瑞星卡卡安全论坛
baofxwxf - 2007-1-14 23:41:00
病毒名称 处理结果 扫描方式 路径 文件 病毒来源
Backdoor.Gpigeon.2006.aym 清除成功 登录系统后扫描 Explorer.EXE>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 登录系统后扫描 RfwMain.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 登录系统后扫描 nvsvc32.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 登录系统后扫描 IEXPLORE.EXE>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 登录系统后扫描 nSvcAppFlt.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 登录系统后扫描 wscntfy.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 登录系统后扫描 WoptiMem.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 登录系统后扫描 RunDLL32.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 登录系统后扫描 ctfmon.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 登录系统后扫描 AgentSvr.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 手动扫描 Explorer.EXE>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 手动扫描 nvsvc32.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 手动扫描 IEXPLORE.EXE>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 手动扫描 nSvcAppFlt.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 手动扫描 wscntfy.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 手动扫描 WoptiMem.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 手动扫描 RunDLL32.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 手动扫描 ctfmon.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 手动扫描 QQ.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 手动扫描 TIMPlatform.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 手动扫描 RfwMain.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 手动扫描 qqpet.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 手动扫描 mplayerc.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 清除成功 手动扫描 taskmgr.exe>>C:\WINDOWS\SYSTEM32\SEKEY.DLL 本机
Backdoor.Gpigeon.2006.aym 重新启动计算机后删除文件手动扫描 C:\WINDOWS\system32 se.DLL 本机
Backdoor.Gpigeon.2006.aym 重新启动计算机后删除文件手动扫描 C:\WINDOWS\system32 SEKEY.DLL 本机
SEKEY.DLL和SE.DLL删不掉,选择显示系统文件和隐藏文件,会看到它,它会占用瑞星等一切开机后运行过的程序的进程,删掉后看不到它,但在地址栏中输入地址就会看到它。
每次瑞星杀毒之后都会显示重新启动计算机后删除文件,但没有用,一开机就会有,而且再次感染执行过的程序。瑞星和卡巴斯基都已经世最新的,都删不掉,瑞星还能查出来,卡巴根本就查不出来。打开过的程序多了以后(打开后又关掉),电脑就变得很慢。
附件:
8199552007114233153.jpg
天拓 - 2007-1-14 23:46:00
灰鸽子2006 是个隐藏文件在C盘里,灰鸽子可以盗取客户的QQ号以及帐号宽带帐号密码等等!建议您用GHOST备份文件还原一下,或者从做系统 或者是找灰鸽子相关资料
newcenturymoon - 2007-1-14 23:53:00
| 引用: |
【天拓的贴子】灰鸽子2006 是个隐藏文件在C盘里,灰鸽子可以盗取客户的QQ号以及帐号宽带帐号密码等等!建议您用GHOST备份文件还原一下,或者从做系统 或者是找灰鸽子相关资料 ……………… |
汗死 为了个鸽子就格系统?
newcenturymoon - 2007-1-14 23:53:00
安全模式下 双击我的电脑-工具-文件夹选项-查看-显示所有文件和文件夹,把“隐藏受保护的系统文件”的勾去掉。
删除
C:\WINDOWS\SYSTEM32\SEKEY.DLL
C:\WINDOWS\SYSTEM32\SE.exe
C:\WINDOWS\SYSTEM32\SE.dll
大白鸟来了 - 2007-1-15 0:40:00
那个系统可以重做了,那么多毒,你还会用得放心吗?别浪费时间了,重做吧
baofxwxf - 2007-1-15 12:34:00
安全模式下 双击我的电脑-工具-文件夹选项-查看-显示所有文件和文件夹,把“隐藏受保护的系统文件”的勾去掉。
删除
C:\WINDOWS\SYSTEM32\SEKEY.DLL
C:\WINDOWS\SYSTEM32\SE.exe
C:\WINDOWS\SYSTEM32\SE.dll
都是过了,可还是不行,不能真正的删掉,安全模式,DOS下,都不行。选择的是显示所有隐藏文件包括系统文件,就可以看到他俩,删掉。但之后在地址栏中输入它们的地址,会弹出一个打开方式的对话框。选择记事本,可以打开,说明这东西还在。但就是看不到它。而且删掉他的时候发现所有开机后运行过得程序都在调用sekey.dll,包括瑞星防火墙,杀毒软件,实施监控等。一开始删它的时候还必须是没有运行过瑞星,要不然瑞星就会调用它,而瑞星又不能结束,所以还必须在运行瑞星之前删掉它。
真的是束手无策,跪求高手帮忙,或有什么可以联系瑞星公司的,打算向瑞星公司求助。
现在的瑞星只能清除被感染的程序,而原病毒还在。卡巴斯基6.0.3的根本就什么都查不出来
newcenturymoon - 2007-1-15 12:35:00
| 引用: |
【大白鸟来了的贴子】那个系统可以重做了,那么多毒,你还会用得放心吗?别浪费时间了,重做吧 ……………… |
那个就是1个文件捣鬼 就是那个dll插入进程 他会报所有被插入的进程有病毒 所以看上去很多
newcenturymoon - 2007-1-15 12:35:00
下载 System Repair Engineer,
http://www.kztechs.com/sreng/download.html
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
baohe - 2007-1-15 15:22:00
| 引用: |
【baofxwxf的贴子】安全模式下 双击我的电脑-工具-文件夹选项-查看-显示所有文件和文件夹,把“隐藏受保护的系统文件”的勾去掉。 删除 C:\WINDOWS\SYSTEM32\SEKEY.DLL C:\WINDOWS\SYSTEM32\SE.exe C:\WINDOWS\SYSTEM32\SE.dll 都是过了,可还是不行,不能真正的删掉,安全模式,DOS下,都不行。选择的是显示所有隐藏文件包括系统文件,就可以看到他俩,删掉。但之后在地址栏中输入它们的地址,会弹出一个打开方式的对话框。选择记事本,可以打开,说明这东西还在。但就是看不到它。而且删掉他的时候发现所有开机后运行过得程序都在调用sekey.dll,包括瑞星防火墙,杀毒软件,实施监控等。一开始删它的时候还必须是没有运行过瑞星,要不然瑞星就会调用它,而瑞星又不能结束,所以还必须在运行瑞星之前删掉它。 真的是束手无策,跪求高手帮忙,或有什么可以联系瑞星公司的,打算向瑞星公司求助。 现在的瑞星只能清除被感染的程序,而原病毒还在。卡巴斯基6.0.3的根本就什么都查不出来 ……………… |
对付鸽子,一般是先用 SREng 一类的日志工具扫系统日志,找到其服务项(主要是服务名),然后,记下鸽子服务指向的木马文件名及其路径,删除鸽子的服务。
重启系统。重启后,因为鸽子的服务被删除了,鸽子自然不能加载运行。
这时,根据刚才记下的路径及其文件名,找到并删除鸽子的文件即可。
对于你的具体情况来说,更简单些。
只要根据SRENG日志判定鸽子的服务名,然后,打开注册表编辑器,在HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES分支的左栏,找到鸽子的服务名,删除。重启系统。显示隐藏文件。找到并删除下列文件即可:
C:\WINDOWS\SYSTEM32\SEKEY.DLL
C:\WINDOWS\SYSTEM32\SE.DLL
C:\WINDOWS\SYSTEM32\SE.EXE
baofxwxf - 2007-1-16 18:06:00
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Wopti Memory Defreg><D:\优化大师\WoptiMem.exe> [鲁锦]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [(Verified)NVIDIA Corporation]
<NvMediaCenter><RunDLL32.exe NvMCTray.dll,NvTaskbarInit> [(Verified)NVIDIA Corporation]
<StormCodec_Helper><"D:\媒体播放\Storm Codec\StormSet.exe" /S /opti> [N/A]
<RavTask><"D:\基本程序\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<RfwMain><"D:\基本程序\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
==================================
启动文件夹
N/A
==================================
服务
[Autodesk Licensing Service / Autodesk Licensing Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk>
[ForceWare Intelligent Application Manager (IAM) / ForceWare Intelligent Application Manager (IAM)][Running/Auto Start]
<C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe><>
[Forceware Web Interface / ForcewareWebInterface][Running/Auto Start]
<"C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe" -k runservice><Apache Software Foundation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[ForceWare IP service / nSvcIp][Stopped/Manual Start]
<C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe><NVIDIA Corporation>
[ForceWare user log service / nSvcLog][Running/Auto Start]
<C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe><NVIDIA Corporation>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Rising Proxy Service / RfwProxySrv][Stopped/Manual Start]
<d:\基本程序\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
<d:\基本程序\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"D:\基本程序\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
<"D:\基本程序\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[RSVPE / Smarytcer RSVP][Stopped/Auto Start]
<C:\WINDOWS\system32\servce><N/A>
==================================
驱动程序
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[DS1410D / DS1410D][Stopped/Auto Start]
<SYSTEM32\drivers\DS1410D.SYS><N/A>
[ExpScaner / ExpScaner][Running/Auto Start]
<\??\D:\基本程序\Rising\Rav\ExpScan.sys><>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HookCont / HookCont][Running/Auto Start]
<\??\D:\基本程序\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\D:\基本程序\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\D:\基本程序\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl][Running/Auto Start]
<\??\D:\基本程序\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
<system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\D:\基本程序\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs][Running/Auto Start]
<\??\d:\基本程序\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\D:\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[nvata / nvata][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\nvata.sys><NVIDIA Corporation>
[NVIDIA nForce Networking Controller Driver / NVENETFD][Running/Manual Start]
<system32\DRIVERS\NVENETFD.sys><NVIDIA Corporation>
[NVIDIA Network Bus Enumerator / nvnetbus][Running/Manual Start]
<system32\DRIVERS\nvnetbus.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsFwDrv / RsFwDrv][Running/Auto Start]
<\??\D:\基本程序\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
<\??\D:\基本程序\Rising\Rav\RSPPSYS.sys><Rising>
[Secdrv / Secdrv][Running/Auto Start]
<system32\DRIVERS\secdrv.sys><N/A>
[Sentinel / Sentinel][Running/Auto Start]
<\SystemRoot\System32\Drivers\SENTINEL.SYS><Rainbow Technologies, Inc.>
[sptd / sptd][Running/Boot Start]
<\SystemRoot\System32\Drivers\sptd.sys><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[TSP / TSP][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\klif.sys><N/A>
baofxwxf - 2007-1-16 18:07:00
浏览器加载项
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\下载工具\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[IeCatch2 Class]
{A5366673-E8CA-11D3-9CD9-0090271D075B} <D:\下略载毓工ぞ具運\FlashGet\JCCatch.dll, N/A>
[启动迅雷]
{0062C9BD-B349-40DE-91A0-755F37ACD559} <D:\下载工具\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\office\Office12\REFIEBAR.DLL, Microsoft Corporation>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Tencent\QQ\QQ.EXE, TENCENT>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\下载工具\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[IeCatch2 Class]
{A5366673-E8CA-11D3-9CD9-0090271D075B} <D:\下略载毓工ぞ具運\FlashGet\JCCatch.dll, N/A>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[上传到QQ网络硬盘]
<D:\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用网际快车下载]
<D:\下载工具\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<D:\下载工具\FlashGet\jc_all.htm, N/A>
[使用迅雷下载]
<D:\下载工具\Thunder\Program\GetUrl.htm, N/A>
[使用迅雷下载全部链接]
<D:\下载工具\Thunder\Program\GetAllUrl.htm, N/A>
[导出到 Microsoft Excel(&X)]
<res://D:\office\Office12\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<D:\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Tencent\QQ\SendMMS.htm, N/A>
baofxwxf - 2007-1-16 18:09:00
正在运行的进程
[PID: 688][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 808][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 848][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 892][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 904][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\nvappfilter.dll] [NVIDIA, 1, 0, 2, 0]
[PID: 1060][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1104][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\nvappfilter.dll] [NVIDIA, 1, 0, 2, 0]
[PID: 1208][D:\基本程序\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1224][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\nvappfilter.dll] [NVIDIA, 1, 0, 2, 0]
[PID: 1392][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\nvappfilter.dll] [NVIDIA, 1, 0, 2, 0]
[PID: 1564][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\nvappfilter.dll] [NVIDIA, 1, 0, 2, 0]
[PID: 1572][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 17.0.54.0]
[C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] [Autodesk, 17.0.54.110]
[D:\下载工具\Thunder\ComDlls\XunLeiBHO_002.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[D:\基本程序\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\dfshim.dll] [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
[C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Shfusion.dll] [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Fusion.dll] [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\culture.dll] [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\zh-CHS\ShFusRes.dll] [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
[D:\实用小程序\Unlocker\UnlockerCOM.dll] [N/A, N/A]
[D:\基本程序\WinRAR\rarext.dll] [N/A, N/A]
[D:\基本程序\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Common Files\Autodesk shared\dwf common\DWFShellExtension.dll] [Autodesk, Inc., 1.1.0.278]
[C:\Program Files\Common Files\Autodesk shared\dwf common\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Common Files\Autodesk shared\dwf common\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.10.9131]
[C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.10.9131]
[C:\WINDOWS\system32\nvshell.dll] [N/A, N/A]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.42]
[PID: 1596][D:\基本程序\Rising\Rav\Ravmond.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 43]
[D:\基本程序\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
[D:\基本程序\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[D:\基本程序\Rising\Rav\rfwctrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[D:\基本程序\Rising\Rav\RsPPsys.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[D:\基本程序\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[D:\基本程序\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[D:\基本程序\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\基本程序\Rising\Rav\RsLog.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[D:\基本程序\Rising\Rav\HOOKSYS.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
[D:\基本程序\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
[D:\基本程序\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[D:\基本程序\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[D:\基本程序\Rising\Rav\regmon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[D:\基本程序\Rising\Rav\psapi.dll] [Microsoft Corporation, 4.00]
[D:\基本程序\Rising\Rav\HookWeb.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[D:\基本程序\Rising\Rav\MemMon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
[D:\基本程序\Rising\Rav\expscan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[D:\基本程序\Rising\Rav\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[D:\基本程序\Rising\Rav\HookCont.dll] [Rising, 19, 0, 0, 0]
[D:\基本程序\Rising\Rav\SpamEng.dll] [N/A, 18, 0, 0, 6]
[D:\基本程序\Rising\Rav\engine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
[C:\WINDOWS\system32\nvappfilter.dll] [NVIDIA, 1, 0, 2, 0]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\基本程序\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[D:\基本程序\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[D:\基本程序\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[D:\基本程序\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 34]
[D:\基本程序\Rising\Rav\ExtFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 23]
[D:\基本程序\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[D:\基本程序\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
[D:\基本程序\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[PID: 1724][d:\基本程序\rising\rfw\rfwsrv.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 30]
[d:\基本程序\rising\rfw\RfwRule.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 3]
[d:\基本程序\rising\rfw\rfwlog.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 2]
[d:\基本程序\rising\rfw\Rfwdrv.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 10]
[d:\基本程序\rising\rfw\psapi.dll] [Microsoft Corporation, 4.00]
[d:\基本程序\rising\rfw\MonDrv.dll] [rs, 1, 0, 0, 4]
[d:\基本程序\rising\rfw\ProcLib.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 5]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[d:\基本程序\rising\rfw\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
baofxwxf - 2007-1-16 18:11:00
[PID: 2012][d:\基本程序\rising\rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 66]
[d:\基本程序\rising\rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 31]
[d:\基本程序\rising\rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[d:\基本程序\rising\rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[d:\基本程序\rising\rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[d:\基本程序\rising\rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[d:\基本程序\rising\rfw\PSAPI.DLL] [Microsoft Corporation, 4.00]
[PID: 276][C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe] [Apache Software Foundation, 2.0.52]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\libapr.dll] [Apache Software Foundation, 0.0.0.0]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\libaprutil.dll] [Apache Software Foundation, 0.0.0.0]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\libapriconv.dll] [Apache Software Foundation, 0.0.0.0]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\libhttpd.dll] [Apache Software Foundation, 2.0.52]
[C:\WINDOWS\system32\nvappfilter.dll] [NVIDIA, 1, 0, 2, 0]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_access.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_actions.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_alias.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_auth.so] [N/A, N/A]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\nv_common.dll] [NVIDIA, 2, 2, 0, 464]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_cgi.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_env.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_expires.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_headers.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_include.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_log_config.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_mime.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_negotiation.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_rewrite.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_setenvif.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_ssl.so] [Apache Software Foundation, 2.0.47]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\SSLEAY32.dll] [N/A, N/A]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\LIBEAY32.dll] [N/A, N/A]
[PID: 376][C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe] [NVIDIA Corporation, 2, 2, 0, 464]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nv_common.dll] [NVIDIA, 2, 2, 0, 464]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\NMI.dll] [NVIDIA Corporation, 2, 2, 0, 464]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nv_resource_L1033.dll] [NVIDIA Corporation, 1, 0, 1, 0]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 456][C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe] [Apache Software Foundation, 2.0.52]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\libapr.dll] [Apache Software Foundation, 0.0.0.0]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\libaprutil.dll] [Apache Software Foundation, 0.0.0.0]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\libapriconv.dll] [Apache Software Foundation, 0.0.0.0]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\libhttpd.dll] [Apache Software Foundation, 2.0.52]
[C:\WINDOWS\system32\nvappfilter.dll] [NVIDIA, 1, 0, 2, 0]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_access.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_actions.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_alias.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_auth.so] [N/A, N/A]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\nv_common.dll] [NVIDIA, 2, 2, 0, 464]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_cgi.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_env.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_expires.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_headers.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_include.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_log_config.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_mime.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_negotiation.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_rewrite.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_setenvif.so] [Apache Software Foundation, 2.0.49]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_ssl.so] [Apache Software Foundation, 2.0.47]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\SSLEAY32.dll] [N/A, N/A]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\LIBEAY32.dll] [N/A, N/A]
[PID: 520][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.9131]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 424][C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe] [, 1, 0, 1, 0]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\NMI.dll] [NVIDIA Corporation, 2, 2, 0, 464]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nv_common.dll] [NVIDIA, 2, 2, 0, 464]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nv_resource_L1033.dll] [NVIDIA Corporation, 1, 0, 1, 0]
[PID: 1448][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nmp.dll] [NVIDIA Corporation, 2, 2, 0, 464]
[C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nv_common.dll] [NVIDIA, 2, 2, 0, 464]
[PID: 1552][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1012][D:\优化大师\WoptiMem.exe] [鲁锦, 3.1.6.1222]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1956][C:\WINDOWS\system32\RunDLL32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\NvMCTray.dll] [NVIDIA Corporation, 6.14.10.9131]
[C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.10.9131]
[PID: 1972][D:\基本程序\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[D:\基本程序\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\基本程序\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[D:\基本程序\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[D:\基本程序\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
baofxwxf - 2007-1-16 18:12:00
[PID: 2004][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2240][D:\基本程序\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
[D:\基本程序\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
[D:\基本程序\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
[D:\基本程序\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[D:\基本程序\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[D:\基本程序\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\基本程序\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[D:\基本程序\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[D:\基本程序\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2304][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\nvappfilter.dll] [NVIDIA, 1, 0, 2, 0]
[PID: 1160][C:\WINDOWS\system32\taskmgr.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 320][D:\Tencent\QQ\QQ.exe] [TENCENT, 0, 0, 0, 0]
[D:\Tencent\QQ\QQBaseClassInDll.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\QQHelperDll.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\BasicCtrlDll.dll] [Tencent, 5, 0, 200, 370]
[D:\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Tencent\QQ\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[D:\Tencent\QQ\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[D:\Tencent\QQ\QQAPI.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[D:\Tencent\QQ\LoginCtrl.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\npkcntc.dll] [INCA Internet Co., Ltd., 2006, 6, 27, 1]
[D:\Tencent\QQ\npkpdb.dll] [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[D:\Tencent\QQ\QQRes.dll] [tencent, 1, 0, 0, 1]
[D:\Tencent\QQ\QQMainFrame.dll] [N/A, N/A]
[D:\Tencent\QQ\CQQApplication.dll] [N/A, N/A]
[C:\WINDOWS\system32\nvappfilter.dll] [NVIDIA, 1, 0, 2, 0]
[D:\Tencent\QQ\NewSkin.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\HostingMgr.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\CameraDll.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\MailSummary.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\QQSpace.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\vbscript.dll] [Microsoft Corporation, 5.6.0.8825]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[D:\Tencent\QQ\QQGroupMng.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\GroupLive.dll] [N/A, N/A]
[D:\Tencent\QQ\QQSysMsgMng.dll] [N/A, N/A]
[D:\Tencent\QQ\UserDefinedHead.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\QQPlugin.dll] [N/A, N/A]
[D:\Tencent\QQ\QQConfigPlugin.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\QQPet.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[D:\Tencent\QQ\QRingMng.dll] [N/A, N/A]
[D:\Tencent\QQ\PhoneAPI.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[D:\Tencent\QQ\VPortal.dll] [, 1, 0, 0, 4]
[D:\Tencent\QQ\QQAvatar.dll] [N/A, N/A]
[D:\Tencent\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[D:\Tencent\QQ\LongConnection.dll] [tencent, 5, 0, 200, 160]
[D:\Tencent\QQ\BQQApplication.dll] [N/A, N/A]
[D:\Tencent\QQ\CommercesMng.dll] [, 1, 0, 0, 1]
[D:\Tencent\QQ\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
[D:\Tencent\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 240]
[D:\Tencent\QQ\QQSceneMng.dll] [N/A, N/A]
[D:\Tencent\QQ\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 1, 3, 30]
[D:\Tencent\QQ\QQAllInOne.dll] [N/A, N/A]
[D:\Tencent\QQ\SCCore.dll] [TENCENT, 2, 0, 0, 1]
[D:\Tencent\QQ\QQCustomFace.dll] [N/A, N/A]
[D:\Tencent\QQ\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Tencent\QQ\ImageOle.dll] [TODO: <Company name>, 1.0.0.1]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[D:\基本程序\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[D:\Tencent\QQ\GroupConnection.dll] [Tencent, 0, 3, 3, 5]
[D:\Tencent\QQ\QQZip.dll] [tencent, 0, 3, 2, 4]
[PID: 3876][D:\Tencent\QQ\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\SYSTEM32\SEKEY.DLL] [N/A, N/A]
[D:\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 2108][D:\Tencent\QQ宠物管家\PetDoctor.exe] [N/A, N/A]
[D:\Tencent\QQ宠物管家\petskinhook.dll] [N/A, N/A]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\nvappfilter.dll] [NVIDIA, 1, 0, 2, 0]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[D:\基本程序\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 2948][D:\Tencent\QQ\qqpet\qqpet.exe] [腾讯公司, 2, 43, 101, 2]
[D:\Tencent\QQ\qqpet\Pnet.dll] [N/A, N/A]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Tencent\QQ\qqpet\QQPetResDownload.dll] [, 6, 1, 101, 1]
[D:\Tencent\QQ\qqpet\QQPetCommunity.dll] [, 6, 3, 101, 1]
[C:\WINDOWS\system32\nvappfilter.dll] [NVIDIA, 1, 0, 2, 0]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[D:\基本程序\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[D:\Tencent\QQ宠物管家\petskinhook.dll] [N/A, N/A]
[PID: 2512][D:\Tencent\QQ宠物管家\QQPetSkinMonitor.exe] [N/A, N/A]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3376][D:\网站浏览器\Maxthon\Max.exe] [Maxthon International Ltd., 1, 5, 3, 18]
[D:\网站浏览器\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 17.0.54.0]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42]
[C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CorperfmonExt.dll] [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
[C:\WINDOWS\system32\nvappfilter.dll] [NVIDIA, 1, 0, 2, 0]
[D:\网站浏览器\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[D:\基本程序\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[D:\网络电视\SBVT\NMCMPEG2Demux.dll] [N/A, N/A]
[D:\网络电视\SBVT\NMCMPEG2HDDemux.dll] [N/A, N/A]
[D:\媒体播放\Storm Codec\Codecs\empgdmx.ax] [Elecard Ltd., 1, 0, 19, 51017]
[C:\WINDOWS\system32\ffdshow.ax] [N/A, 1.0.2.1997]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll] [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
[C:\WINDOWS\system32\UNISPIM5.IME] [北京紫光华宇软件股份有限公司, 5.0.0.5091]
[PID: 2396][D:\媒体播放\千千静听\TTPlayer.exe] [Alen Soft, 4, 6, 8, 0]
[D:\媒体播放\千千静听\ttpcomm.dll] [N/A, N/A]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\媒体播放\千千静听\ttpres.dll] [Alen Soft, 4, 6, 8, 0]
[D:\媒体播放\千千静听\msdmo.dll] [Microsoft Corporation, 6.03.01.0400]
[PID: 2624][C:\WINDOWS\system32\NOTEPAD.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2196][D:\下载工具\BitComet\BitComet.exe] [www.BitComet.com, 0.70]
[D:\下载工具\BitComet\dbghelp.dll] [Microsoft Corporation, 6.3.0011.3 (DbgBuild.040120-1256)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\nvappfilter.dll] [NVIDIA, 1, 0, 2, 0]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[D:\基本程序\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 17.0.54.0]
[PID: 2696][D:\下载工具\FlashGet\FlashGet.exe] [Amaze Soft, 1, 7, 1, 0]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\nvappfilter.dll] [NVIDIA, 1, 0, 2, 0]
[PID: 2972][C:\Documents and Settings\晨风\桌面\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\nvappfilter.dll] [NVIDIA, 1, 0, 2, 0]
[C:\Documents and Settings\晨风\桌面\Plugins\SRECXTMG.SRE] [Smallfrogs Studio, 1, 5, 0, 55]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
NVIDIA App Filter over [MSAFD Tcpip [TCP/IP]]
C:\WINDOWS\system32\nvappfilter.dll(NVIDIA, NVIDIA IAM LSP)
NVIDIA App Filter over [MSAFD Tcpip [UDP/IP]]
C:\WINDOWS\system32\nvappfilter.dll(NVIDIA, NVIDIA IAM LSP)
NVIDIA App Filter over [MSAFD Tcpip [RAW/IP]]
C:\WINDOWS\system32\nvappfilter.dll(NVIDIA, NVIDIA IAM LSP)
NVIDIA App Filter
C:\WINDOWS\system32\nvappfilter.dll(NVIDIA, NVIDIA IAM LSP)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 serial.alcohol-soft.com
==================================
API HOOK
N/A
==================================
[/CODE]
newcenturymoon - 2007-1-16 18:22:00
安全模式下
打开sreng 启动项目
服务 win32服务应用程序
把隐藏微软已经验证的钩挑上
找到RSVPE / Smarytcer RSVP
选中删除服务 然后设置
双击我的电脑-工具-文件夹选项-查看-显示所有文件和文件夹,把“隐藏受保护的系统文件”的勾去掉。
然后删除C:\WINDOWS\system32\servce
1
© 2000 - 2026 Rising Corp. Ltd.