1   1  /  1  页   跳转

跳出网页gg.99mov.com求教。

跳出网页gg.99mov.com求教。

昨天查找旅游网站时,开始有弹出页面
http://gg.99mov.com/ad/gg1.html
http://stbanner.allyes.com/sm/78mmsnew/0531/500x300/images/5003001_01.gif
下载了system repair engineer
日志如下:请高手帮忙看看:
_____________________________________________________________________________
2006-06-12,14:53:52

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe">  [Symantec Corporation]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
    <vptray><C:\PROGRA~1\SYMANT~1\VPTray.exe>  [Symantec Corporation]
    <pdfFactory Pro 分配器 v2><"C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /runonce>  [FinePrint Software, LLC]
    <StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  []
    <Dell QuickSet><C:\Program Files\Dell\QuickSet\Quickset.exe>  [Dell Inc]
    <ShowLOMControl><>  []
    <msstart><C:\WINDOWS\System32\msstart.exe>  []
    <DAEMON Tools><"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033>  [DT Soft Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <1><\\asia.med.ge.com\sysvol\asia.med.ge.com\scripts\tools\tqcrunas\tqcrunas.exe -f \\asia.med.ge.com\sysvol\asia.med.ge.com\scripts\tools\tqcrunas\mvcmp.tqc>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]

==================================
启动文件夹
[Adobe Reader Speed Launch]
  <D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk><N>
[Cisco Systems VPN Client]
  <D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Cisco Systems VPN Client.lnk><N>
[Microsoft Office]
  <D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk><N>
[RealSecure(r) Desktop Protector]
  <D:\Documents and Settings\All Users\Start Menu\Programs\Startup\RealSecure(r) Desktop Protector.lnk><N>
[金山词霸 2003]
  <D:\Documents and Settings\All Users\Start Menu\Programs\Startup\金山词霸 2003.lnk><N>

==================================
服务
[pcAnywhere Host Service / awhost32]
  <C:\Program Files\Symantec\pcAnywhere\awhost32.exe><Symantec Corporation>
[BlackICE / BlackICE]
  <"C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe"><Internet Security Systems, Inc.>
[Symantec Event Manager / ccEvtMgr]
  <"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc]
  <"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr]
  <"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[Cisco Systems, Inc. VPN Service / CVPND]
  <"C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe"><Cisco Systems, Inc.>
[Symantec AntiVirus Definition Watcher / DefWatch]
  <"C:\Program Files\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[EvtEng / EvtEng]
  <C:\Program Files\Intel\Wireless\Bin\EvtEng.exe><Intel Corporation>
[Contivity VPN Service / ExtranetAccess]
  <"C:\Program Files\Nortel Networks\Extranet_serv.exe"><Nortel Networks NA, Inc.>
[Hummingbird Inetd / HCLInetd]
  <C:\WINDOWS\System32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe><Hummingbird Ltd.>
[InstallDriver Table Manager / IDriverT]
  <"C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"><Macrovision Corporation>
[IT iona_services.config_rep.cnhcg38yp1xl cfr-MyDomain / IT iona_services.config_rep.cnhcg38yp1xl cfr-MyDomain]
  <"D:\Ideas10\Iona\OrbixE2A\asp\5.1\bin\itconfig_rep.exe" -ORBproduct_dir "D:\Ideas10\Iona\OrbixE2A" -ORBlicense_file "d:\Ideas10\Iona\OrbixE2A\Licenses.txt" -ORBconfig_dir "D:\Ideas10\Iona\OrbixE2A\etc" -ORBconfig_domains_dir "d:\Ideas10\Iona\OrbixE2A\etc\domains" -ORBdomain_name cfr-MyDomain -ORBname iona_services.config_rep.cnhcg38yp1xl -plugin=config_rep it_jump_start><N/A>
[Hummingbird Jconfig Daemon / Jconfigd]
  <C:\WINDOWS\System32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe><Hummingbird Ltd.>
[MATLAB Server / matlabserver]
  <d:\lixi\tools\Matlab5\webserver\bin\matlabserver.exe><N/A>
[NICCONFIGSVC / NICCONFIGSVC]
  <C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe><Dell Inc.>
[nidevldu / nidevldu]
  <system32\nipalsm.exe><National Instruments Corporation>
[NILM License manager / NILM License manager]
  <"C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe"><Macrovision Corporation>
[nipxirmu / nipxirmu]
  <system32\nipalsm.exe><National Instruments Corporation>
[NI Service Locator / niSvcLoc]
  <C:\WINDOWS\System32\niSvcLoc.exe -s><National Instruments>
[RapApp / RapApp]
  <"C:\Program Files\ISS\issSensors\DesktopProtection\RapApp.exe"><Internet Security Systems, Inc.>
[RegSrvc / RegSrvc]
  <C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe><Intel Corporation>
[Spectrum24 Event Monitor / S24EventMonitor]
  <C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe><Intel Corporation>
[SavRoam / SavRoam]
  <"C:\Program Files\Symantec AntiVirus\SavRoam.exe"><symantec>
[Symantec Network Drivers Service / SNDSrvc]
  <"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Symantec SPBBCSvc / SPBBCSvc]
  <C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe><Symantec Corporation>
[Symantec AntiVirus / Symantec AntiVirus]
  <"C:\Program Files\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>

==================================
浏览器加载项
[Adobe PDF Reader Link Helper]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Solid Converter PDF]
  {259F616C-A300-44F5-B04A-ED001A26C85C} <C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll, VoyagerSoft, LLC>
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~1\FlashGet\jccatch.dll, Amaze Soft>
[Google Toolbar Helper]
  {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[易趣购物]
  {DE607142-AC19-422e-866A-6D70ABDF119A} <http://click2.ad4all.net/url2/urlmanage/url.asp?id=5, N/A>
[SupportCentral]
  {E5CA3FCB-32F0-4602-A3FD-0785E3F0F5BF} <C:\WINDOWS\System32\SCTOOL~1.DLL, >
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\PROGRA~1\FlashGet\fgiebar.dll, Amaze Soft>
[CyberArticle Express]
  {769A6A36-ED24-4376-BC7C-80225BF35698} <C:\Program Files\CyberArticle\CAExp.dll, Wizissoft>
[Solid Converter PDF]
  {259F616C-A300-44F5-B04A-ED001A26C85C} <C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll, VoyagerSoft, LLC>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[Edit Class]
  {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\System32\CMBEdit.dll, >
[DjVuCtl Class]
  {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} <C:\Program Files\LizardTech\DjVuControl\DjVuCntl.dll, LizardTech>
[VGAPlayer Control]
  {339C1EE2-1029-46B8-81F1-360217F26FC4} <C:\WINDOWS\DOWNLO~1\VGAPLA~1.OCX, 北京翰博尔信息技术有限公司>
[Java Plug-in 1.3.1_04]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\npjava131_04.dll, JavaSoft / Sun Microsystems, Inc.>
[JNILoader Control]
  {8F0DF9DB-AA5A-4ED0-9176-1C4A9C762C59} <C:\WINDOWS\DOWNLO~1\CONFLICT.1\STJNIL~1.OCX, Databeam>
[Java Plug-in 1.3.1_04]
  {CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} <C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\npjava131_04.dll, JavaSoft / Sun Microsystems, Inc.>
[E&xport to Microsoft Excel]
  <res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000, N/A>
[Google 搜索(&G)]
  <res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html, N/A>
[上传到QQ网络硬盘]
  <D:\LiXi\Tools\qq\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[保存: 完整网页...]
  <C:\Program Files\CyberArticle\script\Save.htm, N/A>
[保存: 更多保存内容...]
  <C:\Program Files\CyberArticle\script\SaveAuto.htm, N/A>
[反向链接]
  <res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html, N/A>
[导入当前页到超星阅览器(&A)]
  <C:\Program Files\SSREADER36\ss_all.htm, N/A>
[导入选中部分到超星阅览器(&S)]
  <C:\Program Files\SSREADER36\ss_select.htm, N/A>
[添加到QQ自定义面板]
  <D:\LiXi\Tools\qq\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\LiXi\Tools\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\LiXi\Tools\qq\SendMMS.htm, N/A>
[类似网页]
  <res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html, N/A>
[缓存的网页快照]
  <res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html, N/A>
[翻译英文字词(&T)]
  <res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html, N/A>

最后编辑2006-06-13 09:46:09
分享到:
gototop
 

==================================
正在运行的进程
[PID: 1188][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1236][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1260][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.1557 (xpsp2_gdr.040517-1325)>
[PID: 1308][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1320][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1532][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1764][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1812][C:\Program Files\Intel\Wireless\Bin\EvtEng.exe]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 2, 11>
[PID: 1892][C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe]  <Intel Corporation ><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 2, 11>
[PID: 1944][C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe]  <Intel? Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\PfMgrApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\MurocApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\S24MUDLL.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\C1XStngs.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll]  <N/A><N/A>
    [C:\Program Files\Intel\Wireless\Bin\LSAWRAPI.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\D8021Xps.DLL]  <N/A><N/A>
[PID: 472][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 540][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 988][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.1699 (xpsp2.050610-1533)>
    [C:\WINDOWS\system32\fppmon2.dll]  <FinePrint Software, LLC><2.15>
    [C:\WINDOWS\system32\fppr232.dll]  <FinePrint Software, LLC><2.15>
    [C:\WINDOWS\System32\Hummingbird\Connectivity\7.10\Accessories\hcllpr.dll]  <Hummingbird Ltd.><7.1.0.0>
    [C:\WINDOWS\System32\Hummingbird\Connectivity\7.10\Accessories\hcllpr.nls]  <Hummingbird Ltd.><7.1.0.0>
    [C:\WINDOWS\system32\awmon.dll]  <Symantec Corporation><9.2.1>
    [C:\WINDOWS\system32\pxc25pm.dll]  <Tracker Software><2.50.0002>
[PID: 1116][C:\WINDOWS\System32\SCardSvr.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1684][C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe]  <Intel><9, 0, 2, 11>
    [C:\PROGRA~1\Intel\Wireless\Bin\IntelAE5.dll]  <Meetinghouse Data Communications><3, 0, 0, 60>
    [C:\PROGRA~1\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 2, 11>
    [C:\PROGRA~1\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\D8021Xps.DLL]  <N/A><N/A>
[PID: 412][C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe]  <Internet Security Systems, Inc.><7.0.322>
    [C:\Program Files\ISS\issSensors\DesktopProtection\FileSec.dll]  <Internet Security Systems, Inc.><7.0.319>
    [C:\Program Files\ISS\issSensors\DesktopProtection\AC_Base.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\blackdll.dll]  <Internet Security Systems, Inc.><7.0.321>
    [C:\Program Files\ISS\issSensors\DesktopProtection\VpnICE.dll]  <Internet Security Systems, Inc.><7.0.320>
    [C:\Program Files\ISS\issSensors\DesktopProtection\RapAd.dll]  <Internet Security Systems, Inc.><7.0.05.0>
    [C:\Program Files\ISS\issSensors\DesktopProtection\Comply\AC_McAfee.dll]  <Internet Security Systems, Inc.><7.0.320>
    [C:\Program Files\ISS\issSensors\DesktopProtection\Comply\AC_Norton.dll]  <Internet Security Systems, Inc.><7.0.320>
    [C:\Program Files\ISS\issSensors\DesktopProtection\iss-pam1.dll]  <Internet Security Systems><1.10.106.3>
[PID: 612][C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe]  <Cisco Systems, Inc.><4.6.02.0011>
    [C:\WINDOWS\System32\vsdata.dll]  <Zone Labs Inc.><5.5.058.000>
    [C:\WINDOWS\System32\VSINIT.dll]  <Zone Labs Inc.><5.5.058.000>
[PID: 632][C:\Program Files\Symantec AntiVirus\DefWatch.exe]  <Symantec Corporation><10.0.1.1000>
[PID: 652][C:\WINDOWS\System32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe]  <Hummingbird Ltd.><7.1.0.0>
    [C:\WINDOWS\System32\HCLNLS.dll]  <Hummingbird Ltd.><7.1.0.0>
    [C:\WINDOWS\System32\Hummingbird\Connectivity\7.10\Inetd\humprdin.dll]  <Hummingbird Ltd.><7.1.0.0>
    [C:\WINDOWS\System32\Hummingbird\Connectivity\7.10\Inetd\HCINETD.NLS]  <Hummingbird Ltd.><7.1.0.0>
[PID: 744][D:\Ideas10\Iona\OrbixE2A\asp\5.1\bin\itconfig_rep.exe]  <IONA Technologies><5.1>
    [C:\WINDOWS\System32\it_app_svc4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\System32\it_art4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\System32\it_ifc4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\system32\it_iiop_profile4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\system32\it_giop4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\system32\it_iiop4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\System32\it_atli4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\System32\it_atli_iop4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\system32\it_atli_tcp_ws4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\system32\it_cfr_svr4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\System32\it_cfr4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\System32\it_poa4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\System32\it_location4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\System32\it_pss4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\System32\it_ots4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\System32\it_plain_text_key4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\system32\it_pss_db4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\System32\it_pss_r4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\System32\it_ots_psk4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\System32\it_db2.dll]  <Sleepycat Software><3.2.9>
    [C:\WINDOWS\system32\it_cfr_svr_store_pss_r4_vc60.dll]  <IONA Technologies><4>
    [C:\WINDOWS\system32\it_ots_lite4_vc60.dll]  <IONA Technologies><4>
[PID: 840][C:\WINDOWS\System32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe]  <Hummingbird Ltd.><7.1.0.0>
[PID: 1060][C:\WINDOWS\System32\tcpsvcs.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1040][C:\WINDOWS\System32\Hummingbird\Connectivity\7.10\Jconfig\hjavaw.exe]  <Hummingbird Ltd.><7.1.0.0>
[PID: 1620][d:\lixi\tools\Matlab5\webserver\bin\matlabserver.exe]  <N/A><N/A>
    [d:\lixi\tools\Matlab5\bin\libeng.dll]  <N/A><N/A>
    [d:\lixi\tools\Matlab5\bin\libmx.dll]  <N/A><N/A>
    [d:\lixi\tools\Matlab5\bin\libut.dll]  <N/A><N/A>
    [d:\lixi\tools\Matlab5\bin\libmi.dll]  <N/A><N/A>
    [d:\lixi\tools\Matlab5\bin\LMGR325C.dll]  <Globetrotter Software Inc><5.12b>
[PID: 1632][C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\javaw.exe]  <N/A><N/A>
    [C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\hotspot\jvm.dll]  <N/A><N/A>
    [C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\hpi.dll]  <N/A><N/A>
    [C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\verify.dll]  <N/A><N/A>
    [C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\java.dll]  <N/A><N/A>
    [C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\zip.dll]  <N/A><N/A>
    [C:\Program Files\Hummingbird\Connectivity\7.10\Jconfig\hclwutil.dll]  <Hummingbird Ltd.><7.1.0.0>
    [C:\Program Files\Hummingbird\Connectivity\7.10\Jconfig\humprdjc.dll]  <Hummingbird Ltd.><7.1.0.0>
    [C:\Program Files\Hummingbird\Connectivity\7.10\Jconfig\hcljwprod.dll]  <Hummingbird Ltd.><7.1.0.0>
    [C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\net.dll]  <N/A><N/A>
    [C:\Program Files\Hummingbird\Connectivity\7.10\Jconfig\hcljfileutility.dll]  <Hummingbird Ltd.><7.1.0.0>
[PID: 1968][C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe]  <Microsoft Corporation><7.00.9466>
[PID: 228][C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe]  <Dell Inc.><7, 0, 10, 0>
[PID: 252][C:\WINDOWS\System32\niSvcLoc.exe]  <National Instruments><7.0.0.10051>
    [C:\WINDOWS\System32\nisvcloc.dll]  <National Instruments><7.0.0.10051>
[PID: 240][C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe]  <Intel Corporation><9, 0, 2, 11>
[PID: 336][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 356][C:\Program Files\Symantec AntiVirus\Rtvscan.exe]  <Symantec Corporation><10.0.1.1000>
    [C:\WINDOWS\System32\CBA.DLL]  <LANDesk Software Ltd.><6.12.0.137 E>
    [C:\WINDOWS\System32\MsgSys.dll]  <LANDesk Software Ltd.><6.12.0.137 E>
    [C:\WINDOWS\System32\NTS.dll]  <LANDesk Software Ltd.><6.12.0.137 E>
    [C:\WINDOWS\System32\PDS.DLL]  <LANDesk Software Ltd.><6.12.0.137 E>
    [C:\Program Files\Symantec AntiVirus\NAVLU.dll]  <Symantec Corporation><10.0.1.1000>
    [C:\Program Files\Symantec AntiVirus\NAVNTUTL.DLL]  <Symantec Corporation><10.0.1.1000>
    [c:\program files\common files\symantec shared\ssc\ScsComms.dll]  <Symantec Corporation><10.0.1.1000>
    [C:\Program Files\Symantec AntiVirus\I2ldvp3.dll]  <Symantec Corporation><10.0.1.1000>
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  <Symantec Corporation><103.5.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ccL35.dll]  <Symantec Corporation><103.5.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ccDec.dll]  <Symantec Corporation><103.5.4.3>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\decsdk.dll]  <Symantec Corporation><3.02.12.35>
gototop
 

[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\ccScan.dll]  <Symantec Corporation><103.5.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL]  <Symantec Corporation><1.4.0.11>
    [C:\Program Files\Symantec AntiVirus\DefUtDCD.dll]  <Symantec Corporation><3.1.13a.0>
    [C:\Program Files\Symantec AntiVirus\SAVRT32.DLL]  <Symantec Corporation><9.5.0.44>
    [C:\Program Files\Symantec AntiVirus\IMail.dll]  <Symantec Corporation><10.0.1.1000>
    [C:\Program Files\Symantec AntiVirus\NotesExt.dll]  <Symantec Corporation><10.0.1.1000>
    [C:\Program Files\Symantec AntiVirus\vpmsece3.dll]  <Symantec Corporation><10.0.1.1000>
    [C:\Program Files\Symantec AntiVirus\SymProtectStorage.dll]  <Symantec Corporation><10.0.1.1000>
    [C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCEvt.dll]  <Symantec Corporation><1,5,1,3>
    [C:\Program Files\Symantec AntiVirus\DefUtDCS.dll]  <Symantec Corporation><3.1.13a.0>
    [C:\Program Files\Symantec\LiveUpdate\LuComServerPS_2_6.DLL]  <Symantec Corporation><2.6.18.0>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060611.006\ccEraser.dll]  <Symantec Corporation><106.1.5.2>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060611.006\ecmsvr32.dll]  <Symantec Corporation><61.1.0.11>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060611.006\NAVEX32a.DLL]  <Symantec Corporation><20061.1.0.14>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060611.006\NAVENG32.DLL]  <Symantec Corporation><20061.1.0.14>
    [C:\Program Files\Symantec AntiVirus\NAVAP32.DLL]  <Symantec Corporation><9.5.0.44>
[PID: 1916][C:\WINDOWS\System32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 1032][C:\WINDOWS\system32\nipalsm.exe]  <National Instruments Corporation><1.6.2f1>
    [C:\WINDOWS\system32\nipxirmu.dll]  <National Instruments Corporation><1.0.0f1>
    [C:\WINDOWS\system32\NIPALU.dll]  <National Instruments Corporation><1.6.2f1>
    [C:\WINDOWS\system32\nipalut.dll]  <National Instruments Corporation><1.6.2f1>
    [C:\WINDOWS\system32\NIPAL32.dll]  <National Instruments Corporation><1.6.2f1>
    [C:\WINDOWS\system32\NIINI32.dll]  <National Instruments><2.6.0 (Build 1)>
    [C:\Program Files\National Instruments\MAX\mxsutils.dll]  <National Instruments><3.0.0.3014>
    [C:\Program Files\National Instruments\MAX\mxsout.dll]  <National Instruments><3.0.0.3014>
    [C:\Program Files\National Instruments\MAX\mxsxport.dll]  <National Instruments><3.0.0.3014>
    [C:\WINDOWS\System32\nirpc.dll]  <National Instruments Corporation><3.0.1f1>
[PID: 1080][C:\WINDOWS\system32\nipalsm.exe]  <National Instruments Corporation><1.6.2f1>
    [C:\WINDOWS\system32\nidevldu.dll]  <National Instruments Corporation><1.0.0f0>
    [C:\WINDOWS\system32\niorbu.dll]  <National Instruments Corporation><1.0.1f0>
    [C:\WINDOWS\system32\NIPALU.dll]  <National Instruments Corporation><1.6.2f1>
    [C:\WINDOWS\system32\nipalut.dll]  <National Instruments Corporation><1.6.2f1>
    [C:\WINDOWS\system32\NIPAL32.dll]  <National Instruments Corporation><1.6.2f1>
    [C:\WINDOWS\system32\NIINI32.dll]  <National Instruments><2.6.0 (Build 1)>
[PID: 1616][C:\WINDOWS\System32\wbem\wmiprvse.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 3004][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll]  <VoyagerSoft, LLC><2.2.158.0>
    [C:\PROGRA~1\FlashGet\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
    [C:\WINDOWS\System32\msdmo.dll]  <N/A><N/A>
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  <N/A><N/A>
    [C:\Program Files\Hummingbird\Connectivity\7.10\HostExplorer\Ftp\heshell.dll]  <Hummingbird Ltd.><7.1.0.0>
    [D:\LiXi\Tools\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\PROGRA~1\ULTRAE~1\ue32ctmn.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll]  <Symantec Corporation><10.0.1.1000>
    [C:\WINDOWS\System32\igfxpph.dll]  <Intel Corporation><3.0.0.4363>
    [C:\WINDOWS\System32\hccutils.DLL]  <Intel Corporation><3.0.0.4363>
    [C:\WINDOWS\System32\igfxres.dll]  <Intel Corporation><3.0.0.4363>
    [C:\WINDOWS\System32\igfxress.dll]  <Intel Corporation><3.0.0.4363>
    [C:\WINDOWS\System32\igfxsrvc.dll]  <Intel Corporation><3.0.0.4363>
    [C:\WINDOWS\System32\SCTOOL~1.DLL]  <><1, 0, 0, 1>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><7.0.7.2006011200>
    [C:\Program Files\Lotus\Sametime Client\autoaway.dll]  <IBM Rehovot><6, 51, 0, 0>
[PID: 3904][C:\PROGRA~1\SYMANT~1\VPTray.exe]  <Symantec Corporation><10.0.1.1000>
    [C:\Program Files\Symantec AntiVirus\SAVRT32.DLL]  <Symantec Corporation><9.5.0.44>
    [C:\Program Files\Symantec AntiVirus\Cliproxy.dll]  <Symantec Corporation><10.0.1.1000>
    [C:\PROGRA~1\SYMANT~1\NAVNTUTL.DLL]  <Symantec Corporation><10.0.1.1000>
    [c:\program files\common files\symantec shared\ssc\ScsComms.dll]  <Symantec Corporation><10.0.1.1000>
    [C:\WINDOWS\System32\nts.dll]  <LANDesk Software Ltd.><6.12.0.137 E>
    [C:\WINDOWS\System32\cba.dll]  <LANDesk Software Ltd.><6.12.0.137 E>
    [C:\WINDOWS\System32\MsgSys.dll]  <LANDesk Software Ltd.><6.12.0.137 E>
    [C:\WINDOWS\System32\PDS.DLL]  <LANDesk Software Ltd.><6.12.0.137 E>
[PID: 3996][C:\Program Files\Dell\QuickSet\Quickset.exe]  <Dell Inc><7, 0, 10, 0>
    [C:\Program Files\Dell\QuickSet\IWH9.dll]  <Dell Inc><7, 0, 10, 0>
    [C:\Program Files\Dell\QuickSet\IWH10.dll]  <Dell Inc><7, 0, 10, 0>
    [C:\Program Files\Intel\Wireless\Bin\MurocApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\S24MUDLL.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\C1XStngs.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll]  <N/A><N/A>
    [C:\Program Files\Intel\Wireless\Bin\LSAWRAPI.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\D8021Xps.DLL]  <N/A><N/A>
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  <N/A><N/A>
    [C:\Program Files\Lotus\Sametime Client\autoaway.dll]  <IBM Rehovot><6, 51, 0, 0>
[PID: 4004][C:\WINDOWS\System32\msstart.exe]  <N/A><1, 0, 0, 1>
[PID: 164][C:\Program Files\DAEMON Tools\daemon.exe]  <DT Soft Ltd.><4.00.0.0>
    [C:\Program Files\DAEMON Tools\daemon.dll]  <DT Soft Ltd.><4.00.0.0>
    [C:\Program Files\DAEMON Tools\PFCTOC.DLL]  <Padus(R), Inc.><1, 0, 0, 12>
    [C:\Program Files\DAEMON Tools\Plugins\Images\bw5mount.dll]  <N/A><1.0.6.0>
    [C:\Program Files\DAEMON Tools\Plugins\Images\ccdmount.dll]  <GENERIC><1.10.0.0>
    [C:\Program Files\DAEMON Tools\Plugins\Images\mdsmount.dll]  <GENERIC><1.12.0.0>
    [C:\Program Files\DAEMON Tools\Plugins\Images\nrgmount.dll]  <GENERIC><1.11.0.0>
gototop
 

[C:\Program Files\DAEMON Tools\Plugins\Images\pdimount.dll]  <GENERIC><1.01.0.0>
[PID: 1312][C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe]  <Intel><9, 0, 2, 11>
    [C:\PROGRA~1\Intel\Wireless\Bin\IntelAE5.dll]  <Meetinghouse Data Communications><3, 0, 0, 60>
    [C:\PROGRA~1\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 2, 11>
    [C:\PROGRA~1\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\D8021Xps.DLL]  <N/A><N/A>
[PID: 2168][C:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 916][C:\Program Files\ISS\issSensors\DesktopProtection\blackice.exe]  <Internet Security Systems, Inc.><7.0.320>
    [C:\Program Files\ISS\issSensors\DesktopProtection\FileSec.dll]  <Internet Security Systems, Inc.><7.0.319>
[PID: 1712][C:\WINDOWS\System32\taskmgr.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  <N/A><N/A>
[PID: 2660][C:\WINDOWS\System32\igfxsrvc.exe]  <Intel Corporation><3.0.0.4363>
    [C:\WINDOWS\System32\igfxsrvc.dll]  <Intel Corporation><3.0.0.4363>
[PID: 3884][C:\Program Files\Kingsoft\Powerword 2003\Xdict.exe]  <Kingsoft Co, Ltd.><6, 0, 3, 0>
    [C:\Program Files\Kingsoft\Powerword 2003\ITextOut.dll]  <Kingsoft><1, 1, 0, 0>
    [C:\Program Files\Kingsoft\Powerword 2003\CJKTAB32.dll]  <N/A><N/A>
    [C:\Program Files\Kingsoft\Powerword 2003\XImage32.dll]  <N/A><N/A>
    [C:\Program Files\Kingsoft\Powerword 2003\xfile.dll]  <N/A><N/A>
    [C:\Program Files\Kingsoft\Powerword 2003\KPic10.dll]  <N/A><N/A>
    [C:\Program Files\Kingsoft\Powerword 2003\ijl11.dll]  <Intel Corporation><1.1.2>
    [C:\Program Files\Kingsoft\Powerword 2003\toTTSEngine50.dll]  <Kingsoft Corporation><1, 0, 0, 1>
    [C:\Program Files\Kingsoft\Powerword 2003\NormGrab.DLL]  <Kingsoft Co, Ltd.><6, 0, 0, 0>
    [C:\Program Files\Kingsoft\Powerword 2003\DicMngr.dll]  <Kingsoft><1, 0, 0, 0>
    [C:\Program Files\Kingsoft\Powerword 2003\DBCore10.dll]  <Kingsoft  Corp.><1, 0, 0, 0>
    [C:\Program Files\Kingsoft\Powerword 2003\XdictGrb.dll]  <Kingsoft Co, Ltd.><6, 0, 0, 0>
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  <N/A><N/A>
    [C:\Program Files\Lotus\Sametime Client\autoaway.dll]  <IBM Rehovot><6, 51, 0, 0>
[PID: 2072][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [c:\program files\google\googletoolbar1.dll]  <Google Inc.><3, 0, 131, 0>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><7.0.7.2006011200>
    [C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll]  <VoyagerSoft, LLC><2.2.158.0>
    [C:\PROGRA~1\FlashGet\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\WINDOWS\System32\Macromed\Common\SwSupport.dll]  <Macromedia, Inc.><10.0r210>
    [C:\Program Files\Lotus\Sametime Client\autoaway.dll]  <IBM Rehovot><6, 51, 0, 0>
[PID: 3896][C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE]  <Microsoft Corporation><11.0.6353>
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  <N/A><N/A>
    [C:\PROGRA~1\Kingsoft\POWERW~1\PWOFFI~1.DLL]  <Kingsoft Co, Ltd.><6, 0, 0, 0>
    [C:\Program Files\Symantec AntiVirus\vpmsece3.dll]  <Symantec Corporation><10.0.1.1000>
    [C:\Program Files\Symantec AntiVirus\SAVRT32.DLL]  <Symantec Corporation><9.5.0.44>
    [C:\Program Files\Lotus\Sametime Client\autoaway.dll]  <IBM Rehovot><6, 51, 0, 0>
[PID: 2144][C:\Program Files\Microsoft Office\Office\EXCEL.EXE]  <Microsoft Corporation><9.0.6627>
    [C:\Program Files\Lotus\Sametime Client\autoaway.dll]  <IBM Rehovot><6, 51, 0, 0>
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  <N/A><N/A>
[PID: 624][C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe]  <Adobe Systems Incorporated><7.0.8.2006051600>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\BIB.dll]  <Adobe Systems Incorporated><1.1.18>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.dll]  <Adobe Systems Incorporated><7.0.8.2006051600>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\AGM.dll]  <Adobe Systems Incorporated><4.14.45>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\CoolType.dll]  <Adobe Systems Incorporated><5.01.41>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\ACE.dll]  <Adobe Systems Incorporated><2.07.28>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Accessibility.api]  <Adobe Systems Incorporated><7.0.7.2006011300>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\AcroForm.api]  <Adobe Systems Incorporated><7.0.8.2006051600>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Annots.api]  <Adobe Systems Incorporated><7.0.7.2006011300>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Checkers.api]  <Adobe Systems Incorporated><7.0.5.2005092300>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\DigSig.api]  <Adobe Systems Incorporated><7.0.8.2006051600>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\eBook.api]  <Adobe Systems Incorporated><7.0.0.2004121400>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\EScript.api]  <Adobe Systems Incorporated><7.0.8.2006051600>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\EWH32.api]  <Adobe Systems Incorporated><7.0.8.2006051600>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\FileOpen.api]  <FileOpen Systems Inc.><5, 6, 24, 17>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\fOpen32.api]  <FileOpen Systems Inc.><1, 0, 0, 1>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\HLS.api]  <Adobe Systems Incorporated><7.0.0.2004121400>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\IA32.api]  <Adobe Systems Incorporated><7.0.5.2005092300>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\ImageViewer.API]  <Adobe Systems Inc.><7.0.0.41005>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\LegalPDF.api]  <Adobe Systems Incorporated><7.0.5.2005092300>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\MakeAccessible.api]  <Adobe Systems Incorporated><7.0.5.2005092300>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Multimedia.api]  <Adobe Systems Incorporated><7.0.5.2005092300>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PDDom.api]  <Adobe Systems Incorporated><7.0.7.2006011300>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks.api]  <Adobe Systems Incorporated><7.0.0.2004121400>
gototop
 

[C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PPKLite.api]  <Adobe Systems Incorporated><7.0.8.2006051600>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\reflow.api]  <Adobe Systems Incorporated><7.0.5.2005092300>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\SaveAsRTF.api]  <Adobe Systems Incorporated><7.0.5.2005092300>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Search.api]  <Adobe Systems Incorporated><7.0.0.2004121400>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Search5.api]  <Adobe Systems Incorporated><7.0.0.2004121400>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\SendMail.api]  <Adobe Systems Incorporated><7.0.5.2005092300>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Soap.api]  <Adobe Systems Incorporated><7.0.5.2005092300>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Spelling.api]  <Adobe Systems Incorporated><7.0.5.2005092300>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Updater.api]  <Adobe Systems Incorporated><7.0.8.2006051600>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\weblink.api]  <Adobe Systems Incorporated><7.0.7.2006011300>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\xdict32.API]  <Kingsoft Co, Ltd.><6, 0, 0, 0>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\fowp4kbd.api]  <FileOpen Systems Inc.><5, 3, 10, 18>
    [C:\WINDOWS\System32\ATMLIB.dll]  <Adobe Systems><5.1 Build 225>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\esdupdate.dll]  <Adobe Systems><3.1.0.9>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppint2.dll]  <FinePrint Software, LLC><2.15>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppr232.dll]  <FinePrint Software, LLC><2.15>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppgraf2.dll]  <FinePrint Software, LLC><2.15>
    [C:\Program Files\Adobe\Acrobat 7.0\Reader\SPPlugins\ADMPlugin.apl]  <Adobe Systems Incorporated><3.10x32>
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  <N/A><N/A>
[PID: 2860][C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe]  <FinePrint Software, LLC><2.15>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppr232.dll]  <FinePrint Software, LLC><2.15>
    [C:\Program Files\Lotus\Sametime Client\autoaway.dll]  <IBM Rehovot><6, 51, 0, 0>
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  <N/A><N/A>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  <Adobe Systems, Inc.><7.0.0.0>
[PID: 3408][C:\Program Files\Microsoft Office\Office\EXCEL.EXE]  <Microsoft Corporation><9.0.6627>
    [C:\Program Files\Lotus\Sametime Client\autoaway.dll]  <IBM Rehovot><6, 51, 0, 0>
[PID: 236][C:\Program Files\Lotus\Sametime Client\Connect.exe]  <Lotus Development Corporation><6, 51, 0, 0>
    [C:\Program Files\Lotus\Sametime Client\connecte.dll]  <Lotus Development Corporation><6, 51, 0, 0>
    [C:\PROGRA~1\Lotus\SAMETI~1\connect.ocx]  <Ubique Ltd.><6, 51, 0, 0>
    [C:\PROGRA~1\Lotus\SAMETI~1\connect.dll]  <Ubique Ltd.><6, 51, 0, 0>
    [C:\Program Files\Lotus\Sametime Client\autoaway.dll]  <IBM Rehovot><6, 51, 0, 0>
    [C:\Program Files\Common Files\Lotus\Sametime\vpaot.ocx]  <Ubique Ltd.><6, 51, 0, 0>
    [C:\PROGRA~1\COMMON~1\Lotus\Sametime\vpcore.ocx]  <Ubique Ltd.><6, 51, 0, 0>
    [C:\PROGRA~1\Lotus\SAMETI~1\VpStore.ocx]  <Ubique Ltd.><6, 51, 0, 0>
    [C:\PROGRA~1\COMMON~1\Lotus\Sametime\VpList.ocx]  <Ubique Ltd.><6, 51, 0, 0>
    [C:\PROGRA~1\COMMON~1\Lotus\Sametime\treeui.ocx]  <Ubique Ltd.><6, 51, 0, 0>
    [C:\PROGRA~1\COMMON~1\Lotus\Sametime\directui.ocx]  <Ubique Ltd.><6, 51, 0, 0>
    [C:\PROGRA~1\COMMON~1\Lotus\Sametime\ListUI.ocx]  <Ubique Ltd.><6, 51, 0, 0>
    [C:\PROGRA~1\COMMON~1\Lotus\Sametime\CommUI.ocx]  <Ubique Ltd.><6, 5, 1, 1>
    [C:\PROGRA~1\COMMON~1\Lotus\Sametime\MeetUI.ocx]  <Ubique Ltd.><6, 51, 0, 1>
    [C:\PROGRA~1\COMMON~1\Lotus\Sametime\InviteUI.ocx]  <Ubique Ltd.><6, 51, 0, 0>
    [C:\PROGRA~1\COMMON~1\Lotus\Sametime\commui.dll]  <Ubique Ltd.><6, 5, 1, 1>
    [C:\PROGRA~1\COMMON~1\Lotus\Sametime\meetui.dll]  <Ubique Ltd.><6, 51, 0, 1>
    [C:\PROGRA~1\COMMON~1\Lotus\Sametime\inviteui.dll]  <Ubique Ltd.><6, 51, 0, 0>
    [C:\PROGRA~1\Lotus\SAMETI~1\vpStore.dll]  <Ubique Ltd.><6, 51, 0, 0>
    [C:\PROGRA~1\COMMON~1\Lotus\Sametime\treeui.dll]  <Ubique Ltd.><6, 51, 0, 0>
    [C:\PROGRA~1\COMMON~1\Lotus\Sametime\directUI.dll]  <Ubique Ltd.><6, 51, 0, 0>
    [C:\PROGRA~1\COMMON~1\Lotus\Sametime\listUI.dll]  <Ubique Ltd.><6, 51, 0, 0>
[PID: 1416][D:\Documents and Settings\305013868.GEMEDASIA\Desktop\sreng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\Program Files\Lotus\Sametime Client\autoaway.dll]  <IBM Rehovot><6, 51, 0, 0>

==================================
文件关联
.TXT  Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  Error. [AutoCADScriptFile]
.CHM  Error. [C:\WINDOWS\hh.exe %1]
.HLP  Error. [C:\WINDOWS\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF  Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

双击我的电脑,工具,文件夹选项,查看,单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示确定更改时,单击“是”,清除“隐藏已知文件类型的扩展名
楼主是否清楚这4个服务是什么???
nipxirmu / nipxirmu]
<system32\nipalsm.exe><National Instruments Corporation>
[NI Service Locator / niSvcLoc]
<C:\WINDOWS\System32\niSvcLoc.exe -s><National Instruments>
[nidevldu / nidevldu]
<system32\nipalsm.exe><National Instruments Corporation>
Contivity VPN Service / ExtranetAccess]
<"C:\Program Files\Nortel Networks\Extranet_serv.exe"><Nortel Networks NA, Inc.>

ALT+CTRL+DELETE调出任务管理器,终止msstart.exe的进程,如果有的话。
运行System Repair Engineer,使用“启动项目,注册表”来删除以下选项。
(如果在注册表里无法识别那一下,可以选中一项后,点“编辑”这样会有很明细的路径)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<msstart><C:\WINDOWS\System32\msstart.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<1><\\asia.med.ge.com\sysvol\asia.med.ge.com\scripts\tools\tqcrunas\tqcrunas.exe -f \\asia.med.ge.com\sysvol\asia.med.ge.com\scripts\tools\tqcrunas\mvcmp.tqc> [这项很怪,如果你也不知道,建议删除]

删除
C:\WINDOWS\System32\msstart.exe
\\asia.med.ge.com
gototop
 

运行System Repair Engineer,使用“系统修复,文件关联,勾选“全选”点“修复”使所有扩展名都恢复正常。
修复后,请重启。
如果还未解决问题,请再扫份日志粘上来。
另盼告之那4个服务。
gototop
 

非常感谢无邪兄。
1关于上述4个服务,那是和NI公司的Labview软件相关的,应该不是病毒。
2我刚刚按你帖子,将msstart.exe删除,还不知道结果如何,但是我的诺顿现在无法检测病毒了,提示“could not start scan,scan engine return error 0x20000058”.(在删msstart.exe前已经这样了,估计是恶意网页搞的鬼)
3\\asia.med.ge.com 是我公司的某服务器,也许被病毒引用了。
再次感谢
gototop
 

请问在扫描结果最后的文件关联都是什么?请赐教
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT