瑞星卡卡安全论坛
靠我中毒了 - 2007-6-22 14:21:00
中了这个juexiao.exe,请高手解决!
中了这个juexiao.exe,删除了过以后又有了,然后C:\windows\Temp里就出现一些莫名其妙的东西,比如juexiao.exe,bb.exe.dodolook.exe,helper.exe,qqhelper.exe,然后电脑里悄悄的就被装上了流氓软件,似乎杀不干净了,这几天被这个东西搞的郁闷之极。
请高手指点,不胜感激.
火影忍者 - 2007-6-22 14:35:00
下载 System Repair Engineer,
http://www.kztechs.com/sreng/download.html
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
yangyi - 2007-6-22 15:11:00
下载 System Repair Engineer,
http://www.kztechs.com/sreng/download.html
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
靠我中毒了 - 2007-6-22 15:16:00
CODE]
2007-06-22,14:46:32
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows 98 SE -
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SystemTray><SysTray.Exe> [Microsoft Corporation]
<LoadPowerProfile><Rundll32.exe powrprof.dll,LoadCurrentPwrScheme> [Microsoft Corporation]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Corporation Limited]
<internat.exe><internat.exe> [Microsoft Corporation]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<RavMon><C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<RfwService><"C:\PROGRAM FILES\RISING\RFW\RFWSRV.EXE" -service> [Beijing Rising Technology Corporation Limited]
<RavMon><"C:\Program Files\Rising\Rav\RavMon.exe" -system> [Beijing Rising Technology Co., Ltd.]
==================================
启动文件夹
N/A
==================================
服务
N/A
==================================
驱动程序
N/A
==================================
浏览器加载项
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL, Adobe Systems Incorporated>
[上网助手]
{BB936323-19FA-4521-BA29-ECA6A121BC78} <C:\PROGRAM FILES\3721\ASSIST\ASBAR.DLL, 3721>
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\SYSTEM\XUNLEIBHO_V5.DLL, (>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\PROGRAM FILES\TENCENT\QQ\QQ.EXE, N/A>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\SYSTEM\MSDXM.OCX, Microsoft Corporation>
[上网助手]
{BB936323-19FA-4521-BA29-ECA6A121BC78} <C:\PROGRAM FILES\3721\ASSIST\ASBAR.DLL, 3721>
[完美网译通]
{F43BD772-ABDD-43b7-A96A-3E9E61946EC0} <C:\WINDOWS\WORLD2\TOOLBAR\HMTOOLBAR.DLL, 北京完美时空有限公司>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH9B.OCX, Adobe Systems, Inc.>
[CNNIC_IDN]
{9A578C98-3C2F-4630-890B-FC04196EF420} <C:\WINDOWS\SYSTEM\CDN.DLL, CNNIC>
[PowerPlayer Control]
{5EC7C511-CD0F-42E6-830C-1BD9882F3458} <C:\WINDOWS\DOWNLO~1\POWERP~1.DLL, PPStream Inc.>
[CellWeb5 Control]
{3F166327-8030-4881-8BD2-EA25350E574A} <C:\WINDOWS\SYSTEM\CELLWEB5.OCX, Cell Software Inc>
[添加到QQ自定义面板]
<C:\PROGRAM FILES\TENCENT\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\PROGRAM FILES\TENCENT\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\PROGRAM FILES\TENCENT\QQ\SendMMS.htm, N/A>
[&使用迅雷下载]
<C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\geturl.htm, N/A>
[&使用迅雷下载全部链接]
<C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\getAllurl.htm, N/A>
[上传到QQ网络硬盘]
<C:\PROGRAM FILES\TENCENT\QQ\AddToNetDisk.htm, N/A>
靠我中毒了 - 2007-6-22 15:18:00
正在运行的进程
[C:\WINDOWS\SYSTEM\MSI.DLL] [Microsoft Corporation, 2.0.2600.2]
[C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\MSINFO\IEINFO5.SYS] [N/A, ]
[C:\WINDOWS\SYSTEM\WININET.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\CRYPT32.DLL] [Microsoft Corporation, 5.131.1877.4]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\MSOSS.DLL] [Microsoft Corporation, 5.131.1877.3]
[C:\WINDOWS\SYSTEM\RAVEXT.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\WINDOWS\SYSTEM\OLEAUT32.DLL] [Microsoft Corporation, 2.40.4518]
[C:\WINDOWS\SYSTEM\OLE32.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3812.600]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.10.8924.0]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\MSPP32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MSNET32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3812.600]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.10.8924.0]
[PID: 4294938401][C:\WINDOWS\SYSTEM\SPOOL32.EXE] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\SPOOLSS.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\MSNP32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\MSNET32.DLL] [Microsoft Corporation, 4.10.1998]
[PID: 4294944489][C:\WINDOWS\SYSTEM\MPREXE.EXE] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MPRSERV.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\MSPWL32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\PROGRAM FILES\RISING\RFW\RFWLOG.DLL] [Beijing Rising Technology Corporation Limited, 3, 1, 0, 2]
[C:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL] [Beijing Rising Technology Corporation Limited, 3, 1, 0, 0]
[C:\PROGRAM FILES\RISING\RFW\RFWDRV.DLL] [Beijing Rising Technology Corporation Limited, 3, 0, 1, 5]
[PID: 4294837097][C:\PROGRAM FILES\RISING\RFW\RFWSRV.EXE] [Beijing Rising Technology Corporation Limited, 3, 1, 0, 36]
[C:\WINDOWS\SYSTEM\OLEAUT32.DLL] [Microsoft Corporation, 2.40.4518]
[C:\WINDOWS\SYSTEM\OLE32.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[C:\WINDOWS\SYSTEM\MFC42LOC.DLL] [Microsoft Corporation, 4.21.7303]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.10.8924.0]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\SHDOCVW.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\PROGRAM FILES\RISING\RAV\PNGDLL.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\PROGRAM FILES\RISING\RAV\RSXML.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL] [rising, 18, 0, 0, 1]
[C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
靠我中毒了 - 2007-6-22 15:22:00
[PID: 4294845749][C:\PROGRAM FILES\RISING\RAV\RAVMON.EXE] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 45]
[C:\WINDOWS\SYSTEM\VERSION.DLL] [Microsoft Corporation, 4.10.1998]
[C:\PROGRAM FILES\RISING\RAV\BWLIST.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[C:\WINDOWS\SYSTEM\WSOCK32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MSWSOCK.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\WS2_32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\WININET.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\OLEAUT32.DLL] [Microsoft Corporation, 2.40.4518]
[C:\WINDOWS\SYSTEM\OLE32.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\CRYPT32.DLL] [Microsoft Corporation, 5.131.1877.4]
[C:\WINDOWS\SYSTEM\MSOSS.DLL] [Microsoft Corporation, 5.131.1877.3]
[C:\WINDOWS\SYSTEM\WS2HELP.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3812.600]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\PROGRAM FILES\RISING\RAV\RSGUILIB.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[C:\WINDOWS\SYSTEM\MSVCP60.DLL] [Microsoft Corporation, 6.00.8972.0]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[C:\WINDOWS\SYSTEM\MFC42LOC.DLL] [Microsoft Corporation, 4.21.7303]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.10.8924.0]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\IGFXPPH.DLL] [Intel Corporation, 3,0,0,1132]
[C:\WINDOWS\SYSTEM\HCCUTILS.DLL] [Intel Corporation, 3,0,0,1132]
[C:\PROGRAM FILES\3721\ASSIST\XPSTYLE.DLL] [N/A, ]
[C:\PROGRAM FILES\3721\ASSIST\ASSECBLK.DLL] [3721, 1, 0, 0, 9]
[C:\PROGRAM FILES\3721\ASSIST\ADFILTER.DLL] [ , 1, 0, 1, 6]
[C:\PROGRAM FILES\3721\ASSIST\OPTIMUM.DLL] [N/A, ]
[C:\PROGRAM FILES\3721\ASSIST\REPAIR.DLL] [北京三七二一科技有限公司, 1, 0, 4, 1001]
[C:\PROGRAM FILES\3721\ASSIST\ASFSKS.DLL] [3721.com, 2, 1, 1, 87]
[C:\WINDOWS\SYSTEM\IPHLPAPI.DLL] [Microsoft Corporation, 5.00.1717.2]
[C:\WINDOWS\SYSTEM\IPCFGDLL.DLL] [Microsoft Corporation, 5.00.1717.2]
[C:\WINDOWS\SYSTEM\DHCPCSVC.DLL] [N/A, ]
[C:\WINDOWS\SYSTEM\ICMP.DLL] [Microsoft Corporation, 5.00.1454.1]
[C:\WINDOWS\SYSTEM\SENSAPI.DLL] [Microsoft Corporation, 5.50.4807.2300]
[C:\PROGRAM FILES\WINRAR\RAREXT.DLL] [N/A, ]
[C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\WINDOWS\SYSTEM\MSTASK.DLL] [Microsoft Corporation, 4.71.1972.1]
[C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\WINDOWS\SYSTEM\ASYCFILT.DLL] [Microsoft Corporation, 2.40.4518]
[C:\PROGRAM FILES\3721\ASSIST\ASNOAD.DLL] [$, 1, 0, 0, 9]
[C:\WINDOWS\SYSTEM\WINMM.DLL] [Microsoft Corporation, 4.03.1998]
[C:\PROGRAM FILES\3721\ASSIST\ASBAR.DLL] [3721, 1, 0, 1, 1008]
[C:\WINDOWS\SYSTEM\SETUPAPI.DLL] [Microsoft Corporation, 5.00.1671.1]
[C:\WINDOWS\SYSTEM\CFGMGR32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\WINSPOOL.DRV] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\COMDLG32.DLL] [Microsoft Corporation, 4.72.3510.2300]
[C:\WINDOWS\SYSTEM\LZ32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\NTDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\BROWSELC.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\ES.DLL] [Microsoft Corporation, 1998.09.1003.0]
[C:\WINDOWS\SYSTEM\SENS.DLL] [Microsoft Corporation, 5.50.4807.2300]
[C:\WINDOWS\SYSTEM\ESTIER2.DLL] [Microsoft Corporation, 1998.09.1003.0]
[C:\WINDOWS\SYSTEM\ESSHARED.DLL] [Microsoft Corporation, 1998.09.1003.0]
[C:\WINDOWS\SYSTEM\LINKINFO.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MSLS31.DLL] [Microsoft Corporation, 3.10.349.0]
[C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\NETAPI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] [N/A, ]
[C:\WINDOWS\SYSTEM\WEBCHECK.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\SHDOCLC.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSAFD.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\RNR20.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\WSOCK32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MSWSOCK.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\WS2_32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\WS2HELP.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MSI.DLL] [Microsoft Corporation, 2.0.2600.2]
[C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\MSINFO\IEINFO5.SYS] [N/A, ]
[C:\WINDOWS\SYSTEM\RAVEXT.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\WINDOWS\SYSTEM\MSSHRUI.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\SVRAPI.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MSNET32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MYDOCS.DLL] [Microsoft Corporation, 4.72.3510.2300]
[C:\WINDOWS\SYSTEM\SHFOLDER.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\WININET.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\CRYPT32.DLL] [Microsoft Corporation, 5.131.1877.4]
[C:\WINDOWS\SYSTEM\MSOSS.DLL] [Microsoft Corporation, 5.131.1877.3]
[C:\WINDOWS\SYSTEM\OLEAUT32.DLL] [Microsoft Corporation, 2.40.4518]
[C:\WINDOWS\SYSTEM\MSHTML.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MLANG.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\URLMON.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\VERSION.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\SHD401LC.DLL] [Microsoft Corporation, 5.50.4914.1400]
[C:\WINDOWS\SYSTEM\BROWSEUI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\SHDOC401.DLL] [Microsoft Corporation, 5.50.4914.1400]
[C:\WINDOWS\SYSTEM\OLE32.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\SHDOCVW.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3812.600]
[PID: 4294780869][C:\WINDOWS\EXPLORER.EXE] [Microsoft Corporation, 4.72.3110.1]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.10.8924.0]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHFOLDER.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3812.600]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\RNR20.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\MSAFD.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\RPCLTSCM.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\WSOCK32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MSWSOCK.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\WS2_32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\WININET.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\OLEAUT32.DLL] [Microsoft Corporation, 2.40.4518]
[C:\WINDOWS\SYSTEM\CRYPT32.DLL] [Microsoft Corporation, 5.131.1877.4]
[C:\WINDOWS\SYSTEM\MSOSS.DLL] [Microsoft Corporation, 5.131.1877.3]
[C:\WINDOWS\SYSTEM\WS2HELP.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.10.8924.0]
[C:\WINDOWS\SYSTEM\DIGEST.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\NTDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MSNSSPC.DLL] [Microsoft Corporation, 6.00.7753]
[C:\WINDOWS\SYSTEM\MSAPSSPC.DLL] [Microsoft Corporation, 5.00.7729]
[C:\WINDOWS\SYSTEM\MSVCRT40.DLL] [Microsoft Corporation, 4.22.0000]
[C:\WINDOWS\SYSTEM\SECUR32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\OLE32.DLL] [Microsoft Corporation, 4.71.2900]
[PID: 4294793745][C:\WINDOWS\SYSTEM\RPCSS.EXE] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\MSVCRT20.DLL] [Microsoft Corporation, 2.11.000]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\PROGRAM FILES\RISING\RFW\PNGDLL.DLL] [Rising, 17, 0, 0, 2]
[C:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 17, 0, 0, 17]
靠我中毒了 - 2007-6-22 15:23:00
[PID: 4294816853][C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE] [Beijing Rising Technology Corporation Limited, 3, 1, 0, 19]
[C:\PROGRAM FILES\RISING\RFW\RSGUILIB.DLL] [Beijing Rising Technology Co., Ltd., 17, 0, 0, 40]
[C:\WINDOWS\SYSTEM\MSVCP60.DLL] [Microsoft Corporation, 6.00.8972.0]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3812.600]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[C:\WINDOWS\SYSTEM\MFC42LOC.DLL] [Microsoft Corporation, 4.21.7303]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.10.8924.0]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\USBUI.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\WMI.DLL] [Microsoft Corporation, 5.00.1755.1]
[C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.10.1998]
[PID: 4294743249][C:\WINDOWS\SYSTEM\SYSTRAY.EXE] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\BATMETER.DLL] [Microsoft Corporation, 5.00.0910.1900]
[C:\WINDOWS\SYSTEM\POWRPROF.DLL] [Microsoft Corporation, 5.00.0910.1900]
[C:\WINDOWS\SYSTEM\SETUPAPI.DLL] [Microsoft Corporation, 5.00.1671.1]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\CFGMGR32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\WINSPOOL.DRV] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\VERSION.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\COMDLG32.DLL] [Microsoft Corporation, 4.72.3510.2300]
[C:\WINDOWS\SYSTEM\LZ32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\NTDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\WINMM.DLL] [Microsoft Corporation, 4.03.1998]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3812.600]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.10.8924.0]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.10.1998]
[PID: 4294768409][C:\WINDOWS\SYSTEM\INTERNAT.EXE] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3812.600]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.10.8924.0]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\MSRD3X40.DLL] [Microsoft Corporation, 4.00.2927.4]
[C:\WINDOWS\SYSTEM\ODBCCP32.DLL] [Microsoft Corporation, 3.520.4403.2]
[C:\WINDOWS\SYSTEM\VERSION.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ODBCJT32.DLL] [Microsoft Corporation, 4.0.4403.2]
[C:\WINDOWS\SYSTEM\MSJTER40.DLL] [Microsoft Corporation, 4.00.2927.2]
[C:\WINDOWS\SYSTEM\MSJINT40.DLL] [Microsoft Corporation, 4.00.2927.2]
[C:\WINDOWS\SYSTEM\ODBCJI32.DLL] [Microsoft Corporation, 4.0.4403.2]
[C:\WINDOWS\SYSTEM\MSJET40.DLL] [Microsoft Corporation, 4.00.2927.17]
[C:\WINDOWS\SYSTEM\MSWSTR10.DLL] [Microsoft Corporation, 4.00.2927.10]
[C:\WINDOWS\SYSTEM\ODBC32.DLL] [Microsoft Corporation, 3.520.4403.2]
[C:\WINDOWS\SYSTEM\ODBCINT.DLL] [Microsoft Corporation, 3.520.4403.2]
[C:\WINDOWS\SYSTEM\COMDLG32.DLL] [Microsoft Corporation, 4.72.3510.2300]
[C:\PROGRAM FILES\RISING\RAV\RSLOG.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3812.600]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[C:\WINDOWS\SYSTEM\MFC42LOC.DLL] [Microsoft Corporation, 4.21.7303]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.10.8924.0]
[C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL] [rising, 18, 0, 0, 1]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\WINDOWS\SYSTEM\OLEAUT32.DLL] [Microsoft Corporation, 2.40.4518]
[C:\WINDOWS\SYSTEM\OLE32.DLL] [Microsoft Corporation, 4.71.2900]
[C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 4294768873][C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[PID: 4294748861][C:\WINDOWS\SYSTEM\WMIEXE.EXE] [Microsoft Corporation, 5.00.1755.1]
[C:\WINDOWS\SYSTEM\WMICORE.DLL] [Microsoft Corporation, 5.00.1755.1]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.10.8924.0]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\WINTRUST.DLL] [Microsoft Corporation, 5.131.1877.5]
[C:\WINDOWS\SYSTEM\URLMON.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSAFD.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\RNR20.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\WSOCK32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MSWSOCK.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHFOLDER.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\SENSAPI.DLL] [Microsoft Corporation, 5.50.4807.2300]
[C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\RICHED20.DLL] [Microsoft Corporation, 5.30.23.1200]
[PID: 4294578589][C:\WINDOWS\DESKTOP\新建文件夹\123\SRENG.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINDOWS\SYSTEM\WS2_32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\WININET.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\WS2HELP.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\WINMM.DLL] [Microsoft Corporation, 4.03.1998]
[C:\WINDOWS\SYSTEM\CRYPT32.DLL] [Microsoft Corporation, 5.131.1877.4]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\MSOSS.DLL] [Microsoft Corporation, 5.131.1877.3]
[C:\WINDOWS\SYSTEM\VERSION.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\OLEAUT32.DLL] [Microsoft Corporation, 2.40.4518]
[C:\WINDOWS\SYSTEM\OLEDLG.DLL] [Microsoft Corporation, 1.0]
[C:\WINDOWS\SYSTEM\MSVCRT20.DLL] [Microsoft Corporation, 2.11.000]
[C:\WINDOWS\SYSTEM\OLE32.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\WINSPOOL.DRV] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\COMDLG32.DLL] [Microsoft Corporation, 4.72.3510.2300]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3812.600]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.10.8924.0]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
靠我中毒了 - 2007-6-22 15:24:00
==================================
文件关联
.TXT OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [C:\WINDOWS\winhlp32.exe %1]
.INI OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS OK. [C:\WINDOWS\WScript.exe "%1" %*]
.JS OK. [C:\WINDOWS\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MS.w95.spi.tcp
C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.udp
C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.raw
C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.rsvptcp
C:\WINDOWS\SYSTEM\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
MS.w95.spi.rsvpudp
C:\WINDOWS\SYSTEM\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
MS.w95.spi.osp
C:\WINDOWS\SYSTEM\mswsosp.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
靠我中毒了 - 2007-6-22 15:27:00
高手帮我看看啊,我快烦死了,每次开机过会就死机,这个是单位的电脑有急用的,麻烦帮我看看,不胜感谢!!!!!!!
1
© 2000 - 2026 Rising Corp. Ltd.