瑞星卡卡安全论坛
lxdnpx - 2007-11-1 22:34:00
正版瑞星总是根除不了,
刚杀了,
前一分钟杀了,还没有杀完全盘,再停下杀一下进程,进程中的CHVOST又感染了。
烦
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.1.4322)
多种病毒携带者 - 2007-11-1 23:36:00
Trojan.DL.Win32.Agent.znj.........这个毒我也中过。。最后是把硬盘直接拆了。拿去电脑公司搞的- -
mopery - 2007-11-2 5:43:00
http://download.kztechs.com/files/sreng2.zip 下载System Repair Engineer
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
lxdnpx - 2007-11-2 17:26:00
[CODE]
2007-11-02,17:02:34
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows Server 2003 Enterprise Edition (Build 3790) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RfwMain><"d:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [N/A]
<ShStatEXE><"C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE> [(Verified)"McAfee, Inc."]
<McAfeeUpdaterUI><"C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey> [(Verified)"McAfee, Inc."]
<LiveUpatePower><C:\Program Files\完美卸载V2007 完整版\MyUpdate.exe -PowerOn> []
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Science and Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><%SystemRoot%\system32\logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [(Verified)Beijing Rising Science and Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ATICCC><; "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay> [N/A]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<MSPY2002><; C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC> [(Verified)Microsoft Windows Publisher]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
<SoundMan><; SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
lxdnpx - 2007-11-2 17:27:00
启动文件夹
N/A
==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Stopped/Disabled]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart][Stopped/Disabled]
<C:\WINDOWS\system32\ati2sgag.exe><>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[McAfee Framework Service / McAfeeFramework][Running/Auto Start]
<"C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart><McAfee, Inc.>
[McAfee McShield / McShield][Running/Auto Start]
<"C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe"><McAfee, Inc.>
[McAfee Task Manager / McTaskManager][Running/Auto Start]
<"C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe"><McAfee, Inc.>
[P4P Service / P4P Service][Running/Auto Start]
<C:\Program Files\Common Files\Sogou PXP\p2psvr.exe><Sohu.com Inc.>
[PnpWMmng / PnpWMmng][Running/Auto Start]
<C:\PROGRA~1\完美卸~1\PnpWMmng.exe><完美卸载>
[Rising Proxy Service / RfwProxySrv][Stopped/Manual Start]
<d:\program files\rising\rfw\rfwproxy.exe><N/A>
[Rising Personal Firewall Service / RfwService][Stopped/Auto Start]
<d:\program files\rising\rfw\rfwsrv.exe><N/A>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
==================================
驱动程序
[Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
<system32\drivers\ALCXSENS.SYS><Sensaura>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AliIde / AliIde][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[ati2mtag / ati2mtag][Running/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[CmdIde / CmdIde][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[EagleNT / EagleNT][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\EagleNT.sys><N/A>
[HookUrl / HookUrl][Stopped/Auto Start]
<\??\d:\Program Files\Rising\Rfw\HookUrl.sys><N/A>
[IGALIVE / IGALIVE][Running/Auto Start]
<\??\C:\Program Files\IGALIVE\IGALIVE.sys><N/A>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
<system32\DRIVERS\ipinip.sys><N/A>
[MegaIDE / MegaIDE][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.>
[McAfee Inc. / mfeapfk][Running/Manual Start]
<system32\drivers\mfeapfk.sys><McAfee, Inc.>
[McAfee Inc. / mfeavfk][Running/Manual Start]
<system32\drivers\mfeavfk.sys><McAfee, Inc.>
[McAfee Inc. / mfebopk][Running/Manual Start]
<system32\drivers\mfebopk.sys><McAfee, Inc.>
[McAfee Inc. / mfehidk][Running/Manual Start]
<system32\drivers\mfehidk.sys><McAfee, Inc.>
[VSCore mferkdk / mferkdk][Running/System Start]
<\??\C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys><McAfee, Inc.>
[McAfee Inc. / mfetdik][Running/System Start]
<system32\drivers\mfetdik.sys><McAfee, Inc.>
[mProcRs / mProcRs][Stopped/Auto Start]
<\??\d:\program files\rising\rfw\mProcRs.sys><N/A>
[PnpWmkDrv / PnpWmkDrv][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\PnpWmkDrv.sys><Windows (R) 2000 DDK provider>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[QKeyServiceDisplay / QKeyService][Running/Boot Start]
<\SystemRoot\system32\KeyCrypt.sys><Tencent Technology (Shenzhen) Company Limited>
[RsFwDrv / RsFwDrv][Stopped/Auto Start]
<\??\d:\Program Files\Rising\Rfw\RsFwDrv.sys><N/A>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Realtek RTL8169 Gigabit Ethernet Adapter NT Driver / RTL8169][Running/Manual Start]
<system32\DRIVERS\RT8169xp.sys><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[TesSafe / TesSafe][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>
[xshvf / xshvf][Running/Manual Start]
<\??\D:\1\data\xsVF.sys><HintSoft Inc.
