瑞星卡卡安全论坛
忘记明天 - 2006-12-28 0:41:00
[CODE]
2006-12-28,00:28:07
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<racer><> [N/A]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [(Verified)RealNetworks, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<Super Rabbit SRCK><"D:\Program Files\Super Rabbit\MagicSet\srck.exe" /autokill:260,245,48> [Super Rabbit Soft]
<CPushSetup><"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\Common Files\CPUSH\cpush.dll"> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<main><rundll32.exe "C:\program files\internet explorer\use061222.dll" mymain> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
<UIHost><"\Program Files\Logonui\Royale.exe"> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{578AA714-A6FF-11E0-9A84-00C04FD8DBD8}><C:\WINDOWS\system32\h78AA714.log> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<WebSecurity><C:\WINDOWS\system32\PvSec.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\certrmgr]
<WinlogonNotify: certrmgr><certrmgr.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\competUi]
<WinlogonNotify: competUi><competUi.dll> [Microsoft Corporation]
忘记明天 - 2006-12-28 0:42:00
启动文件夹
N/A
==================================
服务
[dos.eeewl.com / dos.eeewl.com][Stopped/Auto Start]
<C:\WINDOWS\system32\nsvc.exe><N/A>
[E5A3DD04 / E5A3DD04][Stopped/Auto Start]
<C:\WINDOWS\system32\E5A3DD04.EXE -service><Microsoft Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[QoS Manager / QoSvc][Stopped/Auto Start]
<C:\WINDOWS\system32\COM\Qos.exe><Application Service>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon][Running/Auto Start]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[WindowsLogin / WindowsLogin][Stopped/Auto Start]
<C:\WINDOWS\system32\Svchost.exe -k WindowsLogin-->C:\WINDOWS\system32\MDserivces\services\Svchost.dll><Microsoft Corporation>
[COM+ Messages / COM+ Messages][Stopped/Auto Start]
<"C:\WINDOWS\system32\svchosts.exe" -e te-110-12-0000049><N/A>
[PRINTSK / PRINTSK][Stopped/Auto Start]
<C:\WINDOWS\system32\PRINTSK.EXE -service><Microsoft Corporation>
[System Administrator / Tech][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\hgrqy.dll><Microsoft Corporation>
==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
<system32\drivers\ac97intc.sys><Intel Corporation>
[AliIde / AliIde][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\aliide.sys><N/A>
[BaseTDI / BaseTDI][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
[CmdIde / CmdIde][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[dtscsi / dtscsi][Running/Manual Start]
<\SystemRoot\System32\Drivers\dtscsi.sys><N/A>
[ENUS_NDIS_DRIVER / ENUS_NDIS_DRIVER][Running/Boot Start]
<\SystemRoot\system32\enusndis.sys><N/A>
[ExpScaner / ExpScaner][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[hnbkuo4 / hnbkuo41][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\hnbkuo41.sys><N/A>
[HookCont / HookCont][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[jddeechj / jddeechj][Stopped/Boot Start]
<\SystemRoot\system32\drivers\jddeechj.sys><N/A>
[kmsinput / kmsinput][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[LanPort / LanPort][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\LanPort.sys><N/A>
[MegaIDE / MegaIDE][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[msqmx / msqmx][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msqmx.sys><N/A>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
<system32\drivers\npf.sys><N/A>
[npkcrypt / npkcrypt][Stopped/Auto Start]
<\??\D:\Tence\npkcrypt.sys><N/A>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[parcls / parcls][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\parcls.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Others/Auto Start]
<\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Running/Auto Start]
<system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[sptd / sptd][Running/Boot Start]
<\SystemRoot\System32\Drivers\sptd.sys><N/A>
[sssp / ssspk][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\ssspk.sys><N/A>
[ViaIde / ViaIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
忘记明天 - 2006-12-28 0:43:00
浏览器加载项
[TBSB02607 Class]
{92CE9EC0-A77A-4A62-91F3-007C6E45BA47} <C:\PROGRA~1\KASPER~1\kaka.dll, N/A>
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[360safe]
{25A12546-9786-4C8F-BCBA-627F3001D89F} <C:\Program Files\360safe\360safe.dll, N/A>
[Kaspersky Anti-Virus]
{8498248D-CDCE-4E95-8F88-B8C9BF96A1C2} <C:\Program Files\Kaspersky Anti-Virus\kaka.dll, N/A>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\AliEdit.dll, www.alipay.com>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[实用搜索工具条2.0]
{03465FF5-00AE-411A-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[TBSB02553 Class]
{0A5ABA17-9FB8-466F-BFD2-80631AD9326A} <C:\PROGRA~1\360safe\360safe.dll, N/A>
[360safe]
{25A12546-9786-4C8F-BCBA-627F3001D89F} <C:\Program Files\360safe\360safe.dll, N/A>
[Kaspersky Anti-Virus]
{8498248D-CDCE-4E95-8F88-B8C9BF96A1C2} <C:\Program Files\Kaspersky Anti-Virus\kaka.dll, N/A>
[TBSB02607 Class]
{92CE9EC0-A77A-4A62-91F3-007C6E45BA47} <C:\PROGRA~1\KASPER~1\kaka.dll, N/A>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[]
{F770522B-198D-4134-9D74-D30F41B3BA44} <C:\WINDOWS\system32\jyldjbpmicvagdl.dll, N/A>
忘记明天 - 2006-12-28 0:44:00
正在运行的进程
[PID: 468][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 524][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 548][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\competUi.dll] [Microsoft Corporation, 5.131.3790.1830]
[PID: 596][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 608][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 768][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 812][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 884][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 912][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 984][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1084][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1096][C:\Program Files\Rising\Rav\Ravmond.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 39]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\rfwctrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[C:\Program Files\Rising\Rav\RsPPsys.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RsLog.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\HOOKSYS.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
[C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[C:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[C:\Program Files\Rising\Rav\regmon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\HookWeb.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[C:\Program Files\Rising\Rav\MemMon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
[C:\Program Files\Rising\Rav\expscan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[C:\Program Files\Rising\Rav\HookCont.dll] [Rising, 19, 0, 0, 0]
[C:\Program Files\Rising\Rav\SpamEng.dll] [N/A, 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\engine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
[C:\Program Files\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[C:\Program Files\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[C:\Program Files\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 30]
[C:\Program Files\Rising\Rav\ExtFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 23]
[C:\Program Files\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[C:\Program Files\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
[C:\Program Files\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\Unpacker.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
[C:\Program Files\Rising\Rav\ScanPack.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 18]
[C:\Program Files\Rising\Rav\RsVM.dll] [N/A, 19, 0, 0, 13]
[C:\Program Files\Rising\Rav\Uroutine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[C:\Program Files\Rising\Rav\Uscript.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
[C:\Program Files\Rising\Rav\ScanNet.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\RsStore.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\Rising\Rav\ExtMail.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
[PID: 1424][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1908][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\rmjqe.dll] [N/A, N/A]
[C:\WINDOWS\system32\PvSec.dll] [, 5, 1, 100, 2500]
[C:\Program Files\578AA714\0C5D07FF.DLL] [N/A, N/A]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\ACDSee\picaview.dll] [ACD Systems, Ltd., 2, 0, 0, 78]
[C:\Program Files\ACDSee\PlugIns\IDE_ACDStd.apl] [ACD Systems, Ltd., 1, 3, 4, 22]
[C:\WINDOWS\system32\jyldjbpmicvagdl.dll] [N/A, N/A]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[PID: 1080][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1768][C:\Program Files\racer-han-cnc\racer.exe] [Putian Runway, 3,3,116,192]
忘记明天 - 2006-12-28 0:44:00
[C:\Program Files\racer-han-cnc\rwxre.dll] [Mozilla Foundation, 1.7.3: 2006072418]
[C:\Program Files\racer-han-cnc\nspr4.dll] [Netscape Communications Corporation, 4.5 Beta]
[C:\Program Files\racer-han-cnc\xpcom.dll] [Mozilla Foundation, 1.7.3: 2006072418]
[C:\Program Files\racer-han-cnc\nss3.dll] [Netscape Communications Corporation, 3.9.1]
[C:\Program Files\racer-han-cnc\softokn3.dll] [Netscape Communications Corporation, 3.9.1]
[C:\Program Files\racer-han-cnc\gkgfx.dll] [Mozilla Foundation, 1.7.3: 2006072418]
[C:\Program Files\racer-han-cnc\xpcom_compat.dll] [Mozilla Foundation, 1.7.3: 2006072418]
[C:\Program Files\racer-han-cnc\js3250.dll] [Netscape Communications Corporation, 4.0]
[C:\Program Files\racer-han-cnc\components\racer_base_comp.dll] [Putian Runway, 3,3,116,192]
[C:\Program Files\racer-han-cnc\racer_base.dll] [Putian Runway, 3,3,116,192]
[C:\Program Files\racer-han-cnc\kbdhook.dll] [Putian Runway, 3,3,116,192]
[C:\Program Files\racer-han-cnc\components\pipnss.dll] [Mozilla Foundation, 1.7.3: 2006072418]
[C:\Program Files\racer-han-cnc\components\gklayout.dll] [Mozilla Foundation, 1.7.3: 2006072418]
[C:\Program Files\racer-han-cnc\components\jar50.dll] [Mozilla Foundation, 1.7.3: 2006072418]
[C:\Program Files\racer-han-cnc\components\xpcom_compat_c.dll] [Mozilla Foundation, 1.7.3: 2006072418]
[C:\Program Files\racer-han-cnc\components\racer_ad_comp.dll] [Putian Runway, 3,3,116,192]
[C:\Program Files\racer-han-cnc\components\racer_access_dhcpplus.dll] [Putian Runway, 3,3,116,192]
[C:\Program Files\racer-han-cnc\dhcpplus.dll] [北京润汇科技有限公司, 0, 11, 19, 44]
[C:\Program Files\racer-han-cnc\components\racer_nss4_comp.dll] [Putian Runway, 3,3,116,192]
[C:\Program Files\racer-han-cnc\nss4.dll] [北京润汇科技有限公司, 1, 0, 0, 4]
[C:\Program Files\racer-han-cnc\wpcap.dll] [CACE Technologies, 3, 2, 0, 29]
[C:\Program Files\racer-han-cnc\packet.dll] [CACE Technologies, 3, 2, 0, 29]
[C:\Program Files\racer-han-cnc\WanPacket.dll] [CACE Technologies, 3, 2, 0, 29]
[C:\Program Files\578AA714\0C5D07FF.DLL] [N/A, N/A]
[PID: 2056][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\578AA714\0C5D07FF.DLL] [N/A, N/A]
[PID: 3896][C:\Program Files\racer-han-cnc\RacerKp.exe] [北京润汇科技有限公司, 1, 0, 0, 1]
[C:\Program Files\578AA714\0C5D07FF.DLL] [N/A, N/A]
[PID: 800][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\578AA714\0C5D07FF.DLL] [N/A, N/A]
[PID: 1808][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\System\MS578AA7.DLL] [N/A, N/A]
[C:\Program Files\578AA714\0C5D07FF.DLL] [N/A, N/A]
[PID: 2416][C:\Program Files\Rising\Rav\Rav.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
[C:\Program Files\Rising\Rav\PlugIn\RsPgScan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 17]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RavUI.Dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 30]
[C:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
[C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\578AA714\0C5D07FF.DLL] [N/A, N/A]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[C:\Program Files\Rising\Rav\MVEngine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[C:\Program Files\Rising\Rav\Engine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
[C:\Program Files\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[C:\Program Files\Rising\Rav\Unpacker.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
[C:\Program Files\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 30]
[C:\Program Files\Rising\Rav\ExtFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 23]
[C:\Program Files\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[C:\Program Files\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
[C:\Program Files\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[C:\Program Files\Rising\Rav\ExtOLE.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[C:\Program Files\Rising\Rav\ScanPack.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 18]
[C:\Program Files\Rising\Rav\RsVM.dll] [N/A, 19, 0, 0, 13]
[C:\Program Files\Rising\Rav\RsStore.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\Rising\Rav\RsLog.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\Uroutine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[C:\Program Files\Rising\Rav\Uscript.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
[C:\Program Files\Rising\Rav\ScanNet.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 3132][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3760]
[C:\Program Files\578AA714\0C5D07FF.DLL] [N/A, N/A]
[PID: 204][F:\新建文件夹 (2)\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\Program Files\578AA714\0C5D07FF.DLL] [N/A, N/A]
忘记明天 - 2006-12-28 0:45:00
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
[/CODE]
鸟儿天上飞 - 2006-12-28 1:18:00
IceSword冰刃-斩断木马黑手的利刃
下载地址1:
中文:http://202.38.64.10/~jfpan/download/IceSword120_cn.zip
使用IceSword杀毒的一些基本操作
http://forum.ikaka.com/topic.asp?board=28&artid=7168178
1、运行IceSword。
2、用IceSword禁止进程创建。
3、找到并右击IceSword自身的进程名,点击“模块信息”。仔细查看模块中是否有C:\Program Files\578AA714\0C5D07FF.DLL。如果有,用IceSword强制卸除之(千万不要省略这一步)。
4、用IceSword结束下列进程(已经被病毒模块插入了):
[PID: 204][F:\新建文件夹 (2)\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[PID: 3132][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3760]
[PID: 2416][C:\Program Files\Rising\Rav\Rav.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
[PID: 1908][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2056][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1768][C:\Program Files\racer-han-cnc\racer.exe] [Putian Runway, 3,3,116,192]
[PID: 3896][C:\Program Files\racer-han-cnc\RacerKp.exe] [北京润汇科技有限公司, 1, 0, 0, 1]
[PID: 800][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1808][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
5、用IceSword删除上述加载项(启动组)
<main><rundll32.exe "C:\program files\internet explorer\use061222.dll" mymain> [N/A]
<{578AA714-A6FF-11E0-9A84-00C04FD8DBD8}><C:\WINDOWS\system32\h78AA714.log> [N/A]
<WebSecurity><C:\WINDOWS\system32\PvSec.dll> []
用IceSword删除上述加载项(服务)
[dos.eeewl.com / dos.eeewl.com]
[E5A3DD04 / E5A3DD04]
[QoS Manager / QoSvc]
[WindowsLogin / WindowsLogin]
[COM+ Messages / COM+ Messages]
[PRINTSK / PRINTSK]
[System Administrator / Tech]
6、用IceSword删除那些加载项指向的文件(有部分文件无法删除用强制删除)
C:\WINDOWS\system32\rmjqe.dll
C:\WINDOWS\system32\PvSec.dll
C:\Program Files\578AA714\0C5D07FF.DLL
C:\program files\internet explorer\use061222.dll
C:\WINDOWS\system32\h78AA714.log
C:\WINDOWS\system32\PvSec.dll
C:\WINDOWS\system32\nsvc.exe
C:\WINDOWS\system32\E5A3DD04.EXE
C:\WINDOWS\system32\COM\Qos.exe
C:\WINDOWS\system32\MDserivces\services\Svchost.dll
SystemRoot\system32\enusndis.sys
C:\WINDOWS\system32\svchosts.exe
SystemRoot\System32\DRIVERS\hnbkuo41.sys
C:\WINDOWS\system32\PRINTSK.EXE
C:\WINDOWS\system32\hgrqy.dll
C:\WINDOWS\system32\drivers\LanPort.sys
C:\WINDOWS\system32\drivers\msqmx.sys
system32\drivers\npf.sys
SystemRoot\System32\DRIVERS\ssspk.sys
C:\WINDOWS\system32\jyldjbpmicvagdl.dll
7、点击IceSword工具栏上的“文件”、“设置”,取消“禁止进程创建”。
8、点击IceSword工具栏上的“文件”、“重启并监视”。此时,系统重启。
9.在用SRENG从新扫描日志上传
1
© 2000 - 2026 Rising Corp. Ltd.