瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】qq被盗了,怀疑有木马,请哥哥们帮我看下日志

123   1  /  3  页   跳转

【求助】qq被盗了,怀疑有木马,请哥哥们帮我看下日志

【求助】qq被盗了,怀疑有木马,请哥哥们帮我看下日志

HijackThis_815汉化版扫描日志 V1.99.1
保存于      11:15:46, 日期 2006-10-4
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
D:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Tool\ske\TrojanAssistant.exe
D:\Tool\Hijackthis1991zww\HijackThis1991zww.exe
D:\Tool\Hijackthis1991zww\HijackThis1991zww.exe

O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\KakaTool.dll
O4 - 启动项HKLM\\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [KernelFaultCheck] ; %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [Super Rabbit SafeEdit] ; D:\Program Files\Super Rabbit\MagicSet\SRFC.EXE /Load
O4 - 启动项HKLM\\Run: [Super Rabbit SRRestore] ; D:\Program Files\Super Rabbit\MagicSet\srrest.exe /autosave
O4 - 启动项HKLM\\Run: [ATIPTA] ; C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [MSPY2002] ; C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [SoundMan] ; SOUNDMAN.EXE
O4 - HKCU\..\Run: [Super Rabbit IEPro] D:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096088341547
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{94964B43-60DD-4C1C-9E3C-621C83883004}: NameServer = 218.6.200.139 61.139.2.69
O23 - NT 服务: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - NT 服务: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - NT 服务: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe

最后编辑2006-10-04 21:39:41.530000000
分享到:
gototop
 

2006-10-04,11:17:12

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <Super Rabbit IEPro><D:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD>  [Super Rabbit Soft]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <KernelFaultCheck><; %systemroot%\system32\dumprep 0 -k>  []
    <Super Rabbit SafeEdit><; D:\Program Files\Super Rabbit\MagicSet\SRFC.EXE /Load>  [Super Rabbit Soft]
    <Super Rabbit SRRestore><; D:\Program Files\Super Rabbit\MagicSet\srrest.exe /autosave>  [Super Rabbit Soft]
    <ATIPTA><; C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>  [ATI Technologies, Inc.]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <MSPY2002><; C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC>  []
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
    <SoundMan><; SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\SYSTEM32\Userinit.exe,>  [Microsoft Corporation]
    <UIHost><logonui.exe>  [Microsoft Corporation]
gototop
 

==================================
启动文件夹
服务
[Ati HotKey Poller / Ati HotKey Poller]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[C-DillaCdaC11BA / C-DillaCdaC11BA]
  <C:\WINDOWS\system32\drivers\CDAC11BA.EXE><Macrovision>
[Rising Proxy  Service / RfwProxySrv]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>

==================================
浏览器加载项
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\WINDOWS\system32\dllcache\dhtmled.ocx, Microsoft Corporation>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[RMGetLicense Class]
  {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\Mshtml.dll, Microsoft Corporation>
[卡卡上网安全助手]
  {AFF6E516-CBE5-4F8A-9C2F-38A68013E766} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[AUDIO__X_MS_WMA Moniker Class]
  {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[TencentVmpCtl Class]
  {D9819BD5-422B-4281-8523-726466ED692B} <C:\Program Files\Tencent\Viewpoint Media Player\AxMetaStream.dll, Viewpoint Corporation>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[CPasswordEditCtrl Object]
  {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>

==================================
正在运行的进程
[PID: 416][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 464][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 492][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 536][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 548][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 704][C:\WINDOWS\system32\Ati2evxx.exe]  <ATI Technologies Inc.><6.14.10.4114>
    [C:\WINDOWS\system32\Ati2edxx.dll]  <ATI Technologies, Inc.><6, 14, 10, 2496>
[PID: 716][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 776][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 892][C:\Program Files\Rising\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 908][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1012][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1088][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1108][C:\Program Files\Rising\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 35>
gototop
 

[C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
    [C:\Program Files\Rising\Rav\HOOKSYS.dll]  <Beijing Rising Technology Co., Ltd.><18, 1, 0, 11>
    [C:\Program Files\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 32>
    [C:\Program Files\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
    [C:\Program Files\Rising\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\HookWeb.dll]  <rising><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [C:\Program Files\Rising\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\SpamEng.dll]  <N/A><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 34>
    [C:\Program Files\Rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [C:\Program Files\Rising\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 27>
    [C:\Program Files\Rising\Rav\RSUnpack.dll]  <Beijing Rising Technology Co., Ltd.><1, 0, 0, 17>
    [C:\Program Files\Rising\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\Rising\Rav\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\ScanNet.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1160][c:\program files\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 33>
    [c:\program files\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
    [c:\program files\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [c:\program files\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [c:\program files\rising\rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [c:\program files\rising\rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 1380][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 1476][C:\Program Files\Rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1980][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2012][c:\program files\rising\rfw\RfwMain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 52>
    [c:\program files\rising\rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [c:\program files\rising\rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [c:\program files\rising\rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 344][C:\Program Files\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
[PID: 360][C:\Program Files\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 33>
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 616][D:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE]  <Super Rabbit Soft><7.30>
[PID: 764][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1624][C:\WINDOWS\system32\drivers\CDAC11BA.EXE]  <Macrovision><4.20.020>
[PID: 1700][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 1136][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3036][C:\WINDOWS\system32\wuauclt.exe]  <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[PID: 2724][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\KakaTool.dll]  <Beijing Rising Technology Co., Ltd.><2, 0, 0, 9>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
[PID: 3544][C:\WINDOWS\system32\wbem\wmiprvse.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3172][D:\Tool\ske\TrojanAssistant.exe]  <Yahoo! CN><2.1.2.51>
    [D:\Tool\ske\fsk.dll]  <3721.com><2, 1, 1, 90>
[PID: 3360][D:\Tool\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

各位高手:
非常感谢您留心我这份系统诊断报告,小菜鸟十万火急等待您的帮助!
该诊断报告由360安全卫士提供 http://www.360safe.com
诊断时间: 2006-10-04  11:19:33
诊断平台: Microsoft Windows XP  Service Pack 2
IE版本: Internet Explorer V6.0.2900.2180 Build:62900.2180
计算机物理内存:510MB - 当前可用内存:277MB

100 - 未知 - Process: sriecli.exe [http://www.superrsoft.com] - "D:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE" /LOAD
100 - 未知 - Process: TrojanAssistant.exe [清除木马] - "D:\Tool\ske\TrojanAssistant.exe"
R0 - 未知 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.hao123.com/
O3 - 未知 - Toolbar: (第三方IE工具栏) - [无效的CLSID:{710EB7A1-45ED-11D0-924A-0020AFC7AC4D}] - {710EB7A1-45ED-11D0-924A-0020AFC7AC4D} -
O3 - 未知 - Toolbar: (第三方IE工具栏) - [无效的CLSID:{1E796980-9CC5-11D1-A83F-00C04FC99D61}] - {1E796980-9CC5-11D1-A83F-00C04FC99D61} -
O17 - 未知 - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{94964B43-60DD-4C1C-9E3C-621C83883004}: NameServer = 218.6.200.139 61.139.2.69
O18 - 未知 - Protocol: 电子书编译工具Web Compiler相关 - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - C:\WINDOWS\wc98pp.dll

