2120270 - 2007-4-18 18:46:00
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<EXPLORER><C:\Program Files\Common Files\System\wab32res.exe> []
<mdr05ru6u><C:\DOCUME~1\Owner\LOCALS~1\Temp\iexpl0re.exe> []
<q4whl><C:\DOCUME~1\Owner\LOCALS~1\Temp\crasos.exe> []
<ht96ch0vif9k><C:\DOCUME~1\Owner\LOCALS~1\Temp\1explore.exe> []
<89x><C:\DOCUME~1\Owner\LOCALS~1\Temp\Servere.exe> [N/A]
<y077241><C:\DOCUME~1\Owner\LOCALS~1\Temp\c0nime.exe> []
<z8rir2dlb><C:\DOCUME~1\Owner\LOCALS~1\Temp\winlog0n.exe> []
<eh0k631um9bwej><C:\DOCUME~1\Owner\LOCALS~1\Temp\Servera.exe> []
<h6dh9gyfmrq1x><C:\DOCUME~1\Owner\LOCALS~1\Temp\rundl132.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<IgfxTray><C:\WINDOWS\system32\igfxtray.exe> [Intel Corporation]
<HotKeysCmds><C:\WINDOWS\system32\hkcmd.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<SoundMAXPnP><C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe> [Analog Devices, Inc.]
<SoundMAX><"C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray> [Analog Devices, Inc.]
<qcsszjcz><c:\chenhu2\chenqxms.exe> [陈虎]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<RavStub><"C:\PROGRAM FILES\RISING\RAV\ravstub.exe" /RUNONCE> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
==================================
启动文件夹
N/A
==================================
服务
[Application Management / AppMgmt][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[TCP/IP Check / Hello Download][Stopped/Auto Start]
<C:\Program Files\Common Files\System\wab32res.exe><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
<"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
==================================
驱动程序
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[ExpScaner / ExpScaner][Running/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\ExpScan.sys><>
[HookCont / HookCont][Running/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\HookSys.sys><Rising>
[ialm / ialm][Running/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[IsDrv120 / IsDrv120][Running/System Start]
<\SystemRoot\System32\Drivers\IsDrv120.sys><N/A>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\MEMSCAN.sys><瑞星软件有限公司>
[MidiSyn / MidiSyn][Stopped/Manual Start]
<system32\drivers\MidiSyn.sys><Analog Devices Inc>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
<\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[senfilt / senfilt][Running/Manual Start]
<system32\drivers\senfilt.sys><Sensaura>
[smwdm / smwdm][Running/Manual Start]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/Manual Start]
<system32\drivers\ialmsbw.sys><Intel Corporation>
[Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start]
<system32\drivers\ialmkchw.sys><Intel Corporation>
==================================
浏览器加载项
[联想]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.lenovo.com, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash6.ocx, Macromedia, Inc.>
2120270 - 2007-4-18 18:47:00
===
正在运行的进程
[PID: 408][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 472][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 496][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 540][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 552][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 700][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 756][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 840][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 892][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 936][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1220][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\LgSy0.dll] [N/A, ]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\fyzo0.dll] [N/A, ]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\Msxo0.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\Gjzo0.dll] [N/A, ]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\Kavs0.dll] [N/A, ]
[C:\chenhu2\cqxms.dll] [N/A, ]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\Rav20.dll] [N/A, ]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1600][C:\WINDOWS\system32\igfxtray.exe] [Intel Corporation, 3.0.0.2331]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.2331]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3.0.0.2331]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.2331]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.2331]
[C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3.0.0.2331]
[PID: 1612][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3.0.0.2331]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.2331]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3.0.0.2331]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.2331]
[C:\WINDOWS\system32\igfxhk.dll] [Intel Corporation, 3.0.0.2331]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.2331]
[PID: 1636][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3208]
[PID: 1656][C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe] [Analog Devices, Inc., 5, 0, 1, 57]
[C:\Program Files\Analog Devices\SoundMAX\SMWDMIF.dll] [Analog Devices, Inc., 5, 0, 0, 460]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1700][C:\Program Files\Analog Devices\SoundMAX\Smax4.exe] [Analog Devices, Inc., 5, 0, 0, 18]
[PID: 1712][C:\chenhu2\chenqxms.exe] [陈虎, 1.000]
[C:\chenhu2\cqxms.dll] [N/A, ]
[PID: 1740][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1228][C:\program files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1996][C:\WINDOWS\system32\notepad.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2332][C:\Documents and Settings\Owner\桌面\sreng2\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\Rav20.dll] [N/A, ]
[C:\chenhu2\cqxms.dll] [N/A, ]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\Kavs0.dll] [N/A, ]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\Gjzo0.dll] [N/A, ]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\LgSy0.dll] [N/A, ]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\Msxo0.dll] [N/A, ]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\fyzo0.dll] [N/A, ]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 mmm.caifu18.net
127.0.0.1 www.18dmm.com
127.0.0.1 d.qbbd.com
127.0.0.1 www.5117music.com
127.0.0.1 www.union123.com
127.0.0.1 www.wu7x.cn
127.0.0.1 www.54699.com
127.0.0.1 60.169.0.66
127.0.0.1 60.169.1.29
127.0.0.1 www.97725.com
127.0.0.1 down.97725.com
127.0.0.1 ip.315hack.com
127.0.0.1 ip.54liumang.com
127.0.0.1 www.41ip.com
127.0.0.1 xulao.com
127.0.0.1 www.heixiou.com
127.0.0.1 www.9cyy.com
127.0.0.1 www.hunll.com
127.0.0.1 www.down.hunll.com
127.0.0.1 do.77276.com
127.0.0.1 www.baidulink.com
127.0.0.1 adnx.yygou.cn
127.0.0.1 222.73.220.45
127.0.0.1 www.f5game.com
127.0.0.1 www.guazhan.cn
127.0.0.1 wm,103715.com
127.0.0.1 www.my6688.cn
127.0.0.1 i.96981.com
127.0.0.1 d.77276.com
127.0.0.1 www1.cw988.cn
127.0.0.1 cool.47555.com
127.0.0.1 www.asdwc.com
127.0.0.1 55880.cn
127.0.0.1 61.152.169.234
127.0.0.1 cc.wzxqy.com
127.0.0.1 www.54699.com
127.0.0.1 t.gcuj.com
127.0.0.1 www.puma163.com
127.0.0.1 ceoww.com
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
2120270 - 2007-4-18 18:49:00
求助传说中的高手高手高高手帮忙 谢了
孤独更可靠 - 2007-4-18 18:50:00
<EXPLORER><C:\Program Files\Common Files\System\wab32res.exe> []
<mdr05ru6u><C:\DOCUME~1\Owner\LOCALS~1\Temp\iexpl0re.exe> []
<q4whl><C:\DOCUME~1\Owner\LOCALS~1\Temp\crasos.exe> []
<ht96ch0vif9k><C:\DOCUME~1\Owner\LOCALS~1\Temp\1explore.exe> []
<89x><C:\DOCUME~1\Owner\LOCALS~1\Temp\Servere.exe> [N/A]
<y077241><C:\DOCUME~1\Owner\LOCALS~1\Temp\c0nime.exe> []
<z8rir2dlb><C:\DOCUME~1\Owner\LOCALS~1\Temp\winlog0n.exe> []
<eh0k631um9bwej><C:\DOCUME~1\Owner\LOCALS~1\Temp\Servera.exe> []
<h6dh9gyfmrq1x><C:\DOCUME~1\Owner\LOCALS~1\Temp\rundl132.exe> []
[C:\DOCUME~1\Owner\LOCALS~1\Temp\LgSy0.dll] [N/A, ]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\fyzo0.dll] [N/A, ]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\Msxo0.dll] [N/A, ]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\Gjzo0.dll] [N/A, ]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\Kavs0.dll] [N/A, ]
[C:\chenhu2\cqxms.dll] [N/A, ]
[C:\DOCUME~1\Owner\LOCALS~1\Temp\Rav20.dll] [N/A, ]
哈,好眼熟啊
删除不掉的..
强制删除工具 PowerRMV
下载地址: http://free.ys168.com/?gudugengkekao
(其他工具-PowerRMV.com 大小101.4KB)
SRENG操作方法:
http://hi.baidu.com/%B9%C2%B6%C0%B8%FC%BF%C9%BF%BF/blog/item/9025a818a7592ab44aedbc05.html
2120270 - 2007-4-18 18:50:00
救命啊~机子慢的一塌糊涂~~
subomaoming - 2007-4-18 19:04:00
做完孤独说的那些后,用sreng修复hosts
© 2000 - 2026 Rising Corp. Ltd.