瑞星卡卡安全论坛
沿边 - 2005-11-28 20:57:00
最近机器老是出现这个这个病毒,每次杀都是删除成功,可是也解决不了,它的路径是c:\ststem volume information\_restore...
飞跃迷离 - 2005-11-28 21:00:00
请关闭系统还原!如果关闭系统请参考:
【整理】瑞星杀毒时提示“请解压”怎么办?
http://forum.ikaka.com/topic.asp?board=28&artid=5216854
沿边 - 2005-12-1 14:33:00
关闭系统还原后怎么办,瑞星不是提示需要解压,而是删除成功,但是再杀还是有,而且最近也觉得网速慢了.
沿边 - 2005-12-1 14:35:00
而且我把IE清除了,再杀还是有
顺风尿尿尿你一腿 - 2005-12-1 14:35:00
再杀毒时瑞星提示的路径是什么地方?
沿边 - 2005-12-1 14:38:00
还是上面那个地方c:\ststem volume information\_restore...
BlackStone - 2005-12-1 14:40:00
| 引用: |
【沿边的贴子】还是上面那个地方c:\ststem volume information\_restore...
........................... |
关闭XP的系统还原再杀
附件:
5887812005121144032.JPG
沿边 - 2005-12-1 14:50:00
好的,我试试.这个地方也有方法但是我有些疑惑 http://forum.ikaka.com/topic.asp?board=39&artid=7446751 病毒在系统还原与IE缓存中,可以通过关闭和删除这些来删除病毒.
另清空C:\DOCUME~1\GIVNEK~1\LOCALS~1\Temp\目录所有文件.他说的地址,Temp下有很多文件的,要全删除吗?那样对电脑有影响吗?
沿边 - 2005-12-1 15:16:00
不行啊,刚杀一遍瑞星就没有发现病毒,扫描病毒0个?可是之前我还刚杀过一遍,删除那种病毒8个呢.怎么一关闭系统还原反而找不着病毒了?是怎么回事啊?
BlackStone - 2005-12-1 15:31:00
应该没问题了
关闭系统Windows自动把还原的染毒文件删除了
沿边 - 2005-12-1 15:35:00
我还是想问问 http://forum.ikaka.com/topic.asp?board=39&artid=7446751 病毒在系统还原与IE缓存中,可以通过关闭和删除这些来删除病毒.另清空C:\DOCUME~1\GIVNEK~1\LOCALS~1\Temp\目录所有文件. 他说的地址,Temp下有很多文件的,要全删除吗?那样对电脑有影响吗?
BlackStone - 2005-12-1 15:52:00
全部删除没问题的
C:\DOCUME~1\GIVNEK~1\LOCALS~1\Temp本来就是存放临时文件的
沿边 - 2005-12-1 15:56:00
谢谢,知道了
沿边 - 2005-12-4 12:14:00
不行啊,再重新打开系统还原后,病毒还在,还是那个病毒,出现黄色网页
沿边 - 2005-12-4 19:42:00
高手,能不能帮我看看啊,为什么按照上面的方法不行呢?如果我重新再打开系统还原后,病毒就又出现了.
命运里の金色 - 2005-12-4 20:04:00
控制面板-性能和维护-在您的硬盘上释放空间-其他选项-系统还原-清理
关闭系统还原时,选择清空还原点
看看病毒是不是存在
再重新打开系统还原后,病毒还在,还是那个病毒,出现黄色网页
这个情况是不是你没把还原点删除,后来又去还原系统了
沿边 - 2005-12-4 20:16:00
我就按照六楼的方法做的,选择关闭系统还原,点机应用时,它会问你:这样会失去所有的还原点,继续 吗? 我点的继续才能关闭系统还原的,关闭以后杀,没有发现病毒.可是昨天我打开机器又恢复了系统还原,不一会那个黄色网页就出现了.还是那个病毒名称.
沿边 - 2005-12-4 20:25:00
我刚刚又杀了一遍,是在开着系统还原的状态下,没有发现病毒,可是 为什么那个黄色网页还出现呢?
命运里の金色 - 2005-12-4 22:17:00
| 引用: |
【沿边的贴子】我刚刚又杀了一遍,是在开着系统还原的状态下,没有发现病毒,可是 为什么那个黄色网页还出现呢? ........................... |
用置顶帖子里的hijackthis扫描后,把日志贴上来
冰点的鱼 - 2005-12-4 22:33:00
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\Program Files\Rising\Rfw\rfwsrv.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Rising\Rfw\rfwmain.exe
C:\Program Files\Maxthon\Thundermini\ThunderMini.exe
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Maxthon\Maxthon.exe
C:\WINDOWS\system32\mspaint.exe
C:\DOCUME~1\sun\LOCALS~1\Temp\Rar$EX00.538\HijackThis1991zww.exe
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v4.dll
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - F:\QQ\QQIEHelper.dll
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: Infofo 工具栏 - {D74EC18E-3DDD-4174-B1B1-949FE3B8366D} - C:\Program Files\Infofo Bar\infofobar.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - IE工具栏增项: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll
O3 - IE工具栏增项: Infofo 工具栏 - {D74EC18E-3DDD-4174-B1B1-949FE3B8366D} - C:\Program Files\Infofo Bar\infofobar.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [thunder_mini] C:\Program Files\Maxthon\Thundermini\ThunderMini.exe
O4 - 启动项HKLM\\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - 启动项HKLM\\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera 301x
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - 启动项HKLM\\Run: [Update] C:\WINDOWS\System32\Update.exe
O4 - 启动项HKLM\\Run: [SVCH0ST] C:\Program Files\sfx software\SVCH0ST.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [iPlusAgent] "C:\Program Files\iriver\iriver plus\iAgent.exe"
O4 - HKCU\..\Run: [SDO2005] C:\Program Files\盛大圈圈\SDOLauncher.exe -s"-s 3"
O8 - IE右键菜单中的新增项目: &使用迷你迅雷下载 - C:\Program Files\Maxthon\Thundermini\geturl.htm
O8 - IE右键菜单中的新增项目: 使用Kugoo下载 - E:\Program Files\KuGoo2\KugooDownX.htm
O8 - IE右键菜单中的新增项目: 百度-搜索MP3 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUMP3.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索图片 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUIMG.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索新闻 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUNEWS.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索歌词 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDULYRIC.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索网页 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUSEARCH.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索贴吧 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUPOST.HTM
O8 - IE右键菜单中的新增项目: 百度-词典搜索 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_DIC.HTM
O9 - 浏览器额外的按钮: Infofo 工具栏 - {8507326C-B5C1-4559-BB91-0919E753836F} - C:\Program Files\Infofo Bar\infofobar.dll
O9 - 浏览器额外的“工具”菜单项: Infofo 工具栏 - {8507326C-B5C1-4559-BB91-0919E753836F} - C:\Program Files\Infofo Bar\infofobar.dll
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - F:\QQ\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - F:\QQ\QQIEHelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1133703580333
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl Object) - https://tenpay.qq.com/download/qqedit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{613666EA-89F4-4499-9D2B-EC760398F5C2}: NameServer = 202.101.172.46 202.101.172.47
O20 - AppInit_DLLs: 351677AppInit.DLL
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - C:\Program Files\Rising\Rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
命运里の金色 - 2005-12-5 13:24:00
O4 - 启动项HKLM\\Run: [Update] C:\WINDOWS\System32\Update.exe
O4 - 启动项HKLM\\Run: [SVCH0ST] C:\Program Files\sfx software\SVCH0ST.exe
请把这两个文件打包发到virusdied@yahoo.com.cn,谢谢,有结果我会悄悄话告诉你,礼拜五到家才能给你结果
沿边 - 2005-12-6 17:30:00
Logfile of HijackThis v1.99.1
Scan saved at 17:25:11, on 2005-12-6
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
运行进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\rising\Rfw\rfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lenovo\幸福一键通\Kbdriver.exe
C:\Program Files\Lenovo\幸福一键通\FlyShuttle.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\VM303_STI.EXE
C:\Program Files\rising\Rfw\RfwMain.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\system32\conime.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
c:\program files\rising\rav\RAVMON.EXE
D:\Program Files\Netease\pp\popo.exe
D:\Program Files\Netease\pp\popo.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Xi\NetTransport 2\NetTransport.exe
D:\Program Files\shadu\HijackThis v1.99.1 汉化版\HijackThis.exe
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - D:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (没有文件)
O3 - Toolbar: (no name) - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - (没有文件)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Lskbdrv] C:\Program Files\Lenovo\幸福一键通\Kbdriver.exe
O4 - HKLM\..\Run: [LenSoft] C:\Program Files\Lenovo\幸福一键通\FlyShuttle.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [ExFilter] Rundll32.exe "C:\PROGRA~1\CNNIC\Cdn\cdnspie.dll",ExecFilter solo
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [NMGameX_AutoRun] C:\WINDOWS\System32\Rundll32.exe NMGameX.dll,LiveProcess /aa
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - HKLM\..\Run: [mstasks.exe] C:\WINDOWS\System32\mstasks.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: 腾讯QQ.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 使用影音传送带下载 - D:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - D:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: 收藏此页到ViVi - http://vivi.sina.com.cn/collect/click.php?agent=ddt
O8 - Extra context menu item: 新浪搜索 - http://cha.sina.com.cn/ddt.html
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\qq\SendMMS.htm
O9 - Extra button: 联想 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.legend.com (文件故障)
O9 - Extra button: 卓越 - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: 金山词霸 - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\新建文件夹\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\新建文件夹\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.legend.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{59F3EB3F-D3EB-4D56-A585-46BCB5684BE4}: NameServer = 211.98.192.3 61.233.65.3
O17 - HKLM\System\CS1\Services\Tcpip\..\{59F3EB3F-D3EB-4D56-A585-46BCB5684BE4}: NameServer = 211.98.192.3 61.233.65.3是这样吗?上传日志我不太会,第一次上传,不知道是不是
沿边 - 2005-12-7 15:55:00
高手能不能帮我看看啊,这个病毒又和以前不太一样了,网页出现的地址不是原来的地址,内容也不一样,可是瑞星查杀时,还是显示这个病毒的名称,而且现在是开机就有,日志再上传一下
Logfile of HijackThis v1.99.1
Scan saved at 15:51:54, on 2005-12-7
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
运行进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\rising\Rfw\rfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lenovo\幸福一键通\Kbdriver.exe
C:\Program Files\Lenovo\幸福一键通\FlyShuttle.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\Program Files\rising\Rfw\rfwmain.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\VM303_STI.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\system32\conime.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
c:\program files\rising\rav\RAVMON.EXE
c:\program files\rising\rav\RAV.EXE
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\shadu\HijackThis v1.99.1 汉化版\HijackThis.exe
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - D:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (没有文件)
O3 - Toolbar: (no name) - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - (没有文件)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Lskbdrv] C:\Program Files\Lenovo\幸福一键通\Kbdriver.exe
O4 - HKLM\..\Run: [LenSoft] C:\Program Files\Lenovo\幸福一键通\FlyShuttle.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [ExFilter] Rundll32.exe "C:\PROGRA~1\CNNIC\Cdn\cdnspie.dll",ExecFilter solo
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [NMGameX_AutoRun] C:\WINDOWS\System32\Rundll32.exe NMGameX.dll,LiveProcess /aa
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - HKLM\..\Run: [mstasks.exe] C:\WINDOWS\System32\mstasks.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: 腾讯QQ.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 使用影音传送带下载 - D:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - D:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: 收藏此页到ViVi - http://vivi.sina.com.cn/collect/click.php?agent=ddt
O8 - Extra context menu item: 新浪搜索 - http://cha.sina.com.cn/ddt.html
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\qq\SendMMS.htm
O9 - Extra button: 联想 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.legend.com (文件故障)
O9 - Extra button: 卓越 - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: 金山词霸 - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\新建文件夹\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\新建文件夹\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.legend.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{59F3EB3F-D3EB-4D56-A585-46BCB5684BE4}: NameServer = 211.98.192.3 61.233.65.3
O17 - HKLM\System\CS1\Services\Tcpip\..\{59F3EB3F-D3EB-4D56-A585-46BCB5684BE4}: NameServer = 211.98.192.3 61.233.65.3
BlackStone - 2005-12-7 15:58:00
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [mstasks.exe] C:\WINDOWS\System32\mstasks.exe
修复
重启
删除C:\WINDOWS\System32\mstasks.exe;C:\WINDOWS\htpatch.exe试试
沿边 - 2005-12-7 16:29:00
用autoruns扫的
NT\CurrentVersion\Winlogon\Userinit
+ C:\WINDOWS\system32\userinit.exeUserinit Logon ApplicationMicrosoft Corporationc:\windows\system32\userinit.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
+ Explorer.exeWindows ExplorerMicrosoft Corporationc:\windows\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ BigDog303VimicroVimicroc:\windows\vm303_sti.exe
+ ExFiltercdnspiec:\program files\cnnic\cdn\cdnspie.dll
+ HTpatchc:\windows\htpatch.exe
+ IMJPMIG8.1Microsoft IMEMicrosoft Corporationc:\windows\ime\imjp8_1\imjpmig.exe
+ IMSCMig微软拼音输入法安装工具Microsoft Corporationc:\program files\common files\microsoft shared\ime\imsc40a\imscmig.exe
+ LenSoftFlyShuttle Microsoft 基础类应用程序c:\program files\lenovo\幸福一键通\flyshuttle.exe
+ Lskbdrvc:\program files\lenovo\幸福一键通\kbdriver.exe
+ mstasks.exeFile not found: C:\WINDOWS\System32\mstasks.exe
+ NMGameX_AutoRunRun a DLL as an AppMicrosoft Corporationc:\windows\system32\rundll32.exe
+ NvCplDaemonNVIDIA Taskbar Utility LibraryNVIDIA Corporationc:\windows\system32\nvqtwk.dll
+ nwizNVIDIA nView Control Panel, Version 28.32 NVIDIA Corporationc:\windows\system32\nwiz.exe
+ PHIME2002A微軟新注音輸入法 2002aMicrosoft Corporationc:\windows\system32\ime\tintlgnt\tintsetp.exe
+ PHIME2002ASync微軟新注音輸入法 2002aMicrosoft Corporationc:\windows\system32\ime\tintlgnt\tintsetp.exe
+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmon.exe
+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtimer.exe
+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwmain.exe
+ SoundManRealtek Sound ManagerRealtek Semiconductor Corp.C:\WINDOWS\soundman.exe
+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe
C:\Documents and Settings\All Users\「开始」菜单\程序\启动
+ InterVideo WinCinema Manager.lnkWinCinema Managerc:\program files\intervideo\common\bin\wincinemamgr.exe
C:\Documents and Settings\Owner\「开始」菜单\程序\启动
+ 腾讯QQ.lnkd:\program files\新建文件夹\qq.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ ctfmon.exeCTF LoaderMicrosoft Corporationc:\windows\system32\ctfmon.exe
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
+ Internet ExplorerWindows NT User Data Migration ToolMicrosoft Corporationc:\windows\system32\shmgrate.exe
+ Internet Explorer 6IE 5.0 Per-User Install UtilityMicrosoft Corporationc:\windows\system32\ie4uinit.exe
+ Microsoft Outlook Express 6Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe
+ Microsoft Windows Media PlayerADVPACKMicrosoft Corporationc:\windows\system32\advpack.dll
+ NetMeeting 3.01ADVPACKMicrosoft Corporationc:\windows\system32\advpack.dll
+ Outlook ExpressWindows NT User Data Migration ToolMicrosoft Corporationc:\windows\system32\shmgrate.exe
+ Themes SetupMicrosoft(C) Register ServerMicrosoft Corporationc:\windows\system32\regsvr32.exe
+ Windows Media PlayerMicrosoft Windows Media Player 安装实用程序Microsoft Corporationc:\windows\inf\unregmp2.exe
+ Windows Messenger 4.7ADVPACKMicrosoft Corporationc:\windows\system32\advpack.dll
+ Windows 桌面更新Microsoft(C) Register ServerMicrosoft Corporationc:\windows\system32\regsvr32.exe
+ 通讯簿 6Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
+ Browseui 预加载程序Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 组件类别缓存程序Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ CDBurnWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ PostBootReminderWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ SysTraySystray shell service objectMicrosoft Corporationc:\windows\system32\stobject.dll
+ WebCheckWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
+ shell32.dllWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ Auto Update Property Sheet ExtensionAutomatic Updates Control PanelMicrosoft Corporationc:\windows\system32\wuaucpl.cpl
+ Extensions Manager FolderExtensions ManagerMicrosoft Corporationc:\windows\system32\extmgr.dll
+ Microsoft Office HTML Icon HandlerMicrosoft Office 2003 componentMicrosoft Corporationc:\program files\microsoft office\office11\msohev.dll
+ Portable Media Devices便携媒体设备命令行解释器扩展Microsoft Corporationc:\windows\system32\audiodev.dll
+ Portable Media Devices Menu便携媒体设备命令行解释器扩展Microsoft Corporationc:\windows\system32\audiodev.dll
+ Previous VersionsPrevious Versions property pageMicrosoft Corporationc:\windows\system32\twext.dll
+ Previous Versions Property PagePrevious Versions property pageMicrosoft Corporationc:\windows\system32\twext.dll
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
+ Set Program Access and DefaultsShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realplayer\rpshell.dll
+ Web FoldersMicrosoft Web FoldersMicrosoft Corporationc:\program files\common files\microsoft shared\web folders\msonsext.dll
+ Windows Media Player Add to Playlist Context Menu HandlerWindows Media Player LauncherMicrosoft Corporationc:\windows\system32\wmpshell.dll
+ Windows Media Player Burn Audio CD Context Menu HandlerWindows Media Player LauncherMicrosoft Corporationc:\windows\system32\wmpshell.dll
+ Windows Media Player Play as Playlist Context Menu HandlerWindows Media Player LauncherMicrosoft Corporationc:\windows\system32\wmpshell.dll
HKLM\Software\Classes\Folder\Shellex\ColumnHandlers
+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ {24F14F01-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ {24F14F02-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ {66742402-F9B9-11D1-A202-0000F81FEDEE}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ NTIECatcher ClassNet Transport IE Helper ModuleXid:\program files\xi\nettransport 2\ntiehelper.dll
+ QQBrowserHelperObject ClassQQIEHelper Module深圳市腾讯计算机系统有限公司c:\program files\tencent\qq\qqiehelper.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
沿边 - 2005-12-7 16:32:00
+ shdocvw.dllShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ Windows MessengerWindows MessengerMicrosoft Corporationc:\program files\messenger\msmsgs.exe
+ 联想File not found: http://www.legend.com
+ 腾讯QQd:\program files\新建文件夹\qq.exe
HKLM\System\CurrentControlSet\Services
+ AudioSrv管理基于 Windows 的程序的音频设备。如果此服务被终止,音频设备及其音效将不能正常工作。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ Browser维护网络上计算机的更新列表,并将列表提供给计算机指定浏览。如果服务停止,列表不会被更新或维护。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ CryptSvc提供三种管理服务: 编录数据库服务,它确定 Windows 文件的签字; 受保护的根服务,它从此计算机添加和删除受信根证书机构的证书;和密钥(Key)服务,它帮助注册此计算机获取证书。如果此服务被终止,这些管理服务将无法正常运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ DcomLaunch为 DCOM 服务提供加载功能。Microsoft Corporationc:\windows\system32\svchost.exe
+ Dhcp通过注册和更改 IP 地址以及 DNS 名称来管理网络配置。Microsoft Corporationc:\windows\system32\svchost.exe
+ Dnscache为此计算机解析和缓冲域名系统 (DNS) 名称。如果此服务被停止,计算机将不能解析 DNS 名称并定位 Active Directory 域控制器。如果此服务被禁用,任何明确依赖它的服务将不能启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ ERSvc服务和应用程序在非标准环境下运行时允许错误报告。Microsoft Corporationc:\windows\system32\svchost.exe
+ Eventlog启用在事件查看器查看基于 Windows 的程序和组件颁发的事件日志消息。无法终止此服务。Microsoft Corporationc:\windows\system32\services.exe
+ helpsvc启用在此计算机上运行帮助和支持中心。如果停止服务,帮助和支持中心将不可用。如果禁用服务,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ lanmanserver支持此计算机通过网络的文件、打印、和命名管道共享。如果服务停止,这些功能不可用。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ lanmanworkstation创建和维护到远程服务的客户端网络连接。如果服务停止,这些连接将不可用。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ LmHosts允许对“TCP/IP 上 NetBIOS (NetBT)”服务以及 NetBIOS 名称解析的支持。Microsoft Corporationc:\windows\system32\svchost.exe
+ NtFrs32c:\windows\system32\ntfrs32.exe
+ NVSvcNVIDIA Driver Helper Service, Version 28.32NVIDIA Corporationc:\windows\system32\nvsvc32.exe
+ PlugPlay使计算机在极少或没有用户输入的情况下能识别并适应硬件的更改。终止或禁用此服务会造成系统不稳定。Microsoft Corporationc:\windows\system32\services.exe
+ PolicyAgent管理 IP 安全策略以及启动 ISAKMP/Oakley (IKE) 和 IP 安全驱动程序。Microsoft Corporationc:\windows\system32\lsass.exe
+ ProtectedStorage提供对敏感数据(如私钥)的保护性存储,以便防止未授权的服务,过程或用户对其的非法访问。Microsoft Corporationc:\windows\system32\lsass.exe
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwsrv.exe
+ RpcSs提供终结点映射程序 (endpoint mapper) 以及其它 RPC 服务。Microsoft Corporationc:\windows\system32\svchost.exe
+ RsCCenterCCenterrisingc:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe
+ SamSs存储本地用户帐户的安全信息。Microsoft Corporationc:\windows\system32\lsass.exe
+ Schedule使用户能在此计算机上配置和制定自动任务的日程。如果此服务被终止,这些任务将无法在日程时间里运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ seclogon启用替换凭据下的启用进程。如果此服务被终止,此类型登录访问将不可用。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ SENS跟踪系统事件,如登录 Windows,网络以及电源事件等。将这些事件通知给 COM+ 事件系统 “订阅者(subscriber)”。Microsoft Corporationc:\windows\system32\svchost.exe
+ SharedAccess为家庭或小型办公网络提供网络地址转换,定址以及名称解析和/或防止入侵服务。Microsoft Corporationc:\windows\system32\svchost.exe
+ ShellHWDetectionGeneric Host Process for Win32 ServicesMicrosoft Corporationc:\windows\system32\svchost.exe
+ Spooler将文件加载到内存中以便迟后打印。Microsoft Corporationc:\windows\system32\spoolsv.exe
+ srservice执行系统还原功能。 要停止服务,请从“我的电脑”的属性中的系统还原选项卡关闭系统还原Microsoft Corporationc:\windows\system32\svchost.exe
+ stisvc为扫描仪和照相机提供图像捕获。Microsoft Corporationc:\windows\system32\svchost.exe
+ Themes为用户提供使用主题管理的经验。Microsoft Corporationc:\windows\system32\svchost.exe
+ TrkWks在计算机内 NTFS 文件之间保持链接或在网络域中的计算机之间保持链接。Microsoft Corporationc:\windows\system32\svchost.exe
+ UMWdf启用 Windows 用户模式驱动程序。Microsoft Corporationc:\windows\system32\wdfmgr.exe
+ W32Time维护在网络上的所有客户端和服务器的时间和日期同步。如果此服务被停止,时间和日期的同步将不可用。如果此服务被禁用,任何明确依赖它的服务都将不能启动。
Microsoft Corporationc:\windows\system32\svchost.exe
+ WebClient使基于 Windows 的程序能创建、访问和修改基于 Internet 的文件。如果此服务被终止,将会失去这些功能。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ winmgmt提供共同的界面和对象模式以便访问有关操作系统、设备、应用程序和服务的管理信息。如果此服务被终止,多数基于 Windows 的软件将无法正常运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ wscsvc监视系统安全设置和配置。Microsoft Corporationc:\windows\system32\svchost.exe
+ wuauserv允许下载并安装 Windows 更新。如果此服务被禁用,计算机将不能使用 Windows Update 网站的自动更新功能。Microsoft Corporationc:\windows\system32\svchost.exe
+ WZCSVC为您的 802.11 适配器提供自动配置Microsoft Corporationc:\windows\system32\svchost.exe
HKLM\System\CurrentControlSet\Services
+ ACPIACPI Driver for NTMicrosoft Corporationc:\windows\system32\drivers\acpi.sys
+ aecMicrosoft Acoustic Echo CancellerMicrosoft Corporationc:\windows\system32\drivers\aec.sys
+ AFDAFD 网络支持环境Microsoft Corporationc:\windows\system32\drivers\afd.sys
+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\windows\system32\drivers\alcxwdm.sys
+ AsyncMacRAS Asynchronous Media DriverMicrosoft Corporationc:\windows\system32\drivers\asyncmac.sys
+ atapiIDE/ATAPI Port DriverMicrosoft Corporationc:\windows\system32\drivers\atapi.sys
+ AtmarpcATM ARP Client ProtocolMicrosoft Corporationc:\windows\system32\drivers\atmarpc.sys
+ audstubAudStub DriverMicrosoft Corporationc:\windows\system32\drivers\audstub.sys
+ BaseTDIbasetdiRisingc:\windows\system32\drivers\basetdi.sys
+ basic2NTRksample driverConexantc:\windows\system32\drivers\hsf_bsc2.sys
+ CCDECODEWDM Closed Caption VBI CodecMicrosoft Corporationc:\windows\system32\drivers\ccdecode.sys
+ CdromSCSI CD-ROM DriverMicrosoft Corporationc:\windows\system32\drivers\cdrom.sys
+ DiskPnP Disk DriverMicrosoft Corporationc:\windows\system32\drivers\disk.sys
+ DMusicMicrosoft Kernel DLS SynthesizerMicrosoft Corporationc:\windows\system32\drivers\dmusic.sys
+ drmkaudMicrosoft Kernel DRM Audio Descrambler FilterMicrosoft Corporationc:\windows\system32\drivers\drmkaud.sys
+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys
+ FdcFloppy Disk Controller DriverMicrosoft Corporationc:\windows\system32\drivers\fdc.sys
+ FlpydiskFloppy DriverMicrosoft Corporationc:\windows\system32\drivers\flpydisk.sys
+ FsVgaFull Screen Video DriverMicrosoft Corporationc:\windows\system32\drivers\fsvga.sys
+ FtdiskFT Disk DriverMicrosoft Corporationc:\windows\system32\drivers\ftdisk.sys
+ gameenumGame Port EnumeratorMicrosoft Corporationc:\windows\system32\drivers\gameenum.sys
+ GpcGeneric Packet ClassifierMicrosoft Corporationc:\windows\system32\drivers\msgpc.sys
+ hidusbUSB Miniport Driver for Input DevicesMicrosoft Corporationc:\windows\system32\drivers\hidusb.sys
+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys
+ HookRegc:\program files\rising\rav\hookreg.sys
+ HookSys瑞星c:\program files\rising\rav\hooksys.sys
+ HSF_DPHSF_DP driverConexant Systemsc:\windows\system32\drivers\hsf_dp.sys
+ hsf_msftWinACHSF driverConexantc:\windows\system32\drivers\hsf_msft.sys
+ HSFHWBS2HSF_HWB2 WDM driverConexant Systemsc:\windows\system32\drivers\hsfhwbs2.sys
+ HTTP此服务实现超文本传送协议(HTTP)。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\drivers\http.sys
+ i8042prti8042 Port DriverMicrosoft Corporationc:\windows\system32\drivers\i8042prt.sys
+ ImapiIMAPI Kernel DriverMicrosoft Corporationc:\windows\system32\drivers\imapi.sys
+ ip6fw为家庭或小型办公网络提供入侵保护服务。Microsoft Corporationc:\windows\system32\drivers\ip6fw.sys
+ IpFilterDriverIP Traffic Filter DriverMicrosoft Corporationc:\windows\system32\drivers\ipfltdrv.sys
+ IpInIpIP in IP Tunnel DriverMicrosoft Corporationc:\windows\system32\drivers\ipinip.sys
+ IpNatIP Network Address TranslatorMicrosoft Corporationc:\windows\system32\drivers\ipnat.sys
+ IPSecIPSEC driverMicrosoft Corporationc:\windows\system32\drivers\ipsec.sys
沿边 - 2005-12-7 16:32:00
+ IRENUMInfra-Red Bus EnumeratorMicrosoft Corporationc:\windows\system32\drivers\irenum.sys
+ isapnpPNP ISA Bus DriverMicrosoft Corporationc:\windows\system32\drivers\isapnp.sys
+ KbdclassKeyboard Class DriverMicrosoft Corporationc:\windows\system32\drivers\kbdclass.sys
+ kmixerKernel Mode Audio MixerMicrosoft Corporationc:\windows\system32\drivers\kmixer.sys
+ kmsinputc:\windows\system32\drivers\kmsinput.sys
+ mdmxsdkDiagnostic Interface DRIVERConexantc:\windows\system32\drivers\mdmxsdk.sys
+ MouclassMouse Class DriverMicrosoft Corporationc:\windows\system32\drivers\mouclass.sys
+ mouhidHID Mouse Filter DriverMicrosoft Corporationc:\windows\system32\drivers\mouhid.sys
+ ms_mpu401MPU401 Adapter DriverMicrosoft Corporationc:\windows\system32\drivers\msmpu401.sys
+ MSJDrvrc:\windows\system32\drivers\msjdrvr.sys
+ MSKSSRVMS KS ServerMicrosoft Corporationc:\windows\system32\drivers\mskssrv.sys
+ MSPCLOCKMS Proxy ClockMicrosoft Corporationc:\windows\system32\drivers\mspclock.sys
+ MSPQMMS Proxy Quality ManagerMicrosoft Corporationc:\windows\system32\drivers\mspqm.sys
+ mssmbiosSystem Management BIOS DriverMicrosoft Corporationc:\windows\system32\drivers\mssmbios.sys
+ MSTEEWDM Tee/Communication Transform Filter Microsoft Corporationc:\windows\system32\drivers\mstee.sys
+ NABTSFECWDM NABTS/FEC VBI CodecMicrosoft Corporationc:\windows\system32\drivers\nabtsfec.sys
+ NdisIPMicrosoft IP DriverMicrosoft Corporationc:\windows\system32\drivers\ndisip.sys
+ NdisTapiRemote Access NDIS TAPI DriverMicrosoft Corporationc:\windows\system32\drivers\ndistapi.sys
+ NdisuioNDIS 用户模式 I/O 协议Microsoft Corporationc:\windows\system32\drivers\ndisuio.sys
+ NdisWanRemote Access NDIS WAN DriverMicrosoft Corporationc:\windows\system32\drivers\ndiswan.sys
+ NetBTNetBios over TcpipMicrosoft Corporationc:\windows\system32\drivers\netbt.sys
+ New0c:\windows\system32\new.sys
+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.c:\program files\tencent\qq\npkcrypt.sys
+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 28.32 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys
+ NwlnkFltIPX Traffic Filter DriverMicrosoft Corporationc:\windows\system32\drivers\nwlnkflt.sys
+ NwlnkFwdIPX Traffic Forwarder DriverMicrosoft Corporationc:\windows\system32\drivers\nwlnkfwd.sys
+ ParportParallel Port DriverMicrosoft Corporationc:\windows\system32\drivers\parport.sys
+ PCINT Plug and Play PCI EnumeratorMicrosoft Corporationc:\windows\system32\drivers\pci.sys
+ PCIIdeGeneric PCI IDE Bus DriverMicrosoft Corporationc:\windows\system32\drivers\pciide.sys
+ PptpMiniportWAN Miniport (PPTP)Microsoft Corporationc:\windows\system32\drivers\raspptp.sys
+ ProcessorProcessor Device DriverMicrosoft Corporationc:\windows\system32\drivers\processr.sys
+ PSchedQoS Packet SchedulerMicrosoft Corporationc:\windows\system32\drivers\psched.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys
+ RasAcdRemote Access Auto Connection DriverMicrosoft Corporationc:\windows\system32\drivers\rasacd.sys
+ Rasl2tpWAN Miniport (L2TP)Microsoft Corporationc:\windows\system32\drivers\rasl2tp.sys
+ RasPppoe远程访问 PPPOE 驱动程序Microsoft Corporationc:\windows\system32\drivers\raspppoe.sys
+ RasptiDirect ParallelMicrosoft Corporationc:\windows\system32\drivers\raspti.sys
+ RDPCDDRDP MiniportMicrosoft Corporationc:\windows\system32\drivers\rdpcdd.sys
+ redbookRedbook Audio Filter DriverMicrosoft Corporationc:\windows\system32\drivers\redbook.sys
+ RksampleRksample WDM driverConexantc:\windows\system32\drivers\hsf_samp.sys
+ RsFwDrvnt_fwdrvRisingc:\program files\rising\rfw\rsfwdrv.sys
+ rtl8139NDIS 5.0 driver Realtek Semiconductor Corporation c:\windows\system32\drivers\rtl8139.sys
+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys
+ serenumSerial Port EnumeratorMicrosoft Corporationc:\windows\system32\drivers\serenum.sys
+ SerialSerial Device DriverMicrosoft Corporationc:\windows\system32\drivers\serial.sys
+ sisagpSiS NT AGP FilterSilicon Integrated Systems Corporationc:\windows\system32\drivers\sisagpx.sys
+ SiSideSiS PCI Mini IDE DriverSilicon Integrated Systems Corp.c:\windows\system32\drivers\siside.sys
+ sisperfSiS Filter DriverSilicon Integrated Systems Corp.c:\windows\system32\drivers\sisperf.sys
+ SLIPMicrosoft Slip Deframing Filter MinidriverMicrosoft Corporationc:\windows\system32\drivers\slip.sys
+ splitterMicrosoft Kernel Audio SplitterMicrosoft Corporationc:\windows\system32\drivers\splitter.sys
+ streamipMicrosoft IP Test DriverMicrosoft Corporationc:\windows\system32\drivers\streamip.sys
+ swenumPlug and Play Software Device EnumeratorMicrosoft Corporationc:\windows\system32\drivers\swenum.sys
+ swmidiMicrosoft GS Wavetable SynthesizerMicrosoft Corporationc:\windows\system32\drivers\swmidi.sys
+ sysaudioSystem Audio WDM FilterMicrosoft Corporationc:\windows\system32\drivers\sysaudio.sys
+ TcpipTCP/IP Protocol DriverMicrosoft Corporationc:\windows\system32\drivers\tcpip.sys
+ TermDDTerminal Server DriverMicrosoft Corporationc:\windows\system32\drivers\termdd.sys
+ UIUSysDiagnostic Interface DRIVERConexantc:\windows\system32\drivers\uiusys.sys
+ UpdateUpdate DriverMicrosoft Corporationc:\windows\system32\drivers\update.sys
+ usbehciEHCI eUSB Miniport DriverMicrosoft Corporationc:\windows\system32\drivers\usbehci.sys
+ usbhubDefault Hub Driver for USBMicrosoft Corporationc:\windows\system32\drivers\usbhub.sys
+ usbohciOHCI USB Miniport DriverMicrosoft Corporationc:\windows\system32\drivers\usbohci.sys
+ USBSTORUSB Mass Storage Class DriverMicrosoft Corporationc:\windows\system32\drivers\usbstor.sys
+ VgaSave控制 VGA 显示适配器以提供基本显示功能。Microsoft Corporationc:\windows\system32\drivers\vga.sys
+ WanarpRemote Access IP ARP DriverMicrosoft Corporationc:\windows\system32\drivers\wanarp.sys
+ wdmaudMMSYSTEM Wave/Midi API mapperMicrosoft Corporationc:\windows\system32\drivers\wdmaud.sys
+ winachsfWinACHSF driverConexant Systemsc:\windows\system32\drivers\hsf_cnxt.sys
+ WSTCODECWDM WST Codec DriverMicrosoft Corporationc:\windows\system32\drivers\wstcodec.sys
+ ZSMC303Video streaming and Capture Device DriverVMc:\windows\system32\drivers\usbvm303.sys
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
沿边 - 2005-12-7 16:35:00
+ autocheck autochk *Auto Check UtilityMicrosoft Corporationc:\windows\system32\autochk.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
+ Your Image File Name Here without a pathSymbolic Debugger for Windows 2000Microsoft Corporationc:\windows\system32\ntsd.exe
HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls
+ advapi32Advanced Windows 32 Base APIMicrosoft Corporationc:\windows\system32\advapi32.dll
+ comdlg32Common Dialogs DLLMicrosoft Corporationc:\windows\system32\comdlg32.dll
+ gdi32GDI Client DLLMicrosoft Corporationc:\windows\system32\gdi32.dll
+ imagehlpWindows NT Image HelperMicrosoft Corporationc:\windows\system32\imagehlp.dll
+ kernel32Windows NT BASE API Client DLLMicrosoft Corporationc:\windows\system32\kernel32.dll
+ lz32LZ Expand/Compress API DLLMicrosoft Corporationc:\windows\system32\lz32.dll
+ ole32Microsoft OLE for WindowsMicrosoft Corporationc:\windows\system32\ole32.dll
+ oleaut32Microsoft Corporationc:\windows\system32\oleaut32.dll
+ olecli32Object Linking and Embedding Client LibraryMicrosoft Corporationc:\windows\system32\olecli32.dll
+ olecnv32Microsoft OLE for WindowsMicrosoft Corporationc:\windows\system32\olecnv32.dll
+ olesvr32Object Linking and Embedding Server LibraryMicrosoft Corporationc:\windows\system32\olesvr32.dll
+ olethk32Microsoft OLE for WindowsMicrosoft Corporationc:\windows\system32\olethk32.dll
+ rpcrt4Remote Procedure Call RuntimeMicrosoft Corporationc:\windows\system32\rpcrt4.dll
+ shell32Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ urlInternet Shortcut Shell Extension DLLMicrosoft Corporationc:\windows\system32\url.dll
+ urlmonOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ user32Windows XP USER API Client DLLMicrosoft Corporationc:\windows\system32\user32.dll
+ versionVersion Checking and File Installation LibrariesMicrosoft Corporationc:\windows\system32\version.dll
+ wininetInternet Extensions for Win32Microsoft Corporationc:\windows\system32\wininet.dll
+ wldap32Win32 LDAP API DLLMicrosoft Corporationc:\windows\system32\wldap32.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
+ crypt32chainCrypto API32Microsoft Corporationc:\windows\system32\crypt32.dll
+ cryptnetCrypto Network Related APIMicrosoft Corporationc:\windows\system32\cryptnet.dll
+ cscdllOffline Network AgentMicrosoft Corporationc:\windows\system32\cscdll.dll
+ ScCertPropCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll
+ ScheduleCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll
+ sclgntfySecondary Logon Service Notification DLLMicrosoft Corporationc:\windows\system32\sclgntfy.dll
+ SensLognCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll
+ termsrvCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll
+ wlballoonCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll
HKCU\Control Panel\Desktop\Scrnsave.exe
+ C:\WINDOWS\System32\logon.scrLogon Screen SaverMicrosoft Corporationc:\windows\system32\logon.scr
HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{59F3EB3F-D3EB-4D56-A585-46BCB5684BE4}] DATAGRAM 4Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{59F3EB3F-D3EB-4D56-A585-46BCB5684BE4}] SEQPACKET 4Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{89EA5E81-4E0F-4751-93A4-58680C819B2D}] DATAGRAM 5Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{89EA5E81-4E0F-4751-93A4-58680C819B2D}] SEQPACKET 5Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{DF3E2B0C-B2DF-4391-B1D5-9488BA891275}] DATAGRAM 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{DF3E2B0C-B2DF-4391-B1D5-9488BA891275}] SEQPACKET 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{E7FC798D-BC33-42D1-B3AF-153A3424A700}] DATAGRAM 3Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{E7FC798D-BC33-42D1-B3AF-153A3424A700}] SEQPACKET 3Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{F70A0718-F2B6-496C-B197-42800DE81A3A}] DATAGRAM 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{F70A0718-F2B6-496C-B197-42800DE81A3A}] SEQPACKET 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{F8CB7A06-5DD2-4AAF-8584-E05F97A8AE67}] DATAGRAM 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{F8CB7A06-5DD2-4AAF-8584-E05F97A8AE67}] SEQPACKET 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD Tcpip [RAW/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD Tcpip [TCP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD Tcpip [UDP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ RSVP TCP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\windows\system32\rsvpsp.dll
+ RSVP UDP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\windows\system32\rsvpsp.dll
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
+ BJ Language MonitorLangage Monitor for Canon Bubble-Jet PrinterMicrosoft Corporationc:\windows\system32\cnbjmon.dll
+ Local PortLocal Spooler DLLMicrosoft Corporationc:\windows\system32\localspl.dll
+ Microsoft Document Imaging Writer MonitorMicrosoft? Document ImagingMicrosoft Corporationc:\windows\system32\mdimon.dll
+ PJL Language MonitorPJL Language monitorMicrosoft Corporationc:\windows\system32\pjlmon.dll
+ Standard TCP/IP PortStandard TCP/IP Port Monitor DLLMicrosoft Corporationc:\windows\system32\tcpmon.dll
+ USB MonitorStandard Dynamic Printing Port Monitor DLLMicrosoft Corporationc:\windows\system32\usbmon.dll终于完了
BlackStone - 2005-12-7 16:47:00
保存日志时注意选择Options->Hide Microsoft Entries菜单项(设置了这项后点工具栏的刷新按钮)
沿边 - 2005-12-7 16:48:00
我只找着C:\WINDOWS\System32\mstasks. dll;没有找到有C:\WINDOWS\htpatch.exe,找了好几遍,也还是没有
© 2000 - 2026 Rising Corp. Ltd.