瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求轩辕小聪哥哥帮助!!!!!!急急急急急急!!!!

1   1  /  1  页   跳转

求轩辕小聪哥哥帮助!!!!!!急急急急急急!!!!

求轩辕小聪哥哥帮助!!!!!!急急急急急急!!!!

我的机器上次中的trojan.dl.small.ixk在您的指点下成功删除了!!
但是今天又提示发现这个病毒 还改了个路径上次在C:WINDOWS\SYSTEM32里面
现在跑到C:\system volume information\_restore这个地方了 杀毒软件每发现一次病毒文件名都不一样 都是A022XXX.dll一系列数字  我把autoruns.exe报告粘贴上去麻烦您给看一下 不甚感激啊!!!!!!!!!帮帮我
最后编辑2006-05-23 20:09:27
分享到:
gototop
 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ NvCplDaemonNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll

+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.f:\rav\ravtask.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

+ SysTraysFile not found: CLSID\{590498A3-4131-4D8F-BA4B-36791A9803B1}\InprocServer32

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Delphi Context Menu Shell Extension Examplec:\windows\system32\bin\contmenu.dll

+ Desktop ExplorerNVIDIA Desktop Explorer, Version 61.77 NVIDIA Corporationc:\windows\system32\nvshell.dll

+ Desktop Explorer MenuNVIDIA Desktop Explorer, Version 61.77 NVIDIA Corporationc:\windows\system32\nvshell.dll

+ NvCpl DesktopContext ClassNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll

+ nView Desktop Context MenuNVIDIA Desktop Explorer, Version 61.77 NVIDIA Corporationc:\windows\system32\nvshell.dll

+ Play on my TV helperNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ TRS Shell ExtensionTRS Shell Extension DLLc:\windows\system32\trsshext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ CPub ObjectFile not found: C:\Downloads\mp3\P4P\sodaie.dll

+ IeCatch2 Classjccatch ModuleAmaze Softe:\program files\flashget\jccatch.dll

+ QQBrowserHelperObject ClassQQIEHelper Module深圳市腾讯计算机系统有限公司e:\qq\qqiehelper.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ BitComet工具栏BitComet Toolbar for IEe:\bt\bitcomet\bitcometbar\bitcometbar0.5.dll

HKCU\Software\Microsoft\Internet Explorer\Extensions

+ 发送到信息中心...c:\myeoffice\informationcenter\bin\ieext.js

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ &FlashGetFile not found: E:\PROGRA~1\FlashGet\flashget.exe

+ Yahoo 1G电邮File not found: http://cn.mail.yahoo.com/promo/rd1

+ 浩方对战平台浩方对战平台上海浩方在线信息技术有限公司e:\浩方\浩方对战平台\gameclient.exe

+ 情景聊天File not found: http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/

+ 上网助手File not found: http://assistant.3721.com/index.htm?fb=Cns

+ 手机短信File not found: http://sms.3721.com/ie/index.htm?pid=U_taijilian_48651

+ 腾讯QQQQTENCENTe:\qq\qq.exe

Task Scheduler

+ Symantec NetDetect.jobSymantec NetDetectSymantec Corporationc:\program files\symantec\liveupdate\ndetect.exe

HKLM\System\CurrentControlSet\Services

+ NVSvcProvides system and desktop level support to the NVIDIA display driverNVIDIA Corporationc:\windows\system32\nvsvc32.exe

+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.f:\rising\rfw\rfwsrv.exe

+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.f:\rav\ccenter.exe

+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.f:\rav\ravmond.exe

+ STI SimulatorFile not found: C:\WINDOWS\System32\PAStiSvc.exe

HKLM\System\CurrentControlSet\Services

+ ac97intcIntel(r) Integrated Controller Hub Audio DriverIntel Corporationc:\windows\system32\drivers\ac97intc.sys

+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\windows\system32\drivers\basetdi.sys

+ bmnadapterTAP-Win32 Virtual Network DriverThe OpenVPN Projectc:\windows\system32\drivers\bmnet.sys

+ CA561Universal Serial Bus Camera DriverSPc:\windows\system32\drivers\spca561.sys

+ cdawdmFile not found: system32\DRIVERS\CDAWDM.sys

+ cdnprotFile not found: system32\drivers\cdnprot.sys

+ d347busFile not found: system32\DRIVERS\d347bus.sys

+ d347prtSCSI miniport c:\windows\system32\drivers\d347prt.sys

+ E100BNDIS 5 driverIntel Corporationc:\windows\system32\drivers\e100b325.sys

+ EagleNTFile not found: C:\WINDOWS\system32\drivers\EagleNT.sys

+ ExpScanerExpScan.sysf:\rav\expscan.sys

+ HookContTDI HOOK DriverRising tech Co. ltdf:\rav\hookcont.sys

+ HookRegf:\rav\hookreg.sys

+ HookSysHooksysRisingf:\rav\hooksys.sys

+ HookUrlHookUrlBeijing Rising Technology Co., Ltd.f:\rising\rfw\hookurl.sys

+ kmsinputc:\windows\system32\drivers\kmsinput.sys

+ MEMSCANMemScan Driver瑞星软件有限公司f:\rav\memscan.sys

+ mProcRsRising Personal FireWall  mprocrs.sysBeijing Rising Technology Co., Ltd.f:\rising\rfw\mprocrs.sys

+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.e:\qq\npkcrypt.sys

+ npkycrypFile not found: E:\QQ\npkycryp.sys

+ NPPTNTnProtect NPSC Kernel Mode Driver for NTINCA Internet Co., Ltd.c:\windows\system32\npptnt.sys

+ NPPTNT2nProtect NPSC Kernel Mode Driver for NTINCA Internet Co., Ltd.c:\windows\system32\npptnt2.sys

+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 61.77 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys

+ nv4NVIDIA Compatible Windows 2000 Miniport Driver, Version 61.77 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys

+ PAC7311PA707UCMPixArt Imaging Inc.c:\windows\system32\drivers\pa707ucm.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys

+ RsFwDrvnt_fwdrvBeijing Rising Technology Co., Ltd.f:\rising\rfw\rsfwdrv.sys

+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys

+ SmartCdFile not found: System32\Drivers\SmartCd.sys

HKCU\Control Panel\Desktop\Scrnsave.exe

+ C:\WINDOWS\方圆之间.scrFlashSaver屏幕保护程序联想(北京)有限公司
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT