[F:\anzhuang\Thunder\Components\ResWorker\DsBho_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 18]
[F:\anzhuang\Thunder\Components\ResWorker\DataProcessor_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
[F:\安装\瑞星\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[C:\WINDOWS\system32\nvshell.dll] [, ]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17]
[F:\anzhuang\AVG Anti-Spyware 7.5\shellexecutehook.dll] [GRISOFT s.r.o., 7, 5, 1, 36]
[F:\anzhuang\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 74]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[F:\anzhuang\AVG Anti-Spyware 7.5\context.dll] [GRISOFT s.r.o., 7, 5, 1, 36]
[PID: 1544 / SYSTEM][f:\安装\瑞星\rising\rfw\rfwstub.exe] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[f:\安装\瑞星\rising\rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[f:\安装\瑞星\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[f:\安装\瑞星\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 1712 / SYSTEM][F:\安装\瑞星\RISING\RAV\RavStub.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.9]
[F:\安装\瑞星\RISING\RAV\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[F:\安装\瑞星\RISING\RAV\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[F:\安装\瑞星\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[f:\安装\瑞星\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[f:\安装\瑞星\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 1812 / Administrator][f:\安装\瑞星\rising\rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 7.0.1.65]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[f:\安装\瑞星\rising\rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 88]
[F:\安装\瑞星\Rising\Rfw\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[f:\安装\瑞星\rising\rfw\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[f:\安装\瑞星\rising\rfw\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0]
[f:\安装\瑞星\rising\rfw\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16]
[f:\安装\瑞星\rising\rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[f:\安装\瑞星\rising\rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.7]
[f:\安装\瑞星\rising\rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0]
[f:\安装\瑞星\rising\rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4]
[f:\安装\瑞星\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[f:\安装\瑞星\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[f:\安装\瑞星\rising\rfw\RfwRule.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.13]
[PID: 1844 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[f:\安装\瑞星\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[f:\安装\瑞星\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 284 / SYSTEM][F:\anzhuang\AVG Anti-Spyware 7.5\guard.exe] [GRISOFT s.r.o., 7, 5, 1, 22]
[F:\anzhuang\AVG Anti-Spyware 7.5\engine.dll] [GRISOFT s.r.o., 4, 2, 0, 19]
[PID: 588 / SYSTEM][F:\anzhuang\StormII\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 3, 15]
[PID: 1020 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.9136]
[PID: 1124 / SYSTEM][C:\Program Files\Common Files\Sogou PXP\p2psvr.exe] [Sohu.com Inc., 2, 0, 0, 32]
[C:\Program Files\Sogou PXP\vodsvr.dll] [Sohu.com Inc., 2, 4, 0, 6]
[C:\Program Files\Sogou PXP\pxpnet.dll] [Sohu.com Inc., 1, 0, 0, 9]
[C:\Program Files\Sogou PXP\p2pclient.dll] [Sohu.com Inc., 2, 9, 1, 6]
[PID: 1892 / Administrator][F:\安装\瑞星\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.23]
[F:\安装\瑞星\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[F:\安装\瑞星\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[F:\安装\瑞星\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[F:\安装\瑞星\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 20.0.0.0]
[F:\安装\瑞星\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16]
[PID: 1940 / Administrator][F:\anzhuang\AVG Anti-Spyware 7.5\avgas.exe] [GRISOFT s.r.o., 7, 5, 1, 43]
[F:\anzhuang\AVG Anti-Spyware 7.5\engine.dll] [GRISOFT s.r.o., 4, 2, 0, 19]
[f:\安装\瑞星\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[f:\安装\瑞星\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 2076 / Administrator][F:\安装\瑞星\卡卡\runiep.exe] [Beijing Rising Technology Co., Ltd., 5.0.0.16]
[F:\安装\瑞星\卡卡\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[F:\安装\瑞星\卡卡\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 2144 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[f:\安装\瑞星\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[f:\安装\瑞星\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[PID: 2152 / Administrator][F:\安装\瑞星\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 20.0.01.19]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[F:\安装\瑞星\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[F:\安装\瑞星\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[F:\安装\瑞星\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[F:\安装\瑞星\Rising\Rav\recomp.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 38]
[F:\安装\瑞星\Rising\Rav\refs.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17]
[F:\安装\瑞星\Rising\Rav\viruslib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26]
[F:\安装\瑞星\Rising\Rav\relibldr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[F:\安装\瑞星\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0]
[F:\安装\瑞星\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16]
[F:\安装\瑞星\Rising\Rav\MonRule.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.29]
[F:\安装\瑞星\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4]
[F:\安装\瑞星\Rising\Rav\Rsguilib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 88]
[F:\安装\瑞星\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0]
[PID: 2840 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3472 / Administrator][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[f:\安装\瑞星\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[f:\安装\瑞星\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\WINDOWS\system32\kakatool.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.4]
[F:\anzhuang\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29]
[F:\anzhuang\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 74]
[F:\anzhuang\Thunder\Components\ResWorker\DsBho_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 18]
[F:\anzhuang\Thunder\Components\ResWorker\DataProcessor_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
[F:\安装\瑞星\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0]
[PID: 2016 / Administrator][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[f:\安装\瑞星\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[f:\安装\瑞星\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[C:\WINDOWS\system32\kakatool.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.4]
[F:\anzhuang\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29]
[F:\anzhuang\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 74]
[F:\anzhuang\Thunder\Components\ResWorker\DsBho_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 18]
[F:\anzhuang\Thunder\Components\ResWorker\DataProcessor_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
[F:\安装\瑞星\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sogou.com Inc., 3.2.0.0]
[C:\WINDOWS\system32\IME\SogouInput\Plugin\SgImeWord.dll] [Sogou.com Inc., 3.2.0.0]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17]
[F:\anzhuang\AVG Anti-Spyware 7.5\shellexecutehook.dll] [GRISOFT s.r.o., 7, 5, 1, 36]
[PID: 3664 / Administrator][F:\anzhuang\FlashGet\FlashGet.exe] [FLASHGET, 2, 9, 0, 1184]
[F:\anzhuang\FlashGet\storage.dll] [FLASHGET, 2, 0, 0, 1003]
[F:\anzhuang\FlashGet\dbghelp.dll] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[F:\anzhuang\FlashGet\LiveUpdateUI.dll] [FLASHGET, 1, 1, 0, 1002]
[F:\anzhuang\FlashGet\BugReport.dll] [, 1, 1, 0, 1001]
[F:\anzhuang\FlashGet\zlib.dll] [, 1.1.4.0]
[F:\anzhuang\FlashGet\modules\ComHelper\ComHelper.dll] [FLASHGET, 1, 0, 0, 1002]
[F:\anzhuang\FlashGet\modules\Downstat\Downstat.dll] [FLASHGET, 1, 0, 0, 1008]
[F:\anzhuang\FlashGet\modules\INMEDIA\InMedia.dll] [FlashGet, 1, 0, 0, 1002]
[F:\anzhuang\FlashGet\modules\P4pclient\P4pclient.dll] [ , 1, 0, 0, 1005]
[F:\anzhuang\FlashGet\modules\SearchTop\SearchTop.dll] [FLASHGET, 1, 0, 0, 1002]
[F:\anzhuang\FlashGet\modules\Security\Security.dll] [ FlashGet, 1, 0, 0, 1006]
[F:\anzhuang\FlashGet\modules\SnapShot\SnapShot.dll] [ FlashGet, 1, 0, 0, 1027]
[F:\anzhuang\FlashGet\modules\SoBar\SoBar.dll] [FLASHGET, 1, 0, 0, 1003]
[F:\anzhuang\FlashGet\modules\TaskNotifier\tasknotifier.dll] [FLASHGET, 1, 0, 0, 1002]
[F:\anzhuang\FlashGet\modules\garage\garage.dll] [N/A, ]
[F:\anzhuang\FlashGet\modules\SnapShot\SamplerCli.dll] [ , 1, 0, 0, 1002]
[F:\anzhuang\FlashGet\explorerbar.dll] [Ingo A. Kubbilun, 1, 0, 0, 1]
[F:\anzhuang\FlashGet\testwrap.dll] [N/A, ]
[F:\anzhuang\FlashGet\btwrap.dll] [FLASHGET, 1, 0, 1, 1007]
[F:\anzhuang\FlashGet\btcore.dll] [FLASHGET, ]
[F:\anzhuang\FlashGet\p2spmgr.dll] [FLASHGET, 1, 8, 11, 24]
[F:\anzhuang\FlashGet\p2snetio.dll] [FLASHGET, 1, 0, 0, 7925]
[F:\anzhuang\FlashGet\p2sprot.dll] [FLASHGET, 1, 8, 11, 17]
[F:\anzhuang\FlashGet\p2pprot.dll] [FLASHGET, 1, 8, 11, 17]
[F:\anzhuang\FlashGet\p2pcore.dll] [FlashGet, 1.0.6.1071]
[F:\anzhuang\FlashGet\p2spwrap.dll] [FLASHGET, 1, 0, 1, 1008]
[F:\anzhuang\FlashGet\hashgen.dll] [FLASHGET, 1, 0, 0, 1]
[C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0]
[F:\安装\瑞星\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[PID: 1608 / SYSTEM][C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE] [Microsoft Corporation, 11.0.5525]
[PID: 2708 / Administrator][F:\anzhuang\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[f:\安装\瑞星\rising\rfw\ijt_base.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.10]
[f:\安装\瑞星\rising\rfw\olemon.dll] [Beijing Rising Technology Co., Ltd., 7.0.0.6]
[F:\anzhuang\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 2076, F:\安装\瑞星\卡卡\RUNIEP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2076, F:\安装\瑞星\卡卡\RUNIEP.EXE]
==================================
API HOOK
入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: 0x00E81FFD)
入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: 0x00E820E5)
==================================
隐藏进程
N/A
==================================
[/CODE]