12   2  /  2  页   跳转

Trojan.PSW.LMir.lrp很狂啊

文件都无法找到,还谈什么删除?
gototop
 

请扫个SRENG的日志
gototop
 

2006-12-11,23:23:01

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)


启动项目


注册表

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
(ctfmon.exe)(C:\WINDOWS\system32\ctfmon.exe) [(Verified)Microsoft Corporation]
(Super Rabbit IEPro)(F:\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD) [Super Rabbit Soft]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(load)() [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
(SunTown)() [N/A]
(NeroCheck)(C:\WINDOWS\system32\NeroCheck.exe) [Ahead Software Gmbh]
(HPDJ Taskbar Utility)(C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe) [(Verified)HP]
(HPHUPD06)(F:\hp\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe) [Hewlett-Packard]
(HP Software Update)("F:\hp\HP Software Update\HPWuSchd2.exe") [Hewlett-Packard Company]
(HP Component Manager)("C:\Program Files\HP\hpcoretech\hpcmpmgr.exe") [Hewlett-Packard Company]
(HPHmon06)(C:\WINDOWS\system32\hphmon06.exe) [Hewlett-Packard]
(DAEMON Tools-2052)("F:\ttxx-daemontools347\tools\daemon.exe" -lang 2052) [DAEMON'S HOME]
(stup.exe)(C:\PROGRA~1\TENCENT\Adplus\stup.exe) [Tencent]
(SoftickPPP)("C:\Program Files\Softick\PPP\Bin\PPPGate.exe") [Softick]
(RavTask)("F:\Rising\Rav\RavTask.exe" -system) [Beijing Rising Technology Co., Ltd.]
(RavScanBD)("F:\Rising\Rav\ScanBD.exe" /INST) [Beijing Rising Technology Co., Ltd.]
(AddrPlus2)(; RUNDLL32.EXE C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll,Rundll32) [N/A]
(ATIPTA)(; C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe) [ATI Technologies, Inc.]
(IMJPMIG8.1)(; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32) [(Verified)Microsoft Corporation]
(iTunesHelper)(; "C:\Program Files\iTunes\iTunesHelper.exe") [Apple Computer, Inc.]
(jmekey)(; C:\Program Files\jmesoft\hotkey.exe) [JME Co., Ltd.]
(OhgInstall)(; C:\Program Files\智能驱动\Install.exe S) [N/A]
(PHIME2002A)(; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName) [(Verified)Microsoft Corporation]
(PHIME2002ASync)(; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC) [(Verified)Microsoft Corporation]
(SoundMan)(; SOUNDMAN.EXE) [(Verified)Realtek Semiconductor Corp.]
(TeamSun LPC)(; "C:\Program Files\founder\IP_Phone\slpc.exe" Tray) [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(shell)(Explorer.exe) [(Verified)Microsoft Corporation]
(Userinit)(C:\WINDOWS\system32\userinit.exe,) [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(AppInit_DLLs)(338448M.BMP) [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(UIHost)(logonui.exe) [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
({32CD708B-60A7-4C00-9377-D73EAA495F0F})(C:\WINDOWS\system32\RavExt.dll) [Beijing Rising Technology Co., Ltd.]




--------------------------------------------------------------------------------



启动文件夹

[DuDu下载加速器]
(C:\Documents and Settings\All Users\「开始」菜单\程序\启动\DuDu下载加速器.lnk --) C:\PROGRA~1\DuDu\Speed\DuDuAcc.exe [DuDu.com])(N)
[HP Digital Imaging Monitor]
(C:\Documents and Settings\All Users\「开始」菜单\程序\启动\HP Digital Imaging Monitor.lnk --) F:\hp\DIGITA~1\bin\hpqtra08.exe [Hewlett-Packard Co.])(N)
[HP Image Zone 快速启动 ]
(C:\Documents and Settings\All Users\「开始」菜单\程序\启动\HP Image Zone 快速启动 .lnk --) F:\hp\DIGITA~1\bin\hpqthb08.exe [Hewlett-Packard Co.])(N)
[腾讯QQ]
(C:\Documents and Settings\banana\「开始」菜单\程序\启动\腾讯QQ.lnk --) C:\PROGRA~1\Tencent\fzQQ\QQ.exe [TENCENT])(N)
gototop
 

服务

[Application Management / AppMgmt]
(C:\WINDOWS\system32\svchost.exe -k netsvcs--)%SystemRoot%\System32\appmgmts.dll)(N/A)
[ASP.NET State Service / aspnet_state]
(C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe)(Microsoft Corporation)
[Ati HotKey Poller / Ati HotKey Poller]
(C:\WINDOWS\system32\Ati2evxx.exe)(ATI Technologies Inc.)
[ATI Smart / ATI Smart]
(C:\WINDOWS\system32\ati2sgag.exe)()
[Human Interface Device Access / HidServ]
(C:\WINDOWS\System32\svchost.exe -k netsvcs--)%SystemRoot%\System32\hidserv.dll)(N/A)
[iPod 服务 / iPodService]
("C:\Program Files\iPod\bin\iPodService.exe")(Apple Computer, Inc.)
[Network Logons / NetWorkLogons]
(rundll32.exe KB27861012.log,start)(Microsoft Corporation)
[P4P Service / P4P Service]
(C:\Program Files\Common Files\Sogou PXP\p2psvr.exe)(Sohu.com Inc.)
[Pml Driver HPZ12 / Pml Driver HPZ12]
(C:\WINDOWS\system32\HPZipm12.exe)(HP)
[Sysbak hotkey Server / Sysbak_hotkey_Server]
(C:\Program Files\Founder\Emergency Center\Hotkey.exe)(N/A)
[TeamSun LPC / TeamSun LPC]
(C:\PROGRA~1\founder\IP_Phone\slpc.exe)(N/A)
[Windows DHCP Service / WinDHCPsvc]
(C:\WINDOWS\system32\rundll32.exe windhcp.ocx,start)(Microsoft Corporation)



--------------------------------------------------------------------------------



驱动程序

[Service for Realtek AC97 Audio (WDM) / ALCXWDM]
(system32\drivers\ALCXWDM.SYS)(Realtek Semiconductor Corp.)
[ati2mtag / ati2mtag]
(system32\DRIVERS\ati2mtag.sys)(ATI Technologies Inc.)
[Rising TDI Base Driver / BaseTDI]
(System32\DRIVERS\BaseTDI.SYS)(Beijing Rising Technology Co., Ltd.)
[d347bus / d347bus]
(\SystemRoot\system32\DRIVERS\d347bus.sys)()
[d347prt / d347prt]
(\SystemRoot\System32\Drivers\d347prt.sys)()
[EagleNT / EagleNT]
(\??\C:\WINDOWS\system32\drivers\EagleNT.sys)(N/A)
[ferdr / ferdr]
(\??\C:\WINDOWS\system32\Drivers\Ferdr.sys)(N/A)
[GEAR CDRom Filter / GEARAspiWDM]
(SYSTEM32\DRIVERS\GEARAspiWDM.sys)(GEAR Software Inc.)
[HOOKAPI / HOOKAPI]
(\??\F:\RISING\RAV\HookApi.Sys)(瑞星软件有限公司)
[IEEE-1284.4 Driver HPZid412 / HPZid412]
(system32\DRIVERS\HPZid412.sys)(HP)
[Print Class Driver for IEEE-1284.4 HPZipr12 / HPZipr12]
(system32\DRIVERS\HPZipr12.sys)(HP)
[USB to IEEE-1284.4 Translation Driver HPZius12 / HPZius12]
(system32\DRIVERS\HPZius12.sys)(HP)
[npkcrypt / npkcrypt]
(\??\C:\Program Files\Tencent\fzQQ\npkcrypt.sys)(N/A)
[npkycryp / npkycryp]
(\??\C:\Program Files\Tencent\fzQQ\npkycryp.sys)(N/A)
[PauseDrv / PauseDrv]
(\??\C:\WINDOWS\system32\Drivers\PauseDrv.sys)(N/A)
[Direct Parallel Link Driver / Ptilink]
(system32\DRIVERS\ptilink.sys)(Parallel Technologies, Inc.)
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
(system32\DRIVERS\RTL8139.SYS)(Realtek Semiconductor Corporation)
[Secdrv / Secdrv]
(system32\DRIVERS\secdrv.sys)(N/A)
[SiSide / SiSide]
(\SystemRoot\system32\DRIVERS\siside.sys)(Silicon Integrated Systems Corp.)
[sisidex / sisidex]
(\SystemRoot\system32\drivers\sisidex.sys)(Windows (R) 2000 DDK provider)
[Add Performance Filter Driver / sisperf]
(\SystemRoot\system32\drivers\sisperf.sys)(Silicon Integrated Systems Corp.)
[SAMSUNG Mobile USB Device II 1.0 driver (WDM) / ssm_bus]
(system32\DRIVERS\ssm_bus.sys)(MCCI)
[SAMSUNG Mobile USB Modem II 1.0 Filter / ssm_mdfl]
(system32\DRIVERS\ssm_mdfl.sys)(MCCI)
[SAMSUNG Mobile USB Modem II 1.0 Drivers / ssm_mdm]
(system32\DRIVERS\ssm_mdm.sys)(MCCI)
[VHDISK / VHDISK]
(C:\WINDOWS\SYSTEM32\DRIVERS\VHDISK.SYS)(N/A)
[RSPPSYS / RSPPSYS]
(\??\F:\Rising\Rav\RSPPSYS.sys)(Rising)
[ExpScaner / ExpScaner]
(\??\F:\Rising\Rav\ExpScan.sys)()
[HookCont / HookCont]
(\??\F:\Rising\Rav\HOOKCONT.sys)(Rising)
[HookSys / HookSys]
(\??\F:\Rising\Rav\HookSys.sys)(Rising)

gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT