瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 【求助】这倒底是不是流氓或病毒软件呀?
亿万千百 - 2007-6-3 11:40:00
2007-5-29 18:06:40我在反病毒区发过贴,但没有人能回答,现在放到此区来看看,我把如贴内容放过来。
每次启动机器后都有一个rundll32.exe的进程,用瑞星卡卡查看进程如下:
[rundll32.exe]
PID = 0x288
CommandLine = rundll32.exe \JOnAS.dll,Service
rundll32.exe
0x1000000
C:\WINNT\system32\rundll32.exe
5.00.2134.1
Microsoft Corporation
Run a DLL as an App
2000-01-10 20:00:00

ntdll.dll
0x77f80000
C:\WINNT\system32\NTDLL.DLL
5.00.2195.7006
Microsoft Corporation
NT Layer DLL
2005-08-16 03:56:12

KERNEL32.dll
0x77e60000
C:\WINNT\system32\KERNEL32.DLL
5.00.2195.7099
Microsoft Corporation
Windows NT BASE API Client DLL
2006-06-21 14:51:46

GDI32.dll
0x77f40000
C:\WINNT\system32\GDI32.DLL
5.00.2195.7073
Microsoft Corporation
GDI Client DLL
2005-12-31 00:15:30

USER32.dll
0x77df0000
C:\WINNT\system32\USER32.DLL
5.00.2195.7032
Microsoft Corporation
Windows 2000 USER API Client DLL
2005-06-03 07:18:06

IMAGEHLP.dll
0x77900000
C:\WINNT\system32\IMAGEHLP.DLL
5.00.2195.6613
Microsoft Corporation
Windows NT Image Helper
2003-06-19 12:05:04

MSVCRT.DLL
0x78000000
C:\WINNT\system32\msvcrt.dll
6.10.9844.0
Microsoft Corporation
Microsoft (R) C Runtime Library
2003-06-19 12:05:04

IMM32.DLL
0x75e00000
C:\WINNT\system32\imm32.dll
5.00.2195.6655
Microsoft Corporation
Windows 2000 IMM32 API Client DLL
2003-06-19 12:05:04

ADVAPI32.DLL
0x796d0000
C:\WINNT\system32\ADVAPI32.DLL
5.00.2195.7038
Microsoft Corporation
Advanced Windows 32 Base API
2005-06-03 07:18:06

RPCRT4.dll
0x786f0000
C:\WINNT\system32\rpcrt4.dll
5.00.2195.7085
Microsoft Corporation
Remote Procedure Call Runtime
2006-04-13 13:16:40

LPK.DLL
0x6c330000
C:\WINNT\system32\lpk.dll
5.00.2195.6692
Microsoft Corporation
Language Pack
2003-06-19 12:05:04

USP10.dll
0x65d20000
C:\WINNT\system32\usp10.dll
1.0325.2195.6692
Microsoft Corporation
Uniscribe Unicode script processor
2003-06-19 12:05:04

这里最让人怀疑的是那个名为JOnAS.dll的文件,它在winnt\temp\目录下,可以用卡卡结束此进程,结束此进程后不会再运行,除非重启,有时瑞星会提示是病毒是不是删除或杀毒,但删除或杀毒一次后,下次重启后又可能会出现瑞星提示。以网上也没找到关于JOnAS.dll文件的有用信息,所以在此贴出来大家帮我看看,谢谢。
亿万千百 - 2007-6-3 11:41:00
每次开机后我都手动把此进程结束了,今天开机后此进程变以了,如下:
[rundll32.exe]
PID = 0x278
CommandLine = rundll32.exe "C:\WINNT\TEMP\Gentad\Octopus.dll",Service
rundll32.exe
0x1000000
C:\WINNT\system32\rundll32.exe
5.00.2134.1
Microsoft Corporation
Run a DLL as an App
2000-01-10 20:00:00

ntdll.dll
0x77f80000
C:\WINNT\system32\NTDLL.DLL
5.00.2195.7006
Microsoft Corporation
NT Layer DLL
2005-08-16 03:56:12

KERNEL32.dll
0x77e60000
C:\WINNT\system32\KERNEL32.DLL
5.00.2195.7099
Microsoft Corporation
Windows NT BASE API Client DLL
2006-06-21 14:51:46

GDI32.dll
0x77f40000
C:\WINNT\system32\GDI32.DLL
5.00.2195.7133
Microsoft Corporation
GDI Client DLL
2007-03-06 19:17:16

USER32.dll
0x77df0000
C:\WINNT\system32\USER32.DLL
5.00.2195.7133
Microsoft Corporation
Windows 2000 USER API Client DLL
2007-03-06 19:17:18

IMAGEHLP.dll
0x77900000
C:\WINNT\system32\IMAGEHLP.DLL
5.00.2195.6613
Microsoft Corporation
Windows NT Image Helper
2003-06-19 12:05:04

MSVCRT.DLL
0x78000000
C:\WINNT\system32\msvcrt.dll
6.10.9844.0
Microsoft Corporation
Microsoft (R) C Runtime Library
2003-06-19 12:05:04

IMM32.DLL
0x75e00000
C:\WINNT\system32\imm32.dll
5.00.2195.6655
Microsoft Corporation
Windows 2000 IMM32 API Client DLL
2003-06-19 12:05:04

ADVAPI32.DLL
0x796d0000
C:\WINNT\system32\ADVAPI32.DLL
5.00.2195.7038
Microsoft Corporation
Advanced Windows 32 Base API
2005-06-03 07:18:06

RPCRT4.dll
0x786f0000
C:\WINNT\system32\rpcrt4.dll
5.00.2195.7085
Microsoft Corporation
Remote Procedure Call Runtime
2006-04-13 13:16:40

LPK.DLL
0x6c330000
C:\WINNT\system32\lpk.dll
5.00.2195.6692
Microsoft Corporation
Language Pack
2003-06-19 12:05:04

USP10.dll
0x65d20000
C:\WINNT\system32\usp10.dll
1.0325.2195.6692
Microsoft Corporation
Uniscribe Unicode script processor
2003-06-19 12:05:04

Octopus.dll
0x10000000
C:\WINNT\Temp\Gentad\Octopus.dll



1970-01-01 08:00:00

ole32.dll
0x7cf00000
C:\WINNT\system32\OLE32.DLL
5.00.2195.7059
Microsoft Corporation
Microsoft OLE for Windows
2005-09-05 16:17:35

SHLWAPI.dll
0x70a70000
C:\WINNT\system32\SHLWAPI.DLL
6.00.2800.1907 (xpsp2.070219-1040)
Microsoft Corporation
Shell Light-weight Utility Library
2007-02-19 12:56:54

SHELL32.dll
0x78f90000
C:\WINNT\system32\SHELL32.DLL
5.00.3900.7105
Microsoft Corporation
Windows Shell Common Dll
2006-07-13 15:08:54

COMCTL32.dll
0x71710000
C:\WINNT\system32\comctl32.dll
5.81
Microsoft Corporation
Common Controls Library
2006-08-28 16:44:10

WS2_32.dll
0x74fb0000
C:\WINNT\system32\ws2_32.dll
5.00.2195.6601
Microsoft Corporation
Windows Socket 2.0 32-Bit DLL
2003-06-19 12:05:04

WS2HELP.DLL
0x74fa0000
C:\WINNT\system32\ws2help.dll
5.00.2134.1
Microsoft Corporation
Windows Socket 2.0 Helper for Windows NT
2000-01-10 20:00:00

WININET.dll
0x63000000
C:\WINNT\system32\WININET.DLL
6.00.2800.1593
Microsoft Corporation
Internet Extensions for Win32
2007-02-19 13:31:24

CRYPT32.dll
0x79c40000
C:\WINNT\system32\CRYPT32.DLL
5.131.2195.6926
Microsoft Corporation
Crypto API32
2005-06-03 07:18:08

MSASN1.dll
0x773f0000
C:\WINNT\system32\msasn1.dll
5.00.2195.6905
Microsoft Corporation
ASN.1 Runtime APIs
2005-06-03 07:18:08

OLEAUT32.dll
0x77990000
C:\WINNT\system32\OLEAUT32.DLL
2.40.4522
Microsoft Corporation

2003-06-19 12:05:04

VERSION.dll
0x777e0000
C:\WINNT\system32\version.dll
5.00.2195.6623
Microsoft Corporation
Version Checking and File Installation Libraries
2003-06-19 12:05:04

LZ32.DLL
0x75950000
C:\WINNT\system32\lz32.dll
5.00.2195.6611
Microsoft Corporation
LZ Expand/Compress API DLL
2003-06-19 12:05:04

SETUPAPI.dll
0x6d990000
C:\WINNT\system32\SETUPAPI.DLL
5.00.2195.6622
Microsoft Corporation
Windows Setup API
2003-06-19 12:05:04

USERENV.DLL
0x794d0000
C:\WINNT\system32\USERENV.DLL
5.00.2195.7002
Microsoft Corporation
Userenv
2005-06-03 07:18:06

NETAPI32.dll
0x7cea0000
C:\WINNT\system32\NETAPI32.DLL
5.00.2195.7108
Microsoft Corporation
Net Win32 API DLL
2006-08-17 21:14:10

Secur32.dll
0x797b0000
C:\WINNT\system32\secur32.dll
5.00.2195.6695
Microsoft Corporation
Security Support Provider Interface
2003-06-19 12:05:04

NTDSAPI.dll
0x77bd0000
C:\WINNT\system32\ntdsapi.dll
5.00.2195.6666
Microsoft Corporation
NT5DS
2003-06-19 12:05:04

DNSAPI.DLL
0x77960000
C:\WINNT\system32\dnsapi.dll
5.00.2195.7100
Microsoft Corporation
DNS Client API DLL
2006-07-06 19:45:02

WSOCK32.dll
0x74fd0000
C:\WINNT\system32\wsock32.dll
5.00.2195.6603
Microsoft Corporation
Windows Socket 32-Bit DLL
2003-06-19 12:05:04

WLDAP32.DLL
0x77930000
C:\WINNT\system32\WLDAP32.DLL
5.00.2195.7017
Microsoft Corporation
Win32 LDAP API DLL
2005-06-03 07:18:08

NETRAP.dll
0x75150000
C:\WINNT\system32\netrap.dll
5.00.2134.1
Microsoft Corporation
Net Remote Admin Protocol DLL
2000-01-10 20:00:00

SAMLIB.dll
0x750e0000
C:\WINNT\system32\samlib.dll
5.00.2195.6944
Microsoft Corporation
SAM Library DLL
2005-06-03 07:18:24

RASAPI32.DLL
0x774a0000
C:\WINNT\system32\RASAPI32.DLL
5.00.2195.6920
Microsoft Corporation
Remote Access API
2005-06-03 07:18:08

rasman.dll
0x77480000
C:\WINNT\system32\RASMAN.DLL
5.00.2195.6824
Microsoft Corporation
Remote Access Connection Manager
2005-06-03 07:18:08

TAPI32.dll
0x774f0000
C:\WINNT\system32\TAPI32.DLL
5.00.2195.6664
Microsoft Corporation
Microsoft? Windows(TM) Telephony API Client DLL
2003-06-19 12:05:04

RTUTILS.DLL
0x777f0000
C:\WINNT\system32\rtutils.dll
5.00.2168.1
Microsoft Corporation
Routing Utilities
2000-01-10 20:00:00

rsabase.dll
0x7ca00000
C:\WINNT\system32\RSABASE.DLL
5.00.2195.6619
Microsoft Corporation
Microsoft Base Cryptographic Provider (Export Version)
2003-06-19 12:05:04

rnr20.dll
0x77800000
C:\WINNT\system32\RNR20.DLL
5.00.2195.6603
Microsoft Corporation
Windows Socket2 NameSpace DLL
2003-06-19 12:05:04

iphlpapi.dll
0x77300000
C:\WINNT\system32\IPHLPAPI.DLL
5.00.2195.7097
Microsoft Corporation
IP Helper API
2006-05-19 17:17:56

ICMP.dll
0x774e0000
C:\WINNT\system32\icmp.dll
5.00.2134.1
Microsoft Corporation
ICMP DLL
2000-01-10 20:00:00

MPRAPI.dll
0x772e0000
C:\WINNT\system32\mprapi.dll
5.00.2181.1
Microsoft Corporation
Windows NT MP Router Administration DLL
2000-01-10 20:00:00

ACTIVEDS.DLL
0x77370000
C:\WINNT\system32\activeds.dll
5.00.2195.6601
Microsoft Corporation
ADs Router Layer DLL
2003-06-19 12:05:04

ADSLDPC.DLL
0x77340000
C:\WINNT\system32\adsldpc.dll
5.00.2195.6993
Microsoft Corporation
ADs LDAP Provider C DLL
2005-06-03 07:18:08

DHCPCSVC.DLL
0x77320000
C:\WINNT\system32\DHCPCSVC.DLL
5.00.2195.7085
Microsoft Corporation
DHCP Client Service
2006-05-19 17:17:56

winrnr.dll
0x777a0000
C:\WINNT\system32\winrnr.dll
5.00.2160.1
Microsoft Corporation
LDAP RnR Provider DLL
2000-01-10 20:00:00

rasadhlp.dll
0x777b0000
C:\WINNT\system32\rasadhlp.dll
5.00.2195.7098
Microsoft Corporation
Remote Access AutoDial Helper
2006-07-06 19:45:02

msafd.dll
0x74f50000
C:\WINNT\system32\msafd.dll
5.00.2195.6602
Microsoft Corporation
Microsoft Windows Sockets 2.0 Service Provider
2003-06-19 12:05:04

wshtcpip.dll
0x74f90000
C:\WINNT\system32\wshtcpip.dll
5.00.2195.6601
Microsoft Corporation
Windows Sockets Helper DLL
2003-06-19 12:05:04


这次JOnAS.dll变成Octopus.dll了,真的晕呀。
亿万千百 - 2007-6-5 9:56:00
没人回答了,我自己顶
夏日冰风 - 2007-6-5 13:28:00
下载 System Repair Engineer,
http://www.kztechs.com/sreng/download.html
解压缩sreng2.zip
运行SREng.exe
智能扫描--扫描--保存报告
日志贴上来 一次贴不完分次粘贴
小职员online - 2007-6-5 15:47:00
开始_运行 键入%temp%
找找有没有exe文件和ini文件
exe文件一律删掉,不能删就说明是恶意程序。
ini文件是配置文件,有的话,打开把内容看一看
这个目录下文件都可以删掉,不会影响正常系统的。
亿万千百 - 2007-6-6 14:28:00
那个文件不是在%temp%目录下,是在winnt\temp\目录下(我是2K的操作系统)
海生 - 2007-6-6 14:30:00
建议你先到安全模式下面去清空所有的临时文件夹,然后再用瑞星杀毒查一下
亿万千百 - 2007-6-7 9:38:00
谢谢海生,此方法已经试过了,只要把rundll32.exe进程结束后就可以删除这个文件,清空temp目录,临时目录,还有网页缓存目录,但重启后此文件又出来了。
夏日冰风 - 2007-6-7 10:14:00
可能这个文件是其他程序生成的
建议贴个日志
Crazy栋栋 - 2007-6-7 14:36:00
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
    <WMPNSCFG><C:\Program Files\Windows Media Player\WMPNSCFG.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <nwiz><nwiz.exe /install>  []
    <RTHDCPL><RTHDCPL.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <Alcmtr><ALCMTR.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <NvCplDaemon><; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [NVIDIA Corporation]
    <NvMediaCenter><; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>  [NVIDIA Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><"\Program Files\Logonui\Logonui.exe">  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    <WinlogonNotify: WgaLogon><WgaLogon.dll>  [(Verified)Microsoft Corporation]

==================================
启动文件夹
N/A

==================================
服务
[Windows afwt RunThem / afwt][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\varo\fkby.dll><N/A>
[CoolWare / CoolWare][Running/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\struts.dll><>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[ijlwru / ijlwru][Stopped/Auto Start]
  <C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\COMMON~1\vjlweu\vjlweu.dll,Service -s><Microsoft Corporation>
[NVIDIA Display Driver Service / NVSvc][Stopped/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>

==================================
驱动程序
[afweww4 / afweww42][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\afweww42.sys><N/A>
[AliIde / AliIde][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD Processor Driver / AmdK8][Running/System Start]
  <system32\DRIVERS\AmdK8.sys><Advanced Micro Devices>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[ewdmaudn / ewdmaudn][Stopped/Manual Start]
  <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ewdmaudn.sys><N/A>
[ExpScaner / ExpScaner][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[GMSIPCI / GMSIPCI][Stopped/Manual Start]
  <\??\G:\INSTALL\GMSIPCI.SYS><N/A>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
  <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HookCont / HookCont][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
  <system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
[m5288 / m5288][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\m5288.sys><ULi Electronics Inc.>
[MEMSCAN / MEMSCAN][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs][Running/Auto Start]
  <\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[MSICPL / MSICPL][Stopped/Manual Start]
  <\??\G:\install4\MSICPL.sys><N/A>
[Netgroup Packet Filter / NPF][Running/Manual Start]
  <system32\drivers\npf.sys><Politecnico di Torino>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\F:\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[NTACCESS / NTACCESS][Stopped/Manual Start]
  <\??\G:\NTACCESS.sys><N/A>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[oreans32 / oreans32][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\oreans32.sys><N/A>
[PANTECH GSM Handset USB Device driver (WDM) / pan_bus][Stopped/Manual Start]
  <system32\DRIVERS\pan_bus.sys><MCCI>
[PANTECH GSM Handset EMMI Drivers (WDM) / pan_emmi][Stopped/Manual Start]
  <system32\DRIVERS\pan_emmi.sys><MCCI>
[PANTECH GSM Handset Filter / pan_mdfl][Stopped/Manual Start]
  <system32\DRIVERS\pan_mdfl.sys><MCCI>
[PANTECH GSM Handset Drivers / pan_mdm][Stopped/Manual Start]
  <system32\DRIVERS\pan_mdm.sys><MCCI>
[peibiz8 / peibiz85][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\peibiz85.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  <\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[RsFwDrv / RsFwDrv][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Secdrv / Secdrv][Running/Auto Start]
  <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[SetupNTGLM7X / SetupNTGLM7X][Stopped/Manual Start]
  <\??\G:\NTGLM7X.sys><N/A>
[StarForce Protection Environment Driver (version 1.x.a) / sfdrv01a][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfdrv01a.sys><Protection Technology (StarForce)>
[StarForce Protection Helper Driver (version 2.x) / sfhlp02][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfhlp02.sys><Protection Technology (StarForce)>
[StarForce Protection Synchronization Driver (version 4.x) / sfsync04][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfsync04.sys><Protection Technology (StarForce)>
[StarForce Protection VFS Driver (version 2.x) / sfvfs02][Running/Boot Start]
  <\SystemRoot\System32\drivers\sfvfs02.sys><Protection Technology (StarForce)>
[sptd / sptd][Running/Boot Start]
  <\SystemRoot\System32\Drivers\sptd.sys><N/A>
[sxvssg7 / sxvssg78][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\sxvssg78.sys><N/A>
[ujxftz6 / ujxftz63][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\ujxftz63.sys><N/A>
[ULi M526X Ethernet NT Driver / ULI5261XP][Running/Manual Start]
  <system32\DRIVERS\ULILAN51.SYS><ULi Electronics Inc.>
Crazy栋栋 - 2007-6-7 14:37:00
==================================
浏览器加载项
[WebThunder Browser Helper]
  {00000AAA-A363-466E-BEF5-9BB68697AA7F} <F:\迅雷\WebThunderBHO_Now.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
  {3597E185-1674-49C8-88C7-580F0357E2BF} <, N/A>
[wxbSoftShutDown Class]
  {3597E186-1674-49C8-88C7-580F0357E2BF} <, N/A>
[启动迅雷5]
  {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <F:\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[启动Web迅雷]
  {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <F:\Tencent\QQ\QQ.EXE, TENCENT>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[BoBo P2P多媒体网络点播/广播/直播系统 V2]
  {A8C3B40D-5384-44AD-ACC4-504B4D8A85F5} <C:\WINDOWS\DOWNLO~1\BOBO_A~1.OCX, 广州易播信息科技有限公司>
[WebActivater Control]
  {C661F36D-DF85-4EF4-83C7-E107B83D04B1} <C:\WINDOWS\system32\3DShowVM.ocx, QQ>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[WebThunder Browser Helper]
  {00000AAA-A363-466E-BEF5-9BB68697AA7F} <F:\迅雷\WebThunderBHO_Now.dll, Thunder Networking Technologies,LTD>
[WebThunder Class]
  {03507A1A-E0C5-4404-AA26-205385C0892D} <, N/A>
[GigagetIEHelper Class]
  {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} <C:\WINDOWS\system32\gigagetbho_v10.dll, N/A>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\WINDOWS\system32\dllcache\dhtmled.ocx, Microsoft Corporation>
[Thunder Browser Helper]
  {3597E185-1674-49C8-88C7-580F0357E2BF} <, N/A>
[wxbSoftShutDown Class]
  {3597E186-1674-49C8-88C7-580F0357E2BF} <, N/A>
[BitComet Helper]
  {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <D:\BitComet\tools\BitCometBHO_1.1.3.28.dll, BitComet>
[超级兔子上网精灵]
  {43869BB3-22FD-4F15-9B46-238106BA2F4E} <, N/A>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[超级兔子上网精灵]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <, N/A>
[MediaComm Class]
  {7670648D-461B-42AF-BDFE-46D26AF5EFF2} <F:\迅雷\InMedia\MediaAddin13.dll, Thunder Networking Technologies,LTD>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[RMGetLicense Class]
  {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[]
  {B69003B3-C55E-4B48-836C-BC5946FC3B28} <C:\Program Files\Messenger\msgsc.dll, Microsoft Corporation>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
  {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[&使用迅雷下载]
  <F:\Thunder\Program\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <F:\Thunder\Program\getallurl.htm, N/A>
[上传到QQ网络硬盘]
  <F:\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用Web迅雷下载]
  <F:\迅雷\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
  <F:\迅雷\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <F:\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <F:\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <F:\Tencent\QQ\SendMMS.htm, N/A>
Crazy栋栋 - 2007-6-7 14:38:00
==================================
正在运行的进程
[PID: 632][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 696][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 736][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WgaLogon.dll]  [Microsoft Corporation, 1.7.0018.5]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 780][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\AppPatch\AcAdProc.dll]  [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[PID: 792][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 948][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3732][C:\WINDOWS\RTHDCPL.exe]  [Realtek Semiconductor Corp., 2.0.5.4]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 3776][C:\WINDOWS\explorer.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\WINDOW~2\wmpband.dll]  [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\WPDShServiceObj.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\PortableDeviceTypes.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.9128]
    [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.9128]
    [C:\WINDOWS\system32\nvshell.dll]  [, ]
    [F:\迅雷\WebThunderBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 2, 10]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [F:\Tencent\QQ\qdshm.dll]  [, 1, 0, 101, 20]
    [F:\Tencent\QQ\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\WINDOWS\system32\wpdshext.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\TudouUpload.dll]  [www.Tudou.com, 1.1.0.0]
[PID: 3064][c:\program files\rising\rfw\RfwMain.exe]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 70]
    [c:\program files\rising\rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
    [c:\program files\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [c:\program files\rising\rfw\RfwCtrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [c:\program files\rising\rfw\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [c:\program files\rising\rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 3992][F:\千千\TTPlayer.exe]  [Alen Soft, 4, 6, 9, 0]
    [F:\千千\ttpcomm.dll]  [N/A, ]
    [F:\千千\ttpres.dll]  [Alen Soft, 4, 6, 9, 0]
    [F:\千千\msdmo.dll]  [Microsoft Corporation, 6.03.01.0400]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [F:\千千\AddIn\ttp_asf.dll]  [N/A, ]
    [F:\千千\AddIn\ttp_lrcsh.dll]  [N/A, ]
[PID: 1596][F:\MagicSet\SRTask.exe]  [, 2.8.0.0]
[PID: 1936][C:\Program Files\ChinaNet\VnetClient.exe]  [, 2006, 3, 17, 1]
    [C:\Program Files\ChinaNet\Communicate.dll]  [GDCN, 2006, 2, 15, 1]
    [C:\Program Files\ChinaNet\DialModule.dll]  [GDCN, 2006, 3, 8, 18]
    [C:\Program Files\ChinaNet\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\PROGRA~1\ChinaNet\CLIENT~1.DLL]  [, 2004, 2, 28, 1]
    [C:\PROGRA~1\ChinaNet\PLUGIN~1.OCX]  [, 2006, 2, 8, 1]
    [C:\PROGRA~1\ChinaNet\sign.dll]  [0, 2004, 12, 1, 1]
    [C:\PROGRA~1\ChinaNet\WEBPLU~1.DLL]  [, 2005, 8, 18, 1]
    [C:\PROGRA~1\ChinaNet\ADVERT~1.OCX]  [, 2006, 2, 20, 1]
    [C:\PROGRA~1\ChinaNet\VnetBs.ocx]  [, 2004, 11, 18, 1]
    [C:\PROGRA~1\ChinaNet\ACCOUN~2.DLL]  [, 2006, 5, 29, 14]
    [C:\PROGRA~1\ChinaNet\AccountMgr.dll]  [, 2006, 5, 26, 9]
    [C:\PROGRA~1\ChinaNet\VnetSkin.ocx]  [GDDC, 2005, 11, 14, 1]
    [C:\PROGRA~1\ChinaNet\DialogStyle.dll]  [, 1, 0, 0, 1]
    [C:\PROGRA~1\ChinaNet\Timer.ocx]  [, 2006, 3, 24, 9]
    [C:\PROGRA~1\ChinaNet\PLUGIN~2.OCX]  [, 2006, 4, 4, 1]
    [C:\PROGRA~1\ChinaNet\NEWMES~1.DLL]  [, 2006, 5, 24, 16]
    [C:\PROGRA~1\ChinaNet\PassCtrl.dll]  [GDCN, 2006, 3, 1, 16]
    [C:\WINDOWS\system32\wpcap.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\WINDOWS\system32\pthreadVC.dll]  [N/A, ]
    [C:\WINDOWS\system32\packet.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\PROGRA~1\ChinaNet\PlugPush.dll]  [, 2004, 12, 21, 1]
    [C:\PROGRA~1\ChinaNet\ALLINT~1.DLL]  [, 2006, 5, 29, 11]
    [C:\PROGRA~1\ChinaNet\VNETLO~1.OCX]  [, 2005, 10, 9, 1]
    [C:\PROGRA~1\ChinaNet\StatNum.dll]  [, 2006, 3, 1, 1]
    [C:\PROGRA~1\ChinaNet\VNETON~1.OCX]  [, 2005, 3, 2, 1]
    [C:\PROGRA~1\ChinaNet\ALLFUN~1.DLL]  [GDCN, 2006, 5, 24, 14]
    [C:\PROGRA~1\ChinaNet\VnetOptLog.dll]  [, 2006, 3, 14, 10]
    [C:\PROGRA~1\ChinaNet\MAGICD~1.OCX]  [, 1, 0, 0, 1]
    [C:\Program Files\Common Files\Microsoft Shared\INK\PENCHS.DLL]  [Microsoft Corporation, 1.0.1038.0]
    [C:\PROGRA~1\ChinaNet\DlgSkin.ocx]  [, 2005, 11, 14, 1]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1044][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3580][F:\Tencent\TT\TTraveler.exe]  [腾讯公司, 3, 3, 200, 290]
    [C:\WINDOWS\system32\KakaTool.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 3, 0]
    [F:\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll]  [腾讯公司, 1, 1, 0, 5]
    [F:\Tencent\TT\Plugins\TWeather\TWeather.dll]  [, 1, 0, 0, 3]
    [F:\Tencent\TT\TTNetFavor.dll]  [N/A, ]
    [C:\Program Files\Common Files\Microsoft Shared\INK\PENCHS.DLL]  [Microsoft Corporation, 1.0.1038.0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
    [C:\WINDOWS\system32\IMSC40A.IME]  [Microsoft Corporation, 6.0.0.2527]
    [C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL]  [Microsoft Corporation, 9.0.5510.0]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [E:\Storm Codec\Codecs\VSFilter.dll]  [Gabest, 1, 0, 1, 3]
    [E:\Storm Codec\Codecs\PmpSplt.ax]  [cooleyes, 1, 0, 0, 8]
    [C:\Program Files\StormII\Codec\AviSplitter.ax]  [Gabest, 1, 0, 0, 7]
    [C:\Program Files\StormII\Codec\RadGtSplitter.ax]  [Gabest, 1, 0, 0, 0]
    [C:\Program Files\StormII\Codec\MP4Splitter.ax]  [Gabest, 1, 0, 0, 2]
    [C:\Program Files\StormII\codec\FLVSplitter.ax]  [Gabest, 1, 0, 0, 1]
    [C:\Program Files\StormII\codec\ac3filter.ax]  [, 1.01a]
    [C:\WINDOWS\system32\ffdshow.ax]  [, 1.0.2.2028]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\system32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
[PID: 1788][F:\迅雷\WebThunder.exe]  [深圳市迅雷网络技术有限公司, 1, 8, 3, 127]
    [F:\迅雷\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 13, 4, 58]
    [F:\迅雷\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [F:\迅雷\TaskManager.dll]  [Thunder Networking Technologies,LTD, 1, 1, 1, 24]
    [F:\迅雷\download_interface.dll]  [Thunder Networking Technologies,LTD, 2, 15, 2, 98]
    [F:\迅雷\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
    [F:\迅雷\asyn_dns.dll]  [Thunder Networking Technologies,LTD, 2, 15, 2, 98]
    [F:\迅雷\Inmedia\iEmbedShell.dll]  [ , 1, 0, 0, 19]
    [F:\迅雷\InMedia\iEmbed10.dll]  [ , 3, 3, 1, 82]
    [F:\迅雷\CacheServer.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Common Files\Microsoft Shared\INK\PENCHS.DLL]  [Microsoft Corporation, 1.0.1038.0]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[PID: 1716][D:\同花顺2007\LiveUpdate.exe]  [上海核新软件技术有限公司, 2006, 11, 2, 0]
[PID: 2612][C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2632][C:\WINDOWS\system32\taskmgr.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3272][C:\Program Files\Rising\Rav\RsAgent.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
[PID: 2448][C:\WINDOWS\msagent\AgentSvr.exe]  [Microsoft Corporation, 2.00.0.3424]
[PID: 2460][C:\Documents and Settings\Administrator\桌面\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
Crazy栋栋 - 2007-6-7 14:39:00
==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost
127.0.0.1 mmsk.cn
127.0.0.1 bbs.mmsk.cn
127.0.0.1 www.mmsk.cn
127.0.0.1 soudong.com
127.0.0.1 www.soudong.com

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================
Crazy栋栋 - 2007-6-7 14:48:00
呼呼 全贴上来了~~看的我都快晕吐了~~只能求各位大侠帮帮忙了
一开始是JOnAS.dll 后来又变成Octopus.dll 都是rundll32.exe使用的模块 每次都查到有毒 还总是重启后删除 我手动删除 先结束进程 再删 可每次删完了还有 到底是哪个程序创建的啊? 网上查  rundll32.exe本身貌似没问题 不过任务管理器当中每次都有2 3个 rundll32.exe在运行 这进程这么牛啊?~~要开那么多~~ 彻底无语!
夏日冰风 - 2007-6-7 15:34:00
在安全模式下显示隐藏文件(我的电脑-文件夹选项-查看-隐藏受保护的操作系统文件 去掉前面的钩)删除
 
C:\PROGRA~1\varo\fkby.dll
C:\WINDOWS\system32\struts.dll
C:\PROGRA~1\COMMON~1\vjlweu\vjlweu.dll
<\SystemRoot\System32\DRIVERS\afweww42.sys
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ewdmaudn.sys>
<\??\C:\WINDOWS\system32\drivers\oreans32.sys>
<\SystemRoot\System32\DRIVERS\peibiz85.sys>
<\SystemRoot\System32\DRIVERS\sxvssg78.sys>
<\SystemRoot\System32\DRIVERS\ujxftz63.sys>
F:\Tencent\QQ\qdshm.dll
F:\Tencent\QQ\MFC42.DLL



打开SREng-在"启动项目->服务->"驱动程序"选中"隐藏已认证的微软项目" 然后将下面名称的驱动删除

[afweww4 / afweww42][Stopped/Boot Start]
[ewdmaudn / ewdmaudn][Stopped/Manual Start]
[oreans32 / oreans32][Running/System Start]
[peibiz8 / peibiz85][Stopped/Boot Start]
[sxvssg7 / sxvssg78][Stopped/Boot Start]
[ujxftz6 / ujxftz63][Stopped/Boot Start]



打开SREng-在"启动项目->服务->"Win32服务应用程序"选中"隐藏已认证的微软服务" 然后将下面名称的服务删除

[Windows afwt RunThem / afwt][Stopped/Auto Start]
[CoolWare / CoolWare][Running/Auto Start]
[ijlwru / ijlwru][Stopped/Auto Start]


修复HOSTS 文件
夏日冰风 - 2007-6-7 15:38:00
[C:\WINDOWS\system32\TudouUpload.dll] [www.Tudou.com, 1.1.0.0]
这个不太确定 如果你认得不是恶意程序的 不要删除
KILLall病毒 - 2007-6-8 22:23:00
我也碰到一样的问题,JOnAS.dll变成了Octopus.dll ,进程里面有两个rundll32.exe 瑞星查出来叫Trojan.Mnless.ktc 就是杀不掉,急啊
亿万千百 - 2007-6-25 9:38:00
我自己还没贴上来,“Crazy栋栋”倒贴上来了,有意思。此问题我已解决。
亿万千百 - 2007-6-25 10:01:00
我用“超级巡警”在非系统分区找到一个被病毒感染的可执行文件,删掉后此问题就解决了。在这里我要感谢lorise给予我的帮助,再次谢谢他。

在这里我说明一下,因为我之前只用了“超级巡警”扫描了非系统分区,而没有用其它杀毒软件扫描,所以我上面是要强调在非系统分区找到了被病毒感染的可执行文件。
Crazy栋栋 - 2007-6-25 13:19:00
o_O 好的 我去试试!!嘿嘿
1
查看完整版本: 【求助】这倒底是不是流氓或病毒软件呀?