瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】SRE日志请帮忙分析一下,查出病毒但杀不掉

1   1  /  1  页   跳转

【求助】SRE日志请帮忙分析一下,查出病毒但杀不掉

【求助】SRE日志请帮忙分析一下,查出病毒但杀不掉

今天杀毒发现了很多木马病毒大多都杀了,但有个kdjs1/2/3/5/6/7/9.exe在C:/WINDOWS/SYSTEM32反复出现,还有两个是在临时文件夹中wm0328[1].exe和wmsj0328[1].exe能查出来但删不掉,用强制删除去找不到文件,郁闷死了~~~~~~~~~
下面是SRE日志请帮忙分析一下,非常感谢!!!!!!!!


[CODE]

2007-03-31,18:34:58

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
    <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <RfwMain><"d:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <KernelFaultCheck><; %systemroot%\system32\dumprep 0 -k>  [N/A]
    <BigDogPath><C:\WINDOWS\VM_STI.EXE USB PC Camera 301P>  [N/A]
    <RavTask><"d:\Program Files\rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <twister><"D:\Program Files\Filseclab\Twister\twister.exe" -a>  [Filseclab Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <RavStub><"d:\Program Files\rising\Rav\ravstub.exe" /RUNONCE>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\UserInit.exe,>  [(Verified)Microsoft Windows Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]

最后编辑2007-03-31 19:25:19
分享到:
gototop
 

==================================
启动文件夹
[费尔消息服务]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\费尔消息服务.lnk --> C:\PROGRA~1\COMMON~1\FILSEC~1\FilMsg.exe [费尔安全实验室]><N>

==================================
服务
[8A565E68 / 8A565E68][Stopped/Auto Start]
  <C:\WINDOWS\system32\8A565E68.EXE -service><Microsoft Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  <d:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
  <d:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"d:\Program Files\rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"d:\Program Files\rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Print Spooler / Spooler][Stopped/Disabled]
  <><N/A>

==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[Apaidi / Apaidi][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\Apaidi.sys><N/A>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[bootdrv / bootdrv][Stopped/Boot Start]
  <\SystemRoot\System32\Drivers\bootdrv.sys><N/A>
[ExpScaner / ExpScaner][Running/Auto Start]
  <\??\d:\Program Files\rising\Rav\ExpScan.sys><>
[Filseclab Dynamic Defense System Driver / filar][Running/System Start]
  <\??\C:\PROGRA~1\COMMON~1\FILSEC~1\filar.sys><Filseclab Corporation>
[HOOKAPI / HOOKAPI][Stopped/Manual Start]
  <\??\D:\PROGRAM FILES\RISING\RAV\HookApi.Sys><瑞星软件有限公司>
[HookCont / HookCont][Running/Auto Start]
  <\??\d:\Program Files\rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
  <\??\d:\Program Files\rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
  <\??\d:\Program Files\rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl][Running/Auto Start]
  <\??\d:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[IMMDRV / IMMDRV][Running/Manual Start]
  <\??\D:\PROGRA~1\FILSEC~1\Twister\immdrv.sys><Filseclab Corp.>
[IsDrv120 / IsDrv120][Running/System Start]
  <\SystemRoot\System32\Drivers\IsDrv120.sys><N/A>
[kmsinput / kmsinput][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[MEMSCAN / MEMSCAN][Running/Auto Start]
  <\??\d:\Program Files\rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs][Running/Auto Start]
  <\??\d:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[New0 / New0][Stopped/Auto Start]
  <\??\C:\WINDOWS\system32\new.sys><N/A>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[oreans32 / oreans32][Stopped/System Start]
  <\??\C:\WINDOWS\system32\drivers\oreans32.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsFwDrv / RsFwDrv][Running/Auto Start]
  <\??\d:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
  <\??\d:\Program Files\rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start]
  <system32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[sptd / sptd][Running/Boot Start]
  <\SystemRoot\System32\Drivers\sptd.sys><N/A>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[USB PC Camera 301P / ZSMC301b][Stopped/Manual Start]
  <System32\Drivers\usbVM31b.sys><VM>
gototop
 

==================================
启动文件夹
[费尔消息服务]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\费尔消息服务.lnk --> C:\PROGRA~1\COMMON~1\FILSEC~1\FilMsg.exe [费尔安全实验室]><N>

==================================
服务
[8A565E68 / 8A565E68][Stopped/Auto Start]
  <C:\WINDOWS\system32\8A565E68.EXE -service><Microsoft Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  <d:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
  <d:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"d:\Program Files\rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"d:\Program Files\rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Print Spooler / Spooler][Stopped/Disabled]
  <><N/A>

==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[Apaidi / Apaidi][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\Apaidi.sys><N/A>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[bootdrv / bootdrv][Stopped/Boot Start]
  <\SystemRoot\System32\Drivers\bootdrv.sys><N/A>
[ExpScaner / ExpScaner][Running/Auto Start]
  <\??\d:\Program Files\rising\Rav\ExpScan.sys><>
[Filseclab Dynamic Defense System Driver / filar][Running/System Start]
  <\??\C:\PROGRA~1\COMMON~1\FILSEC~1\filar.sys><Filseclab Corporation>
[HOOKAPI / HOOKAPI][Stopped/Manual Start]
  <\??\D:\PROGRAM FILES\RISING\RAV\HookApi.Sys><瑞星软件有限公司>
[HookCont / HookCont][Running/Auto Start]
  <\??\d:\Program Files\rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
  <\??\d:\Program Files\rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
  <\??\d:\Program Files\rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl][Running/Auto Start]
  <\??\d:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[IMMDRV / IMMDRV][Running/Manual Start]
  <\??\D:\PROGRA~1\FILSEC~1\Twister\immdrv.sys><Filseclab Corp.>
[IsDrv120 / IsDrv120][Running/System Start]
  <\SystemRoot\System32\Drivers\IsDrv120.sys><N/A>
[kmsinput / kmsinput][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[MEMSCAN / MEMSCAN][Running/Auto Start]
  <\??\d:\Program Files\rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs][Running/Auto Start]
  <\??\d:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[New0 / New0][Stopped/Auto Start]
  <\??\C:\WINDOWS\system32\new.sys><N/A>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[oreans32 / oreans32][Stopped/System Start]
  <\??\C:\WINDOWS\system32\drivers\oreans32.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsFwDrv / RsFwDrv][Running/Auto Start]
  <\??\d:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
  <\??\d:\Program Files\rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start]
  <system32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[sptd / sptd][Running/Boot Start]
  <\SystemRoot\System32\Drivers\sptd.sys><N/A>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[USB PC Camera 301P / ZSMC301b][Stopped/Manual Start]
  <System32\Drivers\usbVM31b.sys><VM>

==================================
gototop
 

==================================
浏览器加载项
[QQCycloneHelper Class]
  {00000000-12C9-4305-82F9-43058F20E8D2} <d:\Program Files\Tencent\QQDownload\QQIEHelper02.dll, 腾讯公司>
[WebThunder Browser Helper]
  {00000AAA-A363-466E-BEF5-9BB68697AA7F} <d:\Program Files\Thunder Network\WebThunder\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[启动迅雷]
  {0062C9BD-B349-40DE-91A0-755F37ACD559} <d:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[启动Web迅雷]
  {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <D:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[金山快译(&K)]
  {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <C:\Program Files\Common Files\Kingsoft\Extract\AddIns\IEBand.dll, 金山软件股份有限公司>
[photo_uploader Control]
  {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <d:\PROGRA~1\PHOTO_~1\PHOTO_~1.OCX, >
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[PasswordEditCtrl Class]
  {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[QQCycloneHelper Class]
  {00000000-12C9-4305-82F9-43058F20E8D2} <d:\Program Files\Tencent\QQDownload\QQIEHelper02.dll, 腾讯公司>
[WebThunder Browser Helper]
  {00000AAA-A363-466E-BEF5-9BB68697AA7F} <d:\Program Files\Thunder Network\WebThunder\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
[金山快译(&K)]
  {6C3797D2-3FEF-4CD4-B654-D3AE55B4128C} <C:\Program Files\Common Files\Kingsoft\Extract\AddIns\IEBand.dll, 金山软件股份有限公司>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[&使用超级旋风下载]
  <d:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
[&使用超级旋风下载全部链接]
  <d:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
[&使用迅雷下载]
  <d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
  <D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用Web迅雷下载]
  <d:\Program Files\Thunder Network\WebThunder\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
  <d:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[导出当前页到超星阅览器(&A)]
  <d:\Program Files\SSREADER36\ss_all.htm, N/A>
[导出选中部分到超星阅览器(&S)]
  <d:\Program Files\SSREADER36\ss_select.htm, N/A>

==================================
正在运行的进程
[PID: 488][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 556][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 580][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\8A565E68.DLL]  [Microsoft Corporation, ]
[PID: 628][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 640][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 792][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1428][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\WINDOWS\system32\8A565E68.DLL]  [Microsoft Corporation, ]
    [C:\PROGRA~1\WINDOW~2\wmpband.dll]  [Microsoft Corporation, 9.00.00.3250]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [d:\Program Files\Thunder Network\WebThunder\WebThunderBHO_016.dll]  [Thunder Networking Technologies,LTD, 6, 0, 0, 5]
    [d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [D:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
[PID: 1756][d:\program files\rising\rfw\RfwMain.exe]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 48]
    [d:\program files\rising\rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 23]
    [d:\program files\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [d:\program files\rising\rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 448][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3018]
[PID: 704][C:\WINDOWS\VM_STI.EXE]  [VM., 4.2.610.4]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
[PID: 688][D:\Program Files\Filseclab\Twister\twister.exe]  [Filseclab Corporation, 7, 0, 3, 21929]
    [D:\Program Files\Filseclab\Twister\Twshlext.DLL]  [Filseclab Corp., 2, 0, 1, 988]
    [D:\Program Files\Filseclab\Twister\Quarantine.dll]  [Filseclab Corp., 2, 0, 0, 581]
    [D:\Program Files\Filseclab\Twister\W32Tools.dll]  [Filseclab Corp., 1, 0, 2, 1772]
    [D:\Program Files\Filseclab\Twister\virsubm.dll]  [Filseclab Corp., 2, 0, 2, 496]
    [D:\Program Files\Filseclab\Twister\psmgr.dll]  [Filseclab Corp., 1, 0, 1, 1071]
    [D:\Program Files\Filseclab\Twister\zipexp.dll]  [Filseclab Corp., 1, 0, 1, 164]
    [D:\Program Files\Filseclab\Twister\emlib.dll]  [Filseclab Corp., 1, 0, 2, 1250]
    [D:\Program Files\Filseclab\Twister\ctools.dll]  [Filseclab Corp., 1, 0, 0, 19]
    [D:\Program Files\Filseclab\Twister\Regpro.dll]  [Filseclab Corp., 2, 0, 1, 1236]
    [D:\Program Files\Filseclab\Twister\twsupdate.dll]  [Filseclab Corp., 1, 0, 1, 499]
    [D:\Program Files\Filseclab\Twister\FAPIConv.dll]  [Filseclab Corp., 1, 0, 0, 45]
    [D:\Program Files\Filseclab\Twister\mdcoder.dll]  [Filseclab Corp., 1, 0, 0, 21]
    [D:\Program Files\Filseclab\Twister\Schedule.dll]  [Filseclab Corp., 1, 0, 1, 32]
    [D:\Program Files\Filseclab\Twister\lsf.dll]  [Filseclab Corp., 1, 0, 1, 280]
    [D:\Program Files\Filseclab\Twister\falgorit.dll]  [Filseclab Corp., 1, 0, 0, 446]
    [D:\Program Files\Filseclab\Twister\message.dll]  [Filseclab Corp., 1, 0, 1, 1598]
    [D:\Program Files\Filseclab\Twister\fgui.dll]  [Filseclab Corp., 1, 0, 1, 128]
    [D:\Program Files\Filseclab\Twister\kdf.dll]  [Filseclab Corp., 1, 0, 3, 1019]
    [D:\Program Files\Filseclab\Twister\Decexp.dll]  [Filseclab Corp., 2, 0, 2, 1940]
    [D:\Program Files\Filseclab\Twister\Unchm.dll]  [Filseclab Corp., 1, 0, 2, 114]
    [D:\Program Files\Filseclab\Twister\unrar.dll]  [N/A, ]
    [D:\Program Files\Filseclab\Twister\unemb.dll]  [Filseclab Corp., 2, 0, 2, 528]
    [D:\Program Files\Filseclab\Twister\unsevzip.dll]  [Filseclab Corp., 1, 0, 1, 95]
    [D:\Program Files\Filseclab\Twister\unmisc.dll]  [Filseclab Corp., 1, 0, 1, 211]
    [D:\Program Files\Filseclab\Twister\AntiRK.dll]  [Filseclab Corporation, 2, 0, 0, 2132]
    [D:\Program Files\Filseclab\Twister\filvss.dll]  [Filseclab Corporation, 2, 0, 0, 816]
    [D:\Program Files\Filseclab\Twister\tsc.dll]  [Filseclab Corp., 1, 0, 1, 71]
    [D:\Program Files\Filseclab\Twister\filau.dll]  [Filseclab, 1, 0, 0, 10]
    [D:\Program Files\Filseclab\Twister\unzip32.dll]  [Info-ZIP, 5.52]
    [D:\Program Files\Filseclab\Twister\unacev2.dll]  [N/A, ]
    [D:\Program Files\Filseclab\Twister\filvss.cn]  [Filseclab Corporation, 2, 0, 0, 817]
    [D:\Program Files\Filseclab\Twister\AntiRK.cn]  [Filseclab Corporation, 2, 0, 0, 2133]
    [D:\Program Files\Filseclab\Twister\plus.dll]  [Filseclab Corporation, 2.0.502.1050]
[PID: 892][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1568][C:\Program Files\Common Files\Filseclab\FilMsg.exe]  [费尔安全实验室, 4, 0, 0, 985]
    [C:\Program Files\Common Files\Filseclab\twsupdate.dll]  [Filseclab Corp., 1, 0, 1, 497]
    [C:\Program Files\Common Files\Filseclab\W32Tools.dll]  [Filseclab Corp., 1, 0, 2, 1642]
    [C:\Program Files\Common Files\Filseclab\FAPIConv.dll]  [Filseclab Corp., 1, 0, 0, 45]
    [C:\Program Files\Common Files\Filseclab\mdcoder.dll]  [Filseclab Corp., 1, 0, 0, 21]
[PID: 2928][D:\sreng\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
gototop
 

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost
127.0.0.1      mmm.caifu18.net
127.0.0.1      www.18dmm.com
127.0.0.1      d.qbbd.com
127.0.0.1      www.5117music.com
127.0.0.1      www.union123.com
127.0.0.1      www.wu7x.cn
127.0.0.1      www.54699.com
127.0.0.1      60.169.0.66
127.0.0.1      60.169.1.29
127.0.0.1      www.97725.com
127.0.0.1      down.97725.com
127.0.0.1      ip.315hack.com
127.0.0.1      ip.54liumang.com
127.0.0.1      www.41ip.com
127.0.0.1      xulao.com
127.0.0.1      www.heixiou.com
127.0.0.1      www.9cyy.com
127.0.0.1      www.hunll.com
127.0.0.1      www.down.hunll.com
127.0.0.1      do.77276.com
127.0.0.1      www.baidulink.com
127.0.0.1      adnx.yygou.cn
127.0.0.1      222.73.220.45
127.0.0.1      www.f5game.com
127.0.0.1      www.guazhan.cn
127.0.0.1      wm,103715.com
127.0.0.1      www.my6688.cn
127.0.0.1      i.96981.com
127.0.0.1      d.77276.com
127.0.0.1      www1.cw988.cn
127.0.0.1      cool.47555.com
127.0.0.1      www.asdwc.com
127.0.0.1      55880.cn

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

麻烦把以下文件压缩传给我 我的QQ:397005089
C:\WINDOWS\system32\8A565E68.EXE
C:\WINDOWS\system32\8A565E68.DLL
==========================================================================================
1. 杀毒前关闭系统还原(Win2000系统可以忽略):右键 我的电脑 ,属性,系统还原,在所有驱动器上关闭系统还原 打勾即可。 
清除IE的临时文件:打开IE 点工具-->Internet选项 : Internet临时文件,点“删除文件”按钮 ,将 删除所有脱机内容 打勾,点确定删除。

关闭QQ等应用程序。进行如下操作前,请不要进行任何双击打开磁盘的操作。哈哈``中的跟裸的一样
==========================================================================================
用IceSword(中文名字叫冰刃):打开IceSword.exe然后按上面的 “文件”然后点 “设置” 然后勾选“禁止进线程创建”和“禁止协件功能”然后点 确定。
点冰刃最下面的文件找到以下项目删除:
C:\WINDOWS\system32\8A565E68.DLL
C:\WINDOWS\system32\new.sys
C:\WINDOWS\system32\8A565E68.EXE
C:\WINDOWS\\System32\Drivers\bootdrv.sys
C:\WINDOWS\system32\drivers\Apaidi.sys
C:\WINDOWS\System32\Drivers\IsDrv120.sys
==========================================================================================
重启计算机 然后再进入安全模式执行如下的操作(重启电脑 连续按F8 选择第一项 安全模式)
==========================================================================================
在SERng中 点 启动项目 --> 服务 --> Win32服务应用程序 进入后(勾选 隐藏已认证的微软项目),用鼠标左键在对应要修复的项上单击 然后点“删除服务”,再点“设置”按钮即可(注意到最后弹出的窗口中要点 “NO 否”才是确认删除服务。)
删除如下项目:
[8A565E68 / 8A565E68][Stopped/Auto Start]
<C:\WINDOWS\system32\8A565E68.EXE -service><Microsoft Corporation>
[Print Spooler / Spooler][Stopped/Disabled]
<><N/A>
==========================================================================================
在SERng中 点 启动项目 --> 服务 --> 驱动程序 进入后 (勾选 隐藏已认证的微软项目),用鼠标左键在对应要修复的项上单击 然后点“设置” 按钮即可(注意到最后弹出的窗口中要点 “NO 否”才是确认删除驱动。)[注:有关可疑驱动如果你不知道的话建议删除,不删除可疑把类型设置为disabled 文件也就不用删除。删除后不能正常工作,本人不负任何责任!]
删除如下项目:
[bootdrv / bootdrv][Stopped/Boot Start]
<\SystemRoot\System32\Drivers\bootdrv.sys><N/A>
[Apaidi / Apaidi][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\Apaidi.sys><N/A>
[IsDrv120 / IsDrv120][Running/System Start]
<\SystemRoot\System32\Drivers\IsDrv120.sys><N/A>
[New0 / New0][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\new.sys><N/A>

==========================================================================================
在SREng中 点系统修复 --> 点Windows Shell/IE 勾全选,点“修复”
在SREng中 点系统修复 --> 点HOSTS 文件 按重设

==========================================================================================
好了 最后在安全模式用 WINDOWS 清理助手、恶意软件清理助手、360安全卫士
==========================================================================================
WINDOWS 清理助手
使用方法:
运行ArSwp.exe,然后按立即清理,扫描完毕后就按清理 建议全部清理
==========================================================================================
恶意软件清理助手
使用方法:
运行RogueCleaner.exe,然后按检测恶意软件,扫描完毕后按清理选中的项目 建议全部清理
=========================================================================================
360安全卫士  (如果运行安装文件没有反映 请用修复工具修复后再运行安装文件)
使用方法:
安装后,运行360安全卫士,然后按查杀恶意软件-》开始扫描 扫描完毕后就按立即清理 建议全部清理==========================================================================================
好了,现在重启 回来正常模式 重新扫日志给我看``
==========================================================================================
友情提醒:
1. 建议通过Windows Update安装好系统补丁程序(下不了补丁的用户可以用XP的换号器进行换号)
2. 给系统管理员帐户设置足够复杂的管理员密码,最好是10位以上,字母+数字+其它符号
3. 禁用自动播放,用U盘时候,不要双击打开,用右键打开
4. 安装杀毒软件和防火墙 (有很多人都不用,那只会令一些病毒、蠕虫、木马等在你家的电脑上开Party)
5. 第5个也是最重要的一个 就是养好上网习惯  养成上网好习惯 远离病毒烦恼!!

                                                                        分析:無毒侑禮
                                                                        时间:2007-3-31
                                                                          QQ:397005089
gototop
 

WINDOWS 清理助手: 官方下载地址:http://www.arswp.com/download/arswp/arswp.rar

使用方法:
运行ArSwp.exe,然后按立即清理,扫描完毕后就按清理 建议全部清理

恶意软件清理助手  霏凡下载地址:http://www.crsky.com/soft/6251.html

使用方法:
运行RogueCleaner.exe,然后按检测恶意软件,扫描完毕后按清理选中的项目 建议全部清理

360安全卫士  官方下载地址:http://www.360safe.com/download.html

使用方法:
安装后,运行360安全卫士,然后按查杀恶意软件-》开始扫描 扫描完毕后就按立即清理 建议全部清理
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT