瑞星卡卡安全论坛
damadaha - 2006-6-2 21:17:00
在任务管理器里看到的`不能结束`每次开机变化成新的数字和字母`知道的帮忙解决一下吧`谢谢了!
damadaha - 2006-6-2 21:18:00
damadaha - 2006-6-2 21:18:00
damadaha - 2006-6-2 21:13:00
帮忙看看日志吧`好象还有别的病毒``谢谢帮忙了!
HijackThis_815汉化版扫描日志 V1.99.1
保存于 21:10:48, 日期 2006-6-2
操作系统: Windows XP (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 (6.00.2600.0000)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rfw\rfwsrv.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Rising\Rfw\RfwMain.exe
C:\WINDOWS\System32\00THotkey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\System32\TFNF5.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\System32\conime.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\System32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\拼音加加4.o\jj4\jjsvr4.exe
C:\Program Files\淘宝网\淘宝旺旺\WangWang.exe
C:\Program Files\Tencent\qq\QQ.exe
C:\Program Files\Tencent\qq\QQ.exe
C:\Program Files\Tencent\qq\QQ.exe
C:\Program Files\Tencent\qq\QQ.exe
C:\Program Files\Tencent\qq\QQ.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Iparmor\Iparmor.exe
C:\Program Files\Tencent\TT\TTraveler.exe
C:\Program Files\KuGoo3\KuGoo.exe
C:\WINDOWS\TEMP\CAB1.tmp
C:\Program Files\HijackThis1991汉化版\HijackThis1991zww.exe
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - 启动项HKLM\\Run: [nwiz] nwiz.exe /installquiet
O4 - 启动项HKLM\\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - 启动项HKLM\\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - 启动项HKLM\\Run: [TFNF5] TFNF5.exe
O4 - 启动项HKLM\\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - 启动项HKLM\\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - 启动项HKLM\\Run: [TFncKy] TFncKy.exe /Type 20
O4 - 启动项HKLM\\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe"
O4 - 启动项HKLM\\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [MoveSearch] C:\Program Files\wsearch\Search.exe
O4 - 启动项HKLM\\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [pyjj] C:\Program Files\拼音加加4.o\jj4\jjsvr4.exe
O4 - HKCU\..\Run: [Outlook] C:\Program Files\Common Files\System\Explore.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 查看 Exif 信息(&V) - res://C:\Program Files\Exif Show\ExShow.dll/EXSHOW.HTML
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\qq\SendMMS.htm
O9 - 浏览器额外的按钮: (no name) - AutorunsDisabled - (no file)
O9 - 浏览器额外的按钮: 实用网址导航 - {1D901067-2529-4A9B-9B6B-7A1DB3A44CB5} - C:\Program Files\CoolWebsite\QuickLink.dll (file missing)
O16 - DPF: {0150EB11-5FB4-4D9E-85EA-0F155705227E} (Yahoo! 相册轻松上载工具 Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_7cn.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/1007/aliedit.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {C661F36D-DF85-4EF4-83C7-E107B83D04B1} (WebActivater Control) - http://dl_dir.qq.com/3dshow/3DShowVM.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0BEF21E3-E8A7-4FFA-85A4-6E025A27E6C1}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{2C1FB4EA-3BBA-4A06-8848-FD274C63EDEA}: NameServer = 202.99.160.68 202.99.166.4
O18 - 列举现有的协议: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: SensSrv - C:\WINDOWS\SYSTEM32\senssrv.dll
O20 - Winlogon Notify: WebCheck - C:\WINDOWS\system32\fn0021dmg.dll (file missing)
O21 - SSODL: SysTray.Exgl - {636821FC-6F5C-2f1b-B164-E67214F678E2} - C:\WINDOWS\System32\qnflhoaa.dll
O23 - NT 服务: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - NT 服务: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - NT 服务: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - C:\Program Files\Rising\Rfw\rfwsrv.exe
O23 - NT 服务: Print Spooler (Spooler) - Unknown owner - C:\WINDOWS\system32\spoolsv.exe (file missing)
我无邪 - 2006-6-2 21:15:00
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。
我无邪 - 2006-6-2 21:22:00
请到www.27814939.ys168.com下载诺顿进程管理器终止所有CAB1.tmp,C:\Program Files\Common Files\System\Explore.exe的进程
控制面板-添加或删除程序-卸载网络猪
关闭所有浏览窗口以及一些不必要的程序
运行Hijackthis,扫描结束后在下列选项前打上勾,然后选"修复""
O4 - 启动项HKLM\\Run: [MoveSearch] C:\Program Files\wsearch\Search.exe
O4 - HKCU\..\Run: [Outlook] C:\Program Files\Common Files\System\Explore.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O20 - Winlogon Notify: WebCheck - C:\WINDOWS\system32\fn0021dmg.dll (file missing)
O21 - SSODL: SysTray.Exgl - {636821FC-6F5C-2f1b-B164-E67214F678E2} - C:\WINDOWS\System32\qnflhoaa.dll(这项不知道,是否修复请三思)
双击我的电脑--工具---文件夹选项--查看--单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示您确定更改时,单击“是”
删除
C:\WINDOWS\TEMP所有能删除的东东
C:\Program Files\wsearch
C:\Program Files\Common Files\System\Explore.exe
damadaha - 2006-6-3 21:57:00
2006-06-02,21:48:00
System Repair Engineer 2.0.12.350 (2.0 RC 1)
Windows XP Home Edition - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><; C:\WINDOWS\System32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<pyjj><C:\Program Files\拼音加加4.o\jj4\jjsvr4.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Outlook><; C:\Program Files\Common Files\System\Explore.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<HOMESyn.exe><; D:\HomeSchoolAII\HOMESyn.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Key><; C:\DOCUME~1\maxiang\LOCALS~1\Temp\21.tmp>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<KuGoo3><; "C:\Program Files\KuGoo3\KuGoo.exe">
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Windows update loader><; C:\Windows\xpupdate.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<run><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE NvQTwk,NvCplDaemon initialize>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<nwiz><nwiz.exe /installquiet>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<00THotkey><C:\WINDOWS\System32\00THotkey.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Apoint><C:\Program Files\Apoint2K\Apoint.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TFNF5><TFNF5.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TouchED><C:\Program Files\TOSHIBA\TouchED\TouchED.Exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Tpwrtray><TPWRTRAY.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TFncKy><TFncKy.exe /Type 20>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TosHKCW.exe><"C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<MoveSearch><; C:\Program Files\wsearch\Search.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<StormCodec_Helper><; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ANX MICROSOFT SYSTEM><; winanx.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<explore><; C:\WINDOWS\System32\mshost.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMEKRMIG6.1><; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<iTunesHelper><; "C:\Program Files\iTunes\iTunesHelper.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<netfilt4><; C:\WINDOWS\System32\netfilt4.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<QuickTime Task><; "C:\Program Files\QuickTime\qttask.exe" -atboottime>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Spooler SubSystem App><; C:\WINDOWS\System32\spoolsvc.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<spoolsv><; C:\WINDOWS\System32\spoolsv\spoolsv.exe -printer>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<spoolsvv><; C:\WINDOWS\System32\spoolsvv.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<System><; C:\WINDOWS\System32\kernels8.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Thunder><; "C:\Program Files\Thunder Network\Thunder\ThunderShell.exe" /s>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Update><; C:\Program Files\Common Files\UPDAT\Update.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Windows木马防火墙><; C:\Program Files\ftc\Trojanwall.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<winsysupd><; C:\windows\winsysupd7.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<yassistse><; "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<YLive.exe><; C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\System32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
==================================
damadaha - 2006-6-3 21:59:00
启动文件夹
服务
[Network IPSEC Connections / 8NASCAR]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
[InstallDriver Table Manager / IDriverT]
<C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe><Macrovision Corporation>
[IMAPI CD-Burning COM Service / ImapiService]
<C:\WINDOWS\System32\imapi.exe><Microsoft Corporation>
[iPodService / iPodService]
<C:\Program Files\iPod\bin\iPodService.exe><N/A>
[NVIDIA Driver Helper Service / NVSvc]
<C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[Rising Personal Firewall Service / RfwService]
<C:\Program Files\Rising\Rfw\rfwsrv.exe><Beijing Rising Technology Corporation Limited>
[Print Spooler / Spooler]
<C:\WINDOWS\system32\spoolsv.exe><N/A>
==================================
浏览器加载项
[QuickBtn]
{1D901067-2529-4A9B-9B6B-7A1DB3A44CB5} <C:\Program Files\CoolWebsite\QuickLink.dll, N/A>
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[Yahoo! 相册轻松上载工具 Class]
{0150EB11-5FB4-4D9E-85EA-0F155705227E} <C:\WINDOWS\Downloaded Program Files\YDropperCN.dll, Yahoo! Inc.>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\System32\LegitCheckControl.DLL, Microsoft Corporation>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\System32\aliedit\AliEdit.dll, www.alipay.com>
[MSN Photo Upload Tool]
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[AxSubmitControl Class]
{8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} <C:\WINDOWS\DOWNLO~1\SUBMIT~1.DLL, >
[WebActivater Control]
{C661F36D-DF85-4EF4-83C7-E107B83D04B1} <C:\WINDOWS\System32\3DShowVM.ocx, QQ>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[&使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\getallurl.htm, N/A>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[查看 Exif 信息(&V)]
<res://C:\Program Files\Exif Show\ExShow.dll/EXSHOW.HTML, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\qq\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 320][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>
[C:\WINDOWS\System32\qnflhoaa.dll] <N/A><N/A>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[C:\WINDOWS\System32\RAVEXT.DLL] <Beijing Rising Technology Co., Ltd.><17, 0, 0, 8>
[C:\PROGRA~1\ftc\Commenu.dll] <Fygsoft and Microsoft><3.0.0.63>
[C:\WINDOWS\System32\PYJJ4.IME] <加加工作组><4.0.0.20>
[PID: 452][C:\Program Files\Rising\Rfw\RfwMain.exe] <Beijing Rising Technology Corporation Limited><3, 1, 0, 18>
[C:\Program Files\Rising\Rfw\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><17, 0, 0, 40>
[C:\Program Files\Rising\Rfw\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
[C:\Program Files\Rising\Rfw\PngDll.dll] <Rising><17, 0, 0, 2>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1028][C:\WINDOWS\System32\00THotkey.exe] <东芝公司><1, 0, 0, 12>
[C:\WINDOWS\system32\TSCI.DLL] <Toshiba><1.0.0.0>
[C:\WINDOWS\system32\THCI.DLL] <Toshiba><1.0.0.0>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1148][C:\Program Files\Apoint2K\Apoint.exe] <Alps Electric Co., Ltd.><5.3.6.128>
[C:\WINDOWS\System32\VXDIF.DLL] <Alps Electric Co., Ltd.><5.3.1.47>
[C:\Program Files\Apoint2K\Apoint.DLL] <Alps Electric Co., Ltd.><5.3.305.172>
[C:\Program Files\Apoint2K\EzAuto.dll] <Alps Electric Co., Ltd.><4.5.1.82>
[C:\Program Files\Apoint2K\EzLaunch.DLL] <Alps Electric Co., Ltd.><4.5.0.46>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1220][C:\WINDOWS\System32\TFNF5.exe] <Toshiba Corp.><1. 0. 1. 0>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1280][C:\Program Files\Apoint2K\Apntex.exe] <Alps Electric Co., Ltd.><5.0.1.13>
[C:\WINDOWS\System32\VXDIF.DLL] <Alps Electric Co., Ltd.><5.3.1.47>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1276][C:\WINDOWS\System32\conime.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1432][C:\Program Files\TOSHIBA\TouchED\TouchED.Exe] <东芝公司><2, 0, 1, 6>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1440][C:\WINDOWS\System32\TPWRTRAY.EXE] <东芝公司><5.07.14>
[C:\WINDOWS\System32\TPwrReg.dll] <东芝公司><5.06.6>
[C:\WINDOWS\System32\Tdevdetect.dll] <东芝公司><5.07.14>
[C:\WINDOWS\system32\TSCI.DLL] <Toshiba><1.0.0.0>
[C:\WINDOWS\system32\THCI.DLL] <Toshiba><1.0.0.0>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1468][C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe] <TOSHIBA Corporation><2.39>
[C:\WINDOWS\System32\THCI.dll] <Toshiba><1.0.0.0>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1556][C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe] <TOSHIBA CORPORATION><2, 0, 0, 1>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1764][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3510>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1772][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1636][C:\Program Files\拼音加加4.o\jj4\jjsvr4.exe] <加加开发组><4.0.0.19>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 392][C:\Program Files\淘宝网\淘宝旺旺\WangWang.exe] <淘宝(中国)软件有限公司><1, 5, 5, 1226>
[C:\Program Files\淘宝网\淘宝旺旺\AliViewCtrl.dll] <vline><1, 0, 0, 1>
[C:\Program Files\淘宝网\淘宝旺旺\VLNetwork.dll] <><1, 0, 0, 6>
[C:\Program Files\淘宝网\淘宝旺旺\AliViewMedia.dll] <vline><1, 0, 0, 1>
[C:\Program Files\淘宝网\淘宝旺旺\VideoCAP.dll] <><1, 0, 0, 4>
[C:\Program Files\淘宝网\淘宝旺旺\VLAudio.dll] <><1, 0, 0, 4>
[C:\Program Files\淘宝网\淘宝旺旺\JsmShow.dll] <><1, 0, 0, 3>
[C:\Program Files\淘宝网\淘宝旺旺\Ali_Res.DLL] <N/A><N/A>
[C:\Program Files\淘宝网\淘宝旺旺\RichOne.dll] <淘宝(中国)软件有限公司><1.0.0.1>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <><17, 0, 0, 7>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\淘宝网\淘宝旺旺\WangWangX.dll] <><1, 0, 0, 1>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 664][C:\Program Files\Tencent\qq\QQ.exe] <TENCENT><0, 0, 0, 0>
[C:\Program Files\Tencent\qq\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\BasicCtrlDll.dll] <Tencent><5, 0, 200, 14>
[C:\Program Files\Tencent\qq\QQAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\LoginCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\npkcntc.dll] <INCA Internet Co., Ltd.><2005, 9, 1, 1>
[C:\Program Files\Tencent\qq\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[C:\Program Files\Tencent\qq\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\NewSkin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\HostingMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\CameraDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\MailSummary.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQSpace.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQAllInOne.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\SCCore.dll] <N/A><N/A>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQGroupMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\UserDefinedHead.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQConfigPlugin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\LongConnection.dll] <tencent><5, 0, 201, 14>
[C:\Program Files\Tencent\qq\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\FlashAvatarDll.dll] <><1, 4, 0, 1>
[C:\Program Files\Tencent\qq\BQQApplication.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CommercesMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\Program Files\Tencent\qq\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 140>
[C:\Program Files\Tencent\qq\QQSceneMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQCustomFace.dll] <N/A><N/A>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\Program Files\Tencent\qq\ImageOle.dll] <TODO: <Company name>><1.0.0.1>
[C:\WINDOWS\System32\PYJJ4.IME] <加加工作组><4.0.0.20>
[C:\Program Files\Tencent\qq\GroupConnection.dll] <Tencent><0, 3, 3, 5>
damadaha - 2006-6-3 22:00:00
[PID: 680][C:\Program Files\Tencent\qq\QQ.exe] <TENCENT><0, 0, 0, 0>
[C:\Program Files\Tencent\qq\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\BasicCtrlDll.dll] <Tencent><5, 0, 200, 14>
[C:\Program Files\Tencent\qq\QQAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\LoginCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\npkcntc.dll] <INCA Internet Co., Ltd.><2005, 9, 1, 1>
[C:\Program Files\Tencent\qq\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[C:\Program Files\Tencent\qq\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\NewSkin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\HostingMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\CameraDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\MailSummary.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQSpace.dll] <><1, 0, 0, 1>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQGroupMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\UserDefinedHead.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQAllInOne.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\SCCore.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQCustomFace.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\GroupConnection.dll] <Tencent><0, 3, 3, 5>
[C:\Program Files\Tencent\qq\QQConfigPlugin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\LongConnection.dll] <tencent><5, 0, 201, 14>
[C:\Program Files\Tencent\qq\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\FlashAvatarDll.dll] <><1, 4, 0, 1>
[C:\Program Files\Tencent\qq\QQPhoneHelper.dll] <腾讯科技(深圳)有限公司><2, 0, 3, 30>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\Program Files\Tencent\qq\QQMagicFace.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQSceneMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\ImageOle.dll] <TODO: <Company name>><1.0.0.1>
[C:\Program Files\Tencent\qq\BQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CommercesMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\Program Files\Tencent\qq\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 140>
[C:\Program Files\Tencent\qq\QQZip.dll] <tencent><0, 3, 2, 4>
[PID: 720][C:\Program Files\Tencent\qq\QQ.exe] <TENCENT><0, 0, 0, 0>
[C:\Program Files\Tencent\qq\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\BasicCtrlDll.dll] <Tencent><5, 0, 200, 14>
[C:\Program Files\Tencent\qq\QQAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\LoginCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\npkcntc.dll] <INCA Internet Co., Ltd.><2005, 9, 1, 1>
[C:\Program Files\Tencent\qq\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[C:\Program Files\Tencent\qq\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\NewSkin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\HostingMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\CameraDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\MailSummary.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQSpace.dll] <><1, 0, 0, 1>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQGroupMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\UserDefinedHead.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQConfigPlugin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\LongConnection.dll] <tencent><5, 0, 201, 14>
[C:\Program Files\Tencent\qq\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\FlashAvatarDll.dll] <><1, 4, 0, 1>
[C:\Program Files\Tencent\qq\BQQApplication.dll] <N/A><N/A>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CommercesMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\Program Files\Tencent\qq\QQUdpGetFileLib.dll] <tencent><0, 2, 2, 3>
[C:\Program Files\Tencent\qq\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 140>
[C:\Program Files\Tencent\qq\QQSceneMng.dll] <N/A><N/A>
[PID: 740][C:\Program Files\Tencent\qq\QQ.exe] <TENCENT><0, 0, 0, 0>
[C:\Program Files\Tencent\qq\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\BasicCtrlDll.dll] <Tencent><5, 0, 200, 14>
[C:\Program Files\Tencent\qq\QQAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\LoginCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\npkcntc.dll] <INCA Internet Co., Ltd.><2005, 9, 1, 1>
[C:\Program Files\Tencent\qq\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[C:\Program Files\Tencent\qq\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\NewSkin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\HostingMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\CameraDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\MailSummary.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQSpace.dll] <><1, 0, 0, 1>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQGroupMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQAllInOne.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\SCCore.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQCustomFace.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\GroupConnection.dll] <Tencent><0, 3, 3, 5>
[C:\Program Files\Tencent\qq\UserDefinedHead.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQConfigPlugin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\LongConnection.dll] <tencent><5, 0, 201, 14>
[C:\Program Files\Tencent\qq\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\FlashAvatarDll.dll] <><1, 4, 0, 1>
[C:\Program Files\Tencent\qq\BQQApplication.dll] <N/A><N/A>
[C:\WINDOWS\System32\l3codeca.acm] <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CommercesMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\Program Files\Tencent\qq\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 140>
[C:\Program Files\Tencent\qq\QQSceneMng.dll] <N/A><N/A>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
damadaha - 2006-6-3 22:01:00
[PID: 1088][C:\Program Files\Tencent\qq\QQ.exe] <TENCENT><0, 0, 0, 0>
[C:\Program Files\Tencent\qq\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\BasicCtrlDll.dll] <Tencent><5, 0, 200, 14>
[C:\Program Files\Tencent\qq\QQAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\LoginCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\npkcntc.dll] <INCA Internet Co., Ltd.><2005, 9, 1, 1>
[C:\Program Files\Tencent\qq\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[C:\Program Files\Tencent\qq\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\NewSkin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\HostingMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\CameraDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\MailSummary.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQSpace.dll] <><1, 0, 0, 1>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQGroupMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\UserDefinedHead.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQAllInOne.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\SCCore.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQCustomFace.dll] <N/A><N/A>
[C:\WINDOWS\System32\l3codeca.acm] <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\FlashAvatarDll.dll] <><1, 4, 0, 1>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\Program Files\Tencent\qq\ImageOle.dll] <TODO: <Company name>><1.0.0.1>
[C:\Program Files\Tencent\qq\QQMagicFace.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQSceneMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\LongConnection.dll] <tencent><5, 0, 201, 14>
[C:\Program Files\Tencent\qq\QQConfigPlugin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\GroupConnection.dll] <Tencent><0, 3, 3, 5>
[C:\Program Files\Tencent\qq\QQZip.dll] <tencent><0, 3, 2, 4>
[C:\Program Files\Tencent\qq\BQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CommercesMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\Program Files\Tencent\qq\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 140>
[PID: 2160][C:\WINDOWS\System32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 484][C:\Program Files\Iparmor\Iparmor.exe] <luosoft.com><5.5.0.0>
[C:\Program Files\Iparmor\getportlistxp.dll] <><1, 0, 0, 1>
[C:\Program Files\Iparmor\socketinit.dll] <N/A><N/A>
[C:\Program Files\Iparmor\hookhookdll.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <><17, 0, 0, 7>
[PID: 2776][C:\Program Files\Tencent\TT\TTraveler.exe] <腾讯公司><3.0.0.246>
[C:\Program Files\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll] <腾讯公司><1, 1, 0, 5>
[C:\Program Files\Tencent\TT\Plugins\TWeather\TWeather.dll] <><1, 0, 0, 3>
[C:\Program Files\Tencent\TT\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <><17, 0, 0, 7>
[C:\WINDOWS\System32\PYJJ4.IME] <加加工作组><4.0.0.20>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[PID: 3084][C:\Program Files\KuGoo3\KuGoo.exe] <><3.2.0.71>
[C:\Program Files\KuGoo3\RandomShuffle.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <><17, 0, 0, 7>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\WINDOWS\System32\PYJJ4.IME] <加加工作组><4.0.0.20>
[C:\Program Files\KuGoo3\OggSplitter.dll] <RadLight><1.0.0.2>
[C:\Program Files\KuGoo3\kgmpg.dll] < ><1, 0, 4, 1>
[C:\Program Files\KuGoo3\mp3parse.dll] < ><1, 0, 2, 1>
[PID: 3948][C:\Program Files\Thunder Network\Thunder\Thunder.exe] <Thunder Networking Technologies,LTD><5.1.5.189>
[C:\Program Files\Thunder Network\Thunder\UpdateDownload.dll] <Thunder Networking Technologies,LTD><1, 0, 0, 2>
[C:\Program Files\Thunder Network\Thunder\download_interface.dll] <Thunder Networking Technologies,LTD><1, 0, 2, 74>
[C:\Program Files\Thunder Network\Thunder\log4cplus.dll] <><1, 0, 2, 1>
[C:\Program Files\Thunder Network\Thunder\stlport_vc646.dll] <STLport Consulting, Inc.><4.6.2003.1031>
[C:\Program Files\Thunder Network\Thunder\msgmanage.dll] <Thunder Networking Technologies,LTD><1, 0, 0, 15>
[C:\Program Files\Thunder Network\Thunder\historyinfo_manage.dll] <Thunder Networking Technologies,LTD><5, 2, 0, 148>
[C:\Program Files\Thunder Network\Thunder\iEmbed.dll] <Thunder Networking Technologies,LTD><1, 1, 0, 22>
[C:\Program Files\Thunder Network\Thunder\RegisterDll.dll] <Thunder Networking Technologies,LTD><1, 2, 0, 7>
[C:\Program Files\Thunder Network\Thunder\FloatBar.dll] <Thunder Networking Technologies,LTD><1, 0, 0, 2>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <><17, 0, 0, 7>
[C:\Program Files\Thunder Network\Thunder\iTargetAd.dll] <Thunder Networking Technologies,LTD><1, 0, 0, 59>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\WINDOWS\System32\PYJJ4.IME] <加加工作组><4.0.0.20>
[PID: 3044][D:\MMMXXX\xiazai\System Repair Engineer智能扫描 日志\SREng.exe] <Smallfrogs Studio><2.0.12.350>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
damadaha - 2006-6-3 22:03:00
贴完了``好多啊`谢谢我无邪的帮助``
damadaha - 2006-6-3 22:45:00
诺顿进程管理器--不能终止6EB0.tmp C403.tmp
添加或删除程序--找不到网络猪
C:\WINDOWS\TEMP所有能删除的东东--不能删除6EB0.tmp C403.tmp(KillBox也不能)
C:\Program Files\wsearch--找不到wsearch
C:\Program Files\Common Files\System\Explore.exe--找不到Explore.exe
另外木马克星总提示Explore.exe正在盗取密码或者企图访问网络
帮忙解决一下吧!万分感谢!
damadaha - 2006-6-4 0:02:00
顶一下
damadaha - 2006-6-5 18:53:00
帮一下忙吧谢谢了
我无邪 - 2006-6-5 20:46:00
使用System Repair Engineer,再扫份报告粘上来。
damadaha - 2006-6-5 22:10:00
2006-06-05,22:08:38
System Repair Engineer 2.0.12.350 (2.0 RC 1)
Windows XP Home Edition - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<pyjj><C:\Program Files\拼音加加4.o\jj4\jjsvr4.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<HOMESyn.exe><; D:\HomeSchoolAII\HOMESyn.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Key><; C:\DOCUME~1\maxiang\LOCALS~1\Temp\21.tmp>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<KuGoo3><; "C:\Program Files\KuGoo3\KuGoo.exe">
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<run><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<nwiz><nwiz.exe /installquiet>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<00THotkey><C:\WINDOWS\System32\00THotkey.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Apoint><C:\Program Files\Apoint2K\Apoint.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TFNF5><TFNF5.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TouchED><C:\Program Files\TOSHIBA\TouchED\TouchED.Exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Tpwrtray><TPWRTRAY.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TFncKy><TFncKy.exe /Type 20>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TosHKCW.exe><"C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<StormCodec_Helper><; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMEKRMIG6.1><; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<iTunesHelper><; "C:\Program Files\iTunes\iTunesHelper.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<QuickTime Task><; "C:\Program Files\QuickTime\qttask.exe" -atboottime>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<spoolsv><; C:\WINDOWS\System32\spoolsv\spoolsv.exe -printer>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Thunder><; "C:\Program Files\Thunder Network\Thunder\ThunderShell.exe" /s>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Update><; C:\Program Files\Common Files\UPDAT\Update.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Windows木马防火墙><; C:\Program Files\ftc\Trojanwall.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<yassistse><; "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<YLive.exe><; C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\System32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
==================================
damadaha - 2006-6-5 22:11:00
启动文件夹
服务
[Network IPSEC Connections / 8NASCAR]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
[InstallDriver Table Manager / IDriverT]
<C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe><Macrovision Corporation>
[IMAPI CD-Burning COM Service / ImapiService]
<C:\WINDOWS\System32\imapi.exe><Microsoft Corporation>
[iPodService / iPodService]
<C:\Program Files\iPod\bin\iPodService.exe><N/A>
[NVIDIA Driver Helper Service / NVSvc]
<C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[Rising Personal Firewall Service / RfwService]
<C:\Program Files\Rising\Rfw\rfwsrv.exe><Beijing Rising Technology Corporation Limited>
[Print Spooler / Spooler]
<C:\WINDOWS\system32\spoolsv.exe><N/A>
==================================
damadaha - 2006-6-5 22:12:00
浏览器加载项
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll, N/A>
[Google Toolbar Helper]
{AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[QuickBtn]
{1D901067-2529-4A9B-9B6B-7A1DB3A44CB5} <C:\Program Files\CoolWebsite\QuickLink.dll, N/A>
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[Yahoo! 相册轻松上载工具 Class]
{0150EB11-5FB4-4D9E-85EA-0F155705227E} <C:\WINDOWS\Downloaded Program Files\YDropperCN.dll, Yahoo! Inc.>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\System32\LegitCheckControl.DLL, Microsoft Corporation>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\System32\aliedit\AliEdit.dll, www.alipay.com>
[MSN Photo Upload Tool]
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[AxSubmitControl Class]
{8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} <C:\WINDOWS\DOWNLO~1\SUBMIT~1.DLL, >
[WebActivater Control]
{C661F36D-DF85-4EF4-83C7-E107B83D04B1} <C:\WINDOWS\System32\3DShowVM.ocx, QQ>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[&使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[Google 搜索(&G)]
<res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html, N/A>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[反向链接]
<res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html, N/A>
[查看 Exif 信息(&V)]
<res://C:\Program Files\Exif Show\ExShow.dll/EXSHOW.HTML, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\qq\SendMMS.htm, N/A>
[类似网页]
<res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html, N/A>
[缓存的网页快照]
<res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html, N/A>
[翻译英文字词(&T)]
<res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html, N/A>
==================================
damadaha - 2006-6-5 22:12:00
正在运行的进程
[PID: 1124][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>
[C:\WINDOWS\System32\qnflhoaa.dll] <N/A><N/A>
[C:\WINDOWS\System32\PYJJ4.IME] <加加工作组><4.0.0.20>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[C:\WINDOWS\System32\RAVEXT.DLL] <Beijing Rising Technology Co., Ltd.><17, 0, 0, 8>
[C:\PROGRA~1\ftc\Commenu.dll] <Fygsoft and Microsoft><3.0.0.63>
[C:\Program Files\Real\RealPlayer\rpshell.dll] <RealNetworks, Inc.><1.0.1.2237>
[C:\WINDOWS\System32\PNCRT.dll] <Real Networks, Inc><6.0.0.0>
[C:\Program Files\Real\RealPlayer\lang\rpext_cn.dll] <RealNetworks, Inc.><6.0.12.298>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[PID: 1384][C:\Program Files\Rising\Rfw\RfwMain.exe] <Beijing Rising Technology Corporation Limited><3, 1, 0, 18>
[C:\Program Files\Rising\Rfw\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><17, 0, 0, 40>
[C:\Program Files\Rising\Rfw\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
[C:\Program Files\Rising\Rfw\PngDll.dll] <Rising><17, 0, 0, 2>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1708][C:\WINDOWS\System32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1752][C:\WINDOWS\System32\00THotkey.exe] <东芝公司><1, 0, 0, 12>
[C:\WINDOWS\system32\TSCI.DLL] <Toshiba><1.0.0.0>
[C:\WINDOWS\system32\THCI.DLL] <Toshiba><1.0.0.0>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1856][C:\Program Files\Apoint2K\Apoint.exe] <Alps Electric Co., Ltd.><5.3.6.128>
[C:\WINDOWS\System32\VXDIF.DLL] <Alps Electric Co., Ltd.><5.3.1.47>
[C:\Program Files\Apoint2K\Apoint.DLL] <Alps Electric Co., Ltd.><5.3.305.172>
[C:\Program Files\Apoint2K\EzAuto.dll] <Alps Electric Co., Ltd.><4.5.1.82>
[C:\Program Files\Apoint2K\EzLaunch.DLL] <Alps Electric Co., Ltd.><4.5.0.46>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1892][C:\Program Files\Apoint2K\Apntex.exe] <Alps Electric Co., Ltd.><5.0.1.13>
[C:\WINDOWS\System32\VXDIF.DLL] <Alps Electric Co., Ltd.><5.3.1.47>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1912][C:\WINDOWS\System32\conime.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1924][C:\WINDOWS\System32\TFNF5.exe] <Toshiba Corp.><1. 0. 1. 0>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1940][C:\Program Files\TOSHIBA\TouchED\TouchED.Exe] <东芝公司><2, 0, 1, 6>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1168][C:\WINDOWS\System32\TPWRTRAY.EXE] <东芝公司><5.07.14>
[C:\WINDOWS\System32\TPwrReg.dll] <东芝公司><5.06.6>
[C:\WINDOWS\System32\Tdevdetect.dll] <东芝公司><5.07.14>
[C:\WINDOWS\system32\TSCI.DLL] <Toshiba><1.0.0.0>
[C:\WINDOWS\system32\THCI.DLL] <Toshiba><1.0.0.0>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1392][C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe] <TOSHIBA Corporation><2.39>
[C:\WINDOWS\System32\THCI.dll] <Toshiba><1.0.0.0>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 156][C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe] <TOSHIBA CORPORATION><2, 0, 0, 1>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1064][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3510>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 252][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 200][C:\Program Files\拼音加加4.o\jj4\jjsvr4.exe] <加加开发组><4.0.0.19>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[PID: 1364][C:\Program Files\淘宝网\淘宝旺旺\WangWang.exe] <淘宝(中国)软件有限公司><1, 5, 5, 1226>
[C:\Program Files\淘宝网\淘宝旺旺\AliViewCtrl.dll] <vline><1, 0, 0, 1>
