实在是看不明白上面的。不过我还用瑞星的听诊器给听了一下。也发上来让大家看看吧!
扫描结果:
无可疑文件
系统活动进程
C:\PROGRAM FILES\SYMANTEC\NORTON GHOST 2003\GHOSTSTARTSERVIE.EXE
C:\WINDOWS\SYSTEM32\SVCH0ST.EXE
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\WINDOWS\SYSTEM32\QUARTZ32.DLL
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\QUARTZ32.DLL
C:\WINDOWS\SYSTEM32\WINLOGER.EXE
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\WINDOWS\SYSTEM32\QUARTZ32.DLL
C:\WINDOWS\SYSTEM32\SP00LSV.EXE
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\WINDOWS\SYSTEM32\QUARTZ32.DLL
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\QUARTZ32.DLL
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\QUARTZ32.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SPTED.DLL
C:\WINDOWS\SYSTEM32\QUARTZ32.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\QUARTZ32.DLL
F:\瑞星\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRA~1\WINDOW~2\WMPBAND.DLL
C:\PROGRA~1\YOK.COM\SUPERS~1\YOK_SUPERSEARCH.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
F:\瑞星\RISING\RFW\RFWSRV.EXE
F:\瑞星\RISING\RFW\RFWRULE.DLL
F:\瑞星\RISING\RFW\RFWLOG.DLL
F:\瑞星\RISING\RFW\RFWDRV.DLL
F:\瑞星\RISING\RFW\PSAPI.DLL
F:\瑞星\RISING\RFW\MONDRV.DLL
F:\瑞星\RISING\RFW\PROCLIB.DLL
F:\瑞星\RISING\RFW\MPORTS.DLL
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\HPZSNT07.DLL
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
F:\瑞星\RISING\RFW\RFWMAIN.EXE
F:\瑞星\RISING\RFW\RSGUILIB.DLL
F:\瑞星\RISING\RFW\RSCOMMON.DLL
F:\瑞星\RISING\RFW\PNGDLL.DLL
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\WINDOWS\SYSTEM32\KAKATOOL.DLL
C:\PROGRA~1\YOK.COM\SUPERS~1\YOK_SUPERSEARCH.DLL
C:\WINDOWS\SYSTEM32\QUARTZ32.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
F:\瑞星\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\DOCUMENTS AND SETTINGS\CONGCONG\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\OP6RGDYZ\RSDETECT[1].EXE
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\PROGRAM FILES\SYMANTEC\NORTON GHOST 2003\GHOSTSTARTTRAYAPP.EXE
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\SYSTEM32\RES.EXE
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOHMR08.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPQCXM08.DLL
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPODVB08.DLL
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOCXI08.DLL
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPQCOB08.DLL
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPODIO08.DLL
C:\WINDOWS\SYSTEM32\HPZIDR12.DLL
C:\WINDOWS\SYSTEM32\HPZIPR12.DLL
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOTDD01.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPODVD08.DLL
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPQCXM08.DLL
C:\WINDOWS\SYSTEM32\WINWB86.IME
F:\新浪下载助手\DUDUACC.EXE
F:\新浪下载助手\DDDSKIN.DLL
F:\新浪下载助手\DDDDL.DLL
C:\WINDOWS\SYSTEM32\WINWB86.IME
F:\新浪下载助手\DUDUPROS.EXE
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\WINDOWS\SYSTEM32\QUARTZ32.DLL
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOEVM08.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPQCXM08.DLL
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOCXI08.DLL
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPQCOB08.DLL
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOSTS08.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPQTAP08.DLL
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOSTS08.RSC
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPQCXM08.DLL
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOCXI08.DLL
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPQCOB08.DLL
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPODIO08.DLL
C:\WINDOWS\SYSTEM32\HPZIPR12.DLL
C:\WINDOWS\SYSTEM32\HPZIDR12.DLL
C:\WINDOWS\MSAGENT\AGENTSVR.EXE
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\WINDOWS\SYSTEM32\MSACM32.DRV
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32
PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
SoundMan = SOUNDMAN.EXE
GhostStartTrayApp = C:\PROGRAM FILES\SYMANTEC\NORTON GHOST 2003\GHOSTSTARTTRAYAPP.EXE
NeroFilterCheck = C:\WINDOWS\SYSTEM32\NEROCHECK.EXE
IMSCMig = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /PRELOAD
BigDogPath = C:\WINDOWS\VM_STI.EXE VIMICRO USB PC CAMERA 301X
YOKAssiant = RUNDLL32.EXE C:\PROGRA~1\YOK.COM\SUPERS~1\YOK_SUPERSEARCH.DLL,YOKASSIANT
RfwMain = "F:\瑞星\RISING\RFW\RFWMAIN.EXE" -STARTUP
RavTask = "F:\瑞星\RISING\RAV\RAVTASK.EXE" -SYSTEM
res = C:\WINDOWS\SYSTEM32\RES.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
RavStub = "F:\瑞星\RISING\RAV\RAVSTUB.EXE" /RUNONCE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
MSMSGS = "C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE" /BACKGROUND
msq = C:\WINDOWS\SYSTEM32\IEXPLORER.EXE
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = notepad.exe %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
ScCertProp = WLNOTIFY.DLL
Schedule = WLNOTIFY.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
wlballoon = WLNOTIFY.DLL