瑞星卡卡安全论坛
death9999 - 2005-12-28 10:08:00
最近总用一些网站自动弹出
System Repair Engineer 2.0.12.350 (2.0 RC 1)
Windows XP Professional Service Pack 2 - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Super Rabbit CDNotify><C:\Program Files\Super Rabbit\MagicSet\srcdnoti.exe /LOAD>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<STYLEXP><C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<msnmsgr><; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<run><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ASUS Probe><C:\Program Files\ASUS\Probe\AsusProb.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Smapp><C:\Program Files\Analog Devices\SoundMAX\SMTray.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<nwiz><; nwiz.exe /install>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvMediaCenter><; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RfwMain><"C:\Program Files\rising\Rfw\rfwmain.exe" -Startup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Super Rabbit SRRestore><C:\Program Files\Super Rabbit\MagicSet\srrest.exe /autosave>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<KernelFaultCheck><; %systemroot%\system32\dumprep 0 -k>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SysExplr><; F:\JB\SYSEXPLR.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Knight V><; >
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<AddrPlus3><RUNDLL32.EXE C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll,Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NMGameX_AutoRun><; C:\WINDOWS\system32\Rundll32.exe nmgamex.dll,LiveProcess /aa>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Super Rabbit SafeEdit><C:\Program Files\Super Rabbit\MagicSet\SRFC.EXE /Load>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"C:\Program Files\rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ExFilter><Rundll32.exe "C:\PROGRA~1\CNNIC\Cdn\cdnspie.dll,ExecFilter solo">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<DAEMON Tools-2052><; ; "I:\Daemon\daemon.exe" -lang 2052>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<DTService><rundll32.exe C:\DOCUME~1\Bolton.Z\LOCALS~1\Temp\RarSFX4\DTSERV~1.DLL,Load>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
==================================
启动文件夹
[Microsoft Office]
<C:\Documents and Settings\All Users.WINDOWS\「开始」菜单\程序\启动\Microsoft Office.lnk><N>
[LCDPlayer]
<C:\Documents and Settings\All Users.WINDOWS\「开始」菜单\程序\启动\LCDPlayer.lnk><H>
[TeamTalk语音社区]
<C:\Documents and Settings\All Users.WINDOWS\「开始」菜单\程序\启动\TeamTalk语音社区.Lnk><N>
[Adobe Reader Speed Launch]
<C:\Documents and Settings\All Users.WINDOWS\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk><N>
[CPUCooL]
<C:\Documents and Settings\Bolton.Z\「开始」菜单\程序\启动\CPUCooL.lnk><N>
[腾讯QQ]
<C:\Documents and Settings\Bolton.Z\「开始」菜单\程序\启动\腾讯QQ.lnk><H>
[Adobe Gamma]
<C:\Documents and Settings\Bolton.Z\「开始」菜单\程序\启动\Adobe Gamma.lnk><N>
==================================
服务
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Autodesk Licensing Service / Autodesk Licensing Service]
<"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk>
[CPUCooLServer Service / CPUCooLServer]
<"C:\Program Files\CPUCooL\CooLSrv.exe"><N/A>
[InstallDriver Table Manager / IDriverT]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[RaySat_3dsmax8 Server / mi-raysat_3dsmax8]
<F:\3D\mentalray\satellite\raysat_3dsmax8server.exe><N/A>
[npkcsvc / npkcsvc]
<C:\WINDOWS\system32\npkcsvc.exe><INCA Internet Co., Ltd.>
[NVIDIA Display Driver Service / NVSvc]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Rising Personal Firewall Service / RfwService]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SoundMAX Agent Service / SoundMAX Agent Service (default)]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[StyleXPService / StyleXPService]
<"C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe"><>
death9999 - 2005-12-28 10:09:00
==================================
浏览器加载项
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Tencent Browser Helper]
{0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\AddrPlus\IEHelp.dll, Tencent>
[IDDTInitObj Class]
{15DDE989-CD45-4561-BF99-D22C0D5C2B74} <I:\UC\UCddt\ddtinit.dll, N/A>
[NaviHelperObj Class]
{3E422F49-1566-40D3-B43D-077EF739AC32} <C:\WINDOWS\NaviHelper.dll, TODO: <公司名>>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <I:\QQ2005\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[MMSAssist BHO]
{6671A431-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL, >
[KillObj Class]
{66C28884-4E5D-494B-80C9-CAA27528FD6D} <I:\UC\UCddt\ddtkillw.ocx, 北京新浪信息技术有限公司>
[IeCatch2 Class]
{A5366673-E8CA-11D3-9CD9-0090271D075B} <I:\FLASHG~1\jccatch.dll, Amaze Soft>
[MacroMediapd]
{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} <C:\WINDOWS\system32\microapmddt.dll, MacroMedia>
[CoTGT_BHO Class]
{C333CF63-767F-4831-94AC-E683D962C63C} <, N/A>
[浩方对战平台]
{0A155D3C-68E2-4215-A47A-E800A446447A} <F:\浩方对战平台\GameClient.exe, 上海浩方在线信息技术有限公司>
[新浪UC]
{2253922F-1B26-4C74-8B57-E3AEE748DBB8} <I:\UC\UC.exe, 北京新浪信息技术有限公司>
[解霸]
{367E0A21-8601-4986-9C9A-153BF5ACA118} <F:\JB\MPLAYER.EXE, N/A>
[MMSAssistMenu]
{6671A433-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL, >
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <I:\QQ2005\QQ.EXE, TENCENT>
[FlashGet]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <I:\FLASHG~1\flashget.exe, Amaze Soft>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <I:\QQ2005\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[新浪点点通]
{F60C7D81-8471-4D40-AAFE-56D318F34C2D} <I:\UC\UCddt\DDTONG~1.DLL, 北京新浪信息技术有限公司>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[]
{974AD624-EA50-4831-A6C0-3040F6665396} <I:\UC\UCddt\rssband.dll, 北京新浪信息技术有限公司>
[新浪点点通阅读器]
{F0646DC8-58CD-4C64-8F6B-525043914685} <I:\UC\UCddt\rssband.dll, 北京新浪信息技术有限公司>
[金山快译(&K)]
{6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <F:\金山快译\IEBand.dll, 金山软件股份有限公司>
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <I:\FLASHG~1\fgiebar.dll, Amaze Soft>
[新浪点点通]
{F60C7D81-8471-4D40-AAFE-56D318F34C2D} <I:\UC\UCddt\DDTONG~1.DLL, 北京新浪信息技术有限公司>
[WebActivater Control]
{3D8F74EE-8692-4F8F-B8D2-7522E732519E} <C:\WINDOWS\system32\WEBACT~1.OCX, QQ>
[PortalCom Control 2.0]
{48038521-20FB-11D8-BC64-00B0D07A8A19} <C:\WINDOWS\DOWNLO~1\PORTAL~1.OCX, Huawei Co. Ltd.>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, >
[Npv Control]
{9675ABBF-8D0B-4956-868C-934B5A7928D4} <C:\WINDOWS\system32\npv.ocx, ?????>
[MsnMessengerSetupDownloadControl Class]
{B38870E4-7ECB-40DA-8C6A-595F0A5519FF} <C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[NPKCX Control]
{D6FCA8ED-4715-43DE-9BD2-2789778A5B09} <C:\WINDOWS\system32\npkcx.ocx, INCA Internet Co., Ltd.>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Tencent Browser Helper]
{0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\AddrPlus\IEHelp.dll, Tencent>
[IDDTInitObj Class]
{15DDE989-CD45-4561-BF99-D22C0D5C2B74} <I:\UC\UCddt\ddtinit.dll, N/A>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\MSDXM.OCX, Microsoft Corporation>
[Tabular Data Control]
{333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[NaviHelperObj Class]
{3E422F49-1566-40D3-B43D-077EF739AC32} <C:\WINDOWS\NaviHelper.dll, TODO: <公司名>>
[PortalCom Control 2.0]
{48038521-20FB-11D8-BC64-00B0D07A8A19} <C:\WINDOWS\DOWNLO~1\PORTAL~1.OCX, Huawei Co. Ltd.>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <I:\QQ2005\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[MMSAssist BHO]
{6671A431-5C3D-463D-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL, >
[KillObj Class]
{66C28884-4E5D-494B-80C9-CAA27528FD6D} <I:\UC\UCddt\ddtkillw.ocx, 北京新浪信息技术有限公司>
[金山快译(&K)]
{6C3797D2-3FEF-4CD4-B654-D3AE55B4128C} <F:\金山快译\IEBand.dll, 金山软件股份有限公司>
[搜虎]
{7A38130D-BEB7-4D60-BE7A-4C4AB6A85CD1} <, N/A>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[]
{974AD624-EA50-4831-A6C0-3040F6665396} <I:\UC\UCddt\rssband.dll, 北京新浪信息技术有限公司>
[IeCatch2 Class]
{A5366673-E8CA-11D3-9CD9-0090271D075B} <I:\FLASHG~1\jccatch.dll, Amaze Soft>
[MacroMediapd]
{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} <C:\WINDOWS\system32\microapmddt.dll, MacroMedia>
[CoTGT_BHO Class]
{C333CF63-767F-4831-94AC-E683D962C63C} <, N/A>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <I:\FLASHG~1\fgiebar.dll, Amaze Soft>
[新浪点点通阅读器]
{F0646DC8-58CD-4C64-8F6B-525043914685} <I:\UC\UCddt\rssband.dll, 北京新浪信息技术有限公司>
[新浪点点通]
{F60C7D81-8471-4D40-AAFE-56D318F34C2D} <I:\UC\UCddt\DDTONG~1.DLL, 北京新浪信息技术有限公司>
[ >> 彩信发送 <<]
<res://C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL/mms.htm, N/A>
[上传到QQ网络硬盘]
<I:\QQ2005\AddToNetDisk.htm, N/A>
[使用彩信超级自写发送到手机]
<http://mms.sina.com.cn/mmsnews.html, N/A>
[使用新浪下载助手下载]
<I:\UC\UCddt\sinadl.htm, N/A>
[使用网际快车下载]
<I:\FLASHG~1\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<I:\FLASHG~1\jc_all.htm, N/A>
[发送图片到手机(&M)]
<http://sms.sina.com.cn/diy/send.html?from=467, N/A>
[导出到 Microsoft Excel(&x)]
<res://I:\Office\Office10\EXCEL.EXE/3000, N/A>
[导出当前页到超星阅览器(&A)]
<F:\SSREADER36\ss_all.htm, N/A>
[导出选中部分到超星阅览器(&S)]
<F:\SSREADER36\ss_select.htm, N/A>
[收藏此页到新浪ViVi]
<http://vivi.sina.com.cn/collect/click.php?agent=ddt, N/A>
[新浪搜索]
<http://cha.sina.com.cn/ddt.html, N/A>
[添加到QQ自定义面板]
<I:\QQ2005\AddPanel.htm, N/A>
[添加到QQ表情]
<I:\QQ2005\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<I:\QQ2005\SendMMS.htm, N/A>
[解霸实时播放]
<F:\JB\MPURLGET.HTM, N/A>
death9999 - 2005-12-28 10:10:00
==================================
正在运行的进程
[PID: 468][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 516][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 540][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 584][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 596][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 756][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 816][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 884][C:\Program Files\rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 900][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\System32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 924][C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe] <><0, 20, 0, 3000>
[PID: 972][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 1036][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 1056][C:\Program Files\rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 6>
[C:\Program Files\rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\Program Files\rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[C:\Program Files\rising\Rav\HOOKSYS.dll] <Rising><18, 1, 0, 9>
[C:\Program Files\rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
[C:\Program Files\rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\rising\Rav\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\rising\Rav\HookWeb.dll] <rising><18, 0, 0, 1>
[C:\Program Files\rising\Rav\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
[C:\Program Files\rising\Rav\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\rising\Rav\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[C:\Program Files\rising\Rav\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\rising\Rav\SpamEng.dll] <N/A><18, 0, 0, 4>
[C:\Program Files\rising\Rav\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
[C:\Program Files\rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\Program Files\rising\Rav\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\rising\Rav\ExtMail.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
[PID: 1168][c:\program files\rising\rfw\rfwsrv.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 25>
[c:\program files\rising\rfw\RfwRule.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 10>
[c:\program files\rising\rfw\rfwlog.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
[c:\program files\rising\rfw\Rfwdrv.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 19>
[c:\program files\rising\rfw\MonDrv.dll] <rs><1, 0, 0, 4>
[c:\program files\rising\rfw\ProcLib.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[c:\program files\rising\rfw\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[PID: 1328][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 1412][C:\Program Files\rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\Program Files\rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1708][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[C:\DOCUME~1\Bolton.Z\LOCALS~1\Temp\RarSFX4\DTSERV~1.DLL] <><1, 2, 0, 0>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[I:\UC\UCIdleHook.dll] <北京新浪信息技术有限公司><1, 0, 1, 0>
[C:\DOCUME~1\Bolton.Z\LOCALS~1\Temp\RarSFX4\ext\dtdl.dll] <N/A><N/A>
[C:\DOCUME~1\Bolton.Z\LOCALS~1\Temp\RarSFX4\ext\dtsm.dll] <N/A><N/A>
[C:\WINDOWS\system32\microapmddt.dll] <MacroMedia><1, 1, 0, 0>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] <Adobe Systems Incorporated><7.0.5.2005092300>
[I:\FLASHG~1\jccatch.dll] <Amaze Soft><1, 1, 4, 0>
[C:\Program Files\TENCENT\AddrPlus\IEHelp.dll] <Tencent><2, 1, 0, 10>
[C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL] <><1, 2, 0, 2>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
death9999 - 2005-12-28 10:12:00
[PID: 1800][c:\program files\rising\rfw\RfwMain.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 40>
[c:\program files\rising\rfw\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[c:\program files\rising\rfw\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[c:\program files\rising\rfw\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[I:\UC\UCIdleHook.dll] <北京新浪信息技术有限公司><1, 0, 1, 0>
[PID: 1944][C:\Program Files\Analog Devices\SoundMAX\SMTray.exe] <Analog Devices, Inc.><3, 2, 17, 0>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[PID: 2000][C:\Program Files\rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\Program Files\rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[PID: 2024][C:\Program Files\rising\Rav\Ravmon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 99>
[C:\Program Files\rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\Program Files\rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\Program Files\rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[I:\UC\UCIdleHook.dll] <北京新浪信息技术有限公司><1, 0, 1, 0>
[PID: 2032][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3427>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[PID: 180][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[PID: 212][C:\Program Files\Super Rabbit\MagicSet\srcdnoti.exe] <Super Rabbit Soft><1.20>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[PID: 332][C:\WINDOWS\system32\conime.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[PID: 1184][C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe] <Autodesk><2.66.000>
[PID: 1828][C:\Program Files\CPUCooL\CooLSrv.exe] <N/A><N/A>
[PID: 252][C:\WINDOWS\system32\nvsvc32.exe] <NVIDIA Corporation><6.14.10.7184>
[C:\WINDOWS\system32\NVRSZHC.DLL] <NVIDIA Corporation><6.14.10.7184>
[PID: 304][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] <Analog Devices, Inc.><3, 2, 6, 0>
[PID: 392][C:\WINDOWS\system32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 2360][C:\WINDOWS\system32\wscntfy.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
death9999 - 2005-12-28 10:12:00
[PID: 3516][I:\QQ2005\QQ.exe] <TENCENT><14, 27, 0, 082>
[I:\QQ2005\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[I:\QQ2005\QQHelperDll.dll] <><1, 0, 0, 1>
[I:\QQ2005\BasicCtrlDll.dll] <Tencent><0, 3, 3, 6>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[I:\QQ2005\QQAPI.dll] <><1, 0, 0, 1>
[I:\QQ2005\TMDlls\TIMProxy.dll] <tencent><0, 3, 2, 4>
[I:\QQ2005\LoginCtrl.dll] <><1, 0, 0, 1>
[I:\QQ2005\QQRes.dll] <tencent><1, 0, 0, 1>
[I:\QQ2005\QQMainFrame.dll] <N/A><N/A>
[I:\QQ2005\CQQApplication.dll] <N/A><N/A>
[I:\QQ2005\NewSkin.dll] <><1, 0, 0, 1>
[I:\QQ2005\HostingMgr.dll] <><1, 0, 0, 1>
[I:\QQ2005\MailSummary.dll] <><1, 0, 0, 1>
[I:\QQ2005\QQSpace.dll] <><1, 0, 0, 1>
[I:\QQ2005\QQAllInOne.dll] <N/A><N/A>
[I:\QQ2005\CameraDll.dll] <><1, 0, 0, 1>
[I:\QQ2005\SCCore.dll] <N/A><N/A>
[C:\WINDOWS\system32\msdmo.dll] <N/A><N/A>
[I:\QQ2005\UserDefinedHead.dll] <><1, 0, 0, 1>
[I:\QQ2005\QQPlugin.dll] <N/A><N/A>
[I:\QQ2005\QQCustomFace.dll] <N/A><N/A>
[I:\QQ2005\QQPet.dll] <><1, 0, 0, 1>
[I:\QQ2005\QQSysMsgMng.dll] <N/A><N/A>
[I:\QQ2005\QQConfigPlugin.dll] <><1, 0, 0, 1>
[I:\UC\UCIdleHook.dll] <北京新浪信息技术有限公司><1, 0, 1, 0>
[I:\QQ2005\QQAvatar.dll] <N/A><N/A>
[I:\QQ2005\FlashAvatarDll.dll] <><1, 4, 0, 1>
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[I:\QQ2005\QQMagicFace.dll] <><1, 0, 0, 1>
[I:\QQ2005\QQSceneMng.dll] <N/A><N/A>
[I:\QQ2005\QRingMng.dll] <N/A><N/A>
[I:\QQ2005\PhoneAPI.dll] <><1, 0, 0, 1>
[I:\QQ2005\DialerAllinOne.dll] <tencent><1, 4, 0, 0>
[I:\QQ2005\LongConnection.dll] <tencent><0, 3, 3, 8>
[I:\QQ2005\BQQApplication.dll] <N/A><N/A>
[I:\QQ2005\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[I:\QQ2005\CommercesMng.dll] <><1, 0, 0, 1>
[I:\QQ2005\QQUdpGetFileLib.dll] <tencent><0, 2, 2, 3>
[I:\QQ2005\QQAddr.dll] <深圳市腾讯计算机系统有限公司><4, 0, 200, 32>
[I:\QQ2005\npkcntc.dll] <INCA Internet Co., Ltd.><2005, 9, 1, 1>
[I:\QQ2005\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[I:\QQ2005\QQZip.dll] <tencent><0, 3, 2, 4>
[I:\QQ2005\QQPhoneHelper.dll] <腾讯科技(深圳)有限公司><1, 1, 0, 10>
[PID: 3600][I:\QQ2005\TIMPlatform.exe] <tencent><0, 3, 1, 8>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[I:\QQ2005\TMDlls\TIMProxy.dll] <tencent><0, 3, 2, 4>
[PID: 3628][I:\UC\uc.exe] <北京新浪信息技术有限公司><4.5.0.620>
[I:\UC\vcl60.bpl] <Borland Software Corporation><6.0.6.240>
[I:\UC\rtl60.bpl] <Borland Software Corporation><6.0.6.243>
[I:\UC\ucavatar.bpl] <><1.0.0.0>
[I:\UC\BORLNDMM.DLL] <Borland Software Corporation><6.0.10.157>
[I:\UC\CC3260MT.DLL] <Borland Corporation><0.0.0.0 (informal build)>
[I:\UC\vclx60.bpl] <Borland Software Corporation><6.0.6.163>
[I:\UC\vclie60.bpl] <Borland Software Corporation><6.0.6.163>
[I:\UC\ucchatroom.bpl] <><1.0.0.0>
[I:\UC\LANGUAGERES.DLL] <北京新浪信息技术有限公司><1.0.0.0>
[I:\UC\ucui.bpl] <><1.0.0.0>
[I:\UC\UCDControl.bpl] <><1.0.0.0>
[I:\UC\bcbie60.bpl] <N/A><N/A>
[I:\UC\uchm.bpl] <><1.0.0.0>
[I:\UC\ucres.dll] <北京新浪信息技术有限公司><1.0.0.0>
[I:\UC\uczip.dll] <Longmaster><3.8.0.1>
[I:\UC\ucmessager.dll] <N/A><N/A>
[I:\UC\STLPMT45.DLL] <N/A><N/A>
[I:\UC\uchall.dll] <><3.0.0.0>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[I:\UC\UCIdleHook.dll] <北京新浪信息技术有限公司><1, 0, 1, 0>
[I:\UC\UCHttpDl.dll] <北京新浪信息技术有限公司><1, 1, 9, 0>
[I:\UC\HelpEx.dll] <北京新浪信息技术有限公司><1.0.0.0>
[I:\UC\UCBugCatch.dll] <北京新浪信息技术有限公司><1, 2, 8, 0>
[I:\UC\UCSocket.DLL] <北京新浪信息技术有限公司><1, 1, 21, 0>
[C:\Program Files\rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[I:\UC\ActiveX\BROWSE~1.DLL] <北京新浪信息技术有限公司><2.0.1>
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[I:\UC\UCAudioChat.dll] <Bejing Sina Information Technology Co.,Ltd><2004, 8, 30, 2>
[I:\UC\UCVideo.DLL] <Beijing Sina Information Technology Co.,Ltd><4, 0, 1, 1>
[I:\UC\UcMediaPlayer.DLL] <><1, 0, 0, 1>
[C:\WINDOWS\system32\WINABCX.IME] <PKUETI><5.22.216>
[I:\UC\UCACodec.dll] <Bejing Sina Information Technology Co.,Ltd ><1.0.2>
[I:\UC\UCVCodec.dll] <Beijing Sina Information Technology Co.,Ltd><2, 0, 1, 0>
[PID: 3856][F:\BitComet\BitComet.exe] <www.BitComet.com><0.59.>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[C:\Program Files\rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[I:\UC\UCIdleHook.dll] <北京新浪信息技术有限公司><1, 0, 1, 0>
[PID: 872][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 1552][F:\金山词霸 2005\xdict.exe] <Kingsoft Co, Ltd.><8, 5, 0, 0>
[F:\金山词霸 2005\DicMngr.dll] <Kingsoft><1, 0, 0, 0>
[F:\金山词霸 2005\doshow.dll] <N/A><N/A>
[F:\金山词霸 2005\ITextOut.dll] <Kingsoft><1, 1, 0, 0>
[F:\金山词霸 2005\KPic10.dll] <N/A><N/A>
[F:\金山词霸 2005\ijl11.dll] <Intel Corporation><1.1.2>
[F:\金山词霸 2005\NormGrab.DLL] <Kingsoft Co, Ltd.><6, 0, 0, 0>
[F:\金山词霸 2005\toTTSEngine50.dll] <Kingsoft Corporation><1, 0, 0, 1>
[F:\金山词霸 2005\xfile.dll] <N/A><N/A>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[F:\金山词霸 2005\DBCore10.dll] <Kingsoft Corp.><1, 0, 0, 0>
[F:\金山词霸 2005\XdictGrb.dll] <Kingsoft Co, Ltd.><8, 5, 0, 0>
[I:\UC\UCIdleHook.dll] <北京新浪信息技术有限公司><1, 0, 1, 0>
[PID: 3072][F:\金山快译\KTEngine.exe] <Kingsoft><1, 0, 0, 0>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[F:\金山快译\GTS\EnglishSChinese\EngSCh.dll] <N/A><N/A>
death9999 - 2005-12-28 10:13:00
[PID: 692][I:\TT\TTraveler.exe] <腾讯公司><2, 2, 0, 224>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[F:\金山快译\IEBand.dll] <金山软件股份有限公司><4, 0, 0, 0>
[C:\Program Files\Common Files\Kingsoft\Extract\KSVoice.dll] <N/A><N/A>
[C:\Program Files\Common Files\Kingsoft\Extract\KSEngine.dll] <金山软件有限公司><2, 0, 1, 0>
[I:\UC\UCddt\DDTONG~1.DLL] <北京新浪信息技术有限公司><1, 2, 1, 5>
[I:\UC\UCddt\ddtsh.ocx] <北京新浪信息技术有限公司><1, 1, 1, 1>
[I:\UC\UCddt\ddtrss.ocx] <><1, 1, 0, 1>
[I:\UC\UCddt\ddtstock.ocx] <北京新浪信息技术有限公司><1, 1, 0, 5>
[I:\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll] <腾讯公司><1, 1, 0, 5>
[I:\TT\Plugins\TWeather\TWeather.dll] <><1, 0, 0, 1>
[I:\UC\UCIdleHook.dll] <北京新浪信息技术有限公司><1, 0, 1, 0>
[I:\TT\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[C:\Program Files\rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[PID: 2400][I:\PsCS9.0\精灵\Photpshop双语精灵.exe] <EraSoft><2.09.0005>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[I:\UC\UCIdleHook.dll] <北京新浪信息技术有限公司><1, 0, 1, 0>
[I:\PsCS9.0\精灵\dmshell.dll] <N/A><N/A>
[I:\PsCS9.0\精灵\200~1.1\dmplayer.dll] <N/A><N/A>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 3164][I:\pscs2\Photoshop.exe] <Adobe Systems, Incorporated><9.0 (9.0x196)>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[I:\pscs2\Photoshop.dll] <Adobe Systems, Incorporated><9.0 (9.0x196)>
[I:\pscs2\PSViews.dll] <Adobe Systems, Incorporated><9.0 (9.0x196)>
[I:\pscs2\PSArt.dll] <Adobe Systems, Incorporated><9.0 (9.0x196)>
[I:\pscs2\epic_pers.dll] <Adobe Systems Incorporated><1.0.1.14>
[I:\pscs2\asneu.dll] <Adobe Systems Inc.><1, 6, 0, 8>
[I:\pscs2\Plug-Ins\Extensions\FastCore.8BX] <Adobe Systems, Incorporated><9.0 (9.0x196)>
[I:\pscs2\PLUGIN.dll] <Adobe Systems, Incorporated><9.0 (9.0x196)>
[I:\pscs2\Plug-Ins\Extensions\MMXCore.8BX] <Adobe Systems, Incorporated><9.0 (9.0x196)>
[I:\pscs2\Plug-Ins\Extensions\MultiProcessor Support.8BX] <Adobe Systems, Incorporated><9.0 (9.0x196)>
[I:\pscs2\Required\ADMPlugin.apl] <Adobe Systems Incorporated><3.10x21>
[I:\pscs2\Required\PNGIcons.apl] <Adobe Systems Incorporated><1.22x1>
[I:\pscs2\Required\ASDataStream.apl] <Adobe Systems Incorporated><1.03x2>
[I:\pscs2\Plug-Ins\Parser\PDFPlugin.8BI] <Adobe Systems, Incorporated><8.0 (8.0x115)>
[I:\pscs2\BIB.dll] <Adobe Systems Incorporated><1.1.17>
[I:\pscs2\JP2KLib.dll] <Adobe system Incorporated><1.0.43211>
[C:\Program Files\Common Files\Adobe\Plug-Ins\CS2\File Formats\Camera Raw.8BI] <Adobe Systems Incorporated><3.0>
[I:\pscs2\BIBUtils.dll] <Adobe Systems Incorporated><1.00.0>
[I:\pscs2\ACE.dll] <Adobe Systems Incorporated><2.08.06>
[I:\pscs2\AGM.dll] <Adobe Systems Incorporated><4.15.20>
[I:\pscs2\CoolType.dll] <Adobe Systems Incorporated><5.02.18>
[I:\pscs2\AXE8SharedExpat.dll] <Adobe Systems Incorporated><3.2.406>
[I:\pscs2\VersionCue.dll] <Adobe Systems, Incorporated><4.0.0.2837j>
[I:\pscs2\pdfsettings.dll] <Adobe Systems Incorporated><1.00.0>
[I:\pscs2\versioncueui.dll] <Adobe Systems, Incorporated><4.0.0.2837j>
[I:\pscs2\AdobeXMP.dll] <Adobe Systems Incorporated><3.1.1-111>
[C:\WINDOWS\system32\ATMLIB.dll] <Adobe Systems><5.1 Build 226>
[I:\pscs2\Plug-Ins\Adobe Photoshop Only\Automate\ScriptingSupport.8li] <Adobe Systems Incorporated><9.0>
[I:\UC\UCIdleHook.dll] <北京新浪信息技术有限公司><1, 0, 1, 0>
[I:\pscs2\epic_regs.dll] <Adobe Systems Incorporated><1.0.1.14>
[I:\pscs2\AdobeLM.dll] <Adobe Systems, Inc.><1,7,5,7>
[I:\pscs2\LIBAGLUC28.DLL] <IBM Corporation and others><2, 8, 0, 0>
[I:\pscs2\agldt28l.dll] <IBM Corporation and others><2, 8, 0, 0>
[C:\DOCUME~1\Bolton.Z\LOCALS~1\Temp\Adobelm_Cleanup.0001.dir.0001\~df394b.tmp] <N/A><N/A>
[C:\DOCUME~1\Bolton.Z\LOCALS~1\Temp\Adobelm_Cleanup.0001.dir.0001\~de2fd8.tmp] <N/A><2.67.010>
[I:\pscs2\Tw10122.dat] <Adobe Systems, Incorporated><9.0 (9.0x196)>
[C:\DOCUME~1\Bolton.Z\LOCALS~1\Temp\Adobelm_Cleanup.0001.dir.0002\~df394b.tmp] <N/A><N/A>
[I:\pscs2\AdobeUpdater.dll] <Adobe Systems Incorporated><4, 0, 0, 44>
[C:\DOCUME~1\Bolton.Z\LOCALS~1\Temp\Adobelm_Cleanup.0001] <Macrovision Europe Ltd.><1, 0, 0, 1>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[PID: 4080][C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe] <Adobe Systems><2.67.010>
[C:\DOCUME~1\Bolton.Z\LOCALS~1\Temp\Adobelm_Cleanup.0001] <Macrovision Europe Ltd.><1, 0, 0, 1>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[PID: 1680][C:\WINDOWS\system32\NOTEPAD.EXE] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[I:\UC\UCIdleHook.dll] <北京新浪信息技术有限公司><1, 0, 1, 0>
[PID: 3576][F:\下载\sreng2\SREng.exe] <Smallfrogs Studio><2.0.12.350>
[C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll] <Tencent><2, 1, 0, 10>
[I:\UC\UCIdleHook.dll] <北京新浪信息技术有限公司><1, 0, 1, 0>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
death9999 - 2005-12-28 10:14:00
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS Error. [超级解霸3000]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
晕死日志怎么这么大啊!斑竹帮忙看看,辛苦了
death9999 - 2005-12-28 10:30:00
把这个日志也发上来,还有如何用System Repair Engineer修复
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 10:26:48, 日期 2005-12-28
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\rising\Rav\RavStub.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\rising\Rav\RavTask.exe
C:\Program Files\rising\Rav\Ravmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Super Rabbit\MagicSet\srcdnoti.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\CPUCooL\CooLSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\wscntfy.exe
I:\QQ2005\QQ.exe
I:\QQ2005\TIMPlatform.exe
I:\UC\uc.exe
F:\BitComet\BitComet.exe
C:\WINDOWS\system32\svchost.exe
F:\金山词霸 2005\xdict.exe
F:\金山快译\KTEngine.exe
I:\TT\TTraveler.exe
C:\Program Files\HijackTHis\HijackThis1991汉化版\HijackThis1991zww.exe
R3 - URLSearchHook: QQ Search Hook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\AddrPlus\IEHelp.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\Program Files\TENCENT\AddrPlus\IEHelp.dll
O2 - BHO: IDDTInitObj Class - {15DDE989-CD45-4561-BF99-D22C0D5C2B74} - I:\UC\UCddt\ddtinit.dll (file missing)
O2 - BHO: NaviHelperObj Class - {3E422F49-1566-40D3-B43D-077EF739AC32} - C:\WINDOWS\NaviHelper.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - I:\QQ2005\QQIEHelper.dll
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O2 - BHO: KillObj Class - {66C28884-4E5D-494B-80C9-CAA27528FD6D} - I:\UC\UCddt\ddtkillw.ocx
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - I:\FLASHG~1\jccatch.dll
O2 - BHO: MacroMediapd - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - C:\WINDOWS\system32\microapmddt.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - (no file)
O3 - IE工具栏增项: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - F:\金山快译\IEBand.dll
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - I:\FLASHG~1\fgiebar.dll
O3 - IE工具栏增项: 新浪点点通 - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - I:\UC\UCddt\DDTONG~1.DLL
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - 启动项HKLM\\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - 启动项HKLM\\Run: [NvCplDaemon] ; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [nwiz] ; nwiz.exe /install
O4 - 启动项HKLM\\Run: [NvMediaCenter] ; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - 启动项HKLM\\Run: [RfwMain] "C:\Program Files\rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [Super Rabbit SRRestore] C:\Program Files\Super Rabbit\MagicSet\srrest.exe /autosave
O4 - 启动项HKLM\\Run: [KernelFaultCheck] ; %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [SysExplr] ; F:\JB\SYSEXPLR.EXE
O4 - 启动项HKLM\\Run: [Knight V] ;
O4 - 启动项HKLM\\Run: [AddrPlus3] RUNDLL32.EXE C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll,Rundll32
O4 - 启动项HKLM\\Run: [NMGameX_AutoRun] ; C:\WINDOWS\system32\Rundll32.exe nmgamex.dll,LiveProcess /aa
O4 - 启动项HKLM\\Run: [Super Rabbit SafeEdit] C:\Program Files\Super Rabbit\MagicSet\SRFC.EXE /Load
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - 启动项HKLM\\Run: [ExFilter] Rundll32.exe "C:\PROGRA~1\CNNIC\Cdn\cdnspie.dll,ExecFilter solo"
O4 - 启动项HKLM\\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [DAEMON Tools-2052] ; ; "I:\Daemon\daemon.exe" -lang 2052
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Super Rabbit CDNotify] C:\Program Files\Super Rabbit\MagicSet\srcdnoti.exe /LOAD
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [msnmsgr] ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: CPUCooL.lnk = C:\Program Files\CPUCooL\CPUCooL.exe
O4 - Startup: 腾讯QQ.lnk = I:\QQ2005\QQ.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = I:\Office\Office10\OSA.EXE
O4 - Global Startup: LCDPlayer.lnk = ?
O4 - Global Startup: TeamTalk语音社区.Lnk = I:\TeamTalk\TeamTalk.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - IE右键菜单中的新增项目: >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL/mms.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - I:\QQ2005\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 使用彩信超级自写发送到手机 - http://mms.sina.com.cn/mmsnews.html
O8 - IE右键菜单中的新增项目: 使用新浪下载助手下载 - I:\UC\UCddt\sinadl.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - I:\FLASHG~1\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - I:\FLASHG~1\jc_all.htm
O8 - IE右键菜单中的新增项目: 发送图片到手机(&M) - http://sms.sina.com.cn/diy/send.html?from=467
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Excel(&x) - res://I:\Office\Office10\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 导出当前页到超星阅览器(&A) - F:\SSREADER36\ss_all.htm
O8 - IE右键菜单中的新增项目: 导出选中部分到超星阅览器(&S) - F:\SSREADER36\ss_select.htm
O8 - IE右键菜单中的新增项目: 收藏此页到新浪ViVi - http://vivi.sina.com.cn/collect/click.php?agent=ddt
O8 - IE右键菜单中的新增项目: 新浪搜索 - http://cha.sina.com.cn/ddt.html
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - I:\QQ2005\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - I:\QQ2005\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - I:\QQ2005\SendMMS.htm
O8 - IE右键菜单中的新增项目: 解霸实时播放 - F:\JB\MPURLGET.HTM
O9 - 浏览器额外的按钮: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - F:\浩方对战平台\GameClient.exe
O9 - 浏览器额外的“工具”菜单项: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - F:\浩方对战平台\GameClient.exe
death9999 - 2005-12-28 10:31:00
O9 - 浏览器额外的按钮: 新浪UC - {2253922F-1B26-4C74-8B57-E3AEE748DBB8} - I:\UC\UC.exe
O9 - 浏览器额外的按钮: 解霸 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - F:\JB\MPLAYER.EXE
O9 - 浏览器额外的“工具”菜单项: 超级解霸 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - F:\JB\MPLAYER.EXE
O9 - 浏览器额外的按钮: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O9 - 浏览器额外的“工具”菜单项: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - I:\QQ2005\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - I:\QQ2005\QQ.EXE
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - I:\FLASHG~1\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - I:\FLASHG~1\flashget.exe
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - I:\QQ2005\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - I:\QQ2005\QQIEHelper.dll
O9 - 浏览器额外的按钮: 新浪点点通 - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - I:\UC\UCddt\DDTONG~1.DLL
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的按钮: (no name) - {974AD624-EA50-4831-A6C0-3040F6665396} - I:\UC\UCddt\rssband.dll (HKCU)
O9 - 浏览器额外的“工具”菜单项: 新浪点点通阅读器 - {974AD624-EA50-4831-A6C0-3040F6665396} - I:\UC\UCddt\rssband.dll (HKCU)
O9 - 浏览器额外的按钮: 新浪点点通阅读器 - {F0646DC8-58CD-4C64-8F6B-525043914685} - I:\UC\UCddt\rssband.dll (HKCU)
O11 - Options group: [TBH] QQ地址栏搜索插件
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {48038521-20FB-11D8-BC64-00B0D07A8A19} (PortalCom Control 2.0) - http://221.208.250.138/PortalAX02.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120809633140
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {9675ABBF-8D0B-4956-868C-934B5A7928D4} (Npv Control) - https://nprotect.lineage2.com.cn/nprotect/nprotect2004/ncsoft/npv.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - https://nprotect.lineage2.com.cn/nprotect/keycrypt/npkcx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{859F0012-6F68-4F89-AEBA-4C3A2216765E}: NameServer = 202.97.224.69 202.97.227.138
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - NT 服务: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - NT 服务: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - NT 服务: CPUCooLServer Service (CPUCooLServer) - Unknown owner - C:\Program Files\CPUCooL\CooLSrv.exe
O23 - NT 服务: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - NT 服务: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - F:\3D\mentalray\satellite\raysat_3dsmax8server.exe
O23 - NT 服务: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcsvc.exe
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\Ravmond.exe
O23 - NT 服务: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - NT 服务: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
飞跃迷离 - 2005-12-28 11:18:00
关于“MMSAssist”楼主可以先尝试从开始-->设置-->控制面板-->添加删除程序, 卸载
重新启动到安全模式(进入安全模式的方法:重新启动电脑, 开机自动检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式(Safe Mode)进入Windows。)
请关闭所有IE界面,重新使用HijackThis扫描一次,选中下面建议修复的项目,让HijackThis修复,修复前请允许HijackThis保留备份。(如果楼主知道是安全的可以不必勾选)
O2 - BHO: NaviHelperObj Class - {3E422F49-1566-40D3-B43D-077EF739AC32} - C:\WINDOWS\NaviHelper.dll
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O2 - BHO: MacroMediapd - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - C:\WINDOWS\system32\microapmddt.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - (no file)
O4 - 启动项HKLM\\Run: [Knight V] ;
O8 - IE右键菜单中的新增项目: >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL/mms.htm
然后打开我的电脑→再点工具→打开文件夹选项→查看→把隐藏受保护的系统文件(推荐)和隐藏已知文件类型的扩展名的勾去掉→再显示所有文件→找到以下文件并删除:(如果有的话)
C:\WINDOWS\NaviHelper.dll
C:\WINDOWS\system32\microapmddt.dll
删除文件夹C:\PROGRA~1\MMSASS~1
然后用System Repair Engineer修复文件关联,如何用System Repair Engineer修复?
请参考:
【推荐】请朋友们今后使用“SREng”代替HiJackThis导出报告及SREng的操
http://forum.ikaka.com/topic.asp?board=67&artid=7584895
AzraelZ - 2005-12-28 15:19:00
十分感谢斑竹,但还是有,可能是我的3D Max带的,我在观察观察
1
© 2000 - 2026 Rising Corp. Ltd.