瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 救命啊!怎么还是杀不掉QQ的像册病毒啊?还有删除不掉xiaran.dat这个文件?
明天一定努力 - 2006-6-6 21:40:00
我瑞星是今天(2006年6月6日)更新的18.30.12版本,我的QQ还是自动发送病毒信息,怎么办啊!我用的是2000 server 版系统,发送的病毒网址最后一个是数字4,不是2!
有朋友说删除xiaran.dat这个文件,可这个文件在安全模式下也删除不掉啊,结束几个应用这个文件的进程我也没给它删掉,都六天了,我的QQ还在发病毒......
轩辕小聪 - 2006-6-6 21:36:00
刘麻子?
http://forum.ikaka.com/topic.asp?board=28&artid=6979213下载Autoruns和System Repair Engineer 2.0.12.350导出日志。
注意用Autoruns的时候,必须先选Option-Hide Microsoft Entries,然后选Files-Refresh,然后再选Files-Save。
轩辕小聪 - 2006-6-6 21:38:00
还有,如果是worm.viking病毒的并发症,请先把worm.viking病毒搞定,在置顶帖有专杀的地址。
mopery - 2006-6-6 22:05:00
http://download.rising.com.cn/zsgj/VirusKiller.scr
点这网址直接下载..
明天一定努力 - 2006-6-6 22:06:00
2006-06-06,22:09:19

System Repair Engineer 2.0.12.350 (2.0 RC 1)
    Windows 2000 Advanced Server Service Pack 2 - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <ctfmon.exe><C:\WINNT\System32\Ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <internat.exe><internat.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <NvCplDaemon><; RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <KavStart><"C:\KAV2006\KAVStart.exe" -startup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <WangWang><"C:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <RavScanBD><"C:\Program Files\Rising\Rav\ScanBD.exe" /INST>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <Userinit><userinit.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <AppInit_DLLs><KB2357802.LOG>

==================================
启动文件夹
服务
[Logical Disk Manager Administrative Service / dmadmin]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[NVIDIA Display Driver Service / NVSvc]
  <C:\WINNT\System32\nvsvc32.exe><NVIDIA Corporation>
[Rising Proxy  Service / RfwProxySrv]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
明天一定努力 - 2006-6-6 22:06:00
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINNT\System32\xunleibho_v6.dll, >
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll, Thunder Networking Technologies,LTD>
[就要你]
  {42CE9921-7259-11D6-B76A-0010A48548DC} <url:http://www.91ni.com, N/A>
[网吧.net计划]
  {64187580-726B-11D6-B76A-0010A48548DC} <url:http://www.sicent.net, N/A>
[网址大全]
  {C18CB140-0BBB-11D4-8FE8-0088CC102438} <http://www.mpsoft.net/wz.htm, N/A>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[@msdxmLC.dll,-1@2052,电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\System32\msdxm.ocx, Microsoft Corporation>
[BitComet工具栏]
  {3F1ABCDB-A875-46c1-8345-B72A4567E486} <F:\BT软件\BitComet\BitCometBar\BitCometBar0.6.dll, N/A>
[CEditCtrl Object]
  {488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINNT\System32\aliedit\AliEdit.dll, www.alipay.com>
[AxInputControl Class]
  {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINNT\DOWNLO~1\INPUTC~1.DLL, >
[KSHScan Control]
  {ACFE8232-03C5-4AEC-AF5E-42B806724096} <C:\WINNT\System32\kingsoft\ONLINE~1\KSHScan.ocx, kingsoft>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\System32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[&使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
明天一定努力 - 2006-6-6 22:07:00
正在运行的进程
[PID: 164][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.00.2195.2901>
[PID: 192][\??\C:\WINNT\system32\csrss.exe]  <Microsoft Corporation><5.00.2195.2581>
[PID: 188][\??\C:\WINNT\system32\winlogon.exe]  <Microsoft Corporation><5.00.2195.2953>
[PID: 240][C:\WINNT\system32\services.exe]  <Microsoft Corporation><5.00.2195.2780>
    [C:\WINNT\system32\dmserver.dll]  <VERITAS Software Corp.><2195.2778.297.3>
[PID: 252][C:\WINNT\system32\lsass.exe]  <Microsoft Corporation><5.00.2195.2964>
[PID: 420][c:\program files\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
    [c:\program files\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
    [c:\program files\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [c:\program files\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [c:\program files\rising\rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [c:\program files\rising\rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 432][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 508][C:\Program Files\Rising\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 524][C:\Program Files\Rising\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 22>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
    [C:\Program Files\Rising\Rav\HOOKSYS.dll]  <Rising><18, 1, 0, 9>
    [C:\Program Files\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [C:\Program Files\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\HookWeb.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [C:\Program Files\Rising\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\SpamEng.dll]  <N/A><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
    [C:\Program Files\Rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 15>
    [C:\Program Files\Rising\Rav\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\ScanElf.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\Program Files\Rising\Rav\ExtMail.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
mopery - 2006-6-6 22:07:00
别扫了  你立刻下专杀..立刻查杀 ...杀完再扫个日志上来..
明天一定努力 - 2006-6-6 22:08:00
[PID: 556][C:\WINNT\system32\spoolsv.exe]  <Microsoft Corporation><5.00.2161.1>
[PID: 592][C:\WINNT\System32\msdtc.exe]  <Microsoft Corporation><1999.9.3421.3>
[PID: 720][C:\WINNT\System32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 744][C:\WINNT\System32\llssrv.exe]  <Microsoft Corporation><5.00.2195.2649>
[PID: 784][C:\WINNT\System32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.5303>
[PID: 844][C:\Program Files\Rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 916][C:\WINNT\system32\regsvc.exe]  <Microsoft Corporation><5.00.2195.2104>
[PID: 940][C:\WINNT\system32\MSTask.exe]  <Microsoft Corporation><4.71.2195.6920>
[PID: 964][C:\WINNT\System32\WBEM\WinMgmt.exe]  <Microsoft Corporation><1.50.1085.0029>
[PID: 1000][C:\WINNT\System32\inetsrv\inetinfo.exe]  <Microsoft Corporation><5.00.0984>
[PID: 1520][C:\WINNT\system32\Dfssvc.exe]  <Microsoft Corporation><5.00.2195.2841>
[PID: 1724][C:\WINNT\System32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 880][C:\Program Files\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
[PID: 440][C:\Program Files\Rising\Rfw\rfwmain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 51>
    [C:\Program Files\Rising\Rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [C:\Program Files\Rising\Rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
[PID: 1216][C:\WINNT\System32\internat.exe]  <Microsoft Corporation><5.00.2920.0000>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
[PID: 1744][C:\Program Files\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 19>
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
[PID: 1420][C:\Program Files\淘宝网\淘宝旺旺\WangWang.exe]  <淘宝(中国)软件有限公司><1, 5, 5, 1226>
    [C:\Program Files\淘宝网\淘宝旺旺\AliViewCtrl.dll]  <vline><1, 0, 0, 1>
    [C:\Program Files\淘宝网\淘宝旺旺\VLNetwork.dll]  <><1, 0, 0, 6>
    [C:\Program Files\淘宝网\淘宝旺旺\AliViewMedia.dll]  <vline><1, 0, 0, 1>
    [C:\Program Files\淘宝网\淘宝旺旺\VideoCAP.dll]  <><1, 0, 0, 4>
    [C:\Program Files\淘宝网\淘宝旺旺\VLAudio.dll]  <><1, 0, 0, 4>
    [C:\Program Files\淘宝网\淘宝旺旺\JsmShow.dll]  <><1, 0, 0, 3>
    [C:\Program Files\淘宝网\淘宝旺旺\Ali_Res.DLL]  <N/A><N/A>
    [C:\Program Files\淘宝网\淘宝旺旺\RichOne.dll]  <淘宝(中国)软件有限公司><1.0.0.1>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINNT\System32\msdmo.dll]  <N/A><N/A>
    [C:\Program Files\淘宝网\淘宝旺旺\WangWangX.dll]  <><1, 0, 0, 1>
    [C:\WINNT\System32\CHENHU4.IME]  <chenhu><5.8>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
[PID: 748][C:\WINNT\Explorer.exe]  <Microsoft Corporation><5.00.3315.2846>
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\xiaran.dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINNT\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\WINNT\System32\xunleibho_v6.dll]  <><4, 4, 0, 31>
    [C:\WINNT\System32\nvshell.dll]  <NVIDIA Corporation><6.14.10.5303>
    [C:\WINNT\System32\NVWRSZHC.DLL]  <NVIDIA Corporation><6.14.10.5303>
    [C:\WINNT\System32\CHENHU4.IME]  <chenhu><5.8>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
明天一定努力 - 2006-6-6 22:08:00
[PID: 408][C:\Program Files\Rising\Rav\RsAgent.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
[PID: 1664][C:\WINNT\msagent\AgentSvr.exe]  <Microsoft Corporation><2.00.0.3422>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
[PID: 1268][C:\Octopus\Server.exe]  <吉胜科技><15.4.11.850>
    [C:\Octopus\printcard.dll]  <N/A><N/A>
    [C:\Octopus\regcode.dll]  <N/A><N/A>
    [C:\Octopus\remoteclientdll.dll]  <N/A><N/A>
    [C:\Octopus\icdevice.dll]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\xiaran.dat]  <N/A><N/A>
    [C:\WINNT\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\WINNT\System32\CHENHU4.IME]  <chenhu><5.8>
[PID: 1548][C:\Program Files\Tencent\QQ\QQ.exe]  <TENCENT><0, 0, 0, 0>
    [C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\QQHelperDll.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\BasicCtrlDll.dll]  <Tencent><5, 0, 200, 160>
    [C:\Program Files\Tencent\QQ\QQAPI.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  <tencent><0, 3, 2, 4>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\LoginCtrl.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\npkcntc.dll]  <INCA Internet Co., Ltd.><2006, 3, 2, 1>
    [C:\Program Files\Tencent\QQ\npkpdb.dll]  <INCA Internet Co., Ltd.><2003, 10, 1, 1>
    [C:\Program Files\Tencent\QQ\QQRes.dll]  <tencent><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\WizardCtrl.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\QQMainFrame.dll]  <N/A><N/A>
    [C:\WINNT\System32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\Program Files\Tencent\QQ\CQQApplication.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\NewSkin.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\HostingMgr.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\CameraDll.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\MailSummary.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\QQSpace.dll]  <><1, 0, 0, 1>
    [C:\WINNT\System32\msdmo.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\QQGroupMng.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\GroupLive.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\UserDefinedHead.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\QQPlugin.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\QQConfigPlugin.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\LongConnection.dll]  <tencent><5, 0, 200, 160>
    [C:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\QRingMng.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\PhoneAPI.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\DialerAllinOne.dll]  <tencent><1, 4, 0, 0>
    [C:\Program Files\Tencent\QQ\QQAllInOne.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\SCCore.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\QQAvatar.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  <><1, 4, 0, 1>
    [C:\Program Files\Tencent\QQ\QQPet.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\BQQApplication.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\xiaran.dat]  <N/A><N/A>
    [C:\WINNT\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\Tencent\QQ\CommercesMng.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [C:\Program Files\Tencent\QQ\QQAddr.dll]  <深圳市腾讯计算机系统有限公司><5, 0, 101, 200>
    [C:\Program Files\Tencent\QQ\QQSceneMng.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\QQPhoneHelper.dll]  <腾讯科技(深圳)有限公司><2, 0, 3, 30>
[PID: 1684][C:\Program Files\Tencent\QQ\TIMPlatform.exe]  <tencent><0, 3, 1, 8>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  <tencent><0, 3, 2, 4>
明天一定努力 - 2006-6-6 22:09:00
[PID: 1576][C:\Program Files\Tencent\QQ\QQ.exe]  <TENCENT><0, 0, 0, 0>
    [C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\QQHelperDll.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\BasicCtrlDll.dll]  <Tencent><5, 0, 200, 160>
    [C:\Program Files\Tencent\QQ\QQAPI.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  <tencent><0, 3, 2, 4>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\LoginCtrl.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\npkcntc.dll]  <INCA Internet Co., Ltd.><2006, 3, 2, 1>
    [C:\Program Files\Tencent\QQ\npkpdb.dll]  <INCA Internet Co., Ltd.><2003, 10, 1, 1>
    [C:\Program Files\Tencent\QQ\QQRes.dll]  <tencent><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\QQMainFrame.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\CQQApplication.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\NewSkin.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\HostingMgr.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\CameraDll.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\MailSummary.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\QQSpace.dll]  <><1, 0, 0, 1>
    [C:\WINNT\System32\msdmo.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\QQGroupMng.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\GroupLive.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\UserDefinedHead.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\QQPlugin.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\QQConfigPlugin.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [C:\Program Files\Tencent\QQ\QRingMng.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\PhoneAPI.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\DialerAllinOne.dll]  <tencent><1, 4, 0, 0>
    [C:\Program Files\Tencent\QQ\QQAllInOne.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\SCCore.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\QQAvatar.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  <><1, 4, 0, 1>
    [C:\Program Files\Tencent\QQ\LongConnection.dll]  <tencent><5, 0, 200, 160>
    [C:\Program Files\Tencent\QQ\QQPet.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\BQQApplication.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\xiaran.dat]  <N/A><N/A>
    [C:\WINNT\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\Tencent\QQ\CommercesMng.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\QQ\QQAddr.dll]  <深圳市腾讯计算机系统有限公司><5, 0, 101, 200>
    [C:\Program Files\Tencent\QQ\QQSceneMng.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\QQCustomFace.dll]  <N/A><N/A>
    [C:\WINNT\System32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\Program Files\Tencent\QQ\GroupConnection.dll]  <Tencent><5, 0, 202, 170>
[PID: 1840][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2800.1106>
    [C:\WINNT\System32\xunleibho_v6.dll]  <><4, 4, 0, 31>
    [C:\Program Files\Tencent\QQ\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 1>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
明天一定努力 - 2006-6-6 22:09:00
[C:\WINNT\System32\CHENHU4.IME]  <chenhu><5.8>
    [C:\WINNT\System32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 1688][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2800.1106>
    [C:\WINNT\System32\xunleibho_v6.dll]  <><4, 4, 0, 31>
    [C:\Program Files\Tencent\QQ\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 1>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINNT\System32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_001.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 8>
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\xiaran.dat]  <N/A><N/A>
    [C:\WINNT\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[PID: 2120][C:\WINNT\NOTEPAD.EXE]  <Microsoft Corporation><5.00.2140.1>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
[PID: 2068][F:\serng2\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>

==================================
文件关联
.TXT  Error. [NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
轩辕小聪 - 2006-6-6 22:09:00
先下专杀,杀完后再扫日志。
明天一定努力 - 2006-6-6 22:10:00
专杀用了,没毒
明天一定努力 - 2006-6-6 22:10:00
就是专杀用后的
轩辕小聪 - 2006-6-6 22:24:00
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\xiaran.dat] <N/A><N/A>
果真是这个家伙,还有这两个:
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
用Autoruns扫个日志才能看到它们的注册表项,注意要隐藏微软签名项哦。
轩辕小聪 - 2006-6-6 22:24:00
又看不见了。
轩辕小聪 - 2006-6-6 22:24:00
再来一帖。
明天一定努力 - 2006-6-6 22:29:00
晕,不会用AUTORUNS。出来一大堆东西啊
轩辕小聪 - 2006-6-6 22:33:00
菜单栏你总能见到吧,如何操作参考第1楼的回帖。
或直接参考http://forum.ikaka.com/topic.asp?board=28&artid=7318038
明天一定努力 - 2006-6-6 22:43:00
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit

+ userinit.exeUserinit Logon ApplicationMicrosoft Corporationc:\winnt\system32\userinit.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

+ Explorer.exeWindows ExplorerMicrosoft Corporationc:\winnt\explorer.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ KavStartFile not found: C:\KAV2006\KAVStart.exe

+ NvCplDaemonRun a DLL as an AppMicrosoft Corporationc:\winnt\system32\rundll32.exe

+ RavScanBDScanBD ApplicationBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\scanbd.exe

+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe

+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwmain.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

+ ctfmon.exeFile not found: C:\WINNT\System32\Ctfmon.exe

+ internat.exeKeyboard Language Indicator AppletMicrosoft Corporationc:\winnt\system32\internat.exe

HKLM\SOFTWARE\Classes\Protocols\Filter

+ Class Install HandlerOLE32 Extensions for Win32Microsoft Corporationc:\winnt\system32\urlmon.dll

+ deflateOLE32 Extensions for Win32Microsoft Corporationc:\winnt\system32\urlmon.dll

+ gzipOLE32 Extensions for Win32Microsoft Corporationc:\winnt\system32\urlmon.dll

+ lzdhtmlOLE32 Extensions for Win32Microsoft Corporationc:\winnt\system32\urlmon.dll

+ text/webviewhtmlWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

HKLM\SOFTWARE\Classes\Protocols\Handler

+ aboutMicrosoft (R) HTML ViewerMicrosoft Corporationc:\winnt\system32\mshtml.dll

+ cdlOLE32 Extensions for Win32Microsoft Corporationc:\winnt\system32\urlmon.dll

+ fileOLE32 Extensions for Win32Microsoft Corporationc:\winnt\system32\urlmon.dll

+ ftpOLE32 Extensions for Win32Microsoft Corporationc:\winnt\system32\urlmon.dll

+ gopherOLE32 Extensions for Win32Microsoft Corporationc:\winnt\system32\urlmon.dll

+ httpOLE32 Extensions for Win32Microsoft Corporationc:\winnt\system32\urlmon.dll

+ httpsOLE32 Extensions for Win32Microsoft Corporationc:\winnt\system32\urlmon.dll

+ itsMicrosoft? InfoTech Storage System LibraryMicrosoft Corporationc:\winnt\system32\itss.dll

+ javascriptMicrosoft (R) HTML ViewerMicrosoft Corporationc:\winnt\system32\mshtml.dll

+ localOLE32 Extensions for Win32Microsoft Corporationc:\winnt\system32\urlmon.dll

+ mailtoMicrosoft (R) HTML ViewerMicrosoft Corporationc:\winnt\system32\mshtml.dll

+ mhtmlMicrosoft Internet Messaging APIMicrosoft Corporationc:\winnt\system32\inetcomm.dll

+ mkOLE32 Extensions for Win32Microsoft Corporationc:\winnt\system32\urlmon.dll

+ resMicrosoft (R) HTML ViewerMicrosoft Corporationc:\winnt\system32\mshtml.dll
明天一定努力 - 2006-6-6 22:44:00
+ sysimageMicrosoft (R) HTML ViewerMicrosoft Corporationc:\winnt\system32\mshtml.dll

+ vbscriptMicrosoft (R) HTML ViewerMicrosoft Corporationc:\winnt\system32\mshtml.dll

+ vnd.ms.radioWindows Media Player 2 ActiveX ControlMicrosoft Corporationc:\winnt\system32\msdxm.ocx

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components

+ Address Book 5Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe

+ CRLUpdateUPDCRLMicrosoft Corporationc:\winnt\system32\updcrl.exe

+ EnableRevocationMicrosoft(C) Register ServerMicrosoft Corporationc:\winnt\system32\regsvr32.exe

+ Internet Explorer 6IE 5.0 Per-User Install UtilityMicrosoft Corporationc:\winnt\system32\ie4uinit.exe

+ Microsoft Outlook Express 6Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe

+ Microsoft Windows Media PlayerADVPACKMicrosoft Corporationc:\winnt\system32\advpack.dll

+ NetMeeting 3.01ADVPACKMicrosoft Corporationc:\winnt\system32\advpack.dll

+ Windows 桌面更新Microsoft(C) Register ServerMicrosoft Corporationc:\winnt\system32\regsvr32.exe

+ 自定义浏览器Microsoft Internet Explorer Customization DLLMicrosoft Corporationc:\winnt\system32\iedkcs32.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler

+ Browseui 预加载程序Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 组件类别缓存程序Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

+ Network.ConnectionTrayNetwork Connections ShellMicrosoft Corporationc:\winnt\system32\netshell.dll

+ SysTraySystray shell service objectMicrosoft Corporationc:\winnt\system32\stobject.dll

+ WebCheckWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ iexplore.datc:\program files\internet explorer\iexplore.dat

+ iexplore.sysc:\program files\internet explorer\iexplore.sys

+ MsInfo.xrFile not found: C:\Program Files\Common Files\Microsoft Shared\MSINFO\MsInfo.xr

+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll

+ shell32.dllWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ xiaran.datc:\program files\common files\microsoft shared\msinfo\xiaran.dat

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ .CAB file viewerCabinet File Viewer Shell ExtensionMicrosoft Corporationc:\winnt\system32\cabview.dll

+ ActiveDesktopWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ ActiveX 高速缓存文件夹Object Control ViewerMicrosoft Corporationc:\winnt\system32\occache.dll

+ BandProxyShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ Briefcase FolderWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ CDF Extension Copy HookShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll

+ Channel MenuChannel Definition File ViewerMicrosoft Corporationc:\winnt\system32\cdfview.dll

+ Channel PropertiesChannel Definition File ViewerMicrosoft Corporationc:\winnt\system32\cdfview.dll

+ CmdFileIconWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ Code Download AgentWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll

+ ConnectionAgentWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll

+ Crypto PKO ExtensionCrypto Shell ExtensionsMicrosoft Corporationc:\winnt\system32\cryptext.dll

+ Crypto Sign ExtensionCrypto Shell ExtensionsMicrosoft Corporationc:\winnt\system32\cryptext.dll

+ Darwin App PublisherShell Application ManagerMicrosoft Corporationc:\winnt\system32\appwiz.cpl

+ Desktop ExplorerNVIDIA Desktop Explorer, Version 53.03 NVIDIA Corporationc:\winnt\system32\nvshell.dll

+ Desktop Explorer MenuNVIDIA Desktop Explorer, Version 53.03 NVIDIA Corporationc:\winnt\system32\nvshell.dll

+ Directory Context Menu VerbsDirectory Service Common UIMicrosoft Corporationc:\winnt\system32\dsuiext.dll

+ Directory NamespaceDirectory Service UIMicrosoft Corporationc:\winnt\system32\dsfolder.dll

+ Directory Object FindDirectory Service FindMicrosoft Corporationc:\winnt\system32\dsquery.dll

+ Directory Property UIDirectory Service Common UIMicrosoft Corporationc:\winnt\system32\dsuiext.dll

+ Directory Query UIDirectory Service FindMicrosoft Corporationc:\winnt\system32\dsquery.dll

+ Directory Start/Search FindDirectory Service FindMicrosoft Corporationc:\winnt\system32\dsquery.dll

+ Disk Copy ExtensionWindows DiskCopyMicrosoft Corporationc:\winnt\system32\diskcopy.dll

+ Disk Quota UIWindows Shell Disk Quota UI DLLMicrosoft Corporationc:\winnt\system32\dskquoui.dll

+ Display Adapter CPL ExtensionAdvanced display adapter propertiesMicrosoft Corporationc:\winnt\system32\deskadp.dll

+ Display Control Panel HTML ExtensionsWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ Display Monitor CPL ExtensionAdvanced display monitor propertiesMicrosoft Corporationc:\winnt\system32\deskmon.dll

+ Display Panning CPL ExtensionFile not found: deskpan.dll

+ Display TroubleShoot CPL ExtensionAdvanced display performance propertiesMicrosoft Corporationc:\winnt\system32\deskperf.dll

+ DS Security PageDirectory Service Security UIMicrosoft Corporationc:\winnt\system32\dssec.dll

+ Favorites BandShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll

+ File Property Page ExtensionWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ File Types PageWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ Folder Options Property Page ExtensionWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ HTML 缩略图的解压缩程序Thumbnail View ExtensionMicrosoft Corporationc:\winnt\system32\thumbvw.dll

+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\winnt\system32\hticons.dll

+ ICC 配置文件Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\winnt\system32\icmui.dll

+ ICM 打印机管理Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\winnt\system32\icmui.dll

+ ICM 监视器管理Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\winnt\system32\icmui.dll

+ ICM 扫描仪管理Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\winnt\system32\icmui.dll

+ IE4 套件初始屏幕Shell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
明天一定努力 - 2006-6-6 22:44:00
+ IIS Shell ExtentionPWS Tray ExtensionMicrosoft Corporationc:\winnt\system32\inetsrv\w3ext.dll

+ Installed Apps EnumeratorShell Application ManagerMicrosoft Corporationc:\winnt\system32\appwiz.cpl

+ InternetShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll

+ Internet Name SpaceShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll

+ Internet 临时文件Shell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll

+ Internet 临时文件Shell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll

+ InternetShortcutShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll

+ ISFBand OCShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll

+ IShellFolderBandShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ LNK 文件缩略图接口代理程序Thumbnail View ExtensionMicrosoft Corporationc:\winnt\system32\thumbvw.dll

+ Microsoft AutoCompleteShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ Microsoft Browser ArchitectureShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll

+ Microsoft BrowserBandShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ Microsoft CopyTo ServiceWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ Microsoft Internet 工具栏Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ Microsoft MoveTo ServiceWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ Microsoft New Object ServiceWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ Microsoft SendTo ServiceWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ Microsoft Url History 服务Shell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll

+ Microsoft Url 搜索挂接Shell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll

+ Microsoft 多个自动完成列表容器Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ Microsoft 历史自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ Microsoft 外壳文件夹自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ MIME File Types HookWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ MMC Icon HandlerMMC Shell Extension DLLMicrosoft Corporationc:\winnt\system32\mmcshext.dll

+ MRU 自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ Multimedia File Property SheetControl Panel Drivers AppletMicrosoft Corporationc:\winnt\system32\mmsys.cpl

+ MyDocs Copy HookMy Documents Folder UIMicrosoft Corporationc:\winnt\system32\mydocs.dll

+ MyDocs Drop TargetMy Documents Folder UIMicrosoft Corporationc:\winnt\system32\mydocs.dll

+ MyDocs FolderMy Documents Folder UIMicrosoft Corporationc:\winnt\system32\mydocs.dll

+ MyDocs PropertiesMy Documents Folder UIMicrosoft Corporationc:\winnt\system32\mydocs.dll

+ NTFS Security PageSecurity Shell ExtensionMicrosoft Corporationc:\winnt\system32\rshx32.dll

+ nView Desktop Context MenuNVIDIA Desktop Explorer, Version 53.03 NVIDIA Corporationc:\winnt\system32\nvshell.dll

+ Office 图形筛选器缩略图的解压缩程序Thumbnail View ExtensionMicrosoft Corporationc:\winnt\system32\thumbvw.dll

+ Offline Files Folder OptionsClient Side Caching UIMicrosoft Corporationc:\winnt\system32\cscui.dll

+ Offline Files MenuClient Side Caching UIMicrosoft Corporationc:\winnt\system32\cscui.dll

+ OLE Docfile Property PageOLE DocFile Property PageMicrosoft Corporationc:\winnt\system32\docprop.dll

+ Open With Context Menu HandlerWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ PlusPack CPL ExtensionEffects Control Panel extensionMicrosoft Corporationc:\winnt\system32\plustab.dll

+ PostAgentWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll

+ Printers Security PageSecurity Shell ExtensionMicrosoft Corporationc:\winnt\system32\rshx32.dll

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll

+ Search Assistant OCShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll

+ Sendmail serviceSend MailMicrosoft Corporationc:\winnt\system32\sendmail.dll

+ Sendmail serviceSend MailMicrosoft Corporationc:\winnt\system32\sendmail.dll

+ Shell Application ManagerShell Application ManagerMicrosoft Corporationc:\winnt\system32\appwiz.cpl

+ Shell Automation Folder ViewWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ Shell Automation Inproc ServiceShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll

+ Shell Automation ServiceWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ Shell Band Site MenuShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ Shell DocObject ViewerShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll

+ Shell Drag and Drop helperWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ Shell extensions for Microsoft Windows Network objectsNetwork object shell UIMicrosoft Corporationc:\winnt\system32\ntlanui2.dll

+ Shell Extensions for RealOne PlayerRealOne Player Shell ExtensionsRealNetworksc:\program files\real\realone player\rpshellext.dll
明天一定努力 - 2006-6-6 22:44:00
+ Shell extensions for sharingShell extensions for sharingMicrosoft Corporationc:\winnt\system32\ntshrui.dll

+ Shell extensions for sharingShell extensions for sharingMicrosoft Corporationc:\winnt\system32\ntshrui.dll

+ Shell Favorite FolderWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ Shell properties for a DS objectDirectory Service UIMicrosoft Corporationc:\winnt\system32\dsfolder.dll

+ Shell Scrap DataHandlerShell scrap object handlerMicrosoft Corporationc:\winnt\system32\shscrap.dll

+ Subscription MgrWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll

+ Tasks Folder Icon HandlerTask Scheduler interface DLLMicrosoft Corporationc:\winnt\system32\mstask.dll

+ Tasks Folder Shell ExtensionTask Scheduler interface DLLMicrosoft Corporationc:\winnt\system32\mstask.dll

+ TrayAgentWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll

+ TridentImageExtractorShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ Web Printer Shell ExtensionPrint UI DLLMicrosoft Corporationc:\winnt\system32\printui.dll

+ Web 搜索Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ WebCheckWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll

+ WebCheck SyncMgr HandlerWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll

+ WebCheckChannelAgentWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll

+ WebCheckWebCrawlerWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll

+ Windows Script Host 的外壳扩展Microsoft (r) Shell Extension for Windows Script HostMicrosoft Corporationc:\winnt\system32\wshext.dll

+ WinRAR shell extensionc:\program files\winrar\rarext.dll

+ 补充的外壳文件夹Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 补充的外壳文件夹 2Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 菜单条Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 菜单外壳文件夹Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 菜单站点Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 菜单桌面栏Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 窗格中的搜索Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 地址 EditBoxShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 地址(&A)Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 地址条解析程序Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 跟踪弹出栏Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 跟踪外壳菜单Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 公文包Windows BriefcaseMicrosoft Corporationc:\winnt\system32\syncui.dll

+ 将加密项添加到资源管理器的上下文菜单中Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ 开始菜单Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ 可访问的Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 历史记录Shell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll

+ 链接(&L)Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 媒体区Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 频道句柄对象Channel Definition File ViewerMicrosoft Corporationc:\winnt\system32\cdfview.dll

+ 频道快捷方式Channel Definition File ViewerMicrosoft Corporationc:\winnt\system32\cdfview.dll

+ 频道文件Channel Definition File ViewerMicrosoft Corporationc:\winnt\system32\cdfview.dll

+ 全局文件夹设置Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 任务计划Task Scheduler interface DLLMicrosoft Corporationc:\winnt\system32\mstask.dll

+ 搜索区Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 缩略图Thumbnail View ExtensionMicrosoft Corporationc:\winnt\system32\thumbvw.dll

+ 脱机文件夹Client Side Caching UIMicrosoft Corporationc:\winnt\system32\cscui.dll

+ 外壳 DeskBarShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 外壳 DeskBarAppShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 外壳 Rebar BandSiteShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 网络和拨号连接Network Connections ShellMicrosoft Corporationc:\winnt\system32\netshell.dll

+ 微缩图图像Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 文件夹快捷方式Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ 我的电脑Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ 下载状态Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 已装好的卷Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ 用户(&P)...Find PeopleMicrosoft Corporationc:\program files\outlook express\wabfind.dll

+ 用户帮助Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 预订文件夹Web Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll

+ 摘要信息缩略图处理程序(DOCFILES)Thumbnail View ExtensionMicrosoft Corporationc:\winnt\system32\thumbvw.dll

+ 注册数目路选项实用程序Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 自定义 MRU 自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll

+ 字体Windows Font FolderMicrosoft Corporationc:\winnt\system32\fontext.dll

+ 浏览器栏Shell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
明天一定努力 - 2006-6-6 22:45:00
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ 金山毒霸2006File not found: C:\KAV2006\KAVEXT.DLL

HKLM\Software\Classes\Folder\Shellex\ColumnHandlers

+ Fax Tiff Data Column ProviderFax Tiff Data Column ProviderMicrosoft Corporationc:\winnt\system32\faxshell.dll

+ ShAVColumnProvider classDocProp2Microsoft Corporationc:\winnt\system32\docprop2.dll

+ Version Column ProviderDocProp2Microsoft Corporationc:\winnt\system32\docprop2.dll

+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ {24F14F01-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ {24F14F02-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ QQBrowserHelperObject ClassQQIEHelper Module深圳市腾讯计算机系统有限公司c:\program files\tencent\qq\qqiehelper.dll

+ Thunder Browser HelperXunLeiBHOThunder Networking Technologies,LTDc:\program files\thunder network\thunder\comdlls\xunleibho_001.dll

+ ThunderIEHelper Classxunleibho BHOc:\winnt\system32\xunleibho_v6.dll

HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks

+ shdocvw.dllShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ msdxm.ocxWindows Media Player 2 ActiveX ControlMicrosoft Corporationc:\winnt\system32\msdxm.ocx

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ @shdoclc.dll,-864c:\winnt\web\related.htm

+ 就要你File not found: url:http://www.91ni.com

+ 腾讯QQQQTENCENTc:\program files\tencent\qq\qq.exe

+ 网吧.net计划File not found: url:http://www.sicent.net

+ 网址大全File not found: http://www.mpsoft.net/wz.htm

HKLM\System\CurrentControlSet\Services

+ Alerter通知所选用户和计算机有关系统管理级警报。Microsoft Corporationc:\winnt\system32\services.exe

+ Browser维护网络上计算机的最新列表以及提供这个列表给请求的程序。Microsoft Corporationc:\winnt\system32\services.exe

+ Dfs管理分布于局域网或广域网的逻辑卷。Microsoft Corporationc:\winnt\system32\dfssvc.exe

+ Dhcp通过注册和更改 IP 地址以及 DNS 名称来管理网络配置。Microsoft Corporationc:\winnt\system32\services.exe

+ dmserver逻辑磁盘管理器监视狗服务Microsoft Corporationc:\winnt\system32\services.exe

+ Dnscache解析和缓冲域名系统 (DNS) 名称。Microsoft Corporationc:\winnt\system32\services.exe

+ Eventlog记录程序和 Windows 发送的事件消息。事件日志包含对诊断问题有所帮助的信息。您可以在“事件查看器”中查看报告。Microsoft Corporationc:\winnt\system32\services.exe

+ IISADMIN允许通过 Internet 信息服务的管理单元管理 Web 和 FTP 服务。Microsoft Corporationc:\winnt\system32\inetsrv\inetinfo.exe

+ lanmanserver提供 RPC 支持、文件、打印以及命名管道共享。Microsoft Corporationc:\winnt\system32\services.exe

+ lanmanworkstation提供网络链结和通讯。Microsoft Corporationc:\winnt\system32\services.exe

+ LicenseServiceMicrosoft? License ServerMicrosoft Corporationc:\winnt\system32\llssrv.exe

+ LmHosts允许对“TCP/IP 上 NetBIOS (NetBT)”服务以及 NetBIOS 名称解析的支持。Microsoft Corporationc:\winnt\system32\services.exe

+ MSDTC并列事务,是分布于两个以上的数据库,消息队列,文件系统,或其它事务保护资源管理器。Microsoft Corporationc:\winnt\system32\msdtc.exe

+ NtmsSvc管理可移动媒体、驱动程序和库。Microsoft Corporationc:\winnt\system32\svchost.exe

+ NVSvcProvides system and desktop level support to the NVIDIA display driverNVIDIA Corporationc:\winnt\system32\nvsvc32.exe

+ PlugPlay管理设备安装以及配置,并且通知程序关于设备更改的情况。Microsoft Corporationc:\winnt\system32\services.exe

+ PolicyAgent管理 IP 安全策略以及启动 ISAKMP/Oakley (IKE) 和 IP 安全驱动程序。Microsoft Corporationc:\winnt\system32\lsass.exe

+ ProtectedStorage提供对敏感数据(如私钥)的保护性存储,以便防止未授权的服务,过程或用户对其的非法访问。Microsoft Corporationc:\winnt\system32\services.exe

+ RemoteRegistry允许远程注册表操作。Microsoft Corporationc:\winnt\system32\regsvc.exe

+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwsrv.exe

+ RpcSs提供终结点映射程序 (endpoint mapper) 以及其它 RPC 服务。Microsoft Corporationc:\winnt\system32\svchost.exe

+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe

+ SamSs存储本地用户帐户的安全信息。Microsoft Corporationc:\winnt\system32\lsass.exe

+ Schedule允许程序在指定时间运行。Microsoft Corporationc:\winnt\system32\mstask.exe

+ seclogon在不同凭据下启用启动过程Microsoft Corporationc:\winnt\system32\services.exe

+ SENS跟踪系统事件,如登录 Windows,网络以及电源事件等。将这些事件通知给 COM+ 事件系统 “订阅者(subscriber)”。Microsoft Corporationc:\winnt\system32\svchost.exe

+ SMTPSVC跨网传送电子邮件Microsoft Corporationc:\winnt\system32\inetsrv\inetinfo.exe

+ Spooler将文件加载到内存中以便迟后打印。Microsoft Corporationc:\winnt\system32\spoolsv.exe

+ TrkWks当文件在网络域的 NTFS 卷中移动时发送通知。Microsoft Corporationc:\winnt\system32\services.exe

+ W3SVC通过 Internet 信息服务的管理单元提供 Web 连接和管理。Microsoft Corporationc:\winnt\system32\inetsrv\inetinfo.exe

+ WinMgmt提供系统管理信息。Microsoft Corporationc:\winnt\system32\wbem\winmgmt.exe

HKLM\System\CurrentControlSet\Services

+ ACPIACPI Driver for NTMicrosoft Corporationc:\winnt\system32\drivers\acpi.sys

+ AFDAncillary Function Driver for WinSockMicrosoft Corporationc:\winnt\system32\drivers\afd.sys

+ agp440440 NT AGP FilterMicrosoft Corporationc:\winnt\system32\drivers\agp440.sys

+ ALCXSENSSensaura WDM 3D Audio DriverSensaurac:\winnt\system32\drivers\alcxsens.sys

+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\winnt\system32\drivers\alcxwdm.sys

+ AsyncMacRAS Asynchronous Media DriverMicrosoft Corporationc:\winnt\system32\drivers\asyncmac.sys

+ atapiIDE/ATAPI Port DriverMicrosoft Corporationc:\winnt\system32\drivers\atapi.sys

+ AtmarpcATM ARP Client ProtocolMicrosoft Corporationc:\winnt\system32\drivers\atmarpc.sys

+ atssseFile not found: C:\WINNT\System32\sosdrp.sys

+ audstubAudStub DriverMicrosoft Corporationc:\winnt\system32\drivers\audstub.sys

+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\winnt\system32\drivers\basetdi.sys

+ CCDECODEWDM Closed Caption VBI CodecMicrosoft Corporationc:\winnt\system32\drivers\ccdecode.sys

+ CdromSCSI CD-ROM DriverMicrosoft Corporationc:\winnt\system32\drivers\cdrom.sys

+ DiskPnP Disk DriverMicrosoft Corporationc:\winnt\system32\drivers\disk.sys

+ dmioNT Disk Manager I/O DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmio.sys

+ dmloadNT Disk Manager Startup DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmload.sys
明天一定努力 - 2006-6-6 22:45:00
+ DMusicMicrosoft DirectMusic Software Synthesizer (WDM)Microsoft Corporationc:\winnt\system32\drivers\dmusic.sys

+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys

+ FdcFloppy Disk Controller DriverMicrosoft Corporationc:\winnt\system32\drivers\fdc.sys

+ FsVgaFull Screen Video DriverMicrosoft Corporationc:\winnt\system32\drivers\fsvga.sys

+ FtdiskFT Disk DriverMicrosoft Corporationc:\winnt\system32\drivers\ftdisk.sys

+ gameenumGame Port EnumeratorMicrosoft Corporationc:\winnt\system32\drivers\gameenum.sys

+ GpcGeneric Packet ClassifierMicrosoft Corporationc:\winnt\system32\drivers\msgpc.sys

+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys

+ HookRegc:\program files\rising\rav\hookreg.sys

+ HookSysHooksysRisingc:\program files\rising\rav\hooksys.sys

+ HookUrlHookUrlBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\hookurl.sys

+ i8042prti8042 Port DriverMicrosoft Corporationc:\winnt\system32\drivers\i8042prt.sys

+ IpFilterDriverIP Traffic Filter DriverMicrosoft Corporationc:\winnt\system32\drivers\ipfltdrv.sys

+ IpInIpIP in IP Tunnel DriverMicrosoft Corporationc:\winnt\system32\drivers\ipinip.sys

+ IpNatIP Network Address TranslatorMicrosoft Corporationc:\winnt\system32\drivers\ipnat.sys

+ IPSECIPSEC driverMicrosoft Corporationc:\winnt\system32\drivers\ipsec.sys

+ isapnpPNP ISA Bus DriverMicrosoft Corporationc:\winnt\system32\drivers\isapnp.sys

+ KbdclassKeyboard Class DriverMicrosoft Corporationc:\winnt\system32\drivers\kbdclass.sys

+ kmixerKernel Mode Audio MixerMicrosoft Corporationc:\winnt\system32\drivers\kmixer.sys

+ KWatch3Kingsoft Antivirus KWatch DriverKingsoft Corporationc:\winnt\system32\drivers\kwatch3.sys

+ MEMSCANMemScan Driver瑞星软件有限公司c:\program files\rising\rav\memscan.sys

+ MouclassMouse Class DriverMicrosoft Corporationc:\winnt\system32\drivers\mouclass.sys

+ MPEMicrosoft MPE to IP FilterMicrosoft Corporationc:\winnt\system32\drivers\mpe.sys

+ mProcRsRising Personal FireWall  mprocrs.sysBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\mprocrs.sys

+ ms_mpu401MPU401 Adapter DriverMicrosoft Corporationc:\winnt\system32\drivers\msmpu401.sys

+ MSKSSRVMS KS ServerMicrosoft Corporationc:\winnt\system32\drivers\mskssrv.sys

+ MSPCLOCKMS Proxy ClockMicrosoft Corporationc:\winnt\system32\drivers\mspclock.sys

+ MSPQMMS Proxy Quality ManagerMicrosoft Corporationc:\winnt\system32\drivers\mspqm.sys

+ MSTEEWDM Tee/Communication Transform Filter Microsoft Corporationc:\winnt\system32\drivers\mstee.sys

+ NABTSFECWDM NABTS/FEC VBI CodecMicrosoft Corporationc:\winnt\system32\drivers\nabtsfec.sys

+ NdisTapiRemote Access NDIS TAPI DriverMicrosoft Corporationc:\winnt\system32\drivers\ndistapi.sys

+ NdisWanRemote Access NDIS WAN DriverMicrosoft Corporationc:\winnt\system32\drivers\ndiswan.sys

+ NetBTNetBios over TcpipMicrosoft Corporationc:\winnt\system32\drivers\netbt.sys

+ NetDetectNetwork Card Detection driverMicrosoft Corporationc:\winnt\system32\drivers\netdtect.sys

+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.c:\program files\tencent\qq\npkcrypt.sys

+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 53.03 NVIDIA Corporationc:\winnt\system32\drivers\nv4_mini.sys

+ NwlnkFltIPX Traffic Filter DriverMicrosoft Corporationc:\winnt\system32\drivers\nwlnkflt.sys

+ NwlnkFwdIPX Traffic Forwarder DriverMicrosoft Corporationc:\winnt\system32\drivers\nwlnkfwd.sys

+ NwlnkIpxNWLink IPX/SPX/NetBIOS Compatible Transport ProtocolMicrosoft Corporationc:\winnt\system32\drivers\nwlnkipx.sys

+ NwlnkNbNWLink NetBIOSMicrosoft Corporationc:\winnt\system32\drivers\nwlnknb.sys

+ NwlnkSpxNWLink SPX/SPXII ProtocolMicrosoft Corporationc:\winnt\system32\drivers\nwlnkspx.sys

+ ParallelParallel Printer DriverMicrosoft Corporationc:\winnt\system32\drivers\parallel.sys

+ ParportParallel Port DriverMicrosoft Corporationc:\winnt\system32\drivers\parport.sys

+ PCINT Plug and Play PCI EnumeratorMicrosoft Corporationc:\winnt\system32\drivers\pci.sys

+ PCIIdeGeneric PCI IDE Bus DriverMicrosoft Corporationc:\winnt\system32\drivers\pciide.sys

+ PptpMiniportWAN Miniport (PPTP)Microsoft Corporationc:\winnt\system32\drivers\raspptp.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\winnt\system32\drivers\ptilink.sys

+ RasAcdRemote Access Auto Connection DriverMicrosoft Corporationc:\winnt\system32\drivers\rasacd.sys

+ Rasl2tpWAN Miniport (L2TP)Microsoft Corporationc:\winnt\system32\drivers\rasl2tp.sys

+ RasptiDirect ParallelMicrosoft Corporationc:\winnt\system32\drivers\raspti.sys

+ RCARCA filterMicrosoft Corporationc:\winnt\system32\drivers\rca.sys

+ redbookRedbook Audio Filter DriverMicrosoft Corporationc:\winnt\system32\drivers\redbook.sys

+ RsFwDrvnt_fwdrvBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rsfwdrv.sys

+ rtl8029Realtek 8029(AS) PCI Ethernet adapter driverREALTEK Semiconductor Corp.c:\winnt\system32\drivers\rtl8029.sys

+ serenumSerial Port EnumeratorMicrosoft Corporationc:\winnt\system32\drivers\serenum.sys

+ SerialSerial Device DriverMicrosoft Corporationc:\winnt\system32\drivers\serial.sys

+ SLIPMicrosoft Slip Deframing Filter MinidriverMicrosoft Corporationc:\winnt\system32\drivers\slip.sys

+ spudSpecial Purpose Utility DriverMicrosoft Corporationc:\winnt\system32\drivers\spud.sys

+ streamipMicrosoft IP DriverMicrosoft Corporationc:\winnt\system32\drivers\streamip.sys

+ swenumPlug and Play Software Device EnumeratorMicrosoft Corporationc:\winnt\system32\drivers\swenum.sys

+ swmidiMicrosoft GS Wavetable SynthesizerMicrosoft Corporationc:\winnt\system32\drivers\swmidi.sys

+ sysaudioSystem Audio WDM FilterMicrosoft Corporationc:\winnt\system32\drivers\sysaudio.sys

+ TcpipTCP/IP Protocol DriverMicrosoft Corporationc:\winnt\system32\drivers\tcpip.sys

+ uhcdUniversal Host Controller DriverMicrosoft Corporationc:\winnt\system32\drivers\uhcd.sys

+ UpdateUpdate DriverMicrosoft Corporationc:\winnt\system32\drivers\update.sys

+ usbhubDefault Hub Driver for USBMicrosoft Corporationc:\winnt\system32\drivers\usbhub.sys

+ VgaSaveVGA/Super VGA Video DriverMicrosoft Corporationc:\winnt\system32\drivers\vga.sys

+ WanarpRemote Access IP ARP DriverMicrosoft Corporationc:\winnt\system32\drivers\wanarp.sys

+ wdmaudMMSYSTEM Wave/Midi API mapperMicrosoft Corporationc:\winnt\system32\drivers\wdmaud.sys

+ WSTCODECWDM WST Codec DriverMicrosoft Corporationc:\winnt\system32\drivers\wstcodec.sys

HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute

+ autocheck autochk *Auto Check UtilityMicrosoft Corporationc:\winnt\system32\autochk.exe

+ DfsInitWindows NT Distributed File System InitializerMicrosoft Corporationc:\winnt\system32\dfsinit.exe

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
明天一定努力 - 2006-6-6 22:45:00
+ Your Image File Name Here without a pathSymbolic Debugger for Windows 2000Microsoft Corporationc:\winnt\system32\ntsd.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls

+ KB2357802.LOGFile not found: KB2357802.LOG

HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls

+ advapi32Advanced Windows 32 Base APIMicrosoft Corporationc:\winnt\system32\advapi32.dll

+ comdlg32Common Dialogs DLLMicrosoft Corporationc:\winnt\system32\comdlg32.dll

+ gdi32GDI Client DLLMicrosoft Corporationc:\winnt\system32\gdi32.dll

+ imagehlpWindows NT Image HelperMicrosoft Corporationc:\winnt\system32\imagehlp.dll

+ kernel32Windows NT BASE API Client DLLMicrosoft Corporationc:\winnt\system32\kernel32.dll

+ lz32LZ Expand/Compress API DLLMicrosoft Corporationc:\winnt\system32\lz32.dll

+ ole32Microsoft OLE for WindowsMicrosoft Corporationc:\winnt\system32\ole32.dll

+ oleaut32Microsoft Corporationc:\winnt\system32\oleaut32.dll

+ olecli32Object Linking and Embedding Client LibraryMicrosoft Corporationc:\winnt\system32\olecli32.dll

+ olecnv32Microsoft OLE for WindowsMicrosoft Corporationc:\winnt\system32\olecnv32.dll

+ olesvr32Object Linking and Embedding Server LibraryMicrosoft Corporationc:\winnt\system32\olesvr32.dll

+ olethk32Microsoft OLE for WindowsMicrosoft Corporationc:\winnt\system32\olethk32.dll

+ rpcrt4Remote Procedure Call RuntimeMicrosoft Corporationc:\winnt\system32\rpcrt4.dll

+ shell32Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll

+ urlInternet Shortcut Shell Extension DLLMicrosoft Corporationc:\winnt\system32\url.dll

+ urlmonOLE32 Extensions for Win32Microsoft Corporationc:\winnt\system32\urlmon.dll

+ user32Windows 2000 USER API Client DLLMicrosoft Corporationc:\winnt\system32\user32.dll

+ versionVersion Checking and File Installation LibrariesMicrosoft Corporationc:\winnt\system32\version.dll

+ wininetInternet Extensions for Win32Microsoft Corporationc:\winnt\system32\wininet.dll

+ wldap32Win32 LDAP API DLLMicrosoft Corporationc:\winnt\system32\wldap32.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ crypt32chainCrypto API32Microsoft Corporationc:\winnt\system32\crypt32.dll

+ cryptnetCrypto Network Related APIMicrosoft Corporationc:\winnt\system32\cryptnet.dll

+ cscdllOffline Network AgentMicrosoft Corporationc:\winnt\system32\cscdll.dll

+ sclgntfySecondary Logon Service Notification DLLMicrosoft Corporationc:\winnt\system32\sclgntfy.dll

+ SensLognCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\winnt\system32\wlnotify.dll

+ termsrvCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\winnt\system32\wlnotify.dll

HKCU\Control Panel\Desktop\Scrnsave.exe

+ (无)File not found: (无)

HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{2D9A43B6-6355-4822-8B86-FD47C78B000D}] DATAGRAM 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{2D9A43B6-6355-4822-8B86-FD47C78B000D}] SEQPACKET 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{8A320D8C-67E2-45E5-AE28-8100491E366C}] DATAGRAM 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{8A320D8C-67E2-45E5-AE28-8100491E366C}] SEQPACKET 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{E2D10D1E-B7EC-41D8-9779-4E7DAB05590B}] DATAGRAM 4Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{E2D10D1E-B7EC-41D8-9779-4E7DAB05590B}] SEQPACKET 4Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{F2110C06-5B36-419E-A7E6-44C82878CBB7}] DATAGRAM 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{F2110C06-5B36-419E-A7E6-44C82878CBB7}] SEQPACKET 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NwlnkNb] DATAGRAM 3Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NwlnkNb] SEQPACKET 3Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD nwlnkipx [IPX]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD nwlnkspx [SPX II]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD nwlnkspx [SPX II] [Pseudo Stream]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD nwlnkspx [SPX]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD nwlnkspx [SPX] [Pseudo Stream]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD Tcpip [RAW/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD Tcpip [TCP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ MSAFD Tcpip [UDP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll

+ RSVP TCP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\winnt\system32\rsvpsp.dll

+ RSVP UDP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\winnt\system32\rsvpsp.dll

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors

+ BJ Language MonitorLangage Monitor for Canon Bubble-Jet PrinterMicrosoft Corporationc:\winnt\system32\cnbjmon.dll

+ Local PortLocal Spooler DLLMicrosoft Corporationc:\winnt\system32\localspl.dll

+ PJL Language MonitorSpooler Setup DLLMicrosoft Corporationc:\winnt\system32\pjlmon.dll

+ Standard TCP/IP PortStandard TCP/IP Port Monitor DLLMicrosoft Corporationc:\winnt\system32\tcpmon.dll

+ USB MonitorStandard USB printing Port Monitor DLLMicrosoft Corporationc:\winnt\system32\usbmon.dll

HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages

+ msv1_0Microsoft Authentication Package v1.0Microsoft Corporationc:\winnt\system32\msv1_0.dll

HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages

+ FPNWCLNTFPNW Client DLLMicrosoft Corporationc:\winnt\system32\fpnwclnt.dll

+ KDCSVCKDC ServiceMicrosoft Corporationc:\winnt\system32\kdcsvc.dll

+ RASSFMRemote Access Subauthentication dllMicrosoft Corporationc:\winnt\system32\rassfm.dll

+ scecliWindows Security Configuration Editor Client EngineMicrosoft Corporationc:\winnt\system32\scecli.dll

HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages

+ kerberosKerberos Security PackageMicrosoft Corporationc:\winnt\system32\kerberos.dll

+ msv1_0Microsoft Authentication Package v1.0Microsoft Corporationc:\winnt\system32\msv1_0.dll

+ schannelTLS / SSL Security ProviderMicrosoft Corporationc:\winnt\system32\schannel.dll

我无邪 - 2006-6-6 22:49:00
完了???
+ KB2357802.LOGFile not found: KB2357802.LOG这项删除它
其实你可以不粘出报告来
你可以在众多的项里直接找到要删除的东东
野丫童童 - 2006-6-7 8:39:00
我那病毒是不是跟这个一样?就是会自动发现面这句话:并附上伪装得很像的病毒网址~!杀不掉吗?
“QQ病毒“看看啊. 我最近的照片~ 才扫描到QQ象册上的 ^_^ !”
1
查看完整版本: 救命啊!怎么还是杀不掉QQ的像册病毒啊?还有删除不掉xiaran.dat这个文件?