|
正在运行的进程
[PID: 540 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 604 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 628 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[PID: 676 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[PID: 688 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[PID: 852 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[PID: 920 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[PID: 1064 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\jwlah.dll] [N/A, ]
[C:\WINDOWS\System32\sehhter.dll] [N/A, ]
[C:\WINDOWS\System32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\System32\jzijj.dll] [N/A, ]
[C:\WINDOWS\System32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\System32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\System32\msepbe.dll] [N/A, ]
[PID: 1140 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[PID: 1304 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[PID: 1820 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[PID: 216 / SYSTEM][C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe] [Autodesk, 2.66.000]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[PID: 452 / SYSTEM][C:\WINDOWS\SoundMan.exe] [1, 1.00]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[C:\WINDOWS\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8169]
[PID: 992 / Administrator][C:\WINDOWS\system32\RunDll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[C:\WINDOWS\system\cmicnfg.cpl] [C-Media Corporation, 1, 0, 41, 16]
[C:\WINDOWS\System32\udaprop.dll] [C-Media Corporation, 1.0.2.2]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 16]
[C:\WINDOWS\system32\SHAProc.dat] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\PTSShell.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\WSockDrv32.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\NewSys55.Sys] [N/A, ]
[PID: 1012 / Administrator][C:\Program Files\ngsrv\epsng_certd_bjrcb.exe] [OEM, 1, 0, 7, 802]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[C:\WINDOWS\system32\bjrcb_11.dll] [OEM, 1, 1, 7, 802]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 16]
[C:\WINDOWS\system32\SHAProc.dat] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\PTSShell.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\WSockDrv32.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\NewSys55.Sys] [N/A, ]
[PID: 1192 / Administrator][C:\WINDOWS\system32\Rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 16]
[C:\WINDOWS\system32\SHAProc.dat] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\PTSShell.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\WSockDrv32.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\NewSys55.Sys] [N/A, ]
[PID: 1108 / SYSTEM][C:\Program Files\ngsrv\ngslotd.exe] [OEM, 1, 2, 7, 802]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[C:\Program Files\ngsrv\slotmon\hidmon.dll] [Feitian Technologies Co.,Ltd., 1, 0, 7, 802]
[PID: 2212 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[PID: 3820 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp243.tmp] [N/A, ]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[PID: 352 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 16]
[C:\Program Files\Internet Explorer\PLUGINS\NewSys55.Sys] [N/A, ]
[C:\WINDOWS\system32\SHAProc.dat] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\PTSShell.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\WSockDrv32.dll] [N/A, ]
[PID: 5628 / Administrator][F:\Program Files\Rising\Rav\Rav.exe] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 62]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 16]
[F:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[F:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[F:\Program Files\Rising\Rav\Rsguilib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 88]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[F:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0]
[F:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4]
[F:\Program Files\Rising\Rav\RsCommon.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[F:\Program Files\Rising\Rav\ravpagem.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 92]
[F:\Program Files\Rising\Rav\htmllib.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.15]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17]
[F:\Program Files\Rising\Rav\ravpagew.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 84]
[F:\Program Files\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0]
[F:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.10]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.2.54.0]
[F:\Program Files\Rising\Rav\fakescan.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.13]
[F:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.36]
[F:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.4]
[F:\Program Files\Rising\Rav\SysMail.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.10]
[F:\Program Files\Rising\Rav\RsStore.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.8]
[F:\Program Files\Rising\Rav\RsLog.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.34]
[F:\Program Files\Rising\Rav\recomp.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 27]
[F:\Program Files\Rising\Rav\refs.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 13]
[F:\Program Files\Rising\Rav\viruslib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17]
[F:\Program Files\Rising\Rav\relibldr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 13]
[F:\Program Files\Rising\Rav\mvengine.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 14]
[F:\Program Files\Rising\Rav\posttrt.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 14]
[F:\Program Files\Rising\Rav\ffr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 10]
[F:\Program Files\Rising\Rav\nvfile.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[F:\Program Files\Rising\Rav\scanexec.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 15]
[F:\Program Files\Rising\Rav\unexe.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4]
[F:\Program Files\Rising\Rav\scanex.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 44]
[F:\Program Files\Rising\Rav\pearc.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5]
[C:\Program Files\Internet Explorer\PLUGINS\NewSys55.Sys] [N/A, ]
[F:\Program Files\Rising\Rav\scanpack.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 8]
[F:\Program Files\Rising\Rav\revm.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 8]
[F:\Program Files\Rising\Rav\urutils.dll] [, 20, 0, 0, 3]
[F:\Program Files\Rising\Rav\ur000.dat] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[F:\Program Files\Rising\Rav\scriptci.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[F:\Program Files\Rising\Rav\uroutine.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26]
[F:\Program Files\Rising\Rav\extfile.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 29]
[C:\WINDOWS\system32\WSockDrv32.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\PTSShell.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\SHAProc.dat] [N/A, ]
[F:\Program Files\Rising\Rav\ur001.dat] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 2]
[F:\Program Files\Rising\Rav\extmail.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9]
[F:\Program Files\Rising\Rav\extole.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 11]
[F:\Program Files\Rising\Rav\scansct.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 6]
[C:\WINDOWS\system32\WINSvr32.dll] [N/A, ]
[C:\WINDOWS\system32\mfchlp32.dll] [N/A, ]
[C:\WINDOWS\system32\Kvsc3.dll] [N/A, ]
[C:\WINDOWS\system32\rzysdhbx.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dlL] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\fmsbbqi.dll] [N/A, ]
[C:\WINDOWS\system32\tciocp32.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\MsIMMs32.dll] [N/A, ]
[PID: 3128 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 16]
[C:\Program Files\TENCENT\SSPlus\SAddr1.dll] [Tencent, 5, 0, 6, 18]
[C:\Program Files\Internet Explorer\PLUGINS\NewSys55.Sys] [N/A, ]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.2.54.0]
[C:\Program Files\Tencent\QQToolbar\IEBar.dll] [TENCENT, 2, 0, 21, 10]
[C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\Toolbar.dll] [TENCENT, 2, 0, 21, 10]
[C:\WINDOWS\system32\SSup.dll] [TENCENT, 5, 0, 3, 11]
[C:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
[F:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx] [Adobe Systems, Inc., 9,0,115,0]
[C:\WINDOWS\system32\WSockDrv32.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\PTSShell.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\SHAProc.dat] [N/A, ]
[PID: 5292 / Administrator][C:\Program Files\WinRAR\WinRAR.exe] [N/A, ]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 16]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.2.54.0]
[C:\Program Files\Internet Explorer\PLUGINS\NewSys55.Sys] [N/A, ]
[C:\WINDOWS\system32\WSockDrv32.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\PTSShell.dll] [N/A, ]
[C:\WINDOWS\system32\SHAProc.dat] [N/A, ]
[C:\WINDOWS\system32\WINSvr32.dll] [N/A, ]
[C:\WINDOWS\system32\mfchlp32.dll] [N/A, ]
[C:\WINDOWS\system32\Kvsc3.dll] [N/A, ]
[C:\WINDOWS\system32\rzysdhbx.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dlL] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\fmsbbqi.dll] [N/A, ]
[C:\WINDOWS\system32\tciocp32.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\MsIMMs32.dll] [N/A, ]
[PID: 4616 / Administrator][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 16]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.2.54.0]
[C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] [Autodesk, 16.2.54.0]
[C:\WINDOWS\system32\msosiocp.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\NewSys55.Sys] [N/A, ]
[C:\WINDOWS\system32\WSockDrv32.dll] [N/A, ]
[C:\WINDOWS\system32\MsIMMs32.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\tciocp32.dll] [N/A, ]
[C:\WINDOWS\system32\fmsbbqi.dll] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dlL] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\rzysdhbx.dll] [N/A, ]
[C:\WINDOWS\system32\PTSShell.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\SHAProc.dat] [N/A, ]
[C:\WINDOWS\system32\Kvsc3.dll] [N/A, ]
[C:\WINDOWS\system32\mfchlp32.dll] [N/A, ]
[C:\WINDOWS\system32\WINSvr32.dll] [N/A, ]
[PID: 14492 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX13.52672\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll] [TENCENT, 5, 0, 3, 16]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX13.52672\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[C:\Program Files\Internet Explorer\PLUGINS\NewSys55.Sys] [N/A, ]
[C:\WINDOWS\system32\WSockDrv32.dll] [N/A, ]
[C:\WINDOWS\system32\MsIMMs32.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\PTSShell.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\SHAProc.dat] [N/A, ]
[C:\WINDOWS\system32\Kvsc3.dll] [N/A, ]
[C:\WINDOWS\system32\rzysdhbx.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dlL] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\fmsbbqi.dll] [N/A, ]
[C:\WINDOWS\system32\tciocp32.dll] [N/A, ]
[C:\WINDOWS\system32\mfchlp32.dll] [N/A, ]
[C:\WINDOWS\system32\WINSvr32.dll] [N/A, ]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.2.54.0]
[PID: 7232 / Administrator][C:\WINDOWS\system32\HHHCompress.dll] [N/A, ]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[C:\WINDOWS\system32\xdksydiwow.dll] [Microsoft Corporation, 5.1.2600.3099]
[PID: 6896 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp2FE.tmp] [N/A, ]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[PID: 17804 / SYSTEM][C:\WINDOWS\system32\qoq.exe] [N/A, ]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[PID: 18384 / SYSTEM][C:\WINDOWS\system32\qoq.exe] [N/A, ]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
[PID: 6116 / SYSTEM][C:\WINDOWS\system32\qoq.exe] [N/A, ]
[C:\WINDOWS\system32\jwlah.dll] [N/A, ]
[C:\WINDOWS\system32\sehhter.dll] [N/A, ]
[C:\WINDOWS\system32\xgnfn.dll] [N/A, ]
[C:\WINDOWS\system32\jzijj.dll] [N/A, ]
[C:\WINDOWS\system32\xbcvxb.dll] [N/A, ]
[C:\WINDOWS\system32\zdbfbd.dll] [N/A, ]
[C:\WINDOWS\system32\msepbe.dll] [N/A, ]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================
进程特权扫描
特殊特权被允许: SeSystemtimePrivilege [PID = 452, C:\WINDOWS\SOUNDMAN.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1012, C:\PROGRAM FILES\NGSRV\EPSNG_CERTD_BJRCB.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1108, C:\PROGRAM FILES\NGSRV\NGSLOTD.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3820, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\TMP243.TMP]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3820, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\TMP243.TMP]
特殊特权被允许: SeDebugPrivilege [PID = 5292, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 5292, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 7232, C:\WINDOWS\SYSTEM32\HHHCOMPRESS.DLL]
特殊特权被允许: SeLoadDriverPrivilege [PID = 7232, C:\WINDOWS\SYSTEM32\HHHCOMPRESS.DLL]
特殊特权被允许: SeDebugPrivilege [PID = 6896, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\TMP2FE.TMP]
特殊特权被允许: SeLoadDriverPrivilege [PID = 6896, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\TMP2FE.TMP]
特殊特权被允许: SeSystemtimePrivilege [PID = 17804, C:\WINDOWS\SYSTEM32\QOQ.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 18384, C:\WINDOWS\SYSTEM32\QOQ.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 6116, C:\WINDOWS\SYSTEM32\QOQ.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
|