=======================================

100 - 安全 - Process: smss.exe [进程为会话管理子系统用以初始化系统变量,ms-dos驱动名称类似lpt1以及com,调用win32壳子系统和运行在windows登陆过程。] - \SystemRoot\System32\smss.exe
100 - 安全 - Process: csrss.exe [客户端服务子系统,用以控制windows图形相关子系统。] - C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestT
100 - 安全 - Process: winlogon.exe [windows nt用户登陆程序。] - winlogon.exe
100 - 安全 - Process: services.exe [用于管理windows服务系统进程。] - C:\WINDOWS\system32\services.exe
100 - 安全 - Process: lsass.exe [本地安全权限服务控制windows安全机制。] - C:\WINDOWS\system32\lsass.exe
100 - 安全 - Process: ati2evxx.exe [ati显卡相关后台程序。] - C:\WINDOWS\system32\Ati2evxx.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k DcomLaunch
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k rpcss
100 - 安全 - Process: CCenter.exe [瑞星杀毒软件控制台相关程序。] - "C:\Program Files\Rising\Rav\CCenter.exe"
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\System32\svchost.exe -k netsvcs
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k NetworkService
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k LocalService
100 - 安全 - Process: RavMonD.exe [瑞星杀毒软件的一部分。] - "C:\Program Files\Rising\Rav\Ravmond.exe"
100 - 安全 - Process: rfwsrv.exe [瑞星出品的防火墙程序,用于抵御黑客攻击。] - "c:\program files\rising\rfw\rfwsrv.exe"
100 - 安全 - Process: spoolsv.exe [windows打印任务控制程序,用以打印机就绪。] - C:\WINDOWS\system32\spoolsv.exe
100 - 安全 - Process: RavStub.exe [瑞星出品的杀毒软件相关程序。] - "C:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND
100 - 安全 - Process: explorer.exe [windows program manager或者windows explorer用于控制windows图形shell,包括开始菜单、任务栏,桌面和文件管理。] - C:\WINDOWS\Explorer.EXE
100 - 安全 - Process: rfwmain.exe [瑞星公司出品的瑞星杀毒软件个人防火墙程序,用于抵御黑客攻击。] -  -StartUp
100 - 安全 - Process: RavTask.exe [瑞星出品的杀毒软件相关程序。] - "C:\Program Files\Rising\Rav\RavTask.exe" -system
100 - 安全 - Process: RavMon.exe [瑞星杀毒软件防火墙。] - "C:\Program Files\Rising\Rav\Ravmon.exe" -SYSTEM
100 - 未知 - Process: sriecli.exe [http://www.superrsoft.com] - "D:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE" /LOAD
100 - 安全 - Process: ctfmon.exe [office xp输入法图标。] - "C:\WINDOWS\system32\ctfmon.exe"
100 - 安全 - Process: CDAC11BA.EXE [macrovision公司的版权保护软件,用于保护一些软件不被非法拷贝复制。] - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
100 - 安全 - Process: wdfmgr.exe [windows media player播放器相关程序。] - C:\WINDOWS\system32\wdfmgr.exe
100 - 安全 - Process: alg.exe [这是一个应用层网关服务用于网络共享。] - C:\WINDOWS\System32\alg.exe
100 - 安全 - Process: wuauclt.exe [windows操作系统后台程序,用于系统升级。] - "C:\WINDOWS\system32\wuauclt.exe"
100 - 安全 - Process: IEXPLORE.EXE [microsoft internet explorer浏览器用于浏览网页。] - "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
100 - 安全 - Process: wmiprvse.exe [wmi 提供程序 (wmi provider) 在 wmi 和操作系统、应用程序以及其他系统的组件之间充当中介.此进程为合法的系统进程。] - C:\WINDOWS\system32\wbem\wmiprvse.exe
100 - 未知 - Process: TrojanAssistant.exe [清除木马] - "D:\Tool\ske\TrojanAssistant.exe"
100 - 安全 - Process: 360Safe.exe [360安全卫士] - "D:\Tool\360safe\360Safe.exe"
R0 - 未知 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.hao123.com/
R1 - 安全 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=about:blank
O3 - 默认 - Toolbar: (卡卡上网安全助手) - [卡卡安全助手工具条软件相关程序。] - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\KakaTool.dll
O3 - 未知 - Toolbar: (第三方IE工具栏) - [无效的CLSID:{710EB7A1-45ED-11D0-924A-0020AFC7AC4D}] - {710EB7A1-45ED-11D0-924A-0020AFC7AC4D} -
O3 - 未知 - Toolbar: (第三方IE工具栏) - [无效的CLSID:{1E796980-9CC5-11D1-A83F-00C04FC99D61}] - {1E796980-9CC5-11D1-A83F-00C04FC99D61} -
O4 - 安全 - HKLM\..\Run: [TkBellExe] [是Real Networks产品定时升级检测程序。] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 安全 - HKLM\..\Run: [RavTask] [瑞星杀毒软件的任务计划程序。] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 安全 - HKLM\..\Run: [KernelFaultCheck] [windows的错误报告工具] ; %systemroot%\system32\dumprep 0 -k
O4 - 安全 - HKLM\..\Run: [Super Rabbit SafeEdit] [超级兔子安全视窗。] ; D:\Program Files\Super Rabbit\MagicSet\SRFC.EXE /Load
O4 - 安全 - HKLM\..\Run: [Super Rabbit SRRestore] [超级兔子:对计算机进行优化,设置的工具] ; D:\Program Files\Super Rabbit\MagicSet\srrest.exe /autosave
O4 - 安全 - HKLM\..\Run: [ATIPTA] [ati显卡驱动的系统托盘图标,可调节显卡属性] ; C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - 安全 - HKLM\..\Run: [IMJPMIG8.1] [微软Microsoft输入法编辑器程序。] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 安全 - HKLM\..\Run: [MSPY2002] [是微软Microsoft翻译工具的一部分。] ; C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - 安全 - HKLM\..\Run: [PHIME2002A] [输入法软件相关程序。] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 安全 - HKLM\..\Run: [PHIME2002ASync] [输入法软件相关程序。] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 安全 - HKLM\..\Run: [SoundMan] [Realtek声卡相关程序。] ; SOUNDMAN.EXE
O4 - 安全 - HKCU\..\Run: [Super Rabbit IEPro] [超级兔子ie保护专家] D:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD
O4 - 安全 - HKCU\..\Run: [ctfmon.exe] [office xp输入法图标。] C:\WINDOWS\system32\ctfmon.exe
O16 - 安全 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (Windows升级工具V5) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096088341547
O16 - 安全 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Flash播放器) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - 安全 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (瑞星免费在线查毒插件) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - 未知 - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{94964B43-60DD-4C1C-9E3C-621C83883004}: NameServer = 218.6.200.139 61.139.2.69
O18 - 安全 - Protocol: OFFICE 相关 - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O18 - 未知 - Protocol: 电子书编译工具Web Compiler相关 - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - C:\WINDOWS\wc98pp.dll
O18 - 安全 - Protocol: OFFICE 相关 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
O23 - 安全 - Service: Ati HotKey Poller [ati显卡相关后台程序。] - C:\WINDOWS\system32\ati2evxx.exe
O23 - 安全 - Service: C-DillaCdaC11BA [是MacroVision safeCast反复制保护软件。该进程是一些软件为了保护其产品不被盗版而安装的。] - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - 安全 - Service: RfwProxySrv [瑞星防火墙相关程序。] - c:\program files\Rising\Rfw\rfwProxy.exe
O23 - 安全 - Service: RfwService [是瑞星个人防火墙相关程序。] - c:\program files\Rising\Rfw\rfwsrv.exe
O23 - 安全 - Service: RsCCenter [是瑞星杀毒软件控制台相关程序。] - C:\Program Files\Rising\Rav\CCenter.exe
O23 - 安全 - Service: RsRavMon [是瑞星杀毒软件相关监控程序。] - C:\Program Files\Rising\Rav\RavMonD.exe
O24 - 安全 - COOKIES: ad08.focalink.com - Restricted Cookies
O24 - 安全 - COOKIES: adbureau.com - Restricted Cookies
O24 - 安全 - COOKIES: admonitor.com - Restricted Cookies
O24 - 安全 - COOKIES: ads.enliven.com - Restricted Cookies
O24 - 安全 - COOKIES: advertising.com - Restricted Cookies
O24 - 安全 - COOKIES: adviva.com - Restricted Cookies
O24 - 安全 - COOKIES: adviva.net - Restricted Cookies
O24 - 安全 - COOKIES: atdmt.com - Restricted Cookies
O24 - 安全 - COOKIES: bfast.com - Restricted Cookies
O24 - 安全 - COOKIES: bluemountain.com - Restricted Cookies
O24 - 安全 - COOKIES: brilliantdigital.com - Restricted Cookies
O24 - 安全 - COOKIES: centrport.com - Restricted Cookies
O24 - 安全 - COOKIES: clickagents.com - Restricted Cookies
O24 - 安全 - COOKIES: cometcursors.com - Restricted Cookies
O24 - 安全 - COOKIES: commission-junction.com - Restricted Cookies
O24 - 安全 - COOKIES: coremetrics.com - Restricted Cookies
O24 - 安全 - COOKIES: doubleclick.com - Restricted Cookies
O24 - 安全 - COOKIES: doubleclick.net - Restricted Cookies
O24 - 安全 - COOKIES: engage.com - Restricted Cookies
O24 - 安全 - COOKIES: enigmasoftwaregroup.com - Restricted Cookies
O24 - 安全 - COOKIES: excite.com - Restricted Cookies
O24 - 安全 - COOKIES: fastadvert.com - Restricted Cookies
O24 - 安全 - COOKIES: fastclick.com - Restricted Cookies
O24 - 安全 - COOKIES: fickenisgeil.de - Restricted Cookies
O24 - 安全 - COOKIES: flycast.com - Restricted Cookies
O24 - 安全 - COOKIES: freshgirls.com - Restricted Cookies
O24 - 安全 - COOKIES: hitbox.com - Restricted Cookies
O24 - 安全 - COOKIES: hitboxcentral.com - Restricted Cookies
O24 - 安全 - COOKIES: hitslink.com - Restricted Cookies
O24 - 安全 - COOKIES: linksynergy.com - Restricted Cookies
O24 - 安全 - COOKIES: lop.com - Restricted Cookies
O24 - 安全 - COOKIES: marketscore.com - Restricted Cookies
O24 - 安全 - COOKIES: mediaplex.com - Restricted Cookies
O24 - 安全 - COOKIES: offshoreclicks.com - Restricted
gototop
 

Cookies
O24 - 安全 - COOKIES: porntrack.com - Restricted Cookies
O24 - 安全 - COOKIES: qksrv.com - Restricted Cookies
O24 - 安全 - COOKIES: rccl.bridgetrack - Restricted Cookies
O24 - 安全 - COOKIES: redv.com - Restricted Cookies
O24 - 安全 - COOKIES: S005-01-4-11-234545-68181.com - Restricted Cookies
O24 - 安全 - COOKIES: servedby.advertising.com - Restricted Cookies
O24 - 安全 - COOKIES: servedfor.valuead.com - Restricted Cookies
O24 - 安全 - COOKIES: sexlist.com - Restricted Cookies
O24 - 安全 - COOKIES: sextracker.com - Restricted Cookies
O24 - 安全 - COOKIES: shopathomeselect.com - Restricted Cookies
O24 - 安全 - COOKIES: site.chatpoint.com - Restricted Cookies
O24 - 安全 - COOKIES: targetnet.com - Restricted Cookies
O24 - 安全 - COOKIES: travelocity.com - Restricted Cookies
O24 - 安全 - COOKIES: valueclick.com - Restricted Cookies
O24 - 安全 - COOKIES: webtrendslive.com - Restricted Cookies
O24 - 安全 - COOKIES: ad08.focalink.com - Restricted Cookies
O24 - 安全 - COOKIES: adbureau.com - Restricted Cookies
O24 - 安全 - COOKIES: admonitor.com - Restricted Cookies
O24 - 安全 - COOKIES: ads.enliven.com - Restricted Cookies
O24 - 安全 - COOKIES: advertising.com - Restricted Cookies
O24 - 安全 - COOKIES: adviva.com - Restricted Cookies
O24 - 安全 - COOKIES: adviva.net - Restricted Cookies
O24 - 安全 - COOKIES: atdmt.com - Restricted Cookies
O24 - 安全 - COOKIES: bfast.com - Restricted Cookies
O24 - 安全 - COOKIES: bluemountain.com - Restricted Cookies
O24 - 安全 - COOKIES: brilliantdigital.com - Restricted Cookies
O24 - 安全 - COOKIES: centrport.com - Restricted Cookies
O24 - 安全 - COOKIES: clickagents.com - Restricted Cookies
O24 - 安全 - COOKIES: cometcursors.com - Restricted Cookies
O24 - 安全 - COOKIES: commission-junction.com - Restricted Cookies
O24 - 安全 - COOKIES: coremetrics.com - Restricted Cookies
O24 - 安全 - COOKIES: doubleclick.com - Restricted Cookies
O24 - 安全 - COOKIES: doubleclick.net - Restricted Cookies
O24 - 安全 - COOKIES: engage.com - Restricted Cookies
O24 - 安全 - COOKIES: enigmasoftwaregroup.com - Restricted Cookies
O24 - 安全 - COOKIES: excite.com - Restricted Cookies
O24 - 安全 - COOKIES: fastadvert.com - Restricted Cookies
O24 - 安全 - COOKIES: fastclick.com - Restricted Cookies
O24 - 安全 - COOKIES: fickenisgeil.de - Restricted Cookies
O24 - 安全 - COOKIES: flycast.com - Restricted Cookies
O24 - 安全 - COOKIES: freshgirls.com - Restricted Cookies
O24 - 安全 - COOKIES: hitbox.com - Restricted Cookies
O24 - 安全 - COOKIES: hitboxcentral.com - Restricted Cookies
O24 - 安全 - COOKIES: hitslink.com - Restricted Cookies
O24 - 安全 - COOKIES: linksynergy.com - Restricted Cookies
O24 - 安全 - COOKIES: lop.com - Restricted Cookies
O24 - 安全 - COOKIES: marketscore.com - Restricted Cookies
O24 - 安全 - COOKIES: mediaplex.com - Restricted Cookies
O24 - 安全 - COOKIES: offshoreclicks.com - Restricted Cookies
O24 - 安全 - COOKIES: porntrack.com - Restricted Cookies
O24 - 安全 - COOKIES: qksrv.com - Restricted Cookies
O24 - 安全 - COOKIES: rccl.bridgetrack - Restricted Cookies
O24 - 安全 - COOKIES: redv.com - Restricted Cookies
O24 - 安全 - COOKIES: S005-01-4-11-234545-68181.com - Restricted Cookies
O24 - 安全 - COOKIES: servedby.advertising.com - Restricted Cookies
O24 - 安全 - COOKIES: servedfor.valuead.com - Restricted Cookies
O24 - 安全 - COOKIES: sexlist.com - Restricted Cookies
O24 - 安全 - COOKIES: sextracker.com - Restricted Cookies
O24 - 安全 - COOKIES: shopathomeselect.com - Restricted Cookies
O24 - 安全 - COOKIES: site.chatpoint.com - Restricted Cookies
O24 - 安全 - COOKIES: targetnet.com - Restricted Cookies
O24 - 安全 - COOKIES: travelocity.com - Restricted Cookies
O24 - 安全 - COOKIES: valueclick.com - Restricted Cookies
O24 - 安全 - COOKIES: webtrendslive.com - Restricted Cookies

=======================================
360Safe.exe=1.0.7.7007
AntiAdwa.dll=1.0.7.7007
AntiEng.dll=1.0.7.1001
AntiActi.dll=1.0.0.2002
CleanHis.dll=1.0.1.3003
safelive.exe=1.0.0.1002
live.dll=1.0.0.1007

=======================================
操作历史报告:
----------查杀恶意软件历史----------

2006-10-02 17:12
查杀恶意软件 - IEXPLORER木马 - 危险 -
查杀恶意软件 - Tray - 危险 - C:\WINDOWS\system32\tdll.dll
查杀恶意软件 - u1.sky99.cn - 危险 - C:\WINDOWS\rundl132.exe

2006-10-02 17:12
查杀恶意软件 - IEXPLORER木马 - 危险 -

2006-10-02 17:13
查杀恶意软件 - IEXPLORER木马 - 危险 -

2006-10-02 17:13
查杀恶意软件 - IEXPLORER木马 - 危险 -

2006-10-02 17:15
查杀恶意软件 - IEXPLORER木马 - 危险 -

2006-10-02 17:16
查杀恶意软件 - 网络实名 - 危险 -
查杀恶意软件 - 雅虎助手&上网助手 - 危险 -
查杀恶意软件 - IEXPLORER木马 - 危险 -

2006-10-02 17:17
查杀恶意软件 - IEXPLORER木马 - 危险 -

2006-10-02 17:41
查杀恶意软件 - IEXPLORER木马 - 危险 -

2006-10-02 17:52
查杀恶意软件 - IEXPLORER木马 - 危险 -

2006-10-02 17:56
查杀恶意软件 - IEXPLORER木马 - 危险 -

2006-10-02 22:29
查杀恶意软件 - 网络实名 - 危险 -
查杀恶意软件 - 雅虎助手&上网助手 - 危险 -
查杀恶意软件 - u1.sky99.cn - 危险 - C:\WINDOWS\rundl132.exe

2006-10-03 22:23
查杀恶意软件 - 网络实名 - 危险 -
查杀恶意软件 - 雅虎助手&上网助手 - 危险 -


----------插件卸载操作历史----------

2006-10-02 17:13
插件管理 - IEXPLORER木马 -
2006-10-02 17:17
插件管理 - IEXPLORER木马 -
2006-10-02 17:53
插件管理 - IEXPLORER木马 -
2006-10-02 17:53
插件管理 - IEXPLORER木马 -
2006-10-02 22:29
插件管理 - 腾讯QQ附带的QQIEHelper插件 - C:\PROGRA~1\Tencent\QQ\QQIEHE~1.DLL
2006-10-03 12:22
插件管理 - 超级兔子上网精灵 - D:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~1.DLL
2006-10-03 12:22
插件管理 - 腾讯QQ附带的QQIEHelper插件 -
2006-10-03 19:32
插件管理 - 腾讯QQ附带的QQIEHelper插件 -
2006-10-03 21:39
插件管理 - 腾讯QQ附带的QQIEHelper插件 -
2006-10-03 23:21
插件管理 - 腾讯QQ附带的QQIEHelper插件 -
2006-10-04 00:54
插件管理 - 腾讯QQ附带的QQIEHelper插件 -

----------全面诊断修复历史----------

2006-10-02 17:14
O4 - 危险 - rundll32 - rundll32 rscfg.dll s
2006-10-02 17:20
O4 - 危险 - rundll32 - rundll32 rscfg.dll s
2006-10-02 17:42
O4 - 危险 - rundll32 - rundll32 rscfg.dll s
2006-10-02 17:42
O4 - 危险 - rundll32 - rundll32 rscfg.dll s

----------一键修复操作历史----------

2006-10-02 17:14
O4 - 危险 - rundll32 - rundll32 rscfg.dll s

=======================================

360安全卫士,彻底查杀各种流氓软件,全面保护系统安全,并赠送正版卡巴斯基V6.0
最新免费下载:http://www.360safe.com
gototop
 

引用:
【我中了魔波的贴子】 这么多日志啊``真是全面``
………………

可是还没是没人来看~~
gototop
 

gototop
 

这下惨了,~~~昨天我发现有个人盗了我同学的QQ,他也承认了。我就骂了他一顿。他就问我是不是不服,我说是。然后过了一会,机子速度明显慢了下来,兔子还查出了恶意程序。qq自动退出,再登的时候就……………………5555555555555555555555555555555555555555555555555555555555555555
gototop
 

谢谢哥哥,俺这就去做
gototop
 
123   1  /  3  页   跳转
页面顶部
Powered by Discuz!NT