瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助:任务管理器闪一下就消失了,系统时常死机,无法运行瑞星杀毒软件

1   1  /  1  页   跳转

求助:任务管理器闪一下就消失了,系统时常死机,无法运行瑞星杀毒软件

求助:任务管理器闪一下就消失了,系统时常死机,无法运行瑞星杀毒软件

任务管理器闪一下就消失了,系统时常死机,无法运行瑞星杀毒软件

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      8:53:49, 日期 2084-09-27
操作系统:  Windows XP SP1 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\exe
C:\WINDOWS\System32\wuaucll.exe
C:\WINDOWS\System32\conime.exe
C:\WINDOWS\Intel\rundll32.exe
C:\PROGRA~1\HEWLET~1\ORDERR~1\ORDERR~1.EXE
C:\DOCUME~1\cw\LOCALS~1\Temp\mhs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\DOCUME~1\cw\LOCALS~1\Temp\zts2.exe
C:\PROGRA~1\MESSEN~1\msmsgs.exe
C:\win32app\nsr\bin\nsrexecd.exe
c:\orant\bin\oracle80.exe
C:\orant\BIN\TNSLSNR80.EXE
C:\orant\bin\OWASTsvr.exe
C:\win32app\nsr\bin\portmap.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe
C:\WINDOWS\System32\cmd.exe
C:\Program Files\Internet Explorer\IEXPL0RE.EXE
C:\WINDOWS\System32\cmd.exe
C:\Program Files\Internet Explorer\IEXPL0RE.EXE
C:\WINDOWS\System32\cmd.exe
C:\Program Files\Internet Explorer\IEXPL0RE.EXE
C:\WINDOWS\System32\cmd.exe
C:\Program Files\Internet Explorer\IEXPL0RE.EXE
C:\cwwin\cwgl.exe
C:\WINDOWS\System32\cmd.exe
C:\Program Files\Internet Explorer\IEXPL0RE.EXE
C:\PROGRA~1\INTERN~1\IEXPLORE.EXE
C:\WINDOWS\smss.exe
C:\WINDOWS\Logo1_.exe
C:\DOCUME~1\cw\LOCALS~1\Temp\Rar$EX00.579\HijackThis1991zww.exe

R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar0.dll
F2 - REG:system.ini: Shell=Explorer.exe ntio.exe
F3 - REG:win.ini: load=C:\WINDOWS\rundl132.exe
O2 - BHO: AntiFish Class - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: AssistHelper - {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\kakatool.dll (file missing)
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4A40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar0.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - 启动项HKLM\\Run: [Start] Start.exe
O4 - 启动项HKLM\\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - 启动项HKLM\\Run: [TProgram] C:\WINDOWS\smss.exe
O4 - 启动项HKLM\\Run: [rzt] C:\WINDOWS\Intel\rundll32.exe
O4 - 启动项HKLM\\Run: [bygblf] C:\WINDOWS\System32\dtkxwg.exe
O4 - 启动项HKLM\\Run: [mhs] C:\DOCUME~1\cw\LOCALS~1\Temp\mhs.exe
O4 - 启动项HKLM\\Run: [zts2] C:\DOCUME~1\cw\LOCALS~1\Temp\zts2.exe
O4 - 启动项HKLM\\RunOnce: [YahooC:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ysearch.dll130796] regsvr32 /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ysearch.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - IE右键菜单中的新增项目: Download All by FlashGet - D:\PROGRA~1\FLASHGET\jc_all.htm
O8 - IE右键菜单中的新增项目: Download using FlashGet - D:\PROGRA~1\FLASHGET\jc_link.htm
O8 - IE右键菜单中的新增项目: 添加到雅虎订阅(&Y) - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT
O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar0.dll/203
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D8C1B32-6AB5-4619-9A07-A6B52E75D0C0}: NameServer = 10.8.101.241
O17 - HKLM\System\CS1\Services\Tcpip\..\{8D8C1B32-6AB5-4619-9A07-A6B52E75D0C0}: NameServer = 10.8.101.241
O17 - HKLM\System\CS2\Services\Tcpip\..\{8D8C1B32-6AB5-4619-9A07-A6B52E75D0C0}: NameServer = 10.8.101.241
O17 - HKLM\System\CS3\Services\Tcpip\..\{8D8C1B32-6AB5-4619-9A07-A6B52E75D0C0}: NameServer = 10.8.101.241
O18 - 列举现有的协议: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\Mshtml.dll
O18 - 列举现有的协议: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\System32\msvidctl.dll
O18 - 列举现有的协议: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: ipp - (no CLSID) - (no file)
O18 - 列举现有的协议: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - 列举现有的协议: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\Mshtml.dll
O18 - 列举现有的协议: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\Mshtml.dll
O18 - 列举现有的协议: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll
O18 - 列举现有的协议: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - 列举现有的协议: msdaipp - (no CLSID) - (no file)
O18 - 列举现有的协议: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
O18 - 列举现有的协议: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
O18 - 列举现有的协议: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\Mshtml.dll
O18 - 列举现有的协议: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\Mshtml.dll
O18 - 列举现有的协议: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\System32\msvidctl.dll
O18 - 列举现有的协议: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\Mshtml.dll
O18 - 列举现有的协议: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\System32\msdxm.ocx
O18 - 列举现有的协议: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll
O20 - AppInit_DLLs: 235780M.BMP
O23 - NT 服务: NetWorker Backup and Recover Server (nsrd) - Unknown owner - C:\win32app\nsr\bin\nsrd (file missing)
O23 - NT 服务: NetWorker Remote Exec Service (nsrexecd) - Unknown owner - C:\win32app\nsr\bin\nsrexecd (file missing)
O23 - NT 服务: OracleAgent80 - oracle - C:\orant\agentbin\DBSNMP.EXE
O23 - NT 服务: OracleClientCache80 - Unknown owner - C:\orant\BIN\ONRSD80.EXE
O23 - NT 服务: OracleDataGatherer - Unknown owner - C:\orant\bin\vppdc.exe
O23 - NT 服务: OracleExtprocAgent - Unknown owner - C:\orant\BIN\EXTPROCT.EXE
O23 - NT 服务: OracleNamesService80 - Unknown owner - C:\orant\BIN\NAMES80.EXE
O23 - NT 服务: OracleServiceORCL - Oracle Corporation - c:\orant\bin\oracle80.exe
O23 - NT 服务: OracleStartORCL - Unknown owner - C:\orant\BIN\strtdb80.exe
O23 - NT 服务: OracleTNSListener80 - Unknown owner - C:\orant\BIN\TNSLSNR80.EXE
O23 - NT 服务: OracleWebAssistant - Oracle Corporation - C:\orant\bin\OWASTsvr.exe
O23 - NT 服务: Storage Management Portmapper (portmap) - Unknown owner - C:\win32app\nsr\bin\portmap (file missing)
O23 - NT 服务: Svchost Service For Windows (svchost) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)

最后编辑2006-12-01 09:45:35
分享到:
gototop
 

http://mopery.hits.io/viking.zip
http://berrykwok.hits.io/viking.zip

下载专杀查杀..查杀前先关闭杀软..

查杀完后..

http://www.kztechs.com/sreng/sreng2.zip 下载System Repair Engineer
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
gototop
 

该机器还弹出一些非法网页,在桌面建立快捷方式
gototop
 

2006-12-01,09:36:02

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <wow><C:\WINDOWS\System32\Launcher.exe>  [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><C:\WINDOWS\rundl132.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <Start><Start.exe>  [N/A]
    <OrderReminder><C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe>  [Hewlett-Packard]
    <TProgram><C:\WINDOWS\smss.exe>  [fnPNhLDt9WvokwS6RKuZ]
    <rzt><C:\WINDOWS\Intel\rundll32.exe>  [N/A]
    <bygblf><C:\WINDOWS\System32\dtkxwg.exe>  [N/A]
    <mhs><C:\DOCUME~1\cw\LOCALS~1\Temp\mhs.exe>  [N/A]
    <zts2><C:\DOCUME~1\cw\LOCALS~1\Temp\zts2.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe ntio.exe>  [N/A]
    <Userinit><C:\WINDOWS\System32\Userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><235780M.BMP>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{4BAB150F-DD97-476D-9C1E-41B6CDC0CA7A}><C:\PROGRA~1\Yahoo!\Assistant\yClickOn.dll>  [YAHOO Corporation Limited]
    <{E568441B-9EF3-49F8-9A67-4141AC41ADD4}><C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll>  [Yahoo! China]

==================================
启动文件夹
N/A

==================================
服务
[1A1588D5 / 1A1588D5]
  <C:\WINDOWS\System32\1A1588D5.EXE -service><Microsoft Corporation>
[4807EC19 / 4807EC19]
  <C:\WINDOWS\System32\4807EC19.EXE -service><Microsoft Corporation>
[Human Interface Device Access / HidServ]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[MRTServ / MRTServ]
  <C:\WINDOWS\System32\MRTServ.exe><Microsoft Corporation>
[NetWorker Backup and Recover Server / nsrd]
  <C:\win32app\nsr\bin\nsrd><N/A>
[NetWorker Remote Exec Service / nsrexecd]
  <C:\win32app\nsr\bin\nsrexecd><N/A>
[OracleAgent80 / OracleAgent80]
  <C:\orant\agentbin\DBSNMP.EXE><oracle>
[OracleClientCache80 / OracleClientCache80]
  <C:\orant\BIN\ONRSD80.EXE><N/A>
[OracleDataGatherer / OracleDataGatherer]
  <C:\orant\bin\vppdc.exe><N/A>
[OracleExtprocAgent / OracleExtprocAgent]
  <C:\orant\BIN\EXTPROCT.EXE extproc><N/A>
[OracleNamesService80 / OracleNamesService80]
  <C:\orant\BIN\NAMES80.EXE><N/A>
[OracleServiceORCL / OracleServiceORCL]
  <c:\orant\bin\oracle80.exe ORCL><Oracle Corporation>
[OracleStartORCL / OracleStartORCL]
  <C:\orant\BIN\strtdb80.exe><N/A>
[OracleTNSListener80 / OracleTNSListener80]
  <C:\orant\BIN\TNSLSNR80.EXE><N/A>
[OracleWebAssistant / OracleWebAssistant]
  <C:\orant\bin\OWASTsvr.exe><Oracle Corporation>
[Storage Management Portmapper / portmap]
  <C:\win32app\nsr\bin\portmap><N/A>
[Remote Procedure Call (RPC) Window / RpcLocators]
  <C:\WINDOWS\System32\RpcLocators.exe><Microsoft Corporation>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Svchost Service For Windows / svchost]
  <C:\WINDOWS\svchost.exe><N/A>

==================================
驱动程序
[BaseTDI / BaseTDI]
  <\??\C:\WINDOWS\System32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
[btfirst / btfirst]
  <\SystemRoot\System32\DRIVERS\btfirst.sys><YAHOO Corporation.>
[ExpScaner / ExpScaner]
  <\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[HookCont / HookCont]
  <\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
  <\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
  <\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[MEMSCAN / MEMSCAN]
  <\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[Netgroup Packet Filter / NPF]
  <System32\DRIVERS\npf.sys><CACE Technologies>
[nv / nv]
  <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
  <System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
  <System32\DRIVERS\secdrv.sys><N/A>
[SiS AGP Filter / SISAGP]
  <\SystemRoot\System32\DRIVERS\SISAGPX.sys><Silicon Integrated Systems Corporation>
[SiSide / SiSide]
  <\SystemRoot\System32\DRIVERS\siside.sys><Silicon Integrated Systems Corp.>
[Add Performance Filter Driver / sisperf]
  <\SystemRoot\system32\drivers\sisperf.sys><Silicon Integrated Systems Corp.>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1]
  <System32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[squell / squell]
  <\??\C:\DOCUME~1\cw\LOCALS~1\Temp\wincab.sys><N/A>
[SVKP / SVKP]
  <\??\C:\WINDOWS\System32\SVKP.sys><AntiCracking>

==================================
浏览器加载项
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll, yahoo! china>
[assist]
  {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll, Yahoo! China>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\System32\kakatool.dll, N/A>
[雅虎助手]
  {406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar0.dll, yahoo! china>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[Download All by FlashGet]
  <D:\PROGRA~1\FLASHGET\jc_all.htm, N/A>
[Download using FlashGet]
  <D:\PROGRA~1\FLASHGET\jc_link.htm, N/A>
[添加到雅虎订阅(&Y)]
  <res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT, N/A>
[雅虎搜索]
  <res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar0.dll/203, N/A>

gototop
 

==================================
正在运行的进程
[PID: 472][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 520][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 544][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 588][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 600][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 784][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 832][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\orant\bin\oci.dll]  [Oracle Corporation, 8.0.5.0.1]
    [C:\orant\bin\ORA805.dll]  [Oracle Corporation, 8.0.5.0.0]
    [C:\orant\bin\CORE40.dll]  [Oracle Corporation, 4.0.5.0.0]
    [C:\orant\bin\NLSRTL33.dll]  [Oracle Corporation, 3.3.2.0.0]
    [C:\orant\bin\NL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\OTRACE80.dll]  [Oracle Corporation, 8.0.4.0.0]
    [C:\orant\bin\NS80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [C:\orant\bin\nasns80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\nz80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NNFG80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [C:\orant\bin\NNCI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NNG80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [C:\orant\bin\NMP80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NPL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NT80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [C:\orant\bin\NCR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NMS80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NNFD80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NNFN80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\PLS805.dll]  [Oracle Corporation, 8.0.5.0.0]
    [C:\orant\bin\NDWSI80.DLL]  [N/A, N/A]
    [C:\orant\bin\SQLLib80.dll]  [Oracle Corporation, 8.0.5.0.0]
    [C:\orant\bin\xa80.dll]  [Oracle Corporation, 8.0.5.0.0]
[PID: 932][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 960][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1172][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\system32\ZLhp1020.DLL]  [Zenographics, Inc., 5, 53, 3723, 0]
    [C:\WINDOWS\system32\ZLM.dll]  [Zenographics, Inc., 5, 50, 1416, 0]
    [C:\WINDOWS\system32\ZLMhp1.DLL]  [Zenographics, 5, 51, 1203, 0]
    [C:\WINDOWS\system32\ZPJL.dll]  [Zenographics, Inc., 1, 0, 1410, 1]
    [C:\WINDOWS\system32\ZSPOOL.dll]  [Zenographics, Inc., 5, 51, 709, 0]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\IMFPrint.DLL]  [Zenographics, Inc., 5, 54, 330, 0]
    [C:\WINDOWS\system32\Imf32.dll]  [Zenographics, Inc., 5, 60, 1204, 0]
    [C:\WINDOWS\system32\ZTAG32.dll]  [Zenographics, Inc., 5, 60, 1210, 0]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\ZPPPCL.DLL]  [Zenographics, Inc., 5, 51, 710, 0]
    [C:\WINDOWS\system32\ZPP.dll]  [Zenographics, Inc., 5, 51, 709, 0]
    [C:\WINDOWS\system32\ZGDI32.dll]  [Zenographics, Inc., 5, 51, 628, 0]
[PID: 1388][C:\WINDOWS\Explorer.exe]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\PROGRA~1\Yahoo!\Assistant\yClickOn.dll]  [YAHOO Corporation Limited, 3, 0, 1, 1002]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll]  [Yahoo! China, 3, 1, 3, 1019]
    [C:\WINDOWS\system32\ansi.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\ztdll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\mywow.dll]  [N/A, N/A]
    [C:\WINDOWS\Dll.dll]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 3, 1021]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  [yahoo! china, 3, 4, 8, 1099]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 1, 1010]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll]  [Yahoo! China, 3, 1, 1, 1016]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
gototop
 

[C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll]  [Yahoo! China, 3, 0, 2, 1002]
[PID: 1468][C:\WINDOWS\smss.exe]  [fnPNhLDt9WvokwS6RKuZ, 0.00.0119]
    [C:\WINDOWS\System32\ztdll.dll]  [N/A, N/A]
[PID: 1632][C:\WINDOWS\rundl132.exe]  [, 1.0.0.0]
    [C:\WINDOWS\System32\ztdll.dll]  [N/A, N/A]
[PID: 1724][C:\WINDOWS\System32\conime.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\ztdll.dll]  [N/A, N/A]
[PID: 1760][C:\WINDOWS\Intel\rundll32.exe]  [N/A, N/A]
    [C:\WINDOWS\System32\ztdll.dll]  [N/A, N/A]
[PID: 1808][C:\DOCUME~1\cw\LOCALS~1\Temp\zts2.exe]  [N/A, N/A]
    [C:\DOCUME~1\cw\LOCALS~1\Temp\zts2.dll]  [N/A, N/A]
[PID: 1820][C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe]  [Hewlett-Packard, 2, 0, 1, 26]
[PID: 1888][C:\DOCUME~1\cw\LOCALS~1\Temp\mhs.exe]  [N/A, N/A]
    [C:\DOCUME~1\cw\LOCALS~1\Temp\mhs.dll]  [N/A, N/A]
[PID: 1896][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\ztdll.dll]  [N/A, N/A]
[PID: 240][C:\WINDOWS\System32\MRTServ.exe]  [Microsoft Corporation, 1.18.1507.0]
[PID: 388][C:\win32app\nsr\bin\nsrexecd.exe]  [N/A, N/A]
    [C:\win32app\nsr\bin\LIBNSR.DLL]  [N/A, N/A]
    [C:\win32app\nsr\bin\LIBRAP.DLL]  [N/A, N/A]
    [C:\win32app\nsr\bin\LIBRPC.DLL]  [N/A, N/A]
    [C:\win32app\nsr\bin\liblocal.dll]  [N/A, N/A]
[PID: 776][c:\orant\bin\oracle80.exe]  [Oracle Corporation, 8.0.5.0.0]
    [c:\orant\bin\ORA805.dll]  [Oracle Corporation, 8.0.5.0.0]
    [c:\orant\bin\CORE40.dll]  [Oracle Corporation, 4.0.5.0.0]
    [c:\orant\bin\NLSRTL33.dll]  [Oracle Corporation, 3.3.2.0.0]
    [c:\orant\bin\NL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\OTRACE80.dll]  [Oracle Corporation, 8.0.4.0.0]
    [c:\orant\bin\NS80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [c:\orant\bin\nasns80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\nz80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NNFG80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [c:\orant\bin\NNCI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NNG80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [c:\orant\bin\NMP80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NPL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NT80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [c:\orant\bin\NCR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NMS80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NNFD80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NNFN80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\NI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [c:\orant\bin\PLS805.dll]  [Oracle Corporation, 8.0.5.0.0]
    [c:\orant\bin\NDWSI80.DLL]  [N/A, N/A]
    [c:\orant\bin\O80VSNOP.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\orasbt.dll]  [N/A, N/A]
    [C:\orant\bin\ntp80.DLL]  [Oracle Corporation, 8.0.4.0.0 Production]
[PID: 896][C:\orant\BIN\TNSLSNR80.EXE]  [N/A, N/A]
    [C:\orant\BIN\NR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NS80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [C:\orant\BIN\CORE40.dll]  [Oracle Corporation, 4.0.5.0.0]
    [C:\orant\BIN\NLSRTL33.dll]  [Oracle Corporation, 3.3.2.0.0]
    [C:\orant\BIN\OTRACE80.dll]  [Oracle Corporation, 8.0.4.0.0]
    [C:\orant\BIN\ORA805.dll]  [Oracle Corporation, 8.0.5.0.0]
    [C:\orant\BIN\NL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NNFG80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [C:\orant\BIN\NNCI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NNG80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [C:\orant\BIN\NMP80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NPL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NCR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NT80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [C:\orant\BIN\nasns80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\nz80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NMS80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NNFD80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\BIN\NNFN80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\ntus80.DLL]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\ntn80.DLL]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\ntt80.DLL]  [Oracle Corporation, 8.0.4.0.2 Production]
[PID: 920][C:\orant\bin\OWASTsvr.exe]  [Oracle Corporation, 8.0.5.0.0]
    [C:\orant\bin\OCI.dll]  [Oracle Corporation, 8.0.5.0.1]
    [C:\orant\bin\ORA805.dll]  [Oracle Corporation, 8.0.5.0.0]
    [C:\orant\bin\CORE40.dll]  [Oracle Corporation, 4.0.5.0.0]
    [C:\orant\bin\NLSRTL33.dll]  [Oracle Corporation, 3.3.2.0.0]
    [C:\orant\bin\NL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\OTRACE80.dll]  [Oracle Corporation, 8.0.4.0.0]
    [C:\orant\bin\NS80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [C:\orant\bin\nasns80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\nz80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NNFG80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [C:\orant\bin\NNCI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NNG80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [C:\orant\bin\NMP80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NPL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NT80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [C:\orant\bin\NCR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NMS80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NNFD80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NNFN80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\NI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\orant\bin\PLS805.dll]  [Oracle Corporation, 8.0.5.0.0]
    [C:\orant\bin\NDWSI80.DLL]  [N/A, N/A]
    [C:\orant\bin\owasmus.dll]  [N/A, N/A]
[PID: 980][C:\win32app\nsr\bin\portmap.exe]  [N/A, N/A]
    [C:\win32app\nsr\bin\LIBRPC.DLL]  [N/A, N/A]
    [C:\win32app\nsr\bin\liblocal.dll]  [N/A, N/A]
[PID: 1088][C:\WINDOWS\System32\RpcLocators.exe]  [Microsoft Corporation, 1.0.0.0]
[PID: 888][C:\WINDOWS\.exe]  [N/A, N/A]
    [C:\WINDOWS\System32\ztdll.dll]  [N/A, N/A]
[PID: 1420][C:\WINDOWS\System32\wuaucll.exe]  [N/A, N/A]
    [C:\WINDOWS\System32\ztdll.dll]  [N/A, N/A]
[PID: 2172][C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe]  [Yahoo! China, 3, 1, 6, 1022]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll]  [Yahoo! China, 3, 1, 3, 1019]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 3, 1021]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  [yahoo! china, 3, 4, 8, 1099]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 1, 1010]
    [C:\WINDOWS\System32\ztdll.dll]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\ynotifier.dll]  [yahoo! china, 3, 0, 1, 1001]
[PID: 2608][C:\WINDOWS\System32\wuauclt.exe]  [Microsoft Corporation, 5.4.3630.1106 (xpsp1.020828-1920)]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 3, 1021]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll]  [Yahoo! China, 3, 1, 3, 1019]
    [C:\WINDOWS\System32\ztdll.dll]  [N/A, N/A]
[PID: 3284][C:\WINDOWS\System32\cmd.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 3292][C:\Program Files\Internet Explorer\IEXPL0RE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3692][C:\WINDOWS\System32\cmd.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 3708][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 3, 1021]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll]  [Yahoo! China, 3, 1, 3, 1019]
    [C:\WINDOWS\System32\ztdll.dll]  [N/A, N/A]
[PID: 3780][C:\DOCUME~1\cw\LOCALS~1\Temp\Rar$EX00.469\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 3, 1021]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll]  [Yahoo! China, 3, 1, 3, 1019]
    [C:\WINDOWS\System32\ztdll.dll]  [N/A, N/A]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  Error. [WindowFiles]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
[D:\]
[autorun]
OPEN=D:\command.com
[E:\]
[AutoRun]
open=update.exe
[F:\]
[AutoRun]
open=update.exe

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT