瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 快要被cn911.exe折腾死了,救命啊【求助】(扫描结果已粘贴)

12345   2  /  5  页   跳转

快要被cn911.exe折腾死了,救命啊【求助】(扫描结果已粘贴)

[C:\Program Files\CheckPoint\SecuRemote\bin\cpP11Modules.dll]  [Check Point Software Technologies, 59,8,000,013]
    [C:\Program Files\CheckPoint\SecuRemote\bin\exm_objlib.dll]  [Check Point Software Technologies, 54,8,2000,03]
    [C:\Program Files\CheckPoint\SecuRemote\bin\ocsp_usersr.dll]  [Check Point Software Technologies, 59,8,0010,00]
    [C:\Program Files\CheckPoint\SecuRemote\bin\srcln_usersr.dll]  [Check Point Software Technologies, 59,8,0010,00]
    [C:\Program Files\CheckPoint\SecuRemote\bin\vpninfo_usersr.dll]  [Check Point Software Technologies, 59,8,0010,00]
    [C:\Program Files\CheckPoint\SecuRemote\bin\cpstatlib.dll]  [Check Point Software Technologies, 54,8,2000,07]
    [C:\Program Files\CheckPoint\SecuRemote\bin\cpstatreg.dll]  [Check Point Software Technologies, 54,8,2000,07]
    [C:\Program Files\CheckPoint\SecuRemote\bin\cpdag.dll]  [Check Point Software Technologies, 54,8,2000,26]
    [C:\Program Files\CheckPoint\SecuRemote\bin\IkeStatus.dll]  [Check Point Software Technologies, 59,8,0010,05]
    [C:\Program Files\CheckPoint\SecuRemote\bin\ReportDT.dll]  [Check Point Software Technologies, 59,8,0010,05]
    [C:\Program Files\CheckPoint\SecuRemote\bin\tunnel_test_usersr.dll]  [Check Point Software Technologies, 59,8,0010,00]
    [C:\Program Files\CheckPoint\SecuRemote\bin\ieproxy_usersr.dll]  [Check Point Software Technologies, 59,8,0010,00]
    [C:\Program Files\CheckPoint\SecuRemote\bin\om_services.dll]  [Check Point Software Technologies, 59,8,000,038]
    [C:\Program Files\CheckPoint\SecuRemote\bin\cprti.dll]  [Check Point Software Technologies, 54,8,2000,26]
    [C:\Program Files\CheckPoint\SecuRemote\bin\ikessl_usersr.dll]  [Check Point Software Technologies, 59,8,0010,00]
    [C:\Program Files\CheckPoint\SecuRemote\bin\CAEnroll_usersr.dll]  [Check Point Software Technologies, 59,8,0010,00]
    [C:\Program Files\CheckPoint\SecuRemote\bin\CPLogLUUID.dll]  [Check Point Software Technologies, 54,8,2000,04]
    [C:\Program Files\CheckPoint\SecuRemote\bin\ckp_scv.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\scv\SCVMonitor.dll]  [Check Point Software Technologies, 59,8,0010,04]
    [C:\Program Files\CheckPoint\SecuRemote\scv\ScriptRun.dll]  [Check Point Software Technologies, 59,8,0010,04]
    [C:\Program Files\CheckPoint\SecuRemote\scv\RegMonitor.dll]  [Check Point Software Technologies, 59,8,0010,04]
    [C:\Program Files\CheckPoint\SecuRemote\scv\ProcessMonitor.dll]  [Check Point Software Technologies, 59,8,0010,04]
    [C:\Program Files\CheckPoint\SecuRemote\scv\OsMonitor.dll]  [Check Point Software Technologies, 59,8,0010,04]
    [C:\Program Files\CheckPoint\SecuRemote\scv\HWMonitor.dll]  [Check Point Software Technologies, 59,8,0010,04]
    [C:\Program Files\CheckPoint\SecuRemote\scv\HotFixMonitor.dll]  [Check Point Software Technologies, 59,8,0010,04]
    [C:\Program Files\CheckPoint\SecuRemote\scv\GroupMonitor.dll]  [Check Point Software Technologies, 59,8,0010,04]
    [C:\Program Files\CheckPoint\SecuRemote\scv\BrowserMonitor.dll]  [Check Point Software Technologies, 59,8,0010,04]
    [C:\Program Files\CheckPoint\SecuRemote\scv\AntiVirusMonitor.dll]  [Check Point Software Technologies, 59,8,0010,04]
    [C:\Program Files\CheckPoint\SecuRemote\bin\proxystub.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\Dispatcher.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\SwInst.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\SiteMgr.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\SimpIpc.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\ScvMgr.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\PolMgr.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\dtftpclient.dll]  [Check Point Software Technologies, 59,8,0010,05]
    [C:\Program Files\CheckPoint\SecuRemote\bin\verify.dll]  [Check Point Software Technologies, 54,8,2000,06]
    [C:\Program Files\CheckPoint\SecuRemote\bin\PolClnt.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\dtmessage.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\LogMgr.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\HAPolSrv.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\ConnMgr.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\CPLogRepository.dll]  [Check Point Software Technologies, 54,8,2000,04]
    [C:\Program Files\CheckPoint\SecuRemote\bin\CPLogKlogUnify.dll]  [Check Point Software Technologies, 54,8,2000,04]
    [C:\Program Files\CheckPoint\SecuRemote\bin\CPLogLuuidDatabase.dll]  [Check Point Software Technologies, 54,8,2000,04]
    [C:\Program Files\CheckPoint\SecuRemote\bin\cp_bdb.dll]  [Check Point Software Technologies, 54,8,2000,05]
[PID: 1620][C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\OS.dll]  [Check Point Software Technologies, 59,8,000,026]
    [C:\Program Files\CheckPoint\SecuRemote\bin\CP_version_info.dll]  [Check Point Software Technologies, 59,8,000,026]
    [C:\Program Files\CheckPoint\SecuRemote\bin\dtplat.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\FileHash_DYN.dll]  [Check Point Software Technologies, 59,8,0010,05]
    [C:\Program Files\CheckPoint\SecuRemote\bin\cpbcrypt.dll]  [Check Point Software Technologies, 59,8,000,013]
    [C:\Program Files\CheckPoint\SecuRemote\bin\DataStruct.dll]  [Check Point Software Technologies, 59,8,000,026]
    [C:\Program Files\CheckPoint\SecuRemote\bin\RunAs.dll]  [Check Point Software Technologies, 59,8,0010,05]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
[PID: 1636][C:\MAINT\sid\DISTH\DistH.exe]  [IBM, 4.5.0.4822]
[PID: 1652][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
[PID: 1712][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
gototop
 

[PID: 1848][C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccL40.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 104.0.11.1]
[PID: 1920][C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccL40.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccSet.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\SPBBC\SPBBCEVT.DLL]  [Symantec Corporation, 2.2.0.7]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCSETEVT.DLL]  [Symantec Corporation, 104.0.11.1]
[PID: 280][C:\WINNT\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\bthcrp.dll]  [Broadcom Corporation, 3.0.1.915]
    [C:\WINNT\system32\WidcommSdk.dll]  [Broadcom Corporation, 3.0.1.915]
    [C:\WINNT\system32\wbtapi.dll]  [Broadcom Corporation, 3.0.1.915]
    [C:\WINNT\system32\dbmon.dll]  [Lotus Development Corporation, 2.00.00.88]
    [C:\WINNT\system32\dbmonlang.dll]  [Lotus Development Corporation, 2.00.00.88]
[PID: 568][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
[PID: 592][C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe]  [Broadcom Corporation, 3.0.1.915]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
[PID: 624][C:\Program Files\Symantec\SCS3\Symantec AntiVirus\DefWatch.exe]  [Symantec Corporation, 10.1.4.4010]
    [C:\Program Files\Common Files\Symantec Shared\ccL40.dll]  [Symantec Corporation, 104.0.11.1]
[PID: 672][C:\Program Files\Nokia\GCS\GCSServer.exe]  [Nokia, 4, 2, 20, 0]
[PID: 764][C:\Program Files\Nokia\GCS\gcssync.exe]  [Nokia, 4, 2, 20, 0]
[PID: 784][C:\Program Files\iPass\iPassConnect\iPCAgent.exe]  [iPass, Inc., 3, 40, 0, 0]
[PID: 860][C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe]  [N/A, N/A]
    [C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\libmrt60.dll]  [N/A, N/A]
    [C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\libcpl60.dll]  [N/A, N/A]
    [C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\libdes60.dll]  [N/A, N/A]
    [C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\libguid60.dll]  [N/A, N/A]
    [C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\libmem60.dll]  [N/A, N/A]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\libtcp60.dll]  [N/A, N/A]
[PID: 1332][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  [Microsoft Corporation, 7.00.9466]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
[PID: 1348][C:\WINNT\system32\PROT_SRV.EXE]  [N/A, N/A]
[PID: 1372][C:\WINNT\system32\pagents.exe]  [N/A, N/A]
[PID: 1392][C:\WINNT\system32\PSTARTSR.EXE]  [N/A, N/A]
[PID: 1556][C:\Program Files\Symantec\SCS3\Symantec AntiVirus\SavRoam.exe]  [symantec, 10.1.4.4010]
    [C:\Program Files\Common Files\Symantec Shared\SSC\Transman.dll]  [Symantec Corporation, 10.1.4.4010]
    [C:\WINNT\system32\CBA.DLL]  [LANDesk Software Ltd., 6.12.0.142 E]
    [C:\WINNT\system32\MsgSys.dll]  [LANDesk Software Ltd., 6.12.0.142 E]
    [C:\WINNT\system32\NTS.dll]  [LANDesk Software Ltd., 6.12.0.142 E]
    [C:\WINNT\system32\PDS.DLL]  [LANDesk Software Ltd., 6.12.0.142 E]
    [c:\program files\common files\symantec shared\ssc\ScsComms.dll]  [Symantec Corporation, 10.1.4.4010]
[PID: 2036][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
[PID: 188][C:\Program Files\Symantec\SCS3\Symantec AntiVirus\Rtvscan.exe]  [Symantec Corporation, 10.1.4.4010]
    [C:\WINNT\system32\CBA.DLL]  [LANDesk Software Ltd., 6.12.0.142 E]
    [C:\WINNT\system32\MsgSys.dll]  [LANDesk Software Ltd., 6.12.0.142 E]
    [C:\WINNT\system32\NTS.dll]  [LANDesk Software Ltd., 6.12.0.142 E]
    [C:\WINNT\system32\PDS.DLL]  [LANDesk Software Ltd., 6.12.0.142 E]
    [C:\Program Files\Symantec\SCS3\Symantec AntiVirus\NAVLU.dll]  [Symantec Corporation, 10.1.4.4010]
    [C:\Program Files\Symantec\SCS3\Symantec AntiVirus\I2ldvp3.dll]  [Symantec Corporation, 10.1.4.4010]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\Program Files\Common Files\Symantec Shared\ccL40.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Symantec\SCS3\Symantec AntiVirus\NAVNTUTL.DLL]  [Symantec Corporation, 10.1.4.4010]
    [c:\program files\common files\symantec shared\ssc\ScsComms.dll]  [Symantec Corporation, 10.1.4.4010]
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccDec.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\decsdk.dll]  [Symantec Corporation, 3.02.14.10]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll]  [Symantec Corporation, 3.02.14.10]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll]  [Symantec Corporation, 3.02.14.10]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll]  [Symantec Corporation, 3.02.14.10]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll]  [Symantec Corporation, 3.02.14.10]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll]  [Symantec Corporation, 3.02.14.10]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll]  [Symantec Corporation, 3.02.14.10]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll]  [Symantec Corporation, 3.02.14.10]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll]  [Symantec Corporation, 3.02.14.10]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll]  [Symantec Corporation, 3.02.14.10]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll]  [Symantec Corporation, 3.02.14.10]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll]  [Symantec Corporation, 3.02.14.10]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll]  [Symantec Corporation, 3.02.14.10]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll]  [Symantec Corporation, 3.02.14.10]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll]  [Symantec Corporation, 3.02.14.10]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll]  [Symantec Corporation, 3.02.14.10]
    [C:\Program Files\Common Files\Symantec Shared\ccScan.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL]  [Symantec Corporation, 51.3.0.11]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070127.007\ccEraser.dll]  [Symantec Corporation, 106.3.3.2]
    [C:\Program Files\Symantec\SCS3\Symantec AntiVirus\DefUtDCD.dll]  [Symantec Corporation, 3.1.13a.0]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070127.007\ecmsvr32.dll]  [Symantec Corporation, 71.1.0.11]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070127.007\NAVEX32a.DLL]  [Symantec Corporation, 20071.1.0.15]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070127.007\NAVENG32.DLL]  [Symantec Corporation, 20071.1.0.15]
    [C:\Program Files\Symantec\SCS3\Symantec AntiVirus\SAVRT32.DLL]  [Symantec Corporation, 9.7.1.4]
    [C:\Program Files\Symantec\SCS3\Symantec AntiVirus\vpmsece4.dll]  [Symantec Corporation, 10.1.4.4010]
    [C:\Program Files\Symantec\SCS3\Symantec AntiVirus\SymProtectStorage.dll]  [Symantec Corporation, 10.1.4.4010]
    [C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCEvt.dll]  [Symantec Corporation, 2.2.0.7]
gototop
 

[PID: 356][C:\WINNT\RCSERV.EXE]  [IBM Corporation, 3, 8, 1, 0]
[PID: 388][C:\WINNT\system32\TpKmpSVC.exe]  [N/A, N/A]
[PID: 604][C:\Program Files\CyberArmor\casvc.exe]  [InfoExpress, 3.0.40520]
[PID: 612][C:\WINNT\itlm\tlmagent.exe]  [N/A, N/A]
    [C:\Program Files\IBM\GSK7\lib\gsk7ssl.dll]  [IBM Corporation, 7.0.3.16]
    [C:\Program Files\IBM\GSK7\lib\gsk7cms.dll]  [IBM Corporation, 7.0.3.16]
    [C:\Program Files\IBM\GSK7\lib\gsk7sys.dll]  [IBM Corporation, 7.0.3.16]
    [C:\Program Files\IBM\GSK7\lib\gsk7km.dll]  [IBM Corporation, 7.0.3.16]
    [C:\Program Files\IBM\GSK7\lib\gsk7kjni.dll]  [IBM Corporation, 7.0.3.16]
    [C:\Program Files\IBM\GSK7\lib\gsk7kicc.dll]  [IBM Corporation, 7.0.3.16]
    [C:\Program Files\IBM\GSK7\lib\gsk7iccs.dll]  [IBM Corporation, 7.0.3.16]
    [C:\Program Files\IBM\GSK7\icc\icclib\icclib.dll]  [N/A, N/A]
    [C:\Program Files\IBM\GSK7\icc\osslib\libeay32.dll]  [N/A, N/A]
    [C:\Program Files\IBM\GSK7\lib\gsk7dbfl.dll]  [IBM Corporation, 7.0.3.16]
    [C:\Program Files\IBM\GSK7\lib\gsk7valn.dll]  [IBM Corporation, 7.0.3.16]
[PID: 2452][C:\MAINT\SID\DISTH\BBCLIENT.EXE]  [IBM, 1, 0, 0, 4]
[PID: 3420][C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe]  [Nokia., 6, 80, 56, 4]
    [C:\WINNT\system32\NclTools.dll]  [Nokia., 6, 80, 18, 3]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\Program Files\Common Files\PCSuite\Transports\NCLIrDAMM.dll]  [Nokia Corp., 6, 80, 26, 0]
    [C:\Program Files\Common Files\PCSuite\Transports\NCLRSMM.dll]  [Nokia, 6, 80, 33, 0]
    [C:\Program Files\Common Files\PCSuite\Transports\NCLUSBMM.dll]  [Nokia, 6, 80, 37, 0]
    [C:\Program Files\Common Files\PCSuite\Transports\NclMSBTMM.dll]  [Nokia., 6, 80, 38, 2]
    [C:\Program Files\Common Files\PCSuite\Transports\NclBCBTMM.dll]  [Nokia, 6, 80, 48, 2]
[PID: 2984][C:\PROGRA~1\CYBERA~1\pcs.exe]  [InfoExpress, 3.0.40520B]
    [C:\WINNT\system32\Vsctool.dll]  [N/A, N/A]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
[PID: 4092][C:\PROGRA~1\CYBERA~1\pcshelp.exe]  [InfoExpress, 3.0.40520]
[PID: 2864][C:\WINNT\system32\ZCfgSvc.exe]  [Intel Corporation, 8, 1, 0, 47_ITP]
    [C:\WINNT\system32\PfMgrApi.dll]  [Intel Corporation, 8, 1, 0, 47_ITP]
    [C:\WINNT\system32\PsRegApi.dll]  [Intel Corporation, 8, 1, 0, 47_ITP]
    [C:\WINNT\system32\WConfig.DLL]  [Intel Corporation, 8, 1, 0, 47_ITP]
    [C:\WINNT\system32\WiFiAdap.DLL]  [Intel Corporation, 8, 1, 0, 47_ITP]
    [C:\WINNT\system32\PsGuiMgr.dll]  [Intel Corporation., 8, 1, 0, 47_ITP]
    [C:\WINNT\system32\ShellNav.dll]  [, 1, 0, 0, 1]
    [C:\WINNT\system32\C1XStngs.dll]  [Intel Corporation, 8, 1, 0, 47_ITP]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\LSAWRAPI.dll]  [N/A, N/A]
    [C:\WINNT\system32\S24MUDLL.dll]  [Intel Corporation, 8, 1, 0, 47_ITP]
    [C:\WINNT\system32\D8021Xps.dll]  [N/A, N/A]
[PID: 2660][C:\WINNT\system32\1XConfig.exe]  [Intel, 8, 1, 0, 47_ITP]
    [C:\WINNT\system32\IntelAE5.dll]  [Meetinghouse Data Communications, 5, 0, 3, 3]
    [C:\WINNT\system32\PsRegApi.dll]  [Intel Corporation, 8, 1, 0, 47_ITP]
    [C:\WINNT\system32\D8021Xps.dll]  [N/A, N/A]
[PID: 3444][C:\WINNT\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4149]
    [C:\WINNT\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2508]
    [C:\WINNT\system32\atipdlxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2513]
    [C:\WINNT\system32\ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4149]
[PID: 720][C:\WINNT\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll]  [IBM Corp., 1, 0, 0, 0]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.0.2004121400]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUNETU.DLL]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\RSSU.DLL]  [Mobiliti, Inc., 4, 7, 0, 20 ]
[PID: 2928][C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe]  [Check Point Software Technologies, 1, 0, 0, 1]
    [C:\Program Files\CheckPoint\SecuRemote\bin\cpprod50.dll]  [Check Point Software Technologies, 54,8,2000,05]
    [C:\Program Files\CheckPoint\SecuRemote\bin\DataStruct.dll]  [Check Point Software Technologies, 59,8,000,026]
    [C:\Program Files\CheckPoint\SecuRemote\bin\OS.dll]  [Check Point Software Technologies, 59,8,000,026]
    [C:\Program Files\CheckPoint\SecuRemote\bin\cpbcrypt.dll]  [Check Point Software Technologies, 59,8,000,013]
    [C:\Program Files\CheckPoint\SecuRemote\bin\CP_version_info.dll]  [Check Point Software Technologies, 59,8,000,026]
    [C:\Program Files\CheckPoint\SecuRemote\bin\Resolve.dll]  [Check Point Software Technologies, 59,8,000,026]
    [C:\Program Files\CheckPoint\SecuRemote\bin\objlib.dll]  [Check Point Software Technologies, 54,8,2000,06]
    [C:\Program Files\CheckPoint\SecuRemote\bin\CPSrvIS.dll]  [Check Point Software Technologies, 54,8,2000,03]
    [C:\Program Files\CheckPoint\SecuRemote\bin\ComUtils.dll]  [Check Point Software Technologies, 59,8,000,026]
    [C:\Program Files\CheckPoint\SecuRemote\bin\cpcert.dll]  [Check Point Software Technologies, 59,8,000,013]
    [C:\Program Files\CheckPoint\SecuRemote\bin\Encode.dll]  [Check Point Software Technologies, 59,8,000,026]
    [C:\Program Files\CheckPoint\SecuRemote\bin\cpprng.dll]  [Check Point Software Technologies, 59,8,000,013]
    [C:\Program Files\CheckPoint\SecuRemote\bin\cpopenssl.dll]  [Check Point Software Technologies, 54,8,2000,06]
    [C:\Program Files\CheckPoint\SecuRemote\bin\cpcryptutil.dll]  [Check Point Software Technologies, 59,8,000,013]
    [C:\Program Files\CheckPoint\SecuRemote\bin\ndb.dll]  [Check Point Software Technologies, 54,8,2000,03]
    [C:\Program Files\CheckPoint\SecuRemote\bin\AppUtils.dll]  [Check Point Software Technologies, 59,8,000,026]
    [C:\Program Files\CheckPoint\SecuRemote\bin\EventUtils.dll]  [Check Point Software Technologies, 59,8,000,026]
    [C:\Program Files\CheckPoint\SecuRemote\bin\FileHash_DYN.dll]  [Check Point Software Technologies, 59,8,0010,05]
    [C:\Program Files\CheckPoint\SecuRemote\bin\gui.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\dtplat.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\GuiServiceInterface.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\LangPack.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\proxystub.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\Dispatcher.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\FwBinding.dll]  [Check Point Software Technologies, 59,8,0010,05]
    [C:\Program Files\CheckPoint\SecuRemote\bin\cpfwsys.dll]  [Check Point Software Technologies, 54,8,2000,26]
    [C:\Program Files\CheckPoint\SecuRemote\bin\cpsys.dll]  [Check Point Software Technologies, 54,8,2000,26]
    [C:\Program Files\CheckPoint\SecuRemote\bin\cvars.dll]  [Check Point Software Technologies, 54,8,2000,03]
    [C:\Program Files\CheckPoint\SecuRemote\bin\mastersapi.dll]  [Check Point Software Technologies, 54,8,2000,06]
    [C:\Program Files\CheckPoint\SecuRemote\bin\fwsmtpobj.dll]  [Check Point Software Technologies, 54,8,2000,06]
    [C:\Program Files\CheckPoint\SecuRemote\bin\fwadb.dll]  [Check Point Software Technologies, 54,8,2000,06]
    [C:\Program Files\CheckPoint\SecuRemote\bin\skey.dll]  [Check Point Software Technologies, 54,8,2000,06]
    [C:\Program Files\CheckPoint\SecuRemote\bin\fwsetdb.dll]  [Check Point Software Technologies, 54,8,2000,03]
    [C:\Program Files\CheckPoint\SecuRemote\bin\cpii.dll]  [Check Point Software Technologies, 54,8,2000,26]
    [C:\Program Files\CheckPoint\SecuRemote\bin\ReportDT.dll]  [Check Point Software Technologies, 59,8,0010,05]
    [C:\Program Files\CheckPoint\SecuRemote\bin\dtis_lang_pack.dll]  [Check Point Software Technologies, 59,8,0010,05]
    [C:\Program Files\CheckPoint\SecuRemote\bin\IkeStatus.dll]  [Check Point Software Technologies, 59,8,0010,05]
    [C:\Program Files\CheckPoint\SecuRemote\bin\SimpIpc.dll]  [Check Point Software Technologies, 59,8,0010,19]
    [C:\Program Files\CheckPoint\SecuRemote\bin\LogRedir.dll]  [Check Point Software Technologies, 59,8,0010,19]
[PID: 1864][C:\WINNT\system32\rundll32.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
[PID: 2796][C:\Program Files\Common Files\PCSuite\Services\NclBTHandler.exe]  [Nokia, 6, 80, 1, 1]
    [C:\WINNT\system32\NclTools.dll]  [Nokia., 6, 80, 18, 3]
    [C:\WINNT\system32\wbtapi.dll]  [Broadcom Corporation, 3.0.1.915]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
gototop
 

[PID: 428][C:\Program Files\Mobiliti\Unplugged\BIN\MNUNET.EXE]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\NAWPROJ.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\NAWUSER.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUSYNCC.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\NAWRAS.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUNETSP.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNULOG.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\oaobsrvr.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUTRCAN.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNURES.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUFILE.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUINET.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\monuse.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUSYNCS.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\NAWUTIL.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\DTMPROXY.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\Program Files\Mobiliti\Unplugged\BIN\RSSU.DLL]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MBCSUDTM.DLL]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MBCSLDTM.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUCSAFE.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\DSSdelta.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
[PID: 988][C:\Program Files\CyberArmor\pcshelp.exe]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
[PID: 3188][C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe]  [Sun Microsystems, Inc., 5.0.60.5]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
[PID: 3228][C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe]  [N/A, N/A]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\Program Files\ThinkPad\PkgMgr\HOTKEY_2\tphk_2k.dll]  [N/A, N/A]
    [C:\WINNT\system32\Oemdspif.dll]  [ATI Technologies, Inc., 6.14.0017]
    [C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\tpfnf7.dll]  [N/A, N/A]
[PID: 3952][C:\Program Files\Synaptics\SynTP\SynTPLpr.exe]  [Synaptics, Inc., 7.5.17.13 08Nov04]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]
[PID: 4072][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe]  [Synaptics, Inc., 7.5.17.13 08Nov04]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\SynCOM.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]
    [C:\WINNT\system32\SynTPAPI.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]
[PID: 376][C:\WINNT\system32\RunDll32.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll]  [IBM Corp., 1, 0, 0, 0]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\tppwrw32.dll]  [IBM Corp., 1, 0, 0, 0]
[PID: 2512][C:\WINNT\system32\rundll32.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll]  [N/A, N/A]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\tppwrw32.dll]  [IBM Corp., 1, 0, 0, 0]
[PID: 2372][C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe]  [IBM Corp., 1, 0, 0, 0]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\US\EzMApRes.dll]  [N/A, N/A]
[PID: 2340][C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE]  [Nokia, 6, 80, 53, 3]
    [C:\WINNT\system32\ConnAPI.DLL]  [Nokia., 6, 80, 55, 5]
    [C:\PROGRA~1\Nokia\NOKIAP~1\PCSCM.dll]  [Nokia, 6, 80, 66, 0]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]
    [C:\Program Files\Common Files\PCSuite\ConfServer\ConfServer.dll]  [Nokia, 6, 80, 20, 4]
    [C:\WINNT\system32\NclTools.dll]  [Nokia., 6, 80, 18, 3]
    [C:\PROGRA~1\Nokia\NOKIAP~1\Lang\LaunchApplication_eng.NLR]  [Nokia, 6, 80, 56, 1]
[PID: 2168][C:\WINNT\system32\SKDAEMON.EXE]  [LITE-ON TECHNOLOGY CORP., 1, 0, 0, 3]
    [C:\WINNT\system32\skutil.dll]  [LITE-ON TECHNOLOGY CORP., 1, 1, 0, 1]
    [C:\WINNT\system32\SKUsbKbd.dll]  [LITE-ON TECHNOLOGY CORP., 1, 1, 0, 0]
    [C:\WINNT\system32\skosd.dll]  [LITE-ON TECHNOLOGY CORP., 1, 1, 0, 0]
    [C:\WINNT\system32\skhooks.dll]  [LITE-ON Corp., 1, 0, 0, 0]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]
[PID: 1724][C:\Program Files\Pointsec\P95tray.exe]  [Pointsec Mobile Technologies AB, 5.2.2]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]
[PID: 3172][C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfep.exe]  [N/A, N/A]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]
[PID: 3528][C:\Program Files\Common Files\Symantec Shared\ccApp.exe]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccL40.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccSet.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCALERT.DLL]  [Symantec Corporation, 104.0.11.1]
[PID: 4048][C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe]  [N/A, N/A]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]
[PID: 2596][C:\PROGRA~1\Symantec\SCS3\SYMANT~1\VPTray.exe]  [Symantec Corporation, 10.1.4.4010]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\Program Files\Common Files\Symantec Shared\ccL40.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Symantec\SCS3\Symantec AntiVirus\SAVRT32.DLL]  [Symantec Corporation, 9.7.1.4]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]
    [C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccProSub.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccAlert.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Symantec\SCS3\Symantec AntiVirus\Cliproxy.dll]  [Symantec Corporation, 10.1.4.4010]
    [C:\Program Files\Symantec\SCS3\Symantec AntiVirus\NAVNTUTL.DLL]  [Symantec Corporation, 10.1.4.4010]
    [c:\program files\common files\symantec shared\ssc\ScsComms.dll]  [Symantec Corporation, 10.1.4.4010]
    [C:\Program Files\Common Files\Symantec Shared\ccSet.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\WINNT\system32\nts.dll]  [LANDesk Software Ltd., 6.12.0.142 E]
    [C:\WINNT\system32\cba.dll]  [LANDesk Software Ltd., 6.12.0.142 E]
    [C:\WINNT\system32\MsgSys.dll]  [LANDesk Software Ltd., 6.12.0.142 E]
    [C:\WINNT\system32\PDS.DLL]  [LANDesk Software Ltd., 6.12.0.142 E]
[PID: 3392][C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe]  [IBM Corporation, 1.06]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]
[PID: 620][C:\WINNT\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]
[PID: 3484][C:\Program Files\IBM\Bluetooth Software\BTTray.exe]  [Broadcom Corporation, 3.0.1.915]
    [C:\WINNT\system32\wbtapi.dll]  [Broadcom Corporation, 3.0.1.915]
    [C:\WINNT\system32\btosif.dll]  [Broadcom Corporation, 3.0.1.915]
    [C:\Program Files\IBM\Bluetooth Software\BtBalloon.dll]  [Broadcom Corporation, 3.0.1.915]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\btrez.dll]  [Broadcom Corporation, 3.0.1.915]
    [C:\WINNT\system32\CSH.dll]  [Blue Sky Software Corporation, 2.00.039]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]
    [C:\Program Files\IBM\Bluetooth Software\btkeyind.dll]  [N/A, N/A]
gototop
 

[PID: 3740][C:\Program Files\Mobiliti\Unplugged\BIN\MNUAGENT.EXE]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\NAWUSER.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\NAWUTIL.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\NAWPROJ.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUINET.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUNETSP.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUPREF.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\NAWRAS.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNURES.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUSYNCC.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNULOG.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\oaobsrvr.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUTRCAN.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUFILE.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\monuse.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUSYNCS.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\DTMPROXY.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUSCHED.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUABOUT.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\NAWSETUP.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\Program Files\Mobiliti\Unplugged\BIN\RSSU.DLL]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MBCSUDTM.DLL]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MBCSLDTM.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\MNUCSAFE.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\Program Files\Mobiliti\Unplugged\BIN\DSSdelta.dll]  [Mobiliti, Inc., 4, 7, 0, 20 ]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]
[PID: 1368][C:\Users\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [C:\WINNT\system32\cahooknt.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\cahookd.dll]  [InfoExpress, 3.0.40520]
    [C:\WINNT\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.13 08Nov04]

==================================
File Associations
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1      localhost
125.91.6.27session.17game.com
125.91.12.67session.17game.com
59.188.15.100  chargeuser.wjwg.com
59.188.15.100 bbs.wjwg.com

==================================
API HOOK
Warning! System Repair Engineer
remind you that following
functions have modified to
abnormal values by unknown
reasons:
Entry Error: LoadLibraryExW
Entry Error: CreateProcessA
Entry Error: CreateProcessW

==================================


[/CODE]
gototop
 

引用:
【newcenturymoon的贴子】下载 System Repair Engineer,
http://www.kztechs.com/sreng/download.html
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
友情提示:
扫描前关闭所有手工打开的软件和窗口,扫描后将日志发上来。但请不要用附件形式贴。
注意在没有进一步提示前,勿要胡乱修复,否则系统可能变的情况更糟。
         
如果发现SREng.exe运行无反应或者不能运行或者扫描出错,你可以将SREng.exe重命名为SREng.com(SREng.scr\SREng.bat\SREng.pif)或者abc.exe运行.
另外那个 病毒文件麻烦发到newcenturymoon@126.com
………………


扫描完了,报告贴上来了,我的是英文XP,SP2,公司笔记本,进程很多,贴了不少.病毒文件也已经发你了,请查收.
gototop
 

似乎没人过问,伤心的~~
现在电脑已经不能注销或重启了,因为这样做都会蓝屏....
不知道是不是病毒发作了:(
gototop
 

没人可以救我?
gototop
 

引用:
【suzhou758的贴子】似乎没人过问,伤心的~~
现在电脑已经不能注销或重启了,因为这样做都会蓝屏....
不知道是不是病毒发作了:(

………………

中“熊猫烧香”变种了。病毒主体文件名为:ncscv32.exe。
解决办法:

1、将下列内容粘贴到记事本窗口:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ncscv32.exe]
"Debugger"="ncscv32.exe"

末尾留一空行。保存为kill_panda.reg。

2、双击kill_panda.reg,将其导入注册表。重启系统,这只熊猫就死了。
此外,你系统中还有这只熊猫下载的一些木马。建议:重装一下杀软,升级病毒库,全盘杀毒吧。瑞星已经能杀这个变种。
gototop
 

在盘里没找到ncscv32.exe(可能本来就没有,不清楚),打开了显示系统隐含文件....
文件也已经导入注册表并重启系统,已确认在注册表里可以找到,但问题还是发生.苦恼中....

对那句"末尾留一空行"不是很能明白,不理解,不知道baohu斑竹是否可以做下那个reg文件发我邮箱里,ryx1191@sina.con,谢谢先.
先用了电脑上的升过级更新完的Symantec Antivirus全盘杀了,没有发现任何.后又用了瑞星的在线杀毒,10元/月的那个,结果也是没有发现任何异常.郁闷的.......
gototop
 
12345   2  /  5  页   跳转
页面顶部
Powered by Discuz!NT