瑞星卡卡安全论坛
enjoy30 - 2006-4-6 11:29:00
我的电脑中了backdoor.bifrose.fw病毒,怎么也杀不掉!
用瑞星,提示“清除成功”,可重启后病毒依旧。
另还中了Trojan.spy.banker.fcz病毒,瑞星,提示“删除成功”,但重启后病毒依旧
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 11:21:04, 日期 06-4-6
操作系统: Windows 98 SE (Win9x 4.10.2222A)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\YAHOO!\ASSISTANT\YLIVE.EXE
C:\PROGRAM FILES\ZARVASOFT\SMART UPDATE UTILITY\AHNSD.EXE
C:\PROGRAM FILES\YAHOO!\ASSISTANT\YASSISTSE.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\RISING\RAV\RAV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\MY DOCUMENTS\ODC\HIJACKTHIS1991ZWW.EXE
R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YDRAGSEARCH.DLL
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YPHTB.DLL
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YANGLING.DLL
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - 启动项HKLM\\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - 启动项HKLM\\Run: [internat.exe] internat.exe
O4 - 启动项HKLM\\Run: [SystemTray] SysTray.Exe
O4 - 启动项HKLM\\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - 启动项HKLM\\Run: [helper.dll] C:\WINDOWS\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - 启动项HKLM\\Run: [YLive.exe] C:\PROGRA~1\YAHOO!\ASSIST~1\YLive.exe
O4 - 启动项HKLM\\Run: [AHNSD] "C:\Program Files\ZarvaSoft\Smart Update Utility\AhnSD.exe"
O4 - 启动项HKLM\\Run: [yassistse] "C:\PROGRAM FILES\YAHOO!\ASSISTANT\YASSISTSE.EXE"
O4 - 启动项HKLM\\Run: [nwiz32] c:\windows\system\nwiz32.exe
O4 - 启动项HKLM\\Run: [LoadQM] loadqm.exe
O4 - 启动项HKLM\\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - 启动项HKLM\\RunServices: [RsCcenter] "C:\Program Files\Rising\Rav\CCenter.exe"
O4 - 启动项HKLM\\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - 启动项HKLM\\RunServices: [SchedulingAgent] mstask.exe
O4 - 启动项HKLM\\RunServices: [Intnet] C:\WINDOWS\Intnet.exe
O4 - 启动项HKLM\\RunServices: [kavsvc] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe"
O4 - 启动项HKLM\\RunOnce: [YahooC:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\yasbar.dll919602] regsvr32 /s C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\yasbar.dll
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL/246
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\PROGRAM FILES\TENCENT\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\PROGRAM FILES\TENCENT\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\PROGRAM FILES\TENCENT\QQ\SendMMS.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\PROGRAM FILES\TENCENT\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 添加到雅虎订阅(&Y) - res://C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YRSS.DLL/YRSSMENUEXT
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - 浏览器额外的按钮: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)
O9 - 浏览器额外的按钮: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - 浏览器额外的“工具”菜单项: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - 浏览器额外的“工具”菜单项: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O11 - Options group: [!CNS] 上网助手-地址栏搜索
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 202.101.103.54,202.101.103.55
开江叶荣添 - 2006-4-6 11:44:00
就是,麻烦的病毒,还是重新做系统,如果有Ghost 还原也可以!
enjoy30 - 2006-4-6 11:57:00
这是这几天瑞星的扫描结果
病毒名称 处理结果 发现日期 扫描方式 路径 文件
Backdoor.Bifrose.fw 清除成功 2006-03-24 10:58 手动扫描 IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Trojan.Spy.Banker.fcz 删除成功 2006-03-24 11:01 手动扫描 C:\WINDOWS\SYSTEM nwiz32.dll
Trojan.PSW.LMir.jkb 删除成功 2006-03-24 11:11 手动扫描 C:\WINDOWS 29831.DLL
Trojan.PSW.LMir.jkb 删除成功 2006-03-24 11:22 手动扫描 C:\RECYCLED DC0.EXE
Trojan.PSW.GamePass.al 删除成功 2006-03-24 11:22 手动扫描 C:\RECYCLED DC1.EXE
Trojan.Spy.Banker.fcz 删除成功 2006-03-27 11:18 定时扫描 C:\WINDOWS\SYSTEM nwiz32.dll
Trojan.DL.Small.cux 删除成功 2006-03-27 11:22 定时扫描 C:\WINDOWS\Downloaded Program Files StoreProtect.dll
Backdoor.Bifrose.fw 清除成功 2006-03-27 16:55 手动扫描 IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Trojan.Spy.Banker.fcz 删除成功 2006-03-27 16:57 手动扫描 C:\WINDOWS\SYSTEM nwiz32.dll
Backdoor.Bifrose.fw 清除成功 2006-03-28 09:22 手动扫描 IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Backdoor.Bifrose.fw 清除成功 2006-03-28 16:09 手动扫描 IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Backdoor.Bifrose.fw 清除成功 2006-03-28 16:15 手动扫描 IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Backdoor.Bifrose.fw 清除成功 2006-03-28 16:52 手动扫描 IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Backdoor.Bifrose.fw 清除成功 2006-03-29 09:27 手动扫描 IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Backdoor.Bifrose.fw 清除成功 2006-04-03 13:39 手动扫描 IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Backdoor.Bifrose.fw 清除成功 2006-04-04 09:18 手动扫描 IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Backdoor.Bifrose.fw 清除成功 2006-04-05 09:30 手动扫描 IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Backdoor.Bifrose.fw 清除成功 2006-04-05 10:42 手动扫描 IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Trojan.Spy.Banker.fcz 删除成功 2006-04-05 10:44 手动扫描 C:\WINDOWS\SYSTEM nwiz32.dll
Trojan.Spy.Banker.fcz 删除成功 2006-04-05 11:17 定时扫描 C:\WINDOWS\SYSTEM nwiz32.dll
Trojan.Spy.Banker.fcz 删除成功 2006-04-05 14:09 手动扫描 C:\WINDOWS\SYSTEM nwiz32.dll
Backdoor.Bifrose.fw 清除成功 2006-04-06 10:50 手动扫描 IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Trojan.Spy.Banker.fcz 删除成功 2006-04-06 10:53 手动扫描 C:\WINDOWS\SYSTEM nwiz32.dll
Trojan.PSW.GamePass.bm 删除成功 2006-04-06 11:06 手动扫描 C:\Program Files\Internet Explorer test.exe
enjoy30 - 2006-4-6 14:01:00
斑主,能不能赶紧帮忙解决,万分感谢!!
不言放弃 - 2006-4-6 14:11:00
【回复“enjoy30”的帖子】
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
下载System Repair Engineer 2.0.12.350
导出全部日志
enjoy30 - 2006-4-7 9:28:00
SRENG日志
2006-04-07,09:19:07
System Repair Engineer 2.0.12.350 (2.0 RC 1)
Windows 98 Second Edition
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<msnmsgr><"C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ScanRegistry><C:\WINDOWS\scanregw.exe /autorun>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TaskMonitor><C:\WINDOWS\taskmon.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<internat.exe><internat.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SystemTray><SysTray.Exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<LoadPowerProfile><Rundll32.exe powrprof.dll,LoadCurrentPwrScheme>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<helper.dll><C:\WINDOWS\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<YLive.exe><C:\PROGRA~1\YAHOO!\ASSIST~1\YLive.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<AHNSD><"C:\Program Files\ZarvaSoft\Smart Update Utility\AhnSD.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<yassistse><"C:\PROGRAM FILES\YAHOO!\ASSISTANT\YASSISTSE.EXE">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<nwiz32><c:\windows\system\nwiz32.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<LoadQM><loadqm.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<KAVPersonal50><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<YahooC:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\yasbar.dll533217><regsvr32 /s C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\yasbar.dll>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<RsCcenter><"C:\Program Files\Rising\Rav\CCenter.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<LoadPowerProfile><Rundll32.exe powrprof.dll,LoadCurrentPwrScheme>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<SchedulingAgent><mstask.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<Intnet><C:\WINDOWS\Intnet.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<kavsvc><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe">
==================================
启动文件夹
服务
==================================
浏览器加载项
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL, Yahoo!>
[DragSearch]
{62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YDRAGSEARCH.DLL, >
[Yahoo!Photo]
{33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YPHTB.DLL, Yahoo! China>
[AntiFish Class]
{38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YANGLING.DLL, Yahoo.>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[情景聊天]
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[雅虎助手]
{5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
[寻宝乐趣多]
{59BC54A2-56B3-44a0-93E5-432D58746E26} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao, N/A>
[Yahoo 1G电邮]
{507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A>
[]
{FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
[]
{ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH8A.OCX, Macromedia, Inc.>
[MsnMessengerSetupDownloadControl Class]
{B38870E4-7ECB-40DA-8C6A-595F0A5519FF} <C:\WINDOWS\DOWNLOADED PROGRAM FILES\MSNMESSENGERSETUPDOWNLOADER.OCX, Microsoft Corporation>
[雅虎搜索]
<res://C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL/246, N/A>
[添加到QQ自定义面板]
<C:\PROGRAM FILES\TENCENT\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\PROGRAM FILES\TENCENT\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\PROGRAM FILES\TENCENT\QQ\SendMMS.htm, N/A>
[上传到QQ网络硬盘]
<C:\PROGRAM FILES\TENCENT\QQ\AddToNetDisk.htm, N/A>
[添加到雅虎订阅(&Y)]
<res://C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YRSS.DLL/YRSSMENUEXT, N/A>
enjoy30 - 2006-4-7 9:31:00
继续
==================================
正在运行的进程
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4294963297][C:\WINDOWS\SYSTEM\MPREXE.EXE] <Microsoft Corporation><4.10.1998>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[PID: 4294945421][C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4294852237][C:\WINDOWS\SYSTEM\MSTASK.EXE] <Microsoft Corporation><4.71.1972.1>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YPHTB.DLL] <Yahoo! China><1, 1, 2, 1034>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YDRAGSEARCH.DLL] < ><1, 2, 7, 1006>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL] <Yahoo!><2, 1, 5, 1045>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YALLIVEEX.DLL] < ><2, 0, 0, 1006>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YALIVE.DLL] <$><2, 0, 5, 1031>
[C:\PROGRAM FILES\3721\AUTOLIVE.DLL] <$><1, 1, 4, 1026>
[C:\WINDOWS\SYSTEM\RAVEXT.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSHOOK.DLL] <北京三七二一科技有限公司><1, 0, 2, 7>
[C:\WINDOWS\SYSTEM\DHCPCSVC.DLL] <N/A><N/A>
[C:\PROGRAM FILES\3721\ALREX.DLL] <$><1, 0, 1, 1001>
[C:\PROGRAM FILES\3721\HELPER.DLL] <$><1, 0, 9, 1324>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] <$><2, 0, 0, 1013>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4294949709][C:\WINDOWS\EXPLORER.EXE] <Microsoft Corporation><4.72.3110.1>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMINEX.DLL] <国风因特软件(北京)有限公司><1, 0, 2, 8>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSIO.DLL] <北京三七二一科技有限公司><1, 0, 2, 7>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMINIO.DLL] <北京三七二一科技有限公司><1, 0, 3, 6>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4294900565][C:\WINDOWS\RUNDLL32.EXE] <Microsoft Corporation><4.10.1998>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4292937077][C:\WINDOWS\SYSTEM\RPCSS.EXE] <Microsoft Corporation><4.71.2900>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] <$><2, 0, 0, 1013>
[C:\PROGRAM FILES\3721\HELPER.DLL] <$><1, 0, 9, 1324>
[C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL] <rising><18, 0, 0, 1>
[C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 4292979381][C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4292983097][C:\WINDOWS\TASKMON.EXE] <Microsoft Corporation><4.10.1998>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4292890509][C:\WINDOWS\SYSTEM\INTERNAT.EXE] <Microsoft Corporation><4.10.2222>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] <$><2, 0, 0, 1013>
[PID: 4292886797][C:\WINDOWS\SYSTEM\SYSTRAY.EXE] <Microsoft Corporation><4.10.2222>
[C:\PROGRAM FILES\3721\NOTIFIER.DLL] <$><1, 0, 0, 5>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\PROGRAM FILES\3721\AUTOLIVE.DLL] <$><1, 1, 4, 1026>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] <$><2, 0, 0, 1013>
[C:\PROGRAM FILES\3721\HELPER.DLL] <$><1, 0, 9, 1324>
[PID: 4292900181][C:\WINDOWS\RUNDLL32.EXE] <Microsoft Corporation><4.10.1998>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YNOTIFIER.DLL] <$><1, 0, 0, 5>
[C:\PROGRAM FILES\3721\HELPER.DLL] <$><1, 0, 9, 1324>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YALLIVEEX.DLL] < ><2, 0, 0, 1006>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YALIVE.DLL] <$><2, 0, 5, 1031>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] <$><2, 0, 0, 1013>
[PID: 4292873141][C:\PROGRAM FILES\YAHOO!\ASSISTANT\YLIVE.EXE] < ><2, 0, 0, 1002>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] <$><2, 0, 0, 1013>
[C:\PROGRAM FILES\ZARVASOFT\SMART UPDATE UTILITY\NLS\ASD0804.NLS] <AhnLab, Inc.><5, 0, 0, 5>
[PID: 4292877185][C:\PROGRAM FILES\ZARVASOFT\SMART UPDATE UTILITY\AHNSD.EXE] <AhnLab, Inc.><5, 3, 0, 23>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\SHELL\YASMENU.DLL] <Yahoo><1, 0, 1, 1006>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\SHELL\YIEANGEL.DLL] <Yahoo><1, 0, 1, 1001>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\SHELL\YMENUINFO.DLL] <Yahoo><1, 0, 0, 2>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\SHELL\YASSECBLK.DLL] <Yahoo><1, 0, 2, 1002>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] <$><2, 0, 0, 1013>
[PID: 4292881365][C:\PROGRAM FILES\YAHOO!\ASSISTANT\YASSISTSE.EXE] <Yahoo!><1, 0, 1, 1001>
[C:\WINDOWS\SYSTEM\DHCPCSVC.DLL] <N/A><N/A>
[C:\PROGRAM FILES\3721\HELPER.DLL] <$><1, 0, 9, 1324>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] <$><2, 0, 0, 1013>
[PID: 4292906345][C:\WINDOWS\LOADQM.EXE] <Microsoft Corporation><5.4.1103.3>
[C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH8A.OCX] <Macromedia, Inc.><8,0,24,0>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] <$><2, 0, 0, 1013>
[C:\PROGRAM FILES\3721\HELPER.DLL] <$><1, 0, 9, 1324>
[C:\WINDOWS\SYSTEM\DCIMAN32.DLL] <Intel(R) Corp., Microsoft Corp.><4.03.1998>
[PID: 4293090489][C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE] <Microsoft Corporation><7.0.0816>
[C:\WINDOWS\SYSTEM\DHCPCSVC.DLL] <N/A><N/A>
[PID: 4293048313][C:\WINDOWS\SYSTEM\WMIEXE.EXE] <Microsoft Corporation><5.00.1755.1>
enjoy30 - 2006-4-7 9:31:00
还有
[C:\PROGRAM FILES\RISING\RAV\EXTFILE.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\PROGRAM FILES\RISING\RAV\RSSTORE.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\PROGRAM FILES\RISING\RAV\EXTOLE.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\PROGRAM FILES\RISING\RAV\EXTMAIL.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\PROGRAM FILES\RISING\RAV\SCANSCT.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\PROGRAM FILES\RISING\RAV\SCANMAC.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\PROGRAM FILES\RISING\RAV\NVFILE.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\PROGRAM FILES\RISING\RAV\RSLOG.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[C:\PROGRAM FILES\RISING\RAV\POSTTRTX.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 1>
[C:\PROGRAM FILES\RISING\RAV\POSTTRT.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\PROGRAM FILES\RISING\RAV\SCANEX.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\PROGRAM FILES\RISING\RAV\UNEXE.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[C:\PROGRAM FILES\RISING\RAV\UNPACKER.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\PROGRAM FILES\RISING\RAV\SCANEXEC.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\PROGRAM FILES\RISING\RAV\ENGINE.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
[C:\PROGRAM FILES\RISING\RAV\MVENGINE.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\PROGRAM FILES\RISING\RAV\VIRUSLIB.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\PROGRAM FILES\RISING\RAV\LIBLOAD.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\PROGRAM FILES\RISING\RAV\RAVUIMSG.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
[C:\PROGRAM FILES\RISING\RAV\SCANNER.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
[C:\PROGRAM FILES\RISING\RAV\BWLIST.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] <$><2, 0, 0, 1013>
[C:\PROGRAM FILES\3721\HELPER.DLL] <$><1, 0, 9, 1324>
[C:\PROGRAM FILES\RISING\RAV\PNGDLL.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\PROGRAM FILES\RISING\RAV\RAVUI.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 53>
[C:\PROGRAM FILES\RISING\RAV\RSGUILIB.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
[C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL] <rising><18, 0, 0, 1>
[C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\PROGRAM FILES\RISING\RAV\PLUGIN\RSPGSCAN.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 4293155085][C:\PROGRAM FILES\RISING\RAV\RAV.EXE] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 50>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] <$><2, 0, 0, 1013>
[C:\PROGRAM FILES\3721\HELPER.DLL] <$><1, 0, 9, 1324>
[PID: 4293359453][C:\WINDOWS\SYSTEM\DDHELP.EXE] <Microsoft Corporation><4.06.03.0518>
[C:\WINDOWS\SYSTEM\RAVEXT.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSHOOK.DLL] <北京三七二一科技有限公司><1, 0, 2, 7>
[C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH8A.OCX] <Macromedia, Inc.><8,0,24,0>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSIO.DLL] <北京三七二一科技有限公司><1, 0, 2, 7>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMINIO.DLL] <北京三七二一科技有限公司><1, 0, 3, 6>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YANGLING.DLL] <Yahoo.><1, 0, 2, 1002>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YPHTB.DLL] <Yahoo! China><1, 1, 2, 1034>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YDRAGSEARCH.DLL] < ><1, 2, 7, 1006>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL] <Yahoo!><2, 1, 5, 1045>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WEB FOLDERS\MSONSEXT.DLL] <N/A><N/A>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSPLUS.DLL] <3721><1, 0, 0, 2>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YALLIVEEX.DLL] < ><2, 0, 0, 1006>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YALIVE.DLL] <$><2, 0, 5, 1031>
[C:\PROGRAM FILES\3721\AUTOLIVE.DLL] <$><1, 1, 4, 1026>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSHINT.DLL] <3721><1, 0, 0, 6>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YSCRBLOCK.DLL] <Yahoo><1, 0, 1, 1000>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] <$><2, 0, 0, 1013>
[C:\PROGRAM FILES\3721\ALREX.DLL] <$><1, 0, 1, 1001>
[C:\PROGRAM FILES\3721\SCRBLOCK.DLL] <3721><1, 0, 1, 1000>
[C:\PROGRAM FILES\3721\HELPER.DLL] <$><1, 0, 9, 1324>
[PID: 4293315309][C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE] <Microsoft Corporation><6.00.2800.1106>
[C:\WINDOWS\SYSTEM\NWIZ32.DLL] <N/A><N/A>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] <$><2, 0, 0, 1013>
[C:\PROGRAM FILES\3721\HELPER.DLL] <$><1, 0, 9, 1324>
[PID: 4293410417][C:\MY DOCUMENTS\ODC\SRENG.EXE] <Smallfrogs Studio><2.0.12.350>
==================================
文件关联
.TXT OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [C:\WINDOWS\winhlp32.exe %1]
.INI OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS OK. [C:\WINDOWS\WScript.exe "%1" %*]
.JS OK. [C:\WINDOWS\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
不言放弃 - 2006-4-7 9:40:00
【回复“enjoy30”的帖子】
开始--运行
输入regedit
确定
进入注册表
删除如下几项:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<nwiz32><c:\windows\system\nwiz32.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<Intnet><C:\WINDOWS\Intnet.exe>
=================
另外
C:\WINDOWS\SYSTEM\NWIZ32.DLL
插入到多个系统进程中
既然楼主使用的是WIN98
就可以进入纯DOS下
删除
C:\WINDOWS\SYSTEM\NWIZ32.DLL
c:\windows\system\nwiz32.exe
C:\WINDOWS\Intnet.exe
enjoy30 - 2006-4-7 9:42:00
今天早上一开机扫描这两个病毒还在,晕~~~~
Backdoor.Bifrose.fw清除成功2006-04-07 09:09手动扫描IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Trojan.Spy.Banker.fcz删除成功2006-04-07 09:12手动扫描C:\WINDOWS\SYSTEMnwiz32.dll
不言放弃 - 2006-4-7 9:55:00
| 引用: |
【enjoy30的贴子】今天早上一开机扫描这两个病毒还在,晕~~~~ Backdoor.Bifrose.fw清除成功2006-04-07 09:09手动扫描IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE Trojan.Spy.Banker.fcz删除成功2006-04-07 09:12手动扫描C:\WINDOWS\SYSTEMnwiz32.dll
........................... |
这是一个木马后门
也相当于一个ROOTKIT
一般来说不是专业杀软所能查杀的
需要手工操作来解决
enjoy30 - 2006-4-7 10:30:00
我用你的方法试了,但是在DOS下找不着C:\WINDOWS\Intnet.exe这个文件,重启后打开瑞星还是能找到病毒:
Backdoor.Bifrose.fw清除成功2006-04-07 09:59手动扫描IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
应该要怎么处理?
1
© 2000 - 2026 Rising Corp. Ltd.