瑞星卡卡安全论坛
photosynthesis - 2006-12-15 12:26:00
我用的是瑞星在线杀毒服务,检测出这两个病毒,但是无法杀去,说是需要解压后杀出。
两个病毒的文件路径是
C:\Documents and Settings\TX\Local Settings\Temp\Setup_623.exe>>$TEMP\insshell.exe
Dropper.Rynima.e
C:\Documents and Settings\TX\Local Settings\Temp\Setup_623.exe>>$TEMP\InShell.exe
Trojan.Agent.yly
我在安全模式下,把temp名下所有文件全处删除,但是瑞星依然可以查出这两个病毒。真不知道怎么办了。。中毒状况是自动弹出网页,还有联网一段时间后会自动弹出警告窗口,说法是connection is reset by peer。 是不是中木马了? 愿意在线等。。本人实在是黔驴技穷走投无路了
photosynthesis - 2006-12-15 12:30:00
sreng日志如下。。我的电脑显示sreng是问号符号,也不知道怎么回事。于是我照着这个论坛里面一个人的sreng日志把重要的信息都自己添了一下。但愿能顺利解决。
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<MsnMsgr><; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
<ibmmessages><; C:\Program Files\IBM\Messages By IBM\ibmmessages.exe> [IBM]
<Super Rabbit IEPro><D:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD> [Super Rabbit Soft]
<Super Rabbit Start Button><D:\Program Files\Super Rabbit\MagicSet\SRSB.EXE /Load> [Super Rabbit Soft]
<Yahoo! Pager><"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet> [(Verified)Yahoo! Inc.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TPHOTKEY><; C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe> [N/A]
<EZEJMNAP><; C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe> [IBM Corp.]
<SoundMAXPnP><C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe> [Analog Devices, Inc.]
<SoundMAX><C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray> [Analog Devices, Inc.]
<ATIPTA><; C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe> [ATI Technologies, Inc.]
<UpdateManager><; "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r> [Sonic Solutions]
<QCWLICON><; C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE> [IBM Corp.]
<MSPY2002><C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC> [(Verified)N/A]
<DAEMON Tools><"e:\Program Files\DAEMON Tools\daemon.exe" -lang 1033> [(Verified)DT Soft Ltd.]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<HP Software Update><; D:\Program Files\HP\HP Software Update\HPWuSchd2.exe> [Hewlett-Packard Co.]
<IntelliPoint><"C:\Program Files\Microsoft IntelliPoint\point32.exe"> [Microsoft Corporation]
<RavTask><; "d:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
<ATICCC><; "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"> [N/A]
<QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.]
<iTunesHelper><; "C:\Program Files\iTunes\iTunesHelper.exe"> [(Verified)Apple Computer, Inc.]
<Desktop><"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Run> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<Super Rabbit SRCK><"D:\Program Files\Super Rabbit\MagicSet\srck.exe" /autokill:54> [Super Rabbit Soft]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\Media\svchost.exe,C:\WINDOWS\system32\userinit.exe,> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<PostBootReminder><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Corporation]
<CDBurn><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Corporation]
<WebCheck><%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Corporation]
<SysTray><C:\WINDOWS\system32\stobject.dll> [(Verified)Microsoft Corporation]
<UPnPMonitor><C:\WINDOWS\system32\upnpui.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
<WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
<WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
<WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
<WinlogonNotify: ScCertProp><wlnotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
<WinlogonNotify: Schedule><wlnotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
<WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
<WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
<WinlogonNotify: termsrv><wlnotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
<WinlogonNotify: wlballoon><wlnotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Corporation]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\WINDOWS\RESOUR~1\Themes\THINKT~1\IBMTHI~1.SCR> [Hua Software (website http://www.21hua.com)]
photosynthesis - 2006-12-15 12:33:00
=================================
启动文件夹
[腾讯QQ]
<C:\Documents and Settings\TX\「开始」菜单\程序\启动\腾讯QQ.lnk --> E:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><H>
==================================
服务
[ACU Configuration Service / ACS]
<C:\WINDOWS\system32\acs.exe><N/A>
[ASP.NET State Service / aspnet_state]
<C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart]
<C:\WINDOWS\system32\ati2sgag.exe><>
[Windows Install Helper / BKMARKS]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IXOOE.DLL,Export 1087><N/A>
[Bluetooth Service / btwdins]
<C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe><Broadcom Corporation>
[Network Engine / Hardware]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\fyrzz.dll><Microsoft Corporation>
[IBM Rapid Restore Ultra Service / IBM Rapid Restore Ultra Service]
<"C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe"><>
[IBM PM Service / IBMPMSVC]
<C:\WINDOWS\system32\ibmpmsvc.exe><N/A>
[InstallDriver Table Manager / IDriverT]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[iPod Service / iPod Service]
<"D:\Program Files\iPod\bin\iPodService.exe"><Apple Computer, Inc.>
[Microsoft Send / Microsoft Send]
<><N/A>
[Pml Driver HPZ12 / Pml Driver HPZ12]
<C:\WINDOWS\system32\HPZipm12.exe><HP>
[IBM PSA Access Driver Control / PsaSrv]
<><N/A>
[QCONSVC / QCONSVC]
<System32\QCONSVC.EXE><N/A>
[Rising Process Communication Center / RsCCenter]
<"d:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"d:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[System Event Notification / SENS]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\xiafxdob.dll><N/A>
[Volume Shadddddow Copyerq / Service332245]
<><N/A>
[Symantec Network Drivers Service / SNDSrvc]
<"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[SoundMAX Agent Service / SoundMAX Agent Service (default)]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[IBM HDD APS Logging Service / TPHDEXLGSVC]
<System32\TPHDEXLG.EXE><N/A>
[IBM KCU Service / TpKmpSVC]
<C:\WINDOWS\system32\TpKmpSVC.exe><N/A>
[VisionService / VisionService]
<C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\vision\VISVER.DLL,Service><Microsoft Corporation>
[Protector Suite Virtual Token / vtserver]
<"C:\Program Files\Common Files\Virtual Token\vtserver.exe"><UPEK Inc.>
[Windows Firewall / Windows Firewall]
<C:\WINDOWS\system32\iexp1ore.exe><N/A>
[Windows NT Service32 / Windows NT Service32]
<"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Start><Microsoft Corporation>
[Windows Media Connect (WMC) / WmcCds]
<c:\program files\windows media connect\mswmccds.exe><Microsoft Corporation>
photosynthesis - 2006-12-15 12:38:00
浏览器加载项
[IEMonitor Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\WINDOWS\system32\IESHEL~1.DLL, >
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <D:\PROGRA~1\SUPERR~1\MagicSet\haokanbar.dll, Xiang Feng Technology>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <E:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <E:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <E:\PROGRA~1\FlashGet\fgiebar.dll, Amaze Soft>
[实用搜索工具条2.0]
{03465FF5-00AE-411a-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <D:\PROGRA~1\SUPERR~1\MagicSet\haokanbar.dll, Xiang Feng Technology>
[YInstStarter Class]
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} <C:\Program Files\Yahoo!\Common\yinsthelper.dll, N/A>
[MSN Photo Upload Tool]
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[System Requirements Lab Class]
{BE833F39-1E0C-468C-BA70-25AAEE55775E} <C:\WINDOWS\Downloaded Program Files\sysreqlab.dll, Husdawg, LLC>
[QuickTime Object]
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <C:\Program Files\QuickTime\QTPlugin.ocx, Apple Computer, Inc.>
[实用搜索工具条2.0]
{03465FF5-00AE-411A-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[ActiveMovieControl Object]
{05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[IEMonitor Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\WINDOWS\system32\IESHEL~1.DLL, >
[MyLoader Class]
{09BA1AA9-CAD4-4C14-BDE6-922DFF5F6F38} <C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEMDATA\OcP9HE1MzU_2002.dll, >
[Shockwave ActiveX Control]
{166B1BCA-3F9C-11CF-8075-444553540000} <%SystemRoot%\system32\Macromed\Director\SwDir.dll, N/A>
[PowerList Control]
{20C2C286-BDE8-441B-B73D-AFA22D914DA5} <D:\PROGRA~1\PPStream\POWERL~1.OCX, PPStream.com>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[XML DOM Document]
{2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\system32\msxml3.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[Tabular Data Control]
{333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[Info cache]
{385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, N/A>
[MallObj Class]
{3B30B48F-617D-4F73-A20F-D3D54357F103} <C:\WINDOWS\system32\mallgoo2.dll, 上海奥德易海科技>
[QuickTime Object]
{4063BE15-3B08-470D-A0D5-B37161CFFD69} <C:\Program Files\QuickTime\QTPlugin.ocx, Apple Computer, Inc.>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <D:\PROGRA~1\SUPERR~1\MagicSet\haokanbar.dll, Xiang Feng Technology>
[XML Document]
{48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, N/A>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <d:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_003.dll, Thunder Networking Technologies,LTD>
[]
{4F07F79F-087F-42CF-8B36-7A88D06088E9} <C:\PROGRA~1\MSNMES~1\MSGSC8~1.DLL, Microsoft Corporation>
[MSN Photo Upload Tool]
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <E:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Yahoo! IE Services Button]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} <C:\Program Files\Yahoo!\Common\yiesrvc.dll, N/A>
[PowerPlayer Control]
{5EC7C511-CD0F-42E6-830C-1BD9882F3458} <D:\PROGRA~1\PPStream\POWERP~1.DLL, PPStream Inc.>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Microsoft 外壳 UI 帮助程序]
{64AB4BB7-111E-11D1-8F79-00C04FC2FBE1} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[实用搜索]
{6CFD436C-7AAD-4E50-992F-C0C87A94CAD2} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <D:\PROGRA~1\SUPERR~1\MagicSet\haokanbar.dll, Xiang Feng Technology>
[MediaComm Class]
{7670648D-461B-42AF-BDFE-46D26AF5EFF2} <d:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin07.dll, Thunder Networking Technologies,LTD>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[XML DOM Document 4.0]
{88D969C0-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml4.dll, Microsoft Corporation>
[XML HTTP 4.0]
{88D969C5-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml4.dll, Microsoft Corporation>
[Skype Detection Object]
{9E385F0A-0BA2-430C-96AA-4399C5E40F6C} <, N/A>
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[RMGetLicense Class]
{A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[]
{B69003B3-C55E-4B48-836C-BC5946FC3B28} <C:\Program Files\Messenger\msgsc.dll, Microsoft Corporation>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[OWSClientMiscApis Class]
{BDEADE3F-C265-11D0-BCED-00A0C90AB50F} <C:\PROGRA~1\MICROS~2\Office10\OWSCLT.DLL, Microsoft Corporation>
[OWSBrowserUI Class]
{BDEADE43-C265-11D0-BCED-00A0C90AB50F} <C:\PROGRA~1\MICROS~2\Office10\OWSCLT.DLL, Microsoft Corporation>
[System Requirements Lab Class]
{BE833F39-1E0C-468C-BA70-25AAEE55775E} <C:\WINDOWS\Downloaded Program Files\sysreqlab.dll, Husdawg, LLC>
[browser Class]
{C86488AF-13D5-4FEF-9DDF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\Office\USERDATA\ZsaDBu16F5_2002.dll, Microsoft Corporation>
[E:\Program Files\Tencent\QQ\QQPlayerSvr.exe]
{CD108273-D434-43E6-AA90-1469F97EB398} <, N/A>
[VIDEO__X_MS_ASF Moniker Class]
{CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Windows Live Sign-in Control]
{D2517915-48CE-4286-970F-921E881B8C5C} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[iTunesDetector Class]
{D719897A-B07A-4C0C-AEA9-9B663A28DFCB} <C:\Program Files\iTunes\ITDetector.ocx, Apple Computer, Inc.>
[MessengerChecker Class]
{DA4F543C-C8A9-4E88-9A79-548CBB46F18F} <C:\Program Files\Yahoo!\Messenger\YPagerChecker.dll, Yahoo! Inc.>
[QuickTimeCheck Class]
{DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21} <C:\Program Files\QuickTime\QTSystem\QuickTimeCheck.ocx, Apple Computer, Inc.>
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <E:\PROGRA~1\FlashGet\fgiebar.dll, Amaze Soft>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\DOWNLO~1\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[Messenger Class]
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <, N/A>
[XML HTTP Request]
{ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\system32\msxml3.dll, N/A>
[VqqSpeedDlProxy Class]
{F138084D-84D7-48CD-BEA8-04772457516E} <d:\WINDOWS\vqqsdl.dll, Tencent Technology (Shenzhen) Company Limited>
[XML DOM Document 3.0]
{F5078F32-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\system32\msxml3.dll, N/A>
[XML HTTP 3.0]
{F5078F35-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\system32\msxml3.dll, N/A>
[XML DOM Document]
{F6D90F11-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\system32\msxml3.dll, N/A>
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\system32\msxml3.dll, N/A>
[&使用迅雷下载]
<d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
<E:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用网际快车下载]
<E:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<E:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
<E:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<E:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<E:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
photosynthesis - 2006-12-15 12:39:00
正在运行的进程
[PID: 972][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1020][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1044][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1092][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1104][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\pwdmon.dll] [N/A, N/A]
[PID: 1252][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1304][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1364][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1448][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1496][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1344][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1292][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2000][C:\WINDOWS\system32\notepad.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 468][C:\Program Files\Microsoft Office\Office10\WINWORD.EXE] [Microsoft Corporation, 10.0.2627]
[d:\Program Files\Rising\Rav\RsPlugIn.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[d:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 24]
[C:\WINDOWS\system32\btsendto_office.dll] [Broadcom Corporation, 3.0.1.917]
[C:\WINDOWS\system32\btosif.dll] [Broadcom Corporation, 3.0.1.917]
[C:\WINDOWS\system32\btsendto.dll] [Broadcom Corporation, 3.0.1.917]
[C:\WINDOWS\system32\WidcommSdk.dll] [Broadcom Corporation, 3.0.1.917]
[C:\WINDOWS\system32\wbtapi.dll] [Broadcom Corporation, 3.0.1.917]
[PID: 1896][C:\Program Files\Microsoft Office\Office10\WINWORD.EXE] [Microsoft Corporation, 10.0.2627]
[d:\Program Files\Rising\Rav\RsPlugIn.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[d:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 24]
[C:\WINDOWS\system32\btsendto_office.dll] [Broadcom Corporation, 3.0.1.917]
[C:\WINDOWS\system32\btosif.dll] [Broadcom Corporation, 3.0.1.917]
[C:\WINDOWS\system32\btsendto.dll] [Broadcom Corporation, 3.0.1.917]
[C:\WINDOWS\system32\WidcommSdk.dll] [Broadcom Corporation, 3.0.1.917]
[C:\WINDOWS\system32\wbtapi.dll] [Broadcom Corporation, 3.0.1.917]
[C:\WINDOWS\system32\CSH.dll] [Blue Sky Software Corporation, 2.00.039]
[d:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 1580][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\iTunes\iTunesMiniPlayer.dll] [Apple Computer, Inc., 7.0.2.16]
[C:\Program Files\iTunes\iTunesMiniPlayer.Resources\zh_CN.lproj\iTunesMiniPlayerLocalized.dll] [Apple Computer, Inc., 7.0.2.1]
[C:\Program Files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll] [Apple Computer, Inc., 7.0.2.16]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[C:\WINDOWS\system32\Macromed\Common\SwSupport.dll] [Macromedia, Inc., 10.1r11]
[PID: 1416][C:\DOCUME~1\TX\LOCALS~1\Temp\Rar$EX06.500\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\DOCUME~1\TX\LOCALS~1\Temp\Rar$EX06.500\SREng\Plugins\SRECXTMG.SRE] [Smallfrogs Studio, 1, 5, 0, 55]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock ???
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS ??
127.0.0.1 localhost
==================================
photosynthesis - 2006-12-15 12:41:00
驱动程序那一块不知道怎么回事贴不出来。。我想可能上面的信息够用了吧?如果实在要驱动程序,我再想想办法。。就是为了下个雷曼。。就变成这样子了。。哎
photosynthesis - 2006-12-15 12:52:00
我是在线等。。。下决心今天要把这个问题解决了
photosynthesis - 2006-12-15 12:54:00
如果这个情况已经出现过了,麻烦哪位好心人指条路,带我去看那张帖子,谢谢了
高歌猛进 - 2006-12-15 13:21:00
参考:http://forum.ikaka.com/topic.asp?board=28&artid=5216854
如扫描工具无法运行,请重新下载安装,将后缀改为.com,运行后贴日志上来
photosynthesis - 2006-12-15 14:14:00
我上面的日志不可以吗?
高歌猛进 - 2006-12-15 14:52:00
一定要真实反映运行状态的日志
photosynthesis - 2006-12-15 14:53:00
不知道怎么,serng很多字都是问号
photosynthesis - 2006-12-15 15:08:00
能不能告诉我其他的软件也可以生成扫描日志报告的,这个sreng中文全都变成了问号
不言放弃 - 2006-12-15 15:33:00
【回复“photosynthesis”的帖子】
修复如下自启动项:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Desktop><"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Run> []
===========
开始--运行
输入regedit
确定
进入注册表
修改
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\Media\svchost.exe,C:\WINDOWS\system32\userinit.exe,> [N/A]
为
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
或直接使用SRE编辑修复
修复方法如上
============
修复如下浏览器加载项:
[实用搜索工具条2.0]
{03465FF5-00AE-411a-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[System Requirements Lab Class]
{BE833F39-1E0C-468C-BA70-25AAEE55775E} <C:\WINDOWS\Downloaded Program Files\sysreqlab.dll, Husdawg, LLC>
[实用搜索工具条2.0]
{03465FF5-00AE-411A-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[Info cache]
{385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, N/A>
[MallObj Class]
{3B30B48F-617D-4F73-A20F-D3D54357F103} <C:\WINDOWS\system32\mallgoo2.dll, 上海奥德易海科技>
[实用搜索]
{6CFD436C-7AAD-4E50-992F-C0C87A94CAD2} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[System Requirements Lab Class]
{BE833F39-1E0C-468C-BA70-25AAEE55775E} <C:\WINDOWS\Downloaded Program Files\sysreqlab.dll, Husdawg, LLC>
===========
修复如下服务项:
[Windows Install Helper / BKMARKS]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IXOOE.DLL,Export 1087><N/A>
[Network Engine / Hardware]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\fyrzz.dll><Microsoft Corporation>
[Microsoft Send / Microsoft Send]
<><N/A>
[System Event Notification / SENS]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\xiafxdob.dll><N/A>
[Volume Shadddddow Copyerq / Service332245]
<><N/A>
[VisionService / VisionService]
<C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\vision\VISVER.DLL,Service><Microsoft Corporation>
[Windows Firewall / Windows Firewall]
<C:\WINDOWS\system32\iexp1ore.exe><N/A>
[Windows NT Service32 / Windows NT Service32]
<"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Start><Microsoft Corporation>
==========
开始--运行
输入regedit
确定
进入注册表
依次展开
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Services](X代表1,2,3,4....)
找到后删除如下文件夹:
BKMARKS
Hardware
Microsoft Send
SENS
Service332245
VisionService
Windows Firewall
Windows NT Service32
依次展开
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Enum\Root\](X代表1,2,3,4....)
删除如下文件夹:
LEGACY_BKMARKS
LEGACY_Hardware
LEGACY_Microsoft Send
LEGACY_SENS
LEGACY_Service332245
LEGACY_VisionService
LEGACY_Windows Firewall
LEGACY_Windows NT Service32
===========
卸载
C:\Program Files\superutilbar\
C:\Program Files\vision\
C:\WINDOWS\system32\NTService32.dll
C:\WINDOWS\Media\svchost.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\
C:\WINDOWS\system32\mallgoo2.dll
C:\WINDOWS\Downloaded Program Files\sysreqlab.dll
C:\WINDOWS\SYSTEM32\WBEM\IXOOE.DLL
C:\WINDOWS\system32\fyrzz.dll
C:\WINDOWS\System32\xiafxdob.dll
C:\WINDOWS\system32\iexp1ore.exe
以及C:\Documents and Settings\TX\Local Settings\Temp\下的所有文件及文件夹
另外
C:\WINDOWS\system32\pwdmon.dll已经插入系统核心进程
请用KILLBOX这个工具的延迟删除功能删除C:\WINDOWS\system32\pwdmon.dll
==========
“System Repair Engineer”的使用操作参考:
http://forum.ikaka.com/topic.asp?board=67&artid=8125594
另外
日志不全
缺少驱动项
请导出全部日志
photosynthesis - 2006-12-15 16:20:00
sreng都是问号。。。贴不出来,怎么办?
photosynthesis - 2006-12-15 16:41:00
Drivers
[000070a0 / 000070a0]
<\SystemRoot\system32\drivers\000070a0.SYS><N/A>
[abp480n5 / abp480n5]
<\SystemRoot\system32\DRIVERS\ABP480N5.SYS><Microsoft Corporation>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc]
<system32\drivers\ac97intc.sys><Intel Corporation>
[adpu160m / adpu160m]
<\SystemRoot\system32\DRIVERS\adpu160m.sys><Microsoft Corporation>
[aeaudio / aeaudio]
<system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[AEGIS Protocol (IEEE 802.1x) v3.2.0.3 / AegisP]
<system32\DRIVERS\AegisP.sys><Meetinghouse Data Communications>
[Aha154x / Aha154x]
<\SystemRoot\system32\DRIVERS\aha154x.sys><Microsoft Corporation>
[aic78u2 / aic78u2]
<\SystemRoot\system32\DRIVERS\aic78u2.sys><Microsoft Corporation>
[aic78xx / aic78xx]
<\SystemRoot\system32\DRIVERS\aic78xx.sys><Microsoft Corporation>
[AliIde / AliIde]
<\SystemRoot\system32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD AGP Bus Filter Driver / amdagp]
<\SystemRoot\system32\DRIVERS\amdagp.sys><Advanced Micro Devices, Inc.>
[ANC / ANC]
<System32\drivers\ANC.SYS><IBM Corp.>
[Api Drivers / Api]
<\??\C:\WINDOWS\system32\Drivers\Api.sys><N/A>
[Dual-band Wi-Fi Wireless Mini PCI Adapter / AR5211]
<system32\DRIVERS\ar5211.sys><Atheros Communications, Inc.>
[asc / asc]
<\SystemRoot\system32\DRIVERS\asc.sys><Advanced System Products, Inc.>
[asc3350p / asc3350p]
<\SystemRoot\system32\DRIVERS\asc3350p.sys><Microsoft Corporation>
[asc3550 / asc3550]
<\SystemRoot\system32\DRIVERS\asc3550.sys><Advanced System Products, Inc.>
[ati2mtag / ati2mtag]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Broadcom NetXtreme Gigabit Ethernet / b57w2k]
<system32\DRIVERS\b57xp32.sys><Broadcom Corporation>
[BaseTDI / BaseTDI]
<\??\C:\WINDOWS\system32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
[蓝牙音频设备 / btaudio]
<system32\drivers\btaudio.sys><Broadcom Corporation>
[蓝牙虚拟通信驱动程序 / BTDriver]
<system32\DRIVERS\btport.sys><Broadcom Corporation>
[Bluetooth Protocol Stack / BTKRNL]
<\SystemRoot\system32\drivers\btkrnl.sys><Broadcom Corporation>
[蓝牙局域网接入服务器 / BTWDNDIS]
<system32\DRIVERS\btwdndis.sys><Broadcom Corporation>
[WIDCOMM USB Bluetooth Driver / BTWUSB]
<System32\Drivers\btwusb.sys><Broadcom Corporation>
[cd20xrnt / cd20xrnt]
<\SystemRoot\system32\DRIVERS\cd20xrnt.sys><Microsoft Corporation>
[cdawdm / cdawdm]
<system32\DRIVERS\CDAWDM.sys><N/A>
[cdhafbjc / cdhafbjc]
<\SystemRoot\system32\drivers\cdhafbjc.sys><中国互联网络信息中心(CNNIC)>
[CmdIde / CmdIde]
<\SystemRoot\system32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[dac2w2k / dac2w2k]
<\SystemRoot\system32\DRIVERS\dac2w2k.sys><Mylex Corporation>
[dpti2o / dpti2o]
<\SystemRoot\system32\DRIVERS\dpti2o.sys><Microsoft Corporation>
[drvmcdb / drvmcdb]
<\SystemRoot\system32\drivers\drvmcdb.sys><Sonic Solutions>
[drvnddm / drvnddm]
<system32\drivers\drvnddm.sys><Sonic Solutions>
[dtscsi / dtscsi]
<\SystemRoot\System32\Drivers\dtscsi.sys><N/A>
[Intel(R) PRO Adapter Driver / E100B]
<system32\DRIVERS\e100b325.sys><Intel Corporation>
[EagleNT / EagleNT]
<\??\C:\WINDOWS\system32\drivers\EagleNT.sys><N/A>
[IBM Access Support / EGATHDRV]
<\??\C:\WINDOWS\SYSTEM32\EGATHDRV.SYS><IBM Corporation>
[ExpScaner / ExpScaner]
<\??\d:\Program Files\Rising\Rav\ExpScan.sys><>
[GEAR CDRom Filter / GEARAspiWDM]
<SYSTEM32\DRIVERS\GEARAspiWDM.sys><GEAR Software Inc.>
[HookCont / HookCont]
<\??\d:\Program Files\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
<\??\d:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
<\??\d:\Program Files\Rising\Rav\HookSys.sys><Rising>
[IEEE-1284.4 Driver HPZid412 / HPZid412]
<system32\DRIVERS\HPZid412.sys><HP>
[Print Class Driver for IEEE-1284.4 HPZipr12 / HPZipr12]
<system32\DRIVERS\HPZipr12.sys><HP>
[USB to IEEE-1284.4 Translation Driver HPZius12 / HPZius12]
<system32\DRIVERS\HPZius12.sys><HP>
[HSFHWICH / HSFHWICH]
<system32\DRIVERS\HSFHWICH.sys><Conexant Systems, Inc.>
[HSF_DP / HSF_DP]
<system32\DRIVERS\HSF_DP.sys><Conexant Systems, Inc.>
[ibmfilter / ibmfilter]
<\??\C:\WINDOWS\system32\drivers\ibmfilter.sys><IBM>
[IBMPMDRV / IBMPMDRV]
<system32\DRIVERS\ibmpmdrv.sys><IBM Corp.>
[IBMTPCHK / IBMTPCHK]
<System32\drivers\IBMBLDID.SYS><N/A>
[ini910u / ini910u]
<\SystemRoot\system32\DRIVERS\ini910u.sys><Microsoft Corporation>
[IsDrv120 / IsDrv120]
<2 - 系统找不到指定的文件。
><N/A>
[mdmxsdk / mdmxsdk]
<system32\DRIVERS\mdmxsdk.sys><Conexant>
[MEMSCAN / MEMSCAN]
<\??\d:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mraid35x / mraid35x]
<\SystemRoot\system32\DRIVERS\mraid35x.sys><American Megatrends Inc.>
[msprotect / msprotect]
<system32\DRIVERS\msprotect.sys><Windows (R) 2000 DDK provider>
[msqmx / msqmx]
<\??\C:\WINDOWS\system32\drivers\msqmx.sys><Microsoft Corporation>
[npkcrypt / npkcrypt]
<\??\E:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkycryp / npkycryp]
photosynthesis - 2006-12-15 16:42:00
<\??\E:\Program Files\Tencent\QQ\npkycryp.sys><N/A>
[NSC Infrared Device Driver / NSCIRDA]
<system32\DRIVERS\nscirda.sys><National Semiconductor Corporation>
[nv / nv]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[PCDRNDISUIO Usermode I/O Protocol / PcdrNdisuio]
<system32\DRIVERS\pcdrndisuio.sys><Windows (R) 2000 DDK provider>
[Padus ASPI Shell / Pfc]
<system32\drivers\pfc.sys><Padus, Inc.>
[PMEM / PMEM]
<\??\C:\WINDOWS\SYSTEM32\DRIVERS\PMEMNT.SYS><Microsoft Corporation>
[IBM PSA Access Driver / psadd]
<\??\C:\WINDOWS\system32\Drivers\psadd.sys><IBM Corporation>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[QCNDISIF / QCNDISIF]
<System32\drivers\qcndisif.SYS><IBM Corporation.>
[ql1080 / ql1080]
<\SystemRoot\system32\DRIVERS\ql1080.sys><QLogic Corporation>
[Ql10wnt / Ql10wnt]
<\SystemRoot\system32\DRIVERS\ql10wnt.sys><Microsoft Corporation>
[ql12160 / ql12160]
<\SystemRoot\system32\DRIVERS\ql12160.sys><QLogic Corporation>
[ql1280 / ql1280]
<\SystemRoot\system32\DRIVERS\ql1280.sys><QLogic Corporation>
[QuakeDRV / QuakeDRV]
<\SystemRoot\system32\DRIVERS\quakedrv.sys><N/A>
[Secdrv / Secdrv]
<system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[ShockMgr / ShockMgr]
<C:\WINDOWS\SYSTEM32\DRIVERS\ShockMgr.SYS><IBM Corporation>
[Shockprf / Shockprf]
<C:\WINDOWS\SYSTEM32\DRIVERS\Shockprf.SYS><IBM Corporation>
[SIS AGP Bus Filter / sisagp]
<\SystemRoot\system32\DRIVERS\sisagp.sys><Silicon Integrated Systems Corporation>
[Smapint / Smapint]
<System32\drivers\Smapint.sys><Microsoft Corporation>
[SMI helper driver / SmiHlp]
<\??\C:\Program Files\IBM fingerprint software\smihlp.sys><UPEK Inc.>
[smwdm / smwdm]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1]
<system32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[Sparrow / Sparrow]
<\SystemRoot\system32\DRIVERS\sparrow.sys><Adaptec, Inc.>
[sptd / sptd]
<\SystemRoot\System32\Drivers\sptd.sys><N/A>
[sscdbhk5 / sscdbhk5]
<system32\drivers\sscdbhk5.sys><Sonic Solutions>
[ssrtln / ssrtln]
<system32\drivers\ssrtln.sys><Sonic Solutions>
[symc810 / symc810]
<\SystemRoot\system32\DRIVERS\symc810.sys><Symbios Logic Inc.>
[symc8xx / symc8xx]
<\SystemRoot\system32\DRIVERS\symc8xx.sys><LSI Logic>
[SYMDNS / SYMDNS]
<\SystemRoot\System32\Drivers\SYMDNS.SYS><Symantec Corporation>
[SymEvent / SymEvent]
<\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[SYMFW / SYMFW]
<\SystemRoot\System32\Drivers\SYMFW.SYS><Symantec Corporation>
[SYMIDS / SYMIDS]
<\SystemRoot\System32\Drivers\SYMIDS.SYS><Symantec Corporation>
[SYMIDSCO / SYMIDSCO]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\IDS-DI~1\20060922.092\symidsco.sys><N/A>
[SYMNDIS / SYMNDIS]
<\SystemRoot\System32\Drivers\SYMNDIS.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV]
<\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI]
<\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[sym_hi / sym_hi]
<\SystemRoot\system32\DRIVERS\sym_hi.sys><LSI Logic>
[sym_u3 / sym_u3]
<\SystemRoot\system32\DRIVERS\sym_u3.sys><LSI Logic>
[Synaptics TouchPad Driver / SynTP]
<system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[TCP/IP Protocol Driver / Tcpip]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[TC USB Kernel Driver / TcUsb]
<System32\Drivers\tcusb.sys><UPEK Inc.>
[TDSMAPI / TDSMAPI]
<System32\drivers\TDSMAPI.SYS><N/A>
[tfsnboio / tfsnboio]
<system32\dla\tfsnboio.sys><Sonic Solutions>
[tfsncofs / tfsncofs]
<system32\dla\tfsncofs.sys><Sonic Solutions>
[tfsndrct / tfsndrct]
<system32\dla\tfsndrct.sys><Sonic Solutions>
[tfsndres / tfsndres]
<system32\dla\tfsndres.sys><Sonic Solutions>
[tfsnifs / tfsnifs]
<system32\dla\tfsnifs.sys><Sonic Solutions>
[tfsnopio / tfsnopio]
<system32\dla\tfsnopio.sys><Sonic Solutions>
[tfsnpool / tfsnpool]
<system32\dla\tfsnpool.sys><Sonic Solutions>
[tfsnudf / tfsnudf]
<system32\dla\tfsnudf.sys><Sonic Solutions>
[tfsnudfa / tfsnudfa]
<system32\dla\tfsnudfa.sys><Sonic Solutions>
[TosIde / TosIde]
<\SystemRoot\system32\DRIVERS\toside.sys><Microsoft Corporation>
[TPDiskPM / TPDiskPM]
<C:\WINDOWS\SYSTEM32\DRIVERS\TPDiskPM.SYS><IBM Corporation>
[TPHKDRV / TPHKDRV]
<C:\WINDOWS\SYSTEM32\DRIVERS\TPHKDRV.SYS><IBM Corporation>
[TPInput / TPInput]
<System32\DRIVERS\TPInput.sys><IBM Corporation>
[NSC Integrated Trusted Platform Module 1.1 / TPM11]
<system32\DRIVERS\nsctpm11.sys><National Semiconductor Corp.>
[TPPWRIF / TPPWRIF]
<System32\drivers\Tppwrif.sys><N/A>
[TSMAPIP / TSMAPIP]
<System32\drivers\TSMAPIP.SYS><N/A>
[ultra / ultra]
<\SystemRoot\system32\DRIVERS\ultra.sys><Promise Technology, Inc.>
[ViaIde / ViaIde]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[Sony Ericsson W600 driver (WDM) / w600bus]
<system32\DRIVERS\w600bus.sys><MCCI>
[Sony Ericsson W600 USB WMC Modem Filter / w600mdfl]
<system32\DRIVERS\w600mdfl.sys><MCCI>
[Sony Ericsson W600 USB WMC Modem Drivers / w600mdm]
<system32\DRIVERS\w600mdm.sys><MCCI>
不言放弃 - 2006-12-15 18:36:00
【回复“photosynthesis”的帖子】
修复如下自启动项:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Desktop><"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Run> []
===========
开始--运行
输入regedit
确定
进入注册表
修改
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\Media\svchost.exe,C:\WINDOWS\system32\userinit.exe,> [N/A]
为
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
或直接使用SRE编辑修复
修复方法如上
============
修复如下浏览器加载项:
[实用搜索工具条2.0]
{03465FF5-00AE-411a-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[System Requirements Lab Class]
{BE833F39-1E0C-468C-BA70-25AAEE55775E} <C:\WINDOWS\Downloaded Program Files\sysreqlab.dll, Husdawg, LLC>
[实用搜索工具条2.0]
{03465FF5-00AE-411A-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[Info cache]
{385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, N/A>
[MallObj Class]
{3B30B48F-617D-4F73-A20F-D3D54357F103} <C:\WINDOWS\system32\mallgoo2.dll, 上海奥德易海科技>
[实用搜索]
{6CFD436C-7AAD-4E50-992F-C0C87A94CAD2} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[System Requirements Lab Class]
{BE833F39-1E0C-468C-BA70-25AAEE55775E} <C:\WINDOWS\Downloaded Program Files\sysreqlab.dll, Husdawg, LLC>
===========
修复如下服务项:
[Windows Install Helper / BKMARKS]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IXOOE.DLL,Export 1087><N/A>
[Network Engine / Hardware]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\fyrzz.dll><Microsoft Corporation>
[Microsoft Send / Microsoft Send]
<><N/A>
[System Event Notification / SENS]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\xiafxdob.dll><N/A>
[Volume Shadddddow Copyerq / Service332245]
<><N/A>
[VisionService / VisionService]
<C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\vision\VISVER.DLL,Service><Microsoft Corporation>
[Windows Firewall / Windows Firewall]
<C:\WINDOWS\system32\iexp1ore.exe><N/A>
[Windows NT Service32 / Windows NT Service32]
<"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Start><Microsoft Corporation>
==========
修复如下驱动项
[000070a0 / 000070a0]
<\SystemRoot\system32\drivers\000070a0.SYS><N/A>
========
开始--运行
输入regedit
确定
进入注册表
依次展开
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Services](X代表1,2,3,4....)
找到后删除如下文件夹:
BKMARKS
Hardware
Microsoft Send
SENS
Service332245
VisionService
Windows Firewall
Windows NT Service32
000070a0
依次展开
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Enum\Root\](X代表1,2,3,4....)
删除如下文件夹:
LEGACY_BKMARKS
LEGACY_Hardware
LEGACY_Microsoft Send
LEGACY_SENS
LEGACY_Service332245
LEGACY_VisionService
LEGACY_Windows Firewall
LEGACY_Windows NT Service32
LEGACY_000070a0
===========
卸载
C:\Program Files\superutilbar\
C:\Program Files\vision\
C:\WINDOWS\system32\NTService32.dll
C:\WINDOWS\Media\svchost.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\
C:\WINDOWS\system32\mallgoo2.dll
C:\WINDOWS\Downloaded Program Files\sysreqlab.dll
C:\WINDOWS\SYSTEM32\WBEM\IXOOE.DLL
C:\WINDOWS\system32\fyrzz.dll
C:\WINDOWS\System32\xiafxdob.dll
C:\WINDOWS\system32\iexp1ore.exe
以及C:\Documents and Settings\TX\Local Settings\Temp\下的所有文件及文件夹
另外
C:\WINDOWS\system32\pwdmon.dll已经插入系统核心进程
请用KILLBOX这个工具的延迟删除功能删除C:\WINDOWS\system32\pwdmon.dll
==========
“System Repair Engineer”的使用操作参考:
http://forum.ikaka.com/topic.asp?board=67&artid=8125594
photosynthesis - 2006-12-16 4:11:00
2006-12-15,03:59:12
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<MsnMsgr><; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
<ibmmessages><; C:\Program Files\IBM\Messages By IBM\ibmmessages.exe> [IBM]
<Super Rabbit IEPro><D:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD> [Super Rabbit Soft]
<Super Rabbit Start Button><D:\Program Files\Super Rabbit\MagicSet\SRSB.EXE /Load> [Super Rabbit Soft]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TPHOTKEY><; C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe> [N/A]
<EZEJMNAP><; C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe> [IBM Corp.]
<SoundMAXPnP><C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe> [Analog Devices, Inc.]
<SoundMAX><C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray> [Analog Devices, Inc.]
<ATIPTA><; C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe> [ATI Technologies, Inc.]
<UpdateManager><; "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r> [Sonic Solutions]
<QCWLICON><; C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE> [IBM Corp.]
<MSPY2002><C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC> [(Verified)N/A]
<DAEMON Tools><"e:\Program Files\DAEMON Tools\daemon.exe" -lang 1033> [(Verified)DT Soft Ltd.]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<HP Software Update><; D:\Program Files\HP\HP Software Update\HPWuSchd2.exe> [Hewlett-Packard Co.]
<IntelliPoint><"C:\Program Files\Microsoft IntelliPoint\point32.exe"> [Microsoft Corporation]
<RavTask><; "d:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
<ATICCC><; "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"> [N/A]
<QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.]
<iTunesHelper><; "C:\Program Files\iTunes\iTunesHelper.exe"> [(Verified)Apple Computer, Inc.]
<Desktop><"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Run> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\WINDOWS\RESOUR~1\Themes\THINKT~1\IBMTHI~1.SCR> [Hua Software (website http://www.21hua.com)]
==================================
启动文件夹
[腾讯QQ]
<C:\Documents and Settings\TX\「开始」菜单\程序\启动\腾讯QQ.lnk --> E:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><H>
==================================
服务
[ACU Configuration Service / ACS]
<C:\WINDOWS\system32\acs.exe><N/A>
[ASP.NET State Service / aspnet_state]
<C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart]
<C:\WINDOWS\system32\ati2sgag.exe><>
[Bluetooth Service / btwdins]
<C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe><Broadcom Corporation>
[IBM Rapid Restore Ultra Service / IBM Rapid Restore Ultra Service]
<"C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe"><>
[IBM PM Service / IBMPMSVC]
<C:\WINDOWS\system32\ibmpmsvc.exe><N/A>
[InstallDriver Table Manager / IDriverT]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[iPod Service / iPod Service]
<"D:\Program Files\iPod\bin\iPodService.exe"><Apple Computer, Inc.>
[Pml Driver HPZ12 / Pml Driver HPZ12]
<C:\WINDOWS\system32\HPZipm12.exe><HP>
[IBM PSA Access Driver Control / PsaSrv]
<><N/A>
[QCONSVC / QCONSVC]
<System32\QCONSVC.EXE><N/A>
[Rising Process Communication Center / RsCCenter]
<"d:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"d:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Symantec Network Drivers Service / SNDSrvc]
<"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[SoundMAX Agent Service / SoundMAX Agent Service (default)]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[IBM HDD APS Logging Service / TPHDEXLGSVC]
<System32\TPHDEXLG.EXE><N/A>
[IBM KCU Service / TpKmpSVC]
<C:\WINDOWS\system32\TpKmpSVC.exe><N/A>
[VisionService / VisionService]
<C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\vision\VISVER.DLL,Service><Microsoft Corporation>
[Protector Suite Virtual Token / vtserver]
<"C:\Program Files\Common Files\Virtual Token\vtserver.exe"><UPEK Inc.>
[Windows NT Service32 / Windows NT Service32]
<"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Start><Microsoft Corporation>
[Windows Media Connect (WMC) / WmcCds]
<c:\program files\windows media connect\mswmccds.exe><Microsoft Corporation>
[Windows Media Connect (WMC) 帮助程序 / WmcCdsLs]
<C:\Program Files\Windows Media Connect\mswmcls.exe><Microsoft Corporation>
photosynthesis - 2006-12-16 4:15:00
驱动程序
[000070a0 / 000070a0]
<\SystemRoot\system32\drivers\000070a0.SYS><N/A>
[abp480n5 / abp480n5]
<\SystemRoot\system32\DRIVERS\ABP480N5.SYS><Microsoft Corporation>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc]
<system32\drivers\ac97intc.sys><Intel Corporation>
[adpu160m / adpu160m]
<\SystemRoot\system32\DRIVERS\adpu160m.sys><Microsoft Corporation>
[aeaudio / aeaudio]
<system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[AEGIS Protocol (IEEE 802.1x) v3.2.0.3 / AegisP]
<system32\DRIVERS\AegisP.sys><Meetinghouse Data Communications>
[Aha154x / Aha154x]
<\SystemRoot\system32\DRIVERS\aha154x.sys><Microsoft Corporation>
[aic78u2 / aic78u2]
<\SystemRoot\system32\DRIVERS\aic78u2.sys><Microsoft Corporation>
[aic78xx / aic78xx]
<\SystemRoot\system32\DRIVERS\aic78xx.sys><Microsoft Corporation>
[AliIde / AliIde]
<\SystemRoot\system32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD AGP Bus Filter Driver / amdagp]
<\SystemRoot\system32\DRIVERS\amdagp.sys><Advanced Micro Devices, Inc.>
[ANC / ANC]
<System32\drivers\ANC.SYS><IBM Corp.>
[Api Drivers / Api]
<\??\C:\WINDOWS\system32\Drivers\Api.sys><N/A>
[Dual-band Wi-Fi Wireless Mini PCI Adapter / AR5211]
<system32\DRIVERS\ar5211.sys><Atheros Communications, Inc.>
[asc / asc]
<\SystemRoot\system32\DRIVERS\asc.sys><Advanced System Products, Inc.>
[asc3350p / asc3350p]
<\SystemRoot\system32\DRIVERS\asc3350p.sys><Microsoft Corporation>
[asc3550 / asc3550]
<\SystemRoot\system32\DRIVERS\asc3550.sys><Advanced System Products, Inc.>
[ati2mtag / ati2mtag]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Broadcom NetXtreme Gigabit Ethernet / b57w2k]
<system32\DRIVERS\b57xp32.sys><Broadcom Corporation>
[BaseTDI / BaseTDI]
<\??\C:\WINDOWS\system32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
[蓝牙音频设备 / btaudio]
<system32\drivers\btaudio.sys><Broadcom Corporation>
[蓝牙虚拟通信驱动程序 / BTDriver]
<system32\DRIVERS\btport.sys><Broadcom Corporation>
[Bluetooth Protocol Stack / BTKRNL]
<\SystemRoot\system32\drivers\btkrnl.sys><Broadcom Corporation>
[蓝牙局域网接入服务器 / BTWDNDIS]
<system32\DRIVERS\btwdndis.sys><Broadcom Corporation>
[WIDCOMM USB Bluetooth Driver / BTWUSB]
<System32\Drivers\btwusb.sys><Broadcom Corporation>
[cd20xrnt / cd20xrnt]
<\SystemRoot\system32\DRIVERS\cd20xrnt.sys><Microsoft Corporation>
[cdawdm / cdawdm]
<system32\DRIVERS\CDAWDM.sys><N/A>
[cdhafbjc / cdhafbjc]
<\SystemRoot\system32\drivers\cdhafbjc.sys><中国互联网络信息中心(CNNIC)>
[CmdIde / CmdIde]
<\SystemRoot\system32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[dac2w2k / dac2w2k]
<\SystemRoot\system32\DRIVERS\dac2w2k.sys><Mylex Corporation>
[dpti2o / dpti2o]
<\SystemRoot\system32\DRIVERS\dpti2o.sys><Microsoft Corporation>
[drvmcdb / drvmcdb]
<\SystemRoot\system32\drivers\drvmcdb.sys><Sonic Solutions>
[drvnddm / drvnddm]
<system32\drivers\drvnddm.sys><Sonic Solutions>
[dtscsi / dtscsi]
<\SystemRoot\System32\Drivers\dtscsi.sys><N/A>
[Intel(R) PRO Adapter Driver / E100B]
<system32\DRIVERS\e100b325.sys><Intel Corporation>
[EagleNT / EagleNT]
<\??\C:\WINDOWS\system32\drivers\EagleNT.sys><N/A>
[IBM Access Support / EGATHDRV]
<\??\C:\WINDOWS\SYSTEM32\EGATHDRV.SYS><IBM Corporation>
[ExpScaner / ExpScaner]
<\??\d:\Program Files\Rising\Rav\ExpScan.sys><>
[GEAR CDRom Filter / GEARAspiWDM]
<SYSTEM32\DRIVERS\GEARAspiWDM.sys><GEAR Software Inc.>
[HookCont / HookCont]
<\??\d:\Program Files\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
<\??\d:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
<\??\d:\Program Files\Rising\Rav\HookSys.sys><Rising>
[IEEE-1284.4 Driver HPZid412 / HPZid412]
<system32\DRIVERS\HPZid412.sys><HP>
[Print Class Driver for IEEE-1284.4 HPZipr12 / HPZipr12]
<system32\DRIVERS\HPZipr12.sys><HP>
[USB to IEEE-1284.4 Translation Driver HPZius12 / HPZius12]
<system32\DRIVERS\HPZius12.sys><HP>
[HSFHWICH / HSFHWICH]
<system32\DRIVERS\HSFHWICH.sys><Conexant Systems, Inc.>
[HSF_DP / HSF_DP]
<system32\DRIVERS\HSF_DP.sys><Conexant Systems, Inc.>
[ibmfilter / ibmfilter]
<\??\C:\WINDOWS\system32\drivers\ibmfilter.sys><IBM>
[IBMPMDRV / IBMPMDRV]
<system32\DRIVERS\ibmpmdrv.sys><IBM Corp.>
[IBMTPCHK / IBMTPCHK]
<System32\drivers\IBMBLDID.SYS><N/A>
[ini910u / ini910u]
<\SystemRoot\system32\DRIVERS\ini910u.sys><Microsoft Corporation>
[mdmxsdk / mdmxsdk]
<system32\DRIVERS\mdmxsdk.sys><Conexant>
photosynthesis - 2006-12-16 4:16:00
[MEMSCAN / MEMSCAN]
<\??\d:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mraid35x / mraid35x]
<\SystemRoot\system32\DRIVERS\mraid35x.sys><American Megatrends Inc.>
[msprotect / msprotect]
<system32\DRIVERS\msprotect.sys><Windows (R) 2000 DDK provider>
[msqmx / msqmx]
<\??\C:\WINDOWS\system32\drivers\msqmx.sys><Microsoft Corporation>
[npkcrypt / npkcrypt]
<\??\E:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkycryp / npkycryp]
<\??\E:\Program Files\Tencent\QQ\npkycryp.sys><N/A>
[NSC Infrared Device Driver / NSCIRDA]
<system32\DRIVERS\nscirda.sys><National Semiconductor Corporation>
[nv / nv]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[PCDRNDISUIO Usermode I/O Protocol / PcdrNdisuio]
<system32\DRIVERS\pcdrndisuio.sys><Windows (R) 2000 DDK provider>
[Padus ASPI Shell / Pfc]
<system32\drivers\pfc.sys><Padus, Inc.>
[PMEM / PMEM]
<\??\C:\WINDOWS\SYSTEM32\DRIVERS\PMEMNT.SYS><Microsoft Corporation>
[IBM PSA Access Driver / psadd]
<\??\C:\WINDOWS\system32\Drivers\psadd.sys><IBM Corporation>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[QCNDISIF / QCNDISIF]
<System32\drivers\qcndisif.SYS><IBM Corporation.>
[ql1080 / ql1080]
<\SystemRoot\system32\DRIVERS\ql1080.sys><QLogic Corporation>
[Ql10wnt / Ql10wnt]
<\SystemRoot\system32\DRIVERS\ql10wnt.sys><Microsoft Corporation>
[ql12160 / ql12160]
<\SystemRoot\system32\DRIVERS\ql12160.sys><QLogic Corporation>
[ql1280 / ql1280]
<\SystemRoot\system32\DRIVERS\ql1280.sys><QLogic Corporation>
[QuakeDRV / QuakeDRV]
<\SystemRoot\system32\DRIVERS\quakedrv.sys><N/A>
[Secdrv / Secdrv]
<system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[ShockMgr / ShockMgr]
<C:\WINDOWS\SYSTEM32\DRIVERS\ShockMgr.SYS><IBM Corporation>
[Shockprf / Shockprf]
<C:\WINDOWS\SYSTEM32\DRIVERS\Shockprf.SYS><IBM Corporation>
[SIS AGP Bus Filter / sisagp]
<\SystemRoot\system32\DRIVERS\sisagp.sys><Silicon Integrated Systems Corporation>
[Smapint / Smapint]
<System32\drivers\Smapint.sys><Microsoft Corporation>
[SMI helper driver / SmiHlp]
<\??\C:\Program Files\IBM fingerprint software\smihlp.sys><UPEK Inc.>
[smwdm / smwdm]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1]
<system32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[Sparrow / Sparrow]
<\SystemRoot\system32\DRIVERS\sparrow.sys><Adaptec, Inc.>
[sptd / sptd]
<\SystemRoot\System32\Drivers\sptd.sys><N/A>
[sscdbhk5 / sscdbhk5]
<system32\drivers\sscdbhk5.sys><Sonic Solutions>
[ssrtln / ssrtln]
<system32\drivers\ssrtln.sys><Sonic Solutions>
[symc810 / symc810]
<\SystemRoot\system32\DRIVERS\symc810.sys><Symbios Logic Inc.>
[symc8xx / symc8xx]
<\SystemRoot\system32\DRIVERS\symc8xx.sys><LSI Logic>
[SYMDNS / SYMDNS]
<\SystemRoot\System32\Drivers\SYMDNS.SYS><Symantec Corporation>
[SymEvent / SymEvent]
<\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[SYMFW / SYMFW]
<\SystemRoot\System32\Drivers\SYMFW.SYS><Symantec Corporation>
[SYMIDS / SYMIDS]
<\SystemRoot\System32\Drivers\SYMIDS.SYS><Symantec Corporation>
[SYMIDSCO / SYMIDSCO]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\IDS-DI~1\20060922.092\symidsco.sys><N/A>
[SYMNDIS / SYMNDIS]
<\SystemRoot\System32\Drivers\SYMNDIS.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV]
<\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI]
<\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[sym_hi / sym_hi]
<\SystemRoot\system32\DRIVERS\sym_hi.sys><LSI Logic>
[sym_u3 / sym_u3]
<\SystemRoot\system32\DRIVERS\sym_u3.sys><LSI Logic>
[Synaptics TouchPad Driver / SynTP]
<system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[TCP/IP Protocol Driver / Tcpip]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[TC USB Kernel Driver / TcUsb]
<System32\Drivers\tcusb.sys><UPEK Inc.>
[TDSMAPI / TDSMAPI]
<System32\drivers\TDSMAPI.SYS><N/A>
[tfsnboio / tfsnboio]
<system32\dla\tfsnboio.sys><Sonic Solutions>
[tfsncofs / tfsncofs]
<system32\dla\tfsncofs.sys><Sonic Solutions>
[tfsndrct / tfsndrct]
<system32\dla\tfsndrct.sys><Sonic Solutions>
[tfsndres / tfsndres]
<system32\dla\tfsndres.sys><Sonic Solutions>
[tfsnifs / tfsnifs]
<system32\dla\tfsnifs.sys><Sonic Solutions>
[tfsnopio / tfsnopio]
<system32\dla\tfsnopio.sys><Sonic Solutions>
[tfsnpool / tfsnpool]
<system32\dla\tfsnpool.sys><Sonic Solutions>
[tfsnudf / tfsnudf]
<system32\dla\tfsnudf.sys><Sonic Solutions>
[tfsnudfa / tfsnudfa]
<system32\dla\tfsnudfa.sys><Sonic Solutions>
[TosIde / TosIde]
<\SystemRoot\system32\DRIVERS\toside.sys><Microsoft Corporation>
[TPDiskPM / TPDiskPM]
<C:\WINDOWS\SYSTEM32\DRIVERS\TPDiskPM.SYS><IBM Corporation>
[TPHKDRV / TPHKDRV]
<C:\WINDOWS\SYSTEM32\DRIVERS\TPHKDRV.SYS><IBM Corporation>
[TPInput / TPInput]
<System32\DRIVERS\TPInput.sys><IBM Corporation>
[NSC Integrated Trusted Platform Module 1.1 / TPM11]
<system32\DRIVERS\nsctpm11.sys><National Semiconductor Corp.>
[TPPWRIF / TPPWRIF]
<System32\drivers\Tppwrif.sys><N/A>
[TSMAPIP / TSMAPIP]
<System32\drivers\TSMAPIP.SYS><N/A>
[ultra / ultra]
<\SystemRoot\system32\DRIVERS\ultra.sys><Promise Technology, Inc.>
[ViaIde / ViaIde]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[Sony Ericsson W600 driver (WDM) / w600bus]
<system32\DRIVERS\w600bus.sys><MCCI>
[Sony Ericsson W600 USB WMC Modem Filter / w600mdfl]
<system32\DRIVERS\w600mdfl.sys><MCCI>
[Sony Ericsson W600 USB WMC Modem Drivers / w600mdm]
<system32\DRIVERS\w600mdm.sys><MCCI>
[Sony Ericsson W600 USB WMC Device Management Drivers / w600mgmt]
<system32\DRIVERS\w600mgmt.sys><MCCI>
photosynthesis - 2006-12-16 4:16:00
浏览器加载项
[IEMonitor Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\WINDOWS\system32\IESHEL~1.DLL, >
[Vision]
{6671A431-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\vision\vision.dll, N/A>
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <D:\PROGRA~1\SUPERR~1\MagicSet\haokanbar.dll, Xiang Feng Technology>
[MMSAssistMenu]
{6671A433-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\vision\vision.dll, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <E:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <E:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <E:\PROGRA~1\FlashGet\fgiebar.dll, Amaze Soft>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <D:\PROGRA~1\SUPERR~1\MagicSet\haokanbar.dll, Xiang Feng Technology>
[YInstStarter Class]
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} <C:\Program Files\Yahoo!\Common\yinsthelper.dll, N/A>
[MSN Photo Upload Tool]
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[QuickTime Object]
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <C:\Program Files\QuickTime\QTPlugin.ocx, Apple Computer, Inc.>
[ActiveMovieControl Object]
{05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[IEMonitor Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\WINDOWS\system32\IESHEL~1.DLL, >
[MyLoader Class]
{09BA1AA9-CAD4-4C14-BDE6-922DFF5F6F38} <C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEMDATA\OcP9HE1MzU_2002.dll, >
[Shockwave ActiveX Control]
{166B1BCA-3F9C-11CF-8075-444553540000} <%SystemRoot%\system32\Macromed\Director\SwDir.dll, N/A>
[PowerList Control]
{20C2C286-BDE8-441B-B73D-AFA22D914DA5} <D:\PROGRA~1\PPStream\POWERL~1.OCX, PPStream.com>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[XML DOM Document]
{2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\system32\msxml3.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[Tabular Data Control]
{333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[IETag Factory]
{38481807-CA0E-42D2-BF39-B33AF135CC4D} <C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\IETAG.DLL, Microsoft Corporation>
[QuickTime Object]
{4063BE15-3B08-470D-A0D5-B37161CFFD69} <C:\Program Files\QuickTime\QTPlugin.ocx, Apple Computer, Inc.>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <D:\PROGRA~1\SUPERR~1\MagicSet\haokanbar.dll, Xiang Feng Technology>
[XML Document]
{48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, N/A>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <d:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_003.dll, Thunder Networking Technologies,LTD>
[]
{4F07F79F-087F-42CF-8B36-7A88D06088E9} <C:\PROGRA~1\MSNMES~1\MSGSC8~1.DLL, Microsoft Corporation>
[MSN Photo Upload Tool]
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <E:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Yahoo! IE Services Button]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} <C:\Program Files\Yahoo!\Common\yiesrvc.dll, N/A>
[PowerPlayer Control]
{5EC7C511-CD0F-42E6-830C-1BD9882F3458} <D:\PROGRA~1\PPStream\POWERP~1.DLL, PPStream Inc.>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Microsoft 外壳 UI 帮助程序]
{64AB4BB7-111E-11D1-8F79-00C04FC2FBE1} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Vision]
{6671A431-5C3D-463D-A7CF-5587F9B7E191} <C:\PROGRA~1\vision\vision.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <D:\PROGRA~1\SUPERR~1\MagicSet\haokanbar.dll, Xiang Feng Technology>
[MediaComm Class]
{7670648D-461B-42AF-BDFE-46D26AF5EFF2} <d:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin07.dll, Thunder Networking Technologies,LTD>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[XML DOM Document 4.0]
{88D969C0-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml4.dll, Microsoft Corporation>
[XML HTTP 4.0]
{88D969C5-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml4.dll, Microsoft Corporation>
[Skype Detection Object]
{9E385F0A-0BA2-430C-96AA-4399C5E40F6C} <, N/A>
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[RMGetLicense Class]
{A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[]
{B69003B3-C55E-4B48-836C-BC5946FC3B28} <C:\Program Files\Messenger\msgsc.dll, Microsoft Corporation>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[OWSClientMiscApis Class]
{BDEADE3F-C265-11D0-BCED-00A0C90AB50F} <C:\PROGRA~1\MICROS~2\Office10\OWSCLT.DLL, Microsoft Corporation>
[OWSBrowserUI Class]
{BDEADE43-C265-11D0-BCED-00A0C90AB50F} <C:\PROGRA~1\MICROS~2\Office10\OWSCLT.DLL, Microsoft Corporation>
[browser Class]
{C86488AF-13D5-4FEF-9DDF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\Office\USERDATA\ZsaDBu16F5_2002.dll, Microsoft Corporation>
[E:\Program Files\Tencent\QQ\QQPlayerSvr.exe]
{CD108273-D434-43E6-AA90-1469F97EB398} <, N/A>
[VIDEO__X_MS_ASF Moniker Class]
{CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Windows Live Sign-in Control]
{D2517915-48CE-4286-970F-921E881B8C5C} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[iTunesDetector Class]
{D719897A-B07A-4C0C-AEA9-9B663A28DFCB} <C:\Program Files\iTunes\ITDetector.ocx, Apple Computer, Inc.>
[MessengerChecker Class]
{DA4F543C-C8A9-4E88-9A79-548CBB46F18F} <C:\Program Files\Yahoo!\Messenger\YPagerChecker.dll, Yahoo! Inc.>
[QuickTimeCheck Class]
{DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21} <C:\Program Files\QuickTime\QTSystem\QuickTimeCheck.ocx, Apple Computer, Inc.>
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <E:\PROGRA~1\FlashGet\fgiebar.dll, Amaze Soft>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\DOWNLO~1\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[Messenger Class]
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <, N/A>
[XML HTTP Request]
{ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\system32\msxml3.dll, N/A>
[VqqSpeedDlProxy Class]
{F138084D-84D7-48CD-BEA8-04772457516E} <d:\WINDOWS\vqqsdl.dll, Tencent Technology (Shenzhen) Company Limited>
[XML DOM Document 3.0]
{F5078F32-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\system32\msxml3.dll, N/A>
[XML HTTP 3.0]
{F5078F35-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\system32\msxml3.dll, N/A>
[XML DOM Document]
{F6D90F11-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\system32\msxml3.dll, N/A>
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\system32\msxml3.dll, N/A>
[&使用迅雷下载]
<d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[>>彩信发送<<]
<res://C:\PROGRA~1\vision\vision.dll/mms.htm, N/A>
[上传到QQ网络硬盘]
<E:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用网际快车下载]
<E:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<E:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
<E:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<E:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<E:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
photosynthesis - 2006-12-16 4:17:00
正在运行的进程
[PID: 1052][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1100][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1128][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1176][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1188][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1368][C:\Program Files\Common Files\Virtual Token\vtserver.exe] [UPEK Inc., 4.5.5.1108]
[C:\Program Files\Common Files\Virtual Token\psutil.dll] [UPEK Inc., 4.5.5.1108]
[C:\Program Files\IBM fingerprint software\psfus.dll] [UPEK Inc., 4.5.5.1108]
[C:\Program Files\Common Files\Virtual Token\passport.dll] [UPEK Inc., 4.5.5.1108]
[C:\Program Files\Common Files\Virtual Token\DevTc.dll] [UPEK Inc., 4.5.5.1108]
[C:\Program Files\Common Files\Virtual Token\BTcVer.dll] [UPEK Inc., 4.5.5.1108]
[C:\Program Files\Common Files\Virtual Token\Remote.dll] [UPEK Inc., 4.5.5.1108]
[PID: 1388][C:\WINDOWS\system32\ibmpmsvc.exe] [N/A, N/A]
[PID: 1424][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4138]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2503]
[PID: 1436][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1504][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1544][d:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 1560][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1628][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1800][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1812][d:\Program Files\Rising\Rav\Ravmond.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 1, 33]
[d:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 19]
[d:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[d:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[d:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
[d:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[d:\Program Files\Rising\Rav\RsLog.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[d:\Program Files\Rising\Rav\HOOKSYS.dll] [Beijing Rising Technology Co., Ltd., 18, 1, 0, 11]
[d:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 30]
[d:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
[d:\Program Files\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
[d:\Program Files\Rising\Rav\regmon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[d:\Program Files\Rising\Rav\psapi.dll] [Microsoft Corporation, 4.00]
[d:\Program Files\Rising\Rav\HookWeb.dll] [rising, 18, 0, 0, 2]
[d:\Program Files\Rising\Rav\MemMon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
[d:\Program Files\Rising\Rav\expscan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[d:\Program Files\Rising\Rav\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[d:\Program Files\Rising\Rav\MailMon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[d:\Program Files\Rising\Rav\SpamEng.dll] [N/A, 18, 0, 0, 6]
[d:\Program Files\Rising\Rav\engine.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 30]
[d:\Program Files\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
[d:\Program Files\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
[d:\Program Files\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
[d:\Program Files\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 14]
[d:\Program Files\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 7]
[d:\Program Files\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 9]
[d:\Program Files\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 18]
[d:\Program Files\Rising\Rav\Unpacker.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[d:\Program Files\Rising\Rav\ScanNet.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[d:\Program Files\Rising\Rav\ExtOLE.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[PID: 376][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\bthcrp.dll] [Broadcom Corporation, 3.0.1.917]
[C:\WINDOWS\system32\WidcommSdk.dll] [Broadcom Corporation, 3.0.1.917]
[C:\WINDOWS\system32\wbtapi.dll] [Broadcom Corporation, 3.0.1.917]
[C:\WINDOWS\system32\hpz3l3xu.dll] [Hewlett-Packard Company, 60.051.645.00]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\hpzpp3xu.dll] [Hewlett-Packard Corporation, 60.051.645.00]
[PID: 552][d:\Program Files\Rising\Rav\RavStub.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 16]
[d:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[d:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 1740][C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe] [Broadcom Corporation, 3.0.1.917]
[PID: 1944][C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe] [, 4,1,0,4074]
[PID: 1984][C:\WINDOWS\system32\HPZipm12.exe] [HP, 9, 0, 0, 0]
[PID: 2012][C:\WINDOWS\System32\QCONSVC.EXE] [IBM Corp., 3, 7, 1, 0]
[PID: 616][C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe] [Symantec Corporation, 5.5.1.6]
[C:\WINDOWS\system32\SymNeti.DLL] [Symantec Corporation, 5.5.1.6]
[PID: 764][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] [Analog Devices, Inc., 3, 2, 6, 0]
[PID: 820][C:\WINDOWS\System32\TPHDEXLG.EXE] [IBM Corporation, 1.0.0.1]
[PID: 912][C:\WINDOWS\system32\TpKmpSVC.exe] [N/A, N/A]
[PID: 932][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 3636][C:\WINDOWS\system32\acs.exe] [N/A, N/A]
[C:\WINDOWS\system32\athcfg11.dll] [Atheros, 4.1.100.148]
[C:\WINDOWS\system32\athcfg11Res.dll] [Atheros Communications, Inc., 4.1.0.148]
[C:\PROGRA~1\ThinkPad\CONNEC~1\QcAthExt.dll] [N/A, N/A]
[C:\WINDOWS\system32\AegisE5.dll] [Meetinghouse Data Communications, 3, 0, 1, 33]
[PID: 3728][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2456][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\Downloaded Program Files\871590\ExDLL.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\webpageparser.dll] [N/A, N/A]
[C:\WINDOWS\system32\Charset.dll] [N/A, N/A]
[C:\WINDOWS\system32\CreateDomTree.dll] [N/A, N/A]
[C:\WINDOWS\Downloaded Program Files\871590\fshook.dll] [, 1, 0, 0, 1]
[C:\Program Files\iTunes\iTunesMiniPlayer.dll] [Apple Computer, Inc., 7.0.2.16]
[C:\Program Files\iTunes\iTunesMiniPlayer.Resources\zh_CN.lproj\iTunesMiniPlayerLocalized.dll] [Apple Computer, Inc., 7.0.2.1]
[C:\Program Files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll] [Apple Computer, Inc., 7.0.2.16]
[C:\WINDOWS\system32\IESHEL~1.DLL] [, 5.1.2600.0]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[C:\WINDOWS\system32\Macromed\Common\SwSupport.dll] [Macromedia, Inc., 10.1r11]
[C:\WINDOWS\system32\gamepy.ime] [PRIVATE, 1, 0, 0, 1]
[C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 1.1.4322.2032]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorie.dll] [Microsoft Corporation, 1.1.4322.573]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorld.dll] [Microsoft Corporation, 1.1.4322.2032]
[PID: 2908][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3100][C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe] [Analog Devices, Inc., 5, 0, 2, 2]
[C:\Program Files\Analog Devices\SoundMAX\SMWDMIF.dll] [Analog Devices, Inc., 5, 0, 2, 008]
[PID: 996][E:\Program Files\DAEMON Tools\daemon.exe] [DT Soft Ltd., 4.00.0.0]
[e:\Program Files\DAEMON Tools\daemon.dll] [DT Soft Ltd., 4.00.0.0]
[e:\Program Files\DAEMON Tools\PFCTOC.DLL] [Padus(R), Inc., 1, 0, 0, 12]
[e:\Program Files\DAEMON Tools\Plugins\Images\bw5mount.dll] [N/A, 1.0.6.0]
[e:\Program Files\DAEMON Tools\Plugins\Images\ccdmount.dll] [GENERIC, 1.10.0.0]
[e:\Program Files\DAEMON Tools\Plugins\Images\mdsmount.dll] [GENERIC, 1.12.0.0]
[e:\Program Files\DAEMON Tools\Plugins\Images\nrgmount.dll] [GENERIC, 1.11.0.0]
[e:\Program Files\DAEMON Tools\Plugins\Images\pdimount.dll] [GENERIC, 1.01.0.0]
[PID: 3272][C:\Program Files\Microsoft IntelliPoint\point32.exe] [Microsoft Corporation, 5.30.607.0]
[C:\Program Files\Microsoft IntelliPoint\point32.dll] [Microsoft Corporation, 5.30.606.0]
[C:\Program Files\Microsoft IntelliPoint\dpgmkb.dll] [Microsoft Corporation, 5.30.606.0]
[C:\Program Files\Microsoft IntelliPoint\dpgcmd.dll] [Microsoft Corporation, 5.30.606.0]
[C:\Program Files\Microsoft IntelliPoint\srres.dll] [Microsoft Corporation, 5.30.587.0]
[C:\Program Files\Microsoft IntelliPoint\ipres.dll] [Microsoft Corporation, 5.30.601.0]
[PID: 3380][C:\Program Files\QuickTime\qttask.exe] [Apple Computer, Inc., 7.1.3]
[PID: 3432][D:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE] [Super Rabbit Soft, 7.93]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690]
[C:\WINDOWS\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[D:\PROGRA~1\SUPERR~1\MagicSet\shlobj71.ocx] [Sky Software (http://www.ssware.com), 7, 1, 0, 0]
[PID: 3492][D:\Program Files\Super Rabbit\MagicSet\SRSB.EXE] [Super Rabbit Soft, 1.20]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690]
[C:\WINDOWS\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[D:\Temp\sreng2\SREng\SREng.com] [Smallfrogs Studio, 2.2.6.605]
photosynthesis - 2006-12-16 4:17:00
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
photosynthesis - 2006-12-16 4:20:00
照着做了,问题还是没有解决,可能是上次的日志不够全吧,并且有些删除了重起后,又会出现,看看现在的我补上的日志,还什么什么补充的吧。。。又麻烦了,谢谢。
不言放弃 - 2006-12-16 13:49:00
【回复“photosynthesis”的帖子】
同时按ctrl+alt+del组合键
调出任务管理器--进程
在【待结束的进程名称】上按右键
结束Explorer.EXE进程
这时桌面消失
==========
同时按Ctrl+Alt+Del组合键调出“Windows任务管理器”
在“Windows任务管理器”中选“文件”--“新建任务”
在“创建新任务”中输入explorer.exe--按“Enter”键
这时重新显示桌面
===========
修复如下自启动项
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Desktop><"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Run> []
==========
修复如下服务项
[VisionService / VisionService]
<C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\vision\VISVER.DLL,Service><Microsoft Corporation>
[Windows NT Service32 / Windows NT Service32]
<"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Start><Microsoft Corporation>
==========
修复如下驱动项
[000070a0 / 000070a0]
<\SystemRoot\system32\drivers\000070a0.SYS><N/A>
===========
修复如下浏览器加载项
[Vision]
{6671A431-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\vision\vision.dll, N/A>
[MMSAssistMenu]
{6671A433-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\vision\vision.dll, N/A>
===========
开始--运行
输入regedit
确定
进入注册表
依次展开
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Services](X代表1,2,3,4....)
找到后删除如下文件夹:
VisionService
Windows NT Service32
000070a0
依次展开
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Enum\Root\](X代表1,2,3,4....)
删除如下文件夹:
LEGACY_VisionService
LEGACY_Windows NT Service32
LEGACY_000070a0
=============
卸载
C:\Program Files\vision\
C:\Program Files\MMSAssist\
========
删除
C:\Program Files\vision\
C:\Program Files\MMSAssist\
C:\WINDOWS\Downloaded Program Files\871590\ExDLL.dll
C:\WINDOWS\system32\webpageparser.dll
C:\WINDOWS\system32\Charset.dll
C:\WINDOWS\system32\CreateDomTree.dll
C:\WINDOWS\Downloaded Program Files\871590\fshook.dll
C:\WINDOWS\system32\NTService32.dll
C:\WINDOWS\system32\drivers\000070a0.SYS
C:\WINDOWS\Downloaded Program Files\871590\
1
© 2000 - 2026 Rising Corp. Ltd.