瑞星卡卡安全论坛
ltjj - 2006-12-8 22:14:00
标题:菜鸟求救!
各位大虾:
感谢您关注我的这份报告,小菜鸟急需您的帮助!
本扫描/诊断报告由 雅虎助手IE修复专家 生成
操作系统: Windows XP
IE版本号: 6.0.2900.2180
===============================================================
以下是我的扫描报告正文:
*** 扫描项列表 ***
进程中依赖的非微软模块
1.037 - 进程 lsass.exe 依赖的非微软模块 - uxtheme.dll,(未验证)Microsoft Corporation,
相关文件:C:\WINDOWS\system32\uxtheme.dll
2.037 - 进程 explorer.exe 依赖的非微软模块 - uxtheme.dll,(未验证)Microsoft Corporation,
相关文件:C:\WINDOWS\system32\uxtheme.dll
3.037 - 进程 explorer.exe 依赖的非微软模块 - PvSec.dll,Unknow Owner,
相关文件:C:\WINDOWS\system32\PvSec.dll
4.037 - 进程 explorer.exe 依赖的非微软模块 - reporter.dll,Unknow Owner,
相关文件:C:\WINDOWS\system32\reporter.dll
IE修复专家扫描到的系统信息
5.P00 - 正在运行的服务 - Application Layer Gateway Service,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\alg.exe
内容:C:\WINDOWS\System32\alg.exe
6.P00 - 正在运行的服务 - Windows Audio,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\audiosrv.dll
内容:C:\WINDOWS\System32\svchost.exe -k netsvcs
7.P00 - 正在运行的服务 - Cryptographic Services,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\cryptsvc.dll
内容:C:\WINDOWS\system32\svchost.exe -k netsvcs
8.P00 - 正在运行的服务 - DCOM Server Process Launcher,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\rpcss.dll
内容:C:\WINDOWS\system32\svchost -k DcomLaunch
9.P00 - 正在运行的服务 - DHCP Client,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\dhcpcsvc.dll
内容:C:\WINDOWS\system32\svchost.exe -k netsvcs
10.P00 - 正在运行的服务 - Logical Disk Manager,Microsoft Corp.,
相关文件:C:\WINDOWS\system32\dmserver.dll
内容:C:\WINDOWS\System32\svchost.exe -k netsvcs
11.P00 - 正在运行的服务 - DNS Client,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\dnsrslvr.dll
内容:C:\WINDOWS\system32\svchost.exe -k NetworkService
12.P00 - 正在运行的服务 - Error Reporting Service,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\ersvc.dll
内容:C:\WINDOWS\System32\svchost.exe -k netsvcs
13.P00 - 正在运行的服务 - Event Log,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\services.exe
内容:C:\WINDOWS\system32\services.exe
14.P00 - 正在运行的服务 - COM+ Event System,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\es.dll
内容:C:\WINDOWS\system32\svchost.exe -k netsvcs
15.P00 - 正在运行的服务 - Fast User Switching Compatibility,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\shsvcs.dll
内容:C:\WINDOWS\System32\svchost.exe -k netsvcs
16.P00 - 正在运行的服务 - Help and Support,Microsoft Corporation,
相关文件:C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll
内容:C:\WINDOWS\System32\svchost.exe -k netsvcs
17.P00 - 正在运行的服务 - IIS Admin,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\inetsrv\inetinfo.exe
内容:C:\WINDOWS\system32\inetsrv\inetinfo.exe
18.P00 - 正在运行的服务 - Server,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\srvsvc.dll
内容:C:\WINDOWS\system32\svchost.exe -k netsvcs
19.P00 - 正在运行的服务 - Workstation,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\wkssvc.dll
内容:C:\WINDOWS\system32\svchost.exe -k netsvcs
20.P00 - 正在运行的服务 - TCP/IP NetBIOS Helper,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\lmhsvc.dll
内容:C:\WINDOWS\system32\svchost.exe -k LocalService
21.P00 - 正在运行的服务 - Machine Debug Manager,Microsoft Corporation,
相关文件:C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
内容:"C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"
22.P00 - 正在运行的服务 - SQL Server (SQLEXPRESS),Microsoft Corporation,
相关文件:C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -sSQLEXPRESS
内容:"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
23.P00 - 正在运行的服务 - Network Connections,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\netman.dll
内容:C:\WINDOWS\System32\svchost.exe -k netsvcs
24.P00 - 正在运行的服务 - Network Location Awareness (NLA),Microsoft Corporation,
相关文件:C:\WINDOWS\system32\mswsock.dll
内容:C:\WINDOWS\system32\svchost.exe -k netsvcs
25.P00 - 正在运行的服务 - NVIDIA Display Driver Service,NVIDIA Corporation,
相关文件:C:\WINDOWS\system32\nvsvc32.exe
内容:C:\WINDOWS\system32\nvsvc32.exe
26.P00 - 正在运行的服务 - Plug and Play,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\services.exe
内容:C:\WINDOWS\system32\services.exe
27.P00 - 正在运行的服务 - IPSEC Services,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\lsass.exe
内容:C:\WINDOWS\system32\lsass.exe
28.P00 - 正在运行的服务 - Protected Storage,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\lsass.exe
内容:C:\WINDOWS\system32\lsass.exe
29.P00 - 正在运行的服务 - Remote Access Connection Manager,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\rasmans.dll
内容:C:\WINDOWS\system32\svchost.exe -k netsvcs
30.P00 - 正在运行的服务 - Remote Access Connection Management,Unknow Owner,
相关文件:C:\Program Files\Messenger\msnhost.dll
内容:C:\WINDOWS\System32\svchost.exe -k netsvcs
31.P00 - 正在运行的服务 - Remote Registry,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\regsvc.dll
内容:C:\WINDOWS\system32\svchost.exe -k LocalService
32.P00 - 正在运行的服务 - Remote Procedure Call (RPC),Microsoft Corporation,
相关文件:C:\WINDOWS\system32\rpcss.dll
内容:C:\WINDOWS\system32\svchost -k rpcss
33.P00 - 正在运行的服务 - Rising Process Communication Center,Beijing Rising Technology Co., Ltd.,
相关文件:D:\Program Files\Rising\Rav\CCenter.exe
内容:"D:\Program Files\Rising\Rav\CCenter.exe"
34.P00 - 正在运行的服务 - Rising RealTime Monitor,Beijing Rising Technology Co., Ltd.,
相关文件:D:\Program Files\Rising\Rav\RavMonD.exe
内容:"D:\Program Files\Rising\Rav\Ravmond.exe"
35.P00 - 正在运行的服务 - Security Accounts Manager,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\lsass.exe
内容:C:\WINDOWS\system32\lsass.exe
36.P00 - 正在运行的服务 - Task Scheduler,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\schedsvc.dll
内容:C:\WINDOWS\System32\svchost.exe -k netsvcs
37.P00 - 正在运行的服务 - Secondary Logon,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\seclogon.dll
内容:C:\WINDOWS\System32\svchost.exe -k netsvcs
38.P00 - 正在运行的服务 - System Event Notification,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\sens.dll
内容:C:\WINDOWS\system32\svchost.exe -k netsvcs
39.P00 - 正在运行的服务 - Windows Firewall/Internet Connection Sharing (ICS),Microsoft Corporation,
相关文件:C:\WINDOWS\system32\ipnathlp.dll
内容:C:\WINDOWS\system32\svchost.exe -k netsvcs
40.P00 - 正在运行的服务 - Shell Hardware Detection,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\shsvcs.dll
内容:C:\WINDOWS\System32\svchost.exe -k netsvcs
41.P00 - 正在运行的服务 - Simple Mail Transfer Protocol (SMTP),Microsoft Corporation,
相关文件:C:\WINDOWS\system32\inetsrv\inetinfo.exe
内容:C:\WINDOWS\system32\inetsrv\inetinfo.exe
42.P00 - 正在运行的服务 - Print Spooler,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\spoolsv.exe
内容:C:\WINDOWS\system32\spoolsv.exe
43.P00 - 正在运行的服务 - System Restore Service,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\srsvc.dll
内容:C:\WINDOWS\system32\svchost.exe -k netsvcs
44.P00 - 正在运行的服务 - SSDP Discovery Service,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\ssdpsrv.dll
内容:C:\WINDOWS\system32\svchost.exe -k LocalService
45.P00 - 正在运行的服务 - Windows Image Acquisition (WIA),Microsoft Corporation,
相关文件:C:\WINDOWS\system32\wiaservc.dll
内容:C:\WINDOWS\system32\svchost.exe -k imgsvc
46.P00 - 正在运行的服务 - Telephony,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\tapisrv.dll
内容:C:\WINDOWS\System32\svchost.exe -k netsvcs
47.P00 - 正在运行的服务 - Terminal Services,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\termsrv.dll
内容:C:\WINDOWS\System32\svchost -k DComLaunch
48.P00 - 正在运行的服务 - Themes,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\shsvcs.dll
内容:C:\WINDOWS\System32\svchost.exe -k netsvcs
49.P00 - 正在运行的服务 - Distributed Link Tracking Client,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\trkwks.dll
内容:C:\WINDOWS\system32\svchost.exe -k netsvcs
50.P00 - 正在运行的服务 - Windows User Mode Driver Framework,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\wdfmgr.exe
内容:C:\WINDOWS\system32\wdfmgr.exe
51.P00 - 正在运行的服务 - Windows Time,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\w32time.dll
内容:C:\WINDOWS\System32\svchost.exe -k netsvcs
52.P00 - 正在运行的服务 - World Wide Web Publishing,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\inetsrv\inetinfo.exe
内容:C:\WINDOWS\system32\inetsrv\inetinfo.exe
53.P00 - 正在运行的服务 - WebClient,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\webclnt.dll
内容:C:\WINDOWS\system32\svchost.exe -k LocalService
54.P00 - 正在运行的服务 - Windows Management Instrumentation,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\wbem\wmisvc.dll
内容:C:\WINDOWS\system32\svchost.exe -k netsvcs
55.P00 - 正在运行的服务 - Security Center,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\wscsvc.dll
内容:C:\WINDOWS\System32\svchost.exe -k netsvcs
ltjj - 2006-12-8 22:15:00
56.P00 - 正在运行的服务 - Automatic Updates,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\wuauserv.dll
内容:C:\WINDOWS\system32\svchost.exe -k netsvcs
57.P00 - 正在运行的服务 - Wireless Zero Configuration,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\wzcsvc.dll
内容:C:\WINDOWS\System32\svchost.exe -k netsvcs
58.R00 - IE首页 - http://www.baidu.com/,Unknow Owner,
内容:http://www.baidu.com/
59.R00 - IE自定义搜索引擎 - http://seek.yisou.com/srchcust.htm,Unknow Owner,
内容:http://seek.yisou.com/srchcust.htm
60.O02 - 浏览器辅助对象(BHO) - AcrobatReader AcroIEHlprObj,Adobe Systems Incorporated,
CLSID:{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
相关文件:D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
61.O02 - 浏览器辅助对象(BHO) - Yahoo!Photo,Yahoo! China,
CLSID:{33BBE430-0E42-4f12-B075-8D21ACB10DCB}
相关文件:C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll
62.O02 - 浏览器辅助对象(BHO) - 雅虎助手,Yahoo!,
CLSID:{406F94F0-504F-4a40-8DFD-58B0666ABEBD}
相关文件:C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
63.O02 - 浏览器辅助对象(BHO) - DragSearch BHO,yahoo! china,
CLSID:{62EED7C6-9F02-42f9-B634-98E2899E147B}
相关文件:C:\Program Files\Yahoo!\Assistant\Assist\YDragSearch.dll
64.O03 - IE工具条“链接”的标题 - 链接,Unknow Owner,
内容:链接
65.O03 - IE第三方工具条 - 雅虎助手,Yahoo!,
CLSID:{406F94F0-504F-4a40-8DFD-58B0666ABEBD}
相关文件:C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
内容:雅虎助手
66.O03 - IE第三方工具条 - 卡卡上网安全助手,Beijing Rising Technology Co., Ltd.,
CLSID:{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C}
相关文件:C:\WINDOWS\system32\KakaTool.dll
67.O04 - 公用自启动目录 - Adobe Reader Speed Launch,Unknow Owner,
相关文件:D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
68.O04 - 当前用户自启动目录 - QQ即时通讯软件,Tencent,
相关文件:D:\Tencent\QQ\QQ.exe
69.O04 - 自动运行项(Run) - 微软日语输入法,Microsoft,
相关文件:(文件不存在)(隐藏)(系统); "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
内容:; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
70.O04 - 自动运行项(Run) - 微软智能输入法2002A(动态),Microsoft Corporation,
相关文件:C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
内容:C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
71.O04 - 自动运行项(Run) - 微软智能输入法2002A(名称),Microsoft Corporation,
相关文件:C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
内容:C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
72.O04 - 自动运行项(Run) - 声卡管理优化软件,Avance Logic, Inc.,
相关文件:C:\WINDOWS\SOUNDMAN.EXE
内容:SOUNDMAN.EXE
73.O04 - 自动运行项(Run) - yassistse,Yahoo! China,
相关文件:C:\Program Files\Yahoo!\Assistant\yassistse.exe
内容:"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
74.O04 - 自动运行项(Run) - 虚拟光驱软件Deamon Tools,Unknow Owner,
相关文件:(文件不存在)(隐藏)(系统); "D:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
内容:; "D:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
75.O04 - 自动运行项(Run) - 输入法,Microsoft Corporation,
相关文件:C:\Program Files\Common Files\Microsoft Shared\IME\IMSC40A\IMSCMIG.EXE /Preload
内容:C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
76.O04 - 自动运行项(Run) - BigDog303,Vimicro,
相关文件:C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
内容:C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
77.O04 - 自动运行项(Run) - NVIDIA系列显卡的调节工具,NVIDIA Corporation,
相关文件:C:\WINDOWS\system32\nvcpl.dll
内容:RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
78.O04 - 自动运行项(Run) - NVIDIA显示卡NView向导,NVIDIA,
相关文件:C:\WINDOWS\system32\nwiz.exe /install
内容:nwiz.exe /install
79.O04 - 自动运行项(Run) - NVIDIA系列显卡媒体中心程序,NVIDIA Corporation,
相关文件:C:\WINDOWS\system32\nvmctray.dll
内容:RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
80.O04 - 自动运行项(Run) - RealOne Player免费版的驻留程序,RealNetworks, Inc.,
相关文件:C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
内容:"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
81.O04 - 自动运行项(Run) - RavTask,Beijing Rising Technology Co., Ltd.,
相关文件:D:\Program Files\Rising\Rav\RavTask.exe -system
内容:"D:\Program Files\Rising\Rav\RavTask.exe" -system
82.O04 - 自动运行项(Run) - 一款影音编码解码器软件。,Unknow Owner,
相关文件:D:\Program Files\Ringz Studio\Storm Codec\StormSet.exe /S /opti
内容:"D:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
83.O04 - 自动运行项(Run) - Windows多种输入技术的支持程序,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\ctfmon.exe
内容:C:\WINDOWS\system32\ctfmon.exe
84.O04 - 自动运行项(RunOnce) - KKDelay,Beijing Rising Technology Co., Ltd.,
相关文件:D:\Program Files\Rising\RunOnce.exe
内容:D:\Program Files\Rising\RunOnce.exe
85.O08 - IE右键菜单 - &使用迅雷下载,Unknow Owner,
相关文件:D:\Program Files\Thunder\Program\geturl.htm
86.O08 - IE右键菜单 - &使用迅雷下载全部链接,Unknow Owner,
相关文件:D:\Program Files\Thunder\Program\GetAllUrl.htm
87.O08 - IE右键菜单 - 上传到QQ网络硬盘,Unknow Owner,
相关文件:D:\Tencent\QQ\AddToNetDisk.htm
88.O08 - IE右键菜单 - 导出到 Microsoft Office Excel(&X),Microsoft Corporation,
相关文件:D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE /3000
89.O08 - IE右键菜单 - 添加到QQ自定义面板,Unknow Owner,
相关文件:D:\Tencent\QQ\AddPanel.htm
90.O08 - IE右键菜单 - 添加到QQ表情,Unknow Owner,
相关文件:D:\Tencent\QQ\AddEmotion.htm
91.O08 - IE右键菜单 - 用QQ彩信发送该图片,Unknow Owner,
相关文件:D:\Tencent\QQ\SendMMS.htm
92.O09 - IE菜单项和工具栏按钮 - 启动迅雷5,Thunder Networking Technologies,LTD,
相关文件:D:\Program Files\Thunder\Thunder.exe
93.O09 - IE工具栏按钮 - 浩方对战平台,上海浩方在线信息技术有限公司,
相关文件:D:\Program Files\浩方对战平台\GameClient.exe
94.O09 - IE菜单项和工具栏按钮 - 番茄花园,Unknow Owner,
网页路径:http://www.tomatolei.com
95.O09 - IE工具栏按钮 - 信息检索,Microsoft Corporation,
相关文件:D:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL
96.O09 - IE菜单项和工具栏按钮 - 腾讯QQ,TENCENT,
相关文件:D:\Tencent\QQ\QQ.exe
97.O09 - IE菜单项和工具栏按钮 - Windows Messenger,Microsoft Corporation,
相关文件:C:\Program Files\Messenger\msmsgs.exe
98.O16 - 下载的ActiveX插件 - 中国工商银行个人银行,Unknow Owner,
CLSID:{73E4740C-08EB-4133-896B-8D0A7C9EE3CD}
相关文件:C:\WINDOWS\Downloaded Program Files\InputControl.dll
网页路径:https://mybank.icbc.com.cn/icbc/perbank/AXSafeControls.cab
99.O17 - 本机网络设置 NameServer - 202.107.225.78 202.107.225.79,Unknow Owner,
内容:202.107.225.78 202.107.225.79
100.O18 - 网络协议过滤器 - OFFICE 相关,Microsoft Corporation,
CLSID:{807553E5-5146-11D5-A672-00B0D022E945}
相关文件:C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
101.O18 - 网络协议处理器 - OFFICE 相关,Microsoft Corporation,
CLSID:{32505114-5902-49B2-880A-1F7738E5A384}
相关文件:C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
102.O20 - 程序错误缺省调试器 - vsjitdebugger.exe,Microsoft Corporation,
相关文件:C:\WINDOWS\system32\vsjitdebugger.exe -p %ld -e %ld
内容:"C:\WINDOWS\system32\vsjitdebugger.exe" -p %ld -e %ld
103.O21 - 自启动项SSODL - 管理托盘图标对象的程序,Microsoft Corporation,
CLSID:{35CEC8A3-2BE6-11D2-8773-92E220524153}
相关文件:C:\WINDOWS\system32\stobject.dll
内容:{35CEC8A3-2BE6-11D2-8773-92E220524153}
104.O21 - 自启动项SSODL - WebSecurity,Unknow Owner,
CLSID:{3DD78ACF-0745-4532-94F8-A574457E1A81}
相关文件:C:\WINDOWS\system32\PvSec.dll
内容:{3DD78ACF-0745-4532-94F8-A574457E1A81}
105.O21 - 自启动项SSODL - CLink,Unknow Owner,
CLSID:{FC055E7D-8144-4706-8586-2F1C49FCDD2A}
相关文件:C:\WINDOWS\system32\reporter.dll
内容:{FC055E7D-8144-4706-8586-2F1C49FCDD2A}
106.O25 - http协议缺省启动程序 - "D:\Tencent\TT\TTraveler.exe" "%1",腾讯公司,
相关文件:D:\Tencent\TT\TTraveler.exe "%1"
内容:"D:\Tencent\TT\TTraveler.exe" "%1"
107.O25 - ftp协议缺省启动程序 - "D:\Tencent\TT\TTraveler.exe" "%1",腾讯公司,
相关文件:D:\Tencent\TT\TTraveler.exe "%1"
内容:"D:\Tencent\TT\TTraveler.exe" "%1"
108.O25 - https协议缺省启动程序 - "D:\Tencent\TT\TTraveler.exe" "%1",腾讯公司,
相关文件:D:\Tencent\TT\TTraveler.exe "%1"
内容:"D:\Tencent\TT\TTraveler.exe" "%1"
109.O25 - htmlfile协议缺省启动程序 - "D:\Tencent\TT\TTraveler.exe" "%1",腾讯公司,
相关文件:D:\Tencent\TT\TTraveler.exe "%1"
内容:"D:\Tencent\TT\TTraveler.exe" "%1"
110.O27 - 文件执行挂钩 - Media Filter,Microsoft Corporation,
CLSID:{B876D045-E0B1-4E79-9359-0B1BF00813EA}
相关文件:C:\WINDOWS\system32\filter.dll
内容:Media Filter
111.O31 - 浏览栏区对象 - 每日提示,Microsoft Corporation,
CLSID:{4D5C8C25-D075-11d0-B416-00C04FB90376}
相关文件:C:\WINDOWS\system32\shdocvw.dll
112.O31 - 浏览栏区对象 - 雅虎订阅(&Y),Yahoo! China,
CLSID:{19CE93DE-8334-42C6-B2CA-BFE3DF5196A3}
相关文件:C:\Program Files\Yahoo!\Assistant\Assist\yrss.dll
红夜鬼1 - 2006-12-8 22:28:00
请下载SREng2(最新版) ,使用“智能扫描”,按下“扫描”按钮进行扫描,
扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告
日志文件内容复制-粘贴上来,,日志一次粘不完,分次粘完,请不要修改。
下载地址
http://www.kztechs.com/sreng/sreng2.zip
ltjj - 2006-12-10 11:48:00
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<SoundMan><SOUNDMAN.EXE> [(Verified)Avance Logic, Inc.]
<yassistse><"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"> [Yahoo! China]
<DAEMON Tools><; "D:\Program Files\DAEMON Tools\daemon.exe" -lang 1033> [(Verified)DT Soft Ltd.]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<BigDog303><C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)> [N/A]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
<nwiz><nwiz.exe /install> [N/A]
<NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit> [NVIDIA Corporation]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<RavTask><"D:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<StormCodec_Helper><"D:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> [N/A]
<PWRISOVM.EXE><D:\Program Files\PowerISO\PWRISOVM.EXE> [PowerISO Computing, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<WebSecurity><C:\WINDOWS\system32\PvSec.dll> []
<NetWork><C:\WINDOWS\system32\reporter.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{78BF3960-61F0-4F4E-825D-3554FA61E847}><C:\WINDOWS\system32\wmpkn.dll> [N/A]
==================================
启动文件夹
[Adobe Reader Speed Launch]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk --> D:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [Adobe Systems Incorporated]><N>
[腾讯QQ]
<C:\Documents and Settings\linte\「开始」菜单\程序\启动\腾讯QQ.lnk --> D:\Tencent\QQ\QQ.exe [TENCENT]><N>
ltjj - 2006-12-10 11:49:00
服务
[Human Interface Device Access / HidServ]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Machine Debug Manager / MDM]
<"C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"><Microsoft Corporation>
[NVIDIA Display Driver Service / NVSvc]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Remote Access Connection Management / Remote Access Connection Management]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\Program Files\Messenger\msnhost.dll><N/A>
[Rising Process Communication Center / RsCCenter]
<"D:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon]
<"D:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
==================================
驱动程序
[Service for Avance AC97 Audio (WDM) / ALCXWDM]
<system32\drivers\ALCXWDM.SYS><Avance Logic, Inc.>
[BaseTDI / BaseTDI]
<\??\C:\WINDOWS\system32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
[ExpScaner / ExpScaner]
<\??\D:\Program Files\Rising\Rav\ExpScan.sys><>
[hdfs / hdfs]
<\??\C:\WINDOWS\system32\drivers\hdfs.sys><N/A>
[hijibaih / hijibaih]
<\SystemRoot\system32\drivers\hijibaih.sys><中国互联网络信息中心(CNNIC)>
[HookCont / HookCont]
<\??\D:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg]
<\??\D:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
<\??\D:\Program Files\Rising\Rav\HookSys.sys><Rising>
[kmsinput / kmsinput]
<\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[LanPort / LanPort]
<\??\C:\WINDOWS\system32\drivers\LanPort.sys><N/A>
[lhzeenoi / lhzeenoi]
<\SystemRoot\System32\DRIVERS\lhzeenoi.sys><N/A>
[MEMSCAN / MEMSCAN]
<\??\D:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[npkcrypt / npkcrypt]
<\??\D:\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[parcls / parcls]
<\??\C:\WINDOWS\system32\drivers\parcls.sys><N/A>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsNTGDI / RsNTGDI]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS]
<\??\D:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[SCDEmu / SCDEmu]
<C:\WINDOWS\SYSTEM32\DRIVERS\SCDEmu.SYS><PowerISO Computing, Inc.>
[Secdrv / Secdrv]
<system32\DRIVERS\secdrv.sys><N/A>
[sptd / sptd]
<\SystemRoot\System32\Drivers\sptd.sys><N/A>
==================================
浏览器加载项
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Yahoo!Photo]
{33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll, Yahoo! China>
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[DragSearch BHO]
{62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, yahoo! china>
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <D:\Program Files\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[浩方对战平台]
{0A155D3C-68E2-4215-A47A-E800A446447A} <D:\Program Files\浩方对战平台\GameClient.exe, 上海浩方在线信息技术有限公司>
[番茄花园]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.tomatolei.com, N/A>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Tencent\QQ\QQ.EXE, TENCENT>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, >
[ActiveMovieControl Object]
{05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[MMCPlayer Class]
{05C1004E-2596-48E5-8E26-39362985EEB9} <C:\WINDOWS\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[PowerPlr Control]
{2354A44B-3CEB-4829-9940-545B03103538} <C:\WINDOWS\DOWNLO~1\PowerPlr.ocx, 创智数码科技股份有限公司>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Yahoo!Photo]
{33BBE430-0E42-4F12-B075-8D21ACB10DCB} <C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll, Yahoo! China>
ltjj - 2006-12-10 11:49:00
[雅虎助手]
{406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\AliEdit.dll, www.alipay.com>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Yahoo!Live]
{57421194-58FB-49AE-9B4F-FD48869B9AD4} <C:\Program Files\Yahoo!\Assistant\yaLive.dll, yahoo! china>
[DragSearch BHO]
{62EED7C6-9F02-42F9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, yahoo! china>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, >
[MediaComm Class]
{7670648D-461B-42AF-BDFE-46D26AF5EFF2} <D:\Program Files\Thunder\Components\InMedia\MediaAddin09.dll, Thunder Networking Technologies,LTD>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Program Files\Thunder\ComDlls\XunLeiBHO_004.dll, Thunder Networking Technologies,LTD>
[AxSubmitControl Class]
{8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} <C:\WINDOWS\DOWNLO~1\SUBMIT~1.DLL, >
[photo_uploader Control]
{A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <C:\WINDOWS\DOWNLO~1\PHOTO_~1.OCX, N/A>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[卡卡上网安全助手]
{AFF6E516-CBE5-4F8A-9C2F-38A68013E766} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[BDHlprObj Class]
{CA92B524-BC8A-4610-BD2C-6BD3E28155D0} <C:\WINDOWS\DOWNLO~1\BDHelper.dll, >
[AUDIO__MP3 Moniker Class]
{CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
{CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[assist]
{FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} <C:\Program Files\Yahoo!\Assistant\Assist\yassist.dll, Yahoo! China>
[&使用迅雷下载]
<D:\Program Files\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<D:\Program Files\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
<D:\Tencent\QQ\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<D:\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Tencent\QQ\SendMMS.htm, N/A>
ltjj - 2006-12-10 11:53:00
==================================
正在运行的进程
[PID: 548][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 616][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 640][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 684][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 696][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 848][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 908][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 984][D:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 1004][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\program files\messenger\msnhost.dll] [N/A, N/A]
[PID: 1088][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1188][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1200][D:\Program Files\Rising\Rav\Ravmond.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 39]
[D:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
[D:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[D:\Program Files\Rising\Rav\rfwctrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[D:\Program Files\Rising\Rav\RsPPsys.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[D:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[D:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\Program Files\Rising\Rav\RsLog.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[D:\Program Files\Rising\Rav\HOOKSYS.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
[D:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[D:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
[D:\Program Files\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[D:\Program Files\Rising\Rav\regmon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[D:\Program Files\Rising\Rav\HookWeb.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[D:\Program Files\Rising\Rav\MemMon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
[D:\Program Files\Rising\Rav\expscan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[D:\Program Files\Rising\Rav\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[D:\Program Files\Rising\Rav\HookCont.dll] [Rising, 19, 0, 0, 0]
[D:\Program Files\Rising\Rav\SpamEng.dll] [N/A, 18, 0, 0, 6]
[D:\Program Files\Rising\Rav\engine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
[D:\Program Files\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[D:\Program Files\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[D:\Program Files\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[D:\Program Files\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 25]
[D:\Program Files\Rising\Rav\ExtFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 22]
[D:\Program Files\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[D:\Program Files\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
[D:\Program Files\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[D:\Program Files\Rising\Rav\Unpacker.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
[D:\Program Files\Rising\Rav\ScanPack.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
[D:\Program Files\Rising\Rav\RsVM.dll] [N/A, 19, 0, 0, 8]
[D:\Program Files\Rising\Rav\ScanNet.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[D:\Program Files\Rising\Rav\ExtOLE.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[D:\Program Files\Rising\Rav\Uscript.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[D:\Program Files\Rising\Rav\Uroutine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
[PID: 1340][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1616][D:\Program Files\Rising\Rav\RavStub.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
[D:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1772][C:\WINDOWS\system32\inetsrv\inetinfo.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1792][C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe] [Microsoft Corporation, 7.00.9466]
[PID: 1868][C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe] [Microsoft Corporation, 2005.090.1399.00]
[PID: 1932][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.9689]
[C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.10.9689]
[PID: 1984][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2036][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 2148][C:\WINDOWS\SOUNDMAN.EXE] [Avance Logic, Inc., 5.0.10]
[PID: 2240][C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe] [Yahoo! China, 3, 0, 2, 1003]
[C:\PROGRA~1\Yahoo!\Assistant\shell\yAsMenu.dll] [Yahoo! China, 3, 0, 0, 1001]
[C:\PROGRA~1\Yahoo!\Assistant\shell\yAssecblk.dll] [Yahoo! China, 3, 0, 4, 1006]
[C:\PROGRA~1\Yahoo!\Assistant\shell\yIEAngel.dll] [Yahoo! China, 3, 0, 1, 1001]
[C:\PROGRA~1\Yahoo!\Assistant\shell\yMenuInfo.dll] [Yahoo! China, 3, 0, 0, 1000]
ltjj - 2006-12-10 11:53:00
[PID: 2280][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2484][C:\WINDOWS\VM303_STI.EXE] [Vimicro, 4, 3, 625, 61]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\WINDOWS\system32\VM303Prp.Ax] [Vimicro, 4.3. 625.61]
[PID: 2988][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3536]
[PID: 3028][D:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[D:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[D:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[PID: 3132][D:\Program Files\PowerISO\PWRISOVM.EXE] [PowerISO Computing, Inc., 3, 5, 0, 0]
[PID: 3144][D:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
[D:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 29]
[D:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
[D:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[D:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[D:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[D:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 3260][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3384][D:\Tencent\QQ\QQ.exe] [TENCENT, 0, 0, 0, 0]
[D:\Tencent\QQ\QQBaseClassInDll.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\QQHelperDll.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\BasicCtrlDll.dll] [Tencent, 5, 0, 200, 370]
[D:\Tencent\QQ\QQAPI.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[D:\Tencent\QQ\LoginCtrl.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\npkcntc.dll] [INCA Internet Co., Ltd., 2006, 6, 27, 1]
[D:\Tencent\QQ\npkpdb.dll] [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[D:\Tencent\QQ\QQRes.dll] [tencent, 1, 0, 0, 1]
[D:\Tencent\QQ\QQMainFrame.dll] [N/A, N/A]
[D:\Tencent\QQ\CQQApplication.dll] [N/A, N/A]
[D:\Tencent\QQ\NewSkin.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\HostingMgr.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\CameraDll.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\MailSummary.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\QQSpace.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[D:\Tencent\QQ\QQGroupMng.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\GroupLive.dll] [N/A, N/A]
[D:\Tencent\QQ\QQSysMsgMng.dll] [N/A, N/A]
[D:\Tencent\QQ\UserDefinedHead.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\QQPlugin.dll] [N/A, N/A]
[D:\Tencent\QQ\QQConfigPlugin.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\QRingMng.dll] [N/A, N/A]
[D:\Tencent\QQ\PhoneAPI.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[D:\Tencent\QQ\VPortal.dll] [, 1, 0, 0, 4]
[D:\Tencent\QQ\LongConnection.dll] [tencent, 5, 0, 200, 160]
[D:\Tencent\QQ\QQPet.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\QQAvatar.dll] [N/A, N/A]
[D:\Tencent\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[D:\Tencent\QQ\BQQApplication.dll] [N/A, N/A]
[D:\Tencent\QQ\QQAllInOne.dll] [N/A, N/A]
[D:\Tencent\QQ\SCCore.dll] [TENCENT, 2, 0, 0, 1]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[D:\Tencent\QQ\CommercesMng.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
[D:\Tencent\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 240]
[D:\Tencent\QQ\QQSceneMng.dll] [N/A, N/A]
[D:\Tencent\QQ\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 1, 1, 11]
[PID: 3508][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\PvSec.dll] [, 5, 1, 100, 2500]
[C:\WINDOWS\system32\wmpkn.dll] [N/A, N/A]
[C:\WINDOWS\system32\reporter.dll] [N/A, N/A]
[C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.10.9689]
[C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.10.9689]
[C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.10.9689]
[C:\WINDOWS\system32\nvshell.dll] [N/A, N/A]
[D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.7.2006011200]
[C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll] [Yahoo! China, 3, 0, 4, 1006]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll] [Yahoo!, 2, 1, 9, 1049]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] [yahoo! china, 3, 0, 1, 1001]
[PID: 3540][D:\Tencent\QQ\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[D:\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 2956][D:\Tencent\TT\TTraveler.exe] [腾讯公司, 3.1.0.261]
[D:\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll] [腾讯公司, 1, 1, 0, 5]
[D:\Tencent\TT\Plugins\TWeather\TWeather.dll] [, 1, 0, 0, 3]
[D:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[D:\Tencent\TT\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 4]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[PID: 4040][D:\Tencent\TT\TCPlus.exe] [腾讯公司, 1, 0, 0, 5]
[D:\Tencent\TT\QQDownload.dll] [Tencent Technology (Shenzhen) Company Limited, 1, 0, 101, 28]
[D:\Tencent\TT\TNProxy.dll] [Tencent Technology(Shenzhen) Company Limited, 2, 1, 101, 60]
[PID: 3100][E:\TDdownload\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
cchccx - 2006-12-10 16:11:00
超级兔子,,
360安全卫士
红夜鬼1 - 2006-12-10 19:34:00
hijibaih / hijibaih]
<\SystemRoot\system32\drivers\hijibaih.sys
运行(双击)SRENG2,点“启动项目,服务,点“驱动程序”
勾选“隐藏微软服务”选中病毒服务
hijibaih / hijibaih]
,选择“删除服务”
点“设置”选择“否”
重启按F8进入安全模式下
显示隐藏文件
删除:
<\SystemRoot\system32\drivers\hijibaih.sys
山川一龙 - 2006-12-10 21:40:00
高手
ltjj - 2006-12-11 12:58:00
高手在帮忙看看吧 我照做了卡卡扫描出来还是有,就是那个WADWX插件,还有WEBSECURITY和NETWORK
1
© 2000 - 2026 Rising Corp. Ltd.