瑞星卡卡安全论坛
Crosy - 2007-1-29 9:13:00
我的问题是,每天早上开机的时候,到11点钟这段时间,就时不时的弹出iexplore,在进程里就会出现这个ie,用kk看到这样一个进程信息
[iexplore.exe]
PID = 0x95c
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe" -k "http://www.2100book.com/ "
而且后面的参数(即网站名)会发生变化。这是怎么回事啊?我看了所有的关于这个问题的解决方法,在我这里都不行,到底是怎么回事啊?
下面是SREng扫描日志
[CODE]
2007-01-29,08:54:36
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows Server 2003 Standard Edition Service Pack 1 (Build 3790)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<igfxhkcmd><C:\WINDOWS\system32\hkcmd.exe> [Intel Corporation]
<igfxpers><C:\WINDOWS\system32\igfxpers.exe> [Intel Corporation]
<SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> [Synaptics, Inc.]
<QlbCtrl><%ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start> [ Hewlett-Packard Development Company, L.P.]
<ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"> [(Verified)Symantec Corporation]
<vptray><C:\PROGRA~1\SYMANT~1\VPTray.exe> [(Verified)Symantec Corporation]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<High Definition Audio Property Page Shortcut><; CHDAudPropShortcut.exe> [Windows (R) Server 2003 DDK provider]
<runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<Acronis Scheduler2 Service><; "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"> [Acronis]
<TrueImageMonitor.exe><; C:\Program Files\Acronis\TrueImageEnterprise\TrueImageMonitor.exe> [Acronis]
<Super Rabbit SRRestore><; C:\PROGRA~1\SUPERR~1\MagicSet\SRRest.exe /FIRST> [Super Rabbit Soft]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><%SystemRoot%\system32\logonui.exe> [(Verified)Microsoft Corporation]
==================================
启动文件夹
[服务管理器]
<C:\Documents and Settings\All Users.WINDOWS\「开始」菜单\程序\启动\服务管理器.lnk --> C:\PROGRA~1\MICROS~1\80\Tools\Binn\sqlmangr.exe [Microsoft Corporation]><N>
==================================
服务
[Acronis Scheduler2 Service / AcrSch2Svc][Stopped/Disabled]
<"C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe"><Acronis>
[AddFiltr / AddFiltr][Stopped/Manual Start]
<"C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe"><Hewlett-Packard Development Company, L.P.>
[Symantec Event Manager / ccEvtMgr][Running/Auto Start]
<"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr][Running/Auto Start]
<"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[Symantec AntiVirus Definition Watcher / DefWatch][Running/Auto Start]
<"C:\Program Files\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[FileCopyService / FileCopyService][Running/Auto Start]
<d:\mis\development\gmcc\gzmis\filecopyservice\install\filecopyservice.exe><>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[hpqwmiex / hpqwmiex][Running/Auto Start]
<C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe><Hewlett-Packard Development Company, L.P.>
[LiveUpdate / LiveUpdate][Stopped/Manual Start]
<"C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE"><Symantec Corporation>
[Machine Debug Manager / MDM][Running/Auto Start]
<"C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"><Microsoft Corporation>
[Microsoft Search / MSSEARCH][Running/Auto Start]
<"C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe"><Microsoft Corporation>
[MSSQLSERVER / MSSQLSERVER][Running/Auto Start]
<C:\PROGRA~1\MICROS~1\MSSQL\binn\sqlservr.exe><Microsoft Corporation>
[MSSQLServerADHelper / MSSQLServerADHelper][Stopped/Manual Start]
<C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe><Microsoft Corporation>
[SavRoam / SavRoam][Stopped/Manual Start]
<"C:\Program Files\Symantec AntiVirus\SavRoam.exe"><symantec>
[Symantec SPBBCSvc / SPBBCSvc][Running/Auto Start]
<"C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"><Symantec Corporation>
[sqlserver support for winnt / sqlservech][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k sqlservech-->c:\windows\system32\sqlservech.dll><Microsoft Corporation>
[SQLSERVERAGENT / SQLSERVERAGENT][Stopped/Manual Start]
<C:\PROGRA~1\MICROS~1\MSSQL\binn\sqlagent.exe><Microsoft Corporation>
[Symantec AntiVirus / Symantec AntiVirus][Running/Auto Start]
<"C:\Program Files\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>
==================================
驱动程序
[atccmm41 / atccmm41][Stopped/Boot Start]
<\SystemRoot\system32\drivers\atccmm41.sys><N/A>
[d347bus / d347bus][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\d347bus.sys><>
[d347prt / d347prt][Running/Boot Start]
<\SystemRoot\System32\Drivers\d347prt.sys><>
[Intel(R) PRO Network Connection Driver / E100B][Running/Manual Start]
<system32\DRIVERS\e100b325.sys><Intel Corporation>
[Symantec Eraser Control driver / eeCtrl][Running/System Start]
<\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys><Symantec Corporation>
[EraserUtilRebootDrv / EraserUtilRebootDrv][Running/Manual Start]
<\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys><Symantec Corporation>
[Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService][Running/Manual Start]
<system32\drivers\CHDAud.sys><Conexant Systems Inc.>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HSFHWAZL / HSFHWAZL][Running/Manual Start]
<system32\DRIVERS\HSFHWAZL.sys><Conexant Systems, Inc.>
[HSF_DPV / HSF_DPV][Running/Manual Start]
<system32\DRIVERS\HSF_DPV.sys><Conexant Systems, Inc.>
[ialm / ialm][Running/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
<system32\DRIVERS\ipinip.sys><N/A>
[mdmxsdk / mdmxsdk][Running/Auto Start]
<system32\DRIVERS\mdmxsdk.sys><Conexant>
[NAVENG / NAVENG][Running/Manual Start]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070128.006\naveng.sys><Symantec Corporation>
[NAVEX15 / NAVEX15][Running/Manual Start]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070128.006\navex15.sys><Symantec Corporation>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\C:\Program Files\Tencent\TM\TMDlls\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[rimmptsk / rimmptsk][Running/Manual Start]
<system32\DRIVERS\rimmptsk.sys><REDC>
[rimsptsk / rimsptsk][Running/Manual Start]
<system32\DRIVERS\rimsptsk.sys><REDC>
[Ricoh xD-Picture Card Driver / rismxdp][Running/Manual Start]
<system32\DRIVERS\rixdptsk.sys><REDC>
[RsAntiSpyware / RsAntiSpyware][Stopped/Disabled]
<\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[SAVRT / SAVRT][Running/System Start]
<\??\C:\Program Files\Symantec AntiVirus\savrt.sys><Symantec Corporation>
[SAVRTPEL / SAVRTPEL][Running/System Start]
<\??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys><Symantec Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[Acronis Snapshots Manager / snapman][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\snapman.sys><Acronis>
[SPBBCDrv / SPBBCDrv][Running/System Start]
<\??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys><Symantec Corporation>
[SymEvent / SymEvent][Running/Disabled]
<\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
<system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[Acronis TrueImage FS Filter / tifsfilter][Running/Auto Start]
<system32\DRIVERS\tifsfilt.sys><Acronis>
[Acronis TrueImage Backup Archive Explorer / timounter][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\timntr.sys><Acronis>
[Conexant Setup API / UIUSys][Stopped/Manual Start]
<system32\DRIVERS\UIUSYS.SYS><N/A>
[vqglzc16 / vqglzc16][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\vqglzc16.sys><Microsoft Corporation>
[Intel(R) PRO/Wireless 3945ABG Adapter Driver / w39n51][Stopped/Manual Start]
<system32\DRIVERS\w39n51.sys><Intel? Corporation>
[winachsf / winachsf][Running/Manual Start]
<system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
zzsd1 - 2007-1-29 9:32:00
试试微 点吧
Crosy - 2007-1-29 9:32:00
正在运行的进程
[PID: 580][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 752][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 888][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 1016][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 1044][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[C:\WINDOWS\system32\relog_ap.dll] [Acronis, 1,0,0,6]
[PID: 1312][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 1472][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 1552][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 1612][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 1624][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 1740][C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.8.3]
[PID: 1812][C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.8.3]
[C:\PROGRA~1\COMMON~1\SYMANT~1\SPBBC\SPBBCEVT.DLL] [Symantec Corporation, 2.2.0.7]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCSETEVT.DLL] [Symantec Corporation, 104.0.8.3]
[PID: 1940][C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe] [Symantec Corporation, 2.2.0.7]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCEvt.dll] [Symantec Corporation, 2.2.0.7]
[C:\Program Files\Common Files\Symantec Shared\SPBBC\bbRGen.dll] [Symantec Corporation, 2.2.0.7]
[PID: 408][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\WINDOWS\system32\spool\PRTPROCS\W32X86\vprproc.dll] [Windows (R) 2000 DDK provider, 5.00.2195.1620]
[PID: 460][C:\WINDOWS\system32\msdtc.exe] [Microsoft Corporation, 2001.12.4720.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 692][C:\Program Files\Symantec AntiVirus\DefWatch.exe] [Symantec Corporation, 10.1.4.4000]
[C:\Program Files\Common Files\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.8.3]
[PID: 780][d:\mis\development\gmcc\gzmis\filecopyservice\install\filecopyservice.exe] [ , 0.0.0.0]
[c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_b4858548\mscorlib.dll] [N/A, N/A]
[c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_0ed20cae\system.dll] [N/A, N/A]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_0622aaef\system.xml.dll] [N/A, N/A]
[PID: 1064][C:\WINDOWS\system32\inetsrv\inetinfo.exe] [Microsoft Corporation, 6.0.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 1264][C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe] [Microsoft Corporation, 7.10.3077]
[PID: 1460][C:\PROGRA~1\MICROS~1\MSSQL\binn\sqlservr.exe] [Microsoft Corporation, 2000.080.0194.00]
[PID: 1720][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 1928][C:\Program Files\Symantec AntiVirus\Rtvscan.exe] [Symantec Corporation, 10.1.4.4000]
[C:\WINDOWS\system32\CBA.DLL] [LANDesk Software Ltd., 6.12.0.142 E]
[C:\WINDOWS\system32\MsgSys.dll] [LANDesk Software Ltd., 6.12.0.142 E]
[C:\WINDOWS\system32\NTS.dll] [LANDesk Software Ltd., 6.12.0.142 E]
[C:\WINDOWS\system32\PDS.DLL] [LANDesk Software Ltd., 6.12.0.142 E]
[C:\Program Files\Symantec AntiVirus\NAVLU.dll] [Symantec Corporation, 10.1.4.4000]
[C:\Program Files\Symantec AntiVirus\I2ldvp3.dll] [Symantec Corporation, 10.1.4.4000]
[C:\Program Files\Common Files\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Symantec AntiVirus\NAVNTUTL.DLL] [Symantec Corporation, 10.1.4.4000]
[c:\program files\common files\symantec shared\ssc\ScsComms.dll] [Symantec Corporation, 10.1.4.4000]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\ccDec.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\decsdk.dll] [Symantec Corporation, 3.02.14.10]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll] [Symantec Corporation, 3.02.14.10]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll] [Symantec Corporation, 3.02.14.10]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll] [Symantec Corporation, 3.02.14.10]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll] [Symantec Corporation, 3.02.14.10]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll] [Symantec Corporation, 3.02.14.10]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll] [Symantec Corporation, 3.02.14.10]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll] [Symantec Corporation, 3.02.14.10]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll] [Symantec Corporation, 3.02.14.10]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll] [Symantec Corporation, 3.02.14.10]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll] [Symantec Corporation, 3.02.14.10]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll] [Symantec Corporation, 3.02.14.10]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll] [Symantec Corporation, 3.02.14.10]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll] [Symantec Corporation, 3.02.14.10]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll] [Symantec Corporation, 3.02.14.10]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll] [Symantec Corporation, 3.02.14.10]
[C:\Program Files\Common Files\Symantec Shared\ccScan.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL] [Symantec Corporation, 51.3.0.11]
[C:\Program Files\Symantec AntiVirus\DefUtDCD.dll] [Symantec Corporation, 3.1.13a.0]
[C:\Program Files\Symantec AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.7.1.4]
[C:\Program Files\Symantec AntiVirus\NotesExt.dll] [Symantec Corporation, 10.1.4.4000]
[C:\Program Files\Symantec AntiVirus\vpmsece4.dll] [Symantec Corporation, 10.1.4.4000]
[C:\Program Files\Symantec AntiVirus\SymProtectStorage.dll] [Symantec Corporation, 10.1.4.4000]
[C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCEvt.dll] [Symantec Corporation, 2.2.0.7]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070128.006\ccEraser.dll] [Symantec Corporation, 106.3.3.2]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070128.006\ecmsvr32.dll] [Symantec Corporation, 71.1.0.11]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070128.006\NAVEX32a.DLL] [Symantec Corporation, 20071.1.0.15]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070128.006\NAVENG32.DLL] [Symantec Corporation, 20071.1.0.15]
[PID: 1296][C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe] [Microsoft Corporation, 9.107.5512.0]
[PID: 2612][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 2704][C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe] [Hewlett-Packard Development Company, L.P., 2, 0, 1, 9]
[PID: 3068][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 3500][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\Program Files\Super Rabbit\MagicSet\srcd.dll] [Super Rabbit Software, 1.02.0002]
[C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll] [Symantec Corporation, 10.1.4.4000]
[C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4543]
[PID: 3600][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 3736][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 3796][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[PID: 1340][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4543]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
Crosy - 2007-1-29 9:35:00
[PID: 728][C:\WINDOWS\system32\igfxpers.exe] [Intel Corporation, 3.0.0.4543]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4543]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2076][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] [Synaptics, Inc., 8.3.8 16Jun06]
[C:\WINDOWS\system32\SynCOM.dll] [Synaptics, Inc., 8.3.8 16Jun06]
[C:\WINDOWS\system32\SynTPAPI.dll] [Synaptics, Inc., 8.3.8 16Jun06]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2108][C:\Program Files\Common Files\Symantec Shared\ccApp.exe] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.8.3]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCALERT.DLL] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2184][C:\PROGRA~1\SYMANT~1\VPTray.exe] [Symantec Corporation, 10.1.4.4000]
[C:\Program Files\Common Files\Symantec Shared\ccL40.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Symantec AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.7.1.4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\ccProSub.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Common Files\Symantec Shared\ccAlert.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Symantec AntiVirus\Cliscan.dll] [Symantec Corporation, 10.1.4.4000]
[C:\Program Files\Symantec AntiVirus\NAVNTUTL.DLL] [Symantec Corporation, 10.1.4.4000]
[C:\Program Files\Common Files\Symantec Shared\ccSet.dll] [Symantec Corporation, 104.0.8.3]
[C:\Program Files\Symantec AntiVirus\Cliproxy.dll] [Symantec Corporation, 10.1.4.4000]
[PID: 2408][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
[C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2488][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1100][C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 3820][C:\Program Files\Microsoft Visual Studio .NET 2003\Common7\IDE\devenv.exe] [Microsoft Corporation, 7.10.3077]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_b4858548\mscorlib.dll] [N/A, N/A]
[c:\windows\assembly\nativeimages1_v1.1.4322\microsoft.vsdesigner\7.0.5000.0__b03f5f7f11d50a3a_adbf1bc2\microsoft.vsdesigner.dll] [N/A, N/A]
[c:\windows\assembly\nativeimages1_v1.1.4322\microsoft.visualstudio\1.0.5000.0__b03f5f7f11d50a3a_f4080e8d\microsoft.visualstudio.dll] [N/A, N/A]
[c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_0ed20cae\system.dll] [N/A, N/A]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_3328266a\system.windows.forms.dll] [N/A, N/A]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_8441e618\system.drawing.dll] [N/A, N/A]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_0622aaef\system.xml.dll] [N/A, N/A]
[PID: 4052][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[PID: 1488][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.3790.1830 (srv03_sp1_rtm.050324-1447)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2640][c:\windows\system32\inetsrv\w3wp.exe] [Microsoft Corporation, 6.0.3790.1830 (srv03_sp1_rtm.050324-1447)]
[c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_b4858548\mscorlib.dll] [N/A, N/A]
[c:\windows\assembly\gac\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\cscompmgd.dll] [ , 7.10.3052.4]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\q4k7odh0.dll] [ , 0.0.0.0]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\c44d45a6\e00b8a67_e03ec701\main.dll] [ , 0.0.0.0]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\5413b1fe\903b3799_0941c701\controls.dll] [ , 1.0.2582.23994]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\d7ec9db1\9f580dc2_553cc701\common.dll] [ , 1.0.2576.24671]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\95d0452e\ef15f4c2_553cc701\email.dll] [ , 1.0.2576.24672]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\62c888f6\10c2044f_cf39c701\expensebs.dll] [ , 1.0.2573.15447]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\a85b48f1\80434479_b03ec701\budgetbs.dll] [ , 1.0.2579.24503]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\9386eb5e\afb94d91_3f3cc701\publicws.dll] [ , 1.0.2576.14194]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\a8968f1d\e076d031_d63dc701\querymanage.dll] [ , 1.0.2578.20828]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\0ea64604\c40c3e9b_b641c701\application.dll] [ , 1.0.2583.17947]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\361580d3\6fb325c4_553cc701\query.dll] [ , 1.0.2576.24673]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\ed686627\40ba7704_5c3fc701\approve.dll] [ , 1.0.2580.18142]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\1739e1d6\30380fae_d83ec701\publicbs.dll] [ , 1.0.2579.33137]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\ad81cbf7\6266a74f_3521c501\textboxdatetime.dll] [ , 1.0.1890.21065]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\d76e7acf\b0ffe27e_7640c701\individuation.dll] [ , 0.0.0.0]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\34564526\00cb9505_dc3ec701\manage.dll] [ , 1.0.2579.33855]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\5170e4a1\60e58e39_3bf3c401\microsoft.applicationblocks.data.dll] [ , 1.0.1831.38173]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\assembly\dl2\0224327d\40417e9b_4739c701\jobaccess.dll] [ , 1.0.2572.29505]
Crosy - 2007-1-29 9:36:00
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\k3jixli0.dll] [N/A, N/A]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\h1rrs9lp.dll] [N/A, N/A]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\rd2ottfa.dll] [N/A, N/A]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\uio2zmsv.dll] [N/A, N/A]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\jue9khcv.dll] [N/A, N/A]
[c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\dgmis\0d4cb8ca\fb297fe4\0xmetcdg.dll] [N/A, N/A]
[PID: 2512][C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5, 5, 4, 268]
[C:\Program Files\Thunder Network\Thunder\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 14]
[C:\Program Files\Thunder Network\Thunder\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 2, 12, 2, 44]
[C:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll] [Thunder Networking Technologies,LTD, 2, 12, 2, 44]
[C:\Program Files\Thunder Network\Thunder\Program\iTargetAD.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 13]
[C:\Program Files\Thunder Network\Thunder\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 8]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\Program Files\Thunder Network\Thunder\Components\DiagnoseHelper\DiagnoseHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 10]
[C:\Program Files\Thunder Network\Thunder\Components\PortVerify\PortVerify.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
[C:\Program Files\Thunder Network\Thunder\Components\ExplorerHelper\ExplorerHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
[C:\Program Files\Thunder Network\Thunder\Components\DTAG\DTAG.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
[C:\Program Files\Thunder Network\Thunder\Program\LiveUpdate.dll] [, 1, 0, 1, 17]
[C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll] [ , 1, 0, 0, 15]
[C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed08.dll] [ , 3, 2, 0, 63]
[C:\Program Files\Thunder Network\Thunder\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 1, 0, 3, 14]
[C:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 2, 1, 43]
[C:\Program Files\Thunder Network\Thunder\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 6]
[C:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 13]
[C:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VPSHELL.dll] [, 1, 0, 0, 1]
[C:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VideoPicture.dll] [XunLei, 1, 0, 0, 1]
[C:\Program Files\Thunder Network\Thunder\Program\msgmanage.dll] [Thunder Networking Technologies,LTD, 2, 0, 1, 38]
[C:\Program Files\Thunder Network\Thunder\Plugins\BhoAdv\bho_adv.dll] [深圳市迅雷网络技术有限公司, 1.0.1.0]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[PID: 3324][D:\Tools\sreng2\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
[/CODE]
1
© 2000 - 2026 Rising Corp. Ltd.