瑞星卡卡安全论坛
神风拖拉机 - 2007-8-20 21:50:00
各位高手:
非常感谢您留心我这份系统诊断报告,小菜鸟十万火急等待您的帮助!
诊断时间: 2007-08-20 21:25:00
诊断平台: Microsoft Windows XP Service Pack 2
IE版本: Internet Explorer V6.0.2900.2180 Build:62900.2180
计算机物理内存:511.36MB - 当前可用内存:306.54MB
100 - 未知 - Process: smss.exe [Windows NT Session Manager] - C:\WINDOWS\System32\smss.exe
100 - 未知 - Process: csrss.exe [Client Server Runtime Process] - C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=base
100 - 未知 - Process: winlogon.exe [Windows NT Logon Application] - C:\WINDOWS\system32\winlogon.exe
100 - 未知 - Process: services.exe [Services and Controller app] - C:\WINDOWS\system32\services.exe
100 - 未知 - Process: lsass.exe [LSA Shell (Export Version)] - C:\WINDOWS\system32\lsass.exe
100 - 未知 - Process: ati2evxx.exe [] - C:\WINDOWS\system32\Ati2evxx.exe
100 - 未知 - Process: svchost.exe [Generic Host Process for Win32 Services] - C:\WINDOWS\system32\svchost -k DcomLaunch
100 - 未知 - Process: svchost.exe [Generic Host Process for Win32 Services] - C:\WINDOWS\system32\svchost -k rpcss
100 - 未知 - Process: CCenter.exe [CCenter] -
100 - 未知 - Process: MsMpEng.exe [Service Executable] - C:\Program Files\Windows Defender\MsMpEng.exe
100 - 未知 - Process: svchost.exe [Generic Host Process for Win32 Services] - C:\WINDOWS\System32\svchost.exe -k netsvcs
100 - 未知 - Process: svchost.exe [Generic Host Process for Win32 Services] - C:\WINDOWS\system32\svchost.exe -k NetworkService
100 - 未知 - Process: svchost.exe [Generic Host Process for Win32 Services] - C:\WINDOWS\system32\svchost.exe -k LocalService
100 - 未知 - Process: RavMonD.exe [RavMond] -
100 - 未知 - Process: ati2evxx.exe [] - C:\WINDOWS\system32\Ati2evxx.exe
100 - 未知 - Process: explorer.exe [Windows Explorer] - C:\WINDOWS\Explorer.EXE
100 - 未知 - Process: spoolsv.exe [Spooler SubSystem App] - C:\WINDOWS\system32\spoolsv.exe
100 - 未知 - Process: RavStub.exe [Rising RavStub] - C:\Program Files\Rising\Rav\RavStub.exe
100 - 未知 - Process: guard.exe [AVG Anti-Spyware guard] - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
100 - 未知 - Process: slserv.exe [User-Level Modem Service] - C:\WINDOWS\system32\slserv.exe
100 - 未知 - Process: svchost.exe [Generic Host Process for Win32 Services] - C:\WINDOWS\system32\svchost.exe -k imgsvc
100 - 未知 - Process: VStart.exe [音速启动 - 您的启动专家] - D:\音速启动\VStart.exe
100 - 未知 - Process: MemEmpty.exe [内存释放专家] - D:\MemEmpty.exe
100 - 未知 - Process: UnlockerAssistant.exe [] - C:\Program Files\Unlocker\UnlockerAssistant.exe
100 - 未知 - Process: RavTask.exe [RavTimer] -
100 - 未知 - Process: RavMon.exe [RavMon] -
100 - 未知 - Process: ctfmon.exe [CTF Loader] - C:\WINDOWS\system32\ctfmon.exe
100 - 未知 - Process: SSAAD.exe [SonicStage Atrac Hard Disk Monitor] - E:\sony\SsAAD.exe
100 - 未知 - Process: alg.exe [Application Layer Gateway Service] - C:\WINDOWS\System32\alg.exe
100 - 未知 - Process: TTraveler.exe [Tencent Traveler] - C:\Program Files\TT\TTraveler.exe
100 - 未知 - Process: Thunder5.exe [Thunder] - C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe
100 - 未知 - Process: orangeaug.com [RavOrangeAug] - C:\Documents and Settings\Administrator\桌面\orangeaug.com
100 - 未知 - Process: conime.exe [Console IME] - C:\WINDOWS\system32\conime.exe
100 - 未知 - Process: RsAgent.exe [RsAgent Application] - C:\Program Files\Rising\Rav\RsAgent.exe
100 - 未知 - Process: agentsvr.exe [Microsoft Agent Server] - C:\WINDOWS\msagent\AgentSvr.exe -Embedding
100 - 未知 - Process: iexplore.exe [Internet Explorer] - C:\Program Files\Internet Explorer\iexplore.exe
100 - 未知 - Process: Rav.exe [Rising Antivirus Main exe] -
100 - 未知 - Process: ScanBD.exe [ScanBD Application] - C:\Program Files\Rising\Rav\ScanBD.exe
100 - 未知 - Process: WinRAR.exe [] -
100 - 未知 - Process: 360安全卫士诊断工具.exe [诊断报告工具] - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX01.837\360安全卫士诊断工具.exe
R0 - 未知 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.hao123.com/
O2 - 未知 - BHO: (ThunderAtOnce Class) - [迅雷浏览器高级特性支持模块] - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll
O3 - 未知 - Toolbar: (第三方IE工具栏) - [无效的CLSID:{710EB7A1-45ED-11D0-924A-0020AFC7AC4D}] - {710EB7A1-45ED-11D0-924A-0020AFC7AC4D} -
O3 - 未知 - Toolbar: (第三方IE工具栏) - [无效的CLSID:{1E796980-9CC5-11D1-A83F-00C04FC99D61}] - {1E796980-9CC5-11D1-A83F-00C04FC99D61} -
O4 - 未知 - HKLM\..\Run: [MemEmpty] [内存释放专家] D:\\MemEmpty.exe /h
O4 - 未知 - HKLM\..\Run: [asgfdjs2] [] C:\WINDOWS\system32\vbsdaas2.exe
O4 - 未知 - HKLM\..\Run: [UnlockerAssistant] [] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O8 - 未知 - Extra context menu item: 使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\geturl.htm
O8 - 未知 - Extra context menu item: 使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm
O9 - 未知 - Extra button: 启动迅雷5(HKLM) - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - 未知 - Extra button: 浩方对战平台(HKLM) - C:\Program Files\浩方对战平台\GameClient.exe
O9 - 未知 - Extra button: 信息检索(HKLM) - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - 未知 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - 未知 - DPF: {2375BEE5-F175-4F1C-81EC-8E4E2E72E2DD} (PhotoDraw) - http://photo.qq.com/qzone_v4/QzoneMediaTools.cab
O16 - 未知 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (PasswordEditCtrl) - https://password.qq.com/download/qqedit2.cab
O18 - 未知 - Protocol: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC}
O21 - 未知 - Protocol Icons: HKCR\http\shell\open\command - "C:\Program Files\TT\TTraveler.exe" "%1"
O21 - 未知 - Protocol Icons: HKCR\ftp\shell\open\command - "C:\Program Files\TT\TTraveler.exe" "%1"
O21 - 未知 - Protocol Icons: HKCR\https\shell\open\command - "C:\Program Files\TT\TTraveler.exe" "%1"
O21 - 未知 - Protocol Icons: HKCR\htmlfile\shell\open\command - "C:\Program Files\TT\TTraveler.exe" "%1"
O23 - 未知 - Service: MSCSPTISRV [MSCSPTISRV] - "C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe" - (not running)
O23 - 未知 - Service: PACSPTISVR [PACSPTISVR] - "C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe" - (not running)
O23 - 未知 - Service: SLService [SmartLinkService] - slserv.exe - (running)
O23 - 未知 - Service: SPTISRV [Sony SPTI Service] - "C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe" - (not running)
O23 - 未知 - Service: SSScsiSV [SonicStage SCSI Service] - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe - (not running)
=======================================
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
神风拖拉机 - 2007-8-20 21:50:00
R1 - 安全 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm
O2 - 安全 - BHO: (Thunder Browser Helper) - [迅雷附带下载监视器相关文件。] - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll
O4 - 安全 - HKLM\..\Run: [VStart5.0] [一款音速启动程序。] D:\音速启动\VStart.exe
O4 - 安全 - HKLM\..\Run: [RavTask] [瑞星杀毒软件的任务计划程序。] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 安全 - HKLM\..\RunOnce: [RavStub] [是瑞星杀毒软件相关程序。] "C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE
O4 - 安全 - HKCU\..\Run: [ctfmon.exe] [office xp输入法图标。] C:\WINDOWS\system32\ctfmon.exe
O4 - 安全 - HKCU\..\Run: [SsAAD.exe] [索尼音乐管理软件相关程序。] E:\sony\SsAAD.exe
O4 - 安全 - Startup folder: [腾讯QQ.lnk] [qq:即时通讯软件] C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk
O8 - 安全 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O18 - 安全 - Protocol: OFFICE 相关 - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O23 - 安全 - Service: Ati HotKey Poller [ati显卡相关后台程序。] - C:\WINDOWS\system32\Ati2evxx.exe - (running)
O23 - 安全 - Service: AVG Anti-Spyware Guard [一款杀毒软件AVG的相关服务。] - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe - (running)
O23 - 安全 - Service: RsCCenter [是瑞星杀毒软件控制台相关程序。] - "C:\Program Files\Rising\Rav\CCenter.exe" - (running)
O23 - 安全 - Service: RsRavMon [是瑞星杀毒软件相关监控程序。] - "C:\Program Files\Rising\Rav\Ravmond.exe" - (running)
O23 - 安全 - Service: ServiceLayer [nokia手机软件的进程。] - "C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe" - (not running)
O23 - 安全 - Service: WinDefend [Windows Defender 自动保护服务的核心引擎,包括在Microsoft AntiSpywaresoftware的工具组件中。] - "C:\Program Files\Windows Defender\MsMpEng.exe" - (running)
=======================================
O31 - 未知 - Folder Menu: {F9DB5320-233E-11D1-9F84-707F02C10627} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll - Adobe Systems, Inc. - PDF Shell Extension - 7.0.0.0 - 110592 - 4b0991cd076b617a2231b19a6663c1c9
O31 - 未知 - SEApproved: {42071714-76d4-11d1-8b24-00a0c9068ff3} - deskpan.dll - - - - 0 -
O31 - 未知 - SEApproved: 无效的CLSID:Shell extensions for file compression - - - - - 0 -
O31 - 未知 - SEApproved: 无效的CLSID:加密上下文菜单 - - - - - 0 -
O31 - 未知 - SEApproved: {0DF44EAA-FF21-4412-828E-260A8728E7F1} - - - - - 0 -
O31 - 未知 - SEApproved: {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} - - - - - 0 -
O31 - 未知 - SEApproved: {7A9D77BD-5403-11d2-8785-2E0420524153} - - - - - 0 -
O31 - 未知 - SEApproved: 无效的CLSID:Shell Extensions for RealOne Player - - - - - 0 -
O31 - 未知 - SEApproved: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - C:\Program Files\WinRAR\rarext.dll - - - - 126464 - 1972f2dcc1f03adc7a6146ffe119d507
O31 - 未知 - SEApproved: 无效的CLSID:粉碎文件 - - - - - 0 -
O31 - 未知 - SEApproved: {6C125022-639D-43cc-9F3D-647E6CC69EF1} - C:\WINDOWS\ContextBG.dll - Grigri - Apply a background to the shell context menu - 1.0.0.1 - 249856 - 4b88c36895b16c76b19c5a9b62a55f3e
O31 - 未知 - SEApproved: {416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A} - C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll - Nokia - Phone Browser - 6.81.46.1 - 544768 - ee72989bdac20cc914adef6a7bceedb9
O31 - 未知 - SEApproved: {669751ED-D558-49AE-B01A-3B374CC7910E} - C:\WINDOWS\system32\ssup.dll - - - - 0 -
O31 - 未知 - SEApproved: {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} - C:\Program Files\Unlocker\UnlockerCOM.dll - - - - 8704 - de1d9412c60fccbab699bff3e58951f5
O31 - 未知 - SEApproved: {1C7593CB-C1CC-4BA7-BE52-8EEA47F9CB1D} - C:\WINDOWS\system32\RavExt.dll - Beijing Rising Technology Co., Ltd. - Rising Shell Ext Module - 19.0.0.9 - 106496 - fa20734a7acabcfe9d727fb343da4e8a
O31 - 未知 - Directory Menu: {8934FCEF-F5B8-468f-951F-78A921CD3920} - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll - Anti-Malware Development a.s. - Context-Menu (Shell Extension) - 7.5.0.47 - 98304 - 46077565f38707ae894eed58a11f613e
O31 - 未知 - Directory Menu: {1C7593CB-C1CC-4BA7-BE52-8EEA47F9CB1D} - C:\WINDOWS\system32\RavExt.dll - Beijing Rising Technology Co., Ltd. - Rising Shell Ext Module - 19.0.0.9 - 106496 - fa20734a7acabcfe9d727fb343da4e8a
O31 - 未知 - Directory Menu: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - C:\Program Files\WinRAR\rarext.dll - - - - 126464 - 1972f2dcc1f03adc7a6146ffe119d507
O31 - 未知 - BootExecute: bsmain - - - - 0 -
O31 - 未知 - BootExecute: - - - - 0 -
O31 - 未知 - LSA: Security Packages - sv1_0.dll - - - - 0 -
O31 - 未知 - LSA: Security Packages - channel.dll - - - - 0 -
=======================================
O40 - Explorer.EXE - Beijing Rising Technology Co., Ltd. - C:\WINDOWS\system32\RavExt.dll - Rising Shell Ext Module - fa20734a7acabcfe9d727fb343da4e8a
O40 - Explorer.EXE - Adobe Systems, Inc. - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll - PDF Shell Extension - 4b0991cd076b617a2231b19a6663c1c9
O40 - Explorer.EXE - Grigri - C:\WINDOWS\ContextBG.dll - Apply a background to the shell context menu - 4b88c36895b16c76b19c5a9b62a55f3e
O40 - Explorer.EXE - - C:\Program Files\Unlocker\UnlockerHook.dll - - 0be47e7f7d991b5a3e377407862d60c3
O40 - Explorer.EXE - - C:\Program Files\Unlocker\UnlockerCOM.dll - - de1d9412c60fccbab699bff3e58951f5
O40 - Explorer.EXE - - C:\Program Files\Tencent\QQ\qdshm.dll - QQDiskShellMenu Module - e7537ad41b93cfb161b60e18c2ddd075
O40 - Explorer.EXE - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\RSCOMMON.DLL - Rising Common Function Dynamic Link Library - 58432e6c58f1b4c339adc1a79bf864b6
O40 - Explorer.EXE - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll - Context-Menu (Shell Extension) - 46077565f38707ae894eed58a11f613e
=======================================
O41 - AVG Anti-Spyware Driver - AVG Anti-Spyware Driver - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys - (running) - - - 7d78b7fd0ebe00f177b053a08c78e35b
O41 - AvgAsCln - AVG7 Clean Driver - C:\WINDOWS\system32\drivers\AvgAsCln.sys - (running) - AVG7 Clean Driver - GRISOFT, s.r.o. - 6d4a1da6e6d522b3ebbcbff4a3589ec5
O41 - BaseTDI - basetdi - C:\WINDOWS\system32\drivers\basetdi.sys - (running) - basetdi - Beijing Rising Technology Co., Ltd. - 0064810c1b03f2c889130b669a4ce937
O41 - ExpScaner - ExpScan.sys - C:\Program Files\Rising\Rav\ExpScan.sys - (running) - ExpScan.sys - - 5a690926c7181d5c0b2721016442c9c3
O41 - HookCont - HookCont - C:\Program Files\Rising\Rav\HookCont.sys - (running) - HookCont - Rising - 3926cb7b005564bc77d6b40235c53817
O41 - HookReg - HookReg - C:\Program Files\Rising\Rav\HOOKREG.sys - (running) - - - 997c395147f8e5b3f714bdd112fe8945
O41 - HookSys - Hooksys - C:\Program Files\Rising\Rav\HookSys.sys - (running) - Hooksys - Rising - 265b67f85db6226f2439e13e7c1fa8bf
O41 - MEMSCAN - MemScan Driver - C:\Program Files\Rising\Rav\MemScan.sys - (running) - MemScan Driver - Beijing Rising Technology Co., Ltd. - a909256ef59a987fda249aa3ded01e76
O41 - npkcrypt - nProtect KeyCrypt Driver - C:\Program Files\QQ2006\npkcrypt.sys - (running) - nProtect KeyCrypt Driver - INCA Internet Co., Ltd. - 8bcb281a2540e7aff0cd00f9878fe21f
O41 - PxHelp20 - Px Engine Device Driver for Windows 2000/XP - C:\WINDOWS\system32\drivers\pxhelp20.sys - (running) - Px Engine Device Driver for Windows 2000/XP - Sonic Solutions - 86724469cd077901706854974cd13c3e
O41 - rcrbjjq - sys 应用程序 - C:\WINDOWS\system32\drivers\rcrbjjq.sys - (running) - sys 应用程序 - 北京三七二一科技有限公司 - 2df9912f08d1a95efb688bf841038632
O41 - RsNTGDI - RsNTGDI - C:\WINDOWS\system32\drivers\RsNTGdi.sys - (running) - RsNTGDI - Beijing Rising Technology Co., Ltd. - 17214e7b192cb93ff014fca1484b97ad
O41 - RSPPSYS - RSPPSYS.SYS - C:\Program Files\Rising\Rav\rsppsys.sys - (running) - RSPPSYS.SYS - Rising - f38c10d8c21626a4878ea16717e971fa
O41 - hwcdcmdm0 - USB Modem/Serial Device Driver - C:\WINDOWS\system32\drivers\ewusbmdm.sys - (not running) - USB Modem/Serial Device Driver - QUALCOMM Incorporated - 947c340b57bb7d7cf6345769044b3bbe
O41 - hwusbser - USB Modem/Serial Device Driver - C:\WINDOWS\system32\drivers\ewusbser.sys - (not running) - USB Modem/Serial Device Driver - QUALCOMM Incorporated - 947c340b57bb7d7cf6345769044b3bbe
O41 - NPF - npf - C:\WINDOWS\system32\drivers\npf.sys - (not running) - npf - CACE Technologies - d21fee8db254ba762656878168ac1db6
O41 - npkcusb - nProtect KeyCrypt Driver - C:\Program Files\QQ2006\npkcusb.sys - (not running) - nProtect KeyCrypt Driver - INCA Internet Co., Ltd. - 9d26933101f655f0d21118e561708239
O41 - SmartAVS - Smart Assistant Driver [CWJ] - C:\WINDOWS\system32\drivers\SmartAVS.sys - (not running) - Smart Assistant Driver [CWJ] - All-In-Smart [CWJ] - d46fc369a879b116925ab226f8c4008a
=======================================
我怀疑我中了帕虫病毒,但又不像,我一开机瑞星就伞就变红色了,360又打开不了,说什么出错了,终结者专杀工具V3也杀不出,用橙色八月也没有用,不知道怎么办好,按照网上的方法杀AV,在分区盘上单击鼠标右键——打开,看到每个盘跟目录下有 autorun.inf 和 sxs.exe 两个文件,将其删除。我也找不到这二个文件,放U盘进去后双击是不能打开的,要右键打开才行的,我电脑里好多公司的文件,不能格呀,谁能救我,我跪送10Q币!!~~~
神风拖拉机 - 2007-8-20 21:51:00
真的要帮忙,格机后没有资料后我会下岗的~~~就当可怜一下小弟吧!~
天月来了 - 2007-8-20 21:59:00
下载 System Repair Engineer(2.5版本),到你的“Windows”文件夹里。
http://www.kztechs.com/sreng/download.html
1 解压缩sreng2.zip
2 将SREngPs.exe运行.
3 智能扫描=》扫描=》保存报告
4 把日志中的报告文字内容完整复制分段贴上来,不要修改
神风拖拉机 - 2007-8-20 22:05:00
兄弟你怎么叫我怎么做,你等等,我就去办~~~~
为了饭碗我什么都不要了~~
神风拖拉机 - 2007-8-20 22:09:00
[CODE]
2007-08-20,21:55:08
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<SsAAD.exe><E:\sony\SsAAD.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<VStart5.0><D:\音速启动\VStart.exe> [3L软件工作室(3LSoft)]
<MemEmpty><D:\\MemEmpty.exe /h> [www.jpexe.com]
<asgfdjs2><C:\WINDOWS\system32\vbsdaas2.exe> [N/A]
<UnlockerAssistant><"C:\Program Files\Unlocker\UnlockerAssistant.exe"> []
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<RavStub><"C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
<{A3C95A74-638D-4C6B-A856-4B27664A7F47}><C:\WINDOWS\system32\wgdoor0.dll> []
<{6826A3DB-EA8E-4E67-880D-53D04C7C0BD8}><C:\WINDOWS\system32\qjdoor0.dll> []
<{EDFF29C1-5A70-4460-AC1D-16DCB4B672F0}><C:\WINDOWS\system32\rxdoor0.dll> []
<{68F7767A-090C-4BBF-A015-720ACC6706E2}><C:\WINDOWS\system32\wddoor0.dll> []
<{08E909A4-B236-48DD-8BCC-90A604B93E68}><C:\WINDOWS\system32\tldoor0.dll> []
<{D8CC4845-441C-44F8-9053-28F2EF67655B}><C:\WINDOWS\system32\dadoor0.dll> []
<{781FBCC1-99C7-4AE0-95F7-66EA49E86DD7}><C:\WINDOWS\system32\zxdoor0.dll> []
<{4E3FBFA4-F1CC-4B66-B333-B9F0FF4B4748}><C:\WINDOWS\system32\mydoor0.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<PHIME2002A><; > [N/A]
<PHIME2002ASync><; > [N/A]
神风拖拉机 - 2007-8-20 22:10:00
[CODE]
2007-08-20,21:55:08
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<SsAAD.exe><E:\sony\SsAAD.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<VStart5.0><D:\音速启动\VStart.exe> [3L软件工作室(3LSoft)]
<MemEmpty><D:\\MemEmpty.exe /h> [www.jpexe.com]
<asgfdjs2><C:\WINDOWS\system32\vbsdaas2.exe> [N/A]
<UnlockerAssistant><"C:\Program Files\Unlocker\UnlockerAssistant.exe"> []
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<RavStub><"C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
<{A3C95A74-638D-4C6B-A856-4B27664A7F47}><C:\WINDOWS\system32\wgdoor0.dll> []
<{6826A3DB-EA8E-4E67-880D-53D04C7C0BD8}><C:\WINDOWS\system32\qjdoor0.dll> []
<{EDFF29C1-5A70-4460-AC1D-16DCB4B672F0}><C:\WINDOWS\system32\rxdoor0.dll> []
<{68F7767A-090C-4BBF-A015-720ACC6706E2}><C:\WINDOWS\system32\wddoor0.dll> []
<{08E909A4-B236-48DD-8BCC-90A604B93E68}><C:\WINDOWS\system32\tldoor0.dll> []
<{D8CC4845-441C-44F8-9053-28F2EF67655B}><C:\WINDOWS\system32\dadoor0.dll> []
<{781FBCC1-99C7-4AE0-95F7-66EA49E86DD7}><C:\WINDOWS\system32\zxdoor0.dll> []
<{4E3FBFA4-F1CC-4B66-B333-B9F0FF4B4748}><C:\WINDOWS\system32\mydoor0.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<PHIME2002A><; > [N/A]
<PHIME2002ASync><; > [N/A]
==================================
启动文件夹
[腾讯QQ]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><N>
==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
<C:\WINDOWS\system32\Ati2evxx.exe><>
[AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Stopped/Auto Start]
<C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe><Anti-Malware Development a.s.>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe"><Macrovision Corporation>
[MSCSPTISRV / MSCSPTISRV][Stopped/Manual Start]
<"C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe"><Sony Corporation>
[PACSPTISVR / PACSPTISVR][Stopped/Manual Start]
<"C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe"><Sony Corporation>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon][Running/Auto Start]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[ServiceLayer / ServiceLayer][Stopped/Manual Start]
<"C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe"><Nokia.>
[SmartLinkService / SLService][Running/Auto Start]
<slserv.exe><>
[Sony SPTI Service / SPTISRV][Stopped/Manual Start]
<"C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe"><Sony Corporation>
[SonicStage SCSI Service / SSScsiSV][Stopped/Manual Start]
<C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe><Sony Corporation>
newcenturymoon - 2007-8-20 22:11:00
参考http://forum.ikaka.com/topic.asp?board=28&artid=8351280
神风拖拉机 - 2007-8-20 22:12:00
==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
<system32\drivers\ac97intc.sys><Intel Corporation>
[AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
<System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
[ati2mtag / ati2mtag][Running/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
<\??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys><N/A>
[AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
<System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
[BaseTDI / BaseTDI][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
[CONAN / CONAN][Running/Manual Start]
<system32\drivers\o2mmb.sys><O2 Micro>
[ExpScaner / ExpScaner][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
<system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[HookCont / HookCont][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HUAWEI Mobile Connect - 3G Modem / hwcdcmdm0][Stopped/Manual Start]
<system32\DRIVERS\ewusbmdm.sys><QUALCOMM Incorporated>
[HUAWEI Mobile Connect - 3G Application Interface / hwusbser][Stopped/Manual Start]
<system32\DRIVERS\ewusbser.sys><QUALCOMM Incorporated>
[MbxStby / MbxStby][Running/Manual Start]
<system32\drivers\MbxStby.sys><O2 Micro>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><Beijing Rising Technology Co., Ltd.>
[Mtlmnt5 / Mtlmnt5][Running/Manual Start]
<system32\DRIVERS\Mtlmnt5.sys><>
[Mtlstrm / Mtlstrm][Stopped/Manual Start]
<system32\DRIVERS\Mtlstrm.sys><>
[Nokia USB Generic / Nokia USB Generic][Stopped/Manual Start]
<system32\drivers\nmwcdc.sys><Nokia>
[Nokia USB Modem / Nokia USB Modem][Stopped/Manual Start]
<system32\drivers\nmwcdcm.sys><Nokia>
[Nokia USB Phone Parent / Nokia USB Phone Parent][Stopped/Manual Start]
<system32\drivers\nmwcd.sys><Nokia>
[Nokia USB Port / Nokia USB Port][Stopped/Manual Start]
<system32\drivers\nmwcdcj.sys><Nokia>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
<system32\drivers\npf.sys><CACE Technologies>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\C:\Program Files\QQ2006\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkcusb / npkcusb][Stopped/Manual Start]
<\??\C:\Program Files\QQ2006\npkcusb.sys><INCA Internet Co., Ltd.>
[NtMtlFax / NtMtlFax][Stopped/Manual Start]
<system32\DRIVERS\NtMtlFax.sys><>
[nv / nv][Stopped/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[rcrbjjq / rcrbjjq][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\rcrbjjq.sys><N/A>
[RecAgent / RecAgent][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\RecAgent.sys><>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver / RTL8023xp][Running/Manual Start]
<system32\DRIVERS\Rtlnicxp.sys><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[SmartLink AMR_PCI Driver / Slntamr][Running/Manual Start]
<system32\DRIVERS\slntamr.sys><>
[SlNtHal / SlNtHal][Stopped/Manual Start]
<system32\DRIVERS\Slnthal.sys><>
[SlWdmSup / SlWdmSup][Running/Manual Start]
<system32\DRIVERS\SlWdmSup.sys><>
[SmartAVS / SmartAVS][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\SmartAVS.sys><All-In-Smart [CWJ]>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
<system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[Vinyl AC'97 Audio Controller (WDM) / VIAudio][Running/Manual Start]
<system32\drivers\vinyl97.sys><VIA Technologies, Inc.>
==================================
浏览器加载项
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[浩方对战平台]
{0A155D3C-68E2-4215-A47A-E800A446447A} <C:\Program Files\浩方对战平台\GameClient.exe, 上海浩方在线信息技术有限公司>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft Corporation>
[PhotoDraw Class]
{2375BEE5-F175-4F1C-81EC-8E4E2E72E2DD} <C:\WINDOWS\system32\QQPhotoDraw.dll, TENCENT>
[PasswordEditCtrl Class]
{E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[ThunderAtOnce Class]
{01443AEC-0FD1-40FD-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, N/A>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[IETag Factory]
{38481807-CA0E-42D2-BF39-B33AF135CC4D} <C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\IETAG.DLL, Microsoft Corporation>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[WangWangObj Class]
{6E213FC7-DD5A-4115-B7E6-D4C7838C361E} <C:\Program Files\Alisoft\WangWang\WangWangX4.dll, 阿里软件(中国)有限公司>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[RMGetLicense Class]
{A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation>
[WebVGPlayer Class]
{AA899B43-24BD-4B6B-BBD0-45557D8D11E0} <C:\PROGRA~1\VIEWGOOD\WEBPLA~1\VGPlayer.dll, >
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\Mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[]
{C1626E66-C26B-C628-E1DF-CDACCFA26EE1} <C:\Program Files\Common Files\goskdl.dll, Microsoft Corporation>
[AUDIO__X_MS_WMA Moniker Class]
{CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[Vod Class]
{EEDD6FF9-13DE-496B-9A1C-D78B3215E266} <C:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DapPlayer1.0.0.41.dll, XunLei>
[使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
==================================
神风拖拉机 - 2007-8-20 22:14:00
正在运行的进程
[PID: 464 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 528 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 556 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Ati2evxx.dll] [, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 600 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 612 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 768 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [, ]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2494]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 780 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 844 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 952 / SYSTEM][RsHide] [N/A, ]
[PID: 968 / SYSTEM][C:\Program Files\Windows Defender\MsMpEng.exe] [Microsoft Corporation, 1.1.1593.0]
[C:\Program Files\Windows Defender\MpSvc.dll] [Microsoft Corporation, 1.1.1593.0]
[C:\Program Files\Windows Defender\MpClient.dll] [Microsoft Corporation, 1.1.1593.0]
[C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{56D4D67C-38B1-4D4D-9FF6-4F2D00CBECB3}\mpengine.dll] [Microsoft Corporation, 1.1.2803.0]
[C:\Program Files\Windows Defender\mprtplug.dll] [Microsoft Corporation, 1.1.1593.0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1024 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1112 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1220 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1256 / SYSTEM][RsHide] [N/A, ]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\rfwctrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[C:\Program Files\Rising\Rav\RsPPsys.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RsLog.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\HOOKSYS.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
[C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[C:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[C:\Program Files\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[C:\Program Files\Rising\Rav\regmon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\psapi.dll] [Microsoft Corporation, 4.00]
[C:\Program Files\Rising\Rav\HookWeb.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[C:\Program Files\Rising\Rav\MemMon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 14]
[C:\Program Files\Rising\Rav\expscan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[C:\Program Files\Rising\Rav\HookCont.dll] [Rising, 19, 0, 0, 0]
[C:\Program Files\Rising\Rav\SpamEng.dll] [, 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\engine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 30]
[C:\Program Files\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[C:\Program Files\Rising\Rav\ExtFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
[C:\Program Files\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 78]
[C:\Program Files\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[C:\Program Files\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
[C:\Program Files\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[C:\Program Files\Rising\Rav\ScanPack.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 24]
[C:\Program Files\Rising\Rav\RsVM.dll] [, 19, 0, 0, 20]
[C:\Program Files\Rising\Rav\Uroutine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 53]
[C:\Program Files\Rising\Rav\Uscript.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[C:\Program Files\Rising\Rav\ExtOLE.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
[C:\Program Files\Rising\Rav\ScanNet.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\ExtMail.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
[PID: 1368 / Administrator][C:\WINDOWS\system32\Ati2evxx.exe] [, ]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2494]
神风拖拉机 - 2007-8-20 22:15:00
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1440 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\WINDOWS\ContextBG.dll] [Grigri, 1, 0, 0, 1]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Unlocker\UnlockerCOM.dll] [N/A, ]
[C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll] [Anti-Malware Development a.s., 7, 5, 0, 47]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\Program Files\Common Files\goskdl.dll] [Microsoft Corporation, 1. 0. 0. 1]
[C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll] [Nokia, 6, 81, 46, 1]
[C:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll] [Nokia, 6, 81, 68, 0]
[C:\WINDOWS\system32\ConnAPI.DLL] [Nokia., 6, 81, 62, 0]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_chi-sc.nlr] [Nokia, 6, 81, 29, 0]
[C:\Program Files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr] [Nokia, 6, 81, 11, 0]
[C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.2.9]
[C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 3, 11]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 4]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\wgdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\qjdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\rxdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\wddoor0.dll] [N/A, ]
[C:\WINDOWS\system32\tldoor0.dll] [N/A, ]
[C:\WINDOWS\system32\dadoor0.dll] [N/A, ]
[C:\WINDOWS\system32\zxdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\mydoor0.dll] [N/A, ]
[C:\WINDOWS\system32\qhdoor0.dll] [N/A, ]
[PID: 1576 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1740 / SYSTEM][RsHide] [N/A, ]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 172 / SYSTEM][C:\WINDOWS\system32\slserv.exe] [ , 2.80.00(24Apr2000)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 240 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1052 / Administrator][D:\音速启动\VStart.exe] [3L软件工作室(3LSoft), 5.23.0020]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9782]
[C:\WINDOWS\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[C:\WINDOWS\COMCTL32.OCX] [Microsoft Corporation, 6.00.8105]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1132 / Administrator][D:\MemEmpty.exe] [www.jpexe.com, 1.00]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9782]
[C:\WINDOWS\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1100 / Administrator][C:\Program Files\Unlocker\UnlockerAssistant.exe] [N/A, ]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
神风拖拉机 - 2007-8-20 22:15:00
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1440 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\WINDOWS\ContextBG.dll] [Grigri, 1, 0, 0, 1]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Unlocker\UnlockerCOM.dll] [N/A, ]
[C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll] [Anti-Malware Development a.s., 7, 5, 0, 47]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\Program Files\Common Files\goskdl.dll] [Microsoft Corporation, 1. 0. 0. 1]
[C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll] [Nokia, 6, 81, 46, 1]
[C:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll] [Nokia, 6, 81, 68, 0]
[C:\WINDOWS\system32\ConnAPI.DLL] [Nokia., 6, 81, 62, 0]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_chi-sc.nlr] [Nokia, 6, 81, 29, 0]
[C:\Program Files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr] [Nokia, 6, 81, 11, 0]
[C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.2.9]
[C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 3, 11]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 4]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\wgdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\qjdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\rxdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\wddoor0.dll] [N/A, ]
[C:\WINDOWS\system32\tldoor0.dll] [N/A, ]
[C:\WINDOWS\system32\dadoor0.dll] [N/A, ]
[C:\WINDOWS\system32\zxdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\mydoor0.dll] [N/A, ]
[C:\WINDOWS\system32\qhdoor0.dll] [N/A, ]
[PID: 1576 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1740 / SYSTEM][RsHide] [N/A, ]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 172 / SYSTEM][C:\WINDOWS\system32\slserv.exe] [ , 2.80.00(24Apr2000)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 240 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1052 / Administrator][D:\音速启动\VStart.exe] [3L软件工作室(3LSoft), 5.23.0020]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9782]
[C:\WINDOWS\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[C:\WINDOWS\COMCTL32.OCX] [Microsoft Corporation, 6.00.8105]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1132 / Administrator][D:\MemEmpty.exe] [www.jpexe.com, 1.00]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9782]
[C:\WINDOWS\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1100 / Administrator][C:\Program Files\Unlocker\UnlockerAssistant.exe] [N/A, ]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
神风拖拉机 - 2007-8-20 22:16:00
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1440 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\WINDOWS\ContextBG.dll] [Grigri, 1, 0, 0, 1]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Unlocker\UnlockerCOM.dll] [N/A, ]
[C:\Program Files\Tencent\QQ\qdshm.dll] [, 1, 0, 101, 20]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll] [Anti-Malware Development a.s., 7, 5, 0, 47]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\Program Files\Common Files\goskdl.dll] [Microsoft Corporation, 1. 0. 0. 1]
[C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll] [Nokia, 6, 81, 46, 1]
[C:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll] [Nokia, 6, 81, 68, 0]
[C:\WINDOWS\system32\ConnAPI.DLL] [Nokia., 6, 81, 62, 0]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_chi-sc.nlr] [Nokia, 6, 81, 29, 0]
[C:\Program Files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr] [Nokia, 6, 81, 11, 0]
[C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.2.9]
[C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 3, 11]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 4]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\wgdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\qjdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\rxdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\wddoor0.dll] [N/A, ]
[C:\WINDOWS\system32\tldoor0.dll] [N/A, ]
[C:\WINDOWS\system32\dadoor0.dll] [N/A, ]
[C:\WINDOWS\system32\zxdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\mydoor0.dll] [N/A, ]
[C:\WINDOWS\system32\qhdoor0.dll] [N/A, ]
[PID: 1576 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1740 / SYSTEM][RsHide] [N/A, ]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 172 / SYSTEM][C:\WINDOWS\system32\slserv.exe] [ , 2.80.00(24Apr2000)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 240 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1052 / Administrator][D:\音速启动\VStart.exe] [3L软件工作室(3LSoft), 5.23.0020]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9782]
[C:\WINDOWS\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[C:\WINDOWS\COMCTL32.OCX] [Microsoft Corporation, 6.00.8105]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1132 / Administrator][D:\MemEmpty.exe] [www.jpexe.com, 1.00]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9782]
[C:\WINDOWS\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1100 / Administrator][C:\Program Files\Unlocker\UnlockerAssistant.exe] [N/A, ]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
神风拖拉机 - 2007-8-20 22:16:00
[PID: 1188 / Administrator][RsHide] [N/A, ]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[PID: 1232 / Administrator][RsHide] [N/A, ]
[C:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 1284 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[PID: 1296 / Administrator][E:\sony\SsAAD.exe] [, 4.0.00.05080]
[E:\sony\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[E:\sony\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[E:\sony\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1496 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 2496 / Administrator][C:\Program Files\TT\TTraveler.exe] [腾讯公司, 3, 3, 200, 290]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Program Files\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll] [腾讯公司, 1, 1, 0, 5]
[C:\Program Files\TT\Plugins\TWeather\TWeather.dll] [, 1, 0, 0, 3]
[C:\Program Files\TT\TTNetFavor.dll] [N/A, ]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\WINDOWS\system32\WINABCX.IME] [PKUETI, 5.22.216]
[C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]
[PID: 2664 / Administrator][C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5, 6, 7, 326]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Program Files\Thunder Network\Thunder\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 1, 2, 26]
[C:\Program Files\Thunder Network\Thunder\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 46]
[C:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031]
[C:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 46]
[C:\Program Files\Thunder Network\Thunder\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 1, 0, 8]
[C:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DownAndPlay.dll] [, 1, 0, 0, 18]
[C:\Program Files\Thunder Network\Thunder\Program\iTargetAD.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 28]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll] [ , 1, 0, 0, 19]
[C:\Program Files\Thunder Network\Thunder\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 1, 2, 1, 36]
[C:\Program Files\Thunder Network\Thunder\Components\Security\ThunderSafe.dll] [深圳市迅雷网络技术有限公司, 1, 0, 2, 17]
[C:\Program Files\Thunder Network\Thunder\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 1, 4, 15]
[C:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll] [Thunder Networking Technologies,LTD, 2, 2, 2, 55]
[C:\Program Files\Thunder Network\Thunder\Program\LiveUpdate.dll] [Thunder Networking Technologies,LTD, 1, 2, 1, 20]
[C:\Program Files\Thunder Network\Thunder\Components\ExplorerHelper\ExplorerHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 15]
[C:\Program Files\Thunder Network\Thunder\Components\Tips\TipsClient.dll] [Thunder Networking Technologies,LTD, 2, 1, 3, 58]
[C:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VPSHELL.dll] [XunLei, 1, 2, 0, 10]
[C:\Program Files\Thunder Network\Thunder\Components\UserExperience\UserExperience.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsXlCom.dll] [, 1, 0, 0, 16]
[C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed10.dll] [ , 3, 3, 1, 83]
[C:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 13, 4, 58]
[C:\Program Files\Thunder Network\Thunder\Program\MSVCIRT.dll] [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Thunder Network\Thunder\Program\XLNet.Dll] [Thunder Networking Technologies,LTD, 1, 2, 0, 8]
[C:\Program Files\Thunder Network\Thunder\Plugins\BhoAdv\bho_adv.dll] [深圳市迅雷网络技术有限公司, 1.0.1.0]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VideoPicture.dll] [XunLei, 1, 2, 0, 11]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\MediaWorker.dll] [Thunder Networking Technologies,LTD, 1, 2, 0, 18]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 3968 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1684 / Administrator][RsHide] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[PID: 380 / Administrator][RsHide] [N/A, ]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 4072 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.2.9]
[C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 3, 11]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 4]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\WINABCX.IME] [PKUETI, 5.22.216]
[C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]
[C:\WINDOWS\system32\rxdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\qjdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\wgdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\zxdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\dadoor0.dll] [N/A, ]
[C:\WINDOWS\system32\tldoor0.dll] [N/A, ]
[C:\WINDOWS\system32\wddoor0.dll] [N/A, ]
[C:\WINDOWS\system32\mydoor0.dll] [N/A, ]
[C:\WINDOWS\system32\qhdoor0.dll] [N/A, ]
[PID: 2364 / Administrator][RsHide] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\Program Files\Rising\Rav\PlugIn\RsPgScan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 17]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RavUI.Dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 30]
[C:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
神风拖拉机 - 2007-8-20 22:16:00
, 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 3064 / Administrator][C:\Program Files\Rising\Rav\ScanBD.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\Program Files\Rising\Rav\RsCommx.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\BDEngine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
[C:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[C:\Program Files\Rising\Rav\BDEX.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 3]
[C:\Program Files\Rising\Rav\BDLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 1]
[PID: 2236 / Administrator][C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe] [Anti-Malware Development a.s., 7, 5, 0, 47]
[C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll] [Anti-Malware Development a.s., 4, 2, 0, 15]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\qhdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\mydoor0.dll] [N/A, ]
[C:\WINDOWS\system32\zxdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\dadoor0.dll] [N/A, ]
[C:\WINDOWS\system32\tldoor0.dll] [N/A, ]
[C:\WINDOWS\system32\wddoor0.dll] [N/A, ]
[C:\WINDOWS\system32\rxdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\qjdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\wgdoor0.dll] [N/A, ]
[PID: 3476 / Administrator][C:\Program Files\TTPlayer\TTPlayer.exe] [Alen Soft, 4, 6, 9, 0]
[C:\Program Files\TTPlayer\ttpcomm.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Program Files\TTPlayer\ttpres.dll] [Alen Soft, 4, 6, 9, 0]
[C:\Program Files\TTPlayer\msdmo.dll] [Microsoft Corporation, 6.03.01.0400]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2264 / Administrator][C:\Documents and Settings\Administrator\桌面\SREngPS\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Documents and Settings\Administrator\桌面\SREngPS\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[C:\WINDOWS\system32\wgdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\qjdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\rxdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\wddoor0.dll] [N/A, ]
[C:\WINDOWS\system32\tldoor0.dll] [N/A, ]
[C:\WINDOWS\system32\dadoor0.dll] [N/A, ]
[C:\WINDOWS\system32\zxdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\mydoor0.dll] [N/A, ]
[C:\WINDOWS\system32\qhdoor0.dll] [N/A, ]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1052, D:\音速启动\VSTART.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1132, D:\MEMEMPTY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1132, D:\MEMEMPTY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1100, C:\PROGRAM FILES\UNLOCKER\UNLOCKERASSISTANT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1188, C:\WINDOWS\RSHIDE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1232, C:\WINDOWS\RSHIDE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1296, E:\SONY\SSAAD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2496, C:\PROGRAM FILES\TT\TTRAVELER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2664, C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\THUNDER5.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1684, C:\WINDOWS\RSHIDE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 380, C:\WINDOWS\RSHIDE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2364, C:\WINDOWS\RSHIDE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3064, C:\PROGRAM FILES\RISING\RAV\SCANBD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2236, C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3476, C:\PROGRAM FILES\TTPLAYER\TTPLAYER.EXE]
==================================
API HOOK
入口点错误:RegCreateKeyExA (危险等级: 高, 被下面模块所HOOK: 0x00E81FE5)
入口点错误:RegCreateKeyExW (危险等级: 高, 被下面模块所HOOK: 0x00E820B5)
入口点错误:Process32NextW (危险等级: 高, 被下面模块所HOOK: 0x00E83865)
入口点错误:Module32FirstW (危险等级: 高, 被下面模块所HOOK: 0x00E83905)
入口点错误:TerminateProcess (危险等级: 高, 被下面模块所HOOK: 0x00E84055)
入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: 0x00E82185)
入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: 0x00E82255)
入口点错误:FindWindowA (危险等级: 高, 被下面模块所HOOK: 0x00E839D5)
入口点错误:FindWindowExA (危险等级: 高, 被下面模块所HOOK: 0x00E83B75)
入口点错误:FindWindowExW (危险等级: 高, 被下面模块所HOOK: 0x00E83C45)
入口点错误:FindWindowW (危险等级: 高, 被下面模块所HOOK: 0x00E83AA5)
入口点错误:SendMessageA (危险等级: 高, 被下面模块所HOOK: 0x00E83D15)
入口点错误:SendMessageW (危险等级: 高, 被下面模块所HOOK: 0x00E83DE5)
==================================
隐藏进程
N/A
==================================
[/CODE]
神风拖拉机 - 2007-8-20 22:19:00
天月来了,我传日志上去了,帮我看看,怎么杀了~我请你喝茶
天月来了 - 2007-8-20 22:30:00
说说电脑哪里异常,杀毒软件是否杀出病毒,病毒的文件名,路径。
超级游戏迷 - 2007-8-20 22:34:00
seawave - 2007-8-20 22:44:00
老大,你的是电脑还是百宝箱,先赶快报有用的东西备份出来,这是首要的,把瑞星安装文件和升级包全部放到桌面,进安全模式查吧
神风拖拉机 - 2007-8-20 22:45:00
今晚杀到几个:
Trojan.psw.Win32.Wowar.tt
Backdoor.Win32.Gpigeon.abp
adware.Win32.Adpop.a
trojan.DL.QQhelper.ee
神风拖拉机 - 2007-8-20 22:48:00
我的电脑是用不了360,瑞星,U盘双击开不了,瑞星一开机就是红色的伞,受不了,只有AVG用得了~
天月来了 - 2007-8-20 22:50:00
参考他们建议的贴里的处理病毒的方法,清理下面你的日志里显示的病毒异常项。
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<asgfdjs2><C:\WINDOWS\system32\vbsdaas2.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{A3C95A74-638D-4C6B-A856-4B27664A7F47}><C:\WINDOWS\system32\wgdoor0.dll> []
<{6826A3DB-EA8E-4E67-880D-53D04C7C0BD8}><C:\WINDOWS\system32\qjdoor0.dll> []
<{EDFF29C1-5A70-4460-AC1D-16DCB4B672F0}><C:\WINDOWS\system32\rxdoor0.dll> []
<{68F7767A-090C-4BBF-A015-720ACC6706E2}><C:\WINDOWS\system32\wddoor0.dll> []
<{08E909A4-B236-48DD-8BCC-90A604B93E68}><C:\WINDOWS\system32\tldoor0.dll> []
<{D8CC4845-441C-44F8-9053-28F2EF67655B}><C:\WINDOWS\system32\dadoor0.dll> []
<{781FBCC1-99C7-4AE0-95F7-66EA49E86DD7}><C:\WINDOWS\system32\zxdoor0.dll> []
<{4E3FBFA4-F1CC-4B66-B333-B9F0FF4B4748}><C:\WINDOWS\system32\mydoor0.dll> []
==================================
浏览器加载项
[]
{C1626E66-C26B-C628-E1DF-CDACCFA26EE1} <C:\Program Files\Common Files\goskdl.dll, Microsoft Corporation>
==================================
正在运行的进程
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv10.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\Program Files\Common Files\goskdl.dll] [Microsoft Corporation, 1. 0. 0. 1]
[C:\WINDOWS\system32\wgdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\qjdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\rxdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\wddoor0.dll] [N/A, ]
[C:\WINDOWS\system32\tldoor0.dll] [N/A, ]
[C:\WINDOWS\system32\dadoor0.dll] [N/A, ]
[C:\WINDOWS\system32\zxdoor0.dll] [N/A, ]
[C:\WINDOWS\system32\mydoor0.dll] [N/A, ]
[C:\WINDOWS\system32\qhdoor0.dll] [N/A, ]
——————————————————————————————————————
只有以下项目,你可以在清理以上项目以后,在扫日志的SRENG工具中的:启动项目》服务》驱动程序》修改下面启动类型为“Disabled”
驱动程序
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
<system32\drivers\npf.sys><CACE Technologies>
[NtMtlFax / NtMtlFax][Stopped/Manual Start]
<system32\DRIVERS\NtMtlFax.sys><>
[rcrbjjq / rcrbjjq][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\rcrbjjq.sys><N/A>
神风拖拉机 - 2007-8-20 22:56:00
这么深奥,我那里会,能不能简单一点~~
我刚才重启了一下机子,发现了二个病毒,
TROJAN.PSW.WIN32
TROJAN.PSW.OXXX(看不到)
现在还在杀,一直用瑞星在杀,在发现,不能停的,杀了十分钟了,我不知道怎么办好,现在还在杀这二个病毒,真的是不能停的~~
xiaoshzi - 2007-8-20 23:09:00
你电脑里有什么重要的东西不能恢复啊,只要你做过备份,什么数据都可以恢复的
神风拖拉机 - 2007-8-20 23:10:00
我什么东西做备份呢??平时我见瑞星时不时帮我做备份的,但我不知道怎么把做好的备份的东西引出来!!!
天月来了 - 2007-8-20 23:16:00
重启计算机 进入
安全模式下(开机后不断 按F8键 然后出来一个高级菜单 选择第一项 安全模式 进入系统)
进安全模式下,将这文件删除,如不能删除,可以改名。
C:\Program Files\Common Files\goskdl.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\rsv10.tmp
重启电脑,仍然进安全模式下。
你先用日志的SRENG工具处理一下吧。
在扫日志的SRENG工具中的:启动项目》注册表》删除下面:
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<asgfdjs2><C:\WINDOWS\system32\vbsdaas2.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{A3C95A74-638D-4C6B-A856-4B27664A7F47}><C:\WINDOWS\system32\wgdoor0.dll> []
<{6826A3DB-EA8E-4E67-880D-53D04C7C0BD8}><C:\WINDOWS\system32\qjdoor0.dll> []
<{EDFF29C1-5A70-4460-AC1D-16DCB4B672F0}><C:\WINDOWS\system32\rxdoor0.dll> []
<{68F7767A-090C-4BBF-A015-720ACC6706E2}><C:\WINDOWS\system32\wddoor0.dll> []
<{08E909A4-B236-48DD-8BCC-90A604B93E68}><C:\WINDOWS\system32\tldoor0.dll> []
<{D8CC4845-441C-44F8-9053-28F2EF67655B}><C:\WINDOWS\system32\dadoor0.dll> []
<{781FBCC1-99C7-4AE0-95F7-66EA49E86DD7}><C:\WINDOWS\system32\zxdoor0.dll> []
<{4E3FBFA4-F1CC-4B66-B333-B9F0FF4B4748}><C:\WINDOWS\system32\mydoor0.dll> []
——————————————————————————————————————————
在扫日志的SRENG工具中的:系统修复》浏览器加载项》删除下面:
浏览器加载项
[]
{C1626E66-C26B-C628-E1DF-CDACCFA26EE1} <C:\Program Files\Common Files\goskdl.dll, Microsoft Corporation>
———————————————————————————————————————————
重启电脑,删除下面文件。
C:\Documents and Settings\Administrator\Local Settings\Temp\rsv10.tmp
C:\Program Files\Common Files\goskdl.dll
C:\WINDOWS\system32\wgdoor0.dll
C:\WINDOWS\system32\qjdoor0.dll
C:\WINDOWS\system32\rxdoor0.dll
[C:\WINDOWS\system32\wddoor0.dll
C:\WINDOWS\system32\tldoor0.dll
C:\WINDOWS\system32\dadoor0.dll
C:\WINDOWS\system32\zxdoor0.dll
C:\WINDOWS\system32\mydoor0.dll
C:\WINDOWS\system32\qhdoor0.dll
——————————————————————————————————————
在扫日志的SRENG工具中的:启动项目》服务》驱动程序》修改下面启动类型为“Disabled”
驱动程序
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
<system32\drivers\npf.sys><CACE Technologies>
[NtMtlFax / NtMtlFax][Stopped/Manual Start]
<system32\DRIVERS\NtMtlFax.sys><>
[rcrbjjq / rcrbjjq][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\rcrbjjq.sys><N/A>
————————————————————————————————————————
重启电脑,看有无异常,没有异常,就升级杀软至最新版本,全盘杀毒。
还有异常,就再扫日志。
天月来了 - 2007-8-20 23:19:00
照着他们建议的贴,慢慢做吧。
不然没人帮得了你了。要不你求7楼的版主给你远程清理吧。
1
© 2000 - 2026 Rising Corp. Ltd.