] [C:\windows\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [D:\我的文档\桌面\Rising\Rav\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [D:\我的文档\桌面\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [D:\我的文档\桌面\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.18] [D:\我的文档\桌面\Rising\Rav\rspalvd.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.21] [D:\我的文档\桌面\Rising\Rav\ravbintl.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 26] [D:\我的文档\桌面\Rising\Rav\mruleui.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 10] [D:\我的文档\桌面\Rising\Rav\MonTray.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.93] [C:\windows\system32\dopdy.dll] [, 4.3.5.0] [D:\我的文档\桌面\Rising\Rav\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [D:\我的文档\桌面\Rising\Rav\RavITray.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 19] [D:\我的文档\桌面\Rising\Rav\ScanPrxy.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.15] [D:\我的文档\桌面\Rising\Rav\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [PID: 1904 / Administrator][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654] [C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\gtn.dll] [Google Inc., 3, 1, 807, 1746] [C:\windows\system32\adbfeebj.dll] [N/A, ] [C:\windows\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll] [Google Inc., 3, 1, 807, 1746] [C:\windows\system32\dopdy.dll] [, 4.3.5.0] [PID: 2044 / LOCAL SERVICE][C:\windows\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\System32\adbfeebj.dll] [N/A, ] [PID: 176 / SYSTEM][C:\Program Files\StormII\stormliv.exe] [北京暴风网际科技有限公司, 3, 7, 11, 16] [C:\windows\system32\adbfeebj.dll] [N/A, ] [C:\windows\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 196 / Administrator][d:\我的文档\桌面\Rising\Rav\RsMain.exe] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5] [C:\windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\windows\system32\adbfeebj.dll] [N/A, ] [C:\windows\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [d:\我的文档\桌面\Rising\Rav\rspalmgr.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.29] [d:\我的文档\桌面\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [d:\我的文档\桌面\Rising\Rav\RSXML.DLL] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [C:\windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [d:\我的文档\桌面\Rising\Rav\RsGuiLib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 70] [C:\windows\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [d:\我的文档\桌面\Rising\Rav\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 28] [d:\我的文档\桌面\Rising\Rav\ravbmenu.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 16] [d:\我的文档\桌面\Rising\Rav\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [d:\我的文档\桌面\Rising\Rav\rspalvd.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.21] [d:\我的文档\桌面\Rising\Rav\ravppops.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [d:\我的文档\桌面\Rising\Rav\ravbintl.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 26] [d:\我的文档\桌面\Rising\Rav\ravpsafe.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.24] [d:\我的文档\桌面\Rising\Rav\MonState.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7] [d:\我的文档\桌面\Rising\Rav\ScanPrxy.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.15] [d:\我的文档\桌面\Rising\Rav\psafecfg.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.19] [d:\我的文档\桌面\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [d:\我的文档\桌面\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.18] [C:\windows\system32\F65BDEC7.dll] [N/A, ] [C:\windows\system32\E4814792.dll] [N/A, ] [C:\windows\system32\C7029C5D.dll] [N/A, ] [C:\windows\system32\1957817A.dll] [N/A, ] [C:\windows\system32\rBWN2dra.dll] [N/A, ] [d:\我的文档\桌面\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [d:\我的文档\桌面\Rising\Rav\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [d:\我的文档\桌面\Rising\Rav\ravxpage.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 82] [d:\我的文档\桌面\Rising\Rav\ravxmons.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 24] [d:\我的文档\桌面\Rising\Rav\ravptool.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.20] [d:\我的文档\桌面\Rising\Rav\log2file.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.5] [C:\windows\system32\dopdy.dll] [, 4.3.5.0] [d:\我的文档\桌面\Rising\Rav\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [d:\我的文档\桌面\Rising\Rav\htmllib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [d:\我的文档\桌面\Rising\Rav\rsvrinfo.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5] [d:\我的文档\桌面\Rising\Rav\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [d:\我的文档\桌面\Rising\Rav\refs.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [d:\我的文档\桌面\Rising\Rav\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [d:\我的文档\桌面\Rising\Rav\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [PID: 264 / SYSTEM][d:\我的文档\桌面\Rising\Rav\RavTask.exe] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 23] [C:\windows\system32\adbfeebj.dll] [N/A, ] [d:\我的文档\桌面\Rising\Rav\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [d:\我的文档\桌面\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [d:\我的文档\桌面\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.18] [d:\我的文档\桌面\Rising\Rav\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [C:\windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [d:\我的文档\桌面\Rising\Rav\rsstub.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [C:\windows\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [d:\我的文档\桌面\Rising\Rav\rstask.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 36] [PID: 328 / SYSTEM][d:\我的文档\桌面\Rising\Rav\ScanFrm.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.11] [C:\windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\windows\system32\adbfeebj.dll] [N/A, ] [d:\我的文档\桌面\Rising\Rav\combase.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [d:\我的文档\桌面\Rising\Rav\moncomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [d:\我的文档\桌面\Rising\Rav\scansrvp.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.11] [d:\我的文档\桌面\Rising\Rav\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [d:\我的文档\桌面\Rising\Rav\ScanSrv.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.9] [d:\我的文档\桌面\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [d:\我的文档\桌面\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\windows\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [d:\我的文档\桌面\Rising\Rav\ScanRavT.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.23] [d:\我的文档\桌面\Rising\Rav\ScanBT.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.39] [d:\我的文档\桌面\Rising\Rav\ScanStub.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.8] [d:\我的文档\桌面\Rising\Rav\RsLog.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.34] [d:\我的文档\桌面\Rising\Rav\ScanAdd.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.15] [d:\我的文档\桌面\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.1] [d:\我的文档\桌面\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.18] [d:\我的文档\桌面\Rising\Rav\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.33] [d:\我的文档\桌面\Rising\Rav\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [d:\我的文档\桌面\Rising\Rav\refs.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [d:\我的文档\桌面\Rising\Rav\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [d:\我的文档\桌面\Rising\Rav\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [d:\我的文档\桌面\Rising\Rav\mvengine.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [d:\我的文档\桌面\Rising\Rav\SysMail.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.5] [d:\我的文档\桌面\Rising\Rav\posttrt.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [d:\我的文档\桌面\Rising\Rav\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [d:\我的文档\桌面\Rising\Rav\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [d:\我的文档\桌面\Rising\Rav\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5] [d:\我的文档\桌面\Rising\Rav\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [d:\我的文档\桌面\Rising\Rav\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 24] [d:\我的文档\桌面\Rising\Rav\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [d:\我的文档\桌面\Rising\Rav\scanpe.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7] [d:\我的文档\桌面\Rising\Rav\ur000.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 8] [d:\我的文档\桌面\Rising\Rav\urutils.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [d:\我的文档\桌面\Rising\Rav\revm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2] [d:\我的文档\桌面\Rising\Rav\ur001.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 7] [d:\我的文档\桌面\Rising\Rav\extfile.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 13] [d:\我的文档\桌面\Rising\Rav\extole.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [d:\我的文档\桌面\Rising\Rav\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [d:\我的文档\桌面\Rising\Rav\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3] [d:\我的文档\桌面\Rising\Rav\scriptci.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [d:\我的文档\桌面\Rising\Rav\uroutine.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [d:\我的文档\桌面\Rising\Rav\ur023.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [d:\我的文档\桌面\Rising\Rav\ur024.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [d:\我的文档\桌面\Rising\Rav\ur025.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [d:\我的文档\桌面\Rising\Rav\scanmac.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4] [d:\我的文档\桌面\Rising\Rav\ur004.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [d:\我的文档\桌面\Rising\Rav\ur014.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [d:\我的文档\桌面\Rising\Rav\ur027.dat] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 5] [d:\我的文档\桌面\Rising\Rav\rsstore.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 9] [d:\我的文档\桌面\Rising\Rav\scanelf.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 1] [PID: 336 / SYSTEM][C:\windows\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\adbfeebj.dll] [N/A, ] [PID: 396 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)] [C:\WINDOWS\system32\adbfeebj.dll] [N/A, ] [PID: 1460 / Administrator][d:\我的文档\桌面\Rising\Rav\RsAgent.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.17] [C:\windows\system32\adbfeebj.dll] [N/A, ] [C:\windows\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\dopdy.dll] [, 4.3.5.0] [d:\我的文档\桌面\Rising\Rav\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [C:\windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [d:\我的文档\桌面\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [d:\我的文档\桌面\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [d:\我的文档\桌面\Rising\Rav\ScanPrxy.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.15] [C:\windows\msagent\AgentMPx.dll] [Microsoft Corporation, 2.00.0.2115] [PID: 1084 / Administrator][C:\windows\msagent\AgentSvr.exe] [Microsoft Corporation, 2.00.0.2202] [C:\windows\system32\adbfeebj.dll] [N/A, ] [C:\windows\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\dopdy.dll] [, 4.3.5.0] [C:\windows\msagent\AgentDP2.dll] [Microsoft Corporation, 2.00.0.2115] [PID: 4044 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\adbfeebj.dll] [N/A, ] [C:\windows\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\dopdy.dll] [, 4.3.5.0] [C:\windows\system32\browselc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [c:\program files\google\googletoolbar1.dll] [Google Inc., 4, 0, 1306, 3130] [C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.16] [C:\Program Files\Common Files\PushWare\cpush.dll] [, 1.1.2.8] [C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 44] [C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll] [Google Inc., 3, 1, 807, 1746] [C:\windows\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [d:\我的文档\桌面\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.62] [C:\windows\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\windows\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx] [Adobe Systems, Inc., 9,0,115,0] [C:\windows\system32\F65BDEC7.dll] [N/A, ] [C:\windows\system32\E4814792.dll] [N/A, ] [C:\windows\system32\C7029C5D.dll] [N/A, ] [C:\windows\system32\1957817A.dll] [N/A, ] [C:\windows\system32\rBWN2dra.dll] [N/A, ] [PID: 2704 / Administrator][d:\我的文档\桌面\123.com.EXE] [Smallfrogs Studio, 2.7.0.1210] [C:\windows\system32\adbfeebj.dll] [N/A, ] [PID: 2556 / Administrator][d:\我的文档\桌面\SREa2239101.EXE] [Smallfrogs Studio, 2.7.0.1210] [C:\windows\system32\adbfeebj.dll] [N/A, ] [C:\windows\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\windows\system32\dopdy.dll] [, 4.3.5.0] [d:\我的文档\桌面\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] ================================== 文件关联 .TXT Error. [C:\windows\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [C:\windows\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 60.173.10.243 www.sznews.com 60.173.10.243 www.idoer.org 60.173.10.243 soso.com 60.173.10.243 www.soso.com 60.173.10.243 wenwen.soso.com 60.173.10.243 www.lhgz.com.cn 60.173.10.243 qq123.d189.5kweb.cn 60.173.10.243 www.taxexpert.com.cn 60.173.10.243 web.szds.gov.cn 60.173.10.243 www.szgs.gov.cn 60.173.10.243 www.szds.gov.cn 60.173.10.243 www.qz315.cn 60.173.10.243 www.315safe.com 60.173.10.243 www.315.gov.cn 60.173.10.243 www.315wm.com 60.173.10.243 www.ca315.com.cn 60.173.10.243 www.315ts.net 60.173.10.243 szgz.gov.cn 60.173.10.243 www.szgz.gov.cn 127.0.0.1 localhost ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 700, C:\WINDOWS\SYSTEM32\WINLOGON.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 1084, C:\WINDOWS\MSAGENT\AGENTSVR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1084, C:\WINDOWS\MSAGENT\AGENTSVR.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 2704, D:\我的文档\桌面\123.COM.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2704, D:\我的文档\桌面\123.COM.EXE] ================================== 计划任务 N/A ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]