瑞星卡卡安全论坛
防火墙007 - 2006-9-16 15:03:00
deadmanzj - 2006-9-16 15:06:00
那个是RAVDM木马释放的文件。。
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改
防火墙007 - 2006-9-16 15:14:00
防火墙007 - 2006-9-16 15:17:00
附上内容
A problem has been delected and windows has been shut down
to prevent damage to your computer.
KERNEL_STACK_INPAGE_ERROR
If this is the first time you've seen this stop error screen.
restart your computer.If this screen appares again,follow these step:
check to make sure any new hardware or software is properly installed.
If this is a new installation,ask your hardware or software manufactuer
for any windows updates you might need.
If problems continue,disable or remove any newly installed hardware or
software.Disable BIOS memory options such as caching or shadowing.
If you need to use Safe Mode to remove or disable components,restart
your computer,press F8 to select Advanced Start up options,and then
select Safe Mode.
Technical information:
*** stop: 0x00000077 (0xc000000E,0Xc000000E,0x00000000,0x03DFA000)
Beginning dump of phisical memory
防火墙007 - 2006-9-16 15:20:00
防火墙007 - 2006-9-16 15:21:00
防火墙007 - 2006-9-16 15:22:00
帮帮忙,给我号号脉!
klxq - 2006-9-16 15:23:00
系统重新启动了.
防火墙007 - 2006-9-16 15:30:00
2006-09-16,15:20:08
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [Microsoft Corporation]
<pyjj><; D:\Program Files\jj4\jjsvr4.exe> [加加开发组]
<Super Rabbit IEPro><; D:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD> [Super Rabbit Soft]
<PcSync><D:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog> [Time Information Services Ltd.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<nwiz><nwiz.exe /install> [NVIDIA Corporation]
<SoundMan><; SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<AGRSMMSG><; AGRSMMSG.exe> [Agere Systems]
<KTPWare><C:\Program Files\Elantech\ktp.exe> [ELANTECH Devices Corp.]
<RemoteControl><"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"> [Cyberlink Corp.]
<IgrsSignal><"C:\Program Files\lenovo\IGRS\Ext\IgrsSignal.exe"> [Lenovo Group Limited]
<IgrsNotify><"C:\Program Files\lenovo\IGRS\Ext\IgrsNotify.exe"> [Lenovo Group Limited]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [Microsoft Corporation]
<StormCodec_Helper><"d:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> []
<MRUpdateClient><d:\Program Files\Morrowsoft\MRICU\MRUpdate\AutoClient.exe> []
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> []
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
<stup.exe><C:\PROGRA~1\TENCENT\Adplus\stup.exe> [Tencent]
<PCSuiteTrayApplication><D:\PROGRA~2\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup> [Nokia]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<RavStub><"C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\Userinit.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igrswn]
<WinlogonNotify: igrswn><C:\Program Files\lenovo\IGRS\Ext\igrswn.dll> [Lenovo Group Limited]
==================================
启动文件夹
[AutoCAD 启动加速器]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\AutoCAD 启动加速器.lnk><H>
[腾讯QQ]
<C:\Documents and Settings\cz\「开始」菜单\程序\启动\腾讯QQ.lnk><N>
==================================
服务
[Autodesk Licensing Service / Autodesk Licensing Service]
<"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk>
[Gmail Server / Gmail]
<C:\WINDOWS\system32\su.exe><N/A>
[General Updater/AutoUpdater Service / GUA]
<"C:\Program Files\lenovo\GUA\GUA.exe"><lenovo>
[IGRS / IGRS]
<C:\Program Files\lenovo\IGRS\IGRS.exe><Lenovo Group Limited>
[IGRSFILE / IGRSFILE]
<C:\Program Files\lenovo\IGRS Profiles\File Profile\IgrsFile.exe><Lenovo Group Limited>
[IgrsMonitor / IgrsMonitor]
<"C:\Program Files\lenovo\IGRS\Ext\IgrsMonitor.exe"><Lenovo Group Limited>
[MicroGrid DirectRouter / MicroGrid.DirectRouter]
<C:\Program Files\lenovo\IGRS\Ext\router.exe><Lenovo Group Limited>
[NVIDIA Display Driver Service / NVSvc]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Rising Personal Firewall Service / RfwService]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[ServiceLayer / ServiceLayer]
<"C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe"><Nokia.>
[WMCSVC / WMCSVC]
<C:\Program Files\lenovo\IGRS\Ext\wmcsvc.exe><Lenovo Group Limited>
防火墙007 - 2006-9-16 15:31:00
==================================
浏览器加载项
[Tencent Browser Helper]
{0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr1.dll, Tencent>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <D:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[易趣购物]
{DE60714F-AC17-427e-861A-FD60CBDF119A} <http://click2.ad4all.net/url2/urlmanage/url.asp?id=1, N/A>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <D:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[IMCv1 Control]
{6924091F-CD97-41E1-B1D4-D9079409D413} <C:\PROGRA~1\LtUcx\1003\c0.dll, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[Tencent Browser Helper]
{0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr1.dll, Tencent>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <D:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Microsoft 外壳 UI 帮助程序]
{64AB4BB7-111E-11D1-8F79-00C04FC2FBE1} <%SystemRoot%\system32\shdocvw.dll, N/A>
[IMCv1 Control]
{6924091F-CD97-41E1-B1D4-D9079409D413} <C:\PROGRA~1\LtUcx\1003\c0.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <D:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[卡卡上网安全助手]
{AFF6E516-CBE5-4F8A-9C2F-38A68013E766} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Messenger Object]
{B69003B3-C55E-4B48-836C-BC5946FC3B28} <C:\Program Files\Messenger\msgsc.dll, Microsoft Corporation>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\MSADC\msadco.dll, Microsoft Corporation>
[AUDIO__MP3 Moniker Class]
{CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AUDIO__WAV Moniker Class]
{CD3AFA7B-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AUDIO__X_MS_WMA Moniker Class]
{CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[&使用迅雷下载]
<d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用影音传送带下载]
<, N/A>
[使用影音传送带下载全部链接]
<, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://D:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
防火墙007 - 2006-9-16 15:32:00
==================================
正在运行的进程
[PID: 600][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 664][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 688][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[PID: 732][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 744][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 900][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 968][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1072][C:\Program Files\Rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1088][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1184][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1264][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1280][C:\Program Files\Rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 35>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
[C:\Program Files\Rising\Rav\HOOKSYS.dll] <Beijing Rising Technology Co., Ltd.><18, 1, 0, 11>
[C:\Program Files\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 32>
[C:\Program Files\Rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\Rising\Rav\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\HookWeb.dll] <rising><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[C:\Program Files\Rising\Rav\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Rising\Rav\SpamEng.dll] <N/A><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 34>
[C:\Program Files\Rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 15>
[C:\Program Files\Rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[C:\Program Files\Rising\Rav\RSUnpack.dll] <Beijing Rising Technology Co., Ltd.><1, 0, 0, 13>
[C:\Program Files\Rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\Rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[C:\Program Files\Rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[C:\Program Files\Rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[PID: 1656][c:\program files\rising\rfw\rfwsrv.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 33>
[c:\program files\rising\rfw\RfwRule.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
[c:\program files\rising\rfw\rfwlog.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
[c:\program files\rising\rfw\Rfwdrv.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
[c:\program files\rising\rfw\MonDrv.dll] <rs><1, 0, 0, 4>
[c:\program files\rising\rfw\ProcLib.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 1684][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[C:\WINDOWS\system32\AcSignIcon.dll] <Autodesk><16.2.54.0>
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] <Tencent><4, 2, 4, 43>
[C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] <Autodesk><16.2.54.0>
[C:\Program Files\TENCENT\Adplus\SSAddr1.dll] <Tencent><4, 2, 4, 43>
[PID: 1924][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 2032][C:\Program Files\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 240][D:\Program Files\jj4\jjsvr4.exe] <加加开发组><4.0.0.20>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] <Tencent><4, 2, 4, 43>
[PID: 288][c:\program files\rising\rfw\RfwMain.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 52>
[c:\program files\rising\rfw\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
[c:\program files\rising\rfw\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[c:\program files\rising\rfw\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] <Tencent><4, 2, 4, 43>
[PID: 1020][C:\Program Files\Elantech\ktp.exe] <ELANTECH Devices Corp.><5, 0, 1, 9>
[C:\Program Files\Elantech\KtpXPdll.dll] <ELANTECH Devices Corp.><5, 0, 1, 8>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[C:\Program Files\Elantech\KtpDll.Dll] <ELANTECH Devices Corp.><5.0.1.6>
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] <Tencent><4, 2, 4, 43>
[PID: 1056][C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe] <Cyberlink Corp.><5.00.0000>
[C:\Program Files\CyberLink\Shared Files\CLRCEngine2.dll] <CyberLink Corp.><3.20.0000>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
防火墙007 - 2006-9-16 15:33:00
[PID: 1164][C:\Program Files\lenovo\IGRS\Ext\IgrsSignal.exe] <Lenovo Group Limited><1, 0, 0, 4>
[C:\WINDOWS\system32\WMCAPI.dll] <Lenovo Group Limited><2, 0, 2, 19>
[C:\WINDOWS\system32\wmcdrv.dll] <Lenovo Group Limited><3, 1, 0, 10>
[C:\WINDOWS\system32\wmcinst.dll] <Lenovo Group Limited><2, 0, 1, 3>
[C:\WINDOWS\system32\igrsrt.dll] <Lenovo Group Limited><1, 0, 0, 13>
[C:\Program Files\lenovo\IGRS\Ext\IgrsNotifyPS.dll] <N/A><N/A>
[C:\Program Files\lenovo\IGRS\Ext\IgrsMonitorPS.dll] <N/A><N/A>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] <Tencent><4, 2, 4, 43>
[PID: 1204][C:\Program Files\lenovo\IGRS\Ext\IgrsNotify.exe] <Lenovo Group Limited><1, 0, 0, 8>
[C:\Program Files\lenovo\IGRS\Ext\NotifyUI.dll] <Lenovo Group Limited><1, 0, 0, 7>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[C:\Program Files\lenovo\IGRS\Ext\IgrsNotifyPS.dll] <N/A><N/A>
[PID: 1212][C:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[PID: 1240][C:\Program Files\Rising\Rav\Ravmon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 33>
[C:\Program Files\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] <Tencent><4, 2, 4, 43>
[PID: 1248][C:\Program Files\lenovo\GUA\GUA.exe] <lenovo><1.0.0.19>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[PID: 1420][D:\Program Files\Morrowsoft\MRICU\MRUpdate\AutoClient.exe] <><1.0.0.94>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[PID: 1472][C:\Program Files\lenovo\IGRS\IGRS.exe] <Lenovo Group Limited><1.0.0.174>
[C:\Program Files\lenovo\IGRS\framework.dll] <Lenovo Group Limited><1.0.0.174>
[C:\Program Files\lenovo\IGRS\ReliablePlugin.dll] <Lenovo Group Limited><1.0.0.174>
[C:\WINDOWS\system32\WMCAPI.dll] <Lenovo Group Limited><2, 0, 2, 19>
[C:\WINDOWS\system32\wmcdrv.dll] <Lenovo Group Limited><3, 1, 0, 10>
[C:\WINDOWS\system32\wmcinst.dll] <Lenovo Group Limited><2, 0, 1, 3>
[C:\Program Files\lenovo\IGRS\CorePlugin.dll] <Lenovo Group Limited><1.0.0.174>
[C:\Program Files\lenovo\IGRS\SocketPlugin.dll] <Lenovo Group Limited><1.0.0.174>
[C:\Program Files\lenovo\IGRS\BTComPlugin.dll] <Lenovo Group Limited><1.0.0.174>
[C:\Program Files\lenovo\IGRS\SerialPortMonitor.dll] <lenovo><1, 0, 1, 19>
[C:\Program Files\lenovo\IGRS\ProxyPlugin.dll] <Lenovo Group Limited><1.0.0.174>
[C:\Program Files\lenovo\IGRS\LoggingPlugin.dll] <Lenovo Group Limited><1.0.0.174>
[C:\Program Files\lenovo\IGRS\DebugPlugin.dll] <Lenovo Group Limited><1.0.0.174>
[PID: 1512][D:\PROGRA~2\Nokia\NOKIAP~1\LAUNCH~1.EXE] <Nokia><6, 80, 53, 3>
[C:\WINDOWS\system32\ConnAPI.DLL] <Nokia.><6, 80, 55, 5>
[D:\PROGRA~2\Nokia\NOKIAP~1\PCSCM.dll] <Nokia><6, 80, 66, 0>
[C:\Program Files\Common Files\PCSuite\ConfServer\ConfServer.dll] <Nokia><6, 80, 20, 4>
[C:\WINDOWS\system32\NclTools.dll] <Nokia.><6, 80, 18, 3>
[D:\PROGRA~2\Nokia\NOKIAP~1\Lang\LaunchApplication_chi-sc.NLR] <Nokia><6, 80, 56, 0>
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] <Tencent><4, 2, 4, 43>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[PID: 1528][C:\Program Files\lenovo\IGRS\Ext\IgrsMonitor.exe] <Lenovo Group Limited><1, 0, 1, 13>
[C:\WINDOWS\system32\IgrsApi.dll] <Lenovo Group Limited><1.0.0.174>
[C:\WINDOWS\system32\WMCAPI.dll] <Lenovo Group Limited><2, 0, 2, 19>
[C:\WINDOWS\system32\wmcdrv.dll] <Lenovo Group Limited><3, 1, 0, 10>
[C:\WINDOWS\system32\wmcinst.dll] <Lenovo Group Limited><2, 0, 1, 3>
[C:\Program Files\lenovo\IGRS\Ext\IgrsMonitorPS.dll] <N/A><N/A>
[PID: 1572][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[PID: 1596][C:\Program Files\lenovo\IGRS\Ext\router.exe] <Lenovo Group Limited><1, 3, 0, 12>
[PID: 1328][C:\WINDOWS\system32\nvsvc32.exe] <NVIDIA Corporation><6.14.10.7840>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[PID: 1752][D:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe] <Time Information Services Ltd.><2.00 (486)>
[D:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll] <Nokia><6, 80, 66, 0>
[C:\WINDOWS\system32\ConnAPI.DLL] <Nokia.><6, 80, 55, 5>
[D:\Program Files\Nokia\Nokia PC Suite 6\PCSL.dll] <Nokia><6, 80, 4, 0>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
防火墙007 - 2006-9-16 15:33:00
[D:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\Lang\PcSync2_chi-sc.nlr] <Time Information Services Ltd.><8.00 (486)>
[D:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\Resource\PcSync2_Nokia.ngr] <Time Information Services Ltd.><8.00 (486)>
[C:\Program Files\Common Files\Nokia\Adapters\NclSet.dll] <Nokia><6.80.9.0>
[C:\Program Files\Common Files\Nokia\Adapters\Nclaeo.dsc] <Nokia Mobile Phones Ltd.><4.00.008>
[C:\Program Files\Common Files\Nokia\MPAPI\MPAPIps.dll] <Nokia Corporation><6.80.73.0>
[C:\Program Files\Common Files\PCSuite\ConfServer\ConfServer.dll] <Nokia><6, 80, 20, 4>
[C:\WINDOWS\system32\NclTools.dll] <Nokia.><6, 80, 18, 3>
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] <Tencent><4, 2, 4, 43>
[D:\Program Files\Nokia\Nokia PC Suite 6\CommonSelectDevice.dll] <Nokia><6, 80, 73, 0>
[PID: 468][C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe] <Nokia Corporation><6.80.161.0>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[C:\Program Files\Common Files\Nokia\MPAPI\MPAPIps.dll] <Nokia Corporation><6.80.73.0>
[PID: 1244][C:\WINDOWS\system32\wbem\wmiprvse.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2236][C:\WINDOWS\system32\wuauclt.exe] <Microsoft Corporation><5.4.3790.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2360][D:\Program Files\Super Rabbit\MagicSet\MagicSet.exe] <Super Rabbit Soft><7.80>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] <Tencent><4, 2, 4, 43>
[PID: 2548][C:\WINDOWS\system32\wscntfy.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] <Tencent><4, 2, 4, 43>
[PID: 2544][C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe] <Nokia.><6, 80, 56, 4>
[C:\WINDOWS\system32\NclTools.dll] <Nokia.><6, 80, 18, 3>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[C:\Program Files\Common Files\PCSuite\Services\NclDS.dll] <Nokia><6, 80, 12, 0>
[C:\Program Files\Common Files\PCSuite\Transports\NCLIrDAMM.dll] <Nokia Corp.><6, 80, 26, 0>
[C:\Program Files\Common Files\PCSuite\Transports\NCLRSMM.dll] <Nokia><6, 80, 33, 0>
[C:\Program Files\Common Files\PCSuite\Transports\NCLUSBMM.dll] <Nokia><6, 80, 37, 0>
[C:\Program Files\Common Files\PCSuite\Transports\NclMSBTMM.dll] <Nokia.><6, 80, 38, 2>
[PID: 2896][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3424][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] <Tencent><4, 2, 4, 43>
[C:\Program Files\TENCENT\Adplus\SSAddr1.dll] <Tencent><4, 2, 4, 43>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[C:\WINDOWS\system32\AcSignIcon.dll] <Autodesk><16.2.54.0>
[D:\Program Files\Super Rabbit\MagicSet\haokanbar.dll] <Xiang Feng Technology><2, 2, 0, 1612>
[D:\Program Files\Tencent\QQ\QQIEHelper.dll] <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] <Adobe Systems, Inc.><9,0,16,0>
[C:\Program Files\Elantech\KtpDll.Dll] <ELANTECH Devices Corp.><5.0.1.6>
[PID: 584][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 656][C:\Program Files\WinRAR\WinRAR.exe] <N/A><N/A>
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] <Tencent><4, 2, 4, 43>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
[C:\WINDOWS\system32\AcSignIcon.dll] <Autodesk><16.2.54.0>
[D:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll] <Nokia><6, 80, 37, 4>
[D:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll] <Nokia><6, 80, 66, 0>
[C:\WINDOWS\system32\ConnAPI.DLL] <Nokia.><6, 80, 55, 5>
[D:\Program Files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_chi-sc.nlr] <Nokia><6, 80, 26, 0>
[D:\Program Files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr] <Nokia><6, 80, 8, 0>
[PID: 2112][C:\DOCUME~1\cz\LOCALS~1\Temp\Rar$EX00.922\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] <Tencent><4, 2, 4, 43>
[C:\WINDOWS\system32\PYJJ4.IME] <加加工作组><4.0.0.21>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
防火墙007 - 2006-9-16 19:39:00
各位大虾们帮忙解决啊!别保留啊!!!跪谢!!!
防火墙007 - 2006-9-17 11:23:00
没人搞懂吗?斑竹帮我看看啊!
轩辕小聪 - 2006-9-17 17:55:00
[Gmail Server / Gmail]
<C:\WINDOWS\system32\su.exe><N/A>
灰鸽子
用SREng在“启动项目”-“服务”-“Win32服务应用程序”中点“隐藏微软服务”,选中此项,点“删除服务”,再点“设置”,在弹出的对话框中点“否”
重启后删除C:\WINDOWS\system32\su.exe
newcenturymoon - 2006-9-17 18:05:00
蓝屏 应该和病毒无关 检查一下硬件
防火墙007 - 2006-9-17 22:12:00
还有,我的电池装上以后会反复启动!
防火墙007 - 2006-9-17 22:14:00
这个我还得好好看看了
1
© 2000 - 2026 Rising Corp. Ltd.