暗夜徘徊者 - 2006-7-7 13:24:00
公司的局域网电脑,安装的趋势防毒
Logfile of HijackThis v1.99.0
Scan saved at 13:09:55, on 2006-7-7
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\WZCBDL Service\WZCBDLS.exe
C:\WINNT\Explorer.EXE
C:\WINNT\TEMP\CHB3C8.EXE
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Trend Micro\OfficeScan Client\TSC.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\D-Link\Air USB Utility\AirCFG.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Documents and Settings\Administrator\桌面\HijackThis.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WangWang] "C:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE"
O4 - HKLM\..\Run: [gemstrmw] C:\WINNT\system32\gemstrmw.exe /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [D-Link Air USB Utility] C:\Program Files\D-Link\Air USB Utility\AirCFG.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java 控制台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} (ObjWinNTCheck Class) - http://10.34.156.14/officescan/console/ClientInstall/WinNTChk.cab
O16 - DPF: {017767CF-2834-11D4-98F9-00C0DF242218} (INtess-ICDV3.0 WECC Client Control) - http://211.138.200.20/images/iccctrls.cab
O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupINICtrl Class) - http://10.34.156.14/officescan/console/ClientInstall/setupini.cab
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) - http://10.34.156.14/officescan/console/ClientInstall/setup.cab
O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} (Encrypt Class) - http://10.34.156.14/officescan/console/html/AtxEnc.cab
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/1007/aliedit.cab
O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class) - http://10.34.156.14/officescan/console/ClientInstall/RemoveCtrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1140677900406
O16 - DPF: {DDB1E5C2-75A3-477B-BC0F-3CE60C7B0AE2} (BossFlash Control) - http://10.32.197.52:7799/bossflash_dl/server/bossflashsetupD6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF314E00-BFC4-4D6E-A30E-468DF49845B9}: NameServer = 10.32.166.158
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: OfficeScanNT 实时扫描 - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT 个人防火墙 - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: OfficeScanNT 侦听程序 - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: WZCBDL Service - D-Link - C:\Program Files\WZCBDL Service\WZCBDLS.exe
暗夜徘徊者 - 2006-7-7 13:38:00
CHB3C8.EXE没办法结束进程
我无邪 - 2006-7-7 13:40:00
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。
暗夜徘徊者 - 2006-7-7 13:52:00
2006-07-07,13:52:21
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<PcSync><C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog> [Time Information Services Ltd.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Synchronization Manager><mobsync.exe /logon> [Microsoft Corporation]
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<WangWang><"C:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE"> [淘宝(中国)软件有限公司]
<gemstrmw><C:\WINNT\system32\gemstrmw.exe /r> [Gemplus]
<SunJavaUpdateSched><C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe> [Sun Microsystems, Inc.]
<PCSuiteTrayApplication><C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray> [Nokia]
<OfficeScanNT Monitor><"C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow> [Trend Micro Inc.]
<D-Link Air USB Utility><C:\Program Files\D-Link\Air USB Utility\AirCFG.exe> [D-Link]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINNT\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
==================================
启动文件夹
服务
[Logical Disk Manager Administrative Service / dmadmin]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[HP Web Jetadmin / HPWebJetadmin]
<"C:\Program Files\HP Web Jetadmin\hpwebjetd.exe" -k runservice><Apache Software Foundation>
[OfficeScanNT 实时扫描 / ntrtscan]
<C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe><Trend Micro Inc.>
[OfficeScanNT 个人防火墙 / OfcPfwSvc]
<C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe><Trend Micro Inc.>
[OfficeScanNT 侦听程序 / tmlisten]
<C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe><Trend Micro Inc.>
[WZCBDL Service / WZCBDLService]
<"C:\Program Files\WZCBDL Service\WZCBDLS.exe"><D-Link>
==================================
浏览器加载项
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[SSVHelper Class]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll, Sun Microsystems, Inc.>
[ObjWinNTCheck Class]
{00134F72-5284-44F7-95A8-52A619F70751} <C:\WINNT\Downloaded Program Files\WinNTChk.dll, Trend Micro Inc.>
[INtess-ICDV3.0 WECC Client Control]
{017767CF-2834-11D4-98F9-00C0DF242218} <C:\WINNT\DOWNLO~1\ICCCtrls.dll, 华为技术有限公司>
[OfficeScan Corp Edition Web-Deployment SetupINICtrl Class]
{08D75BB0-D2B5-11D1-88FC-0080C859833B} <C:\WINNT\Downloaded Program Files\OfficeScanSetupINI.dll, Trend Micro Inc.>
[OfficeScan Corp Edition Web-Deployment SetupCtrl Class]
{08D75BC1-D2B5-11D1-88FC-0080C859833B} <C:\WINNT\Downloaded Program Files\OfficeScanSetup.dll, Trend Micro Inc.>
[Encrypt Class]
{35C3D91E-401A-4E45-88A5-F3B32CD72DF4} <C:\WINNT\Downloaded Program Files\AtxEnc.dll, Trend Micro Inc.>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINNT\system32\aliedit\AliEdit.dll, www.alipay.com>
[OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class]
{5EFE8CB1-D095-11D1-88FC-0080C859833B} <C:\WINNT\Downloaded Program Files\OfficeScanRemoveCtrl.dll, Trend Micro Inc.>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINNT\system32\wuweb.dll, Microsoft Corporation>
[Java Plug-in]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in]
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.5.0_06]
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll, Sun Microsystems, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[BossFlash Control]
{DDB1E5C2-75A3-477B-BC0F-3CE60C7B0AE2} <C:\PROGRA~1\BOSSFL~1\BOSSFL~1.OCX, >
==================================
暗夜徘徊者 - 2006-7-7 14:00:00
==================================
正在运行的进程
[PID: 140][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.00.2195.6601>
[PID: 172][\??\C:\WINNT\system32\csrss.exe] <Microsoft Corporation><5.00.2195.6601>
[PID: 192][\??\C:\WINNT\system32\winlogon.exe] <Microsoft Corporation><5.00.2195.6997>
[PID: 220][C:\WINNT\system32\services.exe] <Microsoft Corporation><5.00.2195.7035>
[C:\WINNT\system32\dmserver.dll] <VERITAS Software Corp.><2195.6605.297.3>
[PID: 232][C:\WINNT\system32\lsass.exe] <Microsoft Corporation><5.00.2195.7011>
[PID: 368][C:\WINNT\System32\SCardSvr.exe] <Microsoft Corporation><5.00.2195.6609>
[PID: 428][C:\WINNT\system32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 456][C:\WINNT\system32\spoolsv.exe] <Microsoft Corporation><5.00.2195.7059>
[C:\WINNT\system32\hptcpmon.dll] <Hewlett Packard><2.40.01.017>
[C:\WINNT\system32\hptcpmib.dll] <Hewlett Packard><2.40.01.017>
[PID: 516][C:\WINNT\system32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 548][C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcDog.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInAPI.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\TimeString.dll] <N/A><N/A>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] <N/A><N/A>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInMain.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInTray.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\tmdbg20.dll] <trend_company_name><1, 0, 0, 1>
[PID: 648][C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwCommon.dll] <N/A><N/A>
[C:\Program Files\Trend Micro\OfficeScan Client\ZLib.dll] <Trend Micro Inc.><1.31.0.1708>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] <N/A><N/A>
[C:\Program Files\Trend Micro\OfficeScan Client\tmdbg20.dll] <trend_company_name><1, 0, 0, 1>
[C:\Program Files\Trend Micro\OfficeScan Client\tmCfwApi.dll] <Trend Micro Inc.><1.2.0.1029>
[PID: 672][C:\WINNT\system32\regsvc.exe] <Microsoft Corporation><5.00.2195.6701>
[PID: 688][C:\WINNT\system32\MSTask.exe] <Microsoft Corporation><4.71.2195.6972>
[PID: 712][C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\TMSOCK.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\loadhttp.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInAPI.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] <N/A><N/A>
[C:\Program Files\Trend Micro\OfficeScan Client\libTmCAV.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\Pwd.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcDog.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\tmdbg20.dll] <trend_company_name><1, 0, 0, 1>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInMain.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInTray.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\TmUpdate.dll] <Trend Micro Inc.><2,6,0,1367>
[PID: 792][C:\WINNT\System32\WBEM\WinMgmt.exe] <Microsoft Corporation><1.50.1085.0100>
[PID: 812][C:\WINNT\system32\mspmspsv.exe] <Microsoft Corporation><7.10.00.3059>
[PID: 836][C:\WINNT\system32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 848][C:\Program Files\WZCBDL Service\WZCBDLS.exe] <D-Link><1, 0, 0, 20319>
[C:\WINNT\system32\WZCBDL.DLL] <Alpha Networks Inc.><1, 2, 3, 30606>
[C:\WINNT\system32\QCKGen.dll] <D-Link Corporation><1, 0, 0, 20316>
[C:\WINNT\system32\libwlan.dll] <Alpha Networks Inc.><1, 2, 8, 30703>
[C:\WINNT\system32\NIOCApi.dll] <D-Link Corporation ><2, 0, 0, 30429>
[PID: 1052][C:\WINNT\Explorer.EXE] <Microsoft Corporation><5.00.3700.6690>
[C:\WINNT\system32\igfxpph.dll] <Intel Corporation><3.0.0.3847>
[C:\WINNT\system32\hccutils.DLL] <Intel Corporation><3.0.0.3847>
[C:\WINNT\system32\igfxres.dll] <Intel Corporation><3.0.0.3847>
[C:\WINNT\system32\igfxsrvc.dll] <Intel Corporation><3.0.0.3847>
[C:\WINNT\system32\igfxdev.dll] <Intel Corporation><3.0.0.3847>
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] <Adobe Systems Incorporated><6.0.1.2003110300>
[C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll] <Sun Microsystems, Inc.><5.0.60.5>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[PID: 1100][C:\WINNT\TEMP\CHB3C8.EXE] <N/A><N/A>
[PID: 1168][C:\WINNT\SOUNDMAN.EXE] <Realtek Semiconductor Corp.><5.1.0.28>
[
暗夜徘徊者 - 2006-7-7 14:00:00
PID: 1224][C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe] <Sun Microsystems, Inc.><5.0.60.5>
[PID: 1244][C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE] <Nokia><6, 70, 41, 5>
[C:\WINNT\system32\ConnAPI.DLL] <Nokia.><6, 70, 39, 5>
[C:\PROGRA~1\Nokia\NOKIAP~1\PCSCM.dll] <Nokia><6, 70, 58, 3>
[C:\Program Files\Common Files\PCSuite\ConfServer\ConfServer.dll] <Nokia><6, 70, 14, 1>
[C:\PROGRA~1\Nokia\NOKIAP~1\Lang\LaunchApplication_chi-sc.NLR] <Nokia><6, 70, 31, 1>
[PID: 1252][C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\loadhttp.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\Pwd.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInAPI.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] <N/A><N/A>
[C:\Program Files\Trend Micro\OfficeScan Client\TimeString.dll] <N/A><N/A>
[C:\Program Files\Trend Micro\OfficeScan Client\ntmonres.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInMain.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInTray.dll] <Trend Micro Inc.><7.0.0.1116>
[C:\Program Files\Trend Micro\OfficeScan Client\tmdbg20.dll] <trend_company_name><1, 0, 0, 1>
[PID: 1268][C:\Program Files\D-Link\Air USB Utility\AirCFG.exe] <D-Link><3, 1, 5, 30723>
[C:\WINNT\system32\libwlan.dll] <Alpha Networks Inc.><1, 2, 8, 30703>
[C:\WINNT\system32\NIOCApi.dll] <D-Link Corporation ><2, 0, 0, 30429>
[C:\WINNT\system32\QCKGen.dll] <D-Link Corporation><1, 0, 0, 20316>
[PID: 1280][C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe] <Time Information Services Ltd.><2.00 (467)>
[C:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll] <Nokia><6, 70, 58, 3>
[C:\WINNT\system32\ConnAPI.DLL] <Nokia.><6, 70, 39, 5>
[C:\Program Files\Nokia\Nokia PC Suite 6\PCSL.dll] <Nokia><6, 70, 4, 0>
[C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\Lang\PcSync2_chi-sc.nlr] <Time Information Services Ltd.><8.00 (467)>
[C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\Resource\PcSync2_Nokia.ngr] <Time Information Services Ltd.><8.00 (467)>
[C:\Program Files\Common Files\Nokia\Adapters\NclSet.dll] <Nokia><6.70.9.0>
[C:\Program Files\Common Files\Nokia\Adapters\Nclaeo.dsc] <Nokia Mobile Phones Ltd.><4.00.008>
[C:\Program Files\Common Files\Nokia\MPAPI\MPAPIps.dll] <Nokia Corporation><6.70.73.0>
[C:\Program Files\Common Files\PCSuite\ConfServer\ConfServer.dll] <Nokia><6, 70, 14, 1>
[C:\Program Files\Nokia\Nokia PC Suite 6\CommonSelectDevice.dll] <Nokia><6, 70, 65, 3>
[PID: 1420][C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe] <Nokia Corporation><6.70.161.0>
[C:\Program Files\Common Files\Nokia\MPAPI\MPAPIps.dll] <Nokia Corporation><6.70.73.0>
[PID: 1496][C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE] <Nokia.><6, 70, 45, 1>
[C:\WINNT\system32\NclTools.dll] <Nokia.><6, 70, 12, 0>
[C:\Program Files\Common Files\PCSuite\Transports\NCLIrDAMM.dll] <Nokia Corp.><6, 70, 20, 1>
[C:\Program Files\Common Files\PCSuite\Transports\NCLRSMM.dll] <Nokia><6, 70, 30, 0>
[C:\Program Files\Common Files\PCSuite\Transports\NCLUSBMM.dll] <Nokia><6, 70, 32, 1>
[C:\Program Files\Common Files\PCSuite\Services\NclDS.dll] <Nokia><6, 70, 9, 0>
[PID: 1656][C:\WINNT\system32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[PID: 1680][C:\Documents and Settings\Administrator\桌面\HijackThis.exe] <Soeperman Enterprises Ltd.><1.99>
[PID: 1632][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><6.00.2800.1106>
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] <Adobe Systems Incorporated><6.0.1.2003110300>
[C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll] <Sun Microsystems, Inc.><5.0.60.5>
[C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] <N/A><N/A>
[C:\WINNT\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[PID: 1352][C:\Documents and Settings\Administrator\桌面\sreng2\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[PID: 620][C:\Documents and Settings\Administrator\桌面\sreng2\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
我无邪 - 2006-7-7 14:28:00
日志看不出问题来
建议对C:\WINNT\TEMP\CHB3C8.EXE下手
请到www.27814939.ys168.com,点“我的软件”下载诺顿进程管理器,终止CHB3C8.EXE 的进程
删除C:\WINNT\TEMP所有能删除的东东。
暗夜徘徊者 - 2006-7-7 14:38:00
谢谢!
我把C:\WINNT\TEMP\CHB3C8.EXE 更名后,重启了
然后就删掉了
© 2000 - 2026 Rising Corp. Ltd.