[CODE] 2012-12-23,10:57:21 System Repair Engineer 2.8.2.1321 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 Windows 安全更新检查 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [Microsoft Corporation] <"D:\Program Files\Foxmail 7.0\Foxmail.exe" -min> [(Verified)Tencent Technology(Shenzhen) Company Limited] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <"C:\Program Files\Rising\AntiSpyware\rstray.exe" /startup> [(Verified)Beijing Rising Information Technology Corporation Limited] <%systemroot%\system32\dumprep 0 -k> [File is missing] <"C:\Program Files\Rising\Rav\RSTRAY.EXE" -system> [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [Microsoft Corporation] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AEB6717E-7E19-11d0-97EE-00C04FD91972}> [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <%SystemRoot%\system32\SHELL32.dll> [Microsoft Corporation] <%SystemRoot%\system32\SHELL32.dll> [Microsoft Corporation] <%SystemRoot%\system32\webcheck.dll> [Microsoft Corporation] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy] <%SystemRoot%\System32\dimsntfy.dll> [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] [Intel Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [Microsoft Corporation] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <浏览器自定义组件> [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] <%SystemRoot%\system32\ie4uinit.exe> [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] [(Verified)Microsoft Corporation] ================================== 启动文件夹 N/A ================================== 服务 [Application Layer Gateway Service / ALG][Stopped/Disabled] [Application Management / AppMgmt][Stopped/Manual Start] %SystemRoot%\System32\appmgmts.dll> [Windows Audio / AudioSrv][Running/Auto Start] %SystemRoot%\System32\audiosrv.dll> [Background Intelligent Transfer Service / BITS][Stopped/Disabled] C:\WINDOWS\system32\qmgr.dll> [Computer Browser / Browser][Stopped/Disabled] %SystemRoot%\System32\browser.dll> [ClipBook / ClipSrv][Stopped/Disabled] [COM+ System Application / COMSysApp][Stopped/Manual Start] [Cryptographic Services / CryptSvc][Running/Auto Start] %SystemRoot%\System32\cryptsvc.dll> [DCOM Server Process Launcher / DcomLaunch][Running/Auto Start] %SystemRoot%\system32\rpcss.dll> [DHCP Client / Dhcp][Running/Auto Start] %SystemRoot%\System32\dhcpcsvc.dll> [Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start] [Logical Disk Manager / dmserver][Running/Auto Start] %SystemRoot%\System32\dmserver.dll> [DNS Client / Dnscache][Stopped/Manual Start] %SystemRoot%\System32\dnsrslvr.dll> [Wired AutoConfig / Dot3svc][Stopped/Manual Start] %SystemRoot%\System32\dot3svc.dll> [Extensible Authentication Protocol Service / EapHost][Stopped/Manual Start] %SystemRoot%\System32\eapsvc.dll> [Event Log / Eventlog][Running/Auto Start] [COM+ Event System / EventSystem][Running/Manual Start] C:\WINDOWS\system32\es.dll> [Fast User Switching Compatibility / FastUserSwitchingCompatibility][Stopped/Manual Start] %SystemRoot%\System32\shsvcs.dll> [HID Input Service / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [Health Key and Certificate Management Service / hkmsvc][Stopped/Manual Start] %SystemRoot%\System32\kmsvc.dll> [HTTP SSL / HTTPFilter][Stopped/Manual Start] %SystemRoot%\System32\w3ssl.dll> [InstallDriver Table Manager / IDriverT][Stopped/Manual Start] <"C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"> [IMAPI CD-Burning COM Service / ImapiService][Stopped/Auto Start] [Server / LanmanServer][Running/Auto Start] %SystemRoot%\System32\srvsvc.dll> [Workstation / lanmanworkstation][Running/Auto Start] %SystemRoot%\System32\wkssvc.dll> [TCP/IP NetBIOS Helper / LmHosts][Stopped/Disabled] %SystemRoot%\System32\lmhsvc.dll> [Messenger / Messenger][Stopped/Disabled] %SystemRoot%\System32\msgsvc.dll> [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Disabled] <><(File is missing)> [Distributed Transaction Coordinator / MSDTC][Stopped/Disabled] [Windows Installer / MSIServer][Stopped/Manual Start] [Network Access Protection Agent / napagent][Stopped/Manual Start] %SystemRoot%\System32\qagentrt.dll> [Network DDE / NetDDE][Stopped/Disabled] [Network DDE DSDM / NetDDEdsdm][Stopped/Disabled] [Net Logon / Netlogon][Stopped/Disabled] [Network Connections / Netman][Running/Manual Start] %SystemRoot%\System32\netman.dll> [Network Location Awareness (NLA) / Nla][Stopped/Disabled] %SystemRoot%\System32\mswsock.dll> [NT LM Security Support Provider / NtLmSsp][Stopped/Disabled] [Plug and Play / PlugPlay][Running/Auto Start] [IPSEC Services / PolicyAgent][Stopped/Manual Start] [Protected Storage / ProtectedStorage][Running/Auto Start] [Remote Access Auto Connection Manager / RasAuto][Stopped/Manual Start] %SystemRoot%\System32\rasauto.dll> [Remote Access Connection Manager / RasMan][Running/Manual Start] %SystemRoot%\System32\rasmans.dll> [Remote Desktop Help Session Manager / RDSessMgr][Stopped/Disabled] [Routing and Remote Access / RemoteAccess][Stopped/Disabled] %SystemRoot%\System32\mprdim.dll> [Remote Registry / RemoteRegistry][Stopped/Disabled] %SystemRoot%\system32\regsvc.dll> [Remote Procedure Call (RPC) Locator / RpcLocator][Stopped/Disabled] [Remote Procedure Call (RPC) / RpcSs][Running/Auto Start] %SystemRoot%\system32\rpcss.dll> [Rsd Service / RsMgrSvc][Running/Auto Start] <"C:\Program Files\Rising\RSD\RsMgrSvc.exe"> [Rav Service / RsRavMon][Running/Auto Start] <"C:\Program Files\Rising\Rav\RavMonD.exe"> [QoS RSVP / RSVP][Stopped/Disabled] [Security Accounts Manager / SamSs][Running/Auto Start] [Smart Card / SCardSvr][Stopped/Disabled] [Task Scheduler / Schedule][Stopped/Disabled] %SystemRoot%\system32\schedsvc.dll> [Secondary Logon / seclogon][Running/Auto Start] %SystemRoot%\System32\seclogon.dll> [System Event Notification / SENS][Running/Auto Start] %SystemRoot%\system32\sens.dll> [Windows Firewall/Internet Connection Sharing (ICS) / SharedAccess][Stopped/Manual Start] %SystemRoot%\System32\ipnathlp.dll> [Shell Hardware Detection / ShellHWDetection][Running/Auto Start] %SystemRoot%\System32\shsvcs.dll> [Print Spooler / Spooler][Running/Auto Start] [SSDP Discovery Service / SSDPSRV][Stopped/Disabled] %SystemRoot%\System32\ssdpsrv.dll> [Windows Image Acquisition (WIA) / stisvc][Running/Manual Start] %SystemRoot%\system32\wiaservc.dll> [MS Software Shadow Copy Provider / SwPrv][Stopped/Disabled] [Performance Logs and Alerts / SysmonLog][Stopped/Disabled] [Telephony / TapiSrv][Running/Manual Start] %SystemRoot%\System32\tapisrv.dll> [Terminal Services / TermService][Running/Manual Start] %SystemRoot%\System32\termsrv.dll> [Themes / Themes][Running/Auto Start] %SystemRoot%\System32\shsvcs.dll> [Telnet / TlntSvr][Stopped/Disabled] [Distributed Link Tracking Client / TrkWks][Stopped/Disabled] %SystemRoot%\system32\trkwks.dll> [Windows User Mode Driver Framework / UMWdf][Stopped/Manual Start] [Universal Plug and Play Device Host / upnphost][Stopped/Manual Start] %SystemRoot%\System32\upnphost.dll> [Volume Shadow Copy / VSS][Stopped/Disabled] [Windows Time / W32Time][Stopped/Disabled] C:\WINDOWS\system32\w32time.dll> [WebClient / WebClient][Stopped/Disabled] %SystemRoot%\System32\webclnt.dll> [Windows Management Instrumentation / winmgmt][Running/Auto Start] %SystemRoot%\system32\wbem\WMIsvc.dll> [Portable Media Serial Number Service / WmdmPmSN][Stopped/Disabled] C:\WINDOWS\system32\mspmsnsv.dll> [Windows Management Instrumentation Driver Extensions / Wmi][Stopped/Manual Start] %SystemRoot%\System32\advapi32.dll> [WMI Performance Adapter / WmiApSrv][Stopped/Disabled] [Security Center / wscsvc][Stopped/Disabled] %SYSTEMROOT%\system32\wscsvc.dll> [Wireless Zero Configuration / WZCSVC][Stopped/Disabled] %SystemRoot%\System32\wzcsvc.dll> [Network Provisioning Service / xmlprov][Stopped/Manual Start] %SystemRoot%\System32\xmlprov.dll> ================================== 驱动程序 [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start] [Microsoft ACPI Driver / ACPI][Running/Boot Start] <\SystemRoot\system32\DRIVERS\ACPI.sys> [Microsoft Embedded Controller Driver / ACPIEC][Running/Boot Start] <\SystemRoot\System32\DRIVERS\ACPIEC.sys> [Microsoft Kernel Acoustic Echo Canceller / aec][Stopped/Manual Start] [AFD / AFD][Running/System Start] <\SystemRoot\System32\drivers\afd.sys> [Intel AGP Bus Filter / agp440][Running/Boot Start] <\SystemRoot\system32\DRIVERS\agp440.sys> [1394 ARP 客户端协议 / Arp1394][Running/Manual Start] [RAS Asynchronous Media Driver / AsyncMac][Stopped/Manual Start] [标准 IDE/ESDI 硬盘控制器 / atapi][Running/Boot Start] <\SystemRoot\system32\DRIVERS\atapi.sys> [音频存根驱动程序 / audstub][Running/Manual Start] [CD-ROM Driver / Cdrom][Running/System Start] [Microsoft ACPI Control Method Battery Driver / CmBatt][Running/Manual Start] [Microsoft Composite Battery Driver / Compbatt][Running/Boot Start] <\SystemRoot\system32\DRIVERS\compbatt.sys> [磁盘驱动器 / Disk][Running/Boot Start] <\SystemRoot\system32\DRIVERS\disk.sys> [Dritek Keyboard Filter Driver / DKbFltr][Running/Manual Start] [dmboot / dmboot][Stopped/Disabled] [dmio / dmio][Stopped/Disabled] [dmload / dmload][Stopped/Disabled] [Microsoft Kernel DLS Syntheiszer / DMusic][Stopped/Manual Start] [Microsoft Kernel DRM Audio Descrambler / drmkaud][Stopped/Manual Start] [Intel(R) PRO Adapter Driver / E100B][Stopped/Manual Start] [FltMgr / FltMgr][Running/Boot Start] <\SystemRoot\system32\DRIVERS\fltMgr.sys> [FsVga / FsVga][Running/System Start] [Volume Manager Driver / Ftdisk][Running/Boot Start] <\SystemRoot\system32\DRIVERS\ftdisk.sys> [GEAR ASPI Filter Driver / GEARAspiWDM][Running/Manual Start] [Generic Packet Classifier / Gpc][Running/Manual Start] [Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start] [Microsoft HID Class Driver / HidUsb][Running/Manual Start] [hooksys / hooksys][Running/System Start] <\??\C:\WINDOWS\system32\drivers\Hooksys.sys> [HookTdi / HookTdi][Running/System Start] <\??\C:\WINDOWS\system32\drivers\HookTdi.sys> [HTTP / HTTP][Stopped/Manual Start] [HyperVM / HyperVM][Running/System Start] <\??\C:\WINDOWS\system32\drivers\hvm.sys> [i8042 键盘及 PS/2 鼠标端口驱动程序 / i8042prt][Running/System Start] [ialm / ialm][Running/Manual Start] [CD 烧制筛选驱动器 / Imapi][Running/System Start] [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start] [IntelIde / IntelIde][Running/Boot Start] <\SystemRoot\system32\DRIVERS\intelide.sys> [Intel Processor Driver / intelppm][Running/System Start] [IPv6 Windows Firewall Driver / Ip6Fw][Stopped/Manual Start] [IP Traffic Filter Driver / IpFilterDriver][Stopped/Manual Start] [IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start] [IP Network Address Translator / IpNat][Stopped/Manual Start] [IPSEC driver / IPSec][Running/System Start] [IR Enumerator Service / IRENUM][Stopped/Manual Start] [PnP ISA/EISA Bus Driver / isapnp][Running/Boot Start] <\SystemRoot\system32\DRIVERS\isapnp.sys> [Keyboard Class Driver / Kbdclass][Running/System Start] [Keyboard HID Driver / kbdhid][Running/System Start] [Microsoft Kernel Wave Audio Mixer / kmixer][Running/Manual Start] [Mouse Class Driver / Mouclass][Running/System Start] [Mouse HID Driver / mouhid][Running/Manual Start] [WebDav Client Redirector / MRxDAV][Stopped/Manual Start] [MRxSmb / MRxSmb][Running/System Start] [Microsoft Streaming Service Proxy / MSKSSRV][Stopped/Manual Start] [Microsoft Streaming Clock Proxy / MSPCLOCK][Stopped/Manual Start] [Microsoft Streaming Quality Manager Proxy / MSPQM][Stopped/Manual Start] [Microsoft System Management BIOS Driver / mssmbios][Running/Manual Start] [Remote Access NDIS TAPI Driver / NdisTapi][Running/Manual Start] [NDIS 用户模式 I/O 协议 / Ndisuio][Stopped/Manual Start] [Remote Access NDIS WAN Driver / NdisWan][Running/Manual Start] [NetBIOS Interface / NetBIOS][Running/System Start] [NetBios over Tcpip / NetBT][Running/System Start] [1394 网络驱动程序 / NIC1394][Running/Manual Start] [NSC Infrared Device Driver / NSCIRDA][Stopped/Manual Start] [IPX Traffic Filter Driver / NwlnkFlt][Stopped/Manual Start] [IPX Traffic Forwarder Driver / NwlnkFwd][Stopped/Manual Start] [O2MDRDR / O2MDRDR][Running/Boot Start] <\SystemRoot\system32\DRIVERS\o2media.sys> [O2SDRDR / O2SDRDR][Running/Boot Start] <\SystemRoot\system32\DRIVERS\o2sd.sys> [OHCI Compliant IEEE 1394 Host Controller / ohci1394][Running/Boot Start] <\SystemRoot\system32\DRIVERS\ohci1394.sys> [Intel PentiumIII Processor Driver / P3][Stopped/System Start] [Parallel port driver / Parport][Stopped/Manual Start] [PCI Bus Driver / PCI][Running/Boot Start] <\SystemRoot\system32\DRIVERS\pci.sys> [PCIIde / PCIIde][Running/Boot Start] <\SystemRoot\system32\DRIVERS\pciide.sys> [Pcmcia / Pcmcia][Running/Boot Start] <\SystemRoot\system32\DRIVERS\pcmcia.sys> [WAN Miniport (PPTP) / PptpMiniport][Running/Manual Start] [QoS Packet Scheduler / PSched][Running/Manual Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [qprotect_0001 / qprotect_0001][Stopped/Manual Start] <\??\d:\program files\11game\tuqtt.sys> [Remote Access Auto Connection Driver / RasAcd][Running/System Start] [WAN Miniport (IrDA) / Rasirda][Stopped/Manual Start] [WAN Miniport (L2TP) / Rasl2tp][Running/Manual Start] [远程访问 PPPOE 驱动程序 / RasPppoe][Running/Manual Start] [Direct Parallel / Raspti][Running/Manual Start] [Rdbss / Rdbss][Running/System Start] [RDPCDD / RDPCDD][Running/System Start] [Terminal Server Device Redirector Driver / rdpdr][Running/Manual Start] [Digital CD Audio Playback Filter Driver / redbook][Running/System Start] [rsd protect / rsdsys][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\protreg.sys> [Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Running/Manual Start] [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start] [sdbus / sdbus][Stopped/Manual Start] [Secdrv / Secdrv][Stopped/Manual Start] [Serenum Filter Driver / serenum][Stopped/Manual Start] [Serial port driver / Serial][Stopped/System Start] [SATALink driver accelerator / SiFilter][Stopped/Disabled] <\SystemRoot\system32\DRIVERS\SiWinAcc.sys> [Microsoft Kernel Audio Splitter / splitter][Stopped/Manual Start] [sptd / sptd][Running/Boot Start] <\SystemRoot\System32\Drivers\sptd.sys> [Srv / Srv][Running/Manual Start] [Software Bus Driver / swenum][Running/Manual Start] [Microsoft Kernel GS Wavetable Synthesizer / swmidi][Stopped/Manual Start] [Microsoft Kernel System Audio Device / sysaudio][Running/Manual Start] [TCP/IP Protocol Driver / Tcpip][Running/System Start] [Terminal Device Driver / TermDD][Running/System Start] [IBM PS/2 TrackPoint Filter Driver / TwoTrack][Stopped/Manual Start] [Microcode Update Driver / Update][Running/Manual Start] [Apple Mobile USB Driver / USBAAPL][Stopped/Manual Start] [Microsoft USB Generic Parent Driver / usbccgp][Running/Manual Start] [Microsoft USB 2.0 Enhanced Host Controller Miniport Driver / usbehci][Running/Manual Start] [USB2 Enabled Hub / usbhub][Running/Manual Start] [Microsoft USB Open Host Controller Miniport Driver / usbohci][Running/Boot Start] <\SystemRoot\system32\DRIVERS\usbohci.sys> [USB 扫描仪驱动程序 / usbscan][Stopped/Manual Start] [USB 大容量存储设备 / USBSTOR][Stopped/Manual Start] [Microsoft USB Universal Host Controller Miniport Driver / usbuhci][Running/Manual Start] [VgaSave / VgaSave][Running/System Start] <\SystemRoot\System32\drivers\vga.sys> [viamraid / viamraid][Stopped/Boot Start] <\SystemRoot\system32\DRIVERS\viamraid.sys> [Performance Tools Driver 10.0 / VSPerfDrv100][Stopped/Manual Start] <\??\E:\Program Files\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\VSPerfDrv100.sys> [Remote Access IP ARP Driver / Wanarp][Running/Manual Start] [Microsoft WINMM WDM Audio Compatibility Driver / wdmaud][Running/Manual Start] [WpdUsb / WpdUsb][Stopped/Manual Start] [Windows 套接字 2 .0 Non-IFS 服务提供程序支持环境 / WS2IFSL][Running/System Start] <\SystemRoot\System32\drivers\ws2ifsl.sys> ================================== 浏览器加载项 [WebThunder Browser Helper] {00000AAA-A363-466E-BEF5-9BB68697AA7F} [] {889D2FEB-5411-4565-8998-1DD2C5261283} <, > [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [Java(tm) Plug-In 2 SSV Helper] {DBC80044-A445-435b-BC74-9C25C1C588A9} [Microsoft Web Test Recorder 10.0 Helper] {DDA57003-0068-4ed2-9D32-4D1EC707D94D} [Microsoft Web Test Recorder 9.0 Helper] {E31CE47F-C268-41ba-897B-B415E613947D} [浩方电竞平台] {0A155D3C-68E2-4215-A47A-E800A446447A} [瑞星卡卡工具条(&R)] {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} [] {054527AE-EB44-4229-8987-15CE9210E307} <, > [] {A1B156BD-2CD6-4E7C-9C64-CEB2B8C0A929} <, > [] {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF} <, > [WebThunder Browser Helper] {00000AAA-A363-466E-BEF5-9BB68697AA7F} [] {03507A1A-E0C5-4404-AA26-205385C0892D} <, > [] {0A155D3C-68E2-4215-A47A-E800A446447A} <, > [] {889D2FEB-5411-4565-8998-1DD2C5261283} <, > [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [Java(tm) Plug-In 2 SSV Helper] {DBC80044-A445-435B-BC74-9C25C1C588A9} [Microsoft Web Test Recorder 10.0 Helper] {DDA57003-0068-4ED2-9D32-4D1EC707D94D} [Microsoft Web Test Recorder 9.0 Helper] {E31CE47F-C268-41BA-897B-B415E613947D} ================================== 正在运行的进程 [PID: 524 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [PID: 584 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\CSRSRV.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\basesrv.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\winsrv.dll] [Microsoft Corporation, 5.1.2600.6001 (xpsp_sp3_gdr.100618-1712)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\KERNEL32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\sxs.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 612 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\AUTHZ.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MSASN1.dll] [Microsoft Corporation, 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\NDdeApi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\PROFMAP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_gdr.081015-1312)] [C:\WINDOWS\system32\USERENV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\PSAPI.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\REGAPI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\SETUPAPI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WINSTA.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\WINTRUST.dll] [Microsoft Corporation, 5.131.2600.5922 (xpsp_sp3_gdr.091223-1907)] [C:\WINDOWS\system32\IMAGEHLP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WS2_32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WS2HELP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\system32\MSGINA.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\COMCTL32.dll] [Microsoft Corporation, 5.82 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\ODBC32.dll] [Microsoft Corporation, 3.525.3012.0 (xpsp_sp3_gdr.101108-1643)] [C:\WINDOWS\system32\comdlg32.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.6018 (xpsp_sp3_gdr.100726-1746)] [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)] [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll] [Microsoft Corporation, 6.0 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\odbcint.dll] [Microsoft Corporation, 3.525.1117.0 built by: (_sqlbld)] [C:\WINDOWS\system32\SHSVCS.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\sfc.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\Apphelp.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\msctfime.ime] [Microsoft Corporation, 5.1.2600.5768 (xpsp_sp3_gdr.090226-1442)] [C:\WINDOWS\system32\WINSCARD.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\WTSAPI32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\sxs.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\WINMM.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\cscdll.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\System32\dimsntfy.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\rsaenh.dll] [Microsoft Corporation, 5.1.2600.5507 (xpsp.080318-1711)] [C:\WINDOWS\system32\WlNotify.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MPR.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WINSPOOL.DRV] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\msv1_0.dll] [Microsoft Corporation, 5.1.2600.5876 (xpsp_sp3_gdr.090909-1234)] [C:\WINDOWS\system32\cryptdll.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\SAMLIB.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\cscui.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\NTMARTA.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\WLDAP32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\WINDOWS\system32\MSACM32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\midimap.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [PID: 656 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\NCObjAPI.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\system32\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0] [C:\WINDOWS\system32\SCESRV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\AUTHZ.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\USERENV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\umpnpmgr.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\WINSTA.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_gdr.081015-1312)] [C:\WINDOWS\system32\ShimEng.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\AppPatch\AcAdProc.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\system32\Apphelp.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\eventlog.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\PSAPI.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WS2_32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WS2HELP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\wtsapi32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [PID: 668 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\LSASRV.dll] [Microsoft Corporation, 5.1.2600.6058 (xpsp_sp3_gdr.101220-1709)] [C:\WINDOWS\system32\MPR.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\MSASN1.dll] [Microsoft Corporation, 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_gdr.081015-1312)] [C:\WINDOWS\system32\NTDSAPI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\WS2_32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WS2HELP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WLDAP32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\SAMLIB.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\SAMSRV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\cryptdll.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\ShimEng.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\AppPatch\AcGenral.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WINMM.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\system32\MSACM32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.6018 (xpsp_sp3_gdr.100726-1746)] [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)] [C:\WINDOWS\system32\USERENV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll] [Microsoft Corporation, 6.0 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\msprivs.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\kerberos.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\msv1_0.dll] [Microsoft Corporation, 5.1.2600.5876 (xpsp_sp3_gdr.090909-1234)] [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\netlogon.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\w32time.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0] [C:\WINDOWS\system32\schannel.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\wdigest.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\rsaenh.dll] [Microsoft Corporation, 5.1.2600.5507 (xpsp.080318-1711)] [C:\WINDOWS\system32\setupapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\scecli.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\pstorsvc.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\psbase.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\dssenh.dll] [Microsoft Corporation, 5.1.2600.5507 (xpsp.080318-1711)] [PID: 828 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\ShimEng.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\AppPatch\AcGenral.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\WINMM.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\system32\MSACM32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.6018 (xpsp_sp3_gdr.100726-1746)] [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)] [C:\WINDOWS\system32\USERENV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll] [Microsoft Corporation, 6.0 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\NTMARTA.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\SAMLIB.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\WLDAP32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [c:\windows\system32\rpcss.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [c:\windows\system32\WS2_32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\WS2HELP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.700] [c:\windows\system32\termsrv.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [c:\windows\system32\ICAAPI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [c:\windows\system32\SETUPAPI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\WINTRUST.dll] [Microsoft Corporation, 5.131.2600.5922 (xpsp_sp3_gdr.091223-1907)] [C:\WINDOWS\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MSASN1.dll] [Microsoft Corporation, 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413)] [C:\WINDOWS\system32\IMAGEHLP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [c:\windows\system32\AUTHZ.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [c:\windows\system32\mstlsapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [c:\windows\system32\ACTIVEDS.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [c:\windows\system32\adsldpc.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_gdr.081015-1312)] [c:\windows\system32\ATL.DLL] [Microsoft Corporation, 3.05.2284] [C:\WINDOWS\system32\REGAPI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\rsaenh.dll] [Microsoft Corporation, 5.1.2600.5507 (xpsp.080318-1711)] [PID: 896 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\ShimEng.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\AppPatch\AcGenral.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\WINMM.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\system32\MSACM32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.6018 (xpsp_sp3_gdr.100726-1746)] [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)] [C:\WINDOWS\system32\USERENV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll] [Microsoft Corporation, 6.0 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp_sp3_qfe.100823-1643)] [c:\windows\system32\rpcss.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [c:\windows\system32\WS2_32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\WS2HELP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\rsaenh.dll] [Microsoft Corporation, 5.1.2600.5507 (xpsp.080318-1711)] [C:\WINDOWS\system32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\winrnr.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\WLDAP32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\hnetcfg.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\wshtcpip.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.700] [PID: 956 / SYSTEM][C:\Program Files\Rising\RSD\RsMgrSvc.exe] [Beijing Rising Information Technology Co., Ltd., 1.0.0.38] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MSASN1.dll] [Microsoft Corporation, 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\Program Files\Rising\RSD\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.4] [C:\Program Files\Rising\RSD\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.1] [C:\WINDOWS\system32\Wtsapi32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\WINSTA.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_gdr.081015-1312)] [C:\WINDOWS\system32\msv1_0.dll] [Microsoft Corporation, 5.1.2600.5876 (xpsp_sp3_gdr.090909-1234)] [C:\WINDOWS\system32\cryptdll.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WS2_32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WS2HELP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [PID: 984 / SYSTEM][C:\Program Files\Rising\Rav\RavMonD.exe] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 14] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\Program Files\Rising\Rav\combase.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 27] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MSASN1.dll] [Microsoft Corporation, 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413)] [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll] [Microsoft Corporation, 6.0 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WS2_32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WS2HELP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\Program Files\Rising\Rav\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.8] [C:\Program Files\Rising\Rav\scansrvp.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.12] [C:\Program Files\Rising\Rav\cnt09.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 1] [C:\Program Files\Rising\Rav\moncomm.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.4] [C:\Program Files\Rising\Rav\MonBase.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 1] [C:\Program Files\Rising\Rav\Rslog.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.26] [C:\Program Files\Rising\Rav\RsStore.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.12] [C:\Program Files\Rising\Rav\mondrvd.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 12] [C:\Program Files\Rising\Rav\defmon.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 66] [C:\WINDOWS\system32\PSAPI.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\Program Files\Rising\Rav\moncom08.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.2] [C:\Program Files\Rising\Rav\taskplug.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.2] [C:\Program Files\Rising\Rav\mondrvm.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 8] [C:\Program Files\Rising\Rav\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 33] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp_sp3_qfe.100823-1643)] [C:\Program Files\Rising\Rav\FileMon.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 37] [C:\Program Files\Rising\Rav\MailMon.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 56] [C:\Program Files\Rising\Rav\rsindent.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.1.0] [C:\Program Files\Rising\Rav\cnt08.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 1] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\Rising\Rav\proccomm.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.2] [C:\Program Files\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.4] [C:\Program Files\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.1] [C:\WINDOWS\system32\Wtsapi32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\WINSTA.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_gdr.081015-1312)] [C:\Program Files\Rising\Rav\Hooksys.dll] [Beijing Rising Information Technology Co., Ltd., 25, 0, 0, 9] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\rstask.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 8] [C:\WINDOWS\system32\WINMM.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\Program Files\Rising\Rav\rsstub.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.1] [C:\Program Files\Rising\Rav\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.1] [C:\Program Files\Rising\Rav\hookTdi.dll] [Beijing Rising Information Technology Co., Ltd., 25, 0, 0, 9] [C:\Program Files\Rising\Rav\BACore.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 1, 3] [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.6018 (xpsp_sp3_gdr.100726-1746)] [C:\Program Files\Rising\Rav\rsnetsvr.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.12] [C:\WINDOWS\system32\wintrust.dll] [Microsoft Corporation, 5.131.2600.5922 (xpsp_sp3_gdr.091223-1907)] [C:\WINDOWS\system32\IMAGEHLP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\Program Files\Rising\Rav\bawhite.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 5] [C:\Program Files\Rising\Rav\ScanAdd.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.31] [C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 74] [C:\Program Files\Rising\Rav\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 14] [C:\Program Files\Rising\Rav\refs.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 6] [C:\Program Files\Rising\Rav\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 8] [C:\Program Files\Rising\Rav\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 5] [C:\WINDOWS\system32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\hnetcfg.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\wshtcpip.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\Program Files\Rising\Rav\ScanSrv.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 17] [C:\WINDOWS\system32\sfc.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\rsaenh.dll] [Microsoft Corporation, 5.1.2600.5507 (xpsp.080318-1711)] [C:\Program Files\Rising\Rav\scanpe.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 30] [C:\Program Files\Rising\Rav\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 8] [C:\Program Files\Rising\Rav\engext.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 40] [C:\Program Files\Rising\Rav\vmicore.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 25] [C:\WINDOWS\system32\USERENV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\msv1_0.dll] [Microsoft Corporation, 5.1.2600.5876 (xpsp_sp3_gdr.090909-1234)] [C:\WINDOWS\system32\cryptdll.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\Program Files\Rising\Rav\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 5] [C:\Program Files\Rising\Rav\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 7] [C:\Program Files\Rising\Rav\scantj.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 9] [C:\Program Files\Rising\Rav\extsfx.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 10] [C:\Program Files\Rising\Rav\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 8] [C:\Program Files\Rising\Rav\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 0] [C:\Program Files\Rising\Rav\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 20] [C:\Program Files\Rising\Rav\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 44] [C:\Program Files\Rising\Rav\extarch.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 24] [C:\Program Files\Rising\Rav\extcomp.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 6] [C:\Program Files\Rising\Rav\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 0] [PID: 1008 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\System32\ShimEng.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\AppPatch\AcGenral.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\System32\WINMM.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\System32\MSACM32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.6018 (xpsp_sp3_gdr.100726-1746)] [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)] [C:\WINDOWS\system32\USERENV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\System32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\System32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll] [Microsoft Corporation, 6.0 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\System32\NTMARTA.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\System32\SAMLIB.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\WLDAP32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\System32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [c:\windows\system32\shsvcs.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\System32\WINSTA.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_gdr.081015-1312)] [c:\windows\system32\dhcpcsvc.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [c:\windows\system32\WS2_32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\WS2HELP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\System32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\System32\SETUPAPI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\WINTRUST.dll] [Microsoft Corporation, 5.131.2600.5922 (xpsp_sp3_gdr.091223-1907)] [C:\WINDOWS\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MSASN1.dll] [Microsoft Corporation, 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413)] [C:\WINDOWS\system32\IMAGEHLP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [c:\windows\system32\audiosrv.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\msv1_0.dll] [Microsoft Corporation, 5.1.2600.5876 (xpsp_sp3_gdr.090909-1234)] [C:\WINDOWS\System32\cryptdll.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [c:\windows\system32\wkssvc.dll] [Microsoft Corporation, 5.1.2600.5826 (xpsp_sp3_gdr.090609-1434)] [c:\windows\system32\NTDSAPI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [c:\windows\system32\cryptsvc.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [c:\windows\system32\certcli.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [c:\windows\system32\ATL.DLL] [Microsoft Corporation, 3.05.2284] [C:\WINDOWS\system32\CRYPTUI.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [c:\windows\system32\ESENT.dll] [Microsoft Corporation, 5.1.2468.0 (Lab03_N(jliem).010306-1456)] [c:\windows\system32\es.dll] [Microsoft Corporation, 2001.12.4414.706] [C:\WINDOWS\System32\wtsapi32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [c:\windows\system32\srvsvc.dll] [Microsoft Corporation, 5.1.2600.6031 (xpsp_sp3_gdr.100826-1646)] [c:\windows\system32\dmserver.dll] [Microsoft Corp., 2600.5512.503.0] [C:\WINDOWS\System32\rsaenh.dll] [Microsoft Corporation, 5.1.2600.5507 (xpsp.080318-1711)] [c:\windows\system32\seclogon.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\System32\HNETCFG.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\wbem\wmisvc.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\system32\VSSAPI.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [c:\windows\system32\sens.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [c:\windows\system32\tapisrv.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\ACTIVEDS.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [c:\windows\system32\adsldpc.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [c:\windows\system32\PSAPI.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [c:\windows\system32\rtutils.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\Wbem\wbemcore.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\System32\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0] [C:\WINDOWS\System32\Wbem\esscli.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\System32\Wbem\wbemcomn.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\System32\Wbem\FastProx.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\System32\SXS.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [c:\windows\system32\rasmans.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\WINIPSEC.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\netcfgx.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\CLUSAPI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [c:\windows\system32\netman.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\MPRAPI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\netshell.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\credui.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [c:\windows\system32\dot3api.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\dot3dlg.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\OneX.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\eappcfg.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\eappprxy.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\RASAPI32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\rasman.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\TAPI32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\WZCSAPI.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\WZCSvc.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\WMI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [c:\windows\system32\EapolQec.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\QUtil.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\comsvcs.dll] [Microsoft Corporation, 2001.12.4414.702] [C:\WINDOWS\system32\colbact.DLL] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\MTXCLU.DLL] [Microsoft Corporation, 2001.12.4414.706] [C:\WINDOWS\system32\WSOCK32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\RESUTILS.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\wbem\wmiutils.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\system32\wbem\repdrvfs.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\system32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\System32\wshtcpip.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\wbem\wmiprvsd.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\NCObjAPI.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\system32\wbem\wbemess.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\System32\rastapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\unimdm.tsp] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\uniplat.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\kmddsp.tsp] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\ndptsp.tsp] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\h323.tsp] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\hidphone.tsp] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\HID.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\System32\rasppp.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\ntlsapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\kerberos.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\System32\RASQEC.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\raschap.dll] [Microsoft Corporation, 5.1.2600.5886 (xpsp_sp3_gdr.091012-1253)] [C:\WINDOWS\System32\rastls.dll] [Microsoft Corporation, 5.1.2600.5886 (xpsp_sp3_gdr.091012-1253)] [C:\WINDOWS\System32\SCHANNEL.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\System32\WinSCard.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\System32\RASDLG.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\wbem\ncprov.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\system32\wbem\wbemcons.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [PID: 1168 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.6024 (xpsp_sp3_gdr.100817-1626)] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\ShimEng.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\AppPatch\AcGenral.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WINMM.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\system32\MSACM32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.6018 (xpsp_sp3_gdr.100726-1746)] [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)] [C:\WINDOWS\system32\USERENV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll] [Microsoft Corporation, 6.0 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\SPOOLSS.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WS2_32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WS2HELP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\localspl.dll] [Microsoft Corporation, 5.1.2600.5809 (xpsp_sp3_gdr.090507-1329)] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\WINTRUST.dll] [Microsoft Corporation, 5.131.2600.5922 (xpsp_sp3_gdr.091223-1907)] [C:\WINDOWS\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MSASN1.dll] [Microsoft Corporation, 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413)] [C:\WINDOWS\system32\IMAGEHLP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\winspool.drv] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\netapi32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_gdr.081015-1312)] [C:\WINDOWS\system32\tcpmon.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\usbmon.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\System32\winrnr.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\WLDAP32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\win32spl.dll] [Microsoft Corporation, 5.1.2600.5664 (xpsp_sp3_gdr.080827-1248)] [C:\WINDOWS\system32\NETRAP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\NTDSAPI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\inetpp.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [PID: 1356 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\BROWSEUI.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\system32\SHDOCVW.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MSASN1.dll] [Microsoft Corporation, 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413)] [C:\WINDOWS\system32\CRYPTUI.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_gdr.081015-1312)] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\system32\WINTRUST.dll] [Microsoft Corporation, 5.131.2600.5922 (xpsp_sp3_gdr.091223-1907)] [C:\WINDOWS\system32\IMAGEHLP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WLDAP32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.6018 (xpsp_sp3_gdr.100726-1746)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\ShimEng.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\AppPatch\AcGenral.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WINMM.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\MSACM32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\USERENV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll] [Microsoft Corporation, 6.0 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\msctfime.ime] [Microsoft Corporation, 5.1.2600.5768 (xpsp_sp3_gdr.090226-1442)] [C:\WINDOWS\system32\appHelp.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.700] [C:\Documents and Settings\Administrator\Application Data\AUIcon\AUIcon.dll] [, 3.0.6.6] [C:\WINDOWS\system32\PSAPI.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WS2_32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WS2HELP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\IPHLPAPI.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\OLEACC.dll] [Microsoft Corporation, 4.2.5406.0 (xpclient.010817-1148)] [C:\WINDOWS\system32\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0] [C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\System32\cscui.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\System32\CSCDLL.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\themeui.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\MSIMG32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\actxprxy.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\RASAPI32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\rasman.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\TAPI32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\rtutils.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\msutb.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\ntshrui.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\ATL.DLL] [Microsoft Corporation, 3.05.2284] [C:\WINDOWS\system32\LINKINFO.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WINSTA.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\webcheck.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WSOCK32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 7] [C:\WINDOWS\system32\stobject.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\BatMeter.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\POWRPROF.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\SETUPAPI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\WTSAPI32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\NETSHELL.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\credui.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\dot3api.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\dot3dlg.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\OneX.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\eappcfg.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\eappprxy.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\msi.dll] [Microsoft Corporation, 4.5.6001.22299] [C:\WINDOWS\system32\msv1_0.dll] [Microsoft Corporation, 5.1.2600.5876 (xpsp_sp3_gdr.090909-1234)] [C:\WINDOWS\system32\cryptdll.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MPRAPI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\ACTIVEDS.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\adsldpc.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\SAMLIB.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\System32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\rsaenh.dll] [Microsoft Corporation, 5.1.2600.5507 (xpsp.080318-1711)] [C:\WINDOWS\system32\hnetcfg.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\wshtcpip.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\Program Files\Rising\Rav\wbshld.dll] [Beijing Rising Information Technology Co., Ltd., 24, 0, 0, 81] [C:\WINDOWS\system32\SXS.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.4543] [C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4543] [C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4543] [C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3.0.0.4543] [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4543] [C:\WINDOWS\system32\MLANG.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [d:\Program Files\WinRAR\rarext.dll] [, ] [C:\WINDOWS\system32\ravext.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 6] [C:\WINDOWS\system32\KakaExt.dll] [Beijing Rising Information Technology Co., Ltd., 22.0.0.4] [C:\WINDOWS\system32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\WINDOWS\system32\midimap.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\browselc.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\sensapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\gdiplus.dll] [Microsoft Corporation, 5.2.6001.22319 (vistasp1_ldr.081126-1506)] [C:\WINDOWS\system32\DUSER.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\MPR.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\drprov.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\System32\ntlanman.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\System32\NETUI0.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\System32\NETUI1.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\System32\NETRAP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\System32\davclnt.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\sti.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\CFGMGR32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\mscms.dll] [Microsoft Corporation, 5.1.2600.5627 (xpsp_sp3_gdr.080624-1245)] [C:\WINDOWS\system32\WINSPOOL.DRV] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [PID: 1544 / Administrator][C:\Program Files\Rising\AntiSpyware\rstray.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.32] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\COMCTL32.dll] [Microsoft Corporation, 6.0 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\Program Files\Rising\AntiSpyware\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 4] [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.6018 (xpsp_sp3_gdr.100726-1746)] [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MSASN1.dll] [Microsoft Corporation, 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\msctfime.ime] [Microsoft Corporation, 5.1.2600.5768 (xpsp_sp3_gdr.090226-1442)] [C:\WINDOWS\system32\ATL.dll] [Microsoft Corporation, 3.05.2284] [C:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 7] [C:\Program Files\Rising\AntiSpyware\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\Program Files\Rising\AntiSpyware\ComServ.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.33] [C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\Program Files\Rising\AntiSpyware\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\AntiSpyware\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Rising\AntiSpyware\rscommon.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.1.1] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [C:\WINDOWS\system32\Wtsapi32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\WINSTA.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_gdr.081015-1312)] [C:\Program Files\Rising\AntiSpyware\rsxml1.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [C:\Program Files\Rising\AntiSpyware\pngdll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [C:\Program Files\Rising\AntiSpyware\runiep.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.78] [C:\Program Files\Rising\AntiSpyware\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.11] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\AntiSpyware\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\WINDOWS\system32\USERENV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\wsock32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WS2_32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WS2HELP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\RASAPI32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\rasman.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\TAPI32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\rtutils.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WINMM.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\msv1_0.dll] [Microsoft Corporation, 5.1.2600.5876 (xpsp_sp3_gdr.090909-1234)] [C:\WINDOWS\system32\cryptdll.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\sensapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\System32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\System32\winrnr.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\WLDAP32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\system32\rsaenh.dll] [Microsoft Corporation, 5.1.2600.5507 (xpsp.080318-1711)] [C:\WINDOWS\system32\hnetcfg.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\wshtcpip.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\SETUPAPI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\Apphelp.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [PID: 1576 / Administrator][C:\Program Files\Rising\Rav\RSTRAY.EXE] [Beijing Rising Information Technology Co., Ltd., 23.0.0.12] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)] [C:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\COMCTL32.dll] [Microsoft Corporation, 6.0 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\jscript.dll] [Microsoft Corporation, 5.7.6002.22145] [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\Program Files\Rising\Rav\comserv.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.15] [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.6018 (xpsp_sp3_gdr.100726-1746)] [C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\Program Files\Rising\Rav\rslang.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.1] [C:\Program Files\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.4] [C:\Program Files\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.1] [C:\WINDOWS\system32\Wtsapi32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\WINSTA.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_gdr.081015-1312)] [C:\Program Files\Rising\Rav\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.2] [C:\Program Files\Rising\Rav\rsxml.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.2] [C:\Program Files\Rising\Rav\MonState.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 2] [C:\Program Files\Rising\Rav\ScanEvnt.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.10] [C:\Program Files\Rising\Rav\rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.12] [C:\Program Files\Rising\Rav\rsconf.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.8] [C:\Program Files\Rising\Rav\rspalvd.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.7] [C:\Program Files\Rising\Rav\mruleui.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 10] [C:\Program Files\Rising\Rav\MonTray.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.1.30] [C:\WINDOWS\system32\WINMM.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\Program Files\Rising\Rav\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.14] [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MSASN1.dll] [Microsoft Corporation, 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413)] [C:\Program Files\Rising\Rav\UsbServ.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 3] [C:\Program Files\Rising\Rav\ScanTray.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.56] [C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 23, 0, 0, 3] [C:\Program Files\Rising\Rav\wbshld.dll] [Beijing Rising Information Technology Co., Ltd., 24, 0, 0, 81] [C:\WINDOWS\system32\PSAPI.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\shdocvw.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\system32\CRYPTUI.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\WINTRUST.dll] [Microsoft Corporation, 5.131.2600.5922 (xpsp_sp3_gdr.091223-1907)] [C:\WINDOWS\system32\IMAGEHLP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WLDAP32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\SETUPAPI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\mlang.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\mshtml.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\system32\msls31.dll] [Microsoft Corporation, 3.10.349.0] [C:\WINDOWS\system32\ATL.dll] [Microsoft Corporation, 3.05.2284] [C:\Program Files\Rising\Rav\dfw.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.67] [C:\Program Files\Rising\Rav\ScanPrxy.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.32] [C:\WINDOWS\system32\USERENV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\NTMARTA.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\SAMLIB.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\Program Files\Rising\Rav\GCompt.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.56] [C:\Program Files\Rising\Rav\Isol.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.14] [C:\Program Files\Rising\Rav\rsstore.dll] [Beijing Rising Information Technology Co., Ltd., 23.0.0.12] [C:\WINDOWS\system32\MSIMTF.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\SXS.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\ImgUtil.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\pngfilt.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\dxtrans.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\ddrawex.dll] [Microsoft Corporation, 5.03.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\DDRAW.dll] [Microsoft Corporation, 5.03.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\DCIMAN32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\dxtmsft.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\wsock32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WS2_32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WS2HELP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\RASAPI32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\rasman.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\TAPI32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\rtutils.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\msv1_0.dll] [Microsoft Corporation, 5.1.2600.5876 (xpsp_sp3_gdr.090909-1234)] [C:\WINDOWS\system32\cryptdll.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\sensapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\System32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\System32\winrnr.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\rsaenh.dll] [Microsoft Corporation, 5.1.2600.5507 (xpsp.080318-1711)] [C:\WINDOWS\system32\hnetcfg.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\wshtcpip.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [PID: 1584 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\MSUTB.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\ShimEng.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\AppPatch\AcGenral.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WINMM.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\system32\MSACM32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.6018 (xpsp_sp3_gdr.100726-1746)] [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)] [C:\WINDOWS\system32\USERENV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll] [Microsoft Corporation, 6.0 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\msctfime.ime] [Microsoft Corporation, 5.1.2600.5768 (xpsp_sp3_gdr.090226-1442)] [C:\Program Files\Rising\Rav\wbshld.dll] [Beijing Rising Information Technology Co., Ltd., 24, 0, 0, 81] [C:\WINDOWS\system32\PSAPI.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MSASN1.dll] [Microsoft Corporation, 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413)] [C:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 7] [PID: 1976 / Administrator][C:\Program Files\Rising\RSD\popwndexe.exe] [Beijing Rising Information Technology Co., Ltd., 1.0.0.7] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 7] [C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\Program Files\Rising\RSD\rsdk.dll] [Beijing Rising Information Technology Co., Ltd., 1.0.0.2] [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.6018 (xpsp_sp3_gdr.100726-1746)] [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll] [Microsoft Corporation, 6.0 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp_sp3_qfe.100823-1643)] [C:\Program Files\Rising\RSD\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 1.0.0.30] [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MSASN1.dll] [Microsoft Corporation, 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413)] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\msxml3.dll] [Microsoft Corporation, 8.100.1052.0] [C:\WINDOWS\system32\USERENV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\system32\mlang.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\msctfime.ime] [Microsoft Corporation, 5.1.2600.5768 (xpsp_sp3_gdr.090226-1442)] [C:\Program Files\Rising\Rav\wbshld.dll] [Beijing Rising Information Technology Co., Ltd., 24, 0, 0, 81] [C:\WINDOWS\system32\PSAPI.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\wsock32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WS2_32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WS2HELP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\RASAPI32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\rasman.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_gdr.081015-1312)] [C:\WINDOWS\system32\TAPI32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\rtutils.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WINMM.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\msv1_0.dll] [Microsoft Corporation, 5.1.2600.5876 (xpsp_sp3_gdr.090909-1234)] [C:\WINDOWS\system32\cryptdll.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\sensapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\System32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\System32\winrnr.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\WLDAP32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\rsaenh.dll] [Microsoft Corporation, 5.1.2600.5507 (xpsp.080318-1711)] [C:\WINDOWS\system32\hnetcfg.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\wshtcpip.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [PID: 832 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\IMM32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\ShimEng.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\AppPatch\AcGenral.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WINMM.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\system32\MSACM32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.6018 (xpsp_sp3_gdr.100726-1746)] [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)] [C:\WINDOWS\system32\USERENV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll] [Microsoft Corporation, 6.0 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp_sp3_qfe.100823-1643)] [C:\Program Files\Rising\Rav\wbshld.dll] [Beijing Rising Information Technology Co., Ltd., 24, 0, 0, 81] [C:\WINDOWS\system32\PSAPI.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MSASN1.dll] [Microsoft Corporation, 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413)] [C:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 7] [C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\msctfime.ime] [Microsoft Corporation, 5.1.2600.5768 (xpsp_sp3_gdr.090226-1442)] [PID: 2308 / Administrator][C:\Program Files\Rising\AntiSpyware\knownsvr.exe] [Beijing Rising Information Technology Co., Ltd., 6.0.0.14] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\Program Files\Rising\AntiSpyware\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.11] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MSASN1.dll] [Microsoft Corporation, 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413)] [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll] [Microsoft Corporation, 6.0 (xpsp_sp3_qfe.100823-1643)] [C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\WINDOWS\system32\Wtsapi32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\WINSTA.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_gdr.081015-1312)] [PID: 1240 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\ShimEng.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\AppPatch\AcGenral.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\WINMM.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\system32\MSACM32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.6018 (xpsp_sp3_gdr.100726-1746)] [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)] [C:\WINDOWS\system32\USERENV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll] [Microsoft Corporation, 6.0 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\comctl32.dll] [Microsoft Corporation, 5.82 (xpsp_sp3_qfe.100823-1643)] [c:\windows\system32\wiaservc.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\CFGMGR32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [c:\windows\system32\setupapi.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [c:\windows\system32\mscms.dll] [Microsoft Corporation, 5.1.2600.5627 (xpsp_sp3_gdr.080624-1245)] [c:\windows\system32\WINSPOOL.DRV] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [c:\windows\system32\WINSTA.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_gdr.081015-1312)] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\WINTRUST.dll] [Microsoft Corporation, 5.131.2600.5922 (xpsp_sp3_gdr.091223-1907)] [C:\WINDOWS\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MSASN1.dll] [Microsoft Corporation, 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413)] [C:\WINDOWS\system32\IMAGEHLP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\actxprxy.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\sti.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [PID: 2664 / Administrator][D:\Program Files\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.8.2.1321] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\system32\user32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\system32\Apphelp.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [PID: 2680 / Administrator][D:\Program Files\sreng2\SRE1a964ccb.EXE] [Smallfrogs Studio, 2.8.2.1321] [C:\WINDOWS\system32\ntdll.dll] [Microsoft Corporation, 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)] [C:\WINDOWS\system32\kernel32.dll] [Microsoft Corporation, 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)] [C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\GDI32.dll] [Microsoft Corporation, 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)] [C:\WINDOWS\system32\comdlg32.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\ADVAPI32.dll] [Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] [C:\WINDOWS\system32\RPCRT4.dll] [Microsoft Corporation, 5.1.2600.6022 (xpsp_sp3_gdr.100813-1643)] [C:\WINDOWS\system32\Secur32.dll] [Microsoft Corporation, 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)] [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\COMCTL32.dll] [Microsoft Corporation, 6.0 (xpsp_sp3_qfe.100823-1643)] [C:\WINDOWS\system32\msvcrt.dll] [Microsoft Corporation, 7.0.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.5912 (xpsp_sp3_gdr.091207-1454)] [C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.6018 (xpsp_sp3_gdr.100726-1746)] [C:\WINDOWS\system32\WINSPOOL.DRV] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\oledlg.dll] [Microsoft Corporation, 1.0 (xpsp.080413-2108)] [C:\WINDOWS\system32\ole32.dll] [Microsoft Corporation, 5.1.2600.6010 (xpsp_sp3_gdr.100712-1633)] [C:\WINDOWS\system32\OLEAUT32.dll] [Microsoft Corporation, 5.1.2600.5512] [C:\WINDOWS\system32\VERSION.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\MSASN1.dll] [Microsoft Corporation, 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413)] [C:\WINDOWS\system32\WINMM.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0845)] [C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\system32\WS2_32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\WS2HELP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\IMM32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\LPK.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\USP10.dll] [Microsoft Corporation, 1.0420.2600.5969 (xpsp_sp3_gdr.100416-1716)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\RICHED20.DLL] [Microsoft Corporation, 5.30.23.1230] [C:\WINDOWS\system32\NTMARTA.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\SAMLIB.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\WLDAP32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\Program Files\Rising\Rav\wbshld.dll] [Beijing Rising Information Technology Co., Ltd., 24, 0, 0, 81] [C:\WINDOWS\system32\PSAPI.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\Program Files\Rising\AntiSpyware\RegCall.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 7] [C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\msctfime.ime] [Microsoft Corporation, 5.1.2600.5768 (xpsp_sp3_gdr.090226-1442)] [C:\WINDOWS\system32\sfc.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\WINTRUST.dll] [Microsoft Corporation, 5.131.2600.5922 (xpsp_sp3_gdr.091223-1907)] [C:\WINDOWS\system32\IMAGEHLP.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [D:\Program Files\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [C:\WINDOWS\system32\wsock32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\RASAPI32.DLL] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\rasman.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\NETAPI32.dll] [Microsoft Corporation, 5.1.2600.5694 (xpsp_sp3_gdr.081015-1312)] [C:\WINDOWS\system32\TAPI32.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\rtutils.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\msv1_0.dll] [Microsoft Corporation, 5.1.2600.5876 (xpsp_sp3_gdr.090909-1234)] [C:\WINDOWS\system32\cryptdll.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\iphlpapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\sensapi.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)] [C:\WINDOWS\system32\USERENV.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\System32\mswsock.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\system32\DNSAPI.dll] [Microsoft Corporation, 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] [C:\WINDOWS\System32\winrnr.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.6049 (xpsp_sp3_gdr.101103-1638)] [C:\WINDOWS\system32\rsaenh.dll] [Microsoft Corporation, 5.1.2600.5507 (xpsp.080318-1711)] [C:\WINDOWS\system32\hnetcfg.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\System32\wshtcpip.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)] [C:\WINDOWS\system32\xpsp2res.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\Winsta.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\utildll.dll] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\WINDOWS\system32\SETUPAPI.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)] [C:\WINDOWS\system32\cryptnet.dll] [Microsoft Corporation, 5.131.2600.5512 (xpsp.080413-2113)] [C:\WINDOWS\system32\WINHTTP.dll] [Microsoft Corporation, 5.1.2600.5727 (xpsp_sp3_gdr.081215-1359)] [C:\WINDOWS\system32\Cabinet.dll] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)] [C:\WINDOWS\system32\CLBCATQ.DLL] [Microsoft Corporation, 2001.12.4414.700] [C:\WINDOWS\system32\COMRes.dll] [Microsoft Corporation, 2001.12.4414.700] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\system32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 MSAFD Tcpip [TCP/IP] C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD Tcpip [UDP/IP] C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD Tcpip [RAW/IP] C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) RSVP UDP Service Provider C:\WINDOWS\system32\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider) RSVP TCP Service Provider C:\WINDOWS\system32\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{F784E4E2-2E04-4BAD-954F-C6E05988A28D}] SEQPACKET 0 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{F784E4E2-2E04-4BAD-954F-C6E05988A28D}] DATAGRAM 0 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{2F89D63F-17E9-4306-BC4B-0263AE9CCA1D}] SEQPACKET 1 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{2F89D63F-17E9-4306-BC4B-0263AE9CCA1D}] DATAGRAM 1 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{3AF3E2EB-8998-463D-B8CF-94AEC77AB819}] SEQPACKET 2 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) MSAFD NetBIOS [\Device\NetBT_Tcpip_{3AF3E2EB-8998-463D-B8CF-94AEC77AB819}] DATAGRAM 2 C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider) ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 127.0.0.1 atm.youku.com 127.0.0.1 Fvid.atm.youku.com 127.0.0.1 html.atm.youku.com 127.0.0.1 valb.atm.youku.com 127.0.0.1 valf.atm.youku.com 127.0.0.1 valo.atm.youku.com 127.0.0.1 valp.atm.youku.com 127.0.0.1 lstat.youku.com 127.0.0.1 speed.lstat.youku.com 127.0.0.1 urchin.lstat.youku.com 127.0.0.1 stat.youku.com 127.0.0.1 static.lstat.youku.com 127.0.0.1 valc.atm.youku.com 127.0.0.1 vid.atm.youku.com 127.0.0.1 walp.atm.youku.com 127.0.0.1 images.sohu.com 127.0.0.1 adextensioncontrol.tudou.com 127.0.0.1 iwstat.tudou.com 127.0.0.1 nstat.tudou.com 127.0.0.1 stats.tudou.com 127.0.0.1 *.p2v.tudou.com* 127.0.0.1 at-img1.tdimg.com 127.0.0.1 at-img2.tdimg.com 127.0.0.1 at-img3.tdimg.com 127.0.0.1 adplay.tudou.com 127.0.0.1 adcontrol.tudou.com 127.0.0.1 stat.tudou.com http://adcontrol.tudou.com/ http://a.alimama.cn/* http://cpro.baidu.com/* http://cb.baidu.com/ecom* http://img.uu1001.cn/* */saleloader_*.js !*/tuidefer_3.js */adcontrol/* */tudoumini/* http://stat.tudou.com/crossdomain.xml *.tudou.com/adcontrol* http://c.qling.com/code_img/* http://ua7.tdimg.com/7/3129/* http://u4.tdimg.com/5/186/122/* http://ua.tdimg.com:8080/picture/4013/* http://js.tudouui.com/bin/tmp/* http://links.imgup.cn/201103/25/11/* http://u1.tdimg.com/0/84/172/* http://u1.tdimg.com/6/9/57/* http://at-img2.tdimg.com/board/2011/2/* http://at-img1.tdimg.com/board/2010/12/* http://u3.tdimg.com/4/74/90/* http://at-img4.tdimg.com/board/2011/4/* ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 612, C:\WINDOWS\SYSTEM32\WINLOGON.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 668, C:\WINDOWS\SYSTEM32\LSASS.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1008, C:\WINDOWS\SYSTEM32\SVCHOST.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1168, C:\WINDOWS\SYSTEM32\SPOOLSV.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1356, C:\WINDOWS\EXPLORER.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 832, C:\WINDOWS\SYSTEM32\CONIME.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1240, C:\WINDOWS\SYSTEM32\SVCHOST.EXE] ================================== 计划任务 N/A ================================== Windows 安全更新检查 N/A ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]