瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求杀,Dropper.Rynima.e和Trojan.Agent.yly

123   2  /  3  页   跳转

求杀,Dropper.Rynima.e和Trojan.Agent.yly

一定要真实反映运行状态的日志
gototop
 

不知道怎么,serng很多字都是问号
gototop
 

能不能告诉我其他的软件也可以生成扫描日志报告的,这个sreng中文全都变成了问号
gototop
 

【回复“photosynthesis”的帖子】
修复如下自启动项:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Desktop><"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Run> []

===========

开始--运行
输入regedit
确定
进入注册表

修改
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\Media\svchost.exe,C:\WINDOWS\system32\userinit.exe,> [N/A]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>

或直接使用SRE编辑修复
修复方法如上

============

修复如下浏览器加载项:
[实用搜索工具条2.0]
{03465FF5-00AE-411a-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>

[System Requirements Lab Class]
{BE833F39-1E0C-468C-BA70-25AAEE55775E} <C:\WINDOWS\Downloaded Program Files\sysreqlab.dll, Husdawg, LLC>

[实用搜索工具条2.0]
{03465FF5-00AE-411A-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>

[Info cache]
{385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, N/A>

[MallObj Class]
{3B30B48F-617D-4F73-A20F-D3D54357F103} <C:\WINDOWS\system32\mallgoo2.dll, 上海奥德易海科技>

[实用搜索]
{6CFD436C-7AAD-4E50-992F-C0C87A94CAD2} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>

[System Requirements Lab Class]
{BE833F39-1E0C-468C-BA70-25AAEE55775E} <C:\WINDOWS\Downloaded Program Files\sysreqlab.dll, Husdawg, LLC>

===========

修复如下服务项:
[Windows Install Helper / BKMARKS]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IXOOE.DLL,Export 1087><N/A>

[Network Engine / Hardware]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\fyrzz.dll><Microsoft Corporation>

[Microsoft Send / Microsoft Send]
<><N/A>

[System Event Notification / SENS]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\xiafxdob.dll><N/A>

[Volume Shadddddow Copyerq / Service332245]
<><N/A>

[VisionService / VisionService]
<C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\vision\VISVER.DLL,Service><Microsoft Corporation>

[Windows Firewall / Windows Firewall]
<C:\WINDOWS\system32\iexp1ore.exe><N/A>

[Windows NT Service32 / Windows NT Service32]
<"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Start><Microsoft Corporation>

==========

开始--运行
输入regedit
确定
进入注册表
依次展开
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Services](X代表1,2,3,4....)
找到后删除如下文件夹:
BKMARKS
Hardware
Microsoft Send
SENS
Service332245
VisionService
Windows Firewall
Windows NT Service32

依次展开
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Enum\Root\](X代表1,2,3,4....)
删除如下文件夹:
LEGACY_BKMARKS
LEGACY_Hardware
LEGACY_Microsoft Send
LEGACY_SENS
LEGACY_Service332245
LEGACY_VisionService
LEGACY_Windows Firewall
LEGACY_Windows NT Service32

===========

卸载
C:\Program Files\superutilbar\
C:\Program Files\vision\
C:\WINDOWS\system32\NTService32.dll
C:\WINDOWS\Media\svchost.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\
C:\WINDOWS\system32\mallgoo2.dll
C:\WINDOWS\Downloaded Program Files\sysreqlab.dll
C:\WINDOWS\SYSTEM32\WBEM\IXOOE.DLL
C:\WINDOWS\system32\fyrzz.dll
C:\WINDOWS\System32\xiafxdob.dll
C:\WINDOWS\system32\iexp1ore.exe
以及C:\Documents and Settings\TX\Local Settings\Temp\下的所有文件及文件夹

另外
C:\WINDOWS\system32\pwdmon.dll已经插入系统核心进程
请用KILLBOX这个工具的延迟删除功能删除C:\WINDOWS\system32\pwdmon.dll

==========

“System Repair Engineer”的使用操作参考:
http://forum.ikaka.com/topic.asp?board=67&artid=8125594

另外
日志不全
缺少驱动项
请导出全部日志
gototop
 

sreng都是问号。。。贴不出来,怎么办?
gototop
 

Drivers
[000070a0 / 000070a0]
  <\SystemRoot\system32\drivers\000070a0.SYS><N/A>
[abp480n5 / abp480n5]
  <\SystemRoot\system32\DRIVERS\ABP480N5.SYS><Microsoft Corporation>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[adpu160m / adpu160m]
  <\SystemRoot\system32\DRIVERS\adpu160m.sys><Microsoft Corporation>
[aeaudio / aeaudio]
  <system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[AEGIS Protocol (IEEE 802.1x) v3.2.0.3 / AegisP]
  <system32\DRIVERS\AegisP.sys><Meetinghouse Data Communications>
[Aha154x / Aha154x]
  <\SystemRoot\system32\DRIVERS\aha154x.sys><Microsoft Corporation>
[aic78u2 / aic78u2]
  <\SystemRoot\system32\DRIVERS\aic78u2.sys><Microsoft Corporation>
[aic78xx / aic78xx]
  <\SystemRoot\system32\DRIVERS\aic78xx.sys><Microsoft Corporation>
[AliIde / AliIde]
  <\SystemRoot\system32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD AGP Bus Filter Driver / amdagp]
  <\SystemRoot\system32\DRIVERS\amdagp.sys><Advanced Micro Devices, Inc.>
[ANC / ANC]
  <System32\drivers\ANC.SYS><IBM Corp.>
[Api Drivers / Api]
  <\??\C:\WINDOWS\system32\Drivers\Api.sys><N/A>
[Dual-band Wi-Fi Wireless Mini PCI Adapter / AR5211]
  <system32\DRIVERS\ar5211.sys><Atheros Communications, Inc.>
[asc / asc]
  <\SystemRoot\system32\DRIVERS\asc.sys><Advanced System Products, Inc.>
[asc3350p / asc3350p]
  <\SystemRoot\system32\DRIVERS\asc3350p.sys><Microsoft Corporation>
[asc3550 / asc3550]
  <\SystemRoot\system32\DRIVERS\asc3550.sys><Advanced System Products, Inc.>
[ati2mtag / ati2mtag]
  <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Broadcom NetXtreme Gigabit Ethernet / b57w2k]
  <system32\DRIVERS\b57xp32.sys><Broadcom Corporation>
[BaseTDI / BaseTDI]
  <\??\C:\WINDOWS\system32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
[蓝牙音频设备 / btaudio]
  <system32\drivers\btaudio.sys><Broadcom Corporation>
[蓝牙虚拟通信驱动程序 / BTDriver]
  <system32\DRIVERS\btport.sys><Broadcom Corporation>
[Bluetooth Protocol Stack / BTKRNL]
  <\SystemRoot\system32\drivers\btkrnl.sys><Broadcom Corporation>
[蓝牙局域网接入服务器 / BTWDNDIS]
  <system32\DRIVERS\btwdndis.sys><Broadcom Corporation>
[WIDCOMM USB Bluetooth Driver / BTWUSB]
  <System32\Drivers\btwusb.sys><Broadcom Corporation>
[cd20xrnt / cd20xrnt]
  <\SystemRoot\system32\DRIVERS\cd20xrnt.sys><Microsoft Corporation>
[cdawdm / cdawdm]
  <system32\DRIVERS\CDAWDM.sys><N/A>
[cdhafbjc / cdhafbjc]
  <\SystemRoot\system32\drivers\cdhafbjc.sys><中国互联网络信息中心(CNNIC)>
[CmdIde / CmdIde]
  <\SystemRoot\system32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[dac2w2k / dac2w2k]
  <\SystemRoot\system32\DRIVERS\dac2w2k.sys><Mylex Corporation>
[dpti2o / dpti2o]
  <\SystemRoot\system32\DRIVERS\dpti2o.sys><Microsoft Corporation>
[drvmcdb / drvmcdb]
  <\SystemRoot\system32\drivers\drvmcdb.sys><Sonic Solutions>
[drvnddm / drvnddm]
  <system32\drivers\drvnddm.sys><Sonic Solutions>
[dtscsi / dtscsi]
  <\SystemRoot\System32\Drivers\dtscsi.sys><N/A>
[Intel(R) PRO Adapter Driver / E100B]
  <system32\DRIVERS\e100b325.sys><Intel Corporation>
[EagleNT / EagleNT]
  <\??\C:\WINDOWS\system32\drivers\EagleNT.sys><N/A>
[IBM Access Support / EGATHDRV]
  <\??\C:\WINDOWS\SYSTEM32\EGATHDRV.SYS><IBM Corporation>
[ExpScaner / ExpScaner]
  <\??\d:\Program Files\Rising\Rav\ExpScan.sys><>
[GEAR CDRom Filter / GEARAspiWDM]
  <SYSTEM32\DRIVERS\GEARAspiWDM.sys><GEAR Software Inc.>
[HookCont / HookCont]
  <\??\d:\Program Files\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
  <\??\d:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
  <\??\d:\Program Files\Rising\Rav\HookSys.sys><Rising>
[IEEE-1284.4 Driver HPZid412 / HPZid412]
  <system32\DRIVERS\HPZid412.sys><HP>
[Print Class Driver for IEEE-1284.4 HPZipr12 / HPZipr12]
  <system32\DRIVERS\HPZipr12.sys><HP>
[USB to IEEE-1284.4 Translation Driver HPZius12 / HPZius12]
  <system32\DRIVERS\HPZius12.sys><HP>
[HSFHWICH / HSFHWICH]
  <system32\DRIVERS\HSFHWICH.sys><Conexant Systems, Inc.>
[HSF_DP / HSF_DP]
  <system32\DRIVERS\HSF_DP.sys><Conexant Systems, Inc.>
[ibmfilter / ibmfilter]
  <\??\C:\WINDOWS\system32\drivers\ibmfilter.sys><IBM>
[IBMPMDRV / IBMPMDRV]
  <system32\DRIVERS\ibmpmdrv.sys><IBM Corp.>
[IBMTPCHK / IBMTPCHK]
  <System32\drivers\IBMBLDID.SYS><N/A>
[ini910u / ini910u]
  <\SystemRoot\system32\DRIVERS\ini910u.sys><Microsoft Corporation>
[IsDrv120 / IsDrv120]
  <2 - 系统找不到指定的文件。
><N/A>
[mdmxsdk / mdmxsdk]
  <system32\DRIVERS\mdmxsdk.sys><Conexant>
[MEMSCAN / MEMSCAN]
  <\??\d:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mraid35x / mraid35x]
  <\SystemRoot\system32\DRIVERS\mraid35x.sys><American Megatrends Inc.>
[msprotect / msprotect]
  <system32\DRIVERS\msprotect.sys><Windows (R) 2000 DDK provider>
[msqmx / msqmx]
  <\??\C:\WINDOWS\system32\drivers\msqmx.sys><Microsoft Corporation>
[npkcrypt / npkcrypt]
  <\??\E:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkycryp / npkycryp]
gototop
 

<\??\E:\Program Files\Tencent\QQ\npkycryp.sys><N/A>
[NSC Infrared Device Driver / NSCIRDA]
  <system32\DRIVERS\nscirda.sys><National Semiconductor Corporation>
[nv / nv]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[PCDRNDISUIO Usermode I/O Protocol / PcdrNdisuio]
  <system32\DRIVERS\pcdrndisuio.sys><Windows (R) 2000 DDK provider>
[Padus ASPI Shell / Pfc]
  <system32\drivers\pfc.sys><Padus, Inc.>
[PMEM / PMEM]
  <\??\C:\WINDOWS\SYSTEM32\DRIVERS\PMEMNT.SYS><Microsoft Corporation>
[IBM PSA Access Driver / psadd]
  <\??\C:\WINDOWS\system32\Drivers\psadd.sys><IBM Corporation>
[Direct Parallel Link Driver / Ptilink]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20]
  <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[QCNDISIF / QCNDISIF]
  <System32\drivers\qcndisif.SYS><IBM Corporation.>
[ql1080 / ql1080]
  <\SystemRoot\system32\DRIVERS\ql1080.sys><QLogic Corporation>
[Ql10wnt / Ql10wnt]
  <\SystemRoot\system32\DRIVERS\ql10wnt.sys><Microsoft Corporation>
[ql12160 / ql12160]
  <\SystemRoot\system32\DRIVERS\ql12160.sys><QLogic Corporation>
[ql1280 / ql1280]
  <\SystemRoot\system32\DRIVERS\ql1280.sys><QLogic Corporation>
[QuakeDRV / QuakeDRV]
  <\SystemRoot\system32\DRIVERS\quakedrv.sys><N/A>
[Secdrv / Secdrv]
  <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[ShockMgr / ShockMgr]
  <C:\WINDOWS\SYSTEM32\DRIVERS\ShockMgr.SYS><IBM Corporation>
[Shockprf / Shockprf]
  <C:\WINDOWS\SYSTEM32\DRIVERS\Shockprf.SYS><IBM Corporation>
[SIS AGP Bus Filter / sisagp]
  <\SystemRoot\system32\DRIVERS\sisagp.sys><Silicon Integrated Systems Corporation>
[Smapint / Smapint]
  <System32\drivers\Smapint.sys><Microsoft Corporation>
[SMI helper driver / SmiHlp]
  <\??\C:\Program Files\IBM fingerprint software\smihlp.sys><UPEK Inc.>
[smwdm / smwdm]
  <system32\drivers\smwdm.sys><Analog Devices, Inc.>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1]
  <system32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[Sparrow / Sparrow]
  <\SystemRoot\system32\DRIVERS\sparrow.sys><Adaptec, Inc.>
[sptd / sptd]
  <\SystemRoot\System32\Drivers\sptd.sys><N/A>
[sscdbhk5 / sscdbhk5]
  <system32\drivers\sscdbhk5.sys><Sonic Solutions>
[ssrtln / ssrtln]
  <system32\drivers\ssrtln.sys><Sonic Solutions>
[symc810 / symc810]
  <\SystemRoot\system32\DRIVERS\symc810.sys><Symbios Logic Inc.>
[symc8xx / symc8xx]
  <\SystemRoot\system32\DRIVERS\symc8xx.sys><LSI Logic>
[SYMDNS / SYMDNS]
  <\SystemRoot\System32\Drivers\SYMDNS.SYS><Symantec Corporation>
[SymEvent / SymEvent]
  <\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[SYMFW / SYMFW]
  <\SystemRoot\System32\Drivers\SYMFW.SYS><Symantec Corporation>
[SYMIDS / SYMIDS]
  <\SystemRoot\System32\Drivers\SYMIDS.SYS><Symantec Corporation>
[SYMIDSCO / SYMIDSCO]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\IDS-DI~1\20060922.092\symidsco.sys><N/A>
[SYMNDIS / SYMNDIS]
  <\SystemRoot\System32\Drivers\SYMNDIS.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV]
  <\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI]
  <\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[sym_hi / sym_hi]
  <\SystemRoot\system32\DRIVERS\sym_hi.sys><LSI Logic>
[sym_u3 / sym_u3]
  <\SystemRoot\system32\DRIVERS\sym_u3.sys><LSI Logic>
[Synaptics TouchPad Driver / SynTP]
  <system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[TCP/IP Protocol Driver / Tcpip]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[TC USB Kernel Driver / TcUsb]
  <System32\Drivers\tcusb.sys><UPEK Inc.>
[TDSMAPI / TDSMAPI]
  <System32\drivers\TDSMAPI.SYS><N/A>
[tfsnboio / tfsnboio]
  <system32\dla\tfsnboio.sys><Sonic Solutions>
[tfsncofs / tfsncofs]
  <system32\dla\tfsncofs.sys><Sonic Solutions>
[tfsndrct / tfsndrct]
  <system32\dla\tfsndrct.sys><Sonic Solutions>
[tfsndres / tfsndres]
  <system32\dla\tfsndres.sys><Sonic Solutions>
[tfsnifs / tfsnifs]
  <system32\dla\tfsnifs.sys><Sonic Solutions>
[tfsnopio / tfsnopio]
  <system32\dla\tfsnopio.sys><Sonic Solutions>
[tfsnpool / tfsnpool]
  <system32\dla\tfsnpool.sys><Sonic Solutions>
[tfsnudf / tfsnudf]
  <system32\dla\tfsnudf.sys><Sonic Solutions>
[tfsnudfa / tfsnudfa]
  <system32\dla\tfsnudfa.sys><Sonic Solutions>
[TosIde / TosIde]
  <\SystemRoot\system32\DRIVERS\toside.sys><Microsoft Corporation>
[TPDiskPM / TPDiskPM]
  <C:\WINDOWS\SYSTEM32\DRIVERS\TPDiskPM.SYS><IBM Corporation>
[TPHKDRV / TPHKDRV]
  <C:\WINDOWS\SYSTEM32\DRIVERS\TPHKDRV.SYS><IBM Corporation>
[TPInput / TPInput]
  <System32\DRIVERS\TPInput.sys><IBM Corporation>
[NSC Integrated Trusted Platform Module 1.1 / TPM11]
  <system32\DRIVERS\nsctpm11.sys><National Semiconductor Corp.>
[TPPWRIF / TPPWRIF]
  <System32\drivers\Tppwrif.sys><N/A>
[TSMAPIP / TSMAPIP]
  <System32\drivers\TSMAPIP.SYS><N/A>
[ultra / ultra]
  <\SystemRoot\system32\DRIVERS\ultra.sys><Promise Technology, Inc.>
[ViaIde / ViaIde]
  <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[Sony Ericsson W600 driver (WDM) / w600bus]
  <system32\DRIVERS\w600bus.sys><MCCI>
[Sony Ericsson W600 USB WMC Modem Filter / w600mdfl]
  <system32\DRIVERS\w600mdfl.sys><MCCI>
[Sony Ericsson W600 USB WMC Modem Drivers / w600mdm]
  <system32\DRIVERS\w600mdm.sys><MCCI>
gototop
 

【回复“photosynthesis”的帖子】
修复如下自启动项:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Desktop><"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Run> []

===========

开始--运行
输入regedit
确定
进入注册表

修改
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\Media\svchost.exe,C:\WINDOWS\system32\userinit.exe,> [N/A]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>

或直接使用SRE编辑修复
修复方法如上

============

修复如下浏览器加载项:
[实用搜索工具条2.0]
{03465FF5-00AE-411a-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>

[System Requirements Lab Class]
{BE833F39-1E0C-468C-BA70-25AAEE55775E} <C:\WINDOWS\Downloaded Program Files\sysreqlab.dll, Husdawg, LLC>

[实用搜索工具条2.0]
{03465FF5-00AE-411A-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>

[Info cache]
{385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, N/A>

[MallObj Class]
{3B30B48F-617D-4F73-A20F-D3D54357F103} <C:\WINDOWS\system32\mallgoo2.dll, 上海奥德易海科技>

[实用搜索]
{6CFD436C-7AAD-4E50-992F-C0C87A94CAD2} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>

[System Requirements Lab Class]
{BE833F39-1E0C-468C-BA70-25AAEE55775E} <C:\WINDOWS\Downloaded Program Files\sysreqlab.dll, Husdawg, LLC>

===========

修复如下服务项:
[Windows Install Helper / BKMARKS]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IXOOE.DLL,Export 1087><N/A>

[Network Engine / Hardware]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\fyrzz.dll><Microsoft Corporation>

[Microsoft Send / Microsoft Send]
<><N/A>

[System Event Notification / SENS]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\xiafxdob.dll><N/A>

[Volume Shadddddow Copyerq / Service332245]
<><N/A>

[VisionService / VisionService]
<C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\vision\VISVER.DLL,Service><Microsoft Corporation>

[Windows Firewall / Windows Firewall]
<C:\WINDOWS\system32\iexp1ore.exe><N/A>

[Windows NT Service32 / Windows NT Service32]
<"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Start><Microsoft Corporation>

==========

修复如下驱动项
[000070a0 / 000070a0]
<\SystemRoot\system32\drivers\000070a0.SYS><N/A>

========

开始--运行
输入regedit
确定
进入注册表
依次展开
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Services](X代表1,2,3,4....)
找到后删除如下文件夹:
BKMARKS
Hardware
Microsoft Send
SENS
Service332245
VisionService
Windows Firewall
Windows NT Service32
000070a0

依次展开
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Enum\Root\](X代表1,2,3,4....)
删除如下文件夹:
LEGACY_BKMARKS
LEGACY_Hardware
LEGACY_Microsoft Send
LEGACY_SENS
LEGACY_Service332245
LEGACY_VisionService
LEGACY_Windows Firewall
LEGACY_Windows NT Service32
LEGACY_000070a0

===========

卸载
C:\Program Files\superutilbar\
C:\Program Files\vision\
C:\WINDOWS\system32\NTService32.dll
C:\WINDOWS\Media\svchost.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\
C:\WINDOWS\system32\mallgoo2.dll
C:\WINDOWS\Downloaded Program Files\sysreqlab.dll
C:\WINDOWS\SYSTEM32\WBEM\IXOOE.DLL
C:\WINDOWS\system32\fyrzz.dll
C:\WINDOWS\System32\xiafxdob.dll
C:\WINDOWS\system32\iexp1ore.exe
以及C:\Documents and Settings\TX\Local Settings\Temp\下的所有文件及文件夹

另外
C:\WINDOWS\system32\pwdmon.dll已经插入系统核心进程
请用KILLBOX这个工具的延迟删除功能删除C:\WINDOWS\system32\pwdmon.dll

==========

“System Repair Engineer”的使用操作参考:
http://forum.ikaka.com/topic.asp?board=67&artid=8125594
gototop
 

2006-12-15,03:59:12

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <MsnMsgr><; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>  [(Verified)Microsoft Corporation]
    <ibmmessages><; C:\Program Files\IBM\Messages By IBM\ibmmessages.exe>  [IBM]
    <Super Rabbit IEPro><D:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD>  [Super Rabbit Soft]
    <Super Rabbit Start Button><D:\Program Files\Super Rabbit\MagicSet\SRSB.EXE /Load>  [Super Rabbit Soft]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <TPHOTKEY><; C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe>  [N/A]
    <EZEJMNAP><; C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe>  [IBM Corp.]
    <SoundMAXPnP><C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe>  [Analog Devices, Inc.]
    <SoundMAX><C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray>  [Analog Devices, Inc.]
    <ATIPTA><; C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>  [ATI Technologies, Inc.]
    <UpdateManager><; "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r>  [Sonic Solutions]
    <QCWLICON><; C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE>  [IBM Corp.]
    <MSPY2002><C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC>  [(Verified)N/A]
    <DAEMON Tools><"e:\Program Files\DAEMON Tools\daemon.exe" -lang 1033>  [(Verified)DT Soft Ltd.]
    <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <HP Software Update><; D:\Program Files\HP\HP Software Update\HPWuSchd2.exe>  [Hewlett-Packard Co.]
    <IntelliPoint><"C:\Program Files\Microsoft IntelliPoint\point32.exe">  [Microsoft Corporation]
    <RavTask><; "d:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [N/A]
    <ATICCC><; "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe">  [N/A]
    <QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime>  [Apple Computer, Inc.]
    <iTunesHelper><; "C:\Program Files\iTunes\iTunesHelper.exe">  [(Verified)Apple Computer, Inc.]
    <Desktop><"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Run>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\RESOUR~1\Themes\THINKT~1\IBMTHI~1.SCR>  [Hua Software (website http://www.21hua.com)]

==================================
启动文件夹
[腾讯QQ]
  <C:\Documents and Settings\TX\「开始」菜单\程序\启动\腾讯QQ.lnk --> E:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><H>

==================================
服务
[ACU Configuration Service / ACS]
  <C:\WINDOWS\system32\acs.exe><N/A>
[ASP.NET State Service / aspnet_state]
  <C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Ati HotKey Poller / Ati HotKey Poller]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart]
  <C:\WINDOWS\system32\ati2sgag.exe><>
[Bluetooth Service / btwdins]
  <C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe><Broadcom Corporation>
[IBM Rapid Restore Ultra Service / IBM Rapid Restore Ultra Service]
  <"C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe"><>
[IBM PM Service / IBMPMSVC]
  <C:\WINDOWS\system32\ibmpmsvc.exe><N/A>
[InstallDriver Table Manager / IDriverT]
  <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[iPod Service / iPod Service]
  <"D:\Program Files\iPod\bin\iPodService.exe"><Apple Computer, Inc.>
[Pml Driver HPZ12 / Pml Driver HPZ12]
  <C:\WINDOWS\system32\HPZipm12.exe><HP>
[IBM PSA Access Driver Control / PsaSrv]
  <><N/A>
[QCONSVC / QCONSVC]
  <System32\QCONSVC.EXE><N/A>
[Rising Process Communication Center / RsCCenter]
  <"d:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"d:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Symantec Network Drivers Service / SNDSrvc]
  <"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[SoundMAX Agent Service / SoundMAX Agent Service (default)]
  <C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[IBM HDD APS Logging Service / TPHDEXLGSVC]
  <System32\TPHDEXLG.EXE><N/A>
[IBM KCU Service / TpKmpSVC]
  <C:\WINDOWS\system32\TpKmpSVC.exe><N/A>
[VisionService / VisionService]
  <C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\vision\VISVER.DLL,Service><Microsoft Corporation>
[Protector Suite Virtual Token / vtserver]
  <"C:\Program Files\Common Files\Virtual Token\vtserver.exe"><UPEK Inc.>
[Windows NT Service32 / Windows NT Service32]
  <"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Start><Microsoft Corporation>
[Windows Media Connect (WMC) / WmcCds]
  <c:\program files\windows media connect\mswmccds.exe><Microsoft Corporation>
[Windows Media Connect (WMC) 帮助程序 / WmcCdsLs]
  <C:\Program Files\Windows Media Connect\mswmcls.exe><Microsoft Corporation>
gototop
 

驱动程序
[000070a0 / 000070a0]
  <\SystemRoot\system32\drivers\000070a0.SYS><N/A>
[abp480n5 / abp480n5]
  <\SystemRoot\system32\DRIVERS\ABP480N5.SYS><Microsoft Corporation>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[adpu160m / adpu160m]
  <\SystemRoot\system32\DRIVERS\adpu160m.sys><Microsoft Corporation>
[aeaudio / aeaudio]
  <system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[AEGIS Protocol (IEEE 802.1x) v3.2.0.3 / AegisP]
  <system32\DRIVERS\AegisP.sys><Meetinghouse Data Communications>
[Aha154x / Aha154x]
  <\SystemRoot\system32\DRIVERS\aha154x.sys><Microsoft Corporation>
[aic78u2 / aic78u2]
  <\SystemRoot\system32\DRIVERS\aic78u2.sys><Microsoft Corporation>
[aic78xx / aic78xx]
  <\SystemRoot\system32\DRIVERS\aic78xx.sys><Microsoft Corporation>
[AliIde / AliIde]
  <\SystemRoot\system32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD AGP Bus Filter Driver / amdagp]
  <\SystemRoot\system32\DRIVERS\amdagp.sys><Advanced Micro Devices, Inc.>
[ANC / ANC]
  <System32\drivers\ANC.SYS><IBM Corp.>
[Api Drivers / Api]
  <\??\C:\WINDOWS\system32\Drivers\Api.sys><N/A>
[Dual-band Wi-Fi Wireless Mini PCI Adapter / AR5211]
  <system32\DRIVERS\ar5211.sys><Atheros Communications, Inc.>
[asc / asc]
  <\SystemRoot\system32\DRIVERS\asc.sys><Advanced System Products, Inc.>
[asc3350p / asc3350p]
  <\SystemRoot\system32\DRIVERS\asc3350p.sys><Microsoft Corporation>
[asc3550 / asc3550]
  <\SystemRoot\system32\DRIVERS\asc3550.sys><Advanced System Products, Inc.>
[ati2mtag / ati2mtag]
  <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Broadcom NetXtreme Gigabit Ethernet / b57w2k]
  <system32\DRIVERS\b57xp32.sys><Broadcom Corporation>
[BaseTDI / BaseTDI]
  <\??\C:\WINDOWS\system32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
[蓝牙音频设备 / btaudio]
  <system32\drivers\btaudio.sys><Broadcom Corporation>
[蓝牙虚拟通信驱动程序 / BTDriver]
  <system32\DRIVERS\btport.sys><Broadcom Corporation>
[Bluetooth Protocol Stack / BTKRNL]
  <\SystemRoot\system32\drivers\btkrnl.sys><Broadcom Corporation>
[蓝牙局域网接入服务器 / BTWDNDIS]
  <system32\DRIVERS\btwdndis.sys><Broadcom Corporation>
[WIDCOMM USB Bluetooth Driver / BTWUSB]
  <System32\Drivers\btwusb.sys><Broadcom Corporation>
[cd20xrnt / cd20xrnt]
  <\SystemRoot\system32\DRIVERS\cd20xrnt.sys><Microsoft Corporation>
[cdawdm / cdawdm]
  <system32\DRIVERS\CDAWDM.sys><N/A>
[cdhafbjc / cdhafbjc]
  <\SystemRoot\system32\drivers\cdhafbjc.sys><中国互联网络信息中心(CNNIC)>
[CmdIde / CmdIde]
  <\SystemRoot\system32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[dac2w2k / dac2w2k]
  <\SystemRoot\system32\DRIVERS\dac2w2k.sys><Mylex Corporation>
[dpti2o / dpti2o]
  <\SystemRoot\system32\DRIVERS\dpti2o.sys><Microsoft Corporation>
[drvmcdb / drvmcdb]
  <\SystemRoot\system32\drivers\drvmcdb.sys><Sonic Solutions>
[drvnddm / drvnddm]
  <system32\drivers\drvnddm.sys><Sonic Solutions>
[dtscsi / dtscsi]
  <\SystemRoot\System32\Drivers\dtscsi.sys><N/A>
[Intel(R) PRO Adapter Driver / E100B]
  <system32\DRIVERS\e100b325.sys><Intel Corporation>
[EagleNT / EagleNT]
  <\??\C:\WINDOWS\system32\drivers\EagleNT.sys><N/A>
[IBM Access Support / EGATHDRV]
  <\??\C:\WINDOWS\SYSTEM32\EGATHDRV.SYS><IBM Corporation>
[ExpScaner / ExpScaner]
  <\??\d:\Program Files\Rising\Rav\ExpScan.sys><>
[GEAR CDRom Filter / GEARAspiWDM]
  <SYSTEM32\DRIVERS\GEARAspiWDM.sys><GEAR Software Inc.>
[HookCont / HookCont]
  <\??\d:\Program Files\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
  <\??\d:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
  <\??\d:\Program Files\Rising\Rav\HookSys.sys><Rising>
[IEEE-1284.4 Driver HPZid412 / HPZid412]
  <system32\DRIVERS\HPZid412.sys><HP>
[Print Class Driver for IEEE-1284.4 HPZipr12 / HPZipr12]
  <system32\DRIVERS\HPZipr12.sys><HP>
[USB to IEEE-1284.4 Translation Driver HPZius12 / HPZius12]
  <system32\DRIVERS\HPZius12.sys><HP>
[HSFHWICH / HSFHWICH]
  <system32\DRIVERS\HSFHWICH.sys><Conexant Systems, Inc.>
[HSF_DP / HSF_DP]
  <system32\DRIVERS\HSF_DP.sys><Conexant Systems, Inc.>
[ibmfilter / ibmfilter]
  <\??\C:\WINDOWS\system32\drivers\ibmfilter.sys><IBM>
[IBMPMDRV / IBMPMDRV]
  <system32\DRIVERS\ibmpmdrv.sys><IBM Corp.>
[IBMTPCHK / IBMTPCHK]
  <System32\drivers\IBMBLDID.SYS><N/A>
[ini910u / ini910u]
  <\SystemRoot\system32\DRIVERS\ini910u.sys><Microsoft Corporation>
[mdmxsdk / mdmxsdk]
  <system32\DRIVERS\mdmxsdk.sys><Conexant>
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT