瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 电脑中了不知什么毒,情况很糟糕。麻烦各位达人帮忙看看。
夏天微微 - 2007-7-19 19:51:00
前晚正在平时常去的一小说论坛浏览帖子。突然弹出数个窗口,接着显示**错误什么的。然后死机,重启就显示无法加载什么模块。瑞星杀软跟防火墙全挂了。防火墙蹦出无数图标在任务栏排成一条龙大概有十多个。用鼠标去点就会立刻隐藏。杀软无法进行设置以及升级,一升级就蹦出个对话窗问是否停止升级。IE主页被篡改。用360跟卡卡修复后又固态萌发无法彻底修复。不知道该如何是好了。电脑驱动坏了读不了盘,又没法重装系统。哪位大人救救我的电脑吧。
报告用附件发上来吧。

附件: 8242692007719194050.txt
scco - 2007-7-19 20:09:00
木马?
Enao2005 - 2007-7-19 20:39:00
注册表项目
编辑<shell>为<Explorer.exe>  []

删除服务
[Distributed File System / Dfs][Running/Auto Start]
  <C:\WINDOWS\system32\Dfssvr.exe><Microsoft Corporation>
[Logical System Managet / llsservet][Stopped/Auto Start]
  <C:\Program Files\Common Files\svchost.cnc><N/A>
[Fax 2Client / ms_2fax][Running/Auto Start]
  <C:\WINDOWS\system32\234b1.exe><N/A>
[Server Inetrnet / Server Inetrnet][Running/Auto Start]
  <C:\WINDOWS\serve><N/A>
[Intranet Messenger / WalALET][Stopped/Auto Start]
  <C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE C:\WINDOWS\SYSTEM32\WBEM\ZGMAV.DLL,Export 1087><N/A>
[Windows System Hardware BackUp / WindowsSystemHDBackUp][Stopped/Auto Start]
  <C:\WINDOWS\system32\        ><N/A>

删除驱动服务
[oreans32 / oreans32][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\oreans32.sys><N/A>

重启后删除
C:\WINDOWS\serv
C:\WINDOWS\SYSTEM32\WBEM\ZGMAV.DLL
C:\WINDOWS\system32\serverhelp.dll
C:\WINDOWS\system32\winlib .dll]  [N/A, ]
C:\WINDOWS\system32\msplrct.dll]  [
C:\WINDOWS\system32\234b1.exe
C:\WINDOWS\cacls.exe
webhelp.exe
C:\WINDOWS\system32\Dfssvr.exe
C:\Program Files\Common Files\svchost.cnc
C:\WINDOWS\system32\234b1.exe
C:\WINDOWS\system32\drivers\oreans32.sys

无法删除的文件可以尝试用unclocker,DELBOX(enao.ys168.com下载)
夏天微微 - 2007-7-19 20:39:00
不止是木马。
看了一些帖子自己觉得可能是帕虫。按那些达人教的方法做了,可什么都查不出来。还是原样。求哪位教教我怎么做吧。
夏天微微 - 2007-7-19 20:42:00
谢谢Enao2005。真的很感谢你。谢谢谢谢。在这给您鞠躬了。
我先去试一下。
等下告诉您结果,要不成估计还得劳您再帮忙看看。
夏天微微 - 2007-7-19 20:44:00
达人,是用什么编辑啊?
mopery - 2007-7-19 21:23:00
引用:
【夏天微微的贴子】达人,是用什么编辑啊?
………………


sreng
夏天微微 - 2007-7-19 21:50:00
C:\WINDOWS\serv
C:\WINDOWS\SYSTEM32\WBEM\ZGMAV.DLL
C:\WINDOWS\system32\winlib .dll] [N/A, ]
C:\WINDOWS\system32\msplrct.dll] [
C:\WINDOWS\webhelp.exe
这几个找不到。
杀软已经可以升级了。谢谢你喔。大虾。
只是我的IE主页还是那个讨厌的网站怎么也改不掉。
我该怎么办啊。
火影忍者 - 2007-7-19 21:51:00
删除驱动服务
[oreans32 / oreans32][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\oreans32.sys><N/A>这个没有问题.
夏天微微 - 2007-7-19 21:53:00
在线静候回答拉。
火影忍者 - 2007-7-19 21:54:00
补充
驱动程序
[a30qvmu / a30qvmu][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\a30qvmu.sys><N/A>
[mxdispdr / mxdispdr][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\mxdispdr.sys><N/A>
[qnpx / qnpxx][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\qnpxx.sys><N/A>
[w8nr6pay1 / w8nr6pay1a][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\w8nr6pay1a.sys><N/A>
夏天微微 - 2007-7-19 22:06:00
引用:
【火影忍者的贴子】删除驱动服务
[oreans32 / oreans32][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\oreans32.sys><N/A>这个没有问题.
………………

已经删掉了,怎么办喔。
夏天微微 - 2007-7-19 22:07:00
开机进入的时候啪啪两声响,无法加载什么项目,找不到指定文件。
这怎么办喔?
夏天微微 - 2007-7-19 22:34:00
火影忍者大哥帮帮忙教下我怎么做啊
火影忍者 - 2007-7-19 22:41:00
引用:
【夏天微微的贴子】开机进入的时候啪啪两声响,无法加载什么项目,找不到指定文件。
这怎么办喔?
………………

什么开机两声响啊...是不是硬件有问题啊..

什么文件无法加载?具体点!!
夏天微微 - 2007-7-19 23:11:00
引用:
【火影忍者的贴子】
什么开机两声响啊...是不是硬件有问题啊..

什么文件无法加载?具体点!!
………………

就是文件无法加载的时候会响一声喔。
具体的一个etb7118.dll
一个pponqw4.dll
第一个不晓得错没,我没仔细看噢。第二个没错拉。
还有就是我中毒以后主页就被改了。到现在还没好。
怎么处理呀?
我用过卡卡了。没用。修复又变回来了
ADL - 2007-7-19 23:23:00
引用:
【夏天微微的贴子】
就是文件无法加载的时候会响一声喔。
具体的一个etb7118.dll
一个pponqw4.dll
第一个不晓得错没,我没仔细看噢。第二个没错拉。
还有就是我中毒以后主页就被改了。到现在还没好。
怎么处理呀?
我用过卡卡了。没用。修复又变回来了
………………

下载autoruns http://anding.ys168.com/ 删除与之相关的残留项!
    autoruns使用方法:http://forum.ikaka.com/topic.asp?board=3&artid=8331592




附件: 293892007719231317.gif
IBM①5 - 2007-7-19 23:58:00
etb7118.dll
pponqw4.dll
在电脑上搜索这两个动态链接文件,如果搜得到,就把它们删除,就可以了!
夏天微微 - 2007-7-20 4:39:00
火影大人,你说的这两个驱动:
[w8nr6pay1 / w8nr6pay1a][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\w8nr6pay1a.sys><N/A>
[pponqw4 / pponqw44][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\pponqw44.sys><N/A>
删不掉呀。删掉又蹦出来了。我都折腾一晚上了。
瑞星报pponqw4.dll这个东西是毒,提示重启后删除但是重启了还在。
IE主页还是被修改的状态。IE自定义搜索引擎跟备用搜索引擎被改了。这是360报的。
开机有两个模块无法加载。etb7118.dll这个是找不到指定文件。pponqw4.dll这个是拒绝访问。
请问该如何解决啊。
又扫描了一份日志,你帮我看看吧,

附件: 824269200772043212.txt
夏天微微 - 2007-7-20 4:44:00
怎么找不到文件???
我贴上来吧。
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <PCTVOICE><pctspk.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <RavTask><"D:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <RfwMain><"D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [N/A]
    <BigDogPath><C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera>  [N/A]
    <SunJavaUpdateSched><C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe>  [Sun Microsystems, Inc.]
    <runeip><"D:\Program Files\Rising\AntiSpyware\runiep.exe" /startup>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
    <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll>  [Beijing Rising Technology Co., Ltd.]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\system32\年韵20~1.SCR>  [Microsoft Corp.                                                                                    ]

==================================
启动文件夹
[腾讯QQ]
  <C:\Documents and Settings\mickey\「开始」菜单\程序\启动\腾讯QQ.lnk --> D:\PROGRA~1\9you\qq\QQ.exe [TENCENT]><N>

==================================
服务
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  <d:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
  <d:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"D:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"D:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Windows Media Connect Service / WMConnectCDS][Stopped/Manual Start]
  <C:\Program Files\Windows Media Connect 2\wmccds.exe><Microsoft Corporation>
[Windows Driver Foundation - User-mode Driver Framework / WudfSvc][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup-->%SystemRoot%\System32\WUDFSvc.dll><Microsoft Corporation>

==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[ExpScaner / ExpScaner][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\ExpScan.sys><>
[HookCont / HookCont][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[MEMSCAN / MEMSCAN][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs][Running/Auto Start]
  <\??\d:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[msnc / msnc][Stopped/Auto Start]
  <system32\DRIVERS\msnc.sys><N/A>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
  <system32\drivers\npf.sys><Politecnico di Torino>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[W2K Pctel Serial Device Driver / Ptserial][Running/Manual Start]
  <system32\DRIVERS\ptserial.sys><PCTEL, INC.>
[QuakeDRV / QuakeDRV][Stopped/Boot Start]
  <\SystemRoot\system32\DRIVERS\quakedrv.sys><N/A>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  <\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising Technology Co., Ltd.>
[RsFwDrv / RsFwDrv][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[SiS315 / SiS315][Running/Manual Start]
  <system32\DRIVERS\sisgrp.sys><Silicon Integrated Systems Corporation>
[SiS AGP Filter / sisagp][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\SISAGPX.sys><Silicon Integrated Systems Corporation>
[SiSkp / SiSkp][Running/System Start]
  <system32\drivers\srvkp.sys><N/A>
[SiS PCI Fast Ethernet Adapter Driver / SISNIC][Running/Manual Start]
  <system32\DRIVERS\sisnic.sys><SiS Corporation>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start]
  <system32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[sptd / sptd][Running/Boot Start]
  <\SystemRoot\System32\Drivers\sptd.sys><N/A>
[SAMSUNG Mobile USB Device II 1.0 driver (WDM) / ssm_bus][Stopped/Manual Start]
  <system32\DRIVERS\ssm_bus.sys><MCCI>
[SAMSUNG Mobile USB Modem II 1.0 Filter / ssm_mdfl][Stopped/Manual Start]
  <system32\DRIVERS\ssm_mdfl.sys><MCCI>
[SAMSUNG Mobile USB Modem II 1.0 Drivers / ssm_mdm][Stopped/Manual Start]
  <system32\DRIVERS\ssm_mdm.sys><MCCI>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
  <system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[W2k Vmodem / Vmodem][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\vmodem.sys><PCTEL, INC.>
[W2k Vpctcom / Vpctcom][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\vpctcom.sys><PCtel, Inc.>
[W2k Vvoice / Vvoice][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\vvoice.sys><PCtel, Inc.>
[w8nr6pay1 / w8nr6pay1a][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\w8nr6pay1a.sys><N/A>
[Winbond Infrared Device Driver / WBFIRDMA][Running/Manual Start]
  <system32\DRIVERS\wbfirdma.sys><Winbond Electronics Corp.>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[Windows Driver Foundation - User-mode Driver Framework Platform Driver / WudfPf][Stopped/Manual Start]
  <system32\DRIVERS\WudfPf.sys><Microsoft Corporation>
[Windows Driver Foundation - User-mode Driver Framework Reflector / WudfRd][Stopped/Manual Start]
  <system32\DRIVERS\wudfrd.sys><Microsoft Corporation>
[xAntiArpSpoof Service / xAntiArp][Stopped/Manual Start]
  <system32\DRIVERS\xAntiArp.sys><N/A>
[VIMICRO USB PC Camera / ZSMC302][Stopped/Manual Start]
  <System32\Drivers\usbVM31b.sys><VM>
[688810 / 688810][Running/]
  <2 - 系统找不到指定的文件。
><N/A>
夏天微微 - 2007-7-20 4:44:00
浏览器加载项
[BitComet Helper]
  {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <, N/A>
[Windows Live Sign-in Helper]
  {9030D464-4C02-4ABF-8ECC-5164760863C6} <, N/A>
[NavigatMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\Program Files\360safe\safemon\safemon.dll, >
[Java Plug-in 1.5.0_05]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll, Sun Microsystems, Inc.>
[启动迅雷5]
  {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <D:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[金山快译(&K)]
  {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <E:\Program Files\Kingsoft\FastAIT 2006\IEBand.dll, 金山软件股份有限公司>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[EditCtrl Class]
  {488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\aliedit.dll, >
[163Uploader Control]
  {8686F2A6-DC01-4E8F-BDE3-DCC7DBBAD6AE} <C:\WINDOWS\system32\163UPL~1.OCX, 广州网易互动娱乐有限公司>
[Java Plug-in 1.5.0_05]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll, Sun Microsystems, Inc.>
[Tencent Safety Online Base Module]
  {C09B522F-8AED-4E21-A65C-DC1AB652BAEE} <C:\WINDOWS\system32\TSOBase\TSOBase.ocx, Tencent Corporation>
[WebActivater Control]
  {C661F36D-DF85-4EF4-83C7-E107B83D04B1} <C:\WINDOWS\system32\3DShowVM.ocx, QQ>
[Java Plug-in 1.5.0_05]
  {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll, Sun Microsystems, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[PasswordEditCtrl Class]
  {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[ActiveMovieControl Object]
  {05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[Web Browser Applet Control]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\WINDOWS\system32\Msjava.dll, Microsoft Corporation>
[TBSB07481 Class]
  {2C5ACA01-1327-4D22-874E-A6AC7094481C} <C:\Program Files\工具条(T)\tbu05089\工具条.dll, N/A>
[BitComet Helper]
  {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <, N/A>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[金山快译(&K)]
  {6C3797D2-3FEF-4CD4-B654-D3AE55B4128C} <E:\Program Files\Kingsoft\FastAIT 2006\IEBand.dll, 金山软件股份有限公司>
[MSURL Class]
  {6CDD9D1F-7501-4B0F-90CD-5ADA4F15E6E8} <C:\WINDOWS\system32\msurlpar.dll, Statistics>
[WangWangObj Class]
  {6E213FC7-DD5A-4115-B7E6-D4C7838C361E} <D:\Program Files\淘宝网\淘宝旺旺\WangWangX4.dll, 阿里软件(中国)有限公司>
[360SafeLive]
  {87515F61-A66C-4319-A0E0-D416CB8059E3} <D:\Program Files\360safe\live.dll, 360safe.com>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Windows Live Sign-in Helper]
  {9030D464-4C02-4ABF-8ECC-5164760863C6} <, N/A>
[windows 信息管理]
  {B1B9CA6E-D469-4501-9ADC-90DC1F1EE841} <C:\WINDOWS\system32\serverhelp.dll, >
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[NavigatMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\Program Files\360safe\safemon\safemon.dll, >
[Tencent Safety Online Base Module]
  {C09B522F-8AED-4E21-A65C-DC1AB652BAEE} <C:\WINDOWS\system32\TSOBase\TSOBase.ocx, Tencent Corporation>
[工具条(T)]
  {CC75D4E4-0DB5-4A0D-8B26-354A29757405} <C:\Program Files\工具条(T)\tbu05089\工具条.dll, N/A>
[AUDIO__MP3 Moniker Class]
  {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[PasswordEditCtrl Class]
  {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[&使用BitComet下载]
  <res://D:\Program Files\BitComet\BitComet.exe/AddLink.htm, N/A>
[&使用BitComet下载全部链接]
  <res://D:\Program Files\BitComet\BitComet.exe/AddAllLink.htm, N/A>
[&使用BitComet下载本页视频]
  <res://D:\Program Files\BitComet\BitComet.exe/AddVideo.htm, N/A>
[&使用迅雷下载]
  <D:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <D:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ表情]
  <D:\Program Files\9you\qq\AddEmotion.htm, N/A>
[设为 Messenger Live 头像]
  <C:\Program Files\MSNShell\Bin\SetMSNDP.htm, N/A>
夏天微微 - 2007-7-20 4:45:00
正在运行的进程
[PID: 564][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 620][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1760][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\WINDOWS\system32\shlhook.dll]  [Beijing Rising Technology Co., Ltd., 4.0.0.7]
    [D:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [D:\Program Files\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
[PID: 2036][d:\program files\rising\rfw\RfwMain.exe]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 72]
    [d:\program files\rising\rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
    [d:\program files\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [d:\program files\rising\rfw\RfwCtrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [d:\program files\rising\rfw\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [d:\program files\rising\rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [D:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [D:\Program Files\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
[PID: 264][C:\WINDOWS\system32\pctspk.exe]  [, 1, 0, 0, 1]
    [D:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2416][C:\WINDOWS\VM_STI.EXE]  [BIGDOG, 4, 2, 610, 4]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [D:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [D:\Program Files\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
[PID: 2456][C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe]  [Sun Microsystems, Inc., 5.0.50.5]
[PID: 2472][C:\WINDOWS\system32\rundll32.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\PROGRA~1\StormII\StormSet.dll]  [北京暴风网际科技有限公司, 2, 7, 4, 16]
[PID: 2504][D:\Program Files\Rising\AntiSpyware\runiep.exe]  [Beijing Rising Technology Co., Ltd., 4.0.0.15]
    [D:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2636][D:\Program Files\TheWorld 2.0\TheWorld.exe]  [Phoenix Studio, 2, 0, 4, 4]
    [D:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [D:\Program Files\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 2, 0, 0, 1]
    [C:\WINDOWS\system32\dllMergeDict.dll]  [N/A, ]
    [D:\Program Files\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
[PID: 3864][D:\Program Files\360safe\safemon\360Tray.exe]  [奇虎网, 3, 5, 2, 1001]
    [D:\Program Files\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [D:\Program Files\360safe\safemon\SafeKrnl.dll]  [奇虎网, 3, 5, 0, 1001]
    [D:\Program Files\360safe\AntiAdwa.dll]  [360Safe.com, 3, 5, 1, 1001]
    [D:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 3340][D:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
    [D:\Program Files\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [D:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\WINDOWS\system32\shlhook.dll]  [Beijing Rising Technology Co., Ltd., 4.0.0.7]
    [C:\DOCUME~1\mickey\LOCALS~1\Temp\Rar$DI00.048\SREng【teyqiu】.com]  [Smallfrogs Studio, 2.4.12.806]
    [D:\Program Files\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [D:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
夏天微微 - 2007-7-20 4:45:00
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================
隐藏进程
N/A
1
查看完整版本: 电脑中了不知什么毒,情况很糟糕。麻烦各位达人帮忙看看。