瑞星卡卡安全论坛
gail528 - 2007-5-30 18:13:00
开始是系统时间被修改,而且不能装杀毒软件,
重装系统后,autorun文件夹还是删不掉,而且CPU占用率很高
杀毒软件查到病毒(木马)不能删除 文件是autorun.pif,wmpns.dll
日志:
[CODE]
2007-05-30,17:47:12
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<bgswitch><C:\WINDOWS\system32\bgswitch.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
<VisualTaskTips><C:\Program Files\VisualTaskTips\VisualTaskTips.exe> [VisualTaskTips.com]
<Vistadrv><C:\Program Files\Vista\systool\Vistadrive\vsdrv.exe> []
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<IgfxTray><C:\WINDOWS\system32\igfxtray.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<HotKeysCmds><C:\WINDOWS\system32\hkcmd.exe> [(Verified)Microsoft Windows Publisher]
<ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"> [(Verified)Symantec Corporation]
<vptray><C:\PROGRA~1\SYMANT~1\VPTray.exe> [(Verified)Symantec Corporation]
<CnsM.dll><Rundll32.exe C:\PROGRA~1\3721\CnsM.dll,Rundll32> [3721]
<helper.dll><C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32> []
<RfwMain><"D:\rxf\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<PostBootReminder><%SystemRoot%\system32\SHELL32.dll> [Microsoft Corporation]
<CDBurn><%SystemRoot%\system32\SHELL32.dll> [Microsoft Corporation]
<WebCheck><%SystemRoot%\system32\webcheck.dll> [Microsoft Corporation]
<SysTray><C:\WINDOWS\system32\stobject.dll> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
<WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
<WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
<WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
<WinlogonNotify: NavLogon><C:\WINDOWS\system32\NavLogon.dll> [(Verified)Symantec Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
<WinlogonNotify: ScCertProp><wlnotify.dll> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
<WinlogonNotify: Schedule><wlnotify.dll> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
<WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
<WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
<WinlogonNotify: termsrv><wlnotify.dll> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
<WinlogonNotify: wlballoon><wlnotify.dll> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [Microsoft Corporation]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
<Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
<Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
<Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\WINDOWS\system32\logon.scr> [Axialis Software]
gail528 - 2007-5-30 18:14:00
启动文件夹
N/A
==================================
服务
[Symantec Event Manager / ccEvtMgr][Running/Auto Start]
<"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc][Stopped/Manual Start]
<"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr][Running/Auto Start]
<"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[Symantec AntiVirus Definition Watcher / DefWatch][Running/Auto Start]
<"C:\Program Files\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd][Stopped/Manual Start]
<"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><N/A>
[SavRoam / SavRoam][Stopped/Manual Start]
<"C:\Program Files\Symantec AntiVirus\SavRoam.exe"><symantec>
[Symantec Network Drivers Service / SNDSrvc][Stopped/Manual Start]
<"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Symantec SPBBCSvc / SPBBCSvc][Stopped/Manual Start]
<"C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"><Symantec Corporation>
[Print Spooler / Spooler][Running/Auto Start]
<C:\WINDOWS\system32\spoolsv.exe><Microsoft Corporation>
[Symantec AntiVirus / Symantec AntiVirus][Running/Auto Start]
<"C:\Program Files\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>
[Rising Proxy Service / RfwProxySrv][Stopped/Manual Start]
<d:\rxf\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
<d:\rxf\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
==================================
驱动程序
[Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
<system32\drivers\ALCXSENS.SYS><Sensaura>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[ialm / ialm][Running/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[NAVENG / NAVENG][Stopped/Manual Start]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070529.034\naveng.sys><Symantec Corporation>
[NAVEX15 / NAVEX15][Stopped/Manual Start]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070529.034\navex15.sys><Symantec Corporation>
[NetGroup Packet Filter Driver / NPF][Stopped/Manual Start]
<system32\drivers\npf.sys><Politecnico di Torino>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[SAVRT / SAVRT][Running/System Start]
<\??\C:\Program Files\Symantec AntiVirus\savrt.sys><Symantec Corporation>
[SAVRTPEL / SAVRTPEL][Running/System Start]
<\??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys><Symantec Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[SPBBCDrv / SPBBCDrv][Stopped/Manual Start]
<\??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys><Symantec Corporation>
[SymEvent / SymEvent][Running/Manual Start]
<\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI][Running/System Start]
<\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/Manual Start]
<system32\drivers\ialmsbw.sys><Intel Corporation>
[Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start]
<system32\drivers\ialmkchw.sys><Intel Corporation>
[ldpikc / ldpikc][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\ldpikc.sys><N/A>
[Symantec Eraser Control driver / eeCtrl][Running/System Start]
<\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys><Symantec Corporation>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\D:\yingyong\qq\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Basetdi / Basetdi][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
[RsFwDrv / RsFwDrv][Running/Auto Start]
<\??\D:\rxf\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[HookUrl / HookUrl][Stopped/Auto Start]
<\??\D:\rxf\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[mProcRs / mProcRs][Running/Auto Start]
<\??\d:\rxf\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
gail528 - 2007-5-30 18:18:00
浏览器加载项
[SrchHook Class]
{F08555B0-9CC3-11D2-AA8E-000000000000} <C:\WINDOWS\system32\IEBHO.dll, >
[番茄花园]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.tomatolei.com, N/A>
[番茄工具条]
{6451F285-9E41-4D8C-813D-794CA7BFEAB4} <C:\WINDOWS\system32\IETool.dll, N/A>
[番茄工具条]
{6451F285-9E41-4D8C-813D-794CA7BFEAB4} <C:\WINDOWS\system32\IETool.dll, N/A>
[AutoLive]
{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2} <C:\PROGRA~1\3721\autolive.dll, >
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\flash.ocx, Adobe Systems, Inc.>
[SrchHook Class]
{F08555B0-9CC3-11D2-AA8E-000000000000} <C:\WINDOWS\system32\IEBHO.dll, >
==================================
正在运行的进程
[PID: 664][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 712][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\winsrv.dll] [Microsoft Corporation, 5.1.2600.2751 (xpsp_sp2_gdr.050831-1520)]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[PID: 1472][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
[C:\WINDOWS\system32\BROWSEUI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\SHDOCVW.dll] [Microsoft Corporation, 6.00.2900.2987 (xpsp_sp2_gdr.060901-0121)]
[C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\WINDOWS\system32\themeui.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ntshrui.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055)]
[C:\WINDOWS\system32\NETSHELL.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\credui.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[C:\WINDOWS\system32\webcheck.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\stobject.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll] [Symantec Corporation, 10.0.0.359]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\WINDOWS\system32\cabview.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\3721\autolive.dll] [, 2, 5, 1, 1004]
[C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006]
[C:\WINDOWS\system32\MSGINA.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.2350]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.2350]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.2350]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.2350]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3.0.0.2350]
[D:\yingyong\WINRAR\rarext.dll] [N/A, ]
[C:\WINDOWS\system32\RASDLG.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\zipfldr.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\mydocs.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1856][C:\Program Files\VisualTaskTips\VisualTaskTips.exe] [VisualTaskTips.com, 2, 1, 0, 0]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[PID: 1872][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5.1.0.29]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[PID: 1884][C:\WINDOWS\system32\igfxtray.exe] [Intel Corporation, 3.0.0.2350]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.2350]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3.0.0.2350]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.2350]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.2350]
[C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3.0.0.2350]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[PID: 1924][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3.0.0.2350]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.2350]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3.0.0.2350]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.2350]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\igfxhk.dll] [Intel Corporation, 3.0.0.2350]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.2350]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[PID: 1968][C:\Program Files\Common Files\Symantec Shared\ccApp.exe] [Symantec Corporation, 103.5.1.9]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\Program Files\Common Files\Symantec Shared\ccL35.dll] [Symantec Corporation, 103.5.1.9]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 103.5.1.9]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCALERT.DLL] [Symantec Corporation, 103.5.1.9]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCEMLPXY.DLL] [Symantec Corporation, 103.5.1.9]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\WINDOWS\system32\SYMREDIR.DLL] [Symantec Corporation, 5.5.1.6]
[C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 103.5.1.9]
[C:\Program Files\Common Files\Symantec Shared\ccProSub.dll] [Symantec Corporation, 103.5.1.9]
[C:\Program Files\Symantec AntiVirus\SavEmail.dll] [Symantec Corporation, 10.0.0.359]
[C:\WINDOWS\system32\TcpIpDog0.dll] [N/A, ]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[PID: 1984][C:\PROGRA~1\SYMANT~1\VPTray.exe] [Symantec Corporation, 10.0.0.359]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
gail528 - 2007-5-30 18:19:00
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Symantec AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.5.0.44]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[C:\Program Files\Symantec AntiVirus\Cliscan.dll] [Symantec Corporation, 10.0.0.359]
[C:\PROGRA~1\SYMANT~1\NAVNTUTL.DLL] [Symantec Corporation, 10.0.0.359]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Symantec AntiVirus\Cliproxy.dll] [Symantec Corporation, 10.0.0.359]
[C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055)]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[PID: 1996][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[PID: 452][C:\Program Files\Symantec AntiVirus\DoScan.exe] [Symantec Corporation, 10.0.0.359]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[C:\Program Files\Symantec AntiVirus\Cliscan.dll] [Symantec Corporation, 10.0.0.359]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Symantec AntiVirus\NAVNTUTL.DLL] [Symantec Corporation, 10.0.0.359]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Symantec AntiVirus\I2ldvp3.dll] [Symantec Corporation, 10.0.0.359]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 103.5.1.9]
[C:\Program Files\Common Files\Symantec Shared\ccL35.dll] [Symantec Corporation, 103.5.1.9]
[C:\Program Files\Common Files\Symantec Shared\ccDec.dll] [Symantec Corporation, 103.5.1.9]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\decsdk.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll] [Symantec Corporation, 3.02.12.35]
[C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\ccScan.dll] [Symantec Corporation, 103.5.1.9]
[C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL] [Symantec Corporation, 1.4.0.11]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20050412.023\ccEraser.dll] [Symantec Corporation, 103.5.1.9]
[C:\Program Files\Symantec AntiVirus\DefUtDCD.dll] [Symantec Corporation, 3.1.13a.0]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20050412.023\ecmsvr32.dll] [Symantec Corporation, 1.4.1.12]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20050412.023\NAVEX32a.DLL] [Symantec Corporation, 2004.4.0.15]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20050412.023\NAVENG32.DLL] [Symantec Corporation, 2004.4.0.15]
[C:\Program Files\Symantec AntiVirus\NAVAP32.DLL] [Symantec Corporation, 9.5.0.44]
[C:\Program Files\Symantec AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.5.0.44]
[C:\Program Files\Common Files\Symantec Shared\SSC\scandlgs.dll] [Symantec Corporation, 10.0.0.359]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055)]
[C:\WINDOWS\system32\ntshrui.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\shdocvw.dll] [Microsoft Corporation, 6.00.2900.2987 (xpsp_sp2_gdr.060901-0121)]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[PID: 2700][D:\denglu\Dr.COM宽带认证客户端\ishare_user.exe] [N/A, ]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[C:\WINDOWS\system32\TcpIpDog0.dll] [N/A, ]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[PID: 3116][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[C:\PROGRA~1\3721\autolive.dll] [, 2, 5, 1, 1004]
[C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055)]
[C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\TcpIpDog0.dll] [N/A, ]
[C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006]
[C:\PROGRA~1\3721\notifier.dll] [, 2.5.0.1002]
[PID: 2044][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
gail528 - 2007-5-30 18:21:00
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[PID: 2228][D:\rxf\Rising\Rfw\rfwmain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 70]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[D:\rxf\Rising\Rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[D:\rxf\Rising\Rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\rxf\Rising\Rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[D:\rxf\Rising\Rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[D:\rxf\Rising\Rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[PID: 3560][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[PID: 888][D:\yingyong\qq\QQ\QQ.exe] [TENCENT, 0, 0, 0, 0]
[D:\yingyong\qq\QQ\QQBaseClassInDll.dll] [, 1, 0, 0, 1]
[D:\yingyong\qq\QQ\QQHelperDll.dll] [, 1, 0, 0, 1]
[D:\yingyong\qq\QQ\BasicCtrlDll.dll] [Tencent, 7, 0, 101, 80]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[D:\yingyong\qq\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[D:\yingyong\qq\QQ\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0]
[C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[D:\yingyong\qq\QQ\PYKer.dll] [飘云 http://www.pyqq.cn, 飘云]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[D:\yingyong\qq\QQ\ipsearcher.dll] [, 1.0.0.3]
[D:\yingyong\qq\QQ\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[D:\yingyong\qq\QQ\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[D:\yingyong\qq\QQ\QQAPI.dll] [, 1, 0, 0, 1]
[D:\yingyong\qq\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[D:\yingyong\qq\QQ\LoginCtrl.dll] [N/A, ]
[D:\yingyong\qq\QQ\npkcntc.dll] [INCA Internet Co., Ltd., 2006, 6, 27, 1]
[D:\yingyong\qq\QQ\npkpdb.dll] [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[D:\yingyong\qq\QQ\LoginCtrlRes.dll] [, 1, 0, 0, 1]
[D:\yingyong\qq\QQ\QQRes.dll] [tencent, 1, 0, 0, 1]
[D:\yingyong\qq\QQ\QQMainFrame.dll] [N/A, ]
[C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055)]
[D:\yingyong\qq\QQ\CQQApplication.dll] [N/A, ]
[D:\yingyong\qq\QQ\NewSkin.dll] [, 1, 0, 0, 1]
[D:\yingyong\qq\QQ\HostingMgr.dll] [, 1, 0, 0, 1]
[D:\yingyong\qq\QQ\CameraDll.dll] [, 1, 0, 0, 1]
[D:\yingyong\qq\QQ\MailSummary.dll] [, 1, 0, 0, 1]
[D:\yingyong\qq\QQ\QQKnowledgeSearch.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\TcpIpDog0.dll] [N/A, ]
[D:\yingyong\qq\QQ\QQAllInOne.dll] [N/A, ]
[D:\yingyong\qq\QQ\GroupLive.dll] [N/A, ]
[D:\yingyong\qq\QQ\SCCore.dll] [TENCENT, 2, 0, 0, 1]
[D:\yingyong\qq\QQ\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\yingyong\qq\QQ\QQSpace.dll] [, 1, 0, 0, 1]
[D:\yingyong\qq\QQ\vbscript.dll] [Microsoft Corporation, 5.6.0.7426]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[D:\yingyong\qq\QQ\QQGroupMng.dll] [, 1, 0, 0, 1]
[D:\yingyong\qq\QQ\QQAvatar.dll] [N/A, ]
[D:\yingyong\qq\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[D:\yingyong\qq\QQ\UserDefinedHead.dll] [, 1, 0, 0, 1]
[D:\yingyong\qq\QQ\QQPlugin.dll] [N/A, ]
[D:\yingyong\qq\QQ\QQConfigPlugin.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\shdocvw.dll] [Microsoft Corporation, 6.00.2900.2987 (xpsp_sp2_gdr.060901-0121)]
[D:\yingyong\qq\QQ\QRingMng.dll] [N/A, ]
[D:\yingyong\qq\QQ\LongConnection.dll] [tencent, 5, 0, 200, 160]
[D:\yingyong\qq\QQ\PhoneAPI.dll] [, 1, 0, 0, 1]
[D:\yingyong\qq\QQ\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[D:\yingyong\qq\QQ\QQPet.dll] [, 1, 0, 0, 1]
[D:\yingyong\qq\QQ\QQSysMsgMng.dll] [N/A, ]
[D:\yingyong\qq\QQ\BQQApplication.dll] [N/A, ]
[D:\yingyong\qq\QQ\CommercesMng.dll] [, 1, 0, 0, 1]
[D:\yingyong\qq\QQ\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
[D:\yingyong\qq\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 280]
[D:\yingyong\qq\QQ\QQSceneMng.dll] [N/A, ]
[D:\yingyong\qq\QQ\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 1, 9, 92]
gail528 - 2007-5-30 18:21:00
[PID: 2336][D:\yingyong\qq\QQ\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[D:\yingyong\qq\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 2040][C:\Program Files\Windows NT\Accessories\WORDPAD.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[PID: 3712][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\SHDOCVW.dll] [Microsoft Corporation, 6.00.2900.2987 (xpsp_sp2_gdr.060901-0121)]
[C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[C:\PROGRA~1\3721\scrblock.dll] [3721, 2.5.0.1002]
[C:\PROGRA~1\3721\alrex.dll] [, 2.5.0.1002]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[C:\WINDOWS\system32\BROWSEUI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\PROGRA~1\3721\autolive.dll] [, 2, 5, 1, 1004]
[C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055)]
[C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006]
[C:\WINDOWS\system32\IETool.dll] [N/A, ]
[C:\WINDOWS\system32\IEBHO.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\TcpIpDog0.dll] [N/A, ]
[C:\WINDOWS\system32\mshtml.dll] [Microsoft Corporation, 6.00.2900.2963 (xpsp_sp2_gdr.060727-2358)]
[C:\WINDOWS\system32\Macromed\Flash\flash.ocx] [Adobe Systems, Inc., 9,0,16,0]
[C:\WINDOWS\system32\MSGINA.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\webcheck.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ntshrui.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\mydocs.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1504][D:\srg\sreng2\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINDOWS\system32\USER32.dll] [Microsoft Corporation, 5.1.2600.2622 (xpsp_sp2_gdr.050301-1519)]
[C:\WINDOWS\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\SHELL32.dll] [Microsoft Corporation, 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009)]
[C:\WINDOWS\system32\WININET.dll] [Microsoft Corporation, 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
[C:\PROGRA~1\3721\CnsM.dll] [3721, 2.5.1.1003]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\WINDOWS\system32\MSCTF.dll] [Microsoft Corporation, 5.1.2600.2575 (xpsp.041130-1728)]
[C:\Program Files\VisualTaskTips\VttHooks.dll] [N/A, ]
[C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\urlmon.dll] [Microsoft Corporation, 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055)]
[C:\WINDOWS\system32\TcpIpDog0.dll] [N/A, ]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
C:\WINDOWS\system32\TcpIpDog0.dll(, N/A)
MSAFD Tcpip [UDP/IP]
C:\WINDOWS\system32\TcpIpDog0.dll(, N/A)
MSAFD Tcpip [RAW/IP]
C:\WINDOWS\system32\TcpIpDog0.dll(, N/A)
RSVP UDP Service Provider
C:\WINDOWS\system32\TcpIpDogR0.dll(, N/A)
RSVP TCP Service Provider
C:\WINDOWS\system32\TcpIpDogR0.dll(, N/A)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
219.153.32.215 auto.search.msn.com
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
轩辕小聪 - 2007-5-30 18:25:00
请说清楚“autorun文件夹”的路径。到底是“autorun”还是“runauto..”?!
天月来了 - 2007-5-30 18:26:00
病毒位置
天月来了 - 2007-5-30 18:27:00
最好来个图
gail528 - 2007-5-30 22:25:00
不好意思抄错了
是runauto
在F盘的
是一个空文件夹
杀毒软件有时不能用
而且查得到但是删除不了
gail528 - 2007-5-30 22:27:00
我不知道怎么发图片上来
好象没看到上传附件的按纽
loveperday - 2007-5-30 22:30:00
你的开机启动项目怎么这么多。,。。。
gail528 - 2007-5-30 22:35:00
不清楚也
还没用优化软件优化
天月来了 - 2007-5-30 23:11:00
点这个页面右上角的“回复”,你就知道怎么做了。
你用WinRAR打开各个磁盘看看不明文件。尤其F盘的,如果有不明的抓图来。
gail528 - 2007-5-31 16:14:00
c盘有个autoexec.bat可能有问题
但是图片传不上来
E盘的System Volume Information文件夹打不开
现在传上来的是F盘的那个runauto..(病毒)文件夹的图片
几乎每个盘下都有desktop.ini,Thumbs.db
附件:
8533632007531160430.bmp
Jokkkka - 2007-5-31 16:29:00
该用户帖子内容已被屏蔽
gail528 - 2007-5-31 16:43:00
Jokkkka - 2007-5-31 16:51:00
该用户帖子内容已被屏蔽
1
© 2000 - 2026 Rising Corp. Ltd.