瑞星卡卡安全论坛
西门吹胡子 - 2006-9-11 22:15:00
西门吹胡子 - 2006-9-11 22:18:00
[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[winlogon.exe]
CommandLine = winlogon.exe
[services.exe]
CommandLine = C:\WINDOWS\system32\services.exe
[lsass.exe]
CommandLine = C:\WINDOWS\system32\lsass.exe
[ibmpmsvc.exe]
CommandLine = C:\WINDOWS\System32\ibmpmsvc.exe
[ati2evxx.exe]
CommandLine = C:\WINDOWS\System32\Ati2evxx.exe
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss
[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs
[S24EvMon.exe]
CommandLine = C:\WINDOWS\System32\S24EvMon.exe
[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k NetworkService
[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k LocalService
[explorer.exe]
CommandLine = C:\WINDOWS\Explorer.EXE
[ccSetMgr.exe]
CommandLine = "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
[ccEvtMgr.exe]
CommandLine = "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe
[tp4serv.exe]
CommandLine = "C:\WINDOWS\system32\tp4serv.exe"
[TPHKMGR.exe]
CommandLine = "C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe"
[EzEjMnAp.Exe]
CommandLine = "C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe"
[AGRSMMSG.exe]
CommandLine = "C:\WINDOWS\AGRSMMSG.exe"
[rundll32.exe]
CommandLine = "C:\WINDOWS\system32\RunDll32.exe" C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
[VPTray.exe]
CommandLine = "C:\PROGRA~1\SYMANT~1\VPTray.exe"
[TPONSCR.exe]
CommandLine = "C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe"
[TpScrex.exe]
CommandLine = "C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe"
[iparmor.exe]
CommandLine = "C:\Temp\iparmor\iparmor.exe" mini
[ctfmon.exe]
CommandLine = "C:\WINDOWS\system32\ctfmon.exe"
[JJSvr4.exe]
CommandLine = "C:\Program Files\jj4\jjsvr4.exe"
[cisvc.exe]
CommandLine = C:\WINDOWS\system32\cisvc.exe
[cvpnd.exe]
CommandLine = "C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe"
[DefWatch.exe]
CommandLine = "C:\Program Files\Symantec AntiVirus\DefWatch.exe"
[ntmulti.exe]
CommandLine = "C:\Program Files\lotus\notes\ntmulti.exe"
[QCONSVC.EXE]
CommandLine = System32\QCONSVC.EXE
[RegSrvc.exe]
CommandLine = C:\WINDOWS\System32\RegSrvc.exe
西门吹胡子 - 2006-9-11 22:19:00
Logfile of Kaka v2. 0. 0. 9 Scan Module v2. 0. 0. 1
Scan saved at 22:06:54, on 2006-09-11
Platform: Microsoft Windows XP Professional Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP2; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
Running processes:
[smss.exe]
CommandLine =
[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k imgsvc
[Rtvscan.exe]
CommandLine = "C:\Program Files\Symantec AntiVirus\Rtvscan.exe"
[TpKmpSvc.exe]
CommandLine = C:\WINDOWS\system32\TpKmpSVC.exe
[wdfmgr.exe]
CommandLine = C:\WINDOWS\system32\wdfmgr.exe
[alg.exe]
CommandLine = C:\WINDOWS\System32\alg.exe
[vpngui.exe]
CommandLine = "C:\Program Files\Cisco Systems\VPN Client\vpngui.exe"
[nlnotes.exe]
CommandLine = NLNOTES.EXE
[ntaskldr.exe]
CommandLine = "C:\Program Files\lotus\notes\ntaskldr.EXE" C:\Program Files\lotus\notes\ntaskldr.EXE
[XDICT.EXE]
CommandLine = "C:\Program Files\Kingsoft\PowerWord 2005\XDICT.EXE"
[tsrv.exe]
CommandLine = C:\WINDOWS\tsrv.exe s
[iexplore.exe]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe" -nohome
[slbrwiad.exe]
CommandLine = C:\WINDOWS\system32\slbrwiad.exe C:\WINDOWS\system32\wuapx9tt.dll
[wuapx9tt.exe]
CommandLine = C:\WINDOWS\system32\wuapx9tt.exe
[iexplore.exe]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe"
[KkScan.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KkScan.exe"
[iexplore.exe]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe"
[cidaemon.exe]
CommandLine = "cidaemon.exe" DownLevelDaemon "c:\system volume information\catalog.wci" 196672l 1180l
西门吹胡子 - 2006-9-11 22:19:00
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\System32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm
R3 - URLSearchHook: (no name) - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - (no file)
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 download.microsoft.com
O1 - Hosts: 127.0.0.1 go.microsoft.com
O1 - Hosts: 127.0.0.1 msdn.microsoft.com
O1 - Hosts: 127.0.0.1 office.microsoft.com
O1 - Hosts: 127.0.0.1 windowsupdate.microsoft.com
O1 - Hosts: 127.0.0.1 http://www.microsoft.com/downloads/Search.aspx?displaylang=en
O1 - Hosts: 127.0.0.1 avp.ru
O1 - Hosts: 127.0.0.1 www.avp.ru
O1 - Hosts: 127.0.0.1 http://avp.ru
O1 - Hosts: 127.0.0.1 http://www.avp.ru
O1 - Hosts: 127.0.0.1 kaspersky.ru
O1 - Hosts: 127.0.0.1 www.kaspersky.ru
O1 - Hosts: 127.0.0.1 http://kaspersky.ru
O1 - Hosts: 127.0.0.1 kaspersky.com
O1 - Hosts: 127.0.0.1 www.kaspersky.com
O1 - Hosts: 127.0.0.1 http://kaspersky.com
O1 - Hosts: 127.0.0.1 kaspersky-labs.com
O1 - Hosts: 127.0.0.1 www.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 http://kaspersky-labs.com
O1 - Hosts: 127.0.0.1 avp.ru/download/
O1 - Hosts: 127.0.0.1 www.avp.ru/download/
O1 - Hosts: 127.0.0.1 http://www.avp.ru/download/
O1 - Hosts: 127.0.0.1 http://www.kaspersky.ru/updates/
O1 - Hosts: 127.0.0.1 http://www.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 http://kaspersky.ru/updates/
O1 - Hosts: 127.0.0.1 http://kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 downloads1.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 downloads2.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 downloads3.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 downloads4.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 downloads5.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 http://downloads1.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 http://downloads2.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 http://downloads3.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 http://downloads4.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 http://downloads5.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 downloads1.kaspersky-labs.com/products/
O1 - Hosts: 127.0.0.1 downloads2.kaspersky-labs.com/products/
O1 - Hosts: 127.0.0.1 downloads3.kaspersky-labs.com/products/
O1 - Hosts: 127.0.0.1 downloads4.kaspersky-labs.com/products/
O1 - Hosts: 127.0.0.1 downloads5.kaspersky-labs.com/products/
O1 - Hosts: 127.0.0.1 http://downloads1.kaspersky-labs.com/products/
O1 - Hosts: 127.0.0.1 http://downloads2.kaspersky-labs.com/products/
O1 - Hosts: 127.0.0.1 http://downloads3.kaspersky-labs.com/products/
O1 - Hosts: 127.0.0.1 http://downloads4.kaspersky-labs.com/products/
O1 - Hosts: 127.0.0.1 http://downloads5.kaspersky-labs.com/products/
O1 - Hosts: 127.0.0.1 downloads1.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 downloads2.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 downloads3.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 downloads4.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 downloads5.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 http://downloads1.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 http://downloads2.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 http://downloads3.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 http://downloads4.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 http://downloads5.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 ftp://downloads1.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 ftp://downloads2.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 ftp://downloads3.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 ftp://downloads4.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 ftp://downloads5.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 ftp://downloads1.kaspersky-labs.com/products/
O1 - Hosts: 127.0.0.1 ftp://downloads2.kaspersky-labs.com/products/
O1 - Hosts: 127.0.0.1 ftp://downloads3.kaspersky-labs.com/products/
O1 - Hosts: 127.0.0.1 ftp://downloads4.kaspersky-labs.com/products/
O1 - Hosts: 127.0.0.1 ftp://downloads5.kaspersky-labs.com/products/
O1 - Hosts: 127.0.0.1 ftp://downloads1.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 ftp://downloads2.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 ftp://downloads3.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 ftp://downloads4.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 ftp://downloads5.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 http://updates.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 http://updates1.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 http://updates2.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 http://updates3.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 http://updates4.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 ftp://updates.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 ftp://updates1.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 ftp://updates2.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 ftp://updates3.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 ftp://updates4.kaspersky-labs.com/updates/
O1 - Hosts: 127.0.0.1 viruslist.com
O1 - Hosts: 127.0.0.1 www.viruslist.com
O1 - Hosts: 127.0.0.1 http://viruslist.com
O1 - Hosts: 127.0.0.1 viruslist.ru
O1 - Hosts: 127.0.0.1 www.viruslist.ru
O1 - Hosts: 127.0.0.1 http://viruslist.ru
O1 - Hosts: 127.0.0.1 ftp://ftp.kasperskylab.ru/updates/
O1 - Hosts: 127.0.0.1 symantec.com
O1 - Hosts: 127.0.0.1 www.symantec.com
O1 - Hosts: 127.0.0.1 http://symantec.com
O1 - Hosts: 127.0.0.1 customer.symantec.com
O1 - Hosts: 127.0.0.1 http://customer.symantec.com
O1 - Hosts: 127.0.0.1 liveupdate.symantec.com
O1 - Hosts: 127.0.0.1 http://liveupdate.symantec.com
O1 - Hosts: 127.0.0.1 liveupdate.symantecliveupdate.com
O1 - Hosts: 127.0.0.1 http://liveupdate.symantecliveupdate.com
O1 - Hosts: 127.0.0.1 securityresponse.symantec.com
O1 - Hosts: 127.0.0.1 http://securityresponse.symantec.com
O1 - Hosts: 127.0.0.1 service1.symantec.com
O1 - Hosts: 127.0.0.1 http://service1.symantec.com
O1 - Hosts: 127.0.0.1 symantec.com/updates
O1 - Hosts: 127.0.0.1 http://symantec.com/updates
O1 - Hosts: 127.0.0.1 updates.symantec.com
O1 - Hosts: 127.0.0.1 http://updates.symantec.com
O1 - Hosts: 127.0.0.1 eset.com/
O1 - Hosts: 127.0.0.1 www.eset.com/
O1 - Hosts: 127.0.0.1 http://www.eset.com/
O1 - Hosts: 127.0.0.1 eset.com/products/index.php
O1 - Hosts: 127.0.0.1 www.eset.com/products/index.php
O1 - Hosts: 127.0.0.1 http://www.eset.com/products/index.php
O1 - Hosts: 127.0.0.1 eset.com/download/index.php
O1 - Hosts: 127.0.0.1 www.eset.com/download/index.php
O1 - Hosts: 127.0.0.1 http://www.eset.com/download/index.php
O1 - Hosts: 127.0.0.1 eset.com/joomla/
O1 - Hosts: 127.0.0.1 www.eset.com/joomla/
O1 - Hosts: 127.0.0.1 http://www.eset.com/joomla/
O1 - Hosts: 127.0.0.1 u3.eset.com/
O1 - Hosts: 127.0.0.1 http://u3.eset.com/
O1 - Hosts: 127.0.0.1 u4.eset.com/
O1 - Hosts: 127.0.0.1 http://u4.eset.com/
O1 - Hosts: 127.0.0.1 www.symantec.com/updates
西门吹胡子 - 2006-9-11 22:19:00
O2 - BHO: 卡卡上网安全助手 - {AFF6E516-CBE5-4F8A-9C2F-38A68013E766} - C:\WINDOWS\system32\kakatool.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [pyjj] C:\Program Files\jj4\jjsvr4.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [iparmor] C:\Temp\iparmor\iparmor.exe mini
O4 - Startup: desktop.ini =
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: desktop.ini =
O9 - Extra Button: (no name) - {D6E814A0-E0C5-11d4-8D29-0050BA6940E4}? - C:\WINDOWS\system32\shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O15 - Trusted Zone:
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://61.222.107.211/iNotes6W.cab
O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} - http://zs.kingsoft.com/KOSInit.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124347276515
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = westwd.com,westwd.com,westwd.com,westwd.com,kspcb.nanyapcb.com.tw,fpg.com.tw
O17 - HKLM\System\CCS\Services\Tcpip\..\{873CCEC2-E7C3-4E35-9D7A-197012A73EC7}: NameServer = 61.177.7.1,10.214.3.10
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF7EFFBC-AAA2-4E5F-A029-EECE6CECDEBF}: Domain = westwd.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF7EFFBC-AAA2-4E5F-A029-EECE6CECDEBF}: NameServer = 10.10.10.8
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll
O20 - AppInit_DLLs: msji449c14b7.dll daniwshb.dll msv1nv4_.dll
O20 - Winlogon Notify: acac
O20 - Winlogon Notify: NavLogon
O20 - Winlogon Notify: PCANotify
O20 - Winlogon Notify: WgaLogon
O20 - Winlogon Notify: wuapx9tt
O23 - Service: Ati HotKey Poller (Ati HotKey Poller) - - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - "C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe"
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - "C:\Program Files\Symantec AntiVirus\DefWatch.exe"
O23 - Service: Human Interface Device Access (HidServ) - - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: IBM PM Service (IBMPMSVC) - - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: Multi-user Cleanup Service (Multi-user Cleanup Service) - IBM Corp - "C:\Program Files\lotus\notes\ntmulti.exe"
O23 - Service: Pml Driver HPZ12 (Pml Driver HPZ12) - HP - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzipm12.exe
O23 - Service: QCONSVC (QCONSVC) - IBM Corp. - C:\WINDOWS\system32\qconsvc.exe
O23 - Service: RegSrvc (RegSrvc) - Intel Corporation - C:\WINDOWS\system32\regsrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\s24evmon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - "C:\Program Files\Symantec AntiVirus\SavRoam.exe"
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"
O23 - Service: Symantec AntiVirus (Symantec AntiVirus) - Symantec Corporation - "C:\Program Files\Symantec AntiVirus\Rtvscan.exe"
O23 - Service: IBM KCU Service (TpKmpSVC) - - C:\WINDOWS\system32\tpkmpsvc.exe
西门吹胡子 - 2006-9-11 22:28:00
听说System Repair Engineer能智能扫描,结果我的XP是繁体的,全是乱码,郁闷,请问版主有解决的办法吗?
谢谢阿!
我无邪 - 2006-9-11 22:29:00
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。
从头爱你 - 2006-9-11 22:36:00
| 引用: |
【西门吹胡子的贴子】听说System Repair Engineer能智能扫描,结果我的XP是繁体的,全是乱码,郁闷,请问版主有解决的办法吗?
谢谢阿! ……………… |
那hj呢``
(http://forum.ikaka.com/topic.asp?board=67&artid=7018885)
HijackThis V1.99.1 完全汉化版(8月15日更新.)
baohe - 2006-9-11 22:40:00
【回复“西门吹胡子”的帖子】
C:\WINDOWS\tsrv.exe s
C:\WINDOWS\system32\wuapx9tt.exe
找到这两个文件,打包,加密(解压密码用virus),发到:baohelin@yahoo.com.cn。帮你看看。
西门吹胡子 - 2006-9-11 22:51:00
| 引用: |
【从头爱你的贴子】
那hj呢``
(http://forum.ikaka.com/topic.asp?board=67&artid=7018885) HijackThis V1.99.1 完全汉化版(8月15日更新.)
……………… |
好咧,呵呵,谢谢,请看!
西门吹胡子 - 2006-9-11 22:51:00
HijackThis_815汉化版扫描日志 V1.99.1
保存于 下午 10:38:02, 日期 2006/9/11
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\tp4serv.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\RunDll32.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Temp\iparmor\iparmor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\jj4\jjsvr4.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\lotus\notes\ntmulti.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
C:\Program Files\Kingsoft\PowerWord 2005\XDICT.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\slbrwiad.exe
C:\WINDOWS\system32\wuapx9tt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Temp\hijackthis1[1].99.1汉化第二版(new).exe
C:\Program Files\333\HijackThis1991汉化版\HijackThis1991zww.exe
R3 - URLSearchHook: (no name) - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - (no file)
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O3 - IE工具栏增项: 縐縐奻厙假?翑忒 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [TrackPointSrv] tp4serv.exe
O4 - 启动项HKLM\\Run: [ATIModeChange] Ati2mdxx.exe
O4 - 启动项HKLM\\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - 启动项HKLM\\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - 启动项HKLM\\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - 启动项HKLM\\Run: [TP4EX] tp4ex.exe
O4 - 启动项HKLM\\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - 启动项HKLM\\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - 启动项HKLM\\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - 启动项HKLM\\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - 启动项HKLM\\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - 启动项HKLM\\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - 启动项HKLM\\Run: [S3TRAY2] S3Tray2.exe
O4 - 启动项HKLM\\Run: [iparmor] C:\Temp\iparmor\iparmor.exe mini
O4 - 启动项HKLM\\Run: [pdfFactory Pro 分配器 v2] ; C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
O4 - 启动项HKLM\\Run: [yassistse] ; "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - 启动项HKLM\\Run: [YLive.exe] ; C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [pyjj] C:\Program Files\jj4\jjsvr4.exe
O9 - 浏览器额外的按钮: (no name) - {D6E814A0-E0C5-11d4-8D29-0050BA6940E4}? - C:\WINDOWS\system32\shdocvw.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://61.222.107.211/iNotes6W.cab
O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} - http://zs.kingsoft.com/KOSInit.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124347276515
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{873CCEC2-E7C3-4E35-9D7A-197012A73EC7}: NameServer = 61.177.7.1,10.214.3.10
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF7EFFBC-AAA2-4E5F-A029-EECE6CECDEBF}: Domain = westwd.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF7EFFBC-AAA2-4E5F-A029-EECE6CECDEBF}: NameServer = 10.10.10.8
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = westwd.com,westwd.com,westwd.com,westwd.com,kspcb.nanyapcb.com.tw,fpg.com.tw
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = westwd.com,westwd.com,westwd.com,kspcb.nanyapcb.com.tw,fpg.com.tw
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = westwd.com,westwd.com,westwd.com,westwd.com,kspcb.nanyapcb.com.tw,fpg.com.tw
O20 - AppInit_DLLs: msji449c14b7.dll daniwshb.dll msv1nv4_.dll
O20 - Winlogon Notify: acac - C:\WINDOWS\system32\acac.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: wuapx9tt - C:\WINDOWS\system32\wuapx9tt.dll
O23 - NT 服务: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - NT 服务: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - NT 服务: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - NT 服务: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - NT 服务: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - NT 服务: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - NT 服务: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - NT 服务: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - NT 服务: Multi-user Cleanup Service - IBM Corp - C:\Program Files\lotus\notes\ntmulti.exe
O23 - NT 服务: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - NT 服务: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - NT 服务: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - NT 服务: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - NT 服务: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - NT 服务: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - NT 服务: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
西门吹胡子 - 2006-9-11 23:02:00
| 引用: |
【baohe的贴子】【回复“西门吹胡子”的帖子】 C:\WINDOWS\tsrv.exe s
C:\WINDOWS\system32\wuapx9tt.exe
找到这两个文件,打包,加密(解压密码用virus),发到:baohelin@yahoo.com.cn。帮你看看。
……………… |
已发送,请查阅,谢谢!
baohe - 2006-9-11 23:06:00
| 引用: |
【西门吹胡子的贴子】
好咧,呵呵,谢谢,请看!
……………… |
咔吧宰了一个(邮件病毒)
另一个,我看看在说。
附件:
1558472006911225807.jpg
baohe - 2006-9-11 23:24:00
【回复“西门吹胡子”的帖子】
另外一个——C:\WINDOWS\system32\wuapx9tt.exe,在我的系统中无法运行。
卡巴斯基不报毒。
但我觉得它不是什么好东西。
西门吹胡子 - 2006-9-12 8:52:00
| 引用: |
【baohe的贴子】【回复“西门吹胡子”的帖子】 另外一个——C:\WINDOWS\system32\wuapx9tt.exe,在我的系统中无法运行。 卡巴斯基不报毒。 但我觉得它不是什么好东西。 ……………… |
大哥,这个玩意还有那个wuapx9tt。dll我再安全模式下删不掉,更改文件权限天杀的居然不让我更改,重启进入adminstrators居然又找不到着俩文件了,真晕,请继续指教。
那4个tsrv文件很容易就删除了。
baohe - 2006-9-12 8:57:00
| 引用: |
【西门吹胡子的贴子】
大哥,这个玩意还有那个wuapx9tt。dll我再安全模式下删不掉,更改文件权限天杀的居然不让我更改,重启进入adminstrators居然又找不到着俩文件了,真晕,请继续指教。 那4个tsrv文件很容易就删除了。 ……………… |
请用SSM禁止C:\WINDOWS\system32\wuapx9tt.exe加载运行。将SSM设置为“自动运行”。
然后重启系统,再删除C:\WINDOWS\system32\wuapx9tt.exe。
试试看。
西门吹胡子 - 2006-9-12 9:05:00
弱弱的问一下,SSM是什么?。。。
西门吹胡子 - 2006-9-12 9:16:00
再请问一下,木马克星扫出来的这些信息又价值吗,谢谢!
C:\WINDOWS\webwork\webwork.nls文件被系统注入: C:\WINDOWS\Explorer.EXE 程序
C:\WINDOWS\webwork\webwork.nls文件被系统注入: C:\WINDOWS\Explorer.EXE 程序
C:\WINDOWS\tsrv.dll文件被系统注入: [System Process] 程序
C:\WINDOWS\tsrv.dll文件被系统注入: C:\Program Files\lotus\notes\NLNOTES.EXE 程序
C:\WINDOWS\system32\decdnet.dll文件被系统注入: C:\Program Files\Kingsoft\PowerWord 2005\XDICT.EXE 程序
C:\WINDOWS\system32\ra32dnet.dll文件被系统注入: C:\Program Files\Kingsoft\PowerWord 2005\XDICT.EXE 程序
C:\WINDOWS\tsrv.dll文件被系统注入: C:\Program Files\Kingsoft\PowerWord 2005\XDICT.EXE 程序
C:\WINDOWS\system32\msvfjspr.dll文件被系统注入: C:\Program Files\lotus\notes\NLNOTES.EXE 程序
C:\WINDOWS\system32\msvfjspr.dll文件被系统注入: C:\Program Files\Kingsoft\PowerWord 2005\XDICT.EXE 程序
C:\WINDOWS\system32\Flash.ocx文件被系统注入: C:\Program Files\Internet Explorer\iexplore.exe 程序
C:\WINDOWS\system32\PYJJ4.IME文件被系统注入: C:\Program Files\Internet Explorer\iexplore.exe 程序
C:\WINDOWS\system32\PYJJ4.IME文件被系统注入: C:\Program Files\lotus\notes\NLNOTES.EXE 程序
C:\WINDOWS\system32\Flash.ocx文件被系统注入: C:\Program Files\Internet Explorer\iexplore.exe 程序
C:\WINDOWS\SYSTEM32\C:\WINDOWS\system32\NavLogon.dll怀疑为流氓软件2229或者系统文件,测试期间请将此信息发送到木马克星论坛
C:\WINDOWS\SYSTEM32\WgaLogon.dll怀疑为流氓软件2229或者系统文件,测试期间请将此信息发送到木马克星论坛
C:\WINDOWS\SYSTEM32\C:\WINDOWS\system32\wuapx9tt.dll怀疑为流氓软件2229或者系统文件,测试期间请将此信息发送到木马克星论坛
发现可疑系统服务:C:\WINDOWS\SYSTEM32\TPKMPSVC.EXE
以上又个问题:“C:\WINDOWS\tsrv.dll文件被系统注入: [System Process] 程序
C:\WINDOWS\tsrv.dll文件被系统注入: C:\Program Files\lotus\notes\NLNOTES.EXE 程序”
又没有搞错,terv不是被干了吗,注册表也找不到,怎么还能加注,我靠,webwork也卸载了阿,怎么回事阿
西门吹胡子 - 2006-9-12 9:18:00
大哥阿,在线等阿
baohe - 2006-9-12 9:22:00
| 引用: |
【西门吹胡子的贴子】弱弱的问一下,SSM是什么?。。。 ……………… |
使用参考:
http://forum.ikaka.com/topic.asp?board=28&artid=7781820
http://forum.ikaka.com/topic.asp?board=28&artid=8010460
附件:
155847200691291443.jpg
西门吹胡子 - 2006-9-12 11:31:00
大哥,我下了这个最大的好处是终于揪出吃资源的东西:C:\WINDOWS\system32\cisvc.exe 上网查了一下,是XP自带的索引服务,但我到别的机子上看到这个进程最多才占300k左右,我这个是不是中镖了?禁止掉又问题吗?
西门吹胡子 - 2006-9-12 11:33:00
在线等
西门吹胡子 - 2006-9-12 13:13:00
| 引用: |
【baohe的贴子】 请用SSM禁止C:\WINDOWS\system32\wuapx9tt.exe加载运行。将SSM设置为“自动运行”。 然后重启系统,再删除C:\WINDOWS\system32\wuapx9tt.exe。 试试看。
……………… |
大哥,这个删了,但wuapx9tt。dll怎么弄也删不了,也不知道怎么查他被谁调用了,请指点,谢谢
西门吹胡子 - 2006-9-12 13:57:00
大哥,你真是在调用我的主观能动性阿, 我用killbox把这俩文件都干了,进程里也不会有了,cisvc.exe 也禁用了,那我的系统是否真的干净了呢,这个SSM 能当防火墙用吗
西门吹胡子 - 2006-9-12 14:01:00
SRE也弄好了,但启动的时候跳出来这个玩意,你帮我看看是什么,谢谢阿
附件:
7482462006912135322.JPG
我无邪 - 2006-9-12 20:03:00
关闭所有浏览窗口以及一些不必要的程序
运行Hijackthis,扫描结束后在下列选项前打上勾,然后选"修复""
O20 - AppInit_DLLs: msji449c14b7.dll daniwshb.dll msv1nv4_.dll
O20 - Winlogon Notify: acac - C:\WINDOWS\system32\acac.dll
以下三项无法确定,如果你也不知道,我建议你删除它们。
O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: wuapx9tt - C:\WINDOWS\system32\wuapx9tt.dll
重启后删除
C:\WINDOWS\system32\wuapx9tt.dll
C:\WINDOWS\SYSTEM32\WgaLogon.dll
C:\WINDOWS\SYSTEM32\PCANotify.dl
C:\WINDOWS\system32\acac.dll
还有问题的
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。
西门吹胡子 - 2006-9-13 8:48:00
大哥,我弄了几天差不多了,谢谢阿!
我去查了一下PCANotify.dll式个特洛伊木马, 但WgaLogon.dll
,好像是说和XP的一个程序,请看http://www.liutilities.com/products/wintaskspro/processlibrary/wgalogon/
Security Risk (0-5): 0 ( Secure Now )
Spyware: No ( Remove )
Virus: No ( Remove )
Trojan: No ( Remove )
我就没干他,不知道这样对吗?附上System Repair Engineer扫描信息。
HijackThis_815汉化版扫描日志 V1.99.1
保存于 上午 08:31:30, 日期 2006/9/13
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\lotus\notes\ntmulti.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\system32\tp4serv.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\jj4\jjsvr4.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\lotus\notes\NLNOTES.EXE
C:\Program Files\lotus\notes\ntaskldr.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\333\HijackThis1991汉化版\HijackThis1991zww.exe
R3 - URLSearchHook: (no name) - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - IE工具栏增项: 縐縐奻厙假?翑忒 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [TrackPointSrv] tp4serv.exe
O4 - 启动项HKLM\\Run: [ATIModeChange] ; Ati2mdxx.exe
O4 - 启动项HKLM\\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - 启动项HKLM\\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - 启动项HKLM\\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - 启动项HKLM\\Run: [TP4EX] tp4ex.exe
O4 - 启动项HKLM\\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - 启动项HKLM\\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - 启动项HKLM\\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - 启动项HKLM\\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - 启动项HKLM\\Run: [IMEKRMIG6.1] ; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - 启动项HKLM\\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - 启动项HKLM\\Run: [S3TRAY2] ; S3Tray2.exe
O4 - 启动项HKLM\\Run: [iparmor] ; C:\Temp\iparmor\iparmor.exe mini
O4 - 启动项HKLM\\Run: [yassistse] ; "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - 启动项HKLM\\Run: [YLive.exe] ; C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [pyjj] C:\Program Files\jj4\jjsvr4.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O9 - 浏览器额外的按钮: (no name) - {D6E814A0-E0C5-11d4-8D29-0050BA6940E4}? - C:\WINDOWS\system32\shdocvw.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://61.222.107.211/iNotes6W.cab
O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} - http://zs.kingsoft.com/KOSInit.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124347276515
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{873CCEC2-E7C3-4E35-9D7A-197012A73EC7}: NameServer = 61.177.7.1,10.214.3.10
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF7EFFBC-AAA2-4E5F-A029-EECE6CECDEBF}: Domain = westwd.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF7EFFBC-AAA2-4E5F-A029-EECE6CECDEBF}: NameServer = 10.10.10.8
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = westwd.com,westwd.com,westwd.com,westwd.com,kspcb.nanyapcb.com.tw,fpg.com.tw
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = westwd.com,westwd.com,westwd.com,kspcb.nanyapcb.com.tw,fpg.com.tw
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = westwd.com,westwd.com,westwd.com,westwd.com,kspcb.nanyapcb.com.tw,fpg.com.tw
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: System Safety Monitor - C:\WINDOWS\SYSTEM32\SSMWinlogonEx.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - NT 服务: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - NT 服务: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - NT 服务: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - NT 服务: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - NT 服务: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - NT 服务: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - NT 服务: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - NT 服务: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - NT 服务: Multi-user Cleanup Service - IBM Corp - C:\Program Files\lotus\notes\ntmulti.exe
O23 - NT 服务: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - NT 服务: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - NT 服务: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - NT 服务: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - NT 服务: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - NT 服务: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - NT 服务: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
西门吹胡子 - 2006-9-13 8:51:00
SRE智能扫描信息
2006-09-13,08:40:05
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [Microsoft Corporation]
<pyjj><C:\Program Files\jj4\jjsvr4.exe> [加加开发组]
<swg><C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe> [Google Inc.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<TrackPointSrv><tp4serv.exe> [IBM Corporation]
<ATIModeChange><; Ati2mdxx.exe> [ATI Technologies, Inc.]
<BluetoothAuthenticationAgent><rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent> [Microsoft Corporation]
<TPHOTKEY><C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe> []
<BMMLREF><C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE> []
<TP4EX><tp4ex.exe> [IBM Corporation]
<EZEJMNAP><C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe> [IBM Corp.]
<AGRSMMSG><AGRSMMSG.exe> [Agere Systems]
<ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe> [ATI Technologies, Inc.]
<BMMGAG><RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor> [IBM Corp.]
<IMEKRMIG6.1><; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE> [Microsoft Corporation]
<vptray><C:\PROGRA~1\SYMANT~1\VPTray.exe> [Symantec Corporation]
<S3TRAY2><; S3Tray2.exe> [S3 Graphics, Inc.]
<iparmor><; C:\Temp\iparmor\iparmor.exe mini> []
<yassistse><; "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"> []
<YLive.exe><; C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
<WinlogonNotify: NavLogon><C:\WINDOWS\system32\NavLogon.dll> [Symantec Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\System Safety Monitor]
<WinlogonNotify: System Safety Monitor><SSMWinlogonEx.dll> [System Safety Limited]
西门吹胡子 - 2006-9-13 8:53:00
==================================
启动文件夹
[Cisco Systems VPN Client]
<C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\Cisco Systems VPN Client.lnk><N>
==================================
服务
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\System32\Ati2evxx.exe><N/A>
[pcAnywhere Host Service / awhost32]
<C:\Program Files\Symantec\pcAnywhere\awhost32.exe><Symantec Corporation>
[Symantec Event Manager / ccEvtMgr]
<"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc]
<"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr]
<"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[Cisco Systems, Inc. VPN Service / CVPND]
<"C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe"><Cisco Systems, Inc.>
[Symantec AntiVirus Definition Watcher / DefWatch]
<"C:\Program Files\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[IBM PM Service / IBMPMSVC]
<C:\WINDOWS\System32\ibmpmsvc.exe><N/A>
[Multi-user Cleanup Service / Multi-user Cleanup Service]
<"C:\Program Files\lotus\notes\ntmulti.exe"><IBM Corp>
[Pml Driver HPZ12 / Pml Driver HPZ12]
<C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe><HP>
[QCONSVC / QCONSVC]
<System32\QCONSVC.EXE><IBM Corp.>
[RegSrvc / RegSrvc]
<C:\WINDOWS\System32\RegSrvc.exe><Intel Corporation>
[Spectrum24 Event Monitor / S24EventMonitor]
<C:\WINDOWS\System32\S24EvMon.exe><Intel Corporation>
[SavRoam / SavRoam]
<"C:\Program Files\Symantec AntiVirus\SavRoam.exe"><symantec>
[Symantec Network Drivers Service / SNDSrvc]
<"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Symantec AntiVirus / Symantec AntiVirus]
<"C:\Program Files\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>
[IBM KCU Service / TpKmpSVC]
<C:\WINDOWS\system32\TpKmpSVC.exe><N/A>
==================================
浏览器加载项
[Google Toolbar Helper]
{AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[iNotes6 Class]
{3BFFE033-BF43-11D5-A271-00A024A51325} <C:\WINDOWS\Downloaded Program Files\inotes6W.dll, IBM Corporation>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\System32\wuweb.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Flash.ocx, Macromedia, Inc.>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[Google Script Object]
{00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[Query Class]
{01C2F1E8-5C69-4B5C-B052-26941B6C23A6} <, N/A>
[EWA Control]
{18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\COMMON~1\Synacast\SynaLive\SYNACA~1.OCX, Synacast>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\System32\mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[Tabular Data Control]
{333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\System32\tdc.ocx, Microsoft Corporation>
[iNotes6 Class]
{3BFFE033-BF43-11D5-A271-00A024A51325} <C:\WINDOWS\Downloaded Program Files\inotes6W.dll, IBM Corporation>
[DEInsertTableParam Class]
{47B0DFC7-B7A3-11D1-ADC5-006008A5848C} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[XML Document]
{48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\System32\msxml3.dll, N/A>
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\HHCTRL.OCX, Microsoft Corporation>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[金山毒霸在??毒]
{577A1997-6FD0-4972-B234-885DA583F9CE} <C:\PROGRA~1\KOS\KOSClean.ocx, N/A>
[Grabcom Control]
{6231CB1A-29F4-43D1-809B-A67B36995357} <C:\PROGRA~1\ONDAMP~1.01\AMVCON~1\grabcom.ocx, actions>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web Browser]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Grabcom Control]
{9931CB1A-29F4-43D1-809B-A67B36995357} <C:\PROGRA~1\ONDAMP~1.01\MEDIAM~1\grabcom.ocx, actions>
[WinSC Class]
{9ACEEE31-1440-471B-AA46-72B061FE7D61} <, N/A>
[Google Toolbar Helper]
{AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\System32\mshtml.dll, Microsoft Corporation>
[BrowserHAP Class]
{AEF6F648-78D8-4456-BEE7-5ADE23D209FD} <C:\Program Files\HBClient\hapast.dll, N/A>
[卡卡上网安全助手]
{AFF6E516-CBE5-4F8A-9C2F-38A68013E766} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Microsoft DirectAnimation Control]
{B6FFC24C-7E13-11D0-9B47-00C04FC2F51D} <C:\WINDOWS\System32\danim.dll, Microsoft Corporation>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
{CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Flash.ocx, Macromedia, Inc.>
[Microsoft DirectAnimation Path]
{D7A7D7C3-D47F-11D0-89D3-00A0C90833E6} <C:\WINDOWS\System32\daxctle.ocx, Microsoft Corporation>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[DuiSo.com Search]
{E2218499-2FD4-4EED-A94A-7F0B9C6E300E} <, N/A>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[IERPCtl Class]
{FDC7A535-4070-4B92-A0EA-D9994BCC0DC5} <C:\Program Files\Real\RealPlayer\rpplugins\ierpplug.dll, RealNetworks, Inc.>
西门吹胡子 - 2006-9-13 8:54:00
==================================
正在运行的进程
[PID: 1456][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1556][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1580][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\WgaLogon.dll] <Microsoft Corp.><1.5.0512.0>
[C:\WINDOWS\system32\SSMWinlogonEx.dll] <System Safety Limited><2.0.8.582>
[C:\WINDOWS\system32\NavLogon.dll] <Symantec Corporation><9.0.0.338>
[PID: 1624][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1636][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1800][C:\WINDOWS\System32\ibmpmsvc.exe] <N/A><N/A>
[PID: 1856][C:\WINDOWS\System32\Ati2evxx.exe] <N/A><N/A>
[PID: 1892][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1984][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 224][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 320][C:\WINDOWS\System32\S24EvMon.exe] <Intel Corporation ><4, 1, 0, 3>
[PID: 472][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 680][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 704][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll] <IBM Corp.><1, 0, 0, 0>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[C:\Program Files\ONDA MP3 Player Utilities 4.01\AMVConverter\AmvTransform.dll] <><1, 0, 0, 1>
[C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll] <Symantec Corporation><9.0.0.338>
[PID: 940][C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe] <Symantec Corporation><2.2.0.577>
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] <Symantec Corporation><2.2.0.577>
[PID: 976][C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe] <Symantec Corporation><2.2.0.577>
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] <Symantec Corporation><2.2.0.577>
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCSETEVT.DLL] <Symantec Corporation><2.2.0.577>
[PID: 1136][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[C:\WINDOWS\system32\fppmon2.dll] <FinePrint Software, LLC><2.15>
[C:\WINDOWS\system32\fppr232.dll] <FinePrint Software, LLC><2.15>
[C:\WINDOWS\system32\HPTcpMon.dll] <Hewlett Packard><2.50.01.006>
[C:\WINDOWS\system32\HPZJSN01.dll] <Hewlett Packard Company><1, 0, 0, 3>
[C:\WINDOWS\system32\hpzjfw01.dll] <Hewlett-Packard><4.02.009.0>
[C:\WINDOWS\system32\HPTcpMUI.dll] <Microsoft Corporation><2.50.01.006>
[C:\WINDOWS\system32\hptcpmib.dll] <Hewlett Packard><2.50.01.006>
[C:\WINDOWS\system32\awmon.dll] <Symantec Corporation><9.2.1>
[PID: 308][C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe] <Cisco Systems, Inc.><4.0.3 (C)>
[C:\WINDOWS\system32\vsdata.dll] <Zone Labs Inc.><4.0.146.033>
[C:\WINDOWS\system32\VSINIT.dll] <Zone Labs Inc.><4.0.146.033>
[PID: 520][C:\Program Files\Symantec AntiVirus\DefWatch.exe] <Symantec Corporation><9.0.0.338>
[PID: 572][C:\Program Files\lotus\notes\ntmulti.exe] <IBM Corp><6.0.40.4008>
[PID: 600][C:\WINDOWS\System32\QCONSVC.EXE] <IBM Corp.><3, 0, 0, 0>
[PID: 660][C:\WINDOWS\System32\RegSrvc.exe] <Intel Corporation><4, 1, 0, 0>
[PID: 1048][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1308][C:\Program Files\Symantec AntiVirus\Rtvscan.exe] <Symantec Corporation><9.0.0.338>
[C:\WINDOWS\system32\CBA.DLL] <Intel? Corporation><6.12.0.112 E>
[C:\WINDOWS\system32\MsgSys.dll] <Intel? Corporation><6.12.0.112 E>
[C:\WINDOWS\system32\NTS.dll] <Intel? Corporation><6.12.0.112 E>
[C:\WINDOWS\system32\PDS.DLL] <Intel? Corporation><6.12.0.112 E>
[C:\Program Files\Symantec AntiVirus\NAVLU.dll] <Symantec Corporation><9.0.0.338>
[C:\Program Files\Symantec AntiVirus\I2ldvp3.dll] <Symantec Corporation><9.0.0.338>
[C:\Program Files\Symantec AntiVirus\ecmldr32.DLL] <Symantec Corp.><1.1.0.3>
[C:\Program Files\Symantec AntiVirus\SAVRT32.DLL] <Symantec Corporation><9.3.0.28>
[C:\Program Files\Symantec AntiVirus\NAVNTUTL.DLL] <Symantec Corporation><9.0.0.338>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060910.037\ecmsvr32.dll] <Symantec Corporation><61.2.1.10>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060910.037\NAVEX32a.DLL] <Symantec Corporation><20061.2.0.26>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060910.037\NAVENG32.DLL] <Symantec Corporation><20061.2.0.26>
[C:\Program Files\Symantec AntiVirus\IMail.dll] <Symantec Corporation><9.0.0.338>
[C:\Program Files\Symantec AntiVirus\NotesExt.dll] <Symantec Corporation><9.0.0.338>
[C:\Program Files\Symantec AntiVirus\vpmsece.dll] <Symantec Corporation><9.0.0.338>
[C:\Program Files\Common Files\Symantec Shared\SSC\scandlgs.dll] <Symantec Corporation><9.0.0.338>
[C:\Program Files\Symantec AntiVirus\DecSDK.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2ID.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2ZIP.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2SS.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2GZIP.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2CAB.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2LHA.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2ARJ.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2TNEF.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2LZ.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2AMG.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2TAR.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2RTF.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2Text.dll] <Symantec Corporation><3.02.11.32>
[PID: 880][C:\WINDOWS\system32\TpKmpSVC.exe] <N/A><N/A>
[PID: 584][C:\WINDOWS\system32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 2064][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2712][C:\WINDOWS\system32\tp4serv.exe] <IBM Corporation><3.10>
[C:\WINDOWS\system32\tp4uires.dll] <N/A><N/A>
[PID: 2868][C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe] <N/A><N/A>
[C:\Program Files\ThinkPad\PkgMgr\HOTKEY_2\tphk_2k.dll] <N/A><N/A>
[C:\WINDOWS\system32\Oemdspif.dll] <ATI Technologies, Inc.><6.14.0010>
[PID: 3016][C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe] <IBM Corp.><1, 0, 0, 0>
[PID: 3072][C:\WINDOWS\AGRSMMSG.exe] <Agere Systems><2.1.31 2.1.31 06/27/2003 08:53:31>
[PID: 3124][C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe] <N/A><N/A>
[PID: 3200][C:\WINDOWS\system32\RunDll32.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll] <IBM Corp.><1, 0, 0, 0>
[C:\PROGRA~1\ThinkPad\UTILIT~1\tppwrw32.dll] <IBM Corp.><1, 0, 0, 0>
[PID: 3216][C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe] <IBM Corporation><1.06>
[PID: 3220][C:\PROGRA~1\SYMANT~1\VPTray.exe] <Symantec Corporation><9.0.0.338>
[C:\Program Files\Symantec AntiVirus\SAVRT32.DLL] <Symantec Corporation><9.3.0.28>
[C:\Program Files\Symantec AntiVirus\Cliproxy.dll] <Symantec Corporation><9.0.0.338>
[C:\PROGRA~1\SYMANT~1\NAVNTUTL.DLL] <Symantec Corporation><9.0.0.338>
[C:\Program Files\Symantec AntiVirus\Cliscan.dll] <Symantec Corporation><9.0.0.338>
[PID: 3248][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3280][C:\Program Files\jj4\jjsvr4.exe] <加加开发组><4.0.0.20>
© 2000 - 2026 Rising Corp. Ltd.