瑞星卡卡安全论坛
bobo125 - 2007-6-10 15:23:00
Backdoor.Gpigeon.2006.ikn 这个病毒瑞星可以杀出来,但是重新启动后又出现了!
根本就不能治本!听说这个病毒很恶劣,急死人了,求求大家帮我解决下!!
另外我到网上也找了下这方面的相关资料但是没有这个版本病毒的情况,在安全模式下杀毒软件都找不出来!在注册表里找了找在IE的文件里面有好几个跟灰鸽子有关的文件删了后,重新启动再杀毒又出现了,完全没想法了!
newcenturymoon - 2007-6-10 15:24:00
下载 System Repair Engineer,
http://www.kztechs.com/sreng/download.html
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
火影忍者 - 2007-6-10 15:34:00
照楼上操作,请勿乱操作...
bobo125 - 2007-6-10 16:31:00
[CODE]
2007-03-07,13:04:33
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Professional Service Pack 4 (Build 2195) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
bobo125 - 2007-6-10 16:32:00
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Internat.exe><internat.exe> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Synchronization Manager><mobsync.exe /logon> [(Verified)Microsoft Windows 2000 Publisher]
<Cmaudio><; RunDll32 cmicnfg.cpl,CMICtrlWnd> [N/A]
<CmPCIaudio><; RunDll32 CMICNFG3.CPL,CMICtrlWnd> [N/A]
<C-Media Mixer><; Mixer.exe /startup> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<Super Rabbit Desktop Set><D:\超级兔子\DS.EXE /Load> [Super Rabbit Software]
<svpecld><C:\WINNT\system32\svpecld.exe> []
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<StormCodec_Helper><"D:\爆风\StormSet.exe" /S /opti> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows 2000 Publisher]
<Userinit><C:\WINNT\system32\userinit.exe,> [(Verified)Microsoft Windows 2000 Publisher]
==================================
启动文件夹
[Microsoft Office]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk --> C:\PROGRA~1\MICROS~2\Office\OSA9.EXE [Microsoft Corporation]><N>
==================================
bobo125 - 2007-6-10 16:32:00
服务
[BlackHole Remote Control Services / BRC_Services][Running/Auto Start]
<"C:\WINNT\system32\brc_Server.exe" /service><N/A>
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Security Iealcy / Iealcyqliver][Stopped/Auto Start]
<C:\WINNT\system32\iealcy.exe><N/A>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
<C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\system32\mspmsnsv.dll><Microsoft Corporation>
==================================
bobo125 - 2007-6-10 16:32:00
驱动程序
[BaseTDI / BaseTDI][Running/Auto Start]
<\??\C:\WINNT\system32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
[C-Media PCI Audio Driver (WDM) / cmpci][Running/Manual Start]
<system32\drivers\cmaudio.sys><C-Media Inc>
[C-Media WDM Audio Interface / cmuda][Stopped/Manual Start]
<system32\drivers\cmuda.sys><C-Media Inc>
[C-Media PCI Audio Interface / cmuda3][Stopped/Manual Start]
<system32\drivers\cmuda3.sys><C-Media Inc>
[dmboot / dmboot][Stopped/Disabled]
<System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
<\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload][Running/Boot Start]
<\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[ExpScaner / ExpScaner][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[WAN Miniport Driver For PPPoE Protocol / GNetPPPoE][Running/Manual Start]
<system32\DRIVERS\PPPoE.SYS><Guangdong Data Communications Network Co.Ltd.>
[HookCont / HookCont][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[kbkdrhk / kbkdrhk][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\kbkdrhk.sys><N/A>
[KWatch3 / KWatch3][Running/System Start]
<\??\C:\WINNT\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[Netgroup Packet Filter / NPF][Running/Manual Start]
<system32\drivers\npf.sys><Politecnico di Torino>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
<\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[SiS300 / SiS300][Running/Manual Start]
<system32\DRIVERS\sis300p.sys><Silicon Integrated Systems Corporation>
==================================
bobo125 - 2007-6-10 16:33:00
浏览器加载项
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <D:\迅雷\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\迅雷\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <D:\迅雷\Thunder.exe, Thunder Networking Technologies,LTD>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\QQ\QQ.EXE, TENCENT>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
[MMCPlayer Class]
{05C1004E-2596-48E5-8E26-39362985EEB9} <C:\WINNT\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINNT\system32\aliedit\AliEdit.dll, www.alipay.com>
[VCR.Scan]
{E4F500BF-C1A3-11D6-9697-0090961B771E} <C:\WINNT\Downloaded Program Files\VCRSCAN.OCX, New Technology Wave Inc.>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <D:\迅雷\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[FGCatchUrl]
{FB5DA724-162B-11D3-8B9B-AA70B4B0B524} <D:\网际快车\jccatch.dll, N/A>
[上传到QQ网络硬盘]
<D:\QQ\AddToNetDisk.htm, N/A>
[使用迅雷下载]
<D:\迅雷\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
<D:\迅雷\Program\getallurl.htm, N/A>
[添加到QQ自定义面板]
<D:\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\QQ\SendMMS.htm, N/A>
==================================
bobo125 - 2007-6-10 16:33:00
正在运行的进程
[PID: 144][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 168][\??\C:\WINNT\system32\csrss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 164][\??\C:\WINNT\system32\winlogon.exe] [Microsoft Corporation, 5.00.2195.6997]
[C:\WINNT\system32\IAC97U4.dll] [C-Media Corporation, 4.10.00.003Aa]
[C:\WINNT\system32\SMIDI32.DLL] [N/A, ]
[C:\WINNT\system32\wdmaud.drv] [Microsoft Corporation, 5.00.2195.6673]
[C:\WINNT\system32\msacm32.drv] [Microsoft Corporation, 5.00.2134.1]
[PID: 988][C:\WINNT\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690]
[C:\WINNT\AppPatch\AcLayers.DLL] [Microsoft Corporation, 5.00.2195.6717]
[C:\WINNT\system32\IAC97U4.dll] [C-Media Corporation, 4.10.00.003Aa]
[C:\WINNT\system32\SMIDI32.DLL] [N/A, ]
[C:\WINNT\system32\wdmaud.drv] [Microsoft Corporation, 5.00.2195.6673]
[C:\WINNT\system32\msacm32.drv] [Microsoft Corporation, 5.00.2134.1]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[D:\迅雷\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
[D:\迅雷\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 2]
[C:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation, 6.00.8168.0]
[D:\迅雷\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 4]
[C:\WINNT\system32\msadp32.acm] [Microsoft Corporation, 5.00.2134.1]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[D:\QQ\qdshm.dll] [, 1, 0, 101, 20]
[D:\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[C:\WINNT\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1152][D:\超级兔子\DS.EXE] [Super Rabbit Software, 1.50]
[C:\WINNT\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690]
[C:\WINNT\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1192][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
[C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1224][C:\WINNT\system32\internat.exe] [Microsoft Corporation, 5.00.2920.0000]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1308][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2800.1106]
[D:\迅雷\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.0.4]
[D:\迅雷\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
[D:\迅雷\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 2]
[C:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation, 6.00.8168.0]
[D:\迅雷\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINNT\system32\IAC97U4.dll] [C-Media Corporation, 4.10.00.003Aa]
[C:\WINNT\system32\SMIDI32.DLL] [N/A, ]
[C:\WINNT\system32\wdmaud.drv] [Microsoft Corporation, 5.00.2195.6673]
[C:\WINNT\system32\msacm32.drv] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\msadp32.acm] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 1312][C:\Program Files\ChinaNet\VnetClient.exe] [, 2006, 6, 30, 11]
[C:\Program Files\ChinaNet\Communicate.dll] [GDCN, 2006, 2, 15, 1]
[C:\Program Files\ChinaNet\DialModule.dll] [GDCN, 2006, 7, 25, 15]
[C:\Program Files\ChinaNet\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[C:\PROGRA~1\ChinaNet\CLIENT~1.DLL] [, 2004, 2, 28, 1]
[C:\PROGRA~1\ChinaNet\PLUGIN~1.OCX] [, 2006, 6, 2, 14]
[C:\PROGRA~1\ChinaNet\sign.dll] [0, 2004, 12, 1, 1]
[C:\PROGRA~1\ChinaNet\PostPlug.dll] [, 2004, 12, 16, 2]
[C:\PROGRA~1\ChinaNet\ADVERT~1.OCX] [, 2006, 2, 20, 1]
[C:\PROGRA~1\ChinaNet\VnetBs.ocx] [, 2004, 11, 18, 1]
[C:\PROGRA~1\ChinaNet\VnetSkin.ocx] [GDDC, 2005, 12, 21, 1]
[C:\PROGRA~1\ChinaNet\DialogStyle.dll] [, 1, 0, 0, 1]
[C:\PROGRA~1\ChinaNet\BDSearch.ocx] [gdcn, 2005, 12, 22, 1]
[C:\PROGRA~1\ChinaNet\PageFram.ocx] [Workgroup, 2006, 9, 21, 21]
[C:\PROGRA~1\ChinaNet\AccPage.ocx] [, 6, 12, 6, 11]
[C:\PROGRA~1\ChinaNet\AccountMgr.dll] [, 2006, 5, 26, 11]
[C:\PROGRA~1\ChinaNet\Timer.ocx] [, 2006, 12, 5, 17]
[C:\PROGRA~1\ChinaNet\PLUGIN~2.OCX] [, 2006, 4, 4, 1]
[C:\PROGRA~1\ChinaNet\NEWMES~1.DLL] [, 2006, 12, 5, 11]
[C:\PROGRA~1\ChinaNet\PassCtrl.dll] [GDCN, 2006, 3, 1, 16]
[C:\WINNT\system32\wpcap.dll] [Politecnico di Torino, 3, 0, 0, 18]
[C:\WINNT\system32\pthreadVC.dll] [N/A, ]
[C:\WINNT\system32\packet.dll] [Politecnico di Torino, 3, 0, 0, 18]
[C:\PROGRA~1\ChinaNet\PlugPush.dll] [, 2004, 12, 21, 1]
[C:\PROGRA~1\ChinaNet\ALLINT~1.DLL] [, 2006, 7, 19, 14]
[C:\PROGRA~1\ChinaNet\VNETLO~1.OCX] [, 2005, 10, 9, 1]
[C:\PROGRA~1\ChinaNet\StatNum.dll] [, 2006, 3, 1, 1]
[C:\PROGRA~1\ChinaNet\VNETON~1.OCX] [, 2005, 3, 2, 1]
[C:\PROGRA~1\ChinaNet\ALLFUN~1.DLL] [GDCN, 2006, 8, 23, 16]
[C:\PROGRA~1\ChinaNet\VnetOptLog.dll] [ , 2006, 5, 10, 14]
[C:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation, 6.00.8168.0]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\PROGRA~1\ChinaNet\DlgSkin.ocx] [, 2005, 11, 14, 1]
[C:\WINNT\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\WINNT\system32\IAC97U4.dll] [C-Media Corporation, 4.10.00.003Aa]
[C:\WINNT\system32\SMIDI32.DLL] [N/A, ]
[C:\WINNT\system32\wdmaud.drv] [Microsoft Corporation, 5.00.2195.6673]
[C:\WINNT\system32\msacm32.drv] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\msadp32.acm] [Microsoft Corporation, 5.00.2134.1]
[PID: 1532][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2800.1106]
[D:\迅雷\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.0.4]
[D:\迅雷\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
[D:\迅雷\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 2]
[C:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation, 6.00.8168.0]
[D:\迅雷\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINNT\system32\IAC97U4.dll] [C-Media Corporation, 4.10.00.003Aa]
[C:\WINNT\system32\SMIDI32.DLL] [N/A, ]
[C:\WINNT\system32\wdmaud.drv] [Microsoft Corporation, 5.00.2195.6673]
[C:\WINNT\system32\msacm32.drv] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\msadp32.acm] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[PID: 1728][D:\sreng2\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINNT\system32\IAC97U4.dll] [C-Media Corporation, 4.10.00.003Aa]
[C:\WINNT\system32\SMIDI32.DLL] [N/A, ]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP Error. [winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
bobo125 - 2007-6-10 16:33:00
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
火影忍者 - 2007-6-10 16:38:00
打开SREng-在"启动项目->服务->"Win32服务应用程序"选中"隐藏已认证的微软服务" 然后将下面名称的服务删除(选中有问题的服务后,点“删除服务”,点“设置”按钮即可。 注意弹出的窗口中要点 “NO 否”才是确认删除服务)(不能删除的就禁用:启动类型改为disabled,点中修改启动类型,点设置):
[Security Iealcy / Iealcyqliver][Stopped/Auto Start]
<C:\WINNT\system32\iealcy.exe><N/A>
打开SREng-在"启动项目->服务->驱动程序"选中"隐藏已认证的微软服务" 然后将下面名称的服务删除(选中有问题的服务后,点“删除服务”,点“设置”按钮即可。 注意弹出的窗口中要点 “NO 否”才是确认删除服务)(不能删除的就禁用:启动类型改为disabled,点中修改启动类型,点设置):
[kbkdrhk / kbkdrhk][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\kbkdrhk.sys><N/A>
用xdelbox(http://www.i170.com/attach/92EB2ED9-6D11-441D-8A28-2A9B08F0452E 下载)删除以下文件:
使用说明:删除时复制所有要删除文件的路径,选中抑制再生,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
C:\WINNT\system32\iealcy.exe
C:\WINNT\system32\drivers\kbkdrhk.sys
重装下QQ
杀软报的路径和文件名是什么?
bobo125 - 2007-6-10 16:44:00
5555555555我看不懂!!!
taylor05771 - 2007-6-10 16:50:00
| 引用: |
【火影忍者的贴子】打开SREng-在"启动项目->服务->"Win32服务应用程序"选中"隐藏已认证的微软服务" 然后将下面名称的服务删除(选中有问题的服务后,点“删除服务”,点“设置”按钮即可。 注意弹出的窗口中要点 “NO 否”才是确认删除服务)(不能删除的就禁用:启动类型改为disabled,点中修改启动类型,点设置): [Security Iealcy / Iealcyqliver][Stopped/Auto Start] <C:\WINNT\system32\iealcy.exe><N/A>
打开SREng-在"启动项目->服务->驱动程序"选中"隐藏已认证的微软服务" 然后将下面名称的服务删除(选中有问题的服务后,点“删除服务”,点“设置”按钮即可。 注意弹出的窗口中要点 “NO 否”才是确认删除服务)(不能删除的就禁用:启动类型改为disabled,点中修改启动类型,点设置): [kbkdrhk / kbkdrhk][Running/Boot Start] <\SystemRoot\\SystemRoot\System32\drivers\kbkdrhk.sys><N/A>
用xdelbox(http://www.i170.com/attach/92EB2ED9-6D11-441D-8A28-2A9B08F0452E 下载)删除以下文件: 使用说明:删除时复制所有要删除文件的路径,选中抑制再生,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。 C:\WINNT\system32\iealcy.exe C:\WINNT\system32\drivers\kbkdrhk.sys
重装下QQ
杀软报的路径和文件名是什么?
……………… |
漏了 这个呢
[BlackHole Remote Control Services / BRC_Services][Running/Auto Start]
<"C:\WINNT\system32\brc_Server.exe" /service><N/A>
从名称看 应该是 黑洞
taylor05771 - 2007-6-10 16:50:00
| 引用: |
【火影忍者的贴子】打开SREng-在"启动项目->服务->"Win32服务应用程序"选中"隐藏已认证的微软服务" 然后将下面名称的服务删除(选中有问题的服务后,点“删除服务”,点“设置”按钮即可。 注意弹出的窗口中要点 “NO 否”才是确认删除服务)(不能删除的就禁用:启动类型改为disabled,点中修改启动类型,点设置): [Security Iealcy / Iealcyqliver][Stopped/Auto Start] <C:\WINNT\system32\iealcy.exe><N/A>
打开SREng-在"启动项目->服务->驱动程序"选中"隐藏已认证的微软服务" 然后将下面名称的服务删除(选中有问题的服务后,点“删除服务”,点“设置”按钮即可。 注意弹出的窗口中要点 “NO 否”才是确认删除服务)(不能删除的就禁用:启动类型改为disabled,点中修改启动类型,点设置): [kbkdrhk / kbkdrhk][Running/Boot Start] <\SystemRoot\\SystemRoot\System32\drivers\kbkdrhk.sys><N/A>
用xdelbox(http://www.i170.com/attach/92EB2ED9-6D11-441D-8A28-2A9B08F0452E 下载)删除以下文件: 使用说明:删除时复制所有要删除文件的路径,选中抑制再生,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。 C:\WINNT\system32\iealcy.exe C:\WINNT\system32\drivers\kbkdrhk.sys
重装下QQ
杀软报的路径和文件名是什么?
……………… |
漏了 这个呢
[BlackHole Remote Control Services / BRC_Services][Running/Auto Start]
<"C:\WINNT\system32\brc_Server.exe" /service><N/A>
从名称看 应该是 黑洞
bobo125 - 2007-6-10 16:54:00
瑞星查出来这个病毒是这么个情况!
文件名:IEXPLORE.EXE
文件路径:IEXPLORE.EXE>>C:\Program\ Files\Internet Explorer\
IEXPLORE.EXE
病毒名:Backdoor.Gpigeon.2006.ikn
状态:清除成功(但是重新开起机器又有了)
火影忍者 - 2007-6-10 16:57:00
| 引用: |
【bobo125的贴子】5555555555我看不懂!!! ……………… |
哪句不懂?
SRE就是你扫日志的工具!
bobo125 - 2007-6-10 17:21:00
好了,我按您说的都做了!!用瑞星杀了下好象没有出现了!!先谢谢了
刚才那位朋友提醒了下[BlackHole Remote Control Services / BRC_Services][Running/Auto Start]
<"C:\WINNT\system32\brc_Server.exe" /service><N/A>
请问要删了吗?
bobo125 - 2007-6-10 17:31:00
重起好象没有了!真的非常感谢你啊~顺便问句上面那位朋友说的
[BlackHole Remote Control Services / BRC_Services][Running/Auto Start]
<"C:\WINNT\system32\brc_Server.exe" /service><N/A>也要删掉吗?
bobo125 - 2007-6-10 17:54:00
谢谢你们两位的帮助~~~万分感谢~
火影忍者 - 2007-6-10 18:05:00
还有问题,可下载金山灰鸽子专杀试试!
C灬覇ヤ盜﹏ - 2007-6-10 18:41:00
我看不懂
taylor05771 - 2007-6-10 19:05:00
| 引用: |
【bobo125的贴子】重起好象没有了!真的非常感谢你啊~顺便问句上面那位朋友说的 [BlackHole Remote Control Services / BRC_Services][Running/Auto Start] <"C:\WINNT\system32\brc_Server.exe" /service><N/A>也要删掉吗? ……………… |
当然要
bobo125 - 2007-6-10 19:13:00
这个病毒那些木马客星,木马杀客,金山专杀,安全卫士360之类的专杀工具都发现不了我全用了,只有瑞星杀毒和瑞星灰鸽子专杀才能查到,但是就是治标不治本,重新启动就又有了,按你的办法总算是没有再出现了,希望再也不要复发了,呵呵!偶像啊以后多跟你们学学~
bobo125 - 2007-6-10 19:41:00
taylor05771和火影两位麻烦再帮我看看我最新的扫描结果看看还有什么问题不,再次感谢你们~~~
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Internat.exe><internat.exe> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Synchronization Manager><mobsync.exe /logon> [(Verified)Microsoft Windows 2000 Publisher]
<Cmaudio><; RunDll32 cmicnfg.cpl,CMICtrlWnd> [N/A]
<CmPCIaudio><; RunDll32 CMICNFG3.CPL,CMICtrlWnd> [N/A]
<C-Media Mixer><; Mixer.exe /startup> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<Super Rabbit Desktop Set><D:\超级兔子\DS.EXE /Load> [Super Rabbit Software]
<svpecld><C:\WINNT\system32\svpecld.exe> []
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<StormCodec_Helper><"D:\爆风\StormSet.exe" /S /opti> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows 2000 Publisher]
<Userinit><C:\WINNT\system32\userinit.exe,> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<Network.ConnectionTray><C:\WINNT\system32\NETSHELL.dll> [(Verified)Microsoft Windows 2000 Publisher]
<WebCheck><%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Component Publisher]
<SysTray><stobject.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
<WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
<WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
<WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
<WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
<WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
<WinlogonNotify: wzcnotif><wzcdlg.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
<Windows Media Player><C:\WINNT\inf\unregmp2.exe /ShowWMP> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
<自定义浏览器><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6A5110B5-E14B-4268-A065-EF89FF33C325}]
<EnableRevocation><regsvr32.exe /s /n /i:"S 2 true 3 true 4 true 5 true 6 true 7 true" initpki.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
<Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
<Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Component Publisher]
==================================
bobo125 - 2007-6-10 19:42:00
taylor05771和火影两位麻烦再帮我看看我最新的扫描结果看看还有什么问题不,再次感谢你们~~~
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Internat.exe><internat.exe> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Synchronization Manager><mobsync.exe /logon> [(Verified)Microsoft Windows 2000 Publisher]
<Cmaudio><; RunDll32 cmicnfg.cpl,CMICtrlWnd> [N/A]
<CmPCIaudio><; RunDll32 CMICNFG3.CPL,CMICtrlWnd> [N/A]
<C-Media Mixer><; Mixer.exe /startup> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<Super Rabbit Desktop Set><D:\超级兔子\DS.EXE /Load> [Super Rabbit Software]
<svpecld><C:\WINNT\system32\svpecld.exe> []
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<StormCodec_Helper><"D:\爆风\StormSet.exe" /S /opti> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows 2000 Publisher]
<Userinit><C:\WINNT\system32\userinit.exe,> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<Network.ConnectionTray><C:\WINNT\system32\NETSHELL.dll> [(Verified)Microsoft Windows 2000 Publisher]
<WebCheck><%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Component Publisher]
<SysTray><stobject.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
<WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
<WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
<WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
<WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
<WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
<WinlogonNotify: wzcnotif><wzcdlg.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
<Windows Media Player><C:\WINNT\inf\unregmp2.exe /ShowWMP> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
<自定义浏览器><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6A5110B5-E14B-4268-A065-EF89FF33C325}]
<EnableRevocation><regsvr32.exe /s /n /i:"S 2 true 3 true 4 true 5 true 6 true 7 true" initpki.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
<Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
<Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Component Publisher]
==================================
bobo125 - 2007-6-10 19:43:00
浏览器加载项
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <D:\迅雷\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\迅雷\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <D:\迅雷\Thunder.exe, Thunder Networking Technologies,LTD>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\QQ\QQ.EXE, TENCENT>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
[MMCPlayer Class]
{05C1004E-2596-48E5-8E26-39362985EEB9} <C:\WINNT\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINNT\system32\aliedit\AliEdit.dll, www.alipay.com>
[VCR.Scan]
{E4F500BF-C1A3-11D6-9697-0090961B771E} <C:\WINNT\Downloaded Program Files\VCRSCAN.OCX, New Technology Wave Inc.>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <D:\迅雷\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[FGCatchUrl]
{FB5DA724-162B-11D3-8B9B-AA70B4B0B524} <D:\网际快车\jccatch.dll, N/A>
[上传到QQ网络硬盘]
<D:\QQ\AddToNetDisk.htm, N/A>
[使用迅雷下载]
<D:\迅雷\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
<D:\迅雷\Program\getallurl.htm, N/A>
[添加到QQ自定义面板]
<D:\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\QQ\SendMMS.htm, N/A>
==================================
bobo125 - 2007-6-10 19:45:00
正在运行的进程
[PID: 144][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2195.6601]
[C:\WINNT\system32\ntdll.dll] [Microsoft Corporation, 5.00.2195.7006]
[C:\WINNT\System32\sfcfiles.dll] [Microsoft Corporation, 5.00.2195.7038]
[PID: 168][\??\C:\WINNT\system32\csrss.exe] [Microsoft Corporation, 5.00.2195.6601]
[C:\WINNT\system32\ntdll.dll] [Microsoft Corporation, 5.00.2195.7006]
[C:\WINNT\system32\CSRSRV.dll] [Microsoft Corporation, 5.00.2195.6824]
[C:\WINNT\system32\basesrv.dll] [Microsoft Corporation, 5.00.2195.7011]
[C:\WINNT\system32\winsrv.dll] [Microsoft Corporation, 5.00.2195.7135]
[C:\WINNT\system32\USER32.dll] [Microsoft Corporation, 5.00.2195.7133]
[C:\WINNT\system32\KERNEL32.dll] [Microsoft Corporation, 5.00.2195.7099]
[C:\WINNT\system32\GDI32.dll] [Microsoft Corporation, 5.00.2195.7133]
[C:\WINNT\system32\MSVCRT.dll] [Microsoft Corporation, 6.10.9844.0]
[C:\WINNT\system32\LPK.DLL] [Microsoft Corporation, 5.00.2195.6692]
[C:\WINNT\system32\USP10.dll] [Microsoft Corporation, 1.0325.2195.6692]
[C:\WINNT\system32\ADVAPI32.dll] [Microsoft Corporation, 5.00.2195.7038]
[C:\WINNT\system32\RPCRT4.dll] [Microsoft Corporation, 5.00.2195.7085]
[PID: 996][C:\WINNT\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690]
[C:\WINNT\system32\ntdll.dll] [Microsoft Corporation, 5.00.2195.7006]
[C:\WINNT\system32\ADVAPI32.DLL] [Microsoft Corporation, 5.00.2195.7038]
[C:\WINNT\system32\KERNEL32.dll] [Microsoft Corporation, 5.00.2195.7099]
[C:\WINNT\system32\RPCRT4.dll] [Microsoft Corporation, 5.00.2195.7085]
[C:\WINNT\system32\GDI32.DLL] [Microsoft Corporation, 5.00.2195.7133]
[C:\WINNT\system32\USER32.dll] [Microsoft Corporation, 5.00.2195.7133]
[C:\WINNT\system32\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1907 (xpsp2.070219-1040)]
[C:\WINNT\system32\msvcrt.dll] [Microsoft Corporation, 6.10.9844.0]
[C:\WINNT\system32\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINNT\system32\IMM32.DLL] [Microsoft Corporation, 5.00.2195.6655]
[C:\WINNT\system32\LPK.DLL] [Microsoft Corporation, 5.00.2195.6692]
[C:\WINNT\system32\USP10.dll] [Microsoft Corporation, 1.0325.2195.6692]
[C:\WINNT\system32\shim.dll] [Microsoft Corporation, 5.00.2195.6717]
[C:\WINNT\AppPatch\AcLayers.DLL] [Microsoft Corporation, 5.00.2195.6717]
[C:\WINNT\system32\SHELL32.dll] [Microsoft Corporation, 5.00.3900.7105]
[C:\WINNT\system32\OLE32.DLL] [Microsoft Corporation, 5.00.2195.7059]
[C:\WINNT\system32\CLBCATQ.DLL] [Microsoft Corporation, 2000.2.3529.0]
[C:\WINNT\system32\OLEAUT32.dll] [Microsoft Corporation, 2.40.4522]
[C:\WINNT\system32\cscui.dll] [Microsoft Corporation, 5.00.2195.6705]
[C:\WINNT\system32\CSCDLL.DLL] [Microsoft Corporation, 5.00.2195.6713]
[C:\WINNT\system32\SHDOCVW.DLL] [Microsoft Corporation, 6.00.2800.1907 (xpsp2.070219-1040)]
[C:\WINNT\system32\browseui.dll] [Microsoft Corporation, 6.00.2800.1907 (xpsp2.070219-1040)]
[C:\WINNT\system32\LINKINFO.DLL] [Microsoft Corporation, 5.00.2195.7069]
[C:\WINNT\system32\ntshrui.dll] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\ATL.DLL] [Microsoft Corporation, 3.00.9435]
[C:\WINNT\system32\NETAPI32.DLL] [Microsoft Corporation, 5.00.2195.7108]
[C:\WINNT\system32\Secur32.dll] [Microsoft Corporation, 5.00.2195.6695]
[C:\WINNT\system32\NTDSAPI.dll] [Microsoft Corporation, 5.00.2195.6666]
[C:\WINNT\system32\DNSAPI.DLL] [Microsoft Corporation, 5.00.2195.7100]
[C:\WINNT\system32\WSOCK32.dll] [Microsoft Corporation, 5.00.2195.6603]
[C:\WINNT\system32\WS2_32.DLL] [Microsoft Corporation, 5.00.2195.6601]
[C:\WINNT\system32\WS2HELP.DLL] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\WLDAP32.DLL] [Microsoft Corporation, 5.00.2195.7017]
[C:\WINNT\system32\NETRAP.dll] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\SAMLIB.dll] [Microsoft Corporation, 5.00.2195.6944]
[C:\WINNT\system32\USERENV.DLL] [Microsoft Corporation, 5.00.2195.7002]
[C:\WINNT\system32\mydocs.dll] [Microsoft Corporation, 5.00.3502.6601]
[C:\WINNT\system32\MPR.DLL] [Microsoft Corporation, 5.00.2195.6824]
[C:\WINNT\System32\ntlanman.dll] [Microsoft Corporation, 5.00.2195.6824]
[C:\WINNT\System32\NETUI0.dll] [Microsoft Corporation, 5.00.2195.6601]
[C:\WINNT\System32\NETUI1.dll] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\NETSHELL.dll] [Microsoft Corporation, 5.00.2195.6604]
[C:\WINNT\system32\webcheck.dll] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINNT\system32\stobject.dll] [Microsoft Corporation, 5.00.2195.6601]
[C:\WINNT\system32\BATMETER.DLL] [Microsoft Corporation, 5.00.3502.6601]
[C:\WINNT\system32\SETUPAPI.DLL] [Microsoft Corporation, 5.00.2195.6622]
[C:\WINNT\system32\POWRPROF.DLL] [Microsoft Corporation, 5.00.3502.6601]
[C:\WINNT\system32\WINMM.DLL] [Microsoft Corporation, 5.00.2161.1]
[C:\WINNT\system32\IAC97U4.dll] [C-Media Corporation, 4.10.00.003Aa]
[C:\WINNT\system32\SMIDI32.DLL] [N/A, ]
[C:\WINNT\system32\MSI.DLL] [Microsoft Corporation, 3.1.4000.4033]
[C:\WINNT\system32\wdmaud.drv] [Microsoft Corporation, 5.00.2195.6673]
[C:\WINNT\system32\msacm32.drv] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\MSACM32.dll] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\es.dll] [Microsoft Corporation, 2000.2.3529.0]
[C:\WINNT\system32\TxfAux.Dll] [Microsoft Corporation, 2000.2.3529.0]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINNT\system32\INDICDLL.dll] [Microsoft Corporation, 5.00.2920.0000]
[C:\WINNT\system32\browselc.dll] [Microsoft Corporation, 6.00.2800.1106]
[D:\迅雷\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
[C:\WINNT\system32\WININET.dll] [Microsoft Corporation, 6.00.2800.1593]
[C:\WINNT\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2195.6926]
[C:\WINNT\system32\MSASN1.dll] [Microsoft Corporation, 5.00.2195.6905]
[D:\迅雷\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 2]
[C:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation,
bobo125 - 2007-6-10 19:46:00
6.00.8168.0]
[D:\迅雷\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 4]
[C:\WINNT\system32\urlmon.dll] [Microsoft Corporation, 6.00.2800.1593]
[C:\WINNT\system32\VERSION.dll] [Microsoft Corporation, 5.00.2195.6623]
[C:\WINNT\system32\LZ32.DLL] [Microsoft Corporation, 5.00.2195.6611]
[C:\WINNT\system32\mlang.dll] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINNT\system32\mshtml.dll] [Microsoft Corporation, 6.00.2800.1593]
[C:\WINNT\system32\c_is2022.dll] [Microsoft Corporation, 5.00.2195.6688]
[C:\WINNT\system32\shdoclc.dll] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINNT\system32\MSLS31.DLL] [Microsoft Corporation, 3.10.337.0]
[C:\WINNT\system32\webvw.dll] [Microsoft Corporation, 5.00.3900.7069]
[C:\WINNT\system32\imgutil.dll] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINNT\system32\mshtmled.dll] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINNT\system32\msadp32.acm] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\docprop2.dll] [Microsoft Corporation, 5.00.2178.1]
[C:\WINNT\system32\MSVFW32.DLL] [Microsoft Corporation, 5.00.2195.6612]
[C:\WINNT\system32\AVIFIL32.DLL] [Microsoft Corporation, 5.00.2195.6612]
[C:\WINNT\system32\faxshell.dll] [Microsoft Corporation, 5.00.2134.1]
[PID: 1132][D:\超级兔子\DS.EXE] [Super Rabbit Software, 1.50]
[C:\WINNT\system32\ntdll.dll] [Microsoft Corporation, 5.00.2195.7006]
[C:\WINNT\system32\KERNEL32.DLL] [Microsoft Corporation, 5.00.2195.7099]
[C:\WINNT\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690]
[C:\WINNT\system32\USER32.dll] [Microsoft Corporation, 5.00.2195.7133]
[C:\WINNT\system32\GDI32.dll] [Microsoft Corporation, 5.00.2195.7133]
[C:\WINNT\system32\ADVAPI32.dll] [Microsoft Corporation, 5.00.2195.7038]
[C:\WINNT\system32\RPCRT4.dll] [Microsoft Corporation, 5.00.2195.7085]
[C:\WINNT\system32\ole32.dll] [Microsoft Corporation, 5.00.2195.7059]
[C:\WINNT\system32\OLEAUT32.dll] [Microsoft Corporation, 2.40.4522]
[C:\WINNT\system32\IMM32.DLL] [Microsoft Corporation, 5.00.2195.6655]
[C:\WINNT\system32\LPK.DLL] [Microsoft Corporation, 5.00.2195.6692]
[C:\WINNT\system32\USP10.dll] [Microsoft Corporation, 1.0325.2195.6692]
[C:\WINNT\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINNT\system32\SHELL32.dll] [Microsoft Corporation, 5.00.3900.7105]
[C:\WINNT\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2800.1907 (xpsp2.070219-1040)]
[C:\WINNT\system32\msvcrt.dll] [Microsoft Corporation, 6.10.9844.0]
[C:\WINNT\system32\COMCTL32.dll] [Microsoft Corporation, 5.81]
[C:\WINNT\system32\INDICDLL.dll] [Microsoft Corporation, 5.00.2920.0000]
[PID: 1156][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
[C:\WINNT\system32\ntdll.dll] [Microsoft Corporation, 5.00.2195.7006]
[C:\WINNT\system32\MFC42.DLL] [Microsoft Corporation, 6.00.9586.0]
[C:\WINNT\system32\MSVCRT.dll] [Microsoft Corporation, 6.10.9844.0]
[C:\WINNT\system32\KERNEL32.dll] [Microsoft Corporation, 5.00.2195.7099]
[C:\WINNT\system32\GDI32.dll] [Microsoft Corporation, 5.00.2195.7133]
[C:\WINNT\system32\USER32.dll] [Microsoft Corporation, 5.00.2195.7133]
[C:\WINNT\system32\ADVAPI32.dll] [Microsoft Corporation, 5.00.2195.7038]
[C:\WINNT\system32\RPCRT4.dll] [Microsoft Corporation, 5.00.2195.7085]
[C:\WINNT\system32\SHELL32.dll] [Microsoft Corporation, 5.00.3900.7105]
[C:\WINNT\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2800.1907 (xpsp2.070219-1040)]
[C:\WINNT\system32\COMCTL32.dll] [Microsoft Corporation, 5.81]
[C:\WINNT\system32\IMM32.DLL] [Microsoft Corporation, 5.00.2195.6655]
[C:\WINNT\system32\LPK.DLL] [Microsoft Corporation, 5.00.2195.6692]
[C:\WINNT\system32\USP10.dll] [Microsoft Corporation,
bobo125 - 2007-6-10 19:47:00
1.0325.2195.6692]
[C:\WINNT\system32\MFC42LOC.DLL] [Microsoft Corporation, 6.00.8665.0]
[C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1196][C:\WINNT\system32\internat.exe] [Microsoft Corporation, 5.00.2920.0000]
[C:\WINNT\system32\ntdll.dll] [Microsoft Corporation, 5.00.2195.7006]
[C:\WINNT\system32\KERNEL32.DLL] [Microsoft Corporation, 5.00.2195.7099]
[C:\WINNT\system32\USER32.DLL] [Microsoft Corporation, 5.00.2195.7133]
[C:\WINNT\system32\GDI32.dll] [Microsoft Corporation, 5.00.2195.7133]
[C:\WINNT\system32\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINNT\system32\ADVAPI32.dll] [Microsoft Corporation, 5.00.2195.7038]
[C:\WINNT\system32\RPCRT4.dll] [Microsoft Corporation, 5.00.2195.7085]
[C:\WINNT\system32\IMM32.DLL] [Microsoft Corporation, 5.00.2195.6655]
[C:\WINNT\system32\SETUPAPI.DLL] [Microsoft Corporation, 5.00.2195.6622]
[C:\WINNT\system32\MSVCRT.DLL] [Microsoft Corporation, 6.10.9844.0]
[C:\WINNT\system32\USERENV.DLL] [Microsoft Corporation, 5.00.2195.7002]
[C:\WINNT\system32\SHELL32.DLL] [Microsoft Corporation, 5.00.3900.7105]
[C:\WINNT\system32\SHLWAPI.dll] [Microsoft Corporation, 6.00.2800.1907 (xpsp2.070219-1040)]
[C:\WINNT\system32\LPK.DLL] [Microsoft Corporation, 5.00.2195.6692]
[C:\WINNT\system32\USP10.dll] [Microsoft Corporation, 1.0325.2195.6692]
[C:\WINNT\system32\INDICDLL.dll] [Microsoft Corporation, 5.00.2920.0000]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 272][D:\sreng2\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINNT\system32\ntdll.dll] [Microsoft Corporation, 5.00.2195.7006]
[C:\WINNT\system32\kernel32.dll] [Microsoft Corporation, 5.00.2195.7099]
[C:\WINNT\system32\USER32.dll] [Microsoft Corporation, 5.00.2195.7133]
[C:\WINNT\system32\GDI32.dll] [Microsoft Corporation, 5.00.2195.7133]
[C:\WINNT\system32\comdlg32.dll] [Microsoft Corporation, 5.00.3700.6693]
[C:\WINNT\system32\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1907 (xpsp2.070219-1040)]
[C:\WINNT\system32\msvcrt.dll] [Microsoft Corporation, 6.10.9844.0]
[C:\WINNT\system32\ADVAPI32.dll] [Microsoft Corporation, 5.00.2195.7038]
[C:\WINNT\system32\RPCRT4.dll] [Microsoft Corporation, 5.00.2195.7085]
[C:\WINNT\system32\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINNT\system32\SHELL32.DLL] [Microsoft Corporation, 5.00.3900.7105]
[C:\WINNT\system32\WINSPOOL.DRV] [Microsoft Corporation, 5.00.2195.6659]
[C:\WINNT\system32\MPR.DLL] [Microsoft Corporation, 5.00.2195.6824]
[C:\WINNT\system32\oledlg.dll] [Microsoft Corporation, 1.0]
[C:\WINNT\system32\ole32.dll] [Microsoft Corporation, 5.00.2195.7059]
[C:\WINNT\system32\OLEAUT32.dll] [Microsoft Corporation, 2.40.4522]
[C:\WINNT\system32\VERSION.dll] [Microsoft Corporation, 5.00.2195.6623]
[C:\WINNT\system32\LZ32.DLL] [Microsoft Corporation, 5.00.2195.6611]
[C:\WINNT\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2195.6926]
[C:\WINNT\system32\MSASN1.dll] [Microsoft Corporation, 5.00.2195.6905]
[C:\WINNT\system32\WINMM.dll] [Microsoft Corporation, 5.00.2161.1]
[C:\WINNT\system32\WS2_32.dll] [Microsoft Corporation, 5.00.2195.6601]
[C:\WINNT\system32\WS2HELP.DLL] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\WININET.dll] [Microsoft Corporation, 6.00.2800.1593]
[C:\WINNT\system32\IMM32.DLL] [Microsoft Corporation, 5.00.2195.6655]
[C:\WINNT\system32\LPK.DLL] [Microsoft Corporation, 5.00.2195.6692]
[C:\WINNT\system32\USP10.dll] [Microsoft Corporation, 1.0325.2195.6692]
[C:\WINNT\system32\IAC97U4.dll] [C-Media Corporation, 4.10.00.003Aa]
[C:\WINNT\system32\SMIDI32.DLL] [N/A, ]
[C:\WINNT\system32\RICHED20.DLL] [Microsoft Corporation, 5.30.23.1227]
[C:\WINNT\system32\INDICDLL.dll] [Microsoft Corporation, 5.00.2920.0000]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINNT\system32\sfc.dll] [Microsoft Corporation, 5.00.2195.6673]
[C:\WINNT\system32\sfcfiles.dll] [Microsoft Corporation, 5.00.2195.7038]
[C:\WINNT\system32\Sensapi.dll] [Microsoft Corporation, 5.00.2195.6627]
[C:\WINNT\system32\wintrust.dll] [Microsoft Corporation, 5.131.2195.6824]
[C:\WINNT\system32\IMAGEHLP.dll] [Microsoft Corporation, 5.00.2195.6613]
[C:\WINNT\system32\rsaenh.dll] [Microsoft Corporation, 5.00.2195.6611]
[C:\WINNT\system32\USERENV.dll] [Microsoft Corporation, 5.00.2195.7002]
[C:\WINNT\system32\secur32.dll] [Microsoft Corporation, 5.00.2195.6695]
[C:\WINNT\system32\netapi32.dll] [Microsoft Corporation, 5.00.2195.7108]
[C:\WINNT\system32\NTDSAPI.dll] [Microsoft Corporation, 5.00.2195.6666]
[C:\WINNT\system32\DNSAPI.DLL] [Microsoft Corporation, 5.00.2195.7100]
[C:\WINNT\system32\WSOCK32.dll] [Microsoft Corporation, 5.00.2195.6603]
[C:\WINNT\system32\WLDAP32.DLL] [Microsoft Corporation, 5.00.2195.7017]
[C:\WINNT\system32\NETRAP.dll] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\SAMLIB.dll] [Microsoft Corporation, 5.00.2195.6944]
[C:\WINNT\system32\CLBCATQ.DLL] [Microsoft Corporation, 2000.2.3529.0]
[C:\WINNT\system32\LINKINFO.DLL] [Microsoft Corporation, 5.00.2195.7069]
[C:\WINNT\system32\ntshrui.dll] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\ATL.DLL] [Microsoft Corporation, 3.00.9435]
[C:\WINNT\system32\cscui.dll] [Microsoft Corporation, 5.00.2195.6705]
[C:\WINNT\system32\CSCDLL.DLL] [Microsoft Corporation, 5.00.2195.6713]
[PID: 1052][D:\sreng2\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINNT\system32\ntdll.dll] [Microsoft Corporation, 5.00.2195.7006]
[C:\WINNT\system32\kernel32.dll] [Microsoft Corporation, 5.00.2195.7099]
[C:\WINNT\system32\USER32.dll] [Microsoft Corporation, 5.00.2195.7133]
[C:\WINNT\system32\GDI32.dll] [Microsoft Corporation, 5.00.2195.7133]
[C:\WINNT\system32\comdlg32.dll] [Microsoft Corporation,
bobo125 - 2007-6-10 19:47:00
5.00.3700.6693]
[C:\WINNT\system32\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1907 (xpsp2.070219-1040)]
[C:\WINNT\system32\msvcrt.dll] [Microsoft Corporation, 6.10.9844.0]
[C:\WINNT\system32\ADVAPI32.dll] [Microsoft Corporation, 5.00.2195.7038]
[C:\WINNT\system32\RPCRT4.dll] [Microsoft Corporation, 5.00.2195.7085]
[C:\WINNT\system32\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINNT\system32\SHELL32.DLL] [Microsoft Corporation, 5.00.3900.7105]
[C:\WINNT\system32\WINSPOOL.DRV] [Microsoft Corporation, 5.00.2195.6659]
[C:\WINNT\system32\MPR.DLL] [Microsoft Corporation, 5.00.2195.6824]
[C:\WINNT\system32\oledlg.dll] [Microsoft Corporation, 1.0]
[C:\WINNT\system32\ole32.dll] [Microsoft Corporation, 5.00.2195.7059]
[C:\WINNT\system32\OLEAUT32.dll] [Microsoft Corporation, 2.40.4522]
[C:\WINNT\system32\VERSION.dll] [Microsoft Corporation, 5.00.2195.6623]
[C:\WINNT\system32\LZ32.DLL] [Microsoft Corporation, 5.00.2195.6611]
[C:\WINNT\system32\CRYPT32.dll] [Microsoft Corporation, 5.131.2195.6926]
[C:\WINNT\system32\MSASN1.dll] [Microsoft Corporation, 5.00.2195.6905]
[C:\WINNT\system32\WINMM.dll] [Microsoft Corporation, 5.00.2161.1]
[C:\WINNT\system32\WS2_32.dll] [Microsoft Corporation, 5.00.2195.6601]
[C:\WINNT\system32\WS2HELP.DLL] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\WININET.dll] [Microsoft Corporation, 6.00.2800.1593]
[C:\WINNT\system32\IMM32.DLL] [Microsoft Corporation, 5.00.2195.6655]
[C:\WINNT\system32\LPK.DLL] [Microsoft Corporation, 5.00.2195.6692]
[C:\WINNT\system32\USP10.dll] [Microsoft Corporation, 1.0325.2195.6692]
[C:\WINNT\system32\IAC97U4.dll] [C-Media Corporation, 4.10.00.003Aa]
[C:\WINNT\system32\SMIDI32.DLL] [N/A, ]
[C:\WINNT\system32\RICHED20.DLL] [Microsoft Corporation, 5.30.23.1227]
[C:\WINNT\system32\INDICDLL.dll] [Microsoft Corporation, 5.00.2920.0000]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINNT\system32\sfc.dll] [Microsoft Corporation, 5.00.2195.6673]
[C:\WINNT\system32\sfcfiles.dll] [Microsoft Corporation, 5.00.2195.7038]
[C:\WINNT\system32\Sensapi.dll] [Microsoft Corporation, 5.00.2195.6627]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP Error. [winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
© 2000 - 2026 Rising Corp. Ltd.