瑞星卡卡安全论坛
海潮探长 - 2006-8-27 14:32:00
Logfile of HijackThis v1.99.1
Scan saved at 14:35:16, on 2006-8-27
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\QCONSVC.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\Tencent\TT\TTraveler.exe
C:\Program Files\Tencent\QQ\TIMPlatfrom.exe
C:\Program Files\Rising\Rav\Rav.exe
C:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\Downloads\ha_hijackthis_1991\HijackThis.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,C:\WINDOWS\System32\updown11.exe
O2 - BHO: (no name) - {16B770A0-0E87-4278-B748-2460D64A8386} - (no file)
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] ; C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [EZEJMNAP] ; C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [ibmmessages] ; C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
O4 - HKLM\..\Run: [IBMPRC] ; C:\IBMTOOLS\UTILS\ibmprc.exe
O4 - HKLM\..\Run: [IMEKRMIG6.1] ; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] ; C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [DataLayer] ; C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
O4 - HKLM\..\Run: [Nokia Tray Application] ; C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] ; "C:\Program Files\D-Tools\daemon.exe" -lang 2052
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ibmmessages] ; C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [Windows Tagmsnger] ; tagmr.exe
O4 - HKCU\..\Run: [MSMSGS] ; "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: 使用影音传送带下载 - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://service.beisen.com.cn/ScriptX.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {7260569F-1D40-4E7F-B95B-2E68D35668B9} (MofileUploadX Control) - http://www.mofile.com/activex/UploadFX.CAB
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} (photo_uploader Control) - http://upload.photo.163.com/photoup.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{762F721C-CA85-41DE-AAF6-B5681E29EBA6}: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{762F721C-CA85-41DE-AAF6-B5681E29EBA6}: NameServer = 192.168.1.1
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINDOWS\System32\urlmon.dll
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\System32\msvidctl.dll
O18 - Protocol: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\System32\urlmon.dll
O18 - Protocol: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\System32\urlmon.dll
O18 - Protocol: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\System32\urlmon.dll
O18 - Protocol: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\System32\urlmon.dll
O18 - Protocol: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\System32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\System32\urlmon.dll
O18 - Protocol: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll
O18 - Protocol: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\System32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\System32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\System32\msdxm.ocx
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O21 - SSODL: DVDBurn - {790448C3-4239-45AF-C98B-367991A8B103} - C:\WINDOWS\Downloaded Program Files\AfxEdit.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - (no file)
O23 - Service: QCONSVC - Lenovo - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
目前srchasst.inf文件丢失,搜索助手被迫禁用。
IE在编辑——查找功能中,“查找下一项”为灰色。
还想请教如何杀死updown11.exe文件
我无邪 - 2006-8-27 14:42:00
关闭所有浏览窗口以及一些不必要的程序
运行Hijackthis,扫描结束后在下列选项前打上勾,然后选"修复
O21 - SSODL: DVDBurn - {790448C3-4239-45AF-C98B-367991A8B103} - C:\WINDOWS\Downloaded Program Files\AfxEdit.dll (file missing)
O4 - HKCU\..\Run: [Windows Tagmsnger] ; tagmr.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,C:\WINDOWS\System32\updown11.exe
你把updown11.exe发到我的邮箱里来吧twtxk@126.com
海潮探长 - 2006-8-27 14:50:00
【回复“我无邪”的帖子】
已发送,查收。
搜遍全网未找到有关updown11.exe的资讯
海潮探长 - 2006-8-27 14:54:00
最严重时候,系统还原之前所设的还原点全部被删除,无法上网,无法还原系统到较早时刻(否则就没有这么严重后果了)
恶意软件清理大师一开启即被关闭(非法操作)
进程管理器内出现cdnup,以及一些数字.exe的进程。
选择重新启动关机时,蓝屏,蓝屏内容闪过未能详细查看。
用超级兔子IE修复多次修理,修复winsock后重新启动,终于可以上网。但其他问题还在。
安全模式下也无法删除updown11.exe
我无邪 - 2006-8-27 14:55:00
好,一会我就去。
海潮探长 - 2006-8-27 14:59:00
【回复“我无邪”的帖子】
以下是SREng生成的log文件。
2006-08-27,15:03:08
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ibmmessages><; C:\Program Files\IBM\Messages By IBM\ibmmessages.exe> [IBM]
<MSMSGS><; ; "C:\Program Files\Messenger\msmsgs.exe" /background> []
<IBM RecordNow!><; ; > []
<MsnMsgr><; ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> [Synaptics, Inc.]
<TPKMAPHELPER><; C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper> [IBM Corp.]
<EZEJMNAP><; C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe> [IBM Corp.]
<ibmmessages><; C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe> [IBM]
<IBMPRC><; C:\IBMTOOLS\UTILS\ibmprc.exe> [IBM Corp.]
<IMEKRMIG6.1><; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE> [Microsoft Corporation]
<MSPY2002><; C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC> []
<DataLayer><; C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe> [Nokia Mobile Phone Ltd.]
<Nokia Tray Application><; C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe> [Nokia]
<DAEMON Tools-1033><; "C:\Program Files\D-Tools\daemon.exe" -lang 2052> [DAEMON'S HOME]
<QCWLICON><C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE> [Lenovo]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> []
<KnightIII><; ; > []
<TP4EX><; ; tp4ex.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<9><C:\WINDOWS\System32\Ravdm.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\System32\userinit.exe,C:\WINDOWS\System32\updown11.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
<WinlogonNotify: AtiExtEvent><Ati2evxx.dll> [ATI Technologies Inc.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\QConGina]
<WinlogonNotify: QConGina><QConGina.dll> [Lenovo]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tpfnf2]
<WinlogonNotify: tpfnf2><notifyf2.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tphotkey]
<WinlogonNotify: tphotkey><tphklock.dll> []
==================================
启动文件夹
服务
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\System32\Ati2evxx.exe><ATI Technologies Inc.>
[C-DillaCdaC11BA / C-DillaCdaC11BA]
<C:\WINDOWS\System32\drivers\CDAC11BA.EXE><N/A>
[windows dll service / dll service]
<><N/A>
[EvtEng / EvtEng]
<C:\Program Files\Intel\Wireless\Bin\EvtEng.exe><Intel Corporation>
[IBM Rapid Restore Ultra Service / IBM Rapid Restore Ultra Service]
<C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe><>
[IBM PM Service / IBMPMSVC]
<C:\WINDOWS\System32\ibmpmsvc.exe><N/A>
[IBM PSA Access Driver Control / PsaSrv]
<><N/A>
[QCONSVC / QCONSVC]
<System32\QCONSVC.EXE><Lenovo>
[RegSrvc / RegSrvc]
海潮探长 - 2006-8-27 15:00:00
【回复“海潮探长”的帖子】
[C:\Program Files\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\WINDOWS\System32\SynTPFcs.dll] <Synaptics, Inc.><7.5.17.8 19Nov03>
[PID: 1816][C:\Program Files\Tencent\TT\TTraveler.exe] <腾讯公司><2, 2, 0, 224>
[C:\WINDOWS\System32\SynTPFcs.dll] <Synaptics, Inc.><7.5.17.8 19Nov03>
[C:\WINDOWS\System32\AcSignIcon.dll] <Autodesk><16.0.0.86>
[C:\Program Files\Tencent\TT\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
[C:\Program Files\Tencent\QQ\QQHook.dll] <N/A><N/A>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] <Autodesk><16.0.0.86>
[PID: 3728][C:\Program Files\Tencent\QQ\QQ.exe] <TENCENT><12, 75, 0, 8045>
[C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\BasicCtrlDll.dll] <Tencent><0, 2, 2, 2>
[C:\Program Files\Tencent\QQ\QQZip.dll] <tencent><2.05>
[C:\Program Files\Tencent\QQ\ImagePro.dll] <Tencent><1.3.8.4>
[C:\Program Files\Tencent\QQ\InPlus.dll] <Tencent><1.3.8.4>
[C:\WINDOWS\System32\SynTPFcs.dll] <Synaptics, Inc.><7.5.17.8 19Nov03>
[C:\Program Files\Tencent\QQ\QQAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\TIMProxy.dll] <tencent><2.05>
[C:\Program Files\Tencent\QQ\HostingMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\LoginCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\LongConnection.dll] <tencent><0, 2, 2, 2>
[C:\Program Files\Tencent\QQ\QQConfigPlugin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\CameraDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQGroupMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\UserDefinedHead.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQCustomFace.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQAllInOne.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\SCCore.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\GroupConnection.dll] <Tencent><0, 3, 1, 14>
[C:\Program Files\Tencent\QQ\NewSkin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\Program Files\Tencent\QQ\BQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQMMSender.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QRingMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\videodevice.dll] <Tencent><1.3.8.4>
[C:\Program Files\Tencent\QQ\QQSceneMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQHook.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQGame\GameLogCore.Dll] <><0, 10, 106, 13>
[C:\Program Files\Tencent\QQGame\Core.dll] <é??úêDìú???????ú?μí3óD?T1???><0, 10, 0, 0>
[C:\Program Files\Tencent\QQGame\NetCenter.dll] <é??úêDìú???????ú?μí3óD?T1???><0, 10, 0, 0>
[C:\Program Files\Tencent\QQGame\CmdCenter.dll] <深圳市腾讯计算机系统有限公司><0, 10, 0, 0>
[C:\Program Files\Tencent\QQGame\HelpDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQGame\ResEx.dll] <深圳市腾讯计算机系统有限公司><0, 10, 0, 0>
[C:\Program Files\Tencent\QQGame\GameLogAidMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQGame\COMToolKit.dll] <><1, 0, 0, 3>
[C:\Program Files\Tencent\QQGame\QQGameAvatar.dll] <深圳市腾讯计算机系统有限公司 Tencent Computer System Ltd.><0, 10, 0, 0>
[C:\Program Files\Tencent\QQ\QQUdpGetFileLib.dll] <tencent><2.05>
[PID: 3780][C:\Program Files\Tencent\QQ\TIMPlatfrom.exe] <tencent><2.05>
[C:\WINDOWS\System32\SynTPFcs.dll] <Synaptics, Inc.><7.5.17.8 19Nov03>
[C:\Program Files\Tencent\QQ\TIMProxy.dll] <tencent><2.05>
[PID: 3860][C:\Program Files\Tencent\QQ\QQ.exe] <TENCENT><12, 75, 0, 8045>
[C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\BasicCtrlDll.dll] <Tencent><0, 2, 2, 2>
[C:\Program Files\Tencent\QQ\QQZip.dll] <tencent><2.05>
[C:\Program Files\Tencent\QQ\ImagePro.dll] <Tencent><1.3.8.4>
[C:\Program Files\Tencent\QQ\InPlus.dll] <Tencent><1.3.8.4>
[C:\WINDOWS\System32\SynTPFcs.dll] <Synaptics, Inc.><7.5.17.8 19Nov03>
[C:\Program Files\Tencent\QQ\QQAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\TIMProxy.dll] <tencent><2.05>
[C:\Program Files\Tencent\QQ\HostingMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\LoginCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQHook.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\LongConnection.dll] <tencent><0, 2, 2, 2>
[C:\Program Files\Tencent\QQ\QQConfigPlugin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\CameraDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQGroupMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\UserDefinedHead.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQCustomFace.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQAllInOne.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\SCCore.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\GroupConnection.dll] <Tencent><0, 3, 1, 14>
[C:\Program Files\Tencent\QQ\NewSkin.dll] <><1, 0, 0, 1>
海潮探长 - 2006-8-27 15:00:00
[C:\Program Files\Tencent\QQ\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\Program Files\Tencent\QQ\BQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQMMSender.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QRingMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\videodevice.dll] <Tencent><1.3.8.4>
[C:\Program Files\Tencent\QQ\QQSceneMng.dll] <N/A><N/A>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\ShareFiles.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQGame\GameLogCore.Dll] <><0, 10, 106, 13>
[C:\Program Files\Tencent\QQGame\Core.dll] <é??úêDìú???????ú?μí3óD?T1???><0, 10, 0, 0>
[C:\Program Files\Tencent\QQGame\NetCenter.dll] <é??úêDìú???????ú?μí3óD?T1???><0, 10, 0, 0>
[C:\Program Files\Tencent\QQGame\CmdCenter.dll] <深圳市腾讯计算机系统有限公司><0, 10, 0, 0>
[C:\Program Files\Tencent\QQGame\HelpDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQGame\ResEx.dll] <深圳市腾讯计算机系统有限公司><0, 10, 0, 0>
[C:\Program Files\Tencent\QQGame\GameLogAidMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQGame\COMToolKit.dll] <><1, 0, 0, 3>
[C:\Program Files\Tencent\QQGame\QQGameAvatar.dll] <深圳市腾讯计算机系统有限公司 Tencent Computer System Ltd.><0, 10, 0, 0>
[C:\Program Files\Tencent\QQ\ImageOle.dll] <TODO: <Company name>><1.0.0.1>
[PID: 3884][C:\Program Files\Tencent\QQ\QQ.exe] <TENCENT><12, 75, 0, 8045>
[C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\BasicCtrlDll.dll] <Tencent><0, 2, 2, 2>
[C:\Program Files\Tencent\QQ\QQZip.dll] <tencent><2.05>
[C:\Program Files\Tencent\QQ\ImagePro.dll] <Tencent><1.3.8.4>
[C:\Program Files\Tencent\QQ\InPlus.dll] <Tencent><1.3.8.4>
[C:\WINDOWS\System32\SynTPFcs.dll] <Synaptics, Inc.><7.5.17.8 19Nov03>
[C:\Program Files\Tencent\QQ\QQAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\TIMProxy.dll] <tencent><2.05>
[C:\Program Files\Tencent\QQ\HostingMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\LoginCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\LongConnection.dll] <tencent><0, 2, 2, 2>
[C:\Program Files\Tencent\QQ\QQConfigPlugin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\CameraDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQGroupMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\UserDefinedHead.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQCustomFace.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQAllInOne.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\SCCore.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\GroupConnection.dll] <Tencent><0, 3, 1, 14>
[C:\Program Files\Tencent\QQ\NewSkin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\Program Files\Tencent\QQ\BQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQMMSender.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QRingMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\videodevice.dll] <Tencent><1.3.8.4>
[C:\Program Files\Tencent\QQ\QQSceneMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQHook.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQGame\GameLogCore.Dll] <><0, 10, 106, 13>
[C:\Program Files\Tencent\QQGame\Core.dll] <é??úêDìú???????ú?μí3óD?T1???><0, 10, 0, 0>
[C:\Program Files\Tencent\QQGame\NetCenter.dll] <é??úêDìú???????ú?μí3óD?T1???><0, 10, 0, 0>
[C:\Program Files\Tencent\QQGame\CmdCenter.dll] <深圳市腾讯计算机系统有限公司><0, 10, 0, 0>
[C:\Program Files\Tencent\QQGame\HelpDll.dll] <><1, 0, 0, 1>
海潮探长 - 2006-8-27 15:00:00
[C:\Program Files\Tencent\QQGame\ResEx.dll] <深圳市腾讯计算机系统有限公司><0, 10, 0, 0>
[C:\Program Files\Tencent\QQGame\GameLogAidMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQGame\COMToolKit.dll] <><1, 0, 0, 3>
[C:\Program Files\Tencent\QQGame\QQGameAvatar.dll] <深圳市腾讯计算机系统有限公司 Tencent Computer System Ltd.><0, 10, 0, 0>
[PID: 2264][C:\Program Files\Rising\Rav\Rav.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 75>
[C:\Program Files\Rising\Rav\PlugIn\RsPgScan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 17>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RavUI.Dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 61>
[C:\Program Files\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[C:\Program Files\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\WINDOWS\System32\SynTPFcs.dll] <Synaptics, Inc.><7.5.17.8 19Nov03>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\WINDOWS\System32\AcSignIcon.dll] <Autodesk><16.0.0.86>
[C:\Program Files\Rising\Rav\RavUIMsg.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 25>
[C:\Program Files\Tencent\QQ\QQHook.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\Rising\Rav\MVEngine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 14>
[C:\Program Files\Rising\Rav\Engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[C:\Program Files\Rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\Program Files\Rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 14>
[C:\Program Files\Rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
[C:\Program Files\Rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\Rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[C:\Program Files\Rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[C:\Program Files\Rising\Rav\ExtMail.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\Program Files\Rising\Rav\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\ExtFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[C:\Program Files\Rising\Rav\ScanNet.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 2820][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\WINDOWS\System32\SynTPFcs.dll] <Synaptics, Inc.><7.5.17.8 19Nov03>
[C:\WINDOWS\System32\AcSignIcon.dll] <Autodesk><16.0.0.86>
[C:\Program Files\Tencent\QQ\QQHook.dll] <N/A><N/A>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[PID: 1664][F:\Downloads\ha_hijackthis_1991\HijackThis.exe] <Soeperman Enterprises Ltd.><1.99.0001>
[C:\WINDOWS\System32\SynTPFcs.dll] <Synaptics, Inc.><7.5.17.8 19Nov03>
[C:\Program Files\Tencent\QQ\QQHook.dll] <N/A><N/A>
[C:\WINDOWS\System32\AcSignIcon.dll] <Autodesk><16.0.0.86>
[C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] <Autodesk><16.0.0.86>
[PID: 1468][C:\Program Files\Xi\NetTransport 2\NetTransport.exe] <Xi><1.92.273>
[C:\WINDOWS\System32\SynTPFcs.dll] <Synaptics, Inc.><7.5.17.8 19Nov03>
[C:\WINDOWS\System32\AcSignIcon.dll] <Autodesk><16.0.0.86>
[C:\Program Files\Xi\NetTransport 2\libssl.dll] <Xi><0.97d.17>
[C:\Program Files\Xi\NetTransport 2\libssh.dll] <Xi><3.1.009>
[C:\Program Files\Tencent\QQ\QQHook.dll] <N/A><N/A>
[PID: 2572][C:\Program Files\WinRAR\WinRAR.exe] <N/A><N/A>
[C:\WINDOWS\System32\SynTPFcs.dll] <Synaptics, Inc.><7.5.17.8 19Nov03>
[C:\WINDOWS\System32\AcSignIcon.dll] <Autodesk><16.0.0.86>
[C:\Program Files\Nokia\Nokia PC Suite 5\NokiaPhoneBrowser.dll] <Nokia><5, 0, 0, 39>
[C:\Program Files\Tencent\QQ\QQHook.dll] <N/A><N/A>
[PID: 2784][C:\DOCUME~1\LRF\LOCALS~1\Temp\Rar$EX00.058\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\WINDOWS\System32\SynTPFcs.dll] <Synaptics, Inc.><7.5.17.8 19Nov03>
[C:\Program Files\Tencent\QQ\QQHook.dll] <N/A><N/A>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
海潮探长 - 2006-8-27 15:05:00
最新发现,
瑞星扫毒,内存Services.exe进程发现两个Trojan.PSW.QQGame.v
我无邪 - 2006-8-27 15:19:00
运行(双击)System Repair Engineer,点“启动项目,服务,点“Win32服务应用程序”勾选“隐藏微软服务”选中病毒服务windows dll service ,选择“删除服务”点“设置”选择“否”
关于C:\WINDOWS\System32\updown11.exe的方法
你看以下的帖子
http://forum.ikaka.com/topic.asp?board=28&artid=8139884
有一点点区别,你要终止的只是updown11.exe,思路是一样的。
我无邪 - 2006-8-27 15:20:00
对了,修复后重启,再扫份日志粘上来。
海潮探长 - 2006-8-27 15:24:00
修复不了,
修复完以后再扫描,那一项还是没变化。连SREng也修复不了,把勾去掉,过一会再去看,它自己又加回来了。
我无邪 - 2006-8-27 15:26:00
http://forum.ikaka.com/topic.asp?board=28&artid=8139884
这个帖子你看了没有,我刚刚亲自做了测试,完美解决问题。
关键是,要终止updown11.exe的进程
好好看帖子的说明。
海潮探长 - 2006-8-27 15:26:00
在SREng里,呈红色,点选编辑,改动键值,去掉逗号以后所有内容。
换栏,然后再切换回来时,全部又变回原来的样子了。
直接用regedit修改该值也是一样,修改后关闭,再打开,自己又加回去了。
海潮探长 - 2006-8-27 15:30:00
原来这东西是mouser.exe的同类啊……
删了
但是不知道会有什么后遗症,IE也还没有恢复正常啊
我无邪 - 2006-8-27 15:36:00
还有什么异常?
你重启后,再扫描一份日志粘上来。
海潮探长 - 2006-8-27 15:45:00
目前搜索助手好象是坏了,schrasst.inf也丢失了,不知道该怎么修复。
还有就是IE编辑——查找里,“查找下一项”的按钮为灰色。
暂时还没发现别的问题
Logfile of HijackThis v1.99.1
Scan saved at 15:49:19, on 2006-8-27
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\QCONSVC.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\Tencent\TT\TTraveler.exe
F:\Downloads\ha_hijackthis_1991\HijackThis.exe
O2 - BHO: (no name) - {16B770A0-0E87-4278-B748-2460D64A8386} - (no file)
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] ; C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [EZEJMNAP] ; C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [ibmmessages] ; C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
O4 - HKLM\..\Run: [IBMPRC] ; C:\IBMTOOLS\UTILS\ibmprc.exe
O4 - HKLM\..\Run: [IMEKRMIG6.1] ; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] ; C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [DataLayer] ; C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
O4 - HKLM\..\Run: [Nokia Tray Application] ; C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] ; "C:\Program Files\D-Tools\daemon.exe" -lang 2052
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [KnightIII] ; ;
O4 - HKLM\..\Run: [TP4EX] ; ; tp4ex.exe
O4 - HKCU\..\Run: [ibmmessages] ; C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [MSMSGS] ; ; "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IBM RecordNow!] ; ;
O4 - HKCU\..\Run: [MsnMsgr] ; ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: 使用影音传送带下载 - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://service.beisen.com.cn/ScriptX.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {7260569F-1D40-4E7F-B95B-2E68D35668B9} (MofileUploadX Control) - http://www.mofile.com/activex/UploadFX.CAB
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} (photo_uploader Control) - http://upload.photo.163.com/photoup.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{762F721C-CA85-41DE-AAF6-B5681E29EBA6}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{762F721C-CA85-41DE-AAF6-B5681E29EBA6}: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{762F721C-CA85-41DE-AAF6-B5681E29EBA6}: NameServer = 192.168.1.1
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - (no file)
O23 - Service: QCONSVC - Lenovo - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
我无邪 - 2006-8-27 15:47:00
这日志看不出问题来
如果没有异常,就这么着吧。
海潮探长 - 2006-8-27 15:55:00
好吧,多谢
修复IE我另外再想办法
1
© 2000 - 2026 Rising Corp. Ltd.