瑞星卡卡安全论坛
披着羊皮的小狼 - 2007-4-26 8:58:00
我的笔记本电脑不知着么了,只要是一启动或者注销,系统时间就会变成1980年11月11日,时间不变,知道原因的大虾来搭救我这只小狼吧!!!!!!!!!!!!!!!!!!!!!!

lihualau - 2007-4-26 9:00:00
用sreng扫描,贴出结果
披着羊皮的小狼 - 2007-4-26 9:36:00
那个文件太大了 我用QQ发给你好吗
披着羊皮的小狼 - 2007-4-26 9:37:00
2007-04-26,09:19:33
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<tqfh><C:\DOCUME~1\user\LOCALS~1\Temp\Servera.exe> []
<ravtask><C:\WINDOWS\system32\SVCH0ST.EXE> [N/A]
<QQDownload><"d:\Tencent\QQDownload\QQDownload.exe" autostart> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<wgsa><C:\DOCUME~1\user\LOCALS~1\Temp\wgso.exe> [N/A]
<SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<SkyTel><SkyTel.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<shualai><C:\WINDOWS\shualai.exe /i> []
<RTHDCPL><RTHDCPL.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<QShot><C:\Program Files\BenQ\QShot\QShot.exe> [BenQ Corp]
<QPresentation><C:\Program Files\BenQ\QPresentation\QPresentation.exe /s> [BenQ Corp.]
<QPower><C:\Program Files\BenQ\QPower\QPower.exe /s> [BENQ]
<QMusic2><"C:\Program Files\BenQ\QMusic2\QMAgent.exe"> []
<Q-MediaBar><"C:\Program Files\BenQ\Q-MediaBar\QBar.exe" /stop> [ ]
<Q-HotkeyMgr><"C:\Program Files\BenQ\Q-HotkeyMgr\HotkeySensor.exe"> [BenQ Corp.]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
<Persistence><C:\WINDOWS\system32\igfxpers.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<pccguide.exe><"C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"> [N/A]
<nwiztlbb><C:\WINDOWS\system32\nwiztlbb.exe> []
<nwizmhxy><C:\WINDOWS\system32\nwizmhxy.exe> []
<nwimezt><C:\WINDOWS\system32\nwimezt.exe> []
<NeroFilterCheck><C:\WINDOWS\system32\NeroCheck.exe> [Ahead Software Gmbh]
<MSPY2002><C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC> [(Verified)Microsoft Windows Publisher]
<msccrt><C:\WINDOWS\msccrt.exe> []
<mppds><C:\WINDOWS\mppds.exe> []
<mhsa><C:\DOCUME~1\user\LOCALS~1\Temp\mhso.exe> []
<kernelmh><C:\WINDOWS\Kernelmh.exe> []
<IviRCService><"C:\Program Files\BenQ\Common\Bin\iviRCService.exe"> []
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<IMEKRMIG6.1><C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE> [(Verified)Microsoft Windows Publisher]
<IMCServerAutoStart><"C:\Program Files\BenQ\IMCSvr\IMCSvr.exe"> [InterVideo Inc.]
<IgfxTray><C:\WINDOWS\system32\igfxtray.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<HotKeysCmds><C:\WINDOWS\system32\hkcmd.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<BenQSurround><C:\Program Files\BenQ\BenQ Surround\BenQSurround.exe> [BenQ Corp.]
<Alcmtr><ALCMTR.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<AGRSMMSG><AGRSMMSG.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<ACU><"C:\Program Files\Atheros\ACU.exe" -nogui> [Atheros Communications, Inc.]
<runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<KKDelay><C:\Program Files\Rising\AntiSpyware\RunOnce.exe> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<twin><C:\WINDOWS\system32\ctfnom.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe chkfat.exe> []
<Userinit><C:\WINDOWS\system32\Userinit.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
<WinlogonNotify: igfxcui><igfxdev.dll> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\WINDOWS\JOYBOOK.SCR> []
==================================
披着羊皮的小狼 - 2007-4-26 9:38:00
启动文件夹
[InterVideo Scheduler server]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\InterVideo Scheduler server.lnk --> C:\PROGRA~1\BenQ\QMEDIA~1\SchSvr.exe [InterVideo Inc.]><N>
[腾讯QQ]
<C:\Documents and Settings\user\「开始」菜单\程序\启动\腾讯QQ.lnk --> D:\Tencent\QQ\QQ.exe [TENCENT]><N>
==================================
服务
[Atheros 配置服务 / ACS][Running/Auto Start]
<C:\WINDOWS\system32\acs.exe><Atheros>
[Application Management / AppMgmt][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Volume Optimization / AtWork][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\eqghy.dll><Microsoft Corporation>
[CoolWare / CoolWare][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\struts.dll><>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[P4P Service / P4P Service][Running/Auto Start]
<C:\Program Files\Common Files\Sogou PXP\p2psvr.exe><Sohu.com Inc.>
[Trend Micro Central Control Component / PcCtlCom][Stopped/Auto Start]
<C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe><N/A>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
<"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Network IPSEC Connections / SoSCAR][Running/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLL2KXP.EXE C:\WINDOWS\SYSTEM32\WBEM\DZCGE.DLL,Export 1087><Microsoft Corporation>
[Trend Micro Real-time Service / Tmntsrv][Stopped/Auto Start]
<C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe><N/A>
[Trend Micro Personal Firewall / TmPfw][Stopped/Auto Start]
<C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe><N/A>
[Trend Micro Proxy Service / tmproxy][Stopped/Auto Start]
<C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe><N/A>
[Ulead Burning Helper / UleadBurningHelper][Running/Auto Start]
<C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe><Ulead Systems, Inc.>
[Windows ycnv RunThem / ycnv][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\txiq\dhsa.dll>< >
[Rising Proxy Service / RfwProxySrv][Stopped/Manual Start]
<c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
==================================
驱动程序
[AEGIS Protocol (IEEE 802.1x) v3.4.10.0 / AegisP][Running/Auto Start]
<system32\DRIVERS\AegisP.sys><Meetinghouse Data Communications>
[Agere Systems Soft Modem / AgereSoftModem][Stopped/Manual Start]
<system32\DRIVERS\AGRSM.sys><Agere Systems>
[Atheros Wireless Network Adapter Service / AR5211][Running/Manual Start]
<system32\DRIVERS\ar5211.sys><Atheros Communications, Inc.>
[BaseTDI / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[BenQ QEye / Cam5603D][Running/Manual Start]
<System32\Drivers\BisonCam.sys><N/A>
[ExpScaner / ExpScaner][Running/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\ExpScan.sys><>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HOOKAPI / HOOKAPI][Stopped/Manual Start]
<\??\C:\PROGRAM FILES\RISING\RAV\HookApi.Sys><瑞星软件有限公司>
[HookCont / HookCont][Running/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\HookSys.sys><Rising>
[ialm / ialm][Running/Manual Start]
<system32\DRIVERS\igxpmp32.sys><Intel Corporation>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
<system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
[IVI ASPI Shell / Iviaspi][Running/Manual Start]
<system32\drivers\iviaspi.sys><InterVideo, Inc.>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\MEMSCAN.sys><瑞星软件有限公司>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\D:\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Padus ASPI Shell / pfc][Running/Manual Start]
<system32\drivers\pfc.sys><Padus, Inc.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
<\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\RSPPSYS.sys><Rising>
[Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver / RTLE8023xp][Running/Manual Start]
<system32\DRIVERS\Rtenicxp.sys><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
<system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[tifm21 / tifm21][Running/Manual Start]
<system32\drivers\tifm21.sys><Texas Instruments>
[Tmfilter / Tmfilter][Running/Auto Start]
<system32\drivers\TmXPFlt.sys><Trend Micro Inc.>
[Tmpreflt / Tmpreflt][Running/Auto Start]
<system32\drivers\Tmpreflt.sys><Trend Micro Inc.>
[Trend Micro TDI Driver / tmtdi][Running/System Start]
<\SystemRoot\System32\Drivers\tmtdi.sys><Trend Micro Inc.>
[Common Firewall Driver / tm_cfw][Running/Auto Start]
<\SystemRoot\System32\Drivers\tm_cfw.sys><Trend Micro Inc.>
[Vsapint / Vsapint][Running/Auto Start]
<system32\drivers\VsapiNT.sys><Trend Micro Inc.>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[QBIOSIO.dll / QBIOSIO.dll][Running/Disabled]
<\??\C:\Program Files\BenQ\Shared\QBIOSIO.dll><N/A>
[RsFwDrv / RsFwDrv][Running/Auto Start]
<\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[HookUrl / HookUrl][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[mProcRs / mProcRs][Running/Auto Start]
<\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
==================================
披着羊皮的小狼 - 2007-4-26 9:40:00
浏览器加载项
[QQCycloneHelper Class]
{00000000-12C9-4305-82F9-43058F20E8D2} <d:\Tencent\QQDownload\QQIEHelper01.dll, 腾讯公司>
[PowerPlr Control]
{2354A44B-3CEB-4829-9940-545B03103538} <C:\WINDOWS\DOWNLO~1\PowerPlr.ocx, 创智数码科技股份有限公司>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[QQCycloneHelper Class]
{00000000-12C9-4305-82F9-43058F20E8D2} <d:\Tencent\QQDownload\QQIEHelper01.dll, 腾讯公司>
[PowerPlr Control]
{2354A44B-3CEB-4829-9940-545B03103538} <C:\WINDOWS\DOWNLO~1\PowerPlr.ocx, 创智数码科技股份有限公司>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Flash7.ocx, Macromedia, Inc.>
[myIEDog Sita]
{DE0DDC2E-E6C9-4514-A8A3-D8B335594332} <C:\WINDOWS\system32\iehooks.dll, N/A>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[&使用超级旋风下载]
<d:\Tencent\QQDownload\geturl.htm, N/A>
[&使用超级旋风下载全部链接]
<d:\Tencent\QQDownload\getAllurl.htm, N/A>
==================================
披着羊皮的小狼 - 2007-4-26 9:42:00
==================================
正在运行的进程
[PID: 672][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 736][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 764][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 808][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 820][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1024][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 1088][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1268][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\windows\system32\eqghy.dll] [Microsoft Corporation, 5.1.2600.0]
[c:\windows\system32\struts.dll] [, 1, 0, 0, 4]
[PID: 1396][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1524][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1960][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2016][C:\WINDOWS\system32\acs.exe] [Atheros, 4.2.0.384]
[C:\WINDOWS\system32\AegisE5.dll] [Meetinghouse Data Communications, 3, 2, 15, 0]
[C:\WINDOWS\system32\athcfg20U.dll] [Atheros, 4.2.0.384]
[C:\WINDOWS\system32\athcfg20ResU.dll] [Atheros Communications, Inc., 4.2.0.384]
[C:\WINDOWS\system32\odbcbcp.dll] [Microsoft Corporation, 2000.085.1117.00 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\athcfg11resloc.dll] [Atheros Communications, Inc., 4.2.0.384]
[PID: 1048][C:\PROGRAM FILES\RISING\RAV\RavStub.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
[C:\PROGRAM FILES\RISING\RAV\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1516][C:\Program Files\Common Files\Sogou PXP\p2psvr.exe] [Sohu.com Inc., 2, 0, 0, 32]
[C:\Program Files\Sogou PXP\vodsvr.dll] [Sohu.com Inc., 2, 4, 3, 0]
[C:\Program Files\Sogou PXP\pxpnet.dll] [Sohu.com Inc., 2, 0, 0, 18]
[C:\Program Files\Sogou PXP\p2pclient.dll] [Sohu.com Inc., 2, 9, 1, 7]
[PID: 1636][C:\WINDOWS\SYSTEM32\RUNDLL2KXP.EXE] [Microsoft Corporation, 5.00.2134.1]
[C:\WINDOWS\SYSTEM32\WBEM\DZCGE.DLL] [Microsoft Corporation, 5, 1, 2600, 2709]
[PID: 324][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1376][C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe] [Ulead Systems, Inc., 1, 0, 0, 4]
[PID: 2088][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\progra~1\txiq\dhsa.dll] [ , 4, 1, 0, 6]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[c:\progra~1\txiq\imxf.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 2288][C:\WINDOWS\Explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\WINDOWS\system32\winsock32.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\DOCUME~1\user\LOCALS~1\Temp\mhso0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3B.tmp.rom] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3C.tmp..rom] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\Kavs0.dll] [N/A, ]
[C:\WINDOWS\system32\mhxy100.dll] [N/A, ]
[C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.4670]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4670]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4670]
[C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3.0.0.4670]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4670]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[C:\WINDOWS\system32\nwiztlbb.dll] [N/A, ]
[PID: 3468][C:\WINDOWS\system32\chkfat.exe] [N/A, ]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 2788][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] [Synaptics, Inc., 8.3.8 16Jun06]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\WINDOWS\system32\SynCOM.dll] [Synaptics, Inc., 8.3.8 16Jun06]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\SynTPAPI.dll] [Synaptics, Inc., 8.3.8 16Jun06]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 2820][C:\WINDOWS\shualai.exe] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\shualai.dll] [N/A, ]
[PID: 1196][C:\WINDOWS\RTHDCPL.EXE] [Realtek Semiconductor Corp., 2.0.8.7]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 2880][C:\Program Files\BenQ\QShot\QShot.exe] [BenQ Corp, 1, 0, 0, 9]
[C:\Program Files\BenQ\QShot\Q32MLTran.dll] [BenQ Corp., 1.0.0.1]
[C:\Program Files\BenQ\QShot\dhpolywin.dll] [N/A, ]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 1856][C:\Program Files\BenQ\QPresentation\QPresentation.exe] [BenQ Corp., 1, 1, 0, 29]
[C:\Program Files\BenQ\QPresentation\QPDDInfo.dll] [BenQ Corp., 1, 0, 0, 1]
[C:\Program Files\BenQ\QPresentation\QBIOSFn.dll] [N/A, ]
[C:\Program Files\BenQ\QPresentation\QBIOSUt.dll] [N/A, ]
[C:\Program Files\BenQ\QPresentation\Q32MLTran.dll] [BenQ Corp., 1.0.0.1]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 3056][C:\Program Files\BenQ\QPower\QPower.exe] [BENQ, 1, 0, 1, 1]
[C:\Program Files\BenQ\QPower\QBIOSFn.dll] [N/A, ]
[C:\Program Files\BenQ\QPower\QBIOSUt.dll] [N/A, ]
[C:\Program Files\BenQ\QPower\Q32MLTran.dll] [BenQ Corp., 1.0.0.1]
[C:\Program Files\BenQ\QPower\Q32HotkeySensor.dll] [BenQ Corp., 1.2.0.2]
[C:\Program Files\BenQ\QPower\Q32FancyUI.dll] [BenQ Corp., 1.0.0.3]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
披着羊皮的小狼 - 2007-4-26 9:43:00
[PID: 3116][C:\Program Files\BenQ\QMusic2\QMAgent.exe] [, 1, 0, 0, 1]
[C:\Program Files\BenQ\QMusic2\CDRIP.DLL] [Albert L Faber, 115]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 2216][C:\Program Files\BenQ\Q-MediaBar\QBar.exe] [ , 2, 0, 13120, 2]
[C:\Program Files\BenQ\Q-MediaBar\QBSetting.DLL] [N/A, ]
[C:\Program Files\BenQ\Q-MediaBar\MLTran.DLL] [N/A, ]
[C:\Program Files\BenQ\Q-MediaBar\FlashPlayer.DLL] [, 1, 0, 0, 2]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\Flash7.ocx] [Macromedia, Inc., 7,0,19,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\Kavs0.dll] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\mhso0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 144][C:\Program Files\BenQ\Q-HotkeyMgr\HotkeySensor.exe] [BenQ Corp., 1.0.0.13]
[C:\Program Files\BenQ\Q-HotkeyMgr\QBSetting.DLL] [N/A, ]
[C:\Program Files\BenQ\Q-HotkeyMgr\Q32HotkeySensor.dll] [BenQ Corp., 1.2.0.2]
[C:\Program Files\BenQ\Q-HotkeyMgr\dhpolywin.dll] [N/A, ]
[C:\Program Files\BenQ\Q-HotkeyMgr\QBIOSFn.dll] [N/A, ]
[C:\Program Files\BenQ\Q-HotkeyMgr\QBIOSUt.dll] [N/A, ]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 3184][C:\WINDOWS\system32\igfxpers.exe] [Intel Corporation, 3.0.0.4670]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4670]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 3372][C:\WINDOWS\Kernelmh.exe] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 3120][C:\Program Files\BenQ\Common\Bin\iviRCService.exe] [, 1, 0, 0, 1]
[C:\Program Files\BenQ\Common\Bin\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 3364][C:\Program Files\BenQ\IMCSvr\IMCSvr.exe] [InterVideo Inc., 1.1.31.7]
[C:\Program Files\BenQ\IMCSvr\gdiplus.dll] [Microsoft Corporation, 5.1.3097.0 (xpclient.010817-1148)]
[C:\Program Files\BenQ\IMCSvr\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[C:\Program Files\BenQ\IMCSvr\log4cpp.dll] [Bastiaan Bakker, LifeLine Networks bv , 0.3.2rc2]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\BenQ\IMCSvr\IviAvSrc.dll] [InterVideo Inc., 3.1.21.2]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\msxml4.dll] [Microsoft Corporation, 4.20.9818.0]
[C:\Program Files\BenQ\IMCSvr\IviDvrCtrl.dll] [, 1, 0, 0, 1]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 3380][C:\WINDOWS\system32\igfxtray.exe] [Intel Corporation, 3.0.0.4670]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4670]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4670]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4670]
[C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3.0.0.4670]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 3388][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3.0.0.4670]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4670]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4670]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4670]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 1832][C:\Program Files\BenQ\BenQ Surround\BenQSurround.exe] [BenQ Corp., 1, 0, 0, 4]
[C:\Program Files\BenQ\BenQ Surround\Q32MLTran.dll] [BenQ Corp., 1.0.0.1]
[C:\Program Files\BenQ\BenQ Surround\QBIOSFn.dll] [N/A, ]
[C:\Program Files\BenQ\BenQ Surround\QBIOSUt.dll] [N/A, ]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 2964][C:\WINDOWS\AGRSMMSG.exe] [Agere Systems, 2.1.73 2.1.73 08/30/2006 16:40:02]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 1404][C:\Program Files\Atheros\ACU.exe] [Atheros Communications, Inc., 4.2.0.384]
[C:\WINDOWS\system32\wcapiU.dll] [Atheros, 4.2.0.384]
[C:\WINDOWS\system32\athcfg20U.dll] [Atheros, 4.2.0.384]
[C:\WINDOWS\system32\wgapi.dll] [Atheros, 4.2.0.384]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\WINDOWS\system32\wgapiloc.dll] [Atheros, 4.2.0.384]
[C:\Program Files\Atheros\ACUloc.dll] [Atheros Communications, Inc., 4.2.0.384]
[C:\Program Files\Atheros\oemresloc.dll] [Atheros Communications, Inc., 4.2.0.384]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 3856][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 3744][C:\Program Files\BenQ\QMedia Center\SchSvr.exe] [InterVideo Inc., 3.1.6.0]
[C:\Program Files\BenQ\QMedia Center\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 2156][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 3608][C:\Program Files\Rising\Rav\RsAgent.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[PID: 3992][C:\WINDOWS\msagent\AgentSvr.exe] [Microsoft Corporation, 2.00.0.3422]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\Kavs0.dll] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\mhso0.dll] [N/A, ]
[PID: 3260][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
披着羊皮的小狼 - 2007-4-26 9:43:00
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[d:\Tencent\QQDownload\QQIEHelper01.dll] [腾讯公司, 1, 1, 0, 5]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.0.2003051500]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\Kavs0.dll] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\mhso0.dll] [N/A, ]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\Flash7.ocx] [Macromedia, Inc., 7,0,19,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\WINDOWS\system32\xpsp3res.dll] [Microsoft Corporation, 5.1.2600.2838 (xpsp_sp2_gdr.060131-1513)]
[PID: 3760][C:\Program Files\Rising\Rfw\rfwmain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 70]
[C:\Program Files\Rising\Rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[C:\Program Files\Rising\Rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[C:\Program Files\Rising\Rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\Rising\Rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\Kavs0.dll] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\mhso0.dll] [N/A, ]
[C:\Program Files\Rising\Rfw\PSAPI.DLL] [Microsoft Corporation, 4.00]
[PID: 1608][C:\PROGRA~1\INTERN~1\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[d:\Tencent\QQDownload\QQIEHelper01.dll] [腾讯公司, 1, 1, 0, 5]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\Flash7.ocx] [Macromedia, Inc., 7,0,19,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\xpsp3res.dll] [Microsoft Corporation, 5.1.2600.2838 (xpsp_sp2_gdr.060131-1513)]
[PID: 3868][C:\PROGRA~1\INTERN~1\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[d:\Tencent\QQDownload\QQIEHelper01.dll] [腾讯公司, 1, 1, 0, 5]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 3660][C:\DOCUME~1\user\LOCALS~1\Temp\sreng2.zip 的临时目录 1\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[c:\progra~1\txiq\gkvd.dll] [, 1, 0, 0, 6]
[c:\progra~1\txiq\lpai.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\user\LOCALS~1\Temp\~Tm3D.tmp.rom] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\Kavs0.dll] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\mhso0.dll] [N/A, ]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
披着羊皮的小狼 - 2007-4-26 9:44:00
终于发好了 ,,这个东东太长了
星10000 - 2007-4-26 10:30:00
XP开机自动注销的解决方法
http://hi.baidu.com/503165656/blog/item/a5c8723d6c857bef3d6d9722.html
针对近期猖獗的修改系统日期病毒的免疫办法
针对近期猖獗的修改系统日期病毒的免疫办法
字体大小: 小 中 大 近期有大量病毒将系统时间修改,多见为调整系统时间为198x年左右,使得卡巴斯基等很多安全软件的授权失效,无法正常使用
现在提供一个简单的防止日期被修改的方法
1.点击开始-->运行 输入secpol.msc,点确定,如图1,
2.接着会出现“本地安全策略”的管理对话框,我们在左边的树形框内依次点开
安全设置-->本地策略-->用户权利指派,右边就会出现如图2所示的列表
3.双击右边的”更改系统时间“,出现图3,接着就是要按删除,直到把所有存在的用户名全部删除为止,这时按 ”确定“ 即可
好了,现在那些修改日期的流氓/病毒就再也不能简单地修改你的系统日期了!
不过这样一来你自己也不可以修改时间日期了
如果要修改,可以通过BIOS的时间设置进行修改
或者是再用刚才那个里面的”添加用户或组“,将你自己的用户名重新添加进去
水树雨下 - 2007-4-26 10:35:00
<tqfh><C:\DOCUME~1\user\LOCALS~1\Temp\Servera.exe> []
<ravtask><C:\WINDOWS\system32\SVCH0ST.EXE> [N/A]
<wgsa><C:\DOCUME~1\user\LOCALS~1\Temp\wgso.exe> [N/A]
shualai><C:\WINDOWS\shualai.exe /i> []
<nwiztlbb><C:\WINDOWS\system32\nwiztlbb.exe> []
<nwizmhxy><C:\WINDOWS\system32\nwizmhxy.exe> []
<nwimezt><C:\WINDOWS\system32\nwimezt.exe> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<mppds><C:\WINDOWS\mppds.exe> []
<mhsa><C:\DOCUME~1\user\LOCALS~1\Temp\mhso.exe> []
<kernelmh><C:\WINDOWS\Kernelmh.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
shell><Explorer.exe chkfat.exe> []
建议重做系统,升级杀软进行扫毒
七夕魔君 - 2007-4-26 10:47:00
你中的是卫金,用冰山
饭后点心 - 2007-4-26 11:09:00
又是马群,又是改时间.还是重做系统比较方便.最好把QQ也重装下
1
© 2000 - 2026 Rising Corp. Ltd.