瑞星卡卡安全论坛
紫剑76 - 2006-12-29 7:43:00
开机后总是显示:
1、加载C:\WINDOWS\system32\hrgcik38.dll时出错.找不到指定的模块.
2、加载C:\PROGRA~1\3721\helper.dll时出错,找不到指定的模块.
3、加载C:\WINDOWS\DOWNLO~1\CNSMIN.dll时出错,找不到指定的模块.
除了扫描病毒时总出现一个杀不死的病毒(hrgcik38)外,使用机器时并没出现其他问题,不知道应该怎么处理啊 请高手帮忙给看一下哈!
2006-12-29,07:31:36
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<swg><C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe> [(Verified)Google Inc.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe> [N/A]
<CnsMin><Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32> [N/A]
<wallpaper><c:\windows\system32\壁纸自动换.exe> [N/A]
<helper.dll><C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32> [N/A]
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<CnxDslTaskBar><"C:\Program Files\ADSL\AccessRunner ADSL\CnxDslTb.exe"> [Conexant Systems Inc.]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<NMGameX_AutoRun><C:\WINDOWS\system32\Rundll32.exe nmgamex.dll,LiveProcess /aa> [NMGameX]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [N/A]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [N/A]
<UnlockerAssistant><"D:\王磊\新建文件夹\Unlocker\UnlockerAssistant.exe"> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<RavStub><"C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><> [N/A]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
==================================
启动文件夹
N/A
==================================
服务
[Human Interface Device Access / HidServ]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
==================================
驱动程序
[abp480n5 / abp480n5]
<C:\WINDOWS\SYSTEM32\DRIVERS\abp480n5.SYS><Microsoft Corporation>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc]
<system32\drivers\ac97intc.sys><Intel Corporation>
[aic78u2 / aic78u2]
<C:\WINDOWS\SYSTEM32\DRIVERS\aic78u2.SYS><Microsoft Corporation>
[aic78xx / aic78xx]
<C:\WINDOWS\SYSTEM32\DRIVERS\aic78xx.SYS><Microsoft Corporation>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AliIde / AliIde]
<C:\WINDOWS\SYSTEM32\DRIVERS\AliIde.SYS><Acer Laboratories Inc.>
[AMD K8 Processor Driver / AmdK8]
<System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
[Rising TDI Base Driver / BaseTDI]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[cd20xrnt / cd20xrnt]
<C:\WINDOWS\SYSTEM32\DRIVERS\cd20xrnt.SYS><Microsoft Corporation>
[CmdIde / CmdIde]
<C:\WINDOWS\SYSTEM32\DRIVERS\CmdIde.SYS><CMD Technology, Inc.>
[AccessRunner USB ADSL WAN Adapter Filter Driver / CnxEtP]
<system32\DRIVERS\CnxEtP.sys><Conexant>
[AccessRunner USB ADSL Interface Device Driver / CnxEtU]
<system32\DRIVERS\CnxEtU.sys><Conexant>
[AccessRunner USB ADSL WAN Adapter Driver / CnxTgN]
<system32\DRIVERS\CnxTgN.sys><Conexant Systems Inc.>
[ExpScaner / ExpScaner]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS]
<system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[HookCont / HookCont]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[hrgcik3 / hrgcik38]
<\SystemRoot\System32\DRIVERS\hrgcik38.sys><N/A>
[ialm / ialm]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[MEMSCAN / MEMSCAN]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mraid35x / mraid35x]
<C:\WINDOWS\SYSTEM32\DRIVERS\mraid35x.SYS><American Megatrends Inc.>
[npkcrypt / npkcrypt]
<\??\C:\Program Files\QQ2006\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[ql1080 / ql1080]
<C:\WINDOWS\SYSTEM32\DRIVERS\ql1080.SYS><QLogic Corporation>
[Ql10wnt / Ql10wnt]
<C:\WINDOWS\SYSTEM32\DRIVERS\Ql10wnt.SYS><Microsoft Corporation>
[ql12160 / ql12160]
<C:\WINDOWS\SYSTEM32\DRIVERS\ql12160.SYS><QLogic Corporation>
[ql1280 / ql1280]
<C:\WINDOWS\SYSTEM32\DRIVERS\ql1280.SYS><QLogic Corporation>
[rfsafe / rfsafe]
<\SystemRoot\system32\drivers\rfsafe.sys><N/A>
[RsNTGDI / RsNTGDI]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS]
<\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp]
<system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
<system32\DRIVERS\secdrv.sys><N/A>
[Sparrow / Sparrow]
<C:\WINDOWS\SYSTEM32\DRIVERS\Sparrow.SYS><Adaptec, Inc.>
[symc810 / symc810]
<C:\WINDOWS\SYSTEM32\DRIVERS\symc810.SYS><Symbios Logic Inc.>
[symc8xx / symc8xx]
<C:\WINDOWS\SYSTEM32\DRIVERS\symc8xx.SYS><LSI Logic>
[sym_hi / sym_hi]
<C:\WINDOWS\SYSTEM32\DRIVERS\sym_hi.SYS><LSI Logic>
[sym_u3 / sym_u3]
<C:\WINDOWS\SYSTEM32\DRIVERS\sym_u3.SYS><LSI Logic>
[TCP/IP Protocol Driver / Tcpip]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[TosIde / TosIde]
<C:\WINDOWS\SYSTEM32\DRIVERS\TosIde.SYS><Microsoft Corporation>
[ultra / ultra]
<C:\WINDOWS\SYSTEM32\DRIVERS\ultra.SYS><Promise Technology, Inc.>
[ViaIde / ViaIde]
<C:\WINDOWS\SYSTEM32\DRIVERS\ViaIde.SYS><Microsoft Corporation>
紫剑76 - 2006-12-29 7:43:00
==================================
浏览器加载项
[IDDTInitObj Class]
{15DDE989-CD45-4561-BF99-D22C0D5C2B74} <C:\PROGRA~1\sina\DLFast\DDTInit.dll, 北京新浪信息技术有限公司>
[KillObj Class]
{66C28884-4E5D-494B-80C9-CAA27528FD6D} <C:\PROGRA~1\sina\DLFast\ddtkillw.ocx, 北京新浪信息技术有限公司>
[Google Toolbar Helper]
{AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[FlashGet]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\flashget.exe, N/A>
[新浪点点通]
{F60C7D81-8471-4D40-AAFE-56D318F34C2D} <C:\PROGRA~1\sina\DLFast\DDTONG~1.DLL, 北京新浪信息技术有限公司>
[]
{974AD624-EA50-4831-A6C0-3040F6665396} <C:\PROGRA~1\sina\DLFast\rssband.dll, 北京新浪信息技术有限公司>
[新浪点点通阅读器]
{F0646DC8-58CD-4C64-8F6B-525043914685} <C:\PROGRA~1\sina\DLFast\rssband.dll, 北京新浪信息技术有限公司>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[新浪点点通]
{F60C7D81-8471-4D40-AAFE-56D318F34C2D} <C:\PROGRA~1\sina\DLFast\DDTONG~1.DLL, 北京新浪信息技术有限公司>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft Corporation>
[Google Script Object]
{00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[ActiveMovieControl Object]
{05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[IDDTInitObj Class]
{15DDE989-CD45-4561-BF99-D22C0D5C2B74} <C:\PROGRA~1\sina\DLFast\DDTInit.dll, 北京新浪信息技术有限公司>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[IETag Factory]
{38481807-CA0E-42D2-BF39-B33AF135CC4D} <C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\IETAG.DLL, Microsoft Corporation>
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[KillObj Class]
{66C28884-4E5D-494B-80C9-CAA27528FD6D} <C:\PROGRA~1\sina\DLFast\ddtkillw.ocx, 北京新浪信息技术有限公司>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[]
{974AD624-EA50-4831-A6C0-3040F6665396} <C:\PROGRA~1\sina\DLFast\rssband.dll, 北京新浪信息技术有限公司>
[RMGetLicense Class]
{A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation>
[Google Toolbar Helper]
{AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[AUDIO__MP3 Moniker Class]
{CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AUDIO__WAV Moniker Class]
{CD3AFA7B-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AUDIO__X_MS_WMA Moniker Class]
{CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
{CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9a.ocx, Adobe Systems, Inc.>
[新浪点点通阅读器]
{F0646DC8-58CD-4C64-8F6B-525043914685} <C:\PROGRA~1\sina\DLFast\rssband.dll, 北京新浪信息技术有限公司>
[新浪点点通]
{F60C7D81-8471-4D40-AAFE-56D318F34C2D} <C:\PROGRA~1\sina\DLFast\DDTONG~1.DLL, 北京新浪信息技术有限公司>
[IEDown Class]
{F917534D-535B-416B-8E8F-0C04756C31A8} <C:\WINDOWS\system32\GLIEDown2.dll, 联众公司>
[使用彩信超级自写发送到手机]
<http://mms.sina.com.cn/mmsnews.html, N/A>
[使用新浪下载助手下载]
<C:\PROGRA~1\sina\DLFast\sinadl.htm, N/A>
[使用网际快车下载]
<E:\xz\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<E:\xz\FlashGet\jc_all.htm, N/A>
[发送图片到手机(&M)]
<http://sms.sina.com.cn/diy/send.html?from=467, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[新浪搜索]
<http://cha.sina.com.cn/ddt.html, N/A>
紫剑76 - 2006-12-29 7:44:00
==================================
正在运行的进程
[PID: 440][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 504][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 528][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 572][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 584][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 736][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 780][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 848][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 880][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 928][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 988][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1044][C:\Program Files\Rising\Rav\Ravmond.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 43]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\rfwctrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[C:\Program Files\Rising\Rav\RsPPsys.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RsLog.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\HOOKSYS.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
[C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[C:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[C:\Program Files\Rising\Rav\regmon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\HookWeb.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[C:\Program Files\Rising\Rav\MemMon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
[C:\Program Files\Rising\Rav\expscan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[C:\Program Files\Rising\Rav\HookCont.dll] [Rising, 19, 0, 0, 0]
[C:\Program Files\Rising\Rav\SpamEng.dll] [N/A, 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\engine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
[C:\Program Files\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[C:\Program Files\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[C:\Program Files\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 32]
[C:\Program Files\Rising\Rav\ExtFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 23]
[C:\Program Files\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[C:\Program Files\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
[C:\Program Files\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\Unpacker.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
[C:\Program Files\Rising\Rav\ScanPack.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 18]
[C:\Program Files\Rising\Rav\RsVM.dll] [N/A, 19, 0, 0, 13]
[C:\Program Files\Rising\Rav\Uroutine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[C:\Program Files\Rising\Rav\Uscript.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
[C:\Program Files\Rising\Rav\RsStore.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[PID: 1236][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[d:\王磊\联众\glacm.dll] [N/A, N/A]
[C:\Program Files\QQ2006\qdshm.dll] [, 1, 0, 101, 20]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1384][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\Ssgb3mon.dll] [Samsung Electronics., 1, 0, 0, 0]
[PID: 1480][C:\Program Files\Rising\Rav\RavStub.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1724][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1792][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 336][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1140][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5, 1, 0, 52]
[PID: 1164][C:\Program Files\ADSL\AccessRunner ADSL\CnxDslTb.exe] [Conexant Systems Inc., 2.099.085.000]
[C:\Program Files\ADSL\AccessRunner ADSL\CnxDslWz.dll] [Conexant Systems Inc., 2.099.085.000]
[C:\WINDOWS\system32\CnxHwIo.dll] [Conexant Systems Inc., 2.099.085.000]
[PID: 1144][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
紫剑76 - 2006-12-29 7:45:00
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[PID: 1116][C:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
[C:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 1260][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1296][C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe] [Google Inc., 1, 0, 720, 3640]
[C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5746\swg.dll] [Google Inc., 1, 2, 908, 5746]
[C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5746\res_zh-CN.dll] [Google Inc., 1, 2, 908, 5746]
[PID: 324][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\sina\DLFast\DDTONG~1.DLL] [北京新浪信息技术有限公司, 1, 2, 1, 5]
[C:\PROGRA~1\sina\DLFast\DDTInit.dll] [北京新浪信息技术有限公司, 1, 2, 1, 7]
[C:\PROGRA~1\sina\DLFast\DDTUpdate.dll] [北京新浪信息技术有限公司, 1, 2, 1, 1]
[C:\PROGRA~1\sina\DLFast\DDTcomm.dll] [北京新浪信息技术有限公司, 1, 1, 0, 3]
[C:\PROGRA~1\sina\DLFast\DDTDLF~1.OCX] [, 1, 1, 0, 1]
[C:\PROGRA~1\sina\DLFast\ddtkillw.ocx] [北京新浪信息技术有限公司, 1, 1, 0, 5]
[c:\program files\google\googletoolbar1.dll] [Google Inc., 4, 0, 1019, 5266]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\Macromed\Flash\Flash9a.ocx] [Adobe Systems, Inc., 9,0,0,296]
[d:\王磊\联众\glacm.dll] [N/A, N/A]
[PID: 2120][D:\王磊\backups\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[d:\王磊\联众\glacm.dll] [N/A, N/A]
[PID: 2296][D:\王磊\联众\GLWorld.exe] [北京联众电脑技术有限责任公司, 2, 6, 1, 23]
[D:\王磊\联众\GLWorld_Res.dll] [北京联众电脑技术有限责任公司, 2, 6, 1, 23]
[C:\WINDOWS\system32\codecvt.dll] [N/A, N/A]
[D:\王磊\联众\GLAvatar.ocx] [, 2, 2, 0, 32]
[d:\王磊\联众\GLHGStart.dll] [NHN Corp., 1, 0, 1, 0]
[D:\王磊\联众\GLAdCtrl.ocx] [Globallink, 2, 1, 0, 5]
[C:\WINDOWS\system32\Macromed\Flash\Flash9a.ocx] [Adobe Systems, Inc., 9,0,0,296]
[C:\WINDOWS\system32\GLZip.dll] [GlobalLink, 1, 0, 0, 1]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[d:\王磊\联众\glacm.dll] [N/A, N/A]
[PID: 2420][D:\王磊\联众\OurFriend\ourfriend.exe] [, 1, 0, 0, 1]
[D:\王磊\联众\OurFriend\ODCtrlRes.dll] [, 1, 0, 0, 1]
[D:\王磊\联众\OurFriend\ourfriend_res.dll] [, 1, 0, 0, 1]
[d:\王磊\联众\glacm.dll] [N/A, N/A]
[C:\WINDOWS\system32\GLPNG.dll] [globallink(ourgame) , 1, 0, 0, 2]
[C:\WINDOWS\system32\GLCOMPRESS.dll] [globallink, 1, 0, 0, 2]
[D:\王磊\联众\roomicon.dll] [Beijing GlobalLink Computer Corp., 2, 5, 0, 6]
[D:\王磊\联众\people.dll] [Beijing GlobalLink Computer Corp., 2, 2, 0, 3]
[D:\王磊\联众\Image\Room\Table0.dll] [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
[D:\王磊\联众\Image\Room\Table1.dll] [Beijing GlobalLink Computer Corp., 2, 1, 2, 255]
[D:\王磊\联众\Image\Room\Table2.dll] [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
[D:\王磊\联众\Image\Room\Player0_0.dll] [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
[D:\王磊\联众\Image\Room\Player0_1.dll] [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
[D:\王磊\联众\Image\Room\Player0_2.dll] [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
[D:\王磊\联众\Image\Room\Player0_3.dll] [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
[D:\王磊\联众\Image\Room\Player0_4.dll] [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
[D:\王磊\联众\Image\Room\Player0_5.dll] [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
[D:\王磊\联众\Image\Room\Player0_6.dll] [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
[D:\王磊\联众\Image\Room\Player0_7.dll] [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
[D:\王磊\联众\Image\Room\Player0_8.dll] [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
[D:\王磊\联众\Image\Room\Player0_9.dll] [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
[D:\王磊\联众\Image\Room\Player0_10.dll] [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
[D:\王磊\联众\Image\Room\Player0_11.dll] [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
[D:\王磊\联众\Image\Room\Player0_12.dll] [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
[D:\王磊\联众\Image\Room\Player0_13.dll] [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
[D:\王磊\联众\Image\Room\Player0_14.dll] [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
[D:\王磊\联众\Image\Room\Player0_15.dll] [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
紫剑76 - 2006-12-29 7:45:00
[D:\王磊\联众\Image\Room\Player1_0.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player1_1.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player1_2.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player1_3.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player1_4.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player1_5.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player1_6.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player1_7.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player1_8.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player1_9.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player1_10.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player1_11.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player1_12.dll] [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
[D:\王磊\联众\Image\Room\Player1_13.dll] [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
[D:\王磊\联众\Image\Room\Player1_14.dll] [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
[D:\王磊\联众\Image\Room\Player1_15.dll] [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
[D:\王磊\联众\Image\Room\Player2_0.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player2_1.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player2_2.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player2_3.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player2_4.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player2_5.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player2_6.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player2_7.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player2_8.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player2_9.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player2_10.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player2_11.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player2_12.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player2_13.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player2_14.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\Image\Room\Player2_15.dll] [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
[D:\王磊\联众\GLAvatar.ocx] [, 2, 2, 0, 32]
[D:\王磊\联众\GLChatEx.ocx] [GlobalLink, 2, 5, 1, 29]
[D:\王磊\联众\glchatex.dll] [GlobalLink, 2, 5, 1, 29]
[D:\王磊\联众\odctrls\ourfriend_skn.dll] [, 1, 0, 5, 4]
[C:\WINDOWS\system32\codecvt.dll] [N/A, N/A]
[C:\WINDOWS\system32\GLGIFTGA.dll] [globallink(ourgame) , 1, 0, 0, 2]
[PID: 2524][C:\WINDOWS\system32\NOTEPAD.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[d:\王磊\联众\glacm.dll] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
水树雨下 - 2006-12-29 7:50:00
http://www.pctutu.com/下载超级兔子清理流氓软件
紫剑76 - 2006-12-29 8:21:00
用兔子清理过了,除了“2、加载C:\PROGRA~1\3721\helper.dll时出错,找不到指定的模块.”没有了
剩下的两个还是存在啊
1、加载C:\WINDOWS\system32\hrgcik38.dll时出错.找不到指定的模块.
3、加载C:\WINDOWS\DOWNLO~1\CNSMIN.dll时出错,找不到指定的模块
水树雨下 - 2006-12-29 8:25:00
开始,运行,regedit展开注册表,查找那两个dll文件相关的项删除
紫剑76 - 2006-12-29 8:34:00
天那 都看晕了 不知道怎么找啊???(俺是一绝对菜鸟)
水树雨下 - 2006-12-29 8:36:00
编辑,查找,输入那个dll文件名,查找下一个……
紫剑76 - 2006-12-29 8:49:00
谢谢楼上的 已经删除了 这样就可以了吗?
紫剑76 - 2006-12-29 8:58:00
1、加载C:\WINDOWS\system32\hrgcik38.dll时出错.找不到指定的模块.这个家伙怎么这么顽固啊????
还是存在。每次杀毒都会杀出它,可是重启后也删除不了,这到底是个什么病毒啊???????????
紫剑76 - 2006-12-29 9:37:00
谁能告诉我这是什么病毒啊????(加载C:\WINDOWS\system32\hrgcik38.dll时出错.找不到指定的模块)
紫剑76 - 2006-12-29 10:30:00
| 引用: |
【紫剑76的贴子】1、加载C:\WINDOWS\system32\hrgcik38.dll时出错.找不到指定的模块.这个家伙怎么这么顽固啊???? 还是存在。每次杀毒都会杀出它,可是重启后也删除不了,这到底是个什么病毒啊??????????? ……………… |
1
© 2000 - 2026 Rising Corp. Ltd.