瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 日志贴上来了.大家帮忙看看吧,谢谢

12   2  /  2  页   跳转

日志贴上来了.大家帮忙看看吧,谢谢

==================================
浏览器加载项
[Adobe PDF Reader Link Helper]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Windows Live Sign-in Helper]
  {9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
[ST]
  {9394EDE7-C8B5-483E-8773-474BF36AF6E4} <C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll, Microsoft Corporation>
[MSNToolBandBHO]
  {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\zh-cn\msntb.dll, Microsoft Corporation>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\MSMSGS.EXE, Microsoft Corporation>
[百万图库]
  {6713E8D2-850A-101B-AFC0-4210102A8DA7} <http://www.26-3.com/p, N/A>
[铃声图片下载]
  {7713E8D2-850A-101B-AFC0-4210102A8DA7} <http://www.7169.com/sms/index.htm, N/A>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[MSN]
  {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\zh-cn\msntb.dll, Microsoft Corporation>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\System32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[Checkers Class]
  {00B71CFB-6864-4346-A978-C0A14556272C} <C:\WINDOWS\Downloaded Program Files\msgrchkr.dll, Microsoft Corporation>
[MSN Photo Upload Tool]
  {4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[MessengerStatsClient Class]
  {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} <C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll, Microsoft Corporation>
[MsnMessengerSetupDownloadControl Class]
  {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} <C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx, Microsoft Corporation>
[IEDown Class]
  {D0A29C6C-AA71-4423-8C4A-5998B774C448} <C:\WINDOWS\System32\GLIEDown2.dll, 联众公司>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Ravonline]
  {DA984A6D-508E-11D6-AA49-0050FF3C628D} <C:\WINDOWS\Downloaded Program Files\RsOnline.dll, Beijing Rising Tech. Co., Ltd.>
[VqqSpeedDlProxy Class]
  {F138084D-84D7-48CD-BEA8-04772457516E} <C:\WINDOWS\vqqsdl.dll, Tencent>
[导出到 Microsoft Excel(&x)]
  <res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[用比特精灵下载(&B)]
  <C:\Program Files\BitSpirit\bsurl.htm, N/A>

==================================
gototop
 

==================================
正在运行的进程
[PID: 744][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 828][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 852][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\reset5.dll]  [N/A, N/A]
    [c:\WINDOWS\System32\LgNotify.dll]  [Intel Corporation, 8, 0, 0, 162]
[PID: 896][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 908][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1080][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1252][C:\Program Files\Rising\Rav\CCenter.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 1268][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1304][C:\WINDOWS\System32\S24EvMon.exe]  [Intel Corporation , 8, 0, 0, 162]
[PID: 1548][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1604][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1684][C:\Program Files\Rising\Rfw\rfwsrv.exe]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 30]
    [C:\Program Files\Rising\Rfw\RfwRule.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 3]
    [C:\Program Files\Rising\Rfw\rfwlog.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 2]
    [C:\Program Files\Rising\Rfw\Rfwdrv.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 9]
    [C:\Program Files\Rising\Rfw\MonDrv.dll]  [rs, 1, 0, 0, 4]
    [C:\Program Files\Rising\Rfw\ProcLib.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 5]
    [C:\Program Files\Rising\Rfw\mPorts.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[PID: 1944][C:\WINDOWS\system32\ZCfgSvc.exe]  [Intel Corporation, 8, 0, 0, 162]
    [C:\WINDOWS\system32\PfMgrApi.dll]  [Intel Corporation, 8, 0, 0, 162]
    [C:\WINDOWS\system32\PsRegApi.dll]  [Intel Corporation, 8, 0, 0, 162]
    [C:\WINDOWS\system32\WConfig.DLL]  [Intel Corporation, 8, 0, 0, 162]
    [C:\WINDOWS\system32\WiFiAdap.DLL]  [Intel Corporation, 8, 0, 0, 162]
    [C:\WINDOWS\system32\PsGuiMgr.dll]  [Intel Corporation., 8, 0, 0, 162]
    [C:\WINDOWS\system32\C1XStngs.dll]  [Intel Corporation, 8, 0, 0, 162]
    [c:\Program Files\Intel\PROSetWireless\PROSet\CHS\ZcSvcCHS.dll]  [Intel Corporation, 8, 0, 0, 107]
    [c:\Program Files\Intel\PROSetWireless\PROSet\CHS\PmApiCHS.dll]  [Intel Corporation, 8, 0, 0, 107]
    [C:\WINDOWS\system32\S24MUDLL.dll]  [Intel Corporation, 8, 0, 0, 162]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [c:\Program Files\Intel\PROSetWireless\PROSet\CHS\C1XStCHS.dll]  [Intel Corporation, 8, 0, 0, 107]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]
[PID: 176][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\windhcp.ocx]  [N/A, N/A]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.7.2006011200]
    [D:\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\WINDOWS\System32\igfxpph.dll]  [Intel Corporation, 3.0.0.3775]
    [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3.0.0.3775]
[PID: 240][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\system32\hpzlnt05.dll]  [HP, 2,118,0,0]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll]  [Windows (R) 2000 DDK provider, 5.00.2195.1620]
[PID: 396][C:\Program Files\Rising\Rav\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 628][C:\PROGRA~1\svhost32.exe]  [N/A, N/A]
    [C:\DOCUME~1\吕麦菲\LOCALS~1\Temp\f.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 704][C:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 772][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3034]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 780][C:\Program Files\Rising\Rfw\rfwmain.exe]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 56]
    [C:\Program Files\Rising\Rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
    [C:\Program Files\Rising\Rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rfw\RfwCtrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [C:\Program Files\Rising\Rfw\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [C:\Program Files\Rising\Rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]
[PID: 1136][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1172][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  [Microsoft Corporation, 7.00.9466]
[PID: 1216][C:\WINDOWS\System32\RegSrvc.exe]  [Intel Corporation, 8, 0, 0, 162]
[PID: 1248][C:\WINDOWS\system32\srvany.exe]  [N/A, N/A]
[PID: 1524][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1528][C:\WINDOWS\system32\resetservice.exe]  [N/A, N/A]
[PID: 1932][C:\Program Files\Rising\Rav\RsAgent.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 1952][C:\WINDOWS\msagent\AgentSvr.exe]  [Microsoft Corporation, 2.00.0.3422]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 1668][C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe]  [HP, 2,118,0,0]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\spool\drivers\w32x86\3\HPZR3205.DLL]  [HP, 2,118,0,0]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 2108][C:\WINDOWS\System32\hkcmd.exe]  [Intel Corporation, 3.0.0.3775]
    [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3.0.0.3775]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\igfxdev.dll]  [Intel Corporation, 3.0.0.3775]
    [C:\WINDOWS\System32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.3775]
    [C:\WINDOWS\System32\igfxres.dll]  [Intel Corporation, 3.0.0.3775]
    [C:\WINDOWS\System32\igfxhk.dll]  [Intel Corporation, 3.0.0.3775]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 2200][C:\WINDOWS\System32\1XConfig.exe]  [Intel, 8, 0, 0, 162]
    [C:\WINDOWS\System32\IntelAE5.dll]  [Meetinghouse Data Communications, 1, 42, 19, 1]
    [C:\WINDOWS\System32\SSLEAY32.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\LIBEAY32.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\PsRegApi.dll]  [Intel Corporation, 8, 0, 0, 162]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 2212][C:\WINDOWS\CameraFixer.exe]  [, 1, 0, 0, 2]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 2228][C:\WINDOWS\vsnpstd3.exe]  [, 1, 0, 2, 2]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 2248][C:\WINDOWS\Download\svhost32.exe]  [N/A, N/A]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[PID: 2260][C:\Program Files\Rising\KakaToolBar\runiep.exe]  [Beijing Rising Technology Co., Ltd., 1, 0, 1, 3]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\iep_ctrl.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 2308][C:\DOCUME~1\吕麦菲\LOCALS~1\Temp\mhs2.exe]  [N/A, N/A]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\DOCUME~1\吕麦菲\LOCALS~1\Temp\mhs2.dll]  [N/A, N/A]
gototop
 

[PID: 2352][C:\Program Files\Common Files\Microsoft Shared\MSINFO\svchost.exe]  [N/A, N/A]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
[PID: 2384][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 3000][C:\WINDOWS\System32\wuauclt.exe]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 3628][C:\Program Files\Real\RealPlayer\RealPlay.exe]  [RealNetworks, Inc., 6.0.12.872]
    [C:\WINDOWS\System32\PNCRT.dll]  [Real Networks, Inc, 6.0.0.0]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Real\Update_OB\rnms3270.dll]  [RealNetworks, Inc., 7.0.1.2866]
    [C:\Program Files\Common Files\Real\Common\objb3201.dll]  [RealNetworks, Inc., 0.1.0.5858]
    [C:\Program Files\Common Files\Real\RCAPlugins\uisy3201.dll]  [RealNetworks, Inc., 0.1.0.3363]
    [C:\Program Files\Common Files\Real\Update_OB\rnad3201.dll]  [RealNetworks, Inc., 0.1.0.3034]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Real\Update_OB\rnqu3270.dll]  [RealNetworks, Inc., 7.0.0.3286]
    [C:\Program Files\Common Files\Real\Update_OB\setu3270.dll]  [RealNetworks, Inc., 7.0.0.3914]
[PID: 680][C:\Program Files\MSN Messenger\msnmsgr.exe]  [Microsoft Corporation, 8.1.0168.00_ClientV8.1]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\msdmo.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 3240][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\KakaTool.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 2, 6]
    [D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.7.2006011200]
    [C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll]  [Microsoft Corporation, 01.02.3000.1001]
    [C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\zh-cn\msntb.dll]  [Microsoft Corporation, 01.02.5000.1021]
    [C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\zh-cn\mtbres.dll]  [Microsoft Corporation, 01.02.5000.1021]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
[PID: 3664][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]
[PID: 2172][F:\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
gototop
 

用瑞星卡卡删除下列项目,完成后用杀软扫描一遍
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<IEXPLORE.EXE><; IEXPLORE.EXE Http://www.86vod.com> [N/A]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<Nice><C:\Program Files\Common Files\Microsoft Shared\MSINFO\svchost.exe> [N/A]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<load><C:\PROGRA~1\svhost32.exe> [N/A]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<tsnpstd3><C:\WINDOWS\tsnpstd3.exe> []
<snpstd3><C:\WINDOWS\vsnpstd3.exe> []
<xy><C:\WINDOWS\Download\svhost32.exe> [N/A]
<mhs2><C:\DOCUME~1\吕麦菲\LOCALS~1\Temp\mhs2.exe> [N/A]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<NiceSoft><C:\WINDOWS\System32\explore.exe> [N/A]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\reset5]
<WinlogonNotify: reset5><reset5.dll> [N/A]

服务
[Reset 5 / Reset 5]
<C:\WINDOWS\system32\srvany.exe><N/A>
[Windows DHCP Service / WinDHCPsvc]
<C:\WINDOWS\System32\rundll32.exe windhcp.ocx,start><Microsoft Corporation>
[WinXP DHCP Service / WinXPDHCPsvc]
<C:\WINDOWS\System32\rundll32.exe xpdhcp.dll,start><Microsoft Corporation>

驱动程序
[AR / AR]
<\??\C:\WINDOWS\System32\a.sys><N/A>
[New0 / New0]
<\??\C:\WINDOWS\System32\new.sys><N/A>
[WINIO / WINIO]
<\??\C:\WINDOWS\Downloaded Program Files\winio.sys><N/A>

浏览器加载项
[百万图库]
{6713E8D2-850A-101B-AFC0-4210102A8DA7} <http://www.26-3.com/p, N/A>
[铃声图片下载]
{7713E8D2-850A-101B-AFC0-4210102A8DA7} <http://www.7169.com/sms/index.htm, N/A>
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT