瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 【求助】"我无邪"大哥3
软风★≈ - 2006-5-23 22:06:00
正在运行的进程
[PID: 616][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 672][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 696][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
[PID: 748][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
[PID: 760][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
    [C:\WINDOWS\system32\relog_ap.dll]  <Acronis><1,0,0,6>
[PID: 936][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
[PID: 1008][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
[PID: 1108][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
[PID: 1152][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
[PID: 1280][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
[PID: 1512][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
[PID: 1660][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
    [C:\WINDOWS\c5wh.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\PROGRA~1\FLASHGET\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
[PID: 1796][C:\WINDOWS\system32\msime.exe]  <Microsoft Corporation><5.1.2600.2180>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
    [C:\WINDOWS\c5wh.dll]  <N/A><N/A>
[PID: 1844][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3018>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
    [C:\WINDOWS\c5wh.dll]  <N/A><N/A>
[PID: 1892][C:\Program Files\Acronis\TrueImageEnterprise\TrueImageMonitor.exe]  <Acronis><8,1,0,941>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
    [C:\WINDOWS\c5wh.dll]  <N/A><N/A>
[PID: 1956][C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe]  <Acronis><1,0,0,196>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
    [C:\WINDOWS\c5wh.dll]  <N/A><N/A>
[PID: 1968][C:\Herosoft\HeroV8\SysExplr.EXE]  <N/A><N/A>
    [C:\Herosoft\HeroV8\HttpReq.dll]  <N/A><N/A>
    [C:\Herosoft\HeroV8\CoolMenu.dll]  <N/A><N/A>
    [C:\Herosoft\HeroV8\httphlp.dll]  <N/A><N/A>
    [C:\Herosoft\HeroV8\AVCDROM.dll]  <N/A><N/A>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
    [C:\Herosoft\HeroV8\Sys936.DLL]  <N/A><N/A>
    [C:\WINDOWS\c5wh.dll]  <N/A><N/A>
[PID: 1976][C:\Program Files\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\WINDOWS\c5wh.dll]  <N/A><N/A>
[PID: 1984][C:\Program Files\Rising\Rfw\rfwmain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 51>
    [C:\Program Files\Rising\Rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
    [C:\Program Files\Rising\Rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\WINDOWS\c5wh.dll]  <N/A><N/A>
[PID: 1996][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
    [C:\WINDOWS\c5wh.dll]  <N/A><N/A>
[PID: 2028][C:\Program Files\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 19>
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\WINDOWS\c5wh.dll]  <N/A><N/A>
[PID: 284][C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe]  <Sony Corporation.><1, 0, 0, 1>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
    [C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\ResidenceRes.dll]  <N/A><N/A>
    [C:\WINDOWS\c5wh.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
[PID: 452][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
[PID: 1588][C:\Program Files\Rising\Rav\RsAgent.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\WINDOWS\c5wh.dll]  <N/A><N/A>
[PID: 1716][C:\WINDOWS\msagent\AgentSvr.exe]  <Microsoft Corporation><2.00.0.3422>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
    [C:\WINDOWS\c5wh.dll]  <N/A><N/A>
[PID: 836][C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe]  <Acronis><1,0,0,196>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
[PID: 1672][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
[PID: 1140][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
[PID: 2400][C:\Program Files\Rising\Rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
    [C:\Program Files\Rising\Rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
    [C:\Program Files\Rising\Rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [C:\Program Files\Rising\Rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [C:\Program Files\Rising\Rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [C:\Program Files\Rising\Rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
    [C:\Program Files\Rising\Rfw\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[PID: 2464][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
[PID: 4016][D:\我的文档\新建文件夹\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\WINDOWS\KB2153662.LOG]  <N/A><N/A>
    [C:\WINDOWS\c5wh.dll]  <N/A><N/A>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
1
查看完整版本: 【求助】"我无邪"大哥3