瑞星卡卡安全论坛
寻找者 - 2005-12-20 14:44:00
Logfile of HijackThis v1.99.1
Scan saved at 14:43:43, on 2005-12-20
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
运行进程:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\rising\Rav\CCenter.exe
C:\Program Files\rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\rising\Rav\RavStub.exe
C:\WINNT\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\rising\Rav\RavTask.exe
C:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\BitComet\BitComet.exe
C:\Downloads\software\HijaclThis V1.99.1 汉化版\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\BitComet\BitCometBar\BitCometBar0.1.dll
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O11 - Options group: [!CNS] 网络实名
O12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131333305234
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O18 - Protocol: ipp - (no CLSID) - (没有文件)
O18 - Protocol: mp3 - (no CLSID) - (没有文件)
O18 - Protocol: msdaipp - (no CLSID) - (没有文件)
不言放弃 - 2005-12-20 14:45:00
日志不会
寻找者 - 2005-12-20 14:48:00
症状:最近上网,打开IE后,发现特别的慢,并且在运行比如WORD等程序时,很久电脑没有响应,然后就突然的死机。查看进程表后发现explorer.exe经常占用85%到100%的内存。我查看了一下,我仅仅开了瑞星杀毒软件和BT下载程序。请问如何确定是什么原因吗?
请两位斑竹看看,是否有毒,哪些需要修复的?谢谢!
O18 - Protocol: ipp - (no CLSID) - (没有文件)这种没有文件的项为什么修复不了啊?
不言放弃 - 2005-12-20 14:49:00
建议导出全部日志
baohe - 2005-12-20 14:53:00
【回复“寻找者”的帖子】
日志有点儿怪。
HijackThis不好使了?
寻找者 - 2005-12-20 14:56:00
Logfile of HijackThis v1.99.1
Scan saved at 14:57:10, on 2005-12-20
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
运行进程:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\rising\Rav\CCenter.exe
C:\Program Files\rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\rising\Rav\RavStub.exe
C:\WINNT\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\rising\Rav\RavTask.exe
C:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Downloads\software\HijaclThis V1.99.1 汉化版\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\BitComet\BitCometBar\BitCometBar0.1.dll
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O11 - Options group: [!CNS] 网络实名
O12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131333305234
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O18 - Protocol: ipp - (no CLSID) - (没有文件)
O18 - Protocol: mp3 - (no CLSID) - (没有文件)
O18 - Protocol: msdaipp - (no CLSID) - (没有文件)
寻找者 - 2005-12-20 14:57:00
上面是重新扫描的日志。
请问:怎么怪了?谢谢
不言放弃 - 2005-12-20 14:57:00
日志没有问题
不过日志不全
BlackStone - 2005-12-20 14:58:00
用Autoruns保存一个日志发上来
日志保存方法:选择File->Save菜单项
保存日志时注意选择Options->Hide Microsoft Entries菜单项(设置了这项后点工具栏的刷新按钮)工具的下载、使用参考
http://forum.ikaka.com/topic.asp?board=28&artid=7318038
寻找者 - 2005-12-20 15:01:00
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
+ C:\WINNT\system32\userinit.exeUserinit Logon ApplicationMicrosoft Corporationc:\winnt\system32\userinit.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
+ Explorer.exeWindows ExplorerMicrosoft Corporationc:\winnt\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ RavMonRavMonBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmon.exe
+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe
+ Synchronization ManagerMicrosoft Synchronization ManagerMicrosoft Corporationc:\winnt\system32\mobsync.exe
C:\Documents and Settings\All Users\「开始」菜单\程序\启动
+ Acrobat Assistant.lnkAcroTrayAdobe Systems Inc.c:\program files\adobe\acrobat 5.0\distillr\acrotray.exe
+ Microsoft Office.lnkMicrosoft Office XP componentMicrosoft Corporationc:\program files\microsoft office\office10\osa.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ ctfmon.exeCicero LoaderMicrosoft Corporationc:\winnt\system32\ctfmon.exe
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
+ Address Book 5Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe
+ CRLUpdateUPDCRLMicrosoft Corporationc:\winnt\system32\updcrl.exe
+ EnableRevocationMicrosoft(C) Register ServerMicrosoft Corporationc:\winnt\system32\regsvr32.exe
+ Internet Explorer 6IE 5.0 Per-User Install UtilityMicrosoft Corporationc:\winnt\system32\ie4uinit.exe
+ Internet Explorer 访问Windows NT User Data Migration ToolMicrosoft Corporationc:\winnt\system32\shmgrate.exe
+ Microsoft Outlook Express 6Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe
+ Microsoft Windows Media PlayerADVPACKMicrosoft Corporationc:\winnt\system32\advpack.dll
+ NetMeeting 3.01ADVPACKMicrosoft Corporationc:\winnt\system32\advpack.dll
+ Outlook Express 访问Windows NT User Data Migration ToolMicrosoft Corporationc:\winnt\system32\shmgrate.exe
+ Windows Media PlayerMicrosoft Windows Media Player 安装实用程序Microsoft Corporationc:\winnt\inf\unregmp2.exe
+ Windows 桌面更新Microsoft(C) Register ServerMicrosoft Corporationc:\winnt\system32\regsvr32.exe
+ 自定义浏览器Microsoft Internet Explorer Customization DLLMicrosoft Corporationc:\winnt\system32\iedkcs32.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
+ Browseui 预加载程序Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 组件类别缓存程序Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ Network.ConnectionTrayNetwork Connections ShellMicrosoft Corporationc:\winnt\system32\netshell.dll
+ SysTraySystray shell service objectMicrosoft Corporationc:\winnt\system32\stobject.dll
+ WebCheckWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll
+ shell32.dllWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ Microsoft Office HTML Icon HandlerMicrosoft Office XP componentMicrosoft Corporationc:\program files\microsoft office\office10\msohev.dll
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll
+ Shell Extensions for RealOne PlayerRealOne Player Shell ExtensionsRealNetworksc:\program files\real\realone player\rpshellext.dll
+ TuneUp Shredder Shell Context Menu ExtensionTuneUp Shredder Shell ExtensionTuneUp Software GmbHc:\program files\tuneup utilities 2004\sdshelex.dll
+ Web FoldersMicrosoft Web FoldersMicrosoft Corporationc:\program files\common files\microsoft shared\web folders\msonsext.dll
+ WinRAR shell extensionc:\program files\winrar\rarext.dll
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ Web 文件夹Microsoft Web FoldersMicrosoft Corporationc:\program files\common files\microsoft shared\web folders\msonsext.dll
HKLM\Software\Classes\Folder\Shellex\ColumnHandlers
+ Fax Tiff Data Column ProviderFax Tiff Data Column ProviderMicrosoft Corporationc:\winnt\system32\faxshell.dll
+ ShAVColumnProvider classDocProp2Microsoft Corporationc:\winnt\system32\docprop2.dll
+ Version Column ProviderDocProp2Microsoft Corporationc:\winnt\system32\docprop2.dll
+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ {24F14F01-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ {24F14F02-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ AcroIEHlprObj ClassAcroIEHelper Modulec:\program files\adobe\acrobat 5.0\acrobat\activex\acroiehelper.ocx
+ IeCatch2 Classjccatch ModuleAmaze Softc:\program files\flashget\jccatch.dll
寻找者 - 2005-12-20 15:03:00
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
+ shdocvw.dllShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ FlashGet BarFlashGet IE BarAmaze Softc:\program files\flashget\fgiebar.dll
Task Scheduler
+ 1-Click Maintenance.jobTuneUp System OptimizerTuneUp Software GmbHc:\program files\tuneup utilities 2004\systemoptimizer.exe
HKLM\System\CurrentControlSet\Services
+ Browser维护网络上计算机的最新列表以及提供这个列表给请求的程序。Microsoft Corporationc:\winnt\system32\services.exe
+ Dhcp通过注册和更改 IP 地址以及 DNS 名称来管理网络配置。Microsoft Corporationc:\winnt\system32\services.exe
+ dmserver逻辑磁盘管理器监视狗服务Microsoft Corporationc:\winnt\system32\services.exe
+ Dnscache解析和缓冲域名系统 (DNS) 名称。Microsoft Corporationc:\winnt\system32\services.exe
+ Eventlog记录程序和 Windows 发送的事件消息。事件日志包含对诊断问题有所帮助的信息。您可以在“事件查看器”中查看报告。Microsoft Corporationc:\winnt\system32\services.exe
+ lanmanserver提供 RPC 支持、文件、打印以及命名管道共享。Microsoft Corporationc:\winnt\system32\services.exe
+ lanmanworkstation提供网络链结和通讯。Microsoft Corporationc:\winnt\system32\services.exe
+ LmHosts允许对“TCP/IP 上 NetBIOS (NetBT)”服务以及 NetBIOS 名称解析的支持。Microsoft Corporationc:\winnt\system32\services.exe
+ Messenger发送和接收系统管理员或者“警报器”服务传递的消息。Microsoft Corporationc:\winnt\system32\services.exe
+ NtmsSvc管理可移动媒体、驱动程序和库。Microsoft Corporationc:\winnt\system32\svchost.exe
+ PlugPlay管理设备安装以及配置,并且通知程序关于设备更改的情况。Microsoft Corporationc:\winnt\system32\services.exe
+ PolicyAgent管理 IP 安全策略以及启动 ISAKMP/Oakley (IKE) 和 IP 安全驱动程序。Microsoft Corporationc:\winnt\system32\lsass.exe
+ ProtectedStorage提供对敏感数据(如私钥)的保护性存储,以便防止未授权的服务,过程或用户对其的非法访问。Microsoft Corporationc:\winnt\system32\services.exe
+ RemoteRegistry允许远程注册表操作。Microsoft Corporationc:\winnt\system32\regsvc.exe
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwsrv.exe
+ RpcSs提供终结点映射程序 (endpoint mapper) 以及其它 RPC 服务。Microsoft Corporationc:\winnt\system32\svchost.exe
+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe
+ SamSs存储本地用户帐户的安全信息。Microsoft Corporationc:\winnt\system32\lsass.exe
+ Schedule允许程序在指定时间运行。Microsoft Corporationc:\winnt\system32\mstask.exe
+ seclogon在不同凭据下启用启动过程Microsoft Corporationc:\winnt\system32\services.exe
+ SENS跟踪系统事件,如登录 Windows,网络以及电源事件等。将这些事件通知给 COM+ 事件系统 “订阅者(subscriber)”。Microsoft Corporationc:\winnt\system32\svchost.exe
+ Spooler将文件加载到内存中以便迟后打印。Microsoft Corporationc:\winnt\system32\spoolsv.exe
+ StiSvcStill Image Devices MonitorMicrosoft Corporationc:\winnt\system32\stisvc.exe
+ TrkWks当文件在网络域的 NTFS 卷中移动时发送通知。Microsoft Corporationc:\winnt\system32\services.exe
+ WinMgmt提供系统管理信息。Microsoft Corporationc:\winnt\system32\wbem\winmgmt.exe
+ wuauserv允许下载并安装 Windows 更新。如果此服务被禁用,计算机将不能使用 Windows Update 网站的自动更新功能。Microsoft Corporationc:\winnt\system32\svchost.exe
HKLM\System\CurrentControlSet\Services
寻找者 - 2005-12-20 15:03:00
+ ACPIACPI Driver for NTMicrosoft Corporationc:\winnt\system32\drivers\acpi.sys
+ ACPIECACPI Embedded Controller DriverMicrosoft Corporationc:\winnt\system32\drivers\acpiec.sys
+ AFDAncillary Function Driver for WinSockMicrosoft Corporationc:\winnt\system32\drivers\afd.sys
+ AgereSoftModemSoftModem Device DriverAgere Systemsc:\winnt\system32\drivers\agrsm.sys
+ aksusbAladdin USB Key DriverAladdin Knowledge Systemsc:\winnt\system32\drivers\aksusb.sys
+ AsyncMacRAS Asynchronous Media DriverMicrosoft Corporationc:\winnt\system32\drivers\asyncmac.sys
+ atapiIDE/ATAPI Port DriverMicrosoft Corporationc:\winnt\system32\drivers\atapi.sys
+ AtmarpcATM ARP Client ProtocolMicrosoft Corporationc:\winnt\system32\drivers\atmarpc.sys
+ audstubAudStub DriverMicrosoft Corporationc:\winnt\system32\drivers\audstub.sys
+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\winnt\system32\drivers\basetdi.sys
+ C-DillaFile not found: C:\WINNT\System32\drivers\CDANT.SYS
+ CCDECODEWDM Closed Caption VBI CodecMicrosoft Corporationc:\winnt\system32\drivers\ccdecode.sys
+ CdaC15BAMacrovision SECURITY DriverMacrovision Europe Ltdc:\winnt\system32\drivers\cdac15ba.sys
+ CdromSCSI CD-ROM DriverMicrosoft Corporationc:\winnt\system32\drivers\cdrom.sys
+ CmBattControl Method Battery DriverMicrosoft Corporationc:\winnt\system32\drivers\cmbatt.sys
+ CoachCapCOACHCAPZoran Microelectronics Ltd.c:\winnt\system32\drivers\coachcap.sys
+ CompbattComposite Battery DriverMicrosoft Corporationc:\winnt\system32\drivers\compbatt.sys
+ cs429xCrystal AC9x WDM DriverCirrus Logic, Inc.c:\winnt\system32\drivers\cwawdm.sys
+ DiskPnP Disk DriverMicrosoft Corporationc:\winnt\system32\drivers\disk.sys
+ dmioNT Disk Manager I/O DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmio.sys
+ dmloadNT Disk Manager Startup DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmload.sys
+ DMusicMicrosoft DirectMusic Software Synthesizer (WDM)Microsoft Corporationc:\winnt\system32\drivers\dmusic.sys
+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys
+ FdcFloppy Disk Controller DriverMicrosoft Corporationc:\winnt\system32\drivers\fdc.sys
+ FlpydiskFloppy DriverMicrosoft Corporationc:\winnt\system32\drivers\flpydisk.sys
+ FsVgaFull Screen Video DriverMicrosoft Corporationc:\winnt\system32\drivers\fsvga.sys
+ FtdiskFT Disk DriverMicrosoft Corporationc:\winnt\system32\drivers\ftdisk.sys
+ GEARAspiWDMCDRom Class Filter DriverGEAR Software Inc.c:\winnt\system32\drivers\gearaspiwdm.sys
+ GpcGeneric Packet ClassifierMicrosoft Corporationc:\winnt\system32\drivers\msgpc.sys
+ hardlockHardlock Device Driver for Windows NTAladdin Knowledge Systemsc:\winnt\system32\drivers\hardlock.sys
+ HaspntHASP Kernel Device Driver for Windows NTAladdin Knowledge Systemsc:\winnt\system32\drivers\haspnt.sys
+ HidUsbUSB Miniport Driver for Input DevicesMicrosoft Corporationc:\winnt\system32\drivers\hidusb.sys
+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys
+ HookRegc:\program files\rising\rav\hookreg.sys
+ HookSysHooksysRisingc:\program files\rising\rav\hooksys.sys
+ i8042prti8042 Port DriverMicrosoft Corporationc:\winnt\system32\drivers\i8042prt.sys
+ ialmController Hub for Intel Graphics DriverIntel Corporationc:\winnt\system32\drivers\ialmnt5.sys
+ IpFilterDriverIP Traffic Filter DriverMicrosoft Corporationc:\winnt\system32\drivers\ipfltdrv.sys
+ IpInIpIP in IP Tunnel DriverMicrosoft Corporationc:\winnt\system32\drivers\ipinip.sys
+ IpNatIP Network Address TranslatorMicrosoft Corporationc:\winnt\system32\drivers\ipnat.sys
+ IPSECIPSEC driverMicrosoft Corporationc:\winnt\system32\drivers\ipsec.sys
+ IRENUMInfra-Red Bus EnumeratorMicrosoft Corporationc:\winnt\system32\drivers\irenum.sys
+ isapnpPNP ISA Bus DriverMicrosoft Corporationc:\winnt\system32\drivers\isapnp.sys
+ KbdclassKeyboard Class DriverMicrosoft Corporationc:\winnt\system32\drivers\kbdclass.sys
+ kmixerKernel Mode Audio MixerMicrosoft Corporationc:\winnt\system32\drivers\kmixer.sys
+ mcnahook.sysNative API Filter driver for System Safety Monitor (tm)Max Computingc:\program files\system safety monitor\mcnahook.sys
+ MEMSCANMemScan Driver瑞星软件有限公司c:\program files\rising\rav\memscan.sys
+ MouclassMouse Class DriverMicrosoft Corporationc:\winnt\system32\drivers\mouclass.sys
+ mouhidHID Mouse Filter DriverMicrosoft Corporationc:\winnt\system32\drivers\mouhid.sys
+ MPEMicrosoft MPE to IP FilterMicrosoft Corporationc:\winnt\system32\drivers\mpe.sys
+ MSKSSRVMS KS ServerMicrosoft Corporationc:\winnt\system32\drivers\mskssrv.sys
+ MSPCLOCKMS Proxy ClockMicrosoft Corporationc:\winnt\system32\drivers\mspclock.sys
+ MSPQMMS Proxy Quality ManagerMicrosoft Corporationc:\winnt\system32\drivers\mspqm.sys
+ MSTEEWDM Tee/Communication Transform Filter Microsoft Corporationc:\winnt\system32\drivers\mstee.sys
+ NABTSFECWDM NABTS/FEC VBI CodecMicrosoft Corporationc:\winnt\system32\drivers\nabtsfec.sys
+ NbfNetBEUI ProtocolMicrosoft Corporationc:\winnt\system32\drivers\nbf.sys
+ NdisIPMicrosoft IP DriverMicrosoft Corporationc:\winnt\system32\drivers\ndisip.sys
+ NdisTapiRemote Access NDIS TAPI DriverMicrosoft Corporationc:\winnt\system32\drivers\ndistapi.sys
+ NdisuioNDIS 用户模式 I/O 协议Microsoft Corporationc:\winnt\system32\drivers\ndisuio.sys
+ NdisWanRemote Access NDIS WAN DriverMicrosoft Corporationc:\winnt\system32\drivers\ndiswan.sys
+ NetBTNetBios over TcpipMicrosoft Corporationc:\winnt\system32\drivers\netbt.sys
+ NetDetectNetwork Card Detection driverMicrosoft Corporationc:\winnt\system32\drivers\netdtect.sys
+ New0c:\winnt\system32\new.sys
+ NwlnkFltIPX Traffic Filter DriverMicrosoft Corporationc:\winnt\system32\drivers\nwlnkflt.sys
+ NwlnkFwdIPX Traffic Forwarder DriverMicrosoft Corporationc:\winnt\system32\drivers\nwlnkfwd.sys
+ ParallelParallel Printer DriverMicrosoft Corporationc:\winnt\system32\drivers\parallel.sys
+ ParportParallel Port DriverMicrosoft Corporationc:\winnt\system32\drivers\parport.sys
+ PCINT Plug and Play PCI EnumeratorMicrosoft Corporationc:\winnt\system32\drivers\pci.sys
+ PCIIdeGeneric PCI IDE Bus DriverMicrosoft Corporationc:\winnt\system32\drivers\pciide.sys
+ PcmciaPCMCIA Bus DriverMicrosoft Corporationc:\winnt\system32\drivers\pcmcia.sys
+ pfcPadus(R) ASPI ShellPadus, Inc.c:\winnt\system32\drivers\pfc.sys
+ POWERKEYc:\program files\launch manager\powerkey.sys
+ PptpMiniportWAN Miniport (PPTP)Microsoft Corporationc:\winnt\system32\drivers\raspptp.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\winnt\system32\drivers\ptilink.sys
+ RasAcdRemote Access Auto Connection DriverMicrosoft Corporationc:\winnt\system32\drivers\rasacd.sys
+ Rasl2tpWAN Miniport (L2TP)Microsoft Corporationc:\winnt\system32\drivers\rasl2tp.sys
+ RasptiDirect ParallelMicrosoft Corporationc:\winnt\system32\drivers\raspti.sys
+ RCARCA filterMicrosoft Corporationc:\winnt\system32\drivers\rca.sys
+ redbookRedbook Audio Filter DriverMicrosoft Corporationc:\winnt\system32\drivers\redbook.sys
+ RsFwDrvnt_fwdrvRisingc:\program files\rising\rfw\rsfwdrv.sys
+ rtl8139NDIS 5.0 driver Realtek Semiconductor Corporation c:\winnt\system32\drivers\rtl8139.sys
+ SfloppySCSI Floppy DriverMicrosoft Corporationc:\winnt\system32\drivers\sfloppy.sys
+ SLIPMicrosoft Slip Deframing Filter MinidriverMicrosoft Corporationc:\winnt\system32\drivers\slip.sys
+ streamipMicrosoft IP DriverMicrosoft Corporationc:\winnt\system32\drivers\streamip.sys
+ swenumPlug and Play Software Device EnumeratorMicrosoft Corporationc:\winnt\system32\drivers\swenum.sys
+ swmidiMicrosoft GS Wavetable SynthesizerMicrosoft Corporationc:\winnt\system32\drivers\swmidi.sys
+ SymEventSymantec Event LibrarySymantec Corporationc:\program files\symantec\symevent.sys
+ SynTPSynaptics Touchpad DriverSynaptics, Inc.c:\winnt\system32\drivers\syntp.sys
+ sysaudioSystem Audio WDM FilterMicrosoft Corporationc:\winnt\system32\drivers\sysaudio.sys
+ TcpipTCP/IP Protocol DriverMicrosoft Corporationc:\winnt\system32\drivers\tcpip.sys
+ uhcdUniversal Host Controller DriverMicrosoft Corporationc:\winnt\system32\drivers\uhcd.sys
+ UpdateUpdate DriverMicrosoft Corporationc:\winnt\system32\drivers\update.sys
+ usbehciEHCI eUSB Miniport DriverMicrosoft Corporationc:\winnt\system32\drivers\usbehci.sys
+ usbhubDefault Hub Driver for USBMicrosoft Corporationc:\winnt\system32\drivers\usbhub.sys
+ usbhub20Default Hub Driver for USB 2.0Microsoft Corporationc:\winnt\system32\drivers\usbhub20.sys
+ usbprintUSB Printer driverMicrosoft Corporationc:\winnt\system32\drivers\usbprint.sys
+ usbscanUSB Scanner DriverMicrosoft Corporationc:\winnt\system32\drivers\usbscan.sys
+ USBSTORUSB Mass Storage Class DriverMicrosoft Corporationc:\winnt\system32\drivers\usbstor.sys
+ VgaSaveVGA/Super VGA Video DriverMicrosoft Corporationc:\winnt\system32\drivers\vga.sys
+ WanarpRemote Access IP ARP DriverMicrosoft Corporationc:\winnt\system32\drivers\wanarp.sys
+ Wbuttonc:\winnt\system32\drivers\wbutton.sys
+ wdmaudMMSYSTEM Wave/Midi API mapperMicrosoft Corporationc:\winnt\system32\drivers\wdmaud.sys
+ WSTCODECWDM WST Codec DriverMicrosoft Corporationc:\winnt\system32\drivers\wstcodec.sys
+ {5C8B2B65-A385-11d5-A78B-00104B672758}Ch7017 MinidriverIntel Corporationc:\winnt\system32\drivers\a310.sys
+ {6080A529-897E-4629-A488-ABA0C29B635E}Intel Graphics Platform (SoftBIOS) Driver for Windows 2000(R) & Windows XP(TM)Intel Corporationc:\winnt\system32\drivers\ialmsbw.sys
+ {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}Intel Graphics Chipset (KCH) Driver for Windows 2000(R) & Windows XP(TM)Intel Corporationc:\winnt\system32\drivers\ialmkchw.sys
不言放弃 - 2005-12-20 15:03:00
日志没有问题
寻找者 - 2005-12-20 15:04:00
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
+ autocheck autochk *Auto Check UtilityMicrosoft Corporationc:\winnt\system32\autochk.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
+ Your Image File Name Here without a pathSymbolic Debugger for Windows 2000Microsoft Corporationc:\winnt\system32\ntsd.exe
HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls
+ advapi32Advanced Windows 32 Base APIMicrosoft Corporationc:\winnt\system32\advapi32.dll
+ comdlg32Common Dialogs DLLMicrosoft Corporationc:\winnt\system32\comdlg32.dll
+ gdi32GDI Client DLLMicrosoft Corporationc:\winnt\system32\gdi32.dll
+ imagehlpWindows NT Image HelperMicrosoft Corporationc:\winnt\system32\imagehlp.dll
+ kernel32Windows NT BASE API Client DLLMicrosoft Corporationc:\winnt\system32\kernel32.dll
+ lz32LZ Expand/Compress API DLLMicrosoft Corporationc:\winnt\system32\lz32.dll
+ ole32Microsoft OLE for WindowsMicrosoft Corporationc:\winnt\system32\ole32.dll
+ oleaut32Microsoft Corporationc:\winnt\system32\oleaut32.dll
+ olecli32Object Linking and Embedding Client LibraryMicrosoft Corporationc:\winnt\system32\olecli32.dll
+ olecnv32Microsoft OLE for WindowsMicrosoft Corporationc:\winnt\system32\olecnv32.dll
+ olesvr32Object Linking and Embedding Server LibraryMicrosoft Corporationc:\winnt\system32\olesvr32.dll
+ olethk32Microsoft OLE for WindowsMicrosoft Corporationc:\winnt\system32\olethk32.dll
+ rpcrt4Remote Procedure Call RuntimeMicrosoft Corporationc:\winnt\system32\rpcrt4.dll
+ shell32Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ urlInternet Shortcut Shell Extension DLLMicrosoft Corporationc:\winnt\system32\url.dll
+ urlmonOLE32 Extensions for Win32Microsoft Corporationc:\winnt\system32\urlmon.dll
+ user32Windows 2000 USER API Client DLLMicrosoft Corporationc:\winnt\system32\user32.dll
+ versionVersion Checking and File Installation LibrariesMicrosoft Corporationc:\winnt\system32\version.dll
+ wininetInternet Extensions for Win32Microsoft Corporationc:\winnt\system32\wininet.dll
+ wldap32Win32 LDAP API DLLMicrosoft Corporationc:\winnt\system32\wldap32.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
+ crypt32chainCrypto API32Microsoft Corporationc:\winnt\system32\crypt32.dll
+ cryptnetCrypto Network Related APIMicrosoft Corporationc:\winnt\system32\cryptnet.dll
+ cscdllOffline Network AgentMicrosoft Corporationc:\winnt\system32\cscdll.dll
+ sclgntfySecondary Logon Service Notification DLLMicrosoft Corporationc:\winnt\system32\sclgntfy.dll
+ SensLognCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\winnt\system32\wlnotify.dll
+ wzcnotifWireless Zero Configuration Service UIMicrosoft Corporationc:\winnt\system32\wzcdlg.dll
HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{84F93DA0-A9FE-4457-96DC-D8C9DE088A94}] DATAGRAM 6Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{84F93DA0-A9FE-4457-96DC-D8C9DE088A94}] SEQPACKET 6Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{AAD44F12-0F54-4810-916F-8E17034D4E9F}] DATAGRAM 7Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{AAD44F12-0F54-4810-916F-8E17034D4E9F}] SEQPACKET 7Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{CCE5C574-1EA7-4EB7-851E-57EC2BB9F558}] DATAGRAM 5Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{CCE5C574-1EA7-4EB7-851E-57EC2BB9F558}] SEQPACKET 5Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{6019FC74-E8FD-4724-8E59-5D8D9CF34AA9}] DATAGRAM 8Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{6019FC74-E8FD-4724-8E59-5D8D9CF34AA9}] SEQPACKET 8Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{7319F228-E110-4B2C-9870-0ABC3CA81B9F}] DATAGRAM 9Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{7319F228-E110-4B2C-9870-0ABC3CA81B9F}] SEQPACKET 9Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{99A3B646-C7D9-44E7-91FC-5717B12E706C}] DATAGRAM 4Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{99A3B646-C7D9-44E7-91FC-5717B12E706C}] SEQPACKET 4Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\Nbf_{561DAA7F-05D1-4CF1-89EC-7FA9CE94ADBD}] DATAGRAM 12Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\Nbf_{561DAA7F-05D1-4CF1-89EC-7FA9CE94ADBD}] SEQPACKET 12Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\Nbf_{CE4EF98C-A166-4C0A-8EAC-7DE8AB689BA5}] DATAGRAM 3Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\Nbf_{CE4EF98C-A166-4C0A-8EAC-7DE8AB689BA5}] SEQPACKET 3Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{01551322-F969-42DC-B30C-4C30C30C477F}] DATAGRAM 10Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{01551322-F969-42DC-B30C-4C30C30C477F}] SEQPACKET 10Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{561DAA7F-05D1-4CF1-89EC-7FA9CE94ADBD}] DATAGRAM 13Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{561DAA7F-05D1-4CF1-89EC-7FA9CE94ADBD}] SEQPACKET 13Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{BDE87539-FAFE-4B24-992D-D613A6F626DE}] DATAGRAM 11Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{BDE87539-FAFE-4B24-992D-D613A6F626DE}] SEQPACKET 11Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{C7A470EA-6AA2-4A11-8CC1-C01EB5C72C92}] DATAGRAM 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{C7A470EA-6AA2-4A11-8CC1-C01EB5C72C92}] SEQPACKET 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{CE4EF98C-A166-4C0A-8EAC-7DE8AB689BA5}] DATAGRAM 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{CE4EF98C-A166-4C0A-8EAC-7DE8AB689BA5}] SEQPACKET 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{E1505C9F-E353-46E7-8FAD-C1DF0FF01CCB}] DATAGRAM 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{E1505C9F-E353-46E7-8FAD-C1DF0FF01CCB}] SEQPACKET 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD Tcpip [RAW/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD Tcpip [TCP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD Tcpip [UDP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ RSVP TCP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\winnt\system32\rsvpsp.dll
+ RSVP UDP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\winnt\system32\rsvpsp.dll
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
+ BJ Language MonitorLangage Monitor for Canon Bubble-Jet PrinterMicrosoft Corporationc:\winnt\system32\cnbjmon.dll
+ FPP1:FinePrint pdfFactoryFinePrint Software, LLCc:\winnt\system32\fppmon1.dll
+ hpZJLanguageMonitorHP1Zenographicsc:\winnt\system32\zlmhp1.dll
+ Local PortLocal Spooler DLLMicrosoft Corporationc:\winnt\system32\localspl.dll
+ PDF PortAcrobat ? PDF PortAdobe Systems Incorporated.c:\winnt\system32\pdfports.dll
+ PJL Language MonitorSpooler Setup DLLMicrosoft Corporationc:\winnt\system32\pjlmon.dll
+ Standard TCP/IP PortStandard TCP/IP Port Monitor DLLMicrosoft Corporationc:\winnt\system32\tcpmon.dll
+ USB MonitorStandard USB printing Port Monitor DLLMicrosoft Corporationc:\winnt\system32\usbmon.dll
+ Windows NT Fax MonitorFax Print MonitorMicrosoft Corporationc:\winnt\system32\msfaxmon.dll
寻找者 - 2005-12-20 15:07:00
对不起,没有隐藏WINDOWS,下面是隐藏后的,帮忙看一下,谢谢!
不言放弃 - 2005-12-20 15:07:00
看得眼花
楼主机器有什么异常
寻找者 - 2005-12-20 15:07:00
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ RavMonRavMonBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmon.exe
+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe
C:\Documents and Settings\All Users\「开始」菜单\程序\启动
+ Acrobat Assistant.lnkAcroTrayAdobe Systems Inc.c:\program files\adobe\acrobat 5.0\distillr\acrotray.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll
+ Shell Extensions for RealOne PlayerRealOne Player Shell ExtensionsRealNetworksc:\program files\real\realone player\rpshellext.dll
+ TuneUp Shredder Shell Context Menu ExtensionTuneUp Shredder Shell ExtensionTuneUp Software GmbHc:\program files\tuneup utilities 2004\sdshelex.dll
+ WinRAR shell extensionc:\program files\winrar\rarext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ AcroIEHlprObj ClassAcroIEHelper Modulec:\program files\adobe\acrobat 5.0\acrobat\activex\acroiehelper.ocx
+ IeCatch2 Classjccatch ModuleAmaze Softc:\program files\flashget\jccatch.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ FlashGet BarFlashGet IE BarAmaze Softc:\program files\flashget\fgiebar.dll
Task Scheduler
+ 1-Click Maintenance.jobTuneUp System OptimizerTuneUp Software GmbHc:\program files\tuneup utilities 2004\systemoptimizer.exe
HKLM\System\CurrentControlSet\Services
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwsrv.exe
+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe
HKLM\System\CurrentControlSet\Services
+ AgereSoftModemSoftModem Device DriverAgere Systemsc:\winnt\system32\drivers\agrsm.sys
+ aksusbAladdin USB Key DriverAladdin Knowledge Systemsc:\winnt\system32\drivers\aksusb.sys
+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\winnt\system32\drivers\basetdi.sys
+ C-DillaFile not found: C:\WINNT\System32\drivers\CDANT.SYS
+ CdaC15BAMacrovision SECURITY DriverMacrovision Europe Ltdc:\winnt\system32\drivers\cdac15ba.sys
+ CoachCapCOACHCAPZoran Microelectronics Ltd.c:\winnt\system32\drivers\coachcap.sys
+ cs429xCrystal AC9x WDM DriverCirrus Logic, Inc.c:\winnt\system32\drivers\cwawdm.sys
+ dmioNT Disk Manager I/O DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmio.sys
+ dmloadNT Disk Manager Startup DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmload.sys
+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys
+ GEARAspiWDMCDRom Class Filter DriverGEAR Software Inc.c:\winnt\system32\drivers\gearaspiwdm.sys
+ hardlockHardlock Device Driver for Windows NTAladdin Knowledge Systemsc:\winnt\system32\drivers\hardlock.sys
+ HaspntHASP Kernel Device Driver for Windows NTAladdin Knowledge Systemsc:\winnt\system32\drivers\haspnt.sys
+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys
+ HookRegc:\program files\rising\rav\hookreg.sys
+ HookSysHooksysRisingc:\program files\rising\rav\hooksys.sys
+ ialmController Hub for Intel Graphics DriverIntel Corporationc:\winnt\system32\drivers\ialmnt5.sys
+ mcnahook.sysNative API Filter driver for System Safety Monitor (tm)Max Computingc:\program files\system safety monitor\mcnahook.sys
+ MEMSCANMemScan Driver瑞星软件有限公司c:\program files\rising\rav\memscan.sys
+ New0c:\winnt\system32\new.sys
+ pfcPadus(R) ASPI ShellPadus, Inc.c:\winnt\system32\drivers\pfc.sys
+ POWERKEYc:\program files\launch manager\powerkey.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\winnt\system32\drivers\ptilink.sys
+ RsFwDrvnt_fwdrvRisingc:\program files\rising\rfw\rsfwdrv.sys
+ rtl8139NDIS 5.0 driver Realtek Semiconductor Corporation c:\winnt\system32\drivers\rtl8139.sys
+ SymEventSymantec Event LibrarySymantec Corporationc:\program files\symantec\symevent.sys
+ SynTPSynaptics Touchpad DriverSynaptics, Inc.c:\winnt\system32\drivers\syntp.sys
+ Wbuttonc:\winnt\system32\drivers\wbutton.sys
+ {5C8B2B65-A385-11d5-A78B-00104B672758}Ch7017 MinidriverIntel Corporationc:\winnt\system32\drivers\a310.sys
+ {6080A529-897E-4629-A488-ABA0C29B635E}Intel Graphics Platform (SoftBIOS) Driver for Windows 2000(R) & Windows XP(TM)Intel Corporationc:\winnt\system32\drivers\ialmsbw.sys
+ {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}Intel Graphics Chipset (KCH) Driver for Windows 2000(R) & Windows XP(TM)Intel Corporationc:\winnt\system32\drivers\ialmkchw.sys
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
+ FPP1:FinePrint pdfFactoryFinePrint Software, LLCc:\winnt\system32\fppmon1.dll
+ hpZJLanguageMonitorHP1Zenographicsc:\winnt\system32\zlmhp1.dll
+ PDF PortAcrobat ? PDF PortAdobe Systems Incorporated.c:\winnt\system32\pdfports.dll
影子110 - 2005-12-20 15:36:00
+ FPP1:FinePrint pdfFactoryFinePrint Software, LLCc:\winnt\system32\fppmon1.dll
+ hpZJLanguageMonitorHP1Zenographicsc:\winnt\system32\zlmhp1.dll
这两个~~~
(你可以先去掉前面的勾试试看~~~)
寻找者 - 2005-12-20 16:17:00
您所说的哪两项肯定没问题!
请斑竹帮忙看一下啊!
寻找者 - 2005-12-20 16:37:00
天天泡泡同志,能麻烦你抽空看一下吗?谢谢!
BlackStone - 2005-12-20 16:52:00
看不出问题,用RootkitRevealer扫描看看
工具使用下载参考http://forum.ikaka.com/topic.asp?board=28&artid=7538008
1
© 2000 - 2026 Rising Corp. Ltd.