瑞星卡卡安全论坛
psok - 2006-8-11 23:15:00
种了trojan病毒,安全模式杀了多次也杀不掉,copy了一个日志,大侠帮看看啊
Logfile of HijackThis v1.99.1
Scan saved at 22:55:53, on 2006-8-12
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Monitor\netmon.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\SoftEther\SoftEther.exe
d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\System32\conime.exe
C:\Program Files\QuickTime\qttask.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\wdfmgr.exe
C:\WINDOWS\System32\Rundll32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
D:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Rising\Rav\Rav.exe
D:\Program Files\HijackThis.exe
O3 - Toolbar: 系统标准按钮(&E) - {6B2455FD-3669-4555-8DF8-69FD5BC846F8} - C:\WINDOWS\system32\SystemToolbar.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [Intranet] C:\WINDOWS\intranet.exe
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
O4 - HKLM\..\Run: [IESAddr] RunDll32 "C:\WINDOWS\Downlo~1\Gladiator.dll",Boot
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [BIE] Rundll32 C:\WINDOWS\DOWNLO~1\BDPlugin.dll,Rundll32
O4 - HKCU\..\Run: [Taskmor.exe] C:\WINDOWS\taskmor.exe
O4 - HKCU\..\Run: [caishowmanage] C:\Program Files\CaiShow Tech\CaiShow\UpdateManager.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &使用迅雷下载 - d:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\qq\SendMMS.htm
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/1007/aliedit.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1154719534300
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AXSafeControls.cab
O16 - DPF: {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} (photo_uploader Control) - http://upload.photo.163.com/photoup.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Location Awareness (NLA) (Device Access) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Procedure Call (RPC) - Unknown owner - C:\WINDOWS\Grver1.23.dll (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: SoftEther Virtual LAN Card (SoftEther) - Unknown owner - C:\Program Files\SoftEther\SoftEther.exe" service (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Microsoft Windows Spool Service (Windows Spool Service) - Unknown owner - C:\WINDOWS\wdfmgr.exe
我无邪 - 2006-8-11 23:33:00
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe这一项想问问你是否知道是什么东东?
开始→运行→输入services.msc,打开“服务”→查找 Location Awareness (NLA),Network Monitor,Procedure Call,Microsoft Windows Spool Service→双击→启动类型→禁止→停止→应用→确定。禁止Location Awareness (NLA),Network Monitor,Procedure Call,Microsoft Windows Spool Service这4个服务 (每一个逗号隔开的就是一个病毒的服务,请逐一禁用)
关闭所有浏览窗口以及一些不必要的程序
运行Hijackthis,扫描结束后在下列选项前打上勾,然后选"修复
O4 - HKCU\..\Run: [Taskmor.exe] C:\WINDOWS\taskmor.exe
O4 - HKLM\..\Run: [Intranet] C:\WINDOWS\intranet.exe
O3 - Toolbar: 系统标准按钮(&E) - {6B2455FD-3669-4555-8DF8-69FD5BC846F8} - C:\WINDOWS\system32\SystemToolbar.dll (file missing)
删除
C:\WINDOWS\intranet.exe
C:\WINDOWS\taskmor.exe
重启后删除
C:\Program Files\Network Monitor
C:\WINDOWS\wdfmgr.exe
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。
得道高僧 - 2006-8-12 0:24:00
高手!!
psok - 2006-8-12 22:21:00
2006-08-13,22:08:46
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<caishowmanage><C:\Program Files\CaiShow Tech\CaiShow\UpdateManager.EXE> []
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<IgfxTray><C:\WINDOWS\System32\igfxtray.exe> [Intel Corporation]
<HotKeysCmds><C:\WINDOWS\System32\hkcmd.exe> [Intel Corporation]
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<AGRSMMSG><AGRSMMSG.exe> [Agere Systems]
<Apoint><C:\Program Files\Apoint2K\Apoint.exe> [Alps Electric Co., Ltd.]
<LManager><C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE> [Dritek System Inc.]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<openvpn-gui><C:\Program Files\OpenVPN\bin\openvpn-gui.exe> []
<IESAddr><RunDll32 "C:\WINDOWS\Downlo~1\Gladiator.dll",Boot> [Beijing Zhongsou Online Software]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [Microsoft Corporation]
<QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.]
<StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> []
<iTunesHelper><"D:\Program Files\iTunes\iTunesHelper.exe"> [Apple Computer, Inc.]
<MSConfig><C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto> [Microsoft Corporation]
<BIE><Rundll32 C:\WINDOWS\DOWNLO~1\BDPlugin.dll,Rundll32> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE> [Microsoft Corporation]
<Userinit><C:\WINDOWS\SYSTEM32\Userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}><C:\WINDOWS\System32\iifgggh.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqnljj]
<WinlogonNotify: ssqnljj><ssqnljj.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xxyvt]
<WinlogonNotify: xxyvt><C:\WINDOWS\System32\xxyvt.dll> []
==================================
启动文件夹
[Adobe Gamma Loader]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>
==================================
服务
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Canon Camera Access Library 8 / CCALib8]
<C:\Program Files\Canon\CAL\CALMAIN.exe><Canon Inc.>
[Location Awareness (NLA) / Device Access]
<C:\Program Files\Common Files\G_Server1.23.dll><N/A>
[ewido security suite control / ewido security suite control]
<C:\Program Files\ewido anti-malware\ewidoctrl.exe><N/A>
[ewido security suite guard / ewido security suite guard]
<C:\Program Files\ewido anti-malware\ewidoguard.exe><N/A>
[InstallDriver Table Manager / IDriverT]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[iPodService / iPodService]
<D:\Program Files\iPod\bin\iPodService.exe><Apple Computer, Inc.>
[Network Monitor / Network Monitor]
<C:\Program Files\Network Monitor\netmon.exe service><N/A>
[OpenVPN Service / OpenVPNService]
<C:\Program Files\OpenVPN\bin\openvpnserv.exe><N/A>
[Procedure Call (RPC) / Procedure Call (RPC)]
<C:\WINDOWS\Grver1.23.dll><N/A>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SoftEther Virtual LAN Card / SoftEther]
<"C:\Program Files\SoftEther\SoftEther.exe" service><SoftEther.com>
[StarWind iSCSI Service / StarWindService]
<d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe><Rocket Division Software>
[Network IPSEC Connections / WalALET]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
[Microsoft Windows Spool Service / Windows Spool Service]
<"C:\WINDOWS\wdfmgr.exe"><N/A>
==================================
浏览器加载项
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx, >
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[]
{FEE62CE5-89E2-4063-9220-8994D08476F0} <C:\WINDOWS\System32\xxyvt.dll, N/A>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\MSMSGS.EXE, Microsoft Corporation>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\System32\aliedit\AliEdit.dll, www.alipay.com>
[MUWebControl Class]
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\System32\muweb.dll, Microsoft Corporation>
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, >
[photo_uploader Control]
{A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <C:\WINDOWS\DOWNLO~1\PHOTO_~1.OCX, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[&使用迅雷下载]
<d:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
<d:\Program Files\Thunder Network\Thunder\getallurl.htm, N/A>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
<D:\Program Files\KuGoo3\KuGoo3DownX.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\qq\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 908][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 980][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1004][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.1557 (xpsp2_gdr.040517-1325)>
[C:\WINDOWS\System32\xxyvt.dll] <N/A><N/A>
[PID: 1052][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1064][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1224][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1300][C:\Program Files\Rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1320][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1508][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1596][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1668][C:\Program Files\Rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 33>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
[C:\Program Files\Rising\Rav\HOOKSYS.dll] <Beijing Rising Technology Co., Ltd.><18, 1, 0, 11>
[C:\Program Files\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[C:\Program Files\Rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\Rising\Rav\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\HookWeb.dll] <rising><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
psok - 2006-8-12 22:21:00
[C:\Program Files\Rising\Rav\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Rising\Rav\SpamEng.dll] <N/A><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[C:\Program Files\Rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\Rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 14>
[C:\Program Files\Rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\Rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[C:\Program Files\Rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[C:\Program Files\Rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\Program Files\Rising\Rav\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\ExtMail.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 160][C:\Program Files\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 300][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.1699 (xpsp2.050610-1533)>
[PID: 1248][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\WINDOWS\System32\xxyvt.dll] <N/A><N/A>
[C:\WINDOWS\Downlo~1\Gladiator.dll] <Beijing Zhongsou Online Software><2, 0, 0, 6>
[C:\WINDOWS\DOWNLO~1\BDPlugin.dll] <><1, 0, 0, 7>
[C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] <><1, 0, 0, 1>
[D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] <N/A><N/A>
[PID: 1424][C:\Program Files\SoftEther\SoftEther.exe] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftSSH.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftIF.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftTCP.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftRC4.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftSSL.dll] <SoftEther.com><1, 0, 0, 0>
[PID: 1648][d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe] <Rocket Division Software><2.6.1 Build 0x20050401>
[PID: 1944][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 380][C:\WINDOWS\System32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 292][C:\WINDOWS\System32\igfxtray.exe] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\hccutils.DLL] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxdev.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\DOWNLO~1\BDPlugin.dll] <><1, 0, 0, 7>
[C:\WINDOWS\System32\igfxsrvc.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxres.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxress.dll] <Intel Corporation><3,0,0,2104>
[PID: 332][C:\WINDOWS\System32\hkcmd.exe] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\hccutils.DLL] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxdev.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\DOWNLO~1\BDPlugin.dll] <><1, 0, 0, 7>
[C:\WINDOWS\System32\igfxsrvc.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxhk.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxres.dll] <Intel Corporation><3,0,0,2104>
[PID: 356][C:\WINDOWS\SOUNDMAN.EXE] <Realtek Semiconductor Corp.><5.1.02>
[PID: 388][C:\WINDOWS\AGRSMMSG.exe] <Agere Systems><2.1.28 2.1.28 03/31/2003 13:54:16>
[PID: 1176][C:\Program Files\Apoint2K\Apoint.exe] <Alps Electric Co., Ltd.><5.3.7.146>
[C:\WINDOWS\System32\VXDIF.DLL] <Alps Electric Co., Ltd.><6.0.1.62>
[C:\Program Files\Apoint2K\Apoint.DLL] <Alps Electric Co., Ltd.><5.3.203.162>
[C:\Program Files\Apoint2K\EzAuto.dll] <Alps Electric Co., Ltd.><4.5.1.83>
[C:\Program Files\Apoint2K\EzLaunch.DLL] <Alps Electric Co., Ltd.><4.5.0.47>
[PID: 540][C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE] <Dritek System Inc.><1,2,0,1>
[C:\PROGRA~1\LAUNCH~1\LgKCUtl.dll] <Dritek System Inc.><2, 0, 1, 1>
[C:\PROGRA~1\LAUNCH~1\SzUPFUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\OSDUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\RgnMaker.dll] <Dritek System Inc.><12.07.1999 ( VC60 )>
[C:\PROGRA~1\LAUNCH~1\CDRomUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\MixerUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\ComFnUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\Wnd2File.dll] <Dritek System Inc.><3.00>
[PID: 596][C:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 652][C:\Program Files\OpenVPN\bin\openvpn-gui.exe] <N/A><N/A>
[C:\Program Files\OpenVPN\bin\libeay32.dll] <N/A><N/A>
[PID: 660][C:\Program Files\Rising\Rav\Ravmon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 30>
[C:\Program Files\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\WINDOWS\DOWNLO~1\BDPlugin.dll] <><1, 0, 0, 7>
[PID: 868][C:\Program Files\Apoint2K\Apntex.exe] <Alps Electric Co., Ltd.><5.0.1.15>
[C:\WINDOWS\System32\VXDIF.DLL] <Alps Electric Co., Ltd.><6.0.1.62>
[PID: 616][C:\Program Files\QuickTime\qttask.exe] <Apple Computer, Inc.><6.5>
[PID: 1752][C:\WINDOWS\System32\conime.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1732][C:\Program Files\Canon\CAL\CALMAIN.exe] <Canon Inc.><8, 0, 0, 21>
[PID: 264][D:\Program Files\iTunes\iTunesHelper.exe] <Apple Computer, Inc.><6.0.2.23>
[D:\Program Files\iTunes\iTunesHelper.Resources\zh_CN.lproj\iTunesHelperLocalized.DLL] <Apple Computer, Inc.><6.0.2.11>
[D:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.DLL] <Apple Computer, Inc.><6.0.2.23>
[PID: 736][C:\WINDOWS\System32\Rundll32.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\DOWNLO~1\BDPlugin.dll] <><1, 0, 0, 7>
[C:\WINDOWS\DOWNLO~1\BDEx.dll] <><1, 0, 0, 2>
[PID: 784][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1564][D:\Program Files\iPod\bin\iPodService.exe] <Apple Computer, Inc.><6.0.2.23>
[D:\Program Files\iPod\bin\iPodService.Resources\zh_CN.lproj\iPodServiceLocalized.DLL] <Apple Computer, Inc.><6.0.2.11>
[D:\Program Files\iPod\bin\iPodService.Resources\iPodService.DLL] <Apple Computer, Inc.><6.0.2.23>
[PID: 2508][C:\WINDOWS\System32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[PID: 2576][C:\WINDOWS\System32\msiexec.exe] <Microsoft Corporation><3.1.4000.1823>
[PID: 3092][D:\BT\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\WINDOWS\DOWNLO~1\BDPlugin.dll] <><1, 0, 0, 7>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
SHANA - 2006-8-12 22:24:00
我无邪大哥不愧是.........................
我无邪 - 2006-8-12 22:47:00
关闭所有浏览窗口以及一些不必要的程序
运行(双击)System Repair Engineer,使用“系统修复,浏览器加载项”来删除以下选项。
C:\WINDOWS\System32\xxyvt.dll
运行(双击)System Repair Engineer,使用“启动项目,注册表”来删除以下选项。
C:\WINDOWS\System32\iifgggh.dll
ssqnljj.dll
C:\WINDOWS\System32\xxyvt.dll
运行(双击)System Repair Engineer,点“启动项目,服务,点“Win32服务应用程序”勾选“隐藏微软服务”选中病毒服务Microsoft Windows Spool Service,Network IPSEC Connections ,Procedure Call (RPC),Network Monitor,Location Awareness,选择“删除服务”点“设置”选择“否”最后重启。(每一个逗号隔开的就是一个病毒的服务,请逐一删除)
重启后删除
C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL
C:\WINDOWS\Grver1.23.dll
C:\WINDOWS\wdfmgr.exe
C:\Program Files\Network Monitor
C:\Program Files\Common Files\G_Server1.23.dll
C:\WINDOWS\System32\iifgggh.dll
ssqnljj.dll
C:\WINDOWS\System32\xxyvt.dll
请再扫份日志粘上来。
psok - 2006-8-15 22:19:00
好像又出现了很多 ,用先用hijack扫了一个 ,麻烦大侠帮我再看看
Logfile of HijackThis v1.99.1
Scan saved at 22:06:43, on 2006-8-16
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\SoftEther\SoftEther.exe
d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\winlogon.exe
C:\WINDOWS\wdfmgr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\System32\conime.exe
C:\Program Files\QuickTime\qttask.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\iPod\bin\iPodService.exe
c:\drsmartload.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\explorer.exe
D:\Program Files\HijackThis.exe
R3 - URLSearchHook: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\kakatool.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
O4 - HKLM\..\Run: [IESAddr] RunDll32 "C:\WINDOWS\Downlo~1\Gladiator.dll",Boot
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [caishowmanage] C:\Program Files\CaiShow Tech\CaiShow\UpdateManager.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &使用迅雷下载 - d:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\qq\SendMMS.htm
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/1007/aliedit.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1154719534300
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AXSafeControls.cab
O16 - DPF: {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} (photo_uploader Control) - http://upload.photo.163.com/photoup.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: SoftEther Virtual LAN Card (SoftEther) - Unknown owner - C:\Program Files\SoftEther\SoftEther.exe" service (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Windows Kernel Services - Unknown owner - C:\WINDOWS\winlogon.exe
O23 - Service: Microsoft Windows Spool Service (Windows Spool Service) - Unknown owner - C:\WINDOWS\wdfmgr.exe
我无邪 - 2006-8-15 22:31:00
开始→运行→输入services.msc,打开“服务”→查找 Windows Kernel Services,Microsoft Windows Spool Service→双击→启动类型→禁止→停止→应用→确定。禁止Windows Kernel Services,Microsoft Windows Spool Service这个服务
关闭所有浏览窗口以及一些不必要的程序
运行Hijackthis,扫描结束后在下列选项前打上勾,然后选"修复"
R3 - URLSearchHook: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll
重启后删除
C:\WINDOWS\winlogon.exe
C:\WINDOWS\wdfmgr.exe
C:\Program Files\Deskbar
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。
psok - 2006-8-15 23:57:00
C:\WINDOWS\winlogon.exe
C:\WINDOWS\wdfmgr.exe
没有找到,System Repair Engineer,使用“智能扫描“:(谢谢)
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<IgfxTray><C:\WINDOWS\System32\igfxtray.exe> [Intel Corporation]
<HotKeysCmds><C:\WINDOWS\System32\hkcmd.exe> [Intel Corporation]
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<AGRSMMSG><AGRSMMSG.exe> [Agere Systems]
<Apoint><C:\Program Files\Apoint2K\Apoint.exe> [Alps Electric Co., Ltd.]
<LManager><C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE> [Dritek System Inc.]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<openvpn-gui><C:\Program Files\OpenVPN\bin\openvpn-gui.exe> []
<IESAddr><RunDll32 "C:\WINDOWS\Downlo~1\Gladiator.dll",Boot> [Beijing Zhongsou Online Software]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [Microsoft Corporation]
<QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.]
<StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> []
<iTunesHelper><"D:\Program Files\iTunes\iTunesHelper.exe"> [Apple Computer, Inc.]
<MSConfig><C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE> [Microsoft Corporation]
<Userinit><C:\WINDOWS\SYSTEM32\Userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xxyvt]
<WinlogonNotify: xxyvt><C:\WINDOWS\System32\xxyvt.dll> []
==================================
启动文件夹
[Adobe Gamma Loader]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>
==================================
服务
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Canon Camera Access Library 8 / CCALib8]
<C:\Program Files\Canon\CAL\CALMAIN.exe><Canon Inc.>
[InstallDriver Table Manager / IDriverT]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[iPodService / iPodService]
<D:\Program Files\iPod\bin\iPodService.exe><Apple Computer, Inc.>
[OpenVPN Service / OpenVPNService]
<C:\Program Files\OpenVPN\bin\openvpnserv.exe><N/A>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SoftEther Virtual LAN Card / SoftEther]
<"C:\Program Files\SoftEther\SoftEther.exe" service><SoftEther.com>
[StarWind iSCSI Service / StarWindService]
<d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe><Rocket Division Software>
[Windows Kernel Services / Windows Kernel Services]
<"C:\WINDOWS\winlogon.exe"><N/A>
[Microsoft Windows Spool Service / Windows Spool Service]
<"C:\WINDOWS\wdfmgr.exe"><N/A>
==================================
浏览器加载项
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx, >
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[]
{CC4185F1-A5AA-4E60-95CD-A4E073701CDE} <C:\WINDOWS\System32\xxyvt.dll, N/A>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\MSMSGS.EXE, Microsoft Corporation>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\System32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\System32\aliedit\AliEdit.dll, www.alipay.com>
[MUWebControl Class]
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\System32\muweb.dll, Microsoft Corporation>
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, >
[photo_uploader Control]
{A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <C:\WINDOWS\DOWNLO~1\PHOTO_~1.OCX, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[&使用迅雷下载]
<d:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
<d:\Program Files\Thunder Network\Thunder\getallurl.htm, N/A>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
<D:\Program Files\KuGoo3\KuGoo3DownX.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\qq\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 908][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 980][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1004][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.1557 (xpsp2_gdr.040517-1325)>
[C:\WINDOWS\System32\xxyvt.dll] <N/A><N/A>
[PID: 1052][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1064][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1224][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1300][C:\Program Files\Rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1320][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1508][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1560][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1628][C:\Program Files\Rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 33>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
[C:\Program Files\Rising\Rav\HOOKSYS.dll] <Beijing Rising Technology Co., Ltd.><18, 1, 0, 11>
[C:\Program Files\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[C:\Program Files\Rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\Rising\Rav\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\HookWeb.dll] <rising><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[C:\Program Files\Rising\Rav\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
psok - 2006-8-15 23:58:00
[C:\Program Files\Rising\Rav\SpamEng.dll] <N/A><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[C:\Program Files\Rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\Rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 14>
[C:\Program Files\Rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\Rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[C:\Program Files\Rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[C:\Program Files\Rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\Program Files\Rising\Rav\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\ExtMail.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 2032][C:\Program Files\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 268][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.1699 (xpsp2.050610-1533)>
[PID: 804][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\WINDOWS\System32\xxyvt.dll] <N/A><N/A>
[C:\WINDOWS\Downlo~1\Gladiator.dll] <Beijing Zhongsou Online Software><2, 0, 0, 6>
[d:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] <><1, 0, 0, 1>
[D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] <N/A><N/A>
[PID: 1452][C:\Program Files\SoftEther\SoftEther.exe] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftSSH.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftIF.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftTCP.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftRC4.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftSSL.dll] <SoftEther.com><1, 0, 0, 0>
[PID: 1872][d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe] <Rocket Division Software><2.6.1 Build 0x20050401>
[PID: 1664][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 264][C:\WINDOWS\System32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 1100][C:\WINDOWS\wdfmgr.exe] <N/A><N/A>
[PID: 624][C:\Program Files\Canon\CAL\CALMAIN.exe] <Canon Inc.><8, 0, 0, 21>
[PID: 888][C:\WINDOWS\System32\igfxtray.exe] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\hccutils.DLL] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxdev.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxsrvc.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxres.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxress.dll] <Intel Corporation><3,0,0,2104>
[PID: 944][C:\WINDOWS\System32\hkcmd.exe] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\hccutils.DLL] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxdev.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxsrvc.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxhk.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxres.dll] <Intel Corporation><3,0,0,2104>
[PID: 968][C:\WINDOWS\SOUNDMAN.EXE] <Realtek Semiconductor Corp.><5.1.02>
[PID: 976][C:\WINDOWS\AGRSMMSG.exe] <Agere Systems><2.1.28 2.1.28 03/31/2003 13:54:16>
[PID: 1256][C:\Program Files\Apoint2K\Apoint.exe] <Alps Electric Co., Ltd.><5.3.7.146>
[C:\WINDOWS\System32\VXDIF.DLL] <Alps Electric Co., Ltd.><6.0.1.62>
[C:\Program Files\Apoint2K\Apoint.DLL] <Alps Electric Co., Ltd.><5.3.203.162>
[C:\Program Files\Apoint2K\EzAuto.dll] <Alps Electric Co., Ltd.><4.5.1.83>
[C:\Program Files\Apoint2K\EzLaunch.DLL] <Alps Electric Co., Ltd.><4.5.0.47>
[PID: 1480][C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE] <Dritek System Inc.><1,2,0,1>
[C:\PROGRA~1\LAUNCH~1\LgKCUtl.dll] <Dritek System Inc.><2, 0, 1, 1>
[C:\PROGRA~1\LAUNCH~1\SzUPFUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\OSDUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\RgnMaker.dll] <Dritek System Inc.><12.07.1999 ( VC60 )>
[C:\PROGRA~1\LAUNCH~1\CDRomUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\MixerUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\ComFnUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\Wnd2File.dll] <Dritek System Inc.><3.00>
[PID: 1524][C:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 2376][C:\Program Files\OpenVPN\bin\openvpn-gui.exe] <N/A><N/A>
[C:\Program Files\OpenVPN\bin\libeay32.dll] <N/A><N/A>
[PID: 2392][C:\Program Files\Apoint2K\Apntex.exe] <Alps Electric Co., Ltd.><5.0.1.15>
[C:\WINDOWS\System32\VXDIF.DLL] <Alps Electric Co., Ltd.><6.0.1.62>
[PID: 2472][C:\Program Files\Rising\Rav\Ravmon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 30>
[C:\Program Files\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 2492][C:\Program Files\QuickTime\qttask.exe] <Apple Computer, Inc.><6.5>
[PID: 2496][C:\WINDOWS\System32\conime.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 2648][D:\Program Files\iTunes\iTunesHelper.exe] <Apple Computer, Inc.><6.0.2.23>
[D:\Program Files\iTunes\iTunesHelper.Resources\zh_CN.lproj\iTunesHelperLocalized.DLL] <Apple Computer, Inc.><6.0.2.11>
[D:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.DLL] <Apple Computer, Inc.><6.0.2.23>
[PID: 2712][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 2796][D:\Program Files\iPod\bin\iPodService.exe] <Apple Computer, Inc.><6.0.2.23>
[D:\Program Files\iPod\bin\iPodService.Resources\zh_CN.lproj\iPodServiceLocalized.DLL] <Apple Computer, Inc.><6.0.2.11>
[D:\Program Files\iPod\bin\iPodService.Resources\iPodService.DLL] <Apple Computer, Inc.><6.0.2.23>
[PID: 3104][C:\WINDOWS\System32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[PID: 3452][D:\BT\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[PID: 3508][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\WINDOWS\Downlo~1\Gladiator.dll] <Beijing Zhongsou Online Software><2, 0, 0, 6>
[C:\WINDOWS\System32\kakatool.dll] <Beijing Rising Technology Co., Ltd.><2, 0, 0, 9>
[C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] <><1, 0, 0, 1>
[D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] <N/A><N/A>
[C:\WINDOWS\System32\xxyvt.dll] <N/A><N/A>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
yanmings - 2006-8-16 0:08:00
安全模式下,用sreng
删除启动项目=>注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IESAddr><RunDll32 "C:\WINDOWS\Downlo~1\Gladiator.dll",Boot> [Beijing Zhongsou Online Software]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xxyvt]
<WinlogonNotify: xxyvt><C:\WINDOWS\System32\xxyvt.dll> []
删除系统修复=>浏览器加载项
[]
{CC4185F1-A5AA-4E60-95CD-A4E073701CDE} <C:\WINDOWS\System32\xxyvt.dll, N/A>
开始-运行-输入regedit 打开注册表编辑器,分别定位到HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Services(X代表任意,比如1,2 ,3……)
查找Windows Kernel Services 和Microsoft Windows Spool Service / Windows Spool Service目录,查到的清删除整个目录
在安全模式下删除(如果文件删除不了 可以下载置顶工具的killbox)
C:\WINDOWS\System32\xxyvt.dll
C:\WINDOWS\Downlo~1\Gladiator.dll
C:\WINDOWS\winlogon.exe
C:\WINDOWS\wdfmgr.exe
william9991 - 2006-8-16 1:33:00
提示一下~:瑞星对trojandownloder家族木马下载器是若不见,应该考虑用其他软件交叉杀毒
有时候比扫描log更能绝处逢生
我无邪 - 2006-8-16 21:10:00
楼主修复后,建议重启再扫份日志粘上来。
psok - 2006-8-16 22:26:00
昨天晚上删除了一夜,以为终于搞定,今天一用 又出现了很多病毒,请大侠帮忙再看看,辛苦了.c:盘老是有一个文件abcd.exe, 又多了一个目录:!submit目录,里面有Gladiator.dll wdfgr.exe winlogon.exe xxyvt.dll文件, 进程里面又出现WINLOGON
hijack
Logfile of HijackThis v1.99.1
Scan saved at 22:06:00, on 2006-8-17
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\SoftEther\SoftEther.exe
d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\System32\conime.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\wuauclt.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\kakatool.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &使用迅雷下载 - d:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 使用KuGoo3下载(&K) - D:\Program Files\KuGoo3\KuGoo3DownX.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\qq\SendMMS.htm
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/1007/aliedit.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1154719534300
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AXSafeControls.cab
O16 - DPF: {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} (photo_uploader Control) - http://upload.photo.163.com/photoup.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: SoftEther Virtual LAN Card (SoftEther) - Unknown owner - C:\Program Files\SoftEther\SoftEther.exe" service (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Windows Kernel Services - Unknown owner - C:\WINDOWS\winlogon.exe (file missing)
psok - 2006-8-16 22:29:00
SREng2
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<IgfxTray><C:\WINDOWS\System32\igfxtray.exe> [Intel Corporation]
<HotKeysCmds><C:\WINDOWS\System32\hkcmd.exe> [Intel Corporation]
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<AGRSMMSG><AGRSMMSG.exe> [Agere Systems]
<Apoint><C:\Program Files\Apoint2K\Apoint.exe> [Alps Electric Co., Ltd.]
<LManager><C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE> [Dritek System Inc.]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<openvpn-gui><C:\Program Files\OpenVPN\bin\openvpn-gui.exe> []
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [Microsoft Corporation]
<QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.]
<StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> []
<iTunesHelper><"D:\Program Files\iTunes\iTunesHelper.exe"> [Apple Computer, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE> [Microsoft Corporation]
<Userinit><C:\WINDOWS\SYSTEM32\Userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
==================================
启动文件夹
[Adobe Gamma Loader]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>
==================================
服务
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Canon Camera Access Library 8 / CCALib8]
<C:\Program Files\Canon\CAL\CALMAIN.exe><Canon Inc.>
[InstallDriver Table Manager / IDriverT]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[iPodService / iPodService]
<D:\Program Files\iPod\bin\iPodService.exe><Apple Computer, Inc.>
[OpenVPN Service / OpenVPNService]
<C:\Program Files\OpenVPN\bin\openvpnserv.exe><N/A>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SoftEther Virtual LAN Card / SoftEther]
<"C:\Program Files\SoftEther\SoftEther.exe" service><SoftEther.com>
[StarWind iSCSI Service / StarWindService]
<d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe><Rocket Division Software>
[Windows Kernel Services / Windows Kernel Services]
<"C:\WINDOWS\winlogon.exe"><N/A>
==================================
浏览器加载项
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx, >
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\MSMSGS.EXE, Microsoft Corporation>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\System32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\System32\aliedit\AliEdit.dll, www.alipay.com>
[MUWebControl Class]
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\System32\muweb.dll, Microsoft Corporation>
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, >
[photo_uploader Control]
{A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <C:\WINDOWS\DOWNLO~1\PHOTO_~1.OCX, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[&使用迅雷下载]
<d:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
<d:\Program Files\Thunder Network\Thunder\getallurl.htm, N/A>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
<D:\Program Files\KuGoo3\KuGoo3DownX.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\qq\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 908][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 980][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1004][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.1557 (xpsp2_gdr.040517-1325)>
[PID: 1052][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1064][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1224][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1248][C:\Program Files\Rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1264][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1432][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1484][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1508][C:\Program Files\Rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 33>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
[C:\Program Files\Rising\Rav\HOOKSYS.dll] <Beijing Rising Technology Co., Ltd.><18, 1, 0, 11>
[C:\Program Files\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[C:\Program Files\Rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\Rising\Rav\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\HookWeb.dll] <rising><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[C:\Program Files\Rising\Rav\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Rising\Rav\SpamEng.dll] <N/A><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[C:\Program Files\Rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\Rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 14>
[C:\Program Files\Rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\Rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
psok - 2006-8-16 22:29:00
[C:\Program Files\Rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[C:\Program Files\Rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\Program Files\Rising\Rav\ExtMail.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\Program Files\Rising\Rav\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[PID: 1880][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.1699 (xpsp2.050610-1533)>
[PID: 2040][C:\Program Files\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 212][C:\Program Files\SoftEther\SoftEther.exe] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftSSH.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftIF.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftTCP.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftRC4.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftSSL.dll] <SoftEther.com><1, 0, 0, 0>
[PID: 380][d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe] <Rocket Division Software><2.6.1 Build 0x20050401>
[PID: 392][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 432][C:\WINDOWS\System32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 600][C:\Program Files\Canon\CAL\CALMAIN.exe] <Canon Inc.><8, 0, 0, 21>
[PID: 2920][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] <><1, 0, 0, 1>
[D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] <N/A><N/A>
[PID: 3036][C:\WINDOWS\System32\igfxtray.exe] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\hccutils.DLL] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxdev.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxsrvc.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxres.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxress.dll] <Intel Corporation><3,0,0,2104>
[PID: 1988][C:\WINDOWS\System32\hkcmd.exe] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\hccutils.DLL] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxdev.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxsrvc.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxhk.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxres.dll] <Intel Corporation><3,0,0,2104>
[PID: 888][C:\WINDOWS\SOUNDMAN.EXE] <Realtek Semiconductor Corp.><5.1.02>
[PID: 3056][C:\WINDOWS\AGRSMMSG.exe] <Agere Systems><2.1.28 2.1.28 03/31/2003 13:54:16>
[PID: 1784][C:\Program Files\Apoint2K\Apoint.exe] <Alps Electric Co., Ltd.><5.3.7.146>
[C:\WINDOWS\System32\VXDIF.DLL] <Alps Electric Co., Ltd.><6.0.1.62>
[C:\Program Files\Apoint2K\Apoint.DLL] <Alps Electric Co., Ltd.><5.3.203.162>
[C:\Program Files\Apoint2K\EzAuto.dll] <Alps Electric Co., Ltd.><4.5.1.83>
[C:\Program Files\Apoint2K\EzLaunch.DLL] <Alps Electric Co., Ltd.><4.5.0.47>
[PID: 3104][C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE] <Dritek System Inc.><1,2,0,1>
[C:\PROGRA~1\LAUNCH~1\LgKCUtl.dll] <Dritek System Inc.><2, 0, 1, 1>
[C:\PROGRA~1\LAUNCH~1\SzUPFUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\OSDUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\RgnMaker.dll] <Dritek System Inc.><12.07.1999 ( VC60 )>
[C:\PROGRA~1\LAUNCH~1\CDRomUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\MixerUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\ComFnUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\Wnd2File.dll] <Dritek System Inc.><3.00>
[PID: 3116][C:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 832][C:\Program Files\OpenVPN\bin\openvpn-gui.exe] <N/A><N/A>
[C:\Program Files\OpenVPN\bin\libeay32.dll] <N/A><N/A>
[PID: 3152][C:\Program Files\QuickTime\qttask.exe] <Apple Computer, Inc.><6.5>
[PID: 3180][D:\Program Files\iTunes\iTunesHelper.exe] <Apple Computer, Inc.><6.0.2.23>
[D:\Program Files\iTunes\iTunesHelper.Resources\zh_CN.lproj\iTunesHelperLocalized.DLL] <Apple Computer, Inc.><6.0.2.11>
[D:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.DLL] <Apple Computer, Inc.><6.0.2.23>
[PID: 3188][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 3240][C:\WINDOWS\System32\conime.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 3252][C:\Program Files\Rising\Rav\Ravmon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 32>
[C:\Program Files\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 3276][D:\Program Files\iPod\bin\iPodService.exe] <Apple Computer, Inc.><6.0.2.23>
[D:\Program Files\iPod\bin\iPodService.Resources\zh_CN.lproj\iPodServiceLocalized.DLL] <Apple Computer, Inc.><6.0.2.11>
[D:\Program Files\iPod\bin\iPodService.Resources\iPodService.DLL] <Apple Computer, Inc.><6.0.2.23>
[PID: 2408][C:\Program Files\Apoint2K\Apntex.exe] <Alps Electric Co., Ltd.><5.0.1.15>
[C:\WINDOWS\System32\VXDIF.DLL] <Alps Electric Co., Ltd.><6.0.1.62>
[PID: 336][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\WINDOWS\System32\kakatool.dll] <Beijing Rising Technology Co., Ltd.><2, 0, 0, 9>
[C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] <><1, 0, 0, 1>
[D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] <N/A><N/A>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\WINDOWS\System32\UNISPIM.IME] <北京清华紫光软件股份有限公司><3.0.0.0 alpha 21225>
[PID: 3864][D:\Program Files\Tencent\qq\QQ.exe] <TENCENT><14, 45, 0, 110>
[D:\Program Files\Tencent\qq\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\QQHelperDll.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\BasicCtrlDll.dll] <Tencent><0, 3, 3, 6>
[D:\Program Files\Tencent\qq\QQAPI.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\TIMProxy.dll] <tencent><0, 3, 2, 4>
[D:\Program Files\Tencent\qq\LoginCtrl.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\npkcntc.dll] <INCA Internet Co., Ltd.><2005, 9, 1, 1>
[D:\Program Files\Tencent\qq\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[D:\Program Files\Tencent\qq\QQOneClick.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\QQRes.dll] <tencent><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\QQMainFrame.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\CQQApplication.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\NewSkin.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\HostingMgr.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\MailSummary.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\QQSpace.dll] <><1, 0, 0, 1>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\QQSysMsgMng.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\QQConfigPlugin.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\LongConnection.dll] <tencent><0, 3, 3, 8>
[D:\Program Files\Tencent\qq\QQPlugin.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\ShareFiles.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\QQZip.dll] <tencent><0, 3, 2, 4>
[D:\Program Files\Tencent\qq\UserDefinedHead.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\QRingMng.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\PhoneAPI.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\DialerAllinOne.dll] <tencent><1, 4, 0, 0>
[D:\Program Files\Tencent\qq\QQAllInOne.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\CameraDll.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\SCCore.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\QQCustomFace.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\FlashAvatarDll.dll] <><1, 4, 0, 1>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[D:\Program Files\Tencent\qq\QQAvatar.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\QQSceneMng.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\QQPet.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\GroupConnection.dll] <Tencent><0, 3, 3, 5>
psok - 2006-8-16 22:30:00
[D:\Program Files\Tencent\qq\BQQApplication.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\CommercesMng.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[D:\Program Files\Tencent\qq\QQAddr.dll] <深圳市腾讯计算机系统有限公司><4, 0, 200, 32>
[D:\Program Files\Tencent\qq\QQPhoneHelper.dll] <腾讯科技(深圳)有限公司><2, 0, 6, 60>
[PID: 3892][D:\Program Files\Tencent\qq\TIMPlatform.exe] <tencent><0, 3, 1, 8>
[D:\Program Files\Tencent\qq\TIMProxy.dll] <tencent><0, 3, 2, 4>
[PID: 684][D:\Program Files\Tencent\qq\QQ.exe] <TENCENT><14, 45, 0, 110>
[D:\Program Files\Tencent\qq\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\QQHelperDll.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\BasicCtrlDll.dll] <Tencent><0, 3, 3, 6>
[D:\Program Files\Tencent\qq\QQAPI.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\TIMProxy.dll] <tencent><0, 3, 2, 4>
[D:\Program Files\Tencent\qq\LoginCtrl.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\npkcntc.dll] <INCA Internet Co., Ltd.><2005, 9, 1, 1>
[D:\Program Files\Tencent\qq\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[D:\Program Files\Tencent\qq\QQRes.dll] <tencent><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\QQMainFrame.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\CQQApplication.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\NewSkin.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\HostingMgr.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\MailSummary.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\QQSpace.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\QQAllInOne.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\CameraDll.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\SCCore.dll] <N/A><N/A>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\QQSysMsgMng.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\QQCustomFace.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\QQPet.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\LongConnection.dll] <tencent><0, 3, 3, 8>
[D:\Program Files\Tencent\qq\QQPlugin.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\ShareFiles.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\QQZip.dll] <tencent><0, 3, 2, 4>
[D:\Program Files\Tencent\qq\QQConfigPlugin.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\QRingMng.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\PhoneAPI.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\DialerAllinOne.dll] <tencent><1, 4, 0, 0>
[D:\Program Files\Tencent\qq\UserDefinedHead.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\QQAvatar.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\FlashAvatarDll.dll] <><1, 4, 0, 1>
[D:\Program Files\Tencent\qq\BQQApplication.dll] <N/A><N/A>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[D:\Program Files\Tencent\qq\QQMagicFace.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\QQSceneMng.dll] <N/A><N/A>
[D:\Program Files\Tencent\qq\CommercesMng.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\qq\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[D:\Program Files\Tencent\qq\QQAddr.dll] <深圳市腾讯计算机系统有限公司><4, 0, 200, 32>
[D:\Program Files\Tencent\qq\QQFileTransfer.dll] <Tencent><0, 3, 3, 5>
[D:\Program Files\Tencent\qq\GroupConnection.dll] <Tencent><0, 3, 3, 5>
[C:\WINDOWS\System32\UNISPIM.IME] <北京清华紫光软件股份有限公司><3.0.0.0 alpha 21225>
[C:\WINDOWS\System32\upengine.dll] <北京清华紫光软件股份有限公司><3.0.0.0 alpha 21225>
[PID: 3092][D:\BT\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
我无邪 - 2006-8-16 22:46:00
运行(双击)System Repair Engineer,点“启动项目,服务,点“Win32服务应用程序”勾选“隐藏微软服务”选中病毒服务Windows Kernel Services,选择“删除服务”点“设置”选择“否”最后重启
重启后删除
C:\WINDOWS\winlogon.exe不要搜索,手工查找。
psok - 2006-8-18 14:09:00
刚杀完,今天winlogon又出来,还有好多其他的毒,气死我了,大侠再帮我看看吧,我已经把winlogon给删了.
还受到漏洞攻击 Blaster Rpc Exploit MS-4011 exploit
Logfile of HijackThis v1.99.1
Scan saved at 14:00:17, on 2006-8-19
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\SoftEther\SoftEther.exe
d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\System32\conime.exe
C:\Program Files\QuickTime\qttask.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\ZTE MC315 无线网卡\ZTE MC315.exe
C:\Program Files\Rising\Rav\Rav.exe
D:\Program Files\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\kakatool.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &使用迅雷下载 - d:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 使用KuGoo3下载(&K) - D:\Program Files\KuGoo3\KuGoo3DownX.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\qq\SendMMS.htm
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/1007/aliedit.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1154719534300
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AXSafeControls.cab
O16 - DPF: {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} (photo_uploader Control) - http://upload.photo.163.com/photoup.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2C9F0424-C97E-4892-BE5C-0E54E7B596F0}: NameServer = 220.192.8.58 220.192.32.103
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: SoftEther Virtual LAN Card (SoftEther) - Unknown owner - C:\Program Files\SoftEther\SoftEther.exe" service (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
我无邪 - 2006-8-19 0:23:00
这日志没看出问题来
有异常
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。
psok - 2006-8-19 0:49:00
好的 ,谢谢 ,c:盘下老有个abcd.exe和pro3-install.exe,估计是病毒,删了又反复出现,我开机就报告在dos下 dreve.exe 被删除 然后发现病毒
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<IgfxTray><C:\WINDOWS\System32\igfxtray.exe> [Intel Corporation]
<HotKeysCmds><C:\WINDOWS\System32\hkcmd.exe> [Intel Corporation]
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<AGRSMMSG><AGRSMMSG.exe> [Agere Systems]
<Apoint><C:\Program Files\Apoint2K\Apoint.exe> [Alps Electric Co., Ltd.]
<LManager><C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE> [Dritek System Inc.]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<openvpn-gui><C:\Program Files\OpenVPN\bin\openvpn-gui.exe> []
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [Microsoft Corporation]
<iTunesHelper><"D:\Program Files\iTunes\iTunesHelper.exe"> [Apple Computer, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE> [Microsoft Corporation]
<Userinit><C:\WINDOWS\SYSTEM32\Userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
==================================
启动文件夹
[Adobe Gamma Loader]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>
==================================
服务
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Canon Camera Access Library 8 / CCALib8]
<C:\Program Files\Canon\CAL\CALMAIN.exe><Canon Inc.>
[InstallDriver Table Manager / IDriverT]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[iPodService / iPodService]
<D:\Program Files\iPod\bin\iPodService.exe><Apple Computer, Inc.>
[OpenVPN Service / OpenVPNService]
<C:\Program Files\OpenVPN\bin\openvpnserv.exe><N/A>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SoftEther Virtual LAN Card / SoftEther]
<"C:\Program Files\SoftEther\SoftEther.exe" service><SoftEther.com>
[StarWind iSCSI Service / StarWindService]
<d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe><Rocket Division Software>
[Microsoft Windows Spool Service / Windows Spool Service]
<"C:\WINDOWS\wdfmgr.exe"><N/A>
==================================
浏览器加载项
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx, >
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[AlxTB BHO Class]
{F1FABE79-25FC-46de-8C5A-2C6DB9D64333} <C:\WINDOWS\System32\AlxTB1.dll, Alexa Internet>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\MSMSGS.EXE, Microsoft Corporation>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\System32\aliedit\AliEdit.dll, www.alipay.com>
[MUWebControl Class]
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\System32\muweb.dll, Microsoft Corporation>
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, >
[photo_uploader Control]
{A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <C:\WINDOWS\DOWNLO~1\PHOTO_~1.OCX, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[&使用迅雷下载]
<d:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
<d:\Program Files\Thunder Network\Thunder\getallurl.htm, N/A>
[Mail to a Friend...]
<http://client.alexa.com/holiday/script/actions/mailto.htm, N/A>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
<D:\Program Files\KuGoo3\KuGoo3DownX.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\qq\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 908][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 980][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1004][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.1557 (xpsp2_gdr.040517-1325)>
[C:\WINDOWS\system32\igfxsrvc.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\hccutils.DLL] <Intel Corporation><3,0,0,2104>
[PID: 1052][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1064][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1224][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1248][C:\Program Files\Rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1264][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1468][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1496][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1508][C:\Program Files\Rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 33>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
[C:\Program Files\Rising\Rav\HOOKSYS.dll] <Beijing Rising Technology Co., Ltd.><18, 1, 0, 11>
[C:\Program Files\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[C:\Program Files\Rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
psok - 2006-8-19 0:49:00
[C:\Program Files\Rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\Rising\Rav\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\HookWeb.dll] <rising><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[C:\Program Files\Rising\Rav\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Rising\Rav\SpamEng.dll] <N/A><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[C:\Program Files\Rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\Rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 14>
[C:\Program Files\Rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\Rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[C:\Program Files\Rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[C:\Program Files\Rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\Program Files\Rising\Rav\RsStore.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Rising\Rav\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\ExtMail.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\Program Files\Rising\Rav\ScanNet.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1880][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.1699 (xpsp2.050610-1533)>
[PID: 2036][C:\Program Files\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 280][C:\Program Files\SoftEther\SoftEther.exe] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftSSH.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftIF.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftTCP.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftRC4.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftSSL.dll] <SoftEther.com><1, 0, 0, 0>
[PID: 572][d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe] <Rocket Division Software><2.6.1 Build 0x20050401>
[PID: 640][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 668][C:\WINDOWS\System32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 832][C:\Program Files\Canon\CAL\CALMAIN.exe] <Canon Inc.><8, 0, 0, 21>
[PID: 9268][C:\WINDOWS\wdfmgr.exe] <N/A><N/A>
[PID: 3288][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] <><1, 0, 0, 1>
[D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] <N/A><N/A>
[C:\WINDOWS\System32\AlxTB1.dll] <Alexa Internet><7, 0, 1, 57>
[PID: 3568][C:\WINDOWS\System32\igfxtray.exe] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\hccutils.DLL] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxdev.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxsrvc.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxres.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxress.dll] <Intel Corporation><3,0,0,2104>
[PID: 3608][C:\WINDOWS\System32\hkcmd.exe] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\hccutils.DLL] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxdev.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxsrvc.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxhk.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxres.dll] <Intel Corporation><3,0,0,2104>
[PID: 3620][C:\WINDOWS\SOUNDMAN.EXE] <Realtek Semiconductor Corp.><5.1.02>
[PID: 3616][C:\WINDOWS\AGRSMMSG.exe] <Agere Systems><2.1.28 2.1.28 03/31/2003 13:54:16>
[PID: 3644][C:\Program Files\Apoint2K\Apoint.exe] <Alps Electric Co., Ltd.><5.3.7.146>
[C:\WINDOWS\System32\VXDIF.DLL] <Alps Electric Co., Ltd.><6.0.1.62>
[C:\Program Files\Apoint2K\Apoint.DLL] <Alps Electric Co., Ltd.><5.3.203.162>
[C:\Program Files\Apoint2K\EzAuto.dll] <Alps Electric Co., Ltd.><4.5.1.83>
[C:\Program Files\Apoint2K\EzLaunch.DLL] <Alps Electric Co., Ltd.><4.5.0.47>
[PID: 2396][C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE] <Dritek System Inc.><1,2,0,1>
[C:\PROGRA~1\LAUNCH~1\LgKCUtl.dll] <Dritek System Inc.><2, 0, 1, 1>
[C:\PROGRA~1\LAUNCH~1\SzUPFUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\OSDUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\RgnMaker.dll] <Dritek System Inc.><12.07.1999 ( VC60 )>
[C:\PROGRA~1\LAUNCH~1\CDRomUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\MixerUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\ComFnUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\Wnd2File.dll] <Dritek System Inc.><3.00>
[PID: 3660][C:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 3840][C:\Program Files\OpenVPN\bin\openvpn-gui.exe] <N/A><N/A>
[C:\Program Files\OpenVPN\bin\libeay32.dll] <N/A><N/A>
[PID: 3656][D:\Program Files\iTunes\iTunesHelper.exe] <Apple Computer, Inc.><6.0.2.23>
[D:\Program Files\iTunes\iTunesHelper.Resources\zh_CN.lproj\iTunesHelperLocalized.DLL] <Apple Computer, Inc.><6.0.2.11>
[D:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.DLL] <Apple Computer, Inc.><6.0.2.23>
[PID: 3696][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1108][C:\Program Files\Apoint2K\Apntex.exe] <Alps Electric Co., Ltd.><5.0.1.15>
[C:\WINDOWS\System32\VXDIF.DLL] <Alps Electric Co., Ltd.><6.0.1.62>
[PID: 3680][C:\Program Files\Rising\Rav\Ravmon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 32>
[C:\Program Files\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 4000][C:\WINDOWS\System32\conime.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 8096][D:\Program Files\iPod\bin\iPodService.exe] <Apple Computer, Inc.><6.0.2.23>
[D:\Program Files\iPod\bin\iPodService.Resources\zh_CN.lproj\iPodServiceLocalized.DLL] <Apple Computer, Inc.><6.0.2.11>
[D:\Program Files\iPod\bin\iPodService.Resources\iPodService.DLL] <Apple Computer, Inc.><6.0.2.23>
[PID: 3600][D:\Program Files\HA_LeapFTP2.7.6.613_yfy\LeapFTP.exe] <汉化: 余飞雨><2.7.6.613>
[C:\WINDOWS\System32\UNISPIM.IME] <北京清华紫光软件股份有限公司><3.0.0.0 alpha 21225>
[C:\WINDOWS\System32\upengine.dll] <北京清华紫光软件股份有限公司><3.0.0.0 alpha 21225>
[PID: 4756][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] <><1, 0, 0, 1>
[D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] <N/A><N/A>
[C:\WINDOWS\System32\AlxTB1.dll] <Alexa Internet><7, 0, 1, 57>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[PID: 4724][D:\BT\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
我无邪 - 2006-8-19 0:55:00
运行(双击)System Repair Engineer,点“启动项目,服务,点“Win32服务应用程序”勾选“隐藏微软服务”选中病毒服务Microsoft Windows Spool Service,选择“删除服务”点“设置”选择“否”最后重启
重启后删除
C:\WINDOWS\wdfmgr.exe
再扫份日志粘上来。
psok - 2006-8-19 20:04:00
请大侠再看看,删去了
C:\WINDOWS\wdfmgr.exe还发现一个C:\WINDOWS\winlogon.exe也被我删除了
Windows XP Home Edition Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<IgfxTray><C:\WINDOWS\System32\igfxtray.exe> [Intel Corporation]
<HotKeysCmds><C:\WINDOWS\System32\hkcmd.exe> [Intel Corporation]
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<AGRSMMSG><AGRSMMSG.exe> [Agere Systems]
<Apoint><C:\Program Files\Apoint2K\Apoint.exe> [Alps Electric Co., Ltd.]
<LManager><C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE> [Dritek System Inc.]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<openvpn-gui><C:\Program Files\OpenVPN\bin\openvpn-gui.exe> []
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [Microsoft Corporation]
<iTunesHelper><"D:\Program Files\iTunes\iTunesHelper.exe"> [Apple Computer, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE> [Microsoft Corporation]
<Userinit><C:\WINDOWS\SYSTEM32\Userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
==================================
启动文件夹
[Adobe Gamma Loader]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>
==================================
服务
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Canon Camera Access Library 8 / CCALib8]
<C:\Program Files\Canon\CAL\CALMAIN.exe><Canon Inc.>
[InstallDriver Table Manager / IDriverT]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[iPodService / iPodService]
<D:\Program Files\iPod\bin\iPodService.exe><Apple Computer, Inc.>
[OpenVPN Service / OpenVPNService]
<C:\Program Files\OpenVPN\bin\openvpnserv.exe><N/A>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SoftEther Virtual LAN Card / SoftEther]
<"C:\Program Files\SoftEther\SoftEther.exe" service><SoftEther.com>
[StarWind iSCSI Service / StarWindService]
<d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe><Rocket Division Software>
==================================
浏览器加载项
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx, >
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[AlxTB BHO Class]
{F1FABE79-25FC-46de-8C5A-2C6DB9D64333} <C:\WINDOWS\System32\AlxTB1.dll, N/A>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\MSMSGS.EXE, Microsoft Corporation>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\System32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\System32\aliedit\AliEdit.dll, www.alipay.com>
[MUWebControl Class]
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\System32\muweb.dll, Microsoft Corporation>
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, >
[photo_uploader Control]
{A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <C:\WINDOWS\DOWNLO~1\PHOTO_~1.OCX, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[&使用迅雷下载]
<d:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
<d:\Program Files\Thunder Network\Thunder\getallurl.htm, N/A>
[使用KuGoo3下载(&K)]
<D:\Program Files\KuGoo3\KuGoo3DownX.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
==================================
正在运行的进程
[PID: 908][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 980][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1004][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.1557 (xpsp2_gdr.040517-1325)>
[PID: 1052][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1064][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1220][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1296][C:\Program Files\Rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1316][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1504][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1540][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1588][C:\Program Files\Rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 33>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
[C:\Program Files\Rising\Rav\HOOKSYS.dll] <Beijing Rising Technology Co., Ltd.><18, 1, 0, 11>
[C:\Program Files\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[C:\Program Files\Rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
psok - 2006-8-19 20:04:00
[C:\Program Files\Rising\Rav\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\HookWeb.dll] <rising><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[C:\Program Files\Rising\Rav\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Rising\Rav\SpamEng.dll] <N/A><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[C:\Program Files\Rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\Rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 14>
[C:\Program Files\Rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\Rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[C:\Program Files\Rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[C:\Program Files\Rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\Program Files\Rising\Rav\ExtMail.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 1984][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.1699 (xpsp2.050610-1533)>
[PID: 220][C:\Program Files\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 856][C:\Program Files\SoftEther\SoftEther.exe] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftSSH.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftIF.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftTCP.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftRC4.dll] <SoftEther.com><1, 0, 0, 0>
[C:\Program Files\SoftEther\SoftSSL.dll] <SoftEther.com><1, 0, 0, 0>
[PID: 1288][d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe] <Rocket Division Software><2.6.1 Build 0x20050401>
[PID: 1380][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1748][C:\Program Files\Canon\CAL\CALMAIN.exe] <Canon Inc.><8, 0, 0, 21>
[PID: 628][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[PID: 848][C:\WINDOWS\System32\igfxtray.exe] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\hccutils.DLL] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxdev.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxsrvc.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxres.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxress.dll] <Intel Corporation><3,0,0,2104>
[PID: 928][C:\WINDOWS\System32\hkcmd.exe] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\hccutils.DLL] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxdev.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxsrvc.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxhk.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\System32\igfxres.dll] <Intel Corporation><3,0,0,2104>
[PID: 1520][C:\WINDOWS\SOUNDMAN.EXE] <Realtek Semiconductor Corp.><5.1.02>
[PID: 1792][C:\WINDOWS\AGRSMMSG.exe] <Agere Systems><2.1.28 2.1.28 03/31/2003 13:54:16>
[PID: 1924][C:\Program Files\Apoint2K\Apoint.exe] <Alps Electric Co., Ltd.><5.3.7.146>
[C:\WINDOWS\System32\VXDIF.DLL] <Alps Electric Co., Ltd.><6.0.1.62>
[C:\Program Files\Apoint2K\Apoint.DLL] <Alps Electric Co., Ltd.><5.3.203.162>
[C:\Program Files\Apoint2K\EzAuto.dll] <Alps Electric Co., Ltd.><4.5.1.83>
[C:\Program Files\Apoint2K\EzLaunch.DLL] <Alps Electric Co., Ltd.><4.5.0.47>
[PID: 1104][C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE] <Dritek System Inc.><1,2,0,1>
[C:\PROGRA~1\LAUNCH~1\LgKCUtl.dll] <Dritek System Inc.><2, 0, 1, 1>
[C:\PROGRA~1\LAUNCH~1\SzUPFUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\OSDUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\RgnMaker.dll] <Dritek System Inc.><12.07.1999 ( VC60 )>
[C:\PROGRA~1\LAUNCH~1\CDRomUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\MixerUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\ComFnUtl.dll] <Dritek System Inc.><1.00>
[C:\PROGRA~1\LAUNCH~1\Wnd2File.dll] <Dritek System Inc.><3.00>
[PID: 1516][C:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 316][C:\Program Files\OpenVPN\bin\openvpn-gui.exe] <N/A><N/A>
[C:\Program Files\OpenVPN\bin\libeay32.dll] <N/A><N/A>
[PID: 348][C:\Program Files\Rising\Rav\Ravmon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 32>
[C:\Program Files\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 364][C:\Program Files\Apoint2K\Apntex.exe] <Alps Electric Co., Ltd.><5.0.1.15>
[C:\WINDOWS\System32\VXDIF.DLL] <Alps Electric Co., Ltd.><6.0.1.62>
[PID: 428][C:\WINDOWS\System32\conime.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 452][D:\Program Files\iTunes\iTunesHelper.exe] <Apple Computer, Inc.><6.0.2.23>
[D:\Program Files\iTunes\iTunesHelper.Resources\zh_CN.lproj\iTunesHelperLocalized.DLL] <Apple Computer, Inc.><6.0.2.11>
[D:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.DLL] <Apple Computer, Inc.><6.0.2.23>
[PID: 556][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1720][D:\Program Files\iPod\bin\iPodService.exe] <Apple Computer, Inc.><6.0.2.23>
[D:\Program Files\iPod\bin\iPodService.Resources\zh_CN.lproj\iPodServiceLocalized.DLL] <Apple Computer, Inc.><6.0.2.11>
[D:\Program Files\iPod\bin\iPodService.Resources\iPodService.DLL] <Apple Computer, Inc.><6.0.2.23>
[PID: 744][C:\WINDOWS\System32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[PID: 2676][D:\BT\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
我无邪 - 2006-8-19 21:22:00
没看出问题来,有异常你描述 一下。
1
© 2000 - 2026 Rising Corp. Ltd.