返回信息流RT,昨天起经常会自己跳出dos窗口,闪一下就没了,瑞星也启动不了,没有什么其他中都迹象。。不知道什么原因,希望达人能指点一下。。谢谢
这是一条镜像帖。来源:北邮人论坛 / security / #17948同步于 2008/6/11
该镜像源已超过 30 天没有更新,可能在源站已被删除。
Security机器人发帖
求助,瑞星打不开,经常会跳出dos窗口
K180
2008/6/11镜像同步12 回复
订阅后,新回复会通过你的通知中心匿名送达。
9 条回复
谢谢。是这个日志么
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
D:\TT\TT\TTraveler.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\CMMON32.EXE
D:\迅雷\Thunder\Program\Thunder5.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\taskmgr.exe
F:\hijackthis1.97_qoo\HijackThis.exe
O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - D:\
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Adobe Reader 7\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\realplayer11gold_cn\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {398C9B84-4EF7-47B5-9862-DE29543B3C42} - C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys (file missing)
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\
O2 - BHO: (no name) - {A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E} - C:\Program Files\Internet Explorer\IEXPLORE32.win (file missing)
O2 - BHO: (no name) - {C5E87A05-F463-4841-B19E-DD3EC3862368} - C:\Program Files\Internet Explorer\IEXPLORE32.Sys (file missing)
O2 - BHO: (no name) - {EE12D60D-AD9A-4095-B839-3BE6862679FD} - C:\Program Files\Internet Explorer\IEXPLORE32.Dat (file missing)
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Global Startup: ntuser.dat
O4 - Global Startup: ntuser.dat.LOG
O8 - Extra context menu item: 使用迅雷下载 - D:\
O8 - Extra context menu item: 使用迅雷下载全部链接 - D:\
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {6CF97BBD-55EC-4D30-B470-C8EE5D687217} (CUpdateCtrl Object) - http://www.lcread.com/UpDateATL.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7CBEC4A2-C2B1-4F3F-B558-88DCBA69BDD2}: NameServer = 211.71.128.6 211.71.128.30
谢谢版主了~又用那个扫描了一下,机子好像没有蓝屏过啊,就是最近会时不时跳个命令行窗口出来然后又一下没了,杀毒不仅瑞星启动不了,今天换卡巴也不行
CODE]
2008-06-11,18:45:39
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [(Verified)"RealNetworks, Inc."]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Science and Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><?粓?> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [(Verified)Beijing Rising Science and Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safe.exe]
<IFEO[360safe.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.exe]
<IFEO[360safebox.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe]
<IFEO[360tray.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe]
<IFEO[avp.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe]
<IFEO[CCenter.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rav.exe]
<IFEO[Rav.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMon.exe]
<IFEO[RavMon.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe]
<IFEO[RavMonD.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStub.exe]
<IFEO[RavStub.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe]
<IFEO[RavTask.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwcfg.exe]
<IFEO[rfwcfg.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwmain.exe]
<IFEO[rfwmain.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwProxy.exe]
<IFEO[rfwProxy.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe]
<IFEO[rfwsrv.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwstub.exe]
<IFEO[rfwstub.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe]
<IFEO[runiep.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxTray.exe]
<IFEO[safeboxTray.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmartUp.exe]
<IFEO[SmartUp.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<BigDogPath><; C:\WINDOWS\VM_STI.EXE USB PC Camera 301P> [N/A]
<DbgHlp32><; C:\WINDOWS\DbgHlp32.exe> [N/A]
<fmsiocps><; C:\WINDOWS\fmsiocps.exe> [N/A]
<Grid Service><; "C:\Program Files\GridService\peer.exe" -n Grid> [Mercury]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<msccrt><; C:\WINDOWS\msccrt.exe> [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ngmqeoxc><; C:\WINDOWS\gqoczdia.exe> [N/A]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
<SiSUSBRG><; C:\WINDOWS\SiSUSBrg.exe> [Silicon Integrated Systems Corp.]
<Smapp><; C:\Program Files\Analog Devices\SoundMAX\SMTray.exe> [Analog Devices, Inc.]
<ticisms><; C:\WINDOWS\ticisms.exe> [N/A]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [(Verified)"RealNetworks, Inc."]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<WinShell><; "C:\WINDOWS\system32\Rundll32.exe" "C:\WINDOWS\system32\shell32.dll",Control_RunDLL "c:\Temp\dat87.tmp"> [N/A]
==================================
启动文件夹
N/A
==================================
服务
[2FD78035 / 2FD78035][Stopped/Auto Start]
<C:\WINDOWS\system32\58D072ED.EXE -d><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[卡巴斯基网络代理 / klnagent][Running/Auto Start]
<"C:\Program Files\Kaspersky Lab\NetworkAgent\klnagent.exe"><Kaspersky Lab>
[Rising Process Communication Center / RsCCenter][Stopped/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Stopped/Auto Start]
<"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[Windows Media Connect Service / WMConnectCDS][Stopped/Manual Start]
<C:\Program Files\Windows Media Connect 2\wmccds.exe><Microsoft Corporation>
[Windows Driver Foundation - User-mode Driver Framework / WudfSvc][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup-->%SystemRoot%\System32\WUDFSvc.dll><Microsoft Corporation>
==================================
驱动程序
[aeaudio / aeaudio][Running/Manual Start]
<system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[HookCont / HookCont][Running/System Start]
<\SystemRoot\system32\drivers\HookCont.sys><Beijing Rising Technology Co., Ltd>
[HookNtos / HookNtos][Running/System Start]
<\SystemRoot\system32\drivers\HookNtos.sys><Beijing Rising Technology Co., Ltd>
[HookReg / HookReg][Running/System Start]
<\SystemRoot\system32\drivers\HookReg.sys><Beijing Rising Technology Co., Ltd>
[HookSys / HookSys][Running/System Start]
<\SystemRoot\system32\drivers\HookSys.sys><Beijing Rising Technology Co., Ltd>
[IIS Manager / IIS Manager ][Stopped/Manual Start]
<\??\c:\Temp\1.tmp><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[SiS315 / SiS315][Running/System Start]
<system32\DRIVERS\sisgrp.sys><Silicon Integrated Systems Corporation>
[SiS AGP Filter / SISAGP][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\SISAGPX.sys><Silicon Integrated Systems Corporation>
[SISCom_Com / SiSCom][Stopped/Manual Start]
<\??\G:\Drivers\Display\WinXP_2K\utilDLL\SiSCom.sys><N/A>
[SiS191/SiS190 Ethernet Device NDIS 5.1 Driver / SiSGbeXP][Running/Manual Start]
<system32\DRIVERS\SiSGbeXP.sys><Silicon Integrated Systems Corp.>
[SiSkp / SiSkp][Stopped/System Start]
<system32\DRIVERS\srvkp.sys><N/A>
[SiSRaid2 / SiSRaid2][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\SiSRaid2.sys><Silicon Integrated Systems>
[smwdm / smwdm][Running/Manual Start]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[Windows Driver Foundation - User-mode Driver Framework Platform Driver / WudfPf][Stopped/Manual Start]
<system32\DRIVERS\WudfPf.sys><Microsoft Corporation>
[Windows Driver Foundation - User-mode Driver Framework Reflector / WudfRd][Stopped/Manual Start]
<system32\DRIVERS\wudfrd.sys><Microsoft Corporation>
[USB PC Camera 301P / ZSMC301b][Stopped/Manual Start]
<System32\Drivers\usbVM31b.sys><VM>
==================================
浏览器加载项
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <D:\迅雷\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Adobe Reader 7\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[RealPlayer Download and Record Plugin for Internet Explorer]
{3049C3E9-B461-4BC5-8870-4C09146192CA} <D:\realplayer11gold_cn\rpbrowserrecordplugin.dll, RealPlayer>
[]
{398C9B84-4EF7-47B5-9862-DE29543B3C42} <C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys, N/A>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\迅雷\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[]
{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E} <C:\Program Files\Internet Explorer\IEXPLORE32.win, N/A>
[]
{C5E87A05-F463-4841-B19E-DD3EC3862368} <C:\Program Files\Internet Explorer\IEXPLORE32.Sys, N/A>
[]
{EE12D60D-AD9A-4095-B839-3BE6862679FD} <C:\Program Files\Internet Explorer\IEXPLORE32.Dat, N/A>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[CUpdateCtrl Object]
{6CF97BBD-55EC-4D30-B470-C8EE5D687217} <C:\WINDOWS\Downloaded Program Files\UpDateATL.dll, KingHoo Corporation>
[ThunderAtOnce Class]
{01443AEC-0FD1-40FD-9C87-E93D1494C233} <D:\迅雷\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Adobe Reader 7\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[PeerDraw Class]
{10072CEC-8CC1-11D1-986E-00A0C955B42E} <C:\Program Files\Common Files\Microsoft Shared\VGX\vgx.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[RealPlayer Download and Record Plugin for Internet Explorer]
{3049C3E9-B461-4BC5-8870-4C09146192CA} <D:\realplayer11gold_cn\rpbrowserrecordplugin.dll, RealPlayer>
[]
{398C9B84-4EF7-47B5-9862-DE29543B3C42} <C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys, N/A>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <D:\迅雷\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[XMP Class]
{6483F145-A768-4C41-AACC-52D4D7845851} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work, >
[XDRM]
{693571CB-54A3-4E90-9D52-EEAE1334E2D3} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xdrm.dll_1_work, >
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\迅雷\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[]
{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E} <C:\Program Files\Internet Explorer\IEXPLORE32.win, N/A>
[RMGetLicense Class]
{A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[]
{C5E87A05-F463-4841-B19E-DD3EC3862368} <C:\Program Files\Internet Explorer\IEXPLORE32.Sys, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx, Adobe Systems, Inc.>
[]
{EE12D60D-AD9A-4095-B839-3BE6862679FD} <C:\Program Files\Internet Explorer\IEXPLORE32.Dat, N/A>
[XPPlayer Class]
{F3E70CEA-956E-49CC-B444-73AFE593AD7F} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\pplayer.dll_1_work, Thunder>
[使用迅雷下载]
<D:\迅雷\Thunder\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
<D:\迅雷\Thunder\Program\getallurl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
==================================
正在运行的进程
[PID: 648 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 720 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 744 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0]
[D:\sogo\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 788 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 800 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 956 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1032 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1136 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1184 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1300 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1556 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0]
[D:\sogo\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31]
[D:\迅雷\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.16]
[D:\Adobe Reader 7\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.5.2005092300]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[D:\迅雷\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 61]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\WPDShServiceObj.dll] [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
[C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
[C:\WINDOWS\system32\PortableDeviceTypes.dll] [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[D:\Adobe Reader 7\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17]
[D:\WinRAR v3.40.中文版\rarext.dll] [N/A, ]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[D:\10\ACDSee\picaview.dll] [ACD Systems, Ltd., 2, 0, 0, 78]
[D:\10\ACDSee\PlugIns\IDE_ACDStd.apl] [ACD Systems, Ltd., 3,0,31,0]
[C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[C:\WINDOWS\system32\wpdshext.dll] [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
[PID: 1736 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.1897.0]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.1897.0]
[PID: 1896 / Administrator][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.4279]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0]
[PID: 1932 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0]
[PID: 188 / SYSTEM][C:\Program Files\Kaspersky Lab\NetworkAgent\klnagent.exe] [Kaspersky Lab, 6.0.1405.0]
[C:\Program Files\Kaspersky Lab\NetworkAgent\klcsrt.dll] [STLport Consulting, Inc., 4.6.2003.1031]
[C:\Program Files\Kaspersky Lab\NetworkAgent\klcsagt.dll] [Kaspersky Lab, 6.0.1405.0]
[C:\Program Files\Kaspersky Lab\NetworkAgent\klcsstd.dll] [Kaspersky Lab, 6.0.1405.0]
[C:\Program Files\Kaspersky Lab\NetworkAgent\FSSync.dll] [Kaspersky Lab, 6.0.1405.0]
[C:\Program Files\Kaspersky Lab\NetworkAgent\LIBEAY32.dll] [OpenSSL, 9, 7, 0, 1]
[C:\Program Files\Kaspersky Lab\NetworkAgent\klcstr.dll] [Kaspersky Lab, 6.0.1405.0]
[C:\Program Files\Kaspersky Lab\NetworkAgent\SSLEAY32.dll] [OpenSSL, 9, 7, 0, 1]
[C:\Program Files\Kaspersky Lab\NetworkAgent\klcskca.dll] [Kaspersky Lab, 6.0.1405.0]
[C:\Program Files\Kaspersky Lab\NetworkAgent\klcsnagt.dll] [Kaspersky Lab, 6.0.1405.0]
[C:\Program Files\Kaspersky Lab\NetworkAgent\cleanapi.dll] [Kaspersky Lab, 1.0.24.0]
[C:\Program Files\Kaspersky Lab\NetworkAgent\klsecur2.dll] [Kaspersky Lab, 6.0.1405.0]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 244 / SYSTEM][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] [Analog Devices, Inc., 3, 2, 6, 0]
[PID: 324 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1240 / Administrator][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0]
[PID: 220 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1920 / Administrator][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1480 / Administrator][C:\WINDOWS\system32\CMMON32.EXE] [Microsoft Corporation, 7.02.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0]
[D:\sogo\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31]
[PID: 1472 / Administrator][D:\TT\TT\TTraveler.exe] [腾讯公司, 2, 2, 0, 224]
[D:\TT\TT\dbghelp.dll] [Microsoft Corporation, 6.3.0005.1 (DbgBuild.030922-1449)]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0]
[D:\sogo\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31]
[D:\TT\TT\Plugins\TWeather\TWeather.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[D:\TT\TT\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 4]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1632 / Administrator][D:\迅雷\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5.7.7.441]
[D:\迅雷\Thunder\Program\BugReport.dll] [迅雷网络, 1, 0, 1, 4]
[D:\迅雷\Thunder\Program\ThunderEx.dll] [, 1, 2, 3, 20]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0]
[D:\sogo\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31]
[D:\迅雷\Thunder\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 3, 1, 56]
[D:\迅雷\Thunder\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 2, 21, 2, 217]
[D:\迅雷\Thunder\Program\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031]
[D:\迅雷\Thunder\Program\asyn_dns.dll] [Thunder Networking Technologies,LTD, 2, 21, 2, 217]
[D:\迅雷\Thunder\Program\streammedialib.dll] [, 1, 3, 2, 118]
[D:\迅雷\Thunder\Program\al.dll] [, 1, 0, 1, 3]
[D:\迅雷\Thunder\Program\xldc.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 14]
[D:\迅雷\Thunder\Program\bd.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 6]
[D:\迅雷\Thunder\Program\XLNet.Dll] [Thunder Networking Technologies,LTD, 1, 3, 4, 18]
[D:\迅雷\Thunder\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 1, 0, 8]
[D:\迅雷\Thunder\Program\FloatBar.dll] [Giganology Inc., 1, 0, 0, 2]
[D:\迅雷\Thunder\Components\DownAndPlay\DownAndPlay.dll] [, 1, 0, 8, 26]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[D:\迅雷\Thunder\Program\iTargetAD.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[D:\迅雷\Thunder\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 1, 5, 0, 16]
[D:\迅雷\Thunder\Program\XLCommunityEx.dll] [N/A, ]
[D:\迅雷\Thunder\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 16, 5, 63]
[D:\迅雷\Thunder\Program\MSVCIRT.dll] [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\迅雷\Thunder\Components\Security\ThunderSafe.dll] [深圳市迅雷网络技术有限公司, 1, 0, 7, 71]
[D:\迅雷\Thunder\Program\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0]
[D:\迅雷\Thunder\Components\Security\XLSafeUI.dll] [深圳市迅雷网络技术有限公司, 1, 0, 7, 71]
[D:\迅雷\Thunder\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 1, 6, 20]
[D:\迅雷\Thunder\Plugins\XLSafeHost\XLSafeHost.dll] [深圳市迅雷网络技术有限公司, 1, 0, 7, 57]
[D:\迅雷\Thunder\Plugins\XLSafeHost\ThunderRAV\bin\rsscan.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[D:\迅雷\Thunder\Components\ExplorerHelper\ExplorerHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 16]
[D:\迅雷\Thunder\ComDlls\ThunderAgent_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 4, 23]
[D:\迅雷\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 61]
[D:\迅雷\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.16]
[D:\迅雷\Thunder\Components\Tips\TipsClient.dll] [Thunder Networking Technologies,LTD, 2, 2, 11, 106]
[D:\迅雷\Thunder\Components\DownloadStat\DownloadStat.dll] [深圳市迅雷网络技术有限公司, 1, 3, 1, 4]
[D:\迅雷\Thunder\Components\Tips\XLIPC.DLL] [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
[PID: 3844 / Administrator][D:\realplayer11gold_cn\realplay.exe] [RealNetworks, Inc., 11.0.0.372]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0]
[C:\Program Files\Common Files\Real\Common\objb3201.dll] [RealNetworks, Inc., 0.1.0.7455]
[D:\realplayer11gold_cn\rpplugins\rpap3260.dll] [RealNetworks, Inc., 6.0.14.748]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\Program Files\Common Files\Real\Common\pnrs3260.dll] [RealNetworks, Inc., 6.0.9.4840]
[D:\realplayer11gold_cn\lang\cdplay_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\dbcomp_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\embed_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\gemctl_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\pngui_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\pdgenxfer_cn.dll] [N/A, ]
[D:\realplayer11gold_cn\lang\rjctl_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rjeq_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rjres_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rjskin_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rjviz_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rjfade_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rjdlg_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rjmisc_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rjprog_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rjwma_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rpapp_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rpclsvc_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rpclutil_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rpdemand_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rpdsplyr_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rpgutil_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rpmnpane_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rpplylst_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\rpwebctl_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\tcdinfo_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\tclsvc_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\tdwnmgr_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\tmp3_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\twave_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\teasdk_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\tearm_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\tmdedit_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\upgrdlib_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\lang\mydevices_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[D:\realplayer11gold_cn\rpplugins\rpcl3260.dll] [RealNetworks, Inc., 6.0.9.3877]
[C:\Program Files\Common Files\Real\RCAPlugins\uisy3201.dll] [RealNetworks, Inc., 0.1.0.4601]
[C:\Program Files\Common Files\Real\Plugins\zipf3260.dll] [RealNetworks, Inc., 6.0.8.3308]
[C:\Program Files\Common Files\Real\RCAPlugins\rpcontrols1.dll] [RealNetworks, Inc., 6.0.1.2995]
[C:\Program Files\Common Files\Real\Plugins\pxcb3210.dll] [RealNetworks, Inc., 1.0.0.4758]
[D:\realplayer11gold_cn\rpplugins\rpmn3260.dll] [RealNetworks, Inc., 6.0.9.3704]
[C:\Program Files\Common Files\Real\RCAPlugins\rpcontrols2.dll] [RealNetworks, 6.0.1.2995]
[C:\Program Files\Common Files\Real\RCAPlugins\gema3201.dll] [RealNetworks, Inc., 0.1.0.4580]
[D:\realplayer11gold_cn\rpplugins\rpwe3260.dll] [RealNetworks, Inc., 6.0.1.3045]
[D:\realplayer11gold_cn\rpplugins\rjbc3260.dll] [RealNetworks, Inc., 6.0.1.3049]
[C:\Program Files\Common Files\Real\Common\pngu3267.dll] [RealNetworks, Inc., 6.7.0.3485]
[D:\sogo\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31]
[D:\realplayer11gold_cn\rpplugins\rpms3260.dll] [RealNetworks, Inc., 6.0.1.3039]
[D:\realplayer11gold_cn\rpplugins\MPACore.dll] [RealNetworks, Inc., 1.0.3.3058]
[C:\Program Files\Common Files\Real\RCAPlugins\gemx3201.dll] [RealNetworks, Inc., 0.1.0.6637]
[D:\realplayer11gold_cn\rpplugins\myde3260.dll] [RealNetworks, Inc., 6.0.10.3270]
[C:\Program Files\Common Files\Real\Common\pnen3260.dll] [ , 10.0.0.6773]
[C:\Program Files\Common Files\Real\Plugins\vsrlocal.dll] [ , 10.1.0.142]
[C:\Program Files\Common Files\Real\Plugins\vidsite.dll] [ , 10.0.0.6049]
[C:\Program Files\Common Files\Real\Plugins\clntxres.dll] [ , 10.0.0.18137]
[D:\realplayer11gold_cn\rpplugins\rjbe3260.dll] [RealNetworks, Inc., 6.0.4.3044]
[C:\Program Files\Common Files\Real\Plugins\smplfsys.dll] [ , 10.0.0.15514]
[C:\Program Files\Common Files\Real\Plugins\ramfformat.dll] [ , 10.0.0.12522]
[C:\Program Files\Common Files\Real\Plugins\mp3render.dll] [ , 10.0.0.4425]
[C:\Program Files\Common Files\Real\Common\rjbviz.dll] [RealNetworks, Inc., 1.0.2.4662]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[D:\realplayer11gold_cn\HXAudioDeviceHook.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\Program Files\Common Files\Real\Codecs\colorcvt.dll] [ , 10.0.1.0]
[C:\Program Files\Common Files\Real\Visualizations\AKWLyric_Real_br.rpv] [KWLyric_WMP, 1, 0, 0, 1]
[C:\WINDOWS\system32\hpbr.dll] [N/A, ]
[D:\realplayer11gold_cn\dbghelp.dll] [Microsoft Corporation, 6.0.0017.0 (DbgBuild.020528-1721)]
[c:\windows\system32\mfplat.dll] [Microsoft Corporation, 11.0.5358.4827 (WMP_11.060509-2009)]
[C:\Program Files\Common Files\Real\Common\twebbrowse.dll] [RealNetworks, Inc., 1.0.2.2364]
[D:\realplayer11gold_cn\rpbrowserrecordplugin.dll] [RealPlayer, 1.0.0.522]
[D:\realplayer11gold_cn\lang\rpbrp_cn.dll] [RealNetworks, Inc., 6.0.14.0]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[C:\Program Files\Common Files\Real\Update_OB\rnad3201.dll] [RealNetworks, Inc., 0.1.0.4279]
[C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx] [Adobe Systems, Inc., 9,0,115,0]
[PID: 3920 / Administrator][F:\sreng2\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0]
[D:\sogo\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31]
[F:\sreng2\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 188, C:\PROGRAM FILES\KASPERSKY LAB\NETWORKAGENT\KLNAGENT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1472, D:\TT\TT\TTRAVELER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1632, D:\迅雷\THUNDER\PROGRAM\THUNDER5.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
【 在 rebirthatsix 的大作中提到: 】
: 我先看下,你用置顶里的sreng2再扫描一下,这个hijack的不全
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safe.exe]
<IFEO[360safe.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.exe]
<IFEO[360safebox.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe]
<IFEO[360tray.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe]
<IFEO[avp.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe]
<IFEO[CCenter.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rav.exe]
<IFEO[Rav.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMon.exe]
<IFEO[RavMon.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe]
<IFEO[RavMonD.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStub.exe]
<IFEO[RavStub.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe]
<IFEO[RavTask.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwcfg.exe]
<IFEO[rfwcfg.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwmain.exe]
<IFEO[rfwmain.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwProxy.exe]
<IFEO[rfwProxy.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe]
<IFEO[rfwsrv.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwstub.exe]
<IFEO[rfwstub.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe]
<IFEO[runiep.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxTray.exe]
<IFEO[safeboxTray.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmartUp.exe]
<IFEO[SmartUp.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
首先,这些项被修改了,这个东西就是造成你杀毒软件无法启动的原因,比较容易理解的说法就是他把上面这些注册表项中第一个exe的运行实际镜像替换成了后面的taskman.exe,而这前面的exe就包括了ravxxx.exe(瑞星),kavxxx.exe(卡巴)等等,所以运行这些东西都会导致实际开启的是taskman.exe,这个也极有可能就是你说的黑窗口
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<DbgHlp32><; C:\WINDOWS\DbgHlp32.exe> [N/A]
<fmsiocps><; C:\WINDOWS\fmsiocps.exe> [N/A]
<msccrt><; C:\WINDOWS\msccrt.exe> [N/A]
然后就是这3个,都不是什么正常的启动项
还有这个
服务
[2FD78035 / 2FD78035][Stopped/Auto Start]
<C:\WINDOWS\system32\58D072ED.EXE -d><N/A> 这个100%是木马
解决方法:首先保证你的进程列表里没有以上这些项目中包含的exe,如果有,一概结束
然后在保证都结束的前提下,把上面列出的项目依次用sreng2删除,注册表用注册表启动项来删除,或者直接开regedit.exe找对应的地方手动删除,服务的话sreng2里有专门管理服务的功能,也可以在里面删除
多谢版主了,辛苦了^_^
要停止再删除是下边的这三项,上边注册表中的项,跟那个服务是吧
<DbgHlp32><; C:\WINDOWS\DbgHlp32.exe> [N/A]
<fmsiocps><; C:\WINDOWS\fmsiocps.exe> [N/A]
<msccrt><; C:\WINDOWS\msccrt.exe> [N/
【 在 rebirthatsix 的大作中提到: 】
: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safe.exe]
: <IFEO[360safe.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.exe]
: ...................
【 在 K180 的大作中提到: 】
: 多谢版主了,辛苦了^_^
: 要停止再删除是下边的这三项,上边注册表中的项,跟那个服务是吧
: <DbgHlp32><; C:\WINDOWS\DbgHlp32.exe> [N/A]
: ...................
对,先停止,不停止的话很可能你删除了之后它们会再写回去
进程里边我看了一下没有这些,这样就不用再停止了吧
【 在 rebirthatsix 的大作中提到: 】
: 对,先停止,不停止的话很可能你删除了之后它们会再写回去