瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 一个难搞的病毒,喜欢病毒的来看看

12   1  /  2  页   跳转

一个难搞的病毒,喜欢病毒的来看看

一个难搞的病毒,喜欢病毒的来看看

我系统里中了rootkit.win32.vanti.e.木马,老是杀不死,在system32里自动生成了一个名为vq4up.dll的文件
在安全模式下删过,但重启后又有了
中了此木马的表现为,启动不了杀毒软件,用windows里的自带DOS里的内部命令时会自己关闭DOS,用过瑞星,金山,卡巴能查出来,但杀不死

我也在网上找个关于这个木马的资料,但他们中的和我中的不太一样,我在安全模式下把注册表里的关于这个的都删了,木马文件也删了的,但重启都会在c:\windows\system32\vq4up.dll又重新创建一个出来,进程里也没有此木马进程
最后编辑2005-11-13 23:48:55
分享到:
gototop
 

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <load><>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <run><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <SKYNET Personal FireWall><D:\Program Files soft\SkyNet\FireWall\pfw.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
  <INET><C:\WINDOWS\System32\INETSRV\inetsync.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <Userinit><C:\WINDOWS\System32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <AppInit_DLLs><>

==================================
启动文件夹
服务
[Apache / Apache]
  <"D:\usr\local\apache\Apache.exe" --ntservice><N/A>
[Gray_Pigeon_Server / GrayPigeonServer]
  <><N/A>
[kavsvc / kavsvc]
  <"d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe"><Kaspersky Lab>
[Macromedia Licensing Service / Macromedia Licensing Service]
  <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[Microsoft Webserver / Microsoft Webserver]
  <C:\WINDOWS\Microsoft Webserver.exe><N/A>
[MySQL / MySQL]
  <D:\usr\local\mysql\bin\mysqld-nt.exe MySQL><N/A>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd]
  <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><N/A>
[Universal Disk Manager / Universal Disk Manager]
  <><N/A>

==================================
浏览器加载项
[AntiFish Class]
  <C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll>
[QQ]
  <D:\Program Files soft\Tencent\qq\QQ.EXE>
[QQIEFloatBarCfgCmd Class]
  <D:\Program Files soft\Tencent\qq\QQIEHelper.dll>
[电台(&R)]
  <C:\WINDOWS\System32\msdxm.ocx>
[雅虎助手]
  <C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll>
[]
  <C:\WINDOWS\Downloaded Program Files\MediaGatewayX.dll>
[&使用迅雷下载]
  <D:\Program Files soft\Thunder Network\Thunder\geturl.htm>
[&使用迅雷下载全部链接]
  <D:\Program Files soft\Thunder Network\Thunder\getAllurl.htm>
[上传到QQ网络硬盘]
  <D:\Program Files soft\Tencent\qq\AddToNetDisk.htm>
[使用网际快车下载]
  <D:\Program Files soft\FlashGet\jc_link.htm>
[使用网际快车下载全部链接]
  <D:\Program Files soft\FlashGet\jc_all.htm>
[添加到QQ自定义面板]
  <D:\Program Files soft\Tencent\qq\AddPanel.htm>
[添加到QQ表情]
  <D:\Program Files soft\Tencent\qq\AddEmotion.htm>
[用QQ彩信发送该图片]
  <D:\Program Files soft\Tencent\qq\SendMMS.htm>
gototop
 

==================================
正在运行的进程
[PID: 532][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 588][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 612][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 656][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 668][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 836][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 896][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 972][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 988][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1144][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)>
[PID: 1268][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1308][C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe]  <Microsoft Corporation><7.10.3077>
[PID: 1432][C:\WINDOWS\System32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 1932][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\System32\igfxpph.dll]  <Intel Corporation><3.0.0.2209>
    [C:\WINDOWS\System32\hccutils.DLL]  <Intel Corporation><3.0.0.2209>
    [C:\WINDOWS\System32\igfxres.dll]  <Intel Corporation><3.0.0.2209>
    [C:\WINDOWS\System32\igfxsrvc.dll]  <Intel Corporation><3.0.0.2209>
    [C:\WINDOWS\System32\igfxdev.dll]  <Intel Corporation><3.0.0.2209>
[PID: 276][D:\Program Files soft\SkyNet\FireWall\pfw.exe]  <天网><2.7.3.1100>
    [D:\Program Files soft\SkyNet\FireWall\SKYMISC.DLL]  <N/A><N/A>
[PID: 284][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3249>
[PID: 296][C:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 456][D:\Program Files soft\宽带认证客户端\icclient.exe]  <DA Info><2.4.1.4>
    [C:\WINDOWS\System32\WPCAP.DLL]  <CACE Technologies><3, 1, 0, 27>
    [C:\WINDOWS\System32\packet.dll]  <CACE Technologies><3, 1, 0, 27>
    [C:\WINDOWS\System32\WanPacket.dll]  <CACE Technologies><3, 1, 0, 27>
[PID: 528][E:\games\天骥传世1.3\Mir2Tianji.exe]  <天骥传世脱机外辅><1.3.0.0>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\scrchpg.dll]  <Kaspersky Lab><5.0.1.18>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\scrch_ag.dll]  <Kaspersky Lab><5.0.372.1>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\FSSync.dll]  <Kaspersky Lab><5.0.372.0>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\pr_rmt.dll]  <Kaspersky Lab><5.0.372.0>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\ccclient.dll]  <Kaspersky Lab><5.0.372.1>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\klipc.dll]  <Kaspersky Lab><5.0.372.0>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\KLUtil.dll]  <Kaspersky Lab><5.0.372.1>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\rpt.dll]  <Kaspersky Lab><5.0.372.2>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\CCIFACE.dll]  <Kaspersky Lab><5.0.372.1>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\prloader.dll]  <Kaspersky Lab><5.0.372.0>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\prkernel.ppl]  <Kaspersky Lab><5.0.372.0>
    [d:\program files soft\kaspersky lab\kaspersky anti-virus personal\prstring.ppl]  <Kaspersky Lab><5.0.372.0>
    [d:\program files soft\kaspersky lab\kaspersky anti-virus personal\pr_srv.ppl]  <Kaspersky Lab><5.0.372.0>
    [d:\program files soft\kaspersky lab\kaspersky anti-virus personal\pr_clnt.ppl]  <Kaspersky Lab><5.0.372.0>
    [E:\games\天骥传世1.3\Mir2Tianji.Dat]  <N/A><N/A>
    [E:\games\天骥传世1.3\Mir2Tianji.Dat]  <N/A><N/A>
[PID: 164][D:\Program Files soft\Tencent\qq\QQ.exe]  <TENCENT><14, 27, 0, 082>
    [D:\Program Files soft\Tencent\qq\QQBaseClassInDll.dll]  <N/A><1, 0, 0, 1>
    [D:\Program Files soft\Tencent\qq\QQHelperDll.dll]  <N/A><1, 0, 0, 1>
    [D:\Program Files soft\Tencent\qq\BasicCtrlDll.dll]  <Tencent><0, 3, 3, 6>
    [D:\Program Files soft\Tencent\qq\QQAPI.dll]  <N/A><1, 0, 0, 1>
    [D:\Program Files soft\Tencent\qq\TIMProxy.dll]  <tencent><0, 3, 2, 4>
    [D:\Program Files soft\Tencent\qq\LoginCtrl.dll]  <N/A><1, 0, 0, 1>
    [D:\Program Files soft\Tencent\qq\npkcntc.dll]  <INCA Internet Co., Ltd.><2005, 9, 1, 1>
    [D:\Program Files soft\Tencent\qq\npkpdb.dll]  <INCA Internet Co., Ltd.><2003, 10, 1, 1>
    [D:\Program Files soft\Tencent\qq\QQRes.dll]  <tencent><1, 0, 0, 1>
    [D:\Program Files soft\Tencent\qq\QQMainFrame.dll]  <N/A><N/A>
    [D:\Program Files soft\Tencent\qq\CQQApplication.dll]  <N/A><N/A>
    [D:\Program Files soft\Tencent\qq\NewSkin.dll]  <N/A><1, 0, 0, 1>
    [D:\Program Files soft\Tencent\qq\HostingMgr.dll]  <N/A><1, 0, 0, 1>
    [D:\Program Files soft\Tencent\qq\MailSummary.dll]  <N/A><1, 0, 0, 1>
    [D:\Program Files soft\Tencent\qq\QQSpace.dll]  <N/A><1, 0, 0, 1>
    [C:\WINDOWS\System32\msdmo.dll]  <N/A><N/A>
    [D:\Program Files soft\Tencent\qq\QQSysMsgMng.dll]  <N/A><N/A>
    [D:\Program Files soft\Tencent\qq\QQConfigPlugin.dll]  <N/A><1, 0, 0, 1>
    [D:\Program Files soft\Tencent\qq\UserDefinedHead.dll]  <N/A><1, 0, 0, 1>
    [D:\Program Files soft\Tencent\qq\QRingMng.dll]  <N/A><N/A>
    [D:\Program Files soft\Tencent\qq\PhoneAPI.dll]  <N/A><1, 0, 0, 1>
    [D:\Program Files soft\Tencent\qq\DialerAllinOne.dll]  <tencent><1, 4, 0, 0>
    [D:\Program Files soft\Tencent\qq\QQAllInOne.dll]  <N/A><N/A>
    [D:\Program Files soft\Tencent\qq\CameraDll.dll]  <N/A><1, 0, 0, 1>
    [D:\Program Files soft\Tencent\qq\SCCore.dll]  <N/A><N/A>
    [D:\Program Files soft\Tencent\qq\QQCustomFace.dll]  <N/A><N/A>
    [D:\Program Files soft\Tencent\qq\QQPet.dll]  <N/A><1, 0, 0, 1>
    [D:\Program Files soft\Tencent\qq\QQGroupMng.dll]  <N/A><1, 0, 0, 1>
    [D:\Program Files soft\Tencent\qq\LongConnection.dll]  <tencent><0, 3, 3, 8>
    [D:\Program Files soft\Tencent\qq\FlashAvatarDll.dll]  <N/A><1, 4, 0, 1>
    [C:\WINDOWS\System32\macromed\flash\Flash.ocx]  <Macromedia, Inc.><7,0,14,0>
    [D:\Program Files soft\Tencent\qq\QQMagicFace.dll]  <N/A><1, 0, 0, 1>
    [D:\Program Files soft\Tencent\qq\QQAvatar.dll]  <N/A><N/A>
    [D:\Program Files soft\Tencent\qq\QQSceneMng.dll]  <N/A><N/A>
    [D:\Program Files soft\Tencent\qq\GroupConnection.dll]  <Tencent><0, 3, 3, 5>
    [D:\Program Files soft\Tencent\qq\BQQApplication.dll]  <N/A><N/A>
    [D:\Program Files soft\Tencent\qq\QQPlugin.dll]  <N/A><N/A>
    [D:\Program Files soft\Tencent\qq\CommercesMng.dll]  <N/A><1, 0, 0, 1>
    [D:\Program Files soft\Tencent\qq\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [D:\Program Files soft\Tencent\qq\QQAddr.dll]  <深圳市腾讯计算机系统有限公司><4, 0, 200, 32>
    [D:\Program Files soft\Tencent\qq\ImageOle.dll]  <TODO: <Company name>><1.0.0.1>
    [D:\Program Files soft\Tencent\qq\QQPhoneHelper.dll]  <腾讯科技(深圳)有限公司><1, 0, 0, 26>
    [D:\Program Files soft\Tencent\qq\videodevice.dll]  <Tencent><1.5.0.0>
    [D:\Program Files soft\Tencent\qq\inplus.dll]  <Tencent><1.5.0.0>
    [C:\WINDOWS\System32\l3codeca.acm]  <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
    [D:\Program Files soft\Tencent\qq\QQZip.dll]  <tencent><0, 3, 2, 4>
[PID: 796][D:\Program Files soft\Tencent\qq\TIMPlatform.exe]  <tencent><0, 3, 1, 8>
    [D:\Program Files soft\Tencent\qq\TIMProxy.dll]  <tencent><0, 3, 2, 4>
    [E:\games\天骥传世1.3\Mir2Tianji.Dat]  <N/A><N/A>
[PID: 828][D:\Program Files soft\Tencent\TT\TTraveler.exe]  <腾讯公司><2, 2, 0, 224>
    [D:\Program Files soft\Tencent\TT\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
gototop
 

[d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\scrchpg.dll]  <Kaspersky Lab><5.0.1.18>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\scrch_ag.dll]  <Kaspersky Lab><5.0.372.1>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\FSSync.dll]  <Kaspersky Lab><5.0.372.0>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\pr_rmt.dll]  <Kaspersky Lab><5.0.372.0>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\ccclient.dll]  <Kaspersky Lab><5.0.372.1>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\klipc.dll]  <Kaspersky Lab><5.0.372.0>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\KLUtil.dll]  <Kaspersky Lab><5.0.372.1>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\rpt.dll]  <Kaspersky Lab><5.0.372.2>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\CCIFACE.dll]  <Kaspersky Lab><5.0.372.1>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\prloader.dll]  <Kaspersky Lab><5.0.372.0>
    [d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\prkernel.ppl]  <Kaspersky Lab><5.0.372.0>
    [d:\program files soft\kaspersky lab\kaspersky anti-virus personal\prstring.ppl]  <Kaspersky Lab><5.0.372.0>
    [d:\program files soft\kaspersky lab\kaspersky anti-virus personal\pr_srv.ppl]  <Kaspersky Lab><5.0.372.0>
    [d:\program files soft\kaspersky lab\kaspersky anti-virus personal\pr_clnt.ppl]  <Kaspersky Lab><5.0.372.0>
    [C:\WINDOWS\System32\macromed\flash\Flash.ocx]  <Macromedia, Inc.><7,0,14,0>
[PID: 1116][D:\Downloads\SREng.exe]  <Smallfrogs Studio><1.1.0.269>

==================================
文件关联
.TXT  OK. [C:\WINDOWS\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [C:\WINDOWS\System32\winhlp32.exe %1]
.INI  OK. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [C:\WINDOWS\System32\NOTEPAD.EXE %1]

==================================


帮忙看一下
gototop
 

用Hijackthis扫个日志传上来,
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
一楼的附件就是
gototop
 

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files soft\SkyNet\FireWall\pfw.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Program Files soft\宽带认证客户端\icclient.exe
E:\games\天骥传世1.3\Mir2Tianji.exe
E:\games\天骥传世1.3\Mir2Tianji.Dat
E:\games\天骥传世1.3\Mir2Tianji.Dat
D:\Program Files soft\Tencent\qq\QQ.exe
D:\Program Files soft\Tencent\qq\TIMPlatform.exe
E:\games\天骥传世1.3\Mir2Tianji.Dat
D:\Program Files soft\Tencent\TT\TTraveler.exe
D:\Downloads\2535952005811174944\HijackThis1991zww.exe

O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [SKYNET Personal FireWall] D:\Program Files soft\SkyNet\FireWall\pfw.exe
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - D:\Program Files soft\Thunder Network\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - D:\Program Files soft\Thunder Network\Thunder\getAllurl.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - D:\Program Files soft\Tencent\qq\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\Program Files soft\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - D:\Program Files soft\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\Program Files soft\Tencent\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\Program Files soft\Tencent\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\Program Files soft\Tencent\qq\SendMMS.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files soft\Tencent\qq\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files soft\Tencent\qq\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files soft\Tencent\qq\QQIEHelper.dll (file missing)
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files soft\Tencent\qq\QQIEHelper.dll (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O16 - DPF: v3cab - http://searchmiracle.com/cab/v3cab.cab
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c18.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab?refid=2663
O17 - HKLM\System\CCS\Services\Tcpip\..\{D81CCE44-F7B7-45F6-AC05-D7B0EFD833B4}: NameServer = 61.128.192.68
O18 - 列举现有的协议: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - NT 服务: kavsvc - Kaspersky Lab - d:\Program Files soft\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - NT 服务: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - NT 服务: Microsoft Webserver - Unknown owner - C:\WINDOWS\Microsoft Webserver.exe
O23 - NT 服务: MySQL - Unknown owner - D:\usr\local\mysql\bin\mysqld-nt.exe
O23 - NT 服务: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
gototop
 

Microsoft Webserver - Unknown owner - C:\WINDOWS\Microsoft Webserver.exe
干掉他
gototop
 

O23 - NT 服务: Microsoft Webserver - Unknown owner - C:\WINDOWS\Microsoft Webserver.exe灰鸽子
gototop
 

http://forum.ikaka.com/topic.asp?board=28&artid=5666824
看看Baohe的灰鸽子手工查杀方法,也许对你有帮助!
gototop
 

金山那里给你回复了。

还有KV……
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT