瑞星卡卡安全论坛
sayhello - 2006-6-16 23:40:00

[电脑有问题已经一个星期了。具体表现在QQ和文档打字的时候经常死掉,说有问题需要关闭。但是后来发现可能是因为用的清华紫光拼音输入法的缘故。只要换别的输入法用就还没有关闭的问题。就没管它,没用清华紫光。

首先发现电脑可能有病毒是在昨天,用U盘拷东西过来,拷完删掉,却发现每次都删不掉里面的一个隐藏文件,格式化了U盘也没有用,下次用U盘还是会有那个文件。名字不记得了,后缀为.XML。但是对其进行查毒却没反应,对全体进行查毒也没有毒,是最新版的瑞星。
然后今天拿U盘拷了电脑里的文档到别的电脑上,上面的卡巴斯基有反应说U盘里有ROSE病毒。

应该可以说明我的电脑有病毒的吧,可是为什么瑞星没有反应呢?
各位帮帮忙拉~非常感谢~日志还需要吗??需要的话贴在下面:)
sayhello - 2006-6-16 23:42:00
2006-06-16,23:17:04
System Repair Engineer 2.0.12.350 (2.0 RC 1)
Windows XP Professional Service Pack 2 - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ATICCC><"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<StormCodec_Helper><"D:\暴风\Storm Codec\StormSet.exe" /S /opti>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SKYNET Personal FireWall><D:\FireWall\pfw.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Thunder><"D:\迅雷\ThunderShell.exe" /s>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"D:\杀毒\Rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<yassistse><"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
==================================
启动文件夹
[Adobe Gamma Loader]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>
[腾讯QQ]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk><N>
==================================
服务
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart]
<C:\WINDOWS\system32\ati2sgag.exe><>
[Network connection service / netconnecserver]
<C:\WINDOWS\svchost.exe><N/A>
[Rising Process Communication Center / RsCCenter]
<"D:\杀毒\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"D:\杀毒\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
sayhello - 2006-6-16 23:42:00
==================================
浏览器加载项
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v8.dll, >
[AntiFish Class]
{38928D50-8A48-44C2-945F-D2F23F771410} <C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll, Yahoo.>
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll, Yahoo!>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <D:\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[DragSearch BHO]
{62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, >
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <H:\音乐\kugoo\KuGoo3\KuGoo3DownXControl.ocx, N/A>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\MICROS~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll, Yahoo!>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v8.dll, >
[Web Browser Applet Control]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\WINDOWS\system32\msjava.dll, Microsoft Corporation>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Tabular Data Control]
{333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[Yahoo!Photo]
{33BBE430-0E42-4F12-B075-8D21ACB10DCB} <C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
{38928D50-8A48-44C2-945F-D2F23F771410} <C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll, Yahoo.>
[雅虎助手]
{406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll, Yahoo!>
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <D:\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Yahoo!Live]
{57421194-58FB-49AE-9B4F-FD48869B9AD4} <C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll, >
[Router Layer]
{5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} <C:\WINDOWS\System32\aclayer.dll, N/A>
[DragSearch BHO]
{62EED7C6-9F02-42F9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, >
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <H:\音乐\kugoo\KuGoo3\KuGoo3DownXControl.ocx, N/A>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Messenger Object]
{B69003B3-C55E-4B48-836C-BC5946FC3B28} <C:\Program Files\Messenger\msgsc.dll, Microsoft Corporation>
[AUDIO__X_MS_WMA Moniker Class]
{CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[assist]
{FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll, Yahoo!>
[&使用迅雷下载]
<D:\迅雷\geturl.htm, N/A>
[&使用迅雷下载全部链接]
<D:\迅雷\getAllurl.htm, N/A>
[上传到QQ网络硬盘]
<D:\QQ\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
<H:\音乐\kugoo\KuGoo3\KuGoo3DownX.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://D:\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<D:\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\QQ\SendMMS.htm, N/A>
sayhello - 2006-6-16 23:43:00
==================================
正在运行的进程
[PID: 584][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 652][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 680][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 728][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 740][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 892][C:\WINDOWS\system32\Ati2evxx.exe] <ATI Technologies Inc.><6.14.10.4129>
[C:\WINDOWS\system32\Ati2edxx.dll] <ATI Technologies, Inc.><6, 14, 10, 2500>
[PID: 904][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 968][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1076][D:\杀毒\Rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1092][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1140][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1316][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1368][D:\杀毒\Rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 22>
[D:\杀毒\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[D:\杀毒\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[D:\杀毒\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\杀毒\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\杀毒\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\杀毒\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
[D:\杀毒\Rising\Rav\HOOKSYS.dll] <Rising><18, 1, 0, 9>
[D:\杀毒\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[D:\杀毒\Rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\杀毒\Rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\杀毒\Rising\Rav\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[D:\杀毒\Rising\Rav\HookWeb.dll] <rising><18, 0, 0, 1>
[D:\杀毒\Rising\Rav\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[D:\杀毒\Rising\Rav\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\杀毒\Rising\Rav\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[D:\杀毒\Rising\Rav\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[D:\杀毒\Rising\Rav\SpamEng.dll] <N/A><18, 0, 0, 6>
[D:\杀毒\Rising\Rav\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
[D:\杀毒\Rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[D:\杀毒\Rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\杀毒\Rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\杀毒\Rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\杀毒\Rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[D:\杀毒\Rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[D:\杀毒\Rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 15>
[D:\杀毒\Rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[D:\杀毒\Rising\Rav\ScanNet.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[D:\杀毒\Rising\Rav\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[PID: 1580][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 1676][D:\杀毒\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[D:\杀毒\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[D:\杀毒\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1124][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll] <><2, 1, 5, 1045>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] < ><2, 0, 1, 1007>
[C:\WINDOWS\system32\icm32.dll] <Microsoft Corporation><5.1.2600.2709 (xpsp_sp2_gdr.050628-1518)>
[C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll] <><1, 0, 0, 1>
[C:\WINDOWS\system32\xunleibho_v8.dll] <><4, 5, 1, 33>
[C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll] <Yahoo!><2, 1, 8, 1048>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] <><1, 2, 7, 1006>
[H:\音乐\kugoo\KuGoo3\KuGoo3DownXControl.ocx] <N/A><N/A>
[PID: 1512][C:\Program Files\ATI Technologies\ATI.ACE\cli.exe] <ATI Technologies Inc.><1.11.0.0>
[c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_5d820f25\mscorlib.dll] <N/A><N/A>
[c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_fa246bd8\system.windows.forms.dll] <N/A><N/A>
sayhello - 2006-6-16 23:45:00
[c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_fa246bd8\system.windows.forms.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.implementation.dll] <ATI Technologies Inc.><1.2.2217.17118>
[c:\program files\ati technologies\ati.ace\log.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\program files\ati technologies\ati.ace\cli.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\program files\ati technologies\ati.ace\log.foundation.service.dll] <ATI Technologies Inc.><1.2.2217.17268>
[c:\program files\ati technologies\ati.ace\log.foundation.shared.dll] <ATI Technologies Inc.><1.2.2147.29163>
[c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_7cc7ab57\system.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.foundation.xmanifestation.dll] <ATI Technologies Inc.><1.2.2217.17268>
[c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_72cd6cbd\system.xml.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.component.runtime.dll] <ATI Technologies Inc.><1.2.2217.17269>
[c:\program files\ati technologies\ati.ace\aticccom.dll] <ATI Technologies Inc.><1.0.0.0>
[c:\program files\ati technologies\ati.ace\aem.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_8e62dd00\system.drawing.dll] <N/A><N/A>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[c:\program files\ati technologies\ati.ace\cli.caste.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29143>
[c:\program files\ati technologies\ati.ace\cli.caste.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17263>
[c:\program files\ati technologies\ati.ace\cli.component.runtime.shared.dll] <ATI Technologies Inc.><1.2.2147.29143>
[c:\program files\ati technologies\ati.ace\dem.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\program files\ati technologies\ati.ace\dem.graphics.demosinfo.dll] <ATI Technologies Inc.><1.2.2147.29147>
[c:\program files\ati technologies\ati.ace\dem.graphics.demosadapterinfo.dll] <ATI Technologies Inc.><1.2.2159.16348>
[c:\program files\ati technologies\ati.ace\dem.graphics.dematiadapterinfo.dll] <ATI Technologies Inc.><1.2.2147.29155>
[c:\program files\ati technologies\ati.ace\dem.graphics.demdriversettings.dll] <ATI Technologies Inc.><1.2.2147.29143>
[c:\program files\ati technologies\ati.ace\dem.graphics.displaysmanager.shared.dll] <ATI Technologies Inc.><1.2.2147.29142>
[c:\program files\ati technologies\ati.ace\atidemgr.dll] <ATI Technologies Inc.><1.2.2217.17103>
[c:\program files\ati technologies\ati.ace\dem.graphics.demosmodeinfo.dll] <ATI Technologies Inc.><1.2.2147.29149>
[c:\program files\ati technologies\ati.ace\dem.graphics.dematidisplaysmanagersettings.dll] <ATI Technologies Inc.><1.2.2147.29150>
[c:\program files\ati technologies\ati.ace\dem.graphics.demverylargedesktopsettings.dll] <ATI Technologies Inc.><1.2.2147.29146>
[c:\program files\ati technologies\ati.ace\cli.aspect.multivpu2.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17153>
[c:\program files\ati technologies\ati.ace\cli.aspect.multivpu2.graphics.shared.dll] <ATI Technologies Inc.><1.2.2182.27456>
[c:\program files\ati technologies\ati.ace\cli.aspect.multivpu.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17173>
[c:\program files\ati technologies\ati.ace\cli.aspect.multivpu.graphics.shared.dll] <ATI Technologies Inc.><1.2.2182.27452>
[c:\program files\ati technologies\ati.ace\cli.aspect.verylargedesktop.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17153>
[c:\program files\ati technologies\ati.ace\cli.aspect.verylargedesktop.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29147>
[c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17190>
[c:\program files\ati technologies\ati.ace\cli.aspect.radeon3dlegacy.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17187>
[c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour2.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17157>
[c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour2.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29158>
[c:\program files\ati technologies\ati.ace\dem.graphics.demdisplayscoloursettings.dll] <ATI Technologies Inc.><1.2.2147.29145>
[c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17217>
[c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29146>
[c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17203>
[c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29166>
[c:\program files\ati technologies\ati.ace\dem.graphics.mmdeintlacingsettings.dll] <ATI Technologies Inc.><1.2.2147.29167>
[c:\program files\ati technologies\ati.ace\cli.aspect.videooverlay.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17268>
[c:\program files\ati technologies\ati.ace\cli.aspect.videooverlay.graphics.runtime.shared.dll] <ATI Technologies Inc.><1.2.2147.29149>
[c:\program files\ati technologies\ati.ace\dem.graphics.videooverlay.shared.dll] <ATI Technologies Inc.><1.2.2147.29142>
[c:\program files\ati technologies\ati.ace\cli.aspect.smartgart.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17184>
[c:\program files\ati technologies\ati.ace\dem.graphics.demsmartgartsettings.dll] <ATI Technologies Inc.><1.2.2147.29146>
[c:\program files\ati technologies\ati.ace\cli.aspect.vpurecover.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17177>
[c:\program files\ati technologies\ati.ace\cli.aspect.vpurecover.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29145>
[c:\program files\ati technologies\ati.ace\cli.aspect.workstationconfig.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17175>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17236>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt2.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17162>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17227>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29168>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17157>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29148>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17232>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.shared.dll] <ATI Technologies Inc.><1.2.2169.27643>
[c:\program files\ati technologies\ati.ace\cli.aspect.customformats.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29144>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17165>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.shared.dll] <ATI Technologies Inc.><1.2.2169.27620>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17224>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17220>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17230>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29168>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp2.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17159>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp2.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29148>
[c:\program files\ati technologies\ati.ace\cli.aspect.overdrive3.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17196>
[c:\program files\ati technologies\ati.ace\cli.aspect.overdrive3.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29165>
[c:\program files\ati technologies\ati.ace\cli.aspect.overdrive2.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17200>
[c:\program files\ati technologies\ati.ace\dem.graphics.demoverdrivesettings.dll] <ATI Technologies Inc.><1.2.2147.29164>
[c:\program files\ati technologies\ati.ace\cli.aspect.powerplay3.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17193>
[c:\program files\ati technologies\ati.ace\cli.aspect.powerplay3.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29147>
[c:\program files\ati technologies\ati.ace\dem.graphics.dempowerplaysettings.dll] <ATI Technologies Inc.><1.2.2154.21069>
[c:\program files\ati technologies\ati.ace\cli.aspect.displaysoptions.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17211>
[c:\program files\ati technologies\ati.ace\cli.aspect.integratedumaframebuffer.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17206>
sayhello - 2006-6-16 23:46:00
[c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_8e62dd00\system.drawing.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17136>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17139>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17130>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17133>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17125>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17128>
[c:\program files\ati technologies\ati.ace\cli.aspect.displaysmanager.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17143>
[c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.wizard.dll] < ><1.2.2217.17118>
[c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17121>
[c:\program files\ati technologies\ati.ace\cli.aspect.transcode.local.wizard.dll] <ATI Technologies Inc.><1.2.2217.17153>
[c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17123>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.shared.dll] <ATI Technologies Inc.><1.2.2169.27643>
[c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29142>
[c:\program files\ati technologies\ati.ace\cli.aspect.customformats.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29144>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.shared.dll] <ATI Technologies Inc.><1.2.2169.27620>
[c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty2.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29143>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29168>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29148>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29167>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29165>
[c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29157>
[c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29166>
[c:\program files\ati technologies\ati.ace\cli.aspect.transcode.local.shared.dll] <ATI Technologies Inc.><1.2.0.0>
[c:\program files\ati technologies\ati.ace\atixclib.dll] < ><1.0.0.0>
[c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29155>
[PID: 3620][C:\Program Files\ATI Technologies\ATI.ACE\cli.exe] <ATI Technologies Inc.><1.11.0.0>
[c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_5d820f25\mscorlib.dll] <N/A><N/A>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_fa246bd8\system.windows.forms.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.implementation.dll] <ATI Technologies Inc.><1.2.2217.17118>
[c:\program files\ati technologies\ati.ace\log.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\program files\ati technologies\ati.ace\cli.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\program files\ati technologies\ati.ace\log.foundation.service.dll] <ATI Technologies Inc.><1.2.2217.17268>
[c:\program files\ati technologies\ati.ace\log.foundation.shared.dll] <ATI Technologies Inc.><1.2.2147.29163>
[c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_7cc7ab57\system.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.foundation.xmanifestation.dll] <ATI Technologies Inc.><1.2.2217.17268>
[c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_72cd6cbd\system.xml.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.component.systemtray.dll] <ATI Technologies Inc.><1.2.2217.17245>
[c:\program files\ati technologies\ati.ace\cli.caste.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29143>
[c:\program files\ati technologies\ati.ace\cli.component.runtime.dll] <ATI Technologies Inc.><1.2.2217.17269>
[c:\program files\ati technologies\ati.ace\aticccom.dll] <ATI Technologies Inc.><1.0.0.0>
[c:\program files\ati technologies\ati.ace\dem.graphics.displaysmanager.shared.dll] <ATI Technologies Inc.><1.2.2147.29142>
[c:\program files\ati technologies\ati.ace\aem.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\program files\ati technologies\ati.ace\apm.foundation.dll] <ATI Technologies Inc.><1.2.2147.29156>
[c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_8e62dd00\system.drawing.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\zh-chs\cli.component.systemtray.resources.dll] <ATI Technologies Inc.><1.2.2217.17245>
[PID: 2524][D:\锐捷\8021x.exe] <锐捷网络><2, 50, 0, 0>
[C:\WINDOWS\system32\W32N50.dll] <Printing Communications Assoc., Inc. (PCAUSA)><5.03.16.54>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[PID: 3872][C:\WINDOWS\system32\conime.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[PID: 3280][C:\WINDOWS\system32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[PID: 3440][C:\WINDOWS\system32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[PID: 1032][D:\杀毒工具\SREng.exe] <Smallfrogs Studio><2.0.12.350>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
==================================
文件关联
.TXT Error. [NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
sayhello - 2006-6-16 23:46:00
麻烦拉~非常感谢~:)
轩辕小聪 - 2006-6-16 23:49:00
[Network connection service / netconnecserver]
<C:\WINDOWS\svchost.exe><N/A>
很可能是灰鸽子。
在SREng的“启动项目”-“服务”-“Win32服务应用程序”中选“隐藏微软服务”,然后选中这一项,点“删除服务”,在弹出的对话框中点“否”。
重启后删除C:\WINDOWS\svchost.exe
没有看到rose.exe,如果的确中了这个,参考http://forum.ikaka.com/topic.asp?board=28&artid=8003098
sayhello - 2006-6-16 23:56:00
找到SREng的“启动项目”-“服务”,但是“Win32服务应用程序”在哪呢?是服务名还是描述或者其他的??
我无邪 - 2006-6-16 23:59:00
运行System Repair Engineer,使用“系统修复,文件关联,勾选“全选”点“修复”使所有扩展名都恢复正常
运行System Repair Engineer,点“启动项目,服务,点“Win32服务应用程序”勾选“隐藏微软服务”选中病毒服务Network connection service,选择“删除服务”点“设置”选择“否”最后重启
关闭所有浏览窗口以及一些不必要的程序
运行System Repair Engineer,使用“系统修复,浏览器加载项”来删除以下选项。
双击我的电脑,工具,文件夹选项,查看,单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示确定更改时,单击“是”,清除“隐藏已知文件类型的扩展名
删除
C:\WINDOWS\svchost.exe
C:\WINDOWS\System32\aclayer.dll
以上杀的是另二个病毒
你说的这个,看这个帖子
∷病毒危害:
1、在系统中占用大量cpu资源。
2、在每个分区下建立rose.exe 和autorun.inf 2个文件,且它们都设置为系统保护文件,一般情况下用户看不到这两个文件,但是在双击该盘符时病毒就自动运行了。
3、若对该病毒不及时处理,可能会引起部分操作系统崩溃,表现在开机自检后直接并反复重启,无法进入系统,即便重新格式化C盘,重新安装系统之后,也只是清除了C盘的病毒,在其他盘下仍然存在,且会再次发作。
∷杀毒方式:目前我们测试了多个杀毒软件,即便将病毒库升级到最新,它们也暂时不具备查杀该病毒的能力。这也是该病毒传播如此迅速的原因之一。
∷具体方法如下:
1.判断是否中毒,依症状发展顺序有:
无法正常拔除U盘等移动设备,磁盘的右键菜单中第一项为“自动播放”,磁盘根目录下有系统隐藏文件"rose.exe"和"autorun.inf",无法关机,无法打开本地磁盘,资源消耗较大,任务管理器中出现多个"rose.exe"进程,无法启动系统(反复重启),重装系统后依然如故(有待证明),无法从光盘引导启动,无法读取BIOS,按电源开关没有反应(尤其笔记本)。
2.rose.exe的情况:
rose.exe病毒大多是通过移动设备传播的。只要双击磁盘就会激活"rose.exe","rose.exe"和"autorun.inf"就会自动复制到所有磁盘根目录,并会把自动运行信息写入注册表和系统盘下的WINDOWS文件夹下。rose.exe病毒具有潜伏期,一般在中毒24小时后才会看到明显症状,并且随着中毒时间变长,所发生的症状逐渐加深,WINDOWS目录下的病毒文件和注册表项也会变多。这说明rose.exe对电脑的破坏是逐渐加深的,或者其发生了变异。一个非常奇怪的事情就是,似乎迄今为止几款主流的杀毒软件还不能查杀rose.exe病毒,我两次把病毒样本提交给瑞星,但瑞星的工程师坚持认为这不是病毒。
3.预防方法:
其实方法很简单,在插入移动设备时不要双击打开,点右键看第一个菜单是不是“自动播放”,如果是就用资源管理器打开,如果不是应该就没有问题。
4.查杀rose.exe:
如果还能进入操作系统,记住在查杀的过程中不要双击任何磁盘。默认系统盘为C盘。控制面版->文件夹选项->查看,去掉“隐藏受保护的操作系统文件”的选项,选择“显示所有文件和文件夹”。通过资源管理器查看各个磁盘的根目录,如果发现有"rose.exe"和"autorun.inf",那么就可以确定染毒了。手工删除,首先终止任务管理器中的rose.exe进程,开始->运行->msconfig,检查删除可疑项,没有就算了,然后删除注册表中有关"rose.exe"的键值(搜索"rose",把整个shell子键删除),在WINDOWS文件夹中搜索"rose.exe",在C:\WINDOWS\Prefetch下至少可以找到两个文件,删除相关文件。然后删除各个磁盘下的"rose.exe"和"autorun.inf"。以下是在DOS下删除的方法:
C:\>dir autorun.inf/a
C:\>attrib autorun.inf -s -h -r
C:\>del autorun.inf
再依次清除其他各盘以及"rose.exe",如果在windows下可删,就不用在DOS下删了。这样基本上就清除rose.exe了。不能只清除各个磁盘下的"rose.exe"和"autorun.inf",否则会报告无法找到rose.exe,依然无法打开磁盘。
如果不能进入系统,就比较麻烦,这种情况一般中毒时间较长,还没有十分成功的解决方法,欢迎大家跟帖。可以尝试从安全模式或DOS进入,也可以通过深山红叶等工具盘进入,按照上面的方法清除文件后,如果可以的话最好能把注册表也清除一下。如果有备份或系统还原,最好就恢复一下。重启一般会无法读取BIOS信息,笔记本可能无法打开,我的一般做法就是恢复一下BIOS信息(取下主板上的电池反扣)。对于台式机似乎这样可以,对于笔记本就有困难了。进入系统后还要清理一下注册表。如果不行的话,可以尝试恢复BIOS后重装系统。
5.5Q上面传说有rose.exe专杀工具,我没有用过,大家可以去看一下,也可以从这里下载: ftp://222.20.68.103/anti-rose v1.0.exe
∷预防办法:
1、别人将U盘插入自己的电脑,出现操作提示框时,不要选择任何操作,直接关掉。
2、打开我的电脑,找到U盘盘符,右键单击U盘盘符,在弹出的菜单中选择“打开”进入。千万不要直接双击U盘的盘符进去,否则会立刻激活病毒!
3、在我的电脑-工具-文件夹选项-查看-显示所有文件和文件夹,把“隐藏受保护的系统文件”的勾去掉,如果看到U盘中出现了“rose.exe”和“autorun.inf”两个文件,直接删除!
4、在开始--运行中输入“regedit”(XP系统)打开注册表,点“编辑”——“查找”,在弹出的对话框中输入“rose.exe”,找到后将整个shell子键删除,然后继续按F3查找下一个,继续删除查找到有关的键值,直到显示为“注册表搜索完毕”为止。
sayhello - 2006-6-17 0:12:00
谢谢啊~但是我还是找不到那个"win32应用服务程序"在哪呢??服务选项中的服务名中吗??那都是英文啊 没有"win32应用服务程序"
轩辕小聪 - 2006-6-17 0:13:00
晕倒,原来如此,楼主用的还是老版的SREng,那就不用什么“win32应用服务程序”了,直接在“服务”里面找到并操作。
sayhello - 2006-6-17 0:18:00
去哪下载新的??:)
sayhello - 2006-6-17 0:35:00
OK已经删除了:\WINDOWS\svchost.exe
但是没有找到C:\WINDOWS\System32\aclayer.dll,只有aclui.dll和acledit.dll...
另外有一个奇怪的情况,就是在显示隐藏文件之后,桌面上出现了很多关于我白天写的WORD文档的BMP文件,名字都是类似~WRL1425.tmp 这怎么回事??
sayhello - 2006-6-17 0:49:00
新的扫描报告:
2006-06-17,00:39:06
System Repair Engineer 2.0.12.350 (2.0 RC 1)
Windows XP Professional Service Pack 2 - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ATICCC><"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<StormCodec_Helper><"D:\暴风\Storm Codec\StormSet.exe" /S /opti>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SKYNET Personal FireWall><D:\FireWall\pfw.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Thunder><"D:\迅雷\ThunderShell.exe" /s>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"D:\杀毒\Rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<yassistse><"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
==================================
启动文件夹
[Adobe Gamma Loader]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>
[腾讯QQ]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk><N>
==================================
服务
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart]
<C:\WINDOWS\system32\ati2sgag.exe><>
[Rising Process Communication Center / RsCCenter]
<"D:\杀毒\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"D:\杀毒\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
==================================
浏览器加载项
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v8.dll, >
[AntiFish Class]
{38928D50-8A48-44C2-945F-D2F23F771410} <C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll, Yahoo.>
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll, Yahoo!>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <D:\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[DragSearch BHO]
{62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, >
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <H:\音乐\kugoo\KuGoo3\KuGoo3DownXControl.ocx, N/A>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\MICROS~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll, Yahoo!>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v8.dll, >
[Web Browser Applet Control]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\WINDOWS\system32\msjava.dll, Microsoft Corporation>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Tabular Data Control]
{333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[Yahoo!Photo]
{33BBE430-0E42-4F12-B075-8D21ACB10DCB} <C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
{38928D50-8A48-44C2-945F-D2F23F771410} <C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll, Yahoo.>
[雅虎助手]
{406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll, Yahoo!>
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <D:\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Yahoo!Live]
{57421194-58FB-49AE-9B4F-FD48869B9AD4} <C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll, >
[Router Layer]
{5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} <C:\WINDOWS\System32\aclayer.dll, N/A>
[DragSearch BHO]
{62EED7C6-9F02-42F9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, >
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <H:\音乐\kugoo\KuGoo3\KuGoo3DownXControl.ocx, N/A>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Messenger Object]
{B69003B3-C55E-4B48-836C-BC5946FC3B28} <C:\Program Files\Messenger\msgsc.dll, Microsoft Corporation>
[AUDIO__X_MS_WMA Moniker Class]
{CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[assist]
{FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll, Yahoo!>
[&使用迅雷下载]
<D:\迅雷\geturl.htm, N/A>
[&使用迅雷下载全部链接]
<D:\迅雷\getAllurl.htm, N/A>
[上传到QQ网络硬盘]
<D:\QQ\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
<H:\音乐\kugoo\KuGoo3\KuGoo3DownX.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://D:\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<D:\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\QQ\SendMMS.htm, N/A>
我无邪 - 2006-6-17 0:49:00
找不到没有关系,重启后,再扫份报告粘上来。
sayhello - 2006-6-17 0:50:00
==================================
正在运行的进程
[PID: 584][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 648][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 676][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 724][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 736][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 888][C:\WINDOWS\system32\Ati2evxx.exe] <ATI Technologies Inc.><6.14.10.4129>
[C:\WINDOWS\system32\Ati2edxx.dll] <ATI Technologies, Inc.><6, 14, 10, 2500>
[PID: 900][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 964][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1072][D:\杀毒\Rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1088][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1136][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1324][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1360][D:\杀毒\Rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 22>
[D:\杀毒\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[D:\杀毒\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[D:\杀毒\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\杀毒\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\杀毒\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\杀毒\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
[D:\杀毒\Rising\Rav\HOOKSYS.dll] <Rising><18, 1, 0, 9>
[D:\杀毒\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[D:\杀毒\Rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\杀毒\Rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\杀毒\Rising\Rav\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[D:\杀毒\Rising\Rav\HookWeb.dll] <rising><18, 0, 0, 1>
[D:\杀毒\Rising\Rav\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[D:\杀毒\Rising\Rav\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\杀毒\Rising\Rav\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[D:\杀毒\Rising\Rav\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[D:\杀毒\Rising\Rav\SpamEng.dll] <N/A><18, 0, 0, 6>
[D:\杀毒\Rising\Rav\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
[D:\杀毒\Rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[D:\杀毒\Rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\杀毒\Rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\杀毒\Rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\杀毒\Rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[D:\杀毒\Rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[D:\杀毒\Rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 15>
[D:\杀毒\Rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[D:\杀毒\Rising\Rav\ScanNet.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[D:\杀毒\Rising\Rav\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[PID: 1576][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 1672][D:\杀毒\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[D:\杀毒\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[D:\杀毒\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 192][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll] <><2, 1, 5, 1045>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] < ><2, 0, 1, 1007>
[C:\WINDOWS\system32\xunleibho_v8.dll] <><4, 5, 1, 33>
[C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll] <Yahoo!><2, 1, 8, 1048>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] <><1, 2, 7, 1006>
[H:\音乐\kugoo\KuGoo3\KuGoo3DownXControl.ocx] <N/A><N/A>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll] <N/A><1, 0, 1, 1014>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[PID: 432][C:\Program Files\ATI Technologies\ATI.ACE\cli.exe] <ATI Technologies Inc.><1.11.0.0>
[c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_5d820f25\mscorlib.dll] <N/A><N/A>
[c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_fa246bd8\system.windows.forms.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.implementation.dll] <ATI Technologies Inc.><1.2.2217.17118>
[c:\program files\ati technologies\ati.ace\log.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\program files\ati technologies\ati.ace\cli.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\program files\ati technologies\ati.ace\log.foundation.service.dll] <ATI Technologies Inc.><1.2.2217.17268>
[c:\program files\ati technologies\ati.ace\log.foundation.shared.dll] <ATI Technologies Inc.><1.2.2147.29163>
[c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_7cc7ab57\system.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.foundation.xmanifestation.dll] <ATI Technologies Inc.><1.2.2217.17268>
[c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_72cd6cbd\system.xml.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.component.runtime.dll] <ATI Technologies Inc.><1.2.2217.17269>
[c:\program files\ati technologies\ati.ace\aticccom.dll] <ATI Technologies Inc.><1.0.0.0>
[c:\program files\ati technologies\ati.ace\aem.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_8e62dd00\system.drawing.dll] <N/A><N/A>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[c:\program files\ati technologies\ati.ace\cli.caste.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29143>
[c:\program files\ati technologies\ati.ace\cli.caste.graphics.runtime.dll] <ATI Technologies Inc.><1.2.2217.17263>
[c:\program files\ati technologies\ati.ace\cli.component.runtime.shared.dll] <ATI Technologies Inc.><1.2.2147.29143>
[c:\program files\ati technologies\ati.ace\dem.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\program files\ati technologies\ati.ace\dem.graphics.demosinfo.dll] <ATI Technologies Inc.><1.2.2147.29147>
[c:\program files\ati technologies\ati.ace\dem.graphics.demosadapterinfo.dll] <ATI Technologies Inc.><1.2.2159.16348>
[c:\program files\ati technologies\ati.ace\dem.graphics.dematiadapterinfo.dll] <ATI Technologies Inc.><1.2.2147.29155>
[c:\program files\ati technologies\ati.ace\dem.graphics.demdriversettings.dll] <ATI Technologies Inc.><1.2.2147.29143>
[c:\program files\ati technologies\ati.ace\dem.graphics.displaysmanager.shared.dll] <ATI Technologies Inc.><1.2.2147.29142>
[c:\program files\ati technologies\ati.ace\atidemgr.dll] <ATI Technologies Inc.><1.2.2217.17103>
[c:\program files\ati technologies\ati.ace\dem.graphics.demosmodeinfo.dll] <ATI Technologies Inc.><1.2.2147.29149>
[c:\program files\ati technologies\ati.ace\dem.graphics.dematidisplaysmanagersettings.dll] <ATI Technologies Inc.><1.2.2147.29150>
sayhello - 2006-6-17 0:51:00
[c:\program files\ati technologies\ati.ace\dem.graphics.demdevicedfpsettings.dll] <ATI Technologies Inc.><1.2.2147.29164>
[c:\program files\ati technologies\ati.ace\dem.graphics.demdevicedfp2settings.dll] <ATI Technologies Inc.><1.2.2147.29147>
[c:\program files\ati technologies\ati.ace\dem.graphics.demoverdrive3settings.dll] <ATI Technologies Inc.><1.2.2147.29168>
[c:\program files\ati technologies\ati.ace\cli.aspect.overdrive2.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29149>
[c:\program files\ati technologies\ati.ace\cli.aspect.displaysoptions.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29157>
[c:\program files\ati technologies\ati.ace\dem.graphics.demdisplaysmanageroptionssettings.dll] <ATI Technologies Inc.><1.2.2147.29148>
[c:\program files\ati technologies\ati.ace\cli.aspect.integratedumaframebuffer.graphics.shared.dll] <ATI Technologies Inc.><1.2.2210.26509>
[c:\program files\ati technologies\ati.ace\dem.graphics.demumaframebuffersettings.dll] <ATI Technologies Inc.><1.2.2147.29147>
[c:\program files\ati technologies\ati.ace\apm.foundation.dll] <ATI Technologies Inc.><1.2.2147.29156>
[PID: 496][D:\杀毒\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[D:\杀毒\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\杀毒\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\杀毒\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\杀毒\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 512][D:\杀毒\Rising\Rav\Ravmon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 19>
[D:\杀毒\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[D:\杀毒\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[D:\杀毒\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\杀毒\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\杀毒\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\杀毒\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[D:\杀毒\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[PID: 540][C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe] < ><2, 0, 0, 1002>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll] <><2, 1, 5, 1045>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] < ><2, 0, 1, 1007>
[C:\Program Files\Yahoo!\Assistant\yNotifier.dll] <><1, 0, 0, 5>
[PID: 548][C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe] <Yahoo!><1, 0, 1, 1001>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[C:\PROGRA~1\Yahoo!\Assistant\shell\yAsMenu.dll] <Yahoo><1, 0, 1, 1006>
[C:\PROGRA~1\Yahoo!\Assistant\shell\yAssecblk.dll] <Yahoo><1, 0, 2, 1002>
[C:\PROGRA~1\Yahoo!\Assistant\shell\yIEAngel.dll] <Yahoo><1, 0, 1, 1001>
[C:\PROGRA~1\Yahoo!\Assistant\shell\yMenuInfo.dll] <Yahoo><1, 0, 0, 2>
[PID: 564][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[PID: 600][D:\迅雷\Thunder.exe] <><5.0.0.72>
[D:\迅雷\UpdateDownload.dll] <N/A><N/A>
[D:\迅雷\download_interface.dll] <N/A><N/A>
[D:\迅雷\log4cplus.dll] <N/A><N/A>
[D:\迅雷\stlport_vc646.dll] <STLport Consulting, Inc.><4.6.2003.1031>
[D:\迅雷\historyinfo_manage.dll] <N/A><N/A>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[PID: 356][C:\WINDOWS\system32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 2148][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2592][C:\Program Files\ATI Technologies\ATI.ACE\cli.exe] <ATI Technologies Inc.><1.11.0.0>
[c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_5d820f25\mscorlib.dll] <N/A><N/A>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_fa246bd8\system.windows.forms.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.implementation.dll] <ATI Technologies Inc.><1.2.2217.17118>
[c:\program files\ati technologies\ati.ace\log.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\program files\ati technologies\ati.ace\cli.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\program files\ati technologies\ati.ace\log.foundation.service.dll] <ATI Technologies Inc.><1.2.2217.17268>
[c:\program files\ati technologies\ati.ace\log.foundation.shared.dll] <ATI Technologies Inc.><1.2.2147.29163>
[c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_7cc7ab57\system.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.foundation.xmanifestation.dll] <ATI Technologies Inc.><1.2.2217.17268>
[c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_72cd6cbd\system.xml.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.component.wizard.dll] <ATI Technologies Inc.><1.2.2217.17146>
[c:\program files\ati technologies\ati.ace\cli.foundation.clients.dll] <ATI Technologies Inc.><1.2.2147.29142>
[c:\program files\ati technologies\ati.ace\cli.component.wizard.shared.dll] <ATI Technologies Inc.><1.2.2147.29144>
[c:\program files\ati technologies\ati.ace\cli.component.runtime.dll] <ATI Technologies Inc.><1.2.2217.17269>
[c:\program files\ati technologies\ati.ace\aticccom.dll] <ATI Technologies Inc.><1.0.0.0>
[c:\program files\ati technologies\ati.ace\cli.caste.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29143>
[c:\program files\ati technologies\ati.ace\aem.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\program files\ati technologies\ati.ace\dem.graphics.displaysmanager.shared.dll] <ATI Technologies Inc.><1.2.2147.29142>
[c:\program files\ati technologies\ati.ace\cli.caste.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17148>
[c:\program files\ati technologies\ati.ace\cli.caste.graphics.wizard.shared.dll] <ATI Technologies Inc.><1.2.2147.29144>
[c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_8e62dd00\system.drawing.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17136>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17139>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17130>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17133>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17125>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17128>
[c:\program files\ati technologies\ati.ace\cli.aspect.displaysmanager.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17143>
[c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.wizard.dll] < ><1.2.2217.17118>
[c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17121>
[c:\program files\ati technologies\ati.ace\cli.aspect.transcode.local.wizard.dll] <ATI Technologies Inc.><1.2.2217.17153>
[c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.wizard.dll] <ATI Technologies Inc.><1.2.2217.17123>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.shared.dll] <ATI Technologies Inc.><1.2.2169.27643>
[c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29142>
[c:\program files\ati technologies\ati.ace\cli.aspect.customformats.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29144>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.shared.dll] <ATI Technologies Inc.><1.2.2169.27620>
[c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty2.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29143>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29168>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29148>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29167>
[c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29165>
[c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29157>
[c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29166>
[c:\program files\ati technologies\ati.ace\cli.aspect.transcode.local.shared.dll] <ATI Technologies Inc.><1.2.0.0>
[c:\program files\ati technologies\ati.ace\atixclib.dll] < ><1.0.0.0>
[c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29155>
[PID: 2604][C:\Program Files\ATI Technologies\ATI.ACE\cli.exe] <ATI Technologies Inc.><1.11.0.0>
sayhello - 2006-6-17 0:52:00
[c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_5d820f25\mscorlib.dll] <N/A><N/A>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_fa246bd8\system.windows.forms.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.implementation.dll] <ATI Technologies Inc.><1.2.2217.17118>
[c:\program files\ati technologies\ati.ace\log.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\program files\ati technologies\ati.ace\cli.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\program files\ati technologies\ati.ace\log.foundation.service.dll] <ATI Technologies Inc.><1.2.2217.17268>
[c:\program files\ati technologies\ati.ace\log.foundation.shared.dll] <ATI Technologies Inc.><1.2.2147.29163>
[c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_7cc7ab57\system.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.foundation.xmanifestation.dll] <ATI Technologies Inc.><1.2.2217.17268>
[c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_72cd6cbd\system.xml.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\cli.component.systemtray.dll] <ATI Technologies Inc.><1.2.2217.17245>
[c:\program files\ati technologies\ati.ace\cli.caste.graphics.shared.dll] <ATI Technologies Inc.><1.2.2147.29143>
[c:\program files\ati technologies\ati.ace\cli.component.runtime.dll] <ATI Technologies Inc.><1.2.2217.17269>
[c:\program files\ati technologies\ati.ace\aticccom.dll] <ATI Technologies Inc.><1.0.0.0>
[c:\program files\ati technologies\ati.ace\dem.graphics.displaysmanager.shared.dll] <ATI Technologies Inc.><1.2.2147.29142>
[c:\program files\ati technologies\ati.ace\aem.foundation.dll] <ATI Technologies Inc.><1.2.2147.29141>
[c:\program files\ati technologies\ati.ace\apm.foundation.dll] <ATI Technologies Inc.><1.2.2147.29156>
[c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_8e62dd00\system.drawing.dll] <N/A><N/A>
[c:\program files\ati technologies\ati.ace\zh-chs\cli.component.systemtray.resources.dll] <ATI Technologies Inc.><1.2.2217.17245>
[PID: 3584][C:\WINDOWS\system32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[PID: 3384][D:\锐捷\8021x.exe] <锐捷网络><2, 50, 0, 0>
[C:\WINDOWS\system32\W32N50.dll] <Printing Communications Assoc., Inc. (PCAUSA)><5.03.16.54>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[PID: 2340][C:\WINDOWS\system32\conime.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[PID: 3440][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll] <Yahoo><1, 0, 2, 1002>
[C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll] <><2, 1, 5, 1045>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] < ><2, 0, 1, 1007>
[C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll] <Yahoo!><2, 1, 8, 1048>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yaswiper.dll] <Yahoo><1, 0, 1, 1004>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasiesec.dll] <Yahoo><1, 0, 2, 1003>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll] <><1, 1, 2, 1004>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yzsNetProto.dll] <Yahoo><1, 0, 0, 1>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll] <Yahoo! China><1, 1, 3, 1035>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll] <Yahoo! China><1, 0, 1, 1015>
[C:\WINDOWS\system32\xunleibho_v8.dll] <><4, 5, 1, 33>
[C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll] <Yahoo.><1, 0, 2, 1002>
[D:\QQ\QQIEHelper.dll] <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] <><1, 2, 7, 1006>
[H:\音乐\kugoo\KuGoo3\KuGoo3DownXControl.ocx] <N/A><N/A>
[C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[c:\progra~1\yahoo!\assist~1\assist\yadfil~1.dll] < ><1, 0, 3, 1002>
[C:\PROGRA~1\yahoo!\assistant\Shell\yAssecblk.dll] <Yahoo><1, 0, 2, 1002>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yoptimum.dll] <Yahoo><1, 0, 1, 1001>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrepair.dll] <Yahoo><1, 0, 6, 1319>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasfsks.dll] <3721.com><2, 1, 1, 87>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yXPStyle.dll] <Yahoo><1, 0, 2, 1309>
[PID: 328][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2984][D:\杀毒工具\SREng.exe] <Smallfrogs Studio><2.0.12.350>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
我无邪 - 2006-6-17 0:53:00
Router Layer]
{5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} <C:\WINDOWS\System32\aclayer.dll, N/A>
还在
关闭所有浏览窗口以及一些不必要的程序
运行System Repair Engineer,使用“系统修复,浏览器加载项”来删除以下选项。
Router Layer]
{5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} <C:\WINDOWS\System32\aclayer.dll, N/A>
1
© 2000 - 2026 Rising Corp. Ltd.