帮帮忙啊,我的日志4

[PID: 536][C:\SysDayN6\svchost.exe]  [N/A, ]
    [C:\SysDayN6\Ghook.dll]  [N/A, ]
    [C:\WINDOWS\system32\9899C26C.DLL]  [Microsoft Corporation, ]
[PID: 692][C:\WINDOWS\ALCFDRTM.EXE]  [Realtek Semiconductor Corp., 1, 3, 0, 1]
    [C:\SysWsj7\Ghook.dll]  [N/A, ]
    [C:\SysDayN6\Ghook.dll]  [N/A, ]
    [C:\WINDOWS\system32\9899C26C.DLL]  [Microsoft Corporation, ]
[PID: 700][C:\SysWsj7\svchost.exe]  [N/A, ]
    [C:\SysWsj7\Ghook.dll]  [N/A, ]
    [C:\WINDOWS\system32\9899C26C.DLL]  [Microsoft Corporation, ]
[PID: 1084][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\SysWsj7\Ghook.dll]  [N/A, ]
    [C:\SysDayN6\Ghook.dll]  [N/A, ]
    [C:\WINDOWS\system32\9899C26C.DLL]  [Microsoft Corporation, ]
[PID: 2036][C:\WINDOWS\system32\9734EE38.exe]  [N/A, ]
    [C:\WINDOWS\system32\MSVBVM60.DLL]  [Microsoft Corporation, 6.00.9782]
    [C:\WINDOWS\system32\9899C26C.DLL]  [Microsoft Corporation, ]
    [C:\WINDOWS\system32\vb6chs.dll]  [Microsoft Corporation, 6.00.8988]
    [C:\SysWsj7\Ghook.dll]  [N/A, ]
    [C:\SysDayN6\Ghook.dll]  [N/A, ]
[PID: 2400][C:\WINDOWS\system32\26969958.exe]  [N/A, ]
    [C:\WINDOWS\system32\MSVBVM60.DLL]  [Microsoft Corporation, 6.00.9782]
    [C:\WINDOWS\system32\vb6chs.dll]  [Microsoft Corporation, 6.00.8988]
    [C:\SysWsj7\Ghook.dll]  [N/A, ]
    [C:\SysDayN6\Ghook.dll]  [N/A, ]
[PID: 3648][C:\WINDOWS\system32\WgaTray.exe]  [Microsoft Corporation, 1.7.0018.5]
    [C:\SysWsj7\Ghook.dll]  [N/A, ]
    [C:\SysDayN6\Ghook.dll]  [N/A, ]
[PID: 936][C:\WINDOWS\system32\26969958.exe]  [N/A, ]
    [C:\WINDOWS\system32\MSVBVM60.DLL]  [Microsoft Corporation, 6.00.9782]
    [C:\WINDOWS\system32\vb6chs.dll]  [Microsoft Corporation, 6.00.8988]
    [C:\SysWsj7\Ghook.dll]  [N/A, ]
    [C:\SysDayN6\Ghook.dll]  [N/A, ]
[PID: 4088][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\迅雷\迅雷\ComDlls\XunLeiBHO_006.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
    [C:\Program Files\Norton AntiVirus\NavShExt.dll]  [Symantec Corporation, 12.6.0.1]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\SysWsj7\Ghook.dll]  [N/A, ]
    [C:\SysDayN6\Ghook.dll]  [N/A, ]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.3802.3802 built by: dnsrv(bld4act)]
    [D:\迅雷\迅雷\ComDlls\ThunderAgent_005.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 11]
[PID: 608][D:\迅雷\迅雷\Program\Thunder5.exe]  [Thunder Networking Technologies,LTD, 5, 5, 2, 252]
    [D:\迅雷\迅雷\Program\TaskManager.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 10]
    [D:\迅雷\迅雷\Program\download_interface.dll]  [Thunder Networking Technologies,LTD, 2, 11, 2, 22]
    [D:\迅雷\迅雷\Program\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
    [D:\迅雷\迅雷\Program\log4cplus.dll]  [, 1, 0, 2, 1]
    [D:\迅雷\迅雷\Program\asyn_dns.dll]  [Thunder Networking Technologies,LTD, 2, 11, 2, 22]
    [D:\迅雷\迅雷\Program\BHOStub.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 8]
    [D:\迅雷\迅雷\Program\FloatBar.dll]  [Giganology Inc., 1, 0, 0, 2]
    [C:\SysWsj7\Ghook.dll]  [N/A, ]
    [C:\SysDayN6\Ghook.dll]  [N/A, ]
    [D:\迅雷\迅雷\Program\iTargetAD.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 12]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\迅雷\迅雷\Components\DTAG\DTAG.dll]  [, 1, 0, 0, 1]
    [D:\迅雷\迅雷\Program\LiveUpdate.dll]  [, 1, 0, 0, 9]
    [D:\迅雷\迅雷\Program\UpdateDownload.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 8]
    [D:\迅雷\迅雷\Components\InMedia\iEmbedShell.dll]  [ , 1, 0, 0, 14]
    [D:\迅雷\迅雷\Components\InMedia\iEmbed07.dll]  [ , 3, 1, 0, 58]
    [D:\迅雷\迅雷\Components\Community\XLCommunity.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 10]
    [D:\迅雷\迅雷\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 2, 1, 42]
    [D:\迅雷\迅雷\Components\Search\XLSearch.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
    [D:\迅雷\迅雷\Components\P4PClient\P4PClient.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 3]
    [D:\迅雷\迅雷\Plugins\BhoAdv\bho_adv.dll]  [深圳市迅雷网络技术有限公司, 1.0.1.0]
    [D:\迅雷\迅雷\Program\msgmanage.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 15]
[PID: 800][C:\Program Files\Messenger\msmsgs.exe]  [Microsoft Corporation, 4.7.3001]
    [C:\SysWsj7\Ghook.dll]  [N/A, ]
    [C:\SysDayN6\Ghook.dll]  [N/A, ]
[PID: 2672][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.3802.3802 built by: dnsrv(bld4act)]
    [C:\SysWsj7\Ghook.dll]  [N/A, ]
    [C:\SysDayN6\Ghook.dll]  [N/A, ]
[PID: 3512][C:\DOCUME~1\new\LOCALS~1\Temp\Rar$EX01.382\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\SysWsj7\Ghook.dll]  [N/A, ]
    [C:\SysDayN6\Ghook.dll]  [N/A, ]
    [C:\DOCUME~1\new\LOCALS~1\Temp\Rar$EX01.382\Plugins\NWMON.SRE]  [Smallfrogs Studio, 1, 0, 0, 8]
    [C:\PROGRA~1\MICROS~2\OFFICE11\MCPS.DLL]  [Microsoft Corporation, 11.0.6357]

==================================
文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
[C:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
[D:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
[E:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================
最后编辑2007-04-06 22:00:02.840000000