瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 日志粘贴上来了,请红夜鬼过目!

12   2  /  2  页   跳转

日志粘贴上来了,请红夜鬼过目!

然后进了启动项目就跳出

附件附件:

下载次数:193
文件类型:application/octet-stream
文件大小:
上传时间:2007-1-10 10:48:44
描述:



gototop
 

打开后。。。

附件附件:

下载次数:121
文件类型:application/octet-stream
文件大小:
上传时间:2007-1-10 10:51:11
描述:



gototop
 

接着

附件附件:

下载次数:170
文件类型:application/octet-stream
文件大小:
上传时间:2007-1-10 10:52:07
描述:



gototop
 

修改后是这样的,可是。。。。没用,一刷新就又跳出提示了,

附件附件:

下载次数:196
文件类型:application/octet-stream
文件大小:
上传时间:2007-1-10 10:53:58
描述:



gototop
 

今天的日志:
[CODE]

2007-01-10,10:22:55

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <shell><Explorer.exe >  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <switch><c:\windows\system32\壁纸自动换.exe>  [N/A]
    <SoundMan><SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
    <coopen><C:\Program Files\coopen\coopen.exe>  [北京首都在线网络技术有限公司]
    <Alitalk><F:\软件\贸易通\AliTalk.EXE -hideframe>  [Alibaba]
    <Install Alitalk><C:\WINDOWS\temp\alitalk\alitalk.exe -hideframe>  [N/A]
    <helper.dll><C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>  []
    <HP Software Update><C:\Program Files\HP\HP Software Update\HPWuSchd2.exe>  [Hewlett-Packard Development Company, L.P.]
    <poco><; F:\poco\Poco2006.exe>  [广州数联软件有限公司 - http://www.poco.cn/]
    <pshed><C:\Program Files\poco\psched\psched.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe C:\WINDOWS\system32\jvmlts.exe>  [N/A]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\system32\coopen.scr>  [首都在线网络技术有限公司]
gototop
 

==================================
启动文件夹
[HP Digital Imaging Monitor]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\HP Digital Imaging Monitor.lnk --> C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [Hewlett-Packard Development Company, L.P.]><N>

==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Pml Driver HPZ12 / Pml Driver HPZ12][Running/Auto Start]
  <C:\WINDOWS\system32\HPZipm12.exe><HP>

==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AliIde / AliIde][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
  <System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
[CmdIde / CmdIde][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[IEEE-1284.4 Driver HPZid412 / HPZid412][Running/Manual Start]
  <system32\DRIVERS\HPZid412.sys><HP>
[Print Class Driver for IEEE-1284.4 HPZipr12 / HPZipr12][Running/Manual Start]
  <system32\DRIVERS\HPZipr12.sys><HP>
[USB to IEEE-1284.4 Translation Driver HPZius12 / HPZius12][Running/Manual Start]
  <system32\DRIVERS\HPZius12.sys><HP>
[nejjm / nejjm][Running/]
  <2 - 系统找不到指定的文件。
><N/A>
[npkcrypt / npkcrypt][Stopped/Auto Start]
  <\??\C:\Program Files\QQ2006\npkcrypt.sys><N/A>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Running/Manual Start]
  <system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[sdlgo / sdlgo][Running/Boot Start]
  <\SystemRoot\\SystemRoot\System32\drivers\sdlgo.sys><N/A>
gototop
 

==================================
浏览器加载项
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[SrchHook Class]
  {F08555B0-9CC3-11D2-AA8E-000000000000} <C:\WINDOWS\system32\IEBHO.dll, >
[雅虎助手]
  {5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Active Desktop Mover]
  {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[AutoLive]
  {7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2} <C:\PROGRA~1\3721\autolive.dll, >
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[OrderStream Class]
  {E65BE01D-8E13-46F8-BBBF-905FFFF4C00D} <C:\Program Files\poco\pocoorder\ComOrder.dll, 广州数联软件技术有限公司>
[SrchHook Class]
  {F08555B0-9CC3-11D2-AA8E-000000000000} <C:\WINDOWS\system32\IEBHO.dll, >
[使用迅雷下载]
  <C:\Program Files\Thunder\Program\GetUrl.htm, N/A>
[使用迅雷下载全部链接]
  <C:\Program Files\Thunder\Program\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
gototop
 

==================================
正在运行的进程
[PID: 436][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 492][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 516][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 560][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 572][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 724][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 768][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 872][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 952][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 996][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1184][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
    [C:\WINDOWS\system32\HpTcpMon.dll]  [Hewlett Packard, 6.01.00.009]
    [C:\WINDOWS\system32\hpzjrd01.dll]  [Hewlett Packard, 2.01.00.005]
    [C:\WINDOWS\system32\HPTcpMUI.dll]  [Microsoft Corporation, 6.01.00.009]
    [C:\WINDOWS\system32\hptcpmib.dll]  [Hewlett Packard, 6.01.00.009]
    [C:\WINDOWS\system32\hpzll054.dll]  [Hewlett-Packard Company, 60.054.45.00]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\hpzpp054.dll]  [Hewlett-Packard Corporation, 60.054.45.00]
[PID: 1316][C:\WINDOWS\system32\HPZipm12.exe]  [HP, 10, 1, 1, 5]
    [C:\WINDOWS\system32\HPZidr12.dll]  [HP, 10, 1, 1, 5]
[PID: 1340][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\hpowiax2.dll]  [Hewlett-Packard, 7.0.0.177]
[PID: 1372][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 732][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2904][C:\WINDOWS\Explorer.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\PROGRA~1\3721\alrex.dll]  [, 1, 0, 1, 1001]
    [C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]
    [C:\PROGRA~1\3721\autolive.dll]  [, 2, 5, 0, 1002]
    [C:\PROGRA~1\3721\alLiveEx.dll]  [ , 1, 0, 3, 1006]
    [C:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
[PID: 2960][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5, 1, 0, 52]
    [C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]
[PID: 2968][C:\Program Files\coopen\coopen.exe]  [北京首都在线网络技术有限公司, 1, 0, 0]
    [C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
[PID: 2980][C:\WINDOWS\system32\rundll32.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\PROGRA~1\3721\autolive.dll]  [, 2, 5, 0, 1002]
    [C:\PROGRA~1\3721\notifier.dll]  [, 2.5.0.1002]
    [C:\PROGRA~1\3721\alLiveEx.dll]  [ , 1, 0, 3, 1006]
    [C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]
[PID: 1700][C:\Program Files\HP\HP Software Update\HPWuSchd2.exe]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]
[PID: 2996][C:\Program Files\poco\psched\psched.exe]  [N/A, 1, 0, 0, 1]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]
[PID: 3004][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]
[PID: 3016][C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpquio08.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpqtra08.rsc]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpqtao08.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpotra08.dll]  [Hewlett-Packard Development Company, L.P., 70.0.219.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpotra08.rsc]  [Hewlett-Packard Development Company, L.P., 70.0.219.000]
    [C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]
    [C:\Program Files\HP\Digital Imaging\bin\hpqcob08.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpodio08.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpotradd.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpqrif08.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\Unload\hpnkhTA.dll]  [Hewlett-Packard, 7.0.0.229]
    [C:\Program Files\HP\Digital Imaging\bin\hpqmif08.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpodvd09.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpoddcomm09.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\WINDOWS\system32\hpzipr12.dll]  [HP, 10, 1, 1, 5]
    [C:\Program Files\HP\Digital Imaging\bin\hpocxi08.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\WINDOWS\system32\hpzidr12.dll]  [HP, 10, 1, 1, 5]
    [C:\Program Files\HP\Digital Imaging\bin\hpqusg.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[PID: 3516][C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpqmfc09.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpqtap08.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
gototop
 

[C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]
    [C:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.rsc]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpqsti08.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpqcob08.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpqstp08.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpodio08.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpocxi08.dll]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\Program Files\HP\Digital Imaging\bin\hpqsem08.rsc]  [Hewlett-Packard Development Company, L.P., 70.0.170.000]
    [C:\WINDOWS\system32\hpzipr12.dll]  [HP, 10, 1, 1, 5]
    [C:\Program Files\HP\Digital Imaging\bin\crm\hpqcrmcm.dll]  [Hewlett-Packard Company, 70.0.78.000]
    [C:\Program Files\HP\Digital Imaging\bin\crm\xmlparse.dll]  [N/A, 1, 0, 0, 1]
    [C:\Program Files\HP\Digital Imaging\bin\crm\xmltok.dll]  [N/A, 1, 0, 0, 1]
[PID: 2168][C:\Program Files\QQ2006\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]
    [C:\Program Files\QQ2006\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 1536][C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE]  [Microsoft Corporation, 11.0.8026]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\hpzle054.dll]  [HP, 60.054.45.00]
[PID: 3612][C:\Program Files\QQ2006\QQ.EXE]  [TENCENT, 0, 0, 0, 0]
    [C:\Program Files\QQ2006\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 370]
    [C:\Program Files\QQ2006\PYKer.dll]  [飘云 http://www.pyqq.cn, 飘云]
    [C:\Program Files\QQ2006\ipsearcher.dll]  [, 1.0.0.3]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]
    [C:\Program Files\QQ2006\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [C:\Program Files\QQ2006\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [C:\Program Files\QQ2006\QQAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\Program Files\QQ2006\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQMainFrame.dll]  [N/A, N/A]
    [C:\Program Files\QQ2006\CQQApplication.dll]  [N/A, N/A]
    [C:\Program Files\QQ2006\NewSkin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\HostingMgr.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\CameraDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\MailSummary.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [C:\Program Files\QQ2006\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\GroupLive.dll]  [N/A, N/A]
    [C:\Program Files\QQ2006\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQPlugin.dll]  [N/A, N/A]
    [C:\Program Files\QQ2006\QQAllInOne.dll]  [N/A, N/A]
    [C:\Program Files\QQ2006\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [C:\Program Files\QQ2006\QQCustomFace.dll]  [N/A, N/A]
    [C:\Program Files\QQ2006\QQSysMsgMng.dll]  [N/A, N/A]
    [C:\Program Files\QQ2006\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\Program Files\QQ2006\QRingMng.dll]  [N/A, N/A]
    [C:\Program Files\QQ2006\QQMagicFace.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [C:\Program Files\QQ2006\QQAvatar.dll]  [N/A, N/A]
    [C:\Program Files\QQ2006\QQSceneMng.dll]  [N/A, N/A]
    [C:\Program Files\QQ2006\GroupConnection.dll]  [Tencent, 0, 3, 3, 5]
    [C:\Program Files\QQ2006\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [C:\Program Files\QQ2006\VPortal.dll]  [, 1, 0, 0, 4]
    [C:\Program Files\QQ2006\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [C:\Program Files\QQ2006\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 240]
    [C:\Program Files\QQ2006\BQQApplication.dll]  [N/A, N/A]
    [C:\Program Files\QQ2006\CommercesMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [C:\Program Files\QQ2006\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 3, 30]
[PID: 2372][C:\WINDOWS\system32\wuauclt.exe]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]
[PID: 3404][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
gototop
 

[C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\PROGRA~1\3721\scrblock.dll]  [3721, 2.5.0.1002]
    [C:\PROGRA~1\3721\alrex.dll]  [, 1, 0, 1, 1001]
    [C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]
    [C:\PROGRA~1\3721\autolive.dll]  [, 2, 5, 0, 1002]
    [C:\PROGRA~1\3721\alLiveEx.dll]  [ , 1, 0, 3, 1006]
    [C:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [C:\WINDOWS\system32\IEBHO.dll]  [, 1, 0, 0, 1]
[PID: 1300][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\PROGRA~1\3721\scrblock.dll]  [3721, 2.5.0.1002]
    [C:\PROGRA~1\3721\alrex.dll]  [, 1, 0, 1, 1001]
    [C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]
    [C:\PROGRA~1\3721\autolive.dll]  [, 2, 5, 0, 1002]
    [C:\PROGRA~1\3721\alLiveEx.dll]  [ , 1, 0, 3, 1006]
    [C:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [C:\WINDOWS\system32\IEBHO.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
[PID: 1868][C:\Program Files\Thunder\Program\Thunder5.exe]  [Thunder Networking Technologies,LTD, 5.4.0.226]
    [C:\Program Files\Thunder\Program\UpdateDownload.dll]  [N/A, N/A]
    [C:\Program Files\Thunder\Program\msgmanage.dll]  [N/A, N/A]
    [C:\Program Files\Thunder\Program\historyinfo_manage.dll]  [Thunder Networking Technologies,LTD, 5, 2, 0, 148]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]
    [C:\Program Files\Thunder\Program\download_interface.dll]  [Thunder Networking Technologies,LTD, 2, 0, 0, 1]
    [C:\Program Files\Thunder\Program\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
    [C:\Program Files\Thunder\Program\log4cplus.dll]  [, 1, 0, 2, 1]
    [C:\Program Files\Thunder\Program\asyn_dns.dll]  [N/A, N/A]
    [C:\Program Files\Thunder\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 1, 0, 18]
    [C:\Program Files\Thunder\Program\FloatBar.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
    [C:\Program Files\Thunder\Program\iTargetAd.dll]  [N/A, N/A]
[PID: 2788][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.015\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [C:\PROGRA~1\3721\helper.dll]  [, 2, 5, 0, 1003]
    [C:\WINDOWS\system32\jvmlts.dll]  [N/A, N/A]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost
0.0.0.0 182838.com
0.0.0.0 204.177.92.68
0.0.0.0 asiafriendfinder.com
0.0.0.0 asqin123.51.net
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0 www.jpbeauty.com
0.0.0.0 beautishow.com
0.0.0.0 goodmovies88.com
0.0.0.0 hothack.home.chinaren.com
0.0.0.0 hualiao.net
0.0.0.0 iplus.allyes.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 asqin123.51.net
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
219.153.32.215 auto.search.msn.com

==================================
API HOOK
N/A

==================================


[/CODE]
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT