1   1  /  1  页   跳转

机器病毒,删除不了!

机器病毒,删除不了!

发现有1个启动项目,在启动项目里有个ELNORB。EXE文件,没次开机就执行。
在%profies%\localsettings\application data下有几个可以文件
CSRSS。EXE
INETINFO。EXE
LSASS。EXE
SERVICES。EXE
SMSS。EXE
WINLOGON。EXE
该ELONRB。EXE病毒,会把注册表禁止,把文件夹选象去除,没发看隐藏文件。
线把日志发上:
2006-07-25,08:27:46

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional  (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><D:\WINDOWS\System32\ctfmon.exe>  [Microsoft Corporation]
    <Tok-Cirrhatus><"D:\Documents and Settings\Administrator\Local Settings\Application Data\smss.exe">  [ ]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <RavTimer><D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE>  [Beijing Rising Technology Co., Ltd.]
    <RavMon><D:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM>  [Beijing Rising Technology Co., Ltd.]
    <Bron-Spizaetus><"D:\WINDOWS\ShellNew\ElnorB.exe">  [ ]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
    <Microsoft Windows Automatic Games Updater><msgame32.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><D:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <BF4P><; D:\WINDOWS\System32\bf4p.exe>  []
    <Bron-Spizaetus><; "D:\WINDOWS\ShellNew\ElnorB.exe">  [ ]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <CTFMON.EXE><; D:\WINDOWS\System32\CTFMON.EXE>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <Microsoft Windows Automatic Games Updater><; msgame32.exe>  []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <MSMSGS><; "D:\Program Files\Messenger\msmsgs.exe" /background>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <NMGameX_AutoRun><; D:\WINDOWS\System32\Rundll32.exe NMGameX.dll,LiveProcess /aa>  [NMGameX]
    <PHIME2002A><; D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <PHIME2002ASync><; D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
    <SysExplr><; C:\HEROSOFT\Hero3000\SYSEXPLR.EXE>  []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <Tok-Cirrhatus><; "D:\Documents and Settings\Administrator\Local Settings\Application Data\smss.exe">  [ ]

==================================
启动文件夹
[Empty]
  <D:\Documents and Settings\Administrator\「开始」菜单\程序\启动\Empty.pif><N>

==================================
服务
[IMAPI CD-Burning COM Service / ImapiService]
  <D:\WINDOWS\System32\imapi.exe><Microsoft Corporation>
[K4NV / K4NV]
  <"D:\WINDOWS\k4nv.exe"><N/A>
[LexBce Server / LexBceS]
  <D:\WINDOWS\system32\LEXBCES.EXE><Lexmark International, Inc.>
[Rising Process Communication Center / RsCCenter]
  <D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE><rising>
[RsRavMon Service / RsRavMon]
  <D:\PROGRAM FILES\RISING\RAV\Ravmond.exe><Beijing Rising Technology Co., Ltd.>

==================================
最后编辑2006-07-13 22:23:46
分享到:
gototop
 

浏览器加载项
[解霸]
  {367E0A21-8601-4986-9C9A-153BF5ACA118} <C:\HEROSOFT\Hero3000\MPLAYER.EXE, N/A>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <D:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <D:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>

==================================
正在运行的进程
[PID: 388][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 448][\??\D:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 472][\??\D:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [D:\WINDOWS\system32\tssoft32.acm]  <DSP GROUP, INC.><1.01>
    [D:\WINDOWS\system32\tsd32.dll]  <N/A><N/A>
    [D:\WINDOWS\system32\sl_anet.acm]  <Sipro Lab Telecom Inc.><3.02>
    [D:\WINDOWS\System32\iac25_32.ax]  <Intel Corporation><2.05.53>
    [D:\WINDOWS\System32\l3codeca.acm]  <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
[PID: 516][D:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 528][D:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 700][D:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 744][D:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 804][D:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 816][D:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 840][D:\PROGRAM FILES\RISING\RAV\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><17, 0, 1, 53>
    [D:\PROGRAM FILES\RISING\RAV\guidll.dll]  <rising><17, 0, 0, 13>
    [D:\PROGRAM FILES\RISING\RAV\RsCommX.dll]  <rising><17, 0, 0, 3>
    [D:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL]  <Rising Corp.><17, 0, 0, 7>
    [D:\PROGRAM FILES\RISING\RAV\CfgDll.dll]  <rising><17, 0, 0, 60>
    [D:\Program Files\rising\Rav\Scanner.dll]  <Rising><17, 0, 0, 43>
    [D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
    [D:\Program Files\rising\Rav\libload.dll]  <Rising><17, 0, 0, 14>
    [D:\Program Files\rising\Rav\VirusLib.dll]  <Rising><17, 0, 0, 26>
    [D:\PROGRAM FILES\RISING\RAV\MailMon.dll]  < ><17, 0, 0, 9>
    [D:\Program Files\rising\Rav\SpamEng.dll]  <N/A><17, 0, 0, 7>
    [D:\Program Files\rising\Rav\engine.dll]  <rising><17, 0, 0, 37>
    [D:\Program Files\rising\Rav\UnExe.dll]  <Rising><17, 0, 0, 25>
    [D:\PROGRAM FILES\RISING\RAV\MemMon.dll]  <北京瑞星><17, 8, 0, 0>
    [D:\Program Files\rising\Rav\ScanEx.dll]  <Rising><17, 0, 0, 33>
    [D:\PROGRAM FILES\RISING\RAV\expscan.dll]  <N/A><17, 0, 0, 6>
    [D:\Program Files\rising\Rav\PostTrt.dll]  <Rising><17, 0, 0, 15>
    [D:\Program Files\rising\Rav\NvFile.dll]  <瑞星><17, 0, 0, 13>
    [D:\PROGRAM FILES\RISING\RAV\mPorts.dll]  <Beijing Rising Technology Corporation Limited><3, 0, 0, 3>
    [D:\PROGRAM FILES\RISING\RAV\regmon.dll]  < ><17, 0, 0, 12>
    [D:\PROGRAM FILES\RISING\RAV\HookWeb.dll]  <rising><17, 0, 0, 4>
    [D:\Program Files\rising\Rav\ScanMac.dll]  <rising><17, 0, 0, 17>
    [D:\Program Files\rising\Rav\ScanSct.dll]  <rising><17, 0, 0, 27>
    [D:\Program Files\rising\Rav\ScanExec.dll]  <><17, 0, 0, 21>
    [D:\Program Files\rising\Rav\Unpacker.dll]  <rising><17, 0, 0, 19>
    [D:\Program Files\rising\Rav\ExtOLE.dll]  <rising><17, 0, 0, 19>
[PID: 856][D:\PROGRAM FILES\RISING\RAV\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 27>
    [D:\PROGRAM FILES\RISING\RAV\RsCommX.dll]  <rising><17, 0, 0, 3>
    [D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
[PID: 884][D:\WINDOWS\system32\LEXBCES.EXE]  <Lexmark International, Inc.><7.1>
    [D:\WINDOWS\system32\lexp2p32.dll]  <Lexmark International, Inc.><7.1>
    [D:\WINDOWS\system32\lex2kusb.dll]  <Lexmark International, Inc.><7.1>
[PID: 952][D:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)>
    [D:\WINDOWS\system32\LEXLMPM.DLL]  <Lexmark International, Inc.><7.1>
    [D:\WINDOWS\system32\LexBce.dll]  <Lexmark International, Inc.><7.1>
    [D:\WINDOWS\System32\spool\PRTPROCS\W32X86\LG12PP5C.dll]  <Lexmark International><1.0.7.2>
    [D:\WINDOWS\system32\lg12pwr.dll]  <Lexmark International, Inc.><1, 0, 1, 0>
[PID: 956][D:\WINDOWS\system32\LEXPPS.EXE]  <Lexmark International, Inc.><7.1>
    [D:\WINDOWS\system32\LEXBCE.DLL]  <Lexmark International, Inc.><7.1>
[PID: 1112][D:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1192][D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE]  <rising><17, 0, 0, 1>
[PID: 1424][D:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>
    [D:\WINDOWS\System32\tssoft32.acm]  <DSP GROUP, INC.><1.01>
    [D:\WINDOWS\System32\tsd32.dll]  <N/A><N/A>
    [D:\WINDOWS\System32\sl_anet.acm]  <Sipro Lab Telecom Inc.><3.02>
    [D:\WINDOWS\System32\iac25_32.ax]  <Intel Corporation><2.05.53>
    [D:\WINDOWS\System32\l3codeca.acm]  <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
    [D:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [D:\WINDOWS\System32\RAVEXT.DLL]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 8>
[PID: 1768][D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 39>
    [D:\PROGRA~1\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
    [D:\PROGRA~1\RISING\RAV\RSAPPMGR.DLL]  <Rising Corp.><17, 0, 0, 7>
    [D:\PROGRA~1\RISING\RAV\CfgDll.dll]  <rising><17, 0, 0, 60>
    [D:\PROGRA~1\RISING\RAV\RsCommX.dll]  <rising><17, 0, 0, 3>
[PID: 1776][D:\PROGRA~1\RISING\RAV\RAVMON.EXE]  <Beijing Rising Technology Co., Ltd.><17, 0, 1, 37>
    [D:\PROGRA~1\RISING\RAV\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 40>
    [D:\PROGRA~1\RISING\RAV\RSAPPMGR.DLL]  <Rising Corp.><17, 0, 0, 7>
    [D:\PROGRA~1\RISING\RAV\CfgDll.dll]  <rising><17, 0, 0, 60>
    [D:\PROGRA~1\RISING\RAV\RsCommX.dll]  <rising><17, 0, 0, 3>
    [D:\PROGRA~1\RISING\RAV\PngDll.dll]  <Rising><17, 0, 0, 2>
    [D:\PROGRA~1\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
[PID: 1788][D:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 112][D:\Documents and Settings\Administrator\Local Settings\Application Data\winlogon.exe]  < ><1.00.0004>
[PID: 168][D:\WINDOWS\System32\conime.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 220][D:\Documents and Settings\Administrator\Local Settings\Application Data\services.exe]  < ><1.00.0004>
[PID: 228][D:\Documents and Settings\Administrator\Local Settings\Application Data\lsass.exe]  < ><1.00.0004>
[PID: 2680][D:\WINDOWS\system32\NOTEPAD.EXE]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 2712][F:\新建文件夹\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["D:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  Error. [超级解霸3000]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

删除后还有!
gototop
 

我想问下,如果有有两个机器,但安装了两个不同序列号的瑞星,我只知道其中一台机器的瑞星序列号!能不能用这个序列号,下载升级补丁,安装在另一台上!
gototop
 

是吗,发到那里去!能给我邮箱吗
gototop
 

没注意看!SORRY
gototop
 

无邪兄,我把你说的方法试过了,还是不行,在1楼说的下面还会自动生成。
先把日志传上!
2006-07-25,18:45:28

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional  (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><D:\WINDOWS\System32\ctfmon.exe>  [Microsoft Corporation]
    <MSMSGS><; "D:\Program Files\Messenger\msmsgs.exe" /background>  [Microsoft Corporation]
    <Tok-Cirrhatus><"D:\Documents and Settings\Administrator\Local Settings\Application Data\smss.exe">  [ ]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <RavTimer><D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE>  [Beijing Rising Technology Co., Ltd.]
    <RavMon><D:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM>  [Beijing Rising Technology Co., Ltd.]
    <IMJPMIG8.1><; D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <NMGameX_AutoRun><; D:\WINDOWS\System32\Rundll32.exe NMGameX.dll,LiveProcess /aa>  [NMGameX]
    <PHIME2002A><; D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <PHIME2002ASync><; D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
    <SysExplr><; C:\HEROSOFT\Hero3000\SYSEXPLR.EXE>  []
    <Bron-Spizaetus><"D:\WINDOWS\ShellNew\ElnorB.exe">  [ ]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><D:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]

==================================
启动文件夹
[Empty]
  <D:\Documents and Settings\Administrator\「开始」菜单\程序\启动\Empty.pif><N>

==================================
服务
[IMAPI CD-Burning COM Service / ImapiService]
  <D:\WINDOWS\System32\imapi.exe><Microsoft Corporation>
[LexBce Server / LexBceS]
  <D:\WINDOWS\system32\LEXBCES.EXE><Lexmark International, Inc.>
[Rising Process Communication Center / RsCCenter]
  <D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE><rising>
[RsRavMon Service / RsRavMon]
  <D:\PROGRAM FILES\RISING\RAV\Ravmond.exe><Beijing Rising Technology Co., Ltd.>

==================================
浏览器加载项
[解霸]
  {367E0A21-8601-4986-9C9A-153BF5ACA118} <C:\HEROSOFT\Hero3000\MPLAYER.EXE, N/A>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <D:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <D:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
gototop
 

==================================
正在运行的进程
[PID: 388][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 440][\??\D:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 464][\??\D:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [D:\WINDOWS\system32\tssoft32.acm]  <DSP GROUP, INC.><1.01>
    [D:\WINDOWS\system32\tsd32.dll]  <N/A><N/A>
    [D:\WINDOWS\system32\sl_anet.acm]  <Sipro Lab Telecom Inc.><3.02>
    [D:\WINDOWS\System32\iac25_32.ax]  <Intel Corporation><2.05.53>
    [D:\WINDOWS\System32\l3codeca.acm]  <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
[PID: 508][D:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 520][D:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 692][D:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 736][D:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 796][D:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 808][D:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 832][D:\PROGRAM FILES\RISING\RAV\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><17, 0, 1, 53>
    [D:\PROGRAM FILES\RISING\RAV\guidll.dll]  <rising><17, 0, 0, 13>
    [D:\PROGRAM FILES\RISING\RAV\RsCommX.dll]  <rising><17, 0, 0, 3>
    [D:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL]  <Rising Corp.><17, 0, 0, 7>
    [D:\PROGRAM FILES\RISING\RAV\CfgDll.dll]  <rising><17, 0, 0, 60>
    [D:\Program Files\rising\Rav\Scanner.dll]  <Rising><17, 0, 0, 43>
    [D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
    [D:\Program Files\rising\Rav\libload.dll]  <Rising><17, 0, 0, 14>
    [D:\Program Files\rising\Rav\VirusLib.dll]  <Rising><17, 0, 0, 26>
    [D:\PROGRAM FILES\RISING\RAV\MailMon.dll]  < ><17, 0, 0, 9>
    [D:\Program Files\rising\Rav\engine.dll]  <rising><17, 0, 0, 37>
    [D:\Program Files\rising\Rav\UnExe.dll]  <Rising><17, 0, 0, 25>
    [D:\Program Files\rising\Rav\SpamEng.dll]  <N/A><17, 0, 0, 7>
    [D:\Program Files\rising\Rav\ScanEx.dll]  <Rising><17, 0, 0, 33>
    [D:\Program Files\rising\Rav\PostTrt.dll]  <Rising><17, 0, 0, 15>
    [D:\Program Files\rising\Rav\NvFile.dll]  <瑞星><17, 0, 0, 13>
    [D:\PROGRAM FILES\RISING\RAV\MemMon.dll]  <北京瑞星><17, 8, 0, 0>
    [D:\PROGRAM FILES\RISING\RAV\expscan.dll]  <N/A><17, 0, 0, 6>
    [D:\PROGRAM FILES\RISING\RAV\mPorts.dll]  <Beijing Rising Technology Corporation Limited><3, 0, 0, 3>
    [D:\PROGRAM FILES\RISING\RAV\regmon.dll]  < ><17, 0, 0, 12>
    [D:\Program Files\rising\Rav\ScanMac.dll]  <rising><17, 0, 0, 17>
    [D:\PROGRAM FILES\RISING\RAV\HookWeb.dll]  <rising><17, 0, 0, 4>
    [D:\Program Files\rising\Rav\ScanSct.dll]  <rising><17, 0, 0, 27>
    [D:\Program Files\rising\Rav\ScanExec.dll]  <><17, 0, 0, 21>
    [D:\Program Files\rising\Rav\Unpacker.dll]  <rising><17, 0, 0, 19>
    [D:\Program Files\rising\Rav\ExtOLE.dll]  <rising><17, 0, 0, 19>
[PID: 848][D:\PROGRAM FILES\RISING\RAV\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 27>
    [D:\PROGRAM FILES\RISING\RAV\RsCommX.dll]  <rising><17, 0, 0, 3>
    [D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
[PID: 876][D:\WINDOWS\system32\LEXBCES.EXE]  <Lexmark International, Inc.><7.1>
    [D:\WINDOWS\system32\lexp2p32.dll]  <Lexmark International, Inc.><7.1>
    [D:\WINDOWS\system32\lex2kusb.dll]  <Lexmark International, Inc.><7.1>
[PID: 944][D:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)>
    [D:\WINDOWS\system32\LEXLMPM.DLL]  <Lexmark International, Inc.><7.1>
    [D:\WINDOWS\system32\LexBce.dll]  <Lexmark International, Inc.><7.1>
    [D:\WINDOWS\System32\spool\PRTPROCS\W32X86\LG12PP5C.dll]  <Lexmark International><1.0.7.2>
    [D:\WINDOWS\system32\lg12pwr.dll]  <Lexmark International, Inc.><1, 0, 1, 0>
[PID: 948][D:\WINDOWS\system32\LEXPPS.EXE]  <Lexmark International, Inc.><7.1>
    [D:\WINDOWS\system32\LEXBCE.DLL]  <Lexmark International, Inc.><7.1>
[PID: 1112][D:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1188][D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE]  <rising><17, 0, 0, 1>
[PID: 1716][D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 39>
    [D:\PROGRA~1\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
    [D:\PROGRA~1\RISING\RAV\RSAPPMGR.DLL]  <Rising Corp.><17, 0, 0, 7>
    [D:\PROGRA~1\RISING\RAV\CfgDll.dll]  <rising><17, 0, 0, 60>
    [D:\PROGRA~1\RISING\RAV\RsCommX.dll]  <rising><17, 0, 0, 3>
[PID: 1724][D:\PROGRA~1\RISING\RAV\RAVMON.EXE]  <Beijing Rising Technology Co., Ltd.><17, 0, 1, 37>
    [D:\PROGRA~1\RISING\RAV\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 40>
    [D:\PROGRA~1\RISING\RAV\RSAPPMGR.DLL]  <Rising Corp.><17, 0, 0, 7>
    [D:\PROGRA~1\RISING\RAV\CfgDll.dll]  <rising><17, 0, 0, 60>
    [D:\PROGRA~1\RISING\RAV\RsCommX.dll]  <rising><17, 0, 0, 3>
    [D:\PROGRA~1\RISING\RAV\PngDll.dll]  <Rising><17, 0, 0, 2>
    [D:\PROGRA~1\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
[PID: 1800][D:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 172][D:\Documents and Settings\Administrator\Local Settings\Application Data\winlogon.exe]  < ><1.00.0004>
[PID: 196][D:\WINDOWS\System32\conime.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 240][D:\Documents and Settings\Administrator\Local Settings\Application Data\services.exe]  < ><1.00.0004>
[PID: 276][D:\Documents and Settings\Administrator\Local Settings\Application Data\lsass.exe]  < ><1.00.0004>
[PID: 804][F:\新建文件夹\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
[PID: 1076][D:\WINDOWS\explorer.exe]  <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["D:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  Error. [超级解霸3000]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

发现,原来删除的还在,后用瑞星杀,就是无邪兄告诉我的。下栽升级包。后删除病毒。
无邪兄,我想这个或许对你有用,我把图片给你发过来研究!

附件附件:

下载次数:182
文件类型:application/octet-stream
文件大小:
上传时间:2006-7-13 22:13:46
描述:



gototop
 

yanmings 我已经把那个压缩了密码0000。你看收到没
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT