瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助,帮忙看一下是不是中毒了!!【求助】

12   2  /  2  页   跳转

求助,帮忙看一下是不是中毒了!!【求助】


    [C:\Program Files\Tencent\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [C:\Program Files\Tencent\QQ\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, ]
[PID: 2508][C:\Program Files\SAMSUNG\Aio\Shared\Bin\scxsts12.exe]  [N/A, ]
    [C:\Program Files\SAMSUNG\Aio\Shared\Bin\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  [CNNIC, 2, 0, 0, 2]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, ]
    [C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys]  [N/A, ]
    [C:\Program Files\SAMSUNG\Aio\Shared\Bin\scxres12.dll]  [, 1.5.0.0]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\OemDvm12.dll]  [Hewlett-Packard Co., 1.00]
    [C:\WINDOWS\system32\OemCob12.dll]  [Hewlett-Packard Co., 2.00]
    [C:\WINDOWS\system32\OemDvi12.dll]  [Hewlett-Packard Co., 2.00]
    [C:\WINDOWS\system32\OemDio12.dll]  [Hewlett-Packard Co., 3.00]
    [C:\WINDOWS\system32\OemDev12.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\oemipr12.dll]  [HP, 5, 0, 5, 0]
    [C:\WINDOWS\system32\oemidr12.dll]  [HP, 5, 0, 5, 0]
[PID: 2816][C:\WINDOWS\system32\OEMipm12.exe]  [HP, 5, 0, 5, 3]
    [C:\WINDOWS\system32\OEMidr12.dll]  [HP, 5, 0, 5, 0]
[PID: 3080][C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe]  [Microsoft Corporation, 4.100.313.1]
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  [CNNIC, 2, 0, 0, 2]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, ]
    [C:\Program Files\Common Files\Microsoft Shared\Windows Live\msidcrl40.dll]  [Microsoft Corporation, 4.100.313.1]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2408][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  [CNNIC, 2, 0, 0, 2]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, ]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.7.2006011200]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll]  [Microsoft Corporation, 4.100.313.1]
    [I:\PROGRA~1\FLASHGET\JCCATCH.DLL]  [Amaze Soft, 1, 1, 4, 0]
    [C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll]  [CNNIC, 1, 1, 0, 0]
    [C:\Program Files\Common Files\Microsoft Shared\Windows Live\msidcrl40.dll]  [Microsoft Corporation, 4.100.313.1]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\DOCUME~1\pitty\LOCALS~1\Temp\Wmzo0.dll]  [N/A, ]
    [C:\WINDOWS\system32\cmdbcs.dll]  [N/A, ]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.3790.3646 built by: DNSRV(bld4act)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\cdnns.dll]  [CNNIC, 2, 0, 0, 0]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\xpsp3res.dll]  [Microsoft Corporation, 5.1.2600.3059 (xpsp_sp2_gdr.070104-0050)]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\system32\KNT.IME]  [nzq.yeah.net, 4.00.950]
    [C:\WINDOWS\system32\KIme.ime]  [金山软件公司, 1, 0, 0, 1]
    [C:\PROGRA~1\COMMON~1\KingSoft\Extract\KSEngine.dll]  [, 1, 0, 0, 1]
    [C:\PROGRA~1\COMMON~1\KingSoft\Extract\xfile.dll]  [N/A, ]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
[PID: 2840][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  [CNNIC, 2, 0, 0, 2]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2528][C:\Program Files\SuperSoft\RdfSnap\RdfSnap.exe]  [非常软件(北京)工作室, 1.02.0003]
    [C:\WINDOWS\system32\MSVBVM60.DLL]  [Microsoft Corporation, 6.00.9782]
    [C:\WINDOWS\system32\vb6chs.dll]  [Microsoft Corporation, 6.00.8988]
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  [CNNIC, 2, 0, 0, 2]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, ]
    [C:\Program Files\SuperSoft\RdfSnap\PicFormat32.ocx]  [Taproot, 1.00.0001]
    [C:\WINDOWS\system32\MSSTDFMT.DLL]  [Microsoft Corporation, 6.01.9782]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\DOCUME~1\pitty\LOCALS~1\Temp\Wmzo0.dll]  [N/A, ]
    [C:\WINDOWS\system32\cmdbcs.dll]  [N/A, ]
[PID: 2476][I:\Program Files\FlashGet\flashget.exe]  [Amaze Soft, 1, 7, 1, 0]
gototop
 


    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  [CNNIC, 2, 0, 0, 2]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\DOCUME~1\pitty\LOCALS~1\Temp\Wmzo0.dll]  [N/A, ]
    [C:\WINDOWS\system32\cmdbcs.dll]  [N/A, ]
    [C:\WINDOWS\system32\cdnns.dll]  [CNNIC, 2, 0, 0, 0]
[PID: 3916][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  [CNNIC, 2, 0, 0, 2]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, ]
    [C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.3790.3646 built by: DNSRV(bld4act)]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\DOCUME~1\pitty\LOCALS~1\Temp\Wmzo0.dll]  [N/A, ]
    [C:\WINDOWS\system32\cmdbcs.dll]  [N/A, ]
[PID: 3588][C:\DOCUME~1\pitty\LOCALS~1\Temp\Rar$EX01.266\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  [CNNIC, 2, 0, 0, 2]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\DOCUME~1\pitty\LOCALS~1\Temp\Wmzo0.dll]  [N/A, ]
    [C:\WINDOWS\system32\cmdbcs.dll]  [N/A, ]
    [C:\WINDOWS\system32\cdnns.dll]  [CNNIC, 2, 0, 0, 0]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==========================


结束
gototop
 

没人帮忙啊,哪位能帮忙看一下,是不是病毒?
gototop
 


ICESWORD禁止进程创建
删除注册表项
<cs2mty><C:\DOCUME~1\pitty\LOCALS~1\Temp\c0nime.exe> []
<m8jmse20bs9u1jy><C:\DOCUME~1\pitty\LOCALS~1\Temp\Servere.exe> []
<j0es8fv2b><C:\DOCUME~1\pitty\LOCALS~1\Temp\crasos.exe> [N/A]
<0cq><C:\DOCUME~1\pitty\LOCALS~1\Temp\rundl132.exe> []
<458m><C:\DOCUME~1\pitty\LOCALS~1\Temp\winlog0n.exe> []
<c3i3i0><C:\DOCUME~1\pitty\LOCALS~1\Temp\cftmon.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<mppds><C:\WINDOWS\mppds.exe> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<winform><C:\WINDOWS\winform.exe> []
<upxdnd><C:\DOCUME~1\pitty\LOCALS~1\Temp\upxdnd.exe> []
<{754FB7D8-B8FE-4810-B363-A788CD060F1F}><C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys> []
服务
<C:\WINDOWS\system32\servet.exe><N/A>
文件
C:\WINDOWS\cmdbcs.exe
C:\WINDOWS\mppds.exe
C:\WINDOWS\msccrt.exe
C:\WINDOWS\winform.exe
C:\WINDOWS\system32\servet.exe
清空C:\DOCUME~1\pitty\LOCALS~1\Temp下所有文件
gototop
 

谢谢,请问具体要怎么操作.我不大懂.
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT