瑞星卡卡安全论坛
周翀周翀 - 2006-7-29 17:23:00
2006-07-29,17:13:12
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [Microsoft Corporation]
<pyjj><C:\Program Files\jj4\jjsvr4.exe> [加加开发组]
<DesktopSprite><C:\Program Files\SnowFox\DesktopSprite2\DesktopSprite.exe> [SnowFox Studio.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<IgfxTray><C:\WINDOWS\System32\igfxtray.exe> [Intel Corporation]
<HotKeysCmds><C:\WINDOWS\System32\hkcmd.exe> [Intel Corporation]
<IMEKRMIG6.1><C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE> [Microsoft Corporation]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<dla><C:\WINDOWS\system32\dla\tfswctrl.exe> [Sonic Solutions]
<TrackPointSrv><tp4serv.exe> [IBM Corporation]
<CdnCtr><C:\Program Files\CNNIC\Cdn\cdnup.exe> []
<WebThunder><C:\Program Files\Thunder Network\WebThunder\WebThunder.exe> [深圳市迅雷网络技术有限公司]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\System32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><> []
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<Vision><> []
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\PROGRA~1\疯狂赛车\data\GUI\mov\kartss.scr> []
==================================
启动文件夹
服务
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Bluetooth Service / btwdins]
<C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe><WIDCOMM, Inc.>
[IBM Rapid Restore Ultra Service / IBM Rapid Restore Ultra Service]
<C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe><>
[IBM PSA Access Driver Control / PsaSrv]
<C:\WINDOWS\system32\PsaSrv.exe><N/A>
[QCONSVC / QCONSVC]
<System32\QCONSVC.EXE><IBM Corp.>
[Rising Personal Firewall Service / RfwService]
<C:\Program Files\Rising\Rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[StdService / StdService]
<C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\STDSVER.DLL,Service><N/A>
[svchvst.exe / svchvst.exe]
<C:\WINDOWS\svchvst.exe><N/A>
[Registry Protector / WIDETS]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
周翀周翀 - 2006-7-29 17:23:00
浏览器加载项
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_011.dll, Thunder Networking Technologies,LTD>
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\System32\xunleibho_v4.dll, >
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[CPub Object]
{0CA51D02-7739-43EA-8D9A-1E8AD4327B03} <C:\Program Files\P4P\sodaie.dll, N/A>
[Yahoo!Photo]
{33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
{38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll, Yahoo.>
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[DragSearch BHO]
{62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, >
[stdup]
{6A512BF7-EC78-4e8d-9841-6C02E8FA9838} <C:\WINDOWS\SYSTEM32\stdup.dll, MStdup Co Ltd.>
[AtlObj Class]
{7E093FD0-5372-4FD5-9C7B-875668B4CDB2} <C:\WINDOWS\system32\Ado32.dll, >
[IeCatch2 Class]
{A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~1\FlashGet\jccatch.dll, Amaze Soft>
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[Google Toolbar Helper]
{AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[HBObject Class]
{AE22AFE5-1EF4-4D25-9E23-D2825FB17DA1} <C:\PROGRA~1\HBClient\hbhelper.dll, N/A>
[WMHlprObj Class]
{F5824EFB-728A-4726-A5A5-85A68B20EDC3} <C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll, CNNIC>
[浩方对战平台]
{0A155D3C-68E2-4215-A47A-E800A446447A} <C:\Program Files\浩方对战平台\GameClient.exe, 上海浩方在线信息技术有限公司>
[网址大全]
{1FBA04EE-3024-11D2-8F1F-0000F87ABD18} <http://www.coc.cc, N/A>
[网址大全]
{1FBA04EE-3024-11D2-8F1F-0000F87ABD18}? <http://www.coc.cc, N/A>
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[MMSAssistMenu]
{6671A433-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[启动Web迅雷]
{962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\QQ2005\QQ.EXE, N/A>
[@btrez.dll,-4015]
{CCA281CA-C863-46ef-9331-5C8D4460577F} <, N/A>
[FlashGet]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FlashGet\flashget.exe, Amaze Soft>
[易趣购物]
{DE60714F-AC19-427e-861A-FD60ABDF119A} <http://click2.ad4all.net/url2/urlmanage/url.asp?id=1, N/A>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6}? <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[易趣购物]
{EE60714F-AC17-427e-861A-FD60CBDF119A} <http://click2.ad4all.net/url2/urlmanage/url.asp?id=159, N/A>
[精彩图铃]
{EE60714F-AC27-427e-861A-FD60CBDF119A} <http://click2.ad4all.net/url2/urlmanage/url.asp?id=162, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\MSMSGS.EXE, Microsoft Corporation>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\MSDXM.OCX, Microsoft Corporation>
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\PROGRA~1\FlashGet\fgiebar.dll, Amaze Soft>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\System32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[Edit Class]
{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\System32\CMBEdit.dll, >
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\System32\aliedit\AliEdit.dll, www.alipay.com>
[MUWebControl Class]
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\System32\muweb.dll, Microsoft Corporation>
[Java Plug-in 1.4.1]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\IBM\Java141\jre\bin\NPJPI141.dll, IBM.>
[Java Plug-in 1.4.1]
{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} <C:\Program Files\IBM\Java141\jre\bin\NPJPI141.dll, IBM.>
[CPasswordEditCtrl Object]
{E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\System32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[ >> 彩信发送 <<]
<res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm, N/A>
[&使用暴风下载器下载]
<C:\Program Files\Ringz Studio\Storm Downloader\geturl.htm, N/A>
[>>彩信发送<<]
<res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm, N/A>
[Google 搜索(&G)]
<res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html, N/A>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
<C:\Program Files\KuGoo3\KuGoo3DownX.htm, N/A>
[使用Web迅雷下载]
<C:\Program Files\Thunder Network\WebThunder\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
<C:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm, N/A>
[使用网际快车下载]
<C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<C:\Program Files\FlashGet\jc_all.htm, N/A>
[反向链接]
<res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html, N/A>
[发送到 Bluetooth(&B)]
<C:\Program Files\IBM\Bluetooth Software\btsendto_ie_ctx.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[收藏此页到新浪ViVi]
<http://vivi.sina.com.cn/collect/click.php?agent=ddt, N/A>
[新浪搜索]
<http://cha.sina.com.cn/ddt.html, N/A>
[易趣购物]
<C:\Program Files\AD4All\link1\ebaylink.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[添加到雅虎订阅(&Y)]
<res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT, N/A>
[类似网页]
<res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html, N/A>
[精彩图铃]
<C:\Program Files\AD4All\link2\phone.htm, N/A>
[缓存的网页快照]
<res://c:\program files\google\GoogleToolbar2.dll/cmcache.html, N/A>
[翻译英文字词(&T)]
<res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html, N/A>
[访问通用网址]
<C:\Program Files\CNNIC\Cdn\cnnic.htm, N/A>
[雅虎搜索]
<res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246, N/A>
周翀周翀 - 2006-7-29 17:24:00
正在运行的进程
[PID: 428][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 480][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 516][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.1557 (xpsp2_gdr.040517-1325)>
[PID: 560][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 572][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[C:\WINDOWS\system32\pwdmon.dll] <N/A><N/A>
[PID: 756][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
周翀周翀 - 2006-7-29 17:25:00
[PID: 816][C:\Program Files\Rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 832][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 964][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 992][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1008][C:\Program Files\Rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 3>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 17>
[C:\Program Files\Rising\Rav\HOOKSYS.dll] <Rising><18, 1, 0, 9>
[C:\Program Files\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
[C:\Program Files\Rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\HookWeb.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
[C:\Program Files\Rising\Rav\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[C:\Program Files\Rising\Rav\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Rising\Rav\SpamEng.dll] <N/A><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[C:\Program Files\Rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[C:\Program Files\Rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\Rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\Rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[C:\Program Files\Rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[C:\Program Files\Rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\Program Files\Rising\Rav\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\ScanNet.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Rising\Rav\RsStore.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[PID: 1096][C:\Program Files\Rising\Rfw\rfwsrv.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
[C:\Program Files\Rising\Rfw\RfwRule.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
[C:\Program Files\Rising\Rfw\rfwlog.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
[C:\Program Files\Rising\Rfw\Rfwdrv.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
[C:\Program Files\Rising\Rfw\MonDrv.dll] <rs><1, 0, 0, 4>
[C:\Program Files\Rising\Rfw\ProcLib.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 1408][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.1699 (xpsp2.050610-1533)>
[C:\WINDOWS\system32\bthcrp.dll] <WIDCOMM, Inc.><1.4.3 Build 3>
[C:\WINDOWS\system32\WidcommSdk.dll] <WIDCOMM, Inc.><1.4.3 Build 3>
[C:\WINDOWS\system32\wbtapi.dll] <WIDCOMM, Inc.><1.4.3 Build 3>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 1536][C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe] <WIDCOMM, Inc.><1.4.3 Build 3>
[PID: 1564][C:\Program Files\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1820][C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe] <><4,0,0,4021>
[PID: 1944][C:\WINDOWS\System32\QCONSVC.EXE] <IBM Corp.><3, 0, 0, 0>
[PID: 120][C:\WINDOWS\System32\rundll32.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\System32\STDSVER.DLL] <MStdup Co Ltd.><3, 2, 2, 2>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 392][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 972][C:\WINDOWS\System32\conime.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1024][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><1, 0, 0, 3>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 2, 0, 2>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 1, 0, 0>
[C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_011.dll] <Thunder Networking Technologies,LTD><6, 0, 0, 2>
[C:\PROGRA~1\FlashGet\jccatch.dll] <Amaze Soft><1, 1, 4, 0>
[C:\WINDOWS\System32\xunleibho_v4.dll] <><4, 3, 2, 29>
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] <Adobe Systems Incorporated><6.0.0.2003051500>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll] <Yahoo! China><1, 1, 3, 1035>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll] <Yahoo!><2, 1, 8, 1048>
[C:\WINDOWS\system32\dla\tfswshx.dll] <Sonic Solutions><1.04.07a>
[C:\WINDOWS\System32\tfswapi.dll] <Sonic Solutions><1.04.07a>
[C:\WINDOWS\system32\dla\tfswcres.dll] <Sonic Solutions><1.04.07a>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] <><1, 2, 7, 1006>
[C:\WINDOWS\SYSTEM32\stdup.dll] <MStdup Co Ltd.><3, 2, 2, 2>
[C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] <N/A><N/A>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 1292][C:\Program Files\Rising\Rfw\RfwMain.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 51>
[C:\Program Files\Rising\Rfw\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
[C:\Program Files\Rising\Rfw\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rfw\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><1, 0, 0, 3>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 2, 0, 2>
[PID: 252][C:\WINDOWS\System32\igfxtray.exe] <Intel Corporation><3.0.0.2331>
[C:\WINDOWS\System32\hccutils.DLL] <Intel Corporation><3.0.0.2331>
[C:\WINDOWS\System32\igfxdev.dll] <Intel Corporation><3.0.0.2331>
[C:\WINDOWS\System32\igfxsrvc.dll] <Intel Corporation><3.0.0.2331>
[C:\WINDOWS\System32\igfxres.dll] <Intel Corporation><3.0.0.2331>
[C:\WINDOWS\System32\igfxress.dll] <Intel Corporation><3.0.0.2331>
[PID: 248][C:\WINDOWS\System32\hkcmd.exe] <Intel Corporation><3.0.0.2331>
[C:\WINDOWS\System32\hccutils.DLL] <Intel Corporation><3.0.0.2331>
[C:\WINDOWS\System32\igfxdev.dll] <Intel Corporation><3.0.0.2331>
[C:\WINDOWS\System32\igfxsrvc.dll] <Intel Corporation><3.0.0.2331>
[C:\WINDOWS\System32\igfxhk.dll] <Intel Corporation><3.0.0.2331>
[C:\WINDOWS\System32\igfxres.dll] <Intel Corporation><3.0.0.2331>
[PID: 372][C:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
周翀周翀 - 2006-7-29 17:25:00
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 204][C:\WINDOWS\system32\dla\tfswctrl.exe] <Sonic Solutions><1.04.07a>
[C:\WINDOWS\System32\tfswapi.dll] <Sonic Solutions><1.04.07a>
[C:\WINDOWS\system32\dla\tfswcres.dll] <Sonic Solutions><1.04.07a>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><1, 0, 0, 3>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 2, 0, 2>
[PID: 448][C:\Program Files\Rising\Rav\Ravmon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 99>
[C:\Program Files\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><1, 0, 0, 3>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 2, 0, 2>
[PID: 288][C:\WINDOWS\System32\tp4serv.exe] <IBM Corporation><3.12>
[C:\WINDOWS\System32\tp4uires.dll] <N/A><N/A>
[PID: 628][C:\Program Files\CNNIC\Cdn\cdnup.exe] <><2, 3, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 2, 0, 2>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><1, 0, 0, 3>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdntdns.dll] <CNNIC><2, 2, 0, 3>
[PID: 1216][C:\Program Files\Thunder Network\WebThunder\WebThunder.exe] <深圳市迅雷网络技术有限公司><1, 1, 6, 41>
[C:\Program Files\Thunder Network\WebThunder\taskmanage.dll] <Thunder Networking Technologies,LTD><1, 1, 0, 42>
[C:\Program Files\Thunder Network\WebThunder\download_interface.dll] <Thunder Networking Technologies,LTD><1, 0, 3, 70>
[C:\Program Files\Thunder Network\WebThunder\asyn_dns.dll] <N/A><N/A>
[C:\Program Files\Thunder Network\WebThunder\RegisterDll.dll] <Thunder Networking Technologies,LTD><2, 0, 0, 13>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><1, 0, 0, 3>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 2, 0, 2>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 0>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\Program Files\Thunder Network\WebThunder\historyinfo_manage.dll] <Thunder Networking Technologies,LTD><5, 2, 0, 150>
[C:\Program Files\Thunder Network\WebThunder\UpdateDownload.dll] <Thunder Networking Technologies,LTD><1, 0, 1, 8>
[C:\Program Files\Thunder Network\WebThunder\UpdateExec.dll] <Thunder Networking Technologies,LTD><1, 0, 1, 5>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 1, 0, 0>
[C:\Program Files\Thunder Network\WebThunder\iEmbedShell.dll] < ><1, 0, 0, 10>
[C:\Program Files\Thunder Network\WebThunder\iEmbed03.dll] < ><2, 2, 1, 33>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\WINDOWS\System32\Flash.ocx] <Macromedia, Inc.><7,0,19,0>
[PID: 1400][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 2, 0, 2>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><1, 0, 0, 3>
[PID: 1752][C:\Program Files\jj4\jjsvr4.exe] <加加开发组><4.0.0.20>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><1, 0, 0, 3>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 2, 0, 2>
[PID: 1084][C:\Program Files\SnowFox\DesktopSprite2\DesktopSprite.exe] <SnowFox Studio.><2.7.0.55>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><1, 0, 0, 3>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 2, 0, 2>
[PID: 3132][C:\Program Files\Maxthon12\Maxthon.exe] <Maxthon International Ltd.><1, 5, 2, 21>
[C:\Program Files\Maxthon12\maxzlib.dll] < ><1, 0, 0, 2>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><1, 0, 0, 3>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 2, 0, 2>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_011.dll] <Thunder Networking Technologies,LTD><6, 0, 0, 2>
[C:\Program Files\Maxthon12\Services\RealTime\real_time.dll] <><1, 0, 0, 1>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\WINDOWS\System32\JPWB.IME] <常诚研制><4.00.950>
[C:\WINDOWS\System32\PYJJ4.IME] <加加工作组><4.0.0.21>
[C:\WINDOWS\System32\Flash.ocx] <Macromedia, Inc.><7,0,19,0>
[PID: 3092][C:\Program Files\Rising\Rav\RsAgent.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><1, 0, 0, 3>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 2, 0, 2>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 2776][C:\WINDOWS\msagent\AgentSvr.exe] <Microsoft Corporation><2.00.0.3422>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><1, 0, 0, 3>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 2, 0, 2>
[PID: 1136][C:\TDdownload\sreng2\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <CNNIC><2, 2, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] <CNNIC><1, 0, 0, 3>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <CNNIC><2, 2, 0, 2>
[C:\WINDOWS\System32\cdnns.dll] <CNNIC><2, 0, 0, 0>
周翀周翀 - 2006-7-29 17:25:00
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. [C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS Error. []
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
周翀周翀 - 2006-7-29 17:27:00
我家的电脑速度二八号杀了病毒后还是很慢!网络设置没了,开我的电脑还要搜索半天.瑞星的防火墙不知道怎么也坏了!顺便告诉我一下哪些在启动的时候不要啊?
周翀周翀 - 2006-7-29 17:29:00
对于成功帮我解除问题的大虾给予适当奖励包括QQ币
newcenturymoon - 2006-7-29 17:30:00
开始 运行 输入 services.msc 找到svchvst.exe, Registry Protector / WIDETS,StdService双击 停止并且将启动类型改为 已禁用
开始 运行 输入regedit 分别定位到HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Services
查找svchvst.exe, Registry Protector / WIDETS,StdService目录,查到的清删除整个目录
重启计算机
显示所有文件并且显示隐藏的系统文件
删除如下文件C:\WINDOWS\svchvst.exe
C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL
C:\WINDOWS\System32\STDSVER.DLL
下载超级兔子 卸载流氓软件
1
© 2000 - 2026 Rising Corp. Ltd.