瑞星卡卡安全论坛
kouen1986 - 2007-7-1 20:41:00
中了trojan.mnless.kis,在百度上搜了很多方法都没用,用unlocker删了重启之后还会回来,请哪位高手帮忙告诉我应该怎么删除!
谢谢~!
或者告诉我重装是否可以解决,万分感谢!
newcenturymoon - 2007-7-1 20:41:00
病毒路径?
逍遥浪子45 - 2007-7-1 20:47:00
呵呵麻烦以后楼主在发帖子的时候能提供病毒路径及杀软如何处理,最好配合性的发下日志..
.System Repair Engineer(Sreng)-调整和修复系统的免费工具
下载地址1:http://www.kztechs.com/sreng/sreng2.zip
kouen1986 - 2007-7-1 20:51:00
处理结果发现日期扫描方式路径文件
忽略2007-06-30 14:42文件监控C:\WINDOWS\system32winlib .dll
重新启动计算机后删除文件2007-06-30 22:22文件监控C:\WINDOWS\system32winlib .dll
重新启动计算机后删除文件2007-06-30 22:25文件监控C:\WINDOWS\system32winlib .dll
重新启动计算机后删除文件2007-07-01 19:31文件监控C:\WINDOWS\Temp~my1.tmp
重新启动计算机后删除文件2007-07-01 19:31文件监控C:\WINDOWS\Temp~my1.tmp
不好意思,太着急忘记了,我刚才试着进安全模式也进不去了。T.T
逍遥浪子45 - 2007-7-1 20:59:00
安全模式可以用我上面提供的工具修复,具体请发扫描日志来分析,朋友,如果下载后无法运行,请改下任意名字.EXE执行,谢谢合作!~
kouen1986 - 2007-7-1 21:01:00
[CODE]
2007-07-01,20:43:01
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [Microsoft Corporation]
<PcSync><C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog> [Time Information Services Ltd.]
<Super Rabbit IEPro><C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD> [Super Rabbit Soft]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
<igfxhkcmd><C:\WINDOWS\system32\hkcmd.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<IMEKRMIG6.1><C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE> [(Verified)Microsoft Windows Publisher]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<PCSuiteTrayApplication><C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray> [Nokia]
<DataLayer><C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE> [Nokia Mobile Phones Ltd.]
<Windows木马防火墙><D:\程序\系统维护2007\qdf\Trojanwall.exe> [风云谷]
<Vcrmon><D:\程序\系统维护2007\Virus Chaser\Vcrmon.exe> [New Technology Wave Inc.]
<360Safetray><C:\Program Files\360safe\safemon\360Tray.exe /start> [奇虎网]
<StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> []
<Thunder><"C:\Program Files\Thunder Network\Thunder\Thunder.exe" /s> [Thunder Networking Technologies,LTD]
<UnlockerAssistant><"C:\Program Files\Unlocker\UnlockerAssistant.exe"> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
<WinlogonNotify: igfxcui><igfxdev.dll> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
<WinlogonNotify: WgaLogon><WgaLogon.dll> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><D:\程序\屏幕保~1\bubbles.scr> [Microsoft Corporation]
==================================
启动文件夹
N/A
==================================
服务
[Application Management / AppMgmt][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
<C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[ConfigFree Service / CFSvcs][Running/Auto Start]
<C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe><TOSHIBA CORPORATION>
[DVD-RAM_Service / DVD-RAM_Service][Running/Auto Start]
<C:\WINDOWS\system32\DVDRAMSV.exe><Matsushita Electric Industrial Co., Ltd.>
[ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard][Running/Auto Start]
<C:\Program Files\ewido anti-spyware 4.0\guard.exe><Anti-Malware Development a.s.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Virus Chaser Spider NT / SpiderNt][Stopped/Auto Start]
<D:\程序\系统维护2007\Virus Chaser\Spidernt.exe><New Technology Wave Inc.>
[Messenger 共享文件夹 USN 杂志阅读器服务 / usnjsvc][Stopped/Manual Start]
<"C:\Program Files\MSN Messenger\usnsvc.exe"><N/A>
kouen1986 - 2007-7-1 21:01:00
==================================
驱动程序
[acpidisk / acpidisk][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[Access 32bits INT15 routine / BoiHwsetup][Running/Manual Start]
<system32\drivers\BoiHwSetup.sys><Quanta Computer Corp>
[DLABOIOM / DLABOIOM][Running/Auto Start]
<System32\DLA\DLABOIOM.SYS><Sonic Solutions>
[DLACDBHM / DLACDBHM][Running/System Start]
<System32\Drivers\DLACDBHM.SYS><Sonic Solutions>
[DLADResN / DLADResN][Running/Auto Start]
<System32\DLA\DLADResN.SYS><Sonic Solutions>
[DLAIFS_M / DLAIFS_M][Running/Auto Start]
<System32\DLA\DLAIFS_M.SYS><Sonic Solutions>
[DLAOPIOM / DLAOPIOM][Running/Auto Start]
<System32\DLA\DLAOPIOM.SYS><Sonic Solutions>
[DLAPoolM / DLAPoolM][Running/Auto Start]
<System32\DLA\DLAPoolM.SYS><Sonic Solutions>
[DLARTL_N / DLARTL_N][Running/System Start]
<System32\Drivers\DLARTL_N.SYS><Sonic Solutions>
[DLAUDFAM / DLAUDFAM][Running/Auto Start]
<System32\DLA\DLAUDFAM.SYS><Sonic Solutions>
[DLAUDF_M / DLAUDF_M][Running/Auto Start]
<System32\DLA\DLAUDF_M.SYS><Sonic Solutions>
[DRVMCDB / DRVMCDB][Running/Boot Start]
<\SystemRoot\System32\Drivers\DRVMCDB.SYS><Sonic Solutions>
[DRVNDDM / DRVNDDM][Running/Auto Start]
<System32\Drivers\DRVNDDM.SYS><Sonic Solutions>
[Virus Chaser Spider boot hook driver / drwebnet][Running/System Start]
<\SystemRoot\system32\drivers\drwebnet.sys><Doctor Web Ltd>
[ewido anti-spyware 4.0 driver / ewido anti-spyware 4.0 driver][Running/System Start]
<\??\C:\Program Files\ewido anti-spyware 4.0\guard.sys><N/A>
[ExpScaner / ExpScaner][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService][Running/Manual Start]
<system32\drivers\CHDAud.sys><Conexant Systems Inc.>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HookCont / HookCont][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[HSFHWAZL / HSFHWAZL][Running/Manual Start]
<system32\DRIVERS\HSFHWAZL.sys><Conexant Systems, Inc.>
[HSF_DPV / HSF_DPV][Running/Manual Start]
<system32\DRIVERS\HSF_DPV.sys><Conexant Systems, Inc.>
[ialm / ialm][Running/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[IVI ASPI Shell / Iviaspi][Running/Manual Start]
<system32\drivers\iviaspi.sys><InterVideo, Inc.>
[mdmxsdk / mdmxsdk][Stopped/Auto Start]
<system32\DRIVERS\mdmxsdk.sys><Conexant>
[meiudf / meiudf][Running/System Start]
<System32\Drivers\meiudf.sys><Matsushita Electric Industrial Co.,Ltd.>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs][Running/Auto Start]
<\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[TOSHIBA Network Device Usermode I/O Protocol / Netdevio][Running/Auto Start]
<system32\DRIVERS\netdevio.sys><TOSHIBA Corporation.>
[Nokia USB Generic / Nokia USB Generic][Stopped/Manual Start]
<system32\drivers\nmwcdc.sys><Nokia>
[Nokia USB Modem / Nokia USB Modem][Stopped/Manual Start]
<system32\drivers\nmwcdcm.sys><Nokia>
[Nokia USB Phone Parent / Nokia USB Phone Parent][Stopped/Manual Start]
<system32\drivers\nmwcd.sys><Nokia>
[npkcrypt / npkcrypt][Stopped/Auto Start]
<\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Padus ASPI Shell / Pfc][Running/Manual Start]
<system32\drivers\pfc.sys><Padus, Inc.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[Quanta HotKey Keyboard Filter Driver / qkbfiltr][Running/Manual Start]
<system32\drivers\qkbfiltr.sys><Quanta Computer, Inc.>
[Quanta HotKey Mouse Filter Driver / qmofiltr][Running/Manual Start]
<system32\drivers\qmofiltr.sys><Quanta Computer, Inc.>
[RsFwDrv / RsFwDrv][Running/Auto Start]
<\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Running/Manual Start]
<system32\DRIVERS\Rtlnicxp.sys><Realtek Semiconductor Corporation>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[WLAN 传输 / s24trans][Stopped/Disabled]
<system32\DRIVERS\s24trans.sys><N/A>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[Virus Chaser System Monitor / SPIDERCTL][Stopped/Auto Start]
<\??\D:\程序\系统维护2007\Virus Chaser\spider.sys><New Technology Wave Inc.>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
<system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[Conexant Setup API / UIUSys][Stopped/Manual Start]
<system32\DRIVERS\UIUSYS.SYS><N/A>
[Intel(R) PRO/Wireless 3945ABG Adapter Driver / w39n51][Running/Manual Start]
<system32\DRIVERS\w39n51.sys><Intel? Corporation>
[winachsf / winachsf][Running/Manual Start]
<system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
[xFileMgr / xFileMgr][Running/System Start]
<\??\C:\WINDOWS\system32\Drivers\xFileMgr.sys><MS User>
[PCANDIS5 Protocol Driver / PCANDIS5][Running/Manual Start]
<\??\C:\WINDOWS\system32\PCANDIS5.SYS><Printing Communications Assoc., Inc. (PCAUSA)>
==================================
浏览器加载项
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[NavigatMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, >
[Java Plug-in 1.5.0_06]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll, Sun Microsystems, Inc.>
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[PGEdit Class]
{2BFAA61B-5C83-4865-8281-D8BDBF863061} <C:\WINDOWS\Downloaded Program Files\PG_ATL_Edit.dll, 银联网络支付集团有限公司>
[EditCtrl Class]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\aliedit.dll, >
[ThunderAtOnce Class]
{01443AEC-0FD1-40FD-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[IeHelper Class]
{0D42E1BD-09DD-4873-A826-9C7E793EB7B6} <C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DSIeHelper.dll, N/A>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Thunder Browser Helper]
{B69F34DC-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[NavigatMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, >
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Vod Class]
{EEDD6FF9-13DE-496B-9A1C-D78B3215E266} <C:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DapPlayer1.0.0.41.dll, XunLei>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
kouen1986 - 2007-7-1 21:02:00
==================================
正在运行的进程
[PID: 592][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 656][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[PID: 680][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\WgaLogon.dll] [Microsoft Corporation, 1.7.0018.5]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[PID: 724][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[PID: 736][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\DRWEBSP.DLL] [Doctor Web, Ltd., 4.33.0.09160]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[PID: 296][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.2.9]
[C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 3, 11]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 4]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.4436]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4436]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4436]
[C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3.0.0.4436]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4436]
[C:\Program Files\Unlocker\UnlockerCOM.dll] [N/A, ]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\ewido anti-spyware 4.0\context.dll] [Anti-Malware Development a.s., 4, 0, 0, 172]
[PID: 320][c:\program files\rising\rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 72]
[c:\program files\rising\rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[c:\program files\rising\rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[c:\program files\rising\rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[c:\program files\rising\rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[c:\program files\rising\rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[PID: 412][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3.0.0.4436]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4436]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4436]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4436]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[PID: 532][C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe] [Nokia, 6, 41, 22, 3]
[C:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll] [Nokia, 6, 41, 22, 0]
[C:\Program Files\Nokia\Nokia PC Suite 6\PCSL.dll] [Nokia, 6, 41, 3, 0]
[C:\Program Files\Nokia\Nokia PC Suite 6\Lang\LaunchApplication2_chi-sc.NLR] [, 6, 41, 4, 0]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[C:\Program Files\Common Files\PCSuite\ConfServer\ConfServer.dll] [Nokia, 6, 41, 6, 0]
[C:\WINDOWS\system32\msxml4.dll] [Microsoft Corporation, 4.20.9841.0]
[C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.5510]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[PID: 352][D:\程序\系统维护2007\qdf\Trojanwall.exe] [风云谷, 4.7.0.1405]
[D:\程序\系统维护2007\qdf\ftcapi.dll] [fygsoft, 1.1.0.0]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\DRWEBSP.DLL] [Doctor Web, Ltd., 4.33.0.09160]
[PID: 604][D:\程序\系统维护2007\Virus Chaser\Vcrmon.exe] [New Technology Wave Inc., 5, 0, 0, 101]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[PID: 844][C:\Program Files\360safe\safemon\360Tray.exe] [奇虎网, 1, 0, 1, 1004]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\360safe\safemon\SafeKrnl.dll] [奇虎网, 1, 0, 0, 3001]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[C:\Program Files\360safe\live.dll] [360safe.COM, 1, 0, 0, 1011]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\DRWEBSP.DLL] [Doctor Web, Ltd., 4.33.0.09160]
[PID: 1108][C:\Program Files\Unlocker\UnlockerAssistant.exe] [N/A, ]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[PID: 1160][C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5, 6, 7, 326]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Program Files\Thunder Network\Thunder\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 26]
[C:\Program Files\Thunder Network\Thunder\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 46]
[C:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031]
[C:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 46]
[C:\WINDOWS\system32\DRWEBSP.DLL] [Doctor Web, Ltd., 4.33.0.09160]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[C:\Program Files\Thunder Network\Thunder\Program\iTargetAD.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 28]
[C:\Program Files\Thunder Network\Thunder\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 1, 0, 8]
[C:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DownAndPlay.dll] [, 1, 0, 0, 18]
kouen1986 - 2007-7-1 21:02:00
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll] [ , 1, 0, 0, 19]
[C:\Program Files\Thunder Network\Thunder\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 1, 2, 1, 36]
[C:\Program Files\Thunder Network\Thunder\Components\Security\ThunderSafe.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 17]
[C:\Program Files\Thunder Network\Thunder\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 1, 4, 15]
[C:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll] [Thunder Networking Technologies,LTD, 2, 2, 2, 55]
[C:\Program Files\Thunder Network\Thunder\Program\LiveUpdate.dll] [Thunder Networking Technologies,LTD, 1, 2, 1, 20]
[C:\Program Files\Thunder Network\Thunder\Components\ExplorerHelper\ExplorerHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 15]
[C:\Program Files\Thunder Network\Thunder\Components\Tips\TipsClient.dll] [Thunder Networking Technologies,LTD, 2, 1, 3, 58]
[C:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VPSHELL.dll] [XunLei, 1, 2, 0, 10]
[C:\Program Files\Thunder Network\Thunder\Components\UserExperience\UserExperience.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsXlCom.dll] [, 1, 0, 0, 16]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed10.dll] [ , 3, 3, 1, 83]
[C:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 13, 4, 58]
[C:\Program Files\Thunder Network\Thunder\Program\MSVCIRT.dll] [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Thunder Network\Thunder\Program\XLNet.Dll] [Thunder Networking Technologies,LTD, 1, 2, 0, 8]
[C:\Program Files\Thunder Network\Thunder\Plugins\BhoAdv\bho_adv.dll] [深圳市迅雷网络技术有限公司, 1.0.1.0]
[C:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VideoPicture.dll] [XunLei, 1, 2, 0, 11]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\MediaWorker.dll] [Thunder Networking Technologies,LTD, 1, 2, 0, 18]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[PID: 1164][C:\Program Files\MSN Messenger\MsnMsgr.Exe] [Microsoft Corporation, 7.5.0324]
[C:\Program Files\MSN Messenger\msidcrl.dll] [Microsoft Corp., 3.200.60.1]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Program Files\MSN Messenger\MSGSLANG.DLL] [Microsoft Corporation, 7.5.0324]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[C:\WINDOWS\system32\DRWEBSP.DLL] [Doctor Web, Ltd., 4.33.0.09160]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[PID: 1192][C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe] [Time Information Services Ltd., 2.00 (406)]
[C:\Program Files\Nokia\Nokia PC Suite 6\PCSL.dll] [Nokia, 6, 41, 3, 0]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\Lang\PcSync2_chi-sc.nlr] [Time Information Services Ltd., 8.00 (406)]
[C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\Resource\PcSync2_Nokia.ngr] [Time Information Services Ltd., 8.00 (406)]
[C:\Program Files\Common Files\Nokia\Adapters\NclSet.dll] [Nokia, 6.41.5.0]
[C:\Program Files\Common Files\Nokia\Adapters\Nclaeo.dsc] [Nokia Mobile Phones Ltd., 4.00.008]
[C:\Program Files\Common Files\Nokia\MPAPI\MPAPIps.dll] [Nokia Corporation, 6.41.71.0]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[PID: 1272][C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE] [Nokia., 6, 41, 20, 0]
[C:\Program Files\Common Files\PCSuite\Transports\NCLIrDAMM.dll] [Nokia Corp., 6, 41, 11, 0]
[C:\Program Files\Common Files\PCSuite\Transports\NclTools.dll] [Nokia., 6, 41, 5, 1]
[C:\Program Files\Common Files\PCSuite\Transports\NclMSBTMM.dll] [Nokia., 6, 41, 17, 1]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[C:\Program Files\Common Files\PCSuite\Transports\NCLRSMM.dll] [Nokia, 6, 41, 15, 0]
[C:\Program Files\Common Files\PCSuite\Transports\NCLUSBMM.dll] [Nokia, 6, 41, 17, 0]
[C:\Program Files\Common Files\PCSuite\Services\NclDS.dll] [Nokia, 6, 41, 4, 0]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[PID: 1908][D:\程序\系统维护2007\Virus Chaser\spiderml.exe] [Doctor Web, Ltd., 4.33.0.09160]
[D:\程序\系统维护2007\Virus Chaser\vchaser.dll] [N/A, ]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[D:\程序\系统维护2007\Virus Chaser\drwspcnt.dll] [Doctor Web, Ltd., 4.33.0.09160]
[C:\WINDOWS\system32\DRWEBSP.DLL] [Doctor Web, Ltd., 4.33.0.09160]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[PID: 1920][C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe] [Nokia Corporation, 6.41.150.2]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[C:\Program Files\Common Files\Nokia\MPAPI\MPAPIps.dll] [Nokia Corporation, 6.41.71.0]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[PID: 160][C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE] [Nokia Mobile Phones Ltd., 6, 41, 85, 8]
[C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\Lang\DataLayer_chi-sc.nlr] [Nokia, 6, 41, 5, 0]
[C:\WINDOWS\system32\msxml4.dll] [Microsoft Corporation, 4.20.9841.0]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[PID: 2392][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[PID: 2228][C:\Program Files\锐捷网络\Ruijie Supplicant\8021x.exe] [锐捷网络, 2, 41, 0, 0]
[C:\WINDOWS\system32\W32N50.dll] [Printing Communications Assoc., Inc. (PCAUSA), 5.00.13.50]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[PID: 3016][C:\Program Files\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 6, 1, 50]
[C:\Program Files\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[C:\WINDOWS\system32\odbcbcp.dll] [Microsoft Corporation, 2000.085.1117.00 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 1.1.4322.2032]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CorperfmonExt.dll] [Microsoft Corporation, 1.1.4322.2032]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\PROGRA~1\COMMON~1\SYSTEM\MSMAPI\2052\MSMAPI32.DLL] [Microsoft Corporation, 11.0.5601]
[C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll] [Microsoft Corporation, 11.0.6568]
[C:\WINDOWS\system32\DRWEBSP.DLL] [Doctor Web, Ltd., 4.33.0.09160]
[C:\Program Files\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL] [Microsoft Corporation, 9.0.5510.0]
[PID: 2272][C:\Program Files\Rising\Rav\RsLogVw.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[C:\Program Files\Rising\Rav\RsCommx.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\rsguilib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[C:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
kouen1986 - 2007-7-1 21:03:00
[PID: 120][D:\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[D:\程序\系统维护2007\qdf\Filehook.dll] [Fygsoft and Microsoft, 2.0.0.0]
[C:\Program Files\360safe\safemon\safemon.dll] [, 1, 0, 0, 1004]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527]
[C:\WINDOWS\system32\DRWEBSP.DLL] [Doctor Web, Ltd., 4.33.0.09160]
[D:\Plugins\NWMON.SRE] [Smallfrogs Studio, 1, 0, 0, 8]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
DrwebSP.MSAFD Tcpip [TCP/IP]
C:\WINDOWS\system32\DRWEBSP.DLL(Doctor Web, Ltd., Dr.Web Winsock Provider Hook)
DrwebSP.MSAFD Tcpip [UDP/IP]
C:\WINDOWS\system32\DRWEBSP.DLL(Doctor Web, Ltd., Dr.Web Winsock Provider Hook)
DrwebSP.RSVP TCP Service Provider
C:\WINDOWS\system32\DRWEBSP.DLL(Doctor Web, Ltd., Dr.Web Winsock Provider Hook)
DrwebSP.RSVP UDP Service Provider
C:\WINDOWS\system32\DRWEBSP.DLL(Doctor Web, Ltd., Dr.Web Winsock Provider Hook)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
入口点错误:FreeLibrary (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0x5F00002D)
==================================
隐藏进程
N/A
==================================
[/CODE]
kouen1986 - 2007-7-1 21:10:00
日志就是以上这些,麻烦哪位高手帮帮忙,谢谢!
kouen1986 - 2007-7-1 21:28:00
拜托哪位高手帮忙看看,我的电脑现在已经慢得不行了,安全模式也进不去,谢谢~!
kouen1986 - 2007-7-1 22:06:00
拜托哪位高手帮忙看看,我的电脑现在已经慢得不行了,安全模式也进不去,谢谢~!
kouen1986 - 2007-7-1 22:42:00
拜托哪位高手帮忙看看,我的电脑现在已经慢得不行了,安全模式也进不去,谢谢~!
kouen1986 - 2007-7-2 8:22:00
拜托哪位高手帮忙看看,我的电脑现在已经慢得不行了,安全模式也进不去,谢谢~!
kouen1986 - 2007-7-2 15:06:00
拜托哪位高手帮忙看看,我的电脑现在已经慢得不行了,安全模式也进不去,谢谢~!
1
© 2000 - 2026 Rising Corp. Ltd.