瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我的电脑中了Win32.Parite.a.用瑞星杀了好几次还杀不完,付扫描报告

1   1  /  1  页   跳转

我的电脑中了Win32.Parite.a.用瑞星杀了好几次还杀不完,付扫描报告

我的电脑中了Win32.Parite.a.用瑞星杀了好几次还杀不完,付扫描报告

2006-07-29,10:04:37

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联


启动项目


注册表

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
(ctfmon.exe)(C:\WINDOWS\system32\ctfmon.exe) [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(load)() []
(run)() []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
(PHIME2002ASync)(rem C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC) [Microsoft Corporation]
(PHIME2002A)(rem C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName) [Microsoft Corporation]
(EPSON Stylus C41 Series)(rem C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C41 Series" /O5 "LPT1:" /M "Stylus C41") []
(BluetoothAuthenticationAgent)(rem rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent) []
(RavTimer)(rem C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE) [Beijing Rising Technology Co., Ltd.]
(Thunder)(rem "C:\Program Files\Thunder Network\Thunder\ThunderShell.exe" /s) []
(YLive.exe)(C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe) [ ]
(CnsMin)(Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32) [北京三七二一科技有限公司]
(yassistse)("C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe") [Yahoo!]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(shell)(Explorer.exe) [Microsoft Corporation]
(Userinit)(C:\WINDOWS\system32\Userinit.exe,) [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(AppInit_DLLs)() []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(UIHost)(logonui.exe) [Microsoft Corporation]


最后编辑2006-07-29 12:13:29
分享到:
gototop
 

启动文件夹

[腾讯QQ]
(C:\Documents and Settings\XX\「开始」菜单\程序\启动\腾讯QQ.lnk)(N)



--------------------------------------------------------------------------------



服务

[DuDu Accelerator o / DDDProxy]
()(N/A)
[EPSON Printer Status Agent2 / EPSONStatusAgent2]
(C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe)(SEIKO EPSON CORPORATION)
[JMediaService / JMediaService]
(C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\MMSASS~1\MMSSVER.DLL,Service)(N/A)
[Kingsoft Personal Firewall Service / KPfwSvc]
("C:\KAV2005\KPfwSvc.EXE")(N/A)
[Kingsoft Antivirus KWatch Service / KWatchSvc]
()(N/A)
[Rising Process Communication Center / RsCCenter]
(C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE)(rising)
[Security Expert Back Service / SecBkSrv]
(C:\Program Files\Terminator\SecBkSrv.exe)(CNNS)
[Network ConnectionHuahua101 / Service101]
(C:\WINDOWS\system32\lassess.exe)()
[Te1net / Te1net]
(C:\WINDOWS\System32\VIPTray.exe)(N/A)
gototop
 

浏览器加载项

[Yahoo!Photo]
{33BBE430-0E42-4f12-B075-8D21ACB10DCB} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China)
[AntiFish Class]
{38928D50-8A48-44C2-945F-D2F23F771410} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll, Yahoo.)
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!)
[DragSearch BHO]
{62EED7C6-9F02-42f9-B634-98E2899E147B} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, )
[IEHlprObj Class]
{D424FE4E-CAF9-4fdd-BC5F-E6E6B91D53BF} (C:\Progra~1\NetMeeting\nmview.dll, Microsoft Corporation)
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} (C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC)
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!)
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.)
[Ravonline]
{DA984A6D-508E-11D6-AA49-0050FF3C628D} (C:\WINDOWS\Downloaded Program Files\RsOnline.dll, Beijing Rising Tech. Co., Ltd.)
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} (C:\WINDOWS\system32\xunleibho_v14.dll, N/A)
[internet explorer helper]
{02C9B9AB-6372-46C5-B356-773FAF3B6B1E} (C:\WINDOWS\fonts\msshapi.dll, )
[MonitorURL Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} (C:\PROGRA~1\DESKAD~1\deskipn.dll, )
[wmpdrm]
{0E674588-66B7-4E19-9D0E-2053B800F69F} (C:\WINDOWS\system32\wmpdrm.dll, Allsum Info. Tech. Ltd.)
[实用搜索]
{15ADF205-4C54-4CFE-AC88-1EA0BA6D06A0} (, N/A)
[MyIEHelper Class]
{16A770A0-0E87-4278-B748-2460D64A8386} (C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4683.dll, Microsoft Corporation)
[FltSetUp Class]
{1D49D58D-5C84-4B50-8359-D9809BEB2B32} (C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll, Microsoft Corporation)
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} (C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation)
[&Google]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} (c:\program files\google\googletoolbar1.dll, N/A)
[Adobe-Plugins Manager]
{2AFA7CEC-26D9-4256-AF57-497A13180BA5} (C:\WINDOWS\System32\Agm.dll, AdoBeSoft Co.)
[Yahoo!Photo]
{33BBE430-0E42-4F12-B075-8D21ACB10DCB} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China)
[AntiFish Class]
{38928D50-8A48-44C2-945F-D2F23F771410} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll, Yahoo.)
[CaiShowBH Class]
{3AF40CB8-B3BA-4E2D-8968-4BF8DB172997} (C:\Program Files\CaiShow Tech\CaiShow\BrowerHelper.dll, N/A)
[雅虎助手]
{406F94F0-504F-4A40-8DFD-58B0666ABEBD} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!)
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} (C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation)
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} (C:\Program Files\Tencent\QQ\QQIEHelper.dll, N/A)
[NetAccelerate Class]
{5673A7C0-95CC-4646-BB07-3BD71234CEF9} (C:\WINDOWS\system32\wuwebex.dll, Microsoft Corporation)
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} (C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC)
[IEYHlprObj Class]
{5C761D09-377E-4EAC-ADA1-C9CDE39B5674} (C:\WINDOWS\IEYHelper.dll, Eastday Corporation)
[DragSearch BHO]
{62EED7C6-9F02-42F9-B634-98E2899E147B} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, )
[ActiveBHO Class]
{63C55A7F-6E29-8D4F-5C76-4F850F28D13A} (C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll, )
[Vision]
{6671A431-5C3D-463D-A7CF-5587F9B7E191} (C:\PROGRA~1\MMSASS~1\mmsass~1.dll, )
[stdup]
{6A512BF7-EC78-4E8D-9841-6C02E8FA9838} (C:\WINDOWS\System32\stdup.dll, MStdup Co Ltd.)
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[金山快译(&K)]
{6C3797D2-3FEF-4CD4-B654-D3AE55B4128C} (C:\PROGRA~1\Kingsoft\FastAIT\IEBand.dll, N/A)
[Status Class]
{7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} (C:\Program Files\baigoo\BGooBHO.dll, )
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} (C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll, Thunder Networking Technologies,LTD)
[Mini PPGou BHO]
{92FB5F8F-8254-4978-9C50-03D9B0405062} (C:\PROGRA~1\MINIPP~1\MINIPP~1.DLL, N/A)
[IE标准栏]
{954F618B-0DEC-4D1A-9317-E0FC96F87865} (C:\WINDOWS\system32\amstreamxb.dll, )
[IEHlprObj Class]
{999ADFA2-8AD1-47FF-97FC-69FB847458F4} (C:\Progra~1\NetMeeting\nmview.dll, Microsoft Corporation)
[WinSC Class]
{9ACEEE31-1440-471B-AA46-72B061FE7D61} (C:\WINDOWS\system32\WinSC.dll, N/A)
[win32core Class]
{A297EEAE-A541-496B-B2AE-554AD0153B72} (C:\WINDOWS\system32\win32help01.dll, N/A)
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} (C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A)
[Google Toolbar Helper]
{AA58ED58-01DD-4D91-8333-CF10577473F7} (c:\program files\google\googletoolbar1.dll, N/A)
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} (C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation)
[T2BHO Class]
{B1D147E7-873E-4909-8127-695D9BB78728} (C:\WINDOWS\Downloaded Program Files\barhelp24.0.dll, N/A)
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} (%SystemRoot%\System32\shdocvw.dll, N/A)
[Webacc Class]
{CAC068F3-A608-406B-8581-458788A67694} (C:\WINDOWS\system32\svchost.dll, )
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.)
[IEHlprObj Class]
{D424FE4E-CAF9-4FDD-BC5F-E6E6B91D53BF} (C:\Progra~1\NetMeeting\nmview.dll, Microsoft Corporation)
[]
{ECE87D9F-9933-483B-942B-7D7FB569F525} (C:\WINDOWS\system32\Mfhlp.dll, N/A)
[BHelper Class]
{F2E37336-BFDB-409B-8D0E-6F013C438B20} (C:\WINDOWS\system\81aoe810.dll, N/A)
[google bar]
{F651FCAA-F826-4922-8990-C6F99CC67AFC} (C:\WINDOWS\Win32ef.dll, N/A)
gototop
 

正在运行的进程

[PID: 1156][C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\ljhbace.exe] (N/A)(N/A)
[C:\DOCUME~1\XX\LOCALS~1\Temp\gna2.tmp] (N/A)(N/A)
[PID: 1176][C:\WINDOWS\Explorer.EXE] (Microsoft Corporation)(6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
[C:\DOCUME~1\XX\LOCALS~1\Temp\gna2.tmp] (N/A)(N/A)
[PID: 1516][C:\WINDOWS\system32\taskmgr.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[C:\DOCUME~1\XX\LOCALS~1\Temp\gna2.tmp] (N/A)(N/A)
[PID: 2552][C:\Program Files\Tencent\TT\TTraveler.exe] (腾讯公司)(3.0.0.250)
[C:\DOCUME~1\XX\LOCALS~1\Temp\gna2.tmp] (N/A)(N/A)
[C:\Program Files\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll] (腾讯公司)(1, 1, 0, 5)
[C:\Program Files\Tencent\TT\Plugins\TWeather\TWeather.dll] ()(1, 0, 0, 3)
[C:\Program Files\Tencent\TT\PersonalDesktop.dll] (深圳市腾讯计算机系统公司QQ工作小组)(1, 0, 0, 4)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] ( )(2, 0, 1, 1007)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrepair.dll] (Yahoo)(1, 0, 6, 1319)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasfsks.dll] (3721.com)(2, 1, 1, 87)
[C:\PROGRA~1\yahoo!\assistant\Shell\yAssecblk.dll] (Yahoo)(1, 0, 2, 1002)
[C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll] ()(2, 1, 6, 1046)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yoptimum.dll] (Yahoo)(1, 0, 1, 1001)
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] (Macromedia, Inc.)(8,0,22,0)
[PID: 2712][C:\WINDOWS\system32\ctfmon.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[C:\DOCUME~1\XX\LOCALS~1\Temp\gna2.tmp] (N/A)(N/A)
[PID: 3316][C:\Program Files\sreng2\SREng2\SREng.exe] (Smallfrogs Studio)(2.0.21.505)
[C:\DOCUME~1\XX\LOCALS~1\Temp\gna2.tmp] (N/A)(N/A)



--------------------------------------------------------------------------------



文件关联

.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]



--------------------------------------------------------------------------------


Winsock 提供者



--------------------------------------------------------------------------------
gototop
 

我的IE好象还被劫持了,老弹网页..就是杀过也还是弹....
gototop
 

BZ帮帮忙吧~~小弟我在线等的...
gototop
 

谢谢,我这就去做
gototop
 

已经好了~谢谢你们~~
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT