cq7z - 2007-6-5 15:01:00
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 12:04:52, on 2007-06-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
c:\ltdrv\srvany.exe
C:\MaxUser\MaxClient.exe
D:\Baidu Disk Search\BaiduDiskSearch.exe
C:\Program Files\DuDu\Speed\DuDuAcc.exe
C:\Program Files\DuDu\Speed\dudupros.exe
D:\Baidu Disk Search\BaiduCrawl.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
D:\hrims_statistic\mysql\bin\mysqld-nt.exe
D:\hrims_statistic\tomcat5.0\bin\tomcat5.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe
C:\Program Files\Samsung ML-1610 Series\CommonSM\CommonSM.exe
C:\Documents and Settings\Administrator\桌面\1.EXE
d:\My Documents\3.exe
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: DuDu.com - {00018593-C6BD-46F7-9349-DBA1AA674C90} - C:\Program Files\DuDu\Speed\dddiemon.dll
O2 - BHO: iebar - {F3A84AA2-A658-42A6-B701-6E43EF08C6C6} - C:\WINDOWS\system32\Ndvdsapi32.dll (file missing)
O4 - HKLM\..\Run: [BigDogPath] ; C:\WINDOWS\VM_STI.EXE USB PC Camera 301P
O4 - HKLM\..\Run: [CdnCtr] ;
O4 - HKLM\..\Run: [dla] ;
O4 - HKLM\..\Run: [FuncLimi] ; C:\MaxUser\FuncLimi.exe
O4 - HKLM\..\Run: [HotKeysCmds] ; C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IdnMail] ;
O4 - HKLM\..\Run: [IESAddr] ; "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [IgfxTray] ; C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] ; C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [part559] ; c:\ltdrv\part559.exe ltrun
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [RavMon] ; C:\Program Files\rising\Rav\RavMon.exe -system
O4 - HKLM\..\Run: [RavTimer] ;
O4 - HKLM\..\Run: [Samsung Common SM] ; "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [Show_B] ; C:\Ltdrv\Show_B.exe
O4 - HKLM\..\Run: [SoundMan] ; SOUNDMAN.EXE
O4 - HKLM\..\Run: [SoundMAX] ; "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SoundMAXPnP] ; C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [StormCodec_Helper] ; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [Student] ; C:\Program Files\Netcan E-class\ZDSoft.net网知多媒体教学网 V2.1\Student3DVD.exe RunServices
O4 - HKLM\..\Run: [SysExplr] ;
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Update] ;
O4 - HKLM\..\Run: [UpdateManager] ;
O4 - HKCU\..\Run: [BaiduDS] D:\Baidu Disk Search\BaiduDiskSearch.exe -NoOpen
O4 - HKCU\..\Run: [ctfmon.exe] ; C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: DuDu下载加速器.lnk = C:\Program Files\DuDu\Speed\DuDuAcc.exe
O8 - Extra context menu item: &使用DuDu下载 - res://C:\Program Files\DuDu\Speed\dddmext.dll/202
O8 - Extra context menu item: &使用DuDu下载全部链接 - res://C:\Program Files\DuDu\Speed\dddmext.dll/203
O8 - Extra context menu item: &使用DuDu下载选择链接 - res://C:\Program Files\DuDu\Speed\dddmext.dll/204
O8 - Extra context menu item: &使用DuDu捕获页面视频 - res://C:\Program Files\DuDu\Speed\dddmext.dll/205
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\qq\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\qq\SendMMS.htm
O8 - Extra context menu item: 百度Flash搜索 - res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/FLASHSEARCH.HTM
O8 - Extra context menu item: 百度mp3搜索 - res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度信息快递搜索 - res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUIE.HTM
O8 - Extra context menu item: 百度图片搜索 - res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度搜索 - res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度新闻搜索 - res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUNEWS.HTM
O9 - Extra button: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://tomatolei.com (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{19A02677-7C68-4FEF-96BF-061C0BBD6525}: NameServer = 218.201.4.3,61.128.128.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{64CCEEE1-04A1-400D-A316-C61C5C20B467}: NameServer = 10.10.2.1
O22 - SharedTaskScheduler: Browseui 预加载程序 - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: 组件类别缓存程序 - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ltdrv - Unknown owner - c:\ltdrv\srvany.exe
O23 - Service: MService - Unknown owner - C:\MaxUser\MaxClient.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: tjmysql - Unknown owner - D:\hrims_statistic\mysql\bin\mysqld-nt.exe
O23 - Service: tjtomcat - Apache Software Foundation - D:\hrims_statistic\tomcat5.0\bin\tomcat5.exe
--
End of file - 6479 bytes
说明:程序1.exe 3.exe是为扫描日志软件(改了名的)
cq7z - 2007-6-5 15:02:00
SRENG扫描日志
[CODE]
2007-06-05,12:05:06
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<BaiduDS><D:\Baidu Disk Search\BaiduDiskSearch.exe -NoOpen> [Baidu.com, Inc.]
<ctfmon.exe><; C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<BigDogPath><; C:\WINDOWS\VM_STI.EXE USB PC Camera 301P> [N/A]
<CdnCtr><; > [N/A]
<dla><; > [N/A]
<FuncLimi><; C:\MaxUser\FuncLimi.exe> []
<HotKeysCmds><; C:\WINDOWS\system32\hkcmd.exe> [(Verified)Microsoft Windows Publisher]
<IdnMail><; > [N/A]
<IESAddr><; "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun> [Samsung Electronics.]
<IgfxTray><; C:\WINDOWS\system32\igfxtray.exe> [(Verified)Microsoft Windows Publisher]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<MSPY2002><; C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC> [(Verified)Microsoft Windows Publisher]
<part559><; c:\ltdrv\part559.exe ltrun> [N/A]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
<RavMon><; C:\Program Files\rising\Rav\RavMon.exe -system> [Beijing Rising Technology Co., Ltd.]
<RavTimer><; > [N/A]
<Samsung Common SM><; "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun> [Samsung Electronics.]
<Show_B><; C:\Ltdrv\Show_B.exe> []
<SoundMan><; SOUNDMAN.EXE> [(Verified)Microsoft Windows Publisher]
<SoundMAX><; "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray> [Analog Devices, Inc.]
<SoundMAXPnP><; C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe> [Analog Devices, Inc.]
<StormCodec_Helper><; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> []
<Student><; C:\Program Files\Netcan E-class\ZDSoft.net网知多媒体教学网 V2.1\Student3DVD.exe RunServices> [N/A]
<SysExplr><; > [N/A]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<Update><; > [N/A]
<UpdateManager><; > [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><> [N/A]
<{4A8B2074-2074-A8B7-74A8-0748B074A8B7}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\2074A8B7.dll> []
cq7z - 2007-6-5 15:03:00
==================================
启动文件夹
[DuDu下载加速器]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\DuDu下载加速器.lnk --> C:\PROGRA~1\DuDu\Speed\DuDuAcc.exe [DuDu.com]><N>
==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[ltdrv / ltdrv][Running/Auto Start]
<c:\ltdrv\srvany.exe><N/A>
[MService / MService][Stopped/Auto Start]
<C:\MaxUser\MaxClient.exe><N/A>
[NBService / NBService][Stopped/Manual Start]
<C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe><Nero AG>
[Rising Proxy Service / RfwProxySrv][Stopped/Disabled]
<c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Disabled]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Disabled]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Disabled]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[tjmysql / tjmysql][Running/Auto Start]
<D:\hrims_statistic\mysql\bin\mysqld-nt --defaults-file=D:\hrims_statistic\mysql\my.ini tjmysql><N/A>
[tjtomcat / tjtomcat][Running/Auto Start]
<D:\hrims_statistic\tomcat5.0\bin\tomcat5.exe //RS//tjtomcat><Apache Software Foundation>
==================================
驱动程序
[Service for WDM 3D Audio Driver / ALCXSENS][Stopped/Manual Start]
<system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Stopped/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[Team MFP Comm Driver / DgiVecp][Running/Auto Start]
<System32\Drivers\DgiVecp.sys><DeviceGuys, Inc.>
[ExpScaner / ExpScaner][Running/Disabled]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[HOOKAPI / HOOKAPI][Stopped/Disabled]
<\??\C:\PROGRAM FILES\RISING\RAV\HOOKAPI.SYS><瑞星软件有限公司>
[HookCont / HookCont][Running/Disabled]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Disabled]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Disabled]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl][Running/Disabled]
<\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[ialm / ialm][Running/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[IdeBusDr / IdeBusDr][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\IdeBusDr.sys><Intel Corporation>
[Intel(R) Ultra ATA Controller / IdeChnDr][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\IdeChnDr.sys><Intel Corporation>
[MEMSCAN / MEMSCAN][Running/Disabled]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[MidiSyn / MidiSyn][Stopped/Manual Start]
<system32\drivers\MidiSyn.sys><Analog Devices Inc>
[mProcRs / mProcRs][Running/Disabled]
<\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[New0 / New0][Running/Auto Start]
<\??\C:\WINDOWS\system32\new.sys><N/A>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\D:\qq\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkycryp / npkycryp][Stopped/Manual Start]
<\??\D:\qq\npkycryp.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
<\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[RsFwDrv / RsFwDrv][Running/Disabled]
<\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Disabled]
<\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139/810X Family PCI Fast Ethernet NIC NT Driver / rtl8139][Running/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[senfilt / senfilt][Running/Manual Start]
<system32\drivers\senfilt.sys><Sensaura>
[smwdm / smwdm][Running/Manual Start]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[TDDI / TDDI][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\tddi.sys><SafeNet China Ltd.>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[USB PC Camera 301P / ZSMC301b][Stopped/Manual Start]
<System32\Drivers\usbVM31b.sys><VM>
==================================
浏览器加载项
[dddmont Class]
{00018593-C6BD-46F7-9349-DBA1AA674C90} <C:\Program Files\DuDu\Speed\dddiemon.dll, DuDu.com>
[iebar]
{F3A84AA2-A658-42A6-B701-6E43EF08C6C6} <C:\WINDOWS\system32\Ndvdsapi32.dll, N/A>
[番茄花园]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://tomatolei.com, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[dddmont Class]
{00018593-C6BD-46F7-9349-DBA1AA674C90} <C:\Program Files\DuDu\Speed\dddiemon.dll, DuDu.com>
[CellWeb5 Control]
{3F166327-8030-4881-8BD2-EA25350E574A} <D:\cj\bin\CellWeb5.ocx, Cell Software, Inc.>
[HHCtrl Object]
{41B23C28-488E-4E5C-ACE2-BB0BBABE99E8} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[IeCapture Class]
{67B6599D-1ACF-4EA9-9EAB-578DF0FE6F78} <C:\Program Files\Common Files\Baidu\Disk Search\dsie.dll, Baidu Corp.>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\MSADC\msadco.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
{CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[iebar]
{F3A84AA2-A658-42A6-B701-6E43EF08C6C6} <C:\WINDOWS\system32\Ndvdsapi32.dll, N/A>
[&使用DuDu下载]
<res://C:\Program Files\DuDu\Speed\dddmext.dll/202, N/A>
[&使用DuDu下载全部链接]
<res://C:\Program Files\DuDu\Speed\dddmext.dll/203, N/A>
[&使用DuDu下载选择链接]
<res://C:\Program Files\DuDu\Speed\dddmext.dll/204, N/A>
[&使用DuDu捕获页面视频]
<res://C:\Program Files\DuDu\Speed\dddmext.dll/205, N/A>
[上传到QQ网络硬盘]
<D:\qq\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<D:\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\qq\SendMMS.htm, N/A>
[百度Flash搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/FLASHSEARCH.HTM, N/A>
[百度mp3搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUMP3.HTM, N/A>
[百度信息快递搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUIE.HTM, N/A>
[百度图片搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUIMG.HTM, N/A>
[百度搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUSEARCH.HTM, N/A>
[百度新闻搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUNEWS.HTM, N/A>
cq7z - 2007-6-5 15:04:00
==================================
启动文件夹
[DuDu下载加速器]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\DuDu下载加速器.lnk --> C:\PROGRA~1\DuDu\Speed\DuDuAcc.exe [DuDu.com]><N>
==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[ltdrv / ltdrv][Running/Auto Start]
<c:\ltdrv\srvany.exe><N/A>
[MService / MService][Stopped/Auto Start]
<C:\MaxUser\MaxClient.exe><N/A>
[NBService / NBService][Stopped/Manual Start]
<C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe><Nero AG>
[Rising Proxy Service / RfwProxySrv][Stopped/Disabled]
<c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Disabled]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Disabled]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Disabled]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[tjmysql / tjmysql][Running/Auto Start]
<D:\hrims_statistic\mysql\bin\mysqld-nt --defaults-file=D:\hrims_statistic\mysql\my.ini tjmysql><N/A>
[tjtomcat / tjtomcat][Running/Auto Start]
<D:\hrims_statistic\tomcat5.0\bin\tomcat5.exe //RS//tjtomcat><Apache Software Foundation>
==================================
驱动程序
[Service for WDM 3D Audio Driver / ALCXSENS][Stopped/Manual Start]
<system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Stopped/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[Team MFP Comm Driver / DgiVecp][Running/Auto Start]
<System32\Drivers\DgiVecp.sys><DeviceGuys, Inc.>
[ExpScaner / ExpScaner][Running/Disabled]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[HOOKAPI / HOOKAPI][Stopped/Disabled]
<\??\C:\PROGRAM FILES\RISING\RAV\HOOKAPI.SYS><瑞星软件有限公司>
[HookCont / HookCont][Running/Disabled]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Disabled]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Disabled]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl][Running/Disabled]
<\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[ialm / ialm][Running/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[IdeBusDr / IdeBusDr][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\IdeBusDr.sys><Intel Corporation>
[Intel(R) Ultra ATA Controller / IdeChnDr][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\IdeChnDr.sys><Intel Corporation>
[MEMSCAN / MEMSCAN][Running/Disabled]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[MidiSyn / MidiSyn][Stopped/Manual Start]
<system32\drivers\MidiSyn.sys><Analog Devices Inc>
[mProcRs / mProcRs][Running/Disabled]
<\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[New0 / New0][Running/Auto Start]
<\??\C:\WINDOWS\system32\new.sys><N/A>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\D:\qq\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkycryp / npkycryp][Stopped/Manual Start]
<\??\D:\qq\npkycryp.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
<\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[RsFwDrv / RsFwDrv][Running/Disabled]
<\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Disabled]
<\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139/810X Family PCI Fast Ethernet NIC NT Driver / rtl8139][Running/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[senfilt / senfilt][Running/Manual Start]
<system32\drivers\senfilt.sys><Sensaura>
[smwdm / smwdm][Running/Manual Start]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[TDDI / TDDI][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\tddi.sys><SafeNet China Ltd.>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[USB PC Camera 301P / ZSMC301b][Stopped/Manual Start]
<System32\Drivers\usbVM31b.sys><VM>
==================================
浏览器加载项
[dddmont Class]
{00018593-C6BD-46F7-9349-DBA1AA674C90} <C:\Program Files\DuDu\Speed\dddiemon.dll, DuDu.com>
[iebar]
{F3A84AA2-A658-42A6-B701-6E43EF08C6C6} <C:\WINDOWS\system32\Ndvdsapi32.dll, N/A>
[番茄花园]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://tomatolei.com, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[dddmont Class]
{00018593-C6BD-46F7-9349-DBA1AA674C90} <C:\Program Files\DuDu\Speed\dddiemon.dll, DuDu.com>
[CellWeb5 Control]
{3F166327-8030-4881-8BD2-EA25350E574A} <D:\cj\bin\CellWeb5.ocx, Cell Software, Inc.>
[HHCtrl Object]
{41B23C28-488E-4E5C-ACE2-BB0BBABE99E8} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[IeCapture Class]
{67B6599D-1ACF-4EA9-9EAB-578DF0FE6F78} <C:\Program Files\Common Files\Baidu\Disk Search\dsie.dll, Baidu Corp.>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\MSADC\msadco.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
{CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[iebar]
{F3A84AA2-A658-42A6-B701-6E43EF08C6C6} <C:\WINDOWS\system32\Ndvdsapi32.dll, N/A>
[&使用DuDu下载]
<res://C:\Program Files\DuDu\Speed\dddmext.dll/202, N/A>
[&使用DuDu下载全部链接]
<res://C:\Program Files\DuDu\Speed\dddmext.dll/203, N/A>
[&使用DuDu下载选择链接]
<res://C:\Program Files\DuDu\Speed\dddmext.dll/204, N/A>
[&使用DuDu捕获页面视频]
<res://C:\Program Files\DuDu\Speed\dddmext.dll/205, N/A>
[上传到QQ网络硬盘]
<D:\qq\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<D:\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\qq\SendMMS.htm, N/A>
[百度Flash搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/FLASHSEARCH.HTM, N/A>
[百度mp3搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUMP3.HTM, N/A>
[百度信息快递搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUIE.HTM, N/A>
[百度图片搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUIMG.HTM, N/A>
[百度搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUSEARCH.HTM, N/A>
[百度新闻搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUNEWS.HTM, N/A>
© 2000 - 2026 Rising Corp. Ltd.