[C:\Program Files\淘宝网\淘宝旺旺\VLNetwork.dll] <><1, 0, 0, 6>
[C:\Program Files\淘宝网\淘宝旺旺\AliViewMedia.dll] <vline><1, 0, 0, 1>
[C:\Program Files\淘宝网\淘宝旺旺\VideoCAP.dll] <><1, 0, 0, 4>
[C:\Program Files\淘宝网\淘宝旺旺\VLAudio.dll] <><1, 0, 0, 4>
[C:\Program Files\淘宝网\淘宝旺旺\JsmShow.dll] <><1, 0, 0, 3>
[C:\Program Files\淘宝网\淘宝旺旺\Ali_Res.DLL] <N/A><N/A>
[C:\Program Files\淘宝网\淘宝旺旺\RichOne.dll] <淘宝(中国)软件有限公司><1.0.0.1>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <><17, 0, 0, 7>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\淘宝网\淘宝旺旺\WangWangX.dll] <><1, 0, 0, 1>
[C:\WINDOWS\System32\PYJJ4.IME] <加加工作组><4.0.0.20>
damadaha - 2006-6-5 22:13:00
[PID: 1560][C:\Program Files\Iparmor\Iparmor.exe] <luosoft.com><5.5.0.0>
[C:\Program Files\Iparmor\getportlistxp.dll] <><1, 0, 0, 1>
[C:\Program Files\Iparmor\socketinit.dll] <N/A><N/A>
[C:\Program Files\Iparmor\hookhookdll.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <><17, 0, 0, 7>
[PID: 412][C:\Program Files\Tencent\qq\QQ.exe] <TENCENT><0, 0, 0, 0>
[C:\Program Files\Tencent\qq\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\BasicCtrlDll.dll] <Tencent><5, 0, 200, 14>
[C:\Program Files\Tencent\qq\QQAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\LoginCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\npkcntc.dll] <INCA Internet Co., Ltd.><2005, 9, 1, 1>
[C:\Program Files\Tencent\qq\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[C:\Program Files\Tencent\qq\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\NewSkin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\HostingMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\CameraDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\MailSummary.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQSpace.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQAllInOne.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\SCCore.dll] <N/A><N/A>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQGroupMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\UserDefinedHead.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQConfigPlugin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\FlashAvatarDll.dll] <><1, 4, 0, 1>
[C:\Program Files\Tencent\qq\LongConnection.dll] <tencent><5, 0, 201, 14>
[C:\Program Files\Tencent\qq\BQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CommercesMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\Program Files\Tencent\qq\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 140>
[C:\Program Files\Tencent\qq\QQSceneMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <><17, 0, 0, 7>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\Program Files\Tencent\qq\QQCustomFace.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\ImageOle.dll] <TODO: <Company name>><1.0.0.1>
[C:\Program Files\Tencent\qq\QQMagicFace.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\GroupConnection.dll] <Tencent><0, 3, 3, 5>
[PID: 664][C:\Program Files\Tencent\qq\QQ.exe] <TENCENT><0, 0, 0, 0>
[C:\Program Files\Tencent\qq\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\BasicCtrlDll.dll] <Tencent><5, 0, 200, 14>
[C:\Program Files\Tencent\qq\QQAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\LoginCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\npkcntc.dll] <INCA Internet Co., Ltd.><2005, 9, 1, 1>
[C:\Program Files\Tencent\qq\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[C:\Program Files\Tencent\qq\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\NewSkin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\HostingMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\CameraDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\MailSummary.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQSpace.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\UserDefinedHead.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQConfigPlugin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\FlashAvatarDll.dll] <><1, 4, 0, 1>
[C:\Program Files\Tencent\qq\BQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CommercesMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\Program Files\Tencent\qq\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 140>
[C:\Program Files\Tencent\qq\QQSceneMng.dll] <N/A><N/A>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQAllInOne.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\SCCore.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQGroupMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\LongConnection.dll] <tencent><5, 0, 201, 14>
[C:\Program Files\Tencent\qq\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQCustomFace.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\GroupConnection.dll] <Tencent><0, 3, 3, 5>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\Program Files\Tencent\qq\ImageOle.dll] <TODO: <Company name>><1.0.0.1>
[C:\Program Files\Tencent\qq\QQZip.dll] <tencent><0, 3, 2, 4>
[C:\Program Files\Tencent\qq\VqqModule.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\VqqAllInOne.dll] <Tencent><1, 5, 0, 2>
[C:\Program Files\Tencent\qq\tencent-proto1.dll] <Tencent><1.5.0.0>
[C:\Program Files\Tencent\qq\tencent-comlib.dll] <Tencent><1.5.0.0>
[C:\Program Files\Tencent\qq\tencent-proto2.dll] <Tencent><1.5.0.0>
[C:\Program Files\Tencent\qq\QQOneClick.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQMagicFace.dll] <><1, 0, 0, 1>
[C:\WINDOWS\System32\PYJJ4.IME] <加加工作组><4.0.0.20>
[PID: 704][C:\Program Files\Tencent\qq\QQ.exe] <TENCENT><0, 0, 0, 0>
[C:\Program Files\Tencent\qq\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\BasicCtrlDll.dll] <Tencent><5, 0, 200, 14>
[C:\Program Files\Tencent\qq\QQAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\LoginCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\npkcntc.dll] <INCA Internet Co., Ltd.><2005, 9, 1, 1>
[C:\Program Files\Tencent\qq\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[C:\Program Files\Tencent\qq\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\NewSkin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\HostingMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\CameraDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\MailSummary.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQSpace.dll] <><1, 0, 0, 1>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQGroupMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\UserDefinedHead.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQConfigPlugin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\FlashAvatarDll.dll] <><1, 4, 0, 1>
[C:\Program Files\Tencent\qq\LongConnection.dll] <tencent><5, 0, 201, 14>
[C:\Program Files\Tencent\qq\BQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CommercesMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\Program Files\Tencent\qq\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 140>
[C:\Program Files\Tencent\qq\QQSceneMng.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <><17, 0, 0, 7>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
damadaha - 2006-6-5 22:13:00
[PID: 1132][C:\Program Files\Tencent\qq\QQ.exe] <TENCENT><0, 0, 0, 0>
[C:\Program Files\Tencent\qq\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\BasicCtrlDll.dll] <Tencent><5, 0, 200, 14>
[C:\Program Files\Tencent\qq\QQAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\LoginCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\npkcntc.dll] <INCA Internet Co., Ltd.><2005, 9, 1, 1>
[C:\Program Files\Tencent\qq\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[C:\Program Files\Tencent\qq\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\NewSkin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\HostingMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\CameraDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\MailSummary.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQSpace.dll] <><1, 0, 0, 1>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQGroupMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\UserDefinedHead.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQAllInOne.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\SCCore.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQCustomFace.dll] <N/A><N/A>
[C:\WINDOWS\System32\l3codeca.acm] <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
[C:\Program Files\Tencent\qq\QQConfigPlugin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\FlashAvatarDll.dll] <><1, 4, 0, 1>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\Program Files\Tencent\qq\QQMagicFace.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\GroupConnection.dll] <Tencent><0, 3, 3, 5>
[C:\Program Files\Tencent\qq\QQSceneMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\LongConnection.dll] <tencent><5, 0, 201, 14>
[C:\Program Files\Tencent\qq\BQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\CommercesMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\qq\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\Program Files\Tencent\qq\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 140>
[C:\Program Files\Tencent\qq\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\qq\QQPhoneHelper.dll] <腾讯科技(深圳)有限公司><2, 0, 3, 30>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <><17, 0, 0, 7>
[PID: 464][C:\Program Files\Tencent\TT\TTraveler.exe] <腾讯公司><3.0.0.246>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
[C:\Program Files\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll] <腾讯公司><1, 1, 0, 5>
[C:\Program Files\Tencent\TT\Plugins\TWeather\TWeather.dll] <><1, 0, 0, 3>
[C:\Program Files\Tencent\TT\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <><17, 0, 0, 7>
[C:\WINDOWS\System32\PYJJ4.IME] <加加工作组><4.0.0.20>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[PID: 3328][C:\Program Files\KuGoo3\KuGoo.exe] <><3.2.0.73>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <><17, 0, 0, 7>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\WINDOWS\System32\PYJJ4.IME] <加加工作组><4.0.0.20>
[C:\Program Files\KuGoo3\kgmpg.dll] < ><1, 0, 4, 1>
[PID: 1448][C:\Program Files\eMule\eMule.exe] <http://www.emule.org.cn><0.47.0>
[C:\Program Files\eMule\VNNClientS.Dll] <VNN><3.0.22.1>
[C:\Program Files\eMule\ZipLib.dll] <VNN><1.0.0.1>
[C:\Program Files\eMule\vdevstate.dll] <N/A><N/A>
[C:\Program Files\eMule\lang\zh_CN.dll] <http://www.emule-project.net><0.47.0>
[C:\WINDOWS\System32\PYJJ4.IME] <加加工作组><4.0.0.20>
[PID: 2124][D:\MMMXXX\xiazai\System Repair Engineer智能扫描 日志\SREng.exe] <Smallfrogs Studio><2.0.12.350>
[C:\Program Files\Iparmor\SocketArmor.dll] <N/A><N/A>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
我无邪 - 2006-6-5 22:36:00
感觉你的这两个报告,有很大的不同
请问你的报告粘全且没有修改过的吗?
现以最后一个报告来修复
进入控制面版的添加删除程序中卸载W酷站导航(CoolWebsite)
运行System Repair Engineer,点“启动项目,服务,勾选“隐藏微软服务”选中病毒服务Network IPSEC Connections,选择“删除所选服务”“否”
重启
开机检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式进入Windows
关闭所有浏览窗口以及一些不必要的程序
运行System Repair Engineer,使用“系统修复,浏览器加载项”来删除以下选项。
[QuickBtn]
{1D901067-2529-4A9B-9B6B-7A1DB3A44CB5} <C:\Program Files\CoolWebsite\QuickLink.dll, N/A>
运行System Repair Engineer,使用“启动项目,注册表”来删除以下选项。
(如果在注册表里无法识别那一下,可以选中一项后,点“编辑”这样会有很明细的路径)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Key><; C:\DOCUME~1\maxiang\LOCALS~1\Temp\21.tmp(这项很顽固,是吗?)
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<spoolsv><; C:\WINDOWS\System32\spoolsv\spoolsv.exe -printer>
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Update><; C:\Program Files\Common Files\UPDAT\Update.exe>
如果还是无法解决,请把QQ通过悄悄话传来。
damadaha - 2006-6-6 19:10:00
我都是直接粘贴的 没有过修改
按你的方法操作了(不小心还多删除了个东西@_@)
现在任务管理器里看不到它的运行了
谢谢我无邪对我的帮助
1
© 2000 - 2026 Rising Corp. Ltd.