瑞星卡卡安全论坛
tanglinling - 2007-6-13 15:59:00
Logfile of HijackThis v1.99.1
Scan saved at 15:37:05, on 2005-6-13
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Rising\Rav\RavStub.exe
c:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\system32\5A421ED6.exe
C:\WINDOWS\system32\dgd4bs.exe
C:\WINDOWS\SYSTEM32\RUNDLLFOROUR.EXE
C:\WINDOWS\system32\dgd4bs.exe
C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\3721\assistse.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\RpcS.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Rising\Rav\Rav.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\hijackthis\HijackThis.exe
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll (file missing)
O4 - HKLM\..\RunOnce: [ 3721AutoRepair] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\assist\repair.dll,Rundll32
O4 - HKLM\..\RunOnce: [Register C:\Program Files\3721\Autolive.dll] "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files\3721\Autolive.dll",DllRegisterServer
O4 - HKLM\..\RunOnce: [Register C:\Program Files\3721\assist\assist.dll] "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files\3721\assist\assist.dll",DllRegisterServer
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\cdnns.dll' missing
O11 - Options group: [!CNS] 网络实名
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan
Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2007/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{256A5113-6ED1-4B5F-B3E8-45DAC014BB03}: NameServer = 202.96.128.86,61.144.56.101
O17 - HKLM\System\CCS\Services\Tcpip\..\{9DD79538-E095-4AA3-8FFF-10B00963AD6B}: NameServer = 202.96.128.86 202.96.128.166
O17 - HKLM\System\CS1\Services\Tcpip\..\{256A5113-6ED1-4B5F-B3E8-45DAC014BB03}: NameServer = 202.96.128.86,61.144.56.101
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\Mshtml.dll
O18 - Protocol: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\Mshtml.dll
O18 - Protocol: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\Mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\Mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\Mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\Mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O20 - Winlogon Notify: rpcc - C:\WINDOWS\system32\rpcc.dll
O23 - Service: 6FFDB774 - Unknown owner - C:\WINDOWS\system32\7EACEDC5.EXE (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: FFF41376 - Unknown owner - C:\WINDOWS\system32\651D9A6.EXE (file missing)
O23 - Service: P4P Service - Sohu.com Inc. - C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Windows Accounts Driver (WindowsConnections) - Unknown owner - C:\WINDOWS\system32\xets006.exe (file missing)
O23 - Service: wljs1234.3322.org - Unknown owner - C:\WINDOWS\system32\wljs1234.3322.org.exe
标题:菜鸟求救!
各位大虾:
感谢您关注我的这份报告,小菜鸟急需您的帮助!
本扫描/诊断报告由 上网助手IE修复专家 生成
操作系统: Windows XP
IE版本号: 5.50.4134.0600
===============================================================
以下是我的扫描报告正文:
*** 扫描项列表 ***
下列条目被IE修复专家判断为危险:
下列条目被IE修复专家判断为有风险:
下列条目被IE修复专家判断为未知:
1.R00 - IE首页 - http://www.128126.cn/,,
内容:http://www.128126.cn/
安全等级:未知
2.O17 - 本机网络设置 NameServer - 202.96.128.86,61.144.56.101,,
内容:202.96.128.86,61.144.56.101
安全等级:未知
3.O17 - 本机网络设置 NameServer - 202.96.128.86 202.96.128.166,,
内容:202.96.128.86 202.96.128.166
安全等级:未知
4.O36 - Winlogon通知包管理器 - rpcc,,
相关文件:C:\WINDOWS\system32\rpcc.dll
安全等级:未知
下列条目被IE修复专家判断为安全:
5.R00 - IE默认搜索页 - http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch,,
内容:http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
安全等级:安全
6.R00 - IE自定义搜索引擎 - http://seek.3721.com/srchcust.htm,,
内容:http://seek.3721.com/srchcust.htm
安全等级:安全
7.R00 - IE备用搜索引擎 - http://seek.3721.com/srchasst.htm,,
内容:http://seek.3721.com/srchasst.htm
安全等级:安全
8.O11 - IE高级操作 - !CNS (网络实名),,
安全等级:安全
附件:
6606312007613161930.jpg
tanglinling - 2007-6-13 17:10:00
下载SREng2(最新版) 后按下“保存报告”按钮保存报告日志文件(SREng.LOG),日志文件内容复制-粘贴
tanglinling - 2007-6-13 17:10:00
[CODE]
2007-06-13,16:56:59
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\Userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rpcc]
<WinlogonNotify: rpcc><C:\WINDOWS\system32\rpcc.dll> []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<eMuleAutoStart><; C:\Program Files\eMule\eMule.exe -AutoStart> [N/A]
<swg><; C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe> [(Verified)Google Inc]
==================================
启动文件夹
N/A
==================================
服务
[32028FF4 / 32028FF4][Stopped/Auto Start]
<C:\WINDOWS\system32\E10837C7.EXE -32028FF4><Microsoft Corporation>
[6FFDB774 / 6FFDB774][Stopped/Auto Start]
<C:\WINDOWS\system32\7EACEDC5.EXE -p><N/A>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[Autodesk Licensing Service / Autodesk Licensing Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk>
[FFF41376 / FFF41376][Stopped/Auto Start]
<C:\WINDOWS\system32\651D9A6.EXE -g><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[ks8j3jsisd / ks8j3jsisd][Stopped/Auto Start]
<C:\WINDOWS\system32\ks8j3jsisd.exe -j><Microsoft Corporation>
[kusn33sd / kusn33sd][Stopped/Auto Start]
<C:\WINDOWS\system32\kusn33sd.exe -j><Microsoft Corporation>
[QoS Service / MOVEESS][Running/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLLFOROUR.EXE C:\WINDOWS\SYSTEM32\WBEM\TGEUE.DLL,DllRegisterServer 1087><Microsoft Corporation>
[Clipboard / NtStub][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\zhypr.dll><Microsoft Corporation>
[P4P Service / P4P Service][Running/Auto Start]
<C:\Program Files\Common Files\Sogou PXP\p2psvr.exe><Sohu.com Inc.>
[Windows qusr RunThem / qusr][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\lpnm\vzxw.dll>< >
[Rising Proxy Service / RfwProxySrv][Stopped/Manual Start]
<c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Remote Procedure Call System(RPCS) / RpcS][Running/Auto Start]
<C:\WINDOWS\system32\RpcS.exe><Microsoft Corporation>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe windhcp.ocx,input><Microsoft Corporation>
[Windows Accounts Driver / WindowsConnections][Stopped/Auto Start]
<C:\WINDOWS\system32\xets006.exe><N/A>
[wljs1234.3322.org / wljs1234.3322.org][Stopped/Auto Start]
<C:\WINDOWS\system32\wljs1234.3322.org.exe><N/A>
tanglinling - 2007-6-13 17:16:00
==================================
驱动程序
[2310_00 / 2310_00][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\2310_00.sys><HighPoint Technologies, Inc.>
[3WAREDRV / 3WAREDRV][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\3WAREDRV.SYS><N/A>
[3WAREGSM / 3WAREGSM][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\3waregsm.sys><N/A>
[3WDRV100 / 3WDRV100][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\3WDRV100.SYS><N/A>
[AAATIMEO / AAATIMEO][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\aaatimeo.sys><Microsoft Corporation>
[AACSAS / AACSAS][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\aacsas.sys><Adaptec, Inc.>
[AAR81XX / AAR81XX][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\aar81xx.sys><Adaptec, Inc.>
[AARSI3X / AARSI3X][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\aarsi3x.sys><Adaptec, Inc.>
[acpidisk / acpidisk][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[ADP94XX / ADP94XX][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\adp94xx.sys><Adaptec, Inc.>
[ARCM_X86 / ARCM_X86][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\arcm_x86.sys><ARECA Technology Corporation>
[ati2mtag / ati2mtag][Running/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[BB-RUN / BB-RUN][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\bb-run.sys><Promise Technology, Inc.>
[BCHTSW32 / BCHTSW32][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\bchtsw32.sys><Broadcom Corporation>
[BCRAID / BCRAID][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\bcraid.sys><Broadcom Corporation>
[BUSLOGIC / BUSLOGIC][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\buslogic.sys><Microsoft Corporation>
[CDA1000 / CDA1000][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\cda1000.sys><Adaptec, Inc.>
[CdaC15BA / CdaC15BA][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\CdaC15BA.SYS><Macrovision Europe Ltd>
[CmdIde / CmdIde][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[cnprov / cnprov][Running/Boot Start]
<\SystemRoot\system32\drivers\cnprov.sys><中国互联网络信息中心(CNNIC)>
[CPQARRY2 / CPQARRY2][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\cpqarry2.sys><Compaq Computer Corporation>
[CPQCISSM / CPQCISSM][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\cpqcissm.sys><Hewlett-Packard Company>
[CSB6IDE / CSB6IDE][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\csb6ide.sys><ServerWorks Corporation>
[DMX3191 / DMX3191][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\DMX3191.sys><Microsoft Corporation>
[DMX3194 / DMX3194][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\dmx3194.sys><Microsoft Corporation>
[DONTGO / DONTGO][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\DontGo.sys><Promise Technology, Inc.>
[DPTSCSI / DPTSCSI][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\dptscsi.sys><Distributed Processing Technology Corp.>
[eickyy5 / eickyy56][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\eickyy56.sys><N/A>
[ExpScaner / ExpScaner][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[fpohcg / fpohcg][Stopped/Boot Start]
<\SystemRoot\system32\drivers\fpohcg.sys><N/A>
[FT8300 / FT8300][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\ft8300.sys><Promise Technology, Inc.>
[FTTXR52P / FTTXR52P][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\fttxr52P.sys><Promise Technology, Inc.>
[FTTXR54P / FTTXR54P][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\fttxr54P.sys><Promise Technology, Inc.>
[FTTXR5_O / FTTXR5_O][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\fttxr5_O.sys><Promise Technology, Inc.>
[fybhvi3 / fybhvi33][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\fybhvi33.sys><N/A>
[GD31244 / GD31244][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\gd31244.sys><Intel Corporation>
[ggjikll / ggjikll][Stopped/Disabled]
<system32\drivers\ggjikll.sys><N/A>
[Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HOOKAPI / HOOKAPI][Stopped/Manual Start]
<\??\C:\PROGRAM FILES\RISING\RAV\HookApi.Sys><瑞星软件有限公司>
[HookCont / HookCont][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl][Running/Auto Start]
<\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[HPCISSS2 / HPCISSS2][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\HpCISSs2.sys><Hewlett-Packard Company>
[idnaux / idnaux][Running/Auto Start]
<system32\drivers\idnaux.sys><中国互联网络信息中心(CNNIC)>
[IFT2000 / IFT2000][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\ift2000.sys><Infortrend Technology, Inc.>
[INIA100 / INIA100][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\INIA100.sys><Initio corp.>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
<system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
[IPSRAIDN / IPSRAIDN][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\ipsraidn.sys><IBM Corporation>
[JAHCI / JAHCI][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\JAHCI.SYS><JMicron>
tanglinling - 2007-6-13 17:17:00
[jchfaicf / jchfaicf][Stopped/Boot Start]
<\SystemRoot\system32\drivers\jchfaicf.sys><N/A>
[JGOGO / JGOGO][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\JGOGO.SYS><JMicron>
[kmsinput / kmsinput][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[knmlkl / knmlkl][Stopped/Boot Start]
<\SystemRoot\system32\drivers\knmlkl.sys><N/A>
[M5287 / M5287][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\m5287.sys><ULi Electronics Inc.>
[M5288 / M5288][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\m5288.sys><ULi Electronics Inc.>
[M5289 / M5289][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\m5289.sys><ULi Electronics Inc.>
[MEGAIDE / MEGAIDE][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs][Running/Auto Start]
<\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[MSAHCI / MSAHCI][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\msahci.sys><Microsoft Corporation>
[ATK0110 ACPI UTILITY / MTsensor][Running/Manual Start]
<system32\DRIVERS\ASACPI.sys><>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[NVATABUS / NVATABUS][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\NVATABUS.SYS><NVIDIA Corporation>
[onuj / onujr][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\onujr.sys><N/A>
[ovbrno4 / ovbrno44][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\ovbrno44.sys><N/A>
[Padus ASPI Shell / pfc][Running/Manual Start]
<system32\drivers\pfc.sys><Padus, Inc.>
[prodwe / prodwe][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\prodwe.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[ptwewa / ptwewa][Stopped/Boot Start]
<\SystemRoot\system32\drivers\ptwewa.sys><N/A>
[quphzx / quphzx][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\quphzx.sys><N/A>
[RR232X / RR232X][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\rr232x.sys><HighPoint Technologies, Inc.>
[RsFwDrv / RsFwDrv][Running/Auto Start]
<\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[SI3114R5 / SI3114R5][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\Si3114r5.sys><Silicon Image, Inc>
[SI3124R5 / SI3124R5][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\Si3124r5.sys><Silicon Image, Inc>
[SI3132 / SI3132][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\SI3132.sys><Silicon Image, Inc.>
[SI3132R5 / SI3132R5][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\Si3132r5.sys><Silicon Image, Inc>
[SIFILTER / SIFILTER][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\SiWinAcc.sys><Silicon Image, Inc.>
[SIREMFIL / SIREMFIL][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\SiRemFil.sys><Silicon Image, Inc.>
[SISRAID2 / SISRAID2][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\SiSRaid2.sys><Silicon Integrated Systems Corp>
[SISRAID4 / SISRAID4][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\SiSRaid4.sys><Silicon Integrated Systems>
[ST8350 / ST8350][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\st8350.sys><Promise Technology, Inc.>
[SYMC810 / SYMC810][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\symc810.sys><N/A>
[thbznb2 / thbznb20][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\thbznb20.sys><N/A>
[tjpwsb / tjpwsb][Stopped/Boot Start]
<\SystemRoot\system32\drivers\tjpwsb.sys><N/A>
[TRM3X5 / TRM3X5][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\trm3x5.sys><Tekram Technology Co., Ltd.>
[ueulgy8 / ueulgy81][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\ueulgy81.sys><N/A>
[ULSATA2 / ULSATA2][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\ulsata2.sys><Promise Technology, Inc.>
[ULTIMA / ULTIMA][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\Ultima.sys><Aralion INC.>
[ULTIMARX / ULTIMARX][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\UltimaRX.sys><Aralion INC.>
[ViaIde / ViaIde][Stopped/Boot Start]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[W2KADV / W2KADV][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\w2kadv.sys><ConnectCom Solutions, Inc.>
[WD7296A / WD7296A][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\wd7296a.sys><Western Digital Corporation>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[xdcxcq / xdcxcq][Stopped/Boot Start]
<\SystemRoot\system32\drivers\xdcxcq.sys><N/A>
[NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller / yukonwxp][Running/Manual Start]
<system32\DRIVERS\yk51x86.sys><Marvell>
[yykzif / yykzif][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\yykzif.sys><N/A>
[VIMICRO USB PC Camera (ZC030X) / ZSMC303][Running/Manual Start]
<System32\Drivers\usbVM303.sys><Vimicro Corporation>
tanglinling - 2007-6-13 17:18:00
==================================
浏览器加载项
[QQCycloneHelper Class]
{5C3853CE-C7E0-4946-B3FA-1ABDB6F48108} <C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, 腾讯公司>
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, N/A>
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
[Google Script Object]
{00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[MMCPlayer Class]
{05C1004E-2596-48E5-8E26-39362985EEB9} <C:\Program Files\Sogou PXP\MMCShell.dll, Sohu.com Inc.>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Tencent Browser Helper]
{0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr2.dll, Tencent>
[CAdLogic Object]
{11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\CPUSH\cpush0.dll, >
[assist]
{1B0E7716-898E-48CC-9690-4E338E8DE1D3} <C:\PROGRA~1\3721\Assist\assist.dll, >
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[Cbho Object]
{352E3B3A-CAB5-4DBC-B940-C7F84D0447D8} <C:\PROGRA~1\CNNIC\Cdn\cdndrag.dll, N/A>
[腾讯QQ]
{54EBD53A-9BC1-480B-966A-843A333CA162} <C:\WINDOWS\QQIEHelper.dll, N/A>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[QQCycloneHelper Class]
{5C3853CE-C7E0-4946-B3FA-1ABDB6F48108} <C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, 腾讯公司>
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, N/A>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[]
{669751ED-D558-49AE-B01A-3B374CC7910E} <C:\WINDOWS\system32\ssup.dll, TENCENT>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[WangWangObj Class]
{6E213FC7-DD5A-4115-B7E6-D4C7838C361E} <C:\Program Files\Alisoft\WangWang\WangWangX4.dll, 阿里软件(中国)有限公司>
[IEAux Class]
{7605CC7C-00FD-4A5F-BAFD-828342DE6279} <C:\PROGRA~1\OCINS\ieaux.dll, 中国互联网络信息中心(CNNIC)>
[AutoLive]
{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2} <C:\PROGRA~1\3721\autolive.dll, 北京三七二一科技有限公司>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Windows Live Sign-in Helper]
{9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
[Google Toolbar Helper]
{AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\Mshtml.dll, Microsoft Corporation>
[上网助手]
{BB936323-19FA-4521-BA29-ECA6A121BC78} <C:\PROGRA~1\3721\Assist\asbar.dll, 3721>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Windows Live Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, Microsoft Corporation>
[Windows Live Toolbar Helper]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, Microsoft Corporation>
[]
{C74CDF30-68C2-49B4-9918-EBD66B8D9FBF} <C:\WINDOWS\system32\xscayfpgrpzlw.dll, N/A>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[EpsonToolBandKicker Class]
{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} <C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll, SEIKO EPSON CORPORATION>
[BoBoControl Class]
{EC0978ED-24E3-403C-AB7A-060E388553E6} <C:\WINDOWS\Downloaded Program Files\BoBo_ActiveX_V3.ocx, 广州易播信息科技有限公司>
[EPSON Web-To-Page]
{EE5D279F-081B-4404-994D-C6B60AAEBA6D} <C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll, SEIKO EPSON CORPORATION>
tanglinling - 2007-6-13 17:22:00
==================================
正在运行的进程
[PID: 656][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 728][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 756][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\7055723A.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\system32\winlib .dll] [N/A, ]
[C:\WINDOWS\system32\df33sdg.dll] [Microsoft Corporation, ]
[C:\WINDOWS\system32\kusn433sd3.dll] [Microsoft Corporation, ]
[c:\progra~1\lpnm\ycaz.dll] [, 5, 0, 0, 4]
[c:\progra~1\lpnm\dhfe.dll] [ , 5, 0, 0, 4]
[PID: 800][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 812][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1008][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4129]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2500]
[c:\progra~1\lpnm\ycaz.dll] [, 5, 0, 0, 4]
[c:\progra~1\lpnm\dhfe.dll] [ , 5, 0, 0, 4]
[PID: 1024][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1152][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1240][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 1260][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\windows\system32\zhypr.dll] [Microsoft Corporation, 5.1.2600.0]
[C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[PID: 1364][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1464][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1484][C:\Program Files\Rising\Rav\Ravmond.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 39]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\rfwctrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[C:\Program Files\Rising\Rav\RsPPsys.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RsLog.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\HOOKSYS.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
[C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[C:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[C:\Program Files\Rising\Rav\regmon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\psapi.dll] [Microsoft Corporation, 4.00]
[C:\Program Files\Rising\Rav\HookWeb.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[C:\Program Files\Rising\Rav\MemMon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
[C:\Program Files\Rising\Rav\expscan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[C:\Program Files\Rising\Rav\HookCont.dll] [Rising, 19, 0, 0, 0]
[C:\Program Files\Rising\Rav\SpamEng.dll] [, 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\engine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
[C:\Program Files\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[C:\Program Files\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[C:\Program Files\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 30]
[C:\Program Files\Rising\Rav\ExtFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 23]
[C:\Program Files\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[C:\Program Files\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
[C:\Program Files\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\Unpacker.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
[C:\Program Files\Rising\Rav\ScanPack.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 18]
[C:\Program Files\Rising\Rav\RsVM.dll] [, 19, 0, 0, 13]
[C:\Program Files\Rising\Rav\Uroutine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[C:\Program Files\Rising\Rav\Uscript.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
[C:\Program Files\Rising\Rav\ExtOLE.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[PID: 1432][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
tanglinling - 2007-6-13 17:22:00
[c:\progra~1\lpnm\ycaz.dll] [, 5, 0, 0, 4]
[c:\progra~1\lpnm\dhfe.dll] [ , 5, 0, 0, 4]
[C:\WINDOWS\system32\df33sdg.dll] [Microsoft Corporation, ]
[C:\Program Files\AutoCAD2004\AcSignIcon.dll] [Autodesk, 16.0.0.86]
[C:\WINDOWS\KB9279O1.log] [N/A, ]
[C:\WINDOWS\system32\kusn433sd3.dll] [Microsoft Corporation, ]
[C:\WINDOWS\system32\7055723A.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\system32\vqlqh.dll] [N/A, ]
[C:\WINDOWS\system32\thbznb20.dll] [, 1, 1, 1, 1011]
[C:\WINDOWS\system32\eickyy56.dll] [, 1, 1, 1, 1019]
[C:\WINDOWS\system32\ueulgy81.dll] [Microsoft Corporation, 1, 1, 1, 1045]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\Program Files\AutoCAD2004\AcSignCore16.dll] [Autodesk, 16.0.0.86]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 5.00.2000.3]
[PID: 1432][C:\WINDOWS\netdde32.exe] [N/A, ]
[PID: 1432][C:\WINDOWS\system32\netdde32.exe] [N/A, ]
[C:\WINDOWS\system32\audiodev.dll] [Microsoft Corporation, 5.2.3810.3911 built by: DNSRV(bld4act)]
[PID: 2756][C:\WINDOWS\system32\dgd4bs.exe] [N/A, ]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690]
[C:\WINDOWS\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[c:\progra~1\lpnm\ycaz.dll] [, 5, 0, 0, 4]
[c:\progra~1\lpnm\dhfe.dll] [ , 5, 0, 0, 4]
[PID: 544][C:\WINDOWS\system32\dgd4bs.exe] [N/A, ]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690]
[C:\WINDOWS\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[c:\progra~1\lpnm\ycaz.dll] [, 5, 0, 0, 4]
[c:\progra~1\lpnm\dhfe.dll] [ , 5, 0, 0, 4]
[PID: 3048][C:\WINDOWS\system32\5A421ED6.exe] [N/A, ]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690]
[C:\WINDOWS\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[c:\progra~1\lpnm\ycaz.dll] [, 5, 0, 0, 4]
[c:\progra~1\lpnm\dhfe.dll] [ , 5, 0, 0, 4]
[C:\WINDOWS\system32\eickyy56.dll] [, 1, 1, 1, 1019]
[C:\WINDOWS\system32\thbznb20.dll] [, 1, 1, 1, 1011]
[PID: 184][c:\program files\rising\rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 72]
[c:\program files\rising\rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[c:\program files\rising\rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[c:\program files\rising\rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[c:\program files\rising\rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[c:\program files\rising\rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[c:\progra~1\lpnm\ycaz.dll] [, 5, 0, 0, 4]
[c:\progra~1\lpnm\dhfe.dll] [ , 5, 0, 0, 4]
[C:\WINDOWS\system32\eickyy56.dll] [, 1, 1, 1, 1019]
[C:\WINDOWS\system32\thbznb20.dll] [, 1, 1, 1, 1011]
[c:\program files\rising\rfw\PSAPI.DLL] [Microsoft Corporation, 4.00]
[PID: 3068][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[c:\progra~1\lpnm\ycaz.dll] [, 5, 0, 0, 4]
[c:\progra~1\lpnm\dhfe.dll] [ , 5, 0, 0, 4]
[C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[C:\WINDOWS\system32\mucltui.dll] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[PID: 5152][c:\program files\rising\rfw\RfwCfg.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 1, 53]
[c:\program files\rising\rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[c:\program files\rising\rfw\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\WINDOWS\system32\eickyy56.dll] [, 1, 1, 1, 1019]
[C:\WINDOWS\system32\thbznb20.dll] [, 1, 1, 1, 1011]
[c:\progra~1\lpnm\ycaz.dll] [, 5, 0, 0, 4]
[c:\progra~1\lpnm\dhfe.dll] [ , 5, 0, 0, 4]
[c:\program files\rising\rfw\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[c:\program files\rising\rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[c:\program files\rising\rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[c:\program files\rising\rfw\ProxyCtr.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 2]
[c:\program files\rising\rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[c:\program files\rising\rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\AutoCAD2004\AcSignIcon.dll] [Autodesk, 16.0.0.86]
[C:\Program Files\AutoCAD2004\AcSignCore16.dll] [Autodesk, 16.0.0.86]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 2832][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\eickyy56.dll] [, 1, 1, 1, 1019]
[C:\WINDOWS\system32\thbznb20.dll] [, 1, 1, 1, 1011]
[c:\progra~1\lpnm\ycaz.dll] [, 5, 0, 0, 4]
[c:\progra~1\lpnm\dhfe.dll] [ , 5, 0, 0, 4]
[C:\Program Files\AutoCAD2004\AcSignIcon.dll] [Autodesk, 16.0.0.86]
[C:\WINDOWS\system32\winkyy56.dll] [, 1, 1, 1, 1049]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\audiodev.dll] [Microsoft Corporation, 5.2.3810.3911 built by: DNSRV(bld4act)]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 5.00.2000.3]
[C:\Program Files\AutoCAD2004\AcSignCore16.dll] [Autodesk, 16.0.0.86]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll] [腾讯公司, 1, 1, 0, 5]
[PID: 11052][C:\Documents and Settings\Administrator\桌面\sreng2-1\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINDOWS\system32\eickyy56.dll] [, 1, 1, 1, 1019]
[C:\WINDOWS\system32\thbznb20.dll] [, 1, 1, 1, 1011]
[c:\progra~1\lpnm\ycaz.dll] [, 5, 0, 0, 4]
[c:\progra~1\lpnm\dhfe.dll] [ , 5, 0, 0, 4]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
tanglinling - 2007-6-13 17:23:00
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. [hh.exe %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [notepad.exe %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
[D:\]
[autorun]
open=iRvtE.exe
shellexecute=iRvtE.exe
shell\Auto\command=iRvtE.exe
shell=Auto
[E:\]
[autorun]
open=iRvtE.exe
shellexecute=iRvtE.exe
shell\Auto\command=iRvtE.exe
shell=Auto
[F:\]
[autorun]
open=iRvtE.exe
shellexecute=iRvtE.exe
shell\Auto\command=iRvtE.exe
shell=Auto
==================================
HOSTS 文件
20
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
liuyi0108 - 2007-6-13 22:38:00
注意一下C:\WINDOWS\system32\5A421ED6.exe
C:\WINDOWS\system32\dgd4bs.exe
C:\WINDOWS\SYSTEM32\RUNDLLFOROUR.EXE
C:\WINDOWS\system32\dgd4bs.exe
这些有问题的啊 能直接删 的就直接拉
1
© 2000 - 2026 Rising Corp. Ltd.