瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 日志贴上来了.大家帮忙看看吧,谢谢

12   2  /  2  页   跳转

日志贴上来了.大家帮忙看看吧,谢谢

==================================
正在运行的进程
[PID: 744][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 828][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 852][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\reset5.dll]  [N/A, N/A]
    [c:\WINDOWS\System32\LgNotify.dll]  [Intel Corporation, 8, 0, 0, 162]
[PID: 896][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 908][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1080][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1252][C:\Program Files\Rising\Rav\CCenter.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 1268][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1304][C:\WINDOWS\System32\S24EvMon.exe]  [Intel Corporation , 8, 0, 0, 162]
[PID: 1548][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1604][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1684][C:\Program Files\Rising\Rfw\rfwsrv.exe]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 30]
    [C:\Program Files\Rising\Rfw\RfwRule.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 3]
    [C:\Program Files\Rising\Rfw\rfwlog.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 2]
    [C:\Program Files\Rising\Rfw\Rfwdrv.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 9]
    [C:\Program Files\Rising\Rfw\MonDrv.dll]  [rs, 1, 0, 0, 4]
    [C:\Program Files\Rising\Rfw\ProcLib.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 5]
    [C:\Program Files\Rising\Rfw\mPorts.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[PID: 1944][C:\WINDOWS\system32\ZCfgSvc.exe]  [Intel Corporation, 8, 0, 0, 162]
    [C:\WINDOWS\system32\PfMgrApi.dll]  [Intel Corporation, 8, 0, 0, 162]
    [C:\WINDOWS\system32\PsRegApi.dll]  [Intel Corporation, 8, 0, 0, 162]
    [C:\WINDOWS\system32\WConfig.DLL]  [Intel Corporation, 8, 0, 0, 162]
    [C:\WINDOWS\system32\WiFiAdap.DLL]  [Intel Corporation, 8, 0, 0, 162]
    [C:\WINDOWS\system32\PsGuiMgr.dll]  [Intel Corporation., 8, 0, 0, 162]
    [C:\WINDOWS\system32\C1XStngs.dll]  [Intel Corporation, 8, 0, 0, 162]
    [c:\Program Files\Intel\PROSetWireless\PROSet\CHS\ZcSvcCHS.dll]  [Intel Corporation, 8, 0, 0, 107]
    [c:\Program Files\Intel\PROSetWireless\PROSet\CHS\PmApiCHS.dll]  [Intel Corporation, 8, 0, 0, 107]
    [C:\WINDOWS\system32\S24MUDLL.dll]  [Intel Corporation, 8, 0, 0, 162]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [c:\Program Files\Intel\PROSetWireless\PROSet\CHS\C1XStCHS.dll]  [Intel Corporation, 8, 0, 0, 107]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]
[PID: 176][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\windhcp.ocx]  [N/A, N/A]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.7.2006011200]
    [D:\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\WINDOWS\System32\igfxpph.dll]  [Intel Corporation, 3.0.0.3775]
    [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3.0.0.3775]
[PID: 240][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\system32\hpzlnt05.dll]  [HP, 2,118,0,0]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll]  [Windows (R) 2000 DDK provider, 5.00.2195.1620]
[PID: 396][C:\Program Files\Rising\Rav\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 628][C:\PROGRA~1\svhost32.exe]  [N/A, N/A]
    [C:\DOCUME~1\吕麦菲\LOCALS~1\Temp\f.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 704][C:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 772][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3034]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 780][C:\Program Files\Rising\Rfw\rfwmain.exe]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 56]
    [C:\Program Files\Rising\Rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
    [C:\Program Files\Rising\Rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rfw\RfwCtrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [C:\Program Files\Rising\Rfw\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [C:\Program Files\Rising\Rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]
[PID: 1136][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1172][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  [Microsoft Corporation, 7.00.9466]
[PID: 1216][C:\WINDOWS\System32\RegSrvc.exe]  [Intel Corporation, 8, 0, 0, 162]
[PID: 1248][C:\WINDOWS\system32\srvany.exe]  [N/A, N/A]
[PID: 1524][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1528][C:\WINDOWS\system32\resetservice.exe]  [N/A, N/A]
[PID: 1932][C:\Program Files\Rising\Rav\RsAgent.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 1952][C:\WINDOWS\msagent\AgentSvr.exe]  [Microsoft Corporation, 2.00.0.3422]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 1668][C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe]  [HP, 2,118,0,0]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\spool\drivers\w32x86\3\HPZR3205.DLL]  [HP, 2,118,0,0]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 2108][C:\WINDOWS\System32\hkcmd.exe]  [Intel Corporation, 3.0.0.3775]
    [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3.0.0.3775]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\igfxdev.dll]  [Intel Corporation, 3.0.0.3775]
    [C:\WINDOWS\System32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.3775]
    [C:\WINDOWS\System32\igfxres.dll]  [Intel Corporation, 3.0.0.3775]
    [C:\WINDOWS\System32\igfxhk.dll]  [Intel Corporation, 3.0.0.3775]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 2200][C:\WINDOWS\System32\1XConfig.exe]  [Intel, 8, 0, 0, 162]
    [C:\WINDOWS\System32\IntelAE5.dll]  [Meetinghouse Data Communications, 1, 42, 19, 1]
    [C:\WINDOWS\System32\SSLEAY32.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\LIBEAY32.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\PsRegApi.dll]  [Intel Corporation, 8, 0, 0, 162]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 2212][C:\WINDOWS\CameraFixer.exe]  [, 1, 0, 0, 2]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 2228][C:\WINDOWS\vsnpstd3.exe]  [, 1, 0, 2, 2]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 2248][C:\WINDOWS\Download\svhost32.exe]  [N/A, N/A]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[PID: 2260][C:\Program Files\Rising\KakaToolBar\runiep.exe]  [Beijing Rising Technology Co., Ltd., 1, 0, 1, 3]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\iep_ctrl.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 2308][C:\DOCUME~1\吕麦菲\LOCALS~1\Temp\mhs2.exe]  [N/A, N/A]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\DOCUME~1\吕麦菲\LOCALS~1\Temp\mhs2.dll]  [N/A, N/A]
gototop
 

[PID: 2352][C:\Program Files\Common Files\Microsoft Shared\MSINFO\svchost.exe]  [N/A, N/A]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
[PID: 2384][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 3000][C:\WINDOWS\System32\wuauclt.exe]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
[PID: 3628][C:\Program Files\Real\RealPlayer\RealPlay.exe]  [RealNetworks, Inc., 6.0.12.872]
    [C:\WINDOWS\System32\PNCRT.dll]  [Real Networks, Inc, 6.0.0.0]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Real\Update_OB\rnms3270.dll]  [RealNetworks, Inc., 7.0.1.2866]
    [C:\Program Files\Common Files\Real\Common\objb3201.dll]  [RealNetworks, Inc., 0.1.0.5858]
    [C:\Program Files\Common Files\Real\RCAPlugins\uisy3201.dll]  [RealNetworks, Inc., 0.1.0.3363]
    [C:\Program Files\Common Files\Real\Update_OB\rnad3201.dll]  [RealNetworks, Inc., 0.1.0.3034]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Real\Update_OB\rnqu3270.dll]  [RealNetworks, Inc., 7.0.0.3286]
    [C:\Program Files\Common Files\Real\Update_OB\setu3270.dll]  [RealNetworks, Inc., 7.0.0.3914]
[PID: 680][C:\Program Files\MSN Messenger\msnmsgr.exe]  [Microsoft Corporation, 8.1.0168.00_ClientV8.1]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\msdmo.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 3240][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\KakaTool.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 2, 6]
    [D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.7.2006011200]
    [C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll]  [Microsoft Corporation, 01.02.3000.1001]
    [C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\zh-cn\msntb.dll]  [Microsoft Corporation, 01.02.5000.1021]
    [C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\zh-cn\mtbres.dll]  [Microsoft Corporation, 01.02.5000.1021]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
[PID: 3664][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]
[PID: 2172][F:\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\WINDOWS\System32\xpdhcp.dll]  [N/A, N/A]
    [C:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\xydll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\dllwm.dll]  [N/A, N/A]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT