IE被79300.com及tm286.com劫持有SREngLOG报告

正在运行的进程
[PID: 428][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 496][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 520][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 564][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 576][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 736][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 800][E:\Program Files\Rav\CCenter.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 816][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\olite\bin\oci.dll]  [Oracle Corporation, 8.0.5.0.1]
    [C:\olite\bin\ORA805.dll]  [Oracle Corporation, 8.0.5.0.0]
    [C:\olite\bin\CORE40.dll]  [Oracle Corporation, 4.0.5.0.0]
    [C:\olite\bin\NLSRTL33.dll]  [Oracle Corporation, 3.3.2.0.0]
    [C:\olite\bin\NL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\olite\bin\OTRACE80.dll]  [Oracle Corporation, 8.0.4.0.0]
    [C:\olite\bin\NS80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [C:\olite\bin\nasns80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\olite\bin\nz80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\olite\bin\NNFG80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [C:\olite\bin\NNCI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\olite\bin\NNG80.dll]  [Oracle Corporation, 8.0.4.0.2 Production]
    [C:\olite\bin\NMP80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\olite\bin\NPL80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\olite\bin\NR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\olite\bin\NT80.dll]  [Oracle Corporation, 8.0.4.0.1 Production]
    [C:\olite\bin\NCR80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\olite\bin\NMS80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\olite\bin\NNFD80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\olite\bin\NNFN80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\olite\bin\NI80.dll]  [Oracle Corporation, 8.0.4.0.0 Production]
    [C:\olite\bin\PLS805.dll]  [Oracle Corporation, 8.0.5.0.0]
    [C:\olite\bin\NDWSI80.DLL]  [N/A, N/A]
    [C:\olite\bin\SQLLib80.dll]  [Oracle Corporation, 8.0.5.0.0]
    [C:\olite\bin\xa80.dll]  [Oracle Corporation, 8.0.5.0.0]
[PID: 892][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 944][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 956][E:\Program Files\Rav\Ravmond.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 39]
    [E:\Program Files\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
    [E:\Program Files\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [E:\Program Files\Rav\rfwctrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [E:\Program Files\Rav\RsPPsys.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
    [E:\Program Files\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [E:\Program Files\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [E:\Program Files\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [E:\Program Files\Rav\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [E:\Program Files\Rav\HOOKSYS.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
    [E:\Program Files\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
    [E:\Program Files\Rav\libload.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
    [E:\Program Files\Rav\VirusLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [E:\Program Files\Rav\regmon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
    [E:\Program Files\Rav\HookWeb.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
    [E:\Program Files\Rav\MemMon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
    [E:\Program Files\Rav\expscan.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [E:\Program Files\Rav\mPorts.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
    [E:\Program Files\Rav\HookCont.dll]  [Rising, 19, 0, 0, 0]
    [E:\Program Files\Rav\SpamEng.dll]  [N/A, 18, 0, 0, 6]
    [E:\Program Files\Rav\engine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
    [E:\Program Files\Rav\PostTrt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
    [E:\Program Files\Rav\UnExe.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [E:\Program Files\Rav\ScanExec.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
    [E:\Program Files\Rav\ScanEx.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 26]
    [E:\Program Files\Rav\ExtFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 22]
    [E:\Program Files\Rav\NvFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
    [E:\Program Files\Rav\ScanMac.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
    [E:\Program Files\Rav\ScanSct.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
    [E:\Program Files\Rav\Unpacker.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
    [E:\Program Files\Rav\ScanPack.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [E:\Program Files\Rav\RsVM.dll]  [N/A, 19, 0, 0, 9]
    [E:\Program Files\Rav\Uscript.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
    [E:\Program Files\Rav\Uroutine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [E:\Program Files\Rav\ExtOLE.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
最后编辑2006-12-12 12:08:55.700000000