BBYR Achieve
返回信息流
这是一条镜像帖。来源:北邮人论坛 / security / #17948同步于 2008/6/11
该镜像源已超过 30 天没有更新,可能在源站已被删除。
Security机器人发帖

求助,瑞星打不开,经常会跳出dos窗口

K180
2008/6/11镜像同步12 回复
RT,昨天起经常会自己跳出dos窗口,闪一下就没了,瑞星也启动不了,没有什么其他中都迹象。。不知道什么原因,希望达人能指点一下。。谢谢
订阅后,新回复会通过你的通知中心匿名送达。
9 条回复
rebirthatsix机器人#1 · 2008/6/11
看置顶,贴日志
K180机器人#2 · 2008/6/11
谢谢。是这个日志么 Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe D:\TT\TT\TTraveler.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\CMMON32.EXE D:\迅雷\Thunder\Program\Thunder5.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\WINDOWS\system32\taskmgr.exe F:\hijackthis1.97_qoo\HijackThis.exe O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - D:\ O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Adobe Reader 7\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\realplayer11gold_cn\rpbrowserrecordplugin.dll O2 - BHO: (no name) - {398C9B84-4EF7-47B5-9862-DE29543B3C42} - C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys (file missing) O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\ O2 - BHO: (no name) - {A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E} - C:\Program Files\Internet Explorer\IEXPLORE32.win (file missing) O2 - BHO: (no name) - {C5E87A05-F463-4841-B19E-DD3EC3862368} - C:\Program Files\Internet Explorer\IEXPLORE32.Sys (file missing) O2 - BHO: (no name) - {EE12D60D-AD9A-4095-B839-3BE6862679FD} - C:\Program Files\Internet Explorer\IEXPLORE32.Dat (file missing) O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: NTUSER.DAT O4 - Startup: ntuser.dat.LOG O4 - Startup: ntuser.ini O4 - Global Startup: ntuser.dat O4 - Global Startup: ntuser.dat.LOG O8 - Extra context menu item: 使用迅雷下载 - D:\ O8 - Extra context menu item: 使用迅雷下载全部链接 - D:\ O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O16 - DPF: {6CF97BBD-55EC-4D30-B470-C8EE5D687217} (CUpdateCtrl Object) - http://www.lcread.com/UpDateATL.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{7CBEC4A2-C2B1-4F3F-B558-88DCBA69BDD2}: NameServer = 211.71.128.6 211.71.128.30
rebirthatsix机器人#3 · 2008/6/11
我先看下,你用置顶里的sreng2再扫描一下,这个hijack的不全
rebirthatsix机器人#4 · 2008/6/11
看起来你的机器蓝屏过阿,难道是2b瑞星的驱动
K180机器人#5 · 2008/6/11
谢谢版主了~又用那个扫描了一下,机子好像没有蓝屏过啊,就是最近会时不时跳个命令行窗口出来然后又一下没了,杀毒不仅瑞星启动不了,今天换卡巴也不行 CODE] 2008-06-11,18:45:39 System Repair Engineer 2.5.16.900 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <load><> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [(Verified)"RealNetworks, Inc."] <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A] <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Science and Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] <shell><Explorer.exe> [(Verified)Microsoft Windows Publisher] <Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <AppInit_DLLs><?粓?> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [(Verified)Beijing Rising Science and Technology Corporation Limited] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safe.exe] <IFEO[360safe.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.exe] <IFEO[360safebox.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe] <IFEO[360tray.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe] <IFEO[avp.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe] <IFEO[CCenter.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rav.exe] <IFEO[Rav.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMon.exe] <IFEO[RavMon.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe] <IFEO[RavMonD.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStub.exe] <IFEO[RavStub.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe] <IFEO[RavTask.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwcfg.exe] <IFEO[rfwcfg.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwmain.exe] <IFEO[rfwmain.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwProxy.exe] <IFEO[rfwProxy.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe] <IFEO[rfwsrv.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwstub.exe] <IFEO[rfwstub.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe] <IFEO[runiep.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxTray.exe] <IFEO[safeboxTray.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmartUp.exe] <IFEO[SmartUp.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <BigDogPath><; C:\WINDOWS\VM_STI.EXE USB PC Camera 301P> [N/A] <DbgHlp32><; C:\WINDOWS\DbgHlp32.exe> [N/A] <fmsiocps><; C:\WINDOWS\fmsiocps.exe> [N/A] <Grid Service><; "C:\Program Files\GridService\peer.exe" -n Grid> [Mercury] <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher] <IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation] <msccrt><; C:\WINDOWS\msccrt.exe> [N/A] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <ngmqeoxc><; C:\WINDOWS\gqoczdia.exe> [N/A] <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher] <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher] <SiSUSBRG><; C:\WINDOWS\SiSUSBrg.exe> [Silicon Integrated Systems Corp.] <Smapp><; C:\Program Files\Analog Devices\SoundMAX\SMTray.exe> [Analog Devices, Inc.] <ticisms><; C:\WINDOWS\ticisms.exe> [N/A] <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [(Verified)"RealNetworks, Inc."] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <WinShell><; "C:\WINDOWS\system32\Rundll32.exe" "C:\WINDOWS\system32\shell32.dll",Control_RunDLL "c:\Temp\dat87.tmp"> [N/A] ================================== 启动文件夹 N/A ================================== 服务 [2FD78035 / 2FD78035][Stopped/Auto Start] <C:\WINDOWS\system32\58D072ED.EXE -d><N/A> [Human Interface Device Access / HidServ][Stopped/Disabled] <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A> [卡巴斯基网络代理 / klnagent][Running/Auto Start] <"C:\Program Files\Kaspersky Lab\NetworkAgent\klnagent.exe"><Kaspersky Lab> [Rising Process Communication Center / RsCCenter][Stopped/Auto Start] <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.> [SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start] <C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.> [Windows Media Connect Service / WMConnectCDS][Stopped/Manual Start] <C:\Program Files\Windows Media Connect 2\wmccds.exe><Microsoft Corporation> [Windows Driver Foundation - User-mode Driver Framework / WudfSvc][Stopped/Manual Start] <C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup-->%SystemRoot%\System32\WUDFSvc.dll><Microsoft Corporation> ================================== 驱动程序 [aeaudio / aeaudio][Running/Manual Start] <system32\drivers\aeaudio.sys><Andrea Electronics Corporation> [HookCont / HookCont][Running/System Start] <\SystemRoot\system32\drivers\HookCont.sys><Beijing Rising Technology Co., Ltd> [HookNtos / HookNtos][Running/System Start] <\SystemRoot\system32\drivers\HookNtos.sys><Beijing Rising Technology Co., Ltd> [HookReg / HookReg][Running/System Start] <\SystemRoot\system32\drivers\HookReg.sys><Beijing Rising Technology Co., Ltd> [HookSys / HookSys][Running/System Start] <\SystemRoot\system32\drivers\HookSys.sys><Beijing Rising Technology Co., Ltd> [IIS Manager / IIS Manager ][Stopped/Manual Start] <\??\c:\Temp\1.tmp><N/A> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.> [Secdrv / Secdrv][Stopped/Manual Start] <system32\DRIVERS\secdrv.sys><N/A> [SiS315 / SiS315][Running/System Start] <system32\DRIVERS\sisgrp.sys><Silicon Integrated Systems Corporation> [SiS AGP Filter / SISAGP][Running/Boot Start] <\SystemRoot\system32\DRIVERS\SISAGPX.sys><Silicon Integrated Systems Corporation> [SISCom_Com / SiSCom][Stopped/Manual Start] <\??\G:\Drivers\Display\WinXP_2K\utilDLL\SiSCom.sys><N/A> [SiS191/SiS190 Ethernet Device NDIS 5.1 Driver / SiSGbeXP][Running/Manual Start] <system32\DRIVERS\SiSGbeXP.sys><Silicon Integrated Systems Corp.> [SiSkp / SiSkp][Stopped/System Start] <system32\DRIVERS\srvkp.sys><N/A> [SiSRaid2 / SiSRaid2][Running/Boot Start] <\SystemRoot\system32\DRIVERS\SiSRaid2.sys><Silicon Integrated Systems> [smwdm / smwdm][Running/Manual Start] <system32\drivers\smwdm.sys><Analog Devices, Inc.> [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start] <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation> [Windows Driver Foundation - User-mode Driver Framework Platform Driver / WudfPf][Stopped/Manual Start] <system32\DRIVERS\WudfPf.sys><Microsoft Corporation> [Windows Driver Foundation - User-mode Driver Framework Reflector / WudfRd][Stopped/Manual Start] <system32\DRIVERS\wudfrd.sys><Microsoft Corporation> [USB PC Camera 301P / ZSMC301b][Stopped/Manual Start] <System32\Drivers\usbVM31b.sys><VM> ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} <D:\迅雷\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD> [AcroIEHlprObj Class] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Adobe Reader 7\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated> [RealPlayer Download and Record Plugin for Internet Explorer] {3049C3E9-B461-4BC5-8870-4C09146192CA} <D:\realplayer11gold_cn\rpbrowserrecordplugin.dll, RealPlayer> [] {398C9B84-4EF7-47B5-9862-DE29543B3C42} <C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys, N/A> [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\迅雷\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD> [] {A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E} <C:\Program Files\Internet Explorer\IEXPLORE32.win, N/A> [] {C5E87A05-F463-4841-B19E-DD3EC3862368} <C:\Program Files\Internet Explorer\IEXPLORE32.Sys, N/A> [] {EE12D60D-AD9A-4095-B839-3BE6862679FD} <C:\Program Files\Internet Explorer\IEXPLORE32.Dat, N/A> [信息检索(&R)] {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation> [Messenger] {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation> [CUpdateCtrl Object] {6CF97BBD-55EC-4D30-B470-C8EE5D687217} <C:\WINDOWS\Downloaded Program Files\UpDateATL.dll, KingHoo Corporation> [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} <D:\迅雷\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD> [AcroIEHlprObj Class] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Adobe Reader 7\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated> [PeerDraw Class] {10072CEC-8CC1-11D1-986E-00A0C955B42E} <C:\Program Files\Common Files\Microsoft Shared\VGX\vgx.dll, Microsoft Corporation> [HTML Document] {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A> [DHTML Edit Control Safe for Scripting for IE5] {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation> [RealPlayer Download and Record Plugin for Internet Explorer] {3049C3E9-B461-4BC5-8870-4C09146192CA} <D:\realplayer11gold_cn\rpbrowserrecordplugin.dll, RealPlayer> [] {398C9B84-4EF7-47B5-9862-DE29543B3C42} <C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys, N/A> [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <D:\迅雷\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD> [XMP Class] {6483F145-A768-4C41-AACC-52D4D7845851} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work, > [XDRM] {693571CB-54A3-4E90-9D52-EEAE1334E2D3} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xdrm.dll_1_work, > [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation> [Microsoft Web 浏览器] {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation> [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\迅雷\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD> [] {A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E} <C:\Program Files\Internet Explorer\IEXPLORE32.win, N/A> [RMGetLicense Class] {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation> [SearchAssistantOC] {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A> [RDS.DataSpace] {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation> [] {C5E87A05-F463-4841-B19E-DD3EC3862368} <C:\Program Files\Internet Explorer\IEXPLORE32.Sys, N/A> [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx, Adobe Systems, Inc.> [] {EE12D60D-AD9A-4095-B839-3BE6862679FD} <C:\Program Files\Internet Explorer\IEXPLORE32.Dat, N/A> [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\pplayer.dll_1_work, Thunder> [使用迅雷下载] <D:\迅雷\Thunder\Program\geturl.htm, N/A> [使用迅雷下载全部链接] <D:\迅雷\Thunder\Program\getallurl.htm, N/A> [导出到 Microsoft Office Excel(&X)] <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A> ================================== 正在运行的进程 [PID: 648 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 720 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 744 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0] [D:\sogo\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 788 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 800 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 956 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 1032 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 1136 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 1184 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 1300 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 1556 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0] [D:\sogo\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31] [D:\迅雷\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.16] [D:\Adobe Reader 7\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.5.2005092300] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [D:\迅雷\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 61] [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] [C:\WINDOWS\system32\WPDShServiceObj.dll] [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)] [C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)] [C:\WINDOWS\system32\PortableDeviceTypes.dll] [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [D:\Adobe Reader 7\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17] [D:\WinRAR v3.40.中文版\rarext.dll] [N/A, ] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [D:\10\ACDSee\picaview.dll] [ACD Systems, Ltd., 2, 0, 0, 78] [D:\10\ACDSee\PlugIns\IDE_ACDStd.apl] [ACD Systems, Ltd., 3,0,31,0] [C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305] [C:\WINDOWS\system32\wpdshext.dll] [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)] [C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)] [PID: 1736 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.1897.0] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.1897.0] [PID: 1896 / Administrator][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.4279] [C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0] [PID: 1932 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0] [PID: 188 / SYSTEM][C:\Program Files\Kaspersky Lab\NetworkAgent\klnagent.exe] [Kaspersky Lab, 6.0.1405.0] [C:\Program Files\Kaspersky Lab\NetworkAgent\klcsrt.dll] [STLport Consulting, Inc., 4.6.2003.1031] [C:\Program Files\Kaspersky Lab\NetworkAgent\klcsagt.dll] [Kaspersky Lab, 6.0.1405.0] [C:\Program Files\Kaspersky Lab\NetworkAgent\klcsstd.dll] [Kaspersky Lab, 6.0.1405.0] [C:\Program Files\Kaspersky Lab\NetworkAgent\FSSync.dll] [Kaspersky Lab, 6.0.1405.0] [C:\Program Files\Kaspersky Lab\NetworkAgent\LIBEAY32.dll] [OpenSSL, 9, 7, 0, 1] [C:\Program Files\Kaspersky Lab\NetworkAgent\klcstr.dll] [Kaspersky Lab, 6.0.1405.0] [C:\Program Files\Kaspersky Lab\NetworkAgent\SSLEAY32.dll] [OpenSSL, 9, 7, 0, 1] [C:\Program Files\Kaspersky Lab\NetworkAgent\klcskca.dll] [Kaspersky Lab, 6.0.1405.0] [C:\Program Files\Kaspersky Lab\NetworkAgent\klcsnagt.dll] [Kaspersky Lab, 6.0.1405.0] [C:\Program Files\Kaspersky Lab\NetworkAgent\cleanapi.dll] [Kaspersky Lab, 1.0.24.0] [C:\Program Files\Kaspersky Lab\NetworkAgent\klsecur2.dll] [Kaspersky Lab, 6.0.1405.0] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 244 / SYSTEM][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] [Analog Devices, Inc., 3, 2, 6, 0] [PID: 324 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 1240 / Administrator][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0] [PID: 220 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 1920 / Administrator][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 1480 / Administrator][C:\WINDOWS\system32\CMMON32.EXE] [Microsoft Corporation, 7.02.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0] [D:\sogo\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31] [PID: 1472 / Administrator][D:\TT\TT\TTraveler.exe] [腾讯公司, 2, 2, 0, 224] [D:\TT\TT\dbghelp.dll] [Microsoft Corporation, 6.3.0005.1 (DbgBuild.030922-1449)] [C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0] [D:\sogo\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31] [D:\TT\TT\Plugins\TWeather\TWeather.dll] [, 1, 0, 0, 1] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [D:\TT\TT\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 4] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 1632 / Administrator][D:\迅雷\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5.7.7.441] [D:\迅雷\Thunder\Program\BugReport.dll] [迅雷网络, 1, 0, 1, 4] [D:\迅雷\Thunder\Program\ThunderEx.dll] [, 1, 2, 3, 20] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0] [D:\sogo\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31] [D:\迅雷\Thunder\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 3, 1, 56] [D:\迅雷\Thunder\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 2, 21, 2, 217] [D:\迅雷\Thunder\Program\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031] [D:\迅雷\Thunder\Program\asyn_dns.dll] [Thunder Networking Technologies,LTD, 2, 21, 2, 217] [D:\迅雷\Thunder\Program\streammedialib.dll] [, 1, 3, 2, 118] [D:\迅雷\Thunder\Program\al.dll] [, 1, 0, 1, 3] [D:\迅雷\Thunder\Program\xldc.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 14] [D:\迅雷\Thunder\Program\bd.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 6] [D:\迅雷\Thunder\Program\XLNet.Dll] [Thunder Networking Technologies,LTD, 1, 3, 4, 18] [D:\迅雷\Thunder\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 1, 0, 8] [D:\迅雷\Thunder\Program\FloatBar.dll] [Giganology Inc., 1, 0, 0, 2] [D:\迅雷\Thunder\Components\DownAndPlay\DownAndPlay.dll] [, 1, 0, 8, 26] [C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [D:\迅雷\Thunder\Program\iTargetAD.dll] [N/A, ] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [D:\迅雷\Thunder\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 1, 5, 0, 16] [D:\迅雷\Thunder\Program\XLCommunityEx.dll] [N/A, ] [D:\迅雷\Thunder\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 16, 5, 63] [D:\迅雷\Thunder\Program\MSVCIRT.dll] [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)] [D:\迅雷\Thunder\Components\Security\ThunderSafe.dll] [深圳市迅雷网络技术有限公司, 1, 0, 7, 71] [D:\迅雷\Thunder\Program\ATL71.DLL] [Microsoft Corporation, 7.10.3077.0] [D:\迅雷\Thunder\Components\Security\XLSafeUI.dll] [深圳市迅雷网络技术有限公司, 1, 0, 7, 71] [D:\迅雷\Thunder\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 1, 6, 20] [D:\迅雷\Thunder\Plugins\XLSafeHost\XLSafeHost.dll] [深圳市迅雷网络技术有限公司, 1, 0, 7, 57] [D:\迅雷\Thunder\Plugins\XLSafeHost\ThunderRAV\bin\rsscan.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [D:\迅雷\Thunder\Components\ExplorerHelper\ExplorerHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 16] [D:\迅雷\Thunder\ComDlls\ThunderAgent_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 4, 23] [D:\迅雷\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 61] [D:\迅雷\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.16] [D:\迅雷\Thunder\Components\Tips\TipsClient.dll] [Thunder Networking Technologies,LTD, 2, 2, 11, 106] [D:\迅雷\Thunder\Components\DownloadStat\DownloadStat.dll] [深圳市迅雷网络技术有限公司, 1, 3, 1, 4] [D:\迅雷\Thunder\Components\Tips\XLIPC.DLL] [Thunder Networking Technologies,LTD, 1, 0, 0, 2] [PID: 3844 / Administrator][D:\realplayer11gold_cn\realplay.exe] [RealNetworks, Inc., 11.0.0.372] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0] [C:\Program Files\Common Files\Real\Common\objb3201.dll] [RealNetworks, Inc., 0.1.0.7455] [D:\realplayer11gold_cn\rpplugins\rpap3260.dll] [RealNetworks, Inc., 6.0.14.748] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\Program Files\Common Files\Real\Common\pnrs3260.dll] [RealNetworks, Inc., 6.0.9.4840] [D:\realplayer11gold_cn\lang\cdplay_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\dbcomp_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\embed_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\gemctl_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\pngui_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\pdgenxfer_cn.dll] [N/A, ] [D:\realplayer11gold_cn\lang\rjctl_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rjeq_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rjres_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rjskin_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rjviz_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rjfade_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rjdlg_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rjmisc_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rjprog_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rjwma_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rpapp_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rpclsvc_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rpclutil_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rpdemand_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rpdsplyr_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rpgutil_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rpmnpane_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rpplylst_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\rpwebctl_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\tcdinfo_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\tclsvc_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\tdwnmgr_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\tmp3_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\twave_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\teasdk_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\tearm_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\tmdedit_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\upgrdlib_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\lang\mydevices_cn.dll] [RealNetworks, Inc., 6.0.14.0] [D:\realplayer11gold_cn\rpplugins\rpcl3260.dll] [RealNetworks, Inc., 6.0.9.3877] [C:\Program Files\Common Files\Real\RCAPlugins\uisy3201.dll] [RealNetworks, Inc., 0.1.0.4601] [C:\Program Files\Common Files\Real\Plugins\zipf3260.dll] [RealNetworks, Inc., 6.0.8.3308] [C:\Program Files\Common Files\Real\RCAPlugins\rpcontrols1.dll] [RealNetworks, Inc., 6.0.1.2995] [C:\Program Files\Common Files\Real\Plugins\pxcb3210.dll] [RealNetworks, Inc., 1.0.0.4758] [D:\realplayer11gold_cn\rpplugins\rpmn3260.dll] [RealNetworks, Inc., 6.0.9.3704] [C:\Program Files\Common Files\Real\RCAPlugins\rpcontrols2.dll] [RealNetworks, 6.0.1.2995] [C:\Program Files\Common Files\Real\RCAPlugins\gema3201.dll] [RealNetworks, Inc., 0.1.0.4580] [D:\realplayer11gold_cn\rpplugins\rpwe3260.dll] [RealNetworks, Inc., 6.0.1.3045] [D:\realplayer11gold_cn\rpplugins\rjbc3260.dll] [RealNetworks, Inc., 6.0.1.3049] [C:\Program Files\Common Files\Real\Common\pngu3267.dll] [RealNetworks, Inc., 6.7.0.3485] [D:\sogo\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31] [D:\realplayer11gold_cn\rpplugins\rpms3260.dll] [RealNetworks, Inc., 6.0.1.3039] [D:\realplayer11gold_cn\rpplugins\MPACore.dll] [RealNetworks, Inc., 1.0.3.3058] [C:\Program Files\Common Files\Real\RCAPlugins\gemx3201.dll] [RealNetworks, Inc., 0.1.0.6637] [D:\realplayer11gold_cn\rpplugins\myde3260.dll] [RealNetworks, Inc., 6.0.10.3270] [C:\Program Files\Common Files\Real\Common\pnen3260.dll] [ , 10.0.0.6773] [C:\Program Files\Common Files\Real\Plugins\vsrlocal.dll] [ , 10.1.0.142] [C:\Program Files\Common Files\Real\Plugins\vidsite.dll] [ , 10.0.0.6049] [C:\Program Files\Common Files\Real\Plugins\clntxres.dll] [ , 10.0.0.18137] [D:\realplayer11gold_cn\rpplugins\rjbe3260.dll] [RealNetworks, Inc., 6.0.4.3044] [C:\Program Files\Common Files\Real\Plugins\smplfsys.dll] [ , 10.0.0.15514] [C:\Program Files\Common Files\Real\Plugins\ramfformat.dll] [ , 10.0.0.12522] [C:\Program Files\Common Files\Real\Plugins\mp3render.dll] [ , 10.0.0.4425] [C:\Program Files\Common Files\Real\Common\rjbviz.dll] [RealNetworks, Inc., 1.0.2.4662] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [D:\realplayer11gold_cn\HXAudioDeviceHook.dll] [, 1, 0, 0, 1] [C:\WINDOWS\system32\msdmo.dll] [, ] [C:\Program Files\Common Files\Real\Codecs\colorcvt.dll] [ , 10.0.1.0] [C:\Program Files\Common Files\Real\Visualizations\AKWLyric_Real_br.rpv] [KWLyric_WMP, 1, 0, 0, 1] [C:\WINDOWS\system32\hpbr.dll] [N/A, ] [D:\realplayer11gold_cn\dbghelp.dll] [Microsoft Corporation, 6.0.0017.0 (DbgBuild.020528-1721)] [c:\windows\system32\mfplat.dll] [Microsoft Corporation, 11.0.5358.4827 (WMP_11.060509-2009)] [C:\Program Files\Common Files\Real\Common\twebbrowse.dll] [RealNetworks, Inc., 1.0.2.2364] [D:\realplayer11gold_cn\rpbrowserrecordplugin.dll] [RealPlayer, 1.0.0.522] [D:\realplayer11gold_cn\lang\rpbrp_cn.dll] [RealNetworks, Inc., 6.0.14.0] [C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [C:\Program Files\Common Files\Real\Update_OB\rnad3201.dll] [RealNetworks, Inc., 0.1.0.4279] [C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx] [Adobe Systems, Inc., 9,0,115,0] [PID: 3920 / Administrator][F:\sreng2\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 3, 0, 0, 0] [D:\sogo\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31] [F:\sreng2\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 188, C:\PROGRAM FILES\KASPERSKY LAB\NETWORKAGENT\KLNAGENT.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1472, D:\TT\TT\TTRAVELER.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1632, D:\迅雷\THUNDER\PROGRAM\THUNDER5.EXE] ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE] 【 在 rebirthatsix 的大作中提到: 】 : 我先看下,你用置顶里的sreng2再扫描一下,这个hijack的不全
rebirthatsix机器人#6 · 2008/6/11
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safe.exe] <IFEO[360safe.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.exe] <IFEO[360safebox.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe] <IFEO[360tray.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe] <IFEO[avp.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe] <IFEO[CCenter.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rav.exe] <IFEO[Rav.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMon.exe] <IFEO[RavMon.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe] <IFEO[RavMonD.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStub.exe] <IFEO[RavStub.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe] <IFEO[RavTask.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwcfg.exe] <IFEO[rfwcfg.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwmain.exe] <IFEO[rfwmain.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwProxy.exe] <IFEO[rfwProxy.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe] <IFEO[rfwsrv.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwstub.exe] <IFEO[rfwstub.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe] <IFEO[runiep.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxTray.exe] <IFEO[safeboxTray.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmartUp.exe] <IFEO[SmartUp.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] 首先,这些项被修改了,这个东西就是造成你杀毒软件无法启动的原因,比较容易理解的说法就是他把上面这些注册表项中第一个exe的运行实际镜像替换成了后面的taskman.exe,而这前面的exe就包括了ravxxx.exe(瑞星),kavxxx.exe(卡巴)等等,所以运行这些东西都会导致实际开启的是taskman.exe,这个也极有可能就是你说的黑窗口 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <DbgHlp32><; C:\WINDOWS\DbgHlp32.exe> [N/A] <fmsiocps><; C:\WINDOWS\fmsiocps.exe> [N/A] <msccrt><; C:\WINDOWS\msccrt.exe> [N/A] 然后就是这3个,都不是什么正常的启动项 还有这个 服务 [2FD78035 / 2FD78035][Stopped/Auto Start] <C:\WINDOWS\system32\58D072ED.EXE -d><N/A> 这个100%是木马 解决方法:首先保证你的进程列表里没有以上这些项目中包含的exe,如果有,一概结束 然后在保证都结束的前提下,把上面列出的项目依次用sreng2删除,注册表用注册表启动项来删除,或者直接开regedit.exe找对应的地方手动删除,服务的话sreng2里有专门管理服务的功能,也可以在里面删除
K180机器人#7 · 2008/6/11
多谢版主了,辛苦了^_^ 要停止再删除是下边的这三项,上边注册表中的项,跟那个服务是吧 <DbgHlp32><; C:\WINDOWS\DbgHlp32.exe> [N/A] <fmsiocps><; C:\WINDOWS\fmsiocps.exe> [N/A] <msccrt><; C:\WINDOWS\msccrt.exe> [N/ 【 在 rebirthatsix 的大作中提到: 】 : [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safe.exe] : <IFEO[360safe.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher] : [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.exe] : ...................
rebirthatsix机器人#8 · 2008/6/11
【 在 K180 的大作中提到: 】 : 多谢版主了,辛苦了^_^ : 要停止再删除是下边的这三项,上边注册表中的项,跟那个服务是吧 : <DbgHlp32><; C:\WINDOWS\DbgHlp32.exe> [N/A] : ................... 对,先停止,不停止的话很可能你删除了之后它们会再写回去
K180机器人#9 · 2008/6/11
进程里边我看了一下没有这些,这样就不用再停止了吧 【 在 rebirthatsix 的大作中提到: 】 : 对,先停止,不停止的话很可能你删除了之后它们会再写回去