瑞星卡卡安全论坛
13610511 - 2006-8-10 0:48:00
我前天更新的8.7日版上网,用酷狗下歌曲时突然弹出一个黑客的网页,我MP4和F盘里的歌曲全被删掉刚杀上毒,MP4里出现一个日记,日记里写着叫你杀我操??????
接着杀毒软件全部被删防火墙变为4.0.0.0版 请问怎么办!!平时只时看看电影下下BT玩点游戏很少去陌生的网站
经过寻找发现他的主页有QQ号9811522[img][/img]
附件:
726057200681012143.bmp
mopery - 2006-8-10 1:04:00
http://forum.ikaka.com/topic.asp?board=28&artid=6979213第4楼下载System Repair Engineer导出全部日志
13610511 - 2006-8-10 1:37:00
2006-08-10,01:21:56
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [Microsoft Corporation]
<XDeskShow><D:\鱼鱼桌面秀\XDeskShow.exe> [鱼鱼软件]
<BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}><; "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"> [Nero AG]
<LClock><C:\Program Files\LClock\lclock.exe> []
<pyjj><; C:\Program Files\jj4\jjsvr4.exe> [加加开发组]
<Xplus><; "C:\Program Files\Xplus\Xplus_Wait.exe" /min> []
<xvcclip><; C:\Program Files\Xplus\xvcclip.exe> []
<Xplus_spy><; "C:\Program Files\Xplus\xvcclip.exe" /min> []
<MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background> [Microsoft Corporation]
<DesktopSprite><D:\雪狐桌面精灵\DesktopSprite.exe> [mycaca & sonwfox]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<Cmaudio><RunDll32 cmicnfg.cpl,CMICtrlWnd> []
<RfwMain><"D:\瑞星杀毒2006\瑞星个人防火墙\rfwmain.exe" -Startup> [Beijing Rising Technology Corporation Limited]
<RavTask><"D:\瑞星杀毒2006\瑞星杀毒软件\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<NeroFilterCheck><; C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe> [Nero AG]
<NvCplDaemon><; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
<nwiz><; nwiz.exe /install> []
<NvMediaCenter><; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit> [NVIDIA Corporation]
<KernelFaultCheck><; %systemroot%\system32\dumprep 0 -k> []
<RemoteControl><; "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"> [Cyberlink Corp.]
<LanguageShortcut><; "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"> []
<DaemonTools_WhenUSaveNow_Installer><; C:\Program Files\DaemonTools_WhenUSaveNow_Installer\DaemonTools_WhenUSaveNow_Installer.exe> [WhenU.com, Inc.]
<Vistadrv><; C:\Program Files\Vista\systool\Vistadrive\vsdrv.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<RavStub><"D:\瑞星杀毒2006\瑞星杀毒软件\ravstub.exe" /RUNONCE> [Beijing Rising Technology Co., Ltd.]
<Rfw><"D:\瑞星杀毒2006\瑞星个人防火墙\Update\setup.exe" /REPAIR /ONCE> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><wbsys.dll> [Stardock.Net, Inc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<0aMCPClient><C:\PROGRA~1\COMMON~1\Stardock\MCPCore.dll> [Stardock]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCPClient]
<WinlogonNotify: MCPClient><C:\Program Files\Common Files\Stardock\mcpstub.dll> [Stardock]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WBSrv]
<WinlogonNotify: WBSrv><C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll> [Stardock]
==================================
13610511 - 2006-8-10 1:38:00
启动文件夹
[MacVolume]
<C:\Documents and Settings\王磊\「开始」菜单\程序\启动\MacVolume.exe><N>
[Stardock ObjectDock]
<C:\Documents and Settings\王磊\「开始」菜单\程序\启动\Stardock ObjectDock.lnk><N>
[Styler]
<C:\Documents and Settings\王磊\「开始」菜单\程序\启动\Styler.lnk><N>
==================================
服务
[GrayPigeon_ker.com.cn / GrayPigeon_ker.com.cn]
<C:\WINDOWS\ker.exe><N/A>
[InstallDriver Table Manager / IDriverT]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[NBService / NBService]
<C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe><Nero AG>
[NVIDIA Display Driver Service / NVSvc]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Rising Proxy Service / RfwProxySrv]
<d:\瑞星杀毒2006\瑞星个人防火墙\rfwproxy.exe><N/A>
[Cyberlink RichVideo Service(CRVS) / RichVideo]
<"C:\Program Files\CyberLink\Shared files\RichVideo.exe"><>
[Rising Process Communication Center / RsCCenter]
<"D:\瑞星杀毒2006\瑞星杀毒软件\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"D:\瑞星杀毒2006\瑞星杀毒软件\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SF FrontLine Drivers Auto Removal (v1) / sfrem01]
<C:\WINDOWS\system32\sfrem01.exe svc><Protection Technology (StarForce)>
[StarWind iSCSI Service / StarWindService]
<C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe><Rocket Division Software>
13610511 - 2006-8-10 1:38:00
浏览器加载项
[]
{105E4D0C-5E21-41ED-90F9-013EEF271BD6} <C:\WINDOWS\system32\widgetdownload.dll, 鱼鱼桌面秀widget插件下载工具>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\KuGoo\KuGoo3DownXControl.ocx, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[StylerToolBar]
{D2F8F919-690B-4EA2-9FA7-A203D1E04F75} <C:\Program Files\Styler\TB\StylerTB.dll, StyleFantasist>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[]
{105E4D0C-5E21-41ED-90F9-013EEF271BD6} <C:\WINDOWS\system32\widgetdownload.dll, 鱼鱼桌面秀widget插件下载工具>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\System32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\KuGoo\KuGoo3DownXControl.ocx, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[StylerToolBar]
{D2F8F919-690B-4EA2-9FA7-A203D1E04F75} <C:\Program Files\Styler\TB\StylerTB.dll, StyleFantasist>
[&使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
<D:\KuGoo\KuGoo3DownX.htm, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
13610511 - 2006-8-10 1:39:00
正在运行的进程
[PID: 688][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 744][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 772][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[C:\Program Files\Common Files\Stardock\mcpstub.dll] <Stardock><0, 0, 5, 2>
[C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll] <Stardock><5, 0, 0, 1>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[PID: 820][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[PID: 832][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[PID: 1004][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[PID: 1072][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[PID: 1168][D:\瑞星杀毒2006\瑞星杀毒软件\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[PID: 1212][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\System32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[PID: 1280][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\System32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[PID: 1424][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\System32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[PID: 1448][D:\瑞星杀毒2006\瑞星杀毒软件\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 33>
[D:\瑞星杀毒2006\瑞星杀毒软件\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[D:\瑞星杀毒2006\瑞星杀毒软件\RsCommX.dll] <rising><18, 0, 0, 1>
[D:\瑞星杀毒2006\瑞星杀毒软件\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\瑞星杀毒2006\瑞星杀毒软件\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\瑞星杀毒2006\瑞星杀毒软件\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\瑞星杀毒2006\瑞星杀毒软件\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
[D:\瑞星杀毒2006\瑞星杀毒软件\HOOKSYS.dll] <Beijing Rising Technology Co., Ltd.><18, 1, 0, 11>
[D:\瑞星杀毒2006\瑞星杀毒软件\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[D:\瑞星杀毒2006\瑞星杀毒软件\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\瑞星杀毒2006\瑞星杀毒软件\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[D:\瑞星杀毒2006\瑞星杀毒软件\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[D:\瑞星杀毒2006\瑞星杀毒软件\HookWeb.dll] <rising><18, 0, 0, 2>
[D:\瑞星杀毒2006\瑞星杀毒软件\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\瑞星杀毒2006\瑞星杀毒软件\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\瑞星杀毒2006\瑞星杀毒软件\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[D:\瑞星杀毒2006\瑞星杀毒软件\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[D:\瑞星杀毒2006\瑞星杀毒软件\SpamEng.dll] <N/A><18, 0, 0, 6>
[D:\瑞星杀毒2006\瑞星杀毒软件\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[D:\瑞星杀毒2006\瑞星杀毒软件\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[D:\瑞星杀毒2006\瑞星杀毒软件\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\瑞星杀毒2006\瑞星杀毒软件\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[D:\瑞星杀毒2006\瑞星杀毒软件\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 14>
[D:\瑞星杀毒2006\瑞星杀毒软件\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[D:\瑞星杀毒2006\瑞星杀毒软件\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[D:\瑞星杀毒2006\瑞星杀毒软件\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[D:\瑞星杀毒2006\瑞星杀毒软件\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[D:\瑞星杀毒2006\瑞星杀毒软件\ScanNet.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
13610511 - 2006-8-10 1:39:00
[PID: 1624][C:\WINDOWS\system32\iscsiexe.exe] <Microsoft Corporation><5.2.3790.1653 built by: dnsrv(wmbla-s)>
[C:\WINDOWS\system32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[PID: 1664][C:\Program Files\Common Files\Stardock\SDMCP.exe] <Stardock><0, 0, 5, 11>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[PID: 1820][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[C:\PROGRA~1\COMMON~1\Stardock\MCPCore.dll] <Stardock><0, 0, 5, 4>
[C:\Program Files\LClock\LC.dll] <N/A><N/A>
[D:\超级兔子魔法设置\HappyPlayer\Codecs\mmfinfo.dll] <N/A><N/A>
[D:\超级兔子魔法设置\HappyPlayer\Codecs\mkunicode.dll] <N/A><N/A>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[C:\WINDOWS\system32\mp3infp.dll] <win32lab.com><2.52.12.0>
[C:\WINDOWS\system32\nvcpl.dll] <NVIDIA Corporation><6.14.10.8421>
[C:\WINDOWS\system32\NVRSZHC.DLL] <NVIDIA Corporation><6.14.10.8421>
[C:\WINDOWS\system32\nvshell.dll] <N/A><N/A>
[C:\Program Files\Stardock\ObjectDock\DockShellHook.dll] <N/A><N/A>
[C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll] <Nero AG><2, 2, 7, 0>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[C:\WINDOWS\system32\widgetdownload.dll] <鱼鱼桌面秀widget插件下载工具><1.3.0.0>
[C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll] <Thunder Networking Technologies,LTD><5, 0, 0, 2>
[D:\瑞星杀毒2006\瑞星杀毒软件\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1952][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[C:\WINDOWS\system32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[PID: 188][D:\瑞星杀毒2006\瑞星杀毒软件\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[D:\瑞星杀毒2006\瑞星杀毒软件\RsCommX.dll] <rising><18, 0, 0, 1>
[D:\瑞星杀毒2006\瑞星杀毒软件\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[PID: 1760][C:\WINDOWS\system32\nvsvc32.exe] <NVIDIA Corporation><6.14.10.8421>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[PID: 1980][C:\Program Files\CyberLink\Shared files\RichVideo.exe] <><1.1.0808 >
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[PID: 932][C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe] <Rocket Division Software><2.6.1 Build 0x20050401>
[C:\WINDOWS\system32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[PID: 1644][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2212][C:\WINDOWS\system32\RunDll32.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\WINDOWS\system\cmicnfg.cpl] <C-Media Corporation><1, 0, 41, 5>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\WINDOWS\System32\udaprop.dll] <C-Media Corporation><1.0.2.2>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[PID: 2232][D:\瑞星杀毒2006\瑞星杀毒软件\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[D:\瑞星杀毒2006\瑞星杀毒软件\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\瑞星杀毒2006\瑞星杀毒软件\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\瑞星杀毒2006\瑞星杀毒软件\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\瑞星杀毒2006\瑞星杀毒软件\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[PID: 2276][D:\瑞星杀毒2006\瑞星杀毒软件\Ravmon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 30>
[D:\瑞星杀毒2006\瑞星杀毒软件\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[D:\瑞星杀毒2006\瑞星杀毒软件\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\WINDOWS\system32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[D:\瑞星杀毒2006\瑞星杀毒软件\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\瑞星杀毒2006\瑞星杀毒软件\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\瑞星杀毒2006\瑞星杀毒软件\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\瑞星杀毒2006\瑞星杀毒软件\RsCommX.dll] <rising><18, 0, 0, 1>
[D:\瑞星杀毒2006\瑞星杀毒软件\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[C:\Program Files\Stardock\ObjectDock\DockShellHook.dll] <N/A><N/A>
[PID: 2464][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[PID: 2484][D:\鱼鱼桌面秀\XDeskShow.exe] <鱼鱼软件><1.8.0.730>
[C:\WINDOWS\system32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
13610511 - 2006-8-10 1:40:00
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[D:\鱼鱼桌面秀\Res\Dll\calendar100.dll] <><1.2.0.317>
[C:\Program Files\Stardock\ObjectDock\DockShellHook.dll] <N/A><N/A>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[D:\鱼鱼桌面秀\Res\Dll\weather100.dll] <><1.3.0.428>
[D:\鱼鱼桌面秀\Res\Dll\photoalbum100.dll] <><1.3.0.317>
[D:\鱼鱼桌面秀\Res\Dll\mplayer100.dll] <><1.9.0.619>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[PID: 2500][C:\Program Files\LClock\lclock.exe] <N/A><1, 0, 0, 1>
[C:\Program Files\LClock\LC.dll] <N/A><N/A>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\Program Files\LClock\Calendar.dll] <N/A><N/A>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[PID: 2600][D:\雪狐桌面精灵\DesktopSprite.exe] <mycaca & sonwfox><2.71>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[C:\Program Files\Stardock\ObjectDock\DockShellHook.dll] <N/A><N/A>
[PID: 2620][C:\Documents and Settings\王磊\「开始」菜单\程序\启动\MacVolume.exe] <Creative Mindz><0, 0, 0, 1>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[PID: 2704][C:\Program Files\Stardock\ObjectDock\ObjectDock.exe] <Stardock><v1.30.526u>
[C:\Program Files\Stardock\ObjectDock\CrashRpt.dll] <><3.0.2.2>
[C:\Program Files\Stardock\ObjectDock\zlib.dll] <N/A><1.1.3>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\Program Files\Common Files\Stardock\ODImg.dll] <N/A><N/A>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[C:\Program Files\Stardock\ObjectDock\DockShellHook.dll] <N/A><N/A>
[PID: 2732][C:\Program Files\Styler\Styler.exe] <ta2027><1, 4, 0, 1>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\Program Files\Styler\unrar\unrar.dll] <N/A><N/A>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[C:\Program Files\Stardock\ObjectDock\DockShellHook.dll] <N/A><N/A>
[PID: 2308][C:\WINDOWS\system32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\Program Files\Stardock\ObjectDock\DockShellHook.dll] <N/A><N/A>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[PID: 3004][D:\瑞星杀毒2006\瑞星杀毒软件\RsAgent.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
13610511 - 2006-8-10 1:40:00
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\Program Files\Stardock\ObjectDock\DockShellHook.dll] <N/A><N/A>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[D:\瑞星杀毒2006\瑞星杀毒软件\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 3620][C:\Program Files\Maxthon\maxthon.exe] <Maxthon International Ltd.><1, 5, 6, 42>
[C:\Program Files\Maxthon\maxzlib.dll] < ><1, 0, 0, 2>
[C:\WINDOWS\system32\wbsys.dll] <Stardock.Net, Inc><4, 0, 0, 0>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\ObjectDock\DockShellHook.dll] <N/A><N/A>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[C:\Program Files\Maxthon\Services\RealTime\real_time.dll] <><1, 0, 0, 1>
[D:\瑞星杀毒2006\瑞星杀毒软件\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] <Adobe Systems, Inc.><9,0,16,0>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.20>
[PID: 3212][C:\WINDOWS\system32\wscntfy.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\Program Files\Stardock\ObjectDock\DockShellHook.dll] <N/A><N/A>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[PID: 3496][C:\WINDOWS\system32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[PID: 3868][D:\瑞星杀毒2006\瑞星杀毒软件\Rav.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 75>
[D:\瑞星杀毒2006\瑞星杀毒软件\PlugIn\RsPgScan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 17>
[D:\瑞星杀毒2006\瑞星杀毒软件\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\瑞星杀毒2006\瑞星杀毒软件\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\瑞星杀毒2006\瑞星杀毒软件\RsCommX.dll] <rising><18, 0, 0, 1>
[D:\瑞星杀毒2006\瑞星杀毒软件\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[D:\瑞星杀毒2006\瑞星杀毒软件\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\Program Files\Stardock\ObjectDock\DockShellHook.dll] <N/A><N/A>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[D:\瑞星杀毒2006\瑞星杀毒软件\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\瑞星杀毒2006\瑞星杀毒软件\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[D:\瑞星杀毒2006\瑞星杀毒软件\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[D:\瑞星杀毒2006\瑞星杀毒软件\RavUIMsg.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 25>
[D:\瑞星杀毒2006\瑞星杀毒软件\RavQu.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[D:\瑞星杀毒2006\瑞星杀毒软件\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\瑞星杀毒2006\瑞星杀毒软件\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[D:\瑞星杀毒2006\瑞星杀毒软件\MVEngine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
[D:\瑞星杀毒2006\瑞星杀毒软件\Engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[D:\瑞星杀毒2006\瑞星杀毒软件\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\瑞星杀毒2006\瑞星杀毒软件\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[D:\瑞星杀毒2006\瑞星杀毒软件\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\瑞星杀毒2006\瑞星杀毒软件\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 14>
[D:\瑞星杀毒2006\瑞星杀毒软件\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[D:\瑞星杀毒2006\瑞星杀毒软件\RavUI2.Dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 32>
[D:\瑞星杀毒2006\瑞星杀毒软件\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
[D:\瑞星杀毒2006\瑞星杀毒软件\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[D:\瑞星杀毒2006\瑞星杀毒软件\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[D:\瑞星杀毒2006\瑞星杀毒软件\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[D:\瑞星杀毒2006\瑞星杀毒软件\ExtMail.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[D:\瑞星杀毒2006\瑞星杀毒软件\ExtFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[D:\瑞星杀毒2006\瑞星杀毒软件\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[D:\瑞星杀毒2006\瑞星杀毒软件\ScanNet.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 3944][C:\Program Files\jj4\jjsvr4.exe] <加加开发组><4.0.0.19>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\Program Files\Stardock\ObjectDock\DockShellHook.dll] <N/A><N/A>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
[PID: 3028][C:\Documents and Settings\王磊\桌面\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll] <Stardock Corporation><5.01>
[C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll] <Stardock.Net, Inc><4.01>
[C:\Program Files\Stardock\ObjectDock\DockShellHook.dll] <N/A><N/A>
[C:\Program Files\Styler\StylerHelper.dll] <ta2027><1, 3, 1, 1>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
mopery - 2006-8-10 1:42:00
[GrayPigeon_ker.com.cn / GrayPigeon_ker.com.cn]
<C:\WINDOWS\ker.exe><N/A>
鸽子..安全模式...打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索GrayPigeon_ker.com.cn 删除..
删除
C:\WINDOWS\ker.exe
http://www.pctutu.com/srmsdown.asp
下载超级兔子..用超级兔子清理王卸载流氓软件...(安全模式...)
13610511 - 2006-8-10 1:42:00
冲安杀毒后杀毒发现
WINDOWS下的PE病毒 Backdoor.Gpigeon.uql
mopery - 2006-8-10 1:46:00
你只是中了鸽子,,,别人家删了掉东西..按我的做就行..
1
© 2000 - 2026 Rising Corp. Ltd.