作者:余胜桥>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
lxdnpx - 2007-11-2 17:30:00
浏览器加载项
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[FGCatchUrl]
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <C:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
[scriptproxy]
{7DB2D5A0-7241-4E79-B68D-6309F01C5231} <C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll, McAfee, Inc.>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[NavigatMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 奇虎网>
[FlashGet GetFlash Class]
{F156768E-81EF-470C-9057-481BA8380DBA} <C:\Program Files\FlashGet\getflash.dll, www.flashget.com>
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[浩方对战平台]
{0A155D3C-68E2-4215-A47A-E800A446447A} <E:\浩方对战平台\GameClient.exe, 上海浩方在线信息技术有限公司>
[快车]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\Program Files\FlashGet\FlashGet.exe, FlashGet.com>
[@msdxmLC.dll,-1@2052,电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[XMP Class]
{6483F145-A768-4C41-AACC-52D4D7845851} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work, >
[XDRM]
{693571CB-54A3-4E90-9D52-EEAE1334E2D3} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xdrm.dll_1_work, >
[MediaComm Class]
{7670648D-461B-42AF-BDFE-46D26AF5EFF2} <C:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin14.dll, Thunder Networking Technologies,LTD>
[360SafeLive]
{87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360safe.com>
[RMGetLicense Class]
{A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation>
[Thunder DapPlayer]
{EEDD6FF9-13DE-496B-9A1C-D78B3215E266} <C:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DapPlayer3.0.36.60.dll, ShenZhen Thunder Networking Technologies Ltd.>
[XPPlayer Class]
{F3E70CEA-956E-49CC-B444-73AFE593AD7F} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\pplayer.dll_1_work, Thunder>
[FGAutoLive]
{F90D830D-C175-4bbe-82C7-FF94669A4C42} <C:\Program Files\FlashGet\fgupdate.dll, www.flashget.com>
[FGCatchUrl]
{FB5DA724-162B-11D3-8B9B-AA70B4B0B524} <C:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
[&使用快车(FlashGet)下载]
<C:\Program Files\FlashGet\jc_link.htm, N/A>
[&使用快车(FlashGet)下载全部链接]
<C:\Program Files\FlashGet\jc_all.htm, N/A>
[使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
==================================
lxdnpx - 2007-11-2 17:32:00
正在运行的进程
[PID: 428 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 524 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4124]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 568 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 580 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 756 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 804 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 960 / SYSTEM][C:\PROGRA~1\完美卸~1\PnpWMmng.exe] [完美卸载, 5.1.2600.2937 ]
[PID: 996 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1044 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1056 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1228 / NETWORK SERVICE][C:\WINDOWS\system32\msdtc.exe] [Microsoft Corporation, 2001.12.4720.0 (srv03_rtm.030324-2048)]
[PID: 1360 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1392 / SYSTEM][C:\Program Files\McAfee\Common Framework\FrameworkService.exe] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\nailog.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\McAfee\Common Framework\naXML71.dll] [N/A, ]
[C:\Program Files\McAfee\Common Framework\NaiSign.DLL] [N/A, ]
[C:\WINDOWS\system32\epoPGPSDK.dll] [PGP Corporation, 3.5.3]
[C:\Program Files\McAfee\Common Framework\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\McAfee\Common Framework\naCmnLib71.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\applib.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\0409\AgentRes.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\Logging.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\InternetManager.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\naInet.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\UserSpace.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\SecureFrameworkFactory.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\Management.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\cmalib.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\naPolicyManager.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\ScriptSubSys.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\UpdateSubSys.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\Scheduler.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\TCSubSys.dll] [McAfee, Inc., 3.6.0.453]
[PID: 1460 / SYSTEM][C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe] [McAfee, Inc., 8.5.0.781]
[C:\Program Files\McAfee\VirusScan Enterprise\LockDown.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
[C:\Program Files\McAfee\VirusScan Enterprise\mytilus2.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
[C:\Program Files\McAfee\VirusScan Enterprise\mytilus.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
[C:\Program Files\McAfee\VirusScan Enterprise\shutil.dll] [McAfee, Inc., 8.5.0.781]
[C:\Program Files\McAfee\VirusScan Enterprise\wmain.dll] [McAfee, Inc., 8.5.0.781]
[C:\Program Files\McAfee\VirusScan Enterprise\condl.dll] [McAfee, Inc., 8.5.0.781]
[C:\Program Files\McAfee\VirusScan Enterprise\RES0402\McShield.dll] [McAfee, Inc., VSCORE.13.3.1.100]
[C:\Program Files\McAfee\VirusScan Enterprise\MIDUtil.Dll] [McAfee, Inc., 8.5.0.148]
[PID: 1520 / SYSTEM][C:\Program Files\Common Files\Sogou PXP\p2psvr.exe] [Sohu.com Inc., 2, 0, 0, 20]
[C:\Program Files\P4P\p4pipc.dll] [Sohu.com Inc., 1, 0, 0, 11]
[PID: 1540 / SYSTEM][C:\Program Files\McAfee\Common Framework\naPrdMgr.exe] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\NaiSign.DLL] [N/A, ]
[C:\WINDOWS\system32\epoPGPSDK.dll] [PGP Corporation, 3.5.3]
[C:\Program Files\McAfee\Common Framework\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\McAfee\Common Framework\naXML71.dll] [N/A, ]
[C:\Program Files\McAfee\Common Framework\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\McAfee\Common Framework\nailog.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\naCmnLib71.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\applib.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\0409\AgentRes.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\VirusScan Enterprise\VsPlugin.dll] [McAfee, Inc., 8.5.0.781]
[PID: 1656 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
lxdnpx - 2007-11-2 17:32:00
[PID: 1704 / SYSTEM][C:\WINDOWS\system32\Dfssvc.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 252 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 944 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1824 / SYSTEM][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 27]
[PID: 3892 / SYSTEM][C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe] [McAfee, Inc., VSCORE.13.3.1.100.x86]
[C:\Program Files\McAfee\VirusScan Enterprise\LockDown.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
[C:\Program Files\McAfee\VirusScan Enterprise\mytilus.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
[C:\Program Files\McAfee\VirusScan Enterprise\mytilus2.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
[C:\Program Files\McAfee\VirusScan Enterprise\RES0402\McShield.dll] [McAfee, Inc., VSCORE.13.3.1.100]
[C:\Program Files\McAfee\VirusScan Enterprise\FTL.Dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
[C:\Program Files\McAfee\VirusScan Enterprise\naiann.dll] [McAfee, Inc., 8.5.0.781]
[C:\Program Files\McAfee\VirusScan Enterprise\VsEvntUI.dll] [N/A, ]
[C:\Program Files\McAfee\VirusScan Enterprise\NAEvent.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
[C:\Program Files\McAfee\VirusScan Enterprise\shutil.dll] [McAfee, Inc., 8.5.0.781]
[C:\Program Files\McAfee\VirusScan Enterprise\wmain.dll] [McAfee, Inc., 8.5.0.781]
[C:\Program Files\McAfee\Common Framework\GenEvtInf.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\McAfee\Common Framework\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\McAfee\Common Framework\SecureFrameworkFactory.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\VirusScan Enterprise\scriptsv.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
[C:\Program Files\Common Files\McAfee\Engine\mcscan32.dll] [McAfee, Inc., 5.2.00]
[C:\Program Files\McAfee\VirusScan Enterprise\mfebopa.dll] [McAfee, Inc., SYSCORE.13.3.0.116.x86]
[C:\Program Files\McAfee\VirusScan Enterprise\mfehida.dll] [McAfee, Inc., SYSCORE.13.3.0.116.x86]
[C:\Program Files\McAfee\VirusScan Enterprise\mfeapfa.dll] [McAfee, Inc., SYSCORE.13.3.0.116.x86]
[C:\Program Files\McAfee\VirusScan Enterprise\mfeavfa.dll] [McAfee, Inc., SYSCORE.13.3.0.116.x86]
[PID: 3000 / cy33237580][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
[C:\Program Files\McAfee\Common Framework\JrMac.dll] [McAfee, Inc., 1.0.0.125]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\McAfee\VirusScan Enterprise\shext.dll] [McAfee, Inc., 8.5.0.781]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16]
[C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 12]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 13]
[C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.16]
[C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 44]
[C:\Program Files\360safe\safemon\safemon.dll] [奇虎网, 3, 6, 4, 1001]
[PID: 3008 / cy33237580][C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE] [McAfee, Inc., 8.5.0.781]
[C:\Program Files\McAfee\VirusScan Enterprise\LockDown.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
[C:\Program Files\McAfee\VirusScan Enterprise\ftcfg.dll] [McAfee, Inc., 8.5.0.781]
[C:\Program Files\McAfee\VirusScan Enterprise\mytilus2.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
[C:\Program Files\McAfee\VirusScan Enterprise\mytilus.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
[C:\Program Files\McAfee\VirusScan Enterprise\wmain.dll] [McAfee, Inc., 8.5.0.781]
[C:\Program Files\McAfee\VirusScan Enterprise\shutil.dll] [McAfee, Inc., 8.5.0.781]
[C:\Program Files\McAfee\VirusScan Enterprise\RES0402\McShield.dll] [McAfee, Inc., VSCORE.13.3.1.100]
[C:\Program Files\McAfee\VirusScan Enterprise\Graphics.dll] [McAfee, Inc., 8.5.0.781]
[PID: 2724 / cy33237580][C:\Program Files\McAfee\Common Framework\UdaterUI.exe] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\nailog.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\McAfee\Common Framework\naCmnLib71.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\naXML71.dll] [N/A, ]
[C:\Program Files\McAfee\Common Framework\NaiSign.DLL] [N/A, ]
[C:\WINDOWS\system32\epoPGPSDK.dll] [PGP Corporation, 3.5.3]
[C:\Program Files\McAfee\Common Framework\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\McAfee\Common Framework\applib.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\cmalib.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\0409\UpdRes.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\0409\AgentRes.dll] [McAfee, Inc., 3.6.0.453]
[C:\Program Files\McAfee\Common Framework\SecureFrameworkFactory.dll] [McAfee, Inc., 3.6.0.453]
[PID: 3096 / cy33237580][C:\Program Files\完美卸载V2007 完整版\MyUpdate.exe] [, 2.0.0.0]
[C:\Program Files\完美卸载V2007 完整版\SkinPlusPlus.dll] [http://www.killsoft.cn, 3, 1, 0, 0]
[C:\Program Files\完美卸载V2007 完整版\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0]
[PID: 2576 / cy33237580][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.20]
[C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 20.0.0.0]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.10]
[PID: 248 / cy33237580][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 3436 / cy33237580][C:\Program Files\McAfee\Common Framework\McTray.exe] [McAfee, Inc., 1.0.0.125]
[C:\Program Files\McAfee\Common Framework\JrMac.dll] [McAfee, Inc., 1.0.0.125]
[PID: 3620 / cy33237580][D:\Downloads\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[D:\Downloads\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
lxdnpx - 2007-11-2 17:33:00
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE
lxdnpx - 2007-11-2 17:34:00
lxdnpx - 2007-11-2 22:29:00
查看杀毒记录
杀毒软件如何才能杀得清啊.不让他重生
附件:
9572002007112221828.jpg
想要飞得更高 - 2007-11-2 22:40:00
这个问题好解决,进安全模式查杀病毒就可以彻底解决。
lxdnpx - 2007-11-9 8:52:00
它可以清除掉,但就是重新开机或隔几天又再次出现,
如何彻底清除,
烦恼
lxdnpx - 2007-11-9 8:55:00
各位高手:
非常感谢您留心我这份系统诊断报告,小菜鸟十万火急等待您的帮助!
该诊断报告由360安全卫士提供 http://www.360safe.com
诊断时间: 2007-11-09 00:10:52
诊断平台: Microsoft Windows Server 2003
IE版本: Internet Explorer V6.0.3790.0 Build:63790
计算机物理内存:2.00GB - 当前可用内存:1.49GB
100 - 未知 - Process: FrameworkService.exe [Framework Service] - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
100 - 未知 - Process: vstskmgr.exe [Task Manager] - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
100 - 未知 - Process: naPrdMgr.exe [NAI Product Manager] - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
100 - 未知 - Process: shstat.exe [VirusScan tray icon] - C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
100 - 未知 - Process: UdaterUI.exe [Common User Interface] - C:\Program Files\McAfee\Common Framework\UdaterUI.exe
100 - 未知 - Process: Mctray.exe [McAfee Security Agent Taskbar Extension] - C:\Program Files\McAfee\Common Framework\McTray.exe
100 - 未知 - Process: scan32.exe [VirusScan On-Demand Scanner] - C:\Program Files\McAfee\VirusScan Enterprise\SCAN32.EXE
100 - 未知 - Process: mcshield.exe [On-Access Scanner service] - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O2 - 未知 - BHO: (ThunderAtOnce Class) - [迅雷浏览器高级特性支持模块] - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll
O2 - 未知 - BHO: (scriptproxy) - [VSCore Script Scanner] - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O8 - 未知 - Extra context menu item: &使用快车(FlashGet)下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - 未知 - Extra context menu item: &使用快车(FlashGet)下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - 未知 - Extra context menu item: 使用迅雷下载 -
O8 - 未知 - Extra context menu item: 使用迅雷下载全部链接 -
O8 - 未知 - Extra context menu item: 用维棠下载视频 - C:\PROGRA~1\ViDown\vd_link.htm
O9 - 未知 - Extra button: 启动迅雷5(HKLM) - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - 未知 - Extra button: 浩方对战平台(HKLM) - E:\浩方对战平台\GameClient.exe
O9 - 未知 - Extra button: 快车(FlashGet)(HKLM) - C:\Program Files\FlashGet\FlashGet.exe
O23 - 未知 - Service: McShield [为计算机系统提供 McAfee 按访问扫描保护。] - "C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe" - (running)
O23 - 未知 - Service: McTaskManager [允许计划 McAfee 扫描和更新活动。] - "C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe" - (running)
O23 - 未知 - Service: RfwProxySrv [Rising Personal Proxy Service] - d:\program files\rising\rfw\rfwproxy.exe - (not running)
O23 - 未知 - Service: RfwService [Rising Personal Firewall Service] - d:\program files\rising\rfw\rfwsrv.exe - (not running)
O23 - 未知 - Service: TrkSvr [启用同域内的分布式链接跟踪客户端服务,以便在同域内提供更高的可靠性和有效维护。如果此服务被禁用,任何依赖于它的服务将无法启用。] - C:\WINDOWS\system32\trksvr.dll - (not running)
lxdnpx - 2007-11-9 8:55:00
100 - 安全 - Process: smss.exe [进程为会话管理子系统用以初始化系统变量,ms-dos驱动名称类似lpt1以及com,调用win32壳子系统和运行在windows登陆过程。] - C:\WINDOWS\System32\smss.exe
100 - 安全 - Process: csrss.exe [客户端服务子系统,用以控制windows图形相关子系统。] - C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=base
100 - 安全 - Process: winlogon.exe [windows nt用户登陆程序。] - C:\WINDOWS\system32\winlogon.exe
100 - 安全 - Process: services.exe [用于管理windows服务系统进程。] - C:\WINDOWS\system32\services.exe
100 - 安全 - Process: lsass.exe [本地安全权限服务控制windows安全机制。] - C:\WINDOWS\system32\lsass.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k rpcss
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\System32\svchost.exe -k termsvcs
100 - 安全 - Process: CCenter.exe [瑞星杀毒软件控制台相关程序。] - C:\Program Files\Rising\Rav\CCenter.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k NetworkService
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k LocalService
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\System32\svchost.exe -k netsvcs
100 - 安全 - Process: msdtc.exe [microsoft distributed transaction coordinator控制多个服务器的传输,被安装在microsoft personal web server和microsoft sql server。] - C:\WINDOWS\system32\msdtc.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\System32\svchost.exe -k WinErr
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k regsvc
100 - 安全 - Process: dfssvc.exe [管理分布于局域网或广域网的逻辑卷的程序。] - C:\WINDOWS\system32\Dfssvc.exe
100 - 安全 - Process: explorer.exe [windows program manager或者windows explorer用于控制windows图形shell,包括开始菜单、任务栏,桌面和文件管理。] - C:\WINDOWS\Explorer.EXE
100 - 安全 - Process: RavTask.exe [瑞星出品的杀毒软件相关程序。] - C:\Program Files\Rising\Rav\RavTask.exe
100 - 安全 - Process: 360tray.exe [360安全卫士实时监控程序。] - C:\Program Files\360safe\safemon\360tray.exe
100 - 安全 - Process: ctfmon.exe [office xp输入法图标。] - C:\WINDOWS\system32\ctfmon.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\System32\svchost.exe -k tapisrv
100 - 安全 - Process: wmiprvse.exe [wmi 提供程序 (wmi provider) 在 wmi 和操作系统、应用程序以及其他系统的组件之间充当中介.此进程为合法的系统进程。] - C:\WINDOWS\system32\wbem\wmiprvse.exe
100 - 安全 - Process: conime.exe [console ime ime输入法控制台软件。] - C:\WINDOWS\system32\conime.exe
100 - 安全 - Process: Rav.exe [瑞星杀毒软件。] - C:\Program Files\Rising\Rav\rav.exe
100 - 安全 - Process: CLI.exe [ati公司产品的相关产品。] - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
100 - 安全 - Process: 360Safe.exe [360安全卫士相关程序。] - C:\Program Files\360safe\360safe.exe
R1 - 安全 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm
R1 - 安全 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm
O2 - 安全 - BHO: (FGCatchUrl) - [网际快车,支持下载后的文件管理] - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - 安全 - BHO: (Thunder Browser Helper) - [迅雷附带下载监视器相关文件。] - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll
O2 - 安全 - BHO: (FlashGet GetFlash Class) - [网际快车相关程序。] - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - 安全 - Toolbar: (@msdxmLC.dll,-1@2052,电台(&R)) - [是Windows Media Player播放器ActiveX控制相关文件。] - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - 安全 - HKLM\..\Run: [RfwMain] [瑞星防火墙程序,抵御黑客攻击。] "d:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - 安全 - HKLM\..\Run: [ShStatEXE] [一款杀毒软件。] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - 安全 - HKLM\..\Run: [McAfeeUpdaterUI] [mcafee软件升级程序。] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - 安全 - HKLM\..\Run: [RavTask] [瑞星杀毒软件的任务计划程序。] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 安全 - HKLM\..\Run: [360Safetray] [360safe实时保护功能模块。] C:\Program Files\360safe\safemon\360tray.exe /start
O4 - 安全 - HKCU\..\Run: [ctfmon.exe] [office xp输入法图标。] C:\WINDOWS\system32\ctfmon.exe
O16 - 安全 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Flash播放器) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O23 - 安全 - Service: Ati HotKey Poller [ati显卡相关后台程序。] - C:\WINDOWS\system32\Ati2evxx.exe - (not running)
O23 - 安全 - Service: ATI Smart [是一个ati图形显示卡驱程的相关进程。] - C:\WINDOWS\system32\ati2sgag.exe - (not running)
O23 - 安全 - Service: McAfeeFramework [是Network Associates公司的E-policy反病毒套装的一部分。] - "C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart - (running)
O23 - 安全 - Service: NtFrs [在多个服务器间维护文件目录内容的文件同步。] - C:\WINDOWS\system32\ntfrs.exe - (not running)
O23 - 安全 - Service: RsCCenter [是瑞星杀毒软件控制台相关程序。] - "C:\Program Files\Rising\Rav\CCenter.exe" - (running)
lxdnpx - 2007-11-9 8:56:00
O31 - 未知 - SEApproved: 无效的CLSID:Shell extensions for file compression - - - - - 0 -
O31 - 未知 - SEApproved: 无效的CLSID:加密上下文菜单 - - - - - 0 -
O31 - 未知 - SEApproved: {88895560-9AA2-1069-930E-00AA0030EBC8} - hticons.dll - - - - 0 -
O31 - 未知 - SEApproved: {0DF44EAA-FF21-4412-828E-260A8728E7F1} - - - - - 0 -
O31 - 未知 - SEApproved: {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} - - - - - 0 -
O31 - 未知 - SEApproved: {5E2121EE-0300-11D4-8D3B-444553540000} - C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll - - ACE Context Menu - 1.0.0.1 - 73728 - 649e3ab705eb0f3af213dcd4378515cf
O31 - 未知 - SEApproved: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - C:\Program Files\WinRAR\rarext.dll - - - - 128512 - a6848472777fbcfa17236deb3f518d7c
O31 - 未知 - Directory Menu: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - C:\Program Files\WinRAR\rarext.dll - - - - 128512 - a6848472777fbcfa17236deb3f518d7c
O31 - 未知 - BootExecute: bsmain - - - - 0 -
O31 - 未知 - BootExecute: - - - - 0 -
O31 - 未知 - LSA: Notification Packages - DCSVC.dll - - - - 0 -
O31 - 未知 - LSA: Notification Packages - cecli.dll - - - - 0 -
O31 - 未知 - LSA: Security Packages - sv1_0.dll - - - - 0 -
O31 - 未知 - LSA: Security Packages - channel.dll - - - - 0 -
=======================================
O40 - Explorer.EXE - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\JrMac.dll - McAfee Security Agent Taskbar Extension Library - c8ff7b6c7ed409ce91f8b495e1840ae5
O40 - Explorer.EXE - - C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_01.dll - DsBho - 0fcf7645ff260d4919e3596df004ce4c
O40 - Explorer.EXE - Thunder Networking Technologies,LTD - C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_01.dll - DataProcessor - 87302e58383b83a4742fd5a752ba1a05
O40 - Explorer.EXE - - C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll - ACE Context Menu - 649e3ab705eb0f3af213dcd4378515cf
=======================================
lxdnpx - 2007-11-9 8:57:00
O41 - BaseTDI - basetdi - C:\WINDOWS\system32\drivers\basetdi.sys - (running) - basetdi - Beijing Rising Technology Co., Ltd. - 0064810c1b03f2c889130b669a4ce937
O41 - IGALIVE - IGALIVE - C:\Program Files\IGALIVE\IGALIVE.sys - (running) - - -
O41 - PnpWmkDrv - 完美卸载 Driver - C:\WINDOWS\system32\drivers\PnpWmkDrv.sys - (running) - 完美卸载 Driver - Windows (R) 2000 DDK provider - 5b3e48cf6941759c6391dd79b83dcbfe
O41 - QKeyService - KeyCrypt - C:\WINDOWS\system32\KeyCrypt.sys - (running) - KeyCrypt - Tencent Technology (Shenzhen) Company Limited - ecaa6d40a70bee079f3817601bec1692
O41 - EagleNT - EagleNT - C:\WINDOWS\system32\drivers\EagleNT.sys - (not running) - - -
O41 - HookUrl - HookUrl - d:\Program Files\Rising\Rfw\HookUrl.sys - (not running) - - -
O41 - mProcRs - mProcRs - d:\program files\rising\rfw\mProcRs.sys - (not running) - - -
O41 - RsFwDrv - RsFwDrv - d:\Program Files\Rising\Rfw\RsFwDrv.sys - (not running) - - -
O41 - TesSafe - TesSafe NT Driver - C:\WINDOWS\system32\TesSafe.sys - (not running) - TesSafe NT Driver - TENCENT - 14fe65e8752252acd5b177dddc4308ee
O41 - xshvf - XS Verify Driver - D:\1\data\xsVF.sys - (not running) - XS Verify Driver - HintSoft Inc.
作者:余胜桥 - e41b139d097984426961e6e69c57f371
=======================================
360Safe.exe=3.6.4.3003
AntiEng.dll=3.6.4.1001
AntiActi.dll=2.0.0.3000
CleanHis.dll=3.0.2.1000
live.dll=1.0.1.1021
=======================================
操作历史报告:
2007-11-06 00:16
清理恶评插件 - 搜狗工具条&地址栏直通车 - C:\Program Files\P4P
清理恶评插件 - 搜狗客户端共享组件 - C:\Program Files\Common Files\Sogou PXP
----------全面诊断修复历史----------
2007-11-06 00:18
O6 - 危险 - 禁止IE首页相关设置 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel
1
© 2000 - 2026 Rising Corp. Ltd.