瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 麻烦> <帮帮小白的忙IE开机报错已经杀过1次毒(内附HijackThis扫描日志

1   1  /  1  页   跳转

麻烦> <帮帮小白的忙IE开机报错已经杀过1次毒(内附HijackThis扫描日志

麻烦> <帮帮小白的忙IE开机报错已经杀过1次毒(内附HijackThis扫描日志

不知道什么时候中了5个毒,杀完后IE 提示应用程序错误,点击确定整个电脑就无法使用了.....使用超级兔子也无法修复
以前超级兔子改东西时 ,监控中心会提示,有15秒选择时间.现在只看到画面程序自己在点击确认

HijackThis_815汉化版扫描日志 V1.99.1
保存于      9:21:48, 日期 2006-9-1
操作系统:  Windows XP SP1 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
d:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
d:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
d:\Program Files\Rising\Rav\RavStub.exe
D:\Program Files\Rising\Rav\RavTask.exe
D:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\Realplayer.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
E:\广州城市热点资讯有限公司\Dr.COM 客户端软件\ishare_user.exe
d:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe
C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE
C:\TDdownload\rfw.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\setup.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
d:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
C:\TDdownload\Hijackthis1991zww\HijackThis1991zww.exe
C:\WINDOWS\system32\NOTEPAD.EXE

O2 - BHO: 超级兔子上网精灵 - {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} - C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - IE工具栏增项: 超级兔子上网精灵 - {43869BB3-22FD-4F15-9B46-238106BA2F4E} - C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [RavTask] "d:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [Cmaudio] ; RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - 启动项HKLM\\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - 启动项HKLM\\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - 启动项HKLM\\Run: [Realplayer.exe] C:\WINDOWS\System32\Realplayer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Realplayer.exe] C:\WINDOWS\System32\Realplayer.exe
O4 - HKCU\..\Run: [Super Rabbit IEPro] C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - 浏览器额外的按钮: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - d:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - 浏览器额外的“工具”菜单项: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - d:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O18 - 列举现有的协议: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINDOWS\System32\urlmon.dll
O18 - 列举现有的协议: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\System32\msvidctl.dll
O18 - 列举现有的协议: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\System32\urlmon.dll
O18 - 列举现有的协议: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\System32\urlmon.dll
O18 - 列举现有的协议: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\System32\urlmon.dll
O18 - 列举现有的协议: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\System32\urlmon.dll
O18 - 列举现有的协议: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\System32\urlmon.dll
O18 - 列举现有的协议: ipp - (no CLSID) - (no file)
O18 - 列举现有的协议: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - 列举现有的协议: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - 列举现有的协议: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\System32\urlmon.dll
O18 - 列举现有的协议: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll
O18 - 列举现有的协议: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\System32\urlmon.dll
O18 - 列举现有的协议: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - 列举现有的协议: msdaipp - (no CLSID) - (no file)
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - 列举现有的协议: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\System32\msvidctl.dll
O18 - 列举现有的协议: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\System32\msdxm.ocx
O18 - 列举现有的协议: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll
O23 - NT 服务: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - NT 服务: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - d:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - d:\Program Files\Rising\Rav\Ravmond.exe

最后编辑2006-09-01 20:31:23
分享到:
gototop
 

病毒名称                        处理结果    发现日期              扫描方式            路径                                                                                                                    文件                                                                                                                    病毒来源                                                   
Trojan.Zapchast.fa              删除成功    2006-08-26 02:27      手动扫描            D:\Warcraft III\Warcraft III                                                                                            revolt.dll                                                                                                              本机                                                       
Harm.RavFree.lu                删除成功    2006-08-26 02:49      手动扫描            E:\BitComet\Downloads\hfgame.exe                                                                                                        本机                                                       
Trojan.DL.Agent.htu            删除成功    2006-08-26 02:54      手动扫描            E:\新建文件夹\HFGameOPT                                                                                                cgamop.exe                                                                                                              本机                                                       
Trojan.DL.Inject.fe            删除成功    2006-08-26 03:04      手动扫描            E:\Downloads                                                                                                            20060520_wgxz.exe>>ok.exe                                                                                              本机                                                       
Trojan.DL.Inject.fe            删除成功    2006-08-26 03:04      手动扫描            E:\Downloads\20060520_wgxz                                                                                              ok.exe                                                                                                                  本机                                                       
Trojan.Zapchast.fa              忽略        2006-08-26 22:08      屏保扫描            D:\System Volume Information\_restore{E34B9B06-0112-428E-89F0-52C932308837}\RP3                                        A0005880.dll                                                                                                            本机                                                       
Trojan.Zapchast.fa              忽略        2006-08-29 09:44      屏保扫描            D:\System Volume Information\_restore{E34B9B06-0112-428E-89F0-52C932308837}\RP3                                        A0005880.dll                                                                                                            本机                                                       
Harm.RavFree.lu                忽略        2006-08-29 09:53      屏保扫描            E:\System Volume Information\_restore{E34B9B06-0112-428E-89F0-52C932308837}\RP3                                        A0005881.exe                                                                                                            本机                                                       
Trojan.DL.Agent.htu            忽略        2006-08-29 09:53      屏保扫描            E:\System Volume Information\_restore{E34B9B06-0112-428E-89F0-52C932308837}\RP3                                        A0005882.exe                                                                                                            本机                                                       
Trojan.DL.Inject.fe            忽略        2006-08-29 09:53      屏保扫描            E:\System Volume Information\_restore{E34B9B06-0112-428E-89F0-52C932308837}\RP3                                        A0005883.exe>>ok.exe                                                                                                    本机                                                       
Trojan.DL.Inject.fe            忽略        2006-08-29 09:53      屏保扫描            E:\System Volume Information\_restore{E34B9B06-0112-428E-89F0-52C932308837}\RP3                                        A0005884.exe                                                                                                            本机                                                       
Trojan.Zapchast.fa              删除成功    2006-09-01 07:48      手动扫描            D:\System Volume Information\_restore{E34B9B06-0112-428E-89F0-52C932308837}\RP3                                        A0005880.dll                                                                                                            本机                                                       
Harm.RavFree.lu                删除成功    2006-09-01 08:02      手动扫描            E:\System Volume Information\_restore{E34B9B06-0112-428E-89F0-52C932308837}\RP3                                        A0005881.exe                                                                                                            本机                                                       
Trojan.DL.Agent.htu            删除成功    2006-09-01 08:02      手动扫描            E:\System Volume Information\_restore{E34B9B06-0112-428E-89F0-52C932308837}\RP3                                        A0005882.exe                                                                                                            本机                                                       
Trojan.DL.Inject.fe            删除成功    2006-09-01 08:02      手动扫描            E:\System Volume Information\_restore{E34B9B06-0112-428E-89F0-52C932308837}\RP3                                        A0005883.exe>>ok.exe                                                                                                    本机                                                       
Trojan.DL.Inject.fe            删除成功    2006-09-01 08:02      手动扫描            E:\System Volume Information\_restore{E34B9B06-0112-428E-89F0-52C932308837}\RP3                                        A0005884.exe                                                                                                            本机                                                       
gototop
 

O4 - HKCU\..\Run: [Realplayer.exe] C:\WINDOWS\System32\Realplayer.exe
启动项
C:\WINDOWS\system32\Realplayer.exe
C:\WINDOWS\system32\Realplayer.exe
运行中的程序
C:\WINDOWS\system32\brlmon.dll

解决方法
解决方法如下
双击我的电脑,工具,文件夹选项,查看,单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示确定更改时,单击“是”,清除“隐藏已知文件类型的扩展名
ALT+CTRL+DELETE调出任务管理器,终止explorer.exe 还有Realplayer.exe的进程
点“文件”“新任务”“浏览”找到C:\WINDOWS\system32\Realplayer.exe
删除Realplayer.exe
点“文件”“新任务”“浏览”找到C:\WINDOWS\explorer.exe,双击打开
运行(双击)System Repair Engineer,使用“启动项目,注册表”来删除以下选项。
C:\WINDOWS\system32\Realplayer.exe
C:\WINDOWS\system32\Realplayer.exe
删除
C:\WINDOWS\system32\brlmon.dll
把主页改回来。

修复后,重启
请下载SRENG2 使用智能扫描,将日志保存起来,多分二次粘贴上来,日志不要修改

下载地址:http://free5.ys168.com/?ufwihgu168
gototop
 

重启前的日志2006-09-01,20:11:57

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联


启动项目


注册表

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
(ctfmon.exe)(C:\WINDOWS\System32\ctfmon.exe) [Microsoft Corporation]
(MsnMsgr)(; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background) [Microsoft Corporation]
(Super Rabbit IEPro)(C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD) [Super Rabbit Soft]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(load)() []
(run)() []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
(IMJPMIG8.1)(; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32) [Microsoft Corporation]
(PHIME2002ASync)(; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC) [Microsoft Corporation]
(PHIME2002A)(; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName) [Microsoft Corporation]
(RavTask)("d:\Program Files\Rising\Rav\RavTask.exe" -system) [Beijing Rising Technology Co., Ltd.]
(Cmaudio)(; RunDll32 cmicnfg.cpl,CMICtrlWnd) []
(SoundMan)(SOUNDMAN.EXE) [Realtek Semiconductor Corp.]
(ATIPTA)(C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe) [ATI Technologies, Inc.]
(DAEMON Tools)("C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033) [DT Soft Ltd.]
(HP Software Update)(C:\Program Files\HP\HP Software Update\HPWuSchd2.exe) [Hewlett-Packard Co.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(shell)(Explorer.exe) [Microsoft Corporation]
(Userinit)(C:\WINDOWS\system32\userinit.exe,) [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(AppInit_DLLs)() []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(UIHost)(logonui.exe) [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
(WinlogonNotify: AtiExtEvent)(Ati2evxx.dll) [ATI Technologies Inc.]




--------------------------------------------------------------------------------



启动文件夹

[HP Digital Imaging Monitor]
(C:\Documents and Settings\All Users\「开始」菜单\程序\启动\HP Digital Imaging Monitor.lnk)(N)



--------------------------------------------------------------------------------



服务

[Ati HotKey Poller / Ati HotKey Poller]
(C:\WINDOWS\System32\Ati2evxx.exe)(ATI Technologies Inc.)
[ATI Smart / ATI Smart]
(C:\WINDOWS\system32\ati2sgag.exe)()
[Rising Process Communication Center / RsCCenter]
("d:\Program Files\Rising\Rav\CCenter.exe")(Beijing Rising Technology Co., Ltd.)
[RsRavMon Service / RsRavMon]
("d:\Program Files\Rising\Rav\Ravmond.exe")(Beijing Rising Technology Co., Ltd.)



--------------------------------------------------------------------------------



浏览器加载项

[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} (C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology)
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} (d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD)
[启动迅雷]
{0062C9BD-B349-40DE-91A0-755F37ACD559} (d:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD)
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} (, N/A)
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} (C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation)
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} (C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology)
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.)
[&使用迅雷下载]
(d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A)
[&使用迅雷下载全部链接]
(d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A)
[上传到QQ网络硬盘]
(D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A)
[添加到QQ自定义面板]
(D:\Program Files\Tencent\QQ\AddPanel.htm, N/A)
[添加到QQ表情]
(D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A)
[用QQ彩信发送该图片]
(D:\Program Files\Tencent\QQ\SendMMS.htm, N/A)



--------------------------------------------------------------------------------



gototop
 


正在运行的进程
[PID: 604][\SystemRoot\System32\smss.exe] (Microsoft Corporation)(5.1.2600.1106 (xpsp1.020828-1920))
[PID: 672][\??\C:\WINDOWS\system32\csrss.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 696][\??\C:\WINDOWS\system32\winlogon.exe] (Microsoft Corporation)(5.1.2600.1106 (xpsp1.020828-1920))
[C:\WINDOWS\system32\Ati2evxx.dll] (ATI Technologies Inc.)(6.14.10.4113)
[PID: 744][C:\WINDOWS\system32\services.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 756][C:\WINDOWS\system32\lsass.exe] (Microsoft Corporation)(5.1.2600.1106 (xpsp1.020828-1920))
[PID: 912][C:\WINDOWS\System32\Ati2evxx.exe] (ATI Technologies Inc.)(6.14.10.4113)
[C:\WINDOWS\System32\Ati2edxx.dll] (ATI Technologies, Inc.)(6, 14, 10, 2496)
[PID: 952][C:\WINDOWS\system32\svchost.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 1056][d:\Program Files\Rising\Rav\CCenter.exe] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 3)
[PID: 1072][C:\WINDOWS\System32\svchost.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 1236][C:\WINDOWS\System32\svchost.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 1304][C:\WINDOWS\System32\svchost.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 1316][d:\Program Files\Rising\Rav\Ravmond.exe] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 24)
[d:\Program Files\Rising\Rav\BWList.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 5)
[d:\Program Files\Rising\Rav\RsCommX.dll] (rising)(18, 0, 0, 1)
[d:\Program Files\Rising\Rav\rfwctrl.dll] (Beijing Rising Technology Co., Ltd.)(5, 0, 0, 6)
[d:\Program Files\Rising\Rav\RSAPPMGR.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 2)
[d:\Program Files\Rising\Rav\CfgDll.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 12)
[d:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 2)
[d:\Program Files\Rising\Rav\RsLog.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 20)
[d:\Program Files\Rising\Rav\HOOKSYS.dll] (Rising)(18, 1, 0, 9)
[d:\Program Files\Rising\Rav\Scanner.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 6)
[d:\Program Files\Rising\Rav\libload.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 8)
[d:\Program Files\Rising\Rav\VirusLib.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 5)
[d:\Program Files\Rising\Rav\regmon.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 6)
[d:\Program Files\Rising\Rav\HookWeb.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 1)
[d:\Program Files\Rising\Rav\MemMon.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 11)
[d:\Program Files\Rising\Rav\expscan.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[d:\Program Files\Rising\Rav\mPorts.dll] (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 3)
[d:\Program Files\Rising\Rav\HookCont.dll] (Rising)(19, 0, 0, 0)
[d:\Program Files\Rising\Rav\SpamEng.dll] (N/A)(18, 0, 0, 6)
[d:\Program Files\Rising\Rav\engine.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 14)
[d:\Program Files\Rising\Rav\PostTrt.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 4)
[d:\Program Files\Rising\Rav\UnExe.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 5)
[d:\Program Files\Rising\Rav\ScanExec.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 7)
[d:\Program Files\Rising\Rav\ScanEx.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 8)
[d:\Program Files\Rising\Rav\NvFile.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 7)
[d:\Program Files\Rising\Rav\ScanMac.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 7)
[d:\Program Files\Rising\Rav\ScanSct.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 8)
[d:\Program Files\Rising\Rav\Unpacker.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 7)
[d:\Program Files\Rising\Rav\ScanPack.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 9)
[d:\Program Files\Rising\Rav\RsVM.dll] (N/A)(19, 0, 0, 3)
[d:\Program Files\Rising\Rav\ExtOLE.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 7)
[d:\Program Files\Rising\Rav\Uscript.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 10)
[d:\Program Files\Rising\Rav\Uroutine.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 8)
[PID: 1536][C:\WINDOWS\system32\Ati2evxx.exe] (ATI Technologies Inc.)(6.14.10.4113)
[C:\WINDOWS\system32\Ati2edxx.dll] (ATI Technologies, Inc.)(6, 14, 10, 2496)
[PID: 1716][C:\WINDOWS\system32\spoolsv.exe] (Microsoft Corporation)(5.1.2600.0 (XPClient.010817-1148))
[C:\WINDOWS\system32\hpzll3xu.dll] (Hewlett-Packard Company)(60.051.641.00)
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\hpzpp3xu.dll] (Hewlett-Packard Corporation)(60.051.641.00)
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\hpz3r3xu.dll] (Hewlett Packard Corporation)(60.051.641.00)
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\hpzst3xu.dll] (Hewlett-Packard Corporation)(60.051.641.00)
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\hpzle3xu.dll] (HP)(60.051.641.00)
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPFIE3xu.dll] (Hewlett-Packard Company)(A.05.00.008)
[PID: 1928][D:\Program Files\Rising\Rav\RavTask.exe] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 5)
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 2)
[D:\Program Files\Rising\Rav\RSAPPMGR.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 2)
[D:\Program Files\Rising\Rav\CfgDll.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 12)
[D:\Program Files\Rising\Rav\RsCommX.dll] (rising)(18, 0, 0, 1)
[PID: 1940][D:\Program Files\Rising\Rav\Ravmon.exe] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 23)
[D:\Program Files\Rising\Rav\RsGuiLib.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 21)
[D:\Program Files\Rising\Rav\BWList.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 5)
[D:\Program Files\Rising\Rav\RSAPPMGR.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 2)
[D:\Program Files\Rising\Rav\CfgDll.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 12)
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 2)
[D:\Program Files\Rising\Rav\RsCommX.dll] (rising)(18, 0, 0, 1)
[D:\Program Files\Rising\Rav\RsXML.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 2)
[D:\Program Files\Rising\Rav\PngDll.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 5)
[PID: 1948][C:\WINDOWS\SOUNDMAN.EXE] (Realtek Semiconductor Corp.)(5.1.0.22)
[PID: 1972][d:\Program Files\Rising\Rav\RavStub.exe] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 4)
[d:\Program Files\Rising\Rav\RsCommX.dll] (rising)(18, 0, 0, 1)
[d:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 2)
[PID: 2012][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe] (ATI Technologies, Inc.)(6.14.10.5142)
[C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll] (ATI Technologies, Inc.)(6.14.10.5142)
[C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.CHS] (ATI Technologies, Inc.)(6.14.10.5142)
[C:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll] (ATI Technologies, Inc.)(6.14.10.5142)
[PID: 312][C:\WINDOWS\System32\alg.exe] (Microsoft Corporation)(5.1.2600.1106 (xpsp1.020828-1920))
[PID: 324][C:\Program Files\HP\HP Software Update\HPWuSchd2.exe] (Hewlett-Packard Co.)(53.0.13.000)
[PID: 588][C:\WINDOWS\System32\ctfmon.exe] (Microsoft Corporation)(5.1.2600.1106 (xpsp1.020828-1920))
[PID: 532][C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE] (Super Rabbit Soft)(7.76)
[C:\PROGRA~1\SUPERR~1\MagicSet\shlobj71.ocx] (Sky Software (http://www.ssware.com))(7, 1, 0, 0)
[PID: 436][C:\WINDOWS\System32\wdfmgr.exe] (Microsoft Corporation)(5.2.3790.1230 built by: dnsrv(bld4act))
[PID: 1100][C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpquio08.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqtra08.rsc] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqtao08.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpotradd.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpftra01.dll] (Hewlett-Packard)(1, 0, 0, 2)
gototop
 

[C:\Program Files\HP\Digital Imaging\bin\hpqrif08.dll] (Hewlett-Packard Co.)(53.0.20.000)
[C:\Program Files\HP\Digital Imaging\bin\hpodvd09.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpoddcomm09.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpodio08.dll] (Hewlett-Packard Co.)(50.0.165.000)
[PID: 456][C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqmfc09.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqtap08.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.rsc] (Hewlett-Packard Co.)(53.0.13.000)
[PID: 448][C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqmfc09.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqtap08.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.rsc] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqsti08.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqcob08.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqstv08.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqsem08.rsc] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpocxi08.dll] (Hewlett-Packard Co.)(50.0.125.000)
[PID: 644][C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqmfc09.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqtap08.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll] (Hewlett-Packard Co.)(53.0.13.000)
[C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.rsc] (Hewlett-Packard Co.)(53.0.13.000)
[PID: 720][E:\广州城市热点资讯有限公司\Dr.COM 客户端软件\ishare_user.exe] (N/A)(N/A)
[E:\广州城市热点资讯有限公司\Dr.COM 客户端软件\cw3220.DLL] (Borland International)(2.0)
[PID: 808][C:\Program Files\Internet Explorer\iexplore.exe] (Microsoft Corporation)(6.00.2800.1106 (xpsp1.020828-1920))
[C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll] (Xiang Feng Technology)(2, 2, 0, 1612)
[d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll] (Thunder Networking Technologies,LTD)(5, 0, 0, 2)
[C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx] (Adobe Systems, Inc.)(9,0,16,0)
[d:\Program Files\Super Rabbit\HappyPlayer\Codecs\mmfinfo.dll] (N/A)(N/A)
[d:\Program Files\Super Rabbit\HappyPlayer\Codecs\mkunicode.dll] (N/A)(N/A)
[PID: 3636][C:\WINDOWS\System32\taskmgr.exe] (Microsoft Corporation)(5.1.2600.1106 (xpsp1.020828-1920))
[d:\Program Files\Super Rabbit\HappyPlayer\Codecs\mmfinfo.dll] (N/A)(N/A)
[d:\Program Files\Super Rabbit\HappyPlayer\Codecs\mkunicode.dll] (N/A)(N/A)
[d:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 2)
[PID: 4020][C:\WINDOWS\explorer.exe] (Microsoft Corporation)(6.00.2800.1106 (xpsp1.020828-1920))
[d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll] (Thunder Networking Technologies,LTD)(5, 0, 0, 2)
[d:\Program Files\Super Rabbit\HappyPlayer\Codecs\mmfinfo.dll] (N/A)(N/A)
[d:\Program Files\Super Rabbit\HappyPlayer\Codecs\mkunicode.dll] (N/A)(N/A)
[C:\Program Files\WinRAR\rarext.dll] (N/A)(N/A)
[C:\WINDOWS\system32\RavExt.dll] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 7)
[d:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 2)
[PID: 2268][C:\Program Files\Internet Explorer\iexplore.exe] (Microsoft Corporation)(6.00.2800.1106 (xpsp1.020828-1920))
[C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll] (Xiang Feng Technology)(2, 2, 0, 1612)
[d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll] (Thunder Networking Technologies,LTD)(5, 0, 0, 2)
[C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx] (Adobe Systems, Inc.)(9,0,16,0)
[d:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_003.dll] (Thunder Networking Technologies,LTD)(1, 0, 0, 10)
[PID: 2668][d:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe] (Thunder Networking Technologies,LTD)(5.3.0.220)
[d:\Program Files\Thunder Network\Thunder\Program\UpdateDownload.dll] (Thunder Networking Technologies,LTD)(1, 0, 1, 8)
[d:\Program Files\Thunder Network\Thunder\Program\download_interface.dll] (Thunder Networking Technologies,LTD)(1, 0, 4, 71)
[d:\Program Files\Thunder Network\Thunder\Program\log4cplus.dll] ()(1, 0, 2, 1)
[d:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll] (STLport Consulting, Inc.)(4.6.2003.1031)
[d:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll] (N/A)(N/A)
[d:\Program Files\Thunder Network\Thunder\Program\msgmanage.dll] (Thunder Networking Technologies,LTD)(1, 0, 0, 15)
[d:\Program Files\Thunder Network\Thunder\Program\historyinfo_manage.dll] (Thunder Networking Technologies,LTD)(5, 2, 0, 148)
[d:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll] (Thunder Networking Technologies,LTD)(2, 1, 0, 18)
[d:\Program Files\Thunder Network\Thunder\Program\FloatBar.dll] (Thunder Networking Technologies,LTD)(1, 0, 0, 2)
[d:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll] ( )(1, 0, 0, 11)
[d:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed04.dll] ( )(2, 3, 0, 37)
[d:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll] (Thunder Networking Technologies,LTD)(1, 0, 3, 8)
[d:\Program Files\Thunder Network\Thunder\Program\iTargetAd.dll] (Thunder Networking Technologies,LTD)(1, 0, 1, 55)
[C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx] (Adobe Systems, Inc.)(9,0,16,0)
[PID: 3080][d:\Program Files\Rising\Rav\RsAgent.exe] (Beijing Rising Technology Co., Ltd.)(19, 0, 0, 6)
[d:\Program Files\Rising\Rav\RsCommX.dll] (rising)(18, 0, 0, 1)
[PID: 3100][C:\WINDOWS\msagent\AgentSvr.exe] (Microsoft Corporation)(2.00.0.3422)
[PID: 3436][C:\TDdownload\sreng2\SREng2\SREng.exe] (Smallfrogs Studio)(2.0.21.505)
[C:\TDdownload\sreng2\SREng2\Plugins\SREngPluginDemo.SRE] (Smallfrogs Studio)(1, 1, 1, 0)



--------------------------------------------------------------------------------



文件关联

.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]



--------------------------------------------------------------------------------


Winsock 提供者
.^^开机后没有IE报错,瑞星启动也正常了
感谢大大的帮助

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT