123   2  /  3  页   跳转

很多病毒,帮忙看下日志,谢谢

{87515F61-A66C-4319-A0E0-D416CB8059E3} <c:\安全卫士\360safe\live.dll, 360safe.com>
[Vod Class]
  {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} <C:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DapPlayer_Now.dll, XunLei>
[上传到QQ网络硬盘]
  <D:\QQ\AddToNetDisk.htm, N/A>
[使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[导出到 Microsoft Excel(&x)]
  <res://D:\word\Office10\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <D:\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\QQ\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 364 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 852 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 876 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 920 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.1152 (xpsp2.021217-1051)]
[PID: 932 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1108 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1256 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 1568 / NETWORK SERVICE][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1600 / LOCAL SERVICE][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1808 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 228 / maondodo][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\shdocvw32.dll]  [Microsoft Corporation, 6.00.3790.2783 ]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\TPwrCfg.DLL]  [TOSHIBA Corporation, 1, 0, 4, 0]
    [C:\WINDOWS\System32\TPwrReg.dll]  [TOSHIBA Corporation, 1, 0, 1, 0]
    [C:\WINDOWS\System32\TPSTrace.DLL]  [TOSHIBA Corporation, 1, 0, 2, 0]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
    [c:\program files\kaspersky lab\kaspersky internet security 6.0\params.ppl]  [Kaspersky Lab, 6.0.0.299]
    [c:\program files\kaspersky lab\kaspersky internet security 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [c:\program files\kaspersky lab\kaspersky internet security 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Shfusion.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.2.9]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 3, 11]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll]  [, 1, 0, 0, 4]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
[PID: 528 / maondodo][C:\WINDOWS\System32\igfxtray.exe]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxdev.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
    [C:\WINDOWS\System32\igfxsrvc.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxres.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxress.dll]  [Intel Corporation, 3,0,0,2104]
[PID: 536 / maondodo][C:\WINDOWS\System32\hkcmd.exe]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxdev.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
    [C:\WINDOWS\System32\igfxsrvc.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxhk.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxres.dll]  [Intel Corporation, 3,0,0,2104]
[PID: 544 / maondodo][C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe]  [adi, 1, 0, 0, 18]
    [C:\Program Files\Analog Devices\SoundMAX\PMCPL.cpl]  [Analog Devices, 1, 0, 0, 19]
[PID: 556 / maondodo][C:\WINDOWS\System32\00THotkey.exe]  [东芝公司, 1, 0, 0, 21]
    [C:\WINDOWS\system32\TSCI.DLL]  [Toshiba, 1.0.0.0]
    [C:\WINDOWS\system32\THCI.DLL]  [Toshiba, 1.0.0.0]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 576 / maondodo][C:\Program Files\Synaptics\SynTP\SynTPLpr.exe]  [Synaptics, Inc., 7.5.11 30May03]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
[PID: 600 / maondodo][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe]  [Synaptics, Inc., 7.5.11 30May03]
    [C:\WINDOWS\System32\SynCOM.dll]  [Synaptics, Inc., 7.5.11 30May03]
    [C:\WINDOWS\System32\SynTPAPI.dll]  [Synaptics, Inc., 7.5.11 30May03]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
[PID: 332 / maondodo][C:\WINDOWS\LTSMMSG.exe]  [LT,  3.1.118.2 04/18/2003 10:06:28]
[PID: 1672 / maondodo][C:\WINDOWS\System32\TFNF5.exe]  [Toshiba Corp., 1. 0. 1. 0]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
[PID: 1688 / maondodo][C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe]  [TOSHIBA Corporation, 3.01.01]
    [C:\WINDOWS\System32\TCtrlCommon.dll]  [TOSHIBA Corporation, 3.01.00]
    [C:\WINDOWS\System32\THCI.dll]  [Toshiba, 1.0.0.0]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
[PID: 1700 / maondodo][C:\Program Files\TOSHIBA\TouchED\TouchED.Exe]  [东芝公司, 2, 5, 0, 0]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
[PID: 1708 / maondodo][C:\WINDOWS\System32\ezSP_Px.exe]  [Easy Systems Japan Ltd., 1, 0, 0, 0]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
[PID: 1716 / maondodo][C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe]  [TOSHIBA CORPORATION, 2, 1, 0, 1]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
[PID: 1724 / maondodo][C:\WINDOWS\System32\TPSMain.exe]  [TOSHIBA Corporation, 1, 0, 1, 2]
    [C:\WINDOWS\System32\TPSMainCtl.dll]  [TOSHIBA Corporation, 1, 0, 1, 0]
    [C:\WINDOWS\System32\CpuPerf.dll]  [TOSHIBA Corporation, 1, 0, 1, 0]
    [C:\WINDOWS\System32\TPSTrace.DLL]  [TOSHIBA Corporation, 1, 0, 2, 0]
    [C:\WINDOWS\System32\TPwrReg.dll]  [TOSHIBA Corporation, 1, 0, 1, 0]
    [C:\WINDOWS\System32\TPeculiarity.dll]  [TOSHIBA Corporation, 1, 0, 1, 0]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
[PID: 1768 / maondodo][C:\安全卫士\360safe\safemon\360Tray.exe]  [奇虎网, 3, 5, 2, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\安全卫士\360safe\safemon\SafeKrnl.dll]  [奇虎网, 3, 5, 0, 1001]
    [C:\安全卫士\360safe\AntiAdwa.dll]  [360Safe.com, 3, 5, 1, 1001]
[PID: 1872 / maondodo][D:\ipod\iTunesHelper.exe]  [Apple Inc., 7.3.1.3]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
    [D:\ipod\iTunesHelper.Resources\zh_CN.lproj\iTunesHelperLocalized.DLL]  [Apple Inc., 7.3.0.54]
gototop
 

[D:\ipod\iTunesHelper.Resources\iTunesHelper.DLL]  [Apple Inc., 7.3.1.3]
[PID: 1884 / maondodo][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
[PID: 1892 / maondodo][C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe]  [TOSHIBA, 1, 0, 5, 0]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
[PID: 1900 / maondodo][C:\Program Files\MSN Messenger\MsnMsgr.Exe]  [Microsoft Corporation, 8.1.0178.00]
    [C:\Program Files\MSN Messenger\MSNCore.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\Program Files\MSN Messenger\msidcrl40.dll]  [Microsoft Corporation, 4.100.313.1]
    [C:\Program Files\MSN Messenger\ContactsUX.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
    [C:\Program Files\MSN Messenger\msgslang.8.1.0178.00.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\Program Files\MSN Messenger\msgsres.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\Program Files\MSN Messenger\custsat.dll]  [Microsoft Corporation, 9.0.3790.2428 (srv03_sp1_qfe.050422-1043)]
    [C:\Program Files\MSN Messenger\MSGSWCAM.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\WINDOWS\System32\sirenacm.dll]  [Microsoft Corp., 8.1.0178.00]
    [C:\WINDOWS\System32\msdmo.dll]  [, ]
[PID: 1960 / maondodo][C:\WINDOWS\System32\TPSBattM.exe]  [TOSHIBA Corporation, 1, 0, 1, 0]
    [C:\WINDOWS\System32\TPwrCfg.DLL]  [TOSHIBA Corporation, 1, 0, 4, 0]
    [C:\WINDOWS\System32\TPwrReg.dll]  [TOSHIBA Corporation, 1, 0, 1, 0]
    [C:\WINDOWS\System32\TPSTrace.DLL]  [TOSHIBA Corporation, 1, 0, 2, 0]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
[PID: 1956 / maondodo][C:\WINDOWS\system32\RAMASST.exe]  [Matsushita Electric Industrial Co., Ltd., 1, 0, 9, 0]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
[PID: 2020 / maondodo][D:\QQ\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [D:\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [D:\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [D:\QQ\BasicCtrlDll.dll]  [Tencent, 6, 0, 200, 320]
    [D:\QQ\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
    [D:\QQ\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [D:\QQ\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [D:\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [D:\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [D:\QQ\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [D:\QQ\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [D:\QQ\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[PID: 236 / maondodo][D:\QQ\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
    [D:\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 784 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 824 / SYSTEM][C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe]  [TOSHIBA CORPORATION, 3, 0, 0, 12]
    [C:\Program Files\TOSHIBA\ConfigFree\NDSAPI.dll]  [TOSHIBA CORPORATION, 4, 0, 2, 420]
    [C:\Program Files\TOSHIBA\ConfigFree\IpAdrSet.dll]  [TOSHIBA CORPORATION, 3, 0, 0, 5]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 972 / SYSTEM][C:\WINDOWS\System32\DVDRAMSV.exe]  [Matsushita Electric Industrial Co., Ltd., 2, 0, 7, 0]
[PID: 1168 / SYSTEM][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe]  [Analog Devices, Inc., 3, 2, 6, 0]
[PID: 2376 / SYSTEM][C:\Program Files\iPod\bin\iPodService.exe]  [Apple Inc., 7.3.1.3]
    [C:\Program Files\iPod\bin\iPodService.Resources\zh_CN.lproj\iPodServiceLocalized.DLL]  [Apple Inc., 7.3.0.54]
    [C:\Program Files\iPod\bin\iPodService.Resources\iPodService.DLL]  [Apple Inc., 7.3.1.3]
[PID: 3184 / maondodo][D:\Maxthon\Maxthon.exe]  [Maxthon International Ltd., 1, 6, 2, 60]
    [D:\Maxthon\maxzlib.dll]  [ , 1, 0, 0, 2]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
    [C:\WINDOWS\System32\shdocvw32.dll]  [Microsoft Corporation, 6.00.3790.2783 ]
    [D:\Maxthon\Plugin\FloatBar\FloatBar.dll]  [, 1, 9, 0, 0]
    [C:\WINDOWS\System32\odbcbcp.dll]  [Microsoft Corporation, 2000.081.9041.040]
    [C:\WINDOWS\System32\mscoree.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\perfcounter.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CorperfmonExt.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
    [c:\program files\kaspersky lab\kaspersky internet security 6.0\params.ppl]  [Kaspersky Lab, 6.0.0.299]
    [c:\program files\kaspersky lab\kaspersky internet security 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [c:\program files\kaspersky lab\kaspersky internet security 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
gototop
 

[D:\Maxthon\Services\RealTime\real_time.dll]  [, 1, 0, 0, 1]
    [c:\program files\kaspersky lab\kaspersky internet security 6.0\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
    [c:\program files\kaspersky lab\kaspersky internet security 6.0\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9d.ocx]  [Adobe Systems, Inc., 9,0,47,0]
[PID: 3188 / maondodo][D:\Maxthon\Maxthon.exe]  [Maxthon International Ltd., 1, 6, 2, 60]
    [D:\Maxthon\maxzlib.dll]  [ , 1, 0, 0, 2]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
    [C:\WINDOWS\System32\shdocvw32.dll]  [Microsoft Corporation, 6.00.3790.2783 ]
    [D:\Maxthon\Plugin\FloatBar\FloatBar.dll]  [, 1, 9, 0, 0]
    [C:\WINDOWS\System32\odbcbcp.dll]  [Microsoft Corporation, 2000.081.9041.040]
    [C:\WINDOWS\System32\mscoree.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\perfcounter.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CorperfmonExt.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll]  [Microsoft Corporation, 1.1.4322.573]
    [D:\Maxthon\Services\RealTime\real_time.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
    [c:\program files\kaspersky lab\kaspersky internet security 6.0\params.ppl]  [Kaspersky Lab, 6.0.0.299]
    [c:\program files\kaspersky lab\kaspersky internet security 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [c:\program files\kaspersky lab\kaspersky internet security 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
    [c:\program files\kaspersky lab\kaspersky internet security 6.0\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
    [c:\program files\kaspersky lab\kaspersky internet security 6.0\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 4000 / maondodo][C:\WINDOWS\notepad.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
[PID: 3936 / maondodo][E:\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\安全卫士\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.11 30May03]
    [E:\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 544, C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\PMPROXY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 544, C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\PMPROXY.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 556, C:\WINDOWS\SYSTEM32\00THOTKEY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 556, C:\WINDOWS\SYSTEM32\00THOTKEY.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 332, C:\WINDOWS\LTSMMSG.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 332, C:\WINDOWS\LTSMMSG.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1672, C:\WINDOWS\SYSTEM32\TFNF5.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1672, C:\WINDOWS\SYSTEM32\TFNF5.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1688, C:\PROGRAM FILES\TOSHIBA\TOSHIBA CONTROLS\TFNCKY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1688, C:\PROGRAM FILES\TOSHIBA\TOSHIBA CONTROLS\TFNCKY.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1700, C:\PROGRAM FILES\TOSHIBA\TOUCHED\TOUCHED.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1700, C:\PROGRAM FILES\TOSHIBA\TOUCHED\TOUCHED.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1708, C:\WINDOWS\SYSTEM32\EZSP_PX.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1708, C:\WINDOWS\SYSTEM32\EZSP_PX.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1716, C:\PROGRAM FILES\TOSHIBA\WIRELESS HOTKEY\TOSHKCW.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1716, C:\PROGRAM FILES\TOSHIBA\WIRELESS HOTKEY\TOSHKCW.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1724, C:\WINDOWS\SYSTEM32\TPSMAIN.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1724, C:\WINDOWS\SYSTEM32\TPSMAIN.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1768, C:\安全卫士\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1768, C:\安全卫士\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1892, C:\PROGRAM FILES\TOSHIBA\TOSCDSPD\TOSCDSPD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1892, C:\PROGRAM FILES\TOSHIBA\TOSCDSPD\TOSCDSPD.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1960, C:\WINDOWS\SYSTEM32\TPSBATTM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1960, C:\WINDOWS\SYSTEM32\TPSBATTM.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1956, C:\WINDOWS\SYSTEM32\RAMASST.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1956, C:\WINDOWS\SYSTEM32\RAMASST.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2020, D:\QQ\QQ.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2020, D:\QQ\QQ.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 236, D:\QQ\TIMPLATFORM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 236, D:\QQ\TIMPLATFORM.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3184, D:\MAXTHON\MAXTHON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3184, D:\MAXTHON\MAXTHON.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3188, D:\MAXTHON\MAXTHON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3188, D:\MAXTHON\MAXTHON.EXE]

==================================
API HOOK
RVA  错误: LoadLibraryA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\System32\drivers\klif.sys)
RVA  错误: LoadLibraryExA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\System32\drivers\klif.sys)
RVA  错误: LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\System32\drivers\klif.sys)
RVA  错误: LoadLibraryW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\System32\drivers\klif.sys)
RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\System32\drivers\klif.sys)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

该用户帖子内容已被屏蔽
gototop
 

楼主想说明什么?发这么大页的日记报告,中病毒了,就杀杀毒,首推2008版的瑞星。
gototop
 

我可懒得自己动手去杀,都把这些交给瑞星就能搞定了
gototop
 

支持一下,瑞星的东西比其他的好用了,安全放心,不用担心误杀。
gototop
 

太多了啊,楼主也下载使用个瑞星吧,就不会感染上那么多病毒了。
gototop
 

这些东西实在太专业了,我可不懂,反正中毒了我就用瑞星来杀
gototop
 

启动项里还有坏东西,删了
<DiskMan32><C:\WINDOWS\DiskMan32.exe> [N/A]
<ravmsmon><C:\Program Files\NetMeeting\ravmsmon.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{ACADABAF-1000-0010-8000-10AA006D2EA4}><C:\WINDOWS\System32\system.dat> [N/A]
驱动里面
[uoiwcn / uoiwcn6][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\uoiwcn6.sys><N/A>
[vt65y / vt65y][Stopped/Auto Start]
<\??\C:\WINDOWS\System32\drivers\vt65y.sys><N/A>
(如果认识就不要删)

删除文件:
C:\WINDOWS\DiskMan32.exe
C:\Program Files\NetMeeting\ravmsmon.exe
C:\WINDOWS\System32\system.dat
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT