瑞星卡卡安全论坛
xinshouhaoxue - 2007-1-18 13:17:00
症状:双击移动硬盘符大不开,右见单击打开,打不开;
显示隐藏文件,没有autorun.inf
求助!
水树雨下 - 2007-1-18 13:19:00
mizuki.ys168.com下载sreng2扫个日志上来,一次贴不完分段贴,不要修改
xinshouhaoxue - 2007-1-18 13:41:00
[CODE]
2007-01-18,13:22:18
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
xinshouhaoxue - 2007-1-18 13:42:00
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<MsnMsgr><rem "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [N/A]
<myZt2><C:\DOCUME~1\Owner\LOCALS~1\Temp\Zt2\SVCH0ST.EXE> [N/A]
<CTFMON.EXE><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<Sametime Connect><"C:\Program Files\lotus\Sametime Client\Connect.exe"> [Lotus Development Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<IMSCMig><rem C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<MSConfig><rem C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto> [(Verified)Microsoft Corporation]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
<QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.]
<iTunesHelper><"C:\Program Files\iTunes\iTunesHelper.exe"> [(Verified)Apple Computer, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><C:\WINDOWS\system32\SoDAHK.DLL> [Sogou.com Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
==================================
xinshouhaoxue - 2007-1-18 13:42:00
==================================
服务
[Application Management / AppMgmt][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
<C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Autodesk Licensing Service / Autodesk Licensing Service][Running/Auto Start]
<"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><N/A>
[C-DillaCdaC11BA / C-DillaCdaC11BA][Running/Auto Start]
<C:\WINDOWS\system32\drivers\CDAC11BA.EXE><Macrovision>
[Internet Protect Service / DATEING][Stopped/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLL.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[iPod Service / iPod Service][Running/Manual Start]
<"C:\Program Files\iPod\bin\iPodService.exe"><Apple Computer, Inc.>
[Multi-user Cleanup Service / Multi-user Cleanup Service][Running/Auto Start]
<"C:\Program Files\lotus\notes\ntmulti.exe"><IBM Corp>
[P4P Service / P4P Service][Running/Auto Start]
<C:\Program Files\Common Files\Sogou PXP\p2psvr.exe><Sohu.com Inc.>
[Pml Driver HPZ12 / Pml Driver HPZ12][Running/Auto Start]
<C:\WINDOWS\system32\HPZipm12.exe><HP>
[Rising Proxy Service / RfwProxySrv][Stopped/Manual Start]
<c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
<C:\Program Files\Rising\Rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd][Stopped/Manual Start]
<"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><NetGroup - Politecnico di Torino>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe windhcp.ocx,start><Microsoft Corporation>
==================================
xinshouhaoxue - 2007-1-18 13:43:00
驱动程序
[555753796 / 555753796][Running/Boot Start]
<\SystemRoot\System32\drivers\555753796.sys><N/A>
[ADProt / ADProt][Stopped/System Start]
<\SystemRoot\system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司>
[aeaudio / aeaudio][Running/Manual Start]
<system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[CdaC15BA / CdaC15BA][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\CDAC15BA.SYS><Macrovision Europe Ltd>
[cdhgcggd / cdhgcggd][Stopped/Boot Start]
<\SystemRoot\system32\drivers\cdhgcggd.sys><N/A>
[Intel(R) PRO Adapter Driver / E100B][Running/Manual Start]
<system32\DRIVERS\e100b325.sys><Intel Corporation>
[ExpScaner / ExpScaner][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[GEARAspiWDM / GEARAspiWDM][Running/Manual Start]
<System32\Drivers\GEARAspiWDM.sys><GEAR Software Inc.>
[HookCont / HookCont][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl][Running/Auto Start]
<\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[ialm / ialm][Running/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[imufzrhj / imufzrhj][Running/Boot Start]
<\SystemRoot\system32\drivers\imufzrhj.sys><>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs][Running/Auto Start]
<\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[msqmx / msqmx][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msqmx.sys><N/A>
[NetGroup Packet Filter Driver / NPF][Stopped/Manual Start]
<system32\drivers\npf.sys><NetGroup - Politecnico di Torino>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\PxHelp20.sys><Sonic Solutions>
[RsFwDrv / RsFwDrv][Running/Auto Start]
<\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[SENSE4 v2.0 / SENSE4v2][Stopped/Auto Start]
<System32\Drivers\SENSE4v2.sys><Beijing Senselock Inc>
[sentemul / sentemul][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\sentemul.sys><N/A>
[Sentinel / Sentinel][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\sentinel.sys><Rainbow Technologies, Inc.>
[smwdm / smwdm][Running/Manual Start]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[Rainbow USB SuperPro / Sntnlusb][Stopped/Manual Start]
<system32\DRIVERS\SNTNLUSB.SYS><Rainbow Technologies Inc.>
[XScanPF / XScanPF][Stopped/Manual Start]
<\??\C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX00.312\X-Scan-v3.3\dat\xpf.sys><N/A>
==================================
xinshouhaoxue - 2007-1-18 13:44:00
浏览器加载项
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[CPub Object]
{0CA51D02-7739-43EA-8D9A-1E8AD4327B03} <C:\Program Files\P4P\sodaie.dll, Sogou.com Inc.>
[Cbho Object]
{352E3B3A-CAB5-4DBC-B940-C7F84D0447D8} <C:\PROGRA~1\CNNIC\Cdn\cdndrag.dll, N/A>
[]
{669751ED-D558-49AE-B01A-3B374CC7910E} <C:\WINDOWS\system32\ssup.dll, TENCENT>
[Google Toolbar Helper]
{AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[Adobe PDF Conversion Toolbar Helper]
{AE7CD045-E861-484f-8273-0445EE161910} <C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[免费精彩视频超流畅在线观看]
{022C4009-5283-4365-97BF-144054B40E2E} <http://itv.mop.com, N/A>
[MSN Shell 4]
{0713E8D2-850A-101B-AFC0-4210102A8DA7} <C:\Program Files\MSNShell\Bin\MSNShell.exe, N/A>
[我的订阅]
{8755CE6E-0BF7-4441-8751-FB728941B0B4} <C:\Program Files\P4P\rss.dll, Sohu.com Inc.>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Adobe PDF]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} <C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[雅虎助手]
{406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, yahoo! china>
[捜狗直通车]
{DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} <C:\Program Files\P4P\ToolBar.dll, Sogou.com Inc.>
[MMCPlayer Class]
{05C1004E-2596-48E5-8E26-39362985EEB9} <C:\WINDOWS\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
[MSN Photo Upload Tool]
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[pCastPanel Class]
{FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} <C:\WINDOWS\system32\pCastCtl.dll, N/A>
[Google Script Object]
{00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[ActiveMovieControl Object]
{05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[MMCPlayer Class]
{05C1004E-2596-48E5-8E26-39362985EEB9} <C:\WINDOWS\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Microsoft ProgressBar Control, version 5.0 (SP2)]
{0713E8D2-850A-101B-AFC0-4210102A8DA7} <C:\WINDOWS\system32\COMCTL32.OCX, Microsoft Corporation>
[CPub Object]
{0CA51D02-7739-43EA-8D9A-1E8AD4327B03} <C:\Program Files\P4P\sodaie.dll, Sogou.com Inc.>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[XML DOM Document]
{2933BF90-7B36-11D2-B20E-00C04F983E60} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[Cbho Object]
{352E3B3A-CAB5-4DBC-B940-C7F84D0447D8} <C:\PROGRA~1\CNNIC\Cdn\cdndrag.dll, N/A>
[QuickTime Object]
{4063BE15-3B08-470D-A0D5-B37161CFFD69} <C:\Program Files\QuickTime\QTPlugin.ocx, Apple Computer, Inc.>
[雅虎助手]
{406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, yahoo! china>
[Microsoft Office Control]
{4453D895-F2A1-4A38-A285-1EF9BD3F6D5D} <C:\PROGRA~1\MICROS~2\OFFICE11\AUTHZAX.DLL, Microsoft Corporation>
[WEBChatRoomOCX Control]
{448A5F6B-8C03-4B54-A338-F00237C508AD} <C:\PROGRA~1\sina\UCWEBC~1\UCWEBC~1.OCX, N/A>
[Adobe PDF]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} <C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[]
{4F07F79F-087F-42CF-8B36-7A88D06088E9} <"C:\PROGRA~1\MSNMES~1\msgsc.dll", N/A>
[MSN Photo Upload Tool]
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
[Yahoo!Live]
{57421194-58FB-49AE-9B4F-FD48869B9AD4} <C:\Program Files\Yahoo!\Assistant\yalive.dll, yahoo! china>
[Microsoft Shell UI Helper]
{64AB4BB7-111E-11D1-8F79-00C04FC2FBE1} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
[]
{669751ED-D558-49AE-B01A-3B374CC7910E} <C:\WINDOWS\system32\ssup.dll, TENCENT>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[我的订阅]
{8755CE6E-0BF7-4441-8751-FB728941B0B4} <C:\Program Files\P4P\rss.dll, Sohu.com Inc.>
[Microsoft Web Browser]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
[Google Toolbar Helper]
{AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[Adobe PDF Conversion Toolbar Helper]
{AE7CD045-E861-484F-8273-0445EE161910} <C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[3721]
{B83FC273-3522-4CC6-92EC-75CC86678DA4} <C:\WINDOWS\Downloaded Program Files\CnsMin.dll, 北京三七二一科技有限公司>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[AUDIO__MP3 Moniker Class]
{CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
{CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[捜狗直通车]
{DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} <C:\Program Files\P4P\ToolBar.dll, Sogou.com Inc.>
[Detector Class]
{DEEE7FE9-3E06-43EE-B04D-18866CD0AD9C} <C:\Program Files\P4P\ToolBar.dll, Sogou.com Inc.>
[XML HTTP Request]
{ED8C108E-4349-11D2-91A4-00C04F7969E8} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[XML DOM Document]
{F6D90F11-9C73-11D3-B32E-00C04F990BB4} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[pCastPanel Class]
{FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} <C:\WINDOWS\system32\pCastCtl.dll, N/A>
[&使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
<, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到eREAD表情]
<, N/A>
[添加到QQ自定义面板]
<, N/A>
[添加到QQ表情]
<, N/A>
[添加到“我的订阅”]
<C:\Program Files\P4P\rss.htm, N/A>
[用QQ彩信发送该图片]
<, N/A>
[设为 Messenger Live 头像]
<C:\Program Files\MSNShell\BIN\SetMSNDP.htm, N/A>
[转换为 Adobe PDF]
<res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[转换为现有 PDF]
<res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[转换选定的链接为 Adobe PDF]
<res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html, N/A>
[转换选定的链接为现有 PDF]
<res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html, N/A>
[转换选项为 Adobe PDF]
<res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[转换选项为现有 PDF]
<res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[转换链接目标为 Adobe PDF]
<res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[转换链接目标为现有 PDF]
<res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[雅虎搜索]
<res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/203, N/A>
==================================
xinshouhaoxue - 2007-1-18 13:47:00
正在运行的进程
[PID: 612][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 700][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 724][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.3762]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.3762]
[PID: 768][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 780][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 932][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1012][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1096][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 1116][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1156][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1324][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1440][C:\Program Files\Rising\Rfw\rfwsrv.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 30]
[C:\Program Files\Rising\Rfw\RfwRule.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 3]
[C:\Program Files\Rising\Rfw\rfwlog.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 2]
[C:\Program Files\Rising\Rfw\Rfwdrv.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 10]
[C:\Program Files\Rising\Rfw\MonDrv.dll] [rs, 1, 0, 0, 4]
[C:\Program Files\Rising\Rfw\ProcLib.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 5]
[C:\Program Files\Rising\Rfw\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[PID: 1560][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\AdobePDF.dll] [Adobe Systems Incorporated., 7.0.0.00]
[C:\Program Files\Adobe\Acrobat 7.0\Distillr\AdistRes.CHS] [N/A, N/A]
[C:\WINDOWS\system32\hptcpmon.dll] [Hewlett Packard, 2.50.01.004]
[C:\WINDOWS\system32\HPZJSN01.dll] [Hewlett Packard Company, 1, 0, 0, 3]
[C:\WINDOWS\system32\hpzjfw01.dll] [Hewlett-Packard, 4.02.009.0]
[C:\WINDOWS\system32\HPTcpMUI.dll] [Microsoft Corporation, 2.50.01.004]
[C:\WINDOWS\system32\hptcpmib.dll] [Hewlett Packard, 2.50.01.005]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\hpzpp051.DLL] [Hewlett-Packard Corporation, 60.051.42.00]
[PID: 1608][C:\WINDOWS\System32\SCardSvr.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1928][C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe] [N/A, 2.51.000]
[PID: 2000][C:\WINDOWS\system32\drivers\CDAC11BA.EXE] [Macrovision, 4.20.020]
[PID: 148][C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe] [Microsoft Corporation, 7.00.9466]
[PID: 204][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] [Autodesk, 16.1.63.0]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS] [Adobe Systems, Inc., 7.0.0.0]
[C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.3762]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.3762]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.3762]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.3762]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3.0.0.3762]
[C:\Program Files\Kingsoft\XDict\Cjktl32.dll] [N/A, N/A]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\WINDOWS\system32\contmenu.dll] [N/A, N/A]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3.0.0.3762]
[C:\Program Files\Common Files\Autodesk Shared\dwf Common\DWFShellExtensionRes.dll] [Autodesk, Inc., 1.1.0.340]
[C:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.chs] [Adobe Systems Inc., 7.0.5.2005092300\0]
[C:\WINDOWS\system32\socul.dll] [, 1, 0, 1, 3]
[PID: 220][C:\Program Files\Rising\Rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 66]
[C:\Program Files\Rising\Rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 31]
[C:\Program Files\Rising\Rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[C:\Program Files\Rising\Rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\Rising\Rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Kingsoft\XDict\Cjktl32.dll] [N/A, N/A]
[PID: 264][C:\Program Files\lotus\notes\ntmulti.exe] [IBM Corp, 6.0.40.4008]
[PID: 332][C:\WINDOWS\system32\HPZipm12.exe] [HP, 9, 0, 0, 0]
[PID: 704][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3427]
[C:\Program Files\Kingsoft\XDict\Cjktl32.dll] [N/A, N/A]
[PID: 1092][C:\Program Files\QuickTime\qttask.exe] [Apple Computer, Inc., 7.1.3]
[C:\Program Files\Kingsoft\XDict\Cjktl32.dll] [N/A, N/A]
[PID: 1140][C:\Program Files\iTunes\iTunesHelper.exe] [Apple Computer, Inc., 7.0.2.16]
[C:\Program Files\iTunes\iTunesHelper.Resources\zh_CN.lproj\iTunesHelperLocalized.DLL] [Apple Computer, Inc., 7.0.2.1]
[C:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.DLL] [Apple Computer, Inc., 7.0.2.16]
[C:\Program Files\Kingsoft\XDict\Cjktl32.dll] [N/A, N/A]
[PID: 1184][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Kingsoft\XDict\Cjktl32.dll] [N/A, N/A]
[PID: 544][C:\Program Files\iPod\bin\iPodService.exe] [Apple Computer, Inc., 7.0.2.16]
[C:\Program Files\iPod\bin\iPodService.Resources\zh_CN.lproj\iPodServiceLocalized.DLL] [Apple Computer, Inc., 7.0.2.1]
[C:\Program Files\iPod\bin\iPodService.Resources\iPodService.DLL] [Apple Computer, Inc., 7.0.2.16]
[PID: 1264][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2236][C:\Program Files\Kingsoft\XDict\XDICT.EXE] [Kingsoft Co, Ltd., 5, 5, 0, 0]
[C:\Program Files\Kingsoft\XDict\IHooks.dll] [N/A, N/A]
xinshouhaoxue - 2007-1-18 13:52:00
[C:\Program Files\Kingsoft\XDict\IHooks.dll] [N/A, N/A]
[C:\Program Files\Kingsoft\XDict\ITextOut.dll] [N/A, N/A]
[C:\Program Files\Kingsoft\XDict\CJKTAB32.dll] [N/A, N/A]
[C:\Program Files\Kingsoft\XDict\XImage32.dll] [N/A, N/A]
[C:\Program Files\Kingsoft\XDict\NewWord.dll] [N/A, N/A]
[C:\Program Files\Kingsoft\XDict\xfile.dll] [N/A, N/A]
[C:\Program Files\Kingsoft\XDict\ITTSEngine.dll] [N/A, N/A]
[C:\Program Files\Kingsoft\XDict\Cjktl32.dll] [N/A, N/A]
[PID: 2384][C:\Program Files\Rising\Rav\RsAgent.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Kingsoft\XDict\Cjktl32.dll] [N/A, N/A]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[PID: 2424][C:\WINDOWS\msagent\AgentSvr.exe] [Microsoft Corporation, 2.00.0.3424]
[C:\Program Files\Kingsoft\XDict\Cjktl32.dll] [N/A, N/A]
[PID: 2072][C:\Program Files\Rising\Rav\RAVTASK.EXE] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Kingsoft\XDict\Cjktl32.dll] [N/A, N/A]
xinshouhaoxue - 2007-1-18 13:53:00
[PID: 2156][C:\Program Files\Rising\Rav\Ravmond.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 43]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\rfwctrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[C:\Program Files\Rising\Rav\RsPPsys.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RsLog.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\HOOKSYS.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
[C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
[C:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[C:\Program Files\Rising\Rav\regmon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\HookWeb.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[C:\Program Files\Rising\Rav\MemMon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
[C:\Program Files\Rising\Rav\expscan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[C:\Program Files\Rising\Rav\HookCont.dll] [Rising, 19, 0, 0, 0]
[C:\Program Files\Rising\Rav\SpamEng.dll] [N/A, 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\engine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
[C:\Program Files\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[C:\Program Files\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 34]
[C:\Program Files\Rising\Rav\ExtFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 23]
[C:\Program Files\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[C:\Program Files\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
[C:\Program Files\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[C:\Program Files\Rising\Rav\Unpacker.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
[C:\Program Files\Rising\Rav\ScanPack.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 18]
[C:\Program Files\Rising\Rav\RsVM.dll] [N/A, 19, 0, 0, 13]
[C:\Program Files\Rising\Rav\Uroutine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[C:\Program Files\Rising\Rav\RsStore.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\Rising\Rav\ExtOLE.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[C:\Program Files\Rising\Rav\Uscript.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
[C:\Program Files\Rising\Rav\ScanNet.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\ExtMail.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
[C:\Program Files\Rising\Rav\ScanElf.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
xinshouhaoxue - 2007-1-18 13:54:00
[PID: 2204][C:\Program Files\Rising\Rav\RAVMON.EXE] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
[C:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Kingsoft\XDict\Cjktl32.dll] [N/A, N/A]
[PID: 1400][C:\Program Files\Rising\Rav\RavStub.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 212][C:\Program Files\lotus\notes\NLNOTES.EXE] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nnotesws.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nnotes.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nxmlpar.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nxmlcommon.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\js32.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\NLSCCSTR.DLL] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\ndgts.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\LTOUIN22.dll] [Lotus Development Corporation., 2.2.0.8911]
[C:\Program Files\lotus\notes\nplugins.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\Kingsoft\XDict\Cjktl32.dll] [N/A, N/A]
[C:\Program Files\lotus\notes\NSTRINGS.DLL] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nRsVirHD.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[C:\Program Files\lotus\notes\nRsScan.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[C:\Program Files\lotus\notes\namhook.DLL] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nRsVirEM.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[C:\Program Files\lotus\notes\nTCP.DLL] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nNETBIOS.DLL] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nstclientu.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nimuiu.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nimuires.dll] [, 3, 1, 0, 1]
[C:\Program Files\lotus\notes\nNTCP.DLL] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nlsxbe.DLL] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\njemp.DLL] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\jvm\bin\classic\jvm.DLL] [IBM, 131,0,2003,0329]
[C:\Program Files\lotus\notes\jvm\bin\xhpi.dll] [IBM, 131,0,2003,0329]
[C:\Program Files\lotus\notes\jvm\bin\hpi.dll] [IBM, 131,0,2003,0329]
[C:\Program Files\lotus\notes\jvm\bin\java.dll] [IBM, 131,0,2003,0329]
[C:\Program Files\lotus\notes\jvm\bin\classic\core.dll] [IBM, 131,0,2003,0329]
[C:\Program Files\lotus\notes\jvm\bin\zip.dll] [IBM, 131,0,2003,0329]
[C:\Program Files\lotus\notes\jvm\bin\awt.dll] [IBM, 131,0,2003,0329]
[C:\Program Files\lotus\notes\jvm\bin\fontmanager.dll] [IBM, 131,0,2003,0329]
[C:\WINDOWS\system32\ialmgicd.dll] [Intel Corporation, 6.14.10.3762]
[C:\WINDOWS\system32\ialmgdev.dll] [Intel Corporation, 6.14.10.3762]
[C:\Program Files\lotus\notes\jvm\bin\net.dll] [IBM, 131,0,2003,0329]
[C:\Program Files\lotus\notes\nFTGTR40.DLL] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\gtr40nts.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nlxlid102.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nlxrt22.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nlxsum22.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\kvfilter.dll] [Verity, Inc., Build 1797]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86]
[C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] [Autodesk, 16.1.63.0]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS] [Adobe Systems, Inc., 7.0.0.0]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.3762]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.3762]
[C:\Program Files\Common Files\Adobe\Shell\PSICON.DLL] [Adobe Systems, Incorporated, 7.0]
[C:\WINDOWS\system32\contmenu.dll] [N/A, N/A]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\PROGRA~1\彩色文~1\cmext.dll] [Revenger inc., 1.2.1.2]
xinshouhaoxue - 2007-1-18 13:54:00
[PID: 3276][C:\Program Files\lotus\notes\ntaskldr.EXE] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nnotes.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nxmlpar.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nxmlcommon.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\js32.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\NLSCCSTR.DLL] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\ndgts.dll] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\NSTRINGS.DLL] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nRsVirHD.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[C:\Program Files\lotus\notes\nRsScan.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[C:\Program Files\lotus\notes\namhook.DLL] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nRsVirEM.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[C:\Program Files\lotus\notes\nhkdaemn.DLL] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nhldaemn.DLL] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nTCP.DLL] [IBM Corp, 6.5.10.4008]
[C:\Program Files\lotus\notes\nNETBIOS.DLL] [IBM Corp, 6.5.10.4008]
[PID: 3324][C:\Program Files\Common Files\Sogou PXP\p2psvr.exe] [Sohu.com Inc., 2, 0, 0, 22]
[C:\Program Files\P4P\tbupdate.dll] [Sogou.com Inc., 1, 0, 1, 1]
[C:\Program Files\P4P\p4pipc.dll] [Sogou.com Inc., 1, 0, 0, 13]
[C:\Program Files\P4P\SoDALib.dll] [Sohu.com Inc., 1, 2, 1, 7]
[PID: 3688][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
[C:\WINDOWS\system32\SoDAHK.DLL] [Sogou.com Inc., 1, 0, 1, 5]
[C:\Program Files\Kingsoft\XDict\Cjktl32.dll] [N/A, N/A]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx] [Macromedia, Inc., 8,0,24,0]
[PID: 2760][C:\Program Files\WinRAR\WinRAR.exe] [Alexander Roshal, 3.42]
[C:\Program Files\Kingsoft\XDict\Cjktl32.dll] [N/A, N/A]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86]
[PID: 1856][C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX00.390\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\Program Files\Kingsoft\XDict\Cjktl32.dll] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
219.238.46.142 csci
218.244.245.246 cscec
==================================
API HOOK
N/A
==================================
[/CODE]
xinshouhaoxue - 2007-1-18 13:56:00
终于上传完毕,请帮助分析解决谢谢!
水树雨下 - 2007-1-18 13:56:00
运行sreng2启动项目,注册表删除
myZt2><C:\DOCUME~1\Owner\LOCALS~1\Temp\Zt2\SVCH0ST.EXE> [N/A]
启动项目,服务,win32服务应用程序,勾选隐藏微软服务后删除
[Internet Protect Service / DATEING][Stopped/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLL.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe windhcp.ocx,start><Microsoft Corporation>
服务,驱动程序删除
555753796 / 555753796][Running/Boot Start]
<\SystemRoot\System32\drivers\555753796.sys><N/A>
XScanPF / XScanPF][Stopped/Manual Start]
<\??\C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX00.312\X-Scan-v3.3\dat\xpf.sys><N/A>
安全模式下我的电脑,工具,文件夹选项,查看,显示所有文件和文件夹,把“隐藏受保护的系统文件”的勾去掉删除
C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL
windhcp.ocx
C:\WINDOWS\System32\drivers\555753796.sys
清空这个文件夹C:\DOCUME~1\Owner\LOCALS~1\Temp\
清理HOSTS
把移动硬盘接到电脑上,不要用自动运行,用winrar打开看硬盘里有无文件
xinshouhaoxue - 2007-1-18 14:37:00
万分感谢,问题解决了,但我想问和学习一下问题的原因和解决的过程,不知你是否方便解答一下,也好让我自己学习提高一下,谢谢
水樹雨下 - 2007-1-18 14:39:00
多到这里看
xinshouhaoxue - 2007-1-18 14:53:00
我经常来看的,但由于基础知识的匮乏,很吃力,不知道您有什么适合我这种初学者学习的材料之累的,提供些学学,可以吗?我将万分感谢的!
水樹雨下 - 2007-1-18 14:55:00
其实也没什么简单的办法,就是熟悉系统进程,多看,多想,不知道的百度一下,比看书有用多了
UFO不幸外人 - 2007-1-18 15:11:00
再补充一点,多实践,多提问,多分析,才能学习更多的知识
MacNab - 2007-1-18 15:13:00
当你杀毒未果,然后自己重装系统超过10次以后,你就是高手了.呵呵.
水樹雨下 - 2007-1-18 15:19:00
| 引用: |
【MacNab的贴子】当你杀毒未果,然后自己重装系统超过10次以后,你就是高手了.呵呵. ……………… |
等你感慨为什么别人不中毒,而我会中毒,我中了毒杀不掉,而别人能却能杀,你将来就会变成高手
UFO不幸外人 - 2007-1-18 15:22:00
哇,楼上两位说的好有哲理,就是没有看懂,哈哈哈哈哈哈
MacNab - 2007-1-18 15:25:00
我感慨啊,我慨感啊.病毒啊,你为什么总不光临我的机器啊.
附件:
7645232007118151554.JPG
UFO不幸外人 - 2007-1-18 15:27:00
什么软件,介绍一下,我来看看我用不用,估计比较好的软件 高手
哎 想让病毒光临很简单,进入挂马网页就是了
比如http://www.9ifree.cn
太史悟寒 - 2007-1-18 15:27:00
有什么希奇的 我都3000多经验了 还没学到什么! 全都是灌水灌的^^
1
© 2000 - 2026 Rising Corp. Ltd.