手竹病几岁容易得到这种病毒开发不容易

斑竹高手帮帮忙!!重启加cpu 占用但查不出病毒!!(日志)
瑞星卡卡安全论坛
花非花月 -
3:56:00修改在第九楼(新日志),& & & & & & 总是重启,cpu 占用率由市成为100%....用瑞星查不出病毒....好奇怪!,10:56:18System Repair Engineer 2.0.21.505 (2.0 RC 2)Smallfrogs ()Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能以下内容被选中:& & 所有的启动项目(包括注册表、启动文件夹、服务等)& & 浏览器加载项& & 正在运行的进程(包括进程模块信息)& & 文件关联启动项目注册表[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]& & &ctfmon.exe&&C:\WINDOWS\system32\ctfmon.exe&& [Microsoft Corporation][HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]& & &load&&&& [][HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]& & &RavTask&&"C:\Program Files\Rising\Rav\RavTask.exe" -system&& [Beijing Rising Technology Co., Ltd.]& & &PHIME2002ASync&&C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC&& [Microsoft Corporation]& & &PHIME2002A&&C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName&& [Microsoft Corporation]& & &KernelFaultCheck&&%systemroot%\system32\dumprep 0 -k&& [][HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]& & &shell&&Explorer.exe&& [Microsoft Corporation]& & &Userinit&&C:\WINDOWS\system32\userinit.exe,&& [Microsoft Corporation][HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]& & &AppInit_DLLs&&&& [][HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]& & &UIHost&&logonui.exe&& [Microsoft Corporation]==================================启动文件夹服务[Rising Process Communication Center / RsCCenter]& &"C:\Program Files\Rising\Rav\CCenter.exe"&&Beijing Rising Technology Co., Ltd.&[RsRavMon Service / RsRavMon]& &"C:\Program Files\Rising\Rav\Ravmond.exe"&&Beijing Rising Technology Co., Ltd.&==================================浏览器加载项[KAVIEHelper Class]& {1B2F92A1-CDAF-E3F5CE0880} &C:\Program Files\KOS\KOSIEBar.dll, 金山软件股份有限公司&[超级兔子上网精灵]& {B70-4A5B-B789-B25FE09B4AF3} &D:\MAGICSET\haokanbar.dll, N/A&[QQ]& {c95fe080-8f5d-11d2-a20b-00aa003c157b} &D:\qq\QQ.EXE, TENCENT&[QQIEFloatBarCfgCmd Class]& {DEDEB80D-FA35-45d9-A8AFE6} &, N/A&[&Google]& {--9B18-CD4F} &c:\program files\google\googletoolbar1.dll, Google Inc.&[超级兔子上网精灵]& {4FD-4F15-9B46-F4E} &D:\MAGICSET\haokanbar.dll, N/A&[金山毒霸安全助手]& {EF72500A-C234-46C4-BF0A-9AA6913DDF34} &C:\Program Files\KOS\KOSIEBar.dll, 金山软件股份有限公司&[PowerList Control]& {20C2C286-BDE8-441B-B73D-AFA22D914DA5} &C:\WINDOWS\DOWNLO~1\CONFLICT.1\POWERL~1.OCX, &[金山毒霸在线产品升级]& {52DF16E3-6C4F-4B22-8BAF-} &C:\PROGRA~1\KOS\KOSInit.ocx, 金山软件股份有限公司&[Downloader Class]& {26-C98EDB5C549} &C:\WINDOWS\system32\iMopDl.dll, &[VnetAnprIns Class]& {91-4A9A-8BE4-B03} &C:\WINDOWS\Downloaded Program Files\anprins.dll, 中国电信股份有限公司&[PhotoUploadCtrl Control]& {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} &D:\qq\QZone\PHOTOU~1.OCX, tencent&[Shockwave Flash Object]& {D27CDB6E-AE6D-11CF-96B8-} &C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.&[dddolsp Class]& {FCEFD5DD--ABC1-A} &C:\WINDOWS\Downloaded Program Files\dddol.dll, &[Google Script Object]& {00EF-47C0-BD25-CF2D5D657FEB} &c:\program files\google\googletoolbar1.dll, Google Inc.&[ActiveMovieControl Object]& {06-11CE-BF01-00AA0055595A} &C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation&[AlxQhjhq Class]& {149BBDB2-3BF0-DF43-6ED8-3D23B6FA15F9} &, N/A&[实用搜索]& {15ADF205-4C54-4CFE-AC88-1EA0BA6D06A0} &, N/A&[Windows Genuine Advantage]& {A-453E-A040-C7C580BBF700} &C:\WINDOWS\system32\LegitCheckControl.dll, Microsoft? Corporation&[KAVIEHelper Class]& {1B2F92A1-CDAF-E3F5CE0880} &C:\Program Files\KOS\KOSIEBar.dll, 金山软件股份有限公司&[PowerList Control]& {20C2C286-BDE8-441B-B73D-AFA22D914DA5} &C:\WINDOWS\DOWNLO~1\CONFLICT.1\POWERL~1.OCX, &[RealPlayer SMIL Download Handler]& {224E833B-2CC6-42D9-AE39-90B6A38A4FA2} &C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.&[Windows Media Player]& {22D6F312-B0F6-11D0-94AB-E95} &C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation&[&Google]& {--9B18-CD4F} &c:\program files\google\googletoolbar1.dll, Google Inc.&[HTML Document]& {F9-11CF-8FD0-00AA00686F13} &%SystemRoot%\system32\mshtml.dll, N/A&[DHTML Edit Control Safe for Scripting for IE5]& {2D360201-FFF5-11D1-8D03-00A0C959BC0A} &C:\WINDOWS\system32\dllcache\dhtmled.ocx, Microsoft Corporation&[Tabular Data Control]& {333C7BC4-460F-11D0-BC04-} &C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation&[HHCtrl Object]& {41B23C28-488E-4E5C-ACE2-BB0BBABE99E8} &C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation&[超级兔子上网精灵]& {4FD-4F15-9B46-F4E} &D:\MAGICSET\haokanbar.dll, N/A&[XML Document]& {4D9-11D1-A6B3-00C04FD91555} &%SystemRoot%\system32\msxml3.dll, N/A&[HHCtrl Object]& {52A2AAAE-085D-4187-97EA-8C30DB990436} &C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation&[金山毒霸在线产品升级]& {52DF16E3-6C4F-4B22-8BAF-} &C:\PROGRA~1\KOS\KOSInit.ocx, 金山软件股份有限公司&[QQBrowserHelperObject Class]& {54EBD53A-9BC1-480B-966A-843A333CA162} &, N/A&[Shell Name Space]& {DE-11D1-B9F2-00A0C98BC547} &%SystemRoot%\system32\shdocvw.dll, N/A&[金山毒霸在线杀毒]& {577A-5DA583F9CE} &C:\PROGRA~1\KOS\KOSClean.ocx, 金山软件股份有限公司&[PowerPlayer Control]& {5EC7C511-CD0F-42E6-830C-1BD} &C:\WINDOWS\DOWNLO~1\CONFLICT.1\POWERP~1.DLL, PPStream Inc.&[WUWebControl Class]& {6414512B-B978-451D-A0D8-FCFDF33E833C} &C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation&[Windows Media Player]& {6BF52A52-394A-11D3-B153-00C04F79FAA6} &C:\WINDOWS\system32\wmp.dll, Microsoft Corporation&[Active Desktop Mover]& {72267F6A-A6F9-11D0-BC94-00C04FB67863} &%SystemRoot%\system32\SHELL32.dll, N/A&[超级兔子上网精灵]& {B70-4A5B-B789-B25FE09B4AF3} &D:\MAGICSET\haokanbar.dll, N/A&[VnetAnprIns Class]& {91-4A9A-8BE4-B03} &C:\WINDOWS\Downloaded Program Files\anprins.dll, 中国电信股份有限公司&[Microsoft Web 浏览器]& {A-11D0-A96B-00C04FD705A2} &C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation&[Thunder Browser Helper]& {889D2FEB-98-1DD2C5261283} &, N/A&[RMGetLicense Class]& {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} &C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation&[Google Toolbar Helper]& {AA58ED58-01DD-4D91-8333-CF} &, N/A&[Microsoft Scriptlet Component]& {AE24FDAE-03C6-11D1-8B76-} &C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation&[SearchAssistantOC]& {B45FF030--85DE-00C04FA35C89} &%SystemRoot%\system32\shdocvw.dll, N/A&[Messenger Object]& {BE-4B48-836C-BC} &C:\Program Files\Messenger\msgsc.dll, Microsoft Corporation&[Microsoft DirectAnimation Control]& {B6FFC24C-7E13-11D0-9B47-00C04FC2F51D} &C:\WINDOWS\system32\danim.dll, Microsoft Corporation&[Flash 8 ocx ]& {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} &, N/A&[RDS.DataSpace]& {BD96C556-65A3-11D0-983A-00C04FC29E36} &C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation&[AUDIO__MID Moniker Class]& {CD3AFA74-B84F-48F0-9393-7EDC} &C:\WINDOWS\system32\wmp.dll, Microsoft Corporation&[AUDIO__MP3 Moniker Class]& {CD3AFA76-B84F-48F0-9393-7EDC} &C:\WINDOWS\system32\wmp.dll, Microsoft Corporation&[AUDIO__WAV Moniker Class]& {CD3AFA7B-B84F-48F0-9393-7EDC} &C:\WINDOWS\system32\wmp.dll, Microsoft Corporation&[AUDIO__X_MS_WMA Moniker Class]& {CD3AFA84-B84F-48F0-9393-7EDC} &C:\WINDOWS\system32\wmp.dll, Microsoft Corporation&[VIDEO__MPEG Moniker Class]& {CD3AFA89-B84F-48F0-9393-7EDC} &C:\WINDOWS\system32\wmp.dll, Microsoft
花非花月 -
4:03:00Corporation&[VIDEO__X_MS_ASF Moniker Class]& {CD3AFA8F-B84F-48F0-9393-7EDC} &C:\WINDOWS\system32\wmp.dll, Microsoft Corporation&[VIDEO__X_MS_WMV Moniker Class]& {CD3AFA94-B84F-48F0-9393-7EDC} &C:\WINDOWS\system32\wmp.dll, Microsoft Corporation&[RealPlayer G2 Control]& {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} &C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.&[Shockwave Flash Object]& {D27CDB6E-AE6D-11CF-96B8-} &C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.&[VnetAnpr Class]& {E1-4AAD-888B-C8C5A0209E17} &C:\WINDOWS\system32\.vnetplugin_\_0\anpr.dll, N/A&[Rising Web Scan Object]& {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} &C:\WINDOWS\DOWNLO~1\OL2005.dll, Beijing Rising Technology Co., Ltd.&[金山毒霸安全助手]& {EF72500A-C234-46C4-BF0A-9AA6913DDF34} &C:\Program Files\KOS\KOSIEBar.dll, 金山软件股份有限公司&[Messenger Application]& {FB7199AB-79BF-11D2-8D94-} &C:\Program Files\Messenger\msgsc.dll, Microsoft Corporation&[dddolsp Class]& {FCEFD5DD--ABC1-A} &C:\WINDOWS\Downloaded Program Files\dddol.dll, &[&使用迅雷下载]& &D:\迅雷\Program\GetUrl.htm, N/A&[&使用迅雷下载全部链接]& &D:\迅雷\Program\GetAllUrl.htm, N/A&[Google 搜索(&G)]& &res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html, N/A&[上传到QQ网络硬盘]& &D:\qq\AddToNetDisk.htm, N/A&[使用网际快车下载]& &, N/A&[使用网际快车下载全部链接]& &, N/A&[添加到QQ自定义面板]& &D:\qq\AddPanel.htm, N/A&[添加到QQ表情]& &D:\qq\AddEmotion.htm, N/A&[用QQ彩信发送该图片]& &D:\qq\SendMMS.htm, N/A&==================================正在运行的进程[PID: 572][\SystemRoot\System32\smss.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 628][\??\C:\WINDOWS\system32\csrss.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 652][\??\C:\WINDOWS\system32\winlogon.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 696][C:\WINDOWS\system32\services.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 708][C:\WINDOWS\system32\lsass.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 860][C:\WINDOWS\system32\svchost.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 908][C:\WINDOWS\system32\svchost.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 1012][C:\Program Files\Rising\Rav\CCenter.exe]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 3&[PID: 1028][C:\WINDOWS\System32\svchost.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&& & [c:\windows\system32\yjbqtyhf.d1l]& &N/A&&N/A&[PID: 1072][C:\WINDOWS\system32\svchost.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 1144][C:\WINDOWS\system32\svchost.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 1164][C:\Program Files\Rising\Rav\Ravmond.exe]& &Beijing Rising Technology Co., Ltd.&&18, 0, 1, 33&& & [C:\Program Files\Rising\Rav\BWList.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 19&& & [C:\Program Files\Rising\Rav\RsCommX.dll]& &rising&&18, 0, 0, 1&& & [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 2&& & [C:\Program Files\Rising\Rav\CfgDll.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 11&& & [C:\Program Files\Rising\Rav\RSCOMMON.DLL]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 4&& & [C:\Program Files\Rising\Rav\RsLog.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 20&& & [C:\Program Files\Rising\Rav\HOOKSYS.dll]& &Beijing Rising Technology Co., Ltd.&&18, 1, 0, 11&& & [C:\Program Files\Rising\Rav\Scanner.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 30&& & [C:\Program Files\Rising\Rav\libload.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 10&& & [C:\Program Files\Rising\Rav\VirusLib.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 10&& & [C:\Program Files\Rising\Rav\regmon.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 6&& & [C:\Program Files\Rising\Rav\HookWeb.dll]& &rising&&18, 0, 0, 2&& & [C:\Program Files\Rising\Rav\MemMon.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 10&& & [C:\Program Files\Rising\Rav\expscan.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 4&& & [C:\Program Files\Rising\Rav\mPorts.dll]& &Beijing Rising Technology Co., Ltd.&&4, 0, 0, 3&& & [C:\Program Files\Rising\Rav\MailMon.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 5&& & [C:\Program Files\Rising\Rav\SpamEng.dll]& &N/A&&18, 0, 0, 6&& & [C:\Program Files\Rising\Rav\engine.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 30&& & [C:\Program Files\Rising\Rav\PostTrt.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 12&& & [C:\Program Files\Rising\Rav\UnExe.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 11&& & [C:\Program Files\Rising\Rav\ScanExec.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 11&& & [C:\Program Files\Rising\Rav\ScanEx.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 14&& & [C:\Program Files\Rising\Rav\NvFile.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 7&& & [C:\Program Files\Rising\Rav\ScanMac.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 9&& & [C:\Program Files\Rising\Rav\ScanSct.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 18&& & [C:\Program Files\Rising\Rav\Unpacker.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 3&& & [C:\Program Files\Rising\Rav\ExtOLE.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 6&& & [C:\Program Files\Rising\Rav\ScanNet.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 5&[PID: 1524][C:\WINDOWS\Explorer.EXE]& &Microsoft Corporation&&6.00. (xpsp_sp2_rtm.8)&& & [C:\WINDOWS\system32\Yjbqtyhf.dll]& &N/A&&N/A&& & [d:\WinRAR\rarext.dll]& &N/A&&N/A&& & [C:\WINDOWS\system32\RavExt.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 21&& & [C:\Program Files\Rising\Rav\RSCOMMON.DLL]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 4&[PID: 1564][C:\WINDOWS\system32\spoolsv.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_gdr.9)&[PID: 1580][C:\WINDOWS\system32\ctfmon.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 1808][C:\Program Files\Rising\Rav\RavStub.exe]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 16&& & [C:\Program Files\Rising\Rav\RsCommX.dll]& &rising&&18, 0, 0, 1&& & [C:\Program Files\Rising\Rav\RSCOMMON.DLL]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 4&[PID: 1912][C:\Program Files\Rising\Rav\RavTask.exe]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 22&& & [C:\Program Files\Rising\Rav\RSCOMMON.DLL]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 4&& & [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 2&& & [C:\Program Files\Rising\Rav\CfgDll.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 11&& & [C:\Program Files\Rising\Rav\RsCommX.dll]& &rising&&18, 0, 0, 1&[PID: 1936][C:\Program Files\Rising\Rav\Ravmon.exe]& &Beijing Rising Technology Co., Ltd.&&18, 0, 1, 30&& & [C:\Program Files\Rising\Rav\RsGuiLib.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 24&& & [C:\Program Files\Rising\Rav\BWList.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 19&& & [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 2&& & [C:\Program Files\Rising\Rav\CfgDll.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 11&& & [C:\Program Files\Rising\Rav\RSCOMMON.DLL]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 4&& & [C:\Program Files\Rising\Rav\RsCommX.dll]& &rising&&18, 0, 0, 1&& & [C:\Program Files\Rising\Rav\PngDll.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 5&[PID: 616][C:\WINDOWS\System32\alg.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 408][C:\Program Files\ChinaNet\VnetClient.exe]& &&&, 1&& & [C:\Program Files\ChinaNet\Communicate.dll]& &0&&1, 0, 0, 1&& & [C:\Program Files\ChinaNet\DialModule.dll]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\CLIENT~1.DLL]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\PLUGIN~1.OCX]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\sign.dll]& &0&&, 1&& & [C:\PROGRA~1\ChinaNet\SETUPP~1.DLL]& &&&1, 0, 0, 1&& & [C:\PROGRA~1\ChinaNet\SysPlug\\PICPUZ~1.DLL]& &&&, 0&& & [C:\PROGRA~1\ChinaNet\PostPlug.dll]& &&&, 2&& & [C:\PROGRA~1\ChinaNet\ADVERT~1.OCX]& &&&, 0&& & [C:\PROGRA~1\ChinaNet\VnetBs.ocx]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\ACCOUN~2.DLL]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\AccountMgr.dll]& &&&, 2&& & [C:\PROGRA~1\ChinaNet\PLUGIN~2.OCX]& &&&, 2&& & [C:\PROGRA~1\ChinaNet\NEWMES~1.DLL]& &&&, 0&& & [C:\PROGRA~1\ChinaNet\PassCtrl.dll]& &&&1, 0, 0, 1&& & [C:\WINDOWS\system32\wpcap.dll]& &Politecnico di Torino&&3, 0, 0, 18&& & [C:\WINDOWS\system32\pthreadVC.dll]& &N/A&&N/A&& & [C:\WINDOWS\system32\packet.dll]& &Politecnico di Torino&&3, 0, 0, 18&& & [C:\PROGRA~1\ChinaNet\PlugPush.dll]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\ALLINT~1.DLL]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\VNETLO~1.OCX]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\StatNum.dll]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\VNETON~1.OCX]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\ALLFUN~1.DLL]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\VnetOptLog.dll]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\DialogStyle.dll]& &&&1, 0, 0, 1&& & [C:\PROGRA~1\ChinaNet\Timer.ocx]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\VnetSkin.ocx]& &GDDC&&1, 0, 0, 1&& & [C:\PROGRA~1\ChinaNet\PlugIns\sms\SMSCON~1.DLL]& &&&1, 0, 0, 1&& & [C:\PROGRA~1\ChinaNet\PlugIns\sms\smsctl.dll]& &&&1, 0, 0, 1&& & [C:\PROGRA~1\ChinaNet\PlugIns\sms\MsgEg_DLL.dll]& &&&1, 0, 0, 1&& & [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]& &Macromedia, Inc.&&8,0,24,0&& & [C:\PROGRA~1\ChinaNet\DlgSkin.ocx]& &&&1, 0, 0, 1&& & [C:\Program Files\Rising\Rav\RavScrCh.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 4&[PID: 240][C:\Program Files\Internet Explorer\IEXPLORE.EXE]& &Microsoft Corporation&&6.00. (xpsp_sp2_rtm.8)&& & [C:\Program Files\Rising\Rav\RavScrCh.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 4&& & [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]& &Macromedia, Inc.&&8,0,24,0&& & [C:\WINDOWS\system32\Yjbqtyhf.dll]& &N/A&&N/A&& & [C:\WINDOWS\system32\kingsoft\KOS\KOSInit.ocx]& &金山软件股份有限公司&&, 3&& & [C:\PROGRA~1\KOS\KOSClean.ocx]& &金山软件股份有限公司&&, 1&& & [C:\PROGRA~1\KOS\KAEScan.DLL]& &Kingsoft Corp.&&, 25&& & [C:\PROGRA~1\KOS\KAEPlat.DLL]& &Kingsoft Corp.&&, 53&& & [C:\PROGRA~1\KOS\KAEMem.DAT]& &Kingsoft&&, 11&& & [C:\PROGRA~1\KOS\KAVIPC2.DLL]& &Kingsoft Corporation&&, 20&& & [C:\Program Files\KOS\KOSIEBar.dll]& &金山软件股份有限公司&&, 1&[PID: 2240][D:\qq\QQ.exe]& &TENCENT&&0, 0, 0, 0&& & [D:\qq\QQBaseClassInDll.dll]& &&&1, 0, 0, 1&
花非花月 -
4:03:00[D:\qq\QQHelperDll.dll]& &&&1, 0, 0, 1&& & [D:\qq\BasicCtrlDll.dll]& &Tencent&&5, 0, 200, 160&& & [D:\qq\QQAPI.dll]& &&&1, 0, 0, 1&& & [D:\qq\TIMProxy.dll]& &tencent&&0, 3, 2, 4&& & [D:\qq\LoginCtrl.dll]& &&&1, 0, 0, 1&& & [D:\qq\npkcntc.dll]& &INCA Internet Co., Ltd.&&, 1&& & [D:\qq\npkpdb.dll]& &INCA Internet Co., Ltd.&&, 1&& & [C:\WINDOWS\system32\Yjbqtyhf.dll]& &N/A&&N/A&& & [D:\qq\QQRes.dll]& &tencent&&1, 0, 0, 1&& & [D:\qq\WizardCtrl.dll]& &&&1, 0, 0, 1&& & [D:\qq\QQMainFrame.dll]& &N/A&&N/A&& & [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]& &Macromedia, Inc.&&8,0,24,0&& & [D:\qq\CQQApplication.dll]& &N/A&&N/A&& & [D:\qq\NewSkin.dll]& &&&1, 0, 0, 1&& & [D:\qq\HostingMgr.dll]& &&&1, 0, 0, 1&& & [D:\qq\CameraDll.dll]& &&&1, 0, 0, 1&& & [D:\qq\MailSummary.dll]& &&&1, 0, 0, 1&& & [D:\qq\QQSpace.dll]& &&&1, 0, 0, 1&& & [C:\WINDOWS\system32\msdmo.dll]& &N/A&&N/A&& & [D:\qq\QQGroupMng.dll]& &&&1, 0, 0, 1&& & [D:\qq\GroupLive.dll]& &N/A&&N/A&& & [D:\qq\QQSysMsgMng.dll]& &N/A&&N/A&& & [D:\qq\UserDefinedHead.dll]& &&&1, 0, 0, 1&& & [D:\qq\QQPlugin.dll]& &N/A&&N/A&& & [D:\qq\QQConfigPlugin.dll]& &&&1, 0, 0, 1&& & [D:\qq\QRingMng.dll]& &N/A&&N/A&& & [D:\qq\PhoneAPI.dll]& &&&1, 0, 0, 1&& & [D:\qq\DialerAllinOne.dll]& &tencent&&1, 4, 0, 0&& & [D:\qq\QQAvatar.dll]& &N/A&&N/A&& & [D:\qq\FlashAvatarDll.dll]& &&&1, 4, 0, 1&& & [D:\qq\LongConnection.dll]& &tencent&&5, 0, 200, 160&& & [D:\qq\QQPet.dll]& &&&1, 0, 0, 1&& & [D:\qq\BQQApplication.dll]& &N/A&&N/A&& & [D:\qq\QQAllInOne.dll]& &N/A&&N/A&& & [D:\qq\SCCore.dll]& &N/A&&N/A&& & [D:\qq\CommercesMng.dll]& &&&1, 0, 0, 1&& & [D:\qq\PersonalDesktop.dll]& &深圳市腾讯计算机系统公司QQ工作小组&&1, 0, 0, 2&& & [D:\qq\QQAddr.dll]& &深圳市腾讯计算机系统有限公司&&5, 0, 101, 200&& & [D:\qq\QQSceneMng.dll]& &N/A&&N/A&& & [D:\qq\QQPhoneHelper.dll]& &腾讯科技(深圳)有限公司&&2, 0, 6, 60&& & [D:\qq\videodevice.dll]& &Tencent&&1.5.0.0&& & [D:\qq\inplus.dll]& &Tencent&&1.5.0.0&& & [C:\WINDOWS\system32\l3codeca.acm]& &Fraunhofer Institut Integrierte Schaltungen IIS&&1, 9, 0, 0305&[PID: 2276][D:\qq\TIMPlatform.exe]& &tencent&&0, 3, 1, 8&& & [D:\qq\TIMProxy.dll]& &tencent&&0, 3, 2, 4&[PID: 2892][D:\qq\QQ.exe]& &TENCENT&&0, 0, 0, 0&& & [D:\qq\QQBaseClassInDll.dll]& &&&1, 0, 0, 1&& & [D:\qq\QQHelperDll.dll]& &&&1, 0, 0, 1&& & [D:\qq\BasicCtrlDll.dll]& &Tencent&&5, 0, 200, 160&& & [D:\qq\QQAPI.dll]& &&&1, 0, 0, 1&& & [D:\qq\TIMProxy.dll]& &tencent&&0, 3, 2, 4&& & [D:\qq\LoginCtrl.dll]& &&&1, 0, 0, 1&& & [D:\qq\npkcntc.dll]& &INCA Internet Co., Ltd.&&, 1&& & [D:\qq\npkpdb.dll]& &INCA Internet Co., Ltd.&&, 1&& & [C:\WINDOWS\system32\Yjbqtyhf.dll]& &N/A&&N/A&& & [D:\qq\QQRes.dll]& &tencent&&1, 0, 0, 1&& & [D:\qq\QQMainFrame.dll]& &N/A&&N/A&& & [D:\qq\CQQApplication.dll]& &N/A&&N/A&& & [D:\qq\NewSkin.dll]& &&&1, 0, 0, 1&& & [D:\qq\HostingMgr.dll]& &&&1, 0, 0, 1&& & [D:\qq\CameraDll.dll]& &&&1, 0, 0, 1&& & [D:\qq\MailSummary.dll]& &&&1, 0, 0, 1&& & [D:\qq\QQSpace.dll]& &&&1, 0, 0, 1&& & [C:\WINDOWS\system32\msdmo.dll]& &N/A&&N/A&& & [D:\qq\QQGroupMng.dll]& &&&1, 0, 0, 1&& & [D:\qq\GroupLive.dll]& &N/A&&N/A&& & [D:\qq\QQSysMsgMng.dll]& &N/A&&N/A&& & [D:\qq\UserDefinedHead.dll]& &&&1, 0, 0, 1&& & [D:\qq\QQPlugin.dll]& &N/A&&N/A&& & [D:\qq\QQConfigPlugin.dll]& &&&1, 0, 0, 1&& & [D:\qq\QRingMng.dll]& &N/A&&N/A&& & [D:\qq\PhoneAPI.dll]& &&&1, 0, 0, 1&& & [D:\qq\DialerAllinOne.dll]& &tencent&&1, 4, 0, 0&& & [D:\qq\QQAvatar.dll]& &N/A&&N/A&& & [D:\qq\FlashAvatarDll.dll]& &&&1, 4, 0, 1&& & [D:\qq\LongConnection.dll]& &tencent&&5, 0, 200, 160&& & [D:\qq\QQPet.dll]& &&&1, 0, 0, 1&& & [D:\qq\BQQApplication.dll]& &N/A&&N/A&& & [D:\qq\CommercesMng.dll]& &&&1, 0, 0, 1&& & [D:\qq\PersonalDesktop.dll]& &深圳市腾讯计算机系统公司QQ工作小组&&1, 0, 0, 2&& & [D:\qq\QQAddr.dll]& &深圳市腾讯计算机系统有限公司&&5, 0, 101, 200&& & [D:\qq\QQSceneMng.dll]& &N/A&&N/A&& & [D:\qq\QQAllInOne.dll]& &N/A&&N/A&& & [D:\qq\SCCore.dll]& &N/A&&N/A&& & [D:\qq\QQCustomFace.dll]& &N/A&&N/A&& & [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]& &Macromedia, Inc.&&8,0,24,0&& & [D:\qq\GroupConnection.dll]& &Tencent&&5, 0, 202, 170&[PID: 4008][C:\WINDOWS\system32\taskmgr.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 948][D:\System Repair Engine\新建文件夹\SREng2\SREng.exe]& &Smallfrogs Studio&&2.0.21.505&==================================文件关联.TXT& OK. [%SystemRoot%\system32\NOTEPAD.EXE %1].EXE& OK. ["%1" %*].COM& OK. ["%1" %*].PIF& OK. ["%1" %*].REG& OK. [regedit.exe "%1"].BAT& OK. ["%1" %*].SCR& OK. ["%1" /S].CHM& Error. ["hh.exe" %1].HLP& OK. [%SystemRoot%\system32\winhlp32.exe %1].INI& OK. [%SystemRoot%\System32\NOTEPAD.EXE %1].INF& OK. [%SystemRoot%\System32\NOTEPAD.EXE %1].VBS& OK. [%SystemRoot%\System32\WScript.exe "%1" %*].JS& OK. [%SystemRoot%\System32\WScript.exe "%1" %*].LNK& OK. [{0-}]==================================Winsock 提供者==================================
花非花月 -
4:04:00用了一下金山杀毒,发现留下了一些东西,怕和瑞星起冲突,请告诉一声又没有要删的。还有发现了这个,总出现。不知有没有用:[img][/img]附件:
花非花月 -
11:42:00这是金山在线的报告附件:
tanghui1234 -
11:50:00结束占用CPU最高的那个程序就行了 (呵呵 这只能解下燃眉之急)
花非花月 -
13:59:00还是谢谢你
14:05:00C:\Program Files\KOS这是金山的东东,瑞星报病毒了??C:\WINDOWS\system32\Yjbqtyhf.dll这个东东找不着修复的方法你先这样试试吧关闭所有浏览窗口以及一些不必要的程序运行(双击)System Repair Engineer,使用“系统修复,浏览器加载项”来删除以下选项。C:\WINDOWS\Downloaded Program Files\dddol.dllc:\windows\system32\yjbqtyhf.d1l请到www.,点“我的软件”下载KillBox.exe重新启动电脑, 开机检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式进入Windows双击打开KillBox.exe,分别删除c:\windows\system32\yjbqtyhf.d1l(删除时勾选“删除前先结束Explorer.EXE进程”删除C:\WINDOWS\Downloaded Program Files\dddol.dllc:\windows\system32\yjbqtyhf.d1l你再扫份日志粘上来。
花非花月 -
14:09:00谢谢我试一下
花非花月 -
15:13:00,15:02:28System Repair Engineer 2.0.21.505 (2.0 RC 2)Smallfrogs ()Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能以下内容被选中:& & 所有的启动项目(包括注册表、启动文件夹、服务等)& & 浏览器加载项& & 正在运行的进程(包括进程模块信息)& & 文件关联启动项目注册表[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]& & &ctfmon.exe&&C:\WINDOWS\system32\ctfmon.exe&& [Microsoft Corporation][HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]& & &load&&&& [][HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]& & &RavTask&&"C:\Program Files\Rising\Rav\RavTask.exe" -system&& [Beijing Rising Technology Co., Ltd.]& & &PHIME2002ASync&&C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC&& [Microsoft Corporation]& & &PHIME2002A&&C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName&& [Microsoft Corporation]& & &KernelFaultCheck&&%systemroot%\system32\dumprep 0 -k&& [][HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]& & &shell&&Explorer.exe&& [Microsoft Corporation]& & &Userinit&&C:\WINDOWS\system32\userinit.exe,&& [Microsoft Corporation][HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]& & &AppInit_DLLs&&&& [][HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]& & &UIHost&&logonui.exe&& [Microsoft Corporation]==================================启动文件夹服务[Rising Process Communication Center / RsCCenter]& &"C:\Program Files\Rising\Rav\CCenter.exe"&&Beijing Rising Technology Co., Ltd.&[RsRavMon Service / RsRavMon]& &"C:\Program Files\Rising\Rav\Ravmond.exe"&&Beijing Rising Technology Co., Ltd.&==================================浏览器加载项[KAVIEHelper Class]& {1B2F92A1-CDAF-E3F5CE0880} &C:\Program Files\KOS\KOSIEBar.dll, 金山软件股份有限公司&[超级兔子上网精灵]& {B70-4A5B-B789-B25FE09B4AF3} &D:\MAGICSET\haokanbar.dll, N/A&[QQ]& {c95fe080-8f5d-11d2-a20b-00aa003c157b} &D:\qq\QQ.EXE, TENCENT&[QQIEFloatBarCfgCmd Class]& {DEDEB80D-FA35-45d9-A8AFE6} &, N/A&[&Google]& {--9B18-CD4F} &c:\program files\google\googletoolbar1.dll, Google Inc.&[超级兔子上网精灵]& {4FD-4F15-9B46-F4E} &D:\MAGICSET\haokanbar.dll, N/A&[金山毒霸安全助手]& {EF72500A-C234-46C4-BF0A-9AA6913DDF34} &C:\Program Files\KOS\KOSIEBar.dll, 金山软件股份有限公司&[PowerList Control]& {20C2C286-BDE8-441B-B73D-AFA22D914DA5} &C:\WINDOWS\DOWNLO~1\CONFLICT.1\POWERL~1.OCX, &[金山毒霸在线产品升级]& {52DF16E3-6C4F-4B22-8BAF-} &C:\PROGRA~1\KOS\KOSInit.ocx, 金山软件股份有限公司&[Downloader Class]& {26-C98EDB5C549} &C:\WINDOWS\system32\iMopDl.dll, &[VnetAnprIns Class]& {91-4A9A-8BE4-B03} &C:\WINDOWS\Downloaded Program Files\anprins.dll, 中国电信股份有限公司&[PhotoUploadCtrl Control]& {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} &D:\qq\QZone\PHOTOU~1.OCX, tencent&[Shockwave Flash Object]& {D27CDB6E-AE6D-11CF-96B8-} &C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.&[Google Script Object]& {00EF-47C0-BD25-CF2D5D657FEB} &c:\program files\google\googletoolbar1.dll, Google Inc.&[ActiveMovieControl Object]& {06-11CE-BF01-00AA0055595A} &C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation&[AlxQhjhq Class]& {149BBDB2-3BF0-DF43-6ED8-3D23B6FA15F9} &, N/A&[实用搜索]& {15ADF205-4C54-4CFE-AC88-1EA0BA6D06A0} &, N/A&[Windows Genuine Advantage]& {A-453E-A040-C7C580BBF700} &C:\WINDOWS\system32\LegitCheckControl.dll, Microsoft? Corporation&[KAVIEHelper Class]& {1B2F92A1-CDAF-E3F5CE0880} &C:\Program Files\KOS\KOSIEBar.dll, 金山软件股份有限公司&[PowerList Control]& {20C2C286-BDE8-441B-B73D-AFA22D914DA5} &C:\WINDOWS\DOWNLO~1\CONFLICT.1\POWERL~1.OCX, &[RealPlayer SMIL Download Handler]& {224E833B-2CC6-42D9-AE39-90B6A38A4FA2} &C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.&[Windows Media Player]& {22D6F312-B0F6-11D0-94AB-E95} &C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation&[&Google]& {--9B18-CD4F} &c:\program files\google\googletoolbar1.dll, Google Inc.&[HTML Document]& {F9-11CF-8FD0-00AA00686F13} &%SystemRoot%\system32\mshtml.dll, N/A&[DHTML Edit Control Safe for Scripting for IE5]
花非花月 -
15:14:00{2D360201-FFF5-11D1-8D03-00A0C959BC0A} &C:\WINDOWS\system32\dllcache\dhtmled.ocx, Microsoft Corporation&[Tabular Data Control]& {333C7BC4-460F-11D0-BC04-} &C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation&[HHCtrl Object]& {41B23C28-488E-4E5C-ACE2-BB0BBABE99E8} &C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation&[超级兔子上网精灵]& {4FD-4F15-9B46-F4E} &D:\MAGICSET\haokanbar.dll, N/A&[XML Document]& {4D9-11D1-A6B3-00C04FD91555} &%SystemRoot%\system32\msxml3.dll, N/A&[HHCtrl Object]& {52A2AAAE-085D-4187-97EA-8C30DB990436} &C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation&[金山毒霸在线产品升级]& {52DF16E3-6C4F-4B22-8BAF-} &C:\PROGRA~1\KOS\KOSInit.ocx, 金山软件股份有限公司&[QQBrowserHelperObject Class]& {54EBD53A-9BC1-480B-966A-843A333CA162} &, N/A&[Shell Name Space]& {DE-11D1-B9F2-00A0C98BC547} &%SystemRoot%\system32\shdocvw.dll, N/A&[金山毒霸在线杀毒]& {577A-5DA583F9CE} &C:\PROGRA~1\KOS\KOSClean.ocx, 金山软件股份有限公司&[PowerPlayer Control]& {5EC7C511-CD0F-42E6-830C-1BD} &C:\WINDOWS\DOWNLO~1\CONFLICT.1\POWERP~1.DLL, PPStream Inc.&[WUWebControl Class]& {6414512B-B978-451D-A0D8-FCFDF33E833C} &C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation&[Windows Media Player]& {6BF52A52-394A-11D3-B153-00C04F79FAA6} &C:\WINDOWS\system32\wmp.dll, Microsoft Corporation&[Active Desktop Mover]& {72267F6A-A6F9-11D0-BC94-00C04FB67863} &%SystemRoot%\system32\SHELL32.dll, N/A&[超级兔子上网精灵]& {B70-4A5B-B789-B25FE09B4AF3} &D:\MAGICSET\haokanbar.dll, N/A&[VnetAnprIns Class]& {91-4A9A-8BE4-B03} &C:\WINDOWS\Downloaded Program Files\anprins.dll, 中国电信股份有限公司&[Microsoft Web 浏览器]& {A-11D0-A96B-00C04FD705A2} &C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation&[Thunder Browser Helper]& {889D2FEB-98-1DD2C5261283} &, N/A&[RMGetLicense Class]& {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} &C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation&[Google Toolbar Helper]& {AA58ED58-01DD-4D91-8333-CF} &, N/A&[Microsoft Scriptlet Component]& {AE24FDAE-03C6-11D1-8B76-} &C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation&[SearchAssistantOC]& {B45FF030--85DE-00C04FA35C89} &%SystemRoot%\system32\shdocvw.dll, N/A&[Messenger Object]& {BE-4B48-836C-BC} &C:\Program Files\Messenger\msgsc.dll, Microsoft Corporation&[Microsoft DirectAnimation Control]& {B6FFC24C-7E13-11D0-9B47-00C04FC2F51D} &C:\WINDOWS\system32\danim.dll, Microsoft Corporation&[Flash 8 ocx ]& {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} &, N/A&[RDS.DataSpace]& {BD96C556-65A3-11D0-983A-00C04FC29E36} &C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation&[AUDIO__MID Moniker Class]& {CD3AFA74-B84F-48F0-9393-7EDC} &C:\WINDOWS\system32\wmp.dll, Microsoft Corporation&[AUDIO__MP3 Moniker Class]& {CD3AFA76-B84F-48F0-9393-7EDC} &C:\WINDOWS\system32\wmp.dll, Microsoft Corporation&[AUDIO__WAV Moniker Class]& {CD3AFA7B-B84F-48F0-9393-7EDC} &C:\WINDOWS\system32\wmp.dll, Microsoft Corporation&[AUDIO__X_MS_WMA Moniker Class]& {CD3AFA84-B84F-48F0-9393-7EDC} &C:\WINDOWS\system32\wmp.dll, Microsoft Corporation&[VIDEO__MPEG Moniker Class]& {CD3AFA89-B84F-48F0-9393-7EDC} &C:\WINDOWS\system32\wmp.dll, Microsoft Corporation&[VIDEO__X_MS_ASF Moniker Class]& {CD3AFA8F-B84F-48F0-9393-7EDC} &C:\WINDOWS\system32\wmp.dll, Microsoft Corporation&[VIDEO__X_MS_WMV Moniker Class]& {CD3AFA94-B84F-48F0-9393-7EDC} &C:\WINDOWS\system32\wmp.dll, Microsoft Corporation&[RealPlayer G2 Control]& {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} &C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.&[Shockwave Flash Object]& {D27CDB6E-AE6D-11CF-96B8-} &C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.&[VnetAnpr Class]& {E1-4AAD-888B-C8C5A0209E17} &C:\WINDOWS\system32\.vnetplugin_\_0\anpr.dll, N/A&[Rising Web Scan Object]& {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} &C:\WINDOWS\DOWNLO~1\OL2005.dll, Beijing Rising Technology Co., Ltd.&[金山毒霸安全助手]& {EF72500A-C234-46C4-BF0A-9AA6913DDF34} &C:\Program Files\KOS\KOSIEBar.dll, 金山软件股份有限公司&[Messenger Application]& {FB7199AB-79BF-11D2-8D94-} &C:\Program Files\Messenger\msgsc.dll, Microsoft Corporation&[&使用迅雷下载]& &D:\迅雷\Program\GetUrl.htm, N/A&[&使用迅雷下载全部链接]& &D:\迅雷\Program\GetAllUrl.htm, N/A&[Google 搜索(&G)]& &res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html, N/A&[上传到QQ网络硬盘]& &D:\qq\AddToNetDisk.htm, N/A&[使用网际快车下载]& &, N/A&[使用网际快车下载全部链接]& &, N/A&[添加到QQ自定义面板]& &D:\qq\AddPanel.htm, N/A&[添加到QQ表情]& &D:\qq\AddEmotion.htm, N/A&[用QQ彩信发送该图片]& &D:\qq\SendMMS.htm, N/A&==================================正在运行的进程[PID: 572][\SystemRoot\System32\smss.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 628][\??\C:\WINDOWS\system32\csrss.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 652][\??\C:\WINDOWS\system32\winlogon.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 696][C:\WINDOWS\system32\services.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 708][C:\WINDOWS\system32\lsass.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 860][C:\WINDOWS\system32\svchost.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 908][C:\WINDOWS\system32\svchost.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 1012][C:\Program Files\Rising\Rav\CCenter.exe]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 3&[PID: 1028][C:\WINDOWS\System32\svchost.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&& & [c:\windows\system32\yjbqtyhf.d1l]& &N/A&&N/A&[PID: 1076][C:\WINDOWS\system32\svchost.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 1144][C:\WINDOWS\system32\svchost.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 1164][C:\Program Files\Rising\Rav\Ravmond.exe]& &Beijing Rising Technology Co., Ltd.&&18, 0, 1, 33&& & [C:\Program Files\Rising\Rav\BWList.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 19&
花非花月 -
15:15:00[C:\Program Files\Rising\Rav\RsCommX.dll]& &rising&&18, 0, 0, 1&& & [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 2&& & [C:\Program Files\Rising\Rav\CfgDll.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 11&& & [C:\Program Files\Rising\Rav\RSCOMMON.DLL]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 4&& & [C:\Program Files\Rising\Rav\RsLog.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 20&& & [C:\Program Files\Rising\Rav\HOOKSYS.dll]& &Beijing Rising Technology Co., Ltd.&&18, 1, 0, 11&& & [C:\Program Files\Rising\Rav\Scanner.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 30&& & [C:\Program Files\Rising\Rav\libload.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 10&& & [C:\Program Files\Rising\Rav\VirusLib.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 10&& & [C:\Program Files\Rising\Rav\regmon.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 6&& & [C:\Program Files\Rising\Rav\HookWeb.dll]& &rising&&18, 0, 0, 2&& & [C:\Program Files\Rising\Rav\MemMon.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 10&& & [C:\Program Files\Rising\Rav\expscan.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 4&& & [C:\Program Files\Rising\Rav\mPorts.dll]& &Beijing Rising Technology Co., Ltd.&&4, 0, 0, 3&& & [C:\Program Files\Rising\Rav\MailMon.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 5&& & [C:\Program Files\Rising\Rav\SpamEng.dll]& &N/A&&18, 0, 0, 6&& & [C:\Program Files\Rising\Rav\engine.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 30&& & [C:\Program Files\Rising\Rav\PostTrt.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 12&& & [C:\Program Files\Rising\Rav\UnExe.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 11&& & [C:\Program Files\Rising\Rav\ScanExec.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 11&& & [C:\Program Files\Rising\Rav\ScanEx.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 14&& & [C:\Program Files\Rising\Rav\NvFile.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 7&& & [C:\Program Files\Rising\Rav\ScanMac.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 9&& & [C:\Program Files\Rising\Rav\ScanSct.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 18&& & [C:\Program Files\Rising\Rav\Unpacker.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 3&& & [C:\Program Files\Rising\Rav\ExtOLE.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 6&[PID: 1524][C:\WINDOWS\Explorer.EXE]& &Microsoft Corporation&&6.00. (xpsp_sp2_rtm.8)&& & [C:\WINDOWS\system32\Yjbqtyhf.dll]& &N/A&&N/A&[PID: 1540][C:\WINDOWS\system32\ctfmon.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 1572][C:\WINDOWS\system32\spoolsv.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_gdr.9)&[PID: 1856][C:\Program Files\Rising\Rav\RavStub.exe]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 16&& & [C:\Program Files\Rising\Rav\RsCommX.dll]& &rising&&18, 0, 0, 1&& & [C:\Program Files\Rising\Rav\RSCOMMON.DLL]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 4&[PID: 1888][C:\Program Files\Rising\Rav\RavTask.exe]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 22&& & [C:\Program Files\Rising\Rav\RSCOMMON.DLL]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 4&& & [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 2&& & [C:\Program Files\Rising\Rav\CfgDll.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 11&& & [C:\Program Files\Rising\Rav\RsCommX.dll]& &rising&&18, 0, 0, 1&[PID: 1916][C:\Program Files\Rising\Rav\Ravmon.exe]& &Beijing Rising Technology Co., Ltd.&&18, 0, 1, 30&& & [C:\Program Files\Rising\Rav\RsGuiLib.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 24&& & [C:\Program Files\Rising\Rav\BWList.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 19&& & [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 2&& & [C:\Program Files\Rising\Rav\CfgDll.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 11&& & [C:\Program Files\Rising\Rav\RSCOMMON.DLL]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 4&& & [C:\Program Files\Rising\Rav\RsCommX.dll]& &rising&&18, 0, 0, 1&& & [C:\Program Files\Rising\Rav\PngDll.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 5&[PID: 828][C:\WINDOWS\System32\alg.exe]& &Microsoft Corporation&&5.1. (xpsp_sp2_rtm.8)&[PID: 1244][C:\WINDOWS\system32\wuauclt.exe]& &Microsoft Corporation&&5.8.0.2469 built by: lab01_n(wmbla)&[PID: 376][C:\Program Files\ChinaNet\VnetClient.exe]& &&&, 1&& & [C:\Program Files\ChinaNet\Communicate.dll]& &0&&1, 0, 0, 1&& & [C:\Program Files\ChinaNet\DialModule.dll]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\CLIENT~1.DLL]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\PLUGIN~1.OCX]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\sign.dll]& &0&&, 1&& & [C:\PROGRA~1\ChinaNet\SETUPP~1.DLL]& &&&1, 0, 0, 1&& & [C:\PROGRA~1\ChinaNet\SysPlug\\PICPUZ~1.DLL]& &&&, 0&& & [C:\PROGRA~1\ChinaNet\PostPlug.dll]& &&&, 2&& & [C:\PROGRA~1\ChinaNet\ADVERT~1.OCX]& &&&, 0&& & [C:\PROGRA~1\ChinaNet\VnetBs.ocx]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\ACCOUN~2.DLL]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\AccountMgr.dll]& &&&, 2&& & [C:\PROGRA~1\ChinaNet\PLUGIN~2.OCX]& &&&, 2&& & [C:\PROGRA~1\ChinaNet\NEWMES~1.DLL]& &&&, 0&& & [C:\PROGRA~1\ChinaNet\PassCtrl.dll]& &&&1, 0, 0, 1&& & [C:\WINDOWS\system32\wpcap.dll]& &Politecnico di Torino&&3, 0, 0, 18&& & [C:\WINDOWS\system32\pthreadVC.dll]& &N/A&&N/A&& & [C:\WINDOWS\system32\packet.dll]& &Politecnico di Torino&&3, 0, 0, 18&& & [C:\PROGRA~1\ChinaNet\PlugPush.dll]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\ALLINT~1.DLL]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\VNETLO~1.OCX]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\StatNum.dll]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\VNETON~1.OCX]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\ALLFUN~1.DLL]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\VnetOptLog.dll]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\DialogStyle.dll]& &&&1, 0, 0, 1&& & [C:\PROGRA~1\ChinaNet\Timer.ocx]& &&&, 1&& & [C:\PROGRA~1\ChinaNet\VnetSkin.ocx]& &GDDC&&1, 0, 0, 1&& & [C:\PROGRA~1\ChinaNet\PlugIns\sms\SMSCON~1.DLL]& &&&1, 0, 0, 1&& & [C:\PROGRA~1\ChinaNet\PlugIns\sms\smsctl.dll]& &&&1, 0, 0, 1&& & [C:\PROGRA~1\ChinaNet\PlugIns\sms\MsgEg_DLL.dll]& &&&1, 0, 0, 1&& & [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]& &Macromedia, Inc.&&8,0,24,0&& & [C:\Program Files\Rising\Rav\RavScrCh.dll]& &Beijing Rising Technology Co., Ltd.&&18, 0, 0, 4&& & [C:\PROGRA~1\ChinaNet\DlgSkin.ocx]& &&&1, 0, 0, 1&[PID: 1368][D:\qq\QQ.exe]& &TENCENT&&0, 0, 0, 0&& & [D:\qq\QQBaseClassInDll.dll]& &&&1, 0, 0, 1&& & [D:\qq\QQHelperDll.dll]& &&&1, 0, 0, 1&& & [D:\qq\BasicCtrlDll.dll]& &Tencent&&5, 0, 200, 160&& & [D:\qq\QQAPI.dll]& &&&1, 0, 0, 1&& & [D:\qq\TIMProxy.dll]& &tencent&&0, 3, 2, 4&& & [D:\qq\LoginCtrl.dll]& &&&1, 0, 0, 1&& & [D:\qq\npkcntc.dll]& &INCA Internet Co., Ltd.&&, 1&& & [D:\qq\npkpdb.dll]& &INCA Internet Co., Ltd.&&, 1&& & [C:\WINDOWS\system32\Yjbqtyhf.dll]& &N/A&&N/A&& & [D:\qq\QQRes.dll]& &tencent&&1, 0, 0, 1&& & [D:\qq\QQMainFrame.dll]& &N/A&&N/A&& & [D:\qq\CQQApplication.dll]& &N/A&&N/A&& & [D:\qq\NewSkin.dll]& &&&1, 0, 0, 1&& & [D:\qq\HostingMgr.dll]& &&&1, 0, 0, 1&& & [D:\qq\CameraDll.dll]& &&&1, 0, 0, 1&& & [D:\qq\MailSummary.dll]& &&&1, 0, 0, 1&& & [D:\qq\QQSpace.dll]& &&&1, 0, 0, 1&& & [C:\WINDOWS\system32\msdmo.dll]& &N/A&&N/A&& & [D:\qq\QQGroupMng.dll]& &&&1, 0, 0, 1&& & [D:\qq\GroupLive.dll]& &N/A&&N/A&& & [D:\qq\UserDefinedHead.dll]& &&&1, 0, 0, 1&& & [D:\qq\QQPlugin.dll]& &N/A&&N/A&& & [D:\qq\QQConfigPlugin.dll]& &&&1, 0, 0, 1&& & [D:\qq\QRingMng.dll]& &N/A&&N/A&& & [D:\qq\PhoneAPI.dll]& &&&1, 0, 0, 1&& & [D:\qq\DialerAllinOne.dll]& &tencent&&1, 4, 0, 0&& & [D:\qq\QQAvatar.dll]& &N/A&&N/A&& & [D:\qq\FlashAvatarDll.dll]& &&&1, 4, 0, 1&& & [D:\qq\LongConnection.dll]& &tencent&&5, 0, 200, 160&& & [D:\qq\QQPet.dll]& &&&1, 0, 0, 1&& & [D:\qq\QQSysMsgMng.dll]& &N/A&&N/A&& & [D:\qq\BQQApplication.dll]& &N/A&&N/A&[PID: 1808][D:\qq\TIMPlatform.exe]& &tencent&&0, 3, 1, 8&& & [D:\qq\TIMProxy.dll]& &tencent&&0, 3, 2, 4&[PID: 1720][D:\System Repair Engine\新建文件夹\SREng2\SREng.exe]& &Smallfrogs Studio&&2.0.21.505&==================================文件关联.TXT& OK. [%SystemRoot%\system32\NOTEPAD.EXE %1].EXE& OK. ["%1" %*].COM& OK. ["%1" %*].PIF& OK. ["%1" %*].REG& OK. [regedit.exe "%1"].BAT& OK. ["%1" %*].SCR& OK. ["%1" /S].CHM& Error. ["hh.exe" %1].HLP& OK. [%SystemRoot%\system32\winhlp32.exe %1].INI& OK. [%SystemRoot%\System32\NOTEPAD.EXE %1].INF& OK. [%SystemRoot%\System32\NOTEPAD.EXE %1].VBS& OK. [%SystemRoot%\System32\WScript.exe "%1" %*].JS& OK. [%SystemRoot%\System32\WScript.exe "%1" %*].LNK& OK. [{0-}]==================================Winsock 提供者==================================
花非花月 -
15:23:00病毒名称处理结果发现日期扫描方式路径文件病毒来源Harm.RavFree.mj& 删除成功&
11:48& 手动扫描D:\System Volume Information\_restore{BC6-4F47-B222-C602C03838E3}\RP79A0365379.exe本机Harm.RavFree.mj& 删除成功&
11:51& 手动扫描D:\SHADUcncrk_public.rar&&RSUpper.exe本机Harm.RavFree.mj& 删除成功&
11:51& 手动扫描D:\SHADUcncrk_public.exe&&RSUpper.exe本机Harm.RavFree.mj& 删除成功&
14:50& 手动扫描& D:\System Volume Information\_restore{BC6-4F47-B222-C602C03838E3}\RP79A0367429.exe&&RSUpper.exe本机最后一回是在安全模式下杀的。对了,还有c:\windows\system32\yjbqtyhf.d1l删不了,也找不到用了一下金山在线杀毒,误下了金山程序再d盘,删了文件夹发现c盘有东西???发现留下了一些东西,怕和瑞星起冲突,请告诉一声又没有要删的...附件:
19:32:00如果没有系统没有什么异常,没有必要对金山的问题担心。那几个病毒出现在系统还原里。你关掉它就不会再扫出病毒了yjbqtyhf.d1l这个东东很可疑,但我却没有办法删除它如果你实在解决不了,可以考虑使用系统还原来试一下。
花非花月 -
23:55:00引用:【我无邪的贴子】那几个病毒出现在系统还原里。你关掉它就不会再扫出病毒了………………汗....不明白这句话的意思yjbqtyhf.d1l这个东东我搜不到找也没找到。除了重装系统还有别的办法吗?偶对这个词很怵...等会杀完毒我在贴一份日志上来,请看看还有别的问题吗电脑重启很麻烦,不知是否是别的原因造成呢?CPU占用率达到百分之百时一般是打开IE某网站(没准哪个)造成附件:
花非花月 -
23:59:00接楼上:附件:
查看完整版本:

我要回帖

更多关于 竹制伊钩容易开裂吧 的文章

 

随机